Repository navigation
Releases: DevArtsLab/tool-universal-ai-config
Releases · DevArtsLab/tool-universal-ai-config
Release list
v0.2.1
What's Changed
Security
- Project config trust checks (CWE-427):
project_config()and
find_project_root()now skip.ai/directories that are not owned by the
current user, preventing configuration injection (provider credentials,
MCP servers) from shared or world-writable directories. A
SecurityWarningis emitted when a directory is skipped or when ownership
cannot be verified (Windows). Directories that fail verification are
skipped, not loaded.
Changed
- GitHub Actions bumped to Node 24 majors (
checkoutv7,setup-pythonv7,
upload-artifactv7,download-artifactv8,action-gh-releasev3) -
clears the Node 20 deprecation annotations on every run. - Release workflow now derives the GitHub release body from
CHANGELOG.md
instead of relying solely on auto-generated notes.
Full Changelog: v0.2.0...v0.2.1
v0.2.0
What's Changed
Added
ai-config synccommand: writes the unified configuration back to each
provider's native files (export direction;migrateis the import direction)--dry-runpreviews every planned write--provider <name>(repeatable) targets specific providers--allsyncs every known provider, even undetected ones--projectsyncs project-level targets (.cursor/,.vscode/,
.github/copilot-instructions.md,CLAUDE.md,AGENTS.md,.rules)--prunemakes provider MCP lists an exact mirror of the unified config,
backing up files before removing servers
- Per-provider MCP scoping via
providers.<name>.mcp:
{"include": [...]}or{"exclude": [...]} - Provider coverage expanded from 3 to 9: added Cursor, Codex CLI, Gemini CLI,
VS Code (Copilot), Zed, and Continue alongside Devin, Windsurf, and Claude - Multi-format config support: JSON, TOML (
config.toml), and YAML
(config.yaml) are read and written where providers use them - Per-provider MCP shape translation:
mcpServers(most),serverswith
type(VS Code),context_servers(Zed, stdio only), TOML
[mcp_servers.*](Codex), YAML list (Continue) - Rules sync: unified
AGENTS.mdlands as a managed block
(<!-- BEGIN ai-config managed -->) in shared files, or as dedicated rule
files (.cursor/rules/*.mdc,.continue/rules/*.md, Windsurf global rules) - Windsurf coverage spans the Codeium-era paths (
~/.codeium/) and current
~/.windsurf/paths; Devin CLI covers~/.config/devin/and~/.devin/ - MCP migration dedupes identical servers and keeps conflicting same-name
servers under a<name>.<provider>alias instead of silently overwriting "disabled": trueflag on unified MCP server entries: disabled servers
stay in the store as dormant inventory and are never exported by sync,
even when named in a provider'sincludelisttests/suite: 43 tests covering formats, provider translation, sync,
migration, and project-local config
Fixed
AgentEnv.project_configwas declared@propertybut accepts acwd
argument, soget_merged_config(cwd=)(the documented provider integration
call) always raisedTypeErrorProjectConfig.enable_featureoverwrote theenabled_featureslist with
each call, anddisable_featurewrote to adisabled_featureskey that
nothing read - both now correctly maintainenabled_features- All outstanding mypy errors in
project.py,config.py, andmigration.py - Project local MCP overrides were unusable:
save_mcp_config(local=True)
wrote.ai/mcp-config.local.jsonwhileget_mcp_configread
.ai/mcp_config.local.json(andinit-projectgitignored the latter).
Everything now uses the hyphenatedmcp-config.local.json ai-config validatecounted skills in~/.agents/config/skills/instead
of the actual~/.agents/skills/directory
Changed
- BREAKING:
ai-config syncno longer writes to every detected provider
by default. Export is opt-in via"providers.<name>.sync": true, or
explicit--provider/--allflags. Global config is now the
store-of-truth; providers read it directly or receive explicit exports.
This prevents credentials in MCPenvfrom propagating to every installed
tool - Migration dedupes across provider naming schemes (e.g. VS Code registry
names likeio.github.X/foo-mcpmatchfoo), normalizes empty injected
fields on compare, and reuses existing aliases instead of minting.2/.3
suffixes on re-import ProviderMigrator.PROVIDER_PATHSnow derives from the provider registry in
providers.py(single source for read paths and sync targets)- Unified MCP store key renamed to
context_serversin
config/mcp-config.jsonand the loaded unified config; the legacy
mcpServerskey is still accepted on read - New dependencies:
tomli(Python <3.11),tomli-w,pyyaml