XiaoSeS
dd82c8a62c
feat(deploy): wire Feishu credentials into the release surfaces
...
.env.release.example advertised OAUTH2_FEISHU_* knobs that no deployment
path could actually deliver. compose.release.yml has no env_file, so every
variable must be listed explicitly, and the Helm chart and k8s base only
mapped the GitHub secret keys. Setting the documented variables therefore
did nothing.
Adds Feishu to compose.release.yml, the Helm secret template and values,
the k8s deployment and its secret example. GitLab had the identical gap, so
it is wired at the same time rather than leaving the example file half true.
validate-release-config.sh only checked that GitHub's id and secret appear
together. A half-configured provider renders a login button whose exchange
then fails, so the check now loops over all three providers. Its test gained
both-directions cases per provider plus a fully configured pass; reverting
the loop to GitHub-only makes them fail.
Also adds the provider's only failure log. Nothing downstream records a
Feishu userinfo failure -- OAuth2LoginFailureHandler does not log either --
so the previous code was silent on error. Logs the exception class and
Feishu's own error code, never the upstream msg, which can quote the access
token; a test asserts the code is present and the token is not.
Signed-off-by: XiaoSeS <87064762+XiaoSeS@users.noreply.github.com>
2026-09-21 10:18:37 +08:00
XiaoSeS
48376069db
fix(runtime): preserve lifecycle command options
2026-09-17 14:04:48 +08:00
XiaoSeS
b4779735bd
feat(suite): publish suites from multi-skill bundles
2026-09-17 11:16:39 +08:00
XiaoSeS
1dd77ef279
Merge remote-tracking branch 'origin/main' into codex/validate/issue823-20260910
2026-09-10 10:28:34 +08:00
XiaoSeS
78d15a80ac
test(starter): close Zero Slop validation gaps
...
Signed-off-by: XiaoSeS <87064762+XiaoSeS@users.noreply.github.com>
2026-09-10 10:17:20 +08:00
XiaoSeS
c2e2c1f768
fix(starter): harden Zero Slop batch validation
...
Signed-off-by: XiaoSeS <87064762+XiaoSeS@users.noreply.github.com>
2026-09-10 10:05:51 +08:00
XiaoSeS
bed72a3a98
Merge remote-tracking branch 'origin/feat/starter-zero-slop-823' into codex/validate/issue823-20260910
...
Signed-off-by: XiaoSeS <87064762+XiaoSeS@users.noreply.github.com>
# Conflicts:
# builtin-skills/README.md
2026-09-10 09:50:01 +08:00
XiaoSeS
d9696be9e4
merge main into feature/skill-suites
...
Signed-off-by: XiaoSeS <87064762+XiaoSeS@users.noreply.github.com>
2026-09-09 20:37:53 +08:00
XiaoSeS
d824a0498c
fix(skill): harden SkillHub CLI guide bootstrap ( #842 )
...
Deploy Docs / build (push) Waiting to run
Deploy Docs / Deploy (push) Blocked by required conditions
Security / Dependency Review (push) Waiting to run
Security / CodeQL (java-kotlin) (push) Waiting to run
Security / CodeQL (javascript-typescript) (push) Waiting to run
Security / CodeQL (python) (push) Waiting to run
* fix(skill): harden SkillHub CLI guide bootstrap
Signed-off-by: XiaoSeS <87064762+XiaoSeS@users.noreply.github.com>
* test(web): support exact preview browser checks
Signed-off-by: XiaoSeS <87064762+XiaoSeS@users.noreply.github.com>
* test(skill): enforce guide safety contracts
Signed-off-by: XiaoSeS <87064762+XiaoSeS@users.noreply.github.com>
* fix(skill): verify CLI package provenance
Signed-off-by: XiaoSeS <87064762+XiaoSeS@users.noreply.github.com>
* test(web): align CLI provenance assertions
Signed-off-by: XiaoSeS <87064762+XiaoSeS@users.noreply.github.com>
---------
Signed-off-by: XiaoSeS <87064762+XiaoSeS@users.noreply.github.com>
2026-09-09 20:25:50 +08:00
XiaoSeS
ce4590c50f
Merge remote-tracking branch 'origin/main' into feature/skill-suites-signed-final
...
Signed-off-by: XiaoSeS <87064762+XiaoSeS@users.noreply.github.com>
2026-09-09 18:23:05 +08:00
XiaoSeS
acf4448c6f
feat(skill): use latest CLI with registry fallback
...
Signed-off-by: XiaoSeS <87064762+XiaoSeS@users.noreply.github.com>
2026-09-09 17:17:26 +08:00
XiaoSeS
f5c554c9bd
feat(skill): make first-party CLI own skillhub command
...
Signed-off-by: XiaoSeS <87064762+XiaoSeS@users.noreply.github.com>
2026-09-09 15:08:42 +08:00
XiaoSeS
a4b35b236a
fix(suite): bind exact members and protect local installs
...
Signed-off-by: XiaoSeS <87064762+XiaoSeS@users.noreply.github.com>
2026-09-09 13:54:59 +08:00
XiaoSeS
d0e8c168fa
feat(suite): require and expose entry skill
...
Signed-off-by: XiaoSeS <87064762+XiaoSeS@users.noreply.github.com>
2026-09-09 13:54:59 +08:00
XiaoSeS
0ae50f30d7
feat(skill): add first-party SkillHub CLI guide
...
Signed-off-by: XiaoSeS <87064762+XiaoSeS@users.noreply.github.com>
2026-09-09 09:24:21 +08:00
XiaoSeS
859987e3bb
feat(suite): add first-class skill suites
...
Signed-off-by: XiaoSeS <87064762+XiaoSeS@users.noreply.github.com>
2026-09-08 19:30:57 +08:00
FenjuFu
77777d215f
feat(starter): add reviewed Zero Slop skill
...
Signed-off-by: FenjuFu <92919259+FenjuFu@users.noreply.github.com>
2026-09-08 16:14:24 +08:00
XiaoSeS
b9972af39f
Merge pull request #814 from iflytek/codex/issue-728-plugin-scanner-20260904
...
feat(builtin-skills): add HOL Guard plugin scanner
2026-09-04 16:32:29 +08:00
XiaoSeS
3364869b6f
Merge pull request #812 from FenjuFu/fix/issue-810-spa-cache
...
fix(web): revalidate SPA entry point after upgrades
2026-09-04 16:31:53 +08:00
XiaoSeS
bcef4fc5f0
test(builtin-skills): constrain runtime inventory
...
Signed-off-by: XiaoSeS <87064762+XiaoSeS@users.noreply.github.com>
2026-09-04 15:27:04 +08:00
XiaoSeS
7d9ea67169
test(builtin-skills): derive collection size from catalog
...
Signed-off-by: XiaoSeS <87064762+XiaoSeS@users.noreply.github.com>
2026-09-04 15:25:02 +08:00
FenjuFu
3c9eda199c
fix(web): preserve LF endings in nginx assets
...
Signed-off-by: FenjuFu <92919259+FenjuFu@users.noreply.github.com>
2026-09-04 11:56:16 +08:00
FenjuFu
374525468f
test(web): assert SPA cache revalidation
...
Signed-off-by: FenjuFu <92919259+FenjuFu@users.noreply.github.com>
2026-09-04 11:29:58 +08:00
XiaoSeS
7069e87e3b
fix(skill): validate derived registry hosts
...
Signed-off-by: XiaoSeS <87064762+XiaoSeS@users.noreply.github.com>
2026-09-04 11:23:03 +08:00
XiaoSeS
b4616e60fd
fix(skill): derive registry URL for default installs
...
Signed-off-by: XiaoSeS <87064762+XiaoSeS@users.noreply.github.com>
2026-09-04 11:23:03 +08:00
XiaoSeS
5f17e7a181
fix(skill): align helper update with CLI inventory
...
Signed-off-by: XiaoSeS <87064762+XiaoSeS@users.noreply.github.com>
2026-09-04 11:23:03 +08:00
XiaoSeS
613d449d38
feat(skill): complete install-for-agent workflow
...
Signed-off-by: XiaoSeS <87064762+XiaoSeS@users.noreply.github.com>
2026-09-04 11:23:03 +08:00
XiaoSeS
15dad68740
test(promotion): cover global download after approval ( #792 )
...
* test(promotion): cover global download after approval
Signed-off-by: XiaoSeS <87064762+XiaoSeS@users.noreply.github.com>
* test(promotion): align smoke setup with current API
Signed-off-by: XiaoSeS <87064762+XiaoSeS@users.noreply.github.com>
* test(promotion): make download smoke repeatable
Signed-off-by: XiaoSeS <87064762+XiaoSeS@users.noreply.github.com>
* test(promotion): wait for member review readiness
Signed-off-by: XiaoSeS <87064762+XiaoSeS@users.noreply.github.com>
* test(promotion): verify denied approval state
Signed-off-by: XiaoSeS <87064762+XiaoSeS@users.noreply.github.com>
---------
Signed-off-by: XiaoSeS <87064762+XiaoSeS@users.noreply.github.com>
2026-09-02 11:15:10 +08:00
XiaoSeS
aa4ea17c4a
fix(deploy): preserve storage volume ownership
...
Signed-off-by: XiaoSeS <87064762+XiaoSeS@users.noreply.github.com>
2026-08-29 15:58:55 +08:00
XiaoSeS
e9e570133d
fix(web): preserve HTTPS in sub-path redirects
...
Signed-off-by: XiaoSeS <87064762+XiaoSeS@users.noreply.github.com>
2026-08-29 15:29:42 +08:00
ShinyHero666
470e79d6d2
fix(smoke): support separate actuator target ( #689 )
...
Signed-off-by: ShinyHero666 <160204855+ShinyHero666@users.noreply.github.com>
2026-08-26 10:23:31 +08:00
FenjuFu
bbdc0f7a0c
fix(dev): use bash for backend launchers ( #721 )
...
Signed-off-by: FenjuFu <92919259+FenjuFu@users.noreply.github.com>
2026-08-21 09:35:52 +08:00
XiaoSeS
4efeed18c8
fix(deploy): preserve Aliyun source mode in stop command
...
Signed-off-by: XiaoSeS <87064762+XiaoSeS@users.noreply.github.com>
2026-08-07 18:20:06 +08:00
XiaoSeS
8de293b38f
fix(deploy): correct Aliyun runtime stop URL
...
Signed-off-by: XiaoSeS <87064762+XiaoSeS@users.noreply.github.com>
2026-08-07 16:45:12 +08:00
XiaoSeS
9668f3cd5a
fix(deploy): avoid changing runtime helper for PR 576
...
Signed-off-by: XiaoSeS <87064762+XiaoSeS@users.noreply.github.com>
2026-08-06 19:06:55 +08:00
XiaoSeS
d0b7a7c5d4
fix(deploy): backport sub-path runtime fixes to PR 576
...
Signed-off-by: XiaoSeS <87064762+XiaoSeS@users.noreply.github.com>
2026-08-06 18:59:37 +08:00
philsun
34f244e7a4
feat(web): support configurable base-path deployment
...
Signed-off-by: philsun <xinyi.sun@daocloud.io>
2026-08-05 12:50:26 +08:00
XiaoSeS
fc457a0651
test(smoke): decouple admin checks from bootstrap credentials ( #686 )
...
Signed-off-by: XiaoSeS <87064762+XiaoSeS@users.noreply.github.com>
2026-08-04 19:20:34 +08:00
XiaoSeS
5f7c48b7a4
feat(bootstrap): publish starter skills in runtime manifest
...
Signed-off-by: XiaoSeS <87064762+XiaoSeS@users.noreply.github.com>
2026-07-31 18:27:25 +08:00
wowo-zZ
7f934e63ab
feat(bootstrap): verify built-in skill artifacts
...
Signed-off-by: wowo-zZ <zhenggui5228@126.com>
2026-07-31 11:14:42 +08:00
wowo-zZ
0bf822290b
feat(builtin-skills): add reviewed starter collection
...
Signed-off-by: wowo-zZ <zhenggui5228@126.com>
2026-07-30 15:54:09 +08:00
XiaoSeS
6817d98007
Merge pull request #367 from xring/fix/postgres-lostfound
...
Deploy Docs / build (push) Waiting to run
Deploy Docs / Deploy (push) Blocked by required conditions
Security / Dependency Review (push) Waiting to run
Security / CodeQL (java-kotlin) (push) Waiting to run
Security / CodeQL (javascript-typescript) (push) Waiting to run
Security / CodeQL (python) (push) Waiting to run
fix(deploy): isolate PostgreSQL data from volume root
2026-07-30 09:56:00 +08:00
XiaoSeS
3db3c9685f
feat(redis): complete cluster connection support
...
Signed-off-by: XiaoSeS <87064762+XiaoSeS@users.noreply.github.com>
2026-07-29 17:36:06 +08:00
XiaoSeS
dad3c15f92
chore(redis): merge current main for cluster support
...
Signed-off-by: XiaoSeS <87064762+XiaoSeS@users.noreply.github.com>
2026-07-29 16:11:31 +08:00
XiaoSeS
87cb05a096
test(ci): cover Helm workflows in security checks
...
Signed-off-by: XiaoSeS <87064762+XiaoSeS@users.noreply.github.com>
2026-07-29 15:22:36 +08:00
XiaoSeS
bec701e962
test(deploy): wait for final PostgreSQL process
...
Signed-off-by: XiaoSeS <87064762+XiaoSeS@users.noreply.github.com>
2026-07-29 04:21:27 +08:00
XiaoSeS
0dd600ce13
fix(deploy): preserve PostgreSQL PVC data layout
2026-07-29 01:41:20 +08:00
XiaoSeS
e4fb26d4ba
fix(nginx): trust forwarded proto only when configured
...
Signed-off-by: XiaoSeS <87064762+XiaoSeS@users.noreply.github.com>
2026-07-28 20:03:50 +08:00
dongmucat
bf7c71ad2c
fix(scanner): backport local LLM base URL handling for #563
...
Also add Python CodeQL coverage in the security workflow so repository-level script regression checks stay green when Python source exists.
Signed-off-by: dongmucat <1127093059@qq.com>
2026-06-29 14:34:55 +08:00
moses
cb950c2d21
Merge branch 'iflytek:main' into main
2026-06-18 13:57:42 +08:00