Skip to main content
Introducing packages.sweber.dev
All posts
Release1 min read

Logarithm Pro 0.6.0 released

One evidence pack for auditors: events, integrity report, timestamped checkpoints and the retention report with a signed manifest of SHA-256 hashes, as a single ZIP.

By Seya Weber

Logarithm Pro 0.6.0 is out and available to all Pro customers. The free packages stay at 0.4.0. Nothing breaks: 0.5.0 code keeps working as it is.

The evidence pack

When an auditor from ISO 27001, SOC 2 or a financial supervisor asks about your audit log, they want the same things every time: the events, proof that the log was not changed, and proof that your retention rules ran. Until now you had to collect these yourself. buildEvidencePack() puts them in one package:

import { buildEvidencePack, verifyEvidencePack, zipFiles } from "@weber-development/logarithm-export"

const { files } = await buildEvidencePack(store, {
  tenantId: "acme",
  from: "2026-01-01T00:00:00Z",
  title: "Audit evidence Q1 to Q3 2026",
  integrity: await verifyIntegrity(store, { key, tenantId: "acme", checkpoints }),
  checkpoints, // with trusted timestamps from 0.5.0
  retention: { csv: retentionReportCsv(rows), html: retentionReportHtml(rows) },
  signingKey: key,
})
const zip = zipFiles(files) // one download, application/zip

The pack contains the events as CSV and NDJSON, the integrity report, the checkpoints, the retention report and a manifest.json. The manifest lists every file with its size and SHA-256, plus tenant, period and event count. With a signingKey it also carries an HMAC signature, so a changed manifest is detected too.

verifyEvidencePack(files, { signingKey }) re-computes every hash and tells you which file was changed, is missing or was added. An auditor does not need your software: sha256sum against the manifest is enough. You can add your own files, such as policies or notes, with extra.

Update

pnpm add @weber-development/logarithm-export@latest @weber-development/logarithm-integrity@latest @weber-development/logarithm-retention@latest

Logarithm Pro is available on the package page and is part of the Compliance Bundle.

Package in this post

Logarithm

A self-hosted audit log for SaaS apps: who changed what, and when. Field-level diffs in your own Postgres or SQLite, and a ready React view for your customers' admins.

pnpm add @sweberdev/logarithm @sweberdev/logarithm-react
View package

Related posts

Release

Logarithm Pro 0.5.0 released

Trusted RFC 3161 timestamps for integrity checkpoints, and a retention report with the legal basis per tenant that you can hand to an auditor as CSV or a printable page.

Logarithm
Release

Logarithm 0.3.0 released

Counts and breakdowns for dashboards, typed action catalogs, a MySQL and MariaDB store, and in Logarithm Pro alerts to Slack and Teams plus anomaly detection for unusual exports, deletions and failed logins.

Logarithm
Release

Logarithm 0.4.0 released

French and Italian for the activity log, and in Logarithm Pro an S3 and Cloudflare R2 archive for expired events plus log entries that prove your retention policy and erasures actually ran.

Logarithm