From 37444e17c3e8553a73e10c10074d91c16664b750 Mon Sep 17 00:00:00 2001 From: "github-actions[bot]" <41898282+github-actions[bot]@users.noreply.github.com> Date: Fri, 4 Sep 2026 20:45:38 +0000 Subject: [PATCH] ci: release --- .changeset/atomic-expected-publish.md | 5 - .changeset/bounded-media-usage-gc-scan.md | 5 - .changeset/bright-images-replace.md | 8 -- .changeset/byline-finder-avatar-join.md | 19 ---- .changeset/calm-drafts-remember.md | 5 - .changeset/calm-media-crops.md | 9 -- .changeset/calm-ravens-prepare.md | 11 -- .changeset/calm-seals-verify.md | 5 - .changeset/clean-otters-prove.md | 13 --- .changeset/clean-rivers-browse.md | 10 -- .changeset/clear-media-usage-tabs.md | 5 - .changeset/delegated-release-client.md | 16 --- .changeset/draft-overwrite-rev-2121.md | 5 - .changeset/easy-delegated-releases.md | 8 -- .changeset/fair-otters-refresh.md | 7 -- .changeset/fresh-astro-loggers.md | 5 - .changeset/fresh-icons-fill.md | 5 - .changeset/large-media-cards.md | 5 - .changeset/passkey-uv-context.md | 12 --- .changeset/preserve-media-source-identity.md | 6 -- .changeset/quiet-publish-flush.md | 5 - .changeset/sandboxed-save-rejection.md | 21 ---- .changeset/scheduled-sweep-index.md | 5 - .changeset/secure-workflow-invitations.md | 8 -- .changeset/subtle-media-transparency.md | 5 - .changeset/swift-verifiers-match.md | 13 --- .changeset/taxonomy-get-locale-description.md | 5 - .changeset/verify-registry-bundles.md | 28 ----- apps/labeler/CHANGELOG.md | 7 ++ apps/labeler/package.json | 2 +- apps/release-action/CHANGELOG.md | 9 ++ apps/release-action/package.json | 2 +- apps/release-service/CHANGELOG.md | 10 ++ apps/release-service/package.json | 2 +- apps/release-verifier/CHANGELOG.md | 8 ++ apps/release-verifier/package.json | 2 +- fixtures/perf-site/CHANGELOG.md | 8 ++ fixtures/perf-site/package.json | 2 +- infra/blog-demo/CHANGELOG.md | 10 ++ infra/blog-demo/package.json | 2 +- infra/cache-demo/CHANGELOG.md | 10 ++ infra/cache-demo/package.json | 2 +- infra/do-demo/CHANGELOG.md | 10 ++ infra/do-demo/package.json | 2 +- infra/do-solo-demo/CHANGELOG.md | 10 ++ infra/do-solo-demo/package.json | 2 +- packages/admin/CHANGELOG.md | 78 ++++++++++++++ packages/admin/package.json | 2 +- packages/auth-atproto/CHANGELOG.md | 7 ++ packages/auth-atproto/package.json | 2 +- packages/auth/CHANGELOG.md | 12 +++ packages/auth/package.json | 2 +- packages/blocks/CHANGELOG.md | 2 + packages/blocks/package.json | 2 +- packages/cloudflare/CHANGELOG.md | 11 ++ packages/cloudflare/package.json | 2 +- packages/core/CHANGELOG.md | 101 ++++++++++++++++++ packages/core/package.json | 2 +- packages/create-emdash/CHANGELOG.md | 2 + packages/create-emdash/package.json | 2 +- .../gutenberg-to-portable-text/CHANGELOG.md | 2 + .../gutenberg-to-portable-text/package.json | 2 +- packages/plugin-cli/CHANGELOG.md | 39 +++++++ packages/plugin-cli/package.json | 2 +- packages/plugins/embeds/CHANGELOG.md | 7 ++ packages/plugins/embeds/package.json | 2 +- packages/registry-client/CHANGELOG.md | 63 +++++++++++ packages/registry-client/package.json | 2 +- packages/registry-verification/CHANGELOG.md | 46 ++++++++ packages/registry-verification/package.json | 2 +- packages/workerd/CHANGELOG.md | 7 ++ packages/workerd/package.json | 2 +- packages/x402/CHANGELOG.md | 2 + packages/x402/package.json | 2 +- 74 files changed, 484 insertions(+), 277 deletions(-) delete mode 100644 .changeset/atomic-expected-publish.md delete mode 100644 .changeset/bounded-media-usage-gc-scan.md delete mode 100644 .changeset/bright-images-replace.md delete mode 100644 .changeset/byline-finder-avatar-join.md delete mode 100644 .changeset/calm-drafts-remember.md delete mode 100644 .changeset/calm-media-crops.md delete mode 100644 .changeset/calm-ravens-prepare.md delete mode 100644 .changeset/calm-seals-verify.md delete mode 100644 .changeset/clean-otters-prove.md delete mode 100644 .changeset/clean-rivers-browse.md delete mode 100644 .changeset/clear-media-usage-tabs.md delete mode 100644 .changeset/delegated-release-client.md delete mode 100644 .changeset/draft-overwrite-rev-2121.md delete mode 100644 .changeset/easy-delegated-releases.md delete mode 100644 .changeset/fair-otters-refresh.md delete mode 100644 .changeset/fresh-astro-loggers.md delete mode 100644 .changeset/fresh-icons-fill.md delete mode 100644 .changeset/large-media-cards.md delete mode 100644 .changeset/passkey-uv-context.md delete mode 100644 .changeset/preserve-media-source-identity.md delete mode 100644 .changeset/quiet-publish-flush.md delete mode 100644 .changeset/sandboxed-save-rejection.md delete mode 100644 .changeset/scheduled-sweep-index.md delete mode 100644 .changeset/secure-workflow-invitations.md delete mode 100644 .changeset/subtle-media-transparency.md delete mode 100644 .changeset/swift-verifiers-match.md delete mode 100644 .changeset/taxonomy-get-locale-description.md delete mode 100644 .changeset/verify-registry-bundles.md create mode 100644 apps/release-action/CHANGELOG.md create mode 100644 apps/release-service/CHANGELOG.md create mode 100644 apps/release-verifier/CHANGELOG.md diff --git a/.changeset/atomic-expected-publish.md b/.changeset/atomic-expected-publish.md deleted file mode 100644 index b64e17ef2c..0000000000 --- a/.changeset/atomic-expected-publish.md +++ /dev/null @@ -1,5 +0,0 @@ ---- -"emdash": patch ---- - -Fixes publication workflows so callers can pass the approved `_rev` to publish, unpublish, or discard a draft and receive a `CONFLICT` response when the entry changed. Calls that omit `_rev` keep the existing behavior. diff --git a/.changeset/bounded-media-usage-gc-scan.md b/.changeset/bounded-media-usage-gc-scan.md deleted file mode 100644 index cda8c48f91..0000000000 --- a/.changeset/bounded-media-usage-gc-scan.md +++ /dev/null @@ -1,5 +0,0 @@ ---- -"emdash": patch ---- - -Fixes scheduled media-usage cleanup reading far more rows than its batch size on large sites. A cleanup run that had lost its lease scanned the whole occurrence table before returning nothing, so cron ticks could spike into the hundreds of thousands of rows read. Sites on Cloudflare D1 will see those spikes disappear. diff --git a/.changeset/bright-images-replace.md b/.changeset/bright-images-replace.md deleted file mode 100644 index 9fcdc99c4c..0000000000 --- a/.changeset/bright-images-replace.md +++ /dev/null @@ -1,8 +0,0 @@ ---- -"emdash": minor -"@emdash-cms/admin": minor ---- - -Adds **Replace image** to the Media Library for ready JPEG, PNG, and WebP files stored by EmDash. - -Choose a same-format file to update every existing use of an image while preserving its media ID, filename, URL, alt text, caption, and location. The replacement can use different dimensions or an aspect ratio from the original. EmDash overwrites the original bytes and clears the focal point; it does not retain the previous file. The action works with local disk, R2, and S3-compatible storage. diff --git a/.changeset/byline-finder-avatar-join.md b/.changeset/byline-finder-avatar-join.md deleted file mode 100644 index d97ec57275..0000000000 --- a/.changeset/byline-finder-avatar-join.md +++ /dev/null @@ -1,19 +0,0 @@ ---- -"emdash": patch ---- - -Fixes byline profile pages having no way to render the byline's avatar ([#2613](https://github.com/emdash-cms/emdash/issues/2613)). `getByline`, `getBylineBySlug`, and the underlying single-row `BylineRepository` finders now resolve the avatar's media row in the same query, so `avatarStorageKey`, `avatarAlt`, `avatarBlurhash`, and `avatarDominantColor` are populated alongside `avatarMediaId`: - -```astro ---- -import { getBylineBySlug } from "emdash"; - -const byline = await getBylineBySlug(Astro.params.slug, { locale: Astro.currentLocale }); -const avatar = byline?.avatarStorageKey - ? Astro.locals.emdash.getPublicMediaUrl(byline.avatarStorageKey) - : null; ---- -{avatar && {byline.avatarAlt} -``` - -Previously these fields were populated only when a byline was hydrated as a credit on a content entry, so a page keyed on the byline itself — `/authors/` and the like — held a bare media id with no public API to turn it into a URL. Nothing else changes: the lookup still costs one query (the avatar is a `LEFT JOIN`, not a second round trip), and `findMany` still skips the join, so byline list pages are unaffected. diff --git a/.changeset/calm-drafts-remember.md b/.changeset/calm-drafts-remember.md deleted file mode 100644 index a108b9d458..0000000000 --- a/.changeset/calm-drafts-remember.md +++ /dev/null @@ -1,5 +0,0 @@ ---- -"emdash": patch ---- - -Fixes unpublishing content resetting its publication date. Previously published drafts keep their date visible and editable in the admin, and republishing them without a date override reuses it. diff --git a/.changeset/calm-media-crops.md b/.changeset/calm-media-crops.md deleted file mode 100644 index 87467f2d00..0000000000 --- a/.changeset/calm-media-crops.md +++ /dev/null @@ -1,9 +0,0 @@ ---- -"emdash": minor -"@emdash-cms/admin": minor -"@emdash-cms/cloudflare": patch ---- - -Adds cropping for JPEG, PNG, and WebP images stored by EmDash on local disk, Cloudflare R2, or S3-compatible storage. - -Move and resize a rule-of-thirds crop frame with corner handles for fixed ratios and eight handles for Freeform. Choose the original ratio, Freeform, or a common aspect ratio. **Create cropped copy** creates a separate media item with any ratio and names it for the selected ratio or output dimensions. **Replace original** uses the original ratio and replaces the existing item under the same ID and URL, so every reference uses the cropped image without rewriting or republishing content. Local media and responsive renditions revalidate their stable URLs so sites load the replacement instead of keeping a stale cached image. The original bytes and crop history are not retained. diff --git a/.changeset/calm-ravens-prepare.md b/.changeset/calm-ravens-prepare.md deleted file mode 100644 index 4e453d4be7..0000000000 --- a/.changeset/calm-ravens-prepare.md +++ /dev/null @@ -1,11 +0,0 @@ ---- -"@emdash-cms/plugin-cli": minor -"@emdash-cms/registry-client": minor -"@emdash-cms/registry-verification": minor ---- - -Adds interactive package-profile setup for delegated plugin releases. `emdash-plugin release setup` now creates a missing profile or adds delegated-release settings to an existing valid profile before writing the GitHub Actions workflow. Run `emdash-plugin profile setup` to prepare only the profile. - -Interactive setup asks for the GitHub repository when it is absent from `emdash-plugin.jsonc`, lets you choose when releases require approval, and confirms the profile write. Non-interactive callers must pass `--yes` when a profile change is required. - -The release service returns `PACKAGE_PROFILE_REQUIRED` before accepting artifact uploads when the signed profile is missing, lacks delegated-release settings, or names a different GitHub repository. Existing release intents also terminate with an actionable reason if their authoritative profile becomes invalid. diff --git a/.changeset/calm-seals-verify.md b/.changeset/calm-seals-verify.md deleted file mode 100644 index 60602ab085..0000000000 --- a/.changeset/calm-seals-verify.md +++ /dev/null @@ -1,5 +0,0 @@ ---- -"@emdash-cms/registry-verification": patch ---- - -Fixes delegated-release provenance verification so verified GitHub attestations include the repository, workflow, commit, and run identity needed to enforce an exact authorized workload. diff --git a/.changeset/clean-otters-prove.md b/.changeset/clean-otters-prove.md deleted file mode 100644 index 6c9bdaf758..0000000000 --- a/.changeset/clean-otters-prove.md +++ /dev/null @@ -1,13 +0,0 @@ ---- -"@emdash-cms/registry-client": minor ---- - -Adds `DirectPdsClient.getPackageRepository()` for reading a package profile and every package release from one proof-verified AT Protocol repository export. - -Use the method when authorization or version selection requires a complete signed package snapshot: - -```ts -const { profile, releases } = await directPdsClient.getPackageRepository("gallery"); -``` - -The client verifies the repository commit signature, record blocks, and complete Merkle search tree before returning records. Unsigned `repo.getRecord` and `repo.listRecords` envelopes cannot substitute or omit package data. Repository exports use the client's `maxResponseBytes` limit, which defaults to 5 MiB, and a missing export reports `REPOSITORY_NOT_FOUND`. diff --git a/.changeset/clean-rivers-browse.md b/.changeset/clean-rivers-browse.md deleted file mode 100644 index 6ea047ccdb..0000000000 --- a/.changeset/clean-rivers-browse.md +++ /dev/null @@ -1,10 +0,0 @@ ---- -"@emdash-cms/admin": minor ---- - -Adds Media Library browsing and inline uploads to admin media pickers. Editors can search, filter -by type, browse folders, switch between grid and list views, use numbered pages, and select media -from configured providers or a direct URL without leaving the content editor. - -Uploads appear in the picker with an uploading or failed status. Successful uploads become -selected media cards, and gallery selections can be reordered before they are added. diff --git a/.changeset/clear-media-usage-tabs.md b/.changeset/clear-media-usage-tabs.md deleted file mode 100644 index 5d7d2377cc..0000000000 --- a/.changeset/clear-media-usage-tabs.md +++ /dev/null @@ -1,5 +0,0 @@ ---- -"@emdash-cms/admin": patch ---- - -Adds a dedicated **Used in** tab to media details, keeping file information and focal-point controls separate from usage references. diff --git a/.changeset/delegated-release-client.md b/.changeset/delegated-release-client.md deleted file mode 100644 index f7673a7bac..0000000000 --- a/.changeset/delegated-release-client.md +++ /dev/null @@ -1,16 +0,0 @@ ---- -"@emdash-cms/registry-client": minor -"@emdash-cms/plugin-cli": minor ---- - -Adds typed clients for the experimental delegated release service. `ReleaseServiceClient` submits, polls, and cancels GitHub OpenID Connect release intents; manages publisher workload policies and retained delegation; and lets publishers check whether profile-listed approvers have an active passkey and inspect publisher-scoped audit events through a publisher session. `ReleaseServiceOperatorClient` exposes the Cloudflare Access status and sanitized audit, sharded publisher and approver inventory, pause, suspension, revocation, cancellation, reconciliation, resumable encryption-key rotation, Workflow-backed fleet verification, audited key retirement, encrypted R2 archive, and fail-safe publisher restore and abort operations. - -`ReleaseServiceClient` can request, poll, list, and confirm GitHub workflow connections. The first permanent release run records GitHub's signed repository, workflow, ref, and environment as a pending request and returns a browser approval URL. The publisher must confirm those details before the service creates a workload policy. Tag-based connections can cover the current tag or all version tags while keeping the repository and workflow path exact. - -Both clients validate response envelopes and return stable `ReleaseServiceError` codes with retry metadata. Mutation helpers require idempotency keys, and workload polling requests a fresh token from the configured provider for each call. - -The plugin CLI adds `emdash-plugin release dry-run`, `release submit`, `release status`, and `release cancel` for GitHub Actions jobs. The first `release submit` requests browser approval for the permanent workflow and waits for confirmation before creating an intent. Dry-run verifies existing workload admission without creating a connection request, intent, consuming rate budget, or reserving a version. The commands request audience-bound OIDC tokens from the runner, support JSON output, and use the GitHub run identity as the default idempotency key where a mutation occurs. - -Delegated submissions use a URL-source release record: each package or listing-image artifact supplies a checksum-bound HTTPS URL and no blob. The service stages and uploads those bytes through the publisher's delegation, then creates a blob-only release record. Submit and dry-run reject mixed or blob-backed source inputs before requesting GitHub OIDC. - -Interactive `release delegate`, `revoke`, `workload`, `enrol`, `approve`, and `reject` commands print validated browser handoffs. Publisher application sessions, OAuth credentials, and passkey assertions remain at the release-service origin instead of entering the terminal process. diff --git a/.changeset/draft-overwrite-rev-2121.md b/.changeset/draft-overwrite-rev-2121.md deleted file mode 100644 index 655a00cd5d..0000000000 --- a/.changeset/draft-overwrite-rev-2121.md +++ /dev/null @@ -1,5 +0,0 @@ ---- -"@emdash-cms/admin": patch ---- - -Fixes a silent draft-overwrite in the page editor. The editor now echoes the entry's `_rev` token on save and autosave, so the server rejects a save that is based on a stale read with a 409 conflict instead of silently replacing a newer draft revision. Editors who hit a conflict now see a clear error and can reload instead of losing work. diff --git a/.changeset/easy-delegated-releases.md b/.changeset/easy-delegated-releases.md deleted file mode 100644 index 82672d9bd1..0000000000 --- a/.changeset/easy-delegated-releases.md +++ /dev/null @@ -1,8 +0,0 @@ ---- -"@emdash-cms/plugin-cli": minor -"@emdash-cms/registry-client": minor ---- - -Adds `emdash-plugin release setup` to create the permanent GitHub Actions workflow for delegated plugin releases. The generated workflow builds and attests the plugin, waits for first-run browser authorization, and uploads its exact bundle and provenance through GitHub OIDC before publishing. - -`ReleaseServiceClient.uploadReleaseArtifact()` supports custom workflows that need to stage checksum-bound bundle, image, or provenance bytes. Existing URL-source `release submit` workflows remain supported. diff --git a/.changeset/fair-otters-refresh.md b/.changeset/fair-otters-refresh.md deleted file mode 100644 index 2fd7e6ebc4..0000000000 --- a/.changeset/fair-otters-refresh.md +++ /dev/null @@ -1,7 +0,0 @@ ---- -"@emdash-cms/plugin-cli": patch ---- - -Fixes saved OAuth sessions failing to refresh or revoke after the original loopback callback server closes. New logins retain the loopback client registration needed to recreate the same OAuth client. - -Sessions created before this fix do not contain that registration metadata and cannot be resumed. Sign in again after upgrading. diff --git a/.changeset/fresh-astro-loggers.md b/.changeset/fresh-astro-loggers.md deleted file mode 100644 index 3a924bdc20..0000000000 --- a/.changeset/fresh-astro-loggers.md +++ /dev/null @@ -1,5 +0,0 @@ ---- -"emdash": patch ---- - -Fixes Cloudflare development servers failing during cold start with Astro 7.3.1 after Vite discovers `astro/logger/console` and invalidates prebundled server chunks. diff --git a/.changeset/fresh-icons-fill.md b/.changeset/fresh-icons-fill.md deleted file mode 100644 index 2569f7b12c..0000000000 --- a/.changeset/fresh-icons-fill.md +++ /dev/null @@ -1,5 +0,0 @@ ---- -"@emdash-cms/admin": patch ---- - -Updates sidebar navigation icons to use Phosphor's filled style for the active page. diff --git a/.changeset/large-media-cards.md b/.changeset/large-media-cards.md deleted file mode 100644 index 580e40859e..0000000000 --- a/.changeset/large-media-cards.md +++ /dev/null @@ -1,5 +0,0 @@ ---- -"@emdash-cms/admin": patch ---- - -Updates Media Library grid cards to show filenames and file formats below larger previews. diff --git a/.changeset/passkey-uv-context.md b/.changeset/passkey-uv-context.md deleted file mode 100644 index 5d1011c695..0000000000 --- a/.changeset/passkey-uv-context.md +++ /dev/null @@ -1,12 +0,0 @@ ---- -"@emdash-cms/auth": minor -"emdash": patch ---- - -Adds `PasskeyConfig.userVerification` so sites can require, prefer, or discourage passkey user verification. Existing callers keep the `preferred` behavior. - -Adds typed, versioned challenge contexts for registration and authentication. Declare a codec with `defineChallengeContext()`, bind data with `bindChallengeContext()` when generating options, and pass the codec with an `AtomicChallengeStore` to `verifyAuthenticationResponse()` or `verifyRegistrationResponse()` to recover the typed value after verification. - -Atomic challenge stores declare `readonly atomic: true`, so an unrelated `consume()` method on an existing challenge store cannot silently change its behavior. EmDash retains optional challenge context data in its database-backed challenge store. - -Authentication rejects assertions whose signature counter drops from a nonzero value to zero because the counter change can indicate a cloned authenticator. diff --git a/.changeset/preserve-media-source-identity.md b/.changeset/preserve-media-source-identity.md deleted file mode 100644 index 053e6d2af5..0000000000 --- a/.changeset/preserve-media-source-identity.md +++ /dev/null @@ -1,6 +0,0 @@ ---- -"@emdash-cms/admin": patch -"emdash": patch ---- - -Fixes image fields and Portable Text editors so they preserve direct image URLs and external provider identities, allowing selected images to continue rendering after saving or replacement. diff --git a/.changeset/quiet-publish-flush.md b/.changeset/quiet-publish-flush.md deleted file mode 100644 index 5ed01f1982..0000000000 --- a/.changeset/quiet-publish-flush.md +++ /dev/null @@ -1,5 +0,0 @@ ---- -"@emdash-cms/admin": patch ---- - -Fixes Publish saving and awaiting the editor's latest changes before making content live. Validation errors, failed saves, and revision conflicts now stop publishing instead of promoting stale draft data. diff --git a/.changeset/sandboxed-save-rejection.md b/.changeset/sandboxed-save-rejection.md deleted file mode 100644 index d80dd425e2..0000000000 --- a/.changeset/sandboxed-save-rejection.md +++ /dev/null @@ -1,21 +0,0 @@ ---- -"emdash": patch -"@emdash-cms/admin": patch ---- - -Fixes sandboxed `content:beforeSave` hooks being unable to reject content creation or updates. - -Return a version 1 sandbox hook result with a `SAVE_REJECTED` error to stop the save and show the reason to the editor: - -```ts -return { - __emdashSandboxHookResult: true, - version: 1, - error: { - code: "SAVE_REJECTED", - reason: "Add a title before saving.", - }, -}; -``` - -The reason must contain 1–500 characters of plain text. Invalid error results and unexpected sandbox exceptions stop the save with a generic hook error instead of exposing internal details. diff --git a/.changeset/scheduled-sweep-index.md b/.changeset/scheduled-sweep-index.md deleted file mode 100644 index e8ecb7afcb..0000000000 --- a/.changeset/scheduled-sweep-index.md +++ /dev/null @@ -1,5 +0,0 @@ ---- -"emdash": patch ---- - -Fixes scheduled publishing so its recurring check no longer reads every content entry on each run. Sites running the scheduler on a frequent cron trigger, as the Cloudflare deployment guide recommends, previously saw database reads grow with the size of their content library rather than with the amount of scheduled work — a cost that is directly billable on D1 and was paid even when nothing was scheduled. Existing sites pick up the fix when migrations run on upgrade; no configuration or code changes are needed. diff --git a/.changeset/secure-workflow-invitations.md b/.changeset/secure-workflow-invitations.md deleted file mode 100644 index 739da3b541..0000000000 --- a/.changeset/secure-workflow-invitations.md +++ /dev/null @@ -1,8 +0,0 @@ ---- -"@emdash-cms/registry-client": minor -"@emdash-cms/plugin-cli": patch ---- - -Adds publisher-created workflow connection invitations to delegated releases. First-time or unmatched GitHub workflows must use a package-bound, single-use invitation before they can request publisher approval; connected workflows continue without one. - -Create the invitation in the publisher dashboard or with `createWorkflowConnectionInvitation()`, then save its value as the repository's `EMDASH_CONNECTION_INVITATION` GitHub Actions secret. The generated release workflow passes this secret to the release Action automatically. Custom workflows can pass `invitationToken` to `requestWorkflowConnection()`, and publishers can reject pending requests with `rejectWorkflowConnection()`. diff --git a/.changeset/subtle-media-transparency.md b/.changeset/subtle-media-transparency.md deleted file mode 100644 index 14e123ba67..0000000000 --- a/.changeset/subtle-media-transparency.md +++ /dev/null @@ -1,5 +0,0 @@ ---- -"@emdash-cms/admin": patch ---- - -Updates image previews to show a theme-aware checkerboard behind transparent areas. diff --git a/.changeset/swift-verifiers-match.md b/.changeset/swift-verifiers-match.md deleted file mode 100644 index 5c33420e08..0000000000 --- a/.changeset/swift-verifiers-match.md +++ /dev/null @@ -1,13 +0,0 @@ ---- -"@emdash-cms/registry-verification": minor ---- - -Adds optional artifact digest candidates to `GitHubProvenanceVerifier`, allowing callers that compute several supported digest algorithms in one isolated artifact fetch to verify the digest selected by a signed SLSA provenance subject. - -Existing callers can continue passing only `artifactDigest`. Successful results return the candidate that matched the signed subject. - -Fixes `@emdash-cms/registry-verification` when it is rebundled into an Astro Cloudflare application, preventing requests from failing during Worker startup. - -Adds `@emdash-cms/registry-verification/records` for Worker callers that supply an explicit `ProvenanceVerifier`. The runtime-neutral entry does not load the Node-oriented default Sigstore verifier, while the package root keeps the existing default-verifier behavior. - -Fixes `@emdash-cms/registry-verification` when it is rebundled into an Astro Cloudflare application, preventing requests from failing during Worker startup. diff --git a/.changeset/taxonomy-get-locale-description.md b/.changeset/taxonomy-get-locale-description.md deleted file mode 100644 index 34b779b9f0..0000000000 --- a/.changeset/taxonomy-get-locale-description.md +++ /dev/null @@ -1,5 +0,0 @@ ---- -"emdash": patch ---- - -Fixes the OpenAPI description for `GET /_emdash/api/taxonomies/{name}`, which said that omitting `locale` returns the lowest-locale definition. The endpoint returns the configured default locale's definition and only falls back to the lowest locale code when the default locale has none. Behavior is unchanged; only the generated API description was wrong. diff --git a/.changeset/verify-registry-bundles.md