Skip to content

v0.1.0-alpha.2

Pre-release
Pre-release

Choose a tag to compare

@github-actions github-actions released this 10 Sep 05:56
· 59 commits to main since this release
7cc359a

AuthZest v0.1.0-alpha.2

English

This prerelease updates the CLI-first, source-only FastAPI inventory. Python package version: 0.1.0a2; report schema: 1.2. Release commit: 7cc359acbb864ef6d31e3b536787857da4f7e09c.

Changes since alpha.1

  • Recognize supported FastAPI/APIRouter owners, literal prefixes, and repository-local router imports without importing or executing the scanned application.
  • Preserve distinct route registrations and source locations, structured diagnostics, bounded/partial analysis status, and opt-in scan --strict.
  • Record route-local Depends/Security declarations and inherited application/router/include context. dependencies stays local; effective_dependencies includes the supported inherited context.
  • Organize English documentation by topic, with mirrored Korean folders and separate Japanese/Russian README folders. See the documentation index.
  • Gate publishing on version/changelog consistency, fixture-report binary checks, SHA-256 checks, and downloaded-artifact smoke tests in fresh jobs on all three build platforms.

Artifacts and validation

Download the executable for your OS/architecture together with its matching .sha256 file. The provided binaries are Linux x64, macOS arm64, and Windows x64. Verify the checksum before enabling execution; follow the release guide.

Validation covers 451 Python tests, 14 documentation-checker tests, frontend checks/build, and four maintained source-only fixture scans through the built and relocated binaries. Separate CI jobs download and check each artifact without installing AuthZest's Python dependencies. The manual main validation is run 34442310332; the publishing run 34442837616 repeats these gates for the tag.

These are unsigned, unnotarized alpha executables. CI and relocated-copy checks do not establish clean installation or upgrades on consumer devices, nor compatibility with every OS version. No PyPI/npm package is published by this release.

Scope and next work

Dependency declarations are source evidence, not proof of authentication or authorization. Nested callable resolution, security verdicts, live Codex integration, patch application, and verification execution are not implemented. Successful scans are not security passes; unsupported source patterns can produce partial reports.

Next: #33 offline evidence/response contract, followed by #35 user-approved Codex defensive patch and verification workflow.

Read the full English changelog. Compare alpha.1 to alpha.2.

한국어

CLI 중심의 소스 전용 FastAPI 목록 분석을 갱신한 프리릴리스입니다. Python 패키지 버전은 0.1.0a2, 리포트 스키마는 1.2이며 릴리스 커밋은 7cc359acbb864ef6d31e3b536787857da4f7e09c입니다.

alpha.1 이후 변경

  • 스캔 대상 앱을 import하거나 실행하지 않고 지원 범위의 FastAPI/APIRouter 소유자, 리터럴 prefix, 저장소 내부 router import를 인식합니다.
  • 개별 라우트 등록과 원본 소스 위치, 구조화된 진단, bounded/partial 상태, 선택적 scan --strict를 제공합니다.
  • 직접 Depends/Security 선언과 app/router/include 상속 맥락을 기록합니다. dependencies는 직접 선언을 유지하고 effective_dependencies에 지원하는 상속 맥락을 함께 담습니다.
  • 영어 문서를 주제별로 정리하고 한국어는 같은 주제 구조로, 일본어·러시아어 README는 언어별 폴더로 분리했습니다. 한국어 문서 목차를 참고하세요.
  • 버전·변경 기록 일치, 실제 바이너리의 fixture 리포트, SHA-256, 세 빌드 플랫폼의 별도 다운로드 실행 검사가 통과해야 발행하도록 구성했습니다.

배포 파일과 검증

자신의 OS/아키텍처에 맞는 실행 파일과 대응하는 .sha256 파일을 함께 받으세요. 제공 파일은 Linux x64, macOS arm64, Windows x64입니다. 실행 권한을 부여하기 전에 체크섬을 확인하고 한국어 릴리스 가이드를 따르세요.

Python 테스트 451개, 문서 검사기 테스트 14개, frontend 검사·빌드, 직접 관리하는 소스 전용 fixture 4종의 실제 바이너리·복사본 스캔을 검증했습니다. 별도 CI 작업은 AuthZest의 Python 의존성을 설치하지 않고 배포 파일을 내려받아 검사합니다. main 사전 검증은 실행 34442310332이며, 발행 실행 34442837616에서도 태그에 대해 같은 검증을 반복합니다.

서명·공증되지 않은 알파 실행 파일입니다. CI와 복사본 실행 검사는 일반 사용자 기기의 깨끗한 설치·업그레이드 또는 모든 OS 버전의 호환성을 보장하지 않습니다. 이번 릴리스는 PyPI/npm 패키지를 발행하지 않습니다.

범위와 다음 작업

의존성 선언은 소스 근거이며 인증·인가가 안전하다는 증명이 아닙니다. 중첩 함수 해석, 취약점 판정, 실제 Codex 연동, 패치 적용, 검증 실행은 아직 구현하지 않았습니다. 성공 종료는 보안 통과가 아니며 미지원 구문은 부분 분석으로 남을 수 있습니다.

다음은 #33 오프라인 근거·응답 계약, 이후 #35 사용자 승인형 Codex 방어적 수정·검증 흐름입니다.

전체 한국어 변경 기록 · alpha.1과 alpha.2 비교

Merged pull requests / 병합 PR

The original automatically generated PR history is retained below. / 자동 생성된 원래 PR 이력을 아래에 보존합니다.

What's Changed

  • fix(release): make publishing portable by @casing1 in #16
  • docs(release): record first public preview by @casing1 in #18
  • fix(parser): recognize FastAPI route owners by @casing1 in #20
  • chore(ci): require CodeQL before merging by @casing1 in #23
  • feat(parser): compose same-file router prefixes by @casing1 in #24
  • feat(parser): resolve repository-local router imports by @casing1 in #26
  • docs: align CLI-first roadmap and bilingual project guides by @casing1 in #30
  • fix: strengthen evidence reliability and seven-week delivery plan by @casing1 in #34
  • feat: add versioned report and source registration evidence (#32) by @casing1 in #36
  • feat: collect route-local dependency evidence (#28) by @casing1 in #37
  • feat: propagate inherited dependency evidence per registration by @casing1 in #38
  • build: prepare alpha.2 artifacts and organize docs by @casing1 in #40

Full Changelog: v0.1.0-alpha.1...v0.1.0-alpha.2