Skip to content

1.1.2 evidence bundle

Use this page to establish what was published, how it was built, what was verified, and which responsibilities remain with the adopting organization.

Release identity

Evidence Source
Hedron package and files Published 1.1.2 on PyPI
Edron package and files Published 1.1.2 on PyPI
Source tag, wheels, checksums, and attached evidence Published from immutable release-20260925-01 tag
Main merge CI Run 36183189826
Coordinated publication Run 36184225081
Current install and support facts Current release

The GitHub release attaches release-manifest.json, built distributions, generated evidence, and supply-chain artifacts. GitHub Actions records build provenance for the uploaded subjects. Verify hashes against the release manifest before promoting artifacts into an internal index.

Engineering evidence

Question Evidence
What is compatibility-protected? Stability classifications
What combinations are tested? Compatibility matrix
Which capabilities are Supported? Readiness evidence
What passed the 1.0 gate? 1.0 acceptance packet
What are the architecture and trust boundaries? Architecture · Threat model
How are vulnerabilities handled? Security policy
What must the application/platform own? Enterprise diligence

Procurement caveats

Hedron and Edron are MIT-licensed community projects. There is no commercial SLA, managed hosting, identity provider, database, durable queue, or compliance certification. SBOM, provenance, checksums, and automated test evidence support an organization's own diligence; they do not replace dependency review, threat modeling, access control, backup, incident response, or legal review.

Reproduce the documentation checks

uv sync --group docs
bash scripts/ci_checks.sh docs
uv run python scripts/check_100.py --gate ENTRY-100 --verify

The release workflow also installs the published artifact into a clean environment and imports the generated scaffold before creating the GitHub release.