diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 0ad7536..04500cf 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -30,7 +30,7 @@ jobs: name: rust permissions: contents: read - uses: NDDev-OpenNetwork/ci-workflows/.github/workflows/rust-ci.yml@e90a2c7c6c25cd1fb9ac1c68adbc7535f8b17e1e + uses: NDDev-OpenNetwork/ci-workflows/.github/workflows/rust-ci.yml@b4421b8660a7b6462095a9f492ea012b2a609abe # 0.1.17 with: toolchain: '1.98.0' # The three-OS matrix is the evidence ADR-0113 asks for, and standard @@ -46,7 +46,7 @@ jobs: name: supply-chain permissions: contents: read - uses: NDDev-OpenNetwork/ci-workflows/.github/workflows/rust-supply-chain.yml@e90a2c7c6c25cd1fb9ac1c68adbc7535f8b17e1e + uses: NDDev-OpenNetwork/ci-workflows/.github/workflows/rust-supply-chain.yml@b4421b8660a7b6462095a9f492ea012b2a609abe # 0.1.17 with: enable_deny: true enable_audit: true @@ -56,7 +56,7 @@ jobs: name: actionlint permissions: contents: read - uses: NDDev-OpenNetwork/ci-workflows/.github/workflows/actionlint.yml@e90a2c7c6c25cd1fb9ac1c68adbc7535f8b17e1e + uses: NDDev-OpenNetwork/ci-workflows/.github/workflows/actionlint.yml@b4421b8660a7b6462095a9f492ea012b2a609abe # 0.1.17 pr-hygiene: name: pr-hygiene @@ -68,7 +68,7 @@ jobs: # that would use them is off. issues: write # the stale bot closes threads pull-requests: write # the labeler applies labels - uses: NDDev-OpenNetwork/ci-workflows/.github/workflows/pr-hygiene.yml@e90a2c7c6c25cd1fb9ac1c68adbc7535f8b17e1e + uses: NDDev-OpenNetwork/ci-workflows/.github/workflows/pr-hygiene.yml@b4421b8660a7b6462095a9f492ea012b2a609abe # 0.1.17 boundary: diff --git a/.github/workflows/security.yml b/.github/workflows/security.yml index 11a7bac..0829342 100644 --- a/.github/workflows/security.yml +++ b/.github/workflows/security.yml @@ -26,7 +26,7 @@ jobs: actions: read # CodeQL reads the workflow definitions it analyses contents: read security-events: write # CodeQL publishes its findings to code scanning - uses: NDDev-OpenNetwork/ci-workflows/.github/workflows/public-codeql.yml@e90a2c7c6c25cd1fb9ac1c68adbc7535f8b17e1e + uses: NDDev-OpenNetwork/ci-workflows/.github/workflows/public-codeql.yml@b4421b8660a7b6462095a9f492ea012b2a609abe # 0.1.17 with: languages: '["rust", "actions"]' queries: security-and-quality @@ -37,7 +37,7 @@ jobs: permissions: contents: read pull-requests: write # writes the review it produces - uses: NDDev-OpenNetwork/ci-workflows/.github/workflows/public-dependency-review.yml@e90a2c7c6c25cd1fb9ac1c68adbc7535f8b17e1e + uses: NDDev-OpenNetwork/ci-workflows/.github/workflows/public-dependency-review.yml@b4421b8660a7b6462095a9f492ea012b2a609abe # 0.1.17 with: fail_on_severity: moderate @@ -52,13 +52,13 @@ jobs: contents: read id-token: write # mints the OIDC token Scorecard's publication is signed with security-events: write # Scorecard publishes its findings to code scanning - uses: NDDev-OpenNetwork/ci-workflows/.github/workflows/public-scorecard.yml@e90a2c7c6c25cd1fb9ac1c68adbc7535f8b17e1e + uses: NDDev-OpenNetwork/ci-workflows/.github/workflows/public-scorecard.yml@b4421b8660a7b6462095a9f492ea012b2a609abe # 0.1.17 osv: name: osv permissions: contents: read - uses: NDDev-OpenNetwork/ci-workflows/.github/workflows/osv-scan.yml@e90a2c7c6c25cd1fb9ac1c68adbc7535f8b17e1e + uses: NDDev-OpenNetwork/ci-workflows/.github/workflows/osv-scan.yml@b4421b8660a7b6462095a9f492ea012b2a609abe # 0.1.17 zizmor: name: zizmor @@ -66,10 +66,10 @@ jobs: actions: read # the SARIF upload reads this run to attach its results contents: read security-events: write # zizmor publishes its findings to code scanning - uses: NDDev-OpenNetwork/ci-workflows/.github/workflows/zizmor-sarif.yml@e90a2c7c6c25cd1fb9ac1c68adbc7535f8b17e1e + uses: NDDev-OpenNetwork/ci-workflows/.github/workflows/zizmor-sarif.yml@b4421b8660a7b6462095a9f492ea012b2a609abe # 0.1.17 secret-scan: name: secret-scan permissions: contents: read - uses: NDDev-OpenNetwork/ci-workflows/.github/workflows/secret-scan.yml@e90a2c7c6c25cd1fb9ac1c68adbc7535f8b17e1e + uses: NDDev-OpenNetwork/ci-workflows/.github/workflows/secret-scan.yml@b4421b8660a7b6462095a9f492ea012b2a609abe # 0.1.17 diff --git a/CHANGELOG.md b/CHANGELOG.md index 3d04de5..050a26c 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -15,6 +15,16 @@ cut and that this clone does not carry. ## [Unreleased] +## [0.0.72] - 2026-09-16 + +nddev-builder guidance is refreshed against each harness's current native +extension model. Software artifacts are refreshed from verified vendor bytes: +Claude Code 2.1.273, Grok Build 1.0.34, OpenCode 1.18.31 and Antigravity CLI +1.2.4. Codex remains 0.154.0, Cursor 2026.09.10-fd3934a and Pi 0.85.1. +Public reusable workflows pin ci-workflows 0.1.17 +(b4421b8660a7b6462095a9f492ea012b2a609abe). Previous artifact pins remain +available for rollback. + ## [0.0.71] - 2026-09-13 nddev-builder guidance is refreshed against each harness's current native diff --git a/Cargo.lock b/Cargo.lock index 30748fe..8cc2896 100644 --- a/Cargo.lock +++ b/Cargo.lock @@ -25,7 +25,7 @@ checksum = "9330f8b2ff13f34540b44e946ef35111825727b38d33286ef986142615121801" [[package]] name = "codex-setup-system" -version = "0.0.71" +version = "0.0.72" dependencies = [ "harness-runtime", "provider-v3", @@ -76,7 +76,7 @@ checksum = "877a4ace8713b0bcf2a4e7eec82529c029f1d0619886d18145fea96c3ffe5c0f" [[package]] name = "harness-runtime" -version = "0.0.71" +version = "0.0.72" dependencies = [ "provider-v3", "serde", @@ -147,7 +147,7 @@ dependencies = [ [[package]] name = "provider-v3" -version = "0.0.71" +version = "0.0.72" dependencies = [ "serde", "serde_json", @@ -209,7 +209,7 @@ dependencies = [ [[package]] name = "setup-core" -version = "0.0.71" +version = "0.0.72" dependencies = [ "miniz_oxide", "serde", diff --git a/Cargo.toml b/Cargo.toml index 016ae38..5ddc5ef 100644 --- a/Cargo.toml +++ b/Cargo.toml @@ -8,7 +8,7 @@ members = [ ] [workspace.package] -version = "0.0.71" +version = "0.0.72" edition = "2024" rust-version = "1.89" license = "AGPL-3.0-or-later" @@ -23,9 +23,9 @@ sha2 = "0.11" # `setup-core::archive`); an inflate loop is not, because its bugs are # memory-safety bugs and it is not improved by being hand-written here. miniz_oxide = "0.9" -setup-core = { path = "crates/setup-core", version = "0.0.71" } -provider-v3 = { path = "crates/provider-v3", version = "0.0.71" } -harness-runtime = { path = "crates/harness-runtime", version = "0.0.71" } +setup-core = { path = "crates/setup-core", version = "0.0.72" } +provider-v3 = { path = "crates/provider-v3", version = "0.0.72" } +harness-runtime = { path = "crates/harness-runtime", version = "0.0.72" } [workspace.lints.rust] unsafe_code = "forbid" diff --git a/README.md b/README.md index 391114c..1ea9b86 100644 --- a/README.md +++ b/README.md @@ -179,7 +179,7 @@ release is a convenience, not the authorised copy. ```bash docker run --rm -v "$HOME/.config:/config" \ - ghcr.io/nddev-opennetwork/codex-setup-system:0.0.71 \ + ghcr.io/nddev-opennetwork/codex-setup-system:0.0.72 \ status --target /config/