Skip to content

AI Posture v0.4.1

Choose a tag to compare

@snapsynapse snapsynapse released this 30 May 18:04
· 27 commits to main since this release

AI Posture v0.4.1

Patch hardening release for AI Posture. No scoring, likelihood, prior, aggregation-rule, or SPEC.md semantic changes. SPEC.md remains v0.3.2.

Changes

  • Replaced permissive artifact-delivery payload checks with strict server-side validation matching the published estimate-result schema shape.
  • Added regression coverage for spoofed type strings, wrong source URLs, missing estimate notices, HTML-like level names, malformed vectors, malformed posteriors, invalid calendar dates, class-instance payloads, duplicate constraining vectors, and runtime-generated artifact compatibility.
  • Corrected all-vectors-N/A JSON artifact aggregate naming to use schema-valid N/A.
  • Corrected sitemap lastmod drift for assessment, privacy, and terms surfaces.
  • Corrected stale privacy and terms copy around live on-request JSON artifact delivery.
  • Published the missing assistant-guide-v1.0.0 release to satisfy the assistant-guide manifest immutable release URL.

Verification

  • npm test at repo root: 65/65 passing.
  • npm test in worker/: 13/13 passing.
  • git diff --check: clean.
  • Fanout schema-bypass lane found invalid calendar date and class-instance validator bypasses; both were fixed and covered by tests.
  • Fanout false-positive lane accepted completed, scoped, and all-N/A runtime-generated artifacts.
  • Agent-surface lane verified assistant-guide mirror identity, manifest hash and byte count, llms.txt, framework profile, and sitemap discovery locally.
  • Release-integrity lane verified v0.4.1 package/changelog alignment and missing pre-release tags before publication.

Residual Risks

  • The validator intentionally follows the current published JSON Schema, which bounds posterior entries but does not require posterior arrays to sum to 1.
  • The validator intentionally follows the current published JSON Schema, which does not require level and level_name to correspond by mapping.

Asset Digests

  • ai-posture-v0.4.1.tar.gz: 9b8f813b512244a7354388931ab5f3b8ba9084678dd3e9cf57e6b8b98102da1d
  • ai-posture-v0.4.1.zip: ede911d9d07d45f6c96eabb0f52943164d0b05482b0f7336b898f94d7a2b622f