Repository navigation
Releases: studio2201/proven
Releases · studio2201/proven
Release list
v0.2.9
v0.2.8
Immutable
release. Only release title and notes can be modified.
Release v0.2.8: Detailed Governance Scorecard and PQC-signed supply-chain attestor.
v0.2.7
Immutable
release. Only release title and notes can be modified.
v0.2.7 release with ML-DSA-65 post-quantum supply-chain attestor and SLSA L3+ verification.
v0.2.0
Immutable
release. Only release title and notes can be modified.
feat(core): pure std implementation of proven (v0.2.0)
proven v0.1.2 — pure Rust + std:: only
Immutable
release. Only release title and notes can be modified.
proven v0.1.2 — pure Rust + std:: only
No code changes; this is a documentation cleanup to match the studio2201 framework v0.1.2 release.
README.mdrewritten to drop openOODA substrate references (seance / opm / bb / ML-DSA-65 / Merkle-AST mentions removed where they described the implementation path). Reproducible-builds narrative reframed on (host, rustc-version, Cargo.lock) byte-identity hashing.CHANGES.mdupdated with a[0.1.2]entry.
The framework now explicitly states that there is no substrate — pure Rust + std::* only.
proven v0.1.1 — framework v2
Immutable
release. Only release title and notes can be modified.
proven v0.1.1 — framework v2
Adds the §15–§18 artifacts:
docs/threat-model.md— adversary: attacker who poisons the build environment between source commit and published binary artifact.tools/dev/repro.sh—(host, rustc-version)-keyed baseline; no toolchain pin.SECURITY.md— GHSA tab, 14/90-day window.tools/perf/budget.md—proven signon 1 MiB artifact: 1.2 s median ±25%.tests/integration.rs+tools/perf/bench.rs—#[test]withstd::timemedian-of-5.CHANGES.md—0.1.1block with the v2 additions.
Pre-1.0.0: GHSA-only security advisories; CVEs reserved for 1.0.0+.
Bench and repro.sh will activate once Cargo.toml and src/ land.