Release 1.7.4.post12 (PyPI publish counter)
Status: Published on PyPI (2026-07-30 00:42:09 UTC). Operator publish-pypi workflow_dispatch: build → TestPyPI → PyPI.
Public line (marketing): 1.7.4 — README, man pages, stakeholder copy unchanged.
Build / PyPI / About: 1.7.4.post12 — PEP 440 post-release (publish counter per ADR-0073 § PyPI dual counters).
Not in this drop: Git tag · GitHub Release · Docker / container image (PyPI-only .postN).
Theme: Supply-chain floor for gitpython via optional extra [grc-dashboard] (N=1). Nine Dependabot HIGH alerts on the runtime lockfile path; one advisory is only fixed in 3.1.55 (Dependabot PR #1335 stopped at 3.1.54). Streamlit declares gitpython!=3.1.19,<4,>=3.0.7 — compatible with >=3.1.55 (measured against streamlit 1.58.0 and 1.60.0 on PyPI).
Mandatory map: postN ↔ maturity_build
Per ADR-0073: postN counts PyPI uploads; maturity_build counts discrete fixes and may run ahead. This map is the mandatory audit trail.
PyPI / [project] version |
maturity_build (octet) |
Notes |
|---|---|---|
1.7.4 |
.201 |
GA on PyPI (immutable); release PR #1024 |
1.7.4.post1 |
.202 |
SQL drivers → optional extras (#1047) — published |
| (fix, unpublished on PyPI) | .203 |
#1026 |
| (fix, unpublished on PyPI) | .204 |
#1028 |
| (fix, unpublished on PyPI) | .205 |
Deploy / packaging fix train |
| (fix, unpublished on PyPI) | .206 |
main.py --version without config |
| (fix, unpublished on PyPI) | .207 |
fix(connectors) symlink / reparse-point loop guard (#1080) |
1.7.4.post2 |
.208 |
Prior upload on this line |
| (fix, unpublished on PyPI) | .209 |
SQL sampling failures now surface in scan_failures (#1140, #1144) |
| (fix, unpublished on PyPI) | .210 |
Encrypted/corrupt archive members now surface in scan_failures (open-core slice of #828, #1146) |
1.7.4.post3 |
.211 |
Published with soupsieve CVE fix (#1177) |
| (fix, unpublished on PyPI) | .212 |
RBAC now defaults to deny on the full route map (#1133). |
| (fix, unpublished on PyPI) | .213 |
API key comparison now uses UTF-8 byte-safe compare_digest (#1150). |
| (fix, unpublished on PyPI) | .214 |
Operator-gated reopen workflow pins were restored to keep governance automation stable. |
| (fix, unpublished on PyPI) | .215 |
SQL sampling transaction scope is now isolated per connection (#1194). |
| (fix, unpublished on PyPI) | .216 |
One-class compliance profiles now preserve declared-term detections (#1195). |
| (fix, unpublished on PyPI) | .217 |
XLSX exports now neutralize formula-leading cells to prevent spreadsheet injection (#1201). |
| (fix, unpublished on PyPI) | .218 |
Web exposure defaults now enforce a safe-by-default posture for remote surface (#1202). |
| (fix, unpublished on PyPI) | .219 |
Follow-up CodeQL logging and import-cycle hardening landed on the web-exposure path (#1202). |
| (fix, unpublished on PyPI) | .220 |
Remaining routes-context import cycle was removed to stabilize route wiring. |
| (fix, unpublished on PyPI) | .221 |
Config redaction now masks DSN/URL embedded credentials in /config (#1137). |
| (fix, unpublished on PyPI) | .222 |
Prefilter now preserves recall parity with active profile terms/regexes (#1198). |
