Aegis v0.6.4 is a release-infrastructure cut. Every platform tarball now ships the license set (LICENSE + THIRD-PARTY-NOTICES.md, generated from Cargo.lock by cargo-about), a CI lane keeps those notices fresh, and two new drift checks pin the workspace version into the fuzz lockfile and keep release metadata honest. From this tag on, release builds are reproducible: two builds of the same tag must match on every asset digest except the attestation's built_at. Also fixed: scanning a repository no longer trips over Aegis's own state directory, and 25 dead documentation links were repaired.
Added
- CI lanes for every declared-but-untested surface: the optional
tree-sitterfeature (compile + its dedicated tests), the MSRV
(rust-version 1.88 — a bump now must change the job in the same
commit), cargo-machete unused-dependency checks, and a lychee link
check over README and docs (config inlychee.toml). THIRD-PARTY-NOTICES.md, generated fromCargo.lockby the pinned
cargo-about 0.9.2 (scripts/release/generate-notices.sh; its
accepted-license list mirrorsdeny.toml). Every release tarball now
ships it alongside aegis's ownLICENSE, and anoticesCI job
regenerates and diffs the committed file so it cannot go stale
behind a dependency bump.- The workspace
repositorymetadata now points at the real public
mirror (github.com/aliasfoxkde/aegis) instead of the nonexistent
aegis/aegis. - Two CI drift checks close documented "keep in sync by hand" gaps:
scripts/check-license-parity.sh(in thenoticesjob) fails unless
deny.toml's allowed licenses andabout.toml's accepted list are
identical, andscripts/check-fuzz-lock.sh(in the Dependency Policy
job) fails whenfuzz/Cargo.lockpins anaegis-coreversion other
than the workspace's.
Fixed
- The
.aegisstate directory is now a built-in exclusion, like
node_modules,target, and.git. A baseline tracked at
.aegis/baseline.jsonquotes the findings it documents, so any scan
that included it re-flagged those contents under fingerprints naming
the baseline file — which can never appear in the baseline itself —
and every refresh compounded the artifact (one repository's baseline
grew 2,721 → 13,143 entries, ~80% self-referential). The skip applies
to directory scans, single-file scans, and--staged(which now
consults ignore rules via the newScanner::should_ignore), and it
cannot be re-included by.aegisignoreor!rules. The baseline
can now live at the conventional.aegis/baseline.jsoninside the
scanned tree with no out-of-tree dance. - 25 dead
reference:URLs shipped inside pattern definitions (and the
generated pattern docs), includingsoxlaw.com, whose domain had been
taken over and now redirects to unrelated sites; SOX patterns now
point at the official govinfo.gov text. Found by the new link-check
lane's first run (43 broken links). - Release tarballs are byte-reproducible across builders:
build.shnow
pins tar owner/group to0:0, normalizes member modes, sets every
member's mtime to the tag's commit time, and gzips with-n, so the
digests no longer depend on which uid/gid or clock ran the build.
Found by the v0.6.3 cross-check, where two independent builds of the
same tag produced byte-identical binaries but differing tarball
digests. - The release builder image is pinned to
rust:1.88-bookworm(matching
the runtime image) instead of floatingrust:1-bookworm, and every
GitHub Actions ref — including the@nightlytoolchain ref and the
bench cache/artifact actions — is now SHA-pinned.
Known issue (fixed forward): this tag's tarballs record an
INT64_MINmember mtime instead of the tag's commit time —build.shread%ctfrom the annotated tag, whose display is multi-line, and tar silently substituted a garbage date. Extraction is unaffected (GNU tar, busybox tar, python tarfile verified) and digests are stable. The fix (read from the commit + reject a non-numeric epoch) lands in #157.