Skip to content

v0.18.0

Choose a tag to compare

@github-actions github-actions released this 04 Sep 05:40
4f1ca8a

0.18.0 (2026-09-04)

⚠ BREAKING CHANGES

  • server: tokens that fail signature verification are rejected with 401. Deployments without outbound access to the BV-BRC key servers can set --insecure-skip-token-verify to restore the previous behavior.
  • worker,scheduler: restore opt-in gate for BV-BRC token injection (#229)

Features

  • bvbrc,staging: resolve wildcard-glob outputs and recursive ws:// directories; promote workspace staging to supported (#223) (3025ad9)
  • server: opt-in --cors-origins with proper preflight; document the reverse-proxy browser story (#231) (f6c84de)
  • store,server,cli: preserve as-submitted inputs; add gowe submit --label (#242) (aad4cef)
  • ui,server: expandable sub-workflow trees, timing panel, and Grafana link (#235) (706270b)
  • ui: admin view — worker fleet, keys, output verification, redelivery, labels (#234) (1d35eff)

Bug Fixes

  • scheduler: stop hot-looping on orphaned step instances and missing workflows (#232) (5e56b7f)
  • server,store: submissions list workflow filter matches all versions of a name (#241) (1cea960)
  • server: verify BV-BRC token signatures against pinned issuer keys (#243) (a12f703)
  • ui: guard resume/recompute task transitions with CAS and submission-state gates (#233) (3e7d22c)
  • worker,scheduler: restore opt-in gate for BV-BRC token injection (#229) (3709601)