Skip to content

v0.2.0

Choose a tag to compare

@devarispbrown devarispbrown released this 02 Sep 07:13
38eb019

0.2.0 (2026-09-02)

⚠ BREAKING CHANGES

  • core.Tuner gained Deploy, Teardown, ListJobs and ListEndpoints, and store.Store gained WriteTuningJob, UpdateTuningJob, TuningJobs, LeakedEndpoints, WriteValidation, Validation and RecordHoldoutUse. An out-of-tree implementation of either interface must add them. The store schema moves 6 to 8: a 0.1.x database is readable by 0.2.0, a 0.2.0 database is not readable by 0.1.x.

Bug Fixes

  • fake: refuse an Asset with no content (#202) (948e018)

Documentation

  • fold v0.1.7, and give the 0.2.0 breaking changes their notice (#203) (4598b4b)
  • re-record the quickstart GIF for v0.1.7 (#199) (19ba099)

Verifying this release

Every artifact below is covered by checksums.txt, and checksums.txt is
signed with cosign keyless — there is no
private key, so there is none to steal. Each archive also ships an SPDX
SBOM, and the whole set carries SLSA build provenance.

# 1. The checksum file is really ours, and really came from this workflow.
cosign verify-blob checksums.txt \
  --certificate checksums.txt.pem \
  --signature checksums.txt.sig \
  --certificate-identity-regexp '^https://github\.com/uknoAI/kno/\.github/workflows/release\.yml@refs/tags/.+$' \
  --certificate-oidc-issuer https://token.actions.githubusercontent.com

# 2. Your download is really what the checksum file names. Substitute the
#    archive you actually downloaded. Written this way because macOS has no
#    sha256sum, and its shasum does not understand --ignore-missing.
grep " kno_0.2.0_darwin_arm64.tar.gz$" checksums.txt | shasum -a 256 -c -

# 3. It was built by GitHub Actions from this repository, not on a laptop.
gh attestation verify kno_0.2.0_linux_amd64.tar.gz \
  --repo uknoAI/kno \
  --signer-workflow uknoAI/kno/.github/workflows/release.yml

Both identity flags are load-bearing. Without --certificate-identity-regexp,
verify-blob accepts a valid signature from anybody at all; without
--signer-workflow, attestation verify accepts an attestation from any
workflow in the repository. Anchored, they say this file built this binary.

Built with -trimpath, and timestamped from the commit rather than the
clock, so these archives are byte-reproducible — by anyone using the Go
toolchain pinned in this tag's go.mod. A different toolchain produces a
different binary; that is a property of Go, not of this pipeline.

Checksums (SHA-256)

53314e351e72a523ee193e8c4663062057b234ec0f922eb970e10bb1fbb13e62  kno_0.2.0_darwin_amd64.tar.gz
bfc73537576e3a588145f5ba54d330f533eebbd7d7092d101b11e67b0633ecb7  kno_0.2.0_darwin_amd64.tar.gz.sbom.json
d2fd30b61e3895da31d514ce63deb6748cce0f5d4fdfc541b72ef977ba607e84  kno_0.2.0_darwin_arm64.tar.gz
5273b08544b49da8a37d2129429bd055ebcc4f0fbc88112eab96b6aa51bb02c2  kno_0.2.0_darwin_arm64.tar.gz.sbom.json
f6a054840649d3dcf1bf8a07e4591911b25fa724ed1b870229cf642d92410fc1  kno_0.2.0_linux_amd64.tar.gz
1ea40fc1d09a3dca02478c755c12dd34ba2a779aded171134e29bbf9b6db79e5  kno_0.2.0_linux_amd64.tar.gz.sbom.json
4107d1b5f3cbe7b12fb9f1e38d4c0f61860038127f0b29538b51d9df0977b1e5  kno_0.2.0_linux_arm64.tar.gz
92013983a4b0886646f4e15c8025dd40822230112d945967f8539426c56e7fdb  kno_0.2.0_linux_arm64.tar.gz.sbom.json
50cb927c78d76e588e7d20cc8f3157d46917d777736d339c9313dbdbb1781b2a  kno_0.2.0_windows_amd64.zip
d6d41e3926cb442198d7ba53c3d11a9ec5fb297ba048b9af90a8674917b05baa  kno_0.2.0_windows_amd64.zip.sbom.json
e4fbaaa8af693df1f29072fe4ab3f385df3529ce5a2301f70e97bb0e73d3dc5a  kno_0.2.0_windows_arm64.zip
99a4162fb079154746f77924802a630206555ec9c5f46c8ca40a93a360cc1cd6  kno_0.2.0_windows_arm64.zip.sbom.json