Commit Graph
4731 Commits
Author SHA1 Message Date
DottaandPaperclip 408f70e69f fix(runner): preserve stock Codex base instructions (#14920)
## Thinking Path

> - Paperclip is the open source app people use to manage AI agents for
work.
> - The native Runner connects Paperclip tasks to Codex app-server.
> - Paperclip passed its runtime context as `baseInstructions`.
> - That field replaces the stock Codex base prompt.
> - This pull request sends the same Paperclip context as additive
developer instructions.
> - Codex keeps its stock prompt and still receives Paperclip task
instructions and tools.

## Linked Issues or Issue Description

**What happened?**

The native Codex driver and Rust provider sent Paperclip context through
`baseInstructions` on thread start and resume. Codex used this text in
place of its stock base instructions. Direct-chat resume also sent an
empty replacement base. The Runner Lab session path used the same
replacement field.

**Expected behavior**

Codex should retain its stock base prompt. Paperclip should add its
runtime context through `developerInstructions`. Other provider facades
should retain their current instruction handling.

**Steps to reproduce**

1. Create a native Codex session through Paperclip Runner.
2. Inspect the `thread/start` request in the native provider trace.
3. Resume the session and inspect `thread/resume`.
4. Before this fix, these paths set `baseInstructions`. After this fix,
the Codex paths set `developerInstructions` and omit `baseInstructions`.

**Paperclip version or commit**

Reproduced against master at `cad26c6bfb736039c8ed5743da650a44792a083c`.

**Deployment mode**

Built from source. Native Codex app-server and runnerd paths. A local
protocol probe used codex-cli 0.153.4 and a localhost Responses stub.

No duplicate fix or matching public issue was found in the GitHub
search.

## What Changed

- Send additive developer instructions on Codex start and resume in the
TypeScript driver, Rust provider, and Runner Lab session path.
- Carry the additive fragment through runnerd, including runtime asset
path mapping.
- Preserve existing instruction fields for other provider facades,
including OpenCode.
- Add start/resume/direct-chat regression coverage and check the actual
Rust provider request.
- Document the historical option and trace field names. Record progress
and follow-ups in the working checklist.

## Verification

- `pnpm -r typecheck` — passed.
- `pnpm build` — passed.
- Targeted Codex driver lifecycle, driver, and live-session Vitest
suites — 139 tests passed.
- `cargo test --manifest-path
packages/paperclip-runner/runner/Cargo.toml --locked -p
paperclip-runner-core --test codex_provider` — 91 passed, 2 ignored
subprocess helpers.
- Real app-server probe: a localhost Responses stub captured identical
14,732-character stock base instructions on fresh start and cold resume.
Both requests retained the Paperclip marker in developer input. Both
stub turns completed. No paid inference was used.
- Runnerd transport Vitest suite — 182 tests passed.
- The initial `pnpm test:run` attempt reported local dependency-loading,
embedded PostgreSQL startup, and macOS `/var` versus `/private/var` path
failures. It was stopped after those failures. Loading-suite reruns
passed 1,428 tests after the build; native interaction/finalization
reruns passed 38 tests. A seven-suite diagnostic rerun passed 463 tests
and isolated the remaining path and PostgreSQL setup failures.
- With `TMPDIR=/private/tmp`, workspace, gateway, interaction, and
attachment suites passed all 356 tests. The remaining environment-image
and native-session-resumption suites passed all 44 tests with the same
canonical temp path. All affected suites passed on rerun. The original
full local command was stopped after failures and is not claimed as
passing.
- All 55 PR checks passed at `83281439456181396f3707eecda5d2ebc90bd14d`.
Greptile scored 5/5 with no open review threads.
- No paid live campaign or Product E2E browser suite was run. This
change has protocol and regression coverage; it does not claim improved
task quality.

## Risks

- Stock Codex behavior may differ from behavior under the previous
Paperclip replacement prompt. Restoring that behavior is the intended
change.
- Existing Codex threads retain their saved replacement base prompt.
They need a provider session reset to receive the stock base. This PR
does not reset active sessions or alter recovery rules.
- The legacy `baseInstructions` option and trace field names remain for
compatibility. They now describe the additive Paperclip fragment for
Codex.
- The separate Codex-through-ACP dependency patch remains a follow-up in
the harness coverage checklist. This PR covers native app-server
execution.

## Model Used

OpenAI Codex, GPT-6. The exact runtime model variant and context window
are not exposed in this session. Used reasoning, repository inspection,
code editing, shell execution, and test tools.

## Checklist

- [x] I have included a thinking path that traces from project context
to this change
- [x] I have specified the model used (with version and capability
details)
- [x] I have checked ROADMAP.md and confirmed this PR does not duplicate
planned core work
- [x] I have searched GitHub for duplicate or related PRs and linked
them above
- [x] I have either (a) linked existing issues with `Fixes: #` / `Closes
#` / `Refs #` OR (b) described the issue in-PR following the relevant
issue template
- [x] I have not referenced internal/instance-local Paperclip issues or
links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip`
URLs)
- [x] My branch name describes the change (e.g. `docs/...`, `fix/...`)
and contains no internal Paperclip ticket id or instance-derived details
- [x] I have run tests locally and they pass
- [x] I have added or updated tests where applicable
- [x] I have updated relevant documentation to reflect my changes
- [x] I have considered and documented any risks above
- [x] All Paperclip CI gates are green
- [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups
- [x] I will address all Greptile and reviewer comments before
requesting merge

---------

Co-authored-by: Paperclip <noreply@paperclip.ing>
2026-10-02 08:53:47 -05:00
DottaandPaperclip c46e41e81c fix(heartbeat): validate native MCP gateway ownership (#14914)
## Thinking Path

> - Paperclip lets people manage agents and govern their tool access.
> - Native runs receive an immutable MCP tool assignment for one agent.
> - The gateway must enforce that owner when it authenticates a run
token.
> - Older gateway rows stored the owner only in metadata.
> - This change validates the gateway and profile, binds new rows, and
repairs valid older rows on reuse.
> - It also delivers each native assignment once.
> - Other agents cannot use the assignment, and explicit shared gateways
keep their configured scope.

## Linked Issues or Issue Description

Builds on #14012 by @busla (Jón Levy). That PR adds agent binding and
seven regressions. This PR carries that fix onto current master and adds
legacy authentication, profile validation, and duplicate-delivery
coverage. Related: #14864 improves discovery memory use.

**What happened?**
Native gateway creation stored an owner in metadata but left `agentId`
null. Authentication could therefore accept another agent's run token.
Managed discovery could also deliver historical native assignments
again.

**Expected behavior**
A native assignment accepts only its owner's run token. The gateway and
profile must refer to the same immutable assignment. The current
assignment enters the run configuration once.

**Steps to reproduce**
1. Run the database fixtures in `heartbeat-runtime-mcp-servers.test.ts`
on the baseline.
2. Create a native assignment and inspect its stored gateway owner.
3. Authenticate with another agent's run token, then inspect legacy
reuse and managed delivery.
4. The baseline fails six ownership and delivery cases. The fix passes
all twelve cases.

**Paperclip version or commit**
The red baseline is `f2e0f1963`. This PR is based on `cad26c6bf`, which
includes the merged discovery fix.

**Deployment mode**
Native Paperclip Runner execution and managed Codex MCP delivery.
Reproduction uses isolated database and HTTP fixtures.

## What Changed

- Store the agent owner and agent context on new native gateways.
- Validate profile and gateway assignment metadata before reuse or token
creation.
- Bind valid legacy rows with a company-scoped, null-owner update and
validate the result.
- Reject mismatched run tokens before legacy repair.
- Identify native assignments by gateway metadata, the reserved profile
key, or profile source. Reject missing or malformed provenance,
including JSON null.
- Exclude historical native assignments from managed gateway delivery.
Keep their rows for existing runs.
- Add twelve database and HTTP regressions and document the runtime
contract.

## Verification

- Red baseline: six regressions fail and four controls pass before the
initial fix. Two additional regressions reproduce metadata-loss
admission and a JSON-null TypeError before the review fix.
- All twelve ownership regressions pass on the final code, including
owner admission, cross-agent rejection, metadata loss, JSON-null HTTP
401, and explicit shared-gateway admission. Policy, listing-memory, and
discovery HTTP coverage also passes.
- Full workspace typecheck and build pass locally. Server typecheck and
compilation pass again after the review fix. The final ownership and
grant patches pass 42 combined database and HTTP regressions.
- [Full
CI](https://github.com/paperclipai/paperclip/actions/runs/37011383657)
passes for `626a08ae66361cf586105877e24d806b1a7a9c20`: all 54 checks
succeed; two optional Storybook checks skip. This includes full
typecheck, build, all test shards, all eight E2E shards, runner
verification, and the canary dry run.
- Greptile scores that exact head 5/5. No review threads remain
unresolved.

## Risks

Invalid historical native gateway or profile metadata now rejects
authentication. Valid unbound rows are repaired only when their owner
reuses the assignment. Conflicting owners are never overwritten.
Historical rows are retained for existing runs. Explicit shared gateways
use ordinary profiles and keep their configured scopes. The reserved
native profile namespace remains agent-owned even when gateway metadata
is cleared. No schema or dependency changes are included.

## Model Used

Original fix and seven regressions in #14012: Anthropic Claude Opus 5.5,
`claude-opus-5-5`, 1M context, as reported by @busla. Extensions and
verification: OpenAI Codex (GPT-6), with reasoning, repository
inspection, code execution, and tests. This session does not expose the
exact serving model identifier or context window.

## Checklist

- [x] I have included a thinking path that traces from project context
to this change
- [x] I have specified the model used (with version and capability
details)
- [x] I have checked ROADMAP.md and confirmed this PR does not duplicate
planned core work
- [x] I have searched GitHub for duplicate or related PRs and linked
them above
- [x] I have either (a) linked existing issues with `Fixes: #` / `Closes
#` / `Refs #` OR (b) described the issue in-PR following the relevant
issue template
- [x] I have not referenced internal/instance-local Paperclip issues or
links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip`
URLs)
- [x] My branch name describes the change (e.g. `docs/...`, `fix/...`)
and contains no internal Paperclip ticket id or instance-derived details
- [x] I have run tests locally and they pass
- [x] I have added or updated tests where applicable
- [x] I have updated relevant documentation to reflect my changes
- [x] I have considered and documented any risks above
- [x] All Paperclip CI gates are green
- [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups
- [x] I will address all Greptile and reviewer comments before
requesting merge

---------

Co-authored-by: Paperclip <noreply@paperclip.ing>
canary/v2026.1002.0-canary.9
2026-10-02 08:22:33 -05:00
DottaandPaperclip 483dbc8890 fix(tool-access): enforce stored grant restrictions (#14915)
## Thinking Path

> - Paperclip governs the tools that agents can discover and call.
> - Stored grants can limit access to a tool, connection, or
application.
> - The grant matcher must enforce every restriction in that scope.
> - A nonmatching allow list fell through to a policy selector matcher
that ignores allow.
> - This change requires an explicit allow match and validates
additional selectors.
> - Malformed and unknown restrictions deny access.
> - Discovery and execution now enforce the same stored grant limits.

## Linked Issues or Issue Description

Related: #14864 adds the shared database and HTTP discovery fixture used
here. Searched existing public PRs for tool grant scope fixes. No
duplicate scope-validation fix was found.

**What happened?**
A stored grant with a nonmatching `scope.allow` could authorize a tool.
Empty or malformed allow lists, unknown selectors, and combined
mismatching selectors could also authorize access. The fallback policy
matcher does not validate stored grant JSON.

**Expected behavior**
An explicit allow list must match the requested tool, connection, or
application. Every additional selector must also match. Unknown or
malformed restrictions must deny access. Existing null and empty-object
scopes keep their broad grant behavior.

**Steps to reproduce**
1. Run `tool-grant-scope.test.ts` on the baseline.
2. Create a deny profile and a grant that names another tool.
3. Attempt discovery or a call for the tool outside the grant.
4. The baseline authorizes access. The fix denies it.

**Paperclip version or commit**
The red baseline is `f2e0f1963`. This PR is based on `cad26c6bf`, which
includes the merged discovery fix.

**Deployment mode**
The company-scoped MCP gateway. Reproduction uses isolated database
fixtures and a deterministic HTTP provider.

## What Changed

- Require an explicit allow entry to match the gateway or upstream tool
name, connection, or application.
- Apply all additional selectors after the allow match.
- Reject unknown selectors, invalid value types, empty restrictions, and
non-object scopes.
- Preserve null and empty-object scope compatibility.
- Add sixteen regressions, including discovery, successful execution,
and revocation through the HTTP gateway.
- Document stored grant scope behavior.

## Verification

- Red baseline: seven restricted-scope cases and three malformed-root
cases fail. HTTP discovery also exposes tools outside the grant.
- All 16 grant regressions and 35 adjacent policy tests pass locally.
The HTTP test excludes an ungranted tool from discovery, returns 403 for
its call, and verifies that no provider call occurs. It also checks
successful execution and later revocation.
- Server typecheck passes. The final ownership and grant patches also
pass 42 combined database and HTTP regressions.
- [Full
CI](https://github.com/paperclipai/paperclip/actions/runs/37011177989)
passes for `803fa9440111742672c94c4471e5b98f15dd3b97`: all 54 checks
succeed; two optional Storybook checks skip. This includes full
typecheck, build, all test shards, all eight E2E shards, runner
verification, and the canary dry run.
- Greptile scores that exact head 5/5. No review threads remain
unresolved.

## Risks

Stored scopes with unknown keys or malformed restrictions now deny
access. Operators must correct those grants before they can authorize
tools. Null and empty-object scopes keep their previous broad behavior.
There are no schema, dependency, or API changes.

## Model Used

OpenAI Codex (GPT-6), with reasoning, repository inspection, code
execution, database regressions, and HTTP tests. This session does not
expose the exact serving model identifier or context window.

## Checklist

- [x] I have included a thinking path that traces from project context
to this change
- [x] I have specified the model used (with version and capability
details)
- [x] I have checked ROADMAP.md and confirmed this PR does not duplicate
planned core work
- [x] I have searched GitHub for duplicate or related PRs and linked
them above
- [x] I have either (a) linked existing issues with `Fixes: #` / `Closes
#` / `Refs #` OR (b) described the issue in-PR following the relevant
issue template
- [x] I have not referenced internal/instance-local Paperclip issues or
links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip`
URLs)
- [x] My branch name describes the change (e.g. `docs/...`, `fix/...`)
and contains no internal Paperclip ticket id or instance-derived details
- [x] I have run tests locally and they pass
- [x] I have added or updated tests where applicable
- [x] I have updated relevant documentation to reflect my changes
- [x] I have considered and documented any risks above
- [x] All Paperclip CI gates are green
- [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups
- [x] I will address all Greptile and reviewer comments before
requesting merge

---------

Co-authored-by: Paperclip <noreply@paperclip.ing>
2026-10-02 08:21:40 -05:00
cad26c6bfb fix(tool-gateway): bound MCP discovery memory and concurrency (#14864)
## Thinking Path

> - Paperclip is the open source app people use to manage AI agents for
work.
> - Agents discover governed tools through the MCP gateway.
> - A listing repeated policy and full run-row reads for each catalog
tool.
> - Parallel listings multiplied those allocations during run startup.
> - One 900-tool baseline listing used 11,489 queries and about 1.7 GiB
of extra heap in a fixture.
> - This pull request shares reads within a listing and bounds whole
listings across the process.
> - The benefit is lower discovery memory use while execution still
checks current policy.

## Linked Issues or Issue Description

Refs #13115. Its on-demand target change affects the same listing loop.

**What happened?**

MCP discovery repeated roughly 13 reads per tool. Full run snapshots and
repeated connection configurations caused large allocations. Per-listing
bounds alone did not limit concurrent listings across gateways.

**Expected behavior**

Discovery reads shared inputs once per listing. The process bounds
active and queued listings. Catalog payload size and policy evaluation
still grow with the catalog. Tool execution checks current access rules.

**Steps to reproduce**

Create a company with a remote MCP connection, 900 catalog tools, large
schemas, and a large run snapshot. Send concurrent tools/list requests
using a run-bound gateway token. Run the committed benchmark for a
deterministic reproduction.

**Paperclip version or commit**

Baseline: f2e0f19630. Measured on Node
26.4.0 on macOS.

## What Changed

- Keep Michael Nguyen's per-listing policy cache, scalar policy reads,
16-decision bound, and catalog/connection split under repeatable read.
- Admit two whole listings per process and queue at most 32. Return 503
with tool_discovery_busy when full.
- Propagate disconnects to discovery. Stop scheduling new reads and
drain started reads before freeing the slot.
- Project context IDs in gateway authentication and GitHub runtime
discovery. Avoid loading task descriptions and results.
- Keep discovery audit counts and a SHA-256 digest instead of the full
name list. Retain access and activity audit records.
- Sweep expired named gateway tokens at startup and on the existing
scheduler. Delete at most 500 per pass. Add an idempotent expiry-index
migration. Resolve audit token references atomically so cleanup cannot
break admitted requests.
- Return GET 405 with Allow: POST on stateless MCP gateway and
runtime-tools endpoints. Keep runtime-tools authentication.
- Add red-green regressions, HTTP concurrency and policy-revocation
coverage, and browser approval assertions.
- Commit the benchmark harness, raw results, and resource-bound
documentation.

## Verification

- Baseline listing regressions failed with 722 queries for 50 tools and
6,422 for 500. The connection-row duplication regression also failed.
- Follow-up regressions failed before the fixes for full snapshot reads,
abandoned listings, full name-list audits, and expired tokens.
- Listing and scheduler tests: 14 pass. Existing gateway/policy suites
passed after preserving the cleanup return contract.
- Two HTTP journeys pass: initialize, GET/SSE rejection, 16 concurrent
500-tool listings, provider call, policy revocation, and denied retry.
Token cleanup during provider dispatch also completes successfully and
blocks subsequent requests.
- pnpm test:e2e tests/e2e/mcp-user-stories.spec.ts --grep
'@mcp-runnable': 8 pass. The approval journey clicks Allow once in the
browser. Review screenshots wait for loaded content.
- pnpm -r typecheck: passes. pnpm build: passes.
- The general server group completed with 14,755 passes and 18 failures.
The 17 startup mock failures were fixed; all 21 startup tests pass on
rerun. The one Discord timing failure passed on the unchanged baseline
and on rerun (74 tests). UI and CLI groups pass 7,632 tests. Shared and
skill groups pass 853 tests. The remaining database and adapter groups
pass 3,010 tests with one worker after a macOS shared-memory limit
interrupted a parallel run. All 149 serialized route files pass (2,762
tests).
- At 900 tools, one listing falls from 11,489 to 36 queries and from
about 1.7 GiB to 37 MiB of extra heap. Sixteen concurrent listings used
169–187 MiB of extra heap. Four connections used 39 queries per listing.
- Latest-head verification: 54 successful checks and two expected skips
on 5c0793090c. Fresh Greptile review: 5/5
with no unresolved threads.
- Reproduce with server/scripts/benchmark-tool-gateway-listing.ts. See
doc/mcp-discovery-performance.md and
doc/benchmarks/2026-10-01-mcp-discovery.json.

## Risks

- The process-wide FIFO queue can increase discovery latency. Excess
callers must retry 503 responses.
- Cancellation applies to discovery. Started database reads finish
before their slot is released.
- Audit consumers must use visibleToolCount and visibleToolsHash instead
of visibleTools.
- The expiry index can briefly lock the token table during migration.
Sweeps preserve unexpired and non-expiring tokens.
- Measurements use isolated fixtures and deterministic providers. They
do not establish a production heap limit or affected installation count.
Rate-limit reads remain uncached.

## Model Used

- Original listing optimization: Anthropic Claude Opus 5.5
(claude-opus-5-5), Claude Code, extended thinking and tool use, as
recorded by the original author.
- Follow-up fixes and verification: OpenAI Codex, GPT-6, with shell
execution, file edits, database fixtures, and browser tests. The exact
serving model ID and context window are not exposed in this session.

## Checklist

- [x] I have included a thinking path that traces from project context
to this change
- [x] I have specified the model used (with version and capability
details)
- [x] I have checked ROADMAP.md and confirmed this PR does not duplicate
planned core work
- [x] I have searched GitHub for duplicate or related PRs and linked
them above
- [x] I have either (a) linked existing issues with Fixes / Closes /
Refs OR (b) described the issue in-PR following the relevant issue
template
- [x] I have not referenced internal/instance-local Paperclip issues or
links
- [x] My branch name describes the change and contains no internal
Paperclip ticket id or instance-derived details
- [x] I have run tests locally and they pass
- [x] I have added or updated tests where applicable
- [x] I have updated relevant documentation to reflect my changes
- [x] I have considered and documented any risks above
- [x] All Paperclip CI gates are green
- [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups
- [x] I will address all Greptile and reviewer comments before
requesting merge

---------

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
Co-authored-by: Dotta <bippadotta@protonmail.com>
Co-authored-by: Paperclip <noreply@paperclip.ing>
canary/v2026.1002.0-canary.8
2026-10-02 07:45:27 -05:00
dependabot[bot] c83df091b1 build(deps): bump react-i18next from 17.0.12 to 17.0.15 (#12970)
Bumps [react-i18next](https://github.com/i18next/react-i18next) from
17.0.12 to 17.0.15.
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/i18next/react-i18next/blob/master/CHANGELOG.md">react-i18next's
changelog</a>.</em></p>
<blockquote>
<h2>17.0.15</h2>
<ul>
<li>fix(Trans): empty paired component tags now preserve a component's
single valid React-element child, whether supplied through a named
component map (<code>&lt;wrap&gt;&lt;/wrap&gt;</code>), a component
array (<code>&lt;0&gt;&lt;/0&gt;</code>), or indexed JSX children
(<code>&lt;1&gt;&lt;/1&gt;</code>). This matches the existing behavior
for two or more children and self-closing tags. React represents one JSX
child as an element and multiple children as an array; the previous
array-only check silently rendered the one-child case empty.
Compatibility note: when that sole element contains an interpolation
object, the restored raw children can expose an existing React rendering
limitation as an error instead of silently rendering empty; the same
shape already errors with two children. Fixes <a
href="https://redirect.github.com/i18next/react-i18next/issues/1932">#1932</a>.</li>
</ul>
<h2>17.0.14</h2>
<ul>
<li>fix: the <code>i18n</code> object returned by
<code>useTranslation</code> was only refreshed when
<code>i18n.language</code> changed, so a <code>resolvedLanguage</code>
(or <code>languages</code>) change of its own kept handing components
the previous snapshot. That happens whenever the translations for the
current language arrive after the switch — i18next resolves to the
fallback until its store has them — and components reading
<code>i18n.resolvedLanguage</code> (language switchers, for example)
then stayed one switch behind. The cached wrapper is now keyed on all
three language fields, which are exactly the ones the surrounding
<code>useMemo</code> already depends on; wrapper identity still only
changes when the language state does, so the caching from <a
href="https://redirect.github.com/i18next/react-i18next/issues/1885">#1885</a>
is unaffected. Reported via <a
href="https://redirect.github.com/i18next/next-i18next/issues/2348">next-i18next#2348</a>.</li>
</ul>
<h2>17.0.13</h2>
<ul>
<li>fix(types): the selector-form <code>keyPrefix</code> overload of
<code>useTranslation()</code> is now available under
<code>enableSelector: 'strict'</code>. <code>useTranslation</code> was
gated on <code>true | 'optimize'</code> only, so under
<code>'strict'</code> it resolved to the legacy signature and the
selector overload disappeared entirely (<code>keyPrefix: ($) =&gt;
$.ns.foo</code> failed with <code>Type '($: any) =&gt; any' is not
assignable to type 'undefined'</code>). <code>Trans</code> already
handled all three modes. Companion to the same fix for
<code>getFixedT</code> in <a
href="https://redirect.github.com/i18next/i18next/pull/2446">i18next#2446</a>.
Thanks <a
href="https://github.com/hovelopin"><code>@​hovelopin</code></a> (<a
href="https://redirect.github.com/i18next/react-i18next/pull/1930">#1930</a>).</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/i18next/react-i18next/commit/7d38e0919507f0d339ac29b9fbd5f718eaadc829"><code>7d38e09</code></a>
17.0.15</li>
<li><a
href="https://github.com/i18next/react-i18next/commit/875b327d3515c781cd083dd77d3d8838dc1efc06"><code>875b327</code></a>
fix(Trans): preserve single-element children in empty slots</li>
<li><a
href="https://github.com/i18next/react-i18next/commit/5f8c5f9e6c7cdabdc476111d0748c91e33bbaa30"><code>5f8c5f9</code></a>
17.0.14</li>
<li><a
href="https://github.com/i18next/react-i18next/commit/6def81a790ddc55cc6c09a9f306ea6c88e25867c"><code>6def81a</code></a>
fix: refresh the returned i18n wrapper when resolvedLanguage
changes</li>
<li><a
href="https://github.com/i18next/react-i18next/commit/f37ea872c74e74ca64a5b6652cc131893405770b"><code>f37ea87</code></a>
docs: &quot;For AI assistants&quot; paragraph in the README</li>
<li><a
href="https://github.com/i18next/react-i18next/commit/e0592bafde1a904588c115f67b36cddf382e49c5"><code>e0592ba</code></a>
chore: keep dev-only and local files out of the npm package</li>
<li><a
href="https://github.com/i18next/react-i18next/commit/addf646a37f5980af08814b5a2568def28e7e428"><code>addf646</code></a>
17.0.13</li>
<li><a
href="https://github.com/i18next/react-i18next/commit/7c634ee3f396af22ec7b5c3c647b8d5ab198b5ae"><code>7c634ee</code></a>
changelog v17.0.13</li>
<li><a
href="https://github.com/i18next/react-i18next/commit/5ceefb0eff8bb430c658b21e5a08b457e78d87df"><code>5ceefb0</code></a>
fix(types): allow selector keyPrefix in useTranslation under
enableSelector '...</li>
<li><a
href="https://github.com/i18next/react-i18next/commit/aa7ba520255753c50d7fff9ab33ce0c7a60a45a2"><code>aa7ba52</code></a>
chore(examples): require activesupport &gt;= 7.2.3.1 in the RN
Gemfiles</li>
<li>Additional commits viewable in <a
href="https://github.com/i18next/react-i18next/compare/v17.0.12...v17.0.15">compare
view</a></li>
</ul>
</details>
<br />

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
nightly/v2026.1002.0-nightly.0 canary/v2026.1002.0-canary.7
2026-10-01 22:06:28 -07:00
dependabot[bot] f48bbba2ba build(deps): bump @assistant-ui/react from 0.15.21 to 0.15.22 (#12971)
Bumps
[@assistant-ui/react](https://github.com/assistant-ui/assistant-ui/tree/HEAD/packages/react)
from 0.15.21 to 0.15.22.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/assistant-ui/assistant-ui/releases">@​assistant-ui/react's
releases</a>.</em></p>
<blockquote>
<h2><code>@​assistant-ui/react</code><a
href="https://github.com/0"><code>@​0</code></a>.15.22</h2>
<h3>Patch Changes</h3>
<ul>
<li>
<p><a
href="https://redirect.github.com/assistant-ui/assistant-ui/pull/8032">#8032</a>
<a
href="https://github.com/assistant-ui/assistant-ui/commit/d09680175b062b26c393aa274bf4068012b82a9c"><code>d096801</code></a>
- fix: type the assistant transport request body that
<code>prepareSendCommandsRequest</code> receives; its fields are no
longer <code>unknown</code> in <code>@assistant-ui/react</code>, and
<code>threadId</code> is an optional <code>string</code>, absent when a
resume has no remote id, instead of <code>string | null</code> (<a
href="https://github.com/apps/rupic-app"><code>@​rupic-app</code></a>)</p>
</li>
<li>
<p><a
href="https://redirect.github.com/assistant-ui/assistant-ui/pull/8342">#8342</a>
<a
href="https://github.com/assistant-ui/assistant-ui/commit/aa0f33854f1d054ca747710d2144ba9e77c3182e"><code>aa0f338</code></a>
- feat: <code>useAssistantTransportRuntime</code> accepts
<code>cloud</code>: Assistant Cloud backs the thread list and every
request carries the cloud thread id; without <code>cloud</code>,
<code>NEXT_PUBLIC_ASSISTANT_BASE_URL</code> selects Assistant Cloud, as
it does for <code>useLocalRuntime</code>. <code>adapters.history</code>,
which this runtime never read, is deprecated (<a
href="https://github.com/okisdev"><code>@​okisdev</code></a>)</p>
</li>
<li>
<p><a
href="https://redirect.github.com/assistant-ui/assistant-ui/pull/7731">#7731</a>
<a
href="https://github.com/assistant-ui/assistant-ui/commit/455e2ac67bbcb7329d3f8367daf409eac5bc3a27"><code>455e2ac</code></a>
- fix: lock the current scroll container after reasoning content or its
ancestor chain changes (<a
href="https://github.com/Kinfe123"><code>@​Kinfe123</code></a>)</p>
</li>
<li>
<p><a
href="https://redirect.github.com/assistant-ui/assistant-ui/pull/7730">#7730</a>
<a
href="https://github.com/assistant-ui/assistant-ui/commit/af49e91648334569ac36a94f602a66b6dbe031dc"><code>af49e91</code></a>
- fix: prevent stale message hover updates after unmount (<a
href="https://github.com/Kinfe123"><code>@​Kinfe123</code></a>)</p>
</li>
<li>
<p><a
href="https://redirect.github.com/assistant-ui/assistant-ui/pull/7737">#7737</a>
<a
href="https://github.com/assistant-ui/assistant-ui/commit/6cc0bee320a1eccc855b4140249b8ac552010472"><code>6cc0bee</code></a>
- fix: scope selection toolbars to their owning thread (<a
href="https://github.com/Kinfe123"><code>@​Kinfe123</code></a>)</p>
</li>
<li>
<p><a
href="https://redirect.github.com/assistant-ui/assistant-ui/pull/8339">#8339</a>
<a
href="https://github.com/assistant-ui/assistant-ui/commit/967de5db4ca0c876bff20bffb783167651357cdd"><code>967de5d</code></a>
- feat: <code>CloudRendererHost</code> draws a stored conversation in
the Assistant Cloud dashboard's As shown view with the app's own
components; a read only thread now reports itself disabled, so its
composer renders disabled, and ignores composer input instead of
throwing (<a
href="https://github.com/okisdev"><code>@​okisdev</code></a>)</p>
</li>
<li>
<p><a
href="https://redirect.github.com/assistant-ui/assistant-ui/pull/8030">#8030</a>
<a
href="https://github.com/assistant-ui/assistant-ui/commit/e8fac8d7e2eef1b2eee8ccb98dd9d69d03619ae3"><code>e8fac8d</code></a>
- feat: show a message with uploading attachments in the thread while it
is being sent (<a
href="https://github.com/okisdev"><code>@​okisdev</code></a>)</p>
<p><code>MessagePrimitive.Attachments</code> now hands its render
function <code>Attachment</code> rather than
<code>CompleteAttachment</code>, because the row of a message that is
still being sent shows attachments that are still uploading. a render
function that reads <code>attachment.content</code> should check
<code>attachment.status.type === &quot;complete&quot;</code> first.</p>
</li>
<li>
<p><a
href="https://redirect.github.com/assistant-ui/assistant-ui/pull/7877">#7877</a>
<a
href="https://github.com/assistant-ui/assistant-ui/commit/83f53542e7f91d1b93489e534b40151ca34094a8"><code>83f5354</code></a>
- fix: honor registered data-part fallbacks on native MessageContent and
grouped parts (<a
href="https://github.com/Kinfe123"><code>@​Kinfe123</code></a>)</p>
</li>
<li>
<p><a
href="https://redirect.github.com/assistant-ui/assistant-ui/pull/7760">#7760</a>
<a
href="https://github.com/assistant-ui/assistant-ui/commit/84e0cf4c9b7fc92a85d1360b37e2e20b73bed650"><code>84e0cf4</code></a>
- fix: emit declarations from one TypeScript program so two builds of
the same commit produce the same <code>.d.ts</code> (<a
href="https://github.com/okisdev"><code>@​okisdev</code></a>)</p>
<p><code>aui-build</code> now emits the unbundled <code>.d.ts</code>
output in one TypeScript pass over the whole package, so two builds of
the same commit produce identical declarations; the per-module emit it
replaced followed the bundler's load order and let union member order,
alias visibility and import specifiers move between builds. Declarations
import barrels as the source does and keep <code>import type</code>; the
exported types are unchanged. A <code>/// &lt;reference&gt;</code>
directive that must reach the published declarations now carries
<code>preserve=&quot;true&quot;</code> in the source.</p>
</li>
<li>
<p><a
href="https://redirect.github.com/assistant-ui/assistant-ui/pull/7838">#7838</a>
<a
href="https://github.com/assistant-ui/assistant-ui/commit/3d01501c5642b7b0a4f1094a5a0b93976d02eed7"><code>3d01501</code></a>
- fix: every distribution re-exports the same shared surface from
<code>@assistant-ui/core</code>. <code>@assistant-ui/react-ink</code>
gains <code>ReadonlyThreadProvider</code>,
<code>ToolCallMessagePartStatus</code>, <code>groupPartByType</code>,
<code>GroupByContext</code>, <code>VoiceSessionState</code>, the
external store runtime (<code>useExternalStoreRuntime</code>,
<code>useExternalMessageConverter</code>, their adapters and options),
the message queue, the tool approval types, the generative UI renderer
and the cloud thread list hooks; <code>@assistant-ui/react-native</code>
gains <code>VoiceSessionState</code>, the cloud thread list hooks, the
generative UI renderer and the runtime state and adapter types the web
package already carried; <code>@assistant-ui/react</code> gains
<code>MessageRole</code>, <code>RunConfig</code>,
<code>RuntimeCapabilities</code>, <code>RemoteThreadListOptions</code>,
<code>ThreadsState</code>, <code>JoinStrategy</code>,
<code>TitleGenerationAdapter</code>,
<code>createSimpleTitleAdapter</code> and
<code>ChainOfThoughtPartByIndexProvider</code>. (<a
href="https://github.com/okisdev"><code>@​okisdev</code></a>)</p>
</li>
<li>
<p><a
href="https://redirect.github.com/assistant-ui/assistant-ui/pull/7520">#7520</a>
<a
href="https://github.com/assistant-ui/assistant-ui/commit/2171a8e06b8ca739a98eba927ab8b27175dd7be6"><code>2171a8e</code></a>
- fix(react): attach the ExportMarkdown download anchor to the document
so Firefox starts the download (<a
href="https://github.com/Kinfe123"><code>@​Kinfe123</code></a>)</p>
</li>
<li>
<p><a
href="https://redirect.github.com/assistant-ui/assistant-ui/pull/8010">#8010</a>
<a
href="https://github.com/assistant-ui/assistant-ui/commit/1c86c4c9e9cd4f7b2a27efd089d779831e54c2f0"><code>1c86c4c</code></a>
- fix: prevent disabled attachment dropzones from navigating to dropped
files. (<a
href="https://github.com/Kinfe123"><code>@​Kinfe123</code></a>)</p>
</li>
<li>
<p><a
href="https://redirect.github.com/assistant-ui/assistant-ui/pull/7733">#7733</a>
<a
href="https://github.com/assistant-ui/assistant-ui/commit/e2f13068534f9ca2d526a4e683846db7d6f2ec3b"><code>e2f1306</code></a>
- fix: clear attachment drag state when the dropzone is disabled (<a
href="https://github.com/Kinfe123"><code>@​Kinfe123</code></a>)</p>
</li>
<li>
<p><a
href="https://redirect.github.com/assistant-ui/assistant-ui/pull/7897">#7897</a>
<a
href="https://github.com/assistant-ui/assistant-ui/commit/16ef5b3e1f982a392c00a9a90b291c02e6c6fc5c"><code>16ef5b3</code></a>
- fix(react): stop a pending bottom scroll from hijacking
keyboard-driven content growth (<a
href="https://github.com/Kinfe123"><code>@​Kinfe123</code></a>)</p>
</li>
<li>
<p><a
href="https://redirect.github.com/assistant-ui/assistant-ui/pull/7762">#7762</a>
<a
href="https://github.com/assistant-ui/assistant-ui/commit/49283649b9119d8fe3acbc7bd2703d3473a98e9b"><code>4928364</code></a>
- fix: resolve component registries by own keys only, so a component,
tool or data part name that only <code>Object.prototype</code> has
(<code>toString</code>, <code>constructor</code>,
<code>__proto__</code>) takes the <code>Fallback</code> or
<code>GenerativeUIRenderError</code> path instead of rendering the
inherited built-in (<a
href="https://github.com/okisdev"><code>@​okisdev</code></a>)</p>
</li>
<li>
<p><a
href="https://redirect.github.com/assistant-ui/assistant-ui/pull/7725">#7725</a>
<a
href="https://github.com/assistant-ui/assistant-ui/commit/258ad136d849f67c06207cd8cfd944364c1e59cf"><code>258ad13</code></a>
- fix: expose feedback submission state to assistive technology (<a
href="https://github.com/apps/rupic-app"><code>@​rupic-app</code></a>)</p>
</li>
<li>
<p><a
href="https://redirect.github.com/assistant-ui/assistant-ui/pull/7981">#7981</a>
<a
href="https://github.com/assistant-ui/assistant-ui/commit/0252c6966322f09eda17172bfcaab8c641529bcf"><code>0252c69</code></a>
- feat: name the runtime state types <code>ThreadRuntimeState</code>,
<code>MessageRuntimeState</code>, <code>ComposerRuntimeState</code>,
<code>AttachmentRuntimeState</code> and
<code>ThreadListItemRuntimeState</code> (<a
href="https://github.com/okisdev"><code>@​okisdev</code></a>)</p>
<p>these are the states <code>ThreadRuntime</code>,
<code>MessageRuntime</code>, <code>ComposerRuntime</code>,
<code>AttachmentRuntime</code> and <code>ThreadListItemRuntime</code>
return from <code>getState()</code>, now exported by all three
distributions; <code>@assistant-ui/react-native</code> and
<code>@assistant-ui/react-ink</code> had no name for them. in
<code>@assistant-ui/react</code>, <code>ThreadState</code>,
<code>MessageState</code>, <code>ComposerState</code>,
<code>AttachmentState</code> and <code>ThreadListItemState</code> still
name these runtime states but are deprecated: from 0.16 they name the
store states <code>useAuiState</code> reads, as they already do in
<code>@assistant-ui/react-native</code> and
<code>@assistant-ui/react-ink</code>. code that annotates a runtime's
<code>getState()</code> result should move to the new names.</p>
</li>
<li>
<p><a
href="https://redirect.github.com/assistant-ui/assistant-ui/pull/8149">#8149</a>
<a
href="https://github.com/assistant-ui/assistant-ui/commit/1b1ff55c227a8bf58d6413ec8b248162540acc19"><code>1b1ff55</code></a>
- fix(react): keep the selection toolbar in sync after a right-click, so
a context menu that swallows the mouseup no longer leaves it showing
(and quoting) the previous selection (<a
href="https://github.com/samdickson22"><code>@​samdickson22</code></a>)</p>
</li>
<li>
<p><a
href="https://redirect.github.com/assistant-ui/assistant-ui/pull/8065">#8065</a>
<a
href="https://github.com/assistant-ui/assistant-ui/commit/2caacadf195a30efe04aaff8b46679ad99e70e74"><code>2caacad</code></a>
- feat: a tool UI can record what the user did on its tool call with
<code>unstable_recordInteraction</code>, kept on the part as
<code>unstable_interactions</code> and stored in cloud history; the
answer to a human input request is recorded once the runtime accepts it,
the local runtime persists records and keeps them out of model input,
external stores receive them through
<code>unstable_onRecordToolInteraction</code>, and readonly threads
ignore them (<a
href="https://github.com/okisdev"><code>@​okisdev</code></a>)</p>
</li>
<li>
<p><a
href="https://redirect.github.com/assistant-ui/assistant-ui/pull/7068">#7068</a>
<a
href="https://github.com/assistant-ui/assistant-ui/commit/4b069f90fbcb58953ebc7b9c4becca0bf4607842"><code>4b069f9</code></a>
- fix: Use successful Standard Schema output for tool execution and
model output. Keep the original arguments for validation errors and
stored tool calls. (<a
href="https://github.com/ephraimduncan"><code>@​ephraimduncan</code></a>)</p>
</li>
<li>
<p><a
href="https://redirect.github.com/assistant-ui/assistant-ui/pull/7777">#7777</a>
<a
href="https://github.com/assistant-ui/assistant-ui/commit/c51ba8fb3014375ae62784084aaefe3ecc6d72fa"><code>c51ba8f</code></a>
- feat(core): let typed text enter a connected voice session through
<code>sendText</code> (<a
href="https://github.com/okisdev"><code>@​okisdev</code></a>)</p>
</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/assistant-ui/assistant-ui/blob/main/packages/react/CHANGELOG.md">@​assistant-ui/react's
changelog</a>.</em></p>
<blockquote>
<h2>0.15.22</h2>
<h3>Patch Changes</h3>
<ul>
<li>
<p><a
href="https://redirect.github.com/assistant-ui/assistant-ui/pull/8032">#8032</a>
<a
href="https://github.com/assistant-ui/assistant-ui/commit/d09680175b062b26c393aa274bf4068012b82a9c"><code>d096801</code></a>
- fix: type the assistant transport request body that
<code>prepareSendCommandsRequest</code> receives; its fields are no
longer <code>unknown</code> in <code>@assistant-ui/react</code>, and
<code>threadId</code> is an optional <code>string</code>, absent when a
resume has no remote id, instead of <code>string | null</code> (<a
href="https://github.com/apps/rupic-app"><code>@​rupic-app</code></a>)</p>
</li>
<li>
<p><a
href="https://redirect.github.com/assistant-ui/assistant-ui/pull/8342">#8342</a>
<a
href="https://github.com/assistant-ui/assistant-ui/commit/aa0f33854f1d054ca747710d2144ba9e77c3182e"><code>aa0f338</code></a>
- feat: <code>useAssistantTransportRuntime</code> accepts
<code>cloud</code>: Assistant Cloud backs the thread list and every
request carries the cloud thread id; without <code>cloud</code>,
<code>NEXT_PUBLIC_ASSISTANT_BASE_URL</code> selects Assistant Cloud, as
it does for <code>useLocalRuntime</code>. <code>adapters.history</code>,
which this runtime never read, is deprecated (<a
href="https://github.com/okisdev"><code>@​okisdev</code></a>)</p>
</li>
<li>
<p><a
href="https://redirect.github.com/assistant-ui/assistant-ui/pull/7731">#7731</a>
<a
href="https://github.com/assistant-ui/assistant-ui/commit/455e2ac67bbcb7329d3f8367daf409eac5bc3a27"><code>455e2ac</code></a>
- fix: lock the current scroll container after reasoning content or its
ancestor chain changes (<a
href="https://github.com/Kinfe123"><code>@​Kinfe123</code></a>)</p>
</li>
<li>
<p><a
href="https://redirect.github.com/assistant-ui/assistant-ui/pull/7730">#7730</a>
<a
href="https://github.com/assistant-ui/assistant-ui/commit/af49e91648334569ac36a94f602a66b6dbe031dc"><code>af49e91</code></a>
- fix: prevent stale message hover updates after unmount (<a
href="https://github.com/Kinfe123"><code>@​Kinfe123</code></a>)</p>
</li>
<li>
<p><a
href="https://redirect.github.com/assistant-ui/assistant-ui/pull/7737">#7737</a>
<a
href="https://github.com/assistant-ui/assistant-ui/commit/6cc0bee320a1eccc855b4140249b8ac552010472"><code>6cc0bee</code></a>
- fix: scope selection toolbars to their owning thread (<a
href="https://github.com/Kinfe123"><code>@​Kinfe123</code></a>)</p>
</li>
<li>
<p><a
href="https://redirect.github.com/assistant-ui/assistant-ui/pull/8339">#8339</a>
<a
href="https://github.com/assistant-ui/assistant-ui/commit/967de5db4ca0c876bff20bffb783167651357cdd"><code>967de5d</code></a>
- feat: <code>CloudRendererHost</code> draws a stored conversation in
the Assistant Cloud dashboard's As shown view with the app's own
components; a read only thread now reports itself disabled, so its
composer renders disabled, and ignores composer input instead of
throwing (<a
href="https://github.com/okisdev"><code>@​okisdev</code></a>)</p>
</li>
<li>
<p><a
href="https://redirect.github.com/assistant-ui/assistant-ui/pull/8030">#8030</a>
<a
href="https://github.com/assistant-ui/assistant-ui/commit/e8fac8d7e2eef1b2eee8ccb98dd9d69d03619ae3"><code>e8fac8d</code></a>
- feat: show a message with uploading attachments in the thread while it
is being sent (<a
href="https://github.com/okisdev"><code>@​okisdev</code></a>)</p>
<p><code>MessagePrimitive.Attachments</code> now hands its render
function <code>Attachment</code> rather than
<code>CompleteAttachment</code>, because the row of a message that is
still being sent shows attachments that are still uploading. a render
function that reads <code>attachment.content</code> should check
<code>attachment.status.type === &quot;complete&quot;</code> first.</p>
</li>
<li>
<p><a
href="https://redirect.github.com/assistant-ui/assistant-ui/pull/7877">#7877</a>
<a
href="https://github.com/assistant-ui/assistant-ui/commit/83f53542e7f91d1b93489e534b40151ca34094a8"><code>83f5354</code></a>
- fix: honor registered data-part fallbacks on native MessageContent and
grouped parts (<a
href="https://github.com/Kinfe123"><code>@​Kinfe123</code></a>)</p>
</li>
<li>
<p><a
href="https://redirect.github.com/assistant-ui/assistant-ui/pull/7760">#7760</a>
<a
href="https://github.com/assistant-ui/assistant-ui/commit/84e0cf4c9b7fc92a85d1360b37e2e20b73bed650"><code>84e0cf4</code></a>
- fix: emit declarations from one TypeScript program so two builds of
the same commit produce the same <code>.d.ts</code> (<a
href="https://github.com/okisdev"><code>@​okisdev</code></a>)</p>
<p><code>aui-build</code> now emits the unbundled <code>.d.ts</code>
output in one TypeScript pass over the whole package, so two builds of
the same commit produce identical declarations; the per-module emit it
replaced followed the bundler's load order and let union member order,
alias visibility and import specifiers move between builds. Declarations
import barrels as the source does and keep <code>import type</code>; the
exported types are unchanged. A <code>/// &lt;reference&gt;</code>
directive that must reach the published declarations now carries
<code>preserve=&quot;true&quot;</code> in the source.</p>
</li>
<li>
<p><a
href="https://redirect.github.com/assistant-ui/assistant-ui/pull/7838">#7838</a>
<a
href="https://github.com/assistant-ui/assistant-ui/commit/3d01501c5642b7b0a4f1094a5a0b93976d02eed7"><code>3d01501</code></a>
- fix: every distribution re-exports the same shared surface from
<code>@assistant-ui/core</code>. <code>@assistant-ui/react-ink</code>
gains <code>ReadonlyThreadProvider</code>,
<code>ToolCallMessagePartStatus</code>, <code>groupPartByType</code>,
<code>GroupByContext</code>, <code>VoiceSessionState</code>, the
external store runtime (<code>useExternalStoreRuntime</code>,
<code>useExternalMessageConverter</code>, their adapters and options),
the message queue, the tool approval types, the generative UI renderer
and the cloud thread list hooks; <code>@assistant-ui/react-native</code>
gains <code>VoiceSessionState</code>, the cloud thread list hooks, the
generative UI renderer and the runtime state and adapter types the web
package already carried; <code>@assistant-ui/react</code> gains
<code>MessageRole</code>, <code>RunConfig</code>,
<code>RuntimeCapabilities</code>, <code>RemoteThreadListOptions</code>,
<code>ThreadsState</code>, <code>JoinStrategy</code>,
<code>TitleGenerationAdapter</code>,
<code>createSimpleTitleAdapter</code> and
<code>ChainOfThoughtPartByIndexProvider</code>. (<a
href="https://github.com/okisdev"><code>@​okisdev</code></a>)</p>
</li>
<li>
<p><a
href="https://redirect.github.com/assistant-ui/assistant-ui/pull/7520">#7520</a>
<a
href="https://github.com/assistant-ui/assistant-ui/commit/2171a8e06b8ca739a98eba927ab8b27175dd7be6"><code>2171a8e</code></a>
- fix(react): attach the ExportMarkdown download anchor to the document
so Firefox starts the download (<a
href="https://github.com/Kinfe123"><code>@​Kinfe123</code></a>)</p>
</li>
<li>
<p><a
href="https://redirect.github.com/assistant-ui/assistant-ui/pull/8010">#8010</a>
<a
href="https://github.com/assistant-ui/assistant-ui/commit/1c86c4c9e9cd4f7b2a27efd089d779831e54c2f0"><code>1c86c4c</code></a>
- fix: prevent disabled attachment dropzones from navigating to dropped
files. (<a
href="https://github.com/Kinfe123"><code>@​Kinfe123</code></a>)</p>
</li>
<li>
<p><a
href="https://redirect.github.com/assistant-ui/assistant-ui/pull/7733">#7733</a>
<a
href="https://github.com/assistant-ui/assistant-ui/commit/e2f13068534f9ca2d526a4e683846db7d6f2ec3b"><code>e2f1306</code></a>
- fix: clear attachment drag state when the dropzone is disabled (<a
href="https://github.com/Kinfe123"><code>@​Kinfe123</code></a>)</p>
</li>
<li>
<p><a
href="https://redirect.github.com/assistant-ui/assistant-ui/pull/7897">#7897</a>
<a
href="https://github.com/assistant-ui/assistant-ui/commit/16ef5b3e1f982a392c00a9a90b291c02e6c6fc5c"><code>16ef5b3</code></a>
- fix(react): stop a pending bottom scroll from hijacking
keyboard-driven content growth (<a
href="https://github.com/Kinfe123"><code>@​Kinfe123</code></a>)</p>
</li>
<li>
<p><a
href="https://redirect.github.com/assistant-ui/assistant-ui/pull/7762">#7762</a>
<a
href="https://github.com/assistant-ui/assistant-ui/commit/49283649b9119d8fe3acbc7bd2703d3473a98e9b"><code>4928364</code></a>
- fix: resolve component registries by own keys only, so a component,
tool or data part name that only <code>Object.prototype</code> has
(<code>toString</code>, <code>constructor</code>,
<code>__proto__</code>) takes the <code>Fallback</code> or
<code>GenerativeUIRenderError</code> path instead of rendering the
inherited built-in (<a
href="https://github.com/okisdev"><code>@​okisdev</code></a>)</p>
</li>
<li>
<p><a
href="https://redirect.github.com/assistant-ui/assistant-ui/pull/7725">#7725</a>
<a
href="https://github.com/assistant-ui/assistant-ui/commit/258ad136d849f67c06207cd8cfd944364c1e59cf"><code>258ad13</code></a>
- fix: expose feedback submission state to assistive technology (<a
href="https://github.com/apps/rupic-app"><code>@​rupic-app</code></a>)</p>
</li>
<li>
<p><a
href="https://redirect.github.com/assistant-ui/assistant-ui/pull/7981">#7981</a>
<a
href="https://github.com/assistant-ui/assistant-ui/commit/0252c6966322f09eda17172bfcaab8c641529bcf"><code>0252c69</code></a>
- feat: name the runtime state types <code>ThreadRuntimeState</code>,
<code>MessageRuntimeState</code>, <code>ComposerRuntimeState</code>,
<code>AttachmentRuntimeState</code> and
<code>ThreadListItemRuntimeState</code> (<a
href="https://github.com/okisdev"><code>@​okisdev</code></a>)</p>
<p>these are the states <code>ThreadRuntime</code>,
<code>MessageRuntime</code>, <code>ComposerRuntime</code>,
<code>AttachmentRuntime</code> and <code>ThreadListItemRuntime</code>
return from <code>getState()</code>, now exported by all three
distributions; <code>@assistant-ui/react-native</code> and
<code>@assistant-ui/react-ink</code> had no name for them. in
<code>@assistant-ui/react</code>, <code>ThreadState</code>,
<code>MessageState</code>, <code>ComposerState</code>,
<code>AttachmentState</code> and <code>ThreadListItemState</code> still
name these runtime states but are deprecated: from 0.16 they name the
store states <code>useAuiState</code> reads, as they already do in
<code>@assistant-ui/react-native</code> and
<code>@assistant-ui/react-ink</code>. code that annotates a runtime's
<code>getState()</code> result should move to the new names.</p>
</li>
<li>
<p><a
href="https://redirect.github.com/assistant-ui/assistant-ui/pull/8149">#8149</a>
<a
href="https://github.com/assistant-ui/assistant-ui/commit/1b1ff55c227a8bf58d6413ec8b248162540acc19"><code>1b1ff55</code></a>
- fix(react): keep the selection toolbar in sync after a right-click, so
a context menu that swallows the mouseup no longer leaves it showing
(and quoting) the previous selection (<a
href="https://github.com/samdickson22"><code>@​samdickson22</code></a>)</p>
</li>
<li>
<p><a
href="https://redirect.github.com/assistant-ui/assistant-ui/pull/8065">#8065</a>
<a
href="https://github.com/assistant-ui/assistant-ui/commit/2caacadf195a30efe04aaff8b46679ad99e70e74"><code>2caacad</code></a>
- feat: a tool UI can record what the user did on its tool call with
<code>unstable_recordInteraction</code>, kept on the part as
<code>unstable_interactions</code> and stored in cloud history; the
answer to a human input request is recorded once the runtime accepts it,
the local runtime persists records and keeps them out of model input,
external stores receive them through
<code>unstable_onRecordToolInteraction</code>, and readonly threads
ignore them (<a
href="https://github.com/okisdev"><code>@​okisdev</code></a>)</p>
</li>
<li>
<p><a
href="https://redirect.github.com/assistant-ui/assistant-ui/pull/7068">#7068</a>
<a
href="https://github.com/assistant-ui/assistant-ui/commit/4b069f90fbcb58953ebc7b9c4becca0bf4607842"><code>4b069f9</code></a>
- fix: Use successful Standard Schema output for tool execution and
model output. Keep the original arguments for validation errors and
stored tool calls. (<a
href="https://github.com/ephraimduncan"><code>@​ephraimduncan</code></a>)</p>
</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/assistant-ui/assistant-ui/commit/f008537f39f0936992b0f6d2433c092935df5faf"><code>f008537</code></a>
chore: update versions (<a
href="https://github.com/assistant-ui/assistant-ui/tree/HEAD/packages/react/issues/7724">#7724</a>)</li>
<li><a
href="https://github.com/assistant-ui/assistant-ui/commit/967de5db4ca0c876bff20bffb783167651357cdd"><code>967de5d</code></a>
feat(react): CloudRendererHost draws a stored conversation in the
dashboard's...</li>
<li><a
href="https://github.com/assistant-ui/assistant-ui/commit/1b1ff55c227a8bf58d6413ec8b248162540acc19"><code>1b1ff55</code></a>
fix(react): keep the selection toolbar quoting what is selected after a
right...</li>
<li><a
href="https://github.com/assistant-ui/assistant-ui/commit/2caacadf195a30efe04aaff8b46679ad99e70e74"><code>2caacad</code></a>
feat(core): record the user's interactions with a tool ui on its tool
call (#...</li>
<li><a
href="https://github.com/assistant-ui/assistant-ui/commit/e8fac8d7e2eef1b2eee8ccb98dd9d69d03619ae3"><code>e8fac8d</code></a>
feat(core): show a message with uploading attachments while it is sent
(<a
href="https://github.com/assistant-ui/assistant-ui/tree/HEAD/packages/react/issues/8030">#8030</a>)</li>
<li><a
href="https://github.com/assistant-ui/assistant-ui/commit/d09680175b062b26c393aa274bf4068012b82a9c"><code>d096801</code></a>
fix: type the assistant transport body that prepareSendCommandsRequest
receiv...</li>
<li><a
href="https://github.com/assistant-ui/assistant-ui/commit/1c86c4c9e9cd4f7b2a27efd089d779831e54c2f0"><code>1c86c4c</code></a>
fix(react): claim file drops when attachment dropzone is disabled (<a
href="https://github.com/assistant-ui/assistant-ui/tree/HEAD/packages/react/issues/8010">#8010</a>)</li>
<li><a
href="https://github.com/assistant-ui/assistant-ui/commit/0252c6966322f09eda17172bfcaab8c641529bcf"><code>0252c69</code></a>
feat: name the runtime state types and deprecate their old names (<a
href="https://github.com/assistant-ui/assistant-ui/tree/HEAD/packages/react/issues/7981">#7981</a>)</li>
<li><a
href="https://github.com/assistant-ui/assistant-ui/commit/15937b8844db7757d3595d5644bc27196e742f4a"><code>15937b8</code></a>
test(react): skip the initial viewport scroll in the MessageRoot hover
test (...</li>
<li><a
href="https://github.com/assistant-ui/assistant-ui/commit/16ef5b3e1f982a392c00a9a90b291c02e6c6fc5c"><code>16ef5b3</code></a>
fix(react): cancel pending bottom scroll on a keyboard gesture (<a
href="https://github.com/assistant-ui/assistant-ui/tree/HEAD/packages/react/issues/7897">#7897</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/assistant-ui/assistant-ui/commits/@assistant-ui/react@0.15.22/packages/react">compare
view</a></li>
</ul>
</details>
<br />

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
canary/v2026.1002.0-canary.6
2026-10-01 21:36:32 -07:00
dependabot[bot] 3934fd14e5 build(deps-dev): bump @storybook/addon-docs from 10.5.10 to 10.6.0 (#12972)
Bumps
[@storybook/addon-docs](https://github.com/storybookjs/storybook/tree/HEAD/code/addons/docs)
from 10.5.10 to 10.6.0.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/storybookjs/storybook/releases">@​storybook/addon-docs's
releases</a>.</em></p>
<blockquote>
<h2>v10.6.0</h2>
<h2>10.6.0</h2>
<blockquote>
<p>New skills architecture for agentic workflows</p>
</blockquote>
<p>Storybook 10.6 contains hundreds of fixes and improvements:</p>
<ul>
<li>💻 CLI bindings for agent tools/skills</li>
<li>🅰️ Angular-Vite MCP/skills support and improved docgen/snippets
(experimental)</li>
<li>🟢 Vue MCP/skills support and improved docgen/snippets
(experimental)</li>
<li>🧩 Tanstack / NextJS-Vite framework bugfixes</li>
<li>⚡ Improved performance and reduced bundle size</li>
</ul>
<!-- raw HTML omitted -->
<ul>
<li>Addon MCP: Stop silently dropping composed refs from MCP composition
- <a
href="https://redirect.github.com/storybookjs/storybook/pull/36077">#36077</a>,
thanks <a
href="https://github.com/kasperpeulen"><code>@​kasperpeulen</code></a>!</li>
<li>Addon Vitest: Pin storybook/test in optimizeDeps so its CJS-only
deps are prebundled - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35572">#35572</a>,
thanks <a
href="https://github.com/Nic-Polumeyv"><code>@​Nic-Polumeyv</code></a>!</li>
<li>Addon Vitest: Report test runs with failures as failed tool outcomes
- <a
href="https://redirect.github.com/storybookjs/storybook/pull/36080">#36080</a>,
thanks <a
href="https://github.com/kasperpeulen"><code>@​kasperpeulen</code></a>!</li>
<li>Addon Vitest: Resolve story test globs against the project root - <a
href="https://redirect.github.com/storybookjs/storybook/pull/36103">#36103</a>,
thanks <a
href="https://github.com/kasperpeulen"><code>@​kasperpeulen</code></a>!</li>
<li>Addon-vitest: Filter Storybook instrumentation from reported stack
traces - <a
href="https://redirect.github.com/storybookjs/storybook/pull/36120">#36120</a>,
thanks <a
href="https://github.com/ghengeveld"><code>@​ghengeveld</code></a>!</li>
<li>Angular Vite: Resolve tsConfig against the workspace root - <a
href="https://redirect.github.com/storybookjs/storybook/pull/36026">#36026</a>,
thanks <a
href="https://github.com/ndelangen"><code>@​ndelangen</code></a>!</li>
<li>Angular-Vite: Run Compodoc on demand - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35776">#35776</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Add an in-process docgen analyzer, replacing Compodoc under
the flag - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35805">#35805</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Bind only what the component accepts in story snippets, and
report the rest - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35943">#35943</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Decide the migration's zone.js import from the dependency
tree - <a
href="https://redirect.github.com/storybookjs/storybook/pull/36008">#36008</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Declare story args the snippet markup binds by name - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35895">#35895</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Declare style preprocessors as optional peers and name the
missing one - <a
href="https://redirect.github.com/storybookjs/storybook/pull/36098">#36098</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Derive required inputs from Compodoc's own flag - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35758">#35758</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Extract Compodoc parsing into its own package - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35749">#35749</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Extract component JSDoc through TypeScript's APIs - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35977">#35977</a>,
thanks <a
href="https://github.com/huang-julien"><code>@​huang-julien</code></a>!</li>
<li>Angular: Extract docgen on the server via Compodoc - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35733">#35733</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Fix component resolution, MCP output, and dev/build path
aliasing - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35952">#35952</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Fix eight upgrade and migration bugs - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35946">#35946</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Fix ten docgen bugs found across 22 community repositories
- <a
href="https://redirect.github.com/storybookjs/storybook/pull/35941">#35941</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Generate story-docs snippets from the analyzer - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35807">#35807</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Give agents real input and output documentation - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35896">#35896</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Hide class internals from the props table by default - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35887">#35887</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Install the `@storybook/angular-vite` peers that nothing
else brings in - <a
href="https://redirect.github.com/storybookjs/storybook/pull/36002">#36002</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Keep the function control on constructor and generic
signatures - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35921">#35921</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Make experimentalDocgenServer the default in angular-vite -
<a
href="https://redirect.github.com/storybookjs/storybook/pull/35886">#35886</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Migrate Analog projects to angular-vite instead of refusing
them - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35971">#35971</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Print unevaluable story args instead of slicing the file -
<a
href="https://redirect.github.com/storybookjs/storybook/pull/35888">#35888</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Read the story shapes that supply their own markup - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35797">#35797</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Render self-closing tags in server-side docs snippets - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35953">#35953</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Render the required badge for required inputs in the props
table - <a
href="https://redirect.github.com/storybookjs/storybook/pull/36065">#36065</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Resolve `@angular/core` through the package manager, not
the raw specifier - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35999">#35999</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Resolve builder `styles` the way the Angular builders do -
<a
href="https://redirect.github.com/storybookjs/storybook/pull/35998">#35998</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Resolve builder styles against the workspace root - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35974">#35974</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Skip the runtime source decorator when the docgen server
produces snippets - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35906">#35906</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/storybookjs/storybook/blob/next/CHANGELOG.md">@​storybook/addon-docs's
changelog</a>.</em></p>
<blockquote>
<h2>10.6.0</h2>
<blockquote>
<p>New skills architecture for agentic workflows</p>
</blockquote>
<p>Storybook 10.6 contains hundreds of fixes and improvements:</p>
<ul>
<li>💻 CLI bindings for agent tools/skills</li>
<li>🅰️ Angular-Vite MCP/skills support and improved docgen/snippets
(experimental)</li>
<li>🟢 Vue MCP/skills support and improved docgen/snippets
(experimental)</li>
<li>🧩 Tanstack / NextJS-Vite framework bugfixes</li>
<li>⚡ Improved performance and reduced bundle size</li>
</ul>
<!-- raw HTML omitted -->
<ul>
<li>Addon MCP: Stop silently dropping composed refs from MCP composition
- <a
href="https://redirect.github.com/storybookjs/storybook/pull/36077">#36077</a>,
thanks <a
href="https://github.com/kasperpeulen"><code>@​kasperpeulen</code></a>!</li>
<li>Addon Vitest: Pin storybook/test in optimizeDeps so its CJS-only
deps are prebundled - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35572">#35572</a>,
thanks <a
href="https://github.com/Nic-Polumeyv"><code>@​Nic-Polumeyv</code></a>!</li>
<li>Addon Vitest: Report test runs with failures as failed tool outcomes
- <a
href="https://redirect.github.com/storybookjs/storybook/pull/36080">#36080</a>,
thanks <a
href="https://github.com/kasperpeulen"><code>@​kasperpeulen</code></a>!</li>
<li>Addon Vitest: Resolve story test globs against the project root - <a
href="https://redirect.github.com/storybookjs/storybook/pull/36103">#36103</a>,
thanks <a
href="https://github.com/kasperpeulen"><code>@​kasperpeulen</code></a>!</li>
<li>Addon-vitest: Filter Storybook instrumentation from reported stack
traces - <a
href="https://redirect.github.com/storybookjs/storybook/pull/36120">#36120</a>,
thanks <a
href="https://github.com/ghengeveld"><code>@​ghengeveld</code></a>!</li>
<li>Angular Vite: Resolve tsConfig against the workspace root - <a
href="https://redirect.github.com/storybookjs/storybook/pull/36026">#36026</a>,
thanks <a
href="https://github.com/ndelangen"><code>@​ndelangen</code></a>!</li>
<li>Angular-Vite: Run Compodoc on demand - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35776">#35776</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Add an in-process docgen analyzer, replacing Compodoc under
the flag - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35805">#35805</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Bind only what the component accepts in story snippets, and
report the rest - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35943">#35943</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Decide the migration's zone.js import from the dependency
tree - <a
href="https://redirect.github.com/storybookjs/storybook/pull/36008">#36008</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Declare story args the snippet markup binds by name - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35895">#35895</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Declare style preprocessors as optional peers and name the
missing one - <a
href="https://redirect.github.com/storybookjs/storybook/pull/36098">#36098</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Derive required inputs from Compodoc's own flag - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35758">#35758</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Extract Compodoc parsing into its own package - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35749">#35749</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Extract component JSDoc through TypeScript's APIs - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35977">#35977</a>,
thanks <a
href="https://github.com/huang-julien"><code>@​huang-julien</code></a>!</li>
<li>Angular: Extract docgen on the server via Compodoc - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35733">#35733</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Fix component resolution, MCP output, and dev/build path
aliasing - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35952">#35952</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Fix eight upgrade and migration bugs - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35946">#35946</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Fix ten docgen bugs found across 22 community repositories
- <a
href="https://redirect.github.com/storybookjs/storybook/pull/35941">#35941</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Generate story-docs snippets from the analyzer - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35807">#35807</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Give agents real input and output documentation - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35896">#35896</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Hide class internals from the props table by default - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35887">#35887</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Install the <code>@storybook/angular-vite</code> peers that
nothing else brings in - <a
href="https://redirect.github.com/storybookjs/storybook/pull/36002">#36002</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Keep the function control on constructor and generic
signatures - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35921">#35921</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Make experimentalDocgenServer the default in angular-vite -
<a
href="https://redirect.github.com/storybookjs/storybook/pull/35886">#35886</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Migrate Analog projects to angular-vite instead of refusing
them - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35971">#35971</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Print unevaluable story args instead of slicing the file -
<a
href="https://redirect.github.com/storybookjs/storybook/pull/35888">#35888</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Read the story shapes that supply their own markup - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35797">#35797</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Render self-closing tags in server-side docs snippets - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35953">#35953</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Render the required badge for required inputs in the props
table - <a
href="https://redirect.github.com/storybookjs/storybook/pull/36065">#36065</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Resolve <code>@angular/core</code> through the package
manager, not the raw specifier - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35999">#35999</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Resolve builder <code>styles</code> the way the Angular
builders do - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35998">#35998</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Resolve builder styles against the workspace root - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35974">#35974</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Skip the runtime source decorator when the docgen server
produces snippets - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35906">#35906</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Stop marking a defaulted input as required in the props
table - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35899">#35899</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/storybookjs/storybook/commit/a77777356be2aeaff89d7a2b25254db7b2318392"><code>a777773</code></a>
Bump version from &quot;10.6.0-beta.3&quot; to &quot;10.6.0&quot; [skip
ci]</li>
<li><a
href="https://github.com/storybookjs/storybook/commit/f32b3667dad8df220cda0359e170bc49931af68c"><code>f32b366</code></a>
Bump version from &quot;10.6.0-beta.2&quot; to &quot;10.6.0-beta.3&quot;
[skip ci]</li>
<li><a
href="https://github.com/storybookjs/storybook/commit/0ad1336cbf0ecdab9f6b540570ae9015ae73ab86"><code>0ad1336</code></a>
Bump version from &quot;10.6.0-beta.1&quot; to &quot;10.6.0-beta.2&quot;
[skip ci]</li>
<li><a
href="https://github.com/storybookjs/storybook/commit/16359ee17802628c47915c21408cb578d2707b83"><code>16359ee</code></a>
Bump version from &quot;10.6.0-beta.0&quot; to &quot;10.6.0-beta.1&quot;
[skip ci]</li>
<li><a
href="https://github.com/storybookjs/storybook/commit/2e0e2f609d1351ba4384eb52e0728dc9cd8b275b"><code>2e0e2f6</code></a>
Bump version from &quot;10.6.0-alpha.9&quot; to
&quot;10.6.0-beta.0&quot; [skip ci]</li>
<li><a
href="https://github.com/storybookjs/storybook/commit/6a6dec2aedff6744a9d9226e1f6515e3d5e8b42a"><code>6a6dec2</code></a>
Bump version from &quot;10.6.0-alpha.8&quot; to
&quot;10.6.0-alpha.9&quot; [skip ci]</li>
<li><a
href="https://github.com/storybookjs/storybook/commit/cd2d16395a5ffa39189b96aafb6af67f280079db"><code>cd2d163</code></a>
Bump version from &quot;10.6.0-alpha.7&quot; to
&quot;10.6.0-alpha.8&quot; [skip ci]</li>
<li><a
href="https://github.com/storybookjs/storybook/commit/3bf4afdce8aba47cc7960d3a3e09a3fd1ceb2baa"><code>3bf4afd</code></a>
Merge branch 'next' into kasper/tools-cli-bootstrap-perf</li>
<li><a
href="https://github.com/storybookjs/storybook/commit/4ea0b1bc2c1a26ce061f5b44051e8f01273f27fa"><code>4ea0b1b</code></a>
refactor(docs): move anchorBlockIdFromId into docs-tools</li>
<li><a
href="https://github.com/storybookjs/storybook/commit/5c80681f18d273461e1b15cb775a77347079b0b0"><code>5c80681</code></a>
Merge pull request <a
href="https://github.com/storybookjs/storybook/tree/HEAD/code/addons/docs/issues/35965">#35965</a>
from storybookjs/valentin/sb-1804-surface-story-doc...</li>
<li>Additional commits viewable in <a
href="https://github.com/storybookjs/storybook/commits/v10.6.0/code/addons/docs">compare
view</a></li>
</ul>
</details>
<br />

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-10-01 21:14:09 -07:00
Devin FoleyandPaperclip 4e52463203 fix(daytona): recover output from stalled log streams (#14889)
## Thinking Path

> - Paperclip is the open source app people use to manage AI agents for
work.
> - The Daytona driver streams sandbox command output to the host.
> - A log socket can stop delivering bytes without closing or rejecting.
> - Missing permission requests and cancellation results can leave a run
active and block queued work.
> - This pull request switches an idle log stream to saved-output
polling for the same command.
> - The host can receive the missing output without another command
dispatch.

## Linked Issues or Issue Description

**What happened?**

The driver waits for the SDK log-stream promise before it can start
recovery. If that promise never settles, the host can miss new output
that is already in the provider's saved logs. A run can remain active
after a watch completes. Interrupt can then time out with “Execution is
still stopping; termination has not been verified.”

**Expected behavior**

Recover command observation when the live stream stalls. Forward new
permission requests and cancellation results. Require a recorded command
exit before reporting completion. Keep quiet commands running under the
caller's existing lifetime controls.

**Steps to reproduce**

1. Start a session command and leave the callback log promise pending.
2. Put new output in the snapshot API without invoking the stream
callback.
3. Keep the command running until the host receives that output, then
expose its cancellation output and exit code.
4. Verify that the host receives each byte once and dispatches the
command once.

**Paperclip version or commit**

Base commit `479554120d`.

**Agent adapter(s) involved**

Daytona session commands, including sandbox ACP agent sessions.

Related: #14799 handles closed streams; this change handles sockets that
never close. #14485 handles input delivery retries. #13262 adds
permission diagnostics.

## What Changed

- After 15 seconds with no stdout or stderr, switch directly to the
existing status and log-snapshot polling path.
- Ignore callbacks and delayed failures from the abandoned stream. Clear
its idle timer on every exit path.
- Preserve byte-offset deduplication, one command dispatch, and
independent timeouts for recovery reads.
- Add regressions for an initial stream stall, a stall after UTF-8
output, cancellation output, late callbacks, hung recovery reads, and
quiet commands that outlive an operation timeout.
- Update the provider documentation and keep hour-long healthy-stream
coverage active with periodic output.

## Verification

- `pnpm vitest run
packages/plugins/sandbox-providers/daytona/src/plugin.test.ts`: 245
passed.
- `pnpm exec vitest run --project @paperclipai/plugin-daytona`: 339
passed; 14 gated live tests skipped.
- Both new stalled-stream regressions fail on the unchanged base driver
because it never starts snapshot recovery. Both pass with this change.
- `pnpm -r typecheck`: passed.
- `pnpm build`: passed.
- `pnpm test:run`: the local run did not pass. It was stopped after
confirmed local skill-path and macOS skill-cache failures, once complete
PR CI was green. Four chat/email tests could not load connector skill
files from an ancestor directory outside the checkout. Three
company-skills tests hit macOS `EACCES` during cache publication. One
unrelated wakeup test timed out in the full run and passed on a focused
rerun (`1 passed`, `27 skipped`). No source or test assertions were
changed for these failures. This is not a complete local-suite pass.
- Complete PR CI on `11ac4e030b`: 53 successful checks, 2 expected
skips, no pending or failed checks. The clean CI run includes the full
test suite.
- Greptile reviewed `11ac4e030b` at 5/5 with no findings or unresolved
threads. The branch has no merge conflicts with `master`.
- `git diff --check` and a local scan for secrets and private
identifiers passed.

## Risks

- Quiet healthy commands also switch to polling. Full snapshots can
increase bandwidth as output grows; polling remains limited to one
snapshot per second.
- The SDK exposes no stream cancellation handle. The old socket remains
owned by session teardown, and its callbacks cannot publish after
fallback.
- This change recovers a stalled output stream. It does not claim to
identify every cause of an unanswered permission request or change the
requirement to verify termination before releasing work.
- No schema migration or command replay.

## Model Used

OpenAI GPT-6 through Codex, with tool use and code execution. The exact
serving model ID and context window are not exposed in this session.

## Checklist

- [x] I have included a thinking path that traces from project context
to this change
- [x] I have specified the model used (with version and capability
details)
- [x] I have checked ROADMAP.md and confirmed this PR does not duplicate
planned core work
- [x] I have searched GitHub for duplicate or related PRs and linked
them above
- [x] I have either (a) linked existing issues with `Fixes: #` /
`Closes: #` / `Refs: #` OR (b) described the issue in-PR following the
relevant issue template
- [x] I have not referenced internal/instance-local Paperclip issues or
links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip`
URLs)
- [x] My branch name describes the change (e.g. `docs/...`, `fix/...`)
and contains no internal Paperclip ticket id or instance-derived details
- [x] I have run local change-specific tests; the full suite passes in
CI, with local-suite limitations documented above
- [x] I have added or updated tests where applicable
- [x] I have updated relevant documentation to reflect my changes
- [x] I have considered and documented any risks above
- [x] All Paperclip CI gates are green
- [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups
- [x] I will address all Greptile and reviewer comments before
requesting merge

Co-authored-by: Paperclip <noreply@paperclip.ing>
canary/v2026.1002.0-canary.5
2026-10-01 21:04:41 -07:00
Devin Foleyandgithub-actions[bot] 261c24ccf9 docs(release): canonicalize stable notes for v2026.1001.0 (#14890)
## Thinking Path

> - Paperclip is the open source app people use to manage AI agents for
work
> - The release process keeps stable notes under a beta-keyed path
during the soak and renames them to the versioned path after the stable
ships
> - Stable v2026.1001.0 is published. The `canonicalize_stable_notes`
job pushed the rename branch but it does not open a pull request
> - The published notes also have no Contributors section. The previous
stable notes (v2026.916.0) have one
> - This pull request moves the notes to `releases/v2026.1001.0.md` and
adds the Contributors section
> - The benefit is that the repository returns to the canonical
release-notes layout and the external contributors get credit

## Linked Issues or Issue Description

**Issue type**

Missing content

**Where is the issue?**

`releases/` — the stable notes for v2026.1001.0 still live at the
beta-keyed path `releases/beta/v2026.921.0-beta.1.md`, and they have no
Contributors section.

**What's wrong?**

The `canonicalize_stable_notes` job in the stable release run pushed
branch `release-notes/v2026.1001.0-canonicalize` with the rename, but it
does not open a pull request. The notes also do not credit the three
external contributors in the release range.

**Suggested fix**

Merge the workflow's rename commit, plus one commit that appends a `##
Contributors` section in the same format as `releases/v2026.916.0.md`.

## What Changed

- Renamed `releases/beta/v2026.921.0-beta.1.md` to
`releases/v2026.1001.0.md` (workflow commit, no content changes)
- Appended a `## Contributors` section: 77 commits from 8 contributors,
with credits to @austinpilz, @hawikk, and @mouse-value-add
- No other content changed. The notes above the new section match the
published GitHub Release body for v2026.1001.0

## Verification

- `git log --follow releases/v2026.1001.0.md` shows the rename commit
followed by one commit that only appends the Contributors section
- `git rev-list --count v2026.916.1..v2026.1001.0` returns 77
- The author list of that range, minus maintainers and bots, is
@austinpilz, @hawikk, and @mouse-value-add
- The GitHub Release body for v2026.1001.0 is identical to this file
without the Contributors section

## Risks

- Low risk: a documentation-only rename plus one appended section.

## Model Used

- Claude (Anthropic), model ID `claude-fable-5-1` (Claude Fable 5.1),
extended thinking enabled, tool use via Claude Code

## Checklist

- [x] I have included a thinking path that traces from project context
to this change
- [x] I have specified the model used (with version and capability
details)
- [x] I have checked ROADMAP.md and confirmed this PR does not duplicate
planned core work
- [x] I have searched GitHub for duplicate or related PRs and linked
them above
- [x] I have either (a) linked existing issues with `Fixes: #` / `Closes
#` / `Refs #` OR (b) described the issue in-PR following the relevant
issue template
- [x] I have not referenced internal/instance-local Paperclip issues or
links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip`
URLs)
- [x] My branch name describes the change (e.g. `docs/...`, `fix/...`)
and contains no internal Paperclip ticket id or instance-derived details
- [x] I have run tests locally and they pass
- [x] I have added or updated tests where applicable
- [x] I have updated relevant documentation to reflect my changes
- [x] I have considered and documented any risks above
- [ ] All Paperclip CI gates are green
- [ ] Greptile is 5/5 with no open P2s, recommendations, or follow-ups
- [x] I will address all Greptile and reviewer comments before
requesting merge

---------

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
canary/v2026.1002.0-canary.4
2026-10-01 20:31:32 -07:00
dependabot[bot] 479554120d build(deps): bump i18next from 26.4.0 to 26.4.2 (#12973)
Bumps [i18next](https://github.com/i18next/i18next) from 26.4.0 to
26.4.2.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/i18next/i18next/releases">i18next's
releases</a>.</em></p>
<blockquote>
<h2>v26.4.2</h2>
<ul>
<li>fix: <code>$&amp;</code>, <code>$`</code>, <code>$'</code> and
<code>$$</code> inside a nested value (<code>$t(key)</code>) now stay
literal. <code>nest()</code> handed the resolved value straight to
<code>String.replace</code> as the replacement argument, so those
sequences were read as replacement patterns: <code>$&amp;</code>
re-inserted the <code>$t(...)</code> match, <code>$`</code> /
<code>$'</code> inserted the text before / after it, and <code>$$</code>
collapsed to <code>$</code>. Through <code>t()</code> the
<code>$&amp;</code> case was worse than a wrong string: the nested
lookup resets the shared nesting regexp, so the re-inserted
<code>$t(...)</code> was matched again on every pass and
<code>t()</code> never returned — also under the default
<code>escapeValue: true</code> when the value arrives via a variable
forwarded through nesting options (<code>$t(key, { &quot;name&quot;:
&quot;{{name}}&quot; })</code> with a name containing
<code>$&amp;</code>). The value is now <code>$</code>-escaped at the
<code>String.replace</code> call, the same guard
<code>interpolate()</code> already has, and a non-string value returned
by a formatter in the nesting chain (<code>$t(key, myFormat)</code>) is
stringified before that. Nested values are still not HTML-escaped (<a
href="https://redirect.github.com/i18next/i18next/issues/854">#854</a>).
Thanks <a href="https://github.com/mahirhir"><code>@​mahirhir</code></a>
(<a
href="https://redirect.github.com/i18next/i18next/pull/2447">#2447</a>).</li>
</ul>
<h2>v26.4.1</h2>
<ul>
<li>fix(types): the selector-form <code>keyPrefix</code> overload of
<code>getFixedT()</code> is now available under <code>enableSelector:
'strict'</code>. Its constraint was gated on <code>true |
'optimize'</code> only, so under <code>'strict'</code> it collapsed to
<code>never</code>, the overload dropped out, and the returned
<code>t</code> silently lost its <code>keyPrefix</code> scope
(<code>t(($) =&gt; $.deep)</code> failed with <code>Property 'deep' does
not exist on type '{}'</code>). The same call already typechecked under
<code>true</code> and <code>'optimize'</code>. Thanks <a
href="https://github.com/hovelopin"><code>@​hovelopin</code></a> (<a
href="https://redirect.github.com/i18next/i18next/pull/2446">#2446</a>).</li>
</ul>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/i18next/i18next/blob/master/CHANGELOG.md">i18next's
changelog</a>.</em></p>
<blockquote>
<h2>26.4.2</h2>
<ul>
<li>fix: <code>$&amp;</code>, <code>$`</code>, <code>$'</code> and
<code>$$</code> inside a nested value (<code>$t(key)</code>) now stay
literal. <code>nest()</code> handed the resolved value straight to
<code>String.replace</code> as the replacement argument, so those
sequences were read as replacement patterns: <code>$&amp;</code>
re-inserted the <code>$t(...)</code> match, <code>$`</code> /
<code>$'</code> inserted the text before / after it, and <code>$$</code>
collapsed to <code>$</code>. Through <code>t()</code> the
<code>$&amp;</code> case was worse than a wrong string: the nested
lookup resets the shared nesting regexp, so the re-inserted
<code>$t(...)</code> was matched again on every pass and
<code>t()</code> never returned — also under the default
<code>escapeValue: true</code> when the value arrives via a variable
forwarded through nesting options (<code>$t(key, { &quot;name&quot;:
&quot;{{name}}&quot; })</code> with a name containing
<code>$&amp;</code>). The value is now <code>$</code>-escaped at the
<code>String.replace</code> call, the same guard
<code>interpolate()</code> already has, and a non-string value returned
by a formatter in the nesting chain (<code>$t(key, myFormat)</code>) is
stringified before that. Nested values are still not HTML-escaped (<a
href="https://redirect.github.com/i18next/i18next/issues/854">#854</a>).
Thanks <a href="https://github.com/mahirhir"><code>@​mahirhir</code></a>
(<a
href="https://redirect.github.com/i18next/i18next/pull/2447">#2447</a>).</li>
</ul>
<h2>26.4.1</h2>
<ul>
<li>fix(types): the selector-form <code>keyPrefix</code> overload of
<code>getFixedT()</code> is now available under <code>enableSelector:
'strict'</code>. Its constraint was gated on <code>true |
'optimize'</code> only, so under <code>'strict'</code> it collapsed to
<code>never</code>, the overload dropped out, and the returned
<code>t</code> silently lost its <code>keyPrefix</code> scope
(<code>t(($) =&gt; $.deep)</code> failed with <code>Property 'deep' does
not exist on type '{}'</code>). The same call already typechecked under
<code>true</code> and <code>'optimize'</code>. Thanks <a
href="https://github.com/hovelopin"><code>@​hovelopin</code></a> (<a
href="https://redirect.github.com/i18next/i18next/pull/2446">#2446</a>).</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/i18next/i18next/commit/4dba50f20669c3678db0812255716eb7693ad2da"><code>4dba50f</code></a>
26.4.2</li>
<li><a
href="https://github.com/i18next/i18next/commit/e436b625a648e1a48ea27ecf5f2fba8020d67009"><code>e436b62</code></a>
build</li>
<li><a
href="https://github.com/i18next/i18next/commit/d955fb086e9f4ded1200f51ecbb21034dbad1d92"><code>d955fb0</code></a>
fix: stringify formatter results in nested values, changelog
v26.4.2</li>
<li><a
href="https://github.com/i18next/i18next/commit/dfafa3ca725e1415ef20e7fb5b1b3e4468f3c425"><code>dfafa3c</code></a>
fix: keep replacement patterns literal in nested values (<a
href="https://redirect.github.com/i18next/i18next/issues/2447">#2447</a>)</li>
<li><a
href="https://github.com/i18next/i18next/commit/3c9981e22dd471b6bca224aa1f60e04ba3f6153a"><code>3c9981e</code></a>
chore: keep dev-only and local files out of the npm package</li>
<li><a
href="https://github.com/i18next/i18next/commit/c057ee048c55a61c095acc017365e997e4f723f8"><code>c057ee0</code></a>
26.4.1</li>
<li><a
href="https://github.com/i18next/i18next/commit/02e3e1659b7cc9fedaaf53797597483ef8003df2"><code>02e3e16</code></a>
changelog v26.4.1</li>
<li><a
href="https://github.com/i18next/i18next/commit/6f198f2508ba8986d1bbf25a8b922d01afcf0751"><code>6f198f2</code></a>
fix(types): allow selector keyPrefix in getFixedT under enableSelector
'stric...</li>
<li>See full diff in <a
href="https://github.com/i18next/i18next/compare/v26.4.0...v26.4.2">compare
view</a></li>
</ul>
</details>
<br />

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
canary/v2026.1002.0-canary.3
2026-10-01 19:58:00 -07:00
dependabot[bot] b31ce54b81 build(deps): bump react-router-dom from 7.18.2 to 7.18.4 (#12974)
Bumps
[react-router-dom](https://github.com/remix-run/react-router/tree/HEAD/packages/react-router-dom)
from 7.18.2 to 7.18.4.
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/remix-run/react-router/blob/react-router-dom@7.18.4/packages/react-router-dom/CHANGELOG.md">react-router-dom's
changelog</a>.</em></p>
<blockquote>
<h2>v7.18.4</h2>
<h3>Patch Changes</h3>
<ul>
<li>Updated dependencies:
<ul>
<li><a
href="https://github.com/remix-run/react-router/releases/tag/react-router@7.18.4"><code>react-router@7.18.4</code></a></li>
</ul>
</li>
</ul>
<h2>v7.18.3</h2>
<h3>Patch Changes</h3>
<ul>
<li>Updated dependencies:
<ul>
<li><a
href="https://github.com/remix-run/react-router/releases/tag/react-router@7.18.3"><code>react-router@7.18.3</code></a></li>
</ul>
</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/remix-run/react-router/commit/1b1e0b0e79b21692ce907933475233babdd16e3e"><code>1b1e0b0</code></a>
Release v7.18.4 (<a
href="https://github.com/remix-run/react-router/tree/HEAD/packages/react-router-dom/issues/15498">#15498</a>)</li>
<li><a
href="https://github.com/remix-run/react-router/commit/23166dfe7f61323f0d2775af67d2691f9ed0843d"><code>23166df</code></a>
Release v7.18.3 (<a
href="https://github.com/remix-run/react-router/tree/HEAD/packages/react-router-dom/issues/15424">#15424</a>)</li>
<li>See full diff in <a
href="https://github.com/remix-run/react-router/commits/react-router-dom@7.18.4/packages/react-router-dom">compare
view</a></li>
</ul>
</details>
<br />

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-10-01 19:29:44 -07:00
Devin FoleyandPaperclip 4a999089ef Retry transient failures in dashboard reads (#14873)
## Thinking Path

> - Paperclip shows company activity in the dashboard.
> - The dashboard reads company, task, approval, and cost data.
> - A pooled database connection can close during one of these reads.
> - The driver must reject ambiguous statements because writes may have
committed.
> - These four dashboard queries are known to be read-only.
> - This change retries only the failed read and preserves completed
work.

## Linked Issues or Issue Description

Refs #14773, which correctly removed automatic replay of ambiguous
database statements. Searched existing database and dashboard PRs.
Related #8780 changes pool recycling and logging; #13925 adds dashboard
consistency coverage. Neither provides these per-query retries.

**What happened?**

A dashboard request returns a server error when its company lookup, task
count, approval count, or monthly spend query loses its database
connection. Drizzle wraps the driver's connection error in `cause`.

**Expected behavior**

A transient connection failure gets a bounded retry of the specific
read. Completed reads and budget processing are not replayed. Persistent
outages and non-connection errors still fail the request.

**Steps to reproduce**

Inject a typed `CONNECTION_CLOSED` error into one of these reads. Then
allow the next query to succeed. Before this change, the dashboard
request fails immediately.

## What Changed

- Apply independent retries to the company lookup, task counts, pending
approval count, and monthly spend query. Each callback rebuilds its own
query with the same company scope.
- Extract the existing authentication retry helper as
`retryIdempotentDatabaseOperation`. Preserve authentication behavior and
its existing exports.
- Retain the existing limit of three total attempts with 50 ms and 100
ms pauses. Match typed connection codes through the error cause chain.
- Test later-read failures, unchanged query parameters, retry
exhaustion, missing companies, and errors that must not retry. Document
the boundary.

## Verification

- Final focused dashboard, authentication, and real database wire
suites: 38 tests passed. Six initial recovery regressions failed before
the implementation.
- `pnpm -r typecheck`: passed on the final source.
- Independent review: no actionable findings. The reviewer separately
passed all 38 focused tests and checked the code allowlist, attempt
bounds, pauses, and final error identity.
- `pnpm test:run`: the general-server group completed with 14,738 tests
passed, 13 failed, and 87 skipped. All 13 failures match the previously
reproduced clean-base macOS skill-cache failures. The two test files and
their implementations are unchanged from that baseline. The runner
exited after this group, so the remaining local workspace and serialized
groups did not run. All corresponding Linux CI groups passed on this
commit.
- `pnpm build`: passed on the final source.
- Full CI: 53 successful checks and 2 skips on `6a113529c0`. Greptile:
5/5 on that commit, with no review threads or remaining findings.
- Merge compatibility with master `f2e0f19630`, including #14866: no
conflicts. The five reviewed files are unchanged in the resulting merge
tree.

## Risks

A persistent outage adds at most two retries per covered query. Each
connection attempt retains the configured driver timeout. The change
does not repair the underlying network or database failure. Agent
counts, run-activity queries, and the budget workflow stay outside these
retry boundaries. General database statements and disconnected
transactions are not replayed. There is no schema or authorization
change.

## Model Used

OpenAI GPT-6 through Codex, with reasoning, repository inspection, code
editing, and test execution. The runtime does not expose a more specific
serving model identifier or context-window size.

## Checklist

- [x] I have included a thinking path that traces from project context
to this change
- [x] I have specified the model used (with version and capability
details)
- [x] I have checked ROADMAP.md and confirmed this PR does not duplicate
planned core work
- [x] I have searched GitHub for duplicate or related PRs and linked
them above
- [x] I have either (a) linked existing issues with `Fixes: #` / `Closes
#` / `Refs #` OR (b) described the issue in-PR following the relevant
issue template
- [x] I have not referenced internal/instance-local Paperclip issues or
links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip`
URLs)
- [x] My branch name describes the change and contains no internal
Paperclip ticket id or instance-derived details
- [x] I have run tests locally and they pass (38 focused tests; the full
local run has the baseline limitation documented above)
- [x] I have added or updated tests where applicable
- [x] I have updated relevant documentation to reflect my changes
- [x] I have considered and documented any risks above
- [x] All Paperclip CI gates are green
- [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups
- [x] I will address all Greptile and reviewer comments before
requesting merge

Co-authored-by: Paperclip <noreply@paperclip.ing>
2026-10-01 19:23:47 -07:00
dependabot[bot] 40c8468e98 build(deps-dev): bump agentmail from 0.5.20 to 0.5.31 (#12975)
Bumps [agentmail](https://github.com/agentmail-to/agentmail-node) from
0.5.20 to 0.5.31.
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/agentmail-to/agentmail-node/commit/be477c3e9d07de608d94daa3f2235c46456758ad"><code>be477c3</code></a>
Release 0.5.31</li>
<li><a
href="https://github.com/agentmail-to/agentmail-node/commit/553d6a62e10a95c73a87d47b8b1125f716dfb1f2"><code>553d6a6</code></a>
Release 0.5.30</li>
<li><a
href="https://github.com/agentmail-to/agentmail-node/commit/a53948be57e396a8d08344e9d43ee191ae747fd9"><code>a53948b</code></a>
Release 0.5.29</li>
<li><a
href="https://github.com/agentmail-to/agentmail-node/commit/f2b4bb9a452a7343dc0eb6f20a07882d7364b211"><code>f2b4bb9</code></a>
Release 0.5.28</li>
<li><a
href="https://github.com/agentmail-to/agentmail-node/commit/d2c56f73735ed917961e1a16273a9320de6c21cd"><code>d2c56f7</code></a>
Release 0.5.27</li>
<li><a
href="https://github.com/agentmail-to/agentmail-node/commit/df2a12427b4e988024787167e6732bd1d1c5b9ff"><code>df2a124</code></a>
Release 0.5.26</li>
<li><a
href="https://github.com/agentmail-to/agentmail-node/commit/4ae0b9b2eeda5c65beb9fa4a3601a1a44f10947d"><code>4ae0b9b</code></a>
Release 0.5.25</li>
<li><a
href="https://github.com/agentmail-to/agentmail-node/commit/dc085581668947a177f5a087c4f78cf1b75dd2e8"><code>dc08558</code></a>
Release 0.5.24</li>
<li><a
href="https://github.com/agentmail-to/agentmail-node/commit/47210d91803f65b2ebf9ec8d1ae546a050e3d8bc"><code>47210d9</code></a>
Release 0.5.23</li>
<li><a
href="https://github.com/agentmail-to/agentmail-node/commit/0c5f98ff97a492ab77e9c688d3374548d9dd997a"><code>0c5f98f</code></a>
Release 0.5.22</li>
<li>Additional commits viewable in <a
href="https://github.com/agentmail-to/agentmail-node/compare/0.5.20...0.5.31">compare
view</a></li>
</ul>
</details>
<br />

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
canary/v2026.1002.0-canary.2
2026-10-01 19:09:03 -07:00
427e048405 fix(company-skills): approve managed-checkout project dirs for local skill import (#10329)
## Thinking Path

> - Paperclip is the open source app people use to manage AI agents for
work
> - Company skills can be imported into a company from a local folder;
`companySkillService.importFromSource` guards this with
`assertLocalImportSourceAllowed`, which only permits import sources
inside an approved set of roots (managed skills root + registered
project-workspace cwds), realpath-resolved and `${root}${sep}`-anchored
to prevent path traversal/escape
> - A project can exist as a `managed_checkout` (server-managed clone)
with **no registered `project_workspaces` row** — its `primaryWorkspace`
is `null` and `workspaces` is `[]`, so its only real on-disk location is
the server-derived `codebase.managedFolder`
> - Because `configuredRoots` was built solely from the managed skills
root and `workspaces[].cwd`, a `managed_checkout` project's
`managedFolder` was never an approved root, so importing a skill from
that project's own folder was rejected with
`skill_workspace_boundary_denied`
> - This PR adds each project's server-derived `codebase.managedFolder`
to `configuredRoots` so in-place skill imports from managed-checkout
projects are allowed
> - The benefit is that managed-checkout projects can re-import their
own skills in place, without weakening the traversal/escape protections
(the new roots are server-derived and matched exactly like the existing
ones)

## Linked Issues or Issue Description

No public GitHub issue. Describing in-PR (bug):

**What's wrong:** `assertLocalImportSourceAllowed` denies a legitimate
local skill import (`skill_workspace_boundary_denied`) for any project
that is a `managed_checkout` with no registered workspace row.

**Repro:** Create/import a company skill from a `managed_checkout`
project's own folder (`codebase.managedFolder/.agents/skills/<skill>`).
The import is rejected even though the source is inside the project's
server-managed checkout.

**Expected:** The import from a managed-checkout project's own
`managedFolder` subtree should be allowed, while paths outside that
subtree remain denied.

Related context (already merged): #9564 introduced the open-by-default
skill policy / this import boundary. This PR does not change that
boundary's matching logic — it only adds a missing, server-derived
approved root.

## What Changed

- `server/src/services/company-skills.ts`: add
`...projectRows.map((project) => project.codebase.managedFolder)` to
`configuredRoots` in `assertLocalImportSourceAllowed`. `managedFolder`
is server-derived (`resolveManagedProjectWorkspaceDir(companyId,
projectId)` → instance root + sanitized ids); it is
`fs.realpath`-resolved and `${root}${sep}`-prefix matched exactly like
every existing root. `managedFolder` is used rather than
`effectiveLocalFolder` because the latter can fall through to a
user-registered `localFolder`, which is already covered by the
registered workspace cwds.
- `server/src/__tests__/company-skill-import-boundary.test.ts`: add a
regression test — a managed-checkout project's `managedFolder/<skill>`
import is **allowed**, and a **prefix-adjacent sibling** (`managedFolder
+ "-evil"`) stays **denied**.

## Verification

- `cd server && ./node_modules/.bin/vitest run
src/__tests__/company-skill-import-boundary.test.ts` → **2/2 pass**
(embedded-Postgres suite). Covers both the new allow case and the
prefix-adjacent deny case, alongside the existing out-of-tree /
symlink-escape / non-file-scheme rejections.

## Risks

Low risk. The change only **adds** approved roots; it does not alter the
realpath + `${root}${sep}`-anchored matching that closes
traversal/prefix-adjacency escapes. The added roots are fully
server-derived from the instance root + sanitized company/project ids
(same trust class as the existing `resolveManagedSkillsRoot`) — no value
derived from the import `source` argument reaches them. Sanitization
(`[^a-zA-Z0-9._-]+ → -`) prevents separator/level injection, and the
only user-influenced segment (repo name) is normalized via `new
URL(...)`. The regression test's prefix-adjacent (`-evil`) case asserts
the escape class stays closed.

## Model Used

Claude Opus 4.8 (`claude-opus-4-8`), extended thinking + tool use (code
execution, git). Implementation and security review were produced with
Claude; this integration/PR was prepared with `claude-opus-4-8`.

## Checklist

- [x] I have included a thinking path that traces from project context
to this change
- [x] I have specified the model used (with version and capability
details)
- [x] I have checked ROADMAP.md and confirmed this PR does not duplicate
planned core work
- [x] I have searched GitHub for duplicate or related PRs and linked
them above
- [x] I have either (a) linked existing issues with `Fixes: #` / `Closes
#` / `Refs #` OR (b) described the issue in-PR following the relevant
issue template
- [x] I have not referenced internal/instance-local Paperclip issues or
links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip`
URLs)
- [x] My branch name describes the change (e.g. `docs/...`, `fix/...`)
and contains no internal Paperclip ticket id or instance-derived details
- [x] I have run tests locally and they pass
- [x] I have added or updated tests where applicable
- [ ] I have updated relevant documentation to reflect my changes (N/A —
internal boundary fix, no user-facing docs)
- [x] I have considered and documented any risks above
- [ ] All Paperclip CI gates are green (CI in progress)
- [ ] Greptile is 5/5 with no open P2s, recommendations, or follow-ups
(pending review)
- [x] I will address all Greptile and reviewer comments before
requesting merge

Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
Co-authored-by: brandonburr <brandonburr@gmail.com>
canary/v2026.1002.0-canary.1
2026-10-01 17:34:51 -07:00
5207c78f21 docs(release): align 2026.921.0-beta.1 stable notes header with v2026.1001.0 (#14882)
## Thinking Path

> - Paperclip is the open source app people use to manage AI agents for
work
> - Releases are published by `release.yml`. A stable release promotes a
soaked beta, and the stable notes live on master in
`releases/beta/v<beta>.md` until the promotion runs.
> - The curated notes for `2026.921.0-beta.1` have the title `Paperclip
v2026.924.0` and the date `2026-09-24`. That stable did not ship. No
`v2026.924.0` tag or release exists.
> - The next promotion of this beta uses `stable_date=2026-10-01`.
`scripts/release.sh stable --print-version --date 2026-10-01` resolves
to `2026.1001.0`.
> - `publish_stable` reads this file verbatim and uses it as the GitHub
Release body. `canonicalize_stable_notes` copies it to
`releases/v2026.1001.0.md`. Nothing rewrites the header.
> - This pull request updates the title, the release date, and the intro
sentence to `v2026.1001.0` and `2026-10-01`.
> - The benefit is a GitHub Release page and a canonical notes file that
show the correct version and date.

## Linked Issues or Issue Description

**Describe the documentation problem**

The stable notes file `releases/beta/v2026.921.0-beta.1.md` names a
stable version and release date that do not match the version the
release workflow will publish.

**Where is the problem**

`releases/beta/v2026.921.0-beta.1.md`, lines 1, 3, and 5.

**Proposed fix**

Change `v2026.924.0` to `v2026.1001.0` and `2026-09-24` to `2026-10-01`
in the three places that name the version or date. Change nothing else
in the file.

## What Changed

- Title: `# Paperclip v2026.924.0` → `# Paperclip v2026.1001.0`
- Release date: `> Released: 2026-09-24` → `> Released: 2026-10-01`
- Intro sentence: `Paperclip v2026.924.0 carries 77 commits` →
`Paperclip v2026.1001.0 carries 77 commits`

## Verification

- `git diff master --stat` shows one file with 3 insertions and 3
deletions.
- `grep -n '924' releases/beta/v2026.921.0-beta.1.md` returns no lines.
- `git show master:scripts/release.sh > /tmp/r.sh && bash /tmp/r.sh
stable --print-version --date 2026-10-01` prints `2026.1001.0`.
- The rest of the file is byte-identical to master.

## Risks

- Low risk. This is a documentation-only change to a release notes file.
No code or workflow changes.
- If the stable promotion is dispatched with a different `stable_date`,
the header must be updated again to match.

## Model Used

- Claude Fable 5.1 (model ID `claude-fable-5-1`), run as a Paperclip
agent through the Claude Agent SDK, with tool use (shell, git, GitHub
CLI). No extended thinking mode was configured beyond the default.

## Checklist

- [x] I have included a thinking path that traces from project context
to this change
- [x] I have specified the model used (with version and capability
details)
- [x] I have checked ROADMAP.md and confirmed this PR does not duplicate
planned core work
- [x] I have searched GitHub for duplicate or related PRs and linked
them above
- [x] I have either (a) linked existing issues with `Fixes: #` / `Closes
#` / `Refs #` OR (b) described the issue in-PR following the relevant
issue template
- [x] I have not referenced internal/instance-local Paperclip issues or
links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip`
URLs)
- [x] My branch name describes the change (e.g. `docs/...`, `fix/...`)
and contains no internal Paperclip ticket id or instance-derived details
- [x] I have run tests locally and they pass
- [ ] I have added or updated tests where applicable (not applicable:
documentation-only change)
- [x] I have updated relevant documentation to reflect my changes
- [x] I have considered and documented any risks above
- [ ] All Paperclip CI gates are green
- [ ] Greptile is 5/5 with no open P2s, recommendations, or follow-ups
- [x] I will address all Greptile and reviewer comments before
requesting merge

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-authored-by: Bender (Fable) <noreply@paperclip.ing>
Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com>
canary/v2026.1002.0-canary.0
2026-10-01 17:28:00 -07:00
dependabot[bot] f07f8d9599 build(deps-dev): bump @storybook/addon-a11y from 10.5.10 to 10.6.0 (#12976)
Bumps
[@storybook/addon-a11y](https://github.com/storybookjs/storybook/tree/HEAD/code/addons/a11y)
from 10.5.10 to 10.6.0.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/storybookjs/storybook/releases">@​storybook/addon-a11y's
releases</a>.</em></p>
<blockquote>
<h2>v10.6.0</h2>
<h2>10.6.0</h2>
<blockquote>
<p>New skills architecture for agentic workflows</p>
</blockquote>
<p>Storybook 10.6 contains hundreds of fixes and improvements:</p>
<ul>
<li>💻 CLI bindings for agent tools/skills</li>
<li>🅰️ Angular-Vite MCP/skills support and improved docgen/snippets
(experimental)</li>
<li>🟢 Vue MCP/skills support and improved docgen/snippets
(experimental)</li>
<li>🧩 Tanstack / NextJS-Vite framework bugfixes</li>
<li>⚡ Improved performance and reduced bundle size</li>
</ul>
<!-- raw HTML omitted -->
<ul>
<li>Addon MCP: Stop silently dropping composed refs from MCP composition
- <a
href="https://redirect.github.com/storybookjs/storybook/pull/36077">#36077</a>,
thanks <a
href="https://github.com/kasperpeulen"><code>@​kasperpeulen</code></a>!</li>
<li>Addon Vitest: Pin storybook/test in optimizeDeps so its CJS-only
deps are prebundled - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35572">#35572</a>,
thanks <a
href="https://github.com/Nic-Polumeyv"><code>@​Nic-Polumeyv</code></a>!</li>
<li>Addon Vitest: Report test runs with failures as failed tool outcomes
- <a
href="https://redirect.github.com/storybookjs/storybook/pull/36080">#36080</a>,
thanks <a
href="https://github.com/kasperpeulen"><code>@​kasperpeulen</code></a>!</li>
<li>Addon Vitest: Resolve story test globs against the project root - <a
href="https://redirect.github.com/storybookjs/storybook/pull/36103">#36103</a>,
thanks <a
href="https://github.com/kasperpeulen"><code>@​kasperpeulen</code></a>!</li>
<li>Addon-vitest: Filter Storybook instrumentation from reported stack
traces - <a
href="https://redirect.github.com/storybookjs/storybook/pull/36120">#36120</a>,
thanks <a
href="https://github.com/ghengeveld"><code>@​ghengeveld</code></a>!</li>
<li>Angular Vite: Resolve tsConfig against the workspace root - <a
href="https://redirect.github.com/storybookjs/storybook/pull/36026">#36026</a>,
thanks <a
href="https://github.com/ndelangen"><code>@​ndelangen</code></a>!</li>
<li>Angular-Vite: Run Compodoc on demand - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35776">#35776</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Add an in-process docgen analyzer, replacing Compodoc under
the flag - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35805">#35805</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Bind only what the component accepts in story snippets, and
report the rest - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35943">#35943</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Decide the migration's zone.js import from the dependency
tree - <a
href="https://redirect.github.com/storybookjs/storybook/pull/36008">#36008</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Declare story args the snippet markup binds by name - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35895">#35895</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Declare style preprocessors as optional peers and name the
missing one - <a
href="https://redirect.github.com/storybookjs/storybook/pull/36098">#36098</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Derive required inputs from Compodoc's own flag - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35758">#35758</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Extract Compodoc parsing into its own package - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35749">#35749</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Extract component JSDoc through TypeScript's APIs - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35977">#35977</a>,
thanks <a
href="https://github.com/huang-julien"><code>@​huang-julien</code></a>!</li>
<li>Angular: Extract docgen on the server via Compodoc - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35733">#35733</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Fix component resolution, MCP output, and dev/build path
aliasing - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35952">#35952</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Fix eight upgrade and migration bugs - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35946">#35946</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Fix ten docgen bugs found across 22 community repositories
- <a
href="https://redirect.github.com/storybookjs/storybook/pull/35941">#35941</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Generate story-docs snippets from the analyzer - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35807">#35807</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Give agents real input and output documentation - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35896">#35896</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Hide class internals from the props table by default - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35887">#35887</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Install the `@storybook/angular-vite` peers that nothing
else brings in - <a
href="https://redirect.github.com/storybookjs/storybook/pull/36002">#36002</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Keep the function control on constructor and generic
signatures - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35921">#35921</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Make experimentalDocgenServer the default in angular-vite -
<a
href="https://redirect.github.com/storybookjs/storybook/pull/35886">#35886</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Migrate Analog projects to angular-vite instead of refusing
them - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35971">#35971</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Print unevaluable story args instead of slicing the file -
<a
href="https://redirect.github.com/storybookjs/storybook/pull/35888">#35888</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Read the story shapes that supply their own markup - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35797">#35797</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Render self-closing tags in server-side docs snippets - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35953">#35953</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Render the required badge for required inputs in the props
table - <a
href="https://redirect.github.com/storybookjs/storybook/pull/36065">#36065</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Resolve `@angular/core` through the package manager, not
the raw specifier - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35999">#35999</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Resolve builder `styles` the way the Angular builders do -
<a
href="https://redirect.github.com/storybookjs/storybook/pull/35998">#35998</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Resolve builder styles against the workspace root - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35974">#35974</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Skip the runtime source decorator when the docgen server
produces snippets - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35906">#35906</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/storybookjs/storybook/blob/next/CHANGELOG.md">@​storybook/addon-a11y's
changelog</a>.</em></p>
<blockquote>
<h2>10.6.0</h2>
<blockquote>
<p>New skills architecture for agentic workflows</p>
</blockquote>
<p>Storybook 10.6 contains hundreds of fixes and improvements:</p>
<ul>
<li>💻 CLI bindings for agent tools/skills</li>
<li>🅰️ Angular-Vite MCP/skills support and improved docgen/snippets
(experimental)</li>
<li>🟢 Vue MCP/skills support and improved docgen/snippets
(experimental)</li>
<li>🧩 Tanstack / NextJS-Vite framework bugfixes</li>
<li>⚡ Improved performance and reduced bundle size</li>
</ul>
<!-- raw HTML omitted -->
<ul>
<li>Addon MCP: Stop silently dropping composed refs from MCP composition
- <a
href="https://redirect.github.com/storybookjs/storybook/pull/36077">#36077</a>,
thanks <a
href="https://github.com/kasperpeulen"><code>@​kasperpeulen</code></a>!</li>
<li>Addon Vitest: Pin storybook/test in optimizeDeps so its CJS-only
deps are prebundled - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35572">#35572</a>,
thanks <a
href="https://github.com/Nic-Polumeyv"><code>@​Nic-Polumeyv</code></a>!</li>
<li>Addon Vitest: Report test runs with failures as failed tool outcomes
- <a
href="https://redirect.github.com/storybookjs/storybook/pull/36080">#36080</a>,
thanks <a
href="https://github.com/kasperpeulen"><code>@​kasperpeulen</code></a>!</li>
<li>Addon Vitest: Resolve story test globs against the project root - <a
href="https://redirect.github.com/storybookjs/storybook/pull/36103">#36103</a>,
thanks <a
href="https://github.com/kasperpeulen"><code>@​kasperpeulen</code></a>!</li>
<li>Addon-vitest: Filter Storybook instrumentation from reported stack
traces - <a
href="https://redirect.github.com/storybookjs/storybook/pull/36120">#36120</a>,
thanks <a
href="https://github.com/ghengeveld"><code>@​ghengeveld</code></a>!</li>
<li>Angular Vite: Resolve tsConfig against the workspace root - <a
href="https://redirect.github.com/storybookjs/storybook/pull/36026">#36026</a>,
thanks <a
href="https://github.com/ndelangen"><code>@​ndelangen</code></a>!</li>
<li>Angular-Vite: Run Compodoc on demand - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35776">#35776</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Add an in-process docgen analyzer, replacing Compodoc under
the flag - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35805">#35805</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Bind only what the component accepts in story snippets, and
report the rest - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35943">#35943</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Decide the migration's zone.js import from the dependency
tree - <a
href="https://redirect.github.com/storybookjs/storybook/pull/36008">#36008</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Declare story args the snippet markup binds by name - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35895">#35895</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Declare style preprocessors as optional peers and name the
missing one - <a
href="https://redirect.github.com/storybookjs/storybook/pull/36098">#36098</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Derive required inputs from Compodoc's own flag - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35758">#35758</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Extract Compodoc parsing into its own package - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35749">#35749</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Extract component JSDoc through TypeScript's APIs - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35977">#35977</a>,
thanks <a
href="https://github.com/huang-julien"><code>@​huang-julien</code></a>!</li>
<li>Angular: Extract docgen on the server via Compodoc - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35733">#35733</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Fix component resolution, MCP output, and dev/build path
aliasing - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35952">#35952</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Fix eight upgrade and migration bugs - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35946">#35946</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Fix ten docgen bugs found across 22 community repositories
- <a
href="https://redirect.github.com/storybookjs/storybook/pull/35941">#35941</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Generate story-docs snippets from the analyzer - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35807">#35807</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Give agents real input and output documentation - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35896">#35896</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Hide class internals from the props table by default - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35887">#35887</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Install the <code>@storybook/angular-vite</code> peers that
nothing else brings in - <a
href="https://redirect.github.com/storybookjs/storybook/pull/36002">#36002</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Keep the function control on constructor and generic
signatures - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35921">#35921</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Make experimentalDocgenServer the default in angular-vite -
<a
href="https://redirect.github.com/storybookjs/storybook/pull/35886">#35886</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Migrate Analog projects to angular-vite instead of refusing
them - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35971">#35971</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Print unevaluable story args instead of slicing the file -
<a
href="https://redirect.github.com/storybookjs/storybook/pull/35888">#35888</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Read the story shapes that supply their own markup - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35797">#35797</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Render self-closing tags in server-side docs snippets - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35953">#35953</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Render the required badge for required inputs in the props
table - <a
href="https://redirect.github.com/storybookjs/storybook/pull/36065">#36065</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Resolve <code>@angular/core</code> through the package
manager, not the raw specifier - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35999">#35999</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Resolve builder <code>styles</code> the way the Angular
builders do - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35998">#35998</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Resolve builder styles against the workspace root - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35974">#35974</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Skip the runtime source decorator when the docgen server
produces snippets - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35906">#35906</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Stop marking a defaulted input as required in the props
table - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35899">#35899</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/storybookjs/storybook/commit/a77777356be2aeaff89d7a2b25254db7b2318392"><code>a777773</code></a>
Bump version from &quot;10.6.0-beta.3&quot; to &quot;10.6.0&quot; [skip
ci]</li>
<li><a
href="https://github.com/storybookjs/storybook/commit/f32b3667dad8df220cda0359e170bc49931af68c"><code>f32b366</code></a>
Bump version from &quot;10.6.0-beta.2&quot; to &quot;10.6.0-beta.3&quot;
[skip ci]</li>
<li><a
href="https://github.com/storybookjs/storybook/commit/0ad1336cbf0ecdab9f6b540570ae9015ae73ab86"><code>0ad1336</code></a>
Bump version from &quot;10.6.0-beta.1&quot; to &quot;10.6.0-beta.2&quot;
[skip ci]</li>
<li><a
href="https://github.com/storybookjs/storybook/commit/16359ee17802628c47915c21408cb578d2707b83"><code>16359ee</code></a>
Bump version from &quot;10.6.0-beta.0&quot; to &quot;10.6.0-beta.1&quot;
[skip ci]</li>
<li><a
href="https://github.com/storybookjs/storybook/commit/2e0e2f609d1351ba4384eb52e0728dc9cd8b275b"><code>2e0e2f6</code></a>
Bump version from &quot;10.6.0-alpha.9&quot; to
&quot;10.6.0-beta.0&quot; [skip ci]</li>
<li><a
href="https://github.com/storybookjs/storybook/commit/6a6dec2aedff6744a9d9226e1f6515e3d5e8b42a"><code>6a6dec2</code></a>
Bump version from &quot;10.6.0-alpha.8&quot; to
&quot;10.6.0-alpha.9&quot; [skip ci]</li>
<li><a
href="https://github.com/storybookjs/storybook/commit/cd2d16395a5ffa39189b96aafb6af67f280079db"><code>cd2d163</code></a>
Bump version from &quot;10.6.0-alpha.7&quot; to
&quot;10.6.0-alpha.8&quot; [skip ci]</li>
<li><a
href="https://github.com/storybookjs/storybook/commit/898f0ce828ec8bd00985934786724b94f8428c42"><code>898f0ce</code></a>
Bump version from &quot;10.6.0-alpha.6&quot; to
&quot;10.6.0-alpha.7&quot; [skip ci]</li>
<li><a
href="https://github.com/storybookjs/storybook/commit/cf97b46ca1a452f6f47206fd6ed7043a88e38a60"><code>cf97b46</code></a>
Bump version from &quot;10.6.0-alpha.5&quot; to
&quot;10.6.0-alpha.6&quot; [skip ci]</li>
<li><a
href="https://github.com/storybookjs/storybook/commit/2b7f6be9c96f72d6eca4b80af11db1a4ff380e8e"><code>2b7f6be</code></a>
Bump version from &quot;10.6.0-alpha.4&quot; to
&quot;10.6.0-alpha.5&quot; [skip ci]</li>
<li>Additional commits viewable in <a
href="https://github.com/storybookjs/storybook/commits/v10.6.0/code/addons/a11y">compare
view</a></li>
</ul>
</details>
<br />

