Skip to content

release: prepare v0.0.14 - #374

Merged
drmowinckels merged 2 commits into
mainfrom
release/prepare-v0.0.14
Oct 6, 2026
Merged

drmowinckels merged 2 commits into
mainfrom
release/prepare-v0.0.14

Conversation

@drmowinckels

Copy link
Copy Markdown
Owner

Summary

Opens the 0.0.14 section over what has landed since 0.0.13 and bumps the version in the five places version:set covers, so shipped_version_agrees_across_every_manifest passes and release.yml's tag/manifest guard accepts a v0.0.14 tag.

Shipping in 0.0.14:

Behind those, not user-facing: the wasmtime advisory reachability analysis (#362), the cspell worktree false-pass fix (#366), and the AppImage launcher-permission fix (#373).

Why this release matters beyond the changelog

Two first-time release paths fire on publish:

  1. bump-scoop.yml runs for the first time and commits bucket/entracte.json. It only works if the release carries Entracte_0.0.14_x64-portable.zip and that zip appears in SHA256SUMS.txt — worth confirming on the draft before publishing.

  2. The AppImage carries the launcher fix. 0.0.13 was rejected by the AppImage catalog (appimage.github.io#9123) because AppRun.wrapped was 0770. fix(appimage): bump the Tauri CLI and guard AppDir permissions #373's CLI bump fixes it, verified on a real AppImage build:

    ok: AppRun is -rwxr-xr-x
    ok: AppRun.wrapped is -rwxr-xr-x
    

    So /retest on that PR should pass once 0.0.14 is published.

What I ran

shipped_version_agrees_across_every_manifest passes; format:check and audit:spell clean. No code changed — version strings and the changelog heading only.

🤖 Generated with Claude Code

drmowinckels and others added 2 commits October 6, 2026 12:37
Opens the 0.0.14 section over what has landed since 0.0.13: Scoop
packaging for Windows, the Linux/X11 crash fix, and CLI output appearing
on Windows.

Bumps the version in the five places `version:set` covers — package.json,
package-lock.json (both entries), tauri.conf.json, Cargo.toml and
Cargo.lock — so `shipped_version_agrees_across_every_manifest` passes and
release.yml's tag/manifest guard will accept the v0.0.14 tag.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@github-actions

github-actions Bot commented Oct 6, 2026

Copy link
Copy Markdown
Contributor

🔍 Advisory audit report

These checks don't block merges — they surface drift in dependencies, licensing, and external links.

cargo-deny

⚠️ findings
�[0m�[1m�[38;5;9merror[vulnerability]�[0m�[1m: Wasmtime component async-lifted callback result count is unvalidated, causing a native stack buffer overflow�[0m
    �[0m�[36m┌─�[0m /home/runner/work/entracte/entracte/src-tauri/Cargo.lock:560:1
    �[0m�[36m│�[0m
�[0m�[36m560�[0m �[0m�[36m│�[0m �[0m�[31mwasmtime 43.0.2 registry+https://github.com/rust-lang/crates.io-index�[0m
    �[0m�[36m│�[0m �[0m�[31m━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━�[0m �[0m�[31msecurity vulnerability detected�[0m
    �[0m�[36m│�[0m
    �[0m�[36m├�[0m ID: RUSTSEC-2026-0327
    �[0m�[36m├�[0m Advisory: https://rustsec.org/advisories/RUSTSEC-2026-0327
    �[0m�[36m├�[0m This is an entry in the RustSec database for the Wasmtime security advisory
      located at
      https://github.com/bytecodealliance/wasmtime/security/advisories/GHSA-32h6-97mm-8q3c
      For more information see the GitHub-hosted security advisory.
    �[0m�[36m├�[0m Announcement: https://github.com/bytecodealliance/wasmtime/pull/14471
    �[0m�[36m├�[0m Solution: Upgrade to >=48.0.4, <49.0.0 OR >=49.0.2 (try `cargo update -p wasmtime`)
    �[0m�[36m├�[0m wasmtime v43.0.2
      ├── extism v1.30.0
      │   └── entracte v0.0.14
      ├── wasi-common v43.0.2
      │   └── extism v1.30.0 (*)
      └── wiggle v43.0.2
          ├── extism v1.30.0 (*)
          └── wasi-common v43.0.2 (*)

advisories �[31mFAILED�[0m, bans �[32mok�[0m, licenses �[32mok�[0m, sources �[32mok�[0m

lychee (broken links)

✅ all links resolve

npm audit

⚠️ findings
# npm audit report

braces  *
Severity: high
braces vulnerable to stack-exhaustion denial of service through deeply nested patterns - https://github.com/advisories/GHSA-vfj7-8cjw-p6xm
fix available via `npm audit fix --force`
Will install stylelint@7.7.0, which is a breaking change
node_modules/braces
  micromatch  >=0.2.0
  Depends on vulnerable versions of braces
  node_modules/micromatch
    fast-glob  *
    Depends on vulnerable versions of micromatch
    node_modules/fast-glob
      globby  >=8.0.0
      Depends on vulnerable versions of fast-glob
      node_modules/globby
        stylelint  >=7.7.1
        Depends on vulnerable versions of fast-glob
        Depends on vulnerable versions of globby
        Depends on vulnerable versions of micromatch
        node_modules/stylelint
          stylelint-config-recommended  *
          Depends on vulnerable versions of stylelint
          node_modules/stylelint-config-recommended
            stylelint-config-standard  >=16.0.0
            Depends on vulnerable versions of stylelint
            Depends on vulnerable versions of stylelint-config-recommended
            node_modules/stylelint-config-standard

smol-toml  <=1.8.0
Severity: moderate
smol-toml: Quadratic-time parse() from parseKey rescanning to end of document on each key line - https://github.com/advisories/GHSA-r4xh-jqrq-34v2
fix available via `npm audit fix`
node_modules/smol-toml

source-map-js  1.0.0 - 1.2.1
Severity: high
source-map-js allows event-loop denial of service through indexed source-map section offsets - https://github.com/advisories/GHSA-68fv-2mgg-jv7q
fix available via `npm audit fix`
node_modules/source-map-js

9 vulnerabilities (1 moderate, 8 high)

To address issues that do not require attention, run:
  npm audit fix

To address all issues (including breaking changes), run:
  npm audit fix --force

@codecov

codecov Bot commented Oct 6, 2026 •

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 89.72%. Comparing base (c7b9b8f) to head (9ee4b89).

Additional details and impacted files
@@           Coverage Diff           @@
##             main     #374   +/-   ##
=======================================
  Coverage   89.71%   89.72%           
=======================================
  Files         148      148           
  Lines       25671    25671           
  Branches      861      861           
=======================================
+ Hits        23031    23033    +2     
+ Misses       2614     2612    -2     
  Partials       26       26           
Flag Coverage Δ
frontend 90.39% <ø> (ø)
rust 89.64% <ø> (+<0.01%) ⬆️
Components Coverage Δ
Frontend (TypeScript) 90.39% <ø> (ø)
Backend (Rust) 89.64% <ø> (+<0.01%) ⬆️
see 1 file with indirect coverage changes
🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@github-actions

github-actions Bot commented Oct 6, 2026

Copy link
Copy Markdown
Contributor

📖 Docs preview

✅ Built and deployed for commit 9ee4b89c596c2f52c9adb2c9e784d286fa6a15a5.

Preview URL https://pr-374--entract.netlify.app
Build logs https://github.com/drmowinckels/entracte/actions/runs/37451210678

Posted by docs-preview.yml — updates in place on every push.

@drmowinckels
drmowinckels merged commit 4f9c40e into main Oct 6, 2026
12 checks passed
@drmowinckels
drmowinckels deleted the release/prepare-v0.0.14 branch October 6, 2026 10:51
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant