Repository navigation
chore: release v0.54.0 - #953
Merged
Merged
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
chore: release v0.54.0
Version bump + CHANGELOG section for the two features that landed on
mainpastv0.53.4.0.53.4 -> 0.54.0— two backward-compatible features, so MINOR per semver.What's shipping
PR feat(security): Gate enum + wire egress/sensitive-path hooks + refusal telemetry [TASK-943 / SEC-2.1 / F-01] #936 —
Gateenum + wired egress/sensitive-path hooks + refusal telemetry (TASK-943 / SEC-2.1 / F-01).The tool gate was a
bool: it could say ask or don't ask, never no, so refusals lived asout-of-band
bail!s beside the gate at each call site.Gate { Allow, Confirm, Refuse }is computedonce in
exec_gate(), which is what lets the egress (PR [SEC-2.2 / F-04] TASK-944: classify network egress in the tool gate #932) and sensitive-path (PR TASK-945: sensitive-path denylist gated in every mode [SEC-2.3 / F-09] #934)classifiers stop being
return falsestubs. Writes whose content executes later(
.git/hooks/**,.github/workflows/**,.git/config) are refused ahead of every grant;the glued
env --split-string=/-Sshbypass is closed; the brittleinclude_str!-grepexhaustiveness test is replaced by
#[deny(clippy::wildcard_enum_match_arm)]; and everyrefuse/confirm writes a
tool_telemetryrow (gate-refuse/gate-confirm) with the rulethat fired and a bounded
bin[:subcommand]— no argv. Deny-by-defaultMode::Unattendedis not in this release (ISS-410409), so no existing mode's effective behaviour changes.
PR feat(terminal): pin the input line to a fixed footer row in every state #952 — the input line is pinned to a fixed footer row (H-2) in every shell state.
The one target the operator aims their hands at no longer moves with the transcript.
PR #951 (
docs(changelog)) is docs-only and needs no entry of its own.Release gates (run on a clean checkout of
origin/main@03be66b)cargo fmt --all -- --checkcargo clippy --all-targets --all-features -- -D warningscargo test --workspacecargo build --releasegit tag -l v0.54.0aishversion line changed; no dependency churnAfter merge
Tag
v0.54.0on the merge commit and push it —release-production.ymlverifies the tagagainst
Cargo.tomland publishes the release with binary assets. The release is notto be created by hand (that is what burned v0.48.0 and v0.52.0).
Need help on this PR? Tag
@codesmith-botwith what you need. Autofix is disabled.