Commit Graph

  • d07d24eebe fix: clamp poll sleep duration to non-negative in bash-tools process (#24889) Adam 2026-02-23 19:22:58 -08:00
  • dc8423f2c0 fix: back up existing systemd unit before overwriting on update (#24350) (#24937) 青雲 2026-02-24 11:22:55 +08:00
  • 70cfb69a5f fix(doctor): skip false positive permission warnings for Nix store symlinks (#24901) Soumik Bhatta 2026-02-23 22:22:52 -05:00
  • 588ad7fb38 fix: respect agent model config in slug generator (#24776) Bill Cropper 2026-02-23 22:22:48 -05:00
  • e2e10b3da4 fix(slack): map threadId to replyToId for restart sentinel notifications (#24885) David Murray 2026-02-23 19:22:45 -08:00
  • 19c43eade2 fix(memory): strip null bytes from workspace paths causing ENOTDIR (#24876) Omair Afzal 2026-02-24 08:22:42 +05:00
  • 177f167eab fix: guard .trim() calls on potentially undefined workspaceDir (#24875) Omair Afzal 2026-02-24 08:22:39 +05:00
  • 7b2b86c60a fix(exec): add approval race changelog and regressions Peter Steinberger 2026-02-24 03:22:05 +00:00
  • 6f0dd61795 fix(exec): restore two-phase approval registration flow Peter Steinberger 2026-02-24 03:16:26 +00:00
  • c6c1e3e7cf docs(changelog): correct exec approvals reporter credit Peter Steinberger 2026-02-24 03:13:48 +00:00
  • ffd63b7a2c fix(security): trust resolved skill-bin paths in allowlist auto-allow Peter Steinberger 2026-02-24 03:12:22 +00:00
  • 204d9fb404 refactor(security): dedupe shell env probe and add path regression test Peter Steinberger 2026-02-24 03:11:18 +00:00
  • 64aab80201 test(exec): add regressions for safe-bin metadata and chain semantics Peter Steinberger 2026-02-24 03:10:05 +00:00
  • a67689a7e3 fix: harden allow-always shell multiplexer wrapper handling Peter Steinberger 2026-02-24 03:06:34 +00:00
  • 4a3f8438e5 fix(gateway): bind node exec approvals to nodeId Peter Steinberger 2026-02-24 03:05:36 +00:00
  • 9530c01085 refactor(exec): split safe-bin policy modules and dedupe allowlist flow Peter Steinberger 2026-02-24 03:04:57 +00:00
  • c5ac90ab92 docs(changelog): add shell-env fallback hardening note Peter Steinberger 2026-02-24 03:04:43 +00:00
  • 60f1d1959a test: stabilize invoke-system-run env-wrapper assertion on Windows Peter Steinberger 2026-02-24 03:02:32 +00:00
  • d0ef4c75c7 docs(changelog): credit safeBins advisory reporters Peter Steinberger 2026-02-24 02:59:10 +00:00
  • ff10fe8b91 fix(security): require /etc/shells for shell env fallback Peter Steinberger 2026-02-24 02:58:15 +00:00
  • 71f4b93656 docs: refresh clawtributors list Shakker 2026-02-24 02:54:19 +00:00
  • ef1ffacfb2 scripts: exclude unresolved clawtributors from README Shakker 2026-02-24 02:53:30 +00:00
  • 90383e00e9 fix(security): harden autoAllowSkills exec matching Peter Steinberger 2026-02-24 02:52:57 +00:00
  • e578521ef4 fix(security): harden session export image data-url handling Peter Steinberger 2026-02-24 02:52:33 +00:00
  • fefc414576 fix(security): harden structural session path fallback Peter Steinberger 2026-02-24 02:52:25 +00:00
  • ff4e6ca0d9 fix(ios): gate agent deep links with local confirmation Peter Steinberger 2026-02-24 02:51:27 +00:00
  • f8524ec77a fix(security): harden exported session html rendering Peter Steinberger 2026-02-24 02:40:03 +00:00
  • f6afc8c5b6 docs(security): clarify host-side exec trust model defaults Peter Steinberger 2026-02-24 02:39:58 +00:00
  • 1d28da55a5 fix(voice-call): block Twilio webhook replay and stale transitions Peter Steinberger 2026-02-24 02:37:04 +00:00
  • 4663d68384 Tests: make model-catalog fixtures type-valid Gustavo Madeira Santana 2026-02-23 21:36:25 -05:00
  • ce02ad9643 refactor(agents): centralize sandbox media and fs policy helpers Peter Steinberger 2026-02-24 02:30:45 +00:00
  • 207ec7cfae chore(provider): remove unused pruning functions Gustavo Madeira Santana 2026-02-23 21:30:59 -05:00
  • 4032390572 docs(security): clarify trusted user-triggered local actions Peter Steinberger 2026-02-24 02:29:00 +00:00
  • 3f923e8313 test: add env -S allowlist bypass regressions Peter Steinberger 2026-02-24 02:27:22 +00:00
  • 6634030be3 fix: enforce apply_patch workspaceOnly in sandbox mounts Peter Steinberger 2026-02-24 02:23:30 +00:00
  • c070be1bc4 fix(sandbox): harden fs bridge path checks and bind mount policy Peter Steinberger 2026-02-24 02:21:33 +00:00
  • dd9d9c1c60 fix(security): enforce workspaceOnly for sandbox image tool Peter Steinberger 2026-02-24 02:17:06 +00:00
  • 0026255def refactor(security): harden system.run wrapper enforcement Peter Steinberger 2026-02-24 02:17:24 +00:00
  • 5239b55c0a Config: expand Kilo catalog and persist selected Kilo models (#24921) Gustavo Madeira Santana 2026-02-23 21:17:37 -05:00
  • 6c441ea797 fix: support legacy and beta prerelease version formats Peter Steinberger 2026-02-24 02:05:29 +00:00
  • 08e2aa44e7 fix(commands): restrict commands.allowFrom to sender principals Peter Steinberger 2026-02-24 02:00:54 +00:00
  • 223d7dc23d feat(gateway)!: require explicit non-loopback control-ui origins Peter Steinberger 2026-02-24 01:52:15 +00:00
  • edfefdff7d docs(changelog): mark ACP hardening as next npm release Peter Steinberger 2026-02-24 01:56:16 +00:00
  • a1c4bf07c6 fix(security): harden exec wrapper allowlist execution parity Peter Steinberger 2026-02-24 01:51:33 +00:00
  • 5eb72ab769 fix(security): harden browser SSRF defaults and migrate legacy key Peter Steinberger 2026-02-24 01:51:44 +00:00
  • 8779b523dc test(sandbox): speed up agent-config coverage with pure resolvers Peter Steinberger 2026-02-24 01:46:04 +00:00
  • 467666adc7 test(sandbox): use focused modules in lightweight suites Peter Steinberger 2026-02-24 01:45:58 +00:00
  • f0f886ecc4 docs(security): clarify gateway-node trust boundary in docs Peter Steinberger 2026-02-24 01:35:40 +00:00
  • 1f81677093 docs(changelog): note dangerous name-matching audit unification Peter Steinberger 2026-02-24 01:33:00 +00:00
  • 161d9841dc refactor(security): unify dangerous name matching handling Peter Steinberger 2026-02-24 01:32:23 +00:00
  • 6a7c303dcc test(msteams): fix allowlist name-match expectations Peter Steinberger 2026-02-24 01:26:53 +00:00
  • 2e36bdda85 docs(changelog): credit ACP security reporter Peter Steinberger 2026-02-24 01:18:58 +00:00
  • 22467902ea fix(doctor): inherit dangerous name-matching flag in mutable allowlist scan Peter Steinberger 2026-02-24 01:16:14 +00:00
  • e5931554bf test: tighten slow test timeouts and cleanup Peter Steinberger 2026-02-24 01:16:43 +00:00
  • 6c43d0a08e test(gateway): move sessions_send error paths to unit tests Peter Steinberger 2026-02-24 01:16:36 +00:00
  • 63dcd28ae0 fix(acp): harden permission tool-name validation Peter Steinberger 2026-02-24 01:11:24 +00:00
  • f97c0922e1 fix(security): harden account-key handling against prototype pollution Peter Steinberger 2026-02-24 01:09:23 +00:00
  • 12cc754332 fix(acp): harden permission auto-approval policy Peter Steinberger 2026-02-24 01:03:12 +00:00
  • ddf93d9845 docs(security): add vps trust-boundary guidance Peter Steinberger 2026-02-24 01:02:06 +00:00
  • cfa44ea6b4 fix(security): make allowFrom id-only by default with dangerous name opt-in (#24907) Peter Steinberger 2026-02-24 01:01:51 +00:00
  • 41b0568b35 docs(security): clarify shared-agent trust boundaries Peter Steinberger 2026-02-24 00:59:20 +00:00
  • 0cc327546b test(gateway): speed up slow e2e test setup Peter Steinberger 2026-02-24 00:59:44 +00:00
  • 13478cc79a refactor(config): harden catchall hint mapping and array fallback Peter Steinberger 2026-02-24 00:59:44 +00:00
  • 30c622554f Providers: disable developer role for DashScope-compatible endpoints (#24675) Vincent Koc 2026-02-23 19:51:16 -05:00
  • 83eae14ed6 docs: add security-advisory triage reminder to agents guide Peter Steinberger 2026-02-24 00:45:41 +00:00
  • 400220275c docs: clarify multi-instance recommendations for user isolation Peter Steinberger 2026-02-24 00:40:04 +00:00
  • a430e1722b test(channels): reduce media test runtime and polling Peter Steinberger 2026-02-24 00:31:43 +00:00
  • 663f784e4e test(core): trim redundant setup and tighten waits Peter Steinberger 2026-02-24 00:31:36 +00:00
  • f58c1ef34e test(gateway): speed up contract and polling suites Peter Steinberger 2026-02-24 00:31:30 +00:00
  • 7d55277d72 docs: clarify operator trust boundary for shared gateways Peter Steinberger 2026-02-24 00:24:48 +00:00
  • f0c3c8b6a3 fix(config): redact dynamic catchall secret keys Peter Steinberger 2026-02-24 00:21:19 +00:00
  • 8dfa33d373 test(sandbox): add root bind mount regression Peter Steinberger 2026-02-24 00:17:03 +00:00
  • d68380bb7f docs(security): clarify exposed-secret report scope Peter Steinberger 2026-02-24 00:17:00 +00:00
  • 25f6fcc63a docs(changelog): note safeBins exec hardening Peter Steinberger 2026-02-23 23:58:54 +00:00
  • 3b8e33037a fix(security): harden safeBins long-option validation Peter Steinberger 2026-02-23 23:55:28 +00:00
  • 7b4d2cb5cb docs(security): clarify trusted-config dos scope Peter Steinberger 2026-02-23 23:57:26 +00:00
  • a2dfe9879f fix(security): harden regex compilation for filters and redaction Peter Steinberger 2026-02-23 23:54:46 +00:00
  • e6484cb65f refactor: harden kilocode auth ordering and dedupe provider wiring Peter Steinberger 2026-02-23 23:37:07 +00:00
  • f52a0228ca test: optimize auth and audit test runtime Peter Steinberger 2026-02-23 23:31:42 +00:00
  • 13f32e2f7d feat: Add Kilo Gateway provider (#20212) John Fawcett 2026-02-23 17:29:27 -06:00
  • ddb7ec99a8 test: speed up cron test polling and waits Peter Steinberger 2026-02-23 22:42:15 +00:00
  • 0cc46d774c test: consolidate auth-choice tests for faster coverage Peter Steinberger 2026-02-23 22:42:11 +00:00
  • eff3c5c707 Session/Cron maintenance hardening and cleanup UX (#24753) Gustavo Madeira Santana 2026-02-23 17:39:48 -05:00
  • 29b19455e3 test(commands): collapse provider and endpoint matrices Peter Steinberger 2026-02-23 22:16:45 +00:00
  • b922ecb8c1 test(security): reduce duplicate audit assertions Peter Steinberger 2026-02-23 22:16:39 +00:00
  • cd5f3fe0c1 test(config): consolidate env/include scenario coverage Peter Steinberger 2026-02-23 22:16:30 +00:00
  • c248c515a3 test: collapse sandbox agent config duplicate cases Peter Steinberger 2026-02-23 22:01:32 +00:00
  • 287586206c test: consolidate sandbox docker merge scenarios Peter Steinberger 2026-02-23 22:01:22 +00:00
  • 8b192beaaf test: combine web reconnect progression assertions Peter Steinberger 2026-02-23 21:57:30 +00:00
  • ecd278b67b test: merge redundant telegram media path scenarios Peter Steinberger 2026-02-23 21:57:23 +00:00
  • ca761d6225 test: consolidate gateway auth test scenarios Peter Steinberger 2026-02-23 21:57:17 +00:00
  • b9f01e8d3f test: consolidate directive behavior suites for faster runs Peter Steinberger 2026-02-23 21:48:12 +00:00
  • b8fc8e7e6d test: optimize directive behavior test scenarios Peter Steinberger 2026-02-23 21:35:36 +00:00
  • 0183610db3 refactor: de-duplicate channel runtime and payload helpers Peter Steinberger 2026-02-23 21:25:20 +00:00
  • 0ae7f470a2 test: normalize skill prompt path assertions on windows Peter Steinberger 2026-02-23 21:17:29 +00:00
  • 31ca7fb277 test: consolidate directive behavior test scenarios Peter Steinberger 2026-02-23 21:13:11 +00:00
  • 426f803b8a test: speed up sessions_spawn tool harness Peter Steinberger 2026-02-23 21:13:05 +00:00
  • 7e5f771d27 test: speed up skills test suites Peter Steinberger 2026-02-23 21:02:05 +00:00
  • 75423a00d6 refactor: deduplicate shared helpers and test setup Peter Steinberger 2026-02-23 20:40:38 +00:00
  • 1f5e6444ee test: remove redundant pi embedded runner cases Peter Steinberger 2026-02-23 20:15:45 +00:00