Polyrepo
1.3.1
2026-10-09
- New: the Publish form and the Release wizard show the version a package has on npm next to the local one, with the filter Only ahead of npm, so it is clear what is worth publishing. See Web Interface.
- New: when a publish fails because npm wants a sign-in link, a security key or a passkey, the report offers Publish in a terminal: a terminal window opens in the package folder with the publish command, where npm can take the sign-in. Before, the interface could only ask for a one-time code. See Signing in by a link, a key or a passkey.
- New: rows in the package list are tinted by status: red for local changes, yellow for a version ahead of npm, and the accent color for a package that is not on npm.
- New: a Refresh button above the package list of every command form and of the Release wizard rereads the branches, the git state and the npm versions without reloading the page.
- Changed: the button that starts a command stays pinned to the bottom of the page, and so do the buttons of the Release wizard.
- Changed: the cards of a run that has several steps (a tag and then a release, for example) are stacked one under the other at the full width.
1.3.0
2026-10-08
- New:
polyrepo commitcommits whatnpm audit fix,npm updateorsync-depsleft in the working tree (package.jsonand the lock files, or every tracked change with--scope all) without stumbling over branch rules. On a feature branch the commit goes there. On the default branch polyrepo reads the host's rules (GitHub rulesets and branch protection, GitLab protected branches and your role): if direct commits are allowed it commits and pushes; if a pull/merge request is required, or the rules cannot be read, it creates a branch, commits there, pushes it, opens a PR/MR and leaves the default branch untouched. A direct push that the host refuses anyway moves the commit to a branch for you.--message,--mode,--branch,--no-push,--no-pr,--stay,--dry-run,--packagesand--yesadjust it. See Committing Changes. - New: the interface shows a partly fixed
npm audit fixas Partly done instead of a failure, with What is left grouped by the update that fixes each vulnerability, and buttons to preview--force, audit production dependencies only, update one dependency, or apply--forceafter a confirmation. Audit and outdated reports have one colored block per package with a prominent Fix vulnerabilities… / Update dependencies… button. See Fixing what a run found. - New: after a command that changes dependencies, the interface shows what changed in
package.jsonand the lock files, with the change topackage.jsonas a diff, and offers Commit… (the dialog reads the branch rules and recommends a direct commit or a branch and a PR/MR), Discard… and Run tests. - New: under every warning and failure the report suggests the next steps for that situation (commit or stash a dirty working tree, check the npm sign-in, publish again with a one-time password, switch to the default branch, run again, and more), and a finished bump, tag, publish, commit or clone suggests what usually comes next. A cancelled or interrupted run offers to run again and to check your setup, a run that did nothing is marked Needs attention, and the page says so when the server was stopped.
- New: after a command that changes repos, the Packages table refreshes just the packages it touched, in the background.
- New: URLs in reports and logs are clickable.
- Changed: one button style across the interface: neutral, primary, danger (outlined) and critical (solid, for irreversible confirmations), with icons and a soft shadow.
- Changed: report cards with long output take the full width, and the output of a failed command opens by itself. The Packages page and the reports show a centered spinner while they load, and no longer flash an empty state when you come back to Packages.
- Changed: the package is published without its tests and interface sources, and the web interface is rebuilt automatically before every publish.
- Fixed: on Windows an argument with spaces, such as the message of
git commit -m "chore: bump version", was split into several arguments, which broke commits made bybumpand other commands.git,gh,glabandnodeare now started directly, and every other command gets properly quoted arguments. - Fixed: commands started from the interface no longer print the
NO_COLOR … is ignored due to FORCE_COLORwarning.