Commit Graph

366 Commits

Author SHA1 Message Date
Valentin Maerten
bff4f97d7e refactor(remote): template header values instead of expanding ${VAR}
Aligns the syntax with the rest of Task, and lets functions compose: a
Basic credential no longer needs its base64 computed by hand. The strict
expansion this replaces was already gone, so nothing is lost by the
switch.

Only functions resolve — the configuration file is read before any
Taskfile, so {{.VAR}} has nothing to read and produces an empty header.
That is documented next to the option.
2026-08-23 12:35:55 +02:00
Valentin Maerten
433e2bb2ee docs(remote): add the remote.auth schema to next-schema-taskrc.json
Same next/latest split as the docs: schema.json and schema-taskrc.json
are the frozen copies served for the released version.
2026-08-23 12:24:58 +02:00
Valentin Maerten
d10460ab61 docs(remote): document remote.auth under next instead of latest
The rebase landed these additions in the frozen copy served for the
released version, because the commits predated the split into next and
latest.
2026-08-23 12:22:38 +02:00
Valentin Maerten
a41df4a127 fix(remote): report a 401 instead of a missing Taskfile
RemoteExists treated every non-200 as an absent file, so a server
refusing the credentials ended up as "No Taskfile found", sending the
user to check the URL rather than the token. A 401 now stops the search
and reports the status code; the default names need the same credentials,
so trying them would only add rejected requests. A 403 is left alone: it
is also what a server without directory listing answers for a readable
directory.

That message being correct, the expansion no longer needs to refuse an
undefined variable: os.ExpandEnv is inlined and expandEnv is gone. The
`$$` escape goes with it, so a literal value can no longer hold a `$`
followed by a name; a secret carried in an environment variable is
unaffected, as os.Expand never rescans what it substituted.

Header names are validated with httpguts.ValidHeaderFieldName, the table
net/http itself uses, rather than a denylist that let X-Foo(bar) through.
golang.org/x/net was already in the module graph, so tidy only moves it
to the direct block.

Finally, node_http_auth.go becomes http_auth.go: the node_ prefix is for
files defining a Node type, and this one holds the auth concern of
HTTPNode plus hostMatches, which reader.go uses for trusted hosts.
2026-08-23 12:11:55 +02:00
Valentin Maerten
8a93190060 feat(remote): add remote.auth to send HTTP headers when downloading Taskfiles
Authenticating a remote Taskfile so far meant putting the credential in the
include URL, where it leaks into error messages and the confirmation prompt.
`remote.auth` configures free-form headers per host instead, so the URL stays
safe to commit. Values may reference environment variables with ${VAR}.

The headers are injected by a RoundTripper rather than set on the request:
that covers the HEAD probe RemoteExists issues before the GET, and keeps a
cross-host redirect from carrying the credentials. They are resolved when the
request is about to be made, so a cached or offline run does not require a
token it will never send.
2026-08-23 12:11:08 +02:00
Valentin Maerten
b250872d9a feat(release): publish the snap package with goreleaser (#2989) 2026-08-21 15:31:53 +02:00
Valentin Maerten
920de654cd feat(release): announce releases on discord (#2988) 2026-08-21 15:31:53 +02:00
Valentin Maerten
30c998136d feat(release): generate the GitHub release body from the changelog (#2987)
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
2026-08-21 15:31:52 +02:00
Valentin Maerten
1530114bca v3.53.0 2026-08-18 17:14:13 +02:00
Valentin Maerten
2449247e16 feat(homebrew): migrate from Formula to Cask (#2702) 2026-08-18 17:11:28 +02:00
Valentin Maerten
ed98857afc docs: credit JetBrains for the open source licenses (#2984) 2026-08-18 17:00:39 +02:00
Pete Davison
4bcc01fb1e feat: add blog post for remote taskfiles (#2974) 2026-08-18 16:59:59 +02:00
renovate[bot]
d9d0e44cf4 chore(deps): update all non-major dependencies (#2978)
Co-authored-by: Valentin Maerten <maerten.valentin@gmail.com>
2026-08-18 16:58:43 +02:00
Valentin Maerten
936b90c625 feat(website): serve the released docs from a versioned copy (#2979) 2026-08-17 14:15:03 +02:00
Pete Davison
b7836eb893 feat: set content type for example remote taskfile 2026-08-16 11:46:30 +00:00
Pete Davison
1d0719b65a feat: load the sidebar data and titles/excerpts from the blog post markdown document and its frontmatter (#2981) 2026-08-16 12:14:08 +01:00
Pete Davison
50c5ae18e4 fix: minor adjustment to blog post description to match post edit 2026-08-13 21:49:48 +00:00
Andrey Nering
4c144fed8f chore(website): add blog post about the github secure oss fund (#2977)
Co-authored-by: Pete Davison <pd93.uk@outlook.com>
Co-authored-by: Valentin Maerten <maerten.valentin@gmail.com>
2026-08-13 13:18:56 -03:00
Pete Davison
87076b165f feat: enable remote taskfiles (#2906) 2026-08-13 14:38:10 +01:00
Valentin Maerten
37898d9102 feat: command timeouts (#2898) 2026-08-11 22:09:25 +02:00
Valentin Maerten
993508c782 feat(completion): add Nushell completions (#2966) 2026-08-11 20:12:17 +02:00
Valentin Maerten
65471a2ef8 fix: align command schema definitions with the parser (#2967) 2026-08-10 20:25:05 +02:00
Gerard O'Keefe
49eea5352c fix: schema does not allow ignore_error in a for loop (#2044)
Co-authored-by: O'Keefe, Gerard (Gerry) <gokeefe@atb.com>
2026-08-10 18:22:25 +00:00
renovate[bot]
a80bee87cb chore(deps): update all non-major dependencies (#2943) 2026-08-10 16:39:06 +02:00
星尘
2888867c94 feat: support excluding task namespaces (#2959) 2026-08-10 16:23:51 +02:00
shaurya
f174912975 docs: document use_gitignore in schema reference and guide (#2957)
Co-authored-by: no-hup <shauryaj.finance@gmail.com>
2026-08-05 10:48:23 +02:00
shaurya
886d1ea650 docs: close two unterminated code fences and fix --trust flag name (#2955) 2026-08-04 14:24:23 +00:00
renovate[bot]
c05bdcddf5 chore(deps): update dependency netlify-cli to v27 (#2939) 2026-07-25 19:10:54 +02:00
renovate[bot]
1426db91e4 chore(deps): update all non-major dependencies (#2935)
Co-authored-by: Valentin Maerten <maerten.valentin@gmail.com>
2026-07-25 19:01:00 +02:00
Toby Griffiths
aac8c00e99 docs: add missing tasks.{task}.vars to schema reference (#2912) 2026-07-14 20:06:42 +00:00
renovate[bot]
6833ee5c0c chore(deps): update all non-major dependencies (#2909)
Co-authored-by: Valentin Maerten <maerten.valentin@gmail.com>
2026-07-14 22:02:35 +02:00
Nick Gluschenko
dc4ce212e3 docs: add zed extension to community integrations (#2914)
Co-authored-by: Nick Gluschenko <nick.a.lie@gmail.com>
2026-07-13 17:53:22 -03:00
Pete Davison
1f34895185 feat: update experiments workflow to reflect use of issue field instead of labels 2026-07-03 13:31:52 +00:00
Jurgen Braam
3354090f21 docs: Mention version checks introduced in v3.34.0 (#2184) 2026-07-03 14:16:57 +01:00
Andrey Nering
015eb3f0fe docs(adopters): update charm copy 2026-07-02 17:49:17 -03:00
Valentin Maerten
536f490187 v3.52.0 2026-07-02 20:37:51 +02:00
qingyingliu
b5861b1e27 fix: reject include without taskfile or dir (#2892)
Co-authored-by: Valentin Maerten <maerten.valentin@gmail.com>
2026-07-01 19:48:47 +00:00
Pete Davison
c7cb5e1aaa feat: readd example hosted remote taskfile (#2905) 2026-07-01 15:44:33 +01:00
renovate[bot]
6cf0303ab8 chore(deps): update all non-major dependencies (#2889) 2026-06-30 23:19:27 +02:00
Valentin Maerten
e415d7135e fix(docs): wrap join example in v-pre to fix VitePress build
The inline `{{join " " .WORDS}}` example was parsed as a Vue
interpolation, which broke the website build. Wrap it in <span v-pre>
so it renders literally, matching the existing escaped example in the
same file.
2026-06-30 22:25:27 +02:00
Valentin Maerten
9910c33557 fix(remote): define special variables behavior (#2847) 2026-06-29 19:25:25 +01:00
Markus
b93897a6c3 docs: clarify join argument order in templating reference (#2887)
Co-authored-by: Markus Stark <markusstark@MacBook-Air-von-Markus.local>
2026-06-29 17:08:44 +02:00
Valentin Maerten
7fa9d657cd feat(completion): complete task aliases in zsh (#2865) 2026-06-29 14:21:47 +00:00
kjasn
1c743de2b7 feat: Add temp dir option (#2891)
Co-authored-by: Valentin Maerten <maerten.valentin@gmail.com>
2026-06-29 14:13:37 +00:00
Or Carmi
d6cc0ce070 feat: configure output flags via environment variables (#2873)
Co-authored-by: Or Carmi <ocarmi@paloaltonetworks.com>
Co-authored-by: Valentin Maerten <maerten.valentin@gmail.com>
2026-06-29 13:48:37 +00:00
Valentin Maerten
616433df75 feat: add use_gitignore option to exclude ignored files from sources/generates (#2773) 2026-06-29 15:39:33 +02:00
Valentin Maerten
6abbbcb265 feat: do not log secret variables (#2514) 2026-06-29 14:50:08 +02:00
Vessel9817
b9b50ca79c fix: $schema according to schemastore standards (#2893) 2026-06-28 19:18:31 +00:00
renovate[bot]
a72eb84c15 chore(deps): update all non-major dependencies (#2869) 2026-06-21 16:24:20 +02:00
SEONGHYUN HONG
f1ab404fbb docs: fix duplicated word in guide (#2885)
Signed-off-by: s3onghyun <s3onghyun.hong@gmail.com>
2026-06-21 14:19:20 +00:00