Peter Steinberger
|
d72734946a
|
fix(security): harden install base drift cleanup
|
2026-03-07 19:23:01 +00:00 |
|
Peter Steinberger
|
c06014d50c
|
fix(agents): respect explicit provider baseUrl in merge mode (#39103)
Land #39103 by @BigUncle.
Co-authored-by: BigUncle <biguncle2017@gmail.com>
|
2026-03-07 19:22:21 +00:00 |
|
Peter Steinberger
|
537c97cce9
|
fix(agents): apply contextTokens cap for compaction threshold (#39099)
Land #39099 by @MumuTW.
Co-authored-by: MumuTW <clothl47364@gmail.com>
|
2026-03-07 19:19:03 +00:00 |
|
Peter Steinberger
|
e27bbe4982
|
fix(exec): block dangerous override-only env pivots
|
2026-03-07 19:18:05 +00:00 |
|
Peter Steinberger
|
6aa80844b8
|
fix(security): stage installs before publish
|
2026-03-07 19:11:07 +00:00 |
|
ademczuk
|
70be8ce15c
|
fix(daemon): normalise whitespace in checkTokenDrift to prevent false-positive warning (#39108)
|
2026-03-07 14:10:54 -05:00 |
|
Peter Steinberger
|
74ecdec9ba
|
fix(security): harden fs-safe copy writes
|
2026-03-07 19:10:27 +00:00 |
|
Peter Steinberger
|
6bfae2714f
|
refactor: dedupe bluebubbles webhook auth test setup
|
2026-03-07 19:02:01 +00:00 |
|
Peter Steinberger
|
acf3ff91e4
|
refactor: dedupe discord native command test scaffolding
|
2026-03-07 19:02:01 +00:00 |
|
Peter Steinberger
|
0848a47c97
|
refactor: dedupe anthropic probe target test setup
|
2026-03-07 19:02:01 +00:00 |
|
Peter Steinberger
|
8928aba7ee
|
refactor: dedupe minimax provider auth test setup
|
2026-03-07 19:02:01 +00:00 |
|
Peter Steinberger
|
143eca8e86
|
refactor: dedupe runtime snapshot test fixtures
|
2026-03-07 19:02:01 +00:00 |
|
Peter Steinberger
|
31acad4e8f
|
fix: harden zip extraction writes
|
2026-03-07 19:01:35 +00:00 |
|
Peter Steinberger
|
0f53177971
|
fix(tests): stabilize diffs localReq headers (supersedes #39063)
Co-authored-by: Shennng <Shennng@users.noreply.github.com>
|
2026-03-07 18:57:35 +00:00 |
|
Peter Steinberger
|
253e159700
|
fix: harden workspace skill path containment
|
2026-03-07 18:56:15 +00:00 |
|
Peter Steinberger
|
5effa6043e
|
fix(agents): land #38935 from @MumuTW
Co-authored-by: MumuTW <MumuTW@users.noreply.github.com>
|
2026-03-07 18:55:49 +00:00 |
|
Peter Steinberger
|
231c1fa37a
|
fix(models): land #38947 from @davidemanuelDEV
Co-authored-by: davidemanuelDEV <davidemanuelDEV@users.noreply.github.com>
|
2026-03-07 18:54:12 +00:00 |
|
Peter Steinberger
|
2f59a3cff3
|
fix(gateway): land #39064 from @Narcooo
Co-authored-by: Narcooo <Narcooo@users.noreply.github.com>
|
2026-03-07 18:52:42 +00:00 |
|
Peter Steinberger
|
2ada1b71b6
|
fix(models-auth): land #38951 from @MumuTW
Co-authored-by: MumuTW <MumuTW@users.noreply.github.com>
|
2026-03-07 18:51:17 +00:00 |
|
Peter Steinberger
|
02f99c0ff3
|
docs: clarify agent owner trust defaults
|
2026-03-07 18:48:27 +00:00 |
|
Peter Steinberger
|
729ee165ed
|
docs(gateway): clarify trusted operator HTTP endpoints
|
2026-03-07 18:48:17 +00:00 |
|
Peter Steinberger
|
8bd0eb5424
|
fix(outbound): land #38944 from @Narcooo
Co-authored-by: Narcooo <Narcooo@users.noreply.github.com>
|
2026-03-07 18:46:48 +00:00 |
|
Tak Hoffman
|
52e7d4295e
|
fix(gateway): clear stale Slack socket state after disconnect (#39083)
* fix(gateway): restore stale-socket recovery
* test(slack): cover clean socket disconnect status
|
2026-03-07 12:37:32 -06:00 |
|
Peter Steinberger
|
fbb9bb08c5
|
style(test): format gateway auth token coverage
|
2026-03-07 18:33:30 +00:00 |
|
Peter Steinberger
|
10d0e3f3ca
|
fix(dashboard): keep gateway tokens out of URL storage
|
2026-03-07 18:33:30 +00:00 |
|
Vincent Koc
|
f966dde476
|
tests: fix detect-secrets false positives (#39084)
* Tests: rename gateway status env token fixture
* Tests: allowlist feishu onboarding fixtures
* Tests: allowlist Google Chat private key fixture
* Docs: allowlist Brave API key example
* Tests: allowlist pairing password env fixtures
* Chore: refresh detect-secrets baseline
|
2026-03-07 13:21:29 -05:00 |
|
Vincent Koc
|
3acf46ed45
|
Tests: fix doctor gateway auth token formatting
|
2026-03-07 10:18:52 -08:00 |
|
Vincent Koc
|
5290d97574
|
Docs: fix web tools MDX links
|
2026-03-07 10:15:22 -08:00 |
|
Vincent Koc
|
912f7a5525
|
CI: enable Windows pnpm side-effects cache
|
2026-03-07 10:11:52 -08:00 |
|
Vincent Koc
|
de7848e227
|
CI: cache Python and Windows pnpm stores
|
2026-03-07 10:11:51 -08:00 |
|
Vincent Koc
|
61273c072c
|
Docs: remove MDX-breaking secret markers
|
2026-03-07 10:09:00 -08:00 |
|
Vincent Koc
|
e4d80ed556
|
CI: restore main detect-secrets scan (#38438)
* Tests: stabilize detect-secrets fixtures
* Tests: fix rebased detect-secrets false positives
* Docs: keep snippets valid under detect-secrets
* Tests: finalize detect-secrets false-positive fixes
* Tests: reduce detect-secrets false positives
* Tests: keep detect-secrets pragmas inline
* Tests: remediate next detect-secrets batch
* Tests: tighten detect-secrets allowlists
* Tests: stabilize detect-secrets formatter drift
|
2026-03-07 10:06:35 -08:00 |
|
Peter Steinberger
|
46e324e269
|
docs(changelog): credit hook auth throttling report
|
2026-03-07 18:05:11 +00:00 |
|
Peter Steinberger
|
44820dcead
|
fix(hooks): gate methods before auth lockout accounting
|
2026-03-07 18:05:09 +00:00 |
|
jsk
|
262fef6ac8
|
fix(discord): honor commands.allowFrom in guild slash auth (#38794)
* fix(discord): honor commands.allowFrom in guild slash auth
* Update native-command.ts
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Update native-command.commands-allowfrom.test.ts
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* fix(discord): address slash auth review feedback
* test(discord): add slash auth coverage for allowFrom variants
* fix: add changelog entry for discord slash auth fix (#38794) (thanks @jskoiz)
---------
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
Co-authored-by: Shadow <hi@shadowing.dev>
|
2026-03-07 12:03:52 -06:00 |
|
Peter Steinberger
|
278e5220ec
|
test: narrow pairing setup helper token type
|
2026-03-07 17:58:31 +00:00 |
|
Peter Steinberger
|
9dc759023b
|
refactor(agents): share skill plugin fixture writer in tests
|
2026-03-07 17:58:31 +00:00 |
|
Peter Steinberger
|
7eb48d3cf8
|
refactor(auto-reply): share discord auth registry test fixture
|
2026-03-07 17:58:31 +00:00 |
|
Peter Steinberger
|
ce9719c654
|
refactor(test-utils): share direct channel plugin test fixture
|
2026-03-07 17:58:31 +00:00 |
|
Peter Steinberger
|
5f56333016
|
refactor(commands): dedupe config-only channel status fixtures
|
2026-03-07 17:58:31 +00:00 |
|
Peter Steinberger
|
bcb587a3bc
|
refactor(commands): dedupe channel plugin test fixture builders
|
2026-03-07 17:58:31 +00:00 |
|
Peter Steinberger
|
66de964c59
|
refactor(tui): dedupe mode-specific exec secret fixtures
|
2026-03-07 17:58:31 +00:00 |
|
Peter Steinberger
|
e60b28fd1f
|
refactor(tui): dedupe gateway token resolution path
|
2026-03-07 17:58:31 +00:00 |
|
Peter Steinberger
|
a96ef12061
|
refactor(memory): dedupe local embedding init concurrency fixtures
|
2026-03-07 17:58:31 +00:00 |
|
Peter Steinberger
|
98ed7f57c6
|
refactor(feishu): dedupe non-streaming reply dispatcher setup
|
2026-03-07 17:58:31 +00:00 |
|
Peter Steinberger
|
6b0785028f
|
refactor(feishu): dedupe accounts env secret-ref checks
|
2026-03-07 17:58:31 +00:00 |
|
Peter Steinberger
|
7fddb357cb
|
refactor(feishu): dedupe client timeout assertion scaffolding
|
2026-03-07 17:58:31 +00:00 |
|
Peter Steinberger
|
ac5f018877
|
refactor(feishu): dedupe onboarding status env setup tests
|
2026-03-07 17:58:31 +00:00 |
|
Peter Steinberger
|
72df4bd624
|
refactor(web): dedupe self-chat response-prefix tests
|
2026-03-07 17:58:31 +00:00 |
|
Peter Steinberger
|
7e94dec679
|
refactor(pairing): dedupe inferred auth token fixtures
|
2026-03-07 17:58:31 +00:00 |
|