release: v0.10.6 — version bump so the release gate can pass - #269
Merged
Merged
Conversation
Bump node, python and both ClawHub skill manifests 0.10.5 -> 0.10.6, and record what this release ships. 0.10.6 carries five fixes already on main: - Unhandled errors no longer print the API key in a traceback (#264) - A project .env can no longer supply RAFTER_* settings, including the API key (#265) — behavior change, noted in the CHANGELOG - rafter run now checks that an auto-detected branch has been pushed before scanning it (#266) - rafter secrets --diff / rafter agent scan --diff reject an option-shaped ref before it reaches git (#267) - rafter agent init --local --with-gemini no longer runs gemini through a shell (#268) Verified via scripts/check-version-unpublished.sh that 0.10.6 is not yet on npm or PyPI.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Why this exists
Five fixes are already merged to
main(#264, #265, #266, #267, #268) and cannot ship, because the release gate added in #256 correctly refuses to publish a version that is already on the registry.mainstill says0.10.5, and npm and PyPI already serve0.10.5. The bump is the only thing standing betweenmainand a release.Verified both directions before opening this:
What 0.10.6 ships
All five already merged to
main:.envcan no longer supply Rafter's own settings (fix: never take RAFTER_* settings from a project .env #265). Previously a.envin the working directory could overrideRAFTER_API_KEYand otherRAFTER_*settings you configured yourself. Behavior change: if you relied onRAFTER_API_KEYin a project.env, move it to your shell environment or~/.rafter/config.json— the CLI will now report the key as missing if.envwas its only source.rafter runnow checks that an auto-detected branch has been pushed before scanning it (fix(run): refuse an auto-detected branch that is not on the remote #266). Running without--branchfrom a branch that doesn't exist on the remote used to queue a scan that failed later with a "branch not found" error; it now fails fast with a clear message.rafter secrets --diff/rafter agent scan --diffreject an option-shaped ref before it reaches git (fix(secrets): reject a --diff ref that starts with "-" #267). A--diffvalue starting with-could previously be misread by git as an option rather than a ref.rafter agent init --local --with-geminino longer runs through a shell (fix(node): pass paths to child processes as arguments, not shell strings #268). A path containing shell metacharacters could previously have part of it executed during skill registration.Order of operations
This PR only lands the bump on
main. Merging it does not publish anything. The promote PR (main->prod) is what publishes, and it cannot go green until this is onmain. The promote PR is already open and will go green once this merges.After the promote merges, check the registry, not the job:
npm view @rafter-security/cli versionmust read0.10.6.Checks run locally
tsc --noEmit: cleanpnpm run build): cleanvitest run, capped workers, serial files): 2313 passed, 9 skipped, 7 failed — the 7 failures are pre-existing and environment-specific to this box, not caused by this branch: verified by running the identical test files against unmodifiedorigin/mainand getting the same 7 failures (stale systempython3editable install reporting0.9.0from an unrelated checkout, and a pre-existing~/.rafter/config.json/~/.cursorstate that no CI runner has). 3 of the 7 are the known Cursor-hook failures already called out in fix: never take RAFTER_* settings from a project .env #265-fix(node): pass paths to child processes as arguments, not shell strings #268.pytest tests/, isolatedHOME): 1757 passed, 1 skipped, 0 failedscripts/check-version-unpublished.sh 0.10.6: passes for both npm and PyPI