Skip to content

chore: version packages#2

Open
github-actions[bot] wants to merge 1 commit intomainfrom
changeset-release/main
Open

chore: version packages#2
github-actions[bot] wants to merge 1 commit intomainfrom
changeset-release/main

Conversation

@github-actions
Copy link
Copy Markdown
Contributor

@github-actions github-actions bot commented Mar 25, 2026

This PR was opened by the Changesets release GitHub action. When you're ready to do a release, you can merge this and the packages will be published to npm automatically. If you're not ready to do a release yet, that's fine, whenever you add more changesets to main, this PR will be updated.

Releases

@questpie/autopilot@1.1.0

Minor Changes

  • 4558577 Thanks @drepkovsky! - Security hardening: 22 fixes across auth, API, agents, secrets, and dashboard

    API Security: CORS locked to configured origin (not *), security headers (X-Frame-Options, X-Content-Type-Options, HSTS, Referrer-Policy), X-Forwarded-For trusted proxy validation, request body size limits, reduced status endpoint payload for unauthenticated requests.

    Agent Sandbox: SSRF protection blocks private IPs in http_request tool, optional domain allowlist via agent_http_allowlist, per-agent tools config controls Claude SDK built-in tools (fs → read-only, fs_write → read/write, terminal → Bash), PreToolUse hooks enforce fs_scope write globs on Write/Edit and deny patterns on Read, filesystem browser enforces role-based scope for viewers.

    Rate Limiting: Agents now rate-limited (600/min general, 50/min search, 100/min chat), weighted sliding window algorithm, password reset rate limiter (3/15min), timing-safe HMAC and bearer token comparison.

    Secrets & Keys: Agent keys persisted across restarts (encrypted with master key), encrypted YAML support, secret masking in logs, API key hashing utility.

    Auth: Mandatory 2FA for owner/admin roles, invite-only registration via .auth/invites.yaml, password complexity (min 12 chars, digit + special), banned user session blocking, dashboard uses cookie-based auth (no more token in query params).

Patch Changes

  • Updated dependencies [4558577]:
    • @questpie/autopilot-spec@1.1.0
    • @questpie/autopilot-orchestrator@1.1.0

@questpie/autopilot-orchestrator@1.1.0

Minor Changes

  • 4558577 Thanks @drepkovsky! - Security hardening: 22 fixes across auth, API, agents, secrets, and dashboard

    API Security: CORS locked to configured origin (not *), security headers (X-Frame-Options, X-Content-Type-Options, HSTS, Referrer-Policy), X-Forwarded-For trusted proxy validation, request body size limits, reduced status endpoint payload for unauthenticated requests.

    Agent Sandbox: SSRF protection blocks private IPs in http_request tool, optional domain allowlist via agent_http_allowlist, per-agent tools config controls Claude SDK built-in tools (fs → read-only, fs_write → read/write, terminal → Bash), PreToolUse hooks enforce fs_scope write globs on Write/Edit and deny patterns on Read, filesystem browser enforces role-based scope for viewers.

    Rate Limiting: Agents now rate-limited (600/min general, 50/min search, 100/min chat), weighted sliding window algorithm, password reset rate limiter (3/15min), timing-safe HMAC and bearer token comparison.

    Secrets & Keys: Agent keys persisted across restarts (encrypted with master key), encrypted YAML support, secret masking in logs, API key hashing utility.

    Auth: Mandatory 2FA for owner/admin roles, invite-only registration via .auth/invites.yaml, password complexity (min 12 chars, digit + special), banned user session blocking, dashboard uses cookie-based auth (no more token in query params).

Patch Changes

  • Updated dependencies [4558577]:
    • @questpie/autopilot-spec@1.1.0
    • @questpie/autopilot-agents@1.1.0

@questpie/autopilot-spec@1.1.0

Minor Changes

  • 4558577 Thanks @drepkovsky! - Security hardening: 22 fixes across auth, API, agents, secrets, and dashboard

    API Security: CORS locked to configured origin (not *), security headers (X-Frame-Options, X-Content-Type-Options, HSTS, Referrer-Policy), X-Forwarded-For trusted proxy validation, request body size limits, reduced status endpoint payload for unauthenticated requests.

    Agent Sandbox: SSRF protection blocks private IPs in http_request tool, optional domain allowlist via agent_http_allowlist, per-agent tools config controls Claude SDK built-in tools (fs → read-only, fs_write → read/write, terminal → Bash), PreToolUse hooks enforce fs_scope write globs on Write/Edit and deny patterns on Read, filesystem browser enforces role-based scope for viewers.

    Rate Limiting: Agents now rate-limited (600/min general, 50/min search, 100/min chat), weighted sliding window algorithm, password reset rate limiter (3/15min), timing-safe HMAC and bearer token comparison.

    Secrets & Keys: Agent keys persisted across restarts (encrypted with master key), encrypted YAML support, secret masking in logs, API key hashing utility.

    Auth: Mandatory 2FA for owner/admin roles, invite-only registration via .auth/invites.yaml, password complexity (min 12 chars, digit + special), banned user session blocking, dashboard uses cookie-based auth (no more token in query params).

@questpie/autopilot-agents@1.1.0

Patch Changes

  • Updated dependencies [4558577]:
    • @questpie/autopilot-spec@1.1.0

@github-actions github-actions bot force-pushed the changeset-release/main branch 3 times, most recently from c67b384 to 6fa721f Compare March 26, 2026 14:07
@github-actions github-actions bot force-pushed the changeset-release/main branch from 6fa721f to fa781db Compare March 26, 2026 23:16
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants