Commit Graph

  • 684578ecf6 CI: drop trusted label for experienced contributors (#15605) Shadow 2026-02-13 11:23:05 -06:00
  • 3d921b6157 fix(slack): apply limit parameter to emoji-list action (#13421) Marcus Castro 2026-02-13 14:20:41 -03:00
  • 86e4fe0a7a Auth: land codex oauth onboarding flow (#15406) Mariano Belinky 2026-02-13 17:18:20 +00:00
  • 7ec60d6449 fix: use relayAbort helper for addEventListener to preserve AbortError reason Marcus Castro 2026-02-06 20:51:04 -03:00
  • 5ac8d1d2bb test: add abort .bind() behavioral tests (#7174) Marcus Castro 2026-02-06 20:30:37 -03:00
  • d9c582627c perf: use .abort.bind() instead of arrow closures to prevent memory leaks (#7174) Marcus Castro 2026-02-06 20:30:29 -03:00
  • d637a26350 Gateway: sanitize WebSocket log headers (#15592) Shadow 2026-02-13 11:11:54 -06:00
  • b3b49bed80 fix(slack): override video/* MIME to audio/* for voice messages (#14941) Marcus Castro 2026-02-13 14:09:04 -03:00
  • 1f4943af3d fix: note Discord guild allowlist resolution (#12326) (thanks @headswim) Shadow 2026-02-13 11:01:02 -06:00
  • f4e295a63b Discord: fix bare guild ID misrouted as channel ID in parser headswim 2026-02-08 23:06:43 -05:00
  • 5325d2ca51 Discord: gate guild prefix to numeric keys Shadow 2026-02-13 10:57:16 -06:00
  • 397011bd78 fix: increase image tool maxTokens from 512 to 4096 (#11770) Lilo 2026-02-14 00:52:27 +08:00
  • 1c36bec970 Apply suggestion from @Copilot Burak Sormageç 2026-02-11 23:28:53 -05:00
  • ff0ce32840 Apply suggestion from @Copilot Burak Sormageç 2026-02-11 23:28:41 -05:00
  • 23b1b51568 fix(windows): normalize env entries for spawn Burak Sormageç 2026-01-30 16:31:35 +00:00
  • e97aa45428 fix(windows): handle undefined environment variables in runCommandWithTimeout Burak Sormageç 2026-01-30 16:17:36 +00:00
  • d7fb01afad fix(windows): resolve command execution and binary detection issues Burak Sormageç 2026-01-30 14:56:46 +00:00
  • 1eccfa8934 perf(test): trim duplicate e2e suites and harden signal hooks Peter Steinberger 2026-02-13 16:46:31 +00:00
  • 45b9aad0f4 fix(imessage): prevent rpc spawn in tests Peter Steinberger 2026-02-13 17:36:30 +01:00
  • aa7fbf0488 perf(test): trim duplicate sanitize-session-history e2e cases Peter Steinberger 2026-02-13 16:21:59 +00:00
  • b272158fe4 perf(test): eliminate resetModules via injectable seams Peter Steinberger 2026-02-13 16:20:31 +00:00
  • a844fb161c build(protocol): regenerate swift gateway models Peter Steinberger 2026-02-13 16:14:49 +00:00
  • 14fc742000 fix(security): restrict canvas IP-based auth to private networks (#14661) Yi Liu 2026-02-14 00:13:31 +08:00
  • e665d77917 perf(test): remove extra module resets in cli and message suites Peter Steinberger 2026-02-13 16:08:33 +00:00
  • 4c86821aca fix: allow device-paired clients to retrieve TTS API keys (#14613) Sk Akram 2026-02-13 21:37:49 +05:30
  • c2f7b66d22 perf(test): replace module resets with direct spies and runtime seams Peter Steinberger 2026-02-13 16:04:43 +00:00
  • 59733a02c8 fix(configure): reject literal "undefined" and "null" gateway auth tokens (#13767) Omair Afzal 2026-02-13 21:04:41 +05:00
  • 4dc93f40d5 docs: add git local-branch cleanup fallback Peter Steinberger 2026-02-13 17:03:39 +01:00
  • 767fd9f222 fix: classify /tools/invoke errors and sanitize 500s (#13185) (thanks @davidrudduck) Peter Steinberger 2026-02-13 16:52:47 +01:00
  • 242f2f1480 fix: return 500 for tool execution failures instead of 400 David Rudduck 2026-02-10 16:08:43 +10:00
  • f788de30c8 fix(security): sanitize error responses to prevent information leakage (#5) David Rudduck 2026-02-09 16:09:29 +10:00
  • de7d94d9e2 perf(test): remove resetModules from config/sandbox/message suites Peter Steinberger 2026-02-13 15:58:08 +00:00
  • 02fe0c840e perf(test): remove resetModules from auth/models/subagent suites Peter Steinberger 2026-02-13 15:53:26 +00:00
  • c179f71f42 feat: Android companion app improvements & gateway URL camera payloads (#13541) Ahmad Bitar 2026-02-13 23:49:28 +08:00
  • 41f2f359a5 perf(test): reduce module reload overhead in key suites Peter Steinberger 2026-02-13 15:45:08 +00:00
  • 4337fa2096 fix: remove any from doctor-security dmScope regression test (#13129) (thanks @VintLin) Peter Steinberger 2026-02-13 16:43:13 +01:00
  • f612e35907 fix: add dmScope guidance regression coverage (#13129) (thanks @VintLin) Peter Steinberger 2026-02-13 16:42:49 +01:00
  • ca3c83acdf fix(security): clarify dmScope remediation path with explicit CLI command VintLin 2026-02-10 12:39:14 +08:00
  • 31c6a12cfa fix(agents): restore missing runtime helpers and sandbox types Peter Steinberger 2026-02-13 15:42:00 +00:00
  • 5643a93479 fix(security): default standalone servers to loopback bind (#13184) David Rudduck 2026-02-14 01:39:56 +10:00
  • a17f74306d docs(changelog): note codex spark implementation and merged PR attributions Mariano Belinky 2026-02-13 15:39:13 +00:00
  • 5d8eef8b35 perf(test): remove module reloads in browser and embedding suites Peter Steinberger 2026-02-13 15:31:09 +00:00
  • 29d7839582 fix: execute sandboxed file ops inside containers (#4026) davidbors-snyk 2026-02-13 17:29:10 +02:00
  • 1def8c5448 fix(security): extend audit hardening checks Peter Steinberger 2026-02-13 16:26:37 +01:00
  • faa4959111 fix(onboard): include vllm auth group id Peter Steinberger 2026-02-13 15:23:46 +00:00
  • 2e04630105 openai-codex: add gpt-5.3-codex-spark forward-compat model (#15174) loiie45e 2026-02-13 23:21:07 +08:00
  • 96318641d8 fix: Finish credential redaction that was merged unfinished (#13073) Henry Loenwind 2026-02-13 16:19:21 +01:00
  • faec6ccb1d perf(test): reduce module reload churn in unit suites Peter Steinberger 2026-02-13 15:19:09 +00:00
  • 6c4c535813 fix(security): handle additional Unicode angle bracket homoglyphs in content sanitization (#14665) Yi Liu 2026-02-13 23:18:54 +08:00
  • 08b7932df0 feat(agents) : Hugging Face Inference provider first-class support and Together API fix and Direct Injection Refactor Auths [AI-assisted] (#13472) Tonic 2026-02-13 16:18:16 +01:00
  • e50ce897b0 chore(skills): remove duplicate local-places skill Peter Steinberger 2026-02-13 16:15:36 +01:00
  • 4169a4df79 perf(test): remove redundant status module reloads Peter Steinberger 2026-02-13 15:07:28 +00:00
  • 79f4c4c584 perf(test): trim module resets in config suites Peter Steinberger 2026-02-13 15:04:43 +00:00
  • a5faea614b fix(msteams): detect windows local paths for uploads Peter Steinberger 2026-02-13 15:07:27 +00:00
  • c60780ba20 security: enforce 0o600 permissions on WhatsApp credential files (#10529) Abdel Fane 2026-02-13 08:02:15 -07:00
  • 945d302956 test: speed up e2e vitest runtime Peter Steinberger 2026-02-13 14:57:09 +00:00
  • ab4adf7170 fix(macos): ensure exec approval prompt displays the command (#5042) shayan919293 2026-02-13 06:49:06 -08:00
  • a7d6e44719 perf(test): reduce test startup overhead Peter Steinberger 2026-02-13 14:40:23 +00:00
  • 3bcde8df32 fix: finalize vLLM onboarding integration (#12577) (thanks @gejifeng) Peter Steinberger 2026-02-13 15:47:30 +01:00
  • 513fd835a1 tests: fix vLLM onboarding selection gejifeng 2026-02-11 10:46:20 +00:00
  • d44c118334 fix: avoid unused custom preferred provider gejifeng 2026-02-11 08:58:17 +00:00
  • e6715bcb64 format: fix onboarding.ts wrapping gejifeng 2026-02-11 08:13:21 +00:00
  • 03c502ef31 lint: fix unused imports and onboarding preferred provider gejifeng 2026-02-11 08:08:08 +00:00
  • 94d5411f11 fix: remove duplicate TOGETHER_BASE_URL gejifeng 2026-02-11 08:05:37 +00:00
  • 3e7956b008 fix code review gejifeng 2026-02-11 08:00:54 +00:00
  • 0472dd68f0 fix code review gejifeng 2026-02-11 07:53:19 +00:00
  • e73d881c50 Onboarding: add vLLM provider support gejifeng 2026-02-09 10:20:45 +00:00
  • 54bf5d0f41 feat(web-fetch): support Cloudflare Markdown for Agents (#15376) Yaxuan42 2026-02-13 22:46:20 +08:00
  • 7467fcc529 security: use openFileWithinRoot for A2UI file serving (#10525) Abdel Fane 2026-02-13 07:37:10 -07:00
  • 30b6eccae5 feat(gateway): add auth rate-limiting & brute-force protection (#15035) Harald Buerbaumer 2026-02-13 15:32:38 +01:00
  • 9131b22a28 test: migrate suites to e2e coverage layout Peter Steinberger 2026-02-13 14:28:12 +00:00
  • f5160ca6be test: add browser evaluate gate trust-boundary regression Peter Steinberger 2026-02-13 15:18:57 +01:00
  • 25950bcbb8 fix(sessions): normalize absolute sessionFile paths for v2026.2.12 compatibility Ion Mudreac 2026-02-13 16:51:46 +08:00
  • 106d605519 fix: harden msteams mentions and fallback links (#15436) (thanks @hyojin) Peter Steinberger 2026-02-13 15:08:48 +01:00
  • 604dc700a6 MSTeams: fix regex injection in mention name formatting Hyojin Kwak 2026-02-13 22:07:44 +09:00
  • 73c6c80b77 Docs: add User.Read.All permission info for MS Teams user mentions Hyojin Kwak 2026-02-13 21:47:06 +09:00
  • 7c6d6ce06f MS Teams: add user mention support Hyojin Kwak 2026-02-13 21:38:51 +09:00
  • edfdd12d37 TTS: add missing OpenAI voices (ballad, cedar, juniper, marin, verse) (openclaw#11020) thanks @lailoo 大猫子 2026-02-13 21:54:00 +08:00
  • ee31cd47b4 fix: close OC-02 gaps in ACP permission + gateway HTTP deny config (#15390) (thanks @aether-ai-agent) Peter Steinberger 2026-02-13 14:28:50 +01:00
  • 749e28dec7 fix(security): block dangerous tools from HTTP gateway and fix ACP auto-approval (OC-02) aether-ai-agent 2026-02-13 22:28:43 +11:00
  • 8899f9e94a perf(test): optimize heavy suites and stabilize lock timing Peter Steinberger 2026-02-13 13:28:23 +00:00
  • 8307f9738b fix: add changelog entry for signal-cli arch-aware install (#15443) (thanks @jogvan-k) Peter Steinberger 2026-02-13 14:25:02 +01:00
  • 771c7ba14e test: add pickAsset unit tests for architecture-aware signal-cli install Harrington-bot 2026-02-13 13:10:48 +00:00
  • eb4a0a84f2 fix: use Homebrew for signal-cli install on non-x64 architectures Harrington-bot 2026-02-13 13:00:51 +00:00
  • 990413534a fix: land multi-agent session path fix + regressions (#15103) (#15448) Peter Steinberger 2026-02-13 14:17:24 +01:00
  • 5d37b204c0 Tests: disable vmForks on Node 24 and document override Sebastian 2026-02-13 08:15:25 -05:00
  • 94763cd87d Fix OpenAI/Codex tool call id sanitization for transcript policy (#15279) JINNYEONG KIM 2026-02-13 20:39:51 +09:00
  • 07faab6ac3 openai-codex: bridge OAuth profiles into pi auth.json for model discovery (#15184) loiie45e 2026-02-13 19:39:37 +08:00
  • e3cb2564d7 Agents: allow gpt-5.3-codex-spark in fallback and thinking (#14990) Lucky 2026-02-13 12:39:22 +01:00
  • 417509c539 test: stabilize local-timestamp assertion in session resets Peter Steinberger 2026-02-13 04:58:11 +00:00
  • 67251e97bd fix(ci): sync extension versions to root release (#15199) Peter Steinberger 2026-02-13 05:54:03 +01:00
  • fd076eb43a fix: /status shows incorrect context percentage — totalTokens clamped to contextTokens (#15114) (#15133) 青雲 2026-02-13 12:52:19 +08:00
  • b93ad2cd48 fix(slack): populate thread session with existing thread history (#7610) Masataka Shinohara 2026-02-13 13:51:04 +09:00
  • daf13dbb06 fix: enforce feishu dm policy + pairing flow (#14876) (thanks @coygeek) Peter Steinberger 2026-02-13 05:43:30 +01:00
  • f05553413d fix(aa-01): apply security fix Coy Geek 2026-02-10 15:37:51 -08:00
  • 78ec0a1edf fix: stabilize test runner and daemon-cli compat Peter Steinberger 2026-02-13 04:45:04 +00:00
  • ba7dccc49d test: speed up test suite and trim redundant onboarding tests Peter Steinberger 2026-02-13 04:30:39 +00:00
  • ac41176532 Auto-reply: fix non-default agent session transcript path resolution (#15154) Gustavo Madeira Santana 2026-02-12 23:23:12 -05:00
  • 79a38858ae fix: preserve off-mode semantics in auto reply threading (#14976) (thanks @Diaspar4u) Peter Steinberger 2026-02-13 05:20:47 +01:00
  • 3d89f0f14a fix(reply): auto-inject replyToCurrent for reply threading Andrey 2026-02-12 14:44:53 -05:00