Skip to content

v0.30.0: CHANGELOG and version bump - #117

Merged
avrabe merged 1 commit into
mainfrom
release/v0.30.0
Sep 2, 2026
Merged

v0.30.0: CHANGELOG and version bump#117
avrabe merged 1 commit into
mainfrom
release/v0.30.0

Conversation

@avrabe

@avrabe avrabe commented Sep 1, 2026

Copy link
Copy Markdown
Contributor

The v0.30.0 work merged in #114; this is the bump and release notes.

The notes lead with defects rather than features, because that is what the cycle produced. A design concept went to five reviewers — a security architect, an STPA-Sec analysis, a ceremony operator, an adopting engineer and an independent certification assessor — and all five dissented. The useful half of what they found was not about the design at all:

Honest scope

2 of 13 requirements reach verified. The rest are implemented, each with a stated reason in the notes:

requirement why not verified
REQ-PRODUCER-002 port is partial; the shell pipeline still runs real deposits
REQ-CARRYFORWARD-001 its gate needs the orchestrator, which is unwritten
REQ-PAYLOADSMOKE-001 clause 4 deliberately unimplemented — the architecture check covers 4 platforms, execution covers 1
REQ-NOKEYDISK-001, REQ-INSTALLSHADOW-001 verified by shell gates with negative controls that rivet cannot see (rivet#870)

Also recorded: this realm has one operator and cannot staff the two-person rule its own docs prescribed, and the provisional root has no backup at all.

Verified locally: --locked build, workspace tests, claim-check, docs coverage --strict, rivet validate, and varve --version reporting 0.30.0.

The release notes lead with defects rather than features, because that is what
this cycle produced. A design concept went to five reviewers -- a security
architect, an STPA-Sec analysis, a ceremony operator, an adopting engineer and
an independent certification assessor -- and all five dissented. The useful
half of what they found was not about the design: it was live defects in
shipped code, several in the exact failure class varve exists to close.

A command that returned a value no script could use. A signing key written to
/tmp on a shared runner, against this project's own published rule. An
installer that reported success while a different varve won the PATH lookup.
Output identifying a layer without saying which realm it belonged to.

Two of thirteen requirements in scope reach `verified`. The rest are
`implemented`, and the notes say why for each rather than leaving someone to
discover it: the producer port is partial and the shell pipeline still runs the
real deposits; carry-forward's gate needs the orchestrator that does not exist
yet; payload smoke-running is deliberately unimplemented in favour of the
architecture check, which covers all four platforms instead of one; and two
requirements are verified by shell gates with negative controls that rivet
cannot see, because it does not read markers from .sh files (rivet#870).

The notes also record what this project cannot claim. Its own realm has one
operator and cannot staff the two-person rule its documentation prescribed, and
the provisional root has no backup at all -- it was generated straight into CI
and its secret half exists only as a write-only Actions secret.
@avrabe
avrabe merged commit aff086b into main Sep 2, 2026
21 checks passed
@avrabe
avrabe deleted the release/v0.30.0 branch September 2, 2026 04:22
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant