Releases: Eysn0130/DeepLaw
Release list
DeepLaw v0.12.0 — Formal Release
DeepLaw v0.12.0 release notes
Status: formal release contract. These notes describe the v0.12.0 tag only after the public
Release exists. Before that point, exact-commit, platform, machine-consensus, artifact, signature,
provenance, and post-release rows remain release gates rather than completed historical facts.
Implemented
- Semantic Compilation Profile v2 adds packet-local Observation Plans, a bounded run-wide Semantic
Inventory, 15 explicit semantic duties, one closed Finalization Packet, and one atomic
Publication Plan. Observation staging is not recallable and every observation must have exactly
one final disposition. - Run-wide identity resolution reuses stable Entity and Concept identities across packets, records
aliases, and preserves same-name ambiguity rather than merging on model confidence. - Source Summary is a canonical revision-bound Synthesis with exact evidence bindings. A successful
transaction can truthfully retainsemantic_status=partial; unsupported completeness and empty
semantic output fail closed. - Synthesis Refresh is a recoverable saga for successor, withdrawal, transitive staleness, Overview,
and community refresh. Canonical revisions remain authoritative if derived projection fails;
deterministic rebuild never calls a model. - Query Plan v5 makes purpose duties, compiled-first/evidence-first selection, provenance
partitions, stale/uncompiled gaps, and raw fallback explicit while retaining provider-visible
UTF-8 byte limits and read-only query behavior. - Bounded deterministic query-only cross-language expansion improves Chinese-to-English discovery
without rewriting evidence or identity. Query Plan v5 binds the expansion profile, count, and
digest and explicitly records that neither Authority nor stored evidence changed. - Exact Source IR fragment revision identities are accepted by the first-party Source fragment
read surface, so v2 evidence receipts remain directly verifiable without duplicating a legacy
fragment identity in provider-visible fallback cards. - CLI, MCP, and Python API use the same compilation/retrieval domain services. Source, Wiki,
Editor, Synthesis, freshness, contradiction, gap, status, explain, and verify operations use
closed contracts. - The Obsidian bridge waits for layout readiness, exposes governed commands, and cannot treat paths,
frontmatter, Wiki links, or Canvas as identity or Authority. The Tolaria bridge merges existing
configuration into owner-only output (POSIX mode or verified native Windows ACL), uses ephemeral
active-note context, and keeps canonical roots read-only. - Authoritative Pack evidence now exposes capability types, deterministic Challenge Trace/replay,
citation audit, held-out expert review state, and a reusable Pack Core contract while preserving
the physically separate read-onlylaw_supportboundary. - Release evaluation adds frozen Semantic Gold, deterministic successor/withdrawal lifecycle,
first-party CLI query scoring, real cursor continuation, deterministic query-cost accounting,
six isolated machine-review roles, and unanimous consensus binding. - Pull-request CI and Commercial GA jobs explicitly check out the pull-request head SHA. Release
and manual invocations continue to prefer their explicit immutable ref, preventing a synthetic
merge commit from being recorded as the candidate in reproducible-build or platform evidence. - The corrected Semantic Gold adds real multi-Packet identity fusion, target-scoped Entity/Concept
precision with separate extraction completeness and source coverage, claim-level Concept and
Synthesis assertions, structured typed-relation endpoints and valid time for contradictions,
exactproduction/ordinaryapplicability and restricted-payload exclusions for retention
claims, explicit non-mergeable contradiction endpoints, an explicit withdrawal Gap, fully
specified per-field freeze commitment algorithms, one-event-per-valid-time timeline labels, a
scheduled-publication multi-format Event, and fourteen natural-Chinese frozen query variants
scored against the same objects, claims, citations, coverage, safety rules, and budgets as their
canonical cases. - Credential-free evaluation now compiles the entire public corpus through the real governed
transaction using a deterministic no-model Agent, executes all 15 first-party CLI retrieval
cases and five adversarial challenges, and exports source-free bilingual derived Owner packets.
This does not count as external-model evidence or human confirmation. - Provider-visible results are purpose-aware and deduplicated into a bounded Knowledge Capsule;
discovery scores, duplicate revisions/aliases, unrelated graph/Wiki navigation, rejected or
withdrawn bodies, internal paths, and unauthorized metadata remain audit-only. Exact evidence,
Authority, lifecycle, temporal applicability, contradictions, gaps, fallback, and continuation
receipts remain visible. - Freshness checks use bounded exact-identity discovery before broader lexical/dense fallback and
do not traverse graph neighbors that cannot affect the selected revision's dependency state.
This keeps rebuilt derived indexes from expanding a target-scoped check into unrelated work. - The signed 28-source Authoritative Pack gate verifies each immutable source hash, parser/segment
inventory, locator, lifecycle, active release, exact title/citation retrieval, deterministic
rebuild, baseline non-regression, read-onlylaw_support, and zero security failures without
committing source bytes, titles, paths, or private payloads.
Verified
- Contract, unit, integration, failure-path, recovery, MCP stdio, deterministic fake-Agent,
migration, snapshot, restore, rollback, editor boundary, authoritative challenge, capability,
citation, and repository quality tests are part of the mandatory suite. - The Obsidian plugin has TypeScript checks, lifecycle tests, a production bundle build, and a
bundle verifier. The Tolaria temporary-Vault harness verifies merge preservation, active-note
context, open-note UI intent, and no canonical persistence. - Three official CLIs run isolated no-model lifecycle checks for discovery, manifest/config
validation, install, enable/disable, upgrade, remove/re-add, MCP stdio discovery, and two-product
isolation. No lifecycle result is represented as a real-model result. - Fresh-wheel, reproducible wheel/sdist, migration/rollback, derived rebuild, and bounded query
runners are executable release gates. - Read-only release verification now closes SQLite handles deterministically, so official/private
update, deletion, uninstall, and temporary authoritative gates do not retain Windows file locks. - An isolated source-free Authoritative evidence runner emits a digest-bound release report for
capability predicates, Challenge Trace/replay, citation tamper rejection, temporal exclusion,
read-only enforcement, and Authority failures. It explicitly keeps unreviewed legal Gold pending. - Exact v0.11 autonomous Vaults are accepted by the v0.12 verifier, receive a verified autonomous
snapshot before reconciliation, and can be restored without losing compiled Knowledge state. - The public Knowledge Revision Detail contract admits the existing
revision_boundverification
state used by Source Summary and Synthesis revisions, and the synthesis lifecycle regression
validates the emitted detail against that exact Schema. - Retrieval source coverage is target-scoped to revisions that a passing query may admit;
predecessor and withdrawn revisions retained as negative freshness controls cannot inflate or
depress the coverage metric. - Purpose-aware selection preserves exact identities in mixed Event/Concept requests, uses exact
ISO dates as bounded structured anchors without admitting unrelated low-score candidates, and
emits timeline Events in chronological valid-time order. Frozen Chinese variants are executed
cold and warm by the first-party CLI; correct extra objects remain outside target-scoped
precision, while every required object and claim still needs exact evidence. - A profile-v2 cross-source Synthesis may bind exact admitted evidence only from Source Revisions
present in its validated input set. The deterministic retention comparison binds both inputs
directly, making its provider-visible evidence receipt complete even when no companion Claim or
raw fragment is selected. - Autonomous CLI
knowledge context, MCP context, and the Python Context API return the same
Capsule v2 revision set and Query Plan v5. Untouched v0.7 Vaults with no autonomous compilation
run or governed Knowledge Object retain their v1 compatibility context rather than losing
reviewed legacy assets. - The advertised MCP v5 Schema accepts explicit purpose-aware context requests and keeps them
disjoint from frozen v4 input. Bounded meaningful-term matching prevents unrelated
stale_knowledgeoruncompiled_sourcegaps while still discovering an uncompiled Source IR
match on any retained query term. - Single-target retrieval suppresses unrelated compiled candidates without removing required
comparison, timeline, contradiction, fallback, stale, or gap evidence. An explicit target beyond
the admitted scope/sensitivity returns an empty non-identifying gap instead of a nearby public
substitute. - Explicit legacy FTS rebuild and Doctor repair recover deleted or mismatched removable search
rows, then rerun full integrity verification. Audit-chain, Source, Asset, relation, and other
canonical-state failures continue to block repair. - Source-byte tamper checks now cover direct fragment reads and every selected source-bound
compiled revision. Provider-visible contradiction entries retain the exact typed Relation
Revision and titled stable endpoints. Historical evidence-first retrieval returns an exact
immutable referenced fragment only when historical source ...
