NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
PyPI · #4675 most downloaded on PyPI
Python client for Taskcluster
Last release 2 days ago
21 Sep 2026
Ships on a steady schedule
a new release about every 2 weeks
Nearly every release is documented
notes for 60 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
12 years old
491 releases · first in 2014
Removed posix generic-worker binaries due to a security vulnerability when using the interactive feature.
▶ [patch] #6420 Fixes generic worker issue where artifacts were no longer being uploaded.
Removed posix generic-worker binaries due to a security vulnerability when using the interactive feature.
Removed posix generic-worker binaries due to a security vulnerability when using the interactive feature.
▶ [patch] #6405 Expire artifacts handles the case where the artifact is not found during deletion. GCS behaves differently to S3 here, as it will throw an error if the artifact is not found, where S3 would always return 204.
▶ [minor] #5967
This change integrates the d2g tool into Generic Worker so that it can accept a valid, Docker Worker payload.
▶ [patch] #6417 Generic Worker: Interactive sessions suffered from a race condition that was introduced in Generic Worker 54.2.0. This has been fixed.
Removed posix generic-worker binaries due to a security vulnerability when using the interactive feature.
One column per quarter.
Removed posix generic-worker binaries due to a security vulnerability when using the interactive feature.
▶ [minor] #6405
Expire artifacts supports both bulk deletion and single deletion. This can be configured for the deployment using AWS_USE_BULK_DELETE environment variable (false by default). This is needed because not all S3 compatible storages support bulk delete, specifically GCS.
EXPIRE_ARTIFACTS_BATCH_SIZE can be used to control how many records to process at once, i.e. how many parallel delete requests would be sent to storage service (100 by default).
▶ [patch] #6395
Fixed local development environment where artifacts could not be loaded in the UI. This was caused by not using pinned minio/* images.
▶ [patch] #6395 Local development environment now supports live log.
Removed posix generic-worker binaries due to a security vulnerability when using the interactive feature.
▶ [patch] Upgrades to go1.20.6 which is a security release.
▶ [patch] Upgrades to go1.20.6 which is a security release.
go1.20.6 (released 2023-07-11) includes a security fix to the net/http package, as well as bug fixes to the compiler, cgo, the cover tool, the go command, the runtime, and the crypto/ecdsa, go/build, go/printer, net/mail, and text/template packages. See the Go 1.20.6 milestone on our issue tracker for details.
▶ [patch] Hooks page improvements: extra schedule and exchanges displayed as Badge with a proper tooltip.
Removed posix generic-worker binaries due to a security vulnerability when using the interactive feature.
Removed posix generic-worker binaries due to a security vulnerability when using the interactive feature.
▶ [patch]
This change updates d2g to return the resulting generic worker payload with a 125 exit status code in the retry array to fix an intermittent podman issue while pulling the docker image.
▶ [patch] Hooks page now displays table instead of tree view. Table view includes extra information that might be helpful to spot issues with hooks. Most recent task with state is displayed if available, or error if last fire was not successful.
▶ [patch] UI: Refactors how validation schemas are loaded, to ensure they are only fetched and added once to prevent duplicate schema exceptions.
▶ Additional change not described here: #6380.
Removed posix generic-worker binaries due to a security vulnerability when using the interactive feature.
Removed posix generic-worker binaries due to a security vulnerability when using the interactive feature.
▶ [patch] #6330 Fixes UI errors on pages that were loading metaschema twice.
▶ [patch] Upgrades some rust crates and bumps rust version from 1.65.0 to 1.70.0.
Removed posix generic-worker binaries due to a security vulnerability when using the interactive feature.
Removed posix generic-worker binaries due to a security vulnerability when using the interactive feature.
▶ [patch] Upgrades to go1.20.5 from go1.19.10.
Removed posix generic-worker binaries due to a security vulnerability when using the interactive feature.
Removed posix generic-worker binaries due to a security vulnerability when using the interactive feature.
▶ [MAJOR] Remove python 3.7 support as it's hit the EoL date, 2023-06-27.
More info on the python 3.7 release schedule can be found here.
▶ [minor] #6248 Hooks service returns task state with lastFires call. This state is also showed in UI, along with the "Fire Status", which only indicate if task was succesfully created, but does not show if the task completed succesfully or not.
Removed posix generic-worker binaries due to a security vulnerability when using the interactive feature.
Removed posix generic-worker binaries due to a security vulnerability when using the interactive feature.
▶ [patch] Upgrade Node.js version to 18.16.1 (security release).
▶ [minor]
Migrate d2g to tools/d2g.
▶ [patch] Stop running docker-worker tests in the CI.
The tests will remain in the monorepo because we'll look into using them with generic worker once d2g is integrated.
▶ [patch] Upgrade Node.js version to 18.16.1 (security release).
More information can be found here.
▶ [minor] #6142 Worker manager stops instances that are not active in queue after short timeout. This is to prevent instances from running when worker fails to start claiming work or dies and does not reclaims task.
Removed posix generic-worker binaries due to a security vulnerability when using the interactive feature.
Removed posix generic-worker binaries due to a security vulnerability when using the interactive feature.
▶ [minor] #5994
Generic Worker: Adds task.payload.feature.loopbackVideo for loopback video device support on Linux.
The v4l2loopback kernel module must be installed on the host system for this feature to work, although it does not need to be loaded. Generic Worker loads the module with modprobe and generates the virtual video device with a v4l2loopback command. Under the multiuser engine, it also manages file ownership of the device with chown to ensure that only tasks with suitable scopes have read/write access to the virtual device.
For tasks that enable the feature, the virtual video device location will be provided to the task commands via the environment variable TASKCLUSTER_VIDEO_DEVICE. The value of the environment variable depends on deployment configuration, and therefore tasks should not assume a fixed value. Its value will however take the form /dev/video<DEVICE_NUMBER> where <DEVICE_NUMBER> is an integer between 0 and 255. The Generic Worker config setting loopbackVideoDeviceNumber may be used to change the device number. Future releases of Generic Worker may provide the capability of having more than one virtual video device; currently only one virtual video device is supported.
▶ [patch] #6326
Running taskcluster group list without a task group ID now outputs error message:
Error: list expects argument <taskGroupId>
Previously, it incorrectly outputted:
Error: list expects argument <taskId>
Removed posix generic-worker binaries due to a security vulnerability when using the interactive feature.
> go1.19.10 (released 2023-06-06) includes four security fixes to the cmd/go and runtime packages, as well as bug fixes to the compiler, the go comman…
▶ [minor] This essentially reverts the change in #6279.
We learned from RelOps that the simple engine is useful for running generic worker inside a VM and inside of docker containers.
▶ [patch] Upgrade to go 1.19.10.
go1.19.10 (released 2023-06-06) includes four security fixes to the cmd/go and runtime packages, as well as bug fixes to the compiler, the go command, and the runtime.
▶ [minor] #6247 Revert worker-manager from quarantining workers on removal that was introduced in PR 6267.
▶ [MAJOR] Rework the interactive feature for generic worker allowing to run interactive commands in it
▶ [patch]
Introduced github.renderTaskclusterYml endpoint to render provided .taskcluster.yml file for various events.
This might be used for debug purposes or to validate the .taskcluster.yml file
and make sure that resulting tasks and scopes produce expected values.
▶ [patch] Enables CORS for API for local docker-compose development.
▶ Additional change not described here: #6280.
Removed posix generic-worker binaries due to a security vulnerability when using the interactive feature.
▶ [MAJOR] #6277 Generic Worker Simple engine is no longer _released_. It can still be built from source, but since it was never intended to be used as
▶ [MAJOR] #6277 Generic Worker Simple engine is no longer released. It can still be built from source, but since it was never intended to be used as a production engine, and was only intended to support development (e.g. for running unit tests or running in a simple dev deployment) the simple engine binaries are no longer released.
▶ [patch] #5006
Generic Worker on macOS now dumps the output of the last command when it is not able to determine the logged in console user. This doesn't solve issue 5006 but it may provide additional troubleshooting information.
▶ [patch] #6278
Fix UI issue showing "Response code 404" for missing public/actions.json artifact.
▶ [patch] #5807 Fixes escape sequence parsing in logs that are attached to github check runs.
▶ [minor] #6247 Worker manager now also quarantines worker on removeWorker call. This is used to prevent some race conditions when worker is still pol
▶ [minor] #6247
Worker manager now also quarantines worker on removeWorker call. This is used to prevent some race conditions when worker is still polling for new work and is removed/shutdown at the same time.
▶ [patch] The new (unused in production) indexed artifacts feature of Generic Worker was broken in release 51.0.0. This has (hopefully) been fixed.
▶ [patch]
New .taskcuster.yml linter added in UI to help validate github integration.
▶ [patch] Taskcluster YAML validator can load file from URL.
▶ [minor] #6245 Generic Worker payload now supports declaratively mounting indexed artifacts into the task directory. For example:
▶ [minor] #6245 Generic Worker payload now supports declaratively mounting indexed artifacts into the task directory. For example:
payload:
mounts:
content:
namespace: my.index.namespace
artifact: public/image.jpg
file: pics/image.jpg
▶ [MAJOR]
The jsonschema2go tool now considers SHA and KVM to be words that should be
capitalised when generating go type names.
As a consequence, the taskcluster go client is backwardly incomaptible with the
previous release, since the tcgithub.Build struct member Sha has been
renamed to SHA.
▶ [patch]
node-fetch dependency removed in favour of got.
▶ [patch] #5621 Github service patch incorrect query for fetching older builds
▶ [patch] #5621 Github service patch incorrect query for fetching older builds
▶ [patch] #5621 Several Github service improvements:
▶ [patch] #5621 Several Github service improvements:
repo:github.com/org/repo:* role(s) to make sure that given repository has correct permissions to seal and cancel task groupsgithub.cancelBuilds({ organization, repository, sha?, pullNumber? }) to cancel existing running builds▶ [patch] Aligned platforms of released binaries:
▶ [patch] Aligned platforms of released binaries:
Previously there were inconsistencies across tools (e.g. taskcluster cli was released for different platforms than livelog).
▶ [patch] #5621
Extend static/taskcluster/github client with two scopes that are necessary to seal and cancel previously created task groups: queue:cancel-task-group:taskcluster-github and queue:seal-task-group:taskcluster-github.
When github repository is using a different schedulerId than taskcluster-github, then it might be necessary to update corresponding repo:github.com/ roles with correct scopes.
▶ [patch] Adds interactive changelog viewer to the docs section.
▶ [patch] Bump caniuse-lite version with npx update-browserslist-db@latest due to outdated warning.
▶ [patch]
Bump caniuse-lite version with npx update-browserslist-db@latest due to outdated warning.
▶ [minor] #5621
Github service now automatically cancels older task groups to avoid redundancy when there are multiple builds for the same commit sha or pull request. This behavior can be disabled by setting autoCancelPreviousChecks to false in the .taskcluster.yml file.
▶ [MAJOR] #6213 The Generic Worker Docker Engine was an experimental engine that was never used in production. It was an intended starting point for a
▶ [MAJOR] #6213 The Generic Worker Docker Engine was an experimental engine that was never used in production. It was an intended starting point for adding support for docker-worker style payloads. However, a new approach to running Docker Worker payloads in the multiuser engine was agreed, and is under active development. This will provide the same functionality that the Docker Engine was intended to provide. Therefore the old, incomplete, and unused docker engine has been removed.
▶ [patch] #6216 Build freebsd versions of livelog, taskcluster-proxy and start-worker to complement the existing generic-worker builds.
▶ [patch] #6208
Return a malformed payload error if payload.features.interactive is enabled in the task definition, while the enableInteractive worker config is false.
▶ [patch] jsonschema2go cli now has options for generating nested structs, and including default values as struct tags.
▶ [patch] Upgrade Node.js version to 18.16.0 and go version to 1.19.9.
▶ [patch] Upgrade Node.js version to 18.16.0 and go version to 1.19.9.
▶ [minor] #6169 Adds interactive shell support to generic-worker.
The worker configuration variable enableInteractive needs to be set to true to allow the interactive shell feature to be enabled. enableInteractive is disabled by default.
Once the worker configuration variable is set, the interactive feature can be enabled on a per-task basis.
To enable, set task.payload.features.interactive to true. And toggle on Interactive in the Create Task view of the UI.
▶ [patch] #6186 Worker-manager refreshes worker from database before calling removeWorker on terminateAfter time exceeded to prevent from stopping wor
▶ [patch] #6186 Worker-manager refreshes worker from database before calling removeWorker on terminateAfter time exceeded to prevent from stopping workers that were already registered and running since worker scanner has started.
▶ [patch] #6185 Fixed quarantine worker 'reason' field schema to be optional.
▶ [patch] #6185 Fixed quarantine worker 'reason' field schema to be optional.
▶ [patch] #6058
Generic Worker no longer modifies the Access Control Lists of the Interactive Desktop and the associated Windows Station unless additional OS groups have been specified in the task payload osGroups property. Previously Generic Worker would modify the ACLs of these objects even if the access token it was using for launching task command processes already had suitable permissions. This patch is a workaround for a more general issue, which is that the ACL modifications seem not to be appropriate in all cases when a new access token is needed. See https://bugzilla.mozilla.org/show_bug.cgi?id=1815711.
There is a likely to be a follow up fix for the ACL modifications that occur when a new access token is required, once it is understood why the current modifications are not always sufficient.
▶ [patch] Generic worker feature task.Payload.OnExitStatus.PurgeCaches now only purges caches related to the task, instead of all caches on the worker
▶ [patch]
Generic worker feature task.Payload.OnExitStatus.PurgeCaches now only purges caches related to the task, instead of all caches on the worker.
▶ [patch] #5773 Fix UI bug when user profile was missing and causing whole page to crash.
▶ [patch] bug 1590886
Github status handler listens to both taskPending and taskRunning events.
▶ [minor] bug 1826417 Changes the way expire-artifacts works. It uses a separate function to fetch all expired artifacts and then uses bulk delete to
▶ [minor] bug 1826417
Changes the way expire-artifacts works. It uses a separate function to fetch all expired artifacts and then uses bulk delete to remove them from S3 and the database.
▶ [patch] Builds and tests generic worker (multiuser) on macOS Ventura 13 on new, arm64 machines.
▶ [patch] Builds and tests generic worker (multiuser) on macOS Ventura 13 on new, arm64 machines.
▶ [MAJOR] Remove python 3.6 support as it's past its end-of-life date.
Add python 3.10 and python 3.11 support.
▶ [minor] #6147
Adds task.payload.onExitStatus.purgeCaches feature to generic worker to bring to parity with an existing docker worker feature.
purgeCaches is an array of exit status code integers that the user wants all caches associated with the task to be purged.
▶ [minor] #4343 Workers can be quarantined with an optional comment. queue.quarantineWorker accepts a quarantineInfo string. Quarantine details also i
▶ [minor] #4343
Workers can be quarantined with an optional comment. queue.quarantineWorker accepts a quarantineInfo string.
Quarantine details also include timestamp and clientId of the user who quarantined the worker.
This information can be fetched with worker-manager.getWorker.
quarantineDetails would be a list of all the quarantine requests made for the worker.
UI shows this history and allows to specify a comment for quarantine request.
▶ [patch]
Enables missing collaborators_quiet policy to the schema validation of .taskcluster.yml.
▶ [patch] bug 1824937 docker-worker no longer waits indefinitely when downloading an image artifact, and will retry if the connection is idle for 60s
▶ [patch] #6130 This patch ensures that the worker pool ID passed to generic worker contains a slash (/) and will error out describing the issue as op
▶ [patch] #6130
This patch ensures that the worker pool ID passed to generic worker contains a slash (/) and will error out describing the issue as opposed to panicing when an index out of range error.
▶ [patch] bug 1590886 Fix Github statuses: skip unnecessary API updates when task starts running.
▶ [minor] #3652 It is now possible to cancel a sealed task group by calling the queue.cancelTaskGroup API method. This will cancel all scheduled/pendi
▶ [minor] #3652
It is now possible to cancel a sealed task group by calling the queue.cancelTaskGroup API method.
This will cancel all scheduled/pending/running tasks within given group.
▶ [patch] bug 1590886 Github service update statuses back to pending when task is retried.
▶ [minor] #5993
Adds the liveLog and backingLog feature flags to the generic worker payload so they can be disabled for a task. These are enabled by default.
Adds the logs property to the generic worker payload allowing customization of the live and backing log artifact names.
▶ [minor] jsonschema2go: jsonschema default values are encoded into struct tags of generated go types for use with github.com/mcuadros/go-defaults.
▶ [minor] jsonschema2go: jsonschema default values are encoded into struct tags of generated go types for use with github.com/mcuadros/go-defaults.
In order to utilise this new features, callers should call defaults.SetDefaults(&val) before calling json.Unmarshal(data, &val).
▶ [patch] Go upgrade from 1.19.5 to 1.19.7. Also upgraded golangci-lint from 1.50.1 to 1.51.2.
Node.js upgrade from 18.14.1 to 18.15.0.
▶ [patch] Dashboard displays worker manager provisioning stats separately. Values are being automatically reloaded every 30 seconds.
▶ [patch] #6109
The worker-manager methods createWorker, listWorkersForWorkerGroup,
updateWorker, and worker had an extraneous colon (:) character in their
URL path. This colon has been removed. The old paths (containing the colon)
will continue to work, but the new paths are preferred.
▶ [patch] #6067 Worker-manager now considers stoppingCapacity when estimating the required number of workers to start, preventing failed to start work
▶ [patch] #6067
Worker-manager now considers stoppingCapacity when estimating the required number of workers to start, preventing failed to start workers from growing beyond maxCapacity and slowing down the scanner loop.
▶ [MAJOR] #6059 It is now possible to seal a task group which is an operation to prevent additional tasks from being added.
New APIs:
queue.sealTaskGroup to seal task group and prevent addition of new tasks to it. This operation is irreversible.queue.getTaskGroup to return task group information without tasks (use queue.listTaskGroup to return information with tasks)exchange/taskcluster-queue/v1/task-group-sealed reports when a task group is sealed.Updated APIs:
queue.createTask returns HTTP 409 error if task group was sealed.queue.listTaskGroup returns extra fields schedulerId, expires, sealed.exchange/taskcluster-queue/v1/task-group-resolved publishes extra fields schedulerId, expires, sealed.UI updates:
▶ Additional change not described here: #6052.
▶ [patch] Add error handling for docker image release process.
▶ [patch] Add error handling for docker image release process.
▶ [minor] This upgrades Node.js to the latest LTS version available, v18.13.0. Previous version was v16.19.0 and it was scheduled to hit EoL later thi
▶ [minor] This upgrades Node.js to the latest LTS version available, v18.13.0. Previous version was v16.19.0 and it was scheduled to hit EoL later this year.
View the release schedule here.
▶ [patch] Docker worker json schema payload has been tweaked for cleaner go code generation. No functional impact anticipated.
▶ [patch]
Minor and patch version bumps via Dependabot using pmac:
pmac add 6040 6039 6038 6036 6035 6034 6032 6030 6029 6028 6027 6026 6025 6024 6023
▶ [patch] #6014 Bug fix: docker worker no longer accepts non-strings for env var values in task payloads.
▶ [patch] #6021 Docker Worker payload has been tightened to enforce that Docker Worker caches are string to string mappings, rather than string to anything mappings.
▶ [patch] Upgrade git to latest version to address the security vulnerabilities affecting versions 2.39 and older.
▶ [patch] Go update from 1.19.4 to 1.19.5.
▶ [patch] #5266
This patch fetches https://go.dev/dl/?mode=json in order to automatically update the sha256 values of each of the go binaries used in the workers/generic-worker/gw-decision-task/tasks.yml file.
▶ [patch]
Upgrade git to latest version to address the security vulnerabilities affecting versions 2.39 and older.
▶ [patch] Small fix to dockerignore and release process.
▶ [patch] Small fix to dockerignore and release process.
▶ [patch] Add preinstall hook to install clients/client dependency to avoid inconsistent installs. Removes "heroku-(pre|post)build" commands.
▶ [patch] Add preinstall hook to install clients/client dependency to avoid inconsistent installs. Removes "heroku-(pre|post)build" commands.
▶ [patch] Adds caching for static UI assets. UI web server will return 404 for /api/* and /graphql endpoints.
▶ [patch] #5941 Azure certificates updates.
▶ [patch]
Upgrade some major version dependency bumps using pmac tool:
pmac add 5748 5811 5902 5903
▶ [patch]
Upgrades to latest lts/gallium Node version, v16.19.0
▶ [MAJOR] #5518
Assumes different role for github pre-release event: assume:repo:github.com/<owner>/<repo>:release:<action>, where action is one of the release actions
▶ [patch] Reduce monoimage size by excluding unnecessary files.
▶ [patch] #4950
Remove auto-generated actions.json which is not properly configured and is not used in this repo.
▶ [patch] #5938 Upgrade json-e to 4.5.0.
▶ [patch] This patch updates the GitHub Dependabot auto-merge workflow to use the recommended solution for approving/auto-merging minor and patch Dependabot PRs.
▶ [patch] #5844 Filter debug logging information for failed registerWorker calls.
▶ [patch] #5844 Filter debug logging information for failed registerWorker calls.
▶ [patch] #5890 Fix provisioners endpoint returning non-unique workers for the queue view.
▶ [patch] #5851 Improve error reporting for github api calls.
▶ [patch]
Minor and patch version bumps via Dependabot using pmac:
pmac add 5887 5881 5880 5879 5878 5876 5874 5873 5872
▶ [patch]
The Rust client now correctly base64-encodes ext hawk values with the STANDARD alphabet instead of URL_SAFE. This may fix intermittent generation of invalid temporary credentials.
▶ [patch]
This patch makes it so the taskcluster shell client (cli) is built with goreleaser.
goreleaser also will automatically keep our homebrew-tap formula up-to-date during the release process.
GitHub releases will now also contain zipped Windows executables of this cli supporting both amd64 and arm64. arm64 binaries for linux have been added as well.
The darwin and linux binaries are now tarballs.
▶ [patch] This patch cleans up some of the python client and client test code of deprecation warnings.
▶ [patch] #5851 Fix incorrect status reported by github service for unknown branches.
▶ [patch] #5844 Log extra debug information for failed worker registration attempts.
▶ [patch] Patch python client tests to allow lint script.
▶ [patch] Update 46.0.0 release notes that incorrectly linked issue #2791 instead of #5791.
▶ [patch]
Go update from 1.19.3 to 1.19.4. Also updates the git version for generic worker decision tasks from git2.37.1 to git2.39.0.
▶ [patch] This patch cleans up some of the python client and client test code of deprecation warnings.
▶ [patch] Use updated gw-ci-macos-10-14 worker pool.
▶ [patch] #5836 Add worker runner for windows/386 to release artifacts (previously broken).
