Releases: noru-tech/fideslang-tools
Release list
0.2.0 - 2026-10-01
Release Notes
Added
fl doctor(--format text|json|yaml, exit 0): version, bundled taxonomy version and counts,
whether output gets colors and why (flag,FL_COLOR,NO_COLOR/CLICOLOR_FORCE/CLICOLOR,
terminal check,-o), whether./.fides/exists and how many manifest files and resources it
holds, and whether bash/zsh/fish completions and the man page appear installed. Every check is
best-effort and never fails the command.- README: "How do I update fl?" and the update policy:
flnever contacts the network and never
checks for updates; update withbrew upgrade fl,cargo binstall fideslang-clior GitHub
Releases. - Release archives contain shell completions (
completions/fl.bash,completions/_fl,
completions/fl.fish) and man pages (man/fl.1and one per subcommand), generated by
scripts/release-assets.shin a dist build-setup step. The Homebrew formula installs them into
Homebrew's bash, zsh and fish completion directories andman1. - Release archives contain
NOTICE, the attribution for the CC BY 4.0 taxonomy (Homebrew keeps
it inshare/fl/). fl validate --format sarif: a SARIF 2.1.0 log for GitHub code scanning and other SARIF tools.
Every validation code is a rule with ahelpUrito its page; each finding is a result with its
level, message, file and line (the resource'sfides_keyline when it can be found, else 1;
findings read from stdin point atstdin).fl validate --format yaml: the JSON report as YAML, likefl statsandfl taxonomy show.fl validate --format jsongains two additive fields: a top-level"schema_version": 1and a
"help_uri"on each finding. Existing fields are unchanged.- The text report ends (before the summary line) with one
see <url>line per code found, linking
todocs/rules/<CODE>.md; GitHub annotations end with the same link. The base URL is one
constant,DOCS_BASE. --no-colorglobal flag, the same as--color never; it wins over--colorandFL_COLOR.
NO_COLOR,CLICOLOR_FORCEandFL_COLORbehave as before.-v/--verboseglobal flag: extra diagnostics on stderr (files loaded, resource counts, the
filter's effect, timings, the exit code). Stdout is byte-identical with and without it.- A missing manifest path (or no path and no
./.fides/) now prints a fix hint,
hint: pass a file or directory, e.g. fl validate path/to/manifests, after the error. Exit code
stays2. src/validate/codes.rs: one table of validation codes (code, severity, title).-W, the
--deny/--allowcheck and the docs test read it;cargo testfails if a rule emits a code
that is not in the table, or with another severity, or if a code has no docs page.docs/rules/: one page per validation code (E001–E007, W001–W005) with the rule, why it matters,
the controls it relates to, a failing and a passing example with realfl validateoutput, how to
fix it and how to promote or silence it, plus an index. The README rules table links each code.docs/exit-codes.md: what exit codes 0, 1 and 2 mean and which commands return them.llms.txtat the repository root (llms.txt convention): summary, install commands and links to
the key pages.docs/openssf-best-practices.md: prepared answers for the OpenSSF Best Practices "passing"
criteria, with evidence links.- Test fixtures:
tests/fixtures/invalid/w001_deprecated_key.yml(W001 had none) and a corrected,
clean copy of every failing fixture undertests/fixtures/valid/.cargo testchecks that the
passing fixtures stay clean and that every code has a documentation page linked from the README. codeql.yml: CodeQL static analysis of the Rust, Python and workflow code on every pull request,
on main and weekly; results go to code scanning.
Fixed
fl validate --format githubno longer escapes:and,in annotation messages (only in the
fileandtitleproperties, where the runner expects it), so comma-separated "did you mean"
suggestions no longer show%2C. File paths infile=are now escaped too.
Changed
--deny/--allowwith an unknown code is now a usage error (exit2) whose message lists
the valid codes; it used to be accepted and ignored.- Writing to a closed pipe (
fl taxonomy list all --format plain | head -1) now stops quietly
with exit0instead of printingerror: Broken pipe. - README: several headings are now the questions people ask ("How do I install fl?", "How do I
validate a Fides manifest offline?", "How do I draw a data map from Fides manifests?", "How do I
cite fl?"), each answered in its first sentence. The E003 row now listsorganization_fides_key. - CONTRIBUTING and the pull request template: a new rule needs a passing fixture and a docs page.
Install fideslang-cli 0.2.0
Install prebuilt binaries via shell script
curl --proto '=https' --tlsv1.2 -LsSf https://github.com/noru-tech/fideslang-tools/releases/download/v0.2.0/fideslang-cli-installer.sh | shInstall prebuilt binaries via Homebrew
brew install noru-tech/tap/flDownload fideslang-cli 0.2.0
| File | Platform | Checksum |
|---|---|---|
| fideslang-cli-aarch64-apple-darwin.tar.xz | Apple Silicon macOS | checksum |
| fideslang-cli-x86_64-apple-darwin.tar.xz | Intel macOS | checksum |
| fideslang-cli-aarch64-unknown-linux-musl.tar.xz | ARM64 MUSL Linux | checksum |
| fideslang-cli-x86_64-unknown-linux-musl.tar.xz | x64 MUSL Linux | checksum |
Verifying GitHub Artifact Attestations
The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:
gh attestation verify <file-path of downloaded artifact> --repo noru-tech/fideslang-toolsYou can also download the attestation from GitHub and verify against that directly:
gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation> --repo noru-tech/fideslang-tools0.1.3 - 2026-10-01
Release Notes
Changed
- Dependencies refreshed:
serde-saphyrrequirement raised to 1.3 (already locked); all other crates
and every pinned GitHub Action were already at their latest releases.
Install fideslang-cli 0.1.3
Install prebuilt binaries via shell script
curl --proto '=https' --tlsv1.2 -LsSf https://github.com/noru-tech/fideslang-tools/releases/download/v0.1.3/fideslang-cli-installer.sh | shInstall prebuilt binaries via Homebrew
brew install noru-tech/tap/flDownload fideslang-cli 0.1.3
| File | Platform | Checksum |
|---|---|---|
| fideslang-cli-aarch64-apple-darwin.tar.xz | Apple Silicon macOS | checksum |
| fideslang-cli-x86_64-apple-darwin.tar.xz | Intel macOS | checksum |
| fideslang-cli-aarch64-unknown-linux-musl.tar.xz | ARM64 MUSL Linux | checksum |
| fideslang-cli-x86_64-unknown-linux-musl.tar.xz | x64 MUSL Linux | checksum |
Verifying GitHub Artifact Attestations
The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:
gh attestation verify <file-path of downloaded artifact> --repo noru-tech/fideslang-toolsYou can also download the attestation from GitHub and verify against that directly:
gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation> --repo noru-tech/fideslang-tools0.1.2 - 2026-09-30
Release Notes
Added
- Releases attach a CycloneDX SBOM (
fideslang-cli.cdx.xml) generated bycargo-cyclonedx. - Every release publishes
fideslang-clito crates.io:release.ymlcallspublish-crate.ymlas
a dist custom publish job after the GitHub Release is up. It uses Trusted Publishing (OIDC, no
stored secret), skips a version that is already published, and can be run by hand with a tag. - OpenSSF Scorecard workflow and README badge.
CITATION.cff, issue forms, pull request template andCODEOWNERS;docs/demo.tape(VHS script
for a README demo).
Changed
- README restructured: install (Homebrew, release archives), how to verify an archive with
gh attestation verifyand its SHA-256 file, a zero-config quick start, limitations, output
formats and exit codes, citation and trust sections. - The crate is published on crates.io as
fideslang-cli: README shows its badge and the
cargo binstall/cargo installlines. It no longer advertises thecurl | shinstaller. - Crate description and categories updated (
parser-implementationsreplacesdata-structures). release.ymlgrantscontents: writeonly to the jobs that create and upload the release.SECURITY.mdlinks GitHub private vulnerability reporting directly.
