Peter Steinberger
914b9d1e79
fix(agents): block workspaceOnly apply_patch delete symlink escape
2026-02-15 03:28:25 +01:00
Vignesh Natarajan
eafda6f526
Sandbox: add shared bind-aware fs path resolver
2026-02-14 16:53:43 -08:00
Peter Steinberger
5e7c3250cb
fix(security): add optional workspace-only path guards for fs tools
2026-02-14 23:50:24 +01:00
Gustavo Madeira Santana
4434cae565
Security: harden sandboxed media handling ( #9182 )
...
* Message: enforce sandbox for media param
* fix: harden sandboxed media handling (#8780 ) (thanks @victormier)
* chore: format message action runner (#8780 ) (thanks @victormier)
---------
Co-authored-by: Victor Mier <victormier@gmail.com >
2026-02-04 19:11:23 -05:00
cpojer
5ceff756e1
chore: Enable "curly" rule to avoid single-statement if confusion/errors.
2026-01-31 16:19:20 +09:00
Peter Steinberger
c379191f80
chore: migrate to oxlint and oxfmt
...
Co-authored-by: Christoph Nakazawa <christoph.pojer@gmail.com >
2026-01-14 15:02:19 +00:00
Peter Steinberger
3b075dff8a
feat: add per-session agent sandbox
2026-01-03 21:41:58 +01:00