Guoguo
49183d7e8d
fix: update Go and x/text for govulncheck ( #3286 )
2026-07-23 10:08:09 +08:00
Guoguo
e14f8daecb
Revert "docs: add PicoPaw banners to READMEs ( #3096 )" ( #3285 )
...
This reverts commit 083e68b49a .
2026-07-22 17:15:29 +08:00
Mauro
85dcfccad6
Merge pull request #3226 from ACMYuechen/fix/writefile-overwrite-guidance
...
fix(tools): stop write_file from coaching destructive overwrite (#3150 )
2026-07-09 13:31:41 +02:00
Yue_chen
9a0efd7bab
style(tools): wrap write_file guidance Sprintf for golines
2026-07-07 21:04:16 +08:00
Yue_chen
0132837d22
Merge branch 'main' into fix/writefile-overwrite-guidance
2026-07-07 20:46:53 +08:00
Yue_chen
a680d8fcfa
fix(tools): gate write_file overwrite guidance on available tools
...
#3150 reworded write_file's description, overwrite parameter, and guard
error to prefer append_file/edit_file. But those tools register via their
own enable flags and the per-agent allowlist, so a config exposing only
write_file was steered toward tools it does not have — a dead end in the
most restrictive setups.
WriteFileTool now tracks which non-destructive alternatives are available
and names only the ones present; when none are, the guard still blocks the
overwrite without pointing anywhere. The agent wiring registers the editors
before write_file and resolves availability via registry.HasRegistered,
which reflects both the enable flag and the allowlist.
Tests: conditional copy at the tool level (none/one/both) and agent wiring
across the enable-flag and allowlist dimensions.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com >
2026-07-07 20:40:27 +08:00
Mauro
c87b154b61
Merge pull request #3227 from AayushGupta16/fix/anthropic-tool-use-function-fallback
...
fix(providers): resolve tool_use name/args from Function on reloaded history
2026-07-06 13:57:51 +02:00
AayushGupta16
994c0aea11
fix(providers): resolve tool_use name/args from Function on reloaded history
...
ToolCall.Name and .Arguments are json:"-" (runtime-only), so after chat
history round-trips through the session store only ToolCall.Function
survives. The anthropic-messages and anthropic (SDK) providers emitted
tool_use blocks from tc.Name alone, silently skipping every historical
tool call while still emitting the matching tool_result — orphaned
tool_results 400 at the API ("unexpected tool_use_id found in
tool_result blocks"), killing every turn on agents with tool history.
Fall back to Function.Name / json-parsed Function.Arguments (the same
pattern the bedrock and openai_compat providers already use), and cover
the deserialized-history shape with table tests in both providers.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com >
2026-07-05 21:26:34 -07:00
Mauro
b6e6d25d75
Merge pull request #3189 from chengzhichao-xydt/codex/line-body-close
...
fix(line): explicitly ignore resp.Body.Close() errors in Send and classifySDKError
2026-07-05 09:35:40 +02:00
Yue_chen
8f891d5dd0
fix(tools): stop write_file from coaching destructive overwrite ( #3150 )
...
The overwrite guard error ("Set overwrite=true to replace") steered the
model to clobber files like MEMORY.md. Reword write_file's description,
overwrite param, and guard error to prefer append_file/edit_file.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com >
2026-07-05 14:13:31 +08:00
Mauro
0f4a997b47
Merge pull request #3224 from Ethan1918/fix/clear-routed-agent-session
...
fix(agent): clear routed agent session
2026-07-04 12:57:35 +02:00
Ethan1918
79c075fba0
fix(openai_compat): remove unused log import
2026-07-04 14:34:58 +08:00
Ethan1918
ffffb6a0cb
refactor(agent): route /clear through ContextManager.Clear for all agents
...
Address review feedback: the routed-agent /clear path bypassed the
public ContextManager.Clear contract via an unexported hook. Restore
the single Clear call in the command path and resolve the session's
owning agent inside the built-in implementations instead:
- legacy: Clear resolves the owning agent via agentForSession instead
of assuming the default agent
- seahorse: drop ClearContextStore; Clear wipes the engine state and
the owning agent's session store
- command path: persist session scope metadata before Clear so
ownership resolves even when /clear is the session's first message
- add coverage that a custom ContextManager receives Clear for routed
agents
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com >
2026-07-04 14:04:37 +08:00
Ethan1918
c4fb7a2001
fix(agent): clear routed agent session
2026-07-04 04:14:03 +08:00
Mauro
4c5adcd78e
Merge pull request #3128 from chengzhichao-xydt/codex/web-body-close
...
fix(web): explicitly ignore resp.Body.Close() errors after io.ReadAll
2026-07-03 20:45:55 +02:00
Mauro
cf24f32896
Merge pull request #3156 from loafoe/feat/session-token-usage
...
feat(pico): emit per-turn LLM token usage on finalized message
2026-07-03 09:14:36 +02:00
Mauro
4ccb6268a4
Merge pull request #3212 from sipeed/dependabot/npm_and_yarn/web/frontend/react-i18next-17.0.7
...
build(deps): bump react-i18next from 17.0.6 to 17.0.7 in /web/frontend
2026-07-02 23:50:18 +02:00
Mauro
1d9b1c444a
Merge pull request #3214 from sipeed/dependabot/npm_and_yarn/web/frontend/shadcn-4.12.0
...
build(deps): bump shadcn from 4.7.0 to 4.12.0 in /web/frontend
2026-07-02 23:49:35 +02:00
Mauro
0aff1bd7ab
Merge pull request #3215 from sipeed/dependabot/npm_and_yarn/web/frontend/typescript-eslint-8.62.1
...
build(deps-dev): bump typescript-eslint from 8.59.3 to 8.62.1 in /web/frontend
2026-07-02 23:49:10 +02:00
Mauro
1a6dd0efe5
Merge pull request #3216 from sipeed/dependabot/npm_and_yarn/web/frontend/vitejs/plugin-react-6.0.3
...
build(deps-dev): bump @vitejs/plugin-react from 6.0.1 to 6.0.3 in /web/frontend
2026-07-02 23:48:43 +02:00
Mauro
4b02293516
Merge pull request #3160 from danmobot/fix/launcher-setup-csrf
...
fix(auth): reject cross-site launcher setup requests
2026-07-02 23:46:41 +02:00
Mauro
883d43b37d
Merge pull request #3063 from trufae/deltachan
...
feat: add deltachat gateway
2026-07-02 23:45:24 +02:00
Mauro
3b24a48a8c
Merge pull request #3161 from danmobot/fix/exec-custom-allow-deny
...
fix(exec): keep deny patterns active for custom allow rules
2026-07-02 21:51:16 +02:00
Mauro
027226997f
Merge pull request #3209 from sipeed/dependabot/go_modules/github.com/anthropics/anthropic-sdk-go-1.55.1
...
build(deps): bump github.com/anthropics/anthropic-sdk-go from 1.50.2 to 1.55.1
2026-07-02 21:44:00 +02:00
Mauro
ce5274d179
Merge pull request #3210 from sipeed/dependabot/go_modules/golang.org/x/crypto-0.53.0
...
build(deps): bump golang.org/x/crypto from 0.51.0 to 0.53.0
2026-07-02 21:42:38 +02:00
Mauro
79ae6bf97f
Merge pull request #3158 from danmobot/fix/sandbox-fs-windows-paths
...
test: cover sandbox fs Windows path handling
2026-07-02 21:39:45 +02:00
dependabot[bot]
93a58e057e
build(deps-dev): bump @vitejs/plugin-react in /web/frontend
...
Bumps [@vitejs/plugin-react](https://github.com/vitejs/vite-plugin-react/tree/HEAD/packages/plugin-react ) from 6.0.1 to 6.0.3.
- [Release notes](https://github.com/vitejs/vite-plugin-react/releases )
- [Changelog](https://github.com/vitejs/vite-plugin-react/blob/main/packages/plugin-react/CHANGELOG.md )
- [Commits](https://github.com/vitejs/vite-plugin-react/commits/plugin-react@6.0.3/packages/plugin-react )
---
updated-dependencies:
- dependency-name: "@vitejs/plugin-react"
dependency-version: 6.0.3
dependency-type: direct:development
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-07-02 17:21:01 +00:00
dependabot[bot]
70b9cb9ea0
build(deps-dev): bump typescript-eslint in /web/frontend
...
Bumps [typescript-eslint](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/typescript-eslint ) from 8.59.3 to 8.62.1.
- [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases )
- [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/typescript-eslint/CHANGELOG.md )
- [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.62.1/packages/typescript-eslint )
---
updated-dependencies:
- dependency-name: typescript-eslint
dependency-version: 8.62.1
dependency-type: direct:development
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-07-02 17:17:28 +00:00
dependabot[bot]
8fd07bcacb
build(deps): bump shadcn from 4.7.0 to 4.12.0 in /web/frontend
...
Bumps [shadcn](https://github.com/shadcn-ui/ui/tree/HEAD/packages/shadcn ) from 4.7.0 to 4.12.0.
- [Release notes](https://github.com/shadcn-ui/ui/releases )
- [Changelog](https://github.com/shadcn-ui/ui/blob/main/packages/shadcn/CHANGELOG.md )
- [Commits](https://github.com/shadcn-ui/ui/commits/shadcn@4.12.0/packages/shadcn )
---
updated-dependencies:
- dependency-name: shadcn
dependency-version: 4.12.0
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-07-02 17:15:41 +00:00
dependabot[bot]
e56ab1f16e
build(deps): bump react-i18next from 17.0.6 to 17.0.7 in /web/frontend
...
Bumps [react-i18next](https://github.com/i18next/react-i18next ) from 17.0.6 to 17.0.7.
- [Changelog](https://github.com/i18next/react-i18next/blob/master/CHANGELOG.md )
- [Commits](https://github.com/i18next/react-i18next/compare/v17.0.6...v17.0.7 )
---
updated-dependencies:
- dependency-name: react-i18next
dependency-version: 17.0.7
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-07-02 17:14:49 +00:00
dependabot[bot]
addaef78ad
build(deps): bump golang.org/x/crypto from 0.51.0 to 0.53.0
...
Bumps [golang.org/x/crypto](https://github.com/golang/crypto ) from 0.51.0 to 0.53.0.
- [Commits](https://github.com/golang/crypto/compare/v0.51.0...v0.53.0 )
---
updated-dependencies:
- dependency-name: golang.org/x/crypto
dependency-version: 0.53.0
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-07-02 17:14:16 +00:00
dependabot[bot]
ba881f8273
build(deps): bump github.com/anthropics/anthropic-sdk-go
...
Bumps [github.com/anthropics/anthropic-sdk-go](https://github.com/anthropics/anthropic-sdk-go ) from 1.50.2 to 1.55.1.
- [Release notes](https://github.com/anthropics/anthropic-sdk-go/releases )
- [Changelog](https://github.com/anthropics/anthropic-sdk-go/blob/main/CHANGELOG.md )
- [Commits](https://github.com/anthropics/anthropic-sdk-go/compare/v1.50.2...v1.55.1 )
---
updated-dependencies:
- dependency-name: github.com/anthropics/anthropic-sdk-go
dependency-version: 1.55.1
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-07-02 17:14:13 +00:00
pancake
612e485d4e
WIP: Initial support for deltachat gateway
...
Features:
- Support voice messages
- Optional crossposting
- Automatic account creation
- Custom avatar image
2026-07-02 15:23:35 +02:00
LC
2cf030d2fd
fix(providers): surface friendly auth error messages ( #3198 )
nightly
v0.3.1
2026-06-30 17:42:07 +08:00
程智超0668000959
9068fde274
fix: gofumpt formatting on line.go
2026-06-27 10:20:37 +08:00
程智超0668000959
ce4a6c9bba
fix(line): explicitly ignore resp.Body.Close() errors in Send and classifySDKError
2026-06-27 09:19:13 +08:00
Mauro
52320f4875
Merge pull request #3181 from Alix-007/fix/gateway-startup-info-ok
...
fix(gateway): guard startup info assertions
2026-06-26 23:06:34 +02:00
Mauro
c15aac21fe
Merge pull request #3143 from lc6464/fix/isatap-ssrf-guard
...
fix(web): block private IPv4 embeds in ISATAP literals
2026-06-26 22:59:41 +02:00
Mauro
7ee4f41b7e
Merge pull request #3187 from chengzhichao-xydt/codex/http-guard-test-body-close
...
test(utils): explicitly ignore resp.Body.Close() errors in tests
2026-06-26 18:11:24 +02:00
Mauro
d65d592a40
Merge pull request #3188 from chengzhichao-xydt/codex/health-encode-errors
...
fix(health): explicitly ignore json.Encode errors in HTTP handler responses
2026-06-26 18:11:05 +02:00
Mauro
06830c9b19
Merge pull request #3186 from chengzhichao-xydt/codex/membench-body-close
...
fix(membench): explicitly ignore resp.Body.Close() error after io.ReadAll
2026-06-26 18:10:36 +02:00
Mauro
9bc8d15685
Merge pull request #3185 from chengzhichao-xydt/codex/updater-checksum-body-close
...
fix(updater): explicitly ignore resp2.Body.Close() error after io.ReadAll
2026-06-26 18:10:21 +02:00
Mauro
979f440af7
Merge pull request #3184 from chengzhichao-xydt/codex/ws-body-close
...
fix(channels): explicitly ignore resp.Body.Close() errors in websocket dial cleanup
2026-06-26 18:10:06 +02:00
Mauro
377c25e7c5
Merge pull request #3183 from chengzhichao-xydt/codex/onebot-body-close
...
fix(onebot): explicitly ignore resp.Body.Close() error after websocket dial
2026-06-26 18:09:04 +02:00
程智超0668000959
2cdfadaa8b
test(utils): explicitly ignore resp.Body.Close() errors in tests
2026-06-26 23:03:32 +08:00
程智超0668000959
0eb721fff7
fix(health): explicitly ignore json.Encode errors in HTTP handler responses
2026-06-26 22:57:48 +08:00
程智超0668000959
14c9a1f1f8
fix(membench): explicitly ignore resp.Body.Close() error after io.ReadAll
2026-06-26 22:51:51 +08:00
程智超0668000959
500ce72436
fix(onebot): explicitly ignore resp.Body.Close() error after websocket dial
2026-06-26 22:42:43 +08:00
程智超0668000959
583d9e1e14
fix(updater): explicitly ignore resp2.Body.Close() error after io.ReadAll
2026-06-26 22:15:29 +08:00
程智超0668000959
1bd2e84527
fix(channels): explicitly ignore resp.Body.Close() errors in websocket dial cleanup
2026-06-26 22:15:03 +08:00