Skip to content

chore(release): v0.27.0 - #323

Merged
ralyodio merged 1 commit into
mainfrom
release/v0.27.0
Aug 8, 2026
Merged

chore(release): v0.27.0#323
ralyodio merged 1 commit into
mainfrom
release/v0.27.0

Conversation

@ralyodio

Copy link
Copy Markdown
Contributor

Bump to v0.27.0, releasing /crypto — crypto market data from advis0r.com as a CLI verb, a pit command, and a second Claude Code plugin (#322) — alongside two commits that have been sitting on main unreleased:

Minor rather than patch: it adds a command and a plugin, and changes no existing one.

Why the release matters for the plugin

As with v0.26.0 and ticker, the release is what makes the plugin's primary path work. install.sh serves the latest release tarball, not main, so until a release carries it every installed binary answers unknown command "crypto" and the plugin's slash commands fall back to curl — which works, but skips the rendering the verb exists to do.

Verification

Full suite on this exact tree: 1385 tests, 0 failures.

Merging this and publishing the v0.27.0 release triggers publish.yml, which re-runs the tests and pushes to npm with provenance.

🤖 Generated with Claude Code

Bump to v0.27.0, releasing `/crypto` — crypto market data from advis0r.com as
a CLI verb, a pit command, and a second Claude Code plugin (#322) — alongside
two commits that have been sitting on main unreleased: the compact() carry fix
for `ticker` (#321) and the move off the deprecated Node 20 runtime (#320).
Minor rather than patch: it adds a command and a plugin, and changes no
existing one.
As with v0.26.0 and `ticker`, the release is what makes the plugin's primary
path work. install.sh serves the latest release tarball, not main, so until a
release carries it every installed binary answers `unknown command "crypto"`
and the plugin's slash commands fall back to curl — which works, but skips the
rendering the verb exists to do.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@github-actions

Copy link
Copy Markdown

ThreatCrush Security Scan

91 finding(s)

HIGH/CRITICAL: 2 | MEDIUM: 41 | LOW: 48

SeverityRuleLocation
HIGHmanifest-typosquatapps/pwa/package.json:19
HIGHjs-ssrf-outbound-requestapps/pwa/public/sw.js:45
MEDIUMtls-verification-disabledapps/pwa/src/lib/moshpit-gateway.mjs:299
MEDIUMsql-template-interpolationapps/pwa/src/moshpit.mjs:61
MEDIUMsql-template-interpolationapps/pwa/src/moshpit.mjs:75
MEDIUMsql-template-interpolationapps/pwa/src/moshpit.mjs:101
MEDIUMsql-template-interpolationapps/pwa/src/moshpit.mjs:265
MEDIUMsql-template-interpolationapps/pwa/src/moshpit.mjs:269
MEDIUMsql-template-interpolationapps/pwa/src/moshpit.mjs:314
MEDIUMsql-template-interpolationapps/pwa/src/moshpit.mjs:499
MEDIUMsql-template-interpolationapps/pwa/src/moshpit.mjs:675
MEDIUMsql-template-interpolationapps/pwa/src/moshpit.mjs:677
MEDIUMsql-template-interpolationapps/pwa/src/moshpit.mjs:736
MEDIUMsql-template-interpolationapps/pwa/src/moshpit.mjs:782
MEDIUMsql-template-interpolationapps/pwa/src/moshpit.mjs:852
MEDIUMsql-template-interpolationapps/pwa/src/moshpit.mjs:955
MEDIUMsql-template-interpolationapps/pwa/src/moshpit.mjs:1063
MEDIUMsql-template-interpolationapps/pwa/src/moshpit.mjs:1199
MEDIUMjs-unescaped-html-sinkapps/pwa/src/routes/moshpit.mjs:1419
MEDIUMjs-dynamic-code-executionapps/pwa/test/apikey-mask.test.mjs:129
MEDIUMsql-template-interpolationapps/pwa/test/credits-webhook-event-match.test.mjs:111
MEDIUMsql-template-interpolationapps/pwa/test/credits-webhook-event-match.test.mjs:131
MEDIUMsql-template-interpolationapps/pwa/test/moshpit-terms.test.mjs:192
MEDIUMsql-template-interpolationsrc/dns.mjs:2439
MEDIUMsql-template-interpolationsrc/selfupdate.mjs:166
MEDIUMsql-template-interpolationsrc/selfupdate.mjs:170
MEDIUMsql-template-interpolationsrc/selfupdate.mjs:208
MEDIUMsql-template-interpolationsrc/selfupdate.mjs:209
MEDIUMinsecure-temp-filetest/dns-disable-restore.test.mjs:93
MEDIUMinsecure-temp-filetest/dns-disable-restore.test.mjs:310
MEDIUMinsecure-temp-filetest/plugins.test.mjs:92
MEDIUMinsecure-temp-filetest/pty.test.mjs:28
MEDIUMinsecure-temp-filetest/pty.test.mjs:31
MEDIUMinsecure-temp-filetest/pty.test.mjs:40
MEDIUMinsecure-temp-filetest/pty.test.mjs:42
MEDIUMinsecure-temp-filetest/pty.test.mjs:47
MEDIUMinsecure-temp-filetest/pty.test.mjs:48
MEDIUMinsecure-temp-filetest/pty.test.mjs:49
MEDIUMinsecure-temp-filetest/tabs.test.mjs:8
MEDIUMinsecure-temp-filetest/tabs.test.mjs:13
MEDIUMinsecure-temp-filetest/tabs.test.mjs:14
MEDIUMinsecure-temp-filetest/tabs.test.mjs:22
MEDIUMinsecure-temp-filetest/trust.test.mjs:240
LOWsecret-generic-credentialapps/pwa/test/apikey-bearer-scheme.test.mjs:30
LOWsecret-generic-credentialapps/pwa/test/apikey-mask.test.mjs:38
LOWsecret-generic-credentialapps/pwa/test/apikey-reveal.test.mjs:35
LOWsecret-generic-credentialapps/pwa/test/approvals-context.test.mjs:28
LOWsecret-generic-credentialapps/pwa/test/approvals-credits.test.mjs:28
LOWsecret-generic-credentialapps/pwa/test/approvals-notify.test.mjs:26
LOWsecret-generic-credentialapps/pwa/test/approvals-resolve-race.test.mjs:20

…and 41 more. Full results in the Security tab.

Snippets are redacted; ThreatCrush never prints matched credential material.

@ralyodio
ralyodio merged commit 16b311c into mainAug 8, 2026
4 checks passed
@ralyodio
ralyodio deleted the release/v0.27.0 branch August 8, 2026 16:42
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@ralyodio