What's new in v0.26.1
v0.26.1 is a maintenance release of the binary. It is built with Rust 1.99.0 instead of 1.98.1, against the newest compatible releases of its dependencies, and it behaves as 0.26.0 did.
The 1.99.0 compiler
The workspace pins Rust 1.99.0 in rust-toolchain.toml and in rust-version, so every release binary, including the one the container image copies, comes out of the 1.99.0 compiler. No source line of the binary changes for it.
Newer dependencies, same requirements
Cargo.lock moves to the newest releases the existing version requirements allow, and no requirement in the Cargo.toml files changes: hyper 1.12.0, hyper-rustls 0.27.10, hyper-util 0.1.21, which brings in base64 0.23.1, libc 0.2.190, lru 0.18.5, thiserror 2.0.21, tokio 1.53.2, tokio-rustls 0.26.6, toml 1.1.8, uuid 1.27.0 and want 0.3.2. cargo audit reports no advisory on the lockfile of either release, so none of these updates closes a known vulnerability.
Against the 0.26.0 binary, analyze on the 20 trace fixtures of the repository, in JSON and in SARIF, produced the same output apart from the version string: the same 32 findings, with the same signatures. The one line that differed is the pair of example calls a chatty-service suggestion names when every call ties at x1, a pair that already changes from one run to the next on 0.26.0.
Upgrade impact
- MSRV moves to 1.99.0.
perf-sentinel-coredeclaresrust-version = "1.99.0", so a crate that depends on it needs Rust 1.99.0 or newer to build. - Nothing a finding is keyed on moves. Findings, signatures, endpoints and SARIF locations are unchanged, so acknowledgments keep matching and no finding appears or disappears.
- No configuration key is added or removed, no route, metric name or wire format changes, no public signature in
perf-sentinel-coremoves, and the embedded reference data keeps its vintages.
Full detail in CHANGELOG.md.
Verifying this release
# Binary integrity via SLSA build provenance attestation (Build Level 2)
gh attestation verify perf-sentinel-linux-amd64 \
--repo robintra/perf-sentinel
# A periodic disclosure produced by this binary
perf-sentinel verify-hash --report perf-sentinel-report.json \
--expected-identity "https://github.com/robintra/perf-sentinel/.github/workflows/release.yml@refs/tags/v0.26.1" \
--expected-issuer "https://token.actions.githubusercontent.com" \
--verify-binary ./perf-sentinel-linux-amd64gh CLI 2.49 or newer required for gh attestation verify.