gitnexus-release-bot[bot]
d95cfebef3
release: v1.6.10-rc.44
2026-07-17 13:29:07 +00:00
dependabot[bot]
3c36ab906b
chore(deps)(deps): bump @langchain/anthropic in /gitnexus-web ( #2526 )
...
Bumps [@langchain/anthropic](https://github.com/langchain-ai/langchainjs ) from 1.3.29 to 1.5.1.
- [Release notes](https://github.com/langchain-ai/langchainjs/releases )
- [Commits](https://github.com/langchain-ai/langchainjs/commits/@langchain/anthropic@1.5.1 )
---
updated-dependencies:
- dependency-name: "@langchain/anthropic"
dependency-version: 1.5.1
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Gergő Magyar <gergomagyar@icloud.com>
2026-07-17 13:55:12 +01:00
dependabot[bot]
4d85fe1f19
chore(deps)(deps-dev): bump @types/node in /gitnexus-web ( #2528 )
...
Bumps [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node ) from 25.9.1 to 25.9.5.
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases )
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node )
---
updated-dependencies:
- dependency-name: "@types/node"
dependency-version: 25.9.5
dependency-type: direct:development
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Gergő Magyar <gergomagyar@icloud.com>
2026-07-17 13:54:44 +01:00
dependabot[bot]
06ba512046
chore(deps)(deps-dev): bump @babel/parser in /gitnexus ( #2531 )
...
Bumps [@babel/parser](https://github.com/babel/babel/tree/HEAD/packages/babel-parser ) from 8.0.0 to 8.0.4.
- [Release notes](https://github.com/babel/babel/releases )
- [Changelog](https://github.com/babel/babel/blob/main/CHANGELOG.md )
- [Commits](https://github.com/babel/babel/commits/v8.0.4/packages/babel-parser )
---
updated-dependencies:
- dependency-name: "@babel/parser"
dependency-version: 8.0.4
dependency-type: direct:development
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-17 13:24:15 +01:00
dependabot[bot]
22905bb2a7
chore(deps)(deps-dev): bump @babel/traverse in /gitnexus ( #2532 )
...
Bumps [@babel/traverse](https://github.com/babel/babel/tree/HEAD/packages/babel-traverse ) from 8.0.0 to 8.0.4.
- [Release notes](https://github.com/babel/babel/releases )
- [Changelog](https://github.com/babel/babel/blob/main/CHANGELOG.md )
- [Commits](https://github.com/babel/babel/commits/v8.0.4/packages/babel-traverse )
---
updated-dependencies:
- dependency-name: "@babel/traverse"
dependency-version: 8.0.4
dependency-type: direct:development
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-17 13:24:01 +01:00
dependabot[bot]
0b777979d8
chore(deps)(deps-dev): bump @babel/types in /gitnexus ( #2534 )
...
Bumps [@babel/types](https://github.com/babel/babel/tree/HEAD/packages/babel-types ) from 8.0.0 to 8.0.4.
- [Release notes](https://github.com/babel/babel/releases )
- [Changelog](https://github.com/babel/babel/blob/main/CHANGELOG.md )
- [Commits](https://github.com/babel/babel/commits/v8.0.4/packages/babel-types )
---
updated-dependencies:
- dependency-name: "@babel/types"
dependency-version: 8.0.4
dependency-type: direct:development
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-17 13:23:47 +01:00
dependabot[bot]
11c9d791e4
chore(deps): bump github/codeql-action/init from 4.36.2 to 4.37.0 ( #2504 )
...
Bumps [github/codeql-action/init](https://github.com/github/codeql-action ) from 4.36.2 to 4.37.0.
- [Release notes](https://github.com/github/codeql-action/releases )
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md )
- [Commits](8aad20d150...99df26d4f1 )
---
updated-dependencies:
- dependency-name: github/codeql-action/init
dependency-version: 4.37.0
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Gergő Magyar <gergomagyar@icloud.com>
2026-07-17 13:23:26 +01:00
dependabot[bot]
64e9ef8484
chore(deps)(deps): bump @langchain/ollama in /gitnexus-web ( #2527 )
...
Bumps [@langchain/ollama](https://github.com/langchain-ai/langchainjs ) from 1.2.7 to 1.3.0.
- [Release notes](https://github.com/langchain-ai/langchainjs/releases )
- [Commits](https://github.com/langchain-ai/langchainjs/compare/langchain@1.2.7...@langchain/ollama@1.3.0 )
---
updated-dependencies:
- dependency-name: "@langchain/ollama"
dependency-version: 1.3.0
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-17 13:22:37 +01:00
dependabot[bot]
90b5098b24
chore(deps)(deps): bump @langchain/core in /gitnexus-web ( #2530 )
...
Bumps [@langchain/core](https://github.com/langchain-ai/langchainjs ) from 1.2.1 to 1.2.2.
- [Release notes](https://github.com/langchain-ai/langchainjs/releases )
- [Commits](https://github.com/langchain-ai/langchainjs/compare/@langchain/core@1.2.1...@langchain/core@1.2.2 )
---
updated-dependencies:
- dependency-name: "@langchain/core"
dependency-version: 1.2.2
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-17 13:22:18 +01:00
dependabot[bot]
42c4d91cd4
chore(deps)(deps-dev): bump vitest from 4.1.9 to 4.1.10 in /gitnexus-web ( #2533 )
...
Bumps [vitest](https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest ) from 4.1.9 to 4.1.10.
- [Release notes](https://github.com/vitest-dev/vitest/releases )
- [Changelog](https://github.com/vitest-dev/vitest/blob/main/docs/releases.md )
- [Commits](https://github.com/vitest-dev/vitest/commits/v4.1.10/packages/vitest )
---
updated-dependencies:
- dependency-name: vitest
dependency-version: 4.1.10
dependency-type: direct:development
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-17 13:21:52 +01:00
dependabot[bot]
e2e9254938
chore(deps): bump github/codeql-action/upload-sarif ( #2535 )
...
Bumps the codeql-action group with 1 update: [github/codeql-action/upload-sarif](https://github.com/github/codeql-action ).
Updates `github/codeql-action/upload-sarif` from 4.36.2 to 4.37.0
- [Release notes](https://github.com/github/codeql-action/releases )
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md )
- [Commits](8aad20d150...99df26d4f1 )
---
updated-dependencies:
- dependency-name: github/codeql-action/upload-sarif
dependency-version: 4.37.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: codeql-action
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-17 13:21:25 +01:00
dependabot[bot]
0656099332
chore(deps): bump docker/metadata-action from 6.1.0 to 6.2.0 ( #2536 )
...
Bumps [docker/metadata-action](https://github.com/docker/metadata-action ) from 6.1.0 to 6.2.0.
- [Release notes](https://github.com/docker/metadata-action/releases )
- [Commits](80c7e94dd9...dc80280410 )
---
updated-dependencies:
- dependency-name: docker/metadata-action
dependency-version: 6.2.0
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-17 13:21:05 +01:00
dependabot[bot]
731ab6f512
chore(deps): bump marocchino/sticky-pull-request-comment ( #2537 )
...
Bumps [marocchino/sticky-pull-request-comment](https://github.com/marocchino/sticky-pull-request-comment ) from 3.0.4 to 3.0.5.
- [Release notes](https://github.com/marocchino/sticky-pull-request-comment/releases )
- [Commits](0ea0beb66e...5770ad5eb8 )
---
updated-dependencies:
- dependency-name: marocchino/sticky-pull-request-comment
dependency-version: 3.0.5
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-17 13:20:48 +01:00
dependabot[bot]
dc993a6d43
chore(deps): bump github/codeql-action/analyze from 4.36.2 to 4.37.0 ( #2506 )
...
* chore(deps): bump github/codeql-action/analyze from 4.36.2 to 4.37.0
Bumps [github/codeql-action/analyze](https://github.com/github/codeql-action ) from 4.36.2 to 4.37.0.
- [Release notes](https://github.com/github/codeql-action/releases )
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md )
- [Commits](8aad20d150...99df26d4f1 )
---
updated-dependencies:
- dependency-name: github/codeql-action/analyze
dependency-version: 4.37.0
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com>
* ci(codeql): keep action steps in lockstep
Co-authored-by: azizur100389 <azizur100389@gmail.com>
---------
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: azizur100389 <azizur100389@gmail.com>
2026-07-17 11:40:51 +01:00
dependabot[bot]
527ea5fc7a
chore(deps)(deps-dev): bump @babel/types in /gitnexus ( #2518 )
2026-07-17 05:26:54 +01:00
dependabot[bot]
e8fdc2e2ab
chore(deps)(deps-dev): bump @babel/generator in /gitnexus ( #2519 )
2026-07-17 04:42:39 +01:00
dependabot[bot]
91955e6576
chore(deps)(deps-dev): bump @babel/traverse in /gitnexus ( #2520 )
...
CodeQL / Analyze (javascript-typescript) (push) Waiting to run
CodeQL / Analyze (python) (push) Waiting to run
Gitleaks / gitleaks (push) Waiting to run
Publish / Classify release event (push) Waiting to run
Publish / RC guard (marker + release-PR skip) (push) Blocked by required conditions
Publish / ci (push) Blocked by required conditions
Publish / Publish to npm (push) Blocked by required conditions
Publish / Build & Push RC Docker images (push) Blocked by required conditions
Scorecard / Scorecard analysis (push) Waiting to run
Trivy Image Scan / Trivy (gitnexus-cli) (push) Waiting to run
Trivy Image Scan / Trivy (gitnexus-web) (push) Waiting to run
Bumps [@babel/traverse](https://github.com/babel/babel/tree/HEAD/packages/babel-traverse ) from 7.29.7 to 8.0.0.
- [Release notes](https://github.com/babel/babel/releases )
- [Changelog](https://github.com/babel/babel/blob/main/CHANGELOG.md )
- [Commits](https://github.com/babel/babel/commits/v8.0.0/packages/babel-traverse )
---
updated-dependencies:
- dependency-name: "@babel/traverse"
dependency-version: 8.0.0
dependency-type: direct:development
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-16 22:51:51 +01:00
dependabot[bot]
795f81127b
chore(deps)(deps-dev): bump tsx from 4.23.0 to 4.23.1 in /gitnexus ( #2517 )
...
Bumps [tsx](https://github.com/privatenumber/tsx ) from 4.23.0 to 4.23.1.
- [Release notes](https://github.com/privatenumber/tsx/releases )
- [Changelog](https://github.com/privatenumber/tsx/blob/master/release.config.cjs )
- [Commits](https://github.com/privatenumber/tsx/compare/v4.23.0...v4.23.1 )
---
updated-dependencies:
- dependency-name: tsx
dependency-version: 4.23.1
dependency-type: direct:development
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-16 21:54:48 +01:00
dependabot[bot]
d27b1ab8c4
chore(deps)(deps-dev): bump @babel/parser in /gitnexus ( #2521 )
...
Bumps [@babel/parser](https://github.com/babel/babel/tree/HEAD/packages/babel-parser ) from 7.29.7 to 8.0.0.
- [Release notes](https://github.com/babel/babel/releases )
- [Changelog](https://github.com/babel/babel/blob/main/CHANGELOG.md )
- [Commits](https://github.com/babel/babel/commits/v8.0.0/packages/babel-parser )
---
updated-dependencies:
- dependency-name: "@babel/parser"
dependency-version: 8.0.0
dependency-type: direct:development
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-16 21:51:25 +01:00
Parafee41
8292b2bee4
test(cli): lock native load guard for lazy actions ( #2442 )
2026-07-16 15:22:20 +01:00
Parafee41
f45e89e6b6
fix(embeddings): make batch inserts retry-safe ( #2453 )
...
* fix(embeddings): make batch inserts retry-safe
* fix(types): cover optional transformers dependency
* Fix embedding restore test expectation
* test(embeddings): count checkpoint creates
---------
Co-authored-by: Gergő Magyar <gergomagyar@icloud.com>
2026-07-16 15:21:03 +01:00
Parafee41
b85f1ace7a
fix(mcp): avoid api impact schema combinators ( #2489 )
...
Co-authored-by: Gergő Magyar <gergomagyar@icloud.com>
2026-07-16 15:20:22 +01:00
azizur100389
a333d94a00
feat(wiki): allow explicit HTTP LLM hosts ( #2491 )
...
* feat(wiki): allow explicit HTTP LLM hosts
Keep wiki LLM HTTP endpoints fail-closed by default while adding a narrow exact-host opt-in for LAN/self-hosted models.
Co-authored-by: Cursor <cursoragent@cursor.com>
* fix(wiki): simplify insecure LLM flag name
Rename the wiki HTTP opt-in flag to --allow-insecure-connection per review feedback.
Co-authored-by: Cursor <cursoragent@cursor.com>
* fix(wiki): simplify insecure connection env
Rename the wiki HTTP allowlist environment variable and align validation errors with the CLI flag naming.
Co-authored-by: Cursor <cursoragent@cursor.com>
---------
Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Gergő Magyar <gergomagyar@icloud.com>
2026-07-16 13:53:58 +01:00
azizur100389
3dd553b345
feat(taint): expand TS/JS sink model ( #2490 )
...
* feat(taint): expand TS/JS sink model
Co-authored-by: Cursor <cursoragent@cursor.com>
* test(taint): cover TS sink disambiguation end-to-end
Add a real-pipeline integration test proving the expanded TS/JS taint sinks only emit findings for intended imported and receiver-conventional symbols.
Co-authored-by: Cursor <cursoragent@cursor.com>
---------
Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Gergő Magyar <gergomagyar@icloud.com>
2026-07-16 13:11:57 +01:00
Gergo Magyar
573a777ef5
ci(tests): widen the Windows shard watchdog and keep exit diagnostics ( #2449 )
...
The busiest Windows platform shard reached 14m57s against the 15 minute
watchdog on the rc.19 green run and has timed out once since. CI now
sets GITNEXUS_CROSS_PLATFORM_TIMEOUT_MINUTES=20 (the job timeout stays
25), the stale comfortably-under comment reflects reality, and the
runner always logs status, signal, spawn code and elapsed time so the
next status-null death is diagnosable.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-16 12:29:01 +01:00
Gergo Magyar
42de243e9a
ci(release): sync plugin manifests on every version bump ( #2445 )
...
The RC path bumped only gitnexus/package.json, so every v1.6.10-rc tag
through rc.28 shipped the four plugin manifest surfaces frozen at 1.6.9
and failed its own unit suite. The npm version lifecycle script now
runs a fail-closed sync whenever npm version executes, in CI or on a
maintainer's laptop; publish.yml verifies the result and stages the
surfaces into the detached release commit, and the stable path refuses
to publish a tag whose manifests drifted. The sync is textual so a
release commit carries a one-line change per surface instead of
reformatting churn.
Design follows the proposal by @100yenadmin in #2445 , moved onto the
standard npm version hook.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-16 12:29:01 +01:00
Gergő Magyar
3ee1e2cb60
Merge pull request #2513 from electricsheephq/upstream/file-embedding-delete-regression
...
test(embeddings): cover File-row deletion
2026-07-16 12:07:18 +01:00
Eva
5e3531133d
test(embeddings): cover File-row deletion
2026-07-16 17:51:46 +07:00
Gergő Magyar
c4fb511a0a
Merge pull request #2512 from abhigyanpatwari/merge/eva-fixes-2
...
fix: land cache, CLI, and embeddings series (#2476 #2470 #2455 #2468 )
2026-07-16 11:43:02 +01:00
Gergo Magyar
36d25b5a70
test(cli): pin the non-zero exit for not-found context payloads
...
The skip-git ignore test asserted the error payload while relying on
exit 0; since the output() guard an error payload also exits 1, so the
test now captures the payload from the exec failure and pins both.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-16 10:11:32 +00:00
Gergo Magyar
5869dde31d
fix(embeddings): make HTTP generation resumable ( #2468 )
2026-07-16 10:00:50 +00:00
Gergo Magyar
e814c5a10d
fix(embeddings): include File rows in the incremental delete sweeps
...
The zero-symbol File fallback from #2455 writes File embedding rows,
but the filePath-scoped delete sweeps joined through EMBEDDABLE_LABELS
only. Docs repos accumulated duplicate rows on re-analyze and deleted
files left orphans. Free for code repos: no File rows exist to match.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-16 10:00:26 +00:00
Gergo Magyar
de5321ed24
fix(embeddings): fall back to text-bearing file nodes ( #2455 )
2026-07-16 09:58:38 +00:00
Gergo Magyar
e20e326290
fix(cli): fail every tool command loudly on backend error payloads
...
Moves the #2469 guard from cypherCommand into output() so all seven
tool commands that print backend results share the exit semantics.
Adds query and context regression cases.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-16 09:58:14 +00:00
Gergo Magyar
639aab6af0
fix(cli): fail cypher errors loudly ( #2470 )
2026-07-16 09:56:09 +00:00
Gergo Magyar
ee7161ef0d
fix(cache): degrade when the durable generation reset fails
...
An fs failure while resetting a chunk generation now warns and
continues like the neighboring durable-store paths instead of failing
the analyze. Workers recreate the directory on write.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-16 09:55:44 +00:00
Gergo Magyar
dc15de9dec
fix(cache): bound parsedfile generations ( #2476 )
2026-07-16 09:51:46 +00:00
dependabot[bot]
318754e781
chore(deps)(deps): bump axios from 1.16.1 to 1.18.1 in /gitnexus-web ( #2499 )
...
Bumps [axios](https://github.com/axios/axios ) from 1.16.1 to 1.18.1.
- [Release notes](https://github.com/axios/axios/releases )
- [Changelog](https://github.com/axios/axios/blob/v1.x/CHANGELOG.md )
- [Commits](https://github.com/axios/axios/compare/v1.16.1...v1.18.1 )
---
updated-dependencies:
- dependency-name: axios
dependency-version: 1.18.1
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-16 10:30:53 +01:00
dependabot[bot]
43a6f6828f
chore(deps)(deps-dev): bump @vercel/node in /gitnexus-web ( #2502 )
...
Bumps [@vercel/node](https://github.com/vercel/vercel/tree/HEAD/packages/node ) from 5.8.22 to 5.8.23.
- [Release notes](https://github.com/vercel/vercel/releases )
- [Changelog](https://github.com/vercel/vercel/blob/main/packages/node/CHANGELOG.md )
- [Commits](https://github.com/vercel/vercel/commits/@vercel/node@5.8.23/packages/node )
---
updated-dependencies:
- dependency-name: "@vercel/node"
dependency-version: 5.8.23
dependency-type: direct:development
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-16 10:30:21 +01:00
Gergő Magyar
2e2db8b7c9
Merge pull request #2511 from abhigyanpatwari/merge/eva-series-2026-07
...
feat: land determinism and MCP policy series (#2458 #2482 #2464 #2465 #2478 #2480 #2462 #2460 )
2026-07-16 10:26:43 +01:00
Gergo Magyar
c836801c4a
feat(mcp): add deterministic response budgets ( #2460 )
...
Composed with the read-only and repository policies in the CallTool
handler: read-only assert, then budget resolution, then scoped dispatch
with the transport arg stripped.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-16 08:59:05 +00:00
Gergo Magyar
f49ca472fa
feat(mcp): normalize impact and context parameter aliases ( #2462 )
2026-07-16 08:55:49 +00:00
Gergo Magyar
490e74a901
fix(scope): stabilize graph lookup collisions ( #2480 )
2026-07-16 08:55:23 +00:00
Gergo Magyar
b685ba4cc8
test(communities): rebaseline pipeline-pdg goldens for projection order
...
The C#, Java and Go flag-off digests shift with the canonical community
projection from #2478 stacked on the walker sort from #2482 . Regenerated
via vitest -u; mini-repo pipeline golden was already correct.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-16 08:55:09 +00:00
Gergo Magyar
193db519a5
fix(communities): canonicalize projection order ( #2478 )
2026-07-16 08:50:51 +00:00
Gergo Magyar
48a145a47f
feat(mcp): enforce repository allowlist and default ( #2465 )
...
Merged with the read-only policy: both filters compose in server.ts.
Review hardening: assertResourceUri compares the opaque host case
insensitively (GITNEXUS://GROUP bypass) and gains the fail-closed
fallback for unparseable URIs; the backend proxy now also intercepts
queryClusters/queryProcesses/queryClusterDetail/queryProcessDetail;
scrubGroupDescription is shared from read-only-policy.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-16 08:50:07 +00:00
Gergo Magyar
aa0d6ee0a3
fix(mcp): reject group-only args at read-only dispatch
...
crossDepth and subgroup are inert outside @group routing, but rejecting
them keeps the scrubbed schema and the dispatch contract in agreement.
Also documents that resource content scrubbing is cosmetic.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-16 08:43:30 +00:00
Gergo Magyar
a7775de993
feat(mcp): add fail-closed read-only mode ( #2464 )
2026-07-16 08:42:32 +00:00
Gergo Magyar
6b013e7d30
fix(scan): lock in Rust publish order and guard PHP suffix roots
...
Adds the missing #2481 Rust regression test (importer before definer),
fails closed when a PHP namespace suffix matches directories under
different roots, and points the baselines note at #2481/#2482.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-16 08:42:07 +00:00
Gergo Magyar
b53429e901
fix(scan): canonicalize traversal without order-sensitive bindings ( #2482 )
2026-07-16 08:31:46 +00:00