b/.changeset/verify-registry-bundles.md deleted file mode 100644 index a25da46430..0000000000 --- a/.changeset/verify-registry-bundles.md +++ /dev/null @@ -1,28 +0,0 @@ ---- -"emdash": minor -"@emdash-cms/admin": minor -"@emdash-cms/registry-client": minor -"@emdash-cms/registry-verification": minor ---- - -Adds `DirectPdsClient` for reading package profiles and releases with AT Protocol repository proofs, and updates experimental decentralized registry installs and updates to verify current signed records directly from the publisher's PDS. - -#### Aggregator record integrity - -Install and update reject aggregator-supplied profile or release metadata whose URI or CID does not match the publisher's signed records. The server returns `AGGREGATOR_RECORD_MISMATCH` before fetching the artifact or requesting consent. - -#### Publisher identity display - -The admin treats handle resolution as an advisory identity signal. It keeps the install button disabled while attempting to resolve the package DID back to a handle, then blocks installation when `resolveDidToHandle()` conclusively returns `"invalid"`. An indeterminate result caused by a network failure, unsupported DID method, or missing handle displays the publisher DID and does not block installation. - -Install and update trust the publisher DID and the signed repository proofs for the profile and release records. A handle is display metadata and is not an authorization or record-integrity input. - -#### Provenance and release policy - -The installer applies the signed profile's release policy, independently fetches and verifies supplied Sigstore/SLSA provenance, and binds moderation labels to the exact profile or release CID. Missing required provenance and any supplied provenance that is unavailable, malformed, mismatched, or unsupported block installation and updates. Artifact checksums, archive paths, bundle limits, manifest identity, and version use the same verification rules as the registry release tooling. - -The verification package also exports `inspectPackageReleaseRecords` for validating signed records and policy before artifact and provenance evidence is available. - -Registry install and update consent now show the exact verified profile and release CIDs, signed publisher policy, and provenance status. Install consent uses permissions and MCP tools read from the verified bundle rather than the aggregator's record copy. - -Install, update, and delegated-release verification require lowercase base32 multibase `sha2-256` multihashes for package artifacts and provenance documents. The plugin CLI already produces this format. The authenticated image-artifact proxy still accepts legacy bare hexadecimal SHA-256 checksums for display-only images. diff --git a/apps/labeler/CHANGELOG.md b/apps/labeler/CHANGELOG.md index d2a56de11b..197d89bd1c 100644 --- a/apps/labeler/CHANGELOG.md +++ b/apps/labeler/CHANGELOG.md @@ -1,5 +1,12 @@ # @emdash-cms/labeler +## 0.0.2 + +### Patch Changes + +- Updated dependencies [[`66aeecd`](https://github.com/emdash-cms/emdash/commit/66aeecd1feded23c2ee607b799500c390a04eb92), [`529b28b`](https://github.com/emdash-cms/emdash/commit/529b28bd1c0e4257eaa4436721b110beb09d5ba3), [`c7b6fdf`](https://github.com/emdash-cms/emdash/commit/c7b6fdfd1f5dd9a168f5d0f6bfa9b7b9ff343145), [`c7b6fdf`](https://github.com/emdash-cms/emdash/commit/c7b6fdfd1f5dd9a168f5d0f6bfa9b7b9ff343145)]: + - @emdash-cms/registry-verification@0.3.0 + ## 0.0.1 ### Patch Changes diff --git a/apps/labeler/package.json b/apps/labeler/package.json index b53916c836..8aede94518 100644 --- a/apps/labeler/package.json +++ b/apps/labeler/package.json @@ -1,6 +1,6 @@ { "name": "@emdash-cms/labeler", - "version": "0.0.1", + "version": "0.0.2", "private": true, "description": "Metadata-only moderation labeler for the EmDash plugin registry.", "type": "module", diff --git a/apps/release-action/CHANGELOG.md b/apps/release-action/CHANGELOG.md new file mode 100644 index 0000000000..ec1f8c4454 --- /dev/null +++ b/apps/release-action/CHANGELOG.md @@ -0,0 +1,9 @@ +# @emdash-cms/release-action + +## 0.0.1 + +### Patch Changes + +- Updated dependencies [[`66aeecd`](https://github.com/emdash-cms/emdash/commit/66aeecd1feded23c2ee607b799500c390a04eb92), [`529b28b`](https://github.com/emdash-cms/emdash/commit/529b28bd1c0e4257eaa4436721b110beb09d5ba3), [`52fffdc`](https://github.com/emdash-cms/emdash/commit/52fffdc3556396f48a5320a0213da1a03337f642), [`3b124f2`](https://github.com/emdash-cms/emdash/commit/3b124f23126fead8884884b9f3d53e3be5d41bd3), [`920e1f3`](https://github.com/emdash-cms/emdash/commit/920e1f3fe6a7c7bf725c85e26f81e588e1201243), [`e0e60ba`](https://github.com/emdash-cms/emdash/commit/e0e60ba17b93d2022411afb8a3187c08e5142c18), [`c7b6fdf`](https://github.com/emdash-cms/emdash/commit/c7b6fdfd1f5dd9a168f5d0f6bfa9b7b9ff343145), [`c7b6fdf`](https://github.com/emdash-cms/emdash/commit/c7b6fdfd1f5dd9a168f5d0f6bfa9b7b9ff343145)]: + - @emdash-cms/registry-client@0.5.0 + - @emdash-cms/registry-verification@0.3.0 diff --git a/apps/release-action/package.json b/apps/release-action/package.json index 7b4d12e5a8..0e229ea197 100644 --- a/apps/release-action/package.json +++ b/apps/release-action/package.json @@ -1,6 +1,6 @@ { "name": "@emdash-cms/release-action", - "version": "0.0.0", + "version": "0.0.1", "private": true, "description": "GitHub Action for delegated EmDash plugin releases.", "type": "module", diff --git a/apps/release-service/CHANGELOG.md b/apps/release-service/CHANGELOG.md new file mode 100644 index 0000000000..9eb8fab141 --- /dev/null +++ b/apps/release-service/CHANGELOG.md @@ -0,0 +1,10 @@ +# @emdash-cms/release-service + +## 0.0.1 + +### Patch Changes + +- Updated dependencies [[`66aeecd`](https://github.com/emdash-cms/emdash/commit/66aeecd1feded23c2ee607b799500c390a04eb92), [`529b28b`](https://github.com/emdash-cms/emdash/commit/529b28bd1c0e4257eaa4436721b110beb09d5ba3), [`52fffdc`](https://github.com/emdash-cms/emdash/commit/52fffdc3556396f48a5320a0213da1a03337f642), [`3b124f2`](https://github.com/emdash-cms/emdash/commit/3b124f23126fead8884884b9f3d53e3be5d41bd3), [`920e1f3`](https://github.com/emdash-cms/emdash/commit/920e1f3fe6a7c7bf725c85e26f81e588e1201243), [`b8873c7`](https://github.com/emdash-cms/emdash/commit/b8873c7bd1b1755010bcb46e4511eebccba2b48a), [`e0e60ba`](https://github.com/emdash-cms/emdash/commit/e0e60ba17b93d2022411afb8a3187c08e5142c18), [`c7b6fdf`](https://github.com/emdash-cms/emdash/commit/c7b6fdfd1f5dd9a168f5d0f6bfa9b7b9ff343145), [`c7b6fdf`](https://github.com/emdash-cms/emdash/commit/c7b6fdfd1f5dd9a168f5d0f6bfa9b7b9ff343145)]: + - @emdash-cms/registry-client@0.5.0 + - @emdash-cms/registry-verification@0.3.0 + - @emdash-cms/auth@0.37.0 diff --git a/apps/release-service/package.json b/apps/release-service/package.json index 3da5e5ea5b..c8fa8ccd91 100644 --- a/apps/release-service/package.json +++ b/apps/release-service/package.json @@ -1,6 +1,6 @@ { "name": "@emdash-cms/release-service", - "version": "0.0.0", + "version": "0.0.1", "private": true, "description": "Cloudflare Worker for delegated EmDash registry releases.", "type": "module", diff --git a/apps/release-verifier/CHANGELOG.md b/apps/release-verifier/CHANGELOG.md new file mode 100644 index 0000000000..8424e9b1e5 --- /dev/null +++ b/apps/release-verifier/CHANGELOG.md @@ -0,0 +1,8 @@ +# @emdash-cms/release-verifier + +## 0.0.1 + +### Patch Changes + +- Updated dependencies [[`66aeecd`](https://github.com/emdash-cms/emdash/commit/66aeecd1feded23c2ee607b799500c390a04eb92), [`529b28b`](https://github.com/emdash-cms/emdash/commit/529b28bd1c0e4257eaa4436721b110beb09d5ba3), [`c7b6fdf`](https://github.com/emdash-cms/emdash/commit/c7b6fdfd1f5dd9a168f5d0f6bfa9b7b9ff343145), [`c7b6fdf`](https://github.com/emdash-cms/emdash/commit/c7b6fdfd1f5dd9a168f5d0f6bfa9b7b9ff343145)]: + - @emdash-cms/registry-verification@0.3.0 diff --git a/apps/release-verifier/package.json b/apps/release-verifier/package.json index eb1c70d856..dbad7311b9 100644 --- a/apps/release-verifier/package.json +++ b/apps/release-verifier/package.json @@ -1,6 +1,6 @@ { "name": "@emdash-cms/release-verifier", - "version": "0.0.0", + "version": "0.0.1", "private": true, "description": "Isolated Cloudflare Worker for delegated release artifact verification.", "type": "module", diff --git a/fixtures/perf-site/CHANGELOG.md b/fixtures/perf-site/CHANGELOG.md index 0afcb1c250..b81921b740 100644 --- a/fixtures/perf-site/CHANGELOG.md +++ b/fixtures/perf-site/CHANGELOG.md @@ -1,5 +1,13 @@ # @emdash-cms/fixture-perf-site +## 0.0.40 + +### Patch Changes + +- Updated dependencies [[`cd294dc`](https://github.com/emdash-cms/emdash/commit/cd294dc4fcbafa6fe6a33692d11b9f9abf1cc45c), [`b06fc63`](https://github.com/emdash-cms/emdash/commit/b06fc6361a88378a697f8d93f7b7718739dc0ed5), [`595a6b1`](https://github.com/emdash-cms/emdash/commit/595a6b12a11e67b89684bc5f5c14fbb6f0fc5e7f), [`7a5d9c1`](https://github.com/emdash-cms/emdash/commit/7a5d9c1838f6afc5649b7bc0940eacf920b40dab), [`de122b4`](https://github.com/emdash-cms/emdash/commit/de122b4e4b65843312bd393d09601e694ef1dee0), [`05d5596`](https://github.com/emdash-cms/emdash/commit/05d559625224fbfd23fc08608c44a46ef3735c3e), [`9def325`](https://github.com/emdash-cms/emdash/commit/9def3252a991f4b750c2d63effd6a474857cd338), [`b8873c7`](https://github.com/emdash-cms/emdash/commit/b8873c7bd1b1755010bcb46e4511eebccba2b48a), [`965bf33`](https://github.com/emdash-cms/emdash/commit/965bf3303bb71a2444c414585e29960606ae0cbb), [`bb8b087`](https://github.com/emdash-cms/emdash/commit/bb8b087c9a79c07336d2cdcadc6cec92428a2b4a), [`30d4076`](https://github.com/emdash-cms/emdash/commit/30d40760ee09faec1c77254d76d021f457e507b8), [`2970377`](https://github.com/emdash-cms/emdash/commit/29703779c2476bc8f68c317f54b59b4a0744bfe0), [`c7b6fdf`](https://github.com/emdash-cms/emdash/commit/c7b6fdfd1f5dd9a168f5d0f6bfa9b7b9ff343145)]: + - emdash@0.37.0 + - @emdash-cms/cloudflare@0.37.0 + ## 0.0.39 ### Patch Changes diff --git a/fixtures/perf-site/package.json b/fixtures/perf-site/package.json index 6fca44cb93..18c66ca779 100644 --- a/fixtures/perf-site/package.json +++ b/fixtures/perf-site/package.json @@ -1,6 +1,6 @@ { "name": "@emdash-cms/fixture-perf-site", - "version": "0.0.39", + "version": "0.0.40", "private": true, "type": "module", "description": "Fixture site for query-count perf snapshots. Runs under sqlite+node or d1+cloudflare based on EMDASH_FIXTURE_TARGET.", diff --git a/infra/blog-demo/CHANGELOG.md b/infra/blog-demo/CHANGELOG.md index a8653b059c..12448bf3d4 100644 --- a/infra/blog-demo/CHANGELOG.md +++ b/infra/blog-demo/CHANGELOG.md @@ -1,5 +1,15 @@ # @emdash-cms/perf-demo-site +## 0.0.40 + +### Patch Changes + +- Updated dependencies [[`cd294dc`](https://github.com/emdash-cms/emdash/commit/cd294dc4fcbafa6fe6a33692d11b9f9abf1cc45c), [`b06fc63`](https://github.com/emdash-cms/emdash/commit/b06fc6361a88378a697f8d93f7b7718739dc0ed5), [`595a6b1`](https://github.com/emdash-cms/emdash/commit/595a6b12a11e67b89684bc5f5c14fbb6f0fc5e7f), [`7a5d9c1`](https://github.com/emdash-cms/emdash/commit/7a5d9c1838f6afc5649b7bc0940eacf920b40dab), [`de122b4`](https://github.com/emdash-cms/emdash/commit/de122b4e4b65843312bd393d09601e694ef1dee0), [`05d5596`](https://github.com/emdash-cms/emdash/commit/05d559625224fbfd23fc08608c44a46ef3735c3e), [`66aeecd`](https://github.com/emdash-cms/emdash/commit/66aeecd1feded23c2ee607b799500c390a04eb92), [`3b124f2`](https://github.com/emdash-cms/emdash/commit/3b124f23126fead8884884b9f3d53e3be5d41bd3), [`920e1f3`](https://github.com/emdash-cms/emdash/commit/920e1f3fe6a7c7bf725c85e26f81e588e1201243), [`d99a0e8`](https://github.com/emdash-cms/emdash/commit/d99a0e835628edca896e304700746707e1bf56e7), [`9def325`](https://github.com/emdash-cms/emdash/commit/9def3252a991f4b750c2d63effd6a474857cd338), [`b8873c7`](https://github.com/emdash-cms/emdash/commit/b8873c7bd1b1755010bcb46e4511eebccba2b48a), [`965bf33`](https://github.com/emdash-cms/emdash/commit/965bf3303bb71a2444c414585e29960606ae0cbb), [`bb8b087`](https://github.com/emdash-cms/emdash/commit/bb8b087c9a79c07336d2cdcadc6cec92428a2b4a), [`30d4076`](https://github.com/emdash-cms/emdash/commit/30d40760ee09faec1c77254d76d021f457e507b8), [`e0e60ba`](https://github.com/emdash-cms/emdash/commit/e0e60ba17b93d2022411afb8a3187c08e5142c18), [`2970377`](https://github.com/emdash-cms/emdash/commit/29703779c2476bc8f68c317f54b59b4a0744bfe0), [`c7b6fdf`](https://github.com/emdash-cms/emdash/commit/c7b6fdfd1f5dd9a168f5d0f6bfa9b7b9ff343145)]: + - emdash@0.37.0 + - @emdash-cms/cloudflare@0.37.0 + - @emdash-cms/plugin-cli@0.10.0 + - @emdash-cms/plugin-webhook-notifier@0.2.0 + ## 0.0.39 ### Patch Changes diff --git a/infra/blog-demo/package.json b/infra/blog-demo/package.json index 933c82e931..20f3bbfd3d 100644 --- a/infra/blog-demo/package.json +++ b/infra/blog-demo/package.json @@ -1,6 +1,6 @@ { "name": "@emdash-cms/perf-demo-site", - "version": "0.0.39", + "version": "0.0.40", "private": true, "type": "module", "scripts": { diff --git a/infra/cache-demo/CHANGELOG.md b/infra/cache-demo/CHANGELOG.md index f555e93635..f2041caa36 100644 --- a/infra/cache-demo/CHANGELOG.md +++ b/infra/cache-demo/CHANGELOG.md @@ -1,5 +1,15 @@ # @emdash-cms/cache-demo-site +## 0.0.40 + +### Patch Changes + +- Updated dependencies [[`cd294dc`](https://github.com/emdash-cms/emdash/commit/cd294dc4fcbafa6fe6a33692d11b9f9abf1cc45c), [`b06fc63`](https://github.com/emdash-cms/emdash/commit/b06fc6361a88378a697f8d93f7b7718739dc0ed5), [`595a6b1`](https://github.com/emdash-cms/emdash/commit/595a6b12a11e67b89684bc5f5c14fbb6f0fc5e7f), [`7a5d9c1`](https://github.com/emdash-cms/emdash/commit/7a5d9c1838f6afc5649b7bc0940eacf920b40dab), [`de122b4`](https://github.com/emdash-cms/emdash/commit/de122b4e4b65843312bd393d09601e694ef1dee0), [`05d5596`](https://github.com/emdash-cms/emdash/commit/05d559625224fbfd23fc08608c44a46ef3735c3e), [`66aeecd`](https://github.com/emdash-cms/emdash/commit/66aeecd1feded23c2ee607b799500c390a04eb92), [`3b124f2`](https://github.com/emdash-cms/emdash/commit/3b124f23126fead8884884b9f3d53e3be5d41bd3), [`920e1f3`](https://github.com/emdash-cms/emdash/commit/920e1f3fe6a7c7bf725c85e26f81e588e1201243), [`d99a0e8`](https://github.com/emdash-cms/emdash/commit/d99a0e835628edca896e304700746707e1bf56e7), [`9def325`](https://github.com/emdash-cms/emdash/commit/9def3252a991f4b750c2d63effd6a474857cd338), [`b8873c7`](https://github.com/emdash-cms/emdash/commit/b8873c7bd1b1755010bcb46e4511eebccba2b48a), [`965bf33`](https://github.com/emdash-cms/emdash/commit/965bf3303bb71a2444c414585e29960606ae0cbb), [`bb8b087`](https://github.com/emdash-cms/emdash/commit/bb8b087c9a79c07336d2cdcadc6cec92428a2b4a), [`30d4076`](https://github.com/emdash-cms/emdash/commit/30d40760ee09faec1c77254d76d021f457e507b8), [`e0e60ba`](https://github.com/emdash-cms/emdash/commit/e0e60ba17b93d2022411afb8a3187c08e5142c18), [`2970377`](https://github.com/emdash-cms/emdash/commit/29703779c2476bc8f68c317f54b59b4a0744bfe0), [`c7b6fdf`](https://github.com/emdash-cms/emdash/commit/c7b6fdfd1f5dd9a168f5d0f6bfa9b7b9ff343145)]: + - emdash@0.37.0 + - @emdash-cms/cloudflare@0.37.0 + - @emdash-cms/plugin-cli@0.10.0 + - @emdash-cms/plugin-webhook-notifier@0.2.0 + ## 0.0.39 ### Patch Changes diff --git a/infra/cache-demo/package.json b/infra/cache-demo/package.json index a8778eb30b..00fd0bc6d8 100644 --- a/infra/cache-demo/package.json +++ b/infra/cache-demo/package.json @@ -1,6 +1,6 @@ { "name": "@emdash-cms/cache-demo-site", - "version": "0.0.39", + "version": "0.0.40", "private": true, "type": "module", "scripts": { diff --git a/infra/do-demo/CHANGELOG.md b/infra/do-demo/CHANGELOG.md index 37c7b6c605..c20c7b4fcb 100644 --- a/infra/do-demo/CHANGELOG.md +++ b/infra/do-demo/CHANGELOG.md @@ -1,5 +1,15 @@ # @emdash-cms/do-demo-site +## 0.0.40 + +### Patch Changes + +- Updated dependencies [[`cd294dc`](https://github.com/emdash-cms/emdash/commit/cd294dc4fcbafa6fe6a33692d11b9f9abf1cc45c), [`b06fc63`](https://github.com/emdash-cms/emdash/commit/b06fc6361a88378a697f8d93f7b7718739dc0ed5), [`595a6b1`](https://github.com/emdash-cms/emdash/commit/595a6b12a11e67b89684bc5f5c14fbb6f0fc5e7f), [`7a5d9c1`](https://github.com/emdash-cms/emdash/commit/7a5d9c1838f6afc5649b7bc0940eacf920b40dab), [`de122b4`](https://github.com/emdash-cms/emdash/commit/de122b4e4b65843312bd393d09601e694ef1dee0), [`05d5596`](https://github.com/emdash-cms/emdash/commit/05d559625224fbfd23fc08608c44a46ef3735c3e), [`66aeecd`](https://github.com/emdash-cms/emdash/commit/66aeecd1feded23c2ee607b799500c390a04eb92), [`3b124f2`](https://github.com/emdash-cms/emdash/commit/3b124f23126fead8884884b9f3d53e3be5d41bd3), [`920e1f3`](https://github.com/emdash-cms/emdash/commit/920e1f3fe6a7c7bf725c85e26f81e588e1201243), [`d99a0e8`](https://github.com/emdash-cms/emdash/commit/d99a0e835628edca896e304700746707e1bf56e7), [`9def325`](https://github.com/emdash-cms/emdash/commit/9def3252a991f4b750c2d63effd6a474857cd338), [`b8873c7`](https://github.com/emdash-cms/emdash/commit/b8873c7bd1b1755010bcb46e4511eebccba2b48a), [`965bf33`](https://github.com/emdash-cms/emdash/commit/965bf3303bb71a2444c414585e29960606ae0cbb), [`bb8b087`](https://github.com/emdash-cms/emdash/commit/bb8b087c9a79c07336d2cdcadc6cec92428a2b4a), [`30d4076`](https://github.com/emdash-cms/emdash/commit/30d40760ee09faec1c77254d76d021f457e507b8), [`e0e60ba`](https://github.com/emdash-cms/emdash/commit/e0e60ba17b93d2022411afb8a3187c08e5142c18), [`2970377`](https://github.com/emdash-cms/emdash/commit/29703779c2476bc8f68c317f54b59b4a0744bfe0), [`c7b6fdf`](https://github.com/emdash-cms/emdash/commit/c7b6fdfd1f5dd9a168f5d0f6bfa9b7b9ff343145)]: + - emdash@0.37.0 + - @emdash-cms/cloudflare@0.37.0 + - @emdash-cms/plugin-cli@0.10.0 + - @emdash-cms/plugin-webhook-notifier@0.2.0 + ## 0.0.39 ### Patch Changes diff --git a/infra/do-demo/package.json b/infra/do-demo/package.json index 52d9620201..52fef834bb 100644 --- a/infra/do-demo/package.json +++ b/infra/do-demo/package.json @@ -1,6 +1,6 @@ { "name": "@emdash-cms/do-demo-site", - "version": "0.0.39", + "version": "0.0.40", "private": true, "type": "module", "scripts": { diff --git a/infra/do-solo-demo/CHANGELOG.md b/infra/do-solo-demo/CHANGELOG.md index c1464efbc7..bf7c8748da 100644 --- a/infra/do-solo-demo/CHANGELOG.md +++ b/infra/do-solo-demo/CHANGELOG.md @@ -1,5 +1,15 @@ # @emdash-cms/do-solo-demo-site +## 0.0.40 + +### Patch Changes + +- Updated dependencies [[`cd294dc`](https://github.com/emdash-cms/emdash/commit/cd294dc4fcbafa6fe6a33692d11b9f9abf1cc45c), [`b06fc63`](https://github.com/emdash-cms/emdash/commit/b06fc6361a88378a697f8d93f7b7718739dc0ed5), [`595a6b1`](https://github.com/emdash-cms/emdash/commit/595a6b12a11e67b89684bc5f5c14fbb6f0fc5e7f), [`7a5d9c1`](https://github.com/emdash-cms/emdash/commit/7a5d9c1838f6afc5649b7bc0940eacf920b40dab), [`de122b4`](https://github.com/emdash-cms/emdash/commit/de122b4e4b65843312bd393d09601e694ef1dee0), [`05d5596`](https://github.com/emdash-cms/emdash/commit/05d559625224fbfd23fc08608c44a46ef3735c3e), [`66aeecd`](https://github.com/emdash-cms/emdash/commit/66aeecd1feded23c2ee607b799500c390a04eb92), [`3b124f2`](https://github.com/emdash-cms/emdash/commit/3b124f23126fead8884884b9f3d53e3be5d41bd3), [`920e1f3`](https://github.com/emdash-cms/emdash/commit/920e1f3fe6a7c7bf725c85e26f81e588e1201243), [`d99a0e8`](https://github.com/emdash-cms/emdash/commit/d99a0e835628edca896e304700746707e1bf56e7), [`9def325`](https://github.com/emdash-cms/emdash/commit/9def3252a991f4b750c2d63effd6a474857cd338), [`b8873c7`](https://github.com/emdash-cms/emdash/commit/b8873c7bd1b1755010bcb46e4511eebccba2b48a), [`965bf33`](https://github.com/emdash-cms/emdash/commit/965bf3303bb71a2444c414585e29960606ae0cbb), [`bb8b087`](https://github.com/emdash-cms/emdash/commit/bb8b087c9a79c07336d2cdcadc6cec92428a2b4a), [`30d4076`](https://github.com/emdash-cms/emdash/commit/30d40760ee09faec1c77254d76d021f457e507b8), [`e0e60ba`](https://github.com/emdash-cms/emdash/commit/e0e60ba17b93d2022411afb8a3187c08e5142c18), [`2970377`](https://github.com/emdash-cms/emdash/commit/29703779c2476bc8f68c317f54b59b4a0744bfe0), [`c7b6fdf`](https://github.com/emdash-cms/emdash/commit/c7b6fdfd1f5dd9a168f5d0f6bfa9b7b9ff343145)]: + - emdash@0.37.0 + - @emdash-cms/cloudflare@0.37.0 + - @emdash-cms/plugin-cli@0.10.0 + - @emdash-cms/plugin-webhook-notifier@0.2.0 + ## 0.0.39 ### Patch Changes diff --git a/infra/do-solo-demo/package.json b/infra/do-solo-demo/package.json index 951f428c63..db0b3e04d4 100644 --- a/infra/do-solo-demo/package.json +++ b/infra/do-solo-demo/package.json @@ -1,6 +1,6 @@ { "name": "@emdash-cms/do-solo-demo-site", - "version": "0.0.39", + "version": "0.0.40", "private": true, "type": "module", "scripts": { diff --git a/packages/admin/CHANGELOG.md b/packages/admin/CHANGELOG.md index 735f48e5e2..686d29ee0b 100644 --- a/packages/admin/CHANGELOG.md +++ b/packages/admin/CHANGELOG.md @@ -1,5 +1,83 @@ # @emdash-cms/admin +## 0.37.0 + +### Minor Changes + +- [#2899](https://github.com/emdash-cms/emdash/pull/2899) [`595a6b1`](https://github.com/emdash-cms/emdash/commit/595a6b12a11e67b89684bc5f5c14fbb6f0fc5e7f) Thanks [@khoinguyenpham04](https://github.com/khoinguyenpham04)! - Adds **Replace image** to the Media Library for ready JPEG, PNG, and WebP files stored by EmDash. + + Choose a same-format file to update every existing use of an image while preserving its media ID, filename, URL, alt text, caption, and location. The replacement can use different dimensions or an aspect ratio from the original. EmDash overwrites the original bytes and clears the focal point; it does not retain the previous file. The action works with local disk, R2, and S3-compatible storage. + +- [#2861](https://github.com/emdash-cms/emdash/pull/2861) [`05d5596`](https://github.com/emdash-cms/emdash/commit/05d559625224fbfd23fc08608c44a46ef3735c3e) Thanks [@khoinguyenpham04](https://github.com/khoinguyenpham04)! - Adds cropping for JPEG, PNG, and WebP images stored by EmDash on local disk, Cloudflare R2, or S3-compatible storage. + + Move and resize a rule-of-thirds crop frame with corner handles for fixed ratios and eight handles for Freeform. Choose the original ratio, Freeform, or a common aspect ratio. **Create cropped copy** creates a separate media item with any ratio and names it for the selected ratio or output dimensions. **Replace original** uses the original ratio and replaces the existing item under the same ID and URL, so every reference uses the cropped image without rewriting or republishing content. Local media and responsive renditions revalidate their stable URLs so sites load the replacement instead of keeping a stale cached image. The original bytes and crop history are not retained. + +- [#2900](https://github.com/emdash-cms/emdash/pull/2900) [`9def325`](https://github.com/emdash-cms/emdash/commit/9def3252a991f4b750c2d63effd6a474857cd338) Thanks [@khoinguyenpham04](https://github.com/khoinguyenpham04)! - Adds Media Library browsing and inline uploads to admin media pickers. Editors can search, filter + by type, browse folders, switch between grid and list views, use numbered pages, and select media + from configured providers or a direct URL without leaving the content editor. + + Uploads appear in the picker with an uploading or failed status. Successful uploads become + selected media cards, and gallery selections can be reordered before they are added. + +- [#2746](https://github.com/emdash-cms/emdash/pull/2746) [`c7b6fdf`](https://github.com/emdash-cms/emdash/commit/c7b6fdfd1f5dd9a168f5d0f6bfa9b7b9ff343145) Thanks [@ascorbic](https://github.com/ascorbic)! - Adds `DirectPdsClient` for reading package profiles and releases with AT Protocol repository proofs, and updates experimental decentralized registry installs and updates to verify current signed records directly from the publisher's PDS. + + #### Aggregator record integrity + + Install and update reject aggregator-supplied profile or release metadata whose URI or CID does not match the publisher's signed records. The server returns `AGGREGATOR_RECORD_MISMATCH` before fetching the artifact or requesting consent. + + #### Publisher identity display + + The admin treats handle resolution as an advisory identity signal. It keeps the install button disabled while attempting to resolve the package DID back to a handle, then blocks installation when `resolveDidToHandle()` conclusively returns `"invalid"`. An indeterminate result caused by a network failure, unsupported DID method, or missing handle displays the publisher DID and does not block installation. + + Install and update trust the publisher DID and the signed repository proofs for the profile and release records. A handle is display metadata and is not an authorization or record-integrity input. + + #### Provenance and release policy + + The installer applies the signed profile's release policy, independently fetches and verifies supplied Sigstore/SLSA provenance, and binds moderation labels to the exact profile or release CID. Missing required provenance and any supplied provenance that is unavailable, malformed, mismatched, or unsupported block installation and updates. Artifact checksums, archive paths, bundle limits, manifest identity, and version use the same verification rules as the registry release tooling. + + The verification package also exports `inspectPackageReleaseRecords` for validating signed records and policy before artifact and provenance evidence is available. + + Registry install and update consent now show the exact verified profile and release CIDs, signed publisher policy, and provenance status. Install consent uses permissions and MCP tools read from the verified bundle rather than the aggregator's record copy. + + Install, update, and delegated-release verification require lowercase base32 multibase `sha2-256` multihashes for package artifacts and provenance documents. The plugin CLI already produces this format. The authenticated image-artifact proxy still accepts legacy bare hexadecimal SHA-256 checksums for display-only images. + +### Patch Changes + +- [#2761](https://github.com/emdash-cms/emdash/pull/2761) [`8fb13cf`](https://github.com/emdash-cms/emdash/commit/8fb13cf7a6bdabab8e9a4288c685be4715febd63) Thanks [@khoinguyenpham04](https://github.com/khoinguyenpham04)! - Adds a dedicated **Used in** tab to media details, keeping file information and focal-point controls separate from usage references. + +- [#2126](https://github.com/emdash-cms/emdash/pull/2126) [`7887577`](https://github.com/emdash-cms/emdash/commit/788757761732ca691d73f7f8c99e7d3d66bf9dec) Thanks [@swissky](https://github.com/swissky)! - Fixes a silent draft-overwrite in the page editor. The editor now echoes the entry's `_rev` token on save and autosave, so the server rejects a save that is based on a stale read with a 409 conflict instead of silently replacing a newer draft revision. Editors who hit a conflict now see a clear error and can reload instead of losing work. + +- [#2865](https://github.com/emdash-cms/emdash/pull/2865) [`5f9eb67`](https://github.com/emdash-cms/emdash/commit/5f9eb67440cf89ec473d608e99d8b19272a20e96) Thanks [@khoinguyenpham04](https://github.com/khoinguyenpham04)! - Updates sidebar navigation icons to use Phosphor's filled style for the active page. + +- [#2761](https://github.com/emdash-cms/emdash/pull/2761) [`8fb13cf`](https://github.com/emdash-cms/emdash/commit/8fb13cf7a6bdabab8e9a4288c685be4715febd63) Thanks [@khoinguyenpham04](https://github.com/khoinguyenpham04)! - Updates Media Library grid cards to show filenames and file formats below larger previews. + +- [#2830](https://github.com/emdash-cms/emdash/pull/2830) [`965bf33`](https://github.com/emdash-cms/emdash/commit/965bf3303bb71a2444c414585e29960606ae0cbb) Thanks [@khoinguyenpham04](https://github.com/khoinguyenpham04)! - Fixes image fields and Portable Text editors so they preserve direct image URLs and external provider identities, allowing selected images to continue rendering after saving or replacement. + +- [#2860](https://github.com/emdash-cms/emdash/pull/2860) [`afa81c5`](https://github.com/emdash-cms/emdash/commit/afa81c5e847f1492f7b5eba134d97d0bbbb3aed7) Thanks [@ascorbic](https://github.com/ascorbic)! - Fixes Publish saving and awaiting the editor's latest changes before making content live. Validation errors, failed saves, and revision conflicts now stop publishing instead of promoting stale draft data. + +- [#2858](https://github.com/emdash-cms/emdash/pull/2858) [`bb8b087`](https://github.com/emdash-cms/emdash/commit/bb8b087c9a79c07336d2cdcadc6cec92428a2b4a) Thanks [@ascorbic](https://github.com/ascorbic)! - Fixes sandboxed `content:beforeSave` hooks being unable to reject content creation or updates. + + Return a version 1 sandbox hook result with a `SAVE_REJECTED` error to stop the save and show the reason to the editor: + + ```ts + return { + __emdashSandboxHookResult: true, + version: 1, + error: { + code: "SAVE_REJECTED", + reason: "Add a title before saving.", + }, + }; + ``` + + The reason must contain 1–500 characters of plain text. Invalid error results and unexpected sandbox exceptions stop the save with a generic hook error instead of exposing internal details. + +- [#2761](https://github.com/emdash-cms/emdash/pull/2761) [`8fb13cf`](https://github.com/emdash-cms/emdash/commit/8fb13cf7a6bdabab8e9a4288c685be4715febd63) Thanks [@khoinguyenpham04](https://github.com/khoinguyenpham04)! - Updates image previews to show a theme-aware checkerboard behind transparent areas. + +- Updated dependencies [[`66aeecd`](https://github.com/emdash-cms/emdash/commit/66aeecd1feded23c2ee607b799500c390a04eb92), [`52fffdc`](https://github.com/emdash-cms/emdash/commit/52fffdc3556396f48a5320a0213da1a03337f642), [`3b124f2`](https://github.com/emdash-cms/emdash/commit/3b124f23126fead8884884b9f3d53e3be5d41bd3), [`920e1f3`](https://github.com/emdash-cms/emdash/commit/920e1f3fe6a7c7bf725c85e26f81e588e1201243), [`e0e60ba`](https://github.com/emdash-cms/emdash/commit/e0e60ba17b93d2022411afb8a3187c08e5142c18), [`c7b6fdf`](https://github.com/emdash-cms/emdash/commit/c7b6fdfd1f5dd9a168f5d0f6bfa9b7b9ff343145)]: + - @emdash-cms/registry-client@0.5.0 + - @emdash-cms/blocks@0.37.0 + ## 0.36.0 ### Minor Changes diff --git a/packages/admin/package.json b/packages/admin/package.json index 63ec63973c..acf03d3cb4 100644 --- a/packages/admin/package.json +++ b/packages/admin/package.json @@ -1,6 +1,6 @@ { "name": "@emdash-cms/admin", - "version": "0.36.0", + "version": "0.37.0", "description": "Admin UI for EmDash CMS", "type": "module", "main": "dist/index.js", diff --git a/packages/auth-atproto/CHANGELOG.md b/packages/auth-atproto/CHANGELOG.md index 8cdb7cfea1..3a14de1774 100644 --- a/packages/auth-atproto/CHANGELOG.md +++ b/packages/auth-atproto/CHANGELOG.md @@ -1,5 +1,12 @@ # @emdash-cms/auth-atproto +## 0.2.37 + +### Patch Changes + +- Updated dependencies [[`b8873c7`](https://github.com/emdash-cms/emdash/commit/b8873c7bd1b1755010bcb46e4511eebccba2b48a)]: + - @emdash-cms/auth@0.37.0 + ## 0.2.36 ### Patch Changes diff --git a/packages/auth-atproto/package.json b/packages/auth-atproto/package.json index 5ae25060ef..5aa7a2c7e8 100644 --- a/packages/auth-atproto/package.json +++ b/packages/auth-atproto/package.json @@ -1,6 +1,6 @@ { "name": "@emdash-cms/auth-atproto", - "version": "0.2.36", + "version": "0.2.37", "description": "AT Protocol / Atmosphere authentication provider for EmDash CMS", "type": "module", "main": "src/auth.ts", diff --git a/packages/auth/CHANGELOG.md b/packages/auth/CHANGELOG.md index c7f122e4ef..5f167724c9 100644 --- a/packages/auth/CHANGELOG.md +++ b/packages/auth/CHANGELOG.md @@ -1,5 +1,17 @@ # @emdash-cms/auth +## 0.37.0 + +### Minor Changes + +- [#2745](https://github.com/emdash-cms/emdash/pull/2745) [`b8873c7`](https://github.com/emdash-cms/emdash/commit/b8873c7bd1b1755010bcb46e4511eebccba2b48a) Thanks [@ascorbic](https://github.com/ascorbic)! - Adds `PasskeyConfig.userVerification` so sites can require, prefer, or discourage passkey user verification. Existing callers keep the `preferred` behavior. + + Adds typed, versioned challenge contexts for registration and authentication. Declare a codec with `defineChallengeContext()`, bind data with `bindChallengeContext()` when generating options, and pass the codec with an `AtomicChallengeStore` to `verifyAuthenticationResponse()` or `verifyRegistrationResponse()` to recover the typed value after verification. + + Atomic challenge stores declare `readonly atomic: true`, so an unrelated `consume()` method on an existing challenge store cannot silently change its behavior. EmDash retains optional challenge context data in its database-backed challenge store. + + Authentication rejects assertions whose signature counter drops from a nonzero value to zero because the counter change can indicate a cloned authenticator. + ## 0.36.0 ## 0.35.0 diff --git a/packages/auth/package.json b/packages/auth/package.json index 367fab603d..76521f474e 100644 --- a/packages/auth/package.json +++ b/packages/auth/package.json @@ -1,6 +1,6 @@ { "name": "@emdash-cms/auth", - "version": "0.36.0", + "version": "0.37.0", "description": "Passkey-first authentication for EmDash", "type": "module", "main": "dist/index.mjs", diff --git a/packages/blocks/CHANGELOG.md b/packages/blocks/CHANGELOG.md index a07ffac9fb..155dc157da 100644 --- a/packages/blocks/CHANGELOG.md +++ b/packages/blocks/CHANGELOG.md @@ -1,5 +1,7 @@ # @emdash-cms/blocks +## 0.37.0 + ## 0.36.0 ## 0.35.0 diff --git a/packages/blocks/package.json b/packages/blocks/package.json index 4d7450b593..f62569bbbf 100644 --- a/packages/blocks/package.json +++ b/packages/blocks/package.json @@ -1,6 +1,6 @@ { "name": "@emdash-cms/blocks", - "version": "0.36.0", + "version": "0.37.0", "description": "Declarative plugin UI blocks for EmDash CMS", "type": "module", "main": "dist/index.js", diff --git a/packages/cloudflare/CHANGELOG.md b/packages/cloudflare/CHANGELOG.md index 061023d41c..d44d8b1ac1 100644 --- a/packages/cloudflare/CHANGELOG.md +++ b/packages/cloudflare/CHANGELOG.md @@ -1,5 +1,16 @@ # @emdash-cms/cloudflare +## 0.37.0 + +### Patch Changes + +- [#2861](https://github.com/emdash-cms/emdash/pull/2861) [`05d5596`](https://github.com/emdash-cms/emdash/commit/05d559625224fbfd23fc08608c44a46ef3735c3e) Thanks [@khoinguyenpham04](https://github.com/khoinguyenpham04)! - Adds cropping for JPEG, PNG, and WebP images stored by EmDash on local disk, Cloudflare R2, or S3-compatible storage. + + Move and resize a rule-of-thirds crop frame with corner handles for fixed ratios and eight handles for Freeform. Choose the original ratio, Freeform, or a common aspect ratio. **Create cropped copy** creates a separate media item with any ratio and names it for the selected ratio or output dimensions. **Replace original** uses the original ratio and replaces the existing item under the same ID and URL, so every reference uses the cropped image without rewriting or republishing content. Local media and responsive renditions revalidate their stable URLs so sites load the replacement instead of keeping a stale cached image. The original bytes and crop history are not retained. + +- Updated dependencies [[`cd294dc`](https://github.com/emdash-cms/emdash/commit/cd294dc4fcbafa6fe6a33692d11b9f9abf1cc45c), [`b06fc63`](https://github.com/emdash-cms/emdash/commit/b06fc6361a88378a697f8d93f7b7718739dc0ed5), [`595a6b1`](https://github.com/emdash-cms/emdash/commit/595a6b12a11e67b89684bc5f5c14fbb6f0fc5e7f), [`7a5d9c1`](https://github.com/emdash-cms/emdash/commit/7a5d9c1838f6afc5649b7bc0940eacf920b40dab), [`de122b4`](https://github.com/emdash-cms/emdash/commit/de122b4e4b65843312bd393d09601e694ef1dee0), [`05d5596`](https://github.com/emdash-cms/emdash/commit/05d559625224fbfd23fc08608c44a46ef3735c3e), [`9def325`](https://github.com/emdash-cms/emdash/commit/9def3252a991f4b750c2d63effd6a474857cd338), [`b8873c7`](https://github.com/emdash-cms/emdash/commit/b8873c7bd1b1755010bcb46e4511eebccba2b48a), [`965bf33`](https://github.com/emdash-cms/emdash/commit/965bf3303bb71a2444c414585e29960606ae0cbb), [`bb8b087`](https://github.com/emdash-cms/emdash/commit/bb8b087c9a79c07336d2cdcadc6cec92428a2b4a), [`30d4076`](https://github.com/emdash-cms/emdash/commit/30d40760ee09faec1c77254d76d021f457e507b8), [`2970377`](https://github.com/emdash-cms/emdash/commit/29703779c2476bc8f68c317f54b59b4a0744bfe0), [`c7b6fdf`](https://github.com/emdash-cms/emdash/commit/c7b6fdfd1f5dd9a168f5d0f6bfa9b7b9ff343145)]: + - emdash@0.37.0 + ## 0.36.0 ### Minor Changes diff --git a/packages/cloudflare/package.json b/packages/cloudflare/package.json index 46a116f54a..a2833b0267 100644 --- a/packages/cloudflare/package.json +++ b/packages/cloudflare/package.json @@ -1,6 +1,6 @@ { "name": "@emdash-cms/cloudflare", - "version": "0.36.0", + "version": "0.37.0", "description": "Cloudflare adapters for EmDash - D1, R2, Access, and Worker Loader sandbox", "type": "module", "main": "dist/index.mjs", diff --git a/packages/core/CHANGELOG.md b/packages/core/CHANGELOG.md index 2ab73b355d..e7403357c0 100644 --- a/packages/core/CHANGELOG.md +++ b/packages/core/CHANGELOG.md @@ -1,5 +1,106 @@ # emdash +## 0.37.0 + +### Minor Changes + +- [#2899](https://github.com/emdash-cms/emdash/pull/2899) [`595a6b1`](https://github.com/emdash-cms/emdash/commit/595a6b12a11e67b89684bc5f5c14fbb6f0fc5e7f) Thanks [@khoinguyenpham04](https://github.com/khoinguyenpham04)! - Adds **Replace image** to the Media Library for ready JPEG, PNG, and WebP files stored by EmDash. + + Choose a same-format file to update every existing use of an image while preserving its media ID, filename, URL, alt text, caption, and location. The replacement can use different dimensions or an aspect ratio from the original. EmDash overwrites the original bytes and clears the focal point; it does not retain the previous file. The action works with local disk, R2, and S3-compatible storage. + +- [#2861](https://github.com/emdash-cms/emdash/pull/2861) [`05d5596`](https://github.com/emdash-cms/emdash/commit/05d559625224fbfd23fc08608c44a46ef3735c3e) Thanks [@khoinguyenpham04](https://github.com/khoinguyenpham04)! - Adds cropping for JPEG, PNG, and WebP images stored by EmDash on local disk, Cloudflare R2, or S3-compatible storage. + + Move and resize a rule-of-thirds crop frame with corner handles for fixed ratios and eight handles for Freeform. Choose the original ratio, Freeform, or a common aspect ratio. **Create cropped copy** creates a separate media item with any ratio and names it for the selected ratio or output dimensions. **Replace original** uses the original ratio and replaces the existing item under the same ID and URL, so every reference uses the cropped image without rewriting or republishing content. Local media and responsive renditions revalidate their stable URLs so sites load the replacement instead of keeping a stale cached image. The original bytes and crop history are not retained. + +- [#2746](https://github.com/emdash-cms/emdash/pull/2746) [`c7b6fdf`](https://github.com/emdash-cms/emdash/commit/c7b6fdfd1f5dd9a168f5d0f6bfa9b7b9ff343145) Thanks [@ascorbic](https://github.com/ascorbic)! - Adds `DirectPdsClient` for reading package profiles and releases with AT Protocol repository proofs, and updates experimental decentralized registry installs and updates to verify current signed records directly from the publisher's PDS. + + #### Aggregator record integrity + + Install and update reject aggregator-supplied profile or release metadata whose URI or CID does not match the publisher's signed records. The server returns `AGGREGATOR_RECORD_MISMATCH` before fetching the artifact or requesting consent. + + #### Publisher identity display + + The admin treats handle resolution as an advisory identity signal. It keeps the install button disabled while attempting to resolve the package DID back to a handle, then blocks installation when `resolveDidToHandle()` conclusively returns `"invalid"`. An indeterminate result caused by a network failure, unsupported DID method, or missing handle displays the publisher DID and does not block installation. + + Install and update trust the publisher DID and the signed repository proofs for the profile and release records. A handle is display metadata and is not an authorization or record-integrity input. + + #### Provenance and release policy + + The installer applies the signed profile's release policy, independently fetches and verifies supplied Sigstore/SLSA provenance, and binds moderation labels to the exact profile or release CID. Missing required provenance and any supplied provenance that is unavailable, malformed, mismatched, or unsupported block installation and updates. Artifact checksums, archive paths, bundle limits, manifest identity, and version use the same verification rules as the registry release tooling. + + The verification package also exports `inspectPackageReleaseRecords` for validating signed records and policy before artifact and provenance evidence is available. + + Registry install and update consent now show the exact verified profile and release CIDs, signed publisher policy, and provenance status. Install consent uses permissions and MCP tools read from the verified bundle rather than the aggregator's record copy. + + Install, update, and delegated-release verification require lowercase base32 multibase `sha2-256` multihashes for package artifacts and provenance documents. The plugin CLI already produces this format. The authenticated image-artifact proxy still accepts legacy bare hexadecimal SHA-256 checksums for display-only images. + +### Patch Changes + +- [#2783](https://github.com/emdash-cms/emdash/pull/2783) [`cd294dc`](https://github.com/emdash-cms/emdash/commit/cd294dc4fcbafa6fe6a33692d11b9f9abf1cc45c) Thanks [@yumam0815](https://github.com/yumam0815)! - Fixes publication workflows so callers can pass the approved `_rev` to publish, unpublish, or discard a draft and receive a `CONFLICT` response when the entry changed. Calls that omit `_rev` keep the existing behavior. + +- [#2852](https://github.com/emdash-cms/emdash/pull/2852) [`b06fc63`](https://github.com/emdash-cms/emdash/commit/b06fc6361a88378a697f8d93f7b7718739dc0ed5) Thanks [@MA2153](https://github.com/MA2153)! - Fixes scheduled media-usage cleanup reading far more rows than its batch size on large sites. A cleanup run that had lost its lease scanned the whole occurrence table before returning nothing, so cron ticks could spike into the hundreds of thousands of rows read. Sites on Cloudflare D1 will see those spikes disappear. + +- [#2885](https://github.com/emdash-cms/emdash/pull/2885) [`7a5d9c1`](https://github.com/emdash-cms/emdash/commit/7a5d9c1838f6afc5649b7bc0940eacf920b40dab) Thanks [@MA2153](https://github.com/MA2153)! - Fixes byline profile pages having no way to render the byline's avatar ([#2613](https://github.com/emdash-cms/emdash/issues/2613)). `getByline`, `getBylineBySlug`, and the underlying single-row `BylineRepository` finders now resolve the avatar's media row in the same query, so `avatarStorageKey`, `avatarAlt`, `avatarBlurhash`, and `avatarDominantColor` are populated alongside `avatarMediaId`: + + ```astro + --- + import { getBylineBySlug } from "emdash"; + + const byline = await getBylineBySlug(Astro.params.slug, { + locale: Astro.currentLocale, + }); + const avatar = byline?.avatarStorageKey + ? Astro.locals.emdash.getPublicMediaUrl(byline.avatarStorageKey) + : null; + --- + + {avatar && {byline.avatarAlt} + ``` + + Previously these fields were populated only when a byline was hydrated as a credit on a content entry, so a page keyed on the byline itself — `/authors/` and the like — held a bare media id with no public API to turn it into a URL. Nothing else changes: the lookup still costs one query (the avatar is a `LEFT JOIN`, not a second round trip), and `findMany` still skips the join, so byline list pages are unaffected. + +- [#2886](https://github.com/emdash-cms/emdash/pull/2886) [`de122b4`](https://github.com/emdash-cms/emdash/commit/de122b4e4b65843312bd393d09601e694ef1dee0) Thanks [@ascorbic](https://github.com/ascorbic)! - Fixes unpublishing content resetting its publication date. Previously published drafts keep their date visible and editable in the admin, and republishing them without a date override reuses it. + +- [#2900](https://github.com/emdash-cms/emdash/pull/2900) [`9def325`](https://github.com/emdash-cms/emdash/commit/9def3252a991f4b750c2d63effd6a474857cd338) Thanks [@khoinguyenpham04](https://github.com/khoinguyenpham04)! - Fixes Cloudflare development servers failing during cold start with Astro 7.3.1 after Vite discovers `astro/logger/console` and invalidates prebundled server chunks. + +- [#2745](https://github.com/emdash-cms/emdash/pull/2745) [`b8873c7`](https://github.com/emdash-cms/emdash/commit/b8873c7bd1b1755010bcb46e4511eebccba2b48a) Thanks [@ascorbic](https://github.com/ascorbic)! - Adds `PasskeyConfig.userVerification` so sites can require, prefer, or discourage passkey user verification. Existing callers keep the `preferred` behavior. + + Adds typed, versioned challenge contexts for registration and authentication. Declare a codec with `defineChallengeContext()`, bind data with `bindChallengeContext()` when generating options, and pass the codec with an `AtomicChallengeStore` to `verifyAuthenticationResponse()` or `verifyRegistrationResponse()` to recover the typed value after verification. + + Atomic challenge stores declare `readonly atomic: true`, so an unrelated `consume()` method on an existing challenge store cannot silently change its behavior. EmDash retains optional challenge context data in its database-backed challenge store. + + Authentication rejects assertions whose signature counter drops from a nonzero value to zero because the counter change can indicate a cloned authenticator. + +- [#2830](https://github.com/emdash-cms/emdash/pull/2830) [`965bf33`](https://github.com/emdash-cms/emdash/commit/965bf3303bb71a2444c414585e29960606ae0cbb) Thanks [@khoinguyenpham04](https://github.com/khoinguyenpham04)! - Fixes image fields and Portable Text editors so they preserve direct image URLs and external provider identities, allowing selected images to continue rendering after saving or replacement. + +- [#2858](https://github.com/emdash-cms/emdash/pull/2858) [`bb8b087`](https://github.com/emdash-cms/emdash/commit/bb8b087c9a79c07336d2cdcadc6cec92428a2b4a) Thanks [@ascorbic](https://github.com/ascorbic)! - Fixes sandboxed `content:beforeSave` hooks being unable to reject content creation or updates. + + Return a version 1 sandbox hook result with a `SAVE_REJECTED` error to stop the save and show the reason to the editor: + + ```ts + return { + __emdashSandboxHookResult: true, + version: 1, + error: { + code: "SAVE_REJECTED", + reason: "Add a title before saving.", + }, + }; + ``` + + The reason must contain 1–500 characters of plain text. Invalid error results and unexpected sandbox exceptions stop the save with a generic hook error instead of exposing internal details. + +- [#2890](https://github.com/emdash-cms/emdash/pull/2890) [`30d4076`](https://github.com/emdash-cms/emdash/commit/30d40760ee09faec1c77254d76d021f457e507b8) Thanks [@MA2153](https://github.com/MA2153)! - Fixes scheduled publishing so its recurring check no longer reads every content entry on each run. Sites running the scheduler on a frequent cron trigger, as the Cloudflare deployment guide recommends, previously saw database reads grow with the size of their content library rather than with the amount of scheduled work — a cost that is directly billable on D1 and was paid even when nothing was scheduled. Existing sites pick up the fix when migrations run on upgrade; no configuration or code changes are needed. + +- [#2884](https://github.com/emdash-cms/emdash/pull/2884) [`2970377`](https://github.com/emdash-cms/emdash/commit/29703779c2476bc8f68c317f54b59b4a0744bfe0) Thanks [@MA2153](https://github.com/MA2153)! - Fixes the OpenAPI description for `GET /_emdash/api/taxonomies/{name}`, which said that omitting `locale` returns the lowest-locale definition. The endpoint returns the configured default locale's definition and only falls back to the lowest locale code when the default locale has none. Behavior is unchanged; only the generated API description was wrong. + +- Updated dependencies [[`595a6b1`](https://github.com/emdash-cms/emdash/commit/595a6b12a11e67b89684bc5f5c14fbb6f0fc5e7f), [`05d5596`](https://github.com/emdash-cms/emdash/commit/05d559625224fbfd23fc08608c44a46ef3735c3e), [`66aeecd`](https://github.com/emdash-cms/emdash/commit/66aeecd1feded23c2ee607b799500c390a04eb92), [`529b28b`](https://github.com/emdash-cms/emdash/commit/529b28bd1c0e4257eaa4436721b110beb09d5ba3), [`52fffdc`](https://github.com/emdash-cms/emdash/commit/52fffdc3556396f48a5320a0213da1a03337f642), [`9def325`](https://github.com/emdash-cms/emdash/commit/9def3252a991f4b750c2d63effd6a474857cd338), [`8fb13cf`](https://github.com/emdash-cms/emdash/commit/8fb13cf7a6bdabab8e9a4288c685be4715febd63), [`3b124f2`](https://github.com/emdash-cms/emdash/commit/3b124f23126fead8884884b9f3d53e3be5d41bd3), [`7887577`](https://github.com/emdash-cms/emdash/commit/788757761732ca691d73f7f8c99e7d3d66bf9dec), [`920e1f3`](https://github.com/emdash-cms/emdash/commit/920e1f3fe6a7c7bf725c85e26f81e588e1201243), [`5f9eb67`](https://github.com/emdash-cms/emdash/commit/5f9eb67440cf89ec473d608e99d8b19272a20e96), [`8fb13cf`](https://github.com/emdash-cms/emdash/commit/8fb13cf7a6bdabab8e9a4288c685be4715febd63), [`b8873c7`](https://github.com/emdash-cms/emdash/commit/b8873c7bd1b1755010bcb46e4511eebccba2b48a), [`965bf33`](https://github.com/emdash-cms/emdash/commit/965bf3303bb71a2444c414585e29960606ae0cbb), [`afa81c5`](https://github.com/emdash-cms/emdash/commit/afa81c5e847f1492f7b5eba134d97d0bbbb3aed7), [`bb8b087`](https://github.com/emdash-cms/emdash/commit/bb8b087c9a79c07336d2cdcadc6cec92428a2b4a), [`e0e60ba`](https://github.com/emdash-cms/emdash/commit/e0e60ba17b93d2022411afb8a3187c08e5142c18), [`8fb13cf`](https://github.com/emdash-cms/emdash/commit/8fb13cf7a6bdabab8e9a4288c685be4715febd63), [`c7b6fdf`](https://github.com/emdash-cms/emdash/commit/c7b6fdfd1f5dd9a168f5d0f6bfa9b7b9ff343145), [`c7b6fdf`](https://github.com/emdash-cms/emdash/commit/c7b6fdfd1f5dd9a168f5d0f6bfa9b7b9ff343145)]: + - @emdash-cms/admin@0.37.0 + - @emdash-cms/registry-client@0.5.0 + - @emdash-cms/registry-verification@0.3.0 + - @emdash-cms/auth@0.37.0 + - @emdash-cms/gutenberg-to-portable-text@0.37.0 + ## 0.36.0 ### Minor Changes diff --git a/packages/core/package.json b/packages/core/package.json index 9265209d49..04b44a9863 100644 --- a/packages/core/package.json +++ b/packages/core/package.json @@ -1,6 +1,6 @@ { "name": "emdash", - "version": "0.36.0", + "version": "0.37.0", "description": "Astro-native CMS with WordPress migration support", "type": "module", "main": "dist/index.mjs", diff --git a/packages/create-emdash/CHANGELOG.md b/packages/create-emdash/CHANGELOG.md index 129af8296a..042fa866f6 100644 --- a/packages/create-emdash/CHANGELOG.md +++ b/packages/create-emdash/CHANGELOG.md @@ -1,5 +1,7 @@ # create-emdash +## 0.37.0 + ## 0.36.0 ## 0.35.0 diff --git a/packages/create-emdash/package.json b/packages/create-emdash/package.json index 085c4d2fcd..2e87aa99cc 100644 --- a/packages/create-emdash/package.json +++ b/packages/create-emdash/package.json @@ -1,6 +1,6 @@ { "name": "create-emdash", - "version": "0.36.0", + "version": "0.37.0", "description": "Create a new EmDash CMS project", "type": "module", "bin": "./dist/index.mjs", diff --git a/packages/gutenberg-to-portable-text/CHANGELOG.md b/packages/gutenberg-to-portable-text/CHANGELOG.md index 926bc902e5..c2f13f6a50 100644 --- a/packages/gutenberg-to-portable-text/CHANGELOG.md +++ b/packages/gutenberg-to-portable-text/CHANGELOG.md @@ -1,5 +1,7 @@ # @emdash-cms/gutenberg-to-portable-text +## 0.37.0 + ## 0.36.0 ## 0.35.0 diff --git a/packages/gutenberg-to-portable-text/package.json b/packages/gutenberg-to-portable-text/package.json index b57d06ff1a..536f4d48cd 100644 --- a/packages/gutenberg-to-portable-text/package.json +++ b/packages/gutenberg-to-portable-text/package.json @@ -1,6 +1,6 @@ { "name": "@emdash-cms/gutenberg-to-portable-text", - "version": "0.36.0", + "version": "0.37.0", "description": "Convert WordPress Gutenberg blocks to Portable Text", "type": "module", "main": "dist/index.mjs", diff --git a/packages/plugin-cli/CHANGELOG.md b/packages/plugin-cli/CHANGELOG.md index 3684f31672..b7476921e6 100644 --- a/packages/plugin-cli/CHANGELOG.md +++ b/packages/plugin-cli/CHANGELOG.md @@ -1,5 +1,44 @@ # @emdash-cms/registry-cli +## 0.10.0 + +### Minor Changes + +- [#2892](https://github.com/emdash-cms/emdash/pull/2892) [`66aeecd`](https://github.com/emdash-cms/emdash/commit/66aeecd1feded23c2ee607b799500c390a04eb92) Thanks [@ascorbic](https://github.com/ascorbic)! - Adds interactive package-profile setup for delegated plugin releases. `emdash-plugin release setup` now creates a missing profile or adds delegated-release settings to an existing valid profile before writing the GitHub Actions