Skip to content

Releases: LMPrado-DZ23/OmniRoute

3.8.55

Choose a tag to compare

@github-actions github-actions released this 20 Sep 13:21
df4d861
Release v3.8.55

The release whose main product is evidence.

This line had never produced a full-CI verdict at any commit. It has one
now: the Release-Green sweep was split across jobs (#87) — resolve → seven
parallel suites → an aggregator that merges their reports — and the first
verdict it produced was RED, for two real reasons:

  · the integration suite was making a live HTTPS request to aihorde.net
    on every run
  · a false positive of the network guard added earlier in this cycle

Both fixed (#96); the second sweep passed all seven shards.

Security, and it matters for a public deployment:

  · /v1/** no longer answers anonymous callers when REQUIRE_API_KEY is
    false — it was an open LLM relay, and a deployment guide prescribed
    exactly that configuration (#69)
  · the login lockout no longer keys on the reverse-proxy hop, which let
    any stranger lock the owner out of their own dashboard; the operator
    can now name their proxy by exact IP (#75, #97)
  · "Allow Private Provider URLs" no longer also unblocks cloud metadata,
    which reopened the SSRF→IMDS pivot on a VPS (#83)
  · the npm publish gate could be walked around by dispatching a workflow
    that CALLS it (#95), and the plugin publishes installed dependencies
    with scripts enabled while holding a provenance token (#88)

Accessibility, product, docs:

  · the primary button's gradient failed AA at its violet end — 3.96:1 on
    the most-clicked control in the product; axe never flagged it because
    it reports gradients as "incomplete" (#91)
  · every Workspaces error was English in every language (#90)
  · 41 translated READMEs never said which project they belong to (#89)
  · a release note claimed more than the PR shipped, corrected through the
    changelog's own reconciliation ledger rather than around it (#94)

This tag was moved once, before any Release existed and before anything
could consume it: the first attempt could not build. npm on the runner
began enforcing `allowScripts` between 2026-09-19 and 2026-09-20, dropped
onnxruntime-node and with it @huggingface/transformers, and exited 0 —
caught by check:native-deps, fixed in #103.

Known and stated, not hidden: check:pack-artifact is NOT measured in CI.
It falls back to a full `next build`, which no available runner fits, and
the repository has zero self-hosted runners registered. It validates the
npm tarball — which this fork does not publish — and npm-publish.yml runs
that gate itself, so it is not bypassed where it would matter. The sweep
records it as unmeasured rather than reporting green.

Six times this cycle a check was found reporting success while measuring
nothing. Each one now fails first when broken.

v3.8.54

Choose a tag to compare

@LMPrado-DZ23 LMPrado-DZ23 released this 19 Sep 13:12
c4ede43

OmniRoute v3.8.54 — the evolution release of the LMPrado-DZ23 fork.

Thirteen phases, each merged as its own pull request against release/v3.8.54, then three
independent audits (architecture, security, product/UX) and a verification round on the final tree.
The full record is in docs/EVOLUTION_STATUS.md and
audit/FINAL_THREE_AGENT_REVIEW.md.

This release is non-breaking. Every existing HTTP contract is kept; new response fields, headers
and endpoints are additive; and behavior that could surprise an existing installation — SLO webhook
alerts and routing diagnostics — is opt-in and off by default. Upgrading from 3.8.53 needs no
configuration change.

Highlights

The router can now explain itself. A shared contract (RoutingRequest, RoutingCandidate,
RoutingDecision, ProviderAttempt) carries the score factors behind a pick, the explicit reason
every other candidate was excluded, quota state that tells unknown apart from exhausted, and a
policy version stamped on the decision. Preview and live traffic run the same engine, and preview
never touches live routing state. Every routed response carries X-OmniRoute-Decision-Id and
X-OmniRoute-Policy-Version — streaming included — and GET /api/omniroute/route/decisions/{id}
returns the decision behind a request id, with a lookup card in the dashboard.

Observability you can page on. Bounded-cardinality routing metrics, GET /api/metrics in
Prometheus text or JSON, configurable SLOs with an editable card under Settings → Resilience, and
opt-in slo.breached / slo.recovered / provider.circuit_open webhook alerts.

