ForgeGuard 0.2.2
Truth-correction and semantic-integrity release for the read-only Gitea posture checker.
Corrected
- require trusted Gitea product confirmation for Gitea advisory conclusions
- model CVE-2026-27771 as affected, fixed, or unknown version posture
- produce N/A when core evidence is indeterminate
- keep browser and API evidence ownership disjoint
- require an explicit non-empty remote version before reporting disclosure
- neutralize untrusted Markdown output and refuse output-path collisions
- reject nested encoded dot segments and backslash separators
Release safety
- Python 3.11 and 3.12 quality matrix
- wheel and sdist validation
- exact-wheel install, metadata, dependency, and CLI smoke gates
ForgeGuard remains GET-only, single-target, and limited to instances the operator owns or is explicitly authorized to assess.