You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
CommonMark Heading Separation: Added missing blank lines before section headers throughout CHANGELOG.md (specifically before [fix/dependency-version-bump], [fix/auto-update], [fix/develop-tunnel-process-teardown], [fix/playground-postman-ux], and [feature/develop-schema-drift-detection]), preventing markdown parsers from swallowing ATX ## headers into preceding list items and restoring clean rendering across the web documentation portal.
Chunked HTTP Response Preview Capture: In proxy.rs, added bounded initial body segment reading with a dedicated constant BODY_CHUNK_TIMEOUT_MS = 150 when headers terminate exactly at the first TCP buffer boundary. This guarantees that modern frameworks like Next.js and Node.js that flush HTTP headers before chunked body data have their initial response payloads captured into responseBodyPreview for schema drift evaluation.
OpenAPI Runtime Ingestion Precedence: In openApiGenerator.ts, reversed captured traffic iteration ([...requests].reverse()) so the latest live responses take precedence over older snapshots when enriching OpenAPI endpoint schemas.
Rust Backend Crates Upgrade: Upgraded reqwest to 0.13 (enabling rustls TLS engine and json/compression features), tokio-tungstenite to 0.30, and base64 to 0.23. Added #[cfg(unix)] guard on test import in tunnel.rs.
Frontend Workspace Modernization: Upgraded React and React-DOM to 19.3.0, TailwindCSS to 4.3.3, @tailwindcss/vite to 4.3.3, Vite to 7.3.6, @vitejs/plugin-react to 4.7.0, and @tauri-apps/* plugins to latest releases (plugin-opener 2.5.5, plugin-process 2.3.1, plugin-dialog 2.7.3, plugin-updater 2.12.0, cli 2.11.5). Pruned unused @tauri-apps/plugin-shell dependency.
CI & GitHub Actions Security Pinning: Updated all action workflows (ci.yml, codeql.yml, prepare-release.yml, release.yml, scorecard.yml) to immutable, latest-release commit SHAs: actions/checkout@v7.0.1, actions/setup-node@v7.0.0, dorny/paths-filter@v4.0.3, swatinem/rust-cache@v2.9.2, github/codeql-action/*@v4.38.2, peter-evans/create-pull-request@v8.1.1, and actions/upload-artifact@v7.0.1.
Dependabot Anti-Spam Grouping & Limits: Enhanced .github/dependabot.yml by grouping GitHub Actions, npm dependencies, and Cargo crates into unified update bundles (actions, npm-dependencies, cargo-dependencies) and setting open-pull-requests-limit: 3 to eliminate multi-PR alert spam.
CodeQL High-Severity Alerts Remediation: Fixed alerts #14 and #15 (js/incomplete-sanitization) in interopUtils.ts by escaping backslash meta-characters (.replace(/\\/g, '\\\\')) prior to escaping quotation marks in cURL header and body argument generation, preventing backslash neutralization attacks.
Desktop Lockfile Audit & Synchronization: Synchronized package-lock.json with desktop workspace dependencies, resolving missing @tauri-apps/plugin-dialog manifest registration with 0 audit vulnerabilities.
Rust Crates Update: Updated 133 Cargo crates in Cargo.lock to latest compatible versions including tauri v2.11.6, tokio-macros v2.7.2, and rustls v0.23.45.
3-Day Cron Pipeline: Replaced weekly Monday schedule across all ecosystems (github-actions, npm, cargo) with a unified 3-day cron cadence (0 6 */3 * *) to establish a continuous, fast-feedback dependency review pipeline.
Desktop Workspace Targeting: Configured package-ecosystem: "npm" to target directory: "/packages/desktop" directly and set versioning-strategy: "increase". This resolves the silent omission caused by the empty root manifest and ensures actual application packages (react, vite, tailwindcss, @tauri-apps/*) receive automated PRs.
CodeQL Action Grouping: Added groups: codeql-action targeting github/codeql-action/* to ensure init, analyze, and upload-sarif are bundled into a single atomic PR, eliminating runtime version skew and CI breakage.
Throttling & Backpressure: Enforced open-pull-requests-limit: 5 across all ecosystems to prevent review fatigue and repository inbox flooding.
Modified Files:
.github/dependabot.yml
CHANGELOG.md
[fix/v0.2.3-version-bump] - 2026-09-21 (Workspace & Studio Version Bump to v0.2.3 for Next Release Cycle)
Feature Summary:
Comprehensive Version Bump to v0.2.3: Synchronized workspace and package manifests (package.json, packages/desktop/package.json, package-lock.json, Cargo.toml, Cargo.lock, and tauri.conf.json) to version 0.2.3.
Native HTTP Network Headers & Diagnostics: Updated Rust client diagnostic banner in storage.rs to Proxync v0.2.3 (Engine: Tauri v2.11 Core). Synchronized frontend diagnostic logging metadata, log session directives, and support bundle fallbacks in App.tsx and logger.ts to v0.2.3-stable.
UI Version Presentation Alignment: Updated SettingsView.tsx default prop to v0.2.3, App.tsx update toast message (v0.2.3), and sidebar engine indicator (v0.2.3-stable).
Recon & Documentation Badge Alignment: Updated README version shield badge and .agents/architecture.json static recon map to reflect version 0.2.3.