| (fix, unpublished on PyPI) | .223 |
Help output now aligns dev invocation and installed command contract (#1130). |
| (fix, unpublished on PyPI) | .224 |
Demo sessions now resolve audit trail correctly via /logs/{session_id} (#1218). |
| (fix, unpublished on PyPI) | .225 |
Logs fallback hardening removed the CodeQL path-injection sink in demo retrieval (#1218, 4bd3e5bc). |
1.7.4.post4 |
.226 |
Pillow 12.2.0 → 12.3.0 (PYSEC-2026-2253..2257); baseline post3 + N=15. |
| (fix, unpublished on PyPI) | .227 |
Align ATS import footer skill path to private (#1191). |
| (fix, unpublished on PyPI) | .228 |
Standalone HTML form CSRF without WebAuthn (#1231). |
| (fix, unpublished on PyPI) | .229 |
Dataverse org_url / token_url SSRF guards (#1232). |
| (fix, unpublished on PyPI) | .230 |
Aggregate archive decompression budgets (#1233). |
| (fix, unpublished on PyPI) | .231 |
Reject non-finite max_expansion_ratio (nan/inf). |
| (fix, unpublished on PyPI) | .232 |
Secret-by-identity lock + reachable JWT GRACE (#1210, #1212). |
| (fix, unpublished on PyPI) | .233 |
Fail-closed on non-numeric license exp claim. |
| (fix, unpublished on PyPI) | .234 |
Honest build_digest_matched (no signature_ok overclaim) (#1211). |
| (fix, unpublished on PyPI) | .235 |
Zero legacy build_digest_matched bit on migrate (#1211). |
| (fix, unpublished on PyPI) | .236 |
Drop Invoke-Expression from external-review-pack.ps1 (#1192). |
| (fix, unpublished on PyPI) | .237 |
Read .7z members via py7zr BytesIOFactory (#1250, #1248). |
| (fix, unpublished on PyPI) | .238 |
Extract pre-budget .7z members on budget stop (#1250, #1248). |
| (fix, unpublished on PyPI) | .239 |
Orphan session reaper (PID liveness) + interrupt → interrupted (#1251). |
1.7.4.post5 |
.240 |
Post5 wave (archives/sessions/security/integrity train); baseline post4 + N=14 fix( — see 1.7.4.post5.md. |
1.7.4.post6 |
.241 |
Integrity anchor re-baselines on legitimate release upgrade (#1262 / #1263); baseline 1.7.4.post5 + N=1 fix( — see 1.7.4.post6.md. |
| (fix, unpublished on PyPI) | .242 |
.7z batch-extract / post-extract failures sanitized via clean_error() (#1257). |
| (fix, unpublished on PyPI) | .243 |
WebAuthn session satisfies require_api_key on JSON routes (#1258). |
| (fix, unpublished on PyPI) | .244 |
learned_patterns: skip bare filenames + anchor output_file to report.output_dir (#1259, #1260). |
1.7.4.post7 |
.245 |
Post6 baseline 6dc54642 + N=4 discrete fixes (incl. MSSQL defect-fix #1290/#1289) — see 1.7.4.post7.md. |
| (fix, unpublished on PyPI) | .246 |
MSSQL pymssql login_timeout / timeout connect args (#1297, field-caught 2026-07-21). |
| (fix, unpublished on PyPI) | .247 |
Integrity anchor: CRITICAL_MODULES globs + CLI trust surfacing (#1298, field-caught 2026-07-21). |
| (fix, unpublished on PyPI) | .248 |
pyasn1 → 0.6.4 (PYSEC-2026-3455/3456/3457) (#1304). |
| (fix, unpublished on PyPI) | .249 |
SQL connect_args branched per driver: oracle+oracledb → tcp_connect_timeout; mssql+pyodbc → timeout only (#1310 / #1302). |
| (fix, unpublished on PyPI) | .250 |
Oracle discovery skips AUDSYS + 12c+ system schemas (#1316 / #1315; field Podman 2026-07-23). |
1.7.4.post8 |
.250 |
Published 2026-07-23 13:52:06 UTC — post7 baseline b5054d55 + N=5 fix(; see 1.7.4.post8.md. |
| (fix, unpublished on PyPI) | .251 |
CLI pre-flight output dirs + --regenerate-report from SQLite (#1339 / #1324, #1325). |
| (fix, unpublished on PyPI) | .252 |
SQL sampling: deduplicate column values before sample_limit cap (#1343 / #1337). |
| (fix, unpublished on PyPI) | .253 |
Production engine wires BoarThrottler adaptive rate limiting (#1344 / #1320). |
| (fix, unpublished on PyPI) | .254 |
Learned-patterns audit anti-generic blocklist (#1345 / #1327). |
| (fix, unpublished on PyPI) | .255 |
Unified session report export CLI + per-format wrappers (#1346 / #1326). |
| (fix, unpublished on PyPI) | .256 |
Live scan progress lines + remote DB latency operator docs (#1347 / #1328, #1323). |
| (fix, unpublished on PyPI) | .257 |
pypdf 6.13.3 → 6.14.2 — CVE-2026-59935/59936/59937/59938 (DoS via PDF scan path) (#1336). |
1.7.4.post9 |
.257 |
Published 2026-07-28 10:34:16 UTC — post8 baseline 8527b0a4 + N=7 discrete fixes; see 1.7.4.post9.md. |
| (fix, unpublished on PyPI) | .258 |
Executive PDF/DOCX render Markdown inline (report/executive_markdown_render.py, executive_*.py) (#1353, #1357). |
| (fix, unpublished on PyPI) | .259 |
Redis: distinguish WRONGTYPE from connection failure; per-type value-not-sampled counts (#1348 Part A, #1357). |
| (fix, unpublished on PyPI) | .260 |
archive_type_mismatch when compressed extension and magic disagree (#1354 Part A, #1357). |
| (fix, unpublished on PyPI) | .261 |
pypdf floor >=6.14.2 in pyproject.toml (future resolve cannot slip below patched pin) (#1340, #1357). |
1.7.4.post10 |
.261 |
Published 2026-07-28 16:37:23 UTC — post9 baseline 9fa991c2 + N=4 discrete fixes; see 1.7.4.post10.md. |
1.7.4.post11 |
.262 |
Published 2026-07-29 21:32:58 UTC — post10 baseline .261 + N=1 (#1370 Oracle sampling identifiers); see 1.7.4.post11.md. |
1.7.4.post12 |
.263 |
Published 2026-07-30 00:42:09 UTC — post11 baseline .262 + N=1 (gitpython >=3.1.55 floor on [grc-dashboard]); see this file. |
Appendix — Fix set used for N (N=1) (git-literal)
Boundary: post11 release commit (published stamp on main after 1.7.4.post11 upload).
Counted toward N=1 (wheel-affecting packaging only):
.263— #1383: raisegitpythonfloor to>=3.1.55on the[grc-dashboard]extra so streamlit’s transitive GitPython cannot resolve below the last patched version covering nine Dependabot HIGH advisories (GHSA-94p4-4cq8-9g67 first_patched 3.1.55). Lock resolves to 3.1.57.
Not counted toward N:
- CI Action pin bumps (SHA-exact): #1269 / #1268
github/codeql-action→99df26d4f13ea111d4ec1a7dddef6063f76b97e9(v4.37.0); #1107actions/setup-python→ece7cb06caefa5fff74198d8649806c4678c61a1(v6.3.0). - #1378 uv-minor-patch group (47 updates) — not absorbed (undiagnosed CI failures on a stale base; keep security floor separate from bulk lockfile churn).
Highlights (why post12)
[grc-dashboard]installs cannot pull vulnerable GitPython: explicitgitpython>=3.1.55beside streamlit/plotly (base install unchanged).- Dependabot Action PRs unblocked in-repo: SHA pins advanced where the bot cannot rebase under the
non_fast_forwardruleset.
Install
pip install 'data-boar==1.7.4.post12'
# dashboard extra (pulls streamlit → gitpython>=3.1.55):
pip install 'data-boar[grc-dashboard]==1.7.4.post12'See USAGE.md, QUICKSTART.md, and TROUBLESHOOTING.md.
What's Changed
- chore(docker): daemonless Linux build — appuser perms + log/ context by @FabioLeitao in #1026
- docs(man): make data-boar the canonical man page name by @FabioLeitao in #1031
- docs(release-sync): reconcile PUBLISHED_SYNC and PLANS for 1.7.4 GA by @FabioLeitao in #1033
- docs(today-mode): add 2026-06-27 checklist (post-1.7.4 pre-epic) by @FabioLeitao in #1034
- feat(cli): add --version flag to main.py (#1027) by @FabioLeitao in #1040
- build(security): distroless runtime hardening — PR-A (#1028) by @FabioLeitao in #1041
- workflow(ci): tiered security scans in check-all mirror (#1044) by @FabioLeitao in #1045
- ci(release): OIDC PyPI publish workflow and package metadata (#1042) by @FabioLeitao in #1043
- docs(deploy): README index, pt-BR mirrors, Podman section (#1036 #1037 #1038) by @FabioLeitao in #1039
- feat(packaging): SQL driver extras + ADR-0073 PyPI dual counters by @FabioLeitao in #1048
- feat(docker): grype VEX gate + release docs (#1028 PR-B) by @FabioLeitao in #1050
- feat(workflow): Maestro login-env parity and min-spec docs (#1003) by @FabioLeitao in #1051
- feat(workflow): PyPI OIDC dispatch wrapper (#1046) by @FabioLeitao in #1052
- docs(plans): v1.8.0 detection taxonomy survey (#1056) by @FabioLeitao in #1062
- chore(plans): archive drift #91, Bucket A headers, PUBLISHED_SYNC by @FabioLeitao in #1063
- houseclean: gate-trailer-attest + plans wave 2 archive by @FabioLeitao in #1064
- houseclean(plans): archive integrity, rust hotspot bench, external research docs by @FabioLeitao in #1070
- docs(plans): hybrid taxonomy trilogy + subject category axis (#1069, #1071) by @FabioLeitao in #1086
- fix(connectors): guard filesystem walk against symlink loops (#1080) by @FabioLeitao in #1087
- docs(adr): close #1078/#1079 research — benchmarks + OPA prototype by @FabioLeitao in #1088
- feat(licensing): Std/Pro+/Partner tiers + security hardening slice by @FabioLeitao in #1097
- ci(actions): bump anthropics/claude-code-action from 1.0.148 to 1.0.150 by @dependabot[bot] in #1010
- chore(workflow): today-mode 2026-06-30 + Dependabot land batch by @FabioLeitao in #1100
- ci(gitleaks): binary install — no org-license Action by @FabioLeitao in #1109
- chore: add FUNDING.yml (Sponsor → Patreon DataBoar) by @FabioLeitao in #1111
- feat(cli): zero-config data-boar --demo (#1113) by @FabioLeitao in #1119
- docs(adr): UMADR canonical regency in ADR-0000 (#994) by @FabioLeitao in #1118
- chore(release): 1.7.4.post2 (--demo) + postN ritual in release-versioning rule by @FabioLeitao in #1120
- fix(connector): SQL sampling failures → scan_failures (#1140) by @FabioLeitao in #1144
- fix(scan): encrypted/corrupt files → scan_failures (#828 open-core) by @FabioLeitao in #1146
- docs(adr): ADR-0080 local validation gate inviolable (#1152) by @FabioLeitao in #1160
- Revert "docs(adr): ADR-0080 local validation gate inviolable (#1152)" by @FabioLeitao in #1161
- test(adr): Phase 1 ADR governance anti-regression suite (#1162) by @FabioLeitao in #1163
- feat(gate): ADR-0074 materialization + no-coauthorship kombi (gitleaks value-rule + pytest commit-msg gate + auto-strip hook) by @FabioLeitao in #1165
- deps: bump soupsieve to 2.8.4 for CVE-2026-49476/49477 by @FabioLeitao in #1177
- docs(help): separate --demo from config-driven one-shot (#1121) by @FabioLeitao in #1122
- chore(ops): un-ignore today-mode hub (#1147) by @FabioLeitao in #1148
- docs: clarify pipx onboarding edge cases for RHEL9 and Alpine musl by @FabioLeitao in #1175
- docs(contributing): use canonical uv export command by @FabioLeitao in #1179
- [P0][ci] chore(release): 1.7.4.post3 release by @FabioLeitao in #1180
- [P1][ci] fix(actions): corrige pins mortos do operator-gated-reopen (ressuscita guardrail) by @FabioLeitao in #1181
- [P2][docs] docs(compat): enrich distro install matrix for pipx onboarding by @FabioLeitao in #1184
- deps(docker): bump distroless/cc-debian13 from
7f2a0e5tod3cda6eby @dependabot[bot] in #1105 - ci(actions): bump anthropics/claude-code-action from 1.0.150 to 1.0.155 by @dependabot[bot] in #1108
- [P2][docs] docs(workflow): refresh today-mode and two-week cycle by @FabioLeitao in #1186
- [P2][docs] docs(ops): de-claim musl parser gap after timeout artifact by @FabioLeitao in #1187
- [P2][docs] docs(ops): add void-musl parity note to install matrix by @FabioLeitao in #1188
- [P3][docs] docs(cursor): two-tier check-all gate by @FabioLeitao in #1185
- docs(adr): ADR-0073 band-fix — maturity counter starts at 1 by @FabioLeitao in #1124
- docs(ops): BUS gitleaks binary org-wide sweep (#10) by @FabioLeitao in #1125
- chore(cursor): Tier B situationalization wave (#1154) by @FabioLeitao in #1155
- fix(api): RBAC default-deny + constant-time API key (#1133 #1134) by @FabioLeitao in #1143
- [P0][critical][sql] fix(connector): prevent autobegin collisions in SQL sampling by @FabioLeitao in #1203
- fix(detector): harden single-class compliance term detection by @FabioLeitao in #1204
- fix(report): sanitize all XLSX exports against formula injection by @FabioLeitao in #1205
- fix(api): harden web exposure defaults and audit boundaries (#1202) by @FabioLeitao in #1206
- refactor(api): remove routes import cycle in webauthn HTML gate by @FabioLeitao in #1207
- fix(config): redact DSN/URL embedded credentials in /config (#1137) by @FabioLeitao in #1208
- fix(prefilter): preserve recall parity for compliance profile signals by @FabioLeitao in #1209
- docs(today-mode): add 2026-07-12 carryover-sweep checklist by @FabioLeitao in #1213
- fix(help): correct runtime invocation and path examples by @FabioLeitao in #1214
- docs(plans): sync post4 trust-floor PMO snapshot by @FabioLeitao in #1215
- ci(deps): stabilize Dependabot requirements sync for torch 2.12.1 by @FabioLeitao in #1216
- deps(uv): bump torch from 2.10.0 to 2.12.1 by @dependabot[bot] in #975
- fix(api): resolve --demo audit trail lookup for /logs/{session_id} by @FabioLeitao in #1219
- docs(man): align section 1/5 invocation and add anti-drift guard by @FabioLeitao in #1220
- docs(plans): track wheelhouse seed via GitHub Releases by @FabioLeitao in #1221
- docs(compat): wire live wheelhouse URL for Void-musl by @FabioLeitao in #1222
- chore(release): 1.7.4.post4 release by @FabioLeitao in #1224
- docs(release): codify versioning/maturity doctrine + release-publish-sequencing rule by @FabioLeitao in #1226
- security(cursor): move operator runbook skills to private (#1191) by @FabioLeitao in #1239
- fix(security): standalone HTML CSRF for form POSTs (#1231) by @FabioLeitao in #1241
- fix(security): Dataverse SSRF guard on org_url/token_url (#1232) by @FabioLeitao in #1242
- fix(security): aggregate archive decompression budgets (#1233) by @FabioLeitao in #1243
- docs(security): harden LICENSING_SPEC OPSEC phrasing (#1234 #1235) by @FabioLeitao in #1244
- fix(security): lock secret-by-identity and reachable JWT GRACE (#1210 #1212) by @FabioLeitao in #1245
- fix(integrity): honest build_digest_matched (#1211) by @FabioLeitao in #1247
- chore: markdown-lint git-tracked + per-dev gitignore (#1240) by @FabioLeitao in #1249
- fix(security): remove Invoke-Expression in external-review-pack (#1192) by @FabioLeitao in #1252
- fix(archives): restore .7z content read via BytesIOFactory (#1250 #1248) by @FabioLeitao in #1253
- fix(session): orphan running sessions reaper + interrupt finish (#1251) by @FabioLeitao in #1254
- feat(cli): --validate-config WARN for missing optional SQL drivers (#1246) by @FabioLeitao in #1255
- chore(release): 1.7.4.post5 (PyPI publish counter) by @FabioLeitao in #1256
- fix(integrity): re-baseline anchor on legitimate release upgrade by @FabioLeitao in #1263
- chore(release): 1.7.4.post6 (PyPI publish counter) by @FabioLeitao in #1264
- chore(post7): project.urls org, post4 octet backfill, integrity comment by @FabioLeitao in #1265
- feat(connectors): honor explicit SQL driver + no-ODBC mssql via pymssql by @FabioLeitao in #1290
- fix(archives): sanitize .7z batch-extract failure details (#1257) by @FabioLeitao in #1292
- fix(api): WebAuthn session satisfies require_api_key (#1258) by @FabioLeitao in #1293
- fix(learned_patterns): bare filename skip + output_dir anchor (#1259, #1260) by @FabioLeitao in #1294
- docs(release): clarify post5 maturity_build accounting (#1261) by @FabioLeitao in #1295
- chore(release): 1.7.4.post7 PyPI publish counter by @FabioLeitao in #1296
- fix(connectors): pymssql login_timeout/timeout for MSSQL connect_args by @FabioLeitao in #1297
- fix(integrity): expand CRITICAL_MODULES globs + CLI surfacing (#1298) by @FabioLeitao in #1300
- chore(release): 1.7.4.post8 PyPI publish counter by @FabioLeitao in #1301
- docs(compliance-samples): enrich LGPD sample with field-validated categories (#1288) by @FabioLeitao in #1303
- fix(deps): bump pyasn1 to 0.6.4 (PYSEC-2026-3455/3456/3457) by @FabioLeitao in #1304
- docs(plans): add sparse database compat matrix plan (#1237) by @FabioLeitao in #1307
- docs(plans): rewrite wheelhouse plan as pan-ABI matrix (#1182) by @FabioLeitao in #1305
- docs(versioning): CVE/real-bug vs planned post-GA cadence (#1228) by @FabioLeitao in #1309
- fix(connector): branch SQL connect timeout kwargs by driver (#1302) by @FabioLeitao in #1310
- workflow(ops): primary Linux agent tmux + systemd bootstrap by @FabioLeitao in #1313
- fix(connector): skip Oracle 12c+ system schemas including AUDSYS (#1315) by @FabioLeitao in #1316
- chore(release): honest post8 notes — N=5, maturity_build=250 by @FabioLeitao in #1317
- deps(uv): bump pypdf from 6.13.3 to 6.14.2 by @dependabot[bot] in #1336
- fix(cli): pre-flight output dirs + --regenerate-report from SQLite by @FabioLeitao in #1339
- feat(benchmark): blocking safe (recall) axis on official gate by @FabioLeitao in #1341
- feat(sampling): deduplicate column values before sample_limit cap (#1337) by @FabioLeitao in #1343
- deps(uv): bump torch from 2.12.1 to 2.13.0 by @dependabot[bot] in #1266
- feat(scan): adaptive rate limiting in production engine + docs (#1320, #1321) by @FabioLeitao in #1344
- deps(docker): bump distroless/cc-debian13 from
d3cda6etod97bc0aby @dependabot[bot] in #1267 - deps(uv): bump setuptools from 81.0.0 to 83.0.0 by @dependabot[bot] in #1314
- feat(compliance): PCI/saude field patterns + learned anti-generic (#1318, #1327) by @FabioLeitao in #1345
- feat(report): unified session export CLI with per-format wrappers by @FabioLeitao in #1346
- feat(scan): live progress + remote DB latency docs (#1328, #1323) by @FabioLeitao in #1347
- chore(release): 1.7.4.post9 PyPI publish counter by @FabioLeitao in #1350
- docs(release): mark 1.7.4.post9 published on PyPI by @FabioLeitao in #1351
- docs(release): mark 1.7.4.post1–post7 published on PyPI by @FabioLeitao in #1352
- feat(lab-smoke): MSSQL/Oracle/Redis seeds + gitignore depth fix (#1171 prep) by @FabioLeitao in #1355
- fix(post10): markdown PDF/DOCX, Redis WRONGTYPE visibility, archive_type_mismatch by @FabioLeitao in #1357
- chore(release): 1.7.4.post10 PyPI publish counter (maturity_build=261) by @FabioLeitao in #1358
- docs(release): mark 1.7.4.post10 published on PyPI (2026-07-28 16:37:23 UTC) by @FabioLeitao in #1359
- fix(connector): Oracle sampling identifiers + lab-smoke init sidecars by @FabioLeitao in #1372
- docs(packaging): wheelhouse x86-64-v1 install and verification (#1365) by @FabioLeitao in #1373
- test(lab): fixture lab-smoke #1332 CREDIT_CARD FP (#1371) by @FabioLeitao in #1374
- test(deploy): comparable config-ref harness across corners (#1368) by @FabioLeitao in #1375
- docs(plans): pin reproducible mariadb glibc wheelhouse recipe by @FabioLeitao in #1377
- ci(wheelhouse): recipe rebuild with hard-fail gates (#1379) by @FabioLeitao in #1380
- chore(release): 1.7.4.post11 PyPI publish counter by @FabioLeitao in #1381
- docs(release): mark 1.7.4.post11 published on PyPI (2026-07-29) by @FabioLeitao in #1382
- chore(release): 1.7.4.post12 — gitpython floor + CI Action pins by @FabioLeitao in #1384
- docs(release): mark 1.7.4.post12 published on PyPI (2026-07-30) by @FabioLeitao in #1390
Full Changelog: v1.7.4...v1.7.4.post12
Docker image + free-threaded wheelhouse (2026-07-30)
Docker Hub — fabioleitao/data_boar:1.7.4.post12 and :latest share digest sha256:ab8f5dad3e33618e5c0dbb6d880ddafa11fc0e39c8372d5f0f1a2316d8597842 (~309 MB compressed). Base: python:3.14-slim (digest sha256:cea0e604…, Debian 13/trixie) → gcr.io/distroless/cc-debian13:nonroot. ML stack from hosted x86-64-v1 wheelhouse: popcnt=0 on site-packages .so (Celeron-safe); boar_fast_filter embedded. June GA tag 1.7.4 left untouched.
Free-threaded / no-GIL (cp314t): ten additional wheels on wheelhouse-x86-64-v1-2026-07-29 (numpy/scipy/pandas/sklearn + boar_fast_filter, manylinux and musllinux). Not interchangeable with GIL cp314 (SOABI differs). See the wheelhouse release notes for CPU contracts (cp314t numpy popcnt=1477 → x86-64-v2+; GIL v1 cells remain popcnt=0).