You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
This commit was created on GitHub.com and signed with GitHub’s verified signature.
Fixed
Recognize the supported host security wrapper in both MCP configuration formats without changing or removing the wrapper. Verify that it references the expected configuration and server, and retain checks on the original launch command, arguments and environment.
Protect native plugin configuration and integrity metadata from export overwrites, including paths through symbolic links and missing destination children.
Enforce the workspace boundary when reading the implicit synchronization log through MCP tools.
Return HTTP 400 for malformed preview request URLs instead of terminating the local server.
Make workspace configuration cleanup remove only temporary files created by the current save operation.
Redact known environment credential values from managed-runner results, stored traces and progress callbacks while preserving operational adapter/verifier inputs.
Verification scope
Added focused regressions for these defects and checked provider redirects, origin validation, request/response limits and cancellation. See the security review for boundaries and remaining limits.
GitHub release only; no npm publication. Previously published release tags are unchanged.