Skip to content

Releases: aeron100/trove

2.3.0 — Public distribution

Choose a tag to compare

@aeron100 aeron100 released this 30 Jul 23:04

The public-distribution release: the same workflow, now packaged to hand to a
stranger on the internet — a notarized macOS build that opens with no
warnings, an End User License Agreement, and the formal accessibility report
brought to full 4.1.3 conformance.

Download

Platform File
macOS (Apple Silicon) Trove-2.3.0.dmg Signed with a Developer ID and notarized by Apple — open and drag onto Applications. No warning, no right-click dance.
Windows (64-bit) Trove-2.3.0-Setup.exe Installs for your user, no administrator needed. Not code-signed: SmartScreen shows "Windows protected your PC" — choose More info → Run anyway.

Use of the installers is governed by the End User License Agreement.

Coming from Certificate Award Evaluator (1.x)? Trove installs as a new
product — uninstall Certificate Award Evaluator separately. Project files
saved by 1.x are refused rather than misread; re-import the student file into
a new project.

Coming from Trove 2.2.0? Projects open unchanged, and re-activating the
same catalog keeps its ruleset_id — parsing is untouched in this release.

Trust on macOS

The application bundle and the disk image are both code-signed with a
Developer ID certificate and notarized by Apple, with the notarization
ticket stapled to each — so Gatekeeper accepts the download even offline.
Hardened Runtime is enabled; the two entitlements it needs are documented,
with reasons, in the source tree. Windows signing remains an open item; the
SmartScreen step is documented in the user guide.

Status changes are announced (WCAG 4.1.3)

The four passive status lines — import row count, catalog summary,
validation summary, and evaluation status — now post polite accessibility
announcements on every change, so a screen-reader user hears "Evaluating…"
or an import summary without moving focus. The formal conformance report
(VPAT 2.4) is re-stamped for 2.3.0 with 4.1.3 at Supports, and both the
behavior and the census of which lines must announce are test-enforced.

Documentation for reviewers

This is the first release to ship with the compliance set publicly:
the privacy statement
(local-only processing, no telemetry, log-leak caps — each claim tied to an
enforced guarantee) and the
VPAT
(WCAG 2.1 AA, criterion by criterion, with the census probe checked into the
build so the figures cannot drift from the code).

Cleanup

Two columns the catalog pipeline carried but never read are gone. Projects
saved while they existed still open — pinned by a regression test — and the
catalog content digest never included them, so no ruleset_id changes.


1,092 automated tests (1,088 at 2.2.0), type-checked strict,
dependency-audited, SBOM published as a build artifact.

Checksums (SHA-256)

8e3f9016ede3c9f750b9b62a2123d095e158ae219f5ee2652f29917c46058605  Trove-2.3.0-Setup.exe
af4a1c19edc075688a3f2074545e2a7cde240adbe2658f6cda7a5acb471a9355  Trove-2.3.0.dmg