← Files The 5th LedgerARCHIVED FILE

CHANGELOG.md

3.42 KB · Oct 2, 2026 · 00:31 UTC

↓ Download file

# Changelog

All notable changes to the distributed plugin are recorded here.

## 0.1.0 — initial publication candidate

- Package eight local-first governance skills for ChatGPT and Codex.
- Establish authority, Canon, evidence, surface, and lifecycle workflows.
- Include project adoption, truth-drift review, independent challenge, governed
  proposals and closeout, release-evidence review, and content harmonization.
- Add complete install-surface metadata, use the approved square icon for both submitted
  logo fields, keep the horizontal lockup as a source-only repository asset, and include
  public policy links, Apache-2.0 licensing, deterministic candidate construction, and
  reviewer-runnable submission tests.
- Bind build and full validation to one sanitized exact Git commit, require canonical
  full-archive bytes, reject unexpected binary package content, and bind both the full
  owner-approved brand files and their deliberately preserved C2PA payloads.
- Require isolated Python and a separately reviewed release-tool trust decision before
  executing candidate tooling; reject capability drift, inert evidence directives,
  common credential tokens, and punctuation-adjacent local paths.
- Freeze the complete reviewed `0.1.0` skill and shared untrusted-evidence policy bytes,
  require the exact eight-skill inventory, and align whole-public-source secret and
  Windows/UNC path scanning with the bundle.
- Reject non-portable, reserved, or extraction-colliding Git and archive paths before
  any candidate bytes are accepted or written, including file-versus-directory prefix
  aliases and inconsistent directory casing.
- Pin the exact two-file bundled Python helper inventory and require isolated Python for
  every documented helper execution.
- Freeze and validate the complete `0.1.0` distributed path-to-SHA-256 inventory so no
  transitive instruction, metadata, template, helper, or other package file can drift.
- Bound Git query duration and complete-tree listing, entry, per-blob, and aggregate
  resources before loading or materializing exact candidate source; drain child stdout
  and stderr concurrently under one monotonic deadline with independent byte caps.
- Bound untrusted adopter profiles before and after TOML parsing, cap route and
  collection cardinality, reject duplicate routes in linear time, open special files
  nonblocking, and convert parser recursion into a controlled failure.
- Prevent adopter Git placement checks from using lazy fetch, prompts, global/system
  configuration, replacement objects, optional locks, filesystem monitors, external
  exclude files, or caller-selected executables; apply a 15-second query bound.
- Cap candidate path bytes, components, and component length before prefix work, build
  prefixes incrementally, and escape rejected Git/archive paths in diagnostics.
- Open candidate archive inputs through a nonblocking, close-on-exec, no-follow
  descriptor so special files cannot stall before the regular-file check.
- Treat reviewed artifacts as untrusted evidence, minimize sensitive reviewer packets,
  and constrain live remote proof to separately trusted provider or HTTPS boundaries.
- Preserve the skills-only boundary: no MCP server, hooks, apps, connectors,
  authentication, telemetry, UI, hosted/background runtime, or publisher-operated
  network service.

This is the initial candidate. It does not claim review submission, approval,
publication, directory availability, deployment, or release.

SHA-256: 41daac4980f49ebe742719d818fcf1c7d3b4ca08dce9caedf52906790df8d2b5