Skip to content

Release 0.14.0: an SBOM for hardware you did not build - #38

Merged
Zenofex merged 1 commit into
mainfrom
release-0.14.0
Oct 7, 2026
Merged

Zenofex merged 1 commit into
mainfrom
release-0.14.0

Conversation

@Zenofex

@Zenofex Zenofex commented Oct 7, 2026

Copy link
Copy Markdown
Contributor

bootintel submit (#37) is merged but sits under [Unreleased], and the workspace is still 0.13.0 — which is also the latest published release. So nobody can install the command: a brew install or a release download today gets 0.13.0 without it. A merged feature no user can run is not shipped.

The repo's own policy makes this MINOR: "new detector; new subcommand; new flag; new output format".

What this changes

The same four files the 0.13.0 release touched:

  • workspace version 0.13.0 → 0.14.0
  • the bootintel-detectors pin in crates/cli/Cargo.toml
  • Cargo.lock
  • CHANGELOG.md — [Unreleased] closed out into a dated heading

This does not publish anything

cli-release.yml is workflow_dispatch only, with an explicit version input and a dry_run option. Merging this prepares the release; cutting it stays a deliberate manual dispatch afterwards.

Verified the built binary reports bootintel 0.14.0 and still carries submit.

🤖 Generated with Claude Code

Zenofex added a commit that referenced this pull request Oct 7, 2026
#37 shipped a race, and it blocked #38.

Every test in `submit_cli.rs` wrote the same `tmpdir()/boot.log`. Rust
runs tests in parallel threads, and `fs::write` truncates before it
writes, so one test's spawned process could read the file in the instant
another had emptied it. The binary then did exactly what it should:

```
Error: /tmp/submit_cli/boot.log is empty; nothing to submit
```

It passed 7/7 locally and passed on main's own CI run, then failed `test
(default-features)` on the next branch. That is the shape of flake that
survives: red often enough to erode trust in the suite, green often
enough that nobody can reproduce it.

Each test now writes its own `<tag>.log`.

Verified with 15 consecutive runs of the file — 0 failures — and seven
distinct files on disk.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
`bootintel submit` (#37) is merged but sits under [Unreleased], and the
workspace is still 0.13.0, which is also the latest published release. So
nobody can install the command: a `brew install` or a release download today
gets 0.13.0 without it. A merged feature no user can run is not shipped.

The repo's own policy makes this MINOR: "new detector; new subcommand; new
flag; new output format".

Same four files the 0.13.0 release touched: the workspace version, the
detectors pin in crates/cli, Cargo.lock, and the CHANGELOG heading. Nothing
here publishes anything by itself -- cli-release.yml is workflow_dispatch only,
with an explicit version input and a dry_run option -- so the release remains a
deliberate manual act after this lands.

Verified the built binary reports 0.14.0 and still carries `submit`.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@Zenofex
Zenofex merged commit 67e85c5 into main Oct 7, 2026
11 checks passed
@Zenofex
Zenofex deleted the release-0.14.0 branch October 7, 2026 10:33
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant