Skip to content

Releases: NDDev-it-com/macos-ubuntu-bootstrap

2.0.0

Choose a tag to compare

@github-actions github-actions released this 24 Jul 09:14
Immutable release. Only release title and notes can be modified.
c58ee40

Changed

  • Advance managed harness pins to their promoted heads: nddev-codex-app
    dc6db75e8ee019 (config-ownership + overlay-preservation fixes) and
    nddev-zcode-app 66f76394457f07 (source-graph plan/apply collision
    parity), matching the nddev-harnesses expected heads.
  • Sync agent-facing docs to the executable contract: CloakBrowser 0.4.12,
    Chrome DevTools MCP 1.6.0, uv 0.11.30 across AGENTS/README/SECURITY/CLAUDE,
    the install and browser-routing docs, and the release-validation memory.
  • uv/bun are the only package managers. Remove python3-pip from the apt
    baseline; publish only the managed node launcher (npm/npx/corepack no longer
    on PATH); pin uv/bun source tools; bump uv to 0.11.30.
  • Server profile is container-execution-only (was server-build-runtime):
    no host build-essential/pkg-config; project builds/tests run in Docker.
  • One owner per harness (breaking): remove the inline Claude Code, OpenCode,
    MiMoCode, Antigravity, and raw ZCode installers; delegate codex and zcode to
    the nddev-codex-app / nddev-zcode-app modules via RLDYOUR_CODEX_MODULE /
    RLDYOUR_ZCODE_MODULE.
  • Zsh runtime completed: SHA-pinned antidote plugins + zsh-abbr, offline
    static bundle materialization, starship/atuin/carapace pinned standalone
    artifacts (macOS-parity), opt-in reversible login shell; drop the mise shim.
  • Bun selects the x64-baseline artifact on non-AVX2 CPUs.
  • ~/.zshenv.secrets is no longer sourced by every zsh (agent/secret isolation).

1.0.0

Choose a tag to compare

@github-actions github-actions released this 18 Jul 02:27
Immutable release. Only release title and notes can be modified.
0720cc6

First stable release. The module settles its name, reaches a stable adapter
contract, and becomes a first-class GDS module.

Changed

  • Rename the module and adapter identity from new-mac-or-ubuntu to
    macos-ubuntu-bootstrap across the GitHub repository, the adapter contract
    id, the generated GDS anchor, documentation, scripts, templates, tests, and
    managed drop-in markers. Old repository URLs redirect automatically. Machines
    provisioned under the previous marker keep their existing managed blocks
    until they are re-provisioned under the new marker.

Added

  • Onboard the repository as a GDS-managed module: a schema-validated
    .gds/repository.yaml anchor (role module, git-submodule consumption,
    github-release publication) with a bundle-locked compiled policy, while
    preserving the hand-authored AGENTS.md as the source of truth.
  • The GDS control plane consumes this module as a typed git-submodule, so a
    device provisioned through GDS carries the bootstrap.

Stable baseline

  • Plan-first, idempotent bootstrap for Apple Silicon macOS desktops and Ubuntu
    24.04/26.04 desktops and headless servers, with always-explicit profile
    selection.
  • Integrity-pinned AI CLIs, a terminal-first shell (Starship prompt, an
    agent-gated zsh, antidote/atuin/fzf-tab), source and LSP tooling, and a
    hardened loopback-only CloakBrowser runtime with Chrome DevTools MCP and
    Playwright CLI.
  • Owner shell files touched only through delimited, backed-up drop-ins; no
    remote-stream-to-shell execution; fail-closed integrity and browser
    boundaries.
  • CI wired to the pinned nddev-ci-workflows reusable suite: CodeQL, OSSF
    Scorecard, dependency review, secret scan, cross-platform smoke, and
    supply-chain release publication.

0.3.10

Choose a tag to compare

@github-actions github-actions released this 10 Jul 09:04
Immutable release. Only release title and notes can be modified.
0.3.10
0a6b3cc

Fixed

  • Launch Codex through the frozen platform-native binary and isolate package-manager update provenance.

0.3.9

Choose a tag to compare

@github-actions github-actions released this 10 Jul 08:20
Immutable release. Only release title and notes can be modified.
0.3.9
9f8f977

Fixed

  • Harden exact legacy CloakBrowser migration, runtime integrity, launchd convergence, signer verification, and scoped non-interactive cmux hooks.

0.3.8

Choose a tag to compare

@github-actions github-actions released this 10 Jul 07:18
Immutable release. Only release title and notes can be modified.
0.3.8
dead6ab

Fixed

  • Preserve signed unmanaged macOS app bundles during idempotent cask installation.

0.3.7

Choose a tag to compare

@github-actions github-actions released this 10 Jul 05:59
Immutable release. Only release title and notes can be modified.
0.3.7
25e5b7b

Changed

  • Adopt the verified Antigravity CLI 1.1.1 runtime and immutable platform artifacts.

0.3.6

Choose a tag to compare

@github-actions github-actions released this 10 Jul 03:16
Immutable release. Only release title and notes can be modified.
0.3.6
08e5882

Changed

  • Retire Webwright fail-closed and remove its checkout, Python environment,
    dependency lock, and CDP overlay. The compatibility command is now an exact
    tombstone wrapper that exits 78 without starting Python or a browser.
  • Define Playwright CLI and Chrome DevTools MCP as the only active providers,
    both routed through the fixed managed CloakBrowser endpoint.

Security

  • Reject Playwright CLI run-code and --filename escape paths that could
    execute arbitrary code outside the managed CDP configuration.
  • Publish an owner-only canonical browser runtime receipt that binds exact
    content-addressed runtimes, provider binaries, wrappers, service definition,
    source policies, and rigorous live health; add a standalone full verifier.

Fixed

  • Make macOS and Ubuntu strict verification consume the full browser runtime
    integrity verifier instead of accepting command presence or marker matches.

0.3.5

Choose a tag to compare

@github-actions github-actions released this 10 Jul 01:53
Immutable release. Only release title and notes can be modified.
0.3.5
f81c32b

Fixed

  • Restore the standard numeric workflow_dispatch.inputs.version release
    path. Manual dispatch now requires the exact origin/main commit and its
    successful bootstrap-gate, verifies an already existing exact
    non-rewritten tag, and retains the pinned immutable supply-chain publication
    used by numeric tag pushes. Root release automation remains the sole tag
    creator.

0.3.4

Choose a tag to compare

@github-actions github-actions released this 10 Jul 01:22
Immutable release. Only release title and notes can be modified.
0.3.4
f79c352

Fixed

  • Remove the unsupported args input from both pinned
    raven-actions/actionlint workflow steps. The action's default file
    discovery still validates every workflow without emitting GitHub annotation
    warnings, and regression coverage rejects the unsupported input.

0.3.3

Choose a tag to compare

@github-actions github-actions released this 10 Jul 01:05
Immutable release. Only release title and notes can be modified.
0.3.3
2d9de8a

Fixed

  • Replace ambiguous A && B || fallback control flow in macOS target
    validation and Ubuntu GUI gating with explicit conditionals, and reject that
    pattern across all managed shell scripts before hosted ShellCheck runs.