v0.1.0-alpha.3
Pre-releaseAuthZest 0.1.0-alpha.3
An alpha checkpoint for the bounded, user-approved Codex fixture workflow—not a general vulnerability scanner or automatic repair tool.
English
- Adds offline AI review/proposal contracts, explicit sharing and exact-diff decisions, and application/restoration in a fresh owned-fixture copy. Existing checkouts are not edited.
- Adds
codex-fixturewith the version-pinned Codex App Server 0.153.0 adapter. Install and authenticate Codex separately; ordinaryscanremains offline and requires no account. Source sharing can consume Codex usage. - Keeps the separately approved AST configuration check as the default.
--runtime-checkselects—but does not approve—a different fixed check: execute only the byte-identical bundled fixture, observeapp.debug, and check in-memory ASGIGET /healthfor HTTP 200 and{"status":"ok"}. Verification and restoration still require separate exact confirmations. - Records scoped results, source/checker identities, dependency observations and conflict-aware restoration. Scan report schema stays
1.2; runtime-session journal schema1.2is a separate contract.
Limits: the only supported change is the maintained fixture's debug=True → debug=False. No arbitrary repository execution, generated test/command execution, exploit reproduction, or automatic dependency installation. The fixture workflow requires supported POSIX operations; Windows scan support remains, but the fixture runtime workflow is unsupported. The fixed worker keeps a 5-second startup/I/O deadline plus separate 1-second cleanup bound. Process separation is not an OS/network sandbox. Codex transport recovery is not a hard token, provider-attempt, or monetary cap.
One earlier, explicitly authorized source-CLI live run completed draft/apply/runtime-check/restore on ce2834c; the assistant entered the exact phrases, not an independent human reviewer. Native packaging checks and fake-transport tests are separate offline evidence, not additional live-model validation. Neither proves authorization correctness or a verified security fix; broader #35 acceptance remains open.
Standalone executables are unsigned/not notarized, with matching SHA-256 manifests. CI and relocation smoke do not establish clean consumer installation or upgrades. This release does not publish to PyPI or npm.
한국어
일반 취약점 스캐너나 자동 수정 완성본이 아닌, 범위를 제한한 사용자 승인형 Codex fixture 흐름의 알파 중간 버전입니다.
- 오프라인 AI 검토·제안 계약, 명시적 공유·정확한 diff 결정, 새 소유 fixture 복사본의 적용·복구를 추가합니다. 기존 checkout은 수정하지 않습니다.
codex-fixture는 Codex App Server 0.153.0을 고정 사용합니다. Codex는 별도로 설치·로그인해야 하며 공유 시 사용량이 소비될 수 있습니다. 일반scan은 계정 없이 오프라인으로 동작합니다.- 별도 승인 AST 설정 검사가 기본값입니다.
--runtime-check는 실행 승인이 아니라 다른 고정 검사 계획의 선택입니다. 바이트가 동일한 번들 fixture만 실행하여app.debug와 메모리 내 ASGIGET /health의 HTTP 200·{"status":"ok"}를 확인합니다. 검사·복구는 각각 정확한 확인 문구가 필요합니다. - 범위를 명시한 결과, 소스·검사 식별값, 의존성 관찰값과 충돌을 고려한 복구를 기록합니다. 스캔 리포트 스키마는
1.2를 유지하며 런타임 세션 journal1.2와는 별개입니다.
지원 변경은 관리하는 fixture의 debug=True → debug=False뿐입니다. 임의 저장소·생성 테스트/명령 실행, 악용 재현, 의존성 자동 설치는 지원하지 않습니다. fixture 흐름은 지원 POSIX 연산이 필요하며 Windows 스캔은 유지하지만 fixture 런타임 흐름은 지원하지 않습니다. worker의 시작·입출력 5초와 별도 정리 1초 제한을 유지합니다. 프로세스 분리는 OS/네트워크 sandbox가 아니며 Codex 복구 알림 제한은 토큰·제공자 시도·금액 상한이 아닙니다.
앞서 별도 승인받은 ce2834c 소스 CLI 실제 연동에서 초안·적용·런타임 검사·복구가 한 번 완료됐습니다. 확인 문구는 assistant가 입력했으며 독립적인 인간 검토 증거가 아닙니다. native 패키징·가짜 transport 검사는 별도의 오프라인 근거이지 추가 실제 모델 검증이 아닙니다. 인가 정확성이나 보안 수정 효과를 입증하지 않으며 더 넓은 #35 완료 조건은 남아 있습니다.
독립 실행 파일은 서명·공증되지 않았으며 대응 SHA-256 파일을 제공합니다. CI·이동 복사본 smoke는 새 소비자 환경 설치나 업그레이드 검증을 대신하지 않습니다. PyPI·npm 발행은 하지 않습니다.
English changelog · 한국어 변경 이력 · Runtime scope and evidence
Verification / 검증
Published 2026-09-12 from 99be6f5614d283befa2a421b64f84958b680f92f (package 0.1.0a3). Main candidate and tag publishing run passed, including 1,548 Python tests and three-platform fresh artifact checks. All six public files were downloaded again, passed checksums, and matched tag artifacts byte-for-byte. The public macOS binary also passed local relocated scan (7) and fixed runtime (1) checks. Linux/Windows execution evidence is matching-platform CI; Windows runtime checks assert unsupported behavior.
2026-09-12 위 커밋에서 패키지 0.1.0a3로 발행했습니다. main 후보·태그 워크플로, Python 테스트 1,548개와 세 플랫폼 새 다운로드 검사를 통과했습니다. 공개 파일 6개를 다시 내려받아 체크섬과 태그 산출물의 바이트 일치를 확인했고, 공개 macOS 파일은 로컬 이동 scan 7개와 고정 runtime 1개도 통과했습니다. Linux/Windows 실행 근거는 동일 OS CI이며 Windows 런타임 검사는 미지원 동작 확인입니다.
What's Changed
- docs: align guides with published alpha.2 by @casing1 in #42
- docs: require issue and PR tracking metadata by @casing1 in #44
- feat: implement offline AI evidence contracts and evaluation by @casing1 in #45
- feat: add offline proposal-bound decisions by @casing1 in #47
- feat: apply approved changes to owned-fixture copies by @casing1 in #49
- feat(codex): connect the opt-in owned-fixture workflow by @casing1 in #51
- feat(runner): add approved fixture configuration verification by @casing1 in #53
- feat(runner): add approved owned-fixture runtime verification by @casing1 in #55
- chore(release): prepare v0.1.0-alpha.3 by @casing1 in #57
Full Changelog: v0.1.0-alpha.2...v0.1.0-alpha.3