Skip to content

Releases: studio2201/proven

v0.2.9

Choose a tag to compare

@UberMetroid UberMetroid released this 19 Sep 05:25
Immutable release. Only release title and notes can be modified.

Release v0.2.9: Multi-platform release workflow and static binaries.

v0.2.8

Choose a tag to compare

@UberMetroid UberMetroid released this 19 Sep 04:56
Immutable release. Only release title and notes can be modified.

Release v0.2.8: Detailed Governance Scorecard and PQC-signed supply-chain attestor.

v0.2.7

Choose a tag to compare

@UberMetroid UberMetroid released this 19 Sep 04:46
Immutable release. Only release title and notes can be modified.

v0.2.7 release with ML-DSA-65 post-quantum supply-chain attestor and SLSA L3+ verification.

v0.2.0

Choose a tag to compare

@github-actions github-actions released this 18 Sep 07:38
Immutable release. Only release title and notes can be modified.
feat(core): pure std implementation of proven (v0.2.0)

proven v0.1.2 — pure Rust + std:: only

Choose a tag to compare

@UberMetroid UberMetroid released this 18 Sep 06:52
Immutable release. Only release title and notes can be modified.

proven v0.1.2 — pure Rust + std:: only

No code changes; this is a documentation cleanup to match the studio2201 framework v0.1.2 release.

  • README.md rewritten to drop openOODA substrate references (seance / opm / bb / ML-DSA-65 / Merkle-AST mentions removed where they described the implementation path). Reproducible-builds narrative reframed on (host, rustc-version, Cargo.lock) byte-identity hashing.
  • CHANGES.md updated with a [0.1.2] entry.

The framework now explicitly states that there is no substrate — pure Rust + std::* only.

proven v0.1.1 — framework v2

Pre-release

Choose a tag to compare

@UberMetroid UberMetroid released this 18 Sep 06:40
Immutable release. Only release title and notes can be modified.

proven v0.1.1 — framework v2

Adds the §15–§18 artifacts:

  • docs/threat-model.md — adversary: attacker who poisons the build environment between source commit and published binary artifact.
  • tools/dev/repro.sh — (host, rustc-version)-keyed baseline; no toolchain pin.
  • SECURITY.md — GHSA tab, 14/90-day window.
  • tools/perf/budget.md — proven sign on 1 MiB artifact: 1.2 s median ±25%.
  • tests/integration.rs + tools/perf/bench.rs — #[test] with std::time median-of-5.
  • CHANGES.md — 0.1.1 block with the v2 additions.

Pre-1.0.0: GHSA-only security advisories; CVEs reserved for 1.0.0+.

Bench and repro.sh will activate once Cargo.toml and src/ land.