v2.10.0
v2.10.0
Harden repository upgrades and release publication, enforce branch coverage and secret scanning,
and improve validation on Linux and Windows.
Highlights
- Validate upgrade inputs and provenance, and recover interrupted upgrades.
- Require the exact release-event checks before publishing sealed package assets.
- Enforce coverage and secret scanning with locked, cached toolchains.
- Correct Git Bash path identity and Windows process deadline tests.
Changes
| Reference | Date | Description | Author(s) |
|---|---|---|---|
| ce35f1a | 2026-09-08 | Validate upgrade paths, legacy manifests, payload digests and provenance. | asphyx |
| ce35f1a | 2026-09-08 | Restore interrupted upgrades and report final non-compliance as failure. | asphyx |
| ce35f1a | 2026-09-08 | Bound external commands and stream Git inventory metadata. | asphyx |
| ce35f1a | 2026-09-08 | Require exact release-event checks before publishing package assets. | asphyx |
| ce35f1a | 2026-09-08 | Enforce branch coverage and mandatory secret scanning. | asphyx |
| ce35f1a | 2026-09-08 | Select affected hook checks and validate workflow semantics across platforms. | asphyx |
| ce35f1a | 2026-09-08 | Cache locked dependencies and reduce release validation dependencies. | asphyx |
| 4b381c1 | 2026-09-08 | Accept equivalent Git Bash paths while rejecting redirected hook clones. | asphyx |
| caa282e | 2026-09-09 | Document locked CI caches and focused Windows hook checks. | asphyx |
| 19d84d0 | 2026-09-09 | Measure process deadlines after synchronous startup while preserving timeout and descendant cleanup checks. | asphyx |