Skip to content

fix(security): close permission and integration gaps - #1802

Merged
tinsever merged 2 commits into
mainfrom
fix/remaining-security-findings
Sep 26, 2026
Merged

tinsever merged 2 commits into
mainfrom
fix/remaining-security-findings

Conversation

@tinsever

@tinsever tinsever commented Sep 26, 2026 •

Copy link
Copy Markdown
Member

Description

Fix the remaining permission, credential, comment parsing, and workflow issues identified in the security review.

  • Require a fresh GitLab token when the server URL changes, so saved credentials cannot be sent to another host.
  • Check task update permission before duplicating parent links. Users with create-only permission can still duplicate tasks without parent links.
  • Keep ordinary GitLab label changes from changing task status or priority, including through comma-separated label names.
  • Prevent crafted backtick sequences from freezing comment rendering and apply the existing 10,000-character limit to both comment APIs.
  • Keep users on the Gitea settings screen when their Gitea token is invalid. HTTP 401 remains reserved for missing Kaneo authentication.
  • Stop Dependabot automation from merging previously closed PRs, even after a later bot update.
  • Pin Blacksmith actions to commit SHAs and remove their exception from the workflow security scanner.

Related Issue(s)

Follows #1801, which fixed integration permissions when moving projects between workspaces.

Type of Change

  • Bug fix
  • Performance improvement
  • Test addition or update

How Has This Been Tested?

  • Unit tests: pnpm test, 1,345 tests passed across the repository.
  • Integration tests: 31 tests passed against a disposable PostgreSQL database, covering task duplication, GitLab sync boundaries, Gitea credential errors, and comment limits.
  • Other: all 63 security script tests passed with node --test scripts/security/*.test.mjs.
  • Other: repository typechecks, targeted Biome checks, workflow YAML parsing, and pnpm openapi:check passed.

Checklist

  • My code follows the style guidelines of this project
  • I have performed a self-review of my own code
  • I understand and take responsibility for every change, and I wrote this pull request description in my own words
  • I have commented my code, particularly in hard-to-understand areas
  • I have made corresponding changes to the documentation
  • My changes generate no new warnings
  • I have added tests that prove my fix is effective or that my feature works
  • New and existing unit tests pass locally with my changes
  • Any dependent changes have been merged and published

View with [code]smith Autofix with [code]smith
Need help on this PR? Tag @codesmith-bot with what you need. Autofix is disabled.

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 26, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-26T09:04:51.496312Z 73f0a14 Manual request
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@qodo-free-for-open-source-projects

Copy link
Copy Markdown

PR Summary by Qodo

Close permission, integration, comment, and workflow security gaps

🐞 Bug fix 🧪 Tests ⚙️ Configuration changes 🕐 40+ Minutes

Grey Divider

AI Description

• Prevent cross-host credential reuse and enforce permissions across task and GitLab
 synchronization.
• Bound and linearize comment processing while preserving authenticated integration error handling.
• Harden Dependabot and third-party workflow actions with regression coverage.
Diagram

graph TD
  Client["API Client"] --> Routes["API Routes"] --> Guards["Security Guards"] --> Domain["Tasks and Comments"]
  Guards --> Integrations["Git Integrations"]
  Workflows["GitHub Workflows"] --> Automation["Trusted Automation"] --> Actions["Pinned Actions"]
Loading
High-Level Assessment

The targeted defense-in-depth approach is appropriate: each finding is fixed at its authorization, validation, parsing, or automation boundary and backed by focused regression coverage. A broad integration or permission-layer rewrite would increase risk without materially improving these independent fixes.

Files changed (35) +477 / -127

Bug fix (2) +2 / -2
list-gitea-repositories.tsClassify invalid Gitea tokens as request errors +1/-1

Classify invalid Gitea tokens as request errors

• Returns HTTP 400 instead of 401 when repository listing fails token verification, preserving 401 for Kaneo authentication failures.

apps/api/src/gitea-integration/controllers/list-gitea-repositories.ts

verify-gitea-access.tsSeparate Gitea rejection from session authentication +1/-1

Separate Gitea rejection from session authentication

• Maps upstream Gitea 401 responses to HTTP 400 so clients remain on integration settings rather than entering Kaneo login handling.

apps/api/src/gitea-integration/controllers/verify-gitea-access.ts

Tests (1) +19 / -0
normalize-comment-markdown.test.tsCover adversarial backtick normalization +19/-0

Cover adversarial backtick normalization

• Adds correctness coverage for unequal and nested runs plus a timing regression test with thousands of unmatched delimiter lengths.

apps/web/src/lib/normalize-comment-markdown.test.ts

Other (32) +456 / -125
auto-merge.ymlPrevent rejected Dependabot PRs from re-entering automation +7/-3

Prevent rejected Dependabot PRs from re-entering automation

• Limits triggers to bot-driven open and synchronize events, verifies the actor is Dependabot, and rejects any PR with a prior closed event before merging.

.github/workflows/auto-merge.yml

build-images.ymlPin Blacksmith image-build actions +4/-4

Pin Blacksmith image-build actions

• Replaces mutable Blacksmith checkout, builder, and build action tags with immutable commit SHAs.

.github/workflows/build-images.yml

ci.ymlPin Blacksmith actions throughout CI +17/-17

Pin Blacksmith actions throughout CI

• Pins all Blacksmith checkout, Docker builder, and image build invocations in CI to immutable commits.

.github/workflows/ci.yml

code-review.ymlPin code-review checkout actions +2/-2

Pin code-review checkout actions

• Pins trusted workflow checkout steps used by code-review authorization and execution jobs.

.github/workflows/code-review.yml

deploy-site.ymlPin site deployment checkout +1/-1

Pin site deployment checkout

• Uses an immutable Blacksmith checkout commit for site deployments.

.github/workflows/deploy-site.yml

helm-chart.ymlPin Helm publishing checkouts +2/-2

Pin Helm publishing checkouts

• Pins both repository and verified release-tag checkout steps to the approved Blacksmith commit.

.github/workflows/helm-chart.yml

helm-validate.ymlPin Helm validation checkout +1/-1

Pin Helm validation checkout

• Uses an immutable Blacksmith checkout commit during chart validation.

.github/workflows/helm-validate.yml

nightly.ymlPin nightly security scan checkouts +2/-2

Pin nightly security scan checkouts

• Pins Blacksmith checkout usage in nightly secret-scanning and workflow-security jobs.

.github/workflows/nightly.yml

pr-size-labeler.ymlPin trusted size-labeler checkout +1/-1

Pin trusted size-labeler checkout

• Pins the checkout used to read base-branch pull-request size configuration.

.github/workflows/pr-size-labeler.yml

pr-title.ymlPin pull-request title policy checkout +1/-1

Pin pull-request title policy checkout

• Pins the base-branch checkout used to validate pull-request titles.

.github/workflows/pr-title.yml

publish-mcp.ymlPin MCP publishing checkouts +2/-2

Pin MCP publishing checkouts

• Pins Blacksmith checkout steps used by MCP package publishing jobs.

.github/workflows/publish-mcp.yml

publish-planka-import.ymlPin Planka importer publishing checkout +1/-1

Pin Planka importer publishing checkout

• Pins the repository checkout used to publish the Planka import package.

.github/workflows/publish-planka-import.yml

release.ymlPin release workflow checkouts +3/-3

Pin release workflow checkouts

• Pins repository checkout steps across release preparation, validation, and publishing jobs.

.github/workflows/release.yml

ui-review-run.ymlPin UI review execution checkouts +3/-3

Pin UI review execution checkouts

• Pins Blacksmith checkout usage in UI review planning, capture, and supporting jobs.

.github/workflows/ui-review-run.yml

ui-review.ymlPin UI review authorization checkout +1/-1

Pin UI review authorization checkout

• Pins the trusted workflow checkout used to authorize UI review requests.

.github/workflows/ui-review.yml

update-contributors.ymlPin contributor workflow checkout +1/-1

Pin contributor workflow checkout

• Uses an immutable checkout action commit before generating contributor assets.

.github/workflows/update-contributors.yml

schema.tsEnforce comment write limits +4/-2

Enforce comment write limits

• Applies the existing 10,000-character maximum to both comment creation and update payloads.

apps/api/src/comment/schema.ts

index.tsDocument corrected Gitea error semantics +7/-3

Document corrected Gitea error semantics

• Updates route response descriptions to distinguish invalid upstream credentials from missing Kaneo authentication.

apps/api/src/gitea-integration/index.ts

create-gitlab-integration.tsBind stored GitLab tokens to their destination +16/-1

Bind stored GitLab tokens to their destination

• Allows token reuse only when the normalized GitLab base URL is unchanged. A new host, port, or path requires a freshly supplied token before any remote request occurs.

apps/api/src/gitlab-integration/controllers/create-gitlab-integration.ts

schema.tsClarify GitLab token reuse requirements +2/-1

Clarify GitLab token reuse requirements

• Documents that omitting a token is valid only when retaining the existing normalized GitLab base URL.

apps/api/src/gitlab-integration/schema.ts

sync-label-to-gitlab.tsBlock task-field labels from ordinary GitLab label sync +12/-0

Block task-field labels from ordinary GitLab label sync

• Detects status and priority labels, including entries inside comma-separated names, and excludes them from add and remove synchronization paths.

apps/api/src/plugins/gitlab/utils/sync-label-to-gitlab.ts

duplicate-task.tsRequire update permission when duplicating parent links +8/-0

Require update permission when duplicating parent links

• Rejects duplication of tasks carrying parent relations unless the caller has task:update permission, before creating records or copying assets. Standalone tasks remain duplicable with create permission.

apps/api/src/task/controllers/duplicate-task.ts

index.tsPass update authorization into task duplication +9/-3

Pass update authorization into task duplication

• Checks task:update permission for duplication requests and documents the conditional parent-link requirement in route metadata and error responses.

apps/api/src/task/index.ts

openapi.jsonRegenerate API contracts for security behavior +10/-8

Regenerate API contracts for security behavior

• Reflects comment length limits, conditional task duplication permissions, corrected Gitea error semantics, and GitLab token destination requirements.

apps/docs/openapi.json

normalize-comment-markdown.tsMake backtick delimiter matching linear +24/-54

Make backtick delimiter matching linear

• Indexes matching backtick runs in one reverse pass instead of repeatedly scanning suffixes, preventing crafted comments from causing quadratic rendering work.

apps/web/src/lib/normalize-comment-markdown.ts

workflows.test.mjsTest workflow automation and immutable action pins +46/-2

Test workflow automation and immutable action pins

• Adds coverage rejecting previously closed Dependabot PRs and human-triggered reopen paths. It also scans every workflow for immutable Blacksmith commits and confirms the scanner exemption is gone.

scripts/security/workflows.test.mjs

comment-bounds.test.tsTest comment limits across both APIs +57/-0

Test comment limits across both APIs

• Verifies create and update limits on comment and activity endpoints, including acceptance and unchanged storage at exactly 10,000 characters.

tests/api-integration/comment-bounds.test.ts

gitea-credential-errors.test.tsTest Gitea credential error separation +63/-0

Test Gitea credential error separation

• Confirms invalid upstream tokens return 400 without leaking secrets, while anonymous Kaneo requests still return 401 before contacting Gitea.

tests/api-integration/gitea-credential-errors.test.ts

task-duplicate.test.tsTest parent-link duplication permissions +63/-1

Test parent-link duplication permissions

• Covers custom-role and API-key callers with create-only permissions, verifying linked tasks are rejected without side effects while standalone tasks still duplicate.

tests/api-integration/task-duplicate.test.ts

create-gitlab-integration.test.tsTest GitLab token destination binding +61/-1

Test GitLab token destination binding

• Verifies saved tokens are never sent to changed hosts, ports, or paths, while normalized equivalent URLs and fresh replacement tokens remain supported.

tests/api/gitlab-integration/create-gitlab-integration.test.ts

sync-label-to-gitlab.test.tsTest protected GitLab label filtering +24/-0

Test protected GitLab label filtering

• Covers direct and comma-separated status or priority labels for both add and remove paths while preserving ordinary label removal.

tests/api/plugins/gitlab/utils/sync-label-to-gitlab.test.ts

zizmor.ymlRequire immutable pins for Blacksmith actions +1/-4

Require immutable pins for Blacksmith actions

• Removes the Blacksmith tag-pin exception so the workflow scanner requires commit hashes for every action provider.

zizmor.yml

@qodo-free-for-open-source-projects

qodo-free-for-open-source-projects Bot commented Sep 26, 2026 •

Copy link
Copy Markdown

Code Review by Qodo

🐞 Bugs (1) 📘 Rule violations (0) 📎 Requirement gaps (0) 🎨 UX issues (0) 🔗 Cross-repo conflicts (0) 📜 Skill insights (0)

Grey Divider


Action required

1. A scanner comment repeats its setting ✓ Resolved 📘 Rule violation ⚙ Maintainability
Description
The comment above "*": hash-pin merely translates that setting into prose instead of documenting a
non-obvious constraint or rationale. A later change to the pinning policy could leave this redundant
description stale and mislead maintainers about the effective scanner configuration.
Code

zizmor.yml[6]

+        # All actions, including build and checkout providers, use immutable commits.
Evidence
Compliance rule 18 permits comments for constraints or surprising decisions, while the cited comment
only narrates the immediately following wildcard policy.

AGENTS.md: Write Comments Only for Constraints and Surprising Decisions: AGENTS.md: Write Comments Only for Constraints and Surprising Decisions: AGENTS.md: Write Comments Only for Constraints and Surprising Decisions: AGENTS.md: Write Comments Only for Constraints and Surprising Decisions
zizmor.yml[6-7]

Agent prompt
The issue below was found during a code review. Follow the provided context and guidance below and implement a solution

## Issue description
The comment above the wildcard `hash-pin` policy only restates the configuration and can become stale without adding rationale.
## Fix Focus Areas
- zizmor.yml[6-7]
## Recommended Fix
Remove the added comment and leave the self-explanatory wildcard `hash-pin` policy in place.

ⓘ Copy this prompt and use it to remediate the issue with your preferred AI generation tools


2. Eligible Dependabot updates never merge 🐞 Bug ≡ Correctness
Description
The new gh api call queries the pull request's Issues events endpoint, but the dependabot job
grants no issues: read permission. When an otherwise eligible update reaches this step, the API
request is denied and set -euo pipefail prevents the required-check and merge commands from
running.
Code

.github/workflows/auto-merge.yml[R50-52]

+          # A later bot update must not re-enable automation on a rejected PR.
+          gh api --paginate "repos/$GITHUB_REPOSITORY/issues/$PR_NUMBER/events" \
+            | jq -se 'add | all(.[]; .event != "closed")'
Evidence
The changed command calls repos/$GITHUB_REPOSITORY/issues/$PR_NUMBER/events, while the job
explicitly grants only contents, pull-requests, checks, and statuses permissions. Since the shell
enables set -euo pipefail, failure of that unauthorized API request terminates the step before the
subsequent gh pr checks and gh pr merge commands.

.github/workflows/auto-merge.yml[21-28]
.github/workflows/auto-merge.yml[47-67]

Agent prompt
The issue below was found during a code review. Follow the provided context and guidance below and implement a solution

## Issue description
The Dependabot merge step now reads pull-request issue events, but its job token lacks permission for the Issues endpoint. The failing API call stops the shell script before it can evaluate checks or enable auto-merge.
## Fix Focus Areas
- .github/workflows/auto-merge.yml[21-28]
- .github/workflows/auto-merge.yml[50-52]
## Recommended Fix
Add `issues: read` to the `dependabot` job's explicit `permissions` block. Keep the existing event-history check unchanged so it can reject previously closed pull requests while allowing eligible new Dependabot updates to continue to the merge commands.

ⓘ Copy this prompt and use it to remediate the issue with your preferred AI generation tools


Grey Divider

Tip of the day
💡 Did you know, you can type 'qodo, fix this' on a finding and the fix lands right on your PR

More tips ↗ | Customize Qodo ↗ | Qodo docs ↗

Grey Divider

Qodo Logo

Comment thread zizmor.yml Outdated
Comment thread .github/workflows/auto-merge.yml
@tinsever

Copy link
Copy Markdown
Member Author

@codex review

@chatgpt-codex-connector

Copy link
Copy Markdown

Codex Review: Didn't find any major issues. You're on a roll.

Reviewed commit: 73f0a14033

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

@tinsever
tinsever merged commit 1196880 into main Sep 26, 2026
28 checks passed
@tinsever
tinsever deleted the fix/remaining-security-findings branch September 26, 2026 09:05
zaralX pushed a commit to zaralX/kaneo that referenced this pull request Sep 26, 2026
### Features

- gitlab integration: usekaneo#1727
- **tasks:** show subtask progress on cards and list rows: usekaneo#1703
- added project backgrounds: usekaneo#1654
- multiselect for customfield: usekaneo#1735
- **ci:** discord actions webhook: usekaneo#1792
- **ci:** adding zizmor: usekaneo#1790
- **project:** move a project to another workspace: usekaneo#1525
- duplicate a task from the card context menu: usekaneo#1609
- allow manual external resource links: usekaneo#1661
- **ci:** trufflehog implementation: usekaneo#1787
- **task:** let images be resized in the task description: usekaneo#1529
- **web:** add a change-password screen under account settings: usekaneo#1719
- **auth:** add password recovery from the login screen: usekaneo#1773
- add instance user administration panel: usekaneo#1400
- **calendar:** add label-filtered project calendar feeds: usekaneo#1763

### Bug Fixes

- **security:** close permission and integration gaps: usekaneo#1802
- **project:** secure integrations across workspace moves: usekaneo#1801
- **editor:** preserve formatting when pasting Markdown: usekaneo#1797
- **auth:** report invitation email delivery failures: usekaneo#1798
- **gitea:** verify saved repository connections: usekaneo#1796
- **mcp:** keep OAuth requests valid outside UTC: usekaneo#1795
- **i18n:** translate calendar in remaining locales: [1d61ceb](usekaneo@1d61ceb)
- **ci:** zizmor findings: usekaneo#1791
- **integrations:** resolve PRs through linked issue identities: usekaneo#1739
- **auth:** prevent repeated 401s for pending invitations after session expiry: usekaneo#1715
- **auth:** gate sign-in emails to deliverable addresses: usekaneo#1758
- **web:** preserve image uploads across editor recreation: usekaneo#1738
- **reminders:** calculate deadlines from the end of the due day: usekaneo#1762
- **mcp:** support whoami with API keys: usekaneo#1748
- **web:** respect DISABLE_WORKSPACE_CREATION on the onboarding screen: usekaneo#1744
- **backlog:** prevent task remounts during list interactions: usekaneo#1734
- **auth:** prevent role changes from removing the last admin: usekaneo#1733
- **npm:** fixing GHSA-2xp9-vwfh-vxw4: usekaneo#1777
- **web:** guard tiptap setHardBreak against invalid-content schema error: [be3ffb5](usekaneo@be3ffb5)
- **i18n:** prevent locale module crash on stale dynamic import: usekaneo#1775
- **site:** improve search metadata and product discovery: [121183e](usekaneo@121183e)

### Performance Improvements

- **project:** stop returning tasks with project details: usekaneo#1800

### Documentation

- update contributors and sponsors: [fa07f10](usekaneo@fa07f10)
- **site:** add Blacksmith partner badge to site and README: [08a93b8](usekaneo@08a93b8)
- update contributors and sponsors: [8432a45](usekaneo@8432a45)

### Credits

Huge thanks to @tinsever, @zaralX, @TymekV, @MonsPropre, @randoneering, @rdlugs, @tbringuier, @mohiuddin000, @shiminshen, @yavilavi, @thejdubb02, @yigit-serin, @OmG3r, and @zerodarkzone for helping!
@zaralX zaralX mentioned this pull request Sep 26, 2026
14 of 15 tasks
dlanileonardo added a commit to dlanileonardo/kaneo that referenced this pull request Sep 28, 2026
…nds, dup task, billing

Destaques:
- fix(security): CVE-2026-75604, CVE-2026-69192, permission gaps (usekaneo#1802)
- feat: project backgrounds (usekaneo#1654), move project between workspaces (usekaneo#1525)
- feat: duplicate task (usekaneo#1609), subtask progress on cards, task image resize
- feat: full GitLab integration (webhooks, label sync, activity)
- feat: change-password screen, calendar feeds by label, Gantt jump-to-today
- feat: i18n az-AZ/ja-JP/pl-PL, migrate tooling to Vite+ (vp), vitest 5
- chore: migrate CI to Blacksmith runners, TruffleHog secret scan

Conflitos resolvidos (mantendo Agenda + My Tasks usekaneo#1699):
- get-tasks/bulk-update/update-task: integrado subtaskCounts + novos eventos
- task/schema: pagingNumber movido p/ openapi; user/schema importa de la
- board-toolbar/sort-control/context-menu: merge useBackgroundStore + duplicate
- i18n (21 arquivos): agenda + checklistProgress/customFields/duplicate
- en-US: adminUsers + security/billing/calendarFeeds/externalLinks
- load-task-decorations: integrationId nullable; vitest->vite-plus/test imports

Validado: typecheck api/web/libs/site, lint, 759 unit API, 554 web, 733 integração
github-actions Bot added a commit to capital-shield/kaneo that referenced this pull request Oct 3, 2026
### Features

- **web:** redesign settings: usekaneo#1905
- **site:** link community projects from resources: [69ba99d](69ba99d)
- **site:** add a community projects page: [961c309](961c309)
- **site:** sync product preview with home, inbox and my tasks: [30ba825](30ba825)
- missing french translation: usekaneo#1903
- add short task links like /acme/task/KAN-12: usekaneo#1891
- **web:** add home, inbox and my tasks pages: usekaneo#1898
- **web:** wire the task copy shortcuts: usekaneo#1897
- **web:** move task delete into the action group: usekaneo#1896
- **site:** add guides and retarget alternatives: [58f6d47](58f6d47)
- **web:** track the cloud signup funnel: [abacad7](abacad7)
- **docker:** support file-backed secrets for container deployments: usekaneo#1853
- sort labels alphabetically: usekaneo#1856
- **web:** select task ranges with shift-click: usekaneo#1838
- clickable task PR list, task link matching, and reopen completed tasks for new work: usekaneo#1864
- **mcp:** get tasks by ticket ID: usekaneo#1839
- **web:** guide cloud users through invites and plan choice during onboarding: usekaneo#1840
- rank new issue priority with Jev: [594e016](594e016)
- **web:** cloud sign-up and onboarding layout: usekaneo#1832
- gitlab integration: usekaneo#1727
- **tasks:** show subtask progress on cards and list rows: usekaneo#1703
- added project backgrounds: usekaneo#1654
- multiselect for customfield: usekaneo#1735
- **ci:** discord actions webhook: usekaneo#1792
- **ci:** adding zizmor: usekaneo#1790
- **project:** move a project to another workspace: usekaneo#1525
- duplicate a task from the card context menu: usekaneo#1609
- allow manual external resource links: usekaneo#1661
- **ci:** trufflehog implementation: usekaneo#1787
- **task:** let images be resized in the task description: usekaneo#1529
- **web:** add a change-password screen under account settings: usekaneo#1719
- **auth:** add password recovery from the login screen: usekaneo#1773
- add instance user administration panel: usekaneo#1400
- **site:** bring product preview up to date with current app: [dd855f7](dd855f7)
- **site:** refresh marketing site and interactive product previews: [90aec99](90aec99)
- **calendar:** add label-filtered project calendar feeds: usekaneo#1763

### Bug Fixes

- **web:** send subscription revenue as a property: [445b735](445b735)
- **site:** list GitLab with the git integrations: [3c01517](3c01517)
- **site:** serve favicon.ico: [e7ef050](e7ef050)
- **docs:** load the docs font from its real path: [22c7a02](22c7a02)
- **tasks:** make bulk status changes atomic: usekaneo#1873
- **integrations:** preserve rapid legitimate edits: usekaneo#1874
- **integrations:** enforce current task ownership: usekaneo#1867
- **ws:** revoke removed workspace members: usekaneo#1865
- **migrations:** record workflow migration completion: usekaneo#1872
- **auth:** enforce api key quotas and rate limits: usekaneo#1869
- **mcp:** share tools and support workspace label deletion: usekaneo#1871
- **reminders:** persist notification and claim atomically: usekaneo#1870
- **integrations:** require task update permission for imports: usekaneo#1868
- **ci:** publish npm provenance on GitHub-hosted runners: [50779a4](50779a4)
- **gitea:** reject saved tokens for changed servers: usekaneo#1866
- **ci:** pass the GitHub token to AgentScan: usekaneo#1862
- **ci:** resolve nightly warnings and errors: usekaneo#1858
- **api:** make legacy MCP HTTP requests replica independent: usekaneo#1850
- **docker:** disable wget proxy for loopback health checks: usekaneo#1841
- **billing:** resize Creem seats by subscription item id: usekaneo#1836
- **gitea:** prevent outbound comment echoes: usekaneo#1834
- **deps:** migrate Sentry SDKs together to v11 (usekaneo#1826): usekaneo#1826
- **ci:** grant nightly reusable CI scan permission: [0216067](0216067)
- **board:** allow column moves while sorting by task number: usekaneo#1816
- **auth:** backfill instance admin on legacy installations: [b7c6aee](b7c6aee)
- **admin:** harden the user administration panel: usekaneo#1805
- **admin:** allow updating your own email without changing role: [3d57439](3d57439)
- **security:** close permission and integration gaps: usekaneo#1802
- **project:** secure integrations across workspace moves: usekaneo#1801
- **editor:** preserve formatting when pasting Markdown: usekaneo#1797
- **auth:** report invitation email delivery failures: usekaneo#1798
- **gitea:** verify saved repository connections: usekaneo#1796
- **mcp:** keep OAuth requests valid outside UTC: usekaneo#1795
- **i18n:** translate calendar in remaining locales: [1d61ceb](1d61ceb)
- **ci:** zizmor findings: usekaneo#1791
- **integrations:** resolve PRs through linked issue identities: usekaneo#1739
- **auth:** prevent repeated 401s for pending invitations after session expiry: usekaneo#1715
- **auth:** gate sign-in emails to deliverable addresses: usekaneo#1758
- **web:** preserve image uploads across editor recreation: usekaneo#1738
- **reminders:** calculate deadlines from the end of the due day: usekaneo#1762
- **mcp:** support whoami with API keys: usekaneo#1748
- **web:** respect DISABLE_WORKSPACE_CREATION on the onboarding screen: usekaneo#1744
- **backlog:** prevent task remounts during list interactions: usekaneo#1734
- **auth:** prevent role changes from removing the last admin: usekaneo#1733
- **npm:** fixing GHSA-2xp9-vwfh-vxw4: usekaneo#1777
- **web:** guard tiptap setHardBreak against invalid-content schema error: [be3ffb5](be3ffb5)
- **i18n:** prevent locale module crash on stale dynamic import: usekaneo#1775
- **site:** improve search metadata and product discovery: [121183e](121183e)
- **web:** allow non-root runtime configuration writes: usekaneo#1767
- **site:** poof away preview cursor on interaction: [08dcaee](08dcaee)
- **nginx:** allow larger OAuth session headers: usekaneo#1761
- **deps:** resolve open dependabot advisories: [b8432a0](b8432a0)
- **web:** preserve comment markdown spacing: usekaneo#1521

### Performance Improvements

- **project:** stop returning tasks with project details: usekaneo#1800

### Documentation

- update sponsors: [1c51887](1c51887)
- add AI Policy badge to README: [011c8ee](011c8ee)
- update sponsors: [e45c8ac](e45c8ac)
- assign issue types from templates: [4725cfa](4725cfa)
- simplify issue and pull request templates: [cb6ce20](cb6ce20)
- adopt Human Voice AI contribution policy: [b090123](b090123)
- overhaul agents.md: [4d619aa](4d619aa)
- **readme:** highlight cloud and current features: usekaneo#1831
- update contributors and sponsors: [c200d70](c200d70)
- rebuild guides around current Kaneo workflows: usekaneo#1814
- acknowledge BrowserStack testing: [e389a68](e389a68)
- update contributors and sponsors: [fa07f10](fa07f10)
- **site:** add Blacksmith partner badge to site and README: [08a93b8](08a93b8)
- update contributors and sponsors: [8432a45](8432a45)
- **site:** refresh press kit with product screenshots: [3470b0a](3470b0a)
- update blog comparisons for current Kaneo features: [b97bf7d](b97bf7d)
- update contributors and sponsors: [6c7001c](6c7001c)

### Credits

Huge thanks to @tinsever, @MonsPropre, @andrejsshell, @tuttucodes, @druwan, @randoneering, @mazzz1y, @zaralX, @TymekV, @rdlugs, @tbringuier, @mohiuddin000, @shiminshen, @yavilavi, @thejdubb02, @yigit-serin, @OmG3r, and @zerodarkzone for helping!
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant