NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Go modules · #2354 by repository stars
Last release today
09 Oct 2026
Ships on a steady schedule
a new release about every 8 days
Most releases are documented
notes for 4 of 5 stable releases
Nothing withdrawn
no release was ever pulled
2 months old
1160 releases · first in 2026
One column per month.
grpc and jsonparser vulnerabilities are patched ( #1287 ).
Tag v0.1.5 · commit e6445df · tagged 2026-09-20
Release lockfile: release-manifests/0.1.5/openbkn.yaml in openbkn-deploy
git clone https://github.com/openbkn-ai/openbkn-deploy.git && \
cd openbkn-deploy/deploy && \
sudo ./deploy.sh openbkn installUpgrading from 0.1.4 requires a one-time permission-model transition in a maintenance window. Read Upgrade Notes before you upgrade.
search_capabilities entry that ranks every capability kind in one space.search_capabilities entry over every mounted kind (#1397) ranked in one space (#1391).get_kn_detail reports what the network mounted (#1409); concept-group semantics narrow schema recall (#1200).MATCH (#1451).normal_user built-in role (#1410) and retired resource types (#1458).find_skills and search_tools (#1403) — use search_capabilities — and the semantic-search endpoint (#1196).run_code permission denials are separated from authorization outages (#1539); run_sql denials are explained (#1565).get_kn_detail reads from child lists instead of export mode (#1557).deploy/scripts/upgrades/0.1.5/permission_model_transition (#1466). It needs a maintenance window, a reviewed dry-run, and full logical backups of the BKN and Safe databases; stop, apply and start must run in order, and traffic stays closed until the authorization smoke tests pass. Fresh installs receive the current authorization marker from seed data and skip this step.normal_user built-in role is gone (#1410). Grant access explicitly through knowledge networks and catalogs.find_skills, search_tools, the PTC endpoints or the semantic-search endpoint must move to search_capabilities and the standard MCP surface.All 15 component charts are published at 0.1.5 under oci://ghcr.io/openbkn-ai/charts, pinned by the release lockfile: core-data-migrator, bkn-safe, mf-model-manager, mf-model-api, vega-backend, bkn-backend, ontology-query, agent-operator-integration, oss-gateway-backend, sandbox, agent-retrieval, bkn-agent, agent-observability, otelcol-contrib, bkn-studio.
Re-cut from release/0.1.4 to include #1165 (fix(execution-factory): rebuild Skill dataset with embedding model ID), which landed after the original ta
Tag v0.1.4 · commit 96c6d92 · charts and images published 2026-08-27
Release lockfile: deploy/release-manifests/0.1.4/bkn-foundry.yaml
deploy.sh openbkn install --version=0.1.4search_instance and explore_subgraph, a knn/match dual-channel retrieval fused by RRF, and an optional cross-encoder rerank stage — an agent can now go from a question to the instances that answer it without knowing the topology first.Accept-Language, propagates the effective locale downstream, and returns localized errors. All MCP tool schema descriptions are translated, with CI enforcing that no new hard-coded string slips in.normal_user wildcard grants over the data plane were revoked so that per-object configuration actually takes effect.search_instance recalls instances directly from natural language (#829), scoped by object type id (#1049).explore_subgraph traverses from a starting object type by direction and hop count when the topology is unknown (#970).knn_weight (#863) and an optional cross-encoder rerank stage, default off (#838).get_action_info surfaces the action output schema (#1055).total_count and accept sort (#964)./mcp/ptc endpoint supports programmatic tool calling (#945).run_code / run_shell are exposed on the business tool surface (#992).dry_run preview (#843).catalog.resource_manage and resource.query_data (#816); data tables can be authorized by the catalog that owns them (#874).Accept-Language negotiation in comm-go (#820) and locale propagation across Go services (#841), with consumers migrated (#851) and i18n resources and fallback governed centrally (#879).data_view path no longer work; rebind them to a resource.kafka-connect is no longer part of the release lockfile. It is absent from deploy/release-manifests/0.1.4/bkn-foundry.yaml.normal_user wildcard grants on catalog, resource and knowledge_network (#895). See Upgrade Notes.like / not_like are pinned to literal substring matching, consistently across every implementation (#885, #893).SELECT, FROM, GROUP BY and ORDER BY (#884).unsigned_long (#867); Vega JSON numbers survive Context Loader (#859).reranker (#857).search_schema (#780).list_resources filters by knowledge network (#782).mf-model-api returns 404 for a missing model (#976); LLM list latency reduced (#1063).resource_manage implies view_detail (#1132).query_data (#1131); query_data naming is unified and old-spelling object-level grants are migrated at startup (#882).normal_user. The wildcard catalog / resource / knowledge_network grants were revoked (#895) so that per-object and per-catalog configuration is no longer overridden. Role policy rows are rebuilt from grants.json on every start, so the change takes effect on the next restart in every environment, new install or upgrade alike. Restore visibility by issuing explicit catalog-level grants — one per catalog. Capability-plane access (toolboxes, skills, MCP, operators, models, agents) is unchanged.data_query was renamed to query_data (#882). Role grants follow the seed automatically. Object-level grants an administrator issued under the old spelling are migrated by an idempotent startup migration, scoped by resource type so catalog-side query_data is untouched.data_view path must be rebound to a resource before upgrading.kafka-connect left the release lockfile. If your installation depends on it, keep it pinned separately; deploy.sh openbkn install --version=0.1.4 will not manage it.install_opensearch returns early when the Helm release exists. To adopt it on an existing cluster, roll the OpenSearch StatefulSet and then restart vega-backend, whose analyzer capability table is cached with sync.Once.deploy/scripts/upgrades/0.1.4/cleanup_legacy_bkn_trace_data.sh (#1147, #1149). It is idempotent, tolerates an absent legacy evidence index, and fails closed on verification.All 15 component charts are published at 0.1.4 under oci://ghcr.io/openbkn-ai/charts, pinned by the release lockfile: core-data-migrator, bkn-safe, mf-model-manager, mf-model-api, vega-backend, bkn-backend, ontology-query, agent-operator-integration, oss-gateway-backend, sandbox, agent-retrieval, bkn-agent, agent-observability, otelcol-contrib, bkn-studio.
Nothing published for this version
OpenBKN 0.1.4 supply sample compatibility patch p1
OpenBKN 0.1.4 supply sample compatibility patch p1
OpenBKN 0.1.4 hotfix for supply sample compatibility p1
OpenBKN 0.1.4 hotfix for supply sample compatibility p1
fix(context-loader): backport list_resources knowledge-network filter…
fix(context-loader): backport list_resources knowledge-network filter…
… to release/0.1.3 (#785)
* fix(context-loader): list_resources 支持按知识网络过滤
list_resources 只有账户级资源池的分页,没有任何知识网络维度。调用方想知道
「这张网有哪些表」,只能取一页资源回来跟本体绑定求交集——池子一大就必然漏。
14.103.77.23 上池子 21540 条、网络绑定 14 张表,limit 取到 1000 都命中 0 条;
VM 上池子 262 条,limit=50/200/262 分别命中 1/3/28。Agent 拿到空列表就直接
回答「这个网络没有数据表」,整轮问答作废。
改成入参加 kn_id:在场时走本体拿绑定、再按 id 逐个取资源。刻意不碰 vega 的
列表端点——那条路是同一个分页,把调用方的 bug 原样搬进后端,还会一起吃到
#779 的排序不自洽。按 id 直取与池子大小无关,vega 侧零改动。
绑定是几十张表的量级,所以一次全返、不分页,kn_id 在场时忽略
catalog_id/offset/limit;type 仍对该网络的资源生效。多个对象类共用一张表按
资源去重,total_count 是去重后的条数。取资源限并发 8,避免串行到秒级。
取不到资源的绑定按成因分三类上报,不再静默跳过:unbound(压根没绑)、
stale_binding(绑的是已废弃的 data_view,这条不会拿去调 vega,落下去必 500)、
missing(资源已删或无权)。三者对应的动作完全不同,合成一个字段等于让调用
方再猜一次。单条失败不影响其余资源返回。
MCP instructions 原先一边说「其余工具都需要 kn_id」,一边把 list_resources
描述成只能按 catalog_id/type 过滤,模型照着塞 kn_id 又被静默丢弃,拿回的是
全库资源。两处文案一并对齐。
VM 外实测(14.103.77.23,supplychain_bkn_v4_new2):带 kn_id 返 14 条、
total_count=14、unbound 4 条(forecast_event / mrp_plan_order_event /
outsource_order_event / purchase_requisition_event),与 get_kn_detail 的
data_source 集合逐一对齐;不带 kn_id 仍是 50 条 / total_count=21540,且响应
里不出现新增字段。
Closes #781
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
* fix(context-loader): 下游整体不可用时不再伪装成空的资源列表
评审指出的降级语义漏洞:按 kn_id 取绑定资源时,若 vega 整体不可用或 ctx 超时,
所有绑定都落进 missing,调用仍返回成功 + 空 entries。调用方于是要把「后端挂了」
当成「这张网没有表」——正是本 issue 要消灭的那种哑故障,只是换了个位置。
改成:有绑定、一条都没取回来、且首个失败不是单资源成因时,透传下游错误,让
状态码和原因浮上去。
404/403 明确排除在外:一张网只绑一张表、这张表刚好被删或无权访问,是确凿的
建模事实,仍留在 missing 里,不伪装成服务故障。部分失败也照旧——其余资源正常
返回,失败的进 missing。
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →