Files
OpenShell/docs/about/release-notes.mdx
VarshaandJohn Myers 0803c4aa4c refactor(policy)!: remove NetworkBinary harness field (#3222)
* refactor(policy)!: remove NetworkBinary harness field

Closes #3054

Signed-off-by: Varsha Prasad Narsing <varshaprasad96@gmail.com>

* test(policy): preserve unknown fields during migration

Signed-off-by: Varsha Prasad Narsing <varshaprasad96@gmail.com>

* fix(policy): preserve advisor provenance during merge

Signed-off-by: Varsha Prasad Narsing <varshaprasad96@gmail.com>

* fix(policy): remove redundant network binary default

Signed-off-by: John Myers <9696606+johntmyers@users.noreply.github.com>

* fix(policy): record harness schema migration

Signed-off-by: John Myers <9696606+johntmyers@users.noreply.github.com>

---------

Signed-off-by: Varsha Prasad Narsing <varshaprasad96@gmail.com>
Signed-off-by: John Myers <9696606+johntmyers@users.noreply.github.com>
Co-authored-by: John Myers <9696606+johntmyers@users.noreply.github.com>
2026-09-11 16:49:14 +00:00

27 lines
1.7 KiB
Plaintext

---
# SPDX-FileCopyrightText: Copyright (c) 2025-2026 NVIDIA CORPORATION & AFFILIATES. All rights reserved.
# SPDX-License-Identifier: Apache-2.0
title: "NVIDIA OpenShell Release Notes"
sidebar-title: "Release Notes"
description: "Track the latest changes and improvements to NVIDIA OpenShell."
keywords: "Generative AI, Cybersecurity, Release Notes, Changelog, AI Agents"
position: 6
---
NVIDIA OpenShell follows a frequent release cadence. Use the following GitHub resources directly.
## 0.1.0 migration notes
### Network policy binaries
OpenShell 0.1.0 removes the deprecated `NetworkBinary.harness` protobuf field and reserves its field number and name. Generated protobuf decoders ignore the unknown value. When the gateway loads policy history written by an older version, it migrates binaries marked by the former field into endpoint-provenance-marked rules so the upgrade cannot widen private-address access.
Remove `harness` from sandbox policies and provider profiles before upgrading. Policy and profile YAML now reject the property. Provider profiles should list binaries as scalar paths, such as `- /usr/bin/curl`; the transitional object form `- path: /usr/bin/curl` remains accepted and is exported as a scalar.
| Resource | Description |
|---|---|
| [Releases](https://github.com/NVIDIA/OpenShell/releases) | Versioned release notes and downloadable assets. |
| [Release comparison](https://github.com/NVIDIA/OpenShell/compare) | Diff between any two tags or branches. |
| [Merged pull requests](https://github.com/NVIDIA/OpenShell/pulls?q=is%3Apr+is%3Amerged) | Individual changes with review discussion. |
| [Commit history](https://github.com/NVIDIA/OpenShell/commits/main) | Full commit log on `main`. |