Changelog
What changed.
Releases, registry refreshes, and methodology updates. Also available as RSS.
2026-09-18 — Coverage integrity v2
Trust-card/v2 ships: U (ungraded) where static coverage is insufficient, a coverage object in every card, CLI exit code 2 with all artifacts still written, and a --fail-on coverage gate. Registry recomputed under the stricter rule: 3 of 53 cards graded, 50 ungraded and excluded from rankings and averages. Withheld, never inflated. How coverage gating works.
2026-09-09 — Weekly registry refresh goes automatic
50 external targets plus 3 self-scans re-scanned on schedule; per-report badges bound to evidence pages; stale banners past 30 days. Browse the registry.
2026-09-08 — State of MCP Permissions
First ecosystem cut: permission scope predicts the grade. Full report.
2026-09-10 — v0.1.3: verified CLI banner + badge rebrand
CLI banner redrawn from real figlet output; grade badges and OG image carry the OpenTrustBench brand. Release.
2026-09-10 — v0.1.2: ASCII banner rebrand + npm READMEs
CLI banner now reads OpenTrustBench; @opentrustbench/cli and @opentrustbench/core ship package READMEs. Release.
2026-09-10 — v0.1.1: Trust Cards for AI agents and MCP servers
8-rule OWASP-mapped static suite, Trust Cards A–F, SARIF output, CI gate, GitHub Action, Homebrew + PyPI + VS Code distribution. Release.