2026-06-16 - 2026-06-23
Overview
24 Releases published by 1 user
Published
runtime-v0.3.54
Published
runtime-v0.3.53
Published
runtime-v0.3.52
Published
runtime-v0.3.51
Published
runtime-v0.3.50
Published
runtime-v0.3.49
Published
runtime-v0.3.48
Published
runtime-v0.3.47
Published
runtime-v0.3.46
Published
runtime-v0.3.45
Published
runtime-v0.3.44
Published
runtime-v0.3.43
Published
runtime-v0.3.42
Published
runtime-v0.3.41
Published
runtime-v0.3.40
Published
runtime-v0.3.39
Published
runtime-v0.3.38
Published
runtime-v0.3.37
Published
runtime-v0.3.36
Published
runtime-v0.3.35
Published
runtime-v0.3.34
Published
runtime-v0.3.33
Published
runtime-v0.3.32
Published
runtime-v0.3.31
24 Pull requests merged by 5 users
Merged
#172 fix(runtime#3159): deliver management MCP runtime-agnostically via an MCP-wiring PORT
Merged
#171 fix(platform-agent): ship management-MCP diagnostic in heartbeat (cp#3164)
Merged
#170 fix(runtime#133): context-budget detection + compact-and-continue (smallest-scope-first)
Merged
#169 fix(runtime#131): auto-merge propagated .runtime-version bump PRs on consumer templates
Merged
#168 fix(runtime#52): bounded retry/backoff on PR POST in propagate_runtime_version
Merged
#167 fix(runtime#86): re-apply GIT_ASKPASS + add workflow URL-embedding regression gate
Merged
#165 fix(runtime#162): drop inherited OAuth token from ANTHROPIC_AUTH_TOKEN under CP-proxy routing
Merged
#164 fix(#3164 Layer-2): add observability to self-heal identity gates
Merged
#161 fix(llm-auth): drop inherited OAuth token when base URL is the CP proxy
Merged
#160 fix(consumer-drift): stop runtime main going red on every release (propagate set + token-scope reconcile)
Merged
#159 fix(RCA#2970): protect management MCP from user-plugin eviction on the concierge
Merged
#158 feat(core#3082): loaded_mcp_tools producer in the heartbeat
Merged
#155 feat(runtime#38): SSOT public surface for MCP tool schemas + target resolution
Merged
#154 test(#87): author the MISSING test_boot_routes.py + real-subprocess credential_helper
Merged
#157 feat(ssot): gate concierge MCP-present literals against the delivery contract
Merged
#156 fix(concierge): recognize plugin-delivered management MCP in RCA#2970 online gate
Merged
#137 fix(consumer-drift): close DEFAULT_CONSUMERS blind spot + org-scan reconcile
Merged
#141 fix(config): /opt fallback in load_config for concierge self-host safety (core#2919 risk-2)
Merged
#146 test(messaging): behavioral tests for broadcast_message and talk_to_user (#1156)
Merged
#153 fix(plugins): fail install loudly when setup.sh fails for privileged MCP plugin
Merged
#152 fix(secret-scan): correct self-exclude path to .gitea (#150)
Merged
#147 fix(platform-agent): declare mcp_server_present on register/heartbeat (RCA #2970)
Merged
#149 fix(plugins): harden skill copy — no symlink-deref, scrub template PAT (#32 security)
Merged
#148 fix(plugins): default skill-shaped plugins to AgentskillsAdaptor (#32 activation)
8 Issues closed from 5 users
Closed
#20 Security: re-implement MCP-tool RBAC gate (CWE-862, originally #12)
Closed
#162 Inherited OAuth via ANTHROPIC_AUTH_TOKEN under CP-proxy routing -> silent native-Anthropic billing leak
Closed
#86 RCA: publish-runtime cascade still places DISPATCH_TOKEN in git remote URLs
Closed
#133 Auto-heal on context overflow WIPES the session (loses task memory) — should COMPACT instead
Closed
#38 SSOT: base MCP/runtime owns Molecule tool schemas and target resolution
Closed
#87 [needs-regression-test] boot: author the MISSING tests/test_boot_routes.py (4-branch card/JSON-RPC contract) + main() boot-ordering test + credential_helper subprocess test; wire real-executor smoke into THIS repo's CI
Closed
#151 plugin install should fail loud when setup.sh fails (concierge silently missing molecule-mcp)
Closed
#150 RCA: secret-scan workflow self-exclude still points at .github after Gitea migration
3 Issues created by 0 users
Opened
#150 RCA: secret-scan workflow self-exclude still points at .github after Gitea migration
Opened
#151 plugin install should fail loud when setup.sh fails (concierge silently missing molecule-mcp)
Opened
#162 Inherited OAuth via ANTHROPIC_AUTH_TOKEN under CP-proxy routing -> silent native-Anthropic billing leak