CHANGELOG

A public record, not a victory lap.

Released evidence stays separate from experimental work. Every entry names what changed, what passed, and what remains unsettled.

RELEASE LEDGER / 004

The latest claim is the one you can verify.

The website summarizes the record. GitHub keeps the canonical Markdown, immutable tags, signatures, attestations, and downloadable bytes.

Current release
0.4.0-beta.1
Published
2026-07-30
Published crates
21
Release channel
BETA
Version

0.4.0-beta.1

Rebuild only what the evidence invalidates.

All twenty-one framework crates add verified no-op builds, causal lazy-route reuse, observable private cache controls, resumable adaptive asset work, and a clean-revision measurement contract. G4 Adoption remains explicitly open.

  • Build reuse is receipt-bound, exact-set verified, and conservative when causal declarations are absent.
  • Every official starter proves cold, no-op, content-only, asset-only, corruption rejection, and recovery paths.
  • The adaptive asset queue reports deterministic pending, ready, and invalid work without mutating staging.
  • No remote cache, competitor benchmark, low-end-device guarantee, or external adoption result is claimed.
Verify release 0.4.0-beta.1
Version

0.3.0-beta.1

One sealed build, two conformant hosts.

All twenty-one framework crates share one exact version. PBOC v1alpha1, native/OCI deployment, and the Rust Cloudflare application runtime join G1, G2, and OpenSDK at preview stability.

  • Exact bundle verification and host capability admission fail before upload.
  • Rolling and rollback checks bind application, epoch, state schema, sequence, and the exact release chain.
  • The same seven-case corpus passes a least-privilege OCI image and a real Cloudflare Worker edge.
  • Provider credentials remain outside PBOC; Node packages remain private repository tooling.
Verify release 0.3.0-beta.1
Version

0.2.0-beta.1

The package graph becomes one product.

All nineteen framework crates share one exact version. The CLI, G1 native runtime, G2 data contracts, and OpenSDK preview now move together while G3 remains explicitly unreleased.

  • G2 publishes loaders, actions, sessions, idempotency, cache policy, invalidation, and redacted diagnostics.
  • The signed five-target release preserves R0-R7 and P8 gates and adds G1/G2 conformance evidence.
  • PBOC and the Cloudflare application runtime remain G3 work rather than implied beta capabilities.
Verify release 0.2.0-beta.1
Version

0.1.0-preview.1

The native runtime becomes installable.

pliego-router, pliego-runtime, and pliego-sdk are public at 0.1.0-preview.1. G1 is complete, while the complete CLI remains 0.0.2 and that tagged release contains neither G2 nor G3.

  • Bounded HTTP/1.1 and HTTP/2 transport with connection admission, slow-peer deadlines, graceful drain, and overload behavior.
  • Complete, ordered, and async-boundary SSR with route-owned complete and streamed layouts under one output budget.
  • Structured completion events and operator-enabled OTel exclude request values and isolate operator callback panics.
  • The ASVS 5.0 ownership map, real-socket adversarial corpus, fixed-load RSS harness, CodeQL, fuzzing, Chromium, and package reconstruction passed.
  • OpenSDK build/browser/tooling is public preview; its server plane and governance decisions remain pending.
Open the component release
Version

0.0.2

Trust becomes part of the toolchain.

P8 closes the gap between a working framework and one that can be independently evaluated, installed, diagnosed, and verified.

  • 15 crates at 0.0.2, five platform targets, 28 signed release assets, SBOM, provenance, and Sigstore identity.
  • Nine-environment golden matrix including WSL2, Unicode paths, long paths, and a pinned container.
  • Doctor, deterministic support reports, upgrade checks, bounded fuzzing, reproducible benchmarks, and opt-in local telemetry.
Verify release 0.0.2
Version

0.0.1

The framework leaves the workshop.

The first public release established the Rust-native framework, authored developer experience, and accepted R0-R7 evidence baseline.

  • Native SSG, typed views and content, event folds, reactive runtime, DOM lifecycle, adapters, assets, and Hyphae boundary.
  • Signed five-target distribution, authored error pages, official starters, bilingual documentation, and external flagship evidence.
Verify release 0.0.1