Documented changes
32 typed entries
Verified contributors
Credits being verified. Attribution coverage is in progress.
Attribution coverage
attribution in progress; history inventory partial.
Install
Scope
Guard v3.0.0a1 is a preview release published 2026-07-17. Upstream documents: Guard 3.0.0a1 is an opt-in prerelease cut from [`00503c9`](https://github.com/hashgraph-online/hol-guard/commit/00503c950394a3616d44cd5488344a6f6379a602). Stable installations remain on the stable channel. **9 commits • 9 merged pull requests • 1 contributor** since [Guard 2.2.0a170](https://github.com/hashgraph-online/hol-guard/releases/tag/alpha/v2.2.0a170). Its comparison base is alpha/v2.2.0a170. Attribution for this release is being verified.
Changes
Added
24- **policy**: Complete canonical v3 rollout ([#1608](https://github.com/hashgraph-online/hol-guard/pull/1608)) Evidence for: **policy**: Complete canonical v3 rollout ([#1608](https://github.com/hashgraph-online/hol-guard/pull/1608))
- define the public Guard policy schema, YAML authoring model, deterministic normalization, and semantic diff classification Evidence for: define the public Guard policy schema, YAML authoring model, deterministic normalization, and semantic diff classification
- validate signed policy bundle v2 envelopes, bounded inputs, rollback lineage, acknowledgement transitions, and canonical last-good history Evidence for: validate signed policy bundle v2 envelopes, bounded inputs, rollback lineage, acknowledgement transitions, and canonical last-good history
- support canonical policy shadow comparison and controlled runtime enforcement across CLI and daemon sync paths Evidence for: support canonical policy shadow comparison and controlled runtime enforcement across CLI and daemon sync paths
- **policy**: Advertise bundle v2 capability ([#1589](https://github.com/hashgraph-online/hol-guard/pull/1589)) Evidence for: **policy**: Advertise bundle v2 capability ([#1589](https://github.com/hashgraph-online/hol-guard/pull/1589))
- advertise supported policy bundle contract versions in runtime-session sync Evidence for: advertise supported policy bundle contract versions in runtime-session sync
- retain policy document and YAML-import capability fields Evidence for: retain policy document and YAML-import capability fields
- keep canonical policy enforcement disabled unless its existing feature flag is enabled Evidence for: keep canonical policy enforcement disabled unless its existing feature flag is enabled
- **policy**: Validate signed bundle v2 ([#1588](https://github.com/hashgraph-online/hol-guard/pull/1588)) Evidence for: **policy**: Validate signed bundle v2 ([#1588](https://github.com/hashgraph-online/hol-guard/pull/1588))
- add bounded canonical Guard Policy Bundle v2 envelope validation Evidence for: add bounded canonical Guard Policy Bundle v2 envelope validation
- verify canonical payload and bundle hashes plus RSA-PSS signatures against anchored keyrings Evidence for: verify canonical payload and bundle hashes plus RSA-PSS signatures against anchored keyrings
- enforce monotonic bundle transitions, signed rollback metadata, and explicit acknowledgement sequencing Evidence for: enforce monotonic bundle transitions, signed rollback metadata, and explicit acknowledgement sequencing
- **policy**: Advertise YAML capabilities ([#1586](https://github.com/hashgraph-online/hol-guard/pull/1586)) Evidence for: **policy**: Advertise YAML capabilities ([#1586](https://github.com/hashgraph-online/hol-guard/pull/1586))
- advertise supported policy document contract versions in the existing runtime sync handshake Evidence for: advertise supported policy document contract versions in the existing runtime sync handshake
- report YAML import capability state while keeping canonical enforcement absent until explicitly enabled Evidence for: report YAML import capability state while keeping canonical enforcement absent until explicitly enabled
- preserve compatibility with servers that ignore the additive fields Evidence for: preserve compatibility with servers that ignore the additive fields
- **policy**: Add canonical YAML CLI ([#1585](https://github.com/hashgraph-online/hol-guard/pull/1585)) Evidence for: **policy**: Add canonical YAML CLI ([#1585](https://github.com/hashgraph-online/hol-guard/pull/1585))
- add canonical Guard policy YAML validation, formatting, diff, export, and feature-gated import commands Evidence for: add canonical Guard policy YAML validation, formatting, diff, export, and feature-gated import commands
- enforce trusted private file I/O, atomic writes, transactional merge/replace imports, approval gates, and signed policy integrity metadata Evidence for: enforce trusted private file I/O, atomic writes, transactional merge/replace imports, approval gates, and signed policy integrity metadata
- preserve cloud policies alongside imported documents and expose deterministic dry-run plans Evidence for: preserve cloud policies alongside imported documents and expose deterministic dry-run plans
- **policy**: Add versioned policy document schema ([#1582](https://github.com/hashgraph-online/hol-guard/pull/1582)) Evidence for: **policy**: Add versioned policy document schema ([#1582](https://github.com/hashgraph-online/hol-guard/pull/1582))
- define the `guard.hashgraphonline.com/v1alpha1` Guard Policy JSON Schema and semantic contract Evidence for: define the `guard.hashgraphonline.com/v1alpha1` Guard Policy JSON Schema and semantic contract
- add strict bounded YAML parsing, deterministic RFC 8785-compatible canonicalization, and SHA-256 digests Evidence for: add strict bounded YAML parsing, deterministic RFC 8785-compatible canonicalization, and SHA-256 digests
- package the schema with the Python distribution and freeze valid, invalid, precedence, and legacy hash fixtures Evidence for: package the schema with the Python distribution and freeze valid, invalid, precedence, and legacy hash fixtures
Fixed
6- **release**: Stabilize Guard 3 alpha gates ([#1613](https://github.com/hashgraph-online/hol-guard/pull/1613)) Evidence for: **release**: Stabilize Guard 3 alpha gates ([#1613](https://github.com/hashgraph-online/hol-guard/pull/1613))
- keep Windows alpha verification on policy parser, YAML, and signed-bundle contracts supported by the current Windows implementation Evidence for: keep Windows alpha verification on policy parser, YAML, and signed-bundle contracts supported by the current Windows implementation
- make the daemon connect test assert its eventual unlock contract instead of requiring one race-sensitive intermediate snapshot Evidence for: make the daemon connect test assert its eventual unlock contract instead of requiring one race-sensitive intermediate snapshot
- **release**: Run existing Windows policy tests ([#1612](https://github.com/hashgraph-online/hol-guard/pull/1612)) Evidence for: **release**: Run existing Windows policy tests ([#1612](https://github.com/hashgraph-online/hol-guard/pull/1612))
- replace a nonexistent Windows release-test path with existing policy YAML and bundle suites Evidence for: replace a nonexistent Windows release-test path with existing policy YAML and bundle suites
- keep the alpha publication fail-closed until Windows and Linux verification pass Evidence for: keep the alpha publication fail-closed until Windows and Linux verification pass
Other changes
2- Documented change: Guard 3.0.0a1 is an opt-in prerelease cut from [`00503c9`](https://github.com/hashgraph-online/hol-guard/commit/00503c950394a3616d44cd5488344a6f6379a602). Stable installations remain on the stable channel. **9 commits • 9 merged pull requests • 1 contributor** since [Guard 2.2.0a170](https://github.com/hashgraph-online/hol-guard/releases/tag/alpha/v2.2.0a170). Evidence for: Documented change: Guard 3.0.0a1 is an opt-in prerelease cut from [`00503c9`](https://github.com/hashgraph-online/hol-guard/commit/00503c950394a3616d44cd5488344a6f6379a602). Stable installations remain on the stable channel. **9 commits • 9 merged pull requests • 1 contributor** since [Guard 2.2.0a170](https://github.com/hashgraph-online/hol-guard/releases/tag/alpha/v2.2.0a170).
- **release**: Add isolated Guard 3 alpha channel ([#1611](https://github.com/hashgraph-online/hol-guard/pull/1611)) Evidence for: **release**: Add isolated Guard 3 alpha channel ([#1611](https://github.com/hashgraph-online/hol-guard/pull/1611))
Upgrade and compatibility
None documented.
Compare with the previous release
Predecessor on the same channel: alpha/v2.2.0a170
Verified contributors
Credits derive from public pull-request authorship, verified commit authorship, or verified co-authorship — never from thanks text or release metadata. Each distinct contributor is listed once; the evidence ledger paginates every published credit record.
Evidence ledger0 credits
No credits are published for this release yet.