Skip to content

v0.32.0

Choose a tag to compare

@julesklord julesklord released this 12 Jul 08:42
· 21 commits to main since this release

v0.32.0 — 2026-07-12

Security (CRITICAL)

  • Sandbox Validation: Added command validation against dangerous shell patterns (command substitution, /etc redirects, mkfs, dd) while preserving normal shell features.
  • Subprocess Safety: Routed 12+ direct subprocess.run calls through core/subprocess_safety.py with command whitelisting in git_logic, system_tools, model_discovery, paths, and ui_utils.
  • CLI Provider: Replaced 6 bare excepts with specific exception types (ValueError, JSONDecodeError) for proper error tracking.
  • SECURITY.md: Customized with real project versions (0.31.x, 0.30.x) and vulnerability reporting guidelines.

Code Quality (HIGH)

  • repl_tool.py: Eliminated self.__init__() anti-pattern → clean _restart() method with extracted _start_process().
  • Type Annotations: Typed CLIProvider.config as SettingsProvider instead of Any; removed dead ui_adapter parameter from ChatAgent.
  • Dead Code Removal: Removed dead load_api_key from GemStyleRenderer, inline class-body imports (logging/os/Any), and no-op if/pass block in compression.py.

Features

  • Rate Limit Headers: Added parse_rate_limit_headers() utility to parse Retry-After, X-RateLimit-Remaining, and X-RateLimit-Reset from API responses.