Skip to content

Release 0.202.1 - #13

Merged
involvex merged 3 commits into
masterfrom
release/v0.202.1
Sep 27, 2026
Merged

involvex merged 3 commits into
masterfrom
release/v0.202.1

Conversation

@involvex

@involvex involvex commented Sep 27, 2026 •

Copy link
Copy Markdown
Owner

Patch release: security hardening batch plus dependency hygiene.

Includes (already on master): zip-slip guard hardening (TermuxInstaller), storage-get hardening (StorageGetAPI), guava 33.7.1-android, build-classpath constraints/forces.

This PR:

  • Forces kotlin-gradle-plugin to stable 2.4.20 (shipped 2026-09-07; unblocks Dependabot 19, previously beta-only). Buildscript resolved 2.2.10 transitively via AGP; verified 2.2.10 -> 2.4.20 with family aligned via BOM.
  • Documents build-classpath pins and Dependabot dismissal refs (2/11/19) in AGENTS.md.
  • Bumps versionCode 202 -> 203, versionName 0.202.0 -> 0.202.1 (app + 3 library publications + README).

Verification: test green (fresh :app:testDebugUnitTest run), assembleDebug green (versionName prints 0.202.1), lint shows only the 5 known pre-existing errors. commons-io stays at 2.5 (minSdk 21; revisit at minSdk 26).

Summary by Sourcery

Release version 0.202.1 with dependency hardening and synchronized application and library version updates.

Enhancements:

  • Harden the build against vulnerable transitive dependencies by pinning the stable Kotlin Gradle plugin and documenting build-classpath and dependency decisions.

Build:

  • Align the application and published library versions for the 0.202.1 patch release.

Documentation:

  • Update the developer dependency guidance and README to reflect version 0.202.1 and documented dependency dismissals.

@changeset-bot

changeset-bot Bot commented Sep 27, 2026

Copy link
Copy Markdown

⚠️ No Changeset found

Latest commit: 278000d

Merging this PR will not cause a version bump for any packages. If these changes should not result in a new version, you're good to go. If these changes should result in a version bump, you need to add a changeset.

Click here to learn what changesets are, and how to add one.

Click here if you're a maintainer who wants to add a changeset to this PR

@sourcery-ai

sourcery-ai Bot commented Sep 27, 2026 •

Copy link
Copy Markdown

Reviewer's Guide

This patch release hardens build dependency resolution by pinning the stable Kotlin Gradle plugin alongside existing classpath constraints, documents those constraints and risk decisions, and synchronizes the app, published libraries, and project documentation to version 0.202.1.

File-Level Changes

Change Details Files
Promotes the Kotlin Gradle plugin to stable 2.4.20 and applies it consistently across buildscript and subproject configurations.
  • Adds a buildscript classpath constraint for Kotlin Gradle plugin 2.4.20.
  • Forces 2.4.20 on all subproject configurations to override the transitive 2.2.10 resolution.
  • Documents build-classpath pins and related Dependabot decisions.
build.gradle
AGENTS.md
Cuts the 0.202.1 patch release and synchronizes application, library, and documentation version metadata.
  • Increments the app version code and updates the version name.
  • Updates all three published library versions to 0.202.1.
  • Updates the documented and README latest-release versions.
app/build.gradle
terminal-emulator/build.gradle
terminal-view/build.gradle
termux-shared/build.gradle
AGENTS.md
README.md

Tips and commands

Interacting with Sourcery

  • Trigger a new review: Comment @sourcery-ai review on the pull request.
  • Continue discussions: Reply directly to Sourcery's review comments.
  • Generate a GitHub issue from a review comment: Ask Sourcery to create an
    issue from a review comment by replying to it. You can also reply to a
    review comment with @sourcery-ai issue to create an issue from it.
  • Generate a pull request title: Write @sourcery-ai anywhere in the pull
    request title to generate a title at any time. You can also comment
    @sourcery-ai title on the pull request to (re-)generate the title at any time.
  • Generate a pull request summary: Write @sourcery-ai summary anywhere in
    the pull request body to generate a PR summary at any time exactly where you
    want it. You can also comment @sourcery-ai summary on the pull request to
    (re-)generate the summary at any time.
  • Generate reviewer's guide: Comment @sourcery-ai guide on the pull
    request to (re-)generate the reviewer's guide at any time.
  • Resolve all Sourcery comments: Comment @sourcery-ai resolve on the
    pull request to resolve all Sourcery comments. Useful if you've already
    addressed all the comments and don't want to see them anymore.
  • Dismiss all Sourcery reviews: Comment @sourcery-ai dismiss on the pull
    request to dismiss all existing Sourcery reviews. Especially useful if you
    want to start fresh with a new review - don't forget to comment
    @sourcery-ai review to trigger a new review!

Customizing Your Experience

Access your dashboard to:

  • Enable or disable review features such as the Sourcery-generated pull request
    summary, the reviewer's guide, and others.
  • Change the review language.
  • Add, remove or edit custom review instructions.
  • Adjust other review settings.

Getting Help

@sourcery-ai sourcery-ai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Hey - I've reviewed your changes and they look great!


Sourcery is free for open source - if you like our reviews please consider sharing them ✨

Stable 2.4.20 shipped 2026-09-07, unblocking Dependabot 19 (fix was
beta-only). The buildscript classpath resolves 2.2.10 transitively via AGP;
constraints plus subprojects force align the whole plugin family to 2.4.20
via its BOM. Verified with test, assembleDebug and lint (only the 5 known
pre-existing errors).
@kilo-code-bot

kilo-code-bot Bot commented Sep 27, 2026 •

Copy link
Copy Markdown

Code Review Summary

Status: No Issues Found | Recommendation: Merge

Files Reviewed (7 files)
  • build.gradle - kotlin-gradle-plugin 2.4.20 forced in buildscript constraints + subprojects resolutionStrategy.force
  • AGENTS.md - version metadata + build-classpath pin documentation
  • app/build.gradle - versionCode 203, versionName 0.202.1
  • terminal-emulator/build.gradle - publication version 0.202.1
  • terminal-view/build.gradle - publication version 0.202.1
  • termux-shared/build.gradle - publication version 0.202.1
  • README.md - latest version 0.202.1

Reviewed by free · Input: 0 · Output: 0 · Cached: 0

@involvex
involvex merged commit 8a7d356 into master Sep 27, 2026
10 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant