Skip to content

SecureFlow v0.3.0

Latest

Choose a tag to compare

@github-actions github-actions released this 02 Sep 23:59
· 1 commit to main since this release
333609d

SecureFlow v0.3.0

SecureFlow v0.3.0 is a measurement-focused milestone for the local-first evidence chain from deterministic analysis through contextual review, human validation, and reproducible evaluation. The platform remains limited to explicitly authorized code and does not autonomously establish that a candidate is a vulnerability.

Highlights

  • The workspace crates and citation metadata identify version 0.3.0; research use should cite the exact tag or commit.
  • The release path creates a deterministic source-only archive from an exact commit and a separate host-specific Linux bundle, each with an adjacent SHA-256 checksum.
  • The tag workflow builds, attests, and retains the exact archives without publication permission; a separate manually dispatched workflow rebinds the approved tag, successful build run and attempt, artifact ID and digest, checksums, attestations, and draft uploads before publication.
  • Release-note linting requires each prose paragraph and list item to occupy one physical Markdown source line so the GitHub release page uses the full content area consistently.
  • A fresh compact npm CLI run is bound to exact Engine and target commits, binary and report hashes, complete accounting, and three source-reviewed abstentions; it produced zero findings, which is explicitly not a clean verdict.
  • At the recorded 2026-08-30 checkpoint, Engine PR #5 was merged as ffc724d4b0aeb872542f5d683de15850ca0c6c38, hosted main CI passed, and GitHub recomputed all 63 historical fixture dependency alerts as fixed with zero dismissed; this does not establish vulnerability freedom. A separate post-merge npm artifact preserves the original run and records one configuration-mismatch attempt before the scanner-input-matched retained attempt, explicitly exceeding the original one-pass lane.
  • The offline Mitiquete inventory and 50,000/100,000-record synthetic catalog gate are retained as separate, claim-bounded evidence lanes.

Evidence and claim boundary

  • The npm CLI analysis consists of preserved bounded static observations with zero validated vulnerabilities and three unresolved abstentions; the post-merge generation records a one-pass protocol deviation and cannot support a performance comparison, complete-audit claim, or evidence that npm CLI is secure.
  • The Mitiquete workstream currently provides offline source inventory only; it does not include production HTTP requests, remote recon, exploitation, or validated vulnerability findings.
  • The prospective human-comparator study has not started, so v0.3.0 makes no claim of outperforming, replacing, or matching human researchers.
  • Any 50,000/100,000-record knowledge-base gate is synthetic capacity and integrity evidence only; it is not a count of validated vulnerabilities, a completeness claim, or evidence for one-million-record production readiness.
  • Scanner output, API candidates, catalog records, and model suggestions remain leads until evidence is reproduced and a human reviewer validates the security impact.

Publication authority

  • A human maintainer must approve the exact final commit, tag target, release text, locally generated archives and checksums, SBOM, and license-declaration evidence before creating tag v0.3.0.
  • The approved tag authorizes the pinned tag workflow to rebuild, attest, and retain the four release files, but not to publish them; the resulting build run, run attempt, artifact ID and digest, files, checksums, and attestations must be shown and approved before manually dispatching publication.
  • The manual publisher fails closed unless the selected tag, build run and attempt, commit, workflow, exact artifact ID and digest, four files, checksums, attestations, and staged draft uploads agree; automation cannot validate a vulnerability, expand target authorization, approve a future release, or establish superiority over human researchers.

Reproducibility boundary

The source-only archive is designed to be deterministic for one exact commit. The Linux bundle is intentionally host-specific; checksums and GitHub attestations establish artifact integrity and workflow provenance, not cross-host binary reproducibility, dependency trustworthiness, production safety, or research validity.