Releases: ArdurAI/sith
Release list
v0.3.0-beta.4
Sith is a local-first, account-free Kubernetes fleet tool from ArdurAI.
Every archive in this release is reproducibly built from the tagged commit and is accompanied
by an SPDX SBOM, a keyless Sigstore bundle, and GitHub-hosted SLSA provenance.
Changelog
- 9ff3758 feat(e9): publish signed hub OCI image
Verify checksums, signatures, and provenance before installation; see docs/RELEASE.md.
v0.3.0-beta.3
Sith is a local-first, account-free Kubernetes fleet tool from ArdurAI.
Every archive in this release is reproducibly built from the tagged commit and is accompanied
by an SPDX SBOM, a keyless Sigstore bundle, and GitHub-hosted SLSA provenance.
Changelog
- c47f292 docs(session): record F11 directory import checkpoint
- 78af530 feat(f11): add native macOS fleet desktop
- 43f0118 feat(f11): import kubeconfig directories in local UI
- 44fad09 fix(f11): compile desktop cancellation tests on CI
- d6a3ee6 fix(f11): harden kubeconfig directory review gaps
- b99820e fix(f11): harden native desktop review gaps
- dfa4fb9 fix(f11): remove redundant directory candidate bound
Verify checksums, signatures, and provenance before installation; see docs/RELEASE.md.
v0.3.0-beta.2
Sith is a local-first, account-free Kubernetes fleet tool from ArdurAI.
Every archive in this release is reproducibly built from the tagged commit and is accompanied
by an SPDX SBOM, a keyless Sigstore bundle, and GitHub-hosted SLSA provenance.
Changelog
- 6d2d127 fix(e9): publish beta drafts by release ID
Verify checksums, signatures, and provenance before installation; see docs/RELEASE.md.
v0.2.1
Sith is a local-first, account-free Kubernetes fleet tool from ArdurAI.
Every archive in this release is reproducibly built from the tagged commit and is accompanied
by an SPDX SBOM, a keyless Sigstore bundle, and GitHub-hosted SLSA provenance.
Changelog
- 4dc1066 chore(deps): bump actions/checkout in the actions group
- 94d704b chore(deps): bump golang.org/x/term in the go-runtime group
- aea3f17 chore(deps): bump the actions group with 2 updates
- 949320b chore(deps): pin action release commits (#68)
- 6e2bc5b chore(deps): update x/term (#67)
- ad63031 ci(e1): gate multi-layer tenant isolation
- eb1692d ci(security): make isolation fuzz budget deterministic
- 7129d34 docs(ci): close isolation fuzz journal
- 7992456 docs(e0): close two-spoke OCM falsification
- a654acb docs(e1): checkpoint OIDC CI evidence
- 93fe683 docs(e1): close exec credential journal
- 424cc6a docs(e1): close postgres RLS journal
- a57ff09 docs(e1): close tenant-isolation journal
- 9d80592 docs(e1): close workspace auth journal
- b931225 docs(e1): finalize RLS preflight evidence
- 8b2455d docs(e1): record API key exchange evidence
- 3e9123c docs(e1): record AWS STS verification evidence
- 6a0fdff docs(e1): record Azure Entra verification evidence
- 71d0626 docs(e1): record OIDC federation evidence
- 27f8863 docs(e1): record RLS gate evidence
- ed7b41f docs(e1): record cloud identity seam evidence
- 024b099 docs(e1): record isolation-suite evidence
- f8e288e docs(release): prevent durable branch deletion
- 11c045e feat(e1): add cloud identity exchange seam
- 286d972 feat(e1): add forced postgres tenancy boundary
- f0071b5 feat(e1): add workspace tenancy contract
- 27ddb4b feat(e1): bind fleet reads to signed scope
- 68ec421 feat(e1): exchange API keys for signed sessions
- aff198a feat(e1): federate pinned OIDC identities
- 3530df4 feat(e1): verify AWS STS identity proofs
- 44660eb feat(e1): verify Azure Entra workload identities
- 7332864 feat(e1): verify Google service-account identities
- fbbf117 feat(e1): verify signed workspace sessions
- 44ae088 feat(e10): add bounded self-observability metrics
- c9e3737 feat(e10): add sanitized auth refusal logs
- 1ecfb56 feat(e10): add sanitized local trace context (#138)
- fef959f feat(e2): add direct ClusterProxy snapshot transport
- 096dca9 feat(e2): add immutable image digest search
- 5e5f426 feat(e2): collect bounded spoke snapshots
- 9a3911f feat(e2): correlate exact unhealthy workloads
- 658336f feat(e9): add fail-closed Helm hub chart
- 92bedb3 feat(e9): add fail-closed hub resource profiles
- 9e75a13 feat(e9): add immutable OCI image contract
- d29c8da feat(e9): add isolated hub migration command
- 64072f9 feat(fleet): add four-lens entity graph contract
- 75499b1 feat(hub): compose direct OCM runtime
- a4ec7db feat(pep): add structured policy audit logging
- d748b9d feat(pep): gate hub reads through policy hook
- 2f51151 fix(brain): normalize image evidence for fleet correlation
- 0a3dbca fix(brain): stabilize deterministic incident replays
- d76c975 fix(e0): harden OCM falsification evidence
- c23fcba fix(e1): harden signed workspace sessions
- 2721618 fix(e1): remove tenant-key existence oracle
- 2f35b11 fix(e1): require TLS for remote postgres
- a5f5ada fix(e2): harden portable M0 release checks
- 8b56a04 fix(security): pin secure Go toolchain
- b0a2553 refactor(e1): isolate hub network boundary
- 11d90dd test(e0): automate two-spoke OCM falsification
- c2f9641 test(e1): add destructive isolation controls
- 929be80 test(e1): prove exec credential isolation
- 6ce51ce test(e1): prove postgres RLS in CI
Verify checksums, signatures, and provenance before installation; see docs/RELEASE.md.
v0.1.0
Sith is a local-first, account-free Kubernetes fleet tool from ArdurAI.
Every archive in this release is reproducibly built from the tagged commit and is accompanied
by an SPDX SBOM, a keyless Sigstore bundle, and GitHub-hosted SLSA provenance.
Changelog
- a53d262 build(deps): adopt the Go 1.26 toolchain
- f9ae42d chore(build): establish Go module and quality tooling
- ab9f59b ci(actions): enforce the Slice 0 merge gates
- c7e2397 docs(brain): record advisory evidence boundary
- 15def82 docs(build): lock Phase-L build sequence, Slice-0 spec, and conventions
- 0398f5b docs(build): weight build sequence toward the target user's daily workflow
- 6cce2cc docs(e2): spec F2.1 source-abstract fleet model + connector contract
- 4db3bda docs(e2): spec read-federation four-lens graph, investigation brain, integration waves
- a1a9e60 docs(mcp): record local transport and auth decision
- e665439 docs(privacy): record local trust invariants
- 98eb62b docs(research): 2026 market & landscape research for Sith
- 6b81428 docs(reshape): local-first dual-mode plan + reconciled research + Notion doc
- 3b682d7 docs(roadmap): consolidate July-2026 research into combined roadmap
- 5a488ed docs(sessions): record the Slice 0 foundation
- 457fccd docs(spec): local fleet UX — cache-first render (F11.2) + per-pod table stakes (F11.5)
- 23b96be docs(ui): record the local fleet IDE
- 35e4378 feat(brain): add deterministic advisory rules
- 09d5470 feat(cache): add the local fleet store
- ef8f828 feat(cache): hydrate Tier-1 lenses in the background
- 998d26e feat(cache): stream live fleet deltas
- 3227387 feat(cli): add cache-backed fleet reads
- e452841 feat(cli): add stable YAML output
- 35f1190 feat(cli): add the Slice 0 walking skeleton
- 87053ca feat(cli): discover local kubeconfig contexts
- 303544a feat(cli): expose per-resource operations
- 0ce4b3e feat(cli): surface local fleet investigations
- 7ad0759 feat(connector): add the source-abstract contract
- bad1a1f feat(connector): implement local kubeconfig reads
- 5383365 feat(core): add typed Slice 0 foundations
- ab272d5 feat(fleet): enforce workspace-scoped cache reads
- d839144 feat(fleet): normalize advisory evidence
- decef11 feat(keychain): add fail-loud OS secret custody
- c64e8bb feat(localops): add direct Kubernetes operation engine
- 12b60f1 feat(mcp): add loopback fleet read server
- 25c14e2 feat(tui): add the cache-first fleet view
- eec935f feat(tui): discover generic resource lenses
- ec2f089 feat(tui): render generic server columns
- 25aba5f feat(ui): add the local fleet IDE
- baaac7b feat: add the local MCP read server (#61)
- 7a94339 feat: add the local advisory investigation brain (#63)
- 126f441 feat: add the signed release supply chain
- 4fe22d5 feat: add the signed release supply chain (#65)
- dd738d7 fix(ci): pass the package pattern to the lint action
- d2cfb28 release: ship the local MCP read server (#62)
- 6d104e7 release: ship the local advisory investigation brain (#64)
- 5e50168 release: v0.1.0 signed supply chain (#66)
- 2628d29 test(build): verify Makefile metadata injection
- 399b3bd test(cache): prove real fleet parity and staleness
- 7e3c594 test(connector): prove real multi-cluster fan-out
- 8203b1d test(e2e): prove MCP across two clusters
- 6c248b3 test(e2e): prove fleet-wide advisory diagnosis
- bb78b19 test(e2e): prove local operations across two clusters
- 779a0ac test(e2e): prove the web IDE across two clusters
- a23f25b test(privacy): prove local no-egress invariants
Verify checksums, signatures, and provenance before installation; see docs/RELEASE.md.
Homebrew 6 trust
Homebrew 6 requires formula-scoped trust for third-party taps:
brew tap ArdurAI/tap
brew trust --formula ArdurAI/tap/sith
brew install sith
Older Homebrew versions without tap trust can omit the trust line. Do not disable tap trust or trust the whole tap.
SPDX attestation verification
Use predicate type https://spdx.dev/Document/v2.3 when verifying an attached SBOM bundle.