What changed
Fail-closed policy and audit validation, bounded pattern interpreter, notification semantics, transactional reports.
This release incorporates independent adversarial review, strict input and artifact boundaries, package hygiene, deterministic demos, and documented limitations. It remains an alpha/reference implementation, not a production safety certification.
Verification
- 20/20 tests passed on each supported runtime (Node 22 and 24).
- Final
mainCI and CodeQL default setup (extended,remote_and_local) passed. - Zero open code-scanning, Dependabot, or secret-scanning alerts at release time.
- The attached package was installed and its real CLI/demo executed on both runtimes.
- Demo output matched the checked-in golden artifacts byte-for-byte.
Assets
Release packages are accompanied by SHA256SUMS. See CHANGELOG.md, SECURITY.md, and the limitations documentation before use.