Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
18 changes: 18 additions & 0 deletions .editorconfig
Original file line number Diff line number Diff line change
@@ -0,0 +1,18 @@
root = true

[*]
charset = utf-8
end_of_line = lf
insert_final_newline = true
trim_trailing_whitespace = true

[*.py]
indent_style = space
indent_size = 4

[*.{yml,yaml,json,toml,md}]
indent_style = space
indent_size = 2

[Makefile]
indent_style = tab
7 changes: 7 additions & 0 deletions .gitattributes
Original file line number Diff line number Diff line change
@@ -0,0 +1,7 @@
* text=auto eol=lf
*.png binary
*.jpg binary
*.jpeg binary
*.gif binary
*.whl binary
*.gz binary
54 changes: 54 additions & 0 deletions .github/ISSUE_TEMPLATE/bug_report.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,54 @@
name: Bug report
description: Report a reproducible Datary defect using synthetic or non-sensitive data.
title: "bug: "
labels: ["bug"]
body:
- type: markdown
attributes:
value: |
Thanks for helping me make Datary more dependable. Please do not attach confidential recordings.
- type: input
id: version
attributes:
label: Datary version
placeholder: datary 0.2.0
validations:
required: true
- type: dropdown
id: platform
attributes:
label: Platform
options:
- Windows
- macOS
- Linux
- Other
validations:
required: true
- type: textarea
id: reproducer
attributes:
label: Minimal reproducer
description: Include commands and synthetic input.
render: shell
validations:
required: true
- type: textarea
id: expected
attributes:
label: Expected behaviour
validations:
required: true
- type: textarea
id: actual
attributes:
label: Actual behaviour
validations:
required: true
- type: checkboxes
id: privacy
attributes:
label: Data safety
options:
- label: I removed secrets and personal data from this report.
required: true
5 changes: 5 additions & 0 deletions .github/ISSUE_TEMPLATE/config.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
blank_issues_enabled: false
contact_links:
- name: Security vulnerability
url: https://github.com/devkyato/datary-lab/security/policy
about: Please follow the private reporting guidance instead of opening a public issue.
30 changes: 30 additions & 0 deletions .github/ISSUE_TEMPLATE/feature_request.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,30 @@
name: Feature request
description: Propose a focused local-first Datary improvement.
title: "feature: "
labels: ["enhancement"]
body:
- type: textarea
id: problem
attributes:
label: Problem
description: What experiment workflow is difficult today?
validations:
required: true
- type: textarea
id: proposal
attributes:
label: Proposed behaviour
validations:
required: true
- type: textarea
id: evidence
attributes:
label: Reproducibility and safety considerations
description: Mention formats, assumptions, compatibility, privacy, and failure behaviour.
- type: checkboxes
id: boundaries
attributes:
label: Project boundaries
options:
- label: This can remain local-first and does not require telemetry or a hosted service.
required: true
20 changes: 20 additions & 0 deletions .github/PULL_REQUEST_TEMPLATE.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,20 @@
## What changed

<!-- Explain the behaviour and why it belongs in Datary. -->

## Evidence

<!-- Include deterministic tests, commands, or generated reports. -->

## Assumptions and compatibility

<!-- Note metric definitions, session-format effects, privacy, and security boundaries. -->

## Checklist

- [ ] `python -m pytest`
- [ ] `python -m ruff check .`
- [ ] `python -m ruff format --check .`
- [ ] `python -m mypy`
- [ ] Documentation and changelog updated when behaviour changed
- [ ] No secrets, telemetry, background networking, or data execution added
10 changes: 10 additions & 0 deletions .github/dependabot.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,10 @@
version: 2
updates:
- package-ecosystem: github-actions
directory: /
schedule:
interval: weekly
- package-ecosystem: pip
directory: /
schedule:
interval: weekly
15 changes: 15 additions & 0 deletions .github/release.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,15 @@
changelog:
categories:
- title: Security and correctness
labels:
- security
- bug
- title: New work
labels:
- enhancement
- title: Documentation
labels:
- documentation
- title: Other changes
labels:
- "*"
79 changes: 65 additions & 14 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
@@ -1,40 +1,91 @@
name: CI

on:
push:
pull_request:

permissions:
contents: read

concurrency:
group: ci-${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: true

jobs:
test:
name: Python ${{ matrix.python }} / Ubuntu
timeout-minutes: 20
strategy:
fail-fast: false
matrix:
python: ["3.9", "3.10", "3.11", "3.12", "3.13", "3.14"]
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- uses: actions/setup-python@v5
with: {python-version: "${{ matrix.python }}"}
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
- uses: actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # v5.6.0
with:
python-version: ${{ matrix.python }}
cache: pip
- run: python -m pip install --upgrade pip
- run: python -m pip install -e ".[dev]"
- run: pytest
- run: ruff check .
- run: mypy
- run: python -m pip check
- run: python -m pytest
- run: python -m ruff check .
- run: python -m ruff format --check .
- run: python -m mypy
- run: python scripts/verify_reproducible.py
- run: datary generate noisy-sensor --seed 1 > sample.jsonl
- run: datary generate noisy-sensor --seed 1 --output sample.jsonl
- run: datary record demo --format jsonl --time-field timestamp < sample.jsonl
- run: datary inspect demo
- run: datary inspect demo --quality
- run: datary inspect demo --plot value
- run: datary report demo
- run: datary replay demo --no-timing > replay.jsonl
- run: python -m build
- uses: actions/upload-artifact@v4
with: {name: "dist-${{ matrix.python }}", path: dist/*}
- run: python scripts/build_checksums.py
- uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2
with:
name: dist-${{ matrix.python }}
path: |
dist/*
demo/reports/*
demo/plots/*

