Skip to content

v0.4.7

Choose a tag to compare

@houman44 houman44 released this 07 Sep 21:44
· 257 commits to main since this release
838656b

[0.4.7] — 2026-09-07

Added

  • Findings-first certificate restructure (Track A1, #268): certificate.html now surfaces
    critical- and warning-severity findings across all criteria, critical first, in a new section
    between the hero and the relying-party prose summary — a reader reaches "what's wrong" before
    scope/completeness prose. States plainly when there are none, rather than a silent empty
    section. Presentation-only: report.json, attestation.json, summary.json, and badge bytes
    are unchanged.
  • Per-criterion cards show applied weight (Track A2, #271): every rendered metric now shows the
    weight actually applied to the score — renormalized across surviving metrics, matching
    scoreMetrics()'s own renormalization — instead of its nominal declared weight, identically on
    the HTML, Markdown, and terminal certificates. Presentation-only: report.json and the other
    machine artifacts are unchanged.
  • --rubric-pin now accepts witan-rubric-v23-prospective-2026-09-06 (explicit opt-in only; the
    public default stays calibrated v17). v23 adds bounded recognition of coverage-capable
    test-runner flags on commands reachable from a test entry point, with negation guards against
    flags like --no-coverage (#276, #277), and narrows A1's abstention from whole-criterion to
    per-signal so a skip on one unreadable file no longer discards findings/metrics computed from
    files that read fine (#278). No other criterion is signal-scoped yet. Carries no
    precision/recall claim.
  • --run-attempt <n> (Track A5 rider, #282): records which CI run attempt produced a certificate.
    The GitHub Action forwards it automatically from GITHUB_RUN_ATTEMPT; a local scan or any other
    CI never fabricates or defaults one. Surfaced on the HTML/Markdown certificates and as an
    additive-optional predicate.githubRunAttempt field on attestation.json — never inside
    report.json, whose byte-reproducibility guarantee for a pinned revision excludes per-invocation
    values. Verified with a test that scans one revision twice with differing run attempts and
    asserts report.json stays byte-identical while the attestation differs.
  • Certificate remediation output is now prioritized evidence-absence, not one static sentence
    (Track A4, #283): the "what to do next" field is derived from the same gap-detection logic that
    already populates "what was not established" — an unmeasured criterion that could change the
    verdict ranks first, then a capped, per-finding evidence-absence statement for critical/warning
    findings, then the existing coverage/PR-merge-ratio/not-applicable/scan-limitation gaps — with
    every sentence naming an absence, never a score-promise. report.json/attestation.json/
    summary.json/badges unchanged.
  • The HTML certificate's plain-language glossary and "not applicable to this repository" group now
    collapse by default behind native <details>/<summary> (Track A3, #285) — zero JavaScript, so
    the certificate stays a single, offline, self-contained file. Collapsed content stays in the
    markup; a reader with JS disabled or a machine parser still sees it all.

Fixed

  • The MCP Registry publish validator (validate-distribution-metadata.mjs) compared server.json
    against the last observed-live registry state instead of the intended release
    (package.json), so a release-prep commit that missed bumping server.json could still pass
    the check. Root cause of registry issue #1615: v0.4.6 published "0.4.5" to the registry on both
    attempts. Fixed to compare against package.json's version, and docs/release-process.md now
    states that release-identity metadata must be bumped in the same commit that gets tagged (#273).
  • verify-release-currency's cejel.dev check grepped the homepage for a "Current · v"
    marker that moved to /for-engineers/ on 2026-08-31, so it silently reported the surface as
    missing regardless of actual site currency. Split into two checks: the homepage now asserts
    every pinned @cejel/cejel@<version> invocation string names the release version, and
    /for-engineers/ keeps the original marker check (#257).
  • Fixed a CI flake in html-metric-layout.test.ts: the first headless-Chrome invocation in a test
    run pays Chrome's one-time cold-start cost against a shared 15s timeout, which occasionally
    exceeded it on a busy runner. That cost is now paid once in beforeAll, outside any per-viewport
    test's timing budget.

Docs

  • Publishes a defect-class census (docs/defect-class-census.md) mechanically classifying the
    shipped rule inventory against the 2024 CWE Top 25, the 2021 OWASP Top 10, and Cejel's own
    D1-D8 taxonomy, with a CI check that fails on drift between the committed table and a fresh
    derivation (#274, #275). Breadth only — no recall/precision claim.
  • README now publishes v17's calibrated 16/30 and prospective v22's 24/30 in-scope recall figures
    together, with fixture scope and Wilson intervals in the same sentence, guarded so neither
    number can appear without its qualifying context (#259).

[0.4.6] — 2026-09-02