# Changelog All notable changes to this project will be documented in this file. The format is based on [Keep a Changelog](https://keepachangelog.com/en/1.1.0/), and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0.html). Versioning note: the repository tag versions **the contract** (file set, key names, case ids, disposition semantics). Each JSON file additionally carries its own `"version"` field, bumped when that file changes. ## [Unreleased] ### Retracted - **The claim that the Python guard's port cites `severity.mjs` for hybrid severity.** It is false. It was carried in three places — `lexicon/injection-lexicon.json` (`families[hybrid].severity_provenance.not_from`), `docs/lexicon-port-divergence.md` (§ *Severity: the 8 hybrid patterns*), and the `[0.1.0]` entry below — and it was never measured here. It restated an assertion received from `llm-security` (coord message `20260809T201048Z`) as a commons finding. Measured against the guard's own tree, which `llm-ingestion-pipeline-security` asked for twice before this was checked: `severity.mjs` has **never** appeared in `src/llm_ingestion_guard/injection_lexicon.json` at any point in that file's history (`git log -S` returns no commits), and at `0bf0729` — the commit `conformance/manifest.json` pins — the only tree-wide occurrence is `docs/PLAN.md:114`, correctly attributing the *report* module to `output.mjs` + `severity.mjs`. The guard's only source statement for the lexicon is the `note` at `injection_lexicon.json:3`, and it names `injection-patterns.mjs`. **No detection data moves.** `families[hybrid].severity` is still `high`, still sourced to `injection-patterns.mjs:274-281`, re-verified at `b0de0ca`; `severity.mjs` still contains zero occurrences of `CRITICAL_PATTERNS`, `HIGH_PATTERNS`, `MEDIUM_PATTERNS` and `HYBRID_PATTERNS`, re-measured the same day. Only the sentence about the *other* repository falls. The retraction is marked in place rather than edited away, and it is worth naming why this one survived review: the claim arrived bundled with a correct measurement of the same question, from a repository that had done its half properly. The correct half carried the incorrect half past the check — which is precisely the defect `severity_provenance.not_from` was written to warn about, one level up. ### Changed - `lexicon/injection-lexicon.json` **0.5.0 → 0.5.1** — provenance metadata only; no pattern, id, alias, family or severity value changes. ## [0.1.0] — 2026-08-10 Initial extraction. Runtime-neutral detection data, the finding contract, and a conformance corpus, extracted from the `llm-security` Node implementation and a Python guard **without behaviour change** — that invariant is the release, not a caveat on it. What the tag is worth resting on: seven of the eight JSON artefacts were rebuilt from the commons file alone and diffed against their source implementation, three of them against the source module at a pinned commit. The eighth says `verified: false` about itself. The corpus holds 83 cases on which both seeding runtimes were measured agreeing exactly. What it is not: `spec/decode-pipeline.md` does not exist, and the corpus constrains one of the seven data files. Both absences are named in *Not included* rather than papered over. ### Added - `conformance/` — **83 cases, one per injection-lexicon pattern**, plus `manifest.json`. Each case is a directory holding `input.txt` (the exact bytes, no trailing newline) and `expected.json` (the findings, named by commons pattern `id`). Both seeding runtimes were measured producing the **same lexicon finding set on all 83**, through their public entry points — `scanForInjection()` at `b0de0ca` and `scan_output(source=OUTPUT)` at `0bf0729` — with labels mapped to commons ids through the lexicon's own `aliases` block. Not through rebuilt regex tables: a table-level comparison yields a number that describes neither runtime, which is the mistake the divergence document had to retract. **The 13 divergent patterns are in, unmarked, and that is the substantive result.** Their divergence was measured on witness inputs — an attribute run padded past 256 characters, an interior `<`, an unclosed `