Release Notes
🛡️ Security
- Local
.prototoolsconfigs must now be trusted before their security-sensitive settings are applied. Previously, any config, for example one in a freshly cloned repository, could execute arbitrary code on the host as soon as its directory was entered with shell activation, through environment variables (likeBASH_ENVorPROMPT_COMMAND), shell aliases, or plugins.- Security-sensitive settings are
[env](including.envfiles),[shell],[plugins],[backends],[tools.*](exceptaliases), theprotoversion pin, and all[settings]exceptdetect-strategy,lockfile,pin-latest, andtelemetry. - Version pins for built-in tools (and the
npmandcargobackends), version aliases, and the remaining settings are always applied. Pins for other tools also require trust, as loading them downloads and executes a third-party plugin (from the community registry, or an asdf plugin). - User (
~/.prototools) and global (~/.proto/.prototools) configs are always trusted. - All configs are trusted in CI, and within the directories listed in the
PROTO_TRUSTED_PATHSenvironment variable. CI is detected from theCIenvironment variable (or a CI provider's variables), so avoid setting it in your shell profile.
- Security-sensitive settings are
proto install --immutable-lockfile(andPROTO_IMMUTABLE_LOCKFILE) now errors when the lockfile only has a record for a version from other operating systems or architectures. Previously, the version was inherited from that record, and since the other platform's checksum is not valid here, the download was installed without being verified against the lockfile.- Run
proto installwithout--immutable-lockfileon each platform to record its checksum. Installs without--immutable-lockfilestill inherit the version locked by another platform.
- Run
🚀 Updates
- Added unstable Kotlin support:
proto install kotlin. Requires a Java runtime, which can be installed withproto install java. - Added a
closestpin location, which targets the closest directory with a.prototools, starting from the current directory and traversing upwards. When none is found, the current directory is used. Directories with only an environment config (.prototools.<env>), and the user (~/.prototools) and global (~/.proto/.prototools) configs, are never targeted.- This is now the default location for
proto pin,proto unpin,proto alias,proto unalias,proto plugin add,proto plugin remove, andproto install --pin, instead oflocal. Pass--to local(or--from local) for the previous behavior. - The
installMCP tool now pins to the closest config as well.
- This is now the default location for
- Added
proto trust [path]andproto untrust [path]commands, where the path is a config file, or a directory (including its sub-directories), either absolute or relative to the current directory. Defaults to the current directory.- Trust is not affected by changes to the configs.
- When proto adds security-sensitive settings to a config that had none, like
proto plugin add, the config is trusted.
- Added a
trusttarget toproto clean, which removes trust records for config files and directories that no longer exist, so a repository cloned later at the same path is not trusted. Also included in the defaultalltarget. - Updated
proto statusandproto diagnoseto report untrusted configs, andproto diagnoseto warn when every config is trusted because a CI environment was detected in an interactive terminal. - Updated
proto activateto warn about untrusted configs once per shell session. Other commands warn about them too, except tool commands (run,exec,bin,shell), which are executed by scripts and editors. - Added a
libcfield to.protolockrecords created on Linux (gnuormusl), so that machines with different libcs (for example, Alpine and Debian) no longer share a record, and fail each other's checksum verification.- Existing records without a
libccontinue to match every libc, and are backfilled with the current libc on the next install that updates the record. - When only another libc has locked a version, the version is inherited like it is for other operating systems and architectures, or errors with
--immutable-lockfile.
- Existing records without a
- WASM API
- Updated the
load_git_tagsPDK function to return an error, which includes the exit code and stderr ofgit ls-remote, when the tags fail to load, instead of an empty list. Previously, the cause (like an unreachable remote, or an unaccepted Xcode license on macOS) was hidden behind a misleading "Failed to resolve version" error, and previously cached versions were not used as a fallback.- Plugins that should continue without the tags must now handle the error, for example with
.unwrap_or_default().
- Plugins that should continue without the tags must now handle the error, for example with
- Added a
HostPlatformtype, which represents an architecture, operating system, and libc, and can be parsed from<arch>-<os>[-<libc>](for example,arm64-linux-musl) or a Rust target triple (for example,aarch64-unknown-linux-musl). - Updated
HostLibcto deserialize unsupported values asunknown, instead of failing, so that plugins built with this version continue to work when a future version of proto adds a libc. - Updated the
ConfigBuilder::hosttest utility to require aHostPlatform, instead of an operating system and architecture, so that the libc can be configured. For example,.host(HostPlatform::parse("x64-linux-musl")?). The libc is no longer detected from the current machine, and defaults tognufor Linux.
- Updated the
🧩 Plugins
- Schema (config based)
- Added a new v2 schema format, enabled with
format = "2". Settings mirror proto's plugin API types, and support version specific[[overrides]]. - Secondary executable paths now support tokens (
{version}, etc), like the primary executable. - Fixed a configured
latestalias being replaced with the highest stable version.
- Added a new v2 schema format, enabled with
🐞 Fixes
- Fixed a regression where
proto outdatedwould report an installed version as the newest, when it satisfied the configured version's range, instead of the newest available version. - Fixed
proto installfailing to resolve version aliases defined in config ([tools.*.aliases]). - Fixed plugin downloads (from OCI registries, GitHub, and URLs) failing with "An internet connection is required" when the hosts used to detect an internet connection were unreachable or slow, but the plugin's source was reachable. The download is now always attempted, and the internet connection check is only used to explain a failed download, which now also includes the underlying error.
⚙️ Internal
- Updated
schema_toolto v0.19.0. - Updated Rust to v1.99.0.
- Updated dependencies.
Install proto_cli 0.63.0
Install prebuilt binaries via shell script
curl --proto '=https' --tlsv1.2 -LsSf https://github.com/moonrepo/proto/releases/download/v0.63.0/proto_cli-installer.sh | shInstall prebuilt binaries via powershell script
powershell -ExecutionPolicy Bypass -c "irm https://github.com/moonrepo/proto/releases/download/v0.63.0/proto_cli-installer.ps1 | iex"Download proto_cli 0.63.0
| File | Platform | Checksum |
|---|---|---|
| proto_cli-aarch64-apple-darwin.tar.xz | Apple Silicon macOS | checksum |
| proto_cli-x86_64-apple-darwin.tar.xz | Intel macOS | checksum |
| proto_cli-x86_64-pc-windows-msvc.zip | x64 Windows | checksum |
| proto_cli-aarch64-unknown-linux-gnu.tar.xz | ARM64 Linux | checksum |
| proto_cli-x86_64-unknown-linux-gnu.tar.xz | x64 Linux | checksum |
| proto_cli-aarch64-unknown-linux-musl.tar.xz | ARM64 MUSL Linux | checksum |
| proto_cli-x86_64-unknown-linux-musl.tar.xz | x64 MUSL Linux | checksum |