Repository navigation
Releases: IamAngusU/polymorph
Release list
Polymorph 0.4.0a11
Quick install from GitHub:
python -m pip install "https://github.com/IamAngusU/polymorph/releases/download/v0.4.0a11/polymorph_bridge-0.4.0a11-py3-none-any.whl" "nsfw-guard[cpu] @ https://github.com/IamAngusU/nsfw-guard/releases/download/v0.1.0a3/nsfw_guard-0.1.0a3-py3-none-any.whl"
polymorph guard --doctorPolymorph 0.4.0a11 is a tested pre-release.
Highlights:
- Adds the evidence-bound adaptive memory advisor and metadata firewall work accumulated after a10.
- Adds
polymorph guard, an optionalsafety-bridge/v1client for separately installed NSFW Guard. - Auto-discovers the guard on PATH, keeps one process warm, SHA-256-binds files, bounds responses, and never invents a retry.
- Keeps CPU as the default. DirectML and CUDA remain explicit choices.
Local release evidence:
- Compile, Ruff, format, strict mypy, dependency check, executable example: passed.
- Full test suite: 1,280 passed, 8 skipped.
scripts/validate_local.py: passed, including mapping and three workflow performance gates.World-Benchmark.cmd: passed and updated the local eight-record history.- Wheel and sdist: Twine passed; sdist contains all 309 release files.
- Combined clean install with NSFW Guard 0.1.0a3: passed, including a real cross-process scan.
GitHub Actions remain repository-wide disabled. The workflows are prepared, not spending money.
Polymorph Bridge 0.4.0a9
The own-data path is now the front door
Polymorph Bridge 0.4.0a9 turns the safest useful workflow into the shortest workflow:
py -m pip install "https://github.com/IamAngusU/polymorph/releases/download/v0.4.0a9/polymorph_bridge-0.4.0a9-py3-none-any.whl"
polymorph trial your-data.csv --openThe trial runs locally, does not write to the source or destination, does not use the network, and emits a metadata-only HTML/JSON report without record values.
Changes
- Added
polymorph trial FILEandpolymorph trust ...to the primary CLI while retaining the existing compatibility commands. - Added a real product screenshot and direct no-clone install path to the English and German READMEs.
- Reworked the roadmap around evidence-backed status instead of stale version promises.
- Corrected CI documentation: workflow definitions are prepared, but repository GitHub Actions remain disabled.
- Added structured bug, connector, and evidence contribution forms.
- Updated the Trust Center documentation so current releases no longer look pinned to a stale version.
- Kept the repository image-efficient: the product screenshot is WebP, with no redundant PNG tracked.
Local release evidence
- Source commit:
15f391d392c74f2c1fbda7645402cdbff5189775 - Full suite: 1,251 passed, 8 skipped, 0 failed.
- Repeated end-to-end workflow: 365.20 to 375.54 rows/s; median 369.77 rows/s.
- Maximum measured peak RSS: 83.18 MiB.
- Ruff, formatting, strict mypy, package build, Twine checks, clean-wheel install, primary CLI trial, SBOM generation, Trust Center generation, and release-manifest verification passed locally.
- GitHub Actions were disabled and were not used for this evidence.
The attached release manifest binds every downloadable artifact to its SHA-256 digest and this source commit. Measurements describe this specific local Windows host and corpus; they are evidence, not universal performance promises.
Polymorph 0.4.0a8
Evidence-gated data integration
Polymorph 0.4.0a8 makes the safest first evaluation much easier and turns local release evidence into a product surface.
New in a8
polymorph-kit trial FILE --openinspects supported local data without a destination, credentials, network request or write authority.- Trial reports contain schema descriptors and metadata-only quality evidence, not record values or local absolute paths.
polymorph-kit trust MANIFEST VALIDATION --output DIRbuilds a static light-mode Trust Center only when release and clean validation commits match exactly.- Trust evidence labels itself honestly as maintainer-controlled, local and not independently audited.
security-insights.ymlpublishes the project posture using OpenSSF Security Insights 2.2.0.- The README now leads with local-first execution, fail-closed AUTO decisions and explicit write outcomes.
Locally verified release evidence
- Exact commit:
a4f58dd02ec4cc996d91c588290d6ab1b3cf08db - 1,250 tests passed, 8 explicitly skipped, 0 failed, 0 errors
- Compile, Ruff, format, strict mypy, dependency and example checks passed
- Three SQLite workflow runs: 191.44 to 200.83 rows/s, median 197.75 rows/s
- Maximum measured peak RSS: 79.75 MiB
- Wheel and sdist passed Twine; sdist contained all 298 expected release files
- Wheel installed in a clean Python 3.11 venv; installed CLI version and own-data trial passed
- Security Insights passed the official OpenSSF CUE schema using SHA-verified CUE 0.17.1
- All 7 payload artifacts passed the attached SHA-256 release manifest
These are measurements from one maintainer-controlled Windows AMD64 machine. They are not an independent audit or a cross-platform performance promise. The validation explicitly does not cover other operating systems, live PostgreSQL, or full parser OS isolation.
GitHub Actions were not used for this release and are disabled repository-wide.
Fastest start
python -m pip install .\polymorph_bridge-0.4.0a8-py3-none-any.whl
polymorph-kit trial C:\path\to\your-file.csv --openUse release-manifest.json to verify every downloadable artifact before use.
Polymorph 0.4.0a7 - audit throughput recovery
Audit throughput recovery
This corrective pre-release removes an O(history) quota query from every audit append without weakening the write boundary.
Changes
- Audit event count and logical-byte usage are maintained transactionally in SQLite.
- Quotas are still checked before inserts under
BEGIN IMMEDIATEserialization. - Inserted rows, hash-chain tail, and usage metadata receive explicit postcondition checks before commit.
- Existing audit stores receive a one-time usage backfill when opened for writing.
- Multiple writers share the same committed quota state.
- Already serialized event bytes are reused for hashing and accounting.
Measured effect on the same contended host
- Isolated 20,000-event audit median: 3,431 to 6,395 events/s, about 86% faster.
- Signed 1,000-row workflow: previous single run 143.58 rows/s; post-fix three-run median 262.95 rows/s, about 83% higher.
- Peak RSS remained near 87.3 MiB.
Battlefield 6 was using roughly 5.8 CPU cores and the GPU was device-wide near full utilization during these measurements. These values are deliberately not presented as a replacement for the controlled 375.83 rows/s idle baseline.
Verification
- Compile, Ruff, formatting, and strict mypy passed.
- Full tests passed with warnings treated as errors.
- Audit migration, rollback, multi-writer quota, runtime, and workflow regressions passed.
scripts/validate_local.pypassed, including three workflow performance gates.- Wheel and sdist passed Twine checks.
- Clean wheel installation, audit smoke, and connector scaffold smoke passed.
- GitHub Actions remained disabled.
Polymorph 0.4.0a6 - evidence-bound review
Corrective pre-release
This release makes review and recurring-run evidence match the real execution objects instead of test-only shapes.
What changed
- Route preparations now expose source and destination schema fingerprints directly.
- Review artifacts apply to the real
MoveSessionAPI and preserve the reviewer identity. polymorph-kit review modelderives a bounded, metadata-only UI model from preparation JSON.- Review UI presents evidence classes first; numeric confidence is advisory detail and never authority.
- Commit receipts fail closed when a write result has no stable run ID. No random checkpoint identity is fabricated.
- OAuth refresh failures suppress secret-bearing exception causes.
- Windows documentation now states the exact Job Object resource boundary without claiming filesystem or network isolation.
- Quality CLI wording now matches its current content-inspected local-file behavior.
Verification
- Compile, Ruff, formatting, and strict mypy passed.
- Full pytest suite passed with warnings treated as errors.
scripts/validate_local.pyandWorld-Benchmark.cmdpassed locally.- Wheel and sdist passed Twine checks.
- A clean virtual environment installed the wheel, exported the UI, scaffolded a connector, installed its
[test]extra, and passed its generated contract test. - GitHub Actions remain disabled; this release did not run Actions.
Start
py -m pip install polymorph_bridge-0.4.0a6-py3-none-any.whl
polymorph-kit --help
polymorph-kit connector scaffold my-source
polymorph-kit ui export review-uiThis remains a pre-release. Live database, HTTP, and custom-source execution stays fail-closed until source snapshot evidence is implemented for that boundary.
Polymorph v0.4.0a5
Polymorph 0.4.0a5
This pre-release turns Polymorph's conservative write core into a much easier integration surface without weakening Evidence vs Authority.
New
- polymorph-kit connector scaffold: fail-closed source connector starter, no overwrite and no generated GitHub Actions.
- polymorph-kit quality inspect: bounded streaming quality reports with row numbers and issue metadata, never row values.
- Explicit lazy cleaning plans for NFC normalization, whitespace trimming, and empty-to-null.
- Dependency-free EN/DE Web Component plus portable schema-bound review artifacts.
- Thread-safe, in-memory OAuth access-token refresh adapter with redacted representations.
- Durable local recurring-run checkpoints, compare-and-swap generations, idempotent commit receipts, and fenced single-host leases.
- Honest enterprise-readiness, review UI, recurring-run, and ecosystem documentation with copy-paste recipes.
Local acceptance evidence
- Commit: $sha
- 1,249 tests collected; 1,241 passed and 8 environment-dependent skips, with warnings treated as errors.
- Compile, Ruff, format, and strict mypy passed across 72 package modules.
- scripts/validate_local.py passed all checks, three workflows, and all gates.
- World-Benchmark.cmd passed and retained eight historical local observations plus the light-mode SVG.
- Wheel and sdist passed wine check, clean-Venv install, pip check, resource export, entry-point smoke, and generated-connector install/test.
- GitHub Actions remained disabled and did not produce this evidence.
Important boundaries
This is still alpha software. The OAuth adapter is not a token vault or authorization server. Local leases are not distributed locks. Incremental checkpoints are not CDC. Review artifact SHA-256 is content integrity, not identity authentication. No SOC 2, ISO 27001, HIPAA, SLA, or independent-audit claim is made.
Start with README.md, docs/ECOSYSTEM_KIT.md, and docs/ENTERPRISE_READINESS.md. Verify downloads against SHA256SUMS.txt or
elease-manifest.json.
Polymorph 0.4.0a4 - Product Surface
Polymorph 0.4.0a4 turns the alpha into a much easier product to try and embed without weakening its trust model.
Try it without setup
Download polymorph-demo.html and open it locally. It uses synthetic data, needs no account or network, runs no model, and performs no destination write.
For the full local evidence runner, download Polymorph-Run-v1.1.0.zip.
What is new
- Public connector registry for CSV, JSON/JSON5, Excel, Parquet, SQL databases and HTTP JSON.
- Content-based source resolution with explicit-only destinations.
- Opt-in third-party connectors through
polymorph.connectorsPython entry points. - Connector conformance checks without opening an endpoint.
- Versioned payload-free product events with English and German message catalogs.
- Callback, composite and bounded async queue event sinks.
- Explicit
move(...).prepare()thenexecute()embedded API. - Honest
review_required,blocked,not_committed, committed-prefixpartialandunknownoutcomes. - Local responsive HTML demo and
polymorph connectorsexplorer.
Verified locally on Windows
- Compile, Ruff, repository format and strict mypy passed.
- 1,224 tests passed and 8 platform-dependent tests skipped with warnings treated as errors.
- Focused connector, quota, HTTP, Parquet, audit and isolation suite: 278 passed, 7 skipped.
validate_local.pypassed three independent secure-workflow runs and gates.- World Benchmark and longitudinal evidence bundle passed without upload.
- Wheel and sdist passed Twine, the sdist contains all 276 release files, and a clean venv installed and exercised the final wheel.
These are local release observations, not universal performance or security promises. The embedded convenience write path is same-process, requires a content-inspected immutable file source, and refuses secret or opaque forwarding. Use the secure agent and ciphertext-only relay path when endpoint separation matters.
GitHub Actions remain intentionally disabled. This release was built, tested and uploaded locally.
Polymorph 0.4.0a3
Polymorph 0.4.0a3
A security and bounded-work pre-release focused on honest connector outcomes, practical streaming and locally verifiable release evidence.
What changed
- Shared finite
WorkBudgetlimits for direct CSV, HTTP JSON and Parquet operations. - Streaming atomic CSV rewrites instead of rebuilding the complete destination in RAM.
- HTTP JSON depth, node, value, aggregate-byte and cross-page record limits.
- Exact HTTP request-byte accounting, unread destination response bodies and structured
PartialConnectorWriteErrorcommitted-prefix evidence. - Parquet row, row-group, metadata, uncompressed, nesting and decoded-batch limits.
- Windows Job Object CPU, memory, process-count, descendant and kill-on-close enforcement.
- Streaming audit verification, summaries and atomic JSONL export plus no-deletion admission quotas.
- CycloneDX SBOM, source-tree digest, artifact manifest and offline verifier.
- An eight-case multilingual adversarial ambiguity corpus.
Local evidence on the release host
- 1,215 tests passed and 8 environment-specific tests skipped with warnings treated as errors.
- Compile, Ruff, formatter, strict mypy, dependency checks and
validate_local.pypassed. - Three encrypted 1,000-row workflow runs and the local World Benchmark passed.
- A 1,000,000-row CSV rewrite appended 500,000 rows at 184,939 rows/s with a measured 9,613,312-byte RSS increase over baseline.
- The adversarial ambiguity corpus produced zero automatic and zero unsafe automatic decisions. Review-suggestion accuracy was only 25%, retained explicitly as an improvement target.
- Wheel, sdist, Twine checks, 268-file sdist contract and a clean Python 3.11 wheel install passed.
Honest boundaries
- Windows Job Objects provide resource and descendant containment, not filesystem or network isolation. AppContainer remains open.
- The isolated worker still covers content inspection only. Full CSV, JSON, Excel and Parquet parsing needs a bounded framed protocol and backpressure.
- Linux cgroup v2, coordinated relay/outbox/quarantine quotas, external audit witnessing and deployable service agents remain roadmap work.
- The real PostgreSQL harness exists, but this host still has no local PostgreSQL/Docker prerequisite for a full external commit-fault run.
- The SBOM and manifest are hash-verifiable but not identity-signed; Sigstore/GPG requires an operator-controlled identity or key.
- GitHub Actions remained repository-wide disabled throughout this release.
Start with START-HERE.md or START-HERE.de.md. Verify downloads with SHA256SUMS.txt and release-manifest.json.
Polymorph 0.4.0a2 + Run 1.1.0
Polymorph 0.4.0a2 makes the local-first trust layer easier to try and expands useful evidence without granting learned components write authority.
Start in five minutes
English: START-HERE.md
Deutsch: START-HERE.de.md
The Windows Buddy and World-Benchmark.cmd do not upload data, activate models, push commits or start GitHub Actions.
Added
- content-first, read-only Parquet schema inspection and bounded streaming through
polymorph inspect parquet - a 10,000-row local Parquet evidence report with 1.54M rows/second record-read throughput on the documented Windows machine
- an advisory-only 130-term English, German and French ERP/finance/tax glossary
- an independent public multilingual schema corpus sourced from Companies House, INSEE SIRENE, Destatis GENESIS and Peppol terminology
- corpus result: 14/14 correct suggestions, 13 review decisions, 1 deterministic AUTO and 0 unsafe AUTO decisions
polymorph-reviewfor metadata-only measurement of real operator review time and acceptance/correction counts- an opt-in real PostgreSQL connector write and rollback lab that never stores its URL and removes its temporary table
- sanitized checked-in evidence and explicit provenance/limitations
Local validation
- complete compile, Ruff, formatting, strict typing and dependency checks passed
- full test suite passed with optional Parquet and PostgreSQL drivers installed
- three encrypted 1,000-row workflow runs and all performance gates passed
- Wheel and source distribution passed strict Twine metadata checks
- clean base-Wheel installation,
polymorph doctor, packaged glossary and review CLI passed
The PostgreSQL harness could not be executed against a real server on the release machine because neither PostgreSQL nor Docker was installed. The harness reports this as blocked; it does not substitute SQLite evidence or claim a PostgreSQL result.
All benchmark figures apply only to their exact version, corpus, machine and observer mode. The public corpus is intentionally small and is not a universal accuracy claim.
Polymorph Bridge 0.4.0a10 - Adversarial own-data hardening
Adversarial own-data hardening
An independently generated 18-scenario torture pack did more than confirm existing behavior: it exposed three real integration defects. Polymorph Bridge 0.4.0a10 fixes them while retaining the fail-closed authority boundary.
What changed
- Detects valid namespace-prefixed OOXML formula tags such as
<x:f>and retains cached-formula uncertainty for review. - Restores metadata-only
empty_stringquality evidence for empty CSV cells without exposing record values. - Replaces unsafe implicit INTEGER copies with one strict
parse_integertransform exercised by both preflight and execution. - Makes the exact CSV-to-SQLite route preflight-valid and promotable while ambiguous, localized and drifted routes remain REVIEW/BLOCK.
- Accepts an existing local
.sqlite3path directly inpolymorph inspect db; users no longer need to hand-writesqlite:///.... - Adds permanent, self-generating regression tests instead of committing the untrusted external pack or redundant binary fixtures.
Local evidence bound to this release
- Source commit:
51df10728225affe52f585a0ab088e4ad7a476e8 - Full suite: 1,255 passed, 8 skipped, 0 failed.
- Repeated end-to-end workflow: 370.39 to 372.50 rows/s; maximum peak RSS 83.16 MiB.
- Clean-wheel million-row trial: 1,000,000 records scanned in 34.22 seconds, 29,226.06 rows/s, 126.02 MiB process-tree peak RSS.
- Source-checkout scale comparison observed 141.53 MiB at 100k rows and 141.25 MiB at 1M rows.
- Hostile duplicate-key JSON, non-finite JSON, traversal ZIP and high-expansion ZIP inputs were rejected.
- Unsafe automatic decisions: 0. Destination writes: 0. Network requests: 0.
- Compile, Ruff, formatting, strict mypy,
validate_local.py, build, Twine, clean-wheel installation, Trust Center and SHA-256 manifest verification passed. - GitHub Actions remained disabled and were not used for these results.
The precise claim is: bounded streaming behavior was observed from 100k to 1M rows on this Windows test host. This is measured evidence, not a universal constant-memory or performance guarantee.
Install without cloning
py -m pip install "https://github.com/IamAngusU/polymorph/releases/download/v0.4.0a10/polymorph_bridge-0.4.0a10-py3-none-any.whl"
polymorph trial your-data.csv --open
polymorph inspect db .\target.sqlite3 --table customers -o customers.schema.jsonThe attached polymorph-torture-evidence.json contains the sanitized scenario outcomes, measurements, limitations and external-pack digest. The original untrusted ZIP and its scripts are intentionally not distributed.