diff --git a/.changeset/wide-flat-new.md b/.changeset/wide-flat-new.md deleted file mode 100644 index 8ad8de8..0000000 --- a/.changeset/wide-flat-new.md +++ /dev/null @@ -1,6 +0,0 @@ ---- -"@prodisco/sandbox-server": patch -"@prodisco/mcp-server": patch ---- - -Prevent environment variable leaks from sandbox execution. Sandbox code now gets a frozen empty process.env instead of the host's real environment variables. Added defense-in-depth output filter that blocks execution if sensitive env var values appear in output. diff --git a/CHANGELOG.md b/CHANGELOG.md index 03b47b4..4b68765 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -1,5 +1,14 @@ # @prodisco/mcp-server +## 0.1.14 + +### Patch Changes + +- [#59](https://github.com/harche/ProDisco/pull/59) [`7e2154a`](https://github.com/harche/ProDisco/commit/7e2154ae72ab0900b829cd42c419d168e7b65a31) Thanks [@harche](https://github.com/harche)! - Prevent environment variable leaks from sandbox execution. Sandbox code now gets a frozen empty process.env instead of the host's real environment variables. Added defense-in-depth output filter that blocks execution if sensitive env var values appear in output. + +- Updated dependencies [[`7e2154a`](https://github.com/harche/ProDisco/commit/7e2154ae72ab0900b829cd42c419d168e7b65a31)]: + - @prodisco/sandbox-server@0.1.6 + ## 0.1.13 ### Patch Changes diff --git a/package.json b/package.json index 48d920e..9284956 100644 --- a/package.json +++ b/package.json @@ -1,6 +1,6 @@ { "name": "@prodisco/mcp-server", - "version": "0.1.13", + "version": "0.1.14", "description": "ProDisco: Kubernetes MCP server with progressive disclosure", "type": "module", "main": "dist/server.js", @@ -59,7 +59,7 @@ "@orama/orama": "^3.1.5", "@prodisco/loki-client": "^0.1.0", "@prodisco/prometheus-client": "^0.1.0", - "@prodisco/sandbox-server": "^0.1.3", + "@prodisco/sandbox-server": "^0.1.6", "@prodisco/search-libs": "^0.1.0", "chokidar": "^5.0.0", "esbuild": "^0.27.1", diff --git a/packages/sandbox-server/CHANGELOG.md b/packages/sandbox-server/CHANGELOG.md index f35052a..aa44bc7 100644 --- a/packages/sandbox-server/CHANGELOG.md +++ b/packages/sandbox-server/CHANGELOG.md @@ -1,5 +1,11 @@ # @prodisco/sandbox-server +## 0.1.6 + +### Patch Changes + +- [#59](https://github.com/harche/ProDisco/pull/59) [`7e2154a`](https://github.com/harche/ProDisco/commit/7e2154ae72ab0900b829cd42c419d168e7b65a31) Thanks [@harche](https://github.com/harche)! - Prevent environment variable leaks from sandbox execution. Sandbox code now gets a frozen empty process.env instead of the host's real environment variables. Added defense-in-depth output filter that blocks execution if sensitive env var values appear in output. + ## 0.1.5 ### Patch Changes diff --git a/packages/sandbox-server/package.json b/packages/sandbox-server/package.json index 5dcad2b..a357cc4 100644 --- a/packages/sandbox-server/package.json +++ b/packages/sandbox-server/package.json @@ -1,6 +1,6 @@ { "name": "@prodisco/sandbox-server", - "version": "0.1.5", + "version": "0.1.6", "description": "gRPC sandbox server for code execution with Kubernetes context", "type": "module", "main": "dist/client/index.js",