Zum Inhalt springen

releases.sh Release Notes

68 Einträge aus 3 Quellen. Zuletzt aktualisiert:

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

releases.sh

until-Filter bis Tagesende, vollständige /updates/-Historie, Login-Fixes

Bei until-Datumsfiltern in REST API, MCP-Tools und CLI (--until) wird der angegebene Tag jetzt bis zum Tagesende eingeschlossen, außerdem laufen die /updates/-Seiten durch die gesamte Feed-Historie, Google-Anmeldeprobleme sind behoben und OAuth-Fehler führen auf eine eigene Seite, wobei ein Auth-Library-Update eine Sicherheitslücke schließt.

**Fixed** - `until` date filters — bare dates now include releases through the end of that day; the REST API, MCP tools, and CLI `--until` flag were cutting the day off at midnight, so single-day queries returned nothing. - `/updates/` pages — day pages, the sitemap, and the digest archive now follow pagination through the full feed history; they were 404ing or truncating once the feed exceeded 100 releases. - Google sign-in — a duplicate-identity issue left a small number of users unable to sign in with Google; affected rows are cleared and the condition is now rejected at the database level. - OAuth error page — sign-in failures now redirect to a proper page on releases.sh instead of a raw API error screen; the underlying auth library update also closes a security advisory for an OAuth state / magic-link token confusion issue (any in-flight flows at deploy time will need to be restarted).

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

releases.sh

Produkt heißt jetzt durchgängig „Release Notes Index“

Das Produkt heißt jetzt durchgängig "Release Notes Index", etwa in Anmeldeseiten, Social-Preview-Bildern, im MCP-Servernamen und in Produkttexten.

**Changed** - Product name is now consistently "Release Notes Index" across sign-in screens, social preview images, the MCP server's display name in connected clients, and in-product copy.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

releases.sh CLI von releases.sh

Version 0.83.0: Neuer Befehl releases publish für CI-Veröffentlichung

Der neue Befehl releases publish ermöglicht es, Changelog-Updates aus GitLab CI, Buildkite und lokalen Docs-Builds mit RELEASES_API_TOKEN zu veröffentlichen, und releases json validate akzeptiert nun publish: "push"-Changelog-Locators.

Minor Changes

  • 03e8198: Add releases publish so GitLab CI, Buildkite, and local docs builds can push changelog updates with RELEASES_API_TOKEN, using the same plan as the publish-changelog GitHub Action.

    releases json validate accepts publish: "push" changelog locators from the current releases.json schema.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

releases.sh

OAuth-Zustimmung zeigt Weiterleitungsziel und warnt bei unverifizierten Clients

Der OAuth-Zustimmungsbildschirm zeigt jetzt das tatsächliche Weiterleitungsziel des Access Tokens an und warnt bei nicht verifizierten Clients mit externer Weiterleitung mit einem gelben Hinweis.

**Fixed** - OAuth consent screen now shows the real redirect destination — instead of the client's self-reported name and domain, the page shows where your access token is actually sent (another website, an app on this device, or a named app-scheme app); unverified clients that redirect to an external site show an amber warning.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

releases.sh CLI von releases.sh

Version 0.82.0: OAuth-Clients mit official-Option und neuer Update-Befehl

releases admin oauth client create erhält die Optionen --official / --no-official, dazu kommt der neue Befehl releases admin oauth client update für die Flags official, trusted und disabled, und official wird in client list / get angezeigt.

Minor Changes

  • 47efef1: Add --official / --no-official to releases admin oauth client create, a new releases admin oauth client update command for the official, trusted and disabled flags, and show official in client list / get output. The flag controls the "Verified by Releases Index" badge on the consent page and needs an API with buildinternet/releases#2421. An older API ignores official on create and rejects an update that sets only official.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

releases.sh

releases.json: Changelog per GitHub Action mit "publish": "push" deklarieren

In der releases.json lässt sich ein per GitHub Action befüllter Changelog mit "publish": "push" deklarieren, sodass der Listing-Ablauf die Schritte für Domain-Verifizierung, Token und Action-Einrichtung automatisch liefert.

**Added** - `releases.json` push-publish locators — declare a GitHub Action-fed changelog in your domain manifest with `"publish": "push"` alongside the `github` and `path` fields; the listing flow returns the domain-verify, token-mint, and Action-wire-up steps automatically, with no separate manual source setup needed.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

releases.sh

Claude verbindet sich ohne Vorregistrierung mit dem MCP-Server

Claude lässt sich nun über die Option "Use Claude's published identity" ohne manuelle Vorregistrierung mit dem MCP-Server verbinden, der OAuth-Zustimmungsbildschirm listet Follows und Webhooks auf, und der Dark Mode blitzt beim ersten Laden nicht mehr hell auf.

