Changelog
Release history for @gentleduck/query. Newest releases at the top.
1.0.0
Major Changes
95638de: Audit-driven refactor across all 15 public packages. Closes type holes, hardens security boundaries, eliminates dead code, and dedups duplicated patterns.
Highlights
duck-docs— CompiledMdxBody branded type gatesnew Function(body); sanitizeSvg covers SMIL, unquoted javascript: URIs, nested script, CSS url(), bare iframe; code-preview tag + attr allowlistsduck-registry-build— safe-path containment at every fs sink; per-phase Zod cache schemas; JSON.stringify in generated TSX; cache manifest rejection on tamperduck-cli— install pipeline path containment unified across add/init/update; env-var allowlist contract reconciled with one-time warning; aliases.ui regex validationduck-primitives—observe-element-rectrAF loop guard (no leak when empty);compose-refuseCallback memo fix; popper forwardRef restored for R18 peer compatduck-hooks—useDebounceis now a real hook (stable identity, unmount cleanup);useStableIddelegates to React.useId (SSR-safe);scheduleTransitionTimeoutrename strips twouseHookAtTopLevellint suppressionsduck-lazy— spread order fix restores the lazy swap;next/imagemoved behind/lazy-image-nextsubpath so non-Next consumers don't pull the peerduck-vim— single document listener fans out to chord matcher + sequence manager; canonical modifier order;requireResetauto-clears for chord bindings; all three hook dep arrays correctedduck-variants—Props<T, D>makes defaulted variant keys optional and non-defaulted required; boundedpreludeCacheLRU; second-layerfilter2set eliminates last clone in hot pathduck-ttest—predictates/renamed topredicates/, twin dirs deleted, type-utility duplicates reconciled to canonical sources,IsVoidactually distinguishes void from undefined nowduck-calendar—./*wildcard export removed; falsy-zeroweekStartDay: 0(Sunday) bug fixed; Gregorian helpers extracted; HebrewaddMonthsuses Metonic cycleduck-libs—cnMemobounded LRU;filteredObjectrejects typo keys at compile time;parseDaterejects ambiguous one-token inputsduck-query— single AnyReq boundary cast replaces 14as any; param regex escape; throws on unresolved:tokensregisters— schema tightened (z.any()removed); ~1000 LoC of identical block-registry boilerplate replaced with buildersregistry-ui—_audio/_upload(~1.1K LoC) deleted;motion-shellHOC +withMotioncollapses simple motion clones;toDirection()narrower replaces 52as IDirection.Kindcasts; chartCSS_NAMED_COLORSfinite allowlistduck-motion— refcounted bodypointer-eventsownership; easing/blur/duration token dedup; half of public exports were unused and removed
Tests: 3133+ across the monorepo, all green. Type-checks clean across every project. No commits skipped hooks.
0.1.8
Patch Changes
- 95dbbce: Standardize README headers across all packages: centered logo, h1, tagline, nav links, and npm badges (matching the @duck-md template). Replace per-repo
*.gentleduck.orgsubdomain refs with path-basedgentleduck.org/duck-<name>URLs. No runtime code changes.
0.1.7
Patch Changes
- 918b34c: Strip
workspace:*andcatalog:protocol tokens fromdevDependencies/dependencies/peerDependenciesof every public package beforechangeset publish. Previously published artifacts leaked these tokens into npm metadata, which broke strict resolvers (bun, deno) for downstream consumers. Addsscripts/clean-publish.tsand wires it into the rootreleasescript with agit checkoutrestore step so source remains workspace-friendly.
0.1.6
Patch Changes
- 4f93768: fixing bugs and making sure gen support new format
0.1.5
Patch Changes
- 7c62d44: done
- 7c62d44: fixed bug
0.1.5
Patch Changes
- 533602f: fixed gen and query
0.1.4
Patch Changes
- 48e4bbf: fixed deps
0.1.3
Patch Changes
- batman