Skip to content

v0.4.1

Latest

Choose a tag to compare

@github-actions github-actions released this 14 Sep 20:01
· 15 commits to main since this release

v0.4.1 (2026-09-14)

This release is published under the MIT License.

Bug Fixes

  • github: Stop a bearer token following a redirect off its origin (a0cbd44)

urllib.request carries Authorization to the new host. Measured on 3.11, 3.13 and 3.14 with two local servers: a bearer sent to the first arrives intact at the second on all three, so no floor bump retires this.

It is reachable rather than theoretical because API is a reassignable module attribute and headers is caller-supplied.

_CredentialScopedRedirects drops the header when scheme+authority changes, and the opener is built once. Port counts, so two ports on one host are two origins.

CLAUDE.md records why httpx2 was weighed and declined: six packages and about 57,000 lines, into five consumers that declare no HTTP client, to serve one JSON GET that downloads nothing.

Chores

  • Sync the generated CI config to toolchain 20 (874320f)

The stamp moves to 20, carrying generator changes made earlier and never fanned out: one comment names ruff as an installed tool, and the mypy opt-in comment states what decides it rather than what used to.

  • precommit: Read dot-named tracked files with -H (289f212)

codespell skips any file whose basename starts with a dot and exits 0 rather than reporting it read nothing, so .pre-commit-config.yaml and .editorconfig sat outside the check this hook installs.

  • precommit: Regenerate at forge toolchain 21 (a4382d1)

Puts codespell's en-GB_to_en-US dictionary on the hook, so American spelling is gated at commit rather than left to habit, and excludes delimited data files, whose values are the record rather than prose.

  • precommit: Regenerate at forge toolchain 23 (dbb297e)

Drops the en-GB_to_en-US dictionary from codespell. A commit cannot stop a British spelling being written, only sweep one that already exists; the british-spelling validator reports it on the line as it is typed.

  • precommit: Regenerate at toolchain 20 (4ff9abc)

The generated comment text was rewritten. The prose now describes each check in terms of the repo it runs in, rather than the wider set of repos the file is copied across. Two counts, a registry key and a sibling repo's name are gone from it, and a third-party module is now described by what it is instead of being named.

No hook, no rev pin and no setting changed. Only comment lines differ.

  • precommit: Regenerate the forge-managed configs (3b6be8f)

Brings the generated pre-commit config and the tool configs it reads up to the current templates.

markdownlint and prettier move to their YAML spellings. Both tools read those, and YAML can carry the comment marking the file as generated, which the JSON spelling cannot.

  • pyproject: Resync the standard tool sections (d689dfa)

Updates the comment above the managed-key record to describe what the record is for without naming the generator's command.

Continuous Integration

  • release: Queue release runs per branch rather than racing them (a5bc209)

Two pushes to main inside one run's window raced: the second moved the branch while the first was computing a version, so the release push landed on a ref that had already moved and the run failed on a non-fast-forward. The later run cut the correct tag, which makes the failure harmless and red.

Documentation

  • Spell canonicalized the American way (2904307)

Missed by codespell's dictionary and by the stem list, which only find stems someone chose in advance. An enumeration of every -ise/-isation candidate in the tree found it.

  • Use American spelling in comments and prose (1fdcee9)

The fleet standard is American spelling in prose and identifiers alike, gated at commit by codespell's en-GB_to_en-US dictionary. Every hit here is a comment, a docstring or a README line; no identifier, API field or test name changes.


Detailed Changes: v0.4.0...v0.4.1