ShadowShield v0.6.2
Production hardening for failure recovery, durable policy state, supply-chain provenance, repository governance, and honest blind evaluation.
Highlights
- Hardened durable state against symlink, non-regular-file, and swap races with bounded I/O and atomic replacement.
- Made Transformer and vector initialization failures single-flight, traceback-bounded, and safely retryable.
- Added signed SLSA provenance and a signed CycloneDX SBOM for the exact GHCR image, with registry-backed verification before release completion.
- Added the v3 blind generalization snapshot and aggregate reporting; a candidate that missed the frozen acceptance gates was discarded.
- Enforced a hash-only CSP, stronger browser security headers, a permanent www-to-apex redirect, and production CI/security gates.
Verified on the exact release source
- 295 tests passed with 2 optional real-model skips.
- Python 3.10 through 3.14 CI, real-model ML integration, package build, workflow lint, CodeQL, and container security smoke all passed.
- Linux/Python 3.10, strict mypy, Ruff, Actionlint, package isolation, and Trivy with zero fixable high/critical findings passed.
- Exact-SHA GitHub Pages and Vercel production deployments are live.
See CHANGELOG.md for the complete release record.