From 44b047193a6acf17faf72e2f61d5164965b88e9b Mon Sep 17 00:00:00 2001 From: Danil Silantyev Date: Sat, 19 Sep 2026 21:05:13 +0500 Subject: [PATCH 1/2] chore(release): cut development bundle 0.9.7 Stamp compiler, CLI and controller to 0.9.7-dev. Carries the workspace discovery hidden-directory fix and read-only quarantine remote observation. --- CHANGELOG.md | 9 +++++++++ core/cli/root.go | 2 +- core/cmd/gds-controller/main.go | 2 +- core/compiler/types.go | 2 +- .../projections/control-plane/.claude/CLAUDE.md | 4 ++-- .../control-plane/.gds/bundle.lock.yaml | 16 ++++++++-------- .../control-plane/.gds/compiled-policy.json | 4 ++-- .../control-plane/.github/workflows/gds-ci.yml | 4 ++-- tests/golden/projections/control-plane/AGENTS.md | 8 ++++---- 9 files changed, 30 insertions(+), 21 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index 538a708..c03ad9e 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -5,6 +5,15 @@ Versioning. ## [Unreleased] +## [0.9.7] - 2026-09-19 + +- Skip hidden directories during workspace discovery so tool-state and + fixture trees such as `.tmp/` no longer manufacture anchor findings; + `.git` stays the discoverable boundary. +- Observe quarantine remotes read-only through the fetch URL so checkout + quarantine plans work for SSH/HTTPS remotes while network pushes remain + gated behind `validatedPushURL`. + ## [0.9.6] - 2026-09-16 - Cut 0.9.6 as the next published bundle after `gds-v0.9.5`, which remains a diff --git a/core/cli/root.go b/core/cli/root.go index d472e82..4aa5e8d 100644 --- a/core/cli/root.go +++ b/core/cli/root.go @@ -22,7 +22,7 @@ import ( // Version is the development default; a release build overrides it with the // exact tag via -X. It carries the -dev suffix so an unstamped binary can // never claim to be a released one. -var Version = "0.9.6-dev" +var Version = "0.9.7-dev" type options struct { json bool diff --git a/core/cmd/gds-controller/main.go b/core/cmd/gds-controller/main.go index aae6e0a..b372905 100644 --- a/core/cmd/gds-controller/main.go +++ b/core/cmd/gds-controller/main.go @@ -25,7 +25,7 @@ import ( // version is the development default; the release builder stamps the exact // tag via -X main.version. The -dev suffix keeps an unstamped binary honest. -var version = "0.9.6-dev" +var version = "0.9.7-dev" func main() { ctx, stop := signal.NotifyContext( diff --git a/core/compiler/types.go b/core/compiler/types.go index 37dd49e..edf6cc3 100644 --- a/core/compiler/types.go +++ b/core/compiler/types.go @@ -12,7 +12,7 @@ import ( // policy-owner checkout. It tracks the current release line with a -dev // suffix so a development bundle is dated honestly; the development channel // field, not this string, is what classifies the bundle. -const DevelopmentBundleVersion = "0.9.6-dev" +const DevelopmentBundleVersion = "0.9.7-dev" type PolicySource struct { SchemaVersion int `json:"schema_version"` diff --git a/tests/golden/projections/control-plane/.claude/CLAUDE.md b/tests/golden/projections/control-plane/.claude/CLAUDE.md index 7887cee..2a08bc1 100644 --- a/tests/golden/projections/control-plane/.claude/CLAUDE.md +++ b/tests/golden/projections/control-plane/.claude/CLAUDE.md @@ -1,9 +1,9 @@