Release 0.50.0
Release 0.50.0 fixes a security problem with test filenames and cases where reports disagreed with the terminal summary. It also makes random test order easier to repeat and removes the interactive tutorial.
Test filenames cannot become commands
The cleanup command run at the end of each test used to store the test-file path as Bash code. Bash read that code again when the test finished. A filename containing $(...) could therefore run a command. This matters when automated checks run tests from a branch whose filenames another contributor controls (#1315).
Bash now treats the filename as text. These names also no longer prevent the test's checks from running and make it appear risky, the label used when a test may not have checked anything. Update projects that run tests from untrusted branches.
Repeat a random order with its seed
A seed is the number used to reproduce a random test order. Passing --seed now selects that random order automatically. Copying the seed from a failing run is enough to repeat its order, unless you explicitly choose another order (#1287).
bashunit --seed 12345 tests/Snapshots save expected test output for later comparison. Updating them also has a shorter spelling, -u:
bashunit -u --filter test_render_status tests/Reports agree with the run
JSON and JUnit reports no longer contain stray terminal text when a parallel run selects no tests, finishes file cleanup, finds repeated function names or reports a command error. Reports also count a failed file setup or cleanup step once, matching the terminal summary (#1295, #1297, #1299, #1301).
Special characters in paths no longer break JUnit or Cobertura, the XML formats used for test and coverage reports. TAP reports sent directly to the terminal handle # in test descriptions. GitHub Actions error messages safely include special characters in titles and paths, and Markdown summaries handle failure messages that contain triple backticks. Benchmark files that fail to load or set up now make bashunit bench report failure.
The recorded parallel reporting example runs about 1.9 times faster and uses about 1.8 times less processor time after removing repeated calls to base64, the tool used to encode report values. Startup saves about 9 ms in the recorded measurement because loading the display colours no longer starts an extra program for each colour (#1289, #1285).
Tutorial removal
bashunit learn has been removed. Calling it explains the removal and points to the documentation. The guides provide learning material and examples; the runner no longer includes the interactive tutorial.
See the full changelog for 0.50.0 on GitHub.