fix(release): close the 0.19.0 scan findings — sandbox mongo tag, flow-verb timeout walls, video hardening (#329)

- mongo:8-alpine → mongo:8 (tag never existed; a mongo-opted project could spawn no agents) + a Docker Hub tag-existence e2e guard for every sandbox engine
- flow-verb timeouts at both walls: shared SLOW_VERBS policy (i_am_done / submit_up / submit_root / open_pr / i_will_work_on get the 900s server budget); the MCP client now outlasts the server budget (+10s headroom, orchestrator-injected env) so agents receive the middleware's clean 504 envelope instead of dying at the old flat 30s client timeout
- cancellation safety: the quality gate kills+reaps its child on CancelledError; create_pr records the PR via a shield-with-wait-out helper so the write can neither be skipped nor race get_db's rollback
- video engine: renderer sidecar isolated on a render-only network, 2g/2cpu caps, 570s render watchdog with exit-on-hang, 512MB tar decompression cap, CEO notification on terminal render failure, reject under the approve mutex (fail-closed on Redis-down)
- dead python-jose dependency removed (drops ecdsa and its unfixable Minerva advisory PYSEC-2026-1325); panel --font-mono now a real monospace stack

Co-authored-by: Renn F <rennf93@users.noreply.github.com>
This commit is contained in:
Renzo F
2026-07-08 03:26:12 +02:00
committed by GitHub
co-authored by Renn F
parent 2a9d9e25d9
commit 0bf0cd69b3
36 changed files with 865 additions and 55 deletions
+6 -1
View File
@@ -52,13 +52,18 @@ def test_commit_posts_message_and_files(do_module: Any) -> None:
fake_response.json.return_value = {"status": "in_progress", "task_id": "x"}
fake_client.post.return_value = fake_response
with patch("httpx.Client", return_value=fake_client):
with patch("httpx.Client", return_value=fake_client) as client_cls:
result = do_module.commit("feat(api): add /healthz", files=["foo.py"])
assert result["status"] == "in_progress"
args, kwargs = fake_client.post.call_args
assert "/api/v1/do/commit" in args[0]
assert kwargs["json"] == {"message": "feat(api): add /healthz", "files": ["foo.py"]}
# commit stages+commits a large changeset server-side (up to
# git_commit_timeout_seconds, default 180s) — the shared _TIMEOUT (30s)
# is tuned for fast content-tool calls and would give up first.
assert client_cls.call_args.kwargs["timeout"] == do_module._COMMIT_TIMEOUT
assert do_module._COMMIT_TIMEOUT > do_module._TIMEOUT
def test_note_default_scope_note(do_module: Any) -> None: