Skip to content

Release v2.0.0

Choose a tag to compare

@github-actions github-actions released this 02 Sep 06:15
· 121 commits to main since this release
ef701f8

Release v2.0.0

Changes

  • Resolve all findings from the 2026-09-01 stability review (v2.0.0)
  • docs: fix a sentence split by the previous docstring edit
  • docs: cross-reference the dismissed CodeQL alert in identity.py
  • chore: release as 2.0.0, not 1.6.1
  • ci(release): tag from main's version instead of committing to main
  • chore: drop two unused imports in the Maps scraper
  • fix(security): stop sensitive values reaching logs at all
  • fix(security): close log injection across the API surface
  • fix(security): key the identity digests; stop logging precise locations
  • feat: enable Prometheus metrics; remove the dead Postgres layer
  • chore(deps): move psycopg2-binary out of production requirements
  • ci(release): run publish in the production environment
  • chore(deps): lift the redis hold, 7.1.0 -> 8.1.0
  • fix(maps): migrate the job service to the owner-scoped store
  • fix: stop three paths reporting failure as success
  • docs: use X-API-Key, not Authorization: Bearer, in examples
  • ci: fix the four failures the new pipeline found on its first run
  • chore(typing): enable the pydantic mypy plugin
  • chore: ignore agent and code-intelligence tool output
  • docs: correct README drift against the remediated behaviour
  • ci: raise the coverage floor to the measured 65%
  • chore(deps): drop slowapi; it was added for a path that was then deleted
  • test(main): assert the new lifespan wiring
  • test: reset the global rate-limit store between every test
  • test(main): assert the real rate-limit middleware, not slowapi's state
  • fix(main): install the real rate limiter, delete the dead slowapi path
  • fix(maps): pass the caller's api_key through to monitor and webhook services
  • test(auth): /status is key-gated, not public
  • test(boot): treat a commented .env.example key as documented
  • fix(config): keep .env.example runnable without Docker
  • test: retarget auth patches onto _auth_snapshot after AuthSettings removal
  • Merge branch 'fix/phase-5-maps-router' into integration
  • Merge branch 'fix/phase-5-maps-endpoints' into integration
  • Merge branch 'fix/phase-3-news-trends' into integration
  • Merge branch 'fix/phase-3-url-guard-hardening' into integration
  • fix(security): block CGNAT and IPv6-embedded IPv4 in the SSRF guard
  • fix(maps): state the evidence rather than the conclusion, and re-guard monitor URLs
  • fix(maps): stop upstream error strings reaching callers on the non-raising path
  • chore(news): drop an unused import
  • Merge branch 'fix/phase-2-ci' into integration
  • Merge branch 'fix/phase-5-maps-scraper' into integration
  • Merge branch 'fix/phase-3-rate-limiting' into integration
  • Merge branch 'fix/phase-3-security-core' into integration
  • Merge branch 'fix/phase-4-proxy-config' into integration
  • Merge branch 'fix/phase-4-dependencies' into integration
  • Merge branch 'fix/phase-1-boot-auth' into integration
  • fix(proxy): read proxy config from Settings, not os.getenv at import
  • fix(news): cap the article body, stop caching NLP-degraded responses
  • fix(rate-limit): make test isolation and key parsing order-independent
  • fix(maps): label the one empty result that cannot be verified
  • ci: fail with a clear message when the pip-audit pin is missing
  • fix(auth): serialise snapshot refresh; cover the API_KEY placeholder branch
  • fix(maps): close three holes found reviewing the scraper diff
  • fix(maps): close four fabrication and SSRF gaps found in review
  • ci: install from requirements.lock, block on pip-audit, correct coverage floor
  • refactor(maps): split the 3,000-line router into modules by concern
  • fix(news): revalidate redirects, stop caching partial results, rate-limit routes
  • fix(config,auth): act on independent review of the phase-1 boot/auth fixes
  • fix(maps): close SSRF sink, scope jobs to their owner, rate limit every route
  • feat(maps): replace fabricated endpoints with real implementations
  • fix(rate-limit): detect --workers on the command line
  • fix(main): require an API key for /metrics
  • fix(news,trends): close SSRF sink, un-break News, stop caching failures
  • fix(ops): derive base-image tag from the Dockerfile and pin Redis RESP2
  • fix(maps): scope jobs to owners, bound browsers, stop faking success
  • fix(deps): hold redis at 7.x, flag the stale base-image updater
  • fix(core): close CORS/auth disclosure holes, cache corruption and pool leak
  • test: add tests/conftest.py and centralise tool config in pyproject.toml
  • ci: replace no-op pipeline with real test, boot and docker gates (CRT-6)
  • fix(rate-limit): make the limiter actually enforce limits (CRT-8)
  • fix(config,auth): boot from documented config; load the documented API key
  • fix(deps): escape the starlette 0.50 security dead end, lock the closure, delete the phantom DB layer
  • chore: track documentation, untrack generated corpora and scratch files
  • feat(maps): add owner-scoped durable record store
  • feat(security): add shared outbound URL validator for SSRF defence
  • fix(security): stop secrets and signing keys reaching git and Docker contexts
  • chore: bump version to v1.6.1

Images

  • rainmanjam/social-flood:2.0.0
  • ghcr.io/rainmanjam/social-flood:2.0.0
  • Digest: sha256:76cfc8f0aafbdfcfc20886acfa2c5290eb220aa7819e57fc195fe556a16dc4f5

Verify the signature

cosign verify \
  --certificate-identity-regexp 'https://github.com/rainmanjam/social-flood/.github/workflows/release.yml@.*' \
  --certificate-oidc-issuer https://token.actions.githubusercontent.com \
  ghcr.io/rainmanjam/social-flood@sha256:76cfc8f0aafbdfcfc20886acfa2c5290eb220aa7819e57fc195fe556a16dc4f5