Releases: MohammadThabetHassan/trustweave
Release list
TrustWeave 0.3.0
TrustWeave 0.3.0
TrustWeave 0.3.0 is a minor assurance-hardening release for the local-first, deterministic review tool. It introduces the reviewed trustweave.dev/bundle-diff/v1alpha3 writer and strengthens the evidence, validation, and release controls around supplied declarations and already-recorded metadata.
Highlights
- Semantic evidence validation. Current Agent Security Bundles now regenerate expected findings from the embedded manifest and policy during validation, requiring complete coverage and semantic consistency rather than accepting structurally plausible but incomplete declarations.
- Policy and diff hardening. Policy coverage analysis now distinguishes impossible earlier rules from genuinely shadowing rules. The
bundle-diff/v1alpha3writer records policy-only changes and explicit human-review signals for approval-control changes, default-to-allow changes, required-control removal, classification-taxonomy changes, and structural rule-set or matching-boundary changes. - Deterministic assurance evidence. Golden evidence, mutation-contract snapshots, rule catalogs, compatibility contracts, traceability records, and repository-reality checks were refreshed through reviewed deterministic generation.
- Release-process controls. TestPyPI and PyPI workflows are constrained to an exact annotated
v<version>tag and immutable target SHA. The release gate runs formatting, linting, strict typing, static source security, tests, repository reality verification, strict documentation build, and dependency audit before isolated trusted publication. - Documentation and maintainer clarity. The release guide, compatibility contract, citation metadata, and documentation-site release page distinguish the unreleased candidate process from the published package state and preserve the project’s explicit assurance limits.
Compatibility
This release changes the current emitted bundle-diff schema from trustweave.dev/bundle-diff/v1alpha2 to trustweave.dev/bundle-diff/v1alpha3. Consumers that validate or interpret bundle-diff outputs should use the checked-in compatibility contract and accept the documented bounded legacy-reader behavior. Existing historical evidence is not silently redefined.
Verification
The release target is annotated tag v0.3.0, resolving to commit 30308f47e84025315de2083047039e7efe0fd0ae.
The exact target passed hosted CI, CodeQL, mutation-quality, and dependency-graph checks. The TestPyPI trusted-publication workflow completed successfully, followed by an exact-wheel expected-repository provenance verification and a fresh TestPyPI installation. The PyPI trusted-publication workflow completed successfully, followed by exact-wheel expected-repository provenance verification and a fresh production-index installation.
Intentional limits
TrustWeave processes supplied local declarations and pre-recorded metadata only. It does not execute agents, tools, application code, MCP servers, or models; contact remote systems; access credentials; upload results; or enforce runtime decisions. Its artifacts support deterministic review and evidence inspection; they do not prove deployed-system security, runtime enforcement, attack prevention, tool behavior, input authenticity, productivity, adoption, or incident reduction.
See the release guide, compatibility contract, and product contract for the complete evidence and boundary record.
TrustWeave 0.2.3
TrustWeave 0.2.3
TrustWeave 0.2.3 adds verifiable compatibility, evidence, traceability, distribution, resource-bound, and package-provenance controls while preserving the project’s local-only, non-executing safety boundary.
Assurance additions
- A machine-readable compatibility contract, support/deprecation policy, and deterministic validator now keep the package version, supported Python matrix, CLI surface, exit statuses, schemas, and bounded historical readers synchronized.
- A reviewed six-case synthetic golden-evidence corpus protects deterministic staged CI, framework and MCP descriptor handling, trace/risk lifecycle review, declared change/SARIF output, and malformed-input rejection without implicit snapshot refreshes.
- A generated threat-control-test traceability contract links declared boundary threats and out-of-scope risks to implementation, tests, evidence, maintenance triggers, or explicit residual limits.
- Documented local resource bounds now include a fail-closed 50,000 unique-result SARIF ceiling. Clean distribution assurance builds, archive-checks, and fresh-installs both wheel and source distributions.
- Both TestPyPI and PyPI trusted-publishing workflows request project attestations. The exact 0.2.3 wheels were verified against
https://github.com/MohammadThabetHassan/trustweaveafter publication.
Verification record
| Check | Observed result |
|---|---|
| Candidate SHA | 4aed7df9d16907804f8c2460c004a4dc685904bc |
| Hosted CI | Passed: run 32274129672 |
| CodeQL | Passed: run 32274129606 |
| Mutation quality | Passed: run 32274129642; 6,049 of 6,145 mutants killed (98.44%), 96 reviewed equivalent survivors, zero untriaged and zero needs_regression entries |
| TestPyPI publication | Passed: run 32275683187; fresh install and expected-repository attestation verification passed |
| PyPI publication | Passed: run 32276249521; fresh install and expected-repository attestation verification passed |
Boundaries
TrustWeave remains a deterministic evidence-review tool. It does not execute agent tools, contact MCP servers, call models, access credentials, send runtime network traffic, upload findings, or provide runtime enforcement. Published attestation evidence is limited to the exact verified package files above; it is not a general security certification or a claim about deployed agent behavior.
TrustWeave 0.2.2
TrustWeave 0.2.2
TrustWeave 0.2.2 is a developer-experience patch for its local-only, non-executing evidence workflow.
Added
python -m trustweaveis now a supported module-style alternative to the installedtrustweavecommand. Both entry points expose the same version and command surface.- A task-oriented developer integration-routes guide provides local, copy-paste routes for LangGraph-style declarations, exported OpenAI Agents descriptors, JSON-compatible CrewAI snapshots, saved MCP
tools/listresponses, and CI inputs.
Improved developer path
The README, installation guide, CI integration guidance, and reality checks now guide developers toward the correct local input path and independently validate the packaged module entry point from an isolated wheel. The development extra now includes the required Bandit scan, so the documented local quality command set installs consistently.
Verification
The release target is annotated tag v0.2.2 at commit 3b0817e732627a62a18be82e854a58fa085f0922.
- Local verification passed: Ruff formatting and linting, strict Mypy, Bandit, 720 tests, 96.96% branch coverage, repository reality checks, and a strict documentation-site build.
- Hosted CI, CodeQL, mutation-quality, and dependency-graph workflows passed on the exact tagged commit.
- The TestPyPI and PyPI trusted-publishing workflows completed successfully, followed by clean isolated installs from each index. Both
trustweaveandpython -m trustweavereported0.2.2, exposed the documented integration commands, and read packaged schemas successfully.
Boundary unchanged
TrustWeave continues to read only local declarations and already-recorded metadata. It does not execute agents, tools, or application code; connect to MCP servers; call models; access credentials; or publish review artifacts by default. Its output is evidence for human review, not runtime enforcement or a security verdict.
TrustWeave 0.2.1
TrustWeave 0.2.1
TrustWeave 0.2.1 is now published on PyPI from the annotated v0.2.1 tag at commit f1394d5fba8a0fbc24e3a18f45702e83aa65645e.
What changed
This corrective release finalizes the version contract after the pre-publication v0.2.0 audit identified that a top-level CLI version command was missing. The release adds:
trustweave --versionandtrustweave -V, each printing only the import-visible package version and exiting successfully without a subcommand.- Source-checkout and installed-wheel regression coverage for exact version output, empty standard error, metadata synchronization, and no configuration discovery or side effects.
- Synchronized package metadata, citation metadata, generated CLI help, release guidance, and installed-wheel validation for version
0.2.1.
The 0.2.0 hardening work remains included: strict local evidence contracts, versioned schemas, typed local review APIs, deterministic risk lifecycle controls, static chain and MCP review, SARIF exports, reproducible artifacts, and an expanded non-executing CI review workflow.
Verified release evidence
| Control | Result |
|---|---|
| Protected-main CI | Successful on the release target SHA |
| CodeQL and dependency review | Successful on the release target SHA |
| Mutation-quality workflow | 6,044 / 6,140 killed (98.4365%) with 96 equivalent survivors, zero untriaged records, and zero needs_regression records |
| Branch coverage | 95.54% in independent full-suite verification |
| Independent full test suite | 516 passed |
| Tag-local build | Wheel and sdist built and passed twine check |
| Reproducible wheel | Two fixed-epoch wheel builds were byte-identical |
| Clean installation | TestPyPI and PyPI installations both exposed trustweave --version, trustweave -V, and trustweave.__version__ as 0.2.1 |
| Dependency audit | No known vulnerabilities reported for declared runtime requirements |
The attached wheel, source distribution, reproducible CycloneDX SBOM, and SHA-256 checksum file correspond to the verified v0.2.1 source.
Install
python -m pip install --upgrade trustweave==0.2.1
trustweave --versionImportant release boundary
TrustWeave remains a local-first, deterministic, non-executing evidence tool. It does not execute agents, models, tools, MCP servers, shell commands from declarations, or network operations. Its outputs are review evidence, not runtime enforcement, authorization, remediation, signed attestations, or a security certification.
Preserved v0.2.0 audit record
The existing annotated v0.2.0 tag is deliberately retained as an immutable, unpublished audit record. It has no GitHub Release and was never published to PyPI. It must not be moved, reused, or treated as a public release.
See the 0.2.1 release notes, owner release checklist, and supply-chain evidence guide for scope and verification detail.
TrustWeave v0.1.1
TrustWeave 0.1.1
0.1.1 is the first production PyPI release of TrustWeave. It follows clean TestPyPI validation of 0.1.1rc2 and is published from the annotated v0.1.1 tag through a dedicated GitHub OIDC trusted publisher.
Highlights
- Adds deterministic local review workflows for declared agent trust boundaries, policy structure, architecture differences, local trace metadata, MCP metadata profiles, and cited synthetic adversarial scenarios.
- Supports static declaration normalization for LangGraph, OpenAI Agents SDK, and CrewAI proof fixtures without importing SDKs or executing integrations.
- Provides
mcp-scaffold,mcp-import,mcp-profile-check,framework-import,statement, andsarifalongside the existing scan, test, evidence, reporting, verification, diff, policy, and trace commands. - Adds a production release workflow that builds and validates distributions before publishing from a dedicated PyPI environment using GitHub OIDC. No stored PyPI upload token is used.
- Corrects the import-level package version and adds a regression test requiring
trustweave.__version__to matchpyproject.toml.
Verification evidence
The final target passed formatting, linting, strict typing, static security scanning, the full test suite with the 90% branch-coverage gate, repository reality checks, isolated wheel installation, reproducible-wheel verification, dependency audit, SBOM generation, and synthetic evidence workflows. Hosted CI passed on the tagged commit, and the dedicated production PyPI OIDC publishing workflow completed successfully.
Intentional boundaries
TrustWeave reads local declarative files and pre-recorded structured trace metadata. It does not execute agent tools, connect to MCP servers, call models, access credentials, send network traffic, upload SARIF, or provide runtime enforcement. The repository remains private. External signing and provenance attestations remain separately authorized work.
TrustWeave v0.1.0
TrustWeave v0.1.0
TrustWeave v0.1.0 establishes a local-first security-evidence workflow for declared AI-agent trust boundaries. It is an initial pre-release foundation intended for controlled development and review rather than a production-security certification.
Included in this release
| Area | Delivered capability |
|---|---|
| Agent Security Bundle | Validates a declarative manifest and writes reviewed sources, tools, flows, policy decisions, and scope limits. |
| Deterministic policy testing | Runs safe synthetic scenarios that exercise allow, deny, and approval-required outcomes. |
| Local evidence | Produces a hash-linked attestation, a Markdown report, and an internal verification result. |
| Safe reference example | Includes a fully synthetic customer-support agent with a denied untrusted-content-to-external-action path. |
| Project quality | Includes Ruff formatting and linting, strict type checking of the core package, six tests, package build verification, private CI, dependency review, contributor guidance, security policy, threat model, and release procedure. |
Verified evidence
The release target is commit 4f3af3189b14e2e894678207965f6673643c3b55. Local verification passed formatting, linting, type checking, six tests, the end-to-end synthetic evidence workflow, source and wheel builds, an isolated wheel install-and-run test, and an audit of the declared zero-runtime-dependency requirement set. Hosted CI passed on the exact target commit.
Important limitations
TrustWeave v0.1.0 does not execute MCP configurations, agent tools, network requests, model calls, or external actions. It does not automatically discover agent architecture, enforce a deployed runtime, scan vulnerabilities, or guarantee an agent system is secure. Its local attestation is hash-linked but not externally signed or backed by a transparency log.
See README.md, docs/THREAT_MODEL.md, and docs/RELEASE.md for the complete scope and operating procedure.