RedDock v0.8.0 completes Phase 7 — Advanced / Lab.
Highlights:
- Separately gated, short-lived per-Dockyard authorization for one fixed extended TCP service-discovery profile
- Append-only lab policy audit history carried into technical reports and DockPacks
- Bounded, data-only detector manifests with strict startup validation and content-addressed provenance
- Qwen3.5 4B through Ollama documented as the default local-AI path, with compatible providers remaining configurable
- Refreshed v0.8.0 Lab and detector-provenance screenshots
Security:
- Exact single-host enforcement at request, execution, and adapter boundaries
- Arbitrary Host headers rejected for the loopback application
- Detection snapshots fail closed before reconciliation when bounded state would be incomplete
- Declarative plugin output stops at the central rejection threshold
- Full repository security review completed with the validated findings remediated
Verification:
- GitHub CI backend, frontend, dependency audit, production build, and container smoke jobs passed
- 346 backend tests passed locally
- 28 frontend tests passed locally
- Default and lab-enabled production-image smoke tests passed end to end
See CHANGELOG.md, SECURITY.md, and ROADMAP.md for the complete release record.