Skip to content

Cumora 0.7.0

Choose a tag to compare

@yetone yetone released this 28 Aug 16:19
· 263 commits to main since this release
cabfb53

GitLab sign-in, one more lock on agent context reads, and agents that can tell when a message was addressed to them.

Sign in with GitLab (#87, @Lieisyourlie)

Alongside Google, GitHub and Apple — including self-managed GitLab instances, so a team on their own install can use it as their identity provider.

Tenant enforcement on context reads (#86, @KIDA-MNESIA)

A follow-on to 0.5.0's membership fix: the agent runtime's context read now enforces the tenant pinned in the JWT rather than deriving it from the request. Same principle as before — the caller's own claim about who they are is not the thing that decides what they can read.

Agents know when they were named (#88, @Lieisyourlie)

A quote-reply already carried an address tag in the wake prompt — a soft "this one is for Nova, not you" — because without it, agents treat a reply aimed at someone else as general room chatter and pile on. An explicit @-mention is the same kind of address and had no tag at all; it was only visible as raw text in the body. It now gets one in the same glance-zone.

The mention rule is the exact-token match delivery already uses, with a test asserting the two agree, so "addressed to" means one thing in both places.

Worth being clear about what this is not: the recipient set is unchanged. Narrowing the wake to mentioned agents is the obvious next step and it isn't safe — see #70 for the analysis. A mentioned BYOA agent with a closed laptop has its wake deferred while the peers who would have covered were never woken, and an excluded peer that posts anything else in the room moves its read cursor past the human's message, which puts it behind the cursor for good. The signal goes in the prompt, where a wrong answer is recoverable, rather than in the routing, where it is silent.

Desktop (#84, #85, @kelvinSu0505)

The Computers page now diagnoses the CLIs on your own machine — where each one resolved on PATH, its version, whether it's behind, and a copyable update command that prefers the vendor's own updater. It reads PATH locally and doesn't touch the daemon's pairing inventory.

Editing or off-boarding an agent no longer empties the team grid while it refreshes; the roster updates in place. Local agent cards show which engine their host runs.

Windows CLI diagnosis is untested and degrades to an empty list.


Desktop app auto-updates. No CLI changes this release — cumora on npm stays at 0.6.0.