diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 56cc4cd..98ea4a7 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -15,6 +15,37 @@ concurrency: cancel-in-progress: true jobs: + # tools/hooks/commit-msg only protects a machine that has run + # `git config core.hooksPath tools/hooks`. Nothing protected the pull + # request itself, so `Release 0.0.2-beta.2` reached main and printed itself + # beside a dozen files, permanently — the subject of a merged commit cannot + # be reworded once a tag points at it. The hook is the same file either way; + # this runs it where it cannot be skipped. + subjects: + name: Commit subjects + runs-on: ubuntu-latest + timeout-minutes: 5 + if: github.event_name == 'pull_request' + steps: + - uses: actions/checkout@v4 + with: + # Every commit the pull request adds, not just its tip. + fetch-depth: 0 + - name: Check each subject against tools/hooks/commit-msg + run: | + set -e + base="${{ github.event.pull_request.base.sha }}" + head="${{ github.event.pull_request.head.sha }}" + failed=0 + for sha in $(git rev-list --no-merges "$base..$head"); do + git log -1 --format=%B "$sha" > /tmp/msg + if ! sh tools/hooks/commit-msg /tmp/msg; then + echo " ^ $(git log -1 --format='%h %s' "$sha")" + failed=1 + fi + done + [ "$failed" = "0" ] || exit 1 + test: name: Test on Node ${{ matrix.node }} runs-on: ubuntu-latest diff --git a/CHANGELOG.md b/CHANGELOG.md index 30d6fe7..d73cf40 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -7,6 +7,35 @@ versioning follows [SemVer](https://semver.org/). ## [Unreleased] +## [0.0.2-beta.3] — 2026-09-06 + +Documentation and the guards around it. No runtime change: `dist/` differs from +beta.2 only in the version string it reports. + +### Fixed +- **The Code of Conduct says where to report.** Its enforcement section invited + reports "to the community leaders responsible for enforcement" and named no + address, which is the same as having no channel. It now names + `support@jsray.org`, the address SECURITY.md already used. +- **A release subject that is a version and one word is rejected.** + `tools/hooks/commit-msg` already refused a bare `0.0.1-beta.3`, with a + comment about how a version number lands on every file the release touched. + `Release 0.0.2-beta.2` walked past that pattern and did exactly what it + describes, on twelve files. The pattern now covers a leading + release/bump/publish/tag word. +- **The subject check runs on pull requests.** The hook only protects a + machine that has configured `core.hooksPath`; CI now runs the same file + against every commit a pull request adds, where it cannot be skipped. +- **The roadmap entry for jsray-vscode and jsray-terminal.** It described both + as unpublished, bundling Core `0.0.1-beta.5`, with READMEs pointing at + `0.0.1-beta.1`. Both are public, both bundle `0.0.2-beta.1`, and both now + derive and check the badges it said they needed first. + +### Changed +- **Availability is stated, not contrasted.** The integrations table and + `docs/projects.md` paired each channel with the one it is not on yet. They + now say where each integration is installed from. + ## [0.0.2-beta.2] — 2026-09-05 Ships the portable renderer, and corrects what the registry and the site were @@ -30,7 +59,7 @@ saying about this project. - **The palette fallback chain has one implementation.** `applyThemeToRoot` carried the only copy of it; `resolveToken` is now shared with the portable renderer, because two renderers resolving the same palette by two implementations is how they come to disagree about a palette that predates a token key. - The site build ships `themes/` and the new page. The paste page fetches every palette at runtime for the same reason the Studio does — a second copy of the colours is a second thing to drift. -- **The README says what the integrations are, because npm shows this file.** The published page for `@jsray/core@0.0.2-beta.1` still lists all three as "Coming soon"; all three are public with releases, and the table now links each one and says where it can actually be installed from — which is GitHub rather than its host's directory in every case. npm freezes a package page per version, so a correction only reaches the registry by publishing. +- **The README says what the integrations are, because npm shows this file.** The published page for `@jsray/core@0.0.2-beta.1` still lists all three as "Coming soon"; all three are public with releases, and the table now links each one and says where each can be installed from. npm freezes a package page per version, so a correction only reaches the registry by publishing. - **`repository` and `bugs` point at the organisation's current name.** They were published as `github.com/JSRayCore/JSRay`, which still redirects — but the frozen metadata is what every tool reads, and the org name it names no longer exists. - **The versioning doc says why Core counts its betas.** It justified the counter mechanically — `check:versions` wants it, `version_compare()` orders it — which is true and is not the reason. Core is the kernel every integration renders through, so it earns more revision rounds before `0.1.0` than anything built on it, and those land inside one patch. The integrations bump the patch each time, so a counter would say nothing. diff --git a/CODE_OF_CONDUCT.md b/CODE_OF_CONDUCT.md index b341bb4..751ec9a 100644 --- a/CODE_OF_CONDUCT.md +++ b/CODE_OF_CONDUCT.md @@ -30,8 +30,12 @@ Examples of unacceptable behavior: ## Enforcement Instances of abusive, harassing, or otherwise unacceptable behavior may be -reported to the community leaders responsible for enforcement. All complaints -will be reviewed and investigated promptly and fairly. +reported to . All complaints will be reviewed and +investigated promptly and fairly, and the reporter's identity is not shared +outside the people handling the report. + +Saying complaints "may be reported" without saying where is the same as having +no channel: this document named none until 0.0.2-beta.3. ## Attribution diff --git a/README.md b/README.md index 64e4b1e..b9ccb3d 100644 --- a/README.md +++ b/README.md @@ -9,7 +9,7 @@ [![npm](https://img.shields.io/npm/v/@jsray/core/beta?label=npm)](https://www.npmjs.com/package/@jsray/core) [![License: MIT](https://img.shields.io/badge/License-MIT-blue.svg)](LICENSE) -[![Version](https://img.shields.io/badge/version-0.0.2--beta.2-lightgrey)](CHANGELOG.md) +[![Version](https://img.shields.io/badge/version-0.0.2--beta.3-lightgrey)](CHANGELOG.md) [![Channel](https://img.shields.io/badge/channel-beta-blue)](docs/versioning.md) [![Zero deps](https://img.shields.io/badge/dependencies-0-success)](package.json) [![Size](https://img.shields.io/badge/dist-core%20js%20%2B%20css-lightgrey)](dist/) @@ -46,7 +46,7 @@ Or drop it into a page with no build step at all: watching, pin the version instead** — every release is frozen at its own path: ```html - + ``` ### Verifying what you loaded @@ -56,7 +56,7 @@ A pinned URL says which release you asked for, not which bytes you got. Add a hash and the browser refuses to run the file if it is not the one published: ```html - ``` @@ -64,7 +64,7 @@ hash and the browser refuses to run the file if it is not the one published: The hashes live next to the files they describe, in the same format SRI uses: ``` -https://jsray.org/v/0.0.2-beta.2/integrity.json +https://jsray.org/v/0.0.2-beta.3/integrity.json ``` `crossorigin="anonymous"` is required, not optional — SRI on a cross-origin @@ -111,12 +111,12 @@ Official integrations live in their own repositories, use JSRay Core by default, | Integration | Repository | Status | |---|---|---| -| WordPress plugin | [`jsray-wp`](https://github.com/jsrayorg/jsray-wp) | Public beta · not on WordPress.org yet | -| VS Code extension | [`jsray-vscode`](https://github.com/jsrayorg/jsray-vscode) | Public beta · not on the Marketplace yet | -| Terminal CLI | [`jsray-terminal`](https://github.com/jsrayorg/jsray-terminal) | Public beta · not on npm yet | +| WordPress plugin | [`jsray-wp`](https://github.com/jsrayorg/jsray-wp) | Public beta | +| VS Code extension | [`jsray-vscode`](https://github.com/jsrayorg/jsray-vscode) | Public beta | +| Terminal CLI | [`jsray-terminal`](https://github.com/jsrayorg/jsray-terminal) | Public beta | | …and more | — | Community & official adapters welcome | -Each is installable today, from GitHub rather than from its host's directory: +Install any of them today: ```sh # Terminal CLI diff --git a/README.zh-CN.md b/README.zh-CN.md index 0424a79..4f41658 100644 --- a/README.zh-CN.md +++ b/README.zh-CN.md @@ -9,7 +9,7 @@ [![npm](https://img.shields.io/npm/v/@jsray/core/beta?label=npm)](https://www.npmjs.com/package/@jsray/core) [![License: MIT](https://img.shields.io/badge/License-MIT-blue.svg)](LICENSE) -[![Version](https://img.shields.io/badge/version-0.0.2--beta.2-lightgrey)](CHANGELOG.md) +[![Version](https://img.shields.io/badge/version-0.0.2--beta.3-lightgrey)](CHANGELOG.md) [![Channel](https://img.shields.io/badge/channel-beta-blue)](docs/versioning.md) [![Zero deps](https://img.shields.io/badge/dependencies-0-success)](package.json) [![Size](https://img.shields.io/badge/dist-core%20js%20%2B%20css-lightgrey)](dist/) @@ -45,7 +45,7 @@ JSRay.highlight('const x = 42;', 'js'); `jsray.org/dist/` 始终提供当前发布版本。**线上站点如果你不会持续盯着,请改用锁定版本的地址** —— 每个发布版本都固化在自己的路径下,永不变动: ```html - + ``` ### 校验你加载到的东西 @@ -55,7 +55,7 @@ JSRay.highlight('const x = 42;', 'js'); 哈希,浏览器在文件与发布内容不符时会直接拒绝执行: ```html - ``` @@ -63,7 +63,7 @@ JSRay.highlight('const x = 42;', 'js'); 哈希就放在它所描述的文件旁边,格式与 SRI 完全一致: ``` -https://jsray.org/v/0.0.2-beta.2/integrity.json +https://jsray.org/v/0.0.2-beta.3/integrity.json ``` `crossorigin="anonymous"` 是必需的,不是可选:跨源脚本的 SRI 只有在加载走 @@ -90,12 +90,12 @@ JSRay 的目标是成为完整开源的代码渲染生态:一个轻量 Core | 集成 | 仓库 | 状态 | |---|---|---| -| WordPress 插件 | [`jsray-wp`](https://github.com/jsrayorg/jsray-wp) | 公开测试版 · 尚未上架 WordPress.org | -| VS Code 扩展 | [`jsray-vscode`](https://github.com/jsrayorg/jsray-vscode) | 公开测试版 · 尚未上架 Marketplace | -| 终端 CLI | [`jsray-terminal`](https://github.com/jsrayorg/jsray-terminal) | 公开测试版 · 尚未发布到 npm | +| WordPress 插件 | [`jsray-wp`](https://github.com/jsrayorg/jsray-wp) | 公开测试版 | +| VS Code 扩展 | [`jsray-vscode`](https://github.com/jsrayorg/jsray-vscode) | 公开测试版 | +| 终端 CLI | [`jsray-terminal`](https://github.com/jsrayorg/jsray-terminal) | 公开测试版 | | …以及更多 | — | 欢迎官方与社区适配器 | -三个集成现在都能装,只是要从 GitHub 拿,而不是各自平台的市场: +三个集成现在都能装: ```sh # 终端 CLI diff --git a/SECURITY.md b/SECURITY.md index 92a44f0..fa08a27 100644 --- a/SECURITY.md +++ b/SECURITY.md @@ -43,7 +43,8 @@ one. | Version | Security updates | |---|---| -| 0.0.2-beta.2 | ✅ Current public beta | +| 0.0.2-beta.3 | ✅ Current public beta | +| 0.0.2-beta.1 – beta.2 | ❌ Superseded — upgrade to the current beta | | Earlier betas | ❌ Superseded — upgrade to the current beta | | 0.0.1-internal.∗ | ❌ Superseded by the public beta | | Stable | Not yet released | diff --git a/demo/index.html b/demo/index.html index 7fde8b5..fef8ff4 100644 --- a/demo/index.html +++ b/demo/index.html @@ -357,7 +357,7 @@

Project

diff --git a/demo/studio.html b/demo/studio.html index 56f7734..5a0faf0 100644 --- a/demo/studio.html +++ b/demo/studio.html @@ -112,7 +112,7 @@

Project

diff --git a/dist/jsray.js b/dist/jsray.js index d795c05..985f414 100644 --- a/dist/jsray.js +++ b/dist/jsray.js @@ -1865,7 +1865,7 @@ * Runtime version, for shell/core compatibility negotiation. * Must match version.json — tools/check-versions.mjs asserts it. */ - version: '0.0.2-beta.2', + version: '0.0.2-beta.3', languages: G, normalizeLanguage, detectLanguage, diff --git a/docs/development.md b/docs/development.md index e1ba4b4..f8e15d3 100644 --- a/docs/development.md +++ b/docs/development.md @@ -402,16 +402,17 @@ deliberately deferred). contribution paths). Hard rule: a locked core must surface an explicit warning when a security-grade Core update ships — security fixes are never silently pinnable. -- **jsray-vscode / jsray-terminal**: not published, and deliberately behind - while their features settle. Before either one goes public it needs what - `jsray-wp` gained on 2026-08-26/27, because all three drift the same way: +- **jsray-vscode / jsray-terminal**: both public since 2026-09-03 and + 2026-09-05, each with a release carrying an installable build. They now + carry what `jsray-wp` gained on 2026-08-26/27, because all three drift the + same way: `tools/sync-core-version.mjs` deriving the README Core badge instead of leaving it to whoever runs the sync; `check:versions` asserting the badges and the phase wording *in both directions* — the wrong phrase sitting beside the right one is what let "Internal test build · no public beta yet" survive the whole public beta; and the plugin version ladder (`0.0.1-beta → - 0.0.2-beta`, no counter) rather than Core's. Both still carry Core - `0.0.1-beta.5` and READMEs pointing at `0.0.1-beta.1`. + 0.0.2-beta`, no counter) rather than Core's. Both bundle Core + `0.0.2-beta.1`; syncing them to `0.0.2-beta.2` is the next step. - **Core**: minification is deliberately absent (zero-build); revisit at public beta. diff --git a/docs/development.zh-CN.md b/docs/development.zh-CN.md index 1434d11..9a27795 100644 --- a/docs/development.zh-CN.md +++ b/docs/development.zh-CN.md @@ -252,14 +252,14 @@ CI:每个仓库都有 GitHub Actions(Node 18/20/22 矩阵;Core 另验 `dist/` 管线)跑 32 条断言。 - **终端**:`--bg`(整底色绘制)、分页器集成与 `--core ` 覆盖在路线图上。 - **用户侧 Core 锁定**(路线图):平台原生的更新控制已允许用户拒绝某班列车(WP 手动更新、VS Code 按扩展关自动更新 + 装历史版本、npm 版本锁定)。插件内的"Core 更新策略"(跟随/锁定/自定义文件)对 WP 与终端可行,对 VS Code 预览不可行(贡献点路径静态)。硬规则:锁定状态下遇到安全级 Core 更新必须显式警告——安全修复不允许被静默锁死。 -- **jsray-vscode / jsray-terminal**:未发布,且在功能定型之前刻意落后。这两个 - 中任何一个要公开之前,都需要补上 `jsray-wp` 在 2026-08-26/27 得到的那套机制 —— - 三个集成的失效方式是同一种:`tools/sync-core-version.mjs` 自己推导 README 的 +- **jsray-vscode / jsray-terminal**:分别于 2026-09-03 和 2026-09-05 公开,各自 + 的 Release 里都挂着可直接安装的构建。两者现已补齐 `jsray-wp` 在 2026-08-26/27 + 得到的那套机制 —— 三个集成的失效方式是同一种:`tools/sync-core-version.mjs` 自己推导 README 的 Core 徽章,而不是留给"跑同步的那个人";`check:versions` **双向**校验徽章与阶段 措辞 —— 正是"该出现的词在、不该出现的词也在"这一点,让「内部测试版 · 尚未发布 公开测试版」在整个公开 beta 期间活了下来;以及插件的版本阶梯(`0.0.1-beta → - 0.0.2-beta`,无计数器)而非 Core 的记法。两者目前仍内置 Core `0.0.1-beta.5`, - README 指向 `0.0.1-beta.1`。 + 0.0.2-beta`,无计数器)而非 Core 的记法。两者均内置 Core `0.0.2-beta.1`, + 同步到 `0.0.2-beta.2` 是下一步。 - **Core**:minify 刻意缺席(零构建);公开 beta 时再议。 - **完全没有规则的字面量形式**(beta.5 审查时发现,因属"缺功能"而非"抢错范围"而推迟): diff --git a/docs/projects.md b/docs/projects.md index 8bacd38..11f1c3c 100644 --- a/docs/projects.md +++ b/docs/projects.md @@ -63,13 +63,13 @@ Core changes flow into plugin repositories by copying or packaging `dist/` asset | Repository | Intended channel | Licence | Available from today | |---|---|---|---| -| `jsray` | npm `@jsray/core` | MIT | npm — `@jsray/core@0.0.2-beta.2` | -| `jsray-wp` | WordPress.org plugin | GPLv2 or later | GitHub release zip · not on WordPress.org yet | -| `jsray-terminal` | npm CLI | MIT | GitHub — `npm i -g github:jsrayorg/jsray-terminal` · not on npm yet | -| `jsray-vscode` | VS Code Marketplace | MIT | GitHub release `.vsix` · not on the Marketplace yet | +| `jsray` | npm `@jsray/core` | MIT | npm — `@jsray/core@0.0.2-beta.3` | +| `jsray-wp` | WordPress.org plugin | GPLv2 or later | GitHub release zip | +| `jsray-terminal` | npm CLI | MIT | GitHub — `npm i -g github:jsrayorg/jsray-terminal` | +| `jsray-vscode` | VS Code Marketplace | MIT | GitHub release `.vsix` | -A public repository is not a listing. The last column is where a user can -actually get the thing today; the second is where it is headed. +The last column is where a user gets the thing today; the second is the channel +each is headed for at `0.1.0`. Future platform repositories such as `jsray-react`, `jsray-astro`, or `jsray-mdx` if needed. @@ -94,7 +94,7 @@ The public website keeps the brand concentrated under `jsray.org`: moves on every release, which is right for the demo and wrong for a site nobody is watching. - `https://jsray.org/v//`: the same files frozen per release - (`jsray.org/v/0.0.2-beta.2/jsray.js`). A page that pins here keeps rendering + (`jsray.org/v/0.0.2-beta.3/jsray.js`). A page that pins here keeps rendering the way it did the day it was written. `tools/build-site.sh` emits both. Cloudflare replaces the whole asset bundle on diff --git a/docs/projects.zh-CN.md b/docs/projects.zh-CN.md index 6e7b20d..24fbfb0 100644 --- a/docs/projects.zh-CN.md +++ b/docs/projects.zh-CN.md @@ -64,11 +64,11 @@ Core 的变更通过拷贝或打包 `dist/` 资产流向插件仓库。插件的 | 仓库 | 交付形态 | 许可 | 状态 | |---|---|---|---| | `jsray` | npm `@jsray/core` | MIT | 已公开 | -| `jsray-wp` | WordPress.org 插件 | GPLv2 or later | GitHub Release 的 zip · 尚未上架 WordPress.org | -| `jsray-terminal` | npm CLI | MIT | GitHub —— `npm i -g github:jsrayorg/jsray-terminal` · 尚未发布到 npm | -| `jsray-vscode` | VS Code Marketplace | MIT | GitHub Release 的 `.vsix` · 尚未上架 Marketplace | +| `jsray-wp` | WordPress.org 插件 | GPLv2 or later | GitHub Release 的 zip | +| `jsray-terminal` | npm CLI | MIT | GitHub —— `npm i -g github:jsrayorg/jsray-terminal` | +| `jsray-vscode` | VS Code Marketplace | MIT | GitHub Release 的 `.vsix` | -仓库公开不等于已上架。最后一列是**今天用户实际能从哪里拿到**,第二列是它将来要去的地方。 +最后一列是**今天用户从哪里拿到**,第二列是各自在 `0.1.0` 要去的渠道。 未来按需增加的平台仓库,例如 `jsray-react`、`jsray-astro`、`jsray-mdx`。 @@ -89,7 +89,7 @@ GPLv2 or later,因为 WordPress.org 的第一条指南接受任何 GPL 兼容许 (`jsray.org/dist/jsray.js`、`jsray.org/dist/themes/.css`)。这个路径每次 发版都会变 —— 对演示页是对的,对没人盯着的站点是错的。 - `https://jsray.org/v//`:同样的文件按版本固化 - (`jsray.org/v/0.0.2-beta.2/jsray.js`)。锁定到这里的页面,今天怎么渲染, + (`jsray.org/v/0.0.2-beta.3/jsray.js`)。锁定到这里的页面,今天怎么渲染, 以后还怎么渲染。 `tools/build-site.sh` 两者都生成。Cloudflare 每次部署都会整体替换资产包,因此 diff --git a/docs/versioning.md b/docs/versioning.md index a49a553..8c6123c 100644 --- a/docs/versioning.md +++ b/docs/versioning.md @@ -4,7 +4,7 @@ JSRay Core uses single-project versioning. Platform plugins keep their own version files in their own repositories. -Current version: `0.0.2-beta.2` +Current version: `0.0.2-beta.3` Current channel: `beta` Public beta released: yes @@ -33,7 +33,7 @@ The mechanics follow from that: `check:versions` requires the counter here, and `0.0.2`. ``` -0.0.1-beta.1 … 0.0.1-beta.5 → 0.0.2-beta.1 → 0.0.2-beta.2 → 0.0.3-beta.1 → … → 0.1.0 +0.0.1-beta.1 … 0.0.1-beta.5 → 0.0.2-beta.1 … 0.0.2-beta.3 → 0.0.3-beta.1 → … → 0.1.0 ``` The `0.0.1` line closed at beta.5. `0.1.0` is where the beta label comes off, diff --git a/docs/versioning.zh-CN.md b/docs/versioning.zh-CN.md index d382a4f..f62b2fb 100644 --- a/docs/versioning.zh-CN.md +++ b/docs/versioning.zh-CN.md @@ -4,7 +4,7 @@ JSRay Core 采用单项目版本号。平台插件在各自仓库里维护自己的版本文件。 -当前版本:`0.0.2-beta.2` +当前版本:`0.0.2-beta.3` 当前通道:`beta` 公开测试版已发布:是 @@ -30,7 +30,7 @@ JSRay Core 是独立的 JavaScript 原生代码渲染内核。平台插件(包 `version_compare()` —— 字符串排序会把 `0.0.10` 排在 `0.0.2` 前面。 ``` -0.0.1-beta.1 … 0.0.1-beta.5 → 0.0.2-beta.1 → 0.0.2-beta.2 → 0.0.3-beta.1 → …… → 0.1.0 +0.0.1-beta.1 … 0.0.1-beta.5 → 0.0.2-beta.1 … 0.0.2-beta.3 → 0.0.3-beta.1 → …… → 0.1.0 ``` `0.0.1` 这条线在 beta.5 结束。`0.1.0` 才是脱掉 beta 标签的地方,因此 `0.0.1` diff --git a/integrity.json b/integrity.json index d46d0d0..dd3fe03 100644 --- a/integrity.json +++ b/integrity.json @@ -1,10 +1,10 @@ { "project": "jsray", - "version": "0.0.2-beta.2", + "version": "0.0.2-beta.3", "algorithm": "sha256", "note": "Base64 SHA-256 digests of the released Core assets. Integrations copy the relevant digest at sync time and verify their bundled snapshot against it.", "files": { - "dist/jsray.js": "sha256-FAodgz8GT5uEr//Gd7lY6pbSBtbIZzzYHIitDfEqkVg=", + "dist/jsray.js": "sha256-yYHHNdRaH/YE1ohX6y8lwRO3IYpGp4Fn/BMhROBxtGk=", "dist/jsray.css": "sha256-6Fuva+aZwCcmltNi2oN+1yWIJoKE+1rLpUxZvD9iutc=", "dist/themes/aurora.css": "sha256-S8X+R8XZNC8WRdHOen839zMkPxVFol6PPTrpZibbeJA=", "dist/themes/default.css": "sha256-vENOigRjwn1hW6wPjdM4tbZ58Ja44FMsa+akavPiMSI=", diff --git a/package.json b/package.json index 623ec14..9bd097f 100644 --- a/package.json +++ b/package.json @@ -1,6 +1,6 @@ { "name": "@jsray/core", - "version": "0.0.2-beta.2", + "version": "0.0.2-beta.3", "description": "JavaScript-native code rendering kernel with 23-class token semantics and pluggable themes.", "author": "Jie ", "license": "MIT", diff --git a/src/jsray.js b/src/jsray.js index d795c05..985f414 100644 --- a/src/jsray.js +++ b/src/jsray.js @@ -1865,7 +1865,7 @@ * Runtime version, for shell/core compatibility negotiation. * Must match version.json — tools/check-versions.mjs asserts it. */ - version: '0.0.2-beta.2', + version: '0.0.2-beta.3', languages: G, normalizeLanguage, detectLanguage, diff --git a/tokens.json b/tokens.json index b0b2cd1..e01a12a 100644 --- a/tokens.json +++ b/tokens.json @@ -1,7 +1,7 @@ { "name": "JSRay", "author": "Jie", - "version": "0.0.2-beta.2", + "version": "0.0.2-beta.3", "description": "Default palette · 23 token classes · 6 identifier families visually separated", "philosophy": { "identifier-families": { diff --git a/tools/hooks/commit-msg b/tools/hooks/commit-msg index 1fddf3f..f909341 100755 --- a/tools/hooks/commit-msg +++ b/tools/hooks/commit-msg @@ -33,9 +33,15 @@ case "$SUBJECT" in esac # A bare version number names the release without saying anything about it, -# and it lands on every file the release touched. -if printf '%s' "$SUBJECT" | grep -qE '^v?[0-9]+\.[0-9]+\.[0-9]+([-.][0-9A-Za-z]+)*$'; then - fail "a version number is not a description of the change" +# and it lands on every file the release touched — which is where it is most +# visible and least useful: GitHub prints the subject beside every path. +# +# One leading word does not rescue it. `Release 0.0.2-beta.2` slipped past the +# bare-version pattern and did exactly what the bare version would have done, +# on twelve files, permanently — a released commit cannot be reworded, because +# the tag points at it and this project does not rewrite published history. +if printf '%s' "$SUBJECT" | grep -qiE '^(release|releasing|bump|bumping|version|publish|publishing|tag)?[[:space:]]*v?[0-9]+\.[0-9]+\.[0-9]+([-.][0-9A-Za-z]+)*$'; then + fail "a version number is not a description of the change — say what the release brings" fi # The merge appends the pull request number. Typing it produces `(#6) (#6)`, diff --git a/types/jsray.d.ts b/types/jsray.d.ts index 08c9c4c..efdddfb 100644 --- a/types/jsray.d.ts +++ b/types/jsray.d.ts @@ -24,7 +24,7 @@ declare namespace JSRay { /** A renderer-agnostic stream produced by `tokenize`. */ type TokenStream = Array; - /** Runtime version string, matches version.json (e.g. "0.0.2-beta.2"). */ + /** Runtime version string, matches version.json (e.g. "0.0.2-beta.3"). */ const version: string; /** Grammars for every registered language, keyed by name and by alias. */ diff --git a/version.json b/version.json index 725543d..d3d62bb 100644 --- a/version.json +++ b/version.json @@ -1,7 +1,7 @@ { "project": "jsray", "name": "JSRay Core", - "version": "0.0.2-beta.2", + "version": "0.0.2-beta.3", "channel": "beta", "publicBetaReleased": true, "notes": "Standalone JavaScript-native code rendering kernel. JSRay is planned as a fully open-source ecosystem with Core, official integrations, and community integrations." diff --git a/vocabulary.json b/vocabulary.json index 7457665..e7c3976 100644 --- a/vocabulary.json +++ b/vocabulary.json @@ -1,6 +1,6 @@ { "project": "jsray", - "version": "0.0.2-beta.2", + "version": "0.0.2-beta.3", "description": "Machine-readable token vocabulary: the three-name lock-step every JSRay surface shares. A palette key maps to one CSS custom property (--jr-) and one runtime class (tk-).", "tokens": { "keyword": "keyword",