AsiBackbone 7.1.0 Release Notes
Release date: 2026-10-03
7.1.0 is a backward-compatible minor release for the stable 7.x package
family. It adds a signing-input analyzer safety rail and begins documented
deprecation windows for compatibility APIs that should not be used for new
work. Package IDs and the net10.0 target are unchanged. AssemblyVersion
remains 7.0.0.0; package and file versions advance to 7.1.0 and 7.1.0.0.
Signing analyzer safety rail
Analyzer rule ASIB004 reports a warning when code constructs a
SigningRequest, SignatureVerificationRequest, or ManagedKeySignRequest
without setting SignatureInput. Omitting that value silently selects the
pre-6.0 hash-only input, bypasses the ASIB902 warning on direct legacy-input
creation, and produces signatures that fail default version 1 verification.
Set SignatureInput with GovernanceSignatureInput.CreateV1(...). The
first-party GovernanceArtifactSigner and GovernanceArtifactVerifier paths
already do this.
Deprecations and migration paths
GovernanceSignatureInput.CreateLegacy(...)now produces warningASIB902. UseCreateV1(...)for current signing and verification. The legacy method remains callable in7.x; its earliest possible removal is8.0after the published deprecation policy is satisfied.GovernanceOutboxDrainWorkerOptions.RetryClocknow produces warningASIB903. Register aTimeProviderso hosted drain timing, retry readiness, claim transitions, and other time-aware services share one clock. The delegate remains honored in7.x; its earliest possible removal is8.0.- The previously released
ASIB901warning forCapabilityGrantValidationOptions.CreateExecutionBoundary(...)now has a dedicated migration guide. UseCreateBoundExecutionBoundary(...)with host-owned binding expectations.
These are compiler and IDE warnings, not errors. Projects that promote warnings to errors may need to complete the documented migration while upgrading.
Historical signature verification remains supported
VerificationPolicyContext.WithLegacySignatureInputAllowed() is not
deprecated. Applications may continue to opt into verification of retained
artifacts signed with the pre-6.0 input for the duration of their evidence
retention requirements. The new warning applies to creating new legacy signing
inputs, not to intentionally verifying historical evidence.
Repository and dependency maintenance
- Added the repository-local AsiBackbone code-review agent skill.
- Added an XML sitemap to the DocFX site and corrected stale current-release pointers in historical documentation.
- Published the deprecation and major-release policy, including minimum deprecation windows, major-release spacing, announcement requirements, and preceding-line security support.
- Pinned workflow jobs to Ubuntu 24.04, restored project automation, and refreshed test, sample, and infrastructure dependencies. Shipped package dependencies are unchanged.
Upgrade actions
- Build with
AsiBackbone.Analyzersenabled and addressASIB004by supplying version 1 signature input for new signing and verification requests. - Replace new uses of
CreateLegacy(...)withCreateV1(...); retain the explicit legacy-verification opt-in only where historical artifacts require it. - Replace
GovernanceOutboxDrainWorkerOptions.RetryClockwith a registeredTimeProvider. - Follow the dedicated
ASIB901,ASIB902, andASIB903migration guides before the eventual8.0removal boundary.
No persisted schema, canonical wire value, package ID, namespace, service registration contract, or documented runtime default changes in this release.
Release verification
The release candidate is validated through locked restore, Debug and Release
builds, the full test suite, formatting, public API baselines, package metadata
and contents, template and external-consumer smoke tests, documentation release
claims, and DocFX. Stable publication occurs only from the protected v7.1.0
tag after the release-preparation pull request is merged to main.
See also: