0.2.5 - 2026-08-10
Release Notes
Fixed
- A
release cutcan no longer report success while publishing nothing. After the irreversible
cargo publish, the cargo adapter now confirms the target's own{name, version}is actually
visible on the crates.io index (reusing the bounded index-wait, so normal sparse-index propagation
lag is tolerated) before journaling a publish receipt. A silent no-op upload now fails the cut
closed with no fabricated receipt; a registry outage fails closed distinctly from "reached the
registry, version absent". This closes the real-world failure mode where a downstream cut reported
build ok → publishyet the crate never reached crates.io (cut-noop-self-visibility-check,
surfaced by the first real downstream cut).
Changed
- The release version now has a single source of truth: the workspace manifest.
ossctl release cutpublishes the version already in the tree and derives it fromCargo.toml;--versionis now
an optional confirmation that must equal the manifest version (a mismatch refuses the plan/cut),
subsuming the earlier drift guard. The documented recipe (release plan --version X.Y.Z) keeps
working unchanged (release-version-single-source,release-cut-publish-noop).
CI
- Generated/own
publish-crates.ymlis now idempotent. Bothcargo publishinvocations in the
dep-order step tolerate cargo's exact per-package "already exists on crates.io index" diagnostic as
success (anchored match; genuine failures still fail), so a successful engine cut no longer produces
a spurious red CI run when the tag-push publish races the engine's own publish (publish-crates-yml).
Install ossctl 0.2.5
Install prebuilt binaries via shell script
curl --proto '=https' --tlsv1.2 -LsSf https://github.com/jarimustonen/ossctl/releases/download/v0.2.5/ossctl-installer.sh | shInstall prebuilt binaries via powershell script
powershell -ExecutionPolicy Bypass -c "irm https://github.com/jarimustonen/ossctl/releases/download/v0.2.5/ossctl-installer.ps1 | iex"Download ossctl 0.2.5
| File | Platform | Checksum |
|---|---|---|
| ossctl-aarch64-apple-darwin.tar.xz | Apple Silicon macOS | checksum |
| ossctl-x86_64-pc-windows-msvc.zip | x64 Windows | checksum |
| ossctl-aarch64-unknown-linux-musl.tar.xz | ARM64 MUSL Linux | checksum |
| ossctl-x86_64-unknown-linux-musl.tar.xz | x64 MUSL Linux | checksum |
Verifying GitHub Artifact Attestations
The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:
gh attestation verify <file-path of downloaded artifact> --repo jarimustonen/ossctlYou can also download the attestation from GitHub and verify against that directly:
gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation>