Skip to content

0.1.1

Choose a tag to compare

@b10x-bot b10x-bot released this 10 Sep 19:09
· 4 commits to main since this release

Shared checks now require the exact organization bot or GitHub Actions author on every commit after the trusted adoption baseline. Admission runs before scanning and signed-receipt reuse, and covers intermediate commits and merged side branches. Mailmaps and other bot names cannot authorize a commit.

Local commit hooks require exact organization-bot author and committer. The new commit-authorship result and Gates version invalidate earlier receipts. A valid current receipt still reuses common checks with zero scanner invocations.

Validation includes the full Rust gate, real-scanner regressions, signed-evidence tests and mutation tests that fail when either identity guard is removed. The static Linux binary is built with source-path remapping and scanned for private provenance and secrets.