mirror of
https://github.com/TencentCloud/Octop.git
synced 2026-09-29 03:43:01 +08:00
CI: - Drop Python 3.11 from the test matrix (package requires >=3.12); the 3.11 jobs failed at `uv sync`. Linux and Windows now test Python 3.12. - Rename tests/unit/infra/setup/tls/test_store.py -> test_tls_store.py to fix the pytest import collision (duplicate basename) that aborted collection on the 3.12 job. Source bugs uncovered by the suite: - Move ACTOR_SYSTEM to a runtime import in infra/cron/job.py (was wrongly placed under TYPE_CHECKING, causing NameError at runtime). - Add missing users-table columns (login_failed_count, login_locked_until, preferences_json) in infra/db/migrate.py for legacy schema repair. - Make auth.update_me honor explicit nulls via model_dump(exclude_unset=True). - Relax skills hub endpoints to existence/ownership checks (require_agent_row) instead of requiring the agent to be running. - Marshal WebSocket frames onto the owning event loop in chat/ws.py so the starlette TestClient portal does not deadlock. - Include error details in the browser session 503 response. Tests: - Update tests to match current source APIs (harness async create/remove/ rebuild, FakeHarnessAgent skill methods, workspace nested layout, JWT middleware, CLI surface, proactive config defaults, general-assistant template manifest). - Migrate WebSocket tests to starlette TestClient(...).websocket_connect (httpx 0.28 removed AsyncClient.websocket_connect). - Skip memory API tests when the optional harness_memory dependency is absent via pytest.importorskip. - Remove the invalid diagnostic test tests/integration/test_diag_e2e.py (no assertions; inspected private internals only). Also includes the pre-existing uncommitted orca -> Octop rename across docs, README, LICENSE, Dockerfile and docker assets, as requested.
935 B
935 B
Security Policy
Supported versions
| Version | Supported |
|---|---|
latest release on main |
✅ |
| older releases | best effort |
Reporting a vulnerability
Please do not open a public GitHub issue for security vulnerabilities.
- GitHub Security Advisory: Create advisory
- Email: jubaoliang@gmail.com
We aim to acknowledge reports within 3 business days and provide a fix timeline within 7 business days for confirmed issues.
Scope
Octop is a self-hosted control plane. Operators are responsible for:
- Securing the host and network exposure of
octop run - Rotating JWT secrets and admin credentials
- Reviewing tool guard rules under
~/.octop/security/tool_guard/ - Protecting LLM API keys and IM channel credentials
See docs/configuration.md for deployment hardening guidance.