Skip to content

Releases: BargLabs/cejel

Cejel 0.4.5

Choose a tag to compare

@houman44 houman44 released this 25 Aug 00:26
91cb835

Cejel 0.4.5 makes every reader-facing certificate measurement self-contained: enumerable checks name what was found and missing, conditional metrics explain when they apply, status reconciliation now states both agreement and non-applicable cases explicitly, and the former “Claim match rate” display label is replaced by the honest “Implementation-to-claim-source file ratio” with its limit on the face of the certificate. Long HTML metric explanations now wrap safely at supported viewport widths.

The CLI adds --product-name for stable caller-supplied identity across differently named checkouts and --rubric-pin as an explicit, fail-closed route to published prospective rubrics. Caller identity is labeled as context rather than scored evidence; prospective pins are labeled uncalibrated on every human-readable surface. Omitting either flag preserves the calibrated public default, witan-rubric-v17-2026-07-24.

Distribution and verification hardening includes release-binary SBOM scoping, public-surface release-currency readback, and complete presentation/registry regression guards. Existing reports and attestations remain valid; new reports may carry optional presentation metadata documented in the changelog.

Full changelog: https://github.com/BargLabs/cejel/blob/v0.4.5/CHANGELOG.md

Cejel 0.4.4

Choose a tag to compare

@houman44 houman44 released this 18 Aug 21:46
v0.4.4
21ae64c

Cejel 0.4.4 fixes two install-path bugs found by a new CI check that actually exercises the MCP install routes instead of leaving them offered-but-never-tried: the OpenClaw MCP command now pins openclaw@latest and @cejel/cejel@latest instead of a bare openclaw, which on Node 22.15.0 could silently resolve a release predating the mcp add/mcp doctor subcommands the instructions used; and the Smithery instructions now call out that smithery mcp add requires an account, with the no-login generic MCP client config offered as the alternative.

A certificate integrity gap closes: scoreRepoWithPublicCejel — the sealed scoring path shared by the CLI and every published leaderboard row — now rejects an explicitly supplied but unwired rubricVersion instead of silently falling through and naming a rubric that never actually ran. Found while regenerating the public leaderboard.

The .term-tooltip glossary/metric tooltips on the HTML certificate now wrap safely instead of overflowing their box, for any tooltip text longer than the curated glossary anticipates. Reported by an external reviewer.

execGit — the sole production Git subprocess boundary — now scopes the trusted safe.directory entry to the exact scanned working directory instead of relying on ambient global Git config, closing a cross-UID Docker/CI mount gap without widening trust. The bare-npx-invocation guard now fails closed on any unpinned npx/pnpm dlx/bunx invocation of a public-facing package named in this repository's docs, not just @cejel/cejel itself. The release-currency verifier now checks published content, not just version markers, across every surface including a new twelfth one (cejel.dev/changelog/) — this is what caught the leaderboard's stale scorer version and an unpinned npx hero command before this release. Windows and Linux-aarch64 published binaries are now verified against their real target platforms after each release, alongside the existing per-target smoke checks.

Two new opt-in, uncalibrated scanning surfaces ship behind separate npm subpaths that nothing in the default scan imports: a decision-contract conformance checker (@cejel/cejel/decision-contracts) and a D6 shell-signature rule (@cejel/cejel/d-series). Three prospective rubric versions (v20/v21/v22) are selectable only by an explicit evaluation driver that pins rubricVersion; none carry a calibration claim.

The calibrated public default remains v17. This release does not change scoring, rubric behavior, detectors, or published calibration figures — verified with a paired comparison of published 0.4.3 against this release across 8 pinned repos spanning 8 language ecosystems, default settings, zero differences in any field but version metadata. A new regression test (default-scan-pack-isolation.test.ts) asserts the two new packs stay structurally unreachable from the default scan path going forward.

Full changelog: https://github.com/BargLabs/cejel/blob/v0.4.4/CHANGELOG.md

Cejel 0.4.3

Choose a tag to compare

@houman44 houman44 released this 17 Aug 22:19
9b3ef1d

Cejel 0.4.3 closes the stale-version trap an external reviewer hit on first use: npx @cejel/cejel . with no version spec could silently resolve a cached build months out of date, with no error or warning. Every documented invocation across the README, leaderboard site copy, and the calibration issue template now pins @latest, and a guard test fails the build if an unversioned invocation is reintroduced. The Markdown certificate now also carries the CLI version — previously only the HTML and JSON (attestation) certificates recorded it.

Two metric labels still read "primitive coverage" after the 0.4.2 glossary revision meant to remove that word; they now read "Production-readiness basic checks" and "PR trace basic checks" everywhere. A presentation defect in "Lowest contributing measurements" — where a fully-satisfied metric could still appear in that list when its criterion had few measured metrics — is fixed, and a metric's displayed unit no longer repeats the trailing word already in its own label (e.g. "Recent PR merge ratio 0/1 ratio" now reads "Recent PR merge ratio 0/1"). Certificate tooltips now sit clearly above the page, with a higher stacking order and an elevation shadow, instead of blending into the content behind them.

This release also documents the recognized-CI boundary: which five CI systems Cejel treats as real signal, why absence there scores as a true negative rather than an abstention, and why that recognized set changes only through a version-gated rubric change.

The calibrated public default remains v17. This release does not change scoring, rubric behavior, detectors, or published calibration figures.

Cejel 0.4.2

Choose a tag to compare

@houman44 houman44 released this 14 Aug 17:06
8b70fd7

Cejel 0.4.2 improves the human-readable trust certificate across terminal, HTML, and Markdown output. Certificates now provide relying-party orientation, consistent measurements, and a plain-English glossary refined after external review.

Missing coverage is distinguished from a measured zero, capped test-to-source ratios render consistently, and certificate labels distinguish basic checks from automated pipelines.

The release also authenticates OCI attestation readback, rejects private-path leakage in public transparency artifacts, and adds independent release-currency verification.

The calibrated public default remains v17. This release does not change scoring, rubric behavior, detectors, or published calibration figures.

v0.4.1

Choose a tag to compare

@houman44 houman44 released this 13 Aug 03:27

Patch release: report artifacts are now byte-identical regardless of checkout location (#166). No other change; prospective rubrics and the D6 proposal remain unreleased.

Release 0.4.0

Choose a tag to compare

@houman44 houman44 released this 09 Aug 16:34
03ef74b

Cejel 0.4.0

This coordinated release carries the prospective B4 commit-year v19 implementation for explicit evaluation harnesses while keeping the public default on v17. It also adds the separate resource-bounded discovery collector v2 without modifying the SHA-pinned v1.9 collector or historical contracts.

The distribution path reads the exact MCP Registry version back, requires its workflow-derived immutable OCI digest, verifies the GitHub SLSA attestation against the exact release tag and source commit, and reports that tagged-source commit.

The preregistered v19 paired rescore completed 24/24 rows with 0 raw freshness, B4 score/status, headline/coverage, placement, or non-B4 changes. This authorizes the prospective implementation and published delta only; it does not promote v19. The reserved Free LLM CLI remains unavailable.

Release provenance note

The first v0.4.0 distribution run published the OCI image, its signed provenance, and the exact-digest MCP Registry record, then its final automated verifier stopped before GitHub attestation verification because GH_TOKEN was not exported. The Registry readback itself succeeded. An authenticated independent execution of the same verifier confirmed:

  • MCP/OCI digest: sha256:63bd4342c2006c823b0283313036109040651741078e1a0e38677d605a2849ee
  • signed tagged-source commit: 03ef74b
  • source ref: refs/tags/v0.4.0

PR #132 adds the missing job-scoped token for future tagged workflows and records the incident. The immutable v0.4.0 tag and published artifacts were not moved, rebuilt, overwritten, or republished.

See CHANGELOG.md for the full evidence boundary.

Full Changelog: v0.3.2...v0.4.0

CONSTRAINTS-VERSION: 2026-08-01.3

Release 0.3.2

Choose a tag to compare

@houman44 houman44 released this 07 Aug 17:09

What's Changed

Full Changelog: v0.3.1...v0.3.2

v0.3.1

Choose a tag to compare

@houman44 houman44 released this 07 Aug 15:59
c48778d

Breaking

  • report.json and summary.json no longer include generatedAt. The machine-readable scan
    time is provenance for the run, not a repository finding, and now lives in
    attestation.json; the certificate retains its existing human-readable date. Re-running the
    same input now produces byte-identical report and summary artifacts; consumers that read
    generatedAt from either artifact must instead read attestation.json.

Added

  • A separate opt-in D-series pack entrypoint adds the high-confidence D1
    declared-but-unread-config rule. It uses Cejel's resolved TypeScript module graph, cites the
    exact declaration path, and abstains on dynamic config access. It does not feed A1-B6 scoring;
    the frozen three-seed D1 baseline remains unchanged and exact-signature acceptance is reported
    separately.
  • The opt-in D-series pack adds a narrow D2 swallowed-error rule for an awaited operation whose
    catch discards its bound error while returning a static failure result. Exact acceptance and the
    23-repository precision gate are reported separately because the frozen 16-case suite contains
    no D2 seed. The rule does not feed A1-B6 scoring or change the published leaderboard.
  • The opt-in D-series pack adds a narrow D3 unasserted-set-transform rule for a filter that reports
    literal success while pairing retained output with a statically empty explanation ledger. Exact
    acceptance and the 23-repository precision gate are reported separately; the frozen five-seed D3
    baseline remains unchanged. The rule does not feed A1-B6 scoring or change the leaderboard.
  • The opt-in D-series pack adds a narrowly bounded D4 rule for an exact caller/callee shape where a
    statically signalled failure is converted to an empty collection and then returned as literal
    success. It does not infer that emptiness is itself defective, feed A1-B6 scoring, or claim any
    of the four frozen semantic D4 seeds as caught.
  • The opt-in D-series pack adds the high-confidence D5 self-referential-verification rule for
    equality assertions whose visibly named expected value and exercised code are imported from the
    same first-party module. It cites the assertion path and remains outside A1-B6 scoring; the frozen
    four-seed D5 baseline remains unchanged and exact-signature acceptance is reported separately.

Release provenance

0.3.1 is the first Cejel release published with build provenance. The npm package and the
container image both carry attestations naming commit
c48778d54444870a8185d09bdfe5b966ff309221 at ref refs/tags/v0.3.1.

0.3.0 was tagged and built but never published — the registry rejected the upload after a
transparency-log entry had already been created for that real build. The v0.3.0 tag remains
in place; 0.3.1 is its successor, not a retagged retry.

Verify

npm view @cejel/cejel@0.3.1 --json
curl -s "https://registry.npmjs.org/-/npm/v1/attestations/@cejel%2fcejel@0.3.1"

Both resolve to the commit above.

Cejel v0.2.2

Choose a tag to compare

@houman44 houman44 released this 29 Jul 15:15
1054811

Cejel 0.2.2

This coordinated patch release adds Windows and OpenClaw distribution, ships the hardening already merged on main, and fixes confirmed-live certificate presentation issues without changing the rubric, detectors, scores, criterion statuses, or verdict behavior.

Added

  • cejel-Windows-x86_64.exe, built as a Node SEA and verified on Windows with --version, --help, a real scan, source/binary parity, and a second scan while outbound networking is denied.
  • A per-binary SPDX SBOM alongside every own-platform verification receipt, SHA-256 checksum, and GitHub-signed release-set provenance bundle.
  • OpenClaw MCP configuration through the package's shipped cejel-mcp stdio bin, with the OCI image as an alternative.

Fixed

  • Certificates now show both the producing Cejel CLI version and the exact rubric version.
  • Certificates explain when a calibrated dimension band differs from the weighted numeric-score band.
  • Tarball scans now warn when Git history is unavailable and the B2 recent-PR proxy may undercount the criterion.
  • npm documentation uses @latest, explains the stale npx cache footgun, and shows how to check the executing version.

Included from main

  • #39 patch-distribution documentation
  • #40 and #42 D8 Git transport hardening
  • #41 free-core v50 multiple-comparisons disclosure
  • #43 cross-repository preflight script

Windows signing

The Windows executable is intentionally not Authenticode-signed in 0.2.2. The build removes Node's inherited signature and asserts that the final executable is NotSigned. Microsoft SmartScreen may therefore intervene. This release uses the documented verification-first path: own-platform receipts, SPDX SBOMs, SHA-256 checksums, and GitHub-signed build provenance. The NotSigned assertion must be replaced when an approved Authenticode or Azure Trusted Signing path is introduced.

Product boundary

Free Cejel scans code selected by the caller. OpenClaw distribution is an adoption surface; it does not watch, intercept, or govern an agent's runtime actions. Runtime-action governance remains a separate future Agent Pack boundary.

Full details: CHANGELOG.md

Cejel v0.2.0

Choose a tag to compare

@houman44 houman44 released this 25 Jul 03:39
e7b20f9

Cejel v0.2.0 promotes the free-core calibration GO and rubric v17 as the public default.

Highlights

  • Free-core v50 terminal GO: 96.43% finding precision (94.16% lower bound), 95.64% worst-case recall (92.23% lower bound), and 0.66% worst-case FPR (1.10% upper bound).
  • No aggregate candidate or control insufficiency; 200 frozen repositories and 3,405 audited packet cases.
  • Public Action output now distinguishes finding severity from dimension band and represents abstention explicitly.
  • Leaderboard corpus and rubric changelog are rescored and published with witan-rubric-v17-2026-07-24.

Verification

  • Distribution metadata, typecheck, build, and 528 tests passed.
  • Self-cert and badge parity passed.
  • npm dry-run produced cejel-cejel-0.2.0.tgz.
  • Native binaries, checksums, provenance, OCI/MCP metadata, Homebrew, and site deployment are attached and verified in the remaining release workflow.