diff --git a/Cargo.lock b/Cargo.lock index 8a942ee..7da4e14 100644 --- a/Cargo.lock +++ b/Cargo.lock @@ -865,7 +865,7 @@ source = "registry+https://github.com/rust-lang/crates.io-index" checksum = "39cab71617ae0d63f51a36d69f866391735b51691dbda63cf6f96d042b63efeb" dependencies = [ "libc", - "windows-sys 0.52.0", + "windows-sys 0.61.2", ] [[package]] @@ -1918,7 +1918,7 @@ dependencies = [ [[package]] name = "mybibli" -version = "1.19.0" +version = "1.20.0" dependencies = [ "argon2", "askama", @@ -2758,14 +2758,14 @@ dependencies = [ "errno", "libc", "linux-raw-sys", - "windows-sys 0.52.0", + "windows-sys 0.61.2", ] [[package]] name = "rustls" -version = "0.23.40" +version = "0.23.45" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "ef86cd5876211988985292b91c96a8f2d298df24e75989a43a3c73f2d4d8168b" +checksum = "0d41d731c7d2f962d1ccc364cec258de3c0e93b38c2fb3ba97ac74513048d634" dependencies = [ "once_cell", "rustls-pki-types", @@ -2785,9 +2785,9 @@ dependencies = [ [[package]] name = "rustls-webpki" -version = "0.103.13" +version = "0.103.15" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "61c429a8649f110dddef65e2a5ad240f747e85f7758a6bccc7e5777bd33f756e" +checksum = "f3c3cf1d8b1e7d4927e2d154c3fcb02979afb9939629c62cd9048d4f07b60ac2" dependencies = [ "ring", "rustls-pki-types", @@ -3484,7 +3484,7 @@ dependencies = [ "getrandom 0.4.2", "once_cell", "rustix", - "windows-sys 0.52.0", + "windows-sys 0.61.2", ] [[package]] diff --git a/Cargo.toml b/Cargo.toml index 878fe69..ced4566 100644 --- a/Cargo.toml +++ b/Cargo.toml @@ -1,6 +1,6 @@ [package] name = "mybibli" -version = "1.19.0" +version = "1.20.0" edition = "2024" license = "AGPL-3.0-or-later" diff --git a/README.md b/README.md index 832f332..6251cdd 100644 --- a/README.md +++ b/README.md @@ -9,7 +9,7 @@ [](https://github.com/guycorbaz/mybibli/releases) [](LICENSE) [](https://hub.docker.com/r/gcorbaz/mybibli) -[](https://hub.docker.com/r/gcorbaz/mybibli/tags) +[](https://hub.docker.com/r/gcorbaz/mybibli/tags) [](https://github.com/guycorbaz/mybibli/issues) [](https://github.com/guycorbaz/mybibli/commits/main) [](https://github.com/guycorbaz/mybibli/stargazers) @@ -17,7 +17,7 @@ > Personal library cataloging for home collectors. -**Status:** in production since v1.1.1 (2026-05-14). 10 epics shipped; project is in GH-issue-driven polish mode. Current release: `v1.19.0`. Pre-built images on Docker Hub at [`gcorbaz/mybibli`](https://hub.docker.com/r/gcorbaz/mybibli). See [ROADMAP.md](ROADMAP.md) for what's coming next. +**Status:** in production since v1.1.1 (2026-05-14). 10 epics shipped; project is in GH-issue-driven polish mode. Current release: `v1.20.0`. Pre-built images on Docker Hub at [`gcorbaz/mybibli`](https://hub.docker.com/r/gcorbaz/mybibli). See [ROADMAP.md](ROADMAP.md) for what's coming next. ## What it is @@ -38,7 +38,7 @@ Built for collectors who want more than a spreadsheet: ## Screenshots -Live production install (`v1.19.0`, household NAS, 140+ volumes catalogued and growing): +Live production install (`v1.20.0`, household NAS, 140+ volumes catalogued and growing):
@@ -411,7 +411,7 @@ Versioned under `_bmad-output/`:
mybibli has been live in production since v1.1.1 (2026-05-14) on the household NAS that drove the project. v1.0.0 shipped after Epic 9 close (2026-05-10) as the first production-ready build; v1.1.0 added the seed-gate + audit trio (mandatory install floor — see "Installation notes" above); the themed minors v1.2 through v1.8 then delivered the original feature roadmap (browse & find, wishlist, HTTP API, valuation & stats, catalog hygiene, de/it locales + runtime logging, cover handling), each followed by production-driven patch trains. Since v1.8 the project runs in GH-issue-driven polish mode.
-**Current release: `v1.19.0`** (2026-09-11) — the three change requests of a security review run against the 1.18.0 code, and the documentation work it made necessary. [#478](https://github.com/guycorbaz/mybibli/issues/478): the Trash panel's Restore button, which had pointed at an unregistered route since 1.2.0 and silently did nothing, now restores. [#480](https://github.com/guycorbaz/mybibli/issues/480): the seeded development accounts are deleted outright at first boot instead of being parked in the Trash with their published passwords intact — which #478 would otherwise have made restorable. [#479](https://github.com/guycorbaz/mybibli/issues/479): a cover decode runs under a fixed allocation budget, so an image that is small on the wire and enormous once decoded is refused rather than taking the container down. **No migration.** The preceding release, `v1.18.0` (2026-08-18), added management labels ([#443](https://github.com/guycorbaz/mybibli/issues/443)).
+**Current release: `v1.20.0`** (2026-09-23) — the last volume number and the last shelf number in use, shown on the admin Health tab with the next free number after each ([#489](https://github.com/guycorbaz/mybibli/issues/489)). Before printing a new sheet of barcode labels, the librarian reads where the occupied range ends; trashed items still count, so a printed sticker is never reissued. **No migration.** The preceding release, `v1.19.0` (2026-09-11), carried the three change requests of a security review run against the 1.18.0 code, and the documentation work it made necessary. [#478](https://github.com/guycorbaz/mybibli/issues/478): the Trash panel's Restore button, which had pointed at an unregistered route since 1.2.0 and silently did nothing, now restores. [#480](https://github.com/guycorbaz/mybibli/issues/480): the seeded development accounts are deleted outright at first boot instead of being parked in the Trash with their published passwords intact — which #478 would otherwise have made restorable. [#479](https://github.com/guycorbaz/mybibli/issues/479): a cover decode runs under a fixed allocation budget, so an image that is small on the wire and enormous once decoded is refused rather than taking the container down. **No migration.** The preceding release, `v1.18.0` (2026-08-18), added management labels ([#443](https://github.com/guycorbaz/mybibli/issues/443)).
**Release-by-release history lives in [ROADMAP.md](ROADMAP.md)** — one section per version, and the canonical copy. It is deliberately not repeated here: the [GitHub releases page](https://github.com/guycorbaz/mybibli/releases) carries the same notes as published artifacts, chapter 8 of the [user manual](docs/manual/) carries them offline, and the [website roadmap](https://guycorbaz.github.io/mybibli/roadmap.html) tells the same story for a different audience. See [`epics.md`](_bmad-output/planning-artifacts/epics.md) for the epic breakdown and [`sprint-status.yaml`](_bmad-output/implementation-artifacts/sprint-status.yaml) for the story-by-story state.
diff --git a/ROADMAP.md b/ROADMAP.md
index 78aae81..ea1114c 100644
--- a/ROADMAP.md
+++ b/ROADMAP.md
@@ -32,16 +32,38 @@ mybibli follows [Semantic Versioning](https://semver.org/) 2.0.
## Now
-**Current stable: [`v1.19.0`](https://github.com/guycorbaz/mybibli/releases/tag/v1.19.0)**
-(2026-09-11) — the three change requests of a security review run against
-the 1.18.0 code, and the documentation work it made necessary. **No
+**Current stable: [`v1.20.0`](https://github.com/guycorbaz/mybibli/releases/tag/v1.20.0)**
+(2026-09-23) — the last volume number and the last shelf number in use,
+on the admin Health tab, each with the next free number. **No
migration.** The section below has the detail; every release before it
has its own section further down, and this is the file that carries them
— the README quotes only the current release, and the website tells the
same story for a different audience.
-**Open issues: none.** The tracker has been empty since the review
-closed. New work starts from a fresh report.
+**Open issues: none.** The tracker has been empty since the security
+review closed; #489 was opened and shipped the same day. New work starts
+from a fresh report.
+
+## v1.20.0 — where the labels end *(shipped)*
+
+Shipped 2026-09-23. One change request, **no migration**.
+
+- [#489](https://github.com/guycorbaz/mybibli/issues/489) — **the admin
+ Health tab shows the last volume number (V-code) and the last shelf
+ number (L-code) in use, each with the next free number** —
+ `V0142 (next: V0143)`. The librarian prints sheets of pre-generated
+ barcode labels in advance and needs to know where the occupied range
+ ends; since v1.12.0 that answer lived only on the `/catalog` info line
+ ([#428](https://github.com/guycorbaz/mybibli/issues/428)). "Last" is
+ the highest number ever printed, trashed items included, so a sticker
+ already stuck on a book or a shelf is never reissued — the same rule
+ `/catalog` follows, so the two surfaces never contradict each other.
+ An empty catalog reads "none yet"; `V9999` reads "none left".
+- **Dependency fix** — `rustls` 0.23.40 → 0.23.45 for
+ [RUSTSEC-2026-0285](https://rustsec.org/advisories/RUSTSEC-2026-0285)
+ (TLS 1.3 handshake messages accepted across encryption-level
+ boundaries; medium), caught by the release-cut `cargo audit`. Affects
+ the outbound HTTPS client used for metadata lookups; no code change.
## v1.19.0 — the security review *(shipped)*
diff --git a/_bmad-output/implementation-artifacts/sprint-status.yaml b/_bmad-output/implementation-artifacts/sprint-status.yaml
index bca23a8..a30f895 100644
--- a/_bmad-output/implementation-artifacts/sprint-status.yaml
+++ b/_bmad-output/implementation-artifacts/sprint-status.yaml
@@ -1,5 +1,5 @@
# generated: 2026-03-29
-# last_updated: 2026-09-11 (v1.19.0 — minor on v1.18.0, no migration. The three change requests of the 2026-08-18 security review: #478 the Trash Restore button reaches a route that exists, #480 the seeded dev accounts are hard-deleted at first boot instead of parked in the Trash, #479 a cover decode runs under an allocation budget. Plus a documentation audit across every surface.)
+# last_updated: 2026-09-23 (v1.20.0 — minor on v1.19.0, no migration. #489: the admin Health tab shows the last V-code and L-code in use, each with the next free number, for printing label sheets.)
# project: mybibli
# project_key: NOKEY
# tracking_system: file-system
diff --git a/docs/dockerhub-overview.md b/docs/dockerhub-overview.md
index 6fbece9..a6eb69f 100644
--- a/docs/dockerhub-overview.md
+++ b/docs/dockerhub-overview.md
@@ -118,7 +118,7 @@ Both `mybibli-covers` and `mybibli-logs` can be swapped from Docker-named volume
## Tags
- `:latest` — tracks the highest semver release tag.
-- `:1.19.0` (current), `:1.18.0`, `:1.17.0` and every prior release tag back to `:1.1.0` — specific releases. Pin to a specific tag in production-style setups; tracking `:latest` is reasonable for homelab. The full tag list is on the [Tags tab](https://hub.docker.com/r/gcorbaz/mybibli/tags).
+- `:1.20.0` (current), `:1.19.0`, `:1.18.0` and every prior release tag back to `:1.1.0` — specific releases. Pin to a specific tag in production-style setups; tracking `:latest` is reasonable for homelab. The full tag list is on the [Tags tab](https://hub.docker.com/r/gcorbaz/mybibli/tags).
- **No `:dev`, no `:main`, no `:beta` published** — tagged releases only.
## Docs
diff --git a/docs/manual/en/01-installation.tex b/docs/manual/en/01-installation.tex
index 925601b..c452cda 100644
--- a/docs/manual/en/01-installation.tex
+++ b/docs/manual/en/01-installation.tex
@@ -108,8 +108,8 @@ \subsection*{1. Get the compose file and \texttt{.env}}
\begin{lstlisting}
mkdir -p /srv/mybibli && cd /srv/mybibli
-curl -O https://raw.githubusercontent.com/guycorbaz/mybibli/v1.19.0/docker-compose.yml
-curl -O https://raw.githubusercontent.com/guycorbaz/mybibli/v1.19.0/.env.example
+curl -O https://raw.githubusercontent.com/guycorbaz/mybibli/v1.20.0/docker-compose.yml
+curl -O https://raw.githubusercontent.com/guycorbaz/mybibli/v1.20.0/.env.example
cp .env.example .env
\end{lstlisting}
diff --git a/docs/manual/en/08-upgrade-migration.tex b/docs/manual/en/08-upgrade-migration.tex
index bdf1335..09ef69c 100644
--- a/docs/manual/en/08-upgrade-migration.tex
+++ b/docs/manual/en/08-upgrade-migration.tex
@@ -139,6 +139,32 @@ \section{Reading the release notes}
Read the notes before upgrading. Breaking changes are tagged with a
prominent \emph{Breaking} label.
+\section{What's new in 1.20.0}\label{sec:whats-new-1.20.0}
+
+Version 1.20.0 is a minor release on 1.19.0. \emph{No migration} ---
+pull the image, restart, done. It carries one change request.
+
+\begin{itemize}
+ \item \textbf{\#489 \string— where the labels end.} The
+ \texttt{/admin > Health} tab gains a \emph{Barcode labels}
+ section under the entity counters: the last volume number
+ (V-code) and the last shelf number (L-code) in use, each with
+ the next free number --- \texttt{V0142 (next: V0143)}. Read it
+ before printing a new sheet of pre-generated labels, so the
+ sheet starts right after the occupied range.
+
+ ``Last'' means the highest number ever printed, trashed items
+ included: a sticker already stuck on a book or a shelf is never
+ reissued. This is the rule the \texttt{/catalog} info line has
+ followed since 1.12.0, so the two surfaces always agree. An
+ empty catalog reads ``None yet''; \texttt{V9999} reads ``none
+ left'' rather than proposing a number the scanner would reject.
+ \item \textbf{Dependency fix.} The TLS library behind the outbound
+ metadata lookups (\texttt{rustls}) moves from 0.23.40 to
+ 0.23.45 for advisory RUSTSEC-2026-0285. No code change, nothing
+ to configure.
+\end{itemize}
+
\section{What's new in 1.19.0}\label{sec:whats-new-1.19.0}
Version 1.19.0 is a minor release on 1.18.0. \emph{No migration} ---
diff --git a/docs/manual/en/main.tex b/docs/manual/en/main.tex
index 5261396..35f4e25 100644
--- a/docs/manual/en/main.tex
+++ b/docs/manual/en/main.tex
@@ -98,7 +98,7 @@
% ---- Document metadata ----------------------------------------------
\title{\Huge\bfseries mybibli\\[6pt]\Large User Manual}
\author{The mybibli authors\\\small \texttt{https://github.com/guycorbaz/mybibli}}
-\date{Version 1.19.0 — \today}
+\date{Version 1.20.0 — \today}
% =====================================================================
\begin{document}
diff --git a/docs/manual/fr/01-installation.tex b/docs/manual/fr/01-installation.tex
index dc03ce8..2dcdd0d 100644
--- a/docs/manual/fr/01-installation.tex
+++ b/docs/manual/fr/01-installation.tex
@@ -125,8 +125,8 @@ \subsection*{1. Récupérer le fichier compose et le \texttt{.env}}
\begin{lstlisting}
mkdir -p /srv/mybibli && cd /srv/mybibli
-curl -O https://raw.githubusercontent.com/guycorbaz/mybibli/v1.19.0/docker-compose.yml
-curl -O https://raw.githubusercontent.com/guycorbaz/mybibli/v1.19.0/.env.example
+curl -O https://raw.githubusercontent.com/guycorbaz/mybibli/v1.20.0/docker-compose.yml
+curl -O https://raw.githubusercontent.com/guycorbaz/mybibli/v1.20.0/.env.example
cp .env.example .env
\end{lstlisting}
diff --git a/docs/manual/fr/08-upgrade-migration.tex b/docs/manual/fr/08-upgrade-migration.tex
index 08ba17e..266d300 100644
--- a/docs/manual/fr/08-upgrade-migration.tex
+++ b/docs/manual/fr/08-upgrade-migration.tex
@@ -148,6 +148,36 @@ \section{Lire les notes de version}
Lisez les notes avant de mettre à jour. Les breaking changes
portent une étiquette \emph{Breaking} bien visible.
+\section{Nouveautés de la 1.20.0}\label{sec:whats-new-1.20.0}
+
+La version 1.20.0 est une version mineure sur la 1.19.0.
+\emph{Aucune migration} --- on récupère l'image, on redémarre, c'est
+tout. Elle porte une seule demande de changement.
+
+\begin{itemize}
+ \item \textbf{\#489 \string— là où s'arrêtent les étiquettes.}
+ L'onglet \texttt{/admin > Health} gagne une section
+ \emph{Étiquettes à code-barres} sous les compteurs d'entités :
+ le dernier numéro de volume (code V) et le dernier numéro
+ d'étagère (code L) utilisés, chacun avec le prochain numéro
+ libre --- \texttt{V0142 (prochain : V0143)}. À consulter avant
+ d'imprimer une nouvelle planche d'étiquettes pré-générées, pour
+ qu'elle démarre juste après la plage occupée.
+
+ « Dernier » s'entend comme le numéro le plus élevé jamais
+ imprimé, corbeille comprise : une étiquette déjà collée sur un
+ livre ou une étagère n'est jamais réattribuée. C'est la règle
+ que suit la ligne d'information de \texttt{/catalog} depuis la
+ 1.12.0, si bien que les deux affichages concordent toujours. Un
+ catalogue vide affiche « Aucun pour l'instant » ; \texttt{V9999}
+ affiche « plus aucun disponible » plutôt que de proposer un
+ numéro que le lecteur de codes refuserait.
+ \item \textbf{Correctif de dépendance.} La bibliothèque TLS derrière
+ les recherches de métadonnées sortantes (\texttt{rustls}) passe
+ de la 0.23.40 à la 0.23.45 pour l'avis RUSTSEC-2026-0285. Aucun
+ changement de code, rien à configurer.
+\end{itemize}
+
\section{Nouveautés de la 1.19.0}\label{sec:whats-new-1.19.0}
La version 1.19.0 est une version mineure sur la 1.18.0.
diff --git a/docs/manual/fr/main.tex b/docs/manual/fr/main.tex
index 85985fd..3272dd2 100644
--- a/docs/manual/fr/main.tex
+++ b/docs/manual/fr/main.tex
@@ -98,7 +98,7 @@
% ---- Métadonnées du document ---------------------------------------
\title{\Huge\bfseries mybibli\\[6pt]\Large Manuel utilisateur}
\author{Les auteurs de mybibli\\\small \texttt{https://github.com/guycorbaz/mybibli}}
-\date{Version 1.19.0 — \today}
+\date{Version 1.20.0 — \today}
% =====================================================================
\begin{document}
diff --git a/docs/manual/mybibli-manual-en.pdf b/docs/manual/mybibli-manual-en.pdf
index aced77a..386b9ca 100644
Binary files a/docs/manual/mybibli-manual-en.pdf and b/docs/manual/mybibli-manual-en.pdf differ
diff --git a/docs/manual/mybibli-manual-fr.pdf b/docs/manual/mybibli-manual-fr.pdf
index 854f065..7912be5 100644
Binary files a/docs/manual/mybibli-manual-fr.pdf and b/docs/manual/mybibli-manual-fr.pdf differ
diff --git a/website/about.html b/website/about.html
index 531406a..7f7ad35 100644
--- a/website/about.html
+++ b/website/about.html
@@ -63,7 +63,7 @@
mybibli
- v1.19.0
+ v1.20.0