ZSEC Community 0.3.14
ZSEC Community 0.3.14 adds decentralized, credential-free automatic security-intelligence updates.
Each installation independently checks the fixed TalkToAI HTTPS endpoint on a randomized daily schedule. Updates are accepted only after the embedded Ed25519 trust root verifies the signature, sequence, expiry, exact data-only policy, complete catalog schema, and SHA-256 digest. Rollbacks, changed content at a reused sequence, expired metadata, malformed catalogs, remote commands, automatic remediation, malware samples, and derived detection rules are rejected. Installation is atomic and preserves the last accepted catalog when a check fails.
The Windows companion now performs automatic due checks while monitoring remains active. The desktop interface reports the last check, last valid update, next check, accepted sequence, expiry, source, and any error without turning missing evidence green.
The separately signed application channel is notification-only in this release. Because the Windows files are not Authenticode-signed, ZSEC does not automatically download or execute application packages. Microsoft Defender remains the supported Windows real-time and pre-access protection provider; ZSEC Community adds post-change monitoring, scanning, evidence, encrypted quarantine, and update verification.
Release gates: 200 tests passed, 2 platform/environment skips, 12 subtests passed; Ruff, Mypy, static-site validation, main CI, tag CI, and cross-platform native release passed. Two independent Windows desktop builds produced the same full archive SHA-256.
Windows desktop archive SHA-256: c75dc396c3768fdb0af58331b495ecdfcbd272950e75e303e7354f478a1e1605
Source revision: 57557ae4dd03765a59b05a3a0e0006edc13b7bd4