3.7 KiB
3.7 KiB
2.7.0-rc2
- Simplify the cross-platform passive updater with explicit inherited environment and
process.execPath, a bounded wait for the install outcome before CLI exit, and no TTY workaround or external timeout helper. - Show aggregate context-upload progress in an
Uploading contextchild task, deduplicating shared blobs and accounting for resumed uploads. - Support
build: auto:<GitHub HTTPS .cnb URI>with optional#sha256=<hex>pinning. The realkilterset/bun1.0.0 package was fetched and validated for Linux ARM64; its architecture mismatch was correctly rejected for AMD64. - Live CNB Kubernetes Job execution and registry push remain unverified.
2.7.0-rc1
Added
- Add
kuber initto createcompose.ymlwith a first app, log in when needed, and register trust for the current directory. Addkuber add appto insert another service into an existing project while preserving existing services and YAML content. - Support interactive and non-interactive scaffolding with app-root detection, image, Buildpacks, or Dockerfile-template sources, Postgres/S3 claims, resource limits, and replicas.
- Bundle eight Dockerfile and
.dockerignoretemplates:bun-service,bun-next,bun-compiled,node-pnpm,python-web,go-static,rust-static, andstatic-nginx. - Support bare
build: autothrough CNB Buildpacks, including subproject contexts throughx-kuber-build-context. Auto builds require Git and use Git-selected worktree files with.gitignorefiltering, including tracked files matched by ignore rules;.dockerignoredoes not control this selection. - Support
build: auto:<URI>for an HTTPS GitHub release.cnbpackage, optionally pinned with#sha256=<hex>, with server-side package staging, digest verification, and target-architecture validation.
Changed
- Begin generated Compose files with
managedBy: kuber # See https://npmx.dev/@dmgnr/kuber for documentation.and accept the marker in kuber's Compose schema. - Show aggregate context-upload bytes and percentage as a separate task during
kuber up, deduplicating shared blobs across workspaces and accounting for resumed uploads. - Simplify the passive updater to launch the current Bun executable with the inherited runtime environment, without Linux terminal helpers or an external
timeoutcommand. Wait for the bounded install outcome and its success or available-version notice before CLI exit; suppress automatic installs in tests and source-tree development.
Fixed
- Validate scaffold paths and options, refuse to overwrite existing generated files, detect concurrent Compose edits, and roll back newly generated files on failures. Initialization preserves files needed to repair local trust after successful remote registration.
- Reject potential credential files selected for auto-build snapshots and require unsafe paths to be excluded through
.gitignore. - Reject symlinked workspace parents and unsafe snapshot symlink traversal; validate server-side symlink chains and cycles before materialization.
- Remove malformed or expired session files, including sessions with invalid expiry timestamps.
- Bound registry manifest reads, validate supported manifest structure, verify advertised digests against the response bytes, and avoid exposing registry error-response bodies.
- Reject unknown top-level Compose properties while retaining supported fields and
x-extensions.
Release notes
- Auto builds always use CNB Buildpacks, even when a Dockerfile exists; there is no BuildKit fallback. Ordinary Dockerfile builds retain the BuildKit path.
- The
managedBymarker is kuber-specific; ordinarydocker composerejects generated files containing it. - Live CNB Kubernetes Job execution and registry push have not been verified for this release candidate.