Skip to content

Releases: modootoday/humanymous

v0.2.1

Choose a tag to compare

@github-actions github-actions released this 24 Jul 22:48

[0.2.1] - 2026-07-24

Fixed

  • Correct /metrics path + make integrity gauge scrape-safe + doc/artifact defects

v0.2.0

Choose a tag to compare

@github-actions github-actions released this 24 Jul 22:24

[0.2.0] - 2026-07-24

Security

  • Enshrine the SemVer major/minor/patch bump convention
  • Adopter-simulation gap closure — origin contract, cosign, k8s, compliance, OSS
  • Origincloak package, metrics/audit ops surfaces, k8s/systemd/observability
  • Remove CHANGELOG.md (GitHub Releases is the changelog) + use :latest only

v0.1.1

Choose a tag to compare

@github-actions github-actions released this 24 Jul 21:38

[0.1.1] - 2026-07-24

Fixed

  • Make compose.release.yaml actually boot + persist ACME certs

Documentation

  • Add HTTPS/TLS certificate guide + real Let's Encrypt examples
  • Document the published ghcr.io images as a first-class run path

v0.1.0

Choose a tag to compare

@github-actions github-actions released this 24 Jul 20:55

[0.1.0] - 2026-07-24

Security

  • Production hardening — graceful shutdown, health/metrics, ingress caps, admin mTLS
  • Per-page SEO metadata + Glossary/FAQ + strip internal spec labels
  • Resolve CodeQL findings, harden overlay CI, bump action deps
  • Correct trivy-action pin to v0.36.0 (action switched to v-prefix tags)
  • Fix stale conformance drift — origin epoch + token-not-honored
  • Bump aquasecurity/trivy-action 0.28.0 → 0.36.0 (0.28.0 yanked from registry)
  • Relicense BSD-3-Clause → Apache-2.0
  • Automate the changelog + release notes from Conventional Commits (git-cliff)
  • Implement the 8 residual deep-review items (audit/edge/coordinator)
  • Witness co-signs only append-only extensions (consistency-verified, split-view protection)
  • Shared ban + verdict state across a gate fleet via Redis
  • Sweep all public docs for stale content after the hardening pass
  • Proxy forwarding-fidelity verification + close out audit findings
  • Pre-release audit remediation (Red/Blue + judge) + release docs
  • Wargame round 5 — wire Pass trust-upgrade + no-laundering invariant
  • Canonical 3-row alignment mechanic (SoT-36 v2), replacing physics
  • Humanymous Pass engine — server-side physics-placement verify (SoT-36)

Added

  • Ceiling-guard — attestation floor on high-value routes
  • ClickHouse projection hardening — credentials (no URL leak) + table-name validation
  • Token-verifier replay/binding hardening (PAT double-spend, WebAuthn origin, Web Bot Auth lifetime)
  • Redis coordination-channel hardening — wire caps, AUTH, HMAC-signed values
  • Gate ops surfaces — /healthz liveness, broad-CIDR guard, projection drop-counter WARN
  • WebAuthn assertion verification — returning-user possession trust-upgrade
  • Privacy Pass Private Access Token verification (RFC 9578, trust-upgrade)
  • Streaming MAD anomaly detector — shadow-mode observer (log-only, verdict-safe)
  • Durable audit projection to ClickHouse — real infra + cross-checkable rows
  • RFC 6962 Merkle tree — inclusion + consistency proofs over the audit log
  • Web Bot Auth (RFC 9421) signature verification at the gate
  • PROXY protocol v2 real-IP recovery for L4 passthrough deployment
  • Shared sliding-window rate limiting (aggregate flood across nodes)
  • Wargame round 8 — mobile device-motion consistency guard (soft)
  • Wargame round 4 — deeper real-event model, fused SOFT
  • Wargame round 3 — axis ① identity gate (rate-limited attestation)
  • Wargame round 2 — axis ③ engine fusion (delay-free velocity)
  • Wargame round 1 — crypto axis ① + anti-replay + closed KPI loop
  • Blue hardening round 1 — require the raw sub-frame stream (SoT-36 §8)
  • Wargame infra — adaptive difficulty, KPIs, red/blue loop (SoT-36 §8)
  • Non-blocking Pass section on Demo + Playground (SoT-36 §8)
  • Control-plane handlers + client game, wired into the engine (SoT-36)

Fixed

  • Restore docs site root index + two defects found in the docs census
  • SVG theme-toggle + GitHub icons; opaque mobile nav drawer
  • Serve humanymous.css as a static asset (was wrapped in the HTML layout)
  • OG image title overlap — top-anchor the title, drop the crossing waveform
  • Demo issuer.pem must be world-readable for the non-root gate container
  • Ceiling-guard deployment-review remediation — code + stale cleanup
  • Round-5 confirmatory review — revert HR-19 regression, Pass anti-replay ordering, PoW symmetry, docs + CHANGELOG
  • Resolve the remaining review-#4 backlog (FPR no-lockout + self-DoS + fleet + compliance)
  • Deployment review #4 — mass-FP default, self-DoS, XFF trust, topology honesty
  • Deep deployment-suitability review #3 — provenance boundary + edge/PII/audit hardening
  • Deep-review deployment-suitability remediation (PLAN-08 hardening)
  • Deployment-review ship-blockers — Gate GC ticker (OOM-DoS) + remove FoxIO JA4H dead code
  • Fresh puzzle per New + slot alignment + replay after solve
  • Visible cup + robust necessity (outer re-roll, segment distance)
  • Guarantee necessity by construction (no trivial scenes)
  • Make the ramp NECESSARY (no trivially-passable scenes)
  • Exclude 172.16/12 from datacenter stub + resolve real client IP via XFF

Changed

  • DRY token gates + memoize Merkle proof generation
  • Scale seams — distribution interfaces + hot-path coalescing
  • Deep observability — audit completeness, upstream errors, explain, health
  • Structural splits — by-concern files + declarative admin routes
  • Traceability nets — make silent failures loud
  • Quick wins — behavior-preserving
  • Brand identity (定本) + Pulse Aperture SVG assets
  • XFF-spoof bypass profile + forwarded_private defense

Documentation

  • Prepare v0.1.0
  • Reconcile documentation with the codebase (census against source of truth)
  • Brand custom layout + full SEO/AEO/GEO (JSON-LD, OG WebP, llms.txt)
  • Document the ceiling-guard (attested preset, step-up, credential verifiers) + fix stale counts
  • Explain the collapsed RIT-failure signal (final review-6 tidiness item)
  • Positioning + supported-topologies (deployment review #4 briefing)
  • Clear deployment-review recommended-before-release items
  • Ledger console screenshot (the last missing visual asset)
  • Mermaid architecture/workflow diagrams + LaTeX across the doc set
  • Live /demo screenshots (verdict + layer lanes)
  • Custom domain humanymous.net (CNAME + site url)
  • Icon system SVGs — verdict trio + 7-layer sweep
  • Render Mermaid + MathJax on the Jekyll site
  • Brand hero + Mermaid pipeline/verdict diagrams + LaTeX scoring math