dependabot[bot]
b7faebac86
chore(deps): bump actions/setup-python from 4 to 6
...
Bumps [actions/setup-python](https://github.com/actions/setup-python ) from 4 to 6.
- [Release notes](https://github.com/actions/setup-python/releases )
- [Commits](https://github.com/actions/setup-python/compare/v4...v6 )
---
updated-dependencies:
- dependency-name: actions/setup-python
dependency-version: '6'
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com>
2026-01-16 06:18:12 +00:00
sd416
ff3383ce0c
Add GitHub Actions to Dependabot configuration
...
Added configuration for GitHub Actions updates to Dependabot.
2026-01-16 11:46:53 +05:30
Wendong-Fan
aa0597bcff
add Contributors ❤️
CodeQL Advanced / Analyze (actions) (push) Waiting to run
CodeQL Advanced / Analyze (javascript-typescript) (push) Waiting to run
CodeQL Advanced / Analyze (python) (push) Waiting to run
2026-01-16 09:21:59 +08:00
Wendong-Fan
d65ef22c49
Improve formatting and structure of product client use case tasks ( #860 )
2026-01-15 23:55:52 +00:00
Major pratap singh sisodiya
e031401660
actually fixing the issue now
2026-01-16 07:53:31 +08:00
Wendong-Fan
3b974b9663
minor doc update
2026-01-16 07:37:29 +08:00
Wendong-Fan
b2bd691507
docs: add Japanese README ( #857 )
2026-01-15 23:36:38 +00:00
Wendong-Fan
595f63009c
Merge branch 'main' into add-ja-doc
2026-01-15 23:35:43 +00:00
Wendong-Fan
54186f623a
chore: browser tools ( #863 )
2026-01-15 23:31:53 +00:00
Wendong-Fan
f468855410
update
2026-01-16 07:31:22 +08:00
puzhen
bec0e08250
Merge branch 'chore/browser' of github.com:eigent-ai/eigent into chore/browser
2026-01-15 23:16:10 +00:00
puzhen
217af02410
update
2026-01-15 23:15:50 +00:00
Puzhen Zhang
a7adba2d02
Merge branch 'main' into chore/browser
2026-01-15 22:57:47 +00:00
puzhen
bb670c2728
chore browser tools
2026-01-15 22:56:08 +00:00
Wendong-Fan
572e383db5
chore: add toolkit properity
2026-01-16 05:58:03 +08:00
Wendong-Fan
a96c088025
release: 0.0.78 ( #861 )
2026-01-15 21:32:45 +00:00
Wendong-Fan
7e7d36e2f5
release: 0.0.78
2026-01-16 05:32:28 +08:00
eigent
457dea6412
feat: support zhipu ai
CodeQL Advanced / Analyze (actions) (push) Waiting to run
CodeQL Advanced / Analyze (javascript-typescript) (push) Waiting to run
CodeQL Advanced / Analyze (python) (push) Waiting to run
2026-01-15 16:42:38 +00:00
Ikko Ashimine
b48131059c
docs: add Japanese README
2026-01-16 01:34:51 +09:00
Wendong-Fan
8ff8c86784
update usecase
CodeQL Advanced / Analyze (actions) (push) Waiting to run
CodeQL Advanced / Analyze (javascript-typescript) (push) Waiting to run
CodeQL Advanced / Analyze (python) (push) Waiting to run
2026-01-15 02:19:33 +08:00
Wendong-Fan
6d83cb7dd6
Update WeChat QR code via QR Code Updater
...
CodeQL Advanced / Analyze (actions) (push) Waiting to run
CodeQL Advanced / Analyze (javascript-typescript) (push) Waiting to run
CodeQL Advanced / Analyze (python) (push) Waiting to run
🤖 Automated update
2026-01-14 13:31:41 +00:00
Wendong-Fan
5ac27f41f7
fix: agent id issue ( #844 )
CodeQL Advanced / Analyze (actions) (push) Waiting to run
CodeQL Advanced / Analyze (javascript-typescript) (push) Waiting to run
CodeQL Advanced / Analyze (python) (push) Waiting to run
2026-01-14 04:41:44 +00:00
Wendong-Fan
ec8ac901f4
update camel version
2026-01-14 12:41:15 +08:00
Wendong-Fan
4a615b79c2
fix: agent id issue
2026-01-14 12:31:44 +08:00
Wendong-Fan
5f869eb66d
update model platform naming
CodeQL Advanced / Analyze (actions) (push) Waiting to run
CodeQL Advanced / Analyze (javascript-typescript) (push) Waiting to run
CodeQL Advanced / Analyze (python) (push) Waiting to run
2026-01-14 06:29:09 +08:00
Wendong-Fan
586d9d5b3a
feat: add lark ( #842 )
2026-01-13 19:49:12 +00:00
Wendong-Fan
f6c639511c
update camel version
2026-01-14 03:48:46 +08:00
Wendong-Fan
ceb556f111
Merge branch 'main' into add_lark
2026-01-13 19:47:48 +00:00
Wendong-Fan
b9d24686fc
fix: model platform naming
2026-01-14 01:34:28 +08:00
Wendong-Fan
aa6c1b55bc
docs: Update local development setup ( #843 )
2026-01-13 16:44:36 +00:00
Wendong-Fan
edfc7597b1
Merge branch 'main' into dev-guide
2026-01-13 16:44:31 +00:00
Wendong-Fan
2b779e5459
Update README.md
CodeQL Advanced / Analyze (actions) (push) Waiting to run
CodeQL Advanced / Analyze (javascript-typescript) (push) Waiting to run
CodeQL Advanced / Analyze (python) (push) Waiting to run
2026-01-14 00:42:58 +08:00
Wendong-Fan
382db262a1
minor update
2026-01-14 00:33:01 +08:00
Wendong-Fan
f0254895a9
Merge branch 'main' into dev-guide
2026-01-13 16:25:06 +00:00
4pmtong
07c2f8bdb5
🐛 fix middleware for auth
2026-01-13 23:57:18 +08:00
Sun Tao
b5d20be7b3
Update lark_toolkit.py
2026-01-13 23:53:52 +08:00
Sun Tao
e83c3093ae
update
2026-01-13 23:43:46 +08:00
4pmtong
bf0d9c5369
📝 dev guideline
2026-01-13 23:30:38 +08:00
4pmtong
214345884a
📝 docs: optimize local development setup
2026-01-13 23:15:11 +08:00
Wendong-Fan
22a8b4fe38
update readme license
2026-01-13 22:30:34 +08:00
Wendong-Fan
59c58a854f
docs: highlight Local Deployment mode
2026-01-13 22:09:49 +08:00
Wendong-Fan
9446f8aa89
cicd security
2026-01-13 21:55:29 +08:00
Wendong-Fan
bf02500bbb
fix(security): Prevent arbitrary code execution in CI workflow ( #837 )
2026-01-13 13:53:03 +00:00
Wendong-Fan
455d49e8e7
Merge branch 'main' into fix/ci-workflow-security
2026-01-13 13:43:50 +00:00
Wendong-Fan
2a406536e7
chore: add minimax provider ( #840 )
2026-01-13 13:43:13 +00:00
Wendong-Fan
b949bc13b9
remove unused model type file
2026-01-13 21:32:29 +08:00
Sun Tao
3f13d49c7a
update
2026-01-13 19:22:57 +08:00
Cole Murray
102a864d43
fix(security): prevent arbitrary code execution in CI workflow
...
SECURITY FIX: The previous CI workflow was vulnerable to arbitrary code
execution from fork PRs due to using `pull_request_target` with checkout
of untrusted PR code.
Attack vector:
- Attacker forks repo and adds malicious node_modules/.bin/markdownlint-cli
- Opens PR to trigger CI workflow
- npx executes attacker's script with repository write permissions
- Attacker can exfiltrate credentials, comment on PRs, or push code
Fix:
- Split workflow into two separate files
- ci.yml: Uses pull_request_target for commenting (no code checkout)
- lint-markdown.yml: Uses pull_request for linting (safe to checkout)
The pull_request trigger runs fork PRs with read-only permissions and
no access to repository secrets, making it safe to checkout and execute
PR code.
Additional improvements:
- Updated actions to latest versions (checkout@v4, github-script@v7, paths-filter@v3)
- Pin markdownlint-cli version to prevent supply chain attacks
- Added security comments explaining the rationale
Reference: https://securitylab.github.com/research/github-actions-preventing-pwn-requests/
2026-01-12 23:10:48 -08:00
Guohao Li
a1efe01a58
I don't care ( #835 )
CodeQL Advanced / Analyze (actions) (push) Waiting to run
CodeQL Advanced / Analyze (javascript-typescript) (push) Waiting to run
CodeQL Advanced / Analyze (python) (push) Waiting to run
2026-01-13 07:47:38 +01:00
Guohao Li
04224b0d8e
I don't care
2026-01-13 06:47:10 +00:00