• v2.6.7-dev d0a282c22a

    v2.6.7-dev Pre-release

    FTMahringer released this 2026-05-19 02:03:15 +02:00 | 6 commits to main since this release

    v2.6.7-dev

    Plugin Signing Governance

    Added

    • Manifest signature support with embedded signature metadata and canonical payload verification.
    • PluginSigningService to sign and verify plugin manifests locally with keypairs.
    • Trust badges for verified official, verified community, unverified, and tampered plugins.
    • plugin_contract_sign and signature-aware plugin_contract_validate native tools.

    Changed

    • Plugin install and store ingest paths now verify signatures before accepting a manifest.
    • Plugin trust metadata now records signature state alongside source trust.

    Fixed

    • Tampered manifests are blocked with a hard failure instead of falling back to a confirmation prompt.
    Downloads