Skip to content

Proofline v2.0.2

Latest

Choose a tag to compare

@thangldw thangldw released this 24 Aug 02:02
· 1 commit to main since this release
5328eba

Proofline v2.0.2

Released: 2026-08-24

English

What shipped

  • Exact-ref CI dispatch so public qualification can resolve every checkout to one immutable source ref, plus Python and JavaScript/TypeScript CodeQL analysis and pinned Dependabot configuration.
  • Content-free decision-health JSON that reports identifiers and state without leaking decision titles or cited text.
  • A fail-closed pilot dataset freezer that validates source paths, labels, permissions, manifest hashes, and dataset-version identity before real-team evaluation.
  • Manual macOS and Windows desktop artifact workflows with pre-build release-grade gates and post-build lifecycle receipts. Experimental artifacts remain unsigned and are not distribution-qualified.
  • Fail-closed release checks for the desktop Cargo lock and an explicit non-desktop GitHub Release asset allowlist that excludes experimental unsigned installers.
  • Aligned Python, CLI, web, desktop, CI artifact, and plugin manifest versions for immutable release v2.0.2.

Install the proofline-evidence distribution; the executable and import package remain proofline:

python -m pip install proofline-evidence==2.0.2
proofline demo stale-decision

Compatibility and evidence limits

The local-first trust boundary, SQLite data model, evidence-package schemas, and signed-attestation schemas remain compatible with v2.0.1. Pilot tooling is implemented and synthetic qualification exists, but no real-team pilot has been run. Desktop workflows prove experimental build and lifecycle behavior only; Apple Developer ID/notarization and Windows Authenticode evidence are still absent. Scale results remain synthetic rather than team or hosted-production benchmarks. Verify source/version alignment with python scripts/release_check.py --tag v2.0.2 and use the public CI run for the exact release commit as the qualification record.

Tiếng Việt

Nội dung phát hành

  • CI dispatch theo exact ref để qualification công khai resolve mọi checkout tới một source ref bất biến, cùng CodeQL cho Python và JavaScript/TypeScript và Dependabot configuration được pin.
  • Decision-health JSON content-free, chỉ báo identifier và state mà không làm lộ decision title hoặc cited text.
  • Pilot dataset freezer fail-closed để validate source path, label, permission, manifest hash và dataset-version identity trước evaluation với team thật.
  • Workflow desktop artifact manual cho macOS và Windows với release-grade gate trước build cùng lifecycle receipt sau build. Artifact experimental vẫn unsigned và chưa đủ điều kiện distribution.
  • Release check fail-closed cho desktop Cargo lock và allowlist GitHub Release asset non-desktop explicit để loại installer experimental unsigned.
  • Đồng bộ version Python, CLI, web, desktop, CI artifact và plugin manifest cho release bất biến v2.0.2.

Cài distribution proofline-evidence; executable và import package vẫn là proofline:

python -m pip install proofline-evidence==2.0.2
proofline demo stale-decision

Compatibility và giới hạn evidence

Trust boundary local-first, SQLite data model, evidence-package schema và signed-attestation schema vẫn tương thích với v2.0.1. Pilot tooling đã implement và có synthetic qualification nhưng chưa chạy real-team pilot. Workflow desktop chỉ chứng minh experimental build cùng lifecycle behavior; vẫn chưa có evidence Apple Developer ID/notarization và Windows Authenticode. Scale result vẫn là synthetic, không phải benchmark team hoặc hosted production. Verify source/version alignment bằng python scripts/release_check.py --tag v2.0.2 và dùng public CI run của exact release commit làm qualification record.

日本語

出荷内容

  • すべての checkout を単一の immutable source ref に解決できる exact-ref CI dispatch、Python / JavaScript/TypeScript CodeQL、pin 済み Dependabot configuration。
  • Decision title や cited text を漏らさず identifier と state を報告する content-free decision-health JSON。
  • Real-team evaluation 前に source path、label、permission、manifest hash、dataset-version identity を検証する fail-closed pilot dataset freezer。
  • Pre-build release-grade gate と post-build lifecycle receipt を備えた manual macOS / Windows desktop artifact workflow。Experimental artifact は unsigned のままで distribution qualification はありません。
  • Desktop Cargo lock に対する fail-closed release check と、experimental unsigned installer を除外する明示的な non-desktop GitHub Release asset allowlist。
  • Immutable v2.0.2 release に向けた Python、CLI、web、desktop、CI artifact、plugin manifest version の同期。

Distribution proofline-evidence を install します。Executable と import package は proofline のままです。

python -m pip install proofline-evidence==2.0.2
proofline demo stale-decision

Compatibility と evidence limit

Local-first trust boundary、SQLite data model、evidence-package schema、signed-attestation schema は v2.0.1 と互換です。Pilot tooling と synthetic qualification はありますが、real-team pilot は未実施です。Desktop workflow が証明するのは experimental build と lifecycle behavior のみで、Apple Developer ID/notarization と Windows Authenticode evidence はまだありません。Scale result は team / hosted-production benchmark ではなく synthetic です。python scripts/release_check.py --tag v2.0.2 で source/version alignment を検証し、exact release commit の public CI run を qualification record としてください。