# Changelog
All notable changes to this project will be documented in this file. The
format follows [Keep a Changelog](https://keepachangelog.com/en/1.1.0/), and
the project uses semantic versioning within the usual pre-1.0 compatibility
rules.
## [Unreleased]
## [0.1.2] - 2026-09-16
### Changed
- Switched npm release publishing to GitLab OIDC Trusted Publishing.
- Documented the synchronized multi-registry release checklist.
## [0.1.1] - 2026-09-16
### Changed
- Synchronized the Rust core, Python binding, and JavaScript/WASM binding at
version 0.1.1 for the next registry release.
- Added protected-tag publishing for Cargo, PyPI, and npm, with clean
registry-install verification documented for all three packages.
## [0.1.0] - 2026-09-08
### Added
- Archival GEDCOM 5.5 through 7.x parsing, decoding, views, validation, and
reported version conversion.
- Bounded GEDZIP reading and writing.
- Python and JavaScript/WASM bindings over the same Rust core.
- Byte-exact vendored corpus, conformance, property, interoperability, and
adversarial test suites.
### Security
- Refuse traversal, platform-special, duplicate, and central/local-mismatched
GEDZIP paths before returning entry bytes.
- Stage and checksum external fixture downloads before making them visible.
- Reject line injection through programmatically constructed GEDCOM fields.