Repository navigation
Releases: uknoAI/kno
Release list
v0.2.2
0.2.2 (2026-09-10)
Bug Fixes
Documentation
Build & Dependencies
Verifying this release
Every artifact below is covered by checksums.txt, and checksums.txt is
signed with cosign keyless — there is no
private key, so there is none to steal. Each archive also ships an SPDX
SBOM, and the whole set carries SLSA build provenance.
# 1. The checksum file is really ours, and really came from this workflow.
cosign verify-blob checksums.txt \
--certificate checksums.txt.pem \
--signature checksums.txt.sig \
--certificate-identity-regexp '^https://github\.com/uknoAI/kno/\.github/workflows/release\.yml@refs/tags/.+$' \
--certificate-oidc-issuer https://token.actions.githubusercontent.com
# 2. Your download is really what the checksum file names. Substitute the
# archive you actually downloaded. Written this way because macOS has no
# sha256sum, and its shasum does not understand --ignore-missing.
grep " kno_0.2.2_darwin_arm64.tar.gz$" checksums.txt | shasum -a 256 -c -
# 3. It was built by GitHub Actions from this repository, not on a laptop.
gh attestation verify kno_0.2.2_linux_amd64.tar.gz \
--repo uknoAI/kno \
--signer-workflow uknoAI/kno/.github/workflows/release.ymlBoth identity flags are load-bearing. Without --certificate-identity-regexp,
verify-blob accepts a valid signature from anybody at all; without
--signer-workflow, attestation verify accepts an attestation from any
workflow in the repository. Anchored, they say this file built this binary.
Built with -trimpath, and timestamped from the commit rather than the
clock, so these archives are byte-reproducible — by anyone using the Go
toolchain pinned in this tag's go.mod. A different toolchain produces a
different binary; that is a property of Go, not of this pipeline.
Checksums (SHA-256)
d8a9e3cfdd565a78a51985f8a832df519da5a52ac1066cbf5beff79ac64c1877 kno_0.2.2_darwin_amd64.tar.gz
3d2c394f6da15cfb8a7069b143140c02a97fc18aa6f43d1d3e82fc6170a8b7e5 kno_0.2.2_darwin_amd64.tar.gz.sbom.json
c76875edf3795bd244885d90d8a1433045dd488959892cbf10774c803522fff3 kno_0.2.2_darwin_arm64.tar.gz
f4dc7212247d6d236de67c5932174776cea27f2136f958ec8c70791af11b41e4 kno_0.2.2_darwin_arm64.tar.gz.sbom.json
195166275be9b87aad0cfcb1df48b805f12ee01cf847f4b35b9b499147431f2f kno_0.2.2_linux_amd64.tar.gz
a6c89169aa86e3063e22fa826cda80226f2838d862f13dc56bdbefefa43f2fb5 kno_0.2.2_linux_amd64.tar.gz.sbom.json
91094316e2c1f4a26c794533a5fdaa71af02bd98462d86b805a855d3cce97517 kno_0.2.2_linux_arm64.tar.gz
c22ce3f3a79b20500e4eca267ba17e4315a4e68e80a850a74d7a911076441e39 kno_0.2.2_linux_arm64.tar.gz.sbom.json
ef20148aacf3b049eb7f6e3fe9f2d4ec8bdcdbd7e105fba07c7a2f788cd7955f kno_0.2.2_windows_amd64.zip
3c6b3965662736e35d1f09a9a3c25f6443ba294f5265aae9b29510e856c7be9d kno_0.2.2_windows_amd64.zip.sbom.json
493bf3caef6161bfa8ea9b3915e86f54efc8f6ec200a957554dfdc2157e94ef9 kno_0.2.2_windows_arm64.zip
364b22580bcf848679f843c310defde7468ab393c150b7ddf91242d706af7528 kno_0.2.2_windows_arm64.zip.sbom.json
v0.2.1
0.2.1 (2026-09-04)
Features
- bridge: price the eval pass instead of asserting it free (#209) (9a73019)
- tuner: an OpenAI Tuner, and a conformance suite that spans both (#211) (d6fdd6f)
Bug Fixes
- bridge: enforce --bridge-max-serve-minutes during a live run (#206) (2fcae7c)
- bridge: refuse a ready Endpoint that carries no ReadyAt (#208) (5f64979)
Documentation
- fold the hand-written changelog into v0.2.0 (#213) (0435155)
- plans: rewrite the OpenAI Tuner plan after Phase 1 review (#205) (eaedcd3)
Verifying this release
Every artifact below is covered by checksums.txt, and checksums.txt is
signed with cosign keyless — there is no
private key, so there is none to steal. Each archive also ships an SPDX
SBOM, and the whole set carries SLSA build provenance.
# 1. The checksum file is really ours, and really came from this workflow.
cosign verify-blob checksums.txt \
--certificate checksums.txt.pem \
--signature checksums.txt.sig \
--certificate-identity-regexp '^https://github\.com/uknoAI/kno/\.github/workflows/release\.yml@refs/tags/.+$' \
--certificate-oidc-issuer https://token.actions.githubusercontent.com
# 2. Your download is really what the checksum file names. Substitute the
# archive you actually downloaded. Written this way because macOS has no
# sha256sum, and its shasum does not understand --ignore-missing.
grep " kno_0.2.1_darwin_arm64.tar.gz$" checksums.txt | shasum -a 256 -c -
# 3. It was built by GitHub Actions from this repository, not on a laptop.
gh attestation verify kno_0.2.1_linux_amd64.tar.gz \
--repo uknoAI/kno \
--signer-workflow uknoAI/kno/.github/workflows/release.ymlBoth identity flags are load-bearing. Without --certificate-identity-regexp,
verify-blob accepts a valid signature from anybody at all; without
--signer-workflow, attestation verify accepts an attestation from any
workflow in the repository. Anchored, they say this file built this binary.
Built with -trimpath, and timestamped from the commit rather than the
clock, so these archives are byte-reproducible — by anyone using the Go
toolchain pinned in this tag's go.mod. A different toolchain produces a
different binary; that is a property of Go, not of this pipeline.
Checksums (SHA-256)
851130c22b4c5f72f04184bdc54ed77dccac72b885e8670105f749efa26f40e0 kno_0.2.1_darwin_amd64.tar.gz
0bac213e7cb27436d8f03d019e319227d8ba109e85ddaacd62073b9954a3fb27 kno_0.2.1_darwin_amd64.tar.gz.sbom.json
a0f07c2cb8da732d543040563514292b6e8aed2ee7f7fcf7909c61d9fe08b055 kno_0.2.1_darwin_arm64.tar.gz
a2542f28f8b59b3782237f7a034943c1ff91d79cae0cd1c0339cb1f0eb896487 kno_0.2.1_darwin_arm64.tar.gz.sbom.json
f3d4dc7b020521584349372bae3fbab5426063d6c3a8989582895a80a96a8a84 kno_0.2.1_linux_amd64.tar.gz
8ae08114e67eaee1d1b3d80738d765db99524daad19c9a94dfb59767f906a4a7 kno_0.2.1_linux_amd64.tar.gz.sbom.json
1f8524b698c4fd8a60a55a7fa460c92168f55cdaf598231d449eff531fb078a3 kno_0.2.1_linux_arm64.tar.gz
a9b959baf47851bc28275c0896384ed176b87559e5e4e9f5ac1808826d5516e2 kno_0.2.1_linux_arm64.tar.gz.sbom.json
cf6aef2b8483bc9d10c2227c1121f6e17e27ee25f8e4e0f066f390fc47b11e3a kno_0.2.1_windows_amd64.zip
7bc2de92a4e55388d8b667816e9d320d3f16f11c1e08b2b65db0f6032f7731a5 kno_0.2.1_windows_amd64.zip.sbom.json
fb64db414fd3c096d32fe735b4b0112b9bb691709773a52d2e6a36f7718966c5 kno_0.2.1_windows_arm64.zip
a5321c13f9e051b85081ae28a7708bc8e414ef4941848cdee16cf73d66705b19 kno_0.2.1_windows_arm64.zip.sbom.json
v0.2.0
0.2.0 (2026-09-02)
⚠ BREAKING CHANGES
- core.Tuner gained Deploy, Teardown, ListJobs and ListEndpoints, and store.Store gained WriteTuningJob, UpdateTuningJob, TuningJobs, LeakedEndpoints, WriteValidation, Validation and RecordHoldoutUse. An out-of-tree implementation of either interface must add them. The store schema moves 6 to 8: a 0.1.x database is readable by 0.2.0, a 0.2.0 database is not readable by 0.1.x.
Bug Fixes
Documentation
- fold v0.1.7, and give the 0.2.0 breaking changes their notice (#203) (4598b4b)
- re-record the quickstart GIF for v0.1.7 (#199) (19ba099)
Verifying this release
Every artifact below is covered by checksums.txt, and checksums.txt is
signed with cosign keyless — there is no
private key, so there is none to steal. Each archive also ships an SPDX
SBOM, and the whole set carries SLSA build provenance.
# 1. The checksum file is really ours, and really came from this workflow.
cosign verify-blob checksums.txt \
--certificate checksums.txt.pem \
--signature checksums.txt.sig \
--certificate-identity-regexp '^https://github\.com/uknoAI/kno/\.github/workflows/release\.yml@refs/tags/.+$' \
--certificate-oidc-issuer https://token.actions.githubusercontent.com
# 2. Your download is really what the checksum file names. Substitute the
# archive you actually downloaded. Written this way because macOS has no
# sha256sum, and its shasum does not understand --ignore-missing.
grep " kno_0.2.0_darwin_arm64.tar.gz$" checksums.txt | shasum -a 256 -c -
# 3. It was built by GitHub Actions from this repository, not on a laptop.
gh attestation verify kno_0.2.0_linux_amd64.tar.gz \
--repo uknoAI/kno \
--signer-workflow uknoAI/kno/.github/workflows/release.ymlBoth identity flags are load-bearing. Without --certificate-identity-regexp,
verify-blob accepts a valid signature from anybody at all; without
--signer-workflow, attestation verify accepts an attestation from any
workflow in the repository. Anchored, they say this file built this binary.
Built with -trimpath, and timestamped from the commit rather than the
clock, so these archives are byte-reproducible — by anyone using the Go
toolchain pinned in this tag's go.mod. A different toolchain produces a
different binary; that is a property of Go, not of this pipeline.
Checksums (SHA-256)
53314e351e72a523ee193e8c4663062057b234ec0f922eb970e10bb1fbb13e62 kno_0.2.0_darwin_amd64.tar.gz
bfc73537576e3a588145f5ba54d330f533eebbd7d7092d101b11e67b0633ecb7 kno_0.2.0_darwin_amd64.tar.gz.sbom.json
d2fd30b61e3895da31d514ce63deb6748cce0f5d4fdfc541b72ef977ba607e84 kno_0.2.0_darwin_arm64.tar.gz
5273b08544b49da8a37d2129429bd055ebcc4f0fbc88112eab96b6aa51bb02c2 kno_0.2.0_darwin_arm64.tar.gz.sbom.json
f6a054840649d3dcf1bf8a07e4591911b25fa724ed1b870229cf642d92410fc1 kno_0.2.0_linux_amd64.tar.gz
1ea40fc1d09a3dca02478c755c12dd34ba2a779aded171134e29bbf9b6db79e5 kno_0.2.0_linux_amd64.tar.gz.sbom.json
4107d1b5f3cbe7b12fb9f1e38d4c0f61860038127f0b29538b51d9df0977b1e5 kno_0.2.0_linux_arm64.tar.gz
92013983a4b0886646f4e15c8025dd40822230112d945967f8539426c56e7fdb kno_0.2.0_linux_arm64.tar.gz.sbom.json
50cb927c78d76e588e7d20cc8f3157d46917d777736d339c9313dbdbb1781b2a kno_0.2.0_windows_amd64.zip
d6d41e3926cb442198d7ba53c3d11a9ec5fb297ba048b9af90a8674917b05baa kno_0.2.0_windows_amd64.zip.sbom.json
e4fbaaa8af693df1f29072fe4ab3f385df3529ce5a2301f70e97bb0e73d3dc5a kno_0.2.0_windows_arm64.zip
99a4162fb079154746f77924802a630206555ec9c5f46c8ca40a93a360cc1cd6 kno_0.2.0_windows_arm64.zip.sbom.json
v0.1.7
0.1.7 (2026-09-01)
Features
Bug Fixes
- build: the ledger gate reads a minor series, and the v0.2 audit disposes every open entry (#193) (099a82f)
- docs: repair the CHANGELOG, and refuse conflict markers in future (#196) (c0f5692)
- value: the treatment arm carries the Asset's content (#190) (8f09b10)
Documentation
- adr: measured redundancy is cut from v0.2 (#191) (cea92c6)
- correct the v0.2 scope after two cuts (#192) (3726be0)
- fold the hand-written changelog into v0.1.6 (#197) (66c2a18)
- plans: the bridge measurement seam (#189) (ae955db)
- tombstone calibrate-a-judge — the cookbook migration is finished (#188) (6ab9937)
- tombstone check-your-evals, and fix the README's self-contradicting example (#185) (c8e0d62)
Build & Dependencies
Verifying this release
Every artifact below is covered by checksums.txt, and checksums.txt is
signed with cosign keyless — there is no
private key, so there is none to steal. Each archive also ships an SPDX
SBOM, and the whole set carries SLSA build provenance.
# 1. The checksum file is really ours, and really came from this workflow.
cosign verify-blob checksums.txt \
--certificate checksums.txt.pem \
--signature checksums.txt.sig \
--certificate-identity-regexp '^https://github\.com/uknoAI/kno/\.github/workflows/release\.yml@refs/tags/.+$' \
--certificate-oidc-issuer https://token.actions.githubusercontent.com
# 2. Your download is really what the checksum file names. Substitute the
# archive you actually downloaded. Written this way because macOS has no
# sha256sum, and its shasum does not understand --ignore-missing.
grep " kno_0.1.7_darwin_arm64.tar.gz$" checksums.txt | shasum -a 256 -c -
# 3. It was built by GitHub Actions from this repository, not on a laptop.
gh attestation verify kno_0.1.7_linux_amd64.tar.gz \
--repo uknoAI/kno \
--signer-workflow uknoAI/kno/.github/workflows/release.ymlBoth identity flags are load-bearing. Without --certificate-identity-regexp,
verify-blob accepts a valid signature from anybody at all; without
--signer-workflow, attestation verify accepts an attestation from any
workflow in the repository. Anchored, they say this file built this binary.
Built with -trimpath, and timestamped from the commit rather than the
clock, so these archives are byte-reproducible — by anyone using the Go
toolchain pinned in this tag's go.mod. A different toolchain produces a
different binary; that is a property of Go, not of this pipeline.
Checksums (SHA-256)
cbe9727268c37d76232d04ea446a7cf62db3d64e366b081c3fd50a4a2b1b5daf kno_0.1.7_darwin_amd64.tar.gz
35e52d57b4f1fe9a04d9a59720240f52d250368e84c23257ddd56a65ecd2ee08 kno_0.1.7_darwin_amd64.tar.gz.sbom.json
5e8d442d7867f075ba8c747b2a24db62c6d64071d31c2ec3a62c8b9165b538eb kno_0.1.7_darwin_arm64.tar.gz
f9ec15de7166b1daaf0725e7d94f9654c6f5f779ee68e3ac0fcf35062512cf32 kno_0.1.7_darwin_arm64.tar.gz.sbom.json
db4ddb1441bf3d4d8b83203eff5e1ed6635d368bc94e96bcc45206ef72eecad3 kno_0.1.7_linux_amd64.tar.gz
334c8f8830eab990b4de69217066c05e58aebaf448a5a6048852335a3e7bd946 kno_0.1.7_linux_amd64.tar.gz.sbom.json
b2381d7d9d3bd98db0a4c9cecc6cf3b6a921584ef416e067d6906efc5a1e8cee kno_0.1.7_linux_arm64.tar.gz
492a14dcc9f938e0efd0c6fa7dea583371b9e52ab3a311cefa7a407ee52f515a kno_0.1.7_linux_arm64.tar.gz.sbom.json
866e5c6ca65a2fbc1fb5ec600800ddeb59461baa54b0138a7ad8b80b34addf71 kno_0.1.7_windows_amd64.zip
9455a30f9c624e9b8e3453cc92f3cd3bae0b13756d1b9f9f97685a94834d2ef5 kno_0.1.7_windows_amd64.zip.sbom.json
fe74412b2c25224c733b593382dcbf311c61c70a1b8e617d9375e6bdcd8569a1 kno_0.1.7_windows_arm64.zip
ce42cecf77c3a82dd2398d6ef9cd2a03353571015e1f0333854a12b68710616e kno_0.1.7_windows_arm64.zip.sbom.json
v0.1.6
0.1.6 (2026-09-01)
Bug Fixes
- export: a tuning set carries an assistant turn to train on (#183) (5cf4ab2)
- stats: a sample with no spread no longer reports certainty (#182) (9e88389)
Documentation
Verifying this release
Every artifact below is covered by checksums.txt, and checksums.txt is
signed with cosign keyless — there is no
private key, so there is none to steal. Each archive also ships an SPDX
SBOM, and the whole set carries SLSA build provenance.
# 1. The checksum file is really ours, and really came from this workflow.
cosign verify-blob checksums.txt \
--certificate checksums.txt.pem \
--signature checksums.txt.sig \
--certificate-identity-regexp '^https://github\.com/uknoAI/kno/\.github/workflows/release\.yml@refs/tags/.+$' \
--certificate-oidc-issuer https://token.actions.githubusercontent.com
# 2. Your download is really what the checksum file names. Substitute the
# archive you actually downloaded. Written this way because macOS has no
# sha256sum, and its shasum does not understand --ignore-missing.
grep " kno_0.1.6_darwin_arm64.tar.gz$" checksums.txt | shasum -a 256 -c -
# 3. It was built by GitHub Actions from this repository, not on a laptop.
gh attestation verify kno_0.1.6_linux_amd64.tar.gz \
--repo uknoAI/kno \
--signer-workflow uknoAI/kno/.github/workflows/release.ymlBoth identity flags are load-bearing. Without --certificate-identity-regexp,
verify-blob accepts a valid signature from anybody at all; without
--signer-workflow, attestation verify accepts an attestation from any
workflow in the repository. Anchored, they say this file built this binary.
Built with -trimpath, and timestamped from the commit rather than the
clock, so these archives are byte-reproducible — by anyone using the Go
toolchain pinned in this tag's go.mod. A different toolchain produces a
different binary; that is a property of Go, not of this pipeline.
Checksums (SHA-256)
4e54d2b0ce5418db536aaaaa48cc2b926f908aca1e03e948f9a7fed0e3a51997 kno_0.1.6_darwin_amd64.tar.gz
9a4871db7cf8843f660d5be8f853ccb6ff6c083596f6bb6b12aacadc2d5a310c kno_0.1.6_darwin_amd64.tar.gz.sbom.json
1938030c14e38934da12b965a71166177eb7f76bbc23cb982720609a1348d5ec kno_0.1.6_darwin_arm64.tar.gz
eb1a276b0cb0cbf1b1a27ef02c103745c8e8400b41decaef1d91ef455541a022 kno_0.1.6_darwin_arm64.tar.gz.sbom.json
0dc81124997489b21f07ba24e7b437b7d39a0816570fae8873d4fb8962e16a3b kno_0.1.6_linux_amd64.tar.gz
fcb1cd5d9c0e654a3907f5a5966231b5169fa8d309eb4b1918d149192ef0438c kno_0.1.6_linux_amd64.tar.gz.sbom.json
0b19739947e04242aa2419632f9da7380d61f610d677aebd7b4e219e6f6c1cc2 kno_0.1.6_linux_arm64.tar.gz
4a861c7ced8f55739643bc89eda3e55e898e765bdc0dc9725ad1efb2ef59e484 kno_0.1.6_linux_arm64.tar.gz.sbom.json
71acf1ba11ed11dd801c6cb35922a9819584bf64b5fe0734e588d44f8e3e4759 kno_0.1.6_windows_amd64.zip
4ac2e0acbc6a7496f4ddf28588acbed970bbafeb0dd0ceb2f0524896a5f5d334 kno_0.1.6_windows_amd64.zip.sbom.json
a1e6d041437a6f38fc30788914f570b55762f669dec284eee294d96ff7b8eb82 kno_0.1.6_windows_arm64.zip
b47efdf3df9fe32659de485bb95a4c541cf839b55ada116ad57ecc160d6df5d2 kno_0.1.6_windows_arm64.zip.sbom.json
v0.1.5
0.1.5 (2026-09-01)
Features
Bug Fixes
- release: fold the changelog correctly, and stop it racing the tag (#174) (9112255)
- validate: a resumed run restores the tokens it spent (#172) (14291c8)
Documentation
Build & Dependencies
Verifying this release
Every artifact below is covered by checksums.txt, and checksums.txt is
signed with cosign keyless — there is no
private key, so there is none to steal. Each archive also ships an SPDX
SBOM, and the whole set carries SLSA build provenance.
# 1. The checksum file is really ours, and really came from this workflow.
cosign verify-blob checksums.txt \
--certificate checksums.txt.pem \
--signature checksums.txt.sig \
--certificate-identity-regexp '^https://github\.com/uknoAI/kno/\.github/workflows/release\.yml@refs/tags/.+$' \
--certificate-oidc-issuer https://token.actions.githubusercontent.com
# 2. Your download is really what the checksum file names. Substitute the
# archive you actually downloaded. Written this way because macOS has no
# sha256sum, and its shasum does not understand --ignore-missing.
grep " kno_0.1.5_darwin_arm64.tar.gz$" checksums.txt | shasum -a 256 -c -
# 3. It was built by GitHub Actions from this repository, not on a laptop.
gh attestation verify kno_0.1.5_linux_amd64.tar.gz \
--repo uknoAI/kno \
--signer-workflow uknoAI/kno/.github/workflows/release.ymlBoth identity flags are load-bearing. Without --certificate-identity-regexp,
verify-blob accepts a valid signature from anybody at all; without
--signer-workflow, attestation verify accepts an attestation from any
workflow in the repository. Anchored, they say this file built this binary.
Built with -trimpath, and timestamped from the commit rather than the
clock, so these archives are byte-reproducible — by anyone using the Go
toolchain pinned in this tag's go.mod. A different toolchain produces a
different binary; that is a property of Go, not of this pipeline.
Checksums (SHA-256)
a02a4ba1ecd8efac146c14244b3ac5ea9c880681ecf99cd042ee8d8413fb166a kno_0.1.5_darwin_amd64.tar.gz
305dc74cb777bd6132d0e12b7abf81a47d073e1393dc7645271635c7de69ac84 kno_0.1.5_darwin_amd64.tar.gz.sbom.json
02fb6bf297e35fc98cebe56a43cc71f8a1609602a5f3eabb36ca7fb19c6f4507 kno_0.1.5_darwin_arm64.tar.gz
9c94becc93b5b4bfaa0b5ca0a617e80fda8cce52500afb858fbd34eb586cab7b kno_0.1.5_darwin_arm64.tar.gz.sbom.json
0b9492eacb519ea49e2d28202118d993151b8be4e857fe764a9263163e7f9d09 kno_0.1.5_linux_amd64.tar.gz
4cb7feb72f3fc0ab464c7bc8bdebed213a06d7cbe51c7eef3b72ae6f57e847fe kno_0.1.5_linux_amd64.tar.gz.sbom.json
87607895643550635d4e71185ea49c76e4bd09a7a3f16ebba397b5f13095446f kno_0.1.5_linux_arm64.tar.gz
429f07e187e407e9a6471b61c51ef590ad899255adce1a399ce19141a481110c kno_0.1.5_linux_arm64.tar.gz.sbom.json
45f2d6f12e1512b2f2b8246a1696cc63716c6ff404fbeb9b443cb4a3f05ea9d3 kno_0.1.5_windows_amd64.zip
500a147a6e1d4bdf744f26ce080b3ec55b883dcb4a5f4f1f0ff96e3ee47b6320 kno_0.1.5_windows_amd64.zip.sbom.json
cbf3d95dff3f908505f696ac02bff7f5634453a6248a5e063fa33c9273e7ed7a kno_0.1.5_windows_arm64.zip
8f9fc236002878f18f8cf5d9263ea52c3ecae1281a4937a54c2482f8367631c0 kno_0.1.5_windows_arm64.zip.sbom.json
v0.1.4
0.1.4 (2026-09-01)
Features
- every stage reports what it spent, or says it could not (#168) (dd5f0e9)
- kno validate — the holdout finally speaks (#169) (e13b558)
Bug Fixes
- build: the ledger gate refuses duplicate entry ids (#166) (7055062)
- value: a resumed run restores the tokens it spent (#170) (00f0044)
Documentation
- debt: dispose four silent lapses and backstop seven vague triggers (#167) (706b186)
- fold the hand-written changelog into v0.1.3 (#164) (788c09f)
- move the cookbook to uknoAI/kno-examples, leaving tombstones (#163) (94f32df)
Verifying this release
Every artifact below is covered by checksums.txt, and checksums.txt is
signed with cosign keyless — there is no
private key, so there is none to steal. Each archive also ships an SPDX
SBOM, and the whole set carries SLSA build provenance.
