Skip to content

Cut 2.0.0 - #27

Merged
authorTom merged 1 commit into
mainfrom
release/2.0.0
Sep 15, 2026
Merged

authorTom merged 1 commit into
mainfrom
release/2.0.0

Conversation

@authorTom

Copy link
Copy Markdown
Owner

Releases the production-hardening work merged in #26 as 2.0.0.

It's a major because, by the README's versioning rule, upgrading can require action:

  • DECKLE_TRUST_PROXY must be set behind Caddy, Traefik or nginx. Without it, all visitors share one sign-in throttle.
  • /api/v1 rejects more input: non-object bodies, non-hex colours, invalid dates and non-string ids now get a 400.
  • Changing DECKLE_PASSWORD signs out every session.

Changes: package.json and package-lock.json go to 2.0.0, and the changelog's Unreleased section becomes [2.0.0] — 2026-09-15.

After merging, tag v2.0.0 on the merge commit. That publishes the image as :2.0.0, :2.0, :2 and :latest, and the GitHub release gets marked Latest.

🤖 Generated with Claude Code

The production-hardening work from #26. A major by the versioning table,
whose rule is "if an upgrade needs you to do something, it is a major":

- Behind a reverse proxy, DECKLE_TRUST_PROXY must now be set. Without it
  every visitor shares the proxy's sign-in throttle, and ten wrong passwords
  from anyone lock everyone out.
- /api/v1 refuses requests it used to accept: non-object JSON bodies,
  non-hex colours, impossible due dates, non-string ids.
- Changing DECKLE_PASSWORD now signs every session out.

package.json and the lockfile are bumped together.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
@authorTom
authorTom merged commit ea913b1 into main Sep 15, 2026
1 check passed
@authorTom
authorTom deleted the release/2.0.0 branch September 15, 2026 08:42
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant