v1.2.0
⚠️ ken v1.2.0 — superseded by v1.2.1 (security)
Use v1.2.1 instead.
v1.2.0's binaries shipped with golang.org/x/text v0.37.0, which is affected by GO-2026-5970 — an infinite loop on invalid input, reachable via ken's Postgres-connect and Unicode-normalization paths. The advisory was published to the Go vulnerability database shortly after v1.2.0 was tagged.
v1.2.1 is an identical release with x/text bumped to v0.39.0 — same features, fixed dependency.
The full feature notes for this release (the .kenignore memory campaign, the security & correctness review, verified model downloads, and bounded shutdown) are on the v1.2.1 release page.