feat: v2.5.0 - disable_thinking, reasoning models, MIT license, security hardening

Features:
- disable_thinking toggle (issue #11) with per-provider semantics:
  OpenAI classic gets /no_think soft-switch, OpenAI reasoning gets
  reasoning_effort=low, DeepSeek gets both, Anthropic no-op (thinking
  opt-in), Gemini 2.5+ gets thinking_budget=0
- OpenAI reasoning model support (o1/o3/o4-mini/gpt-5 family):
  max_completion_tokens, developer role, reasoning_effort
- Per-request disable_thinking override in ask_question service
- Provider-specific temperature clip (Anthropic 0-1, others 0-2)

Security:
- Require API key re-entry on provider change (OptionsFlow)
- Validate Anthropic json_schema before system-prompt concatenation
- Symlink protection in history file operations
- Hardened secret redaction regexes (sk-*, AIza*, x-api-key)
- get_history service: hard cap on limit (default 10, max 100)

Reliability:
- Retry on 502/503/504 in addition to 429/timeout
- Honor Retry-After header on 429
- Exception chaining (raise ... from err)
- _strip_think_blocks handles nested/dangling tags
- normalize_name sha256 fallback for empty-collapse inputs

UI/housekeeping:
- api_key uses TextSelector(type=PASSWORD)
- DeviceInfo entry_type=SERVICE
- Services unregister on last entry unload
- Dependabot for GitHub Actions
- persist-credentials=false in checkout steps
- manifest requirements pinned with upper bounds
- Ignore docs/plans/ (working artifacts)

License: PolyForm Noncommercial 1.0.0 -> MIT

No breaking changes: service response shape, sensor attributes,
entity IDs and on-disk formats unchanged.
This commit is contained in:
SMKRV
2026-04-17 01:30:57 +03:00
parent 1e2ff81d07
commit 5af733b1b0
27 changed files with 475 additions and 226 deletions
+15
View File
@@ -0,0 +1,15 @@
version: 2
updates:
- package-ecosystem: "github-actions"
directory: "/"
schedule:
interval: "weekly"
commit-message:
prefix: "chore"
labels:
- "dependencies"
- "github-actions"
groups:
actions:
patterns:
- "*"
+4 -3
View File
@@ -26,15 +26,16 @@ jobs:
timeout-minutes: 10
steps:
- name: ⤵️ Check out code from GitHub
- name: Check out code from GitHub
uses: actions/checkout@v4
with:
fetch-depth: 0
persist-credentials: false
- name: 🚀 Run hassfest validation
- name: Run hassfest validation
uses: home-assistant/actions/hassfest@master
- name: Print hassfest version
- name: Print hassfest version
if: always()
run: |
echo "Hassfest version: $(hassfest --version)"
+1
View File
@@ -17,6 +17,7 @@ jobs:
uses: actions/checkout@v4
with:
ref: ${{ github.event.release.tag_name }}
persist-credentials: false
- name: Create zip archive
run: |