Skip to content

chore(release): version packages#3810

Merged
williamzujkowski merged 1 commit into
mainfrom
changeset-release/main
Jun 9, 2026
Merged

chore(release): version packages#3810
williamzujkowski merged 1 commit into
mainfrom
changeset-release/main

Conversation

@github-actions

@github-actions github-actions Bot commented Jun 9, 2026

Copy link
Copy Markdown
Contributor

This PR was opened by the Changesets release GitHub action. When you're ready to do a release, you can merge this and the packages will be published to npm automatically. If you're not ready to do a release yet, that's fine, whenever you add more changesets to main, this PR will be updated.

Releases

nexus-agents@2.129.1

Patch Changes

  • #3809 cda2da6 Thanks @williamzujkowski! - security(jobs): write async job sidecar files (<NEXUS_DATA_DIR>/jobs/result-<jobId>.json) with 0600 permissions (#3753, defense-in-depth). The payload may carry job-result data; restricting to the owner matters if NEXUS_DATA_DIR is ever shared across users. Extracted a persistJobRecord helper (DRY over the four writers) that sets the mode on write and chmods after, so the permission holds even when a terminal status overwrites a pre-existing pending file. Not exploitable today (per-user stdio MCP, randomUUID jobIds) — pure hardening.

@williamzujkowski williamzujkowski merged commit efaf475 into main Jun 9, 2026
@williamzujkowski williamzujkowski deleted the changeset-release/main branch June 9, 2026 17:22
@github-project-automation github-project-automation Bot moved this from Backlog to Done in nexus-agents project Jun 9, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant