Skip to content

Mill v0.3.0

Latest

Choose a tag to compare

@davidahmann davidahmann released this 05 Sep 16:00
· 1 commit to main since this release
9d81051

Mill v0.3.0

0.3.0 is the current qualified public alpha. It adds truthful brownfield
continuation and recovery evidence, deterministic harness evaluation,
provider-measured cache-token observations, and an explicit trusted-host
isolation boundary. It documents—but does not implement—a revision-bound symbol
context adapter and a governed improvement record. The release does not add a
graph service, arbitrary-stack support, autonomous merge/deployment, or a claim
of hostile-host builder isolation.

Install

npm install --save-dev --ignore-scripts @davidahmann/mill@0.3.0
npx --no-install millctl --version

Pin the exact version. The latest channel is a distribution pointer, not an
automatic-update instruction; an existing repository must deliberately requalify
changed delivery machinery.

Exact qualification

  • Tag commit: 9d8105100845b306e508538257832d2c13ea31cc.
  • Reviewed and resulting-main tree: ebe2ba513d713a01754d24c88b0d6ea06c1e4f95.
  • Annotated tag object: f9ae5f652270e54140eb6161c98fe336d002bc40.
  • Preserved tarball SHA-256:
    887c39e859e233e3ace6f06d6bb00c8d9760ccf3d58a28137a751b656e8b1922.
  • npm integrity:
    sha512-6wXxLdhBgwF5Hj4W0UXvxHV7VXLPbm1lpRM4w1XeyoxUnibNaivQfKYDMwQbhTkr+W4SlivKTsC0EnTUkBFF5A==.
  • Canonical qualification digest:
    sha256:f7f832a3e06e971c9fd6c649778e1cfb39f892627f9b3299aff4b23c92145cfb.
  • Candidate run 33975289594
    passed two clean, byte-identical builds; the complete native gate; the
    exact-tag audit; packed greenfield and adoption canaries; and the separately
    pinned v0.1.5 independent policy and downstream canary.
  • Its qualification binds the macOS arm64 / Node 24.20.0 / npm 11.19.0 / Docker
    29.7.2 / Codex CLI 0.153.4 tuple, observed at 2026-09-05T15:35:52.039Z and
    expiring at 2026-10-05T15:35:52.039Z. It does not qualify another host,
    harness, model identity, forge, or recipe.

Publication and recovery

Publish run 33975771369
published the preserved tarball once through the protected npm environment, then
verified npm provenance/signatures and requalified the registry-downloaded
package. The run stopped before GitHub Release creation because the immutable
tag predated this release record. npm publication is never replayed for that
failure. The attended recovery created the release from the exact preserved
candidate assets, downloaded the GitHub tarball again, and bound the resulting
provider readback. It did not rebuild or republish the package.

  • GitHub Release
    carries the tarball, checksum, SBOM, prepublication evidence, and final
    evidence. The final-evidence file SHA-256 is
    b5fd8cf5b5042a4d1b0b6a456b19f6c76c6ad74842ecad272adfd6e6ae7d1e3d.
  • npm provenance,
    signature readback, exact integrity, and the registry-package full canary
    passed before recovery created the GitHub Release.
  • Separate attended channel promotion made GitHub Latest and npm alpha and
    latest select 0.3.0. Provider readback confirms those pointers and the
    unchanged immutable package integrity.

The documentation and workflow closure following the immutable tag adds an
immediate candidate-stage gate for a regular, non-symlink, nonempty release
record with a real docs/ and docs/releases/ parent-directory chain. It
prevents this ordering error in future releases; it does not alter the 0.3.0
tarball, tag, candidate evidence, or trust-root history.