Immutable
release. Only release title and notes can be modified.
Release Notes
Added
fl doctor(--format text|json|yaml, exit 0): version, bundled taxonomy version and counts,
whether output gets colors and why (flag,FL_COLOR,NO_COLOR/CLICOLOR_FORCE/CLICOLOR,
terminal check,-o), whether./.fides/exists and how many manifest files and resources it
holds, and whether bash/zsh/fish completions and the man page appear installed. Every check is
best-effort and never fails the command.- README: "How do I update fl?" and the update policy:
flnever contacts the network and never
checks for updates; update withbrew upgrade fl,cargo binstall fideslang-clior GitHub
Releases. - Release archives contain shell completions (
completions/fl.bash,completions/_fl,
completions/fl.fish) and man pages (man/fl.1and one per subcommand), generated by
scripts/release-assets.shin a dist build-setup step. The Homebrew formula installs them into
Homebrew's bash, zsh and fish completion directories andman1. - Release archives contain
NOTICE, the attribution for the CC BY 4.0 taxonomy (Homebrew keeps
it inshare/fl/). fl validate --format sarif: a SARIF 2.1.0 log for GitHub code scanning and other SARIF tools.
Every validation code is a rule with ahelpUrito its page; each finding is a result with its
level, message, file and line (the resource'sfides_keyline when it can be found, else 1;
findings read from stdin point atstdin).fl validate --format yaml: the JSON report as YAML, likefl statsandfl taxonomy show.fl validate --format jsongains two additive fields: a top-level"schema_version": 1and a
"help_uri"on each finding. Existing fields are unchanged.- The text report ends (before the summary line) with one
see <url>line per code found, linking
todocs/rules/<CODE>.md; GitHub annotations end with the same link. The base URL is one
constant,DOCS_BASE. --no-colorglobal flag, the same as--color never; it wins over--colorandFL_COLOR.
NO_COLOR,CLICOLOR_FORCEandFL_COLORbehave as before.-v/--verboseglobal flag: extra diagnostics on stderr (files loaded, resource counts, the
filter's effect, timings, the exit code). Stdout is byte-identical with and without it.- A missing manifest path (or no path and no
./.fides/) now prints a fix hint,
hint: pass a file or directory, e.g. fl validate path/to/manifests, after the error. Exit code
stays2. src/validate/codes.rs: one table of validation codes (code, severity, title).-W, the
--deny/--allowcheck and the docs test read it;cargo testfails if a rule emits a code
that is not in the table, or with another severity, or if a code has no docs page.docs/rules/: one page per validation code (E001–E007, W001–W005) with the rule, why it matters,
the controls it relates to, a failing and a passing example with realfl validateoutput, how to
fix it and how to promote or silence it, plus an index. The README rules table links each code.docs/exit-codes.md: what exit codes 0, 1 and 2 mean and which commands return them.llms.txtat the repository root (llms.txt convention): summary, install commands and links to
the key pages.docs/openssf-best-practices.md: prepared answers for the OpenSSF Best Practices "passing"
criteria, with evidence links.- Test fixtures:
tests/fixtures/invalid/w001_deprecated_key.yml(W001 had none) and a corrected,
clean copy of every failing fixture undertests/fixtures/valid/.cargo testchecks that the
passing fixtures stay clean and that every code has a documentation page linked from the README. codeql.yml: CodeQL static analysis of the Rust, Python and workflow code on every pull request,
on main and weekly; results go to code scanning.
Fixed
fl validate --format githubno longer escapes:and,in annotation messages (only in the
fileandtitleproperties, where the runner expects it), so comma-separated "did you mean"
suggestions no longer show%2C. File paths infile=are now escaped too.
Changed
--deny/--allowwith an unknown code is now a usage error (exit2) whose message lists
the valid codes; it used to be accepted and ignored.- Writing to a closed pipe (
fl taxonomy list all --format plain | head -1) now stops quietly
with exit0instead of printingerror: Broken pipe. - README: several headings are now the questions people ask ("How do I install fl?", "How do I
validate a Fides manifest offline?", "How do I draw a data map from Fides manifests?", "How do I
cite fl?"), each answered in its first sentence. The E003 row now listsorganization_fides_key. - CONTRIBUTING and the pull request template: a new rule needs a passing fixture and a docs page.
Install fideslang-cli 0.2.0
Install prebuilt binaries via shell script
curl --proto '=https' --tlsv1.2 -LsSf https://github.com/noru-tech/fideslang-tools/releases/download/v0.2.0/fideslang-cli-installer.sh | shInstall prebuilt binaries via Homebrew
brew install noru-tech/tap/flDownload fideslang-cli 0.2.0
| File | Platform | Checksum |
|---|---|---|
| fideslang-cli-aarch64-apple-darwin.tar.xz | Apple Silicon macOS | checksum |
| fideslang-cli-x86_64-apple-darwin.tar.xz | Intel macOS | checksum |
| fideslang-cli-aarch64-unknown-linux-musl.tar.xz | ARM64 MUSL Linux | checksum |
| fideslang-cli-x86_64-unknown-linux-musl.tar.xz | x64 MUSL Linux | checksum |
Verifying GitHub Artifact Attestations
The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:
gh attestation verify <file-path of downloaded artifact> --repo noru-tech/fideslang-toolsYou can also download the attestation from GitHub and verify against that directly:
gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation> --repo noru-tech/fideslang-tools