Repository navigation
A patch release: one user-facing fix for keyboard entry in the worklog, the removal of two unused code paths, and the supply-chain and test work that landed after v6.4.0. No configuration, API or database changes; there is nothing to do when upgrading from 6.4.0.
Fix
Tab out of "Tätigkeit" no longer loses the entry. Filling a new worklog entry from the keyboard, picking the activity and pressing Tab saved the row about 6 ms later, and the refetch that followed remounted it together with the description editor that had just opened: the green confirmation appeared and no field had focus. The cause was the popup of a select: while it closes, focus rests on <body> for one frame, and the check that saves a row when the user leaves the table read that as leaving. The check now waits for the move that follows the commit. Reported by @ngolatka in #771, fixed by @CybotTM in #772.
In the grouped view, the default since 6.4.0, the same Tab landed in "Start" instead of "Beschreibung", because the time cell sits between the two. Tab and Enter's guided fill now walk a row in the order of the flat grid (ticket, customer, project, activity, description) in both views. In the grouped view that order differs from the visual one, as #588 asked. The keyboard flow is covered by browser tests in both views (#772).
Removed
QueryCacheService, whose two calls had no effect; the documentation no longer claims a query cache — @CybotTM (#764)- The unused optimized entry repository — @CybotTM (#762)
Supply chain
- This is the first release whose source archive is built by the organisation's reusable workflow on the tag push, which gives its provenance SLSA Build Level 3; the archive of v6.4.0 was built inside this repository and reaches Level 2. It carries
checksums.txt, SPDX and CycloneDX SBOMs, a build-provenance attestation and a Cosign bundle per file. The verification commands, including--signer-workflow, are in SECURITY.md — @CybotTM (#759, #748, #746, #754) - The source archive is rebuilt after each release and weekly and compared with
checksums.txt— @CybotTM (#752) - CI measures how reproducible the container image is — @CybotTM (#761)
- Semgrep blocks on findings of severity ERROR — @CybotTM (#753)
- The README states the SLSA level reached, not the one aimed at — @CybotTM (#755)
Tests and documentation
- Seven classes the unit suite never reached are covered, and three database-dependent tests moved out of the unit suite — @CybotTM (#760, #757)
- The end-to-end suite waits for a seeded LDAP directory and gives the grouped-editing cases a budget that fits them — @CybotTM (#766, #758)
- Branch coverage is read from where it is recorded — @CybotTM (#751)
- The OpenSSF prerequisites, the release gate, the SAST thresholds and the assurance case, including the secure design principles, are documented — @CybotTM (#749, #767)
- The release command in the docs uses
--verify-tag— @CybotTM (#747)
Full list: v6.4.0...v6.4.1