Commit

Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API

- Guardrails: per-workspace and per-project network allowlist enforced outside the sandbox, command rules via a managed hook, cost and time caps that halt a run and leave its pull request for a person. Fork checkouts start without the fork's settings, hooks, MCP config, commands or CLAUDE.md. - Run credentials: each sandbox gets least-privilege tokens bound to its run, acting for the person who started it, intersected with their current membership; revoked when the run ends. Enforced in identity, the API/MCP and git. - Audit log: every agent action and every write, with on-behalf-of and refusal rules; workspace page, CSV/JSON export, "What it did" on runs. - Security: push protection for secrets, a history scan, dependency vulnerabilities from OSV opening upgrade issues for g1t-agent, and a Security page per project and workspace. - Context hub: catalog of projects, apps, packages, owners and environments with relations; memory capture with review; backfill; search_context and get_entity for people and agents; run context. - Repository instructions (AGENTS.md, CLAUDE.md, .g1t/review.md) from trusted branches only; @g1t-agent mentions and a label rule. - Mission control and the project overview rebuilt around what moved and what needs you. - Public API bodies, MCP results and webhook payloads are snake_case. - Docs link to the source on g1t, never GitHub; the current sidebar link's mark is a straight line.

syntaqxcommitted Parent53719c3Browse files

No changes

This commit changes no files.