github sponge-b0b/arid v2.0.0-beta.1

latest releases: v2.2.3, v2.2.2, v2.2.1...
pre-releaseone month ago

Arid 2.0.0-beta.1 — V2 Contract Freeze Beta

Arid 2.0.0-beta.1 marks the point where the v2 feature set and core machine contracts are considered frozen.

The detector remains intentionally unchanged: Arid still finds exact normalized Python duplicate code and reports DUP001. V2 changes the contracts and automation around that detector, not the detector itself.

This beta is for broader integration and compatibility testing before release-candidate qualification. New product features are not planned after this point. Incompatible machine-contract changes require a demonstrated defect and an explicit contract revision.

What is frozen

The beta carries forward the v2 surface introduced in alpha.1:

  • report schema v4 with schema_version, tool_version, completeness, resolved analysis metadata, and structured errors
  • stable path-independent arid-finding-v1 finding fingerprints
  • hybrid occurrence distribution while structural context/scope retain mixed
  • structured error-v1 and capabilities-v1 contracts
  • focused reporting with whole-project detection
  • --keep-going partial analysis with explicit incomplete status
  • baseline status and safe pruning
  • explicit config/project-root controls and introspection
  • virtual Python source input through --stdin-path
  • multiple report outputs from one scan
  • --no-fail-on-findings
  • the narrowed supported Rust API
  • the official GitHub Action

The schemas remain published under schemas/ and baseline schema v1 remains compatible.

Alpha stabilization results

The alpha contract was exercised against the established Black, Django, mypy, Rich, and Unicode/space-path validation campaign.

For equivalent settings, canonical duplicate groups from v2 were compared directly with qualified Arid 1.2.0 output across Black, Django, mypy, and Rich. The canonical detector results were identical on all four repositories.

Real-world v2 workflow composition was also exercised on representative source:

  • file focus while preserving whole-corpus duplicate context
  • directory focus against the corresponding whole-corpus finding subset
  • baseline enforcement before focus filtering
  • virtual-source replacement without modifying disk-backed source
  • keep-going behavior with one controlled malformed Python file while preserving findings from valid files
  • one large Django scan producing primary JSON plus supplemental JSON, Markdown, SARIF, and text reports from the same analysis

The Django multi-output campaign produced 5,558 duplicate groups consistently across the generated report formats.

No detector-semantic regression was found during alpha stabilization.

Compatibility

Ordinary CLI users who do not consume machine-readable contracts or Rust internals should still recognize Arid v2 behavior.

The exact duplicate detector, DUP001, normalization behavior, baseline schema v1, normal path invocation, worker modes, and default exit-status meanings remain compatible with v1.2.

The intentional v2 migration areas remain:

  • report schema v3 → v4
  • report version → schema_version
  • new required report metadata
  • occurrence distribution mixed → hybrid
  • stable finding fingerprints
  • SARIF finding identity
  • narrower supported Rust API

Detailed migration documentation is scheduled before release-candidate freeze.

Official GitHub Action

The official composite Action continues to install the exact Arid package version encoded in the tagged Action metadata and runs one Arid scan per invocation.

For this beta:

- uses: sponge-b0b/arid@v2.0.0-beta.1
  with:
    paths: .

The production release workflow verifies the published Action end-to-end after the exact beta package is available from PyPI.

Install the beta

With uv:

uv tool install --prerelease allow "arid==2.0.0b1"
arid --version

Or with pip:

python -m pip install --pre "arid==2.0.0b1"
arid --version

Expected version output:

arid 2.0.0-beta.1

What to test

Beta feedback should focus on defects and integration friction in the frozen surface, especially:

  • report-v4/error-v1/capabilities-v1 consumers
  • finding-fingerprint persistence in external tooling
  • focus behavior in larger repositories and monorepos
  • keep-going handling of malformed or unreadable sources
  • baseline maintenance workflows
  • explicit configuration and project-root selection
  • virtual-source integrations used by coding agents or editor tooling
  • multi-output CI pipelines
  • GitHub Action outputs, summaries, SARIF, and failure policy
  • Rust embedding code using the supported v2 API
  • platform-specific installation or packaging behavior

Detector differences from Arid 1.2 under equivalent settings remain defects and should be reported.

Next steps

After beta publication, Arid moves into performance and competitive verification, migration/documentation readiness, and full pre-RC qualification. Performance claims are intentionally not updated in these beta notes; v2 performance evidence is established separately in the next release phase.

Don't miss a new arid release

NewReleases is sending notifications on new releases.