NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
AllStak Flutter SDK for error tracking, request telemetry, breadcrumbs, sanitization, and mobile observability.
Last release 4 months ago
30 May 2026
Too new to tell
only 1 dated releases
Nearly every release is documented
notes for 1 of 1 stable releases
Nothing withdrawn
no release was ever pulled
4 months old
1 releases · first in 2026
One column per month.
Harden SDK reliability certification
Harden SDK reliability certification
allstak (was allstak_flutter). Update your
dependency to allstak: ^1.1.0 and imports to package:allstak/allstak.dart.
The wire SDK identity is unchanged: events still report sdkName: allstak-flutter
and requests still send User-Agent: allstak-flutter/<version>.flutter test no longer write the
production file-backed open-session marker. Production abnormal-session
recovery is unchanged; the change prevents parallel test runs from recovering
a marker left by another forced test and misreporting a normal session as
abnormal.AllStak.runApp()
and AllStak.init() (right after WidgetsFlutterBinding.ensureInitialized()),
so a host app gets iOS POSIX-signal + uncaught-exception and Android NDK/JVM
crash capture — plus the next-launch drain of any stashed crash — with no extra
call. Gated by the new AllStakConfig.autoInstallNativeHandlers (default on),
always skipped under web (kIsWeb) and the flutter test runtime, and a silent
no-op when the native side is unavailable. installNativeHandlers() stays as an
explicit escape hatch and is now idempotent (the previous-launch crash is drained
at most once).liballstak_crash.so) is now default-on in the
plugin android/build.gradle: the CMake build is wired in automatically when an
NDK is present, opt out with allstak.enableNdkCrashCapture=false, and it is
auto-skipped (still builds as a pure-Kotlin library) when no NDK is installed, so
adding the SDK never hard-fails a build.dart:io + Dio)AllStak.runApp() now installs a process-wide HttpOverrides.global so every
dart:io HttpClient is auto-instrumented as an outbound http-request (real
method/host/path/status/duration) with distributed-trace headers
(traceparent, x-allstak-*, baggage) injected — covering package:http's
IOClient, Dio's default adapter, Image.network, etc., with zero per-call
wiring. Requests to the SDK's own ingest host are skipped (no recursion); an
app's pre-existing HttpOverrides is preserved (delegated to) and restored on
close(). Gated by AllStakConfig.enableHttpOverrides (default on), skipped
under web and tests. allstak.httpClient() keeps working unchanged.AllStak.dioInterceptor(wrapperFactory: …)
/ allStakDioInterceptor(...) for apps that use a non-dart:io Dio adapter or
disabled the global overrides. Duck-typed so the SDK never depends on
package:dio. See lib/src/dio_interceptor.dart and lib/src/http_overrides.dart.AllStakConfig.captureLogs (default on) wires an AllStakLogBridge from
init. Attach a package:logging stream with one line —
AllStak.instance?.attachLogging(Logger.root.onRecord) — and records flow to
/ingest/v1/logs; SEVERE/SHOUT records and any record carrying an error
object are promoted to a captured exception, stamped with the active
trace/request ids. Duck-typed against package:logging so there is no SDK
dependency on it. Skipped under the flutter test runtime. See
lib/src/log_bridge.dart./ingest/v1/sessions/start; on graceful shutdown (or
an explicit close() / endSession()) it POSTs /ingest/v1/sessions/end with
the final status and accumulated duration. Sessions are never sampled so
crash-free rates stay accurate.SessionStatus vocabulary (ok / exited / errored / crashed / abnormal)
matches the backend /sessions/end contract; an unhandled/fatal exception marks
the session crashed, feeding crash-free-sessions / crash-free-users release
health on the server.AllStakConfig.enableAutoSessionTracking (default on); a
_SessionLifecycleObserver (WidgetsBindingObserver) drives end-on-detach.
AllStak.sessionId exposes the current session id, also stamped onto error /
log / http payloads for correlation. See lib/src/session.dart.lib/src/offline_queue.dart
(OfflineQueue, OfflineEntry, now exported from the package root)./sessions/start, /sessions/end) are intentionally never persisted so a
replayed stale session can't corrupt release-health math.AllStakConfig.enableOfflineQueue (default on).sendDefaultPiilib/sanitizer.dart) with free-text
VALUE scrubbing on top of the existing key-name redaction, providing comprehensive PII protection
data-scrubbing parity:
sendDefaultPii): Luhn-valid credit-card numbers
(13–19 digits, space/hyphen separators; Luhn-invalid digit runs such as order
ids / timestamps are preserved) and hyphenated US SSNs.sendDefaultPii=true (default false = ): email
addresses and validated-octet IPv4 literals.sessionId) and the explicit
setUser subtree (intentional identity; not stripped by sendDefaultPii,
following privacy-by-default best practices). Regexes compile once; strings >16 KB are skipped; per-value
scrubbing is fail-open so it can never drop an event.ScrubOptions + AllStakConfig.sendDefaultPii (default false) wire
through the existing scrub() call in _send.ios/AllStakPlugin.swift): async-signal-safe POSIX sigaction
handlers for SIGSEGV/SIGABRT/SIGBUS/SIGILL/SIGFPE/SIGTRAP — the force-unwrap
traps, bad-pointer accesses, and Mach-derived faults that never raise an
NSException. Mirrors the sibling allstak-apple SignalCrashHandler:
pre-allocated buffers + a pre-opened fd, single write(), restore the
previous disposition, re-raise. (Mach exception ports remain a future bonus;
signal handlers are the priority and match the apple SDK.)android/src/main/cpp/allstak_crash.c + CMakeLists.txt): an
NDK sigaction handler for the same signals, capturing NDK/native signal
crashes the JVM Thread.setDefaultUncaughtExceptionHandler misses. Stack
unwound via _Unwind_Backtrace; JNI install bridge passes the crash-file
path. The handler makes NO JNI/heap calls — only async-signal-safe writes.ASKC1 text record to a pre-opened
fd under the app-support / files dir. On the next launch (normal context)
the record is read, parsed (lib/src/native_crash.dart), and shipped through
the existing _send transport as /ingest/v1/errors marked
native.crash=true. Stack frames ship as raw 0x… return addresses for
backend symbolication against uploaded debug images.drainPendingSignalCrash MethodChannel method (iOS + Android) feeding the
existing next-launch drain in installNativeHandlers().AllStakConfig.enableNativeCrashCapture (default on).
Degrades gracefully: if the native lib is unavailable (web, tests, or an app
that did not opt into the Android NDK build via
allstak.enableNdkCrashCapture=true), signal capture is a silent no-op and
the SDK keeps working — adding the SDK never forces an NDK toolchain on apps.test/allstak_flutter_test.dart — session lifecycle (start/end POST contract,
status transitions, sessionId stamping, lifecycle-observer end-on-detach),
release auto-detection ordering, and offline-queue integration via injected
seams.test/offline_queue_test.dart — enqueue/drain round-trip, bounded cap + age
eviction, scrub-before-persist invariant, no-store no-op, and corrupt-line
tolerance.test/sanitizer_test.dart — value-pattern scrubbing (Luhn-valid CC vs.
Luhn-invalid passthrough, hyphenated SSN, email + IPv4 gated by
sendDefaultPii, verbatim-identifier skip list, setUser subtree preserved)
on top of the existing key-name denylist coverage.test/native_crash_test.dart — record parsing (well-formed iOS/Android,
unknown-key tolerance, frame cap, corrupt/empty rejection, signal-name
mapping), payload shaping (native.crash=true wire contract), and the
next-launch drain handoff via a mocked native channel (install gating, drain
sequence, opt-out, corrupt-drop).flutter pub get + flutter analyze (no issues) + flutter test
(all green) all pass; dart format applied.swiftc -parse of the full plugin against the iphoneos SDK, and
swiftc -typecheck of the extracted signal-handler logic against Darwin —
both clean (validates the sigaction/backtrace/si_addr API usage).clang -fsyntax-only -std=c11 -Wall -Wextra (with JNI +
android/log.h/unwind.h stubs, and against the host's real signal.h) —
clean. A real NDK/CMake/Gradle build was NOT run (no NDK installed here).Your coding agent can read these notes before it upgrades. Set up the MCP server →