Skip to content

Release v1.17.0

Latest

Choose a tag to compare

@github-actions github-actions released this 29 Sep 07:29
· 1 commit to main since this release
8d13542

Amber v1.17.0 Release Notes

Changed

  • amber bundle Stable (G1): compatibility contract in docs/BUNDLE_CONTRACT.md (entry points, externals, CJS/ESM, inventory sourcemaps, JSON-only assets). Contracted failures print error: amber bundle: and do not write the outfile. --import-map is wired on the CLI. --tree-shake remains a no-op. Not webpack/rollup/esbuild parity.
  • amber compile Stable (G2): SEA contract in docs/COMPILE_CONTRACT.md. Linux and Windows append an AMBER_STANDALONE trailer. macOS stores that trailer in Mach-O segment __AMBER and ad-hoc signs it. Contracted failures print error: amber compile:. Not pkg/nexe/Bun parity.
  • amber install Stable (G3): installer contract in docs/INSTALL_CONTRACT.md. Reads package.json dependencies/devDependencies and package-lock.json top-level dependencies pins; verifies tarball SRI or SHA-1 before unpack. --frozen-lockfile fails closed on a missing lock or a direct version mismatch and does not rewrite the lock. Contracted failures print error: amber install:. Not an npm/yarn/pnpm replacement. amber add / remove / prune / upgrade stay Experimental.
  • Dependencies: futures-util 0.3.34 and wasm-bindgen-futures 0.4.78 (wasm-bindgen 0.2.128). (#128)
  • Website deploy actions: actions/checkout v7, pnpm/action-setup v6, actions/setup-node v7. (#127)

Fixed

  • Node conformance gate: the scorecard exits non-zero unless PASS is at least 55, FAIL is 0, and SKIP is 0. A larger all-PASS suite stays green. Nested CommonJS require no longer keeps the builtin-module loader on the stack, so deep package loads used by the Express and Fastify smokes do not fail with Maximum call stack size exceeded. (#104, #126)
  • Website deploy on pnpm 11: allowBuilds permits esbuild, sharp, and workerd, so pnpm install --frozen-lockfile is not rejected with ERR_PNPM_IGNORED_BUILDS. (#129)
  • Release Assets: macOS 任务安装 openssl@3 并导出 OPENSSL_DIR / PKG_CONFIG_PATH。x86_64-apple-darwin 仍在 macos-latest(ARM)上交叉编译,并从源码构建静态 x86_64 OpenSSL,避免 ARM Homebrew 库。发布步骤要求五套资产齐全(含 Intel mac 归档)后才写 GitHub Release / crates.io。
  • Release Assets SBOM: CycloneDX 改为 anchore/sbom-action 的 file: Cargo.lock(并钉住 action / syft)。path: Cargo.lock 会被当成目录扫描,syft 1.42 以 dir:Cargo.lock 失败,挡住 cosign、GitHub Release 和 crates.io。

📦 预编译二进制资产与 SHA-256 校验和

资产文件名 目标系统 / 架构 文件大小 SHA-256 校验和
amber-v1.17.0-aarch64-apple-darwin.tar.gz macOS Apple Silicon (ARM64) 21.6 MB 235b2e7736f06ef520ed8c2208fedce1cac2ab396dd177f1a1f1dfce527052aa
amber-v1.17.0-aarch64-unknown-linux-gnu.tar.gz Linux (aarch64) 23.7 MB d1277947dba516367df7f2443c8f1513276631e2c3111f0104dcef6dc5f5f859
amber-v1.17.0-x86_64-apple-darwin.tar.gz macOS Intel (x86_64) 24.3 MB 0d024d6a52fbb63f35ea162826df8cbd1fc82173971d02bfa792532d015f7812
amber-v1.17.0-x86_64-pc-windows-msvc.zip Windows (x86_64) 24.9 MB f2f8d6aabef9a1b4d42fc6bfdf8f2219e91b7111adae2a7bee4f5a54bf6a967d
amber-v1.17.0-x86_64-unknown-linux-gnu.tar.gz Linux (x86_64) 24.7 MB da91379c36c9a5d1238f109df70806fcb31316325425f195f48176da0aa1ca9e

校验方法

# 下载对应架构压缩包与 checksums.txt 后执行:
shasum -a 256 -c checksums.txt
# 或 Linux 环境下:
sha256sum -c checksums.txt