You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
This commit was created on GitHub.com and signed with GitHub’s verified signature.
Added
Anonymous, opt-out usage telemetry (PostHog). InitRunner now reports anonymous usage so the maintainers can see whether and how it is used. Per CLI command it sends the command name (from a known list, never arguments), the outcome and exception class (never the message), a coarse duration bucket, OS, Python version, and InitRunner version, tied to a random install id, not to you. No prompts, file contents, paths, arguments, or API keys are sent, and events are anonymous (no PostHog person profiles, and $ip is overridden to 0.0.0.0 so the real source IP is never stored). It is shipped in core with a tiny dependency-free sender that never blocks process exit, and a one-time notice prints before the first send. Turn it off with initrunner telemetry disable, DO_NOT_TRACK=1, or INITRUNNER_TELEMETRY=off; it is off by default in CI. New initrunner telemetry status|enable|disable|reset, a status line in initrunner doctor, and INITRUNNER_TELEMETRY_DEBUG=1 to print events without sending. The dashboard adds the same opt-out posture via posthog-js (no autocapture or session recording, honors Do Not Track). See docs/operations/telemetry.md.
Guided start menu for initrunner new. Running initrunner new with no seed in a terminal now shows a numbered picker (describe / template / example / build offline / import), each annotated with whether it needs an API key. Piped or non-TTY input keeps the previous LLM-conversation fallback. See docs/agents/role_generation.md.
Offline role builder. New initrunner new --offline (and menu option 4) builds a valid role.yaml through a deterministic structured form (name, system prompt, provider/model, tool multi-select, memory/ingest/trigger toggles) with no LLM or network call. Entered tool-field values are parsed through YAML so numbers, booleans, and lists keep their types. Backed by a new pure services/wizard.py.
Credential preflight. Before an AI-backed seed, the builder resolves the API key through the vault and environment, prints Using <provider>:<model>, and on a missing key (in a terminal) offers to enter a key inline, switch provider, or build offline, instead of failing with a 401 mid-generation. Custom-endpoint presets (base_url, api_key_env) are carried through a provider switch.
Refinement-loop commands. The refine step accepts : commands (:help / ?, :yaml, :validate, :explain, :tools, :diff, :model, :undo, :save, :quit). :model changes the model and :undo reverts the last change, both deterministically with no LLM call; each AI refinement prints a +adds -removes change summary. When no API key is configured, plain-text refinement is replaced by a hint, so template, example, and offline roles can still be edited and saved.
First-run offline path. Bare initrunner with no provider configured now offers to build an agent offline, instead of only printing the setup hint.
Fixed
Invalid sidecar module names from awkward role filenames. A stem starting with a digit or containing dots (e.g. 2fa-bot.yaml) produced an unimportable Python sidecar module for imported custom tools; stems are now sanitized to a valid identifier. The same sanitizer is reused by initrunner new --template tool.
Consistent validation display in initrunner new. Post-save warnings now render through the shared validation panel (severity labels, line and column, fix hints) instead of ad-hoc lines.
Security
Bump aiohttp 3.13.4 to 3.14.0. Closes two moderate advisories fixed in 3.14.0: cross-origin redirect leaking per-request cookies (GHSA-hg6j-4rv6-33pg, CVE-2026-47265) and deserialization of untrusted data (GHSA-jg22-mg44-37j8, CVE-2026-34993). aiohttp is a transitive dependency of the optional discord-py and xai-sdk packages. (#146)