Skip to content

sync: merge upstream/main up to Decepticon v1.1.47 - #3

Merged
Exploitacious merged 27 commits into
mainfrom
sync/upstream-2026-09-26
Sep 27, 2026
Merged

Exploitacious merged 27 commits into
mainfrom
sync/upstream-2026-09-26

Conversation

@Exploitacious

Copy link
Copy Markdown
Owner

Merge (not rebase) of upstream PurpleAILAB/Decepticon into the fork, keeping the fork's own 13 commits and history. Merge-base was 258bb30c (2026-08-12); 26 upstream commits pulled. A pure fast-forward is not possible (the fork has 13 commits upstream lacks), so this is a merge commit for review, not an auto-merge.

Upstream changes by area (commit subjects)

Runtime / agents / capabilities

Security / Rules of Engagement

Release / packaging / deps / CI

Launcher (Go client)

  • fix(launcher): reject missing installation secrets; reject legacy salt fallback
  • test(launcher): handle Windows permission semantics

Skills / docs / benchmark

Plus five upstream merge commits from the BitterSecurity release branches.

Areas that touch Job B (langgraph runtime/infra), flagged for the stacked fix PR:

  • containers/langgraph.Dockerfile: adds PYTHONDONTWRITEBYTECODE=1.
  • docker-compose.yml: renames the langgraph/web image org purpleailab -> bittersecurity (inert here; the box builds fork images and never pulls, AUTO_UPDATE=false).
  • langgraph.json: adds the autohunt graph.

Conflict resolution

Only one real conflict: CHANGELOG.md (both sides added entries at the top). Kept the fork's [Unreleased] - Umbrella/Exploitacious fork section on top, appended upstream's [1.1.47]/[1.1.45]/[1.1.44] entries above the shared [1.1.40] tail, and added a fork note recording the merge.

Auto-merged, verified the fork's intent survived:

  • docker-compose.yml: fork's langgraph dev --no-reload kept; took upstream's image org rename.
  • .env.example: fork's telemetry-off (DECEPTICON_TELEMETRY=off, DO_NOT_TRACK=1) kept; upstream added no telemetry endpoint.
  • llm.py / factory.py: fork's OpenCode Go provider and glm-5.3 pin intact.
  • docs/setup-guide.md: clean. uv.lock: taken from upstream (fork never modified it); valid TOML.

Checks (this box)

  • uv run pytest -n auto -q -m "not slow": 5177 passed, 44 skipped (skips are Neo4j-unreachable integration + Windows-only).
  • uv run ruff check .: All checks passed. ruff format --check: 712 files already formatted.
  • make quality-cli: CLI typecheck/build + 31 tests passed. make web-lint && make web-build: compiled successfully.

Not a fast-forward (histories diverged), but this merge is clean and green. Do not merge without maintainer review.

PurpleCHOIms and others added 27 commits August 14, 2026 09:46
…5-26-28-release

fix(release): restore OSS installation readiness
…ata-2-5-release

fix(release): support Python metadata 2.5
…#807)

Bind missing OPPLAN workspaces before filesystem bootstrap and buffer Ollama tool-bound requests to preserve native tool calls. Align orchestration guidance with registered tools and objective states.
* docs(skills): add typed finding locations

* chore(skills): regenerate skill graph

---------

Co-authored-by: NetVar <NetVar1337@users.noreply.github.com>
…ty#811)

* feat(capabilities): add specialist validation contracts

* fix(ci): address CodeQL recommendations

---------

Co-authored-by: NetVar <NetVar1337@users.noreply.github.com>
…y#813)

Add Autohunt as a dedicated autonomous planning lane while preserving Soundwave as the default interview-first workflow.
…#817)

* fix(deps): patch critical Next.js and Vitest advisories

* fix(deps): resolve blocking Python security advisories
* docs: release v1.1.44

* docs(release): clarify onboarding telemetry default

* docs(release): distinguish provider and workload controls

* docs(release): include targeted JavaScript security updates

* docs(release): note canonical distribution paths

* docs(release): clarify version selection before publication
…ssage-event-times-20260924

feat(streaming): persist sub-agent event times
…-1.1.45-20260924

docs: prepare Decepticon v1.1.45 release
…terSecurity#823)

* fix(roe): honor signed root URL targets in web fetch

* fix(roe): compile URL scopes into sandbox network policy

* fix(roe): enforce denied hosts in sandbox egress

* fix(roe): fail closed for unresolved hostname exclusions

* fix(roe): retain target egress when metadata alias is absent

* fix(roe): cover default metadata aliases in egress
…rSecurity#816)

Co-authored-by: Minseok CHOI <31537001+PurpleCHOIms@users.noreply.github.com>
…#825)

* fix: cap Soundwave interview at 8 questions (was ~18)

roe-template drove 10 separate ask_user_question calls and
conops-template another 8 (including one for the DEPRECATED
communication_plan field), so a fresh engagement paid for every
dimension one field at a time before any planning document existed.

- Add a hard 8-question interview budget (CRITICAL_RULES BitterSecurity#12 in
  soundwave.md): only Scope and Success criteria are always asked;
  everything else defaults from schema/RoE/CONOPS content unless the
  operator's answers raise a flag a default cannot cover.
- roe-template: merge related fields into 6 combined questions
  (was 10) instead of one ask_user_question per field.
- conops-template: ask only threat-actor tier + success criteria (2,
  was 8); derive motivation/initial access from tier, drop the
  deprecated communication_plan question, agent-draft the narrative,
  default deconfliction method.
- Fold assumption-challenge follow-ups into the original picker's
  options instead of spawning a second question round.

Fixes BitterSecurity#824

* chore: regenerate skills.cypher for roe/conops-template edits

---------

Co-authored-by: NetVar1337 <netvar1337@users.noreply.github.com>
…-1.1.47-20260926

docs: prepare Decepticon v1.1.47 release
Merge (not rebase) of upstream PurpleAILAB/Decepticon into the fork, keeping
the fork's own 13 commits and history. Merge-base was 258bb30 (2026-08-12);
26 upstream commits pulled.

Conflict resolutions (fork's changes kept unless upstream superseded):
- CHANGELOG.md: kept the fork's [Unreleased] section on top, appended
  upstream's [1.1.47]/[1.1.45]/[1.1.44] release entries above the shared
  [1.1.40] tail. Added a fork note recording this merge.

Auto-merged, verified fork intent survived:
- docker-compose.yml: fork's `langgraph dev --no-reload` command kept; took
  upstream's image org rename (purpleailab -> bittersecurity), which is inert
  here since the box builds fork images and never pulls (AUTO_UPDATE=false).
- .env.example: fork's telemetry-off (DECEPTICON_TELEMETRY=off, DO_NOT_TRACK=1)
  kept; upstream added no telemetry endpoint.
- llm.py / factory.py: fork's OpenCode Go provider and glm-5.3 pin intact.
- docs/setup-guide.md: clean.
- uv.lock: taken from upstream (fork never modified it); valid TOML.


if is_bundle_enabled("standard"):
graph = create_autohunt_agent()
)
)

def resolver(hosts):
@Exploitacious
Exploitacious merged commit e088ec5 into main Sep 27, 2026
32 of 33 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants