Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
123 commits
Select commit Hold shift + click to select a range
f63b431
fix(catalog): declare GLM reasoning effort tiers
xz-dev Aug 21, 2026
410a061
fix(security): clear new CodeQL code-scanning alerts (round 2) (#10888)
diegosouzapw Aug 21, 2026
0f35feb
fix(executors): report WS readyState in Meta AI timeout error (#10727…
diegosouzapw Aug 21, 2026
a8ca957
fix: add cold-restart native-driver regression check to electron smok…
diegosouzapw Aug 21, 2026
7011c5f
fix(cli): repair hollow externalized package dirs in nested distDir n…
diegosouzapw Aug 21, 2026
14d2c90
fix(executor): respect apiType="chat" in forceResponsesUpstream (#548…
YunyunZhai Aug 21, 2026
e708030
fix(resilience): make least-used rotate by recording the use it sorts…
ntdat812 Aug 21, 2026
6ec6940
fix(catalog): preserve provider effort tiers (#10953)
xz-dev Aug 21, 2026
28924fe
fix(models): enforce a synced model's real context window and default…
Neuron-Mr-White Aug 21, 2026
1c1e45c
fix(desktop): pin the NSIS artifact name so the Windows updater stops…
ntdat812 Aug 21, 2026
1f09e2f
feat(rankings): report what a free provider actually served (#10926)
maxmad64bis Aug 21, 2026
d1e5a57
fix(onboarding): add warning when skipping password in setup wizard (…
krishna3554 Aug 21, 2026
63c0125
feat(providers): tool calling for copilot-m365-web via router plannin…
acc0mplish Aug 21, 2026
154c294
feat(docker): add hardened Linux VPS deployment (#10623)
freudantunes Aug 21, 2026
ad3f7bc
fix(ci): clear base-reds on release/v3.8.50 (ESLint / dead-code / vit…
diegosouzapw Aug 21, 2026
089a5e7
fix(quality): register GrokBuildToolCard.tsx eslint suppression (drop…
hartmark Aug 21, 2026
c130f2a
feat(providers): Cursor PKCE login with Bearer quota, auto router, an…
yansigit Aug 21, 2026
6082924
fix(security): close 4 STILL-REAL advisory findings (ACP RCE hardenin…
diegosouzapw Aug 21, 2026
effc542
fix(cli): generated combo PATCH sends literal {id} — resolve $ref par…
diegosouzapw Aug 21, 2026
a492d6d
fix(sse): combo diagnostics provider/connection truncation and quota …
diegosouzapw Aug 21, 2026
48addd5
fix(cli): combo create cannot accept models — add --models option (#1…
diegosouzapw Aug 21, 2026
054cfae
fix(cli): always emit limit.output in OpenCode config (#10940) (#11010)
diegosouzapw Aug 21, 2026
8d07632
fix(providers): route terminal testStatus writes through a single ori…
maxmad64bis Aug 21, 2026
bc0a272
fix(accounts): carry failure kind on rotation — transient cools down,…
maxmad64bis Aug 21, 2026
1f4bde1
fix(sse): guard reasoning-cache write by the same predicate its reade…
maxmad64bis Aug 21, 2026
464ccb3
fix(providers): remove ALLOW_MULTI_CONNECTIONS_PER_COMPAT_NODE, a fla…
maxmad64bis Aug 21, 2026
79e1a8f
fix(providers): remove dead existingConnections lookups on connection…
maxmad64bis Aug 21, 2026
eba58cc
docs(api-keys): unset DEFAULT_RATE_LIMIT_PER_DAY is unlimited (#11017…
RaviTharuma Aug 21, 2026
30e20c6
fix(startup): log when credential health check is disabled (#11016) (…
RaviTharuma Aug 21, 2026
3f0b4ca
fix(codex): drop non-standard SSE events by default (#11014) (#11019)
RaviTharuma Aug 21, 2026
143fd78
fix(search): skip catalog-default SearXNG localhost:8888 (#10981)
RaviTharuma Aug 21, 2026
fefca17
fix(db): pause call-log rotate on SQLITE_CORRUPT (#10979)
RaviTharuma Aug 21, 2026
0fffb45
feat(api): alias GET/HEAD /readyz to /healthz (#10977)
RaviTharuma Aug 21, 2026
9459546
fix(providers): 401 when active terminal grok-cli credentials expire …
RaviTharuma Aug 21, 2026
137e49e
feat(search): first-class X Search via SuperGrok x_search (#10988)
RaviTharuma Aug 21, 2026
f24226f
docs: document runtime RAM for coding-agent /v1/responses (#10983)
RaviTharuma Aug 21, 2026
efece42
docs(docker): N independent DATA_DIRs scale out large /v1/responses (…
RaviTharuma Aug 21, 2026
00dfdad
fix(combo): resolve effort variants via base model capabilities (#11034)
excessivechaos Aug 21, 2026
8f0d0a0
fix: strip unsupported message metadata for Groq (#11026)
sanforex24h Aug 21, 2026
4ac157b
fix(opencode): guard the provider block when merging an existing conf…
ntdat812 Aug 21, 2026
9469b9c
fix(sse): surface bare upstream close as response.failed for Response…
linhdmn Aug 21, 2026
3caa591
feat(sse): add STRICT_ZERO_COST opt-in free-access policy (#10965)
mymusicmyspace Aug 21, 2026
2ab16d3
fix(cli): scoping android instrumentation-hook diagnosis to real plat…
diegosouzapw Aug 21, 2026
484cb6e
fix: add static model catalog for v0-vercel-web web-cookie provider (…
diegosouzapw Aug 21, 2026
861ac69
fix(providers): validate Dify keys against native /v1/chat-messages e…
diegosouzapw Aug 21, 2026
d61eec6
fix(dashboard): treat UncloseAI as a no-auth provider so the connect …
diegosouzapw Aug 21, 2026
a928fad
fix(command-code): surface reasoning-only output as content when no t…
diegosouzapw Aug 21, 2026
4e3e53e
fix(ssrf): honor local-first provider URL flag in outbound guard (#91…
diegosouzapw Aug 21, 2026
99111f3
fix(services): isolate probeBeforeSpawn adoption tests on distinct po…
diegosouzapw Aug 21, 2026
eb4fd74
fix(security): close remaining v3.8.50 advisories (batch 2 — 11 findi…
diegosouzapw Aug 21, 2026
9349af2
fix(quality): rebaseline file-size baseline for modelCapabilities.ts …
hartmark Aug 21, 2026
d01a4ae
fix(release): drain v3.8.50 base-reds — build-breaking import, stale …
diegosouzapw Aug 21, 2026
ae2de45
fix(sse): resolve OpencodeExecutor target format through the provider…
maxmad64bis Aug 21, 2026
02a6c3d
fix(sse): split concatenated tool_call arguments from same-name index…
maxmad64bis Aug 21, 2026
1c920eb
fix(webhooks): remove 3 declared-but-never-emitted ghost events (#11050)
maxmad64bis Aug 21, 2026
666e4aa
fix(providers): route Muse Spark to the Responses API on opencode-zen…
maxmad64bis Aug 21, 2026
c977536
refactor(providers): dedupe identical opencode-zen/opencode-go model …
maxmad64bis Aug 21, 2026
f968496
fix(gamification): validate leaderboard limit/offset before the SQLit…
pacocartones Aug 21, 2026
0ff0490
test(db): assert resetDbInstance swaps the singleton, WAL mode, and s…
pacocartones Aug 22, 2026
9b801b7
fix(dashboard): compute unique connection names from array to avoid o…
rqzbeh Aug 22, 2026
7e48be8
feat(dashboard): trigger key validation on Enter in AddApiKeyModal (#…
rqzbeh Aug 22, 2026
8643e0f
fix(cli): default limit.context to 128k when unknown in OpenCode conf…
rqzbeh Aug 22, 2026
7c39e95
fix(providers): update hailuo-web domain to chat.minimax.io (#11000) …
rqzbeh Aug 22, 2026
7ffa3ef
fix(quality): move #11050 changelog fragment to valid fixes/ section …
hartmark Aug 22, 2026
7ddbaf6
feat(cli): add native Bun backend support and Dockerfile.bun (#11039)
rqzbeh Aug 22, 2026
5a60a46
fix: deprecate blackbox provider since api.blackbox.ai returns 404 (#…
diegosouzapw Aug 22, 2026
e06f8b7
feat(api): flag a pinned account on /v1/combos steps without leaking …
ntdatt812 Aug 22, 2026
b6412c6
fix(command-code): use the documented /provider/v1 chat endpoint (#10…
diegosouzapw Aug 22, 2026
6cd4d38
fix(m365): BizChat invocation shape drift + HAR-import UX + Antigravi…
eenggar-svg Aug 22, 2026
742ccb9
fix(ci): register oauth-autoimport-local-only test in stryker tap.tes…
hartmark Aug 22, 2026
9629693
fix(providers): filter Perplexity model import to the Sonar family (#…
diegosouzapw Aug 22, 2026
d91238b
fix(install): make ONNX chain optional for Android/Termux installs (#…
diegosouzapw Aug 22, 2026
da490a7
fix(sse): resume stream recovery after a completed tool call (#11109)
maxmad64bis Aug 22, 2026
d9b3ce2
test(stream): direct coverage + comment for splitConcatenatedToolCall…
maxmad64bis Aug 22, 2026
02a078e
fix(sse): default summary on freshly-built Chat->Responses reasoning …
maxmad64bis Aug 22, 2026
b44f22a
fix(webhooks): followup ghost-event dispatcher tests + vi i18n (#1105…
maxmad64bis Aug 22, 2026
efc7134
fix(registry): restore models[0] default + guards; note muse-spark ov…
maxmad64bis Aug 22, 2026
78b4082
fix(autopilot): show real suggestion count and link dashboard (#11102)
maxmad64bis Aug 22, 2026
d021423
fix(sse): default summary + strip malformed id on kept Responses inpu…
maxmad64bis Aug 22, 2026
f3b190b
fix(providers): reject silent validation degradation with 400 and rej…
maxmad64bis Aug 22, 2026
84c9dfd
fix(config-audit): persist config audit log to SQLite with retention …
maxmad64bis Aug 22, 2026
c89fc6b
feat(providers): let operators add per-provider error rules via setti…
maxmad64bis Aug 22, 2026
1dd0173
fix(sse): assign a stable index/id to parallel function_call items in…
maxmad64bis Aug 22, 2026
5631e91
fix(providers): learn reasoning_effort capability from upstream 4xx i…
maxmad64bis Aug 22, 2026
dae3a72
fix(i18n): translate providers.harImport* keys into Vietnamese (#1106…
hartmark Aug 22, 2026
a51b8ba
fix(cline): use valid modelType/model format for Cline provider model…
rqzbeh Aug 22, 2026
3157e8a
fix(providers): require API key for Pollinations and fix optional key…
rqzbeh Aug 22, 2026
9a67185
fix(cli): support OpenCode V2 config format in setup-opencode (#11070…
rqzbeh Aug 22, 2026
50fc0d7
fix(resilience): keep Ollama model-not-found failures scoped to conne…
rqzbeh Aug 22, 2026
4220c81
fix(resilience): include RFC1918, CGNAT, and mDNS hosts in isLocalPro…
rqzbeh Aug 22, 2026
367ae2f
fix(search): enforce blockedProviders setting on search endpoint (#11…
rqzbeh Aug 22, 2026
b2509bc
fix(release): drain v3.8.50 base-reds — getTokenLimit contract, vi i1…
diegosouzapw Aug 22, 2026
aa12873
fix(providers): remove Hack Club AI provider (#11118) (#11123)
rqzbeh Aug 22, 2026
56540f2
fix(api): save call logs and add endpoint fallback for local rerank p…
AndrianBalanescu Aug 22, 2026
80d931a
fix(logs): apply filter predicates to merged in-memory call-log rows …
AndrianBalanescu Aug 22, 2026
e15af18
fix(kimi): point kimi-web to international www.kimi.ai (#11045)
MeRezaRezaei Aug 22, 2026
7360ca4
feat(redis): add configurable key namespace prefix (#11042)
MeRezaRezaei Aug 22, 2026
445121f
docs: DEFAULT_RATE_LIMIT_PER_DAY unset is unlimited (#11031)
Prajeeth-12 Aug 22, 2026
c19c73f
fix(claude): restore canonical tool names so Claude Code accepts tool…
linhdmn Aug 22, 2026
5818cfb
docs(cli): update opencode.ts JSDoc to reflect 128k context fallback …
rqzbeh Aug 22, 2026
64b7389
fix(tests): update translate-path golden snapshot and docs for hailuo…
rqzbeh Aug 22, 2026
d3ac1a6
refactor(dashboard): mirror check button disable state in AddApiKeyMo…
rqzbeh Aug 22, 2026
ec6010f
fix(cli): resolve blank device code and undefined verification URL in…
rqzbeh Aug 22, 2026
805252a
feat(mcp): implement dynamic runtime tool schema plumbing for blocked…
rqzbeh Aug 22, 2026
7246e5a
fix(bun): update Dockerfile.bun entrypoint and native bun:sqlite inst…
rqzbeh Aug 22, 2026
de5e237
feat(ci): publish Bun container images (-bun and -web-bun) in Docker …
rqzbeh Aug 22, 2026
2edb7a1
fix(dashboard): keep the provider registry out of node:net (#11122) (…
yourspraveen Aug 22, 2026
ce66d31
fix(quality): drain v3.8.50 base-reds — doc counts + orphan uncloseai…
yourspraveen Aug 22, 2026
92ef3c7
fix(resilience): honor shared-registry passthrough providers (#11071)…
yourspraveen Aug 22, 2026
f387575
fix(memory): treat TokenRouter as system-must-be-first (live HTTP 400…
ggdayup Aug 23, 2026
b384455
fix(api): refuse creating a routing combo without any model (#11162)
maxmad64bis Aug 23, 2026
1058426
fix(executors): rotate on upstream 400 empty-body rejections (opencod…
maxmad64bis Aug 23, 2026
60f25ef
fix(sse): merge purify_history compression notice into the leading sy…
ggdayup Aug 23, 2026
80b8d2a
fix(sse): resume stream recovery after a clean stop with reasoning-on…
maxmad64bis Aug 23, 2026
62ab93d
fix(sse): reject a low-overlap stream-recovery continuation instead o…
maxmad64bis Aug 23, 2026
eb9fa33
feat(api): structured ?format=json for the self-service usage endpoin…
diegosouzapw Aug 23, 2026
3ef54fc
feat(api): return every connection's snapshot under providers[] in om…
diegosouzapw Aug 23, 2026
eb57973
feat(dashboard): add CheaperInference sponsor banner and route banner…
diegosouzapw Aug 23, 2026
d888f1a
fix(combo): accept SSE comment lines (e.g. OpenRouter keep-alives) in…
asorourx Aug 23, 2026
e73ab00
fix(codex): make remote compaction V2 complete reliably (#11041)
jackjinke Aug 23, 2026
2300171
fix(resilience): drain heavyweight SSE on SIGTERM (#11020)
RaviTharuma Aug 23, 2026
e52d2db
fix(compression): CCR must not strand prompts for callers without the…
HouMinXi Aug 23, 2026
28f55b8
board #10963 (GLM guard folded into tip effortTiers chain)
hartmark Aug 23, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
34 changes: 27 additions & 7 deletions .env.example
Original file line number Diff line number Diff line change
Expand Up @@ -87,6 +87,10 @@ DISABLE_SQLITE_AUTO_BACKUP=false
# Used by: src/shared/utils/rateLimiter.ts
# Example: redis://localhost:6379 (or redis://redis:6379 in Docker)
# REDIS_URL=redis://localhost:6379
# Namespace prefix for ALL OmniRoute Redis keys (rate limiter + auth cache +
# quota store). Prevents key collisions when OmniRoute shares a Redis instance
# with other apps (e.g. on 127.0.0.1:6379). Default when unset: omniroute:
# REDIS_KEY_PREFIX=omniroute:
# Host interface docker-compose publishes the Redis sidecar on.
# Default: 127.0.0.1 (loopback only). The compose Redis runs WITHOUT
# `requirepass`, and app containers reach it over the compose network
Expand Down Expand Up @@ -372,9 +376,8 @@ ALLOW_API_KEY_REVEAL=false
# NO_LOG_API_KEY_IDS=key_abc123,key_def456

# Fallback per-day request budget applied to API keys whose `rate_limits`
# column is null. Default (unset/empty/malformed) preserves the legacy
# 1000/day, 5000/week, 20000/month windows so existing deployments do not
# silently lose rate limiting on upgrade.
# column is null. Default (unset/empty) is unlimited (no implicit caps).
# Malformed values preserve the legacy 1000/day, 5000/week, 20000/month windows.
# Set explicitly to "0" to opt out entirely (unlimited fallback). Any
# positive integer N enables N/day, 5N/week, 20N/month.
# Used by: src/shared/utils/apiKeyPolicy.ts — checkRateLimit() fallback.
Expand Down Expand Up @@ -1483,6 +1486,20 @@ CURSOR_USER_AGENT="Cursor/3.4"
# OMNIROUTE_BROWSER_POOL=on
# WEB_COOKIE_USE_BROWSER=0

# ── Kimi Web (international kimi.ai Connect-RPC) ──
# Used by: open-sse/executors/kimi-web.ts. Override the base/chat URLs only if
# you need a mirror or proxy endpoint; defaults target https://www.kimi.ai with
# the Connect-RPC chat path /apiv2/kimi.gateway.chat.v1.ChatService/Chat.
# KIMI_WEB_BASE_URL=https://www.kimi.ai
# KIMI_WEB_CHAT_URL=https://www.kimi.ai/apiv2/kimi.gateway.chat.v1.ChatService/Chat

# When OIDC is enabled, disable password login so users can only authenticate
# via OIDC Single Sign-On. The bare alias OIDC_DISABLE_PASSWORD_LOGIN is also
# accepted; the Dashboard Feature Flag takes precedence. Used by:
# src/app/api/auth/login/route.ts, src/app/api/settings/require-login/route.ts.
# OMNIROUTE_OIDC_DISABLE_PASSWORD_LOGIN=false
# OIDC_DISABLE_PASSWORD_LOGIN=false

# ── Adobe Firefly browser sign-in (system Chrome/Edge CDP) ──
# Used by: open-sse/services/adobeFireflyBrowserLogin.ts. The Firefly login
# flow drives a real, system-installed Chrome or Microsoft Edge via CDP so the
Expand Down Expand Up @@ -1927,10 +1944,6 @@ APP_LOG_TO_FILE=true
# Default: 300000 (5 minutes)
# SEARCH_CACHE_TTL_MS=300000

# ── OpenAI-compatible multi-connection ──
# Allow multiple simultaneous connections per OpenAI-compatible provider node.
# Used by: src/app/api/providers/route.ts
# ALLOW_MULTI_CONNECTIONS_PER_COMPAT_NODE=false

# ── CC-compatible provider (experimental) ──
# Enable the Claude Code compatible provider endpoint.
Expand Down Expand Up @@ -2564,6 +2577,11 @@ APP_LOG_TO_FILE=true
# intended to be published as `omniroute-secure`. See SECURITY.md.
# OMNIROUTE_BUILD_PROFILE=full

# Override the standalone build output directory consumed by the post-build
# colocation step. Default: the real Next.js standalone output under .build/.
# Used by: scripts/build/colocate-standalone.mjs (build tooling, not runtime).
# OMNIROUTE_STANDALONE_DIR=

# Skip emitting `.tar.gz` tarballs during optional-pack staging for the Electron
# standalone tree (pack directories + optional-packs.index.json are still produced).
# Used by the desktop release workflow to trim artifact upload size.
Expand All @@ -2578,6 +2596,8 @@ APP_LOG_TO_FILE=true
# ELECTRON_SMOKE_DATA_DIR=
# ELECTRON_SMOKE_KEEP_DATA=0
# ELECTRON_SMOKE_STREAM_LOGS=0
# #7592: second launch against the same DATA_DIR must pick the native driver.
# ELECTRON_SMOKE_COLD_RESTART=0

# Playground Studio
# Default model used by the improve-prompt route (optional; falls back to model in request body).
Expand Down
9 changes: 7 additions & 2 deletions .github/workflows/dast-smoke.yml
Original file line number Diff line number Diff line change
Expand Up @@ -46,6 +46,7 @@ jobs:
env:
PORT: "20128"
INJECTION_GUARD_MODE: block
REQUIRE_API_KEY: "false"
run: |
node dist/server.js > server.log 2>&1 &
echo $! > server.pid
Expand All @@ -64,16 +65,20 @@ jobs:
# those 302s as "the API accepted a schema-violating request" and the configured-off
# 400 as "rejected a schema-compliant request". Documenting the flow in the spec is
# still right (operators need it); fuzzing it is not what this smoke is for.
# /api/auth/login has brute-force rate limiting: repeated failed logins return 429,
# which Schemathesis flags as rejection of schema-compliant requests.
schemathesis run docs/openapi.yaml --url http://localhost:20128 \
--include-path-regex '^/v1/(chat/completions|models)$|^/api/(auth|keys)' \
--exclude-path-regex '^/api/auth/oidc/' \
--exclude-path-regex '^/api/auth/(oidc/|login)' \
--max-examples 8 --workers 4 --checks all --max-response-time 30 \
--request-timeout 20 --suppress-health-check all --no-color
- name: Install promptfoo
run: npm install -g promptfoo@0.122.0
- name: promptfoo injection-guard (blocking)
env:
OMNIROUTE_URL: http://localhost:20128
OMNIROUTE_API_KEY: not-needed-blocked-before-upstream
run: npx --yes promptfoo@latest eval -c promptfooconfig.yaml --no-cache
run: promptfoo eval -c promptfooconfig.yaml --no-cache
- name: Stop server
if: always()
run: kill "$(cat server.pid)" || true
Expand Down
76 changes: 75 additions & 1 deletion .github/workflows/docker-publish.yml
Original file line number Diff line number Diff line change
Expand Up @@ -183,15 +183,55 @@ jobs:
env:
DOCKER_BUILDKIT_INLINE_CACHE: 1

- name: Build and push BUN base platform image by digest
id: build-bun-base
uses: docker/build-push-action@53b7df96c91f9c12dcc8a07bcb9ccacbed38856a # v7
with:
context: .
file: Dockerfile.bun
target: runner-base
platforms: ${{ matrix.platform }}
outputs: type=image,push-by-digest=true,name-canonical=true,push=true
tags: |
${{ env.IMAGE_NAME }}
${{ env.GHCR_IMAGE_NAME }}
cache-from: type=gha,scope=docker-bun-base-${{ matrix.arch }}
cache-to: type=gha,scope=docker-bun-base-${{ matrix.arch }},mode=max
no-cache: false
env:
DOCKER_BUILDKIT_INLINE_CACHE: 1

- name: Build and push BUN web platform image by digest
id: build-bun-web
uses: docker/build-push-action@53b7df96c91f9c12dcc8a07bcb9ccacbed38856a # v7
with:
context: .
file: Dockerfile.bun
target: runner-web
platforms: ${{ matrix.platform }}
outputs: type=image,push-by-digest=true,name-canonical=true,push=true
tags: |
${{ env.IMAGE_NAME }}
${{ env.GHCR_IMAGE_NAME }}
cache-from: type=gha,scope=docker-bun-web-${{ matrix.arch }}
cache-to: type=gha,scope=docker-bun-web-${{ matrix.arch }},mode=max
no-cache: false
env:
DOCKER_BUILDKIT_INLINE_CACHE: 1

- name: Export digests
env:
DIGEST_BASE: ${{ steps.build.outputs.digest }}
DIGEST_WEB: ${{ steps.build-web.outputs.digest }}
DIGEST_BUN_BASE: ${{ steps.build-bun-base.outputs.digest }}
DIGEST_BUN_WEB: ${{ steps.build-bun-web.outputs.digest }}
run: |
set -euo pipefail
mkdir -p /tmp/digests/base /tmp/digests/web
mkdir -p /tmp/digests/base /tmp/digests/web /tmp/digests/bun-base /tmp/digests/bun-web
touch "/tmp/digests/base/${DIGEST_BASE#sha256:}"
touch "/tmp/digests/web/${DIGEST_WEB#sha256:}"
touch "/tmp/digests/bun-base/${DIGEST_BUN_BASE#sha256:}"
touch "/tmp/digests/bun-web/${DIGEST_BUN_WEB#sha256:}"

- name: Upload base digests
uses: actions/upload-artifact@v7
Expand All @@ -209,6 +249,22 @@ jobs:
if-no-files-found: error
retention-days: 1

- name: Upload bun-base digests
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7
with:
name: digests-bun-base-${{ matrix.arch }}
path: /tmp/digests/bun-base/*
if-no-files-found: error
retention-days: 1

- name: Upload bun-web digests
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7
with:
name: digests-bun-web-${{ matrix.arch }}
path: /tmp/digests/bun-web/*
if-no-files-found: error
retention-days: 1

merge:
name: Publish multi-arch manifests
needs:
Expand Down Expand Up @@ -263,6 +319,20 @@ jobs:
path: /tmp/digests/web
merge-multiple: true

- name: Download bun-base digests
uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8
with:
pattern: digests-bun-base-*
path: /tmp/digests/bun-base
merge-multiple: true

- name: Download bun-web digests
uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8
with:
pattern: digests-bun-web-*
path: /tmp/digests/bun-web
merge-multiple: true

- name: Create Docker Hub manifest
run: |
set -euo pipefail
Expand All @@ -286,6 +356,8 @@ jobs:

create_manifest "${IMAGE_NAME}" "" /tmp/digests/base
create_manifest "${IMAGE_NAME}" "-web" /tmp/digests/web
create_manifest "${IMAGE_NAME}" "-bun" /tmp/digests/bun-base
create_manifest "${IMAGE_NAME}" "-web-bun" /tmp/digests/bun-web

- name: Create GHCR manifest
run: |
Expand All @@ -310,6 +382,8 @@ jobs:

create_manifest "${GHCR_IMAGE_NAME}" "" /tmp/digests/base
create_manifest "${GHCR_IMAGE_NAME}" "-web" /tmp/digests/web
create_manifest "${GHCR_IMAGE_NAME}" "-bun" /tmp/digests/bun-base
create_manifest "${GHCR_IMAGE_NAME}" "-web-bun" /tmp/digests/bun-web

- name: Inspect image
if: needs.prepare.outputs.version != 'main'
Expand Down
5 changes: 5 additions & 0 deletions .github/workflows/electron-release.yml
Original file line number Diff line number Diff line change
Expand Up @@ -279,9 +279,14 @@ jobs:

- name: Smoke packaged Electron app (Linux)
if: matrix.platform == 'linux'
# #7592: also cold-restart against the same DATA_DIR and assert a
# native SQLite driver (not the sql.js WASM fallback) is selected on
# the second launch — blocking here since Linux has no Windows-style
# sandbox caveats that would make it flaky.
env:
ELECTRON_SMOKE_TIMEOUT_MS: 60000
ELECTRON_SMOKE_STREAM_LOGS: "1"
ELECTRON_SMOKE_COLD_RESTART: "1"
run: xvfb-run -a npm run electron:smoke:packaged

- name: Collect installers
Expand Down
1 change: 1 addition & 0 deletions .gitignore
Original file line number Diff line number Diff line change
Expand Up @@ -291,3 +291,4 @@ docker-compose.yml.bak

# Ad-hoc test sandboxes (never tracked — may contain local DBs)
/.sandbox/
.aider*
6 changes: 3 additions & 3 deletions AGENTS.md
Original file line number Diff line number Diff line change
Expand Up @@ -46,7 +46,7 @@ Repository map and Reference Documentation sections below.

## Project at a Glance

**OmniRoute** — unified AI proxy/router. One endpoint, 346 LLM providers, auto-fallback.
**OmniRoute** — unified AI proxy/router. One endpoint, 348 LLM providers, auto-fallback.

| Layer | Location | Purpose |
| ------------- | ----------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
Expand All @@ -56,9 +56,9 @@ Repository map and Reference Documentation sections below.
| Translators | `open-sse/translator/` | Format conversion (OpenAI↔Claude↔Gemini) |
| Transformer | `open-sse/transformer/` | Responses API ↔ Chat Completions |
| Services | `open-sse/services/` | Combo routing, rate limits, caching, etc |
| Database | `src/lib/db/` | SQLite domain modules (157 migrations) |
| Database | `src/lib/db/` | SQLite domain modules (159 migrations) |
| Domain/Policy | `src/domain/` | Policy engine, cost rules, fallback logic |
| MCP Server | `open-sse/mcp-server/` | 109 tools (44 canonical + memory/skill/GitHub/pool/gamification/plugin/Notion/Obsidian/local-corpus/RTK modules), 3 transports (stdio / SSE / Streamable HTTP), 33 scopes |
| MCP Server | `open-sse/mcp-server/` | 110 tools (44 canonical + memory/skill/GitHub/pool/gamification/plugin/Notion/Obsidian/local-corpus/RTK modules), 3 transports (stdio / SSE / Streamable HTTP), 33 scopes |
| A2A Server | `src/lib/a2a/` | JSON-RPC 2.0 agent protocol |
| Skills | `src/lib/skills/` | Extensible skill framework |
| Memory | `src/lib/memory/` | Persistent conversational memory |
Expand Down
13 changes: 13 additions & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -2,13 +2,26 @@

## [Unreleased]

### ✨ New Features

- **feat(sse): STRICT_ZERO_COST** — opt-in, off-by-default `freeAccessPolicy: "strict"` setting
that hard-verifies every auto-combo candidate against live quota state and per-connection
economic safety before it can be dispatched, going beyond `hidePaidModels`'s static catalog
check. Adds curated `hardStopGuaranteed` metadata to `FREE_MODEL_BUDGETS`, a short-TTL quota
cache reusing `getUsageForProvider()`, and a connection-safety guarantee: a candidate backed
by multiple accounts has its `allowedConnectionIds` narrowed to exactly the connections
independently verified `SAFE`, so dispatch can never use an unverified account. An
`excludeTosAvoid` guard (default `false`) is available separately for contractual risk. See
`docs/routing/STRICT_ZERO_COST.md`.

---

## [3.8.50] — TBD

_Living section — regenerated 2026-08-12 from all cycle commits (cycle open `ed2db6cb19` → tip). Bullets carry the merged PR and its author; direct pushes listed separately._

### ✨ New Features
- **feat(search):** first-class X Search provider (`x-search`) on `POST /v1/search` and MCP `omniroute_x_search` using SuperGrok / xAI server-side `x_search`. Explicit provider or `search_type: "x"` only — never auto-selected for web. Reuses `xai-oauth` / `xao` / `xai` credentials. Not the X Developer Platform MCP. ([#10985](https://github.com/diegosouzapw/OmniRoute/issues/10985))
- **feat(core):** add Layer A capability filter at router (#5696)
- **feat(providers):** add DeepAI as paid API-key image provider ([#6671](https://github.com/diegosouzapw/OmniRoute/issues/6671))
- **feat(providers):** add Naga.ac and ChatAnywhere aggregator gateway providers (#6674 — thanks @chirag127)
Expand Down
Loading
Loading