Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
81 changes: 81 additions & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
@@ -1,5 +1,86 @@
# Changelog

## [1.6.0](https://github.com/cloudflare/vibesdk/compare/v1.5.0...v1.6.0) (2026-07-14)


### Features

* add bonk ai code reviews ([189dc48](https://github.com/cloudflare/vibesdk/commit/189dc4837166b3a6887a2d400eb76f0641cc36a0))
* add bonk ai code reviews ([e16961b](https://github.com/cloudflare/vibesdk/commit/e16961b8ab367634471d75da0c5630c8abaf9046))
* add ENABLE_EMAIL_AUTH flag and surface oauth conflict error ([fd052ac](https://github.com/cloudflare/vibesdk/commit/fd052ac92ef7dfac87316d62d834a62a5e3e4798))
* add Login with Cloudflare and per-user AI Gateway toggle (VIBE-22) ([0ebf48d](https://github.com/cloudflare/vibesdk/commit/0ebf48da439502090cc44a307fa7ef08d3de965d))
* cloudflare oauth connect with usage limits and BYOK inference ([6fc180c](https://github.com/cloudflare/vibesdk/commit/6fc180cd1ee68f19f64aa99410468874d09132cd))
* faster blueprint for minimal templates ([1321e43](https://github.com/cloudflare/vibesdk/commit/1321e43cdfecfef9bf47a09006c4408ffab1d8dd))
* Login with Cloudflare + Security Fixes ([a72acdd](https://github.com/cloudflare/vibesdk/commit/a72acdd64b66c3ad9ad8cde2c9d83ddf289d4ab6))
* reduce limits ([9f810e7](https://github.com/cloudflare/vibesdk/commit/9f810e7dbc90039a0fa639bc676e1197066bef51))
* reduce limits ([8299ba5](https://github.com/cloudflare/vibesdk/commit/8299ba554b6eee4920c0c7f5adaf0e677ebcaf3c))
* reduce side of blueprint infer for minimal templates ([3eb0039](https://github.com/cloudflare/vibesdk/commit/3eb0039e57bd398afd7b3ea0616f0a532e292a61))
* **security:** enforce app visibility at the dispatch layer ([124720e](https://github.com/cloudflare/vibesdk/commit/124720ee09f0339c5e4018acf08dc83235121219))
* **security:** rate-limit space previews and cache the asset manifest ([b92ecae](https://github.com/cloudflare/vibesdk/commit/b92ecaefdeaab877408ad10c8b9de4de61907904))
* **security:** revoke space-preview tokens on visibility change ([d74e17a](https://github.com/cloudflare/vibesdk/commit/d74e17a17602a048e362d6dcdd062aadb04d825c))
* **settings:** add connected accounts UI for multi-provider linking ([d446c19](https://github.com/cloudflare/vibesdk/commit/d446c19997a5199b8eec9d8c19d364b26ef2abd6))
* short project titles with live refresh + Think set_title tool ([d3b04f1](https://github.com/cloudflare/vibesdk/commit/d3b04f1cc6d90c76bfc64cbc0965a908c4aac757))
* static analysis for browser rendered preview projects ([22be3f8](https://github.com/cloudflare/vibesdk/commit/22be3f8e74b1897254031dbffa0411893d7a5446))
* static analysis for browser rendered preview projects ([320fc84](https://github.com/cloudflare/vibesdk/commit/320fc84454073e2a720deb6dca6deffa8e9060a3))
* think-based agent + code space ([16670af](https://github.com/cloudflare/vibesdk/commit/16670affa66cae38520e47322399d06ee08d7fcc))


### Bug Fixes

* add cf limits gate ([da3386e](https://github.com/cloudflare/vibesdk/commit/da3386e2e54f11dd54392cc49f4bdac7b2a61ef0))
* add missing lock changes ([b567804](https://github.com/cloudflare/vibesdk/commit/b5678042b61af353a1777695baaaf68f60134ac7))
* **agents:** prevent RCE via bootstrap command whitelist bypass ([ae792a2](https://github.com/cloudflare/vibesdk/commit/ae792a2bb48282714c47464c15ca67942f2eab31))
* **agents:** prevent RCE via bootstrap command whitelist bypass ([5dca3ab](https://github.com/cloudflare/vibesdk/commit/5dca3ab4bec4496c645e7663326705a9df1ec661))
* ai gateway config issue ([01de759](https://github.com/cloudflare/vibesdk/commit/01de759cedaf09f5beb88a80fd8cdfb9dfb7fcfe))
* allow editing package.json in scratch templates ([ee69533](https://github.com/cloudflare/vibesdk/commit/ee6953386fed3490ddcdc407c4bb26ce248d2506))
* **apps:** harden public app endpoints against disclosure, DoS, view tampering ([1023f68](https://github.com/cloudflare/vibesdk/commit/1023f68ab816f04ea55e81f299b8300a9426b647))
* **apps:** harden public app endpoints against disclosure, DoS, view tampering ([3600f72](https://github.com/cloudflare/vibesdk/commit/3600f7234202a1c15f53e0c657cce7fa155c1de3))
* **auth:** close OAuth account-takeover via email-based identity binding ([2303dcf](https://github.com/cloudflare/vibesdk/commit/2303dcfe6f6d6c93e299dbc5e6d3d49ce8d6d53b))
* **auth:** enforce ALLOWED_EMAIL allowlist on OAuth callback ([a39e4e4](https://github.com/cloudflare/vibesdk/commit/a39e4e42b69765856b873672c3adbfe2bf499f70))
* **auth:** harden session/API-key revocation and secret generation ([54fc4e0](https://github.com/cloudflare/vibesdk/commit/54fc4e0bd2803666e7a4e6096632dd9785687329))
* **auth:** harden session/API-key revocation and secret generation ([7c4e0bf](https://github.com/cloudflare/vibesdk/commit/7c4e0bf8d13fac11687d656f6b2fb4633d53735d))
* bonk model name ([57d83c0](https://github.com/cloudflare/vibesdk/commit/57d83c0ce4750adb38958901b27cf896afa99da5))
* bug where preview url did not use tunnel url ([61291d0](https://github.com/cloudflare/vibesdk/commit/61291d0cb3843e398b19ab10ff682efbc1115210))
* bug where preview url did not use tunnel url when getting instance state ([d2abffe](https://github.com/cloudflare/vibesdk/commit/d2abffed7c74e06fe7dead693f80a5c7e9684a8a))
* cf oauth client ci ([3842b66](https://github.com/cloudflare/vibesdk/commit/3842b66e573c246079e73123886094ab59dfa6e7))
* **ci:** use canonical gemini-3-pro-preview slug ([9d22900](https://github.com/cloudflare/vibesdk/commit/9d22900628be6efa632bd322ed13529ef140cf45))
* **ci:** use canonical gemini-3-pro-preview slug ([63e78b1](https://github.com/cloudflare/vibesdk/commit/63e78b1476787b088158d2cd02a9662d859d6785))
* **ci:** use gemini in bonk ai-pr-review workflow and fix vuln ([17f56d6](https://github.com/cloudflare/vibesdk/commit/17f56d61f5addfc9b2aa95b608e35033e671e88d))
* **ci:** use gemini in bonk ai-pr-review workflow and fix vuln ([277dbad](https://github.com/cloudflare/vibesdk/commit/277dbad88e3cc40570d41c260e7f1f9a2e5f61b0))
* fixed github bot's commit mistakes ([a729366](https://github.com/cloudflare/vibesdk/commit/a72936654aa13113e4a73d8902bded052566f0cd))
* improve browser rendering checking logic ([fa397bb](https://github.com/cloudflare/vibesdk/commit/fa397bb0b44aab332139ce99791bf5816dcec3c7))
* manual template selection ([e440372](https://github.com/cloudflare/vibesdk/commit/e440372760d69e6f587bfcb94d93c7bece39a6b6))
* more visibility for containers and workers ([a632039](https://github.com/cloudflare/vibesdk/commit/a632039d2b65a48a2448a5f99744b2f971c66174))
* opencode version issue ([7842ab9](https://github.com/cloudflare/vibesdk/commit/7842ab91fb259753083f37e4571ed6c3b3f8d8fd))
* pass manually selected template and skip ai flow ([ad7ae4e](https://github.com/cloudflare/vibesdk/commit/ad7ae4ec992ec85e17d073a15d63b28ba2462671))
* prevent platform API key leak via user-supplied AI gateway baseUrl ([854676e](https://github.com/cloudflare/vibesdk/commit/854676ebf99642a7afa4055fd982815edc5508c8))
* prevent platform API key leak via user-supplied AI gateway baseUrl ([d8a2526](https://github.com/cloudflare/vibesdk/commit/d8a2526e73f8e46e6c83271ce5e46730cb41f192))
* **preview:** add CORS headers to space preview responses ([d4ab976](https://github.com/cloudflare/vibesdk/commit/d4ab976f97c3424fd5b3aa3175abfe7937e9e381))
* **preview:** token+cookie auth for space previews and Safari banner ([402ab7c](https://github.com/cloudflare/vibesdk/commit/402ab7ca2b2365774027666250eadf95fead3139))
* **preview:** token+cookie auth for space previews and Safari banner ([cf88d69](https://github.com/cloudflare/vibesdk/commit/cf88d691c5451b8e191c898154ae4758e13058d8))
* race condition between instance start and static analysis ([befdde7](https://github.com/cloudflare/vibesdk/commit/befdde72fb8d6defd61184dbe47d8054232ce616))
* refresh Cloudflare AI Gateway list without reconnecting ([074924d](https://github.com/cloudflare/vibesdk/commit/074924db6ae82ad3ee9bc7108c504afc8c072481)), closes [#398](https://github.com/cloudflare/vibesdk/issues/398)
* refresh Cloudflare AI Gateway list without reconnecting ([#398](https://github.com/cloudflare/vibesdk/issues/398)) ([04811ed](https://github.com/cloudflare/vibesdk/commit/04811ed39852b0b6f6822cf85cb88fb81aba2d70))
* remove opencode ref ([e358598](https://github.com/cloudflare/vibesdk/commit/e3585982d3eb5bdc4381dbcc586990435834bcc1))
* resolve require("buffer") deploy error 10021 in Workers bundle ([f14b40c](https://github.com/cloudflare/vibesdk/commit/f14b40c26c9d1d183517d06519e325ff3c22c5a6))
* **security:** block prompt-injection data exfiltration via chat ([f6c475f](https://github.com/cloudflare/vibesdk/commit/f6c475f26ab36fcb498f5864589b6fcf221db718))
* **security:** block prompt-injection data exfiltration via chat ([b6ab895](https://github.com/cloudflare/vibesdk/commit/b6ab895e36e88885aec656cbb641c1f587d61bc2))
* **security:** harden bootstrap command validation against postinstall RCE ([31bfc6f](https://github.com/cloudflare/vibesdk/commit/31bfc6fc5ca4721f8bd4079d2ef2146c4959d362))
* **security:** verify per-port token before sandbox preview access ([34e3bb4](https://github.com/cloudflare/vibesdk/commit/34e3bb4ca5e926aaf0c2c2dabdf5435d23741d19))
* **space:** strip Service-Worker-Allowed from preview responses ([918e974](https://github.com/cloudflare/vibesdk/commit/918e97480ee44e357abe99bf33c27259d6ac7ebd))
* **space:** strip Service-Worker-Allowed from preview responses ([22f1900](https://github.com/cloudflare/vibesdk/commit/22f19000b5e06023001ba9741cc173f14e5f0530))
* styling housekeeping, minor UI improvements ([5821919](https://github.com/cloudflare/vibesdk/commit/5821919bb5cb92603938cf1ac35f581da95dfc85))
* styling housekeeping, minor UI improvements ([c5cd2f1](https://github.com/cloudflare/vibesdk/commit/c5cd2f185db45d9a2c5b807f19df31a3107bed2c))
* truncate long project title in Agent-mode preview header ([#394](https://github.com/cloudflare/vibesdk/issues/394)) ([4051aad](https://github.com/cloudflare/vibesdk/commit/4051aadd31ed26c7688d613f07e6b93ae4ed77ee))
* truncate long project title in preview header ([fb67d6c](https://github.com/cloudflare/vibesdk/commit/fb67d6c5baaac564654a9d8a173cb108f603802c)), closes [#394](https://github.com/cloudflare/vibesdk/issues/394)
* **udiff:** insert diff replacement content literally ([ea1c7be](https://github.com/cloudflare/vibesdk/commit/ea1c7be336521b3537c029650ad7710f18535e75))
* **udiff:** insert diff replacement content literally (avoid $-substitution) ([6fdd77e](https://github.com/cloudflare/vibesdk/commit/6fdd77e9c6a92dd275946c46177ddc36cb70ffb5))
* ui and logging imp for cf oauth ([fd8f281](https://github.com/cloudflare/vibesdk/commit/fd8f2814609b387cd8ad6156b52f1790619ffba9))
* ui and logging imp for cf oauth ([86ebbdb](https://github.com/cloudflare/vibesdk/commit/86ebbdb358bed0ad7a6a90cf2cb1005523623f0d))
* unintended change leading to bad behaviour ([7a586cc](https://github.com/cloudflare/vibesdk/commit/7a586cc41023546cace89df31a84fd00bddc427b))
* wire cf oauth encryption key and per-env jwt/oauth secrets in ci ([d0256b0](https://github.com/cloudflare/vibesdk/commit/d0256b0f047cf0514c7274e2e64dd8963525ef29))
* wrangle rupdate ([9666d98](https://github.com/cloudflare/vibesdk/commit/9666d98518b2292b0aa58e1aee18ac1a95cbb2e9))

## [1.5.0](https://github.com/cloudflare/vibesdk/compare/v1.4.0...v1.5.0) (2026-02-03)


Expand Down
2 changes: 1 addition & 1 deletion package.json
Original file line number Diff line number Diff line change
@@ -1,7 +1,7 @@
{
"name": "vibesdk",
"private": true,
"version": "1.5.0",
"version": "1.6.0",
"type": "module",
"workspaces": [
"space"
Expand Down