Skip to content

NeonDiff v1.0.4

Latest

Choose a tag to compare

@100yenadmin 100yenadmin released this 12 Jul 08:27
fc66d27

v1.0.4

NeonDiff 1.0.4 replaces the earlier free-use-compatible package line with
mandatory API-backed activation for every supported repository review. It is a
real non-prerelease GitHub and npm release, and the installed public package,
activation transition, local dashboard, and browser flow have been verified.

Highlights

  • Require a current production entitlement before useful review or provider
    work on public, private, internal, or unknown repositories.
  • Publish neondiff@1.0.4 as npm latest and a matching non-prerelease
    GitHub Release.
  • Verify the public-registry install, API activation, cache no-bypass behavior,
    local dashboard routes, and installed browser interaction.

Changes

  • Pin the supported distribution to the production license API and prevent
    user-editable legacy values from disabling enforcement or restoring the
    former public-free path.
  • Support bounded-stdin activation with the mode-0600 file backend for
    headless CLI and daemon installs.
  • Fail closed before checkout, provider calls, review generation, or GitHub
    posting when activation is missing, invalid, revoked, expired, out of scope,
    offline, or backed only by diagnostic cache metadata.
  • Gate the CLI, daemon, local dashboard provider route, and quarantined Desktop
    useful-work boundaries while preserving setup and status diagnostics.
  • Preserve the advanced native SwiftUI Desktop application. The local HTML
    dashboard remains a browser/setup surface, not a WebView replacement.

Fixes

  • Recover the reviewed-tarball publish after npm omitted legacy gitHead
    metadata. The v1.0.4-only fallback accepts absence only when exact package
    bytes, npm signatures, and Sigstore/SLSA provenance bind the package to this
    repository, the publish workflow, annotated tag, and release source SHA. A
    present mismatched gitHead still fails closed.
  • Promote the existing immutable package without republishing, confirm registry
    convergence at latest=1.0.4, and remove the owned release-candidate
    quarantine tag.

Breaking / Migration

  • v1.0.3 and earlier do not enforce mandatory activation and must be upgraded.
  • Activate v1.0.4 through neondiff license activate before useful review or
    provider work. Same-origin dashboard activation is not included in v1.0.4
    and remains tracked in
    #556.
  • The package-allowlisted README, setup guide, and schema remain byte-identical
    to the reviewed v1.0.4 tarball. Its compatibility label
    free-source-available-beta does not bypass mandatory runtime activation;
    #559
    tracks the typed copy/schema update in the next immutable package.

Known Boundaries

  • #557
    tracks the owner directive that REQUEST_CHANGES requires exact-head trusted
    authorization. v1.0.4 does not yet provide that review-event policy.
  • #537
    tracks internal daemon upgrade and reboot-safe supervision.
  • #561
    tracks per-repository scheduler error isolation after a recovered GitHub App
    installation lookup delayed an otherwise healthy exact-head review.
  • #559
    tracks package-allowlisted copy, typed publication-proof validation, and a
    serialized predecessor rollback mode for the next immutable patch.
  • website #45
    owns synchronization of the public/free website and installer copy that was
    stale when this proof was captured. The verified install proof here used the
    public npm registry directly, not the website installer route.
  • Predecessor npm/GitHub/tag/Actions cleanup is not complete. Public source,
    forks, caches, clones, and already-downloaded artifacts cannot be recalled.
  • This release does not prove signed or notarized Mac distribution,
    Sparkle/appcast updates, browser/native parity, model quality, full customer
    readiness, or v1.1 completion.

Release Verification

  • Source SHA: fc66d27b6ab9f6a1eb8282d289ef63407cd96982
    (protected-main candidate 42db7c8ff7dba6ceac813238dcebfb54dc83851f)
  • Tag / release: annotated tag object
    c2dbb0fd69800785028eb42e30e72b2cc648eb3c, which peels to the source SHA;
    GitHub Release v1.0.4
  • Package identity: neondiff@1.0.4, shasum
    526c04bd24673351b9cc7136d8747df00ffaa2be, integrity
    sha512-ng6g4Ivn+eFzZWkxhDAOsvaimYQi8HWktnK9xTptNLg37EK/LRh2Xr5Y+sAYnX6Sqa1YBVd3iUZBMtQLQbYvcw==,
    npm provenance,
    no republish
  • CI / workflows:
    activation lifecycle,
    recovery,
    main CI,
    CodeQL,
    Swift Desktop Gate
  • Installed proof: fresh status missing/source=none, provider work denied
    before input, and an internal-team production-smoke entitlement activated as
    active/source=api. The observed plan identifier internal is not customer
    billing or checkout proof. The provider route returned HTTP 200 after
    activation with metadata_only/configured_unverified; that proves
    configuration metadata and route gating, not end-to-end provider inference.
    Cache-only provider access remained denied with HTTP 403; the browser produced
    one redacted Verify API Key result and zero console warnings or errors.
  • Evidence:
    docs/evidence/v1.0.4-publication-proof.json,
    external proof-manifest SHA-256
    29a6ac64f828cf4fe10ad4e299ab0a14447a772c7c8d8b2c815e995468d784d8,
    attested lifecycle aggregate
  • Rollback reference: source baseline refs/tags/v1.0.3 in an isolated recovery
    checkout. v1.0.4 has no authorized npm predecessor-rollback command: the
    current workflow supports forward publication and bounded v1.0.4 recovery,
    not moving latest backward. Channel rollback is owner-gated under #559;
    do not republish immutable versions or mutate dist-tags as an ad hoc shortcut.
  • Proof tier: public release plus installed-package activation/dashboard/browser
    smoke; not signed Mac, customer-runtime, parity, or v1.1 proof