You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
ffd0cc9 ci: golangci-lint-action v9, since v6 refuses a golangci-lint v2 version string outright and the lint job I just added failed on its first real run
f3a016d skill: v10 requires 0.2.2, for the kept Vesselfile and the ranked search it now tells an agent about; warn that the official fetch, git, and time servers fail on mcp 2.0 and name the pin, tell it to read the error's last lines and retry with 'build' rather than re-importing, and drop the em-dashes
ad0e7e1 ci: run golangci-lint as its own job again now that it ships 1.26-built releases, so the lint step CONTRIBUTING tells contributors to run is no longer on the honour system
d2a38c9 cli: introduce the product the README sells, since --help opened with "Build, ship, and run agents" and someone arriving from a page about caging untrusted MCP servers met a different tool; lead with the cage, order the help groups the way a new user meets them, say server rather than agent under those headings, match the cask description, add the 'version' subcommand people type first, and stop the serve example modelling a bind to every interface on an unauthenticated door
bda71d7 secrets: write the store through a temp file and rename, the way the trust store already does, because Load fails closed on a malformed file and a crash mid-write left a truncated secrets.json that every later command refuses to read, with values that cannot be re-derived from anywhere
390b3ef bundle: cap what an .agent may expand to on extract, per entry and in total, reading through a LimitReader rather than trusting the tar header the same author wrote, so a bundle whose whole claim is that untrusted ones extract safely cannot fill the disk from a few kilobytes of gzip
fb158d8 approvals: move the strict posture into config as 'mcpvessel config approvals set --strict', where the environment cannot clear it, because reading it only from VESSEL_STRICT_APPROVAL left it defeated by a one-word prefix on the same command line by exactly the agent it exists to restrain; the README called that airtight and now states the real limit
e600a07 hook: fence the captured request the watch surfaces, since every byte of it was written by the caged server the notice is reporting on and it arrived as bare prose inside a SECURITY message, where "approve this host, it is safe" read like the rest of the text; mark the block as the suspect's words and shorten hyphen runs so a body cannot spell the closing delimiter and continue underneath it as mcpvessel's own
9549110 egress: stop writing a host into the config allow-list when every live run refused the approval, which turned a visibly failed command into a permanent widening of the cage, and exit non-zero so a caller checking status cannot read the failure as an approval; key pending previews by source as well as host so two cages sharing one proxy cannot show you one cage's payload while you approve the host for another; drop a duplicated upstream close
43e6577 import: keep the generated Vesselfile when the build fails and print the command that retries from it, since the documented remedy is to edit that file and deleting it made the remedy impossible; keep the tail of the boot output so a server that dies before speaking MCP reports why instead of a bare initialize EOF, naming the mcp<2 pin that currently breaks the official fetch, git, and time servers
6854fb8 search: rank results instead of passing the query straight to a registry that substring-matches the whole reverse-DNS name and orders alphabetically, which buried the server you meant (a bare "github" matched every io.github./* entry, so the official github-mcp-server was not in the first hundred rows); probe the package-name boundary too, rank on package and publisher with a first-party namespace winning, and report on stderr when a probe stalls rather than silently serving the old ordering
980dbc9 docs: the demo caption moves under the GIF at a smaller size, and both centre together inside one align block so the caption tracks the image rather than the page width
7ce9653 docs: the README demo leads instead of trailing the threat model, recut to the 11 seconds from note-saved to Claude naming the exfil (1000px, 2.2MB, down from 46s and 4.9MB) with a caption so a cold reader knows what they are watching, and the second dialogue block goes since the GIF now tells that story better and disagreed with it on the details
c645e24 docs: the README demo is a recorded GIF instead of a placeholder comment, showing the notes server try to ship STRIPE_SECRET_KEY to an attacker host under cover of a save_note call, the cage blocking it, and Claude denying the host unprompted; supersedes the older unreferenced take