This release adds 1 notable feature for engineering teams evaluating rollout.
✓ No known CVEs patched in this version
Topics
+6 more
Affected surfaces
Summary
AI summaryPR comment authorization now matches pull request author regardless of GitHub author_association.
Full changelog
What's Changed
- Updated Galley PR comment authorization so
/galleycommands are accepted when the comment author matches the recorded pull request author, regardless of GitHubauthor_association. - Kept PR comment handling fail-closed when
pr.author_loginis missing. - Updated the packaged Claude and Codex Galley plugins to version
0.1.5.
Verification
go test ./...
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About Galley
Local-first runtime for supervised AI coding tasks: isolated git worktrees, supervisor review against acceptance criteria, retry/escalate loops, on-disk run evidence, and PR handoff. Supports Codex CLI and Claude Code. Go, MIT.
Related context
Beta — feedback welcome: [email protected]