Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
13 changes: 8 additions & 5 deletions public/llms.txt
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
# Traverse

> Traverse is a governed capability runtime for portable business logic. Value loop: **discover → execute → trace**. Usual authoring is skill-first plain English via `traverse-capability-author` (contract → WASM → human-reviewed PR); manual authoring still uses Rust→WASM — you do **not** need to write Rust for the usual path. One shared `runtime.wasm`; browser, native desktop, CLI, and MCP are clients/embedders, not different Traverse runtimes. Shipped consumers today: JS/TS (`traverse-embedder-web`), Rust (`traverse-embedder`), agents via `traverse-mcp`; Python shells out to `traverse-cli capability-package execute` (**no Python SDK**). Swift/Kotlin/.NET are in-tree only (not certified public packages); edge is planned; cloud placement is an explicit non-goal for v0.1 — see /platforms.html and /what-is-real-today.html. Apache 2.0, pre-1.0 (v0.14.0). The agent proposes; the runtime decides.
> Traverse is a governed capability runtime for portable business logic. Value loop: **discover → execute → trace**. Usual authoring is skill-first plain English via `traverse-capability-author` (contract → WASM → human-reviewed PR); manual authoring still uses Rust→WASM — you do **not** need to write Rust for the usual path. One shared `runtime.wasm`; browser, native desktop, CLI, and MCP are clients/embedders, not different Traverse runtimes. Shipped consumers today: JS/TS (`traverse-embedder-web`), Rust (`traverse-embedder`), agents via `traverse-mcp`; Python shells out to `traverse-cli capability-package execute` (**no Python SDK**). Swift (xcframework on `swift-host-v*` releases), Kotlin (Maven Central `com.traverse-framework:traverse-embedder` 0.14.0), and .NET (nuget.org `TraverseEmbedder` 0.14.0) are published, pre-1.0, and not Certified; edge is planned; cloud placement is an explicit non-goal for v0.1 — see /platforms.html and /what-is-real-today.html. Apache 2.0, pre-1.0 (v0.14.0). The agent proposes; the runtime decides.
- Start here (narrative): https://traverse-framework.com/blog/what-is-real-today-start-here.html
- How do I start with Traverse as an agent?: https://traverse-framework.com/questions/how-do-i-start-with-traverse-as-an-agent.html
- What does Traverse not claim yet?: https://traverse-framework.com/questions/what-does-traverse-not-claim-yet.html
Expand All @@ -9,7 +9,7 @@

Traverse is not a web framework, an agent-orchestration framework, or a general microservices platform. It governs one thing well: a single piece of business logic that must behave identically and auditably on every host where it actually ships. Specs and registry catalog size are governance hygiene, not the pitch.

Current packages: crates.io at 0.14.0 (pin `traverse-registry` at `=0.25.0` if you consume it directly); npm `traverse-embedder-web@0.14.0`.
Current packages: crates.io Traverse at 0.14.0; npm `traverse-embedder-web@0.14.0`. `traverse-registry` **0.27.0** is published (tag `v0.27.0`; exact pins return lifecycle status). Traverse v0.14.0 still pins `=0.25.0` until the consumer slice on traverse#1598 moves. Runtime refusal of `revoked` is not shipped.

## Required reading (agents)

Expand All @@ -25,7 +25,7 @@ Current packages: crates.io at 0.14.0 (pin `traverse-registry` at `=0.25.0` if y
- [Signed model. Exact pin. Bit-identical hosts.](https://traverse-framework.com/blog/signed-exact-ref-digits.html): v0.14.0 weekly demo — signed `digits-mlp-1.0.0` exact-ref package, same bytes on Browser + Node (`ExactModelBrowserHost`); tamper → `digest_mismatch`; test-only key (prod signing #1567). Not catalog `model.execute`. Not Hugging Face.
- [Same WASM. Browser and Node match. Agent still can’t freestyle.](https://traverse-framework.com/blog/same-wasm-multi-host.html): v0.13.0 multi-host — identical `core.authorize@1.2.0` bytes on Browser + Node; agent treasury cheat still denied.
- Weekly demos (public write-ups; repo still private): [signed exact-ref digits](https://traverse-framework.com/blog/signed-exact-ref-digits.html) · [same-wasm multi-host](https://traverse-framework.com/blog/same-wasm-multi-host.html) · [agent freestyle → blocked](https://traverse-framework.com/blog/agent-freestyle-blocked.html) · [How do I run the deny demo?](https://traverse-framework.com/questions/how-do-i-run-the-agent-blocked-weekly-demo.html). Note: `traverse-framework/weekly-demos` is **not publicly cloneable yet** (tracked in [.github#30](https://github.com/traverse-framework/.github/issues/30)) — prefer the blogs until that lands. Access-only tree for this week: `weekly-demos/2026-10-02-signed-exact-ref`.
- [Platforms](https://traverse-framework.com/platforms.html): native + browser shipped; Swift/Kotlin/.NET in progress (not packaged); edge planned; cloud non-goal.
- [Platforms](https://traverse-framework.com/platforms.html): native + browser shipped; Swift/Kotlin/.NET published, pre-1.0, In progress (not Certified); edge planned; cloud non-goal.

## Start here

Expand All @@ -44,7 +44,10 @@ Current packages: crates.io at 0.14.0 (pin `traverse-registry` at `=0.25.0` if y
- [How do I go from a skill draft to a published capability?](https://traverse-framework.com/questions/how-do-i-go-from-skill-draft-to-published-capability.html): after the skill opens the registry PR — review, CI, human merge, next catalog release; no side-door upload.
- [Does capability publish validate model attribution before the registry write?](https://traverse-framework.com/questions/does-capability-publish-validate-model-attribution.html): yes for contract-decidable rules — `traverse-cli capability publish` rejects bad `ai` objects offline before any registry Git write (Decision 109 / Spec 056 v1.1.0 / #1597); keeps `ai` verbatim; evidence digests + rights drift stay registry-CI-only (no CLI network fetch).
- [Does the Traverse registry record model licenses and usage rights?](https://traverse-framework.com/questions/does-the-registry-record-model-rights.html): yes, registry-side (registry spec 026): model-backed contracts declare commercial_use/redistribution/derivatives (`unknown` rejected), LICENSE/NOTICE pinned by sha256, immutable upstream commit, derivation, contract bytes signed; index `usage_class`; signed maintainer declaration, not legal certification; Traverse CLI/runtime enforcement is traverse#1598 (not shipped).
- [What happens when a registry capability version is deprecated or revoked?](https://traverse-framework.com/questions/what-happens-when-a-capability-version-is-revoked.html): nothing is edited or deleted; `deprecated.json` / `revoked.json` siblings; range resolution skips both; per spec 005 + decision 127 exact pins still resolve with a status signal and the runtime decides (fail closed); crate alignment registry#631, Traverse runtime handling traverse#1598.
- [What happens when a registry capability version is deprecated or revoked?](https://traverse-framework.com/questions/what-happens-when-a-capability-version-is-revoked.html): nothing is edited or deleted; `deprecated.json` / `revoked.json` siblings; range resolution skips both; exact pins in published `traverse-registry` 0.27.0 still resolve with lifecycle status (registry#632; #631 closed); runtime refusal is traverse#1598, not shipped in v0.14.0. Narrative: [You don't edit a published capability. You mark it.](https://traverse-framework.com/blog/you-dont-edit-a-published-capability.html).
- [What is the difference between an exact capability pin and a version range?](https://traverse-framework.com/questions/what-is-the-difference-between-an-exact-pin-and-a-version-range.html): a range resolves to the highest active match and skips deprecated and revoked versions; an exact pin in `traverse-registry` 0.27.0 still resolves with lifecycle status and revocation (spec 005 FR-004, decision 127 Q11, registry#632). Traverse v0.14.0 still pins `=0.25.0`. Runtime refusal is traverse#1598, not shipped.
- [What does a status signal on an exact pin mean for a host?](https://traverse-framework.com/questions/what-does-a-status-signal-on-an-exact-pin-mean-for-a-host.html): index `status` (`active` | `deprecated` | `revoked`) is a do-not-run signal the shared `runtime.wasm` is supposed to honor (fail closed). The 0.27.0 crate returns the record and the status; the refusal is not shipped (traverse#1598). Hosts are clients: JS/TS `traverse-embedder-web`, Rust `traverse-embedder`, `traverse-mcp`; Python only via `traverse-cli capability-package execute` (no Python SDK). Swift xcframework on `swift-host-v*` tags; Kotlin Maven Central `com.traverse-framework:traverse-embedder` 0.14.0; .NET nuget.org `TraverseEmbedder` 0.14.0. Published, pre-1.0, not Certified.
- [How should an agent react to a revoked capability during discover?](https://traverse-framework.com/questions/how-should-an-agent-react-to-a-revoked-capability-during-discover.html): do not propose it as active. Range resolution in `traverse-registry` 0.27.0 skips revoked versions. Public `catalog.json` keeps the row with `revoked`. `/discover` skips `deprecated` only. No `revoked.json` on registry main (checked 8 October 2026). The agent proposes; the runtime decides — and that refusal is traverse#1598, not shipped in v0.14.0.
- [What does human review mean for a capability PR?](https://traverse-framework.com/questions/what-does-human-review-mean-for-a-capability-pr.html): a person still merges; skill drafts only; check rule fit, CI, digests, catalog fit.
- [How do I verify a signed capability artifact?](https://traverse-framework.com/questions/how-do-i-verify-a-signed-capability-artifact.html): SHA-256 digest = integrity; Ed25519 signature.json = registry attestation; pin by digest, never a naked URL.
- [How do I review a capability PR as a maintainer?](https://traverse-framework.com/questions/how-do-i-review-a-capability-pr-as-a-maintainer.html): contract fit, green CI (digest/coverage/authoring/licensing), fork artifact mirror before merge; signing automatic after merge; no side door.
Expand Down Expand Up @@ -74,7 +77,7 @@ Current packages: crates.io at 0.14.0 (pin `traverse-registry` at `=0.25.0` if y

