v0.2.0 — runs/ sandbox + default paths
Runtime sandbox + default-path cut
All runtime artefacts (key, report, mapping, term lists, plans, ignore lists) now land under ./runs/ by default. .gitignore ships the sandbox plus belt-and-braces per-artefact globs so default-named outputs stay out of the repo even when an operator runs outside runs/.
Pre-1.0 behaviour change: operators relying on the previous cwd-root defaults must pass explicit --report / --mapping flags or move artefacts under runs/.
CLI defaults
--reportdefault:./pseudonymize-report.jsonl→./runs/pseudonymize-report.jsonl--mappingdefault:./pseudonymize-mapping.json→./runs/pseudonymize-mapping.json- Parent directory of
--reportand--mappingis auto-created on first write, so the new default works on a fresh checkout without an explicitmkdir.
Gitignore
runs/ and local/ sandbox directories; per-artefact globs (*-mapping.json, *-report.jsonl, plan*.jsonl, discovery*.jsonl, ignore.txt, false-positives*.txt); term-list globs (terms.csv, terms.json); !tests/fixtures/** re-include so shipped fixtures stay tracked.
Docs aligned
README Quickstart, every docs/USAGE.md example block, docs/SECURITY.md paths + gitignore guidance, docs/ARCHITECTURE.md data-flow diagram, docs/USER_STORIES.md jq example, docs/roadmap.md (planned convenience items rolled to 0.3.0), docs/landscape/de-identification.md status reference.
Also included (from the pending [Unreleased] cut)
docs/assets/images/architecture-bird.svg— bird's-eye SVG of the public output lane vs the secret artifacts lane, embedded collapsed indocs/ARCHITECTURE.md.- 9 phantom
--flagrows removed fromdocs/USAGE.md; exit code7description widened to cover all three causes. docs/decisions/MADR layout (renamed fromdocs/ADR/);docs/COMPLIANCE.mdPHI disclaimer narrowed;NOTICEexpanded;docs/GLOSSARY.mdalphabetised.
Full diff: v0.1.0...v0.2.0