chore: align VERSION with v1.0.1, add CI version check and release checklist

- VERSION was bumped to 1.1.0 at the v1.0.1 release commit but no 1.1.0
  release exists; align to 1.0.1 so VERSION == latest CHANGELOG release
- Add version-check job to ci.yml (VERSION must match latest CHANGELOG [x.y.z])
- Add docs/RELEASE-CHECKLIST.md for release + metadata sync steps
- Fix benchmark case count in CHANGELOG: 162 -> 163 (routing-benchmark.json
  actually contains 163 cases; ci.yml was already correct)
This commit is contained in:
yhc
2026-08-10 19:11:06 +08:00
parent 539899ddc7
commit d46e88d09a
4 changed files with 41 additions and 2 deletions
+19
View File
@@ -126,3 +126,22 @@ jobs:
echo "case-guard accepted fields outside their contract sections" >&2
exit 1
fi
version-check:
name: version consistency
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
- name: VERSION matches latest CHANGELOG release
shell: pwsh
run: |
$v = (Get-Content VERSION -Raw).Trim()
$cl = Get-Content CHANGELOG.md -Raw
$m = [regex]::Match($cl, '(?m)^## \[(\d+\.\d+\.\d+)\]')
if (-not $m.Success) { Write-Error 'No version header found in CHANGELOG'; exit 1 }
$latest = $m.Groups[1].Value
if ($v -ne $latest) {
Write-Error "VERSION ($v) does not match latest CHANGELOG release ($latest)"
exit 1
}
Write-Host "Version OK: $v"
+1 -1
View File
@@ -12,7 +12,7 @@ Versioning follows [Semantic Versioning](https://semver.org/).
### Added
- **Routing single source of truth** — `skills/config/routing.json` (R0–R39 keyword rules with `must` / `mustAll` / `exclude` semantics). `master-route.ps1` now reads this file; hardcoded routing tables removed from scripts. Routing knowledge lives in one place.
- **Routing regression benchmark** — `skills/tests/routing-benchmark.json` (162 bilingual cases, 40 quick) + `skills/scripts/test-routing.ps1` runner. Any routing change must keep the benchmark green.
- **Routing regression benchmark** — `skills/tests/routing-benchmark.json` (163 bilingual cases, 40 quick) + `skills/scripts/test-routing.ps1` runner. Any routing change must keep the benchmark green.
- **Routing keyword coverage expansion** (benchmark-driven): burp suite family, pcap/wireshark, root-detection/certificate-pinning, buffer overflow, `.so`/native/JNI, go binaries (中文), js-encrypt, webshell, privilege escalation, S3/object storage, memory dump, incident response, Bluetooth/BLE, USB, Unity/game reverse, security assessment, and more.
- **Supply-chain pin gate** — `verify-routing-coherence.ps1` now fails on any auto-install capability lacking `pinnedVersion` / `pinnedCommit` / `pinPolicy` / asset hash. Pinned: frida-tools 14.10.4, pwntools 4.15.0, agent-browser 0.31.1, ida-pro-mcp @commit, SecLists/ProxyCat @commit, nuclei v3.9.0; winget sources annotated with `winget-latest` policy.
- **Client-neutral integration contract** — routing, tests, manifests, and case workflows remain independent of Claude Code, Codex, Cursor, OpenCode, or any other client; client adapters are optional and must not define repository identity.
+1 -1
View File
@@ -1 +1 @@
1.1.0
1.0.1
+20
View File
@@ -0,0 +1,20 @@
# 发布 Checklist
> 每次发版前逐项核对。版本事实源:VERSION 文件必须与 CHANGELOG.md 最新发布版本一致(CI ersion-check job 自动校验,不一致会红)。
## 发版步骤
1. [ ] 确认 CHANGELOG.md 的 [Unreleased] 段内容齐全(Keep a Changelog 分组:Added / Fixed / Security / Removed)
2. [ ] 将 ## [Unreleased] 改为 ## [x.y.z] — YYYY-MM-DD,并把比较链接从 ...HEAD 更新到新 tag
3. [ ] 同步更新 VERSION 文件为 x.y.z
4. [ ] 里程碑版本(如 v1.0.0 / v1.1.0)同步更新 docs/RELEASE_NOTES_v<x.y.z>.md
5. [ ] 打 tag:git tag v<x.y.z> + git push --tags
6. [ ] 推送后确认 CI 全绿(routing 163 基准 + coherence + pin gate + version-check)
## 元数据同步(发版顺手项)
- 新增/删除 bootstrap 能力 → 同步 RULES.md / RULES_zh.md / skills/SKILL.md 的能力列表(以 skills/scripts/bootstrap-manifest.json 为唯一事实源,当前 24 项)
- 新增 field-journal 条目 → 更新 skills/field-journal/_index.md 三处(场景分类 / 高频模式 / 实体倒排)与统计
- 路由规则变更 → 只改 skills/config/routing.json(文档由生成脚本维护或至少保持一致)
> 注:journal 条目底部不再手工维护 <!-- [进化统计] --> 累计注释(已于 2026-08-10 移除,数字无法可靠维护),项目计数以 _index.md 为准。