chore(release): prepare 1.9.0 - #693
Merged
Merged
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Prepare the stable 1.9.0 release with the full highlights and upgrade notes from 1.8.0, including the fixes after the release candidates. Bump the package and lockfile to 1.9.0.
Align both atomic suites with the reviewed rules commit fca3fbf0ef1f1430f12f4f91bacb2205a0c0224f on rustinel-rules main. This uses the merged Linux YARA fixture lifetime fix instead of its temporary branch commit and includes the rules development version bump. Linux, Windows, and signed macOS will validate this exact pin before publication.
Document a scoped exception for RUSTSEC-2026-0327, published after the release candidates. Upstream identifies disabled component-model-async as a workaround.
cargo tree --locked --target all -e features -i wasmtimeconfirms neither component-model nor component-model-async is enabled. YARA-X 1.21.0 remains the latest published version and requires Wasmtime 45.0.3, with no patched 45.x release available. Advisory: GHSA-32h6-97mm-8q3c.Validation:
cargo fmt --all -- --check, locked Cargo metadata, version and lockfile consistency, release notes structure, released field contract, matching rules pins,cargo deny --locked checkfor both root and eBPF dependencies, andgit diff --checkpassed. Cross-platform tests, Clippy, and atomic checks run in CI before merging and publishing.