Skip to content

Releases: Oxelio/forge-publish

v2.3.0

Choose a tag to compare

@forge-publish-release forge-publish-release released this 06 Oct 20:34

v2.3.0 (2026-10-06)

This release is published under the Apache-2.0 License.

Continuous Integration

  • Test supported Forgejo lines weekly (#70, a945794)

Documentation

  • repo: Document squash-only pull request policy (#71, 3156785)

  • security: Add private vulnerability reporting policy (#69, ba0a5fd)

Features

  • distribution: Publish validated releases to PyPI (#72, dabb623)

Detailed Changes: v2.2.1...v2.3.0

v2.2.1

Choose a tag to compare

@forge-publish-release forge-publish-release released this 06 Oct 09:44

v2.2.1 (2026-10-06)

This release is published under the Apache-2.0 License.

Bug Fixes

  • security: Remove plaintext npm token storage and document CodeQL (#68, 9cf620d)

Detailed Changes: v2.2.0...v2.2.1

v2.2.0

Choose a tag to compare

@forge-publish-release forge-publish-release released this 05 Oct 19:04

v2.2.0 (2026-10-05)

This release is published under the Apache-2.0 License.

Build System

  • deps: Generate universal tooling constraints (59b5c2b)

Chores

  • deps: Bump actions/attest from 4.2.1 to 4.2.2 (a18bc84)

Continuous Integration

  • integration: Restrict Forgejo exposure and token scope (c136511)

  • types: Add a reproducible Pyright baseline (686835d)

Features

  • release: Publish a validated runtime SBOM (c927e77)

Detailed Changes: v2.1.0...v2.2.0

v2.1.0

Choose a tag to compare

@forge-publish-release forge-publish-release released this 05 Oct 13:31

v2.1.0 (2026-10-05)

This release is published under the Apache-2.0 License.

Features

  • release: Publish checksums and provenance attestations (58e6aa7)

Detailed Changes: v2.0.0...v2.1.0

v2.0.0

Choose a tag to compare

@forge-publish-release forge-publish-release released this 05 Oct 13:09

v2.0.0 (2026-10-05)

This release is published under the Apache-2.0 License.

Bug Fixes

  • npm: Enforce safe pack scripts with npm 11 (c9971a2)

Chores

  • npm: Checkpoint issue 40 pending compatibility decision (6dcffeb)

Detailed Changes: v1.0.6...v2.0.0

v1.0.6

Choose a tag to compare

@forge-publish-release forge-publish-release released this 04 Oct 02:19

v1.0.6 (2026-10-04)

This release is published under the Apache-2.0 License.

Bug Fixes

  • deb: Guard parser errors with bounded fuzz coverage (3a8ff82)

Detailed Changes: v1.0.5...v1.0.6

v1.0.5

Choose a tag to compare

@forge-publish-release forge-publish-release released this 04 Oct 01:47

v1.0.5 (2026-10-04)

This release is published under the Apache-2.0 License.

Bug Fixes

  • config: Handle URL parser errors (83a08b5)

Detailed Changes: v1.0.4...v1.0.5

v1.0.4

Choose a tag to compare

@forge-publish-release forge-publish-release released this 04 Oct 01:36

v1.0.4 (2026-10-04)

This release is published under the Apache-2.0 License.

Bug Fixes

  • deb: Handle malformed tar extension errors (db658fa)

Detailed Changes: v1.0.3...v1.0.4

v1.0.3

Choose a tag to compare

@forge-publish-release forge-publish-release released this 04 Oct 01:22

v1.0.3 (2026-10-04)

This release is published under the Apache-2.0 License.

Bug Fixes

  • client: Reject package API redirects (08de9db)

  • deb: Bound control archive decoder memory (9722a32)


Detailed Changes: v1.0.2...v1.0.3

v1.0.2

Choose a tag to compare

@forge-publish-release forge-publish-release released this 04 Oct 00:15

v1.0.2 (2026-10-04)

This release is published under the Apache-2.0 License.

Bug Fixes

  • deb: Bound debian-binary member reads (0621f04)

Chores

  • Ignore XML coverage report (fd31172)

Continuous Integration

  • Add dependency review gate (b9b546a)

  • Export XML coverage report (78a943f)

Documentation

  • Document dependency review gate (2fa3049)

Detailed Changes: v1.0.1...v1.0.2