Commit Graph
5039 Commits
Author SHA1 Message Date
Dariusz Dębicki fc052d4a5f Update Universal Model Loader 1.0.8 listing 2026-08-26 19:11:46 +02:00
Dariusz Dębicki 5feefbaa21 Update Universal Model Loader metadata fix listing 2026-08-26 17:50:28 +02:00
Dr.Lt.Data f39cbd56fe fix(custom-node-list): demote mickmumpitz/ComfyUI-SplatKit from default to dev channel (security hold)
Post-registration full re-verify (§14.7) found an unauthenticated CSRF-reachable
arbitrary-directory delete: DatasetProject.make(reset=True) runs shutil.rmtree on an
uncontained os.path.join(output_dir, dataset_name) (nodes/common.py:169-173) — an
absolute or ..-containing name escapes the output dir. Removed from default + node_db/new,
added to node_db/dev with [SECURITY ISSUE] suffix (reversible install-block, §4.7-H mechanic).
Restore to default on author fix (realpath+commonpath containment) + re-verify pass.
2026-08-19 08:43:25 +09:00
Dr.Lt.Data d243fda858 update DB 2026-08-19 08:29:05 +09:00
Dr.Lt.Data abaad8e28b fix(custom-node-list): register ketle-man/comfyui-chat-te (Chat TE, #3177) after last git-clone block + node_db/new sync
PR conflicted on the list tail; manually registered. Deep-verify SAFE (unauth routes are inference/model-load only, no side-effect sink), Non-English PASS.
2026-08-19 07:27:17 +09:00
Dr.Lt.Data d5992a117e update DB 2026-08-18 12:49:34 +09:00
Dr.Lt.Data 4f56cf3dfa Merge pull request #3163 from Zoltar358-ComfyUI/update-universal-model-loader-106
Update Universal Model Loader listing for MiniMax Music3
2026-08-15 13:28:36 +09:00
Dr.Lt.Data 8970a942a8 fix(custom-node-list): register DenRakEiw/ComfyGotchi (#3166) after last git-clone block + node_db/new sync
PR conflicted on the list tail; manually registered. Weak sink (fixed-path
game-state only, no data-loss), SAFE per deep-verify.
2026-08-15 13:22:24 +09:00
Dr.Lt.Data 1b765ac340 fix(custom-node-list): register H3-wave nodepacks after last git-clone block + node_db/new sync
Relocate ANe5s/ComfyUI-MiniMax-H3-Hybrid (#3154) from array head to tail.
Manually register Flow-Wrangler (#3142), minimax-h3-latent (#3151),
buqi-minimax-h3-multigpu (#3158), H3-Continuum (#3159) — their PRs
conflicted on the list tail after the batch merges. buqi-minimax-h3-multigpu
description trimmed to English-only (author's zh restatement dropped, §4.7-D desc policy).
Sync all 7 into node_db/new (newest-first).
2026-08-15 13:06:57 +09:00
Dr.Lt.Data fe4d5d434c Merge pull request #3154 from ANe5s/codex/add-minimax-h3-hybrid
Add ComfyUI MiniMax H3 Hybrid
2026-08-15 13:00:05 +09:00
Dr.Lt.Data 67ec5f5c36 Merge pull request #3152 from CocyNoric/main
Add ComfyUI-ToriiGate-Reforged
2026-08-15 12:59:58 +09:00
Dr.Lt.Data d7c376bb88 Merge pull request #3162 from mickmumpitz/main
Add ComfyUI-SplatKit
2026-08-15 12:59:48 +09:00
Dr.Lt.Data 7e08e10ec1 Merge pull request #3161 from Comfy-Org/fix/issue-3128-c1
fix(ui): show the server's reason for a batch 404, not a false channel message (#3128)
2026-08-15 11:09:17 +09:00
Dr.Lt.Data 98be899011 harden(ui): escape untrusted text before the batch error dialog (#3128)
The dialog renders HTML, so run the server body and the pack title
(registry-derived) through the existing sanitizeHTML() at both sites. The
title is wrapped in String() so a missing title can't throw inside the error
handler; rendered text is unchanged for ordinary values.
2026-08-15 08:16:23 +09:00
Dr.Lt.Data 4fe65b088e fix(ui): surface the server's reason for a batch 404 (#3128)
The batch install/uninstall paths replaced the server's 404 body with a
false "default channel" lead. Drop the 404 branch so a 404 falls through to
the existing server-text path; uninstall never returns 404 anyway. Fixes
#3128 (section 1), reported by plz12345.
2026-08-15 08:16:23 +09:00
Dariusz Dębicki 8950d89648 Update Universal Model Loader listing for MiniMax Music3 2026-08-14 16:47:58 +02:00
mickmumpitz 00c273dbdc Add ComfyUI-SplatKit 2026-08-14 11:59:30 +02:00
Dr.Lt.Data 14de630433 Merge pull request #3157 from Comfy-Org/fix/issue-3128
fix(#3128): state the real install gate in denial messages + stop write_config() clobbering hand-edited config.ini
2026-08-14 08:03:12 +09:00
Dr.Lt.Data aaed26a5a4 fix(config): merge write_config() onto disk instead of rebuilding from the startup snapshot (#3128)
write_config() rebuilt config.ini's [default] section entirely from the
startup snapshot into a fresh parser opened 'w'. Any Manager settings
change therefore silently reverted values hand-edited while ComfyUI was
running (the same config['default'] flags those messages tell users to
edit), deleted the two read-but-never-written keys (http_channel_enabled,
default_cache_as_channel_url), and erased every non-[default] section.

get_config() now tracks which keys callers actually change, and
write_config() re-reads config.ini and overlays only those keys plus the
live preview_method. After a successful write the just-persisted keys are
cleared from the tracker, so a key changed once through the UI does not
stay dirty for the life of the process and re-clobber a later hand-edit of
that same key on the next unrelated write. Hand-edited values, unknown
keys, and foreign sections survive; CRLF sanitization still applies to
every value written; an unparsable config.ini falls back to a full rewrite
instead of failing every settings endpoint.

configparser.read() suppresses OSError, so a config.ini that exists but
cannot be read comes back as an empty parser rather than an exception,
which would silently route the merge into the bootstrap branch and rewrite
the file from defaults. write_config() now detects that case (the file
exists but read() loaded nothing) and refuses the write with a raised
error, leaving the file untouched, rather than destroying its contents
while reporting success.

tests/test_write_config_persistence.py pins the three loss classes
(hand-edit revert, key deletion, section erasure), the settings
round-trip, the persisted-key re-clobber guard, and the silent-read-failure
refusal.
2026-08-14 06:31:38 +09:00
Alexis Rolland 2f3fc41a13 Merge pull request #3153 from adamoster/feat/ltx-2.5-models
feat(models): Add LTX-2.5 model family and LTX-2.3 IC-LoRAs.
2026-08-13 00:30:51 -07:00
Dr.Lt.Data ffb2f03e92 fix(security-messages): state the actual gate in install-denial messages (#3128)
The install-denial diagnostics named the wrong gate, sending users to
settings that could not resolve their denial:

- SECURITY_MESSAGE_FLAG_GIT_URL / _FLAG_PIP omitted the loopback half of
  the flag-AND-loopback predicate, telling users to enable a flag that
  was often already enabled. They now state both conditions, print the
  live --listen value at every emission site, and explain that both
  values are read once at startup (stop the server, edit, then start).
- SECURITY_MESSAGE_MIDDLE_OR_BELOW instructed setting security_level to
  'middle', a value that does not exist; it now names only real values
  (any level other than 'strong': normal, normal-, weak).
- The blocked-risk arm reused SECURITY_MESSAGE_GENERAL, blaming
  security_level although no value of it can help there; it now emits a
  dedicated SECURITY_MESSAGE_BLOCKED_RISK stating this is not a
  configuration problem.
- SECURITY_MESSAGE_NORMAL_MINUS_MODEL now names its loopback-listener
  condition and the same restart guidance.
- The js/common.js dedicated-403 messages mirror the loopback clause.
2026-08-13 12:38:11 +09:00
{name} 8c46ea2921 Add MiniMax H3 Hybrid node 2026-08-12 20:55:48 +08:00
Adam OsterandCursor 7d2e499d85 feat(models): Add LTX-2.3 22B IC-LoRA suite.
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-08-12 12:55:18 +03:00
Adam OsterandCursor 55746905d0 feat(models): Add LTX-2.5 22B model family.
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-08-12 12:46:16 +03:00
CauchyInno ae31058747 Add ComfyUI-ToriiGate-Reforged 2026-08-12 13:44:59 +08:00
Dr.Lt.Data 97421c4965 update DB 2026-08-10 02:32:47 +09:00
Dr.Lt.Data 67acc56924 sync(node_db/new): add ComfyUI MiniMax H3 Context IR Agent (#3145) 2026-08-10 01:56:38 +09:00
Dr.Lt.Data d5d48e7c18 Merge pull request #3145 from JerryZRic/add-minimax-h3-context-ir-agent
Add MiniMax H3 Context IR Agent
2026-08-10 01:55:27 +09:00
JerryZRic 6ab1d9dd93 Add MiniMax H3 Context IR Agent 2026-08-09 20:13:32 +08:00
Dr.Lt.Data 8c5e640f83 docs(custom-node-list): update descriptions for Universal Model Loader (#3123) and Anomalous Model Browser (#3130); drop overbroad nodename_pattern '.*' 2026-08-08 01:26:52 +09:00
Dr.Lt.Data 62441d65dd update DB 2026-08-08 01:20:04 +09:00
Dr.Lt.Data 78bc5df653 feat(custom-node-list): register ComfyUI-Quick-Merge (#3102) — manual add (PR conflicting) after author security fix + node_db/new sync 2026-08-07 12:40:28 +09:00
Dr.Lt.Data 150f23c210 fix(custom-node-list): place ComfyUI-Qwen-FrameKit after last git-clone block + node_db/new sync (#3131, #3135) 2026-08-07 09:00:47 +09:00
Dr.Lt.Data 4814b5d67a Merge pull request #3135 from uron83/register-qwen-framekit
Register ComfyUI-Qwen-FrameKit
2026-08-07 08:55:54 +09:00
Dr.Lt.Data 97399264a2 Merge pull request #3131 from DumiFlex/add-wildcard-pipeline
Add Wildcard Pipeline to custom-node-list.json
2026-08-07 08:55:29 +09:00
Elian Gabriel Hernandez db1aa8d73a Register ComfyUI-Qwen-FrameKit 2026-08-06 16:05:27 +10:00
DumiFlex c975c0ae74 Add Wildcard Pipeline to custom-node-list.json 2026-08-04 21:57:03 +03:00
Dr.Lt.Data d47c934619 update DB 2026-08-04 12:53:08 +09:00
Dr.Lt.Data fe1193c0c8 Relist ComfyUI-Pixaroma to custom-node-list.json
Re-add pixaroma/ComfyUI-Pixaroma after verifying the v1.4.82 security
fixes (PR #3118): the four reported filesystem-access issues are now
contained through a shared path guard. Registered to the default list.

Claude-Session: https://claude.ai/code/session_01VKv6FcDs7S642dM1if3vxD
2026-08-03 20:19:56 +09:00
Dr.Lt.Data 1c3031d62f update DB 2026-08-03 12:49:18 +09:00
Dr.Lt.Data d404e6234a updatevDB 2026-08-02 22:15:31 +09:00
Dhevenddra K G f124e5cfc6 test: fix the install-flags structural guard failing on main (#3116)
Two defects, the second hidden behind the first. CI runs ruff only, so
neither shows up there.

The generic-403 guard counted the copy across all of js/common.js while its
docstring describes exactly the two occurrences inside handle403Response. A
third, unrelated use at line 722 builds the batch-uninstall error message, so
the file-wide count tripped on it. Scoped the count to the handle403Response
block via the existing _js_function_block helper. This part is not
platform-specific; the count is 3 on Linux and Windows alike.

With that passing, the test reached a loop calling js_file.read_text() with no
encoding. That uses the locale encoding, so on cp1252 Windows it raises
UnicodeDecodeError on the four js files containing emoji. Passed
encoding="utf-8" explicitly, and did the same for the other four read_text
calls in the file, which read ASCII sources today and so pass by luck.
2026-08-02 15:08:30 +09:00
Rvage 25f519ed0c Fix: tooltip global listener (#3114)
* remove noise

* fix: remove global tooltip listener
2026-08-02 15:08:27 +09:00
Dr.Lt.Data 2b40deba7d update DB 2026-07-30 02:19:23 +09:00
Dr.Lt.Data 89bf85f0a7 update DB 2026-07-30 01:35:14 +09:00
Dr.Lt.Data 522a437bd8 update DB 2026-07-29 20:48:56 +09:00
Dr.Lt.Data 1a445fa44c update DB 2026-07-29 20:36:58 +09:00
Dr.Lt.Data 314814b336 update DB 2026-07-29 18:40:34 +09:00
Dr.Lt.Data 3af9708ee1 update DB 2026-07-29 08:23:26 +09:00
Dr.Lt.Data 8daa17d9dd update DB 2026-07-29 07:34:04 +09:00