Tags: ghzhost/plumbline
Tags
v0.2.0 See CHANGELOG.md for the full record. Highlights over 0.1.0: a fifteenth suite (conversational_integrity), detached report signatures, SARIF export, run history, recording retention, an SBOM with a release workflow, a GitHub Action for pinning the gate, PyPI packaging as plumbline-eval, mypy wired into CI, a site accessibility check, and the documentation this project holds itself to (model card, responsible-tech statement, operations runbook, Definition of Done, metrics ledger). (Retagged: the first v0.2.0 push exposed a 39-character actions/upload-artifact SHA in release.yml that could not resolve; fixed in ChelseaKR#25 before retagging at this commit.)
v0.1.0 First tagged release of the Plumbline evaluation harness. Leads with nine fail-open defects, closed in the M9 hardening pass. The most serious: a target returning entirely blank responses scored a perfect 1.0000 on five suites and the gate returned PASS, exit 0. A verdict produced before that fix can be a vacuous pass. Gate at this commit: 459 tests OK on CPython 3.11-3.14; the committed demo audit reproduces byte for byte; the report matches its own seal; the tamper drill returns exit 3 then exit 1.