This release adds automated CVE scanning, copies the effective CRTDL into job directories for reproducibility, hardens flattening reliability, and cleans up unused pipeline steps.
What's Changed
Improvements
- CVE checking with govulncheck — Add automated Go vulnerability scanning in CI #246
- Copy effective CRTDL into job directory — Every pipeline step now has access to the effective CRTDL used for the job #244
- ISO 8601 durations in config — Config durations accept both Go
time.Durationand ISO 8601 formats #224
Bug Fixes
- Flattening: stop duplicating sibling blocks in ViewDefinition — Fix duplicated column blocks for sibling attributes in generated ViewDefinitions #301
- Flattener retry with backoff — Handle transient EOF and connection errors from the flattener service with exponential backoff #240
- docs-deploy git identity — Configure git identity early in the docs-deploy workflow #303
Refactors
- Remove unused csv_conversion and parquet_conversion steps — Clean up dead pipeline step code #243
Documentation
- Community dropdown split from version selector — Separate community and version navigation in the docs header #309
CI & Housekeeping
- Restrict Renovate torch updates to stable and alpha releases #247
- Update TORCH to v1.0.0-alpha.18
- Update Go to v1.26.2
- Update PostgreSQL to v18
- Update Vue to v3.5.32, Vite to v8
- Update aws-sdk-go-v2 monorepo
- Update debian:bookworm-slim, nginx-unprivileged, blaze, blazectl, fhir-pseudonymizer
- Update GitHub Actions (codecov v6, gh-release v3, upload-artifact v7, github-script v9, setup-node v6.4.0, harden-runner v2.19.0, cosign v4.1.1, docker/login v4, paths-filter v4)