chore: promote staging to staging-promote/54519776-23969879338 (2026-04-05 04:48 UTC) - #2026
Merged
henrypark133 merged 3 commits intoApr 9, 2026
Conversation
* feat(embeddings): add bedrock provider * refactor(embeddings): address review feedback * fix: CI failures and review feedback for Bedrock embeddings - Replace ENV_MUTEX.lock() with lock_env() to match staging's test pattern - Use db_first_or_default() for non-bedrock model resolution (staging API) - Validate returned embedding dimension matches configured dimension Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com> --------- Co-authored-by: Illia Polosukhin <ilblackdragon@gmail.com> Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
* fix(security): run safety checks on truncated tool output Previously, `sanitize_tool_output()` returned immediately after truncating oversized output, skipping leak detection, policy enforcement, and injection scanning entirely. This allowed an attacker to embed malicious payloads in the first N bytes of oversized tool output and have them delivered unsanitized to the LLM. Restructure the truncation path so it feeds into the same safety pipeline as non-truncated content: leak detection, policy checks, and Aho-Corasick injection scanning all run on the (possibly truncated) content before it is returned. Adds regression tests to verify truncated output is still scanned. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * style: apply rustfmt to fix CI formatting check Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com> --------- Co-authored-by: Wui <wui@Wui-Work-2.local> Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com> Co-authored-by: Illia Polosukhin <ilblackdragon@gmail.com>
…5957 chore: promote staging to staging-promote/833dd32a-23994503713 (2026-04-05 05:33 UTC)
henrypark133
merged commit Apr 9, 2026
1489daa
into
staging-promote/54519776-23969879338
10 of 13 checks passed
theredspoon
pushed a commit
to theredspoon/ironclaw
that referenced
this pull request
Jun 21, 2026
…3994503713 chore: promote staging to staging-promote/7a8967c4-23969879338 (2026-04-05 04:48 UTC)
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Auto-promotion from staging CI
Batch range:
a55aff980a4e235590c3af57ded2542512e2f9f6..833dd32a8b0d874cc8e6a685901f0db69420d473Promotion branch:
staging-promote/833dd32a-23994503713Base:
staging-promote/54519776-23969879338Triggered by: Staging CI batch at 2026-04-05 04:48 UTC
Commits in this batch (21):
Current commits in this promotion (1)
Current base:
staging-promote/54519776-23969879338Current head:
staging-promote/833dd32a-23994503713Current range:
origin/staging-promote/54519776-23969879338..origin/staging-promote/833dd32a-23994503713Auto-updated by staging promotion metadata workflow
Waiting for gates:
Auto-created by staging-ci workflow