v1.2.4
[1.2.4] — 2026-09-19
Security
- Updated dependencies containing RustSec fixes:
rmcp1.8,quick-xml0.41,
rustls0.23.45,rustls-webpki0.103.15 and related transitive packages.
The watcher also moved tonotify8.2 andnotify-debouncer-full0.7,
removing the unmaintainedinstantdependency. - Added
deny.toml: CI rejects known vulnerabilities, yanked versions,
unknown sources and unapproved licenses. Duplicate transitive versions are
currently reported as warnings.
Fixed
- The Windows retry-queue test no longer subtracts 600 seconds from the
Instantof a fresh CI runner. Its test clock advances instead, avoiding an
underflow immediately after the virtual machine starts.
Changed
- All Rust code now follows one
rustfmtbaseline; strict Clippy passes for
every target and feature without exemptions. Long internal signatures were
replaced with named parameter structures. Directcode-index-coreusers
must useCodeWriteParams,TextWriteParams,ReadFileOptionsand
GrepBodyOptions; the MCP protocol and JSON responses are unchanged. - The release profile now uses thin LTO, one codegen unit and symbol stripping.
In clean Windows GNU builds both binaries took 4:29 instead of 2:39 to build,
whilecode-index.exeshrank from 53.3 to 37.4 MB andbsl-indexer.exefrom
56.0 to 39.3 MB. Median repeated indexing time for a 1,200-file corpus went
from 1,895 to 1,874 ms (about 1%). - Added a separate CI workflow for regular pushes and pull requests: formatting,
Clippy, doc tests,cargo-deny,nexteston Linux and Windows, and release
builds at the end. Tag-based publication workflows are unchanged. - Added reproducible
tests/mcp_full_acceptance.py: it starts isolated daemon
and HTTP serve processes on a small 1C fixture, verifiestools/list, and
calls all 32 advertised MCP tools. - The Docker context no longer includes local
.cargo/config.toml, and shell
scripts are forced to LF endings. The Linux image therefore builds and starts
consistently from both Linux and Windows checkouts.
Verification
cargo nextest run --workspace --all-features: 883 passed, 0 failed.cargo test --workspace --all-features --doc: passed (one example is marked
ignored).cargo clippy --all-targets --all-features -- -D warningsand
cargo deny check: passed.- Full MCP acceptance of the current release binaries: 32 of 32 tools passed on
Windows GNU and 32 of 32 in the Debian container.
Russian version of the changelog: CHANGELOG.md.
Full Changelog: v1.2.3...v1.2.4