aflare v0.8.0
Changelog
- 871df03: !1 merge chore/yagni-cleanup-dead-nodes into main ( <>)
- 4713afc: Merge pull request #60 from alib8b8/feat/onboarding-breakpoints-4-10 (@alib8b8)
- f86870c: Merge pull request #61 from alib8b8/feat/stage5-breakpoints-11-13 (@alib8b8)
- 727ffe2: Merge pull request #62 from alib8b8/feat/stage6-7-breakpoints-14-17 (@alib8b8)
- aa23bcf: Merge pull request #63 from alib8b8/feat/stage6-7-breakpoints-14-17 (@alib8b8)
- 7d0c9ea: Merge pull request #64 from alib8b8/chore/yagni-cleanup-dead-nodes (@alib8b8)
- ea711bc: Merge pull request #66 from alib8b8/docs/readme-local-first-sync (@alib8b8)
- 86ee88f: Merge pull request #68 from alib8b8/ci/enforce-pr-squash-merge (@alib8b8)
- ef22a59: Merge pull request #69 from alib8b8/feat/register-builtin-nodes (@alib8b8)
- e207519: Merge remote-tracking branch 'gitcode/main' (@Fancyhe1)
- 0d42514: ci(enforce-pr): allow squash/rebase merges via PR-link API check (@Fancyhe1)
- 50609c6: ci: benchmark 改为只在 release tag / 手动触发时跑 (@alib8b8)
- ce789d1: docs(openclaw): fix tool name inconsistency and add v0.8 migration note (@Fancyhe1)
- 4e86ce2: docs(readme,release): surface one-line install and document Windows + verification status (@Fancyhe1)
- 4b210c7: docs(ux): zero-config onboarding (#67) (@alib8b8)
- d6930f9: feat(cli): onboarding flow for breakpoints 4-10 (@Fancyhe1)
- 90d0e3d: feat(cli): runtime UX improvements for breakpoints 11-13 (@Fancyhe1)
- 3bc6934: feat(cli): template run + unknown-command hints + bare-binary template release (@alib8b8)
- d34ed27: feat(cli,agent): agent presets, onboarding, doctor and upgrade for breakpoints 14-17 (@Fancyhe1)
- cbc4a46: feat(cli,workflow,agent): onboarding + LLM config unification for breakpoints A-F (@Fancyhe1)
- e3d5552: feat(llm): smooth local/offline LLM onboarding (Ollama, vLLM, LM Studio) (@alib8b8)
- 4d20e8d: feat(nodes): register 14 previously-orphan builtin nodes (@alib8b8)
- 212acc7: feat(offline): first-class air-gapped/intranet install & diagnostics (@alib8b8)
- 3bdea3d: feat(security): harden privacy for local/air-gapped deployments (@alib8b8)
- 0f10a3c: feat(security): local-first defaults for data-sensitive / intranet users (@Fancyhe1)
- 8c723bf: feat(workflow,cli): numeric conditions, schedule field, price/condition/schedule keywords (@Fancyhe1)
- 52dec7a: feat: 3 个端到端 Killer Demo 示例 — 让用户一看就想用 (@Fancyhe1)
- 5619c39: feat: 4 experience-layer improvements (streaming, tool visibility, ollama guide, multiline) (@Fancyhe1)
- 1df846e: feat: AI晚报借鉴落地 — sandbox节点 + 信创MCP市场 + 24技能 + Agent编排 (@Fancyhe1)
- 5cae9a1: feat: Agent Plugins 1.0.0 compatibility, Harness concept, and JiuwenSwarm benchmarking (@Fancyhe1)
- 205a5db: feat: Claude-style invisible watermark — distributed embedding, whitespace encoding, redundant recovery (@Fancyhe1)
- b535d96: feat: JiuwenSwarm集群值守 + Avernet多工作流协作 (@Fancyhe1)
- 59719a5: feat: Sprint 2 core features + self-inspection bug fixes (@Fancyhe1)
- bb6de8b: feat: add SSE streaming endpoint for webui chat (@Fancyhe1)
- 69dbcd4: feat: add
aflare chatinteractive agent command (@Fancyhe1) - b172d91: feat: agent self-evolution — skill persistence, self-update, cross-session learning (@Fancyhe1)
- 78cb89b: feat: bridge 323 templates as agent skills via chat_nodes (@Fancyhe1)
- 9866489: feat: fuse chat + daemon into unified AgentLoop (@Fancyhe1)
- 3276d49: feat: integrate Sprig template functions to support all template filters (@Fancyhe1)
- 2f52048: feat: invisible watermarking for content provenance (@Fancyhe1)
- ea9ea95: feat: pack install tracking + plugin platform docs (@Fancyhe1)
- f84925e: feat: pluggable AgentCapability system — 10-type Agent taxonomy integration (@Fancyhe1)
- 75e4a24: feat: promote 5 capability stubs to full implementations + learning system enhancements (@Fancyhe1)
- 7cd8dc4: feat: rename llm-box to aflare, add source watermark, and contributor badge system (@Fancyhe1)
- a65eea1: feat: wire ReActAgent into serve/webui/create modes (@Fancyhe1)
- d025978: feat: workflow review, sandbox session persistence, and habit-tracker (@Fancyhe1)
- 92471e6: feat: 优雅关闭、背压池、ADR、SBOM,以及前序会话的 OTel/错误分类法 (@Fancyhe1)
- b0db3e5: feat: 新增 3 个 fuzz 测试覆盖关键入口 (@Fancyhe1)
- c7a6bfd: feat: 检查工作完成情况 (@alib8b8)
- b5e4c30: feat: 模板库扩充至每个分类 ≥20 个,共计 182 个模板 (@Fancyhe1)
- 15eba28: feat: 添加 MAVLink 无人机控制节点 (drone) (@Fancyhe1)
- 7333828: fix(agent): close learning-store path race between loadEntries and append (@Fancyhe1)
- ec857d7: fix(agent): resolve ineffassign lint in bdi test (@Fancyhe1)
- bf006c4: fix(autoupgrade): default AutoUpdateEnabled to false for local-first users (#65) (@alib8b8)
- 890e14c: fix(ci): enforce-pr gate false-rejects squash merges + bypass via fake PR ref (#71) (@alib8b8)
- 140075d: fix(ci): lower nodes coverage gate to 50%, skip enforce-pr on merge commits (@Fancyhe1)
- 5e9381a: fix(ci): make [skip-pr-gate] override actually work (@Fancyhe1)
- 338d365: fix(cli): address first-run experience and install/update issues (@Fancyhe1)
- 841183e: fix(release): Homebrew formula 更新步骤改为非阻塞 (@alib8b8)
- a390e99: fix(release): SLSA hash 步骤改用 find 仅哈希文件 (@alib8b8)
- 50988e1: fix(release): 移除 go mod tidy hook, 修复 GoReleaser dirty-state 失败 (@alib8b8)
- 5c96c30: fix(test): remove unused setupSecretsStore helper (golangci-lint unused) (@Fancyhe1)
- 1c7eb60: fix: --safe-mode 接入 PolicyExecutor,safeMode 贯穿调用链 (@Fancyhe1)
- bf7f7e5: fix: 5 security & reliability bugs in chat agent (@Fancyhe1)
- fb0ab9d: fix: API 服务器默认安全加固 — 默认绑定 127.0.0.1 + 无认证限 localhost (@Fancyhe1)
- 557ce8e: fix: AdaptiveCapability PreProcess threshold mismatch — changed <= 5 to <= 10 to match Init load count (@Fancyhe1)
- fc298b4: fix: CLI run 路径集成 PolicyExecutor 策略校验 (@Fancyhe1)
- e289949: fix: CORS 从 Allow-Origin: * 改为只允许 localhost 来源 (@Fancyhe1)
- 21df6e7: fix: MCP client 响应体无大小限制 — 加 LimitReader 防 OOM (@Fancyhe1)
- a285416: fix: MCP validateToken 时序攻击 — 用 subtle.ConstantTimeCompare 替代 == (@Fancyhe1)
- 57a672b: fix: PauseWorkflow 中 WAL 和工作流文件拷贝改为原子写 (@Fancyhe1)
- 7992a3b: fix: TestRunWorkflow_Success — 命令含 shell 元字符被 allowlist 拦截 (@Fancyhe1)
- 7407bd4: fix: add nolint:funlen to getExtendedTools (526 lines) (@Fancyhe1)
- c6a048f: fix: checksum 校验从 best-effort 改为强制 fail-closed (@Fancyhe1)
- b209297: fix: correct GitCode mirror URL (aflare/aflare → llm-box/llm-box) (#70) (@alib8b8)
- 6ff020d: fix: correct {{ else } typo in legal templates + remove toJson from join nodes (@Fancyhe1)
- a6a068a: fix: create_workflow path traversal via LLM-controlled skill name (@Fancyhe1)
- bd1bf4e: fix: data race in pipeline.go completed map access (@Fancyhe1)
- 710a9d5: fix: disable goconst linter — too noisy for generic strings (@Fancyhe1)
- 5a5e155: fix: disable gocritic linter — 10 violations across codebase (@Fancyhe1)
- eb1a531: fix: drone 节点接入项目全局 SSRF 防护 (@Fancyhe1)
- d7a5e64: fix: drone_bridge 默认绑 127.0.0.1,加 token 认证 (@Fancyhe1)
- 5f0050b: fix: eliminate command injection via {{ .params }} in execute nodes (@Fancyhe1)
- 275a959: fix: gofmt all files to pass Auto Fix workflow (@Fancyhe1)
- 49fd528: fix: gofmt formatting for policy/marketplace/executor files (@Fancyhe1)
- 19e0cfd: fix: gofmt formatting in health.go struct field alignment (@Fancyhe1)
- 8fb63c6: fix: gofmt formatting in marketplace.go string concatenation (@Fancyhe1)
- 836e6b1: fix: gofmt resume.go after best-effort comment edits (@Fancyhe1)
- 1034df0: fix: gofmt 格式化 25 个文件,修复 CI gofmt 检查失败 (@Fancyhe1)
- 9759e62: fix: handle discarded errors and track nolint debt with real issues (@Fancyhe1)
- 329e1e6: fix: isLocalhost IPv6 解析错误 — 用 net.SplitHostPort 替代手动字符串切割 (@Fancyhe1)
- e4460db: fix: ollama streaming and multi-line input UX (@Fancyhe1)
- 1dbb67b: fix: ollama true streaming with character-level ReAct JSON filter (@Fancyhe1)
- aee4757: fix: ollamaStreamFilter bugs + CallWithToolsStream content loss + tests (@Fancyhe1)
- 0013472: fix: policy YAML structure, add InstallTo method, and test coverage (@Fancyhe1)
- 8557056: fix: relax funlen to 250/120 + nolint 2 largest functions (@Fancyhe1)
- f6fb4a7: fix: remove duplicate golangci-lint from auto-fix.yml (@Fancyhe1)
- 9549d10: fix: remove duplicate id fields in 3 ascend templates (13 depends_on chain breaks) (@Fancyhe1)
- 7e7fbc1: fix: remove python3 -c embedded in YAML execute nodes (@Fancyhe1)
- b2c26f4: fix: remove stale "Small change for PR" comment in version.go (@Fancyhe1)
- 77784c1: fix: rename top-level params: to input_schema: in 126 templates (@Fancyhe1)
- 95ec03e: fix: replace Sprig filters and fix YAML quoting in 20 legal templates (@Fancyhe1)
- 6cb53c9: fix: replace config: with params: in 495 steps across 101 templates (@Fancyhe1)
- 188dc39: fix: replace execute nodes with code_interpreter in github-report to prevent command injection (@Fancyhe1)
- 3466c43: fix: replace toJSON with toJson across all templates (128 occurrences) (@Fancyhe1)
- 50160a0: fix: replace type: with node: in 106 steps across 21 templates (@Fancyhe1)
- b8a61f3: fix: replace unknown node types (ollama, verify, rag, xml_parse, ascend_model_*) with supported aflare nodes (@Fancyhe1)
- ef8b506: fix: replace unsupported Liquid/Sprig template filters with code_interpreter nodes (@Fancyhe1)
- 1aa24f7: fix: resolve 2444 golangci-lint issues to unblock CI (@Fancyhe1)
- 6505cbd: fix: resolve CI lint and format failures on main (@Fancyhe1)
- 54cfe95: fix: resolve all golangci-lint funlen + errorlint issues to unblock CI (@Fancyhe1)
- 9d2accb: fix: resolve errorlint and goconst CI failures (@Fancyhe1)
- 64a308a: fix: resolve lint errors — errorlint, unused vars, gofmt (@Fancyhe1)
- d7d8a95: fix: resolve remaining 10 funlen issues to unblock CI (round 2) (@Fancyhe1)
- ee17d2e: fix: restore golangci-lint thresholds, split giant function, fix trailing newlines (@Fancyhe1)
- 83c24e3: fix: rewrite multi-role-agent from n8n nodes/edges schema to aflare steps format (@Fancyhe1)
- a0fdf42: fix: sandbox security — path traversal protection and crypto-safe random (@Fancyhe1)
- 1a174e8: fix: security hardening — path traversal, shell injection, and timeout fixes (@Fancyhe1)
- d8a0e35: fix: security-scan only creates issue on actual failure (@Fancyhe1)
- 9997b14: fix: self-audit — 6 capability bugs found and fixed (@Fancyhe1)
- a727c9d: fix: self_update node bypasses safe mode — disable binary replacement when safe mode is on (@Fancyhe1)
- 1f10e8c: fix: self_update tool unreachable + learning.json write-only (@Fancyhe1)
- cce05d4: fix: serve/webui --capabilities support + unify MemoryNode/MemoryCapability storage (@Fancyhe1)
- 5990c04: fix: session persistence, context window indicator, and export (@Fancyhe1)
- 55811cb: fix: skip duplicate 'input' param in buildToolDefinitions schema (@Fancyhe1)
- d3b618d: fix: source watermark CLI handlers, error handling gaps, and openclaw naming note (@Fancyhe1)
- 1d2356c: fix: suppress ollama JSON ReAct noise from streaming output (@Fancyhe1)
- f71ff29: fix: suppress staticcheck SA5011 false positive in badge.go (@Fancyhe1)
- 8da4ec6: fix: sync go.sum with go mod tidy (@Fancyhe1)
- 5caf4b2: fix: taskqueue comment, metrics timeout, plugins platform check, CHANGELOG (@Fancyhe1)
- 90d5978: fix: tool call accumulation in CallWithToolsStream — update ID/Name on subsequent chunks (@Fancyhe1)
- ff11fef: fix: tool param passing — LLM args now reach nodes correctly (@Fancyhe1)
- da5f29f: fix: update skills-registry and fix email-digest smtp:// error (@Fancyhe1)
- 61677fc: fix: 修复 10 个 golangci-lint 错误 — 彻底清除红叉 (@Fancyhe1)
- ef3fcbd: fix: 修复 CI staticcheck 告警,恢复 main 绿勾 (@Fancyhe1)
- 93ce1df: fix: 修复 CI 红叉 — gofmt 格式化 + supply-chain govulncheck 容错 (@Fancyhe1)
- b886921: fix: 修复 CI 红叉 — 编译错误 + vet 错误 (@Fancyhe1)
- b90d176: fix: 修复 drone-patrol workflow loop 条件不生效问题 (@Fancyhe1)
- 1f2a758: fix: 安全审计 — 修复 4 个路径遍历 / 命令注入漏洞 (@Fancyhe1)
- e645e32: fix: 安全审计修复 — 3 项漏洞修复 (@Fancyhe1)
- 805d919: fix: 强化 MCP server 路径校验,防止路径遍历攻击 (@Fancyhe1)
- 26ea07f: fix: 强化 code_interpreter 沙箱降级和 sandbox blocked patterns (@Fancyhe1)
- cee6dbb: fix: 源码审查 — 3 项安全加固改进 (@Fancyhe1)
- e939429: fix: 自检修复 — 编译错误、安全限制未生效、竞态条件 (@Fancyhe1)
- b477d38: refactor(openclaw)!: rename plugin id/package/config from llmbox to aflare (@Fancyhe1)
- 1625cef: refactor: improve error handling in sandbox and review commands (@Fancyhe1)
- a812d70: refactor: redesign chat system — CLI-driven, Ctrl-C safe, char-level context (@Fancyhe1)
- 445c063: refactor: 定位收敛 + Policy Engine + Killer Demo + Marketplace (@Fancyhe1)
- b2b3576: release: v0.8.0 (@alib8b8)
- a57303a: retrigger CI (@Fancyhe1)
- 3714124: style(nodes,agent): annotate best-effort os.Remove and log dropped quota ops (@Fancyhe1)
- 00e0725: style: gofmt create/init_wizard after CI format gate failure (@Fancyhe1)
- deae841: style: gofmt generator.go var block alignment (@Fancyhe1)
- 2e7e1ce: test(agent)+ci: add per-package coverage gates and raise agent coverage to 60% (@Fancyhe1)
- 99208b2: test(meta): replace flaky proxy-based version tests with mock transport (@Fancyhe1)
- 06e9e2f: test(webui): fix flaky TestMetricsRateLimiter_Concurrent on arm64 (@Fancyhe1)
- 83ec98c: trigger CI for d7d8a95 (@Fancyhe1)
Install
macOS / Linux:
curl -fsSL https://raw.githubusercontent.com/alib8b8/aflare/main/install.sh | bashWindows (PowerShell):
irm https://raw.githubusercontent.com/alib8b8/aflare/main/install.ps1 | iexHomebrew: brew install alib8b8/tap/aflare
Build verification status
| Artifact | CI verified |
|---|---|
linux-amd64 |
✅ tested on ubuntu-latest (build + vet + race tests + lint) |
linux-arm64 |
✅ tested on ubuntu-24.04-arm (build + vet + race tests + lint) |
darwin-amd64 |
|
darwin-arm64 |
|
windows-amd64 |
|
windows-arm64 |
Verification status reflects the CI matrix in
.github/workflows/ci.ymlat release time.