Skip to content

Vault Prospector 0.3.0-preview.18

0.3.0-preview.18 is the current unsigned Windows x64 manual-test Preview.

Fixed

  • Product updates are discovery-only. Vault Prospector no longer downloads, retains, elevates, or launches an unsigned Preview MSI. Settings links to the public release history and the checksum and keyless Sigstore verification guide.
  • Identity workspaces include vaults accessible to the linked identity even when another connected identity is preferred for display and retrieval.
  • Clipboard Copy without fresh verification requires the live unlocked application session at the service boundary and rechecks that authorization immediately before writing to the clipboard.
  • Object details accurately distinguish Reveal's configured verification from Copy's unlocked session and optional fresh-verification setting.

Download and trust

Download packages, adjacent checksums, and Sigstore bundles from the public binary-only release. The direct installer is intentionally unsigned and displays Unknown Publisher. Verify the exact download against its adjacent SHA-256 file and keyless Sigstore bundle before installation.

Validation boundary

The governed local release gate passed 496/496 tests with zero warnings or errors and no known vulnerable NuGet packages. Browser tests passed 6/6 and all three exact-MSI validators passed. The local candidate upgraded Preview 17 with MSI exit code 0, preserved all five non-log local state files byte-for-byte, reported Windows DisplayVersion 0.3.18, and launched from Program Files. Protected PR CI, exact-main CI, and immutable-tag publication passed. The public release has 16 assets; fresh downloads of all five packages matched their adjacent checksums and passed keyless Sigstore verification. The exact public MSI subsequently installed with exit code 0, preserved all five non-log local-state hashes, matched the verified public ZIP executable, and launched from Program Files.

See the release evidence.

Preview software. Direct packages are unsigned and display Unknown Publisher — verify the published SHA-256 before installing.