Skip to content

v3.1.0

Choose a tag to compare

@Synvoya Synvoya released this 25 Aug 03:15
· 1 commit to master since this release
v3.1.0
b555e24

CodeInspectus 3.1.0 introduces the Repository Trust & Provenance foundation and its first deterministic capability: bounded source-integrity inspection.\n\n## What’s new\n\n- Detects dangerous bidirectional controls, zero-width/default-ignorable token characters, Unicode tag payloads, encoded variation-selector runs, and a conservative subset of mixed-script identifier confusables.\n- Reports exact file, line, code-point column, UTF-8 byte offset, escaped evidence, context, validator identity, confidence, limitations, and approval-required remediation eligibility.\n- Bounds dense candidates before artifact materialization and explicitly truncates rendered evidence while retaining exact spans and sequence lengths.\n- Adds V3 JSON, SARIF, SDK, bundle, MCP, CLI, and rescan support for the independently versioned repository-trust contract.\n- Classifies rescans as resolved, remaining, introduced, or not re-checked without claiming resolution when the capability did not run completely.\n\n## Safety boundary\n\nCodeInspectus remains read-only and never edits source. Cleanup requires explicit approval for the named file and code point, the smallest reversible change by the user’s coding agent, tests, and a CodeInspectus rescan.\n\nExplicit AI attribution, C2PA inspection, statistical watermark verification, and image/video processing are not included in v3.1.0. Unicode evidence is not presented as proof of AI authorship.\n\nNode.js 22 or later is required. See the full changelog and V3 migration guide.