Skip to content

release(8.0.2): community fixes (#142, #144), exempt_ips live smoke; guard-core 4.1.0 tracking - #146

Merged
rennf93 merged 1 commit into
masterfrom
release/8.0.2
Sep 26, 2026
Merged

rennf93 merged 1 commit into
masterfrom
release/8.0.2

Conversation

@rennf93

@rennf93 rennf93 commented Sep 26, 2026 •

Copy link
Copy Markdown
Owner

Release commit for 8.0.2: raises the guard-core floor to >=4.1.0 (published 2026-09-26), carries the trailing-slash route-config resolution fix (#142) and the block-response text/plain Content-Type fix (#144), and completes the lockstep: the exempt_ips live-smoke scenario (#145), red against PyPI by design until now, runs green against the published 4.1.0 engine in this PR's CI. Version bump, changelog, release notes, mike/versions.json and the example image tag.

Summary by CodeRabbit

  • Release
    • Updated the package to version 8.0.2.
    • Route configurations with trailing slashes now resolve according to each router’s redirect-slash setting.
    • Block responses now support text/plain.
    • The minimum supported guard-core version is now 4.1.0.
  • Documentation
    • Updated release notes, version references, and the Docker example to reflect version 8.0.2.
  • Testing
    • Added live-smoke coverage for how exempt_ips interacts with rate limiting, penetration detection, and blacklisting.

@rennf93 rennf93 added the no-issue Chore or dependency PR that does not need an issue label Sep 26, 2026
@github-actions github-actions Bot added documentation Docs, README, CHANGELOG, governance files dependencies pyproject.toml or uv.lock examples examples/ apps and example tests labels Sep 26, 2026
@coderabbitai

coderabbitai Bot commented Sep 26, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Advanced

Run ID: ae926db7-0874-4408-98a6-09a2a7b8715d

📥 Commits

Reviewing files that changed from the base of the PR and between 8a9ce52 and 1494368.

📒 Files selected for processing (6)
  • .mike.yml
  • CHANGELOG.md
  • docs/index.md
  • docs/release-notes.md
  • docs/versions/versions.json
  • pyproject.toml

Included review availability: This review used your included allowance. Your plan provides up to 4 included reviews per hour; 3 remain after this review.


📝 Walkthrough

Walkthrough

The package version changes to 8.0.2, and the minimum guard-core version changes to 4.1.0. The version metadata and Docker example are updated. The changelog and release notes describe the release changes and smoke-test scenario.

Changes

Version 8.0.2

Layer / File(s) Summary
Version and dependency metadata
pyproject.toml, .mike.yml, docs/versions/versions.json, docs/index.md
The package version and latest aliases change to 8.0.2. The minimum guard-core version changes to 4.1.0, and the Docker example uses image tag v8.0.2.
Release notes and changelog
CHANGELOG.md, docs/release-notes.md
The release notes describe route configuration, text/plain block responses, the exempt-IP smoke scenario, and the guard-core version requirement.

Priority: ➖ Normal

Estimated code review effort: 2 (Simple) | ~10 minutes

Change: Bug fix

Merge Risk: ⚪ Minimal · up to 14943

The 8.0.2 release metadata and notes are consistent with the supplied implementation and test evidence. No actionable merge-blocking risk is established.

Security Architecture Review

Security architecture risk: 🔵 Low · up to 14943

No security regression is demonstrated. The new dependency minimum affects deployed installations, while the available test does not establish how every installation identifies clients or handles rate-limit state during failures.

Retained concerns
No architecture-level concerns identified.

Security review details

Security Blast Radius

  • inferred — The dependency floor can affect installations upgrading the package; the evidence does not identify a changed tenant scope, privilege, or production ingress configuration.

Trust Boundaries and Controls

  • observed — The smoke proxy sets both forwarded client-IP headers to 192.168.50.50, matching the scenario's exemption and Redis-key assertions. The available source does not show how the underlying middleware accepts those headers or how production proxies constrain them.

Resilience and Maintainability Implications

  • observed — The harness flushes smoke-prefixed Redis keys before restarting the application with a scenario configuration. The scenario does not establish middleware atomicity, concurrent ordering, retry behavior, or recovery of rate-limit state.

Hardening Proposals

  • proposed — For release assurance, verify the application-observed client IP and the middleware's trusted-proxy rules, then exercise exemption and Redis bucket behavior under concurrent requests and interrupted or repeated execution.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly identifies the 8.0.2 release and summarizes its main changes, including the fixes, live smoke scenario, and guard-core 4.1.0 tracking.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actions github-actions Bot removed the examples examples/ apps and example tests label Sep 26, 2026
@rennf93
rennf93 merged commit d520c94 into master Sep 26, 2026
15 checks passed
@rennf93
rennf93 deleted the release/8.0.2 branch September 27, 2026 18:26
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies pyproject.toml or uv.lock documentation Docs, README, CHANGELOG, governance files no-issue Chore or dependency PR that does not need an issue

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant