Skip to main content

OpenTranscribe v0.5.1 - Dependency Maintenance & Release Pipeline Fixes

· 3 min read
OpenTranscribe Team
OpenTranscribe Development Team

We're releasing OpenTranscribe v0.5.1, a maintenance release that clears the dependency backlog accumulated by Dependabot's weekly grouped PRs and closes out the three release-pipeline gaps discovered while cutting v0.5.0 (issues #937, #938, #939).

What's Changed​

Seven Dependabot groups, consolidated and tested progressively​

Dependabot's grouping configuration produces seven separate PRs every week. Rather than merging each independently — or hand-splitting a risky one into thirteen — this release consolidates all seven into a single branch, merging each group with its own tested commit so a break in one group is caught and fixed before the next lands. git log --first-parent still shows exactly which group brought in which change.

Five packages hidden inside the grouped bumps had real, undetected conflicts — none of them caught by CI alone, only by a real Docker build, npm install, or the full test gate:

  • fastapi 0.141.1 broke route mounting outright. A grouped bump exceeded a cap already documented in the pin's own comment. /api/openapi.json dropped from 395 paths to 3 — every route handler silently failed to mount. Reverted to 0.136.3.
  • tokenizers, sentence-transformers, numpy, and presidio-anonymizer each had a narrower resolver conflict, reverted individually.
  • Frontend typescript hit an npm install ERESOLVE conflict against svelte-check, reverted to ^5.9.3.

Two of these (sentence-transformers, typescript) now have a permanent ignore: entry in .github/dependabot.yml, and fastapi is capped by version range — so Dependabot stops re-proposing a bump already known to break the build, rather than re-litigating the same failure every week.

Two incidental bugs found and fixed along the way​

  • ./opentr.sh rebuild-backend/rebuild-frontend never checked docker compose up --build's exit code, so a broken dependency pin would fail the rebuild silently while the script reported success and left the stale container running.
  • scripts/verify-install-paths.sh's GitHub API helper piped curl's output through grep -m1, which can send curl a SIGPIPE and report a spurious failure once a real API response is large enough — this had been failing every CI run for several days. Fixed with a bash herestring, which has no live process to signal.

Three release-pipeline gaps closed (#937, #938, #939)​

All three were discovered while cutting v0.5.0 and tracked for this release:

  • The publish stage no longer re-scans an image it already scanned (#937). 50-scan.sh scans every image before publish; the post-push scan used to repeat that work unconditionally — about 25 minutes of the v0.5.0 publish stage was spent re-measuring content already measured that morning. It now reuses the prior report whenever the local image's digest matches the recorded scan's digest and the scan policy hasn't changed — which is a stronger guarantee than a second scan, since nothing before this actually proved the image that got pushed is the image that got scanned.
  • The build stage now shares its registry build cache with the publish stage (#938), so rebuilding the same legs on the remote multi-arch builder can reuse work already done locally.
  • The smoke stage's fresh-install rehearsal no longer leaves a stack running behind it (#939), which used to block the stage's own next invocation.

Upgrade Notes​

No database migrations are required. No environment variable changes are required.

How to Update​

docker compose pull
docker compose up -d

Full Changelog​

See CHANGELOG.md for the complete list of changes.