Repository navigation
PermitProbe v0.2.1
PermitProbe v0.2.1 release notes
PermitProbe v0.2.1 hardens report confidentiality, validation availability, evidence lineage and
release provenance following an independent adversarial review of v0.2.0.
Report privacy
Discovery no longer guesses whether an observed path segment is sensitive from its length or
entropy. A response-derived literal survives only when it already occurs in a declared resource
path or is explicitly listed in api.discovery.report_path_literals. Query names follow the same
rule through declared public query contracts and report_query_names. All other values become
{value} or a redacted-name count; reports retain only the number of merged observed variants.
Because different raw locations can now share one safe shape, discovery.* findings are not
eligible for known-finding baselines. They remain visible until the operator adds an explicit
route contract or removes the discovery source.
Bounded validation
api.validation_timeout_ms sets a total wall-clock budget, defaulting to 5000 ms, for JSON
parsing, JSON Schema evaluation and collection/object identity checks in one execution batch.
The budget measures local validation work rather than network time. Expiration records
data.validation_budget, preserves completed delivery evidence and exits 2.
This closes cases where a small response combined with an expensive regular expression, or a
bounded response containing a costly uniqueItems comparison, could occupy a runner beyond the
HTTP timeout.
Active exploration shares one validation budget across its batches and clips each validation to
the remaining total exploration deadline. The POSIX signal-based interrupt requires main-thread
execution with no pre-existing ITIMER_REAL; unsupported library embeddings fail closed as
inconclusive instead of validating without a deadline.
Target-bound evidence
The normalized target scheme, hostname and port now participate in the policy digest. Findings,
baselines, exploration checkpoints and retests are therefore bound to the environment that
produced them. A deployment label cannot turn a finding into fixed on a different origin.
This deliberately invalidates v0.2.0 baseline continuity. Run v0.2.1 against the intended target,
review its findings and create a new baseline. Do not copy or edit old digest values.
Release provenance
The registry-publishing workflow checks out the exact requested tag. Before PyPI upload, it
compares every installed package file in the wheel and sdist with that checkout and verifies the
sdist pyproject.toml byte-for-byte. GitHub asset digests, metadata checks and the isolated-wheel
safe demo remain required.