1.5.7 changelogs - #3907
Conversation
📝 WalkthroughWalkthroughThis PR coordinates a minor version bump across the Bifrost platform. Core increments to v1.5.15 with fixes for Ollama and SGL streaming Authorization headers, framework and all plugins follow with dependency updates, and transports releases v1.5.7 documenting three bug fixes. ChangesCoordinated Release and Version Bumps
Estimated code review effort🎯 1 (Trivial) | ⏱️ ~3 minutes Possibly related PRs
Suggested reviewers
Poem
🚥 Pre-merge checks | ✅ 3 | ❌ 2❌ Failed checks (1 warning, 1 inconclusive)
✅ Passed checks (3 passed)
✏️ Tip: You can configure your own custom pre-merge checks in the settings. ✨ Finishing Touches🧪 Generate unit tests (beta)
Comment |
|
|
Confidence Score: 5/5Safe to merge — all changes are changelog text and version number files with no executable code. Every changed file is either a changelog.md or a version flat file. The changelog entries accurately describe the two streaming auth fixes and the from_memory parameter removal. Version numbers are internally consistent across core, framework, and all plugins. No files require special attention. Important Files Changed
Reviews (1): Last reviewed commit: "1.5.7 changelogs" | Re-trigger Greptile |
There was a problem hiding this comment.
Actionable comments posted: 8
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@core/changelog.md`:
- Line 1: The markdown file contains a top-level list item "- fix: send
Authorization Bearer header on Ollama streaming text and chat completion
requests (`#3906`)" which triggers MD041; add a top-level heading (for example "#
Changelog" or similar) as the very first line of core/changelog.md so the
existing list item is no longer the document's first block, leaving the "- fix:
..." line unchanged below the new heading.
In `@framework/changelog.md`:
- Line 1: Add an H1 heading at the very top of the changelog file (e.g., insert
"# Changelog" as the first line) and ensure there is a blank line after the
heading so the existing list entry "- chore: upgraded core to v1.5.15" no longer
starts the file; this will resolve markdownlint MD041.
In `@plugins/compat/changelog.md`:
- Line 1: Add a top-level Markdown heading to the start of changelog.md so the
file satisfies MD041; insert a line like "# Changelog" (or another appropriate
H1) above the existing first line ("chore: upgraded core to v1.5.15 and
framework to v1.3.15") so the current entry remains intact and the file begins
with an H1.
In `@plugins/governance/changelog.md`:
- Line 1: The changelog currently starts with "- chore: upgraded core to v1.5.15
and framework to v1.3.15" which violates MD041; fix it by adding a top-level
heading (for example "## Changelog" or "# Changelog") as the very first line in
changelog.md, then keep the existing "- chore: ..." entry below the heading so
the file complies with markdownlint.
In `@plugins/jsonparser/changelog.md`:
- Line 1: Add a top-level H1 as the first line of the changelog to satisfy
MD041; insert a single line beginning with "# " before the existing "- chore:
upgraded core to v1.5.15 and framework to v1.3.15" entry so the file
(plugins/jsonparser/changelog.md) starts with an H1 heading rather than a list
item.
In `@plugins/logging/changelog.md`:
- Line 1: Add a top-level H1 heading to the changelog by inserting a first-line
heading (e.g., "# Changelog") above the existing first line "- chore: upgraded
core to v1.5.15 and framework to v1.3.15" in changelog.md so the file no longer
violates MD041 (`first-line-heading`); ensure the new H1 is the very first line
and keep the existing list item unchanged.
In `@plugins/maxim/changelog.md`:
- Line 1: Add a top-level H1 heading above the existing list entry so the file
starts with an H1 (e.g., insert "# Changelog" or another appropriate H1) before
the line "chore: upgraded core to v1.5.15 and framework to v1.3.15" to satisfy
markdownlint MD041.
In `@plugins/mocker/changelog.md`:
- Line 1: Add a top-level H1 as the first line of plugins/mocker/changelog.md so
the file begins with a heading (e.g., add "# Changelog" or a suitable H1) and
move the existing first line ("chore: upgraded core to v1.5.15 and framework to
v1.3.15") below that heading to satisfy markdownlint MD041.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Path: .coderabbit.yaml
Review profile: ASSERTIVE
Plan: Pro
Run ID: e8bf9b4f-3c1c-4731-895f-c0723ff65dd9
📒 Files selected for processing (26)
core/changelog.mdcore/versionframework/changelog.mdframework/versionplugins/compat/changelog.mdplugins/compat/versionplugins/governance/changelog.mdplugins/governance/versionplugins/jsonparser/changelog.mdplugins/jsonparser/versionplugins/logging/changelog.mdplugins/logging/versionplugins/maxim/changelog.mdplugins/maxim/versionplugins/mocker/changelog.mdplugins/mocker/versionplugins/otel/changelog.mdplugins/otel/versionplugins/prompts/changelog.mdplugins/prompts/versionplugins/semanticcache/changelog.mdplugins/semanticcache/versionplugins/telemetry/changelog.mdplugins/telemetry/versiontransports/changelog.mdtransports/version
| @@ -0,0 +1,2 @@ | |||
| - fix: send Authorization Bearer header on Ollama streaming text and chat completion requests (#3906) | |||
There was a problem hiding this comment.
Add a top-level heading to satisfy markdown lint.
Line 1 starts with a list item, which violates MD041 and can fail docs/lint checks.
Suggested fix
+# Changelog
+
- fix: send Authorization Bearer header on Ollama streaming text and chat completion requests (`#3906`)
- fix: SGL provider now sends Authorization header on streaming requests (`#3307`) (thanks [`@hensapir`](https://github.com/hensapir)!)🧰 Tools
🪛 markdownlint-cli2 (0.22.1)
[warning] 1-1: First line in a file should be a top-level heading
(MD041, first-line-heading, first-line-h1)
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@core/changelog.md` at line 1, The markdown file contains a top-level list
item "- fix: send Authorization Bearer header on Ollama streaming text and chat
completion requests (`#3906`)" which triggers MD041; add a top-level heading (for
example "# Changelog" or similar) as the very first line of core/changelog.md so
the existing list item is no longer the document's first block, leaving the "-
fix: ..." line unchanged below the new heading.
| - fix: increase matview sync interval to 1 min (#3886) | ||
| - refactor: remove deferred-fill user-mode OAuth flow support (#3839) | ||
| - chore: upgrade to Go 1.26.3 (#3782) | ||
| - chore: upgraded core to v1.5.15 |
There was a problem hiding this comment.
