Peter Steinberger
|
59925c1a74
|
chore: update dependencies and oxc tooling
|
2026-04-10 19:28:42 +01:00 |
|
Peter Steinberger
|
8127c6cc15
|
build(deps): update workspace dependencies
|
2026-04-10 19:17:39 +01:00 |
|
Michael Appel
|
9f97ad857a
|
fix(security): pin axios to 1.15.0 and add dependency denylist for plugin installs [AI-assisted] (#63891)
* fix: address issue
* fix: address review feedback
* fix: address PR review feedback
* fix: address PR review feedback
* fix: address PR review feedback
* fix: address PR review feedback
* fix: address PR review feedback
* Plugins: fix install security CI regressions
* Plugins: make manifest traversal linear
* Plugins: bound manifest security traversal
* Plugins: block denied node_modules package dirs
* Plugins: match node_modules case-insensitively
* Plugins: block denied package symlink paths
* Tests: normalize blocked symlink assertion
* Plugins: fail closed on unreadable denied paths
* Plugins: block denied node_modules file aliases
* Plugins: inspect node_modules symlink targets
* Plugins: preserve symlink target package paths
* fix: address PR review feedback
* chore(changelog): add axios pin and dependency denylist entry
---------
Co-authored-by: Devin Robison <drobison@nvidia.com>
|
2026-04-10 11:20:05 -06:00 |
|
Peter Steinberger
|
c077af987f
|
perf: add narrow inbound roots sdk surface
|
2026-04-10 17:34:41 +01:00 |
|
Peter Steinberger
|
2ccb5cff22
|
test: move Vitest configs under test
|
2026-04-10 13:44:51 +01:00 |
|
Peter Steinberger
|
0b0c062e97
|
fix: avoid Claude CLI subscription prompt classifier
|
2026-04-10 10:52:35 +01:00 |
|
Shadow
|
d5b25f81cf
|
update carbon
|
2026-04-10 01:53:36 -05:00 |
|
Altay
|
004bab53fa
|
fix(ci): repair protocol drift and audit failures (#63917)
* CI: fix protocol drift and audit failures
* CI: narrow axios release-age exception
* CI: drop ineffective feishu override
* test: fix workspace-root guard mock typing
|
2026-04-09 22:07:51 +01:00 |
|
Peter Steinberger
|
719f06510c
|
chore: bump version to 2026.4.10
|
2026-04-09 03:56:22 +01:00 |
|
Peter Steinberger
|
d41188b65e
|
ci: add runtime import cycle guard
|
2026-04-09 03:56:22 +01:00 |
|
Peter Steinberger
|
0512059dd4
|
chore: prepare 2026.4.9 stable release
|
2026-04-09 03:24:45 +01:00 |
|
Peter Steinberger
|
7810ddc220
|
chore: prepare 2026.4.9-beta.1 release
|
2026-04-09 02:13:31 +01:00 |
|
Mason Huang
|
aa15de8fdc
|
plugin-sdk: split command status surface
|
2026-04-09 01:35:15 +01:00 |
|
Peter Steinberger
|
acdee39fa4
|
ci: stabilize macOS and transcript policy tests
|
2026-04-09 01:10:40 +01:00 |
|
Peter Steinberger
|
3d9a151fd1
|
ci: narrow Windows node test lane
|
2026-04-09 00:40:23 +01:00 |
|
Peter Steinberger
|
0fce013ebf
|
build: mirror bundled plugin runtime deps
|
2026-04-09 00:31:08 +01:00 |
|
Peter Steinberger
|
9286de5d95
|
fix(deps): patch basic-ftp advisory
|
2026-04-08 22:49:45 +01:00 |
|
Peter Steinberger
|
1979a28803
|
fix: patch hono security advisories
|
2026-04-08 18:02:54 +01:00 |
|
Peter Steinberger
|
edf6b490a6
|
fix: harden bundled plugin dependency release checks
|
2026-04-08 15:15:44 +01:00 |
|
scoootscooob
|
d52d5ad6ff
|
release: mirror bundled channel deps at root (#63065)
Merged via squash.
Prepared head SHA: ac26799a54
Co-authored-by: scoootscooob <167050519+scoootscooob@users.noreply.github.com>
Co-authored-by: scoootscooob <167050519+scoootscooob@users.noreply.github.com>
Reviewed-by: @scoootscooob
|
2026-04-08 04:00:17 -07:00 |
|
Nimrod Gutman
|
6681878339
|
feat(ios): pin calver release versioning (#63001)
* feat(ios): decouple app versioning from gateway
* feat(ios): pin calver release versioning
* refactor(ios): drop prerelease version helper fields
* docs(changelog): note pinned ios release versioning (#63001) (thanks @ngutman)
|
2026-04-08 11:25:35 +03:00 |
|
Vincent Koc
|
be530f085d
|
refactor(plugin-sdk): share tool payload extraction
|
2026-04-08 09:07:28 +01:00 |
|
Vincent Koc
|
490c9c80ef
|
perf(plugin-sdk): split web search config contract
|
2026-04-08 09:03:07 +01:00 |
|
Peter Steinberger
|
8cbd60d203
|
chore: prepare 2026.4.9 release
|
2026-04-08 08:02:53 +01:00 |
|
Peter Steinberger
|
4f5c137f88
|
fix: unblock windows update build
|
2026-04-08 07:18:31 +01:00 |
|
Peter Steinberger
|
a53c13fc06
|
chore: prepare 2026.4.8 npm release
|
2026-04-08 06:03:20 +01:00 |
|
Peter Steinberger
|
a4b9755999
|
chore: prepare 2026.4.7-1 npm release
|
2026-04-08 05:08:17 +01:00 |
|
Peter Steinberger
|
4f8471617a
|
chore: prepare 2026.4.8
|
2026-04-08 04:21:51 +01:00 |
|
Peter Steinberger
|
c4efdeddd5
|
fix: harden parallels upgrade flows
|
2026-04-08 03:51:53 +01:00 |
|
Peter Steinberger
|
da858c326b
|
build: exclude plugin sdk build info from npm pack
|
2026-04-08 02:47:43 +01:00 |
|
Peter Steinberger
|
0e91c25c0b
|
chore: prepare 2026.4.7
|
2026-04-08 02:14:59 +01:00 |
|
Gustavo Madeira Santana
|
28fc5d9b5e
|
Plugin SDK: split approval adapter seams
|
2026-04-07 16:06:02 -04:00 |
|
Gustavo Madeira Santana
|
d78512b09d
|
Refactor: centralize native approval lifecycle assembly (#62135)
Merged via squash.
Prepared head SHA: b7c20a7398
Co-authored-by: gumadeiras <5599352+gumadeiras@users.noreply.github.com>
Co-authored-by: gumadeiras <5599352+gumadeiras@users.noreply.github.com>
Reviewed-by: @gumadeiras
|
2026-04-07 14:40:26 -04:00 |
|
Vincent Koc
|
dfb6c9c920
|
perf(plugin-sdk): split channel secret runtime helpers
|
2026-04-07 13:09:12 +01:00 |
|
Peter Steinberger
|
2b5f663c9c
|
fix(ci): prepare plugin sdk boundary dts before lint
|
2026-04-07 10:37:39 +01:00 |
|
Peter Steinberger
|
c2f9de3935
|
feat: unify live cli backend probes
|
2026-04-07 10:35:24 +01:00 |
|
Vincent Koc
|
16877efba3
|
ci(plugins): enforce extension package boundary checks
|
2026-04-07 10:22:12 +01:00 |
|
Vincent Koc
|
4329d94de3
|
fix(plugins): stabilize package boundary tsc checks
|
2026-04-07 10:15:34 +01:00 |
|
Peter Steinberger
|
ba484d263b
|
Tests: add unit-fast Vitest lane
|
2026-04-07 10:03:42 +01:00 |
|
Peter Steinberger
|
54a884865e
|
feat: add fast qa lab ui refresh mode
|
2026-04-07 09:45:11 +01:00 |
|
Vincent Koc
|
fb64ba7bf7
|
refactor(plugins): harden package boundary sdk prep
|
2026-04-07 09:44:43 +01:00 |
|
Peter Steinberger
|
eafe0a6d67
|
build: fix check and bundled runtime staging
|
2026-04-07 09:18:59 +01:00 |
|
Peter Steinberger
|
0af808b457
|
test: add cli backend live matrix metadata
|
2026-04-07 09:06:09 +01:00 |
|
Vincent Koc
|
49fbecbf16
|
perf(plugin-sdk): add web fetch contract artifacts
|
2026-04-07 08:35:27 +01:00 |
|
Peter Steinberger
|
37dccb52ed
|
test: add gemini acp bind docker coverage
|
2026-04-07 07:59:45 +01:00 |
|
Vincent Koc
|
e318f48ff2
|
perf(secrets): narrow channel secret-ref imports
|
2026-04-07 07:38:34 +01:00 |
|
Peter Steinberger
|
a3b2fdf7d6
|
feat(agents): add prompt override and heartbeat controls
|
2026-04-07 07:34:50 +01:00 |
|
Peter Steinberger
|
ce1d2c1004
|
test: cover claude and codex acp bind docker smoke
|
2026-04-07 06:06:29 +01:00 |
|
Vincent Koc
|
2a6e8dca47
|
fix(plugin-sdk): add web-search contract subpath
|
2026-04-06 23:30:56 +01:00 |
|
Peter Steinberger
|
7a3497c8bd
|
refactor: dedupe image generation runtime surface
|
2026-04-06 22:21:00 +01:00 |
|