Skip to content

release: v0.3.0 — insecure-deserialization check, Apache-2.0 - #23

Merged
bkd-dotcom merged 1 commit into
mainfrom
release-v0.3.0
Sep 1, 2026
Merged

release: v0.3.0 — insecure-deserialization check, Apache-2.0#23
bkd-dotcom merged 1 commit into
mainfrom
release-v0.3.0

Conversation

@bkd-dotcom

Copy link
Copy Markdown
Member

Cuts signetry-reviewer v0.3.0: the deser.introduced check and the Apache-2.0
relicense.

Unreleased[0.3.0] — 2026-09-01, pyproject.toml0.3.0, and the two pins
that name the current release move with it — the README install command and the
composite action's default (action.yml, the else branch used when a caller passes
no version input). Local ruff + pytest green.

v1 has stopped moving

release.yml already states the practice: "the moving major tag v1 is repointed on
each release and must NOT trigger this workflow"
. It has not been repointed since
v0.1.2v1 currently points at c5ab468, ten commits and two minor releases
back
, which is before the Signetry rename (5f2e4f0, cd3bea0).

So every consumer pinning Signetry/reviewer@v1 has been resolving pre-rename code —
including this project's own landing page, which advertises @v1 as the way the
reviewer is consumed. v1 gets repointed to v0.3.0 once this merges and the tag is cut.

Worth noting for later: the site's version check validates a @vN pin only for
existence, deliberately not for currency, so it passed green throughout. That rule is
right for a genuinely moving tag, but it cannot detect one that has stopped moving.

Rolls Unreleased into 0.3.0, bumps pyproject to match, and moves the two install
pins that name the current release (the README and the composite action's default).

The moving `v1` tag needs repointing after this tag lands. release.yml already
documents that as the practice ("the moving major tag `v1` is repointed on each
release"), but it had not happened since v0.1.2 — `v1` still points at c5ab468,
ten commits and two minor releases back, which predates the Signetry rename. Anyone
pinning Signetry/reviewer@v1 has been getting pre-rename code, including the site's
own front page.
@bkd-dotcom
bkd-dotcom merged commit 3a1b0d4 into main Sep 1, 2026
4 checks passed
@bkd-dotcom
bkd-dotcom deleted the release-v0.3.0 branch September 1, 2026 14:43
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant