Commit bdab697b73
bdab697b73d276102bae5c8623f0a8327291b6cd
parent: 3b82dd31a9
Verified · cmc
cmc <hello@cleberg.net> · 2026-08-08 03:52 UTC
Release v1.0.0
Bump version to 1.0.0, add CHANGELOG, and document the stability commitment.
Layout: unified · split
CHANGELOG.md
added
+28
| @@ -0,0 +1,28 @@ |
| |
1 | # Changelog |
| |
2 | |
| |
3 | All notable changes to this project are documented here. The format is based on |
| |
4 | [Keep a Changelog](https://keepachangelog.com/en/1.1.0/), and this project adheres |
| |
5 | to [Semantic Versioning](https://semver.org/spec/v2.0.0.html). |
| |
6 | |
| |
7 | ## [1.0.0] - 2026-08-07 |
| |
8 | |
| |
9 | First stable release. The `manifest.json` schema (`manifest_version`) and the CLI |
| |
10 | exit codes are now a committed contract: neither changes in a breaking way without |
| |
11 | a major-version bump. |
| |
12 | |
| |
13 | ## [0.1.0] - 2026-08-06 |
| |
14 | |
| |
15 | ### Added |
| |
16 | |
| |
17 | - Tamper-evident seals and chain of custody: streaming SHA-256 with a path-bound |
| |
18 | Merkle root over a directory, written to a canonical `manifest.json`. |
| |
19 | - Append-only seal chains via `previous`, with the `ignore` globs stored so |
| |
20 | `verify` reuses them. |
| |
21 | - Optional ed25519 signing (`[sign]` extra) and RFC 3161 timestamping |
| |
22 | (`[timestamp]` extra), including full TSA-signature verification with `--tsa-cert`. |
| |
23 | - CLI subcommands `seal`, `verify`, `chain`, `keygen`, `sign`; exit codes |
| |
24 | 0 (intact), 1 (tamper / broken / invalid signature), 2 (usage). |
| |
25 | - PyPI trusted-publishing release workflow. |
| |
26 | |
| |
27 | [1.0.0]: https://github.com/audit-labs/evidence-seal/releases/tag/v1.0.0 |
| |
28 | [0.1.0]: https://github.com/audit-labs/evidence-seal/releases/tag/v0.1.0 |
README.md
+6
| @@ -181,6 +181,12 @@ Further limits to be honest about: |
| 181 | to a trusted root — supply a TSA certificate you already trust. |
181 | to a trusted root — supply a TSA certificate you already trust. |
| 182 | - Private keys are written **unencrypted** — store them accordingly. |
182 | - Private keys are written **unencrypted** — store them accordingly. |
| 183 | |
183 | |
| |
184 | ## Stability |
| |
185 | |
| |
186 | `evidence-seal` is stable as of **v1.0.0** and follows [semantic versioning](https://semver.org). |
| |
187 | The `manifest.json` schema (`manifest_version`) and the CLI exit codes are a |
| |
188 | committed contract — neither changes in a breaking way without a major-version bump. |
| |
189 | |
| 184 | ## Development |
190 | ## Development |
| 185 | |
191 | |
| 186 | ```bash |
192 | ```bash |
evidence_seal/__init__.py
+1 −1
| @@ -1,6 +1,6 @@ |
| 1 | """evidence-seal — tamper-evident seals for audit evidence packages.""" |
1 | """evidence-seal — tamper-evident seals for audit evidence packages.""" |
| 2 | |
2 | |
| 3 | __version__ = "0.1.0" |
3 | __version__ = "1.0.0" |
| 4 | |
4 | |
| 5 | # Hash algorithm and manifest format version. Bump MANIFEST_VERSION only on a |
5 | # Hash algorithm and manifest format version. Bump MANIFEST_VERSION only on a |
| 6 | # breaking change to the manifest schema so verify can refuse the unknown. |
6 | # breaking change to the manifest schema so verify can refuse the unknown. |
pyproject.toml
+1 −1
| @@ -4,7 +4,7 @@ build-backend = "setuptools.build_meta" |
| 4 | |
4 | |
| 5 | [project] |
5 | [project] |
| 6 | name = "evidence-seal" |
6 | name = "evidence-seal" |
| 7 | version = "0.1.0" |
7 | version = "1.0.0" |
| 8 | description = "Tamper-evident seals and chain of custody for audit evidence packages." |
8 | description = "Tamper-evident seals and chain of custody for audit evidence packages." |
| 9 | readme = "README.md" |
9 | readme = "README.md" |
| 10 | requires-python = ">=3.10" |
10 | requires-python = ">=3.10" |