AnterisLab
Resources · Changelog

Every release, in the open

Product changes, platform work and security fixes, newest first. Security entries are published only once a fix is generally available.

AnterisLab follows Semantic Versioning. Entries are grouped as Added, Changed, Fixed and Security. Security entries never disclose exploitation details before a fix is generally available.

v2.4.0 — September 13, 2026

Security · Platform · Marketing site

Added

  • Footer navigation to the full documentation, trust and legal set (Blog, Documentation, Changelog, Security, Status, Compliance, About, Careers, Brand Kit, Privacy, Terms, Cookies).
  • Self-hosted static pages rendered with the same design system as the marketing site.

Changed

  • Marketing pages are fully self-hosted: fonts and scripts are served from assets/anterislab-vendor/. No third-party CDN is contacted at page load.

Security

  • Document-level CSP tightened to default-src 'self'; object-src, base-uri and form-action restricted.
  • Access and refresh tokens are no longer reachable from JavaScript — sessions live in HttpOnly; Secure; SameSite=Lax cookies.
  • API keys are stored as salted hashes; the plaintext value is returned only once at creation.

v2.3.1 — August 30, 2026

Fixed

  • Decision cache no longer returns a stale allow after a policy is tightened; policy version is part of the cache key.
  • Corrected Retry-After arithmetic under burst throttling.

v2.3.0 — August 16, 2026

Added

  • Human approval queue with Slack and email routing.
  • Per-agent spend ceilings and rolling rate limits.

Changed

  • Default fail mode documented and enforced as fail-closed for privileged tools.

v2.2.0 — July 26, 2026

Added

  • Deterministic policy compiler for plain-language rules.
  • Tamper-evident audit export (JSONL + signed manifest).

v2.0.0 — June 14, 2026

Changed

  • Rewritten evaluation core: parallel risk, cost and compliance scoring.
  • Warm-path decision latency reduced from 210ms to under 15ms.