Skip to content

v0.151.70

Choose a tag to compare

@github-actions github-actions released this 01 Oct 08:11
  • Say where every app keeps what it keeps with one word, scope -- session, workspace, tier or host, session by default and each app offering what it can -- so Claude Code and codex are turned on by enable rather than a non-null state (shared is now host, isolated workspace, and a session's own is new for both, with codex a tier's too), Hugging Face's shared becomes a scope that follows the tier's new caches, and a tier may keep what its tools download for each workspace or for all of them under ~/.cache/chase/caches, the XDG cache and data homes and the variables of each tool that keeps its downloads elsewhere named in module.nix beside the CA variables; what is kept on the host at a workspace's or tier's scope is a store, a directory chase makes per tier, binds, fills with its files afresh and points the variables the module names at unless the container sets them, so chase knows nothing of any tool and a consumer's own app can keep one too, and the plugins overlay of a Claude Code that is not the host's is never made for a bare tier, whose refusal would otherwise be flong's missing user rather than chase's (178c4cc)
  • Move each app's machine-wide settings from chase.bindings. to chase.apps., cloudflare's wranglerPackage becoming package and gh and git getting one too, let a tier override any of them under its own apps. (lib/apps.nix's overrides, each defaulting to the machine's value), and make an app read-only and unauthenticated unless a tier says authenticated = true, replacing anonymous: git, github and huggingface hold their credential only then, cloudflare's tier route exists only then while a project's own token keeps the tier's answers (ops.answers), git's credential is github's unless given its own, and every app's unbound credential is refused per tier by name, so the example's trusted says authenticated for git and github and strict says nothing (d3f35c9)
  • Call a grant's per-app section apps rather than bindings, the word the Nix side uses for the machine's own app settings, so chase.jsonc says "apps": { "cloudflare": … }, its refusals name apps.<app>.<field>, a grant still saying bindings is refused with bindings is now apps rather than an unknown field, the app config's envFromBinding becomes envFromGrant, and the jq golden file is written afresh without the entries no test asks for; every checkout's approval is asked again once, as the stored grant it is compared with names the old key (5caf8af)