chore: version packages - #121
Open
github-actions[bot] wants to merge 1 commit into
Open
Conversation
github-actions
Bot
force-pushed
the
changeset-release/main
branch
16 times, most recently
from
August 1, 2026 04:18
8fc93e2 to
0e1cc29
Compare
github-actions
Bot
force-pushed
the
changeset-release/main
branch
from
August 1, 2026 04:56
0e1cc29 to
756c0e7
Compare
7 tasks
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR was opened by the Changesets release GitHub action. When you're ready to do a release, you can merge this and the packages will be published to npm automatically. If you're not ready to do a release yet, that's fine, whenever you add more changesets to main, this PR will be updated.
Releases
seamless-cli@0.11.0
Minor Changes
3ef3b68: Add
seamless apps, so a portal account can see what it owns without opening the dashboard.apps listprints name, plan, status, and instance URL;apps get <id>adds the console URL,region, owners, trial expiry, and whether a service token has been issued (masked, never the live
value). Both take
--jsonand both require a portal session.Applications are now read through the portal's
instanceUrl, which is derived from the serviceplan, rather than the stored
domaincolumn that goes stale when a trial is upgraded. Applicationsthat have not finished provisioning are listed instead of being silently dropped.
initisunchanged: it still reads
domainand still considers only applications that have one.apps listshows the infra id as the reference (falling back to the id before provisioning), andapps getaccepts an id, a name, or an infra id.4917717: Make
seamless inittemplate flags discoverable, predictable, and safe to get wrong.Add
seamless templates list [--json], which prints every starterinitcan scaffold with its id,kind, framework, selecting flags, and status. It reads the same registry
initdoes (soSEAMLESS_TEMPLATES_DIRandSEAMLESS_TEMPLATES_REFapply) and needs no login, so the availabletemplates no longer have to be looked up in the source.
Every template now answers to
--<id>as well as its shorter--<alias>, soseamless init --react-viteworks alongside--basic, and the api starters (--express,--fastify) have a flagfor the first time. The "unknown option" error lists both spellings and points at
seamless templates list.Template flags are also resolved before
initcreates a directory or asks whether to write into onethat is not empty. An unrecognized or conflicting flag now fails immediately instead of surfacing
only after the overwrite confirmation.
6e107cb:
initnow offers the managed path instead of assuming it. A portal session used to make managed thedefault silently, with
--localas the only escape and no way to learn you needed it until after thetemplate prompts. When your account has a provisioned application,
initasks whether to connect itor scaffold a local stack, with managed leading.
Whether managed is even possible is resolved before the first prompt. An account with nothing to
connect no longer answers two prompts and then fails: it says why and continues to a local scaffold.
That message now distinguishes "no applications yet" from "still provisioning", which the old
NoApplicationsErrorgot wrong for anyone mid-provision.A directory that already has files is no longer forced down the integrate path.
initasks whetherto connect it to a managed application or scaffold in place. Scaffolding into a non-empty directory
was previously impossible, so a stray
READMEor.gitwas enough to block a local project, andevery route that now reaches it confirms first: starter files overwrite anything with the same name,
and the confirmation defaults to no.
An unreachable control plane asks before scaffolding a local stack rather than degrading silently.
--localand--app <id>skip the new prompts, and--appwithout a session still fails ratherthan falling back.
490391d: Add a non-interactive
seamless init.--yes(-y) answers every question with the option theprompt marks as recommended, so a scaffold runs from CI, a Dockerfile, or a script with no terminal
attached:
Each question also gets its own flag, honored with or without
--yes:--web=<id|alias>and--api=<id|alias>choose the starters,--email=<address>sets the owner who becomes the admin,--auth=<docker|local>picks how the auth server runs, and--admin=<api|image|source|none>pickswhere the admin console is hosted. Unspecified values fall back to the recommended option, except
the owner email, which has no safe default and is taken from
--emailor the portal session.--yesdeliberately stops rather than guessing in three places. Choosing between a managedapplication and a local stack needs
--app <id>or--local. Scaffolding into a directory that isnot empty needs
--force, since starter files overwrite anything with the same name. Rotating amanaged application's existing service token needs
--forcetoo, because it breaks whatever isalready deployed on the old one.
cc13a6b: Connecting a project to a managed application now wires up its bundled database.
initreads theapplication's database and writes
DATABASE_URLintoapi/.envaspostgres://USER:PASSWORD@host:port/db?sslmode=require.The user and password stay as literal placeholders. The control plane only returns them for
?reveal=true, which this CLI never asks for, so a live database credential never reaches thedeveloper's disk or terminal: they copy those from the dashboard. Anything printed as a connection
string has its userinfo masked regardless.
An application whose database is still provisioning produces a warning rather than a failure, and the
database is read before the service token is rotated so a missing one is never reported against a
project whose old token has already been invalidated. Running
initinside an existing project addsDATABASE_URLonly when there is not one already, so a working connection string is never replacedby a placeholder.
This needs the templates release that teaches the express starter to read
DATABASE_URLandnegotiate TLS. Until
SEAMLESS_TEMPLATES_REFis bumped to it, the value is computed but the pinnedstarter does not declare the placeholder, so nothing is written.
15b487a:
initnow asks for your email and writes it to the scaffolded auth server asOWNER_EMAIL. The authserver grants the admin role at account creation to a signup matching that address, so the local flow
is
init,docker compose up, register. When you are signed in to the portal, the prompt defaults tothat account's email.
seamless bootstrap-adminis removed. It existed to mint the first admin invite, which the ownergrant now covers, and the scaffolded stack no longer enables the bootstrap route or carries a
bootstrap secret.
seamless verifykeeps its own bootstrap secret for the conformance stack and isunaffected.
The grant applies at signup only, so changing
OWNER_EMAILafter an account exists promotes nobody.The success output and the README both say so.
4ecf296: Add per-command help. Every command now answers
-h/--helpwith usage, flags, subcommands, andexamples scoped to that command (
seamless init -h,seamless verify --help), andseamless help <command>prints the same thing. The help text lives in one registry(
src/commands/helpTopics.ts) that both the fullseamless --helpoutput and the per-commandoutput render from, so a flag is documented once and appears in both.
The help check runs before a command parses its own arguments, so
seamless init -hprints helpinstead of treating
-has a project name. A--separator ends the check, so a command can stilltake a literal
-hvalue (seamless config set key -- -h).6deafb1:
seamless loginnow signs in to the Seamless portal instead of the active profile's instance, andno longer needs a profile to exist first. The portal session is stored beside the profile map in
config.jsonand is the only sessioninituses to connect a managed application, so a sessionfor a local or self-hosted instance no longer sends its token to the control plane.
Instance login moves to
seamless profile login [name], which signs in without changing the activeprofile.
seamless login --profile <name>keeps working for one more minor version and prints apointer to the new command.
whoamiandlogoutdefault to the portal session and take--profile <name>to target an instance.Set
SEAMLESS_PORTAL_AUTH_URLto point the portal login at a different auth host.51d9a9e: No command renders a prompt when stdin is not a terminal.
seamless initgot this in 0.11.0; it nowcovers every command that prompts (
login,profile add,users delete,users prepare-device-replacement,sessions revoke,org members remove,config apply, andconfig oauth-providers remove). Each one stops naming the flag that answers the question, so a CIstep or a scripted run fails immediately instead of hanging until its job times out.
The confirmations that guard a destructive action now take
--force, matching whatinitalreadymeans by it:
--yesand-yare accepted aliases everywhere, soseamless config oauth-providers remove --yeskeeps working.
--forcedoes not override--dry-run:config apply --dry-run --forcestillchanges nothing, and cancelling a confirmation still reads as declining rather than as an error.
f08c21a: Scaffolding now requires
init. An unrecognized command reports itself and exits instead of beingtreated as a project name, so
seamless verfyno longer silently creates a directory calledverfyand drops into the interactive scaffold. The error namesseamless init <name>for anyonewho was using the old shortcut.
Ctrl-C is handled everywhere. Clack answers an interrupted prompt with a symbol, which several
prompts cast straight to a string; that surfaced as a
TypeErrormid-scaffold, or as "Selectedtemplate Symbol(...) is not in the registry". Every prompt in init, the OAuth setup, the managed
application picker, and
bootstrap-adminnow cancels cleanly and exits 130.initno longer leaves a project directory behind. Any failure or cancellation after the directoryis created removes it, including a Ctrl-C during a download or a git clone, so a retry is not
blocked by "Directory already exists". Only a directory the command itself created is ever removed,
never an existing one and never the working directory.
Declining the service token rotation prompt, or cancelling the application picker, now cancels the
whole command rather than returning quietly part-way through.
Patch Changes
bf857b1: Update the seamless auth api image to v0.5.0.
e2f53b3:
seamless initno longer hangs when it has no terminal to prompt on. Run on a pipe, it used torender a prompt nobody could answer and wait forever, so a CI step failed only when its job timed
out. It now stops on the first unanswered question and names the flag that answers it:
A run whose answers all come from flags is unaffected and works the same on a pipe as on a
terminal. A terminal too narrow to render a prompt (a pty allocated without a size reports one
column, which used to print one character per line) now warns instead of just looking broken.
f725752: Generated compose files now publish every port on
127.0.0.1instead of all interfaces. A scaffoldedstack was reachable from any machine on the same network, which mattered most for the auth server:
it is configured with
ALLOW_UNCREDENTIALED_DELIVERY_SECRETS=truesoseamless login --localcanread OTP codes from the response, and that opt-in is honored before any service-token check. Anyone
on the LAN could request a code for any user of the stack and read it. Postgres was exposed on the
same terms, with the fixed credentials the compose file ships.
Local development is unchanged: the browser, the CLI, and inter-container traffic all still work.
ffe4331: Update the conformance harness for the removal of the admin bootstrap invite flow in
seamless-auth-api. The verify stack now sets
OWNER_EMAILinstead ofSEAMLESS_BOOTSTRAP_ENABLED/SEAMLESS_BOOTSTRAP_SECRET, and the first-admin spec registers theowner address and asserts the admin role is granted at signup.
2d898e2: Fix conformance project routing when the checkout path contains a directory named with an
api/segment. Playwright applies a
testMatchregex to the absolute file path, so theapiproject'spattern also claimed every adapter and react spec, running browser tests in a project with no
baseURL. Each project now scopes itself withtestDirinstead.c2e4e1b: Scaffold from seamless-templates v0.5.0, which teaches the express starter to read
DATABASE_URLandnegotiate TLS when the connection string carries
sslmode=require. This is what turns on the managedbundled database wiring: the CLI already computed the connection string, but the pinned v0.4.0
starter did not declare the placeholder, so nothing was written.