SecureFlow v0.3.0
SecureFlow v0.3.0 is a measurement-focused milestone for the local-first evidence chain from deterministic analysis through contextual review, human validation, and reproducible evaluation. The platform remains limited to explicitly authorized code and does not autonomously establish that a candidate is a vulnerability.
Highlights
- The workspace crates and citation metadata identify version
0.3.0; research use should cite the exact tag or commit. - The release path creates a deterministic source-only archive from an exact commit and a separate host-specific Linux bundle, each with an adjacent SHA-256 checksum.
- The tag workflow builds, attests, and retains the exact archives without publication permission; a separate manually dispatched workflow rebinds the approved tag, successful build run and attempt, artifact ID and digest, checksums, attestations, and draft uploads before publication.
- Release-note linting requires each prose paragraph and list item to occupy one physical Markdown source line so the GitHub release page uses the full content area consistently.
- A fresh compact npm CLI run is bound to exact Engine and target commits, binary and report hashes, complete accounting, and three source-reviewed abstentions; it produced zero findings, which is explicitly not a clean verdict.
- At the recorded 2026-08-30 checkpoint, Engine PR #5 was merged as
ffc724d4b0aeb872542f5d683de15850ca0c6c38, hostedmainCI passed, and GitHub recomputed all 63 historical fixture dependency alerts as fixed with zero dismissed; this does not establish vulnerability freedom. A separate post-merge npm artifact preserves the original run and records one configuration-mismatch attempt before the scanner-input-matched retained attempt, explicitly exceeding the original one-pass lane. - The offline Mitiquete inventory and 50,000/100,000-record synthetic catalog gate are retained as separate, claim-bounded evidence lanes.
Evidence and claim boundary
- The npm CLI analysis consists of preserved bounded static observations with zero validated vulnerabilities and three unresolved abstentions; the post-merge generation records a one-pass protocol deviation and cannot support a performance comparison, complete-audit claim, or evidence that npm CLI is secure.
- The Mitiquete workstream currently provides offline source inventory only; it does not include production HTTP requests, remote recon, exploitation, or validated vulnerability findings.
- The prospective human-comparator study has not started, so v0.3.0 makes no claim of outperforming, replacing, or matching human researchers.
- Any 50,000/100,000-record knowledge-base gate is synthetic capacity and integrity evidence only; it is not a count of validated vulnerabilities, a completeness claim, or evidence for one-million-record production readiness.
- Scanner output, API candidates, catalog records, and model suggestions remain leads until evidence is reproduced and a human reviewer validates the security impact.
Publication authority
- A human maintainer must approve the exact final commit, tag target, release text, locally generated archives and checksums, SBOM, and license-declaration evidence before creating tag
v0.3.0. - The approved tag authorizes the pinned tag workflow to rebuild, attest, and retain the four release files, but not to publish them; the resulting build run, run attempt, artifact ID and digest, files, checksums, and attestations must be shown and approved before manually dispatching publication.
- The manual publisher fails closed unless the selected tag, build run and attempt, commit, workflow, exact artifact ID and digest, four files, checksums, attestations, and staged draft uploads agree; automation cannot validate a vulnerability, expand target authorization, approve a future release, or establish superiority over human researchers.
Reproducibility boundary
The source-only archive is designed to be deterministic for one exact commit. The Linux bundle is intentionally host-specific; checksums and GitHub attestations establish artifact integrity and workflow provenance, not cross-host binary reproducibility, dependency trustworthiness, production safety, or research validity.