Skip to content

v1.1.0

Choose a tag to compare

@github-actions github-actions released this 16 Jul 16:20
· 25 commits to main since this release

Post–1.0.0 release: parallel review pipeline hardening, install-wide ops visibility, findings quality, security triage, and product docs with UI screenshots.

Added

  • Parallel specialists + structured rationale → senior verifier — roles on a unit always run
    concurrently (Promise.all) with a barrier before the next stage; findings may carry
    reasoning (plus evidence.type=reasoning). Verifier is a principal-SWE batch pass
    (keep/drop/severity) using rationale + packed context. Migration 013_finding_reasoning.sql.
  • Session timing ledger — session.audit.timings / metadata.timings: wall clock per pipeline
    stage, per unit, rollups (longest stage/unit/specialist, byStageMs, tool time). Session report
    Timing / bottlenecks section; worker logs stage=X done … + end-of-job summary.
  • Live specialist heartbeats — SSE specialist_run started / running (interval
    STEW_SPECIALIST_HEARTBEAT_MS, default 15s) / completed / failed. Session blade Live specialists
    banner with per-role elapsed timers.
  • Platform ops analytics — GET /v1/platform/analytics?days=N (platform operators) for
    install-wide success rate, p50/p95 latency, stage averages, specialist role stats, worker queue,
    tokens. UI: Settings → Platform ops (/settings/platform/ops). Distinct from tenant Analytics.
  • GitHub Code Scanning SARIF upload — PR gate publishes via code-scanning/sarifs (gzip+base64).
    STEW_PUBLISH_SARIF (env → platform runtime → org → default On). Requires code scanning enabled
    and security_events: write.
  • Three-level finding confidence — product confidence, specialist modelConfidence,
    optional tokenConfidence (logprobs). UI/SARIF/suggested-fix gate use product confidence.
    Migration 012_finding_confidence_layers.sql.
  • Suggested code fixes — suggestedFix / suggestion / existingCode on findings; Findings UI,
    reports, SARIF, PR comments. Min confidence gate STEW_SUGGESTED_FIX_MIN_CONFIDENCE (default 0.75).
    Migrations 011_finding_suggested_fix.sql.
  • Install-wide platform runtime store — GET/PUT /v1/platform/runtime-config; org may only
    override suggested code fixes when platform policy is Unset.
  • Product docs — docs/UI_GUIDE.md (screenshot tour), docs/README.md,
    docs/REVIEW_PIPELINE.md, session audit notes; screenshots under docs/screenshots/ (kebab-case).

Changed

  • Job queue is Postgres-only — removed file-backed FileJobQueue / jobs.json.
    DATABASE_URL required for multi-replica safety; NATS/Rabbit/Pulsar remain optional wake-up brokers.
  • Specialist timeouts — STEW_SPECIALIST_TIMEOUT_MS (default 8m); truncated runs emit coverage-gap
    findings (steward.specialist_timeout), audit coverageGaps, UI TIMEOUT ledger — never a silent
    clean empty scan. LLM retries: STEW_LLM_MAX_RETRIES + STEW_LLM_REQUEST_TIMEOUT_MS.
  • Session stage pipeline UI — per-stage durations, live active step, skipped optional stages,
    timing bars; audit JSON download only under Review audit (not duplicated on Review report).
  • Members UI — role capability help; Keycloak vs local create-user copy clarified.
  • Runtime UI — Unset / Off / On for booleans; platform vs org scope clearly labeled.
  • Codesteward Graph image — default ghcr.io/codesteward/codesteward-graph.
  • README — self-host focused; docs links to UI guide + pipeline.
  • Local sandbox defaults to in-place repo read (STEW_SANDBOX_COPY=1 for full tree copy).

Fixed

  • GitHub clone host — map api.github.com / GITHUB_API_URL to git host https://github.com
    (resolveGithubGitHost); exact hostnames only (no substring SSRF). Hardened clone args
    (assertSafeGitArg, -- on clone).
  • Keycloak first install user — first OIDC JIT user on empty store gets platformAdmin + product
    admin (parity with local bootstrap).
  • Code scanning triage — crypto temp passwords; Confluence CQL/HTML strip; remove unused
    vulnerable diff package (GHSA-73rr-hh4g-fpgx); root SECURITY.md; CodeQL quality cleanups.
  • Keycloak login path — no fallback to local password form when IdP is configured (break-glass
    only /login?local=1).
  • Workspace GC — delete {STEW_WORKSPACE_DIR}/{sessionId} clones after terminal status
    (STEW_WORKSPACE_KEEP=1 to retain).
  • Container permissions — entrypoint chowns data/workspace volumes for non-root steward.
  • LocalSandbox spawn — handle ENOENT; prefer /bin/bash or /bin/sh; no worker process crash.
  • Resume UI — failure branding only on terminal status; resume clears prior error.
  • CI / release — Trivy 0.72.0; Semgrep GCM authTagLength; zizmor cache-poisoning fixes;
    multi-stage Docker; drop SaaS-billing image from public CI/release; CodeQL action v4.
  • GitHub connector icon visible on light theme (currentColor).
  • Plan-gate UI for audit log / SCIM; SCIM org entitlement; platform GitHub App enforce UX.

Migrations

Operators with Postgres should run migrations through 011–013 (suggested fix, confidence layers,
finding reasoning) if upgrading from 1.0.0:

pnpm migrate
# or: pnpm --filter @codesteward/db run migrate

Upgrade notes

  1. Ensure DATABASE_URL is set (file job queue removed).
  2. Run DB migrations 011–013.
  3. Rebuild/redeploy API, worker, and UI images (or pnpm -r run build).
  4. Optional: set STEW_PLATFORM_ADMIN_EMAILS for additional platform operators under Keycloak.
  5. Helm: set image tag 1.1.0 (chart appVersion updated).

Container images

docker pull ghcr.io/codesteward/codesteward:1.1.0
docker pull ghcr.io/codesteward/codesteward/ui:1.1.0

App image runs API by default (SERVICE=api). Worker:

docker run --rm -e SERVICE=worker ghcr.io/codesteward/codesteward:1.1.0

Images are signed with cosign keyless via GitHub OIDC.
Verify with:

cosign verify ghcr.io/codesteward/codesteward:1.1.0 \
  --certificate-identity-regexp 'https://github.com/Codesteward/codesteward/.*' \
  --certificate-oidc-issuer https://token.actions.githubusercontent.com