From 84596e39dcfd2be9dfee94b787a66c3e1fa302f8 Mon Sep 17 00:00:00 2001 From: Vyncint Ng Date: Tue, 22 Sep 2026 14:50:11 +0700 Subject: [PATCH] release: 2.3.0 The production-readiness release. The lockstep set moves onto reconverge 0.7.0, which is the half that changes what this product can promise: before it, a cluster- or grid-wide barrier under a guard that is only block-uniform produced no findings at all, so the gate this tool is built on could not see that class. Tests now sit under the part that decides what the number is. The exit-code contract the README states had nothing behind it -- exit 1, "the fastest candidates were refused", is the product's argument in one integer and the one a refactor turns into 0 unnoticed. launchbound-runner had no tests at all, and silently read `--budget-secs 30m` as no budget on the machine that costs money. The release itself had two holes: release.yml never created a GitHub release, so 2.2.1 sat on crates.io for twelve days while the repository showed 2.2.0 as Latest, and the semver baseline was a release behind. Both are gated now rather than remembered. And the supply chain: every action pinned to a SHA, every job capped, credentials not persisted, dependabot watching both ecosystems, and a zizmor job that audits online -- which found a stale pin comment on its first run. Signed-off-by: Vyncint Ng --- CHANGELOG.md | 8 ++++++++ Cargo.lock | 22 +++++++++++----------- Cargo.toml | 18 +++++++++--------- 3 files changed, 28 insertions(+), 20 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index 507c039..c9169ab 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -9,6 +9,14 @@ change measured timings are marked `bench:`. ## [Unreleased] +## [2.3.0] - 2026-09-22 + +The production-readiness release. It moves the lockstep set onto a +reconverge that can see a class the old one could not, puts tests under the +part of this tool that decides what the number is, and closes the supply +chain and release gaps that let a published version go unannounced for +twelve days. + ### Changed - **The lockstep pin set moves: cuda-oxide `b0f961df`, reconverge `0.7.0`, diff --git a/Cargo.lock b/Cargo.lock index ff17284..9003f1a 100644 --- a/Cargo.lock +++ b/Cargo.lock @@ -1121,7 +1121,7 @@ checksum = "bf36173d4167ed999940f804952e6b08197cae5ad5d572eb4db150ce8ad5d58f" [[package]] name = "launchbound-bench" -version = "2.2.1" +version = "2.3.0" dependencies = [ "anyhow", "launchbound-space", @@ -1135,7 +1135,7 @@ dependencies = [ [[package]] name = "launchbound-build" -version = "2.2.1" +version = "2.3.0" dependencies = [ "launchbound-space", "serde", @@ -1146,7 +1146,7 @@ dependencies = [ [[package]] name = "launchbound-cli" -version = "2.2.1" +version = "2.3.0" dependencies = [ "anyhow", "clap", @@ -1164,7 +1164,7 @@ dependencies = [ [[package]] name = "launchbound-metal" -version = "2.2.1" +version = "2.3.0" dependencies = [ "launchbound-bench", "launchbound-space", @@ -1175,7 +1175,7 @@ dependencies = [ [[package]] name = "launchbound-model" -version = "2.2.1" +version = "2.3.0" dependencies = [ "launchbound-space", "serde", @@ -1185,7 +1185,7 @@ dependencies = [ [[package]] name = "launchbound-prune" -version = "2.2.1" +version = "2.3.0" dependencies = [ "launchbound-build", "launchbound-space", @@ -1198,7 +1198,7 @@ dependencies = [ [[package]] name = "launchbound-report" -version = "2.2.1" +version = "2.3.0" dependencies = [ "insta", "jsonschema", @@ -1210,7 +1210,7 @@ dependencies = [ [[package]] name = "launchbound-runner" -version = "2.2.1" +version = "2.3.0" dependencies = [ "launchbound-bench", "launchbound-search", @@ -1218,7 +1218,7 @@ dependencies = [ [[package]] name = "launchbound-search" -version = "2.2.1" +version = "2.3.0" dependencies = [ "launchbound-bench", "proptest", @@ -1226,7 +1226,7 @@ dependencies = [ [[package]] name = "launchbound-space" -version = "2.2.1" +version = "2.3.0" dependencies = [ "proptest", "serde", @@ -1237,7 +1237,7 @@ dependencies = [ [[package]] name = "launchbound-tui" -version = "2.2.1" +version = "2.3.0" dependencies = [ "anyhow", "crossterm", diff --git a/Cargo.toml b/Cargo.toml index ee3ffdf..d7c055d 100644 --- a/Cargo.toml +++ b/Cargo.toml @@ -20,7 +20,7 @@ members = [ exclude = ["corpus"] [workspace.package] -version = "2.2.1" +version = "2.3.0" edition = "2024" # MSRV for crates that do not require the pinned nightly (CONTRIBUTING.md); # set by ratatui 0.30. The analysis and compile paths require @@ -38,14 +38,14 @@ categories = ["development-tools", "development-tools::profiling"] # published crate is compatible with a release it was never built against -- # harmless for a path build, wrong as a record. They sat at 2.0.0 through the # whole 2.1.0 line; `just versions` (and a test) now refuse the drift. -launchbound-space = { path = "crates/launchbound-space", version = "2.2.1" } -launchbound-prune = { path = "crates/launchbound-prune", version = "2.2.1" } -launchbound-build = { path = "crates/launchbound-build", version = "2.2.1" } -launchbound-bench = { path = "crates/launchbound-bench", version = "2.2.1" } -launchbound-report = { path = "crates/launchbound-report", version = "2.2.1" } -launchbound-search = { path = "crates/launchbound-search", version = "2.2.1" } -launchbound-model = { path = "crates/launchbound-model", version = "2.2.1" } -launchbound-metal = { path = "crates/launchbound-metal", version = "2.2.1" } +launchbound-space = { path = "crates/launchbound-space", version = "2.3.0" } +launchbound-prune = { path = "crates/launchbound-prune", version = "2.3.0" } +launchbound-build = { path = "crates/launchbound-build", version = "2.3.0" } +launchbound-bench = { path = "crates/launchbound-bench", version = "2.3.0" } +launchbound-report = { path = "crates/launchbound-report", version = "2.3.0" } +launchbound-search = { path = "crates/launchbound-search", version = "2.3.0" } +launchbound-model = { path = "crates/launchbound-model", version = "2.3.0" } +launchbound-metal = { path = "crates/launchbound-metal", version = "2.3.0" } anyhow = "1" clap = { version = "4", features = ["derive"] } serde = { version = "1", features = ["derive"] }