Skip to content

StartOS

vstart-sdk/v2.0.5 Bugfix

This release fixes issues for SREs watching stability and regressions.

✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →

✓ No known CVEs patched in this version

Topics

bitcoin bitcoin-node lightning-node p2p personal-server privacy-enhancing-technologies
+1 more
self-hosted

Affected surfaces

breaking_upgrade

Summary

AI summary

Fixed ExVer range operations to correctly compare downstream revisions, correcting manifest migration ranges.

Changes in this release

Bugfix Medium

ExVer range operations no longer ignore the downstream revision.

ExVer range operations no longer ignore the downstream revision.

Source: llm_adapter@2026-07-14

Confidence: high

Full changelog

What's Changed

Fixed

  • ExVer range operations no longer ignore the downstream revision. compareVersionRangePoints and adjacentVersionRangePoints compared the upstream version twice instead of comparing the downstream on the second pass, so two points that shared an upstream but differed in downstream (1.0.0:3 vs 1.0.0:15) collapsed into a single point. Everything built on the truth tables inherited the error — normalize() silently dropped the lower of the two, and intersects() / satisfiable() could answer on a merged point. =1.0.0:0 || =1.0.0:1 normalized to =1.0.0:1.

    The visible consequence was in packed manifests: canMigrateFrom / canMigrateTo are derived from the version graph and normalized, so any package declaring an other version sharing current's upstream advertised a range narrower than the truth (mempool at 3.3.1:15 with other: [3.3.1:3] shipped canMigrateFrom: <=3.3.1:3 rather than <=3.3.1:15). No upgrade actually broke — StartOS resolves migrations through the version graph rather than gating on this field, and the registry index does not yet populate sourceVersion from it — but the manifests were wrong and would have become load-bearing the moment either changed. The Rust implementation derives its point ordering and was never affected.

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track StartOS

Get notified when new releases ship.

Sign up free

About StartOS

Browser-based, graphical Operating System (OS) that makes running a personal server as easy as running a personal computer.

All releases →

Related context

Earlier breaking changes

  • vstart-sdk/v2.0.4 'setupMain' callback now accepts any DaemonBuildable rather than requiring a Daemons.
  • vstart-sdk/v2.0.4 `Daemons.dynamic` now takes `effects` and returns a `DaemonReconciler` instead of replacing `main`.
  • v0.4.0-beta.9 Previous backups incompatible with v0.4.0; create fresh backup after updating.

Beta — feedback welcome: [email protected]