proof-pr v0.2.5
proof-pr v0.2.5
This patch release adds read-only receipt hygiene suggestions for common missing proof evidence.
Highlights:
- Adds
proof-pr receipt-hygienefor pre-review evidence nudges. - Checks public metadata evidence, secrets posture, workflow permission posture, and rollback specificity.
- Supports
--jsonfor automation and--strictfor future soft gating. - Keeps the receipt schema stable and does not mutate receipts.
Proof:
- PR #15 passed
validate-proofbefore fast-forward merge. - Manual main self-check passed after merge.
- Hygiene text, JSON, warning/strict, and clean/strict smoke checks passed locally.
- Attached release receipt validates under
proof-pr.v1. - Receipt SHA-256:
916371034df9d29e4ee0706a9fc98abe5067290ab1675633d76fe7f7c9bcd817.
Hygiene note: the release tag, target commit, and receipt use noreply/public-safe metadata. This receipt is release review evidence, not supply-chain provenance. No wheel, sdist, SBOM, or artifact attestation is published for v0.2.5.