NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
pub.dev
Drive the real Nomos Peer Office from a Flutter app. Apple runs the shared Peer Office in JavaScriptCore over its release-linked native AOT kernel; WASM peers execute the same typed runtime contract with their own shell. Write TypeScript domains, get a typesafe Dart client, build Flutter widgets.
Last release today
05 Oct 2026
Ships fairly regularly
a new release about every 8 days
Nearly every release is documented
notes for 60 of the last 60 stable releases
1 version withdrawn
withdrawn after publishing
3 months old
162 releases · first in 2026
One column per month.
Rebuild and release the embedded runner assets from @githolon/client 0.103.16; the pub.dev archive now carries the exact npm release stamp proved by t
Rebuild and release the embedded runner assets from @githolon/client 0.103.15; the pub.dev archive now carries the exact npm release stamp proved by t
Rebuild and release the embedded runner assets from @githolon/client 0.103.14; the pub.dev archive now carries the exact npm release stamp proved by t
ApplicationModelApproval.package/.domain gain an optional dispositions field; ApplicationModelDecision.accept, DomainClientModelAdoptionRequired.accept and the generated NomosModelAdoption.accept thread it through the current-frontier transition and promoteDomain — a tenant can acknowledge a genuine field/aggregate removal ({"retired": [sid, ...]}) from model.adopt() instead of only via a raw adapter script.@githolon/client's fix for a compiler bug where a shared enum's cosmetic export-binding name leaked into its field's business-value-contract hash, manufacturing false-positive evolve refusals.Rebuild and release the embedded runner assets from @githolon/client 0.103.13; the pub.dev archive now carries the exact npm release stamp proved by t
nomos_client 0.64.14 with the matching generated application lifecycle.Rebuild and release the embedded runner assets from @githolon/client 0.103.12; the pub.dev archive now carries the exact npm release stamp proved by t
3c5ea6976ea135dfee7d2dbe41f43a715c78eeb69dacdf185ab85dbc392e49c3 kernel and
runner, preserving semantic cross-workspace residency across independently resealed replicas.nomos_client 0.64.13 with the matching typed state-position protocol.Rebuild and release the embedded runner assets from @githolon/client 0.103.11; the pub.dev archive now carries the exact npm release stamp proved by t
nomos_client 0.64.12, preserving clean resident unborn workspaces between genesis and their
first durable push while keeping failed cold mounts retryable.Rebuild and release the embedded runner assets from @githolon/client 0.103.10; the pub.dev archive now carries the exact npm release stamp proved by t
nomos_client 0.64.10 with the matching generated runner custody.Rebuild and release the embedded runner assets from @githolon/client 0.103.9; the pub.dev archive now carries the exact npm release stamp proved by th
nomos_client 0.64.8 so periodic metrics refreshes do not fan out unchanged aggregate
application status or rebuild tenant UI while preserving seeded status for newly attached listeners.Rebuild and release the embedded runner assets from @githolon/client 0.103.8; the pub.dev archive now carries the exact npm release stamp proved by th
171bd538ffccfbf248b2b25962d44676cf78466d5da2dfa32c8618ba5f38bf45 kernel.Rebuild and release the embedded runner assets from @githolon/client 0.103.7; the pub.dev archive now carries the exact npm release stamp proved by th
Rebuild and release the embedded runner assets from @githolon/client 0.103.6; the pub.dev archive now carries the exact npm release stamp proved by th
Consume nomos_client 0.64.6, whose published archive now matches the generated application lifecycle and typed operation surface compiled by this rele
nomos_client 0.64.6, whose published archive now matches the generated application lifecycle
and typed operation surface compiled by this release.Consume nomos_types 0.8.3 throughout the coordinated Flutter release.
nomos_types 0.8.3 throughout the coordinated Flutter release.Bound generated application startup to 45 seconds across identity credentials, home custody and typed client binding. A stalled phase now reaches the
NomosApplicationStartupTimeout instead of leaving an immortal loading indicator.Coalesce identical home connection requests onto one in-flight open while serializing real credential changes on the same native kernel, preventing re
Cross the one-time USDA custody boundary without restoring pre-USDA local snapshots, while retaining the device identity and re-running the normal off
Ship the coherent USDA-native kernel candidate across Apple, web and test-mint runtimes, with immutable kernel identity checks and native typed offer/
Run the generated application against the release-pinned external kernel while retaining that verified runtime for offline restart; a fresh-but-wrong
Mount the generated domain application as the one Flutter application state. Product code supplies sign-in and business facts, then calls intent-shape
commissionAsset; framework runtime hosts,
repositories and serialization helpers are no longer alternate public lanes.NomosRef<T> identities across WebView/WASM snapshots and the production Apple kernel, while
Nomos privately seals owned fields and restores their custody after process restart.Fetch the hash-pinned Apple framework during CocoaPods installation without embedding it in the pub package. Its libuv and uvwasi inputs are now sourc
Keep the kernel executable out of the pub/npm-facing Flutter package. The runner carries only the production + dev-test release descriptors; Android/W
Keep parent-before-child custody ordering inside Nomos: an offline-born child remains retryable framework work until its parent birth reaches custody,
Release the full business-first model surface as one Flutter runtime: aggregate conflict policy, deterministic schema evolution, recursive organisatio
Ship the exact verified-birth kernel now deployed by cloud and web (d8ee1a70fdaa…) in the Apple xcframework. Cloud deployment, the served wasm, native
d8ee1a70fdaa…) in the Apple
xcframework. Cloud deployment, the served wasm, native source identity and both podspec pins now agree;
the published client cannot silently run the older pre-lineage kernel.Ship the framework-owned birth-lineage ceremony used by the headless harness and the corrected kernel verifier for a root-signed, one-link platform pa
Reject a malformed birth certificate chain at the parent admission gate before any birth record or child custody can land. The Apple framework is rebu
Replace configurable home-birth profiles with one public application contract: NomosScope.home(cloud:, application:, authToken:, builder:). Nomos deri
NomosScope.home(cloud:, application:, authToken:, builder:). Nomos derives the canonical subject from the
token, discovers the active framework/home laws, and owns routing, enrollment, provenance, recovery and
persistence internally.NomosHomeSetupFailure while retaining technical detail for support.ca687c59887…) in the Apple xcframework. Dart verifies the
linked binary's full source-wasm identity at startup; CI, pub release and cloud deploy now refuse any
JavaScript/native/cloud skew. There is no engine fallback for a broken package.Bundle the one-call business birth runtime and require nomos_client 0.62.0, whose session-bound generated clients derive the verified principal automa
nomos_client 0.62.0, whose session-bound
generated clients derive the verified principal automatically.nomos_client floor ^0.61.0 (the era-0 release: signer-ready births — birthHome requires ownerKeyHash; the client auto-signs self-serve birth certs on
ownerKeyHash;
the client auto-signs self-serve birth certs on the kernel's typed refusal; follow/acquireSession
accept authorSecret for warranted locally-born children).Nothing published for this version
Nothing published for this version
Nothing published for this version
Runner assets carry the colocated attested-read fix: a generated directive's foreign read(q, {from}) now resolves from the mounted source session in-e
read(q, {from}) now resolves from the mounted source session in-engine (signed envelope, zero HTTP) — the session-alias vs workspace-name keying bug that made it fall through to a 31s HTTP fetch on Flutter. Adds fast-fail SourceSessionNotMounted. Depends on nomos_client ^0.58.0.Nothing published for this version
Pin nomos_client: ^0.56.0 (was a wider range in 0.55.8) to match the generated-client pin convention (NOMOS_CLIENT_DEP) — nomos_client 0.56.0 and nomo
nomos_client: ^0.56.0 (was a wider range in 0.55.8) to match the generated-client
pin convention (NOMOS_CLIENT_DEP) — nomos_client 0.56.0 and nomos_flutter move together.Widen the nomos_client dependency to >=0.55.0 <0.57.0 so nomos_client 0.56.0 (NomosTestCloud, typed snapshot lifecycle, projectionReadFailed) resolves
nomos_client dependency to >=0.55.0 <0.57.0 so nomos_client 0.56.0 (NomosTestCloud,
typed snapshot lifecycle, projectionReadFailed) resolves alongside nomos_flutter — the caret ^0.55.0
wrongly excluded 0.56.0, so the two could not coexist. Bundled JS runner assets are rebuilt from the
compound-key-capable @githolon/client at publish.Carry the @githolon/client fix: sync() now surfaces a typed pushError (endpoint, status, body) with pushFailed:true / stillAhead:true on a non-2xx/inv
sync() now surfaces a typed pushError (endpoint, status,
body) with pushFailed:true / stillAhead:true on a non-2xx/invalid direct offer, instead of
a silent pushed:null that hangs the app waiting on custody that never advances. Runner bundle
rebuilt. Patch bump — keeps the nomos_client: ^0.55.0 pin valid.Export NomosRefAcquire (the ref.acquire(bridge) extension) from the barrel, carrying the nomos_client 0.55.2 session-state DX: explicit workspace stat
NomosRefAcquire (the ref.acquire(bridge) extension) from the barrel, carrying the
nomos_client 0.55.2 session-state DX: explicit workspace state on listWorkspaces(), openable
born/resident refs (await outcome.bornRefs.single.acquire(bridge)), and the
NomosSession.isConnected/assertConnected() fail-at-bind guard.nomos_client: ^0.55.0 pin valid.Fix NomosScope snapshot persistence for multiple sessions: _exportAndSave now binds head()/export() to bridge.session(workspace) instead of the bare p
NomosScope snapshot persistence for multiple sessions: _exportAndSave now binds
head()/export() to bridge.session(workspace) instead of the bare plane-level calls, which
refuse "multiple sessions connected — pass session" once an estate/catalogue sibling session
mounts — previously silently stopping home snapshot persistence.Runner bundle rebuilt to carry issueDelegationCert (the public role-delegation cert lane) and the deriveWorkspaceName addressing helper reachable thro
issueDelegationCert (the public role-delegation cert lane) and the
deriveWorkspaceName addressing helper reachable through the bridge. Native kernel unchanged (efff5199).Native iOS/macOS kernel re-pinned to wasm efff5199 (delegated-authority offline births — the delegation-cert gate verifies a platform's grant to K_roo
nomos_client: ^0.55.0 floor unchanged.Native iOS/macOS kernel re-pinned to wasm f4e05b47 (the Surfaced read-collapse fix — replica as string for RFC-8785 canonicalization; byte-identity pr
nomos_client: ^0.55.0 floor.Fix: the `nomos_client` dependency floor was `^0.54.2`, not `^0.55.0` — 0.55.0 shipped with a stale floor (a release-process no-op), so a Flutter app
nomos_client dependency floor was ^0.54.2, not ^0.55.0 — 0.55.0 shipped with a
stale floor (a release-process no-op), so a Flutter app using a client generated by
@githolon/dsl 0.80.0+ (which pins nomos_client: ^0.55.0) could not pub get without an
override. Floor corrected to ^0.55.0. (A pins tripwire now ties this floor to the generated-client
floor so they can't diverge again.)Bundled runner rebuilt with the adversarial-sweep client fixes (watch rebind, DLQ salvage, self-binding enrollSigner recovery lane). nomos_client floo
nomos_client floor -> ^0.55.0; bundle stamp 0.80.0.Signer-recovery principal normalization fix (see nomos_client 0.54.1); home scope passes the canonical actor. Bundled runner rebuilt. Floors: nomos_cl
`NomosScope.home` recovers parent authority: the born+keyed fast path now verifies the stored device signer is enrolled on the configured parent (one
NomosScope.home recovers parent authority: the born+keyed fast path now verifies the stored
device signer is enrolled on the configured parent (one relation read per open) and lawfully
repairs after a parent custody rebirth — sibling births no longer refuse with an opaque gate
error on a reborn parent. Posture exposed via onParentAuthority / parentAuthorityOf; an
unreachable parent records posture and never bricks offline use. Bundled runner rebuilt
(enrollment + canAuthor ops, authz diagnosis classification).Bundled JS runner rebuilt from @githolon/client 0.77.1 — carries the version stamp the new nomos_client 0.53.0 stale-bundle boot check expects. Upgrad
nomos_client 0.53.0 stale-bundle boot check expects. Upgrading BOTH and rebuilding with
flutter clean yields a verified-fresh pair; a stale baked bundle now fails loudly at boot.The fast kernel. Native + bundled kernel re-pinned to wasm c23d07b2 — the offer-latency arc: a pooled local offer on co2-scale (3MB) law drops from ~3
payloadOmitted: true).Bundled JS runner rebuilt: offer ack decoupled from watch fan-out (watcher-count-independent ack; co2's grid-offer latency), offer span taxonomy, offe
offerPlanned timing envelope.
nomos_client floor → ^0.52.0.Native kernel re-pinned to wasm 7cfe416a (Surfaced conflicts + captured-basis + ATTRIBUTED READS — opt-in per-field author provenance; byte-identity p
nomos_client floor → ^0.51.0.Bundled JS runner rebuilt: atomic session re-open (no routable stale record mid-replace) and identity-change re-mount (new credentials on an open sess
nomos_client floor → ^0.50.0 (HarnessPhaseTimeout / phaseTimeout).Bundled JS runner rebuilt: local-only sessions no longer register cloud sync machinery (the autoSync deadlock fix). nomos_client floor → ^0.49.0 (acqu
nomos_client floor → ^0.49.0 (acquireSession).iOS/macOS native kernel re-pinned to wasm 72604ff7 (the Surfaced/captured-basis kernel, byte-identity proven) — 0.53.0's podspecs still pinned the pre
Bundled JS runtime rebuilt: the runner gains the interfaceOffer op (session-bound client preflight) and the pendingConflicts/watchPendingConflicts lan
interfaceOffer op (session-bound client
preflight) and the pendingConflicts/watchPendingConflicts lanes (Surfaced conflicts).nomos_client floor → ^0.48.0 (session-bound clients, Surfaced DX).No code change — bumps the nomos_client dependency floor to ^0.47.0 (the release that actually carries the Dart-level createWorkspace(domain: ...) sig
nomos_client dependency floor to ^0.47.0 (the release that actually
carries the Dart-level createWorkspace(domain: ...) signature; 0.52.2 fixed the bundled JS runtime but
the corresponding nomos_client publish was missed — see nomos_client 0.47.0's changelog).Fix: `createWorkspace` hardcoded `domain: "workspaces"`, so a tenant birthing through their OWN platform's custom law (e.g. a birthEstateWorkspace dir
createWorkspace hardcoded domain: "workspaces", so a tenant birthing through their OWN
platform's custom law (e.g. a birthEstateWorkspace directive under a co2_platform domain) was refused
by the kernel: the sealed intent always claimed domain: "workspaces" regardless of which law actually
declared the directive. Added a domain parameter (default "workspaces", fully back-compatible) to
NomosBridge.createWorkspace and the underlying @githolon/client createWorkspace/runner handler; call
bridge.createWorkspace(domain: 'co2_platform', directiveId: 'birthEstateWorkspace', domainHash: ..., ...)
to birth through a custom platform law. Regression added proving the parameter reaches the signer (a
domain the workspace doesn't declare is correctly refused BY NAME, never silently dropped to
"workspaces") and that the no-domain default is unchanged.Fix: the 0.52.0 pub artifact embedded a STALE (pre-compact) native framework, defeating the kernel_sha pin — CocoaPods skipped the fetch because Frame
macos/Frameworks/ was missing from .pubignore while
ios/Frameworks/ had it). Fixed the asymmetry, removed the stale local artifact, and HARDENED both
podspecs: prepare_command now stamps the fetched kernel_sha and re-fetches whenever the stamp disagrees
with the pin, instead of trusting bare directory presence. Added native/check_release_framework.sh — a
release-gate script (no embedded Frameworks/ + the pinned runtime URL actually serves the expected
compact-era parser marker) to run before every future dart pub publish.createWorkspace/shareWith runner handlers forgot to await the (async) connected-holon lookup
(need(a) is async; the handler used the unresolved Promise, so typeof h.createWorkspace was always the
string for "undefined", failing every estate-creation call with "connected holon does not expose
createWorkspace()" even on a correct kernel). Fixed at the source
(cloud/web-client/src/webview-runner.mjs) and rebundled into both assets/nomos-native.js and
assets/nomos-runner.js.Native kernel resync (COMPACT-CAPABLE). The bundled NomosKernel.xcframework is rebuilt from kernel 7394d6fe (compact-native, 2026-07-07) — the SAME by
7394d6fe (compact-native, 2026-07-07) — the SAME bytes the cloud runs. Fixes: the native macOS/iOS
runtime could not open a workspace whose lineage (active OR superseded) contains a compact-era
package — it rejected the then-current package encoding. The prior published native kernel
(891bad48, 2026-07-04) predated compact support; the Dart wrapper had advanced without resyncing the AOT.kNativeKernelSha) + the fix
(upgrade nomos_flutter / rebuild), with code nomos.native.stale-kernel — never a cryptic field name.
Requires nomos_client >= 0.46.0. Rebuild your app so the podspec pulls the new xcframework.NomosScope / NomosScope.home expose onCustodyBreak (a CustodyBreakPolicy) for the FIRST workspace mount — plug-and-play rebirth handling (co2 feedback
NomosScope / NomosScope.home expose onCustodyBreak (a CustodyBreakPolicy) for the FIRST
workspace mount — plug-and-play rebirth handling (co2 feedback). Threaded scope → home scope →
bridge.connect; the barrel re-exports CustodyBreakPolicy/NomosCustodyBreak/NomosCustodyStatus/
NomosCustodyEvent so apps need no direct nomos_client import. Null keeps the fail-closed default
(typed break, never silent adoption/loss). Requires nomos_client >= 0.46.0.Bundles the current @githolon/client runner: bridge.attestedRead(from: ) now resolves IN-PLANE from a colocated local-only workspace (the explicit API
@githolon/client runner: bridge.attestedRead(from: <sibling>) now resolves IN-PLANE from a colocated local-only workspace (the explicit API shares the offer-path colocation resolver) — a cross-workspace local read no longer fails attested-read-unreachable/no active installed law declares that query. Pairs with nomos_client ≥0.41.0.Your coding agent can read these notes before it upgrades. Set up the MCP server →