## mckinsey/agents-at-scale-ark — v0.1.69…v0.1.70-rc

_45 commits._

### Features
- **feat(a2a): optional agent card endpoint resolution and JSON-RPC transport check (#3441)** (ccaad00)
- **feat(memory): surface dropped conversation history in chat and ark status (#3321)** (ccd75d1)
- **feat(controller): add ArkConfig.defaultMemory and inject spec.memory at admission (#3307)** (043e1af)
- **feat(devspace): add opt-in SSO mode with a local Dex provider (#3091)** (954426c)
- **feat(ark-cli): make ark-tenant require ark-broker (#3305)** (9387900)
- **feat: Workflow runs screen QBDS update (#3506)** (f093ca9)
- **feat(controller): per-namespace fair scheduling for bounded Query pool (#3329)** (c6de2c2)
- **feat: allow setting headers when creating an A2A server (#3510)** (42d854a)
- **feat(controller): cache impersonated clients for service-account queries (#3400)** (ba991fa)
- **feat(controller): provision the default Memory wherever a broker is present (#3293)** (0cc966d)
- **feat: settings page qbds update (#3433)** (a4d6eb1)

### Fixes
- **fix(mcp): discover path-based OAuth issuers and persist MCPServer status on any change (#3231)** (cc2d56b)
- **fix: critical RCE (CVE-2026-94545) (#3587)** (cd0e536)
- **fix: harden credential redaction (#3530)** (c522413)
- **fix(ark-broker): close RedisChunkStream subscriber connections and stop leaking test handles (#3424)** (704872b)
- **fix(completions): make broker chunk-stream failures non-fatal to queries (#3487)** (9e0465b)
- **fix(dashboard): preserve namespace on query event and workflow links (#3529)** (b7dc68b)
- **fix(ark-api): stop typed Tool PUT dropping subtype configuration (#3507)** (ca86a79)
- **fix(controller): raise default Query.spec.timeout to 30m (#3514)** (88f2105)
- **fix(apiserver): serve ArkConfig in postgres mode so cluster-wide defaults apply (#3335)** (004c73f)
- **fix(ark-broker): reap expired message, event and session rows (#3102)** (75d1b53)
- **perf(broker): append broker persisted memory instead of rewriting the full file (#3491)** (439f3ee)
- **fix(ark-broker): bump @grpc/grpc-js to 1.14.5 to resolve XRAY-1087374 (GHSA-m9gg-hp2v-232j) (#3512)** (e5d29e5)
- **fix: bump axios to 1.20.0 in ark-sdk and ark-cli to resolve 6 high CVEs (#3493)** (916e01e)
- **fix(broker): stop the chart fighting over Memory/default and cover it in the postgres e2e leg (#3287)** (53a9300)
- **fix(ark-api): reject active content disguised by declared type on uploads (#3465)** (a86a5b4)
- **fix(dashboard): show all workflow steps on the workflow runs page (#3267)** (4fedc32)
- **fix(executor): fence tool results as untrusted data (#3466)** (7d19d10)
- **fix(dashboard): block external image sources in rendered markdown (#3464)** (a49ec9b)
- **fix: harden HTTP caching and TLS ciphers as per pentest findings (#3382)** (a23119b)
- **fix: address CVE-2026-90711 (proxy-addr) in ark-broker and ark-cli (#3485)** (a011061)
- **fix(charts): add pg_isready startup, liveness and readiness probes to ark-storage-dev (#3423)** (53b9b0b)
- **fix(postgresql): pg_notify fast path for cross-replica watch delivery (#3129)** (22eba23)
- **fix(controller): ignore spec.cancel on terminal queries (#3397)** (bd7caf1)
- **fix(argo-workflows): use the non-root executor image by default (#3370)** (2f41f5d)
- **fix(dashboard): clickable checkbox labels and wrapped tool description (#3459)** (f47ddc3)
- **fix: bump brace-expansion to 5.0.12 (#3475)** (f7fca83)

### Docs
- **docs: mcp inline tools specs (#2798)** (d0369cf)
- **docs: clarify response.content is the final assistant message for multi-artifact A2A replies (#3478)** (a351a24)
- **docs: document the file upload harness and upload size limit configuration (#3488)** (2a88028)

### Chore
- **chore(main): release 0.1.70-rc (#3477)** (d1cac16)
- **chore(dashboard): scope the minimatch override so eslint can run (#3520)** (f750f52)
- **ci: image-build and e2e-setup cleanups (QEMU skip, prefetch gating, drop go build -a) (#3377)** (6362602)
- **chore: bootstrap v0.1.70 development cycle (#3472)** (9a062b2)
- **Remove unused streaming query toggle** — Removed the per-query streaming annotation and dashboard toggle since streaming is now controlled only at the cluster level via configuration. Streaming can be consumed from any query without needing to set a per-query flag. (74d61ed)

_Recap by [Repo Wrapped](https://repowrapped.com/gh/mckinsey/agents-at-scale-ark?utm_source=github-action)._