TokenPak

Release

TokenPak v1.29.0

v1.29.0 · Sep 23, 2026

Added

  • Opt-in authenticated native token observations report independent request coverage and bounded reservations with explicit response-completion evidence. Token measurements do not establish billed cost or accepted task outcomes.

Fixed

  • Claude prompt submissions appear in fresh companion journals even without the external SQLite executable. Metadata is queued outside the prompt path; it does not count as completed work or provider usage. Configured shell-hook budgets retain their refusal behavior when SQLite is unavailable.
  • Restore the companion MCP startup version banner and content-free malformed JSON diagnostics on stderr, preserving JSON-RPC responses on stdout.
  • Additive accounting migrations preserve historical rows and priced reservation domains without reclassifying older evidence as measured native token usage.
  • The database upgrade gate now migrates seeded snapshots from the six latest published minor baselines through all registered stores, checking row fidelity, current schema and repeated initialization. Missing baselines fail the gate.
  • Packaging tests distinguish the optional build frontend from a generated source-install directory, restoring minimal-install release rehearsals.
  • Background SQLite journal writes close inherited response pipes so a pending write cannot hold up prompt submission or leak writer output into the response.

Changed

  • Clarify README descriptions of default proxy preservation, explicit context tools, provider cache attribution, integration maturity and available editions.
  • Correct Dispatch documentation and CLI help to describe the packaged alpha CLI and runtime, optional dependencies, and unfinished station execution and delivery flow.

Compatibility

  • Native token observations are opt-in. Existing configurations and TIP-1.0 remain supported; absent or incomplete observations remain unavailable.
  • The paired Pro 0.5.0 candidate supports OSS 1.26.0 through 1.29.0. Native token measurement requires OSS 1.29.0. Upgrade both packages together.
  • See upgrade, rollback and release status.

Security

This release accepts the open NLTK GHSA-8mgp-746c-j5xp and Accelerate GHSA-4j2p-28q2-5m79 optional-dependency findings for this release only, following a fresh September 21 dependency audit. Both are High under CVSS v3.1; the Accelerate advisory separately lists Moderate severity under CVSS v4. No verified published fix is available. The base install excludes both packages. Optional integrations must avoid untrusted model paths and checkpoint repositories and cannot rely on these APIs for filesystem containment. See SECURITY.md for affected extras and limitations. Both findings remain open and must be resolved or reassessed before another release; all other release checks remain required.