Added
- Community control plane for 0.13.0. The new
idiolect-communitycrate and
CLI lifecycle provide versionedidiolect.tomlworkspaces, role-aware
maintainer/consent/vote/steward/hybrid governance, resource-bounded Panproto
consequence analysis, three-state verification gates, P-256/ES256 signed
releases, resumable migration runs, federation dependencies, workspace
diagnostics, and symlink-safe portable exports with SHA-256 inventories. - Four protocol records:
dev.idiolect.changeProposal,
dev.idiolect.communityRelease,dev.idiolect.migrationRun, and
dev.idiolect.federation, with examples and generated Rust/TypeScript types. - The orchestrator catalogs and persists all four lifecycle records. Seven new
generated REST/XRPC queries and matching CLI routes cover open or
community-scoped changes, community releases, active or change-scoped
migrations, and federation relationships by owner or peer. - Observer methods
migration-healthandrelease-adoptionexpose the latest
operational progress, failures, releases, artifacts, dependencies, and
signer breadth by community. - A newcomer-first documentation path explains Idiolect without assuming
ATProto or Panproto knowledge, then completes a workspace, governed change,
signed release, migration, and portable exit. New concept, guide, crate,
manifest, CLI, HTTP, and protocol-record references cover the full surface.
Changed
-
Workspace crates and
@idiolect-dev/schemamove to 0.13.0. -
Panproto pins now target v0.74.4 across the workspace, standalone tutorial
crate, documentation, and vendored-Lexicon provenance. This release supplies
the patchedrustlsline required byRUSTSEC-2026-0285, fixes indexed and
dependent GAT cases, and exposes the canonical protocol registry, shared
resource budgets, and three-valued verification results for future tooling. -
The lexicon-evolution gate now installs Panproto's released CLI artifact and
runs its actualcompatanddiff --optic-kindinterfaces. It retains
per-Lexicon evidence and applies policy to the current optic kinds. -
Dependabot now groups the coupled Oxc crates and the paired ATProto parser
packages so future upgrades can pass CI as coherent dependency sets. -
Reviewed Dependabot updates move the release workflow to the current major
versions of its artifact, container, Node, and release actions; Docker builds
to Rust 1.96; and the optional SQLite stores torusqlite0.39. -
GitHub workflows use the current supported
checkout,setup-node, and
artifact-action majors. Rust audit jobs install exactcargo-auditand
cargo-denyversions instead of inheriting tool changes from action wrappers.
Fixed
- The daily Rust audit no longer resolves the vulnerable
rustls 0.23.43
pulled through the older Panproto revision. - The scheduled Rust audit records a bounded exception for
RUSTSEC-2026-0253: the affectedlru 0.16.4is reachable only through
atrium-commononwasm32, outside Idiolect's native target matrix. The
exception can be removed when Atrium moves tolru >=0.18.2. - The audit workflow now has read-only repository permissions and accurately
reports failures as job results; it no longer claims to create GitHub issues.
Security
What's Changed
- chore(deps): bump docker/setup-buildx-action from 3 to 4 by @dependabot[bot] in #1
- chore(deps): bump actions/download-artifact from 4 to 8 by @dependabot[bot] in #2
- chore(deps): bump actions/setup-node from 4 to 6 by @dependabot[bot] in #3
- chore(deps): bump cid from 0.11.2 to 0.11.3 by @dependabot[bot] in #49
- chore(deps): bump rust from 1.85-slim-bookworm to 1.96-slim-bookworm in /deploy/docker by @dependabot[bot] in #71
- feat: add community infrastructure for 0.13.0 by @aaronstevenwhite in #94
- chore(release): prepare 0.13.0 notes by @aaronstevenwhite in #108
New Contributors
- @dependabot[bot] made their first contribution in #1
Full Changelog: v0.12.1...v0.13.0