Features
- feat: add rhcustom provider to legacy settings.json configuration (#2776) @snecklifter
Fixes
- fix: block command injection in EE settings (#2804) @Hrithik-Gavankar
- fix(mcp): prevent path traversal in MCP server tools (CVE-2026-44192) (#2801) @shatakshiiii
- fix: validate activation script path to prevent command injection (#2800) @shatakshiiii
- fix: sanitize playbook filename to prevent command injection (#2799) @shatakshiiii
- fix: prevent API key disclosure via settings (#2796) @cidrblock
- fix(ci): fix lint and test-setup failures on main (#2795) @Hrithik-Gavankar
Maintenance
- chore(deps): update pnpm to v11.5.0 (#2813) @renovate[bot]
- chore(deps): lock file maintenance (#2791) @renovate[bot]
- chore: avoid creating deployment for ci workflow run (#2817) @ssbarnea
- refactor: unify path validation into shared helper (#2802) @shatakshiiii
- chore: upgrade pnpm to 11.x (#2808) @ssbarnea
- chore: upgrade node to 24.15 (#2809) @ssbarnea
- chore: use arm64 macos runner (#2811) @ssbarnea
- chore: sync agent skills from team-devtools (#2803) @ansibuddy
- chore(deps): update github actions (#2793) @renovate[bot]