You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Produce a reproducible release and evidence bundle from the final merged autonomous-security commit so reviewers do not confuse historical v0.1.0-demo artifacts with the current implementation.
Audit finding
The tracked manifest is intentionally tied to commit dd0a157, while the local untracked wheel predates the autonomous API, runner, isolated signer, RPC verifier, and security-proof modules. The historical artifact is valid for its frozen source but cannot represent the new stack.
Depends on merging PRs #36-#40 and the final state of #34/#35.
Scope
Build wheel and source distribution from a clean final checkout.
Clean-install and run every shipped entry point.
Generate fresh deterministic proof and visual evidence from that commit.
Objective
Produce a reproducible release and evidence bundle from the final merged autonomous-security commit so reviewers do not confuse historical
v0.1.0-demoartifacts with the current implementation.Audit finding
The tracked manifest is intentionally tied to commit
dd0a157, while the local untracked wheel predates the autonomous API, runner, isolated signer, RPC verifier, and security-proof modules. The historical artifact is valid for its frozen source but cannot represent the new stack.Depends on merging PRs #36-#40 and the final state of #34/#35.
Scope
Acceptance criteria
pyproject.toml.distfile is cited as evidence.Non-goals
PyPI publication, production-readiness claims, or replacing machine-readable proof with marketing.
Keywords
release-candidatereproducible-buildclean-installevidence-manifestreviewer-brief