docs(changelog): add 2026-05-15 quiet-day entry #50

Closed
documentation-specialist wants to merge 4 commits from docs/changelog-2026-05-15 into main

4 Commits

Author SHA1 Message Date
documentation-specialist 42d70b5906 docs(changelog): add 2026-05-15 quiet-day entry
Secret scan / secret-scan (pull_request) Successful in 2m29s
CI / build (pull_request) Successful in 5m7s
No customer-visible changes. All activity was internal SOP tooling
and docs queue preparation (PRs #40–#49 open, pending CI).

🤖 Generated by Documentation Specialist daily-changelog cron.
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
2026-05-16 01:53:52 +00:00
documentation-specialist 3992150a47 docs(security): add OFFSEC-006 + CWE-22 regression to Security Changelog
Secret scan / secret-scan (pull_request) Successful in 1m29s
CI / build (pull_request) Successful in 3m24s
- OFFSEC-006 (2026-05-14): tenant slug SSRF + token exfiltration in
  promote-tenant-image.sh — RFC-1123 validation + set -f glob disable
- CWE-22 regression (2026-05-13): org_import.go path traversal —
  loadWorkspaceEnv replaces parseEnvFile

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
2026-05-14 04:19:32 +00:00
documentation-specialist 5830875200 docs(changelog): add 2026-05-14 entry — OFFSEC-006 + canvas a11y + CI hardening
Secret scan / secret-scan (pull_request) Successful in 1m0s
CI / build (pull_request) Successful in 2m57s
## 2026-05-14
- 🔒 Security: OFFSEC-006 tenant slug SSRF + token exfiltration fix (core#933)
- 🔧 Fixes: canvas WCAG AA round 3 (core#936, #949)
- 🧹 Internal: CI hardening + test coverage additions + _sanitize_a2a aliases

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
2026-05-14 04:16:42 +00:00
documentation-specialist cece1d6e03 docs(changelog): add 2026-05-13 daily entry
CI / build (pull_request) Successful in 4m19s
## New features
- Docker HEALTHCHECK for workspace containers (core#883)

## Documentation
- Security hub backfill: OWASP link + severity table (docs#35)
- MOLECULE_URL → MOLECULE_API_URL rename (docs#34)
- Remote workspaces graceful shutdown docs (docs#29)
- PLATFORM_URL defaults corrected to host.docker.internal (docs#32)
- Dev channel tagged-form requirement clarified (docs#30)
- MCP server tool registry corrected: 29→87 tools (mcp-server#5)
- CWE-22 path traversal regression documented (docs#31, core#810)
- EC2 Instance Connect IAM permission documented (docs#33)

## Internal
- Platform hardening across molecule-core (handlers, CI, tests, canvas a11y)
- CI tooling migration (.github → .gitea)
- SaaS ADMIN_TOKEN self-heal on startup

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
2026-05-14 00:07:00 +00:00