Repository navigation
Add SECURITY.md policy and enhance tool handling features - #110
Merged
Merged
Conversation
Set up the repository's security policy so GitHub's Security tab is populated instead of showing "This project has not set up a SECURITY.md file yet." - SECURITY.md (English) + SECURITY_CN.md (中文), following the existing bilingual doc convention (CONTRIBUTING.md / CONTRIBUTING_CN.md). - Private reporting routes to GitHub Security Advisories, consistent with the existing .github/ISSUE_TEMPLATE/config.yml contact link. - Covers supported versions (rolling 0.x), reporting steps, coordinated disclosure process, scope, and a safe-harbor clause. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
feat: add view_image tool
Update flashgrep workspace search integration
chore: bump version to 0.2.11
- apply TTFT to first effective streamed output instead of HTTP 200 - allow null TTFT config to wait indefinitely - remove reasoning-specific TTFT override - clarify stream timeout UI copy and next-turn activation
- manage provider stream handler lifecycle in execute_sse_request - cancel background SSE handlers when the response stream is dropped - stop provider adapters from spawning detached stream tasks - add coverage for managed stream cancellation on drop
fix(chat-input): block sending during model switch and ensure backend sync
…s globally Let remote IM users switch session models via /model, propagate the choice to all configured agent types in ai.agent_models, and align desktop ModelSelector with the same cross-agent persistence behavior.
feat(remote-connect): add IM bot model switching and sync agent models globally
…olicy docs: add SECURITY.md security policy (EN + 中文)
fix(image-preview): prevent lightbox image preview from being covered by sidebar
fix(diff-preview): fix text overlap in md file diff content
…bilities fix: preserve multimodal model capabilities
…n tools - propagate remote workspace identity through agent turn submission and reply routing - resolve session-targeted cron and session tool actions from stored workspace bindings - keep scheduled-job reminders ordered after mode and remote file delivery reminders
… Windows capture Consolidate mouse tools into computer_use, split the desktop host into reviewable modules, add permission-aware Tool Card and session UX, and respect global skip tool confirmation. Windows gains AppSelector-based get_app_state and WGC capture fallback; Linux is documented as a legacy compatibility layer.
Replace var(--color-warning, orange) with theme tokens so the color governance audit passes in CI.
… Use Gate macOS-only ax_orchestration imports, expose shared pointer helpers, fix Windows HWND Send in spawn_blocking, add missing WinRT Cargo features, and correct WGC Direct3D11 texture creation APIs.
…te types Use HMODULE::default() for the software parameter and round global pointer coordinates to i32 for scaled-image overlay mapping.
Scope HWND to a block so the async future stays Send across spawn_blocking and screenshot attachment awaits.
…r-platform-ux feat(computer-use): refactor desktop host, unify tool UX, and improve Windows capture
…tions feat: support images in /btw side questions
Add manual ~/.ssh/config parsing when ssh_config crate fails on Include/Match directives, and change config host entries to fill the connection form instead of connecting immediately.
…back-and-fill-form fix(ssh-remote): fallback SSH config parsing and fill-form UX
Remove the legacy top-level GUI theme config provider while preserving theme.id as a thin fallback to themes.current. Tighten theme color governance baselines after low-risk web and installer preset near-color merges.
…sing Add search filters for saved connections and SSH config hosts, polish the saved-list layout, and correctly parse quoted values in manual SSH config fallback.
…g-search-and-config-parse feat(ssh-remote): improve connection dialog search and SSH config parsing
chore: bump version to 0.2.12
Build dialog turn model_rounds from execution new_messages when the host does not persist rounds itself, so Desktop and other surfaces can render CLI session history with text, tools, and thinking content.
…-rounds-persistence fix(agentic): persist rich model rounds from CLI execution messages
Add Aperture, GitPullRequest, Grid3x3, Presentation, and Regex so builtin miniapp meta icons render correctly instead of falling back to Box.
…y-expansion feat(web-ui): register missing Lucide icons for builtin miniapps
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Fixes #
Type and Areas
Type:
Areas:
Motivation / Impact
Verification
Reviewer Notes
Checklist