Download Latest Version BUS Core v1.4.2 source code.zip (1.9 MB)
Email in envelope

Get an email when there's a new version of BUS Core

Home / v1.4.2
Name Modified Size InfoDownloads / Week
Parent folder
BUS-Core-1.4.2.zip 2026-08-26 34.1 MB
BUS Core v1.4.2 source code.tar.gz 2026-08-26 1.6 MB
BUS Core v1.4.2 source code.zip 2026-08-26 1.9 MB
README.md 2026-08-26 2.4 kB
Totals: 4 Items   37.7 MB 0

BUS Core v1.4.2 Release Notes

BUS Core 1.4.2 is a security, release-governance, and analytics-operability maintenance release. It does not add a product domain or expand the data BUS Core sends.

Security and release confidence

  • Replaces unsafe HTML interpolation on reviewed UI paths with text-safe DOM construction and adds hostile-payload regression coverage.
  • Makes configured runtime roots authoritative for capability, secret, settings, database, and configuration state.
  • Adds reviewed hash-locked Windows/Linux runtime, test, and fuzz dependency graphs with blocking CI audits.
  • Pins the container base image and GitHub Actions, narrows publishing permissions, and restores active Linux/Windows CI.
  • Runs the governed Windows release gate in a clean Python 3.11 environment before its isolated smoke and build stages.
  • Fails closed on invalid release inputs while preserving the owner-controlled signing, tag, publication, and deployment boundary.

Analytics and operator clarity

  • Adds root agent governance and a canonical, side-effect-aware operations runbook for BUS Core, Lighthouse, and Agent Smith diagnosis.
  • Separates update-route evidence from product-event evidence and records exact acknowledgement, retry, local-state, and delivery-proof semantics.
  • Reconciles current update-check, manual signed staging, next-start handoff, auth, write-gate, AppData, release-mirror, and build-side-effect documentation with implemented reality.
  • Records unresolved analytics, privacy, generated-compliance, and code-comment drift in the changelog so deferred work remains visible and does not masquerade as shipped behavior.

Known limits

This release does not resolve the telemetry signal-authority conflict, hardcoded non-authoritative UI/report status, silent first-run preference-save failure, packaged privacy/test drift, generated tgc-ops compliance projection, or the separately documented future update/restart/Docker decisions. The authoritative remaining-work list is in CHANGELOG.md under 1.4.2.

Release control

The owner selected public version 1.4.2 and reset the internal revision to 1.4.2.0. This preparation does not build or sign an artifact, create a commit or tag, publish a GitHub release or manifest, deploy, or alter another repository. Build and sign only from the exact validated release commit after it reaches the required default/release branch.

Source: README.md, updated 2026-08-26