nomos_flutter
Drive the real Nomos GitHolon from a Flutter app — a local-first domain runtime. Every platform acquires and retains the same provider-selected compatible WASM; Apple executes it through the resident DrumBrake host. Write TypeScript domains, get a typesafe Dart client, build Flutter widgets.
0.64.0
3.9K downloads/mo
#4210 most downloaded on pub.dev
Captain-App/nomos2
What this package is like to depend on
Last release today
23 Aug 2026
Ships on a steady schedule
a new release about every 8 days
Nearly every release is documented
notes for 123 of 136 stable releases
Nothing withdrawn
no release was ever pulled
2 months old
136 releases · first in 2026
136 releases in the last 12 months
see the full history below
Release timeline
136 releases · Jun 2026 to Aug 2026Releases
latest 60 of 136-
0.64.023 Aug 2026Release notes
Open source →- Consume
nomos_types0.9.0 andnomos_client0.65.0 so Flutter hosts use the same generated typed offer-admission ABI as the kernel and other hosts.
- Consume
-
0.63.7623 Aug 2026Release notes
Open source →- Declare the generated protobuf messages' direct
fixnumruntime dependency so the exact qualified package passes pub.dev validation.
- Declare the generated protobuf messages' direct
-
0.63.6615 Aug 2026Release notes
Open source →- Expand the deterministic Pulley call-fuel envelope so authenticated first-device birth can complete, and retain the underlying Wasmtime trap reason in native host diagnostics.
-
0.63.6515 Aug 2026Release notes
Open source →- Resolve the resident Pulley host from Flutter's real macOS ephemeral plugin-symlink directory, while retaining the existing iOS CocoaPods path.
-
0.63.6415 Aug 2026Release notes
Open source →- Resolve, verify, and retain the provider-selected kernel through a schema-valid OSGi Repository document. The loopback broker serves only the selected exact digest; no private JSON manifest or feature query remains.
-
0.63.6113 Aug 2026Release notes
Open source →- Add the Android application runner used to produce and compose deterministic CycloneDX Pub, Gradle, and CocoaPods dependency evidence for the example app.
- Keep the iOS kernel linker path symbolic so CocoaPods lockfile checksums are identical across clean checkout locations.
-
0.63.5813 Aug 2026Release notes
Open source →- Rebuild and release the embedded runner assets from @githolon/client 0.105.19; the pub.dev archive now carries the exact npm release stamp proved by this commit.
- Keep typed birth evidence off the preliminary signer-enrolment offer so authenticated generated applications can complete first-device startup.
- Consume
nomos_client0.64.34 for the corrected generated runner lifecycle.
-
0.63.5713 Aug 2026Release notes
Open source →- Rebuild and release the embedded runner assets from @githolon/client 0.105.18; the pub.dev archive now carries the exact npm release stamp proved by this commit.
- Open generated applications across arbitrary historical model backlogs while preserving a bounded, typed guard against a genuinely stuck lifecycle step.
- Consume
nomos_client0.64.33 for progress-aware model convergence.
-
0.63.5612 Aug 2026Release notes
Open source →- Rebuild and release the embedded runner assets from @githolon/client 0.105.17; the pub.dev archive now carries the exact npm release stamp proved by this commit.
-
0.63.5512 Aug 2026Release notes
Open source →- Rebuild and release the embedded runner assets from @githolon/client 0.105.16; the pub.dev archive now carries the exact npm release stamp proved by this commit.
- Consume
nomos_client0.64.32 so Flutter applications prove durable device enrolment before generated writes become available.
-
0.63.5412 Aug 2026Release notes
Open source →- Rebuild and release the embedded runner assets from @githolon/client 0.105.15; the pub.dev archive now carries the exact npm release stamp proved by this commit.
- Consume
nomos_client0.64.31 so Flutter applications use the restaged, type-safe intent-offer gate and deterministic signer posture.
-
0.63.5212 Aug 2026Release notes
Open source →- Rebuild and release the embedded runner assets from @githolon/client 0.105.14; the pub.dev archive now carries the exact npm release stamp proved by this commit.
- Restaged with the current kernel candidate: regenerated vendored assets (kernel release identity is baked into them). Published pub.dev archives are immutable, so regenerated bytes ride their own version.
