OpenTranscribe v0.5.1 - Dependency Maintenance & Release Pipeline Fixes
We're releasing OpenTranscribe v0.5.1, a maintenance release that clears the dependency backlog accumulated by Dependabot's weekly grouped PRs and closes out the three release-pipeline gaps discovered while cutting v0.5.0 (issues #937, #938, #939).
What's Changed
Seven Dependabot groups, consolidated and tested progressively
Dependabot's grouping configuration produces seven separate PRs every week. Rather than merging each independently — or hand-splitting a risky one into thirteen — this release consolidates all seven into a single branch, merging each group with its own tested commit so a break in one group is caught and fixed before the next lands. git log --first-parent still shows exactly which group brought in which change.
Five packages hidden inside the grouped bumps had real, undetected conflicts — none of them caught by CI alone, only by a real Docker build, npm install, or the full test gate:
fastapi0.141.1 broke route mounting outright. A grouped bump exceeded a cap already documented in the pin's own comment./api/openapi.jsondropped from 395 paths to 3 — every route handler silently failed to mount. Reverted to0.136.3.tokenizers,sentence-transformers,numpy, andpresidio-anonymizereach had a narrower resolver conflict, reverted individually.- Frontend
typescripthit annpm installERESOLVE conflict againstsvelte-check, reverted to^5.9.3.
Two of these (sentence-transformers, typescript) now have a permanent ignore: entry in .github/dependabot.yml, and fastapi is capped by version range — so Dependabot stops re-proposing a bump already known to break the build, rather than re-litigating the same failure every week.
Two incidental bugs found and fixed along the way
./opentr.sh rebuild-backend/rebuild-frontendnever checkeddocker compose up --build's exit code, so a broken dependency pin would fail the rebuild silently while the script reported success and left the stale container running.scripts/verify-install-paths.sh's GitHub API helper pipedcurl's output throughgrep -m1, which can sendcurla SIGPIPE and report a spurious failure once a real API response is large enough — this had been failing every CI run for several days. Fixed with a bash herestring, which has no live process to signal.
Three release-pipeline gaps closed (#937, #938, #939)
All three were discovered while cutting v0.5.0 and tracked for this release:
- The publish stage no longer re-scans an image it already scanned (#937).
50-scan.shscans every image before publish; the post-push scan used to repeat that work unconditionally — about 25 minutes of the v0.5.0 publish stage was spent re-measuring content already measured that morning. It now reuses the prior report whenever the local image's digest matches the recorded scan's digest and the scan policy hasn't changed — which is a stronger guarantee than a second scan, since nothing before this actually proved the image that got pushed is the image that got scanned. - The build stage now shares its registry build cache with the publish stage (#938), so rebuilding the same legs on the remote multi-arch builder can reuse work already done locally.
- The smoke stage's fresh-install rehearsal no longer leaves a stack running behind it (#939), which used to block the stage's own next invocation.
Upgrade Notes
No database migrations are required. No environment variable changes are required.
How to Update
docker compose pull
docker compose up -d
Full Changelog
See CHANGELOG.md for the complete list of changes.
