Skip to content

Apizr 0.4.1

Apizr 0.4.1 adds explicit application inputs and verifiable, resumable OCI delivery to the Python → REST/MCP workflow.

Delivered functionality since 0.4.0rc1

  • Application dependencies and resources: explicit dependency pins and selected regular files in apizr.toml, carried into REST/MCP bundles and OCI builds with verified wheel closures, safe relative paths and content digests.
  • Source-independent services: generated REST and business MCP services run from packaged application inputs after removal of the original source and bundle, without mounting the source repository.
  • Delivery identities: a DeliveryPlan and DeliveryManifest bind source provenance, selected capabilities, application inputs, bundle, dependencies, platform and the actual image. Identity is destination-neutral.
  • Mandatory proof and admission: a plan can require signed, timestamped proof. Image transfer withholds the final tag until independent verification and explicit admission.
  • Multiple destinations and resume: one immutable build, one to eight explicit OCI destinations, independent authorization and outcomes, and evidence-based recovery after partial delivery without rebuilding or unnecessarily re-uploading/re-signing completed work.
  • Provider-neutral OCI delivery: capability-based registry contracts, using explicit credentials, immutable image identities and per-repository proofs.

The beginner journey remains Python code → discover/select capabilities → expose as REST/MCP → optionally deliver as OCI. Start with installation and the Quickstart; delivery is optional.

Compatibility and limitations

Python 3.11–3.14 remains supported. The coordinated distributions are outerspace-apizr==0.4.1, outerspace-apizr-oci==0.4.1, outerspace-apizr-mcp==0.4.1 and outerspace-apizr-attest==0.4.1. Python import names, the minimal Pydantic-only core and isolated plugin installation remain unchanged. Installation, activation and operator grants are separate. Existing single-source, notebook and historical YAML workflows remain.

Application inputs use explicit bounded pins and regular files; there is no inferred dependency capture or directory snapshot. Existing optional-proof plans and historical v1 proofs remain supported. The OCI proof profile covers one SHA-256 image, same-repository proof and OCI 1.1 referrers. Live-provider qualification is optional interoperability validation, not a remaining functional blocker or a claim of universal registry compatibility.

Destinations execute sequentially. Resume needs retained evidence and explicit artifact selection for uncertain remote state. It is not a distributed transaction or rollback mechanism; admission does not permanently lock a mutable tag. Plugins and generated services run explicitly trusted code.

Explicit deferrals

0.4.2 remains future work: delivery operations through the analysis MCP server, Postman/Bruno/Insomnia, user-facing GitHub/GitLab integrations, initialization, diagnostics, completion and the Homebrew tap. Official distribution images and additional registry integrations are not delivered in 0.4.1. The subsequent release/0.4.2 development line does not add those capabilities to this release.

Publication status

0.4.1 is published and verified. The final release was published on 29 September 2026 for the core and all three optional plugins: core, OCI, MCP and Attest.

  • Immutable v0.4.1 release, source d08b37d126957593a82784ef3ad096e3f8b4929d on release/0.4.1.
  • Qualification #203: QUALIFIED — v0.4.1, using the original archives from CI 36601712772. Security and Documentation passed on that exact source.
  • Publication #204: PUBLISHED AND VERIFIED — v0.4.1. Publisher 36608326995 passed, including signed/timestamped receipt verification and comparison of all eight public package archives with the qualified bytes. No archive was rebuilt.
  • Six installation targets passed across Linux x86_64 / Python 3.11–3.14 and macOS arm64 / Python 3.11 and 3.14. Fresh public installation preserved the minimal core and isolated plugins; activation, imports, REST/MCP and the migration/operator-policy path passed.
  • Source-independent services, proof/admission and multi-destination recovery passed. OCI isolation passed 398 tests and 10 repetitions without skips; all 29 security mutations were killed.

The release was integrated into master by PR #206, commit e49d5f686bc9b2c9610c7849e246594feb48c3d4. That integration has a separate identity; its verification builds do not replace the published release archives.

RC1 qualification history

The immutable v0.4.1rc1 prerelease was published and verified on 29 September 2026:

RC2 NOT REQUIRED: finalization changed coordinated versions and documentation without changing runtime behavior. Final 0.4.1 artifacts were independently qualified and publicly verified as recorded above. RC1 remains immutable historical evidence with its own source, tag, notes and assets.