Repository navigation
Releases: beplus/be
Release list
v0.11.0
@beplus/be now releases the way every @beplus/* library does: one version per commit, built
once, promoted. A merge into dev that bumps the version tags it with a GitHub pre-release and
publishes the tarball to GitHub Packages and then to dev's CodeArtifact, npm.beplus.cloud, where
the estates' builds install be from. That registry had served 0.7.0 as latest since July,
because nothing published be there; a release that installed be after beplus npm auth got
0.7.0's be auto, which picks a Node version, and failed. Fast-forwarding stage publishes the
same bytes to stage's CodeArtifact. Fast-forwarding prod publishes them to prod's CodeArtifact
and turns the GitHub Release into a full release. Fast-forwarding main, the public channel,
publishes them to the public npm registry. dev is the default branch, and scripts/install.sh
installs from main. bin/be itself is unchanged. See docs/releasing.md.
v0.10.0
Make be auto install exactly the beplus CLI version the repository pins, so that a CLI release
cannot change what a deploy runs without a commit in that repository. auto reads
"cli": { "version": "x.y.z" } from the nearest beplus.estate.json, in the current directory or
the closest one above it, and installs that version without consulting the release index. No
manifest, a manifest without a pin, a pin that is not one exact version (2, 2.11, latest,
^2.11.0) or a file that is not valid JSON fails with a message naming the file; nothing falls
back to the newest release, and a manifest further up never stands in for the nearest one. A
leading v and pre-releases are accepted, as everywhere in be. The manifest is read with node,
or with jq where there is no node. be ls-remote auto, be which auto, be run auto and
be exec auto resolve the same pin.
auto no longer reads .n-node-version, .node-version, .nvmrc or engines.node in
package.json, which it inherited from n and which name Node.js versions, not beplus CLI ones.
The help text promised .bepluscloud, .beplus-version and package.json; none of them was ever
read, and beplus.estate.json is now the only place a repository pins its CLI.
v0.9.0
Verify every download against the SHA256SUMS the beplus CLI release publishes beside its
tarballs, and extract only a match. A missing SHA256SUMS, a tarball it does not list or a
mismatch aborts with the URL and extracts nothing; until now a download's integrity rested on TLS
alone. Verifying uses sha256sum, or shasum where there is none. Both line forms the releases
use are read: <hash> <name> from 2.x on, and v1.0.5's <name>: <hash>.
Detect the installed version by comparing $BE_PREFIX/bin/beplus with the downloads it was copied
from. With a 2.x CLI detection always came up empty, so be prune deleted the installed version
along with the rest.
Stop be uninstall at end of input, deleting nothing, as if answered no. It used to ask again for
ever.
Always download the .tar.gz. From major 4 on, be asked for a .tar.xz, which the beplus CLI
release does not publish; --use-xz, --no-use-xz and BE_USE_XZ are gone with it.
v0.8.0
Bump the version to v0.8.0 + update CHANGELOG Sync package-lock.json with bin/bump, point [Unreleased] at v0.8.0...main, and date the v0.8.0 section for the day it is actually released. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>