Repository navigation
Releases: ewanc26/metalbear
Release list
v0.44.0
This is the first signed release. An earlier tag and release of this number, and a 0.44.1, were withdrawn: the release workflow had a mistake of mine that stopped it publishing, and the repaired one is what built this.
Changed
-
Wolfram is pinned to v0.28.0 (was v0.26.0). (#82)
-
Releases are signed, and the updater refuses an unsigned one or one signed by any other key. The private key is only the
RELEASE_SIGNING_KEYsecret; the public half is inpdsadmin/release-signersand built intometalbear-update.sh. The release workflow now fails rather than publish unsigned, and checks its own signature first. Releases up to v0.43.0 are unsigned, so installing one needsALLOW_UNSIGNED=1. (#55)
Added
- Every database now records a schema version, and MetalBear refuses to open one written by a newer build instead of migrating it blindly. Existing databases are stamped as version 1 on first start. It only protects a rollback to a build that has this check, so it starts helping with the release after this one. (#79)
Container image
docker pull ghcr.io/ewanc26/metalbear:0.44.0| Tag | Digest | Platforms |
|---|---|---|
0.44.0-alpine |
sha256:a59f2466e43bada183217497af26bb8f7b41a1c783d76b95973d746b2a0b8971 |
linux/amd64,linux/arm64,linux/arm/v7 |
0.44.0 |
sha256:f74997238437d6ab5e4023c3a58a1e266def090a3da984406ba2cd506915236d |
linux/amd64,linux/arm64 |
0.44.0-dev |
sha256:00e0098ce3ac34fec4a28c4e11a2346f37f70b3c019ec3e28a348334172be5d6 |
linux/amd64,linux/arm64 |
There is no image for the Raspberry Pi 1B or Zero (ARMv6): build from
source with the minimal profile, see docs/pi1-hardware-validation.md.
The Alpine image's linux/arm/v7 covers 32-bit ARMv7 boards only.
Binaries
Prebuilt for Linux (x86_64, aarch64) and macOS (arm64). Each archive
holds the binary, the lexicon corpus records are validated against,
an example configuration, and a note on the runtime libraries it
expects. SHA256SUMS covers every archive and is what
pdsadmin/metalbear-update.sh checks. There is no Intel macOS build.
MetalBear does not terminate TLS: bind it to loopback and put a
reverse proxy in front, forwarding WebSocket upgrades.
What's Changed
- test(build): build module-specific tests only when their module is on by @ewanc26 in #78
- feat(storage): record a schema version in every database and refuse newer ones by @ewanc26 in #79
- ci(flow): fail on live repository metadata drift by @ewanc26 in #80
- feat(update): refuse an unsigned release or one signed by another key by @ewanc26 in #81
- build(wolfram): pin Wolfram v0.28.0 by @ewanc26 in #82
- docs(changelog): one Changed heading under Unreleased by @ewanc26 in #83
- chore(version): bump to 0.44.0 by @ewanc26 in #84
- fix(ci): repair release.yml, whose signing edit duplicated 336 lines by @ewanc26 in #85
- docs(changelog): say v0.44.0 was tagged but not published by @ewanc26 in #86
- chore(version): bump to 0.44.1 by @ewanc26 in #87
- refactor(main): remove five helpers nothing calls by @ewanc26 in #88
- fix(release): make the tree say 0.44.0 again, with 0.44.1 withdrawn by @ewanc26 in #90
Full Changelog: v0.43.0...v0.44.0
v0.43.0
Added
- I can update a prebuilt install from these releases with
pdsadmin/metalbear-update.sh: it checks the SHA-256 (and a signature, once I have a signing key), snapshots the databases, installs, and rolls back if the health check fails. It does nothing unless asked. See docs/updating.md. (#57) - Releases now carry a
SHA256SUMSfile, which is what the updater reads. (#57)
Changed
- The admin app's icons were Expo's placeholder. They are the bear now, drawn from
docs/logo.svgbytools/gen_icons.pyin the house green, and the web favicon uses the same green. (#65) - Container images are tagged with the exact version, the minor and, for the newest stable release only,
latest. A published version tag is never moved, and each release's notes list the image digests and lead with its CHANGELOG section. The README says how to upgrade a container. (#63) - Wolfram is pinned to v0.26.0. (#49)
- OAuth scopes are stricter: an
rpc:method or arepo:collection has to be a real NSID now, checked by Wolfram's validator, sorpc:foo.barno longer parses. AT-URIs given to the admin takedown routes are parsed by Wolfram too. (#59) - A release tag is refused unless it matches the version in
CMakeLists.txt, sits onmainand passed CI. Releases are cut withtools/release.sh. (#52)
Fixed
- The minimal build profile, the one meant for a Raspberry Pi 1B or Zero, did not compile. It does now, and CI builds it, runs the Pi checklist's tests against it and checks that the 64-bit atomics compile for ARMv6Z without libatomic. None of that has run on a Pi yet. (#66)
- The README said there were four DNS providers in one place and three in another. There are four. (#50)
Container image
docker pull ghcr.io/ewanc26/metalbear:0.43.0| Tag | Digest | Platforms |
|---|---|---|
0.43.0-alpine |
sha256:43c01e9cd21e316adfc9f7724f8e0fedbb00e3407a60bce848b6eb53f7e98dfc |
linux/amd64,linux/arm64,linux/arm/v7 |
0.43.0 |
sha256:e08a5f351f45393e9b492f4821e08d1ad07b5e2502581627bd63cc1316503edb |
linux/amd64,linux/arm64 |
0.43.0-dev |
sha256:9c74c5133f42580a512544b2d934a10c7a13a5e1e174bbba7d08856b045d85e9 |
linux/amd64,linux/arm64 |
There is no image for the Raspberry Pi 1B or Zero (ARMv6): build from
source with the minimal profile, see docs/pi1-hardware-validation.md.
The Alpine image's linux/arm/v7 covers 32-bit ARMv7 boards only.
Binaries
Prebuilt for Linux (x86_64, aarch64) and macOS (arm64). Each archive
holds the binary, the lexicon corpus records are validated against,
an example configuration, and a note on the runtime libraries it
expects. SHA256SUMS covers every archive and is what
pdsadmin/metalbear-update.sh checks. There is no Intel macOS build.
MetalBear does not terminate TLS: bind it to loopback and put a
reverse proxy in front, forwarding WebSocket upgrades.
What's Changed
- chore: bump Wolfram to v0.26.0 by @ewanc26 in #49
- docs(dns): four providers, not three by @ewanc26 in #50
- ci: enforce the PR flow with flow-check, drift-check and a single gate by @ewanc26 in #51
- ci(release): gate releases on verify, and add tools/release.sh by @ewanc26 in #52
- ci(flow): merge with rebase only, and reject merge commits in a PR by @ewanc26 in #53
- feat(update): opt-in updater with checksum, backup and automatic rollback by @ewanc26 in #57
- ci(flow): adopt Wolfram's reusable flow checks and canonical flow block by @ewanc26 in #58
- refactor(syntax): use Wolfram's NSID and AT-URI validators by @ewanc26 in #59
- docs(changelog): start CHANGELOG.md, and have release.sh roll it into each version by @ewanc26 in #60
- feat(release): container tags, digests in the notes, and a pull-and-run check by @ewanc26 in #63
- fix(build): make the minimal profile (Pi 1B/Zero) compile, and check it and ARMv6Z atomics in CI by @ewanc26 in #66
- docs(readme): house style order, and admin app icons drawn from the bear by @ewanc26 in #67
- docs(spaces): note where AT Protocol Spaces would land, ahead of the gate by @ewanc26 in #68
- fix(release): fall back to the REST API when a tag push is refused by @ewanc26 in #69
- chore(version): bump to 0.43.0 by @ewanc26 in #70
- ci(flow): sync the flow block and adopt Wolfram's issue forms by @ewanc26 in #74
- ci(release): release by dispatch from main, tagging with GITHUB_TOKEN by @ewanc26 in #75
- fix(release): read the repo slug from the remote, not from GraphQL by @ewanc26 in #76
- fix(ci): let verify push the tag on a dispatch release by @ewanc26 in #77
Full Changelog: v0.42.3...v0.43.0
v0.42.3
Container image
docker pull ghcr.io/ewanc26/metalbear:0.42.3Built for linux/amd64 and linux/arm64.
Binaries
Prebuilt for Linux (x86_64, aarch64) and macOS (arm64). Each
archive contains the binary, the lexicon corpus records are
validated against, an example configuration, and the runtime
libraries it expects. Verify with the accompanying .sha256.
There is no Intel macOS build: GitHub's last x86_64 macOS runner is
being retired. Build from source on an Intel Mac.
MetalBear does not terminate TLS: bind it to loopback and put a
reverse proxy in front, forwarding WebSocket upgrades.
What's Changed
Full Changelog: v0.42.2...v0.42.3
v0.42.2
Container image
docker pull ghcr.io/ewanc26/metalbear:0.42.2Built for linux/amd64 and linux/arm64.
Binaries
Prebuilt for Linux (x86_64, aarch64) and macOS (arm64). Each
archive contains the binary, the lexicon corpus records are
validated against, an example configuration, and the runtime
libraries it expects. Verify with the accompanying .sha256.
There is no Intel macOS build: GitHub's last x86_64 macOS runner is
being retired. Build from source on an Intel Mac.
MetalBear does not terminate TLS: bind it to loopback and put a
reverse proxy in front, forwarding WebSocket upgrades.
What's Changed
- docs(pi1): add hardware validation checklist by @ewanc26 in #45
- docs: tailor contributor and agent guidance by @ewanc26 in #46
Full Changelog: v0.42.1...v0.42.2
v0.42.1
Container image
docker pull ghcr.io/ewanc26/metalbear:0.42.1Built for linux/amd64 and linux/arm64.
Binaries
Prebuilt for Linux (x86_64, aarch64) and macOS (arm64). Each
archive contains the binary, the lexicon corpus records are
validated against, an example configuration, and the runtime
libraries it expects. Verify with the accompanying .sha256.
There is no Intel macOS build: GitHub's last x86_64 macOS runner is
being retired. Build from source on an Intel Mac.
MetalBear does not terminate TLS: bind it to loopback and put a
reverse proxy in front, forwarding WebSocket upgrades.
Full Changelog: v0.42.0...v0.42.1
v0.42.0
Container image
docker pull ghcr.io/ewanc26/metalbear:0.42.0Built for linux/amd64 and linux/arm64.
Binaries
Prebuilt for Linux (x86_64, aarch64) and macOS (arm64). Each
archive contains the binary, the lexicon corpus records are
validated against, an example configuration, and the runtime
libraries it expects. Verify with the accompanying .sha256.
There is no Intel macOS build: GitHub's last x86_64 macOS runner is
being retired. Build from source on an Intel Mac.
MetalBear does not terminate TLS: bind it to loopback and put a
reverse proxy in front, forwarding WebSocket upgrades.
Full Changelog: v0.41.0...v0.42.0
v0.41.0
Container image
docker pull ghcr.io/ewanc26/metalbear:0.41.0Built for linux/amd64 and linux/arm64.
Binaries
Prebuilt for Linux (x86_64, aarch64) and macOS (arm64). Each
archive contains the binary, the lexicon corpus records are
validated against, an example configuration, and the runtime
libraries it expects. Verify with the accompanying .sha256.
There is no Intel macOS build: GitHub's last x86_64 macOS runner is
being retired. Build from source on an Intel Mac.
MetalBear does not terminate TLS: bind it to loopback and put a
reverse proxy in front, forwarding WebSocket upgrades.
Full Changelog: v0.40.0...v0.41.0
v0.40.0
Container image
docker pull ghcr.io/ewanc26/metalbear:0.40.0Built for linux/amd64 and linux/arm64.
Binaries
Prebuilt for Linux (x86_64, aarch64) and macOS (arm64). Each
archive contains the binary, the lexicon corpus records are
validated against, an example configuration, and the runtime
libraries it expects. Verify with the accompanying .sha256.
There is no Intel macOS build: GitHub's last x86_64 macOS runner is
being retired. Build from source on an Intel Mac.
MetalBear does not terminate TLS: bind it to loopback and put a
reverse proxy in front, forwarding WebSocket upgrades.
What's Changed
- feat(blob-store): keep file-backed payloads on disk by @ewanc26 in #31
- fix(video): align limits and project metadata with current code by @ewanc26 in #35
- feat(video): add durable multipart uploads by @ewanc26 in #37
- perf(account): bound resident account contexts by @ewanc26 in #38
Full Changelog: v0.39.1...v0.40.0
v0.39.1
Container image
docker pull ghcr.io/ewanc26/metalbear:0.39.1Built for linux/amd64 and linux/arm64.
Binaries
Prebuilt for Linux (x86_64, aarch64) and macOS (arm64). Each
archive contains the binary, the lexicon corpus records are
validated against, an example configuration, and the runtime
libraries it expects. Verify with the accompanying .sha256.
There is no Intel macOS build: GitHub's last x86_64 macOS runner is
being retired. Build from source on an Intel Mac.
MetalBear does not terminate TLS: bind it to loopback and put a
reverse proxy in front, forwarding WebSocket upgrades.
Full Changelog: v0.39.0...v0.39.1
v0.39.0
Container image
docker pull ghcr.io/ewanc26/metalbear:0.39.0Built for linux/amd64 and linux/arm64.
Binaries
Prebuilt for Linux (x86_64, aarch64) and macOS (arm64). Each
archive contains the binary, the lexicon corpus records are
validated against, an example configuration, and the runtime
libraries it expects. Verify with the accompanying .sha256.
There is no Intel macOS build: GitHub's last x86_64 macOS runner is
being retired. Build from source on an Intel Mac.
MetalBear does not terminate TLS: bind it to loopback and put a
reverse proxy in front, forwarding WebSocket upgrades.
Full Changelog: v0.38.2...v0.39.0