- Add 'okf restore' command to reinstall vendor bundles from okf.lock
- Allow 'okf pull' without arguments to restore from okf.lock
- Skip already installed bundles during restore unless --force is specified
- Harden 'okf vendor remove' to require exact bundle ID match and index.md
- Prevent deletion of parent namespace directories on prefix remove
- Automatically clean up empty okf.lock when last vendor bundle is uninstalled
- Mitigate G110 (decompression bomb) and G304 (path traversal) in package unpacker
- Fix errcheck and staticcheck lint warnings across CLI and test suites
- Resolve index links via b.ResolveLink instead of naive substring matching
- Support bundle-absolute, dot-relative, and anchored links in parent indexes
- Add regression test for parent index link resolution variants
- Credit Alvise (@alvistar) for issue #41 report in CONTRIBUTORS.md
- Record fix in knowledge/log.md
- Cap MCP tag length to 50 characters in tools.json schemas and handler
- Replace repeated fsPassed FlagSet visits with local passed map in cmdUpdate
- Add upfront non-empty type validation to cmdCreate
- Link requirements/mutation-metadata in root knowledge/index.md
- Document update flags and MCP tag length limit in docs/guides/CLI.md
- Credit Rogelio (@rogeliodh) for issue #38 report and analysis in CONTRIBUTORS.md
- Record knowledge updates in knowledge/log.md
- Move MCP server implementation and tool schemas from cmd/okf into pkg/okf
- Move hub vault operations and lifecycle management from cmd/okf into pkg/sync
- Implement generic frontmatter --filter AST evaluation in pkg/okf/filter.go
- Implement --stale-within temporal horizon staleness engine in pkg/okf
- Introduce okf.SaveOptions and HubOp structures for clean API ergonomics
In non-strict mode, all printed diagnostic lines (warnings, gate findings,
broken links, orphans) are prefixed with 'warn ' and reconciled 1:1 into
the headline warning(s) counter.
In strict mode (--strict), gate-failing findings are prefixed with 'gate '
and tracked under a dedicated 'gate finding(s)' summary counter, cleanly
separating them from non-gating advisory 'warn ' lines and 'error ' spec
violations.
Resolves#35
Reported-by: mattgdrums-cloud <mattgdrums-cloud@users.noreply.github.com>
* Introduced IsAbsPath helper to securely detect cross-platform absolute paths
* Patched resolveInBundle to explicitly reject absolute paths early before
they can be evaluated by path.Clean and Join as relative on POSIX systems
* Patched validate method and others to also use IsAbsPath
* Verified with rigorous testing of absolute paths evasion in mutation flow
Co-authored-by: sknr <11868275+sknr@users.noreply.github.com>
Replaces `filepath.ToSlash` with explicit `strings.ReplaceAll(path, "\\", "/")` when normalizing incoming path inputs and concept IDs. `filepath.ToSlash` is a no-op on POSIX operating systems, which allowed an attacker to bypass directory boundary confinement (CWE-22) using Windows-style backslashes (e.g. `..\..\etc\passwd`). This ensures cross-platform defensive behavior regardless of the host OS executing the agent. Includes negative security test cases.
Co-authored-by: sknr <11868275+sknr@users.noreply.github.com>
- Wrap Engine.Sync reconcile and commit phases in a retry loop (DefaultMaxSyncRetries = 5) with exponential backoff and jitter on concurrent 409 head conflicts
- Implement MergeLogContent to automatically union divergent entries in log.md by ISO date heading while preserving ordering and deduplicating
- Prevent spurious collision forking for log.md during parallel agent sync cycles
- Sanitize projectName against newline header injection in GenerateAgentsMarkdown
- Add filepath.Clean and gosec annotation for LintFile path reading
- Add unit tests verifying injection resistance and symlink directory validation
- Fix Makefile lint target so golangci-lint failure exit code is not swallowed
- Address errcheck in defer os.RemoveAll across test suites
- Replace deprecated filepath.HasPrefix with strings.Contains
- Fix staticcheck QF1012 string formatting in pkg/okf/domains.go
- Remove unused variables in pkg/okf/aag/linter.go