Feature: Add concise named progress stages and elapsed timings to qhx install.
Use -v or --debug for safe installer diagnostics while preserving
script-friendly standard output and redacting credentials.
Feature: Add private-CA HTTPS trust for source and mirror registries through
--qhx-ca-file and --mirror-ca-file. Custom CA trust remains separate from
the existing --qhx-insecure and --mirror-insecure plain-HTTP behavior and
is applied consistently to authentication, resolution, transfer, import, and
manifest verification.
Feature: Add repeatable --values, --set, and --set-string inputs for
online and offline installation, upgrades, and dry runs. Inputs follow Helm
merge precedence, while installer-owned image digests, registry destinations,
credentials, and Kubernetes variant values remain protected. This includes
supported Khaled storage and security-context customization.
Feature: Discover source-registry credentials from explicit flags, QHx environment variables, and standard Docker/OCI credential stores and helpers before prompting interactively. Noninteractive failures are explicit and credentials are never logged.
Feature: Add qhx --version using release build metadata, with useful version
information for development builds. Add a dedicated QHx CLI acquisition guide
covering architecture-specific and exact-version installation.
Bug: Publish and verify every required and selected optional installer image from the generated release inventory, including third-party dependencies, at the registry paths used by the installer. Multi-platform manifests are preserved and verified for amd64 and arm64.
Bug: Publish qhx/cli-oras and cabetool-oras as genuine amd64 and arm64 OCI
indexes, and verify that each supported platform pulls the documented
bin/qhx or bin/cabetool executable layout.
Security: Refresh affected Go dependencies, validate digest-pinned SPIRE candidate payloads, and scan both architecture builds and their packaged OCI images before release.
CI/CD: Expand release validation to exercise published CLI version reporting, both ORAS platform children, amd64 and arm64 package downloads, registry mirroring, and offline installation without hidden public-registry access.