Skip to content

v0.7.0

Latest

Choose a tag to compare

@github-actions github-actions released this 06 Oct 01:35
· 1012 commits to main since this release
9eb88ca

nvx 0.7.0 is the first signed release. nvx.exe carries an Authenticode signature from a Certum certificate issued to "Open Source Developer Felix Stubner". SmartScreen may still warn on the first downloads while the certificate builds a reputation.

Install

irm https://raw.githubusercontent.com/fstubner/nvx/v0.7.0/install.ps1 | iex
curl -fsSL https://raw.githubusercontent.com/fstubner/nvx/v0.7.0/install.sh | sh
npm install -g @fstubner/nvx

The npm package installs the binary for your platform and runs no install script.

Highlights

Installs

  • pnpm installs inside the Windows sandbox, the first time and every time after.
  • bun's package manager cannot run in the Windows sandbox outside the drive Windows is installed on. That is a bun limitation, and nvx now names the cause after the failure.
  • The pre-install checks run on every package an npm install brings in, and a lockfile entry must match the registry's record of it.
  • Packages from a private registry are checked on that registry, and contained installs work behind a corporate proxy.
  • The typosquat check runs only on names you chose, and a command that already turns install scripts off is not asked about them.

Containment

  • On macOS a contained install can no longer read your credential files.
  • On macOS a contained install can write only to the project, its own home and a few device files such as /dev/null. It can no longer write the system temp folders or other apps' caches.
  • A contained install can no longer write the project's .git.
  • On Linux a contained process can no longer reach the host's UNIX sockets, and killing nvx stops the contained process.

Setup and shells

  • nvx setup takes seconds instead of minutes on a large drive, and covers every fixed drive in one run.
  • fish and cmd.exe are supported shells.
  • NVX_NODE_MIRROR fetches Node.js from a mirror.
  • The shims run the version a project pins, with or without the shell hook.

Policy and audit

  • A global policy can be a baseline that a project cannot weaken.
  • New commands: nvx policy explain, nvx policy check and nvx audit export.

Releases carry SHA-256 checksums and a build-provenance attestation as before. gh attestation verify nvx.exe --repo fstubner/nvx checks a download (GitHub CLI 2.49 or newer).

The full list, over a hundred changes, is in the changelog.