Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
235 commits
Select commit Hold shift + click to select a range
4fe82ef
📖 docs(gtr): correct the NOTICE status — the generator could not run,…
clubanderson Aug 28, 2026
71c3a0e
🐛 show OIDC display names instead of raw identity keys across hub and…
clubanderson Aug 28, 2026
8db251f
🔒 fix(knowledge): replace AGPL go-docx with stdlib docx text extracti…
clubanderson Aug 28, 2026
a888eba
feat(contribute): add opencode as a contributor relay backend (#5015)
clubanderson Aug 28, 2026
739a125
📖 docs(gtr): keep the gap summary to standing weaknesses (#5018)
clubanderson Aug 28, 2026
cb7994c
🐛 fix(governor): PRs red only on non-required checks are merge-eligib…
clubanderson Aug 28, 2026
389e34f
🐛 fix(notice): commit authoritative dependency licenses (#5014)
Danathar Aug 28, 2026
26bcd47
🐛 fix: answer Claude CLI telemetry and count_tokens locally in the in…
gregoryhunt Aug 28, 2026
dbe75a8
security: confine or honestly refuse every remaining backend on the c…
clubanderson Aug 28, 2026
2737703
🐛 fix(ci): per-branch channel ownership — v4 stops re-pointing edge (…
clubanderson Aug 28, 2026
eef1d2c
fix(dashboard): document the full dashboard API surface in openapi.js…
clubanderson Aug 28, 2026
2de9eec
🧹 lint: fix 121 of 122 staticcheck findings, gate stays off pending t…
clubanderson Aug 28, 2026
f26aee5
📖 docs(readme): drop stale v2 labels from hub deploy and config secti…
clubanderson Aug 29, 2026
da94f8b
📖 docs(development): document how to run the inception integration su…
clubanderson Aug 29, 2026
cd564ee
docs: add agent sandbox confinement section to getting-started guide …
clubanderson Aug 29, 2026
8834874
🐛 fix(contributor): link claude-code's native binary in the container…
Danathar Aug 29, 2026
1c70094
✨ feat(tui): pane interface, four stub panes, static 2×2 grid (#4907 …
Danathar Aug 29, 2026
388a290
feat(contribute): define Pi provider readiness (#5043)
Danathar Aug 29, 2026
e967084
docs: document opencode backend and agent_sandbox config block (#5050)
clubanderson Aug 29, 2026
32960f5
✨ feature: add Kilo headless contributor backend (#5040)
Danathar Aug 29, 2026
f9ad0a8
🐛 fix: stop interactive backend before ready after revoke (#5042)
Danathar Aug 29, 2026
582d4ba
✨ feat(linear): close the remaining L3 gaps — in-flight ledger, sessi…
gregoryhunt Aug 29, 2026
155ae01
🐛 fix: satisfy v4's required gate check before pushing the release co…
clubanderson Aug 29, 2026
5632f13
[sec-check] fix: stop persisting the hub-delivered GitHub token in wo…
kubestellar-hive[bot] Aug 29, 2026
a0248ba
fix(dashboard): poll for contributor state instead of fixed sleep in …
clubanderson Aug 29, 2026
02ceb6a
[quality] cover handleRotateMasterKey handler branches (46% -> 98%) (…
kubestellar-hive[bot] Aug 29, 2026
fa4863b
✨ feat: tui client — list agents (T4) (#5067)
clubanderson Aug 29, 2026
56c5006
🧹 lint: fix errcheck findings outside hub/proxy/dashboard (#4903 step…
clubanderson Aug 29, 2026
4bdb090
[quality] cover mint projected-token loader and advisory file-path re…
kubestellar-hive[bot] Aug 29, 2026
4b2ddbc
[quality] make provenance non-Kubernetes regression test hermetic on …
kubestellar-hive[bot] Aug 29, 2026
d1aece1
fix: give agy a working, honestly-described contributor path (#5048) …
clubanderson Aug 29, 2026
47ce8bd
fix: close ioscan canary exfiltration bypass on comment/digest/review…
clubanderson Aug 29, 2026
f1f5fa5
fix: surface the sandbox two-gate silent failure in the dashboard (#4…
clubanderson Aug 29, 2026
fad4ccc
docs: add kilo backend row and planning: block to reference docs (#5075)
clubanderson Aug 29, 2026
10ff986
🐛 fix: stop reporting a transient API error as a completed task (#5106)
Danathar Aug 29, 2026
a136e69
🐛 fix: record released contributor tasks in the activity feed (#5108)
Danathar Aug 29, 2026
a0eb5fa
🐛 fix: resolve the contributor hub from contributor.env, not just's p…
Danathar Aug 29, 2026
2e8f0da
🐛 fix: make contributor WebSocket closes diagnosable (#5107)
Danathar Aug 29, 2026
abacca0
🐛 fix: warn when the container has no usable Claude credential, and f…
Danathar Aug 29, 2026
6f6d532
[sec-check] fix: apply path-traversal guard in saveProvisionRequest (…
kubestellar-hive[bot] Aug 29, 2026
ce227c6
[quality] add unit tests for uncovered dashboard helpers (#5079)
kubestellar-hive[bot] Aug 29, 2026
82a6334
[quality] unit tests for uncovered hub, worksource and hooks helpers …
kubestellar-hive[bot] Aug 29, 2026
d13b0e7
[quality] unit tests for discord identity setters, retro eligibility,…
kubestellar-hive[bot] Aug 29, 2026
9c5eadb
[quality] unit tests for pkg/knowledge startup paths (CreateVault, au…
kubestellar-hive[bot] Aug 29, 2026
7e650c6
[quality] unit tests for cmd/hive applyConfigOverrides replay, provid…
kubestellar-hive[bot] Aug 29, 2026
c4da11e
🐛 fix: skip tracker/umbrella issues in the ready-work queue (#5105)
Danathar Aug 29, 2026
21f2142
✨ feat: tui client — governor status (T6) (#5089)
Danathar Aug 29, 2026
d797dc4
🐛 fix: ship the agent CLI's credential in the contribute-k8s workload…
Danathar Aug 29, 2026
d1bbdb0
🐛 fix: name external work items by their canonical identity in the ac…
Danathar Aug 29, 2026
7a9ca7e
✨ feat: tui poll loop — tick refresh wired through the app (T12) (#5101)
Danathar Aug 29, 2026
22c52b9
docs: add telemetry/operations agent pages, examples, and getting-sta…
clubanderson Aug 29, 2026
0575502
🐛 fix: dispatch docker.yml explicitly so the release scratch-branch g…
clubanderson Aug 29, 2026
b1ac027
[sec-check] fix: gate kilo local mode behind HIVE_KILO_DANGEROUSLY_RU…
kubestellar-hive[bot] Aug 29, 2026
eba300d
✨ feat: tui tokens pane — per-agent rows and fleet total (T9) (#5095)
Danathar Aug 29, 2026
3d00395
🐛 fix(changelog): remove #5041 duplicates and collapse repeated headi…
clubanderson Aug 29, 2026
cca01de
🐛 fix: an unrecognised API error is not a completed task either (#5125)
Danathar Aug 29, 2026
6c1113d
🧹 refactor: consolidate taskDescOf onto assignDesc now that both exis…
Danathar Aug 29, 2026
8440640
fix(tui): normalize splash-frame race in TestGridGolden (#5131)
clubanderson Aug 29, 2026
884733c
fix(hub): synchronize F20 retry test on read-attempt boundary (#5132)
clubanderson Aug 29, 2026
7c23e47
📖 docs(wiki): remove the phantom Tester agent, point at quality inste…
clubanderson Aug 29, 2026
681b782
📖 docs(beads): document bd decompose (#5175)
clubanderson Aug 30, 2026
7c55f9f
📖 docs(wiki): add the missing quality, guide, and brainstorm agents (…
clubanderson Aug 30, 2026
60bcc4b
docs: document CEL-based agent triggers (triggers: config key) (#5185)
clubanderson Aug 30, 2026
e421911
📖 docs(tui): document hivectl tui, refresh the stale contract-status …
clubanderson Aug 30, 2026
f5b6563
✨ feat(tui): render agents pane (#5133)
Danathar Aug 30, 2026
3173943
✨ feat(tui): parse SSE event stream (#5140)
Danathar Aug 30, 2026
f2d9b1b
✨ feat(tui): render governor pane (#5141)
Danathar Aug 30, 2026
85c17a5
✨ feat: tui client token usage (T8) (#5143)
Danathar Aug 30, 2026
2288bad
✨ feat: tui client events feed (T10) (#5144)
Danathar Aug 30, 2026
b0586d7
✨ feat(tui): render events scrollback (T11) (#5146)
Danathar Aug 30, 2026
8a61e7c
✨ feat(tui): help overlay on `?` (#4907 T23) (#5155)
Danathar Aug 30, 2026
d7b2b61
✨ feat: tui resize handling + minimum-size message (T24) (#5157)
Danathar Aug 30, 2026
482073b
📖 docs(tui): repair the three anchors my heading rename broke (#5206)
clubanderson Aug 30, 2026
02b8c53
🐛 fix(advisory): stop republishing findings under an Analyzed at stam…
Danathar Aug 30, 2026
566c1e4
[quality] make pkg/config K8s-detection tests hermetic on in-cluster …
kubestellar-hive[bot] Aug 30, 2026
b9ae896
[quality] test cmd/hive applyBudgetAlerts threshold-crossing alert wi…
kubestellar-hive[bot] Aug 30, 2026
fd94729
[quality] test cmd/hive hookwire governor mode-change emitter wiring …
kubestellar-hive[bot] Aug 30, 2026
25999c2
[quality] test cmd/hive classifyGitHubAppRepoCoverage (#4360 verdict)…
kubestellar-hive[bot] Aug 30, 2026
8269a7a
[quality] test cmd/hive intent-evidence fetchers (fetchIntentPREviden…
kubestellar-hive[bot] Aug 30, 2026
f6e9ef2
[quality] test cmd/hive review-swarm wiring (planReviewDispatch, refr…
kubestellar-hive[bot] Aug 30, 2026
388a383
[quality] test cmd/hive runEscalationSweep fix-loop escalation wiring…
kubestellar-hive[bot] Aug 30, 2026
bc9881c
[quality] test pkg/dashboard maybeRefreshToken heartbeat token-refres…
kubestellar-hive[bot] Aug 30, 2026
ab3cb81
[quality] test cmd/hive runRotationCheck provider-rotation wiring (ne…
kubestellar-hive[bot] Aug 30, 2026
b849017
[quality] test cmd/hive auto-merge sweep + duplicate-PR guard wiring …
kubestellar-hive[bot] Aug 30, 2026
2c944b8
[quality] test pkg/dashboard knowledge graph + promote handlers (#5197)
kubestellar-hive[bot] Aug 30, 2026
d20bec8
fix(dashboard): explain terminal copy controls (#5201)
Danathar Aug 30, 2026
0a8e9dc
[sec-check] fix: redact github_pat_ fine-grained PATs in contributor-…
kubestellar-hive[bot] Aug 30, 2026
ae64c0b
🧪 test: require a local posture for every backend (#5176)
Danathar Aug 30, 2026
e5a2e88
🧹 lint: fix dashboard errcheck findings (#4903 step 2/5) (#5202)
Danathar Aug 30, 2026
bace931
🐛 fix: clarify byte-exact NOTICE drift failures (#5173)
Danathar Aug 30, 2026
505b307
🐛 fix: survive the two push races that killed v4.0.1 twice (#5142) (#…
Danathar Aug 30, 2026
0a76e18
fix(github): validate PR claims before creation (#5189)
Danathar Aug 30, 2026
f930747
✨ feat(tui): client — pause/resume agent (#4907 T14) (#5152)
Danathar Aug 30, 2026
914fe5e
fix(gateway): forward API websocket upgrades (#5200)
Danathar Aug 30, 2026
7367de4
fix(contributor): allow Claude local file tools (#5169)
Danathar Aug 30, 2026
cddc95a
🐛 fix: detect idle Claude turns with background shells (#5170)
Danathar Aug 30, 2026
6f639b3
[quality] test pkg/dashboard budget history, knowledge 503 gates, act…
kubestellar-hive[bot] Aug 30, 2026
8aa41ec
✨ feat(tui): client — list available models per backend (#4907 T16) (…
Danathar Aug 30, 2026
d038931
🐛 fix(contribute): attach hints name the runtime that actually launch…
Danathar Aug 30, 2026
b43ad76
✨ feat(tui): client — ACMM level get/apply (#4907 T18) (#5209)
clubanderson Aug 30, 2026
34bb822
fix(docker): tolerate bobshell download failure, keep checksum hard-f…
clubanderson Aug 30, 2026
85ecd07
test(cmd/hive): cover writeIntentVerdicts, healGitHubAppInstallation,…
clubanderson Aug 30, 2026
21734d3
🐛 fix: stop flagging refreshable Claude tokens (#5171)
Danathar Aug 30, 2026
3e770d6
🧹 lint: fix pkg/proxy errcheck findings (#4903 step 3/5) (#5208)
clubanderson Aug 30, 2026
78d46fc
fix(lint): errcheck ratchet step 4a of 5 — pkg/hub/saas.go (108 findi…
clubanderson Aug 30, 2026
10c583f
fix(outreach): gate unsupported capability claims (#5205)
Danathar Aug 30, 2026
7e9833a
🐛 fix: triage shared red CI baselines (#5187)
Danathar Aug 30, 2026
c4b2458
✨ feat(tui): adaptive light/dark theme (#4907 T25) (#5158)
Danathar Aug 30, 2026
482094f
fix(lint): errcheck ratchet step 4b of 5 — pkg/hub remainder (116 fin…
clubanderson Aug 30, 2026
b260a9b
🐛 fix: require guide command verification (#5177)
Danathar Aug 30, 2026
c428522
📖 docs(bin): index the six undocumented scripts (#5239)
clubanderson Aug 31, 2026
7b76745
docs: add reference pages for hive-merge.sh and hive-open-issue.sh (#…
clubanderson Aug 31, 2026
ead0845
docs: name Podman in the non-Kubernetes config branch (#5221)
Danathar Aug 31, 2026
74a7ddb
docs: Setup URL is browser-resolved and optional (#5233)
Danathar Aug 31, 2026
1c2c255
[quality] fix hermeticity: redirect Copilot token path in TestCovB_Co…
kubestellar-hive[bot] Aug 31, 2026
2cffb4e
[quality] cover four 0%-covered exported functions: agent.SetKickLogD…
kubestellar-hive[bot] Aug 31, 2026
554ad18
✨ feature(tui): pause/resume keybinding and confirmation modal (#5231)
Danathar Aug 31, 2026
e6cdef6
📖 docs(bin): link the three hive-* wrapper rows to their reference pa…
clubanderson Aug 31, 2026
42fab74
📖 docs(bin): index the 9 missing regression test scripts (#5255)
clubanderson Aug 31, 2026
f302bab
📖 docs(backends): add the missing litellm row (#5264)
clubanderson Aug 31, 2026
291961f
build(deps): Bump debian from `abd67ff` to `8820086` in /src (#5244)
dependabot[bot] Aug 31, 2026
7c63b20
build(deps): Bump anchore/sbom-action from 0.20.9 to 0.24.2 (#5245)
dependabot[bot] Aug 31, 2026
a2c7aad
build(deps): Bump node from `4ebb5ac` to `c075312` in /src (#5246)
dependabot[bot] Aug 31, 2026
f502d6a
build(deps): Bump go.opentelemetry.io/otel/sdk in /src (#5249)
dependabot[bot] Aug 31, 2026
92cd524
fix(github): keep agent metadata out of content (#5198)
Danathar Aug 31, 2026
526c886
[ci-maintainer] fix: ignore cel-go and teatest in dependabot gomod up…
kubestellar-hive[bot] Aug 31, 2026
0bbb3a2
🐛 fix(agent): remove unsafe level suffix helper (#5268)
Danathar Aug 31, 2026
b43816f
fix(dashboard): add Podman onboarding path (#5270)
Danathar Aug 31, 2026
484c657
🐛 fix(advisory): stop no-provenance cached replays refreshing stale-b…
Danathar Aug 31, 2026
39b74d8
feat(tui): add kick agent client call (#5266)
Danathar Aug 31, 2026
9c67997
✨ feature(tui): attach to local agent tmux sessions (#5267)
Danathar Aug 31, 2026
42dab98
[quality] tests: cover 0%-covered funcs in pkg/dashboard, pkg/advisor…
kubestellar-hive[bot] Aug 31, 2026
00e2c75
[quality] tests: cover su-exec helpers writeFileAsUser and healForeig…
kubestellar-hive[bot] Aug 31, 2026
c2b8d1d
[quality] tests: cover pkg/github PR-request hook helpers at 0% (#5257)
kubestellar-hive[bot] Aug 31, 2026
0b1b9cc
[quality] tests: cover pkg/dashboard viewer-identity resolvers and ob…
kubestellar-hive[bot] Aug 31, 2026
295849f
[quality] tests: cover pkg/dashboard requestRoleAllowsOwner, converge…
kubestellar-hive[bot] Aug 31, 2026
20327e9
[quality] tests: cover pkg/hub helpers defaultHostForKind, generation…
kubestellar-hive[bot] Aug 31, 2026
9cc7153
🐛 fix(notice): regenerate after the otel 1.46.0 bumps (#5275)
clubanderson Aug 31, 2026
ba0bf0c
📄 docs(design): evaluate the handoff path for the re-entrant turn mod…
Danathar Aug 31, 2026
4395c31
🐛 fix(test): remove duplicate TestConfiguredDossierCacheMaxEntries (#…
clubanderson Aug 31, 2026
bd87feb
📖 docs(development): document NOTICE regeneration (#5285)
clubanderson Aug 31, 2026
beb6256
🐛 fix(notice): strip the one trailing space CI's generator does not e…
clubanderson Aug 31, 2026
0ba614a
🐛 fix(github): an agent-filed issue no longer authorizes an agent-fil…
Danathar Aug 31, 2026
08505da
🐛 fix(release): merge scratch-branch release commit via PR instead of…
clubanderson Aug 31, 2026
9c57146
docs: gate src/docs/ links, fix stale anchors (#5258) (#5278)
clubanderson Aug 31, 2026
30d28cd
🐛 fix(contributor): decide pane presence by client activity, not by c…
Danathar Aug 31, 2026
6acf8c9
🧪 test(dashboard): make the snapshot pipeline testable (#5235) (#5289)
clubanderson Aug 31, 2026
be2630f
✨ feat(contributor): remind an unattended agent to proceed on its own…
Danathar Aug 31, 2026
34322d4
🐛 fix(ci): classify docs-link-check.yml in the release-lines manifest…
clubanderson Aug 31, 2026
3cb2816
fix(pushbroker): strip trailing blank lines at EOF before push (#5282)
clubanderson Aug 31, 2026
1a614dd
🐛 fix(ci): retry the Quadlet gate's image pull instead of failing on …
Danathar Aug 31, 2026
e8f3899
🐛 fix(governor): the login detector must consult the credential, not …
Danathar Aug 31, 2026
27fb454
build(deps): Bump go.opentelemetry.io/otel/exporters/otlp/otlptrace/o…
dependabot[bot] Aug 31, 2026
d7d5201
🐛 fix(github): stop filing a PR whose content an open PR already carr…
Danathar Aug 31, 2026
1f411dc
✨ tui T13b: wire SSE into the app, keep the poll as fallback (#5300)
Danathar Aug 31, 2026
aa019b2
🐛 fix(contribute-ws): send real WebSocket Ping frames so proxies stop…
clubanderson Aug 31, 2026
6313b46
🐛 fix(dashboard): report the real HTTP failure when a kick response i…
clubanderson Aug 31, 2026
c6fba3d
🐛 fix(hub): stop showing "queued for auto-upgrade" on hives the hub r…
clubanderson Aug 31, 2026
d965073
📖 docs(wiki): make getting-started an actual onboarding path (#5308)
clubanderson Aug 31, 2026
46d1e0a
Merge pull request #5310 from kubestellar/fix/5090-contributor-ws-flap
kubestellar-prow[bot] Aug 31, 2026
f47d2e1
🔧 fix(ci): stop the NOTICE gate from blocking every Dependabot gomod …
clubanderson Aug 31, 2026
13191a5
📖 docs: cover GitLab, Gitea, and Forgejo app setup alongside GitHub (…
clubanderson Aug 31, 2026
4b10e4d
🐛 fix(hub): refuse manual upgrades a spoke cannot collect (#5314)
clubanderson Aug 31, 2026
d0a9276
🐛 fix(dashboard): make copying out of the terminal work, and report i…
clubanderson Aug 31, 2026
bb52796
✨ skills: inject registry skills into agent kicks (#5313)
clubanderson Aug 31, 2026
a801f33
🔧 fix(ci): validate wiki links against the deployed flat layout
clubanderson Aug 31, 2026
8e66edc
Merge pull request #5330 from kubestellar/fix/5309-wiki-link-check
kubestellar-prow[bot] Aug 31, 2026
2264940
🔧 fix(release): merge on SHA evidence instead of the tide-blocked mer…
clubanderson Aug 31, 2026
3bff611
🌱 test(agent): make the agy launch test hermetic (#5332)
clubanderson Aug 31, 2026
b31779e
📖 docs(hub): correct two comments describing forge delivery that does…
clubanderson Aug 31, 2026
31640cc
🐛 fix(contributor): make the task deadline bound hangs, not duration …
clubanderson Aug 31, 2026
7a0faa5
🐛 fix(contribute-ws): stop a reconnect releasing the task it just res…
clubanderson Aug 31, 2026
8fc60ed
🐛 fix(dashboard): stop reporting a succeeding kick as a 504 failure (…
clubanderson Aug 31, 2026
98032f8
🐛 fix: pass the stored forge kind through pendingForgeAPIURL (#5341)
clubanderson Aug 31, 2026
6ddf9a0
fix(config): persist PVC runtime config and dashboard overlay with 06…
kubestellar-hive[bot] Aug 31, 2026
994930f
fix(dashboard): vet model auto-heal targets instead of pinning availa…
clubanderson Aug 31, 2026
2ae69e0
🐛 Reap orphaned Terminating spoke pods (#5328) (#5345)
clubanderson Aug 31, 2026
5e002f1
🔧 fix(release): re-register the release workflow and add a release ba…
clubanderson Aug 31, 2026
fe85399
🔒 fix(entrypoint): harden runtime config recreated by cp at boot (#53…
clubanderson Aug 31, 2026
cf01f18
🐛 fix(hub): L3-L5 verdict — held PRs awaiting review are amber, not '…
clubanderson Aug 31, 2026
d781297
🐛 fix(governor): conflicting PRs are not merge-eligible (#5351)
clubanderson Aug 31, 2026
265510f
🐛 Install the git credential helper system-wide so agents can push (#…
clubanderson Aug 31, 2026
fb38361
🐛 fix(release): remove the empty expression that broke workflow regis…
clubanderson Aug 31, 2026
e9b8c14
🐛 fix(release): stop the release PR superseding its own green gate ch…
clubanderson Aug 31, 2026
e00214b
🐛 fix(release): stop the gate-earning build from blocking the release…
clubanderson Aug 31, 2026
d12ed62
🐛 fix(release): revert the incorrect gate skip and record the real bl…
clubanderson Aug 31, 2026
c9a6d3e
🐛 fix(entrypoint): chown the runtime config to dev so hive can read i…
clubanderson Aug 31, 2026
4a500a1
🐛 fix(release): re-earn gate after opening the release PR (#5356) (#5…
clubanderson Aug 31, 2026
765f063
✨ feat(forge): put the governor's escalation writes behind pkg/forge …
Danathar Aug 31, 2026
bcab144
✨ feat(scheduler): thread a per-repo checkout root so AGENTS.md injec…
Danathar Aug 31, 2026
a22f8f7
✨ feat(acmm): attach level-up advice to status payload and thread a r…
clubanderson Aug 31, 2026
af6001b
🐛 fix(contributor-relay): stop the agent and drop its token on every …
clubanderson Aug 31, 2026
7d0afff
Merge pull request #5372 from kubestellar/feat/5225-acmm-advisor-signals
kubestellar-prow[bot] Aug 31, 2026
db613df
fix: restore the /data ownership invariant (#5369) and make the arm64…
clubanderson Aug 31, 2026
d28335a
🐛 fix(hub): preserve forge kind in heartbeat API URLs (#5377)
Danathar Aug 31, 2026
52a3592
🐛 fix: repair renamed-agent CODEX_HOME by chowning in place, not os.R…
clubanderson Aug 31, 2026
c93cc2e
🐛 relay: complete tasks on an agent-emitted verdict, not terminal chrome
clubanderson Aug 31, 2026
5054ecc
Merge pull request #5382 from kubestellar/fix/5379-codex-home-heal-nfs
kubestellar-prow[bot] Aug 31, 2026
04f6dbe
test: run the entrypoint behavioural suites in the container lane, an…
clubanderson Aug 31, 2026
f5118ee
Merge pull request #5385 from kubestellar/feat/5376-real-completion-s…
kubestellar-prow[bot] Aug 31, 2026
ea0b14b
🐛 fix(dashboard): correct openapi.json drift for /api/status, /api/to…
clubanderson Aug 31, 2026
d1881f6
fix(hub): drain contributor WebSockets with 1012 on SIGTERM
clubanderson Aug 31, 2026
5380db3
feat(hub): surface stuck-pod count per namespace in fleet health (#53…
clubanderson Aug 31, 2026
fbd1d4d
Merge pull request #5394 from kubestellar/fix/5390-sigterm-drain-cont…
kubestellar-prow[bot] Aug 31, 2026
9013b44
Merge pull request #5396 from kubestellar/feat/5328-orphan-visibility
kubestellar-prow[bot] Aug 31, 2026
2db7458
fix(hub): debounce merge-driven self-upgrade so a burst rolls once
clubanderson Aug 31, 2026
168771b
🐛 close two path-filter exemptions and three shape-vs-property assert…
clubanderson Aug 31, 2026
29b8481
✨ skills: resolve agent skills from repo fallback (#5387)
Danathar Aug 31, 2026
6f30298
✨ ux: show the terminal copy control only for login URLs, and name it…
clubanderson Aug 31, 2026
520dbfc
fix(hub): bound the debounce hold so a busy branch cannot starve upgr…
clubanderson Aug 31, 2026
2dfda39
fix(hub): key debounce staleness on provenance, not elapsed time
clubanderson Aug 31, 2026
d0ecc2b
Merge pull request #5399 from kubestellar/fix/5391-self-upgrade-debounce
kubestellar-prow[bot] Aug 31, 2026
3c3d8f3
docs(env-vars): correct the reference and add a drift guard (#5409)
clubanderson Sep 1, 2026
231ca4b
🐛 fix(inference): litellm route falls back to the explicit gateway en…
clubanderson Sep 1, 2026
09b00b0
📝 docs: document the real CI test flags and the relay token lifecycle
kubestellar-ci-bot Sep 1, 2026
92c4b6e
Merge pull request #5445 from kubestellar/docs/5442-5443-dev-and-rela…
kubestellar-prow[bot] Sep 1, 2026
ccb1885
fix(release): mirror gate as a commit status (#5457)
Danathar Sep 1, 2026
e4bef31
🧪 ci: trigger v2 test guards on guarded files (#5388) (#5397)
Danathar Sep 1, 2026
ff7da41
🐛 fix: stop pinning claude agents to a boot-time access token (#5455)
Danathar Sep 1, 2026
c3b2251
[quality] 🧪 test(config): make entrypoint boot-prelude tests hermetic…
kubestellar-hive[bot] Sep 1, 2026
9c93782
[quality] 🧪 test: cover CheckoutRootFor traversal guard and terminal-…
kubestellar-hive[bot] Sep 1, 2026
a6b57db
[quality] 🧪 test(tui): cover the zero-covered attach error types, Kic…
kubestellar-hive[bot] Sep 1, 2026
4991d1e
✨ feat(tui): kick selected agent from TUI (#5450)
Danathar Sep 1, 2026
a9ce194
feat(tui): add set agent model client (#5451)
Danathar Sep 1, 2026
06f9caf
✨ feat: tui client estimated token cost (T28) (#5453)
Danathar Sep 1, 2026
41183e1
✨ feat(tui): add hive display identity client (#5456)
Danathar Sep 1, 2026
5d8d0f4
✨ dashboard: offer Google Antigravity models (#5410)
Danathar Sep 1, 2026
f0e6fd7
🧪 test(inference): extract and cover the litellm route resolution (#5…
clubanderson Sep 1, 2026
ab81f6f
[quality] 🧪 test(agent): stop config token tests writing live /data/h…
kubestellar-hive[bot] Sep 1, 2026
3349c06
Merge pull request #5462 from kubestellar/test/5460-litellm-gateway-f…
kubestellar-prow[bot] Sep 1, 2026
0b3db2a
🔖 release: v4.0.1
actions-user Sep 1, 2026
76eb854
Merge pull request #5465 from kubestellar/release-gate/v4.0.1
github-actions[bot] Sep 1, 2026
8948f99
Merge tag v4.0.1 into v5 (top-up with latest 4.0.0/4.0.1 line)
clubanderson Sep 1, 2026
5a525eb
fix v5-side CI fallout from the v4.0.1 top-up
clubanderson Sep 1, 2026
d6ea05b
docs(openapi): document the v5 approvals routes for the route-parity …
clubanderson Sep 1, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
8 changes: 8 additions & 0 deletions .github/dependabot.yml
Original file line number Diff line number Diff line change
Expand Up @@ -8,6 +8,14 @@ updates:
labels:
- "dependencies"
open-pull-requests-limit: 10
ignore:
# Module path moved upstream to cel.dev/cel-go (v0.26.0+); dependabot
# reports go_module_path_mismatch and fails the whole gomod job.
# Remove once /src/go.mod migrates to the new module path.
- dependency-name: "github.com/google/cel-go"
# teatest lives in a nested module with independent tags; resolving
# github.com/charmbracelet/x@v0.1.0 fails (dependency_file_not_resolvable).
- dependency-name: "github.com/charmbracelet/x/exp/teatest"

- package-ecosystem: "github-actions"
directory: "/"
Expand Down
5 changes: 5 additions & 0 deletions .github/release-lines.yml
Original file line number Diff line number Diff line change
Expand Up @@ -46,6 +46,11 @@ pinned:
# release lines and nothing else: a feature branch gets the same gate through
# `pull_request`, and running it on every pushed branch would burn runner
# minutes re-scanning code that has not reached a release line.
# Added with the docs link checker (#5278), after the v2 line was sunset
# (#5030-era). It gates src/docs/ links on v4 only; v2 is excluded rather
# than back-filled, because the workflow never ran there and adding it
# would gate a line no longer taking doc changes.
docs-link-check.yml: [-v2]
go-security-analysis.yml: []
podman-arm64-lane.yml: []
podman-contract.yml: []
Expand Down
12 changes: 12 additions & 0 deletions .github/workflows/dashboard-lint.yml
Original file line number Diff line number Diff line change
@@ -1,11 +1,23 @@
name: Dashboard Lint

# The checker itself is in scope, not just the files it checks (#5388).
# The syntax-check job runs .github/scripts/check-inline-js.js, but the filter
# named only 'dashboard/**' — so a change that broke the checker (or silently
# stopped it detecting anything) ran no CI at all, and the next dashboard PR
# would then pass against a checker nobody had exercised. The workflow file is
# listed for the same reason: an edit to the `find` invocation here changes
# what gets checked, and that edit must run the job it changes.
on:
push:
paths:
- 'dashboard/**'
- '.github/scripts/check-inline-js.js'
- '.github/workflows/dashboard-lint.yml'
pull_request:
paths:
- 'dashboard/**'
- '.github/scripts/check-inline-js.js'
- '.github/workflows/dashboard-lint.yml'

permissions:
contents: read
Expand Down
92 changes: 82 additions & 10 deletions .github/workflows/docker.yml
Original file line number Diff line number Diff line change
Expand Up @@ -62,6 +62,26 @@ jobs:
# merges and is deleted. workflow_dispatch always pushes so a throwaway branch
# can be published for a hive on demand before merge.
#
# EXCEPTION: `release-gate/*` (#5072). tagged-release.yml pushes its
# release commit to a throwaway `release-gate/v<version>` branch to earn a
# `gate` check on
# that exact SHA before pushing to protected `v4` (see docs/releases.md,
# "Satisfying branch protection"). That push uses the job's default
# GITHUB_TOKEN, and GitHub's documented recursive-workflow guard means a
# GITHUB_TOKEN push never fires another workflow's `push` trigger — so
# tagged-release.yml has to fall back to explicitly dispatching this
# workflow via `gh workflow run docker.yml --ref release-gate/v<version>`
# instead. Without
# this exception, that dispatch would hit the `workflow_dispatch` branch
# below and force push=true on a branch nothing should ever publish images
# for: a full two-platform GHCR push under a one-off scratch branch name,
# solely to obtain a status check that only needs `gate` (a five-second job)
# to run. `release-gate/*` branches are deliberately never in LONG_LIVED and
# are deleted immediately after use (tagged-release.yml's `trap ... EXIT`),
# so this
# exception cannot leave a stray moving tag behind — it only ever prevents
# one from being created in the first place.
#
# The long-lived branch set is defined ONCE below (LONG_LIVED). To add or
# remove one, edit only that list — the whole workflow derives from this job's
# output, so nothing else changes.
Expand All @@ -71,6 +91,14 @@ jobs:
# new release line and never publish its <branch>-latest tag (#4462). The
# release-line guard asserts this list against .github/release-lines.yml —
# see the `env_lists` entry there and src/docs/release-line-guard.md.
#
# NOTE (#5339/#5356): do not special-case `release-gate/*` pull requests in
# this job. GITHUB_TOKEN-opened release PR runs may be recursion-blocked
# before any job starts, and workflow_dispatch check-runs are not associated
# with a PR even when dispatched after it exists. tagged-release.yml handles
# that release-only gap by mirroring its verified check-run as a SHA-scoped
# commit status. Ordinary pull requests still need this job unchanged so
# their head SHA receives the required `gate` check-run (#4965).
gate:
runs-on: ubuntu-latest
outputs:
Expand All @@ -90,13 +118,24 @@ jobs:
EVENT: ${{ github.event_name }}
run: |
push=false
if [ "$EVENT" = "workflow_dispatch" ]; then
push=true
else
for b in $LONG_LIVED; do
if [ "$b" = "$REF_NAME" ]; then push=true; break; fi
done
fi
case "$REF_NAME" in
release-gate/*)
# See the EXCEPTION comment above this job: this scratch branch
# only ever exists to earn a `gate` check for
# tagged-release.yml, never to publish an image, regardless of
# trigger event.
push=false
;;
*)
if [ "$EVENT" = "workflow_dispatch" ]; then
push=true
else
for b in $LONG_LIVED; do
if [ "$b" = "$REF_NAME" ]; then push=true; break; fi
done
fi
;;
esac
echo "push=$push" >> "$GITHUB_OUTPUT"
echo "Push to GHCR: $push (branch=$REF_NAME event=$EVENT)"

Expand All @@ -109,7 +148,22 @@ jobs:
# real `hive --version` smoke test (`docker`), plus `build-and-test`
# (go build + go vet) and `overlayfs-exec-guard`. Building here too would
# be a third image build of the same commit.
if: github.event_name != 'pull_request'
# `release-gate/*` is excluded for the same reason `merge*` already skips
# it (gate forces push=false there): these builds publish NOTHING for the
# scratch branch. They are not merely wasted — branch protection evaluates
# the whole check SUITE, so while any job in it runs the `gate` context is
# not treated as satisfied even though its check-run is already `success`.
# The release job's merge waits 120s and a multi-arch build takes ~10min,
# so the merge could never win that race (#5339, 8th recurrence).
#
# No coverage is lost. A release commit modifies CHANGELOG.md and nothing
# else — no source, no Dockerfile — so its tree is byte-identical to the v4
# tip whose images this workflow already built, published and freshness-
# checked minutes earlier. The `gate` job itself still runs on the scratch
# branch; that is the whole reason the branch exists.
if: >-
github.event_name != 'pull_request' &&
!startsWith(github.ref_name, 'release-gate/')
strategy:
matrix:
include:
Expand Down Expand Up @@ -344,7 +398,16 @@ jobs:
build-contributor:
needs: gate
# Push-only, same as `build` above (#4965).
if: github.event_name != 'pull_request'
# `release-gate/*` is excluded for the same reason `merge*` already skips
# it (gate forces push=false there): these builds publish NOTHING for the
# scratch branch. They are not merely wasted — branch protection evaluates
# the whole check SUITE, so while any job in it runs the `gate` context is
# not treated as satisfied even though its check-run is already `success`.
# The release job's merge waits 120s and a multi-arch build takes ~10min,
# so the merge could never win that race (#5339, 8th recurrence).
if: >-
github.event_name != 'pull_request' &&
!startsWith(github.ref_name, 'release-gate/')
strategy:
matrix:
include:
Expand Down Expand Up @@ -442,7 +505,16 @@ jobs:
build-hub:
needs: gate
# Push-only, same as `build` above (#4965).
if: github.event_name != 'pull_request'
# `release-gate/*` is excluded for the same reason `merge*` already skips
# it (gate forces push=false there): these builds publish NOTHING for the
# scratch branch. They are not merely wasted — branch protection evaluates
# the whole check SUITE, so while any job in it runs the `gate` context is
# not treated as satisfied even though its check-run is already `success`.
# The release job's merge waits 120s and a multi-arch build takes ~10min,
# so the merge could never win that race (#5339, 8th recurrence).
if: >-
github.event_name != 'pull_request' &&
!startsWith(github.ref_name, 'release-gate/')
strategy:
matrix:
include:
Expand Down
81 changes: 81 additions & 0 deletions .github/workflows/docs-link-check.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,81 @@
name: Docs Link Check

