v1.0.0
What's Changed
- feat: add cross-table averages by @wa-pis in #67
- feat: diversify negative rule cases by @wa-pis in #68
- docs: map releases to 1.0 by @wa-pis in #69
- feat: add cross-table negative cases by @wa-pis in #70
- feat: report expected negative cases by @wa-pis in #71
- docs: add reproducible negative example by @wa-pis in #72
- docs: publish public stability map by @wa-pis in #73
- test: version public contract fixtures by @wa-pis in #74
- docs: inventory compatibility surfaces by @wa-pis in #75
- test: preserve previous release contracts by @wa-pis in #76
- docs: define runtime support policy by @wa-pis in #77
- test: enforce operational resource budgets by @wa-pis in #78
- fix: clean staging on cancellation by @wa-pis in #79
- test: cover mid-write disk exhaustion by @wa-pis in #80
- test: cover staged timeout cleanup by @wa-pis in #81
- fix: roll back interrupted publication by @wa-pis in #82
- feat: verify parquet doctor capability by @wa-pis in #83
- feat: verify mcp doctor capability by @wa-pis in #84
- feat: verify trino doctor capability by @wa-pis in #85
- feat: verify provider doctor capability by @wa-pis in #86
- ci: test wheels on supported Python by @wa-pis in #87
- ci: validate ARM64 container targets by @wa-pis in #88
- ci: gate container vulnerabilities by @wa-pis in #89
- ci: enforce dependency license policy by @wa-pis in #90
- docs: record security review dispositions by @wa-pis in #91
- docs: archive cli mcp boundary spec by @wa-pis in #92
- docs: archive compatibility inventory spec by @wa-pis in #93
- docs: archive public stability spec by @wa-pis in #94
- docs: archive contract catalog spec by @wa-pis in #95
- docs: archive release fixture spec by @wa-pis in #96
- docs: archive runtime support spec by @wa-pis in #97
- docs: define remaining 1.0 execution plan by @wa-pis in #98
- docs: archive public Python contract by @wa-pis in #99
- docs: archive artifact contract by @wa-pis in #100
- docs: archive MCP schema contract by @wa-pis in #101
- docs: archive cross-table average spec by @wa-pis in #102
- docs: archive controlled negative spec by @wa-pis in #103
- docs: archive cross-table negative spec by @wa-pis in #104
- docs: archive negative artifact spec by @wa-pis in #105
- docs: archive negative interface example by @wa-pis in #106
- docs: archive resource budget spec by @wa-pis in #107
- ci: skip heavy checks for docs by @wa-pis in #108
- docs(release): plan 1.0.0rc1 hardening by @wa-pis in #109
- fix: enforce dataset spec safety boundary by @wa-pis in #110
- test: cover spec safety adapters by @wa-pis in #111
- Codex/1 0 0rc1 relational synthesis by @wa-pis in #112
- docs(product): define relational synthesis by @wa-pis in #113
- fix(trino): privatize raw query execution by @wa-pis in #114
- docs(roadmap): capture review follow-ups by @wa-pis in #115
- test(trino): guard cursor execution boundary by @wa-pis in #116
- test(trino): preserve safe profiler queries by @wa-pis in #117
- docs(openspec): archive input detection by @wa-pis in #118
- docs(openspec): archive advisor adapter by @wa-pis in #119
- docs(openspec): archive reference agent flow by @wa-pis in #120
- docs(openspec): archive agent review report by @wa-pis in #121
- docs(openspec): archive container vulnerability gate by @wa-pis in #122
- docs(openspec): archive wheel python matrix by @wa-pis in #123
- docs(openspec): archive agent review summary by @wa-pis in #124
- docs(openspec): consolidate completed changes by @wa-pis in #125
- fix: honor generation locale by @wa-pis in #126
- docs: define privacy guarantee limits by @wa-pis in #127
- fix: prevent container version drift by @wa-pis in #128
- fix: honor validation settings by @wa-pis in #129
- feat: record reproducibility evidence by @wa-pis in #130
- fix(io): bound nested JSON inputs by @wa-pis in #131
- docs: add public governance policies by @wa-pis in #132
- ci: gate direct safety boundaries by @wa-pis in #133
- docs: define relational synthesis contract by @wa-pis in #134
- feat(advisor): add discovery contracts by @wa-pis in #135
- feat(advisor): add discovery review workflow by @wa-pis in #136
- test(advisor): cover relationship confidence by @wa-pis in #137
- feat(advisor): add temporal discovery evidence by @wa-pis in #138
- test(rules): cover generic business invariants by @wa-pis in #139
- test(validation): cover grouped reconciliation by @wa-pis in #140
- feat(generation): scale sensitive numeric totals by @wa-pis in #141
- feat(manifest): record effective rule set by @wa-pis in #142
- fix(privacy): suppress raw category values by @wa-pis in #143
- fix(privacy): make sensitive masks opaque by @wa-pis in #144
- chore(types): cover csv profiler by @wa-pis in #145
- chore(types): cover io and parquet by @wa-pis in #146
- chore(types): enforce full package gate by @wa-pis in #147
- docs(contract): bound synthesis by evidence by @wa-pis in #148
- docs(release): record rc coverage evidence by @wa-pis in #149
- docs(roadmap): plan runnable examples by @wa-pis in #150
- docs(examples): add runnable csv journey by @wa-pis in #151
- test(examples): harden csv journey checks by @wa-pis in #152
- docs(examples): add relational csv journey by @wa-pis in #153
- docs(examples): add python api journey by @wa-pis in #154
- docs(plan): add improvement scopes by @wa-pis in #155
- feat(cli): add installed offline demo by @wa-pis in #156
- test(cli): complete offline demo contract by @wa-pis in #157
- fix(csv): classify ISO dates before phones by @wa-pis in #158
- docs: lead with installed demo by @wa-pis in #159
- docs(openspec): archive installed demo change by @wa-pis in #160
- docs: define dependency test profiles by @wa-pis in #161
- ci: add minimum dependency matrix by @wa-pis in #162
- test: pin dependency contract coverage by @wa-pis in #163
- docs: define reproducibility guarantees by @wa-pis in #164
- feat: record normalized dependency evidence by @wa-pis in #165
- docs: record dependency bound decisions by @wa-pis in #166
- ci: gate dependency compatibility drift by @wa-pis in #167
- docs: archive dependency compatibility spec by @wa-pis in #168
- feat: add safe sql export example by @wa-pis in #169
- docs: add runnable mcp stdio journey by @wa-pis in #170
- docs: add disposable trino journey by @wa-pis in #171
- docs: define changelog policy by @wa-pis in #172
- docs: inventory unreleased changelog by @wa-pis in #173
- test: enforce changelog category order by @wa-pis in #174
- docs: classify unreleased summary by @wa-pis in #175
- docs: link unreleased release context by @wa-pis in #176
- docs: move internal release evidence by @wa-pis in #177
- docs: finalize rc changelog categories by @wa-pis in #178
- docs: archive release documentation change by @wa-pis in #179
- fix: redact rare advisor categories by @wa-pis in #180
- docs: record rc gate evidence by @wa-pis in #181
- docs: clarify product fit by @wa-pis in #182
- docs: publish threat model by @wa-pis in #183
- docs: define assurance levels by @wa-pis in #184
- docs: sync completed rc contracts by @wa-pis in #185
- docs: record post-1.0 dispositions by @wa-pis in #186
- docs: record release documentation readiness by @wa-pis in #187
- chore(release): prepare 1.0.0rc1 by @wa-pis in #188
- fix(release): support rc container tags by @wa-pis in #189
- ci: verify published release artifacts by @wa-pis in #190
- fix(ci): honor release checksum paths by @wa-pis in #191
- docs: record published rc2 evidence by @wa-pis in #192
- docs: finalize rc2 security review by @wa-pis in #193
- ci: verify published agent workflow by @wa-pis in #194
- docs: record public rc2 acceptance by @wa-pis in #195
- docs: require boundaries refactor for 1.0 by @wa-pis in #196
- fix(ci): cover every main commit with CodeQL by @wa-pis in #197
- docs: inventory application boundaries by @wa-pis in #198
- refactor(agent): extract workspace store by @wa-pis in #199
- refactor(agent): extract planning service by @wa-pis in #200
- refactor(agent): extract review service by @wa-pis in #201
- refactor(agent): extract approval service by @wa-pis in #202
- refactor(agent): extract recovery service by @wa-pis in #203
- refactor(agent): extract advising service by @wa-pis in #204
- refactor(agent): extract status service by @wa-pis in #205
- refactor(cli): extract doctor service by @wa-pis in #206
- refactor(cli): centralize optional dependencies by @wa-pis in #207
- refactor(cli): extract agent handlers by @wa-pis in #208
- refactor(cli): extract command handlers by @wa-pis in #209
- refactor(cli): extract application dispatch by @wa-pis in #210
- refactor(trino): extract config boundary by @wa-pis in #211
- refactor(trino): extract SQL policy by @wa-pis in #212
- refactor(trino): extract query builders by @wa-pis in #213
- refactor(trino): extract bounded client by @wa-pis in #214
- refactor(trino): extract profiling service by @wa-pis in #215
- refactor(trino): extract masking service by @wa-pis in #216
- test(architecture): enforce application boundaries by @wa-pis in #217
- fix(workspace): reject symlink plan targets by @wa-pis in #218
- fix(agent): enforce spec safety in approval by @wa-pis in #219
- test(trino): cover direct SQL rejection by @wa-pis in #220
- test(agent): reject unsafe advisor payload by @wa-pis in #221
- docs: explain internal boundary migrations by @wa-pis in #222
- test: freeze application boundary contracts by @wa-pis in #223
- chore: record refactor gate evidence by @wa-pis in #224
- chore: archive application boundary change by @wa-pis in #225
- chore: prepare 1.0.0rc3 release by @wa-pis in #226
- Codex/plan rc4 hardening by @wa-pis in #227
- test: align docs checks with rc4 by @wa-pis in #228
- fix(mcp): remove default row sampling by @wa-pis in #229
- docs(openspec): require source-free MCP by @wa-pis in #230
- docs: clarify RC4 safety contract by @wa-pis in #231
- fix(mcp)!: remove row sampling API by @wa-pis in #232
- docs(mcp): document row sampling removal by @wa-pis in #233
- test(mcp): freeze default Trino tools by @wa-pis in #234
- test(mcp): cover default direct services by @wa-pis in #235
- test(mcp): cover transport success paths by @wa-pis in #236
- test(mcp): cover tool validation failures by @wa-pis in #237
- test(mcp): cover tool database failures by @wa-pis in #238
- test(mcp): verify default audit privacy by @wa-pis in #239
- test(mcp): cover nested response serialization by @wa-pis in #240
- test(mcp): add typed source literal fixtures by @wa-pis in #241
- feat: add typed Trino work budget by @wa-pis in #242
- feat: bound canonical Trino arguments by @wa-pis in #243
- feat(mcp): bound raw Trino payloads by @wa-pis in #244
- feat(trino): bound SQL and formula work by @wa-pis in #245
- feat(trino): bound AST work by @wa-pis in #246
- feat(trino): bound projected columns by @wa-pis in #247
- feat(trino): bound statement work by @wa-pis in #248
- feat(trino): stream response budget by @wa-pis in #249
- test(trino): prove shared nested budget by @wa-pis in #250
- docs(release): pin RC4 installation by @wa-pis in #251
- ci: isolate wheel capability checks by @wa-pis in #252
- docs(mcp): clarify privacy boundary by @wa-pis in #253
- docs(release): define durability contract by @wa-pis in #254
- docs(release): define stable promotion by @wa-pis in #255
- chore(release): record lint gate by @wa-pis in #256
- chore(release): record compile gate by @wa-pis in #257
- chore(release): record coverage gate by @wa-pis in #258
- chore(release): record release gates by @wa-pis in #259
- docs(release): disposition rc4 findings by @wa-pis in #260
- chore(release): prepare 1.0.0rc4 by @wa-pis in #261
- docs(release): record rc4 acceptance by @wa-pis in #262
- docs: plan RC5 release hardening by @wa-pis in #263
- docs(release): record rc4 package acceptance by @wa-pis in #264
- docs(release): record rc4 github release by @wa-pis in #265
- ci(release): verify public install profiles by @wa-pis in #266
- docs: add RC5 agent throughput plan by @wa-pis in #267
- ci(release): run README smoke per profile by @wa-pis in #269
- docs: slim agent instructions by @wa-pis in #268
- docs(release): record public profile smoke by @wa-pis in #270
- fix(release): align RC5 acceptance gates by @wa-pis in #271
- docs(release): record profile acceptance by @wa-pis in #272
- docs(release): record expanded matrix by @wa-pis in #273
- ci(release): test public upgrade by @wa-pis in #274
- docs(release): record rc4 acceptance by @wa-pis in #275
- refactor(trino): split response counters by @wa-pis in #276
- fix(trino): budget converted rows by @wa-pis in #277
- fix(mcp): bound serialized responses by @wa-pis in #278
- fix(mcp): bound JSON-RPC request IDs by @wa-pis in #279
- fix(mcp): return bounded overflow errors by @wa-pis in #280
- test(mcp): cover response budget edge cases by @wa-pis in #281
- feat(trino): add cumulative budget types by @wa-pis in #282
- feat(trino): set invocation defaults by @wa-pis in #283
- feat(trino): share nested invocation budget by @wa-pis in #284
- feat(trino): enforce query deadline by @wa-pis in #285
- feat(trino): configure invocation limits by @wa-pis in #286
- chore(deps): bump cryptography from 49.0.0 to 50.0.0 by @dependabot[bot] in #287
- test(trino): cover wide table budget by @wa-pis in #294
- chore(deps): bump actions/attest from 4.2.0 to 4.2.2 by @dependabot[bot] in #293
- chore(deps): bump pypa/gh-action-pypi-publish from 1.14.1 to 1.14.2 by @dependabot[bot] in #291
- chore(deps): bump aquasecurity/trivy-action from a9c7b0f06e461e9d4b4d1711f154ee024b8d7ab8 to ed142fd0673e97e23eac54620cfb913e5ce36c25 by @dependabot[bot] in #290
- chore(deps): bump github/codeql-action/upload-sarif from 4.37.3 to 4.37.6 by @dependabot[bot] in #289
- docs(openspec): record invocation limit tests by @wa-pis in #295
- docs(mcp): clarify README response boundary by @wa-pis in #296
- docs(mcp): clarify example response boundary by @wa-pis in #297
- docs(mcp): scope how-to response claims by @wa-pis in #298
- docs(mcp): scope AI integration claims by @wa-pis in #299
- docs(mcp): fix configuration ownership by @wa-pis in #300
- docs(mcp): clarify application boundaries by @wa-pis in #301
- docs(mcp): clarify diagram boundaries by @wa-pis in #302
- docs(mcp): align canonical response contract by @wa-pis in #303
- docs(mcp): normalize tool surface terms by @wa-pis in #304
- test(docs): guard MCP privacy contract by @wa-pis in #305
- chore(release): record RC5 lint gate by @wa-pis in #306
- chore(release): record RC5 compile gate by @wa-pis in #307
- chore(release): record RC5 coverage gate by @wa-pis in #308
- chore(release): record RC5 full gates by @wa-pis in #309
- test(release): record throughput evidence by @wa-pis in #310
- chore(openspec): record auto cache evidence by @wa-pis in #311
- perf(profiling): stream rule sample once by @wa-pis in #312
- feat(profiling): bound local profile work by @wa-pis in #313
- feat(advisor): add bounded provider settings by @wa-pis in #314
- fix(advisor): budget complete provider request by @wa-pis in #315
- feat(advisor): record bounded run metadata by @wa-pis in #316
- feat(advisor): add OpenAI relationship ranking by @wa-pis in #317
- docs(openspec): record RC5 test evidence by @wa-pis in #318
- feat(advisor): add RC5 preset candidates by @wa-pis in #319
- feat(advisor): add preset benchmark harness by @wa-pis in #320
- fix(advisor): select benchmarked fast defaults by @wa-pis in #321
- fix(rc5): close transport safety gaps by @wa-pis in #322
- fix(mcp): isolate request ID budgets by @wa-pis in #323
- feat(advisor): prepare acceptance benchmark by @wa-pis in #324
- docs(rc5): record advisor acceptance run by @wa-pis in #325
- chore(release): prepare 1.0.0rc5 by @wa-pis in #326
- docs(release): record RC5 publication by @wa-pis in #327
- RC6 final candidate hardening by @wa-pis in #329
- fix(openai): suppress provider error chains by @wa-pis in #331
- fix(advisor): reserve placeholder-shaped values by @wa-pis in #332
- fix(openai): redact incomplete status by @wa-pis in #333
- fix(openai): detach provider exceptions by @wa-pis in #334
- fix(advisor): preserve placeholder provenance by @wa-pis in #335
- fix(openai): harden public error boundary by @wa-pis in #336
- fix(advisor): mask categorical egress by @wa-pis in #337
- fix(trino): preserve safe numeric shape by @wa-pis in #338
- fix(rc6): close public release hardening gaps by @wa-pis in #339
- test(rc6): close openai error evidence by @wa-pis in #340
- docs(rc6): record advisor egress closure by @wa-pis in #341
- docs(rc6): record numeric privacy closure by @wa-pis in #342
- fix(advisor): validate proposed constraints by @wa-pis in #343
- fix(mcp): bound generator transport by @wa-pis in #344
- fix(output): harden artifact boundaries by @wa-pis in #345
- fix(mcp): bound shared request work by @wa-pis in #346
- docs(rc6): record S9 closure evidence by @wa-pis in #347
- fix(trino): redact backend failures by @wa-pis in #348
- docs: define product validation and PostgreSQL gate by @wa-pis in #349
- fix(trino): mask safe-select strings by @wa-pis in #350
- fix(generation): bound semantic providers by @wa-pis in #351
- fix(io): harden filesystem publication by @wa-pis in #352
- fix(io): verify single-entity bundles by @wa-pis in #353
- fix(cli): escape untrusted diagnostics by @wa-pis in #354
- ci: load classifier from trusted base by @wa-pis in #355
- ci(release): bind publication to signed source by @wa-pis in #356
- feat(release): enforce acceptance manifest by @wa-pis in #357
- docs(rc6): record pinned profile gate by @wa-pis in #358
- docs(rc6): record deployed release policy by @wa-pis in #359
- docs: specify PostgreSQL multi-source gate by @wa-pis in #360
- fix: replace source-derived categories by @wa-pis in #361
- fix: sanitize advisor constraint literals by @wa-pis in #362
- fix(security): sanitize scalar categories by @wa-pis in #363
- fix(security): mask nested Trino values by @wa-pis in #364
- fix(security): pin Dockerfile frontend by @wa-pis in #365
- fix(safety): bind CSV check to profile by @wa-pis in #366
- fix(artifacts): reserve control basenames by @wa-pis in #367
- fix(validation): reject duplicate entity stems by @wa-pis in #368
- fix(profiling): enforce field deadlines by @wa-pis in #369
- fix(audit): reserve terminal capacity by @wa-pis in #370
- docs(security): record accepted known issues by @wa-pis in #371
- fix(agent): bind plans to source version by @wa-pis in #372
- docs(privacy): scope category preservation by @wa-pis in #373
- feat(privacy): add local category allowlist by @wa-pis in #374
- feat(privacy): enforce safe local category allowlist by @wa-pis in #375
- fix(trino): enforce table-column allowlist for categories by @wa-pis in #376
- fix(advisor): preserve allowlisted categorical literals by @wa-pis in #377
- fix(release): resolve physical temp path by @wa-pis in #378
- fix(release): resolve installed smoke path by @wa-pis in #379
- docs(openspec): define postgres SQL scope by @wa-pis in #380
- fix(cli): parse qualified preserve fields by @wa-pis in #381
- feat(postgres): add bounded source config by @wa-pis in #382
- feat(postgres): add read-only session boundary by @wa-pis in #383
- feat(postgres): add metadata query builders by @wa-pis in #384
- feat(postgres): add aggregate query builders by @wa-pis in #385
- feat(privacy): validate preserved categories by @wa-pis in #386
- fix(postgres): require typed profiling queries by @wa-pis in #387
- feat(postgres): normalize bounded profiles by @wa-pis in #388
- feat(postgres): export deterministic sql by @wa-pis in #389
- feat(cli): export PostgreSQL SQL files by @wa-pis in #390
- build(postgres): add optional driver extra by @wa-pis in #391
- feat(postgres): add profile cli workflow by @wa-pis in #392
- test(postgres): smoke installed sql workflow by @wa-pis in #393
- fix(release): include psycopg evidence by @wa-pis in #394
- fix(validation): ignore JSON key order by @wa-pis in #395
- docs: document PostgreSQL RC6 workflow by @wa-pis in #396
- docs(release): reconcile RC6 evidence by @wa-pis in #399
- chore(release): prepare 1.0.0 by @wa-pis in #400
Full Changelog: v0.12.0...v1.0.0