Repository navigation
Burrow v0.1.3
This release reduces repeated CI work and simplifies user management actions.
Linux amd64 and arm64 containers and standalone binaries remain supported.
Changes
- Main push CI reuses successful PR regression only when the recorded tested
Git tree matches the merged commit exactly. Missing, expired or invalid
evidence causes full regression. PR, dev and manual runs retain full tests. - Main still builds both native architecture images, tests their production
PostgreSQL startup and publishes the tested images to GHCR and Docker Hub. - Release metadata no longer invalidates dependency build layers. The pinned
image publisher is cached, tested image artifacts are kept for seven days,
and browser tests against packaged binaries avoid rebuilding the frontend.
Both release architectures retain their packaged-binary SQLite/MFA/OIDC
browser suite and production PostgreSQL container smoke tests. - Users password reset uses a lock icon; MFA reset uses a shield icon. Both
retain translated tooltips and accessible labels. - Remove the standalone Revoke sessions button and its management API
(POST /api/v1/users/{id}/revoke-sessions). Integrations using that endpoint
must stop calling it. Password reset, MFA reset, logout and account changes
retain their existing session invalidation behavior.
Install
Docker selects the appropriate Linux architecture from either image:
ghcr.io/arkgravity/burrow:v0.1.3
docker.io/logic3579/burrow:v0.1.3
The six attachments are:
burrow_v0.1.3_linux_amd64.tar.gzburrow_v0.1.3_linux_arm64.tar.gzburrow_v0.1.3_deploy.tar.gzINSTALL.mdIMAGES.txtSHA256SUMS
Both binaries embed the frontend and require glibc 2.36 or newer, such as
Debian 12. Follow the attached installation guide and verify the attachment
checksums.
Upgrade and MFA policy
Back up the database, original master key and configuration before upgrading.
Select the v0.1.3 image or binary, run migration and seed, then start the server.
There is no new database migration; schema v5, identities, passwords, grants,
applications and signing keys are preserved.
The global MFA policy is unchanged from v0.1.2: security.mfa_enabled and
BURROW_MFA_ENABLED default to false. Keep your existing policy setting.
When upgrading from v0.1.0 or v0.1.1, explicitly set BURROW_MFA_ENABLED=true
or security.mfa_enabled: true before startup to retain mandatory MFA.
Native commands do not load .env; exported environment values override YAML.
Verification scope
Release preparation requires successful main push CI for the exact tagged
commit, including its trusted PR regression record or full regression, both
image smoke tests and image publication. Both native release jobs must pass
the packaged-binary browser suite and production PostgreSQL startup checks
before the draft can be published. See Actions for this version's results.
The maintainer accepted the CI/release optimization and Users action changes.
That user-reported acceptance is separate from automated checks, downstream
SSO testing, production validation and OpenID Foundation certification.
中文说明
v0.1.3 优化 CI/release,并简化 Users 用户管理操作。
main 合并后的 push 仅在已成功 PR 的测试 Git tree 与合并提交完全一致时复用完整
回归结果;证据缺失、过期或无效时自动执行完整回归。PR、dev 和手动运行仍执行
完整测试。main 继续构建 amd64/arm64 镜像,验证 PostgreSQL 生产启动并推送双仓库。
发布流程改进构建缓存、缓存固定版本的镜像发布工具、将测试镜像保留七天,使用
已打包二进制运行浏览器测试时不再重复构建前端。两个架构的正式包浏览器回归和
PostgreSQL 容器烟测仍为发布前置条件。
Users 的重置密码改用锁图标,重置 MFA 改用盾牌图标,保留中英文提示和无障碍标签。
移除独立 Revoke sessions 按钮及 POST /api/v1/users/{id}/revoke-sessions API;
使用该接口的集成需停止调用。密码重置、MFA 重置、退出和账户变更仍保留原有的
会话失效处理。
继续提供双架构二进制、统一双架构镜像、共享部署包、安装指南、摘要和校验文件。
升级前备份数据库、原主密钥和配置,依次执行迁移、seed、启动;schema v5 不变。
MFA 开关仍默认关闭,从 v0.1.2 升级保留现有设置;从 v0.1.0/v0.1.1 升级且需要
继续强制 MFA 时,必须在启动前显式设置 BURROW_MFA_ENABLED=true 或 YAML 的
security.mfa_enabled: true。
用户已验收本次需求;人工验收与自动化结果、下游 SSO、生产部署和官方认证分别记录。