Changelog
LedgerForge 1.0.0
The first LedgerForge release: a double-entry ledger with exact integer money handling, durable transaction lifecycles, read-only replay verification and a versioned audit chain, server-enforced spending policies and approval holds for API keys and AI agents, and a hardened HTTP API.
v1.0.0Released 10 October 2026Apache 2.0
Release artefactsv1.0.0
- ledgerforge and ledgerforge-mcp binariesLinux · macOS · Windows
- amd64 and arm64 archives6 builds
- checksums.txtSHA-256
- Source and container SBOMsSPDX
- Multi-platform container imageghcr.io
Highlights
A summary of the release notes. Upgrades are supported from fresh installs and from earlier published releases; read the upgrade notes before you migrate.
Exact money
- Integer postings with explicit precision, exact decimal-token preservation and model.ParseAmount.
- Rejection of nonfinite, negative, lossy and round-to-zero monetary inputs before execution.
- Deterministic split allocation that conserves units and rejects malformed distributions.
Durable lifecycles
- Durable inflight claims that serialise partial commits, voids and queued settlements.
- Durable refund claims: refunds preserve exact units and apply only to APPLIED originals.
- Queue acceptance that persists intent and action before dispatch, with safe recovery.
Verification
- Read-only ledgerforge verify replay with JSON issue reports.
- Canonical v3 hash chains, persistent checkpoints, audit verify, audit export and --anchor.
- Separate reporting of pending coverage and tampering findings.
Agent guardrails
- Per-key currency and precision rules, transaction caps, allowlists and UTC daily capacity.
- Approval holds with independent approve and reject endpoints, and effective-policy inspection.
- Immutable delegation ancestry with intersected policies and shared ancestor budgets.
- MCP identity binding with --api-key or LEDGERFORGE_MCP_API_KEY, plus policy and approval tools.
Hardened API
- Owner-bound key creation that can't broaden scopes or expiry, and authoritative PostgreSQL revocation.
- Sanitised backend errors and explicit body and upload bounds.
- Dedicated webhook signing secrets, URL validation, private-destination controls and redirect rejection.
Release engineering
- ledgerforge version reports version, commit and build date.
- Binaries for Linux, macOS and Windows on amd64 and arm64, checksums and SPDX SBOMs.
- Multi-platform images with attestations, CI vulnerability scanning, fuzz smoke and coverage artefacts.
Install 1.0.0
Download a release archive and check it against checksums.txt, or pull ghcr.io/devaccuracy/ledgerforge:1.0.0. The release page lists the image digest and SBOMs.
$ curl -LO https://github.com/devaccuracy/ledgerforge/releases/download/v1.0.0/ledgerforge_v1.0.0_linux_amd64.tar.gz$ curl -LO https://github.com/devaccuracy/ledgerforge/releases/download/v1.0.0/checksums.txt$ sha256sum -c checksums.txt --ignore-missingledgerforge_v1.0.0_linux_amd64.tar.gz: OK$ tar -xzf ledgerforge_v1.0.0_linux_amd64.tar.gz$ ./ledgerforge_v1.0.0_linux_amd64/ledgerforge versionledgerforge 1.0.0 (commit 64c7aec, built 2026-10-10T05:53:57+00:00)Put a provable ledger under your money movement
Start with the open-source core, or let the LedgerForge team run it for you on dedicated infrastructure.