Skip to content

release: v0.7.0 — signetry-core - #98

Merged
bkd-dotcom merged 1 commit into
mainfrom
release/v0.7.0
Aug 18, 2026
Merged

release: v0.7.0 — signetry-core#98
bkd-dotcom merged 1 commit into
mainfrom
release/v0.7.0

Conversation

@bkd-dotcom

Copy link
Copy Markdown
Member

Version bump + changelog for the work merged since v0.6.0. The release workflow validates that the pushed tag matches pyproject version, so this has to land before tagging.

What's in it

Detection breadth

Executors

SSRF precision

CI

Why minor, not patch

New detection rules and a new executor are features, so 0.6.0 → 0.7.0 rather than 0.6.1.

Also updated

The pinned install references in README.md and docs/ (6 files) move v0.6.0 → v0.7.0 so the documented command matches the tag.

After merge

git tag v0.7.0 && git push origin v0.7.0, then bump the signetry-core pin in Signetry/eval — its corpus additions for eval#11/#12/#29 depend on the new rules.

Detection breadth (Kotlin, Go SSRF, Go/Java path traversal, PHP XXE), the
Aider executor, SSRF precision fixes, and the fork-PR reviewer fix.

Minor bump rather than patch: this adds new detection rules and a new
executor, not just fixes.

Bumps the version-pinned install references in README and docs/ alongside
pyproject, so the documented install command matches the tag.
@github-actions

Copy link
Copy Markdown

Signetry Reviewer — 🟡 Needs human review

A human should decide — the required check is pending; 1 advisory finding(s) to weigh.

Deterministic gates (the authority)

Gate Status
Required status check ⏳ pending
Secret scan ✅ clean
CI permission / OIDC ✅ no forbidden change
Dependency skew ✅ ok
All green

Findings (1, 0 blocking)

  • 🟡 Change touches a protected path: pyproject.toml pyproject.toml (via cross-check)
    • pyproject.toml matches a protected pattern (pyproject.toml). Changes here alter shared/foundational surface and warrant a designated reviewer.
    • Fix: Route to a code owner / architecture reviewer.

Merge

A human should review and merge.

This review is advisory. It never merges on its own judgement — the deterministic gates + a human are the authority. Findings can have false negatives; a green bot verdict is not a guarantee.

@bkd-dotcom
bkd-dotcom merged commit 0d39eb3 into main Aug 18, 2026
8 checks passed
@bkd-dotcom
bkd-dotcom deleted the release/v0.7.0 branch August 18, 2026 20:08
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant