From ef724ecd09ec918bb14fed2b922d64d4927d89b0 Mon Sep 17 00:00:00 2001 From: Shinrai Date: Sat, 3 Oct 2026 11:34:55 -0700 Subject: [PATCH] docs: v1.2.1 release notes and What's New --- README.md | 10 ++++------ docs/changelog/v1/v1.2.1.md | 30 ++++++++++++++++++++++++++++++ 2 files changed, 34 insertions(+), 6 deletions(-) create mode 100644 docs/changelog/v1/v1.2.1.md diff --git a/README.md b/README.md index e13ceed..0001928 100644 --- a/README.md +++ b/README.md @@ -16,19 +16,17 @@ That gating follows slothlet's own rule about **who is calling**: a call made by ## ✨ What's New -### Latest: v1.2.0 (October 2026) +### Latest: v1.2.1 (October 2026) -- **Channel principal: serving to a peer you can't trust ([#53](https://github.com/CLDMV/slothlet-vine/pull/53))** — `serve(api, channel, { principal })` binds a caller identity to the channel, taken from the transport's own authentication and never from a frame. Every call is judged by slothlet's rules as that identity, with the frame's own arguments, before the leaf runs; a refusal answers `VINE_DENIED`. Every subscription resolves as that identity, and the subscriber path a peer claims can only narrow its level. `grow()` takes the same option for its event half. Opt-in: without it nothing changes. -- **`serve({ around })` ([#54](https://github.com/CLDMV/slothlet-vine/pull/54))** — a per-call wrapper for the host's own scope (a transaction under the bound actor, a deadline, an audit record), run after every vine check. Its `invoke()` is fixed to the authorized call and can be retried. -- **Requires `@cldmv/slothlet` `>=3.22.0` ([#59](https://github.com/CLDMV/slothlet-vine/pull/59))** — the release that adds `permissions.global.checkCall`, the call gate the principal uses. -- [View full v1.2.0 Changelog](https://github.com/CLDMV/slothlet-vine/blob/master/docs/changelog/v1/v1.2.0.md) +- **Dev-tooling dependency refresh ([#68](https://github.com/CLDMV/slothlet-vine/pull/68), [#70](https://github.com/CLDMV/slothlet-vine/pull/70))** — Updates to the lockfile only: `vitest` 5.0.3, `@cldmv/vitest-runner` 1.5.1, the jsonv lint/format packages, and the `ws` used by the WebSocket transport tests. No runtime source changed, and the peer ranges are the same as in v1.2.0 (`@cldmv/slothlet >=3.22.0`, optional `ws >=8.0.0`). It's a drop-in replacement for v1.2.0. +- [View full v1.2.1 Changelog](https://github.com/CLDMV/slothlet-vine/blob/master/docs/changelog/v1/v1.2.1.md) ### Recent Releases +- **v1.2.0** (October 2026) — channel principal: `serve({ principal })` judges every call and subscription as a transport-authenticated identity, plus a per-call `serve({ around })` wrapper; requires `@cldmv/slothlet >=3.22.0` ([Changelog](https://github.com/CLDMV/slothlet-vine/blob/master/docs/changelog/v1/v1.2.0.md)) - **v1.1.3** (September 2026) — transports buffer frames that arrive before `grow()`/`serve()` registers a handler, so attaching after an `await` no longer loses the surface frame ([Changelog](https://github.com/CLDMV/slothlet-vine/blob/master/docs/changelog/v1/v1.1.3.md)) - **v1.1.2** (September 2026) — `@cldmv/slothlet` peer floor raised to `>=3.20.0`; no runtime changes ([Changelog](https://github.com/CLDMV/slothlet-vine/blob/master/docs/changelog/v1/v1.1.2.md)) - **v1.1.1** (September 2026) — CI-only: release-flow caller workflows synced to the current v4 templates ([Changelog](https://github.com/CLDMV/slothlet-vine/blob/master/docs/changelog/v1/v1.1.1.md)) -- **v1.1.0** (September 2026) — cross-vine event forwarding in both directions, gated by the emitter's own permissions ([Changelog](https://github.com/CLDMV/slothlet-vine/blob/master/docs/changelog/v1/v1.1.0.md)) 📚 **For complete version history and detailed release notes, see the [docs/changelog/](https://github.com/CLDMV/slothlet-vine/tree/master/docs/changelog/) folder.** diff --git a/docs/changelog/v1/v1.2.1.md b/docs/changelog/v1/v1.2.1.md new file mode 100644 index 0000000..15baf6c --- /dev/null +++ b/docs/changelog/v1/v1.2.1.md @@ -0,0 +1,30 @@ +# Slothlet Vine v1.2.1 Changelog + +**Release Date**: October 2026 +**Release Type**: Patch +**Branch**: `next` → `master` + +--- + +## Overview + +A dev-tooling dependency patch. No runtime source changed: the forwarding core, wire protocol, channel principal, `around`, event forwarding and every transport are exactly as in v1.2.0. Both peer ranges are unchanged too: `@cldmv/slothlet` stays at `>=3.22.0` and the optional `ws` peer at `>=8.0.0`. + +--- + +## 🔧 Dependencies + +All of these are dev dependencies, updated in the lockfile only. + +- **Minor group** ([#68](https://github.com/CLDMV/slothlet-vine/pull/68)): `@cldmv/jsonv` `1.0.9` → `1.1.1`, `@cldmv/prettier-plugin-jsonv` `1.0.6` → `1.1.0`, `@cldmv/vitest-runner` `1.2.0` → `1.5.1`, `ws` `8.21.3` → `8.22.0`. The `ws` bump only affects the WebSocket transport tests. Consumers bring their own `ws`. +- **Patch group** ([#70](https://github.com/CLDMV/slothlet-vine/pull/70)): `@cldmv/eslint-plugin-jsonv` `1.0.10` → `1.0.13`, `vitest` and `@vitest/coverage-v8` `5.0.2` → `5.0.3`. + +## 📚 Documentation + +- **NEW:** [docs/changelog/v1/v1.2.1.md](./v1.2.1.md): this changelog. + +--- + +## Upgrade notes + +- No breaking changes, and no runtime code changed. It's a drop-in replacement for v1.2.0.