Data Boar 1.7.4 GA (xkcd 2¹⁰)
Release 1.7.4
Status: Released (2026-06-26) — merge via PR #1024 (xkcd 2¹⁰); tag v1.7.4, GitHub Release, and Docker Hub publish follow operator release-ritual post-merge. #970 = premature stable attempt without gate — does not VOID this release (ADR-0072, ADR-0073). maturity_build = 201 side-channel (#976).
Public version: 1.7.4 · ADR-0073 Accepted · release gate #406 closed in this train.
Historic RC ladder: 1.7.4-rc.md · 1.7.4-rc-2 working line before this GA.
Highlights
- Maestro Linux-port (gate #704):
Handle-LicensingMatrix.ps1now runs correctly on pwsh-Linux —-WindowStyle Hiddenguarded by$IsWindows;Start-Processwrapped intry/catchto propagate spawn failures; locale-independent redirect detection via HTTP status code (#827, #818, #820). - Licensing matrix enforced (community / pro / enterprise):
Stop-MatrixApiProcesscross-platform; no port collision between tiers on Linux (#820). - Completão smoke gate machine-verifiable: all 10 handlers write
/tmp/databoar_handler/<persona>_sentinel.txtwith the actual bash exit code;Wait-HandlerSentinel.ps1polls and aggregates real pass/fail (#831). - Safe
tmuxpayload injection: base64-encoded payloads +-Refallowlist in all 10 handlers — eliminates shell-quoting injection risks (#830). - Security hardening (#825):
hmac.compare_digestfor API key and MAC comparison (timing-safe); Chart.js vendored (api/static/), CSPscript-src 'self'; rsync excludes.env/.env.*;Maestro.ps1exits non-zero on real handler failures. - 5th lab host registered: alpine emachines E527 added to manifest and documentation (#821).
- Maestro / completão Deep smoke:
lab-completao-host-smoke.shaccepts--bench-config PATH; Docker, Podman, Swarm, LXD, and MicroK8s handlers pass--bench-configbefore--lab-stack-up(#404, #408).
Unreleased changelog source (dense / pre-move from root CHANGELOG)
The root CHANGELOG.md Unreleased section follows Keep a Changelog categories for scanability; this subsection retains the older long-form bullets for operators who need paths, rollback hints, and cross-links in one place.
- Config redaction:
config/redact_config.pyuses substring key matching (withtoken_urlallowlist) so compound keys liketelegram_bot_tokenandfile_passwordsredact on GET/config— #622. - Man page (
data_boar.5): documentlocaleblock and unifiedpatterns_plugin_filesection — #444, #431. - Issue queue / PMO: refresh
PLANS_TODO.mdtriage snapshot (135 open, head-of-queue P1 man + #483; P0 only #606 product scope). - Governance docs: Contributor Covenant 2.1 in
CODE_OF_CONDUCT(+ pt-BR); refreshTERMS_OF_USEandPRIVACY_POLICY(+ pt-BR) for 1.7.4-rc, tier matrix cross-links, optional dashboard auth, and maturity-assessment local storage — closes #419, #423, #424. - Legacy DB module filename:
db/databasse.pyrenamed todb/database.pyso filesystem paths matchsonar-project.propertiesexclusions and operator mental model (GitHub #488). - Release candidate (working line): bump
1.7.4-rconmain(pyproject.toml, man.TH, hybrid lab image defaults, PUBLISHED_SYNC reconciliation); draft GitHub pre-release checklist indocs/releases/1.7.4-rc.md— no Docker Hublatestmove until1.7.4final. - Maestro / completão (Deep benchmark argv):
scripts/lab-completao-host-smoke.shparses--bench-config; container handlers (Docker, Podman, Swarm, LXD, MicroK8s) pass that flag before--lab-stack-upso Deep smoke no longer hitsexit 2on unknown args (issues #404, #408). Draft stable checklist:docs/releases/1.7.4.md. - Lab lessons public archive:
docs/ops/lab_lessons_learned/dated snapshots + hubLAB_LESSONS_LEARNED.mdcontract (ADR 0042); situational.cursor/rules/lab-lessons-learned-archive.mdc; session tokenlab-lessonsinsession-mode-keywords.mdc; cold-start ladder, policy hubs,LAB_COMPLETAO_RUNBOOK,PLANS_TODOIntegration row, and phase-2 situationalization inventory updated. - SQL sampling (SRE + audit posture): Shared builders in
connectors/sql_sampling(tagged SQL, dialect hints),connectors/sql_table_row_estimatefor metadata-first row caps, optional per-statement timeouts andinter_query_delay_msonSQLConnector/ Snowflake,core/sampling_policyfor YAML overrides, and filesystem SQLite path integration. See ADR 0043 and PLAN_SQL_SAMPLING_SRE_AND_AUDIT_EVIDENCE.md. - Lab hybrid completão:
scripts/lab-completao-orchestrate-hybrid-v173.ps1resolvessshHost+ firstrepoPathsfrom the lab manifest; LAB-NODE-02 scan dir prefers/home/leitao/Documentsthen/home/leitao/documents; LAB-NODE-01 / LAB-NODE-03 / lab-node-02 usetmux send-keys -t completaowhen that session exists, elsessh … bash -lcpodman/docker; LAB-NODE-04 passive uses the repo clone path for.venv; imagefabioleitao/data_boar:1.7.3. - Docs / quality gates:
docs/TESTING_POC_GUIDE.mdanddocs/TROUBLESHOOTING_MATRIX.md— unique pseudo-headings (MD024);.cursor/rules/public-tracked-pii-zero-tolerance.mdc— LinkedIn placeholder uses<placeholder-slug>sotests/test_pii_guard.pydoes not treat the comma-terminated/in/examplesample as a real slug. - Developer ergonomics (Windows / PowerShell):
CONTRIBUTING(EN + pt-BR) documents correctActivate.ps1venv activation and the not recognized failure when invokingScripts\activatewithout.ps1;tests/test_pwsh_venv_activate_docs.pyguards tracked.md/.mdcfrom reintroducing the bad.venv…Scripts…activatepath pattern. - Ops docs:
docs/ops/CURSOR_RULES_PHASE2_SITUATIONALIZATION.md(+ pt-BR) — Tier A inventory, Tier B/C backlog, why locale +docker-local-smoke-cleanupstay strongly always-on, pros/cons, and a 13-step reproducible ritual for the next situationalization batch (token-aware follow-up). - Cursor rules (phase 2 — plans / Sonar MCP / study cadence):
plans-status-pl-sync.mdc,plans-archive-on-completion.mdc,sonarqube_mcp_instructions.mdc, andstudy-cadence-reminders.mdcare situational (alwaysApply: false) with narrowglobs; session tokenssonar-mcp/study-check(and scope tokensdocs/feature/houseclean/backlogfor plan drift) plus@…latches bind them in fresh threads —docker-local-smoke-cleanup.mdcstaysalwaysApply: true(short, high-frequency smoke/prune guidance; release sequencing is already situational). Cold-start ladder (EN/pt-BR),session-mode-keywords,AGENTS.md,CURSOR_AGENT_POLICY_HUB, andOPERATOR_SESSION_SHORTHANDSupdated. Rollback:git revertthe commit or restore the four rules fromgit show <parent>:.cursor/rules/<name>.mdc. - Cursor rules (phase 2 — release publish sequencing):
release-publish-sequencing.mdcis situational (alwaysApply: false) with narrowglobsonVERSIONING,docs/releases/**, Docker Hub / image order /PUBLISHED_SYNC,scripts/docker-lab-build.ps1,docker-prune-local.ps1,scripts/docker/README.md, anddocker-smoke-container-hygieneskill; session tokenrelease-ritualand@release-publish-sequencing.mdcbind it in fresh threads —docker-local-smoke-cleanup.mdcstaysalwaysApply: true. Cold-start ladder (EN/pt-BR),session-mode-keywords,AGENTS.md,VERSIONING(+.pt_BR.md),CURSOR_AGENT_POLICY_HUB,OPERATOR_SESSION_SHORTHANDS, anddocker-local-smoke-cleanupcross-links updated. Rollback:git revertthe commit orgit show <parent>:.cursor/rules/release-publish-sequencing.mdc. - Cursor rules (phase 2 — Everything /
