Scoped tokens and the new config format
The major that made CI safe by default. Tokens are now scoped per project and environment, and forge.toml replaced the old JSON config. One command migrates you.
- add
forge token create with per-environment scoping — a preview token cannot deploy to production.
- add
forge.toml config format, including [[service]] blocks for monorepos.
- add
forge export emits the generated Dockerfile and compose file.
- chgDeploys are immutable versions (
v1, v2, …); in-place overwrite is gone.
- chgMinimum Node version for the CLI itself is now 20.
breaking: unscoped account-wide tokens from 2.x stopped working on this release. Run forge token migrate to mint scoped replacements, then update your CI secrets. Legacy forge.json is read for one more minor — forge config migrate converts it to forge.toml.