Blacksmith v0.3.0
Blacksmith v0.3.0 — Trust boundary & automation hardening
Security and install-reliability release after the audit-driven Now/Next slice (N1–N5, X1–X4).
Highlights
Trust & supply chain
- Removed
shell=Truefrom Windows package-manager and uninstall pip paths - Package ID / search query allowlists (fail closed)
- Custom
--filetrust warning +--yes/--dry-run - Hard CI gates (trust boundary, tests,
pip-auditonrequirements.lock, Bandit) - PyPI publish via Trusted Publishing (OIDC; environment
release)
Install honesty & automation
- Per-package install/update outcomes (no all-or-nothing batch bool)
--fail-fastoptional; default best-effort continue- Non-interactive sessions require
--yesor--dry-run(TTY fail-closed) - Dry-run prints action plan: package, manager, id, action
- Flatpak remains a first-class Linux PM; sudo warning only for apt/pacman/yum/snap
- Snap/Flatpak search documented as not implemented yet
Tooling
- GitHub Actions bumped to Node 24 runtimes
- Safe uninstall path deletes (no shell-interpolated cleanup scripts)
Install / upgrade
pip install --upgrade jdi-blacksmith
# or
pip install jdi-blacksmith==0.3.0Notes for operators
- CI/scripts: use
blacksmith install … --yes(or--dry-run) - After verifying this release published via OIDC, delete any leftover
PYPI_API_TOKENrepo secret - Community-shared set YAML is still not fully “safe to recommend” until Later items (esp. signed sets / threat-model doc) land — see roadmap Definition of done
Full changelog
Includes merges: PR #1, #7, #8, #9, #10, #11 (and related fixes on main since v0.2.3).