Skip to content

docs(changelog): 0.1.10 security section and version bump#263

Merged
memtomem merged 1 commit intomainfrom
docs/changelog-0.1.10-security
Apr 18, 2026
Merged

docs(changelog): 0.1.10 security section and version bump#263
memtomem merged 1 commit intomainfrom
docs/changelog-0.1.10-security

Conversation

@memtomem
Copy link
Copy Markdown
Owner

Summary

Adds the [0.1.10] release block to CHANGELOG.md with a Security section covering the watcher-path credential indexing fix, and bumps packages/memtomem/pyproject.toml to 0.1.10. The release itself (tag + GitHub Release + PyPI publish via Trusted Publishers OIDC) is intentionally deferred to a separate session.

Background context: the 2026-04-19 disclosure review declined filing a formal GHSA for this finding (near-zero user base); protection is delivered via a SECURITY: CHANGELOG section on upgrade and two public follow-up issues. Rationale preserved in the project forensics memo.

Scope

Out of scope (follow-ups)

Cross-refs

Gate runs

ruff check / ruff format --check / pytest -m "not ollama" included for project convention. CHANGELOG + pyproject is a text-only diff with no Python changes, so these checks trivially pass.

@memtomem memtomem merged commit 820be61 into main Apr 18, 2026
7 checks passed
@memtomem memtomem deleted the docs/changelog-0.1.10-security branch April 18, 2026 23:05
@github-actions github-actions Bot locked and limited conversation to collaborators Apr 18, 2026
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants