Skip to content

chore(main): release 0.1.0 - #66

Merged
Tom409114 merged 1 commit into
mainfrom
release-please--branches--main--components--scriptspect
Sep 7, 2026
Merged

chore(main): release 0.1.0#66
Tom409114 merged 1 commit into
mainfrom
release-please--branches--main--components--scriptspect

Conversation

@github-actions

@github-actions github-actions Bot commented Aug 31, 2026

Copy link
Copy Markdown
Contributor

🤖 I have created a release beep boop

0.1.0 (2026-09-07)

Features

  • action: M6 — first-class GitHub Action (#51) (24a5bf8)
  • corpus: M8 — read-only corpus scanner + validation methodology (#52) (3285d58)
  • fixer: M4 — safe fixes with dry-run and idempotency (#49) (a91723b)
  • harden ScriptSpect v0.1 and redesign the homepage (5e85cb4)
  • make corpus scans immutable and source-free (b58ba1a)
  • parser: quote/escape/operator-aware lexer + command IR (M1) (#44) (4292fe3)
  • polish generated terminal demo (eb3e06e)
  • publish generated schema contracts (48a9bbe)
  • release: M7 — SHA-256 checksums, release assets, published-tarball verification (#53) (2b339db)
  • reporter,cli,config: M3 — one command to actionable findings (#48) (ece45da)
  • rules: POSIX command + syntax rules PS010-PS026 (M2 part 2) (#46) (125fdaa)
  • rules: PS040, PS041, PS050 — v0.1 rule set complete (M2 part 3) (#47) (8e23d25)
  • rules: rule engine + PS001-PS003, PS030-PS032 (M2 part 1) (#45) (5b877da)
  • ship a self-contained GitHub Action (39a9201)
  • upgrade homepage and harden release evidence (#78) (e98b418)
  • workspaces: M5 — monorepo discovery + workspace-bin-aware PS040 (#50) (cc67eee)

Bug Fixes

  • action: honor scriptspect.config.json when target/severity inputs are unset (#63) (1a393e5)
  • ci: checksums job tarball path, npm version derivation, and clean v0.1.0 tag (#61) (4fc54ab)
  • ci: configure release-please via config file for initial-version 0.1.0 (#59) (33fc062)
  • ci: job-level hashFiles broke workflow validation (#5) (25839b4)
  • ci: load release gate from current main (#75) (670945f)
  • ci: release-please first release is v0.1.0, not 1.0.0 (#57) (20a9b12)
  • close final spec audit gaps (#80) (c9c671c)
  • close hosted CI regressions (1be4049)
  • contain configuration within project root (a138b13)
  • corpus: make hosted evidence reproducible (#77) (bf37b41)
  • dispatch publishing after durable staging (b9ab682)
  • enforce workspace boundaries and bin visibility (7d69edb)
  • fail closed on invalid workspace manifests (#73) (fbcd988)
  • fail closed on unsafe command rewrites (#76) (3fe958e)
  • fail closed when intent discovery times out (c02d0c9)
  • fully encode scoped package purls (#79) (50d02d4)
  • gate release approval on exact intent (8034e1f)
  • honor reviewed npm integrity modes (ff0827a)
  • iterate hosted Action annotations (98f13a1)
  • keep first release changelog canonical (#69) (4d34f86)
  • keep release cancellation effective (c6f54c8)
  • keep release changelog sections unique (#67) (e9e754b)
  • make fixer writes recoverable and race-safe (0efb7a1)
  • make hosted validation portable (13dfcfc)
  • make release recovery monotonic (bfd2d47)
  • make releases recoverable and tag-bound (069a9a7)
  • match the generated Action summary (dde44ea)
  • model shell-specific script structure (3ea5940)
  • patch esbuild development advisory (#68) (78c5006)
  • reject unsafe config and manifest inputs (0497337)
  • release: accept the CLI version banner in bootstrap checks (#83) (51cc781)
  • release: handle npm's initial latest assignment (#84) (6a0aeb3)
  • require provable executable dependencies (28aeb9a)
  • retain hosted Action summary evidence (9b3ec77)
  • route script rewrites through verified transactions (3244af8)
  • target root scripts during rewrites (dbed173)
  • validate manifest bytes and ambiguous scripts (deeb45e)

This PR was generated with Release Please. See documentation.

Maintainer release verification: npm bootstrap integrity contract reviewed and merged in #88; trusted publisher configured for npm-publish.yml / release; bootstrap disabled. Formal publication authorized.

@github-actions
github-actions Bot force-pushed the release-please--branches--main--components--scriptspect branch 2 times, most recently from e917a8a to dd93506 Compare August 31, 2026 22:43
@github-actions
github-actions Bot force-pushed the release-please--branches--main--components--scriptspect branch 3 times, most recently from 4329ca8 to 020cbde Compare September 1, 2026 00:08
@github-actions
github-actions Bot force-pushed the release-please--branches--main--components--scriptspect branch 2 times, most recently from 85fb5b7 to 3bf95fc Compare September 1, 2026 01:43
@github-actions
github-actions Bot force-pushed the release-please--branches--main--components--scriptspect branch 6 times, most recently from dc4af75 to 40b1f03 Compare September 6, 2026 08:43
@github-actions
github-actions Bot force-pushed the release-please--branches--main--components--scriptspect branch from 40b1f03 to 3e161dd Compare September 7, 2026 14:17
@Tom409114
Tom409114 merged commit e1b5905 into main Sep 7, 2026
18 checks passed
@Tom409114
Tom409114 deleted the release-please--branches--main--components--scriptspect branch September 7, 2026 14:20
@Tom409114

Copy link
Copy Markdown
Owner

The untagged, unpublished 0.1.0 candidate is superseded: real release validation found protected-tag writer credentials missing. A replacement bot release PR will include the reviewed workflow fixes. No 0.1.0 npm version or Git tag has been published; retained candidate evidence remains in run 34133881612.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant