Skip to content

v0.6.4

Latest

Choose a tag to compare

@aliasfoxkde aliasfoxkde released this 27 Sep 07:17
· 5 commits to main since this release
Immutable release. Only release title and notes can be modified.
fa5d032

Aegis v0.6.4 is a release-infrastructure cut. Every platform tarball now ships the license set (LICENSE + THIRD-PARTY-NOTICES.md, generated from Cargo.lock by cargo-about), a CI lane keeps those notices fresh, and two new drift checks pin the workspace version into the fuzz lockfile and keep release metadata honest. From this tag on, release builds are reproducible: two builds of the same tag must match on every asset digest except the attestation's built_at. Also fixed: scanning a repository no longer trips over Aegis's own state directory, and 25 dead documentation links were repaired.

Added

  • CI lanes for every declared-but-untested surface: the optional
    tree-sitter feature (compile + its dedicated tests), the MSRV
    (rust-version 1.88 — a bump now must change the job in the same
    commit), cargo-machete unused-dependency checks, and a lychee link
    check over README and docs (config in lychee.toml).
  • THIRD-PARTY-NOTICES.md, generated from Cargo.lock by the pinned
    cargo-about 0.9.2 (scripts/release/generate-notices.sh; its
    accepted-license list mirrors deny.toml). Every release tarball now
    ships it alongside aegis's own LICENSE, and a notices CI job
    regenerates and diffs the committed file so it cannot go stale
    behind a dependency bump.
  • The workspace repository metadata now points at the real public
    mirror (github.com/aliasfoxkde/aegis) instead of the nonexistent
    aegis/aegis.
  • Two CI drift checks close documented "keep in sync by hand" gaps:
    scripts/check-license-parity.sh (in the notices job) fails unless
    deny.toml's allowed licenses and about.toml's accepted list are
    identical, and scripts/check-fuzz-lock.sh (in the Dependency Policy
    job) fails when fuzz/Cargo.lock pins an aegis-core version other
    than the workspace's.

Fixed

  • The .aegis state directory is now a built-in exclusion, like
    node_modules, target, and .git. A baseline tracked at
    .aegis/baseline.json quotes the findings it documents, so any scan
    that included it re-flagged those contents under fingerprints naming
    the baseline file — which can never appear in the baseline itself —
    and every refresh compounded the artifact (one repository's baseline
    grew 2,721 → 13,143 entries, ~80% self-referential). The skip applies
    to directory scans, single-file scans, and --staged (which now
    consults ignore rules via the new Scanner::should_ignore), and it
    cannot be re-included by .aegisignore or ! rules. The baseline
    can now live at the conventional .aegis/baseline.json inside the
    scanned tree with no out-of-tree dance.
  • 25 dead reference: URLs shipped inside pattern definitions (and the
    generated pattern docs), including soxlaw.com, whose domain had been
    taken over and now redirects to unrelated sites; SOX patterns now
    point at the official govinfo.gov text. Found by the new link-check
    lane's first run (43 broken links).
  • Release tarballs are byte-reproducible across builders: build.sh now
    pins tar owner/group to 0:0, normalizes member modes, sets every
    member's mtime to the tag's commit time, and gzips with -n, so the
    digests no longer depend on which uid/gid or clock ran the build.
    Found by the v0.6.3 cross-check, where two independent builds of the
    same tag produced byte-identical binaries but differing tarball
    digests.
  • The release builder image is pinned to rust:1.88-bookworm (matching
    the runtime image) instead of floating rust:1-bookworm, and every
    GitHub Actions ref — including the @nightly toolchain ref and the
    bench cache/artifact actions — is now SHA-pinned.

Known issue (fixed forward): this tag's tarballs record an INT64_MIN member mtime instead of the tag's commit time — build.sh read %ct from the annotated tag, whose display is multi-line, and tar silently substituted a garbage date. Extraction is unaffected (GNU tar, busybox tar, python tarfile verified) and digests are stable. The fix (read from the commit + reject a non-numeric epoch) lands in #157.