From 3df203d0b1c7c2ba57e8c71a3072724bce29ba08 Mon Sep 17 00:00:00 2001 From: Cursor Agent Date: Fri, 9 Oct 2026 21:48:06 +0000 Subject: [PATCH] docs(site): separate published exact-ref hosts from main-only packages Published exact-ref execute is native Rust, the web embedder, and Swift ExactModelHost on swift-host-v0.14.0-4. Kotlin and .NET ExactModelHost are on traverse main and are not in the Maven or NuGet 0.14.0 packages (#1651). Co-authored-by: Enrico Piovesan --- public/llms.txt | 8 ++++---- src/pages/blog/index.astro | 2 +- src/pages/blog/model-rights-are-data.astro | 2 +- src/pages/blog/signed-exact-ref-digits.astro | 4 ++-- ...se-0-14-0-what-changed-for-embedders.astro | 15 ++++++++++----- src/pages/changelog.astro | 2 +- src/pages/platforms.astro | 10 +++++----- ...r-dotnet-embedders-run-exact-ref-yet.astro | 17 +++++++++-------- .../how-do-hosts-trust-signed-models.astro | 6 +++--- .../what-does-traverse-not-claim-yet.astro | 4 ++-- src/pages/questions/what-is-digits-mlp.astro | 2 +- .../what-is-exact-ref-model-execution.astro | 8 ++++---- ...ch-hosts-run-signed-exact-ref-models.astro | 19 ++++++++++--------- 13 files changed, 53 insertions(+), 46 deletions(-) diff --git a/public/llms.txt b/public/llms.txt index f640787..8bd5ffe 100644 --- a/public/llms.txt +++ b/public/llms.txt @@ -68,16 +68,16 @@ Current packages: crates.io Traverse at 0.14.0; npm `traverse-embedder-web@0.14. - [Changelog](https://traverse-framework.com/changelog.html): release-by-release history. - [Security & Permanence Audit](https://traverse-framework.com/security-audit.html): every known finding, its GitHub ticket, and its real status — not a marketing page. - [FAQ](https://traverse-framework.com/faq.html) and [Questions](https://traverse-framework.com/questions.html): 70+ specific Q&A pages, mostly long-tail but accurate. -- [What is exact-ref model execution?](https://traverse-framework.com/questions/what-is-exact-ref-model-execution.html): signed schema `2.0.0` + `model.sig.json`; host-owned trust; `digits-mlp-1.0.0` (test-only key; prod signing #1567); native+web+Swift ExactModelHost execute (swift-host-v0.14.0-1 / #1579); Kotlin/.NET not yet (first landed in v0.12.0). Embedder notes: [v0.14.0: what changed for embedders](https://traverse-framework.com/blog/traverse-0-14-0-what-changed-for-embedders.html) · [Release](https://github.com/traverse-framework/traverse/releases/tag/v0.14.0) · [Announcement #1576](https://github.com/orgs/traverse-framework/discussions/1576). -- [How do hosts trust signed models?](https://traverse-framework.com/questions/how-do-hosts-trust-signed-models.html): host-owned trust roots gate `register_package`; pin by digest + `model.sig.json`; test-only digits-mlp key; exact-ref execute native+web+Swift ExactModelHost; Kotlin/.NET not yet — no claimed ONNX generic runner. -- [Which hosts run signed exact-ref models?](https://traverse-framework.com/questions/which-hosts-run-signed-exact-ref-models.html) · [Is production model signing ready?](https://traverse-framework.com/questions/is-production-model-signing-ready.html) · [Can Kotlin or .NET run exact-ref yet?](https://traverse-framework.com/questions/can-kotlin-or-dotnet-embedders-run-exact-ref-yet.html): honest matrix (native+web+Swift ExactModelHost; Kotlin/.NET #1580/#1602); test-only key ≠ prod (#1567). +- [What is exact-ref model execution?](https://traverse-framework.com/questions/what-is-exact-ref-model-execution.html): discover → execute → trace; one shared `runtime.wasm`; signed schema `2.0.0` + `model.sig.json`; host-owned trust; `digits-mlp-1.0.0` (test-only key; prod signing #1567); published exact-ref execute is native + web + Swift ExactModelHost (`swift-host-v0.14.0-4` / #1579); Kotlin and .NET ExactModelHost are on main (#1580, #1602 closed) and are not in Maven/NuGet 0.14.0 (next cuts #1651; first landed in v0.12.0). Embedder notes: [v0.14.0: what changed for embedders](https://traverse-framework.com/blog/traverse-0-14-0-what-changed-for-embedders.html) · [Release](https://github.com/traverse-framework/traverse/releases/tag/v0.14.0) · [Announcement #1576](https://github.com/orgs/traverse-framework/discussions/1576). +- [How do hosts trust signed models?](https://traverse-framework.com/questions/how-do-hosts-trust-signed-models.html): discover → execute → trace; one shared `runtime.wasm`; host-owned trust roots gate `register_package`; pin by digest + `model.sig.json`; test-only digits-mlp key; published exact-ref execute is native+web+Swift ExactModelHost (`swift-host-v0.14.0-4`); Kotlin and .NET ExactModelHost are on main, not in the published 0.14.0 packages (#1651) — no claimed ONNX generic runner. +- [Which hosts run signed exact-ref models?](https://traverse-framework.com/questions/which-hosts-run-signed-exact-ref-models.html) · [Is production model signing ready?](https://traverse-framework.com/questions/is-production-model-signing-ready.html) · [Can Kotlin or .NET run exact-ref yet?](https://traverse-framework.com/questions/can-kotlin-or-dotnet-embedders-run-exact-ref-yet.html): discover → execute → trace; one shared `runtime.wasm`; published exact-ref is native + web 0.14.0 + Swift `swift-host-v0.14.0-4`; Kotlin and .NET ExactModelHost are on main (#1580, #1602 closed) and not in Maven/NuGet 0.14.0 (#1651); test-only key ≠ prod (#1567). - [What is digits-mlp?](https://traverse-framework.com/questions/what-is-digits-mlp.html): first trained exact-ref package in v0.14.0 (UCI digits MLP, 96.10% held-out, bit-identical); test-only signing; not a general LLM. - [Does the website use the latest traverse-embedder-web?](https://traverse-framework.com/questions/does-the-website-use-the-latest-traverse-embedder.html): site pins `^0.14.0` (matching npm) and `/discover` admits its signed demo fixture through `registerPackage`; the site can lag future releases, so product apps pin published packages, not the website demo. - [How does Traverse complement Hugging Face?](https://traverse-framework.com/questions/how-does-traverse-complement-hugging-face.html): Hub = provenance; Traverse = pinned signed client-first capability; not Transformers.js/Hub replacement; no defer promise until a second executor exists. ## Optional -- [Blog](https://traverse-framework.com/blog.html): engineering write-ups, dated — treat as historical snapshots, not current-state claims. Latest: [You don't edit a published capability. You mark it.](https://traverse-framework.com/blog/you-dont-edit-a-published-capability.html) (deprecation and revocation leave the contract in place; ranges skip the marker; exact pins in `traverse-registry` 0.27.0 still resolve with lifecycle status, registry#632, #631 closed; runtime refusal is traverse#1598, not shipped in v0.14.0). Also: [Model rights are data, not a README](https://traverse-framework.com/blog/model-rights-are-data.html) (AI model rights from contract to host; publish checks on main, signed registry spec 026 record, host trust roots; runtime enforcement #1598 and prod signing #1567 still open). Also: [Signed model. Exact pin. Bit-identical hosts.](https://traverse-framework.com/blog/signed-exact-ref-digits.html) (v0.14.0 weekly demo; Browser+Node; test-only key). Also: [Domain packs are in scope: print-support](https://traverse-framework.com/blog/print-support-domain-pack.html) (capability pack; none published yet). Also: [v0.14.0: what changed for embedders](https://traverse-framework.com/blog/traverse-0-14-0-what-changed-for-embedders.html) (signed Spec 138; native+web+Swift ExactModelHost exact-ref; test-only digits-mlp key). Also: [Where business logic lives (hosts stay thin)](https://traverse-framework.com/blog/where-business-logic-lives.html). Weekly demo: [Same WASM. Browser and Node match. Agent still can’t freestyle.](https://traverse-framework.com/blog/same-wasm-multi-host.html) (v0.13.0 multi-host). Prior: [agent freestyle → blocked](https://traverse-framework.com/blog/agent-freestyle-blocked.html). Authoring: [You don't need Rust to publish a capability](https://traverse-framework.com/blog/you-dont-need-rust-to-publish-a-capability.html). +- [Blog](https://traverse-framework.com/blog.html): engineering write-ups, dated — treat as historical snapshots, not current-state claims. Latest: [You don't edit a published capability. You mark it.](https://traverse-framework.com/blog/you-dont-edit-a-published-capability.html) (deprecation and revocation leave the contract in place; ranges skip the marker; exact pins in `traverse-registry` 0.27.0 still resolve with lifecycle status, registry#632, #631 closed; runtime refusal is traverse#1598, not shipped in v0.14.0). Also: [Model rights are data, not a README](https://traverse-framework.com/blog/model-rights-are-data.html) (AI model rights from contract to host; publish checks on main, signed registry spec 026 record, host trust roots; runtime enforcement #1598 and prod signing #1567 still open). Also: [Signed model. Exact pin. Bit-identical hosts.](https://traverse-framework.com/blog/signed-exact-ref-digits.html) (v0.14.0 weekly demo; Browser+Node; test-only key). Also: [Domain packs are in scope: print-support](https://traverse-framework.com/blog/print-support-domain-pack.html) (capability pack; none published yet). Also: [v0.14.0: what changed for embedders](https://traverse-framework.com/blog/traverse-0-14-0-what-changed-for-embedders.html) (signed Spec 138; published exact-ref is native+web+Swift ExactModelHost on `swift-host-v0.14.0-4`; Kotlin and .NET ExactModelHost are on main, not in Maven/NuGet 0.14.0, #1651; test-only digits-mlp key). Also: [Where business logic lives (hosts stay thin)](https://traverse-framework.com/blog/where-business-logic-lives.html). Weekly demo: [Same WASM. Browser and Node match. Agent still can’t freestyle.](https://traverse-framework.com/blog/same-wasm-multi-host.html) (v0.13.0 multi-host). Prior: [agent freestyle → blocked](https://traverse-framework.com/blog/agent-freestyle-blocked.html). Authoring: [You don't need Rust to publish a capability](https://traverse-framework.com/blog/you-dont-need-rust-to-publish-a-capability.html). - [Discover](https://traverse-framework.com/discover.html): a live browser demo that pulls the public registry and executes a reviewed plan locally. Read [what it proves](https://traverse-framework.com/blog/what-discover-proves.html) before quoting it. - [Compare: vs microservices](https://traverse-framework.com/compare/vs-microservices.html), [vs serverless](https://traverse-framework.com/compare/vs-serverless.html), [vs function calling](https://traverse-framework.com/compare/vs-function-calling.html), [vs agent runtimes](https://traverse-framework.com/compare/vs-agent-runtimes.html), [vs WASM runtimes](https://traverse-framework.com/compare/vs-wasm-runtimes.html), [vs cross-platform frameworks](https://traverse-framework.com/compare/vs-cross-platform-frameworks.html) - [About](https://traverse-framework.com/about.html): project history and motivation. diff --git a/src/pages/blog/index.astro b/src/pages/blog/index.astro index fbc4f2d..a29e4c5 100644 --- a/src/pages/blog/index.astro +++ b/src/pages/blog/index.astro @@ -6,7 +6,7 @@ const posts = [ { href: '/blog/model-rights-are-data.html', title: 'Model rights are data, not a README', desc: 'Featured · Oct 6 · AI model rights from contract to host: offline publish checks, signed registry rights record, host trust roots, and what is still open.' }, { href: '/blog/signed-exact-ref-digits.html', title: 'Signed model. Exact pin. Bit-identical hosts.', desc: 'Featured · Weekly demo: signed digits-mlp-1.0.0 exact-ref package, same bytes on Browser + Node via ExactModelBrowserHost; tamper fail-closed (digest_mismatch). Traverse v0.14.0. Test-only key.' }, { href: '/blog/print-support-domain-pack.html', title: 'Domain packs are in scope: print-support without an app rewrite', desc: 'Featured · Manufacturing-shaped capability pack under discover→execute→trace; apps-not-ready ≠ no domain packs; hosts stay thin; none of the print.* capabilities published yet. registry#596 · #597–#604 · Discussion #1540.' }, - { href: '/blog/traverse-0-14-0-what-changed-for-embedders.html', title: 'v0.14.0: what changed for embedders', desc: 'Featured · Signed Spec 138 (schema 2.0.0 + model.sig.json), host-owned trust, registerPackage, digits-mlp-1.0.0 (test-only key). Native + web + Swift ExactModelHost execute; Kotlin/.NET do not execute exact-ref yet. crates/npm 0.14.0; that release pins registry 0.25.0.' }, + { href: '/blog/traverse-0-14-0-what-changed-for-embedders.html', title: 'v0.14.0: what changed for embedders', desc: 'Featured · Signed Spec 138 (schema 2.0.0 + model.sig.json), host-owned trust, registerPackage, digits-mlp-1.0.0 (test-only key). Published exact-ref: native + web + Swift ExactModelHost (swift-host-v0.14.0-4). Kotlin and .NET ExactModelHost are on main, not in Maven/NuGet 0.14.0 (#1651). crates/npm 0.14.0; that release pins registry 0.25.0.' }, { href: '/blog/same-wasm-multi-host.html', title: 'Same WASM. Browser and Node match. Agent still can’t freestyle.', desc: 'Featured · Weekly demo: identical core.authorize@1.2.0 bytes on Browser + Node deny junior_analyst $2.4M wire; allow treasury_ops + MFA/dual-control. Traverse v0.13.0 multi-host.' }, { href: '/blog/where-business-logic-lives.html', title: 'Where business logic lives (hosts stay thin)', desc: 'Featured · Narrative companion to the where-logic Q&A: capabilities hold non-UI domain rules; hosts = UI + I/O; utilities ≠ ceiling; apps-not-ready ≠ leave logic in the host.' }, { href: '/blog/what-is-real-today-start-here.html', title: 'Start here: what is real in Traverse today', desc: 'Featured · Narrative companion to /what-is-real-today: discover→execute→trace, skill-first authoring, one shared runtime.wasm, honest consumers, pre-1.0.' }, diff --git a/src/pages/blog/model-rights-are-data.astro b/src/pages/blog/model-rights-are-data.astro index 9652f59..ec84aa4 100644 --- a/src/pages/blog/model-rights-are-data.astro +++ b/src/pages/blog/model-rights-are-data.astro @@ -52,7 +52,7 @@ const _body = `

4. Host: trust roots belong to the host

-

Traverse v0.14.0 shipped signed model packages (schema 2.0.0 manifests plus a detached Ed25519 model.sig.json). The app pins the manifest digest and the expected rights; the host owns the trusted keys, and apps can't inject their own. A naked URL is never identity. Exact-ref execute runs on native Rust, the web embedder and Swift today; Kotlin and .NET don't execute exact-ref yet. See How do hosts trust signed models?

+

Traverse v0.14.0 shipped signed model packages (schema 2.0.0 manifests plus a detached Ed25519 model.sig.json). The app pins the manifest digest and the expected rights; the host owns the trusted keys, and apps can't inject their own. A naked URL is never identity. Discover → execute → trace, on one shared runtime.wasm. Published exact-ref execute is native Rust, the web embedder, and Swift ExactModelHost (swift-host-v0.14.0-4). Kotlin and .NET ExactModelHost are on traverse main and are not in the published 0.14.0 packages. See How do hosts trust signed models?

What's still open (as of October 6, 2026)

diff --git a/src/pages/blog/signed-exact-ref-digits.astro b/src/pages/blog/signed-exact-ref-digits.astro index 4679410..59c2c9e 100644 --- a/src/pages/blog/signed-exact-ref-digits.astro +++ b/src/pages/blog/signed-exact-ref-digits.astro @@ -81,7 +81,7 @@ const _body = ` BrowserExactModelBrowserHost from traverse-embedder-web@0.14.0. registerPackage(manifestBytes, wasm, signatureBytes). NodeThe same npm host under Node. Not a native Rust CLI invoke. - Not in this proofSwift, Kotlin, and .NET do not execute exact-ref on the published v0.14.0 pins used here. + Not in this proofThis demo is Browser + Node only, on one shared runtime.wasm. Swift ExactModelHost is published separately on swift-host-v0.14.0-4. The published Kotlin and .NET 0.14.0 packages do not include exact-ref execute. @@ -99,7 +99,7 @@ const _body = `
  • Path: ExactModelBrowserHost + registerPackage (not insertVerified). Host-owned trust roots only.
  • Smoke: 0→0, 7→7, 4→4 on Node; Browser label 0 bit-identical to Node; tamper → digest_mismatch; empty trust → key_untrusted.
  • Signing key: test-only fixture. Production signing is traverse#1567. Do not trust this key in a real host.
  • -
  • Not claimed: Hugging Face. Catalog model.execute (the catalog still has none). Swift / Kotlin / .NET exact-ref execute on published 0.14.0. A separate native CLI. A second runtime.
  • +
  • Not claimed: Hugging Face. Catalog model.execute (the catalog still has none). Exact-ref execute from the published Kotlin or .NET 0.14.0 packages. A separate native CLI. A second runtime.
  • Lead claim: one shared runtime.wasm. Hosts = UI + I/O. Discover → execute → trace.
  • diff --git a/src/pages/blog/traverse-0-14-0-what-changed-for-embedders.astro b/src/pages/blog/traverse-0-14-0-what-changed-for-embedders.astro index 1b701da..3b1c2d3 100644 --- a/src/pages/blog/traverse-0-14-0-what-changed-for-embedders.astro +++ b/src/pages/blog/traverse-0-14-0-what-changed-for-embedders.astro @@ -27,11 +27,15 @@ const _body = `

    Traverse v0.14.0 is the signed exact-ref model cut. One shared runtime.wasm. Hosts stay UI + WASI/WIT I/O. Capabilities still discover → execute → trace. The agent proposes; the runtime decides.

    - Short version for embedders: model packages are signed, bound to the app that pins them, and checked against host-owned trust roots. Native Rust, the web embedder, and Swift (ExactModelHost) execute exact-ref models today. Kotlin and .NET do not — yet. + Short version for embedders: discover → execute → trace. One shared runtime.wasm. Model packages are signed, bound to the app that pins them, and checked against host-owned trust roots. Published exact-ref execute: native Rust, the web embedder, and Swift ExactModelHost on swift-host-v0.14.0-4. Kotlin and .NET ExactModelHost are on traverse main and are not in the published 0.14.0 packages.
    - Update (September 30, 2026): overnight after the v0.14.0 product cut, #1579 closed and the published xcframework swift-host-v0.14.0-1 exposes Spec 138 parity. packages/swift/TraverseEmbedder/Package.swift pins that binary target. Digits conformance is byte-identical on Swift (1,727 / 1,797). Kotlin (#1580) and .NET still do not execute exact-ref. + Update (September 30, 2026): overnight after the v0.14.0 product cut, #1579 closed and the published xcframework swift-host-v0.14.0-1 exposed Spec 138 parity. Package.swift pinned that binary target. Digits conformance was byte-identical on Swift (1,727 / 1,797). Kotlin (#1580) and .NET did not execute exact-ref yet. +
    + +
    + Update (October 9, 2026): Package.swift pins swift-host-v0.14.0-4. Kotlin ExactModelHost is on traverse main (#1580, closed). .NET ExactModelHost is on traverse main (#1602, closed). Maven Central com.traverse-framework:traverse-embedder and nuget.org TraverseEmbedder are both still 0.14.0, which does not include exact-ref execute. Next package cuts: #1651.

    Breaking for Spec 138 consumers

    @@ -51,8 +55,9 @@ const _body = `

    SDKs, MCP, and CLI are embedders and clients of the same orchestrator — not different Traverse runtimes.

    @@ -95,7 +100,7 @@ const _body = ` --- diff --git a/src/pages/changelog.astro b/src/pages/changelog.astro index 3b1c21b..2a65867 100644 --- a/src/pages/changelog.astro +++ b/src/pages/changelog.astro @@ -7,7 +7,7 @@ import SubpageLayout from '@layouts/SubpageLayout.astro';

    Release history

    What shipped in Traverse. Each release is backed by versioned, reviewable work.

    View all releases on GitHub →

    -

    Signed exact-ref models + digits-mlp

    v0.14.0 is a minor lockstep crate + npm release with breaking Spec 138 exact-ref surface changes (0.x minor convention). Model manifests move to schema 2.0.0 with detached Ed25519 model.sig.json; host-owned trust roots; first trained digits-mlp-1.0.0 (test-only key; production signing tracked separately). Exact-ref execute is native + web + Swift ExactModelHost (xcframework swift-host-v0.14.0-1 / Package.swift pin; #1579 closed 2026-09-30) — Kotlin/.NET do not execute exact-ref yet. Pin the Traverse crates and npm at 0.14.0. That release pins traverse-registry at =0.25.0; crates.io has since published traverse-registry 0.27.0. Product Release: Traverse v0.14.0.

    +

    Signed exact-ref models + digits-mlp

    v0.14.0 is a minor lockstep crate + npm release with breaking Spec 138 exact-ref surface changes (0.x minor convention). Model manifests move to schema 2.0.0 with detached Ed25519 model.sig.json; host-owned trust roots; first trained digits-mlp-1.0.0 (test-only key; production signing tracked separately). Discover → execute → trace, on one shared runtime.wasm. Published exact-ref execute is native Rust and the web embedder in this cut, plus Swift ExactModelHost on xcframework swift-host-v0.14.0-4 (Package.swift pin; first on swift-host-v0.14.0-1, #1579 closed 2026-09-30). Kotlin ExactModelHost is on main (#1580) and is not in Maven Central 0.14.0. .NET ExactModelHost is on main (#1602) and is not in nuget.org TraverseEmbedder 0.14.0. Next package cuts: #1651. Pin the Traverse crates and npm at 0.14.0. That release pins traverse-registry at =0.25.0; crates.io has since published traverse-registry 0.27.0. Product Release: Traverse v0.14.0.

    App state machine and target-neutral host authorities

    v0.13.0 is a minor lockstep crate + npm release. Its throughline is the discover → execute → trace loop for governed, standalone embedder apps: Spec 139-embedder-app-state-machine-execution lands the app command state machine that drives that loop end to end, and Spec 140-host-authority-wit-adapters gives it target-neutral host authorities — including a real audio-input capability. crates.io and npm packages are at 0.13.0.

    • App state machine (Spec 139): app_command envelopes (embedder-api 1.1.0) and the state machine driver across Swift, Kotlin, .NET, and web, validated against one shared cross-host golden event log. Decision 99: invoke.input_from resolves host_connector_result.<field> at runtime; app validate rejects an unreachable reference.
    • Host authorities and audio-input (Spec 140): WIT host-adapter interfaces make host authorities target-neutral and runtime-owned (Decision 97), landing first for traverse.audio-input. Real adapters: Apple AVAudioEngine (verified on physical microphone hardware) and browser capture / permission. Bounded artifact staging shared by runtime, web, and Swift.
    • Native publish pipelines: automated release workflows for Maven Central, nuget.org, and the Swift TraverseSwiftHost.xcframework; Kotlin TraverseEmbedder at embedder-api 1.1.0 parity.
    • Security hardening (Decision 100): RuntimeWasmHost runs under explicit fuel and memory limits and fails closed on an out-of-bounds guest response; backup restore bounds decompressed archive-member size.
    • Web fixes: event order under reentrant subscriptions, pinned and zero-major registry version ranges, non-string IndexedDB state keys rejected, accurate browser planner truncation, matching JSON types required in browser plans.

    Upgrade note: pin traverse-embedder-web@0.13.0 with crates at 0.13.0 (lockstep). Apps using invoke.input_from with host_connector_result.<field> need Spec 139 0.2.0 / Spec 138 0.3.0 or later. Swift consumers: TraverseSwiftHost now resolves from the swift-host-v0.13.0 release — there is no GitHub Release object for v0.13.0 (immutable-releases policy). The certified runtime.wasm digest changes in this cut (sha256:a254c161…).

    Read the v0.13.0 release notes → · Announcement

    Exact-ref governed model.execute

    v0.12.0 is a minor lockstep crate + npm release. Spec 138-governed-exact-model-execution / ADR-0074 lands host-staged traverse.model-runtime / model.execute for exact pinned WASM model packages on native and browser wasm-cpu. crates.io and npm packages are at 0.12.0.

    • Host-owned package store, single-consume staged I/O refs, and fail-closed policy / pin / digest checks behind Spec 137 model.execute.
    • CPU-WASM guest ABI with the echo fixture under fixtures/models/fixture-echo-1.0.0/; connector contract traverse.model-runtime 2.0.0.
    • traverse-embedder-web exports matching stage / execute / read helpers so browser hosts share the same envelope contract as native ExactModelHostConnector.

    Upgrade note: apps that want local exact-ref models must declare exact_model_dependencies and use matching model_ref digests — provider authority fields on model.execute payloads fail closed. Pin traverse-embedder-web@0.12.0 with crates at 0.12.0. Pin traverse-registry =0.22.0 if you consume it directly. Certified runtime.wasm digest is unchanged from 0.11.0.

    Read the v0.12.0 release notes →

    One real runtime.wasm across native and browser

    v0.11.0 is a minor lockstep crate + npm release. Native hosts and traverse-embedder-web drive the same nested-wasmi capability executor inside an application-owned runtime.wasm, instead of a canned WAT fixture or a hand-rolled TypeScript WASI/emit_event path. Spec 1402 is complete. crates.io and npm packages are at 0.11.0.

    • Nested-wasmi executor in traverse-runtime-wasm; shared engine-agnostic emit_event and placement validation in traverse-contracts.
    • Production RuntimeWasmHost driver; Swift/wasmi, Kotlin/Chicory, and .NET/Wasmtime conform against the real artifact; digest published via the native runtime artifact registry.
    • Browser BundleEmbedder and composedWorkflow load digest-verified runtime/runtime.wasm from the app bundle and retire the interim TypeScript executor.

    Upgrade note: app bundles must include runtime/runtime.wasm and runtime/runtime.wasm.sha256. Bundles without them fail closed at init. Pin traverse-registry =0.21.0 if you consume it directly.

    Read the v0.11.0 release notes →
    diff --git a/src/pages/platforms.astro b/src/pages/platforms.astro index a0d846b..8cb476c 100644 --- a/src/pages/platforms.astro +++ b/src/pages/platforms.astro @@ -26,7 +26,7 @@ const _body = `

    Native — Linux, macOS, Windows

    Shipped -

    The default target and the most mature. traverse-runtime gives you full orchestration — NativeExecutor, ThreadPoolExecutor, and a Wasmtime-backed WasmExecutor for sandboxed capability execution. This is what traverse-cli runs on, and what every quickstart walks you through.

    +

    The default target and the most mature. traverse-runtime gives you full orchestration — NativeExecutor, ThreadPoolExecutor, and a Wasmtime-backed WasmExecutor for sandboxed capability execution. This is what traverse-cli runs on, and what every quickstart walks you through. Signed exact-ref execute (ExactModelHostConnector) shipped in the v0.14.0 crates. Capabilities still discover → execute → trace on one shared runtime.wasm.

    Three things are true here, all shipped. First, the runtime core builds for wasm32-unknown-unknown with native adapters excluded — contracts, registry resolution, routing, traces, and events all run in a browser or edge-WASM guest with your own executor behind CapabilityExecutor. Second: the public Web/TypeScript embedder SDK (traverse-embedder-web), shipped in v0.8.0, loads a bundle, digest-verifies every WASM capability, and executes it directly in the browser's native WebAssembly host through a minimal WASI preview1 shim — no nested engine, no server sidecar. Third, added in v0.10.0: a governed browser-hosted path for executing a single verified capability by exact id and version, either through traverse-cli serve's verified-entrypoint endpoint or along the validated execute_entrypoint flow, returning a result plus a redacted trace receipt (specs 023, 115).

    -

    Scope it honestly: in-browser workflow execution via the embedder SDK is limited to linear, direct-triggered pipelines — event-driven and conditional edges are rejected at init — and the verified-entrypoint path runs one pre-published capability at a time against already-synced registry state rather than an arbitrary live-registry lookup. traverse-embedder-web@0.14.0 is published to npm (aligned with the v0.14.0 cut). The runtime's requested_target placement router still resolves only local; browser execution is reached through these SDKs and endpoints, not by requesting a browser target.

    +

    Scope it honestly: in-browser workflow execution via the embedder SDK is limited to linear, direct-triggered pipelines — event-driven and conditional edges are rejected at init — and the verified-entrypoint path runs one pre-published capability at a time against already-synced registry state rather than an arbitrary live-registry lookup. traverse-embedder-web@0.14.0 is published to npm (aligned with the v0.14.0 cut) and executes signed exact-ref (ExactModelBrowserHost). The runtime's requested_target placement router still resolves only local; browser execution is reached through these SDKs and endpoints, not by requesting a browser target.

    -

    The engine blocker recorded here as of July 19, 2026 is resolved. The wasmi feasibility spike below was adopted the next day: ADR-0014 selected the wasmi Apple runtime profile, ADR-0015 governed a production Swift wasmi C ABI, and Spec 074 (Approved) now defines the resource-control certification conditions. packages/swift/TraverseEmbedder ships a production WasmiHostBridgeClient backed by TraverseSwiftHost — a released XCFramework wrapping the wasmi interpreter behind a narrow C ABI — that enforces host-owned artifact-size, memory, fuel-per-invocation, and I/O limits on every call. The earlier WasmKit path, which never exposed those controls, has been removed from the package entirely (Decision 96, #1469); WasmKit is not supported. The xcframework ships as versioned swift-host-v* GitHub release assets (currently swift-host-v0.14.0-4), and Package.swift pins its checksum.

    +

    The engine blocker recorded here as of July 19, 2026 is resolved. The wasmi feasibility spike below was adopted the next day: ADR-0014 selected the wasmi Apple runtime profile, ADR-0015 governed a production Swift wasmi C ABI, and Spec 074 (Approved) now defines the resource-control certification conditions. packages/swift/TraverseEmbedder ships a production WasmiHostBridgeClient backed by TraverseSwiftHost — a released XCFramework wrapping the wasmi interpreter behind a narrow C ABI — that enforces host-owned artifact-size, memory, fuel-per-invocation, and I/O limits on every call. The earlier WasmKit path, which never exposed those controls, has been removed from the package entirely (Decision 96, #1469); WasmKit is not supported. The xcframework ships as versioned swift-host-v* GitHub release assets (currently swift-host-v0.14.0-4), and Package.swift pins its checksum. That same published xcframework includes ExactModelHost for signed exact-ref execute (GitHub Release + SPM binary target).

    The iOS and macOS clients in reference-apps run embedded: in-process TraverseEmbedder loading a digest-pinned runtime.wasm, with no traverse-cli serve sidecar. What's still open: Spec 529 (approved September 13, 2026) defines one host-neutral Certified/Preview classification across Web, Linux/Rust, Apple, Android, and Windows/.NET, but the five-platform conformance runner it calls for is later work, so no host is Certified today. Treat this as real, resource-bounded, pre-1.0 execution, not a certified release.

    -

    packages/kotlin/TraverseEmbedder has a working ChicoryRuntimeBridge pinned to Chicory 1.7.5. Bundle validation, lifecycle types, and the no-sidecar Compose reference-app integration have all landed — and the package is published on Maven Central as com.traverse-framework:traverse-embedder (0.14.0, lockstep with the core release). Like every host, it's pre-1.0 and not Certified under Spec 529 yet.

    +

    packages/kotlin/TraverseEmbedder has a working ChicoryRuntimeBridge pinned to Chicory 1.7.5. Bundle validation, lifecycle types, and the no-sidecar Compose reference-app integration have all landed — and the package is published on Maven Central as com.traverse-framework:traverse-embedder (0.14.0, lockstep with the core release). Like every host, it's pre-1.0 and not Certified under Spec 529 yet. That published 0.14.0 AAR does not include signed exact-ref execute. ExactModelHost is on traverse main (#1580, closed) and reaches Maven Central only with the next package cut (#1651).

    @@ -89,7 +89,7 @@ const _body = `

    .NET / WinUI

    In progress -

    packages/dotnet/TraverseEmbedder has a working WasmtimeRuntimeBridge pinned to Wasmtime .NET 44.0.0. Request marshalling, event subscriptions, evidence publication, the shared conformance suite, and the no-sidecar WinUI reference-app integration have all landed — and the package is published on nuget.org as TraverseEmbedder (0.14.0, lockstep with the core release). Like every host, it's pre-1.0 and not Certified under Spec 529 yet.

    +

    packages/dotnet/TraverseEmbedder has a working WasmtimeRuntimeBridge pinned to Wasmtime .NET 44.0.0. Request marshalling, event subscriptions, evidence publication, the shared conformance suite, and the no-sidecar WinUI reference-app integration have all landed — and the package is published on nuget.org as TraverseEmbedder (0.14.0, lockstep with the core release). Like every host, it's pre-1.0 and not Certified under Spec 529 yet. That published 0.14.0 package does not include signed exact-ref execute. ExactModelHost is on traverse main (#1602, closed) and reaches nuget.org only with the next package cut (#1651).

    diff --git a/src/pages/questions/can-kotlin-or-dotnet-embedders-run-exact-ref-yet.astro b/src/pages/questions/can-kotlin-or-dotnet-embedders-run-exact-ref-yet.astro index 2c960b7..206247d 100644 --- a/src/pages/questions/can-kotlin-or-dotnet-embedders-run-exact-ref-yet.astro +++ b/src/pages/questions/can-kotlin-or-dotnet-embedders-run-exact-ref-yet.astro @@ -9,7 +9,7 @@ const jsonLd = JSON.stringify({ name: 'Can Kotlin or .NET embedders run exact-ref models in Traverse yet?', acceptedAnswer: { '@type': 'Answer', - text: 'No for exact-ref execute. Kotlin (Maven Central com.traverse-framework:traverse-embedder 0.14.0) and .NET (nuget.org TraverseEmbedder 0.14.0) are published packages and do not execute signed exact-ref models yet (#1580 and #1602). Native Rust, web, and Swift ExactModelHost (swift-host-v0.14.0-1) do, as of v0.14.0 / #1579.', + text: 'Discover → execute → trace. One shared runtime.wasm. Not from the published 0.14.0 packages. Kotlin ExactModelHost is on traverse main (#1580 closed) but Maven Central com.traverse-framework:traverse-embedder is still 0.14.0. .NET ExactModelHost is on traverse main (#1602 closed) but nuget.org TraverseEmbedder is still 0.14.0. Next package cuts: #1651. Published exact-ref execute is native Rust (v0.14.0), traverse-embedder-web@0.14.0, and Swift ExactModelHost on swift-host-v0.14.0-4.', }, }], }); @@ -25,21 +25,22 @@ const relatedLinks = [ --- -

    Short answer: no for Kotlin and .NET exact-ref execute today. The packages are published — Kotlin com.traverse-framework:traverse-embedder 0.14.0 on Maven Central, .NET TraverseEmbedder 0.14.0 on nuget.org — and they do not have Spec 138 exact-ref parity yet.

    +

    Short answer: discover → execute → trace, on one shared runtime.wasm. Not from the published packages. Kotlin com.traverse-framework:traverse-embedder 0.14.0 on Maven Central and .NET TraverseEmbedder 0.14.0 on nuget.org do not include exact-ref execute. Both ExactModelHost implementations are on traverse main. The next package cuts are #1651.

    -

    What works instead

    -

    Native Rust and the web embedder execute signed exact-ref in the v0.14.0 cut. Swift ExactModelHost reached parity via swift-host-v0.14.0-1 (#1579) — GitHub Release + SPM binary target, not a CocoaPods claim. Full matrix: Which hosts run signed exact-ref models?.

    +

    What a published consumer can run

    +

    Native Rust and the web embedder execute signed exact-ref in the v0.14.0 cut. Swift ExactModelHost is in the published xcframework swift-host-v0.14.0-4, which Package.swift pins (first on swift-host-v0.14.0-1, #1579). Distribution is GitHub Release + SPM binary target, not a CocoaPods claim. Full matrix: Which hosts run signed exact-ref models?.

    -

    Tracked gaps

    +

    On main, not in the published package

      -
    • Kotlin: #1580
    • -
    • .NET: #1602
    • +
    • Kotlin ExactModelHost: #1580 closed. Maven Central still lists 0.13.0 and 0.14.0. The 0.14.0 AAR was published 2026-09-29, before the host.
    • +
    • .NET ExactModelHost: #1602 closed. nuget.org still lists 0.13.0 and 0.14.0.
    • +
    • Next cuts for both packages: #1651.

    Honest consumers

    diff --git a/src/pages/questions/how-do-hosts-trust-signed-models.astro b/src/pages/questions/how-do-hosts-trust-signed-models.astro index 22d782a..a72e07b 100644 --- a/src/pages/questions/how-do-hosts-trust-signed-models.astro +++ b/src/pages/questions/how-do-hosts-trust-signed-models.astro @@ -9,7 +9,7 @@ const jsonLd = JSON.stringify({ name: 'How do hosts trust signed models in Traverse?', acceptedAnswer: { '@type': 'Answer', - text: 'As of Traverse v0.14.0 (signed Spec 138), model packages use schema 2.0.0 manifests plus a detached Ed25519 model.sig.json. Host-owned trust roots gate register_package / registerPackage; apps never add trust. Pin by digest and signature, never a naked URL. The first trained package digits-mlp-1.0.0 ships with a test-only key; production signing is #1567. Exact-ref execute is native Rust, web, and Swift ExactModelHost (swift-host-v0.14.0-1); Kotlin and .NET do not execute exact-ref yet. ONNX as a generic runner is not shipped.', + text: 'Discover → execute → trace. One shared runtime.wasm. As of Traverse v0.14.0 (signed Spec 138), model packages use schema 2.0.0 manifests plus a detached Ed25519 model.sig.json. Host-owned trust roots gate register_package / registerPackage; apps never add trust. Pin by digest and signature, never a naked URL. The first trained package digits-mlp-1.0.0 ships with a test-only key; production signing is #1567. Published exact-ref execute is native Rust, web, and Swift ExactModelHost (swift-host-v0.14.0-4). Kotlin and .NET ExactModelHost are on traverse main and are not in the published 0.14.0 packages (#1651). ONNX as a generic runner is not shipped.', }, }], }); @@ -28,7 +28,7 @@ const relatedLinks = [ --- The first trained package digits-mlp-1.0.0 is signed with a test-only key so CI and demos can exercise the path. Production model signing is tracked separately as #1567. Do not treat the test key as a production trust root.

    Host honesty

    -

    Exact-ref execute is implemented on native Rust, the web embedder, and Swift ExactModelHost (xcframework swift-host-v0.14.0-1 + Package.swift pin). Kotlin and .NET do not execute exact-ref yet — check Platforms. This page is about signed-model trust for Spec 138 exact-ref; it does not claim a generic ONNX runner is shipped. Deeper loop: What is exact-ref model execution?

    +

    Discover → execute → trace, on one shared runtime.wasm. Published exact-ref execute is native Rust, the web embedder, and Swift ExactModelHost (xcframework swift-host-v0.14.0-4 + Package.swift pin). Kotlin and .NET ExactModelHost are on traverse main and are not in the published 0.14.0 packages (#1651) — check Platforms. This page is about signed-model trust for Spec 138 exact-ref; it does not claim a generic ONNX runner is shipped. Deeper loop: What is exact-ref model execution?

    diff --git a/src/pages/questions/what-does-traverse-not-claim-yet.astro b/src/pages/questions/what-does-traverse-not-claim-yet.astro index 6a72216..3ba4e4b 100644 --- a/src/pages/questions/what-does-traverse-not-claim-yet.astro +++ b/src/pages/questions/what-does-traverse-not-claim-yet.astro @@ -9,7 +9,7 @@ const jsonLd = JSON.stringify({ name: 'What does Traverse not claim yet?', acceptedAnswer: { '@type': 'Answer', - text: 'Traverse does not claim a Python SDK; that Swift/Kotlin/.NET hosts are Certified; that Kotlin or .NET execute exact-ref yet; that it is a general agent-orchestration framework or web framework; cloud placement as a v0.1 goal; invented customers or production SLAs; or that approved-spec counts are the product pitch. Swift, Kotlin, and .NET packages are published and pre-1.0. Shipped consumers today are JS/TS and Rust embedders plus MCP; Python is CLI-only; check platforms.html and what-is-real-today.html before assuming a host.', + text: 'Traverse does not claim a Python SDK; that Swift/Kotlin/.NET hosts are Certified; that the published Kotlin or .NET 0.14.0 packages execute exact-ref (both ExactModelHost types are on main; package cuts are #1651); that it is a general agent-orchestration framework or web framework; cloud placement as a v0.1 goal; invented customers or production SLAs; or that approved-spec counts are the product pitch. Discover → execute → trace. One shared runtime.wasm. Swift ExactModelHost is published on swift-host-v0.14.0-4. Swift, Kotlin, and .NET packages are published and pre-1.0. Shipped consumers today are JS/TS and Rust embedders plus MCP; Python is CLI-only; check platforms.html and what-is-real-today.html before assuming a host.', }, }], }); @@ -37,7 +37,7 @@ const relatedLinks = [

    Consumers and packages

    • No Python SDK. Python shells out to traverse-cli capability-package execute. See Does Traverse have a Python SDK?.
    • -
    • Swift / Kotlin / .NET packages are published and pre-1.0 (Swift xcframework on swift-host-v* tags, Kotlin com.traverse-framework:traverse-embedder 0.14.0 on Maven Central, .NET TraverseEmbedder 0.14.0 on nuget.org). They are marked In progress. No host is Certified. Kotlin and .NET do not execute exact-ref yet.
    • +
    • Swift / Kotlin / .NET packages are published and pre-1.0 (Swift xcframework on swift-host-v* tags, currently swift-host-v0.14.0-4, Kotlin com.traverse-framework:traverse-embedder 0.14.0 on Maven Central, .NET TraverseEmbedder 0.14.0 on nuget.org). They are marked In progress. No host is Certified. Swift ExactModelHost on that xcframework executes exact-ref. Kotlin and .NET ExactModelHost are on traverse main and are not in those 0.14.0 packages (#1651).
    • Edge is planned; cloud placement is an explicit non-goal for v0.1.
    diff --git a/src/pages/questions/what-is-digits-mlp.astro b/src/pages/questions/what-is-digits-mlp.astro index 703eadf..cdd3789 100644 --- a/src/pages/questions/what-is-digits-mlp.astro +++ b/src/pages/questions/what-is-digits-mlp.astro @@ -36,7 +36,7 @@ const relatedLinks = [

    A 64→32→10 multilayer perceptron trained on the UCI Optical Recognition of Handwritten Digits dataset (CC BY 4.0). Held-out accuracy is 96.10%. The guest runs bit-identically in the trainer, on the native host, and in the browser embedder — same pinned bytes, same scores.

    How it fits the product

    -

    Exact-ref means the app pins the package by digest and signature and calls governed model.execute — never a naked URL. See What is exact-ref model execution?. Hosts that execute that path today: native Rust, web, and Swift ExactModelHost (swift-host-v0.14.0-1). Kotlin and .NET do not execute exact-ref yet.

    +

    Exact-ref means the app pins the package by digest and signature and calls governed model.execute — never a naked URL. Discover → execute → trace, on one shared runtime.wasm. See What is exact-ref model execution?. Published hosts that execute that path: native Rust, web, and Swift ExactModelHost (swift-host-v0.14.0-4). Kotlin and .NET ExactModelHost are on traverse main and are not in the published 0.14.0 packages.

    Honest limits

      diff --git a/src/pages/questions/what-is-exact-ref-model-execution.astro b/src/pages/questions/what-is-exact-ref-model-execution.astro index cce8e03..d73c1fe 100644 --- a/src/pages/questions/what-is-exact-ref-model-execution.astro +++ b/src/pages/questions/what-is-exact-ref-model-execution.astro @@ -9,7 +9,7 @@ const jsonLd = JSON.stringify({ name: 'What is exact-ref model execution in Traverse?', acceptedAnswer: { '@type': 'Answer', - text: 'Exact-ref model execution is how Traverse runs a WASM model package that an app has pinned by digest and signature — never by a naked URL. Hosts call the Spec 137 model.execute surface with opaque input_ref / output_ref handles. As of Traverse v0.14.0, packages use schema 2.0.0 manifests plus a detached Ed25519 model.sig.json; host-owned trust roots gate register_package; the first trained digits-mlp-1.0.0 ships signed with a test-only key (production signing is separate). Exact-ref execute is implemented on native Rust, web, and Swift ExactModelHost (Package.swift pin to swift-host-v0.14.0-1); Kotlin and .NET do not execute exact-ref yet. First landed in v0.12.0; Swift parity closed #1579 on 2026-09-30.', + text: 'Exact-ref model execution is how Traverse runs a WASM model package that an app has pinned by digest and signature — never by a naked URL. Discover → execute → trace. One shared runtime.wasm; embedders are clients. Hosts call the Spec 137 model.execute surface with opaque input_ref / output_ref handles. As of Traverse v0.14.0, packages use schema 2.0.0 manifests plus a detached Ed25519 model.sig.json; host-owned trust roots gate register_package; the first trained digits-mlp-1.0.0 ships signed with a test-only key (production signing is separate). Published exact-ref execute: native Rust, web, and Swift ExactModelHost (Package.swift pin to swift-host-v0.14.0-4). Kotlin and .NET ExactModelHost are on traverse main and are not in the published 0.14.0 packages (#1651). First landed in v0.12.0; Swift parity closed #1579 on 2026-09-30.', }, }], }); @@ -31,7 +31,7 @@ const relatedLinks = [ --- What landed in v0.14.0

      Spec 138 first shipped in v0.12.0 (see the historical v0.12.0 write-up). v0.14.0 adds signed packages, host-owned trust, machine-readable rights, and the first trained model digits-mlp-1.0.0 (64→32→10 MLP on UCI digits, CC BY 4.0, 96.10% held-out, bit-identical trainer / native / browser). That package is signed with the test-only key; production model signing is #1567.

      -

      Host honesty: exact-ref execute is implemented in the Rust native runtime, the web embedder, and Swift ExactModelHost (published xcframework swift-host-v0.14.0-1; Package.swift binary pin; digits conformance byte-identical). Kotlin and .NET do not execute exact-ref yet. Pin the Traverse crates and npm at 0.14.0. That release still pins traverse-registry at =0.25.0; crates.io has since published traverse-registry 0.27.0.

      +

      Host honesty: discover → execute → trace, on one shared runtime.wasm. Published exact-ref execute is the Rust native runtime, the web embedder, and Swift ExactModelHost (published xcframework swift-host-v0.14.0-4; Package.swift binary pin). Kotlin ExactModelHost is on traverse main (#1580, closed) and is not in Maven Central com.traverse-framework:traverse-embedder 0.14.0. .NET ExactModelHost is on traverse main (#1602, closed) and is not in nuget.org TraverseEmbedder 0.14.0. Next package cuts: #1651. Pin the Traverse crates and npm at 0.14.0. That release still pins traverse-registry at =0.25.0; crates.io has since published traverse-registry 0.27.0.

      What it is not

      -

      It is not “the model is in charge.” It is not Spec 045. It is not a guest model_invoke import — that stays out of scope for Spec 138 v1. And it is not permission to treat a URL as a model identity, or to assume Kotlin/.NET already execute exact-ref.

      +

      It is not “the model is in charge.” It is not Spec 045. It is not a guest model_invoke import — that stays out of scope for Spec 138 v1. And it is not permission to treat a URL as a model identity, or to assume the published Kotlin or .NET 0.14.0 packages already execute exact-ref.

      diff --git a/src/pages/questions/which-hosts-run-signed-exact-ref-models.astro b/src/pages/questions/which-hosts-run-signed-exact-ref-models.astro index d343a70..1fd7a54 100644 --- a/src/pages/questions/which-hosts-run-signed-exact-ref-models.astro +++ b/src/pages/questions/which-hosts-run-signed-exact-ref-models.astro @@ -9,7 +9,7 @@ const jsonLd = JSON.stringify({ name: 'Which hosts run signed exact-ref models in Traverse?', acceptedAnswer: { '@type': 'Answer', - text: 'As of Traverse v0.14.0 and swift-host-v0.14.0-1: native Rust, the web embedder, and Swift ExactModelHost execute signed exact-ref models (Spec 138). Kotlin and .NET embedders do not execute exact-ref yet (tracked #1580 and #1602). digits-mlp-1.0.0 uses a test-only signing key; production custody is #1567. No generic ONNX runner is shipped. One shared runtime.wasm; embedders are clients.', + text: 'Discover → execute → trace. One shared runtime.wasm; embedders are clients. Published exact-ref execute: native Rust in the v0.14.0 crates, traverse-embedder-web@0.14.0, and Swift ExactModelHost on the published xcframework swift-host-v0.14.0-4 (Package.swift binary pin; GitHub Release + SPM, not CocoaPods). Kotlin ExactModelHost is on traverse main (#1580 closed) but Maven Central com.traverse-framework:traverse-embedder is still 0.14.0, which does not include it. .NET ExactModelHost is on traverse main (#1602 closed) but nuget.org TraverseEmbedder is still 0.14.0, which does not include it. Next package cuts: #1651. digits-mlp-1.0.0 uses a test-only key; production custody is #1567. No generic ONNX runner.', }, }], }); @@ -26,21 +26,22 @@ const relatedLinks = [ --- -

      Short answer: native Rust, web (traverse-embedder-web), and Swift ExactModelHost execute signed exact-ref models today. Kotlin and .NET do not — yet. Pin by digest and signature; never treat a naked URL as identity.

      +

      Short answer: discover → execute → trace, on one shared runtime.wasm. Published exact-ref execute is native Rust, the web embedder, and Swift ExactModelHost. Kotlin and .NET ExactModelHost are on traverse main and are not in the published 0.14.0 packages, so Maven Central and nuget.org still cannot run exact-ref. Pin by digest and signature; never treat a naked URL as identity.

      -

      Honest matrix (v0.14.0 / swift-host-v0.14.0-1)

      +

      Honest matrix (checked 9 October 2026)

        -
      • Native Rust — exact-ref execute shipped in the v0.14.0 product cut.
      • -
      • Web — traverse-embedder-web@0.14.0 executes exact-ref.
      • -
      • Swift — ExactModelHost via published xcframework swift-host-v0.14.0-1 and in-repo Package.swift binary pin (#1579). Distribution is GitHub Release + SPM binary target — not a CocoaPods / Swift Package Index first-class package claim.
      • -
      • Kotlin — published com.traverse-framework:traverse-embedder 0.14.0 on Maven Central; no exact-ref execute yet (#1580).
      • -
      • .NET — published TraverseEmbedder 0.14.0 on nuget.org; no exact-ref execute yet (#1602).
      • +
      • Native Rust — exact-ref execute shipped in the v0.14.0 product cut (ExactModelHostConnector).
      • +
      • Web — published traverse-embedder-web@0.14.0 executes exact-ref (ExactModelBrowserHost).
      • +
      • Swift — ExactModelHost is in the published xcframework swift-host-v0.14.0-4, which Package.swift pins. The first ExactModelHost xcframework was swift-host-v0.14.0-1 (#1579). Distribution is GitHub Release + SPM binary target — not a CocoaPods / Swift Package Index package.
      • +
      • Kotlin — ExactModelHost is on traverse main (#1580, closed). Maven Central com.traverse-framework:traverse-embedder is still 0.14.0 (0.13.0 and 0.14.0 only; 0.14.0 published 2026-09-29, before the host). That package does not execute exact-ref.
      • +
      • .NET — ExactModelHost is on traverse main (#1602, closed). nuget.org TraverseEmbedder is still 0.14.0 (0.13.0 and 0.14.0 only). That package does not execute exact-ref.
      • +
      • Next package cuts — #1651. Until those publish, resolving the 0.14.0 Kotlin or .NET package does not run exact-ref.

      Signing honesty