{"service":"tools","entries":[{"service":"tools","sha":"d1a5f87934a038e2c703e138b2ef239be6e1f425","short":"d1a5f87","subject":"Network-tool SSRF guard on openvibe-shared 1.6.0 (platform S9, egress consolidation): the public-address rule, internal names and host normalisation come from openvibe-shared/egress, the rule Live and Events use; createEgress keeps the…","author":"OpenVibers","committed_at":"2026-09-24T04:33:20Z","deployed_at":"2026-09-24T04:33:20.000Z","major":false,"url":"https://github.com/OpenVibers/OpenVibe.Tools/commit/d1a5f87934a038e2c703e138b2ef239be6e1f425","post_id":"pst_01M39313D833G8QVPQ9FGEEF5E"},{"service":"tools","sha":"557de61d3e4f1b81eabfabfe189f4aa7729f66c2","short":"557de61","subject":"Recent tools in the launcher (D31: anonymous and account history): every tool page view puts the tool on top of this browser's ov_recent_tools cookie (first-party, .openvibe.tools, 12 ids, no page script needed across tool hosts); GET…","author":"OpenVibers","committed_at":"2026-09-24T04:23:59Z","deployed_at":"2026-09-24T04:33:20.000Z","major":false,"url":"https://github.com/OpenVibers/OpenVibe.Tools/commit/557de61d3e4f1b81eabfabfe189f4aa7729f66c2","post_id":"pst_01M39313D833G8QVPQ9FGEEF5E"},{"service":"tools","sha":"aa1389ff4e1df9e911d96a2fc86b0b29dabf1f08","short":"aa1389f","subject":"tools.usage: a first record is written with If-Match 0, so two apps creating it at once cannot overwrite each other","author":"OpenVibers","committed_at":"2026-09-24T04:15:17Z","deployed_at":"2026-09-24T04:33:20.000Z","major":false,"url":"https://github.com/OpenVibers/OpenVibe.Tools/commit/aa1389ff4e1df9e911d96a2fc86b0b29dabf1f08","post_id":"pst_01M39313D833G8QVPQ9FGEEF5E"},{"service":"tools","sha":"1a8d739851d6ae5403279e653596ade511d6dd91","short":"1a8d739","subject":"Tools in Search and in people's recent tools (platform S9).","author":"OpenVibers","committed_at":"2026-09-24T04:13:57Z","deployed_at":"2026-09-24T04:33:20.000Z","major":false,"url":"https://github.com/OpenVibers/OpenVibe.Tools/commit/1a8d739851d6ae5403279e653596ade511d6dd91","post_id":"pst_01M39313D833G8QVPQ9FGEEF5E"},{"service":"tools","sha":"597fc6a1a584f9ccdc1eb9d2bec79d6bcbf8ac0f","short":"597fc6a","subject":"Save as paste on the developer tools (platform S9): the output becomes an unlisted OpenVibe.Community paste through the gateway's /api/pastes proxy (as the signed-in person when there is one), linked under the buttons; Clear removes the…","author":"OpenVibers","committed_at":"2026-09-24T04:13:51Z","deployed_at":"2026-09-24T04:33:20.000Z","major":false,"url":"https://github.com/OpenVibers/OpenVibe.Tools/commit/597fc6a1a584f9ccdc1eb9d2bec79d6bcbf8ac0f","post_id":"pst_01M39313D833G8QVPQ9FGEEF5E"},{"service":"tools","sha":"176a7b8be92cccf47b16415ddf0152246b280d7a","short":"176a7b8","subject":"Tools API for developers (platform S10): GET /api/v1/openapi.json, OpenAPI 3.1 generated from the tool descriptors (registry, one run path per tool with its input schema and an example, the jobs facade, problem responses, bearer auth); a…","author":"OpenVibers","committed_at":"2026-09-24T03:49:42Z","deployed_at":"2026-09-24T04:33:20.000Z","major":false,"url":"https://github.com/OpenVibers/OpenVibe.Tools/commit/176a7b8be92cccf47b16415ddf0152246b280d7a","post_id":"pst_01M39313D833G8QVPQ9FGEEF5E"},{"service":"tools","sha":"b0aada2c3887b009176ceb934e7df98faa666cae","short":"b0aada2","subject":"SECURITY.md: how to report a vulnerability (contact@openvibe.network, 7-day reply, scope, supported versions)","author":"OpenVibers","committed_at":"2026-09-24T02:27:54Z","deployed_at":"2026-09-24T04:33:20.000Z","major":false,"url":"https://github.com/OpenVibers/OpenVibe.Tools/commit/b0aada2c3887b009176ceb934e7df98faa666cae","post_id":"pst_01M39313D833G8QVPQ9FGEEF5E"},{"service":"tools","sha":"5ac8309e5abfa74242792b6aee1662b9a85f989a","short":"5ac8309","subject":"openvibe-contracts v0.33.1 (gateway, img, audio, docs) and openvibe-shared v1.5.1 (every app). Descriptors now publish the catalogue's keywords (every tool; what ?q= matches) and each API tool's example as examples[] (145 tools; a job…","author":"OpenVibers","committed_at":"2026-09-24T02:07:02Z","deployed_at":"2026-09-24T04:33:20.000Z","major":false,"url":"https://github.com/OpenVibers/OpenVibe.Tools/commit/5ac8309e5abfa74242792b6aee1662b9a85f989a","post_id":"pst_01M39313D833G8QVPQ9FGEEF5E"},{"service":"tools","sha":"48605fa4c791c5ec5fc3dea321f88ce79332ea4a","short":"48605fa","subject":"Uniform run API, jobs facade, deprecation headers and the Origin check (S6, ADR-027). POST /api/v1/tools/:id/run takes tools.run-request@1 as JSON or multipart exactly as openvibe-sdk v0.6.0 sends it (uploads as file parts; input, files…","author":"OpenVibers","committed_at":"2026-09-24T01:59:23Z","deployed_at":"2026-09-24T04:33:20.000Z","major":false,"url":"https://github.com/OpenVibers/OpenVibe.Tools/commit/48605fa4c791c5ec5fc3dea321f88ce79332ea4a","post_id":"pst_01M39313D833G8QVPQ9FGEEF5E"},{"service":"tools","sha":"fcc2fe0f2eb55e75b327f0980a6869c85143fbe8","short":"fcc2fe0","subject":"Worker threads for sharp and pdf-lib (S5): apps/_shared/jobs/pool.js runs img's image operations and docs' pdf-lib tools in worker_threads, so a large merge or conversion never blocks the event loop (/api/health, the job routes and every…","author":"OpenVibers","committed_at":"2026-09-24T01:15:13Z","deployed_at":"2026-09-24T04:33:20.000Z","major":false,"url":"https://github.com/OpenVibers/OpenVibe.Tools/commit/fcc2fe0f2eb55e75b327f0980a6869c85143fbe8","post_id":"pst_01M39313D833G8QVPQ9FGEEF5E"},{"service":"tools","sha":"13b79ce0a506a5ccdbd03486075f19ec25c82a82","short":"13b79ce","subject":"Docs: Protect, Unlock and the password page count give qpdf its password arguments on stdin (@-) instead of an @file argument file. qpdf 12.3.2 on the host did not expand @file (it opened '@/tmp/…/args' as a PDF), so every Protect PDF in…","author":"OpenVibers","committed_at":"2026-09-24T00:51:16Z","deployed_at":"2026-09-24T04:33:20.000Z","major":false,"url":"https://github.com/OpenVibers/OpenVibe.Tools/commit/13b79ce0a506a5ccdbd03486075f19ec25c82a82","post_id":"pst_01M39313D833G8QVPQ9FGEEF5E"},{"service":"tools","sha":"ef14d5561ad3f74ebfab463d48c5825a7d157d0c","short":"ef14d55","subject":"Guard deploy and docs: systemd resource bounds (MemoryMax 2G img/audio/docs, 1G yt, 768M gateway/text/maps/food; TasksMax 256; Nice 5 for img, audio, docs, yt) and ReadWritePaths for the gateway's data/ (its guard.db); deploy.sh creates…","author":"OpenVibers","committed_at":"2026-09-24T00:22:36Z","deployed_at":"2026-09-24T04:33:20.000Z","major":false,"url":"https://github.com/OpenVibers/OpenVibe.Tools/commit/ef14d5561ad3f74ebfab463d48c5825a7d157d0c","post_id":"pst_01M39313D833G8QVPQ9FGEEF5E"},{"service":"tools","sha":"6818bcc73a1949523fa5f4d88d5a7143f9b9e7b9","short":"6818bcc","subject":"Tools guard (apps/_shared/guard), used by the gateway and every satellite and driven by the tool descriptors: one caller resolver replaces the four copied auth.js files and the job routes' owner logic (service/app principals by token, aud…","author":"OpenVibers","committed_at":"2026-09-24T00:22:29Z","deployed_at":"2026-09-24T04:33:20.000Z","major":false,"url":"https://github.com/OpenVibers/OpenVibe.Tools/commit/6818bcc73a1949523fa5f4d88d5a7143f9b9e7b9","post_id":"pst_01M39313D833G8QVPQ9FGEEF5E"},{"service":"tools","sha":"902b27ec5136ae63556a427b11fe0b54b3cc9238","short":"902b27e","subject":"gitleaks: allow the two hand-made sample JWTs (exp 1 / signature x, sub x / signature sig) in the JWT tool's descriptor example and engine test, matched on path and value","author":"OpenVibers","committed_at":"2026-09-23T23:29:38Z","deployed_at":"2026-09-23T23:29:38.000Z","major":false,"url":"https://github.com/OpenVibers/OpenVibe.Tools/commit/902b27ec5136ae63556a427b11fe0b54b3cc9238","post_id":null},{"service":"tools","sha":"4cc923e4a705c3c153ea1b6787a7513133c47aef","short":"4cc923e","subject":"Tool registry API (capability tools.tool.read, ADR-027): GET /api/v1/tools answers tools.tool-list@1 with schemas as $refs (filters ?family= ?execution= ?api= ?status= ?q=, comma lists; a bad value is 400 tools.query.invalid), GET…","author":"OpenVibers","committed_at":"2026-09-23T23:23:38Z","deployed_at":"2026-09-23T23:23:38.000Z","major":false,"url":"https://github.com/OpenVibers/OpenVibe.Tools/commit/4cc923e4a705c3c153ea1b6787a7513133c47aef","post_id":null},{"service":"tools","sha":"d04dbdac6ce5ab0024838c42acc4bbb075195607","short":"d04dbda","subject":"Tool descriptors: one tools.tool@1 descriptor per catalogue tool (169), kept as pure data next to the code that runs it and merged by the gateway (ADR-027). apps/{img,audio,docs,text,yt,maps}/server/descriptors.js and…","author":"OpenVibers","committed_at":"2026-09-23T23:23:29Z","deployed_at":"2026-09-23T23:23:29.000Z","major":false,"url":"https://github.com/OpenVibers/OpenVibe.Tools/commit/d04dbdac6ce5ab0024838c42acc4bbb075195607","post_id":null},{"service":"tools","sha":"bc5d92e0d991f4bfa24c44ee135391b707386901","short":"bc5d92e","subject":"Browser tools get server engines: the pure transforms behind the dev and text pages move out of the pages into engine files the pages load and Node can require, so a tool API can run the page's own code (ADR-027). public/js/dev-engine.js…","author":"OpenVibers","committed_at":"2026-09-23T23:23:14Z","deployed_at":"2026-09-23T23:23:14.000Z","major":false,"url":"https://github.com/OpenVibers/OpenVibe.Tools/commit/bc5d92e0d991f4bfa24c44ee135391b707386901","post_id":null},{"service":"tools","sha":"c98edd47a41a4a041ab462c72d8d221192295243","short":"c98edd4","subject":"openvibe-contracts v0.33.0 (tools.tool@1, tools.tool-list@1, tools.run@1, tools.job@1 and contracts.tools: checkDescriptor, checkList, jobInput, ADR-027): img, audio and docs move from v0.30.1 (their jobs and tools.job.* events are…","author":"OpenVibers","committed_at":"2026-09-23T23:00:28Z","deployed_at":"2026-09-23T23:00:28.000Z","major":false,"url":"https://github.com/OpenVibers/OpenVibe.Tools/commit/c98edd47a41a4a041ab462c72d8d221192295243","post_id":null},{"service":"tools","sha":"a5fd2dd0889050d860f2a29a83813e7c10c06a92","short":"a5fd2dd","subject":"Net copy: the curl and HTTP status pages say what they do. Both send one HEAD request from our server and show the status line and headers; the curl page promised any method, custom headers and a response body, and the status page a full…","author":"OpenVibers","committed_at":"2026-09-23T22:43:20Z","deployed_at":"2026-09-23T22:43:20.000Z","major":false,"url":"https://github.com/OpenVibers/OpenVibe.Tools/commit/a5fd2dd0889050d860f2a29a83813e7c10c06a92","post_id":null},{"service":"tools","sha":"d2c393111aa830f998a45cc1e4c976ba9eae4524","short":"d2c3931","subject":"Net: the IPv4 and IPv6 pages do what they say, and every net tool has a renderer. The consistency test now also checks that net.html can render each tool's endpoint, which found two pages that showed raw JSON: IPv4 promised a CIDR subnet…","author":"OpenVibers","committed_at":"2026-09-23T22:42:32Z","deployed_at":"2026-09-23T22:42:32.000Z","major":false,"url":"https://github.com/OpenVibers/OpenVibe.Tools/commit/d2c393111aa830f998a45cc1e4c976ba9eae4524","post_id":null}],"next":"MjAyNi0wOS0yM1QyMjo0MjozMi4wMDBafDc1OA","latest_post":{"id":"pst_01M39313D833G8QVPQ9FGEEF5E","title":"Patch notes: 120 changes across 18 sites","url":"https://openvibe.blog/@openvibe/patch-notes-120-changes-across-18-sites","published_at":1790232792495,"entries":120},"posts":[{"id":"pst_01M39313D833G8QVPQ9FGEEF5E","title":"Patch notes: 120 changes across 18 sites","url":"https://openvibe.blog/@openvibe/patch-notes-120-changes-across-18-sites","published_at":1790232792495,"entries":120}]}