NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Go modules · #1416 by repository stars
Last release today
03 Oct 2026
Ships on a steady schedule
a new release about every 8 days
Rarely documented
notes for 5 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
5 years old
2140 releases · first in 2021
One column per quarter.
Bumped 5 vulnerable transitive npm deps in website/ ( js-yaml , svgo , joi , colord ) via pnpm.overrides , closing 7 open Dependabot alerts — all with…
Add !labels key [default] with missing-key errors, explicit fallbacks, and inheritance coverage.
Document label access and an Atmos Pro example that consumes resolved labels; update agent skills, the feature announcement, and roadmap.
Allow macOS Colima startup 12 minutes for provisioning and its VM restart, and give the enclosing setup step 55 minutes to cover both attempts.
New Features
!labels can retrieve an individual metadata label with an optional fallback value.!labels continues to return the complete label map.Documentation
#approved-reviews-by=0 to the Mergify rule Keep Dependabot/Renovate PRs up to date with main, so Mergify stops running update on a bot PR once it has an approval.Since main moved to GitHub's native merge queue (ruleset "Merge Queue", 2026-08-06), this rule fails on essentially every bot PR that gets enqueued — 6 of the last 12 (#3066, #3067, #3071, #3086, #3091, #3098):
Base branch update has failed
protected branch '' check failed: A pull request for this branch has been added to a merge queue. Branches that are queued for merging cannot be updated.
Mechanism:
Mergify's update action merges main into the PR's head branch. GitHub locks that branch while the PR sits in the native queue.
Mergify's built-in "skip if queued" guard is queue-position = -1, which only reflects Mergify's own queue. There is no Mergify condition for GitHub's native queue, and nothing lands on the head SHA either (no check-run or commit status is created on enqueue), so there is nothing else to condition on.
The rule wakes on PR webhooks, not promptly on pushes to main. On the failing PRs the branch had been behind for 50–70 min unnoticed; Mergify re-evaluated ~2 min after the approval/enqueue events, when the branch was already locked:
| PR | approved | enqueued | update failed | merged |
|---|---|---|---|---|
| #3091 | 02:20:02Z | 02:20:09Z | 02:21:44Z | 02:40Z |
| #3098 | 02:22:21Z | 02:22:28Z | 02:24:37Z | 02:43Z |
| #3067 | 20:35:15Z | 20:35:32Z | 20:37:46Z | 21:25Z |
| #3066 | 20:35:30Z | 20:35:35Z | 20:38:05Z | 21:25Z |
Why approval is the right gate: the "Required Pull Request Reviews" ruleset requires 1 approval with no bypass actors, so GitHub cannot enqueue a PR without a current approval. Approval is therefore a strictly earlier signal than enqueue, with no timing dependency (an Actions workflow on pull_request: enqueued toggling a label would be racing that same ~2 min window). After approval the merge queue owns freshness by re-testing against current main.
Side benefit: the ruleset has dismiss_stale_reviews_on_push: true, so today a Mergify update landing after approval dismisses the approval and forces a re-review. That stops.
Context: this rule was added in #2752 because main then had strict: true (require branches up to date). That protection is gone with the merge queue, so the alternative of deleting the rule outright is also valid; this keeps pre-review freshness for bot PRs.
The failures were cosmetic (Mergify is not a required status check; the PRs merged via the queue), but they show up as a red check on every bot PR.
update action docs: "You do not need to use this action if you use the merge queue."cloudfront-distribution-id / cloudfront-invalidation-paths input and invalidation step to the shared .github/actions/s3-deploy composite action.website-deploy-prod.yml (invalidates /* on the prod atmos-docs-site-spa distribution E2WVYUGW40ZPA8) and website-preview-deploy.yml (invalidates only /pr-<N>/* on the dev distribution E1U29O8X09M5UR, so one PR's deploy never busts every other open PR's preview cache).cloudfront.amazonaws.com:443 to both workflows' Harden Runner allowlist.ChunkLoadError (404 on a hashed JS bundle). Root cause: website-deploy-prod.yml runs aws s3 sync --delete but never invalidated CloudFront, and the distribution's legacy per-behavior TTL (min_ttl: 60) floors edge caching regardless of origin Cache-Control. A client hitting a stale edge-cached index.html within that window got 404s on chunks a newer deploy had already deleted.docs/fixes/2026-09-08-website-deploy-race-serialize.md) — confirmed via GitHub Actions run history that the existing concurrency: guard is working correctly.cloudfront:CreateInvalidation/cloudfront:GetInvalidation scoped to their own distribution (confirmed live via aws iam get-role-policy, not just the infra-live Terraform source) — it was simply unused, so this fix is fully contained in cloudposse/atmos with no infra-live change needed.Completed.docs/fixes/2026-09-09-website-cloudfront-stale-chunk-invalidation.mddocs/fixes/2026-09-08-website-deploy-race-serialize.md (related prior incident, confirmed not the same root cause)Bug Fixes
Documentation
Adds pkg/git/providers/azuredevops as a second PullRequestPublisher implementation alongside the existing GitHub provider, so atmos vendor update --pull-request can target Azure DevOps Repos.
azuredevops provider, registered via init() under ci.pull_request.provider: azuredevops.schema.VendorPullRequestConfig gains organization / project / repository fields, since Azure DevOps addresses a repository with three segments instead of GitHub's owner/repository pair. pkg/config's bridgeVendorUpdaterConfig now syncs these three fields into viper along with the rest of vendor.ci.pull_request.* — they were declared on the schema and read by cmd/vendor/update.go but never actually bridged, so provider: azuredevops always failed configuration validation regardless of what atmos.yaml declared (found by testing against a real Azure DevOps org).PullRequestOptions gains an additive Namespace []string field to carry the extra segment (nil for GitHub; the GitHub provider now rejects a non-empty Namespace instead of silently ignoring it).AZURE_DEVOPS_EXT_PAT (HTTP Basic, empty username).reviewers entry (a display name, account name, or email) is resolved through the Identities API before being applied. A group match or an ambiguous match fails loudly instead of guessing; only individuals are supported today. Confirmed against a real Azure DevOps org, resolving both a display name and an email correctly.assignees fails loudly instead of being silently dropped.atmosgit.PullRequestBodyBadger interface lets a PullRequestPublisher return its own badge, since each forge's pull request markdown has its own quirks (raw HTML support, image hosting requirements, light/dark switching); a publisher that doesn't implement it gets a static text-link fallback. GitHub keeps its existing raw-HTML <picture> badge with light/dark switching. Azure DevOps uses a plain, sized markdown image (![]() with Azure DevOps' own =WIDTHxHEIGHT sizing syntax) instead of raw HTML, which doesn't render in Azure DevOps pull request descriptions at all — confirmed against a real pull request.website/docs/cli/configuration/vendor.mdx, a changelog post, and a roadmap milestone.The PullRequestPublisher interface was explicitly designed to support more providers than GitHub, but nothing had implemented a second one yet. Teams hosting components in Azure DevOps Repos had no way to use the Component Updater's automated PR workflow at all.
pkg/git/pull_request.gopkg/git/providers/github/pull_request.gomain for any git-ref-versioned vendor source): #3076New Features
vendor update --pull-request.AZURE_DEVOPS_EXT_PAT.Bug Fixes
Documentation
CastProDownload, a "Download ▾" split-button component offering rendered GIF/MP4/SVG/WEBM artifacts of any .cast file in a public GitHub repo, via the new Atmos Pro cast-rendering service.CastProEmbed, an <iframe> wrapper for the service's hosted HTML player, for embedding a cast player without hosting the source file locally.CastProArtifact module: a pure URL builder (buildArtifactUrl/buildEmbedUrl, with unit tests) and a useCastArtifact hook that follows the render service's three response shapes — an already-rendered artifact (triggers a native download), a still-rendering one (polls on Retry-After, capped at ~60s), and a hard error (surfaces the JSON error message)./cast-pro-demo page exercising both components against a real cloudposse/atmos cast path, and a test:cast-pro-artifact npm script..cast recording in a public GitHub repo to GIF/MP4/SVG/WEBM, or to a hosted HTML player. This lets atmos.tools offer downloads/embeds of casts without needing them committed as static assets first, unlike the existing CastPlayer component.no-release.https://atmos-pro.com/casts/{owner}/{repo}/{ref}/{path}.cast.{gif|mp4|svg|webm}New Features
Tests
Documentation
Documents a Homebrew-specific gap in docs/prd/fips-140-mode.md's "Where It's Wired In" table: the atmos formula in Homebrew/homebrew-core builds with a plain go build and no GOFIPS140, so brew install atmos produces a binary reporting "fips": false in atmos version --format=json, while GitHub Release binaries (built via .goreleaser.yml, which does set GOFIPS140=latest) correctly report "fips": true.
atmos version --format=json showing fips: false looked like GoReleaser had regressed. Investigation confirmed GoReleaser and the local atmos build path (magefiles/build.go) both set GOFIPS140=latest correctly. The actual gap is Homebrew's from-source build, which lives entirely outside this repo. The PRD's wiring table previously claimed "every distinct Go-toolchain build invocation in the repo sets GOFIPS140" without mentioning that Homebrew isn't covered by that claim at all (it's not a build invocation in this repo), so this was an unflagged blind spot.
A fix is proposed upstream: Homebrew/homebrew-core#302847 (draft, pending Homebrew maintainer review — outside this repo's control).
docs/prd/fips-140-mode.mdinternal/exec/version.go (isFIPSBuild() — reads crypto/fips140.Enabled() at runtime).goreleaser.yml (sets GOFIPS140=latest for release binaries)Documentation
Bug Fixes
Adds .claude/skills/homebrew/SKILL.md, an agent skill covering the Homebrew/homebrew-core formula PR workflow for atmos: the real PR template, AI/LLM disclosure rules, the 50-character commit-subject limit, and how to run brew install --build-from-source / brew test / brew audit --strict / brew style locally via a disposable tap without a full homebrew-core clone.
A prior attempt at a Homebrew formula PR (Homebrew/homebrew-core#302847) was auto-closed by BrewTestBot for looking AI-generated and skipping the real PR template. This skill exists so the next attempt (fixing that PR, per its own "do not open a new PR" instruction) follows homebrew-core's actual conventions instead of repeating the same mistake.
.claude/skills/homebrew/SKILL.mdBug Fixes
Reliability
Documentation
actions/setup-go's built-in cache with a restore-only custom cache (restore-keys fallback, ImageOS-free key) in .github/actions/setup-go-cache; no CI job ever saves Go caches anymoresetup-go-cache-warmup.yml the sole cache writer: adds a Linux leg, runs the real compiles (go build ./..., mage acceptance:precompile, and a -race/CGO warm for the race job's namespace), saves under run-unique keys, and triggers on go.mod/go.sum pushes to mainextras=s3-cache so all Linux jobs share the GitHub cache backend; upgrade the race job to runner=xlargekubernetes-e2e nullifying its restored cache with a GOCACHE overridewarm-cache job); PR runs are now restore-onlycustom-gcl binary (full golangci-lint rebuild every run today), the pnpm store in both website workflows, and add restore-only toolchain caches to lint, hooks-tflint, floci, floci-go, and race.tool-versions changes (hashFiles in atmos.yaml ci.cache.key)Storage-level caching works (92 entries / ~99GB active, no eviction thrash), but the caches were functionally hollow: setup-go entries are immutable per go.sum hash, and the old warmup only ran go mod download — so whenever it saved first, the frozen entry had an empty GOCACHE and every later build compiled from scratch while logging a cache hit. Measured live on run 34179823625: 504s go build in Build(linux), a 27-minute race job, and 1-1.8GB re-saved per platform per PR after every dependency merge. The Linux split-brain (build job on RunsOn S3, shards on GitHub cache) meant the warmest cache in the run was invisible to the ten Linux acceptance shards.
Deliberately not done: relocating atmos's own cache root to the Windows work disk — the acceptance shards assert XDG-default paths, and the cache's saver and restorers must agree on the root.
Post-merge verification: dispatch setup-go-cache-warmup.yml, confirm multi-GB go-cache-* entries on refs/heads/main, then compare Build(linux) go build time (expect ~504s → well under 2 min) and race-job duration (expect ~27m → ~10-15m).
🤖 Generated with Claude Code
CI Improvements
Website Builds
Bug Fixes
Documentation
format field to the json version-tracker manager's options.set entries (pkg/version/managers/json/json.go): a Go template (Sprig string functions + Atmos template functions) rendered against the resolved manager.VersionRef, whose output replaces the verbatim value before it's written into the target JSON field.yaml file manager (pkg/version/managers/yaml/) that writes locked values into YAML files at configured field paths, reusing Atmos's own format-preserving YAML editor (pkg/yaml, the engine behind atmos config set/atmos stack set) so comments, anchors/aliases, and key order on untouched fields survive the write. It supports the same optional format field as the json manager, and the same dot-notation path syntax as atmos config set/atmos stack set (sources[0].version, metadata."weird.key"), which is distinct from the json manager's sjson/gjson dialect.format-template rendering and duplicate-path-check logic shared by both managers into pkg/version/managers/format.go and pkg/version/managers/pathutil.go, and updates the json manager to use them (no behavior change).ErrVersionJSONFormatInvalid, ErrVersionYAML*) so a bad format template or an invalid options.set configuration is rejected outright instead of silently writing garbage or an empty string.yaml-specific test that a fixture with comments and an anchor/alias survives an edit untouched, and a test that a bare-digit version string round-trips as a YAML string rather than silently becoming an int.website/docs/cli/configuration/version/files.mdx): a format example/section for json, and a new "Updating YAML Files" section for yaml.json-manager-format, version-tracker-yaml-manager) and two roadmap milestones announcing both features.json manager always wrote a locked dependency's resolved value byte-for-byte. For a dependency sourced from github-releases/github-tags, that value is the raw git tag (e.g. v1.228.0) — wrong when the target field expects bare semver, such as a plugin manifest's version field. Reshaping happens at the write site (setEntry), not on the shared manager.VersionRef type or the lock file, since the same locked dependency may feed multiple write sites that want different shapes, and versions.lock.yaml should stay the untouched, auditable record of what was resolved against upstream.template manager (renders a whole *.tmpl source to a sibling file) nor marker (a plain comment-annotated token rewrite) patches a single field in an existing, hand-maintained YAML document while preserving comments and anchors. The yaml manager fills that gap by reusing Atmos's already-shipped format-preserving YAML editor instead of building new YAML-parsing logic.json-manager Version Tracker gaps shipped in #2900 and #2966.New Features
track apply.Bug Fixes
Documentation
t.Parallel() to every top-level test and t.Run closure in the test files that have no parallelism blockers, across the packages that dominate the CI race job's wall clock:
pkg/describe (46/49 tests); pkg/toolchain itself is excluded — its TestMain routes UI output into one captured buffer, so any parallel test that emits ui.* output races on it, and its heavy tests must stay serial regardlessinternal/exec (76), pkg/runner/step (29), pkg/ai/tools/atmos (29), pkg/config (22), pkg/pro (15), pkg/toolchain/installer (10), cmd/terraform (8), pkg/terraform/ui (7), cmd/toolchain (3), pkg/toolchain/registry/aqua (2)pkg/describe tests serial with explained //nolint:paralleltest directives (they invoke sibling test functions directly with their own *testing.T, so a second t.Parallel() panics)-parallel=4 (ATMOS_TEST_RACE_PARALLEL), and every acceptance-shard test process gets -parallel / -test.parallel = half the runner's cores (ATMOS_TEST_PARALLEL) — without it the 3-vCPU hosted macOS runners oversubscribed and several shards ran 50-150% slower (e.g. shard 1: 665s → 1134s) while 4-vCPU Linux/Windows were unchangedparalleltest linter scoped (via the existing path-except idiom in .golangci.yml) to exactly the converted files so they don't regress; tparallel (already on) caught seven parent tests deferring cleanup while running parallel subtests, now t.Cleanupcmd/stack's fixture copy read the basic scenario's gitignored terraform.tfstate.d/…/terraform.tfstate while a shard-mate was writing it ("another process has locked a portion of the file"); the copy now skips Terraform runtime artifacts via the shared sandbox helper's predicate, exported as testhelpers.IsTerraformArtifactThe CI race job runs the whole ./... suite un-sharded, so its ~27-minute wall clock floors on the slowest packages — pkg/toolchain (556s), pkg/describe (327s), internal/exec (323s), cmd (247s), measured from run 34179823625. Go parallelizes across packages but runs tests within a package serially unless they call t.Parallel(). Locally pkg/describe drops from 18.1s to ~7-10s.
