Zum Hauptinhalt springen
Sicherheitslücken (CVE)CVE-2026-3199 | Sonatype Nexus Repository up to 3.90.x deserialization(18.09.2026 um 20:48 Uhr)
Sicherheitslücken (CVE)CVE-2026-3199 | Sonatype Nexus Repository up to 3.90.x deserialization(18.09.2026 um 20:48 Uhr)
Intelligence View
⚡ tsecurity.de Intelligence

GitHub Release: can1357/oh-my-pi v17.3.7 (18.08.2026)

can1357/oh-my-piv17.3.718.08.2026@github-actions[bot]

@oh-my-pi/pi-ai

Changed

  • Send the omp/<version> User-Agent on xAI chat (xai and xai-oauth) unless the request already set its own.

@oh-my-pi/pi-catalog

Changed

  • Changed the paid xAI (XAI_API_KEY) and SuperGrok (xai-oauth) default models to grok-4.6.

Fixed

  • Raised the GPT-5.6 Sol/Terra/Luna context window on the Codex transport (openai-codex) from 372K to 1M tokens: OpenAI enabled the 1M window for subscription Codex on 2026-08-16, but the Codex model registry still reports the stale 272,000, so discovery now floors these SKUs at 1,000,000 instead of trusting the reported value (openai/codex#38917).

@oh-my-pi/pi-coding-agent

Added

  • Added ExtensionAPI.registerFileWriteFallback(handler) and ExtensionAPI.registerFileDeleteFallback(handler), letting an extension supply a fallback writer or deleter that is consulted when a native write, edit, or apply_patch byte-write or unlink is denied with a permission error (EPERM/EACCES/EROFS) — for hosts that embed the agent inside a sandbox that denies direct filesystem access but exposes a privileged channel. The brokered path is symlink-resolved so a handler's allowlist sees the real destination, a destination that cannot be resolved is not brokered at all, and req.sessionId names the session that issued the mutation so a handler sharing the process-wide registry can enforce policy per session. See docs/extensions.md.

Changed

  • Send the omp/<version> User-Agent on xAI chat (xai and xai-oauth) unless the request already set its own (#8840 by @Jaaneek).
  • Updated the default model for XAI_API_KEY (xai) and SuperGrok OAuth (xai-oauth) to grok-4.6. Automatic model selection continues to prefer paid xai/grok-4.6 when only XAI_API_KEY is set, with xai-oauth/grok-4.6 still available explicitly.

Fixed

  • Fixed omp stats and /stats dashboards being unreachable from container hosts by accepting an explicit --host bind address while preserving the 127.0.0.1 default.

@oh-my-pi/omp-stats

Fixed

  • Fixed the stats dashboard being unreachable from container hosts by accepting an explicit --host bind address while preserving loopback-only binding and same-origin API access by default.

What's Changed

  • fix(ai): send omp User-Agent on xAI chat only by @Jaaneek in #8840

New Contributors

Full Changelog: v17.3.6...v17.3.7

Zum Aktualisieren ziehen
ZERO-DAY CVE-2026-61591 | djust provides Phoenix LiveView-style reactive server-side rendering for…
Advisory →
TTS Reader • tsecurity.de Voice
tsecurity.de Icon
tsecurity.de App
Offline-Lesen, Eilmeldungen & 0ms Ladezeit

Installiere tsecurity.de direkt auf deinen Home-Bildschirm für das ultimative Vollbild-Magazinerlebnis ohne Browser-Leisten.

Nächster Beitrag
Community Radar & Live Chat
Sentinel Bot online • Live-Stream
Dein Cluster: Security Explorer
Match:
lädt…
Verbindung zum Community-Stream wird aufgebaut...
Bearbeitungsmodus — Senden überschreibt deine Nachricht
Community-Puls — was gerade passiert
lädt…
Aktivitäten deiner Analysten
lädt…
Neues Thema oder Eilmeldung einreichen

Reiche interessante Links, Zero-Days oder Debatten ein. Die Community entscheidet per Upvote über die Veröffentlichung.

Heiß diskutierte Einreichungen
🔖 Gespeicherte Artikel
📂 Keine gespeicherten Artikel vorhanden.
Rechts: Artikel Ziehen Links: RSS
Hoch: nächster Artikel Runter: zurück / schließen
News NIS-2 Frühwarnung Tier-1 Intel ⏱️ 3 Min vor 10 Min
Artikeldaten werden geladen...

Rechts: Original Links: RSS-Ansicht
↗ Original-Quelle
Social Reaktionen Stimme abgeben (+5 Karma)
Einstufung & Relevanz-Poll 0 Stimmen
In sozialen Netzwerken teilen 1-Klick