v0.7.2
v0.7.2 release evidence
Status: published and promoted. The signed tag, GitHub Release, npm package, provenance, immutable
verified-installer/bootstrap chain and signed v1 alias are publicly retrievable. Immutable and
post-promotion Action consumers passed.
Outcome
Scope, audit, harden, and retest web projects with AI coding agents and reproducible evidence.
v0.7.2 closes three reproduced false-clean or destructive paths and strengthens independently
executable evidence contracts without adding a detector family or framework claim.
- Demo reruns may clean only a marker-owned output directory and fixed generated children.
Pre-existing unowned directories, symlinks and protected paths are refused. - Technical evidence redaction recognizes normalized singular/plural credential containers and
bounded high-confidence token formats across every report-bundle renderer. It remains leak
prevention for known output shapes, not a general secret scanner. - Direct CommonJS Express routers and exact local CommonJS mounts are inventoried. A structurally
observed imported local registration function that cannot be resolved produces
express_registration_function_unresolved, partial coverage,unknownevidence and exit 3.
Exit 3 means the tool refused a clean result because evidence is incomplete; it is not a
vulnerability count. - Thirteen shipped JSON Schemas compile offline under Ajv Draft 2020-12 and share a curated
agreement corpus with handwritten validators. - The fixed-commit v0.7.0 ordinary-project access review derives all aggregate totals from complete,
digest-bound project records and has an explicit network-only refresh path. - Release documentation separates repository-local signer consistency, GitHub verification,
release-asset attestation, npm OIDC provenance and checksum/SBOM integrity.
Stable scope remains 25 built-in risk rules, three evidence-integrity rules, 16 opt-in external
adapter risk rules and the existing bounded Express, NestJS and Next.js App Router inventory.
Regression evidence
test/demo-output-safety.test.mjsproves an unowned sentinel and owner-created extra child survive
the demo path while a marked rerun succeeds.test/evidence-writer.test.mjsasserts a unique credential sentinel is absent from JSON,
Markdown, HTML, SARIF, JUnit and additional bundle artifacts while allowed evidence remains.- Express extractor and CLI integration fixtures cover direct CommonJS routers, exact mounts,
unresolved imported registration functions and a valid route-free worker neighbour. scripts/check-json-schema-contracts.mjscompiles every schema offline and checks Ajv/manual
agreement for curated positive and negative documents.test/v070-access-review-provenance.test.mjsrejects aggregate drift and project-record digest
tampering while preserving deterministic semantic route hashes.test/release-trust-boundaries.test.mjsrejects stale verification examples and language that
conflates repository-local signer consistency with GitHub account ownership.
Each silently reversible P0 branch has a machine assertion that was confirmed to fail when the old
behavior was planted. Focused Phase 1-7 checks passed before candidate freeze.
Published verification
The bounded candidate tree passed:
npm run check
npm pack --dry-run --json
/usr/local/bin/python3 /Users/kenn/.codex/skills/.system/skill-creator/scripts/quick_validate.py .
git diff --check
git -c gpg.ssh.allowedSignersFile=.github/release-signers verify-tag v0.7.2npm run check completed all generated-contract checks, local Node tests and the Bash 3.2 smoke
suite. Skill validation returned Skill is valid!. npm pack --dry-run --json reported 183 files,
552,526 packed bytes and 2,218,387 unpacked bytes. Real external-adapter tests remain opt-in and
were not downloaded for the local gate.
The first candidate-gate attempt exposed an integration regression: three repository generators
passed a pre-existing mkdtemp root to the newly ownership-aware demo. The generators now use a
new child output path; their existing deterministic --check gates caught the planted old behavior
and passed after the correction.
One final-tree full local gate, one package inspection and bounded channel consumers are enough
unless a channel-specific failure appears.
Public release facts
- The SSH-signed annotated
v0.7.2tag object
ecfa779d317c09d5f0948df880762a914d6f4abcpeels to source commit
30402c866b86d78b66d0d4b495fee40ff6a6f160. Final-tree CI run
32844389181
and CodeQL run
32844389183
passed before tagging. GitHub reports the tag signature asverified: true,reason: valid, and
repository-local.github/release-signersverification also passes. - GitHub Release workflow
32844662253
published the reproducible source archive, SPDX 2.3 SBOM, manifest and checksums on 2026-08-25.
Tag CI run
32844662312
also passed. Public SHA-256 values are
340413987722874ac2b2cac58d09f45e44b7f541dc06045e191a54654bc125fb(archive),
0e7702487a71ea601385be1adb10cb6c8aa75775aa3c63146c228fb82f23fc5f(SBOM),
642f59261ce225ca06d836d95c2046e29654447af18aee27cc352d5b49615207(manifest) and
6300c2822286bfc9913ee694f5daa629572a9a1367029684f5d54db931969552
(SHA256SUMS). Fresh downloads passed checksums, the 473-entry manifest, archive lifecycle,
GitHub asset-digest comparison and GitHub release-asset attestation. - npm workflow
32845017547
publishedweb-app-security-skill@0.7.2at2026-08-25T11:58:03.569Zthrough GitHub OIDC trusted
publishing. npm records source30402c866b86d78b66d0d4b495fee40ff6a6f160, shasum
4b57df8c5c1f60317ffbb1dc54302cd86884eb88, integrity
sha512-KftiDW+ABghvOlH38KU9GumhtL8NC+8Xkw6PmL/sptKvS/9xOsRPNjj6CJBMETwutADXIe09ea9iXAgFXfwRdQ==
and SLSA provenance.
Its 183 files matched corresponding files in the signed source byte for byte. - The four observed release digests are recorded in the verifier trust map, whose default is
0.7.2. The stable Action remains recorded at v0.7.1 until guardedv1promotion and its
post-promotion consumer pass. - Public-state commit
87326f11c0aab3901ac5cb0783d9452e607e83c5passed CI
32845505985
and CodeQL
32845505857.
Itsscripts/install-verified.mjsSHA-256 is
662b7de3d596bb6faf8fac4bf69f325f44c1152c99cbbea5fc25184863b1c6d5. scripts/bootstrap-install.sh, the release contract and English/Chinese verified-installation
paths now pin that immutable verifier and explicit v0.7.2 assets. The README-facing bootstrap
source commit3f42fb70f99f6ccb3c8e8449b2c06749c3b53148passed CI
32845795654
and CodeQL
32845795620.
Itsscripts/bootstrap-install.shSHA-256 is
193ece72d2c7d2c4220a6164a4bb280853ffca1e8de5217535fe95010c146e8a.- The README bootstrap and immutable Action examples now select those public v0.7.2 identities.
Publication commit68cb7fb24e40e4bbd75b13e469a7f57e4412714fpassed CI
32846176471
and CodeQL
32846176455. - A clean-room public bootstrap downloaded the script from immutable commit
3f42fb70f99f6ccb3c8e8449b2c06749c3b53148, matched SHA-256
193ece72d2c7d2c4220a6164a4bb280853ffca1e8de5217535fe95010c146e8a, installed all three
surfaces into an isolated temporary home and returnedWeb App Security Skill 0.7.2. It
verified source commit30402c866b86d78b66d0d4b495fee40ff6a6f160, archive, manifest,
checksums and SBOM. Because the isolated home could not access the macOS keyring, the bootstrap
accurately reported its optional GitHub attestation check as not run; a separate authenticated
gh attestation verifypassed the same public archive with SHA-256
340413987722874ac2b2cac58d09f45e44b7f541dc06045e191a54654bc125fb. - Pre-promotion Action consumer
32846524348
passed. Its immutable job consumed full commit
30402c866b86d78b66d0d4b495fee40ff6a6f160and verified route-security v2 control separation;
its stable job independently proved that the existing v0.7.1@v1alias still passed passive
crawl and authorization-refusal checks before movement. - Pre-promotion evidence commit
cfdad9bcd49396071b1e19510d7471d625e6dcc3passed CI
32846724386
and CodeQL
32846724421. - The SSH-signed annotated
v1tag moved with an exact guarded lease from tag object
b0df7d0c6bd2a9a596d591bb63cff6e6bc8471ffto
758036ee84ad2bc2f31a8ba08969acd2a6b87de6, which peels to
30402c866b86d78b66d0d4b495fee40ff6a6f160. GitHub reportsverified: trueand
reason: valid; repository-local.github/release-signersverification passed with ED25519
fingerprintSHA256:DmZYVL1dLhUmgaJnfZKpZIexgzMv5jk9+YCoBT3zRIg. - Post-promotion public
@v1consumer
32846972801
passed passive crawl, authorization refusal and immutable route-security v2 control-separation
checks.
Artifact identity, consumer success and provenance do not prove every detector conclusion correct
or an audited project secure. v1 is intentionally movable; consumers requiring an immutable
workflow must use the full source commit.