Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
137 commits
Select commit Hold shift + click to select a range
4bd8941
fix(context): calibrate the chars/4 guard estimate with provider-repo…
Sep 29, 2026
2b8d76b
docs(changelog): name the 15054 estimator-calibration fragment and fo…
Oct 6, 2026
2d6d630
docs(i18n): refresh QUALITY_GATES and CONTRIBUTING mirrors across 66 …
diegosouzapw Oct 6, 2026
c079319
fix(api): synthesize string response.id for /v1/responses frames (#15…
yugui923 Oct 6, 2026
da4ddc2
refactor(sse): split handleChatCore into four response-path leaves (#…
HouMinXi Oct 6, 2026
759ab84
fix(proxy-health): skip sweep probes already proven by recent product…
maxmad64bis Oct 6, 2026
563d5df
fix(sse): keep dead Codex refresh token from tripping provider breake…
maxmad64bis Oct 6, 2026
1fe734f
fix(open-sse): replay title-shaped insufficient_quota refusals once (…
maxmad64bis Oct 6, 2026
8349538
feat(i18n): forward the optional reasoning control in the translation…
maxmad64bis Oct 6, 2026
c88abe8
fix(opencode): count silent streamed replies while the first-byte gua…
maxmad64bis Oct 6, 2026
71cc636
fix(providers): a 400 or 429 reading "endpoint is unavailable" now pa…
maxmad64bis Oct 6, 2026
5e232bc
fix(api): log wrapper admission rejections to the request journal (#1…
maxmad64bis Oct 6, 2026
9e0a2f4
fix(proxies): share the refusal store across duplicated server module…
maxmad64bis Oct 6, 2026
95555ed
fix(proxies): set aside region-refused members briefly (#15383)
maxmad64bis Oct 6, 2026
3d43b67
fix(opencode): only a refusal naming the model clears borrowed tools …
maxmad64bis Oct 6, 2026
73565a5
chore(skills): regenerate omni-providers endpoints reference from ope…
diegosouzapw Oct 6, 2026
994324f
feat(i18n): translate several locales per request in sync-ui-keys (#1…
maxmad64bis Oct 6, 2026
2eee95e
feat(plugin): publish useful catalog entries by default, full list on…
maxmad64bis Oct 6, 2026
a23b48c
fix(dashboard): stop reporting import success when discovery was degr…
jonlwheat2-gif Oct 6, 2026
d933c22
test(auth): pin the invariant that makes the 8 provider-auth routes s…
jonlwheat2-gif Oct 6, 2026
90f97f6
fix(mcp): one shared internal hop, read lazily (#15159 M-06) (#15468)
jonlwheat2-gif Oct 6, 2026
0f944a3
fix(providers): point freetheai at freetheai.org (#15385) (#15520)
jonlwheat2-gif Oct 6, 2026
2f29eb2
fix(ci): make check:error-helper trust the call, not the file (#15159…
jonlwheat2-gif Oct 6, 2026
566c203
fix(speech): sanitize upstream audio/transcription error bodies (#151…
jonlwheat2-gif Oct 6, 2026
e05f1bd
fix(transcription): sanitize the Kie createTask failure body (#15159 …
jonlwheat2-gif Oct 6, 2026
655ef61
chore(quality): freeze gateways.ts growth from the freetheai domain m…
diegosouzapw Oct 6, 2026
3efc28e
fix(auth): never sign anyone in through OIDC without an allowlist (#1…
HouMinXi Oct 6, 2026
e381601
fix(auth): let a cache-scoped key reach the cache routes (#15430)
HouMinXi Oct 6, 2026
7daf296
fix(auth): keep a provider wildcard inside the provider it names (#15…
HouMinXi Oct 6, 2026
acecd16
fix(auth): revoke one access token by prefix and stop rewriting last …
HouMinXi Oct 6, 2026
2b2e546
fix(backend): keep TLS fingerprinting when a request carries Next.js …
HouMinXi Oct 6, 2026
408b4f2
fix(sse): drop a replayed responses event when the sequence is a stri…
HouMinXi Oct 6, 2026
588ccb7
fix(sse): keep a clean empty Claude end_turn (#15505)
HouMinXi Oct 6, 2026
bf1f9e8
fix(responses): stop marking native collaboration calls as plaintext …
HouMinXi Oct 6, 2026
ebf3120
fix(quota): register the tracker batch after its binding is ready (#1…
HouMinXi Oct 6, 2026
0256b3d
fix(providers): do not treat a Claude weekly warning as exhaustion (#…
HouMinXi Oct 6, 2026
73582bd
fix(providers): pace Codex usage fetches that bypass the quota gate (…
HouMinXi Oct 6, 2026
866a361
fix(combo): lock a model after a local target timeout (#15494)
HouMinXi Oct 6, 2026
3361111
fix(combo): type the custom-model row in the auto pool check (#15461)
HouMinXi Oct 6, 2026
489428b
fix(mcp): read cost totals from the analytics summary (#15355)
HouMinXi Oct 6, 2026
e8b1a98
test(api): lock the filtered models response against a stale content-…
HouMinXi Oct 6, 2026
a5a056e
fix(dashboard): show the message inside a Cloudflare tunnel error obj…
HouMinXi Oct 6, 2026
a45b818
fix(providers): show a No Auth provider's real requirement on its ban…
HouMinXi Oct 6, 2026
593c851
test(executors): lock the thinking budget against raising a caller ma…
HouMinXi Oct 6, 2026
06090d3
fix(cli): send --allow-no-credential to the server (#15416)
HouMinXi Oct 6, 2026
58269a7
fix(cli): scope the serve port guard to the bind address (#15472)
HouMinXi Oct 6, 2026
83f1a98
fix(providers): load the ChatGPT web validator only when it is tested…
HouMinXi Oct 6, 2026
83b653d
fix(ci): register the cycles ratchet script in the gate manifest (#15…
HouMinXi Oct 6, 2026
fdf397f
build: stamp the service worker after the public directory is recopie…
HouMinXi Oct 6, 2026
15c9588
search: make the search deadlines configurable (#15495)
HouMinXi Oct 6, 2026
5be6f03
feat(claude): add Claude Sonnet 5.5 and correct Sonnet 5 pricing (#15…
HouMinXi Oct 6, 2026
ef3b71c
feat(identity): refresh pinned CLI versions from their release feeds …
HouMinXi Oct 6, 2026
4f4c983
chore(quality): freeze the wave-2 file-size growth (#15680)
diegosouzapw Oct 6, 2026
b8c50e1
fix(release): drain three v3.8.52 base-reds — cycles fast-gate, stale…
woodsonl Oct 6, 2026
ae5d1d6
fix(ci): give the file-size test gate its base LOC in PR mode (#15298)
woodsonl Oct 6, 2026
a46b309
test(plugins): isolate plugin dir per test process (#15296)
woodsonl Oct 6, 2026
ed9188f
fix(db): let current compression engine rows win over legacy keys (#1…
woodsonl Oct 6, 2026
38a2660
refactor(db): drop unreachable aggressiveEnabled fallback in engines-…
woodsonl Oct 6, 2026
e1e9230
fix(compression): merge engines writes by id instead of replacing the…
woodsonl Oct 6, 2026
9d6d1ad
fix(compression): apply the lossy policy to the default-combo fallbac…
woodsonl Oct 6, 2026
f07c521
test(compression): make output-style checks able to fail (#15614)
woodsonl Oct 6, 2026
44efe61
fix(compression): match legacy output text in hu, ja and zh (#15591)
woodsonl Oct 6, 2026
8c1ccf5
fix(db): union dispatch-tagged registry models into authoritative liv…
woodsonl Oct 6, 2026
f43c467
fix(compression): show a retry when settings fail to load (#15346)
woodsonl Oct 6, 2026
02f4358
fix(compression): roll panel saves back per field and resync after a …
woodsonl Oct 6, 2026
a9dbbb0
fix(compression): surface failed settings loads on Hub, Combos and RT…
woodsonl Oct 6, 2026
80a6b73
fix(compression): make the hub safe for overlapping saves (#15593)
woodsonl Oct 6, 2026
7ddee9b
fix(dashboard): show exclusions and RTK save failures, queue RTK conf…
woodsonl Oct 6, 2026
e153401
fix(compression): show a retry when the omniglyph page's settings loa…
woodsonl Oct 6, 2026
6a7361a
fix(dashboard): treat an emptied engine number field as unset (#15612)
woodsonl Oct 6, 2026
39f788b
fix(compression): honor the sent engine config in engine previews (#1…
woodsonl Oct 6, 2026
5e2968b
fix: stop flooring ccr retrievalRampFactor on read (#15603)
woodsonl Oct 6, 2026
11f8c29
fix(compression): one Auto-Clarity control on the caveman page, no st…
woodsonl Oct 6, 2026
25ff0ea
fix(dashboard): preview the injected output-style block (#15589)
woodsonl Oct 6, 2026
5a4b681
docs(compression): align guide claims with source (#15596)
woodsonl Oct 6, 2026
c905a2d
test(compression): cover every Auto-Clarity style source in the pipel…
woodsonl Oct 6, 2026
5fb5121
docs(i18n): carry the corrected ENVIRONMENT.md segments into all loca…
woodsonl Oct 6, 2026
d6b7f72
fix(dashboard): correct the four guard-flag descriptions to the audit…
woodsonl Oct 6, 2026
de762dc
docs: describe check:file-size PR mode accurately (#15345)
woodsonl Oct 6, 2026
5a82a1c
fix(compression): drop the dead per-engine Preserve system prompt che…
woodsonl Oct 6, 2026
db23ab3
chore(i18n): record the wave-3 doc hashes (#15684)
diegosouzapw Oct 6, 2026
f715c86
perf(db): cover the provider health matrix ranking with an index (#15…
maxmad64bis Oct 6, 2026
6d18345
chore(deps): bump trunk-io/analytics-uploader from 2.1.3 to 2.1.5 (#1…
dependabot[bot] Oct 6, 2026
09bd92d
chore(deps): bump github/codeql-action/init from 4.38.1 to 4.38.2 (#1…
dependabot[bot] Oct 6, 2026
e032892
chore(deps): bump github/codeql-action from 4.38.1 to 4.38.2 (#15372)
dependabot[bot] Oct 6, 2026
f4fc9fa
chore(deps): bump github/codeql-action/analyze from 4.38.1 to 4.38.2 …
dependabot[bot] Oct 6, 2026
9dcfa58
chore(deps-dev): bump http-cache-semantics (#15648)
dependabot[bot] Oct 6, 2026
5afba78
deps: bump electron from 44.4.3 to 44.5.1 in /electron (#15577)
dependabot[bot] Oct 6, 2026
266ded0
deps: bump http-cache-semantics (#15649)
dependabot[bot] Oct 6, 2026
77bca6f
fix(sse): skip Trae upstream status on a 2xx with no body (#15686)
diegosouzapw Oct 6, 2026
7534c77
perf(usage): cache slow analytics responses so the dashboard stops bl…
HDBR Oct 6, 2026
0e5425d
fix(usage): bound the pending-request map by retained bytes, not entr…
alvinveroy Oct 6, 2026
511ea7e
fix(db): preserve explicit provider priorities on edit (#15485)
piyush97 Oct 6, 2026
8f0f85c
fix(cli): prefer an existing ~/.omniroute over XDG_CONFIG_HOME in eve…
grapeslush Oct 6, 2026
6a8ee68
fix(cli): spawn npm without DEP0190 on win32 (#15328)
Yi-111-a Oct 6, 2026
f080d71
fix(memory): bound synchronous lexical query work (#15549)
seanford Oct 6, 2026
525ad35
fix(test): drain the served body so stream-readiness leaves no async …
BenjaminAronsson Oct 6, 2026
6fed193
fix(sse): stop stream content stalls from cooling down the account (#…
fouadSalkini Oct 6, 2026
f80cba2
fix(resilience): keep RELAY_TIMEOUT from killing the server via the c…
Theadd Oct 6, 2026
03b3b9e
fix(auto-combo): a quota the fetcher could not read no longer scores …
shannonlowder Oct 6, 2026
3a9ea49
fix: honor Codex quota filter opt-out (#15574)
KiaroSama Oct 6, 2026
e773d96
fix(providers): keep tiered Claude 5.x ids literal on Antigravity (#1…
edosulai Oct 6, 2026
1598919
fix(usage): keep Antigravity family weekly quota keys (#15359)
edosulai Oct 6, 2026
ae10076
fix(translator): disambiguate chronological Gemini tool IDs (#15319)
Kizuno18 Oct 6, 2026
47407e1
fix(translator): resolve the Claude thinking output cap with the rout…
Juriseagle Oct 6, 2026
1bac7b5
fix(providers): omit thinkingBudget 0 on Flash-Lite models (#15491) (…
claw-io Oct 6, 2026
07c66b8
fix(sse): clamp MiMo V2.5/V2.6 reasoning effort on OpenCode (#15299)
fidelix Oct 6, 2026
f7bb503
fix(opencode): declare targetFormat openai-responses for opencode-go …
c4lyp5o Oct 6, 2026
841d180
fix(sse): reject premature upstream EOF in Responses translation (#15…
fidelix Oct 6, 2026
cee37af
fix(sse): preserve Copilot discovered endpoint routing (#15337)
zebrajaeger Oct 6, 2026
b13eaa2
feat(proxy): add an operator HTTP/2 opt-out (#15318)
Kizuno18 Oct 6, 2026
111140b
fix(providers): live model discovery for xiaomi-mimo / xiaomi-mimo-to…
LazyGatto Oct 6, 2026
db3753a
fix(cli): expose built-in auto combos to Claude Code discovery (#15301)
VihaanR Oct 6, 2026
18ee7b7
feat(providers): add Perplexity integration attribution header (#15573)
qirh Oct 6, 2026
f013fd9
fix(qoder): make PAT validation and transient CLI failures robust (#1…
christianmahardhika Oct 6, 2026
b41c7c7
fix(antigravity): strip stream field from Google request envelope (#1…
alltomatos Oct 6, 2026
cda0f92
fix: prevent proxied stream crashes and normalize Groq reasoning (#15…
kalpakprod Oct 6, 2026
17d1cca
fix(sse): register quota batch after imports resolve (#15548)
wedreamer Oct 6, 2026
87b2350
chore(quality): record wave 5 file-size and i18n hashes (#15692)
diegosouzapw Oct 6, 2026
ed0cc91
fix(combo): include monthly quota in reset-aware scoring (#15480)
lorenzozanee Oct 6, 2026
4d470c7
fix(api): route provider-model handlers through management auth (#15479)
lorenzozanee Oct 6, 2026
f2b3dcd
fix(sse): make streaming fetch-start cap configurable (#15542)
lorenzozanee Oct 6, 2026
74eb213
fix(providers): route Command Code Claude models to Messages (#15543)
lorenzozanee Oct 6, 2026
350cbac
docs: clarify npm 11 allow-scripts for global installs (#15541)
lorenzozanee Oct 6, 2026
204de62
fix(kiro): stop discovery from stamping a fake 200k context window (#…
QuangBlue Oct 6, 2026
bdaa86c
fix(api): keep Next's upgrade listener off the run-next server (#15332)
QuangBlue Oct 6, 2026
f12801d
fix(api): standalone server owns SIGTERM so graceful-shutdown cleanup…
QuangBlue Oct 6, 2026
3bb5259
fix(sse): scope type-only context errors in combo streams (#15597)
insoln Oct 6, 2026
09a1624
fix(sse): accept first-party Claude empty end_turn in combo quality g…
insoln Oct 6, 2026
ea48360
fix(sse): stabilize standalone compression worker resolution (#12797)…
insoln Oct 6, 2026
803ab45
test(compression): make worker-specifier and RTK TOML assertions cros…
Junior-HJ Oct 6, 2026
6fc4375
fix(api): stop restricted-key /v1/models leaking aggregator rows via …
yourspraveen Oct 6, 2026
e8a18fc
fix(providers): keep a third-party agent's own User-Agent on OpenCode…
yourspraveen Oct 6, 2026
2c910fd
docs(readme): list auto/subscription and auto/thrifty in the zero-con…
yourspraveen Oct 6, 2026
3cd2d6f
fix(combo): keep declared priority order ahead of session stickiness …
skygunner Oct 6, 2026
697ab20
fix(providers): declare Claude target format for GHE Copilot models (…
lorenzozanee Oct 6, 2026
6b5a88a
fix(sse): calibrate estimator usage on the split chat path
diegosouzapw Oct 6, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
72 changes: 57 additions & 15 deletions .env.example
Original file line number Diff line number Diff line change
Expand Up @@ -22,9 +22,12 @@ JWT_SECRET=
API_KEY_SECRET=

# Initial admin login password — CHANGE THIS before first use!
# Used by: bootstrap only — sets the initial dashboard password on first boot.
# Used by: src/lib/auth/managementPassword.ts — sets the dashboard password at startup
# while none is saved yet; ignored once a password is saved.
# After first login you can change it from Dashboard → Settings → Security.
# Default: CHANGEME (insecure, for local dev only)
# CHANGEME (this template's value) is publicly known. npm and source installs copy this
# file to .env, so replace CHANGEME there before first boot, or set INITIAL_PASSWORD=
# (empty) there to create the password in the dashboard's onboarding wizard instead.
INITIAL_PASSWORD=CHANGEME

# ═══════════════════════════════════════════════════════════════════════════════
Expand Down Expand Up @@ -552,20 +555,36 @@ ALLOW_API_KEY_REVEAL=false
# CORS_ORIGIN=https://your-frontend.example.com # legacy single-origin alias
# CORS_ALLOW_ALL=false

# Allow provider URLs pointing to private/local networks (localhost, 192.168.x.x, etc.).
# REQUIRED for self-hosted providers: LM Studio, Ollama, vLLM, Llamafile, Triton, etc.
# Used by: src/shared/network/outboundUrlGuard.ts — disables SSRF guard for provider calls.
# Default: false (blocked) | Set true to enable local providers.
# Turns off the outbound URL guard's host checks, cloud-metadata block included, on the
# provider paths that follow the guard mode: URL validation, model discovery, provider-node
# base URLs (including remote rerank nodes), and the proxy-fallback test, among other
# provider-adjacent outbound paths such as remote image/media fetch. It also allows
# private webhook targets, except cloud-metadata/link-local endpoints, which stay
# blocked even with this flag on. Local providers work with the defaults:
# OMNIROUTE_ALLOW_LOCAL_PROVIDER_URLS below (default true) already allows local and LAN
# URLs. A value saved from the dashboard toggle takes precedence over this variable.
# Details: docs/reference/ENVIRONMENT.md.
# Used by: src/shared/network/outboundUrlGuardPolicy.ts
# Default: false
# OMNIROUTE_ALLOW_PRIVATE_PROVIDER_URLS=true

# Allow adding/validating providers on local/private addresses (127.0.0.1, localhost, LAN).
# Used by: src/shared/network/outboundUrlGuard.ts — scopes to the provider validation path and
# still blocks cloud-metadata (169.254.169.254, metadata.google.internal). Default: true
# (OmniRoute is local-first). Set false to enforce strict public-only blocking.
# Allow provider URLs on local and private addresses (127.0.0.1, localhost, LAN).
# Default: true (OmniRoute is local-first); the guard then blocks cloud-metadata
# endpoints — all of 169.254.0.0/16 plus the known metadata hostnames. Set false to
# block private and loopback hosts too (public-only mode). The guard checks the
# hostname or IP literal as written first; in public-only mode the safe-fetch
# wrapper (validation, model discovery) also resolves the name and refuses
# private answers.
# Built-in local providers skip these checks for key validation and chat.
# A value saved from the dashboard toggle takes precedence over this variable.
# Used by: src/shared/network/outboundUrlGuardPolicy.ts
# OMNIROUTE_ALLOW_LOCAL_PROVIDER_URLS=false

# Legacy alias toggling the SSRF guard. Used by: src/shared/network/outboundUrlGuard.ts
# When unset, OmniRoute uses the per-feature defaults. Set to "false"/"0" to disable.
# Legacy alias; its dashboard toggle (a DB override) is read before this environment value.
# "false", "0", "no", or "off" in either turns the host checks off the way
# OMNIROUTE_ALLOW_PRIVATE_PROVIDER_URLS=true does, even when that flag's dashboard toggle
# is saved off. Other values leave the guard to the two flags above.
# Used by: src/shared/network/outboundUrlGuardPolicy.ts
# OUTBOUND_SSRF_GUARD_ENABLED=true

# ── Self-hosted unified OpenAI-compatible entry (RIC-738, D4) ────────────────────
Expand Down Expand Up @@ -888,6 +907,12 @@ NEXT_PUBLIC_ENABLE_SOCKS5_PROXY=true
# Set to 1 only for legacy diagnostics. Values above 256 are capped.
# OMNIROUTE_PROXY_DISPATCHER_CONNECTIONS=32

# HTTP/2 negotiation for Undici upstream dispatchers (direct, HTTP/SOCKS proxies,
# relays and their retries). Explicit false/0/no/off forces HTTP/1.1.
# Does not control wreq TLS fingerprinting or provider-specific transports.
# Restart OmniRoute after changing this value; dispatchers are cached.
# OMNIROUTE_UPSTREAM_HTTP2_ENABLED=true

# SOCKS5 handshake (connect) timeout in ms (default 10000, capped at 120000).
# Raise it when a single residential gateway host is hit by high concurrency
# (e.g. 100 simultaneous requests): the real SOCKS5 handshake can exceed 10s
Expand Down Expand Up @@ -1686,6 +1711,8 @@ CURSOR_USER_AGENT="Cursor/3.4"
# FETCH_TIMEOUT_MS=600000 # Total request timeout (default: 600000 = 10 min)
# # Also drives anthropic-compatible-cc-* X-Stainless-Timeout.
# FETCH_HEADERS_TIMEOUT_MS=600000 # Time to receive response headers
# Maximum response-header wait (ms) for streaming requests. Default: 110000; 0 disables.
# OMNIROUTE_FETCH_START_TIMEOUT_CAP_MS=110000
# FETCH_BODY_TIMEOUT_MS=600000 # Time to receive full response body
# FETCH_CONNECT_TIMEOUT_MS=30000 # TCP connection establishment (default: 30s)
# FETCH_KEEPALIVE_TIMEOUT_MS=4000 # Keep-alive socket idle timeout (default: 4s)
Expand Down Expand Up @@ -2234,6 +2261,13 @@ APP_LOG_TO_FILE=true
# Default: 2592000000 (30 days)
# OMNIROUTE_SYNCED_CATALOG_STALE_AFTER_MS=2592000000

# Response cache for GET /api/usage/analytics (#15629). Only responses that took at
# least MIN_COMPUTE_MS to build are kept, per query string, for TTL_MS.
# Used by: src/lib/usage/analyticsResponseCache.ts
# Default: 60000 (60 seconds; 0 disables) and 1000 (1 second)
# OMNIROUTE_ANALYTICS_CACHE_TTL_MS=60000
# OMNIROUTE_ANALYTICS_CACHE_MIN_COMPUTE_MS=1000

# ── NanoBanana (Image Generation) ──
# Polling config for async image generation jobs.
# Used by: open-sse/handlers/imageGeneration.ts
Expand Down Expand Up @@ -2488,6 +2522,13 @@ APP_LOG_TO_FILE=true
# never used for routing). "true" (or 1, yes) enables it.
# PROXY_POOL_EGRESS_OBSERVATION=false

# Opt-in: skip the scheduler probe for proxies already proven by recent
# production traffic (single provider, no recent proxy failure). Default: off.
# PROXY_HEALTH_PASSIVE_SKIP=false
# Window in ms of production traffic the passive skip looks at (60000..599999).
# Default: 300000 (5min).
# PROXY_PASSIVE_WINDOW_MS=300000

# Allow OAuth and provider validation flows to bypass a pinned proxy and connect
# directly when proxy reachability pre-checks fail. Default: false.
# Also configurable from Dashboard > Settings > Feature Flags.
Expand Down Expand Up @@ -2874,9 +2915,8 @@ APP_LOG_TO_FILE=true
# hosted outside localhost, e.g. a LAN box or Tailscale peer running TEI/Infinity/vLLM.
# OFF by default: routing to a remote host changes egress identity, so it must be an
# explicit operator decision. Loopback/private nodes (localhost, 127.0.0.1,
# 172.16-31.x) are always allowed and unaffected by this flag. Remote nodes must also
# pass the provider outbound URL policy (see OMNIROUTE_ALLOW_LOCAL_PROVIDER_URLS);
# cloud-metadata hosts are never routed to.
# 172.16-31.x) are always allowed and unaffected by this flag. A remote node's base URL
# must also pass the provider outbound URL policy (see OMNIROUTE_ALLOW_LOCAL_PROVIDER_URLS).
# RERANK_REMOTE_PROVIDER_NODES=false

# ── Free Proxy Pool (auto-sync scheduler) ──
Expand Down Expand Up @@ -3017,6 +3057,8 @@ APP_LOG_TO_FILE=true
# OMNIROUTE_TRANSLATION_MODEL=gpt-4o-mini
# Per-request timeout in milliseconds (default 60000).
# OMNIROUTE_TRANSLATION_TIMEOUT_MS=60000
# Optional reasoning control, sent as-is to the translation backend when set (e.g. none).
# OMNIROUTE_TRANSLATION_REASONING_EFFORT=
# Number of parallel translation requests (default 4).
# OMNIROUTE_TRANSLATION_CONCURRENCY=4

Expand Down
12 changes: 8 additions & 4 deletions .env.selfhost.example
Original file line number Diff line number Diff line change
Expand Up @@ -23,11 +23,15 @@ APP_BIND_HOST=127.0.0.1

# ── Auth ──────────────────────────────────────────────────────────────
# false = the dashboard and /v1 proxy are open to APP_BIND_HOST's network.
# true = every request needs an API key / dashboard login. The dashboard
# auto-creates INITIAL_PASSWORD on first boot (read it from the logs:
# `docker logs omniroute | grep -i password`). # EDIT ME — set true.
# true = /v1 requests need an API key (a logged-in dashboard session also works);
# the dashboard needs login once a password
# exists. Create the login password in the onboarding wizard on first visit
# (skipping that step turns dashboard login off, even with
# REQUIRE_API_KEY=true); after you submit it, the wizard asks for
# a one-time token from `docker logs omniroute | grep BOOTSTRAP`.
# # EDIT ME — set true.
REQUIRE_API_KEY=false
# INITIAL_PASSWORD= # uncomment to pre-seed the dashboard password
# INITIAL_PASSWORD=strong-password-here # fill in to pre-seed the dashboard password (an empty value behaves like unset)

# ── Memory ceiling (V8 old-space) ──────────────────────────────────────
# 1024 = dashboard + light chat. Coding agents (long POST /v1/responses
Expand Down
8 changes: 6 additions & 2 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -741,6 +741,10 @@ jobs:
- run: npm run build
env:
OMNIROUTE_USE_TURBOPACK: "1"
- name: Verify colocated compression worker
run: node --import tsx/esm --test tests/integration/compression-worker-standalone.int.test.ts
env:
RUN_STANDALONE_INT: "1"
- name: Archive Next.js build for downstream jobs
# Use tar so the archive preserves paths relative to CWD (.build/next/...).
# upload-artifact path-stripping is ambiguous when exclude patterns are used;
Expand Down Expand Up @@ -1066,7 +1070,7 @@ jobs:
- name: Upload test results to Trunk (advisory)
if: ${{ always() && (github.event_name != 'pull_request' || github.event.pull_request.head.repo.full_name == github.repository) }}
continue-on-error: true
uses: trunk-io/analytics-uploader@817e1a2ec58d888825699ee15ea172809bb3f226 # v2.1.3
uses: trunk-io/analytics-uploader@14c0f18990953eecd01c9c5afe3cc63a73b6c371 # v2.1.5
with:
junit-paths: trunk-junit/**/*.xml
org-slug: omniroute
Expand Down Expand Up @@ -1399,7 +1403,7 @@ jobs:
- name: Upload test results to Trunk (advisory)
if: ${{ always() && (github.event_name != 'pull_request' || github.event.pull_request.head.repo.full_name == github.repository) }}
continue-on-error: true
uses: trunk-io/analytics-uploader@817e1a2ec58d888825699ee15ea172809bb3f226 # v2.1.3
uses: trunk-io/analytics-uploader@14c0f18990953eecd01c9c5afe3cc63a73b6c371 # v2.1.5
with:
junit-paths: junit-e2e-results.xml
org-slug: omniroute
Expand Down
4 changes: 2 additions & 2 deletions .github/workflows/codeql.yml
Original file line number Diff line number Diff line change
Expand Up @@ -22,10 +22,10 @@ jobs:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
- uses: github/codeql-action/init@1c5b675653bb5c22dbe9b12b556ec555138e09fd # v4.38.1
- uses: github/codeql-action/init@2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2 # v4.38.2
with:
languages: javascript-typescript
queries: security-extended
- uses: github/codeql-action/analyze@1c5b675653bb5c22dbe9b12b556ec555138e09fd # v4.38.1
- uses: github/codeql-action/analyze@2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2 # v4.38.2
with:
category: "/language:javascript-typescript"
2 changes: 1 addition & 1 deletion .github/workflows/docker-publish.yml
Original file line number Diff line number Diff line change
Expand Up @@ -584,7 +584,7 @@ jobs:
- name: Upload Trivy SARIF to Security tab
if: needs.prepare.outputs.version != 'main'
continue-on-error: true
uses: github/codeql-action/upload-sarif@v4.38.1
uses: github/codeql-action/upload-sarif@v4.38.2
with:
sarif_file: trivy-results.sarif
category: trivy-image
Expand Down
10 changes: 7 additions & 3 deletions .github/workflows/quality.yml
Original file line number Diff line number Diff line change
Expand Up @@ -230,16 +230,20 @@ jobs:
route-guard-membership test-discovery test-runner-api
mutation-test-coverage any-budget:t11 build-scope pack-policy
complexity-ratchets model-lifecycle
cycles lockfile duplication dead-code type-coverage compression-budget
lockfile duplication dead-code type-coverage compression-budget
# #8781: open-sse workspace typecheck gate — the workspace imports @/ which
# escapes to src/ via undeclared path aliases. See check-open-sse-typecheck.mjs.
open-sse-typecheck
# Hard Rule #16 — AI/bot attribution in PR commits, title or body (#14436). Reads the PR
# from GITHUB_EVENT_PATH; no-op on non-PR events. ci.yml only runs on PRs to main.
ai-attribution
)
# Ratchet-mode gates append --ratchet. `cycles` belongs here since #15281
# (69cb18dca8): check-cycles.mjs exits 1 on ANY cycle without --ratchet, and
# the frozen ceiling lives in quality-baseline.json → metrics.cycles — same
# `check:cycles:ratchet` semantics ci.yml runs (base-red #15306).
ratchet_gates=(
secrets vuln-ratchet workflows openapi-breaking
secrets vuln-ratchet workflows openapi-breaking cycles
)
failed=()
for g in "${gates[@]}"; do
Expand Down Expand Up @@ -405,7 +409,7 @@ jobs:
- name: Upload test results to Trunk (advisory)
if: ${{ always() && (github.event_name != 'pull_request' || github.event.pull_request.head.repo.full_name == github.repository) }}
continue-on-error: true
uses: trunk-io/analytics-uploader@817e1a2ec58d888825699ee15ea172809bb3f226 # v2.1.3
uses: trunk-io/analytics-uploader@14c0f18990953eecd01c9c5afe3cc63a73b6c371 # v2.1.5
with:
junit-paths: trunk-junit/**/*.xml
org-slug: omniroute
Expand Down
Loading
Loading