Bumps __version__ and pyproject to 1.4.0 and rolls CHANGELOG's [Unreleased]
section into [1.4.0] - 2026-08-13, opening a fresh [Unreleased]. No behavior
change; this is the release-staging PR. After merge, push the v1.4.0 tag to
trigger release.yml.
- paths-ignore '**/*.md' on push/pull_request so a CHANGELOG/README-only PR
doesn't spin up the (self-hosted, sometimes-offline) Windows test job.
- timeout-minutes on lint (10) / test (15) / catalog-signature (10) so a job
that hangs mid-run fails instead of hanging forever.
Note: timeout-minutes counts from job start, so it does not rescue a job stuck
'Waiting to run' when the Windows runner is offline — paths-ignore covers the
docs case; code PRs still need the runner up.
Starts a per-release changelog. The Unreleased section captures everything
merged since v1.3.0 (ssh-mcp v2 support, sidecar detect/edit, version pin,
permission pre-flight, hot-reload, light theme, visible update checker,
move-to-env, cross-client phase 1) with the ssh-mcp-is-breaking-upstream /
BCC-is-additive distinction called out. Past releases backfilled from tags.