Releases: blisspixel/deepr
Release list
Deepr v2.37.0
Deepr v2.37.0 ships bounded, evidence-first expert investigations for persistent expert councils, with separate factual and perspective learning lanes and stricter no-surprise-bills controls.
Highlights
- Persistent experts can investigate a question with distinct evidence lenses, challenge and revise positions across rounds, and produce provenance-indexed artifacts without mutating expert state during the run.
- Facts and perspectives are kept separate. Hypotheses, theories, stances, concepts, null hypotheses, and original ideas can remain useful without being mislabeled as verified facts or human-reviewed work.
- Explicit bulk learning preflights every selected expert and lane, hash-verifies producer artifacts, locks all targets, and applies atomically. A budget is a ceiling, not consent.
- Remote MCP, REST, WebSocket, A2A, queue, and worker paths now preserve scoped identity and ownership while failing closed on unproven authority, metered consent, or accounting.
- Claude Code is the only currently executable plan-quota adapter, and only after a fresh provider observation proves paid extra usage is disabled. Other plan CLIs remain visible but execution-blocked until Deepr can prove safe confinement and billing posture.
- URL retrieval, outbound MCP, local approvals, graph commits, report absorption, deployment secrets, reservations, and the append-only cost ledger received broad security and lifecycle hardening.
- The council and capacity guides now give exact commands, cost semantics, learning behavior, and honest works-now versus planned boundaries.
Validation
- GitHub CI passed lint, strict type islands, frontend tests and packaging, dependency and secret audits, and the full unit suite on Python 3.12, 3.13, and 3.14.
- 9,203 unit tests passed locally with 85% branch coverage, above the blocking 80% threshold.
- CodeQL passed for Python, JavaScript/TypeScript, and Actions.
- Live validation used local Ollama and safely proven subscription quota only. Paid and metered-at-margin validation spend was exactly $0.00.
- The corrected three-expert pilot staged six candidate writes but applied none. Semantic superiority and held-out evidence quality remain explicit evaluation gates, not release claims.
See docs/CHANGELOG.md for the complete record.
Deepr v2.36.2
Deepr v2.36.2 hardens metered accounting fail-closed paths and soft cost admission without re-enabling live metered chat.
Highlights
- Dual confirmation for live metered expert chat: substrate flag plus DEEPR_ALLOW_METERED_EXPERT_CHAT=1. The substrate flag remains false.
- After durable settle, chat and research paths mirror session spend only (no second ledger write). Deep-research final usage ledger rows charge overrun only.
- Metered skill tools use durable fixed-cost admission when explicitly allowed; SkillExecutor defaults allow_metered_tools=False. Skill manifests clamp budgets and timeouts and treat unknown cost tiers as high.
- Embedding cache document and query embeds share the dual metered-chat confirmation gate.
- Soft cost preflights fail closed on bookkeeping failure across citation validation, gap discovery, map-reduce, multi-pass, curriculum, synthesis, and task planner.
- Documented the metered expert-chat re-enable review checklist.
Validation
- GitHub CI passed on Python 3.12, 3.13, and 3.14 including lint, frontend, core-install, security, and coverage gates.
- This release validation made no paid provider calls.
See docs/CHANGELOG.md for the complete record.
Deepr v2.36.1
Deepr v2.36.1 hardens plan-quota process ownership and lands the durable metered expert-chat admission substrate without re-enabling live metered chat.
Highlights
- Plan-quota CLI stdout/stderr are each hard-capped at 8 MiB raw bytes. Overflow kills and reaps the process tree, returns output_limit_exceeded, and pairs unknown quota usage with a $0 cost event.
- Windows Job Objects and Linux detached supervisors own CLI descendants before launch; unsupported POSIX platforms fail closed before dispatch.
- Metered expert-chat complete/stream, research, and embedding paths share reserve, dispatch-mark, and settlement helpers when execution is enabled.
- Sessions serialize turns and pass min(estimate, remaining session budget) as each call ceiling; missing max_tokens derive from half the dollar hold.
- Live metered chat remains fail-closed (METERED_EXPERT_CHAT_EXECUTION_ENABLED = False) until final deep-research usage settlement, optional metered skill tools, double-count audit, and explicit spend confirmation clear.
Validation
- GitHub CI passed on Python 3.12, 3.13, and 3.14 including lint, frontend, core-install, security, and coverage gates.
- This release validation made no paid provider calls.
See docs/CHANGELOG.md for the complete record.
Deepr v2.36.0
Deepr v2.36.0 closes the verification and cost-accounting loop before widening agent autonomy.
Highlights
- Direct research now uses one finite request envelope for preview, reservation, queued metadata, provider payload, and settlement.
- Expert consultations have durable lifecycle journals, bounded local or explicit plan synthesis, preserved dissent, and cancellation-safe accounting.
deepr eval deliberationprovides an offline 11-case structural evaluator at $0 without enabling live multi-round deliberation.- Plan-quota CLI attempts now write paired idempotent quota and $0 cost events across cancellation, timeout, and runner failure.
- Scheduled local maintenance detects GPU contention and records bounded 30-minute, 2-hour, then 6-hour waits without paid fallback.
- The bundled Deepr research skill, README, roadmap, architecture, capacity guide, model guide, security policy, and deployment docs now describe works-now, visible, and gated capacity consistently.
Safety posture
- One fully priced bounded API research job remains supported under a hard approved ceiling.
- Standalone metered expert chat, unsafe lifecycle mutations, live provider benchmarks, hosted context, automatic paid fallback, and metered multi-call campaigns fail closed until they share the durable transaction contract.
- The AWS research deployment is explicitly an infrastructure preview and blocks paid submission at both API and worker boundaries.
Validation
- 8,426 unit tests passed, 8 skipped, and branch coverage reached 84.62 percent against the 80 percent gate.
- GitHub CI passed on Python 3.12, 3.13, and 3.14, including strict types, frontend, package, security, dependency audit, and SBOM jobs.
- CodeQL passed for Python, JavaScript/TypeScript, and Actions.
- Wheel and sdist both passed isolated install, version, doctor, and 11 of 11 $0 deliberation smoke tests.
- The v2.36 release validation made no paid provider calls.
See docs/CHANGELOG.md for the complete change and migration record.
Deepr v2.35.0
Deepr v2.35.0 hardens the complete expert-learning loop: evidence acquisition, bounded deliberation, persistent belief updates, capacity selection, cost settlement, browser chat, queues, and release packaging.
Highlights
- Expert councils now preserve bounded roster, capacity, dissent, truncation, and synthesis status in durable consult traces returned consistently by CLI and MCP.
- Scheduled local sync, sync-all, and gap work use best-effort GPU contention signals. Busy capacity records a durable wait with 30-minute, 2-hour, then 6-hour retry guidance and never falls through to a paid backend.
- Topic learning and learn-web require replayable fetched evidence, persist source packs and snapshots, reject unsupported candidates, and leave under-ready runs retryable without advancing freshness.
- API-backed absorption now reserves and settles every extraction, contradiction, deduplication, and adjudication call under one caller-supplied ceiling. Local and prepaid-plan paths remain $0.
- Browser expert chat now has explicit API-only admission, bounded session budgets, durable per-turn accounting, truthful cancellation, stable session restoration, and cost breakdown reconciliation.
- CLI version and root help now avoid heavy provider and expert imports. Windows p95 startup measured about 223 ms for version and 217 ms for root help.
- GitHub Releases is now the working binary channel. Installers and
deepr upgraderesolve the exact repository-hosted wheel and fail safely on missing or invalid release metadata. - A measured architecture decision keeps Deepr Python-first. Rust, Go, Mojo, and free-threaded Python remain evidence-gated options for specific proven seams rather than speculative rewrites.
Validation
- Hosted CI passed lint, strict typing, security and SBOM, core-only install, frontend build and packaging, and unit coverage on Python 3.12, 3.13, and 3.14: https://github.com/blisspixel/deepr/actions/runs/29175666752
- CodeQL passed for Python, JavaScript/TypeScript, and Actions: https://github.com/blisspixel/deepr/actions/runs/29175666584
- Local no-key validation: 7,997 passed, 8 skipped, 84.77 percent branch coverage across 8,005 collected tests.
- Frontend validation: lint, TypeScript, production build, and 26 tests passed.
- The committed frontend payload reproduced byte-for-byte with Node 22.23.1 on Windows and Linux.
- Dogfood spend remained $0.20, within the $2 ceiling, with no additional paid calls.
Install
python -m pip install https://github.com/blisspixel/deepr/releases/download/v2.35.0/deepr_research-2.35.0-py3-none-any.whlPyPI publication is not part of this release.
SHA-256
deepr_research-2.35.0-py3-none-any.whl:A2710DE2EEE61FFE1CDB3F2A6F78894DCDDDB71381B4CA75AB0E5E059AB6D029deepr_research-2.35.0.tar.gz:ADC9FE0E20A25EAFCADB8AC714F6F9310CBAE082FB63EE2C13E17BA1D7586B80
v2.34.4
Highlights
- Adds
deepr expert next NAME, a read-only, $0 structural navigator over
claims, freshness, gaps, contradictions, and verified learning-loop evidence. - Returns canonical argv arrays, checks capacity before scheduled compiled
sync, and never executes work or claims semantic maturity. - Keeps legacy profiles readable without persisting migrations from the
read-only command. - Confines belief reads to the exact containment-validated file selected below
the configured expert root, with regressions for directory, file, and
basename-switch symlink escapes. - Corrects expert freshness guidance, local vector-store blockers, storage-root
defaults, and sequential multi-device safety documentation. - Adds research-backed roadmap designs for ExpertEventV2, forgetting-aware
improvement, historically grounded Leonardo-informed and Beethoven-informed
perspectives, and modern agent-harness control patterns.
Validation
- 7,696 unit tests passed with 8 intentional skips.
- 84.56 percent branch coverage against the 80 percent gate.
- Python 3.12, 3.13, and 3.14 CI passed.
- Ruff, formatting, strict mypy islands, file-size, complexity, security,
documentation consistency, frontend lint, frontend tests, TypeScript,
production build, package build, dependency audit, Gitleaks, CodeQL, and
Dependency Graph passed. - Two CodeQL path alerts were dismissed as documented false positives only
after exact containment validation and adversarial symlink regressions proved
the sinks safe.
Upgrade
pip install --upgrade deepr-research==2.34.4v2.34.3
Security and lifecycle hardening
- Make provider cleanup identifiers and cost reservations server-owned, reject them atomically across public submissions, and redact them from public job views.
- Bind status and cancellation to each job's recorded provider.
- Confirm cancellation only after queue, cost, and provider-resource cleanup closure.
- Make completion settlement and cleanup retry-safe before durable terminal status.
- Keep unknown provider statuses active and observable without exposing provider-controlled diagnostics.
- Return fixed public metadata errors across REST and web submission paths.
- Treat cancelled work as terminal in Research Live and preserve retryable cancellation failures in context.
- Correct current command, support, and lifecycle documentation.
Verification
- 7,675 unit tests passed, 8 skipped, with 84.45 percent branch coverage.
- 230 focused lifecycle regressions and 15 frontend tests passed.
- Ruff, formatting, strict mypy, documentation consistency, repository ratchets, lock validation, package build, dependency audit, secret scan, frontend lint, TypeScript, and production build passed.
- Both original no-network cleanup authorization PoCs stop before provider deletion target selection.
- Validation spend: $0.
Deepr v2.34.2
Security
- Prevent unexpected provider response content from entering benchmark validation console or dashboard-captured output.
- Treat unexpected provider responses as failed validation and return a nonzero command exit.
- Return a fixed benchmark-start validation response without exposing caught exception details.
Verification
- 7,577 unit tests passed with 8 intentional skips and 84.43 percent branch coverage.
- Ruff, strict mypy, frontend lint, 13 frontend tests, production build, documentation consistency, repository ratchets, lock verification, and package build passed.
- Regression tests cover secret-bearing provider output, secret-bearing validation exceptions, failure totals, and process exit status.
- Two independent reviews found no remaining medium or high issue.
- Validation spend was $0.
Deepr v2.34.1
Product trust and recovery
- Bound dashboard benchmark approval to the exact tier, quick-run, and judge settings that produced its estimate.
- Added scoped recovery states across expert, trace, benchmark, and settings surfaces without discarding valid cached data.
- Preserved failed benchmark output and added direct setup and retry paths.
Spend and reliability hardening
- Added durable per-call reservations and canonical ledger settlement for benchmark evaluation, judge, and validation calls.
- Enforced adapter output and bounded search maxima before provider submission.
- Failed closed on unpriced models and provider paths without deterministic request-level spend ceilings.
- Serialized destructive demo-data actions and restored benchmark execution from any working directory.
Validation
- Full Python branch-coverage suite and frontend lint, tests, and production build pass locally.
- Strict typing, Ruff, docs consistency, security and complexity ratchets, package lock, package build, and dependency audit pass locally.
- Validation used no provider calls and cost $0.
Deepr v2.34.0
Deepr v2.34.0
Product trust and research continuity release.
- Research Studio now fails closed when OpenAI readiness or cost estimation is unavailable and reports actionable recovery state.
- Queue, ledger, stale-cleanup, live-update, and runtime-version semantics now agree across dashboard and documentation surfaces.
- Research drafts are validated and restored within the current browser tab without persisting uploaded file data.
- Existing drafts are preserved until a different linked prompt is explicitly accepted.
- Overview, Research, Results, and the global status bar now provide clearer narrow-screen hierarchy and accessible control state.
- Frontend draft validation, privacy, arbitration, and failure tests are a blocking CI gate.
- Package metadata now uses current SPDX license fields and builds cleanly as sdist and wheel.
Validation: 7,559 Python unit tests at 84 percent branch coverage in local Cycle 1 validation, 8 frontend draft-state tests, Ruff, strict mypy, TypeScript, frontend production build, documentation consistency, structural ratchets, lock validation, package builds, dependency audit, secret scan, CodeQL, dependency graph, and exact-commit GitHub CI are green. Validation spend: $0.