docs(changelog): add 2026-05-16 entry + backfill 2026-05-14 and 2026-05-15 #51
Open
documentation-specialist
wants to merge 7 commits from
docs/changelog-2026-05-16 into main
pull from: docs/changelog-2026-05-16
merge into: molecule-ai:main
molecule-ai:main
molecule-ai:docs/rfc562-cache-headers
molecule-ai:docs/mcp-server-hermes-stubs-backfill
molecule-ai:docs/changelog-2026-05-18-daily
molecule-ai:backfill/2026-05-16-daily
molecule-ai:docs/changelog-2026-05-17-daily
molecule-ai:tw-fix-53
molecule-ai:docs/changelog-2026-05-17
molecule-ai:docs/workspace-abilities-broadcast-changelog-2026-05-15
molecule-ai:workspace-abilities-broadcast-changelog-2026-05-15
molecule-ai:docs/cwe78-expandwithenv-regression-fix
molecule-ai:docs/cwe22-org-import-path-traversal-fix
molecule-ai:docs/offsec-006-slug-validation
molecule-ai:docs/cwe78-changelog-cleanup
molecule-ai:docs/changelog-2026-05-15
molecule-ai:docs/self-hosted-workspace-docker
molecule-ai:docs/offsec-006-slug-ssrf-advisory
molecule-ai:fix/plugins-mcp-stub-coming-soon
molecule-ai:docs/changelog-2026-05-13
molecule-ai:pr-37-fix
molecule-ai:pr45
molecule-ai:fix/terminationGracePeriodSeconds-in-k8s-yaml
molecule-ai:pr-46
molecule-ai:fix/plugins-mcp-coming-soon-stub
molecule-ai:pr46
molecule-ai:pr-40-review
molecule-ai:fix/mcp-docs-combined
molecule-ai:docs/mcp-server-http-sse-transport
molecule-ai:docs/mcp-server-port-env-var
molecule-ai:docs/changelog-2026-05-14
molecule-ai:docs/changelog-2026-05-13-entries-prs-27-35
molecule-ai:docs/backfill-security-index
molecule-ai:docs/mcp-env-var-rename-from-mcp-server-6
molecule-ai:docs/add-2026-05-13-infra-fix
molecule-ai:fix/stale-platform-url-default
molecule-ai:merge/integration
molecule-ai:merge/pr30-dev-channels-flag
molecule-ai:merge/pr28-changelog-duplicate-fix
molecule-ai:merge/pr31-changelog-security
molecule-ai:docs/dev-channels-flag-page
molecule-ai:docs/fix-changelog-duplicate-sections
molecule-ai:docs/sdk-python-new-remoteagent-params-from-sdk-5-6-7
molecule-ai:chore/sop-checklist-gate
molecule-ai:merge/pr27-sop-checklist-gate
molecule-ai:docs/model-env-and-http-sse-transport
molecule-ai:docs/claude-code-channel-plugin
molecule-ai:docs/a2a-sdk-v0-to-v1-migration
molecule-ai:pr-7
molecule-ai:docs/aws-ec2-provisioner-tutorial-v2
molecule-ai:docs/changelog-catchup-17days
molecule-ai:docs/changelog-backfill-2026-05-10
molecule-ai:docs/changelog-catch-up-2026-04-24-to-05-10
molecule-ai:fix/post-suspension-github-urls
molecule-ai:fix/install-path-gitea
molecule-ai:fix/docs-fly-to-aws-railway-migration
molecule-ai:fix/docs-runtime-model-observability-accuracy
molecule-ai:fix/docs-secrets-aes-to-kms-envelope
molecule-ai:worktree-agent-a26f858441e48bd99
molecule-ai:worktree-agent-ada99ff89e49d3041
molecule-ai:worktree-agent-ae7dd10f3bb93a13d
molecule-ai:docs/dev-channels-tagged-form
molecule-ai:docs/fix-quickstart-clone-urls
molecule-ai:docs/fix-staging-dns-architecture
molecule-ai:design/align-docs-to-landing
molecule-ai:docs/runtime-mcp-spec-compliance
molecule-ai:docs/runtime-mcp-notifications-and-pitfalls
molecule-ai:docs/agent-card-env-vars
molecule-ai:docs/universal-mcp-runtime
molecule-ai:post/why-multi-agent-teams
molecule-ai:fix/ci-runs-on-self-hosted
7 Commits
| Author | SHA1 | Message | Date | |
|---|---|---|---|---|
|
|
f9ac456c4d |
docs(changelog): add claude-code#24 Kimi K2.6 routing to 2026-05-16
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com> |
||
|
|
d1545857f4 |
docs(changelog): add molecule-core#1327 platform-side bearer-token fix
The hermes#23 bearer-token 401 was a two-part issue: workspace-side CONFIGS_DIR fix (already documented) and platform-side token-injection ownership fix (molecule-core#1327). Adds the platform-side fix to the same 2026-05-16 entry. Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com> |
||
|
|
a56d2afe57 |
fix(changelog): trim duplicates per TW re-review
Removes 2026-05-15 section (docs#49 is canonical) and all 2026-05-14 entries that duplicate docs#49 (OFFSEC-006, CWE-78, OFFSEC-003) and docs#45 (Canvas WCAG, OpenClaw, CI improvements, handler coverage). Keeps only the 2026-05-16 section with unique Hermes MCP + Files API + Scripts CI content. Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com> |
||
|
|
d14dccdd44 |
docs(changelog): fold docs#45 unique entries into 2026-05-14 section
Adds CWE-78 (expandWithEnv POSIX-identifier guard regression), OFFSEC-003 workspace-side A2A boundary marker escaping, OpenClaw template models config fix, CI infrastructure improvements, and handler test coverage additions from docs#45 — consolidating all 2026-05-14 content into docs#51 so docs#45 can be closed. Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com> |
||
|
|
2c85205ee7 |
fix(changelog): remove inaccurate set -f clause from OFFSEC-006 entry
The set -f clause was not part of the actual fix (validate_slug() RFC-1123 regex only). Technical-writer review identified the inaccuracy. Removes the clause per docs#51 REQUEST_CHANGES. Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com> |
||
|
|
ba8ec52ca9 |
docs(changelog): add hermes#23 bearer token 401 fix to 2026-05-16
molecule-ai-workspace-template-hermes#23: CONFIGS_DIR fix so molecule MCP server finds the bearer token at /configs/.auth_token. 🤖 Generated by Documentation Specialist cross-repo PR watch. Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com> |
||
|
|
ab799e93b3 |
docs(changelog): add 2026-05-16 + backfill 2026-05-14 and 2026-05-15 entries
2026-05-16: - Fix: Hermes workspace MCP server tools now reach agent loop (#22) - Internal: Files API groundwork (molecule-core#1247/#1255/#1257/#1267) - Internal: Scripts CI improvements (internal#431/#437) 2026-05-15: Quiet day — docs queue maintenance (#40-49 open) 2026-05-14: - Security: OFFSEC-006 tenant slug SSRF fix (#933) - Fix: Canvas accessibility round 3 (#936, #949) - Internal: CI/CD hardening + test coverage Supersedes open docs#50 (2026-05-15 quiet-day entry). 🤖 Generated by Documentation Specialist daily-changelog cron. Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com> |