Releases: lidge-jun/aside-codemode
Release list
v0.9.2
Browser routing boundary fixes
- Require explicit
host: "local"before materializing browser captures or reports into local files. Remote and unresolved hosts fail clearly instead of treating a remote path as local. - Reuse browser caches, approvals and tab journals only with a complete account/host selection. Inherited browsing still works, but incomplete identity cannot reuse persistent state.
- Validate administrative command arguments before changing settings. Reject unknown flags, malformed selectors and flag-shaped/control-character host names.
- Preserve the 0.9.1 per-call MCP
account/hostAPI,browserContextreports andbrowse.context(). - Make report-routing regression tests portable across Windows and Node 18/20/22.
Migration
For local captures/reports, pass --host local in CLI calls or host: "local" in supported MCP calls. To reuse caches or approvals, also select the intended account. Configured defaults may use:
{"browseContext":{"account":"u1","host":"local"}}Replace the account with the one intended for the task. This configuration does not change native Aside defaults. Context reports describe selection, not proof of live authentication.
Verification
Local suite: 1,097 passed, 0 failed, 1 platform-specific skip. Release requires the exact main SHA to pass the five-combination Linux/macOS/Windows CI matrix, followed by the existing OIDC dry-run and publish workflow. No new dependencies.
Includes #50; release promotion #51. npm provenance identifies the publishing workflow and source commit. The attached CycloneDX SBOM describes the dependency-free package.
v0.9.1
What's Changed
- fix(search): bound rg JSON and context memory without hiding partial results by @lidge-jun in #46
- fix(browser): honor per-execution account and host routing by @lidge-jun in #48
- release: v0.9.1 search memory bounds and browser routing by @lidge-jun in #49
Full Changelog: v0.9.0...v0.9.1
v0.9.0
complete now means something narrower than it did
Every open issue in this repository shared one defect: an action that skipped, capped, filtered out or could not apply something the caller asked for still reported full success. Six of them had already been fixed once each, with a symptom test and no written rule, which is why a seventh and an eighth shipped under a green suite.
The change a caller will notice
In 0.8.1 browse.exec and browse.captureMany derived complete from the run status alone. A batch that finished every job and handed back a tree cut at maxTreeChars answered complete: true. In 0.9.0 the same result answers complete: false, sets truncated: true, and names the cut in lostTo.
complete now requires three things: the run finished every job, nothing inside a finished job was cut, and no loss marker was raised. The same tightening reaches the post-action snapshot, ref reads that failed, and text sliced at maxTextChars.
No field is removed and no signature loses a key. But a caller branching on complete will get a different answer for the same page, which is why this is a minor rather than a patch.
Also in this release
fs.listdiscloses a capped listing and names unreadable directories. Decoration now survives the sandbox boundary through a symbol brand rather than an action-name allow-list.search.*gain ascope.coveragerecord with nine entries, socomplete: trueno longer reads as "the string is not there". A newbinaryoption maps to--text.browse.readTextgainscontentShape: a.diffURL answered with a sign-in page isok: true, complete: false.- Eleven output signatures corrected; the drift test now checks the output direction too.
partialis split into losses and advisories, so one marker no longer means two things in two producers.structure/and its checker now ship in the package, wherestructure:checkpreviously could only fail.
How it was checked
1,060 tests across Ubuntu 18/20/22, macOS 22 and Windows 22. Verified by mutation as well as by the green: reverting the six producers turns seven of the new completeness probes red.