SecureFlow v0.2.0
SecureFlow v0.2.0
SecureFlow v0.2.0 strengthens the local-first evidence chain from deterministic
analysis through human review and reproducible evaluation. It remains an
engineering and research platform for explicitly authorized code; it does not
autonomously validate vulnerabilities or establish superiority over human
researchers.
Highlights
- Adds the strict
secureflow-run-v2adapter boundary for compact and
negotiated full Secure Engine evidence, while retaining the frozen v1 reader. - Preserves Engine calibration, deterministic abstentions, graph accounting,
fingerprints, byte locations, and limitations without promoting scanner
output to a human-validated finding. - Adds fail-closed, label-free prospective dataset, protocol-v2, and per-case
submission contracts for a future blinded SecureFlow-assisted-human versus
human-comparator study under equivalent capabilities. - Adds a local advisory catalog path for Rust, npm, GitHub Actions, Go, and
PyPI, with quarantine, provenance, exact aliases, snapshots, deltas, backups,
and modularcore,malicious, andfullbundles. - Adds the offline SecureFlow Web inventory and API-exposure research slice,
including 400 synthetic paired API-risk scenarios. Remote recon and
production HTTP transport remain out of scope for this release. - Hardens release evidence with pinned Rust 1.92.0 gates, a deterministic
CycloneDX 1.5 SBOM, and checksum-bound Cargo dependency license declarations.
Evidence boundary
The repository contains synthetic development fixtures, local measurements,
and traceable advisory-ingestion evidence. These artifacts do not prove global
coverage, production safety, general effectiveness, a database of validated
vulnerabilities, or human replacement. Any task-bounded comparative claim
requires a separately preregistered holdout study, independent blinded
adjudication, uncertainty analysis, and publication of negative and mixed
results.
Release verification
The release archive includes source, schemas, documentation, build provenance,
the CycloneDX SBOM, dependency license declarations, internal SHA256SUMS, and
an external archive checksum. Verify the downloaded archive with its adjacent
.sha256 file before use.