Skip to content

RaySpec v1.8.0

Choose a tag to compare

@iloveautomation iloveautomation released this 15 Aug 08:14
· 304 commits to main since this release
3695ce1

The complete entry for this release is the ## [1.8.0] block in
CHANGELOG.md — Added,
Changed, Fixed, Documentation, Security and Upgrade notes. It is larger than a
GitHub release body can hold, so only its Upgrade notes are reproduced below, verbatim. Where
they point at what is documented "above", that is those changelog sections.

Upgrade notes

Everything below is documented in place above; this is the checklist. Nothing here applies to a
deployment that only authors specs and deploys them — the items are for embedders, for operators of
an existing database, and for authors of documents that were silently doing nothing.

  • Two exported types gained REQUIRED members, so an out-of-repository implementation stops
    typechecking until it grows them.
    ServerConfig (@rayspec/server) gains three:
    frontendCsp: string, permissionsPolicy: string and authRateMultiplier: number. A deployment
    that builds its config with loadServerConfig needs no change — it fills all three from the
    environment; only code that constructs the object literally is affected. FrontendSpec
    (@rayspec/spec) gains cleanUrls: boolean in its OUTPUT type, so a literal built outside this
    repository needs the key; parsing a document is unaffected, because the field carries a default.
  • A document with a mapping key written literally as __proto__ no longer parses. It used to,
    and then quietly did nothing with whatever sat under that key — a rename renamed nothing, a view
    field vanished from the response. It is now a named reserved_document_key error at the parse
    boundary of both profiles. If a document relied on that key surviving into a free-form slot (a
    tool's parameters, the body of a contracts entry), rename it before upgrading.
  • RAYSPEC_AUTH_RATE_MULTIPLIER now has a ceiling and refuses a value above it by name, the way
    its sibling knobs already did. A deployment that set an implausibly large multiplier must lower it
    or the boot stops.
  • A static mount refuses a served file whose on-disk name carries a percent escape when the two
    decoders disagree about it, and refuses a directory index or SPA shell that resolves outside the
    served directory. Both were served before; neither shape is produced by an ordinary build.

Release identity

rayspec-release-identity.json is attached, and it also ships inside the rayspec launcher
package on npm. It maps this closure back to the commit it was built from — per-package tarball
integrity and unpacked file-list digests, the three checked-in JSON Schema artifacts, the lockfile and
dependency-SBOM digests, and the Node/pnpm requirements. Verify a downloaded set with:

pnpm release:identity-verify --tarballs <dir with the attached .tgz files>

For this release that reports 31 package(s), 0 failure(s) against source commit 3695ce1.