Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
6 changes: 3 additions & 3 deletions public/llms.txt
Original file line number Diff line number Diff line change
Expand Up @@ -58,13 +58,13 @@ Current packages: crates.io at 0.14.0 (pin `traverse-registry` at `=0.25.0` if y
- [Changelog](https://traverse-framework.com/changelog.html): release-by-release history.
- [Security & Permanence Audit](https://traverse-framework.com/security-audit.html): every known finding, its GitHub ticket, and its real status — not a marketing page.
- [FAQ](https://traverse-framework.com/faq.html) and [Questions](https://traverse-framework.com/questions.html): 70+ specific Q&A pages, mostly long-tail but accurate.
- [What is exact-ref model execution?](https://traverse-framework.com/questions/what-is-exact-ref-model-execution.html): signed schema `2.0.0` + `model.sig.json`; host-owned trust; `digits-mlp-1.0.0` (test-only key; prod signing #1567); native+web execute only in v0.14.0 (first landed in v0.12.0). Embedder notes: [v0.14.0: what changed for embedders](https://traverse-framework.com/blog/traverse-0-14-0-what-changed-for-embedders.html) · [Release](https://github.com/traverse-framework/traverse/releases/tag/v0.14.0) · [Announcement #1576](https://github.com/orgs/traverse-framework/discussions/1576).
- [How do hosts trust signed models?](https://traverse-framework.com/questions/how-do-hosts-trust-signed-models.html): host-owned trust roots gate `register_package`; pin by digest + `model.sig.json`; test-only digits-mlp key; exact-ref execute native+web only — no claimed ONNX generic runner.
- [What is exact-ref model execution?](https://traverse-framework.com/questions/what-is-exact-ref-model-execution.html): signed schema `2.0.0` + `model.sig.json`; host-owned trust; `digits-mlp-1.0.0` (test-only key; prod signing #1567); native+web+Swift ExactModelHost execute (swift-host-v0.14.0-1 / #1579); Kotlin/.NET not yet (first landed in v0.12.0). Embedder notes: [v0.14.0: what changed for embedders](https://traverse-framework.com/blog/traverse-0-14-0-what-changed-for-embedders.html) · [Release](https://github.com/traverse-framework/traverse/releases/tag/v0.14.0) · [Announcement #1576](https://github.com/orgs/traverse-framework/discussions/1576).
- [How do hosts trust signed models?](https://traverse-framework.com/questions/how-do-hosts-trust-signed-models.html): host-owned trust roots gate `register_package`; pin by digest + `model.sig.json`; test-only digits-mlp key; exact-ref execute native+web+Swift ExactModelHost; Kotlin/.NET not yet — no claimed ONNX generic runner.
- [How does Traverse complement Hugging Face?](https://traverse-framework.com/questions/how-does-traverse-complement-hugging-face.html): Hub = provenance; Traverse = pinned signed client-first capability; not Transformers.js/Hub replacement; no defer promise until a second executor exists.

## Optional

- [Blog](https://traverse-framework.com/blog.html): engineering write-ups, dated — treat as historical snapshots, not current-state claims. Latest: [v0.14.0: what changed for embedders](https://traverse-framework.com/blog/traverse-0-14-0-what-changed-for-embedders.html) (signed Spec 138; native+web exact-ref; test-only digits-mlp key). Also: [Where business logic lives (hosts stay thin)](https://traverse-framework.com/blog/where-business-logic-lives.html). Weekly demo: [Same WASM. Browser and Node match. Agent still can’t freestyle.](https://traverse-framework.com/blog/same-wasm-multi-host.html) (v0.13.0 multi-host). Prior: [agent freestyle → blocked](https://traverse-framework.com/blog/agent-freestyle-blocked.html). Authoring: [You don't need Rust to publish a capability](https://traverse-framework.com/blog/you-dont-need-rust-to-publish-a-capability.html).
- [Blog](https://traverse-framework.com/blog.html): engineering write-ups, dated — treat as historical snapshots, not current-state claims. Latest: [v0.14.0: what changed for embedders](https://traverse-framework.com/blog/traverse-0-14-0-what-changed-for-embedders.html) (signed Spec 138; native+web+Swift ExactModelHost exact-ref; test-only digits-mlp key). Also: [Where business logic lives (hosts stay thin)](https://traverse-framework.com/blog/where-business-logic-lives.html). Weekly demo: [Same WASM. Browser and Node match. Agent still can’t freestyle.](https://traverse-framework.com/blog/same-wasm-multi-host.html) (v0.13.0 multi-host). Prior: [agent freestyle → blocked](https://traverse-framework.com/blog/agent-freestyle-blocked.html). Authoring: [You don't need Rust to publish a capability](https://traverse-framework.com/blog/you-dont-need-rust-to-publish-a-capability.html).
- [Discover](https://traverse-framework.com/discover.html): a live browser demo that pulls the public registry and executes a reviewed plan locally. Read [what it proves](https://traverse-framework.com/blog/what-discover-proves.html) before quoting it.
- [Compare: vs microservices](https://traverse-framework.com/compare/vs-microservices.html), [vs serverless](https://traverse-framework.com/compare/vs-serverless.html), [vs function calling](https://traverse-framework.com/compare/vs-function-calling.html), [vs agent runtimes](https://traverse-framework.com/compare/vs-agent-runtimes.html), [vs WASM runtimes](https://traverse-framework.com/compare/vs-wasm-runtimes.html), [vs cross-platform frameworks](https://traverse-framework.com/compare/vs-cross-platform-frameworks.html)
- [About](https://traverse-framework.com/about.html): project history and motivation.
Expand Down
2 changes: 1 addition & 1 deletion src/pages/blog/index.astro
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,7 @@
import SubpageLayout from '@layouts/SubpageLayout.astro';

const posts = [
{ href: '/blog/traverse-0-14-0-what-changed-for-embedders.html', title: 'v0.14.0: what changed for embedders', desc: 'Featured · Signed Spec 138 (schema 2.0.0 + model.sig.json), host-owned trust, registerPackage, digits-mlp-1.0.0 (test-only key). Native + web execute; Swift/Kotlin/.NET do not yet. crates/npm 0.14.0; registry 0.25.0.' },
{ href: '/blog/traverse-0-14-0-what-changed-for-embedders.html', title: 'v0.14.0: what changed for embedders', desc: 'Featured · Signed Spec 138 (schema 2.0.0 + model.sig.json), host-owned trust, registerPackage, digits-mlp-1.0.0 (test-only key). Native + web + Swift ExactModelHost execute; Kotlin/.NET do not yet. crates/npm 0.14.0; registry 0.25.0.' },
{ href: '/blog/same-wasm-multi-host.html', title: 'Same WASM. Browser and Node match. Agent still can’t freestyle.', desc: 'Featured · Weekly demo: identical core.authorize@1.2.0 bytes on Browser + Node deny junior_analyst $2.4M wire; allow treasury_ops + MFA/dual-control. Traverse v0.13.0 multi-host.' },
{ href: '/blog/where-business-logic-lives.html', title: 'Where business logic lives (hosts stay thin)', desc: 'Featured · Narrative companion to the where-logic Q&A: capabilities hold non-UI domain rules; hosts = UI + I/O; utilities ≠ ceiling; apps-not-ready ≠ leave logic in the host.' },
{ href: '/blog/what-is-real-today-start-here.html', title: 'Start here: what is real in Traverse today', desc: 'Featured · Narrative companion to /what-is-real-today: discover→execute→trace, skill-first authoring, one shared runtime.wasm, honest consumers, pre-1.0.' },
Expand Down
15 changes: 10 additions & 5 deletions src/pages/blog/traverse-0-14-0-what-changed-for-embedders.astro
Original file line number Diff line number Diff line change
Expand Up @@ -27,14 +27,18 @@ const _body = `
<p><a href="https://github.com/traverse-framework/traverse/releases/tag/v0.14.0">Traverse v0.14.0</a> is the signed exact-ref model cut. One shared <code>runtime.wasm</code>. Hosts stay UI + WASI/WIT I/O. Capabilities still <strong>discover → execute → trace</strong>. The agent proposes; the runtime decides.</p>

<div class="callout">
Short version for embedders: model packages are signed, bound to the app that pins them, and checked against host-owned trust roots. Native Rust and the web embedder execute exact-ref models today. Swift / Kotlin / .NET do not — yet.
Short version for embedders: model packages are signed, bound to the app that pins them, and checked against host-owned trust roots. Native Rust, the web embedder, and Swift (<code>ExactModelHost</code>) execute exact-ref models today. Kotlin and .NET do not — yet.
</div>

<div class="callout">
<strong>Update (September 30, 2026):</strong> overnight after the v0.14.0 product cut, <a href="https://github.com/traverse-framework/traverse/issues/1579" target="_blank" rel="noopener">#1579</a> closed and the published xcframework <a href="https://github.com/traverse-framework/traverse/releases/tag/swift-host-v0.14.0-1" target="_blank" rel="noopener"><code>swift-host-v0.14.0-1</code></a> exposes Spec 138 parity. <code>packages/swift/TraverseEmbedder/Package.swift</code> pins that binary target. Digits conformance is byte-identical on Swift (1,727 / 1,797). Kotlin (<a href="https://github.com/traverse-framework/traverse/issues/1580" target="_blank" rel="noopener">#1580</a>) and .NET still do not execute exact-ref.
</div>

<h2 id="breaking">Breaking for Spec 138 consumers</h2>

<ul>
<li>Manifests move to schema <strong>2.0.0</strong>. Every package ships a detached Ed25519 <code>model.sig.json</code> over the exact <code>model.manifest.json</code> bytes.</li>
<li>Host-owned trust roots: <code>TrustedModelKeys</code> (Rust) / <code>trustedPublicKeysHex</code> (web). Apps never add trust.</li>
<li>Host-owned trust roots: <code>TrustedModelKeys</code> (Rust) / <code>trustedPublicKeysHex</code> (web and Swift). Apps never add trust.</li>
<li><code>register_package</code> / <code>registerPackage</code> replaces <code>insertVerified</code> — signature, trusted key, digest, schema, rights, target, and limits are checked before the package enters the cache. Every execute re-hashes cached bytes.</li>
<li>Pins bind the SHA-256 of those manifest bytes and declare <code>target</code>, expected <code>rights</code>, and an optional signer <code>key_id</code>.</li>
</ul>
Expand All @@ -46,8 +50,9 @@ const _body = `
<h2 id="hosts">Honest host matrix</h2>

<ul>
<li><strong>Rust native + web</strong> — exact-ref execute ships in this cut.</li>
<li><strong>Swift / Kotlin / .NET</strong> — in-tree embedders continue; they do <strong>not</strong> execute exact-ref models yet.</li>
<li><strong>Rust native + web</strong> — exact-ref execute shipped in the v0.14.0 product cut.</li>
<li><strong>Swift</strong> — <code>ExactModelHost</code> executes signed exact-ref via the published <code>TraverseSwiftHost</code> xcframework (<code>swift-host-v0.14.0-1</code>) and the in-repo <code>Package.swift</code> binary pin. Still not a CocoaPods / Swift Package Index first-class package; distribution is GitHub Release + SPM binary target.</li>
<li><strong>Kotlin / .NET</strong> — in-tree embedders continue; they do <strong>not</strong> execute exact-ref models yet.</li>
</ul>

<p>SDKs, MCP, and CLI are embedders and clients of the same orchestrator — not different Traverse runtimes.</p>
Expand Down Expand Up @@ -90,7 +95,7 @@ const _body = `
---
<SubpageLayout
title="v0.14.0: what changed for embedders — Traverse Blog"
description="Traverse v0.14.0 for embedders: signed Spec 138 manifests (schema 2.0.0), host-owned trust, registerPackage, digits-mlp-1.0.0 (test-only key). Native + web execute; Swift/Kotlin/.NET do not yet."
description="Traverse v0.14.0 for embedders: signed Spec 138 manifests (schema 2.0.0), host-owned trust, registerPackage, digits-mlp-1.0.0 (test-only key). Native + web + Swift ExactModelHost execute; Kotlin/.NET do not yet."
canonical="https://traverse-framework.com/blog/traverse-0-14-0-what-changed-for-embedders.html"
crumbs={[{ label: 'Home', href: '/' }, { label: 'Blog', href: '/blog.html' }]}
>
Expand Down
Loading
Loading