Conversation
- gui: add Rescan button (hidden until report written, wired to rootAgent)
- gui: surface rescan errors in chat as '✗ Rescan failed: <reason>'
- gui: remove HighlightNode exported no-op (no live callers)
- gui: fyne.LogError for allowlist persistence failures (was _ =)
- mcp: nil guard cmd.Process before Kill in context-cancel goroutine
- mcp: log DiscoverBackend probe failures to stderr instead of silently discarding
- cmd/late-sast: delegate cleanupContainer to CleanupScanEnvironmentTool
- cmd/run-tools: fix broken build (AssessDisclosureContextTool{} not NewAssessDisclosureContextTool())
- session/ttystyle: simplify FormatSessionDisplay, remove intermediate var and redundant rune-len check
- tool/subagent: remove stale TODO comment for unimplemented reviewer/committer types
- tool/docs_lookup: clarify docs_* descriptions (named library → ProContext registry)
- tool/context_index: clarify ctx_* descriptions (arbitrary content → in-session BM25 index)
- changelog: add v2.0.1 release notes
There was a problem hiding this comment.
Pull request overview
This PR is a broad v2.0 refactor that removes the old TUI/project-map flow, expands the SAST toolchain with deterministic setup/scan/cleanup helpers, adds shared tool-result caching/runtime UI state, and updates prompts/docs to drive the new workflow.
Changes:
- Adds new scan workflow tools for container setup, readiness probing, exploit replay, secret scanning, and cleanup.
- Reworks orchestration/agent behavior with shared tool caching, tool runtime events, and stricter subagent middleware.
- Removes the old TUI/project-map code and updates GUI, prompts, docs, and versioning for the new SAST flow.
Reviewed changes
Copilot reviewed 74 out of 76 changed files in this pull request and generated 7 comments.
Show a summary per file
| File | Description |
|---|---|
| Makefile | Bumps default release version to v2.0.0. |
| internal/tui/theme.go | Deletes old TUI markdown theme implementation. |
| internal/tui/styles.go | Deletes old TUI style definitions. |
| internal/tui/state.go | Deletes old TUI state/model definitions. |
| internal/tui/model.go | Deletes old TUI model construction/renderer code. |
| internal/tui/keys.go | Deletes old TUI keymap definitions. |
| internal/tui/interactions.go | Deletes old TUI prompt/confirmation middleware. |
| internal/tui/interactions_test.go | Removes tests for deleted TUI middleware. |
| internal/tool/wait_for_target_ready.go | Adds deterministic container readiness probing tool. |
| internal/tool/wait_for_target_ready_test.go | Adds readiness tool tests. |
| internal/tool/utils.go | Adds architecture JSON parsing helper. |
| internal/tool/subagent.go | Adds retry/backoff/telemetry logic for subagents. |
| internal/tool/setup_container.go | Adds container setup/install helper tool. |
| internal/tool/setup_container_test.go | Adds setup_container tests. |
| internal/tool/sast_tools_test.go | Expands SpawnSubagentTool retry coverage. |
| internal/tool/run_secrets_scanner.go | Adds TruffleHog-backed secrets scanning tool. |
| internal/tool/run_secrets_scanner_test.go | Adds secrets scanner tests. |
| internal/tool/run_exploit_replay.go | Adds deterministic exploit replay tool. |
| internal/tool/run_exploit_replay_test.go | Adds exploit replay tests. |
| internal/tool/resolve_install_strategy_test.go | Adds install-strategy test coverage. |
| internal/tool/docs_lookup.go | Clarifies docs tool descriptions and intended usage. |
| internal/tool/doc.go | Adds package-level tool organization docs. |
| internal/tool/context_index.go | Clarifies ctx_* tool descriptions and usage boundaries. |
| internal/tool/cleanup_scan_environment.go | Adds deterministic scan cleanup tool. |
| internal/tool/cleanup_scan_environment_test.go | Adds cleanup tool tests. |
| internal/tool/bootstrap_scan_toolchain_test.go | Adds bootstrap toolchain tests. |
| internal/tool/assess_disclosure_context_test.go | Adds disclosure-context tests. |
| internal/session/ttystyle.go | Minor cleanup/simplification of session display formatting. |
| internal/session/tool_call_repair_test.go | Adds malformed tool-call repair tests. |
| internal/session/session.go | Adds malformed JSON tool-call repair logic. |
| internal/orchestrator/highlight_middleware.go | Removes project-map highlighting middleware. |
| internal/orchestrator/base.go | Adds shared cache + tool runtime event plumbing. |
| internal/mcp/client.go | Minor MCP transport cleanup/safety logging changes. |
| internal/gui/sast_picker.go | Makes setup callback return errors and recover to picker UI. |
| internal/gui/project_map.go | Removes project map GUI panel. |
| internal/gui/markdown.go | Adds HTML stripping in markdown rendering. |
| internal/gui/events.go | Adds live tool runtime status/timer handling; removes old project-map/snapshot events. |
| internal/gui/confirm.go | Logs failures when persisting allow decisions. |
| internal/gui/app.go | Simplifies main GUI layout, removes mission/project-map UI, adds rescan button support. |
| internal/executor/toolcache.go | Adds shared TTL-based tool result cache + tool timeouts. |
| internal/executor/executor.go | Wires cache/tool runtime callbacks into tool execution loop. |
| internal/executor/executor_test.go | Updates executor test signature. |
| internal/common/version.go | Bumps embedded version string to v2.0.0. |
| internal/common/interfaces.go | Replaces old GUI events with ToolRuntimeEvent and expands architecture data. |
| internal/client/client.go | Adds stderr logging for backend discovery probe failures. |
| internal/assets/sast/references/xss.md | Adds XSS false-positive guidance for email templates. |
| internal/assets/prompts/instruction-sast.md | Rewrites SAST flow to use new deterministic tools. |
| internal/assets/prompts/instruction-sast-setup.md | Rewrites setup prompt around new install/launch/readiness tools. |
| internal/assets/prompts/instruction-sast-scanner.md | Rewrites scanner prompt to use structured tools. |
| internal/assets/prompts/instruction-sast-scanner-binary.md | Rewrites binary scanner prompt to use structured tools. |
| internal/assets/prompts/instruction-sast-retest.md | Rewrites retest prompt around disclosure/cleanup tools. |
| internal/assets/prompts/instruction-sast-auditor.md | Adds output-format/context guidance for auditor agent. |
| internal/agent/agent.go | Adds new subagent middleware/enforcement helpers and middleware assembly changes. |
| internal/agent/agent_test.go | Adds coverage for new middleware and nil-parent handling. |
| go.sum | Updates dependency lockfile for removed/downgraded deps. |
| go.mod | Drops old TUI deps from direct requires and adjusts indirect versions. |
| cmd/run-tools/main.go | Adds a hardcoded helper binary to run disclosure/cleanup/report tools manually. |
| .vscode/settings.json | Adds Linux/amd64/gopls build environment settings. |
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
|
Addressed all Copilot reviewer findings in commit b54e212. Implemented fixes:
Validation:
All pass. |
There was a problem hiding this comment.
Pull request overview
Copilot reviewed 75 out of 77 changed files in this pull request and generated 5 comments.
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
|
Second review pass addressed in commit 3352dc3 and all remaining review threads are now resolved. Fixes included:
Validation:
|
Description of Changes
Contributor License Agreement (CLA)
To accept your code, we legally need you to agree to our CLA so we can maintain the project's Business Source License (BSL) and future open-source transitions.
xbetween the brackets like this:[x])