You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
This commit was created on GitHub.com and signed with GitHub’s verified signature.
Release Notes
v3.1.2 (2026-05-24)
Fixes
Fix mypy [type-arg] failures on xml.etree.ElementTree annotations that broke CI for every Dependabot PR.
Drop end-of-life Python 3.8 from the CI matrix; supported versions are now Python 3.11 and 3.12.
Security
XML parsing hardened with defusedxml via new safe_xml.py wrapper (XXE / billion-laughs protection).
GitHub Actions pinned to commit SHAs with least-privilege permissions: blocks.
Release workflow now publishes SHA256SUMS.txt alongside binaries.
Added Dependabot config for github-actions and pip ecosystems.
UpdateChecker now validates the owner/repo identifier before issuing HTTP requests.
Project / Licensing
Project ownership consolidated under Meraby Labs.
License re-issued as a proprietary EULA: free for personal non-commercial use; commercial use requires a separate license. The project is not open source.
README rewritten to reflect ownership and licensing.
Removed CONTRIBUTING.md and CODE_OF_CONDUCT.md (external contributions are not solicited).
v3.0.0 (2026-02-07)
Major Architecture
Added version.py as single source of truth for version/build/channel.
Added app_settings.py and update_checker.py to centralize config and updates.
Introduced modular mapping registry (mappings/) with validation:
duplicate targets
circular swaps
category registration and merge checks
Refactored conversion engine to support multi-category conversion in a single pass.
Preserved legacy armor constants and default behavior for CLI backward compatibility.
Mapping Expansion
Added built-in categories:
armor (existing 70 pairs)
thrusters
weapons
functional
Added profile loading system (mapping_profiles.py) and profiles/ auto-discovery.