The house · Release notes
Release notes
What changed, when, and which tools it touched. The server answering https://shpbl.com/mcp right now reports 1.47.1 — ask subscription_status and it will tell you itself.
1.47.1
9 September 2026
Compiling is not building
- A real harvest exposed the worst kind of pass: a capability reported green while the file behind it was a skeleton of the thing that had been approved — the right shape, the right types, and a test that asserted nothing about the promised behaviour. Every mechanical check passed, which is exactly why mechanical checks are no longer enough on their own.
- Each approved capability now carries a contract written before any code exists: what it must do, the states it must honour, the host behaviour it leans on, the parents it reuses and the seams it declares. A green result needs every promised claim covered by a test derived from that contract, a declared reuse with its obligations, resolved provenance, and a review that measures the implementation against the claim rather than the signature.
- Part-built is now something a run can say honestly. A capability that implements part of its contract is reported partial and has to name what it left uncovered; nothing downstream may quietly round it up, and the sealed-bundle gate enforces the same rule and flags a result state it does not recognise instead of skipping it.
- Harvesting nominates with ambition — a quality floor, a novelty threshold, duplicate screening and up to 200 ranked, named and explained proposals — and writes no implementation at all until a person approves one by name. The same depth rules apply to every repository; no repository is a special case.
- New sealed editions: The Complete Master Library v1.7.6 for buyers, and the master copy at v1.7.10. Auditing the archives themselves — not the source that made them — turned up two packaging faults, both fixed in these cuts: the buyer archive's own seal file never reached its ZIP, so the verifier it ships crashed instead of verifying, and the printed guide restated a superseded server version and buyer edition. Hashes are published at /root-of-trust.
1.46.2
8 September 2026
A self-check that invokes nothing is prose, not evidence
- An adversarial round found the gate between reading a repository and creating anything refusing on every input — including the path that is supposed to stop and ask you. It was confusing a repository it could not read with a file it had proved absent. It now prints the whole decision checkpoint first, still asks for your decision, and any refusal names the check that failed and how to satisfy it.
- A seventh axis, Function, is exercised on every self-check: a fixed build fixture is put through the real gate and the answer has to be the right shape — no decision returns the checkpoint, a person's approval returns a verdict, a machine-shaped approver is refused. Registered and priced is no longer mistaken for working.
- Capability classification now reads what a body actually does. One that writes to state it closed over is recorded as seamed, never as pure, and the grant asks you to assert a recorded sequence for those stages instead of the same output for the same input.
- The engineered catalogue class table sums to the published 1,117 rows, and the retired discovery pool tells one story everywhere: kept for continuity of the record, read by no tool, counted nowhere.
- New sealed editions: The Complete Master Library v1.7.3 for buyers, and the master copy at v1.7.7, both carrying the reprinted guide. Hashes are published at /root-of-trust.
1.44.0
8 September 2026
Harvesting means composing, and `harvest_repo` now does it
- `harvest_repo` is the shortcut into the harvest lane. Point it at a repository whose licence permits the reuse and it reads what that repository already does, fuses those measured affordances with the runnable capability library, and names ranked proposals in plain language, with a file and a line behind every claim. You no longer walk the full twelve steps — including a repair you may not want or be able to land — to reach a composition.
- It never writes to the target repository: no branch, no commit, no pull request, no repair. Nothing is built until a person approves proposals one at a time and states what the upstream licence permits; an undeclared licence is treated as unknown, never as a yes, and an agent, model, policy or default is refused as the approver.
- Approved proposals come back as seed modules for your own `.shpbl/` library. The previous whole-tree ledger walk is unchanged and still available with `mode: "walk"`, estimates included.
- Sealed editions at the time: The Complete Master Library v1.7.2 for buyers, and the master copy at v1.7.6, both carrying the rebuilt guide, the new harvest lane document and the same offline fusion tool. Hashes are published at /root-of-trust.
- The typed client accepts the new arguments, and the HTTP API, MCP and offline archives describe the same lane in the same words.
1.41.1
7 September 2026
Four doors named everywhere, and a blog that does not cry wolf
- The typed TypeScript client is now part of how the site describes itself rather than a page you had to find: `@shpbl/sdk` is named on the home page, the team-pipeline diagram, agent access, the case studies and the HTTP API page, all pointing at the same seventeen tools, the same key and the same meter.
- Every outbound link to the CMPSBL storefront is gone from the site, and the client's dead source-repository link is retired — the published package on npm and the licence text are the citations now. Licensing pages, checksums and the products themselves are unchanged.
- The Drift Log's house rules were brought in line with the rest of the wording: model-independence is described as owned code that is computed rather than generated, `deterministic` is reserved for posts genuinely about determinism, `intelligence` is retired as a product word, and the fourth door is on the blog's list of places a post may send a reader.
- A throttled writing window no longer looks like a broken generator: when every model tier is rate-limited or out of credit the blog tick falls silent and the next beat retries, instead of recording a run error and answering 500 to its scheduler.
1.41.0
7 September 2026
Honest counts, honest coverage, and plainer failures
- Credentials never come back out. A subscription key or repository token carried into a call, and any credential a run finds inside a host repository, is withheld from every served result, refusal message, ledger and sealed page — the finding is still reported, only the value is withheld. The Complete Master Library v1.7.1 carries the same rule as `KEY-FENCE.md`.
- `library_index` gained a `pools` section: the canonical reconciliation of every total this server quotes — the engineered catalog as published and as searchable, the discovery vault candidates, and the runnable capability units — with the rule that the pools are distinct populations and are never added together. `selfcheck_mcp` points at it rather than explaining itself in passing.
- `evaluate_repo` now states its coverage ceiling in the report: how many eligible code files the call actually read, that a single evaluation is bounded by design, and that full coverage comes from `harvest_repo`. It also separates the licence question (may this code take part in a separate artifact) from key entitlement (which catalog rows you may read), and names the credential the tree was read with.
- GitHub failures on `pin_source` read as plain remedies instead of status codes: a repository with no commits yet says so, a legally withheld repository says so, and no upstream response body is ever relayed.
- `run_gauntlet` remembers the settings a run started with — character budget, voice and checkpoint interval now ride the signed fold token — so a walk is not silently re-planned into default batches at step 2.
- Capability affordance detection rejects import-only evidence, standard-library plumbing and generated UI files, and reports confidence; a capability that reads none of the host's data is no longer presented as a host-fused lead.
- The voice boundary is printed before the tone rules on every run card, and `none` is now an explicit voice: bare wording, no openers, no asides, which is what an automated reviewer wants.
- The offline gate wording no longer implies the offline check has the hosted run's evidence: the rules are identical, but only a connected run can confirm cited files against the real repository tree.
1.40.0
6 September 2026
Interactive checkpoints, offline completion, and caller-owned retention
- A run now stops in an explicit AWAITING_YOU state whenever the operator must choose: personality at 0A, proposal decisions at 9A, authority at 9B, and final placement at 12A. Silence is never approval and a default is used only after the person explicitly chooses it.
- Step 9 records an independent APPROVED, DECLINED, or DEFERRED/NEEDS_EXPLANATION decision for every proposal. Approved proposals may proceed even when others are declined; build approval remains separate from integration approval.
- Offline editions can finish at PACKAGED_FOR_REVIEW without a network connection, subscription, hosted tool, or repository write. Hosted runs and offline delivery now have distinct completion rules.
- Customer harvests remain in that customer's own .shpbl library. SHPBL's own internal intake is segregated from customer editions and never turns customer work into public corpus material.
- Current companion editions: SHPBL-RUN-CONTRACT/1.1.0, Complete Master Library v1.7.1, and Evaluation Master Library v3.4.0. The live API and MCP expose 17 tools.
1.39.0
5 September 2026
Human approval reads as a conversation, not a failure
- Six bounded personality imprints make operator-facing guidance warmer while facts, gates, evidence, licensing, and authority remain unchanged.
- Partial proposal approval is a successful outcome: the run builds approved components, records declined or deferred ones, and continues without treating the whole nomination set as failed.
- Provider-shaped model attribution is rejected while legitimate human and organization names remain valid.
1.38.0
4 September 2026
Purpose-led runs and per-proposal authority
- SHPBL-RUN-CONTRACT/1.1.0 places purpose first for aim and interpretation without allowing it to override evidence, licensing, provenance, authority, or completion gates.
- Nominations are ranked, clearly named, and explained for the specific repository. There is no fixed maximum; unusually large sets require a rationale and the person sets the workload boundary.
- BUILD-APPROVAL.json records a separate decision for every proposal, and delegated human approval must be explicit, scoped, recorded, and non-default.
1.35.8
1 September 2026
Every published surface reads one version, and the last licensing dust is swept
- The version a caller sees is now the version that is running. The root-of-trust file and both machine-readable guides (llms.txt, llms-full.txt) had drifted behind the runtime; they now read the same number as the server, and a test fails the build if any of them drift again.
- The write guard is case-blind: a protected path is refused whether it is written .env or .ENV.
- Crown jewel descriptions no longer ship a retired licence header or a raw ASCII banner. 28 source bodies were rewritten to carry the perpetual licence reference instead of the retired AGPL notice, with the original hash recorded in the row's origin, and all 262 descriptions now read prose pulled from a real labelled field rather than whatever happened to sit at byte zero.
- Catalog outlines return whole catalog figures when a filter is applied, so a filtered view can no longer be mistaken for the size of the library.
- Counts reconcile: the ten private run-engine rows are withheld from every public total, and Build Intent is normalised on the way in so a report header can never contradict the refusal it carries.
1.35.7
1 September 2026
Stress, smoke and pen tested end to end
- The whole API and MCP surface was driven under load and abuse, tool by tool, and the edge cases it coughed up were fixed rather than noted.
- Repository reads survive a flaky network: one retry, then a named refusal instead of a hang.
- A call that omits its arguments entirely is accepted for tools whose arguments are all optional, rather than rejected as malformed.
- Paging is bound to the live totals: a page past the end is refused with the real figure instead of answered with an empty list.
- Abuse control on the paid tools is stated and enforced at thirty calls a minute per key.
1.35.6
1 September 2026
Filters that filter, branches that diagnose themselves
- The pack filter works. It was being dropped between the search call and the vault read; both sides now carry it.
- A bad branch is reported as a bad branch. The repository is confirmed to exist before the tree is looked up, so user/repo#nosuchbranch no longer reads as a missing repository.
- Private run-engine identifiers can no longer surface in public search results.
- The sealed edition's row count and the live discovery count are two separate published figures, held apart by a single sealed constant, so the two can never be quietly summed.
1.35.5
1 September 2026
A discovery machine of our own, a rebuilt front page, and plain English everywhere it matters
- The discovery machine now runs here. It collides capabilities against the gaps the library actually has, screens every candidate against what we already hold so nothing duplicates, and holds the survivors for a human yes or no before anything is published. Nothing is minted on a schedule and nothing merges itself. The accepted results are readable at /discovery — The Ledger — so the invention can be watched from outside.
- FAILSAFE is wired in: every path a run can take now has a stated exit, so a broken step ends in a named refusal instead of a half-finished answer.
- The Drift Log is live at /blog — written notes on what the machine found, what was refused, and why, published as pages a search engine and a reader can both follow.
- The front page was rebuilt around one order: understand, verify, buy. What a buyer needs is above the fold — the offer, the verification strip, the live runner with the repositories already audited rendered on first paint — and the deep technical reading is folded into sections that open on request instead of shouting at everyone. Redundant sections were cut or rewritten rather than stacked.
- Site-wide plain language pass: a developer landing cold reads library instead of corpus, origin instead of provenance, foundation instead of substrate, and "a machine that collides capabilities until a chain answers the gap" instead of a primitive matrix. The precise technical vocabulary is kept where it belongs — these notes, the deeper sections of the Owner's Manual, the certificates.
- The field note signup works end to end — server-side validation, honeypot, no third-party form.
- Two security findings were closed: a public runner view that exposed a user id, and a view running with definer rights it did not need.
- The MCP page film shows its thumbnail on load — a still image until the play is asked for, so no browser is trusted to paint a poster frame.
- The whole discovery vault was re-synthesised through the logic synthesiser: all 10,405 rows now read WORKING at the byte level instead of standing as named stubs with no body, and each one records when it was re-synthesised. Vault rows stay unpromoted — discovery-engine pipelines with no catalog warranty yet — and are counted and cited apart from the 1,117 engineered components, never summed with them.
- Crown jewels are a first-class pool: 262 standalone artifacts that need no synthesiser, each graded by a certification harness — 121 certified, 88 provisional, 53 inconclusive because the harness could not exercise the input contract. Inconclusive is published as a harness limit, never as a defect claimed about the artifact.
- Substance grading, not vibes: every row is read at the byte level and graded, and library_search ranks by substance before it ranks by index score, so a hollow row can no longer outrank a working one.
- Determinism is stated precisely everywhere it appears: no model runs inside our runtime and the corpus is owned outright. Nothing in the library is model output, and the old wording that described discovery rows as machine-generated or lesser is gone.
- Metering is honest: refused calls are never charged, refusal and refund are one atomic step, and the Practitioner month covers 100,000 calls. At the ceiling the paid tools stop for the rest of the calendar month, the counter resets on the first, and the keyless free tools keep working.
- DEFENSE, ACCESS and IDENTITY are wired into every door: abuse control on the public surface, entitlement resolved in code rather than inferred, and a keyless call to a Practitioner tool refused rather than half-served.
- The self-application engines the library runs on itself now number nineteen declared with thirteen live adapters, each reported by name through selfcheck_mcp. They act on the CML, never on a caller's repository, are counted in no published total, and are never citable as prior art or harvestable.
- Fold tokens are signed and bound to the repository and the step they were issued for, so a rewritten ledger or a skipped step is refused rather than believed, and report URLs are stable enough to cite.
1.34.0
31 August 2026
The library runs the gauntlet on itself
- The self-application engines came online as substrate: rule-based repair routing, dependency planning across the release graph, portability evidence gathered from more than one runtime, and self-evolution proposals that may propose and never build.
- Every sealed edition is sealed by CHECKSUMS.sha256 and an out-of-band root hash only. Minisign and every signature-verification path were removed — one fewer thing between a buyer and the bytes they paid for.
- The offline edition clears the Build Intent gate without a key: tools/build-intent.mjs re-hashes the archive against its own checksum file, so entitlement is proved by intact bytes rather than by phoning home.
- Old run records are compacted when an edition is cut, so an archive carries the current reports instead of every report ever generated.
1.33.0
30 August 2026
One upload, one cycle, one sealed download
- The Control Room gained a single cycle: upload an edition once, read the machine's findings, approve or refuse each one inline, and download the sealed result. What used to be several rooms and several uploads is now one path.
- The agent colours became information architecture rather than decoration — harvest, evaluate, compose, library, repair and ship each carry one colour across the site, the documents and the reports.
- Free-lane copy was corrected everywhere it was stale: the free lane is a complete repository evaluation that stops at the composition boundary, and the full gauntlet is the Practitioner step. Nothing on the site claims otherwise now.
1.32.0
28 August 2026
The gate between finding something and building it
- A fourteenth tool, `build_intent`, is the chokepoint every COMPOSE, SPECIALIZE and CREATE now passes through before a line of source exists. It is free at every level: register what the harvest proposes and the server returns the mechanical verdict — the invariants, whether the proposal rests on SHPBL's licensed reusable intelligence, whether this caller may execute the foundry, and the terminal state to report.
- Authority is resolved in code, not inferred by the agent: a purchased Complete Master Library licence key or a Practitioner key. A free run still gets the whole description of what would be built and what it would be worth — it simply does not get the artifact, and the agent is told plainly not to write it anyway.
- Harvest now runs in both directions. Step 7 carries six named gates — host harvest, intersection, lineage, Build Intent, entitlement, completion — and a harvest that only inventories the target no longer counts as finished.
- Terminal states replace optimistic dispositions: BUILT-GREEN and BUILT-FAILED only where the tests actually ran, WOULD-COMPOSE / WOULD-SPECIALIZE / WOULD-CREATE where the licence gate held it at preview. SPECIALIZE now mechanically requires an executable composite ancestor, so a narrower catalog row can no longer be filed as one.
- The downloadable archives are re-cut to match: Evaluation Master Library v3.4.0 and CMPSBL Agent Kit r3.4.0 each carry two new generated documents — BUILD-INTENT.md and FOUNDRY.md — so the shipped method and the running server describe the same procedure.
- All three archives ship the canonical integration report template, its worked specimen, and a Markdown twin of that specimen, and each is validated against the report contract before it is zipped: no unfilled placeholder, no retired address, no stale version, and PROCESS.md naming all seven files a finished offline run must leave on disk.
- The archives are now cut reproducibly — the same inputs produce the same bytes — and every hash is published at /root-of-trust so a buyer can prove the download is the file we issued.
- Authorised builds follow a stated foundry contract — implementation, tests, build and typecheck, provenance — and land through `write_to_repo` with `kind: "foundry"`. Only SHPBL's own internal runs may stage an artifact toward SHPBL's global corpus; everyone else's built software is theirs, retained in their own `.shpbl/` library.
1.30.2
27 August 2026
A third transport: the same thirteen tools over plain HTTP
- The HTTP API is live at /api/public/v1. It dispatches the identical thirteen tool handlers the MCP server uses — same Zod validation, same procedure, same entitlement gate, same meter — so a build step, a script or a service can run the method with no agent in the loop.
- Three endpoints: GET /api/public/v1 for the descriptor, GET /api/public/v1/tools for the manifest, POST /api/public/v1/tools/{tool} to invoke. A Practitioner key travels as an Authorization bearer or as `key` in the body — the same key the MCP doors take.
- Every API call writes to the same register the MCP doors write to, so the register now records which door a run came through instead of assuming an agent.
- The API is a transport, not a product: no new pricing, no separate tool set, no different rules.
1.30.1
26 August 2026
Your composites stay yours — the global ledger is internal-only
- Composites governance is now stated in the tool output itself: the global composite ledger is fed exclusively by SHPBL's own internal runs. Composites a customer's own runs invent are written to that repository's private library (.shpbl/COMPOSITES.md) and are never uploaded, shared, or counted toward the global set.
- The library layout documentation names .shpbl/COMPOSITES.md as the home of private, user-invented composite designs.
- selfcheck_mcp and the site copy now describe the rule plainly, so no agent or buyer can mistake the flow.
- Companion library releases: Evaluation v3.3.3, Agent Kit r3.3.3.
1.30.0
26 August 2026
The invisible 10,404 — vault search fixed, and composites join the library
- Fixed a major bug: a column mismatch in the corpus loader made the entire 10,404-row Discovery Vault invisible to the search tools, so prior-art checks quietly ran against the 1,117-block catalog alone. A regression test now pins the parser to the vault schema.
- New third pool: the Composites Pool — 25 composed-capability designs derived from published case studies. library_search accepts scope: "composites", and prior-art matching consults the pool alongside the catalog and the vault.
- Three pools, counted separately and never summed: 1,117 engineered catalog blocks, 10,404 vault discoveries, 25 composite designs.
- Report links in shipped documents are absolute https://shpbl.com URLs, so they still read correctly from a downloaded, offline archive.
