patchbay v0.3.1
Security
-
Every third-party action in CI and the release workflow is pinned to a full
commit SHA, with the tag it came from kept in a trailing comment. A moving
tag is a standing invitation: whoever controls the action's repository can
change what runs in a job that holds the Apple signing certificate. One trap
worth recording, because it turns a hardening into a broken build if you miss
it —dtolnay/rust-toolchainderives the channel it installs from
github.action_ref, which is exactly how@stablemeans stable. Pinned to a
SHA that default becomes the SHA, so every use now namestoolchain: stable
outright. -
bun installruns with--ignore-scripts. Nothing in the front end's
tree needs a lifecycle script — esbuild and the tauri CLI ship their platform
binaries as optional dependencies rather than postinstall downloads — so the
scripts were only ever an unused path from a compromised package to a runner
that holds the release secrets. -
release.ymliscontents: readat the workflow level, and only the
releasejob raises itself tocontents: write. The three jobs that build
and sign now carry a token that cannot publish a release. -
Every
cargoinvocation takes--locked, so CI fails on a lockfile that
has drifted from the manifests instead of quietly resolving a different
dependency tree than the one that was reviewed. -
The keychain script fetches Apple's CA anchors over HTTPS only
(--proto '=https' --proto-redir '=https' --tlsv1.2). It passes-L, so
without the redirect guard a 302 intohttp://would have been followed and
the trust anchors taken in the clear.
Added
- A
core (Linux)CI job, retiring a TODO that turned out to be wrong about
its own premise.patchbay-corehas nocfg(target_os)branch anywhere: the
macOS-shaped tool locations are plain strings built under a home directory the
caller supplies, and the suite supplies a synthetic one; the Keychain path is
covered throughMemoryKeystore, so no test shells out tosecurity. The
core suite was already portable, and this job is what keeps it that way — it
goes red the moment core reaches for a real$HOMEor a platform cfg. It is
not a claim that patchbay runs on Linux.pb, the panel and the probes are
still macOS-only, which is why exactly one crate is built there.
Fixed
-
The panel's clickable surfaces are real controls. The tool card, the
profile row's switch target, the copyable command and the detail scrim were
each a non-interactive element wearingrole="button", atabIndexand a
hand-written Enter/Space handler; they are now<button>s, and the detail
drawer is a native<dialog>— the same pair the key vault's drawer has used
since it landed. The focus ring, the keyboard behaviour and the announced role
come from the element instead of being re-implemented beside it. Nothing moves
on screen: a button may only hold phrasing content, so the layout elements
inside became spans and the stylesheet carries the boxes. -
The boot splash's light-mode text sat at 4.1:1 on its background, just under
WCAG AA, while being the only thing on screen. It is now 5.3:1. -
headlineExpirysorts with an explicit comparator. The default sort compares
UTF-16 code units, which happens to be right for RFC 3339 stamps but said so
nowhere.
What's Changed
- [docs] readme: drop the duplicated unlinked Migrate bullet by @YJack0000 in #7
- [fix] clear the SonarCloud board: CI supply-chain hardening + native controls in the panel by @YJack0000 in #8
- [chore] release 0.3.1 by @YJack0000 in #9
Full Changelog: v0.3.0...v0.3.1