Skip to content

Releases: uknoAI/kno

v0.2.2

Choose a tag to compare

@devarispbrown devarispbrown released this 10 Sep 18:38
0e262b5

0.2.2 (2026-09-10)

Bug Fixes

  • build: check the changelog fold at merge, not only at creation (#216) (1a842f5)

Documentation

  • fold the hand-written changelog into v0.2.1 (#214) (d3df2a9)

Build & Dependencies

  • deps: Bump modernc.org/sqlite from 1.57.0 to 1.58.0 (#217) (2d6c0ba)

Verifying this release

Every artifact below is covered by checksums.txt, and checksums.txt is
signed with cosign keyless — there is no
private key, so there is none to steal. Each archive also ships an SPDX
SBOM, and the whole set carries SLSA build provenance.

# 1. The checksum file is really ours, and really came from this workflow.
cosign verify-blob checksums.txt \
  --certificate checksums.txt.pem \
  --signature checksums.txt.sig \
  --certificate-identity-regexp '^https://github\.com/uknoAI/kno/\.github/workflows/release\.yml@refs/tags/.+$' \
  --certificate-oidc-issuer https://token.actions.githubusercontent.com

# 2. Your download is really what the checksum file names. Substitute the
#    archive you actually downloaded. Written this way because macOS has no
#    sha256sum, and its shasum does not understand --ignore-missing.
grep " kno_0.2.2_darwin_arm64.tar.gz$" checksums.txt | shasum -a 256 -c -

# 3. It was built by GitHub Actions from this repository, not on a laptop.
gh attestation verify kno_0.2.2_linux_amd64.tar.gz \
  --repo uknoAI/kno \
  --signer-workflow uknoAI/kno/.github/workflows/release.yml

Both identity flags are load-bearing. Without --certificate-identity-regexp,
verify-blob accepts a valid signature from anybody at all; without
--signer-workflow, attestation verify accepts an attestation from any
workflow in the repository. Anchored, they say this file built this binary.

Built with -trimpath, and timestamped from the commit rather than the
clock, so these archives are byte-reproducible — by anyone using the Go
toolchain pinned in this tag's go.mod. A different toolchain produces a
different binary; that is a property of Go, not of this pipeline.

Checksums (SHA-256)

d8a9e3cfdd565a78a51985f8a832df519da5a52ac1066cbf5beff79ac64c1877  kno_0.2.2_darwin_amd64.tar.gz
3d2c394f6da15cfb8a7069b143140c02a97fc18aa6f43d1d3e82fc6170a8b7e5  kno_0.2.2_darwin_amd64.tar.gz.sbom.json
c76875edf3795bd244885d90d8a1433045dd488959892cbf10774c803522fff3  kno_0.2.2_darwin_arm64.tar.gz
f4dc7212247d6d236de67c5932174776cea27f2136f958ec8c70791af11b41e4  kno_0.2.2_darwin_arm64.tar.gz.sbom.json
195166275be9b87aad0cfcb1df48b805f12ee01cf847f4b35b9b499147431f2f  kno_0.2.2_linux_amd64.tar.gz
a6c89169aa86e3063e22fa826cda80226f2838d862f13dc56bdbefefa43f2fb5  kno_0.2.2_linux_amd64.tar.gz.sbom.json
91094316e2c1f4a26c794533a5fdaa71af02bd98462d86b805a855d3cce97517  kno_0.2.2_linux_arm64.tar.gz
c22ce3f3a79b20500e4eca267ba17e4315a4e68e80a850a74d7a911076441e39  kno_0.2.2_linux_arm64.tar.gz.sbom.json
ef20148aacf3b049eb7f6e3fe9f2d4ec8bdcdbd7e105fba07c7a2f788cd7955f  kno_0.2.2_windows_amd64.zip
3c6b3965662736e35d1f09a9a3c25f6443ba294f5265aae9b29510e856c7be9d  kno_0.2.2_windows_amd64.zip.sbom.json
493bf3caef6161bfa8ea9b3915e86f54efc8f6ec200a957554dfdc2157e94ef9  kno_0.2.2_windows_arm64.zip
364b22580bcf848679f843c310defde7468ab393c150b7ddf91242d706af7528  kno_0.2.2_windows_arm64.zip.sbom.json

v0.2.1

Choose a tag to compare

@devarispbrown devarispbrown released this 04 Sep 02:40
40d3d72

0.2.1 (2026-09-04)

Features

  • bridge: price the eval pass instead of asserting it free (#209) (9a73019)
  • tuner: an OpenAI Tuner, and a conformance suite that spans both (#211) (d6fdd6f)

Bug Fixes

  • bridge: enforce --bridge-max-serve-minutes during a live run (#206) (2fcae7c)
  • bridge: refuse a ready Endpoint that carries no ReadyAt (#208) (5f64979)

Documentation

  • fold the hand-written changelog into v0.2.0 (#213) (0435155)
  • plans: rewrite the OpenAI Tuner plan after Phase 1 review (#205) (eaedcd3)

Verifying this release

Every artifact below is covered by checksums.txt, and checksums.txt is
signed with cosign keyless — there is no
private key, so there is none to steal. Each archive also ships an SPDX
SBOM, and the whole set carries SLSA build provenance.

# 1. The checksum file is really ours, and really came from this workflow.
cosign verify-blob checksums.txt \
  --certificate checksums.txt.pem \
  --signature checksums.txt.sig \
  --certificate-identity-regexp '^https://github\.com/uknoAI/kno/\.github/workflows/release\.yml@refs/tags/.+$' \
  --certificate-oidc-issuer https://token.actions.githubusercontent.com

# 2. Your download is really what the checksum file names. Substitute the
#    archive you actually downloaded. Written this way because macOS has no
#    sha256sum, and its shasum does not understand --ignore-missing.
grep " kno_0.2.1_darwin_arm64.tar.gz$" checksums.txt | shasum -a 256 -c -

# 3. It was built by GitHub Actions from this repository, not on a laptop.
gh attestation verify kno_0.2.1_linux_amd64.tar.gz \
  --repo uknoAI/kno \
  --signer-workflow uknoAI/kno/.github/workflows/release.yml

Both identity flags are load-bearing. Without --certificate-identity-regexp,
verify-blob accepts a valid signature from anybody at all; without
--signer-workflow, attestation verify accepts an attestation from any
workflow in the repository. Anchored, they say this file built this binary.

Built with -trimpath, and timestamped from the commit rather than the
clock, so these archives are byte-reproducible — by anyone using the Go
toolchain pinned in this tag's go.mod. A different toolchain produces a
different binary; that is a property of Go, not of this pipeline.

Checksums (SHA-256)

851130c22b4c5f72f04184bdc54ed77dccac72b885e8670105f749efa26f40e0  kno_0.2.1_darwin_amd64.tar.gz
0bac213e7cb27436d8f03d019e319227d8ba109e85ddaacd62073b9954a3fb27  kno_0.2.1_darwin_amd64.tar.gz.sbom.json
a0f07c2cb8da732d543040563514292b6e8aed2ee7f7fcf7909c61d9fe08b055  kno_0.2.1_darwin_arm64.tar.gz
a2542f28f8b59b3782237f7a034943c1ff91d79cae0cd1c0339cb1f0eb896487  kno_0.2.1_darwin_arm64.tar.gz.sbom.json
f3d4dc7b020521584349372bae3fbab5426063d6c3a8989582895a80a96a8a84  kno_0.2.1_linux_amd64.tar.gz
8ae08114e67eaee1d1b3d80738d765db99524daad19c9a94dfb59767f906a4a7  kno_0.2.1_linux_amd64.tar.gz.sbom.json
1f8524b698c4fd8a60a55a7fa460c92168f55cdaf598231d449eff531fb078a3  kno_0.2.1_linux_arm64.tar.gz
a9b959baf47851bc28275c0896384ed176b87559e5e4e9f5ac1808826d5516e2  kno_0.2.1_linux_arm64.tar.gz.sbom.json
cf6aef2b8483bc9d10c2227c1121f6e17e27ee25f8e4e0f066f390fc47b11e3a  kno_0.2.1_windows_amd64.zip
7bc2de92a4e55388d8b667816e9d320d3f16f11c1e08b2b65db0f6032f7731a5  kno_0.2.1_windows_amd64.zip.sbom.json
fb64db414fd3c096d32fe735b4b0112b9bb691709773a52d2e6a36f7718966c5  kno_0.2.1_windows_arm64.zip
a5321c13f9e051b85081ae28a7708bc8e414ef4941848cdee16cf73d66705b19  kno_0.2.1_windows_arm64.zip.sbom.json

v0.2.0

Choose a tag to compare

@devarispbrown devarispbrown released this 02 Sep 07:13
38eb019

0.2.0 (2026-09-02)

⚠ BREAKING CHANGES

  • core.Tuner gained Deploy, Teardown, ListJobs and ListEndpoints, and store.Store gained WriteTuningJob, UpdateTuningJob, TuningJobs, LeakedEndpoints, WriteValidation, Validation and RecordHoldoutUse. An out-of-tree implementation of either interface must add them. The store schema moves 6 to 8: a 0.1.x database is readable by 0.2.0, a 0.2.0 database is not readable by 0.1.x.

Bug Fixes

  • fake: refuse an Asset with no content (#202) (948e018)

Documentation

  • fold v0.1.7, and give the 0.2.0 breaking changes their notice (#203) (4598b4b)
  • re-record the quickstart GIF for v0.1.7 (#199) (19ba099)

Verifying this release

Every artifact below is covered by checksums.txt, and checksums.txt is
signed with cosign keyless — there is no
private key, so there is none to steal. Each archive also ships an SPDX
SBOM, and the whole set carries SLSA build provenance.

# 1. The checksum file is really ours, and really came from this workflow.
cosign verify-blob checksums.txt \
  --certificate checksums.txt.pem \
  --signature checksums.txt.sig \
  --certificate-identity-regexp '^https://github\.com/uknoAI/kno/\.github/workflows/release\.yml@refs/tags/.+$' \
  --certificate-oidc-issuer https://token.actions.githubusercontent.com

# 2. Your download is really what the checksum file names. Substitute the
#    archive you actually downloaded. Written this way because macOS has no
#    sha256sum, and its shasum does not understand --ignore-missing.
grep " kno_0.2.0_darwin_arm64.tar.gz$" checksums.txt | shasum -a 256 -c -

# 3. It was built by GitHub Actions from this repository, not on a laptop.
gh attestation verify kno_0.2.0_linux_amd64.tar.gz \
  --repo uknoAI/kno \
  --signer-workflow uknoAI/kno/.github/workflows/release.yml

Both identity flags are load-bearing. Without --certificate-identity-regexp,
verify-blob accepts a valid signature from anybody at all; without
--signer-workflow, attestation verify accepts an attestation from any
workflow in the repository. Anchored, they say this file built this binary.

Built with -trimpath, and timestamped from the commit rather than the
clock, so these archives are byte-reproducible — by anyone using the Go
toolchain pinned in this tag's go.mod. A different toolchain produces a
different binary; that is a property of Go, not of this pipeline.

Checksums (SHA-256)

53314e351e72a523ee193e8c4663062057b234ec0f922eb970e10bb1fbb13e62  kno_0.2.0_darwin_amd64.tar.gz
bfc73537576e3a588145f5ba54d330f533eebbd7d7092d101b11e67b0633ecb7  kno_0.2.0_darwin_amd64.tar.gz.sbom.json
d2fd30b61e3895da31d514ce63deb6748cce0f5d4fdfc541b72ef977ba607e84  kno_0.2.0_darwin_arm64.tar.gz
5273b08544b49da8a37d2129429bd055ebcc4f0fbc88112eab96b6aa51bb02c2  kno_0.2.0_darwin_arm64.tar.gz.sbom.json
f6a054840649d3dcf1bf8a07e4591911b25fa724ed1b870229cf642d92410fc1  kno_0.2.0_linux_amd64.tar.gz
1ea40fc1d09a3dca02478c755c12dd34ba2a779aded171134e29bbf9b6db79e5  kno_0.2.0_linux_amd64.tar.gz.sbom.json
4107d1b5f3cbe7b12fb9f1e38d4c0f61860038127f0b29538b51d9df0977b1e5  kno_0.2.0_linux_arm64.tar.gz
92013983a4b0886646f4e15c8025dd40822230112d945967f8539426c56e7fdb  kno_0.2.0_linux_arm64.tar.gz.sbom.json
50cb927c78d76e588e7d20cc8f3157d46917d777736d339c9313dbdbb1781b2a  kno_0.2.0_windows_amd64.zip
d6d41e3926cb442198d7ba53c3d11a9ec5fb297ba048b9af90a8674917b05baa  kno_0.2.0_windows_amd64.zip.sbom.json
e4fbaaa8af693df1f29072fe4ab3f385df3529ce5a2301f70e97bb0e73d3dc5a  kno_0.2.0_windows_arm64.zip
99a4162fb079154746f77924802a630206555ec9c5f46c8ca40a93a360cc1cd6  kno_0.2.0_windows_arm64.zip.sbom.json

v0.1.7

Choose a tag to compare

@devarispbrown devarispbrown released this 01 Sep 18:13
b92a7eb

0.1.7 (2026-09-01)

Features

  • bridge: the tuner bridge, and the eval seam that closes the loop (#184) (f900312)

Bug Fixes

  • build: the ledger gate reads a minor series, and the v0.2 audit disposes every open entry (#193) (099a82f)
  • docs: repair the CHANGELOG, and refuse conflict markers in future (#196) (c0f5692)
  • value: the treatment arm carries the Asset's content (#190) (8f09b10)

Documentation

  • adr: measured redundancy is cut from v0.2 (#191) (cea92c6)
  • correct the v0.2 scope after two cuts (#192) (3726be0)
  • fold the hand-written changelog into v0.1.6 (#197) (66c2a18)
  • plans: the bridge measurement seam (#189) (ae955db)
  • tombstone calibrate-a-judge — the cookbook migration is finished (#188) (6ab9937)
  • tombstone check-your-evals, and fix the README's self-contradicting example (#185) (c8e0d62)

Build & Dependencies

  • the link check walks this checkout, not agent worktrees (#194) (1acbc74)

Verifying this release

Every artifact below is covered by checksums.txt, and checksums.txt is
signed with cosign keyless — there is no
private key, so there is none to steal. Each archive also ships an SPDX
SBOM, and the whole set carries SLSA build provenance.

# 1. The checksum file is really ours, and really came from this workflow.
cosign verify-blob checksums.txt \
  --certificate checksums.txt.pem \
  --signature checksums.txt.sig \
  --certificate-identity-regexp '^https://github\.com/uknoAI/kno/\.github/workflows/release\.yml@refs/tags/.+$' \
  --certificate-oidc-issuer https://token.actions.githubusercontent.com

# 2. Your download is really what the checksum file names. Substitute the
#    archive you actually downloaded. Written this way because macOS has no
#    sha256sum, and its shasum does not understand --ignore-missing.
grep " kno_0.1.7_darwin_arm64.tar.gz$" checksums.txt | shasum -a 256 -c -

# 3. It was built by GitHub Actions from this repository, not on a laptop.
gh attestation verify kno_0.1.7_linux_amd64.tar.gz \
  --repo uknoAI/kno \
  --signer-workflow uknoAI/kno/.github/workflows/release.yml

Both identity flags are load-bearing. Without --certificate-identity-regexp,
verify-blob accepts a valid signature from anybody at all; without
--signer-workflow, attestation verify accepts an attestation from any
workflow in the repository. Anchored, they say this file built this binary.

Built with -trimpath, and timestamped from the commit rather than the
clock, so these archives are byte-reproducible — by anyone using the Go
toolchain pinned in this tag's go.mod. A different toolchain produces a
different binary; that is a property of Go, not of this pipeline.

Checksums (SHA-256)

cbe9727268c37d76232d04ea446a7cf62db3d64e366b081c3fd50a4a2b1b5daf  kno_0.1.7_darwin_amd64.tar.gz
35e52d57b4f1fe9a04d9a59720240f52d250368e84c23257ddd56a65ecd2ee08  kno_0.1.7_darwin_amd64.tar.gz.sbom.json
5e8d442d7867f075ba8c747b2a24db62c6d64071d31c2ec3a62c8b9165b538eb  kno_0.1.7_darwin_arm64.tar.gz
f9ec15de7166b1daaf0725e7d94f9654c6f5f779ee68e3ac0fcf35062512cf32  kno_0.1.7_darwin_arm64.tar.gz.sbom.json
db4ddb1441bf3d4d8b83203eff5e1ed6635d368bc94e96bcc45206ef72eecad3  kno_0.1.7_linux_amd64.tar.gz
334c8f8830eab990b4de69217066c05e58aebaf448a5a6048852335a3e7bd946  kno_0.1.7_linux_amd64.tar.gz.sbom.json
b2381d7d9d3bd98db0a4c9cecc6cf3b6a921584ef416e067d6906efc5a1e8cee  kno_0.1.7_linux_arm64.tar.gz
492a14dcc9f938e0efd0c6fa7dea583371b9e52ab3a311cefa7a407ee52f515a  kno_0.1.7_linux_arm64.tar.gz.sbom.json
866e5c6ca65a2fbc1fb5ec600800ddeb59461baa54b0138a7ad8b80b34addf71  kno_0.1.7_windows_amd64.zip
9455a30f9c624e9b8e3453cc92f3cd3bae0b13756d1b9f9f97685a94834d2ef5  kno_0.1.7_windows_amd64.zip.sbom.json
fe74412b2c25224c733b593382dcbf311c61c70a1b8e617d9375e6bdcd8569a1  kno_0.1.7_windows_arm64.zip
ce42cecf77c3a82dd2398d6ef9cd2a03353571015e1f0333854a12b68710616e  kno_0.1.7_windows_arm64.zip.sbom.json

v0.1.6

Choose a tag to compare

@devarispbrown devarispbrown released this 01 Sep 08:01
1b33409

0.1.6 (2026-09-01)

Bug Fixes

  • export: a tuning set carries an assistant turn to train on (#183) (5cf4ab2)
  • stats: a sample with no spread no longer reports certainty (#182) (9e88389)

Documentation

  • fold the hand-written changelog into v0.1.5 (#180) (76fb335)

Verifying this release

Every artifact below is covered by checksums.txt, and checksums.txt is
signed with cosign keyless — there is no
private key, so there is none to steal. Each archive also ships an SPDX
SBOM, and the whole set carries SLSA build provenance.

# 1. The checksum file is really ours, and really came from this workflow.
cosign verify-blob checksums.txt \
  --certificate checksums.txt.pem \
  --signature checksums.txt.sig \
  --certificate-identity-regexp '^https://github\.com/uknoAI/kno/\.github/workflows/release\.yml@refs/tags/.+$' \
  --certificate-oidc-issuer https://token.actions.githubusercontent.com

# 2. Your download is really what the checksum file names. Substitute the
#    archive you actually downloaded. Written this way because macOS has no
#    sha256sum, and its shasum does not understand --ignore-missing.
grep " kno_0.1.6_darwin_arm64.tar.gz$" checksums.txt | shasum -a 256 -c -

# 3. It was built by GitHub Actions from this repository, not on a laptop.
gh attestation verify kno_0.1.6_linux_amd64.tar.gz \
  --repo uknoAI/kno \
  --signer-workflow uknoAI/kno/.github/workflows/release.yml

Both identity flags are load-bearing. Without --certificate-identity-regexp,
verify-blob accepts a valid signature from anybody at all; without
--signer-workflow, attestation verify accepts an attestation from any
workflow in the repository. Anchored, they say this file built this binary.

Built with -trimpath, and timestamped from the commit rather than the
clock, so these archives are byte-reproducible — by anyone using the Go
toolchain pinned in this tag's go.mod. A different toolchain produces a
different binary; that is a property of Go, not of this pipeline.

Checksums (SHA-256)

4e54d2b0ce5418db536aaaaa48cc2b926f908aca1e03e948f9a7fed0e3a51997  kno_0.1.6_darwin_amd64.tar.gz
9a4871db7cf8843f660d5be8f853ccb6ff6c083596f6bb6b12aacadc2d5a310c  kno_0.1.6_darwin_amd64.tar.gz.sbom.json
1938030c14e38934da12b965a71166177eb7f76bbc23cb982720609a1348d5ec  kno_0.1.6_darwin_arm64.tar.gz
eb1a276b0cb0cbf1b1a27ef02c103745c8e8400b41decaef1d91ef455541a022  kno_0.1.6_darwin_arm64.tar.gz.sbom.json
0dc81124997489b21f07ba24e7b437b7d39a0816570fae8873d4fb8962e16a3b  kno_0.1.6_linux_amd64.tar.gz
fcb1cd5d9c0e654a3907f5a5966231b5169fa8d309eb4b1918d149192ef0438c  kno_0.1.6_linux_amd64.tar.gz.sbom.json
0b19739947e04242aa2419632f9da7380d61f610d677aebd7b4e219e6f6c1cc2  kno_0.1.6_linux_arm64.tar.gz
4a861c7ced8f55739643bc89eda3e55e898e765bdc0dc9725ad1efb2ef59e484  kno_0.1.6_linux_arm64.tar.gz.sbom.json
71acf1ba11ed11dd801c6cb35922a9819584bf64b5fe0734e588d44f8e3e4759  kno_0.1.6_windows_amd64.zip
4ac2e0acbc6a7496f4ddf28588acbed970bbafeb0dd0ceb2f0524896a5f5d334  kno_0.1.6_windows_amd64.zip.sbom.json
a1e6d041437a6f38fc30788914f570b55762f669dec284eee294d96ff7b8eb82  kno_0.1.6_windows_arm64.zip
b47efdf3df9fe32659de485bb95a4c541cf839b55ada116ad57ecc160d6df5d2  kno_0.1.6_windows_arm64.zip.sbom.json

v0.1.5

Choose a tag to compare

@devarispbrown devarispbrown released this 01 Sep 05:03
8e8e5ef

0.1.5 (2026-09-01)

Features

  • judge calibrate — a judge is measured before it is trusted (#177) (bd2cc17)

Bug Fixes

  • release: fold the changelog correctly, and stop it racing the tag (#174) (9112255)
  • validate: a resumed run restores the tokens it spent (#172) (14291c8)

Documentation

  • plans: amend redundancy detection with F5 and the moved cookbook (#173) (159d6e1)

Build & Dependencies

  • release: notify kno-www when a release ships (#176) (01ebc01)

Verifying this release

Every artifact below is covered by checksums.txt, and checksums.txt is
signed with cosign keyless — there is no
private key, so there is none to steal. Each archive also ships an SPDX
SBOM, and the whole set carries SLSA build provenance.

# 1. The checksum file is really ours, and really came from this workflow.
cosign verify-blob checksums.txt \
  --certificate checksums.txt.pem \
  --signature checksums.txt.sig \
  --certificate-identity-regexp '^https://github\.com/uknoAI/kno/\.github/workflows/release\.yml@refs/tags/.+$' \
  --certificate-oidc-issuer https://token.actions.githubusercontent.com

# 2. Your download is really what the checksum file names. Substitute the
#    archive you actually downloaded. Written this way because macOS has no
#    sha256sum, and its shasum does not understand --ignore-missing.
grep " kno_0.1.5_darwin_arm64.tar.gz$" checksums.txt | shasum -a 256 -c -

# 3. It was built by GitHub Actions from this repository, not on a laptop.
gh attestation verify kno_0.1.5_linux_amd64.tar.gz \
  --repo uknoAI/kno \
  --signer-workflow uknoAI/kno/.github/workflows/release.yml

Both identity flags are load-bearing. Without --certificate-identity-regexp,
verify-blob accepts a valid signature from anybody at all; without
--signer-workflow, attestation verify accepts an attestation from any
workflow in the repository. Anchored, they say this file built this binary.

Built with -trimpath, and timestamped from the commit rather than the
clock, so these archives are byte-reproducible — by anyone using the Go
toolchain pinned in this tag's go.mod. A different toolchain produces a
different binary; that is a property of Go, not of this pipeline.

Checksums (SHA-256)

a02a4ba1ecd8efac146c14244b3ac5ea9c880681ecf99cd042ee8d8413fb166a  kno_0.1.5_darwin_amd64.tar.gz
305dc74cb777bd6132d0e12b7abf81a47d073e1393dc7645271635c7de69ac84  kno_0.1.5_darwin_amd64.tar.gz.sbom.json
02fb6bf297e35fc98cebe56a43cc71f8a1609602a5f3eabb36ca7fb19c6f4507  kno_0.1.5_darwin_arm64.tar.gz
9c94becc93b5b4bfaa0b5ca0a617e80fda8cce52500afb858fbd34eb586cab7b  kno_0.1.5_darwin_arm64.tar.gz.sbom.json
0b9492eacb519ea49e2d28202118d993151b8be4e857fe764a9263163e7f9d09  kno_0.1.5_linux_amd64.tar.gz
4cb7feb72f3fc0ab464c7bc8bdebed213a06d7cbe51c7eef3b72ae6f57e847fe  kno_0.1.5_linux_amd64.tar.gz.sbom.json
87607895643550635d4e71185ea49c76e4bd09a7a3f16ebba397b5f13095446f  kno_0.1.5_linux_arm64.tar.gz
429f07e187e407e9a6471b61c51ef590ad899255adce1a399ce19141a481110c  kno_0.1.5_linux_arm64.tar.gz.sbom.json
45f2d6f12e1512b2f2b8246a1696cc63716c6ff404fbeb9b443cb4a3f05ea9d3  kno_0.1.5_windows_amd64.zip
500a147a6e1d4bdf744f26ce080b3ec55b883dcb4a5f4f1f0ff96e3ee47b6320  kno_0.1.5_windows_amd64.zip.sbom.json
cbf3d95dff3f908505f696ac02bff7f5634453a6248a5e063fa33c9273e7ed7a  kno_0.1.5_windows_arm64.zip
8f9fc236002878f18f8cf5d9263ea52c3ecae1281a4937a54c2482f8367631c0  kno_0.1.5_windows_arm64.zip.sbom.json

v0.1.4

Choose a tag to compare

@devarispbrown devarispbrown released this 01 Sep 03:06
90d31ec

0.1.4 (2026-09-01)

Features

  • every stage reports what it spent, or says it could not (#168) (dd5f0e9)
  • kno validate — the holdout finally speaks (#169) (e13b558)

Bug Fixes

  • build: the ledger gate refuses duplicate entry ids (#166) (7055062)
  • value: a resumed run restores the tokens it spent (#170) (00f0044)

Documentation

  • debt: dispose four silent lapses and backstop seven vague triggers (#167) (706b186)
  • fold the hand-written changelog into v0.1.3 (#164) (788c09f)
  • move the cookbook to uknoAI/kno-examples, leaving tombstones (#163) (94f32df)

Verifying this release

Every artifact below is covered by checksums.txt, and checksums.txt is
signed with cosign keyless — there is no
private key, so there is none to steal. Each archive also ships an SPDX
SBOM, and the whole set carries SLSA build provenance.

# 1. The checksum file is really ours, and really came from this workflow.
cosign verify-blob checksums.txt \
  --certificate checksums.txt.pem \
  --signature checksums.txt.sig \
  --certificate-identity-regexp '^https://github\.com/uknoAI/kno/\.github/workflows/release\.yml@refs/tags/.+$' \
  --certificate-oidc-issuer https://token.actions.githubusercontent.com

# 2. Your download is really what the checksum file names. Substitute the
#    archive you actually downloaded. Written this way because macOS has no
#    sha256sum, and its shasum does not understand --ignore-missing.
grep " kno_0.1.4_darwin_arm64.tar.gz$" checksums.txt | shasum -a 256 -c -

# 3. It was built by GitHub Actions from this repository, not on a laptop.
gh attestation verify kno_0.1.4_linux_amd64.tar.gz \
  --repo uknoAI/kno \
  --signer-workflow uknoAI/kno/.github/workflows/release.yml

Both identity flags are load-bearing. Without --certificate-identity-regexp,
verify-blob accepts a valid signature from anybody at all; without
--signer-workflow, attestation verify accepts an attestation from any
workflow in the repository. Anchored, they say this file built this binary.

Built with -trimpath, and timestamped from the commit rather than the
clock, so these archives are byte-reproducible — by anyone using the Go
toolchain pinned in this tag's go.mod. A different toolchain produces a
different binary; that is a property of Go, not of this pipeline.

Checksums (SHA-256)

c5123fd8e80c02bac8433ebe2a7ddd4f16c78b9ff27b0be8581dcaf546a9585d  kno_0.1.4_darwin_amd64.tar.gz
e3942a1143aec090d6af329e319f61176be87a55fd0bed8989fc61b34f426800  kno_0.1.4_darwin_amd64.tar.gz.sbom.json
b5bf2c1e71251d089a3f07347e071d484e7c463acbccbc31bdf5354dd0fc9e7a  kno_0.1.4_darwin_arm64.tar.gz
bba3d0f19b4a5c355a3d1e8875061f9c6fafa5b79ac815b2dd707421e76aa66b  kno_0.1.4_darwin_arm64.tar.gz.sbom.json
d87d5c3e2a4e688b44a446f722b0c17efaf2b2716735ddc44e5f506a59f1de90  kno_0.1.4_linux_amd64.tar.gz
f7878d8dc461b3179362a33c7310d8bff535de4fbfecabb802b918c54149af59  kno_0.1.4_linux_amd64.tar.gz.sbom.json
626a29b12c3911c6f9259d726058b2d24968b88ba153b73c20c06e439deecc60  kno_0.1.4_linux_arm64.tar.gz
18f613d5dde19c7d179acafd26bc4f493f85d80097d90821622f4fdceb0d28ce  kno_0.1.4_linux_arm64.tar.gz.sbom.json
c22cdce7d99bf044cfdb9f63b03a3fe2612aecb520605783345cc81e52a4673a  kno_0.1.4_windows_amd64.zip
466c2483cc47da944321366b92b0975ac0e702c4538fd79584fd50d028522d36  kno_0.1.4_windows_amd64.zip.sbom.json
d6abad3dba5dffa391436a4dfee4727ab39a2d77d7c71fecf8e7f9ced919bd0f  kno_0.1.4_windows_arm64.zip
07318f256f698912976ec6e56b1393ff902b179b0ce680c6511505ad475d06a0  kno_0.1.4_windows_arm64.zip.sbom.json

v0.1.3

Choose a tag to compare

@devarispbrown devarispbrown released this 31 Aug 20:59
2140622

0.1.3 (2026-08-31)

Features

  • docs/status.json — generated status data for the site, gated in make check (#150) (cb50d5b)
  • kno eval inspect — whether an eval set can support attribution (#155) (18ebb4a)

Bug Fixes

  • cli: kno export --json names the Select run it rendered from (#156) (074d73f)
  • core: the rejection log prints bounds at four places, not seventeen (#157) (350bc01)
  • value: the harm bound is the exact t quantile, not z beyond df=30 (#158) (4622b90)

Documentation

  • answer the examples plan's blocking question by reading kno-www (#146) (9bc5c47)
  • debt: record two live defects found by the v0.2 Phase-0 workstreams (#159) (37967e5)
  • fold the hand-written changelog into v0.1.2 (#145) (bd858c3)
  • Phase-0 plans for v0.2, all adversarially reviewed (#161) (83c7641)
  • stop advertising an on-ramp that does not exist yet (#162) (89ce9ee)

Build & Dependencies

  • Bump anchore/sbom-action/download-syft from 0.24.0 to 0.24.2 (#135) (23dcfe0)

Verifying this release

Every artifact below is covered by checksums.txt, and checksums.txt is
signed with cosign keyless — there is no
private key, so there is none to steal. Each archive also ships an SPDX
SBOM, and the whole set carries SLSA build provenance.

# 1. The checksum file is really ours, and really came from this workflow.
cosign verify-blob checksums.txt \
  --certificate checksums.txt.pem \
  --signature checksums.txt.sig \
  --certificate-identity-regexp '^https://github\.com/uknoAI/kno/\.github/workflows/release\.yml@refs/tags/.+$' \
  --certificate-oidc-issuer https://token.actions.githubusercontent.com

# 2. Your download is really what the checksum file names. Substitute the
#    archive you actually downloaded. Written this way because macOS has no
#    sha256sum, and its shasum does not understand --ignore-missing.
grep " kno_0.1.3_darwin_arm64.tar.gz$" checksums.txt | shasum -a 256 -c -

# 3. It was built by GitHub Actions from this repository, not on a laptop.
gh attestation verify kno_0.1.3_linux_amd64.tar.gz \
  --repo uknoAI/kno \
  --signer-workflow uknoAI/kno/.github/workflows/release.yml

Both identity flags are load-bearing. Without --certificate-identity-regexp,
verify-blob accepts a valid signature from anybody at all; without
--signer-workflow, attestation verify accepts an attestation from any
workflow in the repository. Anchored, they say this file built this binary.

Built with -trimpath, and timestamped from the commit rather than the
clock, so these archives are byte-reproducible — by anyone using the Go
toolchain pinned in this tag's go.mod. A different toolchain produces a
different binary; that is a property of Go, not of this pipeline.

Checksums (SHA-256)

301577503df566f38c4145f8e59d75c0a5677a19da61a5e9f1e00277fe3e5aff  kno_0.1.3_darwin_amd64.tar.gz
c5efc53ce6125026a64e52f619f8d2c855e72a21e5af9519120bf96862d17b23  kno_0.1.3_darwin_amd64.tar.gz.sbom.json
6bd303d696e84f2f5802c96f990324e2a2ff1cac530ef0970a2b4766bd7e6111  kno_0.1.3_darwin_arm64.tar.gz
2bc11e7025f93fabac97f007d9bd6577ffc7f58300dec7c7b1ff4f4135582c61  kno_0.1.3_darwin_arm64.tar.gz.sbom.json
bb5c5940318686a67982a67167c2207b4713c0c52a48949756e0ce1384d2fbc5  kno_0.1.3_linux_amd64.tar.gz
ed11c0967b2e321b62e2fd107f71346c34eb4d0630fb2a43240ae7b18e98a60a  kno_0.1.3_linux_amd64.tar.gz.sbom.json
9730cd82aac43166a0c1cc1ee8f47b342b8d1a71677434a9630b50f73d49e1d2  kno_0.1.3_linux_arm64.tar.gz
83ce40e10df6d457586726c7ef848cfa6962af055659072bd9268a2551de8cc0  kno_0.1.3_linux_arm64.tar.gz.sbom.json
49fd45501719037a83bb111f5060c64480ef457464dca84f470b849601b28d4c  kno_0.1.3_windows_amd64.zip
148d9f34c04ba8edfd07ca48d9e80607785fa02144a7082d648e101637558a39  kno_0.1.3_windows_amd64.zip.sbom.json
1cec39dfea9d75ed036116da65f8b847661576aa9034c18640f9126be4a44aa0  kno_0.1.3_windows_arm64.zip
042208cc3149407f52b7d22e361ae2ee24019d753a496c301ddbc276530d1f01  kno_0.1.3_windows_arm64.zip.sbom.json

v0.1.2

Choose a tag to compare

@devarispbrown devarispbrown released this 31 Aug 17:46
3bafe13

0.1.2 (2026-08-31)

Features

  • kno demo — the whole loop in one command, for free (#144) (6317b9a)

Bug Fixes

  • ci: the release commit signs itself, and the DCO check stops failing correct trailers (#142) (63cfa20)

Documentation

  • adapters: package godoc names only the adapters that exist (#141) (dec47a8)
  • evaluation best practices in the README, and the deep evaluation-design guide (#137) (bfb85c7)
  • Phase-0 plans for the next body of work, all adversarially reviewed (#140) (648effb)
  • the quickstart tape shows the intervals it claims (#143) (1c6403f)
  • the README quickstart Case matches the recorded tape (#139) (20c7dfe)

Verifying this release

Every artifact below is covered by checksums.txt, and checksums.txt is
signed with cosign keyless — there is no
private key, so there is none to steal. Each archive also ships an SPDX
SBOM, and the whole set carries SLSA build provenance.

# 1. The checksum file is really ours, and really came from this workflow.
cosign verify-blob checksums.txt \
  --certificate checksums.txt.pem \
  --signature checksums.txt.sig \
  --certificate-identity-regexp '^https://github\.com/uknoAI/kno/\.github/workflows/release\.yml@refs/tags/.+$' \
  --certificate-oidc-issuer https://token.actions.githubusercontent.com

# 2. Your download is really what the checksum file names. Substitute the
#    archive you actually downloaded. Written this way because macOS has no
#    sha256sum, and its shasum does not understand --ignore-missing.
grep " kno_0.1.2_darwin_arm64.tar.gz$" checksums.txt | shasum -a 256 -c -

# 3. It was built by GitHub Actions from this repository, not on a laptop.
gh attestation verify kno_0.1.2_linux_amd64.tar.gz \
  --repo uknoAI/kno \
  --signer-workflow uknoAI/kno/.github/workflows/release.yml

Both identity flags are load-bearing. Without --certificate-identity-regexp,
verify-blob accepts a valid signature from anybody at all; without
--signer-workflow, attestation verify accepts an attestation from any
workflow in the repository. Anchored, they say this file built this binary.

Built with -trimpath, and timestamped from the commit rather than the
clock, so these archives are byte-reproducible — by anyone using the Go
toolchain pinned in this tag's go.mod. A different toolchain produces a
different binary; that is a property of Go, not of this pipeline.

Checksums (SHA-256)

c3553dcf0b18271da67622f35a607d88f5f80726e4b78e79d6e8b0102289bb4c  kno_0.1.2_darwin_amd64.tar.gz
dc77284b840bfdc493224472df1b09507c18cd3d4cb82a74008d4309207f5497  kno_0.1.2_darwin_amd64.tar.gz.sbom.json
4f05cec1b5bc0e8ba6bc6f6945be09a46567c4059ea2ea7f64273e14335dc33c  kno_0.1.2_darwin_arm64.tar.gz
f2c5507a87809d2e82d39978e67740abefdb98c0be6b0da70cab04066af3be98  kno_0.1.2_darwin_arm64.tar.gz.sbom.json
c2c72ba6a11b2ec91cf10c23b250ec6b609e1d7b474b6e95e3733a24a5ca00b7  kno_0.1.2_linux_amd64.tar.gz
24055fd6485c02abbcd7ddb0f60acac2f92063e61c9552504010962716796fec  kno_0.1.2_linux_amd64.tar.gz.sbom.json
ce189c541d0622f78c903c63264a7ae62b48e1b83056239ec2d33d93238f5515  kno_0.1.2_linux_arm64.tar.gz
c2ac256493cce9b4ba097b9c845fb27469c21d11ad9997718973dc816fc308f4  kno_0.1.2_linux_arm64.tar.gz.sbom.json
c98fdff62f30e9a01461ac6e37acf59883a2b699e118534ee7dd6e053f84b76a  kno_0.1.2_windows_amd64.zip
c39097f06eee92bb310a3997eed4a292143d772f630445130fe0c8918ec235fc  kno_0.1.2_windows_amd64.zip.sbom.json
7f927cae0c09bb288e4b8bd04c8c9d84eab775e6c4d2e5cf675e1dd172268f32  kno_0.1.2_windows_arm64.zip
b81edb49aea03aba964302bd132df3cbe18aebac9a58a21248d89e593aebf978  kno_0.1.2_windows_arm64.zip.sbom.json

v0.1.1

Choose a tag to compare

@devarispbrown devarispbrown released this 31 Aug 05:05
9de5a85

0.1.1 (2026-08-31)

Features

  • Bedrock and Vertex agent adapters — partner clouds priced (#128) (360cabc)
  • Braintrust Evals adapter — fourth core.Evals source (#124) (638e3d2)
  • Hugging Face adapters — Evals and Pool (#125) (ebd4d4a)

Documentation

  • fold the hand-written changelog into v0.1.0 (#131) (c86e28b)

Build & Dependencies

  • deps: Bump github.com/charmbracelet/glamour from 0.9.1 to 1.0.0 (#136) (2514b25)

Verifying this release

Every artifact below is covered by checksums.txt, and checksums.txt is
signed with cosign keyless — there is no
private key, so there is none to steal. Each archive also ships an SPDX
SBOM, and the whole set carries SLSA build provenance.

# 1. The checksum file is really ours, and really came from this workflow.
cosign verify-blob checksums.txt \
  --certificate checksums.txt.pem \
  --signature checksums.txt.sig \
  --certificate-identity-regexp '^https://github\.com/uknoAI/kno/\.github/workflows/release\.yml@refs/tags/.+$' \
  --certificate-oidc-issuer https://token.actions.githubusercontent.com

# 2. Your download is really what the checksum file names. Substitute the
#    archive you actually downloaded. Written this way because macOS has no
#    sha256sum, and its shasum does not understand --ignore-missing.
grep " kno_0.1.1_darwin_arm64.tar.gz$" checksums.txt | shasum -a 256 -c -

# 3. It was built by GitHub Actions from this repository, not on a laptop.
gh attestation verify kno_0.1.1_linux_amd64.tar.gz \
  --repo uknoAI/kno \
  --signer-workflow uknoAI/kno/.github/workflows/release.yml

Both identity flags are load-bearing. Without --certificate-identity-regexp,
verify-blob accepts a valid signature from anybody at all; without
--signer-workflow, attestation verify accepts an attestation from any
workflow in the repository. Anchored, they say this file built this binary.

Built with -trimpath, and timestamped from the commit rather than the
clock, so these archives are byte-reproducible — by anyone using the Go
toolchain pinned in this tag's go.mod. A different toolchain produces a
different binary; that is a property of Go, not of this pipeline.

Checksums (SHA-256)

3bfa04bcc34b872edbedf2cc83317e8d35cb32dbf931c4bd2bd458db45e15795  kno_0.1.1_darwin_amd64.tar.gz
de13ae519543e75069971b1c9d26cb000b5a27822ca2706b5489f4deef98fb5c  kno_0.1.1_darwin_amd64.tar.gz.sbom.json
2011a1e532beda6932195c240fa41b252bba7a26f745a4ccbac3c2b2fcb28633  kno_0.1.1_darwin_arm64.tar.gz
33dabeef8e62c4c4da5427732d1f064484fdb25bd86d7126ae33efac1e3cf0fc  kno_0.1.1_darwin_arm64.tar.gz.sbom.json
3f6df988a354ee749f31d393aa762d960f95ffb5a38e4de585698fd4a984dc79  kno_0.1.1_linux_amd64.tar.gz
5bd22f6e3bc4299d94761b59e01950fd565000246bbd3567b4454410d7fc5fb8  kno_0.1.1_linux_amd64.tar.gz.sbom.json
bdc224f6547572258a6e34ea3514ea74daf6e88a4fe142aa376e9710870320a3  kno_0.1.1_linux_arm64.tar.gz
fa959799709699fc0d4e35a601b639b02b1c105e5070278b19832a1c0058ac20  kno_0.1.1_linux_arm64.tar.gz.sbom.json
4b43e1e76d9951254b16fb301483df09c1bba5ce906d4058d6e8e9bbbc2711bc  kno_0.1.1_windows_amd64.zip
37dafe9d404d0457d9f605763f76474a54d80a28e2dcbd3b01f6c0cd6e3b9046  kno_0.1.1_windows_amd64.zip.sbom.json
90bfda2b0d0774e58ab3b872f084739c568f3bc051c62ef36ffcaead208d9786  kno_0.1.1_windows_arm64.zip
ef5b8a964f7acb191191d398b850a358af2dbd612dbb39f9dc1ecc783675f227  kno_0.1.1_windows_arm64.zip.sbom.json