Skip to content

brw v0.20.1

Choose a tag to compare

@github-actions github-actions released this 02 Oct 08:52
· 149 commits to main since this release
Immutable release. Only release title and notes can be modified.
v0.20.1
c8e7a9d

Fixed in 0.20.1

Batched assert_value now accepts value: "" on direct CDP and the extension bridge. You can clear a field and verify it is empty; a non-empty field still fails the assertion and stops the batch. Extension 0.7.11 remains current.

Verified with regression tests on both transports, the full task check gate, and a Google Chat create-space dry run on the installed release. No space was created and no message was sent.

Verifying this download

Every file attached below is listed in SHA256SUMS.txt and carries a GitHub build provenance attestation, which ties the file to this repository, this tag and the workflow run that produced it. Run this against anything you download from here:

gh attestation verify brw_0.20.1_macos_universal.pkg --repo Don-Works/brw

Substitute whichever file you downloaded. A checksum alone only proves the file matches this page; the attestation proves the file was built by this repository's release workflow from tag v0.20.1.

A CycloneDX SBOM of the Go dependency graph is attached as brw_0.20.1_sbom.cdx.json.

Installer signing

macOS (universal .pkg)

  • Binaries: ad-hoc signed. The signature identifies no developer.
  • Installer: unsigned. Gatekeeper reports an unidentified developer.
  • Notarization: not performed.

Linux (amd64 .deb / .rpm)

  • Packages: unsigned. There is no distribution GPG key, so dpkg-sig/rpm --checksig have nothing to check. Use the checksums and the build provenance attestation instead.

Linux (arm64 .deb / .rpm)

  • Packages: unsigned. There is no distribution GPG key, so dpkg-sig/rpm --checksig have nothing to check. Use the checksums and the build provenance attestation instead.

Relocatable tarballs (.tar.gz)

  • macOS binaries: ad-hoc signed, which is what lets Apple Silicon run them at all. No Developer ID is involved on this path; scripts/install.sh re-applies the same ad-hoc signature after unpacking. The .pkg signing status is reported separately above.
  • Linux binaries: unsigned, as on the .deb / .rpm path.
  • Every archive ships a matching .sha256. install.sh checks it before unpacking and falls back to SHA256SUMS.txt, and the provenance attestation covers the archive itself.

What's Changed

  • Fix empty-value batch assertions on both browser transports by @revitteth in #49

Full Changelog: v0.20.0...v0.20.1