Skip to content

StartOS

vstart-sdk/v2.0.8 Feature

This release adds 1 notable feature for engineering teams evaluating rollout.

✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →

✓ No known CVEs patched in this version

Topics

bitcoin bitcoin-node lightning-node p2p personal-server privacy-enhancing-technologies
+1 more
self-hosted

Summary

AI summary

Added sdk.host.getBridgeAddress to resolve container dependency addresses.

Full changelog

What's Changed

Added

  • sdk.host.getBridgeAddress resolves the address another container reaches a
    dependency at, replacing a helper every package was copy-pasting.
    Packages
    resolved a dependency by reading bindings[<internalPort>].net.assignedPort
    and prefixing getOsIp. That field is raw metadata: only one of
    assignedPort / assignedSslPort is ever populated, and which one is a
    property of how the dependency bound the port — a binding with addSsl and
    secure.ssl frees assignedPort entirely and carries only
    assignedSslPort, a passthrough binding is the reverse. So every caller was
    implicitly asserting how its dependency terminates TLS, and resolved null
    the day that changed, which is exactly what happened to LND's dependents when
    LND moved its REST interface behind the OS reverse proxy. The new helper
    resolves the binding's own derived address instead, which is correct under
    either arrangement, and returns a Watchable so callers get the same
    const/once/watch/onChange/waitFor strategies as sdk.host.get.
    Because it keys off the binding rather than an exported interface, it also
    resolves bridge-only ports such as tor's SOCKS proxy. ssl narrows a binding
    that publishes both a plaintext and a TLS address (protocol: 'http'/'ws',
    or secure: null with addSsl — bitcoind's RPC is reachable at both);
    fallbackPort keeps the value non-null while the dependency is absent, for a
    flag that must be passed unconditionally against an allocator-guaranteed port

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track StartOS

Get notified when new releases ship.

Sign up free

About StartOS

Browser-based, graphical Operating System (OS) that makes running a personal server as easy as running a personal computer.

All releases →

Related context

Earlier breaking changes

  • vstart-sdk/v2.0.4 'setupMain' callback now accepts any DaemonBuildable rather than requiring a Daemons.
  • vstart-sdk/v2.0.4 `Daemons.dynamic` now takes `effects` and returns a `DaemonReconciler` instead of replacing `main`.
  • v0.4.0-beta.9 Previous backups incompatible with v0.4.0; create fresh backup after updating.

Beta — feedback welcome: [email protected]