InvarLock 0.14.0 extends the signed evaluation engine with evaluator-neutral
qualification and recipient-controlled acceptance handoff.
Highlights
- Adds source-pinned evaluator qualification profiles, authoritative per-record
import replays, and documented JSON, CLI, and Python adapter contracts for
open-source and proprietary evaluators. - Keeps aggregate-only, unsupported, and non-recomputable judge evidence
observation-only so it cannot silently drive a release verdict. - Adds a canonical in-toto/DSSE acceptance envelope and deterministic offline
artifact-delivery handoff. - Demonstrates standalone OPA/Rego and CUE consumption with accepted,
policy-rejected, tampered-subject, untrusted-signer, stale-evidence, and
unsupported-contract fixtures. - Establishes permanent verification and dossier-ingestion compatibility for
v0.13 evidence while leaving every acceptance outcome under the recipient's
current policy. - Separates envelope-signer and receipt-verifier trust, and prevents a fresh
envelope from renewing stale underlying evidence.
Published packages
invarlockinvarlock-diagnosticsinvarlock-runtime-ggufinvarlock-runtime-hf-vision-textinvarlock-runtime-tensorrt-llm
All packages are published at version 0.14.0. See
CHANGELOG.md
for the complete change list.