github sponge-b0b/arid v2.0.0-rc.1

latest releases: v2.2.3, v2.2.2, v2.2.1...
pre-releaseone month ago

Arid 2.0.0-rc.1 — Release Candidate

Arid 2.0.0-rc.1 is the release candidate for the stable 2.0.0 line.

The v2 feature set and core machine contracts have been frozen since beta. This RC is for final qualification of published artifacts, documentation, migration guidance, schemas, the official GitHub Action, and the complete release system.

No new product features are planned for the RC line. Any post-RC source change must be limited to a demonstrated qualification failure, regression, packaging defect, adoption-critical documentation defect, or release-process defect and must rerun the affected qualification gates.

What is in v2

Arid 2.0 keeps the same exact normalized Python duplicate detector and DUP001 behavior while adding stronger contracts and automation around it:

  • report schema v4 with schema_version, tool_version, completeness, resolved analysis metadata, and structured errors
  • stable path-independent arid-finding-v1 fingerprints
  • hybrid occurrence distribution while structural context/scope retain mixed
  • structured error-v1 and capabilities-v1 contracts
  • focused reporting with whole-project detection
  • --keep-going partial analysis with explicit incomplete status
  • baseline status and safe pruning
  • explicit config/project-root controls and introspection
  • virtual Python source input through --stdin-path
  • multiple report outputs from one scan
  • --no-fail-on-findings
  • a deliberately narrow supported Rust application API
  • the official GitHub Action

Baseline schema v1 remains unchanged and existing v1.2 baseline files remain compatible.

Migration readiness

The complete v2 migration guide is available at:

docs/arid-v2-migration-guide.md

Ordinary CLI users who do not consume machine-readable contracts or Rust internals may require no migration work.

The intentional breaking areas are:

  • report schema v3 → v4
  • report version → schema_version
  • new required report metadata
  • required finding fingerprint
  • occurrence distribution mixed → hybrid
  • SARIF Arid finding identity
  • narrowed supported Rust API

Structural context and scope continue to use mixed when appropriate.

Validation status

The v2 detector has been compared directly against qualified Arid 1.2.0 on Black, Django, mypy, and Rich for equivalent settings with no detector-semantic regression found.

The broader real-world campaign also exercised:

  • Unicode and space paths
  • file and directory focus
  • focus after baseline enforcement
  • virtual-source replacement without disk mutation
  • keep-going with a controlled malformed source
  • one large Django scan producing JSON, Markdown, SARIF, and text from the same analysis
  • worker determinism
  • published official Action execution

Performance status

The v2 performance campaign uses the same canonical pinned corpora and repeated Hyperfine methodology as the qualified Arid 1.2 campaign.

Against current stable Pylint 4.0.6, serial Arid v2 measured:

Requests:  191.19x faster
Pydantic:  219.06x faster
Polaris:   249.68x faster

The qualifying Pydantic and Polaris corpora remain far above Arid's required 10x floor.

A paired reversed-order Arid 1.2.0 vs v2 investigation found only low-single-digit serial overhead across the canonical corpora, with no unacceptable regression and no evidence justifying speculative optimization.

Detailed methodology and results are recorded in:

docs/arid-v2-performance-report.md

Official GitHub Action

The RC includes the official composite Action and the production release workflow verifies it against the exact published RC package.

For this release candidate:

- uses: sponge-b0b/arid@v2.0.0-rc.1
  with:
    paths: .

The Action runs one Arid scan, can expose core metrics as outputs, supports job summaries, and can produce SARIF when configured.

Install the RC

With uv:

uv tool install --prerelease allow "arid==2.0.0rc1"
arid --version

Or with pip:

python -m pip install --pre "arid==2.0.0rc1"
arid --version

Expected version output:

arid 2.0.0-rc.1

What remains before stable

The RC must receive a complete published-artifact qualification PASS covering:

  • production release workflow success
  • all supported platform artifacts
  • exact PyPI prerelease installation
  • standalone smoke testing
  • Linux ARM64 native verification
  • report-v4, error-v1, and capabilities-v1 schema validation
  • finding fingerprint validation
  • baseline-v1 compatibility
  • focus, keep-going, multi-output, virtual stdin, baseline maintenance, and project/config/introspection behavior
  • official published GitHub Action verification
  • real-world validation
  • benchmark qualification
  • migration guide and release-note presence

After the latest RC passes completely, promotion to 2.0.0 is metadata-only. Product source, schemas, migration guidance, validation logic, Action implementation logic, and stable release-note content are not changed during stable promotion.

Don't miss a new arid release

NewReleases is sending notifications on new releases.