diff --git a/.gds/bundle.lock.yaml b/.gds/bundle.lock.yaml index 342eced..3336967 100644 --- a/.gds/bundle.lock.yaml +++ b/.gds/bundle.lock.yaml @@ -2,17 +2,17 @@ schema_version: 1 bundle: - version: "0.9.6-dev" + version: "0.9.7-dev" release_sequence: 0 channel: "development" - source_tree_digest: "sha256:b9d572eb73bb14ae8ede20dfc1e9317046dcb544270eff95153746f93f094820" - digest: "sha256:a45453995b649d082b39753c1d7eff869d2dcad5180532cb14f85435fae2a7fa" + source_tree_digest: "sha256:4853ed6bf539e3b59368ea375492691007a286401443ecb2e5f8cbf411a0bef5" + digest: "sha256:2e758ba5ed19ee745625e5a96b322ebc655dbdbc974cf1e646505c907bcba01d" projection: - input_digest: "sha256:90af33f4abbb808f5567e074347f17822cc610029e11a835fb5a8918c376ec9b" - output_digest: "sha256:080add7de51702df727bb8f1b770dcd5fd8343000d8b249af94a7b342a0a240b" + input_digest: "sha256:0ef47bca6d7a8a48831b7d52130db615122f6dc0cff6712821c31f464e1f3af0" + output_digest: "sha256:4d1db8e728c2ad4ba1891b0ad09bad15f3e3b2cc1b9d06960157da67e29e38e5" files: - path: ".gds/compiled-policy.json" - digest: "sha256:211668dd85e9d4bd3f547a1ea0cc9b1a5f486c64bde02a328b53dc3ef665c9fd" + digest: "sha256:9f498788bdc34e52a0ab793c536e0e6a7b360c2e1a20446cbf03ed51986cdc6f" - path: ".github/workflows/gds-ci.yml" - digest: "sha256:eef6659ecb3cd40914b73fde9856ad2bfa96f106ceac52f8c2fda0ef4fc00a79" + digest: "sha256:e533220f267926e39dc8ea8c567771372631898e9ebb0edf4ae76df5a76c9481" diff --git a/.gds/compiled-policy.json b/.gds/compiled-policy.json index c1f15d4..3d03f94 100644 --- a/.gds/compiled-policy.json +++ b/.gds/compiled-policy.json @@ -2,8 +2,8 @@ "schema_version": 1, "compiled_policy": { "repository_id": "repo_01M0EZ7TB3KNXNSP78Z8M64WXG", - "bundle_version": "0.9.6-dev", - "digest": "sha256:3db81f1769ba7f6698cead0d4b4e594dfda90c503c7f4d95b2517b234615f98e" + "bundle_version": "0.9.7-dev", + "digest": "sha256:49f7e5dc62becc5e1c65cefab9f51b834dac7e38b969ce2d3df9fd8720121900" }, "sources": [ { diff --git a/.github/workflows/gds-ci.yml b/.github/workflows/gds-ci.yml index 253e0b6..2ab21b2 100644 --- a/.github/workflows/gds-ci.yml +++ b/.github/workflows/gds-ci.yml @@ -1,8 +1,8 @@ # GENERATED FILE - DO NOT EDIT DIRECTLY # generator: gds -# bundle: 0.9.6-dev -# source-tree-digest: sha256:b9d572eb73bb14ae8ede20dfc1e9317046dcb544270eff95153746f93f094820 -# input-digest: sha256:90af33f4abbb808f5567e074347f17822cc610029e11a835fb5a8918c376ec9b +# bundle: 0.9.7-dev +# source-tree-digest: sha256:4853ed6bf539e3b59368ea375492691007a286401443ecb2e5f8cbf411a0bef5 +# input-digest: sha256:0ef47bca6d7a8a48831b7d52130db615122f6dc0cff6712821c31f464e1f3af0 # output-digest: sha256:b9bf3d0c64c0fb371596e7d090e82e62aebbfde91929115fc15fb28644e4fd38 # edit-source: # - .gds/repository.yaml diff --git a/CHANGELOG.md b/CHANGELOG.md index 538a708..c03ad9e 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -5,6 +5,15 @@ Versioning. ## [Unreleased] +## [0.9.7] - 2026-09-19 + +- Skip hidden directories during workspace discovery so tool-state and + fixture trees such as `.tmp/` no longer manufacture anchor findings; + `.git` stays the discoverable boundary. +- Observe quarantine remotes read-only through the fetch URL so checkout + quarantine plans work for SSH/HTTPS remotes while network pushes remain + gated behind `validatedPushURL`. + ## [0.9.6] - 2026-09-16 - Cut 0.9.6 as the next published bundle after `gds-v0.9.5`, which remains a diff --git a/core/cli/root.go b/core/cli/root.go index d472e82..4aa5e8d 100644 --- a/core/cli/root.go +++ b/core/cli/root.go @@ -22,7 +22,7 @@ import ( // Version is the development default; a release build overrides it with the // exact tag via -X. It carries the -dev suffix so an unstamped binary can // never claim to be a released one. -var Version = "0.9.6-dev" +var Version = "0.9.7-dev" type options struct { json bool diff --git a/core/cmd/gds-controller/main.go b/core/cmd/gds-controller/main.go index aae6e0a..b372905 100644 --- a/core/cmd/gds-controller/main.go +++ b/core/cmd/gds-controller/main.go @@ -25,7 +25,7 @@ import ( // version is the development default; the release builder stamps the exact // tag via -X main.version. The -dev suffix keeps an unstamped binary honest. -var version = "0.9.6-dev" +var version = "0.9.7-dev" func main() { ctx, stop := signal.NotifyContext( diff --git a/core/compiler/types.go b/core/compiler/types.go index 37dd49e..edf6cc3 100644 --- a/core/compiler/types.go +++ b/core/compiler/types.go @@ -12,7 +12,7 @@ import ( // policy-owner checkout. It tracks the current release line with a -dev // suffix so a development bundle is dated honestly; the development channel // field, not this string, is what classifies the bundle. -const DevelopmentBundleVersion = "0.9.6-dev" +const DevelopmentBundleVersion = "0.9.7-dev" type PolicySource struct { SchemaVersion int `json:"schema_version"` diff --git a/tests/golden/projections/control-plane/.claude/CLAUDE.md b/tests/golden/projections/control-plane/.claude/CLAUDE.md index 7887cee..2a08bc1 100644 --- a/tests/golden/projections/control-plane/.claude/CLAUDE.md +++ b/tests/golden/projections/control-plane/.claude/CLAUDE.md @@ -1,9 +1,9 @@