Skip to content

SecureFlow v0.2.0

Choose a tag to compare

@github-actions github-actions released this 30 Aug 15:23
· 4 commits to main since this release
582b233

SecureFlow v0.2.0

SecureFlow v0.2.0 strengthens the local-first evidence chain from deterministic
analysis through human review and reproducible evaluation. It remains an
engineering and research platform for explicitly authorized code; it does not
autonomously validate vulnerabilities or establish superiority over human
researchers.

Highlights

  • Adds the strict secureflow-run-v2 adapter boundary for compact and
    negotiated full Secure Engine evidence, while retaining the frozen v1 reader.
  • Preserves Engine calibration, deterministic abstentions, graph accounting,
    fingerprints, byte locations, and limitations without promoting scanner
    output to a human-validated finding.
  • Adds fail-closed, label-free prospective dataset, protocol-v2, and per-case
    submission contracts for a future blinded SecureFlow-assisted-human versus
    human-comparator study under equivalent capabilities.
  • Adds a local advisory catalog path for Rust, npm, GitHub Actions, Go, and
    PyPI, with quarantine, provenance, exact aliases, snapshots, deltas, backups,
    and modular core, malicious, and full bundles.
  • Adds the offline SecureFlow Web inventory and API-exposure research slice,
    including 400 synthetic paired API-risk scenarios. Remote recon and
    production HTTP transport remain out of scope for this release.
  • Hardens release evidence with pinned Rust 1.92.0 gates, a deterministic
    CycloneDX 1.5 SBOM, and checksum-bound Cargo dependency license declarations.

Evidence boundary

The repository contains synthetic development fixtures, local measurements,
and traceable advisory-ingestion evidence. These artifacts do not prove global
coverage, production safety, general effectiveness, a database of validated
vulnerabilities, or human replacement. Any task-bounded comparative claim
requires a separately preregistered holdout study, independent blinded
adjudication, uncertainty analysis, and publication of negative and mixed
results.

Release verification

The release archive includes source, schemas, documentation, build provenance,
the CycloneDX SBOM, dependency license declarations, internal SHA256SUMS, and
an external archive checksum. Verify the downloaded archive with its adjacent
.sha256 file before use.