Skip to content
Merged
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
48 changes: 48 additions & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
@@ -1,5 +1,53 @@
# Changelog

## [1.1.0](https://www.github.com/flant/trx/compare/v1.0.0...v1.1.0) (2026-09-19)


### Notable Changes

No breaking change: the `BREAKING CHANGE` trailer of ad9f231 described a
rejection of DSA and ElGamal keys and of SHA-1 signatures that the verification
path never applies, since that policy belongs to the `openpgp/v2` API and trdl
uses v1. Tags signed with such keys keep passing verification.

These do change behaviour, without breaking a working configuration:

* `onQuorumFailure` and `onCommandSkipped` run in the working directory trx was started in, not in the checkout, so that a hook reporting a failed verification cannot execute unverified repository content. A relative path such as `./notify.sh` stops resolving inside the repository.
* The operator `env` overrides the repository one, as the README documents, and env names coming from a repository `trx.yaml` are upper-cased.
* An unknown template variable fails the run instead of being rendered as the literal `<no value>`.
* Checking out the target tag removes untracked files left in the clone.
* `--disable-lock` skips locking outright, and an instance that loses the lock race fails instead of deploying concurrently.
* A quorum that lists the same GPG key twice keeps loading, with a warning, but the duplicate no longer counts towards `minNumberOfKeys`: such a quorum now fails verification through `onQuorumFailure`.

### Bug Fixes

* **command:** fail on an unknown template variable ([f6b265e](https://www.github.com/flant/trx/commit/f6b265ebe89a9a60c2991d2b8ccd544fca64a86d))
* **command:** render commands with text/template ([4f4543b](https://www.github.com/flant/trx/commit/4f4543b034237027da7c17252cc6d2c6ee45d203))
* **command:** signal the whole process group, keep hooks alive ([11e8e8e](https://www.github.com/flant/trx/commit/11e8e8e728ff4d722d6f47d1679fe3777fec70ed))
* **command:** upper-case env names in one place, let the operator win ([6c32151](https://www.github.com/flant/trx/commit/6c32151d330792d6e8e9a6b345a1616e3134e4a5))
* **config:** keep accepting initial_last_published_git_commit ([5b8f75a](https://www.github.com/flant/trx/commit/5b8f75a5a2a93e09383e0885ec1120b346d6a5c3))
* **git:** bound clone and fetch, and repair a broken clone ([7e9f572](https://www.github.com/flant/trx/commit/7e9f572122910dd393e7cb0d15dca1843fb8093e))
* **git:** clean the worktree when checking out the target tag ([6101d8c](https://www.github.com/flant/trx/commit/6101d8c6111ac10d478b65c9a9535cfd726faaaa))
* **git:** resolve an annotated tag to its commit ([3ec414f](https://www.github.com/flant/trx/commit/3ec414f4b67afb990eeb79b6dec751483579d050))
* **lock:** skip locking with --disable-lock and fail on a lost race ([#34](https://www.github.com/flant/trx/issues/34)) ([418047c](https://www.github.com/flant/trx/commit/418047c0c0c7957536c58e650747d28d86758143))
* print hook errors, name the right hooks, drop dead code ([4256e98](https://www.github.com/flant/trx/commit/4256e984018a159914fc1f409111dd9b4f2e3b05))
* **quorum:** do not panic on a quorum without a name ([1dc7384](https://www.github.com/flant/trx/commit/1dc738423066449e20b8b7ceb24b48e1759d2ab5))
* **quorum:** support EdDSA (Ed25519) GPG keys in signature verification ([#12](https://www.github.com/flant/trx/issues/12)) ([b32caf4](https://www.github.com/flant/trx/commit/b32caf4a053170c505c8e39f6e4644d0599a1afb))
* **quorum:** warn about a duplicate GPG key instead of refusing to start ([f454712](https://www.github.com/flant/trx/commit/f45471206a22ba6963847e28ac32ea8c214c97f4))
* report the locker and ssh key errors instead of ignoring them ([6caa0b8](https://www.github.com/flant/trx/commit/6caa0b86f514e8fbe54bba20b70d51b51c8b7c57))
* **storage:** write the state atomically ([b39a881](https://www.github.com/flant/trx/commit/b39a881d2092e5791b7cffe2ba3d103f2ec65db1))
* the blocking findings of the main audit ([#37](https://www.github.com/flant/trx/issues/37)) ([c8c3cd9](https://www.github.com/flant/trx/commit/c8c3cd974b473dd0cac0b28a9a30fbc3dfb10f44))


### Tests

* **quorum:** cover a real two-signature quorum, generate the test key ([ad9f231](https://www.github.com/flant/trx/commit/ad9f23118e37c57458c3c6f3d5eee0050eeb2e60))


### Miscellaneous Chores

* release the audit fixes as 1.1.0 ([9b5d0bc](https://www.github.com/flant/trx/commit/9b5d0bc7beac70c304f03bf8f8e56a4351a00d39))

## 1.0.0 (2025-03-21)


Expand Down