Commit Graph
4750 Commits
Author SHA1 Message Date
DottaandPaperclip abd0b628ca Clarify legacy issue document delivery in the operational skill
Preserve the tiny hire manual and original assigned-skill case. Add a focused public document/revision/link oracle and explicit presence/absence provenance for a matched skill-only comparison.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-02 15:24:01 -05:00
DottaandPaperclip 5837aa4442 docs(evals): keep timeout document outcomes unknown
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-02 14:13:51 -05:00
DottaandPaperclip 792533866c docs(evals): close the unchanged-source baseline recovery
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-02 14:02:14 -05:00
DottaandPaperclip 6c27174cd4 docs(evals): retain matched stock-harness results and failures
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-02 13:56:35 -05:00
DottaandPaperclip 1eb5ba4206 fix(evals): retain prerequisites inside the campaign artifact root
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-02 12:59:07 -05:00
DottaandPaperclip f02d8d0df3 fix(evals): use complete Rust protocol test preparation
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-02 12:35:11 -05:00
DottaandPaperclip 712dc98cf5 fix(evals): bind protocol evidence to the built daemon
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-02 12:31:35 -05:00
DottaandPaperclip ac6ddefb58 fix(evals): build the cold daemon before protocol prerequisites
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-02 12:23:54 -05:00
DottaandPaperclip 4163dbfd0f fix(evals): prepare cold prerequisites and fingerprint connection guidance
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-02 12:11:37 -05:00
DottaandPaperclip 36e987246b test(evals): enforce exact-source stock harness prerequisites
Run credential-free gates before live admission and verify retained evidence in direct browser execution. Include evaluated instruction sources in suite revisions and calibrate stale/missing evidence rejection.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-02 11:49:11 -05:00
DottaandPaperclip a63437069d test(evals): cover production default hires across stock harnesses
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-02 11:26:28 -05:00
DottaandPaperclip 19d685a20c fix(agents): reduce default manual and shared legacy guidance
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-02 11:25:09 -05:00
dependabot[bot] cf8ad63c80 build(deps-dev): bump tsx from 4.23.12 to 4.23.15 (#12965)
Bumps [tsx](https://github.com/privatenumber/tsx) from 4.23.12 to
4.23.15.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/privatenumber/tsx/releases">tsx's
releases</a>.</em></p>
<blockquote>
<h2>v4.23.15</h2>
<h2><a
href="https://github.com/privatenumber/tsx/compare/v4.23.14...v4.23.15">4.23.15</a>
(2026-09-20)</h2>
<h3>Bug Fixes</h3>
<ul>
<li>exclude bare builtins from namespace inheritance (<a
href="https://github.com/privatenumber/tsx/commit/38e158857e50bca311be7c232a5057e5a2e5347a">38e1588</a>)</li>
<li>expose require.cache and require.extensions to tsImport CommonJS
modules (<a
href="https://github.com/privatenumber/tsx/commit/2da34075afaed43e2b7fd0aca5fbebaaf337ff3a">2da3407</a>)</li>
<li>make namespaced register() overloads portable for declaration emit
(<a
href="https://github.com/privatenumber/tsx/commit/562c434a5c8695e74327bbeb51cfeb9b86fc7e15">562c434</a>)</li>
</ul>
<hr />
<p>This release is also available on:</p>
<ul>
<li><a href="https://www.npmjs.com/package/tsx/v/4.23.15"><code>npm
package (@​latest dist-tag)</code></a></li>
</ul>
<h2>v4.23.14</h2>
<h2><a
href="https://github.com/privatenumber/tsx/compare/v4.23.13...v4.23.14">4.23.14</a>
(2026-09-20)</h2>
<h3>Bug Fixes</h3>
<ul>
<li>restore the CJS bridge namespace for Node 24 require(esm) under
tsImport() (<a
href="https://redirect.github.com/privatenumber/tsx/issues/802">#802</a>)
(<a
href="https://github.com/privatenumber/tsx/commit/6e5236b065738d3687a06396d064774cfede390f">6e5236b</a>)</li>
</ul>
<hr />
<p>This release is also available on:</p>
<ul>
<li><a href="https://www.npmjs.com/package/tsx/v/4.23.14"><code>npm
package (@​latest dist-tag)</code></a></li>
</ul>
<h2>v4.23.13</h2>
<h2><a
href="https://github.com/privatenumber/tsx/compare/v4.23.12...v4.23.13">4.23.13</a>
(2026-08-30)</h2>
<h3>Bug Fixes</h3>
<ul>
<li><strong>cache:</strong> bound shared transform cache memory (<a
href="https://redirect.github.com/privatenumber/tsx/issues/835">#835</a>)
(<a
href="https://github.com/privatenumber/tsx/commit/28e1f12d04cd2afe1db17f8555b14fe5fb567c6e">28e1f12</a>)</li>
</ul>
<hr />
<p>This release is also available on:</p>
<ul>
<li><a href="https://www.npmjs.com/package/tsx/v/4.23.13"><code>npm
package (@​latest dist-tag)</code></a></li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/privatenumber/tsx/commit/ca66105a17a2a4c6503fe3a12b5b9ec408286011"><code>ca66105</code></a>
test: fix drive-less file URLs in ESM resolver fixtures</li>
<li><a
href="https://github.com/privatenumber/tsx/commit/2da34075afaed43e2b7fd0aca5fbebaaf337ff3a"><code>2da3407</code></a>
fix: expose require.cache and require.extensions to tsImport CommonJS
modules</li>
<li><a
href="https://github.com/privatenumber/tsx/commit/38e158857e50bca311be7c232a5057e5a2e5347a"><code>38e1588</code></a>
fix: exclude bare builtins from namespace inheritance</li>
<li><a
href="https://github.com/privatenumber/tsx/commit/562c434a5c8695e74327bbeb51cfeb9b86fc7e15"><code>562c434</code></a>
fix: make namespaced register() overloads portable for declaration
emit</li>
<li><a
href="https://github.com/privatenumber/tsx/commit/edfb1f05a3f40b879a41a03a0801c2abd3a3ecf9"><code>edfb1f0</code></a>
build: upgrade pkgroll and externalize CJS loader reference</li>
<li><a
href="https://github.com/privatenumber/tsx/commit/70e78284837c859f09b96cd10cd71d007aa4b795"><code>70e7828</code></a>
test: upgrade tinyspy for disposable API</li>
<li><a
href="https://github.com/privatenumber/tsx/commit/9ed2022dfa9ea1be9511fe6abcde8110c25055a7"><code>9ed2022</code></a>
ci: avoid duplicate release notifications</li>
<li><a
href="https://github.com/privatenumber/tsx/commit/872e77ffc5e96ca5c4727e74c0694debcb26219b"><code>872e77f</code></a>
refactor: use disposables for cleanup</li>
<li><a
href="https://github.com/privatenumber/tsx/commit/6e5236b065738d3687a06396d064774cfede390f"><code>6e5236b</code></a>
fix: restore the CJS bridge namespace for Node 24 require(esm) under
tsImport...</li>
<li><a
href="https://github.com/privatenumber/tsx/commit/28e1f12d04cd2afe1db17f8555b14fe5fb567c6e"><code>28e1f12</code></a>
fix(cache): bound shared transform cache memory (<a
href="https://redirect.github.com/privatenumber/tsx/issues/835">#835</a>)</li>
<li>See full diff in <a
href="https://github.com/privatenumber/tsx/compare/v4.23.12...v4.23.15">compare
view</a></li>
</ul>
</details>
<br />

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
canary/v2026.1002.0-canary.12
2026-10-02 08:39:37 -07:00
Nicky LeachandPaperclip b2c565038b test(shared): make the worktree port registry lock suite deterministic (#12798)
## Thinking Path

> - Paperclip is the open source app people use to manage AI agents for
work
> - Shared worktree services use lock leases and worker-thread
heartbeats
> - The lock test suite measured wall-clock timing across two threads
> - Processor contention allowed a heartbeat tick to change the value
during an assertion
> - This pull request removes that timing race and restores a regression
guard
> - The benefit is a stable test suite that still detects slow
heartbeats

## Linked Issues or Issue Description

**What happened?** The worktree port registry lock suite failed at
random under continuous-integration processor contention. The failure
reported a fresh timestamp where the test expected an old timestamp.

**Expected behavior** The suite must pass when the heartbeat runs at its
supported interval. It must also fail when the heartbeat interval
regresses.

**Steps to reproduce**
1. Run `npx vitest run src/worktree-port-registry.test.ts` in
`packages/shared`.
2. Repeat the run under bounded processor contention.
3. Set the heartbeat interval to 3000 ms and run the asynchronous
critical-section test.

**Paperclip version or commit**
`a661caf74e704f7700a8b8a1e79b76ebd04e3483`

**Deployment mode** Built from source.

**Installation method** Built from source.

**Agent adapter(s) involved** Not adapter-specific (core test).

**Database mode** Not database-related.

**Additional context** Related open pull requests are #11994, #11985,
and #11922. This pull request keeps all five tests active and does not
use `skip`, `skipIf`, or `todo`.

## What Changed

- Build the fallback-probe lock state by hand so no live heartbeat
changes the timestamp during the assertion.
- Count distinct heartbeat refreshes in the asynchronous
critical-section test.
- Close the fake probe and settle the pending lock attempt in a
`finally` block.
- Keep production code unchanged.

## Verification

- `npx vitest run src/worktree-port-registry.test.ts` — 5 of 5 tests
pass.
- `npx vitest run` — 72 files and 704 tests pass at submit time.
- `npx tsc --noEmit` — exit code 0.
- Ten target-file runs pass under bounded processor contention.
- A 3000 ms heartbeat interval fails with `expected 2 to be greater than
or equal to 3`.
- An inverted cleanup assertion exits normally in 379 ms without a
leaked worker.

## Risks

Low risk. This pull request changes one test file. It changes test setup
and assertions only.

## Model Used

OpenAI GPT-5 through Codex. Exact model ID: GPT-5. The model used tool
calls and code execution. The context window is not disclosed by the
runtime.

## Checklist

- [x] I have included a thinking path that traces from project context
to this change
- [x] I have specified the model used (with version and capability
details)
- [x] I have checked ROADMAP.md and confirmed this PR does not duplicate
planned core work
- [x] I have searched GitHub for duplicate or related PRs and linked
them above
- [x] I have either (a) linked existing issues with `Fixes: #` /
`Closes: #` / `Refs: #` OR (b) described the issue in-PR following the
relevant issue template
- [x] I have not referenced internal/instance-local Paperclip issues or
links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip`
URLs)
- [x] My branch name describes the change (e.g. `docs/...`, `fix/...`)
and contains no internal Paperclip ticket id or instance-derived details
- [x] I have run tests locally and they pass
- [x] I have added or updated tests where applicable
- [x] I have updated relevant documentation to reflect my changes
- [x] I have considered and documented any risks above
- [x] All Paperclip CI gates are green
- [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups
- [x] I will address all Greptile and reviewer comments before
requesting merge

---------

Co-authored-by: Paperclip <noreply@paperclip.ing>
2026-10-02 08:24:00 -07:00
Nicky LeachandPaperclip 9d0f7e2ddd fix(adapter-utils): make the directory merge lock crash test deterministic (#14881)
## Thinking Path

> - Paperclip is the open source app people use to manage AI agents for
work
> - A workspace restore merges a directory, and a cross-process lock
serializes that merge
> - The lock must recover after the process that holds it crashes
> - One test proves that recovery: it kills the holder process and then
acquires the lock
> - That test failed intermittently for two independent reasons, and
this pull request removes both
> - First, it spawned the holder through the tsx command-line entry
point, which re-spawns the evaluated code in a further child process, so
the kill signal reached only the wrapper and the real holder kept the
lock
> - Second, it replaced the global clock to force a timeout, which left
the acquisition with zero real retries, so a single transient busy
result failed the test
> - The benefit is a deterministic crash-recovery test and a reliable
continuous-integration signal

## Linked Issues or Issue Description

**What happened?**

The test `recovers a killed holder even when its recorded PID has been
reused` in `packages/adapter-utils/src/directory-merge-lock.test.ts`
failed intermittently in continuous integration. The failure reported
`ERR_WORKSPACE_RESTORE_LOCK_TIMEOUT` with `waitMs: 3` and
`knownLocalHolder: false`. A rerun of the same job on the same commit
passed.

**Expected behavior**

The test must pass every run. It must acquire the lock after the holder
process dies.

**Steps to reproduce**

1. Check out `master`.
2. Run `npx vitest run
packages/adapter-utils/src/directory-merge-lock.test.ts`.
3. Repeat the run. The named test fails intermittently.

**Paperclip version or commit**

`32e9f3ba0ec000578936731990d23bb0e77493fa`

**Deployment mode**

Built from source. The failure appears in the general test job of
continuous integration.

**Agent adapter(s) involved**

Not adapter-specific (core bug).

**Relevant logs or output**

```
ERR_WORKSPACE_RESTORE_LOCK_TIMEOUT
workspaceRestoreLock: { ownerState: 'alive', knownLocalHolder: false, waitMs: 3,
                        ownerSameProcess: true, ownerAgeMs: 60030, ownerPredatesProcess: true }
```

## What Changed

The test file had two independent defects. This pull request removes
both.

**1. The kill signal did not reach the real lock holder.**

The test spawned its holder through the tsx command-line entry point.
That entry point re-spawns the evaluated code in a further child
process. `SIGKILL` therefore killed only the wrapper, and the process
that had opened the lock database survived as an orphan that still held
the lock. The test now loads tsx as an `--import` hook, so the spawned
process is the real holder and the kill releases the lock at once. This
also stops the test from leaking an orphan process.

**2. The forced clock left the acquisition with zero retries.**

A test helper replaced `Date.now` to force a timeout. The implementation
reads `Date.now()` one time, to compute its deadline, so that single
read consumed the forced value and every later read returned a time
already past the deadline. The retry loop therefore got one attempt and
no retries. That is correct for a test that asserts a timeout, but the
crash-recovery test asserts a *successful* acquisition, so any transient
busy result on the first attempt failed it.

The fix removes the clock replacement from the whole file and gives each
test a real, short, explicit wait budget:

- `withDirectoryMergeLock` takes a new optional wait-budget parameter.
It threads through to the lock acquisition function. The production
default is the existing 30-second budget, and no production call site
changed.
- The five tests that assert a timeout pass a real 200-millisecond
budget. Each one still times out for the real reason, because the lock
is genuinely held or the legacy lock directory genuinely exists. Each
one now exercises at least four real retries of the 50-millisecond retry
interval.
- The crash-recovery test passes a real 5-second budget. A failure now
reports the structured `ERR_WORKSPACE_RESTORE_LOCK_TIMEOUT` diagnostic
well inside the test timeout, instead of a bare test timeout.

**No test timeout increased.** Every `it(..., N)` timeout in the file
equals its value on `master`.

## Verification

- Measured the first cause rather than assumed it: the spawned wrapper
process reported one process id, and the process that opened the lock
database reported a different process id and named the wrapper as its
parent. The real holder kept the lock for about 50 to 60 milliseconds
after the kill.
- Reproduced the failure deterministically before the change, with no
artificial processor load: 15 of 15 runs failed. Confirmed the fix: 15
of 15 runs passed.
- Ran the lock test file 15 times in series: 12 of 12 tests passed every
time.
- Confirmed the clock replacement is gone: a search for a `Date.now`
override in the file returns nothing.
- Confirmed the production default is unchanged at 30 seconds, and that
the diff touches no production call site.
- Proved the diagnostic still surfaces: with a temporary edit that held
the lock with a genuine live holder, the test failed with
`ERR_WORKSPACE_RESTORE_LOCK_TIMEOUT` and the full `workspaceRestoreLock`
block at about 5 seconds, inside the 15-second test timeout. The
temporary edit was reverted.
- `workspace-restore-merge.test.ts` passed 56 of 56. The adapter test
files that cover every production caller passed 116 of 116 and 52 of 52.
`agent-directory-working-copies.test.ts` passed 70 of 70.
- The `adapter-utils` and `server` type-checks passed with no error.
- Confirmed that no spawned process survives the test run.

## Risks

Low risk. The production change is one optional parameter with the
existing default, so every production caller keeps the real 30-second
budget and no production call site changed. The remaining change is
limited to one test file. The `--import` form of the tsx hook is already
used elsewhere in this repository, in the container image command and in
an end-to-end test configuration. Test coverage does not drop: the owner
record is diagnostic only, the SQLite reserved lock remains the
authority that the tests exercise, and the timeout-asserting tests now
exercise the real retry loop instead of a replaced clock. The file costs
about 0.5 to 0.9 seconds more wall clock than `master`, which is the
cost of the short real waits that replace the instant forced timeout.

## Model Used

Claude Sonnet 5 (`claude-sonnet-5`), used with extended thinking and
tool use for the diagnosis, the measurement, and the change.

## Checklist

Check every box that the state of the pull request satisfies. The local
test runs and the type checks are complete. Reconcile the
continuous-integration and review boxes after the checks reach their
terminal state.

## Test plan

- [x] Continuous integration is green on every check, including the
general test job.
- [x] The general test job passes the file
`packages/adapter-utils/src/directory-merge-lock.test.ts`.
- [x] Greptile returns 5 of 5 with no open item.
- [x] `mergeable: MERGEABLE` is terminal.

---------

Co-authored-by: Paperclip <noreply@paperclip.ing>
2026-10-02 08:17:03 -07:00
DottaandPaperclip 6c1a75da49 feat(connections): make AgentMail a default connection with inline setup (#14772)
## Thinking Path

> - Paperclip is the open source app people use to manage AI agents for
work.
> - Connections give agents access to external services.
> - AgentMail needs both a saved key and an inbox assigned to the agent.
> - Chat requests offered a setup link instead of an inline card and
could treat a saved key as complete.
> - Inbox setup also hid address conflicts behind a generic server error
and a separate review step.
> - This pull request makes AgentMail a default connection, adds the
inline card, reduces setup to two steps, and shows conflicts beside the
address.
> - Shared native dropdown styles also give every caret a consistent
inset.

## Linked Issues or Issue Description

**What happened?**

AgentMail requests in chat did not show a usable inline connection card.
Manual setup required extra screens, ignored saved account keys, and
could trap new-address setup in a locked inbox dropdown. Agent selectors
omitted the avatar from the selected value. A taken address could
produce an HTTP 403 from AgentMail and appear as an internal server
error. Native dropdown arrows also touched the right edge of their
fields.

**Expected behavior**

Make AgentMail available as a default connection. Ask for the API key
inline, with a direct link to its provider page. Default human access to
the company and agent access to the requesting agent. Resume the agent
only after an assigned inbox is active. Manual setup should ask for an
agent and email address, then finish. Address checks should run as the
user types. Taken addresses should show clickable alternatives. A domain
dropdown beside the name should prefer a verified custom domain. Setup
should suggest authorized saved AgentMail keys and show agent avatars in
the picker and selected value.

**Steps to reproduce**

1. Ask an agent to connect AgentMail when it has no assigned inbox.
2. Check that an inline API-key card appears and links to the provider's
API-key page.
3. Open AgentMail setup, choose an agent, and request an address that is
already taken.
4. Correct the inline error, refresh, and finish setup with the same
request ID.
5. Inspect native dropdown carets in light, dark, disabled, and
right-to-left states.

Uses the bounded provider-error parser merged in #14768. Related work:
#13256 introduced AgentMail; #14725 expanded connection search.

## What Changed

- Stop recurring email queries for tasks that have no email thread.
Share the query between the thread provider and activity view. Keep
email-task updates and invalidation-based discovery.
- Make AgentMail available without the experimental chat setting. Keep
the catalog, setup and management routes, agent Channels tab, task email
feed, receiving worker, and agent tools available by default. Other
experimental chat providers stay gated.

- Make the email address and copy icon a single clickable action with
the shared Copied! confirmation. Add View inbox linking directly to the
matching AgentMail console inbox, with the address encoded as one URL
path segment.

- Reorganize inbox Settings around the copyable email address, usage
instructions, and receiving status. Move reconnect credentials into a
disclosure and separate the Disconnect action. Add production Settings
stories for active, paused, unassigned-address, revoked, webhook,
long-address, mobile, and reconnect states. Show repair controls when
the inbox has an error. Keep usage instructions tied to an active inbox
with an address.

- Add AgentMail channel intents and an inline key field with the direct
API-key URL.
- Keep setup and retry state tied to the interaction. Require an active
inbox for completion. Preserve company and agent access checks.
- Reduce manual setup to agent selection and email selection. Put the
domain dropdown beside the address and default to a verified custom
domain. Preserve explicit choices across reloads. Keep receiving
settings under Advanced options.
- Check the initial address and edits after a 350 ms pause. Abort
superseded requests and ignore stale responses. Show clickable
suggestions and retain known creation conflicts across reloads.
- Add a company-scoped, manager-only address check using the saved
credential. Search the visible inbox list instead of fetching an
uncreated inbox: live AgentMail retains negative lookups that can break
subsequent access-key creation. Unlisted addresses remain unknown;
creation is authoritative.
- Suggest labeled saved AgentMail keys in both manual setup and the
inline card. Filter by company, provider, active credential, and
current-user grants on the server. Prefer an account key and preserve
the selected key or an explicit new-key choice across refresh. Use
verified scope metadata and bounded concurrent checks for legacy keys.
Never return secret values.
- Catch an inbox-only key before the email step. Allow its existing
inbox only after an explicit choice. Recover old locked drafts at the
key picker. Save the replacement key before retiring an empty draft,
then use a new setup URL so refresh preserves the switched account; stop
if cleanup fails. Preserve already allocated addresses and their
original accounts.
- Use the shared AgentSelect in email setup. Show the canonical agent
avatar in each option and the selected value, including other consumers
of the shared component. Add regression coverage for legacy and current
Lucide agent-mention icon formats.
- Start each catalog Add connection with a fresh setup identity. Honor
Finish setup's exact draft/account/address instead of resuming an
unrelated browser draft. Return Cancel and Done to Connectors and Email
settings to the inbox. Group the task/thread explanation in a How it
Works card.
- Route AgentMail catalog removal through the email inbox control API,
including unfinished drafts. Refresh both the catalog and inbox views.
- Render each inbox management tab separately. Access uses the saved
account grants and agent controls; Conversations and Activity use the
shared persisted email feed. Activity lifecycle actions use the email
API. Reconnect returns to inbox Settings. Conversation failures show a
retry instead of a false empty state. Email delivery recovery stays in
the task.
- Map documented provider address conflicts to a field error. Preserve
actionable messages for other failures.
- Preserve non-secret draft fields across refresh, scoped to the
requested agent. Never save API keys in browser storage. Resume partial
inbox creation with the original agent, address, and request ID.
- Show an already-created address with explicit retry and new-address
recovery instead of locked inputs. Preserve the original inbox and
resumable draft when choosing another address. Distinguish runtime-key
404 errors and log safe provider status/operation/code.
- Apply final agent access once within email setup authorization for a
new account whose original installs are unchanged. Preserve later
permission edits and reused account installs. Support in-place retry of
progress loading.
- Let a failed inline setup change keys after retiring an empty draft.
Persist its replacement setup identity without storing secrets. Recover
a server-saved account when refresh interrupts the save response, while
preserving intentional account changes.
- Render the production setup in Storybook and add error, recovery, and
mobile states.
- Inset native select carets in shared CSS. Preserve custom icons,
listboxes, keyboard behavior, and forced-color controls.
- Add browser regression coverage and an AgentMail Product E2E case with
persisted-state and rendered-card evidence.

## Verification

- Full `pnpm -r typecheck`, `pnpm build`, `pnpm check:token-gates`, and
`git diff --check` passed after the default-availability change.
- All 485 focused tests passed. These cover setup, management, catalog
and route gates, connection intents, email authorization, Cursor
execution, and the OpenAPI contract. All 39 email integration tests run
with the experimental chat setting off.
- The shared polling change passed four behavioral tests, UI typecheck
and build, and token gates.
- `tests/e2e/agentmail.spec.ts` passed with the actual server setting
off. This full-stack browser test uses simulated provider responses. It
covers catalog entry, saved keys, editable address and domain controls,
creation, conflicts, retry, all management tabs, clipboard feedback, the
provider link, and task email rendering.
- In the live local browser, Add connection reached the editable email
step with the saved account key. The verified custom domain was selected
by default. Both domain choices worked. The existing inbox Settings page
remained available. Both active inboxes completed new mail checks with
the setting off. No new provider inbox or email message was created for
this pass.
- Earlier live provider acceptance covered creation on a verified custom
domain, Finish connecting on the reported draft, successful mail checks
after refresh, and catalog removal of disposable draft and active
connections. Clicking the email address copied the exact address and
showed Copied!. View inbox opened the same inbox in AgentMail’s console.
No email messages were sent.
- Production setup and Settings Storybook builds and interactions
passed. Settings states include active, paused, unassigned, revoked,
webhook, long-address, mobile, and reconnect. Receiving and
revoked-access stories had zero accessibility violations.
- Full local `pnpm test:run` on an earlier revision completed with
14,709 passing, 87 skipped, and four transient failures. All four failed
cases passed in focused reruns without product changes. That serial full
local command was not repeated after each follow-up. The latest-head
full CI suite is the final test gate.
- CI found an obsolete browser assertion that hid every channel when the
flag was off. Updated it to keep AgentMail and the Channels surface
visible while preserving the GitHub chat route gates. All 11 provider
browser tests passed locally after scoping the Channels selector to the
agent sidebar. Two initial local attempts stopped at temporary Postgres
initialization. The passing run used a separate disposable database on
the existing local Postgres server; it was removed after the test.
- Updated the remaining sidebar and aggregator discovery assertions for
default AgentMail availability. Ordinary task fixtures now return no
email thread. All 128 sidebar/task-page tests and all 42 aggregator
tests passed locally.
- Latest head `b42bb4cd5cc9f2d01a99ab8026832d5a956ea85f`: full CI
passed, with 54 successful checks including Snyk and two intentional
Storybook skips. The CI run is
https://github.com/paperclipai/paperclip/actions/runs/37020833647. A
fresh Greptile review scored 5/5 with no unresolved threads. Live model
evaluations and inbound/outbound email delivery were not run.

## Risks

- AgentMail no longer needs experimental opt-in. Setup still requires a
human to connect an account and assign an inbox. Inline setup creates an
inbox after a human submits a new or saved key. Company access, agent
access, inbox assignment, and completion checks remain enforced.
- AgentMail read APIs cannot prove global address availability. The
visible-list check is bounded to 100 entries and cannot see inboxes
outside the key’s scope. The UI reports this limitation, suggests
alternatives without claiming they are free, and keeps final creation
conflicts inline. Lookup outages show an error without preventing the
authoritative creation attempt.
- Native select CSS affects the whole app. Custom-icon selects and
multi-row lists are excluded. Forced-color mode keeps the browser caret.
- Saved-key discovery uses stored verified scope metadata and checks
authorized legacy credentials concurrently within a shared three-second
deadline. Provider outages mark legacy choices unavailable; users can
still enter another key. Final use rechecks authorization and provider
access.
- No database migration or transport default change. Live connection
remains the default.

## Model Used

OpenAI Codex, GPT-6, with reasoning, tool use, and code execution. The
exact served model ID and context-window size are not exposed in this
session.

## Checklist

- [x] I have included a thinking path that traces from project context
to this change
- [x] I have specified the model used (with version and capability
details)
- [x] I have checked ROADMAP.md and confirmed this PR does not duplicate
planned core work
- [x] I have searched GitHub for duplicate or related PRs and linked
them above
- [x] I have either (a) linked existing issues with `Fixes: #` / `Closes
#` / `Refs #` OR (b) described the issue in-PR following the relevant
issue template
- [x] I have not referenced internal/instance-local Paperclip issues or
links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip`
URLs)
- [x] My branch name describes the change (e.g. `docs/...`, `fix/...`)
and contains no internal Paperclip ticket id or instance-derived details
- [x] I have run tests locally and they pass (focused suites; full-suite
limitation documented above)
- [x] I have added or updated tests where applicable
- [x] I have updated relevant documentation to reflect my changes
- [x] I have considered and documented any risks above
- [x] All Paperclip CI gates are green (latest head
`b42bb4cd5cc9f2d01a99ab8026832d5a956ea85f`)
- [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups
(latest head `b42bb4cd5cc9f2d01a99ab8026832d5a956ea85f`)
- [x] I will address all Greptile and reviewer comments before
requesting merge

---------

Co-authored-by: Paperclip <noreply@paperclip.ing>
2026-10-02 10:01:15 -05:00
DottaandPaperclip ec3bacc9bd fix(chat): hide ignored provider information (#14929)
## Thinking Path

> - Paperclip is the open source app people use to manage AI agents for
work.
> - Task and agent chats show agent progress and problems that need
attention.
> - Codex also sends account, skill, and unrelated thread notifications.
> - The runner correctly ignores that information but reports it as a
warning.
> - Chat then shows an internal diagnostic as an actionable provider
notice.
> - This pull request keeps the diagnostic in run logs and removes it
from chat.
> - Real provider warnings, errors, and agent replies remain visible.

## Linked Issues or Issue Description

**What happened?**

Chat showed “Received a provider update” and a warning with the text
“ignored
unrelated provider information”. Its details said “User Actionable: Yes”
even
though no user action was needed. Saved conversations retained the same
noise.

**Expected behavior**

Keep ignored provider information in the run log. Do not show it as chat
activity
or a user warning. Preserve real warnings and errors.

**Steps to reproduce**

1. Start a conversation with the native Codex runner.
2. Have the provider send an account update, skill change, or unrelated
thread
   notification during the turn.
3. Inspect live chat and reload its saved history.

The regression tests also reproduce the old stored notice without a live
account.

**Paperclip version or commit**

Source implementation on master at `e00d10d5d`. The duplicate search
found no
open PR for this fix. Related prior work: #13109 improved
provider-notice
presentation. #12367 added Codex thread normalization. This change
addresses
the internal information that those paths still projected as chat
warnings.

**Deployment mode**

Native Paperclip Runner with the Codex app-server provider. The issue
was seen
in hosted chat and can be reproduced with local provider fixtures.

## What Changed

- Map ignored unrelated Codex information to `harness.diagnostic` in the
Rust
  and TypeScript normalizers.
- Retain a bounded allowlist of redacted provider method and thread/turn
identifiers.
- Use the same Unicode character limit and truncation marker in both
normalizers.
- Share the text redactor through a pure helper. Keep provider
connection code
  out of the standalone demo's source closure.
- Omit that diagnostic and the matching legacy notice from live chat.
- Omit the matching legacy notice from saved chat history.
- Test diagnostic retention, account-notification integration, live and
saved
  chat, and continued visibility of real warnings, errors, and replies.
- Document the local run-log event and historical display behavior.

## Verification

- Passed: 68 tests in the two affected UI transcript suites.
- Passed: 60 TypeScript tests across provider events, transport
behavior, and
  the standalone demo boundary.
- Passed: 13 Rust provider-event tests and the Codex
account-notification
  integration test.
- Passed: `pnpm check:token-gates` and Cargo formatting checks.
- Passed: full `pnpm build` and `pnpm -r typecheck`. After the review
fix,
the provider package build, typecheck, and both provider-event suites
passed again.
- Full local `pnpm test:run` failed: 608 files / 10,904 tests passed, 30
server
suites failed, and 104 files / 4,012 tests were skipped. Most failures
were
  embedded PostgreSQL startup errors. Two tests timed out in
`heartbeat-comment-wake-batching` and
`workspace-git-snapshot-streaming`.
  PostgreSQL startup also failed in `heartbeat-run-event-sequencing` and
`native-finalization-migration`. These server files are unchanged by
this PR.
Isolated heartbeat reruns were skipped locally. The stable test script
stopped
  after this general-server group, so later groups did not run locally.
- The original review thread is resolved. Greptile is 5/5 on current
head
  `683dab7cce57187c57e84c83f5e9da4ad75c9c04`.
- All current-head CI gates passed, including the full
server/chat/workspace
test matrix, Rust and TypeScript runner suites, browser E2E, build,
typecheck,
and release canary. [CI
run](https://github.com/paperclipai/paperclip/actions/runs/37021330663).
- Replay the exact old warning in either transcript adapter. It must
produce
no chat row. A genuine provider warning or error must still produce a
row.

## Risks

- Low risk. The display filter matches one diagnostic code or the
complete
  legacy warning shape. Other provider notices remain visible.
- New ignored-information events use the existing harness-diagnostic
event
type. They retain diagnostic evidence without original account payloads.
- No database migration, API permission, provider execution, or recovery
  behavior changes. This affects the local run log, not Telemetry or
  OpenTelemetry exports.

## Model Used

OpenAI Codex, GPT-6. The exact backend model ID and context-window size
are
not exposed in this session. Used reasoning, repository inspection, code
editing, tool use, and test execution.

## Checklist

- [x] I have included a thinking path that traces from project context
to this change
- [x] I have specified the model used (with version and capability
details)
- [x] I have checked ROADMAP.md and confirmed this PR does not duplicate
planned core work
- [x] I have searched GitHub for duplicate or related PRs and linked
them above
- [x] I have either (a) linked existing issues with `Fixes: #` / `Closes
#` / `Refs #` OR (b) described the issue in-PR following the relevant
issue template
- [x] I have not referenced internal/instance-local Paperclip issues or
links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip`
URLs)
- [x] My branch name describes the change (e.g. `docs/...`, `fix/...`)
and contains no internal Paperclip ticket id or instance-derived details
- [x] I have run the affected tests locally and they pass (the broad
local run has PostgreSQL startup errors and timeouts documented above;
the full CI matrix passed)
- [x] I have added or updated tests where applicable
- [x] I have updated relevant documentation to reflect my changes
- [x] I have considered and documented any risks above
- [x] All Paperclip CI gates are green
- [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups
- [x] I will address all Greptile and reviewer comments before
requesting merge

---------

Co-authored-by: Paperclip <noreply@paperclip.ing>
2026-10-02 09:59:34 -05:00
dependabot[bot] 479debe9e3 build(deps): bump aws-actions/configure-aws-credentials from 6.2.3 to 6.3.0 (#12966)
Bumps
[aws-actions/configure-aws-credentials](https://github.com/aws-actions/configure-aws-credentials)
from 6.2.3 to 6.3.0.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/aws-actions/configure-aws-credentials/releases">aws-actions/configure-aws-credentials's
releases</a>.</em></p>
<blockquote>
<h2>v6.3.0</h2>
<h2><a
href="https://github.com/aws-actions/configure-aws-credentials/compare/v6.2.4...v6.3.0">6.3.0</a>
(2026-09-11)</h2>
<h3>Features</h3>
<ul>
<li>add translate-env-variables option (<a
href="https://redirect.github.com/aws-actions/configure-aws-credentials/issues/1961">#1961</a>)
(<a
href="https://github.com/aws-actions/configure-aws-credentials/commit/57b83659c2db2eb3b9c655186bef9a6a8f6620cb">57b8365</a>)</li>
</ul>
<h2>v6.2.4</h2>
<h2><a
href="https://github.com/aws-actions/configure-aws-credentials/compare/v6.2.3...v6.2.4">6.2.4</a>
(2026-08-31)</h2>
<h3>Bug Fixes</h3>
<ul>
<li>account-ids handling, mask proxy as secret in logs (<a
href="https://redirect.github.com/aws-actions/configure-aws-credentials/issues/1943">#1943</a>)
(<a
href="https://github.com/aws-actions/configure-aws-credentials/commit/aa6526434b08748f8776b29964e3f1f5d90e7b63">aa65264</a>)</li>
<li>skip backoff sleep after the final retryAndBackoff attempt (<a
href="https://redirect.github.com/aws-actions/configure-aws-credentials/issues/1937">#1937</a>)
(<a
href="https://github.com/aws-actions/configure-aws-credentials/commit/3852440c21363386b7b790605685d08a7c1a4876">3852440</a>)</li>
</ul>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/aws-actions/configure-aws-credentials/blob/main/CHANGELOG.md">aws-actions/configure-aws-credentials's
changelog</a>.</em></p>
<blockquote>
<h1>Changelog</h1>
<p>All notable changes to this project will be documented in this file.
See <a
href="https://github.com/conventional-changelog/standard-version">standard-version</a>
for commit guidelines.</p>
<h2><a
href="https://github.com/aws-actions/configure-aws-credentials/compare/v6.2.4...v6.3.0">6.3.0</a>
(2026-09-11)</h2>
<h3>Features</h3>
<ul>
<li>add translate-env-variables option (<a
href="https://redirect.github.com/aws-actions/configure-aws-credentials/issues/1961">#1961</a>)
(<a
href="https://github.com/aws-actions/configure-aws-credentials/commit/57b83659c2db2eb3b9c655186bef9a6a8f6620cb">57b8365</a>)</li>
</ul>
<h2><a
href="https://github.com/aws-actions/configure-aws-credentials/compare/v6.2.3...v6.2.4">6.2.4</a>
(2026-08-31)</h2>
<h3>Bug Fixes</h3>
<ul>
<li>account-ids handling, mask proxy as secret in logs (<a
href="https://redirect.github.com/aws-actions/configure-aws-credentials/issues/1943">#1943</a>)
(<a
href="https://github.com/aws-actions/configure-aws-credentials/commit/aa6526434b08748f8776b29964e3f1f5d90e7b63">aa65264</a>)</li>
<li>skip backoff sleep after the final retryAndBackoff attempt (<a
href="https://redirect.github.com/aws-actions/configure-aws-credentials/issues/1937">#1937</a>)
(<a
href="https://github.com/aws-actions/configure-aws-credentials/commit/3852440c21363386b7b790605685d08a7c1a4876">3852440</a>)</li>
</ul>
<h2><a
href="https://github.com/aws-actions/configure-aws-credentials/compare/v6.2.2...v6.2.3">6.2.3</a>
(2026-07-22)</h2>
<h3>Bug Fixes</h3>
<ul>
<li>attach git credentials before Tag Major Version push (<a
href="https://redirect.github.com/aws-actions/configure-aws-credentials/issues/1877">#1877</a>)
(<a
href="https://github.com/aws-actions/configure-aws-credentials/commit/9ae780b171afa8c5a3a6a2d154a765b709492482">9ae780b</a>)</li>
<li>PackedPolicyTooLarge detection in STS tags (<a
href="https://redirect.github.com/aws-actions/configure-aws-credentials/issues/1899">#1899</a>)
(<a
href="https://github.com/aws-actions/configure-aws-credentials/commit/fa8d6a57bbf44b34439fb080bbdadc7c92c285eb">fa8d6a5</a>)</li>
</ul>
<h2><a
href="https://github.com/aws-actions/configure-aws-credentials/compare/v6.2.1...v6.2.2">6.2.2</a>
(2026-07-07)</h2>
<h3>Miscellaneous Chores</h3>
<ul>
<li>release 6.2.2 (<a
href="https://github.com/aws-actions/configure-aws-credentials/commit/d01d678e65d6d2bd9d5ca7a95d6f07b00e25f2c2">d01d678</a>)</li>
</ul>
<h2><a
href="https://github.com/aws-actions/configure-aws-credentials/compare/v6.2.0...v6.2.1">6.2.1</a>
(2026-06-26)</h2>
<h3>Bug Fixes</h3>
<ul>
<li>enforce allowed-account-ids on all auth paths (<a
href="https://redirect.github.com/aws-actions/configure-aws-credentials/issues/1847">#1847</a>)
(<a
href="https://github.com/aws-actions/configure-aws-credentials/commit/4d281fbc56a82e63c3fc14f2cc22361f34c97493">4d281fb</a>)</li>
</ul>
<h2><a
href="https://github.com/aws-actions/configure-aws-credentials/compare/v6.1.3...v6.2.0">6.2.0</a>
(2026-06-01)</h2>
<h3>Features</h3>
<ul>
<li>add additional session tags by default (<a
href="https://redirect.github.com/aws-actions/configure-aws-credentials/issues/1775">#1775</a>)
(<a
href="https://github.com/aws-actions/configure-aws-credentials/commit/e0ba7685077379a14a82d01fefd511490344ebfc">e0ba768</a>)</li>
<li>add more retry logic and better logging (<a
href="https://redirect.github.com/aws-actions/configure-aws-credentials/issues/1764">#1764</a>)
(<a
href="https://github.com/aws-actions/configure-aws-credentials/commit/540d0c13aedb8d55501d220bd2f0b3cdedfe84e8">540d0c1</a>)</li>
<li>add regex validation to role-session-name (<a
href="https://redirect.github.com/aws-actions/configure-aws-credentials/issues/1765">#1765</a>)
(<a
href="https://github.com/aws-actions/configure-aws-credentials/commit/e35449909c6ede5083a48ba4b8bbfaaa1cf09ba1">e354499</a>)</li>
<li>Allow custom session tags to be passed when assuming a role (<a
href="https://redirect.github.com/aws-actions/configure-aws-credentials/issues/1759">#1759</a>)
(<a
href="https://github.com/aws-actions/configure-aws-credentials/commit/61f50f630f383628add73c1eab3f1935ba07da2b">61f50f6</a>)</li>
<li>expose run id in STS client user-agent (<a
href="https://redirect.github.com/aws-actions/configure-aws-credentials/issues/1774">#1774</a>)
(<a
href="https://github.com/aws-actions/configure-aws-credentials/commit/29d1be30273e7ef371d59fccf6ec54572c64ec89">29d1be3</a>)</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/aws-actions/configure-aws-credentials/commit/e1253824e5c10ff9df46874f81ed3ec929e19cfd"><code>e125382</code></a>
chore(main): release 6.3.0 (<a
href="https://redirect.github.com/aws-actions/configure-aws-credentials/issues/1963">#1963</a>)</li>
<li><a
href="https://github.com/aws-actions/configure-aws-credentials/commit/438100a0eb37d9180319c727b1e108d9a112a27a"><code>438100a</code></a>
chore: add link to GH security docs (<a
href="https://redirect.github.com/aws-actions/configure-aws-credentials/issues/1962">#1962</a>)</li>
<li><a
href="https://github.com/aws-actions/configure-aws-credentials/commit/e92ebccf3986be80a7535da17f1ed57aec450139"><code>e92ebcc</code></a>
chore: Update dist</li>
<li><a
href="https://github.com/aws-actions/configure-aws-credentials/commit/57b83659c2db2eb3b9c655186bef9a6a8f6620cb"><code>57b8365</code></a>
feat: add translate-env-variables option (<a
href="https://redirect.github.com/aws-actions/configure-aws-credentials/issues/1961">#1961</a>)</li>
<li><a
href="https://github.com/aws-actions/configure-aws-credentials/commit/cc49fa741eb53f7c83be6fce8f9b4df000cd3af7"><code>cc49fa7</code></a>
chore(docs): README main branch guidance (<a
href="https://redirect.github.com/aws-actions/configure-aws-credentials/issues/1960">#1960</a>)</li>
<li><a
href="https://github.com/aws-actions/configure-aws-credentials/commit/866cb167f1d1a75ae9c75cdb39377cfd9c0f794e"><code>866cb16</code></a>
chore(deps-dev): bump smol-toml from 1.7.0 to 1.7.2 (<a
href="https://redirect.github.com/aws-actions/configure-aws-credentials/issues/1958">#1958</a>)</li>
<li><a
href="https://github.com/aws-actions/configure-aws-credentials/commit/6782cb1b6df5d32e9354c1e6d6da4f956c0d61c4"><code>6782cb1</code></a>
chore(deps-dev): bump generate-license-file from 4.2.4 to 4.2.5 (<a
href="https://redirect.github.com/aws-actions/configure-aws-credentials/issues/1951">#1951</a>)</li>
<li><a
href="https://github.com/aws-actions/configure-aws-credentials/commit/c20509ac5cba30e782e34cf33a0067e67c746cf0"><code>c20509a</code></a>
chore: Update dist</li>
<li><a
href="https://github.com/aws-actions/configure-aws-credentials/commit/7a41fc6cd2b4970e71974e29fb3f0979f4eb20cb"><code>7a41fc6</code></a>
chore(deps): bump <code>@​aws-sdk/client-sts</code> from 3.1121.0 to
3.1127.0 (<a
href="https://redirect.github.com/aws-actions/configure-aws-credentials/issues/1954">#1954</a>)</li>
<li><a
href="https://github.com/aws-actions/configure-aws-credentials/commit/726b71346f7761addb59879a6c73e0c64ec8f959"><code>726b713</code></a>
chore(deps-dev): bump <code>@​biomejs/biome</code> from 2.5.11 to 2.5.12
(<a
href="https://redirect.github.com/aws-actions/configure-aws-credentials/issues/1957">#1957</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/aws-actions/configure-aws-credentials/compare/e6de054238d6b7531b4efff3b6587d9aade6a06c...e1253824e5c10ff9df46874f81ed3ec929e19cfd">compare
view</a></li>
</ul>
</details>
<br />

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
canary/v2026.1002.0-canary.11
2026-10-02 07:47:01 -07:00
DottaandPaperclip e00d10d5d5 fix(connections): repair stale AI defaults from agent settings (#14916)
## Thinking Path

> - Paperclip manages AI agents and controls the credentials used for
their work.
> - Managed AI connections resolve each responsible user's provider
default.
> - Agent settings created another account but kept the old default
selected.
> - A rejected provider test left the old account marked as connected.
> - Claude ACP reported a typed login failure as a generic
terminal-access error.
> - This pull request repairs the selected account or selects the new
login explicitly.
> - Agents can save and run with the repaired credential, and failed
logins request sign-in.

## Linked Issues or Issue Description

- Fixes #14831.
- Refs #13867. Environment failures remain separate from
credential-health failures.

## What Changed

- Add an agent-settings action to reconnect an unavailable personal
default in place. Keep its connection, grant, default, and agent access.
- State that a new account becomes the user's provider default. Select
its returned grant before changing the agent binding. Keep the actual
sign-in method.
- Show default-update errors and allow retry without another provider
login.
- Show the agent-access choice. Connection managers start with
company-wide access for their own tasks. Other members start with access
for the current agent.
- Use the server's connection-manager permission in the shared list
response. This includes members with a custom management grant.
- Mark credentials as needing attention after an explicit login
rejection in Test or Save. This includes API-key 401 and 403 responses.
Network, quota, and server failures keep the credential health
unchanged.
- Reuse the credential-generation check so an old failure cannot
invalidate a newer reconnect.
- Route Claude's typed provider `access` failure to the existing
login-recovery flow. Replace its generic terminal-access fallback with a
sign-in message.
- Add regression tests and update the AI Connections documentation.

## Verification

- Red: the UI tests failed on the missing reconnect action, unused
returned grant, missing access choice, and lost default-update error.
The server tests failed because rejected credentials stayed connected.
The real ACP fixture returned `acpx_turn_failed` for typed login
failures.
- Green: 156 tests passed across the AI connection, hiring, agent field,
and New Agent suites. All 37 environment-route tests passed. The Claude
ACP authentication fixtures also passed.
- `pnpm check:token-gates` passed.
- `pnpm -r typecheck` passed.
- `pnpm build` passed.
- The full local `pnpm test:run` passed 707 files and 14,503 tests, then
exited with an agent-conversation timeout and embedded PostgreSQL
startup failures in unchanged suites. The isolated conversation and
migration tests passed on rerun. Later local test groups did not run
after this failure.
- [All CI gates
passed](https://github.com/paperclipai/paperclip/actions/runs/37012669356)
on commit `38513dfe2`. This includes the full test matrix, browser
tests, typecheck, build, Runner checks, and canary dry run.
- Greptile reviewed commit `38513dfe2` and returned 5/5 with no open
findings.
- The regression tests use a real embedded database and a real ACP
fixture process. Live provider sign-in requires a valid account and was
not run.

## Risks

- Connecting a new account from agent settings changes the user's
provider default. The dialog states this before sign-in.
- The displayed access choice can allow all company agents to use the
account for its owner's tasks. Reconnect keeps the existing access.
Server permissions still control installs.
- Claude's typed `access` category maps to the provider's
`auth_required` signal. Tool and workspace request failures retain their
existing classification.
- No database migration or provider credential format changes are
required.

## Model Used

- OpenAI GPT-6 through Codex. The exact served model identifier and
context window are not exposed in this session. Capabilities used:
reasoning, repository tools, code editing, and command execution.

## Checklist

- [x] I have included a thinking path that traces from project context
to this change
- [x] I have specified the model used (with version and capability
details)
- [x] I have checked ROADMAP.md and confirmed this PR does not duplicate
planned core work
- [x] I have searched GitHub for duplicate or related PRs and linked
them above
- [x] I have either (a) linked existing issues with `Fixes: #` / `Closes
#` / `Refs #` OR (b) described the issue in-PR following the relevant
issue template
- [x] I have not referenced internal/instance-local Paperclip issues or
links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip`
URLs)
- [x] My branch name describes the change (e.g. `docs/...`, `fix/...`)
and contains no internal Paperclip ticket id or instance-derived details
- [x] I have run tests locally and they pass
- [x] I have added or updated tests where applicable
- [x] I have updated relevant documentation to reflect my changes
- [x] I have considered and documented any risks above
- [x] All Paperclip CI gates are green
- [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups
- [x] I will address all Greptile and reviewer comments before
requesting merge

---------

Co-authored-by: Paperclip <noreply@paperclip.ing>
canary/v2026.1002.0-canary.10
2026-10-02 08:57:52 -05:00
DottaandPaperclip 408f70e69f fix(runner): preserve stock Codex base instructions (#14920)
## Thinking Path

> - Paperclip is the open source app people use to manage AI agents for
work.
> - The native Runner connects Paperclip tasks to Codex app-server.
> - Paperclip passed its runtime context as `baseInstructions`.
> - That field replaces the stock Codex base prompt.
> - This pull request sends the same Paperclip context as additive
developer instructions.
> - Codex keeps its stock prompt and still receives Paperclip task
instructions and tools.

## Linked Issues or Issue Description

**What happened?**

The native Codex driver and Rust provider sent Paperclip context through
`baseInstructions` on thread start and resume. Codex used this text in
place of its stock base instructions. Direct-chat resume also sent an
empty replacement base. The Runner Lab session path used the same
replacement field.

**Expected behavior**

Codex should retain its stock base prompt. Paperclip should add its
runtime context through `developerInstructions`. Other provider facades
should retain their current instruction handling.

**Steps to reproduce**

1. Create a native Codex session through Paperclip Runner.
2. Inspect the `thread/start` request in the native provider trace.
3. Resume the session and inspect `thread/resume`.
4. Before this fix, these paths set `baseInstructions`. After this fix,
the Codex paths set `developerInstructions` and omit `baseInstructions`.

**Paperclip version or commit**

Reproduced against master at `cad26c6bfb736039c8ed5743da650a44792a083c`.

**Deployment mode**

Built from source. Native Codex app-server and runnerd paths. A local
protocol probe used codex-cli 0.153.4 and a localhost Responses stub.

No duplicate fix or matching public issue was found in the GitHub
search.

## What Changed

- Send additive developer instructions on Codex start and resume in the
TypeScript driver, Rust provider, and Runner Lab session path.
- Carry the additive fragment through runnerd, including runtime asset
path mapping.
- Preserve existing instruction fields for other provider facades,
including OpenCode.
- Add start/resume/direct-chat regression coverage and check the actual
Rust provider request.
- Document the historical option and trace field names. Record progress
and follow-ups in the working checklist.

## Verification

- `pnpm -r typecheck` — passed.
- `pnpm build` — passed.
- Targeted Codex driver lifecycle, driver, and live-session Vitest
suites — 139 tests passed.
- `cargo test --manifest-path
packages/paperclip-runner/runner/Cargo.toml --locked -p
paperclip-runner-core --test codex_provider` — 91 passed, 2 ignored
subprocess helpers.
- Real app-server probe: a localhost Responses stub captured identical
14,732-character stock base instructions on fresh start and cold resume.
Both requests retained the Paperclip marker in developer input. Both
stub turns completed. No paid inference was used.
- Runnerd transport Vitest suite — 182 tests passed.
- The initial `pnpm test:run` attempt reported local dependency-loading,
embedded PostgreSQL startup, and macOS `/var` versus `/private/var` path
failures. It was stopped after those failures. Loading-suite reruns
passed 1,428 tests after the build; native interaction/finalization
reruns passed 38 tests. A seven-suite diagnostic rerun passed 463 tests
and isolated the remaining path and PostgreSQL setup failures.
- With `TMPDIR=/private/tmp`, workspace, gateway, interaction, and
attachment suites passed all 356 tests. The remaining environment-image
and native-session-resumption suites passed all 44 tests with the same
canonical temp path. All affected suites passed on rerun. The original
full local command was stopped after failures and is not claimed as
passing.
- All 55 PR checks passed at `83281439456181396f3707eecda5d2ebc90bd14d`.
Greptile scored 5/5 with no open review threads.
- No paid live campaign or Product E2E browser suite was run. This
change has protocol and regression coverage; it does not claim improved
task quality.

## Risks

- Stock Codex behavior may differ from behavior under the previous
Paperclip replacement prompt. Restoring that behavior is the intended
change.
- Existing Codex threads retain their saved replacement base prompt.
They need a provider session reset to receive the stock base. This PR
does not reset active sessions or alter recovery rules.
- The legacy `baseInstructions` option and trace field names remain for
compatibility. They now describe the additive Paperclip fragment for
Codex.
- The separate Codex-through-ACP dependency patch remains a follow-up in
the harness coverage checklist. This PR covers native app-server
execution.

## Model Used

OpenAI Codex, GPT-6. The exact runtime model variant and context window
are not exposed in this session. Used reasoning, repository inspection,
code editing, shell execution, and test tools.

## Checklist

- [x] I have included a thinking path that traces from project context
to this change
- [x] I have specified the model used (with version and capability
details)
- [x] I have checked ROADMAP.md and confirmed this PR does not duplicate
planned core work
- [x] I have searched GitHub for duplicate or related PRs and linked
them above
- [x] I have either (a) linked existing issues with `Fixes: #` / `Closes
#` / `Refs #` OR (b) described the issue in-PR following the relevant
issue template
- [x] I have not referenced internal/instance-local Paperclip issues or
links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip`
URLs)
- [x] My branch name describes the change (e.g. `docs/...`, `fix/...`)
and contains no internal Paperclip ticket id or instance-derived details
- [x] I have run tests locally and they pass
- [x] I have added or updated tests where applicable
- [x] I have updated relevant documentation to reflect my changes
- [x] I have considered and documented any risks above
- [x] All Paperclip CI gates are green
- [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups
- [x] I will address all Greptile and reviewer comments before
requesting merge

---------

Co-authored-by: Paperclip <noreply@paperclip.ing>
2026-10-02 08:53:47 -05:00
DottaandPaperclip c46e41e81c fix(heartbeat): validate native MCP gateway ownership (#14914)
## Thinking Path

> - Paperclip lets people manage agents and govern their tool access.
> - Native runs receive an immutable MCP tool assignment for one agent.
> - The gateway must enforce that owner when it authenticates a run
token.
> - Older gateway rows stored the owner only in metadata.
> - This change validates the gateway and profile, binds new rows, and
repairs valid older rows on reuse.
> - It also delivers each native assignment once.
> - Other agents cannot use the assignment, and explicit shared gateways
keep their configured scope.

## Linked Issues or Issue Description

Builds on #14012 by @busla (Jón Levy). That PR adds agent binding and
seven regressions. This PR carries that fix onto current master and adds
legacy authentication, profile validation, and duplicate-delivery
coverage. Related: #14864 improves discovery memory use.

**What happened?**
Native gateway creation stored an owner in metadata but left `agentId`
null. Authentication could therefore accept another agent's run token.
Managed discovery could also deliver historical native assignments
again.

**Expected behavior**
A native assignment accepts only its owner's run token. The gateway and
profile must refer to the same immutable assignment. The current
assignment enters the run configuration once.

**Steps to reproduce**
1. Run the database fixtures in `heartbeat-runtime-mcp-servers.test.ts`
on the baseline.
2. Create a native assignment and inspect its stored gateway owner.
3. Authenticate with another agent's run token, then inspect legacy
reuse and managed delivery.
4. The baseline fails six ownership and delivery cases. The fix passes
all twelve cases.

**Paperclip version or commit**
The red baseline is `f2e0f1963`. This PR is based on `cad26c6bf`, which
includes the merged discovery fix.

**Deployment mode**
Native Paperclip Runner execution and managed Codex MCP delivery.
Reproduction uses isolated database and HTTP fixtures.

## What Changed

- Store the agent owner and agent context on new native gateways.
- Validate profile and gateway assignment metadata before reuse or token
creation.
- Bind valid legacy rows with a company-scoped, null-owner update and
validate the result.
- Reject mismatched run tokens before legacy repair.
- Identify native assignments by gateway metadata, the reserved profile
key, or profile source. Reject missing or malformed provenance,
including JSON null.
- Exclude historical native assignments from managed gateway delivery.
Keep their rows for existing runs.
- Add twelve database and HTTP regressions and document the runtime
contract.

## Verification

- Red baseline: six regressions fail and four controls pass before the
initial fix. Two additional regressions reproduce metadata-loss
admission and a JSON-null TypeError before the review fix.
- All twelve ownership regressions pass on the final code, including
owner admission, cross-agent rejection, metadata loss, JSON-null HTTP
401, and explicit shared-gateway admission. Policy, listing-memory, and
discovery HTTP coverage also passes.
- Full workspace typecheck and build pass locally. Server typecheck and
compilation pass again after the review fix. The final ownership and
grant patches pass 42 combined database and HTTP regressions.
- [Full
CI](https://github.com/paperclipai/paperclip/actions/runs/37011383657)
passes for `626a08ae66361cf586105877e24d806b1a7a9c20`: all 54 checks
succeed; two optional Storybook checks skip. This includes full
typecheck, build, all test shards, all eight E2E shards, runner
verification, and the canary dry run.
- Greptile scores that exact head 5/5. No review threads remain
unresolved.

## Risks

Invalid historical native gateway or profile metadata now rejects
authentication. Valid unbound rows are repaired only when their owner
reuses the assignment. Conflicting owners are never overwritten.
Historical rows are retained for existing runs. Explicit shared gateways
use ordinary profiles and keep their configured scopes. The reserved
native profile namespace remains agent-owned even when gateway metadata
is cleared. No schema or dependency changes are included.

## Model Used

Original fix and seven regressions in #14012: Anthropic Claude Opus 5.5,
`claude-opus-5-5`, 1M context, as reported by @busla. Extensions and
verification: OpenAI Codex (GPT-6), with reasoning, repository
inspection, code execution, and tests. This session does not expose the
exact serving model identifier or context window.

## Checklist

- [x] I have included a thinking path that traces from project context
to this change
- [x] I have specified the model used (with version and capability
details)
- [x] I have checked ROADMAP.md and confirmed this PR does not duplicate
planned core work
- [x] I have searched GitHub for duplicate or related PRs and linked
them above
- [x] I have either (a) linked existing issues with `Fixes: #` / `Closes
#` / `Refs #` OR (b) described the issue in-PR following the relevant
issue template
- [x] I have not referenced internal/instance-local Paperclip issues or
links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip`
URLs)
- [x] My branch name describes the change (e.g. `docs/...`, `fix/...`)
and contains no internal Paperclip ticket id or instance-derived details
- [x] I have run tests locally and they pass
- [x] I have added or updated tests where applicable
- [x] I have updated relevant documentation to reflect my changes
- [x] I have considered and documented any risks above
- [x] All Paperclip CI gates are green
- [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups
- [x] I will address all Greptile and reviewer comments before
requesting merge

---------

Co-authored-by: Paperclip <noreply@paperclip.ing>
canary/v2026.1002.0-canary.9
2026-10-02 08:22:33 -05:00
DottaandPaperclip 483dbc8890 fix(tool-access): enforce stored grant restrictions (#14915)
## Thinking Path

> - Paperclip governs the tools that agents can discover and call.
> - Stored grants can limit access to a tool, connection, or
application.
> - The grant matcher must enforce every restriction in that scope.
> - A nonmatching allow list fell through to a policy selector matcher
that ignores allow.
> - This change requires an explicit allow match and validates
additional selectors.
> - Malformed and unknown restrictions deny access.
> - Discovery and execution now enforce the same stored grant limits.

## Linked Issues or Issue Description

Related: #14864 adds the shared database and HTTP discovery fixture used
here. Searched existing public PRs for tool grant scope fixes. No
duplicate scope-validation fix was found.

**What happened?**
A stored grant with a nonmatching `scope.allow` could authorize a tool.
Empty or malformed allow lists, unknown selectors, and combined
mismatching selectors could also authorize access. The fallback policy
matcher does not validate stored grant JSON.

**Expected behavior**
An explicit allow list must match the requested tool, connection, or
application. Every additional selector must also match. Unknown or
malformed restrictions must deny access. Existing null and empty-object
scopes keep their broad grant behavior.

**Steps to reproduce**
1. Run `tool-grant-scope.test.ts` on the baseline.
2. Create a deny profile and a grant that names another tool.
3. Attempt discovery or a call for the tool outside the grant.
4. The baseline authorizes access. The fix denies it.

**Paperclip version or commit**
The red baseline is `f2e0f1963`. This PR is based on `cad26c6bf`, which
includes the merged discovery fix.

**Deployment mode**
The company-scoped MCP gateway. Reproduction uses isolated database
fixtures and a deterministic HTTP provider.

## What Changed

- Require an explicit allow entry to match the gateway or upstream tool
name, connection, or application.
- Apply all additional selectors after the allow match.
- Reject unknown selectors, invalid value types, empty restrictions, and
non-object scopes.
- Preserve null and empty-object scope compatibility.
- Add sixteen regressions, including discovery, successful execution,
and revocation through the HTTP gateway.
- Document stored grant scope behavior.

## Verification

- Red baseline: seven restricted-scope cases and three malformed-root
cases fail. HTTP discovery also exposes tools outside the grant.
- All 16 grant regressions and 35 adjacent policy tests pass locally.
The HTTP test excludes an ungranted tool from discovery, returns 403 for
its call, and verifies that no provider call occurs. It also checks
successful execution and later revocation.
- Server typecheck passes. The final ownership and grant patches also
pass 42 combined database and HTTP regressions.
- [Full
CI](https://github.com/paperclipai/paperclip/actions/runs/37011177989)
passes for `803fa9440111742672c94c4471e5b98f15dd3b97`: all 54 checks
succeed; two optional Storybook checks skip. This includes full
typecheck, build, all test shards, all eight E2E shards, runner
verification, and the canary dry run.
- Greptile scores that exact head 5/5. No review threads remain
unresolved.

## Risks

Stored scopes with unknown keys or malformed restrictions now deny
access. Operators must correct those grants before they can authorize
tools. Null and empty-object scopes keep their previous broad behavior.
There are no schema, dependency, or API changes.

## Model Used

OpenAI Codex (GPT-6), with reasoning, repository inspection, code
execution, database regressions, and HTTP tests. This session does not
expose the exact serving model identifier or context window.

## Checklist

- [x] I have included a thinking path that traces from project context
to this change
- [x] I have specified the model used (with version and capability
details)
- [x] I have checked ROADMAP.md and confirmed this PR does not duplicate
planned core work
- [x] I have searched GitHub for duplicate or related PRs and linked
them above
- [x] I have either (a) linked existing issues with `Fixes: #` / `Closes
#` / `Refs #` OR (b) described the issue in-PR following the relevant
issue template
- [x] I have not referenced internal/instance-local Paperclip issues or
links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip`
URLs)
- [x] My branch name describes the change (e.g. `docs/...`, `fix/...`)
and contains no internal Paperclip ticket id or instance-derived details
- [x] I have run tests locally and they pass
- [x] I have added or updated tests where applicable
- [x] I have updated relevant documentation to reflect my changes
- [x] I have considered and documented any risks above
- [x] All Paperclip CI gates are green
- [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups
- [x] I will address all Greptile and reviewer comments before
requesting merge

---------

Co-authored-by: Paperclip <noreply@paperclip.ing>
2026-10-02 08:21:40 -05:00
cad26c6bfb fix(tool-gateway): bound MCP discovery memory and concurrency (#14864)
## Thinking Path

> - Paperclip is the open source app people use to manage AI agents for
work.
> - Agents discover governed tools through the MCP gateway.
> - A listing repeated policy and full run-row reads for each catalog
tool.
> - Parallel listings multiplied those allocations during run startup.
> - One 900-tool baseline listing used 11,489 queries and about 1.7 GiB
of extra heap in a fixture.
> - This pull request shares reads within a listing and bounds whole
listings across the process.
> - The benefit is lower discovery memory use while execution still
checks current policy.

## Linked Issues or Issue Description

Refs #13115. Its on-demand target change affects the same listing loop.

**What happened?**

MCP discovery repeated roughly 13 reads per tool. Full run snapshots and
repeated connection configurations caused large allocations. Per-listing
bounds alone did not limit concurrent listings across gateways.

**Expected behavior**

Discovery reads shared inputs once per listing. The process bounds
active and queued listings. Catalog payload size and policy evaluation
still grow with the catalog. Tool execution checks current access rules.

**Steps to reproduce**

Create a company with a remote MCP connection, 900 catalog tools, large
schemas, and a large run snapshot. Send concurrent tools/list requests
using a run-bound gateway token. Run the committed benchmark for a
deterministic reproduction.

**Paperclip version or commit**

Baseline: f2e0f19630. Measured on Node
26.4.0 on macOS.

## What Changed

- Keep Michael Nguyen's per-listing policy cache, scalar policy reads,
16-decision bound, and catalog/connection split under repeatable read.
- Admit two whole listings per process and queue at most 32. Return 503
with tool_discovery_busy when full.
- Propagate disconnects to discovery. Stop scheduling new reads and
drain started reads before freeing the slot.
- Project context IDs in gateway authentication and GitHub runtime
discovery. Avoid loading task descriptions and results.
- Keep discovery audit counts and a SHA-256 digest instead of the full
name list. Retain access and activity audit records.
- Sweep expired named gateway tokens at startup and on the existing
scheduler. Delete at most 500 per pass. Add an idempotent expiry-index
migration. Resolve audit token references atomically so cleanup cannot
break admitted requests.
- Return GET 405 with Allow: POST on stateless MCP gateway and
runtime-tools endpoints. Keep runtime-tools authentication.
- Add red-green regressions, HTTP concurrency and policy-revocation
coverage, and browser approval assertions.
- Commit the benchmark harness, raw results, and resource-bound
documentation.

## Verification

- Baseline listing regressions failed with 722 queries for 50 tools and
6,422 for 500. The connection-row duplication regression also failed.
- Follow-up regressions failed before the fixes for full snapshot reads,
abandoned listings, full name-list audits, and expired tokens.
- Listing and scheduler tests: 14 pass. Existing gateway/policy suites
passed after preserving the cleanup return contract.
- Two HTTP journeys pass: initialize, GET/SSE rejection, 16 concurrent
500-tool listings, provider call, policy revocation, and denied retry.
Token cleanup during provider dispatch also completes successfully and
blocks subsequent requests.
- pnpm test:e2e tests/e2e/mcp-user-stories.spec.ts --grep
'@mcp-runnable': 8 pass. The approval journey clicks Allow once in the
browser. Review screenshots wait for loaded content.
- pnpm -r typecheck: passes. pnpm build: passes.
- The general server group completed with 14,755 passes and 18 failures.
The 17 startup mock failures were fixed; all 21 startup tests pass on
rerun. The one Discord timing failure passed on the unchanged baseline
and on rerun (74 tests). UI and CLI groups pass 7,632 tests. Shared and
skill groups pass 853 tests. The remaining database and adapter groups
pass 3,010 tests with one worker after a macOS shared-memory limit
interrupted a parallel run. All 149 serialized route files pass (2,762
tests).
- At 900 tools, one listing falls from 11,489 to 36 queries and from
about 1.7 GiB to 37 MiB of extra heap. Sixteen concurrent listings used
169–187 MiB of extra heap. Four connections used 39 queries per listing.
- Latest-head verification: 54 successful checks and two expected skips
on 5c0793090c. Fresh Greptile review: 5/5
with no unresolved threads.
- Reproduce with server/scripts/benchmark-tool-gateway-listing.ts. See
doc/mcp-discovery-performance.md and
doc/benchmarks/2026-10-01-mcp-discovery.json.

## Risks

- The process-wide FIFO queue can increase discovery latency. Excess
callers must retry 503 responses.
- Cancellation applies to discovery. Started database reads finish
before their slot is released.
- Audit consumers must use visibleToolCount and visibleToolsHash instead
of visibleTools.
- The expiry index can briefly lock the token table during migration.
Sweeps preserve unexpired and non-expiring tokens.
- Measurements use isolated fixtures and deterministic providers. They
do not establish a production heap limit or affected installation count.
Rate-limit reads remain uncached.

## Model Used

- Original listing optimization: Anthropic Claude Opus 5.5
(claude-opus-5-5), Claude Code, extended thinking and tool use, as
recorded by the original author.
- Follow-up fixes and verification: OpenAI Codex, GPT-6, with shell
execution, file edits, database fixtures, and browser tests. The exact
serving model ID and context window are not exposed in this session.

## Checklist

- [x] I have included a thinking path that traces from project context
to this change
- [x] I have specified the model used (with version and capability
details)
- [x] I have checked ROADMAP.md and confirmed this PR does not duplicate
planned core work
- [x] I have searched GitHub for duplicate or related PRs and linked
them above
- [x] I have either (a) linked existing issues with Fixes / Closes /
Refs OR (b) described the issue in-PR following the relevant issue
template
- [x] I have not referenced internal/instance-local Paperclip issues or
links
- [x] My branch name describes the change and contains no internal
Paperclip ticket id or instance-derived details
- [x] I have run tests locally and they pass
- [x] I have added or updated tests where applicable
- [x] I have updated relevant documentation to reflect my changes
- [x] I have considered and documented any risks above
- [x] All Paperclip CI gates are green
- [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups
- [x] I will address all Greptile and reviewer comments before
requesting merge

---------

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
Co-authored-by: Dotta <bippadotta@protonmail.com>
Co-authored-by: Paperclip <noreply@paperclip.ing>
canary/v2026.1002.0-canary.8
2026-10-02 07:45:27 -05:00
dependabot[bot] c83df091b1 build(deps): bump react-i18next from 17.0.12 to 17.0.15 (#12970)
Bumps [react-i18next](https://github.com/i18next/react-i18next) from
17.0.12 to 17.0.15.
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/i18next/react-i18next/blob/master/CHANGELOG.md">react-i18next's
changelog</a>.</em></p>
<blockquote>
<h2>17.0.15</h2>
<ul>
<li>fix(Trans): empty paired component tags now preserve a component's
single valid React-element child, whether supplied through a named
component map (<code>&lt;wrap&gt;&lt;/wrap&gt;</code>), a component
array (<code>&lt;0&gt;&lt;/0&gt;</code>), or indexed JSX children
(<code>&lt;1&gt;&lt;/1&gt;</code>). This matches the existing behavior
for two or more children and self-closing tags. React represents one JSX
child as an element and multiple children as an array; the previous
array-only check silently rendered the one-child case empty.
Compatibility note: when that sole element contains an interpolation
object, the restored raw children can expose an existing React rendering
limitation as an error instead of silently rendering empty; the same
shape already errors with two children. Fixes <a
href="https://redirect.github.com/i18next/react-i18next/issues/1932">#1932</a>.</li>
</ul>
<h2>17.0.14</h2>
<ul>
<li>fix: the <code>i18n</code> object returned by
<code>useTranslation</code> was only refreshed when
<code>i18n.language</code> changed, so a <code>resolvedLanguage</code>
(or <code>languages</code>) change of its own kept handing components
the previous snapshot. That happens whenever the translations for the
current language arrive after the switch — i18next resolves to the
fallback until its store has them — and components reading
<code>i18n.resolvedLanguage</code> (language switchers, for example)
then stayed one switch behind. The cached wrapper is now keyed on all
three language fields, which are exactly the ones the surrounding
<code>useMemo</code> already depends on; wrapper identity still only
changes when the language state does, so the caching from <a
href="https://redirect.github.com/i18next/react-i18next/issues/1885">#1885</a>
is unaffected. Reported via <a
href="https://redirect.github.com/i18next/next-i18next/issues/2348">next-i18next#2348</a>.</li>
</ul>
<h2>17.0.13</h2>
<ul>
<li>fix(types): the selector-form <code>keyPrefix</code> overload of
<code>useTranslation()</code> is now available under
<code>enableSelector: 'strict'</code>. <code>useTranslation</code> was
gated on <code>true | 'optimize'</code> only, so under
<code>'strict'</code> it resolved to the legacy signature and the
selector overload disappeared entirely (<code>keyPrefix: ($) =&gt;
$.ns.foo</code> failed with <code>Type '($: any) =&gt; any' is not
assignable to type 'undefined'</code>). <code>Trans</code> already
handled all three modes. Companion to the same fix for
<code>getFixedT</code> in <a
href="https://redirect.github.com/i18next/i18next/pull/2446">i18next#2446</a>.
Thanks <a
href="https://github.com/hovelopin"><code>@​hovelopin</code></a> (<a
href="https://redirect.github.com/i18next/react-i18next/pull/1930">#1930</a>).</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/i18next/react-i18next/commit/7d38e0919507f0d339ac29b9fbd5f718eaadc829"><code>7d38e09</code></a>
17.0.15</li>
<li><a
href="https://github.com/i18next/react-i18next/commit/875b327d3515c781cd083dd77d3d8838dc1efc06"><code>875b327</code></a>
fix(Trans): preserve single-element children in empty slots</li>
<li><a
href="https://github.com/i18next/react-i18next/commit/5f8c5f9e6c7cdabdc476111d0748c91e33bbaa30"><code>5f8c5f9</code></a>
17.0.14</li>
<li><a
href="https://github.com/i18next/react-i18next/commit/6def81a790ddc55cc6c09a9f306ea6c88e25867c"><code>6def81a</code></a>
fix: refresh the returned i18n wrapper when resolvedLanguage
changes</li>
<li><a
href="https://github.com/i18next/react-i18next/commit/f37ea872c74e74ca64a5b6652cc131893405770b"><code>f37ea87</code></a>
docs: &quot;For AI assistants&quot; paragraph in the README</li>
<li><a
href="https://github.com/i18next/react-i18next/commit/e0592bafde1a904588c115f67b36cddf382e49c5"><code>e0592ba</code></a>
chore: keep dev-only and local files out of the npm package</li>
<li><a
href="https://github.com/i18next/react-i18next/commit/addf646a37f5980af08814b5a2568def28e7e428"><code>addf646</code></a>
17.0.13</li>
<li><a
href="https://github.com/i18next/react-i18next/commit/7c634ee3f396af22ec7b5c3c647b8d5ab198b5ae"><code>7c634ee</code></a>
changelog v17.0.13</li>
<li><a
href="https://github.com/i18next/react-i18next/commit/5ceefb0eff8bb430c658b21e5a08b457e78d87df"><code>5ceefb0</code></a>
fix(types): allow selector keyPrefix in useTranslation under
enableSelector '...</li>
<li><a
href="https://github.com/i18next/react-i18next/commit/aa7ba520255753c50d7fff9ab33ce0c7a60a45a2"><code>aa7ba52</code></a>
chore(examples): require activesupport &gt;= 7.2.3.1 in the RN
Gemfiles</li>
<li>Additional commits viewable in <a
href="https://github.com/i18next/react-i18next/compare/v17.0.12...v17.0.15">compare
view</a></li>
</ul>
</details>
<br />

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
nightly/v2026.1002.0-nightly.0 canary/v2026.1002.0-canary.7
2026-10-01 22:06:28 -07:00
dependabot[bot] f48bbba2ba build(deps): bump @assistant-ui/react from 0.15.21 to 0.15.22 (#12971)
Bumps
[@assistant-ui/react](https://github.com/assistant-ui/assistant-ui/tree/HEAD/packages/react)
from 0.15.21 to 0.15.22.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/assistant-ui/assistant-ui/releases">@​assistant-ui/react's
releases</a>.</em></p>
<blockquote>
<h2><code>@​assistant-ui/react</code><a
href="https://github.com/0"><code>@​0</code></a>.15.22</h2>
<h3>Patch Changes</h3>
<ul>
<li>
<p><a
href="https://redirect.github.com/assistant-ui/assistant-ui/pull/8032">#8032</a>
<a
href="https://github.com/assistant-ui/assistant-ui/commit/d09680175b062b26c393aa274bf4068012b82a9c"><code>d096801</code></a>
- fix: type the assistant transport request body that
<code>prepareSendCommandsRequest</code> receives; its fields are no
longer <code>unknown</code> in <code>@assistant-ui/react</code>, and
<code>threadId</code> is an optional <code>string</code>, absent when a
resume has no remote id, instead of <code>string | null</code> (<a
href="https://github.com/apps/rupic-app"><code>@​rupic-app</code></a>)</p>
</li>
<li>
<p><a
href="https://redirect.github.com/assistant-ui/assistant-ui/pull/8342">#8342</a>
<a
href="https://github.com/assistant-ui/assistant-ui/commit/aa0f33854f1d054ca747710d2144ba9e77c3182e"><code>aa0f338</code></a>
- feat: <code>useAssistantTransportRuntime</code> accepts
<code>cloud</code>: Assistant Cloud backs the thread list and every
request carries the cloud thread id; without <code>cloud</code>,
<code>NEXT_PUBLIC_ASSISTANT_BASE_URL</code> selects Assistant Cloud, as
it does for <code>useLocalRuntime</code>. <code>adapters.history</code>,
which this runtime never read, is deprecated (<a
href="https://github.com/okisdev"><code>@​okisdev</code></a>)</p>
</li>
<li>
<p><a
href="https://redirect.github.com/assistant-ui/assistant-ui/pull/7731">#7731</a>
<a
href="https://github.com/assistant-ui/assistant-ui/commit/455e2ac67bbcb7329d3f8367daf409eac5bc3a27"><code>455e2ac</code></a>
- fix: lock the current scroll container after reasoning content or its
ancestor chain changes (<a
href="https://github.com/Kinfe123"><code>@​Kinfe123</code></a>)</p>
</li>
<li>
<p><a
href="https://redirect.github.com/assistant-ui/assistant-ui/pull/7730">#7730</a>
<a
href="https://github.com/assistant-ui/assistant-ui/commit/af49e91648334569ac36a94f602a66b6dbe031dc"><code>af49e91</code></a>
- fix: prevent stale message hover updates after unmount (<a
href="https://github.com/Kinfe123"><code>@​Kinfe123</code></a>)</p>
</li>
<li>
<p><a
href="https://redirect.github.com/assistant-ui/assistant-ui/pull/7737">#7737</a>
<a
href="https://github.com/assistant-ui/assistant-ui/commit/6cc0bee320a1eccc855b4140249b8ac552010472"><code>6cc0bee</code></a>
- fix: scope selection toolbars to their owning thread (<a
href="https://github.com/Kinfe123"><code>@​Kinfe123</code></a>)</p>
</li>
<li>
<p><a
href="https://redirect.github.com/assistant-ui/assistant-ui/pull/8339">#8339</a>
<a
href="https://github.com/assistant-ui/assistant-ui/commit/967de5db4ca0c876bff20bffb783167651357cdd"><code>967de5d</code></a>
- feat: <code>CloudRendererHost</code> draws a stored conversation in
the Assistant Cloud dashboard's As shown view with the app's own
components; a read only thread now reports itself disabled, so its
composer renders disabled, and ignores composer input instead of
throwing (<a
href="https://github.com/okisdev"><code>@​okisdev</code></a>)</p>
</li>
<li>
<p><a
href="https://redirect.github.com/assistant-ui/assistant-ui/pull/8030">#8030</a>
<a
href="https://github.com/assistant-ui/assistant-ui/commit/e8fac8d7e2eef1b2eee8ccb98dd9d69d03619ae3"><code>e8fac8d</code></a>
- feat: show a message with uploading attachments in the thread while it
is being sent (<a
href="https://github.com/okisdev"><code>@​okisdev</code></a>)</p>
<p><code>MessagePrimitive.Attachments</code> now hands its render
function <code>Attachment</code> rather than
<code>CompleteAttachment</code>, because the row of a message that is
still being sent shows attachments that are still uploading. a render
function that reads <code>attachment.content</code> should check
<code>attachment.status.type === &quot;complete&quot;</code> first.</p>
</li>
<li>
<p><a
href="https://redirect.github.com/assistant-ui/assistant-ui/pull/7877">#7877</a>
<a
href="https://github.com/assistant-ui/assistant-ui/commit/83f53542e7f91d1b93489e534b40151ca34094a8"><code>83f5354</code></a>
- fix: honor registered data-part fallbacks on native MessageContent and
grouped parts (<a
href="https://github.com/Kinfe123"><code>@​Kinfe123</code></a>)</p>
</li>
<li>
<p><a
href="https://redirect.github.com/assistant-ui/assistant-ui/pull/7760">#7760</a>
<a
href="https://github.com/assistant-ui/assistant-ui/commit/84e0cf4c9b7fc92a85d1360b37e2e20b73bed650"><code>84e0cf4</code></a>
- fix: emit declarations from one TypeScript program so two builds of
the same commit produce the same <code>.d.ts</code> (<a
href="https://github.com/okisdev"><code>@​okisdev</code></a>)</p>
<p><code>aui-build</code> now emits the unbundled <code>.d.ts</code>
output in one TypeScript pass over the whole package, so two builds of
the same commit produce identical declarations; the per-module emit it
replaced followed the bundler's load order and let union member order,
alias visibility and import specifiers move between builds. Declarations
import barrels as the source does and keep <code>import type</code>; the
exported types are unchanged. A <code>/// &lt;reference&gt;</code>
directive that must reach the published declarations now carries
<code>preserve=&quot;true&quot;</code> in the source.</p>
</li>
<li>
<p><a
href="https://redirect.github.com/assistant-ui/assistant-ui/pull/7838">#7838</a>
<a
href="https://github.com/assistant-ui/assistant-ui/commit/3d01501c5642b7b0a4f1094a5a0b93976d02eed7"><code>3d01501</code></a>
- fix: every distribution re-exports the same shared surface from
<code>@assistant-ui/core</code>. <code>@assistant-ui/react-ink</code>
gains <code>ReadonlyThreadProvider</code>,
<code>ToolCallMessagePartStatus</code>, <code>groupPartByType</code>,
<code>GroupByContext</code>, <code>VoiceSessionState</code>, the
external store runtime (<code>useExternalStoreRuntime</code>,
<code>useExternalMessageConverter</code>, their adapters and options),
the message queue, the tool approval types, the generative UI renderer
and the cloud thread list hooks; <code>@assistant-ui/react-native</code>
gains <code>VoiceSessionState</code>, the cloud thread list hooks, the
generative UI renderer and the runtime state and adapter types the web
package already carried; <code>@assistant-ui/react</code> gains
<code>MessageRole</code>, <code>RunConfig</code>,
<code>RuntimeCapabilities</code>, <code>RemoteThreadListOptions</code>,
<code>ThreadsState</code>, <code>JoinStrategy</code>,
<code>TitleGenerationAdapter</code>,
<code>createSimpleTitleAdapter</code> and
<code>ChainOfThoughtPartByIndexProvider</code>. (<a
href="https://github.com/okisdev"><code>@​okisdev</code></a>)</p>
</li>
<li>
<p><a
href="https://redirect.github.com/assistant-ui/assistant-ui/pull/7520">#7520</a>
<a
href="https://github.com/assistant-ui/assistant-ui/commit/2171a8e06b8ca739a98eba927ab8b27175dd7be6"><code>2171a8e</code></a>
- fix(react): attach the ExportMarkdown download anchor to the document
so Firefox starts the download (<a
href="https://github.com/Kinfe123"><code>@​Kinfe123</code></a>)</p>
</li>
<li>
<p><a
href="https://redirect.github.com/assistant-ui/assistant-ui/pull/8010">#8010</a>
<a
href="https://github.com/assistant-ui/assistant-ui/commit/1c86c4c9e9cd4f7b2a27efd089d779831e54c2f0"><code>1c86c4c</code></a>
- fix: prevent disabled attachment dropzones from navigating to dropped
files. (<a
href="https://github.com/Kinfe123"><code>@​Kinfe123</code></a>)</p>
</li>
<li>
<p><a
href="https://redirect.github.com/assistant-ui/assistant-ui/pull/7733">#7733</a>
<a
href="https://github.com/assistant-ui/assistant-ui/commit/e2f13068534f9ca2d526a4e683846db7d6f2ec3b"><code>e2f1306</code></a>
- fix: clear attachment drag state when the dropzone is disabled (<a
href="https://github.com/Kinfe123"><code>@​Kinfe123</code></a>)</p>
</li>
<li>
<p><a
href="https://redirect.github.com/assistant-ui/assistant-ui/pull/7897">#7897</a>
<a
href="https://github.com/assistant-ui/assistant-ui/commit/16ef5b3e1f982a392c00a9a90b291c02e6c6fc5c"><code>16ef5b3</code></a>
- fix(react): stop a pending bottom scroll from hijacking
keyboard-driven content growth (<a
href="https://github.com/Kinfe123"><code>@​Kinfe123</code></a>)</p>
</li>
<li>
<p><a
href="https://redirect.github.com/assistant-ui/assistant-ui/pull/7762">#7762</a>
<a
href="https://github.com/assistant-ui/assistant-ui/commit/49283649b9119d8fe3acbc7bd2703d3473a98e9b"><code>4928364</code></a>
- fix: resolve component registries by own keys only, so a component,
tool or data part name that only <code>Object.prototype</code> has
(<code>toString</code>, <code>constructor</code>,
<code>__proto__</code>) takes the <code>Fallback</code> or
<code>GenerativeUIRenderError</code> path instead of rendering the
inherited built-in (<a
href="https://github.com/okisdev"><code>@​okisdev</code></a>)</p>
</li>
<li>
<p><a
href="https://redirect.github.com/assistant-ui/assistant-ui/pull/7725">#7725</a>
<a
href="https://github.com/assistant-ui/assistant-ui/commit/258ad136d849f67c06207cd8cfd944364c1e59cf"><code>258ad13</code></a>
- fix: expose feedback submission state to assistive technology (<a
href="https://github.com/apps/rupic-app"><code>@​rupic-app</code></a>)</p>
</li>
<li>
<p><a
href="https://redirect.github.com/assistant-ui/assistant-ui/pull/7981">#7981</a>
<a
href="https://github.com/assistant-ui/assistant-ui/commit/0252c6966322f09eda17172bfcaab8c641529bcf"><code>0252c69</code></a>
- feat: name the runtime state types <code>ThreadRuntimeState</code>,
<code>MessageRuntimeState</code>, <code>ComposerRuntimeState</code>,
<code>AttachmentRuntimeState</code> and
<code>ThreadListItemRuntimeState</code> (<a
href="https://github.com/okisdev"><code>@​okisdev</code></a>)</p>
<p>these are the states <code>ThreadRuntime</code>,
<code>MessageRuntime</code>, <code>ComposerRuntime</code>,
<code>AttachmentRuntime</code> and <code>ThreadListItemRuntime</code>
return from <code>getState()</code>, now exported by all three
distributions; <code>@assistant-ui/react-native</code> and
<code>@assistant-ui/react-ink</code> had no name for them. in
<code>@assistant-ui/react</code>, <code>ThreadState</code>,
<code>MessageState</code>, <code>ComposerState</code>,
<code>AttachmentState</code> and <code>ThreadListItemState</code> still
name these runtime states but are deprecated: from 0.16 they name the
store states <code>useAuiState</code> reads, as they already do in
<code>@assistant-ui/react-native</code> and
<code>@assistant-ui/react-ink</code>. code that annotates a runtime's
<code>getState()</code> result should move to the new names.</p>
</li>
<li>
<p><a
href="https://redirect.github.com/assistant-ui/assistant-ui/pull/8149">#8149</a>
<a
href="https://github.com/assistant-ui/assistant-ui/commit/1b1ff55c227a8bf58d6413ec8b248162540acc19"><code>1b1ff55</code></a>
- fix(react): keep the selection toolbar in sync after a right-click, so
a context menu that swallows the mouseup no longer leaves it showing
(and quoting) the previous selection (<a
href="https://github.com/samdickson22"><code>@​samdickson22</code></a>)</p>
</li>
<li>
<p><a
href="https://redirect.github.com/assistant-ui/assistant-ui/pull/8065">#8065</a>
<a
href="https://github.com/assistant-ui/assistant-ui/commit/2caacadf195a30efe04aaff8b46679ad99e70e74"><code>2caacad</code></a>
- feat: a tool UI can record what the user did on its tool call with
<code>unstable_recordInteraction</code>, kept on the part as
<code>unstable_interactions</code> and stored in cloud history; the
answer to a human input request is recorded once the runtime accepts it,
the local runtime persists records and keeps them out of model input,
external stores receive them through
<code>unstable_onRecordToolInteraction</code>, and readonly threads
ignore them (<a
href="https://github.com/okisdev"><code>@​okisdev</code></a>)</p>
</li>
<li>
<p><a
href="https://redirect.github.com/assistant-ui/assistant-ui/pull/7068">#7068</a>
<a
href="https://github.com/assistant-ui/assistant-ui/commit/4b069f90fbcb58953ebc7b9c4becca0bf4607842"><code>4b069f9</code></a>
- fix: Use successful Standard Schema output for tool execution and
model output. Keep the original arguments for validation errors and
stored tool calls. (<a
href="https://github.com/ephraimduncan"><code>@​ephraimduncan</code></a>)</p>
</li>
<li>
<p><a
href="https://redirect.github.com/assistant-ui/assistant-ui/pull/7777">#7777</a>
<a
href="https://github.com/assistant-ui/assistant-ui/commit/c51ba8fb3014375ae62784084aaefe3ecc6d72fa"><code>c51ba8f</code></a>
- feat(core): let typed text enter a connected voice session through
<code>sendText</code> (<a
href="https://github.com/okisdev"><code>@​okisdev</code></a>)</p>
</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/assistant-ui/assistant-ui/blob/main/packages/react/CHANGELOG.md">@​assistant-ui/react's
changelog</a>.</em></p>
<blockquote>
<h2>0.15.22</h2>
<h3>Patch Changes</h3>
<ul>
<li>
<p><a
href="https://redirect.github.com/assistant-ui/assistant-ui/pull/8032">#8032</a>
<a
href="https://github.com/assistant-ui/assistant-ui/commit/d09680175b062b26c393aa274bf4068012b82a9c"><code>d096801</code></a>
- fix: type the assistant transport request body that
<code>prepareSendCommandsRequest</code> receives; its fields are no
longer <code>unknown</code> in <code>@assistant-ui/react</code>, and
<code>threadId</code> is an optional <code>string</code>, absent when a
resume has no remote id, instead of <code>string | null</code> (<a
href="https://github.com/apps/rupic-app"><code>@​rupic-app</code></a>)</p>
</li>
<li>
<p><a
href="https://redirect.github.com/assistant-ui/assistant-ui/pull/8342">#8342</a>
<a
href="https://github.com/assistant-ui/assistant-ui/commit/aa0f33854f1d054ca747710d2144ba9e77c3182e"><code>aa0f338</code></a>
- feat: <code>useAssistantTransportRuntime</code> accepts
<code>cloud</code>: Assistant Cloud backs the thread list and every
request carries the cloud thread id; without <code>cloud</code>,
<code>NEXT_PUBLIC_ASSISTANT_BASE_URL</code> selects Assistant Cloud, as
it does for <code>useLocalRuntime</code>. <code>adapters.history</code>,
which this runtime never read, is deprecated (<a
href="https://github.com/okisdev"><code>@​okisdev</code></a>)</p>
</li>
<li>
<p><a
href="https://redirect.github.com/assistant-ui/assistant-ui/pull/7731">#7731</a>
<a
href="https://github.com/assistant-ui/assistant-ui/commit/455e2ac67bbcb7329d3f8367daf409eac5bc3a27"><code>455e2ac</code></a>
- fix: lock the current scroll container after reasoning content or its
ancestor chain changes (<a
href="https://github.com/Kinfe123"><code>@​Kinfe123</code></a>)</p>
</li>
<li>
<p><a
href="https://redirect.github.com/assistant-ui/assistant-ui/pull/7730">#7730</a>
<a
href="https://github.com/assistant-ui/assistant-ui/commit/af49e91648334569ac36a94f602a66b6dbe031dc"><code>af49e91</code></a>
- fix: prevent stale message hover updates after unmount (<a
href="https://github.com/Kinfe123"><code>@​Kinfe123</code></a>)</p>
</li>
<li>
<p><a
href="https://redirect.github.com/assistant-ui/assistant-ui/pull/7737">#7737</a>
<a
href="https://github.com/assistant-ui/assistant-ui/commit/6cc0bee320a1eccc855b4140249b8ac552010472"><code>6cc0bee</code></a>
- fix: scope selection toolbars to their owning thread (<a
href="https://github.com/Kinfe123"><code>@​Kinfe123</code></a>)</p>
</li>
<li>
<p><a
href="https://redirect.github.com/assistant-ui/assistant-ui/pull/8339">#8339</a>
<a
href="https://github.com/assistant-ui/assistant-ui/commit/967de5db4ca0c876bff20bffb783167651357cdd"><code>967de5d</code></a>
- feat: <code>CloudRendererHost</code> draws a stored conversation in
the Assistant Cloud dashboard's As shown view with the app's own
components; a read only thread now reports itself disabled, so its
composer renders disabled, and ignores composer input instead of
throwing (<a
href="https://github.com/okisdev"><code>@​okisdev</code></a>)</p>
</li>
<li>
<p><a
href="https://redirect.github.com/assistant-ui/assistant-ui/pull/8030">#8030</a>
<a
href="https://github.com/assistant-ui/assistant-ui/commit/e8fac8d7e2eef1b2eee8ccb98dd9d69d03619ae3"><code>e8fac8d</code></a>
- feat: show a message with uploading attachments in the thread while it
is being sent (<a
href="https://github.com/okisdev"><code>@​okisdev</code></a>)</p>
<p><code>MessagePrimitive.Attachments</code> now hands its render
function <code>Attachment</code> rather than
<code>CompleteAttachment</code>, because the row of a message that is
still being sent shows attachments that are still uploading. a render
function that reads <code>attachment.content</code> should check
<code>attachment.status.type === &quot;complete&quot;</code> first.</p>
</li>
<li>
<p><a
href="https://redirect.github.com/assistant-ui/assistant-ui/pull/7877">#7877</a>
<a
href="https://github.com/assistant-ui/assistant-ui/commit/83f53542e7f91d1b93489e534b40151ca34094a8"><code>83f5354</code></a>
- fix: honor registered data-part fallbacks on native MessageContent and
grouped parts (<a
href="https://github.com/Kinfe123"><code>@​Kinfe123</code></a>)</p>
</li>
<li>
<p><a
href="https://redirect.github.com/assistant-ui/assistant-ui/pull/7760">#7760</a>
<a
href="https://github.com/assistant-ui/assistant-ui/commit/84e0cf4c9b7fc92a85d1360b37e2e20b73bed650"><code>84e0cf4</code></a>
- fix: emit declarations from one TypeScript program so two builds of
the same commit produce the same <code>.d.ts</code> (<a
href="https://github.com/okisdev"><code>@​okisdev</code></a>)</p>
<p><code>aui-build</code> now emits the unbundled <code>.d.ts</code>
output in one TypeScript pass over the whole package, so two builds of
the same commit produce identical declarations; the per-module emit it
replaced followed the bundler's load order and let union member order,
alias visibility and import specifiers move between builds. Declarations
import barrels as the source does and keep <code>import type</code>; the
exported types are unchanged. A <code>/// &lt;reference&gt;</code>
directive that must reach the published declarations now carries
<code>preserve=&quot;true&quot;</code> in the source.</p>
</li>
<li>
<p><a
href="https://redirect.github.com/assistant-ui/assistant-ui/pull/7838">#7838</a>
<a
href="https://github.com/assistant-ui/assistant-ui/commit/3d01501c5642b7b0a4f1094a5a0b93976d02eed7"><code>3d01501</code></a>
- fix: every distribution re-exports the same shared surface from
<code>@assistant-ui/core</code>. <code>@assistant-ui/react-ink</code>
gains <code>ReadonlyThreadProvider</code>,
<code>ToolCallMessagePartStatus</code>, <code>groupPartByType</code>,
<code>GroupByContext</code>, <code>VoiceSessionState</code>, the
external store runtime (<code>useExternalStoreRuntime</code>,
<code>useExternalMessageConverter</code>, their adapters and options),
the message queue, the tool approval types, the generative UI renderer
and the cloud thread list hooks; <code>@assistant-ui/react-native</code>
gains <code>VoiceSessionState</code>, the cloud thread list hooks, the
generative UI renderer and the runtime state and adapter types the web
package already carried; <code>@assistant-ui/react</code> gains
<code>MessageRole</code>, <code>RunConfig</code>,
<code>RuntimeCapabilities</code>, <code>RemoteThreadListOptions</code>,
<code>ThreadsState</code>, <code>JoinStrategy</code>,
<code>TitleGenerationAdapter</code>,
<code>createSimpleTitleAdapter</code> and
<code>ChainOfThoughtPartByIndexProvider</code>. (<a
href="https://github.com/okisdev"><code>@​okisdev</code></a>)</p>
</li>
<li>
<p><a
href="https://redirect.github.com/assistant-ui/assistant-ui/pull/7520">#7520</a>
<a
href="https://github.com/assistant-ui/assistant-ui/commit/2171a8e06b8ca739a98eba927ab8b27175dd7be6"><code>2171a8e</code></a>
- fix(react): attach the ExportMarkdown download anchor to the document
so Firefox starts the download (<a
href="https://github.com/Kinfe123"><code>@​Kinfe123</code></a>)</p>
</li>
<li>
<p><a
href="https://redirect.github.com/assistant-ui/assistant-ui/pull/8010">#8010</a>
<a
href="https://github.com/assistant-ui/assistant-ui/commit/1c86c4c9e9cd4f7b2a27efd089d779831e54c2f0"><code>1c86c4c</code></a>
- fix: prevent disabled attachment dropzones from navigating to dropped
files. (<a
href="https://github.com/Kinfe123"><code>@​Kinfe123</code></a>)</p>
</li>
<li>
<p><a
href="https://redirect.github.com/assistant-ui/assistant-ui/pull/7733">#7733</a>
<a
href="https://github.com/assistant-ui/assistant-ui/commit/e2f13068534f9ca2d526a4e683846db7d6f2ec3b"><code>e2f1306</code></a>
- fix: clear attachment drag state when the dropzone is disabled (<a
href="https://github.com/Kinfe123"><code>@​Kinfe123</code></a>)</p>
</li>
<li>
<p><a
href="https://redirect.github.com/assistant-ui/assistant-ui/pull/7897">#7897</a>
<a
href="https://github.com/assistant-ui/assistant-ui/commit/16ef5b3e1f982a392c00a9a90b291c02e6c6fc5c"><code>16ef5b3</code></a>
- fix(react): stop a pending bottom scroll from hijacking
keyboard-driven content growth (<a
href="https://github.com/Kinfe123"><code>@​Kinfe123</code></a>)</p>
</li>
<li>
<p><a
href="https://redirect.github.com/assistant-ui/assistant-ui/pull/7762">#7762</a>
<a
href="https://github.com/assistant-ui/assistant-ui/commit/49283649b9119d8fe3acbc7bd2703d3473a98e9b"><code>4928364</code></a>
- fix: resolve component registries by own keys only, so a component,
tool or data part name that only <code>Object.prototype</code> has
(<code>toString</code>, <code>constructor</code>,
<code>__proto__</code>) takes the <code>Fallback</code> or
<code>GenerativeUIRenderError</code> path instead of rendering the
inherited built-in (<a
href="https://github.com/okisdev"><code>@​okisdev</code></a>)</p>
</li>
<li>
<p><a
href="https://redirect.github.com/assistant-ui/assistant-ui/pull/7725">#7725</a>
<a
href="https://github.com/assistant-ui/assistant-ui/commit/258ad136d849f67c06207cd8cfd944364c1e59cf"><code>258ad13</code></a>
- fix: expose feedback submission state to assistive technology (<a
href="https://github.com/apps/rupic-app"><code>@​rupic-app</code></a>)</p>
</li>
<li>
<p><a
href="https://redirect.github.com/assistant-ui/assistant-ui/pull/7981">#7981</a>
<a
href="https://github.com/assistant-ui/assistant-ui/commit/0252c6966322f09eda17172bfcaab8c641529bcf"><code>0252c69</code></a>
- feat: name the runtime state types <code>ThreadRuntimeState</code>,
<code>MessageRuntimeState</code>, <code>ComposerRuntimeState</code>,
<code>AttachmentRuntimeState</code> and
<code>ThreadListItemRuntimeState</code> (<a
href="https://github.com/okisdev"><code>@​okisdev</code></a>)</p>
<p>these are the states <code>ThreadRuntime</code>,
<code>MessageRuntime</code>, <code>ComposerRuntime</code>,
<code>AttachmentRuntime</code> and <code>ThreadListItemRuntime</code>
return from <code>getState()</code>, now exported by all three
distributions; <code>@assistant-ui/react-native</code> and
<code>@assistant-ui/react-ink</code> had no name for them. in
<code>@assistant-ui/react</code>, <code>ThreadState</code>,
<code>MessageState</code>, <code>ComposerState</code>,
<code>AttachmentState</code> and <code>ThreadListItemState</code> still
name these runtime states but are deprecated: from 0.16 they name the
store states <code>useAuiState</code> reads, as they already do in
<code>@assistant-ui/react-native</code> and
<code>@assistant-ui/react-ink</code>. code that annotates a runtime's
<code>getState()</code> result should move to the new names.</p>
</li>
<li>
<p><a
href="https://redirect.github.com/assistant-ui/assistant-ui/pull/8149">#8149</a>
<a
href="https://github.com/assistant-ui/assistant-ui/commit/1b1ff55c227a8bf58d6413ec8b248162540acc19"><code>1b1ff55</code></a>
- fix(react): keep the selection toolbar in sync after a right-click, so
a context menu that swallows the mouseup no longer leaves it showing
(and quoting) the previous selection (<a
href="https://github.com/samdickson22"><code>@​samdickson22</code></a>)</p>
</li>
<li>
<p><a
href="https://redirect.github.com/assistant-ui/assistant-ui/pull/8065">#8065</a>
<a
href="https://github.com/assistant-ui/assistant-ui/commit/2caacadf195a30efe04aaff8b46679ad99e70e74"><code>2caacad</code></a>
- feat: a tool UI can record what the user did on its tool call with
<code>unstable_recordInteraction</code>, kept on the part as
<code>unstable_interactions</code> and stored in cloud history; the
answer to a human input request is recorded once the runtime accepts it,
the local runtime persists records and keeps them out of model input,
external stores receive them through
<code>unstable_onRecordToolInteraction</code>, and readonly threads
ignore them (<a
href="https://github.com/okisdev"><code>@​okisdev</code></a>)</p>
</li>
<li>
<p><a
href="https://redirect.github.com/assistant-ui/assistant-ui/pull/7068">#7068</a>
<a
href="https://github.com/assistant-ui/assistant-ui/commit/4b069f90fbcb58953ebc7b9c4becca0bf4607842"><code>4b069f9</code></a>
- fix: Use successful Standard Schema output for tool execution and
model output. Keep the original arguments for validation errors and
stored tool calls. (<a
href="https://github.com/ephraimduncan"><code>@​ephraimduncan</code></a>)</p>
</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/assistant-ui/assistant-ui/commit/f008537f39f0936992b0f6d2433c092935df5faf"><code>f008537</code></a>
chore: update versions (<a
href="https://github.com/assistant-ui/assistant-ui/tree/HEAD/packages/react/issues/7724">#7724</a>)</li>
<li><a
href="https://github.com/assistant-ui/assistant-ui/commit/967de5db4ca0c876bff20bffb783167651357cdd"><code>967de5d</code></a>
feat(react): CloudRendererHost draws a stored conversation in the
dashboard's...</li>
<li><a
href="https://github.com/assistant-ui/assistant-ui/commit/1b1ff55c227a8bf58d6413ec8b248162540acc19"><code>1b1ff55</code></a>
fix(react): keep the selection toolbar quoting what is selected after a
right...</li>
<li><a
href="https://github.com/assistant-ui/assistant-ui/commit/2caacadf195a30efe04aaff8b46679ad99e70e74"><code>2caacad</code></a>
feat(core): record the user's interactions with a tool ui on its tool
call (#...</li>
<li><a
href="https://github.com/assistant-ui/assistant-ui/commit/e8fac8d7e2eef1b2eee8ccb98dd9d69d03619ae3"><code>e8fac8d</code></a>
feat(core): show a message with uploading attachments while it is sent
(<a
href="https://github.com/assistant-ui/assistant-ui/tree/HEAD/packages/react/issues/8030">#8030</a>)</li>
<li><a
href="https://github.com/assistant-ui/assistant-ui/commit/d09680175b062b26c393aa274bf4068012b82a9c"><code>d096801</code></a>
fix: type the assistant transport body that prepareSendCommandsRequest
receiv...</li>
<li><a
href="https://github.com/assistant-ui/assistant-ui/commit/1c86c4c9e9cd4f7b2a27efd089d779831e54c2f0"><code>1c86c4c</code></a>
fix(react): claim file drops when attachment dropzone is disabled (<a
href="https://github.com/assistant-ui/assistant-ui/tree/HEAD/packages/react/issues/8010">#8010</a>)</li>
<li><a
href="https://github.com/assistant-ui/assistant-ui/commit/0252c6966322f09eda17172bfcaab8c641529bcf"><code>0252c69</code></a>
feat: name the runtime state types and deprecate their old names (<a
href="https://github.com/assistant-ui/assistant-ui/tree/HEAD/packages/react/issues/7981">#7981</a>)</li>
<li><a
href="https://github.com/assistant-ui/assistant-ui/commit/15937b8844db7757d3595d5644bc27196e742f4a"><code>15937b8</code></a>
test(react): skip the initial viewport scroll in the MessageRoot hover
test (...</li>
<li><a
href="https://github.com/assistant-ui/assistant-ui/commit/16ef5b3e1f982a392c00a9a90b291c02e6c6fc5c"><code>16ef5b3</code></a>
fix(react): cancel pending bottom scroll on a keyboard gesture (<a
href="https://github.com/assistant-ui/assistant-ui/tree/HEAD/packages/react/issues/7897">#7897</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/assistant-ui/assistant-ui/commits/@assistant-ui/react@0.15.22/packages/react">compare
view</a></li>
</ul>
</details>
<br />

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
canary/v2026.1002.0-canary.6
2026-10-01 21:36:32 -07:00
dependabot[bot] 3934fd14e5 build(deps-dev): bump @storybook/addon-docs from 10.5.10 to 10.6.0 (#12972)
Bumps
[@storybook/addon-docs](https://github.com/storybookjs/storybook/tree/HEAD/code/addons/docs)
from 10.5.10 to 10.6.0.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/storybookjs/storybook/releases">@​storybook/addon-docs's
releases</a>.</em></p>
<blockquote>
<h2>v10.6.0</h2>
<h2>10.6.0</h2>
<blockquote>
<p>New skills architecture for agentic workflows</p>
</blockquote>
<p>Storybook 10.6 contains hundreds of fixes and improvements:</p>
<ul>
<li>💻 CLI bindings for agent tools/skills</li>
<li>🅰️ Angular-Vite MCP/skills support and improved docgen/snippets
(experimental)</li>
<li>🟢 Vue MCP/skills support and improved docgen/snippets
(experimental)</li>
<li>🧩 Tanstack / NextJS-Vite framework bugfixes</li>
<li>⚡ Improved performance and reduced bundle size</li>
</ul>
<!-- raw HTML omitted -->
<ul>
<li>Addon MCP: Stop silently dropping composed refs from MCP composition
- <a
href="https://redirect.github.com/storybookjs/storybook/pull/36077">#36077</a>,
thanks <a
href="https://github.com/kasperpeulen"><code>@​kasperpeulen</code></a>!</li>
<li>Addon Vitest: Pin storybook/test in optimizeDeps so its CJS-only
deps are prebundled - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35572">#35572</a>,
thanks <a
href="https://github.com/Nic-Polumeyv"><code>@​Nic-Polumeyv</code></a>!</li>
<li>Addon Vitest: Report test runs with failures as failed tool outcomes
- <a
href="https://redirect.github.com/storybookjs/storybook/pull/36080">#36080</a>,
thanks <a
href="https://github.com/kasperpeulen"><code>@​kasperpeulen</code></a>!</li>
<li>Addon Vitest: Resolve story test globs against the project root - <a
href="https://redirect.github.com/storybookjs/storybook/pull/36103">#36103</a>,
thanks <a
href="https://github.com/kasperpeulen"><code>@​kasperpeulen</code></a>!</li>
<li>Addon-vitest: Filter Storybook instrumentation from reported stack
traces - <a
href="https://redirect.github.com/storybookjs/storybook/pull/36120">#36120</a>,
thanks <a
href="https://github.com/ghengeveld"><code>@​ghengeveld</code></a>!</li>
<li>Angular Vite: Resolve tsConfig against the workspace root - <a
href="https://redirect.github.com/storybookjs/storybook/pull/36026">#36026</a>,
thanks <a
href="https://github.com/ndelangen"><code>@​ndelangen</code></a>!</li>
<li>Angular-Vite: Run Compodoc on demand - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35776">#35776</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Add an in-process docgen analyzer, replacing Compodoc under
the flag - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35805">#35805</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Bind only what the component accepts in story snippets, and
report the rest - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35943">#35943</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Decide the migration's zone.js import from the dependency
tree - <a
href="https://redirect.github.com/storybookjs/storybook/pull/36008">#36008</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Declare story args the snippet markup binds by name - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35895">#35895</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Declare style preprocessors as optional peers and name the
missing one - <a
href="https://redirect.github.com/storybookjs/storybook/pull/36098">#36098</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Derive required inputs from Compodoc's own flag - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35758">#35758</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Extract Compodoc parsing into its own package - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35749">#35749</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Extract component JSDoc through TypeScript's APIs - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35977">#35977</a>,
thanks <a
href="https://github.com/huang-julien"><code>@​huang-julien</code></a>!</li>
<li>Angular: Extract docgen on the server via Compodoc - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35733">#35733</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Fix component resolution, MCP output, and dev/build path
aliasing - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35952">#35952</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Fix eight upgrade and migration bugs - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35946">#35946</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Fix ten docgen bugs found across 22 community repositories
- <a
href="https://redirect.github.com/storybookjs/storybook/pull/35941">#35941</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Generate story-docs snippets from the analyzer - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35807">#35807</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Give agents real input and output documentation - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35896">#35896</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Hide class internals from the props table by default - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35887">#35887</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Install the `@storybook/angular-vite` peers that nothing
else brings in - <a
href="https://redirect.github.com/storybookjs/storybook/pull/36002">#36002</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Keep the function control on constructor and generic
signatures - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35921">#35921</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Make experimentalDocgenServer the default in angular-vite -
<a
href="https://redirect.github.com/storybookjs/storybook/pull/35886">#35886</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Migrate Analog projects to angular-vite instead of refusing
them - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35971">#35971</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Print unevaluable story args instead of slicing the file -
<a
href="https://redirect.github.com/storybookjs/storybook/pull/35888">#35888</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Read the story shapes that supply their own markup - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35797">#35797</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Render self-closing tags in server-side docs snippets - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35953">#35953</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Render the required badge for required inputs in the props
table - <a
href="https://redirect.github.com/storybookjs/storybook/pull/36065">#36065</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Resolve `@angular/core` through the package manager, not
the raw specifier - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35999">#35999</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Resolve builder `styles` the way the Angular builders do -
<a
href="https://redirect.github.com/storybookjs/storybook/pull/35998">#35998</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Resolve builder styles against the workspace root - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35974">#35974</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Skip the runtime source decorator when the docgen server
produces snippets - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35906">#35906</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/storybookjs/storybook/blob/next/CHANGELOG.md">@​storybook/addon-docs's
changelog</a>.</em></p>
<blockquote>
<h2>10.6.0</h2>
<blockquote>
<p>New skills architecture for agentic workflows</p>
</blockquote>
<p>Storybook 10.6 contains hundreds of fixes and improvements:</p>
<ul>
<li>💻 CLI bindings for agent tools/skills</li>
<li>🅰️ Angular-Vite MCP/skills support and improved docgen/snippets
(experimental)</li>
<li>🟢 Vue MCP/skills support and improved docgen/snippets
(experimental)</li>
<li>🧩 Tanstack / NextJS-Vite framework bugfixes</li>
<li>⚡ Improved performance and reduced bundle size</li>
</ul>
<!-- raw HTML omitted -->
<ul>
<li>Addon MCP: Stop silently dropping composed refs from MCP composition
- <a
href="https://redirect.github.com/storybookjs/storybook/pull/36077">#36077</a>,
thanks <a
href="https://github.com/kasperpeulen"><code>@​kasperpeulen</code></a>!</li>
<li>Addon Vitest: Pin storybook/test in optimizeDeps so its CJS-only
deps are prebundled - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35572">#35572</a>,
thanks <a
href="https://github.com/Nic-Polumeyv"><code>@​Nic-Polumeyv</code></a>!</li>
<li>Addon Vitest: Report test runs with failures as failed tool outcomes
- <a
href="https://redirect.github.com/storybookjs/storybook/pull/36080">#36080</a>,
thanks <a
href="https://github.com/kasperpeulen"><code>@​kasperpeulen</code></a>!</li>
<li>Addon Vitest: Resolve story test globs against the project root - <a
href="https://redirect.github.com/storybookjs/storybook/pull/36103">#36103</a>,
thanks <a
href="https://github.com/kasperpeulen"><code>@​kasperpeulen</code></a>!</li>
<li>Addon-vitest: Filter Storybook instrumentation from reported stack
traces - <a
href="https://redirect.github.com/storybookjs/storybook/pull/36120">#36120</a>,
thanks <a
href="https://github.com/ghengeveld"><code>@​ghengeveld</code></a>!</li>
<li>Angular Vite: Resolve tsConfig against the workspace root - <a
href="https://redirect.github.com/storybookjs/storybook/pull/36026">#36026</a>,
thanks <a
href="https://github.com/ndelangen"><code>@​ndelangen</code></a>!</li>
<li>Angular-Vite: Run Compodoc on demand - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35776">#35776</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Add an in-process docgen analyzer, replacing Compodoc under
the flag - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35805">#35805</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Bind only what the component accepts in story snippets, and
report the rest - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35943">#35943</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Decide the migration's zone.js import from the dependency
tree - <a
href="https://redirect.github.com/storybookjs/storybook/pull/36008">#36008</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Declare story args the snippet markup binds by name - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35895">#35895</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Declare style preprocessors as optional peers and name the
missing one - <a
href="https://redirect.github.com/storybookjs/storybook/pull/36098">#36098</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Derive required inputs from Compodoc's own flag - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35758">#35758</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Extract Compodoc parsing into its own package - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35749">#35749</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Extract component JSDoc through TypeScript's APIs - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35977">#35977</a>,
thanks <a
href="https://github.com/huang-julien"><code>@​huang-julien</code></a>!</li>
<li>Angular: Extract docgen on the server via Compodoc - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35733">#35733</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Fix component resolution, MCP output, and dev/build path
aliasing - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35952">#35952</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Fix eight upgrade and migration bugs - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35946">#35946</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Fix ten docgen bugs found across 22 community repositories
- <a
href="https://redirect.github.com/storybookjs/storybook/pull/35941">#35941</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Generate story-docs snippets from the analyzer - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35807">#35807</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Give agents real input and output documentation - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35896">#35896</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Hide class internals from the props table by default - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35887">#35887</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Install the <code>@storybook/angular-vite</code> peers that
nothing else brings in - <a
href="https://redirect.github.com/storybookjs/storybook/pull/36002">#36002</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Keep the function control on constructor and generic
signatures - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35921">#35921</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Make experimentalDocgenServer the default in angular-vite -
<a
href="https://redirect.github.com/storybookjs/storybook/pull/35886">#35886</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Migrate Analog projects to angular-vite instead of refusing
them - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35971">#35971</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Print unevaluable story args instead of slicing the file -
<a
href="https://redirect.github.com/storybookjs/storybook/pull/35888">#35888</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Read the story shapes that supply their own markup - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35797">#35797</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Render self-closing tags in server-side docs snippets - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35953">#35953</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Render the required badge for required inputs in the props
table - <a
href="https://redirect.github.com/storybookjs/storybook/pull/36065">#36065</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Resolve <code>@angular/core</code> through the package
manager, not the raw specifier - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35999">#35999</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Resolve builder <code>styles</code> the way the Angular
builders do - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35998">#35998</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Resolve builder styles against the workspace root - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35974">#35974</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Skip the runtime source decorator when the docgen server
produces snippets - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35906">#35906</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Stop marking a defaulted input as required in the props
table - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35899">#35899</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/storybookjs/storybook/commit/a77777356be2aeaff89d7a2b25254db7b2318392"><code>a777773</code></a>
Bump version from &quot;10.6.0-beta.3&quot; to &quot;10.6.0&quot; [skip
ci]</li>
<li><a
href="https://github.com/storybookjs/storybook/commit/f32b3667dad8df220cda0359e170bc49931af68c"><code>f32b366</code></a>
Bump version from &quot;10.6.0-beta.2&quot; to &quot;10.6.0-beta.3&quot;
[skip ci]</li>
<li><a
href="https://github.com/storybookjs/storybook/commit/0ad1336cbf0ecdab9f6b540570ae9015ae73ab86"><code>0ad1336</code></a>
Bump version from &quot;10.6.0-beta.1&quot; to &quot;10.6.0-beta.2&quot;
[skip ci]</li>
<li><a
href="https://github.com/storybookjs/storybook/commit/16359ee17802628c47915c21408cb578d2707b83"><code>16359ee</code></a>
Bump version from &quot;10.6.0-beta.0&quot; to &quot;10.6.0-beta.1&quot;
[skip ci]</li>
<li><a
href="https://github.com/storybookjs/storybook/commit/2e0e2f609d1351ba4384eb52e0728dc9cd8b275b"><code>2e0e2f6</code></a>
Bump version from &quot;10.6.0-alpha.9&quot; to
&quot;10.6.0-beta.0&quot; [skip ci]</li>
<li><a
href="https://github.com/storybookjs/storybook/commit/6a6dec2aedff6744a9d9226e1f6515e3d5e8b42a"><code>6a6dec2</code></a>
Bump version from &quot;10.6.0-alpha.8&quot; to
&quot;10.6.0-alpha.9&quot; [skip ci]</li>
<li><a
href="https://github.com/storybookjs/storybook/commit/cd2d16395a5ffa39189b96aafb6af67f280079db"><code>cd2d163</code></a>
Bump version from &quot;10.6.0-alpha.7&quot; to
&quot;10.6.0-alpha.8&quot; [skip ci]</li>
<li><a
href="https://github.com/storybookjs/storybook/commit/3bf4afdce8aba47cc7960d3a3e09a3fd1ceb2baa"><code>3bf4afd</code></a>
Merge branch 'next' into kasper/tools-cli-bootstrap-perf</li>
<li><a
href="https://github.com/storybookjs/storybook/commit/4ea0b1bc2c1a26ce061f5b44051e8f01273f27fa"><code>4ea0b1b</code></a>
refactor(docs): move anchorBlockIdFromId into docs-tools</li>
<li><a
href="https://github.com/storybookjs/storybook/commit/5c80681f18d273461e1b15cb775a77347079b0b0"><code>5c80681</code></a>
Merge pull request <a
href="https://github.com/storybookjs/storybook/tree/HEAD/code/addons/docs/issues/35965">#35965</a>
from storybookjs/valentin/sb-1804-surface-story-doc...</li>
<li>Additional commits viewable in <a
href="https://github.com/storybookjs/storybook/commits/v10.6.0/code/addons/docs">compare
view</a></li>
</ul>
</details>
<br />

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-10-01 21:14:09 -07:00
Devin FoleyandPaperclip 4e52463203 fix(daytona): recover output from stalled log streams (#14889)
## Thinking Path

> - Paperclip is the open source app people use to manage AI agents for
work.
> - The Daytona driver streams sandbox command output to the host.
> - A log socket can stop delivering bytes without closing or rejecting.
> - Missing permission requests and cancellation results can leave a run
active and block queued work.
> - This pull request switches an idle log stream to saved-output
polling for the same command.
> - The host can receive the missing output without another command
dispatch.

## Linked Issues or Issue Description

**What happened?**

The driver waits for the SDK log-stream promise before it can start
recovery. If that promise never settles, the host can miss new output
that is already in the provider's saved logs. A run can remain active
after a watch completes. Interrupt can then time out with “Execution is
still stopping; termination has not been verified.”

**Expected behavior**

Recover command observation when the live stream stalls. Forward new
permission requests and cancellation results. Require a recorded command
exit before reporting completion. Keep quiet commands running under the
caller's existing lifetime controls.

**Steps to reproduce**

1. Start a session command and leave the callback log promise pending.
2. Put new output in the snapshot API without invoking the stream
callback.
3. Keep the command running until the host receives that output, then
expose its cancellation output and exit code.
4. Verify that the host receives each byte once and dispatches the
command once.

**Paperclip version or commit**

Base commit `479554120d`.

**Agent adapter(s) involved**

Daytona session commands, including sandbox ACP agent sessions.

Related: #14799 handles closed streams; this change handles sockets that
never close. #14485 handles input delivery retries. #13262 adds
permission diagnostics.

## What Changed

- After 15 seconds with no stdout or stderr, switch directly to the
existing status and log-snapshot polling path.
- Ignore callbacks and delayed failures from the abandoned stream. Clear
its idle timer on every exit path.
- Preserve byte-offset deduplication, one command dispatch, and
independent timeouts for recovery reads.
- Add regressions for an initial stream stall, a stall after UTF-8
output, cancellation output, late callbacks, hung recovery reads, and
quiet commands that outlive an operation timeout.
- Update the provider documentation and keep hour-long healthy-stream
coverage active with periodic output.

## Verification

- `pnpm vitest run
packages/plugins/sandbox-providers/daytona/src/plugin.test.ts`: 245
passed.
- `pnpm exec vitest run --project @paperclipai/plugin-daytona`: 339
passed; 14 gated live tests skipped.
- Both new stalled-stream regressions fail on the unchanged base driver
because it never starts snapshot recovery. Both pass with this change.
- `pnpm -r typecheck`: passed.
- `pnpm build`: passed.
- `pnpm test:run`: the local run did not pass. It was stopped after
confirmed local skill-path and macOS skill-cache failures, once complete
PR CI was green. Four chat/email tests could not load connector skill
files from an ancestor directory outside the checkout. Three
company-skills tests hit macOS `EACCES` during cache publication. One
unrelated wakeup test timed out in the full run and passed on a focused
rerun (`1 passed`, `27 skipped`). No source or test assertions were
changed for these failures. This is not a complete local-suite pass.
- Complete PR CI on `11ac4e030b`: 53 successful checks, 2 expected
skips, no pending or failed checks. The clean CI run includes the full
test suite.
- Greptile reviewed `11ac4e030b` at 5/5 with no findings or unresolved
threads. The branch has no merge conflicts with `master`.
- `git diff --check` and a local scan for secrets and private
identifiers passed.

## Risks

- Quiet healthy commands also switch to polling. Full snapshots can
increase bandwidth as output grows; polling remains limited to one
snapshot per second.
- The SDK exposes no stream cancellation handle. The old socket remains
owned by session teardown, and its callbacks cannot publish after
fallback.
- This change recovers a stalled output stream. It does not claim to
identify every cause of an unanswered permission request or change the
requirement to verify termination before releasing work.
- No schema migration or command replay.

## Model Used

OpenAI GPT-6 through Codex, with tool use and code execution. The exact
serving model ID and context window are not exposed in this session.

## Checklist

- [x] I have included a thinking path that traces from project context
to this change
- [x] I have specified the model used (with version and capability
details)
- [x] I have checked ROADMAP.md and confirmed this PR does not duplicate
planned core work
- [x] I have searched GitHub for duplicate or related PRs and linked
them above
- [x] I have either (a) linked existing issues with `Fixes: #` /
`Closes: #` / `Refs: #` OR (b) described the issue in-PR following the
relevant issue template
- [x] I have not referenced internal/instance-local Paperclip issues or
links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip`
URLs)
- [x] My branch name describes the change (e.g. `docs/...`, `fix/...`)
and contains no internal Paperclip ticket id or instance-derived details
- [x] I have run local change-specific tests; the full suite passes in
CI, with local-suite limitations documented above
- [x] I have added or updated tests where applicable
- [x] I have updated relevant documentation to reflect my changes
- [x] I have considered and documented any risks above
- [x] All Paperclip CI gates are green
- [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups
- [x] I will address all Greptile and reviewer comments before
requesting merge

Co-authored-by: Paperclip <noreply@paperclip.ing>
canary/v2026.1002.0-canary.5
2026-10-01 21:04:41 -07:00
Devin Foleyandgithub-actions[bot] 261c24ccf9 docs(release): canonicalize stable notes for v2026.1001.0 (#14890)
## Thinking Path

> - Paperclip is the open source app people use to manage AI agents for
work
> - The release process keeps stable notes under a beta-keyed path
during the soak and renames them to the versioned path after the stable
ships
> - Stable v2026.1001.0 is published. The `canonicalize_stable_notes`
job pushed the rename branch but it does not open a pull request
> - The published notes also have no Contributors section. The previous
stable notes (v2026.916.0) have one
> - This pull request moves the notes to `releases/v2026.1001.0.md` and
adds the Contributors section
> - The benefit is that the repository returns to the canonical
release-notes layout and the external contributors get credit

## Linked Issues or Issue Description

**Issue type**

Missing content

**Where is the issue?**

`releases/` — the stable notes for v2026.1001.0 still live at the
beta-keyed path `releases/beta/v2026.921.0-beta.1.md`, and they have no
Contributors section.

**What's wrong?**

The `canonicalize_stable_notes` job in the stable release run pushed
branch `release-notes/v2026.1001.0-canonicalize` with the rename, but it
does not open a pull request. The notes also do not credit the three
external contributors in the release range.

**Suggested fix**

Merge the workflow's rename commit, plus one commit that appends a `##
Contributors` section in the same format as `releases/v2026.916.0.md`.

## What Changed

- Renamed `releases/beta/v2026.921.0-beta.1.md` to
`releases/v2026.1001.0.md` (workflow commit, no content changes)
- Appended a `## Contributors` section: 77 commits from 8 contributors,
with credits to @austinpilz, @hawikk, and @mouse-value-add
- No other content changed. The notes above the new section match the
published GitHub Release body for v2026.1001.0

## Verification

- `git log --follow releases/v2026.1001.0.md` shows the rename commit
followed by one commit that only appends the Contributors section
- `git rev-list --count v2026.916.1..v2026.1001.0` returns 77
- The author list of that range, minus maintainers and bots, is
@austinpilz, @hawikk, and @mouse-value-add
- The GitHub Release body for v2026.1001.0 is identical to this file
without the Contributors section

## Risks

- Low risk: a documentation-only rename plus one appended section.

## Model Used

- Claude (Anthropic), model ID `claude-fable-5-1` (Claude Fable 5.1),
extended thinking enabled, tool use via Claude Code

## Checklist

- [x] I have included a thinking path that traces from project context
to this change
- [x] I have specified the model used (with version and capability
details)
- [x] I have checked ROADMAP.md and confirmed this PR does not duplicate
planned core work
- [x] I have searched GitHub for duplicate or related PRs and linked
them above
- [x] I have either (a) linked existing issues with `Fixes: #` / `Closes
#` / `Refs #` OR (b) described the issue in-PR following the relevant
issue template
- [x] I have not referenced internal/instance-local Paperclip issues or
links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip`
URLs)
- [x] My branch name describes the change (e.g. `docs/...`, `fix/...`)
and contains no internal Paperclip ticket id or instance-derived details
- [x] I have run tests locally and they pass
- [x] I have added or updated tests where applicable
- [x] I have updated relevant documentation to reflect my changes
- [x] I have considered and documented any risks above
- [ ] All Paperclip CI gates are green
- [ ] Greptile is 5/5 with no open P2s, recommendations, or follow-ups
- [x] I will address all Greptile and reviewer comments before
requesting merge

---------

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
canary/v2026.1002.0-canary.4
2026-10-01 20:31:32 -07:00
dependabot[bot] 479554120d build(deps): bump i18next from 26.4.0 to 26.4.2 (#12973)
Bumps [i18next](https://github.com/i18next/i18next) from 26.4.0 to
26.4.2.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/i18next/i18next/releases">i18next's
releases</a>.</em></p>
<blockquote>
<h2>v26.4.2</h2>
<ul>
<li>fix: <code>$&amp;</code>, <code>$`</code>, <code>$'</code> and
<code>$$</code> inside a nested value (<code>$t(key)</code>) now stay
literal. <code>nest()</code> handed the resolved value straight to
<code>String.replace</code> as the replacement argument, so those
sequences were read as replacement patterns: <code>$&amp;</code>
re-inserted the <code>$t(...)</code> match, <code>$`</code> /
<code>$'</code> inserted the text before / after it, and <code>$$</code>
collapsed to <code>$</code>. Through <code>t()</code> the
<code>$&amp;</code> case was worse than a wrong string: the nested
lookup resets the shared nesting regexp, so the re-inserted
<code>$t(...)</code> was matched again on every pass and
<code>t()</code> never returned — also under the default
<code>escapeValue: true</code> when the value arrives via a variable
forwarded through nesting options (<code>$t(key, { &quot;name&quot;:
&quot;{{name}}&quot; })</code> with a name containing
<code>$&amp;</code>). The value is now <code>$</code>-escaped at the
<code>String.replace</code> call, the same guard
<code>interpolate()</code> already has, and a non-string value returned
by a formatter in the nesting chain (<code>$t(key, myFormat)</code>) is
stringified before that. Nested values are still not HTML-escaped (<a
href="https://redirect.github.com/i18next/i18next/issues/854">#854</a>).
Thanks <a href="https://github.com/mahirhir"><code>@​mahirhir</code></a>
(<a
href="https://redirect.github.com/i18next/i18next/pull/2447">#2447</a>).</li>
</ul>
<h2>v26.4.1</h2>
<ul>
<li>fix(types): the selector-form <code>keyPrefix</code> overload of
<code>getFixedT()</code> is now available under <code>enableSelector:
'strict'</code>. Its constraint was gated on <code>true |
'optimize'</code> only, so under <code>'strict'</code> it collapsed to
<code>never</code>, the overload dropped out, and the returned
<code>t</code> silently lost its <code>keyPrefix</code> scope
(<code>t(($) =&gt; $.deep)</code> failed with <code>Property 'deep' does
not exist on type '{}'</code>). The same call already typechecked under
<code>true</code> and <code>'optimize'</code>. Thanks <a
href="https://github.com/hovelopin"><code>@​hovelopin</code></a> (<a
href="https://redirect.github.com/i18next/i18next/pull/2446">#2446</a>).</li>
</ul>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/i18next/i18next/blob/master/CHANGELOG.md">i18next's
changelog</a>.</em></p>
<blockquote>
<h2>26.4.2</h2>
<ul>
<li>fix: <code>$&amp;</code>, <code>$`</code>, <code>$'</code> and
<code>$$</code> inside a nested value (<code>$t(key)</code>) now stay
literal. <code>nest()</code> handed the resolved value straight to
<code>String.replace</code> as the replacement argument, so those
sequences were read as replacement patterns: <code>$&amp;</code>
re-inserted the <code>$t(...)</code> match, <code>$`</code> /
<code>$'</code> inserted the text before / after it, and <code>$$</code>
collapsed to <code>$</code>. Through <code>t()</code> the
<code>$&amp;</code> case was worse than a wrong string: the nested
lookup resets the shared nesting regexp, so the re-inserted
<code>$t(...)</code> was matched again on every pass and
<code>t()</code> never returned — also under the default
<code>escapeValue: true</code> when the value arrives via a variable
forwarded through nesting options (<code>$t(key, { &quot;name&quot;:
&quot;{{name}}&quot; })</code> with a name containing
<code>$&amp;</code>). The value is now <code>$</code>-escaped at the
<code>String.replace</code> call, the same guard
<code>interpolate()</code> already has, and a non-string value returned
by a formatter in the nesting chain (<code>$t(key, myFormat)</code>) is
stringified before that. Nested values are still not HTML-escaped (<a
href="https://redirect.github.com/i18next/i18next/issues/854">#854</a>).
Thanks <a href="https://github.com/mahirhir"><code>@​mahirhir</code></a>
(<a
href="https://redirect.github.com/i18next/i18next/pull/2447">#2447</a>).</li>
</ul>
<h2>26.4.1</h2>
<ul>
<li>fix(types): the selector-form <code>keyPrefix</code> overload of
<code>getFixedT()</code> is now available under <code>enableSelector:
'strict'</code>. Its constraint was gated on <code>true |
'optimize'</code> only, so under <code>'strict'</code> it collapsed to
<code>never</code>, the overload dropped out, and the returned
<code>t</code> silently lost its <code>keyPrefix</code> scope
(<code>t(($) =&gt; $.deep)</code> failed with <code>Property 'deep' does
not exist on type '{}'</code>). The same call already typechecked under
<code>true</code> and <code>'optimize'</code>. Thanks <a
href="https://github.com/hovelopin"><code>@​hovelopin</code></a> (<a
href="https://redirect.github.com/i18next/i18next/pull/2446">#2446</a>).</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/i18next/i18next/commit/4dba50f20669c3678db0812255716eb7693ad2da"><code>4dba50f</code></a>
26.4.2</li>
<li><a
href="https://github.com/i18next/i18next/commit/e436b625a648e1a48ea27ecf5f2fba8020d67009"><code>e436b62</code></a>
build</li>
<li><a
href="https://github.com/i18next/i18next/commit/d955fb086e9f4ded1200f51ecbb21034dbad1d92"><code>d955fb0</code></a>
fix: stringify formatter results in nested values, changelog
v26.4.2</li>
<li><a
href="https://github.com/i18next/i18next/commit/dfafa3ca725e1415ef20e7fb5b1b3e4468f3c425"><code>dfafa3c</code></a>
fix: keep replacement patterns literal in nested values (<a
href="https://redirect.github.com/i18next/i18next/issues/2447">#2447</a>)</li>
<li><a
href="https://github.com/i18next/i18next/commit/3c9981e22dd471b6bca224aa1f60e04ba3f6153a"><code>3c9981e</code></a>
chore: keep dev-only and local files out of the npm package</li>
<li><a
href="https://github.com/i18next/i18next/commit/c057ee048c55a61c095acc017365e997e4f723f8"><code>c057ee0</code></a>
26.4.1</li>
<li><a
href="https://github.com/i18next/i18next/commit/02e3e1659b7cc9fedaaf53797597483ef8003df2"><code>02e3e16</code></a>
changelog v26.4.1</li>
<li><a
href="https://github.com/i18next/i18next/commit/6f198f2508ba8986d1bbf25a8b922d01afcf0751"><code>6f198f2</code></a>
fix(types): allow selector keyPrefix in getFixedT under enableSelector
'stric...</li>
<li>See full diff in <a
href="https://github.com/i18next/i18next/compare/v26.4.0...v26.4.2">compare
view</a></li>
</ul>
</details>
<br />

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
canary/v2026.1002.0-canary.3
2026-10-01 19:58:00 -07:00
dependabot[bot] b31ce54b81 build(deps): bump react-router-dom from 7.18.2 to 7.18.4 (#12974)
Bumps
[react-router-dom](https://github.com/remix-run/react-router/tree/HEAD/packages/react-router-dom)
from 7.18.2 to 7.18.4.
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/remix-run/react-router/blob/react-router-dom@7.18.4/packages/react-router-dom/CHANGELOG.md">react-router-dom's
changelog</a>.</em></p>
<blockquote>
<h2>v7.18.4</h2>
<h3>Patch Changes</h3>
<ul>
<li>Updated dependencies:
<ul>
<li><a
href="https://github.com/remix-run/react-router/releases/tag/react-router@7.18.4"><code>react-router@7.18.4</code></a></li>
</ul>
</li>
</ul>
<h2>v7.18.3</h2>
<h3>Patch Changes</h3>
<ul>
<li>Updated dependencies:
<ul>
<li><a
href="https://github.com/remix-run/react-router/releases/tag/react-router@7.18.3"><code>react-router@7.18.3</code></a></li>
</ul>
</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/remix-run/react-router/commit/1b1e0b0e79b21692ce907933475233babdd16e3e"><code>1b1e0b0</code></a>
Release v7.18.4 (<a
href="https://github.com/remix-run/react-router/tree/HEAD/packages/react-router-dom/issues/15498">#15498</a>)</li>
<li><a
href="https://github.com/remix-run/react-router/commit/23166dfe7f61323f0d2775af67d2691f9ed0843d"><code>23166df</code></a>
Release v7.18.3 (<a
href="https://github.com/remix-run/react-router/tree/HEAD/packages/react-router-dom/issues/15424">#15424</a>)</li>
<li>See full diff in <a
href="https://github.com/remix-run/react-router/commits/react-router-dom@7.18.4/packages/react-router-dom">compare
view</a></li>
</ul>
</details>
<br />

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-10-01 19:29:44 -07:00
Devin FoleyandPaperclip 4a999089ef Retry transient failures in dashboard reads (#14873)
## Thinking Path

> - Paperclip shows company activity in the dashboard.
> - The dashboard reads company, task, approval, and cost data.
> - A pooled database connection can close during one of these reads.
> - The driver must reject ambiguous statements because writes may have
committed.
> - These four dashboard queries are known to be read-only.
> - This change retries only the failed read and preserves completed
work.

## Linked Issues or Issue Description

Refs #14773, which correctly removed automatic replay of ambiguous
database statements. Searched existing database and dashboard PRs.
Related #8780 changes pool recycling and logging; #13925 adds dashboard
consistency coverage. Neither provides these per-query retries.

**What happened?**

A dashboard request returns a server error when its company lookup, task
count, approval count, or monthly spend query loses its database
connection. Drizzle wraps the driver's connection error in `cause`.

**Expected behavior**

A transient connection failure gets a bounded retry of the specific
read. Completed reads and budget processing are not replayed. Persistent
outages and non-connection errors still fail the request.

**Steps to reproduce**

Inject a typed `CONNECTION_CLOSED` error into one of these reads. Then
allow the next query to succeed. Before this change, the dashboard
request fails immediately.

## What Changed

- Apply independent retries to the company lookup, task counts, pending
approval count, and monthly spend query. Each callback rebuilds its own
query with the same company scope.
- Extract the existing authentication retry helper as
`retryIdempotentDatabaseOperation`. Preserve authentication behavior and
its existing exports.
- Retain the existing limit of three total attempts with 50 ms and 100
ms pauses. Match typed connection codes through the error cause chain.
- Test later-read failures, unchanged query parameters, retry
exhaustion, missing companies, and errors that must not retry. Document
the boundary.

## Verification

- Final focused dashboard, authentication, and real database wire
suites: 38 tests passed. Six initial recovery regressions failed before
the implementation.
- `pnpm -r typecheck`: passed on the final source.
- Independent review: no actionable findings. The reviewer separately
passed all 38 focused tests and checked the code allowlist, attempt
bounds, pauses, and final error identity.
- `pnpm test:run`: the general-server group completed with 14,738 tests
passed, 13 failed, and 87 skipped. All 13 failures match the previously
reproduced clean-base macOS skill-cache failures. The two test files and
their implementations are unchanged from that baseline. The runner
exited after this group, so the remaining local workspace and serialized
groups did not run. All corresponding Linux CI groups passed on this
commit.
- `pnpm build`: passed on the final source.
- Full CI: 53 successful checks and 2 skips on `6a113529c0`. Greptile:
5/5 on that commit, with no review threads or remaining findings.
- Merge compatibility with master `f2e0f19630`, including #14866: no
conflicts. The five reviewed files are unchanged in the resulting merge
tree.

## Risks

A persistent outage adds at most two retries per covered query. Each
connection attempt retains the configured driver timeout. The change
does not repair the underlying network or database failure. Agent
counts, run-activity queries, and the budget workflow stay outside these
retry boundaries. General database statements and disconnected
transactions are not replayed. There is no schema or authorization
change.

## Model Used

OpenAI GPT-6 through Codex, with reasoning, repository inspection, code
editing, and test execution. The runtime does not expose a more specific
serving model identifier or context-window size.

## Checklist

- [x] I have included a thinking path that traces from project context
to this change
- [x] I have specified the model used (with version and capability
details)
- [x] I have checked ROADMAP.md and confirmed this PR does not duplicate
planned core work
- [x] I have searched GitHub for duplicate or related PRs and linked
them above
- [x] I have either (a) linked existing issues with `Fixes: #` / `Closes
#` / `Refs #` OR (b) described the issue in-PR following the relevant
issue template
- [x] I have not referenced internal/instance-local Paperclip issues or
links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip`
URLs)
- [x] My branch name describes the change and contains no internal
Paperclip ticket id or instance-derived details
- [x] I have run tests locally and they pass (38 focused tests; the full
local run has the baseline limitation documented above)
- [x] I have added or updated tests where applicable
- [x] I have updated relevant documentation to reflect my changes
- [x] I have considered and documented any risks above
- [x] All Paperclip CI gates are green
- [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups
- [x] I will address all Greptile and reviewer comments before
requesting merge

Co-authored-by: Paperclip <noreply@paperclip.ing>
2026-10-01 19:23:47 -07:00
dependabot[bot] 40c8468e98 build(deps-dev): bump agentmail from 0.5.20 to 0.5.31 (#12975)
Bumps [agentmail](https://github.com/agentmail-to/agentmail-node) from
0.5.20 to 0.5.31.
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/agentmail-to/agentmail-node/commit/be477c3e9d07de608d94daa3f2235c46456758ad"><code>be477c3</code></a>
Release 0.5.31</li>
<li><a
href="https://github.com/agentmail-to/agentmail-node/commit/553d6a62e10a95c73a87d47b8b1125f716dfb1f2"><code>553d6a6</code></a>
Release 0.5.30</li>
<li><a
href="https://github.com/agentmail-to/agentmail-node/commit/a53948be57e396a8d08344e9d43ee191ae747fd9"><code>a53948b</code></a>
Release 0.5.29</li>
<li><a
href="https://github.com/agentmail-to/agentmail-node/commit/f2b4bb9a452a7343dc0eb6f20a07882d7364b211"><code>f2b4bb9</code></a>
Release 0.5.28</li>
<li><a
href="https://github.com/agentmail-to/agentmail-node/commit/d2c56f73735ed917961e1a16273a9320de6c21cd"><code>d2c56f7</code></a>
Release 0.5.27</li>
<li><a
href="https://github.com/agentmail-to/agentmail-node/commit/df2a12427b4e988024787167e6732bd1d1c5b9ff"><code>df2a124</code></a>
Release 0.5.26</li>
<li><a
href="https://github.com/agentmail-to/agentmail-node/commit/4ae0b9b2eeda5c65beb9fa4a3601a1a44f10947d"><code>4ae0b9b</code></a>
Release 0.5.25</li>
<li><a
href="https://github.com/agentmail-to/agentmail-node/commit/dc085581668947a177f5a087c4f78cf1b75dd2e8"><code>dc08558</code></a>
Release 0.5.24</li>
<li><a
href="https://github.com/agentmail-to/agentmail-node/commit/47210d91803f65b2ebf9ec8d1ae546a050e3d8bc"><code>47210d9</code></a>
Release 0.5.23</li>
<li><a
href="https://github.com/agentmail-to/agentmail-node/commit/0c5f98ff97a492ab77e9c688d3374548d9dd997a"><code>0c5f98f</code></a>
Release 0.5.22</li>
<li>Additional commits viewable in <a
href="https://github.com/agentmail-to/agentmail-node/compare/0.5.20...0.5.31">compare
view</a></li>
</ul>
</details>
<br />

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
canary/v2026.1002.0-canary.2
2026-10-01 19:09:03 -07:00
427e048405 fix(company-skills): approve managed-checkout project dirs for local skill import (#10329)
## Thinking Path

> - Paperclip is the open source app people use to manage AI agents for
work
> - Company skills can be imported into a company from a local folder;
`companySkillService.importFromSource` guards this with
`assertLocalImportSourceAllowed`, which only permits import sources
inside an approved set of roots (managed skills root + registered
project-workspace cwds), realpath-resolved and `${root}${sep}`-anchored
to prevent path traversal/escape
> - A project can exist as a `managed_checkout` (server-managed clone)
with **no registered `project_workspaces` row** — its `primaryWorkspace`
is `null` and `workspaces` is `[]`, so its only real on-disk location is
the server-derived `codebase.managedFolder`
> - Because `configuredRoots` was built solely from the managed skills
root and `workspaces[].cwd`, a `managed_checkout` project's
`managedFolder` was never an approved root, so importing a skill from
that project's own folder was rejected with
`skill_workspace_boundary_denied`
> - This PR adds each project's server-derived `codebase.managedFolder`
to `configuredRoots` so in-place skill imports from managed-checkout
projects are allowed
> - The benefit is that managed-checkout projects can re-import their
own skills in place, without weakening the traversal/escape protections
(the new roots are server-derived and matched exactly like the existing
ones)

## Linked Issues or Issue Description

No public GitHub issue. Describing in-PR (bug):

**What's wrong:** `assertLocalImportSourceAllowed` denies a legitimate
local skill import (`skill_workspace_boundary_denied`) for any project
that is a `managed_checkout` with no registered workspace row.

**Repro:** Create/import a company skill from a `managed_checkout`
project's own folder (`codebase.managedFolder/.agents/skills/<skill>`).
The import is rejected even though the source is inside the project's
server-managed checkout.

**Expected:** The import from a managed-checkout project's own
`managedFolder` subtree should be allowed, while paths outside that
subtree remain denied.

Related context (already merged): #9564 introduced the open-by-default
skill policy / this import boundary. This PR does not change that
boundary's matching logic — it only adds a missing, server-derived
approved root.

## What Changed

- `server/src/services/company-skills.ts`: add
`...projectRows.map((project) => project.codebase.managedFolder)` to
`configuredRoots` in `assertLocalImportSourceAllowed`. `managedFolder`
is server-derived (`resolveManagedProjectWorkspaceDir(companyId,
projectId)` → instance root + sanitized ids); it is
`fs.realpath`-resolved and `${root}${sep}`-prefix matched exactly like
every existing root. `managedFolder` is used rather than
`effectiveLocalFolder` because the latter can fall through to a
user-registered `localFolder`, which is already covered by the
registered workspace cwds.
- `server/src/__tests__/company-skill-import-boundary.test.ts`: add a
regression test — a managed-checkout project's `managedFolder/<skill>`
import is **allowed**, and a **prefix-adjacent sibling** (`managedFolder
+ "-evil"`) stays **denied**.

## Verification

- `cd server && ./node_modules/.bin/vitest run
src/__tests__/company-skill-import-boundary.test.ts` → **2/2 pass**
(embedded-Postgres suite). Covers both the new allow case and the
prefix-adjacent deny case, alongside the existing out-of-tree /
symlink-escape / non-file-scheme rejections.

## Risks

Low risk. The change only **adds** approved roots; it does not alter the
realpath + `${root}${sep}`-anchored matching that closes
traversal/prefix-adjacency escapes. The added roots are fully
server-derived from the instance root + sanitized company/project ids
(same trust class as the existing `resolveManagedSkillsRoot`) — no value
derived from the import `source` argument reaches them. Sanitization
(`[^a-zA-Z0-9._-]+ → -`) prevents separator/level injection, and the
only user-influenced segment (repo name) is normalized via `new
URL(...)`. The regression test's prefix-adjacent (`-evil`) case asserts
the escape class stays closed.

## Model Used

Claude Opus 4.8 (`claude-opus-4-8`), extended thinking + tool use (code
execution, git). Implementation and security review were produced with
Claude; this integration/PR was prepared with `claude-opus-4-8`.

## Checklist

- [x] I have included a thinking path that traces from project context
to this change
- [x] I have specified the model used (with version and capability
details)
- [x] I have checked ROADMAP.md and confirmed this PR does not duplicate
planned core work
- [x] I have searched GitHub for duplicate or related PRs and linked
them above
- [x] I have either (a) linked existing issues with `Fixes: #` / `Closes
#` / `Refs #` OR (b) described the issue in-PR following the relevant
issue template
- [x] I have not referenced internal/instance-local Paperclip issues or
links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip`
URLs)
- [x] My branch name describes the change (e.g. `docs/...`, `fix/...`)
and contains no internal Paperclip ticket id or instance-derived details
- [x] I have run tests locally and they pass
- [x] I have added or updated tests where applicable
- [ ] I have updated relevant documentation to reflect my changes (N/A —
internal boundary fix, no user-facing docs)
- [x] I have considered and documented any risks above
- [ ] All Paperclip CI gates are green (CI in progress)
- [ ] Greptile is 5/5 with no open P2s, recommendations, or follow-ups
(pending review)
- [x] I will address all Greptile and reviewer comments before
requesting merge

Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
Co-authored-by: brandonburr <brandonburr@gmail.com>
canary/v2026.1002.0-canary.1
2026-10-01 17:34:51 -07:00
5207c78f21 docs(release): align 2026.921.0-beta.1 stable notes header with v2026.1001.0 (#14882)
## Thinking Path

> - Paperclip is the open source app people use to manage AI agents for
work
> - Releases are published by `release.yml`. A stable release promotes a
soaked beta, and the stable notes live on master in
`releases/beta/v<beta>.md` until the promotion runs.
> - The curated notes for `2026.921.0-beta.1` have the title `Paperclip
v2026.924.0` and the date `2026-09-24`. That stable did not ship. No
`v2026.924.0` tag or release exists.
> - The next promotion of this beta uses `stable_date=2026-10-01`.
`scripts/release.sh stable --print-version --date 2026-10-01` resolves
to `2026.1001.0`.
> - `publish_stable` reads this file verbatim and uses it as the GitHub
Release body. `canonicalize_stable_notes` copies it to
`releases/v2026.1001.0.md`. Nothing rewrites the header.
> - This pull request updates the title, the release date, and the intro
sentence to `v2026.1001.0` and `2026-10-01`.
> - The benefit is a GitHub Release page and a canonical notes file that
show the correct version and date.

## Linked Issues or Issue Description

**Describe the documentation problem**

The stable notes file `releases/beta/v2026.921.0-beta.1.md` names a
stable version and release date that do not match the version the
release workflow will publish.

**Where is the problem**

`releases/beta/v2026.921.0-beta.1.md`, lines 1, 3, and 5.

**Proposed fix**

Change `v2026.924.0` to `v2026.1001.0` and `2026-09-24` to `2026-10-01`
in the three places that name the version or date. Change nothing else
in the file.

## What Changed

- Title: `# Paperclip v2026.924.0` → `# Paperclip v2026.1001.0`
- Release date: `> Released: 2026-09-24` → `> Released: 2026-10-01`
- Intro sentence: `Paperclip v2026.924.0 carries 77 commits` →
`Paperclip v2026.1001.0 carries 77 commits`

## Verification

- `git diff master --stat` shows one file with 3 insertions and 3
deletions.
- `grep -n '924' releases/beta/v2026.921.0-beta.1.md` returns no lines.
- `git show master:scripts/release.sh > /tmp/r.sh && bash /tmp/r.sh
stable --print-version --date 2026-10-01` prints `2026.1001.0`.
- The rest of the file is byte-identical to master.

## Risks

- Low risk. This is a documentation-only change to a release notes file.
No code or workflow changes.
- If the stable promotion is dispatched with a different `stable_date`,
the header must be updated again to match.

## Model Used

- Claude Fable 5.1 (model ID `claude-fable-5-1`), run as a Paperclip
agent through the Claude Agent SDK, with tool use (shell, git, GitHub
CLI). No extended thinking mode was configured beyond the default.

## Checklist

- [x] I have included a thinking path that traces from project context
to this change
- [x] I have specified the model used (with version and capability
details)
- [x] I have checked ROADMAP.md and confirmed this PR does not duplicate
planned core work
- [x] I have searched GitHub for duplicate or related PRs and linked
them above
- [x] I have either (a) linked existing issues with `Fixes: #` / `Closes
#` / `Refs #` OR (b) described the issue in-PR following the relevant
issue template
- [x] I have not referenced internal/instance-local Paperclip issues or
links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip`
URLs)
- [x] My branch name describes the change (e.g. `docs/...`, `fix/...`)
and contains no internal Paperclip ticket id or instance-derived details
- [x] I have run tests locally and they pass
- [ ] I have added or updated tests where applicable (not applicable:
documentation-only change)
- [x] I have updated relevant documentation to reflect my changes
- [x] I have considered and documented any risks above
- [ ] All Paperclip CI gates are green
- [ ] Greptile is 5/5 with no open P2s, recommendations, or follow-ups
- [x] I will address all Greptile and reviewer comments before
requesting merge

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-authored-by: Bender (Fable) <noreply@paperclip.ing>
Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com>
canary/v2026.1002.0-canary.0
2026-10-01 17:28:00 -07:00
dependabot[bot] f07f8d9599 build(deps-dev): bump @storybook/addon-a11y from 10.5.10 to 10.6.0 (#12976)
Bumps
[@storybook/addon-a11y](https://github.com/storybookjs/storybook/tree/HEAD/code/addons/a11y)
from 10.5.10 to 10.6.0.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/storybookjs/storybook/releases">@​storybook/addon-a11y's
releases</a>.</em></p>
<blockquote>
<h2>v10.6.0</h2>
<h2>10.6.0</h2>
<blockquote>
<p>New skills architecture for agentic workflows</p>
</blockquote>
<p>Storybook 10.6 contains hundreds of fixes and improvements:</p>
<ul>
<li>💻 CLI bindings for agent tools/skills</li>
<li>🅰️ Angular-Vite MCP/skills support and improved docgen/snippets
(experimental)</li>
<li>🟢 Vue MCP/skills support and improved docgen/snippets
(experimental)</li>
<li>🧩 Tanstack / NextJS-Vite framework bugfixes</li>
<li>⚡ Improved performance and reduced bundle size</li>
</ul>
<!-- raw HTML omitted -->
<ul>
<li>Addon MCP: Stop silently dropping composed refs from MCP composition
- <a
href="https://redirect.github.com/storybookjs/storybook/pull/36077">#36077</a>,
thanks <a
href="https://github.com/kasperpeulen"><code>@​kasperpeulen</code></a>!</li>
<li>Addon Vitest: Pin storybook/test in optimizeDeps so its CJS-only
deps are prebundled - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35572">#35572</a>,
thanks <a
href="https://github.com/Nic-Polumeyv"><code>@​Nic-Polumeyv</code></a>!</li>
<li>Addon Vitest: Report test runs with failures as failed tool outcomes
- <a
href="https://redirect.github.com/storybookjs/storybook/pull/36080">#36080</a>,
thanks <a
href="https://github.com/kasperpeulen"><code>@​kasperpeulen</code></a>!</li>
<li>Addon Vitest: Resolve story test globs against the project root - <a
href="https://redirect.github.com/storybookjs/storybook/pull/36103">#36103</a>,
thanks <a
href="https://github.com/kasperpeulen"><code>@​kasperpeulen</code></a>!</li>
<li>Addon-vitest: Filter Storybook instrumentation from reported stack
traces - <a
href="https://redirect.github.com/storybookjs/storybook/pull/36120">#36120</a>,
thanks <a
href="https://github.com/ghengeveld"><code>@​ghengeveld</code></a>!</li>
<li>Angular Vite: Resolve tsConfig against the workspace root - <a
href="https://redirect.github.com/storybookjs/storybook/pull/36026">#36026</a>,
thanks <a
href="https://github.com/ndelangen"><code>@​ndelangen</code></a>!</li>
<li>Angular-Vite: Run Compodoc on demand - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35776">#35776</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Add an in-process docgen analyzer, replacing Compodoc under
the flag - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35805">#35805</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Bind only what the component accepts in story snippets, and
report the rest - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35943">#35943</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Decide the migration's zone.js import from the dependency
tree - <a
href="https://redirect.github.com/storybookjs/storybook/pull/36008">#36008</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Declare story args the snippet markup binds by name - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35895">#35895</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Declare style preprocessors as optional peers and name the
missing one - <a
href="https://redirect.github.com/storybookjs/storybook/pull/36098">#36098</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Derive required inputs from Compodoc's own flag - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35758">#35758</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Extract Compodoc parsing into its own package - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35749">#35749</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Extract component JSDoc through TypeScript's APIs - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35977">#35977</a>,
thanks <a
href="https://github.com/huang-julien"><code>@​huang-julien</code></a>!</li>
<li>Angular: Extract docgen on the server via Compodoc - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35733">#35733</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Fix component resolution, MCP output, and dev/build path
aliasing - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35952">#35952</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Fix eight upgrade and migration bugs - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35946">#35946</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Fix ten docgen bugs found across 22 community repositories
- <a
href="https://redirect.github.com/storybookjs/storybook/pull/35941">#35941</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Generate story-docs snippets from the analyzer - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35807">#35807</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Give agents real input and output documentation - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35896">#35896</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Hide class internals from the props table by default - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35887">#35887</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Install the `@storybook/angular-vite` peers that nothing
else brings in - <a
href="https://redirect.github.com/storybookjs/storybook/pull/36002">#36002</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Keep the function control on constructor and generic
signatures - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35921">#35921</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Make experimentalDocgenServer the default in angular-vite -
<a
href="https://redirect.github.com/storybookjs/storybook/pull/35886">#35886</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Migrate Analog projects to angular-vite instead of refusing
them - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35971">#35971</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Print unevaluable story args instead of slicing the file -
<a
href="https://redirect.github.com/storybookjs/storybook/pull/35888">#35888</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Read the story shapes that supply their own markup - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35797">#35797</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Render self-closing tags in server-side docs snippets - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35953">#35953</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Render the required badge for required inputs in the props
table - <a
href="https://redirect.github.com/storybookjs/storybook/pull/36065">#36065</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Resolve `@angular/core` through the package manager, not
the raw specifier - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35999">#35999</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Resolve builder `styles` the way the Angular builders do -
<a
href="https://redirect.github.com/storybookjs/storybook/pull/35998">#35998</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Resolve builder styles against the workspace root - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35974">#35974</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Skip the runtime source decorator when the docgen server
produces snippets - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35906">#35906</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/storybookjs/storybook/blob/next/CHANGELOG.md">@​storybook/addon-a11y's
changelog</a>.</em></p>
<blockquote>
<h2>10.6.0</h2>
<blockquote>
<p>New skills architecture for agentic workflows</p>
</blockquote>
<p>Storybook 10.6 contains hundreds of fixes and improvements:</p>
<ul>
<li>💻 CLI bindings for agent tools/skills</li>
<li>🅰️ Angular-Vite MCP/skills support and improved docgen/snippets
(experimental)</li>
<li>🟢 Vue MCP/skills support and improved docgen/snippets
(experimental)</li>
<li>🧩 Tanstack / NextJS-Vite framework bugfixes</li>
<li>⚡ Improved performance and reduced bundle size</li>
</ul>
<!-- raw HTML omitted -->
<ul>
<li>Addon MCP: Stop silently dropping composed refs from MCP composition
- <a
href="https://redirect.github.com/storybookjs/storybook/pull/36077">#36077</a>,
thanks <a
href="https://github.com/kasperpeulen"><code>@​kasperpeulen</code></a>!</li>
<li>Addon Vitest: Pin storybook/test in optimizeDeps so its CJS-only
deps are prebundled - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35572">#35572</a>,
thanks <a
href="https://github.com/Nic-Polumeyv"><code>@​Nic-Polumeyv</code></a>!</li>
<li>Addon Vitest: Report test runs with failures as failed tool outcomes
- <a
href="https://redirect.github.com/storybookjs/storybook/pull/36080">#36080</a>,
thanks <a
href="https://github.com/kasperpeulen"><code>@​kasperpeulen</code></a>!</li>
<li>Addon Vitest: Resolve story test globs against the project root - <a
href="https://redirect.github.com/storybookjs/storybook/pull/36103">#36103</a>,
thanks <a
href="https://github.com/kasperpeulen"><code>@​kasperpeulen</code></a>!</li>
<li>Addon-vitest: Filter Storybook instrumentation from reported stack
traces - <a
href="https://redirect.github.com/storybookjs/storybook/pull/36120">#36120</a>,
thanks <a
href="https://github.com/ghengeveld"><code>@​ghengeveld</code></a>!</li>
<li>Angular Vite: Resolve tsConfig against the workspace root - <a
href="https://redirect.github.com/storybookjs/storybook/pull/36026">#36026</a>,
thanks <a
href="https://github.com/ndelangen"><code>@​ndelangen</code></a>!</li>
<li>Angular-Vite: Run Compodoc on demand - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35776">#35776</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Add an in-process docgen analyzer, replacing Compodoc under
the flag - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35805">#35805</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Bind only what the component accepts in story snippets, and
report the rest - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35943">#35943</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Decide the migration's zone.js import from the dependency
tree - <a
href="https://redirect.github.com/storybookjs/storybook/pull/36008">#36008</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Declare story args the snippet markup binds by name - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35895">#35895</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Declare style preprocessors as optional peers and name the
missing one - <a
href="https://redirect.github.com/storybookjs/storybook/pull/36098">#36098</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Derive required inputs from Compodoc's own flag - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35758">#35758</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Extract Compodoc parsing into its own package - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35749">#35749</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Extract component JSDoc through TypeScript's APIs - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35977">#35977</a>,
thanks <a
href="https://github.com/huang-julien"><code>@​huang-julien</code></a>!</li>
<li>Angular: Extract docgen on the server via Compodoc - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35733">#35733</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Fix component resolution, MCP output, and dev/build path
aliasing - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35952">#35952</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Fix eight upgrade and migration bugs - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35946">#35946</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Fix ten docgen bugs found across 22 community repositories
- <a
href="https://redirect.github.com/storybookjs/storybook/pull/35941">#35941</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Generate story-docs snippets from the analyzer - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35807">#35807</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Give agents real input and output documentation - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35896">#35896</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Hide class internals from the props table by default - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35887">#35887</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Install the <code>@storybook/angular-vite</code> peers that
nothing else brings in - <a
href="https://redirect.github.com/storybookjs/storybook/pull/36002">#36002</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Keep the function control on constructor and generic
signatures - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35921">#35921</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Make experimentalDocgenServer the default in angular-vite -
<a
href="https://redirect.github.com/storybookjs/storybook/pull/35886">#35886</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Migrate Analog projects to angular-vite instead of refusing
them - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35971">#35971</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Print unevaluable story args instead of slicing the file -
<a
href="https://redirect.github.com/storybookjs/storybook/pull/35888">#35888</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Read the story shapes that supply their own markup - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35797">#35797</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Render self-closing tags in server-side docs snippets - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35953">#35953</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Render the required badge for required inputs in the props
table - <a
href="https://redirect.github.com/storybookjs/storybook/pull/36065">#36065</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Resolve <code>@angular/core</code> through the package
manager, not the raw specifier - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35999">#35999</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Resolve builder <code>styles</code> the way the Angular
builders do - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35998">#35998</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Resolve builder styles against the workspace root - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35974">#35974</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Skip the runtime source decorator when the docgen server
produces snippets - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35906">#35906</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Stop marking a defaulted input as required in the props
table - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35899">#35899</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/storybookjs/storybook/commit/a77777356be2aeaff89d7a2b25254db7b2318392"><code>a777773</code></a>
Bump version from &quot;10.6.0-beta.3&quot; to &quot;10.6.0&quot; [skip
ci]</li>
<li><a
href="https://github.com/storybookjs/storybook/commit/f32b3667dad8df220cda0359e170bc49931af68c"><code>f32b366</code></a>
Bump version from &quot;10.6.0-beta.2&quot; to &quot;10.6.0-beta.3&quot;
[skip ci]</li>
<li><a
href="https://github.com/storybookjs/storybook/commit/0ad1336cbf0ecdab9f6b540570ae9015ae73ab86"><code>0ad1336</code></a>
Bump version from &quot;10.6.0-beta.1&quot; to &quot;10.6.0-beta.2&quot;
[skip ci]</li>
<li><a
href="https://github.com/storybookjs/storybook/commit/16359ee17802628c47915c21408cb578d2707b83"><code>16359ee</code></a>
Bump version from &quot;10.6.0-beta.0&quot; to &quot;10.6.0-beta.1&quot;
[skip ci]</li>
<li><a
href="https://github.com/storybookjs/storybook/commit/2e0e2f609d1351ba4384eb52e0728dc9cd8b275b"><code>2e0e2f6</code></a>
Bump version from &quot;10.6.0-alpha.9&quot; to
&quot;10.6.0-beta.0&quot; [skip ci]</li>
<li><a
href="https://github.com/storybookjs/storybook/commit/6a6dec2aedff6744a9d9226e1f6515e3d5e8b42a"><code>6a6dec2</code></a>
Bump version from &quot;10.6.0-alpha.8&quot; to
&quot;10.6.0-alpha.9&quot; [skip ci]</li>
<li><a
href="https://github.com/storybookjs/storybook/commit/cd2d16395a5ffa39189b96aafb6af67f280079db"><code>cd2d163</code></a>
Bump version from &quot;10.6.0-alpha.7&quot; to
&quot;10.6.0-alpha.8&quot; [skip ci]</li>
<li><a
href="https://github.com/storybookjs/storybook/commit/898f0ce828ec8bd00985934786724b94f8428c42"><code>898f0ce</code></a>
Bump version from &quot;10.6.0-alpha.6&quot; to
&quot;10.6.0-alpha.7&quot; [skip ci]</li>
<li><a
href="https://github.com/storybookjs/storybook/commit/cf97b46ca1a452f6f47206fd6ed7043a88e38a60"><code>cf97b46</code></a>
Bump version from &quot;10.6.0-alpha.5&quot; to
&quot;10.6.0-alpha.6&quot; [skip ci]</li>
<li><a
href="https://github.com/storybookjs/storybook/commit/2b7f6be9c96f72d6eca4b80af11db1a4ff380e8e"><code>2b7f6be</code></a>
Bump version from &quot;10.6.0-alpha.4&quot; to
&quot;10.6.0-alpha.5&quot; [skip ci]</li>
<li>Additional commits viewable in <a
href="https://github.com/storybookjs/storybook/commits/v10.6.0/code/addons/a11y">compare
view</a></li>
</ul>
</details>
<br />

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-10-01 17:08:56 -07:00
dependabot[bot] 41c18aa443 build(deps-dev): bump storybook from 10.5.10 to 10.6.0 (#12984)
Bumps
[storybook](https://github.com/storybookjs/storybook/tree/HEAD/code/core)
from 10.5.10 to 10.6.0.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/storybookjs/storybook/releases">storybook's
releases</a>.</em></p>
<blockquote>
<h2>v10.6.0</h2>
<h2>10.6.0</h2>
<blockquote>
<p>New skills architecture for agentic workflows</p>
</blockquote>
<p>Storybook 10.6 contains hundreds of fixes and improvements:</p>
<ul>
<li>💻 CLI bindings for agent tools/skills</li>
<li>🅰️ Angular-Vite MCP/skills support and improved docgen/snippets
(experimental)</li>
<li>🟢 Vue MCP/skills support and improved docgen/snippets
(experimental)</li>
<li>🧩 Tanstack / NextJS-Vite framework bugfixes</li>
<li>⚡ Improved performance and reduced bundle size</li>
</ul>
<!-- raw HTML omitted -->
<ul>
<li>Addon MCP: Stop silently dropping composed refs from MCP composition
- <a
href="https://redirect.github.com/storybookjs/storybook/pull/36077">#36077</a>,
thanks <a
href="https://github.com/kasperpeulen"><code>@​kasperpeulen</code></a>!</li>
<li>Addon Vitest: Pin storybook/test in optimizeDeps so its CJS-only
deps are prebundled - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35572">#35572</a>,
thanks <a
href="https://github.com/Nic-Polumeyv"><code>@​Nic-Polumeyv</code></a>!</li>
<li>Addon Vitest: Report test runs with failures as failed tool outcomes
- <a
href="https://redirect.github.com/storybookjs/storybook/pull/36080">#36080</a>,
thanks <a
href="https://github.com/kasperpeulen"><code>@​kasperpeulen</code></a>!</li>
<li>Addon Vitest: Resolve story test globs against the project root - <a
href="https://redirect.github.com/storybookjs/storybook/pull/36103">#36103</a>,
thanks <a
href="https://github.com/kasperpeulen"><code>@​kasperpeulen</code></a>!</li>
<li>Addon-vitest: Filter Storybook instrumentation from reported stack
traces - <a
href="https://redirect.github.com/storybookjs/storybook/pull/36120">#36120</a>,
thanks <a
href="https://github.com/ghengeveld"><code>@​ghengeveld</code></a>!</li>
<li>Angular Vite: Resolve tsConfig against the workspace root - <a
href="https://redirect.github.com/storybookjs/storybook/pull/36026">#36026</a>,
thanks <a
href="https://github.com/ndelangen"><code>@​ndelangen</code></a>!</li>
<li>Angular-Vite: Run Compodoc on demand - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35776">#35776</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Add an in-process docgen analyzer, replacing Compodoc under
the flag - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35805">#35805</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Bind only what the component accepts in story snippets, and
report the rest - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35943">#35943</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Decide the migration's zone.js import from the dependency
tree - <a
href="https://redirect.github.com/storybookjs/storybook/pull/36008">#36008</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Declare story args the snippet markup binds by name - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35895">#35895</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Declare style preprocessors as optional peers and name the
missing one - <a
href="https://redirect.github.com/storybookjs/storybook/pull/36098">#36098</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Derive required inputs from Compodoc's own flag - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35758">#35758</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Extract Compodoc parsing into its own package - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35749">#35749</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Extract component JSDoc through TypeScript's APIs - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35977">#35977</a>,
thanks <a
href="https://github.com/huang-julien"><code>@​huang-julien</code></a>!</li>
<li>Angular: Extract docgen on the server via Compodoc - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35733">#35733</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Fix component resolution, MCP output, and dev/build path
aliasing - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35952">#35952</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Fix eight upgrade and migration bugs - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35946">#35946</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Fix ten docgen bugs found across 22 community repositories
- <a
href="https://redirect.github.com/storybookjs/storybook/pull/35941">#35941</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Generate story-docs snippets from the analyzer - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35807">#35807</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Give agents real input and output documentation - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35896">#35896</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Hide class internals from the props table by default - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35887">#35887</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Install the `@storybook/angular-vite` peers that nothing
else brings in - <a
href="https://redirect.github.com/storybookjs/storybook/pull/36002">#36002</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Keep the function control on constructor and generic
signatures - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35921">#35921</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Make experimentalDocgenServer the default in angular-vite -
<a
href="https://redirect.github.com/storybookjs/storybook/pull/35886">#35886</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Migrate Analog projects to angular-vite instead of refusing
them - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35971">#35971</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Print unevaluable story args instead of slicing the file -
<a
href="https://redirect.github.com/storybookjs/storybook/pull/35888">#35888</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Read the story shapes that supply their own markup - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35797">#35797</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Render self-closing tags in server-side docs snippets - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35953">#35953</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Render the required badge for required inputs in the props
table - <a
href="https://redirect.github.com/storybookjs/storybook/pull/36065">#36065</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Resolve `@angular/core` through the package manager, not
the raw specifier - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35999">#35999</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Resolve builder `styles` the way the Angular builders do -
<a
href="https://redirect.github.com/storybookjs/storybook/pull/35998">#35998</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Resolve builder styles against the workspace root - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35974">#35974</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Skip the runtime source decorator when the docgen server
produces snippets - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35906">#35906</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/storybookjs/storybook/blob/next/CHANGELOG.md">storybook's
changelog</a>.</em></p>
<blockquote>
<h2>10.6.0</h2>
<blockquote>
<p>New skills architecture for agentic workflows</p>
</blockquote>
<p>Storybook 10.6 contains hundreds of fixes and improvements:</p>
<ul>
<li>💻 CLI bindings for agent tools/skills</li>
<li>🅰️ Angular-Vite MCP/skills support and improved docgen/snippets
(experimental)</li>
<li>🟢 Vue MCP/skills support and improved docgen/snippets
(experimental)</li>
<li>🧩 Tanstack / NextJS-Vite framework bugfixes</li>
<li>⚡ Improved performance and reduced bundle size</li>
</ul>
<!-- raw HTML omitted -->
<ul>
<li>Addon MCP: Stop silently dropping composed refs from MCP composition
- <a
href="https://redirect.github.com/storybookjs/storybook/pull/36077">#36077</a>,
thanks <a
href="https://github.com/kasperpeulen"><code>@​kasperpeulen</code></a>!</li>
<li>Addon Vitest: Pin storybook/test in optimizeDeps so its CJS-only
deps are prebundled - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35572">#35572</a>,
thanks <a
href="https://github.com/Nic-Polumeyv"><code>@​Nic-Polumeyv</code></a>!</li>
<li>Addon Vitest: Report test runs with failures as failed tool outcomes
- <a
href="https://redirect.github.com/storybookjs/storybook/pull/36080">#36080</a>,
thanks <a
href="https://github.com/kasperpeulen"><code>@​kasperpeulen</code></a>!</li>
<li>Addon Vitest: Resolve story test globs against the project root - <a
href="https://redirect.github.com/storybookjs/storybook/pull/36103">#36103</a>,
thanks <a
href="https://github.com/kasperpeulen"><code>@​kasperpeulen</code></a>!</li>
<li>Addon-vitest: Filter Storybook instrumentation from reported stack
traces - <a
href="https://redirect.github.com/storybookjs/storybook/pull/36120">#36120</a>,
thanks <a
href="https://github.com/ghengeveld"><code>@​ghengeveld</code></a>!</li>
<li>Angular Vite: Resolve tsConfig against the workspace root - <a
href="https://redirect.github.com/storybookjs/storybook/pull/36026">#36026</a>,
thanks <a
href="https://github.com/ndelangen"><code>@​ndelangen</code></a>!</li>
<li>Angular-Vite: Run Compodoc on demand - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35776">#35776</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Add an in-process docgen analyzer, replacing Compodoc under
the flag - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35805">#35805</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Bind only what the component accepts in story snippets, and
report the rest - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35943">#35943</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Decide the migration's zone.js import from the dependency
tree - <a
href="https://redirect.github.com/storybookjs/storybook/pull/36008">#36008</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Declare story args the snippet markup binds by name - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35895">#35895</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Declare style preprocessors as optional peers and name the
missing one - <a
href="https://redirect.github.com/storybookjs/storybook/pull/36098">#36098</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Derive required inputs from Compodoc's own flag - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35758">#35758</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Extract Compodoc parsing into its own package - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35749">#35749</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Extract component JSDoc through TypeScript's APIs - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35977">#35977</a>,
thanks <a
href="https://github.com/huang-julien"><code>@​huang-julien</code></a>!</li>
<li>Angular: Extract docgen on the server via Compodoc - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35733">#35733</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Fix component resolution, MCP output, and dev/build path
aliasing - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35952">#35952</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Fix eight upgrade and migration bugs - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35946">#35946</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Fix ten docgen bugs found across 22 community repositories
- <a
href="https://redirect.github.com/storybookjs/storybook/pull/35941">#35941</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Generate story-docs snippets from the analyzer - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35807">#35807</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Give agents real input and output documentation - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35896">#35896</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Hide class internals from the props table by default - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35887">#35887</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Install the <code>@storybook/angular-vite</code> peers that
nothing else brings in - <a
href="https://redirect.github.com/storybookjs/storybook/pull/36002">#36002</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Keep the function control on constructor and generic
signatures - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35921">#35921</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Make experimentalDocgenServer the default in angular-vite -
<a
href="https://redirect.github.com/storybookjs/storybook/pull/35886">#35886</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Migrate Analog projects to angular-vite instead of refusing
them - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35971">#35971</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Print unevaluable story args instead of slicing the file -
<a
href="https://redirect.github.com/storybookjs/storybook/pull/35888">#35888</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Read the story shapes that supply their own markup - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35797">#35797</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Render self-closing tags in server-side docs snippets - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35953">#35953</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Render the required badge for required inputs in the props
table - <a
href="https://redirect.github.com/storybookjs/storybook/pull/36065">#36065</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Resolve <code>@angular/core</code> through the package
manager, not the raw specifier - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35999">#35999</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Resolve builder <code>styles</code> the way the Angular
builders do - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35998">#35998</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Resolve builder styles against the workspace root - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35974">#35974</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Skip the runtime source decorator when the docgen server
produces snippets - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35906">#35906</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Stop marking a defaulted input as required in the props
table - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35899">#35899</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/storybookjs/storybook/commit/a77777356be2aeaff89d7a2b25254db7b2318392"><code>a777773</code></a>
Bump version from &quot;10.6.0-beta.3&quot; to &quot;10.6.0&quot; [skip
ci]</li>
<li><a
href="https://github.com/storybookjs/storybook/commit/f32b3667dad8df220cda0359e170bc49931af68c"><code>f32b366</code></a>
Bump version from &quot;10.6.0-beta.2&quot; to &quot;10.6.0-beta.3&quot;
[skip ci]</li>
<li><a
href="https://github.com/storybookjs/storybook/commit/db38cb39d9be5609bba4ac3b861b2263c21ae1b6"><code>db38cb3</code></a>
CLI: Serve skills through one path with a single expected-failure
channel</li>
<li><a
href="https://github.com/storybookjs/storybook/commit/79bc6a63e0ecd6eb10baecb6302661da09eea1f7"><code>79bc6a6</code></a>
CLI: Address review on skills reshape; credit skills --all in eval
parser</li>
<li><a
href="https://github.com/storybookjs/storybook/commit/c11b0f2a6eb1e15b489a8c0bc17c5eace4c8a8b5"><code>c11b0f2</code></a>
CLI: Drop per-skill --help; --help always prints the catalog</li>
<li><a
href="https://github.com/storybookjs/storybook/commit/c878263a6ced94ef30148b99758bea139122f5de"><code>c878263</code></a>
CLI: Drop skills get/list, add skills --all</li>
<li><a
href="https://github.com/storybookjs/storybook/commit/c55462ef810dcf5641636a54021861f5d1d90222"><code>c55462e</code></a>
Merge pull request <a
href="https://github.com/storybookjs/storybook/tree/HEAD/code/core/issues/36117">#36117</a>
from storybookjs/kasper/tools-record-storybook-path</li>
<li><a
href="https://github.com/storybookjs/storybook/commit/0ad1336cbf0ecdab9f6b540570ae9015ae73ab86"><code>0ad1336</code></a>
Bump version from &quot;10.6.0-beta.1&quot; to &quot;10.6.0-beta.2&quot;
[skip ci]</li>
<li><a
href="https://github.com/storybookjs/storybook/commit/8ad41c80847390d53af17342e33c94d0f87bb368"><code>8ad41c8</code></a>
CLI: Reject surplus skills arguments</li>
<li><a
href="https://github.com/storybookjs/storybook/commit/8d607e3b18731f63e09d23ad488623f0c01224bd"><code>8d607e3</code></a>
Tools: Match Storybook installations correctly on Windows</li>
<li>Additional commits viewable in <a
href="https://github.com/storybookjs/storybook/commits/v10.6.0/code/core">compare
view</a></li>
</ul>
</details>
<br />

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-10-01 16:32:07 -07:00
dependabot[bot] 67ebed8a52 build(deps): bump lucide-react from 1.45.0 to 1.48.0 (#12985)
Bumps
[lucide-react](https://github.com/lucide-icons/lucide/tree/HEAD/packages/lucide-react)
from 1.45.0 to 1.48.0.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/lucide-icons/lucide/releases">lucide-react's
releases</a>.</em></p>
<blockquote>
<h2>Version 1.48.0</h2>
<h2>What's Changed</h2>
<ul>
<li>feat(icons): added <code>briefcase-plus</code> icon by <a
href="https://github.com/tylerkade"><code>@​tylerkade</code></a> in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/4757">lucide-icons/lucide#4757</a></li>
<li>feat(icons): added <code>square-sparkles</code> icon by <a
href="https://github.com/nananecy"><code>@​nananecy</code></a> in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/3610">lucide-icons/lucide#3610</a></li>
<li>feat(icons): added <code>line-dot-left-horizontal</code> icon by <a
href="https://github.com/nathan-de-pachtere"><code>@​nathan-de-pachtere</code></a>
in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/3855">lucide-icons/lucide#3855</a></li>
<li>fix(packages/svelte,solid): fix shared type imports in Solid and
Svelte by <a
href="https://github.com/karsa-mistmere"><code>@​karsa-mistmere</code></a>
in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/4846">lucide-icons/lucide#4846</a></li>
<li>chore(deps-dev): bump react-native from 0.76.9 to 0.87.1 in the
react-native-deps group across 1 directory by <a
href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/4673">lucide-icons/lucide#4673</a></li>
<li>feat(packages): export __iconNode data across framework packages by
<a href="https://github.com/lx3133584"><code>@​lx3133584</code></a> in
<a
href="https://redirect.github.com/lucide-icons/lucide/pull/4761">lucide-icons/lucide#4761</a></li>
<li>fix(icons): Tweak <code>card-sim</code> chip by <a
href="https://github.com/danielbayley"><code>@​danielbayley</code></a>
in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/3649">lucide-icons/lucide#3649</a></li>
<li>feat(icons): added <code>line-dot-top-vertical</code> icon by <a
href="https://github.com/nathan-de-pachtere"><code>@​nathan-de-pachtere</code></a>
in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/3856">lucide-icons/lucide#3856</a></li>
<li>feat(icons): added <code>line-dot-bottom-vertical</code> icon by <a
href="https://github.com/nathan-de-pachtere"><code>@​nathan-de-pachtere</code></a>
in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/3857">lucide-icons/lucide#3857</a></li>
<li>fix(packages/react-native): pass testID to the rendered Svg element
by <a href="https://github.com/OlegBezr"><code>@​OlegBezr</code></a> in
<a
href="https://redirect.github.com/lucide-icons/lucide/pull/4881">lucide-icons/lucide#4881</a></li>
<li>chore(<code>@​lucide/vue</code>): Fix types <code>@lucide/vue</code>
package and added workflow for it. by <a
href="https://github.com/ericfennis"><code>@​ericfennis</code></a> in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/4883">lucide-icons/lucide#4883</a></li>
<li>test(packages/shared): cover buildLucideIconForReact by <a
href="https://github.com/vugarbbakhishov-hub"><code>@​vugarbbakhishov-hub</code></a>
in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/4872">lucide-icons/lucide#4872</a></li>
<li>feat(site): Better icon detail page and add unreleased flag by <a
href="https://github.com/ericfennis"><code>@​ericfennis</code></a> in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/4877">lucide-icons/lucide#4877</a></li>
<li>fix(icons): changed <code>map-pinned</code> icon by <a
href="https://github.com/jguddas"><code>@​jguddas</code></a> in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/4880">lucide-icons/lucide#4880</a></li>
<li>fix(icons): changed <code>mail-pen</code> by <a
href="https://github.com/karsa-mistmere"><code>@​karsa-mistmere</code></a>
in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/4899">lucide-icons/lucide#4899</a></li>
<li>chore(deps-dev): bump the angular-deps group across 1 directory with
14 updates by <a
href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/4895">lucide-icons/lucide#4895</a></li>
<li>chore(deps): bump the vue-deps group with 3 updates by <a
href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/4893">lucide-icons/lucide#4893</a></li>
<li>chore(typchecking): More typecheck jobs for all packages by <a
href="https://github.com/ericfennis"><code>@​ericfennis</code></a> in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/4885">lucide-icons/lucide#4885</a></li>
<li>feat(icons): add house-cog icon by <a
href="https://github.com/ajaxjiang96"><code>@​ajaxjiang96</code></a> in
<a
href="https://redirect.github.com/lucide-icons/lucide/pull/4904">lucide-icons/lucide#4904</a></li>
</ul>
<h2>New Contributors</h2>
<ul>
<li><a href="https://github.com/nananecy"><code>@​nananecy</code></a>
made their first contribution in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/3610">lucide-icons/lucide#3610</a></li>
<li><a href="https://github.com/OlegBezr"><code>@​OlegBezr</code></a>
made their first contribution in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/4881">lucide-icons/lucide#4881</a></li>
<li><a
href="https://github.com/vugarbbakhishov-hub"><code>@​vugarbbakhishov-hub</code></a>
made their first contribution in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/4872">lucide-icons/lucide#4872</a></li>
<li><a
href="https://github.com/ajaxjiang96"><code>@​ajaxjiang96</code></a>
made their first contribution in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/4904">lucide-icons/lucide#4904</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/lucide-icons/lucide/compare/1.47.0...1.48.0">https://github.com/lucide-icons/lucide/compare/1.47.0...1.48.0</a></p>
<h2>Version 1.47.0</h2>
<h2>What's Changed</h2>
<ul>
<li>feat(icons): add lambda icon by <a
href="https://github.com/UbaidUllah9962"><code>@​UbaidUllah9962</code></a>
in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/4017">lucide-icons/lucide#4017</a></li>
<li>feat(icons): delegated <code>faucet</code> icon from lab by <a
href="https://github.com/karsa-mistmere"><code>@​karsa-mistmere</code></a>
in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/4764">lucide-icons/lucide#4764</a></li>
<li>feat(icons): added <code>door-closed-package</code> icon by <a
href="https://github.com/karsa-mistmere"><code>@​karsa-mistmere</code></a>
in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/4814">lucide-icons/lucide#4814</a></li>
<li>feat(icons): added 'nepali-rupee' icon by <a
href="https://github.com/sarajdhakal"><code>@​sarajdhakal</code></a> in
<a
href="https://redirect.github.com/lucide-icons/lucide/pull/4608">lucide-icons/lucide#4608</a></li>
<li>feat(icons): added <code>tube-lotion</code> icon by <a
href="https://github.com/AlecRust"><code>@​AlecRust</code></a> in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/4029">lucide-icons/lucide#4029</a></li>
<li>feat(icons): Added cupcake icon by <a
href="https://github.com/briz123"><code>@​briz123</code></a> in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/3000">lucide-icons/lucide#3000</a></li>
<li>feat(icons): added square-dashed-x icon by <a
href="https://github.com/EthanHazel"><code>@​EthanHazel</code></a> in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/4535">lucide-icons/lucide#4535</a></li>
<li>feat(icons): add <code>rotate-cw-clock</code> icon by <a
href="https://github.com/gkkconan"><code>@​gkkconan</code></a> in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/3979">lucide-icons/lucide#3979</a></li>
<li>fix(icons): remove path from save-off by <a
href="https://github.com/HPRILLER"><code>@​HPRILLER</code></a> in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/4848">lucide-icons/lucide#4848</a></li>
<li>fix(icons): changed <code>calendar-chevrons-right</code> by <a
href="https://github.com/karsa-mistmere"><code>@​karsa-mistmere</code></a>
in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/4865">lucide-icons/lucide#4865</a></li>
<li>fix(icons): changed <code>broccoli</code> icon by <a
href="https://github.com/jguddas"><code>@​jguddas</code></a> in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/4871">lucide-icons/lucide#4871</a></li>
<li>feat(icons): added square-dashed-plus by <a
href="https://github.com/psjdev"><code>@​psjdev</code></a> in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/4849">lucide-icons/lucide#4849</a></li>
</ul>
<h2>New Contributors</h2>
<ul>
<li><a
href="https://github.com/UbaidUllah9962"><code>@​UbaidUllah9962</code></a>
made their first contribution in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/4017">lucide-icons/lucide#4017</a></li>
<li><a
href="https://github.com/sarajdhakal"><code>@​sarajdhakal</code></a>
made their first contribution in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/4608">lucide-icons/lucide#4608</a></li>
<li><a href="https://github.com/AlecRust"><code>@​AlecRust</code></a>
made their first contribution in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/4029">lucide-icons/lucide#4029</a></li>
<li><a href="https://github.com/gkkconan"><code>@​gkkconan</code></a>
made their first contribution in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/3979">lucide-icons/lucide#3979</a></li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/lucide-icons/lucide/commit/f06ac67e33d645c40b8ce19a0419c85c5d7dd751"><code>f06ac67</code></a>
chore(typchecking): More typecheck jobs for all packages (<a
href="https://github.com/lucide-icons/lucide/tree/HEAD/packages/lucide-react/issues/4885">#4885</a>)</li>
<li>See full diff in <a
href="https://github.com/lucide-icons/lucide/commits/1.48.0/packages/lucide-react">compare
view</a></li>
</ul>
</details>
<br />

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
canary/v2026.1001.0-canary.11
2026-10-01 16:02:11 -07:00
dependabot[bot] c9cde69299 build(deps): bump @anthropic-ai/sdk from 0.121.0 to 0.129.0 (#13386)
Bumps
[@anthropic-ai/sdk](https://github.com/anthropics/anthropic-sdk-typescript)
from 0.121.0 to 0.129.0.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/anthropics/anthropic-sdk-typescript/releases">@​anthropic-ai/sdk's
releases</a>.</em></p>
<blockquote>
<h2>sdk: v0.129.0</h2>
<h2>0.129.0 (2026-09-28)</h2>
<p>Full Changelog: <a
href="https://github.com/anthropics/anthropic-sdk-typescript/compare/sdk-v0.128.0...sdk-v0.129.0">sdk-v0.128.0...sdk-v0.129.0</a></p>
<h3>Features</h3>
<ul>
<li><strong>api:</strong> add between_tools thinking type (<a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/ab51075609a2d583dffdca24856f4214779d9e7f">ab51075</a>)</li>
<li><strong>api:</strong> add claude-sonnet-5-5 (<a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/4e7736625fd23a5607800e8de4aa3c37daa74a07">4e77366</a>)</li>
<li><strong>api:</strong> add ClientToolUnion type for client-executed
tools (<a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/2c1d2d712071a5f10d2e70ea02dc33425b087799">2c1d2d7</a>)</li>
<li><strong>api:</strong> add include_inherited and source to workspace
rate limits (<a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/66e925e54ff3435a56f51f687641728b94aff306">66e925e</a>)</li>
<li><strong>api:</strong> add typed event type values to the Managed
Agents events list filter (<a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/8ac4a26809418453b64fee79f8ec790d32d1f92c">8ac4a26</a>)</li>
<li><strong>api:</strong> cache diagnostics GA — diagnostics on Message
/ MessageCreateParams (<a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/5ba5f29696d520f68a794936eff7337dce83ac05">5ba5f29</a>)</li>
<li><strong>tools:</strong> optionally start tool calls while the reply
streams (<a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/083969beadb360b9c4b329ee2541f67bd78d9caf">083969b</a>)</li>
</ul>
<h3>Bug Fixes</h3>
<ul>
<li><strong>client:</strong> also send X-Stainless-Timeout for
client-level timeouts (<a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/b84783b6ee03eed519d622ea1e477cf8eb3863bf">b84783b</a>)</li>
<li><strong>client:</strong> send upload filenames as given, with no
placeholder (<a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/f9d3e980b1b498c1c452300a205811f6a56de69b">f9d3e98</a>)</li>
<li><strong>helpers:</strong> degrade between_tools thinking to disabled
on fallback hops (<a
href="https://redirect.github.com/anthropics/anthropic-sdk-typescript/issues/841">#841</a>)
(<a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/edbbf05a62ffe2c95c13810f6d7a0a2796786e5f">edbbf05</a>)</li>
<li><strong>internal:</strong> let bundlers drop unused classes with
more than ten private-member assignments (<a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/67c7adbe5ebae805631e104b341d932a1554bda8">67c7adb</a>)</li>
<li><strong>streaming:</strong> show every complete array item and hold
back unfinished numbers in partial tool input (<a
href="https://redirect.github.com/anthropics/anthropic-sdk-typescript/issues/781">#781</a>)
(<a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/58065889d6b112db6da5127484e0a24025e3fa37">5806588</a>)</li>
</ul>
<h3>Performance Improvements</h3>
<ul>
<li><strong>streaming:</strong> drop the redundant iterSSEChunks layer
(<a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/0357f812dab273c0780c558606663a03e93e34df">0357f81</a>)</li>
<li><strong>streaming:</strong> take each string token as one slice in
the partial JSON tokenizer (<a
href="https://redirect.github.com/anthropics/anthropic-sdk-typescript/issues/255">#255</a>)
(<a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/cdfb1e55afebe1c3be50401ca56bebf0ff009a4e">cdfb1e5</a>)</li>
</ul>
<h3>Chores</h3>
<ul>
<li><strong>api:</strong> deprecate the betas param on GA models and
completions methods (<a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/5c74e4532bb69f22afa3e08013645ac059440aef">5c74e45</a>)</li>
<li><strong>api:</strong> list the known model ids first in the Model
types (<a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/94528226386311c3ade468cbdea0326c06a1e53d">9452822</a>)</li>
<li><strong>ci:</strong> choose the CI runner by repository (<a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/33db1ec2e99a415ff98619cf88ddddbf2b7ca7b1">33db1ec</a>)</li>
<li><strong>docs:</strong> clarify that stream: true returns the raw
event stream (<a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/4286c227c3a605bf04d4f59ffb496f44c102a6ec">4286c22</a>)</li>
<li><strong>docs:</strong> make Managed Agents actor descriptions
resource-neutral (<a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/15733f98deaae4aee2fba26c1bfe4ee1514c7080">15733f9</a>)</li>
<li><strong>docs:</strong> restore the research-preview notice on the
Dream type (<a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/b32f8baa27c40ad5901531024bae86e0ca046bb5">b32f8ba</a>)</li>
<li><strong>internal:</strong> move old constants around (<a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/0cd8edfdc6dd91af4ffee4ed3cc7fc8cc22d65e3">0cd8edf</a>)</li>
<li><strong>tests:</strong> add diagnostics to the parser test's Message
fixtures (<a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/eb5ca58d51ed3309b1f317b20f7d248b036ba76a">eb5ca58</a>)</li>
<li><strong>tools:</strong> remove client-side compaction control (<a
href="https://redirect.github.com/anthropics/anthropic-sdk-typescript/issues/802">#802</a>)
(<a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/9c3e8a5ffa38c35dec32f0258becd360babd5fb1">9c3e8a5</a>)</li>
</ul>
<h3>Documentation</h3>
<ul>
<li><strong>api:</strong> prefer each field's own description over its
shared type's (<a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/51934782720725acca570edeb0a3a7501ca7dbd8">5193478</a>)</li>
<li>expand CLAUDE.md into a full contributor guide (<a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/98d2ddbce7c1eabbabe5a130d18d307c237fb75c">98d2ddb</a>)</li>
</ul>
<h2>sdk: v0.128.0</h2>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/anthropics/anthropic-sdk-typescript/blob/main/CHANGELOG.md">@​anthropic-ai/sdk's
changelog</a>.</em></p>
<blockquote>
<h2>0.129.0 (2026-09-28)</h2>
<p>Full Changelog: <a
href="https://github.com/anthropics/anthropic-sdk-typescript/compare/sdk-v0.128.0...sdk-v0.129.0">sdk-v0.128.0...sdk-v0.129.0</a></p>
<h3>Features</h3>
<ul>
<li><strong>api:</strong> add between_tools thinking type (<a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/ab51075609a2d583dffdca24856f4214779d9e7f">ab51075</a>)</li>
<li><strong>api:</strong> add claude-sonnet-5-5 (<a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/4e7736625fd23a5607800e8de4aa3c37daa74a07">4e77366</a>)</li>
<li><strong>api:</strong> add ClientToolUnion type for client-executed
tools (<a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/2c1d2d712071a5f10d2e70ea02dc33425b087799">2c1d2d7</a>)</li>
<li><strong>api:</strong> add include_inherited and source to workspace
rate limits (<a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/66e925e54ff3435a56f51f687641728b94aff306">66e925e</a>)</li>
<li><strong>api:</strong> add typed event type values to the Managed
Agents events list filter (<a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/8ac4a26809418453b64fee79f8ec790d32d1f92c">8ac4a26</a>)</li>
<li><strong>api:</strong> cache diagnostics GA — diagnostics on Message
/ MessageCreateParams (<a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/5ba5f29696d520f68a794936eff7337dce83ac05">5ba5f29</a>)</li>
<li><strong>tools:</strong> optionally start tool calls while the reply
streams (<a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/083969beadb360b9c4b329ee2541f67bd78d9caf">083969b</a>)</li>
</ul>
<h3>Bug Fixes</h3>
<ul>
<li><strong>client:</strong> also send X-Stainless-Timeout for
client-level timeouts (<a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/b84783b6ee03eed519d622ea1e477cf8eb3863bf">b84783b</a>)</li>
<li><strong>client:</strong> send upload filenames as given, with no
placeholder (<a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/f9d3e980b1b498c1c452300a205811f6a56de69b">f9d3e98</a>)</li>
<li><strong>helpers:</strong> degrade between_tools thinking to disabled
on fallback hops (<a
href="https://redirect.github.com/anthropics/anthropic-sdk-typescript/issues/841">#841</a>)
(<a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/edbbf05a62ffe2c95c13810f6d7a0a2796786e5f">edbbf05</a>)</li>
<li><strong>internal:</strong> let bundlers drop unused classes with
more than ten private-member assignments (<a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/67c7adbe5ebae805631e104b341d932a1554bda8">67c7adb</a>)</li>
<li><strong>streaming:</strong> show every complete array item and hold
back unfinished numbers in partial tool input (<a
href="https://redirect.github.com/anthropics/anthropic-sdk-typescript/issues/781">#781</a>)
(<a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/58065889d6b112db6da5127484e0a24025e3fa37">5806588</a>)</li>
</ul>
<h3>Performance Improvements</h3>
<ul>
<li><strong>streaming:</strong> drop the redundant iterSSEChunks layer
(<a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/0357f812dab273c0780c558606663a03e93e34df">0357f81</a>)</li>
<li><strong>streaming:</strong> take each string token as one slice in
the partial JSON tokenizer (<a
href="https://redirect.github.com/anthropics/anthropic-sdk-typescript/issues/255">#255</a>)
(<a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/cdfb1e55afebe1c3be50401ca56bebf0ff009a4e">cdfb1e5</a>)</li>
</ul>
<h3>Chores</h3>
<ul>
<li><strong>api:</strong> deprecate the betas param on GA models and
completions methods (<a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/5c74e4532bb69f22afa3e08013645ac059440aef">5c74e45</a>)</li>
<li><strong>api:</strong> list the known model ids first in the Model
types (<a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/94528226386311c3ade468cbdea0326c06a1e53d">9452822</a>)</li>
<li><strong>ci:</strong> choose the CI runner by repository (<a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/33db1ec2e99a415ff98619cf88ddddbf2b7ca7b1">33db1ec</a>)</li>
<li><strong>docs:</strong> clarify that stream: true returns the raw
event stream (<a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/4286c227c3a605bf04d4f59ffb496f44c102a6ec">4286c22</a>)</li>
<li><strong>docs:</strong> make Managed Agents actor descriptions
resource-neutral (<a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/15733f98deaae4aee2fba26c1bfe4ee1514c7080">15733f9</a>)</li>
<li><strong>docs:</strong> restore the research-preview notice on the
Dream type (<a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/b32f8baa27c40ad5901531024bae86e0ca046bb5">b32f8ba</a>)</li>
<li><strong>internal:</strong> move old constants around (<a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/0cd8edfdc6dd91af4ffee4ed3cc7fc8cc22d65e3">0cd8edf</a>)</li>
<li><strong>tests:</strong> add diagnostics to the parser test's Message
fixtures (<a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/eb5ca58d51ed3309b1f317b20f7d248b036ba76a">eb5ca58</a>)</li>
<li><strong>tools:</strong> remove client-side compaction control (<a
href="https://redirect.github.com/anthropics/anthropic-sdk-typescript/issues/802">#802</a>)
(<a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/9c3e8a5ffa38c35dec32f0258becd360babd5fb1">9c3e8a5</a>)</li>
</ul>
<h3>Documentation</h3>
<ul>
<li><strong>api:</strong> prefer each field's own description over its
shared type's (<a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/51934782720725acca570edeb0a3a7501ca7dbd8">5193478</a>)</li>
<li>expand CLAUDE.md into a full contributor guide (<a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/98d2ddbce7c1eabbabe5a130d18d307c237fb75c">98d2ddb</a>)</li>
</ul>
<h2>0.128.0 (2026-09-22)</h2>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/bf2058689f845dfb10e59bd9ebeb5cb4e9318a9d"><code>bf20586</code></a>
Merge pull request <a
href="https://redirect.github.com/anthropics/anthropic-sdk-typescript/issues/1218">#1218</a>
from anthropics/release-please--branches--main--chan...</li>
<li><a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/da41a5a0e5d6f498f1bb8b71beb5b1e0a2bd1e48"><code>da41a5a</code></a>
chore: release main</li>
<li><a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/3a79b93f0210a83f8bf9fda91a42b577c9e6b93c"><code>3a79b93</code></a>
codegen metadata</li>
<li><a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/4e7736625fd23a5607800e8de4aa3c37daa74a07"><code>4e77366</code></a>
feat(api): add claude-sonnet-5-5</li>
<li><a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/2c1d2d712071a5f10d2e70ea02dc33425b087799"><code>2c1d2d7</code></a>
feat(api): add ClientToolUnion type for client-executed tools</li>
<li><a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/f9d3e980b1b498c1c452300a205811f6a56de69b"><code>f9d3e98</code></a>
fix(client): send upload filenames as given, with no placeholder</li>
<li><a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/8ac4a26809418453b64fee79f8ec790d32d1f92c"><code>8ac4a26</code></a>
feat(api): add typed event type values to the Managed Agents events list
filter</li>
<li><a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/083969beadb360b9c4b329ee2541f67bd78d9caf"><code>083969b</code></a>
feat(tools): optionally start tool calls while the reply streams</li>
<li><a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/9505bf37def4a4ada41c95e4e4fa7fb6b3b3f679"><code>9505bf3</code></a>
codegen metadata</li>
<li><a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/b84783b6ee03eed519d622ea1e477cf8eb3863bf"><code>b84783b</code></a>
fix(client): also send X-Stainless-Timeout for client-level
timeouts</li>
<li>Additional commits viewable in <a
href="https://github.com/anthropics/anthropic-sdk-typescript/compare/sdk-v0.121.0...sdk-v0.129.0">compare
view</a></li>
</ul>
</details>
<br />

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
canary/v2026.1001.0-canary.10
2026-10-01 15:30:19 -07:00
Devin FoleyandPaperclip 4b2bd6563d fix(chat): hide obsolete execution status and system notices (#14874)
## Thinking Path

> - Paperclip lets people oversee agent work through task conversations.
> - Conversations should show failures and waits that still affect the
task.
> - Old run errors and recovery notices remained visible after later
work or task completion.
> - These messages looked current even when no action remained.
> - This change hides obsolete execution status while preserving the
responses and activity.
> - The full diagnostic record stays available in run history.

## Linked Issues or Issue Description

**What happened?**

Task chat kept showing “Run failed”, “Stopped”, and “Waiting to resume”
after the execution had been superseded or the task had finished. Stored
system notices also remained in the conversation. Completed tasks
disabled Retry but kept the error message.

**Expected behavior**

Hide system status that no longer applies. Keep the latest unresolved
failure, active recovery holds, and useful recovery actions visible.
Preserve messages, files, questions, session boundaries, and inspectable
activity.

**Steps to reproduce**

1. Let a task run fail, then record a pre-start recovery wait.
2. Complete a later attempt or mark the task done.
3. Open the task conversation. Before this change, the old error and
wait remain visible.

**Paperclip version or commit**

Reproduced in component tests against `0f9e9be408`.

**Deployment mode**

Task chat in local or hosted deployments; both legacy adapters and the
native runner.

Related: #14857 and #14869 address execution recovery. This PR addresses
the remaining conversation presentation. Searched GitHub for historical
chat status, historical errors, and “Waiting to resume”; no duplicate PR
found.

## What Changed

- Determine status relevance from task state, attempt order, successor
evidence, and recovery state. Time alone does not hide errors.
- Hide obsolete run markers and stored execution notices. Require run or
recovery provenance, so unrelated system updates such as child-task
blockers remain visible. Keep errors from the latest failed attempt
actionable.
- Keep unresolved execution holds visible. A refused pre-start retry
does not replace a real attempt, and another agent’s work does not
resolve a run-specific error.
- Show historical activity without Worked/Stopped labels. Keep
historical failures out of the current turn’s summary.
- Anchor activity to visible comments so removing a notice cannot remove
the response or activity with it.
- Document the presentation rules and cover both runner modes and both
task presentation modes.

## Verification

- 334 focused component and status-policy tests passed across four
files, including the child-task relay regressions.
- `pnpm build` passed. The UI build also passed after the final
presentation changes.
- `pnpm exec vitest run --project @paperclipai/ui`: 667 files and 7,157
tests passed. Subsequent focused tests cover the final activity-anchor,
live-successor, and notice-provenance changes.
- `pnpm -r typecheck` passed. UI typecheck and build passed again after
the review fix.
- `pnpm test:run` completed its general-server phase with 14,716 tests
passed, 17 failed, and 87 skipped; it stopped before later phases. The
failures occurred in four unchanged server suites: chat channels, email
channels, company skills, and runtime skill cache. A targeted rerun
reproduced missing bundled skill paths and `EACCES` during
cache-directory rename on macOS. All Linux CI suites pass for the final
commit, including these server suites.
- Design token gates and diff checks pass.
- All 53 checks pass on commit `7af9753859`; two optional Storybook
checks are skipped. [Final CI
run](https://github.com/paperclipai/paperclip/actions/runs/36931968751)
includes build, full typecheck, all server and workspace test shards,
all eight end-to-end shards, runner verification, and the canary dry
run.
- Greptile scores the final commit at 5/5. No review threads remain
unresolved. The branch is current with `master` and has no merge
conflicts.

## Risks

This changes presentation only. It does not change execution, recovery,
stored comments, or run history. The main risk is hiding a current
diagnostic too early. Tests cover active holds, refused retries,
different agents, missing timestamps and provenance, live successors,
preserved responses, and the current retry target.

The base branch has a dependency override/lockfile mismatch. Local
installation used the same resolution fallback as CI, then restored the
tracked lockfile. No dependency changes are included.

## Model Used

OpenAI Codex (GPT-6). The exact runtime model identifier and context
window are not exposed in this session. Used reasoning, repository
inspection, code execution, and regression tests.

## Checklist

- [x] I have included a thinking path that traces from project context
to this change
- [x] I have specified the model used (with version and capability
details)
- [x] I have checked ROADMAP.md and confirmed this PR does not duplicate
planned core work
- [x] I have searched GitHub for duplicate or related PRs and linked
them above
- [x] I have either (a) linked existing issues with `Fixes: #` / `Closes
#` / `Refs #` OR (b) described the issue in-PR following the relevant
issue template
- [x] I have not referenced internal/instance-local Paperclip issues or
links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip`
URLs)
- [x] My branch name describes the change (e.g. `docs/...`, `fix/...`)
and contains no internal Paperclip ticket id or instance-derived details
- [ ] I have run tests locally and they pass — changed-code tests pass;
unrelated full-suite failures are documented above
- [x] I have added or updated tests where applicable
- [x] I have updated relevant documentation to reflect my changes
- [x] I have considered and documented any risks above
- [x] All Paperclip CI gates are green
- [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups
- [x] I will address all Greptile and reviewer comments before
requesting merge

---------

Co-authored-by: Paperclip <noreply@paperclip.ing>
canary/v2026.1001.0-canary.9
2026-10-01 15:18:47 -07:00
dependabot[bot] 2a36e915ef build(deps): bump @vercel/connect from 0.6.1 to 2.3.3 (#13390)
Bumps
[@vercel/connect](https://github.com/vercel/vercel/tree/HEAD/packages/connect)
from 0.6.1 to 2.3.3.
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/vercel/vercel/blob/main/packages/connect/CHANGELOG.md">@​vercel/connect's
changelog</a>.</em></p>
<blockquote>
<h1><code>@​vercel/connect</code></h1>
<h2>2.0.2</h2>
<h3>Patch Changes</h3>
<ul>
<li>c028593: Update the Core SDK documentation to show how to start an
authorization request.</li>
</ul>
<h2>2.0.1</h2>
<h3>Patch Changes</h3>
<ul>
<li>2ecb357: <code>connectGitHubCredentials</code> now resolves the
GitHub App slug from the connector's metadata and exposes it as
<code>appSlug</code> on the returned credentials, so eve's
<code>githubChannel</code> can derive its invocation token
(<code>botName</code>) without extra configuration.</li>
</ul>
<h2>2.0.0</h2>
<h3>Major Changes</h3>
<ul>
<li>42938f9: Make Eve connector provisioning opt-in with
<code>autoProvision: true</code>. When enabled, try token and
authorization requests before provisioning, then provision and retry
once only when the connector is missing or not linked to the
project.</li>
</ul>
<h2>1.1.0</h2>
<h3>Minor Changes</h3>
<ul>
<li>b9fab7c: Add Sendblue credential helpers for Eve-native channels and
the Chat SDK adapter, including Connect trigger-forwarded webhook
verification for Chat SDK users.</li>
</ul>
<h2>1.0.0</h2>
<h3>Major Changes</h3>
<ul>
<li>9b55136: Default omitted scopes to <code>['*']</code> in token and
authorization requests.</li>
</ul>
<h3>Minor Changes</h3>
<ul>
<li>4199902: Send Vercel API requests to the region from
<code>VERCEL_REGION</code>, with a <code>region</code> option to
override it.</li>
</ul>
<h2>0.9.0</h2>
<h3>Minor Changes</h3>
<ul>
<li>46a5aaa: Add Linq helpers for Eve and Chat SDK applications.
<code>connectLinqCredentials</code> resolves an app-scoped Linq API key,
and <code>connectLinqAdapter</code> adds trusted Connect OIDC
verification for trigger-forwarded Linq webhooks while retaining the
provider signing secret within Connect.</li>
</ul>
<h2>0.8.1</h2>
<h3>Patch Changes</h3>
<ul>
<li><code>@​vercel/oidc</code><a
href="https://github.com/3"><code>@​3</code></a>.8.5</li>
</ul>
<h2>0.8.0</h2>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li>See full diff in <a
href="https://github.com/vercel/vercel/commits/@now/next@2.3.3/packages/connect">compare
view</a></li>
</ul>
</details>
<br />

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
canary/v2026.1001.0-canary.8
2026-10-01 14:44:00 -07:00
Devin FoleyandPaperclip f2e0f19630 Defer agent directory cleanup until stop proof is available (#14866)
## Thinking Path

> - Paperclip manages agents and their persistent files.
> - Each run owns a temporary agent directory and a save receipt.
> - Cleanup needs independent proof that the owning process stopped.
> - A cleanup call without that proof currently waits for the directory
lock anyway.
> - A second lock failure can prevent environment release after the run
already reported a failed save.
> - This change skips cleanup that has no authority and retries
unavailable remote copies after exact destruction proof.
> - The save failure stays visible. Existing lock owners remain
protected.

## Linked Issues or Issue Description

Related work: Refs #14787 (lock diagnostics), #14695 (warm instruction
ownership), #9667 (stale lock proposal), and #9872 (control-plane
ownership proposal). I checked open PRs and issues. This change leaves
the shared filesystem lock protocol in place and does not duplicate the
warm-retention work in #14695.

**What happened?**

Heartbeat cleanup records an explicit unavailable instruction-save
warning, then calls directory release before releasing the environment
lease. Release can wait for a lock even though the copy has no
process-stop proof and cannot be removed. That secondary timeout
prevents the following lease-release step. If destruction proof arrives
later, the unavailable copy is excluded from both recovery queries.

**Expected behavior**

Skip a release that cannot remove anything. Preserve the failed-save
receipt and candidate fields. Once exact remote destruction is recorded,
recover remote cleanup without running a provider command. Unavailable
local copies retain their potentially uncollected edits even if local
stop proof arrives later. A blocked cleanup must not prevent cleanup for
other agents.

**Steps to reproduce**

1. Prepare an agent directory, report its save unavailable, and leave
process-stop proof absent.
2. Hold the shared directory lock and call release. Before this change,
release waits and fails although removal is not authorized.
3. Record destruction of the copy's exact remote lease. Before this
change, neither recovery sweep selects the unavailable copy.

**Paperclip version or commit**

Reproduced against `efc2e6810e9bc0dc8cb412b0e7647c0db9821caa`.

**Deployment mode**

Local and remote execution with persistent agent directories. Tests use
an isolated embedded PostgreSQL database and fixture transports.

## What Changed

- Re-read receipts and skip release before lock acquisition when stop
proof is absent, the copy is superseded, or cleanup is complete. Keep
the same checks inside the lock.
- Recover unavailable remote copies only after exact destruction proof.
Preserve their unavailable state, errors, candidate hash, and candidate
bytes. Keep unavailable local copies and their uncollected edits
unchanged.
- Store destruction-only cleanup authority with the stop proof. Later
cleanup honors it after a lost database response or restart, including
when a transport remains cached.
- Defer failed or unproven cleanup with bounded batches and a retry
delay. Keep failed cleanup visible in logs and its receipt.
- Serialize preparation of an existing run with cleanup. Fresh run
preparation keeps its existing admission path.
- Cover held locks, receipt scope, delayed proof, batch fairness, lost
update responses, cached transports, and concurrent same-run preparation
with database regressions.

## Verification

- Focused directory, legacy instruction-copy, shared lock, and bounded
diagnostic suites: 169 tests passed across four files.
- `pnpm -r typecheck`: passed on the final source.
- `pnpm build`: passed on the final source.
- Completed all selected local `pnpm test:run` groups: 733 general
server suites, 149 serialized suites, and 14 workspace projects. There
are 13 known macOS `EACCES` failures in the unchanged runtime skill
cache tests. Their exact signatures match earlier clean-base results,
and the cache source and test blobs match both that base and this PR
base (existing fix: #14290). One CLI import test timed out under
concurrent load; its full file passed separately (17 tests). Broad
coverage began before the review corrections; the final source has the
focused 169-test run, typecheck, and build. This is a local verification
limit, not a passing full local suite.
- `git diff --check` and local Gitleaks plus private-identifier/PII diff
scans passed.
- Independent review of the final source found no remaining actionable
issue. Its 17 targeted tests cover crash recovery, cached transports,
same-run preparation, real local edit preservation, proof scope, and
batch fairness. The main focused run also covers contained scheduling
failures.
- Final commit `35a24085f7`: Greptile 5/5 with no recommendations and
zero unresolved review threads.
- Final commit `35a24085f7`: all 53 checks passed, including Canary Dry
Run and the security scan; two visual checks were intentionally skipped.
The workspace shard passed on retry after GitHub reported that its first
runner lost communication. An earlier Canary runner shut down after the
release dry run passed. Neither interruption recorded an application
assertion failure; the exact final-head checks are now green.

## Risks

- This repairs cleanup ordering and recovery eligibility. It does not
repair an ambiguous legacy lock owner or restore unsaved files. Actual
collection still fails visibly when its lock cannot be acquired.
- An unavailable remote copy is recovered only after exact destruction
proof. A stopped but retained environment stays protected; recovery does
not execute a command that could restart it.
- Unavailable local copies with later stop proof still retain
potentially uncollected edits. A general local recollection or
reclamation policy remains outside this change.
- Existing-run preparation now waits for the same lock as cleanup. The
fresh-run path is unchanged.
- The cleanup mode is stored in the existing private receipt JSON. No
schema migration or public API change is required.
- No deployment, task replay, or runtime lock deletion was performed.

## Model Used

OpenAI GPT-6 (Codex), with reasoning, repository tools, and test
execution. The runtime does not expose a more specific model suffix or
context-window size.

## Checklist

- [x] I have included a thinking path that traces from project context
to this change
- [x] I have specified the model used (with version and capability
details)
- [x] I have checked ROADMAP.md and confirmed this PR does not duplicate
planned core work
- [x] I have searched GitHub for duplicate or related PRs and linked
them above
- [x] I have either (a) linked existing issues with `Fixes: #` / `Closes
#` OR (b) described the issue in-PR following the relevant issue
template
- [x] I have not referenced internal/instance-local Paperclip issues or
links (only public GitHub references)
- [x] My branch name describes the change and contains no internal
Paperclip ticket id
- [ ] I have run tests locally and they pass
- [x] I have added or updated tests where applicable
- [x] I have updated relevant documentation to reflect my changes
- [x] I have considered and documented any risks above
- [x] All Paperclip CI gates are green
- [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups
- [x] I will address all Greptile and reviewer comments before
requesting merge

---------

Co-authored-by: Paperclip <noreply@paperclip.ing>
2026-10-01 14:28:47 -07:00
dependabot[bot] 0f9e9be408 build(deps): bump @codemirror/state from 6.7.2 to 6.7.6 (#13391)
Bumps [@codemirror/state](https://github.com/codemirror/state) from
6.7.2 to 6.7.6.
<details>
<summary>Commits</summary>
<ul>
<li>See full diff in <a
href="https://github.com/codemirror/state/commits">compare view</a></li>
</ul>
</details>
<br />

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-10-01 13:45:48 -07:00
DottaandPaperclip 4039d4f06b fix(auth): allow scoped low-trust work and owner-chat instruction edits (#14870)
## Thinking Path

> - Paperclip is the open source app people use to manage AI agents for
work.
> - Low-trust agents must work within their assigned scope.
> - Task creation currently rejects these agents before checking
assignment permission or scope.
> - Persistent instruction saves also reject direct requests from
authorized chat owners.
> - This PR checks the requested action and its recorded authority
instead of denying all such work.
> - Agents can organize permitted work and follow their owner's
instruction-edit requests while outside work stays restricted.

## Linked Issues or Issue Description

**What happened?**

Low-trust agents cannot create self-assigned tasks or subtasks, even
within their allowed scope. An authorized user also cannot ask an agent
in their own Agent Chat to update its managed `AGENTS.md`. Agent-folder
collection can hide the permission rejection behind a generic save
failure.

**Expected behavior**

Allow task creation when assignment permissions and project or root-task
scope permit it. Allow instruction self-edits during authenticated
owner-chat execution, subject to the user's current edit permission.
Outside tasks, subtasks, connector messages, and peer agents do not
inherit that instruction authority. Explain the actual denial when a
save fails.

**Steps to reproduce**

1. Configure an active agent with `low_trust_review` and a project or
root-task boundary.
2. Ask it to create an in-scope task assigned to itself, or a subtask of
its own task.
3. As a user with permission to configure that agent, ask it in your
Agent Chat to update its managed `AGENTS.md`.
4. Observe blanket permission denials rather than action-specific
checks.

**Paperclip version or commit**

Rebased onto master at `8ec4b84e1`. This is a core authorization change,
independent of adapter choice.

**Deployment mode**

Authenticated server. Regression coverage uses the server services, HTTP
routes, native tool authority, and embedded PostgreSQL.

Related work: #14775 adds human-directed task execution. #13599 concerns
instruction-path configuration; this PR leaves that configuration
restricted. #11988 proposes separate active-review instruction
protection. #10693 reports unclear authorization denials on a different
API surface.

## What Changed

- Apply task-assignment checks to both HTTP creation routes and native
task creation, including unassigned work. Preserve low-trust policy and
source attribution on the created task and its initial plan.
- Allow self-assigned decomposition within the permitted project or
root-task tree. Resolve workspace-derived project scope before
authorization, and reauthorize existing tasks before duplicate detection
returns them. Keep cross-project and peer-assignment checks.
- Derive instruction self-edit authority from the accepted run identity
and authenticated owner-message wake. Recheck current permissions at
save time. Bind retries to the same request and chat session.
- Reject inherited instruction authority from outside tasks, subtasks,
plugins, connectors, stale sessions, cancelled runs, and peer edits.
- Surface permission errors in instruction and agent-folder save
receipts. Tell chat agents to explain the rejected action and the
specific restriction.
- Update the low-trust policy and implementation documentation.

## Verification

- All 297 tests in 11 focused server suites pass after the rebase. These
cover owner-chat saves, private copies, warm agent directories, reset
and retry boundaries, permission revocation, task creation routes, and
native tool authority.
- After review fixes, all 126 tests in the four affected
authorization/chat suites pass. Workspace scope regressions and 146
existing creation/ownership/workspace-route tests also pass.
- The final duplicate-task and CI fixes pass all 39 tests across
chat-project tools, duplicate creation, environment-selection guards,
and assignee-invokability routes. The duplicate-task test reproduced an
unauthorized response before the fix and verifies denial plus permitted
reuse afterward.
- `pnpm --filter @paperclipai/server typecheck` passes after rebasing;
`pnpm --filter @paperclipai/server exec tsc --noEmit` also passes after
the review fixes.
- `git diff --check origin/master...HEAD` passes.
- Final head `7e73270b86748792649e4ae6fbc6879f73b42b73`: all 54 checks
passed, with two expected skips and no pending or failed checks. This
includes builds, typechecking, the full test matrix, end-to-end tests,
runner verification, the canary dry run, and security scans.
- Greptile is 5/5 on that exact head, with no unresolved review threads.
This change has not been deployed to staging.

## Risks

This changes authorization behavior. The instruction exception must not
become an inherited task permission. The check uses server-owned
execution records, requires the agent's own chat and instructions, and
keeps normal protected-change and responsible-user checks. Saves fail
closed when current provenance or permission is missing. Owner chat
grants a turn-scoped capability; the server does not classify the
message intent or require approval of the exact new file bytes. Prompt
injection within an authorized owner-chat turn remains a model-level
risk. This is the requested owner-chat trust boundary, without a new
per-edit confirmation flow. No database migration or broad trust-preset
change is required.

## Model Used

OpenAI Codex, based on GPT-6, with reasoning, code editing, shell tools,
and test execution. The exact runtime model ID and context-window size
are not exposed in this session.

## Checklist

- [x] I have included a thinking path that traces from project context
to this change
- [x] I have specified the model used (with version and capability
details)
- [x] I have checked ROADMAP.md and confirmed this PR does not duplicate
planned core work
- [x] I have searched GitHub for duplicate or related PRs and linked
them above
- [x] I have either (a) linked existing issues with `Fixes: #` / `Closes
#` / `Refs #` OR (b) described the issue in-PR following the relevant
issue template
- [x] I have not referenced internal/instance-local Paperclip issues or
links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip`
URLs)
- [x] My branch name describes the change (e.g. `docs/...`, `fix/...`)
and contains no internal Paperclip ticket id or instance-derived details
- [x] I have run tests locally and they pass
- [x] I have added or updated tests where applicable
- [x] I have updated relevant documentation to reflect my changes
- [x] I have considered and documented any risks above
- [x] All Paperclip CI gates are green
- [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups
- [x] I will address all Greptile and reviewer comments before
requesting merge

---------

Co-authored-by: Paperclip <noreply@paperclip.ing>
2026-10-01 15:42:40 -05:00
dependabot[bot] e2d4f07207 build(deps): bump googleapis from 176.0.0 to 182.0.0 (#13393)
Bumps
[googleapis](https://github.com/googleapis/google-api-nodejs-client)
from 176.0.0 to 182.0.0.
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/googleapis/google-api-nodejs-client/commit/9eb464beb4310053dec5aef4661d6c6fd73051a8"><code>9eb464b</code></a>
chore: release main (<a
href="https://redirect.github.com/googleapis/google-api-nodejs-client/issues/4023">#4023</a>)</li>
<li><a
href="https://github.com/googleapis/google-api-nodejs-client/commit/9e3b4655c95fde3c69d2a44496a586e906695734"><code>9e3b465</code></a>
feat: regenerate index files</li>
<li><a
href="https://github.com/googleapis/google-api-nodejs-client/commit/279af87fcf2c4016321bde793a8cefd1a542615d"><code>279af87</code></a>
fix(youtubereporting): update the API</li>
<li><a
href="https://github.com/googleapis/google-api-nodejs-client/commit/b37c22595087460ffc1be63471bb56e3e81675f5"><code>b37c225</code></a>
fix(youtubeAnalytics): update the API</li>
<li><a
href="https://github.com/googleapis/google-api-nodejs-client/commit/512e921970a8556fc20aef5e7766826107018957"><code>512e921</code></a>
fix(youtube): update the API</li>
<li><a
href="https://github.com/googleapis/google-api-nodejs-client/commit/6cd997a07c55c80a3f3070cea06affd0aa3274c9"><code>6cd997a</code></a>
fix(workstations): update the API</li>
<li><a
href="https://github.com/googleapis/google-api-nodejs-client/commit/62d5f7629a9ddd6523b4f4050c955a2063007fce"><code>62d5f76</code></a>
fix(workspaceevents): update the API</li>
<li><a
href="https://github.com/googleapis/google-api-nodejs-client/commit/0d71cd6b01ed41b1dff0a04d85567cfd2a511495"><code>0d71cd6</code></a>
feat(workloadmanager): update the API</li>
<li><a
href="https://github.com/googleapis/google-api-nodejs-client/commit/2c46e13798ba24a8b4d2ad9e92f7995d7dcdd93e"><code>2c46e13</code></a>
fix(workflows): update the API</li>
<li><a
href="https://github.com/googleapis/google-api-nodejs-client/commit/c7b8641390370d9af9b12154e6bf455bc344feaa"><code>c7b8641</code></a>
fix(workflowexecutions): update the API</li>
<li>Additional commits viewable in <a
href="https://github.com/googleapis/google-api-nodejs-client/compare/googleapis-v176.0.0...googleapis-v182.0.0">compare
view</a></li>
</ul>
</details>
<br />

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
canary/v2026.1001.0-canary.7
2026-10-01 13:16:41 -07:00
dependabot[bot] d91eceb575 chore(deps): bump actions/github-script from 8.0.0 to 9.0.0 (#13471)
Bumps [actions/github-script](https://github.com/actions/github-script)
from 8.0.0 to 9.0.0.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/actions/github-script/releases">actions/github-script's
releases</a>.</em></p>
<blockquote>
<h2>v9.0.0</h2>
<p><strong>New features:</strong></p>
<ul>
<li><strong><code>getOctokit</code> factory function</strong> —
Available directly in the script context. Create additional
authenticated Octokit clients with different tokens for multi-token
workflows, GitHub App tokens, and cross-org access. See <a
href="https://github.com/actions/github-script#creating-additional-clients-with-getoctokit">Creating
additional clients with <code>getOctokit</code></a> for details and
examples.</li>
<li><strong>Orchestration ID in user-agent</strong> — The
<code>ACTIONS_ORCHESTRATION_ID</code> environment variable is
automatically appended to the user-agent string for request
tracing.</li>
</ul>
<p><strong>Breaking changes:</strong></p>
<ul>
<li><strong><code>require('@actions/github')</code> no longer works in
scripts.</strong> The upgrade to <code>@actions/github</code> v9
(ESM-only) means <code>require('@actions/github')</code> will fail at
runtime. If you previously used patterns like <code>const { getOctokit }
= require('@actions/github')</code> to create secondary clients, use the
new injected <code>getOctokit</code> function instead — it's available
directly in the script context with no imports needed.</li>
<li><code>getOctokit</code> is now an injected function parameter.
Scripts that declare <code>const getOctokit = ...</code> or <code>let
getOctokit = ...</code> will get a <code>SyntaxError</code> because
JavaScript does not allow <code>const</code>/<code>let</code>
redeclaration of function parameters. Use the injected
<code>getOctokit</code> directly, or use <code>var getOctokit =
...</code> if you need to redeclare it.</li>
<li>If your script accesses other <code>@actions/github</code> internals
beyond the standard <code>github</code>/<code>octokit</code> client, you
may need to update those references for v9 compatibility.</li>
</ul>
<h2>What's Changed</h2>
<ul>
<li>Add ACTIONS_ORCHESTRATION_ID to user-agent string by <a
href="https://github.com/Copilot"><code>@​Copilot</code></a> in <a
href="https://redirect.github.com/actions/github-script/pull/695">actions/github-script#695</a></li>
<li>ci: use deployment: false for integration test environments by <a
href="https://github.com/salmanmkc"><code>@​salmanmkc</code></a> in <a
href="https://redirect.github.com/actions/github-script/pull/712">actions/github-script#712</a></li>
<li>feat!: add getOctokit to script context, upgrade
<code>@​actions/github</code> v9, <code>@​octokit/core</code> v7, and
related packages by <a
href="https://github.com/salmanmkc"><code>@​salmanmkc</code></a> in <a
href="https://redirect.github.com/actions/github-script/pull/700">actions/github-script#700</a></li>
</ul>
<h2>New Contributors</h2>
<ul>
<li><a href="https://github.com/Copilot"><code>@​Copilot</code></a> made
their first contribution in <a
href="https://redirect.github.com/actions/github-script/pull/695">actions/github-script#695</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/actions/github-script/compare/v8.0.0...v9.0.0">https://github.com/actions/github-script/compare/v8.0.0...v9.0.0</a></p>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/actions/github-script/commit/3a2844b7e9c422d3c10d287c895573f7108da1b3"><code>3a2844b</code></a>
Merge pull request <a
href="https://redirect.github.com/actions/github-script/issues/700">#700</a>
from actions/salmanmkc/expose-getoctokit + prepare re...</li>
<li><a
href="https://github.com/actions/github-script/commit/ca10bbdd1a7739de09e99a200c7a59f5d73a4079"><code>ca10bbd</code></a>
fix: use <code>@​octokit/core/</code>types import for v7
compatibility</li>
<li><a
href="https://github.com/actions/github-script/commit/86e48e20ac85c970ed1f96e718fd068173948b7b"><code>86e48e2</code></a>
merge: incorporate main branch changes</li>
<li><a
href="https://github.com/actions/github-script/commit/c1084728b5b935ec4ddc1e4cee877b01797b3ff9"><code>c108472</code></a>
chore: rebuild dist for v9 upgrade and getOctokit factory</li>
<li><a
href="https://github.com/actions/github-script/commit/afff112e4f8b57c718168af75b89ce00bc8d091d"><code>afff112</code></a>
Merge pull request <a
href="https://redirect.github.com/actions/github-script/issues/712">#712</a>
from actions/salmanmkc/deployment-false + fix user-ag...</li>
<li><a
href="https://github.com/actions/github-script/commit/ff8117e5b78c415f814f39ad6998f424fee7b817"><code>ff8117e</code></a>
ci: fix user-agent test to handle orchestration ID</li>
<li><a
href="https://github.com/actions/github-script/commit/81c6b7876079abe10ff715951c9fc7b3e1ab389d"><code>81c6b78</code></a>
ci: use deployment: false to suppress deployment noise from integration
tests</li>
<li><a
href="https://github.com/actions/github-script/commit/3953caf8858d318f37b6cc53a9f5708859b5a7b7"><code>3953caf</code></a>
docs: update README examples from <a
href="https://github.com/v8"><code>@​v8</code></a> to <a
href="https://github.com/v9"><code>@​v9</code></a>, add getOctokit docs
and v9 brea...</li>
<li><a
href="https://github.com/actions/github-script/commit/c17d55b90dcdb3d554d0027a6c180a7adc2daf78"><code>c17d55b</code></a>
ci: add getOctokit integration test job</li>
<li><a
href="https://github.com/actions/github-script/commit/a047196d9a02fe92098771cafbb98c2f1814e408"><code>a047196</code></a>
test: add getOctokit integration tests via callAsyncFunction</li>
<li>Additional commits viewable in <a
href="https://github.com/actions/github-script/compare/ed597411d8f924073f98dfc5c65a23a2325f34cd...3a2844b7e9c422d3c10d287c895573f7108da1b3">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=actions/github-script&package-manager=github_actions&previous-version=8.0.0&new-version=9.0.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)


</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-10-01 13:10:29 -07:00
dependabot[bot] 793a98cd8c chore(deps): bump open from 11.0.1 to 11.0.4 (#13473)
Bumps [open](https://github.com/sindresorhus/open) from 11.0.1 to
11.0.4.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/sindresorhus/open/releases">open's
releases</a>.</em></p>
<blockquote>
<h2>v11.0.4</h2>
<ul>
<li>Fix <code>browser</code>/<code>browserPrivate</code> not detecting
Safari or Brave as the default browser 6ae6196</li>
</ul>
<hr />
<p><a
href="https://github.com/sindresorhus/open/compare/v11.0.3...v11.0.4">https://github.com/sindresorhus/open/compare/v11.0.3...v11.0.4</a></p>
<h2>v11.0.3</h2>
<ul>
<li>Fix Windows launches being killed when the parent process exits
734b821</li>
</ul>
<hr />
<p><a
href="https://github.com/sindresorhus/open/compare/v11.0.2...v11.0.3">https://github.com/sindresorhus/open/compare/v11.0.2...v11.0.3</a></p>
<h2>v11.0.2</h2>
<ul>
<li>Update dependencies  6f006ad</li>
</ul>
<hr />
<p><a
href="https://github.com/sindresorhus/open/compare/v11.0.1...v11.0.2">https://github.com/sindresorhus/open/compare/v11.0.1...v11.0.2</a></p>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/sindresorhus/open/commit/41511103abd932225b605b8e7f9e565cc180b1b6"><code>4151110</code></a>
11.0.4</li>
<li><a
href="https://github.com/sindresorhus/open/commit/6ae6196fa199cbc5eb4af007efd52e675c53b590"><code>6ae6196</code></a>
Fix <code>browser</code>/<code>browserPrivate</code> not detecting
Safari or Brave as the default b...</li>
<li><a
href="https://github.com/sindresorhus/open/commit/81deafb72a29ea16b2c3bdd30cdaf294aaa11d77"><code>81deafb</code></a>
11.0.3</li>
<li><a
href="https://github.com/sindresorhus/open/commit/734b821c36ee959dc11e380c3202770969347274"><code>734b821</code></a>
Fix Windows launches being killed when the parent process exits</li>
<li><a
href="https://github.com/sindresorhus/open/commit/ccf1fd644de3dfc9448438e185037eceb2d5d3d7"><code>ccf1fd6</code></a>
11.0.2</li>
<li><a
href="https://github.com/sindresorhus/open/commit/52d2d62d6f02f023720f4ca5a2f73bf050ae3ee7"><code>52d2d62</code></a>
Use <code>hasOwn</code> (<a
href="https://redirect.github.com/sindresorhus/open/issues/372">#372</a>)</li>
<li><a
href="https://github.com/sindresorhus/open/commit/6f006ad1a80950ff0dd9eb7e3252634153e3ef12"><code>6f006ad</code></a>
Update dependencies</li>
<li>See full diff in <a
href="https://github.com/sindresorhus/open/compare/v11.0.1...v11.0.4">compare
view</a></li>
</ul>
</details>
<br />

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-10-01 13:00:29 -07:00
Michael NguyenandClaude Opus 5.5 b721d24cac fix(adapter-utils): retry GitHub broker transport failures before falling back (#14856)
## Thinking Path

> - Paperclip is the open source app people use to manage AI agents for
work
> - Agents run `git` and `gh` through a managed launcher. The launcher
gets a GitHub credential from the Paperclip control plane
> - The launcher sends one request to the credential broker for each
command
> - If that request fails at the transport level, for example after a
10-second timeout, the launcher continues without managed credentials
> - So a slow or restarting control plane removes the managed GitHub
identity from that command. Some agents then use other GitHub identities
that do not have the necessary permissions
> - This pull request retries a failed broker request two more times,
with a short backoff, before the launcher gives up
> - The benefit is that a short control-plane delay does not remove the
managed identity from an agent's GitHub operation

## Linked Issues or Issue Description

Refs #14175. That pull request changes the same broker request loop for
a different failure: sandbox network denials. The pull request that
merges second must rebase.

**What happened**
A Codex agent ran `git` and `gh` through the managed launcher while the
control plane was under heavy memory pressure. Each command printed
`Paperclip: GitHub broker_transport_unavailable; continuing without
managed credentials.` The agent then tried to open the pull request
through a different GitHub integration. GitHub rejected the request with
`403 Resource not accessible by integration`.

**Expected behavior**
A short broker delay or a short transport failure must not remove the
managed GitHub identity from the command. The launcher must try the
broker again before it continues without credentials.

**Steps to reproduce**
1. Set `PAPERCLIP_GITHUB_BROKER_URL` to a closed port.
2. Start a broker on that port after about 300 ms.
3. Run `gh` through the launcher.
4. Before this change, the launcher prints
`broker_transport_unavailable` and runs `gh` without the managed token.

**Version or commit**
`4ac374103` on master. Commit `3166e93a7` has the same code.

**Deployment mode**
Local trusted instance that runs as a launchd service, with
`codex_local` agents.

## What Changed

- `packages/adapter-utils/src/github-launcher.ts`: the broker request
loop now catches transport errors and retries up to two more times,
after 0.5 s and then after 1 s. The loop reads the response body inside
the retry, so a failed or slow body read is also retried. Busy (409)
responses keep their own budget of 30 attempts, separate from transport
retries. After the third transport failure, the launcher prints
`broker_transport_unavailable` as before.
- `packages/adapter-utils/src/github-launcher.test.ts`: two new tests
make the broker fail the first request and answer the second. In one,
the connection drops before the response. In the other, the connection
drops in the middle of the body. Each test checks that `gh` gets the
managed token, that the broker receives exactly two requests, and that
no `broker_transport_unavailable` message appears.
- The existing `broker-offline` test now has a 15-second timeout,
because each command now retries twice before it falls back.

## Verification

- `npx vitest run packages/adapter-utils/src/github-launcher.test.ts`: 9
of 9 tests pass.
- The body-read test fails on the first commit of this pull request and
passes with the second commit.
- `pnpm --filter @paperclipai/adapter-utils typecheck`: passes.
- The existing `broker-offline` test confirms that the launcher still
falls back after the retries, and that local Git still works.

## Risks

- When the broker is unreachable, each `git` or `gh` command now waits
about 1.5 s more before it continues without credentials. When the
broker times out, the worst case is about 31.5 s instead of 10 s.
- The change only adds retries. It does not change which credentials the
launcher accepts or which environment variables it copies.
- #14175 changes the same loop. The pull request that merges second
needs a small rebase.

> For core feature work, check [`ROADMAP.md`](ROADMAP.md) first and
discuss it in `#dev` before opening the PR. Feature PRs that overlap
with planned core work may need to be redirected — check the roadmap
first. See `CONTRIBUTING.md`.

## Model Used

- Anthropic Claude Opus 5.5 (`claude-opus-5-5`), used through Claude
Code with tool use: shell commands, file edits and test runs. The model
wrote the change, the test and this description. The repository owner
approved the change before it was made.

## Checklist

- [x] I have included a thinking path that traces from project context
to this change
- [x] I have specified the model used (with version and capability
details)
- [x] I have checked ROADMAP.md and confirmed this PR does not duplicate
planned core work
- [x] I have searched GitHub for duplicate or related PRs and linked
them above
- [x] I have either (a) linked existing issues with `Fixes: #` / `Closes
#` / `Refs #` OR (b) described the issue in-PR following the relevant
issue template
- [x] I have not referenced internal/instance-local Paperclip issues or
links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip`
URLs)
- [x] My branch name describes the change (e.g. `docs/...`, `fix/...`)
and contains no internal Paperclip ticket id or instance-derived details
- [x] I have run tests locally and they pass — *targeted tests and the
package typecheck; see Verification*
- [x] I have added or updated tests where applicable
- [ ] I have updated relevant documentation to reflect my changes — *no
documentation describes the broker retry*
- [x] I have considered and documented any risks above
- [ ] All Paperclip CI gates are green — *CI has not run yet*
- [ ] Greptile is 5/5 with no open P2s, recommendations, or follow-ups —
*Greptile has not reviewed yet*
- [x] I will address all Greptile and reviewer comments before
requesting merge

🤖 Generated with [Claude Code](https://claude.com/claude-code)

---------

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
2026-10-01 12:57:41 -07:00
DottaandPaperclip 8ec4b84e1c fix(chat): resume messages after failed runs without duplicate delivery (#14857)
## Thinking Path

> - Paperclip is the open source app people use to manage AI agents for
work.
> - A user can send a new message after a native run fails.
> - The server checks that the old execution has stopped before it
starts a fresh turn.
> - A failed run can retain a result accepted before checkpoint or
cleanup failed.
> - The continuation gate treated that saved result as active recovery
and held the new message forever.
> - This pull request removes that false liveness signal while retaining
controller, process, environment, and authorization checks.
> - Live staging then exposed a second defect: chat admission created a
successor without consuming the original deferred receipt, so completion
delivered the message again.
> - Consume that exact receipt atomically with admission, while
preserving separate turns for later chat messages.

## Linked Issues or Issue Description

**What happened?**

A new user message stayed in the queue with `controller_settling` after
the previous run had reached `terminal_failure`. The old coordinator had
no lease owner but still had a `resultId`. Its remote environment had a
verified stop receipt.

**Expected behavior**

Start one fresh turn after execution has stopped and normal admission
checks pass. Preserve the failed run and its accepted result as history.

**Steps to reproduce**

1. Accept a native result, then fail checkpoint or cleanup and exhaust
recovery.
2. Retain the result ID on the terminal failure record and stop the
execution environment.
3. Send a new user message. Before this fix, it waits forever for the
finished controller.

**Paperclip version or commit**

Reproduced in a database-backed regression test on `26900655b`.

**Deployment mode**

Server with a native runner and remote sandbox. Local process stop
checks also apply.

Related: https://github.com/paperclipai/paperclip/pull/14775. Searched
existing PRs for retained-result continuation fixes; no duplicate found.

## What Changed

- Remove the retained-result veto for terminal failures.
- Keep controller ownership, successor, process, environment cleanup,
pending decision, and ordinary admission checks.
- Add regressions for retained results, active execution, missing stop
evidence, and delayed remote cleanup.
- Atomically consume the resumed receipt in agent chat, even though chat
does not coalesce other queued messages.
- Reproduce completion-time duplicate promotion, race cleanup against
periodic recovery, and prove a subsequent chat message keeps its own
turn.
- Document that a saved result does not make a terminal failure active.
- Keep exhausted workspace export on its separate repair path, tested
through the production finalizer.

## Verification

- Red: retained-result admission failed with `controller_settling`
before the original fix. The new chat-specific regression then
reproduced duplicate promotion when the first reply finished.
- Green: 406 tests across native continuation, workspace-export
recovery, and the wake-queue module passed on `cbc531cc0`.
- The chat regressions exercise real Postgres transactions, simultaneous
recovery callbacks, successful completion, the production queue-drain
use case, and repeated drain attempts. A distinct follow-up remains a
separate turn.
- `pnpm -r typecheck` and `pnpm build` passed on `cbc531cc0`.
- The earlier full local test run encountered a timeout and follow-on
failure in unchanged AI connection-adoption tests; all 50 tests passed
on isolated rerun. That local run was stopped after the full CI test
matrix passed on the earlier head.
- All 54 CI checks passed on `cbc531cc0` (2 skipped), including the full
test matrix and browser shards. One unchanged interaction-route test
returned HTTP 500 on its first CI attempt; its full 84-test file passed
locally, and the failed shard passed on one targeted rerun.
- Greptile reviewed `cbc531cc0`: 5/5, no unresolved findings.
- Live staging first verified that the original saved message resumes
and receives a successful response; that test exposed the duplicate now
covered above.
- Deployed exact commit `cbc531cc0410e1ef6e8811c6c5c014c3528351ed` to
the affected staging workspace; deployment verification, health,
authentication, and startup recovery passed.
- Submitted a fresh message through the browser. The agent replied in 39
seconds; server records show exactly one successful run, native phase
`committed`, no error, and an empty queue. A later check more than a
minute after completion found no duplicate run.

## Risks

The change affects admission after native execution failure and
consumption of a resumed deferred receipt. A fresh turn must never
overlap the prior execution, and consuming one chat receipt must not
absorb later messages. Tests retain the controller, process, and
remote-stop guards. This change does not migrate data, apply an old
result, or reset the old retry budget.

## Model Used

OpenAI Codex (GPT-6). The exact runtime model identifier and context
window are not exposed in this session. Used reasoning, repository
inspection, code execution, database-backed tests, and browser
inspection.

## Checklist

- [x] I have included a thinking path that traces from project context
to this change
- [x] I have specified the model used (with version and capability
details)
- [x] I have checked ROADMAP.md and confirmed this PR does not duplicate
planned core work
- [x] I have searched GitHub for duplicate or related PRs and linked
them above
- [x] I have either (a) linked existing issues with `Fixes: #` / `Closes
#` / `Refs #` OR (b) described the issue in-PR following the relevant
issue template
- [x] I have not referenced internal/instance-local Paperclip issues or
links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip`
URLs)
- [x] My branch name describes the change (e.g. `docs/...`, `fix/...`)
and contains no internal Paperclip ticket id or instance-derived details
- [x] I have run tests locally and they pass
- [x] I have added or updated tests where applicable
- [x] I have updated relevant documentation to reflect my changes
- [x] I have considered and documented any risks above
- [x] All Paperclip CI gates are green
- [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups
- [x] I will address all Greptile and reviewer comments before
requesting merge

---------

Co-authored-by: Paperclip <noreply@paperclip.ing>
canary/v2026.1001.0-canary.6
2026-10-01 14:43:02 -05:00
Devin FoleyandPaperclip dd9983b894 fix(adapter-utils): release restore locks when a process crashes (#14869)
## Thinking Path

> - Paperclip is the open source app people use to manage AI agents for
work.
> - Agent runs restore workspace files and collect instruction-file
changes.
> - Writers to the same target directory must wait for each other.
> - The current lock records a PID, which a new process can reuse after
a crash.
> - A reused PID can keep an orphaned lock alive and make each later run
fail.
> - This pull request makes a SQLite file lock decide ownership. The OS
releases it when the process exits.
> - Later runs can proceed after a crash, and concurrent live writers
remain protected.

## Linked Issues or Issue Description

Refs #10914. This addresses crash recovery. It does not cancel a stalled
operation in a process that is still alive.

Related work: #9667, #14787, and #12187. The earlier attempt in #9667
assumes one live server per lock root. This implementation uses an
OS-backed lock to support concurrent writers without treating a
different process token or an old timestamp as proof of a dead owner. It
retains the private lock root and bounded timeout diagnostics from the
merged changes.

After a process dies while holding a restore lock, a replacement process
can reuse its PID. The existing `process.kill(pid, 0)` check then
reports a live owner forever. Later runs can complete their model turn
but fail during file collection or restore.

## What Changed

- Hold a SQLite `BEGIN IMMEDIATE` transaction for each directory write.
Use the existing built-in `node:sqlite` dependency.
- Keep each lock database on a stable inode. Keep PID and time metadata
only for diagnostics.
- Retain the 30-second asynchronous wait and existing timeout error code
and diagnostic fields.
- Fail closed when an old directory lock exists. Document a
stopped-writer upgrade and rollback procedure.
- Add real child-process tests for crashes, PID reuse, live owners, and
connection cleanup. Cover callback failures, independent targets, stable
inodes, invalid lock files, and ambiguous legacy records.

## Verification

- Before the fix, the crash/PID-reuse test and the live-owner test both
failed. Both pass with this change.
- `pnpm exec vitest run
packages/adapter-utils/src/directory-merge-lock.test.ts
packages/adapter-utils/src/workspace-restore-merge.test.ts`: 56 tests
passed.
- Restore and agent-file working-copy integration tests: 118 tests
passed before the additional connection-cleanup test.
- `pnpm -r typecheck`: passed.
- `pnpm build`: passed.
- Full GitHub CI: all checks passed, including Linux workspace tests,
server test shards, build, typecheck, and browser tests.
- Greptile: 5/5, with no review threads or unresolved comments.
- `pnpm test:run`: started locally, then stopped with SIGINT (exit 130)
after full CI passed. The local serial run did not complete and is not
counted as a full local pass. The completed CI shards provide the
full-suite result.

## Risks

- **Upgrade and rollback require a drain.** Stop every old writer that
shares an instance root before switching protocols. Old and new versions
must not write concurrently.
- Existing legacy `.lock/` directories remain blocking. After all
writers stop, preserve run evidence and move those directories to an
operator scratch directory. The new code does not infer that they are
abandoned from PID or age.
- Never delete or replace a `.lock.sqlite` file while writers can run.
These small files remain after release.
- The shared filesystem must support reliable SQLite locking. Broken
network-filesystem locking is unsupported.
- This change prevents new orphaned ownership. It does not recover file
changes lost during earlier failed collections, or interrupt a live
operation that stalls.
- No application database migration or new native dependency is
required. See `doc/workspace-restore-locks.md` for the procedure.

## Model Used

OpenAI Codex based on GPT-6, with code execution and repository tools.
The exact model variant and context window are not exposed in this
session.

## Checklist

- [x] I have included a thinking path that traces from project context
to this change
- [x] I have specified the model used (with version and capability
details)
- [x] I have checked ROADMAP.md and confirmed this PR does not duplicate
planned core work
- [x] I have searched GitHub for duplicate or related PRs and linked
them above
- [x] I have either (a) linked existing issues with `Fixes: #` / `Closes
#` / `Refs #` OR (b) described the issue in-PR following the relevant
issue template
- [x] I have not referenced internal/instance-local Paperclip issues or
links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip`
URLs)
- [x] My branch name describes the change (e.g. `docs/...`, `fix/...`)
and contains no internal Paperclip ticket id or instance-derived details
- [x] I have run tests locally and they pass (focused regression and
integration suites; see the full-suite note above)
- [x] I have added or updated tests where applicable
- [x] I have updated relevant documentation to reflect my changes
- [x] I have considered and documented any risks above
- [x] All Paperclip CI gates are green
- [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups
- [x] I will address all Greptile and reviewer comments before
requesting merge

Co-authored-by: Paperclip <noreply@paperclip.ing>
canary/v2026.1001.0-canary.5
2026-10-01 12:14:48 -07:00
dependabot[bot] 8f7baf2f72 chore(deps): bump @aws-sdk/client-s3 from 3.1122.0 to 3.1141.0 (#13475)
Bumps
[@aws-sdk/client-s3](https://github.com/aws/aws-sdk-js-v3/tree/HEAD/clients/client-s3)
from 3.1122.0 to 3.1141.0.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/aws/aws-sdk-js-v3/releases">@​aws-sdk/client-s3's
releases</a>.</em></p>
<blockquote>
<h2>v3.1141.0</h2>
<h4>3.1141.0(2026-09-25)</h4>
<h5>Chores</h5>
<ul>
<li><strong>codegen:</strong> smithy-aws-typescript-codegen 0.54.0 (<a
href="https://redirect.github.com/aws/aws-sdk-js-v3/pull/8314">#8314</a>)
(<a
href="https://github.com/aws/aws-sdk-js-v3/commit/ad80ce3ebaf394679aabc6e26b2dcd023ce8e010">ad80ce3e</a>)</li>
</ul>
<h5>New Features</h5>
<ul>
<li><strong>client-connect:</strong> Agent Privacy During Hold is a new
privacy capability for Amazon Connect Voice that prevents agent audio
from being captured in call recordings or Contact Lens conversational
analytics during hold. When enabled, agents are automatically muted on
entering hold and unmuted on resuming the contact (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/03527f9ea153365c1e3654ac6d3f3e064d06b5d0">03527f9e</a>)</li>
<li><strong>client-qconnect:</strong> Release shapes for the proactive
agentic recommendations and the multi-knowledge base search features.
Increases the maximum length of QuickResponseContent. (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/e008332b0b70c55d22dfca8a9c2317b67d06a5f3">e008332b</a>)</li>
<li><strong>client-bedrock-agent:</strong> Adds support for calling VPC
configuration API's in Bedrock. These configurations allow the use of On
Prem connectors in Bedrock Managed Knowledge bases (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/18524dc69cf36ebbb8bc7bc33e0bce6311dcdb23">18524dc6</a>)</li>
<li><strong>client-mediaconnect:</strong> This release adds support for
RTMP push router outputs in AWS Elemental MediaConnect. (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/5bd8d80bbca2c1c2545521b03d741b46fccd09b4">5bd8d80b</a>)</li>
<li><strong>client-securityagent:</strong> This release adds the
ListActorMessages operation, which returns the multi-factor
authentication messages received at an actor's server-generated email
address (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/10e53d506db74c48b09b94d9b9387b84dd40ed58">10e53d50</a>)</li>
<li><strong>client-arc-region-switch:</strong> Adds a service quota
checker to Region switch to verify quota parity between your primary and
standby Region, and automatically submit quota limit increases. Adds an
optional EC2 Auto Scaling and ECS setting that waits for instances or
tasks in the scaled-up Region to be healthy in target groups. (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/cca33e380a8985e23a0e3fbb420577aab4b60ac7">cca33e38</a>)</li>
<li><strong>client-bedrock-agentcore-control:</strong> Amazon Bedrock
AgentCore Payments now supports credential rotation for payment
connectors, letting you rotate API and wallet secrets for Quick Create
payment auths from the console. This release also adds Type and Creation
type columns to the payment managers views. (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/adca591f07c448603de2876faaf7914cad441436">adca591f</a>)</li>
<li><strong>client-neptune-graph:</strong> Add GraphIdentifier filter
for ListImportTasks (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/9b9aea9b553ba84f006f95da5d8ffd5381cc8a17">9b9aea9b</a>)</li>
<li><strong>client-rekognition:</strong> This release adds support for
Feedback and Metadata in the GetFaceLivenessSessionResults response.
Feedback returns codes explaining why a Face Liveness check produced its
result. Metadata includes the client SDK type. (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/0831c361bb69d44357ff57360db39afdbb149337">0831c361</a>)</li>
<li><strong>client-glue:</strong> add support for table level federation
(<a
href="https://github.com/aws/aws-sdk-js-v3/commit/a44458b77853cbb25a9fcb362b0a275d7dc1c69b">a44458b7</a>)</li>
<li><strong>client-wellarchitected:</strong> This change releases the
Well-Architected Agent, a generative AI service that analyzes a
customer's AWS environment and delivers personalized, prioritized
recommendations across cost, security, performance, and resilience. (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/d0656586067f70b8d50000300f04512dd089df96">d0656586</a>)</li>
</ul>
<hr />
<p>For list of updated packages, view
<strong>updated-packages.md</strong> in
<strong>assets-3.1141.0.zip</strong></p>
<h2>v3.1140.0</h2>
<h4>3.1140.0(2026-09-24)</h4>
<h5>Documentation Changes</h5>
<ul>
<li><strong>client-route53resolver:</strong> Documentation updates for
Route 53 Resolver. Clarifies which Outpost Resolver operations apply to
first-generation AWS Outposts and that Resolver is managed automatically
on second-generation Outposts. Adds Local Network Interface subnet
compatibility notes for Resolver endpoints. (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/b4432abaaaf19bf4ac5d4d2b09bcc83e4d5440a0">b4432aba</a>)</li>
<li><strong>client-iot:</strong> Fixed ListV2LoggingLevels and
DeleteV2LoggingLevel documentation to include all supported target-types
(<a
href="https://github.com/aws/aws-sdk-js-v3/commit/4dcf76d527e0c1fe76d64cb8ea444ce62d64135b">4dcf76d5</a>)</li>
</ul>
<h5>New Features</h5>
<ul>
<li><strong>clients:</strong> update client endpoints as of 2026-09-24
(<a
href="https://github.com/aws/aws-sdk-js-v3/commit/29a8566cb4c6eeb0cc554f4ae9bf985160556523">29a8566c</a>)</li>
<li><strong>client-eventbridgev2:</strong> Introducing Amazon
EventBridge enhanced Custom event bus, a new shareable event bus for
organizational-scale event-driven applications feature ordered delivery,
deduplication, open event formats, and cross-account bus sharing. (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/69fbe6a22fd7810332b0b0356803a0eee3f563cf">69fbe6a2</a>)</li>
<li><strong>client-datazone:</strong> Amazon DataZone now supports the
TOOLING blueprint category on CreateEnvironmentBlueprint,
UpdateEnvironmentBlueprint, GetEnvironmentBlueprint, and
ListEnvironmentBlueprints, for custom tooling blueprints.
CreateConnection now accepts roleArn in iamProperties. (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/591cd6f5a7b714427cbe87b36b13357d560d48ea">591cd6f5</a>)</li>
<li><strong>client-elasticache:</strong> Added tagging support for
ElastiCache Global DataStore. (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/0fa9da5946312f09942dad6f711885855f0d0b8e">0fa9da59</a>)</li>
<li><strong>client-marketplace-discovery:</strong> AWS Marketplace
Discovery API now supports localized responses and SigV4a request
signing. It returns new fulfillment details, including AMI architecture,
EBS volume and security group information, SaaS quick-launch status, and
SageMaker input and output MIME types. (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/510673e376bbc578d318308136ecb5a841416bc3">510673e3</a>)</li>
<li><strong>client-redshift-data:</strong> Updates to the ListDatabases
and WorkgroupName validation (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/218c24e106efe1ad64658984123af6634fc7278d">218c24e1</a>)</li>
<li><strong>client-securityagent:</strong> Added support for Confluence
export, enabling customers to publish security findings to Confluence
pages. (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/81408527778af52f0c604a4eaca440f445082f78">81408527</a>)</li>
<li><strong>client-cloudwatch:</strong> This release adds Create, Get,
Update, and DeleteResourceMetricsConfiguration to enable detailed metric
collection for an AWS resource, and adds UpdateOTelEnrichment plus
include and exclude filters on StartOTelEnrichment so you can choose
which metric namespaces CloudWatch enriches. (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/765cc1ce8f95a4f62d83dc07b81a927d74e09b52">765cc1ce</a>)</li>
<li><strong>client-eventbridge:</strong> Adds a ManagedBy field to the
DescribeEventBus and ListEventBuses responses, identifying the AWS
service that created an event bus on your behalf. (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/28a639b27585c85376a4b5db528c31efb80e874d">28a639b2</a>)</li>
</ul>
<h5>Tests</h5>
<ul>
<li><strong>undici-http-handler:</strong> update bidi stream e2e test to
nova-2-sonic model (<a
href="https://redirect.github.com/aws/aws-sdk-js-v3/pull/8313">#8313</a>)
(<a
href="https://github.com/aws/aws-sdk-js-v3/commit/d9a37d9d318f2ef7f5bcf6286bf3c7b475e4175b">d9a37d9d</a>)</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/aws/aws-sdk-js-v3/blob/main/clients/client-s3/CHANGELOG.md">@​aws-sdk/client-s3's
changelog</a>.</em></p>
<blockquote>
<h1><a
href="https://github.com/aws/aws-sdk-js-v3/compare/v3.1140.0...v3.1141.0">3.1141.0</a>
(2026-09-25)</h1>
<p><strong>Note:</strong> Version bump only for package
<code>@​aws-sdk/client-s3</code></p>
<h1><a
href="https://github.com/aws/aws-sdk-js-v3/compare/v3.1139.0...v3.1140.0">3.1140.0</a>
(2026-09-24)</h1>
<p><strong>Note:</strong> Version bump only for package
<code>@​aws-sdk/client-s3</code></p>
<h1><a
href="https://github.com/aws/aws-sdk-js-v3/compare/v3.1138.0...v3.1139.0">3.1139.0</a>
(2026-09-23)</h1>
<p><strong>Note:</strong> Version bump only for package
<code>@​aws-sdk/client-s3</code></p>
<h1><a
href="https://github.com/aws/aws-sdk-js-v3/compare/v3.1137.0...v3.1138.0">3.1138.0</a>
(2026-09-22)</h1>
<p><strong>Note:</strong> Version bump only for package
<code>@​aws-sdk/client-s3</code></p>
<h1><a
href="https://github.com/aws/aws-sdk-js-v3/compare/v3.1136.0...v3.1137.0">3.1137.0</a>
(2026-09-21)</h1>
<p><strong>Note:</strong> Version bump only for package
<code>@​aws-sdk/client-s3</code></p>
<h1><a
href="https://github.com/aws/aws-sdk-js-v3/compare/v3.1135.0...v3.1136.0">3.1136.0</a>
(2026-09-18)</h1>
<p><strong>Note:</strong> Version bump only for package
<code>@​aws-sdk/client-s3</code></p>
<h1><a
href="https://github.com/aws/aws-sdk-js-v3/compare/v3.1134.0...v3.1135.0">3.1135.0</a>
(2026-09-17)</h1>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/aws/aws-sdk-js-v3/commit/5bc8d9a96936723ac90d721e0c5a2bff7ee8520d"><code>5bc8d9a</code></a>
Publish v3.1141.0</li>
<li><a
href="https://github.com/aws/aws-sdk-js-v3/commit/6050a3813c26795562b5ada8b0d9ea498eb9f8a1"><code>6050a38</code></a>
Publish v3.1140.0</li>
<li><a
href="https://github.com/aws/aws-sdk-js-v3/commit/03d54a858f80012bbc60046a77242223e8dfd9d9"><code>03d54a8</code></a>
Publish v3.1139.0</li>
<li><a
href="https://github.com/aws/aws-sdk-js-v3/commit/c68e50e4a6e0469a20c2894fe8a29c140553ebb8"><code>c68e50e</code></a>
Publish v3.1138.0</li>
<li><a
href="https://github.com/aws/aws-sdk-js-v3/commit/9a104768684e8f22d4373fcc5d910711e62676d6"><code>9a10476</code></a>
chore(codegen): sync for MetricsRecorder support and core error/retry
fixes (...</li>
<li><a
href="https://github.com/aws/aws-sdk-js-v3/commit/6b432472f9bdf5437319b9186f706e3af5c9a748"><code>6b43247</code></a>
Publish v3.1137.0</li>
<li><a
href="https://github.com/aws/aws-sdk-js-v3/commit/d6b94db8f4a00cc452dbe0aacb247e8ece3897ea"><code>d6b94db</code></a>
Publish v3.1136.0</li>
<li><a
href="https://github.com/aws/aws-sdk-js-v3/commit/2d5f18d08aa373d95692d83cb3d60a6a79248fae"><code>2d5f18d</code></a>
Publish v3.1135.0</li>
<li><a
href="https://github.com/aws/aws-sdk-js-v3/commit/0d6310bf6979ddbf737a7e15cfd8d0e7cec07063"><code>0d6310b</code></a>
Publish v3.1134.0</li>
<li><a
href="https://github.com/aws/aws-sdk-js-v3/commit/615a1ca4661ec0e4cb34b8da89fe60c2419b94d0"><code>615a1ca</code></a>
Publish v3.1133.0</li>
<li>Additional commits viewable in <a
href="https://github.com/aws/aws-sdk-js-v3/commits/v3.1141.0/clients/client-s3">compare
view</a></li>
</ul>
</details>
<br />

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
canary/v2026.1001.0-canary.4
2026-10-01 11:13:22 -07:00