mirror of
https://github.com/rennf93/roboco.git
synced 2026-08-03 07:23:24 +02:00
fix(release): close the 0.19.0 scan findings — sandbox mongo tag, flow-verb timeout walls, video hardening (#329)
- mongo:8-alpine → mongo:8 (tag never existed; a mongo-opted project could spawn no agents) + a Docker Hub tag-existence e2e guard for every sandbox engine - flow-verb timeouts at both walls: shared SLOW_VERBS policy (i_am_done / submit_up / submit_root / open_pr / i_will_work_on get the 900s server budget); the MCP client now outlasts the server budget (+10s headroom, orchestrator-injected env) so agents receive the middleware's clean 504 envelope instead of dying at the old flat 30s client timeout - cancellation safety: the quality gate kills+reaps its child on CancelledError; create_pr records the PR via a shield-with-wait-out helper so the write can neither be skipped nor race get_db's rollback - video engine: renderer sidecar isolated on a render-only network, 2g/2cpu caps, 570s render watchdog with exit-on-hang, 512MB tar decompression cap, CEO notification on terminal render failure, reject under the approve mutex (fail-closed on Redis-down) - dead python-jose dependency removed (drops ecdsa and its unfixable Minerva advisory PYSEC-2026-1325); panel --font-mono now a real monospace stack Co-authored-by: Renn F <rennf93@users.noreply.github.com>
This commit is contained in:
+1
-2
@@ -395,7 +395,7 @@ DEP002 = [
|
||||
"python-multipart",
|
||||
# Database migrations (CLI tool)
|
||||
"alembic",
|
||||
# Auth libraries (used via passlib[bcrypt]; JWT via PyJWT + fastapi_users.jwt)
|
||||
# Auth libraries (used via passlib[bcrypt])
|
||||
"passlib",
|
||||
# LLM utilities (embeddings/token counting)
|
||||
"openai",
|
||||
@@ -423,7 +423,6 @@ DEP002 = [
|
||||
"rich",
|
||||
# Type stubs (used by mypy)
|
||||
"types-passlib",
|
||||
"types-python-jose",
|
||||
"types-PyYAML",
|
||||
]
|
||||
# DEP003: Starlette is a transitive dep of FastAPI, but BaseHTTPMiddleware is needed
|
||||
|
||||
Reference in New Issue
Block a user