Repository navigation
Releases: K1ngBronxo/Clearance-dev
Release list
Clearance v0.1.0-rc.2
First published build of the Clearance CLI.
clearance check <path> reads a project's dependency manifests, lockfiles, vendored licences, model-weight metadata and platform terms, and folds what it finds into one of four verdicts — SHIP, SHIP CONDITIONAL, DO NOT SHIP or UNDETERMINED — with a citation on every finding and a confidence level that decides whether the finding may block.
Six archives, all built from the same source: Linux (amd64, arm64), macOS (amd64, arm64), Windows (amd64, arm64).
Each archive bundles the binary together with the signed corpus bundle — corpus 2026.09.2, Ed25519, 12 licences, 39 obligations, 12 traps, 82 citations — so the first command after unpacking works with no further setup.
checksums.txt carries the SHA-256 of every archive.
Install — Windows (PowerShell)
PowerShell aliases curl to Invoke-WebRequest, which rejects curl's flags, and it ships no unzip. Call curl.exe and unpack with Expand-Archive. Run the lines one at a time: && is a syntax error before PowerShell 7.
$version = '0.1.0-rc.2'
$base = 'https://github.com/K1ngBronxo/Clearance-dev/releases/download/v0.1.0-rc.2'
$name = "clearance_${version}_windows_amd64.zip"
curl.exe -fsSL -o $name "$base/$name"
curl.exe -fsSL -o checksums.txt "$base/checksums.txt"
$want = (Select-String -Path checksums.txt -Pattern ([regex]::Escape($name))).Line.Split(' ')[0]
$got = (Get-FileHash $name -Algorithm SHA256).Hash.ToLower()
if ($got -ne $want) { throw "SHA-256 mismatch for $name" }
Expand-Archive -Path $name -DestinationPath . -Force
.\clearance.exe versionInstall — Linux and macOS
version=0.1.0-rc.2
os=linux # linux | darwin
arch=amd64 # amd64 | arm64
name="clearance_${version}_${os}_${arch}.tar.gz"
base="https://github.com/K1ngBronxo/Clearance-dev/releases/download/v0.1.0-rc.2"
curl -fsSL -o "$name" "$base/$name"
curl -fsSL -o checksums.txt "$base/checksums.txt"
grep -F "$name" checksums.txt | sha256sum -c -
tar -xzf "$name"
./clearance versionOn macOS, use shasum -a 256 -c - in place of sha256sum -c -.
What this release does not carry
No cosign signature, no SLSA build provenance and no SBOM. The release.yml workflow that would produce all three cannot run against this tree: its corpus pre-flight requires maintainer tooling (tools/, corpus-build/) that is deliberately not published, because that tooling holds the Ed25519 code that signs the corpus. These archives were built and verified by hand from the maintainer checkout — download, SHA-256 against checksums.txt, unpack, run, corpus verify OK. Treat checksums.txt as an integrity check, not as provenance.
The corpus itself is signed, and the signature is verified on every load; clearance version reports the signature status.
Licence
The CLI is FSL-1.1-ALv2 — source-available, not open source. The corpus is CC-BY-4.0.