Skip to content

RouteContract v0.1.2

Latest

Choose a tag to compare

@ym0506 ym0506 released this 30 Aug 07:24
· 15 commits to main since this release
Immutable release. Only release title and notes can be modified.
fc4fdd1

RouteContract v0.1.2 is a narrow release-evidence recovery for the Java test library that detects review-worthy execution-structure drift in Apache ShardingSphere-JDBC 5.5.3 integration tests. The v0.1.2 source delta changes only the release identity, changelog, and pinned official OSV Maven database snapshot; runtime and API behavior are unchanged.

Why v0.1.2

The annotated v0.1.1 tag is preserved and unmoved at tag object 906a0d3c056173d8e51af86714934477ee2cb69a, peeling to commit 68078604a273b5529e72f0fac936dc459d44d1f9. Its exact-tag Release evidence run stopped before artifact upload because the pinned official OSV Maven database generation returned HTTP 404. No v0.1.1 GitHub Release was created.

Version 0.1.2 refreshes that external evidence input to the official Maven snapshot generation 1788041965706714, last modified 2026-08-29T22:19:25.841Z, while preserving the failed candidate's public history instead of moving or deleting its tag.

Highlights

  • Captures hook-reported physical JDBC execution attempts for one named application operation.
  • Compares a value-minimized candidate manifest with a human-approved baseline.
  • Produces deterministic structural diffs and stable RCM codes that can fail a required CI check.
  • Omits raw SQL, parameter values, connection properties, exception messages, timestamps, UUIDs, and thread identifiers from canonical manifests.
  • Includes real-MySQL regression, determinism, concurrency, failure-boundary, privacy, and generic-tool comparison fixtures.
  • Provides a checksum-verified, no-registry installation path for the attached JAR and POM assets.

Verified release evidence

  • Annotated tag: v0.1.2 (tag object 6adacbe04d60b3af83d9067a14a878d26a6c90f5)
  • Commit: fc4fdd16c21574afa1150654ce354cf8004b138b
  • Tree: a35d9fee94386428a0eeff77fe39776ea25e4e3a
  • Release evidence workflow run: 7 suites, 52 tests, 0 failures, 0 errors, 0 skipped
  • Actions artifact ID: 9728184111
  • Actions artifact SHA-256: 089fcc24cd5d114be29897ceabbad554a063cae681c95c9023b869b3996e4fcd
  • Public asset set: 11 payloads plus SHA256SUMS
  • SHA256SUMS SHA-256: 7849adf417f0170b08d01902b023e8b328d8796f7c2aeacc471eb7acf8e2b217

The exact-tag workflow ran the public Quick Start from a clean checkout and fresh Gradle home, built the release assets, and installed those assets into an isolated file Maven repository before a standalone MySQL consumer test. This is release-packaging evidence, not evidence of an external user or adoption.

Install from the attached assets

Download all twelve attached files into one new directory, then follow the Release-asset installation instructions. The installer verifies the exact filename set, SHA256SUMS, POM/JAR/source structure, and the SBOM and supply-chain bindings before writing to an explicit empty file Maven repository.

Checksums establish asset integrity; they do not authenticate publisher identity. This v0.1 release has no signature assets or SLSA provenance claim.

Supply-chain boundary

The pinned offline scan used OSV-Scanner 2.5.0 and the official Maven database snapshot last modified at 2026-08-29T22:19:25.841Z. The exact release evidence contains 154 Maven packages, 0 vulnerability findings, 0 accepted vulnerability exceptions, and 0 unreviewed findings.

One package-level license review remains manual-review-required: the digest-pinned mysql:8.4.11 OCI image used only as a test container. It was reviewed on 2026-08-24 and expires on 2026-12-05. This is point-in-time supply-chain evidence, not a vulnerability-free claim, legal advice, legal clearance, or an image-wide license conclusion. Re-review is required immediately if the digest, selected platform, embedded license evidence, or test-container boundary changes.

Compatibility and non-claims

The supported boundary is Java 17 and exactly ShardingSphere-JDBC 5.5.3 for normally returning, non-interrupted, synchronous, non-batch PreparedStatement execution. RouteContract observes hook callbacks; it does not prove a complete route plan, physical-table count, SQL semantic equivalence, enclosing JDBC completion, transaction commit, business success, performance, security, production readiness, external users, adoption, or Apache ShardingSphere endorsement.

No Maven Central publication is claimed for version 0.1.2. See the README, specification, and changelog for usage, limits, and the exact v0.1.2 source delta.