Skip to content

Core 2.0.1 — security and lifecycle fixes

Latest

Choose a tag to compare

@github-actions github-actions released this 23 Sep 19:05
· 3 commits to main since this release
6ed2885

Core 2.0.1 — security and lifecycle fixes

Core 2.0.1 is the published combined release for the merged source at 6ed28858ebb4ce3ca3939f9be96dc091f25822cb.

What changed

  • Updated the PyO3 dependency family to pyo3 0.29.2, pyo3-async-runtimes 0.29.0, and pyo3-log 0.13.4, addressing GHSA-36hh-v3qg-5jq4 and GHSA-chgr-c6px-7xpp.
  • Lifecycle cleanup now emits the terminal event before module cleanup, preserves exact registration ownership, and cancels each owned Python hook waiter. The contract is at-most-once terminal attempt per initialized lifetime; cancellation may interrupt handler delivery, while the host owns cleanup completion.
  • Includes the pinned Actions updates reviewed in PR #113 and lifecycle work reviewed in PR #114, combined through PR #115.

Qualification and provenance

The tag workflow rebuilt and qualified the exact merged source: six native platform builds and all 18 normal-GIL CPython 3.11/3.12/3.13 qualification cells passed, with direct native imports validated. A fresh published-wheel verification on Linux ARM64/Python 3.13 passed 1,164 tests (one skip, two deprecation warnings) and a real delegation/recipe execution.

Verification evidence for the downloaded wheels and loaded native hash is attached as SHA256SUMS and release-evidence-6ed28858ebb4ce3ca3939f9be96dc091f25822cb.zip; see docs/NATIVE_ARTIFACTS.md for the verification procedure.

The qualification scope covers the stated platform/Python matrix and normal-GIL builds; it does not claim all operating systems, authentication paths, or free-threaded CPython 3.13t. The broader eager coroutine wrapper gap remains a separate follow-up documented in PR #114 and is not claimed fixed here.

Adoption

Existing consumers can adopt the binary release with:

python -m pip install --only-binary=:all: amplifier-core==2.0.1
python -m pip check

No restart was performed or forced upgrade is required. The release does not change production runtimes or CI #127.

Security alerts #40–#43 are fixed, not dismissed. The release assets and tag target are unchanged.