Permesh 0.1.0-alpha.3 — evaluation prerelease
Pre-releasePermesh 0.1.0-alpha.3 — evaluation prerelease
Evaluation prerelease, not a stable release. These are the original qualified
artifacts from exact source add7a725745f5e05415b330e8d6be61fcaaf5d67 and
attested workflow 34351503021.
Published alpha.1 and alpha.2 assets remain unchanged.
Changes since alpha.2
- Explicit stable-account identity mappings and pinned JSON identity inventories.
- Private versioned snapshots, offline inspection and scope-aware diffs.
- Read-only offboarding assessment, advisory plans and JSON/HTML verification.
- Resource queries, focused local policies and offline provider development tools.
- Scoped native-provider approvals, launch integrity checks, negotiated discovery,
explicit network context and portable target-specific executable pins. - Host-owned exact-field credentials from 1Password Connect and separately
dispatched Vault/OpenBao KV v2; explicitly selected temporary AWS profiles. - Seven separate provider 0.2.0 candidates: GitHub, Google Workspace, Cloudflare,
AWS IAM, GitLab, Entra and AWS Identity Center. They are distributed separately and are not bundled with the CLI.
Compatibility and migration
Access JSON uses schema 2; control commands
retain schema 1. Local snapshot, diff and offboarding artifacts have independent
versioned contracts. Consumers must check the command, schema, completeness and
limitations. No SDK or negotiated protocol stability is declared.
Legacy bundled provider execution is removed. Follow the explicit
GitHub and Google migration
instructions. Legacy GitHub 0.1.0 remains available; negotiated-v1 providers
require separately distributed 0.2.0 packages. Downloading or updating a package
does not authorize execution, adopt workspace pins or deliver credentials.
The exact alpha.3/0.2.0 pair below passed local packaged acceptance. This does
not establish the oldest compatible host version. Public catalog availability
and acceptance are recorded separately below.
Upgrade the CLI to alpha.3 before using the expanded provider catalog. Alpha.2
rejects negotiated-v1 catalog metadata, including when requesting legacy 0.1.0.
Adding catalog entries does not change existing installed packages, trust or
workspace pins. Separately, upgrading from alpha.2 leaves legacy approval records
stored but requires one fresh scoped review and explicit approval before provider
health checks or queries; old approval authority is not carried into alpha.3.
Qualification and promotion
The reviewed candidate source is
add7a725745f5e05415b330e8d6be61fcaaf5d67,
merged by PR 41 after
three-platform CI, minimum-Rust, dependency checks and all five native PR jobs
passed. Its tree matches reviewed head 4e32264bb646f542d0b9b692cc4f08b58078ac27.
The exact-main attested run 34351503021
passed all five native jobs and its downstream signed-provenance verification.
The exact merged revision also passed
CI and
dependency checks.
On 2026-09-09, all 20 original archive/inventory/checksum subjects were downloaded
and independently verified. Checks covered GitHub upload SHA-256 digests, strict
archive/file allowlists, native architecture, binary/inventory/locked dependency
bindings, registry checksums and dependency notice-content hashes. All 20 subjects
also passed both distributed-bundle and public repository attestation verification
against this exact source/signer SHA, the attested workflow identity,
refs/heads/main, SLSA v1 predicate and hosted-runner requirement.
The original bundle and 20 subjects are retained without rebuilding or recompression.
The release assets are those exact original workflow files.
Packaged acceptance
The exact Apple Silicon executable SHA-256 is
33d366c9b7481bed551b9de41a81af95324984f36d145a03288cf9b2147630a8.
It passed the following local checks:
- Public catalog GitHub 0.1.0 install, update check and idempotent exact-version
update; workspace bytes stayed unchanged and no trust/approval state appeared. - All 35 provider 0.2.0 archives from
run 34349822945,
sourcefde7472c2c32a30bbd885f7c8db6d73b178f4aa1, passed the alpha.3 host
PackageStorevalidator through a separately compiled source-matched harness.
This is five-target package-format acceptance on macOS, not execution of foreign
target binaries. - All seven native macOS providers passed credential-free protocol descriptions
and handshakes, then actual declarative setup through the packaged CLI, explicit
executable trust, no automatic workspace approval, wrong-fingerprint rejection,
exact approval and missing-credential rejection. Reviewed five-target digest maps
and the native resolved digest matched the validated packages; missing and changed
native pins failed before credential delivery. - Portable maps were explicitly applied to the setup-generated local configuration.
The production catalog URL was unchanged. This does not exercise public
guided installation/update of 0.2.0 entries; subsequent public acceptance is
recorded below. - Synthetic identity/resource queries, private snapshots, inspection/diff,
offboarding assessment/plan/verification with local HTML and policy findings
exit 6 passed. Snapshot, plan and HTML modes were 0600 and queries preserved
workspace bytes. Four controlling-PTY checks passed: organization input,
nonprompting JSON, hidden-input EOF and terminal echo restoration. - A uniquely named synthetic macOS Keychain entry passed CLI absence, store,
status and deletion. An independent/usr/bin/securityvalue read exceeded its
20-second deadline. Cleanup ran and a separate CLI status confirmed absence.
The independent value comparison and full interactive desktop acceptance remain
incomplete; the timeout is not recorded as a successful comparison.
The same CLI and the exact GitHub 0.2.0 executable
9f2b82992c62767229af9af93dc5ddc3520d4e43e0a61513f621de1bb4688f02
passed the previously authorized NIPE-Solutions-only read-only health,
provider-status and stable-account JSON query. Credentials and raw reports stayed
out of logs/artifacts; temporary trust/configuration state was removed. Visibility
limitations remained explicit, with no inferred verified email or canonical
identity. This binds that limited live result to exact packaged bytes; it does
not qualify other tenants, providers, API paths or targets.
Original candidate files
This release carries the following original files.
The bundle authenticates the 20 subjects; it is not itself a signed subject or a
platform code signature. Compare downloaded release bytes against these hashes.
| File | Bytes | SHA-256 |
|---|---|---|
permesh-0.1.0-alpha.3-aarch64-apple-darwin.dependencies.json |
106788 | d4b300d4816ebb47b86dad66264967c27cac83a70cd62fbed3c13830133aeb73 |
permesh-0.1.0-alpha.3-aarch64-apple-darwin.dependencies.json.sha256 |
127 | 072ec0907305c106ed416b83a1b019fe84ecea6f8c1dae1ebf896285ae082d00 |
permesh-0.1.0-alpha.3-aarch64-apple-darwin.tar.gz |
5090688 | ec20f27a4aa4c9f776d0475861094bbd83ce884e1cae1cd35d67708617eed250 |
permesh-0.1.0-alpha.3-aarch64-apple-darwin.tar.gz.sha256 |
116 | fdd7d84fd9ad7997118f2438c742cc804e302c4efac245ce1afe4f33012941c2 |
permesh-0.1.0-alpha.3-aarch64-unknown-linux-gnu.dependencies.json |
139919 | afa791bb3b78be3243787e7a602db3c1fbdecb9ac5809fea3000ec8039352c49 |
permesh-0.1.0-alpha.3-aarch64-unknown-linux-gnu.dependencies.json.sha256 |
132 | ce70fc24ab5373d45dfa97c2cf738a47d962aa5a13234c8072d4540dd45e9ce5 |
permesh-0.1.0-alpha.3-aarch64-unknown-linux-gnu.tar.gz |
6260494 | 3296fb6acced1e34b41cb1a4131cbba86ec1fc990debdc2094bc84c8e8fd5d51 |
permesh-0.1.0-alpha.3-aarch64-unknown-linux-gnu.tar.gz.sha256 |
121 | 31c439a37c6ff5ac49540e3b65687a18f99746c908568a3d95b1b210bb54b0b9 |
permesh-0.1.0-alpha.3-x86_64-apple-darwin.dependencies.json |
108684 | 780ecc00a5035a7e8cf93065fda4b1f0653b47dae950db500de4089aa799a4dd |
permesh-0.1.0-alpha.3-x86_64-apple-darwin.dependencies.json.sha256 |
126 | 9cea3f9485eeaff8d35392e07a72edeb14c6d2366de8e5fef35dbaeb2af7013e |
permesh-0.1.0-alpha.3-x86_64-apple-darwin.tar.gz |
5501325 | bf4128c027c7317c0aac0b73460c80561661bd3605e5c3f972b98e861e1d0221 |
permesh-0.1.0-alpha.3-x86_64-apple-darwin.tar.gz.sha256 |
115 | 17d0305a6b5c2597fba199b6d1761a573b8536842f83dbb78ac1ab667ad7314e |
permesh-0.1.0-alpha.3-x86_64-pc-windows-msvc.dependencies.json |
113331 | 15794c109a0c6738104109bd03c36c1dace10f2e27a6b77ca61239b4777fa832 |
permesh-0.1.0-alpha.3-x86_64-pc-windows-msvc.dependencies.json.sha256 |
129 | e0aaa48eb8c041814ae454d69b79be69dda624162355dce5098f295461f0782f |
permesh-0.1.0-alpha.3-x86_64-pc-windows-msvc.zip |
5898540 | 3fcea03f5d39d1d1856f2196da9b5dd83d69f8bd5c8885126b5be18fbef018e6 |
permesh-0.1.0-alpha.3-x86_64-pc-windows-msvc.zip.sha256 |
115 | a963cdb144955bce1f9f89417b08a8b15bda2f130c6423fcb12b6a77fef799d7 |
permesh-0.1.0-alpha.3-x86_64-unknown-linux-gnu.dependencies.json |
141815 | a52bfd2647e42b83081563d4ca3cd375d3a90e0946fe0aa958a2b050ca6fb400 |
permesh-0.1.0-alpha.3-x86_64-unknown-linux-gnu.dependencies.json.sha256 |
131 | 2d88e6c92f5b89f7047da27c9d9f2e7c8033953bf5c8717eaa9b01f5136cf67c |
permesh-0.1.0-alpha.3-x86_64-unknown-linux-gnu.tar.gz |
6720564 | c82ecf7c12f73b625e5b69226185d160e37ec3ab96af8a47bc03e9f7836eabc9 |
permesh-0.1.0-alpha.3-x86_64-unknown-linux-gnu.tar.gz.sha256 |
120 | eb2d5c7546ebe81909505dc36063434a7038e483d9b7969e0c4d3902fd2018ac |
attestation-bundle.json |
15218 | ef8ecd818713c16edbc69ccbfc46fe0875c8f69d3eefa23d6a11455ac5c7b956 |
Follow the release verification procedure
with source SHA add7a725745f5e05415b330e8d6be61fcaaf5d67. Platform code signing
and notarization are absent; GitHub build provenance is a separate assurance.
Published asset verification
On 2026-09-09, all 21 authenticated draft downloads and all 21 unauthenticated
public release downloads matched the original file names, sizes and SHA-256
values above. The release tag resolves to add7a725745f5e05415b330e8d6be61fcaaf5d67.
All 20 draft subjects passed signed-bundle verification. All 20 public release
subjects then passed both signed-bundle and public API verification, each reporting
Validated and verified signed provenance for all 20 candidate files.
To repeat the public checks, use the verifier and Cargo.lock from the exact source
revision above. Put the 20 archive/inventory/checksum files in release-subjects/
and the original bundle beside that directory, then run from that source checkout:
python3.12 scripts/verify_candidates.py release-subjects \
--version 0.1.0-alpha.3 --lockfile Cargo.lock \
--source-sha add7a725745f5e05415b330e8d6be61fcaaf5d67 \
--bundle attestation-bundle.json
python3.12 scripts/verify_candidates.py release-subjects \
--version 0.1.0-alpha.3 --lockfile Cargo.lock \
--source-sha add7a725745f5e05415b330e8d6be61fcaaf5d67The verifier requires authenticated GitHub CLI for repository attestation lookup
and pins workflow identity, source/signer digest, main ref, SLSA v1 and hosted
runners. The two modes verified the same public release subjects.
Public catalog acceptance
Provider catalog PR 23
added the 35 original 0.2.0 entries, preserving the five legacy GitHub entries.
On 2026-09-09, the exact publicly downloaded Apple Silicon alpha.3 CLI passed
public catalog installation and idempotent exact-version update for all seven
native 0.2.0 packages. Every installed executable matched its original digest.
GitHub, Google, Cloudflare and AWS IAM passed guided provider add --portable:
missing consent was rejected; explicit consent completed native trust and
workspace approval; all five target pins and native resolution matched the
catalog. GitLab, Entra and Identity Center passed public installation followed
by explicit native trust, negotiated setup, review and approval. Their five-target
maps were reviewed and applied explicitly; alpha.3 does not offer guided add for
these three types. Wrong approval fingerprints were rejected on that path.
All seven rejected absent credentials before provider API access.
With alpha.3, a GitHub 0.1.0 workspace retained its bytes, selected pin, review
fingerprint and approval after provider update --check found 0.2.0 and an
explicit provider update downloaded it. Downloading did not adopt the new pin.
This checks provider update within alpha.3, not migration of alpha.2 approvals.
Temporary acceptance state was removed. No live credentials or provider API
calls were used; the earlier limited NIPE-Solutions acceptance remains the
only live evidence and binds to the identical released executable hashes.
Evaluation limits
Only the limited NIPE-Solutions GitHub checks above have live candidate evidence.
Broader GitHub checks,
Google, Cloudflare, AWS, GitLab and Entra tenants and separately authorized
Connect/Vault/OpenBao services remain prerequisites. Synthetic API fixtures do
not establish real API permissions or complete effective authorization.
Interactive desktop credential stores and Windows terminals require separate
acceptance. Apple/Windows platform signing and notarization are absent. GitHub
provenance authenticates build subjects, not platform reputation, live-provider
correctness or reproducible builds. The dependency inventory is not a standards
SBOM. MIT remains the project license; required dependency notices ship separately.
No remote remediation, backend, telemetry, hidden update, automatic credential
refresh or infrastructure mutation is introduced. Future phases 6–7 remain
roadmap/ADR work. No verified sponsorship destination is available.