Skip to content

v0.0.20

Choose a tag to compare

@aviggiano aviggiano released this 19 Aug 13:43
176d204

v0.0.20 hardens Ultrafuzz's execution and artifact boundaries, improves OpenRouter reliability, binds worktrees to immutable launch revisions, and formalizes MIT licensing across the workspace.

  • Safer security boundaries. Canonical artifacts now fail closed on detected secrets, while cloud execution, provider environments, archive handling, and governance controls receive defense-in-depth hardening.
  • More reliable runs. OpenRouter sessions recover from rate limits without duplicating work, and worktrees stay bound to the exact revision that launched a run.
  • Clearer project defaults. The workspace now carries MIT license metadata, a one-hour default agent timeout, and aligned operational documentation.

New features

  • [artifacts] [security] Adds a fail-closed publication gate for secret-bearing canonical artifacts, expands credential detection, and makes Kimi credential handling safer. Thanks @aviggiano! (#622)
  • [docs] [security] Adds the MIT license, package license metadata across the workspace, licensing documentation, and CI policy checks for release readiness. Thanks @aviggiano! (#657)

Improvements

  • [runtime] [security] Hardens governance, cloud execution, provider environment isolation, and runtime-integrity boundaries across high-priority AppSec controls. Thanks @aviggiano! (#635)
  • [evals] [security] Bounds evaluation matrices and concurrency, secures remote pricing retrieval against private-address and redirect abuse, and aligns the documented ceilings with the enforced 32-target and 80-row limits. Thanks @aviggiano! (#640, #643)
  • [runtime] [modal] Seals governance data used for cloud handoff, strengthens secret isolation, and makes security classification changes fail closed. Thanks @aviggiano! (#644)
  • [config] [runtime] Raises the default local and cloud agent timeout from 30 minutes to one hour and documents configuration precedence. Thanks @aviggiano! (#646)
  • [runtime] [artifacts] Captures the exact launch revision and binds local, retry, cloud, and workflow worktrees to that immutable source commit. Thanks @aviggiano! (#655)
  • [docs] Simplifies the README landing page while retaining the dedicated licensing and security policy documentation. Thanks @aviggiano! (#666)
  • [workflows] [runtime] Tiers CI by event so pull requests use a curated runtime smoke suite while pushes to main and manual runs retain the full release-validation matrix. Thanks @aviggiano! (#669)

Bug fixes

  • [runtime] [openrouter] Recovers safely from initial and mid-run OpenRouter rate limits, resumes the exact session after substantive work, and prevents duplicate or conflicting replay output. Thanks @aviggiano! (#611, #626, #631)
  • [cli] [security] Upgrades and hardens benchmark ZIP parsing with bounded archive handling and production dependency-advisory gates. Thanks @aviggiano! (#623)
  • [runtime] Declares the generated plain-record validator required by invariant recovery paths and removes the test-only fallback that masked its absence. Thanks @aviggiano! (#668)

Full changelog: v0.0.19...v0.0.20