v0.1.54-dev.3
Pre-releaseNiro v0.1.54-dev.3
Summary
This prerelease exercises Niro Community Edition's new release-safety and
early-access distribution path before the same source commit is promoted to
stable v0.1.54.
Changes
- Added explicit Community Edition support, security-reporting, release-note,
and artifact-verification guidance. - Added a dedicated dev/RC workflow that requires an immutable version and a
full source commit associated with a pull request, reruns the complete test
suite, and publishes version-matched CLI and attack-tool sandbox artifacts. - Added retrying exact image-tag verification so a brief registry propagation
delay cannot strand a release after a successful multi-architecture push. - Made transactional draft lookup compatible with the GitHub CLI versions used
by hosted release runners. - Added
NIRO_CHANNEL=stable,NIRO_CHANNEL=dev, andNIRO_CHANNEL=rcto the
existing macOS, Linux, and Windows installer URLs. - Kept
NIRO_VERSIONas an exact stable, dev, or RC pin and made conflicting
or malformed selectors fail before download. - Hardened stable publication so prerelease tags cannot create a stable release
or move the imagelatesttag.
Security
The release pipeline rejects reused prerelease versions, verifies staged
release-asset digests, publishes only exact prerelease image tags, and prevents
dev or RC releases from moving stable latest. No developer agent, attacker
agent, attack-tool sandbox, CLI permission, or target-access behavior changed.
Compatibility and upgrade
There are no CLI, MCP, configuration, or runtime compatibility changes. The
default installer still selects stable. NIRO_VERSION=latest is no longer a
valid exact pin; omit selectors or use NIRO_CHANNEL=stable instead. Dev and
RC channels are public early-access artifacts intended for testing, and
niro upgrade continues to follow stable.
Known issues
checksums.txtcovers the platform archives but does not yet include
niro.mcpb.- Release artifacts do not yet include detached signatures, a public binary
provenance attestation, or an SBOM. - Windows users must rerun the installer to change versions or channels.
Build provenance: private source commit effd98122bed34ec767a8e86979203a9d7d1498c; channel dev; image sha256:e50098af24bd6b0e1670dc07b6db1f11a3857bea4443916d4b715a8edb491bbf.