Grounded v0.2.1
Image
ghcr.io/ncecere/grounded:v0.2.1
ghcr.io/ncecere/grounded@sha256:a5cd09bde6d692d49fa2d4cd97b59f153b4310033da0613243d5182c5168a082
Deploy by digest. Verify the signature (keyless, GitHub Actions OIDC):
cosign verify ghcr.io/ncecere/grounded@sha256:a5cd09bde6d692d49fa2d4cd97b59f153b4310033da0613243d5182c5168a082 \
--certificate-identity-regexp '^https://github.com/ncecere/grounded/\.github/workflows/.+@refs/tags/v0.2.1$' \
--certificate-oidc-issuer https://token.actions.githubusercontent.comThe OCR sidecar (optional, components/ocr-tesseract), signed the same way:
ghcr.io/ncecere/grounded-ocr:v0.2.1
ghcr.io/ncecere/grounded-ocr@sha256:0fb86be813bb9b66c4a1d2b8f84a8fdf4b2a70e8b58dd61e63d2c710fcab8ec0
Release assets
grounded-v0.2.1-<os>-<arch>.sbom.spdx.json: the image's SBOM (SPDX JSON) for each platform, as attached to the image.grounded-v0.2.1.digest.txt: the image reference by digest.checksums.txt: SHA-256 of the files above (sha256sum -c checksums.txt).
The SBOM and build provenance are also attached to the image as attestations, which the signature covers:
docker buildx imagetools inspect ghcr.io/ncecere/grounded@sha256:a5cd09bde6d692d49fa2d4cd97b59f153b4310033da0613243d5182c5168a082 --format '{{ json .SBOM }}'.
Grounded v0.2.1
v0.2.1 is about navigation and clarity. v0.2.0 added evaluations, costs and budgets, OCR and SSO groups; a review by role found that they had piled up in the admin sidebar, the money pages and the evaluation screens. This release moves, merges and explains what exists — it adds no new features — and finishes per-claim verification. The full list of changes is in the changelog, and the plan with the owner's decisions is in v0.2.1.md.
v0.2.1-rc.1 ran on the reference install before this release; v0.2.1 is the same code, apart from documentation. These notes cover both.
Highlights
- A shorter admin sidebar. Eight collapsible groups — People, Content, Models, Usage & spend, Safety, Records, Operations — that fit a laptop screen, with the current page always visible. Legal holds is now a tab of Retention and Profile migrations a tab of Embedding profiles; old addresses redirect.
- What's switched on, at a glance. The admin Overview has a Features card with each optional feature's state (evaluations, cost tracking, OCR, SSO groups, SystemOne, public access, maintenance) and a link to where it's set. The evaluations switch lives there now.
- The team Overview answers "how are we doing?" Each evaluation set's latest score and trend, and — for owners and admins — this month's spend against the budget. A new Evaluations item in the team sidebar lists every set in the team.
- Spend and limits apart. Team settings' Usage & spend shows spend in one line with the breakdown folded away; Crawl domains moved to a tab of Data sources, so Team settings has five tabs. The Costs Overview is about half as tall, with one "Top spenders" card.
- A simpler agent editor. Six tabs (Build · Evaluations · Appearance · Share · Analytics · Settings); version history, compare and revert are in the header's version badge.
- Per-claim verification. With SystemOne citation checks on, each factual sentence of an answer is a claim with one verdict — supported, not supported or uncited — shown with its text in the citation card ("9 of 10 claims supported"). Evaluations count the same claims, so chat and results agree. The API adds
claims[], including on the OpenAI-compatible endpoint (additive). - Chat. Sources start collapsed; a citation chip opens its claim card (Enter from the keyboard), with "Show source" to jump to the passage.
- Fixes from the walkthrough: editors no longer see budget entries in the team audit log (owners and admins only, like spend); evaluation trends skip runs that have no score; Compare versions includes SystemOne settings; the first Tab reaches "Skip to content"; ⌘K opens moved tabs directly; and many smaller copy, keyboard and phone-layout fixes.
Requirements
Unchanged from v0.2.0.
Upgrading from v0.2.0
A rolling upgrade with no downtime and no database migrations (the schema stays at version 34). Take a backup as for any upgrade (operations/upgrades.md), then change every ?ref=v0.2.0 in your overlay to ?ref=v0.2.1 and pin the new digests of ghcr.io/ncecere/grounded and, if you run OCR, ghcr.io/ncecere/grounded-ocr.
Things people will notice:
- Moved pages: Admin → Legal holds and Admin → Profile migrations are tabs of Retention and Embedding profiles; a team's Crawl domains is a tab of Data sources; an agent's Versions tab is the header's version badge. Old links and bookmarks redirect.
- The evaluations switch moved from Admin → Limits → Evaluations to Admin → Overview → Features.
- Clicking a citation chip opens the claim card instead of jumping straight to the source.
- Answers stored before v0.2.1 keep showing a verdict per citation marker; new answers show claims.
Known limitations
The v0.2.0 limitations still apply. Editors can't withdraw their own domain request yet, and a few shared-component refinements (chart axis ticks, a visible label on table search boxes, breadcrumbs that collapse only when they overflow) are on the roadmap.
Verifying the images
As for v0.2.0, with the tag v0.2.1: docker run --rm ghcr.io/ncecere/grounded@sha256:<digest> version prints grounded v0.2.1 (<commit>), and each release has SPDX SBOMs, digest files and a checksums.txt.
Reporting problems
Report bugs and requests as GitHub issues. Report vulnerabilities privately, as SECURITY.md describes.