- Add dompurify override (3.3.3) to force mermaid's transitive dep away from 3.3.1
- Switch kilo-gateway solid-js from pinned 1.9.10 to catalog (1.9.12) to eliminate seroval@1.3.2
Update hono catalog version from 4.10.7 to 4.12.12 to fix 14 advisories
including JWT algorithm confusion (GHSA-f67f-6cw9-8mq4, GHSA-3vhc-576x-3qv4),
CORS bypass, body limit bypass, XSS, cookie injection, SSE injection,
path traversal, and prototype pollution.
Add null guard for ptyID param in pty.ts to satisfy hono 4.12's stricter
return type for c.req.param().
Update simple-git from 3.31.1 to 3.35.2 in both packages/opencode and
packages/kilo-vscode to fix GHSA-r275-fr43-pm7q (blockUnsafeOperationsPlugin
bypass via case-insensitive protocol.allow config key enables RCE).
Adds a build system that compiles Kilo CLI binaries and packages them
into the backend jar at /cli/{os}/kilo for runtime extraction.
- script/build.ts: orchestrates CLI build + Gradle plugin build
- Local mode (bun run build): builds current platform only
- Production mode (bun run build:production): requires all 6 platforms
- Gradle checkCli task validates binaries before processResources
- Turbo integration via @kilocode/kilo-jetbrains#build
- README with setup and build instructions
* fix(cli): prevent unbounded log file growth with size-based rotation
Fix two issues causing log files to grow to 50+ GB:
1. Server middleware leaked a "started" log line for skipped endpoints
because log.time() was called unconditionally — only timer.stop()
was gated by the skipLogging flag. Restructure to early-return for
skipped paths so no logging occurs at all.
2. Log files had no size limit within a session. A long-running
kilo serve process (e.g. VS Code extension) would write a single
file indefinitely. Add rotating-file-stream (50 MB, maxFiles: 1)
to cap log file size automatically.
* fix(cli): address review feedback on log rotation
- Revert server.ts changes (handled separately in #8141)
- Add error/warning event handlers on rotating-file-stream
- Increase maxFiles from 1 to 3 for better debug headroom
- Set explicit history file path to avoid .txt side-effect
* fix(cli): revert maxFiles back to 1
maxFiles: 1 is sufficient — we only need to cap disk usage, not retain
old rotated fragments. The existing cleanup() handles session-level
file retention separately.
* fix(cli): set maxFiles to 10 for log rotation