Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 2 additions & 2 deletions .github/workflows/release.yml
Original file line number Diff line number Diff line change
Expand Up @@ -55,10 +55,10 @@ jobs:
test -n "$VERSION"
bash check-version.sh "$VERSION"

- name: Check public API compatibility with v5.3.4
- name: Check public API compatibility with v5.3.5
run: |
cargo install cargo-semver-checks --version 0.48.0 --locked
bash scripts/check_semver.sh 5.3.4
bash scripts/check_semver.sh 5.3.5

- name: Check SDK protocol and API alignment
run: |
Expand Down
29 changes: 29 additions & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -7,6 +7,35 @@ and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0

## [Unreleased]

## [5.3.6] - 2026-07-19

### Added

- Expanded TypeScript code-intelligence discovery for nested monorepos,
hoisted and Yarn SDKs, classic `tsserver`, and the TypeScript 7 native LSP.
- Added bounded PDF text extraction to `web_fetch`, including media/signature
detection, normalized metadata, malformed-document errors, and image-only
document handling.
- Added an invariant-checked session snapshot fork operation that rebinds the
session, workspace, run ownership, and subagent parent ownership while
preserving the complete persisted generation.
- Preserved standard MCP tool metadata and call results end to end, including
output schemas, annotations, icons, `_meta`, `structuredContent`, decoded
images, embedded resources, and bounded content-addressed artifacts.

### Fixed

- Kept standalone conversational greetings tool-free and prevented them from
triggering synthetic continuation turns, while retaining the normal tool
surface for greetings that also contain an action request.

### Security

- Made MCP confirmation annotations escalation-only: tool metadata can require
HITL but cannot weaken a host Allow/Ask/Deny decision.
- Allowed an explicitly scoped delegated worker to see a parent-hidden tool
while keeping both parent and worker execution policies authoritative.

## [5.3.5] - 2026-07-17

### Added
Expand Down
Loading
Loading