Releases: NIPE-Solutions/permesh
Release list
Permesh 0.1.0-alpha.3 — evaluation prerelease
Permesh 0.1.0-alpha.3 — evaluation prerelease
Evaluation prerelease, not a stable release. These are the original qualified
artifacts from exact source add7a725745f5e05415b330e8d6be61fcaaf5d67 and
attested workflow 34351503021.
Published alpha.1 and alpha.2 assets remain unchanged.
Changes since alpha.2
- Explicit stable-account identity mappings and pinned JSON identity inventories.
- Private versioned snapshots, offline inspection and scope-aware diffs.
- Read-only offboarding assessment, advisory plans and JSON/HTML verification.
- Resource queries, focused local policies and offline provider development tools.
- Scoped native-provider approvals, launch integrity checks, negotiated discovery,
explicit network context and portable target-specific executable pins. - Host-owned exact-field credentials from 1Password Connect and separately
dispatched Vault/OpenBao KV v2; explicitly selected temporary AWS profiles. - Seven separate provider 0.2.0 candidates: GitHub, Google Workspace, Cloudflare,
AWS IAM, GitLab, Entra and AWS Identity Center. They are distributed separately and are not bundled with the CLI.
Compatibility and migration
Access JSON uses schema 2; control commands
retain schema 1. Local snapshot, diff and offboarding artifacts have independent
versioned contracts. Consumers must check the command, schema, completeness and
limitations. No SDK or negotiated protocol stability is declared.
Legacy bundled provider execution is removed. Follow the explicit
GitHub and Google migration
instructions. Legacy GitHub 0.1.0 remains available; negotiated-v1 providers
require separately distributed 0.2.0 packages. Downloading or updating a package
does not authorize execution, adopt workspace pins or deliver credentials.
The exact alpha.3/0.2.0 pair below passed local packaged acceptance. This does
not establish the oldest compatible host version. Public catalog availability
and acceptance are recorded separately below.
Upgrade the CLI to alpha.3 before using the expanded provider catalog. Alpha.2
rejects negotiated-v1 catalog metadata, including when requesting legacy 0.1.0.
Adding catalog entries does not change existing installed packages, trust or
workspace pins. Separately, upgrading from alpha.2 leaves legacy approval records
stored but requires one fresh scoped review and explicit approval before provider
health checks or queries; old approval authority is not carried into alpha.3.
Qualification and promotion
The reviewed candidate source is
add7a725745f5e05415b330e8d6be61fcaaf5d67,
merged by PR 41 after
three-platform CI, minimum-Rust, dependency checks and all five native PR jobs
passed. Its tree matches reviewed head 4e32264bb646f542d0b9b692cc4f08b58078ac27.
The exact-main attested run 34351503021
passed all five native jobs and its downstream signed-provenance verification.
The exact merged revision also passed
CI and
dependency checks.
On 2026-09-09, all 20 original archive/inventory/checksum subjects were downloaded
and independently verified. Checks covered GitHub upload SHA-256 digests, strict
archive/file allowlists, native architecture, binary/inventory/locked dependency
bindings, registry checksums and dependency notice-content hashes. All 20 subjects
also passed both distributed-bundle and public repository attestation verification
against this exact source/signer SHA, the attested workflow identity,
refs/heads/main, SLSA v1 predicate and hosted-runner requirement.
The original bundle and 20 subjects are retained without rebuilding or recompression.
The release assets are those exact original workflow files.
Packaged acceptance
The exact Apple Silicon executable SHA-256 is
33d366c9b7481bed551b9de41a81af95324984f36d145a03288cf9b2147630a8.
It passed the following local checks:
- Public catalog GitHub 0.1.0 install, update check and idempotent exact-version
update; workspace bytes stayed unchanged and no trust/approval state appeared. - All 35 provider 0.2.0 archives from
run 34349822945,
sourcefde7472c2c32a30bbd885f7c8db6d73b178f4aa1, passed the alpha.3 host
PackageStorevalidator through a separately compiled source-matched harness.
This is five-target package-format acceptance on macOS, not execution of foreign
target binaries. - All seven native macOS providers passed credential-free protocol descriptions
and handshakes, then actual declarative setup through the packaged CLI, explicit
executable trust, no automatic workspace approval, wrong-fingerprint rejection,
exact approval and missing-credential rejection. Reviewed five-target digest maps
and the native resolved digest matched the validated packages; missing and changed
native pins failed before credential delivery. - Portable maps were explicitly applied to the setup-generated local configuration.
The production catalog URL was unchanged. This does not exercise public
guided installation/update of 0.2.0 entries; subsequent public acceptance is
recorded below. - Synthetic identity/resource queries, private snapshots, inspection/diff,
offboarding assessment/plan/verification with local HTML and policy findings
exit 6 passed. Snapshot, plan and HTML modes were 0600 and queries preserved
workspace bytes. Four controlling-PTY checks passed: organization input,
nonprompting JSON, hidden-input EOF and terminal echo restoration. - A uniquely named synthetic macOS Keychain entry passed CLI absence, store,
status and deletion. An independent/usr/bin/securityvalue read exceeded its
20-second deadline. Cleanup ran and a separate CLI status confirmed absence.
The independent value comparison and full interactive desktop acceptance remain
incomplete; the timeout is not recorded as a successful comparison.
The same CLI and the exact GitHub 0.2.0 executable
9f2b82992c62767229af9af93dc5ddc3520d4e43e0a61513f621de1bb4688f02
passed the previously authorized NIPE-Solutions-only read-only health,
provider-status and stable-account JSON query. Credentials and raw reports stayed
out of logs/artifacts; temporary trust/configuration state was removed. Visibility
limitations remained explicit, with no inferred verified email or canonical
identity. This binds that limited live result to exact packaged bytes; it does
not qualify other tenants, providers, API paths or targets.
Original candidate files
This release carries the following original files.
The bundle authenticates the 20 subjects; it is not itself a signed subject or a
platform code signature. Compare downloaded release bytes against these hashes.
| File | Bytes | SHA-256 |
|---|---|---|
permesh-0.1.0-alpha.3-aarch64-apple-darwin.dependencies.json |
106788 | d4b300d4816ebb47b86dad66264967c27cac83a70cd62fbed3c13830133aeb73 |
permesh-0.1.0-alpha.3-aarch64-apple-darwin.dependencies.json.sha256 |
127 | 072ec0907305c106ed416b83a1b019fe84ecea6f8c1dae1ebf896285ae082d00 |
permesh-0.1.0-alpha.3-aarch64-apple-darwin.tar.gz |
5090688 | ec20f27a4aa4c9f776d0475861094bbd83ce884e1cae1cd35d67708617eed250 |
permesh-0.1.0-alpha.3-aarch64-apple-darwin.tar.gz.sha256 |
116 | fdd7d84fd9ad7997118f2438c742cc804e302c4efac245ce1afe4f33012941c2 |
permesh-0.1.0-alpha.3-aarch64-unknown-linux-gnu.dependencies.json |
139919 | afa791bb3b78be3243787e7a602db3c1fbdecb9ac5809fea3000ec8039352c49 |
permesh-0.1.0-alpha.3-aarch64-unknown-linux-gnu.dependencies.json.sha256 |
132 | ce70fc24ab5373d45dfa97c2cf738a47d962aa5a13234c8072d4540dd45e9ce5 |
permesh-0.1.0-alpha.3-aarch64-unknown-linux-gnu.tar.gz |
6260494 | 3296fb6acced1e34b41cb1a4131cbba86ec1fc990debdc2094bc84c8e8fd5d51 |
permesh-0.1.0-alpha.3-aarch64-unknown-linux-gnu.tar.gz.sha256 |
121 | 31c439a37c6ff5ac49540e3b65687a18f99746c908568a3d95b1b210bb54b0b9 |
permesh-0.1.0-alpha.3-x86_64-apple-darwin.dependencies.json |
108684 | 780ecc00a5035a7e8cf93065fda4b1f0653b47dae950db500de4089aa799a4dd |
permesh-0.1.0-alpha.3-x86_64-apple-darwin.dependencies.json.sha256 |
126 | 9cea3f9485eeaff8d35392e07a72edeb14c6d2366de8e5fef35dbaeb2af7013e |
permesh-0.1.0-alpha.3-x86_64-apple-darwin.tar.gz |
5501325 | bf4128c027c7317c0aac0b73460c80561661bd3605e5c3f972b98e861e1d0221 |
permesh-0.1.0-alpha.3-x86_64-apple-darwin.tar.gz.sha256 |
115 | 17d0305a6b5c2597fba199b6d1761a573b8536842f83dbb78ac1ab667ad7314e |
permesh-0.1.0-alpha.3-x86_64-pc-windows-msvc.dependencies.json |
113331 | 15794c109a0c6738104109bd03c36c1dace10f2e27a6b77ca61239b4777fa832 |
permesh-0.1.0-alpha.3-x86_64-pc-windows-msvc.dependencies.json.sha256 |
129 | e0aaa48eb8c041814ae454d69b79be69dda624162355dce5098f295461f0782f |
permesh-0.1.0-alpha.3-x86_64-pc-windows-msvc.zip |
5898540 | 3fcea03f5d39d1d1856f2196da9b5dd83d69f8bd5c8885126b5be18fbef018e6 |
permesh-0.1.0-alpha.3-x86_64-pc-windows-msvc.zip.sha256 |
115 | a963cdb144955bce1f9f89417b08a8b15bda2f130c6423fcb12b6a77fef799d7 |
permesh-0.1.0-alpha.3-x86_64-unknown-linux-gnu.dependencies.json |
141815 | a52bfd2647e42b83081563d4ca3cd375d3a90e0946fe0aa958a2b050ca6fb400 |
permesh-0.1.0-alpha.3-x86_64-unknown-linux-gnu.dependencies.json.sha256 |
131 | 2d88e6c92f5b89f7047da27c9d9f2e7c8033953bf5c8717eaa9b01f5136cf67c |
| `per... |
Permesh 0.1.0-alpha.2
Permesh 0.1.0-alpha.2
Know who has access to what.
Second CLI prerelease for evaluation. Permesh remains local-first and read-only, with no backend or telemetry. This is not stable v0.1.
Changes since alpha.1
- Browser OAuth login for explicitly trusted and approved external providers declaring the flow:
auth login INSTANCE --browser, with--no-openfor manual browser opening. The CLI owns PKCE, callback validation, cancellation and refresh-credential storage in the OS keychain. - Explicit Google provider migration preserving identity mappings, authority and credential references.
- Native Unix terminal acceptance checks, target-bound dependency inventories, and verified GitHub build provenance.
GitHub 0.1.0 remains the only published official provider package. Google 0.1.1, Cloudflare 0.1.0 and AWS 0.1.0 are unpublished drafts awaiting live acceptance. CLI upgrades do not install, update or trust providers automatically.
Qualification
Released source: aad58397e139ed755fcf983da8e9f045e7e5a556. The release contains the original verified artifacts from attested native run 34273757910, without rebuilding or recompression.
CI and fresh dependency checks passed at this exact source. All five native targets passed tests, builds, packaging and synthetic smoke checks. The 20 artifact subjects were independently verified using both the distributed bundle and GitHub's attestation API, pinned to the source, signer, workflow identity, main ref and GitHub-hosted runners. Packaged CLI acceptance includes the offline demo and explicit public GitHub provider install/update checks in isolated local state.
Fresh public downloads of all 21 release files matched the qualified sizes and SHA-256 digests. All 20 signed subjects passed structural checks and provenance verification again through both the published bundle and public attestation lookup. The public Mac Apple Silicon binary also passed the offline demo and isolated GitHub provider install/update acceptance checks.
Verify before extracting
Download your archive, its checksum and attestation-bundle.json. With a current GitHub CLI:
gh attestation verify DOWNLOADED_FILE \
--repo NIPE-Solutions/permesh \
--cert-identity https://github.com/NIPE-Solutions/permesh/.github/workflows/attested-candidates.yml@refs/heads/main \
--source-digest aad58397e139ed755fcf983da8e9f045e7e5a556 \
--signer-digest aad58397e139ed755fcf983da8e9f045e7e5a556 \
--source-ref refs/heads/main \
--predicate-type https://slsa.dev/provenance/v1 \
--deny-self-hosted-runners \
--bundle attestation-bundle.jsonOmit --bundle and its argument to verify through public attestation lookup. Verify the checksum as well; see installation. The bundle is not itself one of the 20 attested subjects; its signature is verified against the trusted issuer.
Evaluation limits
- Executables have no Apple Developer ID/notarization or Windows Authenticode distribution signatures. Build provenance does not replace OS signing or establish reproducible builds.
- Native jobs qualify their actual runner environments. Linux binaries use Ubuntu 24.04 system libraries; no musl, static-linking or older-OS compatibility claim is made.
- Real Google consent and directory visibility, Cloudflare/AWS acceptance, broader GitHub permission/inheritance fixtures, Windows terminal behavior and interactive desktop credential stores remain open.
- AWS source currently uses named credential references and reports IAM policy attachments with unknown effective privilege. Native AWS profiles/SSO refresh and effective-policy evaluation remain unsupported.
- The dependency inventory is Permesh format 1, not a CycloneDX/SPDX SBOM. Package-manager distribution and CLI self-update remain future work.
Existing alpha.1 and GitHub provider 0.1.0 assets remain unchanged. Provider data and credentials were not included in these release artifacts or qualification evidence.
Files
Twenty attested subjects plus the verified bundle:
| File | Bytes | SHA-256 |
|---|---|---|
attestation-bundle.json |
15312 | 564e7b3c7441afb3a156d0078bca70945219c3680fc62a9c337fff27889408db |
permesh-0.1.0-alpha.2-aarch64-apple-darwin.dependencies.json |
107584 | bd43b76627d644b92e9ac4aa4a8b97a5e3244ffa1544f67ea6f0c7f8e67cc564 |
permesh-0.1.0-alpha.2-aarch64-apple-darwin.dependencies.json.sha256 |
127 | ad150408cf611d241162ae7af48129e5852d061a04825ef1fd0f95de6fedbfc2 |
permesh-0.1.0-alpha.2-aarch64-apple-darwin.tar.gz |
4260880 | f45f4668539e1c8aee299c131d9f1b6db08fcf2aed666e488f717336abea87d6 |
permesh-0.1.0-alpha.2-aarch64-apple-darwin.tar.gz.sha256 |
116 | 2a73b671bcb3ab8a09eecd15212b2ef1b305d57ebc8178022fe8cbe8b01259e7 |
permesh-0.1.0-alpha.2-aarch64-unknown-linux-gnu.dependencies.json |
140715 | bccfb50c2ae2db4b9bd4a3bcb19869fe8b61b4a72afaa7198be05f8dbc00e312 |
permesh-0.1.0-alpha.2-aarch64-unknown-linux-gnu.dependencies.json.sha256 |
132 | 792cdfe26d3dfc56508cf73178176d802296b4548c6dbc2c59ed846e53bae539 |
permesh-0.1.0-alpha.2-aarch64-unknown-linux-gnu.tar.gz |
5392925 | dd9d0c8592fd7b6bb5b1e89ddde0928fe8d01aceb864204b3114061d859607db |
permesh-0.1.0-alpha.2-aarch64-unknown-linux-gnu.tar.gz.sha256 |
121 | bb95ba52df1c64de4f44eb0eedcd461b7d090c19f82d13fec7ef2c0837baefc3 |
permesh-0.1.0-alpha.2-x86_64-apple-darwin.dependencies.json |
109480 | a09a8e1a3feebb8fca48ae8958016a5bd6a14b5086cd1a0af2c7334e206188ee |
permesh-0.1.0-alpha.2-x86_64-apple-darwin.dependencies.json.sha256 |
126 | 81bdad3f220004b571285fad3a508010e39b5452c58f1881465663c8c99807ab |
permesh-0.1.0-alpha.2-x86_64-apple-darwin.tar.gz |
4581184 | 7844e10867025724a073c4af632cef0036880d19e9d9da6f55cc7cec432af70e |
permesh-0.1.0-alpha.2-x86_64-apple-darwin.tar.gz.sha256 |
115 | 6ccfa7c3cbae856ae26349de49ab1e13538b8b17c57cbee11a4dc42bfa7d1e92 |
permesh-0.1.0-alpha.2-x86_64-pc-windows-msvc.dependencies.json |
114127 | 0500371a43c06d332786ce497d93df214e4237e70d1b0afd55be34bb4777c02d |
permesh-0.1.0-alpha.2-x86_64-pc-windows-msvc.dependencies.json.sha256 |
129 | 68cff3f52b67ce4b032e4751977a99168cdb6f719a0acfafe07edda5ff389f16 |
permesh-0.1.0-alpha.2-x86_64-pc-windows-msvc.zip |
4921611 | 75612c5c4b41fa5bcfbed1948a89daae7d1f50f87f8da6a2cae4501271ef2280 |
permesh-0.1.0-alpha.2-x86_64-pc-windows-msvc.zip.sha256 |
115 | 985fbd737533e0a8ccdc05a8378548aa9627d4db9c60baa5204287f6f7f4ebc0 |
permesh-0.1.0-alpha.2-x86_64-unknown-linux-gnu.dependencies.json |
142611 | 1992f6d75ea7e61d412fc02a3cfec6f065f9f4a5fee2165e3c225220a1e8c9b1 |
permesh-0.1.0-alpha.2-x86_64-unknown-linux-gnu.dependencies.json.sha256 |
131 | 846bef5c20ce17554217c7ebdd088f46705fc66e04de465b05161a4c25aae30c |
permesh-0.1.0-alpha.2-x86_64-unknown-linux-gnu.tar.gz |
5797310 | cbedb2d56dc8cf12119481bef323d8c0bcca73517769f5aa8fedf24e70acc033 |
permesh-0.1.0-alpha.2-x86_64-unknown-linux-gnu.tar.gz.sha256 |
120 | f0c9262b58adfe6b6b3e584032716e6ca2442d336c57745fbc1fcf68fbcf159c |
Permesh 0.1.0-alpha.1
Permesh 0.1.0-alpha.1
Know who has access to what.
First public CLI prerelease for evaluation. Permesh discovers and correlates access locally, with read-only providers, no backend and no telemetry.
Download the archive for your OS/CPU and its adjacent SHA-256 file. Verify before extraction; each archive includes the MIT license, dependency notices and installation instructions. See the installation guide.
permesh init --demo
permesh doctor
permesh user alice@example.com
permesh user alice@example.com --jsonThe offline demo needs no credentials or network. GitHub is installed separately:
permesh provider install github --version 0.1.0
permesh provider update github --checkInstallation does not trust or run provider code. Follow the explicit trust/setup/approval guide before querying GitHub. Google directory discovery and demo remain bundled.
Qualification
- Cross-platform CI: fmt, strict Clippy, locked tests, native secret-store exercises and Rust 1.91 minimum.
- Dependency checks: cargo-deny and cargo-audit with fresh advisories.
- Native artifacts: five native test/build/version/demo/package jobs. Published bytes are promoted unchanged from these artifacts.
- Independently checked archive allowlists, file types, SHA-256 checksums, MIT text and dependency notice integrity.
- Downloaded Apple Silicon binary passed demo, exact human/JSON version, public provider installation/update checks, and configuration/trust preservation.
- Read-only GitHub health, canonical-user and privileged-access observations matched the previously validated adapter. Only aggregate outcomes were retained; no organization details, credentials or access reports are included.
Known limitations
This is alpha, not stable v0.1. Binaries are unsigned/unnotarized, with no attestation, SBOM or reproducible-build guarantee. Checksums detect corruption, not publisher authenticity. Linux builds target GNU systems using Ubuntu 24.04 system libraries; older OS compatibility is unqualified.
Interactive Windows/Linux credential-store acceptance, broader live GitHub fixtures and live Google tenant qualification remain open. Google requires externally supplied OAuth access tokens. Observed access is not proof of exhaustive effective authorization. External native code is not sandboxed, and provider protocols remain drafts.
There is no CLI self-update, crates.io or package-manager release. provider update updates provider packages only. AWS, Cloudflare, broader authentication flows, Google provider extraction, and stable-release qualification remain next steps.
Full limitations · Roadmap · Private vulnerability reporting
Revision and build environment
Release tag targets 929ae3e2c69d0cd4cbfb2fdbfce6ed3085f36f69. Its entire tree matches reviewed PR head 0e6792eeb848e86b06eb5fb36ab74affae1885e7 and tested PR merge c8f1e92c05aeea4c81daa073075e2e579ef0de89.
| Target | Runner image | Image version |
|---|---|---|
| macOS ARM64 | macos-15-arm64 | 20260829.0321.1 |
| macOS Intel | macos-15 | 20260824.0482.1 |
| Linux x86_64 | ubuntu-24.04 | 20260831.293.1 |
| Linux ARM64 | ubuntu-24.04-arm | 20260831.111.1 |
| Windows x86_64 | windows-2025-vs2026 | 20260824.214.3 |
Archive SHA-256
eb2d29b4320535777529ec6fe8326c685ac206dc529d8d2d2b10df74c0a293db permesh-0.1.0-alpha.1-aarch64-unknown-linux-gnu.tar.gz
183339136a6f0a6a2d6ef09119e32896f837d675e7a105d244f32a807f590908 permesh-0.1.0-alpha.1-x86_64-unknown-linux-gnu.tar.gz
8168852d2b206f73ec9b3fa8cb674a7f435752376976636f915d1c20edcf990a permesh-0.1.0-alpha.1-aarch64-apple-darwin.tar.gz
a6e80169e55cb636a25d90822396ff53ec00218949896f761b72b833c3324ef5 permesh-0.1.0-alpha.1-x86_64-apple-darwin.tar.gz
93f95259d84983a5a086723dffaefaaf81240281bdc11ca2588680d28634eceb permesh-0.1.0-alpha.1-x86_64-pc-windows-msvc.zip