Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
116 commits
Select commit Hold shift + click to select a range
4867a12
docs: add public community and release guides
Obed0101 Jun 13, 2026
5436921
ci: harden release supply chain gates
Obed0101 Jun 13, 2026
2e0ae10
docs: expand MendCode customization guide (#69)
Obed0101 Jun 13, 2026
ad9d4cd
docs: show mascot only in README header (#71)
Obed0101 Jun 13, 2026
1758ed5
docs: remove README mascot header (#74)
Obed0101 Jun 13, 2026
6b0e0b8
fix: show MendCode version on welcome
Obed0101 Jun 13, 2026
5c5e907
fix: align MendCode version and CLI name (#76)
Obed0101 Jun 13, 2026
60ca445
chore: sync main back to dev (#79)
Obed0101 Jun 13, 2026
b1da5d7
docs: add MendCode release flow skill (#81)
Obed0101 Jun 13, 2026
120c218
Add Agent View welcome date context (#80)
Obed0101 Jun 13, 2026
bfa5fd4
[codex] Backport OpenCode terminal and SDK fixes (#83)
Obed0101 Jun 13, 2026
f319f37
fix: prepare v0.1.4 compaction and prompt fixes (#85)
Obed0101 Jun 13, 2026
a745852
Backport OpenCode runtime updates for v0.1.5 (#88)
Obed0101 Jun 13, 2026
4923808
fix: release v0.1.6 memory injection (#91)
Obed0101 Jun 14, 2026
f58608f
feat: add usage insights dashboard (#95)
Obed0101 Jun 14, 2026
2d06971
fix: release v0.1.7 setup memory UX (#98)
Obed0101 Jun 14, 2026
3026de0
fix: complete v0.1.7 memory and docs (#100)
Obed0101 Jun 14, 2026
da84090
fix: release v0.1.8 stats cache and installer
Obed0101 Jun 14, 2026
14ce846
fix: simplify public cli and compaction resume (#107)
Obed0101 Jun 14, 2026
0096300
docs: add v0.1.9 changelog (#110)
Obed0101 Jun 14, 2026
37fa1cc
feat: prepare v0.1.10 tui and memory updates (#112)
Obed0101 Jun 15, 2026
cb0d14b
fix: prepare v0.1.11 tui and mflow updates (#115)
Obed0101 Jun 15, 2026
8f50f67
feat: prepare v0.1.12 rendering and installer updates (#118)
Obed0101 Jun 16, 2026
81543d6
chore: unblock v0.1.12 release dependencies (#122)
Obed0101 Jun 16, 2026
5a64c04
feat: prepare v0.1.13 release
Obed0101 Jun 16, 2026
20c6c6c
fix: update hono for v0.1.13 release
Obed0101 Jun 16, 2026
3cf5668
feat: prepare v0.1.14 package registry release (#132)
Obed0101 Jun 17, 2026
fb18a00
fix: update protobufjs for v0.1.14 release (#136)
Obed0101 Jun 17, 2026
741eedc
release: prepare v0.1.15
Obed0101 Jun 20, 2026
ff6b51c
fix: sync release dependency gates to dev
Obed0101 Jun 20, 2026
6ef1f04
fix: sync final OSV versions to dev
Obed0101 Jun 20, 2026
e8e9a86
fix: allow urgent OSV release versions through age gate (#145) (#146)
Obed0101 Jun 20, 2026
1bde962
Add Usage Insights screenshot (#147)
Obed0101 Jun 20, 2026
1eb370a
docs: sync v0.1.15 summary to dev (#149)
Obed0101 Jun 20, 2026
9b495a0
docs: expand memory center side agent guidance (#150)
Obed0101 Jun 20, 2026
e184095
fix: apply dream schedule proposals (#152)
Obed0101 Jun 20, 2026
e842d8f
docs: update website domain (#155)
Obed0101 Jun 20, 2026
96cb067
docs: remove personal release examples (#158)
Obed0101 Jun 20, 2026
eb8cab2
feat: add loop workflows and changes review
Obed0101 Jun 23, 2026
4c9a564
docs: add workflow screenshots (#163)
Obed0101 Jun 23, 2026
09a9f8a
fix: harden loop workflows (#165)
Obed0101 Jun 23, 2026
825d9b3
fix: keep loops cursor out of detail rows (#168)
Obed0101 Jun 24, 2026
d8a3920
fix: remove loops dashboard cursor sink (#171)
Obed0101 Jun 24, 2026
650323f
feat(loop): add goal budgets and optimize release ci
Obed0101 Jun 24, 2026
58eadd8
release: prepare v0.1.19 (#176)
Obed0101 Jun 26, 2026
9f49990
release: prepare v0.1.20 (#179)
Obed0101 Jul 27, 2026
69b7761
docs(readme): move branding to top and bottom (#181)
Obed0101 Jul 27, 2026
d30f242
fix: harden release dependencies and binary patches (#184)
Obed0101 Jul 28, 2026
0f99ed8
fix: update release dependency pins (#187)
Obed0101 Jul 28, 2026
47f40d6
docs: sync v0.1.20 changelog metadata (#189)
Obed0101 Jul 28, 2026
c7b27e7
feat: consolidate v0.1.20 TUI and runtime updates
Obed0101 Jul 28, 2026
6ace97a
fix: prevent hidden prompt leakage during questions (#194)
Obed0101 Jul 28, 2026
963afc6
docs: refresh README screenshots
Obed0101 Jul 29, 2026
21ba618
release: prepare v0.1.21
Obed0101 Jul 30, 2026
4e9f59f
fix(upgrade): show patch update notifications by default (#205)
Obed0101 Jul 30, 2026
d4fcff5
sync: carry v0.1.22 release fixes back to dev (#209)
Obed0101 Jul 30, 2026
38d47b5
release: prepare v0.1.23 session reliability update (#210)
Obed0101 Jul 31, 2026
582b0e6
fix(release): validate public help output across platforms (#213)
Obed0101 Jul 31, 2026
0e3abe3
fix(release): make help smoke test platform-independent (#215)
Obed0101 Jul 31, 2026
472e889
fix: harden runtime cleanup and session state (#218)
Obed0101 Aug 1, 2026
3743231
fix: repair compacted session cancellation state (#221)
Obed0101 Aug 1, 2026
5a9c608
fix(upgrade): make in-app updates transport-independent (#224)
Obed0101 Aug 2, 2026
e978f36
release: prepare v0.1.27 TUI reliability update (#226)
Obed0101 Aug 2, 2026
42386a5
feat: add durable workflows and harden background lifecycle (#230)
Obed0101 Aug 4, 2026
1d84441
fix: patch vulnerable release dependencies (#232)
Obed0101 Aug 4, 2026
df86414
fix(installer): skip setup prompt without TTY (#235)
Obed0101 Aug 4, 2026
4135338
fix(installer): make Windows downloads resilient
Obed0101 Aug 4, 2026
18ce846
release: prepare v0.1.29 Windows installer fixes
Obed0101 Aug 4, 2026
005bedf
release: prepare v0.1.30 runtime reliability update (#241)
Obed0101 Aug 5, 2026
0cd8ecf
fix(release): build Windows assets on native architectures (#244)
Obed0101 Aug 5, 2026
2cca2e4
fix(release): harden Windows baseline and long-running TUI state (#246)
Obed0101 Aug 5, 2026
1c371c3
fix(release): finalize v0.1.30 TUI recovery and notes (#249)
Obed0101 Aug 5, 2026
1f3ea62
fix(runtime): harden session and workflow recovery (#252)
Obed0101 Aug 8, 2026
50effea
release: integrate v0.1.30 runtime and TUI improvements (#254)
Obed0101 Aug 18, 2026
fa70a2f
chore(deps): bump dompurify to 3.4.13 (#258)
Obed0101 Aug 18, 2026
a40ca02
fix(deps): synchronize DOMPurify lockfile (#259) (#260)
Obed0101 Aug 18, 2026
7d07d19
fix(deps): patch release dependency vulnerabilities (#261) (#262)
Obed0101 Aug 18, 2026
08a736c
fix: stabilize Mermaid interaction and test isolation (#264)
Obed0101 Aug 18, 2026
5d65f77
release: prepare v0.1.31 Loop and Workflow verification (#266)
Obed0101 Aug 19, 2026
d050452
fix: harden long-running session controls (#269)
Obed0101 Aug 20, 2026
65ee075
fix: ship v0.1.33 reliability hotfix (#271)
Obed0101 Aug 20, 2026
ebe810c
fix: size short reasoning blocks (#274)
Obed0101 Aug 21, 2026
b21289f
fix: preserve v prefix in release names (#277)
Obed0101 Aug 21, 2026
2029d45
release: prepare v0.1.35 (#279)
Obed0101 Aug 22, 2026
d4b4cf1
release: prepare v0.1.36 (#281)
Obed0101 Aug 23, 2026
16e6bee
release: prepare v0.1.37
Obed0101 Aug 24, 2026
57a9f3a
release: prepare v0.1.38 (#288)
Obed0101 Aug 25, 2026
4bf92e3
docs: reorganize navigation and Mermaid fixtures
Obed0101 Aug 25, 2026
93bd6cd
release: prepare v0.1.39
Obed0101 Aug 26, 2026
741fcc2
release: prepare v0.1.40 (#297)
Obed0101 Aug 26, 2026
2cc07aa
🐛 fix(release): ship v0.1.41 session and branding hotfix (#299)
Obed0101 Aug 29, 2026
34129d6
🔒 fix(deps): upgrade pacote to 21.5.1 (#301)
Obed0101 Aug 29, 2026
412283c
fix: prevent deletion of unregistered worktree directories (#304)
Obed0101 Sep 3, 2026
354c63a
release: prepare v0.1.42 (#305)
Obed0101 Sep 3, 2026
f203832
fix: refresh release dependency security pins (#308)
Obed0101 Sep 3, 2026
d2f3899
fix: refresh toml security pin (#310)
Obed0101 Sep 3, 2026
cf6d689
fix: make v0.1.42 release installs reproducible (#311)
Obed0101 Sep 3, 2026
e87414c
fix: verify release attestations one artifact at a time
Obed0101 Sep 4, 2026
9a88189
release: prepare v0.1.43 (#315)
Obed0101 Sep 4, 2026
0d4535c
Prepare v0.1.44-beta.1: updater recovery, channels and opt-in continu…
Obed0101 Sep 5, 2026
baa46f1
fix: let backend database preparation finish before client readiness …
Obed0101 Sep 5, 2026
4d80b13
docs: reconcile stable recovery release with beta guidance (#322)
Obed0101 Sep 5, 2026
995a6a6
Add backend Smart Approval, context diagnostics and confined tool orc…
Obed0101 Sep 6, 2026
081ddb3
Integrate compaction and reliability for experimental beta.4 (#324)
Obed0101 Sep 7, 2026
f8a205b
Fix qs vulnerabilities blocking beta.4 release (#325)
Obed0101 Sep 7, 2026
4e3b991
fix: make repeated Esc cancellation terminal
Obed0101 Sep 9, 2026
4f8e510
fix: unblock beta.5 release dependency scan
Obed0101 Sep 9, 2026
ff31077
fix: unblock loop completion and queued prompt controls
Obed0101 Sep 10, 2026
c940e04
fix: preserve TUI transcript follow during reflow (#331)
Obed0101 Sep 10, 2026
40dc837
fix(installer): tolerate transient Windows executable locks (#333)
Obed0101 Sep 10, 2026
48c5dd0
feat: add passive prompt-cache controls
Obed0101 Sep 11, 2026
06217f8
Release v0.1.44-beta.14 reliability candidate (#336)
Obed0101 Sep 14, 2026
d080b73
Fix prerelease pnpm runtime (#337)
Obed0101 Sep 14, 2026
c9339c7
fix: restore beta database migration compatibility (#339)
Obed0101 Sep 14, 2026
544962f
feat: prepare beta16 memory and provider evolution (#340)
Obed0101 Sep 23, 2026
0d8008c
fix: preserve main schema guard during promotion (#341)
Obed0101 Sep 23, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
66 changes: 66 additions & 0 deletions .codex/skills/mendcode-release-flow/SKILL.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,66 @@
---
name: mendcode-release-flow
description: Use for MendCode project changes, release prep, PR promotion, version bump decisions, changelog updates, installer validation, and dev-to-main synchronization. Trigger whenever work may ship to users, touches package metadata/versioning, installer/update/health/changelog behavior, or the user mentions bumping a version, release, changelog, PR to dev/main, or letting the user test before shipping.
---

# MendCode Release Flow

Follow this workflow for MendCode changes that may ship.

## Non-negotiables

- For maintainer/agent work inside the main MendCode repository, use the local `dev` branch by default. Do not create a separate branch unless the user explicitly asks for one, the current worktree has unrelated changes in the same files, or a GitHub contribution flow requires it.
- Preserve unrelated local changes. If the active checkout is dirty, inspect the touched files first. Work in-place on `dev` only when the requested files are clean or the existing edits are clearly part of the same user-approved task.
- If unrelated dirty files conflict with the task, stop and explain the blocker before creating a worktree or branch.
- Before editing release/version/package files, ask or verify whether another agent already bumped the version locally or remotely.
- Do not publish a release, merge to `main`, or overwrite a user worktree without explicit user intent.
- Never leave open public PRs/issues as noise. Close, merge, or explain exactly why they must remain open.
- Never hide security/release failures. If a supply-chain, secret, CodeQL, release, or installer check fails, keep the issue open until fixed or document the exact reason it is accepted.

## Branch Policy

- Internal MendCode maintainers and local agents work on `dev` by default.
- External contributors should use a fork or feature branch and open a PR targeting `dev`, not `main`.
- `main` is the public release branch. Only promote `dev` to `main` after CI passes, the user-visible change has been tested, version/changelog state is correct, and the user intends to ship.
- For internal promotion, prefer a direct `dev` -> `main` PR. Do not create `codex/*` promotion branches unless GitHub cannot represent the intended merge directly or a conflict must be resolved outside the user's local checkout.
- If an emergency promotion branch/worktree is unavoidable, delete the remote branch, local branch, and temporary worktree immediately after merge or close.
- Local release or promotion workspaces under `$TMPDIR/mendcode` must be run through `src/mendcode/script/release` or its sourced cleanup helper so the current workspace's `src/mendcode/node_modules` is removed on success or failure. Do not run broad age-based temp cleaners or delete unowned/active temp workspaces.
- Do not merge random branches directly into `main`. Bring useful branches back through PRs to `dev`, then delete stale branches after merge.
- Before starting, check whether another PR/agent already contains the same work. Prefer continuing the existing local `dev` work over creating a duplicate branch.

## Standard Flow

1. Inspect `git status`, `git worktree list`, open PRs/issues, latest GitHub release, `origin/dev`, and `origin/main`.
2. If a version bump may be needed, determine whether the bump already exists:
- Check `CHANGELOG.md`.
- Check `src/mendcode/packages/opencode/package.json`.
- Check extension/package metadata such as `src/mendcode/packages/extensions/zed/extension.toml`.
- Check recent merged PRs and tags.
3. Ask the user before choosing a new version unless the version is already clearly bumped by another agent.
4. Implement the change on local `dev` unless the Branch Policy says a separate branch/worktree is required.
5. Run focused tests/scripts for the touched area. Use existing repo scripts and generated-client/build checks when relevant.
6. Stop and let the user test locally when the change is user-visible. Do not bump/changelog/merge until the user says it works, unless they explicitly ask for fully autonomous shipping.
7. After the user confirms it works:
- Bump version if needed.
- Add or update `CHANGELOG.md`.
- Open a PR to `dev`, wait for CI, and merge.
- Promote `dev` to `main` with a direct PR whenever possible, resolving conflicts deliberately.
- Sync `main` back to `dev` if needed so both branches have the same tree.
8. If releasing:
- Use the Release workflow from `main`.
- Verify SHA256SUMS.
- Publish with real release notes/changelog, not only a SHA.
- Smoke-test the public installer in a temporary `HOME`.

## Required Checks

- For code: run the narrow test file or command covering the changed path.
- For release: verify `mendcode --version` prints the release version.
- For installer: test `curl -fsSL https://raw.githubusercontent.com/MendCode/MendCode/main/src/mendcode/install | bash -s -- --no-modify-path` in a temporary `HOME`.
- For supply chain: verify secret scan, dependency review/vulnerability checks, CodeQL/Semgrep, and release artifact checksums before publishing.
- For branch hygiene: verify open PRs/issues, latest release, branches, and `git diff origin/main..origin/dev`.
- For local safety: before committing, review `git diff --name-only` and stage only files intentionally changed for this task.

## Reporting

Report only facts that were verified: PR numbers, release URL, version, test commands, and installer result. If the user asked not to report process, keep the final short.
46 changes: 46 additions & 0 deletions .codex/skills/mendcode-session-guardrails/SKILL.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,46 @@
---
name: mendcode-session-guardrails
description: Use at the start of every task in the MendCode repository. Enforces local-only work, risk-based validation, minimal changes, and protection of disk, memory, CPU, and TUI rendering. Load this skill before inspecting or editing code, docs, config, tests, or runtime files.
---

# MendCode Session Guardrails

Apply these rules to every task in this repository unless the user explicitly overrides a specific rule.

## GitHub and external writes

- Work locally by default. Never run `git push`, create, update, merge, or close GitHub PRs/issues, publish releases/packages, upload artifacts, or post GitHub comments.
- A direct user request authorizes only that specific external write. Otherwise stop before it and ask.
- Read-only commands such as `git status`, `git diff`, branch inspection, or remote inspection are allowed when relevant.
- Do not create a commit unless the user explicitly asks for one.

## Scope and non-regression

- Inspect the worktree before editing. Preserve unrelated changes; never reset, clean, revert, or overwrite them.
- Read the relevant callers, tests, configuration, and nearby patterns before changing behavior.
- Make the smallest patch that solves the requested problem. Avoid broad refactors, dependency changes, generated output, migrations, or public API changes unless they are required.
- Do not claim that MendCode is safe merely because a change is small: check imports, data flow, error paths, and affected callers.
- For TUI/runtime work, preserve state ownership and event flow. Do not introduce render loops, duplicate subscriptions, unstable keys, unbounded concurrency, or unnecessary rerenders.

## Tests and validation

- For executable behavior, run the narrowest relevant test, typecheck, lint, or runtime smoke check after editing.
- For a genuinely tiny non-executable change (for example, a skill, documentation, or formatting-only edit), skip the full test suite and validate the file format, frontmatter, and focused diff instead.
- Treat configuration changes as executable when they can alter runtime behavior; validate them accordingly.
- Do not run a full build or full test suite by habit. Expand validation only when the risk or repository workflow requires it, or the user asks.
- Report every check that actually ran and clearly state checks that were intentionally skipped.

## Disk, memory, CPU, and rendering budget

- Prefer targeted reads/searches and bounded commands over full-repository scans, large logs, or repeated whole-file rewrites.
- Do not create unnecessary generated files, caches, dumps, screenshots, or temporary artifacts; clean up anything required for validation.
- Avoid unbounded loops, polling, watchers, retries, uncontrolled parallelism, and duplicate work.
- Keep memory and CPU usage bounded with pagination, lazy work, bounded concurrency, and existing caches/abstractions where appropriate.
- For UI/TUI changes, avoid rendering entire histories or large collections when only a visible/changed slice is needed.
- If a change could affect performance or resource usage, inspect and validate that path specifically instead of assuming it is harmless.

## Stop conditions and reporting

- Ask before destructive actions, production/billing changes, security-impacting changes, or material scope expansion.
- Before finishing, inspect only the relevant diff and confirm no accidental artifacts or unrelated files were changed.
- Report concisely: changed files, real validation results, skipped checks, blockers, and non-goals.
66 changes: 66 additions & 0 deletions .github/ISSUE_TEMPLATE/bug_report.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,66 @@
name: Bug report
description: Report a reproducible MendCode bug
title: "[Bug]: "
labels:
- bug
body:
- type: textarea
id: summary
attributes:
label: Summary
description: What happened?
validations:
required: true
- type: textarea
id: reproduce
attributes:
label: Steps to reproduce
description: Give the smallest reproduction you can.
placeholder: |
1. Run ...
2. Open ...
3. See ...
validations:
required: true
- type: textarea
id: expected
attributes:
label: Expected behavior
validations:
required: true
- type: textarea
id: actual
attributes:
label: Actual behavior
validations:
required: true
- type: input
id: version
attributes:
label: MendCode version
placeholder: mend --version
- type: input
id: os
attributes:
label: OS
placeholder: macOS, Linux, Windows, WSL
- type: input
id: terminal
attributes:
label: Terminal
placeholder: Ghostty, iTerm2, Terminal.app, Windows Terminal
- type: textarea
id: config
attributes:
label: Relevant config
description: Redact secrets. Do not paste API keys or private prompts.
render: text
- type: checkboxes
id: checks
attributes:
label: Checks
options:
- label: I searched existing issues and discussions.
required: true
- label: I removed secrets and private config from this report.
required: true
8 changes: 8 additions & 0 deletions .github/ISSUE_TEMPLATE/config.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,8 @@
blank_issues_enabled: false
contact_links:
- name: Discussions
url: https://github.com/MendCode/MendCode/discussions
about: Ask setup, package, mflow, TUI customization, and plugin/widget questions.
- name: Private vulnerability report
url: https://github.com/MendCode/MendCode/security/advisories/new
about: Report security issues privately. Do not open public issues for vulnerabilities.
45 changes: 45 additions & 0 deletions .github/ISSUE_TEMPLATE/feature_request.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,45 @@
name: Feature request
description: Suggest a MendCode feature or improvement
title: "[Feature]: "
labels:
- enhancement
body:
- type: textarea
id: problem
attributes:
label: Problem
description: What user problem should this solve?
validations:
required: true
- type: textarea
id: solution
attributes:
label: Desired behavior
description: What should MendCode do?
validations:
required: true
- type: textarea
id: alternatives
attributes:
label: Alternatives considered
- type: dropdown
id: area
attributes:
label: Area
options:
- CLI/setup
- TUI customization
- Plugins/widgets
- Packages/team sharing
- mflow
- TSM/worktrees
- Models/providers
- Docs
- Other
- type: checkboxes
id: checks
attributes:
label: Checks
options:
- label: I searched existing issues and discussions.
required: true
21 changes: 21 additions & 0 deletions .github/ISSUE_TEMPLATE/question.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,21 @@
name: Question
description: Ask a usage question
title: "[Question]: "
labels:
- question
body:
- type: markdown
attributes:
value: For general usage help, GitHub Discussions may be a better place than Issues.
- type: textarea
id: question
attributes:
label: Question
description: What are you trying to do?
validations:
required: true
- type: textarea
id: context
attributes:
label: Context
description: Include commands, docs links, or config snippets. Redact secrets.
4 changes: 4 additions & 0 deletions .github/codeql/codeql-config.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,4 @@
name: MendCode CodeQL

paths-ignore:
- src/mendcode/packages/opencode/script/run-workspace-server
10 changes: 10 additions & 0 deletions .github/dependabot.yml
Original file line number Diff line number Diff line change
Expand Up @@ -9,6 +9,8 @@ updates:
time: "09:00"
timezone: "America/New_York"
open-pull-requests-limit: 0
cooldown:
default-days: 7
groups:
bun-dependencies:
patterns:
Expand All @@ -27,6 +29,8 @@ updates:
time: "09:05"
timezone: "America/New_York"
open-pull-requests-limit: 0
cooldown:
default-days: 7
groups:
bun-github-action:
patterns:
Expand All @@ -45,6 +49,8 @@ updates:
time: "09:10"
timezone: "America/New_York"
open-pull-requests-limit: 0
cooldown:
default-days: 7
groups:
bun-console-resource:
patterns:
Expand All @@ -63,6 +69,8 @@ updates:
time: "09:15"
timezone: "America/New_York"
open-pull-requests-limit: 0
cooldown:
default-days: 7
groups:
bun-vscode-sdk:
patterns:
Expand All @@ -81,6 +89,8 @@ updates:
time: "09:30"
timezone: "America/New_York"
open-pull-requests-limit: 0
cooldown:
default-days: 7
groups:
github-actions:
patterns:
Expand Down
3 changes: 3 additions & 0 deletions .github/osv-release.toml
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
[[IgnoredVulns]]
id = "GHSA-j965-2qgj-vjmq"
reason = "aws-sdk v2 has no fixed version reported by OSV. It is retained only as a transitive package while release artifacts are built with scripts disabled, SBOM, and provenance attestations."
32 changes: 32 additions & 0 deletions .github/pull_request_template.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,32 @@
## Summary

Describe what changed and why.

## Type

- [ ] Bug fix
- [ ] Feature
- [ ] Documentation
- [ ] Refactor
- [ ] Release/package maintenance
- [ ] Security hardening

## Verification

List the commands or manual checks you ran.

```bash

```

## Screenshots or Recordings

Required for TUI/UI-facing changes when practical.

## Checklist

- [ ] I kept this PR focused.
- [ ] I tested the affected behavior.
- [ ] I updated docs when behavior changed.
- [ ] I did not include secrets, private config, or unrelated local files.
- [ ] I checked whether release assets, installer behavior, or package docs need updates.
25 changes: 25 additions & 0 deletions .github/release.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,25 @@
changelog:
exclude:
labels:
- ignore-for-release
authors:
- dependabot
categories:
- title: Features
labels:
- enhancement
- feature
- title: Fixes
labels:
- bug
- fix
- title: Documentation
labels:
- documentation
- docs
- title: Security
labels:
- security
- title: Other
labels:
- "*"
Loading
Loading