Repository navigation
Tags: trydirect/stacker
Tags
release: bump version to 0.3.3 - Chat session management with archive and encryption - Agent hardening: per-tenant ownership, token digest verification, fail-closed auth - Marketplace field policy: config_contract, generated-field stripping, derived_jwt signing - Project sync, one-click deploy improvements, deployment container tracking - SSH key authorization fixes, mTLS for Vault, port validation - Stale project/server cleanup, audit-log cron, env size validator - Multiple BDD and migration fixes
Stacker v0.3.0 Highlights: - Shell hook security overhaul (audit C1–M5): path traversal / symlink guards, content validation wired into pre_build/post_deploy/on_failure, real timeout with child.kill(), env scrubbing + PATH/HOME allowlist, hook CWD pinned to project dir. - Marketplace-origin trust marker + --allow-untrusted-hooks / --no-hooks flags on `stacker deploy`. - Two-layer output OOM defence: pipe-level cap (1 MiB + slack) and display-level cap with ANSI-strip before terminal / error-message boundaries. - --from-github install path, SKILL.md, expanded test coverage (auth middleware, Stripe webhook signature, marketplace access, DAG graph, deploy validator). - Documentation: hook execution contract in docs/STACKER_YML_REFERENCE.md, post-audit ledger in docs/SECURITY_AUDIT_HOOKS.md.
PreviousNext