Skip to content

BearBrowser v150.0.6 — first cut through the promotion gate

Choose a tag to compare

@mdheller mdheller released this 04 Aug 06:56
· 8 commits to main since this release
931ef5b

BearBrowser v150.0.6 — first release cut through the promotion gate

This is the first release with Info.plist CFBundleShortVersionString == 150.0.6. Prior releases (v150.0.1 → v150.0.5) shipped Info.plist stuck at 150.0.1 because nightly artifacts were externally relabeled and there was no release-build path. Root cause closed in #148 (split upstream Firefox VERSION from BEARBROWSER_VERSION).

Self-heal architecture landed (#142)

  • promotion-gate.yml — release-publish event → downloads real artifacts, runs verify-package.sh + Info.plist version=tag + update-check hygiene grep. Failure → marks release prerelease + files issue → publish-latest-json sees no /latest.
  • watchdog-latest-release.yml — 6h re-verify of whatever /latest resolves to.
  • rs-mirror-preflight.yml — PR-time WIF handshake + gs list + write-perm round-trip.
  • main-branch-red-watchdog.yml — 3h scan; one deduplicated issue if any workflow on main red > 6h.
  • packaging-and-update-tests.yml — runs the two unit-test suites below.

Unit tests covering exact bug classes that shipped v150.0.1 → v150.0.5

  • test_bearbrowser_patches.py — actors alpha-sort (killed 3 nightlies), sweep NameError (nonlocal missing), pref-line round-trip (malformed prefs).
  • test_update_check.mjs — semver table incl. -rc1 suffix, asserts credentials:"omit" AND referrerPolicy:"no-referrer" on the SAME fetch call.

Adversarial-review culture

  • .github/PULL_REQUEST_TEMPLATE.md — 8-item checklist encoding what manual review keeps catching.
  • .github/CODEOWNERS — forces review request on load-bearing gate files.
  • docs/RETROSPECTIVE-2026-07-30.md — the ten incidents, why CI missed each, systemic gaps.

Branding + polish integrated

  • Cockpit tab title — was SocioProphet Web (upstream client-vue); now BearBrowser Cockpit via post-build rewrite that fails the build if the rewrite misses.
  • Start-page Cockpit tile — was pointing at https://app.socioprophet.ai (remote SaaS!); now resource://bearbrowser-cockpit/index.html.
  • New-tab wordmark — swapped emoji 🐻 for the branded SVG (branding/bearbrowser.svg).
  • Info.plist version__BEARBROWSER_VERSION__ sentinel + release-time gate. Every consumer script updated (prepare-macos-app-bundle, source-build, overlay-binary, build-native-shell).
  • Hamburger appMenu — added a BearBrowser section with BearNet / BearTrap / BearWall / Cockpit. Reachable without knowing resource:// URLs. Was zero entries — Windows/Linux users had no UI entry.

Release-build path (#148)

Nightly workflows now accept workflow_dispatch input release_version. This artifact was built via:

gh workflow run nightly-dmg.yml   --ref main -f release_version=150.0.6
gh workflow run nightly-linux.yml --ref main -f release_version=150.0.6

Verifiable

  • Package gate: 15/15 static assertions on the shipped artifact (local pre-verify + promotion-gate CI).
  • Info.plist CFBundleShortVersionString == 150.0.6 == release tag (asserted by promotion-gate.yml before latest.json publishes).
  • Update-fetch hygiene keywords colocated on the same call (asserted in-shipped-code by promotion-gate.yml).

SHA256

  • BearBrowser-150.0.6-macos.dmg 052a3125d466b5bf43bbfacf1cee37eed443e77f5ba57a747b48661ebf4cfbe9
  • BearBrowser-150.0.6-linux-x86_64.tar.xz 7bf63da3a21b181a2cf63a1f9d5a91d5583c40e13073608cf3b122e4e2e31d3c