Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 2 additions & 0 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -256,6 +256,7 @@ jobs:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
fetch-depth: 0
- uses: pnpm/action-setup@0977fd99725f1db4007ccb2928dbb4e90d06cc86 # v6.0.10
- uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7
with:
Expand Down Expand Up @@ -354,6 +355,7 @@ jobs:
- uses: useblacksmith/checkout@25227e61ff9dafe400e22fa487b673eac4e4409a # v1.8.1
with:
persist-credentials: false
fetch-depth: 0
- uses: pnpm/action-setup@0977fd99725f1db4007ccb2928dbb4e90d06cc86 # v6.0.10
- uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7
with:
Expand Down
7 changes: 7 additions & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -4,6 +4,12 @@ All notable changes to this project are recorded here. Released artifacts are im

## Unreleased

## [0.1.7] - 2026-10-01

### Fixed

- Removed redundant borders around the dashboard sidebar, active navigation item, and overview cards.

## [0.1.6] - 2026-09-30

### Fixed
Expand Down Expand Up @@ -69,4 +75,5 @@ All notable changes to this project are recorded here. Released artifacts are im
[0.1.1]: https://github.com/8lines/gauntlet/releases/tag/v0.1.1
[0.1.2]: https://github.com/8lines/gauntlet/releases/tag/v0.1.2
[0.1.6]: https://github.com/8lines/gauntlet/releases/tag/v0.1.6
[0.1.7]: https://github.com/8lines/gauntlet/releases/tag/v0.1.7
[0.1.0]: https://github.com/8lines/gauntlet/releases/tag/v0.1.0
2 changes: 1 addition & 1 deletion VERSION
Original file line number Diff line number Diff line change
@@ -1 +1 @@
0.1.6
0.1.7
2 changes: 1 addition & 1 deletion apps/dashboard/package.json
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
{
"name": "@8lines/gauntlet-dashboard",
"version": "0.1.6",
"version": "0.1.7",
"private": true,
"license": "Apache-2.0",
"type": "module",
Expand Down
4 changes: 2 additions & 2 deletions apps/server/package.json
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
{
"name": "@8lines/gauntlet-server",
"version": "0.1.6",
"version": "0.1.7",
"private": true,
"license": "Apache-2.0",
"type": "module",
Expand All @@ -24,7 +24,7 @@
"@fastify/static": "10.1.3",
"@modelcontextprotocol/node": "2.0.0",
"@modelcontextprotocol/server": "2.0.0",
"fastify": "5.12.1",
"fastify": "5.12.5",
"yaml": "2.8.3",
"zod": "4.5.4"
},
Expand Down
2 changes: 1 addition & 1 deletion conformance/runner/package.json
Original file line number Diff line number Diff line change
@@ -1,7 +1,7 @@
{
"name": "@8lines/gauntlet-conformance-runner",
"description": "Scenario-driven Adapter v1 conformance libraries, CLI runners, and fixture adapter for Gauntlet implementations.",
"version": "0.1.6",
"version": "0.1.7",
"type": "module",
"license": "Apache-2.0",
"engines": { "node": ">=24 <27" },
Expand Down
2 changes: 1 addition & 1 deletion deploy/compose/.env.example
Original file line number Diff line number Diff line change
@@ -1,4 +1,4 @@
GAUNTLET_IMAGE=ghcr.io/8lines/gauntlet:0.1.6
GAUNTLET_IMAGE=ghcr.io/8lines/gauntlet:0.1.7
GAUNTLET_BIND=127.0.0.1
GAUNTLET_PORT=8080
GAUNTLET_CONFIG_PATH=./config.yaml
Expand Down
18 changes: 9 additions & 9 deletions deploy/helm/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -49,7 +49,7 @@ command argument, values file, rendered manifest, or source control.

Create a reviewed `values.acme-staging.yaml`. This is a complete values file,
not an overlay; keep one complete file per environment and protect changes with
normal code review. The example uses the exact `0.1.6` application tag: stable tags are versioned; only digests are immutable. For digest pinning, set `tag` to
normal code review. The example uses the exact `0.1.7` application tag: stable tags are versioned; only digests are immutable. For digest pinning, set `tag` to
an empty string and set `digest` to the reviewed `sha256:...` value.

<!-- gauntlet:environment-values -->
Expand All @@ -58,7 +58,7 @@ replicaCount: 1

image:
repository: ghcr.io/8lines/gauntlet
tag: "0.1.6"
tag: "0.1.7"
digest: ""
pullPolicy: IfNotPresent
imagePullSecrets: []
Expand Down Expand Up @@ -143,17 +143,17 @@ The chart is public, so `helm pull` needs no `helm registry login`. When you
pull through an authenticated mirror, log in by standard input so the token is
never an argument (`--password-stdin`).

Pull the exact `0.1.6` chart to a local immutable input, render that same archive
Pull the exact `0.1.7` chart to a local immutable input, render that same archive
for review, and install that same archive. Do not install directly from an OCI
URL after previewing a different input. The namespace must already exist.

<!-- gauntlet:pull-render-install -->
```sh
helm pull oci://ghcr.io/8lines/charts/gauntlet --version 0.1.6 --destination .
helm template gauntlet ./gauntlet-0.1.6.tgz \
helm pull oci://ghcr.io/8lines/charts/gauntlet --version 0.1.7 --destination .
helm template gauntlet ./gauntlet-0.1.7.tgz \
--namespace acme-staging \
-f values.acme-staging.yaml > rendered.yaml
helm upgrade --install gauntlet ./gauntlet-0.1.6.tgz \
helm upgrade --install gauntlet ./gauntlet-0.1.7.tgz \
--namespace acme-staging \
-f values.acme-staging.yaml \
--reset-values \
Expand Down Expand Up @@ -222,8 +222,8 @@ file:
<!-- gauntlet:backup-preview -->
```sh
helm get values gauntlet --namespace acme-staging --all > values.before-upgrade.yaml
helm pull oci://ghcr.io/8lines/charts/gauntlet --version 0.1.6 --destination .
helm template gauntlet ./gauntlet-0.1.6.tgz \
helm pull oci://ghcr.io/8lines/charts/gauntlet --version 0.1.7 --destination .
helm template gauntlet ./gauntlet-0.1.7.tgz \
--namespace acme-staging \
-f values.acme-staging.yaml > rendered.upgrade.yaml
```
Expand All @@ -236,7 +236,7 @@ Apply exactly the reviewed local archive:

<!-- gauntlet:upgrade -->
```sh
helm upgrade gauntlet ./gauntlet-0.1.6.tgz \
helm upgrade gauntlet ./gauntlet-0.1.7.tgz \
--namespace acme-staging \
-f values.acme-staging.yaml \
--reset-values \
Expand Down
4 changes: 2 additions & 2 deletions deploy/helm/gauntlet/Chart.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -2,8 +2,8 @@ apiVersion: v2
name: gauntlet
description: Private non-production Gauntlet control plane and dashboard
type: application
version: 0.1.6
appVersion: "0.1.6"
version: 0.1.7
appVersion: "0.1.7"
kubeVersion: ">=1.33.0-0"
annotations:
artifacthub.io/license: Apache-2.0
2 changes: 1 addition & 1 deletion deploy/helm/gauntlet/values.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,7 @@ replicaCount: 1

image:
repository: ghcr.io/8lines/gauntlet
tag: "0.1.6"
tag: "0.1.7"
digest: ""
pullPolicy: IfNotPresent
imagePullSecrets: []
Expand Down
18 changes: 9 additions & 9 deletions deploy/helm/test-chart-package.mjs
Original file line number Diff line number Diff line change
Expand Up @@ -68,12 +68,12 @@ const canonicalChartPayload = Buffer.from([
"annotations:",
" artifacthub.io/license: Apache-2.0",
"apiVersion: v2",
"appVersion: 0.1.6",
"appVersion: 0.1.7",
"description: Private non-production Gauntlet control plane and dashboard",
"kubeVersion: '>=1.33.0-0'",
"name: gauntlet",
"type: application",
"version: 0.1.6",
"version: 0.1.7",
"",
].join("\n"));

Expand Down Expand Up @@ -211,7 +211,7 @@ test("the package projection is a closed, normalized regular-file chart", () =>
assert.equal(stat.mtimeMs, normalizedMtimeMs, path);
assert.deepEqual(readFileSync(projectedPath), readFileSync(join(chartRoot, path)), path);
}
assert.equal(projection.version, "0.1.6");
assert.equal(projection.version, "0.1.7");
} finally {
projection.dispose();
}
Expand Down Expand Up @@ -591,7 +591,7 @@ test("destination race checks never publish or clean exchanged paths", { timeout
const destination = join(fixture, "destination");
const displaced = join(fixture, "destination-original");
const foreign = join(fixture, "foreign");
const foreignArchive = join(foreign, "gauntlet-0.1.6.tgz");
const foreignArchive = join(foreign, "gauntlet-0.1.7.tgz");
const temporarySwapDestination = join(fixture, "temporary-swap");
const finalSwapDestination = join(fixture, "final-swap");
const sentinel = "destination-race-sentinel-915702";
Expand Down Expand Up @@ -639,7 +639,7 @@ test("destination race checks never publish or clean exchanged paths", { timeout
);
assert.equal(readFileSync(exchangedDestinationPath, "utf8"), sentinel);

const exchangedFinalPath = join(finalSwapDestination, "gauntlet-0.1.6.tgz");
const exchangedFinalPath = join(finalSwapDestination, "gauntlet-0.1.7.tgz");
assert.throws(
() => packager.packageChart({
destinationDirectory: finalSwapDestination,
Expand Down Expand Up @@ -681,7 +681,7 @@ test("package cleanup is independent, preserves primary errors, and cannot undo
},
},
});
assert.equal(receipt.archivePath, join(successfulDestination, "gauntlet-0.1.6.tgz"));
assert.equal(receipt.archivePath, join(successfulDestination, "gauntlet-0.1.7.tgz"));
assert.deepEqual(receipt.cleanupPending, ["helm-output"]);
assert.equal(existsSync(receipt.archivePath), true);
assert.equal(outputCleanupCalls, 1);
Expand Down Expand Up @@ -714,7 +714,7 @@ test("package cleanup is independent, preserves primary errors, and cannot undo
},
);
assert.equal(cleanupRoots.length, 2);
assert.equal(existsSync(join(failedDestination, "gauntlet-0.1.6.tgz")), false);
assert.equal(existsSync(join(failedDestination, "gauntlet-0.1.7.tgz")), false);
for (const root of cleanupRoots) {
assert.equal(existsSync(root), true);
removeGeneratedTree(root);
Expand Down Expand Up @@ -745,11 +745,11 @@ test("the pinned Helm package is exact, deterministic, mutation-sensitive, and n
const first = packager.packageChart({ destinationDirectory: firstDestination });
const second = packager.packageChart({ destinationDirectory: secondDestination });
assert.deepEqual(first, {
archivePath: join(firstDestination, "gauntlet-0.1.6.tgz"),
archivePath: join(firstDestination, "gauntlet-0.1.7.tgz"),
cleanupPending: [],
sha256: createHash("sha256").update(readFileSync(first.archivePath)).digest("hex"),
size: lstatSync(first.archivePath).size,
version: "0.1.6",
version: "0.1.7",
});
const firstArchive = readFileSync(first.archivePath);
const secondArchive = readFileSync(second.archivePath);
Expand Down
16 changes: 8 additions & 8 deletions deploy/helm/test-documentation.mjs
Original file line number Diff line number Diff line change
Expand Up @@ -185,7 +185,7 @@ test("the documented values and command blocks are complete and exact", () => {
replicaCount: 1,
image: {
repository: "ghcr.io/8lines/gauntlet",
tag: "0.1.6",
tag: "0.1.7",
digest: "",
pullPolicy: "IfNotPresent",
},
Expand Down Expand Up @@ -222,9 +222,9 @@ test("the documented values and command blocks are complete and exact", () => {
tolerations: [],
affinity: {},
});
assert.match(blocks.get("pull-render-install").text, /helm pull oci:\/\/ghcr\.io\/8lines\/charts\/gauntlet --version 0\.1\.6/);
assert.match(blocks.get("pull-render-install").text, /helm template gauntlet \.\/gauntlet-0\.1\.6\.tgz/);
assert.match(blocks.get("pull-render-install").text, /helm upgrade --install gauntlet \.\/gauntlet-0\.1\.6\.tgz/);
assert.match(blocks.get("pull-render-install").text, /helm pull oci:\/\/ghcr\.io\/8lines\/charts\/gauntlet --version 0\.1\.7/);
assert.match(blocks.get("pull-render-install").text, /helm template gauntlet \.\/gauntlet-0\.1\.7\.tgz/);
assert.match(blocks.get("pull-render-install").text, /helm upgrade --install gauntlet \.\/gauntlet-0\.1\.7\.tgz/);
assert.match(blocks.get("pull-render-install").text, /--reset-values/);
assert.match(blocks.get("private-access").text, /--address 127\.0\.0\.1/);
assert.match(blocks.get("rollback").text, /helm rollback gauntlet 3 /);
Expand Down Expand Up @@ -255,7 +255,7 @@ if [ "$tool" = helm ] && [ "\${1-}" = registry ] && [ "\${2-}" = login ]; then
[ "$payload" = "$DOC_TOKEN" ] || exit 91
fi
if [ "$tool" = helm ] && [ "\${1-}" = pull ]; then
: > "$DOC_ROOT/gauntlet-0.1.6.tgz"
: > "$DOC_ROOT/gauntlet-0.1.7.tgz"
fi
if [ "$tool" = helm ] && [ "\${1-}" = template ]; then
printf '%s\n' 'apiVersion: v1' 'kind: ConfigMap' 'metadata:' ' name: rendered-preview'
Expand Down Expand Up @@ -291,7 +291,7 @@ fi
});
assert.equal(result.status, 0, result.stderr);
}
assert.equal(readFileSync(join(fixture, "gauntlet-0.1.6.tgz")).length, 0);
assert.equal(readFileSync(join(fixture, "gauntlet-0.1.7.tgz")).length, 0);
assert.match(readFileSync(join(fixture, "rendered.yaml"), "utf8"), /rendered-preview/);
assert.match(readFileSync(join(fixture, "rendered.upgrade.yaml"), "utf8"), /rendered-preview/);
assert.equal(readFileSync(receipt, "utf8").includes("fake-registry-token-930412"), false);
Expand All @@ -302,9 +302,9 @@ fi
const install = calls.findIndex((call) => call[0] === "helm" && call[1] === "upgrade" && call[2] === "--install");
assert.ok(pull >= 0 && pull < render && render < install);
assert.deepEqual(calls[pull].slice(1), [
"pull", "oci://ghcr.io/8lines/charts/gauntlet", "--version", "0.1.6", "--destination", ".",
"pull", "oci://ghcr.io/8lines/charts/gauntlet", "--version", "0.1.7", "--destination", ".",
]);
assert.equal(calls[install].includes("./gauntlet-0.1.6.tgz"), true);
assert.equal(calls[install].includes("./gauntlet-0.1.7.tgz"), true);
assert.equal(calls[install].includes("--reset-values"), true);
assert.equal(calls.some((call) => call.includes("--create-namespace")), false);
} finally {
Expand Down
6 changes: 3 additions & 3 deletions deploy/helm/test-rendered-manifests.mjs
Original file line number Diff line number Diff line change
Expand Up @@ -136,7 +136,7 @@ test("the staging render is exactly one hardened single-instance internal worklo
assert.equal(pod.containers.length, 1);
const container = pod.containers[0];
assert.equal(container.name, "gauntlet");
assert.equal(container.image, "ghcr.io/8lines/gauntlet:0.1.6");
assert.equal(container.image, "ghcr.io/8lines/gauntlet:0.1.7");
assert.equal(container.imagePullPolicy, "IfNotPresent");
assert.deepEqual(container.ports, [{ name: "http", containerPort: 8080, protocol: "TCP" }]);
assert.deepEqual(container.env, [
Expand Down Expand Up @@ -375,10 +375,10 @@ function assertExactKeys(value, expected) {
function assertClosedHardenedSurface(resources) {
assert.deepEqual(resources.map(({ kind }) => kind).sort(), ["ConfigMap", "Deployment", "Service"]);
const labels = {
"helm.sh/chart": "gauntlet-0.1.6",
"helm.sh/chart": "gauntlet-0.1.7",
"app.kubernetes.io/name": "gauntlet",
"app.kubernetes.io/instance": "gauntlet",
"app.kubernetes.io/version": "0.1.6",
"app.kubernetes.io/version": "0.1.7",
"app.kubernetes.io/component": "control-plane",
"app.kubernetes.io/part-of": "gauntlet",
"app.kubernetes.io/managed-by": "Helm",
Expand Down
6 changes: 3 additions & 3 deletions docs/ai-skills.md
Original file line number Diff line number Diff line change
Expand Up @@ -64,16 +64,16 @@ unknown directory merely to make installation succeed.

## Install from a release archive

The GitHub release contains `gauntlet-skills-0.1.6.tgz` and records its
The GitHub release contains `gauntlet-skills-0.1.7.tgz` and records its
digest in `SHA256SUMS` and the release inventory. Verify those release files
before extraction. Extract into a new private temporary directory, not directly
into the skills destination:

```sh
skills_unpack="$(mktemp -d)"
chmod 700 "$skills_unpack"
tar -xzf gauntlet-skills-0.1.6.tgz -C "$skills_unpack"
skills_archive_root="$skills_unpack/gauntlet-skills-0.1.6"
tar -xzf gauntlet-skills-0.1.7.tgz -C "$skills_unpack"
skills_archive_root="$skills_unpack/gauntlet-skills-0.1.7"
```

The archive contains a closed manifest, the two validated skill trees, and a
Expand Down
2 changes: 1 addition & 1 deletion docs/integrations/widget.md
Original file line number Diff line number Diff line change
Expand Up @@ -121,7 +121,7 @@ which side the panel opens from: `"bottom-right"` (the default) or
Install the typed package instead of hand-writing the queue stub:

```sh
npm install @8lines/gauntlet-widget@0.1.6
npm install @8lines/gauntlet-widget@0.1.7
```

The package is published publicly on npmjs.org; see
Expand Down
22 changes: 11 additions & 11 deletions docs/releases/installing-packages.md
Original file line number Diff line number Diff line change
Expand Up @@ -25,9 +25,9 @@ Install exact versions from the public registry. No `.npmrc` scope mapping or
token is needed:

```sh
pnpm add @8lines/gauntlet-protocol@0.1.6 \
@8lines/gauntlet-typescript-core@0.1.6 \
@8lines/gauntlet-typescript-node@0.1.6
pnpm add @8lines/gauntlet-protocol@0.1.7 \
@8lines/gauntlet-typescript-core@0.1.7 \
@8lines/gauntlet-typescript-node@0.1.7
```

The published packages are `@8lines/gauntlet-protocol`,
Expand All @@ -44,16 +44,16 @@ runners, and the release job runs on a self-hosted runner. Ensure the lockfile r

The PHP packages are published on Packagist from the public split repositories
`8lines/gauntlet-php-core` and `8lines/gauntlet-symfony-bundle`, each tagged
with an annotated `v0.1.6`. No custom `repositories` entry, `auth.json`, or
with an annotated `v0.1.7`. No custom `repositories` entry, `auth.json`, or
`COMPOSER_AUTH` is needed:

```sh
composer require 8lines/gauntlet-symfony-bundle:0.1.6
composer require 8lines/gauntlet-symfony-bundle:0.1.7
```

The bundle requires the matching `8lines/gauntlet-php-core` release, which
Composer installs automatically. For a framework-neutral integration, require
`8lines/gauntlet-php-core:0.1.6` alone. Verify that `composer.lock` records the
`8lines/gauntlet-php-core:0.1.7` alone. Verify that `composer.lock` records the
expected package versions and source commits.

The split repositories are read-only release mirrors of
Expand Down Expand Up @@ -88,8 +88,8 @@ repository ID used by the application and `settings.xml` must match.
Consume immutable coordinates:

```text
dev.eightlines.gauntlet:core:0.1.6
dev.eightlines.gauntlet:spring-boot-starter:0.1.6
dev.eightlines.gauntlet:core:0.1.7
dev.eightlines.gauntlet:spring-boot-starter:0.1.7
```

Keep Gradle dependency verification and lock metadata enabled in the consumer.
Expand All @@ -100,12 +100,12 @@ The image and the Helm chart are public, so pulling them needs no
`docker login`, `helm registry login`, or Kubernetes imagePullSecret:

```sh
docker pull ghcr.io/8lines/gauntlet:0.1.6
helm pull oci://ghcr.io/8lines/charts/gauntlet --version 0.1.6
docker pull ghcr.io/8lines/gauntlet:0.1.7
helm pull oci://ghcr.io/8lines/charts/gauntlet --version 0.1.7
```

Prefer an image digest in an operator-managed deployment. Pull the Helm chart
at exact version `0.1.6`, render that local archive, and install the same bytes.
at exact version `0.1.7`, render that local archive, and install the same bytes.
A cluster that must pull through an authenticated mirror can still set the
chart's optional `imagePullSecrets` value; the chart never creates that Secret.
When a private mirror does need credentials, supply them without a token
Expand Down
Loading