v0.4.0
Linmas 0.4.0
Proof Chain
- Adds human decision receipts with per-finding dispositions and a derived overall disposition.
- Creates portable offline proof bundles with hashed source evidence, Markdown and HTML reports, and fail-closed verification.
- Adds optional SSH signatures with explicit distinction between cryptographic validity and trusted signer identity.
- Adds a sealed Codex Security adapter that accepts only a completed scan directory with verified manifest, findings, coverage, and artifact hashes.
- Adds an offline
npm run demo:proofpath for reproducible Build Week judging.
Linmas remains defensive-only. Proof bundles are evidence records, not approvals, certifications, or proof that software is secure. Human review remains required.