From 87899a6a3db8c681806cc7215355794782cdc4fb Mon Sep 17 00:00:00 2001 From: Felipe Marzochi Date: Thu, 6 Aug 2026 01:02:45 -0300 Subject: [PATCH 1/2] release: v1.1.18 Bump every version surface to 1.1.18, move the accumulated Unreleased entries into the v1.1.18 sections of CHANGELOG.md and docs/ROADMAP.md, and complete the roadmap log for #1193-#1215. Verified before tagging: real end-to-end installs of the packed tarball in isolated HOMEs on Linux and macOS (registration, state bootstrap, shim, honest headless dashboard message), plus the full CI matrix on Windows. Signed-off-by: Felipe Marzochi --- .agents/plugins/marketplace.json | 2 +- .codex-plugin/plugin.json | 2 +- .gemini-plugin/marketplace.json | 2 +- .gemini-plugin/plugin.json | 2 +- .opencode/package-lock.json | 4 ++-- .opencode/package.json | 2 +- .opencode/plugins/egc-hooks.ts | 4 ++-- CHANGELOG.md | 18 ++++++++++++++++++ agent.yaml | 2 +- docs/ROADMAP.md | 9 +++++++++ package-lock.json | 4 ++-- package.json | 2 +- 12 files changed, 40 insertions(+), 13 deletions(-) diff --git a/.agents/plugins/marketplace.json b/.agents/plugins/marketplace.json index 4178aec27..66e75fe93 100644 --- a/.agents/plugins/marketplace.json +++ b/.agents/plugins/marketplace.json @@ -6,7 +6,7 @@ "plugins": [ { "name": "egc", - "version": "1.1.17", + "version": "1.1.18", "source": { "source": "local", "path": "../.." diff --git a/.codex-plugin/plugin.json b/.codex-plugin/plugin.json index 648811a54..35f4c534f 100644 --- a/.codex-plugin/plugin.json +++ b/.codex-plugin/plugin.json @@ -1,6 +1,6 @@ { "name": "egc", - "version": "1.1.17", + "version": "1.1.18", "description": "Battle-tested Codex workflows \u2014 230 shared EGC skills, production-ready MCP configs, and selective-install-aligned conventions for TDD, security scanning, code review, and autonomous development.", "author": { "name": "Felipe Marzochi", diff --git a/.gemini-plugin/marketplace.json b/.gemini-plugin/marketplace.json index 773a2c69d..0e2537ee5 100644 --- a/.gemini-plugin/marketplace.json +++ b/.gemini-plugin/marketplace.json @@ -12,7 +12,7 @@ "name": "egc", "source": "./", "description": "EGC - Extended Global Context: 63 agents, 230 skills, 77 commands, persistent memory across sessions, and production-ready hooks for TDD, security scanning, code review, and continuous learning", - "version": "1.1.17", + "version": "1.1.18", "author": { "name": "Felipe Marzochi", "email": "fmarzochi@gmail.com" diff --git a/.gemini-plugin/plugin.json b/.gemini-plugin/plugin.json index 6ba9d0001..0d0f3413d 100644 --- a/.gemini-plugin/plugin.json +++ b/.gemini-plugin/plugin.json @@ -1,6 +1,6 @@ { "name": "egc", - "version": "1.1.17", + "version": "1.1.18", "description": "EGC - Extended Global Context: persistent memory and shared context for AI coding tools. 63 agents, 230 skills, 77 commands, production-ready hooks, and selective install workflows evolved through continuous real-world use", "author": { "name": "Felipe Marzochi", diff --git a/.opencode/package-lock.json b/.opencode/package-lock.json index bca95e8ca..ea6db5777 100644 --- a/.opencode/package-lock.json +++ b/.opencode/package-lock.json @@ -1,12 +1,12 @@ { "name": "egc-universal", - "version": "1.1.17", + "version": "1.1.18", "lockfileVersion": 3, "requires": true, "packages": { "": { "name": "egc-universal", - "version": "1.1.17", + "version": "1.1.18", "license": "MIT", "devDependencies": { "@opencode-ai/plugin": "^1.4.3", diff --git a/.opencode/package.json b/.opencode/package.json index 34738c957..691a9bc6a 100644 --- a/.opencode/package.json +++ b/.opencode/package.json @@ -1,6 +1,6 @@ { "name": "egc-universal", - "version": "1.1.17", + "version": "1.1.18", "description": "Extended Global Context (EGC) plugin for OpenCode - agents, commands, hooks, and skills", "main": "dist/index.js", "types": "dist/index.d.ts", diff --git a/.opencode/plugins/egc-hooks.ts b/.opencode/plugins/egc-hooks.ts index 8734bd8e9..82c551d34 100644 --- a/.opencode/plugins/egc-hooks.ts +++ b/.opencode/plugins/egc-hooks.ts @@ -513,7 +513,7 @@ export const EGCHooksPlugin: EGCHooksPluginFn = async ({ */ "shell.env": async () => { const env: Record = { - EGC_VERSION: "1.1.17", + EGC_VERSION: "1.1.18", EGC_PLUGIN: "true", EGC_HOOK_PROFILE: currentProfile, EGC_DISABLED_HOOKS: process.env.EGC_DISABLED_HOOKS || "", @@ -567,7 +567,7 @@ export const EGCHooksPlugin: EGCHooksPluginFn = async ({ const contextBlock = [ "# EGC Context (preserve across compaction)", "", - "## Active Plugin: EGC - Extended Global Context v1.1.17", + "## Active Plugin: EGC - Extended Global Context v1.1.18", "- Hooks: file.edited, tool.execute.before/after, session.created/idle/deleted, shell.env, compacting, permission.ask", "- Tools: run-tests, check-coverage, security-audit, format-code, lint-check, git-summary, changed-files", "- Agents: 13 specialized (planner, architect, tdd-guide, code-reviewer, security-reviewer, build-error-resolver, e2e-runner, refactor-cleaner, doc-updater, go-reviewer, go-build-resolver, database-reviewer, python-reviewer)", diff --git a/CHANGELOG.md b/CHANGELOG.md index cb4fa1b33..59c98f45e 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -4,11 +4,29 @@ All notable changes to EGC are documented here. ## [Unreleased] +## [1.1.18] - 2026-08-06 + +### Security + +- **Guardian no longer denies reading paths it only protects against writes**: legitimate diagnostics of EGC's own install were blocked; now six operational directories are readable and everything else stays denied by default, a design that went through two independent security audits before merging (#1205). +- **Prompt-injection scanning wired into the WebFetch path**: every fetched page is scanned automatically by the advisory heuristic scanner instead of requiring a manual call (#1123, #1126, #1127). + ### Bug Fixes +- **Token Crusher PATH shim could fork-bomb the host under an isolated HOME** (sandboxed installs, CI, containers): shim identity is now anchored to the launcher's physical directory with realpath checks and a circuit breaker, covered by POSIX and Windows regression tests (#1191). +- **Installers now do what the docs say**: Claude Code MCP registration goes through the real CLI instead of a dead config file (#1193), the bare install merges the project `.mcp.json` of the directory you ran it from (#1195), one registration list serves all three entry points so Continue.dev and Zed are finally registered by the shell installers (#1197), and the installation guide matches actual behavior (#1196, #1206). +- **Token Crusher compresses JSON with nested lists**, the shape almost every real API returns; measured on a real payload: 637 KB down to 31 KB (#1204). +- **`egc repair` rebuilds what it can** and reports what it cannot, with the cause, instead of abandoning the whole target over one orphaned file (#1210); `egc doctor` reports state stores honestly instead of a blanket divergence warning (#1194). +- **MCP server builds are self-contained and cross-platform**, no longer reaching outside the package or requiring `chmod` on Windows (#1211). +- **Windows reliability**: the session bridge no longer drops events on slow cold starts (#1203), and subprocess test budgets are sized per platform (#1209, #1212). +- **Learned skills with a `When to Activate` section are summarized correctly** at session start instead of falling back to the intro paragraph (#1213); the devfleet catalog entry points at the repository that exists (#1214). - **Memory corruption from an orphaned marker fixed at the root**: a stale marker left behind in propagated context files (`.cursor`, `.trae`, `AGENTS.md`, `GEMINI.md` and 10 more) could delete real user content instead of just the EGC-managed section; an outdated MCP runtime made it worse by overwriting `.cursor` with no marker at all. Reported directly by Helal Ferrari Cabral (@helalferrari). 57 new tests, CI green on all 3 OSes (#1102, #1103). - **`egc doctor` / state-store divergence fixed**: a bare terminal invocation of `getEGCDir()` fell back to the first harness directory that happened to exist on disk (for example OpenCode) instead of the tool-agnostic `~/.egc` default, silently routing commands to the wrong `state.db`. Reported directly by Helal Ferrari Cabral (@helalferrari) (#1104). +### Changed + +- **Cloning the repository or installing the Codex plugin no longer auto-bundles six third-party MCP servers** (close to 1 GB of RAM combined); the root `.mcp.json` stays for the plugin contract but declares nothing, the Cursor install stops injecting them, and the `mcp-configs/` catalog remains the documented path for installing any of them by hand (#1215). Personal tooling entries left the published package earlier in the same effort (#1202). + ## [1.1.17] - 2026-07-27 ### Bug Fixes diff --git a/agent.yaml b/agent.yaml index 2617bfc79..89cc1502b 100644 --- a/agent.yaml +++ b/agent.yaml @@ -1,6 +1,6 @@ spec_version: "0.1.0" name: egc -version: 1.1.17 +version: 1.1.18 description: "EGC - Extended Global Context. Persistent memory and shared context for AI coding tools. Desenvolvido por Felipe Marzochi. @MarzochiFelipe. https://github.com/Fmarzochi/EGC" author: fmarzochi license: Apache-2.0 diff --git a/docs/ROADMAP.md b/docs/ROADMAP.md index 65f201c70..198947c34 100644 --- a/docs/ROADMAP.md +++ b/docs/ROADMAP.md @@ -4,6 +4,8 @@ This document describes the planned development direction for EGC (Extended Glob ## Unreleased +## v1.1.18: Production Hardening (Released 2026-08-06) + - Guardian Bash command validator extended to three more hosts with a genuine pre-action blocking hook: Cursor (#1071), OpenCode (#1072), and Kiro CLI (#1073), each wired through a host-specific translation adapter that reuses shared stdin-parsing and hooks-merge libraries; Token Crusher wired into OpenCode (#1072) and into Antigravity's global hooks.json (#1067) - Guardian wired into Cline's PreToolUse hook (#1087), researched directly against the cline/cline source rather than the docs (mid-migration to a new SDK plugin system not yet applicable to the VS Code extension); Token Crusher confirmed impossible there (no command-rewrite field in the hook output schema), the same status as Kiro and Windsurf - Roo Code confirmed to have no hook mechanism at all (Guardian and Token Crusher both impossible, not just Crusher): its own issue tracker shows hooks were never implemented (issue #11504 is an open, unresolved feature request), and the project has been archived since 2026-05-15 @@ -34,6 +36,13 @@ This document describes the planned development direction for EGC (Extended Glob - `validate_content` wired into a real `PostToolUse` hook (`post:webfetch:injection-scan`): every `WebFetch` result is now scanned automatically for prompt-injection patterns instead of requiring a manual call, advisory-only, flags on stderr; `scripts/ci/catalog.js` extended to count and lock `rules/` the same way `agents/`, `skills/`, and `commands/` already are, closing the last catalog claim in the README with no CI check keeping it honest (#1126) - An independent security-auditor pass on #1126 found and closed 3 real bypasses, each reproduced and verified before and after the fix: `validateWrite`/`isProtectedPath` didn't trim the path string, so a trailing newline (routine for anything piped through `echo`) defeated every `$`-anchored protected-path pattern, letting writes to `.env`/`.bashrc`/etc. through; `checkGitConfigWrite` blocked `include.path` but missed git's `includeIf..path` conditional-include syntax, the same wholesale-config-load risk; `post-webfetch-injection-scan.js`'s content extraction only read string fields, silently skipping the scan on standard MCP SDK responses shaped as `{ content: [{ type: 'text', text: '...' }] }` (#1127) - The Token Crusher PATH shim can no longer fork-bomb the host under a HOME/USERPROFILE override: shim identity was derived from `os.homedir()`, so an overridden home hid the manifest and made the shim resolve to itself and spawn until the OS killed the whole terminal (reproduced at 2.4 GB in 11 seconds). Resolution is now anchored to the launcher's physical directory (manifest read beside it; the Windows `.cmd` bakes its own directory in via `%~dp0`), every candidate is realpath-checked against shim directories including Windows 8.3 short names, PATH probing only surfaces candidates the platform can actually spawn, and a depth-1 circuit breaker turns any residual self-resolution into a clean exit 127 instead of a fork bomb; covered by 6 new POSIX and Windows regression tests (#1191) +- Installers made honest end to end: Claude Code MCP registration goes through the real CLI instead of a dead config file (#1193), the bare install merges the project `.mcp.json` of the invoking directory and starts the dashboard the README promises, headless runs get a clear message instead of silence (#1195), one MCP registration list serves `egc init` and both shell installers so Continue.dev and Zed are finally registered everywhere (#1197), and the installation guide matches actual behavior command by command (#1196, #1206) +- `egc doctor` reports state stores honestly instead of a blanket divergence warning (#1194); `egc repair` rebuilds what it can and reports what it cannot, with the cause, instead of abandoning the whole target over one orphaned file (#1210) +- Guardian no longer denies reading paths it only protects against writes: six operational directories readable, everything else denied by default, approved by two independent security audits (#1205) +- Token Crusher compresses JSON with lists nested inside an object, the shape almost every real API returns, measured 637 KB to 31 KB on a real payload (#1204); the dashboard launcher dropped its shell-spawn path, clearing the main-branch quality gate (#1207) +- Windows reliability: the session bridge no longer drops events on slow Python cold starts (#1203), subprocess test budgets are sized per platform and centralized (#1209, #1212), and the MCP server builds are self-contained and cross-platform (#1211) +- Personal tooling left the published package (#1202), and neither a repo clone nor the Codex plugin auto-bundles third-party MCP servers any more: the root `.mcp.json` stays for the plugin contract but declares nothing, the Cursor install stops injecting them, and the `mcp-configs/` catalog remains the manual path (#1215) +- Learned skills with a `When to Activate` section are summarized by that section at session start instead of the intro paragraph (#1213); the devfleet catalog entry points at the repository that exists (#1214); the codeql-action references were unified in one commit after three isolated bumps proved unmergeable (#1208) ## v1.1.2: Bidirectional Sync (Released 2026-06-20) diff --git a/package-lock.json b/package-lock.json index 81a84b208..4ea833aaf 100644 --- a/package-lock.json +++ b/package-lock.json @@ -1,12 +1,12 @@ { "name": "@egchq/egc", - "version": "1.1.17", + "version": "1.1.18", "lockfileVersion": 3, "requires": true, "packages": { "": { "name": "@egchq/egc", - "version": "1.1.17", + "version": "1.1.18", "hasInstallScript": true, "license": "Apache-2.0", "dependencies": { diff --git a/package.json b/package.json index 8141604f3..87523d18d 100644 --- a/package.json +++ b/package.json @@ -1,6 +1,6 @@ { "name": "@egchq/egc", - "version": "1.1.17", + "version": "1.1.18", "description": "EGC is a local-first MCP runtime that gives every AI agent the same brain: persistent shared memory, security guardrails, and up to 90% token savings across 23 AI coding tools.", "author": "Felipe Marzochi (https://github.com/Fmarzochi)", "license": "Apache-2.0", From faba07bc74c5931a578053659ebc1c384ca673ae Mon Sep 17 00:00:00 2001 From: Felipe Marzochi Date: Thu, 6 Aug 2026 01:13:58 -0300 Subject: [PATCH 2/2] docs(changelog): enumerate the shipped features so both release documents agree The roadmap's v1.1.18 section spans everything merged since v1.1.17, but the changelog entry only highlighted the hardening batch. The Added section now lists the feature groups that ship too: Guardian host expansion, the Crusher PATH shim, NLI coverage, scoped gain, compaction re-injection, and repo-root support. Signed-off-by: Felipe Marzochi --- CHANGELOG.md | 9 +++++++++ 1 file changed, 9 insertions(+) diff --git a/CHANGELOG.md b/CHANGELOG.md index 59c98f45e..44202e6e1 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -6,6 +6,15 @@ All notable changes to EGC are documented here. ## [1.1.18] - 2026-08-06 +### Added + +- **Guardian command validation extended across the tool ecosystem**: real pre-action blocking hooks wired into Cursor, OpenCode, Kiro CLI, Cline, Amp, Amazon Q Developer CLI, Goose, and OpenHands, each through a host-specific adapter over shared parsing and merge libraries (#1067-#1092); an earlier viability report that wrongly classified three of those hosts as prompt-only was corrected against each project's own source. +- **Token Crusher PATH-level binary shim** (`egc crusher-shim install|uninstall|status`): transparently compresses output from git, npm, gh, pip and friends without an explicit `egc run` wrapper, with full passthrough on TTYs and clean degradation on any resolution failure (#1107, #1110, #1112, #1114). +- **NLI session bus and memory protocol coverage extended** to Aider, Warp, Windsurf, Zed and more, completing the 23-tool surface (#1059-#1062). +- **`egc gain` scoped savings breakdown**: today, current session, current project, since install, and rolling 7/30-day windows, with local-calendar-day boundaries (#1118, @Tyr1onX). +- **Claude Code re-injects project context after compaction** (#1069), and OpenCode restores project context on session creation instead of starting cold (#1115, @Tyr1onX). +- **`doctor`, `repair`, and `auto-update` accept `--repo-root`**, and the cognitive protocol marker is versioned across all 11 install targets so existing installs pick up new protocol sections on the next update (#1093, #1095). + ### Security - **Guardian no longer denies reading paths it only protects against writes**: legitimate diagnostics of EGC's own install were blocked; now six operational directories are readable and everything else stays denied by default, a design that went through two independent security audits before merging (#1205).