Documented changes
99 typed entries
Verified contributors
Credits being verified. Attribution coverage is in progress.
Attribution coverage
attribution in progress; history inventory partial.
Install
Scope
Guard v3.1.0a10 is a preview release published 2026-07-20. Upstream documents: Guard 3.1.0a10 is an opt-in prerelease cut from [`0576441`](https://github.com/hashgraph-online/hol-guard/commit/0576441a95887f82923ce723efcdba4e71a623ac). Stable installations remain on the stable channel. **29 commits • 27 merged pull requests • 2 contributors** since [Guard 3.1.0a5](https://github.com/hashgraph-online/hol-guard/releases/tag/alpha/v3.1.0a5). Its comparison base is alpha/v3.1.0a5. It includes 59 verified contribution deliveries with public evidence links. Attribution for this release is being verif
Changes
Added
17- **guard**: Add opt-in user-managed health leases ([#1692](https://github.com/hashgraph-online/hol-guard/pull/1692)) Evidence for: **guard**: Add opt-in user-managed health leases ([#1692](https://github.com/hashgraph-online/hol-guard/pull/1692))
- add explicit `health-leases enable|disable|status|report` controls for connected user installations Evidence for: add explicit `health-leases enable|disable|status|report` controls for connected user installations
- generate user-scoped P-256 signing and continuity state with private 0600/symlink-safe storage Evidence for: generate user-scoped P-256 signing and continuity state with private 0600/symlink-safe storage
- deliver replay-safe pending leases through the existing purpose-bound Cloud health endpoints with `assuranceLevel=user-managed` Evidence for: deliver replay-safe pending leases through the existing purpose-bound Cloud health endpoints with `assuranceLevel=user-managed`
- **mdm**: Publish vendor-neutral adapter conformance contract ([#1681](https://github.com/hashgraph-online/hol-guard/pull/1681)) Evidence for: **mdm**: Publish vendor-neutral adapter conformance contract ([#1681](https://github.com/hashgraph-online/hol-guard/pull/1681))
- publish a vendor-neutral observer and remediation adapter contract Evidence for: publish a vendor-neutral observer and remediation adapter contract
- add reusable signed-envelope conformance harnesses with strict freshness, replay, mapping, outage, action, generation, and expiry checks Evidence for: add reusable signed-envelope conformance harnesses with strict freshness, replay, mapping, outage, action, generation, and expiry checks
- add deterministic signed fixtures covering the certification matrix Evidence for: add deterministic signed fixtures covering the certification matrix
- **mdm**: Deliver challenge-bound protection leases ([#1674](https://github.com/hashgraph-online/hol-guard/pull/1674)) Evidence for: **mdm**: Deliver challenge-bound protection leases ([#1674](https://github.com/hashgraph-online/hol-guard/pull/1674))
- emit the frozen protection-lease.v1 contract with canonical low-S P-256 signatures Evidence for: emit the frozen protection-lease.v1 contract with canonical low-S P-256 signatures
- register machine health keys and deliver/ack leases through a dedicated machine-owned OAuth/DPoP profile Evidence for: register machine health keys and deliver/ack leases through a dedicated machine-owned OAuth/DPoP profile
- answer only strict identity-bound attestation challenges and expose bounded delivery metrics without weakening local enforcement Evidence for: answer only strict identity-bound attestation challenges and expose bounded delivery metrics without weakening local enforcement
- **mdm**: Run health leases on machine cadence ([#1644](https://github.com/hashgraph-online/hol-guard/pull/1644)) Evidence for: **mdm**: Run health leases on machine cadence ([#1644](https://github.com/hashgraph-online/hol-guard/pull/1644))
- replace the protected five-minute snapshot action with a dedicated machine health lease cadence Evidence for: replace the protected five-minute snapshot action with a dedicated machine health lease cadence
- require workspace and device bindings to be MDM-managed and locked before lease issuance Evidence for: require workspace and device bindings to be MDM-managed and locked before lease issuance
- keep scheduled output bounded to lease metadata while preserving the signed outbox for delivery Evidence for: keep scheduled output bounded to lease metadata while preserving the signed outbox for delivery
- **guard**: Persistent tray/menu-bar icon with canonical dashboard launcher ([#1633](https://github.com/hashgraph-online/hol-guard/pull/1633)) Evidence for: **guard**: Persistent tray/menu-bar icon with canonical dashboard launcher ([#1633](https://github.com/hashgraph-online/hol-guard/pull/1633))
Fixed
22- **release**: Enforce cross-registry alpha uniqueness ([#1760](https://github.com/hashgraph-online/hol-guard/pull/1760)) Evidence for: **release**: Enforce cross-registry alpha uniqueness ([#1760](https://github.com/hashgraph-online/hol-guard/pull/1760))
- include TestPyPI versions when validating a requested release/3.1 alpha version Evidence for: include TestPyPI versions when validating a requested release/3.1 alpha version
- prevent a stale TestPyPI artifact from colliding with a new build before PyPI publication Evidence for: prevent a stale TestPyPI artifact from colliding with a new build before PyPI publication
- lock the cross-registry uniqueness contract in workflow tests Evidence for: lock the cross-registry uniqueness contract in workflow tests
- **release**: Align alpha trusted publisher environment ([#1758](https://github.com/hashgraph-online/hol-guard/pull/1758)) Evidence for: **release**: Align alpha trusted publisher environment ([#1758](https://github.com/hashgraph-online/hol-guard/pull/1758))
- align alpha publishing with the PyPI trusted publisher's `pypi` environment Evidence for: align alpha publishing with the PyPI trusted publisher's `pypi` environment
- keep the workflow contract test synchronized with the registered publisher identity Evidence for: keep the workflow contract test synchronized with the registered publisher identity
- **mdm**: Avoid health lock during cloud delivery ([#1757](https://github.com/hashgraph-online/hol-guard/pull/1757)) Evidence for: **mdm**: Avoid health lock during cloud delivery ([#1757](https://github.com/hashgraph-online/hol-guard/pull/1757))
- keep user health state locks scoped to local state transitions instead of Cloud round trips Evidence for: keep user health state locks scoped to local state transitions instead of Cloud round trips
- reconcile concurrent idempotent acknowledgements without forking lease continuity Evidence for: reconcile concurrent idempotent acknowledgements without forking lease continuity
- validate key identifiers defensively and avoid repeated imports in the live sync loop Evidence for: validate key identifiers defensively and avoid repeated imports in the live sync loop
- **guard**: Add safe MCP policy authoring tools ([`78a4b97`](https://github.com/hashgraph-online/hol-guard/commit/78a4b97f76a7e41cbcaeb59b6040b6fd98d5f617)) Evidence for: **guard**: Add safe MCP policy authoring tools ([`78a4b97`](https://github.com/hashgraph-online/hol-guard/commit/78a4b97f76a7e41cbcaeb59b6040b6fd98d5f617))
- **mdm**: Redact support diagnostics errors ([#1688](https://github.com/hashgraph-online/hol-guard/pull/1688)) Evidence for: **mdm**: Redact support diagnostics errors ([#1688](https://github.com/hashgraph-online/hol-guard/pull/1688))
- preserve bounded machine health state, reason codes, and lease evidence identifiers for support Evidence for: preserve bounded machine health state, reason codes, and lease evidence identifiers for support
- replace arbitrary transport exception text with stable diagnostic codes Evidence for: replace arbitrary transport exception text with stable diagnostic codes
- prove tokens, private keys, host paths, credentials, and raw commands cannot echo through JSON diagnostics Evidence for: prove tokens, private keys, host paths, credentials, and raw commands cannot echo through JSON diagnostics
- **policy**: Suppress rollout cohort hash false positive ([#1680](https://github.com/hashgraph-online/hol-guard/pull/1680)) Evidence for: **policy**: Suppress rollout cohort hash false positive ([#1680](https://github.com/hashgraph-online/hol-guard/pull/1680))
- Document that canonical-policy rollout bucketing hashes opaque installation identifiers, not passwords. Evidence for: Document that canonical-policy rollout bucketing hashes opaque installation identifiers, not passwords.
- Suppress the inapplicable CodeQL password-hashing rule without changing cohort assignment. Evidence for: Suppress the inapplicable CodeQL password-hashing rule without changing cohort assignment.
- **mdm**: Align protection lease duration contract ([#1675](https://github.com/hashgraph-online/hol-guard/pull/1675)) Evidence for: **mdm**: Align protection lease duration contract ([#1675](https://github.com/hashgraph-online/hol-guard/pull/1675))
- align issuer validation with the frozen 180–1800 second protection-lease contract Evidence for: align issuer validation with the frozen 180–1800 second protection-lease contract
- add boundary regression coverage for accepted and rejected lease lifetimes Evidence for: add boundary regression coverage for accepted and rejected lease lifetimes
Other changes
60- Documented change: Guard 3.1.0a10 is an opt-in prerelease cut from [`0576441`](https://github.com/hashgraph-online/hol-guard/commit/0576441a95887f82923ce723efcdba4e71a623ac). Stable installations remain on the stable channel. **29 commits • 27 merged pull requests • 2 contributors** since [Guard 3.1.0a5](https://github.com/hashgraph-online/hol-guard/releases/tag/alpha/v3.1.0a5). Evidence for: Documented change: Guard 3.1.0a10 is an opt-in prerelease cut from [`0576441`](https://github.com/hashgraph-online/hol-guard/commit/0576441a95887f82923ce723efcdba4e71a623ac). Stable installations remain on the stable channel. **29 commits • 27 merged pull requests • 2 contributors** since [Guard 3.1.0a5](https://github.com/hashgraph-online/hol-guard/releases/tag/alpha/v3.1.0a5).
- Merged pull request #1644: feat(mdm): run health leases on machine cadence (#1644) Evidence for: Merged pull request #1644: feat(mdm): run health leases on machine cadence (#1644)
- Merged pull request #1635: fix(guard): preserve current approval authority (#1635) Evidence for: Merged pull request #1635: fix(guard): preserve current approval authority (#1635)
- Merged pull request #1648: fix(guard): complete canonical policy CLI integrity (#1648) Evidence for: Merged pull request #1648: fix(guard): complete canonical policy CLI integrity (#1648)
- Merged pull request #1643: fix(release): handle unchanged integration versions (#1643) Evidence for: Merged pull request #1643: fix(release): handle unchanged integration versions (#1643)
- Merged pull request #1654: fix(runtime): calibrate bounded source inspection (#1654) Evidence for: Merged pull request #1654: fix(runtime): calibrate bounded source inspection (#1654)
- Merged pull request #1637: chore(release): sync repository version to 2.0.1115 [skip release publish] Evidence for: Merged pull request #1637: chore(release): sync repository version to 2.0.1115 [skip release publish]
- Merged pull request #1672: fix(store): index recent Guard event queries (#1672) Evidence for: Merged pull request #1672: fix(store): index recent Guard event queries (#1672)
- Merged pull request #1695: Revert "Release/3.1" Evidence for: Merged pull request #1695: Revert "Release/3.1"
- Direct commit e290b872153a: chore(release): sync repository version to 2.0.1114 [skip release publish] Evidence for: Direct commit e290b872153a: chore(release): sync repository version to 2.0.1114 [skip release publish]
- Merged pull request #1901: Merge remote-tracking branch 'origin/main' into fix/release-31-merge Evidence for: Merged pull request #1901: Merge remote-tracking branch 'origin/main' into fix/release-31-merge
- Merged pull request #1760: fix(release): enforce cross-registry alpha uniqueness (#1760) Evidence for: Merged pull request #1760: fix(release): enforce cross-registry alpha uniqueness (#1760)
- Direct commit 3655d57894a8: fix(guard): centralize action enforcement lattice (#1618) Evidence for: Direct commit 3655d57894a8: fix(guard): centralize action enforcement lattice (#1618)
- Merged pull request #1618: fix(guard): centralize action enforcement lattice (#1618) Evidence for: Merged pull request #1618: fix(guard): centralize action enforcement lattice (#1618)
- Merged pull request #1682: chore(release): merge main into 3.1 Evidence for: Merged pull request #1682: chore(release): merge main into 3.1
- Merged pull request #1640: chore(release): sync repository version to 2.0.1116 [skip release publish] Evidence for: Merged pull request #1640: chore(release): sync repository version to 2.0.1116 [skip release publish]
- Merged pull request #1659: fix(guard): unify authoritative decision surfaces (#1659) Evidence for: Merged pull request #1659: fix(guard): unify authoritative decision surfaces (#1659)
- Merged pull request #1668: fix(release): tolerate registry propagation lag Evidence for: Merged pull request #1668: fix(release): tolerate registry propagation lag
- Merged pull request #1690: chore(release): merge main into 3.1 Evidence for: Merged pull request #1690: chore(release): merge main into 3.1
- Merged pull request #1684: fix(hooks): preserve strict policy without blocking safe observers (#1684) Evidence for: Merged pull request #1684: fix(hooks): preserve strict policy without blocking safe observers (#1684)
- Merged pull request #1692: feat(guard): add opt-in user-managed health leases (#1692) Evidence for: Merged pull request #1692: feat(guard): add opt-in user-managed health leases (#1692)
- Merged pull request #1650: Merge pull request #1650 from hashgraph-online/release/3.1 Evidence for: Merged pull request #1650: Merge pull request #1650 from hashgraph-online/release/3.1
- Direct commit 9b78e5249493: fix(guard): unify authoritative decision surfaces (#1659) Evidence for: Direct commit 9b78e5249493: fix(guard): unify authoritative decision surfaces (#1659)
- Merged pull request #1676: fix(guard): isolate updater execution (#1676) Evidence for: Merged pull request #1676: fix(guard): isolate updater execution (#1676)
- Merged pull request #1646: fix(guard): require trusted policy bundle signatures (#1646) Evidence for: Merged pull request #1646: fix(guard): require trusted policy bundle signatures (#1646)
- Merged pull request #1665: fix(release): ignore TestPyPI attestation sidecars (#1665) Evidence for: Merged pull request #1665: fix(release): ignore TestPyPI attestation sidecars (#1665)
- Merged pull request #1670: fix(release): ignore local attestation sidecars (#1670) Evidence for: Merged pull request #1670: fix(release): ignore local attestation sidecars (#1670)
- Direct commit b4a0248e0af0: Merge pull request #1728 from hashgraph-online/fix/p30-scoped-package-index Evidence for: Direct commit b4a0248e0af0: Merge pull request #1728 from hashgraph-online/fix/p30-scoped-package-index
- Merged pull request #1747: fix(guard): add safe MCP policy authoring tools Evidence for: Merged pull request #1747: fix(guard): add safe MCP policy authoring tools
- Merged pull request #1758: fix(release): align alpha trusted publisher environment (#1758) Evidence for: Merged pull request #1758: fix(release): align alpha trusted publisher environment (#1758)
- Direct commit 2b90e9a2f44e: chore(release): sync repository version to 2.0.1116 [skip release publish] Evidence for: Direct commit 2b90e9a2f44e: chore(release): sync repository version to 2.0.1116 [skip release publish]
- Merged pull request #1633: feat(guard): persistent tray/menu-bar icon with canonical dashboard launcher (#1633) Evidence for: Merged pull request #1633: feat(guard): persistent tray/menu-bar icon with canonical dashboard launcher (#1633)
- Merged pull request #1642: fix(policy): compile canonical tool selectors (#1642) Evidence for: Merged pull request #1642: fix(policy): compile canonical tool selectors (#1642)
- Merged pull request #1666: fix(release): provision revalidation dependencies Evidence for: Merged pull request #1666: fix(release): provision revalidation dependencies
- Merged pull request #1757: fix(mdm): avoid health lock during cloud delivery (#1757) Evidence for: Merged pull request #1757: fix(mdm): avoid health lock during cloud delivery (#1757)
- Merged pull request #1674: feat(mdm): deliver challenge-bound protection leases (#1674) Evidence for: Merged pull request #1674: feat(mdm): deliver challenge-bound protection leases (#1674)
- Merged pull request #1689: fix(hooks): honor benign harness defaults (#1689) Evidence for: Merged pull request #1689: fix(hooks): honor benign harness defaults (#1689)
- Merged pull request #1641: fix(release): harden release train publication (#1641) Evidence for: Merged pull request #1641: fix(release): harden release train publication (#1641)
- Merged pull request #1663: fix(release): ignore generated upload attestations Evidence for: Merged pull request #1663: fix(release): ignore generated upload attestations
- Merged pull request #1680: fix(policy): suppress rollout cohort hash false positive Evidence for: Merged pull request #1680: fix(policy): suppress rollout cohort hash false positive
- Merged pull request #1688: fix(mdm): redact support diagnostics errors (#1688) Evidence for: Merged pull request #1688: fix(mdm): redact support diagnostics errors (#1688)
- Merged pull request #1664: fix(release): ignore registry attestation sidecars (#1664) Evidence for: Merged pull request #1664: fix(release): ignore registry attestation sidecars (#1664)
- Merged pull request #1656: chore(release): sync repository version to 2.0.1117 Evidence for: Merged pull request #1656: chore(release): sync repository version to 2.0.1117
- Merged pull request #1655: test(guard): make policy retry lock test deterministic (#1655) Evidence for: Merged pull request #1655: test(guard): make policy retry lock test deterministic (#1655)
- Merged pull request #1683: docs(guard): add protection operations runbooks (#1683) Evidence for: Merged pull request #1683: docs(guard): add protection operations runbooks (#1683)
- Merged pull request #1651: chore(release): merge main into 3.1 Evidence for: Merged pull request #1651: chore(release): merge main into 3.1
- Merged pull request #1694: refactor(policy): split document adapters Evidence for: Merged pull request #1694: refactor(policy): split document adapters
- Merged pull request #1675: fix(mdm): align protection lease duration contract (#1675) Evidence for: Merged pull request #1675: fix(mdm): align protection lease duration contract (#1675)
- Merged pull request #1657: docs(guard): freeze self-protection authority contracts (#1657) Evidence for: Merged pull request #1657: docs(guard): freeze self-protection authority contracts (#1657)
- Merged pull request #1691: chore(release): synchronize main into 3.1 Evidence for: Merged pull request #1691: chore(release): synchronize main into 3.1
- Direct commit c56ce0af61a5: chore(release): sync repository version to 2.0.1115 [skip release publish] Evidence for: Direct commit c56ce0af61a5: chore(release): sync repository version to 2.0.1115 [skip release publish]
- Merged pull request #1661: fix(release): restore automatic main publication Evidence for: Merged pull request #1661: fix(release): restore automatic main publication
- Merged pull request #1620: chore(release): sync repository version to 2.0.1114 [skip release publish] Evidence for: Merged pull request #1620: chore(release): sync repository version to 2.0.1114 [skip release publish]
- Merged pull request #1660: fix(release): use registered TestPyPI publisher (#1660) Evidence for: Merged pull request #1660: fix(release): use registered TestPyPI publisher (#1660)
- Direct commit df0610fec0f6: Merge branch 'main' into fix/p45-authoritative-decision Evidence for: Direct commit df0610fec0f6: Merge branch 'main' into fix/p45-authoritative-decision
- Merged pull request #1638: fix(ci): reduce workflow latency and async flakes (#1638) Evidence for: Merged pull request #1638: fix(ci): reduce workflow latency and async flakes (#1638)
- Merged pull request #1669: test: synchronize cloud reconnect completion (#1669) Evidence for: Merged pull request #1669: test: synchronize cloud reconnect completion (#1669)
- Merged pull request #1645: fix(release): enforce alpha-only 2.2 train (#1645) Evidence for: Merged pull request #1645: fix(release): enforce alpha-only 2.2 train (#1645)
- Merged pull request #1681: feat(mdm): publish vendor-neutral adapter conformance contract (#1681) Evidence for: Merged pull request #1681: feat(mdm): publish vendor-neutral adapter conformance contract (#1681)
- Merged pull request #1653: fix(guard): preserve registered executable tamper errors (#1653) Evidence for: Merged pull request #1653: fix(guard): preserve registered executable tamper errors (#1653)
Upgrade and compatibility
None documented.
Compare with the previous release
Predecessor on the same channel: alpha/v3.1.0a5
Verified contributors
Credits derive from public pull-request authorship, verified commit authorship, or verified co-authorship — never from thanks text or release metadata. Each distinct contributor is listed once; the evidence ledger paginates every published credit record.
Contributors
- @deep-purple-boots
Implementation · 8 credits
- @github-actions[bot]
Implementation · 3 credits
- @kantorcodes
Implementation · 48 credits
Evidence ledger59 credits
- @deep-purple-bootsSource for deep-purple-boots
Implementation · Pull request author
- @deep-purple-bootsSource for deep-purple-boots
Implementation · Verified commit author
- @deep-purple-bootsSource for deep-purple-boots
Implementation · Pull request author
- @deep-purple-bootsSource for deep-purple-boots
Implementation · Pull request author
- @deep-purple-bootsSource for deep-purple-boots
Implementation · Verified commit author
- @deep-purple-bootsSource for deep-purple-boots
Implementation · Pull request author
- @deep-purple-bootsSource for deep-purple-boots
Implementation · Pull request author
- @deep-purple-bootsSource for deep-purple-boots
Implementation · Verified commit author
- @github-actions[bot]Source for github-actions[bot]
Implementation · Verified commit author
- @github-actions[bot]Source for github-actions[bot]
Implementation · Verified commit author
- @github-actions[bot]Source for github-actions[bot]
Implementation · Verified commit author
- @kantorcodesSource for kantorcodes
Implementation · Pull request author
- @kantorcodesSource for kantorcodes
Implementation · Pull request author
- @kantorcodesSource for kantorcodes
Implementation · Pull request author
- @kantorcodesSource for kantorcodes
Implementation · Pull request author
- @kantorcodesSource for kantorcodes
Implementation · Pull request author
- @kantorcodesSource for kantorcodes
Implementation · Pull request author
- @kantorcodesSource for kantorcodes
Implementation · Pull request author
- @kantorcodesSource for kantorcodes
Implementation · Pull request author
- @kantorcodesSource for kantorcodes
Implementation · Pull request author
- @kantorcodesSource for kantorcodes
Implementation · Pull request author
- @kantorcodesSource for kantorcodes
Implementation · Pull request author
- @kantorcodesSource for kantorcodes
Implementation · Pull request author
- @kantorcodesSource for kantorcodes
Implementation · Pull request author
- @kantorcodesSource for kantorcodes
Implementation · Pull request author
- @kantorcodesSource for kantorcodes
Implementation · Pull request author
- @kantorcodesSource for kantorcodes
Implementation · Pull request author
- @kantorcodesSource for kantorcodes
Implementation · Pull request author
- @kantorcodesSource for kantorcodes
Implementation · Pull request author
- @kantorcodesSource for kantorcodes
Implementation · Pull request author
- @kantorcodesSource for kantorcodes
Implementation · Pull request author
- @kantorcodesSource for kantorcodes
Implementation · Pull request author
- @kantorcodesSource for kantorcodes
Implementation · Pull request author
- @kantorcodesSource for kantorcodes
Implementation · Pull request author
- @kantorcodesSource for kantorcodes
Implementation · Pull request author
- @kantorcodesSource for kantorcodes
Implementation · Pull request author
- @kantorcodesSource for kantorcodes
Implementation · Pull request author
- @kantorcodesSource for kantorcodes
Implementation · Pull request author
- @kantorcodesSource for kantorcodes
Implementation · Pull request author
- @kantorcodesSource for kantorcodes
Implementation · Pull request author
- @kantorcodesSource for kantorcodes
Implementation · Pull request author
- @kantorcodesSource for kantorcodes
Implementation · Pull request author
- @kantorcodesSource for kantorcodes
Implementation · Pull request author
- @kantorcodesSource for kantorcodes
Implementation · Pull request author
- @kantorcodesSource for kantorcodes
Implementation · Pull request author
- @kantorcodesSource for kantorcodes
Implementation · Pull request author
- @kantorcodesSource for kantorcodes
Implementation · Pull request author
- @kantorcodesSource for kantorcodes
Implementation · Pull request author
- @kantorcodesSource for kantorcodes
Implementation · Pull request author
- @kantorcodesSource for kantorcodes
Implementation · Pull request author
- @kantorcodesSource for kantorcodes
Implementation · Pull request author
- @kantorcodesSource for kantorcodes
Implementation · Pull request author
- @kantorcodesSource for kantorcodes
Implementation · Pull request author
- @kantorcodesSource for kantorcodes
Implementation · Verified commit author
- @kantorcodesSource for kantorcodes
Implementation · Pull request author
- @kantorcodesSource for kantorcodes
Implementation · Pull request author
- @kantorcodesSource for kantorcodes
Implementation · Pull request author
- @kantorcodesSource for kantorcodes
Implementation · Pull request author
- @kantorcodesSource for kantorcodes
Implementation · Pull request author