Skip to content

walkerOS v4.6.0

Choose a tag to compare

@github-actions github-actions released this 10 Sep 09:19
· 112 commits to main since this release
64d77db

Changes

The Firehose destination no longer discards every config field except settings
during init, which silently dropped before, consent, mapping, data and
next. A before transformer chain configured on the destination never ran,
and a consent requirement was never enforced. The SNS destination in the same
package was already correct.

The BigQuery destination no longer applies config.timeout as a deadline on the
Storage Write API append stream, which killed healthy connections roughly every
ten seconds and caused reconnect churn, latency spikes, and intermittent 5xx
responses. Error logs now show the error's message, name and status code in CLI
output, and no longer include event payloads.

Bot detection now names nine more uptime and synthetic monitoring services,
including Uptrends, Site24x7, Datadog Synthetics, New Relic Synthetics and
Better Stack. Their requests report as monitor with the product name instead
of generic automation, and several that previously passed as human traffic are
now flagged.

fetchHealth and compareContract accept an optional base URL, so a caller
that is not the local CLI can probe its own backend instead of the one resolved
from WALKEROS_APP_URL and the CLI config file. Omitting it keeps today's
resolution.
diagnostics passes the app URL it reports, so the contract verdict and
appUrl.resolved always describe the same backend. A hosted MCP no longer
probes production while naming its own deployment.

The dataLayer source now stamps every event it captures with its own identity,
so events arrive carrying source.type: 'dataLayer' and
source.platform: 'web' instead of defaulting to the collector. Destinations
that echo events back into the dataLayer can now guard against feedback loops,
and mappings can tell dataLayer-captured events apart.

diagnostics reports the app URL the tool client actually talks to, so a hosted
MCP names its own deployment instead of the local CLI's default.
ToolClient gains a required appBaseUrl() method returning that base without
a trailing slash, so a custom implementation of that interface must add it.

Tools now hand back an appUrl link to the screen they are talking about.
flow_manage get and create link the flow page, deploy_manage deploy and get
link the deployment, and hub_manage releases, threads and step history link
the release history or the step. Links are absolute, built from the base URL the
connected door reports, and omitted rather than guessed when the address cannot
be built. deploy_manage deploy now also passes an explicit projectId through
to the deploy itself, so it no longer deploys into the default project when one
was named.

The MCP server carries hub_manage, which reads a flow's release history, its
rationale and the threads on it, and a read-only frame_manage, which reads the
frames of a measurement plan. The CLI gains the matching programmatic calls.
ToolClient gains eleven required methods, so a custom implementation of that
interface must add them.

A tool call with no project now names how to fix it, instead of stating that a
project is missing and stopping there. Five more flow_manage actions
(update, delete, duplicate, preview_get, preview_delete) resolve the
selected project first, so they no longer fail with a raw server error when
projectId is omitted.

walkeros auth login now uses the standard device authorization grant and
refreshes its session automatically. Existing tokens keep working until they
expire; run walkeros auth login once to switch.
Breaking: getAuthHeaders is async, and it rejects when the session needs a
refresh that cannot be carried out rather than quietly returning no header.
createApiClient no longer throws when unauthenticated, the request it makes
does. Removed exports: getToken, requestDeviceCode, pollForToken, and the
DeviceCodeResult, DeviceCodeOptions, PollOptions and PollResult types;
startDeviceAuthorization and completeDeviceLogin replace the last two.

The auth tool logs in through the standard device authorization grant and
keeps the session refreshed.
Breaking, for anyone implementing ToolClient: resolveToken is replaced by
credentialSource, deleteConfig by an async logout that revokes the session
before dropping it, and requestDeviceCode/pollForToken return the CLI's
device authorization types.

Published Packages