Skip to content

chore(release): v0.2.0a2 — fourth PyPI alpha#198

Merged
MartinCastroAlvarez merged 1 commit into
mainfrom
chore/release-0.2.0a2
May 26, 2026
Merged

chore(release): v0.2.0a2 — fourth PyPI alpha#198
MartinCastroAlvarez merged 1 commit into
mainfrom
chore/release-0.2.0a2

Conversation

@MartinCastroAlvarez
Copy link
Copy Markdown
Owner

Version bump 0.2.0a1 → 0.2.0a2. Already published to PyPI + tagged v0.2.0a2 under the Security deploy-gate (repo-owner standing 'deploy regularly if secure' directive); this PR lands the bump on main so it reflects the published version. 350 tests pass, dep-audit clean, security-motivated (ships the #191 CodeQL fixes). Tier 6.

Security-motivated alpha: ships to consumers the fixes merged since
0.2.0a1, notably the CodeQL security clears (#191: ReDoS +
incomplete-sanitization in format.ts, open-redirect in the login
redirect, stack-trace-exposure in the inline write path), the secure
login backend (#168), the inline formset write path (#183), the
get_app_list registry grouping, and the save-flow / delete-preview /
history backends.

350 tests pass. Tier 6 — version bump; publish handled per the
Security deploy-gate under the repo owner's standing "deploy to PyPI
regularly if secure" directive.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
@MartinCastroAlvarez MartinCastroAlvarez merged commit f05edcb into main May 26, 2026
2 checks passed
@MartinCastroAlvarez MartinCastroAlvarez deleted the chore/release-0.2.0a2 branch May 26, 2026 21:32
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants