server@1.0.0
Major Changes
-
228f828: feat: evidence records carry per-device attestation strength
Pushed Drata/Vanta coverage records replace assignedUserAgentActive /
assignedUserAgentLastSeenAt with agentActive, agentAttestation, and
agentLastSeenAt. agentAttestation is "device" when the record is backed by
that machine's own agent heartbeat (matched on hardware serial) and "user"
when only its assigned user's, so a single push can carry both strengths
truthfully. Breaking for the customer-declared Drata/Vanta record schemas.
Minor Changes
- 2822d51:
remoteSessionIssuers.getcan now look an identity provider up by its upstream issuer URL, returning the one the project would use (preferring project over organization over platform) or 404 when nothing describes that URL yet. The dashboard's automatic setup flows use it to decide whether to reuse an existing provider instead of scanning the provider list in the browser, which also lets them reuse platform-catalog providers for the first time. - b5f47cb: Auto-provision the Drata Custom Connection on connect. When an evidence-sink provider implements the new optional
Provisionercapability, the connect flow creates its vendor-side object and stores the resulting ids, so the customer no longer hand-crafts it against the vendor API. Drata implements it: it find-or-creates the dedicated Custom Connection with the exact record schema andrequiredlist (omittingagentLastSeenAtso never-seen-agent records are never rejected), keyed on a deterministic name so a re-save reuses the connection instead of duplicating it. A new optionalworkspace_idfield defaults to 1, andconnection_idbecomes optional — filled in automatically. - 5cfbb83: Expose MCP Client Metadata to Gram Functions tool calls
- 5bf2d45: Select project skills as additional context for an individual Project Assistant turn.
Patch Changes
- d5e1ea6: Fix three Drata evidence-push defects found running against the live API. The stranded-session sweep failed to decode the session listing (Drata returns numeric session ids inside a data/pagination envelope; the sweep decoded them as strings and misreported the failure via a bare-array fallback) — session ids now tolerate numbers or strings, a null/absent data field counts as an empty sweep, and the envelope's real decode error surfaces. An empty fleet now clears evidence by deleting records directly, because Drata refuses to complete a session with no records. Per-record schema-validation rejections hidden inside 2xx upload responses now fail the push instead of silently publishing a partial fleet.
- 1d888d5: Add
message_created_atandassistant_idcolumns to the ClickHouse
risk_findingstable and stamp them at ingest from the chat-message
attribution lookup.message_created_at(defaulting to scan time for
pre-existing rows) will let the Risk Events listing sort and paginate by
event time from ClickHouse;assistant_idwill power the assistant filter
without a cross-store join. - eca5c54: Fix three Vanta evidence-sink defects against the real CustomResource API, all verified live. Every pushed record now carries the required top-level
externalUrlbase field (an omission was rejected with 400).agent_last_seen_atis always sent — an empty string when no agent has ever reported, rather than omitted — because Vanta's console cannot author an optional-property schema, so a device-declared record schema marks every property required and an omitted field fails at sync. And the response check now matches Vanta's actual full-state PUT contract — 200{"success": true}on a valid set, 4xx on any schema violation — instead of requiring anaccepted/rejectedaccounting object the API never returns, which was failing every push.