Amber v1.17.0 Release Notes
Changed
amber bundle Stable (G1): compatibility contract in docs/BUNDLE_CONTRACT.md (entry points, externals, CJS/ESM, inventory sourcemaps, JSON-only assets). Contracted failures print error: amber bundle: and do not write the outfile. --import-map is wired on the CLI. --tree-shake remains a no-op. Not webpack/rollup/esbuild parity.
amber compile Stable (G2): SEA contract in docs/COMPILE_CONTRACT.md. Linux and Windows append an AMBER_STANDALONE trailer. macOS stores that trailer in Mach-O segment __AMBER and ad-hoc signs it. Contracted failures print error: amber compile:. Not pkg/nexe/Bun parity.
amber install Stable (G3): installer contract in docs/INSTALL_CONTRACT.md. Reads package.json dependencies/devDependencies and package-lock.json top-level dependencies pins; verifies tarball SRI or SHA-1 before unpack. --frozen-lockfile fails closed on a missing lock or a direct version mismatch and does not rewrite the lock. Contracted failures print error: amber install:. Not an npm/yarn/pnpm replacement. amber add / remove / prune / upgrade stay Experimental.
- Dependencies:
futures-util 0.3.34 and wasm-bindgen-futures 0.4.78 (wasm-bindgen 0.2.128). (#128)
- Website deploy actions:
actions/checkout v7, pnpm/action-setup v6, actions/setup-node v7. (#127)
Fixed
- Node conformance gate: the scorecard exits non-zero unless PASS is at least 55, FAIL is 0, and SKIP is 0. A larger all-PASS suite stays green. Nested CommonJS
require no longer keeps the builtin-module loader on the stack, so deep package loads used by the Express and Fastify smokes do not fail with Maximum call stack size exceeded. (#104, #126)
- Website deploy on pnpm 11:
allowBuilds permits esbuild, sharp, and workerd, so pnpm install --frozen-lockfile is not rejected with ERR_PNPM_IGNORED_BUILDS. (#129)
- Release Assets: macOS 任务安装
openssl@3 并导出 OPENSSL_DIR / PKG_CONFIG_PATH。x86_64-apple-darwin 仍在 macos-latest(ARM)上交叉编译,并从源码构建静态 x86_64 OpenSSL,避免 ARM Homebrew 库。发布步骤要求五套资产齐全(含 Intel mac 归档)后才写 GitHub Release / crates.io。
- Release Assets SBOM: CycloneDX 改为
anchore/sbom-action 的 file: Cargo.lock(并钉住 action / syft)。path: Cargo.lock 会被当成目录扫描,syft 1.42 以 dir:Cargo.lock 失败,挡住 cosign、GitHub Release 和 crates.io。
📦 预编译二进制资产与 SHA-256 校验和
| 资产文件名 |
目标系统 / 架构 |
文件大小 |
SHA-256 校验和 |
amber-v1.17.0-aarch64-apple-darwin.tar.gz |
macOS Apple Silicon (ARM64) |
21.6 MB |
235b2e7736f06ef520ed8c2208fedce1cac2ab396dd177f1a1f1dfce527052aa |
amber-v1.17.0-aarch64-unknown-linux-gnu.tar.gz |
Linux (aarch64) |
23.7 MB |
d1277947dba516367df7f2443c8f1513276631e2c3111f0104dcef6dc5f5f859 |
amber-v1.17.0-x86_64-apple-darwin.tar.gz |
macOS Intel (x86_64) |
24.3 MB |
0d024d6a52fbb63f35ea162826df8cbd1fc82173971d02bfa792532d015f7812 |
amber-v1.17.0-x86_64-pc-windows-msvc.zip |
Windows (x86_64) |
24.9 MB |
f2f8d6aabef9a1b4d42fc6bfdf8f2219e91b7111adae2a7bee4f5a54bf6a967d |
amber-v1.17.0-x86_64-unknown-linux-gnu.tar.gz |
Linux (x86_64) |
24.7 MB |
da91379c36c9a5d1238f109df70806fcb31316325425f195f48176da0aa1ca9e |
校验方法
# 下载对应架构压缩包与 checksums.txt 后执行:
shasum -a 256 -c checksums.txt
# 或 Linux 环境下:
sha256sum -c checksums.txt