Apizr 0.4.5
GitHub and PyPI publication is verified. Core, MCP, OCI and Attest are public at 0.4.5, with exact original archive bytes and fresh installed-package proof. The Official MCP Registry entry and Homebrew installation are verified. Automatic third-party indexing is outside the release acceptance criteria.
What you can do with this release
- Inspect ordinary Python scripts and notebooks without executing them; record trusted local experiment Runs and compare their code, data, parameters, environment, metrics and outputs.
- Select a prediction capability from a successful Run and expose it through REST or MCP, with explicit authority, exact dependency evidence and preserved model resources.
- Support private helpers, independent serving functions in unfinished research repositories, structured tuple results and TypedDict inputs shared across REST and MCP.
- Improve MCP discovery with human titles, typed descriptions, output schemas, compact analysis views and actionable agent guidance. Registry installation requires explicit project, operator-policy and plugin-store configuration.
- Coordinate the core, OCI, MCP and Attest packages at 0.4.5.
Start with the Data Scientist quickstart or your first REST/MCP calls.
Upgrade
Follow Install Apizr using 0.4.5. Keep the core and selected plugin profiles at the same version. Generated services have their own runtime dependencies; installation does not activate plugins or grant operator authority.
Compatibility and limitations
Python 3.11–3.14 is qualified on Linux, and 3.11/3.14 on macOS. Existing v1 contracts and explicit authorization boundaries remain intact. Inspection never executes project code. Run executes trusted code with host access and is not a sandbox. Seeds do not prove determinism; comparisons do not establish causality. Scientific libraries remain workload dependencies rather than core requirements.
The immutable package READMEs retain their prepublication candidate/baseline wording. This repository README and the live documentation correct that stale publication status separately; no public archive or tag has been replaced.
Validation
Release and master integration source:
da74e6de5800eab9c275e42c5d4c24a59ac4fcbe (protected squash #281).
Signed annotated tag: v0.4.5. Later documentation commits are not release sources.
| Evidence | Exact run |
|---|---|
| Protected master CI | 38137540311 |
| Security | 38137540314 |
| Release-source documentation | 38137540297 |
| MCP qualification | 38137569400 |
| Protected PyPI publication | 38140159100 |
| Official MCP Registry | 38141521209 |
All protected-source gates passed. The original archives, signed build provenance, release-target exports, delivery evidence and verified signed/timestamped receipt are retained on the immutable GitHub Release. The receipt passed schema, consistency, signature, timestamp and recomputation without warnings. No artifact was rebuilt for publication.
| Qualification | Result |
|---|---|
| Full suite, each of four Linux targets | 6,851 passed, 74 expected OCI skips, zero failures |
| Full suite, each of two macOS targets | 6,850 passed, 75 skips (additional filename-platform limitation), zero failures |
| Experiment tests | 1,357 without skips on each of six targets |
| Dedicated OCI suite | 432 passed, zero skips |
| MCP suite | 324 passed, zero skips on each of six targets; both protocols |
| Client collections | 137 passed, zero skips on four Linux/macOS targets; Bruno/Postman/Insomnia source-free requests |
| Attest | 134 passed, zero skips; 92.67% coverage |
| Forge | 55 passed, zero skips; four Python action targets |
| Security mutations | 90/90 killed; baseline passed |
| Global coverage | 95.15–95.38%; experiment exposure bridge 100% lines/branches |
| Documentation | Strict build and links, anchors and canonical URLs across 105 HTML pages |
| Homebrew candidate | All 17 checks passed on hosted Apple Silicon; public tap qualification below |
Auxiliary client-collection, Attest, Forge and Homebrew candidate evidence comes
from the fully green reviewed PR tree f3684052120d8e4579695993962351a912865e27,
identical to the merged source tree. Published artifacts come only from the
protected master push. See release-qualification.json.
Security
Issue #280 is closed. All 18 original Dependabot alerts (10 high, 8 moderate) are fixed; none dismissed. The original unfiltered npm audit counted 13 affected packages (1 critical, 8 high, 4 moderate), including additional Handlebars advisories; this differs from GitHub's advisory-alert counting. The committed lock now audits at zero critical, high, moderate, low or informational vulnerabilities. Python audits across ten scopes and open CodeQL findings on the qualified source are zero.
Reviewed tooling uses Bruno 4.2.1, Postman CLI 1.73.0 and OpenCollection 0.14.0. Exact-parent compatibility overrides select axios 1.20.0, Faker 10.5.0, csv-parse 7.0.2, form-data 4.0.6, js-yaml 4.3.2, uuid 11.1.1 and yaml 2.8.3; Handlebars 4.7.10 is selected normally. Vendor functionality passed on Linux and macOS. The permanent required security job installs the exact Node lock without lifecycle scripts and blocks an unfiltered audit at moderate or above.
Public installation
Fresh PyPI-only installations outside the checkout passed core version/smoke, the notebook → inspect → Run A/B → list/show → compare → readiness → REST/MCP journey, unchanged notebook bytes, three invalid TypedDict refusals and stale model refusal. The reference journey took 33.72 seconds after preparation; inspection reached its first result in 1.12 seconds on this host, not a performance guarantee. Three plugin profiles were prepared from PyPI, installed and explicitly enabled. The actual uvx registry launcher passed both auto and legacy modes. All four package metadata records, dependencies, Requires-Python, non-yanked state, MCP ownership marker and browser-rendered READMEs were checked.
Public journey, plugins, metadata and retained installation evidence record the checks and their limits.
Original Python archives
All eight public files are byte-identical to the selected protected CI artifacts. The publisher and an independent public download comparison both passed.
| Archive | SHA-256 | PyPI |
|---|---|---|
outerspace_apizr-0.4.5-py3-none-any.whl |
1c8694c6cb6eb394097cf42610946052b3b2a7296ab0c83e0ce65473ebca77ba |
exact public bytes |
outerspace_apizr-0.4.5.tar.gz |
c4dfc1834bdcc885b87dfe0dda58743b41971ac64e58ad74caef7ea369d9b5c7 |
exact public bytes |
outerspace_apizr_oci-0.4.5-py3-none-any.whl |
7578f44bba63b9aaccfa1f7b374209459a64d2dff8c682637bbb5488ab161d88 |
exact public bytes |
outerspace_apizr_oci-0.4.5.tar.gz |
e81792028a733ad8cdc713973b654868aa481fc587dbc5eac96114730199793a |
exact public bytes |
outerspace_apizr_mcp-0.4.5-py3-none-any.whl |
06311b46195f38f75ee2f4b39d7ac49c83b9b81da4c4abcc908c8753802ee11d |
exact public bytes |
outerspace_apizr_mcp-0.4.5.tar.gz |
a55c23b782b434f8052577ae76592b33033415c1acd5356c9031bd83b730f3a2 |
exact public bytes |
outerspace_apizr_attest-0.4.5-py3-none-any.whl |
45988adf701c997b27551561a3bc7ffa98c6b2ac79bcfb93f5b1b8693cdbeea9 |
exact public bytes |
outerspace_apizr_attest-0.4.5.tar.gz |
bbf4e67f588e94ad7bfdea5ee3ac3657fc3fa0dabbaed24963dc53dde0d1836a |
exact public bytes |
MCP ecosystem observations (informational)
Observation: 2026-10-11 13:02 UTC, bound to the exact release source,
descriptor, installed discovery and reproducible MCPB digest
edeb563b7a0e19082baa83f31b498e945a51e9c2f8c962cdfdedcedb1d5540e6.
| Provider | Observed state |
|---|---|
| Official MCP Registry | Verified active io.github.Alien6-Studio/outerspace-apizr 0.4.5, package outerspace-apizr-mcp 0.4.5, stdio and exact repository; required --project, --operator-policy, --plugins-dir and descriptions match server.json |
| Glama | Public schema is stale: three old tool descriptions remain. Version is not exposed. Authenticated verification is unavailable without an existing configured integration; no 0.4.5 indexing success is claimed |
| Smithery | authentication_required; exact listing/version, configuration, public bundle and actual client installation remain unverified. The MCPB release attachment alone proves neither publication nor installation |
| MCPfinder | No matching repository in the inspected snapshot published 2026-10-11 06:03:53 UTC, before this release; propagation remains unverified |
The read-only observation workflow
retains a dated report and the
public Glama observation. Its historical
phase_b_complete: false uses the earlier, broader criterion. The maintainer
subsequently removed these automatic third-party directories from release
acceptance. Their stale or unavailable metadata does not invalidate the
verified artifacts, installations or Official Registry publication.
#279 is completed
under that clarified scope. No third-party indexing success is claimed.
Homebrew
Tap PR #3 uses the exact
immutable public core sdist and verified protected-master provenance. Its
Apple Silicon workflow
passed style, strict online audit, real Formula installation/test, runtime-provider
isolation, version, init, doctor and CI smoke. The PR is merged at
338ea5de4311ec0d3d2713c359594c2d39b03a00. Hosted VM evidence is distinct from physical-host qualification;
Intel and Linux Homebrew runtime remain unqualified.