Skip to content

v6.1.6

Latest

Choose a tag to compare

@jaredwray jaredwray released this 17 Sep 21:34
· 11 commits to main since this release
Immutable release. Only release title and notes can be modified.
8d1eb25

writr@6.1.6 — 2026-09-17

Supply-chain hardening and unpublished writr-rs fixes; JS engine source is unchanged.

Bug Fixes

  • restore writr-rs goldens on Windows CRLF checkouts — unify CR/CRLF to LF before parse so markdown-rs does not keep CR in mdast text (#516)
  • copy async batch buffer input so callers can reuse the packed buffer after renderBatchBufferAsync (#540)
  • lock down the Node WASI loader: instantiate WASI with preview1 only (no process.env, no filesystem preopens) (#545)
  • bound internal math caches and honor caching: false without clearing other callers' entries (#546)
  • gate Rust/WASM parity and fix MDX rendering compatibility in writr-rs (#547)

Documentation

  • retire obsolete Rust divergence document (#549)

Internal

  • upgrade code quality dependencies (#490)
  • upgrade TypeScript and build tooling (#491)
  • upgrade package manager tooling (#492)
  • upgrade GitHub Actions (#493)
  • upgrade React dependencies (#494)
  • upgrade AI SDK dependencies (#495)
  • upgrade hookified (#496)
  • upgrade js-yaml (#497)
  • upgrade marked (#498)
  • upgrade markdown-it (#499)
  • upgrade tinybench (#500)
  • upgrade workspace code quality dependencies (#501)
  • refresh taiki-e/install-action SHA pin (#502)
  • upgrade napi-rs dependencies (#503)
  • upgrade fancy-regex to 0.19.0 (#504)
  • upgrade rquickjs to 0.12.2 (#505)
  • harden supply chain and CI (#506)
  • stage npm releases via OIDC (#507)
  • record npm stage-only, Drydock, and 2FA (#508)
  • replace dummy secrets in benchmark markdown fixtures (#509)
  • record repository lockdown (#510)
  • upgrade katex to 0.18.2 (AIKIDO-2026-293837) (#511)
  • pin @ungap/structured-clone to 1.3.3 (AIKIDO-2026-11068) (#512)
  • uniquify AI integration check name (#513)
  • replace dummy secrets in harness markdown fixtures (#514)
  • add CODEOWNERS for high-risk paths (#517)
  • bootstrap Aikido Safe Chain (#518)
  • set pnpm trustPolicy to no-downgrade (#519)
  • add Socket Firewall to every job (#520)
  • switch release to pnpm stage (#521)
  • record repository lockdown (#522)
  • pin taiki-e/install-action to an authentic v2.86.5 SHA (#523)
  • disable setup-node cache in deploy-site to prevent cache poisoning (#524)
  • remove property-information override (#525)
  • update katex override to 0.18.7 (#526)
  • remove @ungap/structured-clone override (#527)
  • upgrade code quality dependencies (#528)
  • upgrade TypeScript and build tooling (#529)
  • upgrade package manager and monorepo tooling (#530)
  • upgrade GitHub Actions (#531)
  • pin Dev Container images (#532)
  • upgrade React dependencies (#533)
  • upgrade AI SDK dependencies (#534)
  • upgrade hookified (#535)
  • upgrade js-yaml (#536)
  • upgrade zod (#537)
  • upgrade docula (#538)
  • remove undici override (#539)
  • upgrade markdown-it (#541)
  • upgrade marked (#542)
  • upgrade tinybench (#543)
  • upgrade property-information (#544)
  • compare native Rust and JavaScript rendering (#548)

Notes

  • src/** is unchanged since v6.1.5. The published tarball is still files: ["dist", "README.md", "LICENSE"]; writr-rs/ is not published. Runtime source matches 6.1.5. The tarball-affecting changes are production dependency ranges in package.json (hookified, js-yaml, react, html-react-parser, zod, ai) plus scripts/packageManager. The katex 0.18.7 and property-information 7.2.0 pins live in pnpm-workspace.yaml (this repo’s install), not in the npm tarball.
  • Titles that include (breaking) are upgrades of dev tools or unpublished Rust crates, not writr’s public JS API.

Contributors

Full List of Changes

Full diff: v6.1.5...v6.1.6