0.3.0 - 2026-08-11
Release Notes
Removed
- BREAKING (CLI):
--versionis removed fromossctl release plan/release cut. The release
version now derives solely from the workspace manifest (Cargo.toml) — the single source of
truth. A stray--versionis a hardunexpected argumenterror rather than a silently-ignored (or
drift-guarded) flag. To release a new version, bump the manifest (and finalize the CHANGELOG) in a
release commit first, thenplan/cut(release-drop-version-flag; completes the 0.2.5
single-source work).
Added
- Version-source capability model — non-Rust ecosystems no longer fail open. The version-drift and
self-visibility guards now key on a per-ecosystem version-source: manifest-versioned ecosystems
(rust/node/python) fail closed when a target's version can't be read, while distribution-only
targets (homebrew / raw binary / cargo-dist) are legitimately skipped. Previously any target without
a readable manifest version was silently skipped, so the guards were no-ops for npm/PyPI packages
(version-source-fail-closed-nonrust).
Changed
release cut/resumepublish from a clean checkout of the sealed commit. The engine now
materializes a fresh git-worktree checkout of the sealed plan'shead_shaand runs build/publish/dist
from there, instead of the live (mutable) working tree — a cut is reproducible and immune to mid-cut
edits. It fails closed if the sealed commit isn't available locally; the journal and tag still land in
the real repository (release-cut-clean-checkout).- The resume idempotency skip is digest-authenticated. When a resumed cut finds a crate already
published, it now repackages the target.crate, hashes it, and compares against the registry's
published checksum (crates.io sparse-indexcksum) before trusting the skip: a match records the
digest, a mismatch fails closed (DigestMismatch), and an outage/malformed response fails closed
(RegistryUnavailable) — closing the last "receipt without a verified artifact" path. (The definitive
cross-toolchain-safe form — journaling the intended digest at original-publish time — is tracked in
cargo-publish-receipt-provenance-resume-safety.) (is-published-digest-authenticate)
Install ossctl 0.3.0
Install prebuilt binaries via shell script
curl --proto '=https' --tlsv1.2 -LsSf https://github.com/jarimustonen/ossctl/releases/download/v0.3.0/ossctl-installer.sh | shInstall prebuilt binaries via powershell script
powershell -ExecutionPolicy Bypass -c "irm https://github.com/jarimustonen/ossctl/releases/download/v0.3.0/ossctl-installer.ps1 | iex"Download ossctl 0.3.0
| File | Platform | Checksum |
|---|---|---|
| ossctl-aarch64-apple-darwin.tar.xz | Apple Silicon macOS | checksum |
| ossctl-x86_64-pc-windows-msvc.zip | x64 Windows | checksum |
| ossctl-aarch64-unknown-linux-musl.tar.xz | ARM64 MUSL Linux | checksum |
| ossctl-x86_64-unknown-linux-musl.tar.xz | x64 MUSL Linux | checksum |
Verifying GitHub Artifact Attestations
The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:
gh attestation verify <file-path of downloaded artifact> --repo jarimustonen/ossctlYou can also download the attestation from GitHub and verify against that directly:
gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation>