| 文件 | 最后提交记录 | 最后更新时间 |
|---|---|---|
docs(backend): move calendar-capture rules to docs/agents/calendar-capture The Service Map bullet for the SCA-381 calendar-capture contract pushed backend/AGENTS.md past the agents-md-lean budget; keep the one-line contract there and move the full discard-override / auto-link gating / capture-gap rules to docs/agents/calendar-capture.md. | 2 天前 | |
ci(public-build): env-var removal, per-environment flags, real invoker identity checks (#12582) * ci(public-build): env-var removal, per-environment flags, real invoker identity checks Plaintext Cloud Run env vars survived merge deploys, restricted ingress was applied to development, and TBD placeholders passed presence checks into gcloud. Co-authored-by: Cursor <cursoragent@cursor.com> * ci(public-build): probe actAs via IAM testIamPermissions REST gcloud has no iam service-accounts test-iam-permissions subcommand, so the previous preflight would fail every prod deploy. Call the IAM REST method with urllib and a print-access-token bearer instead. * ci(public-build): reject remove_runtime_env_vars overlapping preserved secrets Cubic review (PRRT_kwDOLkKqys6eWSS0): a runtime name in both preserve_runtime_secrets and remove_runtime_env_vars loaded cleanly, yet deployment emits --remove-env-vars for a binding the contract claims to preserve via the merge update strategies — the removal would strip the preserved secret binding. Extend the dedicated overlap rejection to preserve_runtime_secrets and its mirrored fallback_runtime_secrets, with a regression test. --------- Co-authored-by: Cursor <cursoragent@cursor.com> Co-authored-by: David Zhang <9387252+Git-on-my-level@users.noreply.github.com> | 11 小时前 | |
SCA-212: align dev public build gateway contract Co-authored-by: multica-agent <github@multica.ai> | 1 个月前 |
| 文件 | 最后提交记录 | 最后更新时间 |
|---|---|---|
| 2 天前 | ||
| 11 小时前 | ||
| 1 个月前 |