NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
pub.dev
Drive the real Nomos Peer Office from a Flutter app. Apple runs the shared Peer Office in JavaScriptCore over its release-linked native AOT kernel; WASM peers execute the same typed runtime contract with their own shell. Write TypeScript domains, get a typesafe Dart client, build Flutter widgets.
Last release 2 days ago
05 Oct 2026
Ships fairly regularly
a new release about every 8 days
Nearly every release is documented
notes for 60 of the last 60 stable releases
1 version withdrawn
withdrawn after publishing
3 months old
162 releases · first in 2026
One column per month.
package:nomos_flutter/testing.dart compiles for the web again (CAP-790). It exported the Apple native test peer host unconditionally, which reaches da
package:nomos_flutter/testing.dart compiles for the web again (CAP-790). It exported the Apple native test
peer host unconditionally, which reaches dart:ffi, so any Flutter web app that imported generated scenario
code (which imports testing.dart) failed dart2js with "Dart library 'dart:ffi' is not available on this
platform". Where dart:ffi does not exist, the same names now resolve to a host that cannot start:
registerNomosNativeTestPeerHost() does nothing there, so NOMOS_TEST_PEER_HOST=native is still refused
loudly by the harness, and NomosNativeTestPeerHost.start throws UnsupportedError. Native platforms are
unchanged. Native hosts stay 0.67.0 on Kernel 061cbd5b….Requires Flutter 3.41 or later (platform-scoped assets). Uses nomos_client 0.68.0 and nomos_types 0.13.0; regenerate generated clients (the law is nam
Requires Flutter 3.41 or later (platform-scoped assets). Uses nomos_client 0.68.0 and nomos_types 0.13.0; regenerate generated clients (the law is named by its unit set).
061cbd5b… and its stage-zero law 0419d015…, the
Kernel the dev cloud runs.nomos_background_paper_abandoned (CAP-694, CAP-695).--dart-define=NOMOS_TRACE=true writes an opt-in [nomos-trace] timeline across the save path (CAP-741).sealed_main reports what is durable. Only a sealed main advances the saved
recovery bookmark; after a reconnect the unsealed offers are offered again.LiveLinkClosure,
PeerSocketReceipt.closure).lawUnitSet and
lawPackageSha256 in place of applicationBirthContract, offers carry no law expectation, and a
provider-token Home is born under the law the platform serves.shorebird patch needs no --allow-asset-diffs.Web: a peer that boots before the application attaches (a prewarmed peer) no longer loses its readiness announcement. The page holds runtime events un
flushReady, then delivers them in order;
0.66.x could leave the application unable to open after a reload, a navigation or a browser restart.drive() turn re-reads one owed query group
and still runs maintenance, so live streams and readiness keep advancing during a cold start (0.66.3 regression).Watches refresh after a write on iOS and Android again. 0.66.0–0.66.2 deferred watch re-reads with a timer the native JavaScript engines do not have,
drive() turns on every platform (CAP-687).URL global, which neither native engine provides.nomos_background_paper_abandoned, instead of holding its workspace for five minutes (CAP-695).A browser peer waits for a custody lock another page holds only when its page is a reload or back/forward navigation (its predecessor may still be rel
Ship the stage-zero bootstrap law (a11b0f52…) that a clean checkout reproduces. 0.66.0 carried a law whose bundled runtime comments named the build ma
a11b0f52…) that a clean checkout reproduces. 0.66.0 carried a law whose bundled
runtime comments named the build machine's node_modules path, so the release workflow could not reproduce it.
The Kernel is unchanged (69e87227…); only the law's comments differ.NomosPeerRuntimeHost.prewarm(cloud:) starts a Flutter web peer's boot (worker, custody restore, kernel selection and compile) at application launch, b
NomosPeerRuntimeHost.prewarm(cloud:) starts a Flutter web peer's boot (worker, custody restore, kernel selection and
compile) at application launch, before sign-in; the application's transport shares that boot.nomos-runner-web.js?v=<sha>,
nomos-runner-worker.js?v=<sha>), so hosts may cache them immutably and a deploy never pairs stale assets.69e87227… and its stage-zero law e45e6dd8…, the
Kernel the cloud and browser select.runtime/interface-offer.cbor), so peers composed it instead of mounting it.Bind Apple and Android native distributions to the selected cloud/browser Kernel and stage-zero law. Inspect actual native archives and packaged consu
Ship browser custody checkpoint recovery, explicit Kernel repository selection, boot diagnostics and the completed socket-driven runtime; preserve loc
Fetch the current browser kernel repository and controller law without the HTTP cache, while retaining a verified Cache API copy for offline boot. Thi
Keep the browser worker alive across incomplete outbox history and unexpected background selection faults; the peer asks its shell for bounded history
Run the Flutter web peer and WASM Kernel in a dedicated Web Worker. The page carries only Runtime v2 frames, events, Flutter-owned effects and diagnos
Restaged the generated runtime bridge: a lower layer of the Dart release stack moved. Published pub.dev archives are immutable, so regenerated bytes r
Expose bounded typed Kernel work snapshots and active-call transitions in browser peers, including per-operation call, failure and synchronous wall ti
Store browser custody as bounded file and peer-record chunks in atomic IndexedDB transactions. Migrate existing format-1 workspaces without losing Git
Give every physical sync offer a unique effect identity so inline recovery and rebase can finish without repeating the same request forever. Preserve
Retry a refused physical peer startup when an application retries, replacing the failed readiness future and disposing the failed shell. Keep an estab
Keep browser Git custody and peer control records in atomic IndexedDB transactions, with one writer per origin/provider and recovery after tab termina
Add an optional, bounded client inventory reporter that consumes runtime identity reports and uses a host-supplied authenticated transport. Collection
Package the unchanged Apple native code as a static-library XCFramework, avoiding an invalid embedded framework for apps targeting newer iOS versions.
Retain the complete native host ABI in Swift Package Manager release archives so Dart FFI can resolve it after App Store export.
Recover sync after loss of the upstream bookmark by fetching provider history and allowing the kernel to verify a shared ancestor. Preserve pending lo
Pair with nomos_client 0.66.6 for bounded reception teardown.
nomos_client 0.66.6 for bounded reception teardown.Let authenticated parent-workspace cold opens use the application's bounded startup budget instead of incorrectly reporting a healthy provider as offl
Open trusted checkpoint custody without blocking foreground work on a full-history verification pass.
nomos_client 0.65.3.Resolve the current generated Nomos application call surface through nomos_client 0.65.1 while retaining the independently selected runtime kernel lif
nomos_client 0.65.1 while retaining
the independently selected runtime kernel lifecycle.Consume nomos_types 0.9.0 and nomos_client 0.65.0 so Flutter hosts use the same generated typed offer-admission ABI as the kernel and other hosts.
nomos_types 0.9.0 and nomos_client 0.65.0 so Flutter hosts use the same generated
typed offer-admission ABI as the kernel and other hosts.Declare the generated protobuf messages' direct fixnum runtime dependency so the exact qualified package passes pub.dev validation.
fixnum runtime dependency so the exact qualified package passes pub.dev validation.Expand the deterministic Pulley call-fuel envelope so authenticated first-device birth can complete, and retain the underlying Wasmtime trap reason in
Resolve the resident Pulley host from Flutter's real macOS ephemeral plugin-symlink directory, while retaining the existing iOS CocoaPods path.
Resolve, verify, and retain the provider-selected kernel through a schema-valid OSGi Repository document. The loopback broker serves only the selected
Add the Android application runner used to produce and compose deterministic CycloneDX Pub, Gradle, and CocoaPods dependency evidence for the example
Rebuild and release the embedded runner assets from @githolon/client 0.105.19; the pub.dev archive now carries the exact npm release stamp proved by t
nomos_client 0.64.34 for the corrected generated runner lifecycle.Rebuild and release the embedded runner assets from @githolon/client 0.105.18; the pub.dev archive now carries the exact npm release stamp proved by t
nomos_client 0.64.33 for progress-aware model convergence.Rebuild and release the embedded runner assets from @githolon/client 0.105.17; the pub.dev archive now carries the exact npm release stamp proved by t
Rebuild and release the embedded runner assets from @githolon/client 0.105.16; the pub.dev archive now carries the exact npm release stamp proved by t
nomos_client 0.64.32 so Flutter applications prove durable device enrolment before generated writes become available.Rebuild and release the embedded runner assets from @githolon/client 0.105.15; the pub.dev archive now carries the exact npm release stamp proved by t
nomos_client 0.64.31 so Flutter applications use the restaged, type-safe intent-offer gate and deterministic signer posture.Rebuild and release the embedded runner assets from @githolon/client 0.105.14; the pub.dev archive now carries the exact npm release stamp proved by t
Rebuild and release the embedded runner assets from @githolon/client 0.105.13; the pub.dev archive now carries the exact npm release stamp proved by t
Rebuild and release the embedded runner assets from @githolon/client 0.105.12; the pub.dev archive now carries the exact npm release stamp proved by t
nomos_client 0.64.27 so the Flutter package and its Dart runtime use
nomos.cafe as the sole default cloud surface.Rebuild and release the embedded runner assets from @githolon/client 0.105.11; the pub.dev archive now carries the exact npm release stamp proved by t
Rebuild and release the embedded runner assets from @githolon/client 0.105.9; the pub.dev archive now carries the exact npm release stamp proved by th
nomos_client 0.64.25 and rebuild the embedded runner, keeping the Flutter host on the
same immutable runtime bytes as the generated Dart client.Rebuild and release the embedded runner assets from @githolon/client 0.105.7; the pub.dev archive now carries the exact npm release stamp proved by th
Rebuild and release the embedded runner assets from @githolon/client 0.105.6; the pub.dev archive now carries the exact npm release stamp proved by th
THE OWNER CAN NUKE LOCAL CUSTODY — an inoperable app is not an acceptable resting state. The startup failure surface now offers "Reset local data and
FileSnapshotStore gains purgeAll(); the web store REFUSES loudly rather than
silently purging nothing (quarantine there needs IndexedDB key enumeration, which is not built).THE STARTUP DEADLINE MEASURES A STALL, NOT THE WHOLE CEREMONY. It was armed ONCE for all of startup, so a FIRST open — the one path that must do the e
restore_main 8.2s, of which 8.08s is chain replay
across ~40 intents), then materialises genesis and enrols the device. Every subsequent open imports
the checkpoint in ~0.3s. The deadline now re-arms on each phase transition — progress resets it —
so a startup that stops advancing still fails loudly and typed, naming the phase it died in, while
one that is genuinely working is left alone.A FAILED BOOT REFUSES AS ITSELF — a transient fault can no longer destroy good local custody. 0.63.36 reclassified EVERY boot failure that happened wh
nomos.custody.snapshot_corrupt, whose recommended action is quarantine-and-reclone. Boot does
network work, so a cold container or any transient fault threw the device's local custody away and
forced a full re-clone — plus a foreign-source clone to satisfy the kernel's colocated reads —
which is how a LOCAL-FIRST app came to hang 30s in openingCustody and repeat it on every retry.
"Boot failed" is not evidence about the bytes on disk. Only the code that actually read those bytes
may condemn them, and those sites now carry their own custody code and quarantine action.AN ESTATE CAN BE OPENED AGAIN. Opening an estate failed with "generated application cannot identify the active 'estate' model it would supersede" — th
Realm.snapshot(name) now exports mounted, parked, AND born-but-unopened residents,
so the estate persists locally and reopens with its own law.nomos.custody.snapshot_corrupt) that quarantines the bytes — never discards them
— and performs one clean authenticated reconnect. A corrupt v2 envelope is likewise refused
instead of being fed to the tree decoder as though it were legacy binary custody.THE SEATED BARRIER GATES WRITING, NOT OPENING. A device seating into an existing home had to prove its enrollment against cloud truth BEFORE the appli
THE LOCAL-FIRST GATE — a cold, slow or absent cloud can no longer stop a home from opening. The home lifecycle used to hold the first frame until sync
seated (identity, custody, and the right to author); the tail runs in the
background behind the new REQUIRED runConvergenceTail callback and reports as
status, never as a gate.HomeBootstrapStage.syncAttempted moved below seated, so a v1
cursor at that stage — which meant "synced but NOT seated", the opposite of what
the new index implies — is read down to homeAvailable rather than trusted
verbatim. Honouring it would let an upgrading device skip the seating barrier.
Re-seating is an idempotent ensure, so the cost is one redundant check.A late lawful open BEATS a stale startup deadline. The startup-timeout overlay paints over the still-mounted application scope; when the open then com
_startupComplete now clears the deadline error and
rebuilds. Diagnosed live 2026-08-07 from device telemetry: synced sites and
a live estate map underneath the failure surface.THE SEATED BARRIER (architecture/seated_barrier_and_seal_obligation.md Part 3): a new REQUIRED seated stage in the home ceremony (HomeBootstrapStage.s
seated stage in the home ceremony (HomeBootstrapStage.seated + proveSeated on
resumeHomeBootstrap). A device seating into an EXISTING home must now PROVE — by reading the
cloud's canonical state, never by trusting an ack — that its signer enrollment is durably on the
judging chain before the app may author sync-dependent work. A fresh offline home birth is
unaffected (enrollment rides the genesis; local truth suffices — offline-first preserved). An
unproven seat fails typed + retryable (NomosSeatingPendingFailure, code
nomos.client.seating_pending) and resumes at the barrier. This closes the 2026-08-06 class of
loss where work signed by a not-yet-durably-enrolled key was doomed at the shared gate.NomosHomeSetupFailure.toString() now includes the underlying technicalDetail instead of only a generic recommended-action sentence — a real error visi
NomosHomeSetupFailure.toString() now includes the underlying technicalDetail instead of
only a generic recommended-action sentence — a real error visible on screen, not a dead-end
"try again" (diagnosed live 2026-08-06 against build 1178's smoke gate, which surfaced only
the generic message for a genuine, specific failure).@githolon/client's ensureParentSignerEnrollment routing fix (this same session):
the existing-home device-recovery fallback added in 0.63.29 was itself blocked by a separate
routing bug that failed before ever reaching the (already-handled) security refusal — verified
live, the fallback now actually runs end-to-end.Fix a genuine device-loss dead end: a founded receiving group whose one enrolled device is lost had NO lawful recovery lane (every enrolment door corr
architecture/guardian_device_recovery.md) but is the only way a
genuinely locked-out owner recovers today; seatDeviceInExistingHome now falls back to it,
scoped to exactly the named receiving-group-additional-device-requires-current-device-or-guardian
refusal so a healthy home's security posture is unaffected.Rebuild and release the embedded runner assets from @githolon/client 0.105.1; the pub.dev archive now carries the exact npm release stamp proved by th
Rebuild and release the embedded runner assets from @githolon/client 0.105.0; the pub.dev archive now carries the exact npm release stamp proved by th
Rebuild and release the embedded runner assets from @githolon/client 0.104.1; the pub.dev archive now carries the exact npm release stamp proved by th
Rebuild and release the embedded runner assets from @githolon/client 0.103.19; the pub.dev archive now carries the exact npm release stamp proved by t
Rebuild and release the embedded runner assets from @githolon/client 0.103.18; the pub.dev archive now carries the exact npm release stamp proved by t
Rebuild and release the embedded runner assets from @githolon/client 0.103.17; the pub.dev archive now carries the exact npm release stamp proved by t
Your coding agent can read these notes before it upgrades. Set up the MCP server →