spinframework/spin
66.6
Adequate · 29 September 2026
67.4k
lines of production code
Rust
primary language
2
measurements over time
What this system is
This system is the Spin WebAssembly runtime, designed to execute modular, secure WebAssembly components for serverless workloads. It provides a comprehensive CLI for building, managing, and deploying applications, supporting multiple languages and trigger types like HTTP, Redis, and timers. The runtime enforces strict security through a capability-based 'Factors' architecture that isolates and controls access to external resources such as databases, key-value stores, and network connections.
How it got here
2021–2023 — Spin v2 migration and factors architecture
84 changes.
The project underwent a major architectural restructuring to support the Spin manifest v2 format and a new 'Factors' plugin system for modular host capabilities. This period focused on migrating the CLI, templates, and examples to the new standards while introducing comprehensive testing infrastructure and expanding support for multiple languages and backend services.
2024 — Factors runtime architecture and outbound connectivity
54 changes.
This period focused on restructuring the Spin runtime around a modular 'Factors' system to manage host capabilities, replacing the previous monolithic model. It introduced dedicated factors for outbound networking, databases (PostgreSQL, MySQL, Redis, SQLite), and LLM inference, each with strict security controls and connection limits. Comprehensive testing and configuration infrastructure were built to support this new architecture and the expanded set of external integrations.
2025–2026 — modularization and capability security
28 changes.
This period focused on restructuring the codebase into dedicated crates for routing, networking, variables, and TLS to improve modularity and maintainability. It introduced a secure-by-default capability model with automatic detection and denial of unused permissions, alongside new features for environment validation, OpenTelemetry telemetry, and HTTP middleware support.
Features
Add AWS DynamoDB key-value store implementation
Users can now use AWS DynamoDB as a backend for the key-value store factor. This change introduces a new \AwsDynamoKeyValueStore\ that supports runtime configuration for region, table name, and authentication (via explicit credentials or environment variables). It also adds support for strongly consistent reads to improve atomicity in operations like compare-and-swap.
crates/key-value-aws · high confidence
Add Azure Cosmos DB key-value store implementation
Introduces a new key-value store backend for Azure Cosmos DB, allowing applications to persist data in a Cosmos DB container. The implementation supports authentication via explicit account keys or environmental credentials (including Workload Identity and Managed Identity), and optionally uses an app ID to partition data within a shared container. It also includes validation to reject keys containing illegal characters (/, \\, ?, \#) and enforces result size limits on get operations.
crates/key-value-azure · high confidence
Add C and Zig HTTP application templates
New starter templates for C and Zig HTTP components are now available, allowing users to scaffold projects using these languages. The C template provides a basic \main.c\ entry point and a build command targeting \wasm32-wasi\, while the Zig template includes a \src/main.zig\ source file and corresponding build instructions. Both templates are configured for the Spin manifest v2 schema, use kebab-case naming for the application, and include \.gitignore\ files to exclude build artifacts and the \.spin\ directory.
templates/http-c/content, templates/http-zig/content · high confidence
Add C++ HTTP example application
Introduces a new C++ example for the Spin HTTP trigger, allowing users to build and run a simple C++-based HTTP component. The example includes source code (lib.cpp), a Makefile for building the WASM binary using WASI SDK and wit-bindgen, and a spin.toml manifest configured for the v2 schema.
examples/http-cpp · high confidence
Add Grain HTTP template for Spin applications
Users can now scaffold new Spin HTTP applications using the Grain language. This change introduces a new template that generates a \spin.toml\ manifest (v2) with a Wagi HTTP trigger, a \main.gr\ source file printing a Hello World response, and a \.gitignore\ file. The template configures the build process to compile Grain to WebAssembly and sets an empty \allowed\_outbound\_hosts\ list for security.
templates/http-grain/content · high confidence
Add HashiCorp Vault variable provider
Users can now resolve application variables from a HashiCorp Vault instance. The new \VaultVariablesProvider\ supports configuration via server URL, authentication token, KV engine mount point, and an optional key prefix, allowing secrets stored in Vault's KV v2 engine to be used as configuration values.
crates/variables-vault · high confidence
Add OpenAI-compatible remote LLM provider
Users can now connect to remote inference services that follow the OpenAI API specification. This change introduces the \AgentEngine\ implementation in the \llm-remote-http\ crate, which handles remote chat completions and embeddings by sending HTTP POST requests to \/v1/chat/completions\ and \/v1/embeddings\ endpoints. The implementation manages authentication via Bearer tokens, serializes requests using defined schemas (supporting parameters like \max\_completion\_tokens\ and \frequency\_penalty\), and deserializes responses into the system's internal LLM result types.
_crates/llm-remote-http/src/open\ai · high confidence
Add Redis-backed key-value store implementation
A new \spin-factor-key-value\ implementation for Redis is introduced in the \crates/key-value-redis\ crate. This adds a \RedisKeyValueStore\ that connects to a Redis server via a configurable URL, providing standard key-value operations (get, set, delete, exists) and key listing. The implementation enforces result size limits to prevent excessive memory usage and uses an asynchronous connection manager for efficient I/O.
crates/key-value-redis · high confidence
Add Spin 3.x-compatible HTTP Rust template
Introduces a new \http-rust-p2\ template for generating Rust-based HTTP components that are compatible with Spin 3.x hosts. The template scaffolds a project using \spin-sdk\ version 5.2.0, targets the \wasm32-wasip1\ architecture, and utilizes the Spin manifest v2 format (\spin\_manifest\_version = 2\) for configuration, allowing users to quickly start new HTTP services on modern Spin runtimes.
templates/http-rust-p2, templates/http-rust-p2/content · high confidence
Add UI testing crate for golden file snapshots
The new \crates/ui-testing\ crate provides a framework for UI (golden file) testing, allowing developers to define and run snapshot tests that compare application output against expected results. It includes a \UiTestsRunner\ to manage test cases, a \Normalizer\ to handle path and cache directory variations for reproducible snapshots, and support for both synchronous and asynchronous test runners via \libtest\_mimic\ and \snapbox\.
crates/ui-testing · high confidence
Add VS Code dev container with multi-language tooling
Developers can now use a pre-configured VS Code dev container to work with Rust, Go, TinyGo, Grain, and AssemblyScript. The container image installs Go 1.22, TinyGo 0.35.0, the gopls language server, rust-analyzer, Grain v0.4.7, and AssemblyScript via Node.js 17.9.0, and configures VS Code extensions for Rust, Go, and Grain. On startup, it sets the default Rust toolchain and registers WebAssembly targets (wasm32-wasip1, wasm32-wasip2, and wasm32-unknown-unknown).
.devcontainer · high confidence
Add Vault variable provider example with constant-time comparison
This change introduces a new example application (\examples/vault-variable-test\) that demonstrates how to use the Vault Application Variable Provider to retrieve secrets at runtime. The example includes a Rust component that fetches a token from Vault via the variables API and uses the \constant\_time\_eq\ library to securely compare the provided token against the stored secret, returning a JSON response indicating whether authentication was accepted or denied. Configuration files (\spin.toml\, \runtime\_config.toml\) and documentation (\README.md\) are included to guide users through setting up a local Vault instance and running the example.
examples/vault-variable-test · high confidence
Add WAGI HTTP trigger support with CGI header mapping
The WAGI HTTP trigger implementation is added to the \crates/http/src/wagi\ module, introducing support for running WAGI-compliant WebAssembly applications via HTTP. This change includes the necessary license file and core logic to map incoming HTTP requests to CGI-style environment variables (such as \REQUEST\_METHOD\, \PATH\_INFO\, \QUERY\_STRING\, and \SERVER\_NAME\) that WAGI applications expect. It also implements host header parsing to determine the correct server name and port, ensuring compatibility with existing WAGI-based workloads.
crates/http/src/wagi · high confidence
Add outbound MQTT factor with connection and payload limits
A new outbound MQTT factor has been added, enabling Spin applications to connect to and publish messages on MQTT brokers. This factor enforces security and resource limits configurable via the \\[outbound\_mqtt\]\ section in the runtime TOML: \max\_connections\ limits concurrent connections, \wait\_timeout\ controls how long the system waits for a connection permit, and \max\_payload\_size\_bytes\ restricts the size of published messages to prevent excessive resource usage.
crates/factor-outbound-mqtt/src · high confidence
Add remote LLM inference via HTTP
Users can now offload LLM inference and embedding generation to a remote HTTP service. This new \llm-remote-http\ crate implements the \wasi\_llm\ v2 interface, supporting both a default inference protocol and an OpenAI-compatible API mode. It handles authentication via bearer tokens, injects distributed tracing context, and enforces a configurable limit on response body sizes to prevent excessive memory usage.
crates/llm-remote-http/src · high confidence
Add support for libSQL and configurable SQLite database types
The SQLite runtime configuration now supports two database backends: the default local SQLite database and a new libSQL backend. Users can configure these via the \sqlite\_database\ TOML section by specifying \type = "spin"\ for local files (with optional \path\ and \allow\_attach\_file\ settings) or \type = "libsql"\ for remote libSQL instances (requiring \url\ and \token\). The \RuntimeConfigResolver\ handles the creation of appropriate connection creators for each type, allowing applications to choose their storage backend through configuration.
crates/sqlite · high confidence
Added WASI OpenTelemetry host component for telemetry data conversion
This change introduces a new WASI OpenTelemetry host component in \crates/world/src/wasi\_otel\ that bridges WASI telemetry interfaces with the OpenTelemetry Rust SDK. It provides conversion logic for logs, metrics, and traces, allowing applications to export telemetry data (such as log records, resource metrics, and span data) from the WASI environment into standard OpenTelemetry formats for downstream processing.
_crates/world/src/wasi\otel · high confidence
Added async stream producer for WASI component model
The wasi-async crate now exposes a StreamProducer implementation that bridges Tokio channels to the Wasmtime component model. This allows asynchronous data streams to be produced from Rust code into WebAssembly components, enabling efficient, non-blocking data transfer between the host and guest environments.
crates/wasi-async · high confidence
Added build automation for the deny adapter
A new Makefile has been introduced in the capabilities crate to streamline the build process for the deny adapter. It provides targets to compile the adapter to WebAssembly and verify that the generated WIT (WebAssembly Interface Types) matches the committed version, ensuring consistency in CI environments when WITs or the crate itself changes.
crates/capabilities · high confidence
Automatic capability detection and selective denial for Spin components
Spin now automatically infers which capability sets (such as AI models, outbound hosts, environment, files, key-value stores, SQLite databases, and variables) a Wasm component requires by inspecting its imports against known interface names. When composing components, a deny adapter is applied to block any host capabilities that are not explicitly inherited, ensuring that dependencies only access resources the parent component has permission to use. This provides a secure-by-default model where unneeded capabilities are denied at runtime.
crates/capabilities/src · high confidence
Configurable key-value store resolution via TOML
The Spin CLI now supports flexible key-value store configuration through a new \RuntimeConfigResolver\. Users can define multiple store types and assign default stores to specific labels via TOML configuration. The resolver parses the \key\_value\_store\ section, instantiates the appropriate store managers based on registered types, and ensures default stores are applied when no explicit configuration is provided for a label.
_crates/factor-key-value/src/runtime\config · high confidence
Configurable outbound networking and client TLS support
Users can now configure outbound networking restrictions and client TLS settings via the runtime configuration. The \\[outbound\_networking\]\ table allows blocking specific IP CIDRs or private networks, and setting limits on maximum socket and total connections. Additionally, the \\[\[client\_tls\]\]\ array enables per-component TLS configuration, including specifying allowed hosts, custom CA roots (from files, platform roots, or WebPKI), and client certificates for mutual TLS.
_crates/factor-outbound-networking/src/runtime\config · high confidence
Detect missing Wasm source files and offer to rebuild them
The doctor now includes a new diagnostic that checks whether the source files referenced by Wasm components actually exist on disk. If a source file is missing, the tool reports the specific component and path, and if the application is configured to build that component, it offers a treatment to run \spin build\ to regenerate the missing Wasm artifact.
crates/doctor/src/wasm · high confidence
Experimental WASI OTel host support for guest telemetry
The \crates/factor-otel\ module now implements the WASI OTel host bindings, allowing guest components to export OpenTelemetry traces, metrics, and logs through the Spin runtime. This feature is gated behind an experimental flag; when enabled, the runtime links the \wasi:otel/tracing\, \wasi:otel/metrics\, and \wasi:otel/logs\ interfaces and configures batch processors for spans, logs, and metrics based on standard \OTEL\EXPORTER\\*\ environment variables. The implementation supports gRPC and HTTP/Protobuf protocols for all three signal types, while explicitly rejecting HTTP/JSON. If experimental support is enabled but no exporter environment variables are set, a warning is logged indicating that no telemetry will be exported.
crates/factor-otel · high confidence
Extract dependency WIT definitions during build
The \crates/dependency-wit\ crate now automatically extracts and generates WIT (WebAssembly Interface Types) files for application dependencies during the build process. This enables the runtime to inspect component interfaces, identify HTTP middleware, and format dependency exports consistently, ensuring that generated WIT files accurately reflect the imported interfaces and are cleaned up when no dependencies remain.
crates/dependency-wit · high confidence
Initial Redis Rust template with Spin SDK 7.0.0 and WASI-P2 target
Added a new Rust-based template for building Redis subscriber components using the Spin framework. The template uses the Spin SDK v7.0.0, targets the wasm32-wasip2 architecture, and follows the spin\_manifest\_version 2 schema. It includes a basic Redis subscriber component that prints incoming messages, with build instructions configured for the WASI-P2 target. The template also includes a .gitignore file to exclude build artifacts and the .spin directory.
templates/redis-rust/content · high confidence
Initial release of the HTTP PHP application template
Users can now scaffold new Spin applications using PHP 8.2. The template generates a project configured for the Spin manifest v2, including a .gitignore file that excludes the .spin directory, a spin.toml manifest defining the application metadata and HTTP trigger, and a basic index.php entry point. The configuration sets the component executor to Wagi and initializes an empty list for allowed outbound hosts.
templates/http-php/content · high confidence
Introduce LockedApp crate for resolved application configuration
A new \locked-app\ crate has been added to provide internal interfaces for Spin application configuration, specifically targeting trigger executors and host components. This crate defines the data structures for a "locked" application state (the \spin.lock\ file), including models for \LockedApp\, \LockedTrigger\, and \LockedComponent\. It introduces support for host requirements such as local service chaining and middleware, allowing hosts to validate whether they support the features required by an application. The crate also provides utilities for handling application metadata (name, version, description, OCI digest) and managing custom configuration variables, ensuring deterministic serialization and robust error handling for configuration-related issues.
crates/locked-app · high confidence
Introduce Redis trigger for subscribing to channels
Added a new Redis trigger that allows Spin applications to subscribe to Redis channels and invoke components when messages are received. The trigger supports resolving the server address and channel name via template expressions, enabling flexible configuration. It handles connections to multiple Redis servers and channels, dispatching incoming messages to the appropriate components while providing tracing and OpenTelemetry metrics for observability.
crates/trigger-redis · high confidence
Introduce RuntimeFactors derive macro for automatic factor lifecycle management
The new \RuntimeFactors\ derive macro in \crates/factors-derive\ automatically generates the implementation of the \RuntimeFactors\ trait for structs containing factor fields. This macro handles the boilerplate for initializing factors, configuring the application, preparing instance builders, and building instance state, while also enforcing uniqueness of factor types and managing the underlying Wasmtime \ResourceTable\. Users can now define their runtime factors as simple struct fields and rely on the macro to wire up the lifecycle hooks (\init\, \configure\_app\, \prepare\, \build\_instance\_state\) and state accessors (\app\_state\).
crates/factors-derive · high confidence
Introduce SQLite Factor for component-scoped database access
The new SQLite factor enables Spin components to interact with SQLite databases through a structured, secure interface. It enforces a whitelist of allowed databases per component via the \databases\ metadata key, ensuring components can only access explicitly configured stores. The factor integrates with OpenTelemetry for observability, recording database backend details and query execution spans, and supports runtime configuration to map database labels to connection creators dynamically.
crates/factor-sqlite/src · high confidence
Introduce Spin manifest V2 format with component dependencies and target environments
The manifest schema now supports a new V2 format (spin\_manifest\_version = 2) that restructures the application definition under an \[application\] section and introduces several new capabilities. Components can now declare dependencies on other components, registry packages, or remote URLs via the new \dependencies\ field, with optional configuration inheritance. The schema adds \targets\ at both the application and component level to declare compatibility with specific Spin runtime environments (target environments). Additionally, the deprecated \allowed\_http\_hosts\ field is replaced by the more general \allowed\_outbound\_hosts\, and build configurations now support multiple sequential commands and named profiles for overrides.
crates/manifest/src/schema · high confidence
Introduce \`spin doctor\` subcommand for automatic app health checks
The \spin doctor\ subcommand is now available to automatically detect and fix common issues in Spin applications. It analyzes the app manifest and environment to identify problems such as outdated manifest versions (v1 to v2), missing Wasm source files, incorrect Rust Wasm targets, and invalid trigger configurations. For each detected issue, the tool provides a summary and can automatically apply fixes, such as upgrading the manifest schema or correcting file paths, ensuring apps are correctly configured before deployment.
crates/doctor/src · high confidence
Introduce centralized runtime configuration crate for Spin factors
A new \crates/runtime-config\ crate has been added to centralize the resolution and management of runtime configuration for Spin factors. This change introduces a \ResolvedRuntimeConfig\ structure that consolidates settings for key-value stores, SQLite databases, LLM compute, and various outbound network connections (HTTP, Redis, PostgreSQL, MySQL, MQTT), including support for connection limits and memory usage caps. It also integrates variable provider configurations (Azure Key Vault, HashiCorp/OpenBao Vault, Static, and Environment) into the runtime resolution process. Users benefit from a unified configuration source that automatically summarizes active settings (such as connection limits and store types) at startup, ensuring consistent behavior across factors like triggers and CLI operations.
crates/runtime-config · high confidence
Introduce component dependency composition and HTTP middleware pipelines
The \crates/compose\ crate now provides the core logic for composing Spin components. It introduces a \compose\ function that links dependent components by matching dependency names to import names, applying configuration inheritance, and wiring exports to imports within a WAC composition graph. Additionally, it adds a \compose\_middleware\_pipeline\ function that chains HTTP middleware components (adhering to the \wasi:http/handler@0.3.0\ interface) in front of a primary component, applying deny adapters based on capability inheritance settings. This enables users to define components that rely on other components and to insert middleware into the request handling chain.
crates/compose · high confidence
Introduce plugin management infrastructure
The \crates/plugins/src\ module now provides the core backend for the Spin plugin system. It introduces a \PluginManager\ to handle installing, uninstalling, and locating plugins, and a \Catalogue\ that tracks available plugins by cloning the \spinframework/spin-plugins\ Git repository. The system supports installing plugins from the central repository, local files, or remote URLs, and enforces compatibility checks against the running Spin version. It also records installation sources and provides specific error handling for missing plugins, connection failures, and invalid manifests.
crates/plugins/src · high confidence
Introduces configurable global and per-factor connection limits with telemetry
The \connection-semaphore\ crate now supports hierarchical connection limiting, allowing operators to configure both a global limit shared across connection types and a separate limit for specific factors. This change introduces a \ConnectionSemaphore\ that acquires permits from both levels (factor-specific first, then global) to prevent global slots from being held while waiting for factor-specific backlogs. It also adds configurable wait timeouts for acquiring permits and emits OpenTelemetry metrics (counters and histograms) to track acquisition success, wait durations, and rejection events, aiding in monitoring and capacity planning.
crates/connection-semaphore · high confidence
Introduction of a generic resource table for opaque identifier management
A new \Table\ component has been added to the \crates/table\ library to manage unique u32 identifiers for dynamically changing resources. This generic structure allows opaque resources and their lifetimes to be managed across interface boundaries, similar to how file handles are managed in a user-kernel context. It provides methods to push new resources, retrieve them by key, and remove them, ensuring unique allocation while handling capacity limits.
crates/table · high confidence
Introduction of dedicated TLS crate with crypto provider installation
A new \crates/tls\ crate has been added, exposing the \install\_default\_crypto\_provider\ function. This function configures the process-wide rustls crypto provider using the ring backend, ensuring it is installed only once and failing if a provider is already present.
crates/tls · high confidence
Introduction of the Badger plugin update notification system
A new 'Badger' system has been added to the plugin manager to proactively notify users when compatible plugin updates are available. This feature runs a background check to compare the currently installed plugin version against the registry, respecting a 14-day cooldown period to avoid repetitive prompts. Notifications are only displayed in interactive terminal sessions, and the system persists user interaction history in a local JSON file to ensure users are not nagged for the same upgrade repeatedly.
crates/plugins/src/badger · high confidence
Introduction of the spin-app crate for application configuration management
The new \spin-app\ crate provides the core internal interfaces for managing Spin application configuration, serving as the primary interface for trigger executors and host components. It introduces the \App\ struct, which wraps a \LockedApp\ in an \Arc\ to enable efficient cloning and shared access across the runtime. This change centralizes metadata handling, allowing typed extraction of app-level metadata (such as name, version, and OCI digest) and trigger-specific configurations. It also standardizes iteration over components and triggers, and includes logic to handle backward compatibility for legacy trigger metadata formats while ensuring that component filtering and validation are correctly scoped to the retained components.
crates/app · high confidence
New HTTP middleware example application
Added a new Spin application example in the \examples/http-middleware\ directory that demonstrates how to author and use HTTP middleware. The example configures a main application component (\hello\) that reads a custom header, and chains two middleware components (\animal-fact\ and \yelling\) to modify incoming requests and outgoing responses, respectively.
examples/http-middleware · high confidence
New HTTP middleware examples for header injection and response transformation
Added two new middleware examples in the \examples/http-middleware\ directory. The \animal-fact\ example demonstrates how to inject a custom header into an incoming request by fetching data from an external API before passing the request down the pipeline. The \yelling\ example shows how to transform an outgoing response body to uppercase text using streaming, allowing users to see practical patterns for modifying requests and responses within the Spin HTTP middleware chain.
examples/http-middleware/animal-fact, examples/http-middleware/yelling · high confidence
New OpenAI Rust example using Spin v2 manifest and wasip2
Adds a new example application demonstrating how to use the Spin SDK to perform LLM inference via the OpenAI API. The example is built for the wasip2 target and uses the Spin v2 manifest format, configuring an HTTP trigger to call the 'gpt-oss:20b' model and return the generated text and token usage statistics.
examples/open-ai-rust · high confidence
New OpenTelemetry-based telemetry system with HTTP/protobuf support
Spin now uses a new OpenTelemetry-based telemetry system that supports both gRPC and HTTP/protobuf protocols for exporting traces, metrics, and logs. The system automatically detects OTel configuration from environment variables (OTEL\_EXPORTER\_OTLP\_ENDPOINT, etc.) and defaults to HTTP/protobuf. It includes a custom resource detector that sets service.name and service.version, supports W3C TraceContext propagation, and provides macros for recording counters, up/down counters, and histograms. Application logs are forwarded to OTel and can also be emitted as tracing events. The system uses rustls for TLS and includes a development alerting layer for warnings.
crates/telemetry · high confidence
New PostgreSQL outbound factor with connection pooling and type support
The \factor-outbound-pg\ crate introduces a new outbound PostgreSQL factor that manages database connections via a pooled \ClientFactory\ (using \deadpool-postgres\ and \moka\ for caching) and enforces an allow-list of permitted hosts via \AllowedHostChecker\. It implements the \spin::postgres\ WIT interfaces (v1 through v4.2.0), providing structured error handling, OpenTelemetry tracing, and support for a wide range of PostgreSQL data types including dates, timestamps, UUIDs, JSONB, decimals, ranges, and arrays.
crates/factor-outbound-pg/src · high confidence
New Redis Go application template for Spin v2
A new template for generating Redis-triggered Go applications has been added, targeting the Spin v2 manifest schema. The generated project uses the spin-go-sdk v3 for handling Redis payloads and includes a .gitignore file to exclude build artifacts (main.wasm) and the .spin directory. The template configures the application with a kebab-cased name, specifies the Redis address and channel via variables, and sets up the build command using componentize-go.
templates/redis-go/content · high confidence
New WASI factor with socket connection limits and multi-version support
The \crates/factor-wasi\ crate introduces a new WASI implementation factor that supports multiple WASI preview versions (2023-10-18, 2023-11-10, and 2026-03-15) and enforces a configurable limit on the number of concurrently open TCP and UDP sockets per application. It provides synchronous I/O wrappers for standard streams to handle multi-subcomponent scenarios and integrates with the Spin file mounting system to handle directory mounts with transient write permissions.
crates/factor-wasi/src · high confidence
New \`spin build\` command and \`spin targets\` command for managing deployment environments
Spin now includes a dedicated \spin build\ command to compile applications, supporting options for build profiles, specific component IDs, and skipping target compatibility or WIT generation checks. Additionally, a new \spin targets\ command allows users to list and update known target environments, enabling better control over which deployment platforms are available for building and deploying applications.
src/commands · high confidence
New \`spin build\` command with V2 manifest support and per-component builds
Spin now includes a dedicated \spin build\ command (implemented in the new \crates/build\ library) that processes Spin V2 manifests, allowing users to build individual components by ID and optionally skip WIT dependency generation. The build process extracts dependency WITs, supports build profiles, and validates that built components are compatible with declared deployment targets, while maintaining backward compatibility with V1 manifest structures for build configuration.
crates/build/src · high confidence
New automation scripts for SDK bumps, WIT publishing, and Wasmtime release finalization
Added several new shell scripts to streamline release and maintenance workflows: \bump-rust-examples-sdk.sh\ and \bump-rust-template-sdk.sh\ now automate updating the \spin-sdk\ dependency in Rust examples and templates respectively, handling version validation and stripping the leading 'v'; \build-and-publish-wit.sh\ handles building and publishing the spin:up WIT package to the spinframework.dev registry; \push-env-def.sh\ publishes environment TOML definitions to GitHub Container Registry; and \wasmtime-release.sh\ provides subcommands to finalize Wasmtime version bumps by rewriting git dependencies to crates.io versions and managing backports to release branches.
scripts · high confidence
New key-value storage factor with concurrency limits and multi-store support
The \crates/factor-key-value\ crate introduces a new factor that provides key-value storage capabilities to Spin applications. It supports multiple backend store types (such as Redis, SQLite, and Azure Cosmos DB) via a pluggable \StoreManager\ interface, allowing components to access specific stores by label. The factor enforces per-component access control, ensuring components can only interact with explicitly allowed stores. Additionally, it introduces app-wide concurrency limiting for key-value operations through a configurable maximum concurrent operation count and a wait timeout, preventing resource exhaustion under high load. The implementation integrates with OpenTelemetry for tracing and supports multiple API versions (v1, v2, v3, and WASI key-value) for guest access.
crates/factor-key-value/src · high confidence
New outbound MySQL factor with connection limits and async streaming
Spin now includes a dedicated outbound MySQL factor that allows WebAssembly components to connect to MySQL databases. This factor implements the v1, v2, and v3 MySQL interfaces, supporting both synchronous and asynchronous query execution. A key feature is the ability to limit the number of concurrent outbound MySQL connections via the \max\_connections\ configuration option in the \outbound\_mysql\ TOML section, helping prevent resource exhaustion. The implementation also enforces address allow-listing for security and includes result size limits to protect against excessive memory usage.
crates/factor-outbound-mysql/src · high confidence
New outbound Redis factor with connection limits and host allow-listing
This change introduces the \outbound-redis\ factor, enabling Spin applications to connect to Redis instances. It enforces security by validating Redis addresses against an allowed-hosts list and blocking specific networks. To prevent resource exhaustion, it implements a configurable global connection limit (via \max\_connections\ in the \\[outbound\_redis\]\ TOML section) and a wait timeout, using a semaphore to manage concurrent connections across all instances of an application. The factor supports Redis v1, v2, and v3 APIs, including operations like GET, SET, PUBLISH, and generic command execution, while integrating with OpenTelemetry for tracing.
crates/factor-outbound-redis/src · high confidence
New outbound networking configuration crate
A new \outbound-networking-config\ crate has been introduced to centralize outbound networking rules. It provides \OutboundAllowedHosts\ for validating URLs against allowed host patterns (including schemes, hosts, and ports) and \BlockedNetworks\ for filtering IP addresses based on CIDR ranges and private network blocking. This module serves as the core configuration engine for controlling which outbound network requests are permitted or denied.
crates/outbound-networking-config · high confidence
New outbound networking factor with connection limits and TLS configuration
The \factor-outbound-networking\ crate introduces a dedicated factor for managing outbound network access, replacing the previous inline implementation. It adds runtime configuration for global and per-socket connection limits (\max\_total\_connections\, \max\_socket\_connections\) to prevent resource exhaustion, and supports granular TLS client configuration including platform roots, webpki roots, custom root certificates, and mutual TLS (mTLS) per component and host. The factor also enforces \allowed\_outbound\_hosts\ policies, including validation of service chaining targets to ensure components only connect to retained app components, and blocks private or specified IP networks.
crates/factor-outbound-networking/src · high confidence
New serialization helpers for component dependencies and identifiers
The \crates/serde\ library now provides new types to support component dependencies and stricter identifier validation. It introduces \DependencyName\ and \DependencyPackageName\ to parse and serialize dependency references (including package specs, versions, and interfaces), and adds a generic \Id\ type that validates word separators and character constraints, offering improved error messages for common mistakes like using the wrong delimiter. Additionally, new \FixedVersion\ types enforce strict or backward-compatible version checks during deserialization, and a \base64\ module adds custom serialization for byte arrays.
crates/serde · high confidence
New spin-factors-test crate for testing RuntimeFactors
The new \spin-factors-test\ crate provides a \TestEnvironment\ helper to simplify testing \RuntimeFactors\ implementations. It allows tests to construct a default manifest, extend it with specific component configurations, apply runtime configuration, and build instance state for the last component defined in the manifest.
crates/factors-test · high confidence
New spin-oci crate for OCI registry integration
Spin now includes a dedicated \spin-oci\ crate that centralizes all logic for pushing and pulling Spin applications to and from OCI registries. This change introduces a new authentication system that reads credentials from \registry-auth.json\, a client capable of pushing composed applications with configurable assembly modes (simple or archive layers), and a loader that resolves cached OCI artifacts for execution. It also adds validation to ensure all component sources and dependencies are valid WebAssembly binaries before distribution.
crates/oci · high confidence
New terminal output library with colored, structured logging
The \crates/terminal\ crate now provides a dedicated library for formatted terminal output, replacing previous ad-hoc printing logic. It introduces macros (\step\, \warn\, \error\, \einfo\, \cprint\, \ceprint\, \ceprintln\) that automatically apply color coding (green for steps, yellow for warnings, red for errors, cyan for info) and ensure colors are reset after use. This change standardizes how Spin displays build and deployment status, making output more readable and consistent across commands like \spin build\ and \spin up\.
crates/terminal · high confidence
New test-codegen-macro crate for automatic runtime test generation
A new \test-codegen-macro\ crate has been introduced to automatically generate \\#\[test\]\ functions for runtime tests based on the directory structure under \tests/runtime-tests/tests\. This macro eliminates the need for developers to manually write corresponding test functions when adding new runtime tests, streamlining the test maintenance process.
crates/test-codegen-macro · high confidence
New trigger crate with unified CLI and component loading
The \crates/trigger\ crate introduces a new \FactorsTriggerCommand\ that centralizes common CLI options for all Spin triggers, including \--log-dir\, \--truncate-logs\, \--disable-cache\, \--cache\, \--disable-pooling\, \--debug-info\, \--follow\, \--quiet\, \--runtime-config-file\, \--state-dir\, and \--experimental-wasm-feature\. It also provides a new \ComponentLoader\ that supports loading AOT precompiled components when the \unsafe-aot-compilation\ feature is enabled, and handles loading composed components with trigger dependencies.
crates/trigger/src · high confidence
New variable expression resolution system with template support
The \crates/expressions\ crate introduces a new system for resolving application variables, supporting string templates with \{{ expression }}\ syntax. This change adds a \Provider\ trait for dynamic variable sources, a \ProviderResolver\ for asynchronous resolution across multiple providers, and a \Template\ struct for parsing and displaying variable expressions. It also includes validation to ensure required variables are potentially resolvable by at least one provider, improving reliability when variables depend on external configuration sources.
crates/expressions/src · high confidence
Repository governance, documentation, and build infrastructure established
The repository now includes foundational governance and contribution documentation, including AGENTS.md (repository guidelines), CODE\_OF\_CONDUCT.md, CONTRIBUTING.md, GOVERNANCE.md, MAINTAINERS.md, ROADMAP.md, and SECURITY.md. Build and development workflows are standardized via a new Makefile, a Nix flake (flake.nix/flake.lock) for the development shell, and a Cross.toml for cross-compilation. The project license is set to Apache-2.0 with an LLVM exception, and the README has been updated with current usage instructions and language support tables. Build hygiene is improved with a .dockerignore file and updated .gitignore rules, while the legacy readme.md has been removed.
(repo-wide) · high confidence
SQLite-backed key-value store implementation for Spin
This change introduces a new key-value store implementation for Spin applications that uses SQLite as the backend. The \crates/key-value-spin\ crate provides a \SpinKeyValueStore\ that supports both in-memory databases (for ephemeral use) and persistent file-based databases (configurable via runtime configuration paths). It implements the standard key-value operations (get, set, delete, exists, get\_keys) with result size limiting to prevent excessive memory usage, and handles atomic operations and error mapping for the WASI key-value interface.
crates/key-value-spin · high confidence
Spin CLI adds dependency management, build info, and shell completions
The Spin CLI now includes a new \spin dependencies\ command (with \add\, \source\ parsing, and resolution logic for local, HTTP, registry, and component sources) to manage Wasm component dependencies. It also exposes build metadata (version, commit SHA, date, branch, target, profile) via the \build\_info\ module, and provides shell completion support for profiles, components, and environments through the \completions\ module. Additionally, it introduces helpers for directory relationship notifications (\directory\_rels\), optional flag value handling (\opt\_value\), environment parsing (\parse\_env\), and subprocess exit status propagation (\subprocess\), while reorganizing command modules in \commands.rs\ and \lib.rs\ to expose these new capabilities.
src · high confidence
Spin Doctor diagnoses and fixes manifest configuration issues
The \spin doctor\ command now includes specific diagnostics for the application manifest. It detects and can automatically fix missing or incorrect \spin\_manifest\_version\ fields, replacing the deprecated \spin\_version\ key or correcting invalid values. It also identifies missing trigger configurations, such as absent top-level triggers or missing \route\ fields on HTTP components, and can apply default fixes (like adding a default HTTP trigger or setting a route for single-component apps). Additionally, it detects Manifest V1 files and offers an upgrade path to V2, backing up the original file before writing the converted manifest.
crates/doctor/src/manifest · high confidence
Support for static variables via CLI flags and file sources
Users can now provide static variables directly via the CLI using the \--variable\ flag. This supports literal key-value pairs (e.g., \--variable key=value\), loading a single variable's value from a file using the \@\ prefix (e.g., \--variable key=@path/to/file\), and loading multiple variables from JSON or TOML files (e.g., \--variable @path/to/config.json\). The implementation introduces a \StaticVariablesProvider\ that resolves these values from an in-memory map, enabling flexible configuration without external secret managers for static data.
crates/variables-static · high confidence
Target environment validation and definition system
The \crates/environments\ crate now provides a complete system for defining, loading, and validating target deployment environments. Users can specify target environments via a catalogue (hosted in git), HTTP URLs, or local files, with definitions describing supported trigger types, WIT worlds, and host capabilities. The system validates application components against these environments at build time, ensuring compatibility with the target platform's supported worlds and configuration constraints (such as allowed key-value stores or AI models). It also manages caching and lockfiles to optimize loading performance.
crates/environments · high confidence
Removals
Removal of the spin-engine crate
The \spin-engine\ crate has been removed from the codebase. This deletion eliminates the previous generic execution context and engine configuration structures that were previously used to manage WebAssembly module execution, environment variables, and preopened directories.
crates/engine · high confidence
Architecture
Extracted HTTP route matching logic into a dedicated \`crates/routes\` crate
The HTTP trigger's route matching and resolution logic has been moved from the main application code into a new, standalone \crates/routes\ crate. This change introduces a dedicated \Router\ struct that handles building route tables from application configuration, resolving paths to specific component IDs via the \routefinder\ library, and managing duplicate route detection. For users, this represents a structural reorganization that isolates routing concerns, potentially improving maintainability and testability of the HTTP trigger's path-matching behavior without altering the external routing API.
crates/routes · high confidence
Introduce FactorsExecutor for modular Spin app execution
This change introduces the \FactorsExecutor\ and \FactorsExecutorApp\ types in the \crates/factors-executor\ crate, establishing a new architecture for managing Spin app lifecycles. The \FactorsExecutor\ now handles app configuration, component loading via the \ComponentLoader\ trait, and execution hooks through the \ExecutorHooks\ trait, allowing factors to inject behavior during app setup and instance preparation. This modularizes the execution engine, separating core engine management from factor-specific logic and enabling more flexible component dependency handling.
crates/factors-executor · high confidence
Introduce Spin Factors architecture and restructure core crates
The Spin codebase has been restructured around a new 'Factors' plugin system, which modularizes host capabilities (such as key-value stores, outbound networking, SQLite, and LLMs) into separate crates (e.g., \spin-factor-key-value\, \spin-factor-outbound-http\). This change introduces new core crates like \spin-factors\, \spin-factors-executor\, and \spin-factors-test\ to manage these capabilities, while existing functionality is migrated into this new architecture. The diff also shows the addition of several new workspace crates (e.g., \spin-app\, \spin-build\, \spin-dependency-wit\) and updates to dependency manifests to reflect this new modular structure.
(dependencies) · high confidence
Introduce spin\_common crate with shared CLI and utility modules
A new \spin\_common\ crate has been added to centralize shared functionality across the Spin CLI and its plugins. This includes argument parsing helpers (such as \key=value\ parsing), custom assertion macros for better error reporting, standardized Clap styling, and utilities for resolving data directories (including Homebrew-specific paths and environment variable overrides). It also provides manifest file discovery logic that searches upward for \spin.toml\ (with a depth limit and Git root detection), path resolution helpers, SHA-256 digest functions, URL manipulation (including credential removal), and a mechanism to warn on slow operations. This refactoring aims to reduce code duplication and ensure consistent behavior across different parts of the Spin ecosystem.
crates/common · high confidence
Behavioural changes
Added TOML configuration validation to track unused keys
The runtime configuration module now includes a \TomlKeyTracker\ helper that validates TOML configuration files by ensuring all defined keys are explicitly accessed during parsing. This prevents silent failures from typos or deprecated settings by raising a \RuntimeConfigUnusedKeys\ error if any keys in the configuration file are left unused, improving the robustness of configuration handling.
_crates/factors/src/runtime\config · high confidence
Added build script to expose macro expansion directory
A new build script (build.rs) was added to the factor-variables crate. This script sets the SPIN\_FACTORS\_DERIVE\_EXPAND\_DIR environment variable, enabling the spin-factors-derive macro to emit expanded macro output for debugging or analysis purposes.
crates/factor-variables · high confidence
Added database type conversion logic and host world bindings for Spin 3.6
The \crates/world/src\ crate now includes the \conversions.rs\ module, which implements \From\ traits to map database column and value types between the v1, v2, and pg4 (PostgreSQL 4.2.0) RDBMS type systems. This ensures that data returned from database triggers is correctly translated across different API versions. Additionally, \lib.rs\ defines the \spin:runtime/host\ world, importing interfaces from \fermyon:spin\ (v1 and v2), \spin:up/platform\ (v3.2.0, v3.4.0, v4.0.0), and \wasi:keyvalue\, while exporting \spin:redis/inbound-redis\. The file also sets up trappable error types for various Spin and WASI interfaces and defines a \MAX\_HOST\_BUFFERED\_BYTES\ constant to limit the size of host-buffered database query results and HTTP bodies.
crates/world/src · high confidence
CLI error handling and TLS provider initialization refactored
The Spin CLI now explicitly installs the default TLS crypto provider at startup and replaces the previous structopt-based argument parsing with a new run loop that handles errors more gracefully. When a command fails, the CLI checks for subprocess exit status errors to avoid duplicate output; otherwise, it prints the error using the terminal module and displays the full error chain for debugging. This change removes the direct dependency on structopt and the TemplatesCommand enum in the binary entry point, delegating command execution to the spin\_cli::run() function.
src/bin · high confidence
CLI variables can now be provided via file content
The \spin up\ command now supports passing variable values directly from files using the \--variable\ flag. Users can specify \key=@file\ to read a value from a text file, or use \@file.json\ and \@file.toml\ syntax to load multiple key-value pairs from JSON or TOML files. This allows for easier management of sensitive or large configuration values without needing to escape them in the command line.
crates/runtime-factors · high confidence
Deny adapter now supports WASI key-value atomics and batch operations
The deny adapter in \crates/capabilities/deny-adapter\ has been updated to include implementations for \wasi:keyvalue/atomics\ and \wasi:keyvalue/batch\ (version 0.2.0-draft2). This change expands the adapter's capability set to cover these specific key-value operations, ensuring they are explicitly handled (and denied) alongside the existing HTTP, MQTT, MySQL, Postgres, Redis, SQLite, and other Spin/WASI exports.
crates/capabilities/deny-adapter · high confidence
Enable Wasmtime pooling allocator by default for improved performance
The Spin core execution engine now enables Wasmtime's pooling instance allocator by default, significantly reducing syscall and kernel overhead for WebAssembly execution, particularly in async contexts. This change introduces a new \crates/core\ crate that wraps Wasmtime, featuring a \Config\ struct to manage engine settings (including cache, debug info, and pooling), a \Store\ wrapper with execution deadline support, and \StoreLimitsAsync\ for enforcing per-instance memory and table limits. The pooling allocator's resource limits (such as instance counts, memory sizes, and table elements) are configurable via environment variables like \SPIN\_MAX\_INSTANCE\_COUNT\ and \SPIN\_WASMTIME\_INSTANCE\_COUNT\, with sensible defaults derived from the maximum instance count.
crates/core/src · high confidence
Enable macro expansion output for spin-factors-derive
The build script for the factors crate now sets the SPIN\_FACTORS\_DERIVE\_EXPAND\_DIR environment variable, allowing the spin-factors-derive macro to emit its expanded output. This aids in debugging and understanding the generated code during the build process.
crates/factors · high confidence
Enhanced runtime configuration and execution hooks in Spin CLI
The Spin CLI now supports several new runtime capabilities through dedicated executor hooks. Users can now initialize key-value pairs and execute SQLite statements (including from files) at startup via the InitialKvSetterHook and SqlStatementExecutorHook. Memory usage can be constrained per instance using the MaxInstanceMemoryHook. Logging behavior is improved with the StdioLoggingExecutorHooks, which allows following specific component logs and truncating log files on restart. Variable resolution is validated early via the VariablesValidatorHook, and launch metadata is now available for introspection. Summary hooks provide feedback on default key-value and SQLite store usage.
crates/trigger/src/cli · high confidence
Extracted Azure Key Vault and Environment variable providers into separate crates
The Azure Key Vault and environment variable variable providers have been moved from the main variables crate into their own dedicated crates (\crates/variables-azure\ and \crates/variables-env\). This refactoring isolates the implementation details for fetching secrets from Azure Key Vault (supporting both service principal credentials and ambient authentication) and environment variables (including \.env\ file support and configurable prefixes), making the variable resolution system more modular and easier to maintain.
crates/variables-azure, crates/variables-env · high confidence
HTTP trigger now supports multiple WASI HTTP interface versions alongside Spin and Wagi executors
The HTTP trigger in \crates/http\ has been refactored to detect and route requests based on the specific HTTP interface exported by a component. Instead of a single handler type, the system now distinguishes between the native Spin HTTP interface, Wagi CGI, and multiple versions of the WASI HTTP specification (including \wasi:http/incoming-handler\ versions from 2023-10-18 and 2023-11-10, as well as \wasi:http/handler\ versions 0.2 and 0.3). This allows components built against different WASI HTTP standards to be executed correctly by selecting the appropriate executor indices at runtime. Configuration for these executors, including Wagi-specific arguments and static responses, is now defined in the new \config.rs\ module, while \app\_info.rs\ provides metadata about the running application.
crates/http/src · high confidence
HTTP trigger refactored into modular components with OpenTelemetry support
The HTTP trigger implementation has been restructured into distinct modules for headers, instrumentation, middleware, and various execution backends (Spin, Wagi, WASI, WASIp3). This change introduces standardized OpenTelemetry semantic conventions for HTTP request and response tracing, ensuring consistent observability across all HTTP handlers. It also adds support for HTTP middleware composition via the \middleware\ trigger dependency, allowing users to inject custom logic into the request pipeline. Additionally, the server now captures the actual bound address for accurate self-request routing and startup logging, and includes new test data for TLS certificate validation.
crates/trigger-http · high confidence
In-process SQLite implementation with configurable file attachment security
The \spin-sqlite-inproc\ crate now provides the in-process SQLite runtime implementation, replacing the previous abstraction. This change introduces an \allow\_attach\_file\ runtime configuration option that, when disabled (the default), restricts SQLite's \ATTACH DATABASE\ command to only in-memory or temporary files, preventing access to arbitrary host files. The implementation supports both in-memory and persistent file-based databases, automatically creating parent directories for file paths, and exposes async query interfaces that enforce result size limits to prevent memory exhaustion.
crates/sqlite-inproc · high confidence
Introduce the Spin Factors runtime architecture
The runtime now uses a new 'Factors' system to manage host capabilities. This introduces a \Factor\ trait that defines a lifecycle (init, configure\_app, prepare) and allows factors to declare runtime configuration, application state, and per-instance state. The \RuntimeFactors\ trait and its derive macro manage the collection of these factors, handling initialization, configuration, and instance state building. This replaces the previous monolithic host component model with a modular, composable approach where factors can depend on each other's state during preparation.
crates/factors/src · high confidence
Local LLM inference is now opt-in via feature flag
The local LLM engine is now behind the \llm\ feature flag. When the feature is disabled, the LLM factor uses a no-op engine that returns a clear error message stating that local LLM operations are not supported, rather than failing to build or run. When the feature is enabled, the default engine creator initializes a local model engine using the \spin\_llm\_local\ crate, allowing components to perform inference and generate embeddings locally as before.
crates/factor-llm/src · high confidence
Local LLM inference now uses the Candle backend
The local LLM engine has been rewritten to use the Candle library instead of the previous rustformers implementation. This change introduces new source files for the Bert embedding model and Llama inference, enabling local execution of these models via the WASI LLM v2 interface. Users will see a shift in the underlying inference engine, which may affect performance characteristics and model compatibility, while retaining support for local model loading from the registry.
crates/llm-local · high confidence
New template system with manifest v2 support and Liquid filters
The templates crate has been restructured to support the new Spin manifest v2 format, introducing an \AppInfo\ component that detects whether an existing application uses manifest v1 or v2. The system now uses Liquid templates with new string transformation filters (\kebab\_case\, \pascal\_case\, \snake\_case\, \dotted\_pascal\_case\) and an \http\_wildcard\ filter for route generation. Template execution now supports conditional logic based on manifest entries, allows adding components to existing apps, and provides better non-interactive behavior with default value acceptance and git initialization options.
crates/templates · high confidence
Outbound HTTP factor refactored with interceptor support and connection pooling
The outbound HTTP factor has been restructured to support a new \OutboundHttpInterceptor\ trait, allowing applications to inspect, modify, or short-circuit outgoing HTTP requests before they are sent. The implementation now enables connection pooling and reuse by default for both the legacy \fermyon:spin/http\ interface and the \wasi:http/outgoing-handler\ interface, improving performance for repeated requests. Additionally, the runtime configuration has been updated to use \max\_connections\ instead of the deprecated \max\_concurrent\_requests\ to limit concurrent outbound connections, and the factor now integrates with \spin\_factor\_outbound\_networking\ to enforce allowed hosts and blocked networks consistently across HTTP requests.
crates/factor-outbound-http/src · high confidence
Port SQLite implementation to libSQL client
The SQLite factor in \crates/sqlite-libsql\ has been migrated from the previous SQLite driver to the libSQL client. This change introduces a new \LibSqlConnection\ wrapper that handles asynchronous connection creation and query execution against a remote libSQL server, while maintaining the existing \spin\_factor\_sqlite\ interface for compatibility. Users benefit from the underlying libSQL capabilities, including async query support and batch execution, without needing to change their application code.
crates/sqlite-libsql · high confidence
Refactored Postgres type handling with new conversion modules
The Postgres client's type handling has been reorganized into focused modules within \crates/factor-outbound-pg/src/types\. This change introduces dedicated conversion logic for JSONB, UUIDs, decimals, date/time types, and ranges between WIT representations and the tokio\_postgres driver. It also adds support for Postgres INTERVAL types and implements a fallback mechanism that returns unsupported Postgres types as raw byte blobs. Additionally, a new \PgNull\ type allows sending SQL NULLs without enforcing specific Rust types, resolving issues where passing \Option::None\ to non-matching column types previously failed.
crates/factor-outbound-pg/src/types · high confidence
Refactored app source resolution and CLI argument parsing for the \`spin up\` command
The \spin up\ command now uses a dedicated \AppSource\ module to explicitly distinguish between local manifest files, OCI registry references, and bare Wasm files, improving how the application source is identified and validated. Additionally, a new \parsing\ module handles the migration to Clap 4 by splitting raw command-line arguments into those belonging to the \spin up\ command itself and those intended for specific trigger executors, ensuring that trigger-specific flags are correctly passed through without causing parsing conflicts.
src/commands/up · high confidence
Refactored application loader with new caching and file system abstractions
The application loader has been restructured to improve reliability and performance. A new cache module now manages OCI registry entities, storing manifests, Wasm bytes, and data files in a dedicated directory structure with fallback logic for unknown media types. File system operations are abstracted behind a new module that supports both async (Tokio) and synchronous I/O depending on feature flags, ensuring consistent behavior across environments. HTTP downloads are now verified against SHA-256 digests before being persisted, with race-condition handling for concurrent downloads of content-indexed files. The local loader now enforces concurrency limits on file loading to prevent resource exhaustion and supports both copying and direct mounting strategies for WASI file mounts.
crates/loader/src · high confidence
Spin Docs website deployment via Nomad and OCI
The Spin Docs website is now deployed using a Nomad job (spin-docs.nomad) that runs the application from an OCI registry reference. This configuration includes health checks, traffic routing via Traefik to spin.fermyon.dev, and automatic deployment on pushes to the main branch, with manual deployment options available through the GitHub workflow.
deploy · high confidence
Spin Doctor now detects missing Rust compiler and wasm32-wasip2 target
The Rust language diagnostics in Spin Doctor have been updated to check for the presence of the Rust toolchain and the specific \wasm32-wasip2\ target. If Rust is not installed, or if the \wasm32-wasip2\ target is missing from an existing Rustup installation, the doctor will now report these issues and provide automated treatments to install the compiler or add the target via \rustup\. This ensures that Rust-based Spin components are correctly configured for the wasip2 runtime.
crates/doctor/src/rustlang · high confidence
Spin timer example updated to manifest v2 and WASI preview 2
The spin-timer example has been migrated to the Spin manifest version 2, which introduces a new configuration structure for application triggers and component definitions. The example now targets the wasm32-wasip2 architecture instead of the previous wasi preview 1, requiring a build command update. Additionally, the application code has been refactored to use the \variables\ API for accessing configuration values, replacing the older mechanism, and utilizes the updated wit-bindgen 0.12 bindings for the spin-timer world.
examples/spin-timer/app-example · high confidence
Spin-timer example migrated to the new factors-based trigger architecture
The spin-timer example has been rewritten to use the new Spin factors system, replacing the previous trigger implementation. This change introduces a new WIT interface (fermyon:spin/variables@2.0.0) for accessing application variables and updates the trigger structure to implement the new Trigger trait with factors. Users can now build and install the trigger-timer plugin using the updated manifest and pluginify workflow, enabling components to be triggered at timed intervals with support for per-component configuration and global speedup settings.
examples/spin-timer · high confidence
Support for Spin v2 manifest format with automatic v1 migration
The manifest parser now accepts both the new v2 schema and the legacy v1 schema. When a v1 manifest is detected, it is automatically converted to the v2 internal representation, ensuring that legacy fields like \allowed\_http\_hosts\ are correctly mapped to the new \allowed\_outbound\_hosts\ structure (including preserving database access permissions where applicable). This allows existing applications to continue working without manual migration while enabling the use of new v2 features such as component dependencies and build profiles.
crates/manifest/src · high confidence
Support for deprecated 'allowed\_http\_hosts' configuration
The system now explicitly supports the deprecated 'allowed\_http\_hosts' configuration option. A new module in the manifest compatibility layer implements parsing logic for this setting, allowing users to specify a list of allowed HTTP hosts (with optional ports) or use a special 'insecure:allow-all' value to permit all hosts. This change ensures backward compatibility for existing configurations using this legacy field.
crates/manifest/src/compat · high confidence
Trigger-specific middleware handling via component splitting
The local loader now supports assigning different middleware configurations to multiple triggers that point to the same primary component. Previously, trigger-level dependencies like middleware were not properly isolated per trigger; the new logic detects when multiple triggers reference a single component but require distinct middleware, and automatically synthesizes unique component clones for each such trigger. This ensures that each trigger's specific middleware dependencies are correctly resolved and associated with its own component instance, while unmodified triggers continue to share the original component.
crates/loader/src/local · high confidence
Updated Go HTTP template to Spin manifest v2 and new SDK
The Go HTTP application template has been updated to use the Spin manifest v2 format (spin\_manifest\_version = 2) and the new github.com/spinframework/spin-go-sdk/v3 import path. The template now includes a .gitignore file to exclude build artifacts (main.wasm) and the .spin directory, and the spin.toml configuration uses allowed\_outbound\_hosts instead of the deprecated allow\_http\_hosts. Additionally, the main.go file now includes an empty main function required by the compiler, and the build command utilizes go tool componentize-go.
templates/http-go/content · high confidence
Updated Rust HTTP example to use Spin v2 manifest and WASI-HTTP SDK
The Rust HTTP example has been migrated to the Spin v2 manifest format (spin\_manifest\_version = 2) and updated to use the latest Spin Rust SDK. This includes switching the build target from wasm32-wasi to wasm32-wasip2, adopting the new \#\[http\_service\] macro for handler definition, and updating the component source path to reflect the new build output structure. Users running this example will now benefit from the standardized v2 configuration schema and the modern WASI-HTTP interface.
examples/http-rust · high confidence
Updated Rust HTTP template to Spin SDK v7 and v2 manifest
The Rust HTTP template has been upgraded to use the Spin SDK v7.0.0 and the v2 application manifest format. This update switches the compilation target to wasm32-wasip2, updates the Rust edition to 2024 (requiring Rust 1.93+), and replaces the deprecated \allow\_http\_hosts\ configuration with \allowed\_outbound\_hosts\. Additionally, the template now includes a \.gitignore\ file to exclude \.spin/\ and \target/\ directories, and the example code uses the standard \content-type\ header instead of a custom \foobar\ header.
templates/http-rust/content · high confidence
Updated WASI CLI and Clocks interface definitions
The \wit/deps\ directory now includes updated WIT (WebAssembly Interface Types) definitions for the \wasi:cli\ and \wasi:clocks\ packages, covering versions 0.2.0 through 0.3.0-rc-2026-03-15. These changes introduce new interfaces and refine existing ones, such as adding \exit-with-code\ to the CLI exit interface, switching the CLI \run\ function to async in version 0.3.0, and updating the monotonic clock to use \wait-until\ and \wait-for\ instead of subscription-based polling. This ensures the component model interfaces align with the latest WASI specifications.
wit · high confidence
Variables factor now supports WASI Config and expression-based variable resolution
The variables factor has been refactored to support the WASI Config interface (wasi:config/store) alongside existing Spin variable interfaces (v1, v2, v3). It now uses an expression resolver to handle variable resolution, allowing for more flexible variable definitions including environment variables and component-specific configurations. The factor also integrates with OpenTelemetry for tracing and error attribution, distinguishing between guest and host errors.
crates/factor-variables/src · high confidence
Watch command behavior and reliability improvements
The \spin watch\ command now ensures the application does not start serving until the initial build has successfully completed, preventing users from interacting with an unready service. It also fixes several stability issues, including a rebuild loop triggered by empty watch configurations, the failure to delete temporary directories, and incorrect application of \build.watch\ exclusions across all components. Additionally, the command now correctly detects and reacts to manifest file changes, and handles Windows paths properly for workdir-based watch globs.
src/commands/watch · high confidence
Fixes
5 commits (3 fixes) fixing cross
A fix in cross — 5 commits (3 fixs), 7 files.
cross · medium confidence · unverified
Test coverage
Added ABI conformance test suite for Spin components; Added LLM inference test component; Added SQLite runtime test configuration; Added UI tests for invalid Spin v2 manifest formats; Added UI tests for manifest parsing, v1-to-v2 migration, and normalization; Added UI tests for the loader; Added UI tests for v1 manifest migration to v2; Added UI tests for v2 manifest normalization and comprehensive feature coverage; Added WASI test harness for core functionality; Added conformance test suite for Spin runtime; Added in-process Spin runtime for testing; Added integration test for WASI HTTP v0.2.0 proxy component; Added integration test for the variables factor; Added integration tests for OutboundHttpFactor; Added integration tests for core WASI component execution; Added integration tests for the LLM factor; Added integration tests for the Postgres outbound factor; Added integration tests for the key-value factor's store configuration and access control; Added outbound PostgreSQL test component; Added runtime test for WASI-HTTP application; Added runtime test for outbound PostgreSQL connectivity; Added runtime test for outbound Redis connectivity; Added runtime test infrastructure for MySQL outbound connections; Added runtime test suite for validating Spin runtime behavior; Added runtime tests for chained HTTP services and streaming; Added smoke tests for OpenTelemetry tracing capabilities; Added test component for HTTP requests; Added test component for MQTT publisher with username-password authentication; Added test component for SQLite interface behavior; Added test component for WASI HTTP v0.2.0-rc-2023-11-10; Added test component for WASI Key-Value interface; Added test component for WASI TCP sockets; Added test component for internal HTTP request chaining and host validation; Added test component for validating internal HTTP service chaining; Added test components for WASI HTTP middleware and service interfaces; Added test components for WASI P3 service chaining; Added test components for key-value and variables interfaces; Added test fixtures for WASI Preview 2 and manifest validation; Added test fixtures for plugin compatibility and error scenarios; Added test for WASI environment variable injection; Added test helper library for platform 3.0.0 component testing; Added test-components crate for runtime testing; Added tests for SQLite factor configuration and connection handling; Added tests for Spin Doctor manifest validation and migration; Added tests for outbound MQTT factor behavior; Added tests for outbound networking factor configuration and socket quotas; Added tests for the MySQL outbound factor; Added tests for the wasi:config interface; Added tests for variable interpolation in outbound host permissions; Added tests for variable resolution validation; Added unit test for Redis outbound connection validation; Expanded UI test coverage for Spin manifest loader; Expanded integration test suite for Spin applications; Manual test for PostgreSQL SSL root certificate configuration; New test infrastructure and test components for Spin integration and runtime testing; New testing framework infrastructure for runtime validation.
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.
Score
- CAI 66 → 67 (+0.8)
- Rubric changed (rubric-2026.09.9 → rubric-2026.09.18) — scores are not directly comparable.
Lenses
- Code Health 92 → 92 (-0.0)
- Architecture 97 → 97 (-0.3)
- Maturity 62 → 62 (-0.0)
- Readiness 73 → 63 (-10.1)
- Security 57 → 67 (+9.6)
- Performance 85 (new)
Resolved (10)
- Change coupling clique: lib.rs, lib.rs, lib.rs (crates/factor-variables/src/lib.rs)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- Hotspot: crates/factor-outbound-redis/src/host.rs (crates/factor-outbound-redis/src/host.rs)
- Hotspot: crates/trigger/src/cli.rs (crates/trigger/src/cli.rs)
- Members sharing a duplicated core (5 members, 50+ identical tokens) (crates/key-value-azure/src/store.rs)
- Off-boarding risk: anonymized user #1
- Off-boarding risk: anonymized user #2
- TodoComment (crates/templates/src/renderer.rs)
New (43)
- Ambiguous API for componentization. componentize_if_necessary suggests a check-then-act pattern, while componentize suggests an unconditional action. However, without clear documentation, it is unclear if componentize also performs a check internally or if it always transforms. This leads to potential double-processing or confusion about when to use which.
- Ambiguous naming for build functions. build takes many parameters including target_checks and wit_generation, while build_default takes fewer. The name build_default suggests it is a convenience wrapper, but build is not named build_full or build_advanced. This creates confusion about which method to use for standard builds.
- Change coupling: lib.rs ↔ lib.rs (crates/factor-variables/src/lib.rs)
- Change coupling: lib.rs ↔ lib.rs (crates/variables-env/src/lib.rs)
- Documentation: no project overview (README.md)
- FileTooLong: commands/deps.rs (src/commands/deps.rs)
- High: security finding (details withheld)
- High: security finding (details withheld)
- Inconsistent error handling strategy for metadata retrieval. get_metadata implies a Result (likely returning an error on missing key), while require_metadata implies a Result (likely panicking or returning a specific 'not found' error variant). The naming convention is inconsistent with standard Rust patterns where get often returns Option and require/expect panics, or get returns Result and require is not present. Here, both return Result, making the distinction unclear and redundant.
- Low cohesion: ComponentStdioWriter (LCOM4 4) (crates/trigger/src/cli/stdio.rs)
- Low cohesion: KeyValue (LCOM4 6) (crates/componentize/src/abi_conformance/test_key_value.rs)
- Low cohesion: KeyValueDispatch (LCOM4 8) (crates/factor-key-value/src/host.rs)
- Low cohesion: Template (LCOM4 4) (crates/templates/src/template.rs)
- Medium advisory (unsound): RUSTSEC-2026-0306 (Cargo.lock)
- Medium vulnerability: RUSTSEC-2026-0285 (Cargo.lock)
- Medium vulnerability: RUSTSEC-2026-0313 (Cargo.lock)
- Medium vulnerability: RUSTSEC-2026-0314 (Cargo.lock)
- Medium vulnerability: RUSTSEC-2026-0315 (Cargo.lock)
- Members sharing a duplicated core (5 members, 50+ identical tokens) (crates/key-value-azure/src/store.rs)
- Off the main sequence: spin-app
- …and 23 more
Changes since last survey
- 26 commits — 22 feature/other, 4 fixes
By area
- (repo) — 10 commits
- (root) — 3 commits
- crates/capabilities — 3 commits
- crates/templates — 3 commits
- .github/workflows — 1 commit
- crates/app — 1 commit
- crates/dependency-wit — 1 commit
- crates/key-value-azure — 1 commit
- crates/loader — 1 commit
- crates/runtime-config — 1 commit
- examples/spin-timer — 1 commit
Notable commits
- fix: Fix WIT extractor emitting wrong interface when duplicated names
- fix: Merge pull request #3716 from itowlson/extract-deps-fix-dep-imports-and-exports-same-named-itf
- fix: Merge pull request #3720 from ChihweiLHBird/fix-cosmos-kv-sql-injection
- fix: ci: Fix release job when canary release is missing (#3725)
- change: Add OpenBao Variable Provider (#3719)
- change: Add impl for wasi:keyvalue/{atmoics,batch} in deny-all-adapter (#3724)
- change: Add schema directive to empty template
- change: Build the deny adapter without WASI std (#3723)
- change: Explain that FromUtf8Error::into_bytes returns the original bytes
- change: Match inherited capability imports by semver track (#3722)
- change: Merge pull request #3676 from itowlson/avoid-reinstall-env-templates-if-already-there-sorta-kinda-crossing-a-lotta-fingers
- change: Merge pull request #3710 from spinframework/bump-wasmtime/prerelease-49.0.0
- change: Merge pull request #3714 from spinframework/memoize-default-tlsclientconfig
- change: Merge pull request #3717 from itowlson/empty-template-schema-directive
- change: Merge pull request #3718 from spinframework/less-allocatin
- change: Merge pull request #3726 from spinframework/wasmtime-49-0-01
- change: Merge pull request #3727 from ChihweiLHBird/zhiwei/templates-reuse-utf8-buffers
- change: Merge remote-tracking branch 'origin/main' into prerelease-49.0.0
- change: Parameterize Azure Cosmos key-value queries
- change: Reduce string allocations
- …and 6 more
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
spinframework/spin was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 29 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit e95d4a6228110bdd5bf0b72bf0f8b6a523fdbd92 — the exact code this score is about.
- Scored under rubric-2026.09.18 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-c4983f2d4e5c.