Verify the signed release checksum manifest against Pulse's pinned SSH key before either MCP installer accepts a downloaded binary. Remove the unsigned bypass and require one exact digest entry.
Include bare Unix MCP executables in release checksum/signature assembly, cover unavailable, invalid, ambiguous, mismatched, and successful evidence paths with executable regression tests, and enforce MCP installer pins against the configured release key.
Wire outbound alert callbacks before a monitor is published so immediately reconnecting agents cannot create active warnings in the constructor-to-Start gap. Add a pre-Start custom-sensor regression and bind the ordering in monitoring and agent lifecycle contracts.
Change-source: pulse-maintainer
Name every outbound alert-quality field in both operator-facing privacy documents, lock the current schema value in verification, and align the alert-manager adoption test with the telemetry contract.
Change-source: pulse-maintainer
Treat node-scoped HTTP 595 responses as debug-level resource unavailability instead of repeated authentication warnings. Preserve warnings and returned errors for real credential failures.
Refs #1794.
Contract-Neutral: corrects internal log severity without changing API, resource, or extension contracts
Change-source: pulse-maintainer
Keep canonical REST resource projection and owner-snapshot workload mapping aligned with realtime Proxmox backup and runtime evidence. This prevents the overview from showing transient missing backups and uptime before websocket hydration.\n\nRefs #1792
Price Sonnet 5 at its current first-party rate and recognize Fable 5 and Mythos 5 so current models cannot prematurely stop Patrol or make budget enforcement unknown. Refresh the surfaced pricing review date and cover the budget behavior.
Refs #1789