auvik-v0.2.0
Security
- Go toolchain bumped to go1.26.6, which fixes GO-2026-6218 (quadratic
complexity innet/url, reachable fromcliutil.ProbeReachable). The
previously released binary was built with go1.26.5 and carried the advisory.
CI could not catch this: the workflows requestgo-version: "1.26", which
resolves to the latest patched Go, so the security gate scanned a patched
toolchain while the build honoured the pinned one. See issue #210.
Fixed
-
MCP tools are no longer default-denied. Every tool that is not a Cobra
mirror -search,sql,context, and theauvik_search/auvik_get/
auvik_executecode-orchestration trio - returned
MCP tenant gate is not configuredinstead of running. The generated tenant
gate treated "no platform source registered" as a failure rather than as
"nothing to gate", and no connector registers one. The previously released
binary had 6 dead tools. See issue #249. -
Windows binaries now exist.
internal/cli/auvik_snapshot_lock.gocalled
syscall.Flock, which does not exist on Windows, with no build tag - so the
Windows targets had never compiled and were silently absent from the release
assets, even thoughmanifest.jsondeclaredwin32support. Split on
//go:build, withLockFileExon Windows.