release: bump 0.8.8 -> 0.8.9 (#285)
Maintenance release — supply-chain and CI housekeeping only. No library code or public API changes. ### Security - Triaged the pyo3 advisories RUSTSEC-2026-0176 / RUSTSEC-2026-0177 as not affecting Wickra (vulnerable APIs unreachable from the binding; fix blocked upstream by rust-numpy pinning pyo3 `^0.28`). Recorded in `deny.toml` and `osv-scanner.toml`. ### Changed - Java binding: `central-publishing-maven-plugin` 0.5.0 → 0.10.0. - CI GitHub Actions bumped to latest (checkout, setup-go, setup-java, codeql-action, taiki-e/install-action). - Added a Maven ecosystem to Dependabot. Version bumped across all manifests/lockfiles via `bump_version.py`; Cargo.lock refreshed. CHANGELOG `[0.8.9]` filled. Tag/publish to follow on explicit GO.
This commit is contained in:
+3
-3
@@ -2,13 +2,13 @@
|
||||
|
||||
## Supported versions
|
||||
|
||||
Wickra is pre-1.0. Security fixes are applied to the latest released `0.8.8`
|
||||
Wickra is pre-1.0. Security fixes are applied to the latest released `0.8.9`
|
||||
version only; please upgrade to the newest release before reporting an issue.
|
||||
|
||||
| Version | Supported |
|
||||
| --- | --- |
|
||||
| 0.8.8 (latest) | :white_check_mark: |
|
||||
| < 0.8.8 | :x: |
|
||||
| 0.8.9 (latest) | :white_check_mark: |
|
||||
| < 0.8.9 | :x: |
|
||||
|
||||
## Reporting a vulnerability
|
||||
|
||||
|
||||
Reference in New Issue
Block a user