Skip to content

v0.1.3

Choose a tag to compare

@devarispbrown devarispbrown released this 31 Aug 20:59
2140622

0.1.3 (2026-08-31)

Features

  • docs/status.json — generated status data for the site, gated in make check (#150) (cb50d5b)
  • kno eval inspect — whether an eval set can support attribution (#155) (18ebb4a)

Bug Fixes

  • cli: kno export --json names the Select run it rendered from (#156) (074d73f)
  • core: the rejection log prints bounds at four places, not seventeen (#157) (350bc01)
  • value: the harm bound is the exact t quantile, not z beyond df=30 (#158) (4622b90)

Documentation

  • answer the examples plan's blocking question by reading kno-www (#146) (9bc5c47)
  • debt: record two live defects found by the v0.2 Phase-0 workstreams (#159) (37967e5)
  • fold the hand-written changelog into v0.1.2 (#145) (bd858c3)
  • Phase-0 plans for v0.2, all adversarially reviewed (#161) (83c7641)
  • stop advertising an on-ramp that does not exist yet (#162) (89ce9ee)

Build & Dependencies

  • Bump anchore/sbom-action/download-syft from 0.24.0 to 0.24.2 (#135) (23dcfe0)

Verifying this release

Every artifact below is covered by checksums.txt, and checksums.txt is
signed with cosign keyless — there is no
private key, so there is none to steal. Each archive also ships an SPDX
SBOM, and the whole set carries SLSA build provenance.

# 1. The checksum file is really ours, and really came from this workflow.
cosign verify-blob checksums.txt \
  --certificate checksums.txt.pem \
  --signature checksums.txt.sig \
  --certificate-identity-regexp '^https://github\.com/uknoAI/kno/\.github/workflows/release\.yml@refs/tags/.+$' \
  --certificate-oidc-issuer https://token.actions.githubusercontent.com

# 2. Your download is really what the checksum file names. Substitute the
#    archive you actually downloaded. Written this way because macOS has no
#    sha256sum, and its shasum does not understand --ignore-missing.
grep " kno_0.1.3_darwin_arm64.tar.gz$" checksums.txt | shasum -a 256 -c -

# 3. It was built by GitHub Actions from this repository, not on a laptop.
gh attestation verify kno_0.1.3_linux_amd64.tar.gz \
  --repo uknoAI/kno \
  --signer-workflow uknoAI/kno/.github/workflows/release.yml

Both identity flags are load-bearing. Without --certificate-identity-regexp,
verify-blob accepts a valid signature from anybody at all; without
--signer-workflow, attestation verify accepts an attestation from any
workflow in the repository. Anchored, they say this file built this binary.

Built with -trimpath, and timestamped from the commit rather than the
clock, so these archives are byte-reproducible — by anyone using the Go
toolchain pinned in this tag's go.mod. A different toolchain produces a
different binary; that is a property of Go, not of this pipeline.

Checksums (SHA-256)

301577503df566f38c4145f8e59d75c0a5677a19da61a5e9f1e00277fe3e5aff  kno_0.1.3_darwin_amd64.tar.gz
c5efc53ce6125026a64e52f619f8d2c855e72a21e5af9519120bf96862d17b23  kno_0.1.3_darwin_amd64.tar.gz.sbom.json
6bd303d696e84f2f5802c96f990324e2a2ff1cac530ef0970a2b4766bd7e6111  kno_0.1.3_darwin_arm64.tar.gz
2bc11e7025f93fabac97f007d9bd6577ffc7f58300dec7c7b1ff4f4135582c61  kno_0.1.3_darwin_arm64.tar.gz.sbom.json
bb5c5940318686a67982a67167c2207b4713c0c52a48949756e0ce1384d2fbc5  kno_0.1.3_linux_amd64.tar.gz
ed11c0967b2e321b62e2fd107f71346c34eb4d0630fb2a43240ae7b18e98a60a  kno_0.1.3_linux_amd64.tar.gz.sbom.json
9730cd82aac43166a0c1cc1ee8f47b342b8d1a71677434a9630b50f73d49e1d2  kno_0.1.3_linux_arm64.tar.gz
83ce40e10df6d457586726c7ef848cfa6962af055659072bd9268a2551de8cc0  kno_0.1.3_linux_arm64.tar.gz.sbom.json
49fd45501719037a83bb111f5060c64480ef457464dca84f470b849601b28d4c  kno_0.1.3_windows_amd64.zip
148d9f34c04ba8edfd07ca48d9e80607785fa02144a7082d648e101637558a39  kno_0.1.3_windows_amd64.zip.sbom.json
1cec39dfea9d75ed036116da65f8b847661576aa9034c18640f9126be4a44aa0  kno_0.1.3_windows_arm64.zip
042208cc3149407f52b7d22e361ae2ee24019d753a496c301ddbc276530d1f01  kno_0.1.3_windows_arm64.zip.sbom.json