Skip to content

chore(main): release lns libraries - #175

Open
github-actions[bot] wants to merge 1 commit into
mainfrom
release-please--branches--main--groups--lns
Open

chore(main): release lns libraries#175
github-actions[bot] wants to merge 1 commit into
mainfrom
release-please--branches--main--groups--lns

Conversation

@github-actions

@github-actions github-actions Bot commented Jul 28, 2026

Copy link
Copy Markdown
Contributor

🤖 I have created a release beep boop

lns: 0.18.0

0.18.0 (2026-07-31)

⚠ BREAKING CHANGES

  • policy: adopt egress.http as the canonical route table
  • cli: lns volume inspect renames its keys, size_bytes to sizeBytes, disk_bytes to diskBytes and in_use_by to inUseBy. A script reading the old names gets null rather than an error, so update it before upgrading.

Features

  • a11y: label the approval window's dismiss controls (dbd6fa0)
  • add bump-mise operator tooling and move the Claude Code example onto spec.tools (a9e33be)
  • cache provisioned tool trees and record resolved versions per machine (e2cffe5)
  • cli: give lns audit --format table|jsonl (5ca1f7a)
  • cli: give lns config list and get --format json (02ccb74)
  • cli: give lns connector list and grants --format json (4b8d5b1)
  • cli: give lns policy list --format json (a8923d2)
  • cli: give lns ps --format json (feff7fa)
  • cli: give lns sandbox ls --format json (4075a6e)
  • cli: give lns service status --format json (55d8bbf)
  • cli: give lns volume ls --format json (c7db0b7)
  • cli: inspect, revoke, and disconnect-clear per-workload grants (a66f01d)
  • cli: shared machine-readable output seam (e7bb085)
  • cli: tell connect when this project holds a standing decline (6b527d3)
  • compose declared tools from cache, record, and provisioner with first-resolution pinning (7c0acfc)
  • declare developer tools via spec.tools with offline shape validation (4ad4964)
  • detect the workload image's libc flavor from its layer tars (364e00e)
  • disclose declared tools in inspect and the run summary (d4eb56f)
  • pin resolved tool versions into the published artifact at push (3a4489e)
  • pin the mise engine, provisioner rootfs images, and companion artifacts (8067146)
  • policy: add per-workload connector grant store (f852407)
  • policy: per-binary scoping for network routes (ae9d21b)
  • pre-provision a pulled sandbox's pinned tools so it starts offline (6ae5e5f)
  • provision declared tools in a disposable engine guest with a writable staging share (6321296)
  • provision declared tools pre-boot and prepend their bin paths to the workload PATH (b58a110)
  • publish an already-exact tool pin without the index (69565de)
  • re-resolve @latest tools against the index on every run (280dc49)
  • record a pull's tool acquisition on the machine audit chain (e7046aa)
  • record tool provisioning in the run's audit chain (5db2a73)
  • refuse unknown and plugin-backed tools against the pinned registry snapshot (18ddc23)
  • refuse unprovisionable tools at authoring time (ae81794)
  • report the tool versions a push pinned (d689f0e)
  • reuse a tool tree only where its guest-mates are trusted (5197c70)
  • service: gate connector arming on per-workload grants (4012673)
  • service: grant a value already bound on this machine from the card (d804661)
  • service: offer a reconnect alongside spending a bound connection (4e3f31a)
  • service: record per-workload connector grants at consent (45b0405)
  • service: remember a declined connector as a per-workload deny (a3a5772)
  • validate and disclose declared tools in the offline author verbs (05d2907)
  • warn at push when the index does not list an exact tool pin (f7ef447)

Bug Fixes

  • a closed network card reads as undecided on the wire (3943ac3)
  • allowlist an index-resolved version before it becomes a path (00c0b66)
  • allowlist declared tool versions so none can reach the driver shell (ef9a933)
  • artifact: refuse two credential slots naming one connector (fcd8a29)
  • bound staged tool tar ingestion (8325545)
  • bound the provisioner's stderr instead of failing on it (30d9101)
  • bound the version-index query so the fallback fires (691da53)
  • broker: carry confine through the linux-only session fixture (ec0b819)
  • broker: confine an exec session to the workload's identity (be05478)
  • broker: keep the relay credentials out of a confined session (7d3cbd4)
  • cache virtiofsd capability checks (a3acefd)
  • carry the version allowlist in the type that reaches the sinks (4d9b8c9)
  • claim a tool's source host only when the backend names one (7785bc6)
  • cli: clear per-workload grants before dropping a disconnected connector (06b62d3)
  • cli: default a bare registry reference to the Lens hub (6aa8261)
  • cli: make ps report the same status shape as inspect (8715bb6)
  • closing an approval card no longer decides anything (c3b0702)
  • disclose each tool as it commits, not after the set survives (ee5c473)
  • distinguish co-installed musl loaders (d2a5844)
  • gate unprovisionable tools at authoring, not on consume (458f0cb)
  • give each tool its own provisioner engine state (6392cbb)
  • give lns exec the run's own tool PATH (b7d00f8)
  • give the driver sole ownership of the marker channel (4df06c4)
  • honor OCI whiteouts in libc detection (3121a9b)
  • honor the record and manifest schema versions on load (522348c)
  • inject only the companion libs a tool links (0a5a04d)
  • keep a blank PATH segment out of every workload, not just a tooled one (368e07b)
  • keep a warm tool set out of the install queue (0838b9a)
  • keep blank segments off the workload PATH (1c014aa)
  • keep the engine off the warm musl path (dc1477b)
  • keep the guest stats probe's capture stdout-only (8b0841f)
  • keep the tool resolution record when prune reclaims the tool cache (fd88e03)
  • let a pull survive a failed tool pre-provision (80c30f8)
  • let a tool's own name win the registry snapshot row (3de5d73)
  • let a vendor-prefixed version resolve at push (e3cff2a)
  • let every prompting sandbox verb read the terminal it was invoked from (06663cd)
  • let no later layer overturn a musl loader (e686b73)
  • make an exact tool request cache-addressable without the record (af0e77e)
  • make guest content shares read-only (f735aaa)
  • make pull provisioning retry warning neutral (b5434a2)
  • make the provisioner guest boot and install against a live guest (b7961ba)
  • make the snapshot's backend the one mise actually installs from (ff56ce5)
  • make the tool record durable and its neighbours serialized (aef4586)
  • make tool provisioning a filterable, honestly-typed audit event (960a686)
  • map every writable bind, including the root provisioner's (9fa21bf)
  • measure a tool symlink against the path injection will create (3b477fb)
  • move tool tar ingest off the async worker (0099fa1)
  • parse the provisioner's markers from stdout alone (8083b7a)
  • pin the CA store to a snapshot upstream keeps (2db2c31)
  • policy: bound the wait for a contended grant-sidecar lock (c70fbee)
  • policy: let a disconnect cancel a grant the run is still holding (2afdf3c)
  • policy: serialize grant-sidecar writes across processes (8ebd4e9)
  • prune provisioned tool cache safely (cd8fa24)
  • publish a run's tool paths with the gate that exposes them (ddda302)
  • re-apply ingest's tar guards to a manifest read off disk (72cf5cb)
  • re-apply the tree guards to a manifest read off disk (e1ab69f)
  • reap a provisioner guest that never became reachable (e5f6eef)
  • recognize resolver-emitted vendor versions as exact pins (8297b99)
  • refuse a provisioner run that reports one tool twice (7d43298)
  • refuse a staged tool tar that is not the regular file we wrote (454ba27)
  • refuse a tool entry that lives under a symlink (4301a51)
  • refuse a tool symlink that points out of its own tree (a8680e7)
  • refuse a tool symlink whose double slash hides a level (4ef312a)
  • refuse driver-reported tool locations that escape the cache tree (2d663d0)
  • registry: route every registry client through one loopback-aware transport (653bc6d)
  • reject virtiofsd without readonly support (37f37ce)
  • release image cache lock before tool provisioning (81ff895)
  • require consent for published tool installers (902c26c)
  • resolve a hardlinked tool file to its ingested digest (364a7b4)
  • resolve the run before looking up its tool PATH for exec (a4be69c)
  • reuse co-installed latest tool trees (88ca7f5)
  • roll back partial mise bumps (78d769d)
  • run: confine the primary session when the run is unsupervised (d4f586d)
  • service: canonicalize a definition's workload identity directory (75844d6)
  • service: close four gaps in the per-workload grant lifecycle (a277c1a)
  • service: grant a required slot's boot sign-in to its workload (c3e0a4d)
  • service: let a disconnect cancel a boot sign-in's grant too (8c34e23)
  • service: offer a bound value only when one is actually bound (56f5977)
  • service: pin a grant decision to the forget count its card was asked against (8be2654)
  • service: point an unidentifiable run at the stale-service restart (930e688)
  • service: refuse a run that resolves no workload identity (70edc30)
  • service: revalidate deny grants and fix remember_grant ordering (b050418)
  • size pruned caches from metadata (136c5aa)
  • skip the libc memo when the layer set has no digests (99b5d4c)
  • stop dispatch re-locking the stdin its caller already holds (28ea217)
  • stop guessing aqua download hosts (06fd256)
  • stop the provisioner guest before its trees are named final (d9b65a2)
  • stop the push index read at the cap instead of after it (25f6927)
  • supervisor: drop capabilities when the run-as user is root (f7ae228)
  • supervisor: keep the run-as identity when the setuid is dropped (fd9c17a)
  • surface pull-time tool warnings (d6fa2b8)
  • validate dry-run tools before push preview (2228ea8)
  • warn about a differing digest only when a version is fuzzy (7bf9060)
  • write the mise bump's two files atomically (7860987)

Performance Improvements

  • keep the image libc scan off the async worker (918545a)
  • keep warm musl runs out of install queue (aa2581e)
  • memoize the image's libc flavor by its layer digests (e1d0903)
  • resolve latest tool pins concurrently (a3482cf)
  • reuse latest pins after install lock (30f3b14)
  • scan the pulled image's layers for libc in place (6133303)

Code Refactoring

  • policy: adopt egress.http as the canonical route table (f302a01)
e2e-tests: 0.18.0

0.18.0 (2026-07-31)

⚠ BREAKING CHANGES

  • policy: adopt egress.http as the canonical route table
  • cli: lns volume inspect renames its keys, size_bytes to sizeBytes, disk_bytes to diskBytes and in_use_by to inUseBy. A script reading the old names gets null rather than an error, so update it before upgrading.

Features

  • add bump-mise operator tooling and move the Claude Code example onto spec.tools (a9e33be)
  • cli: give lns volume ls --format json (c7db0b7)
  • declare developer tools via spec.tools with offline shape validation (4ad4964)
  • provision declared tools pre-boot and prepend their bin paths to the workload PATH (b58a110)

Bug Fixes

  • broker: confine an exec session to the workload's identity (be05478)
  • broker: keep the relay credentials out of a confined session (7d3cbd4)
  • claim a tool's source host only when the backend names one (7785bc6)
  • make the provisioner guest boot and install against a live guest (b7961ba)
  • stop dispatch re-locking the stdin its caller already holds (28ea217)
  • supervisor: drop capabilities when the run-as user is root (f7ae228)
  • supervisor: keep the run-as identity when the setuid is dropped (fd9c17a)

Performance Improvements

  • reuse latest pins after install lock (30f3b14)

Code Refactoring

  • policy: adopt egress.http as the canonical route table (f302a01)
lns-cli: 0.18.0

0.18.0 (2026-07-31)

⚠ BREAKING CHANGES

  • policy: adopt egress.http as the canonical route table
  • cli: lns volume inspect renames its keys, size_bytes to sizeBytes, disk_bytes to diskBytes and in_use_by to inUseBy. A script reading the old names gets null rather than an error, so update it before upgrading.

Features

  • add bump-mise operator tooling and move the Claude Code example onto spec.tools (a9e33be)
  • cli: give lns audit --format table|jsonl (5ca1f7a)
  • cli: give lns config list and get --format json (02ccb74)
  • cli: give lns connector list and grants --format json (4b8d5b1)
  • cli: give lns policy list --format json (a8923d2)
  • cli: give lns ps --format json (feff7fa)
  • cli: give lns sandbox ls --format json (4075a6e)
  • cli: give lns service status --format json (55d8bbf)
  • cli: give lns volume ls --format json (c7db0b7)
  • cli: inspect, revoke, and disconnect-clear per-workload grants (a66f01d)
  • cli: shared machine-readable output seam (e7bb085)
  • cli: tell connect when this project holds a standing decline (6b527d3)
  • declare developer tools via spec.tools with offline shape validation (4ad4964)
  • disclose declared tools in inspect and the run summary (d4eb56f)
  • pin resolved tool versions into the published artifact at push (3a4489e)
  • policy: per-binary scoping for network routes (ae9d21b)
  • publish an already-exact tool pin without the index (69565de)
  • re-resolve @latest tools against the index on every run (280dc49)
  • record a pull's tool acquisition on the machine audit chain (e7046aa)
  • report the tool versions a push pinned (d689f0e)
  • service: gate connector arming on per-workload grants (4012673)
  • validate and disclose declared tools in the offline author verbs (05d2907)
  • warn at push when the index does not list an exact tool pin (f7ef447)

Bug Fixes

  • bound the version-index query so the fallback fires (691da53)
  • claim a tool's source host only when the backend names one (7785bc6)
  • cli: clear per-workload grants before dropping a disconnected connector (06b62d3)
  • cli: default a bare registry reference to the Lens hub (6aa8261)
  • cli: make ps report the same status shape as inspect (8715bb6)
  • closing an approval card no longer decides anything (c3b0702)
  • gate unprovisionable tools at authoring, not on consume (458f0cb)
  • let every prompting sandbox verb read the terminal it was invoked from (06663cd)
  • make an exact tool request cache-addressable without the record (af0e77e)
  • make tool provisioning a filterable, honestly-typed audit event (960a686)
  • policy: let a disconnect cancel a grant the run is still holding (2afdf3c)
  • prune provisioned tool cache safely (cd8fa24)
  • recognize resolver-emitted vendor versions as exact pins (8297b99)
  • registry: route every registry client through one loopback-aware transport (653bc6d)
  • require consent for published tool installers (902c26c)
  • stop dispatch re-locking the stdin its caller already holds (28ea217)
  • stop the push index read at the cap instead of after it (25f6927)
  • surface pull-time tool warnings (d6fa2b8)
  • validate dry-run tools before push preview (2228ea8)
  • warn about a differing digest only when a version is fuzzy (7bf9060)

Performance Improvements

  • reuse latest pins after install lock (30f3b14)

Code Refactoring

  • policy: adopt egress.http as the canonical route table (f302a01)
lns-service: 0.18.0

0.18.0 (2026-07-31)

⚠ BREAKING CHANGES

  • policy: adopt egress.http as the canonical route table

Features

  • a11y: label the approval window's dismiss controls (dbd6fa0)
  • add bump-mise operator tooling and move the Claude Code example onto spec.tools (a9e33be)
  • cache provisioned tool trees and record resolved versions per machine (e2cffe5)
  • compose declared tools from cache, record, and provisioner with first-resolution pinning (7c0acfc)
  • declare developer tools via spec.tools with offline shape validation (4ad4964)
  • detect the workload image's libc flavor from its layer tars (364e00e)
  • disclose declared tools in inspect and the run summary (d4eb56f)
  • pin the mise engine, provisioner rootfs images, and companion artifacts (8067146)
  • policy: per-binary scoping for network routes (ae9d21b)
  • pre-provision a pulled sandbox's pinned tools so it starts offline (6ae5e5f)
  • provision declared tools in a disposable engine guest with a writable staging share (6321296)
  • provision declared tools pre-boot and prepend their bin paths to the workload PATH (b58a110)
  • re-resolve @latest tools against the index on every run (280dc49)
  • record a pull's tool acquisition on the machine audit chain (e7046aa)
  • record tool provisioning in the run's audit chain (5db2a73)
  • refuse unknown and plugin-backed tools against the pinned registry snapshot (18ddc23)
  • refuse unprovisionable tools at authoring time (ae81794)
  • reuse a tool tree only where its guest-mates are trusted (5197c70)
  • service: gate connector arming on per-workload grants (4012673)
  • service: grant a value already bound on this machine from the card (d804661)
  • service: offer a reconnect alongside spending a bound connection (4e3f31a)
  • service: record per-workload connector grants at consent (45b0405)
  • service: remember a declined connector as a per-workload deny (a3a5772)

Bug Fixes

  • a closed network card reads as undecided on the wire (3943ac3)
  • allowlist an index-resolved version before it becomes a path (00c0b66)
  • artifact: refuse two credential slots naming one connector (fcd8a29)
  • bound staged tool tar ingestion (8325545)
  • bound the provisioner's stderr instead of failing on it (30d9101)
  • bound the version-index query so the fallback fires (691da53)
  • broker: confine an exec session to the workload's identity (be05478)
  • cache virtiofsd capability checks (a3acefd)
  • carry the version allowlist in the type that reaches the sinks (4d9b8c9)
  • claim a tool's source host only when the backend names one (7785bc6)
  • closing an approval card no longer decides anything (c3b0702)
  • disclose each tool as it commits, not after the set survives (ee5c473)
  • distinguish co-installed musl loaders (d2a5844)
  • give each tool its own provisioner engine state (6392cbb)
  • give lns exec the run's own tool PATH (b7d00f8)
  • give the driver sole ownership of the marker channel (4df06c4)
  • honor OCI whiteouts in libc detection (3121a9b)
  • honor the record and manifest schema versions on load (522348c)
  • inject only the companion libs a tool links (0a5a04d)
  • keep a blank PATH segment out of every workload, not just a tooled one (368e07b)
  • keep a warm tool set out of the install queue (0838b9a)
  • keep blank segments off the workload PATH (1c014aa)
  • keep the engine off the warm musl path (dc1477b)
  • keep the guest stats probe's capture stdout-only (8b0841f)
  • keep the tool resolution record when prune reclaims the tool cache (fd88e03)
  • let a pull survive a failed tool pre-provision (80c30f8)
  • let a vendor-prefixed version resolve at push (e3cff2a)
  • let no later layer overturn a musl loader (e686b73)
  • make an exact tool request cache-addressable without the record (af0e77e)
  • make guest content shares read-only (f735aaa)
  • make pull provisioning retry warning neutral (b5434a2)
  • make the provisioner guest boot and install against a live guest (b7961ba)
  • make the snapshot's backend the one mise actually installs from (ff56ce5)
  • make the tool record durable and its neighbours serialized (aef4586)
  • make tool provisioning a filterable, honestly-typed audit event (960a686)
  • map every writable bind, including the root provisioner's (9fa21bf)
  • measure a tool symlink against the path injection will create (3b477fb)
  • move tool tar ingest off the async worker (0099fa1)
  • parse the provisioner's markers from stdout alone (8083b7a)
  • pin the CA store to a snapshot upstream keeps (2db2c31)
  • policy: let a disconnect cancel a grant the run is still holding (2afdf3c)
  • prune provisioned tool cache safely (cd8fa24)
  • publish a run's tool paths with the gate that exposes them (ddda302)
  • re-apply ingest's tar guards to a manifest read off disk (72cf5cb)
  • re-apply the tree guards to a manifest read off disk (e1ab69f)
  • reap a provisioner guest that never became reachable (e5f6eef)
  • recognize resolver-emitted vendor versions as exact pins (8297b99)
  • refuse a provisioner run that reports one tool twice (7d43298)
  • refuse a staged tool tar that is not the regular file we wrote (454ba27)
  • refuse a tool entry that lives under a symlink (4301a51)
  • refuse a tool symlink that points out of its own tree (a8680e7)
  • refuse a tool symlink whose double slash hides a level (4ef312a)
  • refuse driver-reported tool locations that escape the cache tree (2d663d0)
  • registry: route every registry client through one loopback-aware transport (653bc6d)
  • reject virtiofsd without readonly support (37f37ce)
  • release image cache lock before tool provisioning (81ff895)
  • require consent for published tool installers (902c26c)
  • resolve a hardlinked tool file to its ingested digest (364a7b4)
  • resolve the run before looking up its tool PATH for exec (a4be69c)
  • reuse co-installed latest tool trees (88ca7f5)
  • run: confine the primary session when the run is unsupervised (d4f586d)
  • service: canonicalize a definition's workload identity directory (75844d6)
  • service: close four gaps in the per-workload grant lifecycle (a277c1a)
  • service: grant a required slot's boot sign-in to its workload (c3e0a4d)
  • service: let a disconnect cancel a boot sign-in's grant too (8c34e23)
  • service: offer a bound value only when one is actually bound (56f5977)
  • service: pin a grant decision to the forget count its card was asked against (8be2654)
  • service: point an unidentifiable run at the stale-service restart (930e688)
  • service: refuse a run that resolves no workload identity (70edc30)
  • service: revalidate deny grants and fix remember_grant ordering (b050418)
  • size pruned caches from metadata (136c5aa)
  • skip the libc memo when the layer set has no digests (99b5d4c)
  • stop dispatch re-locking the stdin its caller already holds (28ea217)
  • stop guessing aqua download hosts (06fd256)
  • stop the provisioner guest before its trees are named final (d9b65a2)
  • stop the push index read at the cap instead of after it (25f6927)
  • surface pull-time tool warnings (d6fa2b8)
  • warn about a differing digest only when a version is fuzzy (7bf9060)

Performance Improvements

  • keep the image libc scan off the async worker (918545a)
  • keep warm musl runs out of install queue (aa2581e)
  • memoize the image's libc flavor by its layer digests (e1d0903)
  • resolve latest tool pins concurrently (a3482cf)
  • reuse latest pins after install lock (30f3b14)
  • scan the pulled image's layers for libc in place (6133303)

Code Refactoring

  • policy: adopt egress.http as the canonical route table (f302a01)

This PR was generated with Release Please. See documentation.

@github-actions github-actions Bot added autorelease: pending release Release PR managed by release-please labels Jul 28, 2026
@github-actions
github-actions Bot force-pushed the release-please--branches--main--groups--lns branch 8 times, most recently from 1ef5ea5 to 4a192d6 Compare July 31, 2026 07:46
@github-actions
github-actions Bot force-pushed the release-please--branches--main--groups--lns branch from 4a192d6 to 0fa8b85 Compare July 31, 2026 13:28
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

autorelease: pending release Release PR managed by release-please

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants