Skip to content

🦋 New version release - #5

Merged
brentrager merged 1 commit into
mainfrom
changeset-release/main
Apr 9, 2026
Merged

🦋 New version release#5
brentrager merged 1 commit into
mainfrom
changeset-release/main

Conversation

@brentrager

Copy link
Copy Markdown
Contributor

This PR was opened by the Changesets release GitHub action. When you're ready to do a release, you can merge this and the packages will be published to npm automatically. If you're not ready to do a release yet, that's fine, whenever you add more changesets to main, this PR will be updated.

Releases

@smooai/smooth@0.3.0

Minor Changes

  • 799c5ca: Major session: Changesets CI, web dashboard, provider overhaul, port forwarding, security enforcement.

    • Changesets versioning with auto Cargo.toml sync and GitHub Actions release pipeline
    • Husky git hooks with pre-commit cargo checks
    • th up daemon mode (background process with pid file), th down kills it
    • Interactive th auth login with provider/model picker and connection test
    • Kimi + Kimi Code providers (OpenAI-compat and Anthropic-compat)
    • Removed deprecated OpenCode Zen module entirely
    • Web dashboard: shadcn UI components, Tailwind v4 dark theme, responsive sidebar
    • Multi-project pearl support: /api/projects, project switcher, per-project pearl views
    • Pearl kanban with search, timeline view, stats view with bar charts
    • System topology SVG graph (radial layout, pulsing nodes, auto-refresh)
    • Clickable dashboard cards navigating to system/pearls
    • Port forwarding Phase 1: PortPolicy, forward_port tool, Wonk /check/port
    • VM path mapping: guest→host translation for filesystem deny pattern enforcement
    • Rich ANSI colors across CLI (th up/down/status/auth/doctor)
    • Doctor checks on th code startup

@brentrager
brentrager merged commit 8e7adaf into main Apr 9, 2026
brentrager added a commit that referenced this pull request Jun 23, 2026
…red reads

Extends the macOS Seatbelt bash profile toward the plan's P1 security
acceptance criteria:
- P1 #5: kernel-deny writes to workspace/.git/config (not just .git/hooks).
  A writable git config can repoint core.hooksPath or install executing
  aliases that later run OUTSIDE the sandbox — same escape class as a
  planted hook.
- P1 #6: extend credential read-denial from ~/.ssh / ~/.aws / ~/.config/gh
  / ~/.gnupg to also cover ~/.config/gcloud, ~/.kube, ~/.docker, ~/.netrc.

Adds two adversarial tests (run + pass on macOS): a postinstall-style
attempt to plant .git/hooks/post-checkout and overwrite .git/config both
fail (files never exist), and cat-ing cloud/registry/netrc creds leaks no
secret material. 34 smooth-tools tests pass; clippy clean.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016wBikCFJyoowRokiWK5rX1
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant