Skip to content

ShadowShield v0.6.2

Choose a tag to compare

@0xsl1m 0xsl1m released this 25 Jul 20:45
991e630

Production hardening for failure recovery, durable policy state, supply-chain provenance, repository governance, and honest blind evaluation.

Highlights

  • Hardened durable state against symlink, non-regular-file, and swap races with bounded I/O and atomic replacement.
  • Made Transformer and vector initialization failures single-flight, traceback-bounded, and safely retryable.
  • Added signed SLSA provenance and a signed CycloneDX SBOM for the exact GHCR image, with registry-backed verification before release completion.
  • Added the v3 blind generalization snapshot and aggregate reporting; a candidate that missed the frozen acceptance gates was discarded.
  • Enforced a hash-only CSP, stronger browser security headers, a permanent www-to-apex redirect, and production CI/security gates.

Verified on the exact release source

  • 295 tests passed with 2 optional real-model skips.
  • Python 3.10 through 3.14 CI, real-model ML integration, package build, workflow lint, CodeQL, and container security smoke all passed.
  • Linux/Python 3.10, strict mypy, Ruff, Actionlint, package isolation, and Trivy with zero fixable high/critical findings passed.
  • Exact-SHA GitHub Pages and Vercel production deployments are live.

See CHANGELOG.md for the complete release record.