Zum Inhalt springen

67 Einträge aus 3 Quellen. Zuletzt aktualisiert:

Folge jdx, um die Release Notes in deinen Feed zu holen.

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Hk von jdx

hk 1.53.0: Schnelleres Laden der Konfiguration, sichereres Stashing

hk 1.53.0 ergänzt das cargo_deny-Builtin, beschleunigt Konfigurationsauflösung und Hook-Läufe in großen Repos, behebt Hänger nach fehlgeschlagenen Abhängigkeiten sowie Stashing-Fehler und härtet Git-Aufrufe gegen Argument-Injection.

This release adds a cargo-deny builtin, meaningfully speeds up config resolution and hook runs in large repos, and fixes two correctness bugs around dependency graphs and stashing. It also hardens hk's Git invocations against argument injection.

Added

  • cargo_deny builtin (@risu729) #1081. Runs cargo-deny for Rust dependency policy checks (advisories, bans, licenses, sources). It triggers on Cargo.toml, Cargo.lock, and deny.toml/.deny.toml (including .cargo/ and exceptions variants), groups executions by Cargo workspace and runs from the workspace directory, and uses --locked so checks never create or update Cargo.lock.

    ["cargo_deny"] = Builtins.cargo_deny
    

Fixed

  • Dependents no longer hang after a failed dependency (@jdx) #1099. With fail_fast = false, a failed step returned without marking its dependency watch channel as done, so any step with depends on it waited forever and the run hung. The failed step now signals its dependents so they can proceed. fail_fast = true behavior is unchanged. Fixes discussion #1098. …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Hk von jdx

hk 1.52.0: Monorepo-Subprojekte und Linting im Arbeitsverzeichnis

hk 1.52.0 unterstützt Monorepos mit verschachtelten subprojects-Konfigurationen und mise-Umgebungen pro Verzeichnis, ergänzt das Flag --unstaged für Änderungen im Arbeitsverzeichnis und behebt Fehler bei Branch-Guards, leeren Remotes und Conventional-Commit-Scopes.

This release brings hk to monorepos with nested subprojects configs and per-directory mise environments, adds a --unstaged flag for linting only working-tree changes, and ships a batch of correctness fixes for branch guards, empty remotes, and conventional commit scopes.

Added

  • subprojects for monorepos (@jdx) #1094. The root hk.pkl can list literal directories or globs, and each subproject's own hk.pkl is merged into the root run scoped to its directory. Step working directories and glob matching are relative to the subdirectory, flat step names are prefixed with <dir>: (e.g. packages/web:eslint) for --step/skip_steps, and a subproject's env applies only to its own steps. Paired with this, HK_MISE=1 now resolves mise env --json per step dir, so subproject-local tools land on PATH — including for structured argv commands.

    // hk.pkl (repo root)
    subprojects = List("frontend", "packages/*")
    
    // frontend/hk.pkl
    hooks {
      ["check"] {
        steps { ["eslint"] = (Builtins.eslint) { batch = true } }
      }
    }
    ``` …
    

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Fnox von jdx

fnox 1.31.0: Kombinierbare Profile als Overlay-Stack

fnox 1.31.0 erlaubt es, mehrere Profile gleichzeitig als geordneten Overlay-Stack zu aktivieren, und schlägt bei gesperrter Proton-Pass-Sitzung das Entsperren vor.

A small release headlined by composable multi-profile support, plus a friendlier Proton Pass error when your session is locked.

Added

Compose multiple active profiles (#605) -- @gaojunran

You can now activate more than one profile at a time as an ordered overlay stack. The top-level config is the base, and each profile is layered on top in order, with later profiles overriding earlier ones on key conflicts.

# Repeatable flags
fnox -P aws -P prod exec -- ./app

# Comma-separated
fnox -P aws,prod exec -- ./app

# Environment variable
FNOX_PROFILE=aws,prod fnox exec -- ./app

The effective config resolves as top-level config + profiles.aws + profiles.prod, and fnox.<profile>.toml files are loaded for each active profile in order. Write commands (set, remove, import, sync, provider add/remove) target the last active profile by default, and the full profile stack is factored into the daemon's request protocol, socket path, and cache key. Library users get a new with_profiles() builder.

Fixed

Proton Pass suggests unlocking a locked session (#612) -- @TyceHerrman …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Hk von jdx

hk 1.51.0: Strukturiertes argv und ODER-Selektoren

hk 1.51.0 führt shell-freie argv-Befehle mit dateiweiser Argumentexpansion und match_any-Selektoren mit ODER-Logik ein und behebt Fehler bei --quiet/--silent, Hook-Argumenten, Index-Sperren und Linux-Argumentgrenzen.

Two configuration expansions land in this release: shell-free argv commands with per-file argument expansion, and match_any selectors that combine globs and types with OR semantics. Alongside them, correctness fixes for --quiet/--silent, config-based hook argument forwarding, transient index locks, and Linux argument-size limits.

Added

  • Structured argv commands (@jdx) #1067. A step's check/fix/check_list_files/check_diff can now be a Command with an explicit argv list that runs a binary via PATH without a shell. Standalone {{files}} and {{workspace_files}} entries expand to one argument per file (raw paths), so names with spaces or shell metacharacters are passed literally. Auto-batching, hk test, progress output, and fix suggestions all go through shared Command rendering, and many builtins (prettier, ruff, biome, ...) have moved to structured commands. Existing string and platform Script commands are unchanged; structured commands can't be combined with shell or prefix.

    check = new Command {
      argv = List("wc", "-c", "{{files}}")
    }
    ``` …
    

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Fnox von jdx

fnox 1.30.0: Paranoider Env-Modus und Proton-Pass-PAT-Authentifizierung

fnox 1.30.0 führt den Modus env = "exec" samt Top-Level-env-Standard ein, erweitert die Proton-Pass-Authentifizierung per PAT und bereinigt die Standardwerte von fnox export.

A focused release that hardens fnox's secret exposure model with an exec-only env mode, expands Proton Pass authentication for CI and agent use, and cleans up fnox export defaults.

Added

Exec-only env mode and top-level env default (#604) -- @jdx

The per-secret env field gains a new "exec" state, and a new top-level env sets the default for all secrets. This lets you keep secrets out of the interactive shell -- where AI coding agents and other inherited processes would see them -- while still injecting them into fnox exec subprocesses.

env shell integration / fnox export fnox exec fnox get
true (default) yes yes yes
"exec" (new) no yes yes
false no no yes

One line flips a project to default-deny:

env = "exec"   # nothing enters the interactive shell

[secrets]
DATABASE_URL = { provider = "age", value = "..." }               # exec-only (inherited)
PS1_TOKEN    = { provider = "age", value = "...", env = true }   # explicit opt-back-in
``` …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Hk von jdx

hk 1.50.0: Gestagtes pre-commit überall

hk 1.50.0 sorgt dafür, dass hk run pre-commit auch ohne Stashing nur gestagte Dateien sieht, ergänzt das textlint-Builtin und einen inhaltsadressierten Config-Cache und übergibt bei global installierten Hooks --staged.

A cluster of pre-commit correctness fixes so hk run pre-commit (and installed hooks) really only see staged files, plus a textlint builtin, a content-addressed config cache, and a docs accuracy pass.

Added

  • textlint builtin (@smasato) #1036. Adds textlint as a batched natural-language linter for Markdown and plain text. check runs textlint {{ files }}, fix runs textlint --fix {{ files }}, and it auto-suggests when .textlintrc* or a "textlint" entry in package.json is present.

    ["textlint"] = Builtins.textlint
    

Fixed

  • Pre-commit is staged-only, even without stashing (@jdx) #1023. The default file selection for pre-commit steps now stays scoped to staged paths when stash = false, matching the "only what you're committing" expectation instead of also picking up unstaged and untracked matches.

  • Installed global pre-commit hooks pass --staged (@jdx) #1043. hk install --global now generates pre-commit hook commands as hk run pre-commit --from-hook --staged, so an env override like HK_STASH=git can't defeat a repo-level stash = "none" policy. Local config hooks and legacy .git/hooks/ shims are unchanged. Fixes discussion #1030. …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Fnox von jdx

Fnox 1.22.0: Library-API und Korrektur bei fnox set

Fnox 1.22.0 führt eine Top-Level-Fnox-Library-API zum Einbetten in Rust-Anwendungen ein und behebt, dass fnox set verschlüsselte Secrets stillschweigend zu Klartext herabstufen konnte.

v1.22.0 introduces a top-level library API for embedding fnox in Rust applications, and fixes a sharp edge in fnox set that could turn an encrypted secret into plaintext.

Added

Top-level Fnox library API (#442) -- @bglusman

Downstream Rust consumers can now use fnox as a library in three lines instead of replicating the internals of GetCommand::run:

use fnox::Fnox;

let fnox = Fnox::discover()?;          // walks up + merges parent + local + global config
let value = fnox.get("MY_KEY").await?;
let names = fnox.list()?;

The new Fnox type lives in src/library.rs and is re-exported from the crate root. Highlights:

  • Fnox::discover() mirrors the binary's full config-discovery and merge chain via Config::load_smart, including the FNOX_PROFILE env var.
  • Fnox::open(path) loads an explicit config without the upward-search/merge behavior.
  • Fnox::with_profile("staging") builder for non-default profiles.
  • get() returns FnoxError::SecretNotFound with a populated "Did you mean…" suggestion, matching the CLI's UX so callers don't need to recompute it.
  • Fnox is cheap to clone (Config is held behind an Arc) and safe to hold across .await.

set() is intentionally not part of this first cut; it'll get its own design pass.

Fixed

fnox set no longer silently downgrades encrypted secrets to plaintext (#439) -- @rpendleton …

Originalquelle(öffnet in neuem Tab)Problem melden