Skip to content

Loki Mode

v7.74.0 Security

This release includes 2 security fixes for security teams reviewing exposed deployments.

✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 2 known CVEs

Topics

ai-agents aider anthropic autonomous ci-cd claude
+13 more
cline code-review devops gemini github-action github-issues loki-mode multi-agent openai-codex openapi pull-request-review sdlc spec-driven-development

Affected surfaces

auth rbac

Summary

AI summary

Trust‑gate hardening prevents self‑certification overrides, fixes quorum calculation for completion council, and makes project registry updates atomic.

Full changelog

Trust-gate hardening (completion + override + registry)

A deep-hunt wave found and fixed trust-surface defects on the live loki start path.

  • Override council fail-closed: the agent-authored counter-evidence override (the
    stub route reached by loki start) previously lifted a real Critical/High
    code_review BLOCK when the gated agent supplied a trusted proofType plus any
    artifact string. Because the gated agent authors the counter-evidence file
    itself, this was self-certification: a trust gate the gated party can bypass is
    not a gate. The stub route now lifts NOTHING. A code_review BLOCK is cleared only
    by the operator (review and fix, or the human-escape path), or by the real
    multi-judge override council (an adjudicator the agent does not control), which
    is unchanged. Escalation and docs re-framed to stop promising that self-supplied
    counter-evidence lifts a block.
  • Completion-council quorum fix: the live multi-agent vote computed its quorum
    denominator from the number of findings the model returned, not the expected
    council size, so a degraded response with a single APPROVE could declare a run
    COMPLETE and silently skip the anti-sycophancy devil's-advocate. The quorum is
    now computed against the expected council size with an exact-quorum assertion;
    a partial or malformed response fails closed (never COMPLETE).
  • Project registry corruption fix: loki projects add|remove|sync now go through
    the locked, atomic registry API (matching the v7.45.1 hardening) instead of an
    unlocked truncating write that could lose updates or expose a partial file to a
    concurrent reader.
  • Smaller fixes in the CLI: honest errors instead of silent set -e aborts when a
    value flag is the last argument (loki docker --image, loki watch --interval
    / --debounce), and loki context add no longer crashes on filenames with an
    apostrophe.

Security Fixes

  • Trust‑gate override council now rejects self‑authored counter‑evidence; only operator or multi‑judge council can clear a code_review BLOCK
  • Completion council quorum computed against expected council size, preventing premature COMPLETE status with partial responses

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track Loki Mode

Get notified when new releases ship.

Sign up free

About Loki Mode

Multi-agent autonomous SDLC framework. Spec to deployed app. PRD, GitHub issue, OpenAPI/JSON/YAML, or one-line brief. 5 AI providers, 11 quality gates.

All releases →

Related context

Beta — feedback welcome: [email protected]