Releases: snapsynapse/publedge
Release list
PubLedge v0.2.2
PubLedge v0.2.2
Corrects Colorado SB25B-004 commencement, separates it from signature and amended requirement dates, and qualifies predecessor operative history. Three predecessor obligations retain explicit unknown enforcement evidence and stable identifiers.
Adds an optional local enforcement-state override and exact-record regression checks. The protocol remains v0.2.0 and the shared OF record contract remains v0.6.
PubLedge v0.2.1
PubLedge v0.2.1
PubLedge v0.2.1 is a narrow MCP release-identity correction discovered by installing and initializing the exact v0.2.0 release tarball before registry publication.
Fixed
- MCP
initializenow reports package version0.2.1inserverInfo.version. - Modern
server/discoverreports the same package version in its server metadata. - Both values are derived from
package.json, removing the stale1.0.0literal. - Source and installed-package evals now reject version drift across these surfaces.
- Public-claim evaluation now treats protocol specification
v0.2.0and MCP packagev0.2.1as separate, explicit version identities.
Unchanged
- The PubLedge protocol specification remains
v0.2.0. - The Obligation-First v0.6 projection remains 130 validated records.
- The registry remains 18 instruments, 35 obligations, 8 authorities, and 16 mappings.
Release handling
The GitHub-only v0.2.0 release remains immutable. It was not published to npm or the MCP Registry. Registry consumers should use v0.2.1.
See CHANGELOG.md for the complete v0.2.0 migration inventory.
PubLedge v0.2.0
PubLedge v0.2.0
Release date: 2026-08-04
PubLedge v0.2.0 migrates the verifiable-records layer of the PAICE legal graph to Obligation-First v0.6.0 and adds deterministic controls that make schema, lifecycle, manifest, workflow, and generated-output drift fail before publication.
Highlights
- Publishes 130 Obligation-First v0.6 records with explicit authority roles, lifecycle and enforcement posture, provenance, jurisdiction shapes, and stable native identifiers.
- Adds
of:Partyrecords for agreement participants while preserving the semantic boundary between parties and government Authorities. - Corrects superseded, sunset, proposed, prospective, and expired records so legal status, editorial status, and routine enforcement claims remain independent.
- Clarifies that PubLedge Determinations model evidenced administrative issuance, not adjudication, and omits issuance records for proposed or draft instruments.
- Adds one canonical fail-closed CI entrypoint, a reviewed structural fingerprint, scheduled-verification and workflow-invariant evals, and complete manifest-scope checks.
- Verifies raw byte-determinism and generated-tree parity across UTC and America/Denver.
Verification
- All canonical manifest hashes verified.
- 18 instruments, 35 obligations, 8 authorities, and 16 mappings passed cross-reference validation.
- The complete eval suite passed, including deterministic builds, clean-tree parity, workflow invariants, installed-package behavior, temporal status, and MCP initialization.
- 130 Obligation-First records passed v0.6.0 validation and the reviewed structural fingerprint matched.
- The cross-repository federation resolved every PubLedge anchor after all adopters migrated.
Residuals
MANIFEST.yamlproves source-to-current-manifest consistency; it is not an independent timestamp or immutable publication proof.us-ut-oaip-rma-2026-001intentionally has no effective date yet and may continue to produce a non-blocking schema recommendation.- The protocol remains pre-1.0. Consumers should pin compatible minor versions.
See CHANGELOG.md for the complete change inventory.
PubLedge v0.1.3
PubLedge v0.1.3
PubLedge v0.1.3 advances the protocol's maintenance and adoption posture while preparing MCP/npm package 0.1.3.
Highlights
- Publishes installable MCP discovery at
https://publedge.org/.well-known/mcp.jsonand a complete machine-readable endpoint inventory. - Adds a five-minute path for browser, JSON API, and MCP adoption.
- Adds a dedicated authority correction and response intake surface.
- Adds evals for full generated-tree parity, discovery contracts, installed-package behavior, public claims, and feed/schema formats.
- Makes full clean builds authoritative, preventing stale generated files and stale empty feeds from surviving a release.
- Consolidates MCP parsing on shared zero-dependency libraries and narrows the npm runtime package.
- Corrects version, registry-count, freshness, integrity, and JSON-LD availability claims.
Verification
- 158 canonical manifest hashes verified.
- 18 instruments, 35 obligations, 8 authorities, and 16 mappings passed cross-reference validation.
- All 24 evals passed, including obligation lifecycle, local tarball installation, and MCP initialization.
- 116 Obligation-First records passed adopter validation.
- Verification reported 61 fresh records, 0 stale records, and 0 never-verified records.
Residuals
MANIFEST.yamlproves source-to-current-manifest consistency; it is not an independent timestamp or immutable publication proof.us-ut-oaip-rma-2026-001intentionally has no effective date yet and continues to produce a non-blocking schema recommendation.
Historical tag policy
The v0.1.2-pre tag is retained only as an immutable historical reference. Consumers, documentation, release tooling, and dependency automation must not select it. Use v0.1.2 or a later stable tag.
See CHANGELOG.md for the complete change inventory.
PubLedge v0.1.2
PubLedge v0.1.2
PubLedge v0.1.2 advances the protocol's maintenance and adoption posture while publishing MCP/npm package 0.1.2.
Highlights
- Publishes installable MCP discovery at
https://publedge.org/.well-known/mcp.jsonand a complete machine-readable endpoint inventory. - Adds a five-minute path for browser, JSON API, and MCP adoption.
- Adds a dedicated authority correction and response intake surface.
- Adds evals for full generated-tree parity, discovery contracts, installed-package behavior, public claims, and feed/schema formats.
- Makes full clean builds authoritative, preventing stale generated files and stale empty feeds from surviving a release.
- Consolidates MCP parsing on shared zero-dependency libraries and narrows the npm runtime package.
- Corrects version, registry-count, freshness, integrity, and JSON-LD availability claims.
Verification
- 145 canonical manifest hashes verified.
- 18 instruments, 26 obligations, 8 authorities, and 14 mappings passed cross-reference validation.
- All 23 evals passed, including local tarball installation and MCP initialization.
- 105 Obligation-First records passed adopter validation.
- Verification reported 52 fresh records, 0 stale records, and 0 never-verified records.
- npm package dry run: 66 files, 74.7 kB compressed, 267.4 kB unpacked.
Residuals
MANIFEST.yamlproves source-to-current-manifest consistency; it is not an independent timestamp or immutable publication proof.us-ut-oaip-rma-2026-001intentionally has no effective date yet and continues to produce a non-blocking schema recommendation.
See CHANGELOG.md for the complete change inventory.
PubLedge v0.1.1-pre
PubLedge v0.1.1-pre
Released: 2026-05-30
Commit: c1f51aa
Summary
Security hardening and release-readiness patch for the PubLedge prerelease line.
Added
- Verification allowlist for relationship-only instruments that preserve amendment and supersession chains without standalone obligation mappings.
- Evals for MCP URL boundaries, MCP parser lockstep, verification allowlist semantics, generated-output normalization, and manifest scope coverage.
Fixed
- MCP fetch_by_url now accepts only canonical https://publedge.org/ URLs and root-relative canonical paths.
- MCP fetch_by_url now rejects cross-origin, non-HTTPS, protocol-relative, encoded-slash, backslash, whitespace/control-character, query-string, fragment, default-port, and spoof-host URL forms.
- MCP record loading now uses the shared parser/content loader instead of duplicated YAML and container parsing logic.
- Generated-output comparisons normalize sitemap lastmod timestamp churn while keeping public timestamps in generated files.
- CI now invokes the clean-build eval for generated docs consistency.
- Manifest coverage now includes canonical source, tooling, MCP, schema, template, CI, and vendored ontology files, with docs and generated outputs excluded by policy.
Verification
- npm run build: passed
- npm run validate: passed
- npm run evals: passed
- ./scripts/validate-hashes.sh: passed, 117 files checked
- npm run verify: passed
- Direct MCP URL PoCs: canonical absolute and root-relative paths accepted; rejected URL classes covered by eval-mcp-contract
Residual Risk
- No blocking residuals for this release. The build still emits a non-blocking recommendation that us-ut-oaip-rma-2026-001 is missing an effective date.
v0.1.0-pre
[0.1.0-pre] — 2026-04-22
Added
- Protocol specification (
PROTOCOL.md) and prior-art survey (PRIOR-ART.md) - 14 demonstration instruments across 7 authorities (Utah OAIP, SEC Corp Fin, CFPB, IRS Chief Counsel, IRS TEGE, CFTC DSIO, Utah Legislature) and 7 instrument types (JIA, RMA, no-action letter, advisory opinion, private letter ruling, interpretive letter, statute)
- 26 first-class obligation records mapped to instruments via
data/examples/mapping/index.yml(14 mapping entries covering every instrument in the registry) - Canonical hierarchical URL architecture:
/{country}/{jurisdiction}/{authority}/{type}/{instance}/; stable identifier scheme{jurisdiction}-{authority}-{kind}-{YYYY-NNN}; 301 redirect stubs from legacy/container/{id}/paths - Four Utah statutes ingested as first-class instrument records (SB 149, SB 226, HB 452, HB 320)
- Status vocabulary (9 values) with
DEFINITIONS.mdand rendered/definitions/page - Disclaimer & Source Policy at
/reference/disclaimer/ - Frontmatter spec v0.2: decoupled
@typefromobligation_kind; shared interpretive-instrument core fields; withdrawal triplet; redaction_level; renderer-composed disclaimer - JSON Schemas (
schema/jia.schema.json,schema/rma.schema.json); JSON-LD context (schema/context.jsonld) binding to Semantic Arts gist IRIs - JSON Schema draft 2020-12 at
/schema/json/record.schema.jsonfor therecord.jsonpayload shape - MANIFEST.yaml with skill-provenance-style SHA-256 hash integrity across every canonical file
- 5 JIA/RMA templates under
_templates/ - Unified site generator (
scripts/build.js+scripts/build-extras.js); cross-reference validator (scripts/validate.js); structural validator (scripts/verify.js); hash validator (scripts/validate-hashes.sh); link checker; OCR helper - JSON API under
/api/v1/(containers, primaries, authorities, mappings, matrix, comparisons, upcoming, recently-changed, index manifest) - Source PDFs + OCR text co-located with Utah OAIP RMA records
calendar.ics(iCal enforcement calendar);feed.xml(RSS 2.0);feed.json(JSON Feed 1.1);atom.xml(Atom 1.0)- Agent-discovery surfaces:
llms.txt,agents.json,robots.txtwith explicit allow for 25 AI and SEO crawlers Schema.orgJSON-LD across the site:LegalDocumenton every record;WebSite+Organization+DataCatalog@graphon the homepage;ItemListon/instruments.html,/obligations.html,/authorities.html;Dataseton/matrix.html;DefinedTermSeton/definitions/;Articleon/about/;DigitalDocumenton/reference/disclaimer/- Split sitemap index with 7 per-section sitemaps (
records,authorities,statutes,reference,templates,bridges,meta) - MCP server (
mcp-server.js) exposing 13 read-only tools: filtered instrument listing, URL-based fetch, entity-scoped search, coverage matrix, mappings, upcoming milestones, recently-changed records - Reference pages: Protocol, Prior Art, Registry, Vocabulary, Disclaimer
- Jurisdiction index pages at every hierarchy level (
/us/,/us/utah/,/us/utah/oaip/, etc.) - Utah landing at
/us/utah/with narrative + four-chapter statute map - Browseable UI: per-column sort/filter, keyboard shortcuts (
/,?,j/k), rich ARIA search, freshness badges, anchor-copy buttons, print stylesheet, jurisdiction chips, prev/next sibling nav, changelog strip, schema-completeness warnings publedge-source-ingestskill for authored ingestion- Agent-readiness audit artifact at
audits/agent-readiness-2026-04-22.md
Changed
- Registry-as-Dataset positioning throughout: homepage, README, and llms.txt emphasize
DataCatalogsemantics rather than service-site patterns - Status defaults for permission and enforcing colors moved to a WCAG 2.1 AA compliant green (
#1f7a43, 5.8:1 on white) inproject.yml - Dark-mode foreground colors remapped to the link token so navy-on-dark text selectors pass 4.5:1 contrast
- Open Graph
og:imageURL concatenation corrected (prior//imgs/og.pngdouble slash);twitter:siteno longer emits[object Object]from the YAML empty-string parser path - Homepage
og:titlenow includes site name + tagline instead of bare "Home" - Homepage "Obligations" section replaced with a three-card group summary (Requirements / Restrictions / Permissions) plus a four-card "Most cross-cutting" row
Fixed
- Axe-core WCAG 2.1 AA violations: color-contrast (34 instances), link-name on compare bridge CTAs (2 instances), region landmark on site banner (33 instances), heading-order on
/reference/(1 instance) - Favicon 404:
<link rel="icon" href="/favicon.svg" type="image/svg+xml">declared on every generated and hand-authored page NaNdrendering in upcoming-milestones widget when a record haseffective: null(YAML parser returned string"null")- Nested
<a>inside<a>in homepage "Use PubLedge" card grid; cards now use<div>with a linked title generateCompareBridgeemitted empty CTA anchors because containers use.titlenot.name; fixed the fallback chain
Infrastructure
- GitHub Pages source set to
main /docs - CI: pa11y-ci WCAG 2.1 AA pass across every URL in the sitemap on every push and pull request; docs/ sync check; hash validation
.gitignorealigned to portfolio hygiene baseline (.env.*glob,__pycache__/,*.pyc,dist/,build/,.venv/,venv/)