Skip to content

v1.0.2.4 — Infrastructure & Security Hardening

Choose a tag to compare

@MichelKerkmeester MichelKerkmeester released this 01 Jan 16:56
· 10315 commits to main since this release

Major Infrastructure Release - Critical bug fixes, security hardening, tool connection layer install automation, and comprehensive codebase standardization across 70+ files. This release focuses on making the environment easier to use and easier to trust.

 

Security

  • Need: This part of the release improves how the environment saves, finds, and uses context.
  • What changed: CWE-22: Path traversal protection in command-line interface CONFIG.DATA_FILE and DB-stored paths. CWE-400: Input length limits for tool connection layer tool parameters (query 10K, title 500, paths 500 chars). Severity Reduction: MEDIUM severity issues reduced from 4 to 1.
  • Why it matters: That matters because saved context is easier to find, easier to trust, and less likely to get in the way.

 

Fixed - Critical Issues

  • Need: This part of the release improves how the environment saves, finds, and uses context.
  • What changed: SQLite Transaction Nesting: Error in memory_index_scan - indexMemory() now uses composable database.transaction() wrapper. Race Condition: Database changes weren't visible across tool connection layer/script connections - added file-based notification with reinitializeDatabase(). Orphaned Metadata: Failed vector insertions leaving orphaned metadata - explicit transaction control with rollback.
  • Why it matters: That matters because saved context is easier to find, easier to trust, and less likely to get in the way.

 

Fixed - High Priority Issues

  • Need: This part of the release improves how the environment saves, finds, and uses context.
  • What changed: Wrong Dimensions: Schema created with wrong embedding dimensions before provider warmup - getConfirmedEmbeddingDimension() with polling. Cache Invalidation: Constitutional cache didn't invalidate on external database edits - mtime tracking added. Rate Limiting: State lost on server restart - persistent config table in SQLite.
  • Why it matters: That matters because saved context is easier to find, easier to trust, and less likely to get in the way.

 

New Features

  • Need: This part of the release introduces the main capabilities added in this version.
  • What changed: Tool Connection Layer Install Scripts Suite: Shell-based installers for all 6 tool connection layer servers with shared utilities library (33 functions). Sub-agent Delegation: /spec_kit:handover and /memory:save now delegate heavy work to sub-agents for token efficiency. Session Behavior Modes: -brief, --verbose, --debug flags for controlling response verbosity.
  • Why it matters: That matters because the environment can do more useful work without extra setup.

 

Changed

  • Need: This part of the release improves how the environment saves, finds, and uses context.
  • What changed: References Reorganized: 18 files moved from flat structure into 7 logical sub-folders (config/, debugging/, memory/, structure/, templates/, validation/, workflows/). 79 Internal Links Fixed across reference documentation. Lib Consolidation: Shared modules centralized in lib/ folder with re-export wrappers.
  • Why it matters: That matters because saved context is easier to find, easier to trust, and less likely to get in the way.

Full changelog: .opencode/changelog/