Releases: niansia/ContextSec
Release list
ContextSec v0.4.1
Research Preview
ContextSec is an applicability and evidence decision layer. It is not a penetration test or compliance certification.
Independent ecosystem accuracy has not yet been established. The published corpus is maintainer-authored. External labels must follow the non-contributor, distinct-organization protocol, and holdout results are headline-eligible only when both frozen labels and commit-bound predictions have verified attestations.
What's Changed
Full Changelog: v0.4.0...v0.4.1
ContextSec v0.4.0
Research Preview
ContextSec is an applicability and evidence decision layer. It is not a penetration test or compliance certification.
Independent ecosystem accuracy has not yet been established. The published corpus is maintainer-authored. External labels must follow the non-contributor, distinct-organization protocol, and holdout results are headline-eligible only when both frozen labels and commit-bound predictions have verified attestations.
What's Changed
Full Changelog: v0.3.3...v0.4.0
ContextSec v0.3.3
Research Preview
ContextSec is an applicability and evidence decision layer. It is not a penetration test or compliance certification.
Independent ecosystem accuracy has not yet been established. The published corpus is maintainer-authored; external labels and holdout results must be evaluated separately.
What's Changed
- Retry asynchronous release attestation verification by @niansia in #10
- Allow ten minutes for release attestations by @niansia in #11
- Pin the release attestation verifier by @niansia in #12
- Release v0.3.3 verifier compatibility hotfix by @niansia in #13
Full Changelog: v0.3.2...v0.3.3
ContextSec v0.3.2
Research Preview
ContextSec is an applicability and evidence decision layer. It is not a penetration test or compliance certification.
Independent ecosystem accuracy has not yet been established. The published corpus is maintainer-authored; external labels and holdout results must be evaluated separately.
What's Changed
Full Changelog: v0.3.1...v0.3.2
ContextSec v0.3.1
What's Changed
- chore(deps): bump next from 15.0.0 to 15.5.21 in /examples/composite-saas by @dependabot[bot] in #7
- Harden v0.3.1 release evidence and privacy boundaries by @niansia in #8
New Contributors
Full Changelog: v0.3.0...v0.3.1
ContextSec v0.3.0 — Research Preview
First public research preview of ContextSec, the product-security decision layer for AI coding agents.
Highlights:
- 16 product-risk packs, 116 controls, and 9 cross-context compositions
- Evidence-backed Security Profile, deterministic control checks, Control Evaluation Ledger, and release gate
- Fixed no-argument auth(), Clerk/Drizzle and tenant-key aliases, public client-secret namespaces, and unsupported-stack reporting
- Tenant-scoped Prisma CRUD enumeration plus raw-query abstention
- 40 labeled profile cases, 10/10 mutation verification, and 4/4 immutable real-repository cases
- Positive/negative contracts for every published text and dependency detector
- Windows, macOS, and Ubuntu CI across Python 3.11-3.14
- Local-first, offline, read-only profiling with no target-code execution
Artifact:
- contextsec-v0.3.0.zip
- SHA256: a5acebd589227114d5f80613c35d6219c3e65641449d2a466e83753b2f098125
This is a Research Preview, not a penetration-testing or compliance-certification product. Profile accuracy is measured on a maintainer-authored corpus; the four pinned repositories are case studies, not a representative ecosystem sample.