-
0.63.5111 Aug 2026Release notes
Open source →- Rebuild and release the embedded runner assets from @githolon/client 0.105.13; the pub.dev archive now carries the exact npm release stamp proved by this commit.
- Restaged with the current kernel candidate: regenerated vendored assets (kernel release identity is baked into them). Published pub.dev archives are immutable, so regenerated bytes ride their own version.
-
0.63.5011 Aug 2026Release notes
Open source →- Rebuild and release the embedded runner assets from @githolon/client 0.105.12; the pub.dev archive now carries the exact npm release stamp proved by this commit.
- Consume
nomos_client0.64.27 so the Flutter package and its Dart runtime usenomos.cafeas the sole default cloud surface.
-
0.63.4911 Aug 2026Release notes
Open source →- Rebuild and release the embedded runner assets from @githolon/client 0.105.11; the pub.dev archive now carries the exact npm release stamp proved by this commit.
- Restaged with the current kernel candidate: regenerated vendored assets (kernel release identity is baked into them). Published pub.dev archives are immutable, so regenerated bytes ride their own version.
-
0.63.4710 Aug 2026Release notes
Open source →- Rebuild and release the embedded runner assets from @githolon/client 0.105.9; the pub.dev archive now carries the exact npm release stamp proved by this commit.
- Consume
nomos_client0.64.25 and rebuild the embedded runner, keeping the Flutter host on the same immutable runtime bytes as the generated Dart client.
-
0.63.4510 Aug 2026Release notes
Open source →- Rebuild and release the embedded runner assets from @githolon/client 0.105.7; the pub.dev archive now carries the exact npm release stamp proved by this commit.
- Restaged with the current kernel candidate: regenerated vendored assets (kernel release identity is baked into them). Published pub.dev archives are immutable, so regenerated bytes ride their own version.
-
0.63.4409 Aug 2026Release notes
Open source →- Rebuild and release the embedded runner assets from @githolon/client 0.105.6; the pub.dev archive now carries the exact npm release stamp proved by this commit.
- Make the clean-checkout native release proof self-contained: the gate now hydrates the exact content-addressed Apple candidate when the ignored local build tree is absent, then verifies and links that candidate before exercising the CO2 custody handoff.
-
0.63.3907 Aug 2026Release notes
Open source →- THE OWNER CAN NUKE LOCAL CUSTODY — an inoperable app is not an acceptable resting state. The
startup failure surface now offers "Reset local data and retry": it QUARANTINES this device's
snapshot cache (never deletes it) and re-opens, so custody is re-cloned from the cloud. Device
authority is untouched and any un-synced local work stays on disk for recovery. This exists because
a user staring at a screen that will not open needs a route back to a working application that is
not "delete the app and reinstall", and because we cannot promise we will never ship a state the
app cannot digest.
FileSnapshotStoregainspurgeAll(); the web store REFUSES loudly rather than silently purging nothing (quarantine there needs IndexedDB key enumeration, which is not built).
- THE OWNER CAN NUKE LOCAL CUSTODY — an inoperable app is not an acceptable resting state. The
startup failure surface now offers "Reset local data and retry": it QUARANTINES this device's
snapshot cache (never deletes it) and re-opens, so custody is re-cloned from the cloud. Device
authority is untouched and any un-synced local work stays on disk for recovery. This exists because
a user staring at a screen that will not open needs a route back to a working application that is
not "delete the app and reinstall", and because we cannot promise we will never ship a state the
app cannot digest.
-
0.63.3807 Aug 2026Release notes
Open source →- THE STARTUP DEADLINE MEASURES A STALL, NOT THE WHOLE CEREMONY. It was armed ONCE for all of
startup, so a FIRST open — the one path that must do the expensive work — died on the clock while
it was visibly progressing, and the retry restarted that same work from the top, so it never
converged. A first open has no local custody: the device clones the ledger and verifies the chain
from genesis (measured on an iPad 2026-08-07:
restore_main8.2s, of which 8.08s is chain replay across ~40 intents), then materialises genesis and enrols the device. Every subsequent open imports the checkpoint in ~0.3s. The deadline now re-arms on each phase transition — progress resets it — so a startup that stops advancing still fails loudly and typed, naming the phase it died in, while one that is genuinely working is left alone.
- THE STARTUP DEADLINE MEASURES A STALL, NOT THE WHOLE CEREMONY. It was armed ONCE for all of
startup, so a FIRST open — the one path that must do the expensive work — died on the clock while
it was visibly progressing, and the retry restarted that same work from the top, so it never
converged. A first open has no local custody: the device clones the ledger and verifies the chain
from genesis (measured on an iPad 2026-08-07:
-
0.63.3707 Aug 2026Release notes
Open source →- A FAILED BOOT REFUSES AS ITSELF — a transient fault can no longer destroy good local custody.
0.63.36 reclassified EVERY boot failure that happened while a restore snapshot was present as
nomos.custody.snapshot_corrupt, whose recommended action is quarantine-and-reclone. Boot does network work, so a cold container or any transient fault threw the device's local custody away and forced a full re-clone — plus a foreign-source clone to satisfy the kernel's colocated reads — which is how a LOCAL-FIRST app came to hang 30s inopeningCustodyand repeat it on every retry. "Boot failed" is not evidence about the bytes on disk. Only the code that actually read those bytes may condemn them, and those sites now carry their own custody code and quarantine action. - Legacy (pre-envelope) and unstamped v2 snapshots restore normally; the workspace-mismatch guard fires only on a stamp that DISAGREES, never on an absent one.
- A FAILED BOOT REFUSES AS ITSELF — a transient fault can no longer destroy good local custody.
0.63.36 reclassified EVERY boot failure that happened while a restore snapshot was present as
-
0.63.3607 Aug 2026Release notes
Open source →- AN ESTATE CAN BE OPENED AGAIN. Opening an estate failed with "generated application cannot
identify the active 'estate' model it would supersede" — the application looking for the estate's
own installed law and finding none. The law was never missing on the cloud; the estate's LOCAL
custody had never been saved. A generated birth leaves the child resident in the shared kernel
before application code ever acquires it, and host save-all was defined as "every connected
session" — so a born-but-unopened estate was outside the definition and its custody was dropped on
every close.
Realm.snapshot(name)now exports mounted, parked, AND born-but-unopened residents, so the estate persists locally and reopens with its own law. - Durability is now acknowledged PER WORKSPACE HEAD rather than per session, so a realm holding many workspaces cannot mark one durable on the strength of another's save.
- A local snapshot that is not this workspace's is refused, not interpreted. Snapshots now carry
the workspace they belong to; restoring one into a different workspace is a typed, recoverable
custody error (
nomos.custody.snapshot_corrupt) that quarantines the bytes — never discards them — and performs one clean authenticated reconnect. A corrupt v2 envelope is likewise refused instead of being fed to the tree decoder as though it were legacy binary custody. - The kernel's colocated-read residency requirement is satisfied on the DEVICE, not just in the cloud. The rule is enforced by the kernel, so it fires identically on a phone; it had shipped with only the cloud taught to answer it, which left an estate whose history reads a catalogue unable to open on a device at all.
- Restaged with the current kernel candidate: regenerated vendored assets (kernel release identity is baked into them). Published pub.dev archives are immutable, so regenerated bytes ride their own version.
- AN ESTATE CAN BE OPENED AGAIN. Opening an estate failed with "generated application cannot
identify the active 'estate' model it would supersede" — the application looking for the estate's
own installed law and finding none. The law was never missing on the cloud; the estate's LOCAL
custody had never been saved. A generated birth leaves the child resident in the shared kernel
before application code ever acquires it, and host save-all was defined as "every connected
session" — so a born-but-unopened estate was outside the definition and its custody was dropped on
every close.
-
0.63.3507 Aug 2026Release notes
Open source →- THE SEATED BARRIER GATES WRITING, NOT OPENING. A device seating into an existing home had to prove its enrollment against cloud truth BEFORE the application would render. That proof is five attempts with 1+2+4+8s of backoff, four syncs and five remote reads — comfortably past any startup deadline when the serving container is cold, so a FRESH INSTALL reliably showed a terminal "could not open" screen over work that was still legitimately progressing. Authority gates writing; it must never gate opening. The barrier now runs in the background convergence tail: the home opens immediately, and the device still cannot author until the seat proves (typed, retryable, offers durably parked meanwhile).
- This is the same defect class as 0.63.33 and it survived that fix because 0.63.33 was verified on a device that already had custody. The path that never worked is the first open on a new device.
-
0.63.3307 Aug 2026Release notes
Open source →- THE LOCAL-FIRST GATE — a cold, slow or absent cloud can no longer stop a home
from opening. The home lifecycle used to hold the first frame until sync, a
whole-chain replay verification and parent-authority repair had all completed.
That is convergence work: it says how fresh and how provable this custody is,
not whether it may be opened — and blocking on it made a local-first app
unopenable in exactly the conditions it exists to survive. The gate now ends at
seated(identity, custody, and the right to author); the tail runs in the background behind the new REQUIREDrunConvergenceTailcallback and reports as status, never as a gate. - Journal v2.
HomeBootstrapStage.syncAttemptedmoved belowseated, so a v1 cursor at that stage — which meant "synced but NOT seated", the opposite of what the new index implies — is read down tohomeAvailablerather than trusted verbatim. Honouring it would let an upgrading device skip the seating barrier. Re-seating is an idempotent ensure, so the cost is one redundant check.
- THE LOCAL-FIRST GATE — a cold, slow or absent cloud can no longer stop a home
from opening. The home lifecycle used to hold the first frame until sync, a
whole-chain replay verification and parent-authority repair had all completed.
That is convergence work: it says how fresh and how provable this custody is,
not whether it may be opened — and blocking on it made a local-first app
unopenable in exactly the conditions it exists to survive. The gate now ends at
-
0.63.3206 Aug 2026Release notes
Open source →- A late lawful open BEATS a stale startup deadline. The startup-timeout
overlay paints over the still-mounted application scope; when the open then
completed (physical-device first opens routinely outlast the deadline), the
overlay was never cleared — a permanent "could not open" screen over a
WORKING application.
_startupCompletenow clears the deadline error and rebuilds. Diagnosed live 2026-08-07 from device telemetry: synced sites and a live estate map underneath the failure surface.
- A late lawful open BEATS a stale startup deadline. The startup-timeout
overlay paints over the still-mounted application scope; when the open then
completed (physical-device first opens routinely outlast the deadline), the
overlay was never cleared — a permanent "could not open" screen over a
WORKING application.
-
0.63.3106 Aug 2026Release notes
Open source →- THE SEATED BARRIER (architecture/seated_barrier_and_seal_obligation.md Part 3): a new REQUIRED
seatedstage in the home ceremony (HomeBootstrapStage.seated+proveSeatedonresumeHomeBootstrap). A device seating into an EXISTING home must now PROVE — by reading the cloud's canonical state, never by trusting an ack — that its signer enrollment is durably on the judging chain before the app may author sync-dependent work. A fresh offline home birth is unaffected (enrollment rides the genesis; local truth suffices — offline-first preserved). An unproven seat fails typed + retryable (NomosSeatingPendingFailure, codenomos.client.seating_pending) and resumes at the barrier. This closes the 2026-08-06 class of loss where work signed by a not-yet-durably-enrolled key was doomed at the shared gate.
- THE SEATED BARRIER (architecture/seated_barrier_and_seal_obligation.md Part 3): a new REQUIRED
-
0.63.3006 Aug 2026Release notes
Open source →NomosHomeSetupFailure.toString()now includes the underlyingtechnicalDetailinstead of only a generic recommended-action sentence — a real error visible on screen, not a dead-end "try again" (diagnosed live 2026-08-06 against build 1178's smoke gate, which surfaced only the generic message for a genuine, specific failure).- Picks up
@githolon/client'sensureParentSignerEnrollmentrouting fix (this same session): the existing-home device-recovery fallback added in 0.63.29 was itself blocked by a separate routing bug that failed before ever reaching the (already-handled) security refusal — verified live, the fallback now actually runs end-to-end.
-
0.63.2906 Aug 2026Release notes
Open source →- Fix a genuine device-loss dead end: a founded receiving group whose one enrolled device is
lost had NO lawful recovery lane (every enrolment door correctly refuses). Repeating birth is
a side door the additional-device policy isn't wired to (a real gap — flagged for a proper
kernel-level closure, see
architecture/guardian_device_recovery.md) but is the only way a genuinely locked-out owner recovers today;seatDeviceInExistingHomenow falls back to it, scoped to exactly the namedreceiving-group-additional-device-requires-current-device-or-guardianrefusal so a healthy home's security posture is unaffected.
- Fix a genuine device-loss dead end: a founded receiving group whose one enrolled device is
lost had NO lawful recovery lane (every enrolment door correctly refuses). Repeating birth is
a side door the additional-device policy isn't wired to (a real gap — flagged for a proper
kernel-level closure, see
-
0.63.2706 Aug 2026Release notes
Open source →- Rebuild and release the embedded runner assets from @githolon/client 0.105.1; the pub.dev archive now carries the exact npm release stamp proved by this commit.
- Raise the generated model-adoption retry budget from 4 to 12 governed steps. A long-lived workspace with several unresolved model-lifecycle generations backlogged could exhaust the fixed 4-attempt budget before every domain's adoption converged, even though each individual step was succeeding.
-
0.63.2605 Aug 2026Release notes
Open source →- Rebuild and release the embedded runner assets from @githolon/client 0.105.0; the pub.dev archive now carries the exact npm release stamp proved by this commit.
-
0.63.2505 Aug 2026Release notes
Open source →- Rebuild and release the embedded runner assets from @githolon/client 0.104.1; the pub.dev archive now carries the exact npm release stamp proved by this commit.
-
0.63.2305 Aug 2026Release notes
Open source →- Rebuild and release the embedded runner assets from @githolon/client 0.103.19; the pub.dev archive now carries the exact npm release stamp proved by this commit.
-
0.63.2205 Aug 2026Release notes
Open source →- Rebuild and release the embedded runner assets from @githolon/client 0.103.18; the pub.dev archive now carries the exact npm release stamp proved by this commit.
-
0.63.2105 Aug 2026Release notes
Open source →- Rebuild and release the embedded runner assets from @githolon/client 0.103.17; the pub.dev archive now carries the exact npm release stamp proved by this commit.
-
0.63.2005 Aug 2026Release notes
Open source →- Rebuild and release the embedded runner assets from @githolon/client 0.103.16; the pub.dev archive now carries the exact npm release stamp proved by this commit.
-
0.63.1905 Aug 2026Release notes
Open source →- Rebuild and release the embedded runner assets from @githolon/client 0.103.15; the pub.dev archive now carries the exact npm release stamp proved by this commit.
-
0.63.1805 Aug 2026Release notes
Open source →- Rebuild and release the embedded runner assets from @githolon/client 0.103.14; the pub.dev archive now carries the exact npm release stamp proved by this commit.
ApplicationModelApproval.package/.domaingain an optionaldispositionsfield;ApplicationModelDecision.accept,DomainClientModelAdoptionRequired.acceptand the generatedNomosModelAdoption.acceptall thread it through to the kernel'shistoryPreflight/promoteDomain— a tenant can now acknowledge a genuine field/aggregate removal ({"retired": [sid, ...]}) frommodel.adopt()instead of only via a raw adapter script.- Consumes
@githolon/client's fix for a compiler bug where a shared enum's cosmetic export-binding name leaked into its field's business-value-contract hash, manufacturing false-positive evolve refusals.
-
0.63.1704 Aug 2026Release notes
Open source →- Rebuild and release the embedded runner assets from @githolon/client 0.103.13; the pub.dev archive now carries the exact npm release stamp proved by this commit.
- Rebuild and release the embedded runner assets from @githolon/client 0.103.13, resolving private framework routes from custodied law and governing installed-but-not-current application model adoption.
- Consume
nomos_client 0.64.14with the matching generated application lifecycle.
-
0.63.1603 Aug 2026Release notes
Open source →- Rebuild and release the embedded runner assets from @githolon/client 0.103.12; the pub.dev archive now carries the exact npm release stamp proved by this commit.
- Ship the coherent
3c5ea6976ea135dfee7d2dbe41f43a715c78eeb69dacdf185ab85dbc392e49c3kernel and runner, preserving semantic cross-workspace residency across independently resealed replicas. - Consume
nomos_client 0.64.13with the matching typed state-position protocol.
-
0.63.1503 Aug 2026Release notes
Open source →- Rebuild and release the embedded runner assets from @githolon/client 0.103.11; the pub.dev archive now carries the exact npm release stamp proved by this commit.
- Consume
nomos_client 0.64.12, preserving clean resident unborn workspaces between genesis and their first durable push while keeping failed cold mounts retryable.
