cite-wide 0.2.3 Published

Cite-Wide 0.2.3 — every release asset cryptographically attested

Cite-Wide turns the citation chaos of LLM-pasted research into clean, stable, vault-wide references. From 0.2.3, every release asset is cryptographically attested back to the commit and workflow run that built it.

Cite-Wide turns the citation chaos of LLM-pasted research into clean, stable, vault-wide references — and starting with 0.2.3, every release asset is cryptographically attested back to the source code that built it.

Why care?

Most knowledge tools treat citations as plain footnotes — numeric, fragile, prone to corruption the moment you copy-paste a Perplexity response into the same note as a Google AI Overview. Both responses think they're using [1]. Both want to define what [1] means. One wins, one gets silently overwritten, and three weeks later you're staring at attribution that doesn't match the source.

Cite-Wide gives every citation a stable hex identifier ([^a1b2c3]) that survives reordering, copy-paste, and merge between two LLM responses in the same note. Then it dedupes citations pointing at the same URL across different markers, parses LLM-pasted research from Perplexity / Google AI / Claude into the Lossless canonical format, and writes per-citation files into a Citations/ folder for Dataview / Bases queries.

Open Obsidian → Settings → Community Plugins → Browse → "Cite Wide" → Install → Enable.

What 0.2.3 brings

Cryptographic provenance on every release asset. Every main.js, manifest.json, and styles.css in this release is signed via GitHub's artifact attestation system (sigstore-backed, OIDC-verified) at build time. The bytes you install can be traced back to the exact commit and GitHub Actions workflow run that produced them.

Verify any release asset before you enable the plugin:

BASH
gh attestation verify main.js --repo lossless-group/cite-wide

Exit code 0 means the file came out of a legitimate build of the source repo. Anything tampered with mid-flight — a compromised CDN, a maliciously-edited release attachment — fails the verification.

What it changes for users

Installing from inside Obsidian: nothing visible. The Community Plugins directory pulls the latest release the same way it always has. The attestations sit alongside the release as metadata.

Auditing or installing manually: verify before you copy files into your vault. Drop the three release assets into a folder, run gh attestation verify on each, then move them into <vault>/.obsidian/plugins/cite-wide/ only after the cryptographic check passes.

For everyone: the same security primitive GitHub uses for its own first-party tooling. Costs nothing to verify and answers "do I trust this install?" with a real cryptographic chain rather than faith.

How the build pipeline works now

A GitHub Actions workflow (.github/workflows/release.yml) fires on every 3-digit-semver tag push. In a clean Ubuntu runner it checks out the tagged commit, runs pnpm build, signs the three release assets via actions/attest-build-provenance@v1, and creates the GitHub Release with marketing-shape notes pulled from release-notes/<tag>.md in the repo.

Provenance is enforced by infrastructure, not maintainer discipline. Manual gh release create from a developer's machine is no longer the path — every release goes through the workflow.

The Lossless Group plugin family

Cite-Wide sits alongside three sibling plugins, all by The Lossless Group:

PluginWhat it does
Cite Wide (this release)Stable hex-identifier citations + URL-based dedupe + LLM-paste research conversion
Image GinRecraft + Ideogram image generation, Magnific stock search, ImageKit CDN, drag-gate for every dropped or pasted image
PerplexedSource-cited research from Perplexity, Claude, Perplexica (self-hosted), or LM Studio (local) + per-directory templates
MetafetchPull OpenGraph metadata into note frontmatter via OpenGraph.io or Microlink

Each is its own Obsidian plugin, independently installable. They compose well — Cite Wide's hex identifiers in your frontmatter sit alongside Metafetch's OG metadata next to Perplexed's research output, all queryable as structured data.

If Cite-Wide saves you time, buy us a coffee. The plugins are free; the coffee keeps the next one coming.

Under the hood — what shipped in this commit

  • .github/workflows/release.yml — the build-attest-release workflow described above. Identical structure to the workflows landing in image-gin, perplexed, and metafetch as a family-wide pattern

  • release-notes/0.2.3.md (this file) — the convention going forward: each release's marketing-shape copy lives in the repo before the tag is pushed, so the workflow can pick it up. Per content-farm/context-v/skills/changelog-conventions/SKILL.md "These are marketing artifacts, not internal documentation."

  • Version bumped 0.2.2 → 0.2.3 across manifest.json, package.json, versions.json

  • CLAUDE.md repointed to the family-wide Obsidian-Type-Safety.md location (folded in as an unfinished edit from when the reminder was relocated to content-farm/context-v/reminders/)

  • No source-code changes — citation conversion, dedupe, save flow, and LLM-paste parsing all behave identically to 0.2.2