NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
pub.dev
Drive the real Nomos Peer Office from a Flutter app. Apple runs the shared Peer Office in JavaScriptCore over its release-linked native AOT kernel; WASM peers execute the same typed runtime contract with their own shell. Write TypeScript domains, get a typesafe Dart client, build Flutter widgets.
Last release 2 days ago
05 Oct 2026
Ships fairly regularly
a new release about every 8 days
Nearly every release is documented
notes for 60 of the last 60 stable releases
1 version withdrawn
withdrawn after publishing
3 months old
162 releases · first in 2026
One column per month.
NATIVE REALM MIGRATION: the native (dart:ffi) path now runs the SAME shared runner + realm plane every other host runs (createWebviewRunner over openR
createWebviewRunner over openRealm with a native FFI engine plane) — the hand-rolled native ops table and session map are deleted, so the native op surface can no longer drift. This brings the native path: the 11 previously-missing ops (dead-letters, the crypto/E2E surface, checkCompat/compatHas, pull, manifests, …), per-session lawChanged forwarding (compat live-events now work natively), locally-born children opening IN-PLACE, in-plane colocated attested reads, and LRU park/remount (connect(maxMounted: …)), all conformance-tested on macOS. Pairs with @githolon/client 0.60.0 (the bundled runner).x-nomos-auth never rides another session's cloud traffic. The holon's own per-session headers are authoritative on fetches (parity with the WebView/web paths); the pack byte-shuttle and the doorbell WebSocket resolve THEIR session's credential. Conformance: test/native_multisession_auth_test.dart (a loopback fake cloud records auth per request; a tokenless session must not inherit a sibling's token).FIX (native multi-session regression): the native (dart:ffi) transport now retains EVERY connected session. Previously a second bridge.connect(workspa
bridge.connect(workspace:…, session:…) re-booted the single global kernel, replaced the JS engine, and overwrote the singleton workspace placement — listWorkspaces() showed only the latest session and earlier sessions failed session '…' is not connected. The engine now boots ONCE and keeps a per-session placement map (kernel calls, ws files, git tree, restore staging, pack apply, export all route by the session key native-entry stamps on every provider message), and connect forwards session to the runner.cloud) works on the native path — the local:// sentinel never touches dart:io networking (the workspace-status probe answers unborn locally, parity with the node runner's offline lane), and connect no longer requires a cloud argument.test/native_multisession_test.dart, macOS): home connect → sibling connect → listWorkspaces contains both → home query + pre-existing watch still answer → child query/watch works. Runs under plain flutter test against the repo-built kernel slice via the new native/build_test_dylib.sh (the static macos-arm64 slice linked as a loadable test dylib).Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Depend on nomos_client ^0.32.0 — spatial reads (NomosBbox, spatialWithin, watchSpatial) reach app clients; pairs with the ≥0.46 compiler wave (semanti
nomos_client ^0.32.0 — spatial reads (NomosBbox, spatialWithin, watchSpatial) reach app clients; pairs with the ≥0.46 compiler wave (semantic enum names, analyzer-clean output, all-creates proofs with spatial membership).Depend on nomos_client ^0.31.0 — pairs with the 0.42/0.43 compiler wave: the runtime aggregate-meta registry (NomosAggregateMeta/NomosFieldMeta incl.
nomos_client ^0.31.0 — pairs with the 0.42/0.43 compiler wave: the runtime aggregate-meta registry (NomosAggregateMeta/NomosFieldMeta incl. fromBirth), variant() sealed unions, unit() extension types, idOf() typed ids, fromBirth() non-nullable read models, and copyWith on generated VO/arm classes. Recompile domains with @githolon/dsl ≥0.43 tooling.Depend on nomos_client ^0.29.0 — the headless test lane (NodeRunnerTransport + NomosTestHarness in package:nomos_client/nomos_headless.dart) and the l
nomos_client ^0.29.0 — the headless test lane (NodeRunnerTransport + NomosTestHarness in package:nomos_client/nomos_headless.dart) and the law-minted-id offer surface (offerCreates/mintId) are available to app test suites; flutter test drives the real githolon with no plugins/WebView (proof: test/headless_transport_test.dart).WEB SUPPORT: nomos_flutter now compiles and runs on Flutter web. The browser is itself a JS/wasm host, so web uses NO dart:ffi and NO WebView — a new
dart:js_interop transport (web_transport.dart) loads the same @githolon/client browser runner (nomos-runner.js) in-page and drives it over the identical NomosBridge wire. Platform selection is via conditional imports (engine_host.dart), so dart:ffi/flutter_js/flutter_inappwebview never enter the web graph; native (iOS/macOS AOT) and Android (WebView) paths are unchanged. Web persistence (snapshots + device keys) is backed by IndexedDB (async, large-capacity) — NOT localStorage — so a durable save never blocks the main thread or hits the ~5MB cap. Proven end-to-end against the live cloud: connect, ledger clone, offline write → edge admission → main, undo/redo (kernel strike), history, and the profiler flame chart all run in-browser. (Known follow-up: on very large ledgers the runner runs on the single JS thread; a Web Worker host is future work.)macOS NATIVE: macOS now runs the native-AOT kernel (the macos-arm64 slice of the same xcframework iOS uses) instead of the WebView engine — faster, no
_nativeEngine now covers iOS+macOS by default; set NOMOS_FORCE_WEBVIEW=1 to opt back to WebView on macOS. After upgrading: cd macos && pod install. Android stays on the WebView engine.TYPED SNAPSHOT RECOVERY: a corrupt local snapshot is no longer lose-it-or-keep-a-broken-app. Connect with recover: true (via the bridge) to recover IN
recover: true (via the bridge) to recover IN-PLACE — salvage local-only writes + DLQ from the corrupt snapshot, refold fresh from cloud, re-offer the salvaged work. NomosClient.recovery → {salvagedWrites, requeuedDeadLetters, unsalvageable} (unsalvageable = writes the current law refused — kept in the DLQ, never dropped). Quarantine-then-recover becomes one connect. Same kernel (the salvage verbs were already fallible — no deploy).TIER-2 SYNC SIZE (aggregate-before-download): NomosClient.syncSize() → {bytes, kind} via a HEAD on the serving pack (host answers Content-Length, no b
NomosClient.syncSize() → {bytes, kind} via a HEAD on the serving pack (host answers Content-Length, no body, cached ~15s). Sum across your open workspaces to show "X MB to sync" BEFORE any download starts; per-workspace transferProgress (0.35) then fills the bar. Host endpoint live (HEAD /v2/workspaces/:ws/pack). Same kernel.SYNC-STATE UI + REAL LOADING BARS (tier 1): NomosClient exposes syncStatus (truthful aggregated state), transferProgress (live pack byte-progress), cu
NomosClient exposes syncStatus (truthful aggregated state), transferProgress (live pack byte-progress), currentStatus. The native pack shuttle streams the response + emits {received,total,kind} from the host Content-Length (the warm host packs then sends, so the real total is in the headers before the body) — real 0→100ars, never estimated. Drive a sync-state page off nomos.syncStatus. See co2-handover/SYNC_STATE.md (incl. the tier-2 HEAD /pack aggregate-size spec).NATIVE LOCAL WORKSPACE CREATION FIXED: the iOS AOT kernel now uses uvwasi for its filesystem syscalls instead of the incomplete hand-rolled wasi shim.
init a fresh LOCAL workspace on device (the birthEstateWorkspace "Unreachable instruction" trap is gone) — estates/sites/assets all init locally, offline-first, then sync. Same canonical kernel wasm (07929c03); only the per-platform wasi provider changed. Determinism preserved: clock/random stay pinned to constants (the kernel takes time/entropy from captured ports), proven byte-identical (b6fea50e). REQUIRES re-fetching the kernel xcframework: rm -rf ios/Frameworks/NomosKernel.xcframework && pod install.STRICT device-binding for keyless onboarding: NomosScope.home gains authTokenForDevice(devicePublicKey) => Future . The ceremony mints the device key
NomosScope.home gains authTokenForDevice(devicePublicKey) => Future<String>. The ceremony mints the device key FIRST, then calls back for an IdP token whose nonce == sha256(pubkey) (e.g. a Firebase Cloud Function that mints a device-bound custom token). Overrides the static authToken (the relaxed lane). Needed when the parent AuthProvider sets requireDeviceBinding:true. Same kernel (07929c03). See co2-handover/STRICT_FIREBASE.md.KEY-FREE GOVERNANCE: createWorkspace / shareWith (and NomosBridge) default authorSecret to the connection's signing key — the home device key NomosSco
createWorkspace / shareWith (and NomosBridge) default authorSecret to the connection's signing key — the home device key NomosScope.home already loaded. A frontend dev never handles a key to make a workspace or share it. Same kernel (07929c03); Dart-only.OFFLINE BIRTHS no longer trap on device: the native kernel folds the parent shallow-safe (resident frontier, never the panicking genesis walk) when ru
RECOVERY / new-device on a BORN home: NomosScope.home now enrolls THIS device on an already-born home (via the admin-delegated enrollmentGate or keyle
Re-exports nomos_client 0.23.0 (shareWith cross-custody sharing). Bumps the nomos_client floor to ^0.23.0.
shareWith cross-custody sharing). Bumps the nomos_client floor to ^0.23.0.Device key now PERSISTS: NomosDeviceKeyStore (authority credential, separate from the snapshot, file default + Keychain-swappable). NomosScope.home lo
NomosDeviceKeyStore (authority credential, separate from the snapshot, file default + Keychain-swappable). NomosScope.home loads it on launch, saves the minted key on first birth, and reconnects SIGNED — a born home survives a device/session change. deviceKeyStore param. Requires nomos_client ^0.22.0.Durability without the memory bomb: the durable-save-on-write now backs off adaptively (next save gated to ~4x the last save's cost) so the full-ledge
Local-first durability — a delete (or any write) now survives force-quit + reopen, and lands as a visible "saved" number. Three fixes: (1) the snapsho
syncedBase),
so restore replays the un-synced local tail instead of resetting it to cloud main (the delete-resurrection
bug); (2) the author is persisted durably OFF the author thread the instant a write seals, emitting a
persist span — the new "saved" metric (NomosScope shows ready / saved / →main); (3) a thrown converge
replay is dead-lettered, never silently dropped. NomosScope.dispose now tears down ordered (final save →
bridge dispose) — no more bridge disposed race on app close. Kernel unchanged (1249458d…). Proven on
the macOS native harness: delete → kill → reopen → still deleted.HomeBirth.enrollmentGate/HomeBirthEnrollmentEndpoint,
the signed first-birth raw fallback, and allowUnborn home scopes — see the 0.22.x entries below.Kernel pin → c8152e9d… (the GENERICISATION cloud kernel, deployed worker 15080fcf): the kernel names NO domain/directive/aggregate by ad-hoc literal —
c8152e9d… (the GENERICISATION cloud kernel, deployed worker 15080fcf): the kernel
names NO domain/directive/aggregate by ad-hoc literal — AuthProvider, the x5c rotation trigger, the
birth-cert seed, and the genesis-install primitives are first-class (kernel-owned, the law compiles to
them, drift-guarded); parent-attested birth reads its owner/cert locators from the law's declaration; the
keyless arm reads its directive + payload fields from the law. Behaviour-identical + era-safe — every live
ledger replays byte-green (verdict b6fea50e… unchanged), so this is a transparent superset of 0.24.0./v1/runtime/ios/NomosKernel-c8152e9d….xcframework.zip.rm -rf ios/Frameworks/NomosKernel.xcframework
then pod install to re-fetch.Add HomeBirth.enrollmentGate and HomeBirthEnrollmentEndpoint so a tenant can run its live device enrollment gate before the signed home-birth offer. T
HomeBirth.enrollmentGate and HomeBirthEnrollmentEndpoint so a tenant can run its live device
enrollment gate before the signed home-birth offer. This keeps device secrets local while letting the
tenant verify Firebase/AuthProvider identity and record the parent signer/delegation facts.@githolon/client 0.24.10, including x-nomos-auth forwarding
for the first-birth raw signed fallback.Rebuild the embedded runner assets with the first-birth signed raw fallback. When the home bridge is still unborn/lawless and cannot locally seal home
home/birthHome, NomosScope.home now sends the parent birth payload
with the minted device key for the kernel author door.Rebuild the embedded runner assets with the signed-author home-birth fix. NomosScope.home now seals the parent home/birthHome offer locally with the m
NomosScope.home now seals the
parent home/birthHome offer locally with the minted device key and relays opaque intentBytes, so warranted
platform workspaces no longer reject first-launch home birth for missing authorSecret.Rebuild the embedded runner assets with the first-birth lawless-home enrollment fix. NomosScope.home no longer fails before the parent birthHome offer
NomosScope.home
no longer fails before the parent birthHome offer when the home has not yet installed its law.Rebuild the embedded runner assets with allowUnborn forwarding in the native and WebView entrypoints. This is the patch that makes NomosScope.home's u
allowUnborn forwarding in the native and WebView entrypoints.
This is the patch that makes NomosScope.home's unborn-home first launch work through the published
Flutter package.Rebuild the embedded @githolon/client runner assets with the home-birth custody-head race fix. The birthHome ceremony now waits for the born home to h
@githolon/client runner assets with the home-birth custody-head race fix. The
birthHome ceremony now waits for the born home to have a ledger head before peer verification, and the
ceremony's HTTP calls use the native injected transport.NomosScope.home now passes the bridge's unborn-home opt-in before running the birth ceremony. This fixes the iOS/native first-launch failure where con
NomosScope.home now passes the bridge's unborn-home opt-in before running the birth ceremony. This fixes
the iOS/native first-launch failure where connect threw workspace '<home>' has no ledger main before
birthHome could create and verify the home. Plain NomosScope remains strict.nomos_client: ^0.20.2.Structured Nomos runtime failures. NomosNativeTransport now preserves { error, errorInfo } from the shared runner/provider boundary instead of collaps
NomosNativeTransport now preserves { error, errorInfo } from the
shared runner/provider boundary instead of collapsing failures to strings, including provider, fetch,
kernel-call, watch, and auto-sync paths.wasm_rt_trap failures around nomos_call and returns
nomos.native.wasm_trap as structured JSON instead of aborting the app process. The hash-pinned
NomosKernel-04a04ef3....xcframework.zip runtime artifact has been rebuilt and uploaded.nomos_client: ^0.20.1.Native/WebView microtask shim. Bare JavaScriptCore in the iOS flutter_js path does not expose queueMicrotask, but the shared @githolon/client orchestr
flutter_js path does not expose
queueMicrotask, but the shared @githolon/client orchestration uses it for process.nextTick and
post-offer warm queries. The generated nomos-native.js / nomos-runner.js bundles now install a
standards-shaped queueMicrotask fallback before client code loads, so native estate/workspace offers do
not fail with Can't find variable: queueMicrotask.Publish the regenerated JS orchestration bundles from the @githolon/client 0.24.1 build. The generated nomos-runner.js / nomos-native.js assets are no
@githolon/client 0.24.1 build. The
generated nomos-runner.js / nomos-native.js assets are no longer tracked in Git; release tooling
builds them from source and includes them in the pub package, so Flutter consumers get current bytes
without CO2 carrying a local path override.Native (iOS) text-codec shim — no tenant patch needed. Bare JavaScriptCore (the flutter_js engine) has no TextEncoder/TextDecoder; the client orchestr
flutter_js
engine) has no TextEncoder/TextDecoder; the client orchestration uses them, so the native path
crashed at load and required a hand-patch. The bundled nomos-native.js now carries a pure-JS,
WHATWG-correct TextEncoder/TextDecoder (byte-identical to the platform impl, parity-tested), so
NomosScope boots on-device out of the box. The asset is now auto-synced from the build (no stale
bundle). If you carried a local native_transport.dart polyfill, you can delete it.FIX the invalid plugin spec that broke 0.16.2 on pub.dev: Android/macOS were declared with the legacy pluginClass: none, which current Flutter rejects
0.16.2 on pub.dev: Android/macOS were declared with the legacy
pluginClass: none, which current Flutter rejects. They are now correctly OMITTED from the plugin block
(consumed as a plain Dart package on those platforms; iOS keeps the native-AOT kernel plugin). 0.16.2
cannot be overwritten, so this is the corrected republish — pin ^0.17.0 (not the broken 0.16.2).nomos_client: ^0.17.0 (lockstep birth-primitive release).Restore Android + macOS support (hidden-WebView engine); iOS keeps the native-AOT kernel.
nomos_client (was nomos_dsl).Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →