Repository navigation
Releases: krameff/syver
Release list
v0.15.0
Changelog
- c827a45 Merge devel into docs/agent-sandbox-profile
- 1cbbf0a Merge pull request #71 from krameff/docs/0.14.0-shipped
- b19712d Merge pull request #72 from krameff/fix/dgoss-syver-yaml
- 0d9f8d1 Merge pull request #73 from krameff/deps/go-1.27
- 534fc34 Merge pull request #74 from krameff/feature/sbxsyver
- 6d3563a Merge pull request #75 from krameff/docs/agent-sandbox-profile
- 75adae7 Merge pull request #76 from krameff/docs/0.15.0-pending
- 7cf8f51 Merge pull request #77 from krameff/devel
- 2ecf581 build: Go 1.27.1 and golangci-lint v2.14.0
- b6bb2d7 ci: yamllint ignores the agent sandbox profile template
- 244f5fc ci: yamllint ignores the sbx profile template, release regenerates sbxsyver.sha256
- a026886 docs(demo): agent sandbox walkthrough tape and title card
- e343e69 docs(releases): record 0.14.0 as shipped
- c8774de docs(releases): record 0.15.0 as pending
- b98f781 feat(extras): sbxsyver, run syver inside a Docker Sandboxes sandbox
- 851f120 fix(extras): goss-named wrappers find syver.yaml and syver_wait.yaml
v0.14.0
-
documentation
- a new step-by-step guide to testing a container image with
dsyver, indocs/containers/testing-images.md: write a spec for an image, run it, read a failure, and put it in CI so it runs on every image build. The container image page now points to it
- a new step-by-step guide to testing a container image with
-
the Docker wrappers
dsyverand thedgossshim beside it gainSYVER_TEMP_DIR, so every variable they read now has a syver-named form. It pairs withDGOSS_TEMP_DIRrather than aGOSS_*name, because that variable is named after the script rather than the product andGOSS_TEMP_DIRhas never existed.DGOSS_TEMP_DIRis still honoured, a non-emptySYVER_TEMP_DIRwins, and an exported-but-empty one cannot shadow it -- the same contract as every other pair- this fixes the macOS workflow the wrapper README already documented, which exports
SYVER_TEMP_DIRand then runsdgoss.dgossignored the variable and fell back to/tmp, which is the private directory that example exists to work around - the wrapper's documentation now leads with the syver-named variables and spec filenames throughout. Every
GOSS_*equivalent still works andgoss.yamlis still read, so no existing setup needs changing
-
dependencies
- routine updates with no change to any check, flag or rendered output.
Go 1.26.8, up from 1.26.6, which brings the upstream fixes tonet/http, behindserveand thehttp:check, and to the runtime and compilerurfave/cli, the command line framework, moves to 3.13.0gopsutil, which reads process and system information, to 4.26.9prometheus/common, behind theprometheusoutput and/metrics, to 0.72.0gomega, the matcher library behind every assertion, to 1.44.0sprout, the template function library, moves to 1.1.2. Templated specs render as before
v0.13.0
Changelog
- 7c56304 fix(tests): correct the aggregate count for the file fixture
- 994b545 Merge pull request #51 from krameff/fix/one-image-description
- 6fb42aa Merge pull request #52 from krameff/feature/windows-file-owner-acl
- 1fd838c Merge pull request #53 from krameff/feature/windows-service-scm
- df521b4 Merge pull request #54 from krameff/feature/cross-platform-gate
- 68f4da4 Merge pull request #55 from krameff/fix/govulncheck-cross-goos
- 720973e Merge pull request #56 from krameff/devel
- bd6b248 Merge pull request #57 from krameff/docs/0.13.0-release-record
- 2c980da ci: lint and scan for windows and darwin, not just the host
- 61e37bc docs(releases): backfill the v0.12.2 release record
- 1c52c0d docs(releases): record 0.13.0 as assembled
- c5143fd docs(releases): record 0.13.0's merge order and CI results
- 613b976 feat(windows): read services from the Service Control Manager
- 64e2e1a feat(windows): report file owners and ACLs
- b1df1bb fix(ci): build govulncheck for the host, not the scan target
- 6fb70b2 fix(release): one image description everywhere
- 40dcf6e fix(tests): correct the aggregate fixture's assertion count
v0.12.2
Changelog
- 5382296 Merge branch 'devel' of github.com:krameff/syver into devel
- 96537df Merge branch 'devel' of github.com:krameff/syver into devel
- 241ac56 Merge pull request #44 from krameff/feature/fixture-and-sysctl-cleanup
- 3f825d6 Merge pull request #45 from krameff/fix/dev-build-version
- b82e4bd Merge pull request #46 from krameff/feature/windows-mount-backend
- cc6333b Merge pull request #47 from krameff/dependabot/go_modules/devel/github.com/urfave/cli/v3-3.12.0
- 02b1e35 Merge pull request #48 from krameff/dependabot/github_actions/devel/docker/build-push-action-7.4.0
- ae99120 Merge pull request #49 from krameff/dependabot/github_actions/devel/docker/setup-buildx-action-4.4.1
- ee7859e Merge pull request #50 from krameff/devel
- 2d788d5 Updated releases
- 78a11de build(deps): bump docker/build-push-action from 7.3.0 to 7.4.0
- e68bac9 build(deps): bump docker/setup-buildx-action from 4.3.0 to 4.4.1
- 4d984d4 build(deps): bump github.com/urfave/cli/v3 from 3.11.0 to 3.12.0
- 768f493 docs(releases): record v0.12.1
- b30480f feat(windows): mount: backend for drive letters
- 8cb4efd fix(build): stamp devel builds from the release they contain
- 48f5312 refactor(system): read kernel parameters directly and drop go-sysctl
- 476e7ea test(windows): un-skip the mount fixture, counts seeded from a Windows run
v0.12.1
Changelog
- 00dce28 Merge pull request #41 from krameff/dependabot/go_modules/devel/golang.org/x/sys-0.48.0
- c7a7c6b Merge pull request #42 from krameff/0.12.1_pre
- b845e9a Merge pull request #43 from krameff/devel
- d566c19 build(deps): bump golang.org/x/sys from 0.47.0 to 0.48.0
- 307bc77 build(release): annotate release images at index and manifest level
- 26f9eb5 docs(releases): record v0.12.0
- 09f901e feat(dsyver): accept nerdctl, refuse cp strategy under rootless nerdctl
- a4784ce fix(serve): log cache misses at DEBUG so -L can silence them
v0.12.0
Changelog
- a4d4594 Merge pull request #38 from krameff/feature/integration-count-assertions
- d23532d Merge pull request #39 from krameff/feature/windows-registry-and-job-objects
- 1d9aebd Merge pull request #40 from krameff/devel
- 9db31cf Updated and aligned platforms docs
- 129cfcf Updated file
- 242905a Updated ready for 0.12.0 release
- 71664dd Updated releases
- 2ec07fd Updated windows data
- 011c10e docs(changelog): FEAT-013 Windows correctness cluster
- 7154335 docs(platforms): record the Windows port and process findings as measured
- 5462665 docs(releases): name both signing keys and say which signs what
- 8d53084 docs(windows): correct the coverage table and document the skip cascade
- 63a574a feat(registry): accept regedit and PowerShell hive spellings, add view:
- 87b5efa fix(autoadd): honour --log-level, as every other subcommand does
- dd647cf fix(autoadd): report a resource skipped because its lookup failed
- b4f2103 fix(docker): annotate the image index so the package page has a description
- 88d3295 fix(mount): report unsupported platforms honestly, without touching the shared pat
- 9adacfe fix(paths): resolve absolute Windows includes and backslash home paths
- 5ca14f0 fix(process): fail when every status read fails, not just when one does
- 17a3568 fix(windows): kill the whole process tree when a command times out
- 3df9949 fix(windows): make the Job Object attach flag atomic
- a136bb6 test(integration): assert assertion counts, not just exit codes
- 3495ea6 test(integration): report both sides of the distro count mismatch
- 083f2ab test(process): pin the n=1 boundary the all-or-nothing rule cannot express
- 9947cd9 test(registry): pin the grammar, the views, and the value-vs-key warning
- fa0bed5 test(windows): assert the mount fix end to end, and forbid the silent outcome
- 76b72b4 test(windows): assert the new registry grammar and record the new totals
- 9cb5bce test(windows): prove a grandchild dies on timeout and survives success
v0.11.2
Description
- Added Signed SBOM to builds
- container now patched at build time do latest fixes applied
- docs updated and made clearer
Changelog
- e888146 Merge pull request #37 from krameff/devel
- 68ade7c docs(changelog): correct the scan attribution and widen the 0.11.2 heading
- 6fa4b5e feat(release): publish signed SPDX SBOMs
- 59684fe fix(ci): make the golden gate see a deleted fixture,test count
- f84bc0e fix(docker): upgrade alpine packages at image build time
v0.11.1
v0.11.0
Syver 0.11.0 makes Windows checks tell the truth. Fourteen sites were returning success for checks that had never actually run, and this release converts every one of them into an explicit error. The upgrade is therefore expected to turn some passing Windows specs red, and that is the intent: those specs were not being checked. Re-run your Windows specs after upgrading, and read docs/windows.md, which is new in this release and lists every flip alongside what to do instead.
The four that matter most.
- package: passed for any package name at all, because Windows has no package-manager backend and syver fell through to the RPM one, where a missing rpm binary read as "not installed".
- service: passed for a service that does not exist, so a typo in a service name was indistinguishable from a disabled service. registry: reported a key that exists but cannot be read as absent, which is backwards for the hardening specs registry checks are usually written for.
- user:, group: and interface: could not tell a lookup that found nothing from a lookup that failed, so an unreachable domain controller on a domain-joined host looked like a missing account. Genuinely absent still reports exist
syver add was writing fabricated values from the same bad readings. It now fails for a package or a service it cannot honestly describe, and omits mode, owner and group on Windows rather than writing "-1" for each.
There is a security fix that predates this release. A service name taken from a gossfile was interpolated into a PowerShell command line using Go string quoting, which is not PowerShell quoting, so a name containing a subexpression was executed rather than treated as text. Anyone able to write or generate your gossfile could run commands as syver on Windows. Names are now rendered so nothing in them is evaluated. Windows only.
Two things are now documented as broken rather than left to be discovered: user: groups: fails for every user on Windows, and port: is not implemented there. uid and gid are unavailable rather than unimplemented, since Windows id
Outside Windows, a malformed --vars-inline is now rejected while the flag is parsed, with the error naming the flag and quoting the value syver actually received. cmd.exe is where this bites, since it does not treat ' as a quote cnd GOSS_VARS_INLINE are validated the same way. Three dependenciesmoved (golang.org/x/crypto v0.56.0, gopsutil/v4 v4.26.8, prometheus/common v0.71.0) with no effect on gossfiles.
No breaking changes to the gossfile format or the CLI. This is a MInges are real, not because anything was removed. Linux and macOS are unaffected.
Changelog
- bfb7230 Merge branch 'devel' into feature/windows-truthfulness
- 30f2de0 Merge pull request #34 from krameff/feature/windows-truthfulness
- 5729f8a Merge pull request #35 from krameff/devel
- 7cae2c8 Merge remote-tracking branch 'origin/devel' into feature/windows-truthfulness
- b0d6199 Releases details udpated
- e1f36d8 deps: gopsutil to v4.26.8 and prometheus/common to v0.71.0
- 788b588 docs(windows): add a Windows page and re-skip the package fixture
- 692800f docs(windows): add a Windows page, document the serve disclosure
- 0502d63 docs(windows): show the registry key-vs-value distinction
- 7fabf91 feat: make Windows report unsupported paths honestly
- b0baf33 feat: reject a malformed --vars-inline while parsing the flag
- 19cb3aa fix(ci): drop package from the Windows gossfile aggregate
- ea04bd2 fix(ci): let the validate harness host a fixture that is meant to fail
- df0bb39 fix(ci): log in to GHCR before the scheduled Trivy scan
- f407b3d fix(windows): treat ERROR_NONE_MAPPED as a genuine absence
- e8ca7df test(windows): pin the registry key-vs-value distinction
- 006282c test(windows): raise the google.com timeout and document the network dependency
- 965adb2 test(windows): real assertions for interface, service, SIDs and stderr
- e62abbe test(windows): replace the fake user and group fixtures with real ones
- f15754c test(windows): use only assertions verified on both Windows hosts
v0.10.0
0.10.0: migrate gossfile templating from sprig to sprout
Replaces github.com/Masterminds/sprig/v3 with github.com/go-sprout/sprout
v1.1.1 as the template engine behind {{ }} blocks in a gossfile. Sprig has gone quiet since its last release; sprout is the maintained community successor and its sprigin package is a near drop-in replacement.
What changes for anyone writing a gossfile
No function is lost. Sprig had 211, sprout has 293, and the extra 82 are new names rather than replacements.
Five functions render differently, and in every case sprout is fixing a sprig bug rather than introducing one:
| Expression | sprig | sprout |
|---|---|---|
{{ "foo bar" | snakecase }} |
foo__bar |
foo_bar |
{{ "foo bar" | camelcase }} |
Foo Bar |
FooBar |
{{ "foo bar" | kebabcase }} |
foo--bar |
foo-bar |
{{ plural 1 "a" "b" }} |
exec error | <no value> |
{{ "hello" | reverse }} |
exec error | [] |
A gossfile that leaned on the old doubled-separator output will render differently. This is why the release is a MINOR rather than a patch.
Sprout also prints a deprecation warning at render time for some names, which sprig never did. It fires for 55 of the 95 names sprout marks deprecated, mostly the must* and regex* families and older hash spellings such as sha256sum. The other 40 are silent, including upper, which is the only deprecated name used anywhere in this repo. No logger suppression was needed or added.
One thing gets better rather than differently: docs/goss.yaml carried a commented-out sping_basic block with a TODO saying sprig could not accept it. It works under sprout and is now live in the docs.
Dependencies
Net three fewer indirect requirements: Masterminds/goutils, huandu/xstrings and shopspring/decimal all drop out. The x/crypto Trivy suppression stays and its comment now says why: sprout needs it for the same bcrypt template
functions sprig did, so the suppression survives the swap on its own merits rather than by inheritance.
- x/crypto bumped to v0.56.0
Testing, including one thing reviewers should know
template_test.go is new. The template layer had almost no direct coverage before this, so it is the whole safety net for the swap: it pins the five corrected expressions, the funcMap collision behaviour, both missingkey modes, and the measurement that upper is silent.
Two problems were found while verifying it, both fixed here:
-
The
.Funcs()ordering intemplate.gowas unprotected. Its comment calls the ordering load-bearing and warns that reversing it turns a loud failure into a silent one, but swapping the two calls broke no test. The
existing collision test rebuilds the two-call chain inside the test with its own marker map, so it passes whatever production does.TestFuncMapOrderingIsLoadBearingcloses that by rendering through the real filter and asserting on a non-string, where the two implementations actually differ:{{ toUpper 42 }}errors under the correct order and renders<no value>under the reversed one. -
The golden baseline was blind to the template engine. Every templated spec in the tree needs vars or env the harness does not supply, so all eight rendered as zero-byte failures and their goldens recorded an error string that is identical either side of an engine change. A new
render-varscase renders one spec with its vars, using a deliberately double-spaced input because that is where the two engines disagree. While wiring it up, the manifest turned out to listvalidate render addonly, so the new golden would have been written on every run and never compared.
Baseline moves 205 to 208, additions only, nothing existing changed.
Predecessor kept at .golden-baseline.pre-render-vars-205.
Gate
go test -race ./... 532 passed / 0 failed / 7 packages
make lint 0 issues
make vet / make fmt / go mod tidy -diff clean
make check exit 0, govulncheck and Trivy no findings
golden-baseline 208/208 byte-identical
Changelog
- 8d98c6c Merge branch 'devel' into feat/sprig-sprout-change
- 22161d2 Merge pull request #29 from krameff/feat/sprig-sprout-change
- 8490d59 Merge pull request #30 from krameff/devel
- fc7201e Merge pull request #31 from krameff/devel
- 6ecaf97 deps: bump golang.org/x/crypto to v0.56.0
- 9fe6090 feat: migrate gossfile templating from sprig to sprout