Releases: HugoRCD/shelve
Release list
Shelve v3.4.0
Minor Changes
- #765
903908fThanks @voidhrithik! - Add projects to the command palette so you can search and jump to any project across your teams.
Patch Changes
@shelve/cli@5.3.0
Minor Changes
-
#766
ff8d85fThanks @voidhrithik! - From a monorepo root,push,pull,diffandsyncnow run once per package that has its ownshelve.json, and--path <dir>targets a single one. Rootshelve.jsonsettings reach sub-packages instead of being dropped, thoughprojectstays per-package.Three things that were quietly broken now behave:
autoCreateProject: falsestops project creation even under--yes,diffno longer writes an empty env file or creates projects, andshelve runfalls back to its encrypted cache when the API call fails instead of exiting.Errors in
--jsonmode now print the documented envelope on stderr rather than a stack trace. When a package fails partway through a fan-out, the error names it and lists the packages that already finished, in the prose hint and inerror.context.
Shelve v3.3.0
Minor Changes
-
#754
f247f0cThanks @HugoRCD! - Improve audit log UX with enriched API responses, timeline UI, expanded event coverage, and human-readable token scope labels. -
#756
13840b5Thanks @HugoRCD! - Add browser-based device login for the CLI (shelve loginopens Shelve to approve; auto-creates a revocable CLI API token). KeepsSHELVE_TOKEN,--token, and--with-tokenfor CI and manual tokens. Login and authorize pages show CLI-specific messaging when redirecting from the device flow.
@shelve/cli@5.2.0
Minor Changes
- #756
13840b5Thanks @HugoRCD! - Add browser-based device login for the CLI (shelve loginopens Shelve to approve; auto-creates a revocable CLI API token). KeepsSHELVE_TOKEN,--token, and--with-tokenfor CI and manual tokens. Login and authorize pages show CLI-specific messaging when redirecting from the device flow.
Shelve v3.2.0
Shelve v3.1.0
What's Changed
Features 🚀
- feat(lp): add vercel self-hosting docs by @HugoRCD in #606
- feat(app): add otp auth method by @HugoRCD in #609
- feat(lp): add terms and privacy notice by @HugoRCD in #610
- feat(apps): make vault app agnostic by @HugoRCD in #617
- feat(app): upgrade
nuxtand@nuxt/uiby @HugoRCD in #632 - feat(app): add bot-id protection by @HugoRCD in #670
- feat: auto-redirect single-team users by @onmax in #685
- feat(docs): use docus by @HugoRCD in #705
- feat(app): add groups and description for env var by @HugoRCD in #724
- feat(app): improve variable creation form UX by @HugoRCD in #725
- feat(lp): showcase v5 security surface on the landing page by @HugoRCD in #738
- feat(app): expose full token scoping + polish audit logs UI by @HugoRCD in #739
Bug Fixes 🐞
- fix: apply Turborepo best practices by @anthonyshew in #683
- fix(cli): allow global commands without package.json by @onmax in #684
- fix: prevent PGlite deadlock in team creation by @onmax in #687
- fix: broken css and invalid border class by @onmax in #688
- fix(app): use request origin for invitation email URL instead of undefined config by @fmazmz in #716
- fix(app): align welcomeEmail props with EmailService by @HugoRCD in #729
- fix(cli): switch
shelve runto spawn + process-group signal handling by @HugoRCD in #730 - fix(changeset): retarget LP changesets to @shelve/lp by @HugoRCD in #740
- fix(cli): credentials written in the wrong path by @HugoRCD in #745
Documentation 📚
Tests 🧪
- test: add unit and E2E testing infrastructure by @HugoRCD in #721
- test(app): add cli push and pull e2e integration tests by @HugoRCD in #722
- test(cli): cover offline cache, credentials, secret refs, ignore files by @HugoRCD in #734
- test(app): cover tokens, scopes, bearer auth, and audit logs by @HugoRCD in #735
Refactoring 🛠
- refactor(app): improve members table and date across the app by @HugoRCD in #607
- refactor(app): improve navigation by @HugoRCD in #608
- refactor(app): update auth middleware by @HugoRCD in #666
Dependency Updates 📦
- chore(changeset): drop no-op LP changesets by @HugoRCD in #742
- chore(deps): update all non-major dependencies by @renovate[bot] in #743
- chore: upgrade pnpm to v11 and add minimumReleaseAge by @HugoRCD in #744
New Contributors
- @moshetanzer made their first contribution in #661
- @anthonyshew made their first contribution in #683
- @onmax made their first contribution in #684
- @fmazmz made their first contribution in #716
- @github-actions[bot] made their first contribution in #726
Full Changelog: v2.3.3...v3.1.0
@shelve/cli@5.1.0
Minor Changes
-
#751
f9a0848Thanks @HugoRCD! - Add agent-friendly global flags (--json,--quiet,--yes,--non-interactive), structured JSON errors on stderr, non-interactive guards across all commands, and machine-readable output for query commands. Addsshelve doctor,runspawn JSON events, GitHub Action, CI playground smoke tests, LP skills manifest check, troubleshooting docs,shelve-appagent skill, and llms.txt skill links. Includeslogin --token,generate --type, HTTP debug logging, fixes silent fetch failures inshelve run, full CLI documentation on shelve.cloud, and a Docus-published agent skill at/.well-known/skills/. -
#752
787cf07Thanks @HugoRCD! - Add sync policies for push/pull conflict handling,shelve diffandshelve sync, server-side protected environments on projects, and consolidate published agent skills into a single comprehensiveshelveskill (removeshelve-app).
Patch Changes
-
#749
e64d2ecThanks @HugoRCD! - Add a self-containedplayground/run/fixture and rootpnpm playscripts so the fullshelve runflow can be exercised end-to-end without leaving the repo, hitting the production API, or running the Shelve app.- A tiny zero-dep
node:httpfake Shelve API (server.mjs) seeded with a team / project / 3 environments / variables / a fake token (seed.json). Implements the four endpointsshelve runcalls. - An orchestrator (
start.mjs) that boots the server, waits for/health, then spawns the locally-stubbed CLI with the rightSHELVE_*env vars injected and tears the server down on exit / Ctrl-C. - Root scripts:
pnpm play(=shelve run dev),pnpm play:start,pnpm play:fail,pnpm play:watch,pnpm play:server(server only). Each runspnpm -C packages/cli stubfirst so edits inpackages/cli/src/**are picked up without a rebuild. - Two admin endpoints (
POST /__playground/variables,POST /__playground/reset) let you trigger watch-mode reloads from another terminal with a single curl. - Not part of the pnpm workspace —
pnpm installignores it, no host-project lockfile drift can swallow output.
Also fixes several long-standing
shelve runcorrectness and cross-platform bugs the playground surfaced:- CLI orphaned its own child.
runMain(main).then(() => process.exit(0))resolved as soon as theruncommand function returned (right after spawn), killing the CLI before the child had done anything. Withstdio: 'inherit'the orphaned child kept writing to the terminal so it looked fine, but signal forwarding, watch mode and exit-code propagation were all broken. Fix: theruncommand awaits a never-resolving promise;child.on('exit')is now the only path toprocess.exit. --watch --restart-on-changekilled the CLI on the first reload. Killing the old child fired its exit handler which calledprocess.exit(143)before the new child could spawn. Fix: mark the outgoing child with__restartingso its exit handler is a no-op while watch is swapping in a replacement.- Signal handler leak in watch mode. Each respawn registered fresh
process.on(SIGINT|TERM|HUP)listeners. After 10 reloads Node warned. Fix: register process-level signal handlers exactly once and have them target the current child via a module-level ref. process.kill(-pid, …)doesn't work on Windows. Replaced everywhere withtree-kill, which usestaskkill /F /Ton Windows and process-group kill on Unix. Droppeddetached: trueon spawn — no longer needed for cleanup and was what made the CLI missSIGHUPwhen the terminal closed.- Package-manager shims (
pnpm.cmd,npm.cmd,yarn.cmd) didn't spawn on Windows. Node'sspawndoesn't resolve.cmdwithout a shell. Now usesshell: trueon Windows (the shim chain is killed correctly thanks totree-kill). - Parent-death watchdog. Both the CLI's
runcommand and the playground orchestrator poll their originalppidwithprocess.kill(ppid, 0)every 2s. If the parent disappears (terminal force-quit, parent SIGKILL'd, Cursor crashed, …), the child tears down its own subtree instead of running orphaned forever and spammingsetRawMode EIOinto whatever terminal it ended up attached to. - Suspiciously-fast exit warning. If a spawned child exits cleanly in <250ms (probably script-resolution went wrong), the CLI now prints a warning pointing at
--debugandshelve run -- <pm> <script>to bypass script resolution. Script-resolution errors are debug-logged instead of swallowed.
Smoke-tested all variants — SIGINT, terminal SIGHUP, parent
kill -9, watch+restart, failing exit codes — on macOS. No orphans, ports always released, exit codes always propagated. - A tiny zero-dep
@shelve/cli@5.0.3
@shelve/cli@5.0.2
v2.3.3
What's Changed
Breaking Changes 💥
Features 🚀
- feat(apps): add vercel speed insights by @HugoRCD in #597
- feat(apps): remove live stats by @HugoRCD in #598
Refactoring 🛠
- refactor(app): improve integrations view by @HugoRCD in #605
- refactor: improve
.envparsing by @HugoRCD in #595
Full Changelog: v2.3.2...v2.3.3