62 lines
3.4 KiB
Markdown
62 lines
3.4 KiB
Markdown
# Changelog
|
|
|
|
## 0.4.0 - 2026-09-13
|
|
|
|
- Add typed full/partition/delta source coverage, active-record masking, a
|
|
receipt-bound coverage digest, active export and complete audit export.
|
|
- Separate name, website-edge and entity-equivalence identities so aliases cannot
|
|
inherit routes and unrelated metadata does not invalidate stable edges.
|
|
- Replace latest-review admission with authenticated, policy-bound reviewer votes,
|
|
independent identity/group/physical-key quorum, trusted writer acceptance time,
|
|
bounded expiry, risk-class threshold overrides and sticky explicit revocation
|
|
supersession.
|
|
- Bind strict reviewer trust roots and review policy into releases and enforce
|
|
publisher identity and physical-key separation.
|
|
- Store immutable subject-bound observation batches and add exact/reverse lookup,
|
|
bounded DNS-pinned candidate observation, cache-only replay and structured HTTP,
|
|
redirect, canonical, hreflang, JSON-LD, sitemap, country, DNS, TLS and failure
|
|
evidence.
|
|
- Add deterministic evidence bundles, risk-ordered review queues, drift classes,
|
|
revocation-candidate export, schema migrations 4 and 5, 0.3 compatibility
|
|
guidance, architecture decisions and strict end-to-end security fixtures.
|
|
- Add publisher-signed cumulative emergency revocation feeds with seven-day
|
|
freshness, rollback-safe continuity, block-only application to older compatible
|
|
registries, and reinstatement validation against an exact full generation.
|
|
- Add safe scheduled typed-snapshot supersession and a serialized, bandwidth-capped
|
|
observer service; reject compressed bodies, redirect loops and duplicate update
|
|
coordinates before acquisition.
|
|
|
|
## 0.3.0 - 2026-09-13
|
|
|
|
- Snapshot authenticated SQLite bytes into a private file before queries and sign
|
|
sealed receipt bytes, removing mutable-path time-of-check/time-of-use windows.
|
|
- Require consumer-supplied reviewer trust roots during signed verification and
|
|
activation; support retired reviewer keys with OpenSSH validity epochs.
|
|
- Hash the exact source descriptor stream consumed by parsers and add configurable
|
|
expanded-byte, record, database-growth, query-output and diff-output limits.
|
|
- Bind identity decisions to entity metadata, redact descriptions from typed diffs,
|
|
include diff attribution and keep CrUX job IDs stable across output-only limits.
|
|
- Migrate writer stores to schema/rules version 3 while allowing activation over
|
|
pinned version 1 and version 2 generations for revocation checks.
|
|
|
|
## 0.2.0 - 2026-09-13
|
|
|
|
- Open generations from an authenticated immutable SQLite file descriptor and
|
|
reject sidecars, symlinks and unexpected generation files.
|
|
- Authenticate exact reviewer decisions with SSH signatures, retain their proofs
|
|
and re-verify every decision before release signing.
|
|
- Explain resolver abstentions with typed statuses and decision counts.
|
|
- Add exact entity, URL/domain, source-separated popularity, redacted category and
|
|
registry-statistics audit views.
|
|
- Stream typed diffs across source selections, projections, decisions and explicit
|
|
equivalences.
|
|
- Add bounded native evaluation with multilingual, regional and deceptive-query
|
|
regressions plus latency evidence.
|
|
- Normalize rights-bearing future crawler observations without admitting them as
|
|
identity or ownership evidence.
|
|
|
|
## 0.1.0 - 2026-09-12
|
|
|
|
- Initial independent extraction with five rights-reviewed source adapters,
|
|
deterministic normalization, immutable generations and conservative regional
|
|
resolution.
|