A first run that works. The INITIAL_PASSWORD bootstrap is one-time, the wizard can be re-run,
and a failing provider check says what to do about it. On a cold start the login page no longer
abandons its login-requirement probe and leaves a new user on a password prompt that does nothing —
it waits for the answer, retries, and explains itself with a retry button if the answer never
arrives.

Governed API surface. Every OpenAPI operation is classified with x-stability, x-owner,
x-since, x-rate-limit and, for stable operations, x-contract-test. The coverage gate is at
100%, and deprecations emit RFC 9745 Deprecation and RFC 8594 Sunset headers.

Accessibility. In the light theme, zero serious axe violations from 375 px to 1440 px on every
gated page — login, home, providers, settings, resilience, route trace, webhooks, combos, logs and
the onboarding wizard — keyboard flows included and gated end to end. No page overflows
horizontally at any width. One residual is recorded rather than hidden: white on the dark brand
primary measures 3.78:1, which is a brand-colour decision, not a patch-release change.

Quality floor. Core, API, dashboard and open-sse all typecheck at 0 errors — the work that got
there found and fixed 22 runtime bugs red-first, including PATCH /api/keys/[id] silently dropping
blockedModels (a key kept serving models the operator had blocked) and
POST /api/omniroute/route/preview failing for every valid request. Live tests are now opt-in
behind their own RUN_COMBO_LIVE / RUN_BOUNDARY_LIVE flags, so no suite sends real provider
traffic just because an API key happens to be in the environment.

Security fixes worth reading

  • Neither SDK forwards credentials on a cross-origin redirect, and an https → http downgrade is
    refused.
  • A chat completion POST that may already have run is no longer replayed after a timeout.
  • Provider credentials are revealed only to a pipeline-stamped dashboard subject — a programmatic
    management credential can no longer read a stored credential back.
  • Reading provider health no longer probes the circuit breakers. Nine read paths used a call that
    transitioned an OPEN breaker to HALF_OPEN and persisted it, so merely polling health could let a
    request through to a provider that was still down.
  • The TypeScript SDK no longer replays the request body to a cross-origin redirect target.
  • adm-zip moved to 0.6.1, taking the root production dependency audit to zero advisories of any
    severity.

What the audit found

Two rounds, three independent auditors each (architecture, security, product/QA), working in
parallel without access to each other's conclusions. The verification round re-checked every fix on
the final tree; none was missing, partial or wrong. All three returned PASS with CRITICAL 0 and
HIGH 0
.

The evidence that mattered most for a release that changes the router: provider selection is
identical to v3.8.53 in 700 of 700 seeded cases
, with a frozen clock, and previewRoutingDecision
called Math.random zero times over 200 previews with the rotator provably untouched. Explainability
costs less than it did when the auditors first measured it — building the recorded decision went
from 17.0 ms and 591 KiB per request to 4.6 ms and 26.5 KiB at 300 candidates.

Known limits

  • The workspace and budget hierarchy is designed (ADR) but not implemented; it is planned for 3.9.x
    as additive migrations.
  • 151 routes are covered by OpenAPI but have no contract test referencing them yet.
  • One accepted residual advisory: js-yaml 4.3.1 in the Electron build chain (register R-10). It
    does not affect the server or dashboard runtime and needs an Electron lockfile refresh.
  • No live per-candidate latency budget; the routing contract documents exactly what live traffic
    does enforce.
  • The TypeScript and Python SDKs are experimental and deliberately unpublished — the package names
    belong to the upstream project, and publication waits for the HTTP contract freeze in 3.8.59.

Artifacts

Desktop installers are attached below. The container image is published to GHCR:

docker pull ghcr.io/lmprado-dz23/omniroute:3.8.54

Full changelog: CHANGELOG.md

v3.8.53

Choose a tag to compare

@github-actions github-actions released this 13 Sep 19:52
2560ec3

Patch release of the LMPrado-DZ23/OmniRoute fork. It adds the Windows desktop installer that v3.8.52 could not build. Everything else is the same as v3.8.52.

Install

Channel How
Windows OmniRoute.Setup.3.8.53.exe: double-click it and follow the installer (a portable OmniRoute-3.8.53.exe that runs without installing is also attached)
Docker (requires Docker installed) docker run -d --name omniroute -p 127.0.0.1:20128:20128 -v omniroute-data:/app/data ghcr.io/lmprado-dz23/omniroute:3.8.53 (also :latest, multi-arch amd64 + arm64)
Linux OmniRoute-3.8.53.AppImage / omniroute-desktop_3.8.53_amd64.deb (x64), and the arm64 variants
macOS OmniRoute-3.8.53.dmg (Intel) and OmniRoute-3.8.53-arm64.dmg (Apple Silicon)
From source git clone … && npm ci && npm run build && npm start (Node.js 22 or 24 LTS)

Dashboard at http://localhost:20128, API at http://localhost:20128/v1.

What changed

Windows installer builds. In v3.8.52 the Windows build got past bundle verification, then stopped while compressing the installer. A package inside the bundle had a helper shortcut (node_modules/.bin/semver) that pointed at a folder on the Linux build machine, and that folder does not exist on Windows. The bundle cleanup used to check only the top level of node_modules. It now checks the whole tree:

  • a shortcut whose target exists is replaced by a real copy of it;
  • a broken shortcut is removed;
  • a shortcut that points at its own parent folder is removed.

Nightly quality check runs to completion. The scheduled Release-Green sweep ran its heavy test suites all at once, which exhausted the 16 GB GitHub-hosted runner and killed it every night. It now runs them one after another on hosted runners, and no longer fails just because this repository has GitHub Issues turned off.

See v3.8.52 for the Loop stream, MCP approvals, browser allowlist screen and signing pipeline.

Known limitation

  • Installers are not code-signed yet. Signing needs a certificate issued to the publisher, and none has been added to the repository. On Windows, SmartScreen shows a warning: click More info, then Run anyway. On macOS, Gatekeeper blocks the first launch: right-click the app and choose Open. Docker and source installs are unaffected.

Evidence

  • PR #21: root cause, the failing log line, and regression tests (12/12 on Linux with the fix, 9/12 without it)
  • audit/RELEASE_READINESS.md §3.3: v3.8.52 caveat fixes and the signing blocker

v3.8.52

Choose a tag to compare

@github-actions github-actions released this 12 Sep 22:06
a976818

Patch release of the LMPrado-DZ23/OmniRoute fork. It fixes three of the four limitations published with v3.8.51, and prepares the release pipeline for the fourth (installer signing).

Install

Channel How
Docker (requires Docker installed) docker run -d --name omniroute -p 127.0.0.1:20128:20128 -v omniroute-data:/app/data ghcr.io/lmprado-dz23/omniroute:3.8.52 (also :latest, multi-arch amd64 + arm64)
Linux OmniRoute-3.8.52.AppImage / omniroute-desktop_3.8.52_amd64.deb (x64), and the arm64 variants
macOS OmniRoute-3.8.52.dmg (Intel) and OmniRoute-3.8.52-arm64.dmg (Apple Silicon)
From source git clone … && npm ci && npm run build && npm start (Node.js 22 or 24 LTS)

Dashboard at http://localhost:20128, API at http://localhost:20128/v1.

What changed

Loop run stream now streams. GET /api/loop/{id}/stream used to build the whole response and return it at once, so an EventSource reconnected every few seconds. It now sends a snapshot, then a delta only when the run changes, heartbeats every 15 s, closes on a terminal status, caps a connection at 10 minutes, and resumes from Last-Event-ID without replaying events.

MCP approvals are recorded. The review gate stopped trusting a caller's claim of a past approval in v3.8.51, which left every candidate at review_required. Approvals now live in a server-side table (migration 177): an admin approves with POST /api/mcp/review/approve — refused when the gate denies the candidate — and revokes with POST /api/mcp/review/revoke. A stored approval carries over only when permissions are not broadened and the publisher is verified.

Browser allowlist has a settings screen. Settings → Security edits the Browser Use domain allowlist, backed by GET/PUT /api/browser/allowlist. Callers of POST /api/browser/check no longer need to send the domains. Entries are hosts only; schemes, paths, ports, wildcards, IP literals and single-label names are rejected with a reason per entry.

Windows bundle verification fixed. The shared web bundle is packed on Linux, and a symlink target read back on Windows carried a drive prefix, so the integrity check failed on the platform difference. Both sides are normalized; a link that truly points elsewhere still fails.

