Skip to content

Releases: BatchLang/battest

v1.0.14

Choose a tag to compare

@github-actions github-actions released this 22 Sep 10:04

[1.0.14] - 2026-09-22

Canonical repository is the BatchLang organization.

  • Package metadata, installer, schema id, and docs use
    https://github.com/BatchLang/battest. Security contact is
    BatchLang@proton.me. tboy1337 remains the author and maintainer.
  • GitHub Action consumers should use BatchLang/battest@v1.
  • Standalone battest.exe reports company BatchLang.
  • The batch-spec submodule URL is https://github.com/BatchLang/batch-spec.git.
  • PyPI classifiers include Python 3.15 so pyproject-fmt matches the CI image.
  • Installer lint config disables E047 and W067, matching Blinter 1.1.31, and
    quotes the release marker read from disk.

Removed the CI Dependency Graph snapshot job.

  • advanced-security/component-detection-dependency-submission-action hung until
    the 15-minute job timeout and cancelled the whole workflow after a successful
    1.0.13 release. GitHub's configured pip dependency-graph update remains.

v1.0.13

Choose a tag to compare

@github-actions github-actions released this 30 Aug 19:56

[1.0.13] - 2026-08-31

Pinned vendor batch-spec to 0.70.0.

  • Packaged expansion.yaml now includes command_chaining.close_paren_leftover_in_block
    (leftover text after an unquoted ) that closes an IF/FOR/naked group is a live
    syntax error). Command catalogs and %~ modifier letters are unchanged.

v1.0.12

Choose a tag to compare

@github-actions github-actions released this 23 Aug 15:39

[1.0.12] - 2026-08-23

Removed the README PyPI version badge.

  • The live PyPI version shield lagged behind GitHub tags. README badges are
    Python versions, CI, and license only.

v1.0.11

Choose a tag to compare

@github-actions github-actions released this 23 Aug 15:25

[1.0.11] - 2026-08-23

GitHub Releases no longer attach Python wheels.

  • GitHub Releases attach only the Windows zip. Wheels and sdists still publish
    to PyPI.

v1.0.10

Choose a tag to compare

@github-actions github-actions released this 23 Aug 15:13

[1.0.10] - 2026-08-23

README rewrite and unused spec-exec discovery removal.

  • Rewrote the README around install, fixtures, mocking, CLI, and the GitHub Action.
  • Removed unused CLI --include-spec-exec and load_case(..., include_spec_exec=...).
    Discovery no longer opts into vendor/batch-spec/corpus/exec.

v1.0.9

Choose a tag to compare

@github-actions github-actions released this 19 Aug 20:30

[1.0.9] - 2026-08-20

GitHub Action Marketplace listing and installer-test hygiene.

  • Action name is battest Action with branding (check-square, blue).
  • Installer tests assert the parsed GitHub asset-host allowlist and URI host
    check. The regex timeout test builds its nested-quantifier pattern at
    runtime so CodeQL does not treat those fixtures as URL sanitizers or a
    shipped ReDoS expression.

v1.0.8

Choose a tag to compare

@github-actions github-actions released this 19 Aug 18:17

[1.0.8] - 2026-08-20

Production audit: Job assign fail-loud, env-dump integrity, installer host
allowlist, and packaging/CI hygiene.

  • AssignProcessToJobObject failure is a case ERROR. battest does not resume
    cmd.exe outside the job. The job handle is closed if Popen fails. An
    abandoned process skips rmtree of the workdir. JUnit duration includes
    teardown.
  • After seeding, a non-file env dump path is ERROR before spawn. After a
    finished run, missing or non-file dumps are ERROR when expect.env is set.
    Env dumps, equals_file, and files[] reads are capped at 10 MiB.
    copy: refuses junctions/symlinks whose target escapes the fixture tree.
  • Host environment is inherited except stripped BATTEST_*. CI secrets that
    are not named BATTEST_* can reach the SUT and JUnit. expect_calls is not
    a security boundary; call logs live in the writable workdir.
  • Installer download URLs must be https on GitHub asset hosts. Package smoke
    asserts packaged catalogs and schema. Non-Windows unit coverage does not use
    the 90% floor (Windows jobs still do). PSGallery installs pin exact
    PSScriptAnalyzer and Pester versions.
  • Packaged catalog YAML uses the same bounded loader as fixtures. Regex
    workers get multiprocessing.freeze_support() from execute_case. Invalid
    regex patterns fail immediately without spawning a worker.
  • GitHub Action consumers should use tboy1337/battest@v1. Release CI moves
    that major tag to each v1.x.x GitHub release.

v1.0.4

Choose a tag to compare

@github-actions github-actions released this 19 Aug 13:29

[1.0.4] - 2026-08-19

Production audit: host env isolation, destructive-path warnings, installer
release lookup, CodeQL, and PyInstaller spec cleanup.

  • Inherited host BATTEST_* variables are stripped before the script runs, so
    a runner or CI job cannot leak helper names into the case. Fixture env can
    still set BATTEST_* values.
  • Destructive-internal absolute-path warnings match quoted paths with spaces
    (del "C:\Program Files\x.txt") and switches with a colon
    (del /a:h C:\Windows\Temp\x.txt).
  • Fixture YAML larger than 1 MiB is a schema error at load time.
  • CodeQL Rust analysis fetches the locked stub/ crate graph before init so
    rust-analyzer can expand macros. Actions stay on version tags, not commit
    SHAs.
  • The standalone installer queries GitHub releases/latest instead of paging
    100 releases.
  • PyInstaller spec no longer passes removed WinSxS/cipher Analysis arguments.

v1.0.3

Choose a tag to compare

@github-actions github-actions released this 15 Aug 09:55

[1.0.3] - 2026-08-15

Production audit: installer integrity, Windows device path confinement, and
fail-loud fixture loading.

  • The standalone installer verifies the GitHub release-asset SHA-256 digest
    (digest on the Releases API) after download and before extract. A missing
    digest is a hard failure. The GitHub API request uses TLS 1.2 and a
    battest-installer User-Agent.
  • Fixture script, setup, teardown, copy, equals_file, and
    files[].path values cannot be rooted, cannot contain .., and cannot name
    reserved Windows devices (nul, con, aux, clock$, and the rest).
    JSON Schema patterns match those runtime rules.
  • Unreadable scripts fail at load time instead of skipping tilde warnings.
    Wrapper-relative script names must be ASCII so cmd.exe cannot mis-decode
    the UTF-8 wrapper.
  • Destructive-internal absolute-path warnings also match C:/..., quoted
    targets, and /flag forms such as del /f /q C:\Windows\Temp\x.txt.
  • The uninstaller kill helper is kept in parity with
    scripts/installer_ps/Stop-BattestInstalledProcess.ps1.
  • Stub CLI tests fsync the copied helper and retry ETXTBSY on exec as well
    as copy, so cargo llvm-cov on Linux overlayfs does not fail with
    "Text file busy".
  • CI and Action docs continue to pin GitHub Actions to version tags,
    not commit SHAs.

v1.0.2

Choose a tag to compare

@github-actions github-actions released this 15 Aug 03:54

[1.0.2] - 2026-08-15

Production audit: confinement, mock fail-closed, installer, and release gating.

  • PATH-mocking a cmd.exe internal is a MockError at stub write time, not a
    silent skip, so the Python API cannot run the real internal.
  • Fixture script, setup, teardown, copy, and equals_file paths reject
    drive-relative and other rooted values (C:foo, UNC), not only
    Path.is_absolute().
  • Fixture regex also rejects quantified alternation such as (a|a)*. Nested
    quantifiers and the 512-character cap remain.
  • Uninstaller uses delayed errorlevel after rmdir, exits 1 when removal
    fails, kills only %LOCALAPPDATA%\Programs\battest\bin\battest.exe, and
    matches PATH entries by exact segment.
  • CI reads [project].version with tomllib, including the previous commit's
    pyproject.toml via UTF-8 git show (bytes cannot be passed to
    tomllib.loads). It dogfoods examples against the committed stub before
    rebuilding it, creates the GitHub Release only after wheels exist, then
    publishes to PyPI with twine --skip-existing.
  • JSON Schema rejects reserved device stems, caps regex length, and rejects
    rooted file matcher paths. Editors still require lowercase command names.
  • CI and Action docs continue to pin GitHub Actions to version tags, not commit
    SHAs.