Jonathan Singer
a0f17c3a65
Run Claude on OpenCode's Anthropic endpoint, and name the plan in the UI
...
Claude models are served on /messages, which the OpenAI SDK can't speak, so
those runs go through LiteLLM's Anthropic route instead. Prompt caching moves
with them, since LiteLLM consumes the injection points the raw SDK rejects.
Zen and Go now show up by name instead of both reading 'OpenCode
subscription', and Zen keeps its cost tracked: it bills prepaid credits per
request, so those runs were never actually free.
2026-08-25 01:59:30 -04:00
yoni
52fefd2e2a
Rebuild viewer static assets after rebase
2026-08-24 18:29:19 +00:00
yoni
5a7e5ea255
Fix OpenCode routes: drop LiteLLM-only prompt-cache arg, persist subscription provider for viewer label
2026-08-24 18:26:55 +00:00
yoni
7513cea23a
Add OpenCode (Zen/Go) subscription support: strix auth login opencode + opencode/<model> routing
2026-08-24 18:26:50 +00:00
yoni-at-strix
f4ef8867f6
Add MCP server support ( #1137 )
...
* add a generic MCP client and a config for connecting MCP servers
* Add MCP docs and CLI polish: docs page, startup connect summary, --mcp-config flag, compact tool output
* Add MCP connection notes and per-run selection; clean up on cancel and dedupe names
* Show errored MCP tool calls as failed in the TUI
* Sanitize namespaced tool names so model APIs accept them
* Show MCP tool calls distinctly in the terminal and the run viewer
* Say what MCP servers are worth connecting for
* Correct the notes docstring to match how notes reach the agent
* keep the mcp tests from reading your shell's STRIX_MCP_* vars
2026-08-24 14:00:16 -04:00
devin-ai-integration[bot] and Ahmed Allam
391d81bea7
feat(agents): evidence discipline, and coverage as a first-class artifact ( #961 )
...
Co-authored-by: Ahmed Allam <ahmed39652003@gmail.com >
2026-08-24 03:34:09 -07:00
devin-ai-integration[bot] and Ahmed Allam
1c499c5b2d
perf: bootstrap Caido concurrently with the scan start ( #1143 )
...
Co-authored-by: Ahmed Allam <ahmed39652003@gmail.com >
2026-08-21 12:09:59 -07:00
devin-ai-integration[bot] and Ahmed Allam
1ce43d1b94
perf: take heavy imports off the startup path and pre-warm them in the background ( #1141 )
...
Co-authored-by: Ahmed Allam <ahmed39652003@gmail.com >
2026-08-20 20:24:08 -07:00
Alex Schapiro
2cc8167814
docs(skills): correct gRPC guidance, a .proto is not a spec target
2026-08-20 19:27:04 -04:00
Alex Schapiro
d6a3ca7e58
docs(skills): document --workspace-file for supporting files
2026-08-20 19:27:04 -04:00
Alex Schapiro
9099710cef
docs(skills): fix nonexistent --mount flag, document real targeting flags, add application-security-testing skill
...
- Remove --mount from two skills: the flag does not exist in the CLI. Local
paths are mounted writable when passed with -t.
- Document --target-list, --scope-mode, --diff-base, and OpenAPI/Postman
targets, so agents stop putting spec URLs in --instruction prose.
- Add the application-security-testing skill as the entry point for
whole-product AppSec requests, routing each asset to the right workflow.
- Drop contractions and Latin abbreviations across the skill prose.
2026-08-20 19:27:04 -04:00
Alex Schapiro
634cb98241
docs(skills): use current OWASP editions (Top 10:2025, API Top 10 2023)
2026-08-20 19:27:04 -04:00
Alex Schapiro
1b36343eea
fix(skills): avoid unquoted colon in api-security-testing description
2026-08-20 19:27:04 -04:00
Alex Schapiro
b5ef93e744
feat(skills): add target-specific security testing skills (web app, API, OWASP Top 10, code review)
2026-08-20 19:27:04 -04:00
RAJVARDHAN PATIL
e152c4c7c0
fix(report): raise RuntimeError on non-object run.json ( fixes #1109 ) ( #1116 )
2026-08-20 13:41:04 -07:00
OpenPay
fe758af4fc
fix(tui): use single space after ordered-list marker ( #1043 )
2026-08-20 13:40:12 -07:00
oyasumi and oyasumi
deb2057e20
fix(tui): preserve cost when state is truncated ( #1086 )
...
Co-authored-by: oyasumi <oyasumi@kantilabs.xyz >
2026-08-20 13:36:01 -07:00
Alex Schapiro
d6f2218756
Drop strict tool schemas on Claude routes
2026-08-20 23:12:23 +03:00
oyasumi
6f88b7d7d5
Require viewer session for run data
2026-08-19 15:25:57 -04:00
oyasumi
8d3693df8c
Expose viewer host option
2026-08-19 15:25:57 -04:00
bearsyankees
9cd81e5c76
Add semantic browser and Electron security skills
2026-08-19 12:05:47 -04:00
bearsyankees
e8272c6a21
Add HTTP differential testing tools
2026-08-19 12:04:43 -04:00
bearsyankees
aa5867f5df
Add ecosystem supply-chain security skills
2026-08-19 12:03:45 -04:00
bearsyankees
7b8f9cb160
Add argument injection security skill
2026-08-19 12:02:45 -04:00
bearsyankees
2d944a9bcc
Add Azure and Entra security skill
2026-08-19 12:01:21 -04:00
alex s
0478a69ab0
feat(skills): cover OWASP LLM Top 10 2026 ( #1115 )
2026-08-18 18:40:27 -04:00
alex s
8ede419dcc
handle resume tokens gracefully ( #1097 )
...
* Fix telemetry deltas for resumed runs
* Fix resumed telemetry duration
2026-08-17 16:55:27 -04:00
Ahmed Allam
a46a60cf6a
feat(reporting): require contextual CVSS and usage evidence on dependency reports
2026-08-17 14:35:21 +03:00
Ahmed Allam
918442dbc8
cli: render contextual CVSS vector, advisory score, and reasoning for dependency findings
2026-08-17 13:03:41 +03:00
Ahmed Allam
e442db9c93
Contextual CVSS as a full 8-metric breakdown, computed like a normal finding
2026-08-17 13:03:41 +03:00
Ahmed Allam
9c0d30a0d0
reporting: require the source-to-sink trace in reachability evidence, not just CVSS reasoning
2026-08-17 13:03:41 +03:00
Ahmed Allam
55e6e66030
reporting: surface contextual CVSS in the markdown report; require reasoning only for surviving metrics
2026-08-17 13:03:41 +03:00
Ahmed Allam
99e2d5d826
reporting: drop per-metric contextual CVSS reasoning, keep the summary
2026-08-17 13:03:41 +03:00
Ahmed Allam
310f310e28
feat(reporting): contextual CVSS environmental metrics on dependency reports
2026-08-17 13:03:41 +03:00
yoni-at-strix
8551339130
feat: place caller-provided files into the sandbox workspace (extra_files, --workspace-file) ( #1085 )
...
* add extra-files plumbing so orchestrators can drop single files into the sandbox workspace
* reject extra-file paths that collide with a local source tree
* add --workspace-file so CLI users can place files in the sandbox workspace
* reject repeated and control-character workspace paths
* revalidate persisted workspace files when resuming a run
* drop the workspace-file size limit
2026-08-14 16:43:08 -04:00
Alex Schapiro
8ca0c4a9b8
Fix LiteLLM cost model resolution
2026-08-12 17:26:00 +03:00
Ahmed Allam
7cc9fa9faa
chore: release v1.5.3
v1.5.3
2026-08-10 21:28:52 +03:00
devin-ai-integration[bot]
174c16fa26
fix(llm): send OpenRouter app attribution on the request itself ( #1045 )
2026-08-10 11:24:02 -07:00
Ahmed Allam
94a2586aaa
fix(container): write the browser profile as root
2026-08-10 10:08:17 +03:00
Ahmed Allam
372e27fa17
chore(container): drop explanatory comment
2026-08-10 09:54:49 +03:00
Ahmed Allam
ad727edd66
fix(container): keep the browser env alive where image ENV is dropped
2026-08-10 09:54:49 +03:00
devin-ai-integration[bot] and Ahmed Allam
7b3c8f9b74
fix(container): reclaim abandoned browser sessions ( #1034 )
...
Co-authored-by: Ahmed Allam <ahmed39652003@gmail.com >
2026-08-09 16:57:51 -07:00
Ahmed Allam
ae07af6159
chore: drop explanatory comment
2026-08-09 15:44:16 +03:00
Ahmed Allam
649a2e2140
fix(llm): omit parallel_tool_calls on tool-less requests
2026-08-09 15:44:16 +03:00
Ahmed Allam
597aae6715
chore: release v1.5.2
v1.5.2
2026-08-09 04:29:34 +03:00
Ahmed Allam
06b158d1fa
fix(runner): settle child agents before closing sessions at wind-down ( #1025 )
2026-08-08 18:17:58 -07:00
Ahmed Allam
c29eb73c7f
fix(tools): coerce an empty-string list/dict argument to an empty container ( #1024 )
2026-08-08 16:58:30 -07:00
Ahmed Allam
72833b8e43
fix(runner): resume after a user interrupt instead of failing ( #1023 )
2026-08-08 16:44:12 -07:00
Ahmed Allam
1117ba6d4a
fix(sessions): open a sqlite connection per operation, not per thread ( #1022 )
2026-08-08 16:20:01 -07:00
Ahmed Allam
53e4658d88
fix(todo): stop a todo plan failing on priority or duplicates ( #1021 )
2026-08-08 15:18:48 -07:00