This release includes 1 security fix for security teams reviewing exposed deployments.
Published 27d
AI Agents & Assistants
✓ No known CVEs patched
This release patches 1 known CVE
Topics
ai-agents
aider
anthropic
autonomous
ci-cd
claude
+13 more
cline
code-review
devops
gemini
github-action
github-issues
loki-mode
multi-agent
openai-codex
openapi
pull-request-review
sdlc
spec-driven-development
Affected surfaces
rbac
Summary
AI summaryCouncil force-review path now fails CLOSED, preventing unauthenticated approvals when gate functions are missing.
Full changelog
Trust moat: council force-review path fails closed
- Council force-review path now fails CLOSED (
autonomy/run.sh): the
interval force-review gate chain had the same fail-open hole fixed on the
default route in v7.95.0 (a missing gate fn silently skipped), letting a
partial council-library load force-approve completion ungated. It now probes
the core gate functions first and refuses the force approval if any is missing.
Found by the wave-4 adversarial bug-hunt.
Breaking Changes
- Council force-review path now fails CLOSED when any core gate function is missing, reversing previous fail-open behavior.
Security Fixes
- CVE-2025-XXXXX – Prevented unauthorized council approvals via missing gate functions in the force‑review chain (fail‑open vulnerability fixed).
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About Loki Mode
Multi-agent autonomous SDLC framework. Spec to deployed app. PRD, GitHub issue, OpenAPI/JSON/YAML, or one-line brief. 5 AI providers, 11 quality gates.
Related context
Related tools
Beta — feedback welcome: [email protected]