Skip to content

chore: version packages - #402

Merged
cuibonobo merged 1 commit into
mainfrom
changeset-release/main
Oct 5, 2026
Merged

cuibonobo merged 1 commit into
mainfrom
changeset-release/main

Conversation

@cuibonobo

@cuibonobo cuibonobo commented Oct 4, 2026 •

Copy link
Copy Markdown
Member

This PR was opened by the Changesets release GitHub action. When you're ready to do a release, you can merge this and the packages will be published to npm automatically. If you're not ready to do a release yet, that's fine, whenever you add more changesets to main, this PR will be updated.

Releases

@haverstack/[email protected]

Minor Changes

  • #401 3021327 Thanks @cuibonobo! - Percent-encode record IDs, versions and fileIds as single URL path segments, so an ID holding /, ? or # cannot address a different endpoint. An ID of . or .. is refused with StackBadRequestError before any request is sent.

  • #400 6782ac9 Thanks @cuibonobo! - POST /installs lets an app present its manifest for the owner to approve, as the key its session authenticated with: 202 { status: 'pending' } until approved, 200 { status: 'installed', install } once applying it would change nothing. Discovery advertises it with installs: { requests: true }. APIAdapter.requestInstall() sends it, parseInstallBody() and isPlanEmpty() serve it, and installApp() gives each linked key read on its own _install record. A manifest may define only types in its own namespace (the family's namespace is the appId) and commons types, which it defines without claiming.

Patch Changes

@haverstack/[email protected]

Minor Changes

  • Released for a breaking change in @haverstack/core.

Patch Changes

@haverstack/[email protected]

Minor Changes

  • Released for a breaking change in @haverstack/blob-adapter-disk, @haverstack/core, @haverstack/record-adapter-sqlite.

Patch Changes

@haverstack/[email protected]

Minor Changes

  • Released for a breaking change in @haverstack/core.

Patch Changes

@haverstack/[email protected]

Minor Changes

  • Released for a breaking change in @haverstack/core.

Patch Changes

@haverstack/[email protected]

Minor Changes

  • Released for a breaking change in @haverstack/core.

Patch Changes

@haverstack/[email protected]

Minor Changes

  • #400 6782ac9 Thanks @cuibonobo! - POST /installs lets an app present its manifest for the owner to approve, as the key its session authenticated with: 202 { status: 'pending' } until approved, 200 { status: 'installed', install } once applying it would change nothing. Discovery advertises it with installs: { requests: true }. APIAdapter.requestInstall() sends it, parseInstallBody() and isPlanEmpty() serve it, and installApp() gives each linked key read on its own _install record. A manifest may define only types in its own namespace (the family's namespace is the appId) and commons types, which it defines without claiming.

Patch Changes

@haverstack/[email protected]

Minor Changes

  • #400 6782ac9 Thanks @cuibonobo! - POST /installs lets an app present its manifest for the owner to approve, as the key its session authenticated with: 202 { status: 'pending' } until approved, 200 { status: 'installed', install } once applying it would change nothing. Discovery advertises it with installs: { requests: true }. APIAdapter.requestInstall() sends it, parseInstallBody() and isPlanEmpty() serve it, and installApp() gives each linked key read on its own _install record. A manifest may define only types in its own namespace (the family's namespace is the appId) and commons types, which it defines without claiming.

  • #400 de4e587 Thanks @cuibonobo! - An installed app's commitMigration() is held to the file-reference gate. Requests compare as sets of actions, and a plan that changes only name or version is no longer empty.

  • #400 8049dd0 Thanks @cuibonobo! - App installs: Stack.planInstall(), installApp() and uninstallApp() apply an app's manifest (its types and the grants it requests) as one reviewable act, stored as a new _install@1 system type that cannot be granted and only the owner acting alone may write. An installed app may commit migrations within the type families its install claims, to versions the owner approved, when it holds update-any on them. migrateAll() takes { sweep: 'listed' } for a non-owner and returns { migrated, skipped }.

  • #401 ef500b8 Thanks @cuibonobo! - Cap content nesting at 32 levels inside open containers too, the same cap declared fields meet. A deeper value is a StackValidationError at its path rather than a stack overflow.

@haverstack/[email protected]

Minor Changes

  • Released for a breaking change in @haverstack/core.

Patch Changes

@haverstack/[email protected]

Minor Changes

  • Released for a breaking change in @haverstack/core.

Patch Changes

@haverstack/[email protected]

Minor Changes

  • #400 6782ac9 Thanks @cuibonobo! - POST /installs lets an app present its manifest for the owner to approve, as the key its session authenticated with: 202 { status: 'pending' } until approved, 200 { status: 'installed', install } once applying it would change nothing. Discovery advertises it with installs: { requests: true }. APIAdapter.requestInstall() sends it, parseInstallBody() and isPlanEmpty() serve it, and installApp() gives each linked key read on its own _install record. A manifest may define only types in its own namespace (the family's namespace is the appId) and commons types, which it defines without claiming.

Patch Changes

@cuibonobo
cuibonobo force-pushed the changeset-release/main branch from 495023d to 8914b1f Compare October 4, 2026 21:19
@cuibonobo
cuibonobo force-pushed the changeset-release/main branch from 8914b1f to 64dacae Compare October 5, 2026 09:24
@cuibonobo
cuibonobo merged commit 808a264 into main Oct 5, 2026
9 checks passed
@cuibonobo
cuibonobo deleted the changeset-release/main branch October 5, 2026 09:30
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant