Fixed: CodeMender updates (v0.11.0)
CodeMender updates (v0.11.0)
This release introduces updates to CodeMender:
• Tiered location configuration: Added support for configuring the service location using the CM_LOCATION environment variable or location in config.yaml (defaulting to global), replacing the --location command-line flag. • CI gate severity validation: Updated cm find to validate --fail-on severity values (CRITICAL, HIGH, MEDIUM, LOW, or NONE) up front instead of silently ignoring misspelled severities. • Sandboxed VCS branching and hardening: Enabled vcs_branch creation and candidate branch cleanup inside the default sandboxed worker for --architecture sessions, and hardened VCS template expansion against shell metacharacters and command injection. • Bug fixes:
Normalized vulnerability type casing and relative file paths during cm find and consensus runs to prevent duplicate findings. • Extended HTTP 429 retry backoff (Retry-After support and up to 60-second quota refill windows) and automatic stream reconnection to improve scan resilience under rate limiting. • Preserved standalone cm find, cm verify, and cm fix sessions on interrupt (SIGINT/SIGTERM) so interrupted runs can be resumed with cm session resume, while still canceling parallel consensus worker operations.
For more information, see the CodeMender documentation.