fix(security): fix file_tools.py validate_path startswith bypass #7478
All checks were successful
CI / push-validation (pull_request) Successful in 34s
CI / helm (pull_request) Successful in 37s
CI / build (pull_request) Successful in 48s
CI / lint (pull_request) Successful in 1m8s
CI / typecheck (pull_request) Successful in 1m14s
CI / quality (pull_request) Successful in 1m7s
CI / security (pull_request) Successful in 1m15s
CI / integration_tests (pull_request) Successful in 3m7s
CI / unit_tests (pull_request) Successful in 4m54s
CI / docker (pull_request) Successful in 1m26s
CI / coverage (pull_request) Successful in 11m59s
CI / status-check (pull_request) Successful in 3s
auto/needs-reevaluation
controller-managed
Priority
Critical
State
Paused
Type
Bug
fix(invariant): restore ACTION scope in merge_invariants and InvariantSet.merge
All checks were successful
CI / push-validation (pull_request) Successful in 49s
CI / helm (pull_request) Successful in 1m11s
CI / build (pull_request) Successful in 1m59s
CI / lint (pull_request) Successful in 2m6s
CI / typecheck (pull_request) Successful in 2m19s
CI / quality (pull_request) Successful in 2m39s
CI / security (pull_request) Successful in 2m45s
CI / integration_tests (pull_request) Successful in 5m15s
CI / unit_tests (pull_request) Successful in 6m58s
CI / docker (pull_request) Successful in 1m20s
CI / coverage (pull_request) Successful in 13m20s
CI / status-check (pull_request) Successful in 3s
auto/needs-reevaluation
controller-managed
MoSCoW
Must have
Priority
Critical
State
Paused
Type
Bug
fix(security): use relpath containment instead of startswith to prevent prefix-collision bypass
Some checks failed
CI / lint (pull_request) Successful in 57s
CI / typecheck (pull_request) Successful in 1m11s
CI / security (pull_request) Successful in 1m11s
CI / quality (pull_request) Successful in 1m12s
CI / build (pull_request) Successful in 36s
CI / helm (pull_request) Successful in 32s
CI / push-validation (pull_request) Successful in 30s
CI / integration_tests (pull_request) Failing after 4m48s
CI / unit_tests (pull_request) Failing after 5m55s
CI / coverage (pull_request) Has been skipped
CI / docker (pull_request) Has been skipped
CI / status-check (pull_request) Failing after 3s
auto/needs-reevaluation
controller-managed
Priority
Critical
State
Paused
Type
Bug
fix(events): add unsubscribe() to EventBus protocol and implementations (#10356)
Some checks failed
CI / lint (pull_request) Successful in 42s
CI / push-validation (pull_request) Successful in 1m1s
CI / helm (pull_request) Successful in 1m2s
CI / typecheck (pull_request) Successful in 2m4s
CI / build (pull_request) Successful in 2m7s
CI / quality (pull_request) Successful in 2m22s
CI / security (pull_request) Successful in 2m26s
CI / integration_tests (pull_request) Failing after 14m11s
CI / unit_tests (pull_request) Failing after 14m12s
CI / coverage (pull_request) Has been cancelled
CI / docker (pull_request) Has been cancelled
CI / status-check (pull_request) Has been cancelled
MoSCoW
Must have
Priority
Critical
State
In Review
Type
Bug
fix: InvariantService persistence across CLI invocations (Bug #8573)
Some checks failed
CI / helm (pull_request) Successful in 40s
CI / build (pull_request) Successful in 1m12s
CI / lint (pull_request) Failing after 1m41s
CI / unit_tests (pull_request) Failing after 1m49s
CI / quality (pull_request) Successful in 1m55s
CI / security (pull_request) Successful in 1m59s
CI / coverage (pull_request) Has been skipped
CI / docker (pull_request) Has been skipped
CI / push-validation (pull_request) Successful in 42s
CI / typecheck (pull_request) Failing after 1m59s
CI / integration_tests (pull_request) Failing after 1m57s
CI / status-check (pull_request) Failing after 7s
MoSCoW
Must have
Priority
Critical
State
In Review
Type
Bug
fix(auto_debug): return partial state updates from nodes per LangGraph contract
Some checks failed
CI / push-validation (pull_request) Successful in 36s
CI / helm (pull_request) Successful in 38s
CI / build (pull_request) Successful in 1m10s
CI / lint (pull_request) Successful in 1m37s
CI / quality (pull_request) Successful in 1m37s
CI / security (pull_request) Successful in 1m49s
CI / typecheck (pull_request) Successful in 2m0s
CI / integration_tests (pull_request) Successful in 6m39s
CI / unit_tests (pull_request) Failing after 8m35s
CI / coverage (pull_request) Has been skipped
CI / docker (pull_request) Has been skipped
CI / status-check (pull_request) Failing after 6s
MoSCoW
Must have
Priority
Critical
State
In Review
Type
Bug
fix(security): fix file_tools.py validate_path startswith bypass #7478
Some checks failed
CI / lint (pull_request) Successful in 1m4s
CI / typecheck (pull_request) Successful in 1m28s
CI / security (pull_request) Successful in 1m29s
CI / push-validation (pull_request) Successful in 54s
CI / helm (pull_request) Successful in 59s
CI / build (pull_request) Successful in 1m43s
CI / quality (pull_request) Successful in 2m28s
CI / integration_tests (pull_request) Successful in 4m58s
CI / unit_tests (pull_request) Failing after 5m47s
CI / coverage (pull_request) Has been skipped
CI / docker (pull_request) Has been skipped
CI / status-check (pull_request) Failing after 3s
MoSCoW
Must have
Priority
Critical
State
In Review
Type
Bug
fix(lsp): prevent header injection in LSP transport ASCII decoding
Some checks failed
CI / push-validation (pull_request) Successful in 32s
CI / helm (pull_request) Successful in 42s
CI / build (pull_request) Successful in 1m9s
CI / lint (pull_request) Successful in 1m25s
CI / quality (pull_request) Successful in 1m47s
CI / security (pull_request) Successful in 1m52s
CI / typecheck (pull_request) Successful in 1m55s
CI / integration_tests (pull_request) Successful in 7m49s
CI / unit_tests (pull_request) Failing after 10m15s
CI / docker (pull_request) Has been skipped
CI / coverage (pull_request) Has been skipped
CI / status-check (pull_request) Failing after 4s
MoSCoW
Must have
Priority
Critical
State
In Review
Type
Bug
fix(lsp): cleanup subprocess on failed initialization in StdioTransport.start()
Some checks failed
CI / push-validation (pull_request) Successful in 43s
CI / helm (pull_request) Successful in 50s
CI / build (pull_request) Successful in 1m18s
CI / quality (pull_request) Successful in 1m39s
CI / lint (pull_request) Failing after 1m44s
CI / typecheck (pull_request) Successful in 1m47s
CI / security (pull_request) Successful in 1m55s
CI / integration_tests (pull_request) Successful in 4m41s
CI / unit_tests (pull_request) Failing after 7m18s
CI / coverage (pull_request) Has been skipped
CI / docker (pull_request) Has been skipped
CI / status-check (pull_request) Failing after 3s
MoSCoW
Must have
Priority
Critical
State
In Review
Type
Bug
fix(invariants): add ACTION scope to merge_invariants() and InvariantSet.merge() 4-tier pipeline
Some checks failed
CI / benchmark-publish (pull_request) Has been skipped
CI / quality (pull_request) Successful in 1m4s
CI / benchmark-regression (pull_request) Failing after 1m9s
CI / helm (pull_request) Successful in 29s
CI / security (pull_request) Successful in 1m30s
CI / typecheck (pull_request) Successful in 1m30s
CI / push-validation (pull_request) Successful in 35s
CI / build (pull_request) Successful in 1m7s
CI / integration_tests (pull_request) Successful in 3m16s
CI / e2e_tests (pull_request) Successful in 3m49s
CI / unit_tests (pull_request) Failing after 10m46s
CI / lint (pull_request) Failing after 10m48s
CI / coverage (pull_request) Has been cancelled
CI / docker (pull_request) Has been cancelled
CI / status-check (pull_request) Has been cancelled
MoSCoW
Must have
Priority
Critical
State
In Review
Type
Bug
fix(invariant): persist standalone invariants to database
All checks were successful
CI / benchmark-publish (pull_request) Has been skipped
CI / build (pull_request) Successful in 20s
CI / helm (pull_request) Successful in 22s
CI / lint (pull_request) Successful in 3m19s
CI / quality (pull_request) Successful in 3m43s
CI / typecheck (pull_request) Successful in 3m58s
CI / security (pull_request) Successful in 4m9s
CI / unit_tests (pull_request) Successful in 7m53s
CI / docker (pull_request) Successful in 1m29s
CI / coverage (pull_request) Successful in 7m19s
CI / e2e_tests (pull_request) Successful in 11m26s
CI / integration_tests (pull_request) Successful in 15m5s
CI / status-check (pull_request) Successful in 1s
CI / benchmark-regression (pull_request) Successful in 52m13s
auto/needs-reevaluation
controller-managed
MoSCoW
Must have
Priority
Critical
State
Paused
Type
Bug