## Optional

- [Blog](https://traverse-framework.com/blog.html): engineering write-ups, dated — treat as historical snapshots, not current-state claims. Latest: [Model rights are data, not a README](https://traverse-framework.com/blog/model-rights-are-data.html) (AI model rights from contract to host; publish checks on main, signed registry spec 026 record, host trust roots; runtime enforcement #1598 and prod signing #1567 still open). Also: [Signed model. Exact pin. Bit-identical hosts.](https://traverse-framework.com/blog/signed-exact-ref-digits.html) (v0.14.0 weekly demo; Browser+Node; test-only key). Also: [Domain packs are in scope: print-support](https://traverse-framework.com/blog/print-support-domain-pack.html) (capability pack; none published yet). Also: [v0.14.0: what changed for embedders](https://traverse-framework.com/blog/traverse-0-14-0-what-changed-for-embedders.html) (signed Spec 138; native+web+Swift ExactModelHost exact-ref; test-only digits-mlp key). Also: [Where business logic lives (hosts stay thin)](https://traverse-framework.com/blog/where-business-logic-lives.html). Weekly demo: [Same WASM. Browser and Node match. Agent still can’t freestyle.](https://traverse-framework.com/blog/same-wasm-multi-host.html) (v0.13.0 multi-host). Prior: [agent freestyle → blocked](https://traverse-framework.com/blog/agent-freestyle-blocked.html). Authoring: [You don't need Rust to publish a capability](https://traverse-framework.com/blog/you-dont-need-rust-to-publish-a-capability.html).
- [Blog](https://traverse-framework.com/blog.html): engineering write-ups, dated — treat as historical snapshots, not current-state claims. Latest: [You don't edit a published capability. You mark it.](https://traverse-framework.com/blog/you-dont-edit-a-published-capability.html) (deprecation and revocation leave the contract in place; ranges skip the marker; exact pins in `traverse-registry` 0.27.0 still resolve with lifecycle status, registry#632, #631 closed; runtime refusal is traverse#1598, not shipped in v0.14.0). Also: [Model rights are data, not a README](https://traverse-framework.com/blog/model-rights-are-data.html) (AI model rights from contract to host; publish checks on main, signed registry spec 026 record, host trust roots; runtime enforcement #1598 and prod signing #1567 still open). Also: [Signed model. Exact pin. Bit-identical hosts.](https://traverse-framework.com/blog/signed-exact-ref-digits.html) (v0.14.0 weekly demo; Browser+Node; test-only key). Also: [Domain packs are in scope: print-support](https://traverse-framework.com/blog/print-support-domain-pack.html) (capability pack; none published yet). Also: [v0.14.0: what changed for embedders](https://traverse-framework.com/blog/traverse-0-14-0-what-changed-for-embedders.html) (signed Spec 138; native+web+Swift ExactModelHost exact-ref; test-only digits-mlp key). Also: [Where business logic lives (hosts stay thin)](https://traverse-framework.com/blog/where-business-logic-lives.html). Weekly demo: [Same WASM. Browser and Node match. Agent still can’t freestyle.](https://traverse-framework.com/blog/same-wasm-multi-host.html) (v0.13.0 multi-host). Prior: [agent freestyle → blocked](https://traverse-framework.com/blog/agent-freestyle-blocked.html). Authoring: [You don't need Rust to publish a capability](https://traverse-framework.com/blog/you-dont-need-rust-to-publish-a-capability.html).
- [Discover](https://traverse-framework.com/discover.html): a live browser demo that pulls the public registry and executes a reviewed plan locally. Read [what it proves](https://traverse-framework.com/blog/what-discover-proves.html) before quoting it.
- [Compare: vs microservices](https://traverse-framework.com/compare/vs-microservices.html), [vs serverless](https://traverse-framework.com/compare/vs-serverless.html), [vs function calling](https://traverse-framework.com/compare/vs-function-calling.html), [vs agent runtimes](https://traverse-framework.com/compare/vs-agent-runtimes.html), [vs WASM runtimes](https://traverse-framework.com/compare/vs-wasm-runtimes.html), [vs cross-platform frameworks](https://traverse-framework.com/compare/vs-cross-platform-frameworks.html)
- [About](https://traverse-framework.com/about.html): project history and motivation.
Expand Down
3 changes: 2 additions & 1 deletion src/pages/blog/index.astro
Original file line number Diff line number Diff line change
Expand Up @@ -2,10 +2,11 @@
import SubpageLayout from '@layouts/SubpageLayout.astro';

