Skip to content

v0.1.4

Choose a tag to compare

@devarispbrown devarispbrown released this 01 Sep 03:06
90d31ec

0.1.4 (2026-09-01)

Features

  • every stage reports what it spent, or says it could not (#168) (dd5f0e9)
  • kno validate — the holdout finally speaks (#169) (e13b558)

Bug Fixes

  • build: the ledger gate refuses duplicate entry ids (#166) (7055062)
  • value: a resumed run restores the tokens it spent (#170) (00f0044)

Documentation

  • debt: dispose four silent lapses and backstop seven vague triggers (#167) (706b186)
  • fold the hand-written changelog into v0.1.3 (#164) (788c09f)
  • move the cookbook to uknoAI/kno-examples, leaving tombstones (#163) (94f32df)

Verifying this release

Every artifact below is covered by checksums.txt, and checksums.txt is
signed with cosign keyless — there is no
private key, so there is none to steal. Each archive also ships an SPDX
SBOM, and the whole set carries SLSA build provenance.

# 1. The checksum file is really ours, and really came from this workflow.
cosign verify-blob checksums.txt \
  --certificate checksums.txt.pem \
  --signature checksums.txt.sig \
  --certificate-identity-regexp '^https://github\.com/uknoAI/kno/\.github/workflows/release\.yml@refs/tags/.+$' \
  --certificate-oidc-issuer https://token.actions.githubusercontent.com

# 2. Your download is really what the checksum file names. Substitute the
#    archive you actually downloaded. Written this way because macOS has no
#    sha256sum, and its shasum does not understand --ignore-missing.
grep " kno_0.1.4_darwin_arm64.tar.gz$" checksums.txt | shasum -a 256 -c -

# 3. It was built by GitHub Actions from this repository, not on a laptop.
gh attestation verify kno_0.1.4_linux_amd64.tar.gz \
  --repo uknoAI/kno \
  --signer-workflow uknoAI/kno/.github/workflows/release.yml

Both identity flags are load-bearing. Without --certificate-identity-regexp,
verify-blob accepts a valid signature from anybody at all; without
--signer-workflow, attestation verify accepts an attestation from any
workflow in the repository. Anchored, they say this file built this binary.

Built with -trimpath, and timestamped from the commit rather than the
clock, so these archives are byte-reproducible — by anyone using the Go
toolchain pinned in this tag's go.mod. A different toolchain produces a
different binary; that is a property of Go, not of this pipeline.

Checksums (SHA-256)

c5123fd8e80c02bac8433ebe2a7ddd4f16c78b9ff27b0be8581dcaf546a9585d  kno_0.1.4_darwin_amd64.tar.gz
e3942a1143aec090d6af329e319f61176be87a55fd0bed8989fc61b34f426800  kno_0.1.4_darwin_amd64.tar.gz.sbom.json
b5bf2c1e71251d089a3f07347e071d484e7c463acbccbc31bdf5354dd0fc9e7a  kno_0.1.4_darwin_arm64.tar.gz
bba3d0f19b4a5c355a3d1e8875061f9c6fafa5b79ac815b2dd707421e76aa66b  kno_0.1.4_darwin_arm64.tar.gz.sbom.json
d87d5c3e2a4e688b44a446f722b0c17efaf2b2716735ddc44e5f506a59f1de90  kno_0.1.4_linux_amd64.tar.gz
f7878d8dc461b3179362a33c7310d8bff535de4fbfecabb802b918c54149af59  kno_0.1.4_linux_amd64.tar.gz.sbom.json
626a29b12c3911c6f9259d726058b2d24968b88ba153b73c20c06e439deecc60  kno_0.1.4_linux_arm64.tar.gz
18f613d5dde19c7d179acafd26bc4f493f85d80097d90821622f4fdceb0d28ce  kno_0.1.4_linux_arm64.tar.gz.sbom.json
c22cdce7d99bf044cfdb9f63b03a3fe2612aecb520605783345cc81e52a4673a  kno_0.1.4_windows_amd64.zip
466c2483cc47da944321366b92b0975ac0e702c4538fd79584fd50d028522d36  kno_0.1.4_windows_amd64.zip.sbom.json
d6abad3dba5dffa391436a4dfee4727ab39a2d77d7c71fecf8e7f9ced919bd0f  kno_0.1.4_windows_arm64.zip
07318f256f698912976ec6e56b1393ff902b179b0ce680c6511505ad475d06a0  kno_0.1.4_windows_arm64.zip.sbom.json