Skip to content

Releases: My-Denia/WuwaTerm

v0.6.0

Choose a tag to compare

@github-actions github-actions released this 05 Oct 05:36
cfe07f7

0.6.0

Highlights

  • Site: Chinese and English interface support, plus a full Markdown review-report export.
  • Site: filter and navigate findings, then jump to exact source or target spans.
  • Data: the Arikatsu 3.7.0 candidate contains 11,329 extracted records.

Added

  • Site: the whole interface renders in Chinese and English. A topbar toggle
    switches in place without reloading, keeps the manuscript, choices, active
    finding, expansion state and report currency, and sends no request. The
    preference persists in one wuwaterm-lang cookie read server-side, so the
    first paint matches the choice with no hydration mismatch; first visits
    default to Chinese and missing translations fall back to Chinese copy.
    Interface language never changes the manuscript, translation direction,
    terms or evidence. The storage scanner allows exactly that one
    content-pinned cookie write and rejects everything else.
  • Site: the review workbench exports a readable Markdown snapshot of the
    full report (wuwaterm-report.md) beside the manuscript JSON, result JSON
    and translation TXT. It is generated locally without requests, is never
    clipped by the findings filter, and states the report's own rule version,
    dictionary revision, source commit, revisions and request id — never the
    app version. Current, stale-edited and imported-untrusted reports carry
    distinct wording; zero findings and zero coverage keep their true meaning
    and nothing certifies sentence meaning. User text is rendered as literals
    inside code spans and fences, so report structure, links and HTML cannot
    be forged.
  • Site: npm run test:built runs the landing, review-v2 journey,
    shared-quota accounting, parser-rejection, 404, redaction and fail-closed
    checks against the real production build artifact (dist/) through the
    wrangler test harness with a synthetic upstream and local D1 — no real
    model calls and no beta quota. WUWATERM_BROWSER_BUILT=1 npm run test:browser serves the built bundle to the Playwright suite instead of
    the dev server, and CI runs both.
  • Site: a review report with several findings can be filtered by verdict,
    stepped through with previous/next, and jumped to an exact source or target
    span. Candidate source file and id expand locally. Filtering, navigation,
    jumps, and that expansion do not send a review request or change the
    report, choices, manuscript, or export.
  • Site: the public page can show the dictionary version reported by the
    service that is actually running. The panel stays unread until the visitor
    opens it, so a page view does not spend a meta admission. The site accepts
    the current /v1/meta body and a later body that adds game version,
    resource version, and changelist. Absent version fields and a failed read
    stay unknown; the page does not fill them from the repository pin.
  • API: GET /v1/meta adds source_game_version, source_resource_version,
    and source_changelist from the open database. A database that never
    recorded those keys returns null. The route does not copy the active source
    profile.

Fixed

  • Site: imported CRLF manuscripts now locate the exact source and translation
    terms and record manually selected alignment ranges in the report's original
    coordinates. Saved manuscript and translation bytes retain their line endings.
    The English header also wraps within narrow content widths, including a
    390-pixel viewport with a classic scrollbar.
  • Site: a finding displayed after a verdict filter hides the previous active
    finding now becomes the navigation selection. Returning to a broader filter
    preserves it; an empty filter retains the last selection without displaying
    a finding. Navigation remains local and does not change report exports.
  • Site: replace the vulnerable braces resolution with a transparent,
    repository-owned 3.0.3 security patch that bounds nested pattern and direct
    AST traversal. Both build/lint dependency paths use it; the audit policy is
    unchanged. Keep the temporary fork until a verified upstream fix can replace it.
  • Site: pin Next.js to 16.3.6, the patched release for
    GHSA-vcvr-r3jv-pc5j in Node.js next/og image generation. Refresh only
    its locked runtime packages and platform compilers; the site continues to
    use its static Open Graph image.
  • Site: the locked brace-expansion copies move to 1.1.21 and 5.0.12, the
    patched releases for GHSA-6j4f-fj2g-mc7p, GHSA-qhr7-859c-m2p7, and
    GHSA-q2hr-2g5m-vwhr. The two copies stay on their existing major lines, and
    no direct site dependency changes.
  • Site: sending a translation to review now preserves an identical manuscript,
    asks before replacing existing work, and keeps a recoverable undo snapshot.
    Cancelling a handoff leaves any running check intact; replacing a manuscript
    rejects late results from its previous check.

Game Data

  • data: pin Arikatsu 3.7.0 — the active source profile moves to Wuthering
    Waves 3.7.0 / resource 3.7.8 / changelist 8975829 at exact upstream commit
    9218d612ad815e398e064e577e42aaf878899968 (previously 3.6.0 / 3.6.4 /
    8464573 at 6ce8d5eda49f2930da84d8846c144432142c7465). The upstream README
    at that commit labels the checkout Global / Release; that label is the data
    repository's own status line. The candidate built from that checkout carries
    11329 extracted records, up from 10951, with 378 added terms, 0 removed and
    1 changed zh/en pair. The removed set is empty because the diff matches
    source keys: nothing present at 3.6 was dropped. The one change is an
    English spelling correction on the existing speaker row
    Speaker_800543_Name: Panicked Lolo Logistics Staff becomes
    Panicked Lollo Logistics Staff. Category deltas are echo +26, item +60,
    location +17, resonator +5, skill +20, sonata +3, speaker +245 and weapon +2.
    New resonator source rows are not all new names: 心 / Hsin and
    锁暝 / Suoming already occurred in 3.6, 维里奈 / Verina gains another
    source key, and the new strings are 棠宁 / Tangning and
    心狐·漂泊者 / Moon Fox: Rover. Offline gates (verify_db.py,
    verify_seed_terms.py, verify_exact_hits.py, verify_idempotent_build.py)
    pass on this candidate.
  • The required representative exact pair stays 景燃 -> Jingran. It was
    re-measured on the 3.7 candidate and is still single-valued in both
    directions. 穗穗 -> Suisui stays retired for the same reason as in 3.6.
    棠宁 -> Tangning is a new pair that is also single-valued both ways; it
    is the measured new-term sample, not a second required check.
  • A 3.6 review manuscript does not keep its certification under this
    dictionary. The content-derived dictionary revisions differ, a saved 3.6
    resolution context is rejected as stale by review-v2, and the site
    manuscript reconciler marks the imported choice pending until the user
    confirms it against the fresh basis. A fresh check on the 3.7 candidate
    can accept the same sentence once its context carries the new revision.
  • Generated databases and raw game data are excluded from release artifacts.
    Operators build terms.db locally from the pinned source.

Supported Game Data

Validation

Every asset in this release was built and checked by the release
workflow from the exact commit named below:

  • source commit: cfe07f7bb90cf0555755cfabae28eb6f3eed86c9
  • python -m build, python -m twine check --strict dist/*
  • python scripts/check_package_artifacts.py dist/*.whl dist/*.tar.gz
  • clean-venv install, import and CLI smoke for both the wheel and the sdist
  • desktop client test suite on Windows, then the packaged executable's
    own --self-check start-up rehearsal
  • sha256sum -c SHA256SUMS over the downloadable build outputs

Privacy And LLM

Exact database hits do not call the LLM. Free-text sentence translation
can call an OpenAI-compatible endpoint only when the operator configures
one. Do not include tokens, API keys, chat IDs, owner IDs, .env files,
runtime settings, deployment logs, or host names, addresses and paths
that identify a deployment in release materials.

Assets

This release attaches five files:

  • SHA256SUMS
  • WuwaTerm-0.2.0-windows-x64.zip
  • release-manifest.json
  • wuwaterm-0.6.0-py3-none-any.whl
  • wuwaterm-0.6.0.tar.gz

Verify the downloads with sha256sum -c SHA256SUMS.
release-manifest.json records the source commit, the client version,
the data pin and the container image digests this release was built from.

The Windows desktop client in the zip is UNSIGNED: no code signing is
performed on it at any point. Windows SmartScreen will warn about an
unrecognised publisher; continue through More info then Run anyway only
if you trust this download, after checking its checksum.

Container images built from the same commit. The tags listed here are
the immutable sha tags pushed while this release was still a draft.
The vX.Y.Z and X.Y tags are applied to these exact digests only
after a maintainer publishes the draft:

  • ghcr.io/my-denia/wuwaterm:sha-cfe07f7 (digest sha256:4af3630238944718fe7673343b5e4c1304333271076c4c80e68029503ebc1ab9)
  • ghcr.io/my-denia/wuwaterm-builder:sha-cfe07f7 (digest sha256:08aa538dbaf50d3b36830ea896f3dfc4b09d06d6ea7b5528db64cb4fddccba75)

The runtime image needs a locally built terms.db; the builder image is
what builds it. Verify the image pull works for you before relying on it;
if it is denied, build the images from a source checkout at this tag.

Distribution Boundary

This release distributes source code, the Python package artifacts, the
desktop client binary and container images. It does not distribute
generated SQLite databases, generated TextMap files, or Wuthering Waves
game data. The MIT license covers this project's sou...

Read more

v0.5.0

Choose a tag to compare

@github-actions github-actions released this 13 Sep 12:14
e00afb6

0.5.0

The public product and main catch up to a tagged release. WuwaTerm is an
unofficial, independent fan project: look up official Chinese and English
Wuthering Waves terms, translate a sentence with those names locked, or review
a translation you already have.

Try it: https://wuwaterm.denia-official.chatgpt.site (anonymous public beta,
one shared first-come pool, no SLA). Windows client:
WuwaTerm-0.2.0-windows-x64.zip on this release (unsigned). Self-host and
docs: docs/self-hosting.md and
docs/README.md.

Highlights

  • Public beta. No-account lookup, term-locked translation, and review on
    the shared site above (#96, #98, #104, #105, #109).
  • Review workbench. Paste a source string and an existing translation;
    dictionary-first findings, no model call (POST /v1/reviews; default
    review-v1, opt-in review-v2) (#110).
  • Resumable manuscripts. Save or import a local bilingual draft and recheck
    current dictionary evidence before reusing saved choices (#111).
  • Bidirectional term locks. English-to-Chinese placeholder instructions
    keep locked tokens for official-term restoration (#108).
  • API and deploy. /v1/terms returns the backend-ranked exact-to-fuzzy
    list (the unpublished 0.4.1 package line). Transactional runtime-only deploys
    can update bot and API without rebuilding the terminology database (#97,
    #107).
  • Repository front door. Bilingual landing READMEs and a docs index (#112).

Also in this release

  • Owner chat allowlisting is /grant; /authorize is gone (#95).
  • The desktop client's CJK-literal gate covers the whole ui/ package (#93,
    #94).
  • GHCR vX.Y.Z and X.Y image tags are applied only after this GitHub
    Release is published; a discarded draft leaves only sha-<7> registry tags
    (#88).

Supported Game Data

Validation

Every asset in this release was built and checked by the release
workflow from the exact commit named below:

  • source commit: e00afb63b6e045785f144c662a53856c0a81a15e
  • python -m build, python -m twine check --strict dist/*
  • python scripts/check_package_artifacts.py dist/*.whl dist/*.tar.gz
  • clean-venv install, import and CLI smoke for both the wheel and the sdist
  • desktop client test suite on Windows, then the packaged executable's
    own --self-check start-up rehearsal
  • sha256sum -c SHA256SUMS over the downloadable build outputs

Privacy And LLM

Exact database hits do not call the LLM. Free-text sentence translation
can call an OpenAI-compatible endpoint only when the operator configures
one. Do not include tokens, API keys, chat IDs, owner IDs, .env files,
runtime settings, deployment logs, or host names, addresses and paths
that identify a deployment in release materials.

Assets

This release attaches five files:

  • SHA256SUMS
  • WuwaTerm-0.2.0-windows-x64.zip
  • release-manifest.json
  • wuwaterm-0.5.0-py3-none-any.whl
  • wuwaterm-0.5.0.tar.gz

Verify the downloads with sha256sum -c SHA256SUMS.
release-manifest.json records the source commit, the client version,
the data pin and the container image digests this release was built from.

The Windows desktop client in the zip is UNSIGNED: no code signing is
performed on it at any point. Windows SmartScreen will warn about an
unrecognised publisher; continue through More info then Run anyway only
if you trust this download, after checking its checksum.

Container images built from the same commit. The tags listed here are
the immutable sha tags pushed while this release was still a draft.
The vX.Y.Z and X.Y tags are applied to these exact digests only
after a maintainer publishes the draft:

  • ghcr.io/my-denia/wuwaterm:sha-e00afb6 (digest sha256:12ad2ad198aa9d7fca1f0f82dc153dcb45bf025a8b98fe0147b9b5739216fc3d)
  • ghcr.io/my-denia/wuwaterm-builder:sha-e00afb6 (digest sha256:3988f9e973f171d60450fd7259de0db5c7e3f0b8629ff12c49e4b5405afe9cfd)

The runtime image needs a locally built terms.db; the builder image is
what builds it. Verify the image pull works for you before relying on it;
if it is denied, build the images from a source checkout at this tag.

Distribution Boundary

This release distributes source code, the Python package artifacts, the
desktop client binary and container images. It does not distribute
generated SQLite databases, generated TextMap files, or Wuthering Waves
game data. The MIT license covers this project's source code only, not
Wuthering Waves game data or in-game terminology.

Known Limitations

  • WuwaTerm is an unofficial, independent fan project. It is not
    affiliated with, authorized by, or endorsed by Kuro Games.
  • Release artifacts remain self-hosting inputs. A separate anonymous
    public beta is available at https://wuwaterm.denia-official.chatgpt.site;
    it uses one shared, first-come pool and has no SLA or per-visitor
    fairness guarantee.
  • Live Telegram operation requires maintainer-provided credentials and
    chat configuration.
  • Free-text sentence translation requires an external OpenAI-compatible
    endpoint.
  • The desktop client is built and tested on Windows x64 only, and it is
    not code-signed.

v0.4.0

Choose a tag to compare

@github-actions github-actions released this 19 Aug 15:38
ad26b56

0.4.0

Presentation, distribution and data release. A third presentation layer — an
owner-private web interface running inside the API process and off by default —
joins the Telegram bot and the HTTP API; the game-data pin moves to Wuthering
Waves 3.6.0 / resource 3.6.4 / changelist 8464573 at upstream commit
6ce8d5eda49f2930da84d8846c144432142c7465; the desktop client becomes 0.2.0 and
is published as a release asset for the first time; and every release asset is
now built by a workflow from one reviewed commit rather than by hand. The
project also gains its governance entries, a generic self-hosting guide separate
from the owner's own runbook, and one command that runs every offline gate.

Game Data

  • data: pin Arikatsu 3.6.0 — the active source profile moves to Wuthering
    Waves 3.6.0 / resource 3.6.4 / changelist 8464573 at exact upstream commit
    6ce8d5eda49f2930da84d8846c144432142c7465 (previously 3.5.0 / 3.5.5 /
    8059200 at dae29691c04ef0f48d0810b5d244fb0b37288c60). The candidate built
    from that checkout carries 10951 extracted records, up from 10691, with 260
    added terms, 0 removed and 6 changed zh/en pairs; the offline gates
    (verify_db.py, verify_seed_terms.py, verify_exact_hits.py,
    verify_idempotent_build.py) all pass on it and diff_terms_db.py reports
    no removed term.
  • The required representative exact pair is now 景燃 -> Jingran, a resonator
    that is new at 3.6 and single-valued in both directions in the built
    database. The 3.5 pair 穗穗 -> Suisui was retired because 3.6 adds a second
    speaker row 穗穗(通讯中) -> Suisui, which makes the reverse direction
    ambiguous and would fail the check on a correct build. The verifier's tests
    gained a case for that failure shape (a second zh row carrying the same en).
  • No production data is shipped by this change: deployments pick the new pin
    up through deploy/vps-update.sh, which refreshes the checkout and rebuilds
    and re-verifies the candidate on the target host.

HTTP API / Web Presentation Layer

  • New: an owner-private web presentation layer. A mobile-first browser
    interface for dictionary lookup and sentence translation, mounted inside the
    API process as a sub-application over the same protocol-neutral pipeline the
    Telegram bot and the HTTP API already use. It is off by default: with
    WUWATERM_API_WEB_ENABLED unset there is no route, no sub-application and no
    entry in the published API document, and the process behaves exactly as it
    did before the layer existed. When enabled it requires a device credential
    held server-side (WUWATERM_API_WEB_DEVICE_TOKEN) and a marker the reverse
    proxy injects on every proxied request (WUWATERM_API_WEB_EDGE_SECRET);
    without that marker it refuses everything, so reaching the loopback port
    directly does not get past the front door. Session lifetime and the ceiling
    on live sessions are WUWATERM_API_WEB_SESSION_TTL_SECONDS and
    WUWATERM_API_WEB_MAX_SESSIONS. The surface ships no page scripts and the
    browser holds only an opaque HttpOnly session cookie. Decision and cost:
    ADR 0014; operation:
    docs/web-presentation-layer.md. The layer
    landed in an earlier pull request without an entry that introduced it; this
    is that entry, written where the surface belongs rather than backdated.
  • Malformed serve-only numeric settings no longer block operator credential
    commands such as device revoke: from_env() now retains their raw forms
    while falling back safely, and serve validates all eight values strictly
    before logging, credential-store initialization, app construction or socket
    serving.
  • TERM_QUERY_MAX_LENGTH is defined once in wuwaterm_api and imported by
    both the JSON routes and the web views (previously 200 vs a local 120).
  • The web surface envelope now matches the mount path exactly or its
    children only, so a future sibling like /wuwaterm-webhooks is not
    rewritten as a web page.
  • Restyled the owner-private web surface (markup unchanged): ink-and-gold
    palette with a sharp 3px geometry, underline tabs, gold provenance heading
    on result cards, gold focus rings, and a brand bar across the viewport top.
    All previous functional rules stand: system fonts only, zero scripts, one
    round trip, 16px inputs, pre-wrap results.

Channel Adapter

  • Capacity-driven channel skips (queue_full, llm_budget) now DM the bot
    owner, rate-limited to one notice per 10-minute window with the suppressed
    count folded in. Content gates stay silent by design; only degradation the
    owner could not otherwise see is reported. The notice carries counts and
    internal reason vocabulary only, never post text, and its own delivery
    failure is swallowed into the log.
  • Edits now yield to new posts near LLM-budget exhaustion: an edit is
    admitted only if the remaining per-minute budget covers its calls plus a
    two-call headroom (skipped:edit_yield). A yielded edit delays refreshing
    an already-delivered translation; a rejected new post would mean no
    translation at all. ChannelRuntime.budget_remaining exposes the read-only
    reading the gate uses; admission itself still goes through reserve.
  • Edit-token bookkeeping is now bounded: tokens share the entry TTL and are
    pruned on begin_edit itself, so edits skipped before any remember
    (content gates) no longer accumulate in-process forever.
  • Reply-index persistence no longer runs on the event loop. Payloads are
    snapshotted on the loop thread and the write (tmp file + fsync + replace +
    directory fsync) is offloaded, single-flight, coalescing multi-chunk bursts
    into the latest snapshot. Sync callers keep the original inline semantics.
  • An edit whose tracked reply still exists but rejects the in-place edit
    ("uneditable", distinct from "gone") now deletes that reply instead of
    leaving it visible but untracked — an orphan that no later edit could ever
    update again. The no-repost-on-gone policy is unchanged.
  • Review follow-ups (PR #76): the capacity-notice cooldown and pending count
    are now committed only after the owner DM actually sends; a transient
    failure keeps the count and re-arms after a 60-second retry delay instead
    of silencing alerts for the whole 10-minute window. A successful notice
    clears only the skips it reported, so skips that arrive while the DM is in
    flight survive into the next notice instead of being silently zeroed.
  • Edit-token registration is deferred to the moment an edit actually starts
    its first LLM call (the dictionary fast path registers just before its
    emit), so an edit rejected by any bail path — edit_yield, queue_full,
    llm_budget, staleness or authorization rechecks — no longer supersedes an
    admitted in-flight edit whose completed translation was then dropped as
    stale with nothing replacing it.
  • The reply index gains aflush(), wired to the application's
    post_shutdown hook: an offloaded save still queued at shutdown is drained
    (and a cancelled one rewritten inline from memory), and the flush waits out
    an executor write already in flight so an older snapshot cannot replace the
    final one on disk. Replies remembered just before exit survive the restart
    instead of causing duplicate translations. The flush also runs when the
    translator close raises (independent finally), and the offloaded writer
    now uses a dedicated single-worker executor whose futures can be awaited
    safely — a job cancelled while still queued raises immediately instead of
    hanging the shutdown flush.
  • The edit budget-yield gate is capped by the configured per-minute
    capacity: at WUWATERM_CHANNEL_LLM_CALLS_PER_MINUTE of 1-3 the
    required+headroom sum is unreachable even on a fresh window, which would
    have yielded every edit forever; a completely unused window now always
    admits one edit.
  • A multi-chunk edit whose later tracked reply rejects edits ("uneditable")
    now deletes that reply instead of dropping it from the rebuilt index while
    leaving it visible — the same orphan the first-chunk path already handles.
    When that delete itself fails, the id stays tracked as a trailing stale
    extra rather than at the chunk position, so the next edit does not map a
    fresh chunk onto the still-uneditable reply.
  • The capacity owner notice now reports per-reason counts
    (e.g. llm_budget ×2、queue_full ×1) instead of labelling the whole
    aggregated count with whichever reason happened to trigger the notice.
  • Web stylesheet: decorative glyphs are literal Unicode again — CSS
    code-point escapes like \25C6 in a plain Python string parse as octal
    control characters, so the heading diamonds and em-dashes rendered as
    mojibake since the restyle.

Telegram Bot

  • The dictionary stage (exact + full-table fuzzy over sqlite) now runs off
    the event loop via the pipeline's existing offload seam, matching what
    the HTTP adapter already did; a fuzzy lookup can no longer stall every
    concurrent handler.

Desktop Client

  • The client is 0.2.0, the first version distributed as a release asset:
    WuwaTerm-<version>-windows-x64.zip, the one-folder build, listed in
    SHA256SUMS. It is not code-signed — SmartScreen will warn on first run,
    and client/README.md says so and shows what to do.
  • Compatibility contract: client 0.2.x speaks HTTP API v1, served by wuwaterm
    0.3.0 or newer. The client checks it on the /v1/meta reply the status view
    already fetches when the owner presses 刷新 — no new request, and none at
    startup
    : an unconfigured client still sends nothing. A server reporting an
    API version this client does not support gets a warning naming both versions,
    while the service facts stay on screen and the client keeps working.

Distribution And Release Pipeline

  • New .github/workflows/release.yml builds every release asset from one
    reviewed commit: the wheel and the sdist (with...
Read more

v0.3.0

Choose a tag to compare

@My-Denia My-Denia released this 12 Aug 05:06
ea3ce17

v0.3.0

API-first release: one protocol-neutral application layer now serves two
presentation adapters - the existing Telegram bot and a new versioned HTTP
API with revocable device-principal authentication - plus a Windows desktop
client that consumes the API. See CHANGELOG.md for the complete list,
including the Upgrading From 0.2.1 section.

Highlights

  • New wuwaterm_api package: a versioned, plain-text HTTP surface
    (POST /v1/translations, GET /v1/terms, GET /v1/meta, plus health probes)
    served by the same dictionary-first pipeline as the bot, with a stable
    error envelope, request ids, per-device rate limits, a committed OpenAPI
    snapshot and a contract drift gate.
  • Revocable device credentials: devices are registered by an operator with
    shell access; the secret is supplied on standard input and only a salted
    scrypt verifier is stored, so the service never produces or prints
    credential material. Structured per-request completion records carry a
    redacted principal and never the credential, the device id, or the
    translated text.
  • Windows desktop client (client/): exact lookup, sentence translation,
    direction control, mid-flight cancellation, service status, and stable
    error rendering. The device credential lives only in the Windows
    Credential Manager. A missing or unusable settings file leaves the client
    in an explicit unconfigured state - the window says which server address
    is in use, or that none is configured - and settings saves are atomic.
  • Deployment: a second, loopback-only Compose service runs the API; the
    transactional updater and rollback cover both serving containers;
    publication happens through a reverse-proxy path route the host already
    serves. SSH remains an operations channel only - it is never the product
    transport, and revoking an API device never touches SSH access.
  • Architecture: docs/architecture.md rewritten for the multi-adapter
    system; new decision records 0009-0012 cover the HTTP adapter,
    device-principal authentication, the client stack, and the transport
    selection with its threat model and migration path.

Supported Game Data

Validation

  • python scripts/check_repo_hygiene.py
  • python scripts/check_non_goals.py
  • python scripts/check_architecture_boundaries.py
  • python scripts/check_api_contract.py
  • python -m pytest
  • Packaging: build + twine check --strict + scripts/check_package_artifacts.py
    • clean-venv install/import/CLI smoke for both the wheel and the sdist

Privacy And LLM

Exact database hits do not call the LLM. Free-text sentence translation can
call an OpenAI-compatible endpoint only when the operator configures one. Do
not include tokens, API keys, chat IDs, owner IDs, .env files, runtime
settings, or deployment logs in release materials.

Assets

This release attaches the audited source-only Python package artifacts built
from the exact release commit: one wheel, one sdist, and SHA256SUMS. Verify
downloads with sha256sum -c SHA256SUMS.

Distribution Boundary

This release distributes source code only. It does not distribute generated
SQLite databases, generated TextMap files, or Wuthering Waves game data, and
no desktop-client executable is attached; the client is built from source
with client/build.ps1 or taken from the CI build artifact.

Known Limitations

  • Self-hosted; no public hosted service is provided.
  • Live Telegram operation requires maintainer-provided credentials and chat
    configuration.
  • Free-text sentence translation requires an external OpenAI-compatible
    endpoint.
  • The HTTP API serves operator-registered devices; there is no public
    registration.

v0.2.1

Choose a tag to compare

@My-Denia My-Denia released this 05 Aug 17:56
310a55e

v0.2.1

Maintenance release packaging post-v0.2.0 production hardening from PRs #41–#45.
Game-data pin is unchanged (Wuthering Waves 3.5.0 / resource 3.5.5 / changelist
8059200 at dae29691c04ef0f48d0810b5d244fb0b37288c60).

Highlights

  • Channel LLM content-shape failures retry once as plain text instead of
    dropping the post; invalid_api_response is split from content-shape
    invalid_response; budget-of-1 deployments remain correct.
  • Inline /tr <text> preserves Telegram rich-text entities; normalization /
    term-lock / fuzzy correctness fixes for wrong translations; delivery and
    observability hardening on linked-channel paths (#41–#43).
  • Maintainer architecture map, ADRs 0001–0008, and fail-closed import-boundary
    guard wired into local validation and CI (#44–#45; no intentional runtime
    behavior change in those two PRs).

Supported Game Data

Validation

  • python scripts/check_repo_hygiene.py
  • python scripts/check_non_goals.py
  • python scripts/check_architecture_boundaries.py
  • python -m pytest
  • Packaging: build + twine check --strict + scripts/check_package_artifacts.py
    • clean-venv install/import/CLI smoke for wheel and sdist

Privacy And LLM

Exact database hits do not call the LLM. Free-text sentence translation can call
an OpenAI-compatible endpoint only when the operator configures one. Do not
include tokens, API keys, chat IDs, owner IDs, .env files, runtime settings, or
deployment logs in release materials.

Assets

This release attaches the audited source-only Python package artifacts built
from the exact release commit: one wheel, one sdist, and SHA256SUMS. Verify
downloads with sha256sum -c SHA256SUMS.

Distribution Boundary

This release distributes source code only. It does not distribute generated
SQLite databases, generated TextMap files, or Wuthering Waves game data.

Known Limitations

  • Self-hosted bot; no public hosted service is provided.
  • Live Telegram operation requires maintainer-provided credentials and chat
    configuration.
  • Free-text sentence translation requires an external OpenAI-compatible
    endpoint.

v0.2.0

Choose a tag to compare

@My-Denia My-Denia released this 17 Jul 15:20
eeb2643

v0.2.0

Production hardening release: Wuthering Waves 3.5 data pin, transactional VPS
deployment, Telegram structural safety, and default CI packaging gates.

Highlights

  • Active source profile updated to Wuthering Waves 3.5.0 / resource 3.5.5 /
    changelist 8059200 at exact upstream commit
    dae29691c04ef0f48d0810b5d244fb0b37288c60, with provenance recorded in
    generated DB metadata and read-only strong candidate verification gates.
  • VPS updates are now transactional around a separately verified candidate
    database and an immutable revision-labelled runtime image, with DB/image/
    pointer rollback and an immutable deployment manifest. Builder containers no
    longer receive the runtime .env.
  • Every Telegram HTML tag, attribute, link, custom emoji id, and entity is
    protected with opaque structural placeholders; structural drift fails closed.
    Bounded linked-channel admission, atomic multi-chunk LLM call budgets,
    post-queue freshness/authorization checks, and privacy-safe outcome telemetry.
  • Default CI now blocks lockfile drift, packaging regressions (wheel/sdist
    build, strict metadata, clean-venv install, content audit), Docker
    runtime/builder boundary breaks, and deploy config/script failures.

Supported Game Data

Upgrading From v0.1.0

  • The deployment target must be a clean Git checkout with origin and main;
    exported non-Git copies are intentionally not deployable. Use
    deploy/vps-update.sh for live upgrades; see docs/deployment.md.
  • Runtime state (chat_settings.json, channel_replies.json) moved from
    data/ to state/; the updater and runtime perform a validated one-time
    migration and never overwrite existing state.
  • The runtime image only runs the bot; data refresh/build/verify commands moved
    to the builder image (wuwaterm-builder).
  • Rebuild the terms database with the 3.5 pin via the transactional updater;
    see docs/data-refresh.md.

Validation

  • python scripts/check_repo_hygiene.py
  • python scripts/check_non_goals.py
  • python -m pytest
  • python scripts/check_package_artifacts.py dist/*.whl dist/*.tar.gz
  • python scripts/verify_db.py data/terms.candidate.db --profile arikatsu

Assets

This release attaches the audited source-only Python package artifacts built
from the exact release commit: one wheel, one sdist, and SHA256SUMS. Verify
with sha256sum -c SHA256SUMS.

Privacy And LLM

Exact database hits do not call the LLM. Free-text sentence translation can
call an OpenAI-compatible endpoint only when the operator configures one. No
tokens, API keys, chat IDs, owner IDs, .env files, runtime settings, or
deployment logs are included in release materials.

Distribution Boundary

This release distributes source code only. It does not distribute generated
SQLite databases, generated TextMap files, or Wuthering Waves game data. The
MIT license covers this project's source code only, not Wuthering Waves game
data or in-game terminology.

Known Limitations

  • Self-hosted bot; no public hosted service is provided.
  • Live Telegram operation requires maintainer-provided credentials and chat
    configuration.
  • Free-text sentence translation requires an external OpenAI-compatible
    endpoint.

v0.1.0

Choose a tag to compare

@My-Denia My-Denia released this 05 Jul 00:58
6d509d0

v0.1.0

Supported Game Data

Validation

Release target: 6d509d0

Local validation on the release-finalization PR branch:

  • .venv/bin/python -m pytest — 361 passed
  • .venv/bin/python scripts/check_repo_hygiene.py — repo hygiene ok
  • .venv/bin/python scripts/check_non_goals.py — non-goal guard ok
  • git diff --check — passed
  • Local tracked-Markdown relative link check — checked 8 Markdown files; local relative links ok

GitHub validation:

  • PR #31 CI run passed on Python 3.11 and 3.12 before merge.
  • Claude review reported no blocking issues on the final PR head.
  • Codex P2 feedback was addressed; the remaining review thread is outdated.

Privacy And LLM

Exact database hits do not call the LLM. Free-text sentence translation can call
an OpenAI-compatible endpoint only when the operator configures one. Do not
include tokens, API keys, chat IDs, owner IDs, .env files, runtime settings, or
deployment logs in release materials.

Distribution Boundary

This release distributes source code only. It does not include generated SQLite
databases, generated TextMap files, or Wuthering Waves game data as release
assets.

Known Limitations

  • Self-hosted bot; no public hosted service is provided.
  • Live Telegram operation requires maintainer-provided credentials and chat configuration.
  • Free-text sentence translation requires an external OpenAI-compatible endpoint.