OKF4net 0.6.0 is out. It is the largest release of the project so far: more commits than every previous release combined, two new command-line verbs, a static-site generator, and a way to run a knowledge bundle’s computations in real containers.
If you have never heard of the project: the [Open Knowledge Format](https://github.com/GoogleCloudPlatform/knowledge-catalog/blob/main/okf/SPEC.md) (OKF) is Google’s open format for representing knowledge as a plain directory of markdown files with YAML frontmatter. It is meant to be readable by a person with `cat` and by an AI agent alike. [OKF4net](https://github.com/jchable/okf4net) is an independent .NET implementation of OKF v0.2, written against the spec, on the base class library only. The core library, the catalog and the `okf` binary have no third-party dependencies, down to their own YAML-subset parser.
The release in numbers
The first release shipped on 22 July. Ten weeks later:
| 0.1.0 (22 Jul) | 0.5.0 (31 Jul) | 0.6.0 (1 Oct) | |
|---|---|---|---|
| Commits (cumulative) | 54 | 552 | 1,194 |
Projects under src/ | 2 | 7 | 10 |
Lines of C# in src/ | 4,699 | 13,439 | 24,120 |
| Lines of C# in tests | 2,307 | 13,418 | 30,512 |
| Tests run | 218 | 912 | 2,352 |
| NuGet packages | 1 | 6 | 6 |
Agent tools (okf_*) | 0 | 11 | 13 |
Line counts are non-blank lines, comments included. 0.6.0 alone is 642 commits and 146 changelog entries.
The number I care about most is the test row: the suite went from 912 to 2,352 tests, and there is now more test code than product code. Most of what this release did was make existing behaviour harder to break.
What is new
okf audit and okf verify : A bundle is only useful if you know which parts of it someone has actually checked. `okf audit` answers that across the whole bundle: which concepts are stale, which have never been reviewed by a human, where provenance is missing.
okf audit bundles/acme_retail --stale --trust unverified,machine-confirmed
okf audit bundles/acme_retail --stale --trust unverified,machine-confirmed
okf verify records a dated review on a concept (§5.2 of the spec). The two compose over a pipe, so « review everything nobody has reviewed » is one line:
okf audit bundles/acme_retail --trust unverified | cut -d' ' -f1 | okf verify bundles/acme_retail --by human:ada -
A verification stamp is a dated declaration, not a proof: okf verify cannot authenticate who ‘–by’ names. The README says so, and so do I.
okf-render : a second binary that turns a bundle into a browsable static HTML site. It is separate from `okf` on purpose: `okf validate` is the small validator people run in CI, and it should not carry a JavaScript markdown renderer it never executes.
Attested computation in real containers : OKF’s §10 lets a concept declare a computation (a script or a SQL query) and an attester that checks the result. The new `OKF4net.Attestation.Containers` runs the bundle’s *actual* script and its *actual* attester in Docker, Podman or nerdctl, as an unprivileged user with every capability dropped. Nothing is reimplemented in C#. This one is in the repository but not yet published as a package, because it needs a container engine at run time.
A C# code graph in the producer. okfgen, the tool that generates a bundle from a repository, now emits one concept per namespace, type and member, with resolved call links between them. It grew from about 1,000 lines to about 31,800, more than half of them tests.
A hardened agent surface : the MCP server okf-mcp now serves a bundle read-only by default; you opt in to the write tools with ‘OKF_MCP_WRITABLE=1’. Computations run through an agent have a two-minute timeout and can be cancelled. Text that a bundle controls is neutralised before a model sees it.
## What the hardening actually looked like
One story from this cycle is worth telling. The viewer renders markdown in the browser, so it has to stop a hostile bundle from injecting script. We had two tests asserting that raw HTML was disabled. Both were green. The sanitizer had an exploitable hole anyway.
The reason is simple: the test suite runs on .NET and cannot execute JavaScript. Those tests were checking that certain strings appeared in a `.js` file. They would have passed with the sanitizer deleted.
The fix was not a better assertion. It was a separate Node harness that loads the real viewer code and feeds it hostile payloads, run in CI on every change. The same rule now applies everywhere in the repository: code the test runner cannot execute needs its own executable check, and a test that only reads source text has to say it is a smoke check.
## Breaking changes
This is a 0.x release and it breaks things. The ones most likely to affect you:
- A bare ‘attester.resource’ or ‘computation’ path now resolves from the bundle root, not from the concept’s folder (§6.2). okf validate tells you where it found the file and what to write instead.
- The frontmatter fence must be ‘—‘ at column 0. YAML anchors, aliases and tags are rejected with an error that names the feature.
- Bundle.ReadResourceText refuses any path outside the bundle root.
- okf-mcp is read-only unless you set `OKF_MCP_WRITABLE=1`.
The changelog ➡️ https://github.com/jchable/okf4net/blob/main/CHANGELOG.md#060—2026-10-01 lists every one of them at the top of the 0.6.0 section.
Try it
dotnet add package OKF4net # the library
dotnet tool install -g OKF4net.Mcp # the MCP server
Prebuilt okf and okf-render binaries for Windows, Linux and macOS (x64 and arm64) are on the GitHub release page : https://github.com/jchable/okf4net/releases/tag/v0.6.0.
The documentation lives at https://jchable.github.io/okf4net.
## Want to help?
Nearly every commit so far is mine, and I would like that to change. There is a public roadmap : https://github.com/jchable/okf4net/blob/main/ROADMAP.md and a set of issues labelled ‘good first issue’ : https://github.com/jchable/okf4net/labels/good%20first%20issue.
Two areas where a second pair of eyes would help most: the container runtime has only ever been exercised on Docker, never on Podman or nerdctl, and the producer’s code graph only covers C# so far.