Skip to content

Braid v0.2.1

Choose a tag to compare

@Epsirom Epsirom released this 04 Oct 02:23
Immutable release. Only release title and notes can be modified.
fd0fb6d

Braid 0.2.1 is a maintenance release that validates the Pi integration against Pi 1.0.1 and fixes the repository's vulnerable development dependency tree. There are no Braid API or runtime behavior changes from 0.2.0.

Maintenance

  • Upgrade the Pi development dependencies together to 1.0.1 and regenerate the workspace lockfile. Pi's installed minimatch 10.2.6 now resolves the patched brace-expansion 5.0.12; Pi 1.0.1 also removes its published shrinkwrap. Update compatibility fixtures and documentation for the new validation target (#38) — @Epsirom.
  • Add a dedicated dependency-security workflow and npm run audit:dependencies, including development, optional, and peer dependencies. Findings and scanner failures both fail the check, with separate diagnostics and regression coverage (#38) — @Epsirom.

Compatibility and installation

Both packages use 0.2.1, and the Pi package installs the exact matching core dependency. Core requires Node.js 22+; the Pi integration requires Node.js 22.19+ and is tested against Pi 1.0.1.

npm install @chrok/braid@0.2.1
pi install npm:@chrok/pi-braid@0.2.1

Updating Braid does not upgrade a separately installed Pi host. Update that host to Pi 1.0.1 and inspect its own dependency tree. Existing Braid source checkouts need the new lockfile followed by npm ci.

No migration is needed from Braid 0.2.0. For upgrades from 0.1, follow the 0.1 → 0.2 migration guide.

New Contributors

No first-time human contributors in this release.

Validation

222 core tests, 66 Pi tests (including real Pi host sessions with an in-memory provider), both type checks, offline examples, isolated consumer package checks, and package-content inspections. The full dependency audit reports zero known vulnerabilities. The Linux/macOS/Windows CI matrix on Node 22/24, the core-minimum check, and CodeQL pass before release. Paid live provider scenarios were not rerun.

See the changelog and full comparison.