Stability and Maturity
Boruna is at version 3.5.0. It is a local engine and CLI. Since 3.0.0 there is no server component.
Only the latest major line (3.x) is supported. 1.x and 2.x are end of
life. The support, compatibility and deprecation rules are in
lts.md. The Stable tier below is what lts.md
§B covers. Experimental and Alpha components may change in minor releases.
Current status
Suitable for:
- Evaluation, proof-of-concept and internal tooling
- Audit-sensitive AI pipelines that run locally
- Production use of the Stable surfaces, after checking
PERFORMANCE.mdandlimitations.mdagainst your workload
Not suitable for:
- Environments that require a third-party security audit. No external audit has been done.
- Anything that needs a hosted server, distributed workers or a web dashboard. These were removed in 3.0.0.
Stability tiers
Stable (covered by lts.md §B)
.axlanguage 1.1: syntax, type system, pattern matching, records, enums,let mutand loops. Spec:spec/ax-language-1.0.md.- VM execution: bytecode format 1.1, capability enforcement, determinism.
- Workflow DAG schema 1:
workflow.jsonwithschema_version: 1. Spec:spec/workflow-dag-1.0.md. - Evidence bundle format 1.1: hash-chained audit log,
bundle.json, optional AES-256-GCM encryption, verifiable redaction. Reads 1.0 bundles. Spec:spec/evidence-bundle-1.0.md. - Capability set: additions only within the major line.
- CLI commands:
run,compile,workflow validate/run/approve/reject/trigger/resume,evidence inspect/verify/gc-blobs/rotate-kek,migrate,new,lang check/repair,template list/apply. - Bundle storage adapters: local filesystem, and S3, GCS and Azure
Blob behind the
s3,gcsandazurecargo features. - MCP tool responses:
protocol_version: 1on every response from the 14boruna-mcptools. - Standard libraries: 13
std-*packages. Seelts.md§B.7 andstdlib-graduation-tracker.md.
CLI commands not in the list above are Experimental.
Experimental (may change in minor releases)
- Actor system: spawning, message passing, supervision.
- Multi-agent orchestration: the
boruna-orchbinary. - Package system: the
boruna-pkgmanifest format and registry. - App templates: variable names and generated code.
trace2tests: test generation and minimization.- Migration tooling:
boruna migrateis beta and covers pre-1.0 artifacts only. std-guardstandard library (added in 3.1.0).- Evidence extras:
evidence attest,anchor,report,otel,redact,diffandcreate. - Confidence gates:
confidence_gateon approval gates andboruna confidence threshold(3.3.0). - Other commands:
fmt(v1 strips comments),repl,simulate,literate,skills,doctor,size,capability,metrics,policy,lang codes/caps,workflow show/list/schedule/eval/find/graph. lex_full(): the lexer API that keeps comments and whitespace.
Alpha (expect breaking changes)
--livenetwork calls: thehttpcargo feature fornet.fetch, SSRF policy and response handling.replay: replaying a recorded event log.framework test: the message protocol for testing framework apps.
Planned (see roadmap.md)
- External security audit of the VM and capability enforcement
boruna fmtv2 that keeps comments- Language 2.0, where warnings such as
E010become errors
Versioning policy
Boruna follows Semantic Versioning:
- Patch (3.5.x): bug fixes and security fixes.
- Minor (3.x.0): new features. Stable surfaces stay compatible. Experimental and Alpha components may change. Deprecations are announced here.
- Major (x.0.0): may remove deprecated features. The previous major line is end of life on the day the new major ships.
The language, bytecode, workflow schema and bundle format have their own
version numbers, separate from the release version. See lts.md
§B.
Rust toolchain
Boruna builds on stable Rust. CI uses the current stable toolchain. No minimum Rust version is declared.
Security
See SECURITY.md for how to report a vulnerability and
lts.md §D for which releases get security fixes.