Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
92 commits
Select commit Hold shift + click to select a range
6c533e7
fix(upgrade): compare prerelease versions per SemVer
riglar Jun 24, 2026
d543981
fix: suppress refresh countdown in quiet mode
riglar Jun 24, 2026
f77841f
Merge pull request #34 from devicecloud-dev/fix/upgrade-prerelease-co…
riglar Jun 24, 2026
10eade4
Merge pull request #35 from devicecloud-dev/fix/quiet-suppress-refres…
riglar Jun 24, 2026
ea62f72
feat(cloud): warn on deprecated iOS 16 (removal 2026-08-23)
finalerock44 Jun 24, 2026
d794695
Merge pull request #37 from devicecloud-dev/chore/deprecate-ios-16
finalerock44 Jun 24, 2026
62c7672
feat(cloud): drop legacy Maestro removed-versions block; soft-warn on…
finalerock44 Jun 24, 2026
ee995e7
Merge pull request #38 from devicecloud-dev/chore/maestro-deprecation
finalerock44 Jun 24, 2026
ec16bcc
fix(installer): make beta opt-in, add stable/beta channels
riglar Jun 24, 2026
77cf138
chore: add open-source contribution governance
finalerock44 Jun 24, 2026
88c3532
Merge pull request #39 from devicecloud-dev/fix/installer-beta-opt-in
riglar Jun 24, 2026
129f802
chore: drop CODEOWNERS
finalerock44 Jun 24, 2026
ebac7e2
Merge pull request #40 from devicecloud-dev/chore/oss-governance
finalerock44 Jun 24, 2026
dc87257
fix(ci): keep dependabot and fork PRs green (#46)
finalerock44 Jun 24, 2026
07074d3
ci: power CLA via the shared automation GitHub App (#49)
finalerock44 Jun 24, 2026
d3b0acc
docs: set legal entity to Moropo Ltd t/a DeviceCloud (#50)
finalerock44 Jun 24, 2026
3fe1f21
ci: bump the actions group across 1 directory with 6 updates (#47)
dependabot[bot] Jun 24, 2026
d780e55
fix: v5 release blockers — installer, binary version, repeated flags,…
finalerock44 Jun 24, 2026
7fd253a
chore(dev): release 5.0.0-beta.2 (#36)
github-actions[bot] Jun 24, 2026
bd60298
fix: stop CLA locking release PRs (breaks release pipeline) (#52)
finalerock44 Jun 24, 2026
a02584f
feat(live): add a beta warning to `dcd live start` (#54)
finalerock44 Jun 25, 2026
3eedde3
chore(dev): release 5.0.0-beta.3 (#53)
dcd-cli-release-please[bot] Jun 25, 2026
b72b83a
chore: remove dead Maestro 1.39.5/1.41.0 deprecation warning (#57)
finalerock44 Jun 26, 2026
10dfdbf
feat: render DB-driven notices and forward CLI/CI identity (#58)
finalerock44 Jun 26, 2026
58c3b1b
chore(dev): release 5.0.0-beta.4 (#59)
dcd-cli-release-please[bot] Jun 26, 2026
c99f040
fix: notices render polish (#60)
finalerock44 Jun 26, 2026
5adec18
chore: release 5.0.1-beta.1 (#62)
finalerock44 Jun 26, 2026
ee23356
chore(dev): release 5.0.1-beta.1 (#61)
dcd-cli-release-please[bot] Jun 26, 2026
1d331b4
refactor: route notice rendering through ui (add ui.deprecation) (#66)
finalerock44 Jun 29, 2026
851f051
chore: bump eslint-plugin-unicorn from 68.0.0 to 69.0.0 (#70)
dependabot[bot] Jul 10, 2026
cfd9fe2
deps: bump the minor-and-patch group across 1 directory with 9 update…
dependabot[bot] Jul 10, 2026
7fd7748
fix: recover cleanly when the stored session is dead (#72)
riglar Jul 10, 2026
b78a1dc
feat(cloud): device matrix via repeated --ios-config/--android-config…
finalerock44 Jul 13, 2026
bc9c61f
chore: release 5.2.0-beta.1 (#76)
finalerock44 Jul 13, 2026
4ef0292
chore(dev): release 5.2.0-beta.1 (#67)
dcd-cli-release-please[bot] Jul 13, 2026
fc3ea3f
refactor(cloud): rename --ios-config/--android-config to --ios-device…
finalerock44 Jul 13, 2026
8b6fde1
docs: correct the release bump table — a breaking `!` bumps the MAJOR…
finalerock44 Jul 13, 2026
db71189
chore(dev): release 5.2.0-beta.2 (#78)
dcd-cli-release-please[bot] Jul 13, 2026
5560158
fix(cloud): refuse a device matrix on an API that cannot honour it (#80)
finalerock44 Jul 13, 2026
1e7a1eb
chore(dev): release 5.2.0-beta.3 (#81)
dcd-cli-release-please[bot] Jul 13, 2026
cc5ee4d
fix(deps): resolve pnpm audit failures in transitive dependencies (#89)
riglar Jul 23, 2026
cbac88b
chore: bump eslint-plugin-unicorn from 69.0.0 to 71.1.0 (#85)
dependabot[bot] Jul 23, 2026
5730af7
ci: bump actions/setup-node from 6 to 7 in the actions group (#86)
dependabot[bot] Jul 23, 2026
f333be9
deps: bump the minor-and-patch group across 1 directory with 7 update…
dependabot[bot] Jul 23, 2026
a4f11ff
deps: patch js-yaml and brace-expansion DoS advisories (#95)
riglar Jul 27, 2026
1b29d2d
deps: bump chalk from 5.6.2 to 6.0.0 (#98)
dependabot[bot] Jul 30, 2026
7d85979
chore: bump eslint-plugin-unicorn from 71.1.0 to 72.0.0 (#97)
dependabot[bot] Jul 30, 2026
f6fcfaf
feat(artifacts): prefer server-assembled bundle delivery for download…
riglar Jul 30, 2026
47b9d90
deps: bump the minor-and-patch group across 1 directory with 5 update…
dependabot[bot] Jul 30, 2026
a34d9d4
feat: client-side envelope encryption of binaries, flow zips & env va…
riglar Jul 30, 2026
6e244a9
feat(upload): dedup encrypted binaries on the plaintext hash (#101)
riglar Aug 3, 2026
3888fc5
refactor(cloud): remove mitmproxy flags (#102)
riglar Aug 3, 2026
f7934b0
fix(deps): resolve three new transitive security advisories (#106)
finalerock44 Aug 5, 2026
2fd4bdf
chore: regenerate schema types from the current API swagger (#105)
finalerock44 Aug 5, 2026
3d24435
feat(device): add Android API level 37 (Android 17) (#107)
finalerock44 Aug 6, 2026
4af1ddb
ci: bump pnpm/action-setup from 6 to 6.0.9 in the actions group (#103)
dependabot[bot] Aug 6, 2026
3038ed8
chore(dev): release 5.2.0-beta.4 (#91)
dcd-cli-release-please[bot] Aug 7, 2026
13d01ee
fix(cloud): exclude config-shaped files from flow discovery (#114)
finalerock44 Aug 10, 2026
0c70928
chore: bump eslint-plugin-unicorn from 72.0.0 to 73.0.0 (#113)
dependabot[bot] Aug 10, 2026
2223dd4
deps: bump the minor-and-patch group with 5 updates (#112)
dependabot[bot] Aug 10, 2026
96147df
ci: bump pnpm/action-setup from 6.0.9 to 6.0.10 in the actions group …
dependabot[bot] Aug 10, 2026
6858220
chore: pin the next dev beta to 5.3.1-beta.1 (#116)
finalerock44 Aug 10, 2026
57711c6
chore(dev): release 5.3.1-beta.1 (#115)
dcd-cli-release-please[bot] Aug 10, 2026
1973a42
fix(cloud): reject malformed executionOrder instead of silently runni…
finalerock44 Aug 13, 2026
43e7324
chore(dev): release 5.3.1-beta.2 (#118)
dcd-cli-release-please[bot] Aug 13, 2026
1c07fc1
deps: bump the minor-and-patch group with 6 updates (#121)
dependabot[bot] Aug 18, 2026
2b89f3a
ci: stop reaching into the private dcd repo for the mock-api (#124)
finalerock44 Aug 18, 2026
fcfa524
feat!: remove iOS 16 (#126)
finalerock44 Aug 24, 2026
a60611d
chore: release the iOS 16 removal as 5.4.0, not 6.0.0 (#127)
finalerock44 Aug 24, 2026
0aaa652
chore(dev): release 5.4.0-beta.0 (#122)
dcd-cli-release-please[bot] Aug 24, 2026
1333960
feat(device): add iOS 27 and the iPhone 17 family (#131)
finalerock44 Aug 27, 2026
3222dda
fix(ci): point the CLA check at our node24 fork (#135)
finalerock44 Sep 2, 2026
38f6dfa
feat(device): drop the iPhone 17 family (#134)
finalerock44 Sep 2, 2026
b903241
docs(ci): the CLA action fork must stay public (#136)
finalerock44 Sep 2, 2026
0d2234a
deps: bump the minor-and-patch group across 1 directory with 4 update…
dependabot[bot] Sep 2, 2026
fc43dc6
chore: release 5.4.1-beta.1 (#137)
finalerock44 Sep 2, 2026
7ccb0c9
fix(deps): refresh audit overrides to the patched versions (#141)
finalerock44 Sep 10, 2026
df39281
chore: bump mocha from 11.8.0 to 12.0.0 (#140)
dependabot[bot] Sep 10, 2026
7daa42b
chore: bump eslint-plugin-unicorn from 73.0.0 to 74.0.0 (#139)
dependabot[bot] Sep 10, 2026
9b5f751
fix(deps): adopt bplist-parser 0.5 named exports (#143)
finalerock44 Sep 10, 2026
9a4ad49
deps: bump the minor-and-patch group across 1 directory with 5 update…
dependabot[bot] Sep 10, 2026
97cad3d
chore(dev): release 5.4.1-beta.1 (#132)
dcd-cli-release-please[bot] Sep 10, 2026
9d9e413
feat(notices): expose platform, device and Maestro version to notice …
finalerock44 Sep 10, 2026
190a0e9
chore(dev): release 5.5.0-beta.1 (#148)
dcd-cli-release-please[bot] Sep 10, 2026
dac5d1e
feat: add Pixel 8, Pixel 10 family and Pixel 11 device slugs (#151)
finalerock44 Sep 14, 2026
075a0be
chore(dev): release 5.5.0-beta.2 (#152)
dcd-cli-release-please[bot] Sep 14, 2026
a2888fd
feat(cloud): add --render-engine for the emulator software renderer (…
finalerock44 Sep 14, 2026
b974a07
chore(dev): release 5.5.0-beta.3 (#154)
dcd-cli-release-please[bot] Sep 14, 2026
bada03b
ci: bump pnpm/action-setup from 6.0.10 to 6.1.0 in the actions group …
dependabot[bot] Sep 14, 2026
004b478
fix: register tsx's ESM loader only so mocha 12.0.1 can load find-up@…
finalerock44 Sep 14, 2026
1e6e2c0
deps: bump the minor-and-patch group with 7 updates (#156)
dependabot[bot] Sep 14, 2026
9c37f81
chore(dev): release 5.5.0-beta.4 (#158)
dcd-cli-release-please[bot] Sep 15, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
15 changes: 15 additions & 0 deletions .editorconfig
Original file line number Diff line number Diff line change
@@ -0,0 +1,15 @@
# EditorConfig — https://editorconfig.org
# Keep editors aligned with the Prettier config (.prettierrc).
root = true

[*]
charset = utf-8
end_of_line = lf
indent_style = space
indent_size = 2
insert_final_newline = true
trim_trailing_whitespace = true

# Markdown uses two trailing spaces for hard line breaks — don't strip them.
[*.md]
trim_trailing_whitespace = false
63 changes: 63 additions & 0 deletions .github/ISSUE_TEMPLATE/bug_report.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,63 @@
name: Bug report
description: Report a problem with the dcd CLI or dcd-mcp server
labels: ["bug"]
body:
- type: markdown
attributes:
value: |
Thanks for taking the time to file a bug! Please fill in the details below.

⚠️ **Do not report security vulnerabilities here** — see our
[Security Policy](https://github.com/devicecloud-dev/dcd-cli/blob/dev/SECURITY.md).
- type: textarea
id: what-happened
attributes:
label: What happened?
description: A clear description of the bug, including what you expected to happen instead.
validations:
required: true
- type: textarea
id: repro
attributes:
label: Steps to reproduce
description: The exact `dcd` command(s) you ran and what followed. Redact any API keys.
placeholder: |
1. Run `dcd cloud --apiKey *** app.apk flows/`
2. ...
3. See error
validations:
required: true
- type: input
id: version
attributes:
label: CLI version
description: Output of `dcd --version`.
placeholder: "e.g. 5.0.0"
validations:
required: true
- type: dropdown
id: os
attributes:
label: Operating system
options:
- macOS
- Linux
- Windows
- Other (note in description)
validations:
required: true
- type: input
id: install
attributes:
label: How did you install dcd?
placeholder: "binary (curl/irm), npm global, npx, …"
validations:
required: false
- type: textarea
id: logs
attributes:
label: Logs / output
description: Relevant output. Re-run with more detail if you can. This is automatically formatted as code.
render: shell
validations:
required: false
11 changes: 11 additions & 0 deletions .github/ISSUE_TEMPLATE/config.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,11 @@
blank_issues_enabled: false
contact_links:
- name: Questions & help
url: https://discord.gg/gm3mJwcNw8
about: For usage questions and general help, ask in our Discord rather than opening an issue.
- name: Documentation
url: https://docs.devicecloud.dev
about: Check the docs for installation, usage, and command reference.
- name: Report a security vulnerability
url: https://github.com/devicecloud-dev/dcd-cli/blob/dev/SECURITY.md
about: Do not file security issues publicly — email security@devicecloud.dev (see our Security Policy).
35 changes: 35 additions & 0 deletions .github/ISSUE_TEMPLATE/feature_request.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,35 @@
name: Feature request
description: Suggest an idea or improvement for the dcd CLI or dcd-mcp server
labels: ["enhancement"]
body:
- type: markdown
attributes:
value: Thanks for the suggestion! Please describe the problem before the solution.
- type: textarea
id: problem
attributes:
label: What problem are you trying to solve?
description: What are you trying to do, and where does the CLI get in the way today?
validations:
required: true
- type: textarea
id: solution
attributes:
label: Proposed solution
description: What would you like to happen? A concrete command/flag/output sketch helps.
validations:
required: true
- type: textarea
id: alternatives
attributes:
label: Alternatives considered
description: Other approaches or workarounds you've thought about.
validations:
required: false
- type: textarea
id: context
attributes:
label: Additional context
description: Anything else — links, screenshots, related issues.
validations:
required: false
36 changes: 36 additions & 0 deletions .github/PULL_REQUEST_TEMPLATE.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,36 @@
<!--
PR TITLE: must follow Conventional Commits — it becomes the squash-merge
commit and feeds release-please. e.g. feat(cloud): add --json output
Allowed types: feat, fix, perf, deps, revert, refactor, docs, chore, test, ci, build, style
See CONTRIBUTING.md for details.
-->

## What & why

<!-- What does this change do, and why? Link any related issue: Closes #123 -->

## Type of change

<!-- Match this to your PR title's type. -->

- [ ] `fix` — bug fix
- [ ] `feat` — new feature
- [ ] `perf` — performance improvement
- [ ] `refactor` — code change that's neither a fix nor a feature
- [ ] `docs` — documentation only
- [ ] `chore` / `ci` / `build` / `test` — tooling, no user-facing change
- [ ] Breaking change (title has `!` or PR notes a `BREAKING CHANGE:`)

## Checklist

- [ ] PR title follows the Conventional Commits format (see comment above)
- [ ] `pnpm lint` passes
- [ ] `pnpm typecheck` passes
- [ ] `pnpm build` passes
- [ ] I have **not** bumped the version or edited `CHANGELOG.md` (release-please handles this)
- [ ] I have signed the CLA (the bot will prompt on first contribution)
- [ ] Docs / `README.md` / `STYLE_GUIDE.md` updated if behaviour or output changed

## How to test

<!-- Steps a reviewer can follow to verify the change. -->
35 changes: 35 additions & 0 deletions .github/dependabot.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,35 @@
version: 2
updates:
# npm / pnpm dependencies.
- package-ecosystem: npm
directory: "/"
schedule:
interval: weekly
target-branch: dev
open-pull-requests-limit: 10
commit-message:
# Conventional Commit prefix so the squashed PR title matches our PR-title
# lint and release-please picks dependency bumps into the changelog.
prefix: deps
prefix-development: chore
groups:
# Collapse the noise: one PR for all non-major updates.
minor-and-patch:
update-types:
- minor
- patch

# GitHub Actions used by our workflows.
- package-ecosystem: github-actions
directory: "/"
schedule:
interval: weekly
target-branch: dev
commit-message:
prefix: ci
groups:
# One PR per week for ALL action bumps (including majors). Actions are
# low-risk and quick to eyeball together; no need for a PR each.
actions:
patterns:
- "*"
85 changes: 85 additions & 0 deletions .github/workflows/cla.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,85 @@
name: CLA Assistant

# Gates merges on a signed Contributor License Agreement.
#
# Uses CLA Assistant Lite: signatures are stored as a JSON file committed to a
# branch of THIS repo (no third-party service holds the data). Contributors sign
# by commenting the configured phrase on their PR; the action records it and
# flips the check green.
#
# ACTION SOURCE: devicecloud-dev/cla-assistant-action, our fork of the upstream
# contributor-assistant/github-action, which was archived read-only on
# 2026-03-23. We forked because GitHub's Node 20 deprecation began force-running
# node20 actions on Node 24, under which the upstream step does its work, logs
# "All contributors have signed the CLA", and THEN exits non-zero — failing a
# required check on every PR (first hit 2026-09-02, last green 2026-08-31). The
# fork's only change is `using: node24`; dist is unmodified. See its FORK.md.
#
# The fork must stay PUBLIC: this repo is public, and a public repo's workflow
# cannot resolve an action from a private one — it fails at resolution with
# "Unable to resolve action ... not found", before any CLA logic runs, even with
# the org access policy set. Do not flip it private.
#
# AUTH: mints a token from the shared automation GitHub App (the same App
# release-please uses), so signature commits show as the bot and there's no
# personal token to expire.
#
# SETUP REQUIRED before this enforces anything:
# 1. Create/install the automation GitHub App (Contents R/W, Pull requests R/W,
# Issues R/W) and add BOT_APP_ID + BOT_APP_PRIVATE_KEY repo secrets — the
# same secrets release-please uses.
# 2. Create the `cla-signatures` branch (empty orphan) so the action has
# somewhere to write `signatures/version1/cla.json`.
# 3. Finalise CLA.md (legal review) — it's the document contributors agree to.
#
# Until the App secrets exist the CLA step self-skips, so the check is green
# (not failing) on every PR and auto-activates once they're set.
on:
issue_comment:
types: [created]
pull_request_target:
types: [opened, closed, synchronize]

permissions:
actions: write
contents: write
pull-requests: write
statuses: write

jobs:
cla:
runs-on: ubuntu-latest
# Empty until the automation App secrets are configured (see SETUP above).
# While empty, the steps below self-skip so this check passes (green) instead
# of failing on every PR with "Branch cla-signatures not found".
env:
HAS_APP: ${{ secrets.BOT_APP_ID != '' }}
# Only act on the signature comment or on PR events (not every comment).
if: (github.event.issue.pull_request && contains(github.event.comment.body, 'I have read the CLA Document and I hereby sign the CLA')) || github.event_name == 'pull_request_target'
steps:
- uses: actions/create-github-app-token@v3
id: app-token
if: env.HAS_APP == 'true'
with:
app-id: ${{ secrets.BOT_APP_ID }}
private-key: ${{ secrets.BOT_APP_PRIVATE_KEY }}
- uses: devicecloud-dev/cla-assistant-action@v2.6.2
if: env.HAS_APP == 'true'
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
PERSONAL_ACCESS_TOKEN: ${{ steps.app-token.outputs.token }}
with:
path-to-signatures: "signatures/version1/cla.json"
path-to-document: "https://github.com/devicecloud-dev/dcd-cli/blob/dev/CLA.md"
branch: "cla-signatures"
# Do NOT lock the PR on merge (the action's default is true). release-please
# comments on its release PR *after* merge; a locked conversation makes that
# comment fail and takes down the whole Release job (npm publish + binaries
# never run). Keeping this false is load-bearing for the release pipeline.
lock-pullrequest-aftermerge: false
# Internal maintainers (covered by employment/CCLA) + bots skip the prompt.
allowlist: riglar,finalerock44,dependabot[bot],renovate[bot],*[bot]
# Customise the bot's prompts if desired:
custom-notsigned-prcomment: "Thanks for your contribution! Please sign our Contributor License Agreement before we can merge. Comment the line below to sign:"
custom-pr-sign-comment: "I have read the CLA Document and I hereby sign the CLA"
custom-allsigned-prcomment: "All contributors have signed the CLA. ✍️ ✅"
13 changes: 6 additions & 7 deletions .github/workflows/claude-code-review.yml
Original file line number Diff line number Diff line change
Expand Up @@ -12,12 +12,11 @@ on:

jobs:
claude-review:
# Optional: Filter by PR author
# if: |
# github.event.pull_request.user.login == 'external-contributor' ||
# github.event.pull_request.user.login == 'new-developer' ||
# github.event.pull_request.author_association == 'FIRST_TIME_CONTRIBUTOR'

# Skip PRs we shouldn't (or can't) review:
# - Dependabot / forks: no CLAUDE_CODE_OAUTH_TOKEN, so the action would fail.
# - release-please release PRs: just version bumps + changelog — nothing to
# review, and it must never block a release.
if: ${{ github.event.pull_request.head.repo.full_name == github.repository && github.actor != 'dependabot[bot]' && !startsWith(github.head_ref, 'release-please--') }}
runs-on: ubuntu-latest
permissions:
contents: read
Expand All @@ -30,7 +29,7 @@ jobs:

steps:
- name: Checkout repository
uses: actions/checkout@v4
uses: actions/checkout@v7
with:
fetch-depth: 1

Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/claude.yml
Original file line number Diff line number Diff line change
Expand Up @@ -26,7 +26,7 @@ jobs:
actions: read # Required for Claude to read CI results on PRs
steps:
- name: Checkout repository
uses: actions/checkout@v4
uses: actions/checkout@v7
with:
fetch-depth: 1

Expand Down
Loading
Loading