Commit graph

1694 commits

Author SHA1 Message Date
dependabot[bot]
b7faebac86
chore(deps): bump actions/setup-python from 4 to 6
Bumps [actions/setup-python](https://github.com/actions/setup-python) from 4 to 6.
- [Release notes](https://github.com/actions/setup-python/releases)
- [Commits](https://github.com/actions/setup-python/compare/v4...v6)

---
updated-dependencies:
- dependency-name: actions/setup-python
  dependency-version: '6'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-01-16 06:18:12 +00:00
sd416
ff3383ce0c
Add GitHub Actions to Dependabot configuration
Added configuration for GitHub Actions updates to Dependabot.
2026-01-16 11:46:53 +05:30
Wendong-Fan
aa0597bcff add Contributors ❤️
Some checks are pending
CodeQL Advanced / Analyze (actions) (push) Waiting to run
CodeQL Advanced / Analyze (javascript-typescript) (push) Waiting to run
CodeQL Advanced / Analyze (python) (push) Waiting to run
2026-01-16 09:21:59 +08:00
Wendong-Fan
d65ef22c49
Improve formatting and structure of product client use case tasks (#860) 2026-01-15 23:55:52 +00:00
Major pratap singh sisodiya
e031401660 actually fixing the issue now 2026-01-16 07:53:31 +08:00
Wendong-Fan
3b974b9663 minor doc update 2026-01-16 07:37:29 +08:00
Wendong-Fan
b2bd691507
docs: add Japanese README (#857) 2026-01-15 23:36:38 +00:00
Wendong-Fan
595f63009c
Merge branch 'main' into add-ja-doc 2026-01-15 23:35:43 +00:00
Wendong-Fan
54186f623a
chore: browser tools (#863) 2026-01-15 23:31:53 +00:00
Wendong-Fan
f468855410 update 2026-01-16 07:31:22 +08:00
puzhen
bec0e08250 Merge branch 'chore/browser' of github.com:eigent-ai/eigent into chore/browser 2026-01-15 23:16:10 +00:00
puzhen
217af02410 update 2026-01-15 23:15:50 +00:00
Puzhen Zhang
a7adba2d02
Merge branch 'main' into chore/browser 2026-01-15 22:57:47 +00:00
puzhen
bb670c2728 chore browser tools 2026-01-15 22:56:08 +00:00
Wendong-Fan
572e383db5 chore: add toolkit properity 2026-01-16 05:58:03 +08:00
Wendong-Fan
a96c088025
release: 0.0.78 (#861) 2026-01-15 21:32:45 +00:00
Wendong-Fan
7e7d36e2f5 release: 0.0.78 2026-01-16 05:32:28 +08:00
eigent
457dea6412 feat: support zhipu ai
Some checks are pending
CodeQL Advanced / Analyze (actions) (push) Waiting to run
CodeQL Advanced / Analyze (javascript-typescript) (push) Waiting to run
CodeQL Advanced / Analyze (python) (push) Waiting to run
2026-01-15 16:42:38 +00:00
Ikko Ashimine
b48131059c docs: add Japanese README 2026-01-16 01:34:51 +09:00
Wendong-Fan
8ff8c86784 update usecase
Some checks are pending
CodeQL Advanced / Analyze (actions) (push) Waiting to run
CodeQL Advanced / Analyze (javascript-typescript) (push) Waiting to run
CodeQL Advanced / Analyze (python) (push) Waiting to run
2026-01-15 02:19:33 +08:00
Wendong-Fan
6d83cb7dd6 Update WeChat QR code via QR Code Updater
Some checks are pending
CodeQL Advanced / Analyze (actions) (push) Waiting to run
CodeQL Advanced / Analyze (javascript-typescript) (push) Waiting to run
CodeQL Advanced / Analyze (python) (push) Waiting to run
🤖 Automated update
2026-01-14 13:31:41 +00:00
Wendong-Fan
5ac27f41f7
fix: agent id issue (#844)
Some checks are pending
CodeQL Advanced / Analyze (actions) (push) Waiting to run
CodeQL Advanced / Analyze (javascript-typescript) (push) Waiting to run
CodeQL Advanced / Analyze (python) (push) Waiting to run
2026-01-14 04:41:44 +00:00
Wendong-Fan
ec8ac901f4 update camel version 2026-01-14 12:41:15 +08:00
Wendong-Fan
4a615b79c2 fix: agent id issue 2026-01-14 12:31:44 +08:00
Wendong-Fan
5f869eb66d update model platform naming
Some checks are pending
CodeQL Advanced / Analyze (actions) (push) Waiting to run
CodeQL Advanced / Analyze (javascript-typescript) (push) Waiting to run
CodeQL Advanced / Analyze (python) (push) Waiting to run
2026-01-14 06:29:09 +08:00
Wendong-Fan
586d9d5b3a
feat: add lark (#842) 2026-01-13 19:49:12 +00:00
Wendong-Fan
f6c639511c update camel version 2026-01-14 03:48:46 +08:00
Wendong-Fan
ceb556f111
Merge branch 'main' into add_lark 2026-01-13 19:47:48 +00:00
Wendong-Fan
b9d24686fc fix: model platform naming 2026-01-14 01:34:28 +08:00
Wendong-Fan
aa6c1b55bc
docs: Update local development setup (#843) 2026-01-13 16:44:36 +00:00
Wendong-Fan
edfc7597b1
Merge branch 'main' into dev-guide 2026-01-13 16:44:31 +00:00
Wendong-Fan
2b779e5459
Update README.md
Some checks are pending
CodeQL Advanced / Analyze (actions) (push) Waiting to run
CodeQL Advanced / Analyze (javascript-typescript) (push) Waiting to run
CodeQL Advanced / Analyze (python) (push) Waiting to run
2026-01-14 00:42:58 +08:00
Wendong-Fan
382db262a1 minor update 2026-01-14 00:33:01 +08:00
Wendong-Fan
f0254895a9
Merge branch 'main' into dev-guide 2026-01-13 16:25:06 +00:00
4pmtong
07c2f8bdb5 🐛 fix middleware for auth 2026-01-13 23:57:18 +08:00
Sun Tao
b5d20be7b3 Update lark_toolkit.py 2026-01-13 23:53:52 +08:00
Sun Tao
e83c3093ae update 2026-01-13 23:43:46 +08:00
4pmtong
bf0d9c5369 📝 dev guideline 2026-01-13 23:30:38 +08:00
4pmtong
214345884a 📝 docs: optimize local development setup 2026-01-13 23:15:11 +08:00
Wendong-Fan
22a8b4fe38 update readme license 2026-01-13 22:30:34 +08:00
Wendong-Fan
59c58a854f docs: highlight Local Deployment mode 2026-01-13 22:09:49 +08:00
Wendong-Fan
9446f8aa89 cicd security 2026-01-13 21:55:29 +08:00
Wendong-Fan
bf02500bbb
fix(security): Prevent arbitrary code execution in CI workflow (#837) 2026-01-13 13:53:03 +00:00
Wendong-Fan
455d49e8e7
Merge branch 'main' into fix/ci-workflow-security 2026-01-13 13:43:50 +00:00
Wendong-Fan
2a406536e7
chore: add minimax provider (#840) 2026-01-13 13:43:13 +00:00
Wendong-Fan
b949bc13b9 remove unused model type file 2026-01-13 21:32:29 +08:00
Sun Tao
3f13d49c7a update 2026-01-13 19:22:57 +08:00
Cole Murray
102a864d43 fix(security): prevent arbitrary code execution in CI workflow
SECURITY FIX: The previous CI workflow was vulnerable to arbitrary code
execution from fork PRs due to using `pull_request_target` with checkout
of untrusted PR code.

