v2026.7.3

fortemi-react v2026.7.3 release notes.

fortemi-react v2026.7.3

fortemi-react v2026.7.3 is a security-hardening release for the AIWG portable-schema surface (epic #235). The AIWG index, chunk manifests, and Knowledge Shard archives are treated as untrusted input loaded from a URL or file; this release closes a critical prototype-pollution vector, a bundle of SSRF / decompression-bomb / path-traversal / DoS issues, and makes index and embedding-set generation privacy-safe by default.

Highlights

  • Prototype pollution fixed (SEC1, #236): facet aggregation

(`getAiwgFortemiFacets` / `pushFacet`) built its counters on a prototype-bearing object, so an untrusted index record with a facet key of `__proto__` — or any inherited name such as `toString` — mutated `Object.prototype` during an ordinary `useAiwgIndex().search()`. Aggregation now uses null-prototype accumulators; exotic keys are counted as plain data. Critical, zero-interaction.

  • SSRF closed (SEC2, #241): the chunk and detail fetch loaders enforce

same-origin against the base URL plus an http/https/blob/data scheme allowlist, so an absolute manifest `href` can no longer redirect fetches to another origin.

  • Decompression-bomb guard (SEC3, #241): `unpackTarGz` rejects archives whose

gzip footer declares more than a 256 MiB (overridable) decompressed size, before allocating and before checksum validation.

  • Path-traversal guard (SEC4, #241): shard component reads reject `..`,

absolute, backslash, scheme, and null-byte paths; legitimate cluster subdirs such as `notes/000.jsonl` still resolve.

  • Duplicate-scan DoS cap (SEC5, #241): the O(n²) duplicate-pair scan is capped

at 5000 embeddings by default (overridable) so an attacker-supplied embedding set cannot pin the CPU.

  • Privacy/PII enforced at generation (SEC6, #243):

`buildAiwgStaticEmbeddingSet` and `buildAiwgChunkedIndex` now exclude `private`-classified and `pii`-flagged records by default, so a leaked embedding set or scan part no longer carries private/PII-derived vectors. Opt back in with `privacy: { includePrivate, includePii }`; new export `filterAiwgRecordsByPrivacy`.

  • Checksum trust model documented (SEC7, #243): in-archive checksums detect

transport corruption, not tampering — provenance-sensitive imports should verify integrity out of band (a signed manifest, or `prefetchShard`'s `expectedSha256`).

  • Shard attachment data-loss surfaced (E1, #237): shard import now emits an

explicit, counted warning when a note's attachment references cannot be restored (attachment bytes are not yet packaged in shards) instead of silently dropping them. The full attachment round-trip remains tracked in #237 pending the shard binary-packaging contract.

  • AIWG index validator hardened (#239): `validateAiwgFortemiIndexExport` — the

point AIWG re-imports to validate its own generator output — now rejects `record.v1` records carrying v2-only fields, enforces the `privacy.classification` and provenance `confidence` enums, validates provenance item shape, gates `source.graph`/`compatibility` to `export.v2`, and reports the true source version from chunked review-decision exports. The export `source` type was corrected and the `docs.page` known-type constant renamed to `aiwg.kb.page`.

  • Shard conformance harness (#238): a committed structural schema for the

Knowledge Shard contract plus a CI proof that catches shard field-drift the `format-parity` suite missed; full schema/AJV/golden-fixtures backlogged (#255, #256).

  • Docs polish (#253): the standalone app's in-app docs browser now bundles the

v2026.7.3 release note.

Published Packages

Compatibility

Additive and security-focused, with one deliberate default change: the index and embedding-set builders now filter `private`/`pii` records by default. Callers that intentionally build over private or PII-flagged records must opt in via `privacy: { includePrivate, includePii }`. There is no schema, migration, or wire-format change — existing Knowledge Shards, embedding sets, and static indexes remain valid, and the runtime query path is unchanged.

Verification

Release preparation uses the configured release flow:

  • `pnpm typecheck`
  • `pnpm lint`
  • `pnpm test:core`
  • `pnpm test:e2e`
  • `pnpm build`
  • CI green before tag publication