diff --git a/CHANGELOG.md b/CHANGELOG.md index e7965b6..8710123 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -1,5 +1,21 @@ # Changelog +## 0.1.2 + +Native installations whose executable bytes drifted from their verified +install receipt repair instead of deadlocking. + +- An explicit `update` reinstalls a verified release, preserving the drifted + bytes beside the install record and restoring a pinned install to its pin. +- `update status` and `update check` report `mismatch` instead of failing + before command dispatch. +- Automatic-policy startups repair and re-enter the verified image before + product work; saved opt-outs and incidental-suppression contexts fail closed + exactly as before. Attempts are bounded daily by a dedicated stamp. +- Replacement transactions keep every ownership check: the stored receipt is + the invariant, the recorded pin may no longer be changed by a replacement, + and foreign or ambiguous installations still refuse to run. + ## 0.1.1 Consumers can independently pin direct and transitive updater releases. diff --git a/Cargo.lock b/Cargo.lock index 6d7c4de..29763ea 100644 --- a/Cargo.lock +++ b/Cargo.lock @@ -68,7 +68,7 @@ dependencies = [ [[package]] name = "hraness-cli-update" -version = "0.1.1" +version = "0.1.2" dependencies = [ "fs2", "libc", diff --git a/README.md b/README.md index 384a9aa..2fe5135 100644 --- a/README.md +++ b/README.md @@ -16,7 +16,7 @@ automatic updates off or request an update directly. Requires Node 22 or Bun 1.3.14 or later. Install the released library archive: ```sh -bun add https://github.com/hraness/cli-update/releases/download/v0.1.1/hraness-cli-update-0.1.1.tgz +bun add https://github.com/hraness/cli-update/releases/download/v0.1.2/hraness-cli-update-0.1.2.tgz ``` Automatic package replacement currently supports macOS and Linux global diff --git a/VERIFY.md b/VERIFY.md index 28a663e..1fa87fd 100644 --- a/VERIFY.md +++ b/VERIFY.md @@ -7,7 +7,7 @@ commit and the matching immutable Git tag. Rust consumers use that tag. Choose a release and download its assets with the GitHub CLI: ```sh -tag=v0.1.1 +tag=v0.1.2 gh release download "$tag" --repo hraness/cli-update --pattern '*.tgz' --pattern SHA256SUMS shasum -a 256 -c SHA256SUMS gh attestation verify hraness-cli-update-${tag#v}.tgz --repo hraness/cli-update --signer-workflow hraness/cli-update/.github/workflows/release.yml --source-ref "refs/tags/$tag" diff --git a/package.json b/package.json index b1c771c..ce7d696 100644 --- a/package.json +++ b/package.json @@ -1,6 +1,6 @@ { "name": "@hraness/cli-update", - "version": "0.1.1", + "version": "0.1.2", "description": "Automatic updates for installed CLIs, with installation checks and a shared opt-out.", "license": "MIT", "type": "module", diff --git a/rust/Cargo.toml b/rust/Cargo.toml index 44fe34b..c8eed51 100644 --- a/rust/Cargo.toml +++ b/rust/Cargo.toml @@ -1,6 +1,6 @@ [package] name = "hraness-cli-update" -version = "0.1.1" +version = "0.1.2" edition = "2021" rust-version = "1.85" description = "Policy, ownership, and release verification for Hraness native CLI updates" diff --git a/rust/README.md b/rust/README.md index 1356bf2..f79fa15 100644 --- a/rust/README.md +++ b/rust/README.md @@ -10,7 +10,7 @@ Add the crate from an immutable release tag: ```toml [dependencies] -hraness-cli-update = { git = "https://github.com/hraness/cli-update", tag = "v0.1.1" } +hraness-cli-update = { git = "https://github.com/hraness/cli-update", tag = "v0.1.2" } ``` ## Executable integration