Releases: noqt/Lumi-Trace
Release list
v0.10.0
What's Changed
Current first-use path on main (post-release)
This release predates the current no-install Bandit-to-Lumi walkthrough. You can inspect the supplied input and exact result before forking:
https://github.com/noqt/Lumi-Trace/blob/main/docs/TRY_BANDIT_DEMO.md
The workflow runs Bandit 1.9.4 with B602 against an inert app.py fixture. Bandit performs the synthetic scan and already supplies the location; Lumi consumes that SARIF result, builds one review path (app.py) and verifies the bounded evidence package during the job. Artifact upload is disabled. GitHub retains its normal workflow logs and job summary.
This is a synthetic scanner-to-Lumi walkthrough, not a benchmark, model-uplift claim, real vulnerability report or independent-use claim. Lumi is not a vulnerability scanner.
Synthetic Python AppSec worked example
Use the public synthetic-only workflow to map the bundled quickstart finding to likely source context and produce a hash-bound evidence package:
https://github.com/noqt/Lumi-Trace/blob/main/docs/experiments/lumi-python-appsec-context-v1.md
The example uses public synthetic inputs and makes no vulnerability or adoption claim. Its optional privacy-minimised public-receipt window was fixed at 14 days from its recorded T0 and has closed.
Full Changelog: v0.8.1...v0.10.0
v0.8.1
v0.8.0
v0.7.1
v0.5.0
v0.4.2
What's Changed
Full Changelog: v0.4.1...v0.4.2
v0.4.1 (superseded by v0.4.2)
This release is superseded by v0.4.2. Use v0.4.2 for the current public documentation and package boundary.
What's Changed
- Lumi Trace V0.1.0 controlled internal release review by @noqt in #1
- Prepare Lumi Trace v0.4.1 deterministic GitHub release by @noqt in #11
New Contributors
Full Changelog: v0.1.0...v0.4.1
Lumi Trace v0.1.0
Lumi Trace v0.1.0 is the initial public source release of the deterministic, customer-local vulnerability evidence instrument.
Highlights:
- strict manual and SARIF finding import;
- immutable repository snapshots and deterministic indexing/ranking;
- qualified network-denied Docker reproduction;
- fail-closed evidence classification and JSON/SARIF export;
- zero model weights, zero runtime dependencies, and no hosted inference.
Release controls:
- seal: lumi-trace-v0.1-seal:48b9e02f2778e4417861408e41b3dd9175923c0a17d87fe5a493a5c32b5c56b3
- source revision: 8f7c235
- wheel SHA-256: sha256:c3872c3ab25b1df4c4e2f31711f9072d25e4955a1cda3eecd89e421d901c0bba
- source archive SHA-256: sha256:96aaaeb71e49d18ddb98c1be7a65541c2729e56d64083ec637ae307056aa217a
TRACE-001 training remains unauthorised: DO_NOT_BEGIN_TRACE_001.