Installer signing is ready, but not active yet. The release pipeline signs macOS (Developer ID + notarization) and Windows (Authenticode or Azure Trusted Signing) builds as soon as the signing secrets are added to the repository, and keeps producing unsigned builds while they are absent. The secret names are in docs/guides/ELECTRON_GUIDE.md.

Known limitations

  • No Windows installer in this release. The Windows build now gets past bundle verification but stops while compressing the installer: a nested .bin shim inside the bundle is a symlink to an absolute path on the Linux build machine, which does not exist on Windows. The fix ships in the next patch release. Windows users: use Docker or install from source.
  • These installers are still unsigned. Signing needs a certificate issued to the publisher, which the repository does not have yet. Windows SmartScreen shows a warning (More info → Run anyway); macOS Gatekeeper blocks the first launch (right-click → Open). Docker and source installs are unaffected.

Evidence

  • audit/FASE2_REVIEW.md — Fase 2 audit, fix loop and the caveat fixes
  • audit/RELEASE_READINESS.md — gates, published digests, install-path verification

3.8.51

Choose a tag to compare

@github-actions github-actions released this 12 Sep 17:54
1054f19

First tagged release of the LMPrado-DZ23/OmniRoute fork. It closes three blocks of work, each independently audited and fixed at the root cause before merge.

Install

Channel How
Docker docker run -d --name omniroute -p 127.0.0.1:20128:20128 -v omniroute-data:/app/data ghcr.io/lmprado-dz23/omniroute:3.8.51 (also :latest, multi-arch amd64 + arm64)
Linux OmniRoute-3.8.51.AppImage / omniroute-desktop_3.8.51_amd64.deb (x64), and the arm64 variants
macOS OmniRoute-3.8.51.dmg (Intel) and OmniRoute-3.8.51-arm64.dmg (Apple Silicon)
From source git clone … && npm ci && npm run build && npm start (Node.js 22 or 24 LTS)

Dashboard at http://localhost:20128, API at http://localhost:20128/v1.

Known limitations of this release

  • No Windows installer. The Windows leg of the desktop build failed while restoring the shared web bundle: a symlink packed on Linux reads back on Windows with a drive prefix, and the integrity check compared the raw strings. The fix is merged and ships with the next version. Windows users: use Docker or install from source.
  • Installers are not code-signed. macOS Gatekeeper blocks the first launch (right-click → Open, or allow it in System Settings → Privacy & Security); Linux is unaffected. Docker and source installs are unaffected.

What's in it

Audit and hardening of the base. Critical and high findings fixed across SSRF, MCP scopes, Electron IPC, plugins, supply chain (actions pinned to SHAs), database rollback and concurrency. One pre-existing defect found along the way: API keys imported from db.json never authenticated.

Loop Engine and Buzz Hub (both off by default: LOOP_ENGINE_ENABLED, BUZZ_HUB_ENABLED). Report-only agent cycles with a deterministic policy gate, budget and human approval; an agent event bridge over a Nostr relay. The first audit rejected the original: the Nostr identity was stored in plaintext, the relay URL was barely validated, mutating routes had no schema, and approving a step did not re-run the policy gate. All fixed before merge.

Fase 2 modules (all off by default): MCP review gate, Browser Guard, AG-UI event contract, OpenTelemetry-lite tracing, and Brazilian PII recognizers (CEP and PIX random key). An adversarial audit rejected them as they arrived: the browser guard allowed a page-originated click, skipped the domain allowlist when no URL was given, and the MCP gate trusted the caller's claim of a past approval. Each finding was fixed with a regression test that reproduces the audit's input.

Install readiness. Every documented command now resolves against what is actually published, and the image publish job boots the container and requires /healthz before a tag is kept. Images carry org.opencontainers.image.revision, so a pulled digest maps back to a commit. A version tag can no longer try to publish someone else's npm package.

Evidence

  • audit/RELEASE_READINESS.md — gates, published digests, install-path verification
  • audit/LOOP_BUZZ_REVIEW.md — Loop Engine and Buzz Hub audit and fix loop
  • audit/FASE2_REVIEW.md — Fase 2 adversarial audit and fix loop

Radar catalog export (rolling)

Choose a tag to compare

@github-actions github-actions released this 14 Sep 12:47
0f13fe4

Export estável do catálogo OmniRoute para o Radar. Atualizado automaticamente; NÃO é um release de versão do produto.