Skip to content

Releases: noru-tech/fideslang-tools

0.2.0 - 2026-10-01

Choose a tag to compare

@github-actions github-actions released this 01 Oct 10:36
Immutable release. Only release title and notes can be modified.
1c04a46

Release Notes

Added

  • fl doctor (--format text|json|yaml, exit 0): version, bundled taxonomy version and counts,
    whether output gets colors and why (flag, FL_COLOR, NO_COLOR / CLICOLOR_FORCE / CLICOLOR,
    terminal check, -o), whether ./.fides/ exists and how many manifest files and resources it
    holds, and whether bash/zsh/fish completions and the man page appear installed. Every check is
    best-effort and never fails the command.
  • README: "How do I update fl?" and the update policy: fl never contacts the network and never
    checks for updates; update with brew upgrade fl, cargo binstall fideslang-cli or GitHub
    Releases.
  • Release archives contain shell completions (completions/fl.bash, completions/_fl,
    completions/fl.fish) and man pages (man/fl.1 and one per subcommand), generated by
    scripts/release-assets.sh in a dist build-setup step. The Homebrew formula installs them into
    Homebrew's bash, zsh and fish completion directories and man1.
  • Release archives contain NOTICE, the attribution for the CC BY 4.0 taxonomy (Homebrew keeps
    it in share/fl/).
  • fl validate --format sarif: a SARIF 2.1.0 log for GitHub code scanning and other SARIF tools.
    Every validation code is a rule with a helpUri to its page; each finding is a result with its
    level, message, file and line (the resource's fides_key line when it can be found, else 1;
    findings read from stdin point at stdin).
  • fl validate --format yaml: the JSON report as YAML, like fl stats and fl taxonomy show.
  • fl validate --format json gains two additive fields: a top-level "schema_version": 1 and a
    "help_uri" on each finding. Existing fields are unchanged.
  • The text report ends (before the summary line) with one see <url> line per code found, linking
    to docs/rules/<CODE>.md; GitHub annotations end with the same link. The base URL is one
    constant, DOCS_BASE.
  • --no-color global flag, the same as --color never; it wins over --color and FL_COLOR.
    NO_COLOR, CLICOLOR_FORCE and FL_COLOR behave as before.
  • -v / --verbose global flag: extra diagnostics on stderr (files loaded, resource counts, the
    filter's effect, timings, the exit code). Stdout is byte-identical with and without it.
  • A missing manifest path (or no path and no ./.fides/) now prints a fix hint,
    hint: pass a file or directory, e.g. fl validate path/to/manifests, after the error. Exit code
    stays 2.
  • src/validate/codes.rs: one table of validation codes (code, severity, title). -W, the
    --deny / --allow check and the docs test read it; cargo test fails if a rule emits a code
    that is not in the table, or with another severity, or if a code has no docs page.
  • docs/rules/: one page per validation code (E001–E007, W001–W005) with the rule, why it matters,
    the controls it relates to, a failing and a passing example with real fl validate output, how to
    fix it and how to promote or silence it, plus an index. The README rules table links each code.
  • docs/exit-codes.md: what exit codes 0, 1 and 2 mean and which commands return them.
  • llms.txt at the repository root (llms.txt convention): summary, install commands and links to
    the key pages.
  • docs/openssf-best-practices.md: prepared answers for the OpenSSF Best Practices "passing"
    criteria, with evidence links.
  • Test fixtures: tests/fixtures/invalid/w001_deprecated_key.yml (W001 had none) and a corrected,
    clean copy of every failing fixture under tests/fixtures/valid/. cargo test checks that the
    passing fixtures stay clean and that every code has a documentation page linked from the README.
  • codeql.yml: CodeQL static analysis of the Rust, Python and workflow code on every pull request,
    on main and weekly; results go to code scanning.

Fixed

  • fl validate --format github no longer escapes : and , in annotation messages (only in the
    file and title properties, where the runner expects it), so comma-separated "did you mean"
    suggestions no longer show %2C. File paths in file= are now escaped too.

Changed

  • --deny / --allow with an unknown code is now a usage error (exit 2) whose message lists
    the valid codes; it used to be accepted and ignored.
  • Writing to a closed pipe (fl taxonomy list all --format plain | head -1) now stops quietly
    with exit 0 instead of printing error: Broken pipe.
  • README: several headings are now the questions people ask ("How do I install fl?", "How do I
    validate a Fides manifest offline?", "How do I draw a data map from Fides manifests?", "How do I
    cite fl?"), each answered in its first sentence. The E003 row now lists organization_fides_key.
  • CONTRIBUTING and the pull request template: a new rule needs a passing fixture and a docs page.

Install fideslang-cli 0.2.0

Install prebuilt binaries via shell script

curl --proto '=https' --tlsv1.2 -LsSf https://github.com/noru-tech/fideslang-tools/releases/download/v0.2.0/fideslang-cli-installer.sh | sh

Install prebuilt binaries via Homebrew

brew install noru-tech/tap/fl

Download fideslang-cli 0.2.0

File Platform Checksum
fideslang-cli-aarch64-apple-darwin.tar.xz Apple Silicon macOS checksum
fideslang-cli-x86_64-apple-darwin.tar.xz Intel macOS checksum
fideslang-cli-aarch64-unknown-linux-musl.tar.xz ARM64 MUSL Linux checksum
fideslang-cli-x86_64-unknown-linux-musl.tar.xz x64 MUSL Linux checksum

Verifying GitHub Artifact Attestations

The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:

gh attestation verify <file-path of downloaded artifact> --repo noru-tech/fideslang-tools

You can also download the attestation from GitHub and verify against that directly:

gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation> --repo noru-tech/fideslang-tools

0.1.3 - 2026-10-01

Choose a tag to compare

@github-actions github-actions released this 01 Oct 06:55
Immutable release. Only release title and notes can be modified.
d29966d

Release Notes

Changed

  • Dependencies refreshed: serde-saphyr requirement raised to 1.3 (already locked); all other crates
    and every pinned GitHub Action were already at their latest releases.

Install fideslang-cli 0.1.3

Install prebuilt binaries via shell script

curl --proto '=https' --tlsv1.2 -LsSf https://github.com/noru-tech/fideslang-tools/releases/download/v0.1.3/fideslang-cli-installer.sh | sh

Install prebuilt binaries via Homebrew

brew install noru-tech/tap/fl

Download fideslang-cli 0.1.3

File Platform Checksum
fideslang-cli-aarch64-apple-darwin.tar.xz Apple Silicon macOS checksum
fideslang-cli-x86_64-apple-darwin.tar.xz Intel macOS checksum
fideslang-cli-aarch64-unknown-linux-musl.tar.xz ARM64 MUSL Linux checksum
fideslang-cli-x86_64-unknown-linux-musl.tar.xz x64 MUSL Linux checksum

Verifying GitHub Artifact Attestations

The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:

gh attestation verify <file-path of downloaded artifact> --repo noru-tech/fideslang-tools

You can also download the attestation from GitHub and verify against that directly:

gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation> --repo noru-tech/fideslang-tools

0.1.2 - 2026-09-30

Choose a tag to compare

@github-actions github-actions released this 01 Oct 05:46
9bfcc6c

Release Notes

Added

  • Releases attach a CycloneDX SBOM (fideslang-cli.cdx.xml) generated by cargo-cyclonedx.
  • Every release publishes fideslang-cli to crates.io: release.yml calls publish-crate.yml as
    a dist custom publish job after the GitHub Release is up. It uses Trusted Publishing (OIDC, no
    stored secret), skips a version that is already published, and can be run by hand with a tag.
  • OpenSSF Scorecard workflow and README badge.
  • CITATION.cff, issue forms, pull request template and CODEOWNERS; docs/demo.tape (VHS script
    for a README demo).

Changed

  • README restructured: install (Homebrew, release archives), how to verify an archive with
    gh attestation verify and its SHA-256 file, a zero-config quick start, limitations, output
    formats and exit codes, citation and trust sections.
  • The crate is published on crates.io as fideslang-cli: README shows its badge and the
    cargo binstall / cargo install lines. It no longer advertises the curl | sh installer.
  • Crate description and categories updated (parser-implementations replaces data-structures).
  • release.yml grants contents: write only to the jobs that create and upload the release.
  • SECURITY.md links GitHub private vulnerability reporting directly.

Install fideslang-cli 0.1.2

Install prebuilt binaries via shell script

curl --proto '=https' --tlsv1.2 -LsSf https://github.com/noru-tech/fideslang-tools/releases/download/v0.1.2/fideslang-cli-installer.sh | sh

Install prebuilt binaries via Homebrew

brew install noru-tech/tap/fl

Download fideslang-cli 0.1.2

File Platform Checksum
fideslang-cli-aarch64-apple-darwin.tar.xz Apple Silicon macOS checksum
fideslang-cli-x86_64-apple-darwin.tar.xz Intel macOS checksum
fideslang-cli-aarch64-unknown-linux-musl.tar.xz ARM64 MUSL Linux checksum
fideslang-cli-x86_64-unknown-linux-musl.tar.xz x64 MUSL Linux checksum

Verifying GitHub Artifact Attestations

The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:

gh attestation verify <file-path of downloaded artifact> --repo noru-tech/fideslang-tools

You can also download the attestation from GitHub and verify against that directly:

gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation> --repo noru-tech/fideslang-tools

0.1.1 - 2026-09-14

Choose a tag to compare

@github-actions github-actions released this 14 Sep 09:48

Release Notes

Security

  • fl split now refuses resource types and fides_keys that are not plain file names (path
    separators, ., ..), so a crafted manifest can no longer write files outside --out-dir.

Install fideslang-cli 0.1.1

Install prebuilt binaries via shell script

curl --proto '=https' --tlsv1.2 -LsSf https://github.com/noru-tech/fideslang-tools/releases/download/v0.1.1/fideslang-cli-installer.sh | sh

Install prebuilt binaries via Homebrew

brew install noru-tech/tap/fl

Download fideslang-cli 0.1.1

File Platform Checksum
fideslang-cli-aarch64-apple-darwin.tar.xz Apple Silicon macOS checksum
fideslang-cli-x86_64-apple-darwin.tar.xz Intel macOS checksum
fideslang-cli-aarch64-unknown-linux-musl.tar.xz ARM64 MUSL Linux checksum
fideslang-cli-x86_64-unknown-linux-musl.tar.xz x64 MUSL Linux checksum

Verifying GitHub Artifact Attestations

The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:

gh attestation verify <file-path of downloaded artifact> --repo noru-tech/fideslang-tools

You can also download the attestation from GitHub and verify against that directly:

gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation> --repo noru-tech/fideslang-tools

0.1.0 - 2026-09-13

Choose a tag to compare

@github-actions github-actions released this 13 Sep 13:18

Release Notes

Added

  • Initial fl command-line tool for working with Fideslang taxonomies and Fides manifests.
  • Bundled, offline snapshot of the IAB Tech Lab Privacy Taxonomy (IABTechLab/fideslang 3.0.0).
  • fl taxonomy list|cat|tree|show|search|diff|info for browsing and visualizing the taxonomy.
  • fl cat|convert|merge|split for reading and transforming manifests between YAML, JSON and CSV.
  • fl validate with stable diagnostic codes and "did you mean" suggestions; fl stats.
  • fl graph rendering system/dataset/data-use relationships as Graphviz DOT or Mermaid.
  • Shell completions (fl completions) and man pages (fl manpage).

Install fideslang-cli 0.1.0

Install prebuilt binaries via shell script

curl --proto '=https' --tlsv1.2 -LsSf https://github.com/noru-tech/fideslang-tools/releases/download/v0.1.0/fideslang-cli-installer.sh | sh

Install prebuilt binaries via Homebrew

brew install noru-tech/tap/fl

Download fideslang-cli 0.1.0

File Platform Checksum
fideslang-cli-aarch64-apple-darwin.tar.xz Apple Silicon macOS checksum
fideslang-cli-x86_64-apple-darwin.tar.xz Intel macOS checksum
fideslang-cli-aarch64-unknown-linux-musl.tar.xz ARM64 MUSL Linux checksum
fideslang-cli-x86_64-unknown-linux-musl.tar.xz x64 MUSL Linux checksum

Verifying GitHub Artifact Attestations

The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:

gh attestation verify <file-path of downloaded artifact> --repo noru-tech/fideslang-tools

You can also download the attestation from GitHub and verify against that directly:

gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation> --repo noru-tech/fideslang-tools