Skip to content

v0.5.0: Protocol + Hardened Mode + Production Candidate#3

Merged
madeinplutofabio merged 13 commits into
mainfrom
scaffold
Mar 24, 2026
Merged

v0.5.0: Protocol + Hardened Mode + Production Candidate#3
madeinplutofabio merged 13 commits into
mainfrom
scaffold

Conversation

@madeinplutofabio

Copy link
Copy Markdown
Owner

Summary

  • Stage 1a: Protocol Complete — conformance suite, policy schema, reason codes
  • Stage 1b: Hardened Defaults — limits, path enforcement, capped capture, adversarial tests
  • Stage 2: First Hardened Mode — approval, signing, sandbox (bubblewrap), integration tests
  • Stage 3: Production Candidate — CI, release infrastructure, security process, docs

See CHANGELOG.md for full details.

…process, docs

- Production readiness gate (docs/production-readiness-gate.md)
- CI workflow for hardened integration tests (Docker + --network=none)
- Release workflow: sigstore signing, SBOM, PyPI trusted publishing
- SECURITY.md with severity rubric and SLA targets
- Security advisory and release templates
- Dependabot configuration (pip, actions, docker)
- Threat model with trust boundaries and threat classes
- README aligned with hardened mode availability
- Branch protection and repo security settings configured
- Version bumped to 0.5.0
@madeinplutofabio madeinplutofabio merged commit 2ea68ba into main Mar 24, 2026
10 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant