Skip to content

Releases: no42-org/onmsctl

Preview (rolling build of main)

Pre-release

Choose a tag to compare

@github-actions github-actions released this 25 Sep 23:54
51bf6d8

Rolling preview built from main at commit 51bf6d8.

Unstable — rebuilt on every merge to main. Not a release; do
not depend on it. Use a vX.Y.Z release for anything real.

v0.4.7

Choose a tag to compare

@github-actions github-actions released this 21 Aug 19:32
v0.4.7
9875c3f

Highlights

Security-driven maintenance release. No functional changes to commands, kinds, or the REST client.

The reason to take it: the HTTP/2 stack inside the shipped binary is patched. Everything else is routine dependency and CI upkeep.

Security

  • RUSTSEC-2026-0258 — h2 0.4.14 → 0.4.18 (#105). The h2 crate, reached transitively through hyper and reqwest, accepted and queued empty HTTP/2 DATA frames without limit. An unresponsive or hostile server could grow onmsctl's memory unboundedly, or panic it on a length overflow. Low severity, and onmsctl is a client rather than a server, so the exposure is narrow — but the vulnerable code shipped in the binary, so it only clears for users once released.

Dependency updates

  • Container builder base rust:1-bookworm digest refreshed (#107). Build-time only; rust-toolchain.toml still pins the compiler to 1.95.0, so the produced binary is unchanged by it.
  • GitHub Actions pins refreshed (#103): codeql-action 4.37.7, setup-buildx-action 4.3.0.

v0.4.6

Choose a tag to compare

@github-actions github-actions released this 13 Aug 05:36
v0.4.6
71f4747

Highlights

Dependency-only maintenance release. No functional changes to commands, kinds, or the REST client.

Dependency updates

  • comfy-table 7.2.2 → 8.0.0 (#99). One visible change: truncated cells in wide table output now end in … instead of ....
  • rust-deps group (#98): clap 4.6.6, clap_complete 4.6.9, async-trait 0.1.92, similar 3.1.2, thiserror 2.0.20.
  • GitHub Actions pins refreshed (#100).

v0.4.5

Choose a tag to compare

@github-actions github-actions released this 06 Aug 12:24
v0.4.5
4b57787

Maintenance release: dependency updates and a hardened license-compliance gate. No functional changes to the CLI.

Highlights

  • CI now fails pull requests when THIRD-PARTY-LICENSES.md is stale, so the published third-party license report can no longer drift from Cargo.lock. RELEASING.md documents the full version-bump surface. (#94)

Dependencies

  • clap 4.6.4 → 4.6.5 (#95)
  • GitHub Actions pin updates (#96)

v0.4.4

Choose a tag to compare

@github-actions github-actions released this 30 Jul 08:49
v0.4.4
8701122

Highlights

  • SBOM HTML report — releases now attach onmsctl-v0.4.4-sbom-report.html, the CycloneDX SBOM rendered by blitsbom into one self-contained page that works offline: browse the shipped components and licenses without any SBOM tooling (#90, #91).
  • SLSA build provenance — binaries, SBOM, checksums and the container image carry GitHub-issued provenance attestations; verify any downloaded artifact with gh attestation verify <file> --repo no42-org/onmsctl (#81).
  • Supply-chain hardening — container base images are digest-pinned, and RUSTSEC-2026-0185 (quinn-proto; pulled in via reqwest but never compiled into the shipped binary, so not exploitable) is cleared from the lockfile (#83).
  • Preview channel — every merge to main now publishes a signed ghcr.io/no42-org/onmsctl:rc image and a rolling preview prerelease with binaries for all four targets, so a fix can be tested ahead of a release. Verification recipes are in RELEASING.md (#85).

No CLI behaviour changes — this release is supply-chain and release-infrastructure work plus routine dependency updates.

v0.4.3

Choose a tag to compare

@github-actions github-actions released this 16 Jul 06:51
v0.4.3
62c251b

Maintenance release — dependency and toolchain hardening only. No user-facing changes: CLI flags, config schema, and the EventSource YAML schema are unchanged from v0.4.2, and onmsctl still reports 0.4.3 across every capability.

Changed

  • Rust dependencies: clap 4.6.1 → 4.6.2, clap_complete 4.6.5 → 4.6.7, quick-xml 0.40.1 → 0.41.0.
  • CI: pinned GitHub Actions refreshed (grouped Dependabot updates).
  • Regenerated THIRD-PARTY-LICENSES.md to match the updated dependency tree.

Artifacts

Static binaries for {x86_64,aarch64}-unknown-linux-gnu and {x86_64,aarch64}-apple-darwin, each with a .sha256 and an aggregate SHA256SUMS, a CycloneDX SBOM, and keyless Sigstore (cosign) signatures (.sig + .pem). Multi-arch distroless container image at ghcr.io/no42-org/onmsctl:0.4.3 (also tagged 0.4 and latest).

Verification steps for binaries and images are in RELEASING.md.

Full changelog: v0.4.2...v0.4.3

v0.4.2

Choose a tag to compare

@github-actions github-actions released this 30 Jun 23:00
v0.4.2
12e0192

Maintenance and supply-chain hardening release. No CLI, config, or schema changes — a drop-in upgrade from v0.4.1.

Security

  • Bump anyhow → 1.0.103, clearing a freshly-disclosed RUSTSEC advisory (dtolnay/anyhow#451). Also bumps zeroize → 1.9.0.

Build & CI

  • Pinned runner images — all GitHub Actions jobs now run on explicit versions (ubuntu-24.04, macos-26) instead of floating -latest labels, so the release environment can't shift between tags (#62).
  • Refreshed pinned CI action SHAs (checkout, docker buildx/qemu/metadata/login/build-push) via Dependabot.

Docs

  • Corrected container image tag references (no leading v) and synced README version strings.

Artifacts

Four signed static binaries (Linux/macOS × x86_64/aarch64), per-binary SHA256 checksums plus an aggregate SHA256SUMS, a CycloneDX SBOM, and Sigstore cosign signatures (.sig/.pem). Verification recipe in RELEASING.md.

v0.4.1

Choose a tag to compare

@github-actions github-actions released this 17 Jun 20:45
v0.4.1
73e592c

What's Changed

Other Changes

  • feat: distroless OCI image with signed multi-arch GHCR publish by @indigo423 in #51
  • chore(release): bump workspace version to v0.4.1 by @indigo423 in #58

Full Changelog: v0.4.0...v0.4.1

v0.4.0

Choose a tag to compare

@github-actions github-actions released this 17 Jun 15:26
v0.4.0
21b321a

Highlights

New capability — declarative Business Service Monitoring (kind: BusinessService)

Describe a BSM hierarchy as YAML and reconcile it with onmsctl apply -f:

  • Full hierarchy — services plus child-service / IP-service / application / reduction-key edges, per-edge map functions, a per-service reduce function, and attributes.
  • Name-based references resolved to OpenNMS ids at apply time; nodes by {label, location} or {foreignSource, foreignId}. ipServices edges auto-cover the standard node/interface/service alarms; custom reduction keys support {{nodeId}} templating.
  • Whole-object reconcile with a two-pass apply (create → PUT with resolved child ids); child cycles are rejected at plan time; exactly one bsmd reload per mutating apply; services absent from an apply are never auto-deleted.
  • New verbs: onmsctl business-service list | get | delete (alias bs). Works on Horizon 33.x and develop — no version gate.

Documentation

  • README and the quickstart now cover all seven capabilities — added the Business services section and the previously-missing Maintenance windows section, plus examples/business-service.yaml.

Install

Single static binaries for Linux and macOS (x86_64 + aarch64), each cosign-signed (.sig/.pem), with an aggregate SHA256SUMS and a CycloneDX SBOM. Verification recipe in the README.

Full changelog: v0.3.0...v0.4.0

v0.3.0

Choose a tag to compare

@github-actions github-actions released this 15 Jun 21:42
v0.3.0
3fdfdad

onmsctl v0.3.0

Adds kind: DataCollectionSource — declarative management of OpenNMS SNMP data collection (which MIB objects, resource types, and system definitions get collected) over the DB-backed /api/v2/datacollectionconf REST surface.

Highlights

  • New capability kind: DataCollectionSource — one document per datacollection-group. You own only the sources you write; the stock vendor library (MIB2, Cisco, …) stays untouched (additive prune — not a singleton).
    • Whole-source replace — a changed group tree is re-uploaded and the server prunes children you removed; an unchanged source is a no-op (normalized, order-insensitive diff).
    • True-reconcile profile associations — profiles is the full truth: a name added is attached, a name dropped is detached.
    • Inline profileSpec (optional) — create or tune the snmp-collection profile (RRD step / RRAs / storage flag) from zero.
    • Verbs — onmsctl datacollection list [--profiles] | export <name> [--format xml|json] | delete <name> (alias dc).

Server requirement

The DB-backed data-collection endpoint is absent from released Horizon ≤ 37.0.0. Apply preflights it once and fails early — before any write — with a clear "endpoint not available" message on a server that lacks it. All other capabilities are unaffected.

Artifacts

Static binaries for macOS and Linux (aarch64 / x86_64), each cosign-signed (.sig + .pem) alongside a signed SHA256SUMS and a signed CycloneDX SBOM. Install + checksum steps are in the README.

Full Changelog: v0.2.0...v0.3.0