release: 0.9.2 — honest changelog + version unit - #58
Merged
Merged
Conversation
Closes the changelog/version mismatch: since v0.9.1, master
accumulated F2/F3/F4 + the v4 outbound fix + the --help wording fix,
all of it recorded under the SHIPPED [0.9.0] section. This release
makes the changelog and the tags tell the same story.
Release unit (three files move together per AGENTS.md):
- VERSION: 0.9.1 -> 0.9.2
- CHANGELOG.md:
* new [0.9.2] - 2026-09-28 section
* F2/F3/F4 moved verbatim from [0.9.0] into [0.9.2] ### Added
* [0.9.0] now holds exactly one entry (--init idempotency report,
F1) — what tag v0.9.0 (1bc0ad4) actually shipped
* [0.9.2] ### Fixed: v4 outbound peer-column fix (issue #53, PR #54)
and the --help --json wording fix (PR #56)
- skills/box-audit/SKILL.md frontmatter version: 0.9.1 -> 0.9.2
(hand-synced; CI does not catch this)
No other file changes. Tag v0.9.2 is applied to the merge commit by
the release tail.
|
Important
This repository does not receive automatic reviews because it has fewer than 10 stars. ⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Advanced Run ID: Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Change
RELEASE-UNIT PR (VERSION + CHANGELOG + SKILL.md move together per
AGENTS.md). Cuts 0.9.2 to close the changelog/version mismatch:
since tag v0.9.1, master accumulated F2/F3/F4 + the v4 outbound fix +
the
--helpwording fix, all of it recorded under the SHIPPED[0.9.0]section. This PR makes the changelog and the tags tell thesame story.
Problem
[0.9.0] - 2026-09-25contained four entries (F1, F2, F3, F4), buttag v0.9.0 (1bc0ad4) shipped only F1 — F2/F3/F4 merged to master after
the v0.9.0 tag was cut (PRs #46/#51/#52) and were logged under
[0.9.0]at merge time. VERSION has sat at 0.9.1 ever since (v0.9.1was a patch: the lock-gate exit-75 fix, PR #47), while the four post-
v0.9.1 features/fixes had no section of their own. The changelog's
[0.9.0]section no longer described what v0.9.0 actually shipped.Additionally, two things merged since v0.9.1 were never recorded
anywhere: the v4 outbound peer-column fix (issue #53, PR #54) and the
--helpwording fix (PR #56/#57).Fix
Three files, one commit, one unit — no other file changes:
0.9.1→0.9.2## [0.9.2] - 2026-09-28section at the top[0.9.0]into[0.9.2] ### Added:Fail2ban jail discovery (F2),Webhook severity floor (F3),IPv6 outbound parity (F4)(F4 in the PR docs(changelog): reword F4 entry — 'identically to before' overstates on iproute2 6.x #55-reworded wording)[0.9.0]now contains exactly ONE entry —--initidempotency report (F1) — what tag v0.9.0 (1bc0ad4)actually shipped. Its date (2026-09-25) and every other section
are untouched.
### Fixedin[0.9.2]:established-outbound remote extraction hardcoded the 5th awk
field; on iproute2 6.x
sssuppresses the State column so field5 is the Process column and the check extracted nothing (false
"outbound remote: none"). Now resolves the peer column from the
ss header via
ss_peer_column()(5 on 5.x, 4 on 6.x) in a newss_v4_remote_ips(); v6 path unaffected; tier-1 property test(RED on master / GREEN on fix) + tier-2 seeded 6.x proof.
--helpusage block (PR docs(help): --json no longer "always exits 0" in usage block #56): the--jsonparenthetical nolonger claims "always exits 0".
version:0.9.1→0.9.2(hand-synced per AGENTS.md — easy to miss, CI will notcatch it).
Test
Docs/version-only change — no code path touched.
bash test/all.shon this head (release/0.9.2 @ f8234d7, frommaster 5dfb212 = post-PR docs(help): --json no longer "always exits 0" in usage block — rebased #57): all: 4 passed (tiers 1+2+3, no
skips) — run in the local privileged docker.
[0.9.0]section (script-checked, not eyeballed).--versionprintsbox-audit 0.9.2+replayfrom the working tree.Release tail (post-review, maintainer)
Merge house-style; annotate tag v0.9.2 ON THE MERGE COMMIT and
push; empty commit to re-trigger release-check. Post-merge verify:
VERSION=0.9.2 on origin/master, v0.9.2 on origin, release-check green,
and v0.9.0=1bc0ad4 + v0.9.1=d543e5f unchanged (never move an
existing tag).