haelyra
dbe8bfbba9
fix(install): pin Claude settings parent during atomic replacement
...
Reject directory replacement after temporary file creation or staging, preserve unrelated files during cleanup, and retry settings edits observed before the final rename. Add three regression tests for the review findings.
2026-09-07 16:31:33 -04:00
wellkilo
f59cfd57c2
fix(install): harden Claude settings lifecycle
2026-09-07 01:57:04 +08:00
wellkilo
26d3e0038b
fix(install): surface Claude settings failures
2026-09-07 01:13:20 +08:00
wellkilo
569e5a36bb
feat(install): register manual Claude hooks
2026-09-07 00:53:13 +08:00
haelyra and GitHub
e04ea0b9cc
Merge pull request #2949 from affaan-m/dependabot/github_actions/actions-minor-and-patch-6512b1d693
...
chore(deps): bump softprops/action-gh-release from 3.0.2 to 3.0.3 in the actions-minor-and-patch group across 1 directory
2026-09-03 16:51:15 -04:00
dependabot[bot] and GitHub
6a1e0c1bc5
chore(deps): bump softprops/action-gh-release
...
Bumps the actions-minor-and-patch group with 1 update in the / directory: [softprops/action-gh-release](https://github.com/softprops/action-gh-release ).
Updates `softprops/action-gh-release` from 3.0.2 to 3.0.3
- [Release notes](https://github.com/softprops/action-gh-release/releases )
- [Changelog](https://github.com/softprops/action-gh-release/blob/master/CHANGELOG.md )
- [Commits](https://github.com/softprops/action-gh-release/compare/3d0d9888cb7fd7b750713d6e236d1fcb99157228...efb35369e0ad2afab669f228072c1b0d510eae64 )
---
updated-dependencies:
- dependency-name: softprops/action-gh-release
dependency-version: 3.0.3
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: actions-minor-and-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-09-03 20:05:14 +00:00
haelyra and GitHub
d1955a66f6
Merge pull request #2948 from haelyra/maint/dependabot-2026-09-03
...
chore(deps): consolidate verified Dependabot updates
2026-09-03 16:03:10 -04:00
haelyra
8059798888
fix(deps): pin patched @humanfs/node
...
Keep npm and Yarn resolution policy aligned so both lockfile paths stay on the patched release.\n\nCo-authored-by: Svector-anu <svector-anu@users.noreply.github.com >
2026-09-03 15:08:04 -04:00
haelyra
b74e0add1d
test: synchronize dependency update coverage
2026-09-03 15:00:31 -04:00
dependabot[bot] and haelyra
d330b57a50
chore(deps): bump @humanfs/node
...
Bumps the npm-security group with 1 update in the / directory: [@humanfs/node](https://github.com/humanwhocodes/humanfs/tree/HEAD/packages/node ).
Updates `@humanfs/node` from 0.16.7 to 0.16.8
- [Release notes](https://github.com/humanwhocodes/humanfs/releases )
- [Changelog](https://github.com/humanwhocodes/humanfs/blob/main/packages/node/CHANGELOG.md )
- [Commits](https://github.com/humanwhocodes/humanfs/commits/node-v0.16.8/packages/node )
---
updated-dependencies:
- dependency-name: "@humanfs/node"
dependency-version: 0.16.8
dependency-type: indirect
dependency-group: npm-security
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-09-03 14:59:21 -04:00
dependabot[bot] and haelyra
bd97cbe451
chore(deps): bump the npm-minor-and-patch group across 1 directory with 6 updates
...
Bumps the npm-minor-and-patch group with 6 updates in the / directory:
| Package | From | To |
| --- | --- | --- |
| [sql.js](https://github.com/sql-js/sql.js ) | `1.14.1` | `1.14.2` |
| @opencode-ai/plugin | `1.17.3` | `1.18.25` |
| [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node ) | `26.1.2` | `26.4.0` |
| [eslint](https://github.com/eslint/eslint ) | `10.6.0` | `10.9.1` |
| [globals](https://github.com/sindresorhus/globals ) | `17.4.0` | `17.11.0` |
| [markdownlint-cli](https://github.com/igorshubovych/markdownlint-cli ) | `0.48.0` | `0.49.1` |
Updates `sql.js` from 1.14.1 to 1.14.2
- [Release notes](https://github.com/sql-js/sql.js/releases )
- [Commits](https://github.com/sql-js/sql.js/compare/v1.14.1...v1.14.2 )
Updates `@opencode-ai/plugin` from 1.17.3 to 1.18.25
Updates `@types/node` from 26.1.2 to 26.4.0
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases )
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node )
Updates `eslint` from 10.6.0 to 10.9.1
- [Release notes](https://github.com/eslint/eslint/releases )
- [Commits](https://github.com/eslint/eslint/compare/v10.6.0...v10.9.1 )
Updates `globals` from 17.4.0 to 17.11.0
- [Release notes](https://github.com/sindresorhus/globals/releases )
- [Commits](https://github.com/sindresorhus/globals/compare/v17.4.0...v17.11.0 )
Updates `markdownlint-cli` from 0.48.0 to 0.49.1
- [Release notes](https://github.com/igorshubovych/markdownlint-cli/releases )
- [Commits](https://github.com/igorshubovych/markdownlint-cli/compare/v0.48.0...v0.49.1 )
---
updated-dependencies:
- dependency-name: "@opencode-ai/plugin"
dependency-version: 1.18.19
dependency-type: direct:development
update-type: version-update:semver-minor
dependency-group: npm-minor-and-patch
- dependency-name: "@types/node"
dependency-version: 26.2.0
dependency-type: direct:development
update-type: version-update:semver-minor
dependency-group: npm-minor-and-patch
- dependency-name: eslint
dependency-version: 10.8.1
dependency-type: direct:development
update-type: version-update:semver-minor
dependency-group: npm-minor-and-patch
- dependency-name: globals
dependency-version: 17.11.0
dependency-type: direct:development
update-type: version-update:semver-minor
dependency-group: npm-minor-and-patch
- dependency-name: markdownlint-cli
dependency-version: 0.49.1
dependency-type: direct:development
update-type: version-update:semver-minor
dependency-group: npm-minor-and-patch
- dependency-name: sql.js
dependency-version: 1.14.2
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: npm-minor-and-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-09-03 14:59:21 -04:00
dependabot[bot] and haelyra
8dfa7cec0a
chore(deps): bump the cargo-minor-and-patch group across 1 directory with 4 updates
...
Bumps the cargo-minor-and-patch group with 4 updates in the /ecc2 directory: [rusqlite](https://github.com/rusqlite/rusqlite ), [ureq](https://github.com/algesten/ureq ), [thiserror](https://github.com/dtolnay/thiserror ) and [uuid](https://github.com/uuid-rs/uuid ).
Updates `rusqlite` from 0.40.1 to 0.40.2
- [Release notes](https://github.com/rusqlite/rusqlite/releases )
- [Changelog](https://github.com/rusqlite/rusqlite/blob/master/Changelog.md )
- [Commits](https://github.com/rusqlite/rusqlite/compare/v0.40.1...v0.40.2 )
Updates `ureq` from 3.3.0 to 3.4.0
- [Changelog](https://github.com/algesten/ureq/blob/main/CHANGELOG.md )
- [Commits](https://github.com/algesten/ureq/compare/3.3.0...3.4.0 )
Updates `thiserror` from 2.0.19 to 2.0.20
- [Release notes](https://github.com/dtolnay/thiserror/releases )
- [Commits](https://github.com/dtolnay/thiserror/compare/2.0.19...2.0.20 )
Updates `uuid` from 1.24.0 to 1.26.0
- [Release notes](https://github.com/uuid-rs/uuid/releases )
- [Commits](https://github.com/uuid-rs/uuid/compare/v1.24.0...v1.26.0 )
---
updated-dependencies:
- dependency-name: rusqlite
dependency-version: 0.40.2
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: cargo-minor-and-patch
- dependency-name: thiserror
dependency-version: 2.0.20
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: cargo-minor-and-patch
- dependency-name: ureq
dependency-version: 3.4.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: cargo-minor-and-patch
- dependency-name: uuid
dependency-version: 1.24.1
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: cargo-minor-and-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-09-03 14:59:21 -04:00
dependabot[bot] and haelyra
45a48d5e1b
chore(deps): bump the actions-minor-and-patch group across 1 directory with 2 updates
...
Bumps the actions-minor-and-patch group with 2 updates in the / directory: [actions/checkout](https://github.com/actions/checkout ) and [pnpm/action-setup](https://github.com/pnpm/action-setup ).
Updates `actions/checkout` from 7.0.0 to 7.0.1
- [Release notes](https://github.com/actions/checkout/releases )
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md )
- [Commits](https://github.com/actions/checkout/compare/9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0...3d3c42e5aac5ba805825da76410c181273ba90b1 )
Updates `pnpm/action-setup` from 6.0.9 to 6.0.10
- [Release notes](https://github.com/pnpm/action-setup/releases )
- [Commits](https://github.com/pnpm/action-setup/compare/0ebf47130e4866e96fce0953f49152a61190b271...0977fd99725f1db4007ccb2928dbb4e90d06cc86 )
---
updated-dependencies:
- dependency-name: actions/checkout
dependency-version: 7.0.1
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: actions-minor-and-patch
- dependency-name: pnpm/action-setup
dependency-version: 6.0.10
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: actions-minor-and-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-09-03 14:59:21 -04:00
haelyra
23fb7e0c79
ci: avoid redundant Python dependency floors
2026-09-03 14:59:01 -04:00
haelyra and GitHub
22e8cf01d0
test(ci): scale repair timeout on Windows ( #2942 )
2026-09-02 20:48:57 -04:00
haelyra and GitHub
d3652039ac
test(hooks): drain bootstrap children asynchronously ( #2941 )
...
* test(hooks): drain bootstrap children asynchronously
* test(hooks): harden async supervisor lifecycle
* test(hooks): accept Windows child stdin closure
2026-09-02 19:55:26 -04:00
haelyra and GitHub
11813f968c
test(hooks): avoid repeated giant wrapper payloads ( #2940 )
...
* test(hooks): avoid repeated giant wrapper payloads
* test(hooks): assert callback-governed wrapper exits
2026-09-02 17:47:04 -04:00
haelyra and GitHub
90430ab3a7
test(ci): tolerate loaded macOS hook runners ( #2939 )
2026-09-02 16:37:08 -04:00
haelyra and GitHub
348f80a89b
fix(security): update fast-uri to 3.1.7 ( #2936 )
2026-09-02 15:13:20 -04:00
Wu Shuwen and GitHub
de899ac472
fix(tests): preserve session alias HOME isolation ( #2877 )
2026-09-02 14:24:39 -04:00
haelyra and GitHub
ca185ef5f7
chore(release): prepare signed 2.2.1 patch ( #2920 )
2026-08-31 18:14:22 -04:00
Affaan Mustafa and GitHub
a104765bf2
docs(ito-compute): document ito accept and ito_accept MCP workflow ( #2893 )
...
* docs(ito-compute): document ito accept and ito_accept MCP workflow
Updates the canonical ECC skill to cover the new quote acceptance path:
- CLI: ecc ito accept <ticket-id>
- MCP: ito_accept tool
- Explicit buyer-authority guard before accepting
- Clear statement that accept routes to desk, does not purchase
* test(ito-compute): assert the four-tool MCP boundary including ito_accept
The exact-boundary test pinned the three-tool description. Runtime
ito-compute-cli now exposes ito_accept (Ito-Markets/ito-cloud-runtime#1453 ),
so the template boundary assertion moves to four tools.
* docs(ito-compute): drop the firm-quote gate from the accept workflow
Desk quotes are indicative_paper in production (a firm quote requires the
separate human-held signing path and cannot reach the client), so gating
accept on 'a firm quote is ready' described an unfireable condition. Align
with the runtime contract: accept routes the current desk quote to human
review and the result carries quote_class (ito-cloud-runtime#1453).
2026-08-31 15:16:16 -04:00
haelyra and GitHub
005eff40fd
fix(install): harden universal setup release path ( #2888 )
...
* fix(install): harden universal setup release path
* docs(adal): use ecc-universal doctor command
2026-08-30 18:54:00 -04:00
haelyra and GitHub
ce64e417fd
Merge pull request #2913 from affaan-m/fix/opencode-hook-consent
...
fix(install): preserve opencode non-hook defaults
2026-08-30 15:52:28 -04:00
haelyra
64d0d9436f
fix(install): preserve opencode non-hook defaults
2026-08-30 15:35:47 -04:00
haelyra and GitHub
19e2f2b46d
Merge pull request #2912 from affaan-m/fix/packed-install-hook-consent
...
test(ci): confirm hooks in packed target smoke
2026-08-30 15:20:35 -04:00
haelyra
d26b9cccee
test(ci): confirm hooks in packed target smoke
2026-08-30 15:19:01 -04:00
haelyra and GitHub
8211578ee7
Merge pull request #2715 from affaan-m/feat/hook-runtime-consent
...
feat(install): require an explicit hook decision at the apply layer
2026-08-30 15:13:28 -04:00
haelyra
caee3ee455
test(ci): opt in to hooks in packed lifecycle smoke
2026-08-30 15:13:07 -04:00
haelyra and Claude Fable 5
bdbd90a47f
test(install): scale uninstall CLI timeout for Windows CI
...
The uninstall cases run two full CLI passes (install, then uninstall)
over several hundred files under a flat 30s timeout, which is tight
enough on Windows CI to fail intermittently with spawnSync ETIMEDOUT.
install-apply.test.js already scales its timeout by platform for the
same reason; match that precedent rather than re-running past the flake.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com >
2026-08-30 15:09:34 -04:00
6aaa41e028
feat(install): require an explicit hook decision at the apply layer
...
The guided installer asks how ECC hooks should run, but that consent
lived only in the wizard path. Running install-apply directly with a
profile that includes hooks-runtime still materialized the hook runtime
with no disclosure and no decision.
Gate the apply layer instead, so every entry point is covered:
- disclose the six hook capability groups when a plan would materialize
the hook runtime, and refuse to apply until the caller decides
- --enable-hooks confirms the hook runtime; --no-hooks installs the rest
of the selection without it and records the reduced module closure in
install-state
- surface the pending decision as a dry-run warning
- show the same capability disclosure in the guided installer's plan
preview, so the wizard's hook question states what it is asking about
Plans that never materialize hooks (Kimi, --profile minimal,
--without baseline:hooks) are unaffected and need no flag. Repair and
uninstall operate on already-recorded state and stay unchanged.
The capability taxonomy and the held-materialization behavior come from
Samarjeet Singh Tomar's PR #2634 , reworked to fit the single-decision
consent model that shipped with the guided installer in #2649 .
Co-Authored-By: Samarjeet Singh Tomar <samar_tomar@hotmail.com >
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com >
2026-08-30 15:09:34 -04:00
haelyra and GitHub
a89cec9658
Merge pull request #2854 from samartomar/codex/issue-744-pure-plan
...
refactor(install): expose pure manifest planner
2026-08-30 14:50:53 -04:00
haelyra and GitHub
d8e6a51755
Merge pull request #2902 from affaan-m/maint/pr-stewardship-portability-2026-08-29
...
fix: forward-port reviewed ECC 2.2 fixes (13 PRs)
2026-08-29 16:30:55 -04:00
haelyra
299544e680
fix: count observations for whitespace paths
2026-08-29 16:07:00 -04:00
haelyra
1bdda4bdac
fix: close validator and path edge cases
2026-08-29 15:36:59 -04:00
haelyra
703163275d
test: honor per-invocation Bash overrides
2026-08-29 15:11:38 -04:00
dependabot[bot] and haelyra
2f895a1823
chore(deps): bump actions/setup-python from 6.2.0 to 7.0.0
...
Bumps [actions/setup-python](https://github.com/actions/setup-python ) from 6.2.0 to 7.0.0.
- [Release notes](https://github.com/actions/setup-python/releases )
- [Commits](https://github.com/actions/setup-python/compare/a309ff8b426b58ec0e2a45f0f869d46889d02405...5fda3b95a4ea91299a34e894583c3862153e4b97 )
---
updated-dependencies:
- dependency-name: actions/setup-python
dependency-version: 7.0.0
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-08-29 15:01:31 -04:00
haelyra
224da03d01
fix(gateguard): match heredoc tab-strip order
2026-08-29 14:55:14 -04:00
haelyra
fab534f924
test(hooks): keep matcher mirrors in sync
2026-08-29 14:55:14 -04:00
a4d72b2271
fix(gateguard): surface graduated recovery hints
...
Change-Id: I6ade0a2a54a26bd5721c62edf7efa462e8043a08
Co-authored-by: TRAE CLI <traecli@bytedance.com >
2026-08-29 14:55:14 -04:00
dajiaohuang and haelyra
c40d0e4f7c
fix: normalize heredoc line continuations
2026-08-29 14:55:14 -04:00
dajiaohuang and haelyra
9768c075c3
refactor: keep heredoc scanning linear
2026-08-29 14:55:14 -04:00
dajiaohuang and haelyra
9a3ee6864a
refactor: keep heredoc parser state immutable
2026-08-29 14:55:14 -04:00
dajiaohuang and haelyra
e72191ba74
fix: harden heredoc command filtering
2026-08-29 14:55:14 -04:00
dajiaohuang and haelyra
962380c452
fix: ignore heredoc prose in GateGuard
2026-08-29 14:55:14 -04:00
Suliman Abdulrazzaq and haelyra
6fa3efeef7
fix(hooks): use valid wildcard matchers
2026-08-29 14:55:14 -04:00
haelyra
30c41a9bde
fix: close truth and portability review gaps
2026-08-29 14:55:14 -04:00
haelyra
d08331f14e
fix(skill-comply): harden home path redaction
2026-08-29 14:55:13 -04:00
cyre and haelyra
2242e4d99d
fix(skill-comply): redact operator home path from compliance reports
...
_parse_stream_json() persisted raw tool_input/tool_response content into
ObservationEvents that grade() scores and generate_report() writes to
results/<skill>.md -- a report meant to be shared and reviewed.
--add-dir restricts the agent's additional accessible directory to the
sandbox (SANDBOX_BASE = /tmp/skill-comply-sandbox), but that doesn't stop
the agent's own tool calls (a Bash command using ~ expansion, a scenario
setup_commands entry referencing a dotfile) from emitting the operator's
home directory into tool_input/tool_response -- which then lands
verbatim, truncated but not sanitized, in the written report.
Adds _redact_home_path(), pure stdlib (Path.home()), applied to both
input_str and output_str before they're stored on the ObservationEvent.
Scoped deliberately to the home directory only -- grade() needs real
tool-call semantics for LLM-based compliance classification, so
truncating/stripping content the way a pure logging hook could isn't an
option here; only the operator-identifying path component needs to go.
New TestParseStreamJsonRedactsHomePath class in
skills/skill-comply/tests/test_runner.py (3 tests) -- full file now
10/10 passing, up from 7/7. Confirmed tests/test_invariant_runner.py (the
sandbox-execution security tests from #2149 ) still passes clean, 4/4.
Fixes #2730
2026-08-29 14:55:13 -04:00
haelyra and LKL-ZREO
9542c33454
test(skill-stocktake): cover canonical symlink discovery
...
Co-authored-by: LKL-ZREO <891878708@qq.com >
2026-08-29 14:55:13 -04:00