Method: mechanical conversion, then per-package go test -count=2 and go test -race as the arbiter — any file whose tests failed, panicked, or raced was reverted (96 files in the local pass, 13 more after CI runs exposed what local validation could not: package-cache resets (detectionCache, ClearBaseComponentConfigCache) and global-registry writes (atmosio.RegisterSecret) that the mutex makes race-clean but not order-safe, gomonkey code patching in TestGetAffectedComponents (skipped locally under -race and on darwin/arm64), and logical races on tests that swap package-level seams such as os.Stdin, executeTerraformLint, renderAndDeliver, tfoutput.SetDefaultExecutor, SetLastAuthContext, SetLastMergeContext, and one that hits pkg/terminal's unsynchronized lazy viper init). Files skipped or reverted use t.Setenv/t.Chdir (directly or via fixture helpers), mutate package globals (mock getters, SetAtmosConfig, viper, data.InitWriter/ui.InitFormatter, shared cobra command trees), share package caches, or raced under -race. All of cmd/list stays serial: its initTestIO/pkg/flags bindFlagToViper path races on package-level parsers. Those need dependency-injection refactoring before they can go parallel — that's the remaining lever on the race job's floor.
Two genuine production concurrency bugs surfaced by -race during this work (not fixed here): pkg/ui/markdown.NewRenderer races on glamour's shared style bytes when called concurrently (any parallel errors.Format), and the lazy viper.BindEnv init in pkg/ui/theme/pkg/terminal is unsynchronized (concurrent-map panic).
Validated: every converted package green under -count=2 and -race (zero data races), go vet clean, paralleltest lint clean over all scoped packages. Companion to #3077, which warms the race job's build cache and upsizes its runner.
🤖 Generated with Claude Code
fix(ci): serialize website deploys and fix Sentry loader key Erik Osterman (Cloud Posse) (@osterman) (#3072) ## whatconcurrency group to website-deploy-prod.yml (cancel-in-progress: false) so pushes to main deploy one at a time.concurrency group to website-preview-deploy.yml for the same reason.docusaurus-plugin-sentry.docs/fixes/2026-09-08-website-deploy-race-serialize.md.atmos.tools went blank tonight. The live index.html referenced runtime~main.99cb7223.js and main.7524adc2.js, both 404.
The merge queue landed #3024 and #3058 on main three minutes apart. Each push triggered Website Deploy Prod, and the workflow had no concurrency group. Both runs execute aws s3 sync --delete against the single shared origin prefix, and Docusaurus content-hashes every bundle, so two builds never share asset names.
| Time (UTC) | Run | Action |
|---|---|---|
| 02:27:30 | A (#3024) | uploads main.7524adc2.js, runtime~main.99cb7223.js |
| 02:27:55 | A | uploads index.html referencing A's bundles |
| 02:27:58 | B (#3058) | --delete removes A's two bundles; uploads its own |
B's sync plan was computed before A's index.html landed, so B never rewrote it. Result: A's index.html pointing at bundles B deleted, and both runs green.
cancel-in-progress stays false on purpose. Aborting a run mid-sync leaves a half-uploaded site, which is the same failure. With a group, the in-flight deploy finishes, the newest pending run queues behind it, and older pending runs are superseded.
Separately, the same console showed the Sentry loader script CORS-blocked. docusaurus-plugin-sentry v2 builds https://js.sentry-cdn.com/${DSN}.min.js, so the option must be the Loader Script public key, not the DSN. The corrected URL returns 200; the old one returned 404. This did not cause the outage.
actionlint passes on both workflows; the Sentry head tag was rendered locally through the installed plugin and produces the corrected src.🤖 Generated with Claude Code
Bug Fixes
Documentation
/security page to atmos.tools showing our OpenSSF Scorecard and OpenSSF Best Practices badge results.website/plugins/fetch-security-posture) — no client-side runtime dependency on the third-party APIs, and the build never fails if either API is temporarily unavailable (each dataset degrades gracefully with a "verify directly" fallback link).api.scorecard.dev, bestpractices.dev) and linking straight back to them lets evaluators verify the numbers themselves instead of trusting a cached badge.website/plugins/fetch-github-stars, fetch-latest-release), so it fits the codebase's established conventions rather than introducing a new fetch mechanism.cloudposse/atmos recently earned a passing OpenSSF Best Practices badge (project #14393).New Features
Documentation
Bug Fixes
Demo Updates
atmos scaffold generate --update (and atmos init --update, sharing the same engine) with the default --merge-strategy=manual now writes real <<<<<<</=======/>>>>>>> conflict markers plus every non-conflicting change on a real merge conflict, instead of discarding the whole merge and writing nothing.atmos init --update now pins its initial --git commit to .atmos/init/metadata.yaml, the same way atmos scaffold generate already does, and reads it back as the merge base instead of defaulting to live HEAD.--force combined with --update is no longer a silent no-op: an unset --merge-strategy now defaults to theirs in that combination, and an explicitly-passed ours/manual together with --force --update is now a clear validation error instead of silently doing nothing.--update against a file already left with unresolved conflict markers now fails fast with a specific message instead of an opaque three-way merge failed.--force-suggesting error hint across the merge engine to describe what --force actually does now.main before this fix.atmos init --update has the exact base-ref-pinning bug #2989 fixed for atmos scaffold generate, because the fix lived only in cmd/scaffold and was never ported to cmd/init — the two commands' base-ref resolution had drifted apart. This PR extracts the shared logic into pkg/generator/gitinit.go so it can't drift apart a second time.--force being silently ignored under --update made several existing error hints false, and left users with no way to push through a conflict without hand-editing the file.See docs/fixes/2026-09-04-scaffold-init-update-merge-fixes.md for full context, the complete list of changed files, and how each fix was validated (unit tests plus live end-to-end verification against a built binary).
docs/fixes/2026-09-04-scaffold-init-update-merge-fixes.mdinit --update and scaffold generate --update now use the correct target and previously pinned merge base.--force --update defaults to using the template version; incompatible strategies are rejected.atmos terraform test --ci discarded every run and file event from tofu test -json: OpenTofu emits one test_run/test_file event per subject carrying only status, with no progress field, and the parser only accepted events with progress: "complete". The test_summary event has the same shape in both tools, so badge counts stayed right while the results table came out empty and <component>.junit.xml reported tests="0" on a passing run.diagnostic after the run's final event; the parser only attached diagnostics that arrived before it, so failing runs lost their message and file:line (and with them the ::error annotation and the summary's Details column) under Terraform too.testEventComplete accepts a bare terminal status as final; attachLateDiagnostics reconciles diagnostics that arrive after their run. The stop-gap backfillMissingTestJSONRuns guard stays as a last resort but now warns loudly if it ever fires.git merge-base --is-ancestor and a fresh Docker repro that #2942/#2960 are intact and shipped in v1.228.0; re-verification note appended to the existing fix doc.The report came from a repository whose toolchain pins tofu. This repo's own examples/terraform-tests fixture is Terraform-only (it uses variable blocks that OpenTofu rejects), so eleven local repro runs never hit it; diffing raw -json streams from both tools on a minimal module exposed the missing progress field and the diagnostic ordering.
run detail unavailable (pass) and no file/line.components.terraform.command: tofu, one passing + one failing run, GITHUB_ACTIONS=true … --ci): JUnit tests="2" failures="1" with real names and line="12" on the failure; summary lists both runs with tests/min.tftest.hcl:12 in Details; ::error file=…,line=12 annotation emitted.examples/terraform-tests still yields tests="4" with all real run names.docs/fixes/2026-09-08-ci-test-json-opentofu-runs-dropped.mddocs/fixes/2026-08-19-emulator-endpoint-job-container-network-join.md (re-verification note)Bug Fixes
Documentation
Chores
atmos.tools/schemas/atmos/atmos-manifest/1.228.0/atmos-manifest.json) 404ing shortly after every release.atmos-manifest/atmos-config snapshots for all 7 releases affected since the pinning feature shipped (v1.224.0-v1.228.0) directly in prod S3 (already live, no PR needed for that part)..github/scripts/s3-deploy-with-charset.sh and the 4 near-duplicate schema generate/publish steps in website-deploy-prod.yml into two reusable composite actions: .github/actions/s3-deploy and .github/actions/publish-atmos-schema.website/ (js-yaml, svgo, joi, colord) via pnpm.overrides, closing 7 open Dependabot alerts — all within-major patch bumps.website-deploy-prod.yml only regenerated the pinned per-release schema snapshot if: github.event_name == 'release', but every deploy (including ordinary pushes to main) ran aws s3 sync --delete against the same S3 prefix. Since a pinned snapshot from an older release was absent from that run's local build, --delete pruned it — so a pinned URL survived only until the next routine deploy. The docs' own example version (1.219.0) had already succumbed to this.--delete and publishes each release's new snapshot via a direct, non-deleting aws s3 cp, decoupling it from the routine sync's deletion scope..github/scripts/*.sh, per this repo's "CI scripts live in local actions" convention.git push-triggered security-remediate pass; the current branch already had an open diff, so the fixes landed here directly.New Features
Improvements
atmos auth logout (including --all --force) now removes the realm-scoped Azure MSAL token cache (~/.azure/atmos/{realm}/msal_token_cache.json) in addition to the keyring entry and the Atmos device-code token it already cleared.~/.azure/msal_token_cache.json) is intentionally preserved — it is co-owned with a user's own az login session.azure/device-code and azure/interactive providers (interactive embeds device-code); azure/cli and azure/oidc never create a realm MSAL cache and are unaffected.atmos auth logout followed by atmos auth login did not pick up the new access — they kept getting 403 AuthorizationFailed (e.g. Microsoft.ContainerService/managedClusters/read), and atmos auth whoami showed the credential still expiring on the old session's clock.~/.cache/atmos/azure-device-code/<provider>/token.json) but never the realm MSAL cache — a different file — so the next login silently re-minted a token from the stale cached account/refresh token, which predated the PIM elevation.rm ~/.azure/atmos/<realm>/msal_token_cache.json). This makes logout actually forget the sessNote truncated.
