Skip to content

release: prepare 0.4.0 - #78

Merged
KARTIKrocks merged 1 commit into
mainfrom
release/0.4.0
Sep 25, 2026
Merged

KARTIKrocks merged 1 commit into
mainfrom
release/0.4.0

Conversation

@KARTIKrocks

Copy link
Copy Markdown
Owner

Summary

Closes the [Unreleased] section as [0.4.0] and cuts the matching docs snapshot. No code changes.

0.4 gets a snapshot rather than version markers because it changes documented behaviour rather than only adding to it:

Change Why /docs/ must keep describing 0.3
explain honours rules: Its own 0.3 docs said it deliberately did not
only: no longer reaches runtime or plan findings The same config now means something different
slow-query.threshold moved under rules.settings A 0.3 config using the old key is still correct on 0.3

Verified the snapshot actually captured the change: versioned_docs/version-0.4/ carries the new "What only: reaches" section and the reversed explain stance, and version-0.3/ correctly does not.

Type of change

  • Bug fix
  • New detection rule
  • New integration / parser
  • Feature / enhancement
  • Docs only
  • Refactor / chore

Checklist

  • make ci passes (fmt-check, vet, lint, vuln, test-race, lint-docs) across all modules
  • Added/updated tests (and, where practical, a failure-mode check)
  • Updated docs under website/docs/ with a version marker — never website/versioned_docs/
  • Updated AGENTS.md / .sqlguard.example.yml if a convention or config key changed
  • Added an entry under ## [Unreleased] in CHANGELOG.md
  • No new third-party deps in analyzer / middleware / reporter
  • Findings stay redaction-safe (no raw literals leak into a Result)

No tests and no AGENTS.md change: this adds no behaviour. versioned_docs/ is written here, which is the one time that is correct — cut-version.mjs creates the snapshot; no existing snapshot was edited.

What is deliberately not here

The satellite pinning. CONTRIBUTING.md has the root tag first and the satellites pinned to it afterwards, so the eight go.mod files still require v0.3.0 — they cannot point at v0.4.0 until it exists. Sequence after this merges:

  1. git tag v0.4.0 && git push origin v0.4.0
  2. go mod edit -require …@v0.4.0 across the eight satellites, make tidy && make test
  3. Commit that, tag each satellite, push

Verification

  • GOWORK=off make test — all 14 packages pass. The check that matters for a release: go.work normally hides a satellite compiling against a core version it does not actually require, so this is the only run that sees what a consumer's build sees.
  • Full Docusaurus production build across all three live snapshots, clean under onBrokenLinks: 'throw'.
  • make ci stages green — fmt-check, vet, lint, vuln (0 affecting), test; lint-docs fails only on untracked local scratch files outside this branch.
  • maxLiveVersions is 4 and versions.json is now ["0.4", "0.3", "0.2"], so nothing was pushed out of the served set.

Release notes will lead with the breaking changes

Unlike 0.3.0, which led with a security fix, this one needs its migrations up front:

 rules:
+  settings:
+    slow-query:
+      threshold: 200ms
-slow-query:
-  threshold: 200ms

and middleware.NewQueryTracker gains a severity argument — pass analyzer.SeverityWarning to keep the previous behaviour.

Closes the [Unreleased] section as [0.4.0] and cuts the matching docs
snapshot.

0.4 earns a snapshot rather than markers because it changes documented
behaviour rather than only adding to it: `explain` now honours `rules:` after
its own docs said it deliberately did not, `only:` no longer reaches the
runtime or plan findings, and `slow-query.threshold` moved under
`rules.settings`. `/docs/` has to keep describing 0.3 for anyone still on it.

Only the changelog and the snapshot are here. Per CONTRIBUTING the root tag
comes first and the satellites are pinned to it afterwards, so the eight
go.mod files still require v0.3.0 and are updated once v0.4.0 exists.
@coderabbitai

coderabbitai Bot commented Sep 25, 2026

Copy link
Copy Markdown
Contributor

Important

  • 🔍 Trigger review

This repository does not receive automatic reviews because it has fewer than 10 stars.

⚙️ Run configuration

Configuration used: Repository: KARTIKrocks/sqlguard/.coderabbit.yaml

Review profile: ASSERTIVE

Plan: Advanced

Run ID: 753e1633-a665-4ddb-8e9b-4c7369ae8732


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@KARTIKrocks
KARTIKrocks merged commit 372e1b5 into main Sep 25, 2026
27 checks passed
@KARTIKrocks
KARTIKrocks deleted the release/0.4.0 branch September 25, 2026 07:51
@KARTIKrocks KARTIKrocks mentioned this pull request Sep 25, 2026
13 tasks
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant