v2026.7.3
fortemi-react v2026.7.3 release notes.
fortemi-react v2026.7.3
fortemi-react v2026.7.3 is a security-hardening release for the AIWG portable-schema surface (epic #235). The AIWG index, chunk manifests, and Knowledge Shard archives are treated as untrusted input loaded from a URL or file; this release closes a critical prototype-pollution vector, a bundle of SSRF / decompression-bomb / path-traversal / DoS issues, and makes index and embedding-set generation privacy-safe by default.
Highlights
- Prototype pollution fixed (SEC1, #236): facet aggregation
(`getAiwgFortemiFacets` / `pushFacet`) built its counters on a prototype-bearing object, so an untrusted index record with a facet key of `__proto__` — or any inherited name such as `toString` — mutated `Object.prototype` during an ordinary `useAiwgIndex().search()`. Aggregation now uses null-prototype accumulators; exotic keys are counted as plain data. Critical, zero-interaction.
- SSRF closed (SEC2, #241): the chunk and detail fetch loaders enforce
same-origin against the base URL plus an http/https/blob/data scheme allowlist, so an absolute manifest `href` can no longer redirect fetches to another origin.
- Decompression-bomb guard (SEC3, #241): `unpackTarGz` rejects archives whose
gzip footer declares more than a 256 MiB (overridable) decompressed size, before allocating and before checksum validation.
- Path-traversal guard (SEC4, #241): shard component reads reject `..`,
absolute, backslash, scheme, and null-byte paths; legitimate cluster subdirs such as `notes/000.jsonl` still resolve.
- Duplicate-scan DoS cap (SEC5, #241): the O(n²) duplicate-pair scan is capped
at 5000 embeddings by default (overridable) so an attacker-supplied embedding set cannot pin the CPU.
- Privacy/PII enforced at generation (SEC6, #243):
`buildAiwgStaticEmbeddingSet` and `buildAiwgChunkedIndex` now exclude `private`-classified and `pii`-flagged records by default, so a leaked embedding set or scan part no longer carries private/PII-derived vectors. Opt back in with `privacy: { includePrivate, includePii }`; new export `filterAiwgRecordsByPrivacy`.
- Checksum trust model documented (SEC7, #243): in-archive checksums detect
transport corruption, not tampering — provenance-sensitive imports should verify integrity out of band (a signed manifest, or `prefetchShard`'s `expectedSha256`).
- Shard attachment data-loss surfaced (E1, #237): shard import now emits an
explicit, counted warning when a note's attachment references cannot be restored (attachment bytes are not yet packaged in shards) instead of silently dropping them. The full attachment round-trip remains tracked in #237 pending the shard binary-packaging contract.
- AIWG index validator hardened (#239): `validateAiwgFortemiIndexExport` — the
point AIWG re-imports to validate its own generator output — now rejects `record.v1` records carrying v2-only fields, enforces the `privacy.classification` and provenance `confidence` enums, validates provenance item shape, gates `source.graph`/`compatibility` to `export.v2`, and reports the true source version from chunked review-decision exports. The export `source` type was corrected and the `docs.page` known-type constant renamed to `aiwg.kb.page`.
- Shard conformance harness (#238): a committed structural schema for the
Knowledge Shard contract plus a CI proof that catches shard field-drift the `format-parity` suite missed; full schema/AJV/golden-fixtures backlogged (#255, #256).
- Docs polish (#253): the standalone app's in-app docs browser now bundles the
v2026.7.3 release note.
Published Packages
- `@fortemi/[email protected]`
- `@fortemi/[email protected]`
- `@fortemi/[email protected]`
Compatibility
Additive and security-focused, with one deliberate default change: the index and embedding-set builders now filter `private`/`pii` records by default. Callers that intentionally build over private or PII-flagged records must opt in via `privacy: { includePrivate, includePii }`. There is no schema, migration, or wire-format change — existing Knowledge Shards, embedding sets, and static indexes remain valid, and the runtime query path is unchanged.
Verification
Release preparation uses the configured release flow:
- `pnpm typecheck`
- `pnpm lint`
- `pnpm test:core`
- `pnpm test:e2e`
- `pnpm build`
- CI green before tag publication