BREAKING CHANGE: Google Vertex AI is no longer a supported provider. The
CLAUDE_CODE_USE_VERTEX, ANTHROPIC_VERTEX_PROJECT, CLOUD_ML_REGION, and
GOOGLE_APPLICATION_CREDENTIALS environment variables, along with the
use_vertex, vertex_project, and cloud_ml_region config.toml keys, are
removed. Vertex users must switch to Anthropic, AWS Bedrock, or a custom
Anthropic-compatible base URL.
The CLAUDE_CODE_MAX_OUTPUT_TOKENS environment variable and the
max_output_tokens config.toml key are also removed.
* fix(worker): port keygraph shared-core correctness fixes
* refactor(worker): adopt collectors/ and ai/pi/ layout; add task budget cap and cancellation
* refactor(worker): drop inconsistent Collector "Server" suffix
* refactor(worker): drop unused providerConfig/apiKey seams, resolve credentials from env only
* refactor(worker): port oss code_path pattern expansion + external_directory allow
* fix(worker): preserve dotfile paths in code_path avoid patterns (.env no longer stripped to env)
* feat(worker): render Unprocessed Vulnerabilities section in exploit deliverable (align with oss)
* feat(worker): request set_blind_spots for all vuln classes (align auth/ssrf with production prompts)
* refactor(worker): adopt unified permissionSystem* naming and helper layout
* refactor(worker): inline blind_spots into vuln deliverable section array
* chore(worker): drop unused zod dependency (tree is typebox-native)
* fix(worker): normalize base32 TOTP secret to accept padding and whitespace
* refactor(worker): adopt shared toolResult helper and flatSchema naming in collectors
* refactor(worker): use undefined over null in queue-schema builders
* docs(worker): converge renderer/collector doc comments to current pi terminology
* refactor(worker): adopt schema.ts cleanInput/stringEnum helpers in collectors
* feat(worker): converge exploit-collector/renderer with vendored; capture and render overview for blocked findings
* refactor(worker): converge session-tools/pipeline/exploitation-checker with vendored
* refactor(worker): converge task-tool usage reporting with vendored onUsage callback
* refactor(worker): converge structured output onto a submitTool executor channel
* docs(worker): expand exploit-renderer docstring to match shannon-oss
* docs(worker): adopt richer vuln-renderer docstring from shannon-oss
* docs(worker): neutralize billing-detection wording for shannon-oss parity
* fix(worker): verify checkpoint hash in the deliverables clone being reset
* fix(worker): fail fast on malformed exploitation queue JSON
* fix(worker): honor retryable flag when classifying exploitation-queue check failures
* fix(worker): fail fast on corrupted session.json in run-scope validation
* feat(worker): propagate Temporal cancellation signal into agent and auth pi sessions
* fix(worker): mark exploit agent complete when exploitation is skipped so resume skips it
* prompts: drop scan description from executive report prompt
* refactor(worker): add createGenericSubmitTool for raw JSON-schema submit tools
* refactor(worker): gate playwright-cli skill to browser agents via skillsOverride (adopt shannon-oss mechanism)
* docs(worker): correct formatLogTime comment to UTC to match toISOString
* refactor(worker): converge queue-schemas with shannon-oss (guarded count, decl order)
* refactor(worker): converge task-tool with shannon-oss (byte-identical; modelRegistry optional)
* fix(worker): use replaceLiteral for all prompt value insertions to prevent $-mangling
* fix(worker): classify agent execution failures by error type instead of hardcoding validation
* fix(worker): cap auth-failure detail at 250 chars to match shannon-oss
* style(worker): apply biome formatting
* refactor(worker): remove per-session task delegation cap from task tool
* feat: surface report at run root and nest run internals under .shannon
* feat: use plain-language wording in user-facing terminal messages
* feat(cli): guide users to watch scan progress and surface report path on start
* docs: sync run-folder layout and CLI wording across docs and comments
* feat(cli): add version command reporting package version or git SHA
* feat(cli): detect TTY for interactive prompts, color, and progress output
* docs: document --yes flag, version command, and tty module
* fix(cli): FORCE_COLOR precedence and plain uninstall --yes output
* fix(cli): respect empty NO_COLOR
* fix(cli): let NO_COLOR take precedence over FORCE_COLOR
* docs: mark claude-code-router integration as removed
* feat: surface report at run root and nest run internals under .shannon
* feat: use plain-language wording in user-facing terminal messages
* feat(cli): guide users to watch scan progress and surface report path on start
* docs: sync run-folder layout and CLI wording across docs and comments
* feat(cli): add version command reporting package version or git SHA
* feat(cli): detect TTY for interactive prompts, color, and progress output
* docs: document --yes flag, version command, and tty module
* fix(cli): FORCE_COLOR precedence and plain uninstall --yes output
* fix(cli): respect empty NO_COLOR
* fix(cli): let NO_COLOR take precedence over FORCE_COLOR
* docs: mark claude-code-router integration as removed
Apply the same convention from the README pass across the rest of the
repo content so the company and the product are never conflated:
company -> "Keygraph", commercial product -> "the Keygraph platform".
- docs/keygraph-platform.md: retitle "# Keygraph" -> "# Keygraph Platform"
and refer to the product as "the Keygraph platform" throughout (the
page is the platform overview, not a company page).
- docs/coverage-roadmap.md, docs/safety.md: product references updated;
the "Keygraph is not responsible for misuse" line stays as the company.
- llms.txt / llms-full.txt: kept in sync with the README and docs they
mirror, so the combined-context files don't reintroduce the conflation.
No filenames changed.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
The README used "Keygraph" to refer to both the company and the
commercial product, most visibly in "About Keygraph" ("Keygraph...
builds Keygraph"). Refer to the company as "Keygraph" and the
commercial product as "the Keygraph platform" throughout, so the two
are no longer conflated.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Replace the README with the marketing-reviewed version and bring the
project onto one consistent naming scheme:
- "Shannon Lite" -> "Shannon" (the open-source CLI is just Shannon)
- "Shannon Pro" -> "Keygraph" (the commercial platform)
- Rename docs/shannon-pro.md -> docs/keygraph-platform.md and fix the
internal link, matching the README's link target.
- Regenerate llms.txt and llms-full.txt from the updated README and docs.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
* feat(auth): reuse preflight's authenticated session across agents
* fix(preflight): verify saved auth state parses and has cookies or origins
* fix(prompts): strip shared-session block when no auth is configured
* fix(shannon): store shared auth state in the per-session audit dir
* fix(prompts): write stub auth-state in pipeline-testing preflight
* fix(preflight): clear stale auth-state.json before validate-authentication
* fix(preflight): drop auth-state.json on workflow completion
* docs(claude): refresh auth-state.json description for new layout and cleanup
* refactor(prompts): drop unused PLAYWRIGHT_SESSION resolve in login instructions
* style(prompts): collapse verifySavedAuthState signature per biome
* refactor(prompts): require AUTH_STATE_FILE on authenticated runs
* style(prompts): trim numbered-step comments back to step headers