**Added** - Connect Claude to the MCP server using its published identity — Claude's "Use Claude's published identity" option in the connector dialog now works; the server fetches Claude's client metadata on first connect and registers it automatically, with no manual pre-registration step. **Changed** - OAuth consent screen now lists follows and webhooks — connecting an app via OAuth shows that it can follow and unfollow orgs and products and manage your webhooks, matching what the grant actually allows. **Fixed** - Dark mode no longer flashes light on first load — the theme bootstrap now runs as an inline `` script, so the dark class applies before first paint whether you chose dark explicitly or follow your OS setting.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

releases.sh CLI von releases.sh

Version 0.81.1: Claude-Plugin mit neuem MCP-Endpunkt und Skills

Das Claude-Plugin verweist nun auf den Endpunkt agents.releases.sh/mcp, enthält Links zu Dokumentation, Support und Nutzungsbedingungen im Manifest, dokumentiert die genutzten Dienste und enthält die Agent-Skills jetzt im Plugin-Ordner plugins/claude/releases/skills/.

Patch Changes

  • caf3ae1: Point the Claude plugin at the agents.releases.sh/mcp endpoint and add documentation, support and terms links to its manifest.
  • 9eff9b1: Document which Releases.sh services the Claude plugin reaches and what they keep.
  • 0767e87: Move the agent skills into the self-contained Claude plugin folder (plugins/claude/releases/skills/) so the plugin passes Claude plugin directory validation. npx skills add buildinternet/releases-cli finds them at the new path, and the skills update check now reads that path.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

releases.sh

MCP-OAuth auf agents.releases.sh und Anmeldeaufforderung in Clients

Die MCP-OAuth-Anmeldung funktioniert nun auf agents.releases.sh, da Tokens für beide Adressen akzeptiert werden, und Account-MCP-Tools ohne Zugangsdaten lösen in Clients wie Claude eine Anmeldeaufforderung statt eines einfachen Fehlers aus.

**Fixed** - MCP OAuth sign-in now works on `agents.releases.sh` — connecting to `https://agents.releases.sh/mcp\` (the advertised address) was routing tokens to the wrong audience; tokens minted for either `agents.releases.sh` or `mcp.releases.sh` are now accepted on both. - Calling account MCP tools without a credential now prompts sign-in — `follow`, `unfollow`, `list_follows`, `get_personalized_feed`, `list_webhooks`, and `manage_webhook` now return a proper OAuth challenge in clients like Claude, triggering the sign-in flow instead of showing a plain error.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

releases.sh

Publish Tokens, Verzeichnismodus der GitHub Action und höheres API-Key-Limit

Neu sind Publish Tokens für verifizierte Domain-Inhaber, ein Verzeichnismodus der GitHub Action über changelog-glob und das Beanspruchen bereits erfasster Organisationen, außerdem zeigen CLI-Freigabebildschirme klarer an, was bestätigt wird, und das Limit für Read-only-API-Keys steigt von 5 auf 25.

**Added** - Publish tokens — verified domain owners can mint a per-source token from Account → Webhooks & API, copy a ready-to-paste `publish-changelog` workflow step, and revoke it at any time; `releases publish-token` commands in the CLI can mint and manage tokens using the session from `releases login`. - GitHub Action directory mode — set `changelog-glob` (e.g. `changelog/**/*.mdx`) in `publish-changelog` to publish one-file-per-entry Markdown or MDX changelogs; title, date, version, slug, and canonical URL are read from frontmatter, and `draft: true` skips an entry. - Claim a tracked org — an "Own this domain?" link in the org sidebar lets the actual owner start a verification claim on any org the registry already tracks, not just stubs; owners and admins can revoke a claim when it's no longer needed. **Changed** - CLI approval screens now say what they're actually approving — `releases login`, `releases keys`, and `releases publish-token` each show a distinct confirmation screen; `releases login` no longer keeps a long-lived session after the key is created. - Read-only API key limit raised to 25 — the per-user cap for personal keys increases from 5 to 25, leaving room for multiple machines, CI environments, and scripts under one account.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

releases.sh CLI von releases.sh

Version 0.81.0: Login speichert nur noch schreibgeschützten API-Key

releases login speichert nur noch den schreibgeschützten API-Key statt einer Browser-Sitzung, releases keys und releases publish-token verlangen pro Befehl eine neue Browser-Freigabe (mit --no-browser als Alternative), und releases auth logout widerruft den Key direkt und entfernt stets die lokalen Zugangsdaten.

Minor Changes

  • 7237636: releases login no longer keeps a signed-in browser session on disk — only the read-only API key it mints. releases keys and releases publish-token now open a fresh one-time browser approval for each command and sign that session back out as soon as the command finishes, instead of reusing a stored session; every subcommand takes --no-browser (same as login) to print the URL + code instead. releases auth logout revokes the stored key directly (no browser approval needed) and always removes the local credential, even if the server-side revoke fails. A credential file saved before this change is upgraded in place: any leftover session token is signed out and stripped the next time it's touched.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

releases.sh CLI von releases.sh

Version 0.80.1: releases login hinterlässt keine überzähligen Keys mehr

Behoben wurde, dass releases login bei jedem Aufruf einen neuen relu_-Key hinterließ: Der ersetzte Key wird nun widerrufen, die Fehlermeldung beim Erreichen des Key-Limits nennt passende Befehle, und releases auth logout widerruft den gespeicherten Key serverseitig.

Patch Changes

  • d28f481: Fix releases login leaking a new relu_ key on every run. It now remembers the minted key's id and revokes the key it replaces once the new one is safely stored. When the server's active-key limit is hit, the error names the commands to list and revoke keys. releases auth logout also revokes the stored key server-side, best-effort. Fixes #418.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

releases.sh CLI von releases.sh

Version 0.80.0: Neue Befehle für relk_-Publish-Tokens

Mit releases publish-token create/list/revoke lassen sich relk_-Tokens erstellen, auflisten und widerrufen, die auf eine Quelle begrenzt sind und von der GitHub Action publish-changelog als RELEASES_API_TOKEN genutzt werden.

Minor Changes

  • f591610: Add releases publish-token create/list/revoke for minting a relk_ token scoped to one source (used by the publish-changelog GitHub Action as RELEASES_API_TOKEN), matching POST/GET/DELETE /v1/me/publish-tokens[/:id]. Companion to buildinternet/releases#2388.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

releases.sh

Neuer Digest-Endpunkt, Wochen-Digests pro Produkt und MCP-Sichtbarkeitsregeln

Neu ist der Endpunkt GET /v1/collections/:slug/digests/latest, Wochen-Digests fassen jedes Produkt als eine Geschichte zusammen, MCP-Tools beachten dieselben Sichtbarkeitsregeln wie die REST API, und zwei Fehler bei Produktsuche und Source-Detail wurden behoben.

**Added** - `GET /v1/collections/:slug/digests/latest` — fetch the current week's digest for a collection without knowing the week date; the collection page now loads it in parallel with the feed instead of sequentially. **Changed** - Weekly digest summaries now describe each product's week as one story — multiple updates from the same CLI, SDK, or app are grouped into a single account instead of being recapped version-by-version; a version number appears only when it is the news (a major release, or one worth skipping). - MCP tools now follow the same visibility rules as the REST API — deleted and hidden orgs, products, and sources no longer appear in lookups, search, the org directory, or latest releases, and tab completion skips them too. **Fixed** - Searching by product scope no longer drops live results when the product also has hidden or deleted sources. - Source detail no longer shows tombstoned slugs for a parent org or product that was soft-deleted — those fields return absent instead.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

releases.sh CLI von releases.sh

Version 0.79.0: discovery onboard startet keine Remote-Session mehr

releases admin discovery onboard startet keine Remote-Discovery-Session mehr, sondern beendet sich mit Exit-Code 1 und verweist auf releases admin org create, releases admin source create und den Skill local-ingest; onboard apply sowie die Flags --managed-agents / --sandbox wurden entfernt.

Minor Changes

  • d58db28: releases admin discovery onboard no longer starts a remote discovery session. The discovery worker and POST /v1/workflows/discover were retired (buildinternet/releases#2352); the command now exits 1 with a pointer to releases admin org create, releases admin source create, and the local-ingest skill. onboard apply and the --managed-agents / --sandbox engine flags are removed.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

releases.sh CLI von releases.sh

Version 0.78.1: macOS-Binaries neu gebaut und signiert, Startabsturz behoben

Die macOS-Binaries werden nun auf macOS gebaut und ad-hoc signiert, wodurch das Beenden beim Start behoben wird, das durch ungültige Signaturen in v0.77.0 und v0.78.0 unter macOS 27 auftrat.

Patch Changes

  • f8f6646: Fix the macOS binaries being killed on launch. They are now built on macOS and ad-hoc code-signed; v0.77.0 and v0.78.0 shipped with invalid signatures, which macOS 27 enforces (brew upgrade failed while generating shell completions).

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

releases.sh CLI von releases.sh

Version 0.78.0: Workspace-Webhooks und erweiterte Workspace-Liste

Die releases webhook-Befehle akzeptieren jetzt --workspace <id-or-slug> zur Verwaltung gemeinsamer Workspace-Webhooks, und releases workspace list zeigt ID, Slug und die eigene Rolle der Workspaces an.

Minor Changes

  • b1e47d9: Add --workspace <id-or-slug> to releases webhook list/add/show/edit/remove/test/rotate-secret for managing a shared workspace-owned webhook instead of your own, and a new releases workspace list command to find a workspace's id, slug, and your role in it (#406).

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

releases.sh

Interest Alerts per E-Mail oder Webhook und Wochen-Digests auf der Startseite

Neue Interest Alerts benachrichtigen per E-Mail oder Webhook, wenn ein Release aus gefolgten Organisationen oder Produkten zu einem frei formulierten Interesse passt, und lassen sich bearbeiten sowie mit Trefferhistorie ansehen; zudem gibt es Wochen-Digests auf der Startseite und gemeinsame Workspace-Webhooks.

**Added** Interest alerts let you describe what you care about in plain language, and hear about it when a release you already follow matches. Write the interest the way you would say it — "Slack integrations with B2B software" is enough. Releases Index looks only at releases from the organizations and products you follow. When a new release matches, you get an email, a webhook, or both. The default confidence is 0.80, which you can raise or lower, and you can keep up to five interests. The words you write stay private to your account. Turn one on from Account → Notifications. Follows, the digest, and webhooks still cover every release you follow. An interest alert sits beside them, as the note for the release that is actually about the thing you named. - Interest alerts can now be edited and show recent match history — update the query, confidence level, or delivery channel from Account → Notifications and see how many times each alert matched in the last 7 and 30 days. - Weekly digests on the homepage — a full-width reel shows the latest issue from each collection with section rows, summaries on hover, and links that go directly to the upstream release; collection pages open with a latest-issue hero and week dividers in the feed. - Workspace webhooks — teams can add a shared Slack, Discord, or signed-JSON webhook under Account → Workspace → Webhooks; owners and admins manage it, members can view and test deliveries, and all owners and admins are notified on auto-pause.…

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

releases.sh

GitHub Action publish-changelog und automatische Erholung gestoppter Sources

Eine neue GitHub Action publish-changelog veröffentlicht Changelog-Einträge in eine Releases-Index-Source, zudem werden pixelige Avatar-Thumbnails als Medien ausgefiltert, still gestoppte Sources erholen sich selbst, und die Überschriften der Anmeldeseiten wurden vereinfacht.

**Added** - GitHub Action for publishing changelogs — a new `publish-changelog` Action diffs a changelog file on each push, maps changed sections onto upserted releases, and posts them to your Releases Index source; re-running the same commit is a no-op, and URL templates support heading permalink, date, version, and key formats. **Fixed** - Release cards no longer show pixelated avatar crops as inline media — the media filter now rejects CDN transform thumbnails where both resolved dimensions are ≤128 px (Cloudinary path transforms and imgix/Vercel query params), so only full-resolution editorial images appear. - Sources that silently stopped polling now self-heal — a successful manual fetch or re-enable re-arms the actor, and the hourly heartbeat folds unmanaged active sources into its pass so dead alarms recover within one tick rather than waiting out a full polling window. - Sign-in and create-account headings no longer surface a technical aside about API tokens — copy is simplified to focus on the product value.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

releases.sh

Selbst registrierte OAuth-Clients erhalten nur noch Identity- und Read-Scopes

Per Dynamic Client Registration selbst registrierte OAuth-Clients erhalten nur noch Identity- und Read-Scopes als öffentlicher PKCE-Client ohne Client Secret, während Schreib- und Admin-Zugriff nur für vom Betreiber bereitgestellte First-Party-Clients möglich bleibt.

**Fixed** - Dynamic Client Registration is now capped at read-only — OAuth clients that self-register (MCP tools, agent frameworks) receive at most identity and read scopes and are issued a public PKCE client with no client secret; write and admin access remain available only to operator-provisioned first-party clients.

Originalquelle(öffnet in neuem Tab)Problem melden