haelyra
99668f0ef5
fix: resolve nested PowerShell command tokens
2026-09-05 17:38:20 -04:00
haelyra
cb5311222d
fix: scan inline PowerShell command parameters
2026-09-05 17:29:02 -04:00
haelyra
56552d964f
docs: record final ECC-039 verification
2026-09-05 16:58:31 -04:00
haelyra
f43195a255
fix: expand nested PowerShell command scalars
2026-09-05 16:57:10 -04:00
haelyra
8eeac94af3
fix: preserve PowerShell expansion semantics
2026-09-05 16:32:15 -04:00
haelyra
3ad828db47
fix: address PowerShell review bypasses
2026-09-05 16:12:58 -04:00
haelyra
d9f6091ee8
fix: close PowerShell destructive command gate bypass
2026-09-04 15:02:57 -04:00
haelyra and GitHub
e04ea0b9cc
Merge pull request #2949 from affaan-m/dependabot/github_actions/actions-minor-and-patch-6512b1d693
...
chore(deps): bump softprops/action-gh-release from 3.0.2 to 3.0.3 in the actions-minor-and-patch group across 1 directory
2026-09-03 16:51:15 -04:00
dependabot[bot] and GitHub
6a1e0c1bc5
chore(deps): bump softprops/action-gh-release
...
Bumps the actions-minor-and-patch group with 1 update in the / directory: [softprops/action-gh-release](https://github.com/softprops/action-gh-release ).
Updates `softprops/action-gh-release` from 3.0.2 to 3.0.3
- [Release notes](https://github.com/softprops/action-gh-release/releases )
- [Changelog](https://github.com/softprops/action-gh-release/blob/master/CHANGELOG.md )
- [Commits](https://github.com/softprops/action-gh-release/compare/3d0d9888cb7fd7b750713d6e236d1fcb99157228...efb35369e0ad2afab669f228072c1b0d510eae64 )
---
updated-dependencies:
- dependency-name: softprops/action-gh-release
dependency-version: 3.0.3
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: actions-minor-and-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-09-03 20:05:14 +00:00
haelyra and GitHub
d1955a66f6
Merge pull request #2948 from haelyra/maint/dependabot-2026-09-03
...
chore(deps): consolidate verified Dependabot updates
2026-09-03 16:03:10 -04:00
haelyra
8059798888
fix(deps): pin patched @humanfs/node
...
Keep npm and Yarn resolution policy aligned so both lockfile paths stay on the patched release.\n\nCo-authored-by: Svector-anu <svector-anu@users.noreply.github.com >
2026-09-03 15:08:04 -04:00
haelyra
b74e0add1d
test: synchronize dependency update coverage
2026-09-03 15:00:31 -04:00
dependabot[bot] and haelyra
d330b57a50
chore(deps): bump @humanfs/node
...
Bumps the npm-security group with 1 update in the / directory: [@humanfs/node](https://github.com/humanwhocodes/humanfs/tree/HEAD/packages/node ).
Updates `@humanfs/node` from 0.16.7 to 0.16.8
- [Release notes](https://github.com/humanwhocodes/humanfs/releases )
- [Changelog](https://github.com/humanwhocodes/humanfs/blob/main/packages/node/CHANGELOG.md )
- [Commits](https://github.com/humanwhocodes/humanfs/commits/node-v0.16.8/packages/node )
---
updated-dependencies:
- dependency-name: "@humanfs/node"
dependency-version: 0.16.8
dependency-type: indirect
dependency-group: npm-security
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-09-03 14:59:21 -04:00
dependabot[bot] and haelyra
bd97cbe451
chore(deps): bump the npm-minor-and-patch group across 1 directory with 6 updates
...
Bumps the npm-minor-and-patch group with 6 updates in the / directory:
| Package | From | To |
| --- | --- | --- |
| [sql.js](https://github.com/sql-js/sql.js ) | `1.14.1` | `1.14.2` |
| @opencode-ai/plugin | `1.17.3` | `1.18.25` |
| [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node ) | `26.1.2` | `26.4.0` |
| [eslint](https://github.com/eslint/eslint ) | `10.6.0` | `10.9.1` |
| [globals](https://github.com/sindresorhus/globals ) | `17.4.0` | `17.11.0` |
| [markdownlint-cli](https://github.com/igorshubovych/markdownlint-cli ) | `0.48.0` | `0.49.1` |
Updates `sql.js` from 1.14.1 to 1.14.2
- [Release notes](https://github.com/sql-js/sql.js/releases )
- [Commits](https://github.com/sql-js/sql.js/compare/v1.14.1...v1.14.2 )
Updates `@opencode-ai/plugin` from 1.17.3 to 1.18.25
Updates `@types/node` from 26.1.2 to 26.4.0
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases )
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node )
Updates `eslint` from 10.6.0 to 10.9.1
- [Release notes](https://github.com/eslint/eslint/releases )
- [Commits](https://github.com/eslint/eslint/compare/v10.6.0...v10.9.1 )
Updates `globals` from 17.4.0 to 17.11.0
- [Release notes](https://github.com/sindresorhus/globals/releases )
- [Commits](https://github.com/sindresorhus/globals/compare/v17.4.0...v17.11.0 )
Updates `markdownlint-cli` from 0.48.0 to 0.49.1
- [Release notes](https://github.com/igorshubovych/markdownlint-cli/releases )
- [Commits](https://github.com/igorshubovych/markdownlint-cli/compare/v0.48.0...v0.49.1 )
---
updated-dependencies:
- dependency-name: "@opencode-ai/plugin"
dependency-version: 1.18.19
dependency-type: direct:development
update-type: version-update:semver-minor
dependency-group: npm-minor-and-patch
- dependency-name: "@types/node"
dependency-version: 26.2.0
dependency-type: direct:development
update-type: version-update:semver-minor
dependency-group: npm-minor-and-patch
- dependency-name: eslint
dependency-version: 10.8.1
dependency-type: direct:development
update-type: version-update:semver-minor
dependency-group: npm-minor-and-patch
- dependency-name: globals
dependency-version: 17.11.0
dependency-type: direct:development
update-type: version-update:semver-minor
dependency-group: npm-minor-and-patch
- dependency-name: markdownlint-cli
dependency-version: 0.49.1
dependency-type: direct:development
update-type: version-update:semver-minor
dependency-group: npm-minor-and-patch
- dependency-name: sql.js
dependency-version: 1.14.2
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: npm-minor-and-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-09-03 14:59:21 -04:00
dependabot[bot] and haelyra
8dfa7cec0a
chore(deps): bump the cargo-minor-and-patch group across 1 directory with 4 updates
...
Bumps the cargo-minor-and-patch group with 4 updates in the /ecc2 directory: [rusqlite](https://github.com/rusqlite/rusqlite ), [ureq](https://github.com/algesten/ureq ), [thiserror](https://github.com/dtolnay/thiserror ) and [uuid](https://github.com/uuid-rs/uuid ).
Updates `rusqlite` from 0.40.1 to 0.40.2
- [Release notes](https://github.com/rusqlite/rusqlite/releases )
- [Changelog](https://github.com/rusqlite/rusqlite/blob/master/Changelog.md )
- [Commits](https://github.com/rusqlite/rusqlite/compare/v0.40.1...v0.40.2 )
Updates `ureq` from 3.3.0 to 3.4.0
- [Changelog](https://github.com/algesten/ureq/blob/main/CHANGELOG.md )
- [Commits](https://github.com/algesten/ureq/compare/3.3.0...3.4.0 )
Updates `thiserror` from 2.0.19 to 2.0.20
- [Release notes](https://github.com/dtolnay/thiserror/releases )
- [Commits](https://github.com/dtolnay/thiserror/compare/2.0.19...2.0.20 )
Updates `uuid` from 1.24.0 to 1.26.0
- [Release notes](https://github.com/uuid-rs/uuid/releases )
- [Commits](https://github.com/uuid-rs/uuid/compare/v1.24.0...v1.26.0 )
---
updated-dependencies:
- dependency-name: rusqlite
dependency-version: 0.40.2
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: cargo-minor-and-patch
- dependency-name: thiserror
dependency-version: 2.0.20
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: cargo-minor-and-patch
- dependency-name: ureq
dependency-version: 3.4.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: cargo-minor-and-patch
- dependency-name: uuid
dependency-version: 1.24.1
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: cargo-minor-and-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-09-03 14:59:21 -04:00
dependabot[bot] and haelyra
45a48d5e1b
chore(deps): bump the actions-minor-and-patch group across 1 directory with 2 updates
...
Bumps the actions-minor-and-patch group with 2 updates in the / directory: [actions/checkout](https://github.com/actions/checkout ) and [pnpm/action-setup](https://github.com/pnpm/action-setup ).
Updates `actions/checkout` from 7.0.0 to 7.0.1
- [Release notes](https://github.com/actions/checkout/releases )
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md )
- [Commits](https://github.com/actions/checkout/compare/9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0...3d3c42e5aac5ba805825da76410c181273ba90b1 )
Updates `pnpm/action-setup` from 6.0.9 to 6.0.10
- [Release notes](https://github.com/pnpm/action-setup/releases )
- [Commits](https://github.com/pnpm/action-setup/compare/0ebf47130e4866e96fce0953f49152a61190b271...0977fd99725f1db4007ccb2928dbb4e90d06cc86 )
---
updated-dependencies:
- dependency-name: actions/checkout
dependency-version: 7.0.1
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: actions-minor-and-patch
- dependency-name: pnpm/action-setup
dependency-version: 6.0.10
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: actions-minor-and-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-09-03 14:59:21 -04:00
haelyra
23fb7e0c79
ci: avoid redundant Python dependency floors
2026-09-03 14:59:01 -04:00
haelyra and GitHub
22e8cf01d0
test(ci): scale repair timeout on Windows ( #2942 )
2026-09-02 20:48:57 -04:00
haelyra and GitHub
d3652039ac
test(hooks): drain bootstrap children asynchronously ( #2941 )
...
* test(hooks): drain bootstrap children asynchronously
* test(hooks): harden async supervisor lifecycle
* test(hooks): accept Windows child stdin closure
2026-09-02 19:55:26 -04:00
haelyra and GitHub
11813f968c
test(hooks): avoid repeated giant wrapper payloads ( #2940 )
...
* test(hooks): avoid repeated giant wrapper payloads
* test(hooks): assert callback-governed wrapper exits
2026-09-02 17:47:04 -04:00
haelyra and GitHub
90430ab3a7
test(ci): tolerate loaded macOS hook runners ( #2939 )
2026-09-02 16:37:08 -04:00
haelyra and GitHub
348f80a89b
fix(security): update fast-uri to 3.1.7 ( #2936 )
2026-09-02 15:13:20 -04:00
Wu Shuwen and GitHub
de899ac472
fix(tests): preserve session alias HOME isolation ( #2877 )
2026-09-02 14:24:39 -04:00
haelyra and GitHub
ca185ef5f7
chore(release): prepare signed 2.2.1 patch ( #2920 )
2026-08-31 18:14:22 -04:00
Affaan Mustafa and GitHub
a104765bf2
docs(ito-compute): document ito accept and ito_accept MCP workflow ( #2893 )
...
* docs(ito-compute): document ito accept and ito_accept MCP workflow
Updates the canonical ECC skill to cover the new quote acceptance path:
- CLI: ecc ito accept <ticket-id>
- MCP: ito_accept tool
- Explicit buyer-authority guard before accepting
- Clear statement that accept routes to desk, does not purchase
* test(ito-compute): assert the four-tool MCP boundary including ito_accept
The exact-boundary test pinned the three-tool description. Runtime
ito-compute-cli now exposes ito_accept (Ito-Markets/ito-cloud-runtime#1453 ),
so the template boundary assertion moves to four tools.
* docs(ito-compute): drop the firm-quote gate from the accept workflow
Desk quotes are indicative_paper in production (a firm quote requires the
separate human-held signing path and cannot reach the client), so gating
accept on 'a firm quote is ready' described an unfireable condition. Align
with the runtime contract: accept routes the current desk quote to human
review and the result carries quote_class (ito-cloud-runtime#1453).
2026-08-31 15:16:16 -04:00
haelyra and GitHub
005eff40fd
fix(install): harden universal setup release path ( #2888 )
...
* fix(install): harden universal setup release path
* docs(adal): use ecc-universal doctor command
2026-08-30 18:54:00 -04:00
haelyra and GitHub
ce64e417fd
Merge pull request #2913 from affaan-m/fix/opencode-hook-consent
...
fix(install): preserve opencode non-hook defaults
2026-08-30 15:52:28 -04:00
haelyra
64d0d9436f
fix(install): preserve opencode non-hook defaults
2026-08-30 15:35:47 -04:00
haelyra and GitHub
19e2f2b46d
Merge pull request #2912 from affaan-m/fix/packed-install-hook-consent
...
test(ci): confirm hooks in packed target smoke
2026-08-30 15:20:35 -04:00
haelyra
d26b9cccee
test(ci): confirm hooks in packed target smoke
2026-08-30 15:19:01 -04:00
haelyra and GitHub
8211578ee7
Merge pull request #2715 from affaan-m/feat/hook-runtime-consent
...
feat(install): require an explicit hook decision at the apply layer
2026-08-30 15:13:28 -04:00
haelyra
caee3ee455
test(ci): opt in to hooks in packed lifecycle smoke
2026-08-30 15:13:07 -04:00
haelyra and Claude Fable 5
bdbd90a47f
test(install): scale uninstall CLI timeout for Windows CI
...
The uninstall cases run two full CLI passes (install, then uninstall)
over several hundred files under a flat 30s timeout, which is tight
enough on Windows CI to fail intermittently with spawnSync ETIMEDOUT.
install-apply.test.js already scales its timeout by platform for the
same reason; match that precedent rather than re-running past the flake.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com >
2026-08-30 15:09:34 -04:00
6aaa41e028
feat(install): require an explicit hook decision at the apply layer
...
The guided installer asks how ECC hooks should run, but that consent
lived only in the wizard path. Running install-apply directly with a
profile that includes hooks-runtime still materialized the hook runtime
with no disclosure and no decision.
Gate the apply layer instead, so every entry point is covered:
- disclose the six hook capability groups when a plan would materialize
the hook runtime, and refuse to apply until the caller decides
- --enable-hooks confirms the hook runtime; --no-hooks installs the rest
of the selection without it and records the reduced module closure in
install-state
- surface the pending decision as a dry-run warning
- show the same capability disclosure in the guided installer's plan
preview, so the wizard's hook question states what it is asking about
Plans that never materialize hooks (Kimi, --profile minimal,
--without baseline:hooks) are unaffected and need no flag. Repair and
uninstall operate on already-recorded state and stay unchanged.
The capability taxonomy and the held-materialization behavior come from
Samarjeet Singh Tomar's PR #2634 , reworked to fit the single-decision
consent model that shipped with the guided installer in #2649 .
Co-Authored-By: Samarjeet Singh Tomar <samar_tomar@hotmail.com >
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com >
2026-08-30 15:09:34 -04:00
haelyra and GitHub
a89cec9658
Merge pull request #2854 from samartomar/codex/issue-744-pure-plan
...
refactor(install): expose pure manifest planner
2026-08-30 14:50:53 -04:00
haelyra and GitHub
d8e6a51755
Merge pull request #2902 from affaan-m/maint/pr-stewardship-portability-2026-08-29
...
fix: forward-port reviewed ECC 2.2 fixes (13 PRs)
2026-08-29 16:30:55 -04:00
haelyra
299544e680
fix: count observations for whitespace paths
2026-08-29 16:07:00 -04:00
haelyra
1bdda4bdac
fix: close validator and path edge cases
2026-08-29 15:36:59 -04:00
haelyra
703163275d
test: honor per-invocation Bash overrides
2026-08-29 15:11:38 -04:00
dependabot[bot] and haelyra
2f895a1823
chore(deps): bump actions/setup-python from 6.2.0 to 7.0.0
...
Bumps [actions/setup-python](https://github.com/actions/setup-python ) from 6.2.0 to 7.0.0.
- [Release notes](https://github.com/actions/setup-python/releases )
- [Commits](https://github.com/actions/setup-python/compare/a309ff8b426b58ec0e2a45f0f869d46889d02405...5fda3b95a4ea91299a34e894583c3862153e4b97 )
---
updated-dependencies:
- dependency-name: actions/setup-python
dependency-version: 7.0.0
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-08-29 15:01:31 -04:00
haelyra
224da03d01
fix(gateguard): match heredoc tab-strip order
2026-08-29 14:55:14 -04:00
haelyra
fab534f924
test(hooks): keep matcher mirrors in sync
2026-08-29 14:55:14 -04:00
a4d72b2271
fix(gateguard): surface graduated recovery hints
...
Change-Id: I6ade0a2a54a26bd5721c62edf7efa462e8043a08
Co-authored-by: TRAE CLI <traecli@bytedance.com >
2026-08-29 14:55:14 -04:00
dajiaohuang and haelyra
c40d0e4f7c
fix: normalize heredoc line continuations
2026-08-29 14:55:14 -04:00
dajiaohuang and haelyra
9768c075c3
refactor: keep heredoc scanning linear
2026-08-29 14:55:14 -04:00
dajiaohuang and haelyra
9a3ee6864a
refactor: keep heredoc parser state immutable
2026-08-29 14:55:14 -04:00
dajiaohuang and haelyra
e72191ba74
fix: harden heredoc command filtering
2026-08-29 14:55:14 -04:00
dajiaohuang and haelyra
962380c452
fix: ignore heredoc prose in GateGuard
2026-08-29 14:55:14 -04:00
Suliman Abdulrazzaq and haelyra
6fa3efeef7
fix(hooks): use valid wildcard matchers
2026-08-29 14:55:14 -04:00
haelyra
30c41a9bde
fix: close truth and portability review gaps
2026-08-29 14:55:14 -04:00