Skip to content

Releases: K1ngBronxo/Clearance-dev

Clearance v0.1.0-rc.2

Choose a tag to compare

@K1ngBronxo K1ngBronxo released this 27 Sep 09:32

First published build of the Clearance CLI.

clearance check <path> reads a project's dependency manifests, lockfiles, vendored licences, model-weight metadata and platform terms, and folds what it finds into one of four verdicts — SHIP, SHIP CONDITIONAL, DO NOT SHIP or UNDETERMINED — with a citation on every finding and a confidence level that decides whether the finding may block.

Six archives, all built from the same source: Linux (amd64, arm64), macOS (amd64, arm64), Windows (amd64, arm64).

Each archive bundles the binary together with the signed corpus bundle — corpus 2026.09.2, Ed25519, 12 licences, 39 obligations, 12 traps, 82 citations — so the first command after unpacking works with no further setup.

checksums.txt carries the SHA-256 of every archive.

Install — Windows (PowerShell)

PowerShell aliases curl to Invoke-WebRequest, which rejects curl's flags, and it ships no unzip. Call curl.exe and unpack with Expand-Archive. Run the lines one at a time: && is a syntax error before PowerShell 7.

$version = '0.1.0-rc.2'
$base    = 'https://github.com/K1ngBronxo/Clearance-dev/releases/download/v0.1.0-rc.2'
$name    = "clearance_${version}_windows_amd64.zip"

curl.exe -fsSL -o $name "$base/$name"
curl.exe -fsSL -o checksums.txt "$base/checksums.txt"

$want = (Select-String -Path checksums.txt -Pattern ([regex]::Escape($name))).Line.Split(' ')[0]
$got  = (Get-FileHash $name -Algorithm SHA256).Hash.ToLower()
if ($got -ne $want) { throw "SHA-256 mismatch for $name" }

Expand-Archive -Path $name -DestinationPath . -Force
.\clearance.exe version

Install — Linux and macOS

version=0.1.0-rc.2
os=linux          # linux | darwin
arch=amd64        # amd64 | arm64
name="clearance_${version}_${os}_${arch}.tar.gz"
base="https://github.com/K1ngBronxo/Clearance-dev/releases/download/v0.1.0-rc.2"

curl -fsSL -o "$name" "$base/$name"
curl -fsSL -o checksums.txt "$base/checksums.txt"
grep -F "$name" checksums.txt | sha256sum -c -
tar -xzf "$name"

./clearance version

On macOS, use shasum -a 256 -c - in place of sha256sum -c -.

What this release does not carry

No cosign signature, no SLSA build provenance and no SBOM. The release.yml workflow that would produce all three cannot run against this tree: its corpus pre-flight requires maintainer tooling (tools/, corpus-build/) that is deliberately not published, because that tooling holds the Ed25519 code that signs the corpus. These archives were built and verified by hand from the maintainer checkout — download, SHA-256 against checksums.txt, unpack, run, corpus verify OK. Treat checksums.txt as an integrity check, not as provenance.

The corpus itself is signed, and the signature is verified on every load; clearance version reports the signature status.

Licence

The CLI is FSL-1.1-ALv2 — source-available, not open source. The corpus is CC-BY-4.0.