Skip to content

v0.4.1

Choose a tag to compare

@github-actions github-actions released this 23 Sep 20:21
· 17 commits to main since this release
4de9c56

Kranz v0.4.1 delivers the ACP operational fixes and dependency maintenance merged after v0.4.0.

  • An expired ACP permission request closes its own response channel without cancelling sibling candidates.
  • Fixed-profile egress refusals explain a mission grant mismatch without printing destinations.
  • Documentation clarifies active-batch cancellation, readable toolchain caches and relay reachability from the default Docker bridge.
  • Dashboard and experimental Even G2 dependencies and CodeQL action pins are updated; the embedded dashboard is rebuilt.

Upgrade note: filtered Docker egress requires a recognized stable Docker daemon version of at least 25.0.5. Older, prerelease and unrecognized vendor version strings fail closed. This is a conservative DNS prerequisite; existing qualified host, profile and adapter limits still apply.

No event/configuration schema changes or new terminal capability are included. The human review pilot remains separate; this release makes no review-efficiency claim. The Tauri shell remains build-checked, with no supported desktop bundle attached.

Install from crates.io with cargo install kranz --version 0.4.1 --locked, or use a platform archive below. Archives include license notices; SHA256SUMS, build-provenance attestations and the SPDX SBOM accompany this release.

Verification completed on 4de9c56c9e1c0e68813b79548ff0a6bc21db4e59:

  • Protected correction PR #81, main CI and all main security checks passed. The local workspace suite passed 3,116 tests, with 0 failures and 10 ignored; the explicit container egress and cache proofs also passed.
  • Release rehearsal and its five native archive checks passed before tagging.
  • Tagged release builds and their five native archive checks passed on Linux x86-64, macOS Intel/Apple Silicon and Windows x86-64/ARM64. Published archive bytes match those checked artifacts; archive, checksum-manifest and SBOM attestations were verified.
  • All four crates were dry-run, inspected and published bottom-up with matching version, source commit and checksums. An isolated crates.io installation on Apple Silicon verified version, help and embedded licenses outside a source checkout. The tagged archive also served its embedded dashboard and matching notices.

The first main candidate was held before tagging after a Windows test fixture failure. PR #81 serializes that fixture with other tests that change process-wide credential paths; production containment policy is unchanged. A separate local container-helper timeout is retained in the release evidence alongside its owner-label reconciliation and the subsequent successful full-suite run.