Releases: csnyder256/gba-rom-hack-ide
Release list
v0.3.1
v0.3.1 — verified desktop provenance delivery
This patch completes the desktop distribution introduced in v0.3.0. The original Linux installer publication stopped at attestation generation because the generic v3 attestation action required a custom predicate. v0.3.1 uses the current automatic SLSA build-provenance mode and verifies that path in upstream PR/main CI before a tag is published.
- Publish the Linux AppImage, SHA-256 checksums, SHA-512 update manifest, source metadata and signed GitHub/Sigstore provenance bundle together.
- Exercise real attestation creation and verification against the exact workflow source, using an explicitly labelled non-installer contract fixture. Product installers still receive their own attestations in the release job.
- Keep version checks synchronized across the engine, app, backend and desktop. Native runtime acceptance derives the expected installed version from the packaged metadata.
- Retain the sandboxed desktop, authenticated loopback backend, real WebAssembly gameplay, native project picker, persisted preferences and explicit download/restart update control from v0.3.0.
Install and upgrade
Use the version-specific deployment instructions and desktop guide. Verify the AppImage checksum and gh attestation verify before running it. Save your work before accepting a restart. Projects remain outside the installer.
On Linux systems whose graphics driver cannot draw the emulator canvas, --use-angle=swiftshader selects software rendering; it is a runtime option rather than a global default. Build tooling for source projects remains an explicit prerequisite.
Signing boundary
The Linux bundle carries a verified GitHub/Sigstore provenance attestation. Windows Authenticode and macOS Developer ID/notarization are separate identity systems. Their mandatory signing/preflight workflows remain disabled until the owner configures those identities. No signed Windows/macOS installer is claimed or substituted with an unsigned public download.
The advertisement films, searchable documentation library, roadmaps and release timelines remain local drafts held for Cade review.
v0.3.0
Incomplete desktop distribution preview. The source bundles are available, but Linux installer publication stopped at provenance generation. Use the stable release for the verified desktop distribution.
GBA ROM Hack IDE v0.3.0
Desktop workspace
The packaged desktop runs the actual editor and utility-process backend, with native project/ROM pickers and a bundled runtime. The renderer is sandboxed, isolated from Node, and served with the isolation headers needed by the emulator. Loopback HTTP/websocket access and update IPC are scoped to the desktop session. Project intake and preferences survive ordinary restart and upgrades.
Stable updates
Automatic availability checks, manual download, progress, checksum verification and explicit save/restart confirmation. Ordinary quit does not install an update. Downgrades and prereleases are refused. The real updater is exercised against a controlled local feed, including corrupt-byte rejection; fixtures are never installed.
Distribution and trust
The Linux AppImage ships with SHA-256 checksums, source provenance and a cryptographically signed build attestation. Linux auto-updates verify SHA-512 over HTTPS; verify the build attestation separately. Windows Authenticode installers and macOS Developer ID/notarized DMG/ZIP releases have production pipelines that fail without valid signing identities. Their publication is disabled until those identities are configured. Unsigned verification directories are never published as production installers.
All three desktop operating systems are exercised in CI, including source and packaged API/picker/update UI journeys. The standalone prebuilt release remains available. Existing project files and storage formats are unchanged. Decomp build toolchains and optional local-agent accounts remain separate prerequisites; no ROM is included.
Install and upgrade
See desktop installation and signing details and deployment instructions. Back up projects, keep the prior release, and save editor changes before restarting to update.
Runtime corrections
Compiled modernization assets are included in the package. Native Linux/macOS builds use the installed Bash/make toolchain; Windows retains its MSYS2 configuration. Workspace paths are passed as arguments rather than interpolated into shell commands. An actual make target is exercised in a path containing spaces and an apostrophe.
Runtime compatibility
The desktop and headless engine use the same pinned mGBA 2.5.1 core. A checksum-checked build step preserves the existing shared HEAPU8 memory surface omitted by the upstream JavaScript build. The WASM binary is unchanged. Frame callbacks are installed after the game core exists. The desktop's agent callbacks use its actual local port and an inherited ephemeral session token; redirects cannot forward that token to another origin.
Desktop acceptance runs an original homebrew fixture and checks its rendered pixels, advancing frame count, and shared memory surface. CI uses software WebGL on its virtual display. On Linux displays without a usable GPU backend, launch the application with --use-angle=swiftshader.
v0.2.0
gba-rom-hack-ide v0.2.0 — Compiled local workspace
What changed
- Prebuilt Node 22 workspace download and compiled frontend/backend launcher.
- Hardened tool calls, file boundaries and save behavior from the audited changes.
- Current Fastify/Vite toolchain and emulator fixes.
Install and upgrade
Back up your projects first. No ROMs, BIOS files, extracted commercial assets or user projects are shipped. Node 22 and npm dependency installation are required; optional tile intelligence retains its separate Docker setup.
See deployment instructions and the attached checksums.
v0.1.0
First public snapshot. Decomp project scanning, visual editors, AI agent panel, devkitARM build, in-browser emulator. Tooling only: no ROMs or game data are included.