Skip to content

v0.4.0

Choose a tag to compare

@github-actions github-actions released this 20 Jun 14:49
a426d17

gjoa's settings surface lands: a single about:gjoa hub with a curated LibreWolf-Inspired privacy profile*, the about:sovereignty egress trust panel, and a relational code-graph over gjoa's own source — plus four inherited-egress vectors closed and new patch/knob/projector pre-build gates. Built on Firefox 152.0.1.

Features

  • knobs: preflight Gate N + real egress costs + PROFILES↔registry sync (#109)
  • projector: relational code-graph over gjoa's own source (#108)
  • verify: live about-pages + settings-pointer check via Marionette (#106)
  • release: release-notes takes an optional end-ref (backfill past releases) (#105)
  • settings: thin about:preferences pointer -> about:gjoa (no FF patch) (#101)
  • settings: own the surface — about:gjoa settings hub (knobs promoted) (#100)
  • knobs: LibreWolf-Inspired privacy profile + about:knobs dashboard (#83 core) (#99)
  • build: pin the beagle compiler ref (visible drift + baked provenance) (#98)
  • release: factual release-notes generator + CI-placeholder backstop (#97)
  • sovereignty: publish the egress audit tools (open audit = the credibility) (#95)
  • sovereignty: regenerate the egress manifest at import time (#94)
  • sovereignty: about:sovereignty egress trust panel (#93)
  • sovereignty: opt-in maximal-egress-lockdown toggle (default off) (#92)
  • projector: rename-recovery — confidence-scored structural anchor matcher (#74 tail) (#83)
  • projector: JS-on-Fram live store — round-trip through Fram + Datalog queries (#75) (#82)
  • projector: JS-on-Fram — lossless CST -> Fram-format claim records (#75) (#81)
  • tools: Firefox-API seam ratchet — drift monitor for the chrome API surface (#73) (#80)
  • projector: claim-doc fallback for patch 0011 in the build (Phase 5 integration) (#79)
  • projector: JS lossless-CST round-trip reflector + identity-anchored set-body (Phase 5 pilot) (#78)
  • tools: Phase 3 — conflict forecast (pre-bump blast-radius, no build) (#75)

Security & hardening

  • prefs: close 4 Firefox inherited-egress vectors (#91)
  • prep: validate version in pin-firefox before URL/path use (#89)
  • supply-chain: GPG-mandatory pin creation + fix gpg-absent crash (#88)
  • tabs: load picker favicons via page-icon: cache, not the page URL (#87)
  • prep: validate version strings + reject claim-doc path traversal (#86)

Fixes

  • drawer: remove dead js/import lines emitting invalid import() into chrome (#90)

Refactors

  • compression dedup — shared NAV-JS + sh helper (#85)
  • chrome: cross-module declare-extern Any -> real :require imports (#77)

Docs

  • why-beagle: cover the modern beagle/fram/claims affordances + link from README (#107)
  • readme: sharper headline — the power-user extension stack is native (#104)
  • readme: clarify the build flavors — portable builds ARE for sharing (#103)
  • readme: compress + polish; add sailboat logo + new-tab screenshot (#102)

Chores

  • sovereignty: drop arrow-objlit workaround (beagle PR #8 fixed it) (#96)
  • prep: if-with-nil-else -> when/when-not (18 sites) (#84)
  • harden externs — typed stdlib statics + prune dead Any-externs (#76)

Generated from the merged commit log — factual changelog, not announcement copy.

* LibreWolf-Inspired is a curated subset of LibreWolf's privacy defaults — not LibreWolf itself (its compile-time disables and ~20 C++ patches aren't here). The trade-offs are shown on the profile in about:gjoa.