Skip to content

0.20.0 - 2026-07-22

Latest

Choose a tag to compare

@github-actions github-actions released this 22 Jul 17:34

Release Notes

Added

  • Qualified the final v0.20.0 product tree against the checksum-verified published
    v0.19.0 binary (#943). The checked release evidence
    binds all-120 default/semantic/no-pack and frozen base-view query gates, 30-replay
    cache and watch campaigns, and complete same-commit Soundness Lab nightly/deep
    evidence; every blocking gate passes with no unresolved runtime signal, false
    merge, canon violation, cache-history mismatch, or material performance regression.
  • Made --cache-dir transactional, corruption-safe, concurrent, compact, and bounded (#876).
    Immutable checksummed records now commit through one complete generation pointer; interrupted
    or concurrent writers cannot expose partial state, corrupt/oversized entries recompute, and
    a 5 GiB default budget evicts performance data without changing results. New stable
    nose cache status|prune|clear commands and --cache-max-bytes / [query].cache-max-bytes
    expose storage control without deleting unrelated files.
  • Added local nose.semantic-pack-lock.v1 project authorization for typed v1
    semantic packs. nose semantic-pack lock/status content-pin manifest identity,
    semantic digest, selected rows/channels, dependency files, and optional receipts;
    query validates configured locks before analysis, rejects stale/escaped/conflicting
    decisions independent of load order, and can admit dependency-backed near rows or
    receipt-backed, separately attributed external-claim exact collection factories.
    v0 and unlocked v1 remain metadata-only. External packs are local, explicit opt-ins,
    disabled by default, and data-only: nose adds no provider-code execution, registry,
    network resolver, installer, or parser plugin. A shipped Vavr 0.9.x List.of
    reference pack demonstrates the complete lock, receipt, attribution, and rollback
    workflow without claiming builtin certification.
  • Closed the #847 divergent-edit precision-first cycle without overstating readiness.
    Direct changed-to-skipped targets, bounded semantic-change evidence, and pair-local
    variant signals now give users more precise review context, while one internal policy
    decision keeps human, JSON, SARIF, and exit status aligned. No admissible v3 policy had
    development support, so the blind population remains sealed and v2 stays opt-in. The
    official-v0.19.0 closeout is output-compatible after removing reviewed additive evidence
    but misses the runtime gate at +8.74% control-adjusted; default-on enforcement is not
    recommended.
  • Added fail-closed Soundness Lab PR, nightly, deep-campaign, and 0.20 release
    gates. Nightly evidence covers every pinned repository exactly once, retains artifacts on
    failure, binds shards to one source commit and binary, fully diffs non-blocking advisory
    disagreements against the published v0.19.0 binary, and rejects missing artifacts, changed
    pins, timeouts, false merges, canon violations, coverage regressions, unregistered claims,
    unguarded Tier-A cells, and unattributed exclusions. Deterministic shard evidence is separated
    from diagnostic logs, release failures retain a summary, and the release commit's product tree
    must match the checked binding.
  • Kept mixed-exit fragments distinct from whole functions in exact fingerprints. A conditional
    fragment that may return or throw but can also fall through no longer collides with a whole
    function whose completion has different enclosing-control behavior; the Soundness Lab found
    and reproduced this boundary across pinned repositories. The audit oracle now distinguishes
    explicit throw from ordinary evaluation errors independently of the product classifier, and
    cache schema v12 prevents pre-fix feature entries from being reused.
  • Committed the #846 held-out review inputs without publishing their source. The
    official v0.19.0 replay reproduces 54 queries, 1,564 candidate commitments, and the
    exact 214-family sealed selection, then creates three persona-specific packets outside
    Git. Only secret-nonce whole-packet hashes are public before voting. Three independent
    reviews rejected two earlier drafts—the second was still source-fingerprintable
    214/214—so the accepted contract explicitly promises procedural product-metadata
    blindness, not identity hiding from a reviewer who searches public source. All three
    votes must freeze together and blind-ID arbitration must freeze before reveal.
  • Closed the #845 dev-only residual-ranking experiment with a fully judged no-go. Three
    independent blind reviewers labeled all 219 frozen frontier families; exact tuple
    agreement covered 129 and an independent arbiter resolved all 90 worthiness-or-reason
    disagreements. The exact-key-only overlay gives every one of 46 formulas 100% top-10
    truth coverage on every repository. Current is 387/658 (58.81%); the best
    coverage-guarded formula is 449/658 (68.24%), 12 hits short of 70%, and leaves C at
    44/90 (48.89%), one hit below the language floor. Repository-CV out-of-fold is
    416/658 (63.22%). No proposal or signal is retained, held-out stays closed, and product
    code, ranking, surfaces, family membership, and worthy recall remain unchanged.
  • Froze the judgment-blind #845 residual-ranking calibration and complete dev top-up
    frontier. The full 29,348-family universe evaluates 46 unique transparent formulas,
    rejects ambiguous overlap labels, uses exact reported-position gates and deterministic
    total orders, and remains explicitly evidence-incomplete rather than treating missing
    labels as product failures. A non-adaptive 219-family panel packet covers every
    unresolved top-10 position of every formula and therefore every repository CV fold.
    The packet contains no judgments; held-out remains closed and product behavior is
    unchanged until the separately committed panel result decides go or no-go.
  • Recorded the checked #844 proof/actionability no-go. Three independent source reviews
    agree that removing the proven-channel protection reaches only 60% non-action precision
    on its direct frozen boundary (0% for trivial, 75% for shallow-extraction), while
    the broader exact/subdag cohort reaches 42.19% and contains 37 worthy helper,
    parameterization, data-table, and base-extraction hard negatives. Each reviewer's
    five-judgment record is source-packet bound, and future admission requires a 90% point
    precision and one-sided 95% Wilson lower-bound gate. CI reconstructs the no-go and zero
    product drift from the #841 taxonomy, normalized executable-code identity, and the
    checked #843 behavior, quality, and official-v0.19.0 performance evidence.
  • Classified strict declaration-only type contracts as reason-coded declaration output
    (#843). The all-member rule consumes existing language-neutral origin facets for Java,
    TypeScript, Rust, and Swift; incomplete, narrowed, runtime/data/implementation,
    default-body, extension, enum, schema, and unknown evidence stays fail-open. All five
    frozen positives move, eight worthy hard negatives stay default, 54,754 dev families
    and their order remain stable, and full-universe worthy recall remains 2716/2849 with
    zero regressions. Among currently labeled default positions, interim dev P@10 rises
    from 58.05% to 59.04% while the worthy-hit count stays 382; replacement-label coverage
    is 98.33% for #845/#846 to close before a final precision claim. Existing frontend
    facets now truthfully mark Java field initializers, Rust defaults/macros/attributes,
    and parser-recovered Swift bodies. The official-v0.19.0 all-dev result is +0.42% raw /
    +0.35% adjusted; the exact 66 -> 25 -> 6 -> 2 repository escalation across
    3 -> 9 -> 21 -> 40 iterations ends -0.69% adjusted with no material regression.
  • Classified source-coherent Jazzy documentation as reason-coded generated output (#842).
    Every HTML member must carry both a Jazzy asset and an Apple/Dash symbol anchor within
    a bounded 64 KiB head; missing, partial, unreadable, and hand-written lookalikes stay on
    their ranked surface. All 30 frozen head/deep positives move to generated, the three
    worthy HTML hard negatives remain default, and all top=0 preserves ordered family
    IDs and every non-surface field. Default-only slices also remain visible when a generated
    primary leaves that view, including equivalent and negated surface filters. Only
    Alamofire changes across 66 dev repositories. The official-v0.19.0 all-dev comparison
    is -1.26% raw / -1.72% control-adjusted; the exact 3 -> 9 -> 21 -> 40 focused chain
    finishes -1.02% adjusted, with no material aggregate, repository, or stage regression.
    CI reconstructs cohort/corpus summaries from bound per-repository hashes and recomputes
    every performance escalation edge from raw reports.
  • Added the complete #841 dev default-head failure taxonomy and bounded-lever contract.
    The published v0.19.0 output is re-bound at all 658 positions to full raw families,
    source bounds, truth and disjoint mechanical buckets, origin/generated/ranking/path
    cross-tabs, and rejected heuristics. Three independent source audits each confirmed
    all 20 Jazzy-generated and four strict declaration-only deep positives as
    non-actionable, while worthy HTML, incomplete/missing origin, reusable-body, and 35
    proof-backed refactorings remain hash-bound hard negatives. Generated provenance and
    strict declaration-only type contracts clear the 90% gate for #842/#843; blanket
    exact/subdag exemption removal is frozen as a #844 no-go. Held-out source remains
    closed, and CI reconstructs the compact decision overlay from its checked dev-only
    label projection, 8.1 MB core, standalone truth-free audit packets, and all three raw
    vote files. Exact nested schemas and #840/live source bindings replay raw-derived
    facets, predicates, buckets, frozen deep/audit cohorts, bounded generator evidence,
    and audit-key uniqueness rather than trusting dependent hashes. Frozen v5-dev and
    generated-evidence/packet-set commitments, exact command provenance, and a
    source-locked one-time vote rebind reject consistently rehashed substitutions and
    synthetic prior judgments while keeping ordinary CI independent of ignored corpus
    checkouts.
  • Added the split-safe v7 default-head label runway (#840): every v6-unmatched
    dev top-10 family plus deterministic rank 11–30 repository samples now have
    independent three-persona votes and explicit arbitration, while a pre-hashed
    held-out selection exposes neither source nor judgment. The precision-only
    overlay raises dev label coverage from 66.41% to 100%, preserves byte-frozen
    v5/v6 and worthy recall, and reveals the complete 58.05% dev default-head
    baseline for the bounded #841 failure taxonomy. Exact held-out schemas reject
    unknown or value-encoded source/judgment data and held-out overlays. Repository
    identity, commits, and match counts are bound to the hashed corpus and candidate
    commitments. The exact manifest binds its byte and family projection to frozen
    v6, CI replays the complete raw-vote-to-component evidence chain and verifies
    the evaluation sidecar, and split-local bootstrap streams keep unchanged
    held-out intervals independent from dev label growth.
  • Split the product-quality evaluator's user-facing default-head precision from
    full-universe worthy recall (#839). The published v0.19.0 binary now anchors a
    hash-identified 120-repository baseline; executable default-list ID-and-order
    and complete bare-dashboard top-five/summary parity, uncached measurement,
    per-surface counts, explicit
    historical all compatibility mode, and deterministic reports prevent future
    ranking work from measuring the wrong query surface.

Install nose-cli 0.20.0

Install prebuilt binaries via shell script

curl --proto '=https' --tlsv1.2 -LsSf https://github.com/corca-ai/nose/releases/download/v0.20.0/nose-cli-installer.sh | sh

Install prebuilt binaries via Homebrew

brew install corca-ai/tap/nose

Download nose-cli 0.20.0

File Platform Checksum
nose-cli-aarch64-apple-darwin.tar.xz Apple Silicon macOS checksum
nose-cli-x86_64-apple-darwin.tar.xz Intel macOS checksum
nose-cli-aarch64-unknown-linux-gnu.tar.xz ARM64 Linux checksum
nose-cli-x86_64-unknown-linux-gnu.tar.xz x64 Linux checksum