From 40c9f3c7bf8b00a5642b993a57dd727a9c0f733b Mon Sep 17 00:00:00 2001 From: Himanshu Singh Date: Tue, 22 Sep 2026 15:36:20 +0530 Subject: [PATCH] tula v0.3.3 Co-Authored-By: Claude Opus 5 (1M context) --- CHANGELOG.md | 5 ++++- README.md | 2 +- SECURITY.md | 2 +- package.json | 2 +- site/app/install/page.tsx | 2 +- site/lib/site.ts | 2 +- src/version.ts | 2 +- 7 files changed, 10 insertions(+), 7 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index fd6ca45..632db89 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -11,6 +11,8 @@ CI and build plumbing, refactors, and doc-only edits — stays in commit message ## [Unreleased] +## [0.3.3] - 2026-09-22 + ### Fixed - **`brew install hsnice16/tap/tula` works on Homebrew 6 and later.** The formula named `tula-latest` as a conflict, and Homebrew refuses to load a formula from a tap you have not trusted, so the install line failed before downloading anything. To update, name the formula in full — `brew upgrade hsnice16/tap/tula` — since Homebrew refuses the short name for an install it holds no trust for. @@ -382,7 +384,8 @@ what breaks first. - `KeyScope` is tri-state. Kraken exposes no endpoint reporting a key's permissions, and every endpoint gated on trade permission mutates an order, so `canTrade` is `unknown` rather than guessed at. Withdraw scope is provable, and is proven. - Kraken margin and open orders are not read yet, so on a margin account this is not a complete Kraken picture. -[Unreleased]: https://github.com/hsnice16/tula/compare/v0.3.2...HEAD +[Unreleased]: https://github.com/hsnice16/tula/compare/v0.3.3...HEAD +[0.3.3]: https://github.com/hsnice16/tula/compare/v0.3.2...v0.3.3 [0.3.2]: https://github.com/hsnice16/tula/compare/v0.3.1...v0.3.2 [0.3.1]: https://github.com/hsnice16/tula/compare/v0.3.0...v0.3.1 [0.3.0]: https://github.com/hsnice16/tula/compare/v0.2.0...v0.3.0 diff --git a/README.md b/README.md index 390d1a4..3481c9e 100644 --- a/README.md +++ b/README.md @@ -148,7 +148,7 @@ the sigstore-backed attestation proving this repository's release workflow built it wherever the GitHub CLI can — saying so either way. Check one by hand: ```bash -gh attestation verify tula-v0.3.2-darwin-arm64.tar.gz --repo hsnice16/tula \ +gh attestation verify tula-v0.3.3-darwin-arm64.tar.gz --repo hsnice16/tula \ --signer-workflow hsnice16/tula/.github/workflows/release.yml ``` diff --git a/SECURITY.md b/SECURITY.md index aa679ca..3274d5e 100644 --- a/SECURITY.md +++ b/SECURITY.md @@ -291,7 +291,7 @@ keyless, so there is no signing key for this project to generate, publish, rotat or lose. ```bash -gh attestation verify tula-v0.3.2-darwin-arm64.tar.gz --repo hsnice16/tula \ +gh attestation verify tula-v0.3.3-darwin-arm64.tar.gz --repo hsnice16/tula \ --signer-workflow hsnice16/tula/.github/workflows/release.yml ``` diff --git a/package.json b/package.json index 0934640..99a92d0 100644 --- a/package.json +++ b/package.json @@ -1,6 +1,6 @@ { "name": "@hsnice16/tula", - "version": "0.3.2", + "version": "0.3.3", "description": "Your true exposure, what breaks first, and more, across every venue at once.", "license": "MIT", "type": "module", diff --git a/site/app/install/page.tsx b/site/app/install/page.tsx index 6574c24..3513b5f 100644 --- a/site/app/install/page.tsx +++ b/site/app/install/page.tsx @@ -356,7 +356,7 @@ export default function Page() { { - "curl --proto '=https' --tlsv1.2 -fLO https://github.com/hsnice16/tula/releases/download/v0.3.2/tula-v0.3.2-darwin-arm64.tar.gz\ngh attestation verify tula-v0.3.2-darwin-arm64.tar.gz --repo hsnice16/tula --signer-workflow hsnice16/tula/.github/workflows/release.yml" + "curl --proto '=https' --tlsv1.2 -fLO https://github.com/hsnice16/tula/releases/download/v0.3.3/tula-v0.3.3-darwin-arm64.tar.gz\ngh attestation verify tula-v0.3.3-darwin-arm64.tar.gz --repo hsnice16/tula --signer-workflow hsnice16/tula/.github/workflows/release.yml" }

diff --git a/site/lib/site.ts b/site/lib/site.ts index 6e68c18..b8465f2 100644 --- a/site/lib/site.ts +++ b/site/lib/site.ts @@ -10,7 +10,7 @@ export const NAME = 'tula' * the two disagree and `release-cut.sh` bumps this with them: a frame offered * as the tool's own output cannot print a release that was never cut. */ -export const VERSION = '0.3.2' +export const VERSION = '0.3.3' /** * GA4, for the site alone. Held here rather than read from `process.env`: an diff --git a/src/version.ts b/src/version.ts index 3bd9d17..822a666 100644 --- a/src/version.ts +++ b/src/version.ts @@ -1,5 +1,5 @@ export const APP_NAME = 'tula' -export const APP_VERSION = '0.3.2' +export const APP_VERSION = '0.3.3' /** * SemVer says a hyphen means pre-release, and `release.yml` already reads it