Repository navigation
Tags: qnbs/WorldScript-Studio
Tags
v1.29.1 — First published v1.29 desktop release (successor of the unp… …ublished v1.29.0 tag) Ships all v1.29.0 content since v1.28.8: the #553 persistence and data-integrity work, third-party notices and CycloneDX SBOMs in every desktop installer (#871), the corrected in-app Help (#904), the P0 desktop persistence fix #907 (Tauri fs scope for the desktop dotfiles on Linux and macOS, #908) and the qualified dependency train (#872). The signed v1.29.0 tag (cf72dc6) is kept unchanged; its tag-time OSV scan failed on a development-only joi advisory, so its desktop release was cancelled before publication. v1.29.1 adds the joi fix (#909) and the brace-expansion, fast-uri and ip-address fixes (#912) found by the newly executed pre-tag Security Audit; all are development-only and absent from the shipped SBOMs. Pre-tag qualification on f255d76 (record on #872): resulting-main CI/CD and CodeQL green; production READY on the exact SHA; a fresh Security Audit execution after the freeze green; Tauri plugin parity; 3-OS workflow_dispatch build green on the exact candidate; notices byte-identical inside all seven installer formats and three SBOMs bound to the candidate; release-collect and release-notes steps dry-run verbatim with fail-closed negatives; #743 AI invariant unchanged. Linux AppImage runtime-qualified against the real packaged artifact: a v1.28.8 project opens, is edited, saved and reopened; a fresh install creates, saves and reopens with a stable identity; FUTURE and UNSUPPORTED_OLDER projects are refused with Safe Open and stay byte-identical; a legacy project migrates to schema 1 with a verbatim pre-migration snapshot; a second instance exits. Not claimed: OS-native code signing or notarization (#574), Intel macOS (#507), and packaged runtime execution on macOS and Windows.
v1.29.0 — Release-readiness, dependency and desktop-persistence release Ships the accumulated v1.29 work since v1.28.8: third-party notices and CycloneDX SBOMs generated for and bundled into every desktop installer (#881), corrected Help and security claims (no OS-native code-signing overclaim, correct com.worldscript.studio data paths, #904), the qualified dependency tranche (#895, #897, #900) and the P0 desktop persistence fix #907: the Tauri fs scope now grants the desktop dotfiles (.incarnation, .legacy-owner and their atomic-write temp files) on Linux and macOS, where $APPDATA/** never matched a leading-dot path component (#908). Pre-tag qualification on cf72dc6 (record on #872): resulting-main CI/CD and CodeQL green; production deployment READY on the exact SHA; Tauri plugin parity OK; 3-OS workflow_dispatch build green on the exact candidate; THIRD_PARTY_NOTICES byte-identical inside all seven installer formats and three SBOMs bound to the candidate; release-collect and release-notes steps dry-run verbatim, including fail-closed negatives; #743 AI invariant unchanged. Linux AppImage runtime-qualified against the real packaged artifact: an unmodified v1.28.8 profile opens its project; a fresh install saves; FUTURE and UNSUPPORTED_OLDER fixtures show distinct recovery copy with Safe Open, keep the refused project byte-identical and move the marker only after a new project is written; a legacy project migrates to schema 1 with a verbatim pre-migration snapshot and reopens without a second migration; a second instance exits. Not claimed: OS-native code signing or notarization (#574), Intel macOS (#507), and packaged runtime execution on macOS and Windows.
v1.28.8 — Desktop startup-recovery patch release Adds an explicit, non-destructive Safe Open action for a desktop project refused by schema admission (FUTURE / UNSUPPORTED_OLDER), so the application shell is no longer unreachable when the only prior action (Retry) reloads into the same refusal. The refused project stays byte-preserved and the active-project marker untouched; project persistence is fenced to a session-minted identity until the user explicitly establishes a project. reconciliation recorded on #743 (not a reused v1.28.7 exception); the qualification tracker itself remains open. Pre-tag qualification: resulting-main CI/CD and CodeQL green on 868d66b. Cross-platform Tauri build (Ubuntu/Windows/macOS) succeeded via workflow_dispatch on the exact candidate commit. Linux AppImage runtime-qualified against the real packaged artifact: FUTURE and UNSUPPORTED_OLDER fixtures each show distinct, correct recovery copy; Safe Open transitions cleanly to the portal with no Continue option; the refused project's bytes are unchanged (hash-verified) throughout; the active-project marker advances only after a new project is successfully created and written under a fresh session identity; auxiliary writes (codex/vectors) land under that same new identity, never the refused one.
v1.28.4 Patch release: - fix: PWA first-install unprompted reload (#585, PR #613) - fix: shared-origin service-worker cache-read isolation (#514, PR #612) - fix: Factory Reset could report success while user data remained (PR #596) - fix: Factory Reset could reboot into Settings instead of Welcome Portal (PR #592) - fix: preserve-first desktop corruption recovery (PR #542) and a distinct filesystem-I/O recovery action (PR #545) - fix: intentionally cleared project metadata no longer reappears (PR #546) - a11y: Welcome/Home dashboard WCAG AA contrast + reduced-motion cascade fix (#565, PR #609); ManuscriptEditor contrast (PR #560) - security: fflate ZIP64-parsing DoS override (PR #595); routine dependency floor bumps - docs: R-15 secure desktop storage design contract admitted (implementation gated behind Wave 2 prerequisites) - tests: visual regression testing repaired (PR #610); IDB reset-quiescence hardening (PR #596)
PreviousNext