Install fideslang-cli 0.1.2
Install prebuilt binaries via shell script
curl --proto '=https' --tlsv1.2 -LsSf https://github.com/noru-tech/fideslang-tools/releases/download/v0.1.2/fideslang-cli-installer.sh | shInstall prebuilt binaries via Homebrew
brew install noru-tech/tap/flDownload fideslang-cli 0.1.2
| File | Platform | Checksum |
|---|---|---|
| fideslang-cli-aarch64-apple-darwin.tar.xz | Apple Silicon macOS | checksum |
| fideslang-cli-x86_64-apple-darwin.tar.xz | Intel macOS | checksum |
| fideslang-cli-aarch64-unknown-linux-musl.tar.xz | ARM64 MUSL Linux | checksum |
| fideslang-cli-x86_64-unknown-linux-musl.tar.xz | x64 MUSL Linux | checksum |
Verifying GitHub Artifact Attestations
The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:
gh attestation verify <file-path of downloaded artifact> --repo noru-tech/fideslang-toolsYou can also download the attestation from GitHub and verify against that directly:
gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation> --repo noru-tech/fideslang-tools0.1.1 - 2026-09-14
Release Notes
Security
fl splitnow refuses resource types andfides_keys that are not plain file names (path
separators,.,..), so a crafted manifest can no longer write files outside--out-dir.
Install fideslang-cli 0.1.1
Install prebuilt binaries via shell script
curl --proto '=https' --tlsv1.2 -LsSf https://github.com/noru-tech/fideslang-tools/releases/download/v0.1.1/fideslang-cli-installer.sh | shInstall prebuilt binaries via Homebrew
brew install noru-tech/tap/flDownload fideslang-cli 0.1.1
| File | Platform | Checksum |
|---|---|---|
| fideslang-cli-aarch64-apple-darwin.tar.xz | Apple Silicon macOS | checksum |
| fideslang-cli-x86_64-apple-darwin.tar.xz | Intel macOS | checksum |
| fideslang-cli-aarch64-unknown-linux-musl.tar.xz | ARM64 MUSL Linux | checksum |
| fideslang-cli-x86_64-unknown-linux-musl.tar.xz | x64 MUSL Linux | checksum |
Verifying GitHub Artifact Attestations
The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:
gh attestation verify <file-path of downloaded artifact> --repo noru-tech/fideslang-toolsYou can also download the attestation from GitHub and verify against that directly:
gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation> --repo noru-tech/fideslang-tools0.1.0 - 2026-09-13
Release Notes
Added
- Initial
flcommand-line tool for working with Fideslang taxonomies and Fides manifests. - Bundled, offline snapshot of the IAB Tech Lab Privacy Taxonomy (IABTechLab/fideslang 3.0.0).
fl taxonomy list|cat|tree|show|search|diff|infofor browsing and visualizing the taxonomy.fl cat|convert|merge|splitfor reading and transforming manifests between YAML, JSON and CSV.fl validatewith stable diagnostic codes and "did you mean" suggestions;fl stats.fl graphrendering system/dataset/data-use relationships as Graphviz DOT or Mermaid.- Shell completions (
fl completions) and man pages (fl manpage).
Install fideslang-cli 0.1.0
Install prebuilt binaries via shell script
curl --proto '=https' --tlsv1.2 -LsSf https://github.com/noru-tech/fideslang-tools/releases/download/v0.1.0/fideslang-cli-installer.sh | shInstall prebuilt binaries via Homebrew
brew install noru-tech/tap/flDownload fideslang-cli 0.1.0
| File | Platform | Checksum |
|---|---|---|
| fideslang-cli-aarch64-apple-darwin.tar.xz | Apple Silicon macOS | checksum |
| fideslang-cli-x86_64-apple-darwin.tar.xz | Intel macOS | checksum |
| fideslang-cli-aarch64-unknown-linux-musl.tar.xz | ARM64 MUSL Linux | checksum |
| fideslang-cli-x86_64-unknown-linux-musl.tar.xz | x64 MUSL Linux | checksum |
Verifying GitHub Artifact Attestations
The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:
gh attestation verify <file-path of downloaded artifact> --repo noru-tech/fideslang-toolsYou can also download the attestation from GitHub and verify against that directly:
gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation> --repo noru-tech/fideslang-tools