> ## Documentation Index
> Fetch the complete documentation index at: https://chatcli.edilsonfreitas.com/llms.txt
> Use this file to discover all available pages before exploring further.

# v1.215.2

> bind cost, CCR and pending memory stores to their path; fail closed when the credential key cannot be read; classify the exact exec command for the read-only auto-allow

<div className="cc-release-meta">
  <span>Lançada em 11 de outubro de 2026</span>
  <span>26 correções</span>
  <a href="https://github.com/diillson/chatcli/releases/tag/v1.215.2">Release no GitHub</a>
  <a href="https://github.com/diillson/chatcli/compare/v1.215.1...v1.215.2">Comparar mudanças</a>
</div>

<Note>
  As entradas vêm do changelog do projeto e ficam em inglês, como foram escritas nos commits.
</Note>

## Correções

* <span className="cc-scope">atrest</span> bind cost, CCR and pending memory stores to their path <span className="cc-refs">[f535b2c](https://github.com/diillson/chatcli/commit/f535b2c63f9ec75030eed7e7021a0b78ba6528ec)</span>
* <a className="cc-scope" href="/pt/providers/oauth-authentication">auth</a> fail closed when the credential key cannot be read <span className="cc-refs">[45a9a5f](https://github.com/diillson/chatcli/commit/45a9a5faa0daa45625278d0b83c0d16360e7fcab)</span>
* <a className="cc-scope" href="/pt/usage/coder-mode">coder</a> classify the exact exec command for the read-only auto-allow <span className="cc-refs">[f750160](https://github.com/diillson/chatcli/commit/f750160648a01903615cf5013a08e41f46b454f4)</span>
* <a className="cc-scope" href="/pt/usage/coder-mode">coder</a> close command and path injection in the coder tools <span className="cc-refs">[2ebbc06](https://github.com/diillson/chatcli/commit/2ebbc06a689c4a74ab213a7abea6d03550df2131)</span>
* <a className="cc-scope" href="/pt/gateway/chat-gateway">gateway</a> require a sender allowlist on every chat adapter <span className="cc-refs">[0621549](https://github.com/diillson/chatcli/commit/0621549602cb0346ca3dd424ea73068c1a85eaa1)</span>
* <a className="cc-scope" href="/pt/gateway/chat-gateway">gateway</a> sign webhook traffic and guard attachment URLs <span className="cc-refs">[24cf554](https://github.com/diillson/chatcli/commit/24cf554eadcfc88ab10febbc8214c22023b4cdd4)</span>
* <a className="cc-scope" href="/pt/extensions/mcp-integration">mcp</a> bind MCP OAuth tokens to the configured server URL <span className="cc-refs">[951fe24](https://github.com/diillson/chatcli/commit/951fe24b8e090eae86bf8edb13a788916b1e6c91)</span>
* <a className="cc-scope" href="/pt/extensions/mcp-integration">mcp</a> validate the OAuth authorization server and confine MCP redirects <span className="cc-refs">[352c54c](https://github.com/diillson/chatcli/commit/352c54cd1064f76415c79689cc7da64372c374e7)</span>
* <a className="cc-scope" href="/pt/kubernetes/k8s-operator">operator</a> enforce trust boundaries for the AIOps pipeline <span className="cc-refs">[51466b2](https://github.com/diillson/chatcli/commit/51466b29b2909bfb0438691ab75b79b07a812753)</span>
* <a className="cc-scope" href="/pt/extensions/plugin-system">plugins</a> execute the verified bytes and never let a plugin shadow a built-in <span className="cc-refs">[435528d](https://github.com/diillson/chatcli/commit/435528d29b25ff59f2432b24f2e153c10c9550c3)</span>
* <a className="cc-scope" href="/pt/extensions/plugin-system">plugins</a> guard browser navigation and harden web tool egress <span className="cc-refs">[f380090](https://github.com/diillson/chatcli/commit/f38009024ad42e875810932e99e69643d742313a)</span>
* <span className="cc-scope">provision</span> fill in the pinned digests of the engine and model archives <span className="cc-refs">[2e8d83e](https://github.com/diillson/chatcli/commit/2e8d83ef5eedfcae4c79f490d5d8a7665376c9f2)</span>
