bootstrap v2026.09.11
Windows 1.32.0
Added
Bitwarden.CLIin theappsgroup, beside the desktop app.bwreads
and writes the vault from a terminal or a script -bw get password <item>,
orbw unlockonce and a session token for the rest. Requested directly;
1.31.0 had left it out until secrets were being copied into a terminal by
hand.
Linux 1.27.0
Added
GROUP_<name>_UV- Python CLIs installed withuv tool install, each in
its own environment, and kept current withuv tool upgrade. Entries are
nameorname|extra arguments. The phase runs after the release binaries,
which bring uv, and honours--groups,--dry-runand--skip-upgrade.GHOSTTY_DEB_REPO- where Ghostty's.debcomes from; see Changed.- The Bitwarden CLI (
bw) as a release binary, for x86_64 and aarch64.
In neither archive. Requested directly; 1.26.0 had left it out. RELEASE_<name>_TAG_PREFIX- for a repository that releases several
products under one "latest". bitwarden/clients tags web, desktop, browser
and cli releases side by side, and its latest is whichever shipped last; with
cli-vthe newest CLI tag is taken instead.verify-manifests.ymldoes the
same.RELEASE_<name>_ASSET_<arch>- an asset name for one architecture, by
dpkg --print-architecture, overRELEASE_<name>_ASSET. Bitwarden names its
x86_64 zip without an architecture and its arm64 zip with one, which no
placeholder spells for both.
Changed
-
atuin and trippy are release binaries, not apt packages. Ubuntu 24.04
carries neither, so on a noble host (WSL included) both were reported
missing and never installed. On Debian the archive lagged: trixie's atuin is
18.6.1 against the self-hosted sync server's 18.22.0, and its trippy 0.12.2.
Both now come from upstream's musl builds, for x86_64 and aarch64, into
~/.local/binlike starship and uv.A copy apt installed earlier is not removed, and
~/.local/binis ahead of
it on PATH in the zsh fragment;sudo apt remove atuin trippytidies it. -
The modern CLI bundle is release binaries too: bat, delta, eza, fd,
ripgrep, zoxide, fzf, jq, yt-dlp, btop, procs, dust, duf, glow and lnav, plus
gping and shellcheck. Ubuntu 24.04 has no procs, dust or glow, and trails
upstream on the rest by one to three years - yt-dlp from April 2024, which
YouTube has long since broken, and fzf 0.44, from beforefzf --zsh. trixie
is closer, never current. musl builds where upstream makes them for both
architectures; eza and delta are gnu, needing glibc 2.18 and 2.34 on x86_64.
yt-dlp is upstream's zipapp, one file for every architecture, run by
python3.tools/cli-parity.confmarks them@releases.Tags such as
jq-1.8.2andgping-v1.21.0resolve to their version, here
and inverify-manifests.yml;${tag#v}alone would have reinstalled both
on every run. -
gh comes from GitHub's own apt repository (
REPO_githubcli): 2.100.0,
where Ubuntu 24.04 has 2.45 and trixie 2.46. Its key is a binary keyring,
whichgpg --dearmorrejects, sosetup_reponow converts only
ASCII-armoured keys and installs binary ones as they are. -
Node and Go leave the apt list for mise, as OpenTofu did on Windows:
Ubuntu 24.04 ships Node 18, past end of life, and Go 1.22. Run once:
mise use -g node@lts go@latest. -
ansible, ansible-lint, pre-commit and yamllint are
uv toolinstalls in
theinfragroup, which keeps its name: Ubuntu 24.04 has ansible-lint 6.17
against 26.8 upstream.ansiblebrings ansible-core's commands through
--with-executables-from ansible-core. -
Ghostty comes from the community .deb that ghostty.org's Debian and
Ubuntu instructions point to,mkasberg/ghostty-ubuntu. It sat in the
appsapt list, which neither archive carries before Ubuntu 26.04, so it
never installed. The.debis chosen as that project's install.sh chooses -
Ubuntu by version, Debian by codename - and handed to apt, instead of piping
the script into bash. Releases it does not build for, bookworm among them,
are reported missing. -
Nothing apt installed earlier is removed.
~/.local/binis ahead of
/usr/binon a login's PATH, so the new copies win. To tidy up:sudo apt remove bat eza git-delta fd-find ripgrep zoxide fzf jq yt-dlp btop \ procs du-dust duf glow lnav gping shellcheck nodejs npm golang-go \ ansible ansible-lint pre-commit yamllint
Fixed
tripwould have failed as a release binary. The alias was
sudo trip, and sudo'ssecure_pathleaves out~/.local/bin. It now
resolves the full path when the alias is defined.- The script puts
~/.local/binon its own PATH. It never had, so a step
that looked for a release binary by name - delta for the git config, atuin
and carapace for theirs - missed one installed earlier in the same run, or
under the timer, and skipped. The one-offRELEASE_BIN_DIRchecks that
worked around it are gone. - A leftover apt
fd-findshadowed the realfd. The fragment aliased
fdtofdfindwheneverfdfindexisted; it now does so only when there is
nofd.
macOS 1.29.0
Added
-
A
networkgroup:trippy,gpingandnmap. Per-hop loss and
latency in one live view, a ping graph for one host or several, and what a
host exposes. The zsh fragment aliasestriptotrip -u: macOS is the one
platform where trippy traces without root. -
The
flameshotcask inapps. Screenshots annotated before they are
copied: arrows, boxes, numbered markers, blur. macOS asks for the Screen
Recording permission on first capture. -
kubecolorincloud,uvindev,carapaceinshell.kubectlis now an alias forkubecolor, which passes every argument
through and only adds colour, andkone forkubectl.- carapace completes the CLIs zsh has nothing for. git is excluded
(CARAPACE_EXCLUDES=git): zsh's own completion for it is better. - uv handles Python packages and venvs; mise still picks the Python version.
-
difftasticincli, and git settings for it. A structural diff: it
compares syntax, so a reformat is not a change. delta stays the pager for
git diff,show,logandadd -p; difftastic is asked for per command:git difftoolorgit dft(diff.tool=difftastic, no prompt, paged)git ddiff,git dshow <rev>,git dlog- difftastic in place of the
patch
Never
diff.externalglobally: its output is not a patch, so
git diff > x.patchandgit applywould stop working. delta passes
difftastic's output through byte for byte, so the pager needs no exception.
Like delta's, each key is set only when unset. -
git sdiff- the delta view side by side
(-c core.pager='delta --side-by-side' diff), set with delta's keys. -
Completion for the CLIs carapace has no completer for.
- stern and yq: carapace specs in
carapace/specs/, deployed to
~/Library/Application Support/carapace/specs- Go's config directory on
macOS, which carapace uses unless$XDG_CONFIG_HOMEis an absolute path.
Both are Cobra apps, so each spec is one line handing Tab to the tool's
own__complete. - mise:
mise completion zshin the fragment - small, and it asks mise. - uv: its zsh script is ~570 KB, so the fragment registers a stub that
loads it on the first Tab afteruvand replaces itself with the real
_uv; a new shell pays nothing for it.
- stern and yq: carapace specs in
-
The
onlyofficecask inapps. An office suite built around .docx,
.xlsx and .pptx, so files from Microsoft Office keep their layout more often
than in LibreOffice. AGPL-3.0: free for personal and company use.
Changed
-
atuin/config.tomlpoints sync at the self-hosted server
(sync_address = "http://192.168.50.6:8087") instead of atuin's own
api.atuin.shdefault. That isroles/atuinon raspberrypi_master in
mpostument/raspberry-setup, on the house LAN only - 8087 because the
OpenTelemetry collector holds 8888 there.Sync is still off until you run
atuin register(oratuin loginwith the
keyatuin keyprints): this says where, not whether. Off that network a
machine records locally and syncs when it is back.