platform-smoke:
name: Python ${{ matrix.python }} / ${{ matrix.os }}
timeout-minutes: 15
strategy:
fail-fast: false
matrix:
os: [windows-latest, macos-latest]
python: ["3.9", "3.14"]
runs-on: ${{ matrix.os }}
steps:
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
- uses: actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # v5.6.0
with:
python-version: ${{ matrix.python }}
cache: pip
- run: python -m pip install -e ".[dev]"
- run: python -m pytest
- run: datary --version
- run: datary generate sine --seed 1 --duration 1 --output sample.jsonl
- run: datary inspect sample.jsonl --format jsonl --time-field timestamp

wheel-smoke:
name: Clean wheel installation
needs: test
timeout-minutes: 15
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- uses: actions/setup-python@v5
with: {python-version: "3.12"}
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
- uses: actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # v5.6.0
with:
python-version: "3.12"
- run: python -m pip install build
- run: python -m build
- run: python -m venv /tmp/datary-smoke
- run: /tmp/datary-smoke/bin/pip install dist/*.whl
- run: /tmp/datary-smoke/bin/pip check
- run: /tmp/datary-smoke/bin/datary --version

- run: /tmp/datary-smoke/bin/datary generate sine --duration 1 --output /tmp/sine.jsonl
- run: /tmp/datary-smoke/bin/datary inspect /tmp/sine.jsonl --format jsonl --time-field timestamp
26 changes: 25 additions & 1 deletion CHANGELOG.md
Original file line number Diff line number Diff line change
@@ -1,5 +1,29 @@
# Changelog

## 0.2.0 - 2026-07-29

I treated this release as a corrective audit rather than a feature polish. A hard external review
showed that several green tests were confirming the old implementation instead of independently
checking its scientific and security claims.

- Preserved observation order for change metrics and added ordered counterexamples.
- Replaced whole-session recorder and inspector lists with exact disk-backed analysis.
- Made overwrite publication recoverable so a failed replacement keeps the prior session.
- Closed plot traversal and session symlink gaps; hardened manifests, record readers, terminal
output, Markdown, CSV formulas, and generated-file publication.
- Added incremental JSON-array parsing, RFC-style multiline CSV, BOM handling, duplicate-key
rejection, conservative scalar coercion, and non-finite-value evidence.
- Expanded integrity to rejected records, notes, structural counts, and the manifest itself while
documenting that checksums are not authentication.
- Corrected frozen-value positions, same-length schema detection, zero-MAD outliers/spikes, and
global duplicate timestamps.
- Added numeric and timezone-aware ISO 8601 timing, explicit engineering field roles, trapezoidal
control integrals, network throughput, unit-aware comparisons, shared time ranges, and honest
non-resampling warnings.
- Expanded Markdown reports, generator option semantics, Python 3.9 strict typing, adversarial
regression coverage, and Windows/macOS CI smoke tests.
- Introduced session format 2 while retaining format 1 reading compatibility.

## 0.1.3 - 2026-07-29

- Rewrote the project story and workflow in a clearer, more personal voice.
Expand All @@ -21,5 +45,5 @@

## 0.1.0 - 2026-07-29

- Initial release-ready alpha with recording, inspection, comparison, replay, reports, conversion,
- Initial alpha with recording, inspection, comparison, replay, reports, conversion,
deterministic generators, headless plots, integrity verification, and typed Python API.
20 changes: 12 additions & 8 deletions CONTRIBUTING.md
Original file line number Diff line number Diff line change
Expand Up @@ -3,17 +3,21 @@
I built Datary around a small promise: input remains inert, evidence stays local, and every result
should be explainable. If you contribute, please help me keep that promise.

Use Python 3.9 or newer, install `.[dev]`, and run:
Use a supported Python version and install the development extras:

```bash
pytest
ruff check .
mypy
python -m pip install -e ".[dev]"
python -m pytest
python -m ruff check .
python -m ruff format --check .
python -m mypy
python -m build
```

Add deterministic tests for behavioural changes. If a quality rule needs a threshold, explain the
assumption and show the evidence behind its finding.
Behavioural changes need deterministic tests. Mathematical changes need a definition, an ordered
counterexample where relevant, and a statement of assumptions. Security changes need a regression
test for the boundary: traversal, symlink, failed publication, malicious manifest, control
sequence, or formula-like export data.

Please do not add telemetry, background network dependencies, data execution, or
backwards-incompatible session changes without an explicit design discussion and documentation.
Please do not add telemetry, background networking, data execution, or an always-on database.
Discuss session-format changes explicitly and keep older readers in mind.
Loading
Loading