v0.58.0
LatestPackage uploads are the focus of this release. You can now publish Composer packages from zip archives, without a Git repository, both from the web app and from CI.
New Features
- Package uploads (#132): Owners and admins can create a package by uploading a zip whose
composer.jsonis at the root or in a single top-level folder. New versions can be uploaded from the package page. Released versions are immutable, while dev versions such asdev-maincan be replaced. The package page shows each version's README, size and checksum. - Publishing from CI (#132): Organization tokens can now be created with Allow publishing packages. Those tokens can upload new versions of existing uploaded packages through
POST /{organization}/api/packages/upload. Existing tokens stay read-only, andphp artisan token:create --publishcreates a publishing token from the command line. - Upload activity: The activity feed now shows each uploaded version, including which user or token uploaded it.
Improvements
- Upload limits: The maximum archive size (
ARTIFACT_MAX_SIZE, default 64 MB) and the per-token upload rate limit (ARTIFACT_UPLOAD_RATE_LIMIT, default 30 per minute) are now configurable. The bundled nginx config accepts request bodies up to 64 MB. - Separate package sources: Repository and mirror syncs no longer take over an uploaded package with the same name, and archive cleanup never removes an uploaded package's archives.
Fixes
- Fixed package names from synced repositories not being validated as plain
vendor/packagenames. Such a name could place archives outside the package's storage folder.