# Why this exists
#
# kubestellar/docs (the org's published docs site, Next.js on Netlify at
# kubestellar.io/docs/hive/*) pulls a growing subset of src/docs/*.md straight
# from this repo's `v4` branch on every site build
# (kubestellar/docs:scripts/sync-hive-docs.ts fetches the raw file over HTTP
# and rewrites relative links to site routes or GitHub blob URLs). That sync
# runs no Markdown linter and no link checker of its own — it trusts this
# source tree to already be internally consistent.
#
# That trust broke concretely once already: #5206 fixed three cross-reference
# anchors that a heading rename in design/tui.md had silently broken. Nothing
# failed red when it happened; a human had to notice. This job is the gate
# that catches the same class of break before merge, for every relative link
# and heading anchor inside src/docs/ — whether or not the file happens to be
# on the sync manifest today, since that manifest only grows over time.
#
# It intentionally does NOT validate http(s)/mailto links (network-dependent,
# and not what broke in #5206) and does not touch the sync manifest itself,
# which lives in the separate kubestellar/docs repository.
#
# The job also guards a second, differently-shaped surface: the wiki vault at
# src/deploy/data/wiki/. src/Dockerfile bakes that tree into the image and
# src/deploy/entrypoint.sh seeds it with `cp -rn /opt/hive/seed-data/* /data/`,
# so it is served FLAT from /data/wiki/ with nothing above it. A parent-
# relative link there resolves for a reviewer browsing this repo and 404s for
# the operator reading the deployed page — the repo view is the one that lies,
# which is what makes the break invisible in review (#5309). The wiki step
# therefore runs --vault-root, which treats the vault directory as the reader's
# whole filesystem and rejects any escape regardless of what exists in this
# checkout. Outbound wiki references belong in absolute blob/v4 URLs, which
# resolve identically in both views (#5308).

on:
push:
branches:
- v4
- v5
paths:
- 'src/docs/**'
- 'src/deploy/data/wiki/**'
- 'src/scripts/check-docs-links.py'
- 'src/scripts/test-check-docs-links.sh'
- '.github/workflows/docs-link-check.yml'
pull_request:
branches:
- v4
- v5
paths:
- 'src/docs/**'
- 'src/deploy/data/wiki/**'
- 'src/scripts/check-docs-links.py'
- 'src/scripts/test-check-docs-links.sh'
- '.github/workflows/docs-link-check.yml'

permissions:
contents: read

jobs:
link-check:
name: relative links and anchors resolve
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1

- name: Self-test the checker against fixtures
run: bash src/scripts/test-check-docs-links.sh

- name: Check src/docs/ relative links and anchors
run: python3 src/scripts/check-docs-links.py src/docs

# The wiki vault is checked in --vault-root mode, which models the
# DEPLOYED layout rather than this checkout. See the header comment and
# check-docs-links.py's docstring: /data/wiki/ has nothing above it, so a
# parent-relative link is rejected here even when the target exists in
# the repo. Running the plain checker against this tree would pass
# exactly the links that are broken in production (#5309).
- name: Check wiki vault links against the deployed flat layout
run: python3 src/scripts/check-docs-links.py src/deploy/data/wiki --vault-root
66 changes: 56 additions & 10 deletions .github/workflows/go-security-analysis.yml
Original file line number Diff line number Diff line change
Expand Up @@ -36,13 +36,22 @@ name: Go Security Analysis
# correct and complete attribution. See that job's own comment for the full
# reasoning.

# NOTICE is in the path filter because the notice-drift job below compares the
# COMMITTED repo-root NOTICE byte-for-byte against a fresh regeneration
# (`check-notice-drift.sh NOTICE /tmp/NOTICE.generated`). NOTICE does not live
# under src/, so before #5388 a PR editing NOTICE alone — hand-correcting an
# attribution, or reverting the autofix commit — changed the exact file this
# gate polices while running neither that gate nor anything else. The drift
# would surface only on the next unrelated src/ change, attributed to that PR.
# Same shape as dashboard/openapi.json in v2-tests.yml: guarded by a job whose
# filter excluded it.
on:
push:
branches: [v2, v4, v5]
paths: ['src/**', '.github/workflows/**', '.github/release-lines.yml']
paths: ['src/**', 'NOTICE', '.github/workflows/**', '.github/release-lines.yml']
pull_request:
branches: [v2, v4, v5]
paths: ['src/**', '.github/workflows/**', '.github/release-lines.yml']
paths: ['src/**', 'NOTICE', '.github/workflows/**', '.github/release-lines.yml']
schedule:
# Weekly, so a newly-PUBLISHED advisory against unchanged code is still
# found. A push-only trigger cannot catch that: the vulnerability appears
Expand Down Expand Up @@ -145,7 +154,7 @@ jobs:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1

# A fabricated 40-hex SHA looks exactly like a correct pin and is only
# caught when the workflow RUNS. release.yml shipped one (#4908), so every
# caught when the workflow RUNS. tagged-release.yml shipped one (#4908), so every
# tagged release failed at "Prepare all required actions" — discovered
# only when someone tried to cut a release.
- name: Check every pinned action SHA exists
Expand Down Expand Up @@ -185,6 +194,16 @@ jobs:
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1

- name: Exercise NOTICE drift diagnostics
run: src/scripts/test-check-notice-drift.sh

# The autofix workflow commits a generated NOTICE unattended, so the
# guard that decides whether a generated file is fit to commit needs its
# own regression coverage here — notice-autofix.yml runs on
# workflow_run and cannot gate a PR itself.
- name: Exercise generated-NOTICE validation
run: src/scripts/test-validate-generated-notice.sh

- uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0
with:
go-version: '1.25'
Expand All @@ -193,11 +212,38 @@ jobs:
- name: Regenerate NOTICE from the current module graph
run: src/scripts/generate-notice.sh /tmp/NOTICE.generated

# Publish the regenerated file BEFORE the gate runs, so it is uploaded
# on the failing path too — that is the only path where anyone needs it.
# notice-autofix.yml consumes this artifact via workflow_run to commit
# the regeneration back onto a Dependabot branch (#5256). Uploading here
# rather than regenerating in the autofix workflow is deliberate: this
# job already runs the generator with a read-only token and no secrets,
# so the privileged workflow never has to execute PR-head code.
- name: Publish the regenerated NOTICE for the autofix workflow
if: github.event_name == 'pull_request'
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
with:
name: notice-generated
path: /tmp/NOTICE.generated
retention-days: 1
if-no-files-found: error

# The PR number travels with the artifact because workflow_run does not
# expose it: the triggering run's event payload is not forwarded, and
# resolving head SHA back to a PR is an extra API round trip that can
# match the wrong PR when several share a head.
- name: Record the PR number for the autofix workflow
if: github.event_name == 'pull_request'
run: echo "${{ github.event.pull_request.number }}" > /tmp/pr-number.txt

- name: Publish the PR number for the autofix workflow
if: github.event_name == 'pull_request'
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
with:
name: notice-pr-number
path: /tmp/pr-number.txt
retention-days: 1
if-no-files-found: error

- name: Fail if the committed NOTICE is stale
run: |
set -euo pipefail
if ! diff -u NOTICE /tmp/NOTICE.generated; then
echo "::error::NOTICE is out of date with src/go.mod / src/go.sum. Run 'src/scripts/generate-notice.sh' locally (requires a Go toolchain) and commit the regenerated NOTICE." >&2
exit 1
fi
echo "NOTICE matches the current module graph."
run: src/scripts/check-notice-drift.sh NOTICE /tmp/NOTICE.generated
2 changes: 1 addition & 1 deletion .github/workflows/image-attestation-guard.yml
Original file line number Diff line number Diff line change
Expand Up @@ -16,7 +16,7 @@ name: Image Attestation Guard
# branch-pinned, and the path filter below is what keeps it cheap.
#
# Release SBOMs (added in the same change that added this guard) are
# deliberately NOT part of this workflow — release.yml's SBOM step runs
# deliberately NOT part of this workflow — tagged-release.yml's SBOM step runs
# against an already-published image digest and produces a standalone file
# attached to the GitHub Release, never an in-image attestation. See
# src/docs/releases.md, "Software bill of materials (SBOM)".
Expand Down
Loading
Loading