Skip to content

release: v0.10.6 — version bump so the release gate can pass - #269

Merged
Raftersecurity merged 1 commit into
mainfrom
release/v0.10.6
Oct 2, 2026
Merged

Raftersecurity merged 1 commit into
mainfrom
release/v0.10.6

Conversation

@Rome-1

@Rome-1 Rome-1 commented Oct 2, 2026

Copy link
Copy Markdown
Collaborator

Why this exists

Five fixes are already merged to main (#264, #265, #266, #267, #268) and cannot ship, because the release gate added in #256 correctly refuses to publish a version that is already on the registry. main still says 0.10.5, and npm and PyPI already serve 0.10.5. The bump is the only thing standing between main and a release.

Verified both directions before opening this:

./scripts/check-version-unpublished.sh 0.10.6   ->  exit 0   (ok: not published, both registries)
./scripts/check-version-unpublished.sh 0.10.5   ->  exit 1   (correctly refuses)

What 0.10.6 ships

All five already merged to main:

Order of operations

This PR only lands the bump on main. Merging it does not publish anything. The promote PR (main -> prod) is what publishes, and it cannot go green until this is on main. The promote PR is already open and will go green once this merges.

After the promote merges, check the registry, not the job: npm view @rafter-security/cli version must read 0.10.6.

Checks run locally

  • tsc --noEmit: clean
  • Node build (pnpm run build): clean
  • Node test suite (vitest run, capped workers, serial files): 2313 passed, 9 skipped, 7 failed — the 7 failures are pre-existing and environment-specific to this box, not caused by this branch: verified by running the identical test files against unmodified origin/main and getting the same 7 failures (stale system python3 editable install reporting 0.9.0 from an unrelated checkout, and a pre-existing ~/.rafter/config.json / ~/.cursor state that no CI runner has). 3 of the 7 are the known Cursor-hook failures already called out in fix: never take RAFTER_* settings from a project .env #265-fix(node): pass paths to child processes as arguments, not shell strings #268.
  • Python test suite (pytest tests/, isolated HOME): 1757 passed, 1 skipped, 0 failed
  • scripts/check-version-unpublished.sh 0.10.6: passes for both npm and PyPI

Bump node, python and both ClawHub skill manifests 0.10.5 -> 0.10.6, and
record what this release ships.

0.10.6 carries five fixes already on main:

- Unhandled errors no longer print the API key in a traceback (#264)
- A project .env can no longer supply RAFTER_* settings, including the API
  key (#265) — behavior change, noted in the CHANGELOG
- rafter run now checks that an auto-detected branch has been pushed
  before scanning it (#266)
- rafter secrets --diff / rafter agent scan --diff reject an option-shaped
  ref before it reaches git (#267)
- rafter agent init --local --with-gemini no longer runs gemini through a
  shell (#268)

Verified via scripts/check-version-unpublished.sh that 0.10.6 is not yet on
npm or PyPI.
@Raftersecurity
Raftersecurity merged commit eda0fab into main Oct 2, 2026
10 checks passed
@Raftersecurity
Raftersecurity deleted the release/v0.10.6 branch October 2, 2026 21:10
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants