v0.5.0
What's Changed
Features
- Security: Add SARIF output,
PatternDefinitionmetadata, and CI self-audit gate (#1163) - Security: Add transport-agnostic prompt injection defence (#1162)
Performance
- Core: Replace blocking fs I/O in cache, split config module, add TTL eviction (#1172)
Fixes
- Security: Harden
action.ymlsecret handling and add HTTP timeout (#1171) - CLI: CLI consistency sweep (#1170)
- MCP: Use configured AI provider in health check; remove phantom CLI subcommands from docs (#1169)
- CI: Use GET-first to create or move floating minor release tag (#1151)
Docs
- Security: Document
scan-securityCLI,[prompt]limits, and SARIF workflow (#1164) - Agents: Update AGENTS.md for security features (#1165)
Chores
- Rename
code-analyze-coretoaptu-coder-core0.7.0 (#1157) - Update dependencies (#1173, #1155, #1154, #1153, #1152)
Full changelog: v0.4.2...v0.5.0