Skip to content

Polymorph 0.4.0a8

Pre-release
Pre-release

Choose a tag to compare

@IamAngusU IamAngusU released this 12 Sep 17:13
· 10 commits to main since this release

Evidence-gated data integration

Polymorph 0.4.0a8 makes the safest first evaluation much easier and turns local release evidence into a product surface.

New in a8

  • polymorph-kit trial FILE --open inspects supported local data without a destination, credentials, network request or write authority.
  • Trial reports contain schema descriptors and metadata-only quality evidence, not record values or local absolute paths.
  • polymorph-kit trust MANIFEST VALIDATION --output DIR builds a static light-mode Trust Center only when release and clean validation commits match exactly.
  • Trust evidence labels itself honestly as maintainer-controlled, local and not independently audited.
  • security-insights.yml publishes the project posture using OpenSSF Security Insights 2.2.0.
  • The README now leads with local-first execution, fail-closed AUTO decisions and explicit write outcomes.

Locally verified release evidence

  • Exact commit: a4f58dd02ec4cc996d91c588290d6ab1b3cf08db
  • 1,250 tests passed, 8 explicitly skipped, 0 failed, 0 errors
  • Compile, Ruff, format, strict mypy, dependency and example checks passed
  • Three SQLite workflow runs: 191.44 to 200.83 rows/s, median 197.75 rows/s
  • Maximum measured peak RSS: 79.75 MiB
  • Wheel and sdist passed Twine; sdist contained all 298 expected release files
  • Wheel installed in a clean Python 3.11 venv; installed CLI version and own-data trial passed
  • Security Insights passed the official OpenSSF CUE schema using SHA-verified CUE 0.17.1
  • All 7 payload artifacts passed the attached SHA-256 release manifest

These are measurements from one maintainer-controlled Windows AMD64 machine. They are not an independent audit or a cross-platform performance promise. The validation explicitly does not cover other operating systems, live PostgreSQL, or full parser OS isolation.

GitHub Actions were not used for this release and are disabled repository-wide.

Fastest start

python -m pip install .\polymorph_bridge-0.4.0a8-py3-none-any.whl
polymorph-kit trial C:\path\to\your-file.csv --open

Use release-manifest.json to verify every downloadable artifact before use.