This release includes 6 breaking changes for platform teams planning a safe upgrade.
✓ No known CVEs patched in this version
Topics
+2 more
Affected surfaces
Summary
AI summaryRemoved framework adapters, secret providers, plugin loader, multiple subcommands, async validation API, and several flags.
Full changelog
Major Changes
-
f1b3685: Trim surface to a focused .env schema validator.
Removed: framework adapters (express/fastify/nextjs/nestjs/vite), secret providers (Vault/AWS SM/Doppler/1Password), the plugin loader, and the
watch,onboard,hook,migrate,export,fixsubcommands. Also removedvalidateAsyncand the--check-live/--resolve-secrets/--concurrencyflags onvalidate.Kept:
validate,init,diff,generate-example,sync,detect,secrets,codegen. The validator registry remains for the 11 built-in types but no longer supports runtime-loaded plugins or secret providers.
Patch Changes
-
4360845: Post-trim cleanup: sync READMEs with the actual command surface, drop a dead
chokidardep, and fix stale's summarypassedcount.- READMEs rewritten for the 5 trimmed tools so they match what the CLI actually ships. Removed references to commands and flags that no longer exist (
vow fix|hook|audit|diff|policy,vow --offline|--api-key|ANTHROPIC_API_KEY;stale fix|watch,stale --deep,STALE_AI_KEY, SARIF format;aware watch|validate|doctor|add,--exit-code;envalid onboard|hook|export|watch|fix|migrate, plugins, secret providers, framework adapters). Documented the flags each command actually accepts today (e.g.aware diff --check|--json|--target|--quiet,vow check --ignore). - aware: removed unused
chokidardependency (carried over from the droppedaware watchcommand —grep chokidar src/had zero hits). - stale: fixed
summary.passedgoing negative on reports with many issues.buildSummarywas computingtotalChecks - errors - warnings - infos, wheretotalCheckswas per (doc × analyzer) but issues are per finding, so a heavy report trivially overflowed it.totalChecksnow counts analyzers run, andpassedcounts analyzers whose category produced zero issues. Per-categorypassedis now1when that analyzer ran and produced no issues,0otherwise. Test fixture + snapshot updated for the post-trim DriftCategory set. - vow: deleted
docs/workflows/— the three example workflow YAMLs and their README referencedvow check --offline,vow diff,vow policy compile,ANTHROPIC_API_KEY, and the archivedwhenlabs-org/vow@v1composite action, none of which exist anymore.
- READMEs rewritten for the 5 trimmed tools so they match what the CLI actually ships. Removed references to commands and flags that no longer exist (
Breaking Changes
- Removed framework adapters: express, fastify, nextjs, nestjs, vite
- Removed secret providers: Vault, AWS SM, Doppler, 1Password
- Removed plugin loader and runtime-loaded plugins support
- Removed subcommands: watch, onboard, hook, migrate, export, fix (across tools)
- Removed `validateAsync` API
- Removed flags: --check-live, --resolve-secrets, --concurrency on validate
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About WhenLabs-org/when
Developer toolkit: auto-detect stack for AI context files, catch port conflicts, validate .env schemas, spot docs drift, audit dependency licenses, and time coding tasks — 7 MCP tools, one install.
Related context
Related tools
Beta — feedback welcome: [email protected]