Commit Graph
4805 Commits
Author SHA1 Message Date
Tam Nhu Tran f4911694e3 fix(websearch): filter disabled legacy CLI probes and skip unused version fetching
Closes #1716
2026-08-25 15:35:54 -04:00
github-actions[bot] 65dc902299 chore(release): 8.9.0-dev.5 2026-08-25 18:54:51 +00:00
Kai (Tam Nhu) Tran a5aa9ac35f Merge pull request #1717 from mardausdennis/feat/collapsible-proxy-status-widget
feat(dashboard): collapse the CLIProxy status widget
2026-08-25 14:50:28 -04:00
Kai (Tam Nhu) Tran ff27a36b92 Merge pull request #1718 from sgaluza/fix/adopt-settings-publish-by-replacement
fix(shared-manager): publish adopted settings by replacement
2026-08-25 14:50:19 -04:00
Sergey Galuza 4a17f034e2 docs(shared-manager): note why the CAS mismatch raises EEXIST
The code is this file's marker for "a race was detected" - the same one
the reappeared-path and concurrent-replacement guards raise - not a
report that a no-replace link() or open('wx') hit an existing path. Say
so at the throw, so debugging by err.code does not send anyone looking
for a no-replace failure that never happened.

Built [OnSteroids](https://onsteroids.ai)
2026-08-23 08:33:06 +02:00
Sergey Galuza df52662a59 refactor(shared-manager): extract the durable temp write
createFileNoReplace and publishCanonicalContent carried the same
open-wx / fchmod / write / fsync / close block and the same cleanup
handler. Extract writeDurableTempFile and discardTempFile so each
publisher is left with only what distinguishes it: a no-replace link, or
the compare-and-swap guard and the rename.

Also spell out in publishCanonicalContent that its guard is read-then-act
rather than atomic. POSIX has no compare-and-swap rename, so the window
is narrowed from the ~100 ms the old claim-and-republish path left open
to two adjacent syscalls, not closed - and the pre-image sidecar is what
keeps that last outcome recoverable. Worth stating so the guard is not
mistaken for a strict guarantee later.

Built [OnSteroids](https://onsteroids.ai)
2026-08-23 08:32:53 +02:00
Sergey Galuza fa3fd8eb3a refactor(shared-manager): tighten canonical identity capture
Build the canonical identity from the stat getCanonicalFile already
takes, instead of a second lstat of the same inode. One syscall less,
and mode, mtime and identity now describe the same moment rather than
two adjacent ones.

Assert in the adoption race tests that the foreign writer never fired.
It writes only when the canonical path is observed empty, so a zero
count states the invariant the fix establishes - the path is never left
without a regular file - instead of only checking the final content.

Built [OnSteroids](https://onsteroids.ai)
2026-08-23 08:32:39 +02:00
Sergey Galuza 00a4dceb94 fix(shared-manager): publish adopted settings by replacement
Adoption moved the canonical settings.json aside with rename() and left
the path empty until publication, roughly 100 ms later. Claude Code or a
second `ccs` starting inside that window found no file and seeded an
empty placeholder; publication then failed with EEXIST because link() is
no-replace, and the rollback published a backup and unlinked the claim,
destroying the only remaining copy of the user's settings. Recovering
meant digging through sidecar files by hand.

Publish by replacement instead: write a temp file next to the canonical
inode and rename() it over the target, so the path always holds a regular
file and no placeholder can be seeded. A compare-and-swap guard on
(ino, mtime, size) runs immediately before the rename and refuses to
publish when the canonical inode changed since it was read, so a writer
that got there first is still never clobbered. The pre-image backup is
published before the replacement, keeping the old content recoverable if
publication is interrupted.

Drops the canonical claim entirely along with restoreCanonicalClaim, and
folds the two identical sidecar publishers into one helper.
recoverOrphanedCanonicalClaim stays, since claims written by older
versions may still be on disk.

New tests cover both writers seen in the incident: Claude Code seeding
`{}` with a trailing newline, and a second `ccs` seeding the 2-byte
variant from shared-dir-linker. Four tests that pinned the claim-based
design were rewritten, among them `preserves a canonical write that
lands during no-replace publication`, whose intent is now enforced by
the CAS guard instead of by an EEXIST from a no-replace link.

Built [OnSteroids](https://onsteroids.ai)
2026-08-23 08:32:26 +02:00
mardausdennis fde7bd83db feat(dashboard): collapse the CLIProxy status widget
ProxyStatusWidget sits outside the sidebar ScrollArea, so every row it
renders is taken from the provider list. With the proxy running and pool
routing on it renders ten stacked blocks, and the only Collapsible covers
version management, which is already closed in that state.

Add a chevron that collapses the whole widget in local and remote mode,
keeping the status row, version row and action buttons visible. The
preference is stored in localStorage and defaults to expanded, so
existing setups are unchanged. Opening version settings from a collapsed
widget expands it again.
2026-08-22 01:15:41 +02:00
github-actions[bot] a53980782f chore(release): 8.9.0-dev.4 2026-08-21 15:33:50 +00:00
Kai (Tam Nhu) Tran ae1559aeb0 fix(ci): publish dev releases with public access for scoped package (#1715) 2026-08-20 12:14:14 -04:00
Kai (Tam Nhu) Tran 95faef5960 Merge pull request #1710 from kaitranntt/kai/fix/1703-image-analysis-original-backend-route
fix(image-analysis): route original backend at CLIProxy root
2026-08-19 17:43:27 -04:00
Kai (Tam Nhu) Tran 9e2897e770 Merge pull request #1711 from kaitranntt/kai/fix/1706-pnpm-global-store-layout
fix(update): detect pnpm v9+ global store layouts
2026-08-19 17:33:49 -04:00
Tam Nhu Tran a4281cea1b docs: refresh hardening inventory after merge 2026-08-19 16:58:13 -04:00
Tam Nhu Tran 75c45b6043 merge dev: refresh hardening inventory base 2026-08-19 16:58:10 -04:00
Tam Nhu Tran c43cd6caf5 fix(update): detect pnpm v9+ global store layouts
Fixes #1706
2026-08-19 16:43:15 -04:00
Tam Nhu Tran afa663b5b2 fix(image-analysis): route original backend at CLIProxy root
Fixes #1703
2026-08-19 16:43:15 -04:00
Kai (Tam Nhu) Tran 9de6e11a03 Merge pull request #1709 from kaitranntt/kai/docs/hardening-inventory-refresh
docs: refresh hardening inventory counts
2026-08-19 16:43:07 -04:00
Tam Nhu Tran b9190a6e57 docs: refresh hardening inventory counts 2026-08-19 16:35:27 -04:00
Kai (Tam Nhu) Tran 3997dbd258 Merge pull request #1708 from aaron-tsar/fix/image-analysis-profile-backends-launch
fix(image-analysis): honor configured profile_backends at launch
2026-08-19 16:35:08 -04:00
Kai (Tam Nhu) Tran 3b652460ee Merge pull request #1707 from OctoBored/fix/star-history-chart
fix(README): update star history chart to use working domain
2026-08-19 16:34:49 -04:00
Kai (Tam Nhu) Tran 9d725fcebb Merge pull request #1702 from Marc-oss-hub/feat/orcarouter-preset
feat(api): add OrcaRouter provider preset
2026-08-19 16:32:29 -04:00
Kai (Tam Nhu) Tran 28d817a97e Merge pull request #1701 from minhbi245/feat/grok-4-6-selection
feat(cliproxy): add Grok 4.6 selection
2026-08-19 16:32:25 -04:00
Kai (Tam Nhu) Tran e10577804d Merge pull request #1704 from kaitranntt/kai/fix/delegation-stdout-flush
fix(delegation): flush stdout before exit to prevent piped output truncation
2026-08-19 16:32:20 -04:00
Aaron VuandClaude fe3447f487 fix(image-analysis): honor configured profile_backends at launch
resolveImageAnalysisRuntimeStatus defaulted to DEFAULT_IMAGE_ANALYSIS_CONFIG
when callers omitted the config argument. That constant ships empty
profile_backends and a gemini fallback_backend, so the launch paths that call
it without a config (settings profile dispatch and headless delegation) never
saw user-configured mappings.

A profile mapped to another backend still resolved to gemini, failed the
Gemini auth check, and silently dropped to native Read. Profiles whose model
has no vision support could not read images at all, even with a reachable
CLIProxy and an authenticated backend.

getImageAnalysisHookEnv already reads the saved config, so the launch env and
the runtime status disagreed on the same launch: CCS_IMAGE_ANALYSIS_BACKEND_ID
carried the mapped backend while the status object reported native-read.

Default to getImageAnalysisConfig() so both read the same source. Callers that
pass an explicit config keep their existing behavior.

Co-Authored-By: Claude <noreply@anthropic.com>
2026-08-17 15:27:02 +07:00
OctoBored 6e3a16b84c fix(README): update star history chart to use working domain
The current star history chart is broken due to GitHub stargazer API restrictions. Switch to star-history.dera.page which uses an alternative data source and requires no API token.
2026-08-17 07:37:34 +00:00
Tam Nhu Tran 3e49834c9d fix(delegation): flush stdout before exit to prevent piped output truncation
console.log followed immediately by process.exit truncated piped output
at the pipe buffer (about 64 KiB) because stdout writes to pipes are
asynchronous. Interactive TTY runs were unaffected, so the bug only
surfaced for callers consuming ccs delegation output through a pipe,
such as scripts parsing --output-format json results from thinking
heavy GLM sessions.

Await an explicit stdout write callback before exiting in both route()
and _handleContinue().
2026-08-14 17:57:39 -04:00
Marc-oss-hubandClaude ea7906b975 feat(api): add OrcaRouter provider preset
Add a named 'orcarouter' preset to the shared provider catalog mirroring
the existing OpenRouter entry: OpenAI-compatible base URL
https://api.orcarouter.ai/v1, default model openai/gpt-5.5, sk-orca-...
key placeholder, and a dashboard icon. Regenerate the throw-error
baseline for the line shift in provider-preset-catalog.ts.

Co-Authored-By: Claude <noreply@anthropic.com>
2026-08-13 22:29:17 +08:00
Khanh.NVMandClaude Fable 5 c30e9ca617 feat(cliproxy): add Grok 4.6 selection
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-08-13 16:23:24 +07:00
github-actions[bot] a0990e0ef1 chore(release): 8.9.0-dev.3 2026-08-11 02:24:22 +00:00
Kai (Tam Nhu) Tran 2ef2612df8 Merge pull request #1699 from kaitranntt/kai/fix/cliproxy-safe-updates-dev
fix(cliproxy): keep proxy continuously recoverable
2026-08-10 22:20:13 -04:00
Tam Nhu Tran 54c3e86e89 fix(docker): target live cliproxy compose stack 2026-08-10 22:13:29 -04:00
Tam Nhu Tran c8098532a6 chore(hardening): refresh source inventory 2026-08-10 22:13:29 -04:00
Tam Nhu Tran ee891bdd0e docs(docker): document host continuity 2026-08-10 22:13:29 -04:00
Tam Nhu Tran fc56ecaac4 fix(cliproxy): finish concurrent update recovery 2026-08-10 22:13:29 -04:00
Tam Nhu Tran 192b27fbb2 chore(hardening): refresh source inventory 2026-08-10 22:13:29 -04:00
Tam Nhu Tran 4502e5d503 fix(cliproxy): harden update recovery paths 2026-08-10 22:13:29 -04:00
Tam Nhu Tran 8e4def4713 fix(cliproxy): keep proxy available during updates 2026-08-10 22:13:29 -04:00
github-actions[bot] 51afccf504 chore(release): 8.9.0-dev.2 2026-08-09 04:31:15 +00:00
Kai (Tam Nhu) Tran c3abc98e39 Merge pull request #1697 from kaitranntt/kai/ci/sync-docker-smoke-fix-dev
ci: sync Docker smoke fix into dev
2026-08-09 00:26:30 -04:00
Tam Nhu Tran 8ae7dd88f3 ci: merge main Docker smoke fix into dev 2026-08-09 00:16:48 -04:00
Kai (Tam Nhu) Tran febdcdbbf4 Merge pull request #1696 from kaitranntt/kai/ci/docker-smoke-cold-start
ci(docker): allow cold-start healthcheck window
2026-08-09 00:14:23 -04:00
Tam Nhu Tran 78ad297e30 ci(docker): allow cold-start healthcheck window 2026-08-09 00:09:52 -04:00
github-actions[bot] 7c2d02f761 chore(release): 8.9.0-dev.1 2026-08-09 03:53:11 +00:00
semantic-release-bot f8a9518b17 chore(release): 8.9.0 [skip ci]
## [8.9.0](https://github.com/kaitranntt/ccs/compare/v8.8.1...v8.9.0) (2026-08-09)

### Features

* **auth:** share canonical Claude memory ([6841025](https://github.com/kaitranntt/ccs/commit/6841025bb413c5ca1c8ce8e903b55dbd5f269036)), closes [#1688](https://github.com/kaitranntt/ccs/issues/1688)
* **bar:** support --port for ccs bar with sticky port persistence ([34608ce](https://github.com/kaitranntt/ccs/commit/34608ce291fa7d763c8a949b88cd79c8074385df))
* **cliproxy:** expose model context windows ([b073261](https://github.com/kaitranntt/ccs/commit/b0732613a318e92dff2a827e9f7e67bb04184378))
* **cliproxy:** expose request retry config ([d5ea4ee](https://github.com/kaitranntt/ccs/commit/d5ea4eeea353687795856ee567f5adbc23cc8f32))
* **cliproxy:** persist scoped routing rules ([9fb2016](https://github.com/kaitranntt/ccs/commit/9fb2016f9012466afc92049b0b068dbafc487b57))
* **i18n:** add Brazilian Portuguese (pt-BR) locale ([bb2596e](https://github.com/kaitranntt/ccs/commit/bb2596e296caa20a69c897ba472b7ada9eac2eda))
* rebrand CCS as Claude Codex Switch ([#1658](https://github.com/kaitranntt/ccs/issues/1658)) ([3608bf7](https://github.com/kaitranntt/ccs/commit/3608bf71a1515dd65f0cdf29e2c6b5fc1030d723)), closes [#1657](https://github.com/kaitranntt/ccs/issues/1657)
* support claude opus 5 ([ee90dd2](https://github.com/kaitranntt/ccs/commit/ee90dd26403e4366af7a4cdbf179e28f45887dc0))
* **ui:** add codex fast service-tier toggle ([108ff84](https://github.com/kaitranntt/ccs/commit/108ff843f142e0a88d000db2aaa731dbc89f450f))
* **ui:** add fable tier row in model mapping ([b27a007](https://github.com/kaitranntt/ccs/commit/b27a007229388a98bd6254af76b33b1d1ad2135e))
* **ui:** add per-tier codex effort dropdown in model mapping ([e57bded](https://github.com/kaitranntt/ccs/commit/e57bded451de16fb31f639df8e92ebd554288946))
* **ui:** extend reasoning control to xai grok models ([30b54a0](https://github.com/kaitranntt/ccs/commit/30b54a09666642d65f80c01b60da9d19324cafdd))

### Bug Fixes

* apply cliproxy retry settings safely ([480b795](https://github.com/kaitranntt/ccs/commit/480b79551b5f4e849c9f3341d6a8302141ce4bab))
* **auth:** guard shared linking against instance replacement ([54efb82](https://github.com/kaitranntt/ccs/commit/54efb820553c4760cf081f363269ac1a16c85a3a))
* **auth:** preserve explicit resume session continuity ([6721d47](https://github.com/kaitranntt/ccs/commit/6721d47502645325d58fc97a4d11bb53750d0c75)), closes [#1685](https://github.com/kaitranntt/ccs/issues/1685)
* **bar:** bound native credential and quota waits ([da2de60](https://github.com/kaitranntt/ccs/commit/da2de600159cffb9db27d6e7bbeef03daae2b3f0))
* **bar:** harden lifecycle process handling ([1a80717](https://github.com/kaitranntt/ccs/commit/1a80717f998079f449749db04aeed4b6eccc3349))
* **bar:** keep sticky port across `ccs bar stop` via launch.json fallback ([d27b53f](https://github.com/kaitranntt/ccs/commit/d27b53f235fa16c6d5404b96fc183db4bfc9c1e3))
* **bar:** stop false re-auth on non-default native subscription profiles ([a5a5b74](https://github.com/kaitranntt/ccs/commit/a5a5b742e4255051b160001985c4c545e85b0cf8))
* **bar:** treat cached quota rows as stale once their reset passes ([833473c](https://github.com/kaitranntt/ccs/commit/833473c5f61f2df4e6408783a38f18d903384917))
* **cliproxy:** classify Claude quota probe 429s ([bdcfc20](https://github.com/kaitranntt/ccs/commit/bdcfc20c0f78a19d5f7ed306f3094ac6f978482c))
* **cliproxy:** correct Claude Opus 5 metadata ([af4e4fb](https://github.com/kaitranntt/ccs/commit/af4e4fb3531b5474cb2aa719cc2aaae6f112cfb0))
* **cliproxy:** probe Gemini OAuth support ([19c6c3f](https://github.com/kaitranntt/ccs/commit/19c6c3f4577932a3b9c1eb4f8818d6fbec838bca))
* **cliproxy:** retry contended state locks ([66794e0](https://github.com/kaitranntt/ccs/commit/66794e07323780ca1376e29a8fb2833d82c747d1))
* **i18n:** complete Brazilian Portuguese locale ([0a80ddd](https://github.com/kaitranntt/ccs/commit/0a80dddb9cf24ea37dd733fa67a58649cb31ebef))
* **metrics:** enforce exact runtime inventory ([306a827](https://github.com/kaitranntt/ccs/commit/306a8276b3f081560d447ee68243bd35b9051cac))
* propagate fable model mapping across runtime paths ([f7241d0](https://github.com/kaitranntt/ccs/commit/f7241d0874088bfbfd498745c28b8d0ea236029b))
* **proxy:** hoist duplicate system messages before coalescing ([b720231](https://github.com/kaitranntt/ccs/commit/b720231077267e0fcf281ef77b6c188340f6a3b6)), closes [#1459](https://github.com/kaitranntt/ccs/issues/1459)
* **proxy:** stabilize upstream fetch transport ([d8210cf](https://github.com/kaitranntt/ccs/commit/d8210cf0113cf6aa782f856db683e9123cb27711)), closes [#1686](https://github.com/kaitranntt/ccs/issues/1686)
* **shared-manager:** adopt diverged plugin registry files in linkInstancePlugins ([fa6b27f](https://github.com/kaitranntt/ccs/commit/fa6b27f159fd8dd8782f98ae415b572c5cde4eee))
* **shared-manager:** adopt diverged settings.json content before re-linking ([481f013](https://github.com/kaitranntt/ccs/commit/481f013ec2581b943131fde1f11e34a098013b38)), closes [#57](https://github.com/kaitranntt/ccs/issues/57) [#1681](https://github.com/kaitranntt/ccs/issues/1681)
* **shared-manager:** preserve diverged files safely ([7ae617f](https://github.com/kaitranntt/ccs/commit/7ae617f0ee2b377b5d9b74186431fb29ed019368))
* **ui:** preserve codex tuning metadata in live catalog merge ([8d1a093](https://github.com/kaitranntt/ccs/commit/8d1a093cf94341e010903f2918c0dc18da19f94a))
* **ui:** preserve untrusted origins in dev proxy ([c23b6be](https://github.com/kaitranntt/ccs/commit/c23b6bee19af147ef015e67c373d47af2d952c89))
* **websearch:** honor disabled steering per launch ([abc3002](https://github.com/kaitranntt/ccs/commit/abc3002e89cb6f7fd7659b41084b6c835008c6cd))

