2.5.0 - 2026-09-03
Release Notes
Added
- Export a
ValuesReportTypeScript type for consumers of CLI--view values
output.
Changed
- Change the project license from MIT to Apache-2.0. Previously published
releases remain available under the license included with those releases. - Include
LICENSEand copyrightNOTICEfiles in the npm packages, native
release archives, and installable agent skill.
Fixed
- Align TypeScript source-kind types and the report JSON Schema with the
runtime output, including compact CLI reports. - Verify published npm artifacts without false missing-file errors from
shell pipeline handling.
Security
- Update the transitive development dependency
fast-urifrom 3.1.5 to 3.1.7
to address URI normalization advisories reported by the release audit.
Install deckprobe 2.5.0
Install prebuilt binaries via shell script
curl --proto '=https' --tlsv1.2 -LsSf https://github.com/deckflow/deckprobe/releases/download/v2.5.0/deckprobe-installer.sh | shInstall prebuilt binaries via powershell script
powershell -ExecutionPolicy Bypass -c "irm https://github.com/deckflow/deckprobe/releases/download/v2.5.0/deckprobe-installer.ps1 | iex"Download deckprobe 2.5.0
| File | Platform | Checksum |
|---|---|---|
| deckprobe-aarch64-apple-darwin.tar.gz | Apple Silicon macOS | checksum |
| deckprobe-x86_64-apple-darwin.tar.gz | Intel macOS | checksum |
| deckprobe-x86_64-pc-windows-msvc.zip | x64 Windows | checksum |
| deckprobe-aarch64-unknown-linux-gnu.tar.gz | ARM64 Linux | checksum |
| deckprobe-x86_64-unknown-linux-gnu.tar.gz | x64 Linux | checksum |
| deckprobe-aarch64-unknown-linux-musl.tar.gz | ARM64 MUSL Linux | checksum |
| deckprobe-x86_64-unknown-linux-musl.tar.gz | x64 MUSL Linux | checksum |
Verifying GitHub Artifact Attestations
The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:
gh attestation verify <file-path of downloaded artifact> --repo deckflow/deckprobeYou can also download the attestation from GitHub and verify against that directly:
gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation>