mirror of
https://github.com/THU-MAIC/OpenMAIC.git
synced 2026-10-02 09:24:43 +08:00
docs(readme): bring the News section up to v1.1.2 (#1715)
The section stopped at v1.0.0 (2026-08-27) and did not point readers at the six releases published since, so anyone landing on the README had no route to the current release history. Adds one entry per release from v1.0.1 to v1.1.2 in the existing format, each linking its GitHub release and the changelog. The four security releases name their advisories and flag the Behavior/Breaking Changes sections, since v1.1.x changes several defaults (caller-supplied provider base URLs, ALLOW_LOCAL_NETWORKS, Pi as the default chat runtime) that an upgrading user needs to read. Dates are taken from the CHANGELOG headings. They differ by a day from the GitHub Releases publish date for v1.0.2 and v1.1.1; the README already carries the same kind of difference for v0.3.0, so say the word if the release dates are preferred. Refs #1714 Co-authored-by: Yi-111-a <41898262+github-actions[bot]@users.noreply.github.com> Co-authored-by: wyuc <wang-yc24@mails.tsinghua.edu.cn>
This commit is contained in:
@@ -57,6 +57,12 @@ Take the full tour in [Features](#-features), then set it up with [Agent workben
|
||||
|
||||
## 🗞️ News
|
||||
|
||||
- **2026-09-28** — [v1.1.2 released!](https://github.com/THU-MAIC/OpenMAIC/releases/tag/v1.1.2) Security release. When a provider is not configured on the server, the routes that accept a caller-supplied base URL (PDF parsing and connectivity checks, the Azure voice list, model listing, image and video providers, LLM calls) now connect only to addresses that passed validation and refuse redirects ([GHSA-g87c-cm4q-cw5x](https://github.com/THU-MAIC/OpenMAIC/security/advisories/GHSA-g87c-cm4q-cw5x)); classroom media downloads use the same transport. Read the **Behavior Changes** section of the changelog before upgrading. See [changelog](CHANGELOG.md).
|
||||
- **2026-09-27** — [v1.1.1 released!](https://github.com/THU-MAIC/OpenMAIC/releases/tag/v1.1.1) Security release. MinerU Cloud document parsing now holds the presigned upload and result URLs returned by the provider to the same strict public-address policy, validates every redirect hop, and bounds what it reads and decompresses ([GHSA-cpjc-vgjh-c5jp](https://github.com/THU-MAIC/OpenMAIC/security/advisories/GHSA-cpjc-vgjh-c5jp)). See [changelog](CHANGELOG.md).
|
||||
- **2026-09-24** — [v1.1.0 released!](https://github.com/THU-MAIC/OpenMAIC/releases/tag/v1.1.0) Classroom chat now runs on an agent loop: reference a slide element, an interactive component or a whiteboard drawing from the playback bar and ask about it, and the teacher can read the lesson, check an experiment's live state and search the web before answering. Settings are rebuilt around the course workflow with a model choice per generation step, plus first-class Token Plan connections. Read the **Behavior Changes** section before upgrading — Pi is the default chat runtime. See [changelog](CHANGELOG.md).
|
||||
- **2026-09-15** — [v1.0.3 released!](https://github.com/THU-MAIC/OpenMAIC/releases/tag/v1.0.3) Security release. Access-code verification tokens now expire and verification is rate-limited ([GHSA-qpmr-534w-hhpg](https://github.com/THU-MAIC/OpenMAIC/security/advisories/GHSA-qpmr-534w-hhpg)); the render service applies a network policy to the untrusted HTML it renders ([GHSA-vqq3-22q7-289w](https://github.com/THU-MAIC/OpenMAIC/security/advisories/GHSA-vqq3-22q7-289w)); audio provider requests validate redirects and pin their connections ([GHSA-9p8q-rcmg-pmjw](https://github.com/THU-MAIC/OpenMAIC/security/advisories/GHSA-9p8q-rcmg-pmjw)); and Next.js is upgraded to patch a critical RCE. See [changelog](CHANGELOG.md).
|
||||
- **2026-09-14** — [v1.0.2 released!](https://github.com/THU-MAIC/OpenMAIC/releases/tag/v1.0.2) Security release. Closes a cloud-metadata SSRF gap, a DNS-rebinding bypass on media proxying and a classroom overwrite, and tightens two request paths. Read the **Breaking Changes** section before upgrading. See [changelog](CHANGELOG.md).
|
||||
- **2026-09-06** — [v1.0.1 released!](https://github.com/THU-MAIC/OpenMAIC/releases/tag/v1.0.1) Security and stability release; everyone on 1.0.0 should upgrade, as it tightens two defaults. See [changelog](CHANGELOG.md).
|
||||
- **2026-08-27** — **OpenMAIC v1.0.0:** an agent workbench, durable course-building sessions, reusable skills, session materials, provider-neutral server capabilities, and a pluggable persistence stack.
|
||||
- **2026-08-14** — [v0.3.2 released!](https://github.com/THU-MAIC/OpenMAIC/releases/tag/v0.3.2) Video export hardening (deterministic Quiz/PBL covers, fidelity polish, interactive HTML capture, CPU resource profiles); server-backed persistence completed (full document cutover, one-command Postgres stack, incremental saves) plus the asset registry; the `@openmaic/generation` package; four new locales; Amazon Bedrock, Atlas Cloud, and Claude search providers; FunASR ASR. See [changelog](CHANGELOG.md).
|
||||
- **2026-07-21** — [v0.3.1 released!](https://github.com/THU-MAIC/OpenMAIC/releases/tag/v0.3.1) One-click MP4 video export; server-backed runtime storage with a Postgres reference server; direct slide manipulation in the editor (drag, resize, rotate, multi-select); smarter "Edit with AI" (validated JSON Patch edits, multi-session history); expanded Document Parsing (multi-format upload, audio/video extraction, AliDocMind, MinerU); new providers (Azure OpenAI, SearXNG, ComfyUI) and the GPT-5.6 model family; action-level playback navigation; SSRF hardening. See [changelog](CHANGELOG.md).
|
||||
|
||||
Reference in New Issue
Block a user