Skip to content
Changelog

LedgerForge 1.0.0

The first LedgerForge release: a double-entry ledger with exact integer money handling, durable transaction lifecycles, read-only replay verification and a versioned audit chain, server-enforced spending policies and approval holds for API keys and AI agents, and a hardened HTTP API.

v1.0.0Released 10 October 2026Apache 2.0
Release artefactsv1.0.0
  • ledgerforge and ledgerforge-mcp binariesLinux · macOS · Windows
  • amd64 and arm64 archives6 builds
  • checksums.txtSHA-256
  • Source and container SBOMsSPDX
  • Multi-platform container imageghcr.io

Highlights

A summary of the release notes. Upgrades are supported from fresh installs and from earlier published releases; read the upgrade notes before you migrate.

Exact money

  • Integer postings with explicit precision, exact decimal-token preservation and model.ParseAmount.
  • Rejection of nonfinite, negative, lossy and round-to-zero monetary inputs before execution.
  • Deterministic split allocation that conserves units and rejects malformed distributions.

Durable lifecycles

  • Durable inflight claims that serialise partial commits, voids and queued settlements.
  • Durable refund claims: refunds preserve exact units and apply only to APPLIED originals.
  • Queue acceptance that persists intent and action before dispatch, with safe recovery.

Verification

  • Read-only ledgerforge verify replay with JSON issue reports.
  • Canonical v3 hash chains, persistent checkpoints, audit verify, audit export and --anchor.
  • Separate reporting of pending coverage and tampering findings.

Agent guardrails

  • Per-key currency and precision rules, transaction caps, allowlists and UTC daily capacity.
  • Approval holds with independent approve and reject endpoints, and effective-policy inspection.
  • Immutable delegation ancestry with intersected policies and shared ancestor budgets.
  • MCP identity binding with --api-key or LEDGERFORGE_MCP_API_KEY, plus policy and approval tools.

Hardened API

  • Owner-bound key creation that can't broaden scopes or expiry, and authoritative PostgreSQL revocation.
  • Sanitised backend errors and explicit body and upload bounds.
  • Dedicated webhook signing secrets, URL validation, private-destination controls and redirect rejection.

Release engineering

  • ledgerforge version reports version, commit and build date.
  • Binaries for Linux, macOS and Windows on amd64 and arm64, checksums and SPDX SBOMs.
  • Multi-platform images with attestations, CI vulnerability scanning, fuzz smoke and coverage artefacts.

Install 1.0.0

Download a release archive and check it against checksums.txt, or pull ghcr.io/devaccuracy/ledgerforge:1.0.0. The release page lists the image digest and SBOMs.

Release archive
$ curl -LO https://github.com/devaccuracy/ledgerforge/releases/download/v1.0.0/ledgerforge_v1.0.0_linux_amd64.tar.gz$ curl -LO https://github.com/devaccuracy/ledgerforge/releases/download/v1.0.0/checksums.txt$ sha256sum -c checksums.txt --ignore-missingledgerforge_v1.0.0_linux_amd64.tar.gz: OK$ tar -xzf ledgerforge_v1.0.0_linux_amd64.tar.gz$ ./ledgerforge_v1.0.0_linux_amd64/ledgerforge versionledgerforge 1.0.0 (commit 64c7aec, built 2026-10-10T05:53:57+00:00)

Put a provable ledger under your money movement

Start with the open-source core, or let the LedgerForge team run it for you on dedicated infrastructure.