Skip to content

Releases: GottZ/ctx

ctx v4.17.2

Choose a tag to compare

@github-actions github-actions released this 19 Jul 23:45
v4.17.2
30dce74

v4.17.2 — Produktions-Fix: Worker-Deprioritisierung prozessweit (per-Thread-Falle)

Patch-Release. Der v4.17.1-Nightly-/CI-Rot der E-B-Priority-Probe war
kein Flake, sondern korrekter Detect eines Produktions-Bugs:
setpriority(2)/ioprio_set(2) mit who=0 sind unter NPTL per-Thread —
der Overview-Rebuild-Worker renicte einen zufälligen Runtime-Thread
statt des Prozesses. Fix: /proc/self/task-Walk über alle TIDs
(fix(ctxd) Commit, Details dort). Test-Diagnostik gehärtet.

Installation

With Go:

go install github.com/GottZ/ctx/cmd/ctx@v4.17.2

Binary download:
Download the binary for your platform, make it executable, move to PATH:

chmod +x ctx-*
sudo mv ctx-* /usr/local/bin/ctx

ctx v4.17.1

Choose a tag to compare

@github-actions github-actions released this 19 Jul 23:33
v4.17.1
a5b3bce

v4.17.1 — Nebenbefund-Patch: Nightly-Flake-Fix + Dependency-Graph-Reparse

Patch-Release nach Versionsformel (User-Direktive: Nebenbefund-Changes
als Patch). Zwei Commits auf v4.17.0:

  • test(ctxd) db40543: Priority-Probe entflaked (Deadline-Budget aus
    t.Deadline statt flacher 5s, Kind-Exit-Erkennung mit eigener
    Fehlermeldung). Probe bleibt hart — kein Skip, kein Assert-Verlust.
  • chore(deps) a5b3bce: go.mod-Touch als Reparse-Anker für GitHubs
    eingefrorenen Dependency-Graph (13 stale x/crypto-Alerts, Graph
    stand auf Vor-v4.13.0; go.mod trägt 0.54.0 seit 11.07.).

Kein Code-Diff im Produktionspfad, keine Migration — Binary
funktional identisch zu v4.17.0.

Installation

With Go:

go install github.com/GottZ/ctx/cmd/ctx@v4.17.1

Binary download:
Download the binary for your platform, make it executable, move to PATH:

chmod +x ctx-*
sudo mv ctx-* /usr/local/bin/ctx

ctx v4.17.0

Choose a tag to compare

@github-actions github-actions released this 19 Jul 23:14
v4.17.0
077cd50

v4.17.0 — checkpoint-Evidence-Typ: Guard-feste ID-Referenzketten (M107)

Minor-Release nach Versionsformel (Push = Release-Schnitt, User-Direktive
2026-07-20). Ein feat-Commit (077cd50): builtin-Block-Typ checkpoint —
Compaction-Checkpoint-Manifeste und Transcript-Parts verlassen alle
autonomen Pipelines (retrieval=excluded, Guard beidseitig raus,
dream/digest/overview aus), Classify über Titel-Präfix. M107 repariert
den Bestand: 125 retyped, 64 guard-archivierte Evidence-Rows entarchiviert
— Dangling-Manifest-Vorfall 2026-07-20 strukturell geschlossen. Fixt
zugleich die Rerank-Slot-Überläufe (exceed_context_size_error) durch
hex-dichte Checkpoint-Präfixe in Kandidaten-Sets.

Gates: go test -short 32 Pakete, Integration blocktype/store/guard,
golangci-lint, M107-Dry-Run + Live-Verifikation nach Deploy
(Ketten-Sweep 0 hängend, Query-Probe 0 Checkpoint-Quellen).

Installation

With Go:

go install github.com/GottZ/ctx/cmd/ctx@v4.17.0

Binary download:
Download the binary for your platform, make it executable, move to PATH:

chmod +x ctx-*
sudo mv ctx-* /usr/local/bin/ctx

ctx v4.16.0

Choose a tag to compare

@github-actions github-actions released this 14 Jul 21:31
v4.16.0
a61c053

v4.16.0 — Buchfuehrungs-Release: Plan-Korpus-Pointer graph-structural-Abschluss

Minor-Release nach Versionsformel (Push = Release-Schnitt, User-Direktive).
Chore-only: .project-Pointer auf das v4.15.0-Release-Log (Gate-Logs,
LOOP.md-Abschluss-Chronik). Kein Code-Diff, keine Migration —
Binary bleibt byte-identisch zu v4.14.0/v4.15.0 (13246096da7b).

Installation

With Go:

go install github.com/GottZ/ctx/cmd/ctx@v4.16.0

Binary download:
Download the binary for your platform, make it executable, move to PATH:

chmod +x ctx-*
sudo mv ctx-* /usr/local/bin/ctx

ctx v4.15.0

Choose a tag to compare

@github-actions github-actions released this 14 Jul 20:42
v4.15.0
5604b74

v4.15.0 — RC-2-Test-Nachzug: GD2/GD3/GC3-Empfehlungen als belegte Tests

Minor-Release, test-only (4 Wellen nach plan-graph-structural-Abschluss,
User-Direktive: reversible Tests zur Qualitaetssteigerung).

  • GD2: Integrationstest sichtet die Structural-Sektion im wire-gebundenen
    Tagesbericht-Prompt (chatJSON-Seam, Fenster-/Scope-Leak-Arme im
    Exakt-Match); Review-Haertung auf non-default-Home-Scope gegen
    Hardcode-Blindheit.
  • GD3-F3: inaktiver Scope skippt trotz fremder dream_links (E14 erstmals
    integrationsbelegt, Gegenlauf als Fixture-Selbstvalidierung).
  • GC3: data-theme-Assert vor jedem axe-Scan der Focus-Stage-Matrix
    (Bestandsmuster aus dem Contract-Runner nachgezogen).

Jede Welle mit dokumentierter Rot-Probe; adversariale Review-Linse
FREIGABE. Gates: dream-Integrationssuite gruen, e2e 336/336 (4 Last-
Flakes isoliert gruen nachbelegt), test.sh 25/25, eval ohne Regression.
Kein Produktions-Code-Diff, keine Migration.

Installation

With Go:

go install github.com/GottZ/ctx/cmd/ctx@v4.15.0

Binary download:
Download the binary for your platform, make it executable, move to PATH:

chmod +x ctx-*
sudo mv ctx-* /usr/local/bin/ctx

ctx v4.14.0

Choose a tag to compare

@github-actions github-actions released this 14 Jul 19:47
v4.14.0
779db87

v4.14.0 — Graph-Erweiterung: structural links sichtbar (Ego-Graph, FE, Statistik)

Minor-Release, 21 Wellen + Skalen-Bench (plan-graph-structural-2026-07-14).

Der User-Fix: Tagesberichte und forge-sync-Issues erscheinen im Ego-Graph
verbunden — das Traversal folgt beiden Datenklassen pro Hop (fairer
Reissverschluss ueber das geteilte Node-Budget), structural-Fakten kommen
als eigene Wire-Arrays (structural_edges + delivered Legenden) und rendern
default-sichtbar als gebogene Teal-Pfeile (@sigma/edge-curve, MIT).

Server: M104 Traversal-Indizes (idx_struct_links_rev faellt) · M105
Kollisions-Preflight · M106 Statistik-/Prune-Indizes · Q1s/Q2s/4-Leg-Q3
mit Visibility-Triple je Leg (Leak-Gates rot-bewiesen, Counting-Channel-
Proben) · link_class = EIN vereinigter Kanal ueber beide Vokabulare ·
Tagesbericht-Statistik structural (scope-gefiltert) · dream-Statistik
scope-lokal (E14, dokumentiert breaking: Report-Zahlen + Skip-Gate) ·
K8-Scope-Move-Link-Sweep. StructuralNeighbors entfernt.

Frontend: MultiDirectedGraph + keyed Merges · Blocklist-Filter (Unbekanntes
nie versteckt) · Legende im Fieldset (token-gebundene Swatches, sr-only-
Semantik, neue Focus-Stage-axe-Matrix 2x2) · Fenster-Referenzliste mit
graphRev-Invalidierung · e2e-Fixture-Sync (336/336).

Bench @1m+10^5 structural: Zipper-p95 439.72ms < 500ms-Bar (= dream-only-
Niveau), Klassen-Filter-Skip 9.6ms, visible-poor 308ms — keine
Ausweichroute gezogen (REPORT-w5g2-structural.md).

Verifiziert: go -short 37 Pakete, vitest 821/821, Playwright-e2e 336/336,
golangci-lint 0, Integrationssuiten (Isolation + RegistryGolden) gruen.
Migrationen 104-106 laufen beim Boot (reine Indizes + Preflight, kein
Backfill).

Installation

With Go:

go install github.com/GottZ/ctx/cmd/ctx@v4.14.0

Binary download:
Download the binary for your platform, make it executable, move to PATH:

chmod +x ctx-*
sudo mv ctx-* /usr/local/bin/ctx

ctx v4.13.0

Choose a tag to compare

@github-actions github-actions released this 11 Jul 10:36
v4.13.0
cf1d6b5

v4.13.0 — Dependency-Full-Sweep (Go + Frontend)

Minor-Release: alle Dependencies auf aktuellen Stand, Audits clean.

Go: chi 5.3.1, pgx 5.10.0, MCP go-sdk 1.6.1, pgvector-go 0.4.0,
testcontainers 0.43.0, x/crypto 0.54.0, x/sys 0.47.0 (schließt
GO-2026-5024) u. a. — govulncheck 0 Findings.

Frontend: vite 8.1.4, vitest 4.1.10, svelte 5.56.4, svelte-check 4.7.2,
@types/node 26, sv-router 0.18.0. TypeScript bleibt 6.0.3 (TS 7 = tsgo
bricht svelte-check 4.7.2). Overrides gegen transitive Advisories:
undici 7.28.0 (7 GHSA via jsdom), uuid 11.1.1 + tmp 0.2.7 (via
@lhci/cli) — bun audit 0 Findings.

Verifiziert: go test 32/32, golangci-lint 0, vitest 797/797,
Playwright-e2e 321/321, LHCI-Assertions grün, docker build grün.
Keine Migration, DB unberührt. Dazu: docs(ops) Embedding-Backend-
Tuning (7be5c63).

Installation

With Go:

go install github.com/GottZ/ctx/cmd/ctx@v4.13.0

Binary download:
Download the binary for your platform, make it executable, move to PATH:

chmod +x ctx-*
sudo mv ctx-* /usr/local/bin/ctx

ctx v4.12.2

Choose a tag to compare

@github-actions github-actions released this 10 Jul 06:32
v4.12.2
b83ae69

v4.12.2 — dompurify 3.4.10 → 3.4.11 (GHSA-cmwh-pvxp-8882)

Patch-Release: schließt den offenen Dependabot-Alert. Die Lücke
(ALLOWED_ATTR-Pollution über setConfig() unter Umgehung des
3.4.7-Clone-Guards) ist im ctx-Frontend strukturell nicht auslösbar —
kein setConfig()-Aufruf, und der einzige DOMPurify-Consumer
(lib/markdown) registriert nur einen afterSanitizeAttributes-Hook, der
Hardening-Attribute setzt und die Attribut-Allowlist nicht mutiert.

Reiner Patch-Bump, kein Laufzeit-Verhalten geändert. svelte-check
0 Fehler, vitest 797/797, bun install --frozen-lockfile grün.

Co-Authored-By: Claude Opus 4.8 noreply@anthropic.com

Installation

With Go:

go install github.com/GottZ/ctx/cmd/ctx@v4.12.2

Binary download:
Download the binary for your platform, make it executable, move to PATH:

chmod +x ctx-*
sudo mv ctx-* /usr/local/bin/ctx

ctx v4.12.1

Choose a tag to compare

@github-actions github-actions released this 10 Jul 01:06
v4.12.1
e08d9c0

v4.12.1 — CI-Fix: e2e-Fixtures Cookie-Session + gosec-Begründungen

Quickfix auf v4.12.0: der Web-Job hing (tote sessionStorage-Fixtures
nach dem R4-SPA-Umbau) und der Lint-Job schlug mit CI-only gosec-Regeln
fehl (G124 config-abgeleitetes Secure-Flag, G710 allowlist-gebundene
Redirects). Kein Laufzeit-Verhalten geändert — Test-Infrastruktur +
nosec-Begründungen. e2e 421/421 im pinned Container.

Co-Authored-By: Claude Fable 5 noreply@anthropic.com

Installation

With Go:

go install github.com/GottZ/ctx/cmd/ctx@v4.12.1

Binary download:
Download the binary for your platform, make it executable, move to PATH:

chmod +x ctx-*
sudo mv ctx-* /usr/local/bin/ctx

ctx v4.12.0

Choose a tag to compare

@github-actions github-actions released this 10 Jul 00:24
v4.12.0
22e053d

ctx v4.12.0 — OAuth-Stack komplett: Principal-Identität, OAuth-2.1-Server, externes Login, Web-Sessions

25 Wellen des OAuth-Gold-Plans (plan-oauth-2026-07-09), Migrationen 094–102:

Fundament (01): Principal-Entität mit Green-Field-Backfill (1 Key = 1
Principal), ctx_auth + ctx_auth_by_id als die EINE Scope-Materialisierung
(Key-/Tenant-/Principal-Gates fusioniert), additive Audit-FKs, atomar
principal-mintende Key-Pfade.

OAuth-2.1-Server (02/03): persistenter Code-Store (code_hash, atomarer
Take), Advisory-Kern-Fix GHSA-p3jf-x27v-4jg6 (client_id mandatory +
redirect-Allowlist + Code-Client-Bindung), opake ctxt_/ctxr_-Tokens mit
resolveCredential als EINEM Gate-Ort, Refresh-Rotation mit Reuse-Detection
(Replay → Familien-Revoke ohne Wire-Oracle, 90d-Cap), PKCE-S256-Pflicht,
RFC-8707-resource/-Audience-Check, RFC-8414/9728-Discovery, per-Client-
redirect-Allowlist exklusiv + confidential-Secret constant-time, RFC-7591-
DCR mit Guardrails (Modus-Flag fail-closed off, Cap + per-IP-Limiter).

Externes Login (04): Provider-Allowlist (INV-C, Secrets sealbox-versiegelt),
OIDC-Lib + GitHub-Härtetest, DB-gestützte Single-Use-States (Doppel-UUID),
Flow-Handler mit Mix-up-Defense und ssrfguard-Dialer.

Web-Sessions (05): context_web_sessions-Overlay über dem EINEN Token-Store
(E2: Login-Token ist zugleich MCP-Bearer), Cookie-Auflösung an derselben
AuthResult-Materialisierung (Header schlägt Cookie, kein Shape-Sniffing),
Login/Logout/Refresh mit CSRF-Synchronizer (Cookie-Mutationen 403 ohne
X-CSRF-Token; Header-Pfade unberührt), SPA von sessionStorage-Bearer auf
httpOnly-Cookies (Key berührt keinen Client-Storage mehr), SSO-Onboarding
admin-invite (key-loser Principal = 403, SSO ist Identität, nie
Autorisierung), Multi-Tenant-Key-Selektor mint-fresh (nie in-place).

BREAKING (Ops): /authorize verlangt jetzt client_id — Connectoren ohne
konfigurierte client_id bekommen 400. Vor dem Deploy client_id in den
Connector-Konfigurationen sicherstellen (Registrierung via ctx mcp add).

Alle Wellen negativ-geprobt (Rot-Proben dokumentiert), 13 Integrations-
Suiten + test.sh 18/18 + vitest 86/797 + golangci-lint 0 issues.
Offen: Advisory-Publish (P1, folgt mit patched_versions=4.12.0) und
/revoke (X1, bewusst zurückgestellt).

Co-Authored-By: Claude Fable 5 noreply@anthropic.com

Installation

With Go:

go install github.com/GottZ/ctx/cmd/ctx@v4.12.0

Binary download:
Download the binary for your platform, make it executable, move to PATH:

chmod +x ctx-*
sudo mv ctx-* /usr/local/bin/ctx