First published build of the 0.5.2 security line.
The v0.5.2 release workflow failed before building any artifact, so 0.5.2 was never published to PyPI or crates.io. 0.5.3 ships the same runtime code (all 0.5.2 security remediations: delegation chain verification, signed policy activation, segregation of duties, Gate-DB revocation checks for executors, atomic state/stream mutations) with a repaired release pipeline.
Fixed
- Release pipeline: four action pins in
release.ymlreferenced commit SHAs that don't exist upstream. All pins now resolve to real tags. - Tag-exact builds: each release job checks out the release tag.
- PyPI: publishes through Trusted Publishing (OIDC) only.
- crates.io: first publication, from a separate job that uses the configured token.
Changed
- Packaged sources no longer include the
launch/drafts. python-dotenv>=1.2.3.
Install: python -m pip install tempus-ddb==0.5.3
Full details in CHANGELOG.md.