Index and query commands: README.md. New entries go at the end.
U-20260605-01 · 2026-06-05 · QA framework: assertions, data-driven runs, suites, flaky · #release #qa #testing
Nine additions that turn the automation primitives into a full QA / test
framework: assert screen state, drive scripts from data, detect and
quarantine flaky tests, run a scored suite, emit CI-native reports, audit
accessibility / i18n, fan a script across a device matrix, and assert on
audio / video. Each ships with a headless API, an AC_* executor command,
an ac_* MCP tool, and a Qt GUI tab. Full reference page:
docs/source/Eng/doc/new_features/v3_features_doc.rst.
Assertions
- Assertion DSL — verify screen state instead of only driving it:
assert_text(OCR,regex+present=Falsefor absence),assert_image,assert_pixel,assert_window,assert_clipboard(equals/contains/regex,present=Falseto confirm a secret was cleared),assert_process(a named process is / isn't running, via psutil). Returns anAssertionResult; raisesAutoControlAssertionExceptionon mismatch with optional failure screenshot (AC_assert_text / _image / _pixel / _window / _clipboard / _process). - Off-screen assertions —
assert_file(existence / substring / SHA-256 / minimum size — verify a download or export) andassert_http(an http/https endpoint returns a status + optional body text, always with an explicit timeout). Both extend the DSL beyond the screen and plug into the combinators below (AC_assert_file / AC_assert_http). - Assertion combinators —
assert_all([...specs])runs a batch as soft assertions (every spec is checked, all failures collected before raising) and returns aGroupAssertionResult;assert_any([...specs])is the OR-complement (passes when at least one spec passes, short-circuiting — e.g. either a success dialog or a redirect confirms a login);assert_eventually(spec, timeout, interval)retries one declarative assertion spec until it passes or times out (e.g. poll a health endpoint until it returns 200, or wait for a download file to appear). Both are spec-driven ({"kind": "text", "text": "Saved"},{"kind": "http", "url": "..."}) so they work identically from Python, JSON, and MCP across every assertion kind — text/image/pixel/window/clipboard/process/file/http (AC_assert_all / AC_assert_eventually). - Media assertions —
assert_audio_activity(record + RMS threshold for sound vs silence) andassert_video_changes(mean frame-to-frame diff over a segment for motion vs static); pure numeric cores, lazysounddevice/ OpenCV (AC_assert_audio / AC_assert_video_changes).
Data-driven execution
- Data sources —
load_rowsconnectors for CSV / JSON / SQLite / Excel / inline; theAC_for_each_rowblock command runs a body once per row with${row.column}access. SQLite is single read-onlySELECT/WITHonly; paths arerealpath-validated.${var}interpolation now resolves dotted dict-key / list-index paths while preserving types (AC_load_data).
Flaky detection & quarantine
- Flaky report — score intermittent failures from run history by pass↔fail flip rate, grouped by script / source (
AC_flaky_report). - Quarantine — a persistent (mode 0600) skip-list the suite runner honours;
auto_quarantine_from_flakinessauto-populates it above a flip-rate threshold (AC_quarantine_add / _remove / _list / _clear / _auto).
Suite runner + CI reports
- QA suite orchestration —
run_suiteturns action lists into scored cases with setup / teardown, tags, and data-driven expansion; assertion failures → failed, other exceptions → error, quarantined → skipped (AC_run_suite). - JUnit / Allure reports —
write_junit_xml+write_allure_results(orjunit_path/allure_dironAC_run_suite) emit reports Jenkins / GitHub Actions / GitLab CI / Allure parse natively.
Audit, matrix, media
- Accessibility / i18n audit — reuse the a11y tree + OCR to find missing accessible names, WCAG contrast-ratio failures, and ellipsis-truncated strings (
AC_audit_accessibility / AC_audit_contrast). - Mobile device matrix — fan one action list across many Android / iOS devices in parallel, each on an isolated executor, targeting the current device via
${device.*}; per-device pass/fail, failures isolated (AC_run_device_matrix).
U-20260617-01 · 2026-06-17 · Humanized input, macros, parallel runs, cron, file signing · #release #input #flow-control
Thirty-plus automation primitives across input realism, vision, flow
control, triggers, window management, and file security — plus recoverable
deletion and an editor undo. Each ships with a headless API, an AC_*
executor command, and a visual Script Builder entry; vision and window
features keep their geometry / IO operations injectable so the logic is
fully unit-tested. Full reference page:
docs/source/Eng/doc/new_features/v4_features_doc.rst.
Human-like input
- Human-like mouse motion —
move_mouse_humanizedwalks an eased, bowed cubic-Bezier path with optional overshoot + jitter, deterministic byseed(AC_human_move). - Human-like typing —
type_text_humanizedtypes character by character with a jittered per-key delay and optional "thinking" pauses, seedable (AC_human_type).
Vision
- VLM natural-language assertion —
assert_by_descriptionasks a vision-language model whether the screen matches a description; theverify()companion tolocate_by_description(AC_assert_vlm). - Scroll-to-find —
scroll_until_visiblescrolls a direction until a template image or OCR text appears, or the budget runs out (AC_scroll_to_find). - Region colour stats —
region_color_statsreports a region's average + dominant colour and that colour's pixel fraction (AC_region_color_stats). - QR reading —
read_qr_codesdecodes QR codes in a screen region via OpenCV'sQRCodeDetector(no new dependency) (AC_read_qr).
Flow control & variables
- Reusable macros —
AC_define_macro/AC_call_macro: define a named, parameterised action sub-routine once and call it with${arg}bindings. - In-process parallel —
AC_parallelruns branch action lists concurrently, each on an isolated executor so branches never race on shared variables. - Performance-budget assertion —
assert_duration/AC_assert_durationfails a block that takes longer than a millisecond budget. - Read into a variable —
AC_ocr_to_var,AC_shell_to_var,AC_read_file_to_var,AC_http_to_var(body or dotted JSON path),AC_now_to_var(strftime),AC_random_to_var(seeded int / float / choice). - Transform a variable —
AC_transform_var: upper / lower / strip / title / replace / regex-extract / slice, in place or into a new variable. - Assert a variable —
assert_variable/AC_assert_var: eq / ne / lt / gt / contains / regex through the assertion DSL.
Triggers & smart waits
- Composite triggers —
AllOfTrigger/AnyOfTrigger/SequenceTriggercombine any existing trigger by boolean AND / OR / ordered sequence. - Cron trigger —
CronTriggerfires on a five-field cron expression, composing with the boolean triggers (e.g. "at 09:00 and only if the image is on screen"). - More smart waits —
wait_until_clipboard_changes(AC_wait_clipboard_change) andwait_until_window_closed(AC_wait_window_closed).
Window management
- Per-window capture —
capture_windowscreenshots exactly a window's bounds by title (AC_capture_window). - Layout save / restore —
save_window_layout/restore_window_layoutsnapshot every window's position to JSON and move them all back later (AC_save_window_layout/AC_restore_window_layout). - Snap / tile —
snap_windowmoves a window to a screen half, quarter, or maximize (AC_snap_window).
File security & safety
- Action-file signing —
sign_action_file/verify_action_file(HMAC-SHA256 sidecar);execute_filescan require signatures viaJE_AUTOCONTROL_REQUIRE_SIGNED_ACTIONS(AC_sign_action_file/AC_verify_action_file). - Action-file encryption —
encrypt_action_file/decrypt_action_file(Fernet, AES-128-CBC + HMAC) (AC_encrypt_action_file/AC_decrypt_action_file). - Recoverable deletion —
move_to_trashsends a file to the OS recycle bin (Win32SHFileOperationundo flag / macOS Trash / Linux XDG trash, preferringsend2trash) (AC_move_to_trash).
Reporting & notifications
- Screenshot annotation —
annotate_screenshotdraws labelled boxes / translucent highlights / arrows / text onto a capture (AC_annotate_screenshot). - Desktop notifications —
notifyshows a cross-platform toast (notify-send / osascript / PowerShell), injection-safe (AC_notify).
GUI
- Recording Editor undo — every edit is snapshotted; Ctrl+Z (and an Undo button) restore the prior state.
- Triggers tab — "Combine selected" wraps chosen triggers into a composite; new Cron trigger type.
- Assertions tab — new VLM ("screen matches description") assertion kind.
- Every new
AC_*command appears in the visual Script Builder.
Fixes — repaired the USB-passthrough approval-prompt crash on PySide6 6.11.1 (Q_ARG(object) → a Qt signal), eight stale / broken GUI + USB tests, two lost exception chains, and brought thirteen functions back under the cyclomatic-complexity gate.
U-20260618-01 · 2026-06-18 · CLI, recording-to-code, HTTP/SQL/email/PDF steps, waits · #release #cli #integration
Eight headless capabilities that round out scripting, integration, and CI
use: a real command-line interface, recording-to-code generation, and
first-class HTTP / SQL / email / PDF / wait steps. Each ships a headless
Python API, an AC_* executor command, an MCP tool, and a visual Script
Builder entry, and is covered by headless tests (network / SMTP / PDF
backends are injected, so nothing touches the outside world). Full
reference page:
docs/source/Eng/doc/new_features/v5_features_doc.rst.
Command-line interface
je_auto_controlconsole script — run and inspect action files from a shell / CI:run(with--var,--dry-run),validate(aliaslint),list-commands,fmt,record,codegen,version.
Code generation
- Recording → code —
generate_code/generate_code_file(AC_generate_code,je_auto_control codegen) turn a recording or action file into a pytest test, standalone Python, or Robot suite. The defaultcallsstyle emits readableac.<fn>(...)statements, falling back toac.execute_action([...])for flow control.
Integrations
- HTTP / API —
http_request(AC_http_request): method, headers, JSON or raw body, basic / bearer auth, explicit timeout; non-2xx responses are returned (not raised) so you can assert on status.AC_http_to_varnow shares the client and can POST bodies. - SQL —
query_sqlite(AC_sql_to_var/AC_assert_db): read-only, parameter-bound SQLite queries into a variable, or a scalar assertion (e.g.SELECT COUNT(*) ... == 0). - Email (SMTP) —
send_email(AC_send_email): stdlib SMTP with TLS on by default (STARTTLS or implicit SSL over a verified context), attachments, and multiple recipients. - PDF —
extract_pdf_text/pdf_metadata/assert_pdf_text(AC_pdf_to_var/AC_assert_pdf_text): text extraction and content assertions, backed by the optionalpypdfextra (pip install je_auto_control[pdf]).
Smart waits
- Wait for a file —
wait_until_file(AC_wait_for_file) blocks until a file exists and its size stops growing (a download finished writing). - Wait for a TCP port —
wait_until_port(AC_wait_for_port) blocks untilhost:portaccepts connections (pairs withlaunch_process). - Wait for a process —
wait_until_process(AC_wait_for_process) blocks until a process appears or exits — the companion tolaunch_process/kill_process(requires psutil).
Security — HTTP / SMTP enforce http/https or TLS with verified certificates and explicit timeouts; SQL is read-only and parameter-bound; file paths are resolved before I/O.
U-20260619-01 · 2026-06-19 · Agent observability, compliance reports, approvals, SDK · #release #agent #compliance
Caption screenshots into a walkthrough video. Full reference: docs/source/Eng/doc/new_features/v39_features_doc.rst.
write_step_video(AC_write_step_video,ac_write_step_video): turns per-step screenshots into a shareable video where each frame is held for a few seconds with its caption and a pass/fail colour banner burned in. The assembly logic (build_overlay_plan/render_overlay_frame) is separated from OpenCV via injectableloader/drawer/writer_factoryhooks — unit-testable with fakes and nocv2/numpydependency; the real path lazily importscv2only when those hooks are absent. The visual companion to the HTML/JSON reports.
OTel GenAI-convention spans for LLM runs. Full reference: docs/source/Eng/doc/new_features/v38_features_doc.rst.
AgentTrace(AC_trace_record/AC_trace_summary/AC_trace_export/AC_trace_reset,ac_*): records spans whose attributes follow the OpenTelemetry GenAI semantic conventions (gen_ai.operation.name,gen_ai.system,gen_ai.request.model,gen_ai.usage.input_tokens/output_tokens,gen_ai.tool.name) and the"{operation} {model}"span name.to_otel()drops into an OTLP exporter;summary()rolls up token cost and latency; anoperation()context manager times live blocks and marks errors. Pure-stdlib (noopentelemetrydep), injectable clock; pairs with trajectory evaluation (record here, score there).
Map governance evidence to named controls. Full reference: docs/source/Eng/doc/new_features/v37_features_doc.rst.
build_compliance_report(AC_compliance_report,ac_compliance_report): the framework already ships the controls an auditor cares about — egress allowlist, JIT credential leases, maker-checker approval, secrets scanner, audit logging, CycloneDX SBOM. This maps a flatevidencemapping to SOC2 (CC6.1/CC6.3/CC6.8/CC7.3/CC8.1) and ISO 27001 (A.5.23/A.8.16/A.8.30) controls, each markedsatisfied/gap/not_assessed, and renders JSON or a standalone HTML table. The capstone of the governance set — a reporting aid, not a certification.
Score an agent run against a rubric. Full reference: docs/source/Eng/doc/new_features/v36_features_doc.rst.
evaluate_trajectory(AC_evaluate_trajectory,ac_evaluate_trajectory): scores a recorded trajectory (ordered{action, args, observation}steps) against a declarative rubric —required_actions(+ordered),forbidden_actions,max_steps,success_contains. Returns{passed, score, steps, checks}wherescoreis the fraction of applicable checks passed and eachcheckpinpoints a violated expectation. A deterministic, dependency-free signal for agent regression testing; the rubric is plain data so it lives in JSON action files and travels over MCP.
Lock outputs against a human-approved baseline. Full reference: docs/source/Eng/doc/new_features/v35_features_doc.rst.
verify_artifact/approve_artifact(AC_verify_artifact/AC_approve_artifact/AC_pending_artifacts,ac_*): golden-master / snapshot testing for any artifact (text, JSON, OCR output, screenshot bytes).verify_artifactcompares produced content to<name>.approved.<ext>; a mismatch or missing baseline writes<name>.received.<ext>for review and fails, andapprove_artifactpromotes a reviewed received file to the baseline. Complements pixel diffing with a review-gated baseline you commit alongside the test; names are path-traversal-checked.
Pin which hosts automation may reach. Full reference: docs/source/Eng/doc/new_features/v34_features_doc.rst.
EgressPolicy/set_egress_policy(AC_egress_allow/AC_egress_check/AC_egress_reset,ac_*): an allow list (default-deny) and/or deny list offnmatchhost globs (*.example.com) consulted by everyhttp_request(soAC_httpand all features built on it are covered at once). Blocked hosts raiseEgressBlockedbefore a socket opens. Starts in allow-all mode — no behavior change until an operator locks egress down. Closes the exfiltration surface for unattended automation.
Zero standing privilege for secrets. Full reference: docs/source/Eng/doc/new_features/v33_features_doc.rst.
CredentialBroker(AC_lease_secret/AC_lease_valid/AC_revoke_lease/AC_lease_active,ac_*): a consumer takes a short-lived lease (token bound to a secret name + expiry); the real value is fetched only atredeemtime, only while valid, through a pluggable resolver (an unlockedSecretManager, env, vault). Secret values never enter executor/MCP records — the executor/MCP/Builder surfaces manage the lease lifecycle only;redeemis a deliberate Python-API-only escape hatch. Clock and resolver injectable.
Segregation of duties for high-risk steps. Full reference: docs/source/Eng/doc/new_features/v32_features_doc.rst.
ApprovalGate(AC_approval_request/AC_approval_approve/AC_approval_reject/AC_approval_status,ac_*): a maker files a high-risk action and gets a token; a checker — required to be a different principal — approves or rejects it; the action proceeds only onceis_approvedis true. State is an optional shared JSON file so the dispatcher and the human approver can run as separate processes. Pure-stdlib, SOC2-style four-eyes control.
Third-party AC_* commands via entry points. Full reference: docs/source/Eng/doc/new_features/v31_features_doc.rst.
discover_plugins/load_plugins(AC_list_plugins/AC_load_plugins,ac_*): a pip package registers new executor commands declaratively in theje_auto_control.commandsentry-point group; AutoControl discovers and registers them at runtime (immediately usable from JSON flows, socket server, scheduler, MCP). Broken plugins are skipped; the declarative, namespaced complement to the runtime path loader.
MCP 2025-06-18 structured tool output. Full reference: docs/source/Eng/doc/new_features/v30_features_doc.rst.
MCPTool(output_schema=...)— a tool may declare anoutputSchema; its dict result is returned asstructuredContentin thetools/callresponse so clients/LLMs consume a typed, schema-validated object instead of re-parsing text.to_descriptor()advertises it intools/list; non-dict results and schema-less tools are unchanged.ac_validate_rowsis the first built-in to adopt it.
Deterministic eased drags. Full reference: docs/source/Eng/doc/new_features/v29_features_doc.rst.
tween_points/tween_drag/easing_names(AC_tween_drag,ac_tween_drag): drag fromstarttoendalong an eased curve (linear / ease_in_out_quad / ease_out_cubic / ease_in_cubic) — deterministic, pure-math path, injectable sink for tests; complements the humanized jitter.
Turn an action list into a step-by-step SOP. Full reference: docs/source/Eng/doc/new_features/v28_features_doc.rst.
generate_sop/write_sop(AC_generate_sop,ac_generate_sop): map a recorded/authored action list to numbered, human-readable steps + an HTML document (UiPath Task-Capture deliverable); content HTML-escaped, unknown commands degrade gracefully.
Two pure-stdlib audit/analysis tools. Full reference: docs/source/Eng/doc/new_features/v27_features_doc.rst.
- Self-heal analytics —
analyze_heal_log/heal_stats(AC_heal_stats,ac_heal_stats): aggregate the self-heal log into heal-rate, strategy mix, fallback-rate, avg latency and the most-brittle locators — catch decaying selectors before they fail. - Secret scan —
scan_secrets(data)(AC_scan_secrets,ac_scan_secrets): flag hardcoded secrets in action JSON (by key name, value pattern, or high entropy) that should use${secrets.*}; vault refs ignored, previews masked.
Two pure-stdlib utilities. Full reference: docs/source/Eng/doc/new_features/v26_features_doc.rst.
- CI annotations —
emit_annotations(results)(AC_ci_annotations,ac_ci_annotations): turn result dicts into GitHub Actions workflow commands (::error file=...,line=...::msg) so failures show inline in a PR, no reporter action needed. - Clipboard history —
ClipboardHistory/default_clipboard_history(AC_clip_history_capture/list/search/start/stop,ac_clip_history_*): a capped, searchable, newest-first ring buffer of copied text with an optional background poller.
Reusable retry + circuit-breaker primitives. Full reference: docs/source/Eng/doc/new_features/v25_features_doc.rst.
- RetryPolicy —
RetryPolicy(...).run(fn)/retry_call(fn): retry on configured exceptions with exponential backoff (injectable sleep). (The existingAC_retryflow command already retries an action body; this is the reusable callable wrapper.) - CircuitBreaker —
CircuitBreaker/CircuitOpenError(AC_circuit_call,ac_circuit_call): open after N consecutive failures, short-circuit until a reset timeout, then half-open — stops a retry storm hammering a downed dependency. Injectable clock;AC_circuit_callruns an action list through a named breaker.
Replay input with timing fidelity + a press-hold-release DSL, full stack. Full reference: docs/source/Eng/doc/new_features/v24_features_doc.rst.
- Timed timeline replay —
replay_timeline(events, speed=...)(AC_replay_timeline,ac_replay_timeline): replay events honoring eachdelta_msgap, scaled byspeedand clampable; ops = move/click/scroll/press/release/key. - Input-sequence DSL —
run_sequence(steps)(AC_input_sequence,ac_input_sequence): declarative press/hold/release chords +repeat/wait. Both inject sink+sleep for deterministic tests.
The semantic companion to the pixel diff, full stack. Full reference: docs/source/Eng/doc/new_features/v23_features_doc.rst.
- Snapshot & diff —
snapshot/diff_snapshots/snapshot_screen/screen_changed(AC_screen_snapshot/AC_screen_diff/AC_screen_changed,ac_*): normalize the a11y tree to{role, name, bbox}and report what appeared / vanished / moved with a human-readable summary — the feedback signal an agent needs to verify a step ("Save dialog appeared"). - Describe the screen —
describe_screen(AC_describe_screen,ac_describe_screen): a compact "where am I" — role counts + interactive control labels.
The standard VLM-grounding format, full stack. Full reference: docs/source/Eng/doc/new_features/v22_features_doc.rst.
- Number elements —
mark_elements/render_marks/resolve_mark(pure + Pillow): assign1..Nto interactable elements (with centre/role/text), draw numbered red boxes on a screenshot, and map a chosen number back to its element — so a VLM picks a number instead of guessing pixels (directly strengthens the existing VLM locator). - Mark-then-click loop —
mark_screen(render_path=...)/mark_click(n)(AC_mark_screen/AC_mark_click,ac_*): number the live a11y tree (+ optional overlay screenshot), feed marks+image to a model, then click markn.
Durable execution for long flows + a py.typed marker, full stack. Full reference: docs/source/Eng/doc/new_features/v21_features_doc.rst.
- Flow checkpoint & resume —
run_resumable(actions, run_id=..., store=...)/CheckpointStore(AC_run_resumable/AC_checkpoint_status/AC_checkpoint_clear,ac_*): persist step-index + variables after each step; on re-run with the samerun_id, fast-forward past completed steps and rehydrate variables — a flow that crashes at step 400 resumes at 400, not 0. Pluggable (SQLite default), cleared on completion. py.typedmarker — ships the PEP 561 marker so Mypy/Pyright/Pylance honor AutoControl's inline type hints in downstream code (the repo's typed API was previously invisible to type checkers).
Three pure-stdlib internationalization/localization testing helpers that compound, full stack. Full reference: docs/source/Eng/doc/new_features/v20_features_doc.rst.
- Pseudo-localization —
pseudo_localize/pseudo_localize_catalog(AC_pseudo_localize,ac_pseudo_localize): accent + pad UI strings (placeholders preserved,⟦…⟧wrapped) to flush out hardcoded text and pre-stress layout before real translation. - Text-overflow detection —
check_overflow(elements)(AC_check_overflow,ac_check_overflow): flag text whose estimated width exceeds its widget bounds (the #1 l10n bug), computed from the a11y bounds AutoControl already reads. - Catalog completeness —
check_catalog(base, target)(AC_check_catalog,ac_check_catalog): diff a translation catalog for missing / orphaned / empty keys and placeholder mismatches — a CI gate against blank UI.
Three pure-stdlib data-quality helpers (the gate between load_rows/OCR and downstream entry), full stack. Full reference: docs/source/Eng/doc/new_features/v19_features_doc.rst.
- Row schema validation —
validate_rows(rows, schema)(AC_validate_rows,ac_validate_rows): declarative per-field rules (type/required/regex/min/max/min_len/max_len/allowed/unique); returns{ok, valid, invalid, errors}so bad scraped/OCR data is caught before it corrupts an ERP/form. - Field extraction —
extract_fields(text, fields, patterns)(AC_extract_fields,ac_extract_fields): named regex presets (email/url/ipv4/phone/date_iso/amount/hashtag) + custom patterns over free text / OCR blobs. - Row masking —
mask_rows(rows, rules)(AC_mask_rows,ac_mask_rows): mask columns before export —redact/hash(SHA-256) /partial(keep last 4); complements the screenshot-only redaction.
Two pure-stdlib ops tools (security + scale research angles), full stack. Full reference: docs/source/Eng/doc/new_features/v18_features_doc.rst.
- CycloneDX SBOM —
build_sbom/write_sbom(AC_generate_sbom,ac_generate_sbom): emit a CycloneDX 1.6 dependency SBOM (name/version/purl/license) for supply-chain compliance (EU CRA / EO 14028);rootlimits to a package's closure,extra_componentsinventories action files. No third-party dependency. - Duration-aware suite sharding —
shard_flows/merge_results(AC_shard_suite/AC_merge_results): bin-pack flows into N shards balanced by historical per-flow duration (so the slowest worker, not test count, defines runtime), then merge per-shard reports into one rollup.
A non-blocking screen observer (SikuliX observe model), full stack (facade, AC_*, MCP, Script Builder). Full reference: docs/source/Eng/doc/new_features/v17_features_doc.rst.
ScreenObserver(AC_observe_add/AC_observe_remove/AC_observe_list/AC_observe_poll/AC_observe_start/AC_observe_stop,ac_observe_*): register watches that fire on appear / vanish / change of an image/text/pixel and run a callback or action list — react to dialogs/progress/status while the main flow continues.- Testable by design — detection is an injectable
predicate; transition logic is unit-tested viapoll_once()with synthetic values. Built-inimage_predicate/text_predicate/pixel_predicatewrap the existing locate/OCR/pixel helpers.
The accessibility audit gains a WCAG 2.2 / EN 301 549 success-criterion layer, full stack (facade, AC_*, MCP, Script Builder). Full reference: docs/source/Eng/doc/new_features/v16_features_doc.rst.
- WCAG-tagged conformance audit —
wcag_audit(level="AA")(AC_wcag_audit,ac_wcag_audit): tags every defect with its WCAG success-criterion id/level/impact (4.1.2, 1.4.3, 1.4.10) and returns a conformance report withby_criterion/by_impactcounts, filtered to A/AA/AAA — mappable to EN 301 549 for EAA compliance evidence. - Target Size (SC 2.5.8) —
audit_target_size(elements, min_px=24): new WCAG 2.2 rule flagging interactive targets smaller than 24×24 px, computed from element bounds;tag_issueadds SC tagging to any existing audit issue.
Two pure-stdlib tools from the agent/QA research round, full stack (facade, AC_*, MCP, Script Builder). Full reference: docs/source/Eng/doc/new_features/v15_features_doc.rst.
- Agent episodic memory —
AgentMemory(AC_memory_remember/AC_memory_recall/AC_memory_recent/AC_memory_forget/AC_memory_stats,ac_memory_*): SQLite store of(goal → trajectory → outcome)episodes with keyword recall to inject past experience into the planner's context — cross-run learning, no embedding dependency. - Deterministic run —
DeterministicRun/seed_everything(AC_seed_everything,ac_seed_everything): pin the RNG seed and freezetime.timefor awithblock (recording the choices for replay) to kill time/randomness flakiness;time.monotonicleft intact so timeouts still work.
Headless read/write for Excel/Word/PowerPoint, full stack (facade, AC_*, MCP, Script Builder). Optional extra: pip install je_auto_control[office]. Full reference: docs/source/Eng/doc/new_features/v14_features_doc.rst.
- Excel —
read_workbook/write_workbook(AC_read_workbook/AC_write_workbook,ac_read_workbook/ac_write_workbook): read an.xlsxworksheet into row dicts (first row = keys) and write rows back, no GUI. - Word —
read_document/write_document(AC_read_document/AC_write_document): read/write.docxparagraphs. - PowerPoint —
read_presentation/write_presentation(AC_read_presentation/AC_write_presentation): read per-slide text; write slides as{title, body:[...]}.
The backing libraries (openpyxl/python-docx/python-pptx) are optional — each call raises a clear error if missing, and import je_auto_control pulls none of them.
Three pure-stdlib tools for LLM/agent-driven automation, full stack (facade, AC_*, MCP, Script Builder). Full reference: docs/source/Eng/doc/new_features/v13_features_doc.rst.
- Skill / playbook library —
SkillLibrary(AC_skill_save/AC_skill_run/AC_skill_list/AC_skill_remove/AC_skill_search,ac_skill_*): store named, reusable action sequences on disk, search them by name/description/tags, and replay across runs — the durable counterpart to in-memory macros. - Prompt-injection guardrail —
assess_text/scan_text/redact_text(AC_guard_text,ac_guard_text): scan untrusted screen/OCR text for injection patterns (instruction-override, system-prompt exfiltration, jailbreak/chat-template markers …) before feeding it to an LLM; returns{suspicious, score, findings, redacted}. - A2A agent card —
build_agent_card/write_agent_card(AC_agent_card,ac_agent_card): publish an A2A agent card so other agents can discover and call AutoControl as a GUI-automation peer.
Two pure-stdlib authoring-time tools, full stack (facade, AC_*, MCP, Script Builder). Full reference: docs/source/Eng/doc/new_features/v12_features_doc.rst.
- Element repository —
ElementRepository(AC_element_save/AC_element_find/AC_element_click/AC_element_remove/AC_element_list,ac_element_*): save native-UI locators under friendly names (object repository) and reuse them —repo.click("login.submit")instead of repeating name/role everywhere; a UI change is fixed in one place. - Step debugger / tracer —
FlowDebugger(breakpoints,step/continue_/run_to_end, livevariables()) andtrace_actions(AC_debug_trace,ac_debug_trace): step through an action list one command at a time with variables persisting across steps, or get a per-step{index, command, result}trace (withdry_runto plan without running).
Three pure-stdlib quality-of-life tools, full stack (facade, AC_*, MCP, Script Builder). Full reference: docs/source/Eng/doc/new_features/v11_features_doc.rst.
- Synthetic test data —
generate_rows(schema, count, seed=...)/write_dataset(AC_generate_data,ac_generate_data): deterministic fake rows (name/email/phone/int/choice/date…) to drive data-driven runs without real PII; no Faker. - MCP registry manifest —
write_server_manifest("server.json", include_tools=True)(AC_mcp_manifest,ac_mcp_manifest): publish a registry-validserver.jsonso MCP agents/IDEs can discover this server. - Risk-based test selection —
rank_flows/select_flows(AC_rank_tests/AC_select_tests): rank flows by recent failures, flakiness, staleness and never-run from run history; run the riskiest first or only the top-k.
Turn AutoControl from "run a script" into "run a robot." A SQLite-backed work queue implements the production-RPA dispatcher/performer pattern: enqueue items, process one at a time with per-item status, dedup and retry, so a run of thousands is resumable after a crash and parallelizable. Pure stdlib, full stack. Full reference: docs/source/Eng/doc/new_features/v10_features_doc.rst.
- Dispatcher/performer —
WorkQueue.add()enqueues (dedupes by reference);get_next()atomically claims the oldest item;complete()/fail()record the outcome.AC_queue_add/AC_queue_next/AC_queue_complete/AC_queue_fail/AC_queue_stats. - Failure semantics — application errors retry up to
max_retries; business errors (BusinessError/kind="business") never retry.stats()gives per-status counts for dashboards.
Three practitioner-pain fixes for unattended / login automation, all headless and full-stack. Full reference: docs/source/Eng/doc/new_features/v9_features_doc.rst.
- OTP / TOTP for 2FA —
generate_totp/verify_totp(AC_otp_to_var,ac_generate_otp): mint the current 6-digit code from a base32 secret to type into a login form (reuses the remote-desktop TOTP engine). - Native file dialogs —
handle_file_dialog(AC_handle_file_dialog): wait for the OS Open/Save/folder dialog, type the path, confirm — in one call, with an injectable driver. - Locked-session guard —
ensure_interactive_session/is_session_locked(AC_assert_session_active): fail clearly when the workstation is locked / disconnected instead of emitting phantom clicks.
The #1 cause of unattended-automation failure is an unexpected dialog the script never coded for (UAC, "session expiring", Windows Update, a modal). The popup watchdog runs a concurrent guard thread that watches for registered patterns and dismisses them independently of the main flow. Surfaced by the practitioner pain-point research as the top unattended failure cause; full stack (facade, AC_*, MCP, Script Builder), fully headless. Full reference: docs/source/Eng/doc/new_features/v8_features_doc.rst.
- Auto-dismiss popups —
default_popup_watchdog.add_window_rule(title, action="close")then.start()(AC_watchdog_add/AC_watchdog_start/AC_watchdog_stop/AC_watchdog_list): closes a matching window or presses a key (enter/esc) when it appears. - Custom rules —
PopupWatchdog/WatchdogRulepair any detector (image/a11y/text) with a dismisser; a failing rule is logged and skipped, never killing the guard loop.
Object-level desktop automation: read and drive native controls through the OS accessibility API (by name / role / app / AutomationId) instead of clicking pixels or OCR-ing text — far more reliable for native apps. The accessibility layer previously only listed/found/clicked; it now also acts. Ships through the full stack (facade, AC_*, MCP, Script Builder) with a Windows UIAutomation backend; unsupported backends raise a clear error. Full reference: docs/source/Eng/doc/new_features/v7_features_doc.rst.
- Read / set value —
control_get_value/control_set_value(AC_control_get_value/AC_control_set_value): read a textbox/combo value (no OCR) and set it in one call (no per-key typing). - Invoke / toggle —
control_invoke/control_toggle(AC_control_invoke/AC_control_toggle): press a button or flip a checkbox via its control pattern. - Read a table/grid —
read_control_table(AC_read_table): scrape a grid/list/table control into rows of cell strings — desktop data extraction without OCR. - Targets a control by
name/role/app_name/automation_id(the stable Windows identifier), so it survives layout/localization changes.
Two headless cores that shipped without the rest of their stack are now
first-class. Both gain a facade re-export, an AC_* executor command, an
MCP tool, and a Script Builder entry, with headless tests. Full reference:
docs/source/Eng/doc/new_features/v6_features_doc.rst.
- Visual regression (golden images) —
take_golden/compare_to_golden(AC_take_golden/AC_assert_visual): capture a baseline screenshot and fail when the screen drifts beyond a pixel tolerance, with a highlighted diff image and mask regions.AC_assert_visualauto-creates the baseline on first run. PIL-only. - Finite-state machine —
run_state_machine(AC_run_state_machine): drive a script as a declarative{initial, states}spec whoseon_enteractions run through the executor and whose transitions fire onafter/if_var_eq/ predicate guards, bounded bymax_steps/global_timeout_s.
U-20260620-01 · 2026-06-20 · SARIF export, PII redaction, sagas, webhooks, asset store · #release #security #integration
Unify scanner findings for GitHub code scanning. Full reference: docs/source/Eng/doc/new_features/v56_features_doc.rst.
to_sarif/write_sarif/make_finding/from_lint_issues/from_audit_findings(AC_export_sarif,ac_export_sarif): the framework's findings producers (action-lint, secrets scan, WCAG audit, guardrail) had no common export. This builds a SARIF 2.1.0 document — with auto rule catalog and stablepartialFingerprintsfor cross-run dedupe — that GitHub/Azure DevOps code scanning ingests as line-anchored alerts. Pure-stdlibjson+hashlib; adapters normalize the existing lint/audit shapes.
Mask PII in text before it leaks. Full reference: docs/source/Eng/doc/new_features/v55_features_doc.rst.
detect_pii/redact_pii_text(AC_detect_pii/AC_redact_pii,ac_*): image redaction existed but text (OCR, clipboard, LLM I/O, logs) had no string-level PII handling. This detects emails / phones / SSNs / credit cards / IPv4 / IBANs over plain text and redacts withlabel/mask/partial/hash. Overlapping spans dedupe (a card isn't also a phone); patterns are backtracking-safe. Pure-stdlibre+hashlib.
Persist corrected locators so heals aren't forgotten. Full reference: docs/source/Eng/doc/new_features/v54_features_doc.rst.
RepairStore/repair_from_heal(AC_repair_record/AC_repair_resolved/AC_repair_pending/AC_repair_approve,ac_*): runtime self-healing previously threw away the corrected location, so every run re-healed. This records the corrected locator (coords/VLM description/method) from a heal, auto-applies it whenconfidence >= auto_threshold(default 0.9) or queues a reviewable suggestion, andresolved(key)returns the learned fix for reuse. Closes the heal→durable-fix loop; pure-stdlib, fully testable.
Externalize branching into reviewable rule tables. Full reference: docs/source/Eng/doc/new_features/v53_features_doc.rst.
evaluate_table/DecisionTable(AC_decision_table,ac_decision_table): replaces nestedAC_if_varchains with rows ofconditions -> outputsand a hit policy (UNIQUE/FIRST/PRIORITY/COLLECT). Cell conditions are wildcard / literal /{op, value}using the executor's standard comparators (reused, not duplicated). Pure-stdlib, fully testable; the DMN way to keep business rules data-driven.
Undo completed steps when a later one fails. Full reference: docs/source/Eng/doc/new_features/v52_features_doc.rst.
Saga/run_saga(AC_run_saga,ac_run_saga): records a compensating action per step; on any failure runs the completed steps' compensations in LIFO order — the durable-transaction primitiveAC_try(single-block) couldn't provide. Forward actions/compensations are callables (or JSON action lists), so it's fully unit-tested with no side effects; compensation is best-effort (a failing undo is logged, rollback continues). Returns{ok, completed, compensated, failed_step, error}.
Query API/DB JSON with wildcards, recursion, filters. Full reference: docs/source/Eng/doc/new_features/v51_features_doc.rst.
json_query/json_query_one/json_extract(AC_json_query/AC_json_extract,ac_*): the executor's path walker only split on.and indexed — this adds a JSONPath subset ($,.key,[n]/[-n],*/[*],..recursive descent,[?(@.k op v)]filters) over parsed JSON, so array-bearing API/DB responses are easy to extract from.json_extractruns a{key: path}mapping into a flat dict. Pure-stdlibre; the path engineAC_http_to_varand DB-row flows were missing.
Alert Teams/Discord/Slack/webhook. Full reference: docs/source/Eng/doc/new_features/v50_features_doc.rst.
notify_webhook/WebhookChannel(AC_notify_webhook,ac_notify_webhook):notifywas desktop-toast only and ChatOps shipped Slack only — this sends to Slack / Discord / Microsoft Teams / raw webhooks, building the transport-shaped payload (Slack & Teams MessageCard usetext, Discord usescontent) and POSTing via the egress-guarded HTTP client. Thepostertransport is injectable (orset_default_poster), so sending is unit-tested with no network.
Emit run/automation events as CloudEvents. Full reference: docs/source/Eng/doc/new_features/v49_features_doc.rst.
to_cloudevent/EventEmitter/post_cloudevent(AC_emit_event,ac_emit_event): the repo could receive webhooks but not emit events — this wraps run-lifecycle/assertion/failure data in a CloudEvents 1.0 (CNCF) envelope and optionally POSTs it over the egress-guarded HTTP client (interop with Knative, Azure Event Grid, iPaaS, generic webhooks). Thesink/postertransport is injectable, so emission is unit-tested with no network.
Per-environment typed config + credential refs. Full reference: docs/source/Eng/doc/new_features/v48_features_doc.rst.
AssetStore/active_environment(AC_set_asset/AC_get_asset/AC_list_assets,ac_*): the orchestrator "Assets/lockers" pillar — centrally-managed config values that differ by environment (dev/staging/prod) and carry a type (text/int/bool/credential).getcoerces to the declared type and falls back to the default env;credentialassets hold a secret reference thatresolveturns into the real value via an injected resolver (Python-only, so secrets never enterget/executor records). Fills the gap the secret vault (secret-only) and config-sync (whole-blob) left.
Discover what to automate from recorded action logs. Full reference: docs/source/Eng/doc/new_features/v47_features_doc.rst.
mine_action_log/find_repeated_sequences/directly_follows/rank_automation_candidates(AC_mine_actions,ac_mine_actions): mines a recorded action log for frequent, repeatable command n-grams, builds a directly-follows graph, and ranks automation candidates bycount × length— the RPA "task mining" pillar AutoControl recorded data for but never analysed. Pure-stdlib; operates on the existing action-list shape; a candidate that recurs and spans several steps is a strong "extract into a skill" signal.
Catch agents stuck in no-progress loops. Full reference: docs/source/Eng/doc/new_features/v46_features_doc.rst.
LoopGuard/digest_result(AC_loop_guard_observe/AC_loop_guard_reset,ac_*): the top computer-use failure mode is an agent repeating an action with no effect — and the model can't see its own loop.LoopGuardwatches the(tool, args, result)stream and flagsrepeat(same call N times),ping_pong(A-B-A-B), andno_op(observation digest unchanged), escalatingok→warn→criticalby run length. Complements the step/time budget and offline trajectory eval; pure-stdlib, deterministic.
Translate computer-use model clicks to real pixels. Full reference: docs/source/Eng/doc/new_features/v45_features_doc.rst.
CoordinateSpace/xga_space/normalized_space/downscale_png(AC_to_physical/AC_to_model,ac_*): computer-use/VLA models click in a fixed grid (Anthropic downscales to XGA; Gemini returns a 1000×1000 grid), not physical pixels. This maps both ways (round + clamp),xga_spaceaspect-preserves without upscaling, anddownscale_pngresizes a screenshot to the model's input size (Pillow, already core). Pure-arithmetic mapping — unit-tested without a model/GPU.
Trigger flows hands-free from recognized speech. Full reference: docs/source/Eng/doc/new_features/v44_features_doc.rst.
VoiceRouter(AC_voice_register/AC_voice_dispatch/AC_voice_list/AC_voice_clear,ac_*): map spoken trigger phrases toAC_*action lists; feed it recognized text and it runs the closest registered command (phrase matching reuses the fuzzy matcher, so "save the file" fires "save file"). Speech-to-text is out of scope and injectable — the router takes text and arecognizer/runnercallable, so routing is fully unit-tested without audio or any speech dependency (a real Vosk/mic recogniser plugs intolisten_once).
Parse localized numbers/currency/dates. Full reference: docs/source/Eng/doc/new_features/v43_features_doc.rst.
parse_decimal/parse_number/format_decimal/format_currency/format_date(AC_parse_decimal/AC_parse_number/AC_format_decimal/AC_format_currency/AC_format_date,ac_*): OCR/UI text like"1.234,56"(de_DE) parses correctly to1234.56via Babel's CLDR data, and values format back per-locale.babelis an optional[locale]extra, imported lazily; functional tests run underimportorskip(wiring/facade always verified).
Collapse near-identical screenshots. Full reference: docs/source/Eng/doc/new_features/v42_features_doc.rst.
average_hash/dhash/hamming_distance/images_similar/dedupe_images(AC_image_hash/AC_dedupe_images,ac_*): perceptual hashing maps visually similar images to close fingerprints, so near-duplicate frames in a recording or step report cluster by Hamming distance and collapse to one representative. Uses Pillow (already core — no extra dep); the dedupe/compare logic is pure Python with an injectablehasher, so clustering is unit-tested without any image and the real Pillow path underimportorskip.
Push run artifacts to object storage. Full reference: docs/source/Eng/doc/new_features/v41_features_doc.rst.
S3ArtifactStore(AC_s3_upload/AC_s3_download/AC_s3_list/AC_s3_delete,ac_*): upload/download/list/delete reports, screenshots, and recordings against any S3-compatible bucket (AWS S3, MinIO, R2).boto3is an optional[s3]extra and the client is injectable, so the store's logic — and the executor path — are fully unit-tested with a fake client (no boto3/network); the live AWS path is honestly noted as CI-unverifiable. The whole API is relative to the storeprefix. A module-level default store backs the commands.
Match noisy OCR/UI text robustly. Full reference: docs/source/Eng/doc/new_features/v40_features_doc.rst.
fuzzy_ratio/fuzzy_best_match/fuzzy_matches/fuzzy_dedupe(AC_fuzzy_ratio/AC_fuzzy_best_match/AC_fuzzy_dedupe,ac_*): score similarity (0..1), pick the closest candidate from a list, or collapse near-duplicates — so a flow can act on "the button that looks like Submit" rather than an exact label. The default backend is stdlibdifflib(zero extra deps); the optional[fuzzy]extra addsrapidfuzzfor speed, with scores normalised either way.ignore_caseandscore_cutoffsupported.
U-20260621-01 · 2026-06-21 · Tracing, data profiling, JSON/JWT and supply-chain gates · #release #observability #data #security
Carry cross-cutting key-value context across HTTP. Full reference: docs/source/Eng/doc/new_features/v84_features_doc.rst.
Baggage/parse_baggage/format_baggage/inject_baggage/extract_baggage(AC_baggage_parse,AC_baggage_format):trace_contextcarried trace/span identity but nothing propagated cross-cutting context (run_id/tenant/experiment). This implements the W3C Baggage header — a percent-encodedkey=valuelist — with an immutableBaggage(set/remove return new instances) and case-insensitive inject/extract over a headers dict. Pairs withtrace_context. Pure-stdlib, deterministic.
Diff two tabular extracts by key. Full reference: docs/source/Eng/doc/new_features/v83_features_doc.rst.
diff_rows/cell_changes/summarize_diff(AC_diff_rows,AC_cell_changes): the framework diffed screens/snapshots but had nothing to diff two tabular row-sets by key. This keys both sides and reports{added, removed, changed, unchanged}(changed carries{key, old, new}), expands per-cell{key, column, old, new}changes, and counts each bucket. Supports composite keys; last-write-wins on duplicates. Pure-stdlib, deterministic.
Check whether today's data is shaped like the baseline. Full reference: docs/source/Eng/doc/new_features/v82_features_doc.rst.
psi/ks_two_sample/categorical_drift/detect_drift(AC_detect_drift,AC_categorical_drift):statshad A/B experiment tests but no Population Stability Index and no KS two-sample test for reference-vs-current distributions. This adds PSI (quantile-binned log-ratio), the KS statistic with a Kolmogorov p-value, and a categorical chi-square + total-variation summary — pairing withdata_profile.detect_driftgives a one-call{psi, drifted, ks}verdict. Pure-stdlib, deterministic.
Compose config with defaults < file < env < CLI precedence. Full reference: docs/source/Eng/doc/new_features/v81_features_doc.rst.
LayeredConfig/deep_merge/SourceTrace(AC_resolve_config,AC_explain_config):json_patch.merge_patchmerges two docs,config_syncis last-write-wins,AssetStoreis flat-per-env — none compose an ordered precedence stack with deep merge or report which layer won each key.add_layer(name, mapping, priority)thenresolve()deep-merges (nested dicts recursively, scalars/lists replaced);explain("db.host")names the winning layer. Layers are caller-supplied (env passed in, neveros.environimplicitly). Pure-stdlib, deterministic.
Consume text/event-stream responses. Full reference: docs/source/Eng/doc/new_features/v80_features_doc.rst.
parse_event_stream/SSEParser/SSEEvent(AC_parse_sse): the MCP HTTP transport emits SSE, but nothing consumed it — a streaming LLM/agent/chatops endpoint lefthttp_requestwith a raw blob. This implements the WHATWG event-stream parsing algorithm (event/data/id/retry, comments, the leading-space rule, blank-line dispatch) with an incrementalfeedfor chunks and a one-shotparse_event_stream. Pure-stdlib, fully deterministic.
Read 12-factor .env files into config. Full reference: docs/source/Eng/doc/new_features/v79_features_doc.rst.
parse_dotenv/load_dotenv/dotenv_values/dump_dotenv(AC_parse_dotenv,AC_load_dotenv):load_vars_from_jsoningested flat JSON but nothing read the de-facto.envfile. This parsesKEY=VALUElines (exportprefixes, single/double quoting,\n/\tescapes, inline comments) into a plain dict — nopython-dotenvdependency. The loader merges into a caller-supplied mapping rather than mutatingos.environ, so it stays safe and deterministic. Pure-stdlib.
Read standardized API errors out of HTTP responses. Full reference: docs/source/Eng/doc/new_features/v78_features_doc.rst.
parse_problem/is_problem/raise_for_problem/ProblemDetails(AC_parse_problem):http_requestreturned a non-2xx body unparsed, so flows andassert_httphad no structured way to read a standardized API error. This parses the RFC 9457application/problem+jsondocument — registeredtype/title/status/detail/instancemembers plus vendor extensions — returningNonefor non-problem responses or raisingHttpProblemError. Pure-stdlib, fully deterministic.
Survey a row-set and propose a validation schema. Full reference: docs/source/Eng/doc/new_features/v77_features_doc.rst.
profile_rows/infer_schema(AC_profile_rows,AC_infer_schema):validate_rowsconsumes a hand-written schema andstats.describesummarizes one numeric list — nothing surveyed a whole row-set. This profiles each column (null fraction, cardinality, inferred type, top values, numeric min/max/mean) and infers avalidate_rows-compatible schema (required where non-null, unique where distinct, numeric bounds) — the profiler step that feeds the existing validator. Pure-stdlib, fully deterministic.
Correlate spans and logs across HTTP boundaries. Full reference: docs/source/Eng/doc/new_features/v76_features_doc.rst.
SpanContext/new_root_context/child_context/inject_context/extract_context(AC_trace_inject,AC_trace_extract): the existing tracer andagent_tracespans carried no IDs, so a span on one side of an HTTP call couldn't be correlated with the work it triggered on the other. This implements the W3C Trace Context standard — generate/parse/propagatetraceparent+tracestateheaders (version-00, rejects malformed/all-zero IDs), with an injectable RNG for deterministic IDs in tests. Pure-stdlib.
Re-run API flows in CI with no live server. Full reference: docs/source/Eng/doc/new_features/v75_features_doc.rst.
Cassette/CassetteMissError(AC_http_replay): the HTTP client hardcoded itsurllibtransport, so a flow driving a real API couldn't be re-run offline. The client now exposes abuild_call/urllib_transportseam, and this adds a VCR-style cassette —replayreturns a recorded response for a matching request (pure, no network — the CI-valuable half),recording_transportis a thin pass-through over the live transport. Match onmethod/url(optionallybody);save/loadJSON cassettes. Pure-stdlib.
Cap concurrency, honor server back-off. Full reference: docs/source/Eng/doc/new_features/v74_features_doc.rst.
Bulkhead/next_delay/parse_retry_after/parse_ratelimit(AC_bulkhead_run,AC_retry_after):resiliencerecovers andrate_limitpaces, but nothing capped simultaneous in-flight calls (a slow dependency could exhaust every worker) and the HTTP client ignoredRetry-After/RateLimit-*. This adds a bulkhead (bounded-concurrency permit that sheds load withBulkheadFullErrorwhen full) and parsers for the server's advised delay (delta-seconds or HTTP-date). Non-blocking permit counting → deterministic, no threads in tests. Pure-stdlib.
Mergeable p99 for load/soak runs. Full reference: docs/source/Eng/doc/new_features/v73_features_doc.rst.
LatencyDigest/exact_percentiles(AC_percentiles):stats.percentileneeds the full sorted list; this adds a HdrHistogram-style digest with O(1)record, bounded memory (significant-figure buckets), andmergefor cross-shard aggregation — the property you need for a correct aggregate p99 from per-worker results.exact_percentilescovers the small-set case (arbitrary quantiles). Pure-stdlibmath.
SLI, error budget and burn-rate alerts. Full reference: docs/source/Eng/doc/new_features/v72_features_doc.rst.
evaluate_slo/burn_rate/burn_alerts/default_burn_rules(AC_evaluate_slo,AC_burn_alerts): the framework emitted raw signals but had no SLO layer. This computes the SLI over outcome records ([{timestamp, ok}]), the error budget against a target, and the multi-window multi-burn-rate alerts from the Google SRE workbook (page 14.4×@1h, 6×@6h; ticket 1×@3d — firing only when both windows exceed the threshold). Records are plain data, clock injectable, fully deterministic. Pure-stdlib.
Inject faults, verify the system holds. Full reference: docs/source/Eng/doc/new_features/v71_features_doc.rst.
ChaosExperiment/run_experiment/Probe/latency_fault/exception_fault(AC_run_chaos):resiliencerecovers from failures; this causes them and checks a steady-state hypothesis still holds (Chaos Toolkit lifecycle — verify before, inject faults, verify after, roll back LIFO). Probes/faults/rollbacks are callables; the clock/RNG/sleep are injectable so experiments run deterministically in tests with no real failures or sleeping.AC_run_chaosdrives an action-list spec. Pure-stdlib.
Match, diff and snapshot JSON payloads. Full reference: docs/source/Eng/doc/new_features/v70_features_doc.rst.
match_json/diff_json/normalize_json/snapshot_json(AC_match_json,AC_diff_json):json_schemavalidates against an authored schema andjsonpathextracts, but nothing matched two payloads with relaxed rules or diffed them path-by-path. This adds contract/snapshot matching —partial(subset),match_type(Pact-stylelike),ignorevolatile paths — returning{path, kind}mismatches (missing/extra/changed), plus golden-mastersnapshot_json. Composes withjson_schema+json_patch; pure-stdlib.
Attest what was built. Full reference: docs/source/Eng/doc/new_features/v69_features_doc.rst.
build_provenance/subject_for/verify_provenance/write_provenance(AC_build_provenance,AC_verify_provenance): the framework signs action files and inventories deps (SBOM) but couldn't attest what was produced by which build. This adds an in-toto v1 Statement with a SLSA v1 provenance predicate over filesha256digests, and a verifier that re-hashes the artifacts (tamper → mismatch). Complementsaction_signing+sbom; pure-stdlibhashlib+json, fully offline.
Toggle behavior with targeting & rollout. Full reference: docs/source/Eng/doc/new_features/v68_features_doc.rst.
FlagStore/evaluate_flag/is_enabled/assign_variant(AC_evaluate_flag,AC_flag_enabled):decision_tableis one-shot DMN andab_locatoris locator A/B — neither is a product flag store with sticky % rollout. This adds an OpenFeature-shaped engine: targeting rules (eq/in/semver_*…), weighted variants, kill switch, and consistent-hash bucketing (sha256(key.salt.context_key)) so a subject is sticky. Returns{value, variant, reason}(TARGETING_MATCH/SPLIT/DISABLED/ERROR). Pure-stdlib, deterministic.
Apply and merge text diffs. Full reference: docs/source/Eng/doc/new_features/v67_features_doc.rst.
unified_diff/apply_unified/three_way_merge(AC_unified_diff,AC_apply_unified,AC_three_way_merge):difflibgenerates a unified diff but the stdlib can't apply one, and there was no three-way merge. This adds the missing applier (walks@@hunks, verifies context, raises on mismatch) and a line-based three-way merge (non-overlapping edits combine cleanly; overlapping ones emit<<<<<<<conflict markers). Complementsjson_patch(structured JSON); pure-stdlibdifflib.
Schedule "every 2nd Tuesday". Full reference: docs/source/Eng/doc/new_features/v66_features_doc.rst.
parse_rrule/occurrences/next_occurrence(AC_rrule_occurrences,AC_rrule_next): the scheduler's cron is 5-field interval-only — it can't express "every 2nd Tuesday", "the last weekday of the month", or "every weekday for 10 occurrences". This adds an RFC 5545 (iCalendar) RRULE parser + occurrence expander supportingFREQ/INTERVAL/COUNT/UNTIL/BYDAY(with ordinals like2MO/-1FR)/BYMONTHDAY/BYMONTH/BYSETPOS/WKST. Pure-stdlibdatetime+calendar, injectable clock for deterministicnext_occurrence.
Decide whether a difference is real. Full reference: docs/source/Eng/doc/new_features/v65_features_doc.rst.
describe/percentile/two_proportion_z_test/welch_t_test/cohens_d/chi_square_2x2(AC_describe_stats,AC_ab_significance):ab_locatorranks by raw success rate andrun_historystores durations, but nothing computed percentiles or significance. This adds the analysis layer — summary stats + p50/p90/p95/p99, a two-proportion z-test (with CI), Welch's t-test (exact t-distribution p-value via the incomplete beta — no SciPy), Cohen's d, and a 2×2 chi-square. The normal CDF is exact viamath.erf; validated against textbook values (incl. the chi²=z² identity). Pure-stdlibmath+statistics.
Rank a document corpus by relevance. Full reference: docs/source/Eng/doc/new_features/v64_features_doc.rst.
SearchIndex/search_documents/tokenize(AC_search_documents,ac_search_documents):fuzzyis pairwise andskill_librarymatches substrings alphabetically — neither ranks a corpus by relevance. This adds an inverted-index search ranked with Okapi BM25 (k1=1.5,b=0.75,IDF = ln(1+(N−df+0.5)/(df+0.5))) or TF-IDF, so a rare term out-ranks a common one, term frequency saturates, and long docs are normalized down. Incrementaladd/remove, optional stop-words, deterministic ranking. Pure-stdlibmath+collections+re— no database.
Address, diff and patch JSON. Full reference: docs/source/Eng/doc/new_features/v63_features_doc.rst.
resolve_pointer/make_patch/apply_patch/merge_patch/make_merge_patch(AC_resolve_pointer,AC_apply_json_patch,AC_make_json_patch,AC_merge_patch):jsonpathis read-only andapprovalcompares whole artifacts — nothing could address one location, compute a structured delta, or apply a partial update. This adds the three IETF primitives — JSON Pointer (RFC 6901), JSON Patch (RFC 6902, all six ops, atomic apply), and JSON Merge Patch (RFC 7386,nulldeletes) — for config-drift detection, partial updates, HTTP PATCH bodies, and golden-master deltas. Pure-stdlibjson+copy, validated against the RFC test vectors.
Stay under API quotas. Full reference: docs/source/Eng/doc/new_features/v62_features_doc.rst.
TokenBucket/SlidingWindowLimiter/throttle(AC_rate_limit,ac_rate_limit):RetryPolicy/CircuitBreakerrecover from failures but nothing shaped the rate of calls. This adds a token bucket (smooth rate + burst), a sliding-window limiter (Cloudflare's O(1) weighted counter), and a leading-edge throttle decorator. Every limiter takes an injectableclock(andacquireasleep) so it's fully deterministic in CI with no real delays.AC_rate_limitgates an action against a named bucket, returning{acquired, tokens, wait}.
Mint and verify bearer tokens for the APIs you automate. Full reference: docs/source/Eng/doc/new_features/v61_features_doc.rst.
encode_jwt/decode_jwt/ClaimsPolicy(AC_jwt_encode,AC_jwt_decode): the framework had HMAC file signing and an ACME-bound RS256 JWS, but nothing to mint/verify a compact bearer JWT. This adds a pure-stdlib HS256/384/512 codec with full claim validation (exp/nbf/aud/iss, injectable clock) that drops straight intohttp_request's bearer auth. Safe by default: rejectsalg:none, enforces an algorithm allowlist (anti-confusion), and compares signatures withhmac.compare_digest.AC_jwt_decodereturns{ok, claims}so flows can branch without raising.
Flag disallowed dependency licenses. Full reference: docs/source/Eng/doc/new_features/v60_features_doc.rst.
evaluate_sbom/evaluate_license/normalize_spdx/license_findings_to_sarif(AC_check_licenses,ac_check_licenses): the SBOM recorded each dependency's license name but never judged it. This normalizes license strings to SPDX ids and evaluates them against an allowlist/denylist (with a built-inDEFAULT_COPYLEFTset), understanding SPDX expressions (OR= choice,AND= all), then bridges violations into SARIF (denied→error,unknown→warning). Pure-stdlib, fully offline — the license-compliance lane beside the OSV vulnerability lane.
Suppress the vulns that don't affect you. Full reference: docs/source/Eng/doc/new_features/v59_features_doc.rst.
vex_statement/build_vex/apply_vex(AC_apply_vex,ac_apply_vex): the OSV scanner surfaces every known CVE forever — there was no way to record "we checked, this one doesn't affect us". This authors OpenVEX 0.2.0 statements and applies them to the scanner's findings:not_affected/fixedsuppress a finding,affected/under_investigationannotate it. Statements join on the vuln id or an alias, optionally product-scoped;not_affectedrequires a justification or impact statement. Pure-stdlib; chains directly afterAC_scan_vulns.
Match the SBOM against known CVEs. Full reference: docs/source/Eng/doc/new_features/v58_features_doc.rst.
scan_components/match_package/is_affected/findings_to_sarif(AC_scan_vulns,ac_scan_vulns):build_sbomonly inventoried dependencies andto_sarifonly exported findings — nothing ever produced a vulnerability finding. This matches the SBOM's(ecosystem, name, version)components against an OSV advisory database (sweepingintroduced/fixed/last_affectedranges, PEP-503 name normalization, severity→SARIF level) and bridges results into the existing SARIF exporter for GitHub/Azure DevOps code scanning. The advisory DB is injected as data (offline, deterministic); the liveosv.devquery is an optionalfetcherseam. Pure-stdlibre.
Validate nested JSON against a real schema. Full reference: docs/source/Eng/doc/new_features/v57_features_doc.rst.
validate_json/is_valid/assert_schema(AC_validate_json,ac_validate_json): the framework only generated JSON Schema anddata_qualityis a flat per-column checker — neither could validate a nested API request/response body. This adds the consumer: a JSON Schema (Draft 2020-12 subset) validator that reports every violation as{path, keyword, message}(e.g.$.age maximum). Coverstype(incl. integral-floatinteger),enum/const, numeric/string bounds, array & object keywords,allOf/anyOf/oneOf/not, boolean schemas and local$ref. Pure-stdlibre; pairs withjson_queryand thehttp_requesthelper.