- Companion library releases: Evaluation v3.3.2, Agent Kit r3.3.2.
1.29.0
26 August 2026
A welcome, a manual, and a name that says what it does
- New free tool, welcome: on first connect the server greets the operator, lays out the menu of tools with example prompts, explains the three lanes (keep the library, borrow it for $39 a month, or try free), and points to the public User's Manual at shpbl.com/manual and support at dev@KESJr.com.
- Published the User's Manual — the public operator's guide covering every tool, the method, and the library layout — as a page, printable HTML, and PDF.
- Server identity finalised as SHPBL: Harvest Reusable Software Intelligence across the manifest, registry listing, and tool surface.
1.28.1
26 August 2026
Checkpoint pacing you can set, and an honest cheap pre-flight
- run_gauntlet accepts checkpoint_interval (default 3) so the operator chooses how often the run pauses for consent.
- The gauntlet's guidance now says so plainly: for a cheap survey before committing, call harvest_repo with estimate: true — no ledger, no checkpoints, a fraction of the cost.
1.28.0
26 August 2026
Procedure is law — no inference, no reordering, regular check-ins
- New conformance layer: the run rules prohibit an agent from reordering, skipping, or batching gauntlet steps on its own judgement. The procedure is executed as written or not at all.
- The gauntlet enforces sequential order through the ledger digest — a step called out of turn is refused with the correct next step named.
- Mandatory consent handshake: every three steps the run pauses, reports progress in one plain line, and waits for the operator's permission before continuing — moderate token spend, no silent marathons.
- Progress narration is single-line and essential: enough to know it is working, nothing more.
1.27.0
26 August 2026
Meta-capability engines, scanned on every gauntlet
- The ten private meta-capability engines — the run rules that govern how an audit is conducted — are now a mandated scan inside run_gauntlet, not advisory reading.
- Clarified their nature everywhere they appear: they are run-affecting engines, not harvestable library rows, and they never enter the catalog, the vault, or any count.
1.26.0
25 August 2026
Bring Your Own Library — a run reuses what your last run found
- Tools now read the repository's own .shpbl/ findings from earlier harvests, so prior discoveries, composites, and the private ledger inform the next run instead of starting cold.
- Extraction hardened: docstring noise excluded, and a paging race that could drop files under load is fixed.
- Platform detection and relevance gating keep platform-specific capabilities from being proposed for repositories they cannot serve.
1.22.0
25 August 2026
The live Discovery Vault joins the server
- Prior-art matching and library_search now draw on the live Discovery Vault — 10,404 candidate discoveries with semantic clustering — alongside the engineered catalog.
- Vault rows and catalog rows are counted, cited, and displayed separately, always: candidates are not engineered blocks and are never summed into the catalog total.
1.21.0
25 August 2026
Aligned to the current sealed edition, with hands-off file protection
- Verified the full MCP pipeline against the current sealed edition download: component count confirmed at 1,117 engineered artifacts across every surface.
- New hands-off rules: environment files, lockfiles, credentials, and other sensitive paths are excluded from everything the server reads or writes, by deny-list, not by judgement.
1.20.0
25 August 2026
Three lanes, no contribution loop
- The pricing model is now three lanes, stated the same way everywhere: Keep — the Complete Master Library at $499, shipped to your door; Borrow — practitioner access at $39 a month; Try — a free ephemeral evaluation.
- Removed the contribution loop: runs are private by design and a customer's harvests are never solicited, uploaded, or merged into the global library. Demand-pull only — nothing mints artifacts on the server.
1.18.0
25 August 2026
One shape — every run returns a report and what it found
- Every tool now returns the same shape of result: the report and the capabilities found, in a unified four-section payload, with depth set by the caller's tier.
- Fixed quality and paging issues that added noise to large outputs.
1.17.0
25 August 2026
We pointed the server at itself — and shipped what it found
- New free tool, selfcheck_mcp: the server audited against its own six verification axes, live, with one pass / fail / unavailable line per check — tool surface against the priced tier table, version agreement, subscription register, catalog, discovery vault, repository write authority, billing. An unavailable check is never reported as a pass.
- Authority, fixed: a repository connection now records GitHub's own repository_selection field. An installation with an empty repository list used to be read as "all repositories", which made a failed sync indistinguishable from an account-wide grant — two opposite answers, one of which hands out write access.
- The gate now resolves exactly one acting identity, in a stated order: the key passed on the call, then the key in the request header, then the key your signed-in account is bound to. Previously the database picked, so a caller holding two keys could be gated either way on different calls, and the throttle could brake one key while the meter charged another.
- A subscriber who passes their key as a tool argument to list_repos is now paced on their own budget instead of the shared anonymous one.
- The read-credential resolver returns the credential it reports. It used to say "server" and hand back nothing, so a configured token went unused.
- The gauntlet's closing step refuses without a ledger instead of re-running the opening comparison under a closing label.
- Subscription renewal dates are read from both places Stripe now publishes them, so a renewal date is never silently null.
- Key generation is rejection-sampled: every character in a new key is now equally likely.
- Environment files are out of the tree, with a documented .env.example in their place.
- New guards in the test suite pin the two authority rules that were previously only comments: bearer trust stays confined to the sign-in door, and write authority widens only on an explicit grant.
1.16.0
25 August 2026
Nothing charged for a refused call, and both doors documented honestly
- An internal-only tool called with a Practitioner key is now refused before the meter runs, so a refused call never spends an allowance — exactly as subscription_status has always promised.
- Each key is metered against its own monthly ceiling instead of the highest one on sale, and a quota message now names the real number.
- The keyless tools that reach GitHub — evaluate_repo and list_repos — are paced too, which protects the shared survey budget every subscriber depends on.
- When the component ledger cannot be reached, a run says so instead of reporting "no prior art in the library".
- list_repos no longer calls a repository writable when the installation did not grant it.
- Fixed a gauntlet instruction that named a tool which does not exist, and an invalid branch name from an unusual run id.
- The README, server.json, and the distribution roadmap now describe the sign-in door and the key-only door as they actually are.
1.15.0
24 August 2026
Ledger integrity, one owner per name, published server manifest
- Published server.json so MCP clients and the official registry can read the server's identity, endpoint, and transport without a human in the loop.
- Every writing tool now declares its behaviour explicitly (read-only, destructive, open-world), which is what directory review reads.
- The run budget is enforced before any model call, so a spent budget refuses the run instead of overspending it.
- Removed duplicate definitions of the component classes and the verification axes: one owner per name across the codebase.
- Fixed a file-risk pattern that mis-flagged token-handling modules.
- Added privacy, terms, and these release notes as first-class pages.
1.14.0
21 August 2026
Twelve tools, and a name search engines can read
- Folded twenty-two tools into twelve, each titled and annotated: library_index, library_document, and library_search replace eleven reference tools.
- Renamed the product to SHPBL: Harvest Reusable Software Intelligence everywhere.
- repo_access folded into list_repos, so repository discovery is one call.
1.13.0
18 August 2026
Ranked search, a free protocol tool, and brief mode
- Multi-term ranked search with fallbacks, so a near-miss query still returns the right document.
- method_protocol is free: an agent can read the whole method before it spends a call.
- brief: true on the heavy tools, to spend a fraction of the context for the same decision.
1.12.0
15 August 2026
run_gauntlet — the whole method in one call
- One conductor tool sequences evaluation, harvest, library comparison, and the repair order.
- Current sealed edition baseline: the retired Ascension layers are gone from every total.
1.11.0
12 August 2026
Prior art, citations, and submitted capabilities
- A harvest is matched against the library and cites what it matched, so a finding can be traced.
- submit_capability sends a harvested capability for human curation.
Connect the server from agent access. The terms and privacy statement govern its use.