Documentation editorial pass. Replaced concrete example values in CHANGELOG.md and a templates/config.html JSDoc comment with documentation-friendly placeholders for consistency with the project's documentation conventions.
-
Added a pre-release audit step to
bump-version.sh. A new advisory check runs alongside the existing static name-resolution and inline-JS parse passes, scanning the worked tree for two classes of identifying information: maintainer name forms (with the project's GitHub-username form allowlisted via a negative lookahead) and concrete RFC1918 IPs outside a documentation allowlist. The IP allowlist covers RFC 5737 ranges (192.0.2.x,198.51.100.x,203.0.113.x), the common documentation subnets (192.168.0.x,192.168.1.x,10.0.0.x), and the special unroutable address10.254.254.254used byntfy_installer.py's_detect_lan_ipkernel-route trick.Two files are always expected to hit on the names check:
LICENSE(MIT copyright holder) andtemplates/about.html(the/aboutpage's copyright line). These are the project's deliberate attribution surfaces and are file-allowlisted. Any third file flagged is treated as a real leak.The audit is advisory at this release: it prints findings but doesn't gate a bump. After a release cycle or two of validation it can graduate to required, on the same maturation path the static name-resolution check took.