Browse documentation
Docs target stable release v0.9.1.Stable vs main checked 2026-10-09

Upgrade to v0.9.1

Terminal
python -m pip install --upgrade "opentine==0.9.1"
tine repo-verify --help

No storage migration is required. Portable v2 artifacts and v3 repositories written since v0.3 remain readable. Signing is opt-in; unsigned attestations retain their identities.

Structured harness capture

Terminal
tine run --harness codex --harness-arg --json --prompt "Inspect this repo" --save codex.tine
tine run --harness cursor --harness-arg --output-format --harness-arg json --prompt "Inspect this repo" --save cursor.tine

Text-mode stdout stays text. JSON-shaped prose cannot manufacture tool events or charges. Free-text cost parsing remains only for operator-written generic and Pi commands.

Behavior changes

  • On POSIX, discovery refuses an ancestor repository owned by another user. Select a trusted path with --repo or configure OPENTINE_SAFE_DIRECTORIES.
  • Packed annotations for already-held runs are retained in .tine/unadopted instead of silently adopted.
  • Filesystem tools refuse writes inside .git and through hard links. Shell policies reject dangerous git options and configuration injection.
  • The built-in Python tool accepts only the subprocess isolation backend; other backends are refused.
  • Currency must be an uppercase ISO code such as USD. Unsigned workspace pricing overlays produce a stderr notice; OPENTINE_TRUST_WORKSPACE_PRICING=1 suppresses it.
  • Verification APIs require exactly one key source and canonical signature blocks.

Imports are bounded before parsing. Export refuses destination symlinks unless --force replaces them. Terminal and MCP messages sanitize controls and invisible characters. Credential redaction covers more names and free-text shapes.

Use signer and claim selection for approval gates. Signed search ranking describes signature presence; verify authenticity with a trusted key. See the complete changelog.