Skip to content

Changelog

This is the running record of what changed in each TOVIO release. It follows the Keep a Changelog conventions, and the version numbers follow Semantic Versioning.

Pre-release

TOVIO is in active, pre-1.0 development. Phases 0-4 are implementation-complete under their documented supported profiles, including cryptographic permissions, the agent control plane, and the Forge. Phase 5 productization, external publication, hosted/enterprise evidence, and independent review remain open; see the roadmap. The tree is versioned 0.1.0 (pre-alpha, as tovio --version reports), but no public release has been accepted, tagged, or published, and no download artifacts exist yet.

How to read this changelog

Each release groups its changes under standard headings, so you can scan for what affects you:

  • Added --- new features.
  • Changed --- changes to existing behavior that aren't breaking.
  • Deprecated --- features still present but on the way out.
  • Removed --- features taken out.
  • Fixed --- bug fixes.
  • Security --- anything touching the crypto, permission, or audit surface.
  • Breaking changes --- called out explicitly, with the version deprecated and the date the backward-compatibility window closes (see versioning).

Breaking changes are never silent

A breaking change to a Stable format, wire, or token contract always appears here under its own Breaking changes heading --- with the migration path and the deprecation window. TOVIO commits to a one-major-version backward window (N−1). The policy is on the versioning page.

Format & contract versions

Each release pins the version of the four foundational contracts, so an integrator can tell at a glance whether anything they build against moved. Nine further surfaces --- the conformance corpus, the CLI surface, Forge routes, the N-API ABI, the plugin contract, cryptographic domain separation, request proof, Forge operational records, and audit records --- are versioned too, and are registered in the repository's compatibility contract. (See versioning for what these surfaces are.)

Contract Version Specification status
Storage format 1 Review
Wire protocol v1.0 (frozen 2026-07-08) Stable
Capability tokens tovio-capability-v1 Review
MCP / agent API tovio-mcp-v1.3 Review

Unreleased

Work in progress toward the next release. Phase deliverables land here before they're tagged --- track the bigger picture on the roadmap.

Added

  • Public feedback portal for early evaluators, reached from https://tovio.dev/feedback; see feedback, roadmap and updates (ADR-0342).
  • Product releases as Forge records: an immutable tag plus notes and downloadable assets, with tovio release create | list | show | edit | publish | delete and tovio release asset ... (ADR-0350, REQ-REL-001..015).
  • A native issue tracker on the Forge, alongside proposals (ADR-0351).
  • Opportunistic auto-sync, on by default: a successful history-advancing command pulls, folds the lane's upstream in only when conflict-free, and pushes only with consent; --no-sync, TOVIO_NO_SYNC, or sync.auto = off opt out, and tovio sync --watch keeps an idle repository current (ADR-0279).
  • A first-party local desktop app, tovio-desktop, over the working copy; its full CLI-parity migration is in progress (ADR-0291, ADR-0292).

Release template

When a version ships, its section is added at the top using this shape:

## [X.Y.Z] — YYYY-MM-DD

### Breaking changes
- <what broke> — deprecates <prev version>; N−1 window closes <date>. Migration: <documented migration path>.

### Added
- <new feature> (REQ-AREA-NNN)

### Changed
- <changed behavior>

### Deprecated
- <feature on the way out, with its removal target>

### Removed
- <feature removed>

### Fixed
- <bug fix> (TVO-AREA-NNN)

### Security
- <crypto / permission / audit change>

Every entry that touches normative behavior references the relevant REQ-* ID, TVO-* error code, or ADR --- the same traceability the project uses in commits and pull requests (see contributing).

This page is the system of record for release notes: the product updates published through the feedback portal republish entries from here after they land, and never contain anything this page does not.


When an accepted release exists, its attested manifest will be the sole source for CLI, Forge, and npm download metadata. Until that gate passes, no public artifact links appear here. The release policy is described on the versioning page.

Last reviewed September 9, 2026

Suggest an improvement to this page Not for security reports — see disclosure