|
| 1 | +# Changelog |
| 2 | + |
| 3 | +All notable changes to costbomb are documented here. Format loosely follows |
| 4 | +[Keep a Changelog](https://keepachangelog.com/); versions follow SemVer. |
| 5 | + |
| 6 | +## [0.2.0] — 2026-09-07 |
| 7 | + |
| 8 | +First public release — the standalone extract of denial-of-wallet fuzzing. |
| 9 | + |
| 10 | +### Added |
| 11 | +- **Cost meter (the oracle)** — sum over sources: model tokens (input/output/reasoning/ |
| 12 | + cache) + tool-call fees + recursive sub-agent spawn cost. Provider-agnostic price table. |
| 13 | +- **Attack library** — 10 cost-explosion classes: `retry-loop`, `tool-storm`, |
| 14 | + `context-bomb`, `recursion`, `clarification-trap`, `reasoning-inflation`, |
| 15 | + `model-escalation`, `cache-bust`, `tool-cost-asymmetry`, `retrieval-amplification`, |
| 16 | + each with honest capability gating. |
| 17 | +- **Fuzz engine** — evolutionary search, power schedule, p95-over-k fitness, surrogate |
| 18 | + pre-ranking, and a hard own-budget cap (never runs away). |
| 19 | +- **CI gate** — baseline + regression detection with price-drift separation. |
| 20 | +- **Targets** — Fake / Python / HTTP / Mockworld / Persona, behind one `Target` seam. |
| 21 | +- **Proxy meter** — zero-instrumentation metering of a real agent via a base_url swap. |
| 22 | +- **Richer cost model** — downstream tool-cost / blast radius, wall-clock / infra cost, |
| 23 | + and a duplicate-effect (exactly-once) cross-check backed by the real `exactly_once` |
| 24 | + library. |
| 25 | +- **Validation** — per-biller reconciliation (`costbomb.validation`) + full-agent LLM |
| 26 | + and Stripe test-mode harnesses; report labels modeled vs invoice-backed slices. |
| 27 | +- **CLI** — `costbomb run` / `baseline` / `proxy` / `attacks` / `price`, with |
| 28 | + `findings.json` + OTel GenAI-profile export. |
| 29 | + |
| 30 | +### Known limitations |
| 31 | +- The meter's ≤1% accuracy (NFR-8) is **not yet validated against real invoices** |
| 32 | + (`0/20` invoice-grounded fixtures) — see `docs/VALIDATION.md`. Treat as a |
| 33 | + well-engineered tool whose oracle is arithmetic-checked but not bill-proven. |
| 34 | + |
| 35 | +[0.2.0]: https://github.com/swarmproof/costbomb/releases/tag/v0.2.0 |
0 commit comments