Skip to content

v3.46.0 — 29 reviewed fixes, and the standalone packages that were silently skipping them

Choose a tag to compare

@ruvnet ruvnet released this 26 Sep 22:39
· 120 commits to main since this release
39ea61f

What changed

29 reviewed PRs landed together, plus the memory fix that #3352 needed. Every diff was read by a security reviewer first; the combined tree was built and tested before it merged.

Fixes that were silently not working

  • Daemon YAML config was ignored under ESM (#3420); a stale daemon state could end a fresh session (#3421).
  • Workflow steps with hyphenated names never interpolated (#3422).
  • MCP policy enforcement (RUFLO_MCP_ENFORCE_POLICY) was skipped by the shipped stdio launchers (#3423).
  • A late HTTP timeout could double-write a response (#3426).
  • memory_retrieve served stale values when two servers shared a store (#3361); mcp start on stdio no longer SIGKILLs a sibling server (#3365); a dead process no longer holds state.lock for 30 s (#3363).
  • --no-codex-detect was never honoured (#3434); agent instructions were ignored at execution (#3429); browser errors now surface the real detail (#3430).
  • EWCConsolidator EMA direction was inverted (#3395); MoE load-balance loss was computed but never applied (#3330); swarm leader edges were never mirrored (#3357).

Security

  • Namespace/key collisions in the memory upsert no longer delete distinct entries (#3352 + #3359).
  • validateEnv() denylist gains the PATH / search-path family (#3385).
  • Background git calls neutralise repo-local core.fsmonitor (#3382, partial: see below).
  • github-safe.js regression gate covers all three shipped helper copies (#3412).
  • Plugin scripts stop running npx at tool-call time (#3367).

New

  • witness verify --strict (#3424), --request-timeout-ms for the HTTP MCP transport (#3426), a doctor check for agent-browser (#3441), native AgentDB integrity check in doctor (#3431), Simplified Chinese README (#3316).

Upgrade notes

  • embeddings init and models --download now exit 1 when @claude-flow/embeddings is not installed (#3379). Scripts that ran them bare will start failing.
  • sonaTracksGlobal in unified stats changes from boolean to null (#3439).
  • MoE load-balance loss is now on by default for existing persisted models (#3330).
  • globalFisher now moves about 100x slower per update after the EMA direction fix (#3395).
  • Three packages resolve from the registry rather than the release tarballs, and were published standalone first: @claude-flow/memory 3.0.0-alpha.26, @claude-flow/neural 3.0.0-alpha.10, @claude-flow/cli-core 3.7.0-alpha.6. The CLI pins all three exactly.

Known gaps

  • #3382 only neutralises core.fsmonitor. core.hooksPath, filter.*, diff.external, core.sshCommand, GIT_CONFIG_* and about 15 raw git callers are still exposed. #3385's denylist omits GIT_CONFIG_* and HOME.
  • The published @claude-flow/mcp@3.0.0-alpha.9 still ships the shell-string github-safe.js reported in #3411. The source has been shell-free for some time; a corrected mcp publish needs its own decision.

Not included (held for changes): #3333, #3268, #3339, #3393, #3369, #3387, #3425, #3428, #3432, #3433, #3435, #3437, #3440, #3442, #3341, #3373, #3438, #3295, #3296, #3298, #3270, #3307, #3309, #3310.

Full list and validation: #3443.

Full write-up (review method, validation, artifact integrities, what was held and why): https://gist.github.com/ruvnet/d7c5a6f1c3616dbbc6db91fdafb1db32