-
Notifications
You must be signed in to change notification settings - Fork 0
Release Verification
This page records the public release identities, automated validation references, current maturity classification, and stated limits for PALO 3.1 and PALO-AI 2.7.
It is not an independent audit, certification, legal determination, compliance conclusion, or production authorization.
| Item | Recorded value |
|---|---|
| PALO Web | 3.1.0, released 23 August 2026 |
| PALO-AI | 2.7.0 developer preview, released 25 August 2026 |
| PALO-AI release baseline | a8673d2a472108c7b1d8a056c3a6af9962687bee |
| Baseline pull request | #29 |
| Baseline CI run | 32828014857 |
| Verification-page merge | d79db7921ecf8797878650c69dd7a26b18f79dc6 |
| Verification-page pull request | #30 |
| Verification-page CI and Pages deployment | 32850220253 |
The PALO-AI 2.7 baseline run recorded:
- 21 schema contracts and 38 MCP tools;
- successful OPA compilation and policy tests;
- 68 passing Node tests and 3 passing Dify tests;
- 37 source HTML pages and 95 built HTML pages;
- 321 allowlisted source files and an exact 391-file distribution;
- browser smoke over 94 public HTML pages.
The later verification-page deployment recorded 38 source HTML pages, 96 built HTML pages, a 392-file deterministic distribution, and browser smoke over 95 public HTML pages. These later totals reflect the additional verification page; they do not rewrite the earlier PALO-AI 2.7 baseline observation.
The pinned baseline contains negative tests for:
- untrusted Authority Context 1.4 issuers and delegation windows that do not cover the live claim;
- cached-authority revalidation;
- continuous invalidation of Data Fitness Decisions and matching unused capabilities;
- OIDC tenant binding across Action Claim 1.3 and 1.4 tenant locations;
- replayed disclosure observations and post-effect disclosure-receipt failures;
- isolation of unscoped legacy incidents from tenant-aware OIDC results.
Direct sources:
data-assurance.test.js:226assurance.test.js:102data-assurance.test.js:298production-admission.test.js:28data-assurance.test.js:329
The tagged PALO-Hostinger-3.1.0.zip release asset belongs to commit b79fc1056d7e403698ffe2381a97dd689a8d8111.
Its recorded SHA-256 digest is:
f33b272414a6df25eb0b7a6933eb32ab155ee6e546b1de66e8ed17b22ca6aa2b
Later main-branch PALO-AI 2.7 and website changes are not the same artifact as the tagged archive. A rebuilt deployment requires a distinct publication identity and checksum.
The capability matrix tracks 40 capabilities: 5 implemented, 28 prototype, 7 specified, and 0 production-ready.
Current production gaps include:
- SQLite and single-instance reference persistence;
- process-held reference key mechanisms rather than production KMS/HSM custody;
- no storage-level multi-tenant isolation;
- reference connectors without independent non-bypass attestation;
- no universal exactly-once guarantee;
- selected tamper detection inside the same host/key boundary rather than independent evidence custody;
- prototype incident operations;
- no bundled independent production security or cryptographic assessment.
The repository has been developed with AI-assisted engineering and documentation tools under human direction and review, alongside conventional development, testing, and version-control tooling. Commit history records repository authorship and change integration; it does not demonstrate that every task was performed without assistance.