v0.4.0
Highlights
The engine now has proper CI: every push runs cargo fmt --check,
cargo clippy -D warnings, the 47-test suite, a musl static build, and
a wasm smoke test. A weekly audit runs cargo audit + cargo deny.
The Docker image is reproducible (cargo-chef cache layer,
SOURCE_DATE_EPOCH honoured, dead chown -R removed) and the repo
has CODEOWNERS + CONTRIBUTING.md + SECURITY.md.
What's in this release
CI (ci.yml): cargo fmt --check, cargo clippy -D warnings,
cargo test --lib, musl build with clux/muslrust:stable, wasm smoke
test that decodes analyze_repos + render_card outputs and asserts
sizes are sane.
Audit (audit.yml): weekly cargo audit + cargo deny check,
fails on unknown registries or yanked crates.
Wasm auto-PR (wasm.yml): when src/** or Cargo.toml change,
rebuild pkg/ and open a PR into necrometer-dev.github.io. Uses
the org-bot push-to-fork so consumers don't need to wire up a PAT.
deny.toml: unknown registries = deny, unknown git = deny,
wildcards = deny. License allowlist covers every transitive dep.
Docker: two-stage clux/muslrust:stable → alpine:3.20 with a
cargo-chef planner+cook+build pipeline (only the cook layer
invalidates when Cargo.lock changes). SOURCE_DATE_EPOCH honoured.
Dead chown -R /app in entrypoint.sh removed (the runtime image
doesn't mount /app as a user-writable volume).
Governance: .github/CODEOWNERS requires @UberMetroid review on
every file. CONTRIBUTING.md documents the project principles (zero
deps, 256-line ceiling, zero-trust), layout, build commands, and the
version-bump procedure. SECURITY.md documents the threat model,
supported versions, mitigations list, and security@necrometer.dev
as the reporting address.
Verification
cargo test --lib → 47 passed, 0 failed
cargo clippy ... -D warnings → clean
cargo fmt --all -- --check → clean
musl build → static binary passes
wasm-pack build --release → 44801-byte SVG output