Ballast 0.4.1-beta · Windows · invited beta
Ballast 0.4.1-beta — installation review evidence and private provider errors
Invited beta release, September 17, 2026. Download availability is controlled by the beta channel. Existing installations update only when their user applies the patch; publication does not silently replace an installation.
Review before running
Each candidate now has a companion review-evidence ZIP and detached signature. It contains a CycloneDX dependency inventory, dated Python advisory scan, actual package-test results, member hashes, a standalone verifier and curated synthetic tests. The companion signature binds it to the exact application archive hash. An absent or failed evidence/privacy check stops packaging.
The verifier reads archives without extracting them or importing the app. It rejects invalid signatures, changed archive/member hashes, missing/extra files, case-ambiguous names, unsafe paths, symlinks and mismatched companion evidence. First-time users still need an independently trusted release key; obtaining a key from the same untrusted download does not prove the author's identity.
Read REVIEW-BEFORE-RUNNING.md for expected installation behavior and limitations, and REVIEW-EVIDENCE.md for optional reproducible checks. The Guide includes a three-minute lesson, “Review a download before opening it.” Existing lesson completion remains intact; this new lesson starts incomplete.
Provider errors and retained behavior
Strategies benchmark, wheel-eligibility and research-generation failure paths now return an opaque support reference instead of raw provider exception text. The corresponding diagnostic records contain only a fixed operation label and reference. Provider response bodies, credentials and account identifiers are not copied into these error messages or diagnostic records.
The release baseline gate now accepts a hash-verified frozen source snapshot, checking the actual published files and named regression inventory. It no longer needs to identify a dirty integrated release by an unrelated older Git commit. The earlier Git-baseline path and its checks remain supported.
The 0.4.0 historical-volatility stop policy, 48-hour default confirmed-stop cooldown, credential encryption, optional startup, update safeguards and modular course remain. This patch does not change trading semantics or migrate existing ledgers. Setup-help wording now agrees with signed, user-approved updates.
What this does not establish
Windows Authenticode publisher signing and a commissioned independent security review remain pending. Full clean-Windows/device acceptance is a separate task; synthetic tests or an isolated profile on the developer's Windows host do not replace it. A vulnerability scan is dated and scoped, not a malware guarantee.
Noncredential trade history remains plain SQLite, DPAPI cannot protect against malware acting as the same Windows user, and historical cloud copies may persist. Uncertain broker orders may block subsequent protective orders until manually reconciled. Other research, recovery and public-service findings remain open. Read SECURITY.md before considering live operation.
Download, update and recheck
At the beta page, use your existing invitation in “Review or update your download” to retrieve the versioned application, review evidence ZIP and both signed manifests without registering again. Read the review guides before executing files. Ask your reviewer to inspect the exact downloaded artifacts and report its findings; no particular AI or antivirus verdict is guaranteed.
Existing eligible installations can check System for the update, review its notes, and choose when to apply it. Program files are patched while private state is preserved. Read UPDATING.md before maintenance, including limitations for old unsigned updaters. Confirm the 0.4.1-beta title after installation and open Guide > Privacy and safe operation > Review a download before opening it.
For a separate test copy, use synthetic data and paper mode. Do not copy production credentials into it or enable logon startup. Report unexpected prompts or errors with private details removed and include the version and archive hash. A report on an earlier archive does not establish this one's behavior.