## usestrix/strix — v1.6.2…v1.7.0

_98 commits._

### Features
- **feat(cli): pick a prior run interactively when --resume has no name** (e954301)
- **Scarf support** (a1658fe)
- **feat(budget): budget_policy=pause parks every agent at the limit until the operator resumes** (d355838)
- **feat(tui): animate the wait_for_agents indicator (#1383)** (0ff9f8c)
- **feat(llm): structured per-attempt provider request log with provider request ids (#1353)** (56f7d45)
- **feat(mcp): initialize connections lazily (#1347)** (e158eab)
- **feat(config): STRIX_API_TYPE forces responses vs chat completions (#1324)** (65d495b)
- **Require HTTP exchange IDs for findings** — Updated agent instructions to require that vulnerability findings validated through the proxy include the HTTP request IDs that prove the vulnerability, copied from the proxy's request list. Agents must note these IDs during testing and attach them when filing reports, or add them later if needed—leaving the field empty is no longer allowed except for static-only findings with no captured HTTP traffic. (95e085e)
- **Link HTTP requests to vulnerability reports** — Added support for associating HTTP request evidence with vulnerability findings. The system now tracks which HTTP exchanges are related to each reported security issue, allowing users to see the exact network activity that triggered the detection. (22959a7)

### Fixes
- **fix(execution): only unpark a silent wait_for_user while the agent is still waiting on the user** (6688a9b)
- **fix(docker): drop the module docstring** (6b7e3b7)
- **fix(docker): keep DOCKER_HOST on from_env so TLS settings apply; a missing current context is an error** (6dd164e)
- **fix(docker): use the current docker context only, no DOCKER_CONTEXT override** (828462c)
- **fix(docker): drop the per-platform cause tables, show the endpoint and the raw error** (172246b)
- **fix(docker): connect like the docker CLI and explain why the daemon is unreachable** (b46fc2f)
- **fix(cli): let --fail-on through when no terminal is attached** (fc85e00)
- **fix(cli): run headless when no terminal is attached instead of crashing the TUI** (1ee5c2b)
- **fix(preflight): name the dedupe endpoint setting in its timeout message and test the dedupe warm-up** (0c33f57)
- **fix(preflight): give the startup model check its own 30s timeout instead of LLM_TIMEOUT** (3527d1f)
- **fix(deps): declare boto3 directly and exercise Vertex AI and Bedrock auth from the frozen binary in CI** (265e508)
- **fix(deps): ship google-auth with every install so Vertex AI works in release binaries** (86edf1c)
- **fix(resume-picker): cancel on ctrl+c during drawing too** (aa3144d)
- **fix(resume-picker): treat ctrl+c as cancel instead of leaking a KeyboardInterrupt traceback** (28fa7f7)
- **fix(resume-picker): keep --instruction on a picked run, tolerate blank instructions, read UTF-8 keys, fit narrow terminals, cap the window at 8 rows** (cd3bc80)
- **fix(telemetry): route every unraisable and thread exception to strix.log, never stderr** (fa5f99c)
- **fix(telemetry): route every unraisable and thread exception to strix.log, never stderr** (1212160)
- **fix(telemetry): match only http.client responses in the finalizer filter; test PTY teardown through the real SDK session** (d945eee)
- **fix(runtime): terminate PTY exec streams on teardown and silence 3.14 response finalizer noise** (b4be726)
- **fix(cli): install the stderr log handler at startup and prepare the run state before the TUI launches** (25f3978)
- **fix(cli): verify the model before the TUI opens on a direct launch** (5325009)
- **fix(tui): blank row under panel headers; no panel controls when Agents is the only panel** (d218c29)
- **fix(tui): drop the Model label from the stats panel** (849671f)
- **fix(tui): pin the Model panel to the sidebar bottom and enlarge the show-sidebar button** (faca0d4)
- **fix(tui): keep sidebar panels inside the terminal height** (1a680f4)
- **fix(tui): collapsible, zoomable sidebar panels and a sidebar toggle** (701c22b)
- **fix(tui): keep blank lines inside fenced code when rendering report markdown** (e1d7f5c)
- **fix(tui): render report section bodies as markdown** (64dae6f)
- **fix(preflight): check extra headers for subscription models and the dedupe key as sent** (b49ac2f)
- **fix(preflight): skip unused credentials for subscription models, check dedupe credentials too** (08df05d)
- **fix(preflight): name a non-ASCII character in the API key instead of raising UnicodeEncodeError** (539960d)
- **fix(cli): force UTF-8 stdout/stderr on Windows so Rich output never raises** (5c34767)
- **fix(cli): apply the --fail-on threshold regardless of run status** (45b775d)
- **fix(tui): link every wrapped line of the viewer URL to the full URL** (65172fe)
- **fix(finish_scan): stop asking for a section heading in every report field** (c0258b2)
- **fix(config): use the Responses API whenever the model's catalog entry lists /v1/responses** (99c0711)
- **fix(inputs): send reasoning_effort as configured; no route-specific handling** (8ab5e39)
- **fix(inputs): send reasoning_effort=none explicitly on chat completions; hint at the Responses API when tools+effort are rejected** (e1ec259)
- **fix(runner): pick the SDK route from the resolved model override** (066bd60)
- **fix(config): choose Responses vs chat completions from the model, not the base URL** (6ab1234)
- **fix(reporting): restore create_vulnerability_report parameter descrip… (#1391)** (007ed1a)
- **docs + unit test fix** (9b72488)
- **fix(budget): parked agents count as active; park never overwrites a stop** (463b149)
- **perf(prompt): load requested skills after a cache point (#1382)** (954bc0d)
- **perf(llm): give Claude a cache point before the per-run scope (#1376)** (e66c56c)
- **perf(prompt): put per-run scope at the end of the system prompt (#1375)** (50425c2)
- **fix(tui): suspend on ctrl+z (#1371)** (0c70272)
- **fix(dev): make check-all non-mutating (#1360)** (d6dd9de)
- **fix(reporting): move the git blame hint to the end of the tool description** (355a8bb)
- **fix(reporting): make the git blame hint a casual inline note** (77a0cf8)
- **fix(reporting): keep git blame guidance to the technical_analysis field** (cafa4b1)
- **fix(runtime): tear the sandbox down when staging is cancelled** (4c1f00d)
- **fix(runtime): place extra files as agent-writable sandbox files on every backend** (46d7bdb)
- **fix(build): keep the TUI sidecar hook importable on hatchling 1.32.1 (#1325)** (910c1ea)
- **Fix web search query formatting** — Corrected the web search to send only the user's query to Exa search, removing the system prompt that was interfering with search result matching. The system prompt remains active for Perplexity chat responses. (84f4108)
- **fix(models): frontier model check matches the model name only, never the provider route (#1280)** (52b1923)

### Backend
- **readme: remove the Ask DeepWiki badge** (f4645d6)
- **prompts: let the verified user define and change scope in chat (#1443)** (e4dff10)
- **revert(runtime): drop the PTY teardown change in StrixDockerSandboxClient.delete()** (8ea2c99)
- **Resolve PR Comments** (b112281)
- **Fail on Severity** (3cd6c93)
- **Disable by default** (c77bdd2)
- **Made session IDs optional** (c814f6b)
- **Non-streaming path** (3fbccc6)
- **larger default block size** (c9aebc6)
- **Openrouter sticky sessions for caching, with telemetry** (95fbd8d)
- **Fill in blank tool-call ids so strict providers accept the history (#1355)** (ae38fe7)
- **Let agents delete a vulnerability report they filed (#1354)** (4c1be22)
- **runtime: read_only local sources become :ro bind mounts** (56e9ae9)
- **Prompt agents to include local Git blame in technical details (#1329)** (9768351)

### Tests
- **test(preflight): exercise warm_up_llm with a dedicated dedupe model without touching process-wide SDK defaults** (e3401c4)
- **test(pricing): accept any identically priced provider for bare grok-4.5** (7a31053)
- **test: reject a leading heading in any finish_scan example field** (0107a15)

### Docs
- **docs(skills): refresh framework behavior and security testing guidance (#1372)** (6ae036e)
- **Add Vercel AI Gateway provider guide** — Documentation added for configuring Strix with Vercel AI Gateway, an OpenAI-compatible endpoint that provides access to models from multiple providers. The new guide includes setup instructions, available models, and API key configuration. (0c4364a)

### Chore
- **chore: release v1.7.0** (55bc079)
- **refactor(agents): replace respond_to_user with a text-free wait_for_user** (16a3165)
- **ci(package): check for a missing module without a bare negation so shellcheck is happy** (7ce44ef)
- **ci(release): publish a GitHub release only from a tag so a manual run just builds** (6a3d2ec)
- **ci: drop the CodeQL workflow** (881bc09)
- **ci: split CI into per-concern reusable workflows behind one ci-passed gate** (a5b80af)
- **ci: run ruff, mypy, bandit, pytest, Go TUI and viewer checks on every pull request** (2a7864a)
- **refactor(telemetry): keep only the unraisable hook, no docstrings** (deb6d81)
- **refactor(telemetry): collapse the exception hooks into one plain function** (eaf16c6)
- **style: drop docstrings from the header-value check** (4ca15a6)
- **style: drop docstrings from the UTF-8 stream helpers** (7280c40)
- **chore(inputs): drop unused logger** (2635fb5)
- **chore(models): remove the model quality warning and its allowlists** (ef272b8)
- **Update LiteLLM dependency version** — Updated the LiteLLM library requirement to version 1.101.0 or higher to ensure proper support for GPT-6-Astra's max_completion_tokens mapping. (2dadbb7)

_Recap by [Repo Wrapped](https://repowrapped.com/gh/usestrix/strix?utm_source=github-action)._