1.0.0 · 21 July 2026
Stable compatibility contract
An internal release-quorum certificate binds one exact release candidate. A digest-bound proposed-1.0 compatibility contract classifies and ratchets changes. Deterministic SARIF 2.1.0 exporter, no-network rigor verify, content-addressed report-diff records, per-rule maturity schema, and CRA readiness (policy schema 1.4, CycloneDX 1.5/1.6, Article 14 lane). API-stability schema 1.1, a tracked module-size decision registry, and a first-repository tutorial.
0.1.1 · 16 July 2026
Rule and provenance hardening
API-compatibility, performance/reproducibility, operations, scientific/numerical, and documentation rules. Ed25519 message-domain separation for pack and reviewer signatures.
0.1.0 · 16 July 2026
First public release
Read-only scan of the exact Git-tracked inventory, candidate anchoring, content-addressed reports, and the fail-closed promotion path.
Provenance

Versioned GitHub Releases and GHCR images are published through the repository; PyPI availability is established from the public registry, not inferred from a tag or workflow result.