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
feat: implement native Helm release lifecycle controls Mikhail Shirkov (@shirkevich)
release policy with release-wide defaults and operation-specific install, upgrade, and delete overlays.values: key decodes to null, keep inline and values_files template strings consistent, propagate top-level secrets, and honor command-local --mask=false.This is 2 of 4 in the native Helm lifecycle stack and is based on #2846:
release tree, including distinct install and upgrade timeouts and upgrade rollback plus cleanup policy.git diff --check, and generic fixture-name audit pass.docs/prd/native-helm-release-lifecycle.mdThis is 1 of 4 in the native Helm lifecycle stack:
docs/prd/native-helm-release-lifecycle.md.github/workflows/release.yml): add golang.org, go.dev, raw.githubusercontent.com, and dl.google.com to the summarize-notes job's harden-runner allowed-endpoints..github/workflows/build.yml): add --skip=publish to the GoReleaser step in the sign-and-attest-release job..github/workflows/build.yml): replace the broken dawidd6/action-homebrew-bump-formula with a direct brew bump-formula-pr call.docs/fixes/2026-09-06-*.md.Publishing v1.228.0 succeeded (release, binaries, Docker image, website all green), but three downstream jobs failed. None relate to the release contents — they are pre-existing pipeline gaps that were previously masked by the syft break fixed in #3061.
Set up Go with getaddrinfo EAI_AGAIN golang.org before any summarization ran: its egress allow-list lacked the toolchain hosts actions/setup-go resolves (golang.org/go.dev) and downloads from (raw.githubusercontent.com/dl.google.com). (This is not the 125k release-body overflow the summarizer guards against — the draft body was ~5 KB.)goreleaser release --clean against the already-published release; GoReleaser PATCHed target_commitish, which GitHub rejects on a published release (422 Validation Failed). The job only rebuilds dist/* for provenance attestation, so it must not publish — --skip=publish fixes it.undefined method 'safe_system' for module Homebrew. v8 has byte-identical code and the upstream Homebrew-5 fix was reverted, so bumping the action does not help. The wrapped command brew bump-formula-pr is fine, so this calls it directly (atmos is in homebrew-core).docs/fixes/2026-09-06-release-notes-summarizer-egress-golang-org.md, docs/fixes/2026-09-06-sign-and-attest-goreleaser-skip-publish.md, docs/fixes/2026-09-06-homebrew-bump-safe-system.md.brew bump-formula-pr command this PR automates, which pre-validates fix 3.release: published run; its fix doc records the manual fallback.Bug Fixes
Documentation
release data to CI job summaries.hookOnly to watcher promotion.values_files targets in --affected selection, including files outside the chart directory.tests/fixtures/scenarios/helm-lifecycle.This is 4 of 4 in the native Helm lifecycle stack and is based on #2848:
--affected execution must react to the files whose values are rendered, not only to changes in the values_files list itself.components/helm and an unrelated-file negative control.hookOnly to watcher promotion is reported before the action at the default log level with its field path and machine-readable code; Debug output distinguishes derived policy from a directly configured watcher.--dependency-update; six objects include both weighted hooks and the preserved inline Helm template expression, and its full k3s workflow passes end to end.describe component confirms deep-merged stack and component release policy.git diff --check pass.New Features
!secret options, global-scope secret management, and improved secret masking.Bug Fixes
Documentation
--dependency-update support to chart-loading operations without hidden network access by default.This is 3 of 4 in the native Helm lifecycle stack and is based on #2847:
context.Background(), preventing signals and scheduler cancellation from consistently reaching active operations.git diff --check passes.docs/prd/native-helm-release-lifecycle.mdNew Features
--dependency-update support for Helm template, apply, diff, and plan operations.Bug Fixes
Documentation
| Package | Change | Age | Confidence |
|---|---|---|---|
| github.com/agiledragon/gomonkey/v2 | v2.14.0 → v2.14.2 |
v2.14.2: Fix Darwin ARM64 same-page SIGBUS and private method patch corruptionwrite removes execute permission from its own active page (NOP isolation was only 4 KiB on 16 KiB pages)B plus an executable trampolineReference: #188
v2.14.1: Fix potential SIGBUS on Darwin📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.
fix(deps): update module filippo.io/age to v1.3.2 @[renovate[bot]](https://github.com/apps/renovate) (#3066) This PR contains the following updates:| Package | Change | Age | Confidence |
|---|---|---|---|
| filippo.io/age | v1.3.1 → v1.3.2 |
v1.3.2: age v1.3.2age v1.3.2 is a minor release with a wide range of fixes and hardening improvements.
Some previously-accepted inputs are now rejected: headers over 2 MiB or 1024 recipients, malformed SSH keys in recipients files, and non-UTF-8 plaintext written to a terminal (force with -o -).
Pre-built binaries now cover windows/arm64 and darwin/amd64, and release archives include the compatibility plugins (age-plugin-pq, age-plugin-tag, and age-plugin-tagpq).
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.
fix(deps): update aws-sdk-go-v2 monorepo @[renovate[bot]](https://github.com/apps/renovate) (#3044) > ℹ️ **Note** > > This PR body was truncated due to platform limits.This PR contains the following updates:
v1.45.1Note truncated.
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
ci: install syft for GoReleaser SBOM generation Andriy Knysh (@aknysh)
create_namespace setting to native Helm components Andriy Knysh (@aknysh) (#3034)3a39a05 to d7e1218 @dependabot[bot] (#3013)025b74b to b8c3669 in /.devcontainer @dependabot[bot] (#3014)This is a feature preview based on an open pull request. It is intended for testing artifacts and validating functionality before the feature is merge
This is a feature preview based on an open pull request. It is intended for testing artifacts and validating functionality before the feature is merged.
Warning
This release is temporary and may be removed at any time without notice.
This is a feature preview based on an open pull request. It is intended for testing artifacts and validating functionality before the feature is merge
This is a feature preview based on an open pull request. It is intended for testing artifacts and validating functionality before the feature is merged.
Warning
This release is temporary and may be removed at any time without notice.
This is a feature preview based on an open pull request. It is intended for testing artifacts and validating functionality before the feature is merge
This is a feature preview based on an open pull request. It is intended for testing artifacts and validating functionality before the feature is merged.
Warning
This release is temporary and may be removed at any time without notice.
This is a feature preview based on an open pull request. It is intended for testing artifacts and validating functionality before the feature is merge
This is a feature preview based on an open pull request. It is intended for testing artifacts and validating functionality before the feature is merged.
Warning
This release is temporary and may be removed at any time without notice.
This is a feature preview based on an open pull request. It is intended for testing artifacts and validating functionality before the feature is merge
This is a feature preview based on an open pull request. It is intended for testing artifacts and validating functionality before the feature is merged.
Warning
This release is temporary and may be removed at any time without notice.
This is a feature preview based on an open pull request. It is intended for testing artifacts and validating functionality before the feature is merge
This is a feature preview based on an open pull request. It is intended for testing artifacts and validating functionality before the feature is merged.
Warning
This release is temporary and may be removed at any time without notice.
This is a feature preview based on an open pull request. It is intended for testing artifacts and validating functionality before the feature is merge
This is a feature preview based on an open pull request. It is intended for testing artifacts and validating functionality before the feature is merged.
Warning
This release is temporary and may be removed at any time without notice.
This is a feature preview based on an open pull request. It is intended for testing artifacts and validating functionality before the feature is merge
This is a feature preview based on an open pull request. It is intended for testing artifacts and validating functionality before the feature is merged.
Warning
This release is temporary and may be removed at any time without notice.
This is a feature preview based on an open pull request. It is intended for testing artifacts and validating functionality before the feature is merge
This is a feature preview based on an open pull request. It is intended for testing artifacts and validating functionality before the feature is merged.
Warning
This release is temporary and may be removed at any time without notice.
This is a feature preview based on an open pull request. It is intended for testing artifacts and validating functionality before the feature is merge
This is a feature preview based on an open pull request. It is intended for testing artifacts and validating functionality before the feature is merged.
Warning
This release is temporary and may be removed at any time without notice.
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
This is a feature preview based on an open pull request. It is intended for testing artifacts and validating functionality before the feature is merge
This is a feature preview based on an open pull request. It is intended for testing artifacts and validating functionality before the feature is merged.
Warning
This release is temporary and may be removed at any time without notice.
This is a feature preview based on an open pull request. It is intended for testing artifacts and validating functionality before the feature is merge
This is a feature preview based on an open pull request. It is intended for testing artifacts and validating functionality before the feature is merged.
Warning
This release is temporary and may be removed at any time without notice.
This is a feature preview based on an open pull request. It is intended for testing artifacts and validating functionality before the feature is merge
This is a feature preview based on an open pull request. It is intended for testing artifacts and validating functionality before the feature is merged.
Warning
This release is temporary and may be removed at any time without notice.
This is a feature preview based on an open pull request. It is intended for testing artifacts and validating functionality before the feature is merge
This is a feature preview based on an open pull request. It is intended for testing artifacts and validating functionality before the feature is merged.
Warning
This release is temporary and may be removed at any time without notice.
This is a feature preview based on an open pull request. It is intended for testing artifacts and validating functionality before the feature is merge
This is a feature preview based on an open pull request. It is intended for testing artifacts and validating functionality before the feature is merged.
Warning
This release is temporary and may be removed at any time without notice.
This is a feature preview based on an open pull request. It is intended for testing artifacts and validating functionality before the feature is merge
This is a feature preview based on an open pull request. It is intended for testing artifacts and validating functionality before the feature is merged.
Warning
This release is temporary and may be removed at any time without notice.
This is a feature preview based on an open pull request. It is intended for testing artifacts and validating functionality before the feature is merge
This is a feature preview based on an open pull request. It is intended for testing artifacts and validating functionality before the feature is merged.
Warning
This release is temporary and may be removed at any time without notice.
This is a feature preview based on an open pull request. It is intended for testing artifacts and validating functionality before the feature is merge
This is a feature preview based on an open pull request. It is intended for testing artifacts and validating functionality before the feature is merged.
Warning
This release is temporary and may be removed at any time without notice.
This is a feature preview based on an open pull request. It is intended for testing artifacts and validating functionality before the feature is merge
This is a feature preview based on an open pull request. It is intended for testing artifacts and validating functionality before the feature is merged.
Warning
This release is temporary and may be removed at any time without notice.
This is a feature preview based on an open pull request. It is intended for testing artifacts and validating functionality before the feature is merge
This is a feature preview based on an open pull request. It is intended for testing artifacts and validating functionality before the feature is merged.
Warning
This release is temporary and may be removed at any time without notice.
Nothing published for this version
This is a feature preview based on an open pull request. It is intended for testing artifacts and validating functionality before the feature is merge
This is a feature preview based on an open pull request. It is intended for testing artifacts and validating functionality before the feature is merged.
Warning
This release is temporary and may be removed at any time without notice.
This is a feature preview based on an open pull request. It is intended for testing artifacts and validating functionality before the feature is merge
This is a feature preview based on an open pull request. It is intended for testing artifacts and validating functionality before the feature is merged.
Warning
This release is temporary and may be removed at any time without notice.
This is a feature preview based on an open pull request. It is intended for testing artifacts and validating functionality before the feature is merge
This is a feature preview based on an open pull request. It is intended for testing artifacts and validating functionality before the feature is merged.
Warning
This release is temporary and may be removed at any time without notice.
This is a feature preview based on an open pull request. It is intended for testing artifacts and validating functionality before the feature is merge
This is a feature preview based on an open pull request. It is intended for testing artifacts and validating functionality before the feature is merged.
Warning
This release is temporary and may be removed at any time without notice.
This is a feature preview based on an open pull request. It is intended for testing artifacts and validating functionality before the feature is merge
This is a feature preview based on an open pull request. It is intended for testing artifacts and validating functionality before the feature is merged.
Warning
This release is temporary and may be removed at any time without notice.
This is a feature preview based on an open pull request. It is intended for testing artifacts and validating functionality before the feature is merge
This is a feature preview based on an open pull request. It is intended for testing artifacts and validating functionality before the feature is merged.
Warning
This release is temporary and may be removed at any time without notice.
This is a feature preview based on an open pull request. It is intended for testing artifacts and validating functionality before the feature is merge
This is a feature preview based on an open pull request. It is intended for testing artifacts and validating functionality before the feature is merged.
Warning
This release is temporary and may be removed at any time without notice.
This is a feature preview based on an open pull request. It is intended for testing artifacts and validating functionality before the feature is merge
This is a feature preview based on an open pull request. It is intended for testing artifacts and validating functionality before the feature is merged.
Warning
This release is temporary and may be removed at any time without notice.
This is a feature preview based on an open pull request. It is intended for testing artifacts and validating functionality before the feature is merge
This is a feature preview based on an open pull request. It is intended for testing artifacts and validating functionality before the feature is merged.
Warning
This release is temporary and may be removed at any time without notice.
This is a feature preview based on an open pull request. It is intended for testing artifacts and validating functionality before the feature is merge
This is a feature preview based on an open pull request. It is intended for testing artifacts and validating functionality before the feature is merged.
Warning
This release is temporary and may be removed at any time without notice.
This is a feature preview based on an open pull request. It is intended for testing artifacts and validating functionality before the feature is merge
This is a feature preview based on an open pull request. It is intended for testing artifacts and validating functionality before the feature is merged.
Warning
This release is temporary and may be removed at any time without notice.
This is a feature preview based on an open pull request. It is intended for testing artifacts and validating functionality before the feature is merge
This is a feature preview based on an open pull request. It is intended for testing artifacts and validating functionality before the feature is merged.
Warning
This release is temporary and may be removed at any time without notice.
This is a feature preview based on an open pull request. It is intended for testing artifacts and validating functionality before the feature is merge
This is a feature preview based on an open pull request. It is intended for testing artifacts and validating functionality before the feature is merged.
Warning
This release is temporary and may be removed at any time without notice.
Your coding agent can read these notes before it upgrades. Set up the MCP server →