Verify rigscore
Verify this tool before you run it. Every rigscore release is signed via Sigstore keyless OIDC and …
Verify this tool before you run it. Every rigscore release is signed via Sigstore keyless OIDC and …
Major security and distribution hardening. Breaking: continuous coverage scaling replaces the step …
First 1.x release. Adds scoring profiles, baseline/diff mode, richer suppress semantics, and the …
v0.9.0 includes 10 changes: 5 features and 5 fixes.
At the start of 2026, I set out to push AI-assisted development as far as it would go on a single …
v0.8.0 expands the hygiene surface into infrastructure and static-site configs, and simplifies …
v0.7.2 hardens governance validation with negation-aware CRITICAL escalation, catches prompt …
v0.6.3 adds 3 new checks (Claude settings, credential storage, unicode steganography), maps every …
v0.5.0 adds an 11th check — network exposure detection for AI services listening on all interfaces …
Most local AI tools split between two defaults: loopback-only (safe but breaks remote access) and …
v0.4.0 adds continuous monitoring via –watch, a 10th check for Windows/WSL attack surfaces, …
v0.3.0 reweights scoring so AI-specific checks carry 60% of the score. Adds SARIF output, CI mode, …
v0.2.0 adds coherence checking (do your governance claims match your config?), deep secret scanning …
Initial release. 8 checks covering MCP servers, governance files, secrets, Docker, git hooks, and …