Repository navigation
v0.1.3
0.1.3 (2026-08-31)
Features
- docs/status.json — generated status data for the site, gated in make check (#150) (cb50d5b)
- kno eval inspect — whether an eval set can support attribution (#155) (18ebb4a)
Bug Fixes
- cli: kno export --json names the Select run it rendered from (#156) (074d73f)
- core: the rejection log prints bounds at four places, not seventeen (#157) (350bc01)
- value: the harm bound is the exact t quantile, not z beyond df=30 (#158) (4622b90)
Documentation
- answer the examples plan's blocking question by reading kno-www (#146) (9bc5c47)
- debt: record two live defects found by the v0.2 Phase-0 workstreams (#159) (37967e5)
- fold the hand-written changelog into v0.1.2 (#145) (bd858c3)
- Phase-0 plans for v0.2, all adversarially reviewed (#161) (83c7641)
- stop advertising an on-ramp that does not exist yet (#162) (89ce9ee)
Build & Dependencies
Verifying this release
Every artifact below is covered by checksums.txt, and checksums.txt is
signed with cosign keyless — there is no
private key, so there is none to steal. Each archive also ships an SPDX
SBOM, and the whole set carries SLSA build provenance.
# 1. The checksum file is really ours, and really came from this workflow.
cosign verify-blob checksums.txt \
--certificate checksums.txt.pem \
--signature checksums.txt.sig \
--certificate-identity-regexp '^https://github\.com/uknoAI/kno/\.github/workflows/release\.yml@refs/tags/.+$' \
--certificate-oidc-issuer https://token.actions.githubusercontent.com
# 2. Your download is really what the checksum file names. Substitute the
# archive you actually downloaded. Written this way because macOS has no
# sha256sum, and its shasum does not understand --ignore-missing.
grep " kno_0.1.3_darwin_arm64.tar.gz$" checksums.txt | shasum -a 256 -c -
# 3. It was built by GitHub Actions from this repository, not on a laptop.
gh attestation verify kno_0.1.3_linux_amd64.tar.gz \
--repo uknoAI/kno \
--signer-workflow uknoAI/kno/.github/workflows/release.ymlBoth identity flags are load-bearing. Without --certificate-identity-regexp,
verify-blob accepts a valid signature from anybody at all; without
--signer-workflow, attestation verify accepts an attestation from any
workflow in the repository. Anchored, they say this file built this binary.
Built with -trimpath, and timestamped from the commit rather than the
clock, so these archives are byte-reproducible — by anyone using the Go
toolchain pinned in this tag's go.mod. A different toolchain produces a
different binary; that is a property of Go, not of this pipeline.
Checksums (SHA-256)
301577503df566f38c4145f8e59d75c0a5677a19da61a5e9f1e00277fe3e5aff kno_0.1.3_darwin_amd64.tar.gz
c5efc53ce6125026a64e52f619f8d2c855e72a21e5af9519120bf96862d17b23 kno_0.1.3_darwin_amd64.tar.gz.sbom.json
6bd303d696e84f2f5802c96f990324e2a2ff1cac530ef0970a2b4766bd7e6111 kno_0.1.3_darwin_arm64.tar.gz
2bc11e7025f93fabac97f007d9bd6577ffc7f58300dec7c7b1ff4f4135582c61 kno_0.1.3_darwin_arm64.tar.gz.sbom.json
bb5c5940318686a67982a67167c2207b4713c0c52a48949756e0ce1384d2fbc5 kno_0.1.3_linux_amd64.tar.gz
ed11c0967b2e321b62e2fd107f71346c34eb4d0630fb2a43240ae7b18e98a60a kno_0.1.3_linux_amd64.tar.gz.sbom.json
9730cd82aac43166a0c1cc1ee8f47b342b8d1a71677434a9630b50f73d49e1d2 kno_0.1.3_linux_arm64.tar.gz
83ce40e10df6d457586726c7ef848cfa6962af055659072bd9268a2551de8cc0 kno_0.1.3_linux_arm64.tar.gz.sbom.json
49fd45501719037a83bb111f5060c64480ef457464dca84f470b849601b28d4c kno_0.1.3_windows_amd64.zip
148d9f34c04ba8edfd07ca48d9e80607785fa02144a7082d648e101637558a39 kno_0.1.3_windows_amd64.zip.sbom.json
1cec39dfea9d75ed036116da65f8b847661576aa9034c18640f9126be4a44aa0 kno_0.1.3_windows_arm64.zip
042208cc3149407f52b7d22e361ae2ee24019d753a496c301ddbc276530d1f01 kno_0.1.3_windows_arm64.zip.sbom.json