DeepLaw v0.11.0 — Formal Release
DeepLaw v0.11.0 release notes
Release date: 2026-07-30
Release status: formal GA after the exact-tag release workflow succeeds
commercial_release_eligible=true
quality_protocol_eligible=true
competitive_claim_eligible=false
Implemented
- Living Wiki Compiler 的 closed Packet/Plan/Receipt 协议、持久化 Compilation Run Saga、
原子 Knowledge/Relation commit、恢复、abort、projection retry 和 freshness propagation。 - Compiled-first 与 purpose-aware evidence-first 检索;raw fallback、uncompiled source、
stale knowledge、预算和选择原因均进入可核验 Query Plan。 - Rich Living Wiki source/object pages、分片索引、fragment shards、局部/社区/全局 Canvas,
以及删除 FTS、dense、graph、Wiki、Canvas、cache 后的确定性重建。 - CLI、MCP 和稳定 Python API 复用同一领域协调器;
knowledge_support、
knowledge_sink、law_support保持独立进程与权限边界。 - 对 exact signed catalog 的显式
--rebuild-current-catalogowner 操作:仅允许已安装、
签名验证通过且提供 exact local source root 的目录重解析;保留旧 immutable release,
原子切换新 release。 - Living Wiki frozen CLI quality suite、28-source Authoritative Pack 决策矩阵和
同条件 0.10.0 baseline comparison、release manifest v4。Manifest 绑定 exact commit、
tree、version、tag、wheel/sdist、contracts、migration identities、three-OS、
three-host、fresh-wheel、rollback、release notes、已知限制和未声明能力。 - 修正 exact identity 被 kind 排序覆盖,以及 item/character budget 在双通道分配时
超配的问题;limit=1现在在所有 purpose policy 下保持总预算。 - Derived-state rebuild 会安全重建缺失的受控目录,同时继续拒绝 symlink 或非目录目标。
Verified
- 28 份官方资料 exact bytes 均匹配 signed catalog;先完成 snapshot/restore inventory
验证,再逐份 dry-run。13 份no_action,15 份reparse_source_ir,没有伪造
Source Revision,也没有通过普通 Source ingest 绕过 Authoritative Pack。 - 两次隔离重建的 build report 与 SQLite release bytes 分别完全一致:
build report549d677c41ec6e3aa3920462fa870d7fd1af9e5f2ba278422ca72503e2f88d90,
databaseff4bc58e3a77585dccb8b22bd049b50612b0a8c85f7fb858551ea424021fbdc0。 - 新 active official release 为
lawrel_1bee97015ee440c71ea993b083a89005;
28 documents、3237 segments、111 relations。旧 release 保留并可显式 pin/verify。 - 同一 37-case Legal Pack evaluation 上,baseline 与新 release 的 overall、
retrieval、constraint、receipt verification 均为 1.0;Hit@1 为
0.9705882352941176,MRR 为 0.9852941176470589,没有质量回退。 - Frozen Living Wiki suite 使用第一方 CLI 完成 source、compile、query、context、
freshness、withdrawal、gap、verify、Wiki/Canvas 和 destructive rebuild 闭环;
报告明确记录指标、环境、预算、延迟、失败和限制。Exact baseline commit 为
42382b264f4297965c25aaac6e85619e9e0d49b7,其可复现 wheel SHA-256 为
9bda60831e4380092c9a3bdb80103b5ec8abbf5a2be0adf6ffd57f61cfa46ca0;
baseline、fresh wheel 和 comparison 三份报告均作为正式发布资产。 - 本地门禁与 exact candidate 的最终命令、结果记录在
V0_11_ACCEPTANCE_MATRIX.md;正式资产中的 manifest
和 post-release report 是发布字节的最终证据。
Externally verified
- 正式 Release 仅在 exact
v0.11.0tag 的 GitHub Actions Commercial GA workflow
取得 Linux、macOS、Windows 零 skip mandatory suite 后发布。 - 同一 workflow 固定 Codex
0.145.0、Claude Code2.1.220、OpenCode1.18.8
完成 no-model discovery、MCP、deterministic fake-Agent、隔离、拒绝未授权写入和
lifecycle 验证。 - 发布 workflow 对 wheel、sdist、OCI、SBOM、license inventory、OpenVEX、
Evaluation Protocol、Living Wiki quality report、28-source matrix 和文档生成
SHA-256、Sigstore OIDC bundle 与 GitHub provenance attestation。 - 发布后 job 从公开 GitHub Release 重新下载正式资产,校验 checksum/signature/
provenance,安装 exact wheel/sdist,并再次运行 Living Wiki formal-release quality
smoke。任何一项失败都会阻止或使 Release job 失败。
Not verified
- 真实模型任务没有作为 v0.11.0 三宿主验收运行;no-model lifecycle 与真实模型任务
明确分开,real_model_task_e2e=not_executed。 - 未知、未接入或不遵守 DeepLaw 版本化 CLI/MCP/Python 契约的 Agent 未实机验证。
- 28-source evaluation 是 deterministic/source-bound evaluation,不是人工法律结论、
外部机构认证或完整语义 relevance gold。 review_required的 PDF extraction 风险仍保持显式,未被描述为人工审核或官方认证。
Deferred
- DeepLaw Desktop、大型 Web UI、云 SaaS、多租户、团队 RBAC、远程 canonical
database 和通用 Agent Runtime。 - 未经 owner 既有可信 workflow 的新制品发布渠道。
- 全部真实模型/插件组合和命名竞品的冻结、配对、成本与 failure-case 比较。
Not claimed
- 不声称最强、领先、超越 Guanlan、超越 Obsidian、超越 Tolaria 或 SOTA。
- 不声称所有未知 Agent/模型/插件都已实机验证。产品结论仅为:任何遵守 DeepLaw
版本化 CLI/MCP/Python 契约并获得 owner 显式授权的 Agent,都可以通过相同的
受治理编译事务接入。 - 不声称 Agent-generated legal interpretation 具有 legal Authority;其
legal_authority=false。 - 不声称 DeepLaw 是 Obsidian/Tolaria 替代品、法律裁判系统、模型宿主或远程控制面。
Compatibility and rollback
- Python requirement remains
>=3.11; formal gates cover Python 3.11、3.12、3.13。 - v0.11.0 retains additive migration and rollback paths from old Vaults and the v0.6.0
distribution fixture. Snapshot/restore is required before migration or authoritative reparse. - Previous official releases remain immutable and available for historical pinning. Catalog
sequence rollback、unsigned catalog、rewritten same-sequence catalog 均 fail closed。
DeepLaw v0.10.0 — Quality and Superiority Closure
DeepLaw v0.10.0 release notes
DeepLaw v0.10.0 completes the engineering portion of the 1.0 Quality and Superiority Closure
milestone. DeepLaw 2.0 remains the product brand; it is not the package version.
Machine decisions:
commercial_release_eligible=true
quality_protocol_eligible=true
competitive_claim_eligible=false
Delivered
- DeepLaw Evaluation Protocol v1 with public Benchmark, fixed component weights and thresholds,
non-averagable hard failures, and an explicitly non-secret time-frozen holdout. - Actual autonomy/security cases over the shipped commit coordinator, grant policy, lifecycle,
retrieval, disclosure controls, and Ledger hash chain. - Actual source-bound bilingual
deterministic-v2Typed Compiler quality scoring. - One offline runner that generates the complete summary, four component reports, a readable report,
functional scoring digest, and checksum inventory; a second mode independently verifies every
emitted byte. - Release eligibility bound to a clean strict post-freeze commit and the exact candidate wheel
SHA-256. Source-tree reports remain development-only. - Evaluation artifacts included in the release manifest, root checksums, Sigstore OIDC inputs, and
GitHub provenance attestations. - Commercial release manifest v3 with an explicit
quality_protocol_eligibledecision and corrected
comparative evidence gaps. - Restored DeepLaw 2.0 product imagery and synchronized bilingual branding, version identity,
architecture explanation, examples, keywords, and evidence boundaries.
Corrected route
The prior requirement for evaluator-secret data and signatures from two independent institutions
has been retired as the DeepLaw core quality and release gate. A signature authenticates a key and
bytes; it does not by itself prove correctness, independence, or Authority. Independent
replication remains optional.
Historical external-evaluation schemas and runners are retained for reproducibility and optional
comparative use. The v0.7 proposal/review implementation is likewise retained for source-derived
compilation, untrusted imports, migration, rollback, and compatibility. Neither route is the
default for admitted Agent-derived knowledge.
Claim boundary
The exact release can state that it passed DeepLaw Evaluation Protocol v1. It cannot state that:
- the public holdout was secret, unseen, or contamination-free;
- deterministic typed extraction proves model cross-document synthesis;
- no future task can fail;
- DeepLaw is better than a named system that was not executed.
Real Codex, Claude Code, and OpenCode model tasks, actual same-condition named-baseline runs, paired
confidence intervals, and complete comparative cost/failure records remain absent. Therefore
competitive_claim_eligible=false.
Upgrade
No autonomous Ledger schema change is required from v0.9.0. Before upgrading, create and verify an
explicit snapshot. Install the exact v0.10.0 wheel, run deeplaw knowledge doctor and
deeplaw knowledge autonomy verify, then rebuild only the derived layer. See
INSTALL_UPGRADE_ROLLBACK.md.
Rollback restores the pre-upgrade snapshot before installing v0.9.0. Do not point an older binary
at a Vault whose canonical state has changed after the snapshot.
DeepLaw v0.9.0 — commercial GA
DeepLaw v0.9.0 release notes
DeepLaw v0.9.0 delivers the 0.8 Autonomous Knowledge Core and 0.9 Living Wiki / Knowledge
Intelligence phases of the current project brief. It changes the default long-term knowledge model
from universal per-item human review to policy-gated autonomous Agent knowledge while preserving
immutable evidence, owner authority, source integrity, and explicit write capabilities.
Release decision:
commercial_release_eligible=true
competitive_claim_eligible=false
The release flag covers the exact software and supply-chain artifact gates. It does not claim
competitive leadership. Real model tasks on Codex, Claude Code, and OpenCode, actual named-system
baseline runs, evaluator-secret held-outs, confidence intervals, and two independent evaluator
signatures remain external work.
Highlights
- Canonical Agent knowledge is now an immutable Markdown Revision Object paired with a STRICT
SQLite identity/event Ledger record. Stable identity survives filename, title, alias, and path
changes. - A single recoverable commit coordinator handles CAS bytes, compare-and-swap, Ledger state,
hash-chained events, idempotency, workspace materialization, and crash recovery. - The new separately enabled
knowledge_sinksupports bounded Run/capture, typed knowledge and
memory, evidence-bound temporal relations, feedback, consolidation, lifecycle changes, and Skill
revisions under owner-created grants. - Policy-admitted Agent-derived knowledge becomes immediately usable without per-item review, but
remainsagent_derived,legal_authority=false, and unable to grant tools or promote itself to
official, user-provided, or human-verified. - Obsidian/Tolaria-compatible Markdown/YAML/Wikilink editing supports stable rename/move,
reconciliation, explicit conflict preservation, and a foreground Watcher over the same domain
service. - Living Overview, typed Wiki pages, Semantic Lint, scope-safe gap discovery, deterministic
communities, JSON Canvas, memory consolidation, and a checkable-step Skill draft Factory complete
the 0.9 knowledge-intelligence loop. - Current retrieval combines exact, FTS, offline multilingual hash-dense, evidence-duty reranker,
graph, temporal, memory, Wiki, and retained source-derived Tree/code channels under one
partitioned Knowledge Capsule. law_supportv3 can compile independently admitted official, user-private, and explicitly
enabled Agent-interpretation partitions without confusing legal Authority.
Security and correctness changes
- Scope, sensitivity, lifecycle, valid time, kind, and required tags are applied before bounded
lexical/dense/temporal/graph candidate cuts and rechecked before reranking. Unauthorized or
irrelevant high-ranking candidates cannot crowd out admissible knowledge. - Semantic Lint and gap discovery now enforce the caller's scope and maximum sensitivity across
objects, relations, and aliases; other partitions cannot leak through IDs or aggregate counts. - Every new relation requires a valid evidence reference. Historical source-free rows remain
auditable but are not admitted to current graph, recall, or contradiction challenge. - Relation hints that cannot become admitted canonical edges remain explicit Semantic Lint / gap
findings. Memory consolidation verifies every evidence-bound lineage edge before archiving input. - Identity lookup binds aliases to the current revision, filters governance before its bounded
scan, preserves exact ambiguity even with a one-item return limit, and reports truncation. - Graph, contradiction, identity, and Lint scans have explicit resource bounds and incomplete work
becomes a gap/truncation signal. - Canonical writes enqueue disposable derived maintenance instead of synchronously rebuilding the
whole Vault. The Watcher or explicit rebuild drains the queue; stale/damaged indexes fail closed
and current lexical queries use a bounded canonical fallback.
Interfaces
knowledge_supportv3: twelve read-only operations covering search/recall, exact get, context,
explain, verify, inspect, lineage, graph, Wiki, identity, and gaps.knowledge_sinkv2: separate scope-bound mutation process; it is never registered by the default
plugin and cannot mutate Legal Pack, sources, Authority, audit, arbitrary paths, exports, signing,
or permissions.law_supportv3: nine read-only official/private/federated operations in a separate process and
storage boundary.
Upgrade
New Vault:
deeplaw knowledge init --vault ./vault --name my-project --scope project
deeplaw knowledge autonomy verify --vault ./vaultExisting v0.7 Vault:
deeplaw knowledge snapshot create \
--vault ./vault --output ./snapshot-before-v0.9
deeplaw knowledge snapshot verify --snapshot ./snapshot-before-v0.9
deeplaw knowledge autonomy migrate \
--vault ./vault --backup ./pre-autonomy-v0.7-backup
deeplaw knowledge autonomy verify --vault ./vault
deeplaw knowledge autonomy rebuild --vault ./vaultThe migration is additive and retains source-derived v0.7 Assets, Source IR/Tree, Proposal Inbox,
Workbench, and review governance in a separate compatibility partition. Rollback restores the
verified pre-autonomy Vault and retains the replaced v0.9 Vault in a sibling recovery directory.
See INSTALL_UPGRADE_ROLLBACK.md before changing a real Vault.
Compatibility and removals
- The frozen v1/v2 read contracts remain available for their corresponding historical Vaults;
autonomous v0.9 Vaults advertise v3. - The v0.7 proposal/review route is not deleted because it remains the correct boundary for
deterministic source compilation and untrusted external imports. It is no longer presented or
invoked as the default for ordinary Agent-derived memory. - Historical v0.7 release manifests, evaluator fixtures, benchmark registries, and signed release
evidence stay immutable. v0.9 uses the version-general release-manifest v2 contract. - No remote service, team RBAC, CRDT core, Neo4j/Elasticsearch dependency, or large GUI was added.
Known evidence boundary
The checked-in multi-domain Gold set is a non-secret development regression set. The offline dense
implementation has an exact model identity and is not represented as an external neural checkpoint.
No external system result, model-session outcome, held-out label, evaluator identity, or signature
was synthesized for this release. The machine claim gate remains closed until the complete external
protocol succeeds.
DeepLaw v0.7.0 — commercial GA
DeepLaw v0.7.0 — commercial GA
DeepLaw v0.7.0 is the first commercial release of the local, single-user Agent Knowledge OS. It
keeps canonical sources, Source IR, Knowledge Assets, indexes, graphs, feedback, and audit state on
the owner's machine. It requires no cloud account, remote database, telemetry service, or model API
key for its default workflow.
Release decision
The Owner has separated commercial qualification from competitive leadership:
commercial_release_eligible=true
competitive_claim_eligible=false
Real model-task E2E, 17 named-baseline results, secret held-out suites, and independent evaluator
signatures are not complete. This release therefore makes no best, SOTA, overall-leadership, or
all-baselines-surpassed claim. Official-CLI configuration/plugin lifecycle and MCP handshake tests
are no-model acceptance only; they are not presented as real Agent task results.
Product highlights
- Identity v2 separates stable logical source identity, immutable Source Revision, compilation,
proposal set, Knowledge Revision, and governance revision. - Multi-format Source Adapters preserve deterministic Source IR and Source Tree structure before
review-gated many-to-many Knowledge compilation. - The Evidence-Governed Retrieval Fabric combines exact, BM25, Source Tree, reviewed graph,
temporal, feedback, optional Dense, and pinned local reranking behind one admission boundary. - Query Plans, Explain Traces, token-aware Knowledge Capsules, Capsule-bound Run Records, feedback,
and Proposal Inbox artifacts remain source- and audit-bound. - Golden CLI, local curses Workbench, Obsidian/Markdown/JSON Canvas projection, Skill Factory,
resumable jobs, snapshot/restore, migration/rollback, GC, doctor, and selective forgetting form a
complete local operator lifecycle. - The general Knowledge OS and Chinese Legal Pack remain different plugins, processes, stores, and
read-only MCP surfaces.
Distribution and verification
The release includes a byte-reproducible wheel and sdist, an OCI layout archive that runs non-root
and exposes no port, CycloneDX SBOM, installed-license inventory, dependency audit reports,
OpenVEX, SHA-256 checksums, Sigstore/OIDC bundles, GitHub provenance/SBOM attestations, three-OS
test/lifecycle reports, no-model host acceptance, and the commercial release manifest.
The published Sigstore bundles use the exact workflow identity
https://github.com/Eysn0130/DeepLaw/.github/workflows/release.yml@refs/heads/main.
The tagged workflow publishes the already verified exact bytes. A final job downloads the public
GitHub Release assets, verifies checksums, Sigstore identity and GitHub provenance, and performs a
fresh wheel/sdist install, v0.6→v0.7 upgrade, CLI check, and uninstall. See
docs/INSTALL_UPGRADE_ROLLBACK.md and docs/V0_7_ACCEPTANCE_MATRIX.md.
DeepLaw 2.0 v0.3.0
DeepLaw 2.0 的首个完整证据引擎版本。
主要能力
- 版本化 Document IR 与确定性 Markdown 视图
- Evidence Compiler:有界证据、证据义务、显式缺口与可复核 receipt
- 来源绑定的条款与法律主题定位、有限关系路径、时效与抽取风险门禁
- PDF 多候选抽取、截断候选拒绝、页级溯源与资源上限
- Ed25519 签名官方目录,以及与官方内容物理隔离的 OS 用户私有法律资料库
- Codex、Claude Code、OpenCode 的只读 Agent 适配契约;唯一 MCP leaf tool 为 law_support
当前官方目录
当前目录记录 28 份官方来源资料。原始法源与 SQLite 不随仓库或 Release 重新分发;客户端验证签名后从目录中的官方来源获取,并在本地构建不可变 release。
验证
- Python 3.11、3.12、3.13 CI 通过
- 226 项测试通过
- 37/37 已编码白盒检索与安全约束回归通过
- wheel/sdist、完整文档引擎扩展、真实 MCP 握手与 Codex 隔离安装通过
该白盒结果不是独立法律金标、法律意见或外部系统领先证明。Claude Code 与 OpenCode 在本次发布环境仅完成静态契约验证。