v1.0.4
NeonDiff 1.0.4 replaces the earlier free-use-compatible package line with
mandatory API-backed activation for every supported repository review. It is a
real non-prerelease GitHub and npm release, and the installed public package,
activation transition, local dashboard, and browser flow have been verified.
Highlights
- Require a current production entitlement before useful review or provider
work on public, private, internal, or unknown repositories. - Publish
neondiff@1.0.4as npmlatestand a matching non-prerelease
GitHub Release. - Verify the public-registry install, API activation, cache no-bypass behavior,
local dashboard routes, and installed browser interaction.
Changes
- Pin the supported distribution to the production license API and prevent
user-editable legacy values from disabling enforcement or restoring the
former public-free path. - Support bounded-stdin activation with the mode-0600 file backend for
headless CLI and daemon installs. - Fail closed before checkout, provider calls, review generation, or GitHub
posting when activation is missing, invalid, revoked, expired, out of scope,
offline, or backed only by diagnostic cache metadata. - Gate the CLI, daemon, local dashboard provider route, and quarantined Desktop
useful-work boundaries while preserving setup and status diagnostics. - Preserve the advanced native SwiftUI Desktop application. The local HTML
dashboard remains a browser/setup surface, not a WebView replacement.
Fixes
- Recover the reviewed-tarball publish after npm omitted legacy
gitHead
metadata. The v1.0.4-only fallback accepts absence only when exact package
bytes, npm signatures, and Sigstore/SLSA provenance bind the package to this
repository, the publish workflow, annotated tag, and release source SHA. A
present mismatchedgitHeadstill fails closed. - Promote the existing immutable package without republishing, confirm registry
convergence atlatest=1.0.4, and remove the ownedrelease-candidate
quarantine tag.
Breaking / Migration
- v1.0.3 and earlier do not enforce mandatory activation and must be upgraded.
- Activate v1.0.4 through
neondiff license activatebefore useful review or
provider work. Same-origin dashboard activation is not included in v1.0.4
and remains tracked in
#556. - The package-allowlisted README, setup guide, and schema remain byte-identical
to the reviewed v1.0.4 tarball. Its compatibility label
free-source-available-betadoes not bypass mandatory runtime activation;
#559
tracks the typed copy/schema update in the next immutable package.
Known Boundaries
- #557
tracks the owner directive thatREQUEST_CHANGESrequires exact-head trusted
authorization. v1.0.4 does not yet provide that review-event policy. - #537
tracks internal daemon upgrade and reboot-safe supervision. - #561
tracks per-repository scheduler error isolation after a recovered GitHub App
installation lookup delayed an otherwise healthy exact-head review. - #559
tracks package-allowlisted copy, typed publication-proof validation, and a
serialized predecessor rollback mode for the next immutable patch. - website #45
owns synchronization of the public/free website and installer copy that was
stale when this proof was captured. The verified install proof here used the
public npm registry directly, not the website installer route. - Predecessor npm/GitHub/tag/Actions cleanup is not complete. Public source,
forks, caches, clones, and already-downloaded artifacts cannot be recalled. - This release does not prove signed or notarized Mac distribution,
Sparkle/appcast updates, browser/native parity, model quality, full customer
readiness, or v1.1 completion.
Release Verification
- Source SHA:
fc66d27b6ab9f6a1eb8282d289ef63407cd96982
(protected-main candidate42db7c8ff7dba6ceac813238dcebfb54dc83851f) - Tag / release: annotated tag object
c2dbb0fd69800785028eb42e30e72b2cc648eb3c, which peels to the source SHA;
GitHub Release v1.0.4 - Package identity:
neondiff@1.0.4, shasum
526c04bd24673351b9cc7136d8747df00ffaa2be, integrity
sha512-ng6g4Ivn+eFzZWkxhDAOsvaimYQi8HWktnK9xTptNLg37EK/LRh2Xr5Y+sAYnX6Sqa1YBVd3iUZBMtQLQbYvcw==,
npm provenance,
no republish - CI / workflows:
activation lifecycle,
recovery,
main CI,
CodeQL,
Swift Desktop Gate - Installed proof: fresh status
missing/source=none, provider work denied
before input, and an internal-team production-smoke entitlement activated as
active/source=api. The observed plan identifierinternalis not customer
billing or checkout proof. The provider route returned HTTP 200 after
activation withmetadata_only/configured_unverified; that proves
configuration metadata and route gating, not end-to-end provider inference.
Cache-only provider access remained denied with HTTP 403; the browser produced
one redacted Verify API Key result and zero console warnings or errors. - Evidence:
docs/evidence/v1.0.4-publication-proof.json,
external proof-manifest SHA-256
29a6ac64f828cf4fe10ad4e299ab0a14447a772c7c8d8b2c815e995468d784d8,
attested lifecycle aggregate - Rollback reference: source baseline
refs/tags/v1.0.3in an isolated recovery
checkout. v1.0.4 has no authorized npm predecessor-rollback command: the
current workflow supports forward publication and bounded v1.0.4 recovery,
not movinglatestbackward. Channel rollback is owner-gated under #559;
do not republish immutable versions or mutate dist-tags as an ad hoc shortcut. - Proof tier: public release plus installed-package activation/dashboard/browser
smoke; not signed Mac, customer-runtime, parity, or v1.1 proof