Skip to content

Blacksmith v0.3.0

Choose a tag to compare

@github-actions github-actions released this 13 Sep 01:36
· 93 commits to main since this release
6a817a5

Blacksmith v0.3.0 — Trust boundary & automation hardening

Security and install-reliability release after the audit-driven Now/Next slice (N1–N5, X1–X4).

Highlights

Trust & supply chain

  • Removed shell=True from Windows package-manager and uninstall pip paths
  • Package ID / search query allowlists (fail closed)
  • Custom --file trust warning + --yes / --dry-run
  • Hard CI gates (trust boundary, tests, pip-audit on requirements.lock, Bandit)
  • PyPI publish via Trusted Publishing (OIDC; environment release)

Install honesty & automation

  • Per-package install/update outcomes (no all-or-nothing batch bool)
  • --fail-fast optional; default best-effort continue
  • Non-interactive sessions require --yes or --dry-run (TTY fail-closed)
  • Dry-run prints action plan: package, manager, id, action
  • Flatpak remains a first-class Linux PM; sudo warning only for apt/pacman/yum/snap
  • Snap/Flatpak search documented as not implemented yet

Tooling

  • GitHub Actions bumped to Node 24 runtimes
  • Safe uninstall path deletes (no shell-interpolated cleanup scripts)

Install / upgrade

pip install --upgrade jdi-blacksmith
# or
pip install jdi-blacksmith==0.3.0

Notes for operators

  • CI/scripts: use blacksmith install … --yes (or --dry-run)
  • After verifying this release published via OIDC, delete any leftover PYPI_API_TOKEN repo secret
  • Community-shared set YAML is still not fully “safe to recommend” until Later items (esp. signed sets / threat-model doc) land — see roadmap Definition of done

Full changelog

Includes merges: PR #1, #7, #8, #9, #10, #11 (and related fixes on main since v0.2.3).