Skip to content

v0.18.1

This is the first published 0.18 release. It packages the output-contract, human-readable workflow governance, authentication, and release-integrity work validated in the v0.18.0 release commit.

  • Human-readable text remains the default output.

  • --output json emits the compact, versioned ayx.output.v1 envelope. Compact list responses default to 20 projected rows and report total_count, shown_count, truncated, and next_page_token.

  • --output json-full emits the complete recursively redacted envelope for diagnostics, exports, compatibility migration, and raw-field inspection.

  • --output-limit N changes the compact-list cap; 0 means unlimited.

  • Put output selection after the command path:

    ayx one flows list --output json
    ayx one flows list --output json-full

This is a breaking machine-interface change from 0.17.0: automations that consumed the former lossless --output json shape should use json-full while migrating to the compact contract.

Every One leaf command now has an output descriptor so compact responses have stable command identity, resource kind, and intended fields. The default ayx one workflows list view now shows:

ID NAME OWNER LAST UPDATED VERSION

Workflow governance data is assembled from the workflow list, workflow-assets metadata, and the people directory. Owner names are resolved where available; the full response retains raw fields and owner_id. Build-oriented fields such as checksums and compiler versions remain available in json-full but no longer crowd the default human view.

The CLI intentionally keeps /v4 as the canonical gateway for resources that belong there. The richer workflow-asset operations remain on the separate /svc-workflow service, and the endpoint matrix documents that boundary.

  • OAuth2.0 API access/refresh credentials are the recommended authentication method for unattended CLI, CI, and agent use. Import the refresh token once with --refresh-token-env NAME or --refresh-token-stdin; secure persistence keeps the credential pair in the operating-system keyring and automatically renews short-lived access tokens.
  • OAuth credentials are bound to the selected workspace and do not silently fall back to email OTP. Email OTP remains the default interactive method.
  • Refresh-token rotation is persisted when the credential is keyring-backed. Because provider exchange and local keyring storage cannot be one atomic transaction, the CLI fails closed after a local persistence error and tells the operator to re-import a fresh provider-issued pair rather than retrying blindly.
  • Wizard email-OTP authentication is the default for ayx one login.
  • Legacy remains available only as an explicit rollback lane through --auth-flow legacy or AYX_AUTH_ROLLOUT=legacy.
  • Workspace-password retry and saved-password persistence support the same constrained-environment path used by Legacy.
  • The keyring-unavailable onboarding test seam is scoped to the current test thread, eliminating process-global environment-variable races under parallel execution.

The GitHub release workflow builds Linux, Windows, and macOS packages, runs formatting, clippy, and the locked workspace test suite, and publishes:

  • platform archives for Linux, Windows, Intel macOS, and Apple Silicon macOS;
  • SHA256 checksums;
  • CycloneDX SBOMs;
  • Sigstore bundles for release artifacts; and
  • GitHub build-provenance attestations when supported by the repository.

macOS signing and notarization remain conditional on the repository’s signing secrets. The workflow reports that posture in the build summary.

The existing v0.17.0 binary cannot discover this release until the GitHub release is published. After publication, run:

ayx update
ayx --version

The expected version is 0.18.1.