open-swe/agent
Adam Moussa 1ba5ccc65d
harden PR guards + sidebar after security review
- Mirror upstream #1786's nested-shell / executable-normalization hardening
  into the fork-only pr_verdict_guard.py (verdict-gating is a real fork
  control), keeping it in parity with pr_creation_guard.py.
- Close the glued short-flag bypass (bash -c'...') in BOTH guards: a shell's
  -c argument can be concatenated into the same argv token, which the
  space-separated -c detection missed. Diverges pr_creation_guard.py from
  upstream #1786 by design; to be upstreamed.
- Gate the new #1799 sidebar active-thread refresh on ownership so a non-owner
  viewing a shared thread reads last-known state without persisting a metadata
  write (mirrors the is_owner gate on the single-thread read path).
- Fix an F821 in the #1799 cherry-pick (Mapping import / concrete dict type).

Guards remain intentionally fail-open per the honest-agent threat model;
docstrings narrowed to name the residual exotic-shell / stdin-fed vectors.
2026-07-24 16:03:30 -04:00
..
api refactor: split webapp.py into api/ + per-source webhook routes 2026-07-17 14:30:05 -04:00
dashboard harden PR guards + sidebar after security review 2026-07-24 16:03:30 -04:00
graphs refactor: adopt graphs/runtime/providers shims + retarget langgraph.json 2026-07-17 13:57:20 -04:00
integrations feat: optional separate LangSmith key/endpoint for sandboxes (#1760) 2026-07-17 16:22:38 -04:00
middleware harden PR guards + sidebar after security review 2026-07-24 16:03:30 -04:00
providers refactor: adopt graphs/runtime/providers shims + retarget langgraph.json 2026-07-17 13:57:20 -04:00
resources refactor: move docs/resources/assets to domain layout 2026-07-17 13:45:39 -04:00
review feat(open-swe): explicit-request reviewer verdicts + shell verdict guard (#214) 2026-07-20 15:28:00 -04:00
runtime refactor: adopt graphs/runtime/providers shims + retarget langgraph.json 2026-07-17 13:57:20 -04:00
skills feat: outcomes dataset + bootstrap/continual split via skills (#1365) 2026-06-01 13:25:12 -07:00
tools chore: clarify shared response image guidance (#1782) 2026-07-24 15:34:26 -04:00
utils feat(open-swe): port upstream clean batch (#1775, #1785, #1789) (#215) 2026-07-20 19:54:16 +00:00
webhooks fix: add exc_info to swallowed exception in push re-review webhook (#1764) 2026-07-24 15:33:38 -04:00
analyzer.py refactor: consolidate reviewer modules into agent/review/ 2026-07-17 13:52:03 -04:00
chat.py fix: defensive copy in get_reviewer_agent and get_chat_agent [closes #1584] (#1742) 2026-07-17 16:22:38 -04:00
ci_autofix.py refactor: split webapp.py into api/ + per-source webhook routes 2026-07-17 14:30:05 -04:00
ci_monitor.py feat: CI auto-fix and PR babysitting for agent PRs (#1530) 2026-06-15 13:53:50 -07:00
completion.py feat: Jira + Confluence integration (tools + triggers) (#182) 2026-07-13 19:45:54 -04:00
dispatch.py feat: port durable dispatch hardening and startup latency improvements (#160) 2026-07-09 17:11:25 -04:00
encryption.py feat: support TOKEN_ENCRYPTION_KEY rotation via MultiFernet [closes AB-2323] (#1275) 2026-05-08 14:29:23 -07:00
prompt.py feat(open-swe): explicit-request reviewer verdicts + shell verdict guard (#214) 2026-07-20 15:28:00 -04:00
reconcile.py refactor: adopt modular webhook architecture (#1621) + port fork customizations (#85) 2026-06-30 18:46:46 -04:00
reviewer.py feat: clean-review auto-approve for unsolicited verdicts [BLOCKED — security] (#217) 2026-07-21 20:18:25 -04:00
scheduler.py refactor: adopt modular webhook architecture (#1621) + port fork customizations (#85) 2026-06-30 18:46:46 -04:00
server.py feat(open-swe): explicit-request reviewer verdicts + shell verdict guard (#214) 2026-07-20 15:28:00 -04:00
webapp.py refactor: split webapp.py into api/ + per-source webhook routes 2026-07-17 14:30:05 -04:00