sync: merge upstream/main up to Decepticon v1.1.47 - #3
Merged
Merged
Conversation
…5-26-28-release fix(release): restore OSS installation readiness
…ata-2-5-release fix(release): support Python metadata 2.5
…#807) Bind missing OPPLAN workspaces before filesystem bootstrap and buffer Ollama tool-bound requests to preserve native tool calls. Align orchestration guidance with registered tools and objective states.
* docs(skills): add typed finding locations * chore(skills): regenerate skill graph --------- Co-authored-by: NetVar <NetVar1337@users.noreply.github.com>
…ty#811) * feat(capabilities): add specialist validation contracts * fix(ci): address CodeQL recommendations --------- Co-authored-by: NetVar <NetVar1337@users.noreply.github.com>
…y#813) Add Autohunt as a dedicated autonomous planning lane while preserving Soundwave as the default interview-first workflow.
…#817) * fix(deps): patch critical Next.js and Vitest advisories * fix(deps): resolve blocking Python security advisories
* docs: release v1.1.44 * docs(release): clarify onboarding telemetry default * docs(release): distinguish provider and workload controls * docs(release): include targeted JavaScript security updates * docs(release): note canonical distribution paths * docs(release): clarify version selection before publication
…ssage-event-times-20260924 feat(streaming): persist sub-agent event times
…-1.1.45-20260924 docs: prepare Decepticon v1.1.45 release
…terSecurity#823) * fix(roe): honor signed root URL targets in web fetch * fix(roe): compile URL scopes into sandbox network policy * fix(roe): enforce denied hosts in sandbox egress * fix(roe): fail closed for unresolved hostname exclusions * fix(roe): retain target egress when metadata alias is absent * fix(roe): cover default metadata aliases in egress
…rSecurity#816) Co-authored-by: Minseok CHOI <31537001+PurpleCHOIms@users.noreply.github.com>
…#825) * fix: cap Soundwave interview at 8 questions (was ~18) roe-template drove 10 separate ask_user_question calls and conops-template another 8 (including one for the DEPRECATED communication_plan field), so a fresh engagement paid for every dimension one field at a time before any planning document existed. - Add a hard 8-question interview budget (CRITICAL_RULES BitterSecurity#12 in soundwave.md): only Scope and Success criteria are always asked; everything else defaults from schema/RoE/CONOPS content unless the operator's answers raise a flag a default cannot cover. - roe-template: merge related fields into 6 combined questions (was 10) instead of one ask_user_question per field. - conops-template: ask only threat-actor tier + success criteria (2, was 8); derive motivation/initial access from tier, drop the deprecated communication_plan question, agent-draft the narrative, default deconfliction method. - Fold assumption-challenge follow-ups into the original picker's options instead of spawning a second question round. Fixes BitterSecurity#824 * chore: regenerate skills.cypher for roe/conops-template edits --------- Co-authored-by: NetVar1337 <netvar1337@users.noreply.github.com>
…-1.1.47-20260926 docs: prepare Decepticon v1.1.47 release
Merge (not rebase) of upstream PurpleAILAB/Decepticon into the fork, keeping the fork's own 13 commits and history. Merge-base was 258bb30 (2026-08-12); 26 upstream commits pulled. Conflict resolutions (fork's changes kept unless upstream superseded): - CHANGELOG.md: kept the fork's [Unreleased] section on top, appended upstream's [1.1.47]/[1.1.45]/[1.1.44] release entries above the shared [1.1.40] tail. Added a fork note recording this merge. Auto-merged, verified fork intent survived: - docker-compose.yml: fork's `langgraph dev --no-reload` command kept; took upstream's image org rename (purpleailab -> bittersecurity), which is inert here since the box builds fork images and never pulls (AUTO_UPDATE=false). - .env.example: fork's telemetry-off (DECEPTICON_TELEMETRY=off, DO_NOT_TRACK=1) kept; upstream added no telemetry endpoint. - llm.py / factory.py: fork's OpenCode Go provider and glm-5.3 pin intact. - docs/setup-guide.md: clean. - uv.lock: taken from upstream (fork never modified it); valid TOML.
|
|
||
|
|
||
| if is_bundle_enabled("standard"): | ||
| graph = create_autohunt_agent() |
| ) | ||
| ) | ||
|
|
||
| def resolver(hosts): |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Merge (not rebase) of upstream
PurpleAILAB/Decepticoninto the fork, keeping the fork's own 13 commits and history. Merge-base was258bb30c(2026-08-12); 26 upstream commits pulled. A pure fast-forward is not possible (the fork has 13 commits upstream lacks), so this is a merge commit for review, not an auto-merge.Upstream changes by area (commit subjects)
Runtime / agents / capabilities
Security / Rules of Engagement
Release / packaging / deps / CI
Launcher (Go client)
Skills / docs / benchmark
Plus five upstream merge commits from the BitterSecurity release branches.
Areas that touch Job B (langgraph runtime/infra), flagged for the stacked fix PR:
containers/langgraph.Dockerfile: addsPYTHONDONTWRITEBYTECODE=1.docker-compose.yml: renames the langgraph/web image orgpurpleailab->bittersecurity(inert here; the box builds fork images and never pulls,AUTO_UPDATE=false).langgraph.json: adds theautohuntgraph.Conflict resolution
Only one real conflict:
CHANGELOG.md(both sides added entries at the top). Kept the fork's[Unreleased] - Umbrella/Exploitacious forksection on top, appended upstream's[1.1.47]/[1.1.45]/[1.1.44]entries above the shared[1.1.40]tail, and added a fork note recording the merge.Auto-merged, verified the fork's intent survived:
docker-compose.yml: fork'slanggraph dev --no-reloadkept; took upstream's image org rename..env.example: fork's telemetry-off (DECEPTICON_TELEMETRY=off,DO_NOT_TRACK=1) kept; upstream added no telemetry endpoint.llm.py/factory.py: fork's OpenCode Go provider andglm-5.3pin intact.docs/setup-guide.md: clean.uv.lock: taken from upstream (fork never modified it); valid TOML.Checks (this box)
uv run pytest -n auto -q -m "not slow": 5177 passed, 44 skipped (skips are Neo4j-unreachable integration + Windows-only).uv run ruff check .: All checks passed.ruff format --check: 712 files already formatted.make quality-cli: CLI typecheck/build + 31 tests passed.make web-lint && make web-build: compiled successfully.Not a fast-forward (histories diverged), but this merge is clean and green. Do not merge without maintainer review.