From f626d32b7632edb3f15234a136c5156b7b6a0f51 Mon Sep 17 00:00:00 2001 From: arpan Date: Tue, 15 Sep 2026 13:50:52 +0530 Subject: [PATCH] 0.12.1: the verify fixes 0.12.0 was tagged just before `v0.12.0` was cut at the release merge and #213 landed on `main` shortly after, so the published wheel carried none of the three fixes. On the document that found them, a support agent with a grant of twelve refunds an hour, 0.12.0 grades 1 of 1 and calls thirty-one not applicable; this grades 22 of 22. Nothing here touches the enforcement path. The whole of it is `verify/scenarios.py`, the self-check tool, and it under-reported rather than over-claimed, which is the safe direction. It was severe enough to read as a tool that checks nothing. No adapter work: 1.3.0 already declares `ctrlrun>=0.5,<0.13`, so 0.12.1 is inside the range both published adapters accept. Also removed: `adopt-site/`, two files of empty Vite dependency cache swept into the repository root by #138 and referenced by nothing since. It shipped in no distribution, but it is the root a reader lands on. `.vite/` and `node_modules/` are now ignored so it cannot come back. Signed-off-by: arpan --- .gitignore | 6 ++++++ CHANGELOG.md | 14 ++++++++++++++ CITATION.cff | 2 +- adopt-site/.vite/deps/_metadata.json | 8 -------- adopt-site/.vite/deps/package.json | 3 --- pyproject.toml | 2 +- 6 files changed, 22 insertions(+), 13 deletions(-) delete mode 100644 adopt-site/.vite/deps/_metadata.json delete mode 100644 adopt-site/.vite/deps/package.json diff --git a/.gitignore b/.gitignore index ea6040f0..78abf0bf 100644 --- a/.gitignore +++ b/.gitignore @@ -36,3 +36,9 @@ venv/ # `research/*/results/` are; the raw tool captures that produced them are not -- they are # the run, not the finding. audit/**/*.log + +# Build caches from the site tooling. `adopt-site/.vite/deps/` was committed by accident in +# #138 and sat in the repository root for four milestones: two files, an empty dependency +# cache, referenced by nothing. +node_modules/ +.vite/ diff --git a/CHANGELOG.md b/CHANGELOG.md index f2d441d8..b03df7ef 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -9,6 +9,15 @@ any change to one appears here. ## [Unreleased] +## [0.12.1] — the verify fixes 0.12.0 was tagged just before + +`0.12.0` was tagged at the release merge, and these three landed on `main` shortly after, so the +published wheel carried none of them. Nothing here touches the enforcement path: the whole of it +is `verify/scenarios.py`, the self-check tool. It under-reported rather than over-claimed, which +is the safe direction, but the under-report was severe enough to read as a tool that checks +nothing. On the document below, `0.12.0` grades **1 of 1** and calls thirty-one not applicable; +this release grades **22 of 22**. + ### Fixed - **`ctrlrun verify` sized every vector for eighteen spends, and a grant with an ordinary @@ -28,6 +37,11 @@ any change to one appears here. - **A boolean condition was negated with a string.** `X_neq` on `counterparty_new_eq: true` produced `"ctrlrun-verify"`, neither answer; the vector landed in the next rule by accident of `eq` and carried a value no document could mean. A boolean is negated with the other boolean. +- **`adopt-site/` was a committed build cache.** Two files, `.vite/deps/package.json` and an + empty `_metadata.json`, swept into the repository root by #138 and referenced by nothing for + four milestones. Removed, and `.vite/` and `node_modules/` are in `.gitignore` so it cannot + recur. It shipped in no distribution; this is the repository root a reader lands on. + ## [0.12.0] — Hardening diff --git a/CITATION.cff b/CITATION.cff index 725a9641..047c9c84 100644 --- a/CITATION.cff +++ b/CITATION.cff @@ -11,7 +11,7 @@ authors: - family-names: Ghoshal given-names: Arpan email: contact@arpanghoshal.com -version: 0.12.0 +version: 0.12.1 repository-code: https://github.com/CTRLRun/ctrlrun url: https://github.com/CTRLRun/ctrlrun license: Apache-2.0 diff --git a/adopt-site/.vite/deps/_metadata.json b/adopt-site/.vite/deps/_metadata.json deleted file mode 100644 index f9c6a1fa..00000000 --- a/adopt-site/.vite/deps/_metadata.json +++ /dev/null @@ -1,8 +0,0 @@ -{ - "hash": "f5f6dc92", - "configHash": "57c1bbf2", - "lockfileHash": "e3b0c442", - "browserHash": "623c23de", - "optimized": {}, - "chunks": {} -} \ No newline at end of file diff --git a/adopt-site/.vite/deps/package.json b/adopt-site/.vite/deps/package.json deleted file mode 100644 index 3dbc1ca5..00000000 --- a/adopt-site/.vite/deps/package.json +++ /dev/null @@ -1,3 +0,0 @@ -{ - "type": "module" -} diff --git a/pyproject.toml b/pyproject.toml index ae32011e..38de6f1f 100644 --- a/pyproject.toml +++ b/pyproject.toml @@ -4,7 +4,7 @@ build-backend = "setuptools.build_meta" [project] name = "ctrlrun" -version = "0.12.0" +version = "0.12.1" description = "The execution safety layer for AI agents." # Mirrors the repository's GitHub topics, so PyPI search and GitHub search agree. keywords = [