-
0.63.1302 Aug 2026Release notes
Open source →- Rebuild and release the embedded runner assets from @githolon/client 0.103.10; the pub.dev archive now carries the exact npm release stamp proved by this commit.
- Persist every connected home, catalogue, data-profile and estate holon from the process-wide native plane, allowing the next launch to restore each opaque local custody snapshot instead of downloading and replaying its full cloud history. Ordinary projection metrics now inspect only their routed workspace.
- Consume
nomos_client 0.64.10with the matching generated runner custody.
-
0.63.1102 Aug 2026Release notes
Open source →- Rebuild and release the embedded runner assets from @githolon/client 0.103.9; the pub.dev archive now carries the exact npm release stamp proved by this commit.
- Consume
nomos_client 0.64.8so periodic metrics refreshes do not fan out unchanged aggregate application status or rebuild tenant UI while preserving seeded status for newly attached listeners.
-
0.63.1002 Aug 2026Release notes
Open source →- Rebuild and release the embedded runner assets from @githolon/client 0.103.8; the pub.dev archive now carries the exact npm release stamp proved by this commit.
- Ship the bounded generated application lifecycle and typed custody failure surface with the coherent
171bd538ffccfbf248b2b25962d44676cf78466d5da2dfa32c8618ba5f38bf45kernel. - Retain verified cold-start state, serve cloud cold packs from custody and wait for installed read readiness before presenting a generated application as ready.
-
0.63.902 Aug 2026Release notes
Open source →- Rebuild and release the embedded runner assets from @githolon/client 0.103.7; the pub.dev archive now carries the exact npm release stamp proved by this commit.
- Add an exact, fail-closed application model adoption policy for governed tenant law changes.
-
0.63.802 Aug 2026Release notes
Open source →- Rebuild and release the embedded runner assets from @githolon/client 0.103.6; the pub.dev archive now carries the exact npm release stamp proved by this commit.
-
0.63.702 Aug 2026Release notes
Open source →- Consume
nomos_client 0.64.6, whose published archive now matches the generated application lifecycle and typed operation surface compiled by this release. - Fail coordinated publishing when an existing pub.dev archive differs from the package source instead of silently accepting the occupied version.
- Consume
-
0.63.601 Aug 2026Release notes
Open source →- Consume
nomos_types 0.8.3throughout the coordinated Flutter release. - Ship the coordinated typed kernel candidate across native Apple, Web and cloud runtimes, with nominal protobuf operations and USDA custody replacing string-dispatched framework calls.
- Preserve typed kernel refusals through application startup so missing governance law cannot be hidden by a compiled fallback or an indefinite loading state.
- Consume
-
0.63.531 Jul 2026Release notes
Open source →- Bound generated application startup to 45 seconds across identity credentials, home custody and typed
client binding. A stalled phase now reaches the tenant error surface as
NomosApplicationStartupTimeoutinstead of leaving an immortal loading indicator. - Keep one process-wide native kernel plane across generated application scopes. Logout/login and widget reattachment now reuse live custody and compiled plans instead of racing multiple workers against the native singleton; a persisted snapshot seeds only a cold workspace and can never replace a resident one.
- Expose stable authentication, custody-opening, application-binding and ready phases on generated Flutter applications, with an actionable loading surface and retry control supplied by default.
- Bound generated application startup to 45 seconds across identity credentials, home custody and typed
client binding. A stalled phase now reaches the tenant error surface as
-
0.63.430 Jul 2026Release notes
Open source →- Coalesce identical home connection requests onto one in-flight open while serializing real credential changes on the same native kernel, preventing rebuilds from duplicating home ceremonies or engine boots.
- Deliver native JavaScriptCore replies through the push channel instead of re-evaluating settled values, removing the post-offer crash on the production Apple path.
-
0.63.330 Jul 2026Release notes
Open source →- Cross the one-time USDA custody boundary without restoring pre-USDA local snapshots, while retaining the device identity and re-running the normal offer-gated home availability and birth ceremony.
- Leave the old snapshot bytes untouched for forensic recovery; future cloud releases are separately blocked unless the candidate kernel can mount, replay and read every retained live workspace.
-
0.63.230 Jul 2026Release notes
Open source →- Ship the coherent USDA-native kernel candidate across Apple, web and test-mint runtimes, with immutable kernel identity checks and native typed offer/read boundaries.
- Preserve lawful first-run workspace birth when the typed kernel reports that a birth certificate must be signed, while leaving every other typed refusal intact.
-
0.63.123 Jul 2026Release notes
Open source →- Run the generated application against the release-pinned external kernel while retaining that verified runtime for offline restart; a fresh-but-wrong local cache is replaced instead of silently reused.
- Restore application-scale snapshots through the native bulk byte codec, avoiding multi-gigabyte temporary JavaScript allocations for large offline replicas.
- Ship the coordinated Nomos client which understands complete OpenUSD application placement and framework-owned recovery of home and business-child workspaces.
-
0.63.022 Jul 2026Release notes
Open source →- Mount the generated domain application as the one Flutter application state. Product code supplies sign-in
and business facts, then calls intent-shaped actions such as
commissionAsset; framework runtime hosts, repositories and serialization helpers are no longer alternate public lanes. - Carry typed
NomosRef<T>identities across WebView/WASM snapshots and the production Apple kernel, while Nomos privately seals owned fields and restores their custody after process restart. - Add a packed clean-room release gate covering blank-project generation, CO2 multi-record intent fanout, offline merge and replay, macOS native handoff, Flutter analysis/tests and the release web build.
- Mount the generated domain application as the one Flutter application state. Product code supplies sign-in
and business facts, then calls intent-shaped actions such as
-
0.62.319 Jul 2026Release notes
Open source →- Fetch the hash-pinned Apple framework during CocoaPods installation without embedding it in the pub package. Its libuv and uvwasi inputs are now source-pinned, every object targets macOS 11 or earlier, and macOS consumers are explicitly Apple Silicon until an equivalent Intel kernel exists.
- Document the executable-free package boundary: Android and web fetch, verify and retain the immutable kernel on first use; Apple fetches the same release identity while assembling the application.
-
0.62.219 Jul 2026Release notes
Open source →- Keep the kernel executable out of the pub/npm-facing Flutter package. The runner carries only the production + dev-test release descriptors; Android/WebView and Flutter web acquire the exact immutable artifact by digest, verify it, and retain it in framework-owned custody for later offline process restarts.
- Permit compatible old and new kernel digests during gradual rollout by checking the active law against both client and cloud capability sets; an incapable app fails before opening custody with an upgrade action.
- Ship resumable home bootstrap/recovery and truthful automatic parent-first sync. A clean CO2 release build proves offline writes, process restart, generated conflict merge, reconnect convergence and cold replay.
-
0.62.119 Jul 2026Release notes
Open source →- Keep parent-before-child custody ordering inside Nomos: an offline-born child remains retryable framework work until its parent birth reaches custody, instead of exposing a transient lifecycle state as a business refusal or requiring application-driven sync.
- Make sync status fail closed when the local frontier cannot be proved, and rebuild the bundled JavaScript runner so Flutter applications cannot report green before acknowledged work is remotely readable.
-
0.62.019 Jul 2026Release notes
Open source →- Release the full business-first model surface as one Flutter runtime: aggregate conflict policy, deterministic schema evolution, recursive organisation descriptions and generated business clients.
- Rebuild the JavaScript runner and Apple native framework from the same current kernel as cloud/web. Release checks now require Dart versions, dependency floors, runner assets, native pins and kernel inputs to move together, closing the package-skew failure that exposed cryptographic internals to application developers.
-
0.61.317 Jul 2026Release notes
Open source →- Ship the exact verified-birth kernel now deployed by cloud and web (
d8ee1a70fdaa…) in the Apple xcframework. Cloud deployment, the served wasm, native source identity and both podspec pins now agree; the published client cannot silently run the older pre-lineage kernel.
- Ship the exact verified-birth kernel now deployed by cloud and web (
-
0.61.217 Jul 2026Release notes
Open source →- Ship the framework-owned birth-lineage ceremony used by the headless harness and the corrected kernel verifier for a root-signed, one-link platform parent. Application code remains one business birth; signer enrollment, delegation, attestation, warrant ordering and certificate retries stay internal.
-
0.61.117 Jul 2026Release notes
Open source →- Reject a malformed birth certificate chain at the parent admission gate before any birth record or child custody can land. The Apple framework is rebuilt from that exact kernel, keeping native replay identical to cloud and web admission.