v0.118.7 #1491
v0.118.7
#1491
Replies: 0 comments
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
What
Fixed
Check final encoded lines and cumulative bytes, including newlines,
before writing. A refusal stops that journal and reports lost evidence
while preserving the primary output and runtime settlement. This does
not provide complete proofs for oversized runs or resolve trace verify refuses the sealed journal of a successful ~17k-item fan-out: the per-item terminal frame crosses the 1 MiB line bound #1458.
parametersJsonSchema.A missing terminal frame and an unheld writer lease no longer claim a
crash or an unsettled run. An invalid final line also does not exclude
intentional modification. A file journal can stop while the primary
run still succeeds; verification tiers and exit codes are unchanged.
--task. Operating guidance preserves secret host boundaries and separates definition pins from trust in a server. Plugin descriptions now state the limits of metered budgets and trace delivery.Install
Tarballs below: macOS arm64 / x64 · Linux x64 / arm64, plus
SHA256SUMS.Verify: three independent proofs
Provenance
Built from tag
v0.118.7byrelease.ymlon GitHub-hosted runners. Provenance is published twice: GitHub's native
build attestation (proof 2) and the SLSA generator's
multiple.intoto.jsonlrelease asset (proof 3). The release itself is a claim on the
machine-verified timeline: https://nika.sh/timeline
What's Changed
Full Changelog: v0.118.6...v0.118.7
This discussion was created from the release v0.118.7.
All reactions