diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index fedfa57..6d0d61a 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -126,3 +126,22 @@ jobs: echo "case-guard accepted fields outside their contract sections" >&2 exit 1 fi + + version-check: + name: version consistency + runs-on: ubuntu-latest + steps: + - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 + - name: VERSION matches latest CHANGELOG release + shell: pwsh + run: | + $v = (Get-Content VERSION -Raw).Trim() + $cl = Get-Content CHANGELOG.md -Raw + $m = [regex]::Match($cl, '(?m)^## \[(\d+\.\d+\.\d+)\]') + if (-not $m.Success) { Write-Error 'No version header found in CHANGELOG'; exit 1 } + $latest = $m.Groups[1].Value + if ($v -ne $latest) { + Write-Error "VERSION ($v) does not match latest CHANGELOG release ($latest)" + exit 1 + } + Write-Host "Version OK: $v" diff --git a/CHANGELOG.md b/CHANGELOG.md index 6e59428..d2924d7 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -12,7 +12,7 @@ Versioning follows [Semantic Versioning](https://semver.org/). ### Added - **Routing single source of truth** — `skills/config/routing.json` (R0–R39 keyword rules with `must` / `mustAll` / `exclude` semantics). `master-route.ps1` now reads this file; hardcoded routing tables removed from scripts. Routing knowledge lives in one place. -- **Routing regression benchmark** — `skills/tests/routing-benchmark.json` (162 bilingual cases, 40 quick) + `skills/scripts/test-routing.ps1` runner. Any routing change must keep the benchmark green. +- **Routing regression benchmark** — `skills/tests/routing-benchmark.json` (163 bilingual cases, 40 quick) + `skills/scripts/test-routing.ps1` runner. Any routing change must keep the benchmark green. - **Routing keyword coverage expansion** (benchmark-driven): burp suite family, pcap/wireshark, root-detection/certificate-pinning, buffer overflow, `.so`/native/JNI, go binaries (中文), js-encrypt, webshell, privilege escalation, S3/object storage, memory dump, incident response, Bluetooth/BLE, USB, Unity/game reverse, security assessment, and more. - **Supply-chain pin gate** — `verify-routing-coherence.ps1` now fails on any auto-install capability lacking `pinnedVersion` / `pinnedCommit` / `pinPolicy` / asset hash. Pinned: frida-tools 14.10.4, pwntools 4.15.0, agent-browser 0.31.1, ida-pro-mcp @commit, SecLists/ProxyCat @commit, nuclei v3.9.0; winget sources annotated with `winget-latest` policy. - **Client-neutral integration contract** — routing, tests, manifests, and case workflows remain independent of Claude Code, Codex, Cursor, OpenCode, or any other client; client adapters are optional and must not define repository identity. diff --git a/VERSION b/VERSION index 1cc5f65..7f20734 100644 --- a/VERSION +++ b/VERSION @@ -1 +1 @@ -1.1.0 \ No newline at end of file +1.0.1 \ No newline at end of file diff --git a/docs/RELEASE-CHECKLIST.md b/docs/RELEASE-CHECKLIST.md new file mode 100644 index 0000000..2a9173e --- /dev/null +++ b/docs/RELEASE-CHECKLIST.md @@ -0,0 +1,20 @@ +# 发布 Checklist + +> 每次发版前逐项核对。版本事实源:VERSION 文件必须与 CHANGELOG.md 最新发布版本一致(CI ersion-check job 自动校验,不一致会红)。 + +## 发版步骤 + +1. [ ] 确认 CHANGELOG.md 的 [Unreleased] 段内容齐全(Keep a Changelog 分组:Added / Fixed / Security / Removed) +2. [ ] 将 ## [Unreleased] 改为 ## [x.y.z] — YYYY-MM-DD,并把比较链接从 ...HEAD 更新到新 tag +3. [ ] 同步更新 VERSION 文件为 x.y.z +4. [ ] 里程碑版本(如 v1.0.0 / v1.1.0)同步更新 docs/RELEASE_NOTES_v.md +5. [ ] 打 tag:git tag v + git push --tags +6. [ ] 推送后确认 CI 全绿(routing 163 基准 + coherence + pin gate + version-check) + +## 元数据同步(发版顺手项) + +- 新增/删除 bootstrap 能力 → 同步 RULES.md / RULES_zh.md / skills/SKILL.md 的能力列表(以 skills/scripts/bootstrap-manifest.json 为唯一事实源,当前 24 项) +- 新增 field-journal 条目 → 更新 skills/field-journal/_index.md 三处(场景分类 / 高频模式 / 实体倒排)与统计 +- 路由规则变更 → 只改 skills/config/routing.json(文档由生成脚本维护或至少保持一致) + +> 注:journal 条目底部不再手工维护 累计注释(已于 2026-08-10 移除,数字无法可靠维护),项目计数以 _index.md 为准。 \ No newline at end of file