Skip to content
PatchArcPatchArc

Changelog

What changed, when

Format versions are load-bearing in PatchArc: the verifier refuses capsules it does not understand. This page tracks them and the product surface around them.

v0.3.0

2026-08-30

format v0.2

  • 01Redaction now runs at seal time: thirteen detectors, env-file rules, entropy scanning, and your custom rules pass over every diff, commit message, and recorded note before signing; the redaction report is sealed with the rest.
  • 02patcharc run wraps any command and records its outcome: go test, pytest, vitest, jest, playwright, and cargo output become Verification evidence, JUnit XML imports with --junit, and the exit code passes through for CI.
  • 03Ambient capture: patcharc hooks install (or init --auto) reconciles commits the moment they land, records rebase and amend history as rewrite evidence, and can open an Arc automatically when a commit happens with none active.
  • 04Agent attribution: commits carrying agent trailers or agent committer identities are classified agent, assisted, or human in the review, per commit, from Git evidence alone.
  • 05patcharc mcp serves the recorder to any MCP-capable coding agent: start and seal Arcs, record decisions, risks, and test results as tools.
  • 06patcharc open renders a sealed capsule in an embedded local viewer on a loopback port; nothing is uploaded.
  • 07patcharc attest emits a signed in-toto statement (DSSE) for a verified capsule, binding the resulting commit and capsule digest for standard provenance tooling.
  • 08share reads share.default from repository config and defaults to a private link; verification is stricter, checking the signature over the exact stored manifest bytes; capsules now record true per-file line counts and statuses.
  • 09Private and team ArcLinks now render for signed-in members of the owning account.

v0.2.0

2026-08-22

format v0.2

  • 01.parc format 0.2.0 is the source of truth: Ed25519-sealed capsules with canonical-JSON manifests and per-file SHA-256 evidence.
  • 02Hosted service on patcharc.dev: upload sessions, server-side re-verification, ArcLinks with revoke and rotate.
  • 03CLI device-flow login with GitHub and Google approval at patcharc.dev/device; credentials stored at ~/.patcharc/credentials.json (0600).
  • 04BYOK connection API with envelope-encrypted provider keys (per-connection DEK wrapped by a versioned KEK) held only by an isolated key service.
  • 05Per-identity rate limiting on the API (300/min authenticated, 30/min on auth endpoints).
  • 06Website, documentation, comparisons, and blog on patcharc.dev.

Earlier builds (v0.1.x capsules) are not accepted by the current verifier. See the capsule format page for the compatibility rules.