Skip to content

v1.133.0

Choose a tag to compare

@SoundMatt SoundMatt released this 27 Jul 18:24
· 32 commits to main since this release
fed6615

fix: audit findings — stale docs, tool-count inconsistency, undocumented commands

Fixes from a 2026-07-27 deep audit (#74, #75).

#74 — false auth claim, five-vs-six inconsistency, stale tables

  • docs/tool-safety-manual.md: corrected the false "the web dashboard has no
    authentication" claim — fusaops serve --auth user:pass (HTTP Basic Auth,
    with an optional --auth-ro read-only role) genuinely exists.
  • README.md Install section: added jfusa, changed "bundles all five" to
    "bundles all six."
  • README.md "Bundled tools" tables: updated to the actual current tags —
    go-FuSa v0.33.4, cpp-FuSa v0.14.3, c-FuSa v0.5.42, rust-FuSa v0.3.8,
    py-FuSa v0.2.6, java-FuSa v0.4.5, spec v1.11.
  • CLAUDE.md: architecture table expanded from 11 packages to all ~38;
    "future tools" language replaced with the current six-language reality.
    fusaops.go's package doc comment updated to match.

#75 — docs/commands/ and README cover only 9/46 subcommands

  • Added 24 new docs/commands/*.md pages (comp, hooks, impact, disposition,
    pr, verify, sign, qualify, release, safety-case, sci, sas, tara, fmea,
    vuln, template, hara, vv, metrics, badge, slsa, capabilities, req,
    coverage), bringing documented commands from 9 to 33.
  • README.md: new "Compliance, evidence, and workflow commands" section
    gives every previously-unmentioned subcommand a one-line description and
    example.
  • cmd/fusaops/main.go: package doc comment now includes comp.

Full Changelog: v1.132.0...v1.133.0