Skip to content

Agent Plugin Forge 1.0.1

Latest

Choose a tag to compare

@MiguelElGallo MiguelElGallo released this 12 Sep 08:27
eba8fc3

Agent Plugin Forge 1.0.1

Two low-severity security fixes:

  • Consistent import approvals (#14): capture safety-checked file bytes and executable modes together, bind the exact file map into the approval hash, and copy/hash those captured bytes. License hashing uses inspected bytes. The issue required concurrent local source changes; this is not a repository-wide concurrency lock.
  • Safe terminal diagnostics (#15): visibly escape terminal controls and undecodable POSIX filename bytes in human-readable output. Ordinary Unicode paths, file contents, and decoded JSON values are preserved. The issue concerned misleading display, not code execution.

Upgrade

Refresh the marketplace and update the Forge plugin, or install the attached Python wheel for the CLI. Verify forge --version reports 1.0.1.

Generate, review, and approve fresh import plans after upgrading. The approval hash now includes the exact source file map, so hashes saved by earlier versions intentionally do not match. Do not replace an approved hash without review.

Verification

Independent patch review completed; its POSIX surrogateescape finding was fixed and regression-tested. On macOS, Python 3.11.16 and 3.12.13 each passed 386 tests with two platform-specific skips and 92% coverage. Ruff, ty, actionlint, Forge validation, strict docs, and isolated wheel checks passed. The packaged skill instructions and bootstrap helper are unchanged from 1.0.0.

All five PR CI jobs passed, including native Windows (368 passed, 20 platform-specific skips, 91% coverage). A Windows metadata incompatibility found during qualification was corrected and independently reviewed before the green run.

PR #16 merged the exact reviewed head with required checks green. The release tree is eba8fc362ccd1b2feef0d6ed5934b5f811f67587. A fresh public Copilot CLI installation enabled plugin 1.0.1 and matched all nine packaged files from that revision. The documentation deployed from the merged commit. These checks qualify installation and CLI behavior; no new VS Code/Codex runtime or full agent publication invocation is claimed.

The attached wheel and source archive are built from the merged release tree and the wheel passed isolated version, branch-name, and repository-validation checks. SHA256SUMS identifies their exact bytes. This release is published to GitHub, not PyPI.