Artifact
semdiff
A deterministic, severity-ranked semantic diff for four high-risk engineering formats, no LLM calls.
What it establishes
That a focused command-line tool can produce semantic, severity-ranked diffs of high-risk engineering artifacts, Cargo.lock, package-lock.json, OpenAPI, and Kubernetes YAML, deterministically.
What it does not establish
It is not a summariser and makes no language-model calls; not a universal file-type tool, covering only the four formats; not a full OpenAPI linter; not a network tool. Correctness here is the test suite plus determinism, not a proof.
Method
Each artifact is parsed, its load-bearing content extracted, and changes ranked by severity; the output is deterministic and sorted, with a stable JSON schema and defined exit codes.
Results
134 fixture pairs and 137 tests; the demo output is byte-identical to the documented example.
What has to be trusted
The Rust toolchain and the crate dependencies; and the human-authored classification rule table, which is an authored coding scheme and part of the trusted base.
Prior work
Structured and semantic diffing and supply-chain change review. The contribution is the deliberately narrow, deterministic, no-language-model diff for four high-risk formats.
Reproduce it
cargo test && cargo run --release -p semdiff-cli -- file --old fixtures/cargo/basic_old/Cargo.lock --new fixtures/cargo/basic_new/Cargo.lock
Findings drawn from this artifact are on the evidence ledger.