E3: Toolchain refresh — 0.8.0
Goal
Release 0.8.0 "Toolchain refresh": bring every dependency and tool current and resolve all resulting breakages before validation work starts. Breaking release by decision (owner, 2026-10-08): rand 0.10 trait renames, Python ≥ 3.11, Rust ≥ 1.85 / edition 2024. Publishing moves to tokenless Trusted Publishing on PyPI and crates.io (npm already uses it); 'latest' versions are banned from workflows and Dependabot keeps drift from returning.
Release line: 0.8.0 Toolchain → 0.9.0 Validation (E4) → 0.10.0 Path Quality. Blocks all of E4.
Stories
- S3.1 — Rust core: edition 2024, rand 0.10, getrandom 0.4 (size-M)
- S3.2 — Python bindings: PyO3 0.29, maturin 1.15, Python 3.11+ (size-M; after S3.1)
- S3.3 — JS bindings and tooling: wasm-pack 0.15, vitest 5, eslint 10 (size-M; after S3.1)
- S3.4 — CI and publishing: current actions, Trusted Publishing, Dependabot (size-M; after S3.1–S3.3)
- S3.5 — Dev environment and docs refresh (size-S; after S3.4)
- S3.6 — Release 0.8.0 (size-S; after all)
Owner-only prerequisite: register trusted publishers on pypi.org and crates.io (tracked in S3.6).
Live status in TaskNotes (tag oxmpl/sprint/002); narrative in oxmpl - roadmap and oxmpl - sprint-002.