const posts = [
{ href: '/blog/you-dont-edit-a-published-capability.html', title: "You don't edit a published capability. You mark it.", desc: 'Featured · Oct 8 · Deprecation and revocation leave the contract in place. Ranges skip the marker. Exact pins in traverse-registry 0.27.0 still resolve with lifecycle status (registry#632). Runtime refusal is traverse#1598, not shipped in v0.14.0.' },
{ href: '/blog/model-rights-are-data.html', title: 'Model rights are data, not a README', desc: 'Featured · Oct 6 · AI model rights from contract to host: offline publish checks, signed registry rights record, host trust roots, and what is still open.' },
{ href: '/blog/signed-exact-ref-digits.html', title: 'Signed model. Exact pin. Bit-identical hosts.', desc: 'Featured · Weekly demo: signed digits-mlp-1.0.0 exact-ref package, same bytes on Browser + Node via ExactModelBrowserHost; tamper fail-closed (digest_mismatch). Traverse v0.14.0. Test-only key.' },
{ href: '/blog/print-support-domain-pack.html', title: 'Domain packs are in scope: print-support without an app rewrite', desc: 'Featured · Manufacturing-shaped capability pack under discover→execute→trace; apps-not-ready ≠ no domain packs; hosts stay thin; none of the print.* capabilities published yet. registry#596 · #597–#604 · Discussion #1540.' },
{ href: '/blog/traverse-0-14-0-what-changed-for-embedders.html', title: 'v0.14.0: what changed for embedders', desc: 'Featured · Signed Spec 138 (schema 2.0.0 + model.sig.json), host-owned trust, registerPackage, digits-mlp-1.0.0 (test-only key). Native + web + Swift ExactModelHost execute; Kotlin/.NET do not yet. crates/npm 0.14.0; registry 0.25.0.' },
{ href: '/blog/traverse-0-14-0-what-changed-for-embedders.html', title: 'v0.14.0: what changed for embedders', desc: 'Featured · Signed Spec 138 (schema 2.0.0 + model.sig.json), host-owned trust, registerPackage, digits-mlp-1.0.0 (test-only key). Native + web + Swift ExactModelHost execute; Kotlin/.NET do not execute exact-ref yet. crates/npm 0.14.0; that release pins registry 0.25.0.' },
{ href: '/blog/same-wasm-multi-host.html', title: 'Same WASM. Browser and Node match. Agent still can’t freestyle.', desc: 'Featured · Weekly demo: identical core.authorize@1.2.0 bytes on Browser + Node deny junior_analyst $2.4M wire; allow treasury_ops + MFA/dual-control. Traverse v0.13.0 multi-host.' },
{ href: '/blog/where-business-logic-lives.html', title: 'Where business logic lives (hosts stay thin)', desc: 'Featured · Narrative companion to the where-logic Q&A: capabilities hold non-UI domain rules; hosts = UI + I/O; utilities ≠ ceiling; apps-not-ready ≠ leave logic in the host.' },
{ href: '/blog/what-is-real-today-start-here.html', title: 'Start here: what is real in Traverse today', desc: 'Featured · Narrative companion to /what-is-real-today: discover→execute→trace, skill-first authoring, one shared runtime.wasm, honest consumers, pre-1.0.' },
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -52,14 +52,14 @@ const _body = `
<ul>
<li><strong>Rust native + web</strong> — exact-ref execute shipped in the v0.14.0 product cut.</li>
<li><strong>Swift</strong> — <code>ExactModelHost</code> executes signed exact-ref via the published <code>TraverseSwiftHost</code> xcframework (<code>swift-host-v0.14.0-1</code>) and the in-repo <code>Package.swift</code> binary pin. Still not a CocoaPods / Swift Package Index first-class package; distribution is GitHub Release + SPM binary target.</li>
<li><strong>Kotlin / .NET</strong> — in-tree embedders continue; they do <strong>not</strong> execute exact-ref models yet.</li>
<li><strong>Kotlin / .NET</strong> — published packages (Maven Central <code>com.traverse-framework:traverse-embedder</code> 0.14.0, nuget.org <code>TraverseEmbedder</code> 0.14.0); they do <strong>not</strong> execute exact-ref models yet.</li>
</ul>

<p>SDKs, MCP, and CLI are embedders and clients of the same orchestrator — not different Traverse runtimes.</p>

<h2 id="pins">Pins</h2>

<p>crates.io lockstep at <strong>0.14.0</strong> with <code>traverse-embedder-web@0.14.0</code>. Pin <code>traverse-registry =0.25.0</code> if you consume the registry crate directly.</p>
<p>crates.io lockstep at <strong>0.14.0</strong> with <code>traverse-embedder-web@0.14.0</code>. This release pins <code>traverse-registry</code> at <code>=0.25.0</code>. crates.io has since published <code>traverse-registry</code> 0.27.0.</p>

<h2 id="upgrade">Upgrade</h2>

Expand Down
2 changes: 1 addition & 1 deletion src/pages/blog/what-is-real-today-start-here.astro
Original file line number Diff line number Diff line change
Expand Up @@ -61,7 +61,7 @@ const _body = `
<li><strong>Rust</strong> — crates.io <code>traverse-embedder</code> (published)</li>
<li><strong>Agents</strong> — <code>traverse-mcp</code> (published; stdio bootstrap today)</li>
<li><strong>Python</strong> — CLI only: shell out to <code>traverse-cli capability-package execute</code>. <strong>No Python SDK.</strong></li>
<li><strong>Swift / Kotlin / .NET</strong> — in-tree and usable for experiments; not first-class public packages yet</li>
<li><strong>Swift / Kotlin / .NET</strong> — published, pre-1.0, not Certified: Swift xcframework on <code>swift-host-v*</code> tags, Kotlin <code>com.traverse-framework:traverse-embedder</code> 0.14.0 on Maven Central, .NET <code>TraverseEmbedder</code> 0.14.0 on nuget.org</li>
</ul>

<p>Check <a href="/platforms.html">platforms</a> before assuming a host is shipped. See also <a href="/questions/does-traverse-have-a-python-sdk.html">Does Traverse have a Python SDK?</a>.</p>
Expand Down
Loading
Loading