Skip to content

Tags: ghzhost/plumbline

Tags

v0.2.0

Toggle v0.2.0's commit message
v0.2.0

See CHANGELOG.md for the full record. Highlights over 0.1.0: a
fifteenth suite (conversational_integrity), detached report signatures,
SARIF export, run history, recording retention, an SBOM with a release
workflow, a GitHub Action for pinning the gate, PyPI packaging as
plumbline-eval, mypy wired into CI, a site accessibility check, and
the documentation this project holds itself to (model card,
responsible-tech statement, operations runbook, Definition of Done,
metrics ledger).

(Retagged: the first v0.2.0 push exposed a 39-character
actions/upload-artifact SHA in release.yml that could not resolve;
fixed in ChelseaKR#25 before retagging at this commit.)

v0.1.0

Toggle v0.1.0's commit message

Verified

This tag was signed with the committer’s verified signature.
ChelseaKR Chelsea Kelly-Reif
v0.1.0

First tagged release of the Plumbline evaluation harness.

Leads with nine fail-open defects, closed in the M9 hardening pass. The most
serious: a target returning entirely blank responses scored a perfect 1.0000
on five suites and the gate returned PASS, exit 0. A verdict produced before
that fix can be a vacuous pass.

Gate at this commit: 459 tests OK on CPython 3.11-3.14; the committed demo
audit reproduces byte for byte; the report matches its own seal; the tamper
drill returns exit 3 then exit 1.