mirror of
https://github.com/paperclipai/paperclip.git
synced 2026-10-06 21:05:21 +02:00
codex/legacy-document-repaired-skill
4750
Commits
| Author | SHA1 | Message | Date | |
|---|---|---|---|---|
|
|
abd0b628ca |
Clarify legacy issue document delivery in the operational skill
Preserve the tiny hire manual and original assigned-skill case. Add a focused public document/revision/link oracle and explicit presence/absence provenance for a matched skill-only comparison. Co-Authored-By: Paperclip <noreply@paperclip.ing> |
||
|
|
5837aa4442 |
docs(evals): keep timeout document outcomes unknown
Co-Authored-By: Paperclip <noreply@paperclip.ing> |
||
|
|
792533866c |
docs(evals): close the unchanged-source baseline recovery
Co-Authored-By: Paperclip <noreply@paperclip.ing> |
||
|
|
6c27174cd4 |
docs(evals): retain matched stock-harness results and failures
Co-Authored-By: Paperclip <noreply@paperclip.ing> |
||
|
|
1eb5ba4206 |
fix(evals): retain prerequisites inside the campaign artifact root
Co-Authored-By: Paperclip <noreply@paperclip.ing> |
||
|
|
f02d8d0df3 |
fix(evals): use complete Rust protocol test preparation
Co-Authored-By: Paperclip <noreply@paperclip.ing> |
||
|
|
712dc98cf5 |
fix(evals): bind protocol evidence to the built daemon
Co-Authored-By: Paperclip <noreply@paperclip.ing> |
||
|
|
ac6ddefb58 |
fix(evals): build the cold daemon before protocol prerequisites
Co-Authored-By: Paperclip <noreply@paperclip.ing> |
||
|
|
4163dbfd0f |
fix(evals): prepare cold prerequisites and fingerprint connection guidance
Co-Authored-By: Paperclip <noreply@paperclip.ing> |
||
|
|
36e987246b |
test(evals): enforce exact-source stock harness prerequisites
Run credential-free gates before live admission and verify retained evidence in direct browser execution. Include evaluated instruction sources in suite revisions and calibrate stale/missing evidence rejection. Co-Authored-By: Paperclip <noreply@paperclip.ing> |
||
|
|
a63437069d |
test(evals): cover production default hires across stock harnesses
Co-Authored-By: Paperclip <noreply@paperclip.ing> |
||
|
|
19d685a20c |
fix(agents): reduce default manual and shared legacy guidance
Co-Authored-By: Paperclip <noreply@paperclip.ing> |
||
|
|
cf8ad63c80 |
build(deps-dev): bump tsx from 4.23.12 to 4.23.15 (#12965)
Bumps [tsx](https://github.com/privatenumber/tsx) from 4.23.12 to 4.23.15. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/privatenumber/tsx/releases">tsx's releases</a>.</em></p> <blockquote> <h2>v4.23.15</h2> <h2><a href="https://github.com/privatenumber/tsx/compare/v4.23.14...v4.23.15">4.23.15</a> (2026-09-20)</h2> <h3>Bug Fixes</h3> <ul> <li>exclude bare builtins from namespace inheritance (<a href="https://github.com/privatenumber/tsx/commit/38e158857e50bca311be7c232a5057e5a2e5347a">38e1588</a>)</li> <li>expose require.cache and require.extensions to tsImport CommonJS modules (<a href="https://github.com/privatenumber/tsx/commit/2da34075afaed43e2b7fd0aca5fbebaaf337ff3a">2da3407</a>)</li> <li>make namespaced register() overloads portable for declaration emit (<a href="https://github.com/privatenumber/tsx/commit/562c434a5c8695e74327bbeb51cfeb9b86fc7e15">562c434</a>)</li> </ul> <hr /> <p>This release is also available on:</p> <ul> <li><a href="https://www.npmjs.com/package/tsx/v/4.23.15"><code>npm package (@latest dist-tag)</code></a></li> </ul> <h2>v4.23.14</h2> <h2><a href="https://github.com/privatenumber/tsx/compare/v4.23.13...v4.23.14">4.23.14</a> (2026-09-20)</h2> <h3>Bug Fixes</h3> <ul> <li>restore the CJS bridge namespace for Node 24 require(esm) under tsImport() (<a href="https://redirect.github.com/privatenumber/tsx/issues/802">#802</a>) (<a href="https://github.com/privatenumber/tsx/commit/6e5236b065738d3687a06396d064774cfede390f">6e5236b</a>)</li> </ul> <hr /> <p>This release is also available on:</p> <ul> <li><a href="https://www.npmjs.com/package/tsx/v/4.23.14"><code>npm package (@latest dist-tag)</code></a></li> </ul> <h2>v4.23.13</h2> <h2><a href="https://github.com/privatenumber/tsx/compare/v4.23.12...v4.23.13">4.23.13</a> (2026-08-30)</h2> <h3>Bug Fixes</h3> <ul> <li><strong>cache:</strong> bound shared transform cache memory (<a href="https://redirect.github.com/privatenumber/tsx/issues/835">#835</a>) (<a href="https://github.com/privatenumber/tsx/commit/28e1f12d04cd2afe1db17f8555b14fe5fb567c6e">28e1f12</a>)</li> </ul> <hr /> <p>This release is also available on:</p> <ul> <li><a href="https://www.npmjs.com/package/tsx/v/4.23.13"><code>npm package (@latest dist-tag)</code></a></li> </ul> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/privatenumber/tsx/commit/ca66105a17a2a4c6503fe3a12b5b9ec408286011"><code>ca66105</code></a> test: fix drive-less file URLs in ESM resolver fixtures</li> <li><a href="https://github.com/privatenumber/tsx/commit/2da34075afaed43e2b7fd0aca5fbebaaf337ff3a"><code>2da3407</code></a> fix: expose require.cache and require.extensions to tsImport CommonJS modules</li> <li><a href="https://github.com/privatenumber/tsx/commit/38e158857e50bca311be7c232a5057e5a2e5347a"><code>38e1588</code></a> fix: exclude bare builtins from namespace inheritance</li> <li><a href="https://github.com/privatenumber/tsx/commit/562c434a5c8695e74327bbeb51cfeb9b86fc7e15"><code>562c434</code></a> fix: make namespaced register() overloads portable for declaration emit</li> <li><a href="https://github.com/privatenumber/tsx/commit/edfb1f05a3f40b879a41a03a0801c2abd3a3ecf9"><code>edfb1f0</code></a> build: upgrade pkgroll and externalize CJS loader reference</li> <li><a href="https://github.com/privatenumber/tsx/commit/70e78284837c859f09b96cd10cd71d007aa4b795"><code>70e7828</code></a> test: upgrade tinyspy for disposable API</li> <li><a href="https://github.com/privatenumber/tsx/commit/9ed2022dfa9ea1be9511fe6abcde8110c25055a7"><code>9ed2022</code></a> ci: avoid duplicate release notifications</li> <li><a href="https://github.com/privatenumber/tsx/commit/872e77ffc5e96ca5c4727e74c0694debcb26219b"><code>872e77f</code></a> refactor: use disposables for cleanup</li> <li><a href="https://github.com/privatenumber/tsx/commit/6e5236b065738d3687a06396d064774cfede390f"><code>6e5236b</code></a> fix: restore the CJS bridge namespace for Node 24 require(esm) under tsImport...</li> <li><a href="https://github.com/privatenumber/tsx/commit/28e1f12d04cd2afe1db17f8555b14fe5fb567c6e"><code>28e1f12</code></a> fix(cache): bound shared transform cache memory (<a href="https://redirect.github.com/privatenumber/tsx/issues/835">#835</a>)</li> <li>See full diff in <a href="https://github.com/privatenumber/tsx/compare/v4.23.12...v4.23.15">compare view</a></li> </ul> </details> <br /> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>canary/v2026.1002.0-canary.12 |
||
|
|
b2c565038b |
test(shared): make the worktree port registry lock suite deterministic (#12798)
## Thinking Path > - Paperclip is the open source app people use to manage AI agents for work > - Shared worktree services use lock leases and worker-thread heartbeats > - The lock test suite measured wall-clock timing across two threads > - Processor contention allowed a heartbeat tick to change the value during an assertion > - This pull request removes that timing race and restores a regression guard > - The benefit is a stable test suite that still detects slow heartbeats ## Linked Issues or Issue Description **What happened?** The worktree port registry lock suite failed at random under continuous-integration processor contention. The failure reported a fresh timestamp where the test expected an old timestamp. **Expected behavior** The suite must pass when the heartbeat runs at its supported interval. It must also fail when the heartbeat interval regresses. **Steps to reproduce** 1. Run `npx vitest run src/worktree-port-registry.test.ts` in `packages/shared`. 2. Repeat the run under bounded processor contention. 3. Set the heartbeat interval to 3000 ms and run the asynchronous critical-section test. **Paperclip version or commit** `a661caf74e704f7700a8b8a1e79b76ebd04e3483` **Deployment mode** Built from source. **Installation method** Built from source. **Agent adapter(s) involved** Not adapter-specific (core test). **Database mode** Not database-related. **Additional context** Related open pull requests are #11994, #11985, and #11922. This pull request keeps all five tests active and does not use `skip`, `skipIf`, or `todo`. ## What Changed - Build the fallback-probe lock state by hand so no live heartbeat changes the timestamp during the assertion. - Count distinct heartbeat refreshes in the asynchronous critical-section test. - Close the fake probe and settle the pending lock attempt in a `finally` block. - Keep production code unchanged. ## Verification - `npx vitest run src/worktree-port-registry.test.ts` — 5 of 5 tests pass. - `npx vitest run` — 72 files and 704 tests pass at submit time. - `npx tsc --noEmit` — exit code 0. - Ten target-file runs pass under bounded processor contention. - A 3000 ms heartbeat interval fails with `expected 2 to be greater than or equal to 3`. - An inverted cleanup assertion exits normally in 379 ms without a leaked worker. ## Risks Low risk. This pull request changes one test file. It changes test setup and assertions only. ## Model Used OpenAI GPT-5 through Codex. Exact model ID: GPT-5. The model used tool calls and code execution. The context window is not disclosed by the runtime. ## Checklist - [x] I have included a thinking path that traces from project context to this change - [x] I have specified the model used (with version and capability details) - [x] I have checked ROADMAP.md and confirmed this PR does not duplicate planned core work - [x] I have searched GitHub for duplicate or related PRs and linked them above - [x] I have either (a) linked existing issues with `Fixes: #` / `Closes: #` / `Refs: #` OR (b) described the issue in-PR following the relevant issue template - [x] I have not referenced internal/instance-local Paperclip issues or links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip` URLs) - [x] My branch name describes the change (e.g. `docs/...`, `fix/...`) and contains no internal Paperclip ticket id or instance-derived details - [x] I have run tests locally and they pass - [x] I have added or updated tests where applicable - [x] I have updated relevant documentation to reflect my changes - [x] I have considered and documented any risks above - [x] All Paperclip CI gates are green - [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups - [x] I will address all Greptile and reviewer comments before requesting merge --------- Co-authored-by: Paperclip <noreply@paperclip.ing> |
||
|
|
9d0f7e2ddd |
fix(adapter-utils): make the directory merge lock crash test deterministic (#14881)
## Thinking Path
> - Paperclip is the open source app people use to manage AI agents for
work
> - A workspace restore merges a directory, and a cross-process lock
serializes that merge
> - The lock must recover after the process that holds it crashes
> - One test proves that recovery: it kills the holder process and then
acquires the lock
> - That test failed intermittently for two independent reasons, and
this pull request removes both
> - First, it spawned the holder through the tsx command-line entry
point, which re-spawns the evaluated code in a further child process, so
the kill signal reached only the wrapper and the real holder kept the
lock
> - Second, it replaced the global clock to force a timeout, which left
the acquisition with zero real retries, so a single transient busy
result failed the test
> - The benefit is a deterministic crash-recovery test and a reliable
continuous-integration signal
## Linked Issues or Issue Description
**What happened?**
The test `recovers a killed holder even when its recorded PID has been
reused` in `packages/adapter-utils/src/directory-merge-lock.test.ts`
failed intermittently in continuous integration. The failure reported
`ERR_WORKSPACE_RESTORE_LOCK_TIMEOUT` with `waitMs: 3` and
`knownLocalHolder: false`. A rerun of the same job on the same commit
passed.
**Expected behavior**
The test must pass every run. It must acquire the lock after the holder
process dies.
**Steps to reproduce**
1. Check out `master`.
2. Run `npx vitest run
packages/adapter-utils/src/directory-merge-lock.test.ts`.
3. Repeat the run. The named test fails intermittently.
**Paperclip version or commit**
`32e9f3ba0ec000578936731990d23bb0e77493fa`
**Deployment mode**
Built from source. The failure appears in the general test job of
continuous integration.
**Agent adapter(s) involved**
Not adapter-specific (core bug).
**Relevant logs or output**
```
ERR_WORKSPACE_RESTORE_LOCK_TIMEOUT
workspaceRestoreLock: { ownerState: 'alive', knownLocalHolder: false, waitMs: 3,
ownerSameProcess: true, ownerAgeMs: 60030, ownerPredatesProcess: true }
```
## What Changed
The test file had two independent defects. This pull request removes
both.
**1. The kill signal did not reach the real lock holder.**
The test spawned its holder through the tsx command-line entry point.
That entry point re-spawns the evaluated code in a further child
process. `SIGKILL` therefore killed only the wrapper, and the process
that had opened the lock database survived as an orphan that still held
the lock. The test now loads tsx as an `--import` hook, so the spawned
process is the real holder and the kill releases the lock at once. This
also stops the test from leaking an orphan process.
**2. The forced clock left the acquisition with zero retries.**
A test helper replaced `Date.now` to force a timeout. The implementation
reads `Date.now()` one time, to compute its deadline, so that single
read consumed the forced value and every later read returned a time
already past the deadline. The retry loop therefore got one attempt and
no retries. That is correct for a test that asserts a timeout, but the
crash-recovery test asserts a *successful* acquisition, so any transient
busy result on the first attempt failed it.
The fix removes the clock replacement from the whole file and gives each
test a real, short, explicit wait budget:
- `withDirectoryMergeLock` takes a new optional wait-budget parameter.
It threads through to the lock acquisition function. The production
default is the existing 30-second budget, and no production call site
changed.
- The five tests that assert a timeout pass a real 200-millisecond
budget. Each one still times out for the real reason, because the lock
is genuinely held or the legacy lock directory genuinely exists. Each
one now exercises at least four real retries of the 50-millisecond retry
interval.
- The crash-recovery test passes a real 5-second budget. A failure now
reports the structured `ERR_WORKSPACE_RESTORE_LOCK_TIMEOUT` diagnostic
well inside the test timeout, instead of a bare test timeout.
**No test timeout increased.** Every `it(..., N)` timeout in the file
equals its value on `master`.
## Verification
- Measured the first cause rather than assumed it: the spawned wrapper
process reported one process id, and the process that opened the lock
database reported a different process id and named the wrapper as its
parent. The real holder kept the lock for about 50 to 60 milliseconds
after the kill.
- Reproduced the failure deterministically before the change, with no
artificial processor load: 15 of 15 runs failed. Confirmed the fix: 15
of 15 runs passed.
- Ran the lock test file 15 times in series: 12 of 12 tests passed every
time.
- Confirmed the clock replacement is gone: a search for a `Date.now`
override in the file returns nothing.
- Confirmed the production default is unchanged at 30 seconds, and that
the diff touches no production call site.
- Proved the diagnostic still surfaces: with a temporary edit that held
the lock with a genuine live holder, the test failed with
`ERR_WORKSPACE_RESTORE_LOCK_TIMEOUT` and the full `workspaceRestoreLock`
block at about 5 seconds, inside the 15-second test timeout. The
temporary edit was reverted.
- `workspace-restore-merge.test.ts` passed 56 of 56. The adapter test
files that cover every production caller passed 116 of 116 and 52 of 52.
`agent-directory-working-copies.test.ts` passed 70 of 70.
- The `adapter-utils` and `server` type-checks passed with no error.
- Confirmed that no spawned process survives the test run.
## Risks
Low risk. The production change is one optional parameter with the
existing default, so every production caller keeps the real 30-second
budget and no production call site changed. The remaining change is
limited to one test file. The `--import` form of the tsx hook is already
used elsewhere in this repository, in the container image command and in
an end-to-end test configuration. Test coverage does not drop: the owner
record is diagnostic only, the SQLite reserved lock remains the
authority that the tests exercise, and the timeout-asserting tests now
exercise the real retry loop instead of a replaced clock. The file costs
about 0.5 to 0.9 seconds more wall clock than `master`, which is the
cost of the short real waits that replace the instant forced timeout.
## Model Used
Claude Sonnet 5 (`claude-sonnet-5`), used with extended thinking and
tool use for the diagnosis, the measurement, and the change.
## Checklist
Check every box that the state of the pull request satisfies. The local
test runs and the type checks are complete. Reconcile the
continuous-integration and review boxes after the checks reach their
terminal state.
## Test plan
- [x] Continuous integration is green on every check, including the
general test job.
- [x] The general test job passes the file
`packages/adapter-utils/src/directory-merge-lock.test.ts`.
- [x] Greptile returns 5 of 5 with no open item.
- [x] `mergeable: MERGEABLE` is terminal.
---------
Co-authored-by: Paperclip <noreply@paperclip.ing>
|
||
|
|
6c1a75da49 |
feat(connections): make AgentMail a default connection with inline setup (#14772)
## Thinking Path > - Paperclip is the open source app people use to manage AI agents for work. > - Connections give agents access to external services. > - AgentMail needs both a saved key and an inbox assigned to the agent. > - Chat requests offered a setup link instead of an inline card and could treat a saved key as complete. > - Inbox setup also hid address conflicts behind a generic server error and a separate review step. > - This pull request makes AgentMail a default connection, adds the inline card, reduces setup to two steps, and shows conflicts beside the address. > - Shared native dropdown styles also give every caret a consistent inset. ## Linked Issues or Issue Description **What happened?** AgentMail requests in chat did not show a usable inline connection card. Manual setup required extra screens, ignored saved account keys, and could trap new-address setup in a locked inbox dropdown. Agent selectors omitted the avatar from the selected value. A taken address could produce an HTTP 403 from AgentMail and appear as an internal server error. Native dropdown arrows also touched the right edge of their fields. **Expected behavior** Make AgentMail available as a default connection. Ask for the API key inline, with a direct link to its provider page. Default human access to the company and agent access to the requesting agent. Resume the agent only after an assigned inbox is active. Manual setup should ask for an agent and email address, then finish. Address checks should run as the user types. Taken addresses should show clickable alternatives. A domain dropdown beside the name should prefer a verified custom domain. Setup should suggest authorized saved AgentMail keys and show agent avatars in the picker and selected value. **Steps to reproduce** 1. Ask an agent to connect AgentMail when it has no assigned inbox. 2. Check that an inline API-key card appears and links to the provider's API-key page. 3. Open AgentMail setup, choose an agent, and request an address that is already taken. 4. Correct the inline error, refresh, and finish setup with the same request ID. 5. Inspect native dropdown carets in light, dark, disabled, and right-to-left states. Uses the bounded provider-error parser merged in #14768. Related work: #13256 introduced AgentMail; #14725 expanded connection search. ## What Changed - Stop recurring email queries for tasks that have no email thread. Share the query between the thread provider and activity view. Keep email-task updates and invalidation-based discovery. - Make AgentMail available without the experimental chat setting. Keep the catalog, setup and management routes, agent Channels tab, task email feed, receiving worker, and agent tools available by default. Other experimental chat providers stay gated. - Make the email address and copy icon a single clickable action with the shared Copied! confirmation. Add View inbox linking directly to the matching AgentMail console inbox, with the address encoded as one URL path segment. - Reorganize inbox Settings around the copyable email address, usage instructions, and receiving status. Move reconnect credentials into a disclosure and separate the Disconnect action. Add production Settings stories for active, paused, unassigned-address, revoked, webhook, long-address, mobile, and reconnect states. Show repair controls when the inbox has an error. Keep usage instructions tied to an active inbox with an address. - Add AgentMail channel intents and an inline key field with the direct API-key URL. - Keep setup and retry state tied to the interaction. Require an active inbox for completion. Preserve company and agent access checks. - Reduce manual setup to agent selection and email selection. Put the domain dropdown beside the address and default to a verified custom domain. Preserve explicit choices across reloads. Keep receiving settings under Advanced options. - Check the initial address and edits after a 350 ms pause. Abort superseded requests and ignore stale responses. Show clickable suggestions and retain known creation conflicts across reloads. - Add a company-scoped, manager-only address check using the saved credential. Search the visible inbox list instead of fetching an uncreated inbox: live AgentMail retains negative lookups that can break subsequent access-key creation. Unlisted addresses remain unknown; creation is authoritative. - Suggest labeled saved AgentMail keys in both manual setup and the inline card. Filter by company, provider, active credential, and current-user grants on the server. Prefer an account key and preserve the selected key or an explicit new-key choice across refresh. Use verified scope metadata and bounded concurrent checks for legacy keys. Never return secret values. - Catch an inbox-only key before the email step. Allow its existing inbox only after an explicit choice. Recover old locked drafts at the key picker. Save the replacement key before retiring an empty draft, then use a new setup URL so refresh preserves the switched account; stop if cleanup fails. Preserve already allocated addresses and their original accounts. - Use the shared AgentSelect in email setup. Show the canonical agent avatar in each option and the selected value, including other consumers of the shared component. Add regression coverage for legacy and current Lucide agent-mention icon formats. - Start each catalog Add connection with a fresh setup identity. Honor Finish setup's exact draft/account/address instead of resuming an unrelated browser draft. Return Cancel and Done to Connectors and Email settings to the inbox. Group the task/thread explanation in a How it Works card. - Route AgentMail catalog removal through the email inbox control API, including unfinished drafts. Refresh both the catalog and inbox views. - Render each inbox management tab separately. Access uses the saved account grants and agent controls; Conversations and Activity use the shared persisted email feed. Activity lifecycle actions use the email API. Reconnect returns to inbox Settings. Conversation failures show a retry instead of a false empty state. Email delivery recovery stays in the task. - Map documented provider address conflicts to a field error. Preserve actionable messages for other failures. - Preserve non-secret draft fields across refresh, scoped to the requested agent. Never save API keys in browser storage. Resume partial inbox creation with the original agent, address, and request ID. - Show an already-created address with explicit retry and new-address recovery instead of locked inputs. Preserve the original inbox and resumable draft when choosing another address. Distinguish runtime-key 404 errors and log safe provider status/operation/code. - Apply final agent access once within email setup authorization for a new account whose original installs are unchanged. Preserve later permission edits and reused account installs. Support in-place retry of progress loading. - Let a failed inline setup change keys after retiring an empty draft. Persist its replacement setup identity without storing secrets. Recover a server-saved account when refresh interrupts the save response, while preserving intentional account changes. - Render the production setup in Storybook and add error, recovery, and mobile states. - Inset native select carets in shared CSS. Preserve custom icons, listboxes, keyboard behavior, and forced-color controls. - Add browser regression coverage and an AgentMail Product E2E case with persisted-state and rendered-card evidence. ## Verification - Full `pnpm -r typecheck`, `pnpm build`, `pnpm check:token-gates`, and `git diff --check` passed after the default-availability change. - All 485 focused tests passed. These cover setup, management, catalog and route gates, connection intents, email authorization, Cursor execution, and the OpenAPI contract. All 39 email integration tests run with the experimental chat setting off. - The shared polling change passed four behavioral tests, UI typecheck and build, and token gates. - `tests/e2e/agentmail.spec.ts` passed with the actual server setting off. This full-stack browser test uses simulated provider responses. It covers catalog entry, saved keys, editable address and domain controls, creation, conflicts, retry, all management tabs, clipboard feedback, the provider link, and task email rendering. - In the live local browser, Add connection reached the editable email step with the saved account key. The verified custom domain was selected by default. Both domain choices worked. The existing inbox Settings page remained available. Both active inboxes completed new mail checks with the setting off. No new provider inbox or email message was created for this pass. - Earlier live provider acceptance covered creation on a verified custom domain, Finish connecting on the reported draft, successful mail checks after refresh, and catalog removal of disposable draft and active connections. Clicking the email address copied the exact address and showed Copied!. View inbox opened the same inbox in AgentMail’s console. No email messages were sent. - Production setup and Settings Storybook builds and interactions passed. Settings states include active, paused, unassigned, revoked, webhook, long-address, mobile, and reconnect. Receiving and revoked-access stories had zero accessibility violations. - Full local `pnpm test:run` on an earlier revision completed with 14,709 passing, 87 skipped, and four transient failures. All four failed cases passed in focused reruns without product changes. That serial full local command was not repeated after each follow-up. The latest-head full CI suite is the final test gate. - CI found an obsolete browser assertion that hid every channel when the flag was off. Updated it to keep AgentMail and the Channels surface visible while preserving the GitHub chat route gates. All 11 provider browser tests passed locally after scoping the Channels selector to the agent sidebar. Two initial local attempts stopped at temporary Postgres initialization. The passing run used a separate disposable database on the existing local Postgres server; it was removed after the test. - Updated the remaining sidebar and aggregator discovery assertions for default AgentMail availability. Ordinary task fixtures now return no email thread. All 128 sidebar/task-page tests and all 42 aggregator tests passed locally. - Latest head `b42bb4cd5cc9f2d01a99ab8026832d5a956ea85f`: full CI passed, with 54 successful checks including Snyk and two intentional Storybook skips. The CI run is https://github.com/paperclipai/paperclip/actions/runs/37020833647. A fresh Greptile review scored 5/5 with no unresolved threads. Live model evaluations and inbound/outbound email delivery were not run. ## Risks - AgentMail no longer needs experimental opt-in. Setup still requires a human to connect an account and assign an inbox. Inline setup creates an inbox after a human submits a new or saved key. Company access, agent access, inbox assignment, and completion checks remain enforced. - AgentMail read APIs cannot prove global address availability. The visible-list check is bounded to 100 entries and cannot see inboxes outside the key’s scope. The UI reports this limitation, suggests alternatives without claiming they are free, and keeps final creation conflicts inline. Lookup outages show an error without preventing the authoritative creation attempt. - Native select CSS affects the whole app. Custom-icon selects and multi-row lists are excluded. Forced-color mode keeps the browser caret. - Saved-key discovery uses stored verified scope metadata and checks authorized legacy credentials concurrently within a shared three-second deadline. Provider outages mark legacy choices unavailable; users can still enter another key. Final use rechecks authorization and provider access. - No database migration or transport default change. Live connection remains the default. ## Model Used OpenAI Codex, GPT-6, with reasoning, tool use, and code execution. The exact served model ID and context-window size are not exposed in this session. ## Checklist - [x] I have included a thinking path that traces from project context to this change - [x] I have specified the model used (with version and capability details) - [x] I have checked ROADMAP.md and confirmed this PR does not duplicate planned core work - [x] I have searched GitHub for duplicate or related PRs and linked them above - [x] I have either (a) linked existing issues with `Fixes: #` / `Closes #` / `Refs #` OR (b) described the issue in-PR following the relevant issue template - [x] I have not referenced internal/instance-local Paperclip issues or links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip` URLs) - [x] My branch name describes the change (e.g. `docs/...`, `fix/...`) and contains no internal Paperclip ticket id or instance-derived details - [x] I have run tests locally and they pass (focused suites; full-suite limitation documented above) - [x] I have added or updated tests where applicable - [x] I have updated relevant documentation to reflect my changes - [x] I have considered and documented any risks above - [x] All Paperclip CI gates are green (latest head `b42bb4cd5cc9f2d01a99ab8026832d5a956ea85f`) - [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups (latest head `b42bb4cd5cc9f2d01a99ab8026832d5a956ea85f`) - [x] I will address all Greptile and reviewer comments before requesting merge --------- Co-authored-by: Paperclip <noreply@paperclip.ing> |
||
|
|
ec3bacc9bd |
fix(chat): hide ignored provider information (#14929)
## Thinking Path > - Paperclip is the open source app people use to manage AI agents for work. > - Task and agent chats show agent progress and problems that need attention. > - Codex also sends account, skill, and unrelated thread notifications. > - The runner correctly ignores that information but reports it as a warning. > - Chat then shows an internal diagnostic as an actionable provider notice. > - This pull request keeps the diagnostic in run logs and removes it from chat. > - Real provider warnings, errors, and agent replies remain visible. ## Linked Issues or Issue Description **What happened?** Chat showed “Received a provider update” and a warning with the text “ignored unrelated provider information”. Its details said “User Actionable: Yes” even though no user action was needed. Saved conversations retained the same noise. **Expected behavior** Keep ignored provider information in the run log. Do not show it as chat activity or a user warning. Preserve real warnings and errors. **Steps to reproduce** 1. Start a conversation with the native Codex runner. 2. Have the provider send an account update, skill change, or unrelated thread notification during the turn. 3. Inspect live chat and reload its saved history. The regression tests also reproduce the old stored notice without a live account. **Paperclip version or commit** Source implementation on master at `e00d10d5d`. The duplicate search found no open PR for this fix. Related prior work: #13109 improved provider-notice presentation. #12367 added Codex thread normalization. This change addresses the internal information that those paths still projected as chat warnings. **Deployment mode** Native Paperclip Runner with the Codex app-server provider. The issue was seen in hosted chat and can be reproduced with local provider fixtures. ## What Changed - Map ignored unrelated Codex information to `harness.diagnostic` in the Rust and TypeScript normalizers. - Retain a bounded allowlist of redacted provider method and thread/turn identifiers. - Use the same Unicode character limit and truncation marker in both normalizers. - Share the text redactor through a pure helper. Keep provider connection code out of the standalone demo's source closure. - Omit that diagnostic and the matching legacy notice from live chat. - Omit the matching legacy notice from saved chat history. - Test diagnostic retention, account-notification integration, live and saved chat, and continued visibility of real warnings, errors, and replies. - Document the local run-log event and historical display behavior. ## Verification - Passed: 68 tests in the two affected UI transcript suites. - Passed: 60 TypeScript tests across provider events, transport behavior, and the standalone demo boundary. - Passed: 13 Rust provider-event tests and the Codex account-notification integration test. - Passed: `pnpm check:token-gates` and Cargo formatting checks. - Passed: full `pnpm build` and `pnpm -r typecheck`. After the review fix, the provider package build, typecheck, and both provider-event suites passed again. - Full local `pnpm test:run` failed: 608 files / 10,904 tests passed, 30 server suites failed, and 104 files / 4,012 tests were skipped. Most failures were embedded PostgreSQL startup errors. Two tests timed out in `heartbeat-comment-wake-batching` and `workspace-git-snapshot-streaming`. PostgreSQL startup also failed in `heartbeat-run-event-sequencing` and `native-finalization-migration`. These server files are unchanged by this PR. Isolated heartbeat reruns were skipped locally. The stable test script stopped after this general-server group, so later groups did not run locally. - The original review thread is resolved. Greptile is 5/5 on current head `683dab7cce57187c57e84c83f5e9da4ad75c9c04`. - All current-head CI gates passed, including the full server/chat/workspace test matrix, Rust and TypeScript runner suites, browser E2E, build, typecheck, and release canary. [CI run](https://github.com/paperclipai/paperclip/actions/runs/37021330663). - Replay the exact old warning in either transcript adapter. It must produce no chat row. A genuine provider warning or error must still produce a row. ## Risks - Low risk. The display filter matches one diagnostic code or the complete legacy warning shape. Other provider notices remain visible. - New ignored-information events use the existing harness-diagnostic event type. They retain diagnostic evidence without original account payloads. - No database migration, API permission, provider execution, or recovery behavior changes. This affects the local run log, not Telemetry or OpenTelemetry exports. ## Model Used OpenAI Codex, GPT-6. The exact backend model ID and context-window size are not exposed in this session. Used reasoning, repository inspection, code editing, tool use, and test execution. ## Checklist - [x] I have included a thinking path that traces from project context to this change - [x] I have specified the model used (with version and capability details) - [x] I have checked ROADMAP.md and confirmed this PR does not duplicate planned core work - [x] I have searched GitHub for duplicate or related PRs and linked them above - [x] I have either (a) linked existing issues with `Fixes: #` / `Closes #` / `Refs #` OR (b) described the issue in-PR following the relevant issue template - [x] I have not referenced internal/instance-local Paperclip issues or links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip` URLs) - [x] My branch name describes the change (e.g. `docs/...`, `fix/...`) and contains no internal Paperclip ticket id or instance-derived details - [x] I have run the affected tests locally and they pass (the broad local run has PostgreSQL startup errors and timeouts documented above; the full CI matrix passed) - [x] I have added or updated tests where applicable - [x] I have updated relevant documentation to reflect my changes - [x] I have considered and documented any risks above - [x] All Paperclip CI gates are green - [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups - [x] I will address all Greptile and reviewer comments before requesting merge --------- Co-authored-by: Paperclip <noreply@paperclip.ing> |
||
|
|
479debe9e3 |
build(deps): bump aws-actions/configure-aws-credentials from 6.2.3 to 6.3.0 (#12966)
Bumps [aws-actions/configure-aws-credentials](https://github.com/aws-actions/configure-aws-credentials) from 6.2.3 to 6.3.0. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/aws-actions/configure-aws-credentials/releases">aws-actions/configure-aws-credentials's releases</a>.</em></p> <blockquote> <h2>v6.3.0</h2> <h2><a href="https://github.com/aws-actions/configure-aws-credentials/compare/v6.2.4...v6.3.0">6.3.0</a> (2026-09-11)</h2> <h3>Features</h3> <ul> <li>add translate-env-variables option (<a href="https://redirect.github.com/aws-actions/configure-aws-credentials/issues/1961">#1961</a>) (<a href="https://github.com/aws-actions/configure-aws-credentials/commit/57b83659c2db2eb3b9c655186bef9a6a8f6620cb">57b8365</a>)</li> </ul> <h2>v6.2.4</h2> <h2><a href="https://github.com/aws-actions/configure-aws-credentials/compare/v6.2.3...v6.2.4">6.2.4</a> (2026-08-31)</h2> <h3>Bug Fixes</h3> <ul> <li>account-ids handling, mask proxy as secret in logs (<a href="https://redirect.github.com/aws-actions/configure-aws-credentials/issues/1943">#1943</a>) (<a href="https://github.com/aws-actions/configure-aws-credentials/commit/aa6526434b08748f8776b29964e3f1f5d90e7b63">aa65264</a>)</li> <li>skip backoff sleep after the final retryAndBackoff attempt (<a href="https://redirect.github.com/aws-actions/configure-aws-credentials/issues/1937">#1937</a>) (<a href="https://github.com/aws-actions/configure-aws-credentials/commit/3852440c21363386b7b790605685d08a7c1a4876">3852440</a>)</li> </ul> </blockquote> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/aws-actions/configure-aws-credentials/blob/main/CHANGELOG.md">aws-actions/configure-aws-credentials's changelog</a>.</em></p> <blockquote> <h1>Changelog</h1> <p>All notable changes to this project will be documented in this file. See <a href="https://github.com/conventional-changelog/standard-version">standard-version</a> for commit guidelines.</p> <h2><a href="https://github.com/aws-actions/configure-aws-credentials/compare/v6.2.4...v6.3.0">6.3.0</a> (2026-09-11)</h2> <h3>Features</h3> <ul> <li>add translate-env-variables option (<a href="https://redirect.github.com/aws-actions/configure-aws-credentials/issues/1961">#1961</a>) (<a href="https://github.com/aws-actions/configure-aws-credentials/commit/57b83659c2db2eb3b9c655186bef9a6a8f6620cb">57b8365</a>)</li> </ul> <h2><a href="https://github.com/aws-actions/configure-aws-credentials/compare/v6.2.3...v6.2.4">6.2.4</a> (2026-08-31)</h2> <h3>Bug Fixes</h3> <ul> <li>account-ids handling, mask proxy as secret in logs (<a href="https://redirect.github.com/aws-actions/configure-aws-credentials/issues/1943">#1943</a>) (<a href="https://github.com/aws-actions/configure-aws-credentials/commit/aa6526434b08748f8776b29964e3f1f5d90e7b63">aa65264</a>)</li> <li>skip backoff sleep after the final retryAndBackoff attempt (<a href="https://redirect.github.com/aws-actions/configure-aws-credentials/issues/1937">#1937</a>) (<a href="https://github.com/aws-actions/configure-aws-credentials/commit/3852440c21363386b7b790605685d08a7c1a4876">3852440</a>)</li> </ul> <h2><a href="https://github.com/aws-actions/configure-aws-credentials/compare/v6.2.2...v6.2.3">6.2.3</a> (2026-07-22)</h2> <h3>Bug Fixes</h3> <ul> <li>attach git credentials before Tag Major Version push (<a href="https://redirect.github.com/aws-actions/configure-aws-credentials/issues/1877">#1877</a>) (<a href="https://github.com/aws-actions/configure-aws-credentials/commit/9ae780b171afa8c5a3a6a2d154a765b709492482">9ae780b</a>)</li> <li>PackedPolicyTooLarge detection in STS tags (<a href="https://redirect.github.com/aws-actions/configure-aws-credentials/issues/1899">#1899</a>) (<a href="https://github.com/aws-actions/configure-aws-credentials/commit/fa8d6a57bbf44b34439fb080bbdadc7c92c285eb">fa8d6a5</a>)</li> </ul> <h2><a href="https://github.com/aws-actions/configure-aws-credentials/compare/v6.2.1...v6.2.2">6.2.2</a> (2026-07-07)</h2> <h3>Miscellaneous Chores</h3> <ul> <li>release 6.2.2 (<a href="https://github.com/aws-actions/configure-aws-credentials/commit/d01d678e65d6d2bd9d5ca7a95d6f07b00e25f2c2">d01d678</a>)</li> </ul> <h2><a href="https://github.com/aws-actions/configure-aws-credentials/compare/v6.2.0...v6.2.1">6.2.1</a> (2026-06-26)</h2> <h3>Bug Fixes</h3> <ul> <li>enforce allowed-account-ids on all auth paths (<a href="https://redirect.github.com/aws-actions/configure-aws-credentials/issues/1847">#1847</a>) (<a href="https://github.com/aws-actions/configure-aws-credentials/commit/4d281fbc56a82e63c3fc14f2cc22361f34c97493">4d281fb</a>)</li> </ul> <h2><a href="https://github.com/aws-actions/configure-aws-credentials/compare/v6.1.3...v6.2.0">6.2.0</a> (2026-06-01)</h2> <h3>Features</h3> <ul> <li>add additional session tags by default (<a href="https://redirect.github.com/aws-actions/configure-aws-credentials/issues/1775">#1775</a>) (<a href="https://github.com/aws-actions/configure-aws-credentials/commit/e0ba7685077379a14a82d01fefd511490344ebfc">e0ba768</a>)</li> <li>add more retry logic and better logging (<a href="https://redirect.github.com/aws-actions/configure-aws-credentials/issues/1764">#1764</a>) (<a href="https://github.com/aws-actions/configure-aws-credentials/commit/540d0c13aedb8d55501d220bd2f0b3cdedfe84e8">540d0c1</a>)</li> <li>add regex validation to role-session-name (<a href="https://redirect.github.com/aws-actions/configure-aws-credentials/issues/1765">#1765</a>) (<a href="https://github.com/aws-actions/configure-aws-credentials/commit/e35449909c6ede5083a48ba4b8bbfaaa1cf09ba1">e354499</a>)</li> <li>Allow custom session tags to be passed when assuming a role (<a href="https://redirect.github.com/aws-actions/configure-aws-credentials/issues/1759">#1759</a>) (<a href="https://github.com/aws-actions/configure-aws-credentials/commit/61f50f630f383628add73c1eab3f1935ba07da2b">61f50f6</a>)</li> <li>expose run id in STS client user-agent (<a href="https://redirect.github.com/aws-actions/configure-aws-credentials/issues/1774">#1774</a>) (<a href="https://github.com/aws-actions/configure-aws-credentials/commit/29d1be30273e7ef371d59fccf6ec54572c64ec89">29d1be3</a>)</li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/aws-actions/configure-aws-credentials/commit/e1253824e5c10ff9df46874f81ed3ec929e19cfd"><code>e125382</code></a> chore(main): release 6.3.0 (<a href="https://redirect.github.com/aws-actions/configure-aws-credentials/issues/1963">#1963</a>)</li> <li><a href="https://github.com/aws-actions/configure-aws-credentials/commit/438100a0eb37d9180319c727b1e108d9a112a27a"><code>438100a</code></a> chore: add link to GH security docs (<a href="https://redirect.github.com/aws-actions/configure-aws-credentials/issues/1962">#1962</a>)</li> <li><a href="https://github.com/aws-actions/configure-aws-credentials/commit/e92ebccf3986be80a7535da17f1ed57aec450139"><code>e92ebcc</code></a> chore: Update dist</li> <li><a href="https://github.com/aws-actions/configure-aws-credentials/commit/57b83659c2db2eb3b9c655186bef9a6a8f6620cb"><code>57b8365</code></a> feat: add translate-env-variables option (<a href="https://redirect.github.com/aws-actions/configure-aws-credentials/issues/1961">#1961</a>)</li> <li><a href="https://github.com/aws-actions/configure-aws-credentials/commit/cc49fa741eb53f7c83be6fce8f9b4df000cd3af7"><code>cc49fa7</code></a> chore(docs): README main branch guidance (<a href="https://redirect.github.com/aws-actions/configure-aws-credentials/issues/1960">#1960</a>)</li> <li><a href="https://github.com/aws-actions/configure-aws-credentials/commit/866cb167f1d1a75ae9c75cdb39377cfd9c0f794e"><code>866cb16</code></a> chore(deps-dev): bump smol-toml from 1.7.0 to 1.7.2 (<a href="https://redirect.github.com/aws-actions/configure-aws-credentials/issues/1958">#1958</a>)</li> <li><a href="https://github.com/aws-actions/configure-aws-credentials/commit/6782cb1b6df5d32e9354c1e6d6da4f956c0d61c4"><code>6782cb1</code></a> chore(deps-dev): bump generate-license-file from 4.2.4 to 4.2.5 (<a href="https://redirect.github.com/aws-actions/configure-aws-credentials/issues/1951">#1951</a>)</li> <li><a href="https://github.com/aws-actions/configure-aws-credentials/commit/c20509ac5cba30e782e34cf33a0067e67c746cf0"><code>c20509a</code></a> chore: Update dist</li> <li><a href="https://github.com/aws-actions/configure-aws-credentials/commit/7a41fc6cd2b4970e71974e29fb3f0979f4eb20cb"><code>7a41fc6</code></a> chore(deps): bump <code>@aws-sdk/client-sts</code> from 3.1121.0 to 3.1127.0 (<a href="https://redirect.github.com/aws-actions/configure-aws-credentials/issues/1954">#1954</a>)</li> <li><a href="https://github.com/aws-actions/configure-aws-credentials/commit/726b71346f7761addb59879a6c73e0c64ec8f959"><code>726b713</code></a> chore(deps-dev): bump <code>@biomejs/biome</code> from 2.5.11 to 2.5.12 (<a href="https://redirect.github.com/aws-actions/configure-aws-credentials/issues/1957">#1957</a>)</li> <li>Additional commits viewable in <a href="https://github.com/aws-actions/configure-aws-credentials/compare/e6de054238d6b7531b4efff3b6587d9aade6a06c...e1253824e5c10ff9df46874f81ed3ec929e19cfd">compare view</a></li> </ul> </details> <br /> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>canary/v2026.1002.0-canary.11 |
||
|
|
e00d10d5d5 |
fix(connections): repair stale AI defaults from agent settings (#14916)
## Thinking Path > - Paperclip manages AI agents and controls the credentials used for their work. > - Managed AI connections resolve each responsible user's provider default. > - Agent settings created another account but kept the old default selected. > - A rejected provider test left the old account marked as connected. > - Claude ACP reported a typed login failure as a generic terminal-access error. > - This pull request repairs the selected account or selects the new login explicitly. > - Agents can save and run with the repaired credential, and failed logins request sign-in. ## Linked Issues or Issue Description - Fixes #14831. - Refs #13867. Environment failures remain separate from credential-health failures. ## What Changed - Add an agent-settings action to reconnect an unavailable personal default in place. Keep its connection, grant, default, and agent access. - State that a new account becomes the user's provider default. Select its returned grant before changing the agent binding. Keep the actual sign-in method. - Show default-update errors and allow retry without another provider login. - Show the agent-access choice. Connection managers start with company-wide access for their own tasks. Other members start with access for the current agent. - Use the server's connection-manager permission in the shared list response. This includes members with a custom management grant. - Mark credentials as needing attention after an explicit login rejection in Test or Save. This includes API-key 401 and 403 responses. Network, quota, and server failures keep the credential health unchanged. - Reuse the credential-generation check so an old failure cannot invalidate a newer reconnect. - Route Claude's typed provider `access` failure to the existing login-recovery flow. Replace its generic terminal-access fallback with a sign-in message. - Add regression tests and update the AI Connections documentation. ## Verification - Red: the UI tests failed on the missing reconnect action, unused returned grant, missing access choice, and lost default-update error. The server tests failed because rejected credentials stayed connected. The real ACP fixture returned `acpx_turn_failed` for typed login failures. - Green: 156 tests passed across the AI connection, hiring, agent field, and New Agent suites. All 37 environment-route tests passed. The Claude ACP authentication fixtures also passed. - `pnpm check:token-gates` passed. - `pnpm -r typecheck` passed. - `pnpm build` passed. - The full local `pnpm test:run` passed 707 files and 14,503 tests, then exited with an agent-conversation timeout and embedded PostgreSQL startup failures in unchanged suites. The isolated conversation and migration tests passed on rerun. Later local test groups did not run after this failure. - [All CI gates passed](https://github.com/paperclipai/paperclip/actions/runs/37012669356) on commit `38513dfe2`. This includes the full test matrix, browser tests, typecheck, build, Runner checks, and canary dry run. - Greptile reviewed commit `38513dfe2` and returned 5/5 with no open findings. - The regression tests use a real embedded database and a real ACP fixture process. Live provider sign-in requires a valid account and was not run. ## Risks - Connecting a new account from agent settings changes the user's provider default. The dialog states this before sign-in. - The displayed access choice can allow all company agents to use the account for its owner's tasks. Reconnect keeps the existing access. Server permissions still control installs. - Claude's typed `access` category maps to the provider's `auth_required` signal. Tool and workspace request failures retain their existing classification. - No database migration or provider credential format changes are required. ## Model Used - OpenAI GPT-6 through Codex. The exact served model identifier and context window are not exposed in this session. Capabilities used: reasoning, repository tools, code editing, and command execution. ## Checklist - [x] I have included a thinking path that traces from project context to this change - [x] I have specified the model used (with version and capability details) - [x] I have checked ROADMAP.md and confirmed this PR does not duplicate planned core work - [x] I have searched GitHub for duplicate or related PRs and linked them above - [x] I have either (a) linked existing issues with `Fixes: #` / `Closes #` / `Refs #` OR (b) described the issue in-PR following the relevant issue template - [x] I have not referenced internal/instance-local Paperclip issues or links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip` URLs) - [x] My branch name describes the change (e.g. `docs/...`, `fix/...`) and contains no internal Paperclip ticket id or instance-derived details - [x] I have run tests locally and they pass - [x] I have added or updated tests where applicable - [x] I have updated relevant documentation to reflect my changes - [x] I have considered and documented any risks above - [x] All Paperclip CI gates are green - [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups - [x] I will address all Greptile and reviewer comments before requesting merge --------- Co-authored-by: Paperclip <noreply@paperclip.ing>canary/v2026.1002.0-canary.10 |
||
|
|
408f70e69f |
fix(runner): preserve stock Codex base instructions (#14920)
## Thinking Path > - Paperclip is the open source app people use to manage AI agents for work. > - The native Runner connects Paperclip tasks to Codex app-server. > - Paperclip passed its runtime context as `baseInstructions`. > - That field replaces the stock Codex base prompt. > - This pull request sends the same Paperclip context as additive developer instructions. > - Codex keeps its stock prompt and still receives Paperclip task instructions and tools. ## Linked Issues or Issue Description **What happened?** The native Codex driver and Rust provider sent Paperclip context through `baseInstructions` on thread start and resume. Codex used this text in place of its stock base instructions. Direct-chat resume also sent an empty replacement base. The Runner Lab session path used the same replacement field. **Expected behavior** Codex should retain its stock base prompt. Paperclip should add its runtime context through `developerInstructions`. Other provider facades should retain their current instruction handling. **Steps to reproduce** 1. Create a native Codex session through Paperclip Runner. 2. Inspect the `thread/start` request in the native provider trace. 3. Resume the session and inspect `thread/resume`. 4. Before this fix, these paths set `baseInstructions`. After this fix, the Codex paths set `developerInstructions` and omit `baseInstructions`. **Paperclip version or commit** Reproduced against master at `cad26c6bfb736039c8ed5743da650a44792a083c`. **Deployment mode** Built from source. Native Codex app-server and runnerd paths. A local protocol probe used codex-cli 0.153.4 and a localhost Responses stub. No duplicate fix or matching public issue was found in the GitHub search. ## What Changed - Send additive developer instructions on Codex start and resume in the TypeScript driver, Rust provider, and Runner Lab session path. - Carry the additive fragment through runnerd, including runtime asset path mapping. - Preserve existing instruction fields for other provider facades, including OpenCode. - Add start/resume/direct-chat regression coverage and check the actual Rust provider request. - Document the historical option and trace field names. Record progress and follow-ups in the working checklist. ## Verification - `pnpm -r typecheck` — passed. - `pnpm build` — passed. - Targeted Codex driver lifecycle, driver, and live-session Vitest suites — 139 tests passed. - `cargo test --manifest-path packages/paperclip-runner/runner/Cargo.toml --locked -p paperclip-runner-core --test codex_provider` — 91 passed, 2 ignored subprocess helpers. - Real app-server probe: a localhost Responses stub captured identical 14,732-character stock base instructions on fresh start and cold resume. Both requests retained the Paperclip marker in developer input. Both stub turns completed. No paid inference was used. - Runnerd transport Vitest suite — 182 tests passed. - The initial `pnpm test:run` attempt reported local dependency-loading, embedded PostgreSQL startup, and macOS `/var` versus `/private/var` path failures. It was stopped after those failures. Loading-suite reruns passed 1,428 tests after the build; native interaction/finalization reruns passed 38 tests. A seven-suite diagnostic rerun passed 463 tests and isolated the remaining path and PostgreSQL setup failures. - With `TMPDIR=/private/tmp`, workspace, gateway, interaction, and attachment suites passed all 356 tests. The remaining environment-image and native-session-resumption suites passed all 44 tests with the same canonical temp path. All affected suites passed on rerun. The original full local command was stopped after failures and is not claimed as passing. - All 55 PR checks passed at `83281439456181396f3707eecda5d2ebc90bd14d`. Greptile scored 5/5 with no open review threads. - No paid live campaign or Product E2E browser suite was run. This change has protocol and regression coverage; it does not claim improved task quality. ## Risks - Stock Codex behavior may differ from behavior under the previous Paperclip replacement prompt. Restoring that behavior is the intended change. - Existing Codex threads retain their saved replacement base prompt. They need a provider session reset to receive the stock base. This PR does not reset active sessions or alter recovery rules. - The legacy `baseInstructions` option and trace field names remain for compatibility. They now describe the additive Paperclip fragment for Codex. - The separate Codex-through-ACP dependency patch remains a follow-up in the harness coverage checklist. This PR covers native app-server execution. ## Model Used OpenAI Codex, GPT-6. The exact runtime model variant and context window are not exposed in this session. Used reasoning, repository inspection, code editing, shell execution, and test tools. ## Checklist - [x] I have included a thinking path that traces from project context to this change - [x] I have specified the model used (with version and capability details) - [x] I have checked ROADMAP.md and confirmed this PR does not duplicate planned core work - [x] I have searched GitHub for duplicate or related PRs and linked them above - [x] I have either (a) linked existing issues with `Fixes: #` / `Closes #` / `Refs #` OR (b) described the issue in-PR following the relevant issue template - [x] I have not referenced internal/instance-local Paperclip issues or links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip` URLs) - [x] My branch name describes the change (e.g. `docs/...`, `fix/...`) and contains no internal Paperclip ticket id or instance-derived details - [x] I have run tests locally and they pass - [x] I have added or updated tests where applicable - [x] I have updated relevant documentation to reflect my changes - [x] I have considered and documented any risks above - [x] All Paperclip CI gates are green - [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups - [x] I will address all Greptile and reviewer comments before requesting merge --------- Co-authored-by: Paperclip <noreply@paperclip.ing> |
||
|
|
c46e41e81c |
fix(heartbeat): validate native MCP gateway ownership (#14914)
## Thinking Path > - Paperclip lets people manage agents and govern their tool access. > - Native runs receive an immutable MCP tool assignment for one agent. > - The gateway must enforce that owner when it authenticates a run token. > - Older gateway rows stored the owner only in metadata. > - This change validates the gateway and profile, binds new rows, and repairs valid older rows on reuse. > - It also delivers each native assignment once. > - Other agents cannot use the assignment, and explicit shared gateways keep their configured scope. ## Linked Issues or Issue Description Builds on #14012 by @busla (Jón Levy). That PR adds agent binding and seven regressions. This PR carries that fix onto current master and adds legacy authentication, profile validation, and duplicate-delivery coverage. Related: #14864 improves discovery memory use. **What happened?** Native gateway creation stored an owner in metadata but left `agentId` null. Authentication could therefore accept another agent's run token. Managed discovery could also deliver historical native assignments again. **Expected behavior** A native assignment accepts only its owner's run token. The gateway and profile must refer to the same immutable assignment. The current assignment enters the run configuration once. **Steps to reproduce** 1. Run the database fixtures in `heartbeat-runtime-mcp-servers.test.ts` on the baseline. 2. Create a native assignment and inspect its stored gateway owner. 3. Authenticate with another agent's run token, then inspect legacy reuse and managed delivery. 4. The baseline fails six ownership and delivery cases. The fix passes all twelve cases. **Paperclip version or commit** The red baseline is `f2e0f1963`. This PR is based on `cad26c6bf`, which includes the merged discovery fix. **Deployment mode** Native Paperclip Runner execution and managed Codex MCP delivery. Reproduction uses isolated database and HTTP fixtures. ## What Changed - Store the agent owner and agent context on new native gateways. - Validate profile and gateway assignment metadata before reuse or token creation. - Bind valid legacy rows with a company-scoped, null-owner update and validate the result. - Reject mismatched run tokens before legacy repair. - Identify native assignments by gateway metadata, the reserved profile key, or profile source. Reject missing or malformed provenance, including JSON null. - Exclude historical native assignments from managed gateway delivery. Keep their rows for existing runs. - Add twelve database and HTTP regressions and document the runtime contract. ## Verification - Red baseline: six regressions fail and four controls pass before the initial fix. Two additional regressions reproduce metadata-loss admission and a JSON-null TypeError before the review fix. - All twelve ownership regressions pass on the final code, including owner admission, cross-agent rejection, metadata loss, JSON-null HTTP 401, and explicit shared-gateway admission. Policy, listing-memory, and discovery HTTP coverage also passes. - Full workspace typecheck and build pass locally. Server typecheck and compilation pass again after the review fix. The final ownership and grant patches pass 42 combined database and HTTP regressions. - [Full CI](https://github.com/paperclipai/paperclip/actions/runs/37011383657) passes for `626a08ae66361cf586105877e24d806b1a7a9c20`: all 54 checks succeed; two optional Storybook checks skip. This includes full typecheck, build, all test shards, all eight E2E shards, runner verification, and the canary dry run. - Greptile scores that exact head 5/5. No review threads remain unresolved. ## Risks Invalid historical native gateway or profile metadata now rejects authentication. Valid unbound rows are repaired only when their owner reuses the assignment. Conflicting owners are never overwritten. Historical rows are retained for existing runs. Explicit shared gateways use ordinary profiles and keep their configured scopes. The reserved native profile namespace remains agent-owned even when gateway metadata is cleared. No schema or dependency changes are included. ## Model Used Original fix and seven regressions in #14012: Anthropic Claude Opus 5.5, `claude-opus-5-5`, 1M context, as reported by @busla. Extensions and verification: OpenAI Codex (GPT-6), with reasoning, repository inspection, code execution, and tests. This session does not expose the exact serving model identifier or context window. ## Checklist - [x] I have included a thinking path that traces from project context to this change - [x] I have specified the model used (with version and capability details) - [x] I have checked ROADMAP.md and confirmed this PR does not duplicate planned core work - [x] I have searched GitHub for duplicate or related PRs and linked them above - [x] I have either (a) linked existing issues with `Fixes: #` / `Closes #` / `Refs #` OR (b) described the issue in-PR following the relevant issue template - [x] I have not referenced internal/instance-local Paperclip issues or links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip` URLs) - [x] My branch name describes the change (e.g. `docs/...`, `fix/...`) and contains no internal Paperclip ticket id or instance-derived details - [x] I have run tests locally and they pass - [x] I have added or updated tests where applicable - [x] I have updated relevant documentation to reflect my changes - [x] I have considered and documented any risks above - [x] All Paperclip CI gates are green - [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups - [x] I will address all Greptile and reviewer comments before requesting merge --------- Co-authored-by: Paperclip <noreply@paperclip.ing>canary/v2026.1002.0-canary.9 |
||
|
|
483dbc8890 |
fix(tool-access): enforce stored grant restrictions (#14915)
## Thinking Path > - Paperclip governs the tools that agents can discover and call. > - Stored grants can limit access to a tool, connection, or application. > - The grant matcher must enforce every restriction in that scope. > - A nonmatching allow list fell through to a policy selector matcher that ignores allow. > - This change requires an explicit allow match and validates additional selectors. > - Malformed and unknown restrictions deny access. > - Discovery and execution now enforce the same stored grant limits. ## Linked Issues or Issue Description Related: #14864 adds the shared database and HTTP discovery fixture used here. Searched existing public PRs for tool grant scope fixes. No duplicate scope-validation fix was found. **What happened?** A stored grant with a nonmatching `scope.allow` could authorize a tool. Empty or malformed allow lists, unknown selectors, and combined mismatching selectors could also authorize access. The fallback policy matcher does not validate stored grant JSON. **Expected behavior** An explicit allow list must match the requested tool, connection, or application. Every additional selector must also match. Unknown or malformed restrictions must deny access. Existing null and empty-object scopes keep their broad grant behavior. **Steps to reproduce** 1. Run `tool-grant-scope.test.ts` on the baseline. 2. Create a deny profile and a grant that names another tool. 3. Attempt discovery or a call for the tool outside the grant. 4. The baseline authorizes access. The fix denies it. **Paperclip version or commit** The red baseline is `f2e0f1963`. This PR is based on `cad26c6bf`, which includes the merged discovery fix. **Deployment mode** The company-scoped MCP gateway. Reproduction uses isolated database fixtures and a deterministic HTTP provider. ## What Changed - Require an explicit allow entry to match the gateway or upstream tool name, connection, or application. - Apply all additional selectors after the allow match. - Reject unknown selectors, invalid value types, empty restrictions, and non-object scopes. - Preserve null and empty-object scope compatibility. - Add sixteen regressions, including discovery, successful execution, and revocation through the HTTP gateway. - Document stored grant scope behavior. ## Verification - Red baseline: seven restricted-scope cases and three malformed-root cases fail. HTTP discovery also exposes tools outside the grant. - All 16 grant regressions and 35 adjacent policy tests pass locally. The HTTP test excludes an ungranted tool from discovery, returns 403 for its call, and verifies that no provider call occurs. It also checks successful execution and later revocation. - Server typecheck passes. The final ownership and grant patches also pass 42 combined database and HTTP regressions. - [Full CI](https://github.com/paperclipai/paperclip/actions/runs/37011177989) passes for `803fa9440111742672c94c4471e5b98f15dd3b97`: all 54 checks succeed; two optional Storybook checks skip. This includes full typecheck, build, all test shards, all eight E2E shards, runner verification, and the canary dry run. - Greptile scores that exact head 5/5. No review threads remain unresolved. ## Risks Stored scopes with unknown keys or malformed restrictions now deny access. Operators must correct those grants before they can authorize tools. Null and empty-object scopes keep their previous broad behavior. There are no schema, dependency, or API changes. ## Model Used OpenAI Codex (GPT-6), with reasoning, repository inspection, code execution, database regressions, and HTTP tests. This session does not expose the exact serving model identifier or context window. ## Checklist - [x] I have included a thinking path that traces from project context to this change - [x] I have specified the model used (with version and capability details) - [x] I have checked ROADMAP.md and confirmed this PR does not duplicate planned core work - [x] I have searched GitHub for duplicate or related PRs and linked them above - [x] I have either (a) linked existing issues with `Fixes: #` / `Closes #` / `Refs #` OR (b) described the issue in-PR following the relevant issue template - [x] I have not referenced internal/instance-local Paperclip issues or links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip` URLs) - [x] My branch name describes the change (e.g. `docs/...`, `fix/...`) and contains no internal Paperclip ticket id or instance-derived details - [x] I have run tests locally and they pass - [x] I have added or updated tests where applicable - [x] I have updated relevant documentation to reflect my changes - [x] I have considered and documented any risks above - [x] All Paperclip CI gates are green - [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups - [x] I will address all Greptile and reviewer comments before requesting merge --------- Co-authored-by: Paperclip <noreply@paperclip.ing> |
||
|
|
cad26c6bfb |
fix(tool-gateway): bound MCP discovery memory and concurrency (#14864)
## Thinking Path > - Paperclip is the open source app people use to manage AI agents for work. > - Agents discover governed tools through the MCP gateway. > - A listing repeated policy and full run-row reads for each catalog tool. > - Parallel listings multiplied those allocations during run startup. > - One 900-tool baseline listing used 11,489 queries and about 1.7 GiB of extra heap in a fixture. > - This pull request shares reads within a listing and bounds whole listings across the process. > - The benefit is lower discovery memory use while execution still checks current policy. ## Linked Issues or Issue Description Refs #13115. Its on-demand target change affects the same listing loop. **What happened?** MCP discovery repeated roughly 13 reads per tool. Full run snapshots and repeated connection configurations caused large allocations. Per-listing bounds alone did not limit concurrent listings across gateways. **Expected behavior** Discovery reads shared inputs once per listing. The process bounds active and queued listings. Catalog payload size and policy evaluation still grow with the catalog. Tool execution checks current access rules. **Steps to reproduce** Create a company with a remote MCP connection, 900 catalog tools, large schemas, and a large run snapshot. Send concurrent tools/list requests using a run-bound gateway token. Run the committed benchmark for a deterministic reproduction. **Paperclip version or commit** Baseline:canary/v2026.1002.0-canary.8 |
||
|
|
c83df091b1 |
build(deps): bump react-i18next from 17.0.12 to 17.0.15 (#12970)
Bumps [react-i18next](https://github.com/i18next/react-i18next) from 17.0.12 to 17.0.15. <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/i18next/react-i18next/blob/master/CHANGELOG.md">react-i18next's changelog</a>.</em></p> <blockquote> <h2>17.0.15</h2> <ul> <li>fix(Trans): empty paired component tags now preserve a component's single valid React-element child, whether supplied through a named component map (<code><wrap></wrap></code>), a component array (<code><0></0></code>), or indexed JSX children (<code><1></1></code>). This matches the existing behavior for two or more children and self-closing tags. React represents one JSX child as an element and multiple children as an array; the previous array-only check silently rendered the one-child case empty. Compatibility note: when that sole element contains an interpolation object, the restored raw children can expose an existing React rendering limitation as an error instead of silently rendering empty; the same shape already errors with two children. Fixes <a href="https://redirect.github.com/i18next/react-i18next/issues/1932">#1932</a>.</li> </ul> <h2>17.0.14</h2> <ul> <li>fix: the <code>i18n</code> object returned by <code>useTranslation</code> was only refreshed when <code>i18n.language</code> changed, so a <code>resolvedLanguage</code> (or <code>languages</code>) change of its own kept handing components the previous snapshot. That happens whenever the translations for the current language arrive after the switch — i18next resolves to the fallback until its store has them — and components reading <code>i18n.resolvedLanguage</code> (language switchers, for example) then stayed one switch behind. The cached wrapper is now keyed on all three language fields, which are exactly the ones the surrounding <code>useMemo</code> already depends on; wrapper identity still only changes when the language state does, so the caching from <a href="https://redirect.github.com/i18next/react-i18next/issues/1885">#1885</a> is unaffected. Reported via <a href="https://redirect.github.com/i18next/next-i18next/issues/2348">next-i18next#2348</a>.</li> </ul> <h2>17.0.13</h2> <ul> <li>fix(types): the selector-form <code>keyPrefix</code> overload of <code>useTranslation()</code> is now available under <code>enableSelector: 'strict'</code>. <code>useTranslation</code> was gated on <code>true | 'optimize'</code> only, so under <code>'strict'</code> it resolved to the legacy signature and the selector overload disappeared entirely (<code>keyPrefix: ($) => $.ns.foo</code> failed with <code>Type '($: any) => any' is not assignable to type 'undefined'</code>). <code>Trans</code> already handled all three modes. Companion to the same fix for <code>getFixedT</code> in <a href="https://redirect.github.com/i18next/i18next/pull/2446">i18next#2446</a>. Thanks <a href="https://github.com/hovelopin"><code>@hovelopin</code></a> (<a href="https://redirect.github.com/i18next/react-i18next/pull/1930">#1930</a>).</li> </ul> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/i18next/react-i18next/commit/7d38e0919507f0d339ac29b9fbd5f718eaadc829"><code>7d38e09</code></a> 17.0.15</li> <li><a href="https://github.com/i18next/react-i18next/commit/875b327d3515c781cd083dd77d3d8838dc1efc06"><code>875b327</code></a> fix(Trans): preserve single-element children in empty slots</li> <li><a href="https://github.com/i18next/react-i18next/commit/5f8c5f9e6c7cdabdc476111d0748c91e33bbaa30"><code>5f8c5f9</code></a> 17.0.14</li> <li><a href="https://github.com/i18next/react-i18next/commit/6def81a790ddc55cc6c09a9f306ea6c88e25867c"><code>6def81a</code></a> fix: refresh the returned i18n wrapper when resolvedLanguage changes</li> <li><a href="https://github.com/i18next/react-i18next/commit/f37ea872c74e74ca64a5b6652cc131893405770b"><code>f37ea87</code></a> docs: "For AI assistants" paragraph in the README</li> <li><a href="https://github.com/i18next/react-i18next/commit/e0592bafde1a904588c115f67b36cddf382e49c5"><code>e0592ba</code></a> chore: keep dev-only and local files out of the npm package</li> <li><a href="https://github.com/i18next/react-i18next/commit/addf646a37f5980af08814b5a2568def28e7e428"><code>addf646</code></a> 17.0.13</li> <li><a href="https://github.com/i18next/react-i18next/commit/7c634ee3f396af22ec7b5c3c647b8d5ab198b5ae"><code>7c634ee</code></a> changelog v17.0.13</li> <li><a href="https://github.com/i18next/react-i18next/commit/5ceefb0eff8bb430c658b21e5a08b457e78d87df"><code>5ceefb0</code></a> fix(types): allow selector keyPrefix in useTranslation under enableSelector '...</li> <li><a href="https://github.com/i18next/react-i18next/commit/aa7ba520255753c50d7fff9ab33ce0c7a60a45a2"><code>aa7ba52</code></a> chore(examples): require activesupport >= 7.2.3.1 in the RN Gemfiles</li> <li>Additional commits viewable in <a href="https://github.com/i18next/react-i18next/compare/v17.0.12...v17.0.15">compare view</a></li> </ul> </details> <br /> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>nightly/v2026.1002.0-nightly.0 canary/v2026.1002.0-canary.7 |
||
|
|
f48bbba2ba |
build(deps): bump @assistant-ui/react from 0.15.21 to 0.15.22 (#12971)
Bumps [@assistant-ui/react](https://github.com/assistant-ui/assistant-ui/tree/HEAD/packages/react) from 0.15.21 to 0.15.22. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/assistant-ui/assistant-ui/releases">@assistant-ui/react's releases</a>.</em></p> <blockquote> <h2><code>@assistant-ui/react</code><a href="https://github.com/0"><code>@0</code></a>.15.22</h2> <h3>Patch Changes</h3> <ul> <li> <p><a href="https://redirect.github.com/assistant-ui/assistant-ui/pull/8032">#8032</a> <a href="https://github.com/assistant-ui/assistant-ui/commit/d09680175b062b26c393aa274bf4068012b82a9c"><code>d096801</code></a> - fix: type the assistant transport request body that <code>prepareSendCommandsRequest</code> receives; its fields are no longer <code>unknown</code> in <code>@assistant-ui/react</code>, and <code>threadId</code> is an optional <code>string</code>, absent when a resume has no remote id, instead of <code>string | null</code> (<a href="https://github.com/apps/rupic-app"><code>@rupic-app</code></a>)</p> </li> <li> <p><a href="https://redirect.github.com/assistant-ui/assistant-ui/pull/8342">#8342</a> <a href="https://github.com/assistant-ui/assistant-ui/commit/aa0f33854f1d054ca747710d2144ba9e77c3182e"><code>aa0f338</code></a> - feat: <code>useAssistantTransportRuntime</code> accepts <code>cloud</code>: Assistant Cloud backs the thread list and every request carries the cloud thread id; without <code>cloud</code>, <code>NEXT_PUBLIC_ASSISTANT_BASE_URL</code> selects Assistant Cloud, as it does for <code>useLocalRuntime</code>. <code>adapters.history</code>, which this runtime never read, is deprecated (<a href="https://github.com/okisdev"><code>@okisdev</code></a>)</p> </li> <li> <p><a href="https://redirect.github.com/assistant-ui/assistant-ui/pull/7731">#7731</a> <a href="https://github.com/assistant-ui/assistant-ui/commit/455e2ac67bbcb7329d3f8367daf409eac5bc3a27"><code>455e2ac</code></a> - fix: lock the current scroll container after reasoning content or its ancestor chain changes (<a href="https://github.com/Kinfe123"><code>@Kinfe123</code></a>)</p> </li> <li> <p><a href="https://redirect.github.com/assistant-ui/assistant-ui/pull/7730">#7730</a> <a href="https://github.com/assistant-ui/assistant-ui/commit/af49e91648334569ac36a94f602a66b6dbe031dc"><code>af49e91</code></a> - fix: prevent stale message hover updates after unmount (<a href="https://github.com/Kinfe123"><code>@Kinfe123</code></a>)</p> </li> <li> <p><a href="https://redirect.github.com/assistant-ui/assistant-ui/pull/7737">#7737</a> <a href="https://github.com/assistant-ui/assistant-ui/commit/6cc0bee320a1eccc855b4140249b8ac552010472"><code>6cc0bee</code></a> - fix: scope selection toolbars to their owning thread (<a href="https://github.com/Kinfe123"><code>@Kinfe123</code></a>)</p> </li> <li> <p><a href="https://redirect.github.com/assistant-ui/assistant-ui/pull/8339">#8339</a> <a href="https://github.com/assistant-ui/assistant-ui/commit/967de5db4ca0c876bff20bffb783167651357cdd"><code>967de5d</code></a> - feat: <code>CloudRendererHost</code> draws a stored conversation in the Assistant Cloud dashboard's As shown view with the app's own components; a read only thread now reports itself disabled, so its composer renders disabled, and ignores composer input instead of throwing (<a href="https://github.com/okisdev"><code>@okisdev</code></a>)</p> </li> <li> <p><a href="https://redirect.github.com/assistant-ui/assistant-ui/pull/8030">#8030</a> <a href="https://github.com/assistant-ui/assistant-ui/commit/e8fac8d7e2eef1b2eee8ccb98dd9d69d03619ae3"><code>e8fac8d</code></a> - feat: show a message with uploading attachments in the thread while it is being sent (<a href="https://github.com/okisdev"><code>@okisdev</code></a>)</p> <p><code>MessagePrimitive.Attachments</code> now hands its render function <code>Attachment</code> rather than <code>CompleteAttachment</code>, because the row of a message that is still being sent shows attachments that are still uploading. a render function that reads <code>attachment.content</code> should check <code>attachment.status.type === "complete"</code> first.</p> </li> <li> <p><a href="https://redirect.github.com/assistant-ui/assistant-ui/pull/7877">#7877</a> <a href="https://github.com/assistant-ui/assistant-ui/commit/83f53542e7f91d1b93489e534b40151ca34094a8"><code>83f5354</code></a> - fix: honor registered data-part fallbacks on native MessageContent and grouped parts (<a href="https://github.com/Kinfe123"><code>@Kinfe123</code></a>)</p> </li> <li> <p><a href="https://redirect.github.com/assistant-ui/assistant-ui/pull/7760">#7760</a> <a href="https://github.com/assistant-ui/assistant-ui/commit/84e0cf4c9b7fc92a85d1360b37e2e20b73bed650"><code>84e0cf4</code></a> - fix: emit declarations from one TypeScript program so two builds of the same commit produce the same <code>.d.ts</code> (<a href="https://github.com/okisdev"><code>@okisdev</code></a>)</p> <p><code>aui-build</code> now emits the unbundled <code>.d.ts</code> output in one TypeScript pass over the whole package, so two builds of the same commit produce identical declarations; the per-module emit it replaced followed the bundler's load order and let union member order, alias visibility and import specifiers move between builds. Declarations import barrels as the source does and keep <code>import type</code>; the exported types are unchanged. A <code>/// <reference></code> directive that must reach the published declarations now carries <code>preserve="true"</code> in the source.</p> </li> <li> <p><a href="https://redirect.github.com/assistant-ui/assistant-ui/pull/7838">#7838</a> <a href="https://github.com/assistant-ui/assistant-ui/commit/3d01501c5642b7b0a4f1094a5a0b93976d02eed7"><code>3d01501</code></a> - fix: every distribution re-exports the same shared surface from <code>@assistant-ui/core</code>. <code>@assistant-ui/react-ink</code> gains <code>ReadonlyThreadProvider</code>, <code>ToolCallMessagePartStatus</code>, <code>groupPartByType</code>, <code>GroupByContext</code>, <code>VoiceSessionState</code>, the external store runtime (<code>useExternalStoreRuntime</code>, <code>useExternalMessageConverter</code>, their adapters and options), the message queue, the tool approval types, the generative UI renderer and the cloud thread list hooks; <code>@assistant-ui/react-native</code> gains <code>VoiceSessionState</code>, the cloud thread list hooks, the generative UI renderer and the runtime state and adapter types the web package already carried; <code>@assistant-ui/react</code> gains <code>MessageRole</code>, <code>RunConfig</code>, <code>RuntimeCapabilities</code>, <code>RemoteThreadListOptions</code>, <code>ThreadsState</code>, <code>JoinStrategy</code>, <code>TitleGenerationAdapter</code>, <code>createSimpleTitleAdapter</code> and <code>ChainOfThoughtPartByIndexProvider</code>. (<a href="https://github.com/okisdev"><code>@okisdev</code></a>)</p> </li> <li> <p><a href="https://redirect.github.com/assistant-ui/assistant-ui/pull/7520">#7520</a> <a href="https://github.com/assistant-ui/assistant-ui/commit/2171a8e06b8ca739a98eba927ab8b27175dd7be6"><code>2171a8e</code></a> - fix(react): attach the ExportMarkdown download anchor to the document so Firefox starts the download (<a href="https://github.com/Kinfe123"><code>@Kinfe123</code></a>)</p> </li> <li> <p><a href="https://redirect.github.com/assistant-ui/assistant-ui/pull/8010">#8010</a> <a href="https://github.com/assistant-ui/assistant-ui/commit/1c86c4c9e9cd4f7b2a27efd089d779831e54c2f0"><code>1c86c4c</code></a> - fix: prevent disabled attachment dropzones from navigating to dropped files. (<a href="https://github.com/Kinfe123"><code>@Kinfe123</code></a>)</p> </li> <li> <p><a href="https://redirect.github.com/assistant-ui/assistant-ui/pull/7733">#7733</a> <a href="https://github.com/assistant-ui/assistant-ui/commit/e2f13068534f9ca2d526a4e683846db7d6f2ec3b"><code>e2f1306</code></a> - fix: clear attachment drag state when the dropzone is disabled (<a href="https://github.com/Kinfe123"><code>@Kinfe123</code></a>)</p> </li> <li> <p><a href="https://redirect.github.com/assistant-ui/assistant-ui/pull/7897">#7897</a> <a href="https://github.com/assistant-ui/assistant-ui/commit/16ef5b3e1f982a392c00a9a90b291c02e6c6fc5c"><code>16ef5b3</code></a> - fix(react): stop a pending bottom scroll from hijacking keyboard-driven content growth (<a href="https://github.com/Kinfe123"><code>@Kinfe123</code></a>)</p> </li> <li> <p><a href="https://redirect.github.com/assistant-ui/assistant-ui/pull/7762">#7762</a> <a href="https://github.com/assistant-ui/assistant-ui/commit/49283649b9119d8fe3acbc7bd2703d3473a98e9b"><code>4928364</code></a> - fix: resolve component registries by own keys only, so a component, tool or data part name that only <code>Object.prototype</code> has (<code>toString</code>, <code>constructor</code>, <code>__proto__</code>) takes the <code>Fallback</code> or <code>GenerativeUIRenderError</code> path instead of rendering the inherited built-in (<a href="https://github.com/okisdev"><code>@okisdev</code></a>)</p> </li> <li> <p><a href="https://redirect.github.com/assistant-ui/assistant-ui/pull/7725">#7725</a> <a href="https://github.com/assistant-ui/assistant-ui/commit/258ad136d849f67c06207cd8cfd944364c1e59cf"><code>258ad13</code></a> - fix: expose feedback submission state to assistive technology (<a href="https://github.com/apps/rupic-app"><code>@rupic-app</code></a>)</p> </li> <li> <p><a href="https://redirect.github.com/assistant-ui/assistant-ui/pull/7981">#7981</a> <a href="https://github.com/assistant-ui/assistant-ui/commit/0252c6966322f09eda17172bfcaab8c641529bcf"><code>0252c69</code></a> - feat: name the runtime state types <code>ThreadRuntimeState</code>, <code>MessageRuntimeState</code>, <code>ComposerRuntimeState</code>, <code>AttachmentRuntimeState</code> and <code>ThreadListItemRuntimeState</code> (<a href="https://github.com/okisdev"><code>@okisdev</code></a>)</p> <p>these are the states <code>ThreadRuntime</code>, <code>MessageRuntime</code>, <code>ComposerRuntime</code>, <code>AttachmentRuntime</code> and <code>ThreadListItemRuntime</code> return from <code>getState()</code>, now exported by all three distributions; <code>@assistant-ui/react-native</code> and <code>@assistant-ui/react-ink</code> had no name for them. in <code>@assistant-ui/react</code>, <code>ThreadState</code>, <code>MessageState</code>, <code>ComposerState</code>, <code>AttachmentState</code> and <code>ThreadListItemState</code> still name these runtime states but are deprecated: from 0.16 they name the store states <code>useAuiState</code> reads, as they already do in <code>@assistant-ui/react-native</code> and <code>@assistant-ui/react-ink</code>. code that annotates a runtime's <code>getState()</code> result should move to the new names.</p> </li> <li> <p><a href="https://redirect.github.com/assistant-ui/assistant-ui/pull/8149">#8149</a> <a href="https://github.com/assistant-ui/assistant-ui/commit/1b1ff55c227a8bf58d6413ec8b248162540acc19"><code>1b1ff55</code></a> - fix(react): keep the selection toolbar in sync after a right-click, so a context menu that swallows the mouseup no longer leaves it showing (and quoting) the previous selection (<a href="https://github.com/samdickson22"><code>@samdickson22</code></a>)</p> </li> <li> <p><a href="https://redirect.github.com/assistant-ui/assistant-ui/pull/8065">#8065</a> <a href="https://github.com/assistant-ui/assistant-ui/commit/2caacadf195a30efe04aaff8b46679ad99e70e74"><code>2caacad</code></a> - feat: a tool UI can record what the user did on its tool call with <code>unstable_recordInteraction</code>, kept on the part as <code>unstable_interactions</code> and stored in cloud history; the answer to a human input request is recorded once the runtime accepts it, the local runtime persists records and keeps them out of model input, external stores receive them through <code>unstable_onRecordToolInteraction</code>, and readonly threads ignore them (<a href="https://github.com/okisdev"><code>@okisdev</code></a>)</p> </li> <li> <p><a href="https://redirect.github.com/assistant-ui/assistant-ui/pull/7068">#7068</a> <a href="https://github.com/assistant-ui/assistant-ui/commit/4b069f90fbcb58953ebc7b9c4becca0bf4607842"><code>4b069f9</code></a> - fix: Use successful Standard Schema output for tool execution and model output. Keep the original arguments for validation errors and stored tool calls. (<a href="https://github.com/ephraimduncan"><code>@ephraimduncan</code></a>)</p> </li> <li> <p><a href="https://redirect.github.com/assistant-ui/assistant-ui/pull/7777">#7777</a> <a href="https://github.com/assistant-ui/assistant-ui/commit/c51ba8fb3014375ae62784084aaefe3ecc6d72fa"><code>c51ba8f</code></a> - feat(core): let typed text enter a connected voice session through <code>sendText</code> (<a href="https://github.com/okisdev"><code>@okisdev</code></a>)</p> </li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/assistant-ui/assistant-ui/blob/main/packages/react/CHANGELOG.md">@assistant-ui/react's changelog</a>.</em></p> <blockquote> <h2>0.15.22</h2> <h3>Patch Changes</h3> <ul> <li> <p><a href="https://redirect.github.com/assistant-ui/assistant-ui/pull/8032">#8032</a> <a href="https://github.com/assistant-ui/assistant-ui/commit/d09680175b062b26c393aa274bf4068012b82a9c"><code>d096801</code></a> - fix: type the assistant transport request body that <code>prepareSendCommandsRequest</code> receives; its fields are no longer <code>unknown</code> in <code>@assistant-ui/react</code>, and <code>threadId</code> is an optional <code>string</code>, absent when a resume has no remote id, instead of <code>string | null</code> (<a href="https://github.com/apps/rupic-app"><code>@rupic-app</code></a>)</p> </li> <li> <p><a href="https://redirect.github.com/assistant-ui/assistant-ui/pull/8342">#8342</a> <a href="https://github.com/assistant-ui/assistant-ui/commit/aa0f33854f1d054ca747710d2144ba9e77c3182e"><code>aa0f338</code></a> - feat: <code>useAssistantTransportRuntime</code> accepts <code>cloud</code>: Assistant Cloud backs the thread list and every request carries the cloud thread id; without <code>cloud</code>, <code>NEXT_PUBLIC_ASSISTANT_BASE_URL</code> selects Assistant Cloud, as it does for <code>useLocalRuntime</code>. <code>adapters.history</code>, which this runtime never read, is deprecated (<a href="https://github.com/okisdev"><code>@okisdev</code></a>)</p> </li> <li> <p><a href="https://redirect.github.com/assistant-ui/assistant-ui/pull/7731">#7731</a> <a href="https://github.com/assistant-ui/assistant-ui/commit/455e2ac67bbcb7329d3f8367daf409eac5bc3a27"><code>455e2ac</code></a> - fix: lock the current scroll container after reasoning content or its ancestor chain changes (<a href="https://github.com/Kinfe123"><code>@Kinfe123</code></a>)</p> </li> <li> <p><a href="https://redirect.github.com/assistant-ui/assistant-ui/pull/7730">#7730</a> <a href="https://github.com/assistant-ui/assistant-ui/commit/af49e91648334569ac36a94f602a66b6dbe031dc"><code>af49e91</code></a> - fix: prevent stale message hover updates after unmount (<a href="https://github.com/Kinfe123"><code>@Kinfe123</code></a>)</p> </li> <li> <p><a href="https://redirect.github.com/assistant-ui/assistant-ui/pull/7737">#7737</a> <a href="https://github.com/assistant-ui/assistant-ui/commit/6cc0bee320a1eccc855b4140249b8ac552010472"><code>6cc0bee</code></a> - fix: scope selection toolbars to their owning thread (<a href="https://github.com/Kinfe123"><code>@Kinfe123</code></a>)</p> </li> <li> <p><a href="https://redirect.github.com/assistant-ui/assistant-ui/pull/8339">#8339</a> <a href="https://github.com/assistant-ui/assistant-ui/commit/967de5db4ca0c876bff20bffb783167651357cdd"><code>967de5d</code></a> - feat: <code>CloudRendererHost</code> draws a stored conversation in the Assistant Cloud dashboard's As shown view with the app's own components; a read only thread now reports itself disabled, so its composer renders disabled, and ignores composer input instead of throwing (<a href="https://github.com/okisdev"><code>@okisdev</code></a>)</p> </li> <li> <p><a href="https://redirect.github.com/assistant-ui/assistant-ui/pull/8030">#8030</a> <a href="https://github.com/assistant-ui/assistant-ui/commit/e8fac8d7e2eef1b2eee8ccb98dd9d69d03619ae3"><code>e8fac8d</code></a> - feat: show a message with uploading attachments in the thread while it is being sent (<a href="https://github.com/okisdev"><code>@okisdev</code></a>)</p> <p><code>MessagePrimitive.Attachments</code> now hands its render function <code>Attachment</code> rather than <code>CompleteAttachment</code>, because the row of a message that is still being sent shows attachments that are still uploading. a render function that reads <code>attachment.content</code> should check <code>attachment.status.type === "complete"</code> first.</p> </li> <li> <p><a href="https://redirect.github.com/assistant-ui/assistant-ui/pull/7877">#7877</a> <a href="https://github.com/assistant-ui/assistant-ui/commit/83f53542e7f91d1b93489e534b40151ca34094a8"><code>83f5354</code></a> - fix: honor registered data-part fallbacks on native MessageContent and grouped parts (<a href="https://github.com/Kinfe123"><code>@Kinfe123</code></a>)</p> </li> <li> <p><a href="https://redirect.github.com/assistant-ui/assistant-ui/pull/7760">#7760</a> <a href="https://github.com/assistant-ui/assistant-ui/commit/84e0cf4c9b7fc92a85d1360b37e2e20b73bed650"><code>84e0cf4</code></a> - fix: emit declarations from one TypeScript program so two builds of the same commit produce the same <code>.d.ts</code> (<a href="https://github.com/okisdev"><code>@okisdev</code></a>)</p> <p><code>aui-build</code> now emits the unbundled <code>.d.ts</code> output in one TypeScript pass over the whole package, so two builds of the same commit produce identical declarations; the per-module emit it replaced followed the bundler's load order and let union member order, alias visibility and import specifiers move between builds. Declarations import barrels as the source does and keep <code>import type</code>; the exported types are unchanged. A <code>/// <reference></code> directive that must reach the published declarations now carries <code>preserve="true"</code> in the source.</p> </li> <li> <p><a href="https://redirect.github.com/assistant-ui/assistant-ui/pull/7838">#7838</a> <a href="https://github.com/assistant-ui/assistant-ui/commit/3d01501c5642b7b0a4f1094a5a0b93976d02eed7"><code>3d01501</code></a> - fix: every distribution re-exports the same shared surface from <code>@assistant-ui/core</code>. <code>@assistant-ui/react-ink</code> gains <code>ReadonlyThreadProvider</code>, <code>ToolCallMessagePartStatus</code>, <code>groupPartByType</code>, <code>GroupByContext</code>, <code>VoiceSessionState</code>, the external store runtime (<code>useExternalStoreRuntime</code>, <code>useExternalMessageConverter</code>, their adapters and options), the message queue, the tool approval types, the generative UI renderer and the cloud thread list hooks; <code>@assistant-ui/react-native</code> gains <code>VoiceSessionState</code>, the cloud thread list hooks, the generative UI renderer and the runtime state and adapter types the web package already carried; <code>@assistant-ui/react</code> gains <code>MessageRole</code>, <code>RunConfig</code>, <code>RuntimeCapabilities</code>, <code>RemoteThreadListOptions</code>, <code>ThreadsState</code>, <code>JoinStrategy</code>, <code>TitleGenerationAdapter</code>, <code>createSimpleTitleAdapter</code> and <code>ChainOfThoughtPartByIndexProvider</code>. (<a href="https://github.com/okisdev"><code>@okisdev</code></a>)</p> </li> <li> <p><a href="https://redirect.github.com/assistant-ui/assistant-ui/pull/7520">#7520</a> <a href="https://github.com/assistant-ui/assistant-ui/commit/2171a8e06b8ca739a98eba927ab8b27175dd7be6"><code>2171a8e</code></a> - fix(react): attach the ExportMarkdown download anchor to the document so Firefox starts the download (<a href="https://github.com/Kinfe123"><code>@Kinfe123</code></a>)</p> </li> <li> <p><a href="https://redirect.github.com/assistant-ui/assistant-ui/pull/8010">#8010</a> <a href="https://github.com/assistant-ui/assistant-ui/commit/1c86c4c9e9cd4f7b2a27efd089d779831e54c2f0"><code>1c86c4c</code></a> - fix: prevent disabled attachment dropzones from navigating to dropped files. (<a href="https://github.com/Kinfe123"><code>@Kinfe123</code></a>)</p> </li> <li> <p><a href="https://redirect.github.com/assistant-ui/assistant-ui/pull/7733">#7733</a> <a href="https://github.com/assistant-ui/assistant-ui/commit/e2f13068534f9ca2d526a4e683846db7d6f2ec3b"><code>e2f1306</code></a> - fix: clear attachment drag state when the dropzone is disabled (<a href="https://github.com/Kinfe123"><code>@Kinfe123</code></a>)</p> </li> <li> <p><a href="https://redirect.github.com/assistant-ui/assistant-ui/pull/7897">#7897</a> <a href="https://github.com/assistant-ui/assistant-ui/commit/16ef5b3e1f982a392c00a9a90b291c02e6c6fc5c"><code>16ef5b3</code></a> - fix(react): stop a pending bottom scroll from hijacking keyboard-driven content growth (<a href="https://github.com/Kinfe123"><code>@Kinfe123</code></a>)</p> </li> <li> <p><a href="https://redirect.github.com/assistant-ui/assistant-ui/pull/7762">#7762</a> <a href="https://github.com/assistant-ui/assistant-ui/commit/49283649b9119d8fe3acbc7bd2703d3473a98e9b"><code>4928364</code></a> - fix: resolve component registries by own keys only, so a component, tool or data part name that only <code>Object.prototype</code> has (<code>toString</code>, <code>constructor</code>, <code>__proto__</code>) takes the <code>Fallback</code> or <code>GenerativeUIRenderError</code> path instead of rendering the inherited built-in (<a href="https://github.com/okisdev"><code>@okisdev</code></a>)</p> </li> <li> <p><a href="https://redirect.github.com/assistant-ui/assistant-ui/pull/7725">#7725</a> <a href="https://github.com/assistant-ui/assistant-ui/commit/258ad136d849f67c06207cd8cfd944364c1e59cf"><code>258ad13</code></a> - fix: expose feedback submission state to assistive technology (<a href="https://github.com/apps/rupic-app"><code>@rupic-app</code></a>)</p> </li> <li> <p><a href="https://redirect.github.com/assistant-ui/assistant-ui/pull/7981">#7981</a> <a href="https://github.com/assistant-ui/assistant-ui/commit/0252c6966322f09eda17172bfcaab8c641529bcf"><code>0252c69</code></a> - feat: name the runtime state types <code>ThreadRuntimeState</code>, <code>MessageRuntimeState</code>, <code>ComposerRuntimeState</code>, <code>AttachmentRuntimeState</code> and <code>ThreadListItemRuntimeState</code> (<a href="https://github.com/okisdev"><code>@okisdev</code></a>)</p> <p>these are the states <code>ThreadRuntime</code>, <code>MessageRuntime</code>, <code>ComposerRuntime</code>, <code>AttachmentRuntime</code> and <code>ThreadListItemRuntime</code> return from <code>getState()</code>, now exported by all three distributions; <code>@assistant-ui/react-native</code> and <code>@assistant-ui/react-ink</code> had no name for them. in <code>@assistant-ui/react</code>, <code>ThreadState</code>, <code>MessageState</code>, <code>ComposerState</code>, <code>AttachmentState</code> and <code>ThreadListItemState</code> still name these runtime states but are deprecated: from 0.16 they name the store states <code>useAuiState</code> reads, as they already do in <code>@assistant-ui/react-native</code> and <code>@assistant-ui/react-ink</code>. code that annotates a runtime's <code>getState()</code> result should move to the new names.</p> </li> <li> <p><a href="https://redirect.github.com/assistant-ui/assistant-ui/pull/8149">#8149</a> <a href="https://github.com/assistant-ui/assistant-ui/commit/1b1ff55c227a8bf58d6413ec8b248162540acc19"><code>1b1ff55</code></a> - fix(react): keep the selection toolbar in sync after a right-click, so a context menu that swallows the mouseup no longer leaves it showing (and quoting) the previous selection (<a href="https://github.com/samdickson22"><code>@samdickson22</code></a>)</p> </li> <li> <p><a href="https://redirect.github.com/assistant-ui/assistant-ui/pull/8065">#8065</a> <a href="https://github.com/assistant-ui/assistant-ui/commit/2caacadf195a30efe04aaff8b46679ad99e70e74"><code>2caacad</code></a> - feat: a tool UI can record what the user did on its tool call with <code>unstable_recordInteraction</code>, kept on the part as <code>unstable_interactions</code> and stored in cloud history; the answer to a human input request is recorded once the runtime accepts it, the local runtime persists records and keeps them out of model input, external stores receive them through <code>unstable_onRecordToolInteraction</code>, and readonly threads ignore them (<a href="https://github.com/okisdev"><code>@okisdev</code></a>)</p> </li> <li> <p><a href="https://redirect.github.com/assistant-ui/assistant-ui/pull/7068">#7068</a> <a href="https://github.com/assistant-ui/assistant-ui/commit/4b069f90fbcb58953ebc7b9c4becca0bf4607842"><code>4b069f9</code></a> - fix: Use successful Standard Schema output for tool execution and model output. Keep the original arguments for validation errors and stored tool calls. (<a href="https://github.com/ephraimduncan"><code>@ephraimduncan</code></a>)</p> </li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/assistant-ui/assistant-ui/commit/f008537f39f0936992b0f6d2433c092935df5faf"><code>f008537</code></a> chore: update versions (<a href="https://github.com/assistant-ui/assistant-ui/tree/HEAD/packages/react/issues/7724">#7724</a>)</li> <li><a href="https://github.com/assistant-ui/assistant-ui/commit/967de5db4ca0c876bff20bffb783167651357cdd"><code>967de5d</code></a> feat(react): CloudRendererHost draws a stored conversation in the dashboard's...</li> <li><a href="https://github.com/assistant-ui/assistant-ui/commit/1b1ff55c227a8bf58d6413ec8b248162540acc19"><code>1b1ff55</code></a> fix(react): keep the selection toolbar quoting what is selected after a right...</li> <li><a href="https://github.com/assistant-ui/assistant-ui/commit/2caacadf195a30efe04aaff8b46679ad99e70e74"><code>2caacad</code></a> feat(core): record the user's interactions with a tool ui on its tool call (#...</li> <li><a href="https://github.com/assistant-ui/assistant-ui/commit/e8fac8d7e2eef1b2eee8ccb98dd9d69d03619ae3"><code>e8fac8d</code></a> feat(core): show a message with uploading attachments while it is sent (<a href="https://github.com/assistant-ui/assistant-ui/tree/HEAD/packages/react/issues/8030">#8030</a>)</li> <li><a href="https://github.com/assistant-ui/assistant-ui/commit/d09680175b062b26c393aa274bf4068012b82a9c"><code>d096801</code></a> fix: type the assistant transport body that prepareSendCommandsRequest receiv...</li> <li><a href="https://github.com/assistant-ui/assistant-ui/commit/1c86c4c9e9cd4f7b2a27efd089d779831e54c2f0"><code>1c86c4c</code></a> fix(react): claim file drops when attachment dropzone is disabled (<a href="https://github.com/assistant-ui/assistant-ui/tree/HEAD/packages/react/issues/8010">#8010</a>)</li> <li><a href="https://github.com/assistant-ui/assistant-ui/commit/0252c6966322f09eda17172bfcaab8c641529bcf"><code>0252c69</code></a> feat: name the runtime state types and deprecate their old names (<a href="https://github.com/assistant-ui/assistant-ui/tree/HEAD/packages/react/issues/7981">#7981</a>)</li> <li><a href="https://github.com/assistant-ui/assistant-ui/commit/15937b8844db7757d3595d5644bc27196e742f4a"><code>15937b8</code></a> test(react): skip the initial viewport scroll in the MessageRoot hover test (...</li> <li><a href="https://github.com/assistant-ui/assistant-ui/commit/16ef5b3e1f982a392c00a9a90b291c02e6c6fc5c"><code>16ef5b3</code></a> fix(react): cancel pending bottom scroll on a keyboard gesture (<a href="https://github.com/assistant-ui/assistant-ui/tree/HEAD/packages/react/issues/7897">#7897</a>)</li> <li>Additional commits viewable in <a href="https://github.com/assistant-ui/assistant-ui/commits/@assistant-ui/react@0.15.22/packages/react">compare view</a></li> </ul> </details> <br /> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>canary/v2026.1002.0-canary.6 |
||
|
|
3934fd14e5 |
build(deps-dev): bump @storybook/addon-docs from 10.5.10 to 10.6.0 (#12972)
Bumps [@storybook/addon-docs](https://github.com/storybookjs/storybook/tree/HEAD/code/addons/docs) from 10.5.10 to 10.6.0. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/storybookjs/storybook/releases">@storybook/addon-docs's releases</a>.</em></p> <blockquote> <h2>v10.6.0</h2> <h2>10.6.0</h2> <blockquote> <p>New skills architecture for agentic workflows</p> </blockquote> <p>Storybook 10.6 contains hundreds of fixes and improvements:</p> <ul> <li>💻 CLI bindings for agent tools/skills</li> <li>🅰️ Angular-Vite MCP/skills support and improved docgen/snippets (experimental)</li> <li>🟢 Vue MCP/skills support and improved docgen/snippets (experimental)</li> <li>🧩 Tanstack / NextJS-Vite framework bugfixes</li> <li>⚡ Improved performance and reduced bundle size</li> </ul> <!-- raw HTML omitted --> <ul> <li>Addon MCP: Stop silently dropping composed refs from MCP composition - <a href="https://redirect.github.com/storybookjs/storybook/pull/36077">#36077</a>, thanks <a href="https://github.com/kasperpeulen"><code>@kasperpeulen</code></a>!</li> <li>Addon Vitest: Pin storybook/test in optimizeDeps so its CJS-only deps are prebundled - <a href="https://redirect.github.com/storybookjs/storybook/pull/35572">#35572</a>, thanks <a href="https://github.com/Nic-Polumeyv"><code>@Nic-Polumeyv</code></a>!</li> <li>Addon Vitest: Report test runs with failures as failed tool outcomes - <a href="https://redirect.github.com/storybookjs/storybook/pull/36080">#36080</a>, thanks <a href="https://github.com/kasperpeulen"><code>@kasperpeulen</code></a>!</li> <li>Addon Vitest: Resolve story test globs against the project root - <a href="https://redirect.github.com/storybookjs/storybook/pull/36103">#36103</a>, thanks <a href="https://github.com/kasperpeulen"><code>@kasperpeulen</code></a>!</li> <li>Addon-vitest: Filter Storybook instrumentation from reported stack traces - <a href="https://redirect.github.com/storybookjs/storybook/pull/36120">#36120</a>, thanks <a href="https://github.com/ghengeveld"><code>@ghengeveld</code></a>!</li> <li>Angular Vite: Resolve tsConfig against the workspace root - <a href="https://redirect.github.com/storybookjs/storybook/pull/36026">#36026</a>, thanks <a href="https://github.com/ndelangen"><code>@ndelangen</code></a>!</li> <li>Angular-Vite: Run Compodoc on demand - <a href="https://redirect.github.com/storybookjs/storybook/pull/35776">#35776</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Add an in-process docgen analyzer, replacing Compodoc under the flag - <a href="https://redirect.github.com/storybookjs/storybook/pull/35805">#35805</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Bind only what the component accepts in story snippets, and report the rest - <a href="https://redirect.github.com/storybookjs/storybook/pull/35943">#35943</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Decide the migration's zone.js import from the dependency tree - <a href="https://redirect.github.com/storybookjs/storybook/pull/36008">#36008</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Declare story args the snippet markup binds by name - <a href="https://redirect.github.com/storybookjs/storybook/pull/35895">#35895</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Declare style preprocessors as optional peers and name the missing one - <a href="https://redirect.github.com/storybookjs/storybook/pull/36098">#36098</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Derive required inputs from Compodoc's own flag - <a href="https://redirect.github.com/storybookjs/storybook/pull/35758">#35758</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Extract Compodoc parsing into its own package - <a href="https://redirect.github.com/storybookjs/storybook/pull/35749">#35749</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Extract component JSDoc through TypeScript's APIs - <a href="https://redirect.github.com/storybookjs/storybook/pull/35977">#35977</a>, thanks <a href="https://github.com/huang-julien"><code>@huang-julien</code></a>!</li> <li>Angular: Extract docgen on the server via Compodoc - <a href="https://redirect.github.com/storybookjs/storybook/pull/35733">#35733</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Fix component resolution, MCP output, and dev/build path aliasing - <a href="https://redirect.github.com/storybookjs/storybook/pull/35952">#35952</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Fix eight upgrade and migration bugs - <a href="https://redirect.github.com/storybookjs/storybook/pull/35946">#35946</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Fix ten docgen bugs found across 22 community repositories - <a href="https://redirect.github.com/storybookjs/storybook/pull/35941">#35941</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Generate story-docs snippets from the analyzer - <a href="https://redirect.github.com/storybookjs/storybook/pull/35807">#35807</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Give agents real input and output documentation - <a href="https://redirect.github.com/storybookjs/storybook/pull/35896">#35896</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Hide class internals from the props table by default - <a href="https://redirect.github.com/storybookjs/storybook/pull/35887">#35887</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Install the `@storybook/angular-vite` peers that nothing else brings in - <a href="https://redirect.github.com/storybookjs/storybook/pull/36002">#36002</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Keep the function control on constructor and generic signatures - <a href="https://redirect.github.com/storybookjs/storybook/pull/35921">#35921</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Make experimentalDocgenServer the default in angular-vite - <a href="https://redirect.github.com/storybookjs/storybook/pull/35886">#35886</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Migrate Analog projects to angular-vite instead of refusing them - <a href="https://redirect.github.com/storybookjs/storybook/pull/35971">#35971</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Print unevaluable story args instead of slicing the file - <a href="https://redirect.github.com/storybookjs/storybook/pull/35888">#35888</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Read the story shapes that supply their own markup - <a href="https://redirect.github.com/storybookjs/storybook/pull/35797">#35797</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Render self-closing tags in server-side docs snippets - <a href="https://redirect.github.com/storybookjs/storybook/pull/35953">#35953</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Render the required badge for required inputs in the props table - <a href="https://redirect.github.com/storybookjs/storybook/pull/36065">#36065</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Resolve `@angular/core` through the package manager, not the raw specifier - <a href="https://redirect.github.com/storybookjs/storybook/pull/35999">#35999</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Resolve builder `styles` the way the Angular builders do - <a href="https://redirect.github.com/storybookjs/storybook/pull/35998">#35998</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Resolve builder styles against the workspace root - <a href="https://redirect.github.com/storybookjs/storybook/pull/35974">#35974</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Skip the runtime source decorator when the docgen server produces snippets - <a href="https://redirect.github.com/storybookjs/storybook/pull/35906">#35906</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/storybookjs/storybook/blob/next/CHANGELOG.md">@storybook/addon-docs's changelog</a>.</em></p> <blockquote> <h2>10.6.0</h2> <blockquote> <p>New skills architecture for agentic workflows</p> </blockquote> <p>Storybook 10.6 contains hundreds of fixes and improvements:</p> <ul> <li>💻 CLI bindings for agent tools/skills</li> <li>🅰️ Angular-Vite MCP/skills support and improved docgen/snippets (experimental)</li> <li>🟢 Vue MCP/skills support and improved docgen/snippets (experimental)</li> <li>🧩 Tanstack / NextJS-Vite framework bugfixes</li> <li>⚡ Improved performance and reduced bundle size</li> </ul> <!-- raw HTML omitted --> <ul> <li>Addon MCP: Stop silently dropping composed refs from MCP composition - <a href="https://redirect.github.com/storybookjs/storybook/pull/36077">#36077</a>, thanks <a href="https://github.com/kasperpeulen"><code>@kasperpeulen</code></a>!</li> <li>Addon Vitest: Pin storybook/test in optimizeDeps so its CJS-only deps are prebundled - <a href="https://redirect.github.com/storybookjs/storybook/pull/35572">#35572</a>, thanks <a href="https://github.com/Nic-Polumeyv"><code>@Nic-Polumeyv</code></a>!</li> <li>Addon Vitest: Report test runs with failures as failed tool outcomes - <a href="https://redirect.github.com/storybookjs/storybook/pull/36080">#36080</a>, thanks <a href="https://github.com/kasperpeulen"><code>@kasperpeulen</code></a>!</li> <li>Addon Vitest: Resolve story test globs against the project root - <a href="https://redirect.github.com/storybookjs/storybook/pull/36103">#36103</a>, thanks <a href="https://github.com/kasperpeulen"><code>@kasperpeulen</code></a>!</li> <li>Addon-vitest: Filter Storybook instrumentation from reported stack traces - <a href="https://redirect.github.com/storybookjs/storybook/pull/36120">#36120</a>, thanks <a href="https://github.com/ghengeveld"><code>@ghengeveld</code></a>!</li> <li>Angular Vite: Resolve tsConfig against the workspace root - <a href="https://redirect.github.com/storybookjs/storybook/pull/36026">#36026</a>, thanks <a href="https://github.com/ndelangen"><code>@ndelangen</code></a>!</li> <li>Angular-Vite: Run Compodoc on demand - <a href="https://redirect.github.com/storybookjs/storybook/pull/35776">#35776</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Add an in-process docgen analyzer, replacing Compodoc under the flag - <a href="https://redirect.github.com/storybookjs/storybook/pull/35805">#35805</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Bind only what the component accepts in story snippets, and report the rest - <a href="https://redirect.github.com/storybookjs/storybook/pull/35943">#35943</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Decide the migration's zone.js import from the dependency tree - <a href="https://redirect.github.com/storybookjs/storybook/pull/36008">#36008</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Declare story args the snippet markup binds by name - <a href="https://redirect.github.com/storybookjs/storybook/pull/35895">#35895</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Declare style preprocessors as optional peers and name the missing one - <a href="https://redirect.github.com/storybookjs/storybook/pull/36098">#36098</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Derive required inputs from Compodoc's own flag - <a href="https://redirect.github.com/storybookjs/storybook/pull/35758">#35758</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Extract Compodoc parsing into its own package - <a href="https://redirect.github.com/storybookjs/storybook/pull/35749">#35749</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Extract component JSDoc through TypeScript's APIs - <a href="https://redirect.github.com/storybookjs/storybook/pull/35977">#35977</a>, thanks <a href="https://github.com/huang-julien"><code>@huang-julien</code></a>!</li> <li>Angular: Extract docgen on the server via Compodoc - <a href="https://redirect.github.com/storybookjs/storybook/pull/35733">#35733</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Fix component resolution, MCP output, and dev/build path aliasing - <a href="https://redirect.github.com/storybookjs/storybook/pull/35952">#35952</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Fix eight upgrade and migration bugs - <a href="https://redirect.github.com/storybookjs/storybook/pull/35946">#35946</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Fix ten docgen bugs found across 22 community repositories - <a href="https://redirect.github.com/storybookjs/storybook/pull/35941">#35941</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Generate story-docs snippets from the analyzer - <a href="https://redirect.github.com/storybookjs/storybook/pull/35807">#35807</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Give agents real input and output documentation - <a href="https://redirect.github.com/storybookjs/storybook/pull/35896">#35896</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Hide class internals from the props table by default - <a href="https://redirect.github.com/storybookjs/storybook/pull/35887">#35887</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Install the <code>@storybook/angular-vite</code> peers that nothing else brings in - <a href="https://redirect.github.com/storybookjs/storybook/pull/36002">#36002</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Keep the function control on constructor and generic signatures - <a href="https://redirect.github.com/storybookjs/storybook/pull/35921">#35921</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Make experimentalDocgenServer the default in angular-vite - <a href="https://redirect.github.com/storybookjs/storybook/pull/35886">#35886</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Migrate Analog projects to angular-vite instead of refusing them - <a href="https://redirect.github.com/storybookjs/storybook/pull/35971">#35971</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Print unevaluable story args instead of slicing the file - <a href="https://redirect.github.com/storybookjs/storybook/pull/35888">#35888</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Read the story shapes that supply their own markup - <a href="https://redirect.github.com/storybookjs/storybook/pull/35797">#35797</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Render self-closing tags in server-side docs snippets - <a href="https://redirect.github.com/storybookjs/storybook/pull/35953">#35953</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Render the required badge for required inputs in the props table - <a href="https://redirect.github.com/storybookjs/storybook/pull/36065">#36065</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Resolve <code>@angular/core</code> through the package manager, not the raw specifier - <a href="https://redirect.github.com/storybookjs/storybook/pull/35999">#35999</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Resolve builder <code>styles</code> the way the Angular builders do - <a href="https://redirect.github.com/storybookjs/storybook/pull/35998">#35998</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Resolve builder styles against the workspace root - <a href="https://redirect.github.com/storybookjs/storybook/pull/35974">#35974</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Skip the runtime source decorator when the docgen server produces snippets - <a href="https://redirect.github.com/storybookjs/storybook/pull/35906">#35906</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Stop marking a defaulted input as required in the props table - <a href="https://redirect.github.com/storybookjs/storybook/pull/35899">#35899</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/storybookjs/storybook/commit/a77777356be2aeaff89d7a2b25254db7b2318392"><code>a777773</code></a> Bump version from "10.6.0-beta.3" to "10.6.0" [skip ci]</li> <li><a href="https://github.com/storybookjs/storybook/commit/f32b3667dad8df220cda0359e170bc49931af68c"><code>f32b366</code></a> Bump version from "10.6.0-beta.2" to "10.6.0-beta.3" [skip ci]</li> <li><a href="https://github.com/storybookjs/storybook/commit/0ad1336cbf0ecdab9f6b540570ae9015ae73ab86"><code>0ad1336</code></a> Bump version from "10.6.0-beta.1" to "10.6.0-beta.2" [skip ci]</li> <li><a href="https://github.com/storybookjs/storybook/commit/16359ee17802628c47915c21408cb578d2707b83"><code>16359ee</code></a> Bump version from "10.6.0-beta.0" to "10.6.0-beta.1" [skip ci]</li> <li><a href="https://github.com/storybookjs/storybook/commit/2e0e2f609d1351ba4384eb52e0728dc9cd8b275b"><code>2e0e2f6</code></a> Bump version from "10.6.0-alpha.9" to "10.6.0-beta.0" [skip ci]</li> <li><a href="https://github.com/storybookjs/storybook/commit/6a6dec2aedff6744a9d9226e1f6515e3d5e8b42a"><code>6a6dec2</code></a> Bump version from "10.6.0-alpha.8" to "10.6.0-alpha.9" [skip ci]</li> <li><a href="https://github.com/storybookjs/storybook/commit/cd2d16395a5ffa39189b96aafb6af67f280079db"><code>cd2d163</code></a> Bump version from "10.6.0-alpha.7" to "10.6.0-alpha.8" [skip ci]</li> <li><a href="https://github.com/storybookjs/storybook/commit/3bf4afdce8aba47cc7960d3a3e09a3fd1ceb2baa"><code>3bf4afd</code></a> Merge branch 'next' into kasper/tools-cli-bootstrap-perf</li> <li><a href="https://github.com/storybookjs/storybook/commit/4ea0b1bc2c1a26ce061f5b44051e8f01273f27fa"><code>4ea0b1b</code></a> refactor(docs): move anchorBlockIdFromId into docs-tools</li> <li><a href="https://github.com/storybookjs/storybook/commit/5c80681f18d273461e1b15cb775a77347079b0b0"><code>5c80681</code></a> Merge pull request <a href="https://github.com/storybookjs/storybook/tree/HEAD/code/addons/docs/issues/35965">#35965</a> from storybookjs/valentin/sb-1804-surface-story-doc...</li> <li>Additional commits viewable in <a href="https://github.com/storybookjs/storybook/commits/v10.6.0/code/addons/docs">compare view</a></li> </ul> </details> <br /> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |
||
|
|
4e52463203 |
fix(daytona): recover output from stalled log streams (#14889)
## Thinking Path > - Paperclip is the open source app people use to manage AI agents for work. > - The Daytona driver streams sandbox command output to the host. > - A log socket can stop delivering bytes without closing or rejecting. > - Missing permission requests and cancellation results can leave a run active and block queued work. > - This pull request switches an idle log stream to saved-output polling for the same command. > - The host can receive the missing output without another command dispatch. ## Linked Issues or Issue Description **What happened?** The driver waits for the SDK log-stream promise before it can start recovery. If that promise never settles, the host can miss new output that is already in the provider's saved logs. A run can remain active after a watch completes. Interrupt can then time out with “Execution is still stopping; termination has not been verified.” **Expected behavior** Recover command observation when the live stream stalls. Forward new permission requests and cancellation results. Require a recorded command exit before reporting completion. Keep quiet commands running under the caller's existing lifetime controls. **Steps to reproduce** 1. Start a session command and leave the callback log promise pending. 2. Put new output in the snapshot API without invoking the stream callback. 3. Keep the command running until the host receives that output, then expose its cancellation output and exit code. 4. Verify that the host receives each byte once and dispatches the command once. **Paperclip version or commit** Base commit `479554120d`. **Agent adapter(s) involved** Daytona session commands, including sandbox ACP agent sessions. Related: #14799 handles closed streams; this change handles sockets that never close. #14485 handles input delivery retries. #13262 adds permission diagnostics. ## What Changed - After 15 seconds with no stdout or stderr, switch directly to the existing status and log-snapshot polling path. - Ignore callbacks and delayed failures from the abandoned stream. Clear its idle timer on every exit path. - Preserve byte-offset deduplication, one command dispatch, and independent timeouts for recovery reads. - Add regressions for an initial stream stall, a stall after UTF-8 output, cancellation output, late callbacks, hung recovery reads, and quiet commands that outlive an operation timeout. - Update the provider documentation and keep hour-long healthy-stream coverage active with periodic output. ## Verification - `pnpm vitest run packages/plugins/sandbox-providers/daytona/src/plugin.test.ts`: 245 passed. - `pnpm exec vitest run --project @paperclipai/plugin-daytona`: 339 passed; 14 gated live tests skipped. - Both new stalled-stream regressions fail on the unchanged base driver because it never starts snapshot recovery. Both pass with this change. - `pnpm -r typecheck`: passed. - `pnpm build`: passed. - `pnpm test:run`: the local run did not pass. It was stopped after confirmed local skill-path and macOS skill-cache failures, once complete PR CI was green. Four chat/email tests could not load connector skill files from an ancestor directory outside the checkout. Three company-skills tests hit macOS `EACCES` during cache publication. One unrelated wakeup test timed out in the full run and passed on a focused rerun (`1 passed`, `27 skipped`). No source or test assertions were changed for these failures. This is not a complete local-suite pass. - Complete PR CI on `11ac4e030b`: 53 successful checks, 2 expected skips, no pending or failed checks. The clean CI run includes the full test suite. - Greptile reviewed `11ac4e030b` at 5/5 with no findings or unresolved threads. The branch has no merge conflicts with `master`. - `git diff --check` and a local scan for secrets and private identifiers passed. ## Risks - Quiet healthy commands also switch to polling. Full snapshots can increase bandwidth as output grows; polling remains limited to one snapshot per second. - The SDK exposes no stream cancellation handle. The old socket remains owned by session teardown, and its callbacks cannot publish after fallback. - This change recovers a stalled output stream. It does not claim to identify every cause of an unanswered permission request or change the requirement to verify termination before releasing work. - No schema migration or command replay. ## Model Used OpenAI GPT-6 through Codex, with tool use and code execution. The exact serving model ID and context window are not exposed in this session. ## Checklist - [x] I have included a thinking path that traces from project context to this change - [x] I have specified the model used (with version and capability details) - [x] I have checked ROADMAP.md and confirmed this PR does not duplicate planned core work - [x] I have searched GitHub for duplicate or related PRs and linked them above - [x] I have either (a) linked existing issues with `Fixes: #` / `Closes: #` / `Refs: #` OR (b) described the issue in-PR following the relevant issue template - [x] I have not referenced internal/instance-local Paperclip issues or links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip` URLs) - [x] My branch name describes the change (e.g. `docs/...`, `fix/...`) and contains no internal Paperclip ticket id or instance-derived details - [x] I have run local change-specific tests; the full suite passes in CI, with local-suite limitations documented above - [x] I have added or updated tests where applicable - [x] I have updated relevant documentation to reflect my changes - [x] I have considered and documented any risks above - [x] All Paperclip CI gates are green - [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups - [x] I will address all Greptile and reviewer comments before requesting merge Co-authored-by: Paperclip <noreply@paperclip.ing>canary/v2026.1002.0-canary.5 |
||
|
|
261c24ccf9 |
docs(release): canonicalize stable notes for v2026.1001.0 (#14890)
## Thinking Path > - Paperclip is the open source app people use to manage AI agents for work > - The release process keeps stable notes under a beta-keyed path during the soak and renames them to the versioned path after the stable ships > - Stable v2026.1001.0 is published. The `canonicalize_stable_notes` job pushed the rename branch but it does not open a pull request > - The published notes also have no Contributors section. The previous stable notes (v2026.916.0) have one > - This pull request moves the notes to `releases/v2026.1001.0.md` and adds the Contributors section > - The benefit is that the repository returns to the canonical release-notes layout and the external contributors get credit ## Linked Issues or Issue Description **Issue type** Missing content **Where is the issue?** `releases/` — the stable notes for v2026.1001.0 still live at the beta-keyed path `releases/beta/v2026.921.0-beta.1.md`, and they have no Contributors section. **What's wrong?** The `canonicalize_stable_notes` job in the stable release run pushed branch `release-notes/v2026.1001.0-canonicalize` with the rename, but it does not open a pull request. The notes also do not credit the three external contributors in the release range. **Suggested fix** Merge the workflow's rename commit, plus one commit that appends a `## Contributors` section in the same format as `releases/v2026.916.0.md`. ## What Changed - Renamed `releases/beta/v2026.921.0-beta.1.md` to `releases/v2026.1001.0.md` (workflow commit, no content changes) - Appended a `## Contributors` section: 77 commits from 8 contributors, with credits to @austinpilz, @hawikk, and @mouse-value-add - No other content changed. The notes above the new section match the published GitHub Release body for v2026.1001.0 ## Verification - `git log --follow releases/v2026.1001.0.md` shows the rename commit followed by one commit that only appends the Contributors section - `git rev-list --count v2026.916.1..v2026.1001.0` returns 77 - The author list of that range, minus maintainers and bots, is @austinpilz, @hawikk, and @mouse-value-add - The GitHub Release body for v2026.1001.0 is identical to this file without the Contributors section ## Risks - Low risk: a documentation-only rename plus one appended section. ## Model Used - Claude (Anthropic), model ID `claude-fable-5-1` (Claude Fable 5.1), extended thinking enabled, tool use via Claude Code ## Checklist - [x] I have included a thinking path that traces from project context to this change - [x] I have specified the model used (with version and capability details) - [x] I have checked ROADMAP.md and confirmed this PR does not duplicate planned core work - [x] I have searched GitHub for duplicate or related PRs and linked them above - [x] I have either (a) linked existing issues with `Fixes: #` / `Closes #` / `Refs #` OR (b) described the issue in-PR following the relevant issue template - [x] I have not referenced internal/instance-local Paperclip issues or links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip` URLs) - [x] My branch name describes the change (e.g. `docs/...`, `fix/...`) and contains no internal Paperclip ticket id or instance-derived details - [x] I have run tests locally and they pass - [x] I have added or updated tests where applicable - [x] I have updated relevant documentation to reflect my changes - [x] I have considered and documented any risks above - [ ] All Paperclip CI gates are green - [ ] Greptile is 5/5 with no open P2s, recommendations, or follow-ups - [x] I will address all Greptile and reviewer comments before requesting merge --------- Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>canary/v2026.1002.0-canary.4 |
||
|
|
479554120d |
build(deps): bump i18next from 26.4.0 to 26.4.2 (#12973)
Bumps [i18next](https://github.com/i18next/i18next) from 26.4.0 to 26.4.2. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/i18next/i18next/releases">i18next's releases</a>.</em></p> <blockquote> <h2>v26.4.2</h2> <ul> <li>fix: <code>$&</code>, <code>$`</code>, <code>$'</code> and <code>$$</code> inside a nested value (<code>$t(key)</code>) now stay literal. <code>nest()</code> handed the resolved value straight to <code>String.replace</code> as the replacement argument, so those sequences were read as replacement patterns: <code>$&</code> re-inserted the <code>$t(...)</code> match, <code>$`</code> / <code>$'</code> inserted the text before / after it, and <code>$$</code> collapsed to <code>$</code>. Through <code>t()</code> the <code>$&</code> case was worse than a wrong string: the nested lookup resets the shared nesting regexp, so the re-inserted <code>$t(...)</code> was matched again on every pass and <code>t()</code> never returned — also under the default <code>escapeValue: true</code> when the value arrives via a variable forwarded through nesting options (<code>$t(key, { "name": "{{name}}" })</code> with a name containing <code>$&</code>). The value is now <code>$</code>-escaped at the <code>String.replace</code> call, the same guard <code>interpolate()</code> already has, and a non-string value returned by a formatter in the nesting chain (<code>$t(key, myFormat)</code>) is stringified before that. Nested values are still not HTML-escaped (<a href="https://redirect.github.com/i18next/i18next/issues/854">#854</a>). Thanks <a href="https://github.com/mahirhir"><code>@mahirhir</code></a> (<a href="https://redirect.github.com/i18next/i18next/pull/2447">#2447</a>).</li> </ul> <h2>v26.4.1</h2> <ul> <li>fix(types): the selector-form <code>keyPrefix</code> overload of <code>getFixedT()</code> is now available under <code>enableSelector: 'strict'</code>. Its constraint was gated on <code>true | 'optimize'</code> only, so under <code>'strict'</code> it collapsed to <code>never</code>, the overload dropped out, and the returned <code>t</code> silently lost its <code>keyPrefix</code> scope (<code>t(($) => $.deep)</code> failed with <code>Property 'deep' does not exist on type '{}'</code>). The same call already typechecked under <code>true</code> and <code>'optimize'</code>. Thanks <a href="https://github.com/hovelopin"><code>@hovelopin</code></a> (<a href="https://redirect.github.com/i18next/i18next/pull/2446">#2446</a>).</li> </ul> </blockquote> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/i18next/i18next/blob/master/CHANGELOG.md">i18next's changelog</a>.</em></p> <blockquote> <h2>26.4.2</h2> <ul> <li>fix: <code>$&</code>, <code>$`</code>, <code>$'</code> and <code>$$</code> inside a nested value (<code>$t(key)</code>) now stay literal. <code>nest()</code> handed the resolved value straight to <code>String.replace</code> as the replacement argument, so those sequences were read as replacement patterns: <code>$&</code> re-inserted the <code>$t(...)</code> match, <code>$`</code> / <code>$'</code> inserted the text before / after it, and <code>$$</code> collapsed to <code>$</code>. Through <code>t()</code> the <code>$&</code> case was worse than a wrong string: the nested lookup resets the shared nesting regexp, so the re-inserted <code>$t(...)</code> was matched again on every pass and <code>t()</code> never returned — also under the default <code>escapeValue: true</code> when the value arrives via a variable forwarded through nesting options (<code>$t(key, { "name": "{{name}}" })</code> with a name containing <code>$&</code>). The value is now <code>$</code>-escaped at the <code>String.replace</code> call, the same guard <code>interpolate()</code> already has, and a non-string value returned by a formatter in the nesting chain (<code>$t(key, myFormat)</code>) is stringified before that. Nested values are still not HTML-escaped (<a href="https://redirect.github.com/i18next/i18next/issues/854">#854</a>). Thanks <a href="https://github.com/mahirhir"><code>@mahirhir</code></a> (<a href="https://redirect.github.com/i18next/i18next/pull/2447">#2447</a>).</li> </ul> <h2>26.4.1</h2> <ul> <li>fix(types): the selector-form <code>keyPrefix</code> overload of <code>getFixedT()</code> is now available under <code>enableSelector: 'strict'</code>. Its constraint was gated on <code>true | 'optimize'</code> only, so under <code>'strict'</code> it collapsed to <code>never</code>, the overload dropped out, and the returned <code>t</code> silently lost its <code>keyPrefix</code> scope (<code>t(($) => $.deep)</code> failed with <code>Property 'deep' does not exist on type '{}'</code>). The same call already typechecked under <code>true</code> and <code>'optimize'</code>. Thanks <a href="https://github.com/hovelopin"><code>@hovelopin</code></a> (<a href="https://redirect.github.com/i18next/i18next/pull/2446">#2446</a>).</li> </ul> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/i18next/i18next/commit/4dba50f20669c3678db0812255716eb7693ad2da"><code>4dba50f</code></a> 26.4.2</li> <li><a href="https://github.com/i18next/i18next/commit/e436b625a648e1a48ea27ecf5f2fba8020d67009"><code>e436b62</code></a> build</li> <li><a href="https://github.com/i18next/i18next/commit/d955fb086e9f4ded1200f51ecbb21034dbad1d92"><code>d955fb0</code></a> fix: stringify formatter results in nested values, changelog v26.4.2</li> <li><a href="https://github.com/i18next/i18next/commit/dfafa3ca725e1415ef20e7fb5b1b3e4468f3c425"><code>dfafa3c</code></a> fix: keep replacement patterns literal in nested values (<a href="https://redirect.github.com/i18next/i18next/issues/2447">#2447</a>)</li> <li><a href="https://github.com/i18next/i18next/commit/3c9981e22dd471b6bca224aa1f60e04ba3f6153a"><code>3c9981e</code></a> chore: keep dev-only and local files out of the npm package</li> <li><a href="https://github.com/i18next/i18next/commit/c057ee048c55a61c095acc017365e997e4f723f8"><code>c057ee0</code></a> 26.4.1</li> <li><a href="https://github.com/i18next/i18next/commit/02e3e1659b7cc9fedaaf53797597483ef8003df2"><code>02e3e16</code></a> changelog v26.4.1</li> <li><a href="https://github.com/i18next/i18next/commit/6f198f2508ba8986d1bbf25a8b922d01afcf0751"><code>6f198f2</code></a> fix(types): allow selector keyPrefix in getFixedT under enableSelector 'stric...</li> <li>See full diff in <a href="https://github.com/i18next/i18next/compare/v26.4.0...v26.4.2">compare view</a></li> </ul> </details> <br /> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>canary/v2026.1002.0-canary.3 |
||
|
|
b31ce54b81 |
build(deps): bump react-router-dom from 7.18.2 to 7.18.4 (#12974)
Bumps [react-router-dom](https://github.com/remix-run/react-router/tree/HEAD/packages/react-router-dom) from 7.18.2 to 7.18.4. <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/remix-run/react-router/blob/react-router-dom@7.18.4/packages/react-router-dom/CHANGELOG.md">react-router-dom's changelog</a>.</em></p> <blockquote> <h2>v7.18.4</h2> <h3>Patch Changes</h3> <ul> <li>Updated dependencies: <ul> <li><a href="https://github.com/remix-run/react-router/releases/tag/react-router@7.18.4"><code>react-router@7.18.4</code></a></li> </ul> </li> </ul> <h2>v7.18.3</h2> <h3>Patch Changes</h3> <ul> <li>Updated dependencies: <ul> <li><a href="https://github.com/remix-run/react-router/releases/tag/react-router@7.18.3"><code>react-router@7.18.3</code></a></li> </ul> </li> </ul> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/remix-run/react-router/commit/1b1e0b0e79b21692ce907933475233babdd16e3e"><code>1b1e0b0</code></a> Release v7.18.4 (<a href="https://github.com/remix-run/react-router/tree/HEAD/packages/react-router-dom/issues/15498">#15498</a>)</li> <li><a href="https://github.com/remix-run/react-router/commit/23166dfe7f61323f0d2775af67d2691f9ed0843d"><code>23166df</code></a> Release v7.18.3 (<a href="https://github.com/remix-run/react-router/tree/HEAD/packages/react-router-dom/issues/15424">#15424</a>)</li> <li>See full diff in <a href="https://github.com/remix-run/react-router/commits/react-router-dom@7.18.4/packages/react-router-dom">compare view</a></li> </ul> </details> <br /> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |
||
|
|
4a999089ef |
Retry transient failures in dashboard reads (#14873)
## Thinking Path > - Paperclip shows company activity in the dashboard. > - The dashboard reads company, task, approval, and cost data. > - A pooled database connection can close during one of these reads. > - The driver must reject ambiguous statements because writes may have committed. > - These four dashboard queries are known to be read-only. > - This change retries only the failed read and preserves completed work. ## Linked Issues or Issue Description Refs #14773, which correctly removed automatic replay of ambiguous database statements. Searched existing database and dashboard PRs. Related #8780 changes pool recycling and logging; #13925 adds dashboard consistency coverage. Neither provides these per-query retries. **What happened?** A dashboard request returns a server error when its company lookup, task count, approval count, or monthly spend query loses its database connection. Drizzle wraps the driver's connection error in `cause`. **Expected behavior** A transient connection failure gets a bounded retry of the specific read. Completed reads and budget processing are not replayed. Persistent outages and non-connection errors still fail the request. **Steps to reproduce** Inject a typed `CONNECTION_CLOSED` error into one of these reads. Then allow the next query to succeed. Before this change, the dashboard request fails immediately. ## What Changed - Apply independent retries to the company lookup, task counts, pending approval count, and monthly spend query. Each callback rebuilds its own query with the same company scope. - Extract the existing authentication retry helper as `retryIdempotentDatabaseOperation`. Preserve authentication behavior and its existing exports. - Retain the existing limit of three total attempts with 50 ms and 100 ms pauses. Match typed connection codes through the error cause chain. - Test later-read failures, unchanged query parameters, retry exhaustion, missing companies, and errors that must not retry. Document the boundary. ## Verification - Final focused dashboard, authentication, and real database wire suites: 38 tests passed. Six initial recovery regressions failed before the implementation. - `pnpm -r typecheck`: passed on the final source. - Independent review: no actionable findings. The reviewer separately passed all 38 focused tests and checked the code allowlist, attempt bounds, pauses, and final error identity. - `pnpm test:run`: the general-server group completed with 14,738 tests passed, 13 failed, and 87 skipped. All 13 failures match the previously reproduced clean-base macOS skill-cache failures. The two test files and their implementations are unchanged from that baseline. The runner exited after this group, so the remaining local workspace and serialized groups did not run. All corresponding Linux CI groups passed on this commit. - `pnpm build`: passed on the final source. - Full CI: 53 successful checks and 2 skips on `6a113529c0`. Greptile: 5/5 on that commit, with no review threads or remaining findings. - Merge compatibility with master `f2e0f19630`, including #14866: no conflicts. The five reviewed files are unchanged in the resulting merge tree. ## Risks A persistent outage adds at most two retries per covered query. Each connection attempt retains the configured driver timeout. The change does not repair the underlying network or database failure. Agent counts, run-activity queries, and the budget workflow stay outside these retry boundaries. General database statements and disconnected transactions are not replayed. There is no schema or authorization change. ## Model Used OpenAI GPT-6 through Codex, with reasoning, repository inspection, code editing, and test execution. The runtime does not expose a more specific serving model identifier or context-window size. ## Checklist - [x] I have included a thinking path that traces from project context to this change - [x] I have specified the model used (with version and capability details) - [x] I have checked ROADMAP.md and confirmed this PR does not duplicate planned core work - [x] I have searched GitHub for duplicate or related PRs and linked them above - [x] I have either (a) linked existing issues with `Fixes: #` / `Closes #` / `Refs #` OR (b) described the issue in-PR following the relevant issue template - [x] I have not referenced internal/instance-local Paperclip issues or links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip` URLs) - [x] My branch name describes the change and contains no internal Paperclip ticket id or instance-derived details - [x] I have run tests locally and they pass (38 focused tests; the full local run has the baseline limitation documented above) - [x] I have added or updated tests where applicable - [x] I have updated relevant documentation to reflect my changes - [x] I have considered and documented any risks above - [x] All Paperclip CI gates are green - [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups - [x] I will address all Greptile and reviewer comments before requesting merge Co-authored-by: Paperclip <noreply@paperclip.ing> |
||
|
|
40c8468e98 |
build(deps-dev): bump agentmail from 0.5.20 to 0.5.31 (#12975)
Bumps [agentmail](https://github.com/agentmail-to/agentmail-node) from 0.5.20 to 0.5.31. <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/agentmail-to/agentmail-node/commit/be477c3e9d07de608d94daa3f2235c46456758ad"><code>be477c3</code></a> Release 0.5.31</li> <li><a href="https://github.com/agentmail-to/agentmail-node/commit/553d6a62e10a95c73a87d47b8b1125f716dfb1f2"><code>553d6a6</code></a> Release 0.5.30</li> <li><a href="https://github.com/agentmail-to/agentmail-node/commit/a53948be57e396a8d08344e9d43ee191ae747fd9"><code>a53948b</code></a> Release 0.5.29</li> <li><a href="https://github.com/agentmail-to/agentmail-node/commit/f2b4bb9a452a7343dc0eb6f20a07882d7364b211"><code>f2b4bb9</code></a> Release 0.5.28</li> <li><a href="https://github.com/agentmail-to/agentmail-node/commit/d2c56f73735ed917961e1a16273a9320de6c21cd"><code>d2c56f7</code></a> Release 0.5.27</li> <li><a href="https://github.com/agentmail-to/agentmail-node/commit/df2a12427b4e988024787167e6732bd1d1c5b9ff"><code>df2a124</code></a> Release 0.5.26</li> <li><a href="https://github.com/agentmail-to/agentmail-node/commit/4ae0b9b2eeda5c65beb9fa4a3601a1a44f10947d"><code>4ae0b9b</code></a> Release 0.5.25</li> <li><a href="https://github.com/agentmail-to/agentmail-node/commit/dc085581668947a177f5a087c4f78cf1b75dd2e8"><code>dc08558</code></a> Release 0.5.24</li> <li><a href="https://github.com/agentmail-to/agentmail-node/commit/47210d91803f65b2ebf9ec8d1ae546a050e3d8bc"><code>47210d9</code></a> Release 0.5.23</li> <li><a href="https://github.com/agentmail-to/agentmail-node/commit/0c5f98ff97a492ab77e9c688d3374548d9dd997a"><code>0c5f98f</code></a> Release 0.5.22</li> <li>Additional commits viewable in <a href="https://github.com/agentmail-to/agentmail-node/compare/0.5.20...0.5.31">compare view</a></li> </ul> </details> <br /> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>canary/v2026.1002.0-canary.2 |
||
|
|
427e048405 |
fix(company-skills): approve managed-checkout project dirs for local skill import (#10329)
## Thinking Path
> - Paperclip is the open source app people use to manage AI agents for
work
> - Company skills can be imported into a company from a local folder;
`companySkillService.importFromSource` guards this with
`assertLocalImportSourceAllowed`, which only permits import sources
inside an approved set of roots (managed skills root + registered
project-workspace cwds), realpath-resolved and `${root}${sep}`-anchored
to prevent path traversal/escape
> - A project can exist as a `managed_checkout` (server-managed clone)
with **no registered `project_workspaces` row** — its `primaryWorkspace`
is `null` and `workspaces` is `[]`, so its only real on-disk location is
the server-derived `codebase.managedFolder`
> - Because `configuredRoots` was built solely from the managed skills
root and `workspaces[].cwd`, a `managed_checkout` project's
`managedFolder` was never an approved root, so importing a skill from
that project's own folder was rejected with
`skill_workspace_boundary_denied`
> - This PR adds each project's server-derived `codebase.managedFolder`
to `configuredRoots` so in-place skill imports from managed-checkout
projects are allowed
> - The benefit is that managed-checkout projects can re-import their
own skills in place, without weakening the traversal/escape protections
(the new roots are server-derived and matched exactly like the existing
ones)
## Linked Issues or Issue Description
No public GitHub issue. Describing in-PR (bug):
**What's wrong:** `assertLocalImportSourceAllowed` denies a legitimate
local skill import (`skill_workspace_boundary_denied`) for any project
that is a `managed_checkout` with no registered workspace row.
**Repro:** Create/import a company skill from a `managed_checkout`
project's own folder (`codebase.managedFolder/.agents/skills/<skill>`).
The import is rejected even though the source is inside the project's
server-managed checkout.
**Expected:** The import from a managed-checkout project's own
`managedFolder` subtree should be allowed, while paths outside that
subtree remain denied.
Related context (already merged): #9564 introduced the open-by-default
skill policy / this import boundary. This PR does not change that
boundary's matching logic — it only adds a missing, server-derived
approved root.
## What Changed
- `server/src/services/company-skills.ts`: add
`...projectRows.map((project) => project.codebase.managedFolder)` to
`configuredRoots` in `assertLocalImportSourceAllowed`. `managedFolder`
is server-derived (`resolveManagedProjectWorkspaceDir(companyId,
projectId)` → instance root + sanitized ids); it is
`fs.realpath`-resolved and `${root}${sep}`-prefix matched exactly like
every existing root. `managedFolder` is used rather than
`effectiveLocalFolder` because the latter can fall through to a
user-registered `localFolder`, which is already covered by the
registered workspace cwds.
- `server/src/__tests__/company-skill-import-boundary.test.ts`: add a
regression test — a managed-checkout project's `managedFolder/<skill>`
import is **allowed**, and a **prefix-adjacent sibling** (`managedFolder
+ "-evil"`) stays **denied**.
## Verification
- `cd server && ./node_modules/.bin/vitest run
src/__tests__/company-skill-import-boundary.test.ts` → **2/2 pass**
(embedded-Postgres suite). Covers both the new allow case and the
prefix-adjacent deny case, alongside the existing out-of-tree /
symlink-escape / non-file-scheme rejections.
## Risks
Low risk. The change only **adds** approved roots; it does not alter the
realpath + `${root}${sep}`-anchored matching that closes
traversal/prefix-adjacency escapes. The added roots are fully
server-derived from the instance root + sanitized company/project ids
(same trust class as the existing `resolveManagedSkillsRoot`) — no value
derived from the import `source` argument reaches them. Sanitization
(`[^a-zA-Z0-9._-]+ → -`) prevents separator/level injection, and the
only user-influenced segment (repo name) is normalized via `new
URL(...)`. The regression test's prefix-adjacent (`-evil`) case asserts
the escape class stays closed.
## Model Used
Claude Opus 4.8 (`claude-opus-4-8`), extended thinking + tool use (code
execution, git). Implementation and security review were produced with
Claude; this integration/PR was prepared with `claude-opus-4-8`.
## Checklist
- [x] I have included a thinking path that traces from project context
to this change
- [x] I have specified the model used (with version and capability
details)
- [x] I have checked ROADMAP.md and confirmed this PR does not duplicate
planned core work
- [x] I have searched GitHub for duplicate or related PRs and linked
them above
- [x] I have either (a) linked existing issues with `Fixes: #` / `Closes
#` / `Refs #` OR (b) described the issue in-PR following the relevant
issue template
- [x] I have not referenced internal/instance-local Paperclip issues or
links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip`
URLs)
- [x] My branch name describes the change (e.g. `docs/...`, `fix/...`)
and contains no internal Paperclip ticket id or instance-derived details
- [x] I have run tests locally and they pass
- [x] I have added or updated tests where applicable
- [ ] I have updated relevant documentation to reflect my changes (N/A —
internal boundary fix, no user-facing docs)
- [x] I have considered and documented any risks above
- [ ] All Paperclip CI gates are green (CI in progress)
- [ ] Greptile is 5/5 with no open P2s, recommendations, or follow-ups
(pending review)
- [x] I will address all Greptile and reviewer comments before
requesting merge
Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
Co-authored-by: brandonburr <brandonburr@gmail.com>
canary/v2026.1002.0-canary.1
|
||
|
|
5207c78f21 |
docs(release): align 2026.921.0-beta.1 stable notes header with v2026.1001.0 (#14882)
## Thinking Path > - Paperclip is the open source app people use to manage AI agents for work > - Releases are published by `release.yml`. A stable release promotes a soaked beta, and the stable notes live on master in `releases/beta/v<beta>.md` until the promotion runs. > - The curated notes for `2026.921.0-beta.1` have the title `Paperclip v2026.924.0` and the date `2026-09-24`. That stable did not ship. No `v2026.924.0` tag or release exists. > - The next promotion of this beta uses `stable_date=2026-10-01`. `scripts/release.sh stable --print-version --date 2026-10-01` resolves to `2026.1001.0`. > - `publish_stable` reads this file verbatim and uses it as the GitHub Release body. `canonicalize_stable_notes` copies it to `releases/v2026.1001.0.md`. Nothing rewrites the header. > - This pull request updates the title, the release date, and the intro sentence to `v2026.1001.0` and `2026-10-01`. > - The benefit is a GitHub Release page and a canonical notes file that show the correct version and date. ## Linked Issues or Issue Description **Describe the documentation problem** The stable notes file `releases/beta/v2026.921.0-beta.1.md` names a stable version and release date that do not match the version the release workflow will publish. **Where is the problem** `releases/beta/v2026.921.0-beta.1.md`, lines 1, 3, and 5. **Proposed fix** Change `v2026.924.0` to `v2026.1001.0` and `2026-09-24` to `2026-10-01` in the three places that name the version or date. Change nothing else in the file. ## What Changed - Title: `# Paperclip v2026.924.0` → `# Paperclip v2026.1001.0` - Release date: `> Released: 2026-09-24` → `> Released: 2026-10-01` - Intro sentence: `Paperclip v2026.924.0 carries 77 commits` → `Paperclip v2026.1001.0 carries 77 commits` ## Verification - `git diff master --stat` shows one file with 3 insertions and 3 deletions. - `grep -n '924' releases/beta/v2026.921.0-beta.1.md` returns no lines. - `git show master:scripts/release.sh > /tmp/r.sh && bash /tmp/r.sh stable --print-version --date 2026-10-01` prints `2026.1001.0`. - The rest of the file is byte-identical to master. ## Risks - Low risk. This is a documentation-only change to a release notes file. No code or workflow changes. - If the stable promotion is dispatched with a different `stable_date`, the header must be updated again to match. ## Model Used - Claude Fable 5.1 (model ID `claude-fable-5-1`), run as a Paperclip agent through the Claude Agent SDK, with tool use (shell, git, GitHub CLI). No extended thinking mode was configured beyond the default. ## Checklist - [x] I have included a thinking path that traces from project context to this change - [x] I have specified the model used (with version and capability details) - [x] I have checked ROADMAP.md and confirmed this PR does not duplicate planned core work - [x] I have searched GitHub for duplicate or related PRs and linked them above - [x] I have either (a) linked existing issues with `Fixes: #` / `Closes #` / `Refs #` OR (b) described the issue in-PR following the relevant issue template - [x] I have not referenced internal/instance-local Paperclip issues or links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip` URLs) - [x] My branch name describes the change (e.g. `docs/...`, `fix/...`) and contains no internal Paperclip ticket id or instance-derived details - [x] I have run tests locally and they pass - [ ] I have added or updated tests where applicable (not applicable: documentation-only change) - [x] I have updated relevant documentation to reflect my changes - [x] I have considered and documented any risks above - [ ] All Paperclip CI gates are green - [ ] Greptile is 5/5 with no open P2s, recommendations, or follow-ups - [x] I will address all Greptile and reviewer comments before requesting merge 🤖 Generated with [Claude Code](https://claude.com/claude-code) Co-authored-by: Bender (Fable) <noreply@paperclip.ing> Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com>canary/v2026.1002.0-canary.0 |
||
|
|
f07f8d9599 |
build(deps-dev): bump @storybook/addon-a11y from 10.5.10 to 10.6.0 (#12976)
Bumps [@storybook/addon-a11y](https://github.com/storybookjs/storybook/tree/HEAD/code/addons/a11y) from 10.5.10 to 10.6.0. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/storybookjs/storybook/releases">@storybook/addon-a11y's releases</a>.</em></p> <blockquote> <h2>v10.6.0</h2> <h2>10.6.0</h2> <blockquote> <p>New skills architecture for agentic workflows</p> </blockquote> <p>Storybook 10.6 contains hundreds of fixes and improvements:</p> <ul> <li>💻 CLI bindings for agent tools/skills</li> <li>🅰️ Angular-Vite MCP/skills support and improved docgen/snippets (experimental)</li> <li>🟢 Vue MCP/skills support and improved docgen/snippets (experimental)</li> <li>🧩 Tanstack / NextJS-Vite framework bugfixes</li> <li>⚡ Improved performance and reduced bundle size</li> </ul> <!-- raw HTML omitted --> <ul> <li>Addon MCP: Stop silently dropping composed refs from MCP composition - <a href="https://redirect.github.com/storybookjs/storybook/pull/36077">#36077</a>, thanks <a href="https://github.com/kasperpeulen"><code>@kasperpeulen</code></a>!</li> <li>Addon Vitest: Pin storybook/test in optimizeDeps so its CJS-only deps are prebundled - <a href="https://redirect.github.com/storybookjs/storybook/pull/35572">#35572</a>, thanks <a href="https://github.com/Nic-Polumeyv"><code>@Nic-Polumeyv</code></a>!</li> <li>Addon Vitest: Report test runs with failures as failed tool outcomes - <a href="https://redirect.github.com/storybookjs/storybook/pull/36080">#36080</a>, thanks <a href="https://github.com/kasperpeulen"><code>@kasperpeulen</code></a>!</li> <li>Addon Vitest: Resolve story test globs against the project root - <a href="https://redirect.github.com/storybookjs/storybook/pull/36103">#36103</a>, thanks <a href="https://github.com/kasperpeulen"><code>@kasperpeulen</code></a>!</li> <li>Addon-vitest: Filter Storybook instrumentation from reported stack traces - <a href="https://redirect.github.com/storybookjs/storybook/pull/36120">#36120</a>, thanks <a href="https://github.com/ghengeveld"><code>@ghengeveld</code></a>!</li> <li>Angular Vite: Resolve tsConfig against the workspace root - <a href="https://redirect.github.com/storybookjs/storybook/pull/36026">#36026</a>, thanks <a href="https://github.com/ndelangen"><code>@ndelangen</code></a>!</li> <li>Angular-Vite: Run Compodoc on demand - <a href="https://redirect.github.com/storybookjs/storybook/pull/35776">#35776</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Add an in-process docgen analyzer, replacing Compodoc under the flag - <a href="https://redirect.github.com/storybookjs/storybook/pull/35805">#35805</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Bind only what the component accepts in story snippets, and report the rest - <a href="https://redirect.github.com/storybookjs/storybook/pull/35943">#35943</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Decide the migration's zone.js import from the dependency tree - <a href="https://redirect.github.com/storybookjs/storybook/pull/36008">#36008</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Declare story args the snippet markup binds by name - <a href="https://redirect.github.com/storybookjs/storybook/pull/35895">#35895</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Declare style preprocessors as optional peers and name the missing one - <a href="https://redirect.github.com/storybookjs/storybook/pull/36098">#36098</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Derive required inputs from Compodoc's own flag - <a href="https://redirect.github.com/storybookjs/storybook/pull/35758">#35758</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Extract Compodoc parsing into its own package - <a href="https://redirect.github.com/storybookjs/storybook/pull/35749">#35749</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Extract component JSDoc through TypeScript's APIs - <a href="https://redirect.github.com/storybookjs/storybook/pull/35977">#35977</a>, thanks <a href="https://github.com/huang-julien"><code>@huang-julien</code></a>!</li> <li>Angular: Extract docgen on the server via Compodoc - <a href="https://redirect.github.com/storybookjs/storybook/pull/35733">#35733</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Fix component resolution, MCP output, and dev/build path aliasing - <a href="https://redirect.github.com/storybookjs/storybook/pull/35952">#35952</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Fix eight upgrade and migration bugs - <a href="https://redirect.github.com/storybookjs/storybook/pull/35946">#35946</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Fix ten docgen bugs found across 22 community repositories - <a href="https://redirect.github.com/storybookjs/storybook/pull/35941">#35941</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Generate story-docs snippets from the analyzer - <a href="https://redirect.github.com/storybookjs/storybook/pull/35807">#35807</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Give agents real input and output documentation - <a href="https://redirect.github.com/storybookjs/storybook/pull/35896">#35896</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Hide class internals from the props table by default - <a href="https://redirect.github.com/storybookjs/storybook/pull/35887">#35887</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Install the `@storybook/angular-vite` peers that nothing else brings in - <a href="https://redirect.github.com/storybookjs/storybook/pull/36002">#36002</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Keep the function control on constructor and generic signatures - <a href="https://redirect.github.com/storybookjs/storybook/pull/35921">#35921</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Make experimentalDocgenServer the default in angular-vite - <a href="https://redirect.github.com/storybookjs/storybook/pull/35886">#35886</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Migrate Analog projects to angular-vite instead of refusing them - <a href="https://redirect.github.com/storybookjs/storybook/pull/35971">#35971</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Print unevaluable story args instead of slicing the file - <a href="https://redirect.github.com/storybookjs/storybook/pull/35888">#35888</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Read the story shapes that supply their own markup - <a href="https://redirect.github.com/storybookjs/storybook/pull/35797">#35797</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Render self-closing tags in server-side docs snippets - <a href="https://redirect.github.com/storybookjs/storybook/pull/35953">#35953</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Render the required badge for required inputs in the props table - <a href="https://redirect.github.com/storybookjs/storybook/pull/36065">#36065</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Resolve `@angular/core` through the package manager, not the raw specifier - <a href="https://redirect.github.com/storybookjs/storybook/pull/35999">#35999</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Resolve builder `styles` the way the Angular builders do - <a href="https://redirect.github.com/storybookjs/storybook/pull/35998">#35998</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Resolve builder styles against the workspace root - <a href="https://redirect.github.com/storybookjs/storybook/pull/35974">#35974</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Skip the runtime source decorator when the docgen server produces snippets - <a href="https://redirect.github.com/storybookjs/storybook/pull/35906">#35906</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/storybookjs/storybook/blob/next/CHANGELOG.md">@storybook/addon-a11y's changelog</a>.</em></p> <blockquote> <h2>10.6.0</h2> <blockquote> <p>New skills architecture for agentic workflows</p> </blockquote> <p>Storybook 10.6 contains hundreds of fixes and improvements:</p> <ul> <li>💻 CLI bindings for agent tools/skills</li> <li>🅰️ Angular-Vite MCP/skills support and improved docgen/snippets (experimental)</li> <li>🟢 Vue MCP/skills support and improved docgen/snippets (experimental)</li> <li>🧩 Tanstack / NextJS-Vite framework bugfixes</li> <li>⚡ Improved performance and reduced bundle size</li> </ul> <!-- raw HTML omitted --> <ul> <li>Addon MCP: Stop silently dropping composed refs from MCP composition - <a href="https://redirect.github.com/storybookjs/storybook/pull/36077">#36077</a>, thanks <a href="https://github.com/kasperpeulen"><code>@kasperpeulen</code></a>!</li> <li>Addon Vitest: Pin storybook/test in optimizeDeps so its CJS-only deps are prebundled - <a href="https://redirect.github.com/storybookjs/storybook/pull/35572">#35572</a>, thanks <a href="https://github.com/Nic-Polumeyv"><code>@Nic-Polumeyv</code></a>!</li> <li>Addon Vitest: Report test runs with failures as failed tool outcomes - <a href="https://redirect.github.com/storybookjs/storybook/pull/36080">#36080</a>, thanks <a href="https://github.com/kasperpeulen"><code>@kasperpeulen</code></a>!</li> <li>Addon Vitest: Resolve story test globs against the project root - <a href="https://redirect.github.com/storybookjs/storybook/pull/36103">#36103</a>, thanks <a href="https://github.com/kasperpeulen"><code>@kasperpeulen</code></a>!</li> <li>Addon-vitest: Filter Storybook instrumentation from reported stack traces - <a href="https://redirect.github.com/storybookjs/storybook/pull/36120">#36120</a>, thanks <a href="https://github.com/ghengeveld"><code>@ghengeveld</code></a>!</li> <li>Angular Vite: Resolve tsConfig against the workspace root - <a href="https://redirect.github.com/storybookjs/storybook/pull/36026">#36026</a>, thanks <a href="https://github.com/ndelangen"><code>@ndelangen</code></a>!</li> <li>Angular-Vite: Run Compodoc on demand - <a href="https://redirect.github.com/storybookjs/storybook/pull/35776">#35776</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Add an in-process docgen analyzer, replacing Compodoc under the flag - <a href="https://redirect.github.com/storybookjs/storybook/pull/35805">#35805</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Bind only what the component accepts in story snippets, and report the rest - <a href="https://redirect.github.com/storybookjs/storybook/pull/35943">#35943</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Decide the migration's zone.js import from the dependency tree - <a href="https://redirect.github.com/storybookjs/storybook/pull/36008">#36008</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Declare story args the snippet markup binds by name - <a href="https://redirect.github.com/storybookjs/storybook/pull/35895">#35895</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Declare style preprocessors as optional peers and name the missing one - <a href="https://redirect.github.com/storybookjs/storybook/pull/36098">#36098</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Derive required inputs from Compodoc's own flag - <a href="https://redirect.github.com/storybookjs/storybook/pull/35758">#35758</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Extract Compodoc parsing into its own package - <a href="https://redirect.github.com/storybookjs/storybook/pull/35749">#35749</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Extract component JSDoc through TypeScript's APIs - <a href="https://redirect.github.com/storybookjs/storybook/pull/35977">#35977</a>, thanks <a href="https://github.com/huang-julien"><code>@huang-julien</code></a>!</li> <li>Angular: Extract docgen on the server via Compodoc - <a href="https://redirect.github.com/storybookjs/storybook/pull/35733">#35733</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Fix component resolution, MCP output, and dev/build path aliasing - <a href="https://redirect.github.com/storybookjs/storybook/pull/35952">#35952</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Fix eight upgrade and migration bugs - <a href="https://redirect.github.com/storybookjs/storybook/pull/35946">#35946</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Fix ten docgen bugs found across 22 community repositories - <a href="https://redirect.github.com/storybookjs/storybook/pull/35941">#35941</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Generate story-docs snippets from the analyzer - <a href="https://redirect.github.com/storybookjs/storybook/pull/35807">#35807</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Give agents real input and output documentation - <a href="https://redirect.github.com/storybookjs/storybook/pull/35896">#35896</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Hide class internals from the props table by default - <a href="https://redirect.github.com/storybookjs/storybook/pull/35887">#35887</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Install the <code>@storybook/angular-vite</code> peers that nothing else brings in - <a href="https://redirect.github.com/storybookjs/storybook/pull/36002">#36002</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Keep the function control on constructor and generic signatures - <a href="https://redirect.github.com/storybookjs/storybook/pull/35921">#35921</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Make experimentalDocgenServer the default in angular-vite - <a href="https://redirect.github.com/storybookjs/storybook/pull/35886">#35886</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Migrate Analog projects to angular-vite instead of refusing them - <a href="https://redirect.github.com/storybookjs/storybook/pull/35971">#35971</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Print unevaluable story args instead of slicing the file - <a href="https://redirect.github.com/storybookjs/storybook/pull/35888">#35888</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Read the story shapes that supply their own markup - <a href="https://redirect.github.com/storybookjs/storybook/pull/35797">#35797</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Render self-closing tags in server-side docs snippets - <a href="https://redirect.github.com/storybookjs/storybook/pull/35953">#35953</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Render the required badge for required inputs in the props table - <a href="https://redirect.github.com/storybookjs/storybook/pull/36065">#36065</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Resolve <code>@angular/core</code> through the package manager, not the raw specifier - <a href="https://redirect.github.com/storybookjs/storybook/pull/35999">#35999</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Resolve builder <code>styles</code> the way the Angular builders do - <a href="https://redirect.github.com/storybookjs/storybook/pull/35998">#35998</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Resolve builder styles against the workspace root - <a href="https://redirect.github.com/storybookjs/storybook/pull/35974">#35974</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Skip the runtime source decorator when the docgen server produces snippets - <a href="https://redirect.github.com/storybookjs/storybook/pull/35906">#35906</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Stop marking a defaulted input as required in the props table - <a href="https://redirect.github.com/storybookjs/storybook/pull/35899">#35899</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/storybookjs/storybook/commit/a77777356be2aeaff89d7a2b25254db7b2318392"><code>a777773</code></a> Bump version from "10.6.0-beta.3" to "10.6.0" [skip ci]</li> <li><a href="https://github.com/storybookjs/storybook/commit/f32b3667dad8df220cda0359e170bc49931af68c"><code>f32b366</code></a> Bump version from "10.6.0-beta.2" to "10.6.0-beta.3" [skip ci]</li> <li><a href="https://github.com/storybookjs/storybook/commit/0ad1336cbf0ecdab9f6b540570ae9015ae73ab86"><code>0ad1336</code></a> Bump version from "10.6.0-beta.1" to "10.6.0-beta.2" [skip ci]</li> <li><a href="https://github.com/storybookjs/storybook/commit/16359ee17802628c47915c21408cb578d2707b83"><code>16359ee</code></a> Bump version from "10.6.0-beta.0" to "10.6.0-beta.1" [skip ci]</li> <li><a href="https://github.com/storybookjs/storybook/commit/2e0e2f609d1351ba4384eb52e0728dc9cd8b275b"><code>2e0e2f6</code></a> Bump version from "10.6.0-alpha.9" to "10.6.0-beta.0" [skip ci]</li> <li><a href="https://github.com/storybookjs/storybook/commit/6a6dec2aedff6744a9d9226e1f6515e3d5e8b42a"><code>6a6dec2</code></a> Bump version from "10.6.0-alpha.8" to "10.6.0-alpha.9" [skip ci]</li> <li><a href="https://github.com/storybookjs/storybook/commit/cd2d16395a5ffa39189b96aafb6af67f280079db"><code>cd2d163</code></a> Bump version from "10.6.0-alpha.7" to "10.6.0-alpha.8" [skip ci]</li> <li><a href="https://github.com/storybookjs/storybook/commit/898f0ce828ec8bd00985934786724b94f8428c42"><code>898f0ce</code></a> Bump version from "10.6.0-alpha.6" to "10.6.0-alpha.7" [skip ci]</li> <li><a href="https://github.com/storybookjs/storybook/commit/cf97b46ca1a452f6f47206fd6ed7043a88e38a60"><code>cf97b46</code></a> Bump version from "10.6.0-alpha.5" to "10.6.0-alpha.6" [skip ci]</li> <li><a href="https://github.com/storybookjs/storybook/commit/2b7f6be9c96f72d6eca4b80af11db1a4ff380e8e"><code>2b7f6be</code></a> Bump version from "10.6.0-alpha.4" to "10.6.0-alpha.5" [skip ci]</li> <li>Additional commits viewable in <a href="https://github.com/storybookjs/storybook/commits/v10.6.0/code/addons/a11y">compare view</a></li> </ul> </details> <br /> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |
||
|
|
41c18aa443 |
build(deps-dev): bump storybook from 10.5.10 to 10.6.0 (#12984)
Bumps [storybook](https://github.com/storybookjs/storybook/tree/HEAD/code/core) from 10.5.10 to 10.6.0. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/storybookjs/storybook/releases">storybook's releases</a>.</em></p> <blockquote> <h2>v10.6.0</h2> <h2>10.6.0</h2> <blockquote> <p>New skills architecture for agentic workflows</p> </blockquote> <p>Storybook 10.6 contains hundreds of fixes and improvements:</p> <ul> <li>💻 CLI bindings for agent tools/skills</li> <li>🅰️ Angular-Vite MCP/skills support and improved docgen/snippets (experimental)</li> <li>🟢 Vue MCP/skills support and improved docgen/snippets (experimental)</li> <li>🧩 Tanstack / NextJS-Vite framework bugfixes</li> <li>⚡ Improved performance and reduced bundle size</li> </ul> <!-- raw HTML omitted --> <ul> <li>Addon MCP: Stop silently dropping composed refs from MCP composition - <a href="https://redirect.github.com/storybookjs/storybook/pull/36077">#36077</a>, thanks <a href="https://github.com/kasperpeulen"><code>@kasperpeulen</code></a>!</li> <li>Addon Vitest: Pin storybook/test in optimizeDeps so its CJS-only deps are prebundled - <a href="https://redirect.github.com/storybookjs/storybook/pull/35572">#35572</a>, thanks <a href="https://github.com/Nic-Polumeyv"><code>@Nic-Polumeyv</code></a>!</li> <li>Addon Vitest: Report test runs with failures as failed tool outcomes - <a href="https://redirect.github.com/storybookjs/storybook/pull/36080">#36080</a>, thanks <a href="https://github.com/kasperpeulen"><code>@kasperpeulen</code></a>!</li> <li>Addon Vitest: Resolve story test globs against the project root - <a href="https://redirect.github.com/storybookjs/storybook/pull/36103">#36103</a>, thanks <a href="https://github.com/kasperpeulen"><code>@kasperpeulen</code></a>!</li> <li>Addon-vitest: Filter Storybook instrumentation from reported stack traces - <a href="https://redirect.github.com/storybookjs/storybook/pull/36120">#36120</a>, thanks <a href="https://github.com/ghengeveld"><code>@ghengeveld</code></a>!</li> <li>Angular Vite: Resolve tsConfig against the workspace root - <a href="https://redirect.github.com/storybookjs/storybook/pull/36026">#36026</a>, thanks <a href="https://github.com/ndelangen"><code>@ndelangen</code></a>!</li> <li>Angular-Vite: Run Compodoc on demand - <a href="https://redirect.github.com/storybookjs/storybook/pull/35776">#35776</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Add an in-process docgen analyzer, replacing Compodoc under the flag - <a href="https://redirect.github.com/storybookjs/storybook/pull/35805">#35805</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Bind only what the component accepts in story snippets, and report the rest - <a href="https://redirect.github.com/storybookjs/storybook/pull/35943">#35943</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Decide the migration's zone.js import from the dependency tree - <a href="https://redirect.github.com/storybookjs/storybook/pull/36008">#36008</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Declare story args the snippet markup binds by name - <a href="https://redirect.github.com/storybookjs/storybook/pull/35895">#35895</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Declare style preprocessors as optional peers and name the missing one - <a href="https://redirect.github.com/storybookjs/storybook/pull/36098">#36098</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Derive required inputs from Compodoc's own flag - <a href="https://redirect.github.com/storybookjs/storybook/pull/35758">#35758</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Extract Compodoc parsing into its own package - <a href="https://redirect.github.com/storybookjs/storybook/pull/35749">#35749</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Extract component JSDoc through TypeScript's APIs - <a href="https://redirect.github.com/storybookjs/storybook/pull/35977">#35977</a>, thanks <a href="https://github.com/huang-julien"><code>@huang-julien</code></a>!</li> <li>Angular: Extract docgen on the server via Compodoc - <a href="https://redirect.github.com/storybookjs/storybook/pull/35733">#35733</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Fix component resolution, MCP output, and dev/build path aliasing - <a href="https://redirect.github.com/storybookjs/storybook/pull/35952">#35952</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Fix eight upgrade and migration bugs - <a href="https://redirect.github.com/storybookjs/storybook/pull/35946">#35946</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Fix ten docgen bugs found across 22 community repositories - <a href="https://redirect.github.com/storybookjs/storybook/pull/35941">#35941</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Generate story-docs snippets from the analyzer - <a href="https://redirect.github.com/storybookjs/storybook/pull/35807">#35807</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Give agents real input and output documentation - <a href="https://redirect.github.com/storybookjs/storybook/pull/35896">#35896</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Hide class internals from the props table by default - <a href="https://redirect.github.com/storybookjs/storybook/pull/35887">#35887</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Install the `@storybook/angular-vite` peers that nothing else brings in - <a href="https://redirect.github.com/storybookjs/storybook/pull/36002">#36002</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Keep the function control on constructor and generic signatures - <a href="https://redirect.github.com/storybookjs/storybook/pull/35921">#35921</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Make experimentalDocgenServer the default in angular-vite - <a href="https://redirect.github.com/storybookjs/storybook/pull/35886">#35886</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Migrate Analog projects to angular-vite instead of refusing them - <a href="https://redirect.github.com/storybookjs/storybook/pull/35971">#35971</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Print unevaluable story args instead of slicing the file - <a href="https://redirect.github.com/storybookjs/storybook/pull/35888">#35888</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Read the story shapes that supply their own markup - <a href="https://redirect.github.com/storybookjs/storybook/pull/35797">#35797</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Render self-closing tags in server-side docs snippets - <a href="https://redirect.github.com/storybookjs/storybook/pull/35953">#35953</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Render the required badge for required inputs in the props table - <a href="https://redirect.github.com/storybookjs/storybook/pull/36065">#36065</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Resolve `@angular/core` through the package manager, not the raw specifier - <a href="https://redirect.github.com/storybookjs/storybook/pull/35999">#35999</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Resolve builder `styles` the way the Angular builders do - <a href="https://redirect.github.com/storybookjs/storybook/pull/35998">#35998</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Resolve builder styles against the workspace root - <a href="https://redirect.github.com/storybookjs/storybook/pull/35974">#35974</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Skip the runtime source decorator when the docgen server produces snippets - <a href="https://redirect.github.com/storybookjs/storybook/pull/35906">#35906</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/storybookjs/storybook/blob/next/CHANGELOG.md">storybook's changelog</a>.</em></p> <blockquote> <h2>10.6.0</h2> <blockquote> <p>New skills architecture for agentic workflows</p> </blockquote> <p>Storybook 10.6 contains hundreds of fixes and improvements:</p> <ul> <li>💻 CLI bindings for agent tools/skills</li> <li>🅰️ Angular-Vite MCP/skills support and improved docgen/snippets (experimental)</li> <li>🟢 Vue MCP/skills support and improved docgen/snippets (experimental)</li> <li>🧩 Tanstack / NextJS-Vite framework bugfixes</li> <li>⚡ Improved performance and reduced bundle size</li> </ul> <!-- raw HTML omitted --> <ul> <li>Addon MCP: Stop silently dropping composed refs from MCP composition - <a href="https://redirect.github.com/storybookjs/storybook/pull/36077">#36077</a>, thanks <a href="https://github.com/kasperpeulen"><code>@kasperpeulen</code></a>!</li> <li>Addon Vitest: Pin storybook/test in optimizeDeps so its CJS-only deps are prebundled - <a href="https://redirect.github.com/storybookjs/storybook/pull/35572">#35572</a>, thanks <a href="https://github.com/Nic-Polumeyv"><code>@Nic-Polumeyv</code></a>!</li> <li>Addon Vitest: Report test runs with failures as failed tool outcomes - <a href="https://redirect.github.com/storybookjs/storybook/pull/36080">#36080</a>, thanks <a href="https://github.com/kasperpeulen"><code>@kasperpeulen</code></a>!</li> <li>Addon Vitest: Resolve story test globs against the project root - <a href="https://redirect.github.com/storybookjs/storybook/pull/36103">#36103</a>, thanks <a href="https://github.com/kasperpeulen"><code>@kasperpeulen</code></a>!</li> <li>Addon-vitest: Filter Storybook instrumentation from reported stack traces - <a href="https://redirect.github.com/storybookjs/storybook/pull/36120">#36120</a>, thanks <a href="https://github.com/ghengeveld"><code>@ghengeveld</code></a>!</li> <li>Angular Vite: Resolve tsConfig against the workspace root - <a href="https://redirect.github.com/storybookjs/storybook/pull/36026">#36026</a>, thanks <a href="https://github.com/ndelangen"><code>@ndelangen</code></a>!</li> <li>Angular-Vite: Run Compodoc on demand - <a href="https://redirect.github.com/storybookjs/storybook/pull/35776">#35776</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Add an in-process docgen analyzer, replacing Compodoc under the flag - <a href="https://redirect.github.com/storybookjs/storybook/pull/35805">#35805</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Bind only what the component accepts in story snippets, and report the rest - <a href="https://redirect.github.com/storybookjs/storybook/pull/35943">#35943</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Decide the migration's zone.js import from the dependency tree - <a href="https://redirect.github.com/storybookjs/storybook/pull/36008">#36008</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Declare story args the snippet markup binds by name - <a href="https://redirect.github.com/storybookjs/storybook/pull/35895">#35895</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Declare style preprocessors as optional peers and name the missing one - <a href="https://redirect.github.com/storybookjs/storybook/pull/36098">#36098</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Derive required inputs from Compodoc's own flag - <a href="https://redirect.github.com/storybookjs/storybook/pull/35758">#35758</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Extract Compodoc parsing into its own package - <a href="https://redirect.github.com/storybookjs/storybook/pull/35749">#35749</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Extract component JSDoc through TypeScript's APIs - <a href="https://redirect.github.com/storybookjs/storybook/pull/35977">#35977</a>, thanks <a href="https://github.com/huang-julien"><code>@huang-julien</code></a>!</li> <li>Angular: Extract docgen on the server via Compodoc - <a href="https://redirect.github.com/storybookjs/storybook/pull/35733">#35733</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Fix component resolution, MCP output, and dev/build path aliasing - <a href="https://redirect.github.com/storybookjs/storybook/pull/35952">#35952</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Fix eight upgrade and migration bugs - <a href="https://redirect.github.com/storybookjs/storybook/pull/35946">#35946</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Fix ten docgen bugs found across 22 community repositories - <a href="https://redirect.github.com/storybookjs/storybook/pull/35941">#35941</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Generate story-docs snippets from the analyzer - <a href="https://redirect.github.com/storybookjs/storybook/pull/35807">#35807</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Give agents real input and output documentation - <a href="https://redirect.github.com/storybookjs/storybook/pull/35896">#35896</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Hide class internals from the props table by default - <a href="https://redirect.github.com/storybookjs/storybook/pull/35887">#35887</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Install the <code>@storybook/angular-vite</code> peers that nothing else brings in - <a href="https://redirect.github.com/storybookjs/storybook/pull/36002">#36002</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Keep the function control on constructor and generic signatures - <a href="https://redirect.github.com/storybookjs/storybook/pull/35921">#35921</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Make experimentalDocgenServer the default in angular-vite - <a href="https://redirect.github.com/storybookjs/storybook/pull/35886">#35886</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Migrate Analog projects to angular-vite instead of refusing them - <a href="https://redirect.github.com/storybookjs/storybook/pull/35971">#35971</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Print unevaluable story args instead of slicing the file - <a href="https://redirect.github.com/storybookjs/storybook/pull/35888">#35888</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Read the story shapes that supply their own markup - <a href="https://redirect.github.com/storybookjs/storybook/pull/35797">#35797</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Render self-closing tags in server-side docs snippets - <a href="https://redirect.github.com/storybookjs/storybook/pull/35953">#35953</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Render the required badge for required inputs in the props table - <a href="https://redirect.github.com/storybookjs/storybook/pull/36065">#36065</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Resolve <code>@angular/core</code> through the package manager, not the raw specifier - <a href="https://redirect.github.com/storybookjs/storybook/pull/35999">#35999</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Resolve builder <code>styles</code> the way the Angular builders do - <a href="https://redirect.github.com/storybookjs/storybook/pull/35998">#35998</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Resolve builder styles against the workspace root - <a href="https://redirect.github.com/storybookjs/storybook/pull/35974">#35974</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Skip the runtime source decorator when the docgen server produces snippets - <a href="https://redirect.github.com/storybookjs/storybook/pull/35906">#35906</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Angular: Stop marking a defaulted input as required in the props table - <a href="https://redirect.github.com/storybookjs/storybook/pull/35899">#35899</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/storybookjs/storybook/commit/a77777356be2aeaff89d7a2b25254db7b2318392"><code>a777773</code></a> Bump version from "10.6.0-beta.3" to "10.6.0" [skip ci]</li> <li><a href="https://github.com/storybookjs/storybook/commit/f32b3667dad8df220cda0359e170bc49931af68c"><code>f32b366</code></a> Bump version from "10.6.0-beta.2" to "10.6.0-beta.3" [skip ci]</li> <li><a href="https://github.com/storybookjs/storybook/commit/db38cb39d9be5609bba4ac3b861b2263c21ae1b6"><code>db38cb3</code></a> CLI: Serve skills through one path with a single expected-failure channel</li> <li><a href="https://github.com/storybookjs/storybook/commit/79bc6a63e0ecd6eb10baecb6302661da09eea1f7"><code>79bc6a6</code></a> CLI: Address review on skills reshape; credit skills --all in eval parser</li> <li><a href="https://github.com/storybookjs/storybook/commit/c11b0f2a6eb1e15b489a8c0bc17c5eace4c8a8b5"><code>c11b0f2</code></a> CLI: Drop per-skill --help; --help always prints the catalog</li> <li><a href="https://github.com/storybookjs/storybook/commit/c878263a6ced94ef30148b99758bea139122f5de"><code>c878263</code></a> CLI: Drop skills get/list, add skills --all</li> <li><a href="https://github.com/storybookjs/storybook/commit/c55462ef810dcf5641636a54021861f5d1d90222"><code>c55462e</code></a> Merge pull request <a href="https://github.com/storybookjs/storybook/tree/HEAD/code/core/issues/36117">#36117</a> from storybookjs/kasper/tools-record-storybook-path</li> <li><a href="https://github.com/storybookjs/storybook/commit/0ad1336cbf0ecdab9f6b540570ae9015ae73ab86"><code>0ad1336</code></a> Bump version from "10.6.0-beta.1" to "10.6.0-beta.2" [skip ci]</li> <li><a href="https://github.com/storybookjs/storybook/commit/8ad41c80847390d53af17342e33c94d0f87bb368"><code>8ad41c8</code></a> CLI: Reject surplus skills arguments</li> <li><a href="https://github.com/storybookjs/storybook/commit/8d607e3b18731f63e09d23ad488623f0c01224bd"><code>8d607e3</code></a> Tools: Match Storybook installations correctly on Windows</li> <li>Additional commits viewable in <a href="https://github.com/storybookjs/storybook/commits/v10.6.0/code/core">compare view</a></li> </ul> </details> <br /> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |
||
|
|
67ebed8a52 |
build(deps): bump lucide-react from 1.45.0 to 1.48.0 (#12985)
Bumps [lucide-react](https://github.com/lucide-icons/lucide/tree/HEAD/packages/lucide-react) from 1.45.0 to 1.48.0. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/lucide-icons/lucide/releases">lucide-react's releases</a>.</em></p> <blockquote> <h2>Version 1.48.0</h2> <h2>What's Changed</h2> <ul> <li>feat(icons): added <code>briefcase-plus</code> icon by <a href="https://github.com/tylerkade"><code>@tylerkade</code></a> in <a href="https://redirect.github.com/lucide-icons/lucide/pull/4757">lucide-icons/lucide#4757</a></li> <li>feat(icons): added <code>square-sparkles</code> icon by <a href="https://github.com/nananecy"><code>@nananecy</code></a> in <a href="https://redirect.github.com/lucide-icons/lucide/pull/3610">lucide-icons/lucide#3610</a></li> <li>feat(icons): added <code>line-dot-left-horizontal</code> icon by <a href="https://github.com/nathan-de-pachtere"><code>@nathan-de-pachtere</code></a> in <a href="https://redirect.github.com/lucide-icons/lucide/pull/3855">lucide-icons/lucide#3855</a></li> <li>fix(packages/svelte,solid): fix shared type imports in Solid and Svelte by <a href="https://github.com/karsa-mistmere"><code>@karsa-mistmere</code></a> in <a href="https://redirect.github.com/lucide-icons/lucide/pull/4846">lucide-icons/lucide#4846</a></li> <li>chore(deps-dev): bump react-native from 0.76.9 to 0.87.1 in the react-native-deps group across 1 directory by <a href="https://github.com/dependabot"><code>@dependabot</code></a>[bot] in <a href="https://redirect.github.com/lucide-icons/lucide/pull/4673">lucide-icons/lucide#4673</a></li> <li>feat(packages): export __iconNode data across framework packages by <a href="https://github.com/lx3133584"><code>@lx3133584</code></a> in <a href="https://redirect.github.com/lucide-icons/lucide/pull/4761">lucide-icons/lucide#4761</a></li> <li>fix(icons): Tweak <code>card-sim</code> chip by <a href="https://github.com/danielbayley"><code>@danielbayley</code></a> in <a href="https://redirect.github.com/lucide-icons/lucide/pull/3649">lucide-icons/lucide#3649</a></li> <li>feat(icons): added <code>line-dot-top-vertical</code> icon by <a href="https://github.com/nathan-de-pachtere"><code>@nathan-de-pachtere</code></a> in <a href="https://redirect.github.com/lucide-icons/lucide/pull/3856">lucide-icons/lucide#3856</a></li> <li>feat(icons): added <code>line-dot-bottom-vertical</code> icon by <a href="https://github.com/nathan-de-pachtere"><code>@nathan-de-pachtere</code></a> in <a href="https://redirect.github.com/lucide-icons/lucide/pull/3857">lucide-icons/lucide#3857</a></li> <li>fix(packages/react-native): pass testID to the rendered Svg element by <a href="https://github.com/OlegBezr"><code>@OlegBezr</code></a> in <a href="https://redirect.github.com/lucide-icons/lucide/pull/4881">lucide-icons/lucide#4881</a></li> <li>chore(<code>@lucide/vue</code>): Fix types <code>@lucide/vue</code> package and added workflow for it. by <a href="https://github.com/ericfennis"><code>@ericfennis</code></a> in <a href="https://redirect.github.com/lucide-icons/lucide/pull/4883">lucide-icons/lucide#4883</a></li> <li>test(packages/shared): cover buildLucideIconForReact by <a href="https://github.com/vugarbbakhishov-hub"><code>@vugarbbakhishov-hub</code></a> in <a href="https://redirect.github.com/lucide-icons/lucide/pull/4872">lucide-icons/lucide#4872</a></li> <li>feat(site): Better icon detail page and add unreleased flag by <a href="https://github.com/ericfennis"><code>@ericfennis</code></a> in <a href="https://redirect.github.com/lucide-icons/lucide/pull/4877">lucide-icons/lucide#4877</a></li> <li>fix(icons): changed <code>map-pinned</code> icon by <a href="https://github.com/jguddas"><code>@jguddas</code></a> in <a href="https://redirect.github.com/lucide-icons/lucide/pull/4880">lucide-icons/lucide#4880</a></li> <li>fix(icons): changed <code>mail-pen</code> by <a href="https://github.com/karsa-mistmere"><code>@karsa-mistmere</code></a> in <a href="https://redirect.github.com/lucide-icons/lucide/pull/4899">lucide-icons/lucide#4899</a></li> <li>chore(deps-dev): bump the angular-deps group across 1 directory with 14 updates by <a href="https://github.com/dependabot"><code>@dependabot</code></a>[bot] in <a href="https://redirect.github.com/lucide-icons/lucide/pull/4895">lucide-icons/lucide#4895</a></li> <li>chore(deps): bump the vue-deps group with 3 updates by <a href="https://github.com/dependabot"><code>@dependabot</code></a>[bot] in <a href="https://redirect.github.com/lucide-icons/lucide/pull/4893">lucide-icons/lucide#4893</a></li> <li>chore(typchecking): More typecheck jobs for all packages by <a href="https://github.com/ericfennis"><code>@ericfennis</code></a> in <a href="https://redirect.github.com/lucide-icons/lucide/pull/4885">lucide-icons/lucide#4885</a></li> <li>feat(icons): add house-cog icon by <a href="https://github.com/ajaxjiang96"><code>@ajaxjiang96</code></a> in <a href="https://redirect.github.com/lucide-icons/lucide/pull/4904">lucide-icons/lucide#4904</a></li> </ul> <h2>New Contributors</h2> <ul> <li><a href="https://github.com/nananecy"><code>@nananecy</code></a> made their first contribution in <a href="https://redirect.github.com/lucide-icons/lucide/pull/3610">lucide-icons/lucide#3610</a></li> <li><a href="https://github.com/OlegBezr"><code>@OlegBezr</code></a> made their first contribution in <a href="https://redirect.github.com/lucide-icons/lucide/pull/4881">lucide-icons/lucide#4881</a></li> <li><a href="https://github.com/vugarbbakhishov-hub"><code>@vugarbbakhishov-hub</code></a> made their first contribution in <a href="https://redirect.github.com/lucide-icons/lucide/pull/4872">lucide-icons/lucide#4872</a></li> <li><a href="https://github.com/ajaxjiang96"><code>@ajaxjiang96</code></a> made their first contribution in <a href="https://redirect.github.com/lucide-icons/lucide/pull/4904">lucide-icons/lucide#4904</a></li> </ul> <p><strong>Full Changelog</strong>: <a href="https://github.com/lucide-icons/lucide/compare/1.47.0...1.48.0">https://github.com/lucide-icons/lucide/compare/1.47.0...1.48.0</a></p> <h2>Version 1.47.0</h2> <h2>What's Changed</h2> <ul> <li>feat(icons): add lambda icon by <a href="https://github.com/UbaidUllah9962"><code>@UbaidUllah9962</code></a> in <a href="https://redirect.github.com/lucide-icons/lucide/pull/4017">lucide-icons/lucide#4017</a></li> <li>feat(icons): delegated <code>faucet</code> icon from lab by <a href="https://github.com/karsa-mistmere"><code>@karsa-mistmere</code></a> in <a href="https://redirect.github.com/lucide-icons/lucide/pull/4764">lucide-icons/lucide#4764</a></li> <li>feat(icons): added <code>door-closed-package</code> icon by <a href="https://github.com/karsa-mistmere"><code>@karsa-mistmere</code></a> in <a href="https://redirect.github.com/lucide-icons/lucide/pull/4814">lucide-icons/lucide#4814</a></li> <li>feat(icons): added 'nepali-rupee' icon by <a href="https://github.com/sarajdhakal"><code>@sarajdhakal</code></a> in <a href="https://redirect.github.com/lucide-icons/lucide/pull/4608">lucide-icons/lucide#4608</a></li> <li>feat(icons): added <code>tube-lotion</code> icon by <a href="https://github.com/AlecRust"><code>@AlecRust</code></a> in <a href="https://redirect.github.com/lucide-icons/lucide/pull/4029">lucide-icons/lucide#4029</a></li> <li>feat(icons): Added cupcake icon by <a href="https://github.com/briz123"><code>@briz123</code></a> in <a href="https://redirect.github.com/lucide-icons/lucide/pull/3000">lucide-icons/lucide#3000</a></li> <li>feat(icons): added square-dashed-x icon by <a href="https://github.com/EthanHazel"><code>@EthanHazel</code></a> in <a href="https://redirect.github.com/lucide-icons/lucide/pull/4535">lucide-icons/lucide#4535</a></li> <li>feat(icons): add <code>rotate-cw-clock</code> icon by <a href="https://github.com/gkkconan"><code>@gkkconan</code></a> in <a href="https://redirect.github.com/lucide-icons/lucide/pull/3979">lucide-icons/lucide#3979</a></li> <li>fix(icons): remove path from save-off by <a href="https://github.com/HPRILLER"><code>@HPRILLER</code></a> in <a href="https://redirect.github.com/lucide-icons/lucide/pull/4848">lucide-icons/lucide#4848</a></li> <li>fix(icons): changed <code>calendar-chevrons-right</code> by <a href="https://github.com/karsa-mistmere"><code>@karsa-mistmere</code></a> in <a href="https://redirect.github.com/lucide-icons/lucide/pull/4865">lucide-icons/lucide#4865</a></li> <li>fix(icons): changed <code>broccoli</code> icon by <a href="https://github.com/jguddas"><code>@jguddas</code></a> in <a href="https://redirect.github.com/lucide-icons/lucide/pull/4871">lucide-icons/lucide#4871</a></li> <li>feat(icons): added square-dashed-plus by <a href="https://github.com/psjdev"><code>@psjdev</code></a> in <a href="https://redirect.github.com/lucide-icons/lucide/pull/4849">lucide-icons/lucide#4849</a></li> </ul> <h2>New Contributors</h2> <ul> <li><a href="https://github.com/UbaidUllah9962"><code>@UbaidUllah9962</code></a> made their first contribution in <a href="https://redirect.github.com/lucide-icons/lucide/pull/4017">lucide-icons/lucide#4017</a></li> <li><a href="https://github.com/sarajdhakal"><code>@sarajdhakal</code></a> made their first contribution in <a href="https://redirect.github.com/lucide-icons/lucide/pull/4608">lucide-icons/lucide#4608</a></li> <li><a href="https://github.com/AlecRust"><code>@AlecRust</code></a> made their first contribution in <a href="https://redirect.github.com/lucide-icons/lucide/pull/4029">lucide-icons/lucide#4029</a></li> <li><a href="https://github.com/gkkconan"><code>@gkkconan</code></a> made their first contribution in <a href="https://redirect.github.com/lucide-icons/lucide/pull/3979">lucide-icons/lucide#3979</a></li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/lucide-icons/lucide/commit/f06ac67e33d645c40b8ce19a0419c85c5d7dd751"><code>f06ac67</code></a> chore(typchecking): More typecheck jobs for all packages (<a href="https://github.com/lucide-icons/lucide/tree/HEAD/packages/lucide-react/issues/4885">#4885</a>)</li> <li>See full diff in <a href="https://github.com/lucide-icons/lucide/commits/1.48.0/packages/lucide-react">compare view</a></li> </ul> </details> <br /> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>canary/v2026.1001.0-canary.11 |
||
|
|
c9cde69299 |
build(deps): bump @anthropic-ai/sdk from 0.121.0 to 0.129.0 (#13386)
Bumps [@anthropic-ai/sdk](https://github.com/anthropics/anthropic-sdk-typescript) from 0.121.0 to 0.129.0. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/anthropics/anthropic-sdk-typescript/releases">@anthropic-ai/sdk's releases</a>.</em></p> <blockquote> <h2>sdk: v0.129.0</h2> <h2>0.129.0 (2026-09-28)</h2> <p>Full Changelog: <a href="https://github.com/anthropics/anthropic-sdk-typescript/compare/sdk-v0.128.0...sdk-v0.129.0">sdk-v0.128.0...sdk-v0.129.0</a></p> <h3>Features</h3> <ul> <li><strong>api:</strong> add between_tools thinking type (<a href="https://github.com/anthropics/anthropic-sdk-typescript/commit/ab51075609a2d583dffdca24856f4214779d9e7f">ab51075</a>)</li> <li><strong>api:</strong> add claude-sonnet-5-5 (<a href="https://github.com/anthropics/anthropic-sdk-typescript/commit/4e7736625fd23a5607800e8de4aa3c37daa74a07">4e77366</a>)</li> <li><strong>api:</strong> add ClientToolUnion type for client-executed tools (<a href="https://github.com/anthropics/anthropic-sdk-typescript/commit/2c1d2d712071a5f10d2e70ea02dc33425b087799">2c1d2d7</a>)</li> <li><strong>api:</strong> add include_inherited and source to workspace rate limits (<a href="https://github.com/anthropics/anthropic-sdk-typescript/commit/66e925e54ff3435a56f51f687641728b94aff306">66e925e</a>)</li> <li><strong>api:</strong> add typed event type values to the Managed Agents events list filter (<a href="https://github.com/anthropics/anthropic-sdk-typescript/commit/8ac4a26809418453b64fee79f8ec790d32d1f92c">8ac4a26</a>)</li> <li><strong>api:</strong> cache diagnostics GA — diagnostics on Message / MessageCreateParams (<a href="https://github.com/anthropics/anthropic-sdk-typescript/commit/5ba5f29696d520f68a794936eff7337dce83ac05">5ba5f29</a>)</li> <li><strong>tools:</strong> optionally start tool calls while the reply streams (<a href="https://github.com/anthropics/anthropic-sdk-typescript/commit/083969beadb360b9c4b329ee2541f67bd78d9caf">083969b</a>)</li> </ul> <h3>Bug Fixes</h3> <ul> <li><strong>client:</strong> also send X-Stainless-Timeout for client-level timeouts (<a href="https://github.com/anthropics/anthropic-sdk-typescript/commit/b84783b6ee03eed519d622ea1e477cf8eb3863bf">b84783b</a>)</li> <li><strong>client:</strong> send upload filenames as given, with no placeholder (<a href="https://github.com/anthropics/anthropic-sdk-typescript/commit/f9d3e980b1b498c1c452300a205811f6a56de69b">f9d3e98</a>)</li> <li><strong>helpers:</strong> degrade between_tools thinking to disabled on fallback hops (<a href="https://redirect.github.com/anthropics/anthropic-sdk-typescript/issues/841">#841</a>) (<a href="https://github.com/anthropics/anthropic-sdk-typescript/commit/edbbf05a62ffe2c95c13810f6d7a0a2796786e5f">edbbf05</a>)</li> <li><strong>internal:</strong> let bundlers drop unused classes with more than ten private-member assignments (<a href="https://github.com/anthropics/anthropic-sdk-typescript/commit/67c7adbe5ebae805631e104b341d932a1554bda8">67c7adb</a>)</li> <li><strong>streaming:</strong> show every complete array item and hold back unfinished numbers in partial tool input (<a href="https://redirect.github.com/anthropics/anthropic-sdk-typescript/issues/781">#781</a>) (<a href="https://github.com/anthropics/anthropic-sdk-typescript/commit/58065889d6b112db6da5127484e0a24025e3fa37">5806588</a>)</li> </ul> <h3>Performance Improvements</h3> <ul> <li><strong>streaming:</strong> drop the redundant iterSSEChunks layer (<a href="https://github.com/anthropics/anthropic-sdk-typescript/commit/0357f812dab273c0780c558606663a03e93e34df">0357f81</a>)</li> <li><strong>streaming:</strong> take each string token as one slice in the partial JSON tokenizer (<a href="https://redirect.github.com/anthropics/anthropic-sdk-typescript/issues/255">#255</a>) (<a href="https://github.com/anthropics/anthropic-sdk-typescript/commit/cdfb1e55afebe1c3be50401ca56bebf0ff009a4e">cdfb1e5</a>)</li> </ul> <h3>Chores</h3> <ul> <li><strong>api:</strong> deprecate the betas param on GA models and completions methods (<a href="https://github.com/anthropics/anthropic-sdk-typescript/commit/5c74e4532bb69f22afa3e08013645ac059440aef">5c74e45</a>)</li> <li><strong>api:</strong> list the known model ids first in the Model types (<a href="https://github.com/anthropics/anthropic-sdk-typescript/commit/94528226386311c3ade468cbdea0326c06a1e53d">9452822</a>)</li> <li><strong>ci:</strong> choose the CI runner by repository (<a href="https://github.com/anthropics/anthropic-sdk-typescript/commit/33db1ec2e99a415ff98619cf88ddddbf2b7ca7b1">33db1ec</a>)</li> <li><strong>docs:</strong> clarify that stream: true returns the raw event stream (<a href="https://github.com/anthropics/anthropic-sdk-typescript/commit/4286c227c3a605bf04d4f59ffb496f44c102a6ec">4286c22</a>)</li> <li><strong>docs:</strong> make Managed Agents actor descriptions resource-neutral (<a href="https://github.com/anthropics/anthropic-sdk-typescript/commit/15733f98deaae4aee2fba26c1bfe4ee1514c7080">15733f9</a>)</li> <li><strong>docs:</strong> restore the research-preview notice on the Dream type (<a href="https://github.com/anthropics/anthropic-sdk-typescript/commit/b32f8baa27c40ad5901531024bae86e0ca046bb5">b32f8ba</a>)</li> <li><strong>internal:</strong> move old constants around (<a href="https://github.com/anthropics/anthropic-sdk-typescript/commit/0cd8edfdc6dd91af4ffee4ed3cc7fc8cc22d65e3">0cd8edf</a>)</li> <li><strong>tests:</strong> add diagnostics to the parser test's Message fixtures (<a href="https://github.com/anthropics/anthropic-sdk-typescript/commit/eb5ca58d51ed3309b1f317b20f7d248b036ba76a">eb5ca58</a>)</li> <li><strong>tools:</strong> remove client-side compaction control (<a href="https://redirect.github.com/anthropics/anthropic-sdk-typescript/issues/802">#802</a>) (<a href="https://github.com/anthropics/anthropic-sdk-typescript/commit/9c3e8a5ffa38c35dec32f0258becd360babd5fb1">9c3e8a5</a>)</li> </ul> <h3>Documentation</h3> <ul> <li><strong>api:</strong> prefer each field's own description over its shared type's (<a href="https://github.com/anthropics/anthropic-sdk-typescript/commit/51934782720725acca570edeb0a3a7501ca7dbd8">5193478</a>)</li> <li>expand CLAUDE.md into a full contributor guide (<a href="https://github.com/anthropics/anthropic-sdk-typescript/commit/98d2ddbce7c1eabbabe5a130d18d307c237fb75c">98d2ddb</a>)</li> </ul> <h2>sdk: v0.128.0</h2> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/anthropics/anthropic-sdk-typescript/blob/main/CHANGELOG.md">@anthropic-ai/sdk's changelog</a>.</em></p> <blockquote> <h2>0.129.0 (2026-09-28)</h2> <p>Full Changelog: <a href="https://github.com/anthropics/anthropic-sdk-typescript/compare/sdk-v0.128.0...sdk-v0.129.0">sdk-v0.128.0...sdk-v0.129.0</a></p> <h3>Features</h3> <ul> <li><strong>api:</strong> add between_tools thinking type (<a href="https://github.com/anthropics/anthropic-sdk-typescript/commit/ab51075609a2d583dffdca24856f4214779d9e7f">ab51075</a>)</li> <li><strong>api:</strong> add claude-sonnet-5-5 (<a href="https://github.com/anthropics/anthropic-sdk-typescript/commit/4e7736625fd23a5607800e8de4aa3c37daa74a07">4e77366</a>)</li> <li><strong>api:</strong> add ClientToolUnion type for client-executed tools (<a href="https://github.com/anthropics/anthropic-sdk-typescript/commit/2c1d2d712071a5f10d2e70ea02dc33425b087799">2c1d2d7</a>)</li> <li><strong>api:</strong> add include_inherited and source to workspace rate limits (<a href="https://github.com/anthropics/anthropic-sdk-typescript/commit/66e925e54ff3435a56f51f687641728b94aff306">66e925e</a>)</li> <li><strong>api:</strong> add typed event type values to the Managed Agents events list filter (<a href="https://github.com/anthropics/anthropic-sdk-typescript/commit/8ac4a26809418453b64fee79f8ec790d32d1f92c">8ac4a26</a>)</li> <li><strong>api:</strong> cache diagnostics GA — diagnostics on Message / MessageCreateParams (<a href="https://github.com/anthropics/anthropic-sdk-typescript/commit/5ba5f29696d520f68a794936eff7337dce83ac05">5ba5f29</a>)</li> <li><strong>tools:</strong> optionally start tool calls while the reply streams (<a href="https://github.com/anthropics/anthropic-sdk-typescript/commit/083969beadb360b9c4b329ee2541f67bd78d9caf">083969b</a>)</li> </ul> <h3>Bug Fixes</h3> <ul> <li><strong>client:</strong> also send X-Stainless-Timeout for client-level timeouts (<a href="https://github.com/anthropics/anthropic-sdk-typescript/commit/b84783b6ee03eed519d622ea1e477cf8eb3863bf">b84783b</a>)</li> <li><strong>client:</strong> send upload filenames as given, with no placeholder (<a href="https://github.com/anthropics/anthropic-sdk-typescript/commit/f9d3e980b1b498c1c452300a205811f6a56de69b">f9d3e98</a>)</li> <li><strong>helpers:</strong> degrade between_tools thinking to disabled on fallback hops (<a href="https://redirect.github.com/anthropics/anthropic-sdk-typescript/issues/841">#841</a>) (<a href="https://github.com/anthropics/anthropic-sdk-typescript/commit/edbbf05a62ffe2c95c13810f6d7a0a2796786e5f">edbbf05</a>)</li> <li><strong>internal:</strong> let bundlers drop unused classes with more than ten private-member assignments (<a href="https://github.com/anthropics/anthropic-sdk-typescript/commit/67c7adbe5ebae805631e104b341d932a1554bda8">67c7adb</a>)</li> <li><strong>streaming:</strong> show every complete array item and hold back unfinished numbers in partial tool input (<a href="https://redirect.github.com/anthropics/anthropic-sdk-typescript/issues/781">#781</a>) (<a href="https://github.com/anthropics/anthropic-sdk-typescript/commit/58065889d6b112db6da5127484e0a24025e3fa37">5806588</a>)</li> </ul> <h3>Performance Improvements</h3> <ul> <li><strong>streaming:</strong> drop the redundant iterSSEChunks layer (<a href="https://github.com/anthropics/anthropic-sdk-typescript/commit/0357f812dab273c0780c558606663a03e93e34df">0357f81</a>)</li> <li><strong>streaming:</strong> take each string token as one slice in the partial JSON tokenizer (<a href="https://redirect.github.com/anthropics/anthropic-sdk-typescript/issues/255">#255</a>) (<a href="https://github.com/anthropics/anthropic-sdk-typescript/commit/cdfb1e55afebe1c3be50401ca56bebf0ff009a4e">cdfb1e5</a>)</li> </ul> <h3>Chores</h3> <ul> <li><strong>api:</strong> deprecate the betas param on GA models and completions methods (<a href="https://github.com/anthropics/anthropic-sdk-typescript/commit/5c74e4532bb69f22afa3e08013645ac059440aef">5c74e45</a>)</li> <li><strong>api:</strong> list the known model ids first in the Model types (<a href="https://github.com/anthropics/anthropic-sdk-typescript/commit/94528226386311c3ade468cbdea0326c06a1e53d">9452822</a>)</li> <li><strong>ci:</strong> choose the CI runner by repository (<a href="https://github.com/anthropics/anthropic-sdk-typescript/commit/33db1ec2e99a415ff98619cf88ddddbf2b7ca7b1">33db1ec</a>)</li> <li><strong>docs:</strong> clarify that stream: true returns the raw event stream (<a href="https://github.com/anthropics/anthropic-sdk-typescript/commit/4286c227c3a605bf04d4f59ffb496f44c102a6ec">4286c22</a>)</li> <li><strong>docs:</strong> make Managed Agents actor descriptions resource-neutral (<a href="https://github.com/anthropics/anthropic-sdk-typescript/commit/15733f98deaae4aee2fba26c1bfe4ee1514c7080">15733f9</a>)</li> <li><strong>docs:</strong> restore the research-preview notice on the Dream type (<a href="https://github.com/anthropics/anthropic-sdk-typescript/commit/b32f8baa27c40ad5901531024bae86e0ca046bb5">b32f8ba</a>)</li> <li><strong>internal:</strong> move old constants around (<a href="https://github.com/anthropics/anthropic-sdk-typescript/commit/0cd8edfdc6dd91af4ffee4ed3cc7fc8cc22d65e3">0cd8edf</a>)</li> <li><strong>tests:</strong> add diagnostics to the parser test's Message fixtures (<a href="https://github.com/anthropics/anthropic-sdk-typescript/commit/eb5ca58d51ed3309b1f317b20f7d248b036ba76a">eb5ca58</a>)</li> <li><strong>tools:</strong> remove client-side compaction control (<a href="https://redirect.github.com/anthropics/anthropic-sdk-typescript/issues/802">#802</a>) (<a href="https://github.com/anthropics/anthropic-sdk-typescript/commit/9c3e8a5ffa38c35dec32f0258becd360babd5fb1">9c3e8a5</a>)</li> </ul> <h3>Documentation</h3> <ul> <li><strong>api:</strong> prefer each field's own description over its shared type's (<a href="https://github.com/anthropics/anthropic-sdk-typescript/commit/51934782720725acca570edeb0a3a7501ca7dbd8">5193478</a>)</li> <li>expand CLAUDE.md into a full contributor guide (<a href="https://github.com/anthropics/anthropic-sdk-typescript/commit/98d2ddbce7c1eabbabe5a130d18d307c237fb75c">98d2ddb</a>)</li> </ul> <h2>0.128.0 (2026-09-22)</h2> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/anthropics/anthropic-sdk-typescript/commit/bf2058689f845dfb10e59bd9ebeb5cb4e9318a9d"><code>bf20586</code></a> Merge pull request <a href="https://redirect.github.com/anthropics/anthropic-sdk-typescript/issues/1218">#1218</a> from anthropics/release-please--branches--main--chan...</li> <li><a href="https://github.com/anthropics/anthropic-sdk-typescript/commit/da41a5a0e5d6f498f1bb8b71beb5b1e0a2bd1e48"><code>da41a5a</code></a> chore: release main</li> <li><a href="https://github.com/anthropics/anthropic-sdk-typescript/commit/3a79b93f0210a83f8bf9fda91a42b577c9e6b93c"><code>3a79b93</code></a> codegen metadata</li> <li><a href="https://github.com/anthropics/anthropic-sdk-typescript/commit/4e7736625fd23a5607800e8de4aa3c37daa74a07"><code>4e77366</code></a> feat(api): add claude-sonnet-5-5</li> <li><a href="https://github.com/anthropics/anthropic-sdk-typescript/commit/2c1d2d712071a5f10d2e70ea02dc33425b087799"><code>2c1d2d7</code></a> feat(api): add ClientToolUnion type for client-executed tools</li> <li><a href="https://github.com/anthropics/anthropic-sdk-typescript/commit/f9d3e980b1b498c1c452300a205811f6a56de69b"><code>f9d3e98</code></a> fix(client): send upload filenames as given, with no placeholder</li> <li><a href="https://github.com/anthropics/anthropic-sdk-typescript/commit/8ac4a26809418453b64fee79f8ec790d32d1f92c"><code>8ac4a26</code></a> feat(api): add typed event type values to the Managed Agents events list filter</li> <li><a href="https://github.com/anthropics/anthropic-sdk-typescript/commit/083969beadb360b9c4b329ee2541f67bd78d9caf"><code>083969b</code></a> feat(tools): optionally start tool calls while the reply streams</li> <li><a href="https://github.com/anthropics/anthropic-sdk-typescript/commit/9505bf37def4a4ada41c95e4e4fa7fb6b3b3f679"><code>9505bf3</code></a> codegen metadata</li> <li><a href="https://github.com/anthropics/anthropic-sdk-typescript/commit/b84783b6ee03eed519d622ea1e477cf8eb3863bf"><code>b84783b</code></a> fix(client): also send X-Stainless-Timeout for client-level timeouts</li> <li>Additional commits viewable in <a href="https://github.com/anthropics/anthropic-sdk-typescript/compare/sdk-v0.121.0...sdk-v0.129.0">compare view</a></li> </ul> </details> <br /> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>canary/v2026.1001.0-canary.10 |
||
|
|
4b2bd6563d |
fix(chat): hide obsolete execution status and system notices (#14874)
## Thinking Path > - Paperclip lets people oversee agent work through task conversations. > - Conversations should show failures and waits that still affect the task. > - Old run errors and recovery notices remained visible after later work or task completion. > - These messages looked current even when no action remained. > - This change hides obsolete execution status while preserving the responses and activity. > - The full diagnostic record stays available in run history. ## Linked Issues or Issue Description **What happened?** Task chat kept showing “Run failed”, “Stopped”, and “Waiting to resume” after the execution had been superseded or the task had finished. Stored system notices also remained in the conversation. Completed tasks disabled Retry but kept the error message. **Expected behavior** Hide system status that no longer applies. Keep the latest unresolved failure, active recovery holds, and useful recovery actions visible. Preserve messages, files, questions, session boundaries, and inspectable activity. **Steps to reproduce** 1. Let a task run fail, then record a pre-start recovery wait. 2. Complete a later attempt or mark the task done. 3. Open the task conversation. Before this change, the old error and wait remain visible. **Paperclip version or commit** Reproduced in component tests against `0f9e9be408`. **Deployment mode** Task chat in local or hosted deployments; both legacy adapters and the native runner. Related: #14857 and #14869 address execution recovery. This PR addresses the remaining conversation presentation. Searched GitHub for historical chat status, historical errors, and “Waiting to resume”; no duplicate PR found. ## What Changed - Determine status relevance from task state, attempt order, successor evidence, and recovery state. Time alone does not hide errors. - Hide obsolete run markers and stored execution notices. Require run or recovery provenance, so unrelated system updates such as child-task blockers remain visible. Keep errors from the latest failed attempt actionable. - Keep unresolved execution holds visible. A refused pre-start retry does not replace a real attempt, and another agent’s work does not resolve a run-specific error. - Show historical activity without Worked/Stopped labels. Keep historical failures out of the current turn’s summary. - Anchor activity to visible comments so removing a notice cannot remove the response or activity with it. - Document the presentation rules and cover both runner modes and both task presentation modes. ## Verification - 334 focused component and status-policy tests passed across four files, including the child-task relay regressions. - `pnpm build` passed. The UI build also passed after the final presentation changes. - `pnpm exec vitest run --project @paperclipai/ui`: 667 files and 7,157 tests passed. Subsequent focused tests cover the final activity-anchor, live-successor, and notice-provenance changes. - `pnpm -r typecheck` passed. UI typecheck and build passed again after the review fix. - `pnpm test:run` completed its general-server phase with 14,716 tests passed, 17 failed, and 87 skipped; it stopped before later phases. The failures occurred in four unchanged server suites: chat channels, email channels, company skills, and runtime skill cache. A targeted rerun reproduced missing bundled skill paths and `EACCES` during cache-directory rename on macOS. All Linux CI suites pass for the final commit, including these server suites. - Design token gates and diff checks pass. - All 53 checks pass on commit `7af9753859`; two optional Storybook checks are skipped. [Final CI run](https://github.com/paperclipai/paperclip/actions/runs/36931968751) includes build, full typecheck, all server and workspace test shards, all eight end-to-end shards, runner verification, and the canary dry run. - Greptile scores the final commit at 5/5. No review threads remain unresolved. The branch is current with `master` and has no merge conflicts. ## Risks This changes presentation only. It does not change execution, recovery, stored comments, or run history. The main risk is hiding a current diagnostic too early. Tests cover active holds, refused retries, different agents, missing timestamps and provenance, live successors, preserved responses, and the current retry target. The base branch has a dependency override/lockfile mismatch. Local installation used the same resolution fallback as CI, then restored the tracked lockfile. No dependency changes are included. ## Model Used OpenAI Codex (GPT-6). The exact runtime model identifier and context window are not exposed in this session. Used reasoning, repository inspection, code execution, and regression tests. ## Checklist - [x] I have included a thinking path that traces from project context to this change - [x] I have specified the model used (with version and capability details) - [x] I have checked ROADMAP.md and confirmed this PR does not duplicate planned core work - [x] I have searched GitHub for duplicate or related PRs and linked them above - [x] I have either (a) linked existing issues with `Fixes: #` / `Closes #` / `Refs #` OR (b) described the issue in-PR following the relevant issue template - [x] I have not referenced internal/instance-local Paperclip issues or links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip` URLs) - [x] My branch name describes the change (e.g. `docs/...`, `fix/...`) and contains no internal Paperclip ticket id or instance-derived details - [ ] I have run tests locally and they pass — changed-code tests pass; unrelated full-suite failures are documented above - [x] I have added or updated tests where applicable - [x] I have updated relevant documentation to reflect my changes - [x] I have considered and documented any risks above - [x] All Paperclip CI gates are green - [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups - [x] I will address all Greptile and reviewer comments before requesting merge --------- Co-authored-by: Paperclip <noreply@paperclip.ing>canary/v2026.1001.0-canary.9 |
||
|
|
2a36e915ef |
build(deps): bump @vercel/connect from 0.6.1 to 2.3.3 (#13390)
Bumps [@vercel/connect](https://github.com/vercel/vercel/tree/HEAD/packages/connect) from 0.6.1 to 2.3.3. <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/vercel/vercel/blob/main/packages/connect/CHANGELOG.md">@vercel/connect's changelog</a>.</em></p> <blockquote> <h1><code>@vercel/connect</code></h1> <h2>2.0.2</h2> <h3>Patch Changes</h3> <ul> <li>c028593: Update the Core SDK documentation to show how to start an authorization request.</li> </ul> <h2>2.0.1</h2> <h3>Patch Changes</h3> <ul> <li>2ecb357: <code>connectGitHubCredentials</code> now resolves the GitHub App slug from the connector's metadata and exposes it as <code>appSlug</code> on the returned credentials, so eve's <code>githubChannel</code> can derive its invocation token (<code>botName</code>) without extra configuration.</li> </ul> <h2>2.0.0</h2> <h3>Major Changes</h3> <ul> <li>42938f9: Make Eve connector provisioning opt-in with <code>autoProvision: true</code>. When enabled, try token and authorization requests before provisioning, then provision and retry once only when the connector is missing or not linked to the project.</li> </ul> <h2>1.1.0</h2> <h3>Minor Changes</h3> <ul> <li>b9fab7c: Add Sendblue credential helpers for Eve-native channels and the Chat SDK adapter, including Connect trigger-forwarded webhook verification for Chat SDK users.</li> </ul> <h2>1.0.0</h2> <h3>Major Changes</h3> <ul> <li>9b55136: Default omitted scopes to <code>['*']</code> in token and authorization requests.</li> </ul> <h3>Minor Changes</h3> <ul> <li>4199902: Send Vercel API requests to the region from <code>VERCEL_REGION</code>, with a <code>region</code> option to override it.</li> </ul> <h2>0.9.0</h2> <h3>Minor Changes</h3> <ul> <li>46a5aaa: Add Linq helpers for Eve and Chat SDK applications. <code>connectLinqCredentials</code> resolves an app-scoped Linq API key, and <code>connectLinqAdapter</code> adds trusted Connect OIDC verification for trigger-forwarded Linq webhooks while retaining the provider signing secret within Connect.</li> </ul> <h2>0.8.1</h2> <h3>Patch Changes</h3> <ul> <li><code>@vercel/oidc</code><a href="https://github.com/3"><code>@3</code></a>.8.5</li> </ul> <h2>0.8.0</h2> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li>See full diff in <a href="https://github.com/vercel/vercel/commits/@now/next@2.3.3/packages/connect">compare view</a></li> </ul> </details> <br /> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>canary/v2026.1001.0-canary.8 |
||
|
|
f2e0f19630 |
Defer agent directory cleanup until stop proof is available (#14866)
## Thinking Path > - Paperclip manages agents and their persistent files. > - Each run owns a temporary agent directory and a save receipt. > - Cleanup needs independent proof that the owning process stopped. > - A cleanup call without that proof currently waits for the directory lock anyway. > - A second lock failure can prevent environment release after the run already reported a failed save. > - This change skips cleanup that has no authority and retries unavailable remote copies after exact destruction proof. > - The save failure stays visible. Existing lock owners remain protected. ## Linked Issues or Issue Description Related work: Refs #14787 (lock diagnostics), #14695 (warm instruction ownership), #9667 (stale lock proposal), and #9872 (control-plane ownership proposal). I checked open PRs and issues. This change leaves the shared filesystem lock protocol in place and does not duplicate the warm-retention work in #14695. **What happened?** Heartbeat cleanup records an explicit unavailable instruction-save warning, then calls directory release before releasing the environment lease. Release can wait for a lock even though the copy has no process-stop proof and cannot be removed. That secondary timeout prevents the following lease-release step. If destruction proof arrives later, the unavailable copy is excluded from both recovery queries. **Expected behavior** Skip a release that cannot remove anything. Preserve the failed-save receipt and candidate fields. Once exact remote destruction is recorded, recover remote cleanup without running a provider command. Unavailable local copies retain their potentially uncollected edits even if local stop proof arrives later. A blocked cleanup must not prevent cleanup for other agents. **Steps to reproduce** 1. Prepare an agent directory, report its save unavailable, and leave process-stop proof absent. 2. Hold the shared directory lock and call release. Before this change, release waits and fails although removal is not authorized. 3. Record destruction of the copy's exact remote lease. Before this change, neither recovery sweep selects the unavailable copy. **Paperclip version or commit** Reproduced against `efc2e6810e9bc0dc8cb412b0e7647c0db9821caa`. **Deployment mode** Local and remote execution with persistent agent directories. Tests use an isolated embedded PostgreSQL database and fixture transports. ## What Changed - Re-read receipts and skip release before lock acquisition when stop proof is absent, the copy is superseded, or cleanup is complete. Keep the same checks inside the lock. - Recover unavailable remote copies only after exact destruction proof. Preserve their unavailable state, errors, candidate hash, and candidate bytes. Keep unavailable local copies and their uncollected edits unchanged. - Store destruction-only cleanup authority with the stop proof. Later cleanup honors it after a lost database response or restart, including when a transport remains cached. - Defer failed or unproven cleanup with bounded batches and a retry delay. Keep failed cleanup visible in logs and its receipt. - Serialize preparation of an existing run with cleanup. Fresh run preparation keeps its existing admission path. - Cover held locks, receipt scope, delayed proof, batch fairness, lost update responses, cached transports, and concurrent same-run preparation with database regressions. ## Verification - Focused directory, legacy instruction-copy, shared lock, and bounded diagnostic suites: 169 tests passed across four files. - `pnpm -r typecheck`: passed on the final source. - `pnpm build`: passed on the final source. - Completed all selected local `pnpm test:run` groups: 733 general server suites, 149 serialized suites, and 14 workspace projects. There are 13 known macOS `EACCES` failures in the unchanged runtime skill cache tests. Their exact signatures match earlier clean-base results, and the cache source and test blobs match both that base and this PR base (existing fix: #14290). One CLI import test timed out under concurrent load; its full file passed separately (17 tests). Broad coverage began before the review corrections; the final source has the focused 169-test run, typecheck, and build. This is a local verification limit, not a passing full local suite. - `git diff --check` and local Gitleaks plus private-identifier/PII diff scans passed. - Independent review of the final source found no remaining actionable issue. Its 17 targeted tests cover crash recovery, cached transports, same-run preparation, real local edit preservation, proof scope, and batch fairness. The main focused run also covers contained scheduling failures. - Final commit `35a24085f7`: Greptile 5/5 with no recommendations and zero unresolved review threads. - Final commit `35a24085f7`: all 53 checks passed, including Canary Dry Run and the security scan; two visual checks were intentionally skipped. The workspace shard passed on retry after GitHub reported that its first runner lost communication. An earlier Canary runner shut down after the release dry run passed. Neither interruption recorded an application assertion failure; the exact final-head checks are now green. ## Risks - This repairs cleanup ordering and recovery eligibility. It does not repair an ambiguous legacy lock owner or restore unsaved files. Actual collection still fails visibly when its lock cannot be acquired. - An unavailable remote copy is recovered only after exact destruction proof. A stopped but retained environment stays protected; recovery does not execute a command that could restart it. - Unavailable local copies with later stop proof still retain potentially uncollected edits. A general local recollection or reclamation policy remains outside this change. - Existing-run preparation now waits for the same lock as cleanup. The fresh-run path is unchanged. - The cleanup mode is stored in the existing private receipt JSON. No schema migration or public API change is required. - No deployment, task replay, or runtime lock deletion was performed. ## Model Used OpenAI GPT-6 (Codex), with reasoning, repository tools, and test execution. The runtime does not expose a more specific model suffix or context-window size. ## Checklist - [x] I have included a thinking path that traces from project context to this change - [x] I have specified the model used (with version and capability details) - [x] I have checked ROADMAP.md and confirmed this PR does not duplicate planned core work - [x] I have searched GitHub for duplicate or related PRs and linked them above - [x] I have either (a) linked existing issues with `Fixes: #` / `Closes #` OR (b) described the issue in-PR following the relevant issue template - [x] I have not referenced internal/instance-local Paperclip issues or links (only public GitHub references) - [x] My branch name describes the change and contains no internal Paperclip ticket id - [ ] I have run tests locally and they pass - [x] I have added or updated tests where applicable - [x] I have updated relevant documentation to reflect my changes - [x] I have considered and documented any risks above - [x] All Paperclip CI gates are green - [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups - [x] I will address all Greptile and reviewer comments before requesting merge --------- Co-authored-by: Paperclip <noreply@paperclip.ing> |
||
|
|
0f9e9be408 |
build(deps): bump @codemirror/state from 6.7.2 to 6.7.6 (#13391)
Bumps [@codemirror/state](https://github.com/codemirror/state) from 6.7.2 to 6.7.6. <details> <summary>Commits</summary> <ul> <li>See full diff in <a href="https://github.com/codemirror/state/commits">compare view</a></li> </ul> </details> <br /> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |
||
|
|
4039d4f06b |
fix(auth): allow scoped low-trust work and owner-chat instruction edits (#14870)
## Thinking Path > - Paperclip is the open source app people use to manage AI agents for work. > - Low-trust agents must work within their assigned scope. > - Task creation currently rejects these agents before checking assignment permission or scope. > - Persistent instruction saves also reject direct requests from authorized chat owners. > - This PR checks the requested action and its recorded authority instead of denying all such work. > - Agents can organize permitted work and follow their owner's instruction-edit requests while outside work stays restricted. ## Linked Issues or Issue Description **What happened?** Low-trust agents cannot create self-assigned tasks or subtasks, even within their allowed scope. An authorized user also cannot ask an agent in their own Agent Chat to update its managed `AGENTS.md`. Agent-folder collection can hide the permission rejection behind a generic save failure. **Expected behavior** Allow task creation when assignment permissions and project or root-task scope permit it. Allow instruction self-edits during authenticated owner-chat execution, subject to the user's current edit permission. Outside tasks, subtasks, connector messages, and peer agents do not inherit that instruction authority. Explain the actual denial when a save fails. **Steps to reproduce** 1. Configure an active agent with `low_trust_review` and a project or root-task boundary. 2. Ask it to create an in-scope task assigned to itself, or a subtask of its own task. 3. As a user with permission to configure that agent, ask it in your Agent Chat to update its managed `AGENTS.md`. 4. Observe blanket permission denials rather than action-specific checks. **Paperclip version or commit** Rebased onto master at `8ec4b84e1`. This is a core authorization change, independent of adapter choice. **Deployment mode** Authenticated server. Regression coverage uses the server services, HTTP routes, native tool authority, and embedded PostgreSQL. Related work: #14775 adds human-directed task execution. #13599 concerns instruction-path configuration; this PR leaves that configuration restricted. #11988 proposes separate active-review instruction protection. #10693 reports unclear authorization denials on a different API surface. ## What Changed - Apply task-assignment checks to both HTTP creation routes and native task creation, including unassigned work. Preserve low-trust policy and source attribution on the created task and its initial plan. - Allow self-assigned decomposition within the permitted project or root-task tree. Resolve workspace-derived project scope before authorization, and reauthorize existing tasks before duplicate detection returns them. Keep cross-project and peer-assignment checks. - Derive instruction self-edit authority from the accepted run identity and authenticated owner-message wake. Recheck current permissions at save time. Bind retries to the same request and chat session. - Reject inherited instruction authority from outside tasks, subtasks, plugins, connectors, stale sessions, cancelled runs, and peer edits. - Surface permission errors in instruction and agent-folder save receipts. Tell chat agents to explain the rejected action and the specific restriction. - Update the low-trust policy and implementation documentation. ## Verification - All 297 tests in 11 focused server suites pass after the rebase. These cover owner-chat saves, private copies, warm agent directories, reset and retry boundaries, permission revocation, task creation routes, and native tool authority. - After review fixes, all 126 tests in the four affected authorization/chat suites pass. Workspace scope regressions and 146 existing creation/ownership/workspace-route tests also pass. - The final duplicate-task and CI fixes pass all 39 tests across chat-project tools, duplicate creation, environment-selection guards, and assignee-invokability routes. The duplicate-task test reproduced an unauthorized response before the fix and verifies denial plus permitted reuse afterward. - `pnpm --filter @paperclipai/server typecheck` passes after rebasing; `pnpm --filter @paperclipai/server exec tsc --noEmit` also passes after the review fixes. - `git diff --check origin/master...HEAD` passes. - Final head `7e73270b86748792649e4ae6fbc6879f73b42b73`: all 54 checks passed, with two expected skips and no pending or failed checks. This includes builds, typechecking, the full test matrix, end-to-end tests, runner verification, the canary dry run, and security scans. - Greptile is 5/5 on that exact head, with no unresolved review threads. This change has not been deployed to staging. ## Risks This changes authorization behavior. The instruction exception must not become an inherited task permission. The check uses server-owned execution records, requires the agent's own chat and instructions, and keeps normal protected-change and responsible-user checks. Saves fail closed when current provenance or permission is missing. Owner chat grants a turn-scoped capability; the server does not classify the message intent or require approval of the exact new file bytes. Prompt injection within an authorized owner-chat turn remains a model-level risk. This is the requested owner-chat trust boundary, without a new per-edit confirmation flow. No database migration or broad trust-preset change is required. ## Model Used OpenAI Codex, based on GPT-6, with reasoning, code editing, shell tools, and test execution. The exact runtime model ID and context-window size are not exposed in this session. ## Checklist - [x] I have included a thinking path that traces from project context to this change - [x] I have specified the model used (with version and capability details) - [x] I have checked ROADMAP.md and confirmed this PR does not duplicate planned core work - [x] I have searched GitHub for duplicate or related PRs and linked them above - [x] I have either (a) linked existing issues with `Fixes: #` / `Closes #` / `Refs #` OR (b) described the issue in-PR following the relevant issue template - [x] I have not referenced internal/instance-local Paperclip issues or links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip` URLs) - [x] My branch name describes the change (e.g. `docs/...`, `fix/...`) and contains no internal Paperclip ticket id or instance-derived details - [x] I have run tests locally and they pass - [x] I have added or updated tests where applicable - [x] I have updated relevant documentation to reflect my changes - [x] I have considered and documented any risks above - [x] All Paperclip CI gates are green - [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups - [x] I will address all Greptile and reviewer comments before requesting merge --------- Co-authored-by: Paperclip <noreply@paperclip.ing> |
||
|
|
e2d4f07207 |
build(deps): bump googleapis from 176.0.0 to 182.0.0 (#13393)
Bumps [googleapis](https://github.com/googleapis/google-api-nodejs-client) from 176.0.0 to 182.0.0. <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/googleapis/google-api-nodejs-client/commit/9eb464beb4310053dec5aef4661d6c6fd73051a8"><code>9eb464b</code></a> chore: release main (<a href="https://redirect.github.com/googleapis/google-api-nodejs-client/issues/4023">#4023</a>)</li> <li><a href="https://github.com/googleapis/google-api-nodejs-client/commit/9e3b4655c95fde3c69d2a44496a586e906695734"><code>9e3b465</code></a> feat: regenerate index files</li> <li><a href="https://github.com/googleapis/google-api-nodejs-client/commit/279af87fcf2c4016321bde793a8cefd1a542615d"><code>279af87</code></a> fix(youtubereporting): update the API</li> <li><a href="https://github.com/googleapis/google-api-nodejs-client/commit/b37c22595087460ffc1be63471bb56e3e81675f5"><code>b37c225</code></a> fix(youtubeAnalytics): update the API</li> <li><a href="https://github.com/googleapis/google-api-nodejs-client/commit/512e921970a8556fc20aef5e7766826107018957"><code>512e921</code></a> fix(youtube): update the API</li> <li><a href="https://github.com/googleapis/google-api-nodejs-client/commit/6cd997a07c55c80a3f3070cea06affd0aa3274c9"><code>6cd997a</code></a> fix(workstations): update the API</li> <li><a href="https://github.com/googleapis/google-api-nodejs-client/commit/62d5f7629a9ddd6523b4f4050c955a2063007fce"><code>62d5f76</code></a> fix(workspaceevents): update the API</li> <li><a href="https://github.com/googleapis/google-api-nodejs-client/commit/0d71cd6b01ed41b1dff0a04d85567cfd2a511495"><code>0d71cd6</code></a> feat(workloadmanager): update the API</li> <li><a href="https://github.com/googleapis/google-api-nodejs-client/commit/2c46e13798ba24a8b4d2ad9e92f7995d7dcdd93e"><code>2c46e13</code></a> fix(workflows): update the API</li> <li><a href="https://github.com/googleapis/google-api-nodejs-client/commit/c7b8641390370d9af9b12154e6bf455bc344feaa"><code>c7b8641</code></a> fix(workflowexecutions): update the API</li> <li>Additional commits viewable in <a href="https://github.com/googleapis/google-api-nodejs-client/compare/googleapis-v176.0.0...googleapis-v182.0.0">compare view</a></li> </ul> </details> <br /> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>canary/v2026.1001.0-canary.7 |
||
|
|
d91eceb575 |
chore(deps): bump actions/github-script from 8.0.0 to 9.0.0 (#13471)
Bumps [actions/github-script](https://github.com/actions/github-script) from 8.0.0 to 9.0.0. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/actions/github-script/releases">actions/github-script's releases</a>.</em></p> <blockquote> <h2>v9.0.0</h2> <p><strong>New features:</strong></p> <ul> <li><strong><code>getOctokit</code> factory function</strong> — Available directly in the script context. Create additional authenticated Octokit clients with different tokens for multi-token workflows, GitHub App tokens, and cross-org access. See <a href="https://github.com/actions/github-script#creating-additional-clients-with-getoctokit">Creating additional clients with <code>getOctokit</code></a> for details and examples.</li> <li><strong>Orchestration ID in user-agent</strong> — The <code>ACTIONS_ORCHESTRATION_ID</code> environment variable is automatically appended to the user-agent string for request tracing.</li> </ul> <p><strong>Breaking changes:</strong></p> <ul> <li><strong><code>require('@actions/github')</code> no longer works in scripts.</strong> The upgrade to <code>@actions/github</code> v9 (ESM-only) means <code>require('@actions/github')</code> will fail at runtime. If you previously used patterns like <code>const { getOctokit } = require('@actions/github')</code> to create secondary clients, use the new injected <code>getOctokit</code> function instead — it's available directly in the script context with no imports needed.</li> <li><code>getOctokit</code> is now an injected function parameter. Scripts that declare <code>const getOctokit = ...</code> or <code>let getOctokit = ...</code> will get a <code>SyntaxError</code> because JavaScript does not allow <code>const</code>/<code>let</code> redeclaration of function parameters. Use the injected <code>getOctokit</code> directly, or use <code>var getOctokit = ...</code> if you need to redeclare it.</li> <li>If your script accesses other <code>@actions/github</code> internals beyond the standard <code>github</code>/<code>octokit</code> client, you may need to update those references for v9 compatibility.</li> </ul> <h2>What's Changed</h2> <ul> <li>Add ACTIONS_ORCHESTRATION_ID to user-agent string by <a href="https://github.com/Copilot"><code>@Copilot</code></a> in <a href="https://redirect.github.com/actions/github-script/pull/695">actions/github-script#695</a></li> <li>ci: use deployment: false for integration test environments by <a href="https://github.com/salmanmkc"><code>@salmanmkc</code></a> in <a href="https://redirect.github.com/actions/github-script/pull/712">actions/github-script#712</a></li> <li>feat!: add getOctokit to script context, upgrade <code>@actions/github</code> v9, <code>@octokit/core</code> v7, and related packages by <a href="https://github.com/salmanmkc"><code>@salmanmkc</code></a> in <a href="https://redirect.github.com/actions/github-script/pull/700">actions/github-script#700</a></li> </ul> <h2>New Contributors</h2> <ul> <li><a href="https://github.com/Copilot"><code>@Copilot</code></a> made their first contribution in <a href="https://redirect.github.com/actions/github-script/pull/695">actions/github-script#695</a></li> </ul> <p><strong>Full Changelog</strong>: <a href="https://github.com/actions/github-script/compare/v8.0.0...v9.0.0">https://github.com/actions/github-script/compare/v8.0.0...v9.0.0</a></p> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/actions/github-script/commit/3a2844b7e9c422d3c10d287c895573f7108da1b3"><code>3a2844b</code></a> Merge pull request <a href="https://redirect.github.com/actions/github-script/issues/700">#700</a> from actions/salmanmkc/expose-getoctokit + prepare re...</li> <li><a href="https://github.com/actions/github-script/commit/ca10bbdd1a7739de09e99a200c7a59f5d73a4079"><code>ca10bbd</code></a> fix: use <code>@octokit/core/</code>types import for v7 compatibility</li> <li><a href="https://github.com/actions/github-script/commit/86e48e20ac85c970ed1f96e718fd068173948b7b"><code>86e48e2</code></a> merge: incorporate main branch changes</li> <li><a href="https://github.com/actions/github-script/commit/c1084728b5b935ec4ddc1e4cee877b01797b3ff9"><code>c108472</code></a> chore: rebuild dist for v9 upgrade and getOctokit factory</li> <li><a href="https://github.com/actions/github-script/commit/afff112e4f8b57c718168af75b89ce00bc8d091d"><code>afff112</code></a> Merge pull request <a href="https://redirect.github.com/actions/github-script/issues/712">#712</a> from actions/salmanmkc/deployment-false + fix user-ag...</li> <li><a href="https://github.com/actions/github-script/commit/ff8117e5b78c415f814f39ad6998f424fee7b817"><code>ff8117e</code></a> ci: fix user-agent test to handle orchestration ID</li> <li><a href="https://github.com/actions/github-script/commit/81c6b7876079abe10ff715951c9fc7b3e1ab389d"><code>81c6b78</code></a> ci: use deployment: false to suppress deployment noise from integration tests</li> <li><a href="https://github.com/actions/github-script/commit/3953caf8858d318f37b6cc53a9f5708859b5a7b7"><code>3953caf</code></a> docs: update README examples from <a href="https://github.com/v8"><code>@v8</code></a> to <a href="https://github.com/v9"><code>@v9</code></a>, add getOctokit docs and v9 brea...</li> <li><a href="https://github.com/actions/github-script/commit/c17d55b90dcdb3d554d0027a6c180a7adc2daf78"><code>c17d55b</code></a> ci: add getOctokit integration test job</li> <li><a href="https://github.com/actions/github-script/commit/a047196d9a02fe92098771cafbb98c2f1814e408"><code>a047196</code></a> test: add getOctokit integration tests via callAsyncFunction</li> <li>Additional commits viewable in <a href="https://github.com/actions/github-script/compare/ed597411d8f924073f98dfc5c65a23a2325f34cd...3a2844b7e9c422d3c10d287c895573f7108da1b3">compare view</a></li> </ul> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |
||
|
|
793a98cd8c |
chore(deps): bump open from 11.0.1 to 11.0.4 (#13473)
Bumps [open](https://github.com/sindresorhus/open) from 11.0.1 to 11.0.4. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/sindresorhus/open/releases">open's releases</a>.</em></p> <blockquote> <h2>v11.0.4</h2> <ul> <li>Fix <code>browser</code>/<code>browserPrivate</code> not detecting Safari or Brave as the default browser 6ae6196</li> </ul> <hr /> <p><a href="https://github.com/sindresorhus/open/compare/v11.0.3...v11.0.4">https://github.com/sindresorhus/open/compare/v11.0.3...v11.0.4</a></p> <h2>v11.0.3</h2> <ul> <li>Fix Windows launches being killed when the parent process exits 734b821</li> </ul> <hr /> <p><a href="https://github.com/sindresorhus/open/compare/v11.0.2...v11.0.3">https://github.com/sindresorhus/open/compare/v11.0.2...v11.0.3</a></p> <h2>v11.0.2</h2> <ul> <li>Update dependencies 6f006ad</li> </ul> <hr /> <p><a href="https://github.com/sindresorhus/open/compare/v11.0.1...v11.0.2">https://github.com/sindresorhus/open/compare/v11.0.1...v11.0.2</a></p> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/sindresorhus/open/commit/41511103abd932225b605b8e7f9e565cc180b1b6"><code>4151110</code></a> 11.0.4</li> <li><a href="https://github.com/sindresorhus/open/commit/6ae6196fa199cbc5eb4af007efd52e675c53b590"><code>6ae6196</code></a> Fix <code>browser</code>/<code>browserPrivate</code> not detecting Safari or Brave as the default b...</li> <li><a href="https://github.com/sindresorhus/open/commit/81deafb72a29ea16b2c3bdd30cdaf294aaa11d77"><code>81deafb</code></a> 11.0.3</li> <li><a href="https://github.com/sindresorhus/open/commit/734b821c36ee959dc11e380c3202770969347274"><code>734b821</code></a> Fix Windows launches being killed when the parent process exits</li> <li><a href="https://github.com/sindresorhus/open/commit/ccf1fd644de3dfc9448438e185037eceb2d5d3d7"><code>ccf1fd6</code></a> 11.0.2</li> <li><a href="https://github.com/sindresorhus/open/commit/52d2d62d6f02f023720f4ca5a2f73bf050ae3ee7"><code>52d2d62</code></a> Use <code>hasOwn</code> (<a href="https://redirect.github.com/sindresorhus/open/issues/372">#372</a>)</li> <li><a href="https://github.com/sindresorhus/open/commit/6f006ad1a80950ff0dd9eb7e3252634153e3ef12"><code>6f006ad</code></a> Update dependencies</li> <li>See full diff in <a href="https://github.com/sindresorhus/open/compare/v11.0.1...v11.0.4">compare view</a></li> </ul> </details> <br /> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |
||
|
|
b721d24cac |
fix(adapter-utils): retry GitHub broker transport failures before falling back (#14856)
## Thinking Path > - Paperclip is the open source app people use to manage AI agents for work > - Agents run `git` and `gh` through a managed launcher. The launcher gets a GitHub credential from the Paperclip control plane > - The launcher sends one request to the credential broker for each command > - If that request fails at the transport level, for example after a 10-second timeout, the launcher continues without managed credentials > - So a slow or restarting control plane removes the managed GitHub identity from that command. Some agents then use other GitHub identities that do not have the necessary permissions > - This pull request retries a failed broker request two more times, with a short backoff, before the launcher gives up > - The benefit is that a short control-plane delay does not remove the managed identity from an agent's GitHub operation ## Linked Issues or Issue Description Refs #14175. That pull request changes the same broker request loop for a different failure: sandbox network denials. The pull request that merges second must rebase. **What happened** A Codex agent ran `git` and `gh` through the managed launcher while the control plane was under heavy memory pressure. Each command printed `Paperclip: GitHub broker_transport_unavailable; continuing without managed credentials.` The agent then tried to open the pull request through a different GitHub integration. GitHub rejected the request with `403 Resource not accessible by integration`. **Expected behavior** A short broker delay or a short transport failure must not remove the managed GitHub identity from the command. The launcher must try the broker again before it continues without credentials. **Steps to reproduce** 1. Set `PAPERCLIP_GITHUB_BROKER_URL` to a closed port. 2. Start a broker on that port after about 300 ms. 3. Run `gh` through the launcher. 4. Before this change, the launcher prints `broker_transport_unavailable` and runs `gh` without the managed token. **Version or commit** `4ac374103` on master. Commit `3166e93a7` has the same code. **Deployment mode** Local trusted instance that runs as a launchd service, with `codex_local` agents. ## What Changed - `packages/adapter-utils/src/github-launcher.ts`: the broker request loop now catches transport errors and retries up to two more times, after 0.5 s and then after 1 s. The loop reads the response body inside the retry, so a failed or slow body read is also retried. Busy (409) responses keep their own budget of 30 attempts, separate from transport retries. After the third transport failure, the launcher prints `broker_transport_unavailable` as before. - `packages/adapter-utils/src/github-launcher.test.ts`: two new tests make the broker fail the first request and answer the second. In one, the connection drops before the response. In the other, the connection drops in the middle of the body. Each test checks that `gh` gets the managed token, that the broker receives exactly two requests, and that no `broker_transport_unavailable` message appears. - The existing `broker-offline` test now has a 15-second timeout, because each command now retries twice before it falls back. ## Verification - `npx vitest run packages/adapter-utils/src/github-launcher.test.ts`: 9 of 9 tests pass. - The body-read test fails on the first commit of this pull request and passes with the second commit. - `pnpm --filter @paperclipai/adapter-utils typecheck`: passes. - The existing `broker-offline` test confirms that the launcher still falls back after the retries, and that local Git still works. ## Risks - When the broker is unreachable, each `git` or `gh` command now waits about 1.5 s more before it continues without credentials. When the broker times out, the worst case is about 31.5 s instead of 10 s. - The change only adds retries. It does not change which credentials the launcher accepts or which environment variables it copies. - #14175 changes the same loop. The pull request that merges second needs a small rebase. > For core feature work, check [`ROADMAP.md`](ROADMAP.md) first and discuss it in `#dev` before opening the PR. Feature PRs that overlap with planned core work may need to be redirected — check the roadmap first. See `CONTRIBUTING.md`. ## Model Used - Anthropic Claude Opus 5.5 (`claude-opus-5-5`), used through Claude Code with tool use: shell commands, file edits and test runs. The model wrote the change, the test and this description. The repository owner approved the change before it was made. ## Checklist - [x] I have included a thinking path that traces from project context to this change - [x] I have specified the model used (with version and capability details) - [x] I have checked ROADMAP.md and confirmed this PR does not duplicate planned core work - [x] I have searched GitHub for duplicate or related PRs and linked them above - [x] I have either (a) linked existing issues with `Fixes: #` / `Closes #` / `Refs #` OR (b) described the issue in-PR following the relevant issue template - [x] I have not referenced internal/instance-local Paperclip issues or links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip` URLs) - [x] My branch name describes the change (e.g. `docs/...`, `fix/...`) and contains no internal Paperclip ticket id or instance-derived details - [x] I have run tests locally and they pass — *targeted tests and the package typecheck; see Verification* - [x] I have added or updated tests where applicable - [ ] I have updated relevant documentation to reflect my changes — *no documentation describes the broker retry* - [x] I have considered and documented any risks above - [ ] All Paperclip CI gates are green — *CI has not run yet* - [ ] Greptile is 5/5 with no open P2s, recommendations, or follow-ups — *Greptile has not reviewed yet* - [x] I will address all Greptile and reviewer comments before requesting merge 🤖 Generated with [Claude Code](https://claude.com/claude-code) --------- Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com> |
||
|
|
8ec4b84e1c |
fix(chat): resume messages after failed runs without duplicate delivery (#14857)
## Thinking Path > - Paperclip is the open source app people use to manage AI agents for work. > - A user can send a new message after a native run fails. > - The server checks that the old execution has stopped before it starts a fresh turn. > - A failed run can retain a result accepted before checkpoint or cleanup failed. > - The continuation gate treated that saved result as active recovery and held the new message forever. > - This pull request removes that false liveness signal while retaining controller, process, environment, and authorization checks. > - Live staging then exposed a second defect: chat admission created a successor without consuming the original deferred receipt, so completion delivered the message again. > - Consume that exact receipt atomically with admission, while preserving separate turns for later chat messages. ## Linked Issues or Issue Description **What happened?** A new user message stayed in the queue with `controller_settling` after the previous run had reached `terminal_failure`. The old coordinator had no lease owner but still had a `resultId`. Its remote environment had a verified stop receipt. **Expected behavior** Start one fresh turn after execution has stopped and normal admission checks pass. Preserve the failed run and its accepted result as history. **Steps to reproduce** 1. Accept a native result, then fail checkpoint or cleanup and exhaust recovery. 2. Retain the result ID on the terminal failure record and stop the execution environment. 3. Send a new user message. Before this fix, it waits forever for the finished controller. **Paperclip version or commit** Reproduced in a database-backed regression test on `26900655b`. **Deployment mode** Server with a native runner and remote sandbox. Local process stop checks also apply. Related: https://github.com/paperclipai/paperclip/pull/14775. Searched existing PRs for retained-result continuation fixes; no duplicate found. ## What Changed - Remove the retained-result veto for terminal failures. - Keep controller ownership, successor, process, environment cleanup, pending decision, and ordinary admission checks. - Add regressions for retained results, active execution, missing stop evidence, and delayed remote cleanup. - Atomically consume the resumed receipt in agent chat, even though chat does not coalesce other queued messages. - Reproduce completion-time duplicate promotion, race cleanup against periodic recovery, and prove a subsequent chat message keeps its own turn. - Document that a saved result does not make a terminal failure active. - Keep exhausted workspace export on its separate repair path, tested through the production finalizer. ## Verification - Red: retained-result admission failed with `controller_settling` before the original fix. The new chat-specific regression then reproduced duplicate promotion when the first reply finished. - Green: 406 tests across native continuation, workspace-export recovery, and the wake-queue module passed on `cbc531cc0`. - The chat regressions exercise real Postgres transactions, simultaneous recovery callbacks, successful completion, the production queue-drain use case, and repeated drain attempts. A distinct follow-up remains a separate turn. - `pnpm -r typecheck` and `pnpm build` passed on `cbc531cc0`. - The earlier full local test run encountered a timeout and follow-on failure in unchanged AI connection-adoption tests; all 50 tests passed on isolated rerun. That local run was stopped after the full CI test matrix passed on the earlier head. - All 54 CI checks passed on `cbc531cc0` (2 skipped), including the full test matrix and browser shards. One unchanged interaction-route test returned HTTP 500 on its first CI attempt; its full 84-test file passed locally, and the failed shard passed on one targeted rerun. - Greptile reviewed `cbc531cc0`: 5/5, no unresolved findings. - Live staging first verified that the original saved message resumes and receives a successful response; that test exposed the duplicate now covered above. - Deployed exact commit `cbc531cc0410e1ef6e8811c6c5c014c3528351ed` to the affected staging workspace; deployment verification, health, authentication, and startup recovery passed. - Submitted a fresh message through the browser. The agent replied in 39 seconds; server records show exactly one successful run, native phase `committed`, no error, and an empty queue. A later check more than a minute after completion found no duplicate run. ## Risks The change affects admission after native execution failure and consumption of a resumed deferred receipt. A fresh turn must never overlap the prior execution, and consuming one chat receipt must not absorb later messages. Tests retain the controller, process, and remote-stop guards. This change does not migrate data, apply an old result, or reset the old retry budget. ## Model Used OpenAI Codex (GPT-6). The exact runtime model identifier and context window are not exposed in this session. Used reasoning, repository inspection, code execution, database-backed tests, and browser inspection. ## Checklist - [x] I have included a thinking path that traces from project context to this change - [x] I have specified the model used (with version and capability details) - [x] I have checked ROADMAP.md and confirmed this PR does not duplicate planned core work - [x] I have searched GitHub for duplicate or related PRs and linked them above - [x] I have either (a) linked existing issues with `Fixes: #` / `Closes #` / `Refs #` OR (b) described the issue in-PR following the relevant issue template - [x] I have not referenced internal/instance-local Paperclip issues or links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip` URLs) - [x] My branch name describes the change (e.g. `docs/...`, `fix/...`) and contains no internal Paperclip ticket id or instance-derived details - [x] I have run tests locally and they pass - [x] I have added or updated tests where applicable - [x] I have updated relevant documentation to reflect my changes - [x] I have considered and documented any risks above - [x] All Paperclip CI gates are green - [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups - [x] I will address all Greptile and reviewer comments before requesting merge --------- Co-authored-by: Paperclip <noreply@paperclip.ing>canary/v2026.1001.0-canary.6 |
||
|
|
dd9983b894 |
fix(adapter-utils): release restore locks when a process crashes (#14869)
## Thinking Path > - Paperclip is the open source app people use to manage AI agents for work. > - Agent runs restore workspace files and collect instruction-file changes. > - Writers to the same target directory must wait for each other. > - The current lock records a PID, which a new process can reuse after a crash. > - A reused PID can keep an orphaned lock alive and make each later run fail. > - This pull request makes a SQLite file lock decide ownership. The OS releases it when the process exits. > - Later runs can proceed after a crash, and concurrent live writers remain protected. ## Linked Issues or Issue Description Refs #10914. This addresses crash recovery. It does not cancel a stalled operation in a process that is still alive. Related work: #9667, #14787, and #12187. The earlier attempt in #9667 assumes one live server per lock root. This implementation uses an OS-backed lock to support concurrent writers without treating a different process token or an old timestamp as proof of a dead owner. It retains the private lock root and bounded timeout diagnostics from the merged changes. After a process dies while holding a restore lock, a replacement process can reuse its PID. The existing `process.kill(pid, 0)` check then reports a live owner forever. Later runs can complete their model turn but fail during file collection or restore. ## What Changed - Hold a SQLite `BEGIN IMMEDIATE` transaction for each directory write. Use the existing built-in `node:sqlite` dependency. - Keep each lock database on a stable inode. Keep PID and time metadata only for diagnostics. - Retain the 30-second asynchronous wait and existing timeout error code and diagnostic fields. - Fail closed when an old directory lock exists. Document a stopped-writer upgrade and rollback procedure. - Add real child-process tests for crashes, PID reuse, live owners, and connection cleanup. Cover callback failures, independent targets, stable inodes, invalid lock files, and ambiguous legacy records. ## Verification - Before the fix, the crash/PID-reuse test and the live-owner test both failed. Both pass with this change. - `pnpm exec vitest run packages/adapter-utils/src/directory-merge-lock.test.ts packages/adapter-utils/src/workspace-restore-merge.test.ts`: 56 tests passed. - Restore and agent-file working-copy integration tests: 118 tests passed before the additional connection-cleanup test. - `pnpm -r typecheck`: passed. - `pnpm build`: passed. - Full GitHub CI: all checks passed, including Linux workspace tests, server test shards, build, typecheck, and browser tests. - Greptile: 5/5, with no review threads or unresolved comments. - `pnpm test:run`: started locally, then stopped with SIGINT (exit 130) after full CI passed. The local serial run did not complete and is not counted as a full local pass. The completed CI shards provide the full-suite result. ## Risks - **Upgrade and rollback require a drain.** Stop every old writer that shares an instance root before switching protocols. Old and new versions must not write concurrently. - Existing legacy `.lock/` directories remain blocking. After all writers stop, preserve run evidence and move those directories to an operator scratch directory. The new code does not infer that they are abandoned from PID or age. - Never delete or replace a `.lock.sqlite` file while writers can run. These small files remain after release. - The shared filesystem must support reliable SQLite locking. Broken network-filesystem locking is unsupported. - This change prevents new orphaned ownership. It does not recover file changes lost during earlier failed collections, or interrupt a live operation that stalls. - No application database migration or new native dependency is required. See `doc/workspace-restore-locks.md` for the procedure. ## Model Used OpenAI Codex based on GPT-6, with code execution and repository tools. The exact model variant and context window are not exposed in this session. ## Checklist - [x] I have included a thinking path that traces from project context to this change - [x] I have specified the model used (with version and capability details) - [x] I have checked ROADMAP.md and confirmed this PR does not duplicate planned core work - [x] I have searched GitHub for duplicate or related PRs and linked them above - [x] I have either (a) linked existing issues with `Fixes: #` / `Closes #` / `Refs #` OR (b) described the issue in-PR following the relevant issue template - [x] I have not referenced internal/instance-local Paperclip issues or links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip` URLs) - [x] My branch name describes the change (e.g. `docs/...`, `fix/...`) and contains no internal Paperclip ticket id or instance-derived details - [x] I have run tests locally and they pass (focused regression and integration suites; see the full-suite note above) - [x] I have added or updated tests where applicable - [x] I have updated relevant documentation to reflect my changes - [x] I have considered and documented any risks above - [x] All Paperclip CI gates are green - [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups - [x] I will address all Greptile and reviewer comments before requesting merge Co-authored-by: Paperclip <noreply@paperclip.ing>canary/v2026.1001.0-canary.5 |
||
|
|
8f7baf2f72 |
chore(deps): bump @aws-sdk/client-s3 from 3.1122.0 to 3.1141.0 (#13475)
Bumps [@aws-sdk/client-s3](https://github.com/aws/aws-sdk-js-v3/tree/HEAD/clients/client-s3) from 3.1122.0 to 3.1141.0. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/aws/aws-sdk-js-v3/releases">@aws-sdk/client-s3's releases</a>.</em></p> <blockquote> <h2>v3.1141.0</h2> <h4>3.1141.0(2026-09-25)</h4> <h5>Chores</h5> <ul> <li><strong>codegen:</strong> smithy-aws-typescript-codegen 0.54.0 (<a href="https://redirect.github.com/aws/aws-sdk-js-v3/pull/8314">#8314</a>) (<a href="https://github.com/aws/aws-sdk-js-v3/commit/ad80ce3ebaf394679aabc6e26b2dcd023ce8e010">ad80ce3e</a>)</li> </ul> <h5>New Features</h5> <ul> <li><strong>client-connect:</strong> Agent Privacy During Hold is a new privacy capability for Amazon Connect Voice that prevents agent audio from being captured in call recordings or Contact Lens conversational analytics during hold. When enabled, agents are automatically muted on entering hold and unmuted on resuming the contact (<a href="https://github.com/aws/aws-sdk-js-v3/commit/03527f9ea153365c1e3654ac6d3f3e064d06b5d0">03527f9e</a>)</li> <li><strong>client-qconnect:</strong> Release shapes for the proactive agentic recommendations and the multi-knowledge base search features. Increases the maximum length of QuickResponseContent. (<a href="https://github.com/aws/aws-sdk-js-v3/commit/e008332b0b70c55d22dfca8a9c2317b67d06a5f3">e008332b</a>)</li> <li><strong>client-bedrock-agent:</strong> Adds support for calling VPC configuration API's in Bedrock. These configurations allow the use of On Prem connectors in Bedrock Managed Knowledge bases (<a href="https://github.com/aws/aws-sdk-js-v3/commit/18524dc69cf36ebbb8bc7bc33e0bce6311dcdb23">18524dc6</a>)</li> <li><strong>client-mediaconnect:</strong> This release adds support for RTMP push router outputs in AWS Elemental MediaConnect. (<a href="https://github.com/aws/aws-sdk-js-v3/commit/5bd8d80bbca2c1c2545521b03d741b46fccd09b4">5bd8d80b</a>)</li> <li><strong>client-securityagent:</strong> This release adds the ListActorMessages operation, which returns the multi-factor authentication messages received at an actor's server-generated email address (<a href="https://github.com/aws/aws-sdk-js-v3/commit/10e53d506db74c48b09b94d9b9387b84dd40ed58">10e53d50</a>)</li> <li><strong>client-arc-region-switch:</strong> Adds a service quota checker to Region switch to verify quota parity between your primary and standby Region, and automatically submit quota limit increases. Adds an optional EC2 Auto Scaling and ECS setting that waits for instances or tasks in the scaled-up Region to be healthy in target groups. (<a href="https://github.com/aws/aws-sdk-js-v3/commit/cca33e380a8985e23a0e3fbb420577aab4b60ac7">cca33e38</a>)</li> <li><strong>client-bedrock-agentcore-control:</strong> Amazon Bedrock AgentCore Payments now supports credential rotation for payment connectors, letting you rotate API and wallet secrets for Quick Create payment auths from the console. This release also adds Type and Creation type columns to the payment managers views. (<a href="https://github.com/aws/aws-sdk-js-v3/commit/adca591f07c448603de2876faaf7914cad441436">adca591f</a>)</li> <li><strong>client-neptune-graph:</strong> Add GraphIdentifier filter for ListImportTasks (<a href="https://github.com/aws/aws-sdk-js-v3/commit/9b9aea9b553ba84f006f95da5d8ffd5381cc8a17">9b9aea9b</a>)</li> <li><strong>client-rekognition:</strong> This release adds support for Feedback and Metadata in the GetFaceLivenessSessionResults response. Feedback returns codes explaining why a Face Liveness check produced its result. Metadata includes the client SDK type. (<a href="https://github.com/aws/aws-sdk-js-v3/commit/0831c361bb69d44357ff57360db39afdbb149337">0831c361</a>)</li> <li><strong>client-glue:</strong> add support for table level federation (<a href="https://github.com/aws/aws-sdk-js-v3/commit/a44458b77853cbb25a9fcb362b0a275d7dc1c69b">a44458b7</a>)</li> <li><strong>client-wellarchitected:</strong> This change releases the Well-Architected Agent, a generative AI service that analyzes a customer's AWS environment and delivers personalized, prioritized recommendations across cost, security, performance, and resilience. (<a href="https://github.com/aws/aws-sdk-js-v3/commit/d0656586067f70b8d50000300f04512dd089df96">d0656586</a>)</li> </ul> <hr /> <p>For list of updated packages, view <strong>updated-packages.md</strong> in <strong>assets-3.1141.0.zip</strong></p> <h2>v3.1140.0</h2> <h4>3.1140.0(2026-09-24)</h4> <h5>Documentation Changes</h5> <ul> <li><strong>client-route53resolver:</strong> Documentation updates for Route 53 Resolver. Clarifies which Outpost Resolver operations apply to first-generation AWS Outposts and that Resolver is managed automatically on second-generation Outposts. Adds Local Network Interface subnet compatibility notes for Resolver endpoints. (<a href="https://github.com/aws/aws-sdk-js-v3/commit/b4432abaaaf19bf4ac5d4d2b09bcc83e4d5440a0">b4432aba</a>)</li> <li><strong>client-iot:</strong> Fixed ListV2LoggingLevels and DeleteV2LoggingLevel documentation to include all supported target-types (<a href="https://github.com/aws/aws-sdk-js-v3/commit/4dcf76d527e0c1fe76d64cb8ea444ce62d64135b">4dcf76d5</a>)</li> </ul> <h5>New Features</h5> <ul> <li><strong>clients:</strong> update client endpoints as of 2026-09-24 (<a href="https://github.com/aws/aws-sdk-js-v3/commit/29a8566cb4c6eeb0cc554f4ae9bf985160556523">29a8566c</a>)</li> <li><strong>client-eventbridgev2:</strong> Introducing Amazon EventBridge enhanced Custom event bus, a new shareable event bus for organizational-scale event-driven applications feature ordered delivery, deduplication, open event formats, and cross-account bus sharing. (<a href="https://github.com/aws/aws-sdk-js-v3/commit/69fbe6a22fd7810332b0b0356803a0eee3f563cf">69fbe6a2</a>)</li> <li><strong>client-datazone:</strong> Amazon DataZone now supports the TOOLING blueprint category on CreateEnvironmentBlueprint, UpdateEnvironmentBlueprint, GetEnvironmentBlueprint, and ListEnvironmentBlueprints, for custom tooling blueprints. CreateConnection now accepts roleArn in iamProperties. (<a href="https://github.com/aws/aws-sdk-js-v3/commit/591cd6f5a7b714427cbe87b36b13357d560d48ea">591cd6f5</a>)</li> <li><strong>client-elasticache:</strong> Added tagging support for ElastiCache Global DataStore. (<a href="https://github.com/aws/aws-sdk-js-v3/commit/0fa9da5946312f09942dad6f711885855f0d0b8e">0fa9da59</a>)</li> <li><strong>client-marketplace-discovery:</strong> AWS Marketplace Discovery API now supports localized responses and SigV4a request signing. It returns new fulfillment details, including AMI architecture, EBS volume and security group information, SaaS quick-launch status, and SageMaker input and output MIME types. (<a href="https://github.com/aws/aws-sdk-js-v3/commit/510673e376bbc578d318308136ecb5a841416bc3">510673e3</a>)</li> <li><strong>client-redshift-data:</strong> Updates to the ListDatabases and WorkgroupName validation (<a href="https://github.com/aws/aws-sdk-js-v3/commit/218c24e106efe1ad64658984123af6634fc7278d">218c24e1</a>)</li> <li><strong>client-securityagent:</strong> Added support for Confluence export, enabling customers to publish security findings to Confluence pages. (<a href="https://github.com/aws/aws-sdk-js-v3/commit/81408527778af52f0c604a4eaca440f445082f78">81408527</a>)</li> <li><strong>client-cloudwatch:</strong> This release adds Create, Get, Update, and DeleteResourceMetricsConfiguration to enable detailed metric collection for an AWS resource, and adds UpdateOTelEnrichment plus include and exclude filters on StartOTelEnrichment so you can choose which metric namespaces CloudWatch enriches. (<a href="https://github.com/aws/aws-sdk-js-v3/commit/765cc1ce8f95a4f62d83dc07b81a927d74e09b52">765cc1ce</a>)</li> <li><strong>client-eventbridge:</strong> Adds a ManagedBy field to the DescribeEventBus and ListEventBuses responses, identifying the AWS service that created an event bus on your behalf. (<a href="https://github.com/aws/aws-sdk-js-v3/commit/28a639b27585c85376a4b5db528c31efb80e874d">28a639b2</a>)</li> </ul> <h5>Tests</h5> <ul> <li><strong>undici-http-handler:</strong> update bidi stream e2e test to nova-2-sonic model (<a href="https://redirect.github.com/aws/aws-sdk-js-v3/pull/8313">#8313</a>) (<a href="https://github.com/aws/aws-sdk-js-v3/commit/d9a37d9d318f2ef7f5bcf6286bf3c7b475e4175b">d9a37d9d</a>)</li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/aws/aws-sdk-js-v3/blob/main/clients/client-s3/CHANGELOG.md">@aws-sdk/client-s3's changelog</a>.</em></p> <blockquote> <h1><a href="https://github.com/aws/aws-sdk-js-v3/compare/v3.1140.0...v3.1141.0">3.1141.0</a> (2026-09-25)</h1> <p><strong>Note:</strong> Version bump only for package <code>@aws-sdk/client-s3</code></p> <h1><a href="https://github.com/aws/aws-sdk-js-v3/compare/v3.1139.0...v3.1140.0">3.1140.0</a> (2026-09-24)</h1> <p><strong>Note:</strong> Version bump only for package <code>@aws-sdk/client-s3</code></p> <h1><a href="https://github.com/aws/aws-sdk-js-v3/compare/v3.1138.0...v3.1139.0">3.1139.0</a> (2026-09-23)</h1> <p><strong>Note:</strong> Version bump only for package <code>@aws-sdk/client-s3</code></p> <h1><a href="https://github.com/aws/aws-sdk-js-v3/compare/v3.1137.0...v3.1138.0">3.1138.0</a> (2026-09-22)</h1> <p><strong>Note:</strong> Version bump only for package <code>@aws-sdk/client-s3</code></p> <h1><a href="https://github.com/aws/aws-sdk-js-v3/compare/v3.1136.0...v3.1137.0">3.1137.0</a> (2026-09-21)</h1> <p><strong>Note:</strong> Version bump only for package <code>@aws-sdk/client-s3</code></p> <h1><a href="https://github.com/aws/aws-sdk-js-v3/compare/v3.1135.0...v3.1136.0">3.1136.0</a> (2026-09-18)</h1> <p><strong>Note:</strong> Version bump only for package <code>@aws-sdk/client-s3</code></p> <h1><a href="https://github.com/aws/aws-sdk-js-v3/compare/v3.1134.0...v3.1135.0">3.1135.0</a> (2026-09-17)</h1> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/aws/aws-sdk-js-v3/commit/5bc8d9a96936723ac90d721e0c5a2bff7ee8520d"><code>5bc8d9a</code></a> Publish v3.1141.0</li> <li><a href="https://github.com/aws/aws-sdk-js-v3/commit/6050a3813c26795562b5ada8b0d9ea498eb9f8a1"><code>6050a38</code></a> Publish v3.1140.0</li> <li><a href="https://github.com/aws/aws-sdk-js-v3/commit/03d54a858f80012bbc60046a77242223e8dfd9d9"><code>03d54a8</code></a> Publish v3.1139.0</li> <li><a href="https://github.com/aws/aws-sdk-js-v3/commit/c68e50e4a6e0469a20c2894fe8a29c140553ebb8"><code>c68e50e</code></a> Publish v3.1138.0</li> <li><a href="https://github.com/aws/aws-sdk-js-v3/commit/9a104768684e8f22d4373fcc5d910711e62676d6"><code>9a10476</code></a> chore(codegen): sync for MetricsRecorder support and core error/retry fixes (...</li> <li><a href="https://github.com/aws/aws-sdk-js-v3/commit/6b432472f9bdf5437319b9186f706e3af5c9a748"><code>6b43247</code></a> Publish v3.1137.0</li> <li><a href="https://github.com/aws/aws-sdk-js-v3/commit/d6b94db8f4a00cc452dbe0aacb247e8ece3897ea"><code>d6b94db</code></a> Publish v3.1136.0</li> <li><a href="https://github.com/aws/aws-sdk-js-v3/commit/2d5f18d08aa373d95692d83cb3d60a6a79248fae"><code>2d5f18d</code></a> Publish v3.1135.0</li> <li><a href="https://github.com/aws/aws-sdk-js-v3/commit/0d6310bf6979ddbf737a7e15cfd8d0e7cec07063"><code>0d6310b</code></a> Publish v3.1134.0</li> <li><a href="https://github.com/aws/aws-sdk-js-v3/commit/615a1ca4661ec0e4cb34b8da89fe60c2419b94d0"><code>615a1ca</code></a> Publish v3.1133.0</li> <li>Additional commits viewable in <a href="https://github.com/aws/aws-sdk-js-v3/commits/v3.1141.0/clients/client-s3">compare view</a></li> </ul> </details> <br /> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>canary/v2026.1001.0-canary.4 |