es-find):everything-es-cli.mdcis situational (alwaysApply: false) with narrowglobsonscripts/es-find.ps1,EVERYTHING_ES_*,WINDOWS_FAST_CLI_WRAPPERS.*, andeverything-es-searchskill; session tokenes-findand@everything-es-cli.mdcbind it in fresh threads —windows-pcloud-drive-search-discipline.mdcstaysalwaysApply: trueforP:/ huge-tree discipline. Cold-start ladder (EN/pt-BR),session-mode-keywords,AGENTS.md,CURSOR_AGENT_POLICY_HUB,OPERATOR_SESSION_SHORTHANDS, andwindows-pcloud-drive-search-disciplinecross-links updated. - Cursor rules (phase 2 —
docs/private/workspace cues):docs-private-workspace-context.mdcis situational (alwaysApply: false) withglobsonPRIVATE_OPERATOR_NOTES,AGENTS.md,docs/private.example/**,PRIVATE_STACK_SYNC_RITUAL,PRIVATE_LOCAL_VERSIONING, andscripts/private-git-sync.ps1; session tokenprivate-stack-syncand@docs-private-workspace-context.mdcbind it in fresh threads —agent-docs-private-read-access.mdcstaysalwaysApply: true(never self-block). Cold-start ladder (EN/pt-BR),session-mode-keywords,AGENTS.md,CURSOR_AGENT_POLICY_HUB,OPERATOR_SESSION_SHORTHANDS, andstacked-private-syncskill updated. - Windows VeraCrypt default (
Z:):AGENTS.md,windows-pcloud-drive-search-discipline.mdc,session-mode-keywords(private-stack-sync),TOKEN_AWARE_SCRIPTS_HUB,stacked-private-syncskill, andscripts/private-git-sync.ps1align onZ:as the operator default mount for the barenotes-sync.gitmirror;Y:remains a fallback probe only (Z then Y in the script loop). - Cursor rules (phase 2 — homelab SSH):
homelab-ssh-via-terminal.mdcis situational (alwaysApply: false) withglobsdocs/ops/HOMELAB*,scripts/lab-op*,scripts/collect-homelab*,scripts/homelab*, plusdocs/private.example/homelab/**andPRIVATE_OPERATOR_NOTES.md; session tokenhomelabexplicitlyread_file/@-binds this rule; cold-start ladder,AGENTS.md,CURSOR_AGENT_POLICY_HUB,OPERATOR_SESSION_SHORTHANDS. Rollback:git show <parent>:.cursor/rules/homelab-ssh-via-terminal.mdc. - Cursor rules (phase 2 — dossier):
dossier-update-on-evidence.mdcis situational withdocs/private/legal_dossier/**anddocs/private/raw_pastes/**globs; session tokenlegal-dossier-update; ladder +AGENTS.md+ hubs document the latch. - Completão chat latch:
OPERATOR_AGENT_COLD_START_LADDER(+ pt-BR) adds token → rule → wrapper latch;AGENTS.md+CURSOR_AGENT_POLICY_HUBpoint there. - Cursor rules (phase 2 — completão workflow):
lab-completao-workflow.mdcsituational (globsscripts/lab-completao*·docs/ops/LAB_COMPLETAO*); sessioncompletao. Rollback:git show <parent>:.cursor/rules/lab-completao-workflow.mdc. - Agent cold-start (homelab §7): ladder +
AGENTS.mdseventh non-negotiable (integrated terminalssh). - Cross-platform pairing + Linux/macOS gate:
scripts/quick-test.sh,lint-only.sh,pre-commit-and-tests.sh,check-all.sh;SCRIPTS_CROSS_PLATFORM_PAIRING(+ pt-BR);repo-scripts-wrapper-ritual.mdc;TOKEN_AWARE_SCRIPTS_HUB,check-all-gate.mdc,token-aware-automationskill. - Lab-OP sudoers / Podman wrapper:
lab-node-01_labop_sudoersandLAB_OP_PRIVILEGED_COLLECTIONallowlist/bin/bashand/usr/bin/bash.lab-node-01-ansible-labop-podman-apply.shbash resolution +~/.local/binforansible-playbook;lab-node-01_podmanusesansible_facts['ansible_env']. - Void Linux (LAB-NODE-03):
lab-node-01_podmanxbps-install;labop-share-client-install.shfuse-sshfs. - Constrained LAB hosts:
.labop-skip-lab-node-01-podmanskips podman role apply. - Lab personas + Ansible ignore:
LAB_OP_HOST_PERSONAS(+ pt-BR);.gitignoreinventory.local.ini. - Private-git-sync / ladder / completão prompts:
private-git-sync.ps1probes drive root before bare path join;completaolibrary +completao-chat-startertiers +COMPLETAO_MESTREchecklist paths;AGENTS.mdquick index refreshes.
Pre-release checklist (release PR #1024 — operator merge + publish)
- CI green on release branch (Lint + Test + security gates).
-
uv lockmatchespyproject.toml(version = "1.7.4"). -
pyproject.tomlversion = "1.7.4"with no-rc/-betasuffix. - Man pages:
.THline indocs/data_boar.1/docs/data_boar.5shows 1.7.4. - ADR-0073 Accepted; #406 / #977 closed in this PR train.
- Tag + GitHub Release + Docker Hub — operator release-ritual after merge (see below).
-
docs/ops/today-mode/PUBLISHED_SYNC.mdfinal refresh after Hub publish.
Bump type
| From | To | Type |
|---|---|---|
1.7.3 (stable consumer baseline) / 1.7.4-rc on main |
1.7.4 | Minor — adoption docs, governance refresh, Cursor policy situationalization, SQL sampling + lab observability ergonomics (#426) |
How to get 1.7.4 (after publish)
- From source:
uv syncatv1.7.4(ormainwhen it matches that tag). - Docker:
docker pull fabioleitao/data_boar:1.7.4and/ordocker pull fabioleitao/data_boar:latestper your publish policy.
Build and push Docker image
After 1.7.4 final is in pyproject.toml and .\scripts\check-all.ps1 passes on the tag commit:
.\scripts\docker-lab-build.ps1
docker run --rm data_boar:lab python main.py --version
docker tag data_boar:lab fabioleitao/data_boar:1.7.4
docker tag data_boar:lab fabioleitao/data_boar:latest
docker login
docker push fabioleitao/data_boar:1.7.4
docker push fabioleitao/data_boar:latestPaste Short + Full from docs/ops/DOCKER_HUB_REPOSITORY_DESCRIPTION.md into Docker Hub Edit in the same session as the stable push. Refresh today-mode/PUBLISHED_SYNC.md (+ pt-BR) if your ritual includes it.
Publish (tag + GitHub Release)
On the commit that still has version = "1.7.4" in pyproject.toml (before any follow-up -beta / -rc bump on main):
git tag -a v1.7.4 -m "v1.7.4: <short title>"
git push origin main
git push origin v1.7.4
gh release create v1.7.4 --title "v1.7.4" --notes-file docs/releases/1.7.4.mdVerify with gh release view v1.7.4. Full order: situational release-publish-sequencing rule + VERSIONING.md.
After stable publish
Bump main to X.Y.(Z+1)-beta or next -rc in a separate commit after the tag/release/image steps (same sequencing as prior releases).
What's Changed
- fix(ci): unblock main — 4 atomic restores after recent merges (run 25879831696) by @cursor[bot] in #372
- fix(config): scan_scope warning, compliance samples TH/ID/QC, security docs by @FabioLeitao in #373
- chore(deps): consolidate upstream caps for ebcdic and chardet by @FabioLeitao in #374
- ci(actions): bump zizmorcore/zizmor-action from 0.5.3 to 0.5.4 by @dependabot[bot] in #375
- ci(actions): bump github/codeql-action from 4.35.4 to 4.35.5 by @dependabot[bot] in #376
- deps(uv): bump the uv-minor-patch group across 1 directory with 20 updates by @dependabot[bot] in #377
- docs: draft 1.7.4 release checklist (M-PILOT prep) by @FabioLeitao in #428
- docs(man1): operator help sync; fix(maestro): bench Collect sentinel by @FabioLeitao in #466
- docs: Vietnam PDPD + FELCA samples and TECH_GUIDE API routes by @FabioLeitao in #477
- chore(deps): keep pytest stack and tooling out of runtime deps by @FabioLeitao in #499
- fix(docs): man env credentials, legacy db filename, 1.7.4 checklist by @FabioLeitao in #500
- docs(man5,ops): man5 workers/licensing + thin-slice agent handoff by @FabioLeitao in #509
- docs: Contributor Covenant enforcement contact + issue sweep queue by @FabioLeitao in #501
- feat(filesystem): optional mammoth text sample for .doc paths by @FabioLeitao in #515
- fix(engine): catch connector instantiation errors in sequential runs by @FabioLeitao in #518
- feat(compliance): add Brazil health sector sample by @FabioLeitao in #519
- fix(engine): ADR-0049 unknown connector + gitleaks allowlist + pyo3 bump by @FabioLeitao in #526
- feat(cli): --validate-config pre-flight (#520) by @FabioLeitao in #532
- fix(test): _parse_powershell_script timeout 30s (#563) by @FabioLeitao in #564
- feat(cli): --diff session comparison (#521) by @FabioLeitao in #565
- feat(cli): add --export-dsar for DSAR-oriented JSON export (#522) by @FabioLeitao in #566
- feat(licensing): tier fixtures and graceful feature_gate (#559) by @FabioLeitao in #567
- test(licensing): governance_lens OPEN tier regression guard by @FabioLeitao in #568
- docs(plans): G0-G3 gravity tier, plan checkbox discipline, ADR inventory by @FabioLeitao in #584
- chore(workflow): private-git-sync VC secrets and bounded pCloud mirror by @FabioLeitao in #596
- docs(use-cases): hub + scan/remediate, tokenized findings, biometrics by @FabioLeitao in #607
- docs(pitch): executive hub and stakeholder, DPO, CISO decks by @FabioLeitao in #608
- docs: add AUDIENCE_GUIDE with role trails and overlap matrix by @FabioLeitao in #612
- docs: QUICKSTART root guide; audit.ps1 -Mode and exit code by @FabioLeitao in #613
- docs: primers hub, privacy standards primer, hubs INDEX + check_hubs gate by @FabioLeitao in #614
- docs(ops): add INTEGRITY_HUB navigation hub (#576) by @FabioLeitao in #615
- docs(adr): ADR-0056/0057, RULES_AND_SKILLS_HUB, inventory sync tests by @FabioLeitao in #619
- docs(ops): DOCS_AND_HUBS_INDEX master hub index by @FabioLeitao in #620
- docs: CoC 2.1 + terms/privacy refresh (1.7.4-rc) by @FabioLeitao in #621
- fix(security): redact compound keys; man5 locale + plugin; PMO triage by @FabioLeitao in #624
- docs(conduct): databoar.com.br aliases for CoC and compliance contact by @FabioLeitao in #628
- docs(plans): governance/ITSM diagram source for primers #629/#630 by @FabioLeitao in #633
- docs(plans,adr): PRIMERS_HUB hygiene + ADR-0058 by @FabioLeitao in #634
- fix(security): Excel formula injection + API bind warning (#547, #549) by @FabioLeitao in #635
- fix(plugins): validate ml/dl pattern files (ADR-0052, #433) by @FabioLeitao in #636
- [G0·S] chore(hooks): agent safety hardening — beforeShellExecution + pre-commit ADR boundary by @FabioLeitao in #648
- wave-656: release prep 1.7.4 + meta-rules + security (phases 1-3 + partial 4) by @FabioLeitao in #658
- docs(adr): ADR-0061 U-axis sub-order and cross-milestone gate (#655) by @FabioLeitao in #665
- docs(adr): ADR-0062 agent-containment triple-audit offband ping-pong (#659) by @FabioLeitao in #666
- docs(ops): issue queue sequencing map (#654) by @FabioLeitao in #667
- fix(licensing): license-pub-v1.pem + ocr_images PRO tier (#701 #702) by @FabioLeitao in #724
- fix(security): generate canonical build digest for tamper checks (#711) by @FabioLeitao in #726
- feat(security): release manifest generator for file integrity (#713) by @FabioLeitao in #727
- docs(adr): ADR-0066 TAMPERED state behavior (#715) by @FabioLeitao in #729
- fix(security): mask credential env names in validate-config warnings (#730) by @FabioLeitao in #733
- fix(security): resolve CodeQL alerts (#731) by @FabioLeitao in #734
- ci(workflow): enable zizmor enforced mode (#732) by @FabioLeitao in #735
- fix(licensing): TAMPERED tier cap in enforced mode (#712) by @FabioLeitao in #737
- fix(database): migrate filesystem_findings Phase 1 columns (#736) by @FabioLeitao in #738
- chore(scripts): accept --dbtier community in dev JWT issuer (#706) by @FabioLeitao in #739
- feat(licensing): enforce JWT tier gates at MVP call sites (#699) by @FabioLeitao in #740
- feat(maestro): Handle-LicensingMatrix JWT tier matrix smoke (#707) by @FabioLeitao in #741
- docs(assets): add governance and forensics diagrams to docs/assets/diagrams/ by @FabioLeitao in #746
- fix(maestro): handle PS7 redirect exception and bypass locale middleware for JSON requests by @FabioLeitao in #751
- docs(workflow): today-mode 2026-05-29 + #756 lab-disk carryover by @FabioLeitao in #757
- docs(adr): normalize Related docs to table format (#572) by @FabioLeitao in #758
- feat(grc): optional nist_csf_function_hint (CSF 2.0) by @FabioLeitao in #764
- ci(actions): bump zizmorcore/zizmor-action from 0.5.4 to 0.5.6 by @dependabot[bot] in #661
- fix(deps): bump pyjwt 2.12.1 → 2.13.0 (PYSEC-2026-175/177/178/179) by @FabioLeitao in #775
- docs(plans): index #704 #719 #747 #756 in PLANS_TODO + carryover (signed, supersedes #774) by @FabioLeitao in #776
- fix(ci): resolve zizmor workflow-security findings (#388) by @FabioLeitao in #777
- fix(ci): resolve zizmor online findings — Zizmor green on main (#388) by @FabioLeitao in #778
- fix(maestro): port orchestrator to native Linux (#786) by @FabioLeitao in #787
- chore(workflow): canonical lab bare hosts for private-git-sync by @FabioLeitao in #788
- fix(maestro): T14 run repairs (#789-792) by @FabioLeitao in #793
- fix(ci): declare SLACK_WEBHOOK_URL on slack workflow_call (#795) by @FabioLeitao in #796
- deps(uv): bump the uv-minor-patch group across 1 directory with 26 updates by @dependabot[bot] in #780
- ci(actions): bump github/codeql-action from 4.35.5 to 4.36.0 by @dependabot[bot] in #660
- ci(actions): bump SonarSource/sonarqube-scan-action from 7.1.0 to 8.1.0 by @dependabot[bot] in #662
- fix(deps): add httpx2 dev dep for starlette TestClient (#799) by @FabioLeitao in #800
- docs(adr): enrich ADR-0045 as UMADR constitution by @FabioLeitao in #804
- fix(security): pii_history_guard three-dot diff when branch behind main by @FabioLeitao in #806
- docs(homelab): primary Linux workstation protection (ADR 0068) by @FabioLeitao in #807
- fix(ci): pass SLACK_WEBHOOK_URL to slack notify callers (#797) by @FabioLeitao in #798
- fix: bugs de auditoria cli/db (#808, #810) by @FabioLeitao in #814
- docs/chore: glossário + higiene raiz + private.example (#809, #812, #813) by @FabioLeitao in #815
- chore(adr): retrofit ADR-0061/0062 to UMADR + audit 0046-0058 + ADR-0065 NIST stub by @FabioLeitao in #817
- docs: i18n parity (ADR README, Taxonomy Axes) + Podman runbook (#669, #673, #670) by @FabioLeitao in #819
- docs(decision): .doc OLE/CFBF won't-fix — document rationale in TROUBLESHOOTING (#671) by @FabioLeitao in #822
- fix(maestro): Linux-compat redirect + process/port cleanup (#818, #820) by @FabioLeitao in #823
- docs(cursor+homelab): CLAUDE.md, executor×auditor contract, alpine-emachines 5th host (#816, #821) by @FabioLeitao in #824
- fix(maestro/security): Linux-compat + sentinel/escape + hmac + Chart.js vendor (#827, #830, #831, #825) by @FabioLeitao in #833
- release: bump 1.7.4-rc → 1.7.4 + CHANGELOG + release notes by @FabioLeitao in #840
- feat(onboarding): zero-config demo entrypoint scripts/demo.sh + README (#834) by @FabioLeitao in #841
- security(detector): ReDoS guard on third-party regex overrides (#829) by @FabioLeitao in #842
- security(connectors): SSRF guard on outbound URLs (#832) by @FabioLeitao in #844
- security(licensing): kill env tier bypass — fail-closed enforcement + audit trail (#719) by @FabioLeitao in #847
- feat(licensing): QA local signed licenses — 60-day machine-bound issuer by @FabioLeitao in #848
- feat(licensing): connector tier gating — FEATURE_TIER_MAP + registry gate (#843, #705) by @FabioLeitao in #849
- feat(licensing): worker cap dbmax_workers + CI matrix Python 3.14 signal-only (#551) by @FabioLeitao in #850
- chore(privacy): genericize lab hostnames in PLANS_TODO (public hygiene) by @FabioLeitao in #851
- feat(licensing): runtime fingerprint binding + deployment pack (#718, #846) by @FabioLeitao in #852
- feat(licensing): ratify tier ladder — Pro=2 deploys, workers 2/4/8/∞ (#853, docs #855) by @FabioLeitao in #858
- feat(integrity): Phase E — SQLite anchor + re-verify + TINTED/-alpha + open-mode clamp (#856) by @FabioLeitao in #857
- docs(licensing): Pro+ band + tier/claim tables + LICENSE_FAQ (EN+pt-BR) — #855/#853 sweep by @FabioLeitao in #859
- docs(licensing): LICENSE_FAQ — operator draft points (air-gapped, auditability, declarative plugins, official build) by @FabioLeitao in #861
- feat(licensing): revocation kill-switch — sub/jti/dbkid matching, fail-closed + audit (#717) by @FabioLeitao in #862
- feat(licensing): connector tier map fail-closed — unknown type blocked, explicit open-core entries (#854) by @FabioLeitao in #863
- chore(test): warm pwsh once per session + ParseFile timeout 60s (#860) by @FabioLeitao in #864
- deps(uv): bump types-pyyaml from 6.0.12.20260508 to 6.0.12.20260518 by @dependabot[bot] in #664
- ci(zizmor): fix ref-version-mismatch repo-wide (#878) by @FabioLeitao in #879
- ci(zizmor): disable online-audits for deterministic runs (#880) by @FabioLeitao in #881
- ci(zizmor): grant security-events: write for SARIF upload on push (#880 follow-up) by @FabioLeitao in #882
- chore(deps): bump cryptography, python-multipart, starlette to clear CVEs by @FabioLeitao in #896
- feat(ci): deterministic anti-overclaim gate test_claims_consistency (#894) by @FabioLeitao in #895
- feat(rust): maturin as dev-dep + build-capable vs wheel doc (#892) by @FabioLeitao in #897
- chore(deps): bump pyo3 from 0.24.2 to 0.29.0 in /rust/boar_fast_filter in the cargo group across 1 directory by @dependabot[bot] in #866
- chore(deps): bump pypdf floor to >=6.13.0 (clear CVE-2026-54530/54531) by @FabioLeitao in #899
- fix(packaging): requirements.txt pip-installable for uv-less clients (#891) by @FabioLeitao in #898
- fix(rust): build-rust-prefilter.ps1 uv-first + cross-platform (#890) by @FabioLeitao in #901
- fix(maestro): actionable Sync-ContainerArtefact fallback + regression guards (#888) by @FabioLeitao in #902
- fix(maestro): reconcile Handle-web exit code after recovery (#889) by @FabioLeitao in #903
- ci(actions): bump checkout 6.0.3, setup-uv 8.2.0, gitleaks v3 (Lote A Dependabot) by @FabioLeitao in #904
- docs(ops): today-mode 2026-06-16 — safe Dependabot drain (A->C->B) by @FabioLeitao in #905
- deps(uv): bump redis 7.4.0 -> 8.0.0 (Lote C Dependabot) by @FabioLeitao in #906
- deps(uv): Lote B Python bumps + cap rpds-py<2026 (Dependabot) by @FabioLeitao in #907
- test(deps): guards for rpds-py<2026 cap + plotly 6 dashboard path by @FabioLeitao in #908
- docs(adr): ADR 0069 — cap rpds-py below the 2026 CalVer pivot (+ dependabot ignore + guard) by @FabioLeitao in #909
- feat(licensing): issuer accepts encrypted signing key passphrase (#910) by @FabioLeitao in #913
- docs(adr): ship SSHSIG attestation + allowed_signers trust anchor (ADR-0056, #916) by @FabioLeitao in #917
- fix(ci): ignore mariadb PYSEC-2026-217 in pip-audit (no fix yet, #922) by @FabioLeitao in #923
- docs(glossary): provenance, SAST/CI chain, DMBOK governance & ADR lineage by @FabioLeitao in #921
- docs(adr): ADR-0070 — primer taxonomy and home (Proposed) by @FabioLeitao in #924
- docs(glossary): define TAMPERED and TINTED (-alpha) trust terms (Closes #919) by @FabioLeitao in #920
- docs(primers): primer taxonomy — accept ADR-0070, create docs/primers/ (Closes #744) by @FabioLeitao in #925
- docs(adr): re-sign INVENTORY.txt.sig (ADR-0056, after #925) by @FabioLeitao in #927
- docs(testing): sync TESTING.md test module table (Closes #485) by @FabioLeitao in #928
- docs(man5): document sensitivity_detection connector/fuzzy keys (Closes #455, #456) by @FabioLeitao in #930
- ci(actions): bump github/codeql-action from 4.36.0 to 4.36.2 by @dependabot[bot] in #911
- docs: pt-BR mirrors for LICENSING_SPEC + HOSTING_AND_WEBSITE_OPTIONS (#680) by @FabioLeitao in #933
- docs(releases): feature highlights for v1.7.3 (#463) by @FabioLeitao in #934
- docs(quickstart): audience-fit fixes — maintainer ritual, Caminho B label, bash path (#689) by @FabioLeitao in #936
- docs(audience-guide): drop stale #577 hub note + add PMO/CFO/CCO entries by @FabioLeitao in #938
- docs(readme): add forensic-grade positioning tagline (en_US + pt_BR) by @FabioLeitao in #939
- chore(deps): bump pypdf to 6.13.3 (GHSA-jm82-fx9c-mx94) by @FabioLeitao in #943
- fix(completao): close 1.7.4 gate self-provisioner queue (#931 #937 #935 #940 #941) by @FabioLeitao in #942
- docs: fix adoption-path doc drift in entry docs (#945) by @FabioLeitao in #947
- security: self-protecting PII seed gate (#944) by @FabioLeitao in #946
- fix(maestro): completão gate correctness — #794 ASCII, #951 fast-filter wheel, #952 SSH probe, #950 build guard by @FabioLeitao in #961
- chore(release): UNDO unauthorized 1.7.4 promotion → 1.7.4-rc-2 — refs #970 by @FabioLeitao in #972
- docs(changelog): historicidade 1.7.4 VOID + targeting 1.8.0-beta (#772 #976) by @FabioLeitao in #979
- docs(adr): ADR-0072 Commit Gate vs Release Gate (Proposed) — refs #973 by @FabioLeitao in #980
- docs(adr): ADR-0073 octet-maturity + roadmap (Proposed) — refs #977 by @FabioLeitao in #981
- docs(versioning): octet-maturity + roadmap — refs #971 by @FabioLeitao in #982
- docs(agents): Release & Versioning guardrails — refs #978 (a) by @FabioLeitao in #983
- test(release): CI guard stable-com-gate-aberto + denylist 1.7.5 — refs #978 (b) by @FabioLeitao in #986
- chore(cursor): release-versioning.mdc situational guard — refs #978 (c) by @FabioLeitao in #985
- docs(security): posture hub + recover L14 gold — refs #992 by @FabioLeitao in #995
- docs(dashboard): web-first Help + USAGE with screenshots (#1005) by @FabioLeitao in #1008
- docs(use-cases): backup/data-protection criticality-overlay storyboard + GTM partner-channel thesis by @FabioLeitao in #965
- fix(maestro): P0 completão bundle — tmux, sentinels, collect, doas env by @FabioLeitao in #966
- test(pwsh): Pester harness + Tranche 1 logic tests (#984) by @FabioLeitao in #1002
- docs(adr): amend ADR-0062 cross-vendor containment (#991) by @FabioLeitao in #1001
- ci(workflow): operator-gated issue close guard (#990) by @FabioLeitao in #1000
- docs(adr): dangling ADRs + Reserved enum — refs #993 by @FabioLeitao in #996
- docs(adr): ADR-0074 supply-chain posture Proposed — refs #987 by @FabioLeitao in #997
- ci(security): supply-chain Layer 1 — refs #988 by @FabioLeitao in #998
- docs(adr): destensionar ADR-0073 versioning by @FabioLeitao in #1013
- docs(adr): ratificação-prep ADR-0071 + ADR-0072 by @FabioLeitao in #1015
- docs(adr): ROUND 1 ratification — Accepted + Ratified-By (awaiting operator signature) by @FabioLeitao in #1018
- fix(maestro): #969 alpine sync scp+tar fallback + status reset by @FabioLeitao in #1016
- fix(maestro): #948 canonical guard - never align/overwrite regent by @FabioLeitao in #1017
- docs(adr): ROUND 2 ratification - ADR-0068 (awaiting operator signature) by @FabioLeitao in #1019
- feat(maestro): FASE 2 pre-flight gate readiness (#960/#957/#958/#1003) by @FabioLeitao in #1020
- chore(licensing): spin out License Studio to private repo by @FabioLeitao in #1023
- fix(maestro): gate wiring + narrow privilege probe (#1021) by @FabioLeitao in #1022
- release: 1.7.4 GA (xkcd 2¹⁰ — PR #1024) by @FabioLeitao in #1024
Full Changelog: v1.7.3...v1.7.4