Skip to content

Release v1.0.0 - #12

Merged
sanskarIN merged 5 commits into
mainfrom
release-v1.0.0
Sep 27, 2026
Merged

sanskarIN merged 5 commits into
mainfrom
release-v1.0.0

Conversation

@sanskarIN

Copy link
Copy Markdown
Owner

What this changes

Why

How it was tested

Checklist

  • cargo fmt --all --check, cargo clippy --workspace --all-targets --locked -- -D warnings, and cargo test --workspace --locked pass
  • For web changes: npm run format:check, npm run typecheck, and npm test pass
  • New or changed findings carry evidence, a method, and limitations, and have tests with realistic samples
  • No network access, telemetry, or execution of repository code was added to the analysis
  • Documentation in docs/ is updated, and user-visible changes are listed under "Unreleased" in CHANGELOG.md

The code-scanning fix removed the found findings from this test's failure message, but
left a closure that rustfmt formats differently, so the formatting check failed on main.
The message now names the expected rule and file, which carry no secret material.
…ainer Registry

Running the Release workflow by hand without a tag now builds every file from the selected
branch as a trial and keeps them as downloads of the run, without publishing anything, so
a release can be checked before it is tagged. Every job builds the same ref: the full tag
reference, or the trial's exact commit.

Each release also pushes ghcr.io/sanskarin/repodna for linux/amd64 and linux/arm64, tagged
with the version, the minor and major versions, and latest. The image is Alpine Linux with
Git and the release's static repodna binary; it trusts mounted repositories so that
history analysis works on checkouts owned by another user, keeps its storage in
/tmp/repodna so it also runs with --user, and carries the license files. The workflow tests
the amd64 image on the checkout before it pushes.
…rsion

The release notes copied the changelog's link definitions, which follow the last section,
and listed the downloads with a <version> placeholder. They now end with the section's own
text, and the download names carry the version.
Without a signature that covers the whole bundle, Macs with Apple silicon report the
downloaded app as damaged and offer no way to open it. The bundle is now signed ad hoc, so
macOS asks for confirmation in Privacy & Security instead, and the release workflow checks
the signature before it collects the installers.

The installation guide and the desktop page now describe Open Anyway in System Settings,
which replaced Control-click Open in macOS 15.
CodeQL read the ref that the version check handed to every job as possibly untrusted code:
a job output named ref looks like a pull request's branch, so each step that ran code
after the checkout (npm, cargo, and the built binary) was reported as a cache poisoning
risk. Every job now checks out refs/tags/<tag>, or for a trial the commit the run started
from, which is what the output held; only people who can push tags or start the workflow
decide either.
@sanskarIN
sanskarIN merged commit 83b837c into main Sep 27, 2026
56 checks passed
Repository owner deleted a comment from chatgpt-codex-connector Bot Oct 3, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant