Skip to content

Releases: nhtera/Sonde

Sonde Desktop 0.2.1

Choose a tag to compare

@github-actions github-actions released this 06 Oct 16:10

Sonde Desktop 0.2.1: a desktop app for .hurl files, built on the sonde CLI.

Engine: Sonde CLI v1.4.1 + f375962

  • macOS (universal): signed and notarized disk image.
  • Windows (x64, ARM64): the installers are not signed yet; Windows SmartScreen shows "Windows protected your PC" on first launch: choose More info, then Run anyway. Verify the download against checksums.txt first.
  • Linux (x86_64): AppImage (GTK 4, WebKitGTK 6.0: Ubuntu 24.04+, Debian 13, Fedora 40+).
  • Server mode (Sonde-Desktop-Server-*): the app in a browser, for a remote dev box: loopback only, with a one-time launch link and a token.
  • On Windows and Linux, installing updates in place is tested by automated tests only.

No account and no telemetry. Run history stays on this computer, with secrets, credential headers and cookie values masked. Server mode listens on loopback only and needs its token.

Verify: checksums.txt is signed with cosign (keyless, this workflow's identity); every file has a build provenance attestation (gh attestation verify FILE --repo nhtera/Sonde). Sonde-Desktop-0.2.1.update.json lists the update files with their SHA-512, signed with the app's pinned update key.

Sonde Desktop 0.2.0

Choose a tag to compare

@github-actions github-actions released this 06 Oct 02:57

Sonde Desktop 0.2.0: a desktop app for .hurl files, built on the sonde CLI.

Engine: Sonde CLI v1.4.1 + 661852f

0.1.0 has no updater: download this release once; later releases install from the app.

  • macOS (universal): signed and notarized disk image.
  • Windows (x64, ARM64): the installers are not signed yet; Windows SmartScreen shows "Windows protected your PC" on first launch: choose More info, then Run anyway. Verify the download against checksums.txt first.
  • Linux (x86_64): AppImage (GTK 4, WebKitGTK 6.0: Ubuntu 24.04+, Debian 13, Fedora 40+).
  • Server mode (Sonde-Desktop-Server-*): the app in a browser, for a remote dev box: loopback only, with a one-time launch link and a token.
  • On Windows and Linux, installing updates in place is tested by automated tests only.

No account and no telemetry. Run history stays on this computer, with secrets, credential headers and cookie values masked. Server mode listens on loopback only and needs its token.

Verify: checksums.txt is signed with cosign (keyless, this workflow's identity); every file has a build provenance attestation (gh attestation verify FILE --repo nhtera/Sonde). Sonde-Desktop-0.2.0.update.json lists the update files with their SHA-512, signed with the app's pinned update key.

v1.4.1

Choose a tag to compare

@github-actions github-actions released this 05 Oct 18:46

The first published release since v1.3.1. (v1.4.0 was tagged at the same code but never published: the release check refused it, and v1.4.1 adds only that fix. go install …@v1.4.0 works; it has no release files.)

Highlights

  • Secrets a project needs, shared through git. An environment lists its secret names in sonde.yaml (secrets:), the values staying in the secrets file kept out of git. On a fresh clone, the missing secrets file is no error when every listed secret comes from SONDE_SECRET_*, --secret or another source (CI); otherwise the run stops before any request, naming each missing secret and where to set it. sonde run and sonde mcp alike. See sonde-yaml.md.
  • Imports. Collection scripts become suggested asserts and captures (one-line pm.test arrows, OpenCollection scripts), path variables become {{placeholders}}, a / in a request name is no folder; OpenCollection exports and OpenAPI specs exported from a collection import as sent. sonde import reminds you to keep *.secrets out of git.
  • MCP and LSP. gRPC services are listed, MCP tools carry their input schemas, and the LSP knows client-defined variables.

Fixes

  • --cookie-jar writes the file named again.
  • A rendered sonde command masks every credential and quotes safely for cmd.exe.
  • An .http multipart part whose header has a case-changing character no longer panics.
  • A stream records a sent message before the reply it causes.
  • A project edit stays inside the value it changes.

Changelog

Others

  • fd3edff build(desktop): version 0.2.0-rc.1 for the release rehearsal
  • 2d4a820 ci(release): gorelease lists the module's versions from the cache first

Sonde Desktop 0.2.0-rc.1

Pre-release

Choose a tag to compare

Sonde Desktop 0.2.0-rc.1: a desktop app for .hurl files, built on the sonde CLI.

Engine: Sonde CLI v1.4.1 + fd3edff

0.1.0 has no updater: download this release once; later releases install from the app.

  • macOS (universal): signed and notarized disk image.
  • Windows (x64, ARM64): the installers are not signed yet; Windows SmartScreen shows "Windows protected your PC" on first launch: choose More info, then Run anyway. Verify the download against checksums.txt first.
  • Linux (x86_64): AppImage (GTK 4, WebKitGTK 6.0: Ubuntu 24.04+, Debian 13, Fedora 40+).
  • Server mode (Sonde-Desktop-Server-*): the app in a browser, for a remote dev box: loopback only, with a one-time launch link and a token.
  • On Windows and Linux, installing updates in place is tested by automated tests only.

No account and no telemetry. Run history stays on this computer, with secrets, credential headers and cookie values masked. Server mode listens on loopback only and needs its token.

Verify: checksums.txt is signed with cosign (keyless, this workflow's identity); every file has a build provenance attestation (gh attestation verify FILE --repo nhtera/Sonde). Sonde-Desktop-0.2.0-rc.1.update.json lists the update files with their SHA-512, signed with the app's pinned update key.

Sonde Desktop 0.1.0

Choose a tag to compare

@github-actions github-actions released this 04 Oct 12:41

Sonde Desktop 0.1.0: a desktop app for .hurl files, built on the sonde CLI.

  • macOS (universal): signed and notarized disk image.
  • Windows (x64, ARM64): the installers are not signed yet; Windows SmartScreen shows "Windows protected your PC" on first launch: choose More info, then Run anyway. Verify the download against checksums.txt first.
  • Linux (x86_64): AppImage (GTK 4, WebKitGTK 6.0: Ubuntu 24.04+, Debian 13, Fedora 40+).
  • Server mode (Sonde-Desktop-Server-*): the app in a browser, for a remote dev box: loopback only, with a one-time launch link and a token.

No account and no telemetry. Run history stays on this computer, with secrets, credential headers and cookie values masked. Server mode listens on loopback only and needs its token.

Verify: checksums.txt is signed with cosign (keyless, this workflow's identity); every file has a build provenance attestation (gh attestation verify FILE --repo nhtera/Sonde).

Sonde Desktop 0.1.0-rc.1

Pre-release

Choose a tag to compare

Sonde Desktop 0.1.0-rc.1: a desktop app for .hurl files, built on the sonde CLI.

  • macOS (universal): signed and notarized disk image.
  • Windows (x64, ARM64): the installers are not signed yet; Windows SmartScreen shows "Windows protected your PC" on first launch: choose More info, then Run anyway. Verify the download against checksums.txt first.
  • Linux (x86_64): AppImage (GTK 4, WebKitGTK 6.0: Ubuntu 24.04+, Debian 13, Fedora 40+).
  • Server mode (Sonde-Desktop-Server-*): the app in a browser, for a remote dev box: loopback only, with a one-time launch link and a token.

No account and no telemetry. Run history stays on this computer, with secrets, credential headers and cookie values masked. Server mode listens on loopback only and needs its token.

Verify: checksums.txt is signed with cosign (keyless, this workflow's identity); every file has a build provenance attestation (gh attestation verify FILE --repo nhtera/Sonde).

v1.3.1

Choose a tag to compare

@github-actions github-actions released this 28 Sep 17:38

Changelog

Bug fixes

  • 457e77c fix(engine): do not retry an entry whose host is not allowed
  • 4d48baa fix(mcp): name the file relative to the root in assert messages

v1.3.0

Choose a tag to compare

@github-actions github-actions released this 28 Sep 14:40

Sonde 1.3 lets AI agents work with your request files. sonde mcp is a
Model Context Protocol server for Claude Code, Cursor, VS Code and other
MCP clients: it lists and checks .hurl and .sonde files, and, only
when you allow it, runs them against the hosts you name.

Highlights

  • sonde mcp. Two read-only tools are always available:
    sonde_list finds request files and sonde.yaml environments, and
    sonde_check returns syntax errors or a summary of each entry. With
    --allow-run, sonde_run runs one file and returns its --json
    result, plus the response body of each failing entry.
    docs/guides/mcp.md

    claude mcp add sonde -- sonde mcp --allow-run --allow-host localhost:8080
  • Runs are fenced in.

    • --allow-run requires at least one --allow-host, and there is no
      default host.
    • The allowlist is checked on every request, redirect and connection,
      proxies included.
    • Entries that would reroute a connection or write a file fail before
      anything is sent: proxy, connect-to, resolve, unix-socket,
      the netrc options and output. They still run with sonde --test.
    • Tools read only files under --root.
    • Secrets come only from sonde.yaml, SONDE_SECRET_* and the server's
      own flags, and are redacted from everything a tool returns.
    • Each tool call writes one line to an audit log on standard error.

The design is recorded in
decision 0006.
The server uses the official MCP Go SDK, which adds 2 MB to the binary and
no measurable start-up time.

Good to know

  • Host names in --allow-host are matched as written, never resolved:
    localhost does not match 127.0.0.1. Only ASCII names match; write
    internationalized names in punycode.
  • The allowlist trusts names. A wildcard such as *.example.com trusts
    every subdomain, and an allowed gateway reaches whatever it fronts.
  • Response bodies returned to the agent are data from the server under
    test, not instructions.

Compatibility

Every change to the CLI, the JSON report and the engine and exchange
Go packages is additive, as
docs/stability.md
promises for 1.x. The MCP tools are now part of that contract.

Install

brew install nhtera/tap/sonde                                   # macOS, Linux
scoop bucket add nhtera https://github.com/nhtera/scoop-bucket  # Windows
scoop install sonde
go install github.com/nhtera/sonde/cmd/sonde@v1.3.0

Changelog

Features

  • 46e8127 feat(mcp): serve request files to AI agents with sonde mcp

v1.2.0

Choose a tag to compare

@github-actions github-actions released this 28 Sep 02:25

Sonde 1.2 adds a mock server and three protocols beyond plain HTTP:
Server-Sent Events, WebSocket and gRPC. The new protocols are written in
.sonde files; .hurl files stay strict Hurl 8, and each new construct is
a parse error there. There is no 1.1 release: its mock server ships here.

Highlights

  • sonde mock. Serve an OpenAPI 3.0/3.1 or Swagger 2.0 spec as an HTTP
    mock: responses come from the spec's examples and schemas, and requests
    can be validated against it (--validate-requests).
    docs/guides/mock-server.md
  • Server-Sent Events and WebSocket. sonde-stream-* options read a
    response as an event stream; a [SondeMessages] section scripts a
    WebSocket exchange with send, receive and close steps. The
    sondeStream query checks the messages with the usual filters and
    predicates.
    docs/guides/streaming.md
  • gRPC. A [SondeGrpc] section calls unary and server-streaming
    methods with JSON messages, from .proto files, descriptor sets or
    server reflection. The sondeGrpc query checks the status; a status
    other than OK fails the entry unless the entry checks it. gRPC runs on
    Sonde's own HTTP/2 client, so TLS, proxies, verbose output, reports and
    redaction work as for HTTP.
    docs/guides/grpc.md

The designs are recorded in decisions
0004
and 0005.
gRPC support adds 3.6 MB to the binary; the measurements are in 0005.

Compatibility

Every change to the CLI, the JSON report and the engine and exchange
Go packages is additive, as docs/stability.md
promises for 1.x. Hurl compatibility is unchanged (97.3% of Hurl's
blocking integration tests).

Install

brew install nhtera/tap/sonde                                   # macOS, Linux
scoop bucket add nhtera https://github.com/nhtera/scoop-bucket  # Windows
scoop install sonde
go install github.com/nhtera/sonde/cmd/sonde@v1.2.0

Changelog

Features

  • 64ab201 feat(grpc): call gRPC services from .sonde files
  • 4f0991e feat(mock): serve OpenAPI specs as HTTP mocks with sonde mock
  • 533a13f feat(stream): test Server-Sent Events and WebSocket in .sonde files

Bug fixes

  • 5027203 fix(stream): bound the WebSocket close handshake by closing the connection

Others

  • dc5095e ci: check the public API against v1.0.0
  • c4d1085 ci: leave extension and scoped docs/test commits out of CLI release notes
  • 5af437d ci: make the benchmark comparison run every tool
  • 746b266 ci: publish the extension with a locked vsce install

VS Code extension editors/vscode/v1.0.3

Choose a tag to compare

Published to the VS Code Marketplace as sonde v1.0.3.