Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
17 commits
Select commit Hold shift + click to select a range
4d526f5
perf(issues): fetch the issue list's first page in one request (#9088)
27Bslash6 Oct 7, 2026
c4fea18
fix(agent): keep an Antigravity answer a trailing transport error cut…
seacen Oct 7, 2026
bb14e87
feat(issues): add multi_text and multi_url custom property types (MUL…
b0o0wen Oct 7, 2026
e0f84dd
fix(docs): use stable self-host upgrade references (MUL-7897) (#9091)
SATA260 Oct 7, 2026
647b18b
fix(search): recognize digit-containing issue prefixes across search …
Bohan-J Oct 8, 2026
fbd3470
MUL-7875 fix(daemon): preserve Hermes sessions across worktrees (ZIC-…
vicksiyi Oct 8, 2026
8db6cfe
fix(desktop): align navigation and tab toolbar content (#9127)
forrestchang Oct 8, 2026
13520a0
fix(cli): keep member names off free-form property lists (#9093)
SATA260 Oct 8, 2026
5063fc9
MUL-7869: fix(agent): fail kimi runs whose wire log records a failed …
ggbdpq Oct 8, 2026
00e24a8
fix(agent): create fresh OMP sessions without resume (#9131)
vicksiyi Oct 9, 2026
3bacc41
MUL-7573 fix(lark): clear the Typing reaction without trusting in-pro…
WitMiao Oct 9, 2026
e5d4acf
fix(ci): require Go 1.26.9 security patches (#9143)
Bohan-J Oct 9, 2026
c76a012
MUL-7936 fix(onboarding): replace archived Kimi CLI with Kimi Code CL…
xiaoxiaowesley Oct 9, 2026
cf6a8ca
MUL-7842 fix: patch Next.js GHSA-vcvr-r3jv-pc5j (#9007)
r05323028 Oct 9, 2026
10a7e51
MUL-7797 fix(daemon): detect the Codex CLI nested in ChatGPT.app (#8944)
SATA260 Oct 9, 2026
e7742b0
MUL-7776: fix(api): stop returning raw error text in 500 responses (#…
tauanbinato Oct 10, 2026
903c083
chore: merge upstream main e7742b052be2
Oct 10, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
8 changes: 8 additions & 0 deletions .github/RELEASING.md
Original file line number Diff line number Diff line change
Expand Up @@ -10,6 +10,14 @@ formulae, and container images.
The verification job runs the Go tests and `govulncheck` before any publishing
job starts. The vulnerability scan is fail-closed by default.

CI and release jobs require Go `~1.26.9`: at least 1.26.9, while accepting
newer 1.26 patches. This security floor is independent of the development
minimum in `server/go.mod`. A plain `1.26.x` can resolve to an older patch
while the `setup-go` version manifest catches up with an official Go release.
When raising the security floor, update all Go workflows and the pinned
Go builder image in `Dockerfile` together so shipped binaries also receive
the fixes.

## Emergency vulnerability-scan bypass

Use the bypass only when `govulncheck` itself or its live vulnerability database
Expand Down
24 changes: 12 additions & 12 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -72,7 +72,7 @@ jobs:
- name: Setup Go
uses: actions/setup-go@v5
with:
go-version: "1.26.x"
go-version: "~1.26.9"
check-latest: true
cache-dependency-path: server/go.sum

Expand Down Expand Up @@ -348,9 +348,9 @@ jobs:
id: go
uses: actions/setup-go@v5
with:
# Deliberately independent from the minimum patch in server/go.mod:
# CI follows the newest 1.26 patch available to setup-go.
go-version: "1.26.x"
# Keep the security floor even when the setup-go manifest lags;
# continue accepting newer patches within Go 1.26.
go-version: "~1.26.9"
check-latest: true
cache: false

Expand Down Expand Up @@ -450,7 +450,7 @@ jobs:
id: go
uses: actions/setup-go@v5
with:
go-version: "1.26.x"
go-version: "~1.26.9"
check-latest: true
cache: false

Expand Down Expand Up @@ -488,9 +488,9 @@ jobs:
- name: Setup Go
uses: actions/setup-go@v5
with:
# Deliberately independent from the minimum patch in server/go.mod:
# CI follows the newest 1.26 patch available to setup-go.
go-version: "1.26.x"
# Keep the security floor even when the setup-go manifest lags;
# continue accepting newer patches within Go 1.26.
go-version: "~1.26.9"
check-latest: true
cache-dependency-path: server/go.sum

Expand Down Expand Up @@ -527,9 +527,9 @@ jobs:
- name: Setup Go
uses: actions/setup-go@v5
with:
# Deliberately independent from the minimum patch in server/go.mod:
# CI follows the newest 1.26 patch available to setup-go.
go-version: "1.26.x"
# Keep the security floor even when the setup-go manifest lags;
# continue accepting newer patches within Go 1.26.
go-version: "~1.26.9"
check-latest: true
cache-dependency-path: server/go.sum

Expand Down Expand Up @@ -788,7 +788,7 @@ jobs:
- uses: actions/checkout@v6
- uses: actions/setup-go@v5
with:
go-version: "1.26.x"
go-version: "~1.26.9"
cache-dependency-path: server/go.sum
- name: Verify Cursor background lifecycle and watchdog races
shell: bash
Expand Down
6 changes: 3 additions & 3 deletions .github/workflows/desktop-smoke.yml
Original file line number Diff line number Diff line change
Expand Up @@ -30,9 +30,9 @@ jobs:
- name: Setup Go
uses: actions/setup-go@v5
with:
# Deliberately independent from the minimum patch in server/go.mod:
# CI follows the newest 1.26 patch available to setup-go.
go-version: "1.26.x"
# Keep the security floor even when the setup-go manifest lags;
# continue accepting newer patches within Go 1.26.
go-version: "~1.26.9"
check-latest: true
cache-dependency-path: server/go.sum

Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/openclaw-config-smoke.yml
Original file line number Diff line number Diff line change
Expand Up @@ -35,7 +35,7 @@ jobs:
- name: Setup Go
uses: actions/setup-go@v5
with:
go-version: "1.26.x"
go-version: "~1.26.9"
check-latest: true
cache-dependency-path: server/go.sum

Expand Down
18 changes: 9 additions & 9 deletions .github/workflows/release.yml
Original file line number Diff line number Diff line change
Expand Up @@ -54,9 +54,9 @@ jobs:
- name: Setup Go
uses: actions/setup-go@v5
with:
# Deliberately independent from the minimum patch in server/go.mod:
# releases follow the newest 1.26 patch available to setup-go.
go-version: "1.26.x"
# Keep the security floor even when the setup-go manifest lags;
# continue accepting newer patches within Go 1.26.
go-version: "~1.26.9"
check-latest: true
cache-dependency-path: server/go.sum

Expand Down Expand Up @@ -98,9 +98,9 @@ jobs:
- name: Setup Go
uses: actions/setup-go@v5
with:
# Deliberately independent from the minimum patch in server/go.mod:
# releases follow the newest 1.26 patch available to setup-go.
go-version: "1.26.x"
# Keep the security floor even when the setup-go manifest lags;
# continue accepting newer patches within Go 1.26.
go-version: "~1.26.9"
check-latest: true
cache-dependency-path: server/go.sum

Expand Down Expand Up @@ -424,9 +424,9 @@ jobs:
- name: Setup Go
uses: actions/setup-go@v5
with:
# Deliberately independent from the minimum patch in server/go.mod:
# releases follow the newest 1.26 patch available to setup-go.
go-version: "1.26.x"
# Keep the security floor even when the setup-go manifest lags;
# continue accepting newer patches within Go 1.26.
go-version: "~1.26.9"
check-latest: true
cache-dependency-path: server/go.sum

Expand Down
2 changes: 1 addition & 1 deletion CONTRIBUTING.md
Original file line number Diff line number Diff line change
Expand Up @@ -44,7 +44,7 @@ This keeps Docker simple while still isolating schema and data.

- Node.js `22`
- `pnpm` `10.28.2`
- Go `1.26.6`
- Go `1.26.9`
- Docker

## Important Rules
Expand Down
2 changes: 1 addition & 1 deletion Dockerfile
Original file line number Diff line number Diff line change
@@ -1,5 +1,5 @@
# --- Build stage ---
FROM golang:1.26-alpine AS builder
FROM golang:1.26.9-alpine AS builder

RUN apk add --no-cache git

Expand Down
2 changes: 1 addition & 1 deletion README.md
Original file line number Diff line number Diff line change
Expand Up @@ -246,7 +246,7 @@ The docs are also available in [简体中文](https://multica.ai/docs/zh), [日

Contributors: start with the [Contributing Guide](CONTRIBUTING.md).

**Prerequisites:** [Node.js](https://nodejs.org/) 22, [pnpm](https://pnpm.io/) 10.28.2, [Go](https://go.dev/) 1.26.6, [Docker](https://www.docker.com/)
**Prerequisites:** [Node.js](https://nodejs.org/) 22, [pnpm](https://pnpm.io/) 10.28.2, [Go](https://go.dev/) 1.26.9, [Docker](https://www.docker.com/)

```bash
make dev
Expand Down
2 changes: 1 addition & 1 deletion README.zh.md
Original file line number Diff line number Diff line change
Expand Up @@ -238,7 +238,7 @@ Multica 不自带模型。它驱动的是你本来就装好、登录好的那些

想参与贡献,先看[贡献指南](CONTRIBUTING.md)。

**环境要求:**[Node.js](https://nodejs.org/) 22、[pnpm](https://pnpm.io/) 10.28.2、[Go](https://go.dev/) 1.26.6、[Docker](https://www.docker.com/)
**环境要求:**[Node.js](https://nodejs.org/) 22、[pnpm](https://pnpm.io/) 10.28.2、[Go](https://go.dev/) 1.26.9、[Docker](https://www.docker.com/)

```bash
make dev
Expand Down
2 changes: 1 addition & 1 deletion SELF_HOSTING_ADVANCED.md
Original file line number Diff line number Diff line change
Expand Up @@ -428,7 +428,7 @@ If you are upgrading from a binary that pre-dates MUL-2957 (or the auto-hook fai

If you prefer to build and run services manually:

**Prerequisites:** Go 1.26.6, Node.js 22, pnpm 10.28.2, PostgreSQL 17 — a stock install is enough, see [Database Setup](#database-setup).
**Prerequisites:** Go 1.26.9, Node.js 22, pnpm 10.28.2, PostgreSQL 17 — a stock install is enough, see [Database Setup](#database-setup).

```bash
# Start your PostgreSQL (or use: docker compose up -d postgres)
Expand Down
3 changes: 2 additions & 1 deletion apps/desktop/src/main/index.ts
Original file line number Diff line number Diff line change
Expand Up @@ -312,7 +312,8 @@ function createWindow(): BrowserWindow {
minWidth: 900,
minHeight: 600,
titleBarStyle: "hiddenInset",
trafficLightPosition: { x: 16, y: 17 },
// Center the native controls in the main window's 40px tab toolbar.
trafficLightPosition: { x: 16, y: 13 },
show: false,
autoHideMenuBar: true,
// Windows/Linux pick up the window/taskbar icon from this option.
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -37,7 +37,7 @@ import { TabContent } from "./tab-content";
import { WindowOverlay } from "./window-overlay";
import { WindowToolbar, WINDOW_TOOLBAR_CLEARANCE } from "./window-toolbar";

const TOP_BAR_HEIGHT_CLASS = "h-12";
const TOP_BAR_HEIGHT_CLASS = "h-10";
const toolbarMotion = {
type: "spring",
stiffness: 420,
Expand Down
17 changes: 10 additions & 7 deletions apps/desktop/src/renderer/src/components/tab-bar.tsx
Original file line number Diff line number Diff line change
Expand Up @@ -307,7 +307,10 @@ function SortableTabItem({
title={tab.pinned ? `${title} (pinned)` : undefined}
style={{ WebkitAppRegion: "no-drag" } as React.CSSProperties}
className={cn(
"group relative flex size-full min-w-0 items-center gap-1.5 px-2.5 text-caption transition-colors",
// The 36px frame contains a centered 32px content row and a 4px
// bottom connector. Keep the connector clickable without letting it
// shift the icon, title, or hover actions below the toolbar center.
"group relative flex size-full min-w-0 items-center gap-1.5 px-2.5 pb-1 text-caption transition-colors",
"select-none cursor-default",
isActive
? "font-medium text-foreground"
Expand Down Expand Up @@ -392,7 +395,7 @@ function SortableTabItem({
) : (
<span
aria-hidden
className="pointer-events-none absolute inset-x-0.5 top-1 bottom-1 rounded-lg bg-sidebar-accent opacity-0 transition-opacity group-hover/tab:opacity-100"
className="pointer-events-none absolute inset-x-0.5 top-0 bottom-1 rounded-lg bg-sidebar-accent opacity-0 transition-opacity group-hover/tab:opacity-100"
/>
)}
{showSeparator && (
Expand All @@ -401,7 +404,7 @@ function SortableTabItem({
// arrives rather than lingering 2px off its rounded edge.
<span
aria-hidden
className="pointer-events-none absolute left-0 top-1/2 h-4 w-px -translate-y-1/2 bg-surface-border transition-opacity group-hover/tab:opacity-0 prev-tab-hover:opacity-0"
className="pointer-events-none absolute left-0 top-2 h-4 w-px bg-surface-border transition-opacity group-hover/tab:opacity-0 prev-tab-hover:opacity-0"
/>
)}
<ContextMenu>
Expand Down Expand Up @@ -451,7 +454,7 @@ function SortableTabItem({
{showAddedHighlight && (
<motion.span
aria-hidden
className="pointer-events-none absolute inset-x-0.5 top-1 bottom-1 rounded-lg bg-primary/10 ring-1 ring-inset ring-primary/20"
className="pointer-events-none absolute inset-x-0.5 top-0 bottom-1 rounded-lg bg-primary/10 ring-1 ring-inset ring-primary/20"
initial={{ opacity: shouldReduceMotion ? 0.25 : 0.65 }}
animate={{ opacity: 0 }}
transition={{ duration: shouldReduceMotion ? 0.16 : 0.42 }}
Expand Down Expand Up @@ -497,7 +500,7 @@ function NewTabEdgeFeedback({
key={`${signal.tabId}-${signal.sequence}`}
aria-hidden
data-new-tab-edge-feedback="true"
className="pointer-events-none absolute top-4 bottom-1 right-0 z-20 w-8 rounded-r-lg bg-gradient-to-l from-primary/35 via-primary/10 to-transparent"
className="pointer-events-none absolute top-1 bottom-1 right-0 z-20 w-8 rounded-r-lg bg-gradient-to-l from-primary/35 via-primary/10 to-transparent"
initial={{
opacity: shouldReduceMotion ? 0.45 : 0,
x: shouldReduceMotion ? 0 : 4,
Expand Down Expand Up @@ -547,7 +550,7 @@ function NewTabButton() {
aria-label="New tab"
title="New tab"
style={{ WebkitAppRegion: "no-drag" } as React.CSSProperties}
className="mb-1 flex size-7 shrink-0 items-center justify-center self-end rounded-md text-faint-foreground transition-colors hover:bg-muted/50 hover:text-muted-foreground"
className="flex size-7 shrink-0 items-center justify-center self-center rounded-md text-faint-foreground transition-colors hover:bg-muted/50 hover:text-muted-foreground"
>
<Plus className="size-3.5" />
</button>
Expand Down Expand Up @@ -693,7 +696,7 @@ export function TabBar() {
unpinnedCount > 0 && (
<div
aria-hidden
className="mx-1 mb-2.5 h-4 w-px shrink-0 self-end bg-surface-border"
className="mx-1 mb-3 h-4 w-px shrink-0 self-end bg-surface-border"
/>
)}
</Fragment>
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -246,7 +246,7 @@ export function WindowToolbar() {
<div
data-slot="window-toolbar"
data-sidebar-resize-consumer
className="fixed left-0 top-0 z-30 flex h-12 shrink-0 items-center pr-3"
className="fixed left-0 top-0 z-30 flex h-10 shrink-0 items-center pr-3"
style={
{
WebkitAppRegion: "drag",
Expand Down
2 changes: 1 addition & 1 deletion apps/docs/content/docs/cli.ja.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -250,7 +250,7 @@ CLI の設定ファイルには、あなたとして Multica にアクセスで
| | `status <id> <status>` | プロジェクトのステータスを変更 | |
| | `resource list/add/update/remove` | プロジェクトの追加リソースを管理 | `--type`、`--url`、`--local-path`、`--daemon-id`、`--execution-mode`(ローカルディレクトリの `in_place` / `worktree`) |
| `label` | `list/get/create/update/delete` | ワークスペースのラベルを管理 | `list`: `--resource-type`(`issue` または `skill`)、`--full-id`;`create`: `--name`、`--color`、`--resource-type`(`issue` または `skill`)、`--description` |
| `property` | `list/get/create/update/archive/unarchive` | ワークスペースのカスタムプロパティを管理 | `create`: `--name`、`--type`(`text`、`number`、`select`、`multi_select`、`date`、`checkbox`、`url`、`actor`、`multi_actor`)、`--option`(繰り返し可、select 系のみ);`list`: `--include-archived`;タイプは作成後に変更できません |
| `property` | `list/get/create/update/archive/unarchive` | ワークスペースのカスタムプロパティを管理 | `create`: `--name`、`--type`(`text`、`number`、`select`、`multi_select`、`date`、`checkbox`、`url`、`actor`、`multi_actor`、`multi_text`、`multi_url`)、`--option`(繰り返し可、select 系のみ);`list`: `--include-archived`;タイプは作成後に変更できません |
| `agent` | `list/get/create/update/archive/restore` | エージェントを管理 | `--name`、`--runtime-id`(`create` では必須)、`--instructions`、`--conversation-starters`、`--model`、`--thinking-level`、`--mcp-config`、`--permission-mode`、`--max-concurrent-tasks` |
| | `copy <agent-id>` | 新しいエージェントとして複製。元のエージェントは変更されません | `--name`(デフォルトは元の名前 + ` (copy)`)、`--runtime-id`(別のランタイムへ複製する場合は `--model` の同時指定が必須)、`--no-skills`;`custom_env`、`mcp_config`、`runtime_config` などの機密設定は複製されないため、`create` と同じフラグで再指定してください |
| | `tasks <id>` | エージェントの実行を表示 | |
Expand Down
2 changes: 1 addition & 1 deletion apps/docs/content/docs/cli.ko.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -250,7 +250,7 @@ CLI 설정 파일에는 사용자를 대신해 Multica에 접근할 수 있는 t
| | `status <id> <status>` | 프로젝트 상태 변경 | |
| | `resource list/add/update/remove` | 프로젝트 추가 리소스 관리 | `--type`, `--url`, `--local-path`, `--daemon-id`, `--execution-mode`(로컬 디렉터리의 `in_place` / `worktree`) |
| `label` | `list/get/create/update/delete` | 워크스페이스 라벨 관리 | `list`: `--resource-type`(`issue` 또는 `skill`), `--full-id`; `create`: `--name`, `--color`, `--resource-type`(`issue` 또는 `skill`), `--description` |
| `property` | `list/get/create/update/archive/unarchive` | 워크스페이스 사용자 지정 속성 관리 | `create`: `--name`, `--type`(`text`, `number`, `select`, `multi_select`, `date`, `checkbox`, `url`, `actor`, `multi_actor`), `--option`(반복 가능, select 유형만). `list`: `--include-archived`. 유형은 생성 후 변경 불가 |
| `property` | `list/get/create/update/archive/unarchive` | 워크스페이스 사용자 지정 속성 관리 | `create`: `--name`, `--type`(`text`, `number`, `select`, `multi_select`, `date`, `checkbox`, `url`, `actor`, `multi_actor`, `multi_text`, `multi_url`), `--option`(반복 가능, select 유형만). `list`: `--include-archived`. 유형은 생성 후 변경 불가 |
| `agent` | `list/get/create/update/archive/restore` | 에이전트 관리 | `--name`, `--runtime-id`(`create`에서 필수), `--instructions`, `--conversation-starters`, `--model`, `--thinking-level`, `--mcp-config`, `--permission-mode`, `--max-concurrent-tasks` |
| | `copy <agent-id>` | 원래 에이전트에 영향 없이 새 에이전트로 복사 | `--name`(기본값은 원래 이름 + ` (copy)`), `--runtime-id`(다른 런타임으로 복사할 때 `--model`도 필수), `--no-skills`. `custom_env`, `mcp_config`, `runtime_config` 같은 기밀 설정은 복사되지 않으며 `create`와 같은 flag로 다시 제공해야 함 |
| | `tasks <id>` | 에이전트 실행 확인 | |
Expand Down
2 changes: 1 addition & 1 deletion apps/docs/content/docs/cli.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -273,7 +273,7 @@ The tables below cover every current top-level command, grouped the way the CLI
| | `status <id> <status>` | Change project status | |
| | `resource list/add/update/remove` | Manage project resources | `--type`, `--url`, `--local-path`, `--daemon-id`, `--execution-mode` (`in_place` / `worktree` for a local directory) |
| `label` | `list/get/create/update/delete` | Manage workspace labels | `list`: `--resource-type` (`issue` or `skill`), `--full-id`; `create`: `--name`, `--color`, `--resource-type` (`issue` or `skill`), `--description` |
| `property` | `list/get/create/update/archive/unarchive` | Manage workspace custom properties | `create`: `--name`, `--type` (`text`, `number`, `select`, `multi_select`, `date`, `checkbox`, `url`, `actor`, `multi_actor`), `--option` (repeatable, select types only); `list`: `--include-archived`; the type cannot be changed after creation |
| `property` | `list/get/create/update/archive/unarchive` | Manage workspace custom properties | `create`: `--name`, `--type` (`text`, `number`, `select`, `multi_select`, `date`, `checkbox`, `url`, `actor`, `multi_actor`, `multi_text`, `multi_url`), `--option` (repeatable, select types only); `list`: `--include-archived`; the type cannot be changed after creation |
| `agent` | `list/get/create/update/archive/restore` | Manage agents | `--name`, `--runtime-id` (required for `create`), `--instructions`, `--conversation-starters`, `--model`, `--thinking-level`, `--mcp-config`, `--permission-mode`, `--max-concurrent-tasks` |
| | `copy <agent-id>` | Copy into a new agent; the original is untouched | `--name` (defaults to the original name plus ` (copy)`), `--runtime-id` (copying to another runtime also requires `--model`), `--no-skills`; secret configuration such as `custom_env`, `mcp_config`, and `runtime_config` is not copied — re-provide it with the same flags as `create` |
| | `tasks <id>` | View an agent's runs | |
Expand Down
Loading
Loading