v0.5.1
Immutable
release. Only release title and notes can be modified.
What changed
- Added GitHub-compatible primaryLocationLineHash fingerprints while preserving agentHygieneFingerprint/v1, rule IDs, JSON schema 1, and SARIF compatibility.
- Unified CR, LF, and CRLF location handling across rules, suppressions, JSON diagnostics, and SARIF.
- Kept truncated scans fail-closed: unsafe tail fingerprints are omitted and the invocation is marked unsuccessful.
Merged in #8.
Independent release verification
- Release workflow: https://github.com/Yuki9814/agent-hygiene/actions/runs/30363259311
- Downloaded all 3 assets from this immutable release and verified SHA256SUMS independently.
- Wheel SHA-256: 4d48ad2155c6d073578c77f1cbd52b8a3d89a0f45fc044dd8fa2b5303b9dc435
- Source archive SHA-256: 1e6bbe4f2b882b853988fffe0ad6db34e67eaccb407928df706b296f2d3306fe
- Installed the downloaded wheel without dependencies in a fresh virtual environment; version reported agent-hygiene 0.5.1 and the repository self-scan scored 100/100 with no findings.
- Exact-tag GitHub Action smoke: https://github.com/Yuki9814/agent-hygiene/actions/runs/30363426653
Evidence status
Part of #4. External evidence remains N=0 consenting repositories and N=0 independent reviewers; no external adoption is claimed.
Full Changelog: v0.5.0...v0.5.1