Kranz v0.4.0
Kranz v0.4.0 adds evidence views that help operators review a mission before approving the next step.
- Human review packets bring approved scope, changes, check freshness, findings, exceptions and pending decisions together in the CLI, dashboard, authenticated API and evidence exports. Checks against an earlier edit remain visible as historical evidence.
- Baseline/candidate observations provide opt-in, source-bound comparative evidence using the existing contained control runner. They remain advisory and do not replace required checks or human approval.
- Recorded outcome reasons distinguish authentication blocks, checker findings and human boundaries. Ambiguous failures remain unknown, and activity counts preserve repair history.
- Sgian coordination attributes worker activity to a per-run credential. Control calls use bounded process-tree supervision and a restricted environment; dropped worker futures attempt revocation, and the shared scrubber removes Sgian client credentials from output and evidence.
The release also prepares a bounded review-effort pilot. Its cases and human measurements remain future work; no review-efficiency improvement has been measured. Sgian credential revocation is best-effort: engine death, ambiguous issuance or failed cleanup may require operator reconciliation. This release adds no new live-provider qualification or ACP filesystem/terminal provider.
Install the CLI from the matching platform archive below, or use cargo install kranz --version 0.4.0 --locked. The Tauri shell is build-checked and is not distributed as a desktop release artifact.
Documentation: review packets, baseline/candidate observations, outcome reasons, Sgian coordination.
Release evidence for commit fccdef95334f82f4595005407e2ba7caeacc824c:
- Main CI, the nonpublishing rehearsal and the tagged release workflow passed. The local full workspace suite passed 3,110 tests with 0 failures and 10 ignored.
- Native checks of the tagged archives passed on Linux x86-64, macOS ARM64/x86-64 and Windows ARM64/x86-64. Published archives match those tested artifacts byte for byte. All seven assets have verified provenance, including the checksum manifest and SPDX SBOM.
- The tagged macOS ARM archive served its embedded dashboard and matching license notices from an isolated temporary setup.
- kranz-engine, kranz-server, kranz-slack and kranz are published. Each registry archive matches its inspected pre-upload package, records the release commit and carries the 0.4.0 README and MIT license.
- A crates.io installation on macOS ARM64, outside the source checkout with an empty Cargo cache and isolated home, passed version, help and license checks. Installed binary SHA-256:
227708edfe816b51dc214d699409865d00b470a6779a87fa40c39c4e8ceccd98.