Releases: agentinsync/agent-in-sync
Releases · agentinsync/agent-in-sync
Release list
v0.3.3
v0.3.2: feat(frontend): add GitHub repo link to marketing navbar and footer (#9)
Surface the open-source repo (github.com/agentinsync/agent-in-sync) on the marketing pages: a GitHub icon link in the desktop navbar, an entry in the mobile menu, an "Open Source" item in the footer Product column, and the footer social icon now points at the repo (was the org-level URL). Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
v0.3.1: fix(frontend): declare APP_VERSION in turbo build env (#8)
* feat(frontend): bake release tag into sidebar version Wire the release workflow's git tag through a Docker build-arg (APP_VERSION) into Vite's __APP_VERSION__ define, so the sidebar in the production image reflects the tag that built it instead of a hand-bumped root package.json. Local pnpm dev still falls back to package.json — no process change for dev. * fix(frontend): declare APP_VERSION in turbo build env Turbo runs each task in a sanitized child environment and hides any env var not declared in turbo.json. After v0.3.0, the release image still rendered "v0.1.0" in the sidebar because the Docker build did set APP_VERSION=v0.3.0 in the RUN env, but Turbo stripped it before launching Vite — so process.env.APP_VERSION was undefined and the config fell back to root package.json (0.1.0). Declaring "env": ["APP_VERSION"] on the build task both exposes the var to Vite and (correctly) makes Turbo treat changes to it as a cache-bust.
v0.3.0: feat(frontend): bake release tag into sidebar version (#7)
Wire the release workflow's git tag through a Docker build-arg (APP_VERSION) into Vite's __APP_VERSION__ define, so the sidebar in the production image reflects the tag that built it instead of a hand-bumped root package.json. Local pnpm dev still falls back to package.json — no process change for dev.
v0.2.0: fix(security): close auth & PII findings from security review (#6)
* fix(security): close auth & PII findings from security review
- auth: mark Better Auth `domainId`/`isSuperAdmin` additionalFields as
`input: false`. Without this, any authenticated user could POST
`{ isSuperAdmin: true }` to `/api/auth/update-user` and self-promote
to super-admin, bypassing every org/role/ownership check.
- middleware: API-key requests can no longer be redirected to a
different organization via `:orgId` / `x-organization-id`.
Mismatched header returns 403 instead of silently rewriting the
bound org. Session-based auth behavior is unchanged.
- search: drop `users.email` from `getIssueDetail`'s issue / solution /
comment selects and response shape. Previously any authenticated
user could enumerate Public-org issue UUIDs and harvest author
emails. Also drops `email` from the shared `authorSchema` so types
stay consistent.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* fix(mcp-server): drop email from IssueDetail type after backend change
CI build failed because mcp-server's local IssueDetail type still
required `author.email`, which the backend service no longer returns.
The formatter never rendered email anyway, so drop it from the type
and update the test fixtures.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>