workflow. Run `emdash-plugin profile setup` to prepare only the profile. + + Interactive setup asks for the GitHub repository when it is absent from `emdash-plugin.jsonc`, lets you choose when releases require approval, and confirms the profile write. Non-interactive callers must pass `--yes` when a profile change is required. + + The release service returns `PACKAGE_PROFILE_REQUIRED` before accepting artifact uploads when the signed profile is missing, lacks delegated-release settings, or names a different GitHub repository. Existing release intents also terminate with an actionable reason if their authoritative profile becomes invalid. + +- [#2747](https://github.com/emdash-cms/emdash/pull/2747) [`3b124f2`](https://github.com/emdash-cms/emdash/commit/3b124f23126fead8884884b9f3d53e3be5d41bd3) Thanks [@ascorbic](https://github.com/ascorbic)! - Adds typed clients for the experimental delegated release service. `ReleaseServiceClient` submits, polls, and cancels GitHub OpenID Connect release intents; manages publisher workload policies and retained delegation; and lets publishers check whether profile-listed approvers have an active passkey and inspect publisher-scoped audit events through a publisher session. `ReleaseServiceOperatorClient` exposes the Cloudflare Access status and sanitized audit, sharded publisher and approver inventory, pause, suspension, revocation, cancellation, reconciliation, resumable encryption-key rotation, Workflow-backed fleet verification, audited key retirement, encrypted R2 archive, and fail-safe publisher restore and abort operations. + + `ReleaseServiceClient` can request, poll, list, and confirm GitHub workflow connections. The first permanent release run records GitHub's signed repository, workflow, ref, and environment as a pending request and returns a browser approval URL. The publisher must confirm those details before the service creates a workload policy. Tag-based connections can cover the current tag or all version tags while keeping the repository and workflow path exact. + + Both clients validate response envelopes and return stable `ReleaseServiceError` codes with retry metadata. Mutation helpers require idempotency keys, and workload polling requests a fresh token from the configured provider for each call. + + The plugin CLI adds `emdash-plugin release dry-run`, `release submit`, `release status`, and `release cancel` for GitHub Actions jobs. The first `release submit` requests browser approval for the permanent workflow and waits for confirmation before creating an intent. Dry-run verifies existing workload admission without creating a connection request, intent, consuming rate budget, or reserving a version. The commands request audience-bound OIDC tokens from the runner, support JSON output, and use the GitHub run identity as the default idempotency key where a mutation occurs. + + Delegated submissions use a URL-source release record: each package or listing-image artifact supplies a checksum-bound HTTPS URL and no blob. The service stages and uploads those bytes through the publisher's delegation, then creates a blob-only release record. Submit and dry-run reject mixed or blob-backed source inputs before requesting GitHub OIDC. + + Interactive `release delegate`, `revoke`, `workload`, `enrol`, `approve`, and `reject` commands print validated browser handoffs. Publisher application sessions, OAuth credentials, and passkey assertions remain at the release-service origin instead of entering the terminal process. + +- [#2749](https://github.com/emdash-cms/emdash/pull/2749) [`920e1f3`](https://github.com/emdash-cms/emdash/commit/920e1f3fe6a7c7bf725c85e26f81e588e1201243) Thanks [@ascorbic](https://github.com/ascorbic)! - Adds `emdash-plugin release setup` to create the permanent GitHub Actions workflow for delegated plugin releases. The generated workflow builds and attests the plugin, waits for first-run browser authorization, and uploads its exact bundle and provenance through GitHub OIDC before publishing. + + `ReleaseServiceClient.uploadReleaseArtifact()` supports custom workflows that need to stage checksum-bound bundle, image, or provenance bytes. Existing URL-source `release submit` workflows remain supported. + +### Patch Changes + +- [#2743](https://github.com/emdash-cms/emdash/pull/2743) [`d99a0e8`](https://github.com/emdash-cms/emdash/commit/d99a0e835628edca896e304700746707e1bf56e7) Thanks [@ascorbic](https://github.com/ascorbic)! - Fixes saved OAuth sessions failing to refresh or revoke after the original loopback callback server closes. New logins retain the loopback client registration needed to recreate the same OAuth client. + + Sessions created before this fix do not contain that registration metadata and cannot be resumed. Sign in again after upgrading. + +- [#2848](https://github.com/emdash-cms/emdash/pull/2848) [`e0e60ba`](https://github.com/emdash-cms/emdash/commit/e0e60ba17b93d2022411afb8a3187c08e5142c18) Thanks [@ascorbic](https://github.com/ascorbic)! - Adds publisher-created workflow connection invitations to delegated releases. First-time or unmatched GitHub workflows must use a package-bound, single-use invitation before they can request publisher approval; connected workflows continue without one. + + Create the invitation in the publisher dashboard or with `createWorkflowConnectionInvitation()`, then save its value as the repository's `EMDASH_CONNECTION_INVITATION` GitHub Actions secret. The generated release workflow passes this secret to the release Action automatically. Custom workflows can pass `invitationToken` to `requestWorkflowConnection()`, and publishers can reject pending requests with `rejectWorkflowConnection()`. + +- Updated dependencies [[`66aeecd`](https://github.com/emdash-cms/emdash/commit/66aeecd1feded23c2ee607b799500c390a04eb92), [`52fffdc`](https://github.com/emdash-cms/emdash/commit/52fffdc3556396f48a5320a0213da1a03337f642), [`3b124f2`](https://github.com/emdash-cms/emdash/commit/3b124f23126fead8884884b9f3d53e3be5d41bd3), [`920e1f3`](https://github.com/emdash-cms/emdash/commit/920e1f3fe6a7c7bf725c85e26f81e588e1201243), [`e0e60ba`](https://github.com/emdash-cms/emdash/commit/e0e60ba17b93d2022411afb8a3187c08e5142c18), [`c7b6fdf`](https://github.com/emdash-cms/emdash/commit/c7b6fdfd1f5dd9a168f5d0f6bfa9b7b9ff343145)]: + - @emdash-cms/registry-client@0.5.0 + ## 0.9.0 ### Minor Changes diff --git a/packages/plugin-cli/package.json b/packages/plugin-cli/package.json index 8d65290833..51e0bdd722 100644 --- a/packages/plugin-cli/package.json +++ b/packages/plugin-cli/package.json @@ -1,6 +1,6 @@ { "name": "@emdash-cms/plugin-cli", - "version": "0.9.0", + "version": "0.10.0", "description": "CLI for authoring, building, and publishing EmDash plugins. Covers init / build / dev / bundle / publish plus registry search and identity. Atproto OAuth, FAIR-shaped records, sandboxed-plugin-only.", "type": "module", "main": "dist/api.mjs", diff --git a/packages/plugins/embeds/CHANGELOG.md b/packages/plugins/embeds/CHANGELOG.md index 2a84e70fca..168d6f348f 100644 --- a/packages/plugins/embeds/CHANGELOG.md +++ b/packages/plugins/embeds/CHANGELOG.md @@ -1,5 +1,12 @@ # @emdash-cms/plugin-embeds +## 0.1.45 + +### Patch Changes + +- Updated dependencies []: + - @emdash-cms/blocks@0.37.0 + ## 0.1.44 ### Patch Changes diff --git a/packages/plugins/embeds/package.json b/packages/plugins/embeds/package.json index d6d464c3f6..51cf55a53e 100644 --- a/packages/plugins/embeds/package.json +++ b/packages/plugins/embeds/package.json @@ -1,6 +1,6 @@ { "name": "@emdash-cms/plugin-embeds", - "version": "0.1.44", + "version": "0.1.45", "description": "Embed blocks for EmDash CMS - YouTube, Vimeo, Twitter, Bluesky, Mastodon, and more", "type": "module", "main": "src/index.ts", diff --git a/packages/registry-client/CHANGELOG.md b/packages/registry-client/CHANGELOG.md index 81ffb9ee3e..79e260156a 100644 --- a/packages/registry-client/CHANGELOG.md +++ b/packages/registry-client/CHANGELOG.md @@ -1,5 +1,68 @@ # @emdash-cms/registry-client +## 0.5.0 + +### Minor Changes + +- [#2892](https://github.com/emdash-cms/emdash/pull/2892) [`66aeecd`](https://github.com/emdash-cms/emdash/commit/66aeecd1feded23c2ee607b799500c390a04eb92) Thanks [@ascorbic](https://github.com/ascorbic)! - Adds interactive package-profile setup for delegated plugin releases. `emdash-plugin release setup` now creates a missing profile or adds delegated-release settings to an existing valid profile before writing the GitHub Actions workflow. Run `emdash-plugin profile setup` to prepare only the profile. + + Interactive setup asks for the GitHub repository when it is absent from `emdash-plugin.jsonc`, lets you choose when releases require approval, and confirms the profile write. Non-interactive callers must pass `--yes` when a profile change is required. + + The release service returns `PACKAGE_PROFILE_REQUIRED` before accepting artifact uploads when the signed profile is missing, lacks delegated-release settings, or names a different GitHub repository. Existing release intents also terminate with an actionable reason if their authoritative profile becomes invalid. + +- [#2849](https://github.com/emdash-cms/emdash/pull/2849) [`52fffdc`](https://github.com/emdash-cms/emdash/commit/52fffdc3556396f48a5320a0213da1a03337f642) Thanks [@ascorbic](https://github.com/ascorbic)! - Adds `DirectPdsClient.getPackageRepository()` for reading a package profile and every package release from one proof-verified AT Protocol repository export. + + Use the method when authorization or version selection requires a complete signed package snapshot: + + ```ts + const { profile, releases } = + await directPdsClient.getPackageRepository("gallery"); + ``` + + The client verifies the repository commit signature, record blocks, and complete Merkle search tree before returning records. Unsigned `repo.getRecord` and `repo.listRecords` envelopes cannot substitute or omit package data. Repository exports use the client's `maxResponseBytes` limit, which defaults to 5 MiB, and a missing export reports `REPOSITORY_NOT_FOUND`. + +- [#2747](https://github.com/emdash-cms/emdash/pull/2747) [`3b124f2`](https://github.com/emdash-cms/emdash/commit/3b124f23126fead8884884b9f3d53e3be5d41bd3) Thanks [@ascorbic](https://github.com/ascorbic)! - Adds typed clients for the experimental delegated release service. `ReleaseServiceClient` submits, polls, and cancels GitHub OpenID Connect release intents; manages publisher workload policies and retained delegation; and lets publishers check whether profile-listed approvers have an active passkey and inspect publisher-scoped audit events through a publisher session. `ReleaseServiceOperatorClient` exposes the Cloudflare Access status and sanitized audit, sharded publisher and approver inventory, pause, suspension, revocation, cancellation, reconciliation, resumable encryption-key rotation, Workflow-backed fleet verification, audited key retirement, encrypted R2 archive, and fail-safe publisher restore and abort operations. + + `ReleaseServiceClient` can request, poll, list, and confirm GitHub workflow connections. The first permanent release run records GitHub's signed repository, workflow, ref, and environment as a pending request and returns a browser approval URL. The publisher must confirm those details before the service creates a workload policy. Tag-based connections can cover the current tag or all version tags while keeping the repository and workflow path exact. + + Both clients validate response envelopes and return stable `ReleaseServiceError` codes with retry metadata. Mutation helpers require idempotency keys, and workload polling requests a fresh token from the configured provider for each call. + + The plugin CLI adds `emdash-plugin release dry-run`, `release submit`, `release status`, and `release cancel` for GitHub Actions jobs. The first `release submit` requests browser approval for the permanent workflow and waits for confirmation before creating an intent. Dry-run verifies existing workload admission without creating a connection request, intent, consuming rate budget, or reserving a version. The commands request audience-bound OIDC tokens from the runner, support JSON output, and use the GitHub run identity as the default idempotency key where a mutation occurs. + + Delegated submissions use a URL-source release record: each package or listing-image artifact supplies a checksum-bound HTTPS URL and no blob. The service stages and uploads those bytes through the publisher's delegation, then creates a blob-only release record. Submit and dry-run reject mixed or blob-backed source inputs before requesting GitHub OIDC. + + Interactive `release delegate`, `revoke`, `workload`, `enrol`, `approve`, and `reject` commands print validated browser handoffs. Publisher application sessions, OAuth credentials, and passkey assertions remain at the release-service origin instead of entering the terminal process. + +- [#2749](https://github.com/emdash-cms/emdash/pull/2749) [`920e1f3`](https://github.com/emdash-cms/emdash/commit/920e1f3fe6a7c7bf725c85e26f81e588e1201243) Thanks [@ascorbic](https://github.com/ascorbic)! - Adds `emdash-plugin release setup` to create the permanent GitHub Actions workflow for delegated plugin releases. The generated workflow builds and attests the plugin, waits for first-run browser authorization, and uploads its exact bundle and provenance through GitHub OIDC before publishing. + + `ReleaseServiceClient.uploadReleaseArtifact()` supports custom workflows that need to stage checksum-bound bundle, image, or provenance bytes. Existing URL-source `release submit` workflows remain supported. + +- [#2848](https://github.com/emdash-cms/emdash/pull/2848) [`e0e60ba`](https://github.com/emdash-cms/emdash/commit/e0e60ba17b93d2022411afb8a3187c08e5142c18) Thanks [@ascorbic](https://github.com/ascorbic)! - Adds publisher-created workflow connection invitations to delegated releases. First-time or unmatched GitHub workflows must use a package-bound, single-use invitation before they can request publisher approval; connected workflows continue without one. + + Create the invitation in the publisher dashboard or with `createWorkflowConnectionInvitation()`, then save its value as the repository's `EMDASH_CONNECTION_INVITATION` GitHub Actions secret. The generated release workflow passes this secret to the release Action automatically. Custom workflows can pass `invitationToken` to `requestWorkflowConnection()`, and publishers can reject pending requests with `rejectWorkflowConnection()`. + +- [#2746](https://github.com/emdash-cms/emdash/pull/2746) [`c7b6fdf`](https://github.com/emdash-cms/emdash/commit/c7b6fdfd1f5dd9a168f5d0f6bfa9b7b9ff343145) Thanks [@ascorbic](https://github.com/ascorbic)! - Adds `DirectPdsClient` for reading package profiles and releases with AT Protocol repository proofs, and updates experimental decentralized registry installs and updates to verify current signed records directly from the publisher's PDS. + + #### Aggregator record integrity + + Install and update reject aggregator-supplied profile or release metadata whose URI or CID does not match the publisher's signed records. The server returns `AGGREGATOR_RECORD_MISMATCH` before fetching the artifact or requesting consent. + + #### Publisher identity display + + The admin treats handle resolution as an advisory identity signal. It keeps the install button disabled while attempting to resolve the package DID back to a handle, then blocks installation when `resolveDidToHandle()` conclusively returns `"invalid"`. An indeterminate result caused by a network failure, unsupported DID method, or missing handle displays the publisher DID and does not block installation. + + Install and update trust the publisher DID and the signed repository proofs for the profile and release records. A handle is display metadata and is not an authorization or record-integrity input. + + #### Provenance and release policy + + The installer applies the signed profile's release policy, independently fetches and verifies supplied Sigstore/SLSA provenance, and binds moderation labels to the exact profile or release CID. Missing required provenance and any supplied provenance that is unavailable, malformed, mismatched, or unsupported block installation and updates. Artifact checksums, archive paths, bundle limits, manifest identity, and version use the same verification rules as the registry release tooling. + + The verification package also exports `inspectPackageReleaseRecords` for validating signed records and policy before artifact and provenance evidence is available. + + Registry install and update consent now show the exact verified profile and release CIDs, signed publisher policy, and provenance status. Install consent uses permissions and MCP tools read from the verified bundle rather than the aggregator's record copy. + + Install, update, and delegated-release verification require lowercase base32 multibase `sha2-256` multihashes for package artifacts and provenance documents. The plugin CLI already produces this format. The authenticated image-artifact proxy still accepts legacy bare hexadecimal SHA-256 checksums for display-only images. + ## 0.4.0 ### Minor Changes diff --git a/packages/registry-client/package.json b/packages/registry-client/package.json index 5314e66e54..c88feea76f 100644 --- a/packages/registry-client/package.json +++ b/packages/registry-client/package.json @@ -1,6 +1,6 @@ { "name": "@emdash-cms/registry-client", - "version": "0.4.0", + "version": "0.5.0", "description": "Atproto-aware client for the EmDash plugin registry: credential storage, publisher repo operations, and discovery against an aggregator.", "type": "module", "main": "dist/index.js", diff --git a/packages/registry-verification/CHANGELOG.md b/packages/registry-verification/CHANGELOG.md index 14b79867d2..52776f60a9 100644 --- a/packages/registry-verification/CHANGELOG.md +++ b/packages/registry-verification/CHANGELOG.md @@ -1,5 +1,51 @@ # @emdash-cms/registry-verification +## 0.3.0 + +### Minor Changes + +- [#2892](https://github.com/emdash-cms/emdash/pull/2892) [`66aeecd`](https://github.com/emdash-cms/emdash/commit/66aeecd1feded23c2ee607b799500c390a04eb92) Thanks [@ascorbic](https://github.com/ascorbic)! - Adds interactive package-profile setup for delegated plugin releases. `emdash-plugin release setup` now creates a missing profile or adds delegated-release settings to an existing valid profile before writing the GitHub Actions workflow. Run `emdash-plugin profile setup` to prepare only the profile. + + Interactive setup asks for the GitHub repository when it is absent from `emdash-plugin.jsonc`, lets you choose when releases require approval, and confirms the profile write. Non-interactive callers must pass `--yes` when a profile change is required. + + The release service returns `PACKAGE_PROFILE_REQUIRED` before accepting artifact uploads when the signed profile is missing, lacks delegated-release settings, or names a different GitHub repository. Existing release intents also terminate with an actionable reason if their authoritative profile becomes invalid. + +- [#2746](https://github.com/emdash-cms/emdash/pull/2746) [`c7b6fdf`](https://github.com/emdash-cms/emdash/commit/c7b6fdfd1f5dd9a168f5d0f6bfa9b7b9ff343145) Thanks [@ascorbic](https://github.com/ascorbic)! - Adds optional artifact digest candidates to `GitHubProvenanceVerifier`, allowing callers that compute several supported digest algorithms in one isolated artifact fetch to verify the digest selected by a signed SLSA provenance subject. + + Existing callers can continue passing only `artifactDigest`. Successful results return the candidate that matched the signed subject. + + Fixes `@emdash-cms/registry-verification` when it is rebundled into an Astro Cloudflare application, preventing requests from failing during Worker startup. + + Adds `@emdash-cms/registry-verification/records` for Worker callers that supply an explicit `ProvenanceVerifier`. The runtime-neutral entry does not load the Node-oriented default Sigstore verifier, while the package root keeps the existing default-verifier behavior. + + Fixes `@emdash-cms/registry-verification` when it is rebundled into an Astro Cloudflare application, preventing requests from failing during Worker startup. + +- [#2746](https://github.com/emdash-cms/emdash/pull/2746) [`c7b6fdf`](https://github.com/emdash-cms/emdash/commit/c7b6fdfd1f5dd9a168f5d0f6bfa9b7b9ff343145) Thanks [@ascorbic](https://github.com/ascorbic)! - Adds `DirectPdsClient` for reading package profiles and releases with AT Protocol repository proofs, and updates experimental decentralized registry installs and updates to verify current signed records directly from the publisher's PDS. + + #### Aggregator record integrity + + Install and update reject aggregator-supplied profile or release metadata whose URI or CID does not match the publisher's signed records. The server returns `AGGREGATOR_RECORD_MISMATCH` before fetching the artifact or requesting consent. + + #### Publisher identity display + + The admin treats handle resolution as an advisory identity signal. It keeps the install button disabled while attempting to resolve the package DID back to a handle, then blocks installation when `resolveDidToHandle()` conclusively returns `"invalid"`. An indeterminate result caused by a network failure, unsupported DID method, or missing handle displays the publisher DID and does not block installation. + + Install and update trust the publisher DID and the signed repository proofs for the profile and release records. A handle is display metadata and is not an authorization or record-integrity input. + + #### Provenance and release policy + + The installer applies the signed profile's release policy, independently fetches and verifies supplied Sigstore/SLSA provenance, and binds moderation labels to the exact profile or release CID. Missing required provenance and any supplied provenance that is unavailable, malformed, mismatched, or unsupported block installation and updates. Artifact checksums, archive paths, bundle limits, manifest identity, and version use the same verification rules as the registry release tooling. + + The verification package also exports `inspectPackageReleaseRecords` for validating signed records and policy before artifact and provenance evidence is available. + + Registry install and update consent now show the exact verified profile and release CIDs, signed publisher policy, and provenance status. Install consent uses permissions and MCP tools read from the verified bundle rather than the aggregator's record copy. + + Install, update, and delegated-release verification require lowercase base32 multibase `sha2-256` multihashes for package artifacts and provenance documents. The plugin CLI already produces this format. The authenticated image-artifact proxy still accepts legacy bare hexadecimal SHA-256 checksums for display-only images. + +### Patch Changes + +- [#2847](https://github.com/emdash-cms/emdash/pull/2847) [`529b28b`](https://github.com/emdash-cms/emdash/commit/529b28bd1c0e4257eaa4436721b110beb09d5ba3) Thanks [@ascorbic](https://github.com/ascorbic)! - Fixes delegated-release provenance verification so verified GitHub attestations include the repository, workflow, commit, and run identity needed to enforce an exact authorized workload. + ## 0.2.0 ### Minor Changes diff --git a/packages/registry-verification/package.json b/packages/registry-verification/package.json index 7eca41ee95..276c71d350 100644 --- a/packages/registry-verification/package.json +++ b/packages/registry-verification/package.json @@ -1,6 +1,6 @@ { "name": "@emdash-cms/registry-verification", - "version": "0.2.0", + "version": "0.3.0", "description": "Runtime-neutral verification primitives for the EmDash plugin registry.", "type": "module", "main": "dist/index.js", diff --git a/packages/workerd/CHANGELOG.md b/packages/workerd/CHANGELOG.md index c07ee64383..836eeab890 100644 --- a/packages/workerd/CHANGELOG.md +++ b/packages/workerd/CHANGELOG.md @@ -1,5 +1,12 @@ # @emdash-cms/sandbox-workerd +## 0.5.3 + +### Patch Changes + +- Updated dependencies [[`cd294dc`](https://github.com/emdash-cms/emdash/commit/cd294dc4fcbafa6fe6a33692d11b9f9abf1cc45c), [`b06fc63`](https://github.com/emdash-cms/emdash/commit/b06fc6361a88378a697f8d93f7b7718739dc0ed5), [`595a6b1`](https://github.com/emdash-cms/emdash/commit/595a6b12a11e67b89684bc5f5c14fbb6f0fc5e7f), [`7a5d9c1`](https://github.com/emdash-cms/emdash/commit/7a5d9c1838f6afc5649b7bc0940eacf920b40dab), [`de122b4`](https://github.com/emdash-cms/emdash/commit/de122b4e4b65843312bd393d09601e694ef1dee0), [`05d5596`](https://github.com/emdash-cms/emdash/commit/05d559625224fbfd23fc08608c44a46ef3735c3e), [`9def325`](https://github.com/emdash-cms/emdash/commit/9def3252a991f4b750c2d63effd6a474857cd338), [`b8873c7`](https://github.com/emdash-cms/emdash/commit/b8873c7bd1b1755010bcb46e4511eebccba2b48a), [`965bf33`](https://github.com/emdash-cms/emdash/commit/965bf3303bb71a2444c414585e29960606ae0cbb), [`bb8b087`](https://github.com/emdash-cms/emdash/commit/bb8b087c9a79c07336d2cdcadc6cec92428a2b4a), [`30d4076`](https://github.com/emdash-cms/emdash/commit/30d40760ee09faec1c77254d76d021f457e507b8), [`2970377`](https://github.com/emdash-cms/emdash/commit/29703779c2476bc8f68c317f54b59b4a0744bfe0), [`c7b6fdf`](https://github.com/emdash-cms/emdash/commit/c7b6fdfd1f5dd9a168f5d0f6bfa9b7b9ff343145)]: + - emdash@0.37.0 + ## 0.5.2 ### Patch Changes diff --git a/packages/workerd/package.json b/packages/workerd/package.json index 61dc2b94bd..ac6063bcaa 100644 --- a/packages/workerd/package.json +++ b/packages/workerd/package.json @@ -1,6 +1,6 @@ { "name": "@emdash-cms/sandbox-workerd", - "version": "0.5.2", + "version": "0.5.3", "description": "workerd-based plugin sandbox for EmDash on Node.js", "type": "module", "main": "dist/index.mjs", diff --git a/packages/x402/CHANGELOG.md b/packages/x402/CHANGELOG.md index 990cce2321..9b4029144f 100644 --- a/packages/x402/CHANGELOG.md +++ b/packages/x402/CHANGELOG.md @@ -1,5 +1,7 @@ # @emdash-cms/x402 +## 0.37.0 + ## 0.36.0 ## 0.35.0 diff --git a/packages/x402/package.json b/packages/x402/package.json index ca053626b6..4e2007c16f 100644 --- a/packages/x402/package.json +++ b/packages/x402/package.json @@ -1,6 +1,6 @@ { "name": "@emdash-cms/x402", - "version": "0.36.0", + "version": "0.37.0", "description": "x402 payment protocol integration for Astro sites", "license": "MIT", "repository": {