Skip to content

release: v0.4.0 - #113

Merged
snowmead merged 2 commits into
mainfrom
claude/magical-johnson-rf1yny
Oct 7, 2026
Merged

snowmead merged 2 commits into
mainfrom
claude/magical-johnson-rf1yny

Conversation

@snowmead

@snowmead snowmead commented Oct 7, 2026 •

Copy link
Copy Markdown
Owner

Lockstep bump of the workspace crates and language SDKs from 0.3.3 to 0.4.0, following the docs/PUBLISHING.md release checklist. Also bumps rustls to fix RUSTSEC-2026-0285 so the release doesn't ship a known TLS advisory.

Why a minor bump

The lifecycle overhaul (#109) breaks compatibility:

  • Lifecycle JSON envelopes move to schema_version: 2. Integration outputs are now instance-scoped secret_ref objects instead of plaintext credentials.
  • Host commands need an explicit --allow-host-execution grant (the SDKs expose the same option).
  • The shared-database fleet backend is removed. STACKLESS_STATE_URL is rejected, and remote use goes through --controller ssh://host.
  • The HuggingFace catalog integrations are removed (feat(stripe-projects): integrate plugin 0.37.0 → 0.39.1 #110).

Changes

  • Cargo.toml: sets [workspace.package].version and the [workspace.dependencies] pins to 0.4.0. Also bumps the render-client / vercel-client pins and Cargo.lock for the workspace crates.
  • sdks/typescript/package.json + package-lock.json, sdks/python/pyproject.toml: 0.4.0. scripts/check-sdk-versions.sh --tag v0.4.0 passes.
  • CHANGELOG.md: new v0.4.0 — 2026-10-07 section with Breaking / Added / Changed / Fixed / Security / Commits / Install. cargo-dist uses it for the GitHub Release notes.
  • Version references in README.md (go get …@v0.4.0), sdks/go/README.md, docs/PUBLISHING.md, web/public/start.md, and web/public/llms.txt. llms.txt previously said "0.2.1 or newer", but it already describes post-overhaul behavior.
  • Security: rustls 0.23.40 → 0.23.45 for RUSTSEC-2026-0285. The advisory was published after main's last CI run, so cargo audit started failing. The bump also moves rustls-webpki → 0.103.15, aws-lc-rs → 1.18.1 and aws-lc-sys → 0.45.0. The existing cargo vet safe-to-deploy exemptions for those four crates move to the new versions (maintainer-approved). Licenses are unchanged and no new crates enter the graph.

Validation

  • cargo metadata --locked passes and cargo check --workspace --locked builds.
  • scripts/check-sdk-versions.sh --tag v0.4.0 reports lockstep version: 0.4.0 and tag ok: v0.4.0.
  • cargo audit exits 0. cargo vet reports "Vetting Succeeded (2 partially audited, 372 exempted)".

After merge

From the merge commit:

git tag v0.4.0
git tag sdks/go/v0.4.0
git push origin v0.4.0 sdks/go/v0.4.0

v0.4.0 starts cargo-dist (GitHub Release + installer) and publish-packages.yml (crates.io, npm, PyPI). sdks/go/v0.4.0 serves the Go module proxy.

🤖 Generated with Claude Code

https://claude.ai/code/session_015Ems9j3X569RjZWeVnRG65

Lockstep bump workspace crates and language SDKs to 0.4.0. Minor bump
because the lifecycle overhaul (#109) changes the JSON envelope to
schema_version 2 (secret_ref outputs), requires --allow-host-execution
for host commands, and removes the shared-database fleet backend.
CHANGELOG also covers Stripe Projects plugin 0.35.0 → 0.40.0 and the
new herenow, perplexity, and churnkey catalog integrations.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_015Ems9j3X569RjZWeVnRG65
@vercel

vercel Bot commented Oct 7, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
stackless Ready Ready Preview Oct 7, 2026 3:57pm UTC

@snowmead

snowmead commented Oct 7, 2026

Copy link
Copy Markdown
Owner Author

supply-chain is red because of a new advisory, not because of this PR. cargo audit flags RUSTSEC-2026-0285 in rustls 0.23.40 (TLS 1.3 handshake messages accepted across encryption-level boundaries, medium; fixed in >=0.23.45). The advisory was published 2026-09-14, after main's last CI run (2026-09-13), and this PR changes no third-party crates. Main would fail the same check today.

Fix tested locally, not pushed yet. cargo update -p rustls --precise 0.23.45 makes cargo audit pass, and cargo check --workspace --locked still builds. It also bumps aws-lc-rs 1.17.0 → 1.18.1, aws-lc-sys 0.41.0 → 0.45.0 and rustls-webpki 0.103.13 → 0.103.15, so cargo vet then fails on those four unvetted versions. The aws-lc-sys delta alone is about 126k lines. Per docs/DEPENDENCY-REVIEW.md, vetting these needs a maintainer decision: new exemptions, importing third-party audits, or approved delta certifications. I've asked for that decision and will push the bump plus the vet update once it's made. I'm not re-running CI because the advisory fails it the same way every time.


Generated by Claude Code

cargo audit fails on rustls 0.23.40 (TLS 1.3 handshake messages accepted
across encryption-level boundaries). Bump to 0.23.45, which pulls
rustls-webpki 0.103.15, aws-lc-rs 1.18.1, and aws-lc-sys 0.45.0, and
move the existing cargo-vet safe-to-deploy exemptions to those versions.
Licenses are unchanged and no new crates enter the graph.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_015Ems9j3X569RjZWeVnRG65
@snowmead
snowmead merged commit 340eb32 into main Oct 7, 2026
23 checks passed

This branch was successfully deployed

1 active deployment
Preview — 2e81adc7 Deployed Oct 7, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants