v0.25.0
Security & CI hardening release.
Highlights
- CI/security: GitHub-native layer (Dependabot, CodeQL SAST, pip-audit gate, Trivy image scan) plus an in-cluster Jenkins + SonarQube quality gate; Node 20 → Node 24 GitHub Actions bumps.
- Vulnerabilities cleared: all 12 CodeQL code-scanning findings (ReDoS, DOM-XSS, open-redirect) and all 28 Dependabot alerts.
- Desktop: Electron 33 → 43, electron-builder → 26,
tar→ 7 (via override); Linux.desktopwindow/taskbar association. - Docs: new Quality & Security page and README status badges.
Docker image: ghcr.io/leyline-coding/scryme:v0.25.0. Desktop installers are attached by the desktop-release workflow.