Current release
v7.2.0 — Security hardening batch + precision advisory
Install
Release history
v7.2.0 — Precision advisory and security hardening batch (September 7, 2026)
v7.2.0 — Precision advisory and security hardening batch (September 7, 2026)
v7.1.0 — Verification Context v1.0 Rollout (August 16, 2026)
v7.1.0 — Verification Context v1.0 Rollout (August 16, 2026)
proof_ref generation and resolution, to_verification_context() on all 13 verifiers, dedicated API endpoints, the qwed context CLI group, SDK re-exports on the Python client, and Docker-action VC outputs. Additive semver minor — no breaking wire changes.VERIFIED diagnostic without a valid attestation demotes to UNVERIFIABLE in the VC document; malformed diagnostics convert to BLOCKED instead of crashing.v7.0.0 — Full DiagnosticResult Engine Conformance (August 8, 2026)
v7.0.0 — Full DiagnosticResult Engine Conformance (August 8, 2026)
DiagnosticResult complete (META #216). SchemaVerifier, SQLVerifier, CodeVerifier and SecureCodeExecutor, and StatsVerifier — plus fact/image batch verification — now return the unified DiagnosticResult contract. Truth and admission are separated: proven-unsafe code and proven-malicious SQL are VERIFIED (the proof succeeded) with an explicit admission: BLOCKED, and successful stats execution is UNVERIFIABLE because execution is not verification. SDK 6.0.0 → 7.0.0 across Python, TypeScript, and Rust.Full Release Notes → · GitHub Release ↗v6.0.0 — Trust Boundary Completion (August 2, 2026)
v6.0.0 — Trust Boundary Completion (August 2, 2026)
/verify/* endpoints return unified DiagnosticResult. Control plane requires and verifies attestation at the admission boundary before admitting VERIFIED. VERIFIED is a protocol guarantee backed by deterministic proof_ref — heuristic and advisory analysis now reports UNVERIFIABLE with structured advisory_checks. Covers consensus, batch math, control-plane attestation, and agent state. SDK 5.3.0 → 6.0.0 across Python, TypeScript, Rust, Docker, and Kubernetes.Full Release Notes → · GitHub Release ↗v5.2.0 — Structured Verification Diagnostics (June 19, 2026)
v5.2.0 — Structured Verification Diagnostics (June 19, 2026)
DiagnosticResult model with agent_message (agent-safe), developer_fields (structured evidence), and proof_ref (sha256 proof hash — the authority bit). Tri-state status only (VERIFIED / UNVERIFIABLE / BLOCKED). Frozen dataclasses prevent post-construction bypass. Advisory checks structurally separated from verdicts. Migration helper for legacy engine dicts. 83 tests. Additive — no breaking changes.Full Release Notes → · GitHub Release ↗v5.1.2 — SymPy Expression Injection Fix (June 14, 2026)
v5.1.2 — SymPy Expression Injection Fix (June 14, 2026)
parse_expr(). Added safe_parse_expr() wrapper with denylist, stripped __builtins__, allow-listed math namespace. Cache Redis fail-closed. CodSpeed benchmarks.Full Release Notes → · GitHub Release ↗v5.1.1 — Trust Boundary Hardening (May 22, 2026)
v5.1.1 — Trust Boundary Hardening (May 22, 2026)
AttestationStatus enum and is_issued contract. Audit chain isolated per-org with BEGIN IMMEDIATE transactions. Reasoning proof prerequisites enforced. Symbolic/batch verifiers return BLOCKED on missing proof. Unknown agent actions denied. additionalProperties: false strictly enforced. SDK 5.1.1 across Python, TypeScript, Rust.Full Release Notes → · GitHub Release ↗v5.1.0 — Agent State Governance and Fail-Closed Hardening (April 19, 2026)
v5.1.0 — Agent State Governance and Fail-Closed Hardening (April 19, 2026)
CodeExecutor hard-blocked · Default-deny for unknown tools · Bounded math tolerance · verify_logic_rule / verify_identity fail-closed · Ambiguous math expressions blocked · Schema uniqueItems fail-closed · SDK 5.1.0 across Python, TypeScript, Go.Full Release Notes → · GitHub Release ↗v5.0.0 — Enforcement Boundary Hardening (April 4, 2026)
v5.0.0 — Enforcement Boundary Hardening (April 4, 2026)
INCONCLUSIVE status for LLM-translated math · trust_boundary metadata in responses · Mandatory ActionContext for agents · Replay/loop detection · Redis fail-closed rate limiting · Docker required for stats/consensus · security_checks field removed · Admin-only /metrics · SDK 5.0.0 across Python, TypeScript, Go.Full Release Notes → · GitHub Release ↗v4.0.1 — Sentinel Guard Sync (March 23, 2026)
v4.0.1 — Sentinel Guard Sync (March 23, 2026)
POST /verify/process endpoint · Agent security checks (exfiltration, mcp_poison) · Security fixes (info disclosure, symbolic precision) · @qwed-ai/sdk@4.0.1.Full Release Notes → · GitHub Release ↗v4.0.0 — Sentinel Edition (March 12, 2026)
v4.0.0 — Sentinel Edition (March 12, 2026)
v3.0.1 — Ironclad Update (February 4, 2026)
v3.0.1 — Ironclad Update (February 4, 2026)
v2.4.1 — The Reasoning Engine (January 20, 2026)
v2.4.1 — The Reasoning Engine (January 20, 2026)