Skip to content

Release 2.0.2: fix wrapper verification and local security boundaries - #7

Merged
aid-ninja merged 1 commit into
mainfrom
fix/native-manifest-adaptation
Sep 8, 2026
Merged

Release 2.0.2: fix wrapper verification and local security boundaries#7
aid-ninja merged 1 commit into
mainfrom
fix/native-manifest-adaptation

Conversation

@aid-ninja

Copy link
Copy Markdown
Contributor

The supported host security wrapper caused a false integrity failure for native mcp.json. Recognize both MCP formats while rejecting changes to the wrapper's configuration reference, server selector, underlying command, arguments or environment.

The accompanying focused security review reproduced and fixes protected-configuration export overwrites (including symlink paths), an implicit sync-log workspace escape, malformed HTTP request crashes, unsafe cleanup after a failed workspace-config save, and known environment credentials appearing in runner result surfaces. Operational adapter/verifier input is preserved. The security review documents the application-level boundaries and redaction limits.

Validation: all component suites and 86 integration tests passed on Node 25; isolated offline package installation and CLI/MCP smoke checks passed; the 449-entry release manifest verified. Focused provider tests passed for origin checks, redirects, request/response limits and cancellation. Dependency audit reported zero vulnerabilities. Required Node 24/25 CI must pass on the merged commit before the v2.0.2 tag. GitHub release only; existing tags stay unchanged.

@aid-ninja
aid-ninja merged commit 3c4f7c8 into main Sep 8, 2026
5 checks passed
@aid-ninja
aid-ninja deleted the fix/native-manifest-adaptation branch September 8, 2026 04:36
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant