Skip to content

Releases: Ghost-Assembly/quick-template

v0.1.2: current dependencies and Dependabot checks

Choose a tag to compare

@napalm255 napalm255 released this 03 Oct 23:27
174a20f

Refresh shared dependencies, scanner tools, and SHA-pinned GitHub Actions across the Quick extension fleet.

Update Vitest and its coverage provider together to 5.0.3, ESLint to 10.12.0, eslint-plugin-security to 4.2.0, and globals to 17.13.0. Update Python, uv, Ruff, Trivy, gh, and the pinned mise release while retaining Node 24 LTS.

mise-action 5.0.1 fixes cached-binary verification. CodeQL init/analyze remain on the same 4.38.2 commit. Pages/artifact Actions use current stable pinned commits; download-artifact fails on digest mismatches by default. Dependabot scans root and payload npm directories, and its separate SONAR_TOKEN secret is configured across the fleet.

Validation: full local CI and hosted main CI, CodeQL, and Sonar pass. Main has zero security, reliability, maintainability, hotspot, and duplication metrics; no findings are dismissed. No outdated npm direct dependencies or known npm vulnerabilities remain.

v0.1.1

Choose a tag to compare

@napalm255 napalm255 released this 03 Oct 22:29
40e31d2

Standardize the 33 managed files used by QuickClip, QuickMusic, QuickRem, QuickSpot, QuickTiler, and QuickTS.

  • Use Sonar Free-compatible PR and main analysis with exact-revision, zero-issue/duplication checks and no dismissed findings.
  • Report real JavaScript and Python coverage, including untested files. Shared tooling has 29 behavior tests and 91% line/branch coverage.
  • Install native packaging and SVG test tools in hosted jobs.
  • Scope release artifact permissions and preserve the tested ZIP during promotion.
  • Correct the exact historical public Sonar project-ID classification while retaining all credential rules and seven detection fixtures.
  • Generate consistent lifecycle/development documentation and live README badges; leave GNOME submission version assignment to the Extensions website.

Main CI, CodeQL, Sonar, dependency scans, strict workflow audits, and source/history secret scans passed for 40e31d2. Sonar main metrics confirm zero security, reliability, maintainability, hotspots, and duplicated lines. Consumers pin this full immutable revision.

v0.1.0

Choose a tag to compare

@napalm255 napalm255 released this 03 Oct 18:51

Initial approved canonical tooling for QuickClip, QuickMusic, QuickRem, QuickSpot, QuickTiler, and QuickTS. Includes identical pinned CI, security and Sonar workflows, deterministic packaging, generated common documentation, README badges, and immutable template verification. The release targets the full commit that passed hosted CI and CodeQL.