Pre-v0.3.6 release sweep found frontend/package.json stuck at 0.3.5 while the other three version files were 0.3.6. package.json drives the runtime `__APP_VERSION__` (vite.config.js), so a v0.3.6 build was calling itself "v0.3.5" in the first-run footer AND in every auto bug report (undercutting the bug-report feature). Root cause: the release.yml version-bump job only bumped the trio (tauri.conf.json / Cargo.toml / pyproject.toml), never package.json, and no test guarded the lockstep. - Bump frontend/package.json 0.3.5 → 0.3.6 (matches the trip; `--frozen-lockfile` still passes — the version field doesn't affect the bun lock graph). - Add frontend/package.json to the release.yml version-bump job (set absolutely via jq so any prior drift self-heals on the next release). - Add tests/test_app_version.py::test_all_version_files_in_lockstep — fails CI if the four files ever diverge again. - CLAUDE.md versioning rule updated: it's now FOUR lockstep files, not three (docs-sync). Co-authored-by: mergetest <test@local> Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>