What's Changed
A bunch of best-practices housekeeping, security updates, code quality, version upgrades, etc. No functionality gained or lost, should behave the exact same for end users.
- Retire the GitHub Pages update manifest; serve only from the CDN by @anthonysgro in #105
- Point user-facing links at GeoSpoof/geospoof after the org transfer by @anthonysgro in #106
- Hold fast-check at v3 and split npm majors into their own PRs by @anthonysgro in #107
- Migrate to fast-check v4 by @anthonysgro in #113
- CI best practices: cover CDK, SHA-pin actions, assert publish-role trust by @anthonysgro in #114
- Auto-merge devDependency patch bumps from Dependabot by @anthonysgro in #116
- Add CodeQL static analysis by @anthonysgro in #117
- Add SECURITY.md with a private disclosure policy by @anthonysgro in #121
- Force shell-quote ≥1.11.0 to clear a critical transitive advisory by @anthonysgro in #125
- Upgrade to vite 8 + vitest 5 by @anthonysgro in #127
- Drop unused devDeps; declare cdk's coverage dependency by @anthonysgro in #129
- Align on Node 24; upgrade lint-staged to 17 by @anthonysgro in #136
- Upgrade jsdom to 30; raise Node floor to 24.15 by @anthonysgro in #137
- Add repo-hygiene files: .nvmrc, .editorconfig, CODE_OF_CONDUCT.md by @anthonysgro in #138
- Move CONTRIBUTING + CODE_OF_CONDUCT into .github/ by @anthonysgro in #139
- Add OpenSSF Scorecard + CI/Scorecard README badges by @anthonysgro in #140
- Harden release provenance + token permissions (Scorecard fixes) by @anthonysgro in #141
- Fix cdk transitive DoS/SSRF advisories (brace-expansion, fast-uri) by @anthonysgro in #142
- Scope CodeQL to shipped code; document geolocation RNG false positive by @anthonysgro in #143
- 2.2.3 by @anthonysgro in #144
Full Changelog: v2.2.2...v2.2.3