### Documentation

* **ai:** define documentation truth hierarchy ([3bb2d56](https://github.com/kaitranntt/ccs/commit/3bb2d56778a3e775e8d4f2fd236c5984c79e916d))
* **architecture:** reconcile provider and target contracts ([ebe1746](https://github.com/kaitranntt/ccs/commit/ebe174645938c8f86f92eafaaaa57a0db94482a6))
* **architecture:** replace volatile maintainer snapshots ([721ca5f](https://github.com/kaitranntt/ccs/commit/721ca5fc339391530de2498646db91c0dee6b24f))
* clarify disabled WebSearch launch behavior ([f89f136](https://github.com/kaitranntt/ccs/commit/f89f136a1bda46dc58f7c7d9d9a4efccaea9c611))
* **config:** preserve active developer contracts ([fd0d436](https://github.com/kaitranntt/ccs/commit/fd0d4362b388e29dc394e5092bfd3af74d859977))
* **contributing:** align test and UI guidance ([1e11335](https://github.com/kaitranntt/ccs/commit/1e1133534835ea705624feab3f3384ce5bea322a))
* document Brazilian Portuguese locale ([348d230](https://github.com/kaitranntt/ccs/commit/348d2302985b91eb4beedd397c517eb5ccaefcf6))
* **hygiene:** remove superseded local guides ([75e715e](https://github.com/kaitranntt/ccs/commit/75e715eebdf5d759234057c0e7212aee022a11c6))
* **macos:** consolidate CCS Bar maintainer guidance ([4485fd6](https://github.com/kaitranntt/ccs/commit/4485fd64062d14e4dabb4815ca4173322b7d4f55))
* **operations:** refresh runtime contracts ([51e8062](https://github.com/kaitranntt/ccs/commit/51e806299564da03ac8ce98cad35cc962ec01078))
* **product:** refresh product and release contracts ([b918783](https://github.com/kaitranntt/ccs/commit/b918783293381a13f0ba90c17c57743a748fa733))
* **readme:** clarify supported proxy runtimes ([3e38208](https://github.com/kaitranntt/ccs/commit/3e38208b37b6a7e01ff561539367c524d1df4db8)), closes [#1686](https://github.com/kaitranntt/ccs/issues/1686)
* **readme:** route user guides to canonical docs ([deb1ed0](https://github.com/kaitranntt/ccs/commit/deb1ed0e67d6ca71953f0a78f72b9916c8bc8ed5))
* **roadmap:** replace historical trackers with live guidance ([426dc54](https://github.com/kaitranntt/ccs/commit/426dc541a935d60747ce0bfa8e598ff3fa86f94d))

### Tests

* **cliproxy:** cover auto compact windows ([c107a67](https://github.com/kaitranntt/ccs/commit/c107a6752c9d1eb2d510b85fed37ea9bd26fc767))
* **cliproxy:** cover Claude quota probe 429s ([92fb66c](https://github.com/kaitranntt/ccs/commit/92fb66c47bed4c305c8d77ac47330967509b6ff6))
* **cliproxy:** cover concurrent state writers ([d700030](https://github.com/kaitranntt/ccs/commit/d7000300188c1aff78bfc44cd643c9e4cb96819e))
* **cliproxy:** cover Gemini OAuth capabilities ([c4fc5e8](https://github.com/kaitranntt/ccs/commit/c4fc5e89855f1a07b9d01a843c7874fc640e1371))
* **cliproxy:** cover routing rule preservation ([2ce3bfc](https://github.com/kaitranntt/ccs/commit/2ce3bfca26df80481f87ad2b29c4a8d2835e6e7a))
* **docs:** enforce documentation freshness ([8dc6b81](https://github.com/kaitranntt/ccs/commit/8dc6b817b2e9d66752892e12410ec17988676cb0))
* **proxy:** harden system message ordering ([c621241](https://github.com/kaitranntt/ccs/commit/c621241a2e308b6910b556696da40f1820ca9a1d)), closes [#1687](https://github.com/kaitranntt/ccs/issues/1687)
* **ui:** cover Claude Opus 5 catalog visibility ([0629b4a](https://github.com/kaitranntt/ccs/commit/0629b4a40573a41966da7218f5d9e64bd68b32be))
* **websearch:** cover disabled launch snapshots ([9f5706c](https://github.com/kaitranntt/ccs/commit/9f5706c275aa9142f88fcbe4ee4b95cce087b674))

### CI

* **review:** configure explicit reasoning effort ([26c1393](https://github.com/kaitranntt/ccs/commit/26c1393c161a7dfbe7bae7c5c9aff59a0447a002))
2026-08-09 03:44:08 +00:00
Kai (Tam Nhu) Tran 83268d15c8 Merge pull request #1695 from kaitranntt/kai/release/dev-to-main-20260808
feat: promote dev to main
2026-08-08 23:39:59 -04:00
github-actions[bot] 16ef7a3444 chore(release): 8.8.1-dev.22 2026-08-09 03:16:42 +00:00
Kai (Tam Nhu) Tran 27b0ea08fe Merge pull request #1694 from kaitranntt/kai/feat/1688-share-claude-md
feat(auth): share canonical CLAUDE.md across account profiles
2026-08-08 23:12:23 -04:00
Tam Nhu Tran 54efb82055 fix(auth): guard shared linking against instance replacement 2026-08-08 23:06:29 -04:00
Tam Nhu Tran 5f9db033e7 chore: merge origin/dev into issue #1688
# Conflicts:
#	docs/reports/hardening-inventory.json
#	docs/reports/hardening-inventory.md
2026-08-08 22:29:46 -04:00