Programmable v4 Builder v0.6.0
This release publishes the exact portable Builder package, generated plugin payload, manifest, SBOM, checksums, kernel
evidence, and release receipt for one immutable Git revision. Publication does not establish model behavior, project
approval, deployment, audit, Registry acceptance, provider support, or live product evidence.
Release scope
- Source-receipted, EVM-only Chainlink profiles and atomic product packs for CCIP, CRE, Data Feeds, Data Streams, and
VRF v2.5, composed with the matching generic safety capability instead of one umbrella context. - Independently authored Ethereum production invariants from a date-pinned ETHSkills review. ETHSkills source text and
code were not copied because the reviewed repository had no operative license file. - Concise common CLI journeys with at most three primary root causes and explicit exhaustive report output.
- Enforced end-to-end efficiency budgets covering model and judge usage, repository stages, emitted bytes, retries,
latency, activated references, and descendant agents; missing measurements fail closed. - Compiler source-closure revalidation before execution, plugin-payload MCP startup, and stricter project-output proof
boundaries. - No portable same-user candidate execution. The Builder requires a separately trusted external sandbox, ships with an
empty trust store, rejects caller-provided authority, and cannot convert legacy command receipts into proven output.
Generator-backed source inventory
These are source inventories, not execution results:
- The maintainability size generator discovers 321 production JavaScript modules across its two configured roots.
- The generated Contract Registry contains 50 schema contracts and 25 validator closures comprising 1,032 transitive
module bindings across 174 distinct modules. - The release-evidence source inventory finds 54 unit, one fuzz and three invariant Solidity functions in the Fee V2
kernel, 58 functions in total. - The repository gate dynamically discovers 9
evals/tests/*.test.mjsfiles. A filename count is not a model run or
test-pass receipt.
The release artifacts bind these inventories to the exact published commit and tree. A later source change requires new
evidence and cannot reuse this release identity.
Evidence boundary
- The package release requires a clean immutable commit, protected public CI, the complete repository and reference
kernel rehearsal, deterministic artifacts, exact checksums, and post-publication installation canaries. - Real named model tiers and an independent judge were not run for a behavioral claim. A trusted separate-UID,
container, or VM sandbox, comparable public repository population, independently novel holdout and immutable prior
comparator, pinned-fork cases, and installed-host natural-language-to-submission runs remainEXTERNAL_BLOCKED. - No independent audit, Registry activation, provider guarantee, deployment, signature flow, project approval, routing,
or onchain state is claimed by this package release.
The generated receipt retains releaseCandidate: false because package publication does not manufacture the deferred
behavioral evidence. The owner-authorized public tag is an immutable distribution boundary, not an audit verdict.