• v0.3.0 ac8282093d

    Argand Site Registry 0.3.0
    All checks were successful
    Standalone registry checks / check (push) Successful in 3m44s
    Stable

    nicweyand released this 2026-09-13 06:40:31 +00:00 | 11 commits to main since this release

    Signed by nicweyand
    SSH key fingerprint: SHA256:2te+ycJIQON/Wo/dH6+ZkFSQ4HnHWpetV2azx9E65dQ

    Argand Site Registry 0.3.0 closes the security and operational findings from the 0.2 review.

    • Queries use a private authenticated SQLite snapshot; source import and release signing operate on exact opened or sealed bytes.
    • Signed release verification and activation now require independent reviewer trust roots. OpenSSH validity epochs support reviewer-key retirement.
    • Imports and query/diff outputs have finite configurable resource bounds; Curlie descriptions remain redacted from typed diffs with attribution attached.
    • Identity reviews bind displayed entity metadata, CrUX output-only limits no longer change job IDs, and v3 activation can inspect pinned v1/v2 history for rollback safety.

    Compatibility: writer schema and derivation rules advance to version 3. activate requires --allowed-reviewers; Rust callers of release::verify_signed and release::activate must pass the reviewer trust file.

    Validation: 38 Rust tests, eight source-release tests, strict formatting/compiler/Clippy/rustdoc gates, native CLI/Rust/Python parity, RustSec audit, and isolated Forgejo Actions runs 4 and 5.

    Source release:

    • RELEASE.json SHA-256: 8083e44b632c84abc711915314130194bcd16de54d0e93d287a8b4b0acc2626e
    • RELEASE.json.sig SHA-256: f0304b400695b9b5c14e79712914a8b7744b8e59e8a457e30fda7f65a04e80d2
    • source.tar.gz SHA-256: e6db0b982cb3c04f2175936180f0a95f53dcf59bb097fd4d6b6c972a5ad0b669

    This release contains source code only. It acquires no provider data and promotes no destination registry.

    Downloads