v1.4.1
What's New in v1.4.1
Security & Reliability
- JSON input validation for
users createandusers updatecommands (prevents injection) - GPG key fingerprint pinning prevents MITM attacks during client updates
- Read timeouts for interactive prompts (60s for prompts, 300s for API key input)
- Retry logic with exponential backoff for transient API failures (429, 5xx)
Improvements
- XDG Base Directory compliance - respects
$XDG_CONFIG_HOME - Man page documentation (
yatti-api.1) - updated for v1.4.1 - 63 new tests (251 total) covering edge cases, security, and reliability
- Optimized jq calls for better performance
- Installer now installs man page and bash completion automatically
Bug Fixes
- Fixed SC2030 bug:
temp_filewas assigned in subshell and lost - Fixed duplicate
script_dirvariable declaration incmd_update() - Fixed jq exit status causing failure when contexts array is missing in verbose mode
New Environment Variables
YATTI_MAX_RETRIES- Max retry attempts (default: 3)YATTI_TIMEOUT- Request timeout in seconds (default: 60)YATTI_CONNECT_TIMEOUT- Connection timeout in seconds (default: 10)
Full Changelog: v1.4.0...v1.4.1