Skip to content

bootstrap v2026.09.11

Choose a tag to compare

@github-actions github-actions released this 13 Sep 13:30
· 43 commits to main since this release

Windows 1.32.0

Added

  • Bitwarden.CLI in the apps group, beside the desktop app. bw reads
    and writes the vault from a terminal or a script - bw get password <item>,
    or bw unlock once and a session token for the rest. Requested directly;
    1.31.0 had left it out until secrets were being copied into a terminal by
    hand.

Linux 1.27.0

Added

  • GROUP_<name>_UV - Python CLIs installed with uv tool install, each in
    its own environment, and kept current with uv tool upgrade. Entries are
    name or name|extra arguments. The phase runs after the release binaries,
    which bring uv, and honours --groups, --dry-run and --skip-upgrade.
  • GHOSTTY_DEB_REPO - where Ghostty's .deb comes from; see Changed.
  • The Bitwarden CLI (bw) as a release binary, for x86_64 and aarch64.
    In neither archive. Requested directly; 1.26.0 had left it out.
  • RELEASE_<name>_TAG_PREFIX - for a repository that releases several
    products under one "latest". bitwarden/clients tags web, desktop, browser
    and cli releases side by side, and its latest is whichever shipped last; with
    cli-v the newest CLI tag is taken instead. verify-manifests.yml does the
    same.
  • RELEASE_<name>_ASSET_<arch> - an asset name for one architecture, by
    dpkg --print-architecture, over RELEASE_<name>_ASSET. Bitwarden names its
    x86_64 zip without an architecture and its arm64 zip with one, which no
    placeholder spells for both.

Changed

  • atuin and trippy are release binaries, not apt packages. Ubuntu 24.04
    carries neither, so on a noble host (WSL included) both were reported
    missing and never installed. On Debian the archive lagged: trixie's atuin is
    18.6.1 against the self-hosted sync server's 18.22.0, and its trippy 0.12.2.
    Both now come from upstream's musl builds, for x86_64 and aarch64, into
    ~/.local/bin like starship and uv.

    A copy apt installed earlier is not removed, and ~/.local/bin is ahead of
    it on PATH in the zsh fragment; sudo apt remove atuin trippy tidies it.

  • The modern CLI bundle is release binaries too: bat, delta, eza, fd,
    ripgrep, zoxide, fzf, jq, yt-dlp, btop, procs, dust, duf, glow and lnav, plus
    gping and shellcheck. Ubuntu 24.04 has no procs, dust or glow, and trails
    upstream on the rest by one to three years - yt-dlp from April 2024, which
    YouTube has long since broken, and fzf 0.44, from before fzf --zsh. trixie
    is closer, never current. musl builds where upstream makes them for both
    architectures; eza and delta are gnu, needing glibc 2.18 and 2.34 on x86_64.
    yt-dlp is upstream's zipapp, one file for every architecture, run by
    python3. tools/cli-parity.conf marks them @releases.

    Tags such as jq-1.8.2 and gping-v1.21.0 resolve to their version, here
    and in verify-manifests.yml; ${tag#v} alone would have reinstalled both
    on every run.

  • gh comes from GitHub's own apt repository (REPO_githubcli): 2.100.0,
    where Ubuntu 24.04 has 2.45 and trixie 2.46. Its key is a binary keyring,
    which gpg --dearmor rejects, so setup_repo now converts only
    ASCII-armoured keys and installs binary ones as they are.

  • Node and Go leave the apt list for mise, as OpenTofu did on Windows:
    Ubuntu 24.04 ships Node 18, past end of life, and Go 1.22. Run once:
    mise use -g node@lts go@latest.

  • ansible, ansible-lint, pre-commit and yamllint are uv tool installs in
    the infra group, which keeps its name: Ubuntu 24.04 has ansible-lint 6.17
    against 26.8 upstream. ansible brings ansible-core's commands through
    --with-executables-from ansible-core.

  • Ghostty comes from the community .deb that ghostty.org's Debian and
    Ubuntu instructions point to, mkasberg/ghostty-ubuntu. It sat in the
    apps apt list, which neither archive carries before Ubuntu 26.04, so it
    never installed. The .deb is chosen as that project's install.sh chooses -
    Ubuntu by version, Debian by codename - and handed to apt, instead of piping
    the script into bash. Releases it does not build for, bookworm among them,
    are reported missing.

  • Nothing apt installed earlier is removed. ~/.local/bin is ahead of
    /usr/bin on a login's PATH, so the new copies win. To tidy up:

    sudo apt remove bat eza git-delta fd-find ripgrep zoxide fzf jq yt-dlp btop \
      procs du-dust duf glow lnav gping shellcheck nodejs npm golang-go \
      ansible ansible-lint pre-commit yamllint
    

Fixed

  • trip would have failed as a release binary. The alias was
    sudo trip, and sudo's secure_path leaves out ~/.local/bin. It now
    resolves the full path when the alias is defined.
  • The script puts ~/.local/bin on its own PATH. It never had, so a step
    that looked for a release binary by name - delta for the git config, atuin
    and carapace for theirs - missed one installed earlier in the same run, or
    under the timer, and skipped. The one-off RELEASE_BIN_DIR checks that
    worked around it are gone.
  • A leftover apt fd-find shadowed the real fd. The fragment aliased
    fd to fdfind whenever fdfind existed; it now does so only when there is
    no fd.

macOS 1.29.0

Added

  • A network group: trippy, gping and nmap. Per-hop loss and
    latency in one live view, a ping graph for one host or several, and what a
    host exposes. The zsh fragment aliases trip to trip -u: macOS is the one
    platform where trippy traces without root.

  • The flameshot cask in apps. Screenshots annotated before they are
    copied: arrows, boxes, numbered markers, blur. macOS asks for the Screen
    Recording permission on first capture.

  • kubecolor in cloud, uv in dev, carapace in shell.

    • kubectl is now an alias for kubecolor, which passes every argument
      through and only adds colour, and k one for kubectl.
    • carapace completes the CLIs zsh has nothing for. git is excluded
      (CARAPACE_EXCLUDES=git): zsh's own completion for it is better.
    • uv handles Python packages and venvs; mise still picks the Python version.
  • difftastic in cli, and git settings for it. A structural diff: it
    compares syntax, so a reformat is not a change. delta stays the pager for
    git diff, show, log and add -p; difftastic is asked for per command:

    • git difftool or git dft (diff.tool=difftastic, no prompt, paged)
    • git ddiff, git dshow <rev>, git dlog - difftastic in place of the
      patch

    Never diff.external globally: its output is not a patch, so
    git diff > x.patch and git apply would stop working. delta passes
    difftastic's output through byte for byte, so the pager needs no exception.
    Like delta's, each key is set only when unset.

  • git sdiff - the delta view side by side
    (-c core.pager='delta --side-by-side' diff), set with delta's keys.

  • Completion for the CLIs carapace has no completer for.

    • stern and yq: carapace specs in carapace/specs/, deployed to
      ~/Library/Application Support/carapace/specs - Go's config directory on
      macOS, which carapace uses unless $XDG_CONFIG_HOME is an absolute path.
      Both are Cobra apps, so each spec is one line handing Tab to the tool's
      own __complete.
    • mise: mise completion zsh in the fragment - small, and it asks mise.
    • uv: its zsh script is ~570 KB, so the fragment registers a stub that
      loads it on the first Tab after uv and replaces itself with the real
      _uv; a new shell pays nothing for it.
  • The onlyoffice cask in apps. An office suite built around .docx,
    .xlsx and .pptx, so files from Microsoft Office keep their layout more often
    than in LibreOffice. AGPL-3.0: free for personal and company use.

Changed

  • atuin/config.toml points sync at the self-hosted server
    (sync_address = "http://192.168.50.6:8087") instead of atuin's own
    api.atuin.sh default. That is roles/atuin on raspberrypi_master in
    mpostument/raspberry-setup, on the house LAN only - 8087 because the
    OpenTelemetry collector holds 8888 there.

    Sync is still off until you run atuin register (or atuin login with the
    key atuin key prints): this says where, not whether. Off that network a
    machine records locally and syncs when it is back.