github inferstep/ATLAS v3.1.4
V3.1.4 "Maia"

4 hours ago

The first release from ATLAS's new home, inferstep/ATLAS. It carries the
security fixes below, the move to the new image owner, and the new
contributor setup, on top of the changes on main since 3.1.3 (see the end of these notes).

Security: commands ran without approval, and file search read credential files

  • run_background started any command without the approval prompt in the
    default and accept-edits modes, and was checked against a narrower
    deny-list than run_command (env rm -rf / and (rm -rf /) passed it).
    Outside yolo, every tool that runs a command now asks, and one command
    policy covers both. It looks where a command can start: behind env,
    nohup, nice, time, timeout or exec, in a subshell and in a
    command substitution. grep mkfs notes.txt is no longer refused.
  • search_files returned the contents of credential files that
    read_file refuses (.env, keys, cloud credentials) and followed
    symlinks out of the workspace. It now skips both and reports how many
    credential files it skipped (skipped_credential_files). move_file
    refuses to move a credential file to another name, and insert_after
    gets the write deny-list. The rules follow what a tool does, and a test
    fails when a new tool is outside them. Shell commands are not covered,
    and the docs now say so.
  • Approval prompts cut a command at 100 characters, so the end of a chain
    was never shown. The proxy sends the whole command, and
    stop_background names its job.
  • In the TUI, one "allow for session" answer on a deletion approved every
    later deletion without showing which file, and the proxy honoured
    delete_file in session_allowed_tools from any client. Each deletion
    is now asked about on its own: the TUI never auto-answers or sends a
    session approval for delete_file, the proxy ignores one, and a new
    session starts with no approvals. The TUI prompt shows the whole
    command, wrapped; one too long for the screen keeps its first and last
    lines in view and says how many are not shown.
  • The TUI's chat stream, events stream, raw demo lane and feedback calls
    never sent the service token, so on an install with one they failed
    with 401. Every request to the proxy now sends it, ahead of an api-keys
    token.

Moved to inferstep/ATLAS

  • The repository is now github.com/inferstep/ATLAS. Old links, git
    remotes and the install one-liner redirect.
  • Images are published under ghcr.io/inferstep/atlas-* and signed by
    the inferstep/ATLAS build workflow. ghcr.io/itigges22/atlas-* stays
    published for existing installs but gets no new versions.
  • Existing installs: re-run the install command, or git pull and then
    atlas upgrade. atlas upgrade, atlas config migrate and a bootstrap
    re-run move ATLAS_GHCR_OWNER=itigges22 in .env to inferstep. A
    failed upgrade or a rollback puts it back. An install pinned to a
    release from before the move keeps the old owner until it upgrades, and
    an owner set in the shell is left alone.

Fixed

Contributors

  • New issue forms for bugs, features, tasks, docs, spikes and RFCs, and a
    fuller pull request template. CONTRIBUTING is
    rewritten as the path from an issue to a release. GOVERNANCE
    describes the trust ladder and the RFC flow. New
    TRIAGE and INCIDENT_RESPONSE
    guides.
  • The public Roadmap board
    has a Start Here view. The atlas-bot handles /claim and /unclaim,
    reminds and releases stale claims, adds area labels and welcomes
    newcomers.
  • Pull requests now also need the dependency review and a conventional
    title check. An OpenSSF Scorecard runs weekly. Dependabot targets dev.
  • Releases record a deployment per promotion, and publishing :latest or
    a version tag waits for the release owner's approval.

Docs

  • The V3.0 LiveCodeBench figure (74.6%) is withdrawn. The benchmark runner
    never ran LiveCodeBench's hidden tests (see the notice in
    V3_ABLATION_STUDY). The README says
    ATLAS has no current benchmark result.

Upgrade

  • New install: curl -fsSL https://raw.githubusercontent.com/inferstep/ATLAS/main/scripts/atlas-bootstrap.sh | bash
  • Existing install: in your ATLAS folder, run git pull first, then atlas upgrade. Or re-run the install command. Your .env moves from ghcr.io/itigges22 to ghcr.io/inferstep on its own. Start the TUI with atlas tui, which rebuilds it from the new source.
  • Warning: on 3.1.3, atlas upgrade without git pull stays on the old ghcr.io/itigges22 images, which have none of these fixes, and can still say it succeeded.

Verify

  • The tag v3.1.4 is SSH-signed by a key in .github/allowed_signers (in a checkout: git -c gpg.ssh.allowedSignersFile=.github/allowed_signers verify-tag v3.1.4).
  • The images are signed with the inferstep/ATLAS build workflow's identity:
    cosign verify --certificate-identity https://github.com/inferstep/ATLAS/.github/workflows/build-images.yml@refs/tags/v3.1.4 \
      --certificate-oidc-issuer https://token.actions.githubusercontent.com ghcr.io/inferstep/atlas-proxy:3.1.4
    

This release also contains the changes on main since 3.1.3: see CHANGELOG.md (from "Measured reliability" down).

Don't miss a new ATLAS release

NewReleases is sending notifications on new releases.