This is the multi-page printable view of this section. .
Releases and evidence
- 1: 0.10.2 — stable Workbench styling
- 2: 0.10.1 — trustworthy scientific evaluation loop
- 3: 0.10.0 — incomplete publication
- 4: 0.9.8 — Host path translation fix
- 5: 0.9.7 — Context contracts and bilingual site
- 6: 0.9.6 — Host-first execution
- 7: 0.10.3 — actionable project-directory recovery
This page distinguishes a formal tag/public package from local development and separates package publication from verification evidence.
Current release
0.10.3 · Actionable project-directory recovery
- Formal tag:
v0.10.3 - Compatibility: Harbor
>=0.21,<0.22 - Main change: protected project-directory failures now use a stable redaction-safe error, actionable bilingual recovery steps, collapsed technical details and a copy action; source installs retain locked dev dependencies under production hosts.
- Evidence: targeted service/client/setup regressions, a built client bundle and a real source-development setup.
- Limit: source and bundle checks do not replace complete cross-platform TCC/ACL or visual acceptance; desktop app signing remains a Host concern.
Read the 0.10.3 evidence summary.
Release history
| Version | Product step | Evidence note |
|---|---|---|
| 0.10.2 | Stable Workbench styling | Targeted client lifecycle/layout checks and coordinated package publication |
| 0.10.1 | Trustworthy scientific evaluation loop | Coordinated npm/PyPI release with complete automated package and deterministic fixture evidence |
| 0.10.0 | Publication incomplete | npm published; PyPI/tag CI failed before Python artifact build; superseded by 0.10.1 |
| 0.9.8 | Host path translation fix | Synthetic Host integration and complete package checks; no model call |
| 0.9.7 | Context Web contract fixes and bilingual site | Automated package/source/site and public artifact checks; no real-provider evaluation |
| 0.9.6 | Host-first execution and environment identity | Automated package/source checks; no real-provider evaluation |
| 0.9.5 | Consolidated Workbench and release evidence gallery | Synthetic component fixtures; not real provider evaluation |
| 0.9.4 | Native page context and conversation handoff | Synthetic controlled-model interaction evidence |
| 0.9.3 | Reviewed actions and background operations | Component/service fixtures and failure states |
| 0.9.2 | Historical cold-start fixes and public package evidence | Also carried fixes after incomplete 0.9.1 publication |
| 0.9.1 | Publication incomplete | Do not treat as a normal shipped card |
| 0.8.x | Historical Generation Evaluation | Introduced redacted Session Batch and completed-unscored |
| 0.7.x | Four-concept onboarding and Model Broker | Lowered configuration complexity while retaining strict identities |
| 0.6.x | Evaluator governance and meta-evaluation | Separated score validity from raw rewards |
| 0.5.x | Comparable Stack/Manifest/Context architecture | Fixed “who” and “measuring stick” |
| 0.1–0.4 | Candidate prototype → packaged DSH Web integration | Established immutable Candidate, Skill, Adapter and native UI |
Development preview
The untagged one-click updater from commit 8bb59e2 was withdrawn before 0.9.7. Settings checks versions and copies an exact command only when complete installation identity is available; the browser does not execute registry packages. Durable recovery, stronger mutation authorization and broader browser/accessibility coverage remain roadmap work.
1 - 0.10.2 — stable Workbench styling
Released 2026-09-27. Formal source tag: v0.10.2.
Fixed
- Each live Harbor client-plugin lifetime owns its own stylesheet tag, so disposing an older duplicate or hot-reloaded instance cannot remove the active Workbench styles.
- Job status text stays at the card’s top-right corner without stretching to the title height.
- The status background bubble is removed while completion, running, attention and failure colors and symbols remain visible.
- Plugin, Skill and Python Adapter identities align at 0.10.2.
Verification
The 0.10.2 archive records the targeted lifecycle/layout checks and coordinated package publication evidence.
Limits
Targeted source and bundle checks do not replace a complete cross-platform visual acceptance pass. No paid or real-provider Candidate Job was run because this patch does not change evaluation behavior.
Default Host mode remains unrestricted and is not a sandbox. Historical results never become Promotion Gate evidence, and a Job seal is a content-integrity receipt rather than an external signature.
2 - 0.10.1 — trustworthy scientific evaluation loop
Released 2026-09-26. Formal source tag: v0.10.1.
Shipped
- Formal Candidate Experiments execute only the exact
harbor-dsh-evaluator/v2bundle through a strict private Dataset adapter; Dataset verifiers and v1 fallback cannot become score authority. - Trusted Evaluation Reports, content-addressed Job bundles, cross-artifact Evaluator identity, score suppression and execution-failure handling keep invalid evidence out of quality conclusions.
- Repeat-aware Experiments, paired uncertainty, immutable Promotion reports, exact Policy snapshots and stronger Docker/environment invariants make governed comparison auditable.
- Historical diagnosis, Candidate-bound business observations, independent Ground Truth meta-evaluation and confirmed badcase drafts preserve their distinct evidence boundaries.
- Diagnostic, experiment and governed product profiles reveal only the controls justified by their evidence level.
- Plugin, Skill and Python Adapter identities align at 0.10.1, with 34 public schemas in both packages.
Release repair
0.10.0 published to npm, but clean Linux tag/PyPI workflows exposed two release-test portability issues before any Python artifact was built. Public tags and package versions were not moved or overwritten. 0.10.1 contains the same runtime behavior with stable test-helper imports and a bounded shared-runner response budget, and supersedes 0.10.0.
Verification
The 0.10.1 archive records local automated evidence, the 0.10.0 failed-release evidence, and the coordinated 0.10.1 publication status.
Limits
Automated source verification does not establish real-provider business quality. Authenticated manual GUI acceptance and a paid/real-provider Candidate Job were not performed.
Default Host mode is unrestricted and not sandboxed. Historical results never become Promotion Gate evidence, and a Job seal is a content-integrity receipt rather than an external signature.
3 - 0.10.0 — incomplete publication
Tagged 2026-09-26 at 97a385062ba194d5496ba2d98c45a3701d08c01d.
Publication was incomplete. npm 0.10.0 published successfully, but clean Linux tag/PyPI workflows failed before any Python artifact was built. The tag and npm package remain immutable; use 0.10.1 instead.
Intended source scope
The source introduced the exact Evaluator v2 execution boundary, sealed trusted reports, repeat-aware scientific Experiments, governed Gate invariants, hardened Historical/business/meta evidence and three product profiles. Runtime behavior is carried forward by 0.10.1.
Failure evidence
The 0.10.0 archive records the successful npm workflow and the failed PyPI/tag CI runs. The failures were release-test portability and shared-runner latency-threshold issues, not a successful coordinated package release.
Limits
0.10.0 exists only on npm. It has no matching PyPI package or complete GitHub Release and must not be described as a coordinated formal release.
4 - 0.9.8 — Host path translation fix
Released 2026-09-21. Formal source tag: v0.9.8.
Shipped
- Host command translation preserves paths already resolved into the Trial host directory.
- Historical Session Observation and Candidate commands no longer receive a duplicate host-root prefix.
- A HostEnvironment integration test executes the complete SessionObservationAgent upload, digest verification and artifact write path.
- Plugin, Skill and Python Adapter identities align at 0.9.8.
Verification
The 0.9.8 archive records focused and complete automated checks. Publication and evidence status are reported separately.
Limits
The source test uses a synthetic Session Observation without a model call. A fresh Historical Job from the formal package remains required to verify the complete Adapter, Renderer and Judge path.
Default Host mode is not sandboxed. This fix does not change Evaluator criteria, scoring, Gate behavior or data redaction.
5 - 0.9.7 — Context contracts and bilingual site
Released 2026-09-20. Formal source tag: v0.9.7.
Shipped
- Candidate Context v3 is valid in Dashboard overview and Job detail; eligible Jobs can use Compare/Gate.
- Historical Context v2 is recognized explicitly by protocol, including context-only pending Jobs.
- Setup persists the complete installation identity. Settings only copies a reviewable exact update command and never executes registry packages.
- Plugin, Skill and Python Adapter identities align at 0.9.7.
- The bilingual product/documentation site covers all 19 tools, the Skill, Adapter, evaluation concepts, evidence boundaries and roadmap.
Verification
The 0.9.7 archive records automated Node/Python/package/site checks, public package identities and release assets. Publication and evidence status are reported separately.
Limits
0.9.7 did not run a real provider model, real Candidate/Historical Session data, or a paid Harbor evaluation; automated tests do not establish a business-quality baseline.
Default Host mode is not sandboxed. Same-origin is a browser CSRF defense, not caller authentication. Gate is deterministic for fixed inputs and is not deployment.
6 - 0.9.6 — Host-first execution
Released 2026-09-19. Formal source tag: v0.9.6.
Shipped
- Host is the default execution environment; Docker remains explicit opt-in.
- Candidate Context records execution environment so Host and Docker are not silently comparable.
- Plugin, Skill and Python Adapter package identities align at 0.9.6.
- The normal registry setup path remains the supported installation.
Verification
The archive records automated Node/Python/package checks and public release identities. Evidence types are kept separate from business acceptance.
Limits
0.9.6 did not run a real provider model, real Candidate/Historical Session data, or a paid Harbor evaluation; automated tests do not establish a business-quality baseline.
Default Host mode is not sandboxed. Candidate Context v3 Web Compare/Gate also has the documented 0.9.6 contract issue.
The website and GitHub Pages deployment are documentation delivery; they do not retroactively change the 0.9.6 package or evidence status.
7 - 0.10.3 — actionable project-directory recovery
Released on 2026-09-27. Formal source tag: v0.10.3.
What changed
- Directory-read denials now use the stable
HARBOR_PROJECT_ROOT_ACCESS_DENIEDcode without exposing a local path. - The Workbench explains that the failure is not a network issue, provides macOS recovery and alternative project-location steps, keeps technical details collapsed, and can copy the recovery instructions.
- Classification is limited to directory reads so ordinary
EACCESfile operations are not mislabeled. - Source-development setup explicitly includes locked dev dependencies even when the Host runs with
NODE_ENV=production. - Plugin, Skill and Python Adapter identities align at 0.10.3.
Evidence boundary
The 0.10.3 archive records targeted service/client/setup checks, the generated client bundle, source setup and matched public npm/PyPI artifacts. It does not claim complete cross-platform TCC/ACL coverage or fix desktop Host signing and permission declarations.