RaySpec v1.8.0
The complete entry for this release is the ## [1.8.0] block in
CHANGELOG.md — Added,
Changed, Fixed, Documentation, Security and Upgrade notes. It is larger than a
GitHub release body can hold, so only its Upgrade notes are reproduced below, verbatim. Where
they point at what is documented "above", that is those changelog sections.
Upgrade notes
Everything below is documented in place above; this is the checklist. Nothing here applies to a
deployment that only authors specs and deploys them — the items are for embedders, for operators of
an existing database, and for authors of documents that were silently doing nothing.
- Two exported types gained REQUIRED members, so an out-of-repository implementation stops
typechecking until it grows them.ServerConfig(@rayspec/server) gains three:
frontendCsp: string,permissionsPolicy: stringandauthRateMultiplier: number. A deployment
that builds its config withloadServerConfigneeds no change — it fills all three from the
environment; only code that constructs the object literally is affected.FrontendSpec
(@rayspec/spec) gainscleanUrls: booleanin its OUTPUT type, so a literal built outside this
repository needs the key; parsing a document is unaffected, because the field carries a default. - A document with a mapping key written literally as
__proto__no longer parses. It used to,
and then quietly did nothing with whatever sat under that key — arenamerenamed nothing, a view
field vanished from the response. It is now a namedreserved_document_keyerror at the parse
boundary of both profiles. If a document relied on that key surviving into a free-form slot (a
tool'sparameters, the body of acontractsentry), rename it before upgrading. RAYSPEC_AUTH_RATE_MULTIPLIERnow has a ceiling and refuses a value above it by name, the way
its sibling knobs already did. A deployment that set an implausibly large multiplier must lower it
or the boot stops.- A static mount refuses a served file whose on-disk name carries a percent escape when the two
decoders disagree about it, and refuses a directory index or SPA shell that resolves outside the
served directory. Both were served before; neither shape is produced by an ordinary build.
Release identity
rayspec-release-identity.json is attached, and it also ships inside the rayspec launcher
package on npm. It maps this closure back to the commit it was built from — per-package tarball
integrity and unpacked file-list digests, the three checked-in JSON Schema artifacts, the lockfile and
dependency-SBOM digests, and the Node/pnpm requirements. Verify a downloaded set with:
pnpm release:identity-verify --tarballs <dir with the attached .tgz files>
For this release that reports 31 package(s), 0 failure(s) against source commit 3695ce1.