Skip to content

Commit 6658652

Browse files
committed
feat: add .nvmrc file and update Node.js version requirements in package.json and documentation
- Introduced a new .nvmrc file specifying Node.js version 22. - Updated Node.js version requirements in package.json to support ^22.18 or >=24.11. - Adjusted related documentation to reflect the new Node.js version requirements for development and installation.
2 parents 7569996 + b1d18b1 commit 6658652

224 files changed

Lines changed: 32504 additions & 2820 deletions

File tree

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

‎.github/workflows/publish.yml‎

Lines changed: 15 additions & 21 deletions
Original file line numberDiff line numberDiff line change
@@ -56,7 +56,7 @@ jobs:
5656
| sudo tar -xz -C /usr/local/bin gitleaks
5757
gitleaks version
5858
59-
- name: Ensure zip (per-platform binary archives)
59+
- name: Ensure zip and tar (per-platform binary archives)
6060
run: sudo apt-get update && sudo apt-get install -y zip
6161

6262
- run: pnpm install --frozen-lockfile
@@ -70,17 +70,15 @@ jobs:
7070
- name: publish-stable
7171
env:
7272
GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
73-
# OSS release channel runs fully in CI: upload + reconcile + manifest.json.
74-
# All values come from repo Settings → Secrets — no OSS defaults live in
75-
# code. Leave AK/SK unset to skip the OSS channel; once enabled,
76-
# bucket/region/prefix are required.
77-
BAILIAN_OSS_AK: ${{ secrets.BAILIAN_OSS_AK }}
78-
BAILIAN_OSS_SK: ${{ secrets.BAILIAN_OSS_SK }}
79-
BAILIAN_OSS_BUCKET: ${{ secrets.BAILIAN_OSS_BUCKET }}
80-
BAILIAN_OSS_REGION: ${{ secrets.BAILIAN_OSS_REGION }}
81-
BAILIAN_OSS_ENDPOINT: ${{ secrets.BAILIAN_OSS_ENDPOINT }}
82-
BAILIAN_RELEASE_PREFIX: ${{ secrets.BAILIAN_RELEASE_PREFIX }}
83-
BAILIAN_STATIC_PREFIX: ${{ secrets.BAILIAN_STATIC_PREFIX }}
73+
# OSS release channel goes through the FC release function (presigned
74+
# upload + reconcile + manifest.json): this repo holds no OSS
75+
# credentials, the job only presents its GitHub OIDC token (requires
76+
# id-token: write above). The trigger URL is the shared
77+
# FC_TRIGGER_URL (same function serves publish-skills; actions are
78+
# routed by URL path); leave it unset to skip the OSS channel.
79+
# Bucket / prefix / allowlists live in the FC function.
80+
FC_TRIGGER_URL: ${{ vars.FC_TRIGGER_URL }}
81+
FC_RELEASE_AUDIENCE: ${{ vars.FC_RELEASE_AUDIENCE }}
8482
run: node tools/release/publish-stable.mjs ${{ inputs.package == 'knowledge-studio-cli' && '--knowledge' || '' }}
8583

8684
publish-channel:
@@ -116,7 +114,7 @@ jobs:
116114
| sudo tar -xz -C /usr/local/bin gitleaks
117115
gitleaks version
118116
119-
- name: Ensure zip (per-platform binary archives)
117+
- name: Ensure zip and tar (per-platform binary archives)
120118
run: sudo apt-get update && sudo apt-get install -y zip
121119

122120
- run: pnpm install --frozen-lockfile
@@ -130,14 +128,10 @@ jobs:
130128
- name: publish-channel
131129
env:
132130
GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
133-
# OSS release channel — same Settings-injected values as stable.
134-
BAILIAN_OSS_AK: ${{ secrets.BAILIAN_OSS_AK }}
135-
BAILIAN_OSS_SK: ${{ secrets.BAILIAN_OSS_SK }}
136-
BAILIAN_OSS_BUCKET: ${{ secrets.BAILIAN_OSS_BUCKET }}
137-
BAILIAN_OSS_REGION: ${{ secrets.BAILIAN_OSS_REGION }}
138-
BAILIAN_OSS_ENDPOINT: ${{ secrets.BAILIAN_OSS_ENDPOINT }}
139-
BAILIAN_RELEASE_PREFIX: ${{ secrets.BAILIAN_RELEASE_PREFIX }}
140-
BAILIAN_STATIC_PREFIX: ${{ secrets.BAILIAN_STATIC_PREFIX }}
131+
# OSS release channel — same FC-backed flow as stable; no OSS
132+
# credentials in this repo (see publish-stable env notes).
133+
FC_TRIGGER_URL: ${{ vars.FC_TRIGGER_URL }}
134+
FC_RELEASE_AUDIENCE: ${{ vars.FC_RELEASE_AUDIENCE }}
141135
run: node tools/release/publish-channel.mjs ${{ inputs.package == 'knowledge-studio-cli' && '--knowledge' || '' }} --channel "${{ inputs.channel }}"
142136

143137
# bailian-kb-dsh is the dsh plugin (downstream host adapter): independent version,

‎.nvmrc‎

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1 @@
1+
22

‎.vite-hooks/pre-commit‎

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -15,6 +15,8 @@ git add \
1515
skills/bailian-finetune/reference \
1616
skills/bailian-managed-agent/SKILL.md \
1717
skills/bailian-managed-agent/reference \
18+
skills/bailian-sandbox/SKILL.md \
19+
skills/bailian-sandbox/reference \
1820
skills/bailian-web-search/SKILL.md
1921

2022
vp staged

‎AGENTS.md‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -36,7 +36,7 @@ packages/core/src/auth/ # apiKey / console credential 解析与落盘
3636
packages/core/src/client/ # HTTP client / endpoints / console gateway
3737
```
3838

39-
Skill / 命令手册随 `skills/bailian-*/` 经 `bl skill init` 安装(装齐 registry 中全部 `bailian-*`,含共享协议 `bailian-protocol`)。业务 skill(`bailian-cli` / `bailian-gen` / `bailian-finetune` / `bailian-managed-agent` / `bailian-web-search`)执行前读 `skills/bailian-protocol/`;不要依赖 frontmatter `companions`(安装器不强制)。`tools/generate-reference.ts` 从 **`packages/cli/src/commands.ts`** 按一级命令归属表分流写入各 `skills/<skill>/reference/`(纳入 git);`tools/sync-skill-metadata.ts` 从 `packages/cli/package.json` 同步各 `skills/*/SKILL.md` 的 `metadata.version`。两者由根脚本 `pnpm run sync:skill-assets` 和 `.vite-hooks/pre-commit` 执行。hub `bailian-cli` 的路由表不复述领域命令明细;SKILL 文案 / 安装约定 / hand-off 见 [docs/agents/skill-change.md](docs/agents/skill-change.md)。
39+
Skill / 命令手册随 `skills/bailian-*/` 经 `bl skill init` 安装(装齐 registry 中全部 `bailian-*`,含共享协议 `bailian-protocol`)。业务 skill(`bailian-cli` / `bailian-gen` / `bailian-finetune` / `bailian-managed-agent` / `bailian-sandbox` / `bailian-web-search`)执行前读 `skills/bailian-protocol/`;不要依赖 frontmatter `companions`(安装器不强制)。`tools/generate-reference.ts` 从 **`packages/cli/src/commands.ts`** 按一级命令归属表分流写入各 `skills/<skill>/reference/`(纳入 git);`tools/sync-skill-metadata.ts` 从 `packages/cli/package.json` 同步各 `skills/*/SKILL.md` 的 `metadata.version`。两者由根脚本 `pnpm run sync:skill-assets` 和 `.vite-hooks/pre-commit` 执行。hub `bailian-cli` 的路由表不复述领域命令明细;SKILL 文案 / 安装约定 / hand-off 见 [docs/agents/skill-change.md](docs/agents/skill-change.md)。
4040

4141
约定:
4242

‎CHANGELOG.md‎

Lines changed: 73 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -6,6 +6,79 @@ The format follows [Keep a Changelog](https://keepachangelog.com/en/1.1.0/), and
66

77
[中文版](CHANGELOG.zh.md) · [README](README.md) · [Contributing](CONTRIBUTING.md)
88

9+
## [2.0.0] - 2026-09-22
10+
11+
### Added
12+
13+
- **Native MCP registration** — Added `bl mcp connect` and `bl mcp disconnect` to add or remove Bailian MCP servers in Agent-native configurations:
14+
- Supports `streamable-http` and SSE, targeting an individual Agent or all installed Agents with `--agent all`.
15+
- Supports Codex, Claude Code, Cursor, Qoder, Qoder Work, QwenWork, Qwen Code, Gemini, OpenCode, OpenClaw, DeepSeek Harness, ZCode, and WorkBuddy.
16+
- Never overwrites unmanaged entries and preserves registrations modified by users during removal.
17+
- **Broader Skill delivery** — Skill installation and updates now support WorkBuddy, Trae CLI, and DeepSeek DSH through their global Skill directories.
18+
19+
### Fixed
20+
21+
- **Skill operation previews** — `bl skill init`, `add`, `update`, and `remove` now honor `--dry-run`, showing the planned Skills, Agents, and target paths without writing. Invalid requests retain the same failure status as real execution.
22+
- **Safer Skill cleanup** — `bl skill remove` previews and executions now use the same managed-link discovery scope, recognize historical managed links, and recheck targets immediately before deletion to avoid removing changed or unmanaged content.
23+
24+
## [1.28.0] - 2026-09-20
25+
26+
### Added
27+
28+
- **Agent security commands** — `bl agents security overview` (protection overview for the last 24 hours) and `bl agents security alerts` (alert list with risk-level, asset-type, status, vendor, pagination and sorting filters). Both call the per-workspace AgentStudio host and honor the shared `text` / `json` / `--quiet` / `--dry-run` contract. The host is derived from `--workspace-id`, or overridden by `--base-url` / `DASHSCOPE_BASE_URL` / `auth login --base-url` pointed at a workspace or pre-release origin (e.g. `https://<workspace-id>.cn-beijing.maas.aliyuncs.com/api/v1/agentstudio`).
29+
30+
### Internal
31+
32+
- Add Agent security E2E coverage (help, missing-workspace usage error, dry-run host derivation and `--base-url` override, query-string filters, enum fast-fail) and generate the `bailian-cli` skill reference for the new `agents` group.
33+
34+
## [1.27.0] - 2026-09-18
35+
36+
### Added
37+
38+
- **Monitoring, logs, and alerts** — Added `bl monitor`, `bl log`, and `bl alert` command groups for model call statistics, failures, latency, token usage, audit and inference logs, traces, delivery configuration, and alert management.
39+
- **Model discovery and code samples** — Added `bl model search` for relevance-ranked catalog search and `bl model code` for ready-to-run SDK examples.
40+
41+
### Changed
42+
43+
- **Model catalog** — `bl model list` now supports input/output modality filters, hides offline models by default, and can include them with `--include-deprecated`.
44+
45+
### Fixed
46+
47+
- **Speech voices** — `bl speech synthesize --list-voices` now supports the built-in voices and documentation links for `qwen-audio-3.0-tts-plus` and `qwen-audio-3.0-tts-flash`.
48+
- **Unix binary distribution** — Added `.tar.gz` release assets and checksums for macOS and Linux, enabling installation without an `unzip` dependency while retaining `.zip` assets for compatibility.
49+
50+
## [1.26.0] - 2026-09-17
51+
52+
### Changed
53+
54+
- **Simplified authentication** — Console login is now the recommended default and can create an ordinary API key when needed. Existing ordinary API keys and Token Plan subscription keys use the same `bl auth login --api-key <API_KEY>` command.
55+
- **Automatic API key validation and endpoint selection** — API keys are validated before being saved. The CLI automatically selects an available regional endpoint and applies the appropriate Token Plan configuration when applicable.
56+
57+
## [1.25.0] - 2026-09-14
58+
59+
### Added
60+
61+
- **Token Plan harness quota** — `bl token-plan harness-quota` shows Token Plan harness entitlement quota usage (Console auth), joining the harness list with issued entitlements to display used/total quota, usage ratio, and reset time; harnesses with a pending entitlement are listed as issuing.
62+
- Filter the harness list with `--type official_tool|infrastructure`; render as a quota box or `--output json`.
63+
64+
## [1.24.0] - 2026-09-11
65+
66+
### Added
67+
68+
- Sandbox instance and template lifecycle commands, with automatic build polling and `--async` submission.
69+
- `bl sandbox official-images` and template `--image` presets for Code Interpreter, Browser, and All-in-One.
70+
- `bl sandbox file upload` uploads template mount files with `source=sandbox_template`; use the returned File ID in `mntConfig`.
71+
- Sandbox supports shared `--base-url`, environment and Profile configuration, with workspace-based endpoint fallback.
72+
- Dedicated `bailian-sandbox` Skill with command references and instance connection guidance.
73+
74+
### Fixed
75+
76+
- Preserve submitted `templateID` and `buildID` when template-build polling fails, so users can check the existing build before resubmitting.
77+
78+
### Security
79+
80+
- Sandbox REST calls use Bailian Bearer authentication without an E2B SDK or E2B API key. Connection credentials and dry-run environment values are redacted by default.
81+
982
## [1.23.0] - 2026-09-10
1083

1184
### Added

‎CHANGELOG.zh.md‎

Lines changed: 73 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -6,6 +6,79 @@
66

77
[English](CHANGELOG.md) · [README](README.zh.md) · [参与贡献](CONTRIBUTING.zh.md)
88

9+
## [2.0.0] - 2026-09-22
10+
11+
### 新增
12+
13+
- **原生 MCP 注册** —— 新增 `bl mcp connect` 和 `bl mcp disconnect`,支持在 Agent 原生配置中接入或移除百炼 MCP 服务:
14+
- 支持 `streamable-http` 与 SSE,可指定单个 Agent 或使用 `--agent all`。
15+
- 支持 Codex、Claude Code、Cursor、Qoder、Qoder Work、QwenWork、Qwen Code、Gemini、OpenCode、OpenClaw、DeepSeek Harness、ZCode 和 WorkBuddy。
16+
- 不会覆盖非 CLI 管理的同名配置;移除时会保留已被用户修改的注册项。
17+
- **扩展 Skill 分发范围** —— Skill 安装和更新新增支持 WorkBuddy、Trae CLI 与 DeepSeek DSH,并使用各自的全局 Skill 目录。
18+
19+
### 修复
20+
21+
- **Skill 操作预览** —— `bl skill init`、`add`、`update` 和 `remove` 现在会正确响应 `--dry-run`,只读展示计划操作的 Skill、Agent 和目标路径;无效请求的失败状态与实际执行保持一致。
22+
- **Skill 清理安全性** —— `bl skill remove` 的预览与实际执行现在使用相同的托管链接发现范围,可识别历史托管链接,并在删除前重新校验目标,避免误删已变化或不再由 CLI 管理的内容。
23+
24+
## [1.28.0] - 2026-09-20
25+
26+
### 新增
27+
28+
- **Agent 安全命令** —— `bl agents security overview`(最近 24 小时的防护总览)与 `bl agents security alerts`(告警列表,支持风险等级、资产类型、状态、厂商、分页与排序等筛选)。两者均对接按 workspace 区分的 AgentStudio 域名,遵循统一的 `text` / `json` / `--quiet` / `--dry-run` 约定。域名默认由 `--workspace-id` 推导,也可通过 `--base-url` / `DASHSCOPE_BASE_URL` / `auth login --base-url` 指向某个 workspace 或预发源覆盖(例如 `https://<workspace-id>.cn-beijing.maas.aliyuncs.com/api/v1/agentstudio`)。
29+
30+
### 内部
31+
32+
- 补充 Agent 安全 E2E 覆盖(help、缺 workspace 的 usage 错误、dry-run 域名推导与 `--base-url` 覆盖、query string 筛选、枚举快失败),并为新的 `agents` 组生成 `bailian-cli` 技能 reference。
33+
34+
## [1.27.0] - 2026-09-18
35+
36+
### 新增
37+
38+
- **监控、日志与告警** —— 新增 `bl monitor`、`bl log` 和 `bl alert` 命令组,支持查看模型调用量、失败、耗时、Token 用量、审计与推理日志、调用链,配置数据投递并管理告警。
39+
- **模型发现与示例代码** —— 新增 `bl model search`,可按相关度搜索模型目录;新增 `bl model code`,可获取开箱即用的 SDK 调用示例。
40+
41+
### 变更
42+
43+
- **模型目录** —— `bl model list` 新增输入/输出模态筛选,默认隐藏已下线模型,并可通过 `--include-deprecated` 将其包含在结果中。
44+
45+
### 修复
46+
47+
- **语音音色** —— `bl speech synthesize --list-voices` 现在支持查看 `qwen-audio-3.0-tts-plus` 和 `qwen-audio-3.0-tts-flash` 的内置音色及对应文档。
48+
- **Unix 二进制分发** —— 为 macOS 和 Linux 增加带校验和的 `.tar.gz` 发布资产,使安装流程可不依赖 `unzip`,同时保留 `.zip` 资产以兼容现有流程。
49+
50+
## [1.26.0] - 2026-09-17
51+
52+
### 变更
53+
54+
- **简化认证方式** —— 默认推荐使用控制台登录,需要时可自动创建普通 API Key。已有普通 API Key 和 Token Plan 订阅 Key 统一使用 `bl auth login --api-key <API_KEY>` 登录。
55+
- **API Key 自动校验与地域识别** —— API Key 会在保存前进行校验,CLI 自动选择可用地域,并在适用时完成 Token Plan 配置。
56+
57+
## [1.25.0] - 2026-09-14
58+
59+
### 新增
60+
61+
- **Token Plan harness 权益额度** —— `bl token-plan harness-quota` 查看 Token Plan harness 权益额度用量(Console 认证),联合 harness 列表与已发放权益,展示已用/总额度、使用比例和重置时间;待发放权益的 harness 以「发放中」状态列出。
62+
- 通过 `--type official_tool|infrastructure` 筛选 harness 列表;支持额度框输出或 `--output json`。
63+
64+
## [1.24.0] - 2026-09-11
65+
66+
### 新增
67+
68+
- Sandbox 实例与模版生命周期命令,支持自动轮询构建状态和 `--async` 异步提交。
69+
- `bl sandbox official-images` 与模版 `--image` 参数,内置代码解释器、浏览器和全能型镜像预设。
70+
- `bl sandbox file upload` 使用 `source=sandbox_template` 上传模版挂载文件,返回的 File ID 可用于 `mntConfig`。
71+
- Sandbox 复用 `--base-url`、环境变量和 Profile 配置,未配置时通过工作空间拼接接入地址。
72+
- 独立的 `bailian-sandbox` Skill,提供命令参考和实例连接指南。
73+
74+
### 修复
75+
76+
- 模版构建轮询失败时保留已提交的 `templateID` 和 `buildID`,便于先查询已有构建,避免重复提交。
77+
78+
### 安全
79+
80+
- Sandbox REST 调用使用百炼 Bearer 鉴权,不依赖 E2B SDK 或 E2B API Key;连接凭据和 dry-run 环境变量默认脱敏。
81+
982
## [1.23.0] - 2026-09-10
1083

1184
### 新增

‎CONTRIBUTING.md‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -6,7 +6,7 @@ Developer guide for `bailian-cli` — the official CLI for Aliyun Model Studio (
66

77
## Prerequisites
88

9-
- Node.js ≥ 22.12 (required for developing this repo)
9+
- Node.js ^22.18 or >=24.11 (required for developing this repo)
1010
- End users installing the published CLI only need Node.js >= 18.17
1111
- pnpm 10.33.2 (`npm i -g pnpm@10.33.2`)
1212
- A DashScope API key for running e2e tests

‎CONTRIBUTING.zh.md‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -6,7 +6,7 @@
66

77
## 环境要求
88

9-
- 参与本仓库开发:Node.js ≥ 22.12
9+
- 参与本仓库开发:Node.js ^22.18 或 >=24.11
1010
- 仅安装/使用已发布的 CLI:Node.js >= 18.17
1111
- pnpm 10.33.2(`npm i -g pnpm@10.33.2`)
1212
- 跑 e2e 需要一个百炼 API Key

‎INSTALL.md‎

Lines changed: 4 additions & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -70,7 +70,7 @@ bl --version
7070
which bl # Windows: where.exe bl
7171
```
7272

73-
> CDN / GitHub Release 未就绪或下载失败时,若本机已有合格 Node,回退到上方 npm 安装。
73+
> CDN / GitHub Release 未就绪或下载失败时,若本机已有合格 Node,回退到上方 npm 安装。Unix 二进制安装优先解 `.tar.gz`(不依赖 `unzip`);Windows 仍使用 `.zip`。
7474
7575
---
7676

@@ -79,13 +79,9 @@ which bl # Windows: where.exe bl
7979
### 推荐:浏览器登录(控制台会话)
8080

8181
1. 执行 `bl auth status --output json`,判断是否已配置。
82-
2. 若未配置,在**用户本机终端**执行 `bl auth login --console`。
83-
3. 登录成功后执行 `bl auth status --output json` 确认;汇报时只使用 masked 字段,**禁止**回显完整凭据。
84-
85-
### 备选:API Key / Token Plan
86-
87-
- 普通 Key:`bl auth login --api-key <Key>`
88-
- Token Plan:`bl auth login --config token-plan --api-key <Key>`
82+
2. 若未配置,在**用户本机终端**执行 `bl auth login --console`(国际站执行 `bl auth login --console --console-site international`);需要时会自动创建普通 API Key。
83+
3. 如果使用 Token Plan 等订阅计划,不能使用 `--console`,请执行 `bl auth login --api-key <API_KEY>`。
84+
4. 登录成功后执行 `bl auth status --output json` 确认;汇报时只使用 masked 字段,**禁止**回显完整凭据。
8985

9086
### Agent 安全约束
9187

0 commit comments

Comments
 (0)