Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
15 changes: 15 additions & 0 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -32,6 +32,18 @@ jobs:
matrix:
os: [ubuntu-latest, macos-14, windows-2022]
runs-on: ${{ matrix.os }}
# These legs take one to two minutes. Twenty is not a budget, it is a
# tripwire: without one, a job that stops making progress runs to GitHub's
# six-hour default before anyone hears about it. That is not hypothetical —
# a test that blocked on `accept()` with no deadline wedged the Windows leg
# for its full six hours, and the only reason it went unnoticed for a day
# is that every run on `main` was cancelled by the next push first.
#
# On all three rather than Windows alone: nobody here runs Windows as a
# daily driver, so CI is the only signal it has — but a Unix leg that
# suddenly needs twenty minutes has something wrong with it worth hearing
# about too.
timeout-minutes: 20
permissions:
contents: read
steps:
Expand Down Expand Up @@ -113,6 +125,7 @@ jobs:
matrix:
os: [ubuntu-latest, macos-14]
runs-on: ${{ matrix.os }}
timeout-minutes: 20
permissions:
contents: read
steps:
Expand Down Expand Up @@ -148,6 +161,7 @@ jobs:
matrix:
shell: [powershell, pwsh]
runs-on: windows-2022
timeout-minutes: 20
permissions:
contents: read
steps:
Expand Down Expand Up @@ -268,6 +282,7 @@ jobs:
audit:
name: advisories (blocks on a vulnerability)
runs-on: ubuntu-latest
timeout-minutes: 20
permissions:
contents: read
steps:
Expand Down
77 changes: 76 additions & 1 deletion CHANGELOG.md
Original file line number Diff line number Diff line change
@@ -1,7 +1,8 @@
# Changelog

What changed, and what it means for scripts that already use this tool.
Newest first.
Newest first, written by hand — the commit subject rarely explains why a
change matters.

Versions follow [semantic versioning](https://semver.org/). Pre-1.0 rule:
while the version starts with `0.`, a breaking change raises the minor
Expand All @@ -10,8 +11,32 @@ breaking is [written down in CONTRIBUTING.md](CONTRIBUTING.md#compatibility) —
command names, flags, the two output modes and the exit codes are promises;
the Mapbox APIs' own response bodies are not.

Cutting a release adds a `## <version> - <date>` heading below
`## Unreleased`, which stays in place so the next change has somewhere to go.

Dev-channel builds (`v0.1.3-dev.<sha>`) are published straight from a branch
that may never merge. They are not releases and are not listed here.

## Unreleased

## 0.2.1 - 2026-09-15

### Fixed

- A path parameter can no longer change the shape of the request URL. Values
are substituted into a path template, so one carrying URL syntax altered
where the request went rather than naming a segment in it: `?` appended
query parameters the caller never asked for, `..` (and its backslash
spelling) moved the path, and `#` truncated it — each with the caller's
token and the command's method attached. The host was never reachable, so
nothing could be directed at another server. `/`, `?`, `#` and `\` are now
percent-encoded, and a value of `.` or `..` is refused as
`invalid_path_parameter`. Punctuation these values legitimately carry — a
static-images overlay, `@2x`, `.png`, a comma-separated coordinate — is
untouched. See [#15](https://github.com/mapbox/mapbox-cli/pull/15).

## 0.2.0 - 2026-09-14

### Added

- Paginated listings now say when there is more to fetch. A response the API
Expand Down Expand Up @@ -45,6 +70,37 @@ the Mapbox APIs' own response bodies are not.

### Changed

- **Breaking**: nine more commands renamed, continuing #116's cleanup, and
two dropped outright:

| Was | Is now |
| --- | --- |
| `mapbox geocoder forward-geocode` | `mapbox geocoder forward` |
| `mapbox geocoder reverse-geocode` | `mapbox geocoder reverse` |
| `mapbox geocoder batch-geocode` | `mapbox geocoder batch` |
| `mapbox tilesets get-rastertile` | `mapbox tilesets get-tile` |
| `mapbox tilesets get-vectortile` | `mapbox tilesets get-mvt` |
| `mapbox rasterarrays get-mrt-tile` | `mapbox tilesets get-mrt` |
| `mapbox tilequery get` | `mapbox tilesets query` |
| `mapbox static-images get-static-image` | `mapbox static get-image` |
| `mapbox static-tiles get-static-tile` | `mapbox static get-tile` |

`mapbox rasterarrays`, `mapbox tilequery`, `mapbox static-images` and
`mapbox static-tiles` no longer exist: each held exactly one operation,
and that operation now answers under `tilesets` or `static` instead —
the same reasoning 0.1.8 gave for `sprites` and `tilesets` appearing
there. `mapbox static` is new for it.

`static-images get-static-image-auto` and `get-static-image-bbox` are
gone, not renamed — the decision record's reason for withholding both is
that they will merge into `get-image`'s own parameters, but that merge
hasn't happened yet, so today there is simply no way to ask for an
auto-fit or bounding-box static image from this CLI.

Nothing answers to any of the old spellings, the same as 0.1.8's rename:
no hidden alias, and the two dropped commands are not offered under any
spelling.

- The advice under a transport failure now names `ALL_PROXY` alongside
`HTTPS_PROXY` and `NO_PROXY`, and says that a SOCKS proxy is not supported.
`ALL_PROXY=socks5://…` fails the request rather than being ignored, and
Expand All @@ -68,6 +124,25 @@ the Mapbox APIs' own response bodies are not.
no release notes in front of the reader, so breaking an opt-out there would
have happened silently. When both are set the new name wins.

- A usage error under `-o json` now carries clap's own suggestion as `fix`:
`mapbox styles lst` answers `"fix": "A similar subcommand exists: 'list'"`.
Clap renders that tip in a paragraph of its own, and `message` is built from
the first one, so `json` consumers — scripts and agents — were the only ones
not told what was probably meant. It matters most for the renames above: a
script pinned to a command that no longer exists now gets a pointer to the
one that replaced it. `-o text` is unchanged, where clap already printed it.
Misspelled flags are covered too.

### Security

- `rustls` moved to 0.23.45, fixing
[RUSTSEC-2026-0285](https://rustsec.org/advisories/RUSTSEC-2026-0285) —
"TLS 1.3 handshake messages incorrectly accepted across encryption level
boundaries", medium severity, published 2026-09-14. `rustls` is reached
through `reqwest`, so every HTTPS request this CLI makes used the affected
version; nothing in the crate itself had to change. Fixed in
[mapbox/mapbox-cli#2](https://github.com/mapbox/mapbox-cli/pull/2).

## 0.1.8 - 2026-09-14

Initial beta release. The next release is `0.2.0`.
Expand Down
2 changes: 1 addition & 1 deletion Cargo.lock

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

2 changes: 1 addition & 1 deletion Cargo.toml
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
[package]
name = "mapbox-cli"
version = "0.2.0"
version = "0.2.1"
edition = "2021"
description = "A command-line interface for Mapbox APIs, with commands generated at build time from OpenAPI specs."
repository = "https://github.com/mapbox/cli"
Expand Down
5 changes: 2 additions & 3 deletions docs/commands.md
Original file line number Diff line number Diff line change
Expand Up @@ -629,9 +629,7 @@ Two details worth knowing:
is just as partial there, and the API's own document cannot carry the fact
without an envelope this CLI has promised not to add — so a `-o json`
consumer reading stdout alone is unaffected, and one watching stderr is
told. There is no `--all` yet; following the pages is the caller's job,
and [#117](https://github.com/mapbox/mapbox-cli-private/issues/117) tracks
changing that.
told. There is no `--all` yet; following the pages is the caller's job.
- **`--id` searches the page it was given.** On a paginated listing a miss
means "not on this page", which is not the same as "does not exist", so
the error says which and how to look further:
Expand Down Expand Up @@ -3497,6 +3495,7 @@ faults and are not:

| `request_timed_out` | The request ran out of its time budget. Its own code because it is the one transport failure worth retrying or raising `--timeout` for. |
| `missing_path_parameters` | A `{username}`/`{owner}`/`{account}` placeholder went unresolved. |
| `invalid_path_parameter` | A path parameter was `.` or `..`, which would move the request to a different endpoint. Other URL syntax in a path parameter (`/`, `?`, `#`, `\`) is percent-encoded rather than refused, so it names a segment instead of changing the URL's shape. |
| `invalid_data` | `--data` was not valid JSON, or a `@<path>`/`@-` body was empty. |
| `invalid_file` | A file could not be read: one named by `--file`, or one named by `--data @<path>`. Also a `@<path>` that is not valid UTF-8, which a JSON body has to be. |
| `binary_response` | The response was bytes and stdout is a terminal. Redirect it to a file. |
Expand Down
2 changes: 1 addition & 1 deletion scripts/install.ps1
Original file line number Diff line number Diff line change
Expand Up @@ -100,7 +100,7 @@
# installers, which are fetched and run in one line with no release notes
# in front of the reader - and breaking an opt-out is the one change that
# must not happen quietly. So both work here, and the new name wins when
# both are set. See mapbox/mapbox-cli-private#140.
# both are set.
#
# Unset, empty or whitespace is a cleared variable. `0`, `f`, `false`, `n`,
# `no` and `off` are clap's false spellings, the same reading this script
Expand Down
2 changes: 1 addition & 1 deletion scripts/install.sh
Original file line number Diff line number Diff line change
Expand Up @@ -78,7 +78,7 @@ INSTALL_SOURCE="${MAPBOX_CLI_INSTALL_SOURCE:-}"
# release notes in front of them — and breaking an opt-out is the one change
# that must not happen quietly. So both work here, the new name wins when both
# are set, and the old one keeps working for the Dockerfile the comment above
# describes. See mapbox/mapbox-cli-private#140.
# describes.
#
# Unset, empty, or whitespace: a cleared variable. `0`, `f`, `false`, `n`, `no`
# and `off` are clap's false spellings, so a `0` is someone declining the
Expand Down
3 changes: 1 addition & 2 deletions scripts/test-install.ps1
Original file line number Diff line number Diff line change
Expand Up @@ -517,8 +517,7 @@ try {
Start-Case 'MAPBOX_CLI_NO_TELEMETRY is honoured, and outranks the old name'
New-CaseEnv 'telemetry-new-name'
$env:MAPBOX_CLI_INSTALL_SOURCE = 'dockerfile'
# The documented name, which the binary reads and this script did not until
# mapbox/mapbox-cli-private#140.
# The documented name, which the binary reads and this script honours too.
$env:MAPBOX_CLI_NO_TELEMETRY = '1'
[IO.File]::WriteAllText($RequestLog, '')
Invoke-Installer
Expand Down
3 changes: 1 addition & 2 deletions scripts/test-install.sh
Original file line number Diff line number Diff line change
Expand Up @@ -666,8 +666,7 @@ shim curl-recording curl
CURL_LOG="${CASE_DIR}/curl-args"
export MAPBOX_TEST_CURL_LOG="$CURL_LOG"

# The documented name, which the binary reads and this script did not until
# mapbox/mapbox-cli-private#140.
# The documented name, which the binary reads and this script honours too.
: >"$CURL_LOG"
export MAPBOX_CLI_NO_TELEMETRY=1
run_piped && status=0 || status=$?
Expand Down
Loading