• v0.2.0 82b9d652a9

    Argand Site Registry 0.2.0
    All checks were successful
    Standalone registry checks / check (push) Successful in 3m54s
    Stable

    nicweyand released this 2026-09-13 05:31:21 +00:00 | 13 commits to main since this release

    Signed by nicweyand
    SSH key fingerprint: SHA256:2te+ycJIQON/Wo/dH6+ZkFSQ4HnHWpetV2azx9E65dQ

    Argand Site Registry 0.2.0 strengthens the standalone, evidence-backed entity-to-website registry for navigational search and regional destination resolution.

    Security and release integrity:

    • Opens authenticated generation bytes through an immutable file descriptor and rejects SQLite WAL/SHM sidecars, symlinks and unexpected generation files.
    • Requires SSH-authenticated exact reviewer decisions, preserves the signed proof bytes and re-verifies every decision before a dataset release can be signed.
    • Preserves revocation history during activation and reports review-only and revocation-only changes in typed diffs.
    • Keeps source assertions, popularity signals, reviewer decisions and crawler observations separate; observations never establish ownership on their own.

    Operator and consumer improvements:

    • Adds stable resolver outcomes for ambiguous identities, missing/expired reviews, region mismatches and destination ambiguity.
    • Adds exact entity lookup, URL/hostname/registrable-domain reverse lookup, source-separated popularity, redacted Curlie categories and registry history/statistics views.
    • Adds bounded JSONL evaluation with entity, URL and resolution-status judgments plus native p50/p95 latency.
    • Adds a publisher runbook, evaluation guide, isolated CI image and future crawler-evidence contract.

    Schema compatibility: version 0.2 uses database schema 2 and argand.site-rules/v2. Opening a version 1 store applies the append-only migration and preserves its history, but legacy unauthenticated decisions cannot authorize a new signed release. Start a reviewed version 2 store from pinned source snapshots and obtain fresh authenticated decisions.

    Validation: 32 Rust tests and eight Python packaging tests pass with strict formatting, compilation, Clippy, API documentation, shell checks, consumer parity and adversarial trust-boundary cases. Forgejo Actions run 3 passed final commit 82b9d652a98b1895bd44246c39b359d3aa412917 on the repository-scoped isolated runner, including byte-identical package creation and a full acceptance rerun from extracted source: https://git.argand.org/nicweyand/argand-site-registry/actions/runs/3

    Source receipt SHA-256: e5e416d687c7e1fba0c10310247ca5f6cbe8518c846294ace24d478c27e393c7.
    Archive SHA-256: e291493669da70080a2c537a9d54c0a2612595efded0351c8147cff2ee18ba6f.
    Source signature namespace: argand-site-registry-source.
    Signer identity: nicweyand.
    Signer key fingerprint: SHA256:2te+ycJIQON/Wo/dH6+ZkFSQ4HnHWpetV2azx9E65dQ.

    Authenticate the signer key independently, then follow docs/RELEASING.md. Code is AGPL-3.0-or-later. Provider data retains the separate terms documented in LICENSE_SOURCES.md. The attached source release contains no provider dataset, reviewer approval log or production signing key. Argand has not yet switched its embedded registry dependency to this release.

    Downloads