AnterisLab follows Semantic Versioning. Entries are grouped as Added, Changed, Fixed and Security. Security entries never disclose exploitation details before a fix is generally available.
v2.4.0 — September 13, 2026
Security · Platform · Marketing site
Added
- Footer navigation to the full documentation, trust and legal set (Blog, Documentation, Changelog, Security, Status, Compliance, About, Careers, Brand Kit, Privacy, Terms, Cookies).
- Self-hosted static pages rendered with the same design system as the marketing site.
Changed
- Marketing pages are fully self-hosted: fonts and scripts are served from
assets/anterislab-vendor/. No third-party CDN is contacted at page load.
Security
- Document-level CSP tightened to
default-src 'self';object-src,base-uriandform-actionrestricted. - Access and refresh tokens are no longer reachable from JavaScript — sessions live in
HttpOnly; Secure; SameSite=Laxcookies. - API keys are stored as salted hashes; the plaintext value is returned only once at creation.
v2.3.1 — August 30, 2026
Fixed
- Decision cache no longer returns a stale
allowafter a policy is tightened; policy version is part of the cache key. - Corrected
Retry-Afterarithmetic under burst throttling.
v2.3.0 — August 16, 2026
Added
- Human approval queue with Slack and email routing.
- Per-agent spend ceilings and rolling rate limits.
Changed
- Default fail mode documented and enforced as fail-closed for privileged tools.
v2.2.0 — July 26, 2026
Added
- Deterministic policy compiler for plain-language rules.
- Tamper-evident audit export (JSONL + signed manifest).
v2.0.0 — June 14, 2026
Changed
- Rewritten evaluation core: parallel risk, cost and compliance scoring.
- Warm-path decision latency reduced from 210ms to under 15ms.