v1.7.0
Features
- Refresh the frontend design system: reduce to a light/dark theme, modernize page-by-page visuals, add live resource counts to Memory and Integrations nav items. (#37)
- Consolidate sidebar navigation into a 7-persona structure; fold Registry into Catalog, move Costs under Admin Dashboard, move Tagging under Settings, merge MCP Servers and A2A Agents into a single Integrations page. (#20)
- Add Google ADK as an alternate custom-code agent framework alongside Strands. (#18)
- Migrate the AWS Agent Registry integration to the GA namespace and schema. (#22)
- Smooth transient FAILED invocation status and drain CI EventStream responses.
Security
- Require a deployment-trusted issuer host before any OAuth2 token exchange (client-credentials or on-behalf-of) sends a client secret or user access token, closing the residual SSRF/token-disclosure gap left after the connection-sink SSRF guards. Extended the same IP-validated, DNS-pinned fetcher to every other outbound OAuth2/OIDC call in the backend (OIDC discovery, JWKS, generic OAuth2, per-user authorizer linking, Cognito, and the login-callback token exchange). (#49)
- Guard MCP/A2A connection sinks against SSRF via redirect and response-body echo. (#32)
- Stop logging workload token prefixes.
Stats
123 files changed, 12,227 insertions(+), 6,136 deletions(-) since v1.6.1.