Skip to content

Releases: danielcadev/secureflow

SecureFlow v0.3.0

Choose a tag to compare

@github-actions github-actions released this 02 Sep 23:59
333609d

SecureFlow v0.3.0

SecureFlow v0.3.0 is a measurement-focused milestone for the local-first evidence chain from deterministic analysis through contextual review, human validation, and reproducible evaluation. The platform remains limited to explicitly authorized code and does not autonomously establish that a candidate is a vulnerability.

Highlights

  • The workspace crates and citation metadata identify version 0.3.0; research use should cite the exact tag or commit.
  • The release path creates a deterministic source-only archive from an exact commit and a separate host-specific Linux bundle, each with an adjacent SHA-256 checksum.
  • The tag workflow builds, attests, and retains the exact archives without publication permission; a separate manually dispatched workflow rebinds the approved tag, successful build run and attempt, artifact ID and digest, checksums, attestations, and draft uploads before publication.
  • Release-note linting requires each prose paragraph and list item to occupy one physical Markdown source line so the GitHub release page uses the full content area consistently.
  • A fresh compact npm CLI run is bound to exact Engine and target commits, binary and report hashes, complete accounting, and three source-reviewed abstentions; it produced zero findings, which is explicitly not a clean verdict.
  • At the recorded 2026-08-30 checkpoint, Engine PR #5 was merged as ffc724d4b0aeb872542f5d683de15850ca0c6c38, hosted main CI passed, and GitHub recomputed all 63 historical fixture dependency alerts as fixed with zero dismissed; this does not establish vulnerability freedom. A separate post-merge npm artifact preserves the original run and records one configuration-mismatch attempt before the scanner-input-matched retained attempt, explicitly exceeding the original one-pass lane.
  • The offline Mitiquete inventory and 50,000/100,000-record synthetic catalog gate are retained as separate, claim-bounded evidence lanes.

Evidence and claim boundary

  • The npm CLI analysis consists of preserved bounded static observations with zero validated vulnerabilities and three unresolved abstentions; the post-merge generation records a one-pass protocol deviation and cannot support a performance comparison, complete-audit claim, or evidence that npm CLI is secure.
  • The Mitiquete workstream currently provides offline source inventory only; it does not include production HTTP requests, remote recon, exploitation, or validated vulnerability findings.
  • The prospective human-comparator study has not started, so v0.3.0 makes no claim of outperforming, replacing, or matching human researchers.
  • Any 50,000/100,000-record knowledge-base gate is synthetic capacity and integrity evidence only; it is not a count of validated vulnerabilities, a completeness claim, or evidence for one-million-record production readiness.
  • Scanner output, API candidates, catalog records, and model suggestions remain leads until evidence is reproduced and a human reviewer validates the security impact.

Publication authority

  • A human maintainer must approve the exact final commit, tag target, release text, locally generated archives and checksums, SBOM, and license-declaration evidence before creating tag v0.3.0.
  • The approved tag authorizes the pinned tag workflow to rebuild, attest, and retain the four release files, but not to publish them; the resulting build run, run attempt, artifact ID and digest, files, checksums, and attestations must be shown and approved before manually dispatching publication.
  • The manual publisher fails closed unless the selected tag, build run and attempt, commit, workflow, exact artifact ID and digest, four files, checksums, attestations, and staged draft uploads agree; automation cannot validate a vulnerability, expand target authorization, approve a future release, or establish superiority over human researchers.

Reproducibility boundary

The source-only archive is designed to be deterministic for one exact commit. The Linux bundle is intentionally host-specific; checksums and GitHub attestations establish artifact integrity and workflow provenance, not cross-host binary reproducibility, dependency trustworthiness, production safety, or research validity.

SecureFlow v0.2.0

Choose a tag to compare

@github-actions github-actions released this 30 Aug 15:23
582b233

SecureFlow v0.2.0

SecureFlow v0.2.0 strengthens the local-first evidence chain from deterministic
analysis through human review and reproducible evaluation. It remains an
engineering and research platform for explicitly authorized code; it does not
autonomously validate vulnerabilities or establish superiority over human
researchers.

Highlights

  • Adds the strict secureflow-run-v2 adapter boundary for compact and
    negotiated full Secure Engine evidence, while retaining the frozen v1 reader.
  • Preserves Engine calibration, deterministic abstentions, graph accounting,
    fingerprints, byte locations, and limitations without promoting scanner
    output to a human-validated finding.
  • Adds fail-closed, label-free prospective dataset, protocol-v2, and per-case
    submission contracts for a future blinded SecureFlow-assisted-human versus
    human-comparator study under equivalent capabilities.
  • Adds a local advisory catalog path for Rust, npm, GitHub Actions, Go, and
    PyPI, with quarantine, provenance, exact aliases, snapshots, deltas, backups,
    and modular core, malicious, and full bundles.
  • Adds the offline SecureFlow Web inventory and API-exposure research slice,
    including 400 synthetic paired API-risk scenarios. Remote recon and
    production HTTP transport remain out of scope for this release.
  • Hardens release evidence with pinned Rust 1.92.0 gates, a deterministic
    CycloneDX 1.5 SBOM, and checksum-bound Cargo dependency license declarations.

Evidence boundary

The repository contains synthetic development fixtures, local measurements,
and traceable advisory-ingestion evidence. These artifacts do not prove global
coverage, production safety, general effectiveness, a database of validated
vulnerabilities, or human replacement. Any task-bounded comparative claim
requires a separately preregistered holdout study, independent blinded
adjudication, uncertainty analysis, and publication of negative and mixed
results.

Release verification

The release archive includes source, schemas, documentation, build provenance,
the CycloneDX SBOM, dependency license declarations, internal SHA256SUMS, and
an external archive checksum. Verify the downloaded archive with its adjacent
.sha256 file before use.

SecureFlow v0.1.0

Choose a tag to compare

@github-actions github-actions released this 23 Aug 21:30

SecureFlow v0.1.0 is the first public local-first research and engineering release for authorized security analysis. It keeps deterministic evidence, contextual review, benchmark results, AI assistance, and human validation as separate, auditable layers.

Included

  • A nine-package Rust workspace with strict versioned JSON contracts.
  • An authorization-gated Secure Engine process adapter with fail-closed Linux sandboxing, bounded execution, and SHA-256 provenance.
  • Human-only finding adjudication, Markdown reporting, and an append-only reviewed-finding ledger.
  • A local SQLite/FTS5 advisory catalog with exact alias reconciliation, snapshots, incremental deltas, quarantine, backup/restore, and conservative package correlation.
  • Offline SecureFlow Web inventory for Next.js, OpenAPI, manifests, GraphQL, and tRPC, with JSON/SARIF output and a 24-case development corpus.
  • Separate Secure Skill and Secure Bench adapters, prospective-study contracts, and redacted offline Luna request preparation.

Verification

  • Rust and Cargo 1.92.0.
  • 138 automated tests passed.
  • 167 locked Rust dependencies audited against 1,225 RustSec advisories with no reported vulnerabilities at release time.
  • Deterministic CycloneDX SBOM included in the bundle.
  • Downloadable archive checksum and per-file SHA256SUMS included and verified by the release workflow.

Important boundaries

Findings remain candidates until a human validates reproducible evidence. This release does not claim production readiness, general vulnerability-detection effectiveness, superiority over humans or other tools, or a global vulnerability database. Remote recon and provider transport for AI remain disabled. The annotated v0.1.0 tag is intentionally documented as unsigned.

See the changelog, evidence and claim boundaries, and completion audit.

Full changelog: https://github.com/danielcadev/secureflow/commits/v0.1.0