Commit Graph

23 Commits

Author SHA1 Message Date
Diego Rodrigues de Sa e Souza
bc32c6710e fix(security): bump form-data/vite (2 HIGH) + env-harden workflow template-injection + allowlist guarded workflow_run (#3949)
Remediate the real findings the now-functional osv-scanner and zizmor gates
surfaced on release/v3.8.26.

Deps (osv-scanner, 2 HIGH -> 0):
- form-data 4.0.5 -> ^4.0.6 (GHSA-hmw2-7cc7-3qxx, transitive via axios)
- vite 8.0.5 -> ^8.0.16 (GHSA-fx2h-pf6j-xcff HIGH + GHSA-v6wh-96g9-6wx3
  MODERATE; dev-only via vitest/@vitejs/plugin-react/fumadocs-mdx)
Applied via package.json overrides of existing deps (no new allowlist entry
needed). vulnCount 13 -> 10; build:cli + vitest MCP suite (16 files/187 tests)
green post-bump.

Workflows (zizmor, 195 -> 187):
- env-harden 7 template-injection findings by moving each ${{ ... }} into env:
  and referencing "$VAR" in the script (GitHub-documented mitigation):
  ci.yml i18n; electron-release.yml validate/build/release steps.
- allowlist 1 dangerous-triggers FP: deploy-vps.yml on:workflow_run is guarded
  on conclusion=='success' and deploys via SSH without checking out untrusted
  code. Added .zizmor.yml rules.dangerous-triggers.ignore with justification.

Tighten baselines to the improved state (direction: down): vulnCount 13 -> 10,
zizmorFindings 195 -> 187. secretFindings (3) and bundleSize (5601) unchanged.
2026-06-15 23:26:17 -03:00
Diego Rodrigues de Sa e Souza
8981b322d7 ci(quality): make zizmor/gitleaks/osv scanners functional + freeze advisory baselines (#3947)
Three CI security gates in the quality-extended job never produced a value;
diagnose + fix each, then freeze the real measured numbers as advisory ratchet
baselines (dedicatedGate => SKIP in the blocking quality-gate ratchet).

FIX 1 — .zizmor.yml: migrate the config from the pre-1.0 'ignores: []' schema to
the 'rules: {}' schema. zizmor 1.25.2 rejected the old field ('unknown field
`ignores`, expected `rules`') and performed NO audit. Now check:workflows emits
zizmorFindings=195.

FIX 2 — scripts/check/check-secrets.mjs: the gate ran 'gitleaks detect --no-git
--source .', which walks the WHOLE tree including a real node_modules/ (90k+ files
under npm ci) and times out (ETIMEDOUT) — gitleaks has no traversal-exclude flag
(.gitleaks.toml paths filter findings AFTER reading). Scope the scan to the source
dirs (src/open-sse/bin/electron/scripts), one 'gitleaks dir <dir>' invocation each
('gitleaks dir' takes a single path; multiple args fall back to scanning the CWD).
Also fix .gitleaks.toml: it lacked [extend].useDefault=true, so the custom config
REPLACED the default ruleset with zero rules and detected nothing — the gate always
reported 0 regardless of real secrets. Now: ~10s (was 120s timeout), secretFindings=3
(generic-api-key false positives in beta-header strings / column names).

FIX 3 — .github/workflows/ci.yml: the scanner install resolved release URLs via
unauthenticated api.github.com (60 req/hr/IP; returns empty when throttled -> silent
no-op install -> every gate self-skips). Switch gitleaks + osv-scanner to 'gh release
download' (preinstalled + GITHUB_TOKEN-authed, 5000 req/hr); add GH_TOKEN to the step
env. actionlint/zizmor install paths unchanged.

MEASURE + FREEZE (advisory, dedicatedGate:true, direction down) in
config/quality/quality-baseline.json: secretFindings=3, zizmorFindings=195,
vulnCount=13 (LOW=4/MOD=7/HIGH=2), bundleSize=5601. Seeded from a local run with the
real binaries on PATH (2026-06-15). They stay advisory (SKIP in the blocking ratchet;
quality-extended is continue-on-error) until a green CI run confirms the fixed tooling
produces values; the flip to blocking is a follow-up PR. continue-on-error untouched.

Validated locally: zizmor --config parses; check:secrets <60s + real count;
check:workflows/check:vuln-ratchet emit real numbers; ci.yml actionlint-clean; baseline
JSON valid; 103 build-scanner unit tests + 19 check-secrets + 18 quality-ratchet pass;
the 4 keys SKIP in the ratchet. FIX 3 logic is sound but CI-only (cannot run gh release
download against the runner locally).
2026-06-15 22:45:48 -03:00
Diego Rodrigues de Sa e Souza
28d57bf5f8 ci(quality): fix scanner install + size-limit preset, promote codeqlAlerts to blocking (#3945)
FIX 1 — security scanner install (gitleaks/osv/actionlint/zizmor):
the step ran under bash -e and aborted before the $GITHUB_PATH export when
'go install ...gitleaks/v8@latest' failed/produced a non-working binary, so no
scanner landed on PATH and every check self-skipped. Rewritten to set +e,
install from official release downloads, ALWAYS export $HOME/.local/bin, and
print diagnostics. Validated only on the next CI run (binaries install in CI).

FIX 2 — size-limit bundleSize: add @size-limit/file devDependency (the correct
preset for the plain FILE-size .size-limit.json) + allowlist entry. check:bundle-size
now measures the 4 bin entries via the preset (bundleSize=5601) instead of erroring
on the missing preset / falling back to fs.statSync.

FIX 3 — codeqlAlerts promoted to BLOCKING: check-codeql-ratchet.mjs now reads
metrics.codeqlAlerts.value, exits 1 ONLY on a real regression (measured > baseline),
and exits 0 (graceful skip) on any measurement failure (gh absent / no auth /
no repo / API error) so missing infra never blocks. Baseline seeded codeqlAlerts=0
(repo has 0 open alerts). Blocking step wired in the quality-gate job with
security-events:read; the duplicate advisory step removed from quality-extended.
New TDD: evaluateCodeqlRatchet (5 cases).
2026-06-15 21:38:31 -03:00
NOXX - Commiter
d88ae9c157 fix(perplexity-web): update request payload to schema v2.18 to fix HTTP 400 (#3938)
Integrated into release/v3.8.26 — Perplexity-web schema v2.18 payload fix for HTTP 400. Validated: 24/24 perplexity tests, typecheck:core clean, file-size rebaselined (perplexity-web.ts 868->939, justified).
2026-06-15 21:01:45 -03:00
Diego Rodrigues de Sa e Souza
f3679019ab fix(compression): preserve upstream prompt cache for memory + compression (#3890) (#3936) 2026-06-15 20:05:23 -03:00
Randi
cdefc98327 fix: stabilize reasoning streams and request logs (#3879)
Integrated into release/v3.8.26 (reconciled cc-defaults UI with #3921)
2026-06-15 19:57:26 -03:00
NOXX - Commiter
2b886906a5 feat(media): Vertex AI (Google) speech, transcription, music & video generation (#3929)
Integrated into release/v3.8.26
2026-06-15 19:52:55 -03:00
Hernan Javier Ardila Sanchez
edc050fcdf fix(opencode-plugin): include nested combo-refs in LCD context window (#3910)
Integrated into release/v3.8.26
2026-06-15 19:51:43 -03:00
Diego Rodrigues de Sa e Souza
28c7ced2ec fix(providers): register BytePlus ModelArk so its API key validates (#3877) (#3935) 2026-06-15 19:49:51 -03:00
Diego Rodrigues de Sa e Souza
17fee53dbd fix(providers): correct Nous Research key validation probe model + accept non-auth 4xx (#3881) (#3934) 2026-06-15 19:43:22 -03:00
diego-anselmo
a5e704f7d6 fix(sse): anuncia role assistant no 1º delta do stream Responses→Chat (#3911)
Integrated into release/v3.8.26
2026-06-15 19:41:41 -03:00
Diego Rodrigues de Sa e Souza
9f5e651b42 ci(quality): wire Stryker mutation testing as advisory nightly (Fase 7 Task 11) (#3898)
Integrated into release/v3.8.26
2026-06-15 14:11:06 -03:00
Diego Rodrigues de Sa e Souza
e9d789822f ci(quality): freeze per-module coverage floors + wire require-tighten (advisory) (#3901)
Integrated into release/v3.8.26
2026-06-15 14:11:02 -03:00
Innokentiy Solntsev
fd7a5d68ae fix(providers): prevent zombie-socket hangs for zai/glm and tighten default keepAlive (#3907)
Integrated into release/v3.8.26 (zai validator; global keepAlive change reverted on review)
2026-06-15 14:06:48 -03:00
Felipe Almeman
9d846f3680 fix(proxy): direct-connection fallback for control-plane ops when a pinned proxy is unreachable (#3906)
Integrated into release/v3.8.26
2026-06-15 14:05:07 -03:00
Abhishek Divekar
6c1c055a20 feat(combo): add sticky round-robin target limit (#3846)
Integrated into release/v3.8.26
2026-06-15 12:33:15 -03:00
Raxxoor
624c846712 feat(glm): add GLM-5.2 with effort-tier routing (high/max) (#3885)
Integrated into release/v3.8.26
2026-06-15 12:25:58 -03:00
Jack Smith
4caa8451f4 Fix/generate models alias lookup (#3870)
Integrated into release/v3.8.26
2026-06-15 12:24:41 -03:00
Jack Smith
97d589864e Fix/candidate pool empty array (#3871)
Integrated into release/v3.8.26
2026-06-15 12:23:46 -03:00
Diego Rodrigues de Sa e Souza
320a9d3f29 chore(repo): nest quality-gate state under config/quality, declutter root (#3896)
Move the committed quality-gate state files out of the repo root into
config/quality/ and the v3.8.24 documentation audit into docs/ops/, then
re-point every gate script, test and .gitignore entry at the new paths.
Refresh docs/architecture/REPOSITORY_MAP.md (stale since v3.8.2) to match
the current layout.

Moved -> config/quality/:
  quality-baseline.json, complexity-baseline.json, duplication-baseline.json,
  file-size-baseline.json, test-discovery-baseline.json,
  dependency-allowlist.json, .license-allowlist.json
  (generated quality-metrics.json now written here too; still gitignored)

Moved -> docs/ops/:
  DOCUMENTATION_AUDIT_REPORT.md (+ meta.json entry + fabricated-docs skip)

Path updates: check-{complexity,duplication,file-size,test-discovery,deps,
licenses,dead-code,cognitive-complexity,type-coverage}.mjs, check-quality-
ratchet.mjs, collect-metrics.mjs, check-tracked-artifacts.mjs (+ its test and
check-deps test). Also gitignore /logs/ (was untracked-not-ignored).

Tracked root files: 56 -> 48. Tool configs left in root on purpose: most are
auto-discovered there, and the tsconfig variants have location-relative
files:[] arrays that would need 46 path rewrites for a 2-file gain.
2026-06-15 11:32:45 -03:00
diegosouzapw
6e392932c2 feat(i18n): add Azerbaijani (az 🇦🇿) language support
- Add az locale to config/i18n.json (source of truth, 42 locales total)
- Create src/i18n/messages/az.json (UI strings from en.json base)
- Create docs/i18n/az/ directory with full documentation set
- Add 🇦🇿 Azərbaycan dili to README.md language bar
- Add az entry to docs/i18n/README.md index (40 doc languages)
- Add az to generate-multilang.mjs LOCALE_SPECS (Google TL: az)
- Add az to i18n_autotranslate.py lang_map
- Update CHANGELOG.md with feat(i18n) entry
2026-05-15 01:14:43 -03:00
diegosouzapw
c86f60b1d3 feat(i18n): add config/i18n.json as canonical locale list
Adds config/i18n.json (41 locales) + JSON-Schema as the single source of
truth for the locale list, RTL set, and docs-translation policy. This file
is consumed by:

- The runtime UI config in src/i18n/config.ts (next commit).
- The docs translation pipeline (scripts/i18n/run-translation.mjs, added in
  a later commit).
- The drift checker (scripts/i18n/check-translation-drift.mjs).

Fields:
- default: source locale (en)
- rtl: locale codes rendered right-to-left
- uiOnly: locales shipped in UI but not target of docs translation
- docsExcluded: locales NOT receiving docs translations (source language)
- locales[]: code, label, name, native, english, flag

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-13 16:51:41 -03:00
diegosouzapw
dc6d9e2e4b feat(core): add payload rules, tag routing, and scheduled budgets
Introduce runtime-configurable payload mutation/filter rules with file
reload support and a settings API so upstream request bodies can be
customized per model and protocol without restarts.

Expand search support with Google PSE, Linkup, SearchAPI, and SearXNG,
including validation, routing, analytics costing, MCP schema updates,
and search-type-aware provider selection. Update Pollinations to support
anonymous access, endpoint failover, and the latest public model lineup.

Add OmniRoute response metadata headers/SSE comments, per-connection
model exclusion rules, combo tag-based routing, buffered spend writes,
and scheduled daily/weekly/monthly budget resets. Update model catalog
and dashboard UIs to surface source labels and hide models excluded by
all active connections.
2026-04-17 09:00:32 -03:00