Skip to content

ruflo updates — week of 2026-05-10 (243 new commits, tip 5f0c8455c) #3

@github-actions

Description

@github-actions

ruvnet/ruflo — last 7 days

Window: since 2026-05-03 · Upstream tip: 5f0c8455c

feat (74)

  • 056ed8e48 feat(federation): optimizations + ADRs 105-110 (alpha.13 + agentic-flow@fix.8) (#1878) (rUv)
  • 19a569b1a feat(federation): ADR-097 phases 2.a/2.b/3-up/4 + ADR-104 transport (#1876) (rUv)
  • b4a60e037 feat: performance verification + capability historical reference (Reuven)
  • 9817695a6 feat: per-OS verification cognitive containers + tutorial README (Reuven)
  • 76bd35943 feat: ADR-103 witness temporal history + plugin-distributed toolkit (#1868) (Reuven)
  • d031c3d13 feat(agentdb): hierarchical + causal-edge + causal-node delete MCP tools (#1784) (#1789) (rUv)
  • 10cf962e4 feat(neural): substrate upgrades 1-6 + SEO keywords (#1773) (#1776) (rUv)
  • 0a0a246a6 feat(neural): Phase 1 convergence — cli depends on @claude-flow/neural + README cleanup (#1773) (#1774) (rUv)
  • c8827c612 feat(router): Thompson sampling bandit replaces deterministic argmax (#1772) (#1772) (rUv)
  • ba92c5612 feat(cli-core): split cli into cli-core (lite) + cli (umbrella) — alpha.5 (#1764) (rUv)
  • cd0b66f0d feat(ruflo-adr): one-shot import + verify scripts (v0.3.0) (#1758) (rUv)
  • 129a6b405 feat(cost-tracker): P9 — programmatic cost-summary contract (v0.15.0) (Reuven)
  • 1c0804315 feat(cost-tracker): P6 — ADR-097 Phase 3 federation_spend consumer (v0.14.0) (Reuven)
  • 3ea80a9a9 feat(cost-tracker): P10 — telemetry export (Prometheus + webhook) (v0.13.0) (Reuven)
  • 088e18f17 feat(cost-tracker): P11 — cost-per-conversation view (v0.12.0) (Reuven)
  • 4b3169df9 feat(cost-tracker): P8 — GitHub Actions smoke + booster bench on PR (v0.11.0) (Reuven)
  • c16114659 feat(cost-tracker): P7 — corpus v3 expansion (16 → 25 cases) (v0.10.0) (Reuven)
  • 89d7584b4 feat(cost-tracker): P5 — cost-trend skill surfaces drift across bench runs (v0.9.0) (Reuven)
  • 8f580f207 feat(cost-tracker): P4 — encapsulate compact-context Node block as compact.mjs (v0.8.0) (Reuven)
  • 333e6338d feat(cost-tracker): P3 — auto-emit hooks_model-outcome (v0.7.0) (Reuven)
  • 5d2f86080 feat(cost-tracker): P2 — real budget enforcement (v0.6.0) (Reuven)
  • 78f06f623 feat(cost-tracker): P1 — auto-capture token usage from session jsonl (v0.5.0) (Reuven)
  • 0fd61e3e5 feat(cost-tracker): ADR-0002 — verified Agent Booster integration (v0.4.0) (Reuven)
  • d9db4e766 feat(ruflo-workflows): v0.2.0 — adopt plugin contract + 10-tool MCP surface + lifecycle state machine (ADR-0001) (Reuven)
  • 81ec1af40 feat(ruflo-wasm): v0.2.0 — adopt plugin contract + ADR-070 integration cross-reference (ADR-0001) (Reuven)
  • f457b3918 feat(ruflo-testgen): v0.2.0 — adopt plugin contract + SPARC Refinement-phase ownership (ADR-0001) (Reuven)
  • 714f501f7 feat(ruflo-swarm): v0.2.0 — adopt plugin contract + 12-tool MCP surface (ADR-0001) (Reuven)
  • ce37f98c5 feat(ruflo-sparc): v0.2.0 — adopt plugin contract + phase-to-plugin alignment table (ADR-0001) (Reuven)
  • c203bc5d8 feat(ruflo-security-audit): adopt plugin contract — AIDefence static/runtime layered integration (ADR-0001) (Reuven)
  • 414a79d56 feat(ruflo-rvf): adopt plugin contract — cross-plugin RVF ownership table (ADR-0001) (Reuven)
  • 1ef889cb3 feat(ruflo-ruvllm): v0.2.0 — adopt plugin contract + cross-plugin tool ownership table (ADR-0001) (Reuven)
  • 2b6cefd57 feat(ruflo-rag-memory): adopt plugin contract — claude-memories reserved-namespace consumer (ADR-0001) (Reuven)
  • 003624f74 feat(ruflo-plugin-creator): v0.2.0 — scaffold the canonical contract + MCP-drift warnings (ADR-0001) (Reuven)
  • e148c5611 feat(ruflo-neural-trader): adopt plugin contract — already-compliant namespaces + 4-namespace claim (ADR-0001) (Reuven)
  • e24481f51 feat(ruflo-loop-workers): v0.2.0 — adopt plugin contract + 12-worker trigger map (ADR-0001) (Reuven)
  • 312f59943 feat(ruflo-jujutsu): v0.2.0 — adopt plugin contract (ADR-0001, ADR-compliance integration, smoke) (Reuven)
  • 4046967c0 feat(ruflo-iot-cognitum): v0.2.0 — adopt plugin contract (ADR-0001, federation trust-model parallel, smoke) (Reuven)
  • 714cd534c feat(ruflo-goals): adopt plugin contract — legacy-vs-canonical namespace mapping + ADR-099 anchor (ADR-0001) (Reuven)
  • b0168e4a5 feat(ruflo-federation): adopt plugin contract — 3-gate alignment + ADR-097 budget integration + smoke (ADR-0001) (Reuven)
  • 064821831 feat(ruflo-docs): v0.2.0 — adopt plugin contract (ADR-0001, document-worker contract, namespace coordination) (Reuven)
  • ab5ec6b88 feat(ruflo-ddd): v0.2.0 — adopt plugin contract (ADR-0001, namespace coordination, smoke as contract) (Reuven)
  • b6d13ae98 feat(ruflo-daa): v0.2.0 — adopt plugin contract (ADR-0001, intelligence-pipeline alignment) (Reuven)
  • bd384ad5e feat(ruflo-core): v0.2.0 — adopt foundation plugin contract (ADR-0001, MCP server contract, sibling ADR cross-references) (Reuven)
  • 36a01c410 feat(ruflo-autopilot): v0.2.0 — adopt plugin contract (ADR-0001, namespace coordination, smoke as contract) (Reuven)
  • 9982c701f feat(ruflo-aidefence): adopt plugin contract + canonicalize 3-gate pattern (ADR-0001) (Reuven)
  • df49b5176 feat(ruflo-adr): v0.2.0 — adopt plugin contract (ADR-0001, namespace coordination, smoke as contract) (Reuven)
  • 78e5658df feat(ruflo-intelligence): v0.3.0 — surface completeness, 4-step pipeline, IPFS transfer, namespace coordination (Reuven)
  • 6324f5ae0 feat(ruflo-agentdb): v0.3.0 — accurate surface, RaBitQ workflow, namespace contract, hook integration (Reuven)
  • b5b6fb3fb feat(ruflo-browser): v0.2.0 session-as-skill architecture + ADR-0001 (Reuven)
  • 1e11ac84e feat(ruflo-goals): dossier-investigator agent + dossier-collect skill (ADR-099) (#1726) (rUv)
  • 9c1a71f00 feat(providers): add Ollama (Tier-2) — closes #1725 + workflow_execute fix (Reuven)
  • cf96a562c feat(plugins): ADR-098 Part 1 (slice 4/4) — G7 controllers in agentdb + knowledge-graph (Reuven)
  • 00a9d13b5 feat(plugins): ADR-098 Part 1 (slice 3/4) — cost-tracker federation pairing (Reuven)
  • 6130f4061 feat(plugins): ADR-098 Part 1 (slice 2/4) — encryption-at-rest notes for memory plugins (Reuven)
  • 6a4057474 feat(plugins): ADR-098 Part 1 (slice 1/3) — capability sync for security plugins (Reuven)
  • 29542ce6d feat(plugins): ADR-098 Part 3 — security-auditor opus → sonnet (Reuven)
  • 2e5c90c90 feat(plugins): ADR-098 Part 4 — standardize neural-learning hook (Reuven)
  • ccf58ea4d feat(doctor): ADR-096 Phase 5 — encryption-at-rest status section (Reuven)
  • 9d43d8fdb feat(verification): per-source-file MCP witnesses (task #25, iteration #51) (Reuven)
  • 841365f64 feat(encryption): ADR-096 Phase 4 — wire vault into memory DB writes/reads (Reuven)
  • 49c8019ed feat(encryption): ADR-096 Phase 3 — wire vault into terminal-tools (Reuven)
  • 7e1cc06df feat(federation): ADR-097 Phase 1 — budget envelope + hop counter (#1723) (Reuven)
  • 98aa2560e feat(encryption): ADR-096 Phase 2 — wire vault into session-tools (Reuven)
  • cb9a9f346 feat(encryption): ADR-096 Phase 1 — vault primitives + tests (Reuven)
  • b2716337f feat(G7): activate GuardedVectorBackend (5 of 6 controllers wired) (Reuven)
  • 9f38ecc41 feat(G7): activate MutationGuard + AttestationLog (4 of 6 now wired) (Reuven)
  • 6f495369f feat(G2): real Ed25519 signing + verification in agent-federation plugin (Reuven)
  • 591839304 feat(G4): WASM agent prompt routes to Anthropic when WASM echoes input (Reuven)
  • 9c511cf03 feat(G7): activate gnnService + rvfOptimizer via file:// imports (Reuven)
  • 6206b93da feat(G3): real workflow runtime — task/wait/condition step execution (Reuven)
  • 8b586363d feat(G1): agent_execute wires real Anthropic Messages API to agent registry (Reuven)
  • 6d37a5ff9 feat(cli): add 'ruflo verify' for signed witness manifest verification (Reuven)
  • 3c6d126b7 feat: add verification.md witness manifest for regression monitoring (Reuven)
  • 21f668c55 feat: implement ADR-094 transformers migration + ADR-095 gap tracking (Reuven)

fix (83)

  • 858ce28f7 fix(cli): bin/cli.js MCP-stdio auto-detect overrode explicit -t http (Reuven)
  • d065b2d65 fix #1874 + add MCP protocol-compliance smoke layer (Reuven)
  • b289c009e fix(witness): probe workspace packages for @noble/ed25519 (pnpm isolated linker) (Reuven)
  • 3ba0b6141 fix(plugin-agent-federation): add CLAIMS_FOR_MESSAGE_TYPE entries for ADR-101 Component C (Reuven)
  • 8d06e427c fix: #1859 #1862 ruflo-core hooks + CLI flag priority (Reuven)
  • 966335022 fix(@claude-flow/memory@3.0.0-alpha.15): #1867 unblock install on Node 26 (Reuven)
  • 66f7f644d fix(3.7.0-alpha.17): #1565 supervisor, #1856 mid-flight detector, #1857 Windows tasklist (Reuven)
  • f46e52f41 fix(3.7.0-alpha.16): daemon crash recovery (#1855) (Reuven)
  • d88c69dde fix(3.7.0-alpha.15): #1852 Windows shell-injection, #1853 daemon self-kill, #1854 memory path (Reuven)
  • 2804d85f1 fix(3.7.0-alpha.14): auto-compact statusline on narrow terminals (Reuven)
  • ea8cbf697 fix(@claude-flow/embeddings@3.0.0-alpha.16): Windows ERR_PACKAGE_PATH_NOT_EXPORTED (Reuven)
  • a9db4cd3e fix(plugin-code-intelligence@3.0.0-alpha.3): real import edges in GNN bridge (Reuven)
  • e7a11f26f fix(plugin-code-intelligence@3.0.0-alpha.2): real impl for stub helpers (Reuven)
  • c67fa393d fix(3.7.0-alpha.13): persist headless results + ab-test guard (Reuven)
  • 1884ed101 fix(3.7.0-alpha.12): batch resolve issue-fix loop #1839-#1847 (Reuven)
  • 02976fcb9 fix(skills): prune duplicate skill sources to fix truncation (closes #1834) (#1836) (rUv)
  • 67a2197f9 fix(settings): bump skillListingBudgetFraction to 6% (#1834) (#1835) (rUv)
  • addb5cd3f fix(release): hotfix 3.7.0-alpha.11 — strip workspace: protocol leak (#1825) (#1827) (rUv)
  • 23016fdfa fix(hive-mind): use --mcp-config= to stop variadic prompt slurp (#1780) (#1800) (rUv)
  • b9e2eb37e fix(deps): bump vulnerable vitest pins to ^4.0.16 (#1609) (#1819) (rUv)
  • ed6d847fa fix(security): drop bcrypt → bcryptjs to eliminate tar CVE chain (closes #1608) (#1818) (rUv)
  • 367313824 fix(security): retry plain import + actionable error for aidefence load (closes #1807) (#1813) (rUv)
  • 7cee60317 fix(init): skip writing .mcp.json when ruflo MCP already registered (#1779) (#1820) (rUv)
  • 3ed34fe06 fix(hive-mind): re-route task submission to existing task_create MCP tool (#1791.1) (#1806) (rUv)
  • 7ebdaf580 fix(cli): pre-load lazy commands so short flags scope correctly (#1791.2) (#1803) (rUv)
  • 48da302b3 fix(doctor): walk-up .git fallback for git-repo health check (#1791.7) (#1802) (rUv)
  • 0377945c9 fix(memory): make memory init idempotent when DB already exists (#1791.6) (#1801) (rUv)
  • 88f9fba5f fix(doctor): surface config collision between legacy JSON and v3 YAML (#1798) (#1811) (rUv)
  • c42aa265a fix(swarm): reconcile orphan entries on swarm-state.json load (#1799) (#1809) (rUv)
  • 3eb6b4d65 fix(memory): content-hash dedupe in memory_import_claude (#1791.8) (#1808) (rUv)
  • 122193a45 fix(memory): show active embedding provider + HNSW status in stats (#1622) (#1816) (rUv)
  • 7bfd650ee fix(init): make RuFlo attribution trailer opt-in (#1670) (#1815) (rUv)
  • d46972171 fix(hooks): NaN-safe coercion in metrics + pretrain output (#1686) (#1814) (rUv)
  • 93b97548e fix(cli): subcommand --help renders the leaf, not the parent (#1791.4) (#1805) (rUv)
  • b51b804fa fix(doctor): clarify that --fix prints commands rather than auto-applying (#1791.5) (#1804) (rUv)
  • 2fd38f4de fix(wasm): bump default Sonnet from 20250514 to 4.6 (closes #1810) (#1812) (rUv)
  • 6268605f2 fix(statusline): detect Python test_.py / spec_.py files (#1463) (#1821) (rUv)
  • 8221903b0 fix(release): add missing cli runtime deps to umbrella package.json (closes #1795) (#1797) (rUv)
  • 004dda36d fix(plugin): repoint plugin/agents symlink at .claude/agents (33 active md files) (Reuven)
  • a7122a50e fix(intelligence): make Flash Attention + ruvllm coordinator stats truthful (#1770) (#1771) (rUv)
  • 69e72d2e4 fix(daemon): break IPC pipe so background daemon survives parent exit on Windows (#1766) (Reuven)
  • 4e1e2618e fix(ruflo): bump @claude-flow/cli dep range to ^3.7.0-alpha.1 (Reuven)
  • b5b41e392 fix(ci): regenerate package-lock.json to satisfy package.json constraints (#1765) (rUv)
  • d5fbb3bc4 fix(hooks): stop creating empty files via $TOOL_INPUT shell injection (#1747) (#1757) (rUv)
  • cc114c8db fix(mcp): sharpen high-overlap tool descriptions for better selection (#1748 Issue 4) (v3.6.30) (#1756) (rUv)
  • 7aa7fc93e fix(hive-mind): pass --mcp-config to spawned worker (#1748 Issue 2) (v3.6.29) (#1755) (rUv)
  • a002ae49a fix(plugins): hooks per-plugin layout — ruflo-core install now loads hooks (#1748 Issue 1) (#1754) (rUv)
  • 229d273a1 fix(init): #1744 honest defaults + runtime fallbacks (v3.6.28) (#1753) (rUv)
  • 47704f83d fix(agents): coder agents now read docs/adr/*.md alongside docs/SPEC.md (#1749) (#1752) (rUv)
  • 8363b558e fix(ruvocal): drop generic-runes syntax that broke prod build (Reuven)
  • 9cfba12ab fix(ruvocal): autopilot AUTO toggle is silent + autopilotMaxSteps setting was dead wiring (closes #1742) (Reuven)
  • bd07fe6c9 fix(ruvocal/mcp): skip SSE fallback on 4xx/5xx + rate-limit cooldown (closes #1741) (Reuven)
  • 1c3093d46 fix(ruflo-observability): v0.2.0 — namespace-routing fix + adopt plugin contract (ADR-0001) (Reuven)
  • 894a199cc fix(ruflo-migrations): v0.2.0 — namespace-routing fix + adopt plugin contract (ADR-0001) (Reuven)
  • 75d57c4ec fix(ruflo-market-data): v0.2.0 — fix 3 functional bugs (embeddings_embed + namespace-routing) + adopt plugin contract (ADR-0001) (Reuven)
  • 0aeb255b8 fix(ruflo-knowledge-graph): correct embeddings_embed → embeddings_generate + adopt plugin contract (ADR-0001) (Reuven)
  • 9dc248700 fix(ruflo-cost-tracker): v0.2.2 — fix namespace-routing bug + adopt plugin contract (ADR-0001) (Reuven)
  • 6e1bdc211 fix(plugins): pin ruflo-ruvector to ruvector@0.2.25 + expand verified CLI surface (Reuven)
  • f8ce23346 fix: resolve 5 issues from May 1-3 (#1697 #1698 #1686 #1691 #1694) (#1719) (rUv)
  • 1f3b7c8c2 fix(ci): regen v3/pnpm-lock.yaml — was the actual CI culprit (Reuven)
  • 899dcae93 fix(ci): regenerate pnpm-lock.yaml + package-lock.json for typescript ^5.9.3 bump (Reuven)
  • f6d18472d fix(test): bring full vitest suite to 0 failures (Reuven)
  • c1b57e4fd fix(security): close shell injection in update/executor (audit_1776853149979) (Reuven)
  • 73babfb06 fix(security): close shell injection in github-tools MCP (audit_1776853149979) (Reuven)
  • de96b0eed fix(security): restrict file mode on session/memory/terminal stores (audit_1776853149979) (Reuven)
  • fb256ac59 fix(security): denylist loader-hijack env vars in terminal_create (audit_1776853149979) (Reuven)
  • d9fd35956 fix(security): add fetch timeouts to verify + IPFS HEAD probe (audit_1776853149979) (Reuven)
  • 5073f5673 fix(security): drop shell from git calls in statusline (audit_1776853149979) (Reuven)
  • 3baebe177 fix(security): close command injection in github-safe.js (audit_1776853149979) (Reuven)
  • 87cc2f323 fix(verify): resolve plugin paths from source-tree when running locally (Reuven)
  • 6b46946dc fix(intelligence): G6 — content-hash dedup + hoist trigram cache (Reuven)
  • aeeeff72f fix(cli): extract suppression to side-effect module imported FIRST (Reuven)
  • 28fed919b fix(cli): move [AgentDB Patch] suppression to dist/src/index.js (Reuven)
  • ea312c850 fix(aidefence): quick-mode PII detection + wrapper-level stats counters (Reuven)
  • 32c46c2b9 fix(install): #1721 — postinstall script copies all dist/src/* siblings (Reuven)
  • e884b11ee fix(cli): tight match for cosmetic [AgentDB Patch] noise + cover console.log (Reuven)
  • 53409aba5 fix(embeddings): handle agentic-flow shape change in 3.0.0-alpha.14 (Reuven)
  • e3528f206 fix: F9 — actionable bridgeSemanticRoute error + multi-version router probe (Reuven)
  • 565681fff fix: F7 coordination_orchestrate honesty + F11 neural_predict classifier (Reuven)
  • e4b4a3e1e fix: security overrides + F8 perf metrics + F10 attention placeholder (Reuven)
  • 4f2f68d52 fix(embeddings): graceful agentic-flow fallback in downloadEmbeddingModel (Reuven)
  • c5915a718 fix(mcp): ADR-093 — remediate 7 audit findings, ship 3.6.14 (Reuven)
  • a10a13e62 fix(cli,ui): resolve five issues from May 1-3 reports (Reuven)

perf (7)

  • 5addd83b4 perf(plugins): ADR-098 Part 2 (slice 4/4) — token diet for ruflo-cost-tracker/cost-analyst (Reuven)
  • 85eab480e perf(plugins): ADR-098 Part 2 (slice 3/4) — token diet for ruflo-adr/adr-architect (Reuven)
  • 1e5a8ec89 perf(plugins): ADR-098 Part 2 (slice 2/4) — token diet for ruflo-ddd/domain-modeler (Reuven)
  • f1bb3cf84 perf(plugins): ADR-098 Part 2 (slice 1/4) — token diet for iot-cognitum/device-coordinator (Reuven)
  • da2cd80d8 perf: hoist dynamic stdlib imports to static across commands/ (Reuven)
  • 33cb210e6 perf: drop redundant dynamic imports of already-loaded stdlib modules (Reuven)
  • bd55cd7cb perf(memory-bridge): parallelize post-init wiring (intelligence + agentdb) (Reuven)

docs (22)

  • 02eee0bcd docs(adr): bulk-update plugin contract ADR statuses (sweep) (Reuven)
  • a8ba7276d docs(adr): ADR-085/086/087/088/094 status — Proposed/stale → accurate implementation state (Reuven)
  • 3f35608a9 docs(adr): ADR-097/098/099/100 status — Proposed → actual implementation state (Reuven)
  • d93fffa8d docs(adr): ADR-101 federation status — Proposed → Accepted (Implemented) (Reuven)
  • b5a57cbf1 docs: add docs/validation/ — in-repo home for the agentic validation system (Reuven)
  • 8709c8dd5 docs: ADR-102 + bump packages to 3.7.0-alpha.18 (published) (Reuven)
  • acd8ef197 docs(verify): add 2026-05-06 verification run results — 100% semantic pass (#1822) (rUv)
  • 196c837a9 docs(skill): add Security Considerations to github-project-management (#1574) (#1817) (rUv)
  • fe84d50f1 docs(ruflo): sync README with root + add prepublishOnly hook (3.7.0-alpha.9) (Reuven)
  • 6c14c912e docs(userguide): update for v3.7 — substrate upgrades + agentdb delete tools (Reuven)
  • 6af8ef100 docs(readme): refresh top-of-readme badge cluster (Reuven)
  • 2029c71e6 docs: fix init/MCP drift surfaced in #1744 install study (#1751) (rUv)
  • 4f1580bf1 docs(cost-tracker): consistency audit — agent + README mention all 13 skills (v0.16.1) (#1750) (rUv)
  • 9c706d28a docs(cost-tracker): ADR-0003 + corpus v3 bench refresh (v0.16.0) (Reuven)
  • ef1f296c2 docs(adr): ADR-098 — plugin capability sync + token/perf/intel/self-opt pass (Reuven)
  • 8c0d58011 docs: split STATUS doc + cross-link verification.md from root README (Reuven)
  • 52a96f39a docs(verification): add full capability inventory — 300 MCP tools / 49 CLI / 32 plugins / 43 agents (Reuven)
  • bbb90046e docs(adr): ADR-096 — flip status to Accepted, log Phase 1–4 implementation (Reuven)
  • 149ea30a4 docs(plugin): update ruflo-federation Claude Code plugin for ADR-097 (Reuven)
  • 62a6fc5fb docs(adr): ADR-097 — federation-wide budget circuit breaker (#1723) (Reuven)
  • e6478f9ab docs(adr): ADR-096 — encryption-at-rest design (audit_1776853149979) (Reuven)
  • c32ddead2 docs(adr-094): migration plan for @xenova → @huggingface/transformers (Reuven)

chore (27)

  • 5f0c8455c chore: remove archive/ to shrink marketplace clone footprint (#1882) (#1885) (rUv)
  • a075c59fc chore: bump versions for #1874 publish chain (Reuven)
  • 779eb309b chore(witness): register ADR-101-C federation fix as #82 (Reuven)
  • d4795b753 chore(ruflo-core): 0.2.0 → 0.2.1 (publish #1859 #1862 fix) (Reuven)
  • d6936bae3 chore(@claude-flow/memory): bump to 3.0.0-alpha.15 (published) (Reuven)
  • 3c0430b8b chore(witness): add 23 fix entries from 2026-05 issue-fix loop (#1838) (rUv)
  • 0666796a0 chore(witness): regenerate verification.md.json for 3.7.0-alpha.11 (#1837) (rUv)
  • d027af098 chore(release): 3.7.0-alpha.10 — 21 fixes from issue-fix loop (#1823) (rUv)
  • c07b5c263 chore(archive): move root agents/ stubs to archive/agents-root/ (Reuven)
  • f1a82d9ee chore(release): 3.7.0-alpha.8 — agentdb delete tools (#1784/#1789) (Reuven)
  • 3abfb5d0a chore(verification): regenerate inventory + fix CRLF bug in extractor (Reuven)
  • 55ae6ca57 chore(repo): remove stray root pnpm-lock.yaml (Reuven)
  • 003ce127b chore(repo): archive legacy v2/ codebase under archive/v2/ (Reuven)
  • 5c51df58c chore(release): 3.7.0-alpha.1 — cli-core split alpha (Reuven)
  • 0c2b0c02f chore(release): regen witness for 3.6.27 (Ollama provider fix) (Reuven)
  • fb2123905 chore(release): bump to 3.6.26 + regen witness (Reuven)
  • f8cd1c9fe chore(release): bump to 3.6.25 + regen witness manifest (Reuven)
  • f514495c8 chore(verify): regenerate witness for 3.6.24 (27 fixes — adds G7-gvb) (Reuven)
  • dba6b54d6 chore: bump to 3.6.24 (GuardedVectorBackend activated) (Reuven)
  • fdc00cce3 chore(verify): regenerate witness for 3.6.23 (26 fixes) (Reuven)
  • 892f54a78 chore: bump to 3.6.23 (G7 mutationGuard + attestationLog activated) (Reuven)
  • a9421d068 chore(verify): regenerate witness manifest for 3.6.22 (24 fixes) (Reuven)
  • db210a93a chore: bump to 3.6.22 + plugin-agent-federation@1.0.0-alpha.4 (Reuven)
  • 0f5d415e8 chore: bump to 3.6.21 (verify command) (Reuven)
  • 43fda1110 chore: bump to 3.6.20 (G6 auto-memory dedup) (Reuven)
  • 6369151ac chore: bump to 3.6.19 + @claude-flow/embeddings@3.0.0-alpha.15 (Reuven)
  • 2c9e7e360 chore: bump to 3.6.16 (Reuven)

test (10)

