Skip to content

Releases: nripankadas07/trustline-mcp

v0.1.1 — adversarial hardening

Choose a tag to compare

@nripankadas07 nripankadas07 released this 16 Aug 08:57
0cdfe15

What changed

Fail-closed policy and audit validation, bounded pattern interpreter, notification semantics, transactional reports.

This release incorporates independent adversarial review, strict input and artifact boundaries, package hygiene, deterministic demos, and documented limitations. It remains an alpha/reference implementation, not a production safety certification.

Verification

  • 20/20 tests passed on each supported runtime (Node 22 and 24).
  • Final main CI and CodeQL default setup (extended, remote_and_local) passed.
  • Zero open code-scanning, Dependabot, or secret-scanning alerts at release time.
  • The attached package was installed and its real CLI/demo executed on both runtimes.
  • Demo output matched the checked-in golden artifacts byte-for-byte.

Assets

Release packages are accompanied by SHA256SUMS. See CHANGELOG.md, SECURITY.md, and the limitations documentation before use.

v0.1.0 — Initial public alpha

Choose a tag to compare

@nripankadas07 nripankadas07 released this 16 Aug 05:45

Initial public alpha/reference release.

  • Offline, no-key deterministic proof path
  • Versioned machine-readable artifacts plus reviewable Markdown and self-contained HTML
  • CI, packaging, security guidance, limitations, governance, and contribution workflow
  • Synthetic fixtures and explicit evidence boundaries where applicable

Start with the README and review the limitations before interpreting any score or security result.