Release 33.5
What's new
- Added
cronitor connectand integration-management commands for configuring notification integrations. - Hardened credential handling: configuration output and verbose environment reporting no longer print API keys or unrelated environment secrets, and signup persistence errors no longer include returned keys.
- Centralized configuration persistence with atomic writes and platform-specific access handling.
- Added
cronitor configure --restrictand safe warnings when configuration cannot be read.
Configuration permissions
New configuration files are owner-only. Jobs running as another user need credentials in their environment or a configuration file they can access.
Existing files retain their configured access on Linux, macOS, and Windows during ordinary saves; existing world-readable files are not automatically tightened. Use cronitor configure --restrict deliberately, after arranging credentials for jobs running as other users.
FreeBSD builds are included, but its ACL preservation and restriction are not implemented or runtime-verified. Do not rely on this release to preserve ACL-based sharing on FreeBSD.
Credential flags remain supported for compatibility, but environment-based injection avoids exposing values in command arguments and process listings.