Skip to content

sfetch v0.3.0

Choose a tag to compare

@github-actions github-actions released this 29 Dec 21:08

Summary

Introduce a numeric trust rating system (0–100) with transparent factor breakdown and optional policy gating via --trust-minimum.

Highlights

Trust rating (v0.3.0)

  • Trust is now reported as N/100 (level) with factor breakdown (signature/checksum/transport/algo).
  • New workflow none distinguishes "source provides no verification artifacts" from explicit bypass (--insecure).
  • Provenance JSON includes a new trust object and retains legacy trustLevel for one minor cycle.

Policy gating

  • --trust-minimum <0-100> blocks downloads below the specified threshold and prints factor breakdown on failure.

Dogfood corpus (opt-in)

  • Dogfood set lives in testdata/corpus.json and is runnable via make corpus-dryrun.

Exit codes

  • Exit code 0 indicates the requested fetch/install completed (even if the user chose to bypass verification).
  • Non-zero indicates the operation was blocked (e.g., --trust-minimum) or failed (download/verification errors).