v0.4.2regionus-east-1builds/7d41pipeline active
FLA / PUBLIC BETA
CHANGELOG / PUBLIC BETA
$flareo changelog --since=first-release# every shipped change, reverse chronological

WHAT SHIPPED.
AND WHEN.

A public-beta product owes you a real changelog, not a blog full of thought pieces. Every version below links to the shipped change, the date it landed, and the pull request or incident that prompted it.

v0.4.2
2026-04-18

Provenance attestation format update

SLSA provenance attestations now include the full BuildKit frontend version and build argument hashes. Existing attestations remain verifiable; new builds emit the richer predicate.

  • FEATUREEmit BuildKit frontend version in in-toto predicate
  • FEATUREHash-sealed build arguments included in provenance subject
  • FIXRekor entry URL was occasionally truncated in verify output
  • FIXflareo search --json now emits valid JSONL when 0 results
v0.4.1
2026-04-09

Trivy 0.54.1 → 0.54.2 incident fix

Pinned Trivy to the 0.54.1 release across all workers after an upstream schema change caused 37 minutes of degraded scan throughput. Post-mortem published in the architecture repo.

  • FIXPin Trivy binary to 0.54.1 pending schema stabilization
  • FIXScan retry logic now distinguishes panic from timeout
  • FEATUREAdd scan_stage_p99_duration alert at 3× baseline threshold
v0.4.0
2026-03-27

Public status page launched

flareo.sh/status now shows real 90-day component health, incident history, and the exact SQL queries behind every metric. No smoothed averages, no marketing spin.

  • FEATURELive /status dashboard at flareo.sh/status
  • FEATUREPublished SQL for uptime, scan pass, stage p50 metrics
  • FEATURESubscribe via email, RSS, webhook, or Slack webhook
  • FEATURE90-day service-level bar charts per component
v0.3.8
2026-03-12

CLI: flareo verify command

The three-check verification suite is now available as a standalone CLI command. Run cosign, trivy, and slsa-verifier against any image without pulling.

  • FEATURENew `flareo verify <image>` command with --strict and --require-slsa flags
  • FEATUREExit code 4 reserved for verification failures (CI-friendly)
  • FIXflareo pull now auto-verifies signatures before loading into docker
v0.3.5
2026-02-28

Catalog reaches 10 verified modules

Keycloak, Grafana, and CrowdSec joined the catalog. Total build throughput reached 41 pipelines per 7-day window.

  • FEATUREKeycloak 24.0.3 verified and published
  • FEATUREGrafana 10.2.3 verified and published
  • FEATURECrowdSec 1.6.0 verified and published
v0.3.0
2026-02-05

Sandbox preview feature (beta)

Every previewable module can now be spun up in a 30-minute disposable Firecracker microVM, proxied to a unique subdomain. See the live demo at flareo.sh/sandbox.

  • FEATURELive sandbox sessions via Firecracker + Caddy
  • FEATURE30-minute hard TTL with atomic teardown
  • FEATUREEgress deny-all by default; sandboxes can receive but not initiate traffic
  • SECURITYNo shared filesystem or network namespace between sandbox sessions
v0.2.0
2025-12-15

Public beta opens

Flareo enters public beta with 5 verified modules, the full 6-stage pipeline, and no card required for any tier. Paid billing starts September 2026 with 30 days advance notice.

  • BREAKINGflareo.sh is now publicly accessible; invite-only closed beta ended
  • FEATUREEarly 5 modules: Vaultwarden, Caddy, Nginx Proxy Manager, Uptime Kuma, Authentik
  • FEATUREKeyless cosign signing via Sigstore Fulcio and Rekor
§ SUBSCRIBE

Get the next release in your inbox.

One email per shipped version — never more. Or grab the RSS feed if you'd rather not give us your address.