From b3506121018b61135481ac60ee462ecf83d1c11a Mon Sep 17 00:00:00 2001 From: BootIntel Agent Date: Wed, 7 Oct 2026 09:39:22 +0000 Subject: [PATCH] Release 0.14.0: an SBOM for hardware you did not build `bootintel submit` (#37) is merged but sits under [Unreleased], and the workspace is still 0.13.0, which is also the latest published release. So nobody can install the command: a `brew install` or a release download today gets 0.13.0 without it. A merged feature no user can run is not shipped. The repo's own policy makes this MINOR: "new detector; new subcommand; new flag; new output format". Same four files the 0.13.0 release touched: the workspace version, the detectors pin in crates/cli, Cargo.lock, and the CHANGELOG heading. Nothing here publishes anything by itself -- cli-release.yml is workflow_dispatch only, with an explicit version input and a dry_run option -- so the release remains a deliberate manual act after this lands. Verified the built binary reports 0.14.0 and still carries `submit`. Co-Authored-By: Claude Opus 5 (1M context) --- CHANGELOG.md | 2 ++ Cargo.lock | 4 ++-- Cargo.toml | 2 +- crates/cli/Cargo.toml | 2 +- 4 files changed, 6 insertions(+), 4 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index 0de7ce2..db4cf1b 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -8,6 +8,8 @@ All notable changes to bootintel-cli are documented here. Format follows [Keep a ## [Unreleased] +## [0.14.0] — 2026-10-07 — an SBOM for hardware you did not build + ### Added - **`bootintel submit`**: save a boot log to your BootIntel account as a persisted scan and download the server-side artifacts in one step: the CycloneDX 1.6 SBOM diff --git a/Cargo.lock b/Cargo.lock index d0ed04d..794f663 100644 --- a/Cargo.lock +++ b/Cargo.lock @@ -131,7 +131,7 @@ checksum = "b588b76d00fde79687d7646a9b5bdf3cc0f655e0bbd080335a95d7e96f3587da" [[package]] name = "bootintel" -version = "0.13.0" +version = "0.14.0" dependencies = [ "anyhow", "arboard", @@ -154,7 +154,7 @@ dependencies = [ [[package]] name = "bootintel-detectors" -version = "0.13.0" +version = "0.14.0" dependencies = [ "regex", ] diff --git a/Cargo.toml b/Cargo.toml index 0adeeaa..27d3e83 100644 --- a/Cargo.toml +++ b/Cargo.toml @@ -19,7 +19,7 @@ members = ["crates/detectors", "crates/cli"] resolver = "2" [workspace.package] -version = "0.13.0" +version = "0.14.0" edition = "2021" rust-version = "1.90" license = "Apache-2.0" diff --git a/crates/cli/Cargo.toml b/crates/cli/Cargo.toml index 7174114..ac2843e 100644 --- a/crates/cli/Cargo.toml +++ b/crates/cli/Cargo.toml @@ -24,7 +24,7 @@ path = "src/main.rs" # version when packaging for crates.io, which rejects a bare path dep. # This is what publish = false was working around; publishing # bootintel-detectors first makes the workaround unnecessary. -bootintel-detectors = { path = "../detectors", version = "0.13.0" } +bootintel-detectors = { path = "../detectors", version = "0.14.0" } clap = { version = "4.5", features = ["derive", "wrap_help", "env"] } # Shell-completion emitters for `bootintel completions `. Version # tracks the clap major/minor (4.5). No default features — we only use