v0.3.0: Secure Image ID Verification
Breaking Changes
- Security:
Receipt.verify()now requiresimage_idparameter to prevent deriving image ID from untrusted receipt data
What's Changed
Security Improvements
- Enforced external image ID verification in
verify()method - Follows security best practice: never trust data from unverified sources
- Prevents potential security vulnerabilities from trusting receipt-provided image IDs
Test Suite Enhancements
- Added comprehensive test suite with zero-tolerance policy
- Created
run_all_tests.shmaster test runner - All tests and demos now return proper exit codes (0 for success, 1 for failure)
- Test runner aborts immediately on first failure
- Added security verification tests
API Refinements
- Simplified API with consistent naming conventions
- Removed legacy code and unnecessary complexity
- Better error messages and validation
- Cleaner module structure
Files Changed
- Modified receipt verification to require external image ID
- Updated all demos and tests to pass image ID to verify()
- Added new security tests
- Created unified test runner
Installation
# For development
uv tool run maturin build --release
uv pip install --force-reinstall target/wheels/PyR0-*.whlFull Changelog: v0.2.0...v0.3.0