fix(optics): P1 security slice, including api_base lockdown - #145
Merged
Merged
Conversation
Refuse a symlinked installer stage, require effective root for live mutations, pin the observe image to CLI 0.3.24 and wrap node, and read the gate-mcp API key from the environment. @vantio/gate-mcp 0.1.1 is a source candidate only.
The API-key environment tests ship in this pull request. CI has to run them before the slice can be called green. Source candidate only.
gate_get_policy and gate_residual_risk no longer take api_base. The key goes to VANTIO_API_BASE, or https://api.vantio.ai when that variable is unset or blank. A tool argument cannot choose the host. Source candidate only. Not published.
The security slice bumps @vantio/gate-mcp to 0.1.1 in source only. Version metadata, the AI guide, and the generated release inventory now match that candidate. Not an npm release.
The documentation release check rebuilds llms-full.txt from the canonical guide. The guide already names gate-mcp 0.1.1 and the host lockdown. This file now matches that rebuild. CANDIDATE_ONLY. Not published.
This was referenced Sep 30, 2026
zacharybalicki
marked this pull request as ready for review
September 30, 2026 22:44
kvantio
approved these changes
Sep 30, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
CANDIDATE_ONLY. No npm publish, no PyPI publish, and no install.vantio.ai go-live.
Kate queue
Order: #142 → #144 → #145 → #146 → #148 (#147 already merged).
Approve exact head only (
kvantio). No admin bypass.Current head:
8b0af9e29f45a6aa230a4b843f6125d729a14c09What this does
lstatandO_NOFOLLOWand leaves the target.@vantio/cli@0.3.24and startsvantio run node.gate_get_policyandgate_residual_riskreadVANTIO_API_KEYfrom the environment. They do not take anapi_keyargument.api_base. The host isVANTIO_API_BASE, orhttps://api.vantio.aiwhen that variable is unset or blank. A caller-supplied host is ignored.@vantio/gate-mcp0.1.1as a candidate. Not an npm release.Not in this pull request
Optics enforcement removal was #147 (merged). Observation fixes are #146. CLI 0.3.25 and Python 3.1.1 candidate notes are #148.
Do not merge until CI is green, independent council is PASS or PASS_WITH_NONBLOCKING_NOTES, and exact-head
kvantioAPPROVE.