v0.58.0

Latest
View on GitHub

Package uploads are the focus of this release. You can now publish Composer packages from zip archives, without a Git repository, both from the web app and from CI.

New Features

  • Package uploads (#132): Owners and admins can create a package by uploading a zip whose composer.json is at the root or in a single top-level folder. New versions can be uploaded from the package page. Released versions are immutable, while dev versions such as dev-main can be replaced. The package page shows each version's README, size and checksum.
  • Publishing from CI (#132): Organization tokens can now be created with Allow publishing packages. Those tokens can upload new versions of existing uploaded packages through POST /{organization}/api/packages/upload. Existing tokens stay read-only, and php artisan token:create --publish creates a publishing token from the command line.
  • Upload activity: The activity feed now shows each uploaded version, including which user or token uploaded it.

Improvements

  • Upload limits: The maximum archive size (ARTIFACT_MAX_SIZE, default 64 MB) and the per-token upload rate limit (ARTIFACT_UPLOAD_RATE_LIMIT, default 30 per minute) are now configurable. The bundled nginx config accepts request bodies up to 64 MB.
  • Separate package sources: Repository and mirror syncs no longer take over an uploaded package with the same name, and archive cleanup never removes an uploaded package's archives.

Fixes

  • Fixed package names from synced repositories not being validated as plain vendor/package names. Such a name could place archives outside the package's storage folder.
View on GitHub

Pricore can now serve several Composer packages from a single Git repository. You point it at the directories that hold them, and it builds a dist archive for each package.

New Features

  • Monorepo support (#176): Point Pricore at the directories where the composer.json files of a repository live. You can set these package paths when connecting the repository, or later from its Edit page. A path can be a directory (packages/billing), a wildcard (packages/*), or . for the root. Every tag yields a version for each package present at that tag. Subdirectory packages install from dist archives, so keep dist mirroring enabled. Changing the paths removes packages that are no longer selected and starts a full sync.
  • Forced sync from the CLI: php artisan sync:repository --force revisits every tag and branch, even when its commit has not changed.

Improvements

  • Removed packages: When a package's composer.json disappears from a branch or tag, that version is removed on the next sync. This also applies to single-package repositories. Other versions of the package are kept.
  • Invalid composer.json: A composer.json that fails to parse now skips only that package, and the package keeps its existing version. Other packages at the same tag or branch still sync.
  • Package name conflicts: A repository can no longer attach versions to a package name that already belongs to another repository or mirror in the organization. The sync now skips that package and logs a warning.
  • README links: README links and images in subdirectory packages resolve against the package's own directory. Links starting with / resolve against the repository root.

Fixes

  • Fixed a branch or tag without a composer.json on GitHub or GitLab failing the sync job instead of being skipped.
  • Fixed Composer continuing to offer a deleted version, because the package metadata still reported an unchanged Last-Modified date.
  • Fixed a Git clone reused between syncs serving outdated branches and missing new tags.
View on GitHub

Improvements

  • Dashboard: Repository tiles on the organization overview are now ordered by most recent sync instead of alphabetically, so the repositories your team is actively working on come first. Failing and pending repositories are still listed at the top, and repositories that have never synced appear last.
View on GitHub

This release reworks Pricore's interface around one idea: the screens you open most should show what needs your attention. The organization dashboard used to open on totals that rarely change (package, repository and member counts). It now leads with problems: failing syncs, pending repositories and known vulnerabilities. Small text that was hard to read across the app has also been enlarged.

image

New Features

  • Health board dashboard: The organization overview now opens with the state of your registry. A summary shows how many repositories are healthy, failing or pending. Each repository gets a tile with its sync status and a strip of its last 10 syncs, with failing ones first. A security panel breaks down known vulnerabilities by severity next to the downloads chart.
  • Recently visited quick menus: Hover over Repos or Packages in the sidebar to jump straight to the repositories and packages you opened most recently.
  • Redesigned package page: A new header shows the latest version, the description, the source repository with its sync status, and a 30-day download sparkline, above a one-click composer require bar. Readme, Versions and Downloads are now tabs, and package details sit in a sidebar next to the README.

Improvements

  • Readability: Badges, timestamps and other small text no longer drop below 12px, and code blocks in READMEs are no longer shrunk to an unreadable size.
  • Versions list: Versions appear as an aligned table with advisories, archive size, commit and release date. You can filter by stable or dev, and copy the exact composer require command for any version on hover.
  • Packages list: Packages are grouped by vendor, show their description, source and latest version, and can be filtered by name.
  • Repository page: A new header summarizes status, last sync, package count and webhook state. Sync history shows the outcome of recent syncs at a glance, and repositories that haven't synced yet get a Sync Now shortcut.
  • Download stats: The Downloads tab uses a compact summary with exact numbers and the trend compared with the previous 30 days.
  • Labels and notifications: Status labels share one consistent style across the app, and Git provider icons use their brand colors. Notifications have a cleaner design with a countdown bar that pauses on hover.
  • Surfaces: Muted backgrounds lose their beige tint for a more neutral look.
View on GitHub

This release focuses on reliability across Docker upgrades, SQLite syncs and dist archives. Docker Compose users need to update their docker-compose.yml before upgrading (see below).

Thanks to @NiekNijland for their first contributions to Pricore, which include most of the fixes in this release!

Fixes

  • Fixed Docker upgrades silently skipping new database migrations. The pricore-database volume now mounts on /app/database/data: download the latest docker-compose.yml or update the mounts in your own file. Your database moves with the volume, and the container refuses to start with the old layout. If you set DB_DATABASE yourself, change it to /app/database/data/database.sqlite.
  • Fixed "database is locked" errors on SQLite when several repositories sync at the same time.
  • Fixed versions permanently missing their dist archive after a failed build. The next sync now retries it.
  • Fixed GitHub fine-grained tokens not listing the organizations they can access.
  • Fixed security scans failing for packages of deleted organizations.
View on GitHub

This release fixes organization access checks and two-factor authentication for OAuth logins.

Fixes

  • Fixed repository creation accepting SSH keys from another organization. Key ownership is now checked when adding a repository and before Git uses the key. (#182)
  • Fixed forbidden organization pages including private package and repository search data. Search results are now limited to organization members. (#183)
  • Fixed GitHub and GitLab logins skipping local two-factor authentication. Users with two-factor enabled now complete the existing authenticator or recovery-code challenge before signing in. (#184)
View on GitHub

A security release. Upgrading is recommended.

Fixes

  • Fixed registry mirrors allowing server-side requests to private or internal network addresses through mirror URLs, Composer metadata, distribution URLs, or redirects. Mirror requests are now validated and DNS-pinned before connecting, redirects are revalidated, and credentials are only sent to the configured mirror origin. Trusted internal mirrors can be explicitly enabled with MIRROR_ALLOWED_PRIVATE_HOSTS.

Documentation

  • Removed the broken star history chart.

This release fixes Composer installs from lock files that pin older branch commits and improves reliability around installation and queued repository syncs.

Fixes

  • Fixed composer install returning a 404 for branch versions when the lock file pins an older commit. Pricore now tracks dist archives by commit and keeps superseded branch archives available instead of leaving them unreachable. Dist metadata is also cleared when a branch reference moves, preventing an archive from the previous commit being advertised for the new one. Superseded archives are retained indefinitely by default; set DIST_KEEP_DETACHED_DAYS to configure a retention window. (#178, #179)
  • Fixed manual installations enabling public sign-ups because .env.example did not match the documented invite-only default. The manual deployment and contributing guides now use pricore:install to create the first account. (#173)
  • Fixed queued repository sync completion failing when its organization was deleted before the sync finished. (#180)

Improvements

  • Dependencies: Updated Recharts to 3.10.1. (#175)

A security release. Upgrading is recommended.

Fixes

  • Fixed repository identifiers not being validated before being passed to Git. Generic Git repositories are now restricted to https, http, ssh and git URLs, or scp-style user@host:path. GitHub, GitLab and Bitbucket repositories are restricted to owner/repository. Existing repositories are re-checked on their next sync.

Improvements

  • Dependencies: Composer and npm dependencies updated to their latest versions.