Secure Engine 0.1.5
Experimental pre-1.0 release of the local-first Secure Engine CLI and native desktop application. Findings require human validation; a clean report is not a security guarantee.
Phase 6.9 improves exact source identity and source-span propagation through supported aliases and transformations. Value connectivity now preserves argument positions, object properties, helper parameters, return values, and supported imports. Guards, sanitizers, and dominance checks must protect the same propagated value, reducing overbroad control findings while retaining findings for weak, late, non-terminating, or wrong-value barriers.
The private parse cache advances to v6. Evidence Contract v2, taxonomy 1.0.0, secure-json-v1, deterministic SARIF, CLI/desktop parity, local-only behavior, and disabled-by-default AI validation remain preserved.
Dynamic imports, ambiguous aliases, callbacks, recursion, reflective dispatch, unresolved imports, framework middleware, and runtime-only policy remain conservative limitations. This release makes no benchmark ranking, superiority, production-readiness, complete-coverage, or future-holdout performance claim.
RPM SHA-256: b8d6a86bf9d7be7f5d8200056896189b684838e4af8818f61ec4960de4e20c64