github dmno-dev/varlock varlock@1.22.0
varlock v1.22.0

  • #1153 (minor) - Add and() and or() resolver functions for combining boolean conditions
  • #1049 (minor)
    Add varlock freeze for apps with no framework integration baking env into the build (Elysia, Hono, Fastify, compiled binaries): it resolves every value once at deploy time into an encrypted file that ships inside the release, and with _VARLOCK_USE_FROZEN_ENV=1 set at runtime the app boots from that file with no varlock CLI, .env files, or resolver credentials present. Framework integrations already freeze in build output (ssrInjectMode: 'resolved-env', picked automatically on some platforms), and Cloudflare Workers use varlock-wrangler deploy, so those users need nothing new. See the frozen env guide for details, including @dynamic=boot for values the platform sets per instance.
  • #1133 (minor)
    Bundle the icons used by built-in data types, so @generateTsTypes no longer fetches them over the network. Plugins can ship their own icons via plugin.bundledIcons, and plugin data types and resolvers without an icon now use the plugin's icon. Also adds an icons=false option to leave icons out of generated types entirely.
  • #1181 (minor)
    Rename @redactLogs to @redact (the old name still works as a deprecated alias, with a warning) and add @redact={stdout=true} to redact process.stdout/process.stderr writes (and Bun.write to them) in varlock/auto-load and framework integrations, using the same non-TTY rule as varlock run. Opt-in for now; planned to become the default in the next major. Also adds @sensitive={redact=false} to exempt a value that is meant to be printed, and speeds up the partial-match check used by streaming redaction. Fixes revealSensitiveConfig(), which printed its 👁 markers around the value and did not work under Bun.
  • #1161 (minor)
    varlock/auto-load and the framework integrations now warn when no config items are loaded (no .env files found, or none define items) instead of silently continuing with an empty config. This becomes an error in the next major. Set _VARLOCK_ALLOW_EMPTY_CONFIG=1 to allow an empty config, which also lets varlock load and varlock run succeed with an empty config.
  • #1155 (patch) Thanks @timche!
    Fix varlock audit reporting a referenced item as unused when the item referencing it is overridden, either from the process environment or by a higher-priority file
  • #1172 (patch)
    Build the standalone binary with Bun 1.4.2, fixing spawn failures when varlock runs from a directory the current user cannot enter
  • #1160 (patch) - Fix a declared builtin (e.g. VARLOCK_ENV=) resolving empty when the @currentEnv item depends on it
  • #1156 (patch)
    Error output fixes:
    • errors thrown from a root decorator are no longer printed twice
    • a failing exec() no longer dumps a raw stack trace to stdout (which broke load --format json-full); the error now includes the exit code and stderr
    • an invalid static @cache value is reported once
    • a root decorator referencing an invalid item now shows that item's errors
    • json-full item errors no longer include warnings
  • #1167 (patch)
    Detect Fly.io as a platform (VARLOCK_PLATFORM=Fly.io), and warn when VARLOCK_ENV is used but only guessed preview because the platform reports no environment or branch
  • #1169 (patch) Thanks @JayOfTheKeyboard!
    Fix the native helper failing with EACCES when varlock runs from a directory the current user cannot enter, such as after runuser to a service user from a private home directory. This broke varlock cache clear in the standalone binary.
  • #1196 (patch)
    Cached pinned @plugin packages now load without a registry lookup, so offline loads work after the plugin is cached (e.g. via varlock install-plugin). Registry errors now name the plugin and URL.
  • #1168 (patch)
    varlock proxy: @proxy(path=...) rules are now matched against the canonical request path (dot segments resolved, repeated slashes collapsed, unreserved percent-escapes decoded), and that canonical path is what is sent upstream. Previously a request spelled /v1/charges/../refunds/x did not match a path="/v1/refunds/**" block rule even though the upstream routed it to /v1/refunds/x. Paths that cannot be canonicalized unambiguously (encoded slashes, backslashes, control characters, #, ; path parameters, .. above the root, absolute-form request lines inside a tunnel) are now rejected with a 400. A substituteIn=[path] value that would itself change the path structure (contains a path separator, dot segment, or query marker) is refused instead of routing the request somewhere the rules never evaluated.
  • #1170 (patch)
    Fix varlock proxy shutdown hanging when a client had read a blocked response over a MITM tunnel, or still held an idle CONNECT tunnel open
  • #1200 (patch) - Fail with a non-zero exit and name the stuck item when a resolver's promise never settles, instead of silently exiting 0
  • #1194 (patch)
    varlock run and varlock proxy run no longer print a failure hint to stdout when the child exits non-zero; the child's exit code is passed through silently. A command that cannot be started is reported on stderr (exit 127 when not found, 126 when not executable)
  • #1202 (patch)
    Fix redaction of --include-internal values in varlock run, and warn when a sensitive number is injected, since numbers are never redacted
  • #1180 (patch)
    varlock run and varlock proxy run no longer print a "command failed" error when the child handles Ctrl+C (or another forwarded signal) and exits non-zero, e.g. 130
  • #1165 (patch) - Fix varlock scan --install-hook failing in git worktrees, and respect core.hooksPath
  • #1195 (patch) - Fail instead of using partial output when a provider CLI is killed by a signal
  • #1203 (patch) - varlock telemetry disable no longer sends a usage event or creates an anonymous ID before saving the opt-out

Published to

Don't miss a new varlock release

NewReleases is sending notifications on new releases.