release: bump 0.8.8 -> 0.8.9 (#285)

Maintenance release — supply-chain and CI housekeeping only. No library code or
public API changes.

### Security
- Triaged the pyo3 advisories RUSTSEC-2026-0176 / RUSTSEC-2026-0177 as not
  affecting Wickra (vulnerable APIs unreachable from the binding; fix blocked
  upstream by rust-numpy pinning pyo3 `^0.28`). Recorded in `deny.toml` and
  `osv-scanner.toml`.

### Changed
- Java binding: `central-publishing-maven-plugin` 0.5.0 → 0.10.0.
- CI GitHub Actions bumped to latest (checkout, setup-go, setup-java,
  codeql-action, taiki-e/install-action).
- Added a Maven ecosystem to Dependabot.

Version bumped across all manifests/lockfiles via `bump_version.py`; Cargo.lock
refreshed. CHANGELOG `[0.8.9]` filled. Tag/publish to follow on explicit GO.
This commit is contained in:
kingchenc
2026-06-12 23:21:39 +02:00
committed by GitHub
parent 8ccfd638b2
commit f7f0bfbc48
19 changed files with 89 additions and 63 deletions
+3 -3
View File
@@ -2,13 +2,13 @@
## Supported versions
Wickra is pre-1.0. Security fixes are applied to the latest released `0.8.8`
Wickra is pre-1.0. Security fixes are applied to the latest released `0.8.9`
version only; please upgrade to the newest release before reporting an issue.
| Version | Supported |
| --- | --- |
| 0.8.8 (latest) | :white_check_mark: |
| < 0.8.8 | :x: |
| 0.8.9 (latest) | :white_check_mark: |
| < 0.8.9 | :x: |
## Reporting a vulnerability