Carries four merged loops: specs 021, 025, 026 and 027. The v0.9.0 entry in RELEASES.md is the record, and it carries the Known open list this does not.
Four changes can break a caller's script
- A budget or cap flag that is not a number is refused, at exit 2, naming the input and the value.
- A model id the registry does not carry is refused before the first call, at exit 2, naming the id and the absolute path of the registry it consulted (
DRIFTPROOF_REGISTRYwhen set, otherwise the packagedconfig/models.json). - A run that measured nothing no longer reads as a run.
- The receipt schema is v0.6, and
badge,diffandexportverifyreceipt_hashbefore they read a receipt rather than warning and proceeding.
v0.5 of the receipt spec stays readable at spec/receipt.v0.5.schema.json.
And the rest
- Spec 025 - the site, measured in a browser instead of read out of a stylesheet.
- Spec 021 - the carry list, and six controls that were lying about their scope.
- Spec 027 - the confidentiality scan classifies before it scans.