* <span className="cc-scope">provision</span> pin embedded engine and model digests and confine tar extraction <span className="cc-refs">[b81b668](https://github.com/diillson/chatcli/commit/b81b66839a0ba05efc4868793aadf4d04d88e800)</span>
* <span className="cc-scope">redact</span> cover current key formats in the redactor and HTTP logs <span className="cc-refs">[3623409](https://github.com/diillson/chatcli/commit/3623409c5709d06ab07f3795977f72ad53705877)</span>
* <span className="cc-scope">registry</span> match the skills.sh snapshot digest scheme <span className="cc-refs">[48a3b2a](https://github.com/diillson/chatcli/commit/48a3b2a72476e0153b941026aed029a1590b54dc)</span>
* <span className="cc-scope">registry</span> validate skills.sh snapshot paths in OS form and verify their hash <span className="cc-refs">[6b8fbfa](https://github.com/diillson/chatcli/commit/6b8fbfa3b2bea18b591c2ea2fc0ff034a0f3c572)</span>
* <a className="cc-scope" href="/pt/security/overview">security</a> deny unattended policy asks and operator-gate exec elevation <span className="cc-refs">[71dfbcd](https://github.com/diillson/chatcli/commit/71dfbcd8436f0e83b67798035f13dd30584e6d6d)</span>
* <a className="cc-scope" href="/pt/security/overview">security</a> load project configuration only from trusted workspaces <span className="cc-refs">[8b88a9f](https://github.com/diillson/chatcli/commit/8b88a9f25127cc5e92b1a129491a1416fdbdb90d)</span>
* <a className="cc-scope" href="/pt/server/server-mode">server</a> isolate saved sessions per principal and refuse client endpoints <span className="cc-refs">[aba4c6d](https://github.com/diillson/chatcli/commit/aba4c6d00860b293c831628739de0c01908ebb94)</span>
* <a className="cc-scope" href="/pt/server/server-mode">server</a> report a refused client provider\_config as InvalidArgument <span className="cc-refs">[9cb5883](https://github.com/diillson/chatcli/commit/9cb5883c9f45a311f0fc0774901023efaa57728a)</span>
* <a className="cc-scope" href="/pt/server/server-mode">server</a> restrict agent providers to admin callers <span className="cc-refs">[ff02bbd](https://github.com/diillson/chatcli/commit/ff02bbd5cdfc839c0903440c4c6aebf903050e6c)</span>
* <span className="cc-scope">state</span> keep the state directory and its stores owner-only <span className="cc-refs">[e425b00](https://github.com/diillson/chatcli/commit/e425b00d13091620f421692c2a31989edf1329c1)</span>
* <a className="cc-scope" href="/pt/agents/task-graph">taskgraph</a> guard the dashboard with a token and an exact Host <span className="cc-refs">[55eca95](https://github.com/diillson/chatcli/commit/55eca9559fed2d897daa8b7026e0433c8e3e7e06)</span>
* <a className="cc-scope" href="/pt/start/auto-update">update</a> embed the release signing public key <span className="cc-refs">[789a667](https://github.com/diillson/chatcli/commit/789a6673596ecea01659ae0d3ece76c6c5380457)</span>
* <a className="cc-scope" href="/pt/start/auto-update">update</a> verify a signed checksums.txt and accept only strict semver tags <span className="cc-refs">[b60eb2a](https://github.com/diillson/chatcli/commit/b60eb2a0653bbd3a66be14d45554506a0daef59c)</span>
* <span className="cc-scope">webui</span> serve the page only with the token and stop embedding it <span className="cc-refs">[8e5c45c](https://github.com/diillson/chatcli/commit/8e5c45c67c87507b05958e248fb8748a3dbd6646)</span>

***

<CardGroup cols={2}>
  <Card title="Release mais nova: v1.215.3" icon="arrow-left" href="/pt/releases/1.215.3">
    cap the OAuth token-endpoint response size
  </Card>

  <Card title="Release anterior: v1.215.1" icon="arrow-right" href="/pt/releases/1.215.1">
    health-check the server image with chatcli itself; close the webhook channel delivery gaps
  </Card>
</CardGroup>


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.