Add an H1 heading at the top of this changelog file.
Line 1 begins with a list item, triggering markdownlint MD041.
🧰 Tools
🪛 markdownlint-cli2 (0.22.1)
[warning] 1-1: First line in a file should be a top-level heading
(MD041, first-line-heading, first-line-h1)
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@framework/changelog.md` at line 1, Add an H1 heading at the very top of the
changelog file (e.g., insert "# Changelog" as the first line) and ensure there
is a blank line after the heading so the existing list entry "- chore: upgraded
core to v1.5.15" no longer starts the file; this will resolve markdownlint
MD041.
| @@ -1 +1 @@ | |||
| - chore: upgraded core to v1.5.14 and framework to v1.3.14 | |||
| - chore: upgraded core to v1.5.15 and framework to v1.3.15 | |||
There was a problem hiding this comment.
Missing top-level heading in changelog file.
Line 1 should be a heading to satisfy markdownlint MD041.
🧰 Tools
🪛 markdownlint-cli2 (0.22.1)
[warning] 1-1: First line in a file should be a top-level heading
(MD041, first-line-heading, first-line-h1)
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@plugins/compat/changelog.md` at line 1, Add a top-level Markdown heading to
the start of changelog.md so the file satisfies MD041; insert a line like "#
Changelog" (or another appropriate H1) above the existing first line ("chore:
upgraded core to v1.5.15 and framework to v1.3.15") so the current entry remains
intact and the file begins with an H1.
| @@ -1,2 +1 @@ | |||
| - feat: add MCP per-user headers auth type support (#3703) | |||
| - chore: upgraded core to v1.5.14 and framework to v1.3.14 | |||
| - chore: upgraded core to v1.5.15 and framework to v1.3.15 | |||
There was a problem hiding this comment.
Add a top-level heading for markdownlint compliance.
Line 1 starts with - chore: and violates MD041.
🧰 Tools
🪛 markdownlint-cli2 (0.22.1)
[warning] 1-1: First line in a file should be a top-level heading
(MD041, first-line-heading, first-line-h1)
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@plugins/governance/changelog.md` at line 1, The changelog currently starts
with "- chore: upgraded core to v1.5.15 and framework to v1.3.15" which violates
MD041; fix it by adding a top-level heading (for example "## Changelog" or "#
Changelog") as the very first line in changelog.md, then keep the existing "-
chore: ..." entry below the heading so the file complies with markdownlint.
| @@ -1 +1 @@ | |||
| - chore: upgraded core to v1.5.14 and framework to v1.3.14 | |||
| - chore: upgraded core to v1.5.15 and framework to v1.3.15 | |||
There was a problem hiding this comment.
Add a top-level heading to satisfy markdown linting.
Line 1 starts with a list item, which triggers MD041 (first-line-heading). Please add an H1 as the first line.
🧰 Tools
🪛 markdownlint-cli2 (0.22.1)
[warning] 1-1: First line in a file should be a top-level heading
(MD041, first-line-heading, first-line-h1)
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@plugins/jsonparser/changelog.md` at line 1, Add a top-level H1 as the first
line of the changelog to satisfy MD041; insert a single line beginning with "# "
before the existing "- chore: upgraded core to v1.5.15 and framework to v1.3.15"
entry so the file (plugins/jsonparser/changelog.md) starts with an H1 heading
rather than a list item.
| - feat: support dimension rankings logging for team, customer, BU, and user (#3766) | ||
| - refactor: route Starlark nested tool calls through the canonical plugin pipeline (#3794) | ||
| - chore: upgraded core to v1.5.14 and framework to v1.3.14 | ||
| - chore: upgraded core to v1.5.15 and framework to v1.3.15 |
There was a problem hiding this comment.
Add an H1 at the top of the changelog file.
Line 1 begins with a list item and violates MD041 (first-line-heading).
🧰 Tools
🪛 markdownlint-cli2 (0.22.1)
[warning] 1-1: First line in a file should be a top-level heading
(MD041, first-line-heading, first-line-h1)
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@plugins/logging/changelog.md` at line 1, Add a top-level H1 heading to the
changelog by inserting a first-line heading (e.g., "# Changelog") above the
existing first line "- chore: upgraded core to v1.5.15 and framework to v1.3.15"
in changelog.md so the file no longer violates MD041 (`first-line-heading`);
ensure the new H1 is the very first line and keep the existing list item
unchanged.
| @@ -1 +1 @@ | |||
| - chore: upgraded core to v1.5.14 and framework to v1.3.14 | |||
| - chore: upgraded core to v1.5.15 and framework to v1.3.15 | |||
There was a problem hiding this comment.
Insert a top-level heading before the list entry.
Line 1 violates markdownlint MD041 because the file does not start with an H1 heading.
🧰 Tools
🪛 markdownlint-cli2 (0.22.1)
[warning] 1-1: First line in a file should be a top-level heading
(MD041, first-line-heading, first-line-h1)
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@plugins/maxim/changelog.md` at line 1, Add a top-level H1 heading above the
existing list entry so the file starts with an H1 (e.g., insert "# Changelog" or
another appropriate H1) before the line "chore: upgraded core to v1.5.15 and
framework to v1.3.15" to satisfy markdownlint MD041.
| @@ -1 +1 @@ | |||
| - chore: upgraded core to v1.5.14 and framework to v1.3.14 | |||
| - chore: upgraded core to v1.5.15 and framework to v1.3.15 | |||
There was a problem hiding this comment.
Add an H1 heading as the first line.
Current Line 1 triggers markdownlint MD041 (first-line-heading) because it starts directly with a bullet.
🧰 Tools
🪛 markdownlint-cli2 (0.22.1)
[warning] 1-1: First line in a file should be a top-level heading
(MD041, first-line-heading, first-line-h1)
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@plugins/mocker/changelog.md` at line 1, Add a top-level H1 as the first line
of plugins/mocker/changelog.md so the file begins with a heading (e.g., add "#
Changelog" or a suitable H1) and move the existing first line ("chore: upgraded
core to v1.5.15 and framework to v1.3.15") below that heading to satisfy
markdownlint MD041.
Merge activity
|
This release (core v1.5.15, framework v1.3.15) fixes missing `Authorization` header forwarding on streaming requests for the Ollama and SGL providers, ensuring authenticated requests behave correctly during streaming. - Ollama streaming text and chat completion requests now correctly forward the configured API key as an `Authorization: Bearer` header (#3906) - SGL provider now sends the `Authorization` header on streaming requests (#3307) (thanks [@hensapir](https://github.com/hensapir)!) - Governance and Logging APIs: removed the `from_memory` query parameter; virtual key and config list APIs now return consistent DB-backed results, with VK names batch-fetched in a single query (#3903) - Bumped core to v1.5.15, framework to v1.3.15, transports to v1.5.7, and all dependent plugins to their respective patch versions - [x] Bug fix - [ ] Feature - [ ] Refactor - [ ] Documentation - [ ] Chore/CI - [x] Core (Go) - [x] Transports (HTTP) - [x] Providers/Integrations - [x] Plugins - [ ] UI (React) - [ ] Docs Validate that Ollama and SGL streaming requests include the `Authorization: Bearer` header when an API key is configured. ```sh go version go test ./... ``` Configure an Ollama or SGL provider with an API key and issue a streaming chat or text completion request. Inspect outbound request headers to confirm `Authorization: Bearer <key>` is present. - [ ] Yes - [x] No Closes #3906 Closes #3307 Closes #3903 These fixes ensure that API keys configured for Ollama and SGL providers are correctly forwarded on streaming requests. Previously, the `Authorization` header was silently dropped on streaming paths, meaning requests could reach upstream providers without authentication credentials. - [x] I read `docs/contributing/README.md` and followed the guidelines - [x] I added/updated tests where appropriate - [x] I updated documentation where needed - [x] I verified builds succeed (Go and UI) - [x] I verified the CI pipeline passes locally if applicable <!-- This is an auto-generated comment: release notes by coderabbit.ai --> * **Bug Fixes** * Fixed authorization header handling for Ollama streaming requests. * Fixed authorization header forwarding for SGL provider streaming requests. * Improved consistency in virtual key and configuration list API responses by removing unnecessary query parameters. * **Chores** * Updated component versions across the platform. <!-- review_stack_entry_start --> [](https://app.coderabbit.ai/change-stack/maximhq/bifrost/pull/3907?utm_source=github_walkthrough&utm_medium=github&utm_campaign=change_stack) <!-- review_stack_entry_end --> <!-- end of auto-generated comment: release notes by coderabbit.ai -->
* removes from_memory for APIs * docker scout fixes (#3900) * test fixes for hardened runners (#3780) * fix: SGL provider - send Authorization header on streaming requests (#3307) * [fix]: SGL provider - send Authorization header on streaming requests The streaming entry points (ChatCompletionStream, TextCompletionStream) passed nil for the authHeader parameter to the shared OpenAI streaming helpers, so no Authorization header was attached to outbound streaming requests. SGLang servers configured with --api-key always require the header and returned 401 on streaming while non-streaming requests worked. The non-streaming OpenAI helper takes the Key directly and builds the header itself; the streaming helper requires the caller to build it. Mirror the vLLM pattern (core/providers/vllm/vllm.go) and construct the auth header from key.Value when set. Affected packages: - core/providers/sgl/sgl.go - build authHeader for both streaming paths - core/providers/sgl/chat_test.go - regression tests asserting the Authorization header reaches the upstream on chat and text streams - core/changelog.md - changelog entry * [fix]: SGL streaming tests - cancel drain goroutine on test completion The drain goroutines spawned to consume streamChan in TestChatCompletionStream_SetsAuthorizationHeader and TestTextCompletionStream_SetsAuthorizationHeader had no cancellation path: if the streaming pipeline failed to close the channel (e.g. on a test timeout), the goroutines would leak into the test process. Replace the inline `go func() { for range streamChan {} }()` with a shared drainStream helper that selects on both the channel and a `done` channel closed via t.Cleanup, so the goroutine always exits when the test completes regardless of channel state. Addresses Greptile review feedback on PR #3307. --------- Co-authored-by: Akshay Deo <akshay@akshaydeo.com> * ollama streaming auth header (#3906) ## Summary Adds Bearer token authentication support to the Ollama provider's streaming endpoints. Previously, the streaming methods for text completion and chat completion always passed `nil` for the auth header, meaning API keys configured for Ollama were silently ignored during streaming requests. ## Issues Closes #3905 ## Changes - When a non-empty key value is present, a `Bearer` token `Authorization` header is now constructed and passed to the OpenAI-compatible streaming handlers for both `TextCompletionStream` and `ChatCompletionStream` - If no key is configured, the auth header remains `nil`, preserving backward compatibility with unauthenticated local Ollama instances ## Type of change - [x] Bug fix - [ ] Feature - [ ] Refactor - [ ] Documentation - [ ] Chore/CI ## Affected areas - [ ] Core (Go) - [ ] Transports (HTTP) - [x] Providers/Integrations - [ ] Plugins - [ ] UI (React) - [ ] Docs ## How to test Configure an Ollama provider with an API key (e.g., when using a hosted or authenticated Ollama instance) and issue a streaming chat or text completion request. Verify the `Authorization: Bearer <key>` header is included in the outgoing request. ```sh go test ./core/providers/ollama/... ``` ## Breaking changes - [ ] Yes - [x] No ## Related issues ## Security considerations API keys are now correctly forwarded as Bearer tokens in streaming requests to Ollama. Ensure keys are stored and retrieved securely via the existing key management mechanism, as they will now be included in outbound HTTP headers for streaming calls. ## Checklist - [ ] I read `docs/contributing/README.md` and followed the guidelines - [ ] I added/updated tests where appropriate - [ ] I updated documentation where needed - [ ] I verified builds succeed (Go and UI) - [ ] I verified the CI pipeline passes locally if applicable <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Ollama streaming requests now support authentication via bearer tokens for both text and chat completions, enabling proper token-based authentication when API keys are provided. <!-- review_stack_entry_start --> [](https://app.coderabbit.ai/change-stack/maximhq/bifrost/pull/3906?utm_source=github_walkthrough&utm_medium=github&utm_campaign=change_stack) <!-- review_stack_entry_end --> <!-- end of auto-generated comment: release notes by coderabbit.ai --> * 1.5.7 changelogs (#3907) This release (core v1.5.15, framework v1.3.15) fixes missing `Authorization` header forwarding on streaming requests for the Ollama and SGL providers, ensuring authenticated requests behave correctly during streaming. - Ollama streaming text and chat completion requests now correctly forward the configured API key as an `Authorization: Bearer` header (#3906) - SGL provider now sends the `Authorization` header on streaming requests (#3307) (thanks [@hensapir](https://github.com/hensapir)!) - Governance and Logging APIs: removed the `from_memory` query parameter; virtual key and config list APIs now return consistent DB-backed results, with VK names batch-fetched in a single query (#3903) - Bumped core to v1.5.15, framework to v1.3.15, transports to v1.5.7, and all dependent plugins to their respective patch versions - [x] Bug fix - [ ] Feature - [ ] Refactor - [ ] Documentation - [ ] Chore/CI - [x] Core (Go) - [x] Transports (HTTP) - [x] Providers/Integrations - [x] Plugins - [ ] UI (React) - [ ] Docs Validate that Ollama and SGL streaming requests include the `Authorization: Bearer` header when an API key is configured. ```sh go version go test ./... ``` Configure an Ollama or SGL provider with an API key and issue a streaming chat or text completion request. Inspect outbound request headers to confirm `Authorization: Bearer <key>` is present. - [ ] Yes - [x] No Closes #3906 Closes #3307 Closes #3903 These fixes ensure that API keys configured for Ollama and SGL providers are correctly forwarded on streaming requests. Previously, the `Authorization` header was silently dropped on streaming paths, meaning requests could reach upstream providers without authentication credentials. - [x] I read `docs/contributing/README.md` and followed the guidelines - [x] I added/updated tests where appropriate - [x] I updated documentation where needed - [x] I verified builds succeed (Go and UI) - [x] I verified the CI pipeline passes locally if applicable <!-- This is an auto-generated comment: release notes by coderabbit.ai --> * **Bug Fixes** * Fixed authorization header handling for Ollama streaming requests. * Fixed authorization header forwarding for SGL provider streaming requests. * Improved consistency in virtual key and configuration list API responses by removing unnecessary query parameters. * **Chores** * Updated component versions across the platform. <!-- review_stack_entry_start --> [](https://app.coderabbit.ai/change-stack/maximhq/bifrost/pull/3907?utm_source=github_walkthrough&utm_medium=github&utm_campaign=change_stack) <!-- review_stack_entry_end --> <!-- end of auto-generated comment: release notes by coderabbit.ai --> * changelogs (#3909) ## Summary Remediates Docker Scout CVE findings by upgrading transitive `golang.org/x` dependencies and removing the standalone GNU `wget` package from Alpine runtime images, replacing it with the built-in busybox `wget` applet. ## Changes - Bumped `golang.org/x` transitive dependencies (`crypto`, `net`, `sys`, `text`, `term`) across all modules to clear 20 Docker Scout advisories (severity up to 10.0), verified clean with `govulncheck` - Removed standalone `wget` package from Alpine runtime images in `Dockerfile` and `Dockerfile.local`, eliminating CVE-2025-69194 (CVSS 8.8) - Updated `HEALTHCHECK` command from `wget --no-verbose --tries=1` to `wget -q` to use busybox-compatible flags with no functional change in behavior ## Type of change - [ ] Bug fix - [ ] Feature - [ ] Refactor - [ ] Documentation - [x] Chore/CI ## Affected areas - [x] Core (Go) - [x] Transports (HTTP) - [ ] Providers/Integrations - [x] Plugins - [ ] UI (React) - [ ] Docs ## How to test ```sh # Verify no vulnerabilities remain govulncheck ./... # Build Docker image and confirm wget healthcheck works docker build -f transports/Dockerfile -t gateway-test . docker run --rm gateway-test ``` ## Breaking changes - [ ] Yes - [x] No ## Related issues Closes #3900 ## Security considerations - Clears 20 Docker Scout CVE advisories on `golang.org/x` packages, with severities up to 10.0 - Removes CVE-2025-69194 (CVSS 8.8) by eliminating the standalone GNU `wget` package; busybox `wget` is used instead and is not affected by this CVE ## Checklist - [x] I read `docs/contributing/README.md` and followed the guidelines - [x] I added/updated tests where appropriate - [x] I updated documentation where needed - [x] I verified builds succeed (Go and UI) - [x] I verified the CI pipeline passes locally if applicable --------- Co-authored-by: Hen Sapir <hen@sapir.me>
This release (core v1.5.15, framework v1.3.15) fixes missing `Authorization` header forwarding on streaming requests for the Ollama and SGL providers, ensuring authenticated requests behave correctly during streaming. - Ollama streaming text and chat completion requests now correctly forward the configured API key as an `Authorization: Bearer` header (#3906) - SGL provider now sends the `Authorization` header on streaming requests (#3307) (thanks [@hensapir](https://github.com/hensapir)!) - Governance and Logging APIs: removed the `from_memory` query parameter; virtual key and config list APIs now return consistent DB-backed results, with VK names batch-fetched in a single query (#3903) - Bumped core to v1.5.15, framework to v1.3.15, transports to v1.5.7, and all dependent plugins to their respective patch versions - [x] Bug fix - [ ] Feature - [ ] Refactor - [ ] Documentation - [ ] Chore/CI - [x] Core (Go) - [x] Transports (HTTP) - [x] Providers/Integrations - [x] Plugins - [ ] UI (React) - [ ] Docs Validate that Ollama and SGL streaming requests include the `Authorization: Bearer` header when an API key is configured. ```sh go version go test ./... ``` Configure an Ollama or SGL provider with an API key and issue a streaming chat or text completion request. Inspect outbound request headers to confirm `Authorization: Bearer <key>` is present. - [ ] Yes - [x] No Closes #3906 Closes #3307 Closes #3903 These fixes ensure that API keys configured for Ollama and SGL providers are correctly forwarded on streaming requests. Previously, the `Authorization` header was silently dropped on streaming paths, meaning requests could reach upstream providers without authentication credentials. - [x] I read `docs/contributing/README.md` and followed the guidelines - [x] I added/updated tests where appropriate - [x] I updated documentation where needed - [x] I verified builds succeed (Go and UI) - [x] I verified the CI pipeline passes locally if applicable <!-- This is an auto-generated comment: release notes by coderabbit.ai --> * **Bug Fixes** * Fixed authorization header handling for Ollama streaming requests. * Fixed authorization header forwarding for SGL provider streaming requests. * Improved consistency in virtual key and configuration list API responses by removing unnecessary query parameters. * **Chores** * Updated component versions across the platform. <!-- review_stack_entry_start --> [](https://app.coderabbit.ai/change-stack/maximhq/bifrost/pull/3907?utm_source=github_walkthrough&utm_medium=github&utm_campaign=change_stack) <!-- review_stack_entry_end --> <!-- end of auto-generated comment: release notes by coderabbit.ai -->
* docker scout fixes (#3900) * 1.5.7 changelogs (#3907) This release (core v1.5.15, framework v1.3.15) fixes missing `Authorization` header forwarding on streaming requests for the Ollama and SGL providers, ensuring authenticated requests behave correctly during streaming. - Ollama streaming text and chat completion requests now correctly forward the configured API key as an `Authorization: Bearer` header (#3906) - SGL provider now sends the `Authorization` header on streaming requests (#3307) (thanks [@hensapir](https://github.com/hensapir)!) - Governance and Logging APIs: removed the `from_memory` query parameter; virtual key and config list APIs now return consistent DB-backed results, with VK names batch-fetched in a single query (#3903) - Bumped core to v1.5.15, framework to v1.3.15, transports to v1.5.7, and all dependent plugins to their respective patch versions - [x] Bug fix - [ ] Feature - [ ] Refactor - [ ] Documentation - [ ] Chore/CI - [x] Core (Go) - [x] Transports (HTTP) - [x] Providers/Integrations - [x] Plugins - [ ] UI (React) - [ ] Docs Validate that Ollama and SGL streaming requests include the `Authorization: Bearer` header when an API key is configured. ```sh go version go test ./... ``` Configure an Ollama or SGL provider with an API key and issue a streaming chat or text completion request. Inspect outbound request headers to confirm `Authorization: Bearer <key>` is present. - [ ] Yes - [x] No Closes #3906 Closes #3307 Closes #3903 These fixes ensure that API keys configured for Ollama and SGL providers are correctly forwarded on streaming requests. Previously, the `Authorization` header was silently dropped on streaming paths, meaning requests could reach upstream providers without authentication credentials. - [x] I read `docs/contributing/README.md` and followed the guidelines - [x] I added/updated tests where appropriate - [x] I updated documentation where needed - [x] I verified builds succeed (Go and UI) - [x] I verified the CI pipeline passes locally if applicable <!-- This is an auto-generated comment: release notes by coderabbit.ai --> * **Bug Fixes** * Fixed authorization header handling for Ollama streaming requests. * Fixed authorization header forwarding for SGL provider streaming requests. * Improved consistency in virtual key and configuration list API responses by removing unnecessary query parameters. * **Chores** * Updated component versions across the platform. <!-- review_stack_entry_start --> [](https://app.coderabbit.ai/change-stack/maximhq/bifrost/pull/3907?utm_source=github_walkthrough&utm_medium=github&utm_campaign=change_stack) <!-- review_stack_entry_end --> <!-- end of auto-generated comment: release notes by coderabbit.ai --> * changelogs (#3909) ## Summary Remediates Docker Scout CVE findings by upgrading transitive `golang.org/x` dependencies and removing the standalone GNU `wget` package from Alpine runtime images, replacing it with the built-in busybox `wget` applet. ## Changes - Bumped `golang.org/x` transitive dependencies (`crypto`, `net`, `sys`, `text`, `term`) across all modules to clear 20 Docker Scout advisories (severity up to 10.0), verified clean with `govulncheck` - Removed standalone `wget` package from Alpine runtime images in `Dockerfile` and `Dockerfile.local`, eliminating CVE-2025-69194 (CVSS 8.8) - Updated `HEALTHCHECK` command from `wget --no-verbose --tries=1` to `wget -q` to use busybox-compatible flags with no functional change in behavior ## Type of change - [ ] Bug fix - [ ] Feature - [ ] Refactor - [ ] Documentation - [x] Chore/CI ## Affected areas - [x] Core (Go) - [x] Transports (HTTP) - [ ] Providers/Integrations - [x] Plugins - [ ] UI (React) - [ ] Docs ## How to test ```sh # Verify no vulnerabilities remain govulncheck ./... # Build Docker image and confirm wget healthcheck works docker build -f transports/Dockerfile -t gateway-test . docker run --rm gateway-test ``` ## Breaking changes - [ ] Yes - [x] No ## Related issues Closes #3900 ## Security considerations - Clears 20 Docker Scout CVE advisories on `golang.org/x` packages, with severities up to 10.0 - Removes CVE-2025-69194 (CVSS 8.8) by eliminating the standalone GNU `wget` package; busybox `wget` is used instead and is not affected by this CVE ## Checklist - [x] I read `docs/contributing/README.md` and followed the guidelines - [x] I added/updated tests where appropriate - [x] I updated documentation where needed - [x] I verified builds succeed (Go and UI) - [x] I verified the CI pipeline passes locally if applicable * enterprise changelog (#3912) ## Summary Adds the Enterprise v1.4.6 changelog entry to the documentation site and registers it in the docs navigation. ## Changes - Added `docs/changelogs/ent-v1.4.6.mdx` documenting the v1.4.6 release, which is a security and hardening release based on `transports/v1.5.7`. Key highlights include: - **DAC bypass fix**: `from_memory` query paths and shared filter-data caches were bypassing data-access scope enforcement, allowing scoped callers to observe virtual keys, teams, routing rules, and log dimensions belonging to other users. All read paths now apply the caller's DAC scope, and MCP clients no longer leak hidden virtual key IDs. - **DAC scope coverage expanded**: Added DAC wrappers for `GetVirtualKeys`, `GetRoutingRules`, `GetRoutingRulesByScope`, `GetRoutingRule`, and MCP virtual-key config lookups by client ID. - **DAC bypass regression suite**: New end-to-end Postman collection covering `from_memory` list endpoints, hidden virtual key/team detail access, log and MCP filter-data cache isolation, and MCP client assignment leakage. - **CVE remediation**: Updated `golang.org/x` packages (`crypto`, `net`, `sys`, `text`, `term`) clearing 20 advisories with severity up to 10.0, verified with `govulncheck`. - **Hardened container image**: Removed standalone GNU `wget` from the Alpine runtime image, eliminating CVE-2025-69194 (8.8); healthcheck now uses busybox `wget`. - **Ollama and SGL streaming auth fixes**: Both providers now correctly forward `Authorization: Bearer` headers on streaming requests. - **Governance model availability fix**: Access profile evaluation now correctly enforces model availability checks during budget constraint validation across managed and non-managed governance paths. - **Governance and Logging list API cleanup**: Removed the `from_memory` query parameter; list APIs now return consistent DB-backed results with batch-fetched virtual-key names. - Registered `changelogs/ent-v1.4.6` as the first entry in the Enterprise changelogs section of `docs/docs.json`. ## Type of change - [ ] Bug fix - [ ] Feature - [ ] Refactor - [x] Documentation - [ ] Chore/CI ## Affected areas - [ ] Core (Go) - [ ] Transports (HTTP) - [ ] Providers/Integrations - [ ] Plugins - [ ] UI (React) - [x] Docs ## How to test Navigate to the Enterprise changelogs section of the documentation site and confirm that the v1.4.6 entry appears at the top of the list and renders correctly, including the breaking-change warning, feature/fix sections, and dependency tables. ## Breaking changes - [x] Yes - [ ] No v1.4.0 introduced breaking changes. Upgraders should follow the [v1.4.0 Migration Guide](https://docs.example.com/enterprise/migration-guides/v1.4.0) before upgrading to v1.4.6. ## Security considerations This release closes a DAC bypass that allowed scoped callers to read virtual keys, teams, routing rules, and log dimensions belonging to other users via `from_memory` query paths and shared filter-data caches. It also remediates 20 CVEs in `golang.org/x` dependencies (max severity 10.0) and removes a vulnerable `wget` binary (CVE-2025-69194, 8.8) from the container image. ## Checklist - [x] I read `docs/contributing/README.md` and followed the guidelines - [x] I added/updated tests where appropriate - [x] I updated documentation where needed - [x] I verified builds succeed (Go and UI) - [ ] I verified the CI pipeline passes locally if applicable <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit ## Documentation * Added Enterprise v1.4.6 release notes documenting a security-focused release with hardening improvements and critical updates. * Updates include security remediation, governance and model validation enhancements, container image improvements, and authentication updates for supported streaming services. * Removed deprecated parameter from governance and logging APIs. <!-- review_stack_entry_start --> [](https://app.coderabbit.ai/change-stack/maximhq/bifrost/pull/3912?utm_source=github_walkthrough&utm_medium=github&utm_campaign=change_stack) <!-- review_stack_entry_end --> <!-- end of auto-generated comment: release notes by coderabbit.ai -->
This release (core v1.5.15, framework v1.3.15) fixes missing `Authorization` header forwarding on streaming requests for the Ollama and SGL providers, ensuring authenticated requests behave correctly during streaming. - Ollama streaming text and chat completion requests now correctly forward the configured API key as an `Authorization: Bearer` header (#3906) - SGL provider now sends the `Authorization` header on streaming requests (#3307) (thanks [@hensapir](https://github.com/hensapir)!) - Governance and Logging APIs: removed the `from_memory` query parameter; virtual key and config list APIs now return consistent DB-backed results, with VK names batch-fetched in a single query (#3903) - Bumped core to v1.5.15, framework to v1.3.15, transports to v1.5.7, and all dependent plugins to their respective patch versions - [x] Bug fix - [ ] Feature - [ ] Refactor - [ ] Documentation - [ ] Chore/CI - [x] Core (Go) - [x] Transports (HTTP) - [x] Providers/Integrations - [x] Plugins - [ ] UI (React) - [ ] Docs Validate that Ollama and SGL streaming requests include the `Authorization: Bearer` header when an API key is configured. ```sh go version go test ./... ``` Configure an Ollama or SGL provider with an API key and issue a streaming chat or text completion request. Inspect outbound request headers to confirm `Authorization: Bearer <key>` is present. - [ ] Yes - [x] No Closes #3906 Closes #3307 Closes #3903 These fixes ensure that API keys configured for Ollama and SGL providers are correctly forwarded on streaming requests. Previously, the `Authorization` header was silently dropped on streaming paths, meaning requests could reach upstream providers without authentication credentials. - [x] I read `docs/contributing/README.md` and followed the guidelines - [x] I added/updated tests where appropriate - [x] I updated documentation where needed - [x] I verified builds succeed (Go and UI) - [x] I verified the CI pipeline passes locally if applicable <!-- This is an auto-generated comment: release notes by coderabbit.ai --> * **Bug Fixes** * Fixed authorization header handling for Ollama streaming requests. * Fixed authorization header forwarding for SGL provider streaming requests. * Improved consistency in virtual key and configuration list API responses by removing unnecessary query parameters. * **Chores** * Updated component versions across the platform. <!-- review_stack_entry_start --> [](https://app.coderabbit.ai/change-stack/maximhq/bifrost/pull/3907?utm_source=github_walkthrough&utm_medium=github&utm_campaign=change_stack) <!-- review_stack_entry_end --> <!-- end of auto-generated comment: release notes by coderabbit.ai -->
This release (core v1.5.15, framework v1.3.15) fixes missing `Authorization` header forwarding on streaming requests for the Ollama and SGL providers, ensuring authenticated requests behave correctly during streaming. - Ollama streaming text and chat completion requests now correctly forward the configured API key as an `Authorization: Bearer` header (maximhq#3906) - SGL provider now sends the `Authorization` header on streaming requests (maximhq#3307) (thanks [@hensapir](https://github.com/hensapir)!) - Governance and Logging APIs: removed the `from_memory` query parameter; virtual key and config list APIs now return consistent DB-backed results, with VK names batch-fetched in a single query (maximhq#3903) - Bumped core to v1.5.15, framework to v1.3.15, transports to v1.5.7, and all dependent plugins to their respective patch versions - [x] Bug fix - [ ] Feature - [ ] Refactor - [ ] Documentation - [ ] Chore/CI - [x] Core (Go) - [x] Transports (HTTP) - [x] Providers/Integrations - [x] Plugins - [ ] UI (React) - [ ] Docs Validate that Ollama and SGL streaming requests include the `Authorization: Bearer` header when an API key is configured. ```sh go version go test ./... ``` Configure an Ollama or SGL provider with an API key and issue a streaming chat or text completion request. Inspect outbound request headers to confirm `Authorization: Bearer <key>` is present. - [ ] Yes - [x] No Closes maximhq#3906 Closes maximhq#3307 Closes maximhq#3903 These fixes ensure that API keys configured for Ollama and SGL providers are correctly forwarded on streaming requests. Previously, the `Authorization` header was silently dropped on streaming paths, meaning requests could reach upstream providers without authentication credentials. - [x] I read `docs/contributing/README.md` and followed the guidelines - [x] I added/updated tests where appropriate - [x] I updated documentation where needed - [x] I verified builds succeed (Go and UI) - [x] I verified the CI pipeline passes locally if applicable <!-- This is an auto-generated comment: release notes by coderabbit.ai --> * **Bug Fixes** * Fixed authorization header handling for Ollama streaming requests. * Fixed authorization header forwarding for SGL provider streaming requests. * Improved consistency in virtual key and configuration list API responses by removing unnecessary query parameters. * **Chores** * Updated component versions across the platform. <!-- review_stack_entry_start --> [](https://app.coderabbit.ai/change-stack/maximhq/bifrost/pull/3907?utm_source=github_walkthrough&utm_medium=github&utm_campaign=change_stack) <!-- review_stack_entry_end --> <!-- end of auto-generated comment: release notes by coderabbit.ai -->
This release (core v1.5.15, framework v1.3.15) fixes missing `Authorization` header forwarding on streaming requests for the Ollama and SGL providers, ensuring authenticated requests behave correctly during streaming. - Ollama streaming text and chat completion requests now correctly forward the configured API key as an `Authorization: Bearer` header (#3906) - SGL provider now sends the `Authorization` header on streaming requests (#3307) (thanks [@hensapir](https://github.com/hensapir)!) - Governance and Logging APIs: removed the `from_memory` query parameter; virtual key and config list APIs now return consistent DB-backed results, with VK names batch-fetched in a single query (#3903) - Bumped core to v1.5.15, framework to v1.3.15, transports to v1.5.7, and all dependent plugins to their respective patch versions - [x] Bug fix - [ ] Feature - [ ] Refactor - [ ] Documentation - [ ] Chore/CI - [x] Core (Go) - [x] Transports (HTTP) - [x] Providers/Integrations - [x] Plugins - [ ] UI (React) - [ ] Docs Validate that Ollama and SGL streaming requests include the `Authorization: Bearer` header when an API key is configured. ```sh go version go test ./... ``` Configure an Ollama or SGL provider with an API key and issue a streaming chat or text completion request. Inspect outbound request headers to confirm `Authorization: Bearer <key>` is present. - [ ] Yes - [x] No Closes #3906 Closes #3307 Closes #3903 These fixes ensure that API keys configured for Ollama and SGL providers are correctly forwarded on streaming requests. Previously, the `Authorization` header was silently dropped on streaming paths, meaning requests could reach upstream providers without authentication credentials. - [x] I read `docs/contributing/README.md` and followed the guidelines - [x] I added/updated tests where appropriate - [x] I updated documentation where needed - [x] I verified builds succeed (Go and UI) - [x] I verified the CI pipeline passes locally if applicable <!-- This is an auto-generated comment: release notes by coderabbit.ai --> * **Bug Fixes** * Fixed authorization header handling for Ollama streaming requests. * Fixed authorization header forwarding for SGL provider streaming requests. * Improved consistency in virtual key and configuration list API responses by removing unnecessary query parameters. * **Chores** * Updated component versions across the platform. <!-- review_stack_entry_start --> [](https://app.coderabbit.ai/change-stack/maximhq/bifrost/pull/3907?utm_source=github_walkthrough&utm_medium=github&utm_campaign=change_stack) <!-- review_stack_entry_end --> <!-- end of auto-generated comment: release notes by coderabbit.ai -->
This release (core v1.5.15, framework v1.3.15) fixes missing `Authorization` header forwarding on streaming requests for the Ollama and SGL providers, ensuring authenticated requests behave correctly during streaming. - Ollama streaming text and chat completion requests now correctly forward the configured API key as an `Authorization: Bearer` header (#3906) - SGL provider now sends the `Authorization` header on streaming requests (#3307) (thanks [@hensapir](https://github.com/hensapir)!) - Governance and Logging APIs: removed the `from_memory` query parameter; virtual key and config list APIs now return consistent DB-backed results, with VK names batch-fetched in a single query (#3903) - Bumped core to v1.5.15, framework to v1.3.15, transports to v1.5.7, and all dependent plugins to their respective patch versions - [x] Bug fix - [ ] Feature - [ ] Refactor - [ ] Documentation - [ ] Chore/CI - [x] Core (Go) - [x] Transports (HTTP) - [x] Providers/Integrations - [x] Plugins - [ ] UI (React) - [ ] Docs Validate that Ollama and SGL streaming requests include the `Authorization: Bearer` header when an API key is configured. ```sh go version go test ./... ``` Configure an Ollama or SGL provider with an API key and issue a streaming chat or text completion request. Inspect outbound request headers to confirm `Authorization: Bearer <key>` is present. - [ ] Yes - [x] No Closes #3906 Closes #3307 Closes #3903 These fixes ensure that API keys configured for Ollama and SGL providers are correctly forwarded on streaming requests. Previously, the `Authorization` header was silently dropped on streaming paths, meaning requests could reach upstream providers without authentication credentials. - [x] I read `docs/contributing/README.md` and followed the guidelines - [x] I added/updated tests where appropriate - [x] I updated documentation where needed - [x] I verified builds succeed (Go and UI) - [x] I verified the CI pipeline passes locally if applicable <!-- This is an auto-generated comment: release notes by coderabbit.ai --> * **Bug Fixes** * Fixed authorization header handling for Ollama streaming requests. * Fixed authorization header forwarding for SGL provider streaming requests. * Improved consistency in virtual key and configuration list API responses by removing unnecessary query parameters. * **Chores** * Updated component versions across the platform. <!-- review_stack_entry_start --> [](https://app.coderabbit.ai/change-stack/maximhq/bifrost/pull/3907?utm_source=github_walkthrough&utm_medium=github&utm_campaign=change_stack) <!-- review_stack_entry_end --> <!-- end of auto-generated comment: release notes by coderabbit.ai -->
This release (core v1.5.15, framework v1.3.15) fixes missing `Authorization` header forwarding on streaming requests for the Ollama and SGL providers, ensuring authenticated requests behave correctly during streaming. - Ollama streaming text and chat completion requests now correctly forward the configured API key as an `Authorization: Bearer` header (maximhq#3906) - SGL provider now sends the `Authorization` header on streaming requests (maximhq#3307) (thanks [@hensapir](https://github.com/hensapir)!) - Governance and Logging APIs: removed the `from_memory` query parameter; virtual key and config list APIs now return consistent DB-backed results, with VK names batch-fetched in a single query (maximhq#3903) - Bumped core to v1.5.15, framework to v1.3.15, transports to v1.5.7, and all dependent plugins to their respective patch versions - [x] Bug fix - [ ] Feature - [ ] Refactor - [ ] Documentation - [ ] Chore/CI - [x] Core (Go) - [x] Transports (HTTP) - [x] Providers/Integrations - [x] Plugins - [ ] UI (React) - [ ] Docs Validate that Ollama and SGL streaming requests include the `Authorization: Bearer` header when an API key is configured. ```sh go version go test ./... ``` Configure an Ollama or SGL provider with an API key and issue a streaming chat or text completion request. Inspect outbound request headers to confirm `Authorization: Bearer <key>` is present. - [ ] Yes - [x] No Closes maximhq#3906 Closes maximhq#3307 Closes maximhq#3903 These fixes ensure that API keys configured for Ollama and SGL providers are correctly forwarded on streaming requests. Previously, the `Authorization` header was silently dropped on streaming paths, meaning requests could reach upstream providers without authentication credentials. - [x] I read `docs/contributing/README.md` and followed the guidelines - [x] I added/updated tests where appropriate - [x] I updated documentation where needed - [x] I verified builds succeed (Go and UI) - [x] I verified the CI pipeline passes locally if applicable <!-- This is an auto-generated comment: release notes by coderabbit.ai --> * **Bug Fixes** * Fixed authorization header handling for Ollama streaming requests. * Fixed authorization header forwarding for SGL provider streaming requests. * Improved consistency in virtual key and configuration list API responses by removing unnecessary query parameters. * **Chores** * Updated component versions across the platform. <!-- review_stack_entry_start --> [](https://app.coderabbit.ai/change-stack/maximhq/bifrost/pull/3907?utm_source=github_walkthrough&utm_medium=github&utm_campaign=change_stack) <!-- review_stack_entry_end --> <!-- end of auto-generated comment: release notes by coderabbit.ai -->

Summary
This release (core v1.5.15, framework v1.3.15) fixes missing
Authorizationheader forwarding on streaming requests for the Ollama and SGL providers, ensuring authenticated requests behave correctly during streaming.Changes
Authorization: Bearerheader (ollama streaming auth header #3906)Authorizationheader on streaming requests (fix: SGL provider - send Authorization header on streaming requests #3307) (thanks @hensapir!)from_memoryquery parameter; virtual key and config list APIs now return consistent DB-backed results, with VK names batch-fetched in a single query (removes from_memory for APIs #3903)Type of change
Affected areas
How to test
Validate that Ollama and SGL streaming requests include the
Authorization: Bearerheader when an API key is configured.Configure an Ollama or SGL provider with an API key and issue a streaming chat or text completion request. Inspect outbound request headers to confirm
Authorization: Bearer <key>is present.Breaking changes
Related issues
Closes #3906
Closes #3307
Closes #3903
Security considerations
These fixes ensure that API keys configured for Ollama and SGL providers are correctly forwarded on streaming requests. Previously, the
Authorizationheader was silently dropped on streaming paths, meaning requests could reach upstream providers without authentication credentials.Checklist
docs/contributing/README.mdand followed the guidelinesSummary by CodeRabbit
Bug Fixes
Chores