Skip to content

v0.4.0

Choose a tag to compare

@github-actions github-actions released this 15 Sep 06:23
· 25 commits to master since this release

Highlights

The engine now has proper CI: every push runs cargo fmt --check,
cargo clippy -D warnings, the 47-test suite, a musl static build, and
a wasm smoke test. A weekly audit runs cargo audit + cargo deny.

The Docker image is reproducible (cargo-chef cache layer,
SOURCE_DATE_EPOCH honoured, dead chown -R removed) and the repo
has CODEOWNERS + CONTRIBUTING.md + SECURITY.md.

What's in this release

CI (ci.yml): cargo fmt --check, cargo clippy -D warnings,
cargo test --lib, musl build with clux/muslrust:stable, wasm smoke
test that decodes analyze_repos + render_card outputs and asserts
sizes are sane.

Audit (audit.yml): weekly cargo audit + cargo deny check,
fails on unknown registries or yanked crates.

Wasm auto-PR (wasm.yml): when src/** or Cargo.toml change,
rebuild pkg/ and open a PR into necrometer-dev.github.io. Uses
the org-bot push-to-fork so consumers don't need to wire up a PAT.

deny.toml: unknown registries = deny, unknown git = deny,
wildcards = deny. License allowlist covers every transitive dep.

Docker: two-stage clux/muslrust:stable → alpine:3.20 with a
cargo-chef planner+cook+build pipeline (only the cook layer
invalidates when Cargo.lock changes). SOURCE_DATE_EPOCH honoured.
Dead chown -R /app in entrypoint.sh removed (the runtime image
doesn't mount /app as a user-writable volume).

Governance: .github/CODEOWNERS requires @UberMetroid review on
every file. CONTRIBUTING.md documents the project principles (zero
deps, 256-line ceiling, zero-trust), layout, build commands, and the
version-bump procedure. SECURITY.md documents the threat model,
supported versions, mitigations list, and security@necrometer.dev
as the reporting address.

Verification

cargo test --lib           → 47 passed, 0 failed
cargo clippy ... -D warnings → clean
cargo fmt --all -- --check  → clean
musl build                  → static binary passes
wasm-pack build --release   → 44801-byte SVG output