## What Release the prepared AgentOps update as **3.7.0**, the minor release after 3.6.0. Align the CLI and plugin versions, regenerate the Gemini manifest, and rename/update the curated notes and changelog links. ## Why The operator selected a minor release. No 4.0.0 tag or release was published. Migration instructions and the documented removed commands/skills remain accurate. ## How I tested - Go lint and focused version/manifest tests passed. - Full regeneration parity, changelog mirror parity, and release-note coverage from v3.6.0 passed. - The exact 3.7.0 release rehearsal passed in 143 seconds; all 73 full repository gates passed. All 12 security tools ran with zero missing/error tools, critical findings or security-high findings; existing advisories remain reported. - All nine hosted checks passed on `092e1814b6cba46cd9ac1d797dab2a5c8c7c188c`, including Go race/shuffle tests and 1,509 executed Bats passes (31 environment-dependent skips, zero failures). A new CLI wiring regression confirms `ao version --json` reports the build version. - Actual fresh native Claude/Codex 3.7.0 installs and upgrades from 3.6.0 passed with exact 34-skill inventories. Existing implementation validation from PR #1143 remains applicable to unchanged source. - Fresh author-distinct correction review passed for exact head `092e1814b6cba46cd9ac1d797dab2a5c8c7c188c`, covering all changed paths and four acceptance criteria with no unchecked scope. Verdict digest: `e7b24a297a0b232138de011473df8be6eb3eeaf47afd1f300398eecafab2fbab`. ## Checklist - [x] Version owners and generated metadata agree on 3.7.0. - [x] Migration/removal guidance is preserved. - [x] Exact-candidate release checks pass before tagging. - [x] Fresh correction review is recorded before tagging.
14 KiB
Highlights
AgentOps 3.7 makes native coding the default. Give your coding agent accepted behavior and repository checks, implement the change, and have a fresh context judge the exact result. No AgentOps skill, session bootstrap, hook or orchestration service is required. The optional menu has 34 skills, down from the 52 shipped in 3.6.0, with clearer owners for engineering, memory, review and runtime tasks.
The CLI adds recovery repairs and exact-content evidence helpers. Optional context-budget delegation lets Claude Haiku or Codex Luna read large files and write individual targets while the parent receives compact findings or receipts. Separate opt-in read guards block oversized unbounded reads. This release also removes published command, skill and scripted workflow entry points; the migration guidance below is part of the upgrade.
Upgrade Notes
- Update explicit uses of the retired skills using the migration table. The 34-skill menu is optional; ordinary native work needs no replacement skill invocation.
learnmoves tomemory,swarmtoagent-native,codebase-recontoresearch, andbootstrap/handofftodoc. - Replace
ao evalandao redactautomation before updating the binary. Use your repository's evaluator and the owner's disclosure-review process. Genericao provenancecan retain factual evidence but does not run either retired service. - Replace
workflows/rpi.jscalls with native execution or an explicitly selected RPI skill invocation. The scripted retry machinery has been removed. Trackers, Git, scheduling and delivery remain under their existing owners. - Update managed plugins through their runtime. For source links, update the canonical checkout, inspect retired names, and relink the surviving skills you selected.
ao skills link --skill NAMEcan be repeated; without selectors it links the full menu. It does not remove foreign entries or uninstall previously selected skills. - Codex role resources ship in the skill bundle, but installing the plugin alone does not register them. From a checkout, run
bash scripts/install-codex-context-agents.shfor personal configuration or add--project, then restart Codex. See Codex installation for prerequisites and separate hook setup. - Read-budget guards remain disabled until explicitly installed. The Claude and Codex installers preserve existing settings and backups. Codex hook definitions still need review/trust in its native hook manager; linked-worktree hook installation has documented restrictions.
- Preserve existing
.agents/evidence. New CDLC proof uses a caller-selected protected external non-Git destination. A missing route is a failure, not permission to fall back to repository storage.ao initremains an optional local setup command and is not required for native work. - Builds use the Go 1.27.1 toolchain;
cli/go.modretains a Go 1.26.0 language floor. Older installations download the selected toolchain or fail according toGOTOOLCHAIN. CI and maintained Python checks use Python 3.14.
Breaking Changes
- The entire published
ao evalfamily andao redactare removed. Invocations fail as unknown commands with migration pointers. workflows/rpi.jsand its scripted control machinery are removed. AgentOps no longer provides that aggregate retry controller.- Twenty skill roots present in 3.6.0 are removed:
anti-ceremony,automation-shape-routing,bootstrap,codebase-recon,converter,fitness,goals,handoff,learn,operationalize,pattern-mining,product,scaffold,scope,shared,standards,status,swarm,toil-miningandworkflow-builder. Surviving owners cover useful retained behavior; the old names are not aliases.memoryandskill-evalare the two new roots relative to 3.6.0. - The default workflow no longer performs mandatory RPI, recall, bootstrap or learning stages. Callers that need those selected behaviors must request them explicitly. Acceptance, exact content and fresh independent judgment remain the completion bar.
At a Glance
| Area | What changes for the user |
|---|---|
| Native work | Zero mandatory skills; optional guidance when a task needs it. |
| Skills | 34 current roots with explicit migration from the 52-root 3.6.0 bundle. |
| CLI | Recovery repairs, external context routing and exact-content evidence helpers. |
| Context use | Optional Claude/Codex readers, writers and separately installed read guards. |
| Validation | Fresh author-distinct judgment; structural and runtime checks report their actual scope. |
| Ownership | The caller's tracker, Git, runtime, memory destination and delivery policy stay authoritative. |
Product Areas
Install, Upgrade, and Distribution
- Fixed: Full release security checks scan repository-wide and block on Python collection or runtime failures. Nightly installs the declared evaluator dependencies, and importlib collection handles duplicate source/projection test names.
- Added: Optional context-role and read-guard installers preserve unrelated configuration, use unique backups and refuse malformed or unsupported destinations before publishing changes.
- Changed: Native onboarding leads with the agent and shell; managed full plugins and selected source links remain optional distribution paths. Release version defaults are aligned at 3.7.0.
- Changed: Release and installation CI use Go 1.27.1 and Python 3.14. Snapshot release builds remain a no-publish check of the distribution path.
CLI and Operator Commands
- Added:
ao provenance snapshot-intent,manifest,digest,store-verdict,verify-manifest,verify-verdictandverify-subjectsupport exact-content evidence without invoking a tracker, Git or a semantic judge.evidence-orphansinspects references whose bound subjects changed. - Added:
ao provenance verify-judgmentschecks caller-required review profiles against native receipts, independent acceptance and exact subject identity. Requested model names or assistant self-descriptions cannot establish runtime identity. - Added:
ao config contextresolves explicit external routes and can recover the same route from a selected native BD maintenance anchor.ao session read-sourceemits bounded source spans, continuation hashes and file identity facts under an explicit policy. - Added:
ao provenance mine-session --view excerptsprovides bounded cited transcript excerpts without checkpoint writes. The existing event view remains available. - Changed:
ao demoandao quick-startdescribe native execution;ao demo --rpiopts into the workflow example.ao status --evidence-rootreads an explicitly selected evidence store.ao skills link --skillsupports selected skills. - Fixed: Doctor uses unique action backups, validates undo inputs before restoration and protects rename conflicts. Mining checkpoints reject unsafe paths and overlapping writers. Handoffs preserve work/session associations and select the newest valid artifact correctly.
- Fixed: Skill search, evidence status, provenance graph validation, scenario-result publication and changed-path gate routing handle previously missed malformed, corrupt and path-dependent cases.
- Removed: The
ao evalfamily, its unused runtime adapters andao redact.
Skills and Workflows
- Fixed: Claude writers capture check status without a second invocation. Live success and deliberately failing checks ran once, and the direct child returned a plain JSON receipt.
- Changed: The 34-skill menu consolidates retained behavior into existing owners. Plan shapes missing acceptance in the conversation or tracker; Implement repairs known defects; Validate judges exact content from fresh context. RPI remains explicitly selectable.
- Changed: Final judgment is assigned once while preserving every required review leg. A requested retrospective consumes the known outcome and judgment, or names an interim cutoff; it does not become an extra code-acceptance gate.
- Added: Memory combines optional recall, bounded episode mining and reviewed topic curation. CASS and MS retrieve supporting evidence on demand; later work must demonstrate whether adopted guidance helped.
- Added: Skill Eval provides bounded routing and coding evaluations for a named skill decision. Structural conformance, repeated agreement and completed runtime sessions are not evidence of universal skill benefit.
- Added: Claude
bulk-readandcode-writeworkflows delegate to cheap workers and return bounded findings or receipts. Readers continue to EOF despite answer caps; writers require a reference, preserve caller target identities and preflight distinct batch targets. - Removed: The retired skill roots and scripted RPI loop listed under Breaking Changes. Anti-ceremony obligations survive in the operating contract without requiring a standalone skill.
Codex and Runtime Integrations
- Added: Codex-native
bulk-readerandcode-writerTOML roles pingpt-5.6-lunawith low/medium effort and fresh child contexts. The generated bundle carries their resources; the optional installer registers the names. - Fixed: Project registrations point at the real source-owned role TOML files. The installed Codex runtime rejected registrations that pointed through symlinked role paths.
- Added: Claude plugin reader/writer subagents default to Haiku. Native agent dispatch is the default executor path; headless and factory adapters remain selected alternatives.
- Changed: Runtime guidance distinguishes actual native model/session identity, completion, deterministic checks and semantic judgment. Read-only reader instructions do not establish sandbox confinement.
Hooks and Lifecycle
- Added: Separate opt-in Claude
Read|Bashand CodexBashread-budget guards block supported oversized unbounded reads above a configurable budget, default 350 lines. Refusals suggest a bounded slice or reader delegation; waivers and hashed telemetry remain supported. - Fixed: Shell parsing handles quoted literal paths, end-of-options and negative
headlimits without overflow, and avoids false file attribution for uncertain syntax. Repeated refusals are compact. - Fixed: Installer checks include matcher and handler type, preserve unique settings backups and leave hook trust with the native runtime.
Eval, Validation, and Release Gates
- Added: Source-span integrity tests, native judgment-receipt verification, evidence-orphan checks, seeded-defect probes and bounded installed-skill coding trials strengthen evidence about specific behaviors.
- Fixed: Probe contamination and incomplete binding cannot silently count as proven coverage. Skill-trial reporting separates independently accepted work from control artifacts and runtime completion.
- Fixed: Component-owned checks, changed-path routing, generated projections, executable script modes, documentation checks and the local aggregate runner received conformance repairs.
- Changed: Required Go checks include the repository lint contract as well as build, vet and race/shuffled tests. CI and release checks remain mechanical evidence, separate from fresh semantic judgment.
Docs and Onboarding
- Changed: README, runtime installation pages, migration guidance, the workflow reference and the generated skill router describe native execution and the current menu consistently.
- Added: Context-budget design and runtime evidence document invocation, installation, refused reads, role discovery and observed limitations. Memory references document authorized sources, protected drafts and supported topic curation.
- Changed: The release summary covers the full v3.6.0-to-v3.7.0 interval, including CLI removals, recovery, evidence helpers, skill consolidation and runtime changes.
Security, Privacy, and Supply Chain
- Security: Evidence helpers require explicit protected non-Git storage, reject malformed identities and conflicting JSON fields, and publish immutable content-addressed artifacts atomically. Declared Git storage boundaries must resolve before writes.
- Security: Session-mining state protects source files and rejects unsafe ownership, permission and path configurations. Bounded excerpt extraction labels provenance and preserves source/destination authorization boundaries.
- Changed: Source routing checks owner, task, model, destination and native maintenance facts. They do not implement restricted-source access enforcement; the supported source-reading path remains limited to synthetic or already-cleared inputs.
- Changed: Pinned GitHub Actions and dependencies were refreshed, including
golang.org/x/text0.42.0, NumPy 2.5.3, SciPy 1.18.1 and Harbor 0.23.0.
Contributor/Internal Refactors
- Refactored: Consumer-free evaluation machinery and retired workflow scripts were removed while supported bounded evaluation tooling stayed with its declared consumers.
- Changed: Canonical skill sources own behavior, and integrated regeneration owns portable Codex, skill inventory, image and documentation projections. The menu no longer carries retired roots as live skills.
- Fixed: Architecture-check temporary-directory races, Go lint compatibility and source-equivalence checks received targeted repairs.
Known Issues
- Codex's reader followed read-only instructions in live testing, but inherited its writable parent's sandbox. Enforced reader write confinement remains unproven; do not treat the role as a security boundary.
- Installing a Codex plugin does not activate custom agent registrations or trust hooks. The separate role installer and native hook review are required for those optional features.
- The guard covers supported native read/shell paths, not every possible way a program or hosted tool can read data. Bounded output and a reader's completion receipt do not prove semantic comprehension.
- Structural validation of all 34 packages and live tests of selected paths do not establish behavioral efficacy for every skill or task. No generalized token-cost reduction percentage is claimed.
- Restricted-source enforcement remains unavailable for the context/source helpers. Native freshness facts are attestations with documented trust boundaries, not cryptographic proof of process isolation.