▶ [minor] #4624 All language clients now use the getUrl download method to download objects, including verifying hashes provided when the objects were uploaded. However, note that 's3' artifacts are still not verified -- the deployment must use 'object' artifacts to benefit from hash verification.
▶ [patch] This patch switches running CI tasks on generic-worker-windows2012r2 worker pool to the new, windows 2022 worker pool.
…least one is present. This has the effect of a breaking change in the Go client types, leading to this change's designation as major.
▶ [patch]
Upgrade taskcluster-taskgraph version to v4.0.0 as well as upgrade other python packages.
▶ [minor] #5804 Adds pagination to the hooks last fires api call.
This prevents loading all last fires for the hooks that have thousands of records, which results in 500 errors.
Changes the behaviour of the existing get_last_fires function by using a different sort column - creation time instead of task_id.
▶ [patch] #5804 Fix empty error message for hooks last fire.
▶ [patch] #5804 Fix graphql endpoint for hook without last fires.
▶ [MAJOR] #2791 Hashes for object upload and download are now more precisely defined: uploaders should supply all acceptable hash algorithms, and downloaders should verify all recognized algorihtms and ensure that at least one is present. This has the effect of a breaking change in the Go client types, leading to this change's designation as major.
▶ [patch] #4624
The startDownload method now accepts getUrl as a download method.
▶ [patch] This patch switches running CI tasks on generic-worker-ubuntu-18-04 worker pool to the new, 22-04 worker pool.
▶ [patch] Minor and patch version bumps via Dependabot using pmac:
▶ [patch]
Minor and patch version bumps via Dependabot using pmac:
pmac add 5822 5821 5819 5818 5817 5816 5815 5814 5813 5790 5789
▶ [patch] bug 1803745
Docker-worker and generic-worker now skip gzipping artifacts with a .deb extension.
Since this is technically a breaking change, a major version bump is necessary. However, as far as we know, nothing needed this feature.
▶ [minor] #1955 Adds timing statistics to the Task Group page: durations for each task, totals, median and shows distribution graph.
▶ [minor] #5379 MUI tables are now more responsive to smaller width screens. The worker manager page, no longer has the emails of the task owner displayed.
▶ [patch] Go upgrade from 1.18.5 to 1.19.3. Also upgrades golangci-lint version to 1.50.1 for go1.19 support.
▶ [minor] #4605
Generic-worker can now create object artifacts instead of s3 artifacts if the
createObjectArtifacts worker configuration parameter is true.
▶ [patch] #5634 The livelog docker image used by docker-worker now is not based on busybox, but contains only the livelog binary, /etc/ssl/certs/ca-certificates.crt and an empty /tmp directory. This effectively reverses the change from #3866.
▶ [MAJOR] #5799
Docker Worker no longer supports the disableSeccomp capability (added in Docker Worker 44.22.0, but turned out to be unneeded).
Since this is technically a breaking change, a major version bump is necessary. However, as far as we know, nothing needed this feature.
▶ [minor] #4624
The object service now supports an additional download method, getUrl, which handles gzipped content and requires that hashes be validated.
This method is not yet supported by the client libraries (but such support will be added soon).
▶ [patch] #5779
Fix View logs in Taskcluster link in GitHub Checks UI to default to a run ID of 0 to prevent it from being undefined and getting a 400 Bad Response while accessing this link.
▶ [patch] Updated livelog link in GitHub checks UI to points to a streaming livelog. Previous link would only render the logs once the task was complete.
▶ [patch] Upgrades some rust crates and bumps rust version from 1.60.0 to 1.65.0.
▶ [patch] Upgrades to latest Node version, v16.18.1.
▶ [patch] Upgrades to latest Node version, v16.18.1.
▶ [patch] Minor and patch version bumps via Dependabot using pmac:
▶ [patch]
Minor and patch version bumps via Dependabot using pmac:
pmac add 5746 5747 5749 5750 5751
▶ [patch] Upgrades taskgraph from v1.2.0 to v3.4.0.
▶ [patch] #5737 Fix React props handling for TaskGroup page in production mode.
▶ [patch] #5737 Fix React props handling for TaskGroup page in production mode.
▶ [patch] #5728 Adds auto release lock functionality to queued locks to prevent some GitHub handlers to run forever and keep the queue locked.
▶ [patch] Upgrades @xmldom/xmldom to 0.7.6 to fix critical security vulnerability.
▶ [minor] #5728 Changed the way that github events are being handled. There was a problem with treating those callbacks in async manner which resulted in total messages being processed to be limited by consumer's "prefetch" count (5 by default). And resulted in messages being piled up. Introduces extra monitoring information with the numbers of active handlers count and total messages processed.
▶ [patch]
Upgrades @xmldom/xmldom to 0.7.6 to fix critical security vulnerability.
Also utilized the yarn upgrade-interactive --latest command for the following package upgrades:
@azure/ms-rest-js@2.6.2, apollo-server-core@3.10.3, apollo-server-express@3.10.3, aws-sdk@2.1238.0, express@4.18.2, graphql-scalars@1.20.0, jwks-r sa@2.1.5, marked@4.1.1, nodemailer@6.8.0, passport-auth0@1.4.3, pg@8.8.0, sanitize-html@2.7.2, c8@7.12.0, commander@9.4.1, dockerode@3.3.4, nock@13.2.9
▶ [patch] Upgrades to latest Node version, v16.18.0.
▶ [patch] #5726 The github service no longer fetches live logs from workers, but instead fetches backing logs from artifact storage. This reduces exceptions due to certificate expiries of live logs from stateless dns server.
▶ [patch] Reverts commit e2015f35330a4b059d1bccf55c871df2af77bfbb.
▶ [patch] Reverts commit e2015f35330a4b059d1bccf55c871df2af77bfbb.
▶ [patch] Upgrades to latest Node version, v16.17.1, which is a security release.
▶ [minor]
Add a docker-worker capability disableSeccomp to disable the seccomp
system call filter.
It allows significant information leakage, and its use should not be
considered secure. This is required to run rr inside a container, as
described here: https://github.com/mozilla/rr/wiki/Docker
▶ [patch] Adjust GCP CloudBuild config to cancel other ongoing jobs, so that the latest job is the only one that runs and no race conditions will occur with deploying to dev.
▶ [patch]
Upgrade many deps with the following command:
pmac add 5692 5691 5690 5689 5688 5687
▶ [patch] Upgrades to latest Node version, v16.17.1, which is a security release.
▶ [minor] Added basic dashboard stats: Worker pools, provisioners, hooks, clients counts.
▶ [minor] #4534 Add completions for other shells
▶ [minor] #4534 Add completions for other shells
▶ [patch] #5666 The generic-worker no longer panics if it gets no HTTP responses from Queue for over 15 minutes.
▶ [minor] Refactored github status checks handler to do handle task status transitions in single place.
Previous implementation relied on two handlers: taskDefined and statusChanged. For some tasks both events happened at the same time, which led to a race condition and multiple check_runs being created. To prevent concurrent handlers overwriting newer updates, simple time-based check was added to prevent this.
▶ [patch] #5663 This patch upgrades to the new, v2 Docker Hub APIs. v1 APIs were deprecated as of September 5, 2022 - see here for more info.
No changes
No changes
▶ [patch] #5653 Fix a bug with github status checks not being updated.
▶ [patch] #5653 Fix a bug with github status checks not being updated.
In 44.19.1 release github service started tracking additional task state changes, and this resulted in a race condition between "taskDefined" and "status" handlers where both of them would create new check run at the same time. Wrong check run would later get all status updates, while Github UI will be showing a different check run which didn't receive all the updates.
▶ [patch] Upgrade node to the latest LTS release, v16.17.0
▶ [patch] #5041
Add support for private docker registry by adding imagePullSecrets config value.
▶ [minor] #5295 When hovering over a task in a group task, the background color changes for the whole row, now. As opposed to a portion of the row.
▶ [patch] Building and publishing generic worker docker image
▶ [patch] #5217
This patch gets a tail of the last 250 lines of the live.log file and provides it in the GitHub checks view without having to visit the Taskcluster UI.
▶ [patch] Fix broken devel image build
▶ [patch] Fix broken devel image build
(breaking change) default ingress service was renamed to taskcluster and now binds to port 80 instead of 8080
▶ [patch] #5577 Adds linting functionality in the Create Task page.
Validates create task and its payload based on the selected worker type.
▶ [patch] Update go version from 1.18.4 to 1.18.5 for building generic-worker, livelog, taskcluster-proxy, start-worker, and the taskcluster cli. Update golangci-lint from 1.46.2 to 1.47.3 for linting go code.
▶ [patch] #5555 This patch fixes an issue with filtering workers based on quarantined status. The issue only occurs with static workers that are quarantined. When the filter was active, those static, quarantined workers would not be displayed in the list. This issue was first brought up in v44.17.0.
▶ [minor] Docker compose changes and improvements:
generic-worker runs with local docker compose and is able to execute taskstaskcluster and now binds to port 80 instead of 8080/etc/hosts is necessary in order to make HAWK authentication work properly across whole UINew tutorial page is added docs/tutorial/local-dev describing how to launch Taskcluster locally and run a simple task.
▶ [patch] Auto-reload services in docker-compose.dev.yml when source changes. This will allow to develop services without restarting manually docker compose.
▶ [patch] #5602 Introduced docker compose profiles to allow running background tasks and cron jobs.
▶ [patch]
Added scripts to package.json to more easily use the docker compose commands.
New yarn commands: start, stop, dev:start, dev:stop, prod:start, and prod:stop.
▶ [patch] Go update from 1.18.3 to 1.18.4. Also updates the git version for generic worker decision tasks from git2.24.0.2 to git2.37.1.
▶ [patch]
Go update from 1.18.3 to 1.18.4. Also updates the git version for generic worker decision tasks from git2.24.0.2 to git2.37.1.
▶ [patch] bug 1633440 Spread cron task times that started at 00:00 to minimize CPU spikes and DB loads.
▶ [patch]
Set the key field on the login window to a password field instead of a text one
▶ [patch] Fix docker compose sometimes not starting the ingress container
▶ [patch] #5553
This change adds continuous deployment support to the cloudbuild.yaml file so that each change to main results in a new deployment to https://dev.alpha.taskcluster-dev.net/.
▶ [patch] #5554
This patch splits the docker compose file into separate dev and prod configuration files. For prod-like deployments, where you want to use the latest taskcluster/taskcluster docker image, use the command docker compose -f docker-compose.yml -f docker-compose.prod.yml up -d. For development deployments, where local source code mounts as volumes for testing/debugging purposes, use the command docker compose -f docker-compose.yml -f docker-compose.dev.yml up -d.
This change also switches docker-compose (v1) references over to docker compose (v2). See here for more details.
▶ [patch] Upgrade node to the latest LTS release, v16.16.0. This is a security release. More info can be found here.
▶ [patch] Remove unused config value auditLog
▶ [patch]
This patch addresses the following vuln in passport https://security.snyk.io/vuln/SNYK-JS-PASSPORT-2840631. This also upgrades express to the latest stable release.
▶ [patch] #5557 This patch upgrades to Debian 10 docker images, as Debian 9 hit EOL.
▶ [patch] Upgrade node to the latest LTS release, v16.16.0. This is a security release. More info can be found here.
▶ [patch] Remove node-fetch dependency from ui/ as it was only used in abandoned queryServer.js script to cache possible graphql types.
▶ [patch] #5391 Skip github checks if github build is unkown. This happens in periodic and manual hooks that are doing some periodic operations on github repo. Those operations are not initiated by github, so there is no new build/check suite created for those events.
▶ [minor] #5456 This change adds more DB functions to allow for filtering in the DB based on worker state and quarantined status for the workers page.
▶ [minor] #5456 This change adds more DB functions to allow for filtering in the DB based on worker state and quarantined status for the workers page. Previously, filtering would only happen on the initial page loaded from the DB if results were paginated. This should also speed up the workers page rendering when a filter is applied.
▶ [patch] #5529
This patch makes it so that the docker-compose.yml file is updated with the new taskcluster docker image version on a yarn release. Previously, the version wasn't updated, so the meta-generate task would fail on releases. This issue first appeared in v44.16.4.
▶ [patch] #5319
This patch migrates the legacy, process.hrtime([time]) to the new, process.hrtime.bigint().
See Node Docs for more information.
▶ [patch] This patch upgrades dependencies to their latest minor/patch versions. Doing so fixes a handful of vulns found within Snyk and docker scans.
▶ [patch]
Added a cloudbuild.yaml file for the Google Cloud Build trigger on the main branch.
▶ [patch] #5517 This patch fixes the quarantined value on the workers table to be n/a if the quarantined value is in the past. This issue was first no
▶ [patch] This patch returns up the quarantineUntil field in the workerManager.getWorker and workerManager.listWorkers methods. This issue was first n
▶ [patch]
This patch returns up the quarantineUntil field in the workerManager.getWorker and workerManager.listWorkers methods. This issue was first noticed in v44.15.0.
▶ [patch] This patch adds a new field to be logged out on a failed provision call. This field will be used to measure the provisioning failed count.
▶ [patch] This patch adds a new field to be logged out on a failed provision call. This field will be used to measure the provisioning failed count.
▶ [patch] #5503 Add missing task-rerun scope to github handler.
▶ [patch] #5506 Log debug information for incoming Github webhooks.
▶ [patch] #5501
This patch makes it so a user cannot click the Terminate Worker button on a Static or Standalone worker. This patch also moves the Terminate Worker button on the view individual worker page to the speed dial menu alongside the Quarantine button. These issues were first brought up in v44.15.0.
<details> <summary>1 Renovate updates</summary>
</details>
Your coding agent can read these notes before it upgrades. Set up the MCP server →