The first release from ATLAS's new home, inferstep/ATLAS. It carries the
security fixes below, the move to the new image owner, and the new
contributor setup, on top of the changes on main since 3.1.3 (see the end of these notes).
Security: commands ran without approval, and file search read credential files
run_backgroundstarted any command without the approval prompt in the
default and accept-edits modes, and was checked against a narrower
deny-list thanrun_command(env rm -rf /and(rm -rf /)passed it).
Outside yolo, every tool that runs a command now asks, and one command
policy covers both. It looks where a command can start: behindenv,
nohup,nice,time,timeoutorexec, in a subshell and in a
command substitution.grep mkfs notes.txtis no longer refused.search_filesreturned the contents of credential files that
read_filerefuses (.env, keys, cloud credentials) and followed
symlinks out of the workspace. It now skips both and reports how many
credential files it skipped (skipped_credential_files).move_file
refuses to move a credential file to another name, andinsert_after
gets the write deny-list. The rules follow what a tool does, and a test
fails when a new tool is outside them. Shell commands are not covered,
and the docs now say so.- Approval prompts cut a command at 100 characters, so the end of a chain
was never shown. The proxy sends the whole command, and
stop_backgroundnames its job. - In the TUI, one "allow for session" answer on a deletion approved every
later deletion without showing which file, and the proxy honoured
delete_fileinsession_allowed_toolsfrom any client. Each deletion
is now asked about on its own: the TUI never auto-answers or sends a
session approval fordelete_file, the proxy ignores one, and a new
session starts with no approvals. The TUI prompt shows the whole
command, wrapped; one too long for the screen keeps its first and last
lines in view and says how many are not shown. - The TUI's chat stream, events stream, raw demo lane and feedback calls
never sent the service token, so on an install with one they failed
with 401. Every request to the proxy now sends it, ahead of an api-keys
token.
Moved to inferstep/ATLAS
- The repository is now github.com/inferstep/ATLAS. Old links,
git
remotes and the install one-liner redirect. - Images are published under ghcr.io/inferstep/atlas-* and signed by
the inferstep/ATLAS build workflow.ghcr.io/itigges22/atlas-*stays
published for existing installs but gets no new versions. - Existing installs: re-run the install command, or
git pulland then
atlas upgrade.atlas upgrade,atlas config migrateand a bootstrap
re-run moveATLAS_GHCR_OWNER=itigges22in.envtoinferstep. A
failed upgrade or a rollback puts it back. An install pinned to a
release from before the move keeps the old owner until it upgrades, and
an owner set in the shell is left alone.
Fixed
golang.org/x/netin the TUI is now v0.55.0 (GHSA-5cv4-jp36-h3mw).
Contributors
- New issue forms for bugs, features, tasks, docs, spikes and RFCs, and a
fuller pull request template. CONTRIBUTING is
rewritten as the path from an issue to a release. GOVERNANCE
describes the trust ladder and the RFC flow. New
TRIAGE and INCIDENT_RESPONSE
guides. - The public Roadmap board
has a Start Here view. The atlas-bot handles/claimand/unclaim,
reminds and releases stale claims, adds area labels and welcomes
newcomers. - Pull requests now also need the dependency review and a conventional
title check. An OpenSSF Scorecard runs weekly. Dependabot targetsdev. - Releases record a deployment per promotion, and publishing
:latestor
a version tag waits for the release owner's approval.
Docs
- The V3.0 LiveCodeBench figure (74.6%) is withdrawn. The benchmark runner
never ran LiveCodeBench's hidden tests (see the notice in
V3_ABLATION_STUDY). The README says
ATLAS has no current benchmark result.
Upgrade
- New install:
curl -fsSL https://raw.githubusercontent.com/inferstep/ATLAS/main/scripts/atlas-bootstrap.sh | bash - Existing install: in your ATLAS folder, run
git pullfirst, thenatlas upgrade. Or re-run the install command. Your.envmoves fromghcr.io/itigges22toghcr.io/inferstepon its own. Start the TUI withatlas tui, which rebuilds it from the new source. - Warning: on 3.1.3,
atlas upgradewithoutgit pullstays on the oldghcr.io/itigges22images, which have none of these fixes, and can still say it succeeded.
Verify
- The tag
v3.1.4is SSH-signed by a key in.github/allowed_signers(in a checkout:git -c gpg.ssh.allowedSignersFile=.github/allowed_signers verify-tag v3.1.4). - The images are signed with the inferstep/ATLAS build workflow's identity:
cosign verify --certificate-identity https://github.com/inferstep/ATLAS/.github/workflows/build-images.yml@refs/tags/v3.1.4 \ --certificate-oidc-issuer https://token.actions.githubusercontent.com ghcr.io/inferstep/atlas-proxy:3.1.4
This release also contains the changes on main since 3.1.3: see CHANGELOG.md (from "Measured reliability" down).