github nolabs-ai/nono v0.79.0

3 hours ago

Security Advisories

What's Changed

  • fix(cli): accept keyring:// URIs in custom credential_key by @jbtechie in #1931
  • fix(cli): show resolved session hooks in profile output by @MateSaary in #1935
  • ci: harden workflow permissions and add ShellCheck by @SequeI in #1934
  • fix: provide workflow scope by @SequeI in #1937
  • chore(nix): update prebuilt hashes for v0.78.0 by @SequeI in #1936
  • fix(cli): keep protected-root attempts out of actionable denial guidance by @SequeI in #1941
  • fix(policy): let man/apropos/whatis work on Linux by @david-a-wheeler in #1953
  • docs(sandbox): add docker tool sandbox prototype example by @lukehinds in #1955
  • fix(exec): keep session temp files alive against the OS reaper by @panga in #1942
  • chore(deps): bump docker/build-push-action from 7.3.0 to 7.4.0 by @dependabot[bot] in #1962
  • chore(deps): bump docker/setup-buildx-action from 4.3.0 to 4.4.1 by @dependabot[bot] in #1966
  • chore(deps): bump docker/setup-qemu-action from 4.3.0 to 4.4.0 by @dependabot[bot] in #1969
  • chore(deps): bump typify from 0.7.0 to 0.8.0 by @dependabot[bot] in #1965
  • chore(deps): bump rcgen from 0.14.9 to 0.14.10 by @dependabot[bot] in #1963
  • chore(deps): bump syn from 3.0.3 to 3.0.6 by @dependabot[bot] in #1967
  • chore(deps): bump serde_json from 1.0.150 to 1.0.151 by @dependabot[bot] in #1964
  • chore(deps): bump uuid from 1.24.0 to 1.26.1 by @dependabot[bot] in #1968
  • ci: acquire test_env::ENV_LOCK before calling host git by @SequeI in #1972
  • feat(cli)!: remove legacy Claude hook cleanup by @SequeI in #1973
  • fix(aur): update upstream URLs to nolabs-ai by @sarovin in #1979
  • fix(proxy): decode chunked client-credentials token responses by @Gandem in #1976
  • fix(tool-sandbox): isolate network policy by effective command scope by @SequeI in #1981
  • feat(policy): add standalone Snap runtime group by @SequeI in #1990
  • fix(policy): allow Linux font configuration reads by @SequeI in #1991
  • docs(cli): correct credential flag source documentation by @Pybsama in #1998
  • docs: standardize sandbox policy taxonomy by @SequeI in #1993
  • fix(linux): preserve O_PATH in musl builds by @SequeI in #2005
  • feat(cli): render proxy network denials in diagnostic footer by @lukehinds in #1992
  • fix(cli): audit approval backend decisions prior to file operations by @lukehinds in #2010
  • fix(tool-sandbox): derive shim broker socket from executable path by @panga in #2002
  • fix(policy): allow reading Linux MIME types by @SequeI in #2013
  • fix(keystore): refuse empty sanitized PATH for host-side brokers by @SebTardif in #1895
  • docs(NEP): macOS keychain in nono-cli by @kurtisc in #1982
  • chore(deps): bump futures-util from 0.3.32 to 0.3.34 by @dependabot[bot] in #2014
  • chore(deps): bump dns-lookup from 2.1.1 to 4.0.1 by @dependabot[bot] in #2015
  • chore(deps): bump rand from 0.10.2 to 0.10.3 by @dependabot[bot] in #2016
  • chore(deps): bump clap from 4.6.6 to 4.6.7 by @dependabot[bot] in #2017
  • chore(deps): bump hyper-rustls from 0.27.9 to 0.27.10 by @dependabot[bot] in #2018
  • docs(neps): add nep 0004 for linux namespace isolation by @lukehinds in #2021
  • feat(cli): launch and attach to remote agent sessions by @lukehinds in #2022
  • feat(profile): add diagnostics.redaction.extra_env_vars by @christine-at-datadog in #1917
  • fix: file grants negate filesystem.deny - #1949 by @kurtisc in #2019
  • fix(macos): recursively block sockets under denied directories by @SequeI in #2026
  • chore: release v0.79.0 by @SequeI in #2027

New Contributors

Full Changelog: v0.78.0...v0.79.0

Don't miss a new nono release

NewReleases is sending notifications on new releases.