Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
95 commits
Select commit Hold shift + click to select a range
6c533e7
fix(upgrade): compare prerelease versions per SemVer
riglar Jun 24, 2026
d543981
fix: suppress refresh countdown in quiet mode
riglar Jun 24, 2026
f77841f
Merge pull request #34 from devicecloud-dev/fix/upgrade-prerelease-co…
riglar Jun 24, 2026
10eade4
Merge pull request #35 from devicecloud-dev/fix/quiet-suppress-refres…
riglar Jun 24, 2026
ea62f72
feat(cloud): warn on deprecated iOS 16 (removal 2026-08-23)
finalerock44 Jun 24, 2026
d794695
Merge pull request #37 from devicecloud-dev/chore/deprecate-ios-16
finalerock44 Jun 24, 2026
62c7672
feat(cloud): drop legacy Maestro removed-versions block; soft-warn on…
finalerock44 Jun 24, 2026
ee995e7
Merge pull request #38 from devicecloud-dev/chore/maestro-deprecation
finalerock44 Jun 24, 2026
ec16bcc
fix(installer): make beta opt-in, add stable/beta channels
riglar Jun 24, 2026
77cf138
chore: add open-source contribution governance
finalerock44 Jun 24, 2026
88c3532
Merge pull request #39 from devicecloud-dev/fix/installer-beta-opt-in
riglar Jun 24, 2026
129f802
chore: drop CODEOWNERS
finalerock44 Jun 24, 2026
ebac7e2
Merge pull request #40 from devicecloud-dev/chore/oss-governance
finalerock44 Jun 24, 2026
dc87257
fix(ci): keep dependabot and fork PRs green (#46)
finalerock44 Jun 24, 2026
07074d3
ci: power CLA via the shared automation GitHub App (#49)
finalerock44 Jun 24, 2026
d3b0acc
docs: set legal entity to Moropo Ltd t/a DeviceCloud (#50)
finalerock44 Jun 24, 2026
3fe1f21
ci: bump the actions group across 1 directory with 6 updates (#47)
dependabot[bot] Jun 24, 2026
d780e55
fix: v5 release blockers — installer, binary version, repeated flags,…
finalerock44 Jun 24, 2026
7fd253a
chore(dev): release 5.0.0-beta.2 (#36)
github-actions[bot] Jun 24, 2026
bd60298
fix: stop CLA locking release PRs (breaks release pipeline) (#52)
finalerock44 Jun 24, 2026
a02584f
feat(live): add a beta warning to `dcd live start` (#54)
finalerock44 Jun 25, 2026
3eedde3
chore(dev): release 5.0.0-beta.3 (#53)
dcd-cli-release-please[bot] Jun 25, 2026
b72b83a
chore: remove dead Maestro 1.39.5/1.41.0 deprecation warning (#57)
finalerock44 Jun 26, 2026
10dfdbf
feat: render DB-driven notices and forward CLI/CI identity (#58)
finalerock44 Jun 26, 2026
58c3b1b
chore(dev): release 5.0.0-beta.4 (#59)
dcd-cli-release-please[bot] Jun 26, 2026
c99f040
fix: notices render polish (#60)
finalerock44 Jun 26, 2026
5adec18
chore: release 5.0.1-beta.1 (#62)
finalerock44 Jun 26, 2026
ee23356
chore(dev): release 5.0.1-beta.1 (#61)
dcd-cli-release-please[bot] Jun 26, 2026
1d331b4
refactor: route notice rendering through ui (add ui.deprecation) (#66)
finalerock44 Jun 29, 2026
851f051
chore: bump eslint-plugin-unicorn from 68.0.0 to 69.0.0 (#70)
dependabot[bot] Jul 10, 2026
cfd9fe2
deps: bump the minor-and-patch group across 1 directory with 9 update…
dependabot[bot] Jul 10, 2026
7fd7748
fix: recover cleanly when the stored session is dead (#72)
riglar Jul 10, 2026
b78a1dc
feat(cloud): device matrix via repeated --ios-config/--android-config…
finalerock44 Jul 13, 2026
bc9c61f
chore: release 5.2.0-beta.1 (#76)
finalerock44 Jul 13, 2026
4ef0292
chore(dev): release 5.2.0-beta.1 (#67)
dcd-cli-release-please[bot] Jul 13, 2026
fc3ea3f
refactor(cloud): rename --ios-config/--android-config to --ios-device…
finalerock44 Jul 13, 2026
8b6fde1
docs: correct the release bump table — a breaking `!` bumps the MAJOR…
finalerock44 Jul 13, 2026
db71189
chore(dev): release 5.2.0-beta.2 (#78)
dcd-cli-release-please[bot] Jul 13, 2026
5560158
fix(cloud): refuse a device matrix on an API that cannot honour it (#80)
finalerock44 Jul 13, 2026
1e7a1eb
chore(dev): release 5.2.0-beta.3 (#81)
dcd-cli-release-please[bot] Jul 13, 2026
cc5ee4d
fix(deps): resolve pnpm audit failures in transitive dependencies (#89)
riglar Jul 23, 2026
cbac88b
chore: bump eslint-plugin-unicorn from 69.0.0 to 71.1.0 (#85)
dependabot[bot] Jul 23, 2026
5730af7
ci: bump actions/setup-node from 6 to 7 in the actions group (#86)
dependabot[bot] Jul 23, 2026
f333be9
deps: bump the minor-and-patch group across 1 directory with 7 update…
dependabot[bot] Jul 23, 2026
a4f11ff
deps: patch js-yaml and brace-expansion DoS advisories (#95)
riglar Jul 27, 2026
1b29d2d
deps: bump chalk from 5.6.2 to 6.0.0 (#98)
dependabot[bot] Jul 30, 2026
7d85979
chore: bump eslint-plugin-unicorn from 71.1.0 to 72.0.0 (#97)
dependabot[bot] Jul 30, 2026
f6fcfaf
feat(artifacts): prefer server-assembled bundle delivery for download…
riglar Jul 30, 2026
47b9d90
deps: bump the minor-and-patch group across 1 directory with 5 update…
dependabot[bot] Jul 30, 2026
a34d9d4
feat: client-side envelope encryption of binaries, flow zips & env va…
riglar Jul 30, 2026
6e244a9
feat(upload): dedup encrypted binaries on the plaintext hash (#101)
riglar Aug 3, 2026
3888fc5
refactor(cloud): remove mitmproxy flags (#102)
riglar Aug 3, 2026
f7934b0
fix(deps): resolve three new transitive security advisories (#106)
finalerock44 Aug 5, 2026
2fd4bdf
chore: regenerate schema types from the current API swagger (#105)
finalerock44 Aug 5, 2026
3d24435
feat(device): add Android API level 37 (Android 17) (#107)
finalerock44 Aug 6, 2026
4af1ddb
ci: bump pnpm/action-setup from 6 to 6.0.9 in the actions group (#103)
dependabot[bot] Aug 6, 2026
3038ed8
chore(dev): release 5.2.0-beta.4 (#91)
dcd-cli-release-please[bot] Aug 7, 2026
13d01ee
fix(cloud): exclude config-shaped files from flow discovery (#114)
finalerock44 Aug 10, 2026
0c70928
chore: bump eslint-plugin-unicorn from 72.0.0 to 73.0.0 (#113)
dependabot[bot] Aug 10, 2026
2223dd4
deps: bump the minor-and-patch group with 5 updates (#112)
dependabot[bot] Aug 10, 2026
96147df
ci: bump pnpm/action-setup from 6.0.9 to 6.0.10 in the actions group …
dependabot[bot] Aug 10, 2026
6858220
chore: pin the next dev beta to 5.3.1-beta.1 (#116)
finalerock44 Aug 10, 2026
57711c6
chore(dev): release 5.3.1-beta.1 (#115)
dcd-cli-release-please[bot] Aug 10, 2026
1973a42
fix(cloud): reject malformed executionOrder instead of silently runni…
finalerock44 Aug 13, 2026
43e7324
chore(dev): release 5.3.1-beta.2 (#118)
dcd-cli-release-please[bot] Aug 13, 2026
1c07fc1
deps: bump the minor-and-patch group with 6 updates (#121)
dependabot[bot] Aug 18, 2026
2b89f3a
ci: stop reaching into the private dcd repo for the mock-api (#124)
finalerock44 Aug 18, 2026
fcfa524
feat!: remove iOS 16 (#126)
finalerock44 Aug 24, 2026
a60611d
chore: release the iOS 16 removal as 5.4.0, not 6.0.0 (#127)
finalerock44 Aug 24, 2026
0aaa652
chore(dev): release 5.4.0-beta.0 (#122)
dcd-cli-release-please[bot] Aug 24, 2026
1333960
feat(device): add iOS 27 and the iPhone 17 family (#131)
finalerock44 Aug 27, 2026
3222dda
fix(ci): point the CLA check at our node24 fork (#135)
finalerock44 Sep 2, 2026
38f6dfa
feat(device): drop the iPhone 17 family (#134)
finalerock44 Sep 2, 2026
b903241
docs(ci): the CLA action fork must stay public (#136)
finalerock44 Sep 2, 2026
0d2234a
deps: bump the minor-and-patch group across 1 directory with 4 update…
dependabot[bot] Sep 2, 2026
fc43dc6
chore: release 5.4.1-beta.1 (#137)
finalerock44 Sep 2, 2026
7ccb0c9
fix(deps): refresh audit overrides to the patched versions (#141)
finalerock44 Sep 10, 2026
df39281
chore: bump mocha from 11.8.0 to 12.0.0 (#140)
dependabot[bot] Sep 10, 2026
7daa42b
chore: bump eslint-plugin-unicorn from 73.0.0 to 74.0.0 (#139)
dependabot[bot] Sep 10, 2026
9b5f751
fix(deps): adopt bplist-parser 0.5 named exports (#143)
finalerock44 Sep 10, 2026
9a4ad49
deps: bump the minor-and-patch group across 1 directory with 5 update…
dependabot[bot] Sep 10, 2026
97cad3d
chore(dev): release 5.4.1-beta.1 (#132)
dcd-cli-release-please[bot] Sep 10, 2026
9d9e413
feat(notices): expose platform, device and Maestro version to notice …
finalerock44 Sep 10, 2026
190a0e9
chore(dev): release 5.5.0-beta.1 (#148)
dcd-cli-release-please[bot] Sep 10, 2026
dac5d1e
feat: add Pixel 8, Pixel 10 family and Pixel 11 device slugs (#151)
finalerock44 Sep 14, 2026
075a0be
chore(dev): release 5.5.0-beta.2 (#152)
dcd-cli-release-please[bot] Sep 14, 2026
a2888fd
feat(cloud): add --render-engine for the emulator software renderer (…
finalerock44 Sep 14, 2026
b974a07
chore(dev): release 5.5.0-beta.3 (#154)
dcd-cli-release-please[bot] Sep 14, 2026
bada03b
ci: bump pnpm/action-setup from 6.0.10 to 6.1.0 in the actions group …
dependabot[bot] Sep 14, 2026
004b478
fix: register tsx's ESM loader only so mocha 12.0.1 can load find-up@…
finalerock44 Sep 14, 2026
1e6e2c0
deps: bump the minor-and-patch group with 7 updates (#156)
dependabot[bot] Sep 14, 2026
9c37f81
chore(dev): release 5.5.0-beta.4 (#158)
dcd-cli-release-please[bot] Sep 15, 2026
934cc28
chore: give the beta and stable release lines separate changelogs (#161)
finalerock44 Sep 15, 2026
c543d59
chore: reconcile production into dev for the 5.5.0 promotion
finalerock44 Sep 15, 2026
ea27543
chore: pin the 5.5.0 promotion
finalerock44 Sep 15, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion .github/workflows/cli-ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -63,7 +63,7 @@ jobs:
path: cli

- name: Setup pnpm
uses: pnpm/action-setup@v6.0.10
uses: pnpm/action-setup@v6.1.0
with:
version: 10
run_install: false
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/npm-publish.yml
Original file line number Diff line number Diff line change
Expand Up @@ -27,7 +27,7 @@ jobs:
- uses: actions/checkout@v7
# Setup .npmrc file to publish to npm
- name: Setup pnpm
uses: pnpm/action-setup@v6.0.10
uses: pnpm/action-setup@v6.1.0
with:
run_install: false

Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/release-binaries.yml
Original file line number Diff line number Diff line change
Expand Up @@ -27,7 +27,7 @@ jobs:
- uses: actions/checkout@v7

- name: Setup pnpm
uses: pnpm/action-setup@v6.0.10
uses: pnpm/action-setup@v6.1.0
with:
run_install: false

Expand Down
2 changes: 1 addition & 1 deletion .mocharc.json
Original file line number Diff line number Diff line change
@@ -1,5 +1,5 @@
{
"node-option": ["import=tsx"],
"node-option": ["import=tsx/esm"],
"extensions": ["ts"],
"watch-extensions": ["ts"],
"recursive": true,
Expand Down
2 changes: 1 addition & 1 deletion .release-please-manifest-beta.json
Original file line number Diff line number Diff line change
@@ -1,3 +1,3 @@
{
".": "5.0.0-beta.3"
".": "5.5.0-beta.4"
}
261 changes: 261 additions & 0 deletions CHANGELOG-beta.md

Large diffs are not rendered by default.

8 changes: 5 additions & 3 deletions CLAUDE.md
Original file line number Diff line number Diff line change
Expand Up @@ -59,7 +59,7 @@ Full guide in `CONTRIBUTING.md`; the operationally important parts (the ones tha
- PRs are **squash-merged**, so the **PR title becomes the commit** and must be a [Conventional Commit](https://www.conventionalcommits.org). The title — not the branch commits — is what release-please reads to compute the next version, so it matters even though individual commits are squashed away. A `PR Title` CI check enforces it.
- Type → bump: `feat` **minor**; `fix`/`perf`/`deps`/`revert`/`refactor` **patch**; `docs`/`chore`/`test`/`ci`/`build`/`style` are hidden and bump nothing. Allowed scopes are free-form.
- ⚠️ **A `!` (or `BREAKING CHANGE:` footer) bumps the MAJOR — do not use it casually.** The configs set `bump-minor-pre-major: true`, but that only applies **below 1.0.0**; we are on 5.x, so it is inert and a breaking marker means exactly what semver says. A `refactor(cloud)!:` PR title once produced a `6.0.0-beta.1` release PR for what was only a flag rename in an unconsumed beta. Because PRs are squash-merged, **the PR title IS the commit** — the `!` lands even if no branch commit carried it.
- **Never hand-edit `package.json` version, `CHANGELOG.md`, or the `.release-please-manifest*.json` files** — release-please owns all of them. `src/types/generated/schema.types.ts` is likewise generated (openapi-typescript).
- **Never hand-edit `package.json` version, `CHANGELOG.md` / `CHANGELOG-beta.md`, or the `.release-please-manifest*.json` files** — release-please owns all of them. `src/types/generated/schema.types.ts` is likewise generated (openapi-typescript).
- A first-time contributor must sign the CLA (the CLA Assistant bot comments on the first PR); the CLA check must be green to merge.
- **CI (`.github/workflows/cli-ci.yml`) runs the same steps on every PR** — fork, Dependabot and same-repo alike, with no privileged path: gitleaks secret scan, `pnpm lint`, `pnpm typecheck`, `pnpm test:unit`, `pnpm build`, `pnpm audit --audit-level moderate`. **`test/integration/*` is not run by CI at all** (see the Commands section: this public repo no longer reaches into the private `devicecloud-dev/dcd` repo for a mock API), so a green PR says nothing about the integration suite — run it locally with `MOCK_API_DIR` set if a change touches the API surface. gitleaks also runs as a pre-commit hook (allowlist in `.gitleaks.toml`); without the binary installed the hook self-skips and CI is the backstop.

Expand All @@ -72,8 +72,10 @@ Fully automated by [release-please](https://github.com/googleapis/release-please
| `dev` | **beta** (prerelease) | `release-please-config-beta.json` / `.release-please-manifest-beta.json` | `X.Y.Z-beta.N` | `beta` |
| `production` | **stable** | `release-please-config.json` / `.release-please-manifest.json` | `X.Y.Z` | `latest` |

The two manifests track their versions **independently** (e.g. beta `5.0.0-beta.3` while stable is `5.0.0`). On each qualifying push release-please opens/updates a **Release PR** on that branch; merging the Release PR creates the git tag + GitHub Release, and the same workflow run **chains** (as `needs:` jobs, because a `GITHUB_TOKEN`-created release won't fire `release: published`) into:
The two tracks also keep **separate changelog files** — beta writes `CHANGELOG-beta.md`, stable writes `CHANGELOG.md` — so a promotion never conflicts on them. The two manifests track their versions **independently** (e.g. beta `5.0.0-beta.3` while stable is `5.0.0`). On each qualifying push release-please opens/updates a **Release PR** on that branch; merging the Release PR creates the git tag + GitHub Release, and the same workflow run **chains** (as `needs:` jobs, because a `GITHUB_TOKEN`-created release won't fire `release: published`) into:
1. `npm-publish.yml` — publishes to npm. Guards: a prod publish may only run from `production` and its version must **not** carry `-beta`; a beta version **must** carry `-beta`.
2. `release-binaries.yml` — bun-compiles the standalone binaries (`node scripts/build-binaries.mjs`) and uploads them to the GitHub Release. `get.devicecloud.dev` serves them by reading the GitHub Releases API at runtime, so there's no separate manifest to deploy.

**Promoting beta → stable** is a maintainer merging `dev` into `production` via a PR (also gated by `cli-ci.yml`) — that push to `production` is what triggers the stable Release PR. The current `release/promote-v5` branch is exactly such a promotion. Releases prefer an automation GitHub App token (`BOT_APP_ID`) so the Release PR triggers the CI / PR-title / CLA checks that branch protection requires, falling back to `GITHUB_TOKEN` until the App secrets are configured.
**Promoting beta → stable** is a maintainer opening a PR from `dev` into `production` and merging it with a **merge commit** — that push to `production` is what triggers the stable Release PR. Use a merge commit, never squash or rebase: the merge is what makes `production` a descendant of `dev`, so the two branches stay reconcilable and the next promotion's diff is only the commits since the last one. A squash or rebase promotion rewrites the commits, leaves the histories permanently divergent, and forces the next promotion to be reconstructed by hand — that is exactly what the pre-5.5.0 promotions did.

The only conflict a promotion should raise is the `version` line in `package.json` (beta on one side, stable on the other). **Take `dev`'s** — release-please overwrites it from `.release-please-manifest.json` when the Release PR lands. Releases prefer an automation GitHub App token (`BOT_APP_ID`) so the Release PR triggers the CI / PR-title / CLA checks that branch protection requires, falling back to `GITHUB_TOKEN` until the App secrets are configured.
3 changes: 2 additions & 1 deletion CONTRIBUTING.md
Original file line number Diff line number Diff line change
Expand Up @@ -143,7 +143,8 @@ Releases are automated by [release-please](https://github.com/googleapis/release

- Merges to `dev` accumulate into a **beta** release (published to npm under the
`beta` tag).
- Maintainers promote `dev` → `production` for **stable** releases (npm `latest`).
- Maintainers promote `dev` → `production` for **stable** releases (npm `latest`),
always with a **merge commit** so the two branches stay in sync.

release-please reads the Conventional Commit titles of merged PRs to compute the
next version and generate the changelog — which is exactly why the PR title
Expand Down
Loading
Loading