  • 12f2546c0 test+ci: revert to threads pool + tolerate SIGSEGV at exit (Reuven)
  • d59ad3cc4 test: bump guidance-provider 60s → 180s for cold HF embedding model load (Reuven)
  • 5372f8355 test: residual fixes — speedup honesty + inline timeout + macOS Node 24 (Reuven)
  • da2a787c0 test: fix extractToolBlock + WASM/CI skip discriminator + hooks timeout (Reuven)
  • f51c11e2c test: mock sharp globally in vitest setup (transitive dep, never built) (Reuven)
  • 45ebb11cc test+config: skip SONA keyword extraction + switch to forks pool (Reuven)
  • a680501a3 test: skip 5 integration tests revealing real bugs (#1872) (Reuven)
  • 584fc8e66 test+ci: extract-tool-block + workspace build + timeout bump (Reuven)
  • d3fbfa861 test: skip native-binding + integration tests when prereq absent (Reuven)
  • bbe53a21c test(security): regression tests for validateEnv + fs-secure (audit_1776853149979) (Reuven)

ci (10)

  • c51841590 ci+docs: extend regression guards to ubuntu+macos+windows (Reuven)
  • 802dff517 ci: extend path filter to plugin witness scripts (silent coupling fix) (Reuven)
  • 19867b339 ci: surface witness-verify failure details (was exiting silently) (Reuven)
  • a8e9a05b0 ci: use standalone witness verifier + ts-ignore optional sona import (Reuven)
  • aedc7a62b ci: pnpm pack for memory smoke + drop Node 20 from plugin-hooks matrix (Reuven)
  • 4ba3adecd ci: tolerate cross-package conflicts in regression-guard jobs (Reuven)
  • 2ac256afb ci: decouple new regression jobs from broken workspace build (Reuven)
  • 54c706f56 ci: integrate witness manifest verification into v3-ci pipeline (Reuven)
  • 3e8781bd2 ci: add no-better-sqlite3 install smoke for #1867 regression guard (Reuven)
  • fd4c3cb3c ci(windows): add daemon-survives-parent-exit regression test for #1766 (rUv)

other (10)

  • 9d4a9ea96 ADR-101: Federated Claims — cross-node work coordination (Phases 1-3) (#1777) (rUv)
  • 6f11cc794 Update README.md (rUv)
  • 7523e4daa Update README.md (rUv)
  • 1c266663c Revise Ruflo description in README (rUv)
  • cb3809820 Update branding from Claude Flow to Ruflo (rUv)
  • 00039a833 Update README.md (rUv)
  • f8f4cd4bc security: untrack .env files + broaden .gitignore to block .env.* (Reuven)
  • 82cfc9a7b merge: integrate origin/main (#1719 #1726) into local 81-commit train (Reuven)
  • 0535c3823 sec: cap MCP stdin buffer at 10MB to prevent DoS via un-newlined input (Reuven)
  • bc399dc9a sec: tighten npm overrides for protobufjs (critical RCE), tar, uuid (Reuven)

Inspect a commit: git fetch upstream && git show <sha>
Diff a path: git diff upstream/main -- path/to/file
Port a commit: git cherry-pick <sha> (expect conflicts — no shared history)

Metadata

Metadata

Assignees

No one assigned

    Labels

    upstream-digestWeekly digest of ruvnet/ruflo activity

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions