--version printed "dev" for any binary not built with make build, so a
user running a go install build could not say what version they had.
resolveVersion now falls back to the module version from
runtime/debug.ReadBuildInfo() when the build-time stamp is absent,
ignoring the "(devel)" of a local build. The stamped value still wins
when present. It takes the build info as an argument, so a test covers
the choice without a real build.
Model: opus-4-8
ssh install no longer runs a command on the host. It reads .ssh/authorized_keys over sftp, takes the empty reading only from sftp's own message about that path, appends the derived key locally when it is not already present, uploads the result beside the file with mode 0600 and renames it over the original. Any other failure prints what sftp said, writes nothing and exits 1. sftp batch mode disables password prompts, so a key or agent is required; a directory the owner cannot enter reads as a host with no file, which README.md states.
Model: opus-5 (implementation); fable-5-1 (landing)
The README is the specification sneak approved on 2026-09-07, moved
here from the hacks repository: deterministic SSH keys, age identities
with encrypt and decrypt, and child mnemonics, all derived from one
BIP-39 mnemonic and stored nowhere.
Model: fable-5-1