Skip to content

chore(release): v0.33.0 - #344

Merged
ralyodio merged 1 commit into
mainfrom
release-0-33-0
Aug 9, 2026
Merged

chore(release): v0.33.0#344
ralyodio merged 1 commit into
mainfrom
release-0-33-0

Conversation

@ralyodio

@ralyodio ralyodio commented Aug 9, 2026

Copy link
Copy Markdown
Contributor

Bump to v0.33.0, releasing three things that have been sitting on main unreleased:

#342 the herd — agent sessions that outlive the terminal that started them
#341 PRD 0009, the document behind it
#343 moshpit pinned-TLS proxy fix

Why minor, not patch

#342 adds six commands (herd, ps, attach, kill, wait, restore) and six moshscript verbs, and changes none of the existing ones. moshcode start claude without -d behaves exactly as it did in 0.32.0 — the herd is opt-in at every entry point.

Why this release matters more than most

install.sh serves the latest release tarball, not main. Until a release carries it, every installed machine answers unknown command "ps" no matter what is merged. The npm channel is downstream of the same event — publish.yml triggers on a published GitHub release — so nothing reaches either channel until this ships.

No plugin bumps

stocks and crypto are untouched, and neither names a command that moved.

Verification

  • 1470 tests pass, 0 fail, 0 cancelled.
  • moshcode version reads back 0.33.0.
  • Only package.json changes, matching the v0.32.0 / v0.31.0 release commits.

Merging this does not publish anything on its own — the GitHub release still has to be created, which is what fires publish.yml.

🤖 Generated with Claude Code

Bump to v0.33.0, releasing the herd (#342) — agent sessions that outlive
the terminal that started them — along with the PRD behind it (#341) and
the moshpit pinned-TLS proxy fix (#343), all of which have been sitting on
main unreleased.

Minor rather than patch: #342 adds six commands (herd, ps, attach, kill,
wait, restore) and six moshscript verbs, and changes none of the existing
ones. `moshcode start claude` with no -d behaves exactly as it did.

This release is what makes any of it reachable. install.sh serves the
latest release tarball rather than main, so until a release carries it
every installed machine answers `unknown command "ps"` — and the npm
channel only moves when publish.yml sees a published GitHub release.

No plugin bumps: stocks and crypto are untouched, and neither names a
command that moved.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@github-actions

github-actions Bot commented Aug 9, 2026

Copy link
Copy Markdown

ThreatCrush Security Scan

92 finding(s)

HIGH/CRITICAL: 2 | MEDIUM: 42 | LOW: 48

Severity Rule Location
HIGH manifest-typosquat apps/pwa/package.json:19
HIGH js-ssrf-outbound-request apps/pwa/public/sw.js:45
MEDIUM tls-verification-disabled apps/pwa/src/lib/moshpit-gateway.mjs:299
MEDIUM sql-template-interpolation apps/pwa/src/moshpit.mjs:61
MEDIUM sql-template-interpolation apps/pwa/src/moshpit.mjs:75
MEDIUM sql-template-interpolation apps/pwa/src/moshpit.mjs:101
MEDIUM sql-template-interpolation apps/pwa/src/moshpit.mjs:265
MEDIUM sql-template-interpolation apps/pwa/src/moshpit.mjs:269
MEDIUM sql-template-interpolation apps/pwa/src/moshpit.mjs:314
MEDIUM sql-template-interpolation apps/pwa/src/moshpit.mjs:499
MEDIUM sql-template-interpolation apps/pwa/src/moshpit.mjs:675
MEDIUM sql-template-interpolation apps/pwa/src/moshpit.mjs:677
MEDIUM sql-template-interpolation apps/pwa/src/moshpit.mjs:736
MEDIUM sql-template-interpolation apps/pwa/src/moshpit.mjs:782
MEDIUM sql-template-interpolation apps/pwa/src/moshpit.mjs:852
MEDIUM sql-template-interpolation apps/pwa/src/moshpit.mjs:955
MEDIUM sql-template-interpolation apps/pwa/src/moshpit.mjs:1063
MEDIUM sql-template-interpolation apps/pwa/src/moshpit.mjs:1199
MEDIUM js-unescaped-html-sink apps/pwa/src/routes/moshpit.mjs:1419
MEDIUM js-dynamic-code-execution apps/pwa/test/apikey-mask.test.mjs:129
MEDIUM sql-template-interpolation apps/pwa/test/credits-webhook-event-match.test.mjs:111
MEDIUM sql-template-interpolation apps/pwa/test/credits-webhook-event-match.test.mjs:131
MEDIUM sql-template-interpolation apps/pwa/test/moshpit-terms.test.mjs:192
MEDIUM tls-verification-disabled src/dns.mjs:741
MEDIUM sql-template-interpolation src/dns.mjs:2549
MEDIUM sql-template-interpolation src/selfupdate.mjs:166
MEDIUM sql-template-interpolation src/selfupdate.mjs:170
MEDIUM sql-template-interpolation src/selfupdate.mjs:208
MEDIUM sql-template-interpolation src/selfupdate.mjs:209
MEDIUM insecure-temp-file test/dns-disable-restore.test.mjs:93
MEDIUM insecure-temp-file test/dns-disable-restore.test.mjs:310
MEDIUM insecure-temp-file test/plugins.test.mjs:152
MEDIUM insecure-temp-file test/pty.test.mjs:28
MEDIUM insecure-temp-file test/pty.test.mjs:31
MEDIUM insecure-temp-file test/pty.test.mjs:40
MEDIUM insecure-temp-file test/pty.test.mjs:42
MEDIUM insecure-temp-file test/pty.test.mjs:47
MEDIUM insecure-temp-file test/pty.test.mjs:48
MEDIUM insecure-temp-file test/pty.test.mjs:49
MEDIUM insecure-temp-file test/tabs.test.mjs:8
MEDIUM insecure-temp-file test/tabs.test.mjs:13
MEDIUM insecure-temp-file test/tabs.test.mjs:14
MEDIUM insecure-temp-file test/tabs.test.mjs:22
MEDIUM insecure-temp-file test/trust.test.mjs:240
LOW secret-generic-credential apps/pwa/test/apikey-bearer-scheme.test.mjs:30
LOW secret-generic-credential apps/pwa/test/apikey-mask.test.mjs:38
LOW secret-generic-credential apps/pwa/test/apikey-reveal.test.mjs:35
LOW secret-generic-credential apps/pwa/test/approvals-context.test.mjs:28
LOW secret-generic-credential apps/pwa/test/approvals-credits.test.mjs:28
LOW secret-generic-credential apps/pwa/test/approvals-notify.test.mjs:26

…and 42 more. Full results in the Security tab.

Snippets are redacted; ThreatCrush never prints matched credential material.

@ralyodio
ralyodio merged commit eb73884 into main Aug 9, 2026
4 checks passed
@ralyodio
ralyodio deleted the release-0-33-0 branch August 9, 2026 18:05
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant