diff --git a/CHANGELOG.md b/CHANGELOG.md index 898dd00..3180e9f 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -1,5 +1,11 @@ # Changelog +## 0.4.0 (2026-09-22) + +### Features + +- **policy:** bound commit subject length in git.naming (#31) (38116ad) + ## 0.3.2 (2026-09-08) ### Bug Fixes diff --git a/README.md b/README.md index b4f5b92..a2139c6 100644 --- a/README.md +++ b/README.md @@ -13,8 +13,8 @@ Hoolicy turns repeated repository, compliance, supply-chain, and product-quality Install a release binary, use the container, or build with Go 1.26+: ```sh -go install github.com/openhoo/hoolicy/cmd/hoolicy@v0.3.2 -# or: docker run --rm --user "$(id -u):$(id -g)" -v "$PWD:/work:ro" -w /work ghcr.io/openhoo/hoolicy:v0.3.2 check +go install github.com/openhoo/hoolicy/cmd/hoolicy@v0.4.0 +# or: docker run --rm --user "$(id -u):$(id -g)" -v "$PWD:/work:ro" -w /work ghcr.io/openhoo/hoolicy:v0.4.0 check ``` For rootless Podman, add `--userns=keep-id`. Mapping the caller UID lets the non-root image read private repository files without weakening their host permissions. @@ -107,7 +107,7 @@ Use this repository as a versioned remote pack source: packs: - name: repository git: https://github.com/openhoo/hoolicy.git - ref: v0.3.2 + ref: v0.4.0 subdir: packs/repository with: branch_pattern: '^(feat|fix|chore)/[a-z0-9]+(?:-[a-z0-9]+)*$' diff --git a/SECURITY.md b/SECURITY.md index ded2d9d..0bad821 100644 --- a/SECURITY.md +++ b/SECURITY.md @@ -2,7 +2,7 @@ ## Supported versions -Security fixes target the latest `v0.3.x` release until a newer minor line is published. +Security fixes target the latest `v0.4.x` release until a newer minor line is published. ## Reporting a vulnerability diff --git a/VERSION b/VERSION index d15723f..1d0ba9e 100644 --- a/VERSION +++ b/VERSION @@ -1 +1 @@ -0.3.2 +0.4.0 diff --git a/actions/README.md b/actions/README.md index 54df01b..f07ece8 100644 --- a/actions/README.md +++ b/actions/README.md @@ -5,7 +5,7 @@ Use immutable action revisions in consuming repositories. ```yaml - uses: openhoo/hoolicy/actions/check@ with: - version: 0.3.2 + version: 0.4.0 ``` `actions/setup` installs a pinned Cosign verifier, downloads the release archive, diff --git a/actions/check/action.yml b/actions/check/action.yml index 9ee224a..8f46a6d 100644 --- a/actions/check/action.yml +++ b/actions/check/action.yml @@ -4,7 +4,7 @@ inputs: version: description: Hoolicy release version to install. required: false - default: "0.3.2" + default: "0.4.0" executable: description: Optional Hoolicy executable path; skips release installation when set. required: false diff --git a/actions/setup/action.yml b/actions/setup/action.yml index 51d3e17..7d59e5d 100644 --- a/actions/setup/action.yml +++ b/actions/setup/action.yml @@ -4,7 +4,7 @@ inputs: version: description: Hoolicy release version to install. required: false - default: "0.3.2" + default: "0.4.0" outputs: version: description: Hoolicy version configured by this action.