Releases: no42-org/onmsctl
Release list
Preview (rolling build of main)
Rolling preview built from main at commit 51bf6d8.
Unstable — rebuilt on every merge to main. Not a release; do
not depend on it. Use a vX.Y.Z release for anything real.
v0.4.7
Highlights
Security-driven maintenance release. No functional changes to commands, kinds, or the REST client.
The reason to take it: the HTTP/2 stack inside the shipped binary is patched. Everything else is routine dependency and CI upkeep.
Security
- RUSTSEC-2026-0258 —
h20.4.14 → 0.4.18 (#105). Theh2crate, reached transitively throughhyperandreqwest, accepted and queued empty HTTP/2 DATA frames without limit. An unresponsive or hostile server could growonmsctl's memory unboundedly, or panic it on a length overflow. Low severity, andonmsctlis a client rather than a server, so the exposure is narrow — but the vulnerable code shipped in the binary, so it only clears for users once released.
Dependency updates
v0.4.6
Highlights
Dependency-only maintenance release. No functional changes to commands, kinds, or the REST client.
Dependency updates
v0.4.5
Maintenance release: dependency updates and a hardened license-compliance gate. No functional changes to the CLI.
Highlights
- CI now fails pull requests when
THIRD-PARTY-LICENSES.mdis stale, so the published third-party license report can no longer drift fromCargo.lock. RELEASING.md documents the full version-bump surface. (#94)
Dependencies
v0.4.4
Highlights
- SBOM HTML report — releases now attach
onmsctl-v0.4.4-sbom-report.html, the CycloneDX SBOM rendered by blitsbom into one self-contained page that works offline: browse the shipped components and licenses without any SBOM tooling (#90, #91). - SLSA build provenance — binaries, SBOM, checksums and the container image carry GitHub-issued provenance attestations; verify any downloaded artifact with
gh attestation verify <file> --repo no42-org/onmsctl(#81). - Supply-chain hardening — container base images are digest-pinned, and RUSTSEC-2026-0185 (
quinn-proto; pulled in via reqwest but never compiled into the shipped binary, so not exploitable) is cleared from the lockfile (#83). - Preview channel — every merge to
mainnow publishes a signedghcr.io/no42-org/onmsctl:rcimage and a rollingpreviewprerelease with binaries for all four targets, so a fix can be tested ahead of a release. Verification recipes are in RELEASING.md (#85).
No CLI behaviour changes — this release is supply-chain and release-infrastructure work plus routine dependency updates.
v0.4.3
Maintenance release — dependency and toolchain hardening only. No user-facing changes: CLI flags, config schema, and the EventSource YAML schema are unchanged from v0.4.2, and onmsctl still reports 0.4.3 across every capability.
Changed
- Rust dependencies:
clap4.6.1 → 4.6.2,clap_complete4.6.5 → 4.6.7,quick-xml0.40.1 → 0.41.0. - CI: pinned GitHub Actions refreshed (grouped Dependabot updates).
- Regenerated
THIRD-PARTY-LICENSES.mdto match the updated dependency tree.
Artifacts
Static binaries for {x86_64,aarch64}-unknown-linux-gnu and {x86_64,aarch64}-apple-darwin, each with a .sha256 and an aggregate SHA256SUMS, a CycloneDX SBOM, and keyless Sigstore (cosign) signatures (.sig + .pem). Multi-arch distroless container image at ghcr.io/no42-org/onmsctl:0.4.3 (also tagged 0.4 and latest).
Verification steps for binaries and images are in RELEASING.md.
Full changelog: v0.4.2...v0.4.3
v0.4.2
Maintenance and supply-chain hardening release. No CLI, config, or schema changes — a drop-in upgrade from v0.4.1.
Security
- Bump
anyhow→ 1.0.103, clearing a freshly-disclosed RUSTSEC advisory (dtolnay/anyhow#451). Also bumpszeroize→ 1.9.0.
Build & CI
- Pinned runner images — all GitHub Actions jobs now run on explicit versions (
ubuntu-24.04,macos-26) instead of floating-latestlabels, so the release environment can't shift between tags (#62). - Refreshed pinned CI action SHAs (checkout, docker buildx/qemu/metadata/login/build-push) via Dependabot.
Docs
- Corrected container image tag references (no leading
v) and synced README version strings.
Artifacts
Four signed static binaries (Linux/macOS × x86_64/aarch64), per-binary SHA256 checksums plus an aggregate SHA256SUMS, a CycloneDX SBOM, and Sigstore cosign signatures (.sig/.pem). Verification recipe in RELEASING.md.
v0.4.1
What's Changed
Other Changes
- feat: distroless OCI image with signed multi-arch GHCR publish by @indigo423 in #51
- chore(release): bump workspace version to v0.4.1 by @indigo423 in #58
Full Changelog: v0.4.0...v0.4.1
v0.4.0
Highlights
New capability — declarative Business Service Monitoring (kind: BusinessService)
Describe a BSM hierarchy as YAML and reconcile it with onmsctl apply -f:
- Full hierarchy — services plus child-service / IP-service / application / reduction-key edges, per-edge map functions, a per-service reduce function, and attributes.
- Name-based references resolved to OpenNMS ids at apply time; nodes by
{label, location}or{foreignSource, foreignId}.ipServicesedges auto-cover the standard node/interface/service alarms; custom reduction keys support{{nodeId}}templating. - Whole-object reconcile with a two-pass apply (create → PUT with resolved child ids); child cycles are rejected at plan time; exactly one
bsmdreload per mutating apply; services absent from an apply are never auto-deleted. - New verbs:
onmsctl business-service list | get | delete(aliasbs). Works on Horizon 33.x and develop — no version gate.
Documentation
- README and the quickstart now cover all seven capabilities — added the Business services section and the previously-missing Maintenance windows section, plus
examples/business-service.yaml.
Install
Single static binaries for Linux and macOS (x86_64 + aarch64), each cosign-signed (.sig/.pem), with an aggregate SHA256SUMS and a CycloneDX SBOM. Verification recipe in the README.
Full changelog: v0.3.0...v0.4.0
v0.3.0
onmsctl v0.3.0
Adds kind: DataCollectionSource — declarative management of OpenNMS SNMP data collection (which MIB objects, resource types, and system definitions get collected) over the DB-backed /api/v2/datacollectionconf REST surface.
Highlights
- New capability
kind: DataCollectionSource— one document perdatacollection-group. You own only the sources you write; the stock vendor library (MIB2, Cisco, …) stays untouched (additive prune — not a singleton).- Whole-source replace — a changed group tree is re-uploaded and the server prunes children you removed; an unchanged source is a no-op (normalized, order-insensitive diff).
- True-reconcile profile associations —
profilesis the full truth: a name added is attached, a name dropped is detached. - Inline
profileSpec(optional) — create or tune the snmp-collection profile (RRD step / RRAs / storage flag) from zero. - Verbs —
onmsctl datacollection list [--profiles] | export <name> [--format xml|json] | delete <name>(aliasdc).
Server requirement
The DB-backed data-collection endpoint is absent from released Horizon ≤ 37.0.0. Apply preflights it once and fails early — before any write — with a clear "endpoint not available" message on a server that lacks it. All other capabilities are unaffected.
Artifacts
Static binaries for macOS and Linux (aarch64 / x86_64), each cosign-signed (.sig + .pem) alongside a signed SHA256SUMS and a signed CycloneDX SBOM. Install + checksum steps are in the README.
Full Changelog: v0.2.0...v0.3.0