## apollographql/rover — v0.41.0…v1.0.0-rc.0

_402+ commits._

### Features
- **Add rover auth grants revoke, the per-user grant sweep (#3943)** (f9bed91)
- **Add a rover-client operation to check whether a user is an organization member (#3942)** (29e752b)
- **Add --manifest-path to name the project to install into (#3910)** (d7d6405)
- **Add --global to install for the whole machine inside a project (#3908)** (eba050b)
- **Add a rover-client operation to revoke a user's grants under an OAuth client (#3941)** (09cdec4)
- **Add a rover-client operation to look up a client-credential pair by ID (#3903)** (64574f7)
- **feat(persisted-queries): add `--preserve-comments` to `generate` (#3708)** (c38d4a6)
- **Add rover api-key rotate (A1.3, spec FR21-27) (#3892)** (ca51a2d)
- **Add slice-two's settings catalogue and syntactic validation (#3872)** (cec35ba)
- **Add rover config set/unset (#3828)** (45f6182)
- **Add the rover config show inspection verb (#3827)** (668e246)
- **Add the slice-one settings catalogue and syntactic validation (#3824)** (815f13c)
- **Support client-credentials in rover api-key create (#3864)** (08c0562)
- **Add a no-retry timeout Studio service and PairPermissionDenied (#3863)** (fc8a55d)
- **Add rover-client operations to create/rotate/delete client-credential pairs (#3854)** (bf8bb64)
- **Add the `rover plugin` noun with an `install` verb (#3846)** (c0cbebb)
- **Add plaintext, non-sensitive profile settings storage (#3836)** (5d1f88e)
- **Add rover-client operation to enumerate an organization's client-credential pairs (#3834)** (fc70ed7)
- **Add flags for router/composition version and templates-api (#3806)** (146aab4)
- **Add flags for config-home, rover-home, and no-color (#3805)** (82631d3)
- **Add flags for the VCS context environment variables (#3804)** (411f0e6)
- **Add flags for registry-url, telemetry-url/-disabled, checks-timeout, download-host (#3803)** (767e5c9)
- **Add environment variables to flag-only global settings (#3802)** (fd35574)
- **Add rover identity grant management PRD (#3798)** (ef2330b)

### Fixes
- **Fix `auth grants revoke --all` failing to list client-credential pairs (#3963)** (eff16bb)
- **Name the right fix in setting errors (#3955)** (bb242e8)
- **fix(config whoami): accept client-credentials (service account) identities (#3787)** (4cf824d)

### Backend
- **release: v1.0.0-rc.0 (#3968)** (2234591)
- **Read `deleteOAuthClient`'s returned client ID (#3967)** (9d15594)
- **Update Rust crate cc to v1.6.0 (#3966)** (3a55213)
- **Keep `rover --help`'s own description (#3965)** (dc8040b)
- **Update Rust crate insta to v1.49.0 (#3964)** (bda0085)
- **Remove the oauth Cargo feature (#3961)** (188a698)
- **Test that an unconfigured user is unaffected (#3957)** (1732267)
- **Read project settings from the manifest --manifest-path names (#3953)** (8079346)
- **Exercise a client-credential pair's lifecycle against live Studio in e2e (#3949)** (9aea71c)
- **Snapshot pair JSON payloads, list's pairs-query failure, and whoami's grant type (#3948)** (ed90fdf)
- **Update Rust crate uuid to v1.27.0 (#3962)** (4b38352)
- **Test that a client-credential pair's secret never leaks at trace log level (#3946)** (041cbe4)
- **Test the grants sweep's failure injection and non-terminal stdin through the binary (#3950)** (3a9dbae)
- **Report a revoke's GraphQL errors by the Platform API's own messages (#3952)** (c1f2277)
- **Stop registering the unused APOLLO_NODE_MODULES_BIN variable (#3956)** (945449a)
- **Update Rust crate bon to v3.10.2 (#3960)** (6a8dd36)
- **Pin rover api-key's operator/subgraph key output with integration snapshots (#3945)** (9e271bd)
- **Restore the rover api-key rotate CHANGELOG entry (#3937)** (5d7f2e3)
- **Accept any value for a Void mutation result, and say where a response failed to parse (#3959)** (b4c05d9)
- **Test the opt-in to automatic downloads across every case (#3933)** (7f1c5e6)
- **Test that an explicit install is never gated by the opt-in (#3932)** (9e29d87)
- **Test that a per-invocation control outranks the opt-in (#3931)** (e347547)
- **Stop downloading plugins on the fly unless opted in (#3930)** (dd26a86)
- **Opt the tests that download on the fly in to downloading (#3929)** (5041359)
- **Say how to get a plugin nothing opted in to downloading (#3928)** (1d354f8)
- **Read the opt-in to automatic plugin downloads (#3927)** (126dd33)
- **Test lockfile-driven installs against the acceptance criteria** (07e5b56)
- **Install and record rover.yaml's unlocked plugins one at a time** (2c46035)
- **Install the locked releases when no plugin is named** (94088da)
- **Test that every plugin-using command ranks versions identically (#3921)** (e6535bc)
- **Rank rover dev's and rover plugin install's versions by the shared ladder (#3920)** (cbf2fd0)
- **Take the supergraph version from rover.yaml when nothing outranks it (#3919)** (fca71b9)
- **Warn once when supergraph.yaml overrides the manifest's supergraph (#3918)** (7c0aaf7)
- **Pin a floating manifest declaration to its level's locked release (#3917)** (3db818c)
- **Decide each plugin's version request by one precedence ladder (#3916)** (fe06b78)
- **Install and find rover lsp's plugin under the Rover home it was given (#3915)** (9022396)
- **Specify APOLLO_ROVER_ALLOW_AUTOMATIC_DOWNLOAD as a setting (#3947)** (9fabfdc)
- **Record --global as outside the settings catalogue (#3913)** (bc7f6e1)
- **Test install targeting, two-level lookup, and project roots end to end (#3912)** (9435b27)
- **Create the project root --manifest-path names (#3911)** (8a69f1e)
- **Look up a plugin in the project before the global level (#3909)** (3d22a34)
- **Install into the project in scope by default (#3907)** (0c97c47)
- **Let the installer place plugins in a root other than Rover's own (#3906)** (1708dc9)
- **Keep the code review bot's reviewers in the foreground (#3939)** (eb016eb)
- **Report project-file settings in rover config show (#3901)** (d90bdda)
- **Surface project-file settings in configuration notices (#3900)** (5a3d0cb)
- **Resolve settings through the full six-tier chain (#3899)** (3798bd6)
- **Check the project file's settings: section before every command (#3898)** (84424b3)
- **Load a project file's settings: section via plugin discovery (#3897)** (76a5d2d)
- **Classify a project file's settings: section (#3896)** (eecdfef)
- **Update rust Docker tag to v1.99 (#3936)** (57bf69d)
- **Resolve the OAuth endpoint settings through the profile tier (#3895)** (92d1e36)
- **rover api-key rename refuses to rename a client-credential pair (FR31) (#3905)** (a45a711)
- **rover api-key delete deletes client-credential pairs (FR18-20, FR28-30) (#3904)** (47e4fb3)
- **Update Rust crate fs-mistrust to 0.16.0 (#3893)** (6e309ee)
- **Record --no-download as outside the settings catalogue (#3888)** (179fdb6)
- **Test the never-download controls through the real binary (#3886)** (bd5e87e)
- **Fail by name when `--skip-update` finds no installed plugin (#3885)** (4c6335a)
- **Never download under `rover plugin install --no-download` (#3884)** (643171c)
- **Give a plugin missing while downloads are disabled its own error code (#3883)** (9700d55)
- **Report client-credential pairs in rover api-key list (#3871)** (4ba7393)
- **Insert the profile tier for APOLLO_CLIENT_TIMEOUT (#3891)** (074d55a)
- **Update Rust to v1.99.0 (#3890)** (6eeb29c)
- **Update Rust crate lazy_static to v1.5.1 (#3889)** (54e6e56)
- **Insert the profile tier for APOLLO_GRAPH_REF, and forward it (FR90) (#3876)** (9f52e34)
- **templates api profile tier (#3875)** (32f9ad1)
- **Insert the profile tier for APOLLO_ROVER_DOWNLOAD_HOST (#3874)** (3c7c8c1)
- **Insert the profile tier for APOLLO_CHECKS_TIMEOUT_SECONDS (#3873)** (fcb622f)
- **Test plugin lockfile writes and drift through the real binary (#3860)** (351f4e7)
- **Detect a plugin lockfile that has drifted from its manifest (#3859)** (2affc49)
- **Record each plugin install in the global lockfile (#3858)** (7980bd2)
- **Skip shields.io badges in the markdown link check (#3879)** (8ba60f9)
- **Warn about unrecognized profile settings (FR38) (#3831)** (c184d6b)
- **Update jdx/mise-action action to v5.0.1 (#3878)** (020abd9)
- **Write a plugin lockfile only with a permit from the plugin noun (#3857)** (e29fd5a)
- **Refuse a plugin lockfile Rover can't use, naming the file (#3856)** (2620677)
- **Define the plugin-versions.lock format (#3855)** (f9454be)
- **Insert the profile tier for registry URL and telemetry settings (#3826)** (40dd1d5)
- **Give ProfileOpt an explicit-vs-default profile selection marker (#3825)** (c94180b)
- **Update dependency npm:npm to v12.2.0 (#3870)** (76173c9)
- **Classify an HTTP 403 as permission-denied in rover-studio (#3862)** (cf0583d)
- **Correct spec.md: FR16/17 assumed a permission signal that doesn't exist (#3869)** (8b8cd6c)
- **Update Rust crate jsonschema to v0.58.3 (#3822)** (35ade25)
- **Update Rust crate dircpy to v0.3.21 (#3866)** (211c390)
- **Update Rust crate opener to 0.9 (#3852)** (69918c1)
- **Specify TOML for the plugin lockfile (#3867)** (bc6ed93)
- **Test both plugin install spellings end to end (#3850)** (83ff755)
- **Point plugin install errors at `rover plugin install` (#3849)** (e5a4c1a)
- **Deprecate `rover install --plugin` in favor of `rover plugin install` (#3848)** (b6c6f64)
- **Report what `rover plugin install` installed through `CliOutput` (#3847)** (2cd1433)
- **Take the global .rover directory from binstall's rule (#3845)** (c84405e)
- **Name Rover's home directory in one place in binstall (#3844)** (9e6bd5a)
- **ROVER-446: test manifest discovery and layering against real trees (#3842)** (63ea760)
- **ROVER-446: layer project declarations over global ones, per plugin (#3841)** (8c6c4a5)
- **ROVER-446: discover the project and global .rover directories (#3840)** (72a8bbe)
- **ROVER-446: refuse a manifest Rover can't use, naming the file (#3839)** (570cfb8)
- **ROVER-446: define the rover.yaml manifest schema (#3838)** (5c0e4f2)
- **rover auth whoami reports the current grant's type (#3853)** (5728156)
- **Make Profile a handle struct instead of static methods (#3835)** (1bc6e37)
- **Snapshot each plugin install failure's JSON envelope (#3796)** (d24dc25)
- **Name where an on-the-fly plugin version came from (#3795)** (5bd7273)
- **Tell a withdrawn plugin release from one that never existed (#3794)** (0856d24)
- **Report plugin resolution, download, and install failures by code (#3793)** (5e89a9c)
- **Keep plugin download and unpacking failures apart in binstall (#3792)** (11edc80)
- **Give plugin failures their own error codes (#3791)** (d9de2d6)
- **Lock file maintenance (#3819)** (89bf9f7)
- **Update jdx/mise-action action to v5 (#3837)** (799a7c4)
- **Spec for identity and OAuth grant management (#3814)** (5b437dd)
- **Update Rust crate jsonschema to v0.58.1 (#3817)** (ae05564)
- **Update Rust crate apollo-http-client to 0.7.0 (#3815)** (560a468)
- **Refresh schema (#3820)** (52edb95)
- **Update Rust crate serde_with to v3.24.0 (#3818)** (f8b58e8)
- **Update Rust crate jsonschema to 0.58 (#3816)** (7ecdc9d)
- **Update Rust crate tokio-test to v0.4.6 (#3810)** (3606704)
- **Make --profile a global flag accepted by every command (#3801)** (8ad44ca)
- **Update Rust crate cc to v1.5.1 (#3812)** (b969969)
- **Update Rust crate comfy-table to v8.0.1 (#3813)** (a6e4b0c)
- **Update Rust crate cc to v1.5.0 (#3811)** (4420e34)
- **Update Rust crate apollo-federation-types to v0.17.9 (#3799)** (282e46f)
- **Update Rust crate encoding_rs to v0.8.42 (#3800)** (99269e6)
- **Update Rust crate termimad to v0.35.5 (#3789)** (9a39f7b)
- **Update Rust crate thiserror to v2.0.21 (#3790)** (6c03342)
- **Report data.plugins when a run fails (#3782)** (d91d7a3)

_Recap by [Repo Wrapped](https://repowrapped.com/gh/apollographql/rover?utm_source=github-action)._