Repository navigation
Releases: rioriost/postgresem
Release list
postgresem 1.0.1 — macOS 27 rebuild
postgresem 1.0.1 — macOS 27 rebuild
macOS arm64 and amd64 executables were rebuilt with Xcode 27 RC / macOS 27 SDK, Developer ID signed, and accepted by Apple notarization. Application runtime source, external dependencies and public behavior are unchanged from v1.0.0 except for the release version label.
Release automation verifies pinned signed executables, exercises each architecture on native macOS runners, packages metadata from the tagged source, and signs the final SHA256SUMS with the GitHub release workflow identity. Linux binaries and container qualification remain part of the standard release workflow.
The maintainer explicitly approved a v1.0.1-only waiver of independent external review, reviewed-container-image evidence and two 28-day field pilots under ADR 0021. These requirements are waived, not completed. The automated delta review is not an independent third-party assessment. Technical release checks are retained.
Source: 9b79bb686d9d4e06573d5b869b714892e9802a4c.
Release workflow.
Full Changelog: v1.0.0...v1.0.1
Build inputs for macOS 27 release qualification
Digest-pinned Developer ID signed and Apple-notarized executable inputs for the v1.0.1 release workflow. This prerelease is retained for reproducibility. End users should use the final v1.0.1 release, whose tagged metadata and signed checksums are generated after native qualification.
PostgreSQL Semantic Gateway 1.0.0
PostgreSQL Semantic Gateway 1.0.0
The first stable release of postgresem: a PostgreSQL-native semantic gateway
for agents and applications, with governed queries and ingestion instead of a
raw-SQL public interface.
Highlights
- Stable LSQ/LSM, Semantic Snapshot, MCP, CLI, error, migration, and audit
contracts, with documented compatibility, support, and deprecation policies. - Deterministic typed compilation, immutable model publication, catalog drift
detection, and anchored aggregation that preserves the declared business
grain rather than multiplying measures through fan-out joins. - PostgreSQL GRANT/RLS enforcement, guarded query execution, governed
insert/upsert, durable audit, idempotent replay, and role-bound reconciliation. - Stdio and authenticated HTTP MCP, plus Docker, Compose, Podman, and Quadlet
deployment paths. - Meaning Lab, one real-PostgreSQL demo comparing schema-only candidate
queries with explicit business semantics for recognized revenue, SKU revenue,
and MRR. It also demonstrates governed writes, retries, reconciliation,
tenant RLS, and rejection boundaries. English is the default; Japanese is
selectable. The optional OpenAI planner requires explicit user configuration;
the default comparisons are authored scenarios, not fabricated agent output.
Upgrade requirement
Apply migrations through 0011_mutation_reconcile_writer_role before
deploying the new binary. Reconciliation now requires the recorded writer
role as well as the principal. The old role-unbound overload is removed;
do not recreate it during rollback. Cross-version reconciliation at this
schema boundary fails closed. Unused time and PEM/ASN.1 dependencies have
also been removed.
Release evidence and limitations
This release uses the explicitly approved
v1.0.0-only maintainer exception.
The automated source review and remediation evidence
is accepted for corrected source c8a2ca7. Independent third-party review,
reviewed-image evidence, and two 28-day non-fixture pilots are waived, not
completed; field outcomes are not measured. Subsequent changes are restricted
to the documented release-governance paths. Runtime authorization, technical
qualification, artifact signing, SBOM, and provenance controls remain in place.
The exception does not carry forward to later stable releases.
Downloads
Binary archives are available for Linux and macOS, each on amd64 and arm64.
The assets include native Linux binary/image runtime evidence and signed
SHA256SUMS. The multi-architecture container image is
ghcr.io/rioriost/postgresem:1.0.0.
Immutable image:
ghcr.io/rioriost/postgresem@sha256:3b79ad1976f9f87cef54c0195b1fdb71d48542c971cb155345a98232802bf330.
Release commit:
a9315827861ec4b807bdbf5ff4ce92fe3900b808.
Follow release verification
before running an archive or image. Pin the verified container digest for
deployment.
Changelog
| English guide
| Japanese guide
| Changes since v0.7.0
v0.7.0
v0.6.0
v0.5.0
v0.4.0
What's Changed
- chore(deps): Bump sha2 from 0.10.9 to 0.11.0 by @dependabot[bot] in #1
- chore(deps): Bump the github-actions group across 1 directory with 9 updates by @dependabot[bot] in #5
New Contributors
- @dependabot[bot] made their first contribution in #1
Full Changelog: v0.3.0-beta.1...v0.4.0