parseBlobRef sliced the blob:sha256: suffix and returned it unvalidated;
get/getSync then fed it into path.join(this.dir, hash), so a crafted ref
like blob:sha256:../../../etc/passwd escaped the blob directory and read
arbitrary files into resolved image history (base64, raw UTF-8, and the ACP
sync path).
Reject any suffix that is not a canonical 64-char lowercase hex hash in
parseBlobRef, the single choke point for every resolution entry point. Reuse
the shared BLOB_HASH_RE in gc-cli instead of its duplicate HASH_RE.
Fixes#4088
Resolved live ACP generate_image payloads through the blob store before emitting image content while keeping rawOutput compact.
Added regression coverage for content[] image blocks and details.images entries without duplicating blob refs as fallback text.
Fixes#3623
- Added image-reference rendering to make `[Image #N]` placeholders clickable in chat.
- Added MIME-aware image blob materialization with extensioned sidecar paths.
- Added clickable path, line, and URL hyperlinks for read, search, and fetch outputs.
- Hardened OSC8 hyperlink emission with URI validation and control-byte/idempotency checks.
- Added sync truncation helpers to recursively prepare session entries and externalize image data.
- Reworked session persistence to use synchronous preparation plus `writeSync` with close-state checks.
- Added synchronous session-storage APIs and rerouted write paths to `writeLineSync`/`readTextSync`.
- Added `BlobStore.putSync`, migrated hashing to `Bun.SHA256`, and updated hash tests accordingly.
- Changed screenshot format to always use PNG instead of supporting JPEG with quality parameter.
- Changed default extract_readable format from text to markdown.
- Changed screenshot storage to use temporary directory with Snowflake IDs instead of artifacts directory.
- Changed ResizedImage interface to return buffer as Uint8Array with lazy-loaded base64 data getter for improved memory efficiency.
- Removed JPEG quality parameter from screenshot options.
- Removed ability to save screenshots to custom paths or artifacts directory.
- Added BlobStore class for content-addressed storage of large binary data externalized from session files.
- Added getBlobsDir() function to retrieve the path to the blob store directory.
- Added blob reference format (blob:sha256:<hash>) for tracking externalized image data in sessions.
- Changed image persistence to externalize images >=1KB to content-addressed blob store instead of compressing inline, reducing JSONL file size.
- Changed session loading to automatically resolve blob references back to base64 image data.
- Changed session forking to resolve blob references in copied entries to ensure data integrity.