Attack vector:
- Attacker forks repo and adds malicious node_modules/.bin/markdownlint-cli
- Opens PR to trigger CI workflow
- npx executes attacker's script with repository write permissions
- Attacker can exfiltrate credentials, comment on PRs, or push code

Fix:
- Split workflow into two separate files
- ci.yml: Uses pull_request_target for commenting (no code checkout)
- lint-markdown.yml: Uses pull_request for linting (safe to checkout)

The pull_request trigger runs fork PRs with read-only permissions and
no access to repository secrets, making it safe to checkout and execute
PR code.

Additional improvements:
- Updated actions to latest versions (checkout@v4, github-script@v7, paths-filter@v3)
- Pin markdownlint-cli version to prevent supply chain attacks
- Added security comments explaining the rationale

Reference: https://securitylab.github.com/research/github-actions-preventing-pwn-requests/
2026-01-12 23:10:48 -08:00
Guohao Li
a1efe01a58
I don't care (#835)
Some checks are pending
CodeQL Advanced / Analyze (actions) (push) Waiting to run
CodeQL Advanced / Analyze (javascript-typescript) (push) Waiting to run
CodeQL Advanced / Analyze (python) (push) Waiting to run
2026-01-13 07:47:38 +01:00
Guohao Li
04224b0d8e
I don't care 2026-01-13 06:47:10 +00:00