What's Changed
- State-file hardening, crash-atomic writes, and tier-1 test isolation by @sheeki03 in #145
- Prompt-injection evasion resistance, output exfil detection, and policy-loadable seeds by @sheeki03 in #147
- ci: pin all GitHub Actions to commit SHAs + add Dependabot by @sheeki03 in #148
Full Changelog: v0.3.2...v0.3.3