Changelog

What changed.

Releases, registry refreshes, and methodology updates. Also available as RSS.

2026-09-18 — Coverage integrity v2

Trust-card/v2 ships: U (ungraded) where static coverage is insufficient, a coverage object in every card, CLI exit code 2 with all artifacts still written, and a --fail-on coverage gate. Registry recomputed under the stricter rule: 3 of 53 cards graded, 50 ungraded and excluded from rankings and averages. Withheld, never inflated. How coverage gating works.

2026-09-09 — Weekly registry refresh goes automatic

50 external targets plus 3 self-scans re-scanned on schedule; per-report badges bound to evidence pages; stale banners past 30 days. Browse the registry.

2026-09-08 — State of MCP Permissions

First ecosystem cut: permission scope predicts the grade. Full report.

2026-09-10 — v0.1.3: verified CLI banner + badge rebrand

CLI banner redrawn from real figlet output; grade badges and OG image carry the OpenTrustBench brand. Release.

2026-09-10 — v0.1.2: ASCII banner rebrand + npm READMEs

CLI banner now reads OpenTrustBench; @opentrustbench/cli and @opentrustbench/core ship package READMEs. Release.

2026-09-10 — v0.1.1: Trust Cards for AI agents and MCP servers

8-rule OWASP-mapped static suite, Trust Cards A–F, SARIF output, CI gate, GitHub Action, Homebrew + PyPI + VS Code distribution. Release.