Releases: vscode-shellcheck/shellcheck-wasm
Release list
v0.3.0-next.1
0.3.0-next.1 (2026-09-30)
⚠ BREAKING CHANGES
-
BUILD_INFO.cflags, targetFeatures, sha256 and size
moved to BUILD_INFO.artifacts["shellcheck.wasm"]. -
feat: tell hosts whether the engine can compile the artifact
isArtifactSupported() validates two tiny modules, one with return_call
and one with a v128 constant, so a web host can say the browser is too
old (Safari before 18.2, Firefox ESR 115) instead of surfacing a
CompileError. Exported from ./client, so it is MIT.
- style: format client-entry
Features
v0.2.0
0.2.0 (2026-09-30)
⚠ BREAKING CHANGES
-
the ./build-info subpath and readBuildInfo() are
removed; import BUILD_INFO from the package entry instead. -
feat!: lint in a host-supplied worker through an injected file system
The extension is moving to lint documents of any URI scheme by reading
them through vscode.workspace.fs, and later to run on the web, so the
package can no longer reach for node:fs or hand back a synchronous
runner that blocks the caller.
createShellCheck({ module, createWorker }) now owns one Worker at a
time and runs lints through it in FIFO order. Each lint may carry a
ShellCheckFileSystem (async stat, readFile, readDirectory) that is
mounted read-only at guest /. The guest's synchronous WASI calls reach
it through a SharedArrayBuffer bridge: the Worker posts a request and
waits in Atomics.wait while the caller's thread runs the async call,
with payloads over 1 MiB sent in chunks and answers cached for the rest
of the lint. .. is folded lexically and may not leave /; symlink
containment is now the file system's job. An AbortSignal drops a queued
lint or terminates the Worker of the running one; a lost Worker is
replaced on the next lint. The Worker side ships as ./worker
(startWorker), and no shipped module imports a Node built-in.
-
the
./nodeentry (loadModule, createReadOnlyPreopen,
wasmPath) and the synchronous run() export are removed. Use
createShellCheck() with a Worker whose entry calls startWorker(), and
pass the files ShellCheck may read as LintRequest.fs. LintResult carries
stdout and stderr as strings. -
test: benchmark lint latency against 0.1.1 and native ShellCheck
The bridge adds a round trip to the caller's thread for every file
ShellCheck touches, so the redesign has to show it costs no more than
10% over the 0.1.1 node:fs runner. npm run bench installs 0.1.1 into
.cache/bench, runs both in worker_threads Workers on generated 23, 307
and 1503-line scripts with a .shellcheckrc and a sourced file, and
reports native ShellCheck and a +RTS -A64m run as data points.
- ci(release): publish prereleases under the next dist-tag
A version with a prerelease suffix (0.2.0-next.0) would otherwise become
latest on npm and a regular GitHub Release. Publish it with
--tag next and mark its GitHub Release as a prerelease; stable
versions publish as before.
- docs: document the worker API and record the file-system decision
Rewrite the README around createShellCheck, the Worker entry and the
ShellCheckFileSystem contract, including the web requirement of
cross-origin isolation for SharedArrayBuffer. Add ADR 0006 (the package
is file-system agnostic), amend ADR 0005 now that the Worker and bridge
live in the package while policy stays in the host, and note in ADR
0003 that the evidence against a reactor build measured a third-party
build rather than the reactor model.
- chore: release 0.2.0-next.0
- the ./build-info.json subpath export is removed; use
readBuildInfo() from ./build-info or ./node instead.
Features
- add an mit client entry and a prebuilt browser worker (#23) (4361f7d)
- expose build info through readBuildInfo() (#18) (72391de)
- lint through an injected file system in a host-supplied worker (#21) (30d7241)
Bug Fixes
v0.2.0-next.1
What's Changed
- feat: add an mit client entry and a prebuilt browser worker by @timonwong in #23
- refactor: simplify the client scheduler, read-only preopen and build by @timonwong in #25
- chore: release 0.2.0-next.1 by @timonwong in #26
Full Changelog: v0.2.0-next.0...v0.2.0-next.1
v0.2.0-next.0
What's Changed
- docs: configure engineering skills by @timonwong in #14
- fix(preopen): close the host fd when fstat fails after open by @timonwong in #15
- build(wasm): pin the base image digest and verify the fgl tarball by @timonwong in #17
- feat!: expose build info through readBuildInfo() by @timonwong in #18
- docs: qualify parity and document runner and preopen limits by @timonwong in #16
- chore(deps): bump actions/checkout from 4 to 7 by @dependabot[bot] in #20
- feat!: lint through an injected file system in a host-supplied worker by @timonwong in #21
Full Changelog: v0.1.1...v0.2.0-next.0
v0.1.1
What's Changed
- feat: initial shellcheck-wasm package, build pipeline and CI by @timonwong in #1
- fix: use explicit repository object in package.json by @timonwong in #8
- chore(deps): bump docker/setup-buildx-action from 3 to 4 by @dependabot[bot] in #7
- chore(deps): bump actions/setup-node from 4 to 7 by @dependabot[bot] in #6
- chore(deps): bump actions/upload-artifact from 4 to 7 by @dependabot[bot] in #5
- chore(deps-dev): bump @types/node from 22.20.4 to 26.6.1 by @dependabot[bot] in #4
- chore(deps): bump docker/build-push-action from 6 to 7 by @dependabot[bot] in #3
- chore(deps): bump actions/download-artifact from 4 to 8 by @dependabot[bot] in #2
- chore: release 0.1.1 by @timonwong in #9
New Contributors
- @timonwong made their first contribution in #1
- @dependabot[bot] made their first contribution in #7
Full Changelog: https://github.com/vscode-shellcheck/shellcheck-wasm/commits/v0.1.1