# 1. The checksum file is really ours, and really came from this workflow.
cosign verify-blob checksums.txt \
--certificate checksums.txt.pem \
--signature checksums.txt.sig \
--certificate-identity-regexp '^https://github\.com/uknoAI/kno/\.github/workflows/release\.yml@refs/tags/.+$' \
--certificate-oidc-issuer https://token.actions.githubusercontent.com
# 2. Your download is really what the checksum file names. Substitute the
# archive you actually downloaded. Written this way because macOS has no
# sha256sum, and its shasum does not understand --ignore-missing.
grep " kno_0.1.4_darwin_arm64.tar.gz$" checksums.txt | shasum -a 256 -c -
# 3. It was built by GitHub Actions from this repository, not on a laptop.
gh attestation verify kno_0.1.4_linux_amd64.tar.gz \
--repo uknoAI/kno \
--signer-workflow uknoAI/kno/.github/workflows/release.ymlBoth identity flags are load-bearing. Without --certificate-identity-regexp,
verify-blob accepts a valid signature from anybody at all; without
--signer-workflow, attestation verify accepts an attestation from any
workflow in the repository. Anchored, they say this file built this binary.
Built with -trimpath, and timestamped from the commit rather than the
clock, so these archives are byte-reproducible — by anyone using the Go
toolchain pinned in this tag's go.mod. A different toolchain produces a
different binary; that is a property of Go, not of this pipeline.
Checksums (SHA-256)
c5123fd8e80c02bac8433ebe2a7ddd4f16c78b9ff27b0be8581dcaf546a9585d kno_0.1.4_darwin_amd64.tar.gz
e3942a1143aec090d6af329e319f61176be87a55fd0bed8989fc61b34f426800 kno_0.1.4_darwin_amd64.tar.gz.sbom.json
b5bf2c1e71251d089a3f07347e071d484e7c463acbccbc31bdf5354dd0fc9e7a kno_0.1.4_darwin_arm64.tar.gz
bba3d0f19b4a5c355a3d1e8875061f9c6fafa5b79ac815b2dd707421e76aa66b kno_0.1.4_darwin_arm64.tar.gz.sbom.json
d87d5c3e2a4e688b44a446f722b0c17efaf2b2716735ddc44e5f506a59f1de90 kno_0.1.4_linux_amd64.tar.gz
f7878d8dc461b3179362a33c7310d8bff535de4fbfecabb802b918c54149af59 kno_0.1.4_linux_amd64.tar.gz.sbom.json
626a29b12c3911c6f9259d726058b2d24968b88ba153b73c20c06e439deecc60 kno_0.1.4_linux_arm64.tar.gz
18f613d5dde19c7d179acafd26bc4f493f85d80097d90821622f4fdceb0d28ce kno_0.1.4_linux_arm64.tar.gz.sbom.json
c22cdce7d99bf044cfdb9f63b03a3fe2612aecb520605783345cc81e52a4673a kno_0.1.4_windows_amd64.zip
466c2483cc47da944321366b92b0975ac0e702c4538fd79584fd50d028522d36 kno_0.1.4_windows_amd64.zip.sbom.json
d6abad3dba5dffa391436a4dfee4727ab39a2d77d7c71fecf8e7f9ced919bd0f kno_0.1.4_windows_arm64.zip
07318f256f698912976ec6e56b1393ff902b179b0ce680c6511505ad475d06a0 kno_0.1.4_windows_arm64.zip.sbom.json
v0.1.3
0.1.3 (2026-08-31)
Features
- docs/status.json — generated status data for the site, gated in make check (#150) (cb50d5b)
- kno eval inspect — whether an eval set can support attribution (#155) (18ebb4a)
Bug Fixes
- cli: kno export --json names the Select run it rendered from (#156) (074d73f)
- core: the rejection log prints bounds at four places, not seventeen (#157) (350bc01)
- value: the harm bound is the exact t quantile, not z beyond df=30 (#158) (4622b90)
Documentation
- answer the examples plan's blocking question by reading kno-www (#146) (9bc5c47)
- debt: record two live defects found by the v0.2 Phase-0 workstreams (#159) (37967e5)
- fold the hand-written changelog into v0.1.2 (#145) (bd858c3)
- Phase-0 plans for v0.2, all adversarially reviewed (#161) (83c7641)
- stop advertising an on-ramp that does not exist yet (#162) (89ce9ee)
Build & Dependencies
Verifying this release
Every artifact below is covered by checksums.txt, and checksums.txt is
signed with cosign keyless — there is no
private key, so there is none to steal. Each archive also ships an SPDX
SBOM, and the whole set carries SLSA build provenance.
# 1. The checksum file is really ours, and really came from this workflow.
cosign verify-blob checksums.txt \
--certificate checksums.txt.pem \
--signature checksums.txt.sig \
--certificate-identity-regexp '^https://github\.com/uknoAI/kno/\.github/workflows/release\.yml@refs/tags/.+$' \
--certificate-oidc-issuer https://token.actions.githubusercontent.com
# 2. Your download is really what the checksum file names. Substitute the
# archive you actually downloaded. Written this way because macOS has no
# sha256sum, and its shasum does not understand --ignore-missing.
grep " kno_0.1.3_darwin_arm64.tar.gz$" checksums.txt | shasum -a 256 -c -
# 3. It was built by GitHub Actions from this repository, not on a laptop.
gh attestation verify kno_0.1.3_linux_amd64.tar.gz \
--repo uknoAI/kno \
--signer-workflow uknoAI/kno/.github/workflows/release.ymlBoth identity flags are load-bearing. Without --certificate-identity-regexp,
verify-blob accepts a valid signature from anybody at all; without
--signer-workflow, attestation verify accepts an attestation from any
workflow in the repository. Anchored, they say this file built this binary.
Built with -trimpath, and timestamped from the commit rather than the
clock, so these archives are byte-reproducible — by anyone using the Go
toolchain pinned in this tag's go.mod. A different toolchain produces a
different binary; that is a property of Go, not of this pipeline.
Checksums (SHA-256)
301577503df566f38c4145f8e59d75c0a5677a19da61a5e9f1e00277fe3e5aff kno_0.1.3_darwin_amd64.tar.gz
c5efc53ce6125026a64e52f619f8d2c855e72a21e5af9519120bf96862d17b23 kno_0.1.3_darwin_amd64.tar.gz.sbom.json
6bd303d696e84f2f5802c96f990324e2a2ff1cac530ef0970a2b4766bd7e6111 kno_0.1.3_darwin_arm64.tar.gz
2bc11e7025f93fabac97f007d9bd6577ffc7f58300dec7c7b1ff4f4135582c61 kno_0.1.3_darwin_arm64.tar.gz.sbom.json
bb5c5940318686a67982a67167c2207b4713c0c52a48949756e0ce1384d2fbc5 kno_0.1.3_linux_amd64.tar.gz
ed11c0967b2e321b62e2fd107f71346c34eb4d0630fb2a43240ae7b18e98a60a kno_0.1.3_linux_amd64.tar.gz.sbom.json
9730cd82aac43166a0c1cc1ee8f47b342b8d1a71677434a9630b50f73d49e1d2 kno_0.1.3_linux_arm64.tar.gz
83ce40e10df6d457586726c7ef848cfa6962af055659072bd9268a2551de8cc0 kno_0.1.3_linux_arm64.tar.gz.sbom.json
49fd45501719037a83bb111f5060c64480ef457464dca84f470b849601b28d4c kno_0.1.3_windows_amd64.zip
148d9f34c04ba8edfd07ca48d9e80607785fa02144a7082d648e101637558a39 kno_0.1.3_windows_amd64.zip.sbom.json
1cec39dfea9d75ed036116da65f8b847661576aa9034c18640f9126be4a44aa0 kno_0.1.3_windows_arm64.zip
042208cc3149407f52b7d22e361ae2ee24019d753a496c301ddbc276530d1f01 kno_0.1.3_windows_arm64.zip.sbom.json
v0.1.2
0.1.2 (2026-08-31)
Features
Bug Fixes
- ci: the release commit signs itself, and the DCO check stops failing correct trailers (#142) (63cfa20)
Documentation
- adapters: package godoc names only the adapters that exist (#141) (dec47a8)
- evaluation best practices in the README, and the deep evaluation-design guide (#137) (bfb85c7)
- Phase-0 plans for the next body of work, all adversarially reviewed (#140) (648effb)
- the quickstart tape shows the intervals it claims (#143) (1c6403f)
- the README quickstart Case matches the recorded tape (#139) (20c7dfe)
Verifying this release
Every artifact below is covered by checksums.txt, and checksums.txt is
signed with cosign keyless — there is no
private key, so there is none to steal. Each archive also ships an SPDX
SBOM, and the whole set carries SLSA build provenance.
# 1. The checksum file is really ours, and really came from this workflow.
cosign verify-blob checksums.txt \
--certificate checksums.txt.pem \
--signature checksums.txt.sig \
--certificate-identity-regexp '^https://github\.com/uknoAI/kno/\.github/workflows/release\.yml@refs/tags/.+$' \
--certificate-oidc-issuer https://token.actions.githubusercontent.com
# 2. Your download is really what the checksum file names. Substitute the
# archive you actually downloaded. Written this way because macOS has no
# sha256sum, and its shasum does not understand --ignore-missing.
grep " kno_0.1.2_darwin_arm64.tar.gz$" checksums.txt | shasum -a 256 -c -
# 3. It was built by GitHub Actions from this repository, not on a laptop.
gh attestation verify kno_0.1.2_linux_amd64.tar.gz \
--repo uknoAI/kno \
--signer-workflow uknoAI/kno/.github/workflows/release.ymlBoth identity flags are load-bearing. Without --certificate-identity-regexp,
verify-blob accepts a valid signature from anybody at all; without
--signer-workflow, attestation verify accepts an attestation from any
workflow in the repository. Anchored, they say this file built this binary.
Built with -trimpath, and timestamped from the commit rather than the
clock, so these archives are byte-reproducible — by anyone using the Go
toolchain pinned in this tag's go.mod. A different toolchain produces a
different binary; that is a property of Go, not of this pipeline.
Checksums (SHA-256)
c3553dcf0b18271da67622f35a607d88f5f80726e4b78e79d6e8b0102289bb4c kno_0.1.2_darwin_amd64.tar.gz
dc77284b840bfdc493224472df1b09507c18cd3d4cb82a74008d4309207f5497 kno_0.1.2_darwin_amd64.tar.gz.sbom.json
4f05cec1b5bc0e8ba6bc6f6945be09a46567c4059ea2ea7f64273e14335dc33c kno_0.1.2_darwin_arm64.tar.gz
f2c5507a87809d2e82d39978e67740abefdb98c0be6b0da70cab04066af3be98 kno_0.1.2_darwin_arm64.tar.gz.sbom.json
c2c72ba6a11b2ec91cf10c23b250ec6b609e1d7b474b6e95e3733a24a5ca00b7 kno_0.1.2_linux_amd64.tar.gz
24055fd6485c02abbcd7ddb0f60acac2f92063e61c9552504010962716796fec kno_0.1.2_linux_amd64.tar.gz.sbom.json
ce189c541d0622f78c903c63264a7ae62b48e1b83056239ec2d33d93238f5515 kno_0.1.2_linux_arm64.tar.gz
c2ac256493cce9b4ba097b9c845fb27469c21d11ad9997718973dc816fc308f4 kno_0.1.2_linux_arm64.tar.gz.sbom.json
c98fdff62f30e9a01461ac6e37acf59883a2b699e118534ee7dd6e053f84b76a kno_0.1.2_windows_amd64.zip
c39097f06eee92bb310a3997eed4a292143d772f630445130fe0c8918ec235fc kno_0.1.2_windows_amd64.zip.sbom.json
7f927cae0c09bb288e4b8bd04c8c9d84eab775e6c4d2e5cf675e1dd172268f32 kno_0.1.2_windows_arm64.zip
b81edb49aea03aba964302bd132df3cbe18aebac9a58a21248d89e593aebf978 kno_0.1.2_windows_arm64.zip.sbom.json
v0.1.1
0.1.1 (2026-08-31)
Features
- Bedrock and Vertex agent adapters — partner clouds priced (#128) (360cabc)
- Braintrust Evals adapter — fourth core.Evals source (#124) (638e3d2)
- Hugging Face adapters — Evals and Pool (#125) (ebd4d4a)
Documentation
Build & Dependencies
Verifying this release
Every artifact below is covered by checksums.txt, and checksums.txt is
signed with cosign keyless — there is no
private key, so there is none to steal. Each archive also ships an SPDX
SBOM, and the whole set carries SLSA build provenance.
# 1. The checksum file is really ours, and really came from this workflow.
cosign verify-blob checksums.txt \
--certificate checksums.txt.pem \
--signature checksums.txt.sig \
--certificate-identity-regexp '^https://github\.com/uknoAI/kno/\.github/workflows/release\.yml@refs/tags/.+$' \
--certificate-oidc-issuer https://token.actions.githubusercontent.com
# 2. Your download is really what the checksum file names. Substitute the
# archive you actually downloaded. Written this way because macOS has no
# sha256sum, and its shasum does not understand --ignore-missing.
grep " kno_0.1.1_darwin_arm64.tar.gz$" checksums.txt | shasum -a 256 -c -
# 3. It was built by GitHub Actions from this repository, not on a laptop.
gh attestation verify kno_0.1.1_linux_amd64.tar.gz \
--repo uknoAI/kno \
--signer-workflow uknoAI/kno/.github/workflows/release.ymlBoth identity flags are load-bearing. Without --certificate-identity-regexp,
verify-blob accepts a valid signature from anybody at all; without
--signer-workflow, attestation verify accepts an attestation from any
workflow in the repository. Anchored, they say this file built this binary.
Built with -trimpath, and timestamped from the commit rather than the
clock, so these archives are byte-reproducible — by anyone using the Go
toolchain pinned in this tag's go.mod. A different toolchain produces a
different binary; that is a property of Go, not of this pipeline.
Checksums (SHA-256)
3bfa04bcc34b872edbedf2cc83317e8d35cb32dbf931c4bd2bd458db45e15795 kno_0.1.1_darwin_amd64.tar.gz
de13ae519543e75069971b1c9d26cb000b5a27822ca2706b5489f4deef98fb5c kno_0.1.1_darwin_amd64.tar.gz.sbom.json
2011a1e532beda6932195c240fa41b252bba7a26f745a4ccbac3c2b2fcb28633 kno_0.1.1_darwin_arm64.tar.gz
33dabeef8e62c4c4da5427732d1f064484fdb25bd86d7126ae33efac1e3cf0fc kno_0.1.1_darwin_arm64.tar.gz.sbom.json
3f6df988a354ee749f31d393aa762d960f95ffb5a38e4de585698fd4a984dc79 kno_0.1.1_linux_amd64.tar.gz
5bd22f6e3bc4299d94761b59e01950fd565000246bbd3567b4454410d7fc5fb8 kno_0.1.1_linux_amd64.tar.gz.sbom.json
bdc224f6547572258a6e34ea3514ea74daf6e88a4fe142aa376e9710870320a3 kno_0.1.1_linux_arm64.tar.gz
fa959799709699fc0d4e35a601b639b02b1c105e5070278b19832a1c0058ac20 kno_0.1.1_linux_arm64.tar.gz.sbom.json
4b43e1e76d9951254b16fb301483df09c1bba5ce906d4058d6e8e9bbbc2711bc kno_0.1.1_windows_amd64.zip
37dafe9d404d0457d9f605763f76474a54d80a28e2dcbd3b01f6c0cd6e3b9046 kno_0.1.1_windows_amd64.zip.sbom.json
90bfda2b0d0774e58ab3b872f084739c568f3bc051c62ef36ffcaead208d9786 kno_0.1.1_windows_arm64.zip
ef5b8a964f7acb191191d398b850a358af2dbd612dbb39f9dc1ecc783675f227 kno_0.1.1_windows_arm64.zip.sbom.json