Skip to content

Commit afcf678

Browse files
authored
Merge pull request #20 from swarmproof/release/v0.2.0
chore(release): v0.2.0
2 parents 8618092 + 362bd6f commit afcf678

4 files changed

Lines changed: 77 additions & 2 deletions

File tree

‎.github/workflows/publish.yml‎

Lines changed: 40 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,40 @@
1+
name: publish
2+
3+
# Publishes to PyPI when a GitHub Release is published, via PyPI Trusted Publishing
4+
# (OIDC — no API token/secret). One-time setup: register this repo + workflow as a
5+
# trusted publisher on PyPI (https://pypi.org/manage/account/publishing/). Until then
6+
# the build job still runs and attaches artifacts to the release.
7+
on:
8+
release:
9+
types: [published]
10+
workflow_dispatch:
11+
12+
jobs:
13+
build:
14+
runs-on: ubuntu-latest
15+
steps:
16+
- uses: actions/checkout@v4
17+
- uses: actions/setup-python@v5
18+
with:
19+
python-version: "3.11"
20+
- run: python -m pip install --upgrade build twine
21+
- run: python -m build
22+
- run: python -m twine check dist/*
23+
- uses: actions/upload-artifact@v4
24+
with:
25+
name: dist
26+
path: dist/
27+
28+
publish-pypi:
29+
needs: build
30+
runs-on: ubuntu-latest
31+
if: github.event_name == 'release'
32+
environment: pypi
33+
permissions:
34+
id-token: write # required for Trusted Publishing (OIDC)
35+
steps:
36+
- uses: actions/download-artifact@v4
37+
with:
38+
name: dist
39+
path: dist/
40+
- uses: pypa/gh-action-pypi-publish@release/v1

‎CHANGELOG.md‎

Lines changed: 35 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,35 @@
1+
# Changelog
2+
3+
All notable changes to costbomb are documented here. Format loosely follows
4+
[Keep a Changelog](https://keepachangelog.com/); versions follow SemVer.
5+
6+
## [0.2.0] — 2026-09-07
7+
8+
First public release — the standalone extract of denial-of-wallet fuzzing.
9+
10+
### Added
11+
- **Cost meter (the oracle)** — sum over sources: model tokens (input/output/reasoning/
12+
cache) + tool-call fees + recursive sub-agent spawn cost. Provider-agnostic price table.
13+
- **Attack library** — 10 cost-explosion classes: `retry-loop`, `tool-storm`,
14+
`context-bomb`, `recursion`, `clarification-trap`, `reasoning-inflation`,
15+
`model-escalation`, `cache-bust`, `tool-cost-asymmetry`, `retrieval-amplification`,
16+
each with honest capability gating.
17+
- **Fuzz engine** — evolutionary search, power schedule, p95-over-k fitness, surrogate
18+
pre-ranking, and a hard own-budget cap (never runs away).
19+
- **CI gate** — baseline + regression detection with price-drift separation.
20+
- **Targets** — Fake / Python / HTTP / Mockworld / Persona, behind one `Target` seam.
21+
- **Proxy meter** — zero-instrumentation metering of a real agent via a base_url swap.
22+
- **Richer cost model** — downstream tool-cost / blast radius, wall-clock / infra cost,
23+
and a duplicate-effect (exactly-once) cross-check backed by the real `exactly_once`
24+
library.
25+
- **Validation** — per-biller reconciliation (`costbomb.validation`) + full-agent LLM
26+
and Stripe test-mode harnesses; report labels modeled vs invoice-backed slices.
27+
- **CLI** — `costbomb run` / `baseline` / `proxy` / `attacks` / `price`, with
28+
`findings.json` + OTel GenAI-profile export.
29+
30+
### Known limitations
31+
- The meter's ≤1% accuracy (NFR-8) is **not yet validated against real invoices**
32+
(`0/20` invoice-grounded fixtures) — see `docs/VALIDATION.md`. Treat as a
33+
well-engineered tool whose oracle is arithmetic-checked but not bill-proven.
34+
35+
[0.2.0]: https://github.com/swarmproof/costbomb/releases/tag/v0.2.0

‎pyproject.toml‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -4,7 +4,7 @@ build-backend = "hatchling.build"
44

55
[project]
66
name = "costbomb"
7-
version = "0.2.0.dev0"
7+
version = "0.2.0"
88
description = "Denial-of-wallet fuzzing for agent systems — find the inputs that make your agent spend $500 to answer a $0.05 question, and gate CI on spend regressions."
99
readme = "README.md"
1010
requires-python = ">=3.11"

‎src/costbomb/__init__.py‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -23,7 +23,7 @@
2323
from costbomb.targets.base import Target, TargetContext
2424
from costbomb.targets.fake import FakeTarget
2525

26-
__version__ = "0.2.0.dev0"
26+
__version__ = "0.2.0"
2727

2828
__all__ = [
2929
"AttackClass",

0 commit comments

Comments
 (0)