jaberjaber23
acf2587e46
bump v0.6.9
2026-05-12 21:42:08 +03:00
jaberjaber23
4c496be02f
integration fixes
2026-05-12 16:13:08 +03:00
jaberjaber23
c27bfebd17
bump v0.6.7
2026-05-12 15:44:29 +03:00
jaberjaber23
88ad029999
bump v0.6.6
2026-05-12 15:27:09 +03:00
jaberjaber23
6f8463fc91
bump v0.6.5
2026-05-12 15:05:53 +03:00
jaberjaber23
3cce1eb3fb
bump v0.6.4
2026-05-01 13:48:18 +03:00
jaberjaber23
948117d5de
bump v0.6.3
2026-05-01 13:12:25 +03:00
jaberjaber23
15ed29c667
bump v0.6.2
2026-04-29 20:39:59 +03:00
jaberjaber23
aabf83b351
bump v0.6.1
2026-04-29 15:30:46 +03:00
jaberjaber23
e6bab993ae
bump v0.6.0
2026-04-19 22:57:55 +03:00
jaberjaber23
d3d9fa842d
release: v0.5.10
...
Bump workspace version to 0.5.10 and refresh docs.
Bundles the 7 fixes merged on main since v0.5.9:
- #1034 auth fail-closed (#1071 )
- #980 channel agent name prefix (#1072 )
- #1043 multimodal text+images (#1073 )
- #809 openfang hand config subcommand (#1074 )
- #843 context.md re-read per turn (#1075 )
- #905 config get default_model.base_url (#1076 )
- #1069 scheduler unification and migration (#1077 )
README: fix stale 0.3.30 badge and March 2026 header to 0.5.10 and April 2026,
drop em dashes throughout.
CHANGELOG: new 0.5.10 section with the above, plus notes on #818 and #819
which were closed as invalid.
2026-04-17 22:54:56 +03:00
Matteo De Agazio
528a7b9ff7
fix(deps): upgrade wasmtime 41->43 and rumqttc 0.24->0.25 to resolve CVEs (RUSTSEC-2026-0049, 0085-0096)
2026-04-11 23:50:55 +02:00
jaberjaber23
6851bbab09
bump v0.5.9
2026-04-10 21:19:33 +03:00
jaberjaber23
a4c6c038a0
bump v0.5.8
2026-04-10 19:57:59 +03:00
dependabot[bot] and dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
c47e15c1ce
chore(deps): bump prost 0.13 -> 0.14
...
Bumps [prost](https://github.com/tokio-rs/prost ) from 0.13.5 to 0.14.3.
- [Release notes](https://github.com/tokio-rs/prost/releases )
- [Changelog](https://github.com/tokio-rs/prost/blob/master/CHANGELOG.md )
- [Commits](https://github.com/tokio-rs/prost/compare/v0.13.5...v0.14.3 )
---
updated-dependencies:
- dependency-name: prost
dependency-version: 0.14.3
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-04-10 19:16:03 +03:00
Brandon Freeman
e1790b5380
fix: add explicit crypto provider
2026-04-09 17:10:21 +02:00
jaberjaber23
a26f762635
v0.5.7: multi-instance hands + 8 critical fixes
...
## Headline feature
- Multi-instance Hands via optional instance_name (customer ask + #878 ).
Web UI, CLI (--name / -n), API, kernel, registry all threaded. Two
clip-youtube + clip-tiktok instances now coexist. Backward compatible
when instance_name is omitted.
## Critical bug fixes
- #919 [SECURITY] rm bypass closed. process_start tool now validates against
exec_policy allowlist and rejects shell metacharacters in both command
and args. Added 5 regression tests.
- #1013 session_repair phase ordering — dedup now runs BEFORE synthetic
result insertion, fixing Moonshot's non-unique tool_call_id format
(function_name:index). Added regression test.
- #1003 global [[fallback_providers]] now actually used at runtime.
resolve_driver wraps primary in FallbackDriver with global fallback
chain. Network errors escalate to fallback instead of infinite retry.
- #937 Discord gateway heartbeat. Spawns interval task, tracks sequence,
handles ACKs, detects zombie connections, force-closes on missing ACK.
Credits @hello-world-bfree (PR #938 ) for the diagnosis.
- #935 System prompt leak in Web UI. get_agent_session now filters
Role::System by default (?include_system=true for debug). Defense in
depth client-side filter too.
- #984 Custom hands persistence. install_from_path copies to
~/.openfang/hands/. Kernel loads them on startup.
- #884 Workspace version bump 0.5.5 -> 0.5.7. Binaries now correctly
report --version as 0.5.7 instead of stale 0.5.5.
## Cleanup
- rmcp 1.3 builder API adopted (credits @jefflower PR #986 ) for
StreamableHttpClientTransportConfig. Drops unused Arc import.
## Stats
- 22 files changed, all workspace tests passing (1800+)
- Live-tested with daemon: v0.5.7 reported, multi-instance hands
verified end-to-end, Groq round-trip PONG confirmed
2026-04-08 22:59:56 +03:00
jaberjaber23
618e83714c
fix: version bump to 0.5.5, SSRF allowlist, Ollama context, embedding detection
...
- Bump workspace version and Tauri config to 0.5.5 (fixes users stuck on 0.5.1)
- Add ssrf_allowed_hosts config for self-hosted K8s environments (Jerry Jaz)
- Raise Ollama discovered model defaults to 128K context / 16K output (Cureator)
- Expand embedding auto-detection: OpenAI, Groq, Mistral, Together, Fireworks, Cohere, then local providers (Thunder Guardian)
All tests passing. 9 files changed, 272 insertions.
2026-03-30 21:30:48 +03:00
Jaber Jaber
f98bc330d4
Merge pull request #859 from RightNow-AI/dependabot/cargo/governor-0.10.4
...
build(deps): bump governor from 0.8.1 to 0.10.4
2026-03-27 22:04:59 +03:00
Jaber Jaber
86694dd926
Merge pull request #862 from RightNow-AI/dependabot/cargo/toml-0.9.12spec-1.1.0
...
Bump toml from 0.8.2 to 0.9.12+spec-1.1.0
2026-03-27 22:04:55 +03:00
dependabot[bot]
f8da17719e
Bump governor from 0.8.1 to 0.10.4
...
Bumps [governor](https://github.com/boinkor-net/governor ) from 0.8.1 to 0.10.4.
- [Release notes](https://github.com/boinkor-net/governor/releases )
- [Changelog](https://github.com/boinkor-net/governor/blob/master/release.toml )
- [Commits](https://github.com/boinkor-net/governor/compare/v0.8.1...v0.10.4 )
---
updated-dependencies:
- dependency-name: governor
dependency-version: 0.10.4
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-03-27 19:02:27 +00:00
Jaber Jaber
a72e6087d8
Merge pull request #665 from tianrking/main
...
feat(channels): add MQTT pub/sub channel adapter
2026-03-27 22:00:33 +03:00
Sky Moore
991aea85ee
feat: use rmcp for mcp protocol instead of hand rolled
...
Replace the custom JSON-RPC + stdio/SSE transport layer with the rmcp
SDK (crate 'rmcp'). This gives us spec-compliant Streamable-HTTP
transport, automatic Mcp-Session-Id tracking, SSE stream parsing, and
content-type negotiation out of the box while deleting ~300 lines of
hand-rolled plumbing.
Key changes:
- Add rmcp dependency with transport feature
- Replace McpTransportHandle enum with rmcp RunningService
- Replace manual JSON-RPC send_request/send_notification with rmcp client calls
- Add custom HTTP headers support for authenticated remote MCP servers
- Simplify tool discovery and invocation through rmcp's typed API
2026-03-27 16:47:32 +00:00
w0x7ce
bfbf0bb892
feat(channels): add MQTT pub/sub channel adapter
...
Add generic MQTT 3.1.1/5.0 support for IoT and messaging integration:
- MqttConfig with broker_url, TLS, QoS, auth via env vars
- MqttAdapter implementing ChannelAdapter trait
- Support for text and JSON {"text": "..."} payloads
- Command messages via /command args syntax
- Auto-reconnect with exponential backoff
- Message chunking for long responses
Configuration example:
[channels.mqtt]
broker_url = "tcp://broker.hivemq.com:1883"
subscribe_topic = "openfang/inbox"
publish_topic = "openfang/outbox"
2026-03-27 22:08:18 +08:00
Jaber Jaber
b6cb4cc2d9
Merge pull request #657 from xinuxZ/feat/feishu-websocket-receive-mode
...
feat(feishu): add WebSocket receive mode with protobuf framing
2026-03-27 16:44:31 +03:00
Jaber Jaber
6083c24484
Merge pull request #801 from b4iterdev/main
...
feat: add statically compiled native-tls to binary
2026-03-27 05:34:48 +03:00
dependabot[bot]
5212730773
Bump toml from 0.8.2 to 0.9.12+spec-1.1.0
...
Bumps [toml](https://github.com/toml-rs/toml ) from 0.8.2 to 0.9.12+spec-1.1.0.
- [Commits](https://github.com/toml-rs/toml/compare/toml-v0.8.2...toml-v0.9.12 )
---
updated-dependencies:
- dependency-name: toml
dependency-version: 0.9.12+spec-1.1.0
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-03-27 01:10:12 +00:00
Felix
da12f47369
fix: Fix the error when uploading files with Unicode characters in filenames
2026-03-24 19:33:12 +08:00
b4iterdev
78669863b7
feat: add statically compiled native-tls to binary
2026-03-23 14:32:48 +07:00
jaberjaber23
db86ff4ce3
bump v0.5.1
2026-03-20 03:48:59 +03:00
Jaber Jaber
41ffb8537a
Merge pull request #742 from RightNow-AI/dependabot/cargo/zip-4.6.1
...
Bump zip from 2.4.2 to 4.6.1
2026-03-20 03:13:22 +03:00
jaberjaber23
7f752dde99
bump v0.5.0
2026-03-20 00:46:15 +03:00
dependabot[bot]
eaa89defd1
Bump zip from 2.4.2 to 4.6.1
...
Bumps [zip](https://github.com/zip-rs/zip2 ) from 2.4.2 to 4.6.1.
- [Release notes](https://github.com/zip-rs/zip2/releases )
- [Changelog](https://github.com/zip-rs/zip2/blob/master/CHANGELOG.md )
- [Commits](https://github.com/zip-rs/zip2/compare/v2.4.2...v4.6.1 )
---
updated-dependencies:
- dependency-name: zip
dependency-version: 4.6.1
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-03-19 08:17:54 +00:00
jaberjaber23
93ea832394
bump v0.4.9
2026-03-19 02:04:30 +03:00
jaberjaber23
b676b2975a
bump v0.4.8
2026-03-19 00:04:29 +03:00
jaberjaber23
9f9903797e
bump v0.4.5
2026-03-18 05:42:11 +03:00
xinuxz
a95fb4a96b
feat(feishu): add WebSocket receive mode with protobuf framing
...
Add WebSocket long-connection receive mode for the Feishu/Lark adapter
as an alternative to webhook callbacks. WebSocket mode is enabled by
default, requiring no public IP or domain.
- FeishuConnectionMode enum (Webhook/WebSocket) with mode dispatch
- Protobuf binary frame parsing (prost) based on Feishu pbbp2 protocol
- Auto-reconnect, ping/pong heartbeat, ACK, multi-part payload combine
- handle_data_frame reuses parse_event() pipeline (dedup, group filter)
- FeishuMode config enum with bridge-layer adapter creation per mode
2026-03-16 10:37:01 +08:00
Evan Hu and Claude Opus 4.6
77ed954d18
wecom channel adapter
...
* feat: Add WeCom (WeChat Work) channel adapter
- Add wecom.rs channel adapter implementation
- Add WeComConfig in config.rs
- Register WeCom adapter in channel_bridge.rs
WeCom channel supports:
- Inbound messages via callback webhook
- Outbound messages via WeCom API
- Access token caching and auto-refresh
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com >
* fix: handle WeCom callbacks and preserve hand extension tools
* fix: render WeCom replies as plain text
* fix: resolve clippy warnings in wecom adapter
- Remove unused WECOM_API_HOST constant
- Fix needless borrow in send_text call
- Replace assert_eq!(bool, true) with assert!()
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com >
* style: cargo fmt for wecom-related files
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com >
* style: cargo fmt --all
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com >
* fix: upgrade quinn-proto and add cargo audit ignore list
- Upgrade quinn-proto 0.11.13 → 0.11.14 (RUSTSEC-2026-0037 DoS fix)
- Add .cargo/audit.toml to ignore unmaintainable transitive deps
(tauri GTK3 bindings, time pinned by mac-notification-sys, etc.)
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com >
---------
Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com >
2026-03-15 19:50:43 +03:00
dependabot[bot] and dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
e808ca0d08
bump mailparse
...
Bumps [mailparse](https://github.com/staktrace/mailparse ) from 0.15.0 to 0.16.1.
- [Commits](https://github.com/staktrace/mailparse/compare/v0.15.0...v0.16.1 )
---
updated-dependencies:
- dependency-name: mailparse
dependency-version: 0.16.1
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-03-15 16:54:06 +03:00
Evan Hu
14c4c1d1f5
stable hand agent IDs
...
* fix: use fixed agent ID for hand agents based on hand_id
This ensures triggers and cron jobs continue to work after daemon restart,
as hand agents now have stable IDs instead of generating a new UUID each time.
Changes:
- Add AgentId::from_string() method for deterministic ID generation
- Modify spawn_agent_with_parent() to accept optional fixed_id
- Use hand_id-based fixed ID in activate_hand()
See: #519
* remove: remove serena local config from commit
* chore: ignore .serena directory
2026-03-15 06:18:48 +03:00
Mark B and Claude Sonnet 4.6
7505007d8c
release-fast profile
...
Introduces a `release-fast` profile that inherits from `release` but
uses thin LTO and 8 codegen units instead of full LTO + 1, cutting
link time significantly while remaining fast enough for integration
testing. Documents usage in CONTRIBUTING.md.
Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com >
2026-03-15 05:57:33 +03:00
jaberjaber23
fdd6c1a1f7
vault wiring
2026-03-15 05:48:09 +03:00
jaberjaber23
135c37fbf7
community fixes
2026-03-15 01:25:15 +03:00
jaberjaber23
a7a96a7b0f
community fixes
2026-03-15 00:18:34 +03:00
jaberjaber23
52bacf0946
community fixes
2026-03-14 22:49:43 +03:00
jaberjaber23
d55e1b8545
community batch v0.4.0
2026-03-12 23:33:19 +03:00
jaberjaber23
0c059d1dc1
bump v0.3.49
2026-03-12 18:34:16 +03:00
jaberjaber23
b6b8b4ebe1
fix community issues
2026-03-12 16:42:39 +03:00
jaberjaber23
be8a589986
bump v0.3.47
2026-03-12 01:23:35 +03:00
jaberjaber23
98f8d1ca79
fix community PRs (inspired by #438 @pandego, #433 @ozekimasaki, #417 @f-liva, #392 @cryptonahue, #410 @hobostay, #413 @castorinop, #275 @woodcoal, #464 @citadelgrad, #419 @shipdocs, #480 @skeltavik, #439 @modship)
2026-03-11 03:25:16 +03:00