What's Changed
- Skip projectServerConfig:getConfig for a local project id by @nachocossio in #5724
- docs: remove unreleased Computer and harness host pages by @prathmeshpatel in #5793
- test(e2e): pin the attacker-proxy upstream to the test target's origin by @olartgabo in #5795
- Make the server picker popover scrollable when the list overflows by @prathmeshpatel in #5779
- Stop API context churn from looping tools/list into a 429 storm by @nachocossio in #5783
- v1: gate malformed project ids on every read CONVEX-HQ probed by @ZeHuari in #5799
- Summarize recorded errors across the full eval launch by @ZeHuari in #5778
- Codex/report failure recovery by @ignaciojimenezr in #5803
- Fix CSP badge crash during violation bursts by @ignaciojimenezr in #5804
- fix(auth): cancel app subscriptions during rejected-token recovery by @ignaciojimenezr in #5802
- Render a malformed authorization_servers entry as text in the OAuth diagram by @nachocossio in #5796
- Cover the authkit error contract with the real provider by @nachocossio in #5791
- Treat an unauthenticated refusal as an auth gap, and pause the gate on sign-out by @nachocossio in #5794
- List tools for a server set in one hosted request by @nachocossio in #5792
- Fix OAuth debugger token imports for saved servers by @ignaciojimenezr in #5806
- Show refresh guidance when JavaScript loading crashes the app by @ignaciojimenezr in #5813
- Disable npm install scripts in example projects by @chelojimenez in #5811
- Pin claude-code-action by SHA and update vulnerable transitive deps by @olartgabo in #5684
- docs: fix Okta SAML identity mapping and onboarding guide by @chelojimenez in #5819
- fix(auth): honor organization-specific login links by @chelojimenez in #5820
- chore(release): version packages (3.12.9) by @chelojimenez in #5825
Full Changelog: v3.12.8...v3.12.9