# CheckPQC reference script changes ## 1.1.0 — 2026-09-25 - Added `--version`, a report schema version and the script version. - Reports now record UTC start/end times and identify the local OpenSSL vantage point. - Published reproducible SHA-256 and byte-count metadata generated from the exact downloadable source. - Retained read-only behavior, certificate/hostname validation, a 15-second handshake timeout, a 128 KiB output limit and explicit inconclusive results. ## 1.0.0 — 2026-09-24 - Initial standalone Python reference check for authorized TLS and STARTTLS endpoints, using OpenSSL 3.5 or later with X25519MLKEM768 enabled. - Separate local-default and hybrid-only attempts; no software installation, credentials, package dependency or CheckPQC API use. - Recognized negotiation is evidence only for the tested connections, not application encryption, certificate signatures or whole-system readiness. ## Integrity and verification The adjacent `manifest.json` and `tls-check.py.sha256` describe the current source. A hash obtained from the same site helps detect accidental mismatch; it does not independently authenticate the publisher. Inspect the source and obtain it over HTTPS. Python tests cover hybrid and classical evidence, unknown/offered groups, certificate errors, hostname validation, process timeout and output limits. The scheduled workflow declares Windows, macOS and Linux fixture runs and reports the available OpenSSL capability separately. A declared matrix is not a claim that every platform or every production service has been tested. See the editorial policy and recorded workflow results for current verification.