Mill v0.3.0
0.3.0 is the current qualified public alpha. It adds truthful brownfield
continuation and recovery evidence, deterministic harness evaluation,
provider-measured cache-token observations, and an explicit trusted-host
isolation boundary. It documents—but does not implement—a revision-bound symbol
context adapter and a governed improvement record. The release does not add a
graph service, arbitrary-stack support, autonomous merge/deployment, or a claim
of hostile-host builder isolation.
Install
npm install --save-dev --ignore-scripts @davidahmann/mill@0.3.0
npx --no-install millctl --versionPin the exact version. The latest channel is a distribution pointer, not an
automatic-update instruction; an existing repository must deliberately requalify
changed delivery machinery.
Exact qualification
- Tag commit:
9d8105100845b306e508538257832d2c13ea31cc. - Reviewed and resulting-main tree:
ebe2ba513d713a01754d24c88b0d6ea06c1e4f95. - Annotated tag object:
f9ae5f652270e54140eb6161c98fe336d002bc40. - Preserved tarball SHA-256:
887c39e859e233e3ace6f06d6bb00c8d9760ccf3d58a28137a751b656e8b1922. - npm integrity:
sha512-6wXxLdhBgwF5Hj4W0UXvxHV7VXLPbm1lpRM4w1XeyoxUnibNaivQfKYDMwQbhTkr+W4SlivKTsC0EnTUkBFF5A==. - Canonical qualification digest:
sha256:f7f832a3e06e971c9fd6c649778e1cfb39f892627f9b3299aff4b23c92145cfb. - Candidate run 33975289594
passed two clean, byte-identical builds; the complete native gate; the
exact-tag audit; packed greenfield and adoption canaries; and the separately
pinned v0.1.5 independent policy and downstream canary. - Its qualification binds the macOS arm64 / Node 24.20.0 / npm 11.19.0 / Docker
29.7.2 / Codex CLI 0.153.4 tuple, observed at2026-09-05T15:35:52.039Zand
expiring at2026-10-05T15:35:52.039Z. It does not qualify another host,
harness, model identity, forge, or recipe.
Publication and recovery
Publish run 33975771369
published the preserved tarball once through the protected npm environment, then
verified npm provenance/signatures and requalified the registry-downloaded
package. The run stopped before GitHub Release creation because the immutable
tag predated this release record. npm publication is never replayed for that
failure. The attended recovery created the release from the exact preserved
candidate assets, downloaded the GitHub tarball again, and bound the resulting
provider readback. It did not rebuild or republish the package.
- GitHub Release
carries the tarball, checksum, SBOM, prepublication evidence, and final
evidence. The final-evidence file SHA-256 is
b5fd8cf5b5042a4d1b0b6a456b19f6c76c6ad74842ecad272adfd6e6ae7d1e3d. - npm provenance,
signature readback, exact integrity, and the registry-package full canary
passed before recovery created the GitHub Release. - Separate attended channel promotion made GitHub Latest and npm
alphaand
latestselect0.3.0. Provider readback confirms those pointers and the
unchanged immutable package integrity.
The documentation and workflow closure following the immutable tag adds an
immediate candidate-stage gate for a regular, non-symlink, nonempty release
record with a real docs/ and docs/releases/ parent-directory chain. It
prevents this ordering error in future releases; it does not alter the 0.3.0
tarball, tag, candidate evidence, or trust-root history.