nhi.sgit.ai / admin / versions
Release history
Every push to dev is a release: CI validates the site, verifies the version bump, tags the commit v{release}.{major}.{minor}, and deploys to GitHub Pages. The version is owned by admin/build/version.txt and must agree with the release commit's subject.
| Version | Date | What shipped |
|---|---|---|
| v0.1.19 | 19 Aug 2026 | The loop closes: static-publishing pack refreshed to commit a7fb3f5 (r10–r12). The tabletop-11 brief written in this session was adopted into the pack verbatim (plus an intake note), its §5 owed edits landed — the canonical three-line repo-side .gitignore guarding key material, the publish folder's self-ignore removed (it is what the Pages workflow deploys), decisions 13–15 (gitignore ownership, sgit vault attach as phase P9, the CLI workflow generator) — and the second executed tabletop ran the full CI story in simulated-hosting mode: keyed-backup leak proven then excluded, zero-secret public pipeline, fork PRs skipping legibly, rollback as git revert, findings F5–F7, and the canonical Pages workflow committed as templates/github-pages.yml. Two new reader pages (the brief, with its cross-session provenance; the executed run, with an explainer) and the template captured under src/. The real-GitHub run remains owed, its scope defined by the NOT MEASURABLE markers. |
| v0.1.18 | 19 Aug 2026 | Tabletop 11 brief amended after maintainer review: §5 gains the 01__architecture.md row — the architecture doc shows the publish folder's * self-ignore in three places, and needs the two-gitignores distinction cross-referenced (the self-ignore guards derived output; the repo-side set guards key material — two files, two threats). |
| v0.1.17 | 19 Aug 2026 | Tabletop 11 brief published: publishing pipelines (DevOps/CI) — the scenario brief for the next executed tabletop, drafted in this working session and captured under briefs/ for the SGit-AI__CLI architect agent (comms T24). It corrects a conflation between the two ignore systems (git commits everything under .sg_vault/ except local/; sgit's own ignore keeps all of it out of vault content), pre-registers a finding from code inspection — .sg_vault/backups/ is a key-leak hazard in the one-repo pattern, so the canonical .gitignore must cover local/ + backups/ + .sg_vault_new/ — and lists the updates the existing pack files owe (§5), including three candidate decisions: repo-side .gitignore ownership, the attach-read-key command, and the workflow generator. |
| v0.1.16 | 19 Aug 2026 | PKI refactored out to pki.sgit.ai. The spin-out site is live (v0.1.2), so this site's PKI section is now a bridge page: the NHI framing (per-agent keys fill the shared-drives research's three empty rows) plus a link map to pki.sgit.ai's failure, rules, mandate and roadmap pages. The old in-depth pages (keyserver-failure.html, registry-rules.html) forward to their pki.sgit.ai versions so no inbound link breaks — URLs are commitments, per the registry rules themselves. Deep links across the site (collection, document pages, pack pages, thesis, front page) now point at pki.sgit.ai directly; the scoping brief's document page and raw markdown stay here as corpus capture. Comms T18 transferred to pki.sgit.ai's comms; T19 closed. |
| v0.1.15 | 19 Aug 2026 | Static-publishing pack refreshed to commit a1d5ce6 — r9: publish copies no ciphertext. The output is the plaintext surface only (loader, cover, manifest, key file — measured ~5 KB for a 22-object store); the manifest enumerates the store, and the served root is composed at deployment: co-located (serve the repo itself, zero copies — exactly the shape the tabletop's mode B verified) or assembled by a keyless copy. Decision 12 of 12; invariant I1 becomes true by construction. The tabletop page now notes the spec change while keeping its historical record — the exercise changed the spec it tested. Doc 07, architecture, decisions and changelog pages updated to match. |
| v0.1.14 | 19 Aug 2026 | nhi.sgit.ai is live. The custom domain now serves the site with HTTPS, and the github.io URL 301-redirects to it — verified while checking the v0.1.13 deploy. Comms N3 updated: (b) done; the one remaining Pages setting is (a), allowing dev in the github-pages environment so releases publish without the manual push to main. |
| v0.1.13 | 19 Aug 2026 | Static-publishing pack refreshed to commit a3b4ccf: the r8 consistency pass, and the pack's new change-control log captured with its own reader page — r0–r8, newest first, every revision with its trigger (almost always a one-line maintainer question), what changed, and which numbered decisions moved. Notable in r8: plaintext expansion becomes a future sgit vault expand command (decision 11 of 11), manifest entries gain per-object sha256 (closing the tabletop's 12-of-18 keyless-verification gap), and the visibility-downgrade warning lands. The pack now practices the same release discipline as this site's versions page. |
| v0.1.12 | 19 Aug 2026 | Static-publishing pack refreshed to commit 2cedd9a, capturing the pack's most unusual document: an executed tabletop exercise — the maintainer's one-repo-carrying-everything scenario run for real by the dev agent with the shipped CLI (only the unbuilt publish command and GitHub's hosting simulated, marked at every appearance), producing four live findings and measured results (publish → push is a no-op; git dedupes all 17 projection copies; zero-secret CI republish from the committed read key). The document's reader page opens with an explainer for site readers on what a tabletop exercise is and why an agent executing one inside its own codebase is an uncommon use of LLMs. Also in this revision: sgit publish takes no target (one fixed folder; deployment is a separate act — doc 07 rewritten), and the loader is now cleanly separated from a vault's own index.html. |
| v0.1.11 | 19 Aug 2026 | Pack provenance made verifiable: every pack page (hub and per-document) now states the source-repo commit it was captured at, linked, with the guarantee that the raw files under src/ are byte-identical to that commit's tree — the raws stay verbatim precisely so the claim is checkable by diff. The static-publishing pack refreshed to its 18–19 Aug revision (commit 65ebfbd): three new documents from maintainer review — where a published folder may live (the publish-into-work-tree amplification loop; refusals before a byte is written), published API docs (openapi.json generated from the manifest; Swagger UI CDN-pinned with SRI, measured at 2.7× the vault it documents), and the first-party asset origin (publish-time source yes, read-time origin never) — plus the sixth rule/invariant (publishing never changes the vault), phase P4b, and ten maintainer decisions (up from six). |
| v0.1.10 | 18 Aug 2026 | Second dev pack captured: hub.sgit.ai — The Fractal Forge (18 Aug design pack, 9 documents from the SGit-AI__CLI architect-review branch) — the forge whose application layer is the browser, the hub-is-a-vault fractal, the capability audit with its two findings (the sub-vault primitive assumed by every brief does not exist; the structure key is a shipped-but-unused third access tier), permissions as key topology, commercialisation on a blind host, mockups including the live ciphertext panel, and the roadmap with the four stated absences. Sources verbatim under packs/hub-sgit-ai/src/; reader page per document. The pack generator now takes per-pack dates, origins and GitHub sources. |
| v0.1.9 | 18 Aug 2026 | New Packs section for dev brief packs, first pack captured: Static Publishing, sgit vault serve and the publishing matrix — 8 documents from the SGit-AI__CLI architect-review branch, sources verbatim under packs/static-publishing/src/, a hub with the file table and pack README, and a reader page per document (summary, key concepts, key ideas, full markdown). The in-page markdown reader now renders mermaid fences as diagrams, so the pack's sequence diagrams display natively. Packs added to the nav; section generator gen_packs.py. |
| v0.1.8 | 18 Aug 2026 | The eight corpus briefs the collection referenced on GitHub are now captured verbatim in briefs/, each with a full document page (summary, key concepts, key ideas, in-page reader, infographic slot): the hope-driven authorization brief, the catastrophic-risk board thesis, both pull-the-plug briefs, the AOMM source, the sandbox-escape incident analysis, the ambient-authority brief, and the serialised-pull-request brief. Every GitHub blob link on the collection, Hope and AOMM pages now points at the local document page instead; only the wider-corpus pointer still goes to GitHub. |
| v0.1.7 | 18 Aug 2026 | Document links routed through the reader pages: every reader-facing reference to a captured markdown document now points at its documents/ page (summary + in-page reader) instead of the raw file — raw-markdown links remain only inside the document pages themselves, as the source-of-truth reference. The reader restyled as a distinct document sheet: white paper on the cream page, bordered, with an attached label bar naming the source file. |
| v0.1.6 | 18 Aug 2026 | Two new sections. Industry: the market map grouped by which layer each product answers (discovery & governance, workload IAM, secrets & detection, machine identity, platform IdPs), 14 provider profile pages compiled from published analyses, and a SPIFFE concept page with issuance/usage/federation diagrams — concept mentions across the site now link into it. Documents: the original briefs readable in-page — each page carries a summary, key concepts, key ideas, an infographic slot, and the full markdown rendered from the raw file, which stays the source of truth. Both sections are generator-driven (admin/build/gen_industry.py, gen_documents.py). The NHI site brief captured into briefs/. |
| v0.1.5 | 18 Aug 2026 | PKI section, in preparation for pki.sgit.ai: captured the pki.sgit.ai strategy brief (v0.33.59, 16 Aug) verbatim in briefs/; built the hub, the 2019 keyserver-failure page (the three abused properties, the never-delete design goal, what the replacement gave up), and the four registry rules published before the registry exists (owner-only writes, revocation as signed append, size-bounded records, every entry signed; identity vs. mandate). PKI added to the nav; cross-linked from thesis, shared-drives research and the collection. |
| v0.1.4 | 18 Aug 2026 | Captured the shared-drives research brief (v0.33.59, 16 Aug) — source markdown verbatim in briefs/, full presentation page at research/shared-drives.html — and propagated its findings: the thesis page gains its first tested concrete instance; the Hope section gains granularity-by-segregation and attribution-from-content; method and options gain the multi-scenario framing; the collection gains a "can two agents share a working area?" question; comms gains the follow-up tests (one-account-per-agent, audit-trail behaviour) and the monthly re-verification entry. |
| v0.1.3 | 18 Aug 2026 | Comms updated: the site went live at sgit-ai.github.io/SGit-AI__Website__NHI via the one-off v0.1.2 deploy from main; N3 now records what remains (allow dev in the github-pages environment; custom domain + DNS for nhi.sgit.ai). |
| v0.1.2 | 18 Aug 2026 | Deploy from main: pushes to main now run validate → deploy with tagging skipped, so main serves as a deploy-only test/fallback while the github-pages environment still restricts dev. Tagging remains exclusive to dev. One-off test push of this release to main, requested by the project lead. |
| v0.1.1 | 18 Aug 2026 | Release-pipeline shakedown: fixed the first-release edge case in the auto-tag job (empty previous-tag list under pipefail), un-ignored admin/build/ from the stock Python .gitignore, and documented on the comms page the one remaining blocker for going live — the github-pages environment must allow deploys from dev (repo settings, admin-side). |
| v0.1.0 | 18 Aug 2026 | First MVP. The thesis page (two populations), the method (scenario + columns, published before findings), three preliminary option assessments (SPIFFE, commercial broker, do-nothing baseline), the Hope section (concepts and workflows), the collection organised by question, the AOMM promoted to a page, the participant disclosure, the infographics request list, this comms channel, and the CI pipeline with auto-tagging adapted from SGit-AI__Website. |