Skip to content

release: v1.19.0 — the security review - #488

Merged
guycorbaz merged 1 commit into
mainfrom
release/v1.19.0
Sep 11, 2026
Merged

guycorbaz merged 1 commit into
mainfrom
release/v1.19.0

Conversation

@guycorbaz

Copy link
Copy Markdown
Owner

Cuts v1.19.0. No source change — every fix in it is already on main; this is the version bump plus the Foundation Rule 19 documentation sweep.

What ships

Issue What it fixes
#478 The Trash panel's Restore button reaches a route that exists. It had pointed at an unregistered address since story 8-6, so clicking it did nothing at all — no restore, no error, nothing.
#480 The seeded development accounts are hard-deleted at first boot instead of parked in the Trash with the passwords published in SECURITY.md intact. #478 is what made this urgent, and the order mattered.
#479 A cover decode runs under a fixed allocation budget, and the download streams with a hard cap instead of trusting Content-Length.

Also in the tag: supply-chain CI (#481 — actions pinned by SHA, daily RustSec scan), the network-posture documentation (#482), the community-health files (#477), and the documentation audit (#487).

No migration. Pull, restart, done.

Rule 19 checklist

  • Cargo.toml + Cargo.lock → 1.19.0
  • Manual EN + FR — title-page version, install snippets, "What's new in 1.19.0" in chapter 8, PDFs rebuilt and committed
  • README.md — status line, live-install label, image-size badge, current-release paragraph
  • ROADMAP.md — current-stable header, v1.19.0 shipped section, the "merged but not released" block retired
  • docs/dockerhub-overview.md — tags list
  • website/index.html — nav badge, hero headline, hero paragraph, JSON-LD softwareVersion
  • website/roadmap.html — meta descriptions, JSON-LD, nav badge, both narrative paragraphs
  • website/about.html — nav badge
  • website/sitemap.xml — lastmod (stale since May; Rule 19 names it as the one people forget)
  • sprint-status.yaml — last_updated header
  • Grep for every stale version, not just the predecessor — remaining 1.18.0 hits are deliberate historical references, and the 1.15.46 matches are SVG coordinates
  • GitHub Release page — after this merges and the tag is pushed, with the manual PDFs attached (v1.18.0 shipped without them; v1.13.0 through v1.17.0 have them)

Testing

  • cargo clippy --all-targets -- -D warnings — clean.
  • cargo test --lib — 1175 passed.
  • docs/manual/build.sh — both PDFs rebuilt, no undefined references; the English PDF's title page reads Version 1.19.0.

🤖 Generated with Claude Code

https://claude.ai/code/session_01D5cV9QRqQAFpiNKZwZfoNX

Cut the v1.19.0 release documentation: version bump in Cargo.toml /
Cargo.lock, and every version-bearing surface required by Foundation
Rule 19 brought to 1.19.0.

- Manual EN/FR: title-page version, install snippets, a "What's new in
  1.19.0" section in chapter 8 (the Restore button that never worked,
  the seeded accounts leaving no trace, the bounded cover decode, and
  an explicit "nothing to do on upgrade"); the release-notes section
  now states that the PDFs are attached to the release rather than
  promising it once CI is wired. PDFs rebuilt.
- README: status line, live-install label, image-size badge, current-
  release paragraph.
- ROADMAP: current-stable header, a v1.19.0 shipped section, and the
  "merged but not released" block retired now that it has shipped.
- docs/dockerhub-overview.md: tags list.
- website/: index (nav badge, hero, JSON-LD softwareVersion, the hero
  paragraph rewritten around this release), about (nav badge), roadmap
  (meta descriptions, JSON-LD, nav badge, both narrative paragraphs),
  sitemap lastmod — stale since May, and the surface Rule 19 names as
  the easiest to forget.
- sprint-status.yaml: last_updated header.

No source change. The release carries #478, #480 and #479 (merged in
#485, #484 and #486), the supply-chain CI work (#481), the network-
posture documentation (#482), the community-health files (#477) and the
documentation audit (#487). No migration.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01D5cV9QRqQAFpiNKZwZfoNX
@guycorbaz
guycorbaz merged commit 0a399a7 into main Sep 11, 2026
9 checks passed
@guycorbaz
guycorbaz deleted the release/v1.19.0 branch September 11, 2026 09:26
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant