- #1153 (minor) - Add
and()andor()resolver functions for combining boolean conditions - #1049 (minor)
Addvarlock freezefor apps with no framework integration baking env into the build (Elysia, Hono, Fastify, compiled binaries): it resolves every value once at deploy time into an encrypted file that ships inside the release, and with_VARLOCK_USE_FROZEN_ENV=1set at runtime the app boots from that file with no varlock CLI,.envfiles, or resolver credentials present. Framework integrations already freeze in build output (ssrInjectMode: 'resolved-env', picked automatically on some platforms), and Cloudflare Workers usevarlock-wrangler deploy, so those users need nothing new. See the frozen env guide for details, including@dynamic=bootfor values the platform sets per instance. - #1133 (minor)
Bundle the icons used by built-in data types, so@generateTsTypesno longer fetches them over the network. Plugins can ship their own icons viaplugin.bundledIcons, and plugin data types and resolvers without an icon now use the plugin's icon. Also adds anicons=falseoption to leave icons out of generated types entirely. - #1181 (minor)
Rename@redactLogsto@redact(the old name still works as a deprecated alias, with a warning) and add@redact={stdout=true}to redactprocess.stdout/process.stderrwrites (andBun.writeto them) invarlock/auto-loadand framework integrations, using the same non-TTY rule asvarlock run. Opt-in for now; planned to become the default in the next major. Also adds@sensitive={redact=false}to exempt a value that is meant to be printed, and speeds up the partial-match check used by streaming redaction. FixesrevealSensitiveConfig(), which printed its 👁 markers around the value and did not work under Bun. - #1161 (minor)
varlock/auto-loadand the framework integrations now warn when no config items are loaded (no .env files found, or none define items) instead of silently continuing with an empty config. This becomes an error in the next major. Set_VARLOCK_ALLOW_EMPTY_CONFIG=1to allow an empty config, which also letsvarlock loadandvarlock runsucceed with an empty config. - #1155 (patch) Thanks @timche!
Fixvarlock auditreporting a referenced item as unused when the item referencing it is overridden, either from the process environment or by a higher-priority file - #1172 (patch)
Build the standalone binary with Bun 1.4.2, fixing spawn failures when varlock runs from a directory the current user cannot enter - #1160 (patch) - Fix a declared builtin (e.g.
VARLOCK_ENV=) resolving empty when the@currentEnvitem depends on it - #1156 (patch)
Error output fixes:- errors thrown from a root decorator are no longer printed twice
- a failing
exec()no longer dumps a raw stack trace to stdout (which brokeload --format json-full); the error now includes the exit code and stderr - an invalid static
@cachevalue is reported once - a root decorator referencing an invalid item now shows that item's errors
json-fullitem errors no longer include warnings
- #1167 (patch)
Detect Fly.io as a platform (VARLOCK_PLATFORM=Fly.io), and warn whenVARLOCK_ENVis used but only guessedpreviewbecause the platform reports no environment or branch - #1169 (patch) Thanks @JayOfTheKeyboard!
Fix the native helper failing with EACCES when varlock runs from a directory the current user cannot enter, such as afterrunuserto a service user from a private home directory. This brokevarlock cache clearin the standalone binary. - #1196 (patch)
Cached pinned@pluginpackages now load without a registry lookup, so offline loads work after the plugin is cached (e.g. viavarlock install-plugin). Registry errors now name the plugin and URL. - #1168 (patch)
varlock proxy:@proxy(path=...)rules are now matched against the canonical request path (dot segments resolved, repeated slashes collapsed, unreserved percent-escapes decoded), and that canonical path is what is sent upstream. Previously a request spelled/v1/charges/../refunds/xdid not match apath="/v1/refunds/**"block rule even though the upstream routed it to/v1/refunds/x. Paths that cannot be canonicalized unambiguously (encoded slashes, backslashes, control characters,#,;path parameters,..above the root, absolute-form request lines inside a tunnel) are now rejected with a 400. AsubstituteIn=[path]value that would itself change the path structure (contains a path separator, dot segment, or query marker) is refused instead of routing the request somewhere the rules never evaluated. - #1170 (patch)
Fixvarlock proxyshutdown hanging when a client had read a blocked response over a MITM tunnel, or still held an idle CONNECT tunnel open - #1200 (patch) - Fail with a non-zero exit and name the stuck item when a resolver's promise never settles, instead of silently exiting 0
- #1194 (patch)
varlock runandvarlock proxy runno longer print a failure hint to stdout when the child exits non-zero; the child's exit code is passed through silently. A command that cannot be started is reported on stderr (exit 127 when not found, 126 when not executable) - #1202 (patch)
Fix redaction of--include-internalvalues invarlock run, and warn when a sensitive number is injected, since numbers are never redacted - #1180 (patch)
varlock runandvarlock proxy runno longer print a "command failed" error when the child handles Ctrl+C (or another forwarded signal) and exits non-zero, e.g. 130 - #1165 (patch) - Fix
varlock scan --install-hookfailing in git worktrees, and respectcore.hooksPath - #1195 (patch) - Fail instead of using partial output when a provider CLI is killed by a signal
- #1203 (patch) -
varlock telemetry disableno longer sends a usage event or creates an anonymous ID before saving the opt-out
Published to
- ✅ npm