Repository navigation
Update dependency github:yvgude/lean-ctx to v3.11.2 - #2313
Open
renovate[bot] wants to merge 3 commits into
Open
renovate[bot] wants to merge 3 commits into
renovate[bot] wants to merge 3 commits into
Conversation
Up to standards ✅🟢 Issues
|
| Metric | Results |
|---|---|
| Complexity | 0 |
| Duplication | 0 |
NEW Get contextual insights on your PRs based on Codacy's metrics, along with PR and Jira context, without leaving GitHub. Enable AI reviewer
TIP This summary will be updated as you push new changes.
renovate
Bot
force-pushed
the
renovate/github-yvgude-lean-ctx-3.x
branch
2 times, most recently
from
September 25, 2026 23:26
b2cf3b2 to
9bfe341
Compare
renovate
Bot
force-pushed
the
renovate/github-yvgude-lean-ctx-3.x
branch
from
September 26, 2026 13:44
7baadbd to
35c0c6d
Compare
renovate
Bot
force-pushed
the
renovate/github-yvgude-lean-ctx-3.x
branch
from
September 27, 2026 21:30
9ae7008 to
5eb3b5d
Compare
renovate
Bot
force-pushed
the
renovate/github-yvgude-lean-ctx-3.x
branch
2 times, most recently
from
October 5, 2026 17:12
d5f9276 to
dfcf68c
Compare
renovate
Bot
force-pushed
the
renovate/github-yvgude-lean-ctx-3.x
branch
from
October 8, 2026 11:15
d330738 to
499da2b
Compare
renovate
Bot
force-pushed
the
renovate/github-yvgude-lean-ctx-3.x
branch
from
October 9, 2026 16:09
3655d31 to
8d83429
Compare
renovate
Bot
force-pushed
the
renovate/github-yvgude-lean-ctx-3.x
branch
from
October 10, 2026 00:52
48b0c00 to
8564427
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
v3.8.8→v3.11.2Release Notes
yvgude/lean-ctx (github:yvgude/lean-ctx)
v3.11.2Compare Source
Updater and security hotfix for 3.11.1. Agent Tools protocol, configuration and data formats are unchanged.
Upgrade notes
Failed to complete durable update transaction: prepared transaction is missing its integrity digest, and scheduled automatic updates fail the same way. Nothing is changed or damaged: the installed binary keeps running. Install this release once through the channel you installed with —curl -fsSL https://leanctx.com/install.sh | sh,brew upgrade lean-ctx,npm i -g lean-ctx-bin@latest,cargo install lean-ctx --forceor your AUR helper — andlean-ctx updateand automatic updates work again from then on.cosigntool and looks for it under that exact name; installing cosign does not help, because its update then stops at the error above. Extract the Windows ZIP of this release over yourlean-ctx.exe, or update through npm. From 3.11.1 on, no external tool is needed.Security
homejail scope opens projects, not your home directory. 3.11.1 admitted every path below~for reading, so a prompt-injected agent could pull loose personal files (~/Documents/taxes.pdf,~/Downloads,~/Desktop) into the model context. A path is now admitted only when a folder between it and~holds a project marker (.git,Cargo.toml,package.json,go.mod,pyproject.toml,Makefile, …). Every repository below~stays readable; anything else needslean-ctx allow-path <dir>, and the refusal says so.redirect_excludefrom an untrusted workspace is withheld (#2034). Paths inredirect_excludeskip the native-read hook redirect and with it the redaction that path applies. In 3.11.1 a repository's own.lean-ctx.tomlcould extend the list even when the workspace was not trusted, so a cloned repository could opt its reads out (for example with["**"]) on hosts where the read redirect is active. Such a list is now ignored with a[SECURITY]warning until you runlean-ctx trust; the global config andLEAN_CTX_HOOK_EXCLUDEstill apply.Fixed
model_provider = "leanctx-chatgpt"into every such thread and refuses to resume it once that provider is missing (Model provider 'leanctx-chatgpt' not found).lean-ctx doctor --fix,proxyruns and stale-proxy cleanup deleted the[model_providers.leanctx-chatgpt]block by name, including the direct one users restored by hand. Cleanup now only touches a block that targets the local proxy, and repoints it athttps://chatgpt.com/backend-api/codexinstead of deleting it; a block aimed anywhere else is kept verbatim and no longer reported as routed or broken.ctx_multi_repo action=searchwithout a query says so. While a content policy was active, the call was refused with the cross-project policy message instead ofquery is required for search.lean-ctx updateand scheduled updates only install a release newer than the running build; a build ahead of GitHub's latest release was offered, and on a schedule installed, the older release.lean-ctx update <version>and--pinstill install any version on purpose.GITHUB_TOKEN,GH_TOKENorLEAN_CTX_GITHUB_TOKENwhen set (only to api.github.com, without following redirects), raising GitHub's limit from 60 requests per hour per IP address to 5000. An exhausted quota now says so, with the reset time and the fix, instead ofhttp status: 403; a rejected token reports401 Bad credentials. The background version check uses the same client.lean-ctx updateandlean-ctx update --rollbackcomplete again. The updater sealed each prepared transaction with its integrity digest when writing it to disk, but then executed the unsealed copy, which the integrity check rejected every time. The updater now executes exactly the sealed transaction it persisted. A new test runs the real prepare → execute → recover path on a stand-in binary.Upgrade
Full Changelog: yvgude/lean-ctx@v3.11.1...v3.11.2
v3.11.1Compare Source
Highlights
~/.ssh,~/.aws,~/.config, other top-level dot directories,~/Library,~/AppDataand~/snapstay closed.Upgrade notes
path_jail_scopesetting defaults to"home": reads anywhere below your home directory outside the protected zones; writes only in the session's project, host-declared roots and allow entries. Setlean-ctx config set path_jail_scope projectto keep the previous single-project boundary. The setting is global-only; a project-local.lean-ctx.tomlcannot change it. With an implausible$HOME(/, a single path component, not owned by you) the scope falls back toproject.path_jail = falsestill disables the jail.~) no longer opens~/.sshand the like; add an entry inside the zone (lean-ctx allow-path ~/.config/myapp) if a tool must reach it.lean-ctx setup/doctor --fixruns and MCP-start hook refreshes copied the installing session'sLEAN_CTX_PROJECT_ROOTandLEAN_CTX_EXTRA_ROOTSinto user-global agent configs (~/.codex/config.toml,~/.grok/config.toml, global JSON MCP entries), so every later session of that agent opened the same project. The Codex and Grok entries are cleaned on the next agent refresh;lean-ctx doctorreports remaining pins under "Project binding" andlean-ctx doctor --fixremoves them line by line, keeping key order and comments (a pin that shares a line with other keys is listed for a manual edit).LEAN_CTX_EXTRA_ROOTSvalues move intoextra_roots; per-project entries in~/.claude.jsonare left alone. Restart the agent once afterwards.lean-ctx telemetry off,DO_NOT_TRACK=1orLEAN_CTX_TELEMETRY=off; an explicit opt-out made since 3.11.0 stays in effect, andlean-ctx telemetry showprints the exact payload. What the server keeps, including a keyed network hash and the network operator's public name derived from the connection (never the IP address), and how long, is described at leanctx.com/privacy.Security
lean-ctxis on the default shell allowlist, so an agent could runlean-ctx yolo --yes,lean-ctx allow <cmd>,lean-ctx allow-path <dir>,lean-ctx trust,lean-ctx security open,lean-ctx security secrets offorlean-ctx config set <security key>through ctx_shell (or a hook-rewritten Bash call) and then do what the jail or the allowlist had just refused. Those subcommands are now blocked in agent shells with a message to ask the user; listing (--list,status,config show), narrowing (--remove) and tightening (secure,untrust,security secrets on) still run. Run the blocked commands in your own terminal.homescope opens other projects for reading only; writes outside the session's project need an explicitlean-ctx allow-path, so an agent in one repository cannot plant another repository's Git hooks or a binary on yourPATH.Added
lean-ctx allow-path <dir>admits one directory for reading and writing — outside your home directory, a sibling project to edit, or one protected location — effective on the next tool call without a restart.--listshows the jail scope and added directories;--removetakes one out. It refuses/, the home directory and any directory containing it.lean-ctx security statusshows the active jail scope, andlean-ctx doctorreports global project pins.Changed
lean-ctx allow-path <dir>, offered for the enclosing project) for the user to run in their terminal. The previous hints to open a new IDE window or set an env var that the running server cannot see are gone.LEAN_CTX_PROJECT_ROOTpin is still set and the MCP server starts inside a different real project, the session binds to that project and logs a warning. Host-specific roots (CLAUDE_PROJECT_DIR, workspace folders) keep their precedence.DO_NOT_TRACK=1,LEAN_CTX_TELEMETRY=offandlean-ctx telemetry offstill turn telemetry off.unknownfor every installation because no build set it; it now follows the location of the running executable (npm, Homebrew, cargo, PyPI, AUR, release binary). Only the channel name is sent.lean-ctx gainrecord (operations and tokens before/after compression per day, lifetime totals, month of first use), so usage through shell hooks and before telemetry is counted. Failed tool calls are reported by class (invalid input, not found, permission, policy, timeout, edit conflict, too large, unavailable), together with the five most frequent error messages per tool and day as templates: the client replaces every quoted text, path, file name, number, identifier, URL and e-mail address with a placeholder before anything is sent, and drops a message entirely when no safe wording remains. Shell commands that exit non-zero are now reported ascommandinstead ofinternal.telemetry.enabled = falsewithout a recorded choice is re-enabled once on upgrade, and the one-time notice explains it. An opt-out made since 3.11 (lean-ctx telemetry off, declining in setup, and now alsolean-ctx config set telemetry.enabled false) is recorded as explicit and never overridden;DO_NOT_TRACK=1andLEAN_CTX_TELEMETRY=offalways win, and a read-only config is left untouched.feature_aggregatereports how often each CLI command runs (lean-ctx pack export→cli.pack.export,graph build,index build-full,telemetry off…) and every graph, BM25 and semantic index build with its failures. Commands and verbs come from a fixed registry; arguments, paths and queries never become part of a code, and hot-path commands (shell hooks,-c,read,grep, statusline) are not counted.noneseparates installations used only through the CLI and shell hooks from an unrecognised MCP client (other). The client's name is never sent, and what LeanCTX offers each client over MCP is unchanged.lean-ctx telemetry off, orenabled = falseunder[telemetry]in theconfig.tomlit names) and where to see what is sent. The full list stays onlean-ctx telemetry on|offand the payload onlean-ctx telemetry show. An earlier explicit choice is kept.Fixed
tee(> build.log,>> notes.txt,| tee out.txt) were refused everywhere except/tmp,$TMPDIRandwrite_allow_paths; the project root stayed refused even when listed, andallow_paths/extra_rootswere not consulted. Capture may now also go to the session's project and the jail's allow entries./,~, its ancestors andread_only_rootsare never capture targets; downloads (curl -o,wget,dd of=) keep the scratch-only rule.agents.shared_cargo_targetpointed everycargo build/testrun through ctx_shell at<data dir>/build-cache/cargo-target, so./targetkept a stale binary;agents.serialize_build_commandsmade each build wait for builds from other sessions on the machine;agents.cargo_build_jobs = 3capped cargo at three jobs. All three are now opt-in (false,false,0) and documented in the config reference under[agents]. Set them again inconfig.tomlif you relied on the shared cache.grep -r … tarifffollowed by a stdin-readinggrepin the same command line (…; echo x | grep -c x,| grep -v _test) was treated as a recursive walk of the working directory, so the hint named.claude/worktrees/,node_modules/or.venv/although nothing entered them. Only invocations that walk (find, or a grep-like with its own-r/-R) now contribute search roots. Withraw: truethe hint is no longer appended, matching the verbatim promise.lean-ctx updateandenable-gpuno longer require acosignbinary. 3.11.0 verified release signatures by runningcosign, so on machines without it every binary update andenable-gpustopped with "cosign is unavailable; refusing unsigned release". The updater now verifies the keyless signature in-process: the certificate must chain to the embedded Sigstore Fulcio root, carry a valid SCT from the Sigstore CT log, name the release workflow at the exact release tag with the GitHub Actions OIDC issuer, and sign the file. Whencosignis installed it still runs as an additional check (Rekor transparency log). 3.11.0 installations cannot self-update to this release unlesscosignis onPATH(winget install -e --id Sigstore.Cosign,brew install cosign, or a binary from github.com/sigstore/cosign/releases); alternatively reinstall with the install script (macOS/Linux), npm, Homebrew or Cargo, or replace the binary from the release archive.lean-ctx index build-semanticgave up after 10 minutes, which ended the process and discarded the work — on CPU-only machines and with larger models the index was never built. Builds now save finished files every minute and on errors, Ctrl-C or memory aborts, the next run resumes where the last one stopped, and the CLI waits until the build finishes.index statusanddoctorreport an interrupted build aspartialwith the resume command.ctx_indexbuilds the semantic index in the background.build-semanticandbuild-fullno longer block the tool call, wait for the BM25 index instead of embedding an empty or stale one, and a per-project lock keeps two processes from building the same semantic index at once.ctx_readmodes (and redirected native reads) returned a large CLAUDE.md as a headings-only map, because only SKILL.md, AGENTS.md and a few rule files were treated as instructions.CLAUDE.md,CLAUDE.local.md,GEMINI.md,copilot-instructions.md,.windsurfrules, and documents under.claude/agents/and.claude/commands/are now always delivered complete.redirect_excludeworks again. The key was loaded but never applied, so listing a file there changed nothing. Matching paths (globs on the trailing path components, e.g.CLAUDE.md,*.json,docs/**) now skip the native-read hook redirect and are returned in full by automaticctx_readmodes;LEAN_CTX_HOOK_EXCLUDE(comma-separated) takes precedence, as documented since 2.17.4.lean-ctx index build/build-fullno longer stop after 5 minutes while graph and BM25 are still building, which ended the process before the index was saved. A build worker that fails unexpectedly now always releases its slot, so the command reports the failure instead of waiting.Upgrade
Full Changelog: yvgude/lean-ctx@v3.11.0...v3.11.1
v3.11.0Compare Source
Highlights
lean-ctx pack --limitproduces a bounded context bundle, andlean-ctx index whyexplains why a file is or is not indexed.Upgrade notes
LEAN_CTX_CONTEXT_GATEWAY=offfor one run, or setcontext_gateway.enabled = falsein the global config to disable it persistently. The CLIlean-ctx readpath used by shell hooks is outside gateway admission unless a policy pack is active; output redaction still applies.nstores an explicit opt-out that every later upgrade keeps. Earlier versions did not store a declined prompt, so an installation that declined before 3.11.0 is on after the upgrade: the first interactive command shows a one-time notice with the full list, andlean-ctx telemetry offturns it off. Disable it any time withDO_NOT_TRACK=1,LEAN_CTX_TELEMETRY=off, orlean-ctx telemetry off; an earlier explicit opt-out remains in effect. CI jobs (CI,GITHUB_ACTIONS,GITLAB_CI, and other common CI markers) never collect or send telemetry;LEAN_CTX_TELEMETRY_IN_CI=1opts a non-CI machine with such a marker back in. Uselean-ctx telemetry status|show|history|purge-local|delete-remote|reset-idto inspect or manage its payload and ledger.GRAPH_ENGINE_VERSIONand graphINDEX_VERSIONare now 7. Existing graph indexes rebuild before use; do not reuse a version 6 graph.semantic_mode = "auto"is the default. It uses running language servers or a live IDE; it does not start servers unlesssemantic_mode = "eager"is selected in a trusted workspace. Usesemantic_mode = "off"to disable semantic enrichment."git status *"for prefix matching. Setshell_allowlist_subcommand_scoping = falseto restore the former base-binary matching.intelligence_runtime.context_policy_apply = false. Each stdio MCP server targetsmcp_max_rss_mb = 512(raise it, or setLEAN_CTX_MCP_MAX_RSS_MB, for very large indexes);mcp_idle_exit_minutes = 0keeps idle servers running. Theengine-context-store-v1contract andcontext-gateway-v1vocabulary are experimental, not stable compatibility promises.keep_hook_contextoption to retain lean-ctx hook context, orshape_native_outputto disable native Bash shaping.proxy.routing.tierstable is ignored and reported bylean-ctx doctor. Rust embedders importing removed internal modules must move toContextEngineorlean-ctx-sdk.shell_cache_enabledno longer enables cached results.Security
Added
mcp_idle_exit_minutes(LEAN_CTX_MCP_IDLE_EXIT_MINUTES, default0=off) ends a stdio MCP server after that many idle minutes. It is opt-in
because Codex does not restart exited MCP servers. stdin EOF and a dead
parent already end the server.
engine-context-store-v1). One task's plan → delivery → outcome lineage, joined from the execution ledger and Decision Receipts and scoped per tenant/project, is shown bylean-ctx inspect --taskandlean-ctx engine context-lineage; missing links are listed as gaps rather than filled in.lean-ctx autopilot evidence,lean-ctx engine context-policy-evidenceandlean-ctx eval frontier --save-evidence.lean-ctx autopilot policy status|promote|monitor|rollbackkeeps a promoted read-strategy policy (active plus last stable) supplied by the optional licensed runtime. Planning records it in shadow only;intelligence_runtime.context_policy_apply = trueapplies it, and security rules and explicit user choices still take precedence.lean-ctx addon auth NAMEsupports OAuth 2.1 discovery, registration, PKCE, loopback redirect, token attachment, and refresh; --status, --logout, and --no-browser are available. Credentials are encrypted per server using the macOS Keychain, Windows Credential Manager, or a Linux 0600 key file. OAuth declarations on stdio servers or alongside an Authorization header are refused.lean-ctx index why FILE. Explains which indexing rule included or excluded a file, reports encoding and BM25 chunk/freshness information for eligible files, supports --json, and exits 1 for an excluded file. MCP:ctx_index action=why path=FILE.Changed
has a per-process RSS target,
mcp_max_rss_mb(default 512 MB,LEAN_CTX_MCP_MAX_RSS_MB). The guardian uses the lower of it andmax_ram_percent, which on large machines was several GB per process. ACodex app-server that keeps one server per loaded thread therefore no longer
accumulates ~1 GB instances.
memory_cleanupTTLwithout a tool call, a server drops its read cache and resident indexes
without waiting for the next call. A running call or background job keeps
it busy. The release logs process memory and live heap before and after.
figure Activity Monitor shows instead of resident size, which leaves out
pages the memory compressor has taken. An idle server measured 40 MB
resident while still holding a ~180 MB heap. Footprint is read through
proc_pid_rusage, which also replaces apsspawn per sample.(1 s → 60 s, then a five-minute pause) at every pressure level, not only
Critical. Sampling stays at one second, so a rise to a higher level still
evicts at once. Pressure lines log on a level change and at most once a
minute after that; a baseline above a small cap used to log every second.
@modelcontextprotocol/sdk1.30.0 → 1.32.1,proxy-addr2.0.8 andsource-map-js1.2.2; THIRD_PARTY_NOTICES and the asset manifest record the new versions and digests.telemetry onand a one-time notice on the first interactive command show the same list of what is sent; a declined setup prompt is stored as an explicit opt-out; CI jobs never collect or send.Removed
Fixed
echo "a⏎b"; cat <<'EOF'no longer gates the heredoc body as commands; an apostrophe in a comment cannot hide a later heredoc.Configuration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.