Skip to content

v0.2.1

Choose a tag to compare

@devarispbrown devarispbrown released this 04 Sep 02:40
40d3d72

0.2.1 (2026-09-04)

Features

  • bridge: price the eval pass instead of asserting it free (#209) (9a73019)
  • tuner: an OpenAI Tuner, and a conformance suite that spans both (#211) (d6fdd6f)

Bug Fixes

  • bridge: enforce --bridge-max-serve-minutes during a live run (#206) (2fcae7c)
  • bridge: refuse a ready Endpoint that carries no ReadyAt (#208) (5f64979)

Documentation

  • fold the hand-written changelog into v0.2.0 (#213) (0435155)
  • plans: rewrite the OpenAI Tuner plan after Phase 1 review (#205) (eaedcd3)

Verifying this release

Every artifact below is covered by checksums.txt, and checksums.txt is
signed with cosign keyless — there is no
private key, so there is none to steal. Each archive also ships an SPDX
SBOM, and the whole set carries SLSA build provenance.

# 1. The checksum file is really ours, and really came from this workflow.
cosign verify-blob checksums.txt \
  --certificate checksums.txt.pem \
  --signature checksums.txt.sig \
  --certificate-identity-regexp '^https://github\.com/uknoAI/kno/\.github/workflows/release\.yml@refs/tags/.+$' \
  --certificate-oidc-issuer https://token.actions.githubusercontent.com

# 2. Your download is really what the checksum file names. Substitute the
#    archive you actually downloaded. Written this way because macOS has no
#    sha256sum, and its shasum does not understand --ignore-missing.
grep " kno_0.2.1_darwin_arm64.tar.gz$" checksums.txt | shasum -a 256 -c -

# 3. It was built by GitHub Actions from this repository, not on a laptop.
gh attestation verify kno_0.2.1_linux_amd64.tar.gz \
  --repo uknoAI/kno \
  --signer-workflow uknoAI/kno/.github/workflows/release.yml

Both identity flags are load-bearing. Without --certificate-identity-regexp,
verify-blob accepts a valid signature from anybody at all; without
--signer-workflow, attestation verify accepts an attestation from any
workflow in the repository. Anchored, they say this file built this binary.

Built with -trimpath, and timestamped from the commit rather than the
clock, so these archives are byte-reproducible — by anyone using the Go
toolchain pinned in this tag's go.mod. A different toolchain produces a
different binary; that is a property of Go, not of this pipeline.

Checksums (SHA-256)

851130c22b4c5f72f04184bdc54ed77dccac72b885e8670105f749efa26f40e0  kno_0.2.1_darwin_amd64.tar.gz
0bac213e7cb27436d8f03d019e319227d8ba109e85ddaacd62073b9954a3fb27  kno_0.2.1_darwin_amd64.tar.gz.sbom.json
a0f07c2cb8da732d543040563514292b6e8aed2ee7f7fcf7909c61d9fe08b055  kno_0.2.1_darwin_arm64.tar.gz
a2542f28f8b59b3782237f7a034943c1ff91d79cae0cd1c0339cb1f0eb896487  kno_0.2.1_darwin_arm64.tar.gz.sbom.json
f3d4dc7b020521584349372bae3fbab5426063d6c3a8989582895a80a96a8a84  kno_0.2.1_linux_amd64.tar.gz
8ae08114e67eaee1d1b3d80738d765db99524daad19c9a94dfb59767f906a4a7  kno_0.2.1_linux_amd64.tar.gz.sbom.json
1f8524b698c4fd8a60a55a7fa460c92168f55cdaf598231d449eff531fb078a3  kno_0.2.1_linux_arm64.tar.gz
a9b959baf47851bc28275c0896384ed176b87559e5e4e9f5ac1808826d5516e2  kno_0.2.1_linux_arm64.tar.gz.sbom.json
cf6aef2b8483bc9d10c2227c1121f6e17e27ee25f8e4e0f066f390fc47b11e3a  kno_0.2.1_windows_amd64.zip
7bc2de92a4e55388d8b667816e9d320d3f16f11c1e08b2b65db0f6032f7731a5  kno_0.2.1_windows_amd64.zip.sbom.json
fb64db414fd3c096d32fe735b4b0112b9bb691709773a52d2e6a36f7718966c5  kno_0.2.1_windows_arm64.zip
a5321c13f9e051b85081ae28a7708bc8e414ef4941848cdee16cf73d66705b19  kno_0.2.1_windows_arm64.zip.sbom.json