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-10-01 17:08:56 -07:00
dependabot[bot] 41c18aa443 build(deps-dev): bump storybook from 10.5.10 to 10.6.0 (#12984)
Bumps
[storybook](https://github.com/storybookjs/storybook/tree/HEAD/code/core)
from 10.5.10 to 10.6.0.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/storybookjs/storybook/releases">storybook's
releases</a>.</em></p>
<blockquote>
<h2>v10.6.0</h2>
<h2>10.6.0</h2>
<blockquote>
<p>New skills architecture for agentic workflows</p>
</blockquote>
<p>Storybook 10.6 contains hundreds of fixes and improvements:</p>
<ul>
<li>💻 CLI bindings for agent tools/skills</li>
<li>🅰️ Angular-Vite MCP/skills support and improved docgen/snippets
(experimental)</li>
<li>🟢 Vue MCP/skills support and improved docgen/snippets
(experimental)</li>
<li>🧩 Tanstack / NextJS-Vite framework bugfixes</li>
<li>⚡ Improved performance and reduced bundle size</li>
</ul>
<!-- raw HTML omitted -->
<ul>
<li>Addon MCP: Stop silently dropping composed refs from MCP composition
- <a
href="https://redirect.github.com/storybookjs/storybook/pull/36077">#36077</a>,
thanks <a
href="https://github.com/kasperpeulen"><code>@​kasperpeulen</code></a>!</li>
<li>Addon Vitest: Pin storybook/test in optimizeDeps so its CJS-only
deps are prebundled - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35572">#35572</a>,
thanks <a
href="https://github.com/Nic-Polumeyv"><code>@​Nic-Polumeyv</code></a>!</li>
<li>Addon Vitest: Report test runs with failures as failed tool outcomes
- <a
href="https://redirect.github.com/storybookjs/storybook/pull/36080">#36080</a>,
thanks <a
href="https://github.com/kasperpeulen"><code>@​kasperpeulen</code></a>!</li>
<li>Addon Vitest: Resolve story test globs against the project root - <a
href="https://redirect.github.com/storybookjs/storybook/pull/36103">#36103</a>,
thanks <a
href="https://github.com/kasperpeulen"><code>@​kasperpeulen</code></a>!</li>
<li>Addon-vitest: Filter Storybook instrumentation from reported stack
traces - <a
href="https://redirect.github.com/storybookjs/storybook/pull/36120">#36120</a>,
thanks <a
href="https://github.com/ghengeveld"><code>@​ghengeveld</code></a>!</li>
<li>Angular Vite: Resolve tsConfig against the workspace root - <a
href="https://redirect.github.com/storybookjs/storybook/pull/36026">#36026</a>,
thanks <a
href="https://github.com/ndelangen"><code>@​ndelangen</code></a>!</li>
<li>Angular-Vite: Run Compodoc on demand - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35776">#35776</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Add an in-process docgen analyzer, replacing Compodoc under
the flag - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35805">#35805</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Bind only what the component accepts in story snippets, and
report the rest - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35943">#35943</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Decide the migration's zone.js import from the dependency
tree - <a
href="https://redirect.github.com/storybookjs/storybook/pull/36008">#36008</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Declare story args the snippet markup binds by name - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35895">#35895</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Declare style preprocessors as optional peers and name the
missing one - <a
href="https://redirect.github.com/storybookjs/storybook/pull/36098">#36098</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Derive required inputs from Compodoc's own flag - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35758">#35758</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Extract Compodoc parsing into its own package - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35749">#35749</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Extract component JSDoc through TypeScript's APIs - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35977">#35977</a>,
thanks <a
href="https://github.com/huang-julien"><code>@​huang-julien</code></a>!</li>
<li>Angular: Extract docgen on the server via Compodoc - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35733">#35733</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Fix component resolution, MCP output, and dev/build path
aliasing - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35952">#35952</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Fix eight upgrade and migration bugs - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35946">#35946</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Fix ten docgen bugs found across 22 community repositories
- <a
href="https://redirect.github.com/storybookjs/storybook/pull/35941">#35941</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Generate story-docs snippets from the analyzer - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35807">#35807</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Give agents real input and output documentation - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35896">#35896</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Hide class internals from the props table by default - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35887">#35887</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Install the `@storybook/angular-vite` peers that nothing
else brings in - <a
href="https://redirect.github.com/storybookjs/storybook/pull/36002">#36002</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Keep the function control on constructor and generic
signatures - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35921">#35921</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Make experimentalDocgenServer the default in angular-vite -
<a
href="https://redirect.github.com/storybookjs/storybook/pull/35886">#35886</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Migrate Analog projects to angular-vite instead of refusing
them - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35971">#35971</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Print unevaluable story args instead of slicing the file -
<a
href="https://redirect.github.com/storybookjs/storybook/pull/35888">#35888</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Read the story shapes that supply their own markup - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35797">#35797</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Render self-closing tags in server-side docs snippets - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35953">#35953</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Render the required badge for required inputs in the props
table - <a
href="https://redirect.github.com/storybookjs/storybook/pull/36065">#36065</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Resolve `@angular/core` through the package manager, not
the raw specifier - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35999">#35999</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Resolve builder `styles` the way the Angular builders do -
<a
href="https://redirect.github.com/storybookjs/storybook/pull/35998">#35998</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Resolve builder styles against the workspace root - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35974">#35974</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Skip the runtime source decorator when the docgen server
produces snippets - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35906">#35906</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/storybookjs/storybook/blob/next/CHANGELOG.md">storybook's
changelog</a>.</em></p>
<blockquote>
<h2>10.6.0</h2>
<blockquote>
<p>New skills architecture for agentic workflows</p>
</blockquote>
<p>Storybook 10.6 contains hundreds of fixes and improvements:</p>
<ul>
<li>💻 CLI bindings for agent tools/skills</li>
<li>🅰️ Angular-Vite MCP/skills support and improved docgen/snippets
(experimental)</li>
<li>🟢 Vue MCP/skills support and improved docgen/snippets
(experimental)</li>
<li>🧩 Tanstack / NextJS-Vite framework bugfixes</li>
<li>⚡ Improved performance and reduced bundle size</li>
</ul>
<!-- raw HTML omitted -->
<ul>
<li>Addon MCP: Stop silently dropping composed refs from MCP composition
- <a
href="https://redirect.github.com/storybookjs/storybook/pull/36077">#36077</a>,
thanks <a
href="https://github.com/kasperpeulen"><code>@​kasperpeulen</code></a>!</li>
<li>Addon Vitest: Pin storybook/test in optimizeDeps so its CJS-only
deps are prebundled - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35572">#35572</a>,
thanks <a
href="https://github.com/Nic-Polumeyv"><code>@​Nic-Polumeyv</code></a>!</li>
<li>Addon Vitest: Report test runs with failures as failed tool outcomes
- <a
href="https://redirect.github.com/storybookjs/storybook/pull/36080">#36080</a>,
thanks <a
href="https://github.com/kasperpeulen"><code>@​kasperpeulen</code></a>!</li>
<li>Addon Vitest: Resolve story test globs against the project root - <a
href="https://redirect.github.com/storybookjs/storybook/pull/36103">#36103</a>,
thanks <a
href="https://github.com/kasperpeulen"><code>@​kasperpeulen</code></a>!</li>
<li>Addon-vitest: Filter Storybook instrumentation from reported stack
traces - <a
href="https://redirect.github.com/storybookjs/storybook/pull/36120">#36120</a>,
thanks <a
href="https://github.com/ghengeveld"><code>@​ghengeveld</code></a>!</li>
<li>Angular Vite: Resolve tsConfig against the workspace root - <a
href="https://redirect.github.com/storybookjs/storybook/pull/36026">#36026</a>,
thanks <a
href="https://github.com/ndelangen"><code>@​ndelangen</code></a>!</li>
<li>Angular-Vite: Run Compodoc on demand - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35776">#35776</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Add an in-process docgen analyzer, replacing Compodoc under
the flag - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35805">#35805</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Bind only what the component accepts in story snippets, and
report the rest - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35943">#35943</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Decide the migration's zone.js import from the dependency
tree - <a
href="https://redirect.github.com/storybookjs/storybook/pull/36008">#36008</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Declare story args the snippet markup binds by name - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35895">#35895</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Declare style preprocessors as optional peers and name the
missing one - <a
href="https://redirect.github.com/storybookjs/storybook/pull/36098">#36098</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Derive required inputs from Compodoc's own flag - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35758">#35758</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Extract Compodoc parsing into its own package - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35749">#35749</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Extract component JSDoc through TypeScript's APIs - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35977">#35977</a>,
thanks <a
href="https://github.com/huang-julien"><code>@​huang-julien</code></a>!</li>
<li>Angular: Extract docgen on the server via Compodoc - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35733">#35733</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Fix component resolution, MCP output, and dev/build path
aliasing - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35952">#35952</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Fix eight upgrade and migration bugs - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35946">#35946</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Fix ten docgen bugs found across 22 community repositories
- <a
href="https://redirect.github.com/storybookjs/storybook/pull/35941">#35941</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Generate story-docs snippets from the analyzer - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35807">#35807</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Give agents real input and output documentation - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35896">#35896</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Hide class internals from the props table by default - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35887">#35887</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Install the <code>@storybook/angular-vite</code> peers that
nothing else brings in - <a
href="https://redirect.github.com/storybookjs/storybook/pull/36002">#36002</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Keep the function control on constructor and generic
signatures - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35921">#35921</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Make experimentalDocgenServer the default in angular-vite -
<a
href="https://redirect.github.com/storybookjs/storybook/pull/35886">#35886</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Migrate Analog projects to angular-vite instead of refusing
them - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35971">#35971</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Print unevaluable story args instead of slicing the file -
<a
href="https://redirect.github.com/storybookjs/storybook/pull/35888">#35888</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Read the story shapes that supply their own markup - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35797">#35797</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Render self-closing tags in server-side docs snippets - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35953">#35953</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Render the required badge for required inputs in the props
table - <a
href="https://redirect.github.com/storybookjs/storybook/pull/36065">#36065</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Resolve <code>@angular/core</code> through the package
manager, not the raw specifier - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35999">#35999</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Resolve builder <code>styles</code> the way the Angular
builders do - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35998">#35998</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Resolve builder styles against the workspace root - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35974">#35974</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Skip the runtime source decorator when the docgen server
produces snippets - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35906">#35906</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
<li>Angular: Stop marking a defaulted input as required in the props
table - <a
href="https://redirect.github.com/storybookjs/storybook/pull/35899">#35899</a>,
thanks <a
href="https://github.com/valentinpalkovic"><code>@​valentinpalkovic</code></a>!</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/storybookjs/storybook/commit/a77777356be2aeaff89d7a2b25254db7b2318392"><code>a777773</code></a>
Bump version from &quot;10.6.0-beta.3&quot; to &quot;10.6.0&quot; [skip
ci]</li>
<li><a
href="https://github.com/storybookjs/storybook/commit/f32b3667dad8df220cda0359e170bc49931af68c"><code>f32b366</code></a>
Bump version from &quot;10.6.0-beta.2&quot; to &quot;10.6.0-beta.3&quot;
[skip ci]</li>
<li><a
href="https://github.com/storybookjs/storybook/commit/db38cb39d9be5609bba4ac3b861b2263c21ae1b6"><code>db38cb3</code></a>
CLI: Serve skills through one path with a single expected-failure
channel</li>
<li><a
href="https://github.com/storybookjs/storybook/commit/79bc6a63e0ecd6eb10baecb6302661da09eea1f7"><code>79bc6a6</code></a>
CLI: Address review on skills reshape; credit skills --all in eval
parser</li>
<li><a
href="https://github.com/storybookjs/storybook/commit/c11b0f2a6eb1e15b489a8c0bc17c5eace4c8a8b5"><code>c11b0f2</code></a>
CLI: Drop per-skill --help; --help always prints the catalog</li>
<li><a
href="https://github.com/storybookjs/storybook/commit/c878263a6ced94ef30148b99758bea139122f5de"><code>c878263</code></a>
CLI: Drop skills get/list, add skills --all</li>
<li><a
href="https://github.com/storybookjs/storybook/commit/c55462ef810dcf5641636a54021861f5d1d90222"><code>c55462e</code></a>
Merge pull request <a
href="https://github.com/storybookjs/storybook/tree/HEAD/code/core/issues/36117">#36117</a>
from storybookjs/kasper/tools-record-storybook-path</li>
<li><a
href="https://github.com/storybookjs/storybook/commit/0ad1336cbf0ecdab9f6b540570ae9015ae73ab86"><code>0ad1336</code></a>
Bump version from &quot;10.6.0-beta.1&quot; to &quot;10.6.0-beta.2&quot;
[skip ci]</li>
<li><a
href="https://github.com/storybookjs/storybook/commit/8ad41c80847390d53af17342e33c94d0f87bb368"><code>8ad41c8</code></a>
CLI: Reject surplus skills arguments</li>
<li><a
href="https://github.com/storybookjs/storybook/commit/8d607e3b18731f63e09d23ad488623f0c01224bd"><code>8d607e3</code></a>
Tools: Match Storybook installations correctly on Windows</li>
<li>Additional commits viewable in <a
href="https://github.com/storybookjs/storybook/commits/v10.6.0/code/core">compare
view</a></li>
</ul>
</details>
<br />

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-10-01 16:32:07 -07:00
dependabot[bot] 67ebed8a52 build(deps): bump lucide-react from 1.45.0 to 1.48.0 (#12985)
Bumps
[lucide-react](https://github.com/lucide-icons/lucide/tree/HEAD/packages/lucide-react)
from 1.45.0 to 1.48.0.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/lucide-icons/lucide/releases">lucide-react's
releases</a>.</em></p>
<blockquote>
<h2>Version 1.48.0</h2>
<h2>What's Changed</h2>
<ul>
<li>feat(icons): added <code>briefcase-plus</code> icon by <a
href="https://github.com/tylerkade"><code>@​tylerkade</code></a> in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/4757">lucide-icons/lucide#4757</a></li>
<li>feat(icons): added <code>square-sparkles</code> icon by <a
href="https://github.com/nananecy"><code>@​nananecy</code></a> in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/3610">lucide-icons/lucide#3610</a></li>
<li>feat(icons): added <code>line-dot-left-horizontal</code> icon by <a
href="https://github.com/nathan-de-pachtere"><code>@​nathan-de-pachtere</code></a>
in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/3855">lucide-icons/lucide#3855</a></li>
<li>fix(packages/svelte,solid): fix shared type imports in Solid and
Svelte by <a
href="https://github.com/karsa-mistmere"><code>@​karsa-mistmere</code></a>
in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/4846">lucide-icons/lucide#4846</a></li>
<li>chore(deps-dev): bump react-native from 0.76.9 to 0.87.1 in the
react-native-deps group across 1 directory by <a
href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/4673">lucide-icons/lucide#4673</a></li>
<li>feat(packages): export __iconNode data across framework packages by
<a href="https://github.com/lx3133584"><code>@​lx3133584</code></a> in
<a
href="https://redirect.github.com/lucide-icons/lucide/pull/4761">lucide-icons/lucide#4761</a></li>
<li>fix(icons): Tweak <code>card-sim</code> chip by <a
href="https://github.com/danielbayley"><code>@​danielbayley</code></a>
in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/3649">lucide-icons/lucide#3649</a></li>
<li>feat(icons): added <code>line-dot-top-vertical</code> icon by <a
href="https://github.com/nathan-de-pachtere"><code>@​nathan-de-pachtere</code></a>
in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/3856">lucide-icons/lucide#3856</a></li>
<li>feat(icons): added <code>line-dot-bottom-vertical</code> icon by <a
href="https://github.com/nathan-de-pachtere"><code>@​nathan-de-pachtere</code></a>
in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/3857">lucide-icons/lucide#3857</a></li>
<li>fix(packages/react-native): pass testID to the rendered Svg element
by <a href="https://github.com/OlegBezr"><code>@​OlegBezr</code></a> in
<a
href="https://redirect.github.com/lucide-icons/lucide/pull/4881">lucide-icons/lucide#4881</a></li>
<li>chore(<code>@​lucide/vue</code>): Fix types <code>@lucide/vue</code>
package and added workflow for it. by <a
href="https://github.com/ericfennis"><code>@​ericfennis</code></a> in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/4883">lucide-icons/lucide#4883</a></li>
<li>test(packages/shared): cover buildLucideIconForReact by <a
href="https://github.com/vugarbbakhishov-hub"><code>@​vugarbbakhishov-hub</code></a>
in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/4872">lucide-icons/lucide#4872</a></li>
<li>feat(site): Better icon detail page and add unreleased flag by <a
href="https://github.com/ericfennis"><code>@​ericfennis</code></a> in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/4877">lucide-icons/lucide#4877</a></li>
<li>fix(icons): changed <code>map-pinned</code> icon by <a
href="https://github.com/jguddas"><code>@​jguddas</code></a> in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/4880">lucide-icons/lucide#4880</a></li>
<li>fix(icons): changed <code>mail-pen</code> by <a
href="https://github.com/karsa-mistmere"><code>@​karsa-mistmere</code></a>
in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/4899">lucide-icons/lucide#4899</a></li>
<li>chore(deps-dev): bump the angular-deps group across 1 directory with
14 updates by <a
href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/4895">lucide-icons/lucide#4895</a></li>
<li>chore(deps): bump the vue-deps group with 3 updates by <a
href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/4893">lucide-icons/lucide#4893</a></li>
<li>chore(typchecking): More typecheck jobs for all packages by <a
href="https://github.com/ericfennis"><code>@​ericfennis</code></a> in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/4885">lucide-icons/lucide#4885</a></li>
<li>feat(icons): add house-cog icon by <a
href="https://github.com/ajaxjiang96"><code>@​ajaxjiang96</code></a> in
<a
href="https://redirect.github.com/lucide-icons/lucide/pull/4904">lucide-icons/lucide#4904</a></li>
</ul>
<h2>New Contributors</h2>
<ul>
<li><a href="https://github.com/nananecy"><code>@​nananecy</code></a>
made their first contribution in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/3610">lucide-icons/lucide#3610</a></li>
<li><a href="https://github.com/OlegBezr"><code>@​OlegBezr</code></a>
made their first contribution in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/4881">lucide-icons/lucide#4881</a></li>
<li><a
href="https://github.com/vugarbbakhishov-hub"><code>@​vugarbbakhishov-hub</code></a>
made their first contribution in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/4872">lucide-icons/lucide#4872</a></li>
<li><a
href="https://github.com/ajaxjiang96"><code>@​ajaxjiang96</code></a>
made their first contribution in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/4904">lucide-icons/lucide#4904</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/lucide-icons/lucide/compare/1.47.0...1.48.0">https://github.com/lucide-icons/lucide/compare/1.47.0...1.48.0</a></p>
<h2>Version 1.47.0</h2>
<h2>What's Changed</h2>
<ul>
<li>feat(icons): add lambda icon by <a
href="https://github.com/UbaidUllah9962"><code>@​UbaidUllah9962</code></a>
in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/4017">lucide-icons/lucide#4017</a></li>
<li>feat(icons): delegated <code>faucet</code> icon from lab by <a
href="https://github.com/karsa-mistmere"><code>@​karsa-mistmere</code></a>
in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/4764">lucide-icons/lucide#4764</a></li>
<li>feat(icons): added <code>door-closed-package</code> icon by <a
href="https://github.com/karsa-mistmere"><code>@​karsa-mistmere</code></a>
in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/4814">lucide-icons/lucide#4814</a></li>
<li>feat(icons): added 'nepali-rupee' icon by <a
href="https://github.com/sarajdhakal"><code>@​sarajdhakal</code></a> in
<a
href="https://redirect.github.com/lucide-icons/lucide/pull/4608">lucide-icons/lucide#4608</a></li>
<li>feat(icons): added <code>tube-lotion</code> icon by <a
href="https://github.com/AlecRust"><code>@​AlecRust</code></a> in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/4029">lucide-icons/lucide#4029</a></li>
<li>feat(icons): Added cupcake icon by <a
href="https://github.com/briz123"><code>@​briz123</code></a> in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/3000">lucide-icons/lucide#3000</a></li>
<li>feat(icons): added square-dashed-x icon by <a
href="https://github.com/EthanHazel"><code>@​EthanHazel</code></a> in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/4535">lucide-icons/lucide#4535</a></li>
<li>feat(icons): add <code>rotate-cw-clock</code> icon by <a
href="https://github.com/gkkconan"><code>@​gkkconan</code></a> in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/3979">lucide-icons/lucide#3979</a></li>
<li>fix(icons): remove path from save-off by <a
href="https://github.com/HPRILLER"><code>@​HPRILLER</code></a> in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/4848">lucide-icons/lucide#4848</a></li>
<li>fix(icons): changed <code>calendar-chevrons-right</code> by <a
href="https://github.com/karsa-mistmere"><code>@​karsa-mistmere</code></a>
in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/4865">lucide-icons/lucide#4865</a></li>
<li>fix(icons): changed <code>broccoli</code> icon by <a
href="https://github.com/jguddas"><code>@​jguddas</code></a> in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/4871">lucide-icons/lucide#4871</a></li>
<li>feat(icons): added square-dashed-plus by <a
href="https://github.com/psjdev"><code>@​psjdev</code></a> in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/4849">lucide-icons/lucide#4849</a></li>
</ul>
<h2>New Contributors</h2>
<ul>
<li><a
href="https://github.com/UbaidUllah9962"><code>@​UbaidUllah9962</code></a>
made their first contribution in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/4017">lucide-icons/lucide#4017</a></li>
<li><a
href="https://github.com/sarajdhakal"><code>@​sarajdhakal</code></a>
made their first contribution in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/4608">lucide-icons/lucide#4608</a></li>
<li><a href="https://github.com/AlecRust"><code>@​AlecRust</code></a>
made their first contribution in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/4029">lucide-icons/lucide#4029</a></li>
<li><a href="https://github.com/gkkconan"><code>@​gkkconan</code></a>
made their first contribution in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/3979">lucide-icons/lucide#3979</a></li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/lucide-icons/lucide/commit/f06ac67e33d645c40b8ce19a0419c85c5d7dd751"><code>f06ac67</code></a>
chore(typchecking): More typecheck jobs for all packages (<a
href="https://github.com/lucide-icons/lucide/tree/HEAD/packages/lucide-react/issues/4885">#4885</a>)</li>
<li>See full diff in <a
href="https://github.com/lucide-icons/lucide/commits/1.48.0/packages/lucide-react">compare
view</a></li>
</ul>
</details>
<br />

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
canary/v2026.1001.0-canary.11
2026-10-01 16:02:11 -07:00
dependabot[bot] c9cde69299 build(deps): bump @anthropic-ai/sdk from 0.121.0 to 0.129.0 (#13386)
Bumps
[@anthropic-ai/sdk](https://github.com/anthropics/anthropic-sdk-typescript)
from 0.121.0 to 0.129.0.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/anthropics/anthropic-sdk-typescript/releases">@​anthropic-ai/sdk's
releases</a>.</em></p>
<blockquote>
<h2>sdk: v0.129.0</h2>
<h2>0.129.0 (2026-09-28)</h2>
<p>Full Changelog: <a
href="https://github.com/anthropics/anthropic-sdk-typescript/compare/sdk-v0.128.0...sdk-v0.129.0">sdk-v0.128.0...sdk-v0.129.0</a></p>
<h3>Features</h3>
<ul>
<li><strong>api:</strong> add between_tools thinking type (<a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/ab51075609a2d583dffdca24856f4214779d9e7f">ab51075</a>)</li>
<li><strong>api:</strong> add claude-sonnet-5-5 (<a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/4e7736625fd23a5607800e8de4aa3c37daa74a07">4e77366</a>)</li>
<li><strong>api:</strong> add ClientToolUnion type for client-executed
tools (<a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/2c1d2d712071a5f10d2e70ea02dc33425b087799">2c1d2d7</a>)</li>
<li><strong>api:</strong> add include_inherited and source to workspace
rate limits (<a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/66e925e54ff3435a56f51f687641728b94aff306">66e925e</a>)</li>
<li><strong>api:</strong> add typed event type values to the Managed
Agents events list filter (<a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/8ac4a26809418453b64fee79f8ec790d32d1f92c">8ac4a26</a>)</li>
<li><strong>api:</strong> cache diagnostics GA — diagnostics on Message
/ MessageCreateParams (<a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/5ba5f29696d520f68a794936eff7337dce83ac05">5ba5f29</a>)</li>
<li><strong>tools:</strong> optionally start tool calls while the reply
streams (<a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/083969beadb360b9c4b329ee2541f67bd78d9caf">083969b</a>)</li>
</ul>
<h3>Bug Fixes</h3>
<ul>
<li><strong>client:</strong> also send X-Stainless-Timeout for
client-level timeouts (<a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/b84783b6ee03eed519d622ea1e477cf8eb3863bf">b84783b</a>)</li>
<li><strong>client:</strong> send upload filenames as given, with no
placeholder (<a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/f9d3e980b1b498c1c452300a205811f6a56de69b">f9d3e98</a>)</li>
<li><strong>helpers:</strong> degrade between_tools thinking to disabled
on fallback hops (<a
href="https://redirect.github.com/anthropics/anthropic-sdk-typescript/issues/841">#841</a>)
(<a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/edbbf05a62ffe2c95c13810f6d7a0a2796786e5f">edbbf05</a>)</li>
<li><strong>internal:</strong> let bundlers drop unused classes with
more than ten private-member assignments (<a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/67c7adbe5ebae805631e104b341d932a1554bda8">67c7adb</a>)</li>
<li><strong>streaming:</strong> show every complete array item and hold
back unfinished numbers in partial tool input (<a
href="https://redirect.github.com/anthropics/anthropic-sdk-typescript/issues/781">#781</a>)
(<a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/58065889d6b112db6da5127484e0a24025e3fa37">5806588</a>)</li>
</ul>
<h3>Performance Improvements</h3>
<ul>
<li><strong>streaming:</strong> drop the redundant iterSSEChunks layer
(<a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/0357f812dab273c0780c558606663a03e93e34df">0357f81</a>)</li>
<li><strong>streaming:</strong> take each string token as one slice in
the partial JSON tokenizer (<a
href="https://redirect.github.com/anthropics/anthropic-sdk-typescript/issues/255">#255</a>)
(<a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/cdfb1e55afebe1c3be50401ca56bebf0ff009a4e">cdfb1e5</a>)</li>
</ul>
<h3>Chores</h3>
<ul>
<li><strong>api:</strong> deprecate the betas param on GA models and
completions methods (<a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/5c74e4532bb69f22afa3e08013645ac059440aef">5c74e45</a>)</li>
<li><strong>api:</strong> list the known model ids first in the Model
types (<a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/94528226386311c3ade468cbdea0326c06a1e53d">9452822</a>)</li>
<li><strong>ci:</strong> choose the CI runner by repository (<a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/33db1ec2e99a415ff98619cf88ddddbf2b7ca7b1">33db1ec</a>)</li>
<li><strong>docs:</strong> clarify that stream: true returns the raw
event stream (<a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/4286c227c3a605bf04d4f59ffb496f44c102a6ec">4286c22</a>)</li>
<li><strong>docs:</strong> make Managed Agents actor descriptions
resource-neutral (<a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/15733f98deaae4aee2fba26c1bfe4ee1514c7080">15733f9</a>)</li>
<li><strong>docs:</strong> restore the research-preview notice on the
Dream type (<a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/b32f8baa27c40ad5901531024bae86e0ca046bb5">b32f8ba</a>)</li>
<li><strong>internal:</strong> move old constants around (<a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/0cd8edfdc6dd91af4ffee4ed3cc7fc8cc22d65e3">0cd8edf</a>)</li>
<li><strong>tests:</strong> add diagnostics to the parser test's Message
fixtures (<a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/eb5ca58d51ed3309b1f317b20f7d248b036ba76a">eb5ca58</a>)</li>
<li><strong>tools:</strong> remove client-side compaction control (<a
href="https://redirect.github.com/anthropics/anthropic-sdk-typescript/issues/802">#802</a>)
(<a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/9c3e8a5ffa38c35dec32f0258becd360babd5fb1">9c3e8a5</a>)</li>
</ul>
<h3>Documentation</h3>
<ul>
<li><strong>api:</strong> prefer each field's own description over its
shared type's (<a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/51934782720725acca570edeb0a3a7501ca7dbd8">5193478</a>)</li>
<li>expand CLAUDE.md into a full contributor guide (<a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/98d2ddbce7c1eabbabe5a130d18d307c237fb75c">98d2ddb</a>)</li>
</ul>
<h2>sdk: v0.128.0</h2>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/anthropics/anthropic-sdk-typescript/blob/main/CHANGELOG.md">@​anthropic-ai/sdk's
changelog</a>.</em></p>
<blockquote>
<h2>0.129.0 (2026-09-28)</h2>
<p>Full Changelog: <a
href="https://github.com/anthropics/anthropic-sdk-typescript/compare/sdk-v0.128.0...sdk-v0.129.0">sdk-v0.128.0...sdk-v0.129.0</a></p>
<h3>Features</h3>
<ul>
<li><strong>api:</strong> add between_tools thinking type (<a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/ab51075609a2d583dffdca24856f4214779d9e7f">ab51075</a>)</li>
<li><strong>api:</strong> add claude-sonnet-5-5 (<a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/4e7736625fd23a5607800e8de4aa3c37daa74a07">4e77366</a>)</li>
<li><strong>api:</strong> add ClientToolUnion type for client-executed
tools (<a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/2c1d2d712071a5f10d2e70ea02dc33425b087799">2c1d2d7</a>)</li>
<li><strong>api:</strong> add include_inherited and source to workspace
rate limits (<a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/66e925e54ff3435a56f51f687641728b94aff306">66e925e</a>)</li>
<li><strong>api:</strong> add typed event type values to the Managed
Agents events list filter (<a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/8ac4a26809418453b64fee79f8ec790d32d1f92c">8ac4a26</a>)</li>
<li><strong>api:</strong> cache diagnostics GA — diagnostics on Message
/ MessageCreateParams (<a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/5ba5f29696d520f68a794936eff7337dce83ac05">5ba5f29</a>)</li>
<li><strong>tools:</strong> optionally start tool calls while the reply
streams (<a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/083969beadb360b9c4b329ee2541f67bd78d9caf">083969b</a>)</li>
</ul>
<h3>Bug Fixes</h3>
<ul>
<li><strong>client:</strong> also send X-Stainless-Timeout for
client-level timeouts (<a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/b84783b6ee03eed519d622ea1e477cf8eb3863bf">b84783b</a>)</li>
<li><strong>client:</strong> send upload filenames as given, with no
placeholder (<a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/f9d3e980b1b498c1c452300a205811f6a56de69b">f9d3e98</a>)</li>
<li><strong>helpers:</strong> degrade between_tools thinking to disabled
on fallback hops (<a
href="https://redirect.github.com/anthropics/anthropic-sdk-typescript/issues/841">#841</a>)
(<a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/edbbf05a62ffe2c95c13810f6d7a0a2796786e5f">edbbf05</a>)</li>
<li><strong>internal:</strong> let bundlers drop unused classes with
more than ten private-member assignments (<a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/67c7adbe5ebae805631e104b341d932a1554bda8">67c7adb</a>)</li>
<li><strong>streaming:</strong> show every complete array item and hold
back unfinished numbers in partial tool input (<a
href="https://redirect.github.com/anthropics/anthropic-sdk-typescript/issues/781">#781</a>)
(<a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/58065889d6b112db6da5127484e0a24025e3fa37">5806588</a>)</li>
</ul>
<h3>Performance Improvements</h3>
<ul>
<li><strong>streaming:</strong> drop the redundant iterSSEChunks layer
(<a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/0357f812dab273c0780c558606663a03e93e34df">0357f81</a>)</li>
<li><strong>streaming:</strong> take each string token as one slice in
the partial JSON tokenizer (<a
href="https://redirect.github.com/anthropics/anthropic-sdk-typescript/issues/255">#255</a>)
(<a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/cdfb1e55afebe1c3be50401ca56bebf0ff009a4e">cdfb1e5</a>)</li>
</ul>
<h3>Chores</h3>
<ul>
<li><strong>api:</strong> deprecate the betas param on GA models and
completions methods (<a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/5c74e4532bb69f22afa3e08013645ac059440aef">5c74e45</a>)</li>
<li><strong>api:</strong> list the known model ids first in the Model
types (<a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/94528226386311c3ade468cbdea0326c06a1e53d">9452822</a>)</li>
<li><strong>ci:</strong> choose the CI runner by repository (<a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/33db1ec2e99a415ff98619cf88ddddbf2b7ca7b1">33db1ec</a>)</li>
<li><strong>docs:</strong> clarify that stream: true returns the raw
event stream (<a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/4286c227c3a605bf04d4f59ffb496f44c102a6ec">4286c22</a>)</li>
<li><strong>docs:</strong> make Managed Agents actor descriptions
resource-neutral (<a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/15733f98deaae4aee2fba26c1bfe4ee1514c7080">15733f9</a>)</li>
<li><strong>docs:</strong> restore the research-preview notice on the
Dream type (<a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/b32f8baa27c40ad5901531024bae86e0ca046bb5">b32f8ba</a>)</li>
<li><strong>internal:</strong> move old constants around (<a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/0cd8edfdc6dd91af4ffee4ed3cc7fc8cc22d65e3">0cd8edf</a>)</li>
<li><strong>tests:</strong> add diagnostics to the parser test's Message
fixtures (<a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/eb5ca58d51ed3309b1f317b20f7d248b036ba76a">eb5ca58</a>)</li>
<li><strong>tools:</strong> remove client-side compaction control (<a
href="https://redirect.github.com/anthropics/anthropic-sdk-typescript/issues/802">#802</a>)
(<a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/9c3e8a5ffa38c35dec32f0258becd360babd5fb1">9c3e8a5</a>)</li>
</ul>
<h3>Documentation</h3>
<ul>
<li><strong>api:</strong> prefer each field's own description over its
shared type's (<a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/51934782720725acca570edeb0a3a7501ca7dbd8">5193478</a>)</li>
<li>expand CLAUDE.md into a full contributor guide (<a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/98d2ddbce7c1eabbabe5a130d18d307c237fb75c">98d2ddb</a>)</li>
</ul>
<h2>0.128.0 (2026-09-22)</h2>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/bf2058689f845dfb10e59bd9ebeb5cb4e9318a9d"><code>bf20586</code></a>
Merge pull request <a
href="https://redirect.github.com/anthropics/anthropic-sdk-typescript/issues/1218">#1218</a>
from anthropics/release-please--branches--main--chan...</li>
<li><a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/da41a5a0e5d6f498f1bb8b71beb5b1e0a2bd1e48"><code>da41a5a</code></a>
chore: release main</li>
<li><a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/3a79b93f0210a83f8bf9fda91a42b577c9e6b93c"><code>3a79b93</code></a>
codegen metadata</li>
<li><a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/4e7736625fd23a5607800e8de4aa3c37daa74a07"><code>4e77366</code></a>
feat(api): add claude-sonnet-5-5</li>
<li><a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/2c1d2d712071a5f10d2e70ea02dc33425b087799"><code>2c1d2d7</code></a>
feat(api): add ClientToolUnion type for client-executed tools</li>
<li><a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/f9d3e980b1b498c1c452300a205811f6a56de69b"><code>f9d3e98</code></a>
fix(client): send upload filenames as given, with no placeholder</li>
<li><a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/8ac4a26809418453b64fee79f8ec790d32d1f92c"><code>8ac4a26</code></a>
feat(api): add typed event type values to the Managed Agents events list
filter</li>
<li><a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/083969beadb360b9c4b329ee2541f67bd78d9caf"><code>083969b</code></a>
feat(tools): optionally start tool calls while the reply streams</li>
<li><a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/9505bf37def4a4ada41c95e4e4fa7fb6b3b3f679"><code>9505bf3</code></a>
codegen metadata</li>
<li><a
href="https://github.com/anthropics/anthropic-sdk-typescript/commit/b84783b6ee03eed519d622ea1e477cf8eb3863bf"><code>b84783b</code></a>
fix(client): also send X-Stainless-Timeout for client-level
timeouts</li>
<li>Additional commits viewable in <a
href="https://github.com/anthropics/anthropic-sdk-typescript/compare/sdk-v0.121.0...sdk-v0.129.0">compare
view</a></li>
</ul>
</details>
<br />

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
canary/v2026.1001.0-canary.10
2026-10-01 15:30:19 -07:00
Devin FoleyandPaperclip 4b2bd6563d fix(chat): hide obsolete execution status and system notices (#14874)
## Thinking Path

> - Paperclip lets people oversee agent work through task conversations.
> - Conversations should show failures and waits that still affect the
task.
> - Old run errors and recovery notices remained visible after later
work or task completion.
> - These messages looked current even when no action remained.
> - This change hides obsolete execution status while preserving the
responses and activity.
> - The full diagnostic record stays available in run history.

## Linked Issues or Issue Description

**What happened?**

Task chat kept showing “Run failed”, “Stopped”, and “Waiting to resume”
after the execution had been superseded or the task had finished. Stored
system notices also remained in the conversation. Completed tasks
disabled Retry but kept the error message.

**Expected behavior**

Hide system status that no longer applies. Keep the latest unresolved
failure, active recovery holds, and useful recovery actions visible.
Preserve messages, files, questions, session boundaries, and inspectable
activity.

**Steps to reproduce**

1. Let a task run fail, then record a pre-start recovery wait.
2. Complete a later attempt or mark the task done.
3. Open the task conversation. Before this change, the old error and
wait remain visible.

**Paperclip version or commit**

Reproduced in component tests against `0f9e9be408`.

**Deployment mode**

Task chat in local or hosted deployments; both legacy adapters and the
native runner.

Related: #14857 and #14869 address execution recovery. This PR addresses
the remaining conversation presentation. Searched GitHub for historical
chat status, historical errors, and “Waiting to resume”; no duplicate PR
found.

## What Changed

- Determine status relevance from task state, attempt order, successor
evidence, and recovery state. Time alone does not hide errors.
- Hide obsolete run markers and stored execution notices. Require run or
recovery provenance, so unrelated system updates such as child-task
blockers remain visible. Keep errors from the latest failed attempt
actionable.
- Keep unresolved execution holds visible. A refused pre-start retry
does not replace a real attempt, and another agent’s work does not
resolve a run-specific error.
- Show historical activity without Worked/Stopped labels. Keep
historical failures out of the current turn’s summary.
- Anchor activity to visible comments so removing a notice cannot remove
the response or activity with it.
- Document the presentation rules and cover both runner modes and both
task presentation modes.

## Verification

- 334 focused component and status-policy tests passed across four
files, including the child-task relay regressions.
- `pnpm build` passed. The UI build also passed after the final
presentation changes.
- `pnpm exec vitest run --project @paperclipai/ui`: 667 files and 7,157
tests passed. Subsequent focused tests cover the final activity-anchor,
live-successor, and notice-provenance changes.
- `pnpm -r typecheck` passed. UI typecheck and build passed again after
the review fix.
- `pnpm test:run` completed its general-server phase with 14,716 tests
passed, 17 failed, and 87 skipped; it stopped before later phases. The
failures occurred in four unchanged server suites: chat channels, email
channels, company skills, and runtime skill cache. A targeted rerun
reproduced missing bundled skill paths and `EACCES` during
cache-directory rename on macOS. All Linux CI suites pass for the final
commit, including these server suites.
- Design token gates and diff checks pass.
- All 53 checks pass on commit `7af9753859`; two optional Storybook
checks are skipped. [Final CI
run](https://github.com/paperclipai/paperclip/actions/runs/36931968751)
includes build, full typecheck, all server and workspace test shards,
all eight end-to-end shards, runner verification, and the canary dry
run.
- Greptile scores the final commit at 5/5. No review threads remain
unresolved. The branch is current with `master` and has no merge
conflicts.

## Risks

This changes presentation only. It does not change execution, recovery,
stored comments, or run history. The main risk is hiding a current
diagnostic too early. Tests cover active holds, refused retries,
different agents, missing timestamps and provenance, live successors,
preserved responses, and the current retry target.

The base branch has a dependency override/lockfile mismatch. Local
installation used the same resolution fallback as CI, then restored the
tracked lockfile. No dependency changes are included.

## Model Used

OpenAI Codex (GPT-6). The exact runtime model identifier and context
window are not exposed in this session. Used reasoning, repository
inspection, code execution, and regression tests.

## Checklist

- [x] I have included a thinking path that traces from project context
to this change
- [x] I have specified the model used (with version and capability
details)
- [x] I have checked ROADMAP.md and confirmed this PR does not duplicate
planned core work
- [x] I have searched GitHub for duplicate or related PRs and linked
them above
- [x] I have either (a) linked existing issues with `Fixes: #` / `Closes
#` / `Refs #` OR (b) described the issue in-PR following the relevant
issue template
- [x] I have not referenced internal/instance-local Paperclip issues or
links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip`
URLs)
- [x] My branch name describes the change (e.g. `docs/...`, `fix/...`)
and contains no internal Paperclip ticket id or instance-derived details
- [ ] I have run tests locally and they pass — changed-code tests pass;
unrelated full-suite failures are documented above
- [x] I have added or updated tests where applicable
- [x] I have updated relevant documentation to reflect my changes
- [x] I have considered and documented any risks above
- [x] All Paperclip CI gates are green
- [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups
- [x] I will address all Greptile and reviewer comments before
requesting merge

---------

Co-authored-by: Paperclip <noreply@paperclip.ing>
canary/v2026.1001.0-canary.9
2026-10-01 15:18:47 -07:00
dependabot[bot] 2a36e915ef build(deps): bump @vercel/connect from 0.6.1 to 2.3.3 (#13390)
Bumps
[@vercel/connect](https://github.com/vercel/vercel/tree/HEAD/packages/connect)
from 0.6.1 to 2.3.3.
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/vercel/vercel/blob/main/packages/connect/CHANGELOG.md">@​vercel/connect's
changelog</a>.</em></p>
<blockquote>
<h1><code>@​vercel/connect</code></h1>
<h2>2.0.2</h2>
<h3>Patch Changes</h3>
<ul>
<li>c028593: Update the Core SDK documentation to show how to start an
authorization request.</li>
</ul>
<h2>2.0.1</h2>
<h3>Patch Changes</h3>
<ul>
<li>2ecb357: <code>connectGitHubCredentials</code> now resolves the
GitHub App slug from the connector's metadata and exposes it as
<code>appSlug</code> on the returned credentials, so eve's
<code>githubChannel</code> can derive its invocation token
(<code>botName</code>) without extra configuration.</li>
</ul>
<h2>2.0.0</h2>
<h3>Major Changes</h3>
<ul>
<li>42938f9: Make Eve connector provisioning opt-in with
<code>autoProvision: true</code>. When enabled, try token and
authorization requests before provisioning, then provision and retry
once only when the connector is missing or not linked to the
project.</li>
</ul>
<h2>1.1.0</h2>
<h3>Minor Changes</h3>
<ul>
<li>b9fab7c: Add Sendblue credential helpers for Eve-native channels and
the Chat SDK adapter, including Connect trigger-forwarded webhook
verification for Chat SDK users.</li>
</ul>
<h2>1.0.0</h2>
<h3>Major Changes</h3>
<ul>
<li>9b55136: Default omitted scopes to <code>['*']</code> in token and
authorization requests.</li>
</ul>
<h3>Minor Changes</h3>
<ul>
<li>4199902: Send Vercel API requests to the region from
<code>VERCEL_REGION</code>, with a <code>region</code> option to
override it.</li>
</ul>
<h2>0.9.0</h2>
<h3>Minor Changes</h3>
<ul>
<li>46a5aaa: Add Linq helpers for Eve and Chat SDK applications.
<code>connectLinqCredentials</code> resolves an app-scoped Linq API key,
and <code>connectLinqAdapter</code> adds trusted Connect OIDC
verification for trigger-forwarded Linq webhooks while retaining the
provider signing secret within Connect.</li>
</ul>
<h2>0.8.1</h2>
<h3>Patch Changes</h3>
<ul>
<li><code>@​vercel/oidc</code><a
href="https://github.com/3"><code>@​3</code></a>.8.5</li>
</ul>
<h2>0.8.0</h2>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li>See full diff in <a
href="https://github.com/vercel/vercel/commits/@now/next@2.3.3/packages/connect">compare
view</a></li>
</ul>
</details>
<br />

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
canary/v2026.1001.0-canary.8
2026-10-01 14:44:00 -07:00
Devin FoleyandPaperclip f2e0f19630 Defer agent directory cleanup until stop proof is available (#14866)
## Thinking Path

> - Paperclip manages agents and their persistent files.
> - Each run owns a temporary agent directory and a save receipt.
> - Cleanup needs independent proof that the owning process stopped.
> - A cleanup call without that proof currently waits for the directory
lock anyway.
> - A second lock failure can prevent environment release after the run
already reported a failed save.
> - This change skips cleanup that has no authority and retries
unavailable remote copies after exact destruction proof.
> - The save failure stays visible. Existing lock owners remain
protected.

## Linked Issues or Issue Description

Related work: Refs #14787 (lock diagnostics), #14695 (warm instruction
ownership), #9667 (stale lock proposal), and #9872 (control-plane
ownership proposal). I checked open PRs and issues. This change leaves
the shared filesystem lock protocol in place and does not duplicate the
warm-retention work in #14695.

**What happened?**

Heartbeat cleanup records an explicit unavailable instruction-save
warning, then calls directory release before releasing the environment
lease. Release can wait for a lock even though the copy has no
process-stop proof and cannot be removed. That secondary timeout
prevents the following lease-release step. If destruction proof arrives
later, the unavailable copy is excluded from both recovery queries.

**Expected behavior**

Skip a release that cannot remove anything. Preserve the failed-save
receipt and candidate fields. Once exact remote destruction is recorded,
recover remote cleanup without running a provider command. Unavailable
local copies retain their potentially uncollected edits even if local
stop proof arrives later. A blocked cleanup must not prevent cleanup for
other agents.

**Steps to reproduce**

1. Prepare an agent directory, report its save unavailable, and leave
process-stop proof absent.
2. Hold the shared directory lock and call release. Before this change,
release waits and fails although removal is not authorized.
3. Record destruction of the copy's exact remote lease. Before this
change, neither recovery sweep selects the unavailable copy.

**Paperclip version or commit**

Reproduced against `efc2e6810e9bc0dc8cb412b0e7647c0db9821caa`.

**Deployment mode**

Local and remote execution with persistent agent directories. Tests use
an isolated embedded PostgreSQL database and fixture transports.

## What Changed

- Re-read receipts and skip release before lock acquisition when stop
proof is absent, the copy is superseded, or cleanup is complete. Keep
the same checks inside the lock.
- Recover unavailable remote copies only after exact destruction proof.
Preserve their unavailable state, errors, candidate hash, and candidate
bytes. Keep unavailable local copies and their uncollected edits
unchanged.
- Store destruction-only cleanup authority with the stop proof. Later
cleanup honors it after a lost database response or restart, including
when a transport remains cached.
- Defer failed or unproven cleanup with bounded batches and a retry
delay. Keep failed cleanup visible in logs and its receipt.
- Serialize preparation of an existing run with cleanup. Fresh run
preparation keeps its existing admission path.
- Cover held locks, receipt scope, delayed proof, batch fairness, lost
update responses, cached transports, and concurrent same-run preparation
with database regressions.

## Verification

- Focused directory, legacy instruction-copy, shared lock, and bounded
diagnostic suites: 169 tests passed across four files.
- `pnpm -r typecheck`: passed on the final source.
- `pnpm build`: passed on the final source.
- Completed all selected local `pnpm test:run` groups: 733 general
server suites, 149 serialized suites, and 14 workspace projects. There
are 13 known macOS `EACCES` failures in the unchanged runtime skill
cache tests. Their exact signatures match earlier clean-base results,
and the cache source and test blobs match both that base and this PR
base (existing fix: #14290). One CLI import test timed out under
concurrent load; its full file passed separately (17 tests). Broad
coverage began before the review corrections; the final source has the
focused 169-test run, typecheck, and build. This is a local verification
limit, not a passing full local suite.
- `git diff --check` and local Gitleaks plus private-identifier/PII diff
scans passed.
- Independent review of the final source found no remaining actionable
issue. Its 17 targeted tests cover crash recovery, cached transports,
same-run preparation, real local edit preservation, proof scope, and
batch fairness. The main focused run also covers contained scheduling
failures.
- Final commit `35a24085f7`: Greptile 5/5 with no recommendations and
zero unresolved review threads.
- Final commit `35a24085f7`: all 53 checks passed, including Canary Dry
Run and the security scan; two visual checks were intentionally skipped.
The workspace shard passed on retry after GitHub reported that its first
runner lost communication. An earlier Canary runner shut down after the
release dry run passed. Neither interruption recorded an application
assertion failure; the exact final-head checks are now green.

## Risks

- This repairs cleanup ordering and recovery eligibility. It does not
repair an ambiguous legacy lock owner or restore unsaved files. Actual
collection still fails visibly when its lock cannot be acquired.
- An unavailable remote copy is recovered only after exact destruction
proof. A stopped but retained environment stays protected; recovery does
not execute a command that could restart it.
- Unavailable local copies with later stop proof still retain
potentially uncollected edits. A general local recollection or
reclamation policy remains outside this change.
- Existing-run preparation now waits for the same lock as cleanup. The
fresh-run path is unchanged.
- The cleanup mode is stored in the existing private receipt JSON. No
schema migration or public API change is required.
- No deployment, task replay, or runtime lock deletion was performed.

## Model Used

OpenAI GPT-6 (Codex), with reasoning, repository tools, and test
execution. The runtime does not expose a more specific model suffix or
context-window size.

## Checklist

- [x] I have included a thinking path that traces from project context
to this change
- [x] I have specified the model used (with version and capability
details)
- [x] I have checked ROADMAP.md and confirmed this PR does not duplicate
planned core work
- [x] I have searched GitHub for duplicate or related PRs and linked
them above
- [x] I have either (a) linked existing issues with `Fixes: #` / `Closes
#` OR (b) described the issue in-PR following the relevant issue
template
- [x] I have not referenced internal/instance-local Paperclip issues or
links (only public GitHub references)
- [x] My branch name describes the change and contains no internal
Paperclip ticket id
- [ ] I have run tests locally and they pass
- [x] I have added or updated tests where applicable
- [x] I have updated relevant documentation to reflect my changes
- [x] I have considered and documented any risks above
- [x] All Paperclip CI gates are green
- [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups
- [x] I will address all Greptile and reviewer comments before
requesting merge

---------

Co-authored-by: Paperclip <noreply@paperclip.ing>
2026-10-01 14:28:47 -07:00
dependabot[bot] 0f9e9be408 build(deps): bump @codemirror/state from 6.7.2 to 6.7.6 (#13391)
Bumps [@codemirror/state](https://github.com/codemirror/state) from
6.7.2 to 6.7.6.
<details>
<summary>Commits</summary>
<ul>
<li>See full diff in <a
href="https://github.com/codemirror/state/commits">compare view</a></li>
</ul>
</details>
<br />

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-10-01 13:45:48 -07:00
DottaandPaperclip 4039d4f06b fix(auth): allow scoped low-trust work and owner-chat instruction edits (#14870)
## Thinking Path

> - Paperclip is the open source app people use to manage AI agents for
work.
> - Low-trust agents must work within their assigned scope.
> - Task creation currently rejects these agents before checking
assignment permission or scope.
> - Persistent instruction saves also reject direct requests from
authorized chat owners.
> - This PR checks the requested action and its recorded authority
instead of denying all such work.
> - Agents can organize permitted work and follow their owner's
instruction-edit requests while outside work stays restricted.

## Linked Issues or Issue Description

**What happened?**

Low-trust agents cannot create self-assigned tasks or subtasks, even
within their allowed scope. An authorized user also cannot ask an agent
in their own Agent Chat to update its managed `AGENTS.md`. Agent-folder
collection can hide the permission rejection behind a generic save
failure.

**Expected behavior**

Allow task creation when assignment permissions and project or root-task
scope permit it. Allow instruction self-edits during authenticated
owner-chat execution, subject to the user's current edit permission.
Outside tasks, subtasks, connector messages, and peer agents do not
inherit that instruction authority. Explain the actual denial when a
save fails.

**Steps to reproduce**

1. Configure an active agent with `low_trust_review` and a project or
root-task boundary.
2. Ask it to create an in-scope task assigned to itself, or a subtask of
its own task.
3. As a user with permission to configure that agent, ask it in your
Agent Chat to update its managed `AGENTS.md`.
4. Observe blanket permission denials rather than action-specific
checks.

**Paperclip version or commit**

Rebased onto master at `8ec4b84e1`. This is a core authorization change,
independent of adapter choice.

**Deployment mode**

Authenticated server. Regression coverage uses the server services, HTTP
routes, native tool authority, and embedded PostgreSQL.

Related work: #14775 adds human-directed task execution. #13599 concerns
instruction-path configuration; this PR leaves that configuration
restricted. #11988 proposes separate active-review instruction
protection. #10693 reports unclear authorization denials on a different
API surface.

## What Changed

- Apply task-assignment checks to both HTTP creation routes and native
task creation, including unassigned work. Preserve low-trust policy and
source attribution on the created task and its initial plan.
- Allow self-assigned decomposition within the permitted project or
root-task tree. Resolve workspace-derived project scope before
authorization, and reauthorize existing tasks before duplicate detection
returns them. Keep cross-project and peer-assignment checks.
- Derive instruction self-edit authority from the accepted run identity
and authenticated owner-message wake. Recheck current permissions at
save time. Bind retries to the same request and chat session.
- Reject inherited instruction authority from outside tasks, subtasks,
plugins, connectors, stale sessions, cancelled runs, and peer edits.
- Surface permission errors in instruction and agent-folder save
receipts. Tell chat agents to explain the rejected action and the
specific restriction.
- Update the low-trust policy and implementation documentation.

## Verification

- All 297 tests in 11 focused server suites pass after the rebase. These
cover owner-chat saves, private copies, warm agent directories, reset
and retry boundaries, permission revocation, task creation routes, and
native tool authority.
- After review fixes, all 126 tests in the four affected
authorization/chat suites pass. Workspace scope regressions and 146
existing creation/ownership/workspace-route tests also pass.
- The final duplicate-task and CI fixes pass all 39 tests across
chat-project tools, duplicate creation, environment-selection guards,
and assignee-invokability routes. The duplicate-task test reproduced an
unauthorized response before the fix and verifies denial plus permitted
reuse afterward.
- `pnpm --filter @paperclipai/server typecheck` passes after rebasing;
`pnpm --filter @paperclipai/server exec tsc --noEmit` also passes after
the review fixes.
- `git diff --check origin/master...HEAD` passes.
- Final head `7e73270b86748792649e4ae6fbc6879f73b42b73`: all 54 checks
passed, with two expected skips and no pending or failed checks. This
includes builds, typechecking, the full test matrix, end-to-end tests,
runner verification, the canary dry run, and security scans.
- Greptile is 5/5 on that exact head, with no unresolved review threads.
This change has not been deployed to staging.

## Risks

This changes authorization behavior. The instruction exception must not
become an inherited task permission. The check uses server-owned
execution records, requires the agent's own chat and instructions, and
keeps normal protected-change and responsible-user checks. Saves fail
closed when current provenance or permission is missing. Owner chat
grants a turn-scoped capability; the server does not classify the
message intent or require approval of the exact new file bytes. Prompt
injection within an authorized owner-chat turn remains a model-level
risk. This is the requested owner-chat trust boundary, without a new
per-edit confirmation flow. No database migration or broad trust-preset
change is required.

## Model Used

OpenAI Codex, based on GPT-6, with reasoning, code editing, shell tools,
and test execution. The exact runtime model ID and context-window size
are not exposed in this session.

## Checklist

- [x] I have included a thinking path that traces from project context
to this change
- [x] I have specified the model used (with version and capability
details)
- [x] I have checked ROADMAP.md and confirmed this PR does not duplicate
planned core work
- [x] I have searched GitHub for duplicate or related PRs and linked
them above
- [x] I have either (a) linked existing issues with `Fixes: #` / `Closes
#` / `Refs #` OR (b) described the issue in-PR following the relevant
issue template
- [x] I have not referenced internal/instance-local Paperclip issues or
links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip`
URLs)
- [x] My branch name describes the change (e.g. `docs/...`, `fix/...`)
and contains no internal Paperclip ticket id or instance-derived details
- [x] I have run tests locally and they pass
- [x] I have added or updated tests where applicable
- [x] I have updated relevant documentation to reflect my changes
- [x] I have considered and documented any risks above
- [x] All Paperclip CI gates are green
- [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups
- [x] I will address all Greptile and reviewer comments before
requesting merge

---------

Co-authored-by: Paperclip <noreply@paperclip.ing>
2026-10-01 15:42:40 -05:00
dependabot[bot] e2d4f07207 build(deps): bump googleapis from 176.0.0 to 182.0.0 (#13393)
Bumps
[googleapis](https://github.com/googleapis/google-api-nodejs-client)
from 176.0.0 to 182.0.0.
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/googleapis/google-api-nodejs-client/commit/9eb464beb4310053dec5aef4661d6c6fd73051a8"><code>9eb464b</code></a>
chore: release main (<a
href="https://redirect.github.com/googleapis/google-api-nodejs-client/issues/4023">#4023</a>)</li>
<li><a
href="https://github.com/googleapis/google-api-nodejs-client/commit/9e3b4655c95fde3c69d2a44496a586e906695734"><code>9e3b465</code></a>
feat: regenerate index files</li>
<li><a
href="https://github.com/googleapis/google-api-nodejs-client/commit/279af87fcf2c4016321bde793a8cefd1a542615d"><code>279af87</code></a>
fix(youtubereporting): update the API</li>
<li><a
href="https://github.com/googleapis/google-api-nodejs-client/commit/b37c22595087460ffc1be63471bb56e3e81675f5"><code>b37c225</code></a>
fix(youtubeAnalytics): update the API</li>
<li><a
href="https://github.com/googleapis/google-api-nodejs-client/commit/512e921970a8556fc20aef5e7766826107018957"><code>512e921</code></a>
fix(youtube): update the API</li>
<li><a
href="https://github.com/googleapis/google-api-nodejs-client/commit/6cd997a07c55c80a3f3070cea06affd0aa3274c9"><code>6cd997a</code></a>
fix(workstations): update the API</li>
<li><a
href="https://github.com/googleapis/google-api-nodejs-client/commit/62d5f7629a9ddd6523b4f4050c955a2063007fce"><code>62d5f76</code></a>
fix(workspaceevents): update the API</li>
<li><a
href="https://github.com/googleapis/google-api-nodejs-client/commit/0d71cd6b01ed41b1dff0a04d85567cfd2a511495"><code>0d71cd6</code></a>
feat(workloadmanager): update the API</li>
<li><a
href="https://github.com/googleapis/google-api-nodejs-client/commit/2c46e13798ba24a8b4d2ad9e92f7995d7dcdd93e"><code>2c46e13</code></a>
fix(workflows): update the API</li>
<li><a
href="https://github.com/googleapis/google-api-nodejs-client/commit/c7b8641390370d9af9b12154e6bf455bc344feaa"><code>c7b8641</code></a>
fix(workflowexecutions): update the API</li>
<li>Additional commits viewable in <a
href="https://github.com/googleapis/google-api-nodejs-client/compare/googleapis-v176.0.0...googleapis-v182.0.0">compare
view</a></li>
</ul>
</details>
<br />

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
canary/v2026.1001.0-canary.7
2026-10-01 13:16:41 -07:00
dependabot[bot] d91eceb575 chore(deps): bump actions/github-script from 8.0.0 to 9.0.0 (#13471)
Bumps [actions/github-script](https://github.com/actions/github-script)
from 8.0.0 to 9.0.0.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/actions/github-script/releases">actions/github-script's
releases</a>.</em></p>
<blockquote>
<h2>v9.0.0</h2>
<p><strong>New features:</strong></p>
<ul>
<li><strong><code>getOctokit</code> factory function</strong> —
Available directly in the script context. Create additional
authenticated Octokit clients with different tokens for multi-token
workflows, GitHub App tokens, and cross-org access. See <a
href="https://github.com/actions/github-script#creating-additional-clients-with-getoctokit">Creating
additional clients with <code>getOctokit</code></a> for details and
examples.</li>
<li><strong>Orchestration ID in user-agent</strong> — The
<code>ACTIONS_ORCHESTRATION_ID</code> environment variable is
automatically appended to the user-agent string for request
tracing.</li>
</ul>
<p><strong>Breaking changes:</strong></p>
<ul>
<li><strong><code>require('@actions/github')</code> no longer works in
scripts.</strong> The upgrade to <code>@actions/github</code> v9
(ESM-only) means <code>require('@actions/github')</code> will fail at
runtime. If you previously used patterns like <code>const { getOctokit }
= require('@actions/github')</code> to create secondary clients, use the
new injected <code>getOctokit</code> function instead — it's available
directly in the script context with no imports needed.</li>
<li><code>getOctokit</code> is now an injected function parameter.
Scripts that declare <code>const getOctokit = ...</code> or <code>let
getOctokit = ...</code> will get a <code>SyntaxError</code> because
JavaScript does not allow <code>const</code>/<code>let</code>
redeclaration of function parameters. Use the injected
<code>getOctokit</code> directly, or use <code>var getOctokit =
...</code> if you need to redeclare it.</li>
<li>If your script accesses other <code>@actions/github</code> internals
beyond the standard <code>github</code>/<code>octokit</code> client, you
may need to update those references for v9 compatibility.</li>
</ul>
<h2>What's Changed</h2>
<ul>
<li>Add ACTIONS_ORCHESTRATION_ID to user-agent string by <a
href="https://github.com/Copilot"><code>@​Copilot</code></a> in <a
href="https://redirect.github.com/actions/github-script/pull/695">actions/github-script#695</a></li>
<li>ci: use deployment: false for integration test environments by <a
href="https://github.com/salmanmkc"><code>@​salmanmkc</code></a> in <a
href="https://redirect.github.com/actions/github-script/pull/712">actions/github-script#712</a></li>
<li>feat!: add getOctokit to script context, upgrade
<code>@​actions/github</code> v9, <code>@​octokit/core</code> v7, and
related packages by <a
href="https://github.com/salmanmkc"><code>@​salmanmkc</code></a> in <a
href="https://redirect.github.com/actions/github-script/pull/700">actions/github-script#700</a></li>
</ul>
<h2>New Contributors</h2>
<ul>
<li><a href="https://github.com/Copilot"><code>@​Copilot</code></a> made
their first contribution in <a
href="https://redirect.github.com/actions/github-script/pull/695">actions/github-script#695</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/actions/github-script/compare/v8.0.0...v9.0.0">https://github.com/actions/github-script/compare/v8.0.0...v9.0.0</a></p>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/actions/github-script/commit/3a2844b7e9c422d3c10d287c895573f7108da1b3"><code>3a2844b</code></a>
Merge pull request <a
href="https://redirect.github.com/actions/github-script/issues/700">#700</a>
from actions/salmanmkc/expose-getoctokit + prepare re...</li>
<li><a
href="https://github.com/actions/github-script/commit/ca10bbdd1a7739de09e99a200c7a59f5d73a4079"><code>ca10bbd</code></a>
fix: use <code>@​octokit/core/</code>types import for v7
compatibility</li>
<li><a
href="https://github.com/actions/github-script/commit/86e48e20ac85c970ed1f96e718fd068173948b7b"><code>86e48e2</code></a>
merge: incorporate main branch changes</li>
<li><a
href="https://github.com/actions/github-script/commit/c1084728b5b935ec4ddc1e4cee877b01797b3ff9"><code>c108472</code></a>
chore: rebuild dist for v9 upgrade and getOctokit factory</li>
<li><a
href="https://github.com/actions/github-script/commit/afff112e4f8b57c718168af75b89ce00bc8d091d"><code>afff112</code></a>
Merge pull request <a
href="https://redirect.github.com/actions/github-script/issues/712">#712</a>
from actions/salmanmkc/deployment-false + fix user-ag...</li>
<li><a
href="https://github.com/actions/github-script/commit/ff8117e5b78c415f814f39ad6998f424fee7b817"><code>ff8117e</code></a>
ci: fix user-agent test to handle orchestration ID</li>
<li><a
href="https://github.com/actions/github-script/commit/81c6b7876079abe10ff715951c9fc7b3e1ab389d"><code>81c6b78</code></a>
ci: use deployment: false to suppress deployment noise from integration
tests</li>
<li><a
href="https://github.com/actions/github-script/commit/3953caf8858d318f37b6cc53a9f5708859b5a7b7"><code>3953caf</code></a>
docs: update README examples from <a
href="https://github.com/v8"><code>@​v8</code></a> to <a
href="https://github.com/v9"><code>@​v9</code></a>, add getOctokit docs
and v9 brea...</li>
<li><a
href="https://github.com/actions/github-script/commit/c17d55b90dcdb3d554d0027a6c180a7adc2daf78"><code>c17d55b</code></a>
ci: add getOctokit integration test job</li>
<li><a
href="https://github.com/actions/github-script/commit/a047196d9a02fe92098771cafbb98c2f1814e408"><code>a047196</code></a>
test: add getOctokit integration tests via callAsyncFunction</li>
<li>Additional commits viewable in <a
href="https://github.com/actions/github-script/compare/ed597411d8f924073f98dfc5c65a23a2325f34cd...3a2844b7e9c422d3c10d287c895573f7108da1b3">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=actions/github-script&package-manager=github_actions&previous-version=8.0.0&new-version=9.0.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)


</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-10-01 13:10:29 -07:00
dependabot[bot] 793a98cd8c chore(deps): bump open from 11.0.1 to 11.0.4 (#13473)
Bumps [open](https://github.com/sindresorhus/open) from 11.0.1 to
11.0.4.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/sindresorhus/open/releases">open's
releases</a>.</em></p>
<blockquote>
<h2>v11.0.4</h2>
<ul>
<li>Fix <code>browser</code>/<code>browserPrivate</code> not detecting
Safari or Brave as the default browser 6ae6196</li>
</ul>
<hr />
<p><a
href="https://github.com/sindresorhus/open/compare/v11.0.3...v11.0.4">https://github.com/sindresorhus/open/compare/v11.0.3...v11.0.4</a></p>
<h2>v11.0.3</h2>
<ul>
<li>Fix Windows launches being killed when the parent process exits
734b821</li>
</ul>
<hr />
<p><a
href="https://github.com/sindresorhus/open/compare/v11.0.2...v11.0.3">https://github.com/sindresorhus/open/compare/v11.0.2...v11.0.3</a></p>
<h2>v11.0.2</h2>
<ul>
<li>Update dependencies  6f006ad</li>
</ul>
<hr />
<p><a
href="https://github.com/sindresorhus/open/compare/v11.0.1...v11.0.2">https://github.com/sindresorhus/open/compare/v11.0.1...v11.0.2</a></p>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/sindresorhus/open/commit/41511103abd932225b605b8e7f9e565cc180b1b6"><code>4151110</code></a>
11.0.4</li>
<li><a
href="https://github.com/sindresorhus/open/commit/6ae6196fa199cbc5eb4af007efd52e675c53b590"><code>6ae6196</code></a>
Fix <code>browser</code>/<code>browserPrivate</code> not detecting
Safari or Brave as the default b...</li>
<li><a
href="https://github.com/sindresorhus/open/commit/81deafb72a29ea16b2c3bdd30cdaf294aaa11d77"><code>81deafb</code></a>
11.0.3</li>
<li><a
href="https://github.com/sindresorhus/open/commit/734b821c36ee959dc11e380c3202770969347274"><code>734b821</code></a>
Fix Windows launches being killed when the parent process exits</li>
<li><a
href="https://github.com/sindresorhus/open/commit/ccf1fd644de3dfc9448438e185037eceb2d5d3d7"><code>ccf1fd6</code></a>
11.0.2</li>
<li><a
href="https://github.com/sindresorhus/open/commit/52d2d62d6f02f023720f4ca5a2f73bf050ae3ee7"><code>52d2d62</code></a>
Use <code>hasOwn</code> (<a
href="https://redirect.github.com/sindresorhus/open/issues/372">#372</a>)</li>
<li><a
href="https://github.com/sindresorhus/open/commit/6f006ad1a80950ff0dd9eb7e3252634153e3ef12"><code>6f006ad</code></a>
Update dependencies</li>
<li>See full diff in <a
href="https://github.com/sindresorhus/open/compare/v11.0.1...v11.0.4">compare
view</a></li>
</ul>
</details>
<br />

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-10-01 13:00:29 -07:00
Michael NguyenandClaude Opus 5.5 b721d24cac fix(adapter-utils): retry GitHub broker transport failures before falling back (#14856)
## Thinking Path

> - Paperclip is the open source app people use to manage AI agents for
work
> - Agents run `git` and `gh` through a managed launcher. The launcher
gets a GitHub credential from the Paperclip control plane
> - The launcher sends one request to the credential broker for each
command
> - If that request fails at the transport level, for example after a
10-second timeout, the launcher continues without managed credentials
> - So a slow or restarting control plane removes the managed GitHub
identity from that command. Some agents then use other GitHub identities
that do not have the necessary permissions
> - This pull request retries a failed broker request two more times,
with a short backoff, before the launcher gives up
> - The benefit is that a short control-plane delay does not remove the
managed identity from an agent's GitHub operation

## Linked Issues or Issue Description

Refs #14175. That pull request changes the same broker request loop for
a different failure: sandbox network denials. The pull request that
merges second must rebase.

**What happened**
A Codex agent ran `git` and `gh` through the managed launcher while the
control plane was under heavy memory pressure. Each command printed
`Paperclip: GitHub broker_transport_unavailable; continuing without
managed credentials.` The agent then tried to open the pull request
through a different GitHub integration. GitHub rejected the request with
`403 Resource not accessible by integration`.

**Expected behavior**
A short broker delay or a short transport failure must not remove the
managed GitHub identity from the command. The launcher must try the
broker again before it continues without credentials.

**Steps to reproduce**
1. Set `PAPERCLIP_GITHUB_BROKER_URL` to a closed port.
2. Start a broker on that port after about 300 ms.
3. Run `gh` through the launcher.
4. Before this change, the launcher prints
`broker_transport_unavailable` and runs `gh` without the managed token.

**Version or commit**
`4ac374103` on master. Commit `3166e93a7` has the same code.

**Deployment mode**
Local trusted instance that runs as a launchd service, with
`codex_local` agents.

## What Changed

- `packages/adapter-utils/src/github-launcher.ts`: the broker request
loop now catches transport errors and retries up to two more times,
after 0.5 s and then after 1 s. The loop reads the response body inside
the retry, so a failed or slow body read is also retried. Busy (409)
responses keep their own budget of 30 attempts, separate from transport
retries. After the third transport failure, the launcher prints
`broker_transport_unavailable` as before.
- `packages/adapter-utils/src/github-launcher.test.ts`: two new tests
make the broker fail the first request and answer the second. In one,
the connection drops before the response. In the other, the connection
drops in the middle of the body. Each test checks that `gh` gets the
managed token, that the broker receives exactly two requests, and that
no `broker_transport_unavailable` message appears.
- The existing `broker-offline` test now has a 15-second timeout,
because each command now retries twice before it falls back.

## Verification

- `npx vitest run packages/adapter-utils/src/github-launcher.test.ts`: 9
of 9 tests pass.
- The body-read test fails on the first commit of this pull request and
passes with the second commit.
- `pnpm --filter @paperclipai/adapter-utils typecheck`: passes.
- The existing `broker-offline` test confirms that the launcher still
falls back after the retries, and that local Git still works.

## Risks

- When the broker is unreachable, each `git` or `gh` command now waits
about 1.5 s more before it continues without credentials. When the
broker times out, the worst case is about 31.5 s instead of 10 s.
- The change only adds retries. It does not change which credentials the
launcher accepts or which environment variables it copies.
- #14175 changes the same loop. The pull request that merges second
needs a small rebase.

> For core feature work, check [`ROADMAP.md`](ROADMAP.md) first and
discuss it in `#dev` before opening the PR. Feature PRs that overlap
with planned core work may need to be redirected — check the roadmap
first. See `CONTRIBUTING.md`.

## Model Used

- Anthropic Claude Opus 5.5 (`claude-opus-5-5`), used through Claude
Code with tool use: shell commands, file edits and test runs. The model
wrote the change, the test and this description. The repository owner
approved the change before it was made.

## Checklist

- [x] I have included a thinking path that traces from project context
to this change
- [x] I have specified the model used (with version and capability
details)
- [x] I have checked ROADMAP.md and confirmed this PR does not duplicate
planned core work
- [x] I have searched GitHub for duplicate or related PRs and linked
them above
- [x] I have either (a) linked existing issues with `Fixes: #` / `Closes
#` / `Refs #` OR (b) described the issue in-PR following the relevant
issue template
- [x] I have not referenced internal/instance-local Paperclip issues or
links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip`
URLs)
- [x] My branch name describes the change (e.g. `docs/...`, `fix/...`)
and contains no internal Paperclip ticket id or instance-derived details
- [x] I have run tests locally and they pass — *targeted tests and the
package typecheck; see Verification*
- [x] I have added or updated tests where applicable
- [ ] I have updated relevant documentation to reflect my changes — *no
documentation describes the broker retry*
- [x] I have considered and documented any risks above
- [ ] All Paperclip CI gates are green — *CI has not run yet*
- [ ] Greptile is 5/5 with no open P2s, recommendations, or follow-ups —
*Greptile has not reviewed yet*
- [x] I will address all Greptile and reviewer comments before
requesting merge

🤖 Generated with [Claude Code](https://claude.com/claude-code)

---------

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
2026-10-01 12:57:41 -07:00
DottaandPaperclip 8ec4b84e1c fix(chat): resume messages after failed runs without duplicate delivery (#14857)
## Thinking Path

> - Paperclip is the open source app people use to manage AI agents for
work.
> - A user can send a new message after a native run fails.
> - The server checks that the old execution has stopped before it
starts a fresh turn.
> - A failed run can retain a result accepted before checkpoint or
cleanup failed.
> - The continuation gate treated that saved result as active recovery
and held the new message forever.
> - This pull request removes that false liveness signal while retaining
controller, process, environment, and authorization checks.
> - Live staging then exposed a second defect: chat admission created a
successor without consuming the original deferred receipt, so completion
delivered the message again.
> - Consume that exact receipt atomically with admission, while
preserving separate turns for later chat messages.

## Linked Issues or Issue Description

**What happened?**

A new user message stayed in the queue with `controller_settling` after
the previous run had reached `terminal_failure`. The old coordinator had
no lease owner but still had a `resultId`. Its remote environment had a
verified stop receipt.

**Expected behavior**

Start one fresh turn after execution has stopped and normal admission
checks pass. Preserve the failed run and its accepted result as history.

**Steps to reproduce**

1. Accept a native result, then fail checkpoint or cleanup and exhaust
recovery.
2. Retain the result ID on the terminal failure record and stop the
execution environment.
3. Send a new user message. Before this fix, it waits forever for the
finished controller.

**Paperclip version or commit**

Reproduced in a database-backed regression test on `26900655b`.

**Deployment mode**

Server with a native runner and remote sandbox. Local process stop
checks also apply.

Related: https://github.com/paperclipai/paperclip/pull/14775. Searched
existing PRs for retained-result continuation fixes; no duplicate found.

## What Changed

- Remove the retained-result veto for terminal failures.
- Keep controller ownership, successor, process, environment cleanup,
pending decision, and ordinary admission checks.
- Add regressions for retained results, active execution, missing stop
evidence, and delayed remote cleanup.
- Atomically consume the resumed receipt in agent chat, even though chat
does not coalesce other queued messages.
- Reproduce completion-time duplicate promotion, race cleanup against
periodic recovery, and prove a subsequent chat message keeps its own
turn.
- Document that a saved result does not make a terminal failure active.
- Keep exhausted workspace export on its separate repair path, tested
through the production finalizer.

## Verification

- Red: retained-result admission failed with `controller_settling`
before the original fix. The new chat-specific regression then
reproduced duplicate promotion when the first reply finished.
- Green: 406 tests across native continuation, workspace-export
recovery, and the wake-queue module passed on `cbc531cc0`.
- The chat regressions exercise real Postgres transactions, simultaneous
recovery callbacks, successful completion, the production queue-drain
use case, and repeated drain attempts. A distinct follow-up remains a
separate turn.
- `pnpm -r typecheck` and `pnpm build` passed on `cbc531cc0`.
- The earlier full local test run encountered a timeout and follow-on
failure in unchanged AI connection-adoption tests; all 50 tests passed
on isolated rerun. That local run was stopped after the full CI test
matrix passed on the earlier head.
- All 54 CI checks passed on `cbc531cc0` (2 skipped), including the full
test matrix and browser shards. One unchanged interaction-route test
returned HTTP 500 on its first CI attempt; its full 84-test file passed
locally, and the failed shard passed on one targeted rerun.
- Greptile reviewed `cbc531cc0`: 5/5, no unresolved findings.
- Live staging first verified that the original saved message resumes
and receives a successful response; that test exposed the duplicate now
covered above.
- Deployed exact commit `cbc531cc0410e1ef6e8811c6c5c014c3528351ed` to
the affected staging workspace; deployment verification, health,
authentication, and startup recovery passed.
- Submitted a fresh message through the browser. The agent replied in 39
seconds; server records show exactly one successful run, native phase
`committed`, no error, and an empty queue. A later check more than a
minute after completion found no duplicate run.

## Risks

The change affects admission after native execution failure and
consumption of a resumed deferred receipt. A fresh turn must never
overlap the prior execution, and consuming one chat receipt must not
absorb later messages. Tests retain the controller, process, and
remote-stop guards. This change does not migrate data, apply an old
result, or reset the old retry budget.

## Model Used

OpenAI Codex (GPT-6). The exact runtime model identifier and context
window are not exposed in this session. Used reasoning, repository
inspection, code execution, database-backed tests, and browser
inspection.

## Checklist

- [x] I have included a thinking path that traces from project context
to this change
- [x] I have specified the model used (with version and capability
details)
- [x] I have checked ROADMAP.md and confirmed this PR does not duplicate
planned core work
- [x] I have searched GitHub for duplicate or related PRs and linked
them above
- [x] I have either (a) linked existing issues with `Fixes: #` / `Closes
#` / `Refs #` OR (b) described the issue in-PR following the relevant
issue template
- [x] I have not referenced internal/instance-local Paperclip issues or
links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip`
URLs)
- [x] My branch name describes the change (e.g. `docs/...`, `fix/...`)
and contains no internal Paperclip ticket id or instance-derived details
- [x] I have run tests locally and they pass
- [x] I have added or updated tests where applicable
- [x] I have updated relevant documentation to reflect my changes
- [x] I have considered and documented any risks above
- [x] All Paperclip CI gates are green
- [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups
- [x] I will address all Greptile and reviewer comments before
requesting merge

---------

Co-authored-by: Paperclip <noreply@paperclip.ing>
canary/v2026.1001.0-canary.6
2026-10-01 14:43:02 -05:00
Devin FoleyandPaperclip dd9983b894 fix(adapter-utils): release restore locks when a process crashes (#14869)
## Thinking Path

> - Paperclip is the open source app people use to manage AI agents for
work.
> - Agent runs restore workspace files and collect instruction-file
changes.
> - Writers to the same target directory must wait for each other.
> - The current lock records a PID, which a new process can reuse after
a crash.
> - A reused PID can keep an orphaned lock alive and make each later run
fail.
> - This pull request makes a SQLite file lock decide ownership. The OS
releases it when the process exits.
> - Later runs can proceed after a crash, and concurrent live writers
remain protected.

## Linked Issues or Issue Description

Refs #10914. This addresses crash recovery. It does not cancel a stalled
operation in a process that is still alive.

Related work: #9667, #14787, and #12187. The earlier attempt in #9667
assumes one live server per lock root. This implementation uses an
OS-backed lock to support concurrent writers without treating a
different process token or an old timestamp as proof of a dead owner. It
retains the private lock root and bounded timeout diagnostics from the
merged changes.

After a process dies while holding a restore lock, a replacement process
can reuse its PID. The existing `process.kill(pid, 0)` check then
reports a live owner forever. Later runs can complete their model turn
but fail during file collection or restore.

## What Changed

- Hold a SQLite `BEGIN IMMEDIATE` transaction for each directory write.
Use the existing built-in `node:sqlite` dependency.
- Keep each lock database on a stable inode. Keep PID and time metadata
only for diagnostics.
- Retain the 30-second asynchronous wait and existing timeout error code
and diagnostic fields.
- Fail closed when an old directory lock exists. Document a
stopped-writer upgrade and rollback procedure.
- Add real child-process tests for crashes, PID reuse, live owners, and
connection cleanup. Cover callback failures, independent targets, stable
inodes, invalid lock files, and ambiguous legacy records.

## Verification

- Before the fix, the crash/PID-reuse test and the live-owner test both
failed. Both pass with this change.
- `pnpm exec vitest run
packages/adapter-utils/src/directory-merge-lock.test.ts
packages/adapter-utils/src/workspace-restore-merge.test.ts`: 56 tests
passed.
- Restore and agent-file working-copy integration tests: 118 tests
passed before the additional connection-cleanup test.
- `pnpm -r typecheck`: passed.
- `pnpm build`: passed.
- Full GitHub CI: all checks passed, including Linux workspace tests,
server test shards, build, typecheck, and browser tests.
- Greptile: 5/5, with no review threads or unresolved comments.
- `pnpm test:run`: started locally, then stopped with SIGINT (exit 130)
after full CI passed. The local serial run did not complete and is not
counted as a full local pass. The completed CI shards provide the
full-suite result.

## Risks

- **Upgrade and rollback require a drain.** Stop every old writer that
shares an instance root before switching protocols. Old and new versions
must not write concurrently.
- Existing legacy `.lock/` directories remain blocking. After all
writers stop, preserve run evidence and move those directories to an
operator scratch directory. The new code does not infer that they are
abandoned from PID or age.
- Never delete or replace a `.lock.sqlite` file while writers can run.
These small files remain after release.
- The shared filesystem must support reliable SQLite locking. Broken
network-filesystem locking is unsupported.
- This change prevents new orphaned ownership. It does not recover file
changes lost during earlier failed collections, or interrupt a live
operation that stalls.
- No application database migration or new native dependency is
required. See `doc/workspace-restore-locks.md` for the procedure.

## Model Used

OpenAI Codex based on GPT-6, with code execution and repository tools.
The exact model variant and context window are not exposed in this
session.

## Checklist

- [x] I have included a thinking path that traces from project context
to this change
- [x] I have specified the model used (with version and capability
details)
- [x] I have checked ROADMAP.md and confirmed this PR does not duplicate
planned core work
- [x] I have searched GitHub for duplicate or related PRs and linked
them above
- [x] I have either (a) linked existing issues with `Fixes: #` / `Closes
#` / `Refs #` OR (b) described the issue in-PR following the relevant
issue template
- [x] I have not referenced internal/instance-local Paperclip issues or
links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip`
URLs)
- [x] My branch name describes the change (e.g. `docs/...`, `fix/...`)
and contains no internal Paperclip ticket id or instance-derived details
- [x] I have run tests locally and they pass (focused regression and
integration suites; see the full-suite note above)
- [x] I have added or updated tests where applicable
- [x] I have updated relevant documentation to reflect my changes
- [x] I have considered and documented any risks above
- [x] All Paperclip CI gates are green
- [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups
- [x] I will address all Greptile and reviewer comments before
requesting merge

Co-authored-by: Paperclip <noreply@paperclip.ing>
canary/v2026.1001.0-canary.5
2026-10-01 12:14:48 -07:00
dependabot[bot] 8f7baf2f72 chore(deps): bump @aws-sdk/client-s3 from 3.1122.0 to 3.1141.0 (#13475)
Bumps
[@aws-sdk/client-s3](https://github.com/aws/aws-sdk-js-v3/tree/HEAD/clients/client-s3)
from 3.1122.0 to 3.1141.0.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/aws/aws-sdk-js-v3/releases">@​aws-sdk/client-s3's
releases</a>.</em></p>
<blockquote>
<h2>v3.1141.0</h2>
<h4>3.1141.0(2026-09-25)</h4>
<h5>Chores</h5>
<ul>
<li><strong>codegen:</strong> smithy-aws-typescript-codegen 0.54.0 (<a
href="https://redirect.github.com/aws/aws-sdk-js-v3/pull/8314">#8314</a>)
(<a
href="https://github.com/aws/aws-sdk-js-v3/commit/ad80ce3ebaf394679aabc6e26b2dcd023ce8e010">ad80ce3e</a>)</li>
</ul>
<h5>New Features</h5>
<ul>
<li><strong>client-connect:</strong> Agent Privacy During Hold is a new
privacy capability for Amazon Connect Voice that prevents agent audio
from being captured in call recordings or Contact Lens conversational
analytics during hold. When enabled, agents are automatically muted on
entering hold and unmuted on resuming the contact (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/03527f9ea153365c1e3654ac6d3f3e064d06b5d0">03527f9e</a>)</li>
<li><strong>client-qconnect:</strong> Release shapes for the proactive
agentic recommendations and the multi-knowledge base search features.
Increases the maximum length of QuickResponseContent. (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/e008332b0b70c55d22dfca8a9c2317b67d06a5f3">e008332b</a>)</li>
<li><strong>client-bedrock-agent:</strong> Adds support for calling VPC
configuration API's in Bedrock. These configurations allow the use of On
Prem connectors in Bedrock Managed Knowledge bases (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/18524dc69cf36ebbb8bc7bc33e0bce6311dcdb23">18524dc6</a>)</li>
<li><strong>client-mediaconnect:</strong> This release adds support for
RTMP push router outputs in AWS Elemental MediaConnect. (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/5bd8d80bbca2c1c2545521b03d741b46fccd09b4">5bd8d80b</a>)</li>
<li><strong>client-securityagent:</strong> This release adds the
ListActorMessages operation, which returns the multi-factor
authentication messages received at an actor's server-generated email
address (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/10e53d506db74c48b09b94d9b9387b84dd40ed58">10e53d50</a>)</li>
<li><strong>client-arc-region-switch:</strong> Adds a service quota
checker to Region switch to verify quota parity between your primary and
standby Region, and automatically submit quota limit increases. Adds an
optional EC2 Auto Scaling and ECS setting that waits for instances or
tasks in the scaled-up Region to be healthy in target groups. (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/cca33e380a8985e23a0e3fbb420577aab4b60ac7">cca33e38</a>)</li>
<li><strong>client-bedrock-agentcore-control:</strong> Amazon Bedrock
AgentCore Payments now supports credential rotation for payment
connectors, letting you rotate API and wallet secrets for Quick Create
payment auths from the console. This release also adds Type and Creation
type columns to the payment managers views. (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/adca591f07c448603de2876faaf7914cad441436">adca591f</a>)</li>
<li><strong>client-neptune-graph:</strong> Add GraphIdentifier filter
for ListImportTasks (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/9b9aea9b553ba84f006f95da5d8ffd5381cc8a17">9b9aea9b</a>)</li>
<li><strong>client-rekognition:</strong> This release adds support for
Feedback and Metadata in the GetFaceLivenessSessionResults response.
Feedback returns codes explaining why a Face Liveness check produced its
result. Metadata includes the client SDK type. (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/0831c361bb69d44357ff57360db39afdbb149337">0831c361</a>)</li>
<li><strong>client-glue:</strong> add support for table level federation
(<a
href="https://github.com/aws/aws-sdk-js-v3/commit/a44458b77853cbb25a9fcb362b0a275d7dc1c69b">a44458b7</a>)</li>
<li><strong>client-wellarchitected:</strong> This change releases the
Well-Architected Agent, a generative AI service that analyzes a
customer's AWS environment and delivers personalized, prioritized
recommendations across cost, security, performance, and resilience. (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/d0656586067f70b8d50000300f04512dd089df96">d0656586</a>)</li>
</ul>
<hr />
<p>For list of updated packages, view
<strong>updated-packages.md</strong> in
<strong>assets-3.1141.0.zip</strong></p>
<h2>v3.1140.0</h2>
<h4>3.1140.0(2026-09-24)</h4>
<h5>Documentation Changes</h5>
<ul>
<li><strong>client-route53resolver:</strong> Documentation updates for
Route 53 Resolver. Clarifies which Outpost Resolver operations apply to
first-generation AWS Outposts and that Resolver is managed automatically
on second-generation Outposts. Adds Local Network Interface subnet
compatibility notes for Resolver endpoints. (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/b4432abaaaf19bf4ac5d4d2b09bcc83e4d5440a0">b4432aba</a>)</li>
<li><strong>client-iot:</strong> Fixed ListV2LoggingLevels and
DeleteV2LoggingLevel documentation to include all supported target-types
(<a
href="https://github.com/aws/aws-sdk-js-v3/commit/4dcf76d527e0c1fe76d64cb8ea444ce62d64135b">4dcf76d5</a>)</li>
</ul>
<h5>New Features</h5>
<ul>
<li><strong>clients:</strong> update client endpoints as of 2026-09-24
(<a
href="https://github.com/aws/aws-sdk-js-v3/commit/29a8566cb4c6eeb0cc554f4ae9bf985160556523">29a8566c</a>)</li>
<li><strong>client-eventbridgev2:</strong> Introducing Amazon
EventBridge enhanced Custom event bus, a new shareable event bus for
organizational-scale event-driven applications feature ordered delivery,
deduplication, open event formats, and cross-account bus sharing. (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/69fbe6a22fd7810332b0b0356803a0eee3f563cf">69fbe6a2</a>)</li>
<li><strong>client-datazone:</strong> Amazon DataZone now supports the
TOOLING blueprint category on CreateEnvironmentBlueprint,
UpdateEnvironmentBlueprint, GetEnvironmentBlueprint, and
ListEnvironmentBlueprints, for custom tooling blueprints.
CreateConnection now accepts roleArn in iamProperties. (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/591cd6f5a7b714427cbe87b36b13357d560d48ea">591cd6f5</a>)</li>
<li><strong>client-elasticache:</strong> Added tagging support for
ElastiCache Global DataStore. (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/0fa9da5946312f09942dad6f711885855f0d0b8e">0fa9da59</a>)</li>
<li><strong>client-marketplace-discovery:</strong> AWS Marketplace
Discovery API now supports localized responses and SigV4a request
signing. It returns new fulfillment details, including AMI architecture,
EBS volume and security group information, SaaS quick-launch status, and
SageMaker input and output MIME types. (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/510673e376bbc578d318308136ecb5a841416bc3">510673e3</a>)</li>
<li><strong>client-redshift-data:</strong> Updates to the ListDatabases
and WorkgroupName validation (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/218c24e106efe1ad64658984123af6634fc7278d">218c24e1</a>)</li>
<li><strong>client-securityagent:</strong> Added support for Confluence
export, enabling customers to publish security findings to Confluence
pages. (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/81408527778af52f0c604a4eaca440f445082f78">81408527</a>)</li>
<li><strong>client-cloudwatch:</strong> This release adds Create, Get,
Update, and DeleteResourceMetricsConfiguration to enable detailed metric
collection for an AWS resource, and adds UpdateOTelEnrichment plus
include and exclude filters on StartOTelEnrichment so you can choose
which metric namespaces CloudWatch enriches. (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/765cc1ce8f95a4f62d83dc07b81a927d74e09b52">765cc1ce</a>)</li>
<li><strong>client-eventbridge:</strong> Adds a ManagedBy field to the
DescribeEventBus and ListEventBuses responses, identifying the AWS
service that created an event bus on your behalf. (<a
href="https://github.com/aws/aws-sdk-js-v3/commit/28a639b27585c85376a4b5db528c31efb80e874d">28a639b2</a>)</li>
</ul>
<h5>Tests</h5>
<ul>
<li><strong>undici-http-handler:</strong> update bidi stream e2e test to
nova-2-sonic model (<a
href="https://redirect.github.com/aws/aws-sdk-js-v3/pull/8313">#8313</a>)
(<a
href="https://github.com/aws/aws-sdk-js-v3/commit/d9a37d9d318f2ef7f5bcf6286bf3c7b475e4175b">d9a37d9d</a>)</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/aws/aws-sdk-js-v3/blob/main/clients/client-s3/CHANGELOG.md">@​aws-sdk/client-s3's
changelog</a>.</em></p>
<blockquote>
<h1><a
href="https://github.com/aws/aws-sdk-js-v3/compare/v3.1140.0...v3.1141.0">3.1141.0</a>
(2026-09-25)</h1>
<p><strong>Note:</strong> Version bump only for package
<code>@​aws-sdk/client-s3</code></p>
<h1><a
href="https://github.com/aws/aws-sdk-js-v3/compare/v3.1139.0...v3.1140.0">3.1140.0</a>
(2026-09-24)</h1>
<p><strong>Note:</strong> Version bump only for package
<code>@​aws-sdk/client-s3</code></p>
<h1><a
href="https://github.com/aws/aws-sdk-js-v3/compare/v3.1138.0...v3.1139.0">3.1139.0</a>
(2026-09-23)</h1>
<p><strong>Note:</strong> Version bump only for package
<code>@​aws-sdk/client-s3</code></p>
<h1><a
href="https://github.com/aws/aws-sdk-js-v3/compare/v3.1137.0...v3.1138.0">3.1138.0</a>
(2026-09-22)</h1>
<p><strong>Note:</strong> Version bump only for package
<code>@​aws-sdk/client-s3</code></p>
<h1><a
href="https://github.com/aws/aws-sdk-js-v3/compare/v3.1136.0...v3.1137.0">3.1137.0</a>
(2026-09-21)</h1>
<p><strong>Note:</strong> Version bump only for package
<code>@​aws-sdk/client-s3</code></p>
<h1><a
href="https://github.com/aws/aws-sdk-js-v3/compare/v3.1135.0...v3.1136.0">3.1136.0</a>
(2026-09-18)</h1>
<p><strong>Note:</strong> Version bump only for package
<code>@​aws-sdk/client-s3</code></p>
<h1><a
href="https://github.com/aws/aws-sdk-js-v3/compare/v3.1134.0...v3.1135.0">3.1135.0</a>
(2026-09-17)</h1>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/aws/aws-sdk-js-v3/commit/5bc8d9a96936723ac90d721e0c5a2bff7ee8520d"><code>5bc8d9a</code></a>
Publish v3.1141.0</li>
<li><a
href="https://github.com/aws/aws-sdk-js-v3/commit/6050a3813c26795562b5ada8b0d9ea498eb9f8a1"><code>6050a38</code></a>
Publish v3.1140.0</li>
<li><a
href="https://github.com/aws/aws-sdk-js-v3/commit/03d54a858f80012bbc60046a77242223e8dfd9d9"><code>03d54a8</code></a>
Publish v3.1139.0</li>
<li><a
href="https://github.com/aws/aws-sdk-js-v3/commit/c68e50e4a6e0469a20c2894fe8a29c140553ebb8"><code>c68e50e</code></a>
Publish v3.1138.0</li>
<li><a
href="https://github.com/aws/aws-sdk-js-v3/commit/9a104768684e8f22d4373fcc5d910711e62676d6"><code>9a10476</code></a>
chore(codegen): sync for MetricsRecorder support and core error/retry
fixes (...</li>
<li><a
href="https://github.com/aws/aws-sdk-js-v3/commit/6b432472f9bdf5437319b9186f706e3af5c9a748"><code>6b43247</code></a>
Publish v3.1137.0</li>
<li><a
href="https://github.com/aws/aws-sdk-js-v3/commit/d6b94db8f4a00cc452dbe0aacb247e8ece3897ea"><code>d6b94db</code></a>
Publish v3.1136.0</li>
<li><a
href="https://github.com/aws/aws-sdk-js-v3/commit/2d5f18d08aa373d95692d83cb3d60a6a79248fae"><code>2d5f18d</code></a>
Publish v3.1135.0</li>
<li><a
href="https://github.com/aws/aws-sdk-js-v3/commit/0d6310bf6979ddbf737a7e15cfd8d0e7cec07063"><code>0d6310b</code></a>
Publish v3.1134.0</li>
<li><a
href="https://github.com/aws/aws-sdk-js-v3/commit/615a1ca4661ec0e4cb34b8da89fe60c2419b94d0"><code>615a1ca</code></a>
Publish v3.1133.0</li>
<li>Additional commits viewable in <a
href="https://github.com/aws/aws-sdk-js-v3/commits/v3.1141.0/clients/client-s3">compare
view</a></li>
</ul>
</details>
<br />

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
canary/v2026.1001.0-canary.4
2026-10-01 11:13:22 -07:00
DottaandPaperclip efc2e6810e fix: show each task once in dashboard agent cards (#14847)
## Thinking Path

> - Paperclip helps people manage AI agents and their tasks.
> - The dashboard shows recent agent activity in compact cards.
> - Those cards use run records, so two runs for one task can create
duplicate task cards.
> - An operator needs to see each task once when scanning the dashboard.
> - This pull request selects one run per linked task before it applies
the card limit.
> - The live runs page still shows each run for run inspection.

## Linked Issues or Issue Description

**What happened?**

The dashboard showed the same task in two agent cards when that task had
both an active run and a completed run.

**Expected behavior**

The dashboard should show a linked task at most once. It should keep the
active run card when one is present.

**Steps to reproduce**

1. Start an agent run for a task that already has a completed run.
2. Open the company dashboard.
3. Observe two cards linked to the same task.

**Paperclip version or commit**

Reproduced on the pre-change master at `8b4aa0692`.

**Deployment mode**

Local dev, built from source. The bug is in the core dashboard UI and
does not depend on an agent adapter or database mode.

## What Changed

- Select distinct linked tasks from capped active and recent run samples
before applying the dashboard card limit.
- Keep separate cards for runs without a linked task.
- Preserve the dashboard's count of additional distinct cards behind the
live-runs link.
- Add UI and embedded Postgres regression tests for duplicate runs and
document the dashboard rule.
- Give the existing multi-request cross-tenant authorization test enough
time on loaded CI runners.

## Verification

- `pnpm --filter @paperclipai/ui exec vitest run
src/components/ActiveAgentsPanel.test.tsx`
- `pnpm --filter @paperclipai/ui exec vitest run
src/api/heartbeats.test.ts`
- `pnpm exec vitest run server/src/__tests__/dashboard-service.test.ts
server/src/__tests__/agent-live-run-routes.test.ts`
- `pnpm exec vitest run
server/src/__tests__/agent-cross-tenant-authz-routes.test.ts`
- `pnpm --filter @paperclipai/ui typecheck`
- `pnpm --filter @paperclipai/server typecheck`
- `pnpm --filter @paperclipai/ui build`
- `pnpm -r typecheck`
- `pnpm build`
- `pnpm check:token-gates`
- Review the dashboard with an active and a completed run on the same
task. Confirm that it shows one card. Open Live agent runs to inspect
both run records.

## Risks

- A very high volume of recent runs for one task can fill the capped
sample and leave older tasks off the dashboard. The Live runs page
remains available for full run inspection.
- The dashboard may fetch up to 50 distinct run representatives to
preserve its overflow count. The default run API response and persisted
data are unchanged.

> For core feature work, check [`ROADMAP.md`](ROADMAP.md) first and
discuss it in `#dev` before opening the PR. Feature PRs that overlap
with planned core work may need to be redirected — check the roadmap
first. See `CONTRIBUTING.md`.

## Model Used

- OpenAI Codex, GPT-6. The runtime does not expose the exact model ID or
context window size to this task. The model used reasoning, tool calls,
and code execution.

## Checklist

- [x] I have included a thinking path that traces from project context
to this change
- [x] I have specified the model used (with version and capability
details)
- [x] I have checked ROADMAP.md and confirmed this PR does not duplicate
planned core work
- [x] I have searched GitHub for duplicate or related PRs and linked
them above
- [x] I have either (a) linked existing issues with `Fixes: #` / `Closes
#` / `Refs #` OR (b) described the issue in-PR following the relevant
issue template
- [x] I have not referenced internal/instance-local Paperclip issues or
links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip`
URLs)
- [x] My branch name describes the change (e.g. `docs/...`, `fix/...`)
and contains no internal Paperclip ticket id or instance-derived details
- [x] I have run tests locally and they pass
- [x] I have added or updated tests where applicable
- [x] I have updated relevant documentation to reflect my changes
- [x] I have considered and documented any risks above
- [x] All Paperclip CI gates are green
- [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups
- [x] I will address all Greptile and reviewer comments before
requesting merge

---------

Co-authored-by: Paperclip <noreply@paperclip.ing>
2026-10-01 12:18:35 -05:00
Devin FoleyandPaperclip 6f2ce27ca7 fix(workspaces): prepare checkouts without a local seed config (#14810)
## Thinking Path

> - Paperclip is the open source app people use to manage AI agents for
work.
> - Task preparation can create an isolated Git worktree and run its
setup script.
> - The Paperclip repository setup script also prepares a seeded
development instance.
> - A server configured through environment variables can have no local
seed config.
> - This stops ordinary task preparation before the agent starts.
> - This pull request prepares checkout dependencies when no seed source
exists, while preserving errors for invalid sources and existing
development instances.
> - Tasks can start without creating or claiming a seeded development
runtime.

## Linked Issues or Issue Description

**What happened?**

A task with the Paperclip repository fails during setup when the host
has no repository-local or default instance config. The automatic
worktree provisioner requires a seed source even when the task only
needs the checkout.

**Expected behavior**

A plain checkout should prepare its dependencies without a local
development database. A missing custom source, invalid source path, or
existing development instance with a missing source should still fail.
Starting a seeded runtime must still require a valid source.

**Steps to reproduce**

1. Run an environment-configured Paperclip server without a local
instance config.
2. Add the Paperclip repository to a project.
3. Start a task that uses an isolated Git worktree without a custom
provision command.
4. Observe the setup error before agent execution.

**Paperclip version or commit**

Reproduced against `0d3e7bf6ac` with a real script subprocess and
workspace realization regression.

**Deployment mode**

Environment-configured server with external PostgreSQL.

**Additional context**

Searched open and closed GitHub PRs and issues. Related work: Refs
#14795 (seed-source diagnostics) and Refs #11733 (source validation).
This change keeps source validation and seed-readiness checks in place.

## What Changed

- Permit dependency setup when the default seed config is absent
(including the Docker image config path) and the worktree has no
development-instance state.
- Keep missing custom configs, invalid paths, and lost sources for
existing instances as errors.
- Create no config, environment file, or seed manifest for a plain
checkout.
- Keep dependency install failures visible and allow normal instance
setup once a source becomes available.
- Cover the setup script, seed-runtime refusal, and automatic server
worktree realization.
- Document the difference between checkout preparation and
seeded-runtime readiness.

## Verification

- Regression tests failed before the fix for absent-source checkout
preparation and dependency setup.
- `bash -n scripts/provision-worktree.sh`
- `node --test scripts/__tests__/provision-worktree-self-heal.test.mjs`
— 34 passed; 1 existing flock-dependent test skipped on macOS.
- Server regression — 2 passed, covering an unset config and the Docker
image default path.
- `pnpm build` — passed.
- `pnpm -r typecheck` — passed.
- All CI checks passed, including the full test shards, build,
typecheck, browser tests, and canary dry run.
- The first local `pnpm test:run` encountered two chat-test failures
because skill discovery selected an unrelated parent directory. Both
tests pass at the PR commit in a clean temporary checkout. The full
local run was not completed; the redundant clean run was stopped after
the complete CI suite passed.
- `git diff --check` and added-line secrets/PII scan passed.
- Greptile: 5/5, no comments. The branch has no merge conflicts.
- No live tenant deployment or task retry was performed.

## Risks

- A new checkout with no implicit seed config now completes dependency
setup. It has no seeded development instance. A runtime request still
fails until a valid source exists.
- Existing instances and custom source paths retain their failure
behavior. The script does not synthesize a source from environment
credentials or copy a live database.
- No schema, API, or task-setting changes. Revert the commit to restore
the previous setup behavior.

## Model Used

OpenAI Codex (GPT-6), with tool-assisted analysis, code edits, and local
tests. The runtime did not expose a verified model variant or
context-window size.

## Checklist

- [x] I have included a thinking path that traces from project context
to this change
- [x] I have specified the model used (with version and capability
details)
- [x] I have checked ROADMAP.md and confirmed this PR does not duplicate
planned core work
- [x] I have searched GitHub for duplicate or related PRs and linked
them above
- [x] I have either (a) linked existing issues with `Fixes: #` / `Closes
#` / `Refs #` OR (b) described the issue in-PR following the relevant
issue template
- [x] I have not referenced internal/instance-local Paperclip issues or
links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip`
URLs)
- [x] My branch name describes the change (e.g. `docs/...`, `fix/...`)
and contains no internal Paperclip ticket id or instance-derived details
- [x] I have run tests locally and they pass
- [x] I have added or updated tests where applicable
- [x] I have updated relevant documentation to reflect my changes
- [x] I have considered and documented any risks above
- [x] All Paperclip CI gates are green
- [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups
- [x] I will address all Greptile and reviewer comments before
requesting merge

Co-authored-by: Paperclip <noreply@paperclip.ing>
2026-10-01 10:00:25 -07:00
DottaandPaperclip 6d654f63d1 feat(apps): make MCP action test results readable (#14859)
## Thinking Path

> - Paperclip is the open source app people use to manage AI agents for
work.
> - Connected Apps let an operator control which MCP actions an agent
can use.
> - The Permissions page lets the operator run a real action as an
agent.
> - The Test dialog displayed the nested MCP response as escaped JSON.
> - A useful result was hard to read, even when the action worked.
> - This pull request renders known MCP content as a readable preview
and keeps the raw response available.
> - The benefit is faster validation without losing the data needed to
diagnose a failure.

## Linked Issues or Issue Description

**What existing behavior does this improve?**

The per-action Test dialog on a connection's Permissions page.

**Subsystem affected**

ui/ — React board UI.

**Current behavior**

The dialog shows the gateway response as an escaped JSON blob. Text
content that contains JSON stays inside a string. The obsolete
connection Test page also keeps a separate set of stories.

**Proposed behavior**

The dialog uses structured MCP content when present. It parses JSON text
blocks when possible. It shows compact tables, cards, fields, or plain
text. It keeps the full raw response behind a control and opens that
view for errors or unknown block shapes. Stories exercise the
Permissions page dialog, and the obsolete Test page and stories are
removed.

**Reason and benefit**

An operator can inspect a successful action result at a glance and still
inspect the exact gateway response when a call fails or looks wrong.

**Breaking changes**

No API or stored data changes. The Test dialog presentation changes. The
raw response stays available.

**Additional context**

I tested a read-only Notion search through the real Permissions page.
The dialog showed three result cards and the raw response control
worked. Storybook uses invented example data.

No directly matching public issue or open PR was found in the GitHub
search.

## What Changed

- Render structured MCP output and JSON text content in the action Test
dialog.
- Show wide rows as cards, keep short rows as tables, and retain the raw
response for diagnosis.
- Remove the obsolete connection Test page and its stories.
- Add focused dialog tests and Permissions page Storybook cases for
success, errors, mixed blocks, and malformed blocks.
- Document the Test dialog result behavior in the connection playbook.
- Keep agent mention icons visible when the Lucide icon node is
unavailable in server rendering, which repaired a repeatable CI failure.

## Verification

- `pnpm -r typecheck` — passed.
- `pnpm exec vitest run --project @paperclipai/ui` — passed (7,111
tests).
- `pnpm exec vitest run
ui/src/pages/apps/app-detail/ActionTestDialog.test.tsx` — passed (11
tests).
- `pnpm exec vitest run --project @paperclipai/ui
ui/src/components/MarkdownBody.test.tsx` — passed (53 tests).
- `pnpm test:run` — started, then stopped after the review fixes changed
the head; the full sharded suite passed in CI.
- `pnpm build` — passed.
- `pnpm check:token-gates` — passed.
- Use a connected MCP app. Open Permissions, select a read action, and
run Test. Inspect the preview and the raw response control.

## Risks

- MCP tools can return provider-specific block shapes. Unknown blocks
open the raw response so the operator can inspect the exact result.
- Row and field previews limit visible data. The raw response preserves
the complete result.

> This is a targeted improvement to the existing Connected Apps item in
`ROADMAP.md`.

## Model Used

OpenAI Codex, GPT-6. The session used tool access, code execution, and
browser validation. The exact deployment ID and context window were not
exposed to the session.

## Checklist

- [x] I have included a thinking path that traces from project context
to this change
- [x] I have specified the model used (with version and capability
details)
- [x] I have checked ROADMAP.md and confirmed this PR does not duplicate
planned core work
- [x] I have searched GitHub for duplicate or related PRs and linked
them above
- [x] I have either (a) linked existing issues with `Fixes: #` / `Closes
#` / `Refs #` OR (b) described the issue in-PR following the relevant
issue template
- [x] I have not referenced internal/instance-local Paperclip issues or
links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip`
URLs)
- [x] My branch name describes the change (e.g. `docs/...`, `fix/...`)
and contains no internal Paperclip ticket id or instance-derived details
- [x] I have run tests locally and they pass
- [x] I have added or updated tests where applicable
- [x] I have updated relevant documentation to reflect my changes
- [x] I have considered and documented any risks above
- [x] All Paperclip CI gates are green
- [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups
- [x] I will address all Greptile and reviewer comments before
requesting merge

---------

Co-authored-by: Paperclip <noreply@paperclip.ing>
2026-10-01 11:52:26 -05:00
DottaandPaperclip 527e146980 feat(ui): share animated agent setup prompts (#14862)
Use the shared animated prompt-copy control across setup, invitations, webhooks, and task handoffs. Preserve first-click copying, clipboard recovery, and logo continuity. Add Storybook coverage and restore mention icon masks for the current Lucide data shape.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
canary/v2026.1001.0-canary.3
2026-10-01 11:46:14 -05:00
DottaandPaperclip 6395cae072 fix(runner): ship provider pack in the standard Docker image (#14854)
## Thinking Path

> - Paperclip is the open source app people use to manage AI agents for
work.
> - Remote OpenCode and ACPX runs need a provider pack from the
application build.
> - Cloud now builds its application image from the standard production
image.
> - The provider pack was added only to the legacy cloud image target.
> - The standard image therefore cannot supply the pack to downstream
Cloud images.
> - This pull request adds the pack to the production image and lets the
cloud target inherit it.
> - Remote runs can then use the pack that matches the application
source commit.

## Linked Issues or Issue Description

Refs #13827. Refs #14024.

The standard production image does not include the remote provider pack.
Downstream Cloud images inherit that omission. Remote OpenCode and ACPX
runs fail with `runner_remote_provider_artifact_incompatible` and ask
for `PAPERCLIP_RUNNER_REMOTE_PROVIDER_PACK_PATH`.

## What Changed

- Build and copy the provider pack into the standard production image.
- Set the pack path and check that an unprivileged user can read its
artifacts and execute Node.
- Let the legacy cloud target inherit the pack from production.
- Add regression checks for production packaging and cloud inheritance.
- Document stamped image behavior and the default pack path.

## Verification

- The 12 focused Docker stamp and provider-pack reuse tests pass on
commit `4a11f8d52aead55f85527c8e82c6d7f2644ce0da`.
- The new packaging regression failed against the old Dockerfile and
passed with the fix.
- On the current commit, `pnpm build` and `pnpm -r typecheck` pass. All
seven standard-image contract tests also pass.
- The current-head CI build, typecheck, test, browser, and native Runner
checks passed. The local full suite hit one chat-channel assertion
failure; that exact test passed in isolation. The remaining local run
was stopped after CI completed to avoid duplicating its full suite. An
earlier run on the pre-rebase base had a heartbeat comment batching
timeout; the external chat wait integration suite passed all 142 tests
in isolation.
- [The stamped preview image build
passed](https://github.com/paperclipai/paperclip/actions/runs/36885002850/job/110446106393),
including the production-stage provider pack build, copy, and
unprivileged artifact readability/executable check. Publication,
compatibility validation, and deployment of this exact commit to a
staging QA instance passed.
- Reproduced the exact missing-pack error on an existing staging image
with Paperclip Runner, ACPX, and Claude in a remote Daytona computer.
The legacy Claude adapter succeeds with the same account and computer.
After deploying this commit, the same native task succeeded: it computed
`5050` with a real remote shell command, wrote a proof file, read it
back in a separate call, uploaded the file as a deliverable, and
completed the task. The uploaded file contents and Done state persisted
after a page reload. The run trace confirms Paperclip Runner, ACPX, and
Claude. The first run took 2m 59s, including approximately 97s of remote
artifact preparation. A second native run read the unchanged file from
the prior run and completed successfully. Its startup took about 120s;
this verifies repeated execution and file persistence, not fast
provider-pack reuse.

## Risks

- Stamped standard images now include the provider pack and its build
cost. A pack build failure now fails the production image build.
- Unstamped local builds still skip pack generation. Setting the path
alone does not create a pack.
- No database, provider authentication, or runner verification rules
change.

## Model Used

OpenAI Codex, GPT-6. The exact serving model identifier and context
window are not exposed in this session. Capabilities used: repository
inspection, code editing, shell verification, and browser testing.

## Checklist

- [x] I have included a thinking path that traces from project context
to this change
- [x] I have specified the model used (with version and capability
details)
- [x] I have checked ROADMAP.md and confirmed this PR does not duplicate
planned core work
- [x] I have searched GitHub for duplicate or related PRs and linked
them above
- [x] I have either (a) linked existing issues with `Fixes: #` / `Closes
#` / `Refs #` OR (b) described the issue in-PR following the relevant
issue template
- [x] I have not referenced internal/instance-local Paperclip issues or
links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip`
URLs)
- [x] My branch name describes the change (e.g. `docs/...`, `fix/...`)
and contains no internal Paperclip ticket id or instance-derived details
- [ ] I have run tests locally and they pass
- [x] I have added or updated tests where applicable
- [x] I have updated relevant documentation to reflect my changes
- [x] I have considered and documented any risks above
- [x] All Paperclip CI gates are green
- [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups
- [x] I will address all Greptile and reviewer comments before
requesting merge

Co-authored-by: Paperclip <noreply@paperclip.ing>
2026-10-01 11:07:50 -05:00
DottaandPaperclip 33a00d2f1e fix(ui): reopen last visited agent chat (#14848)
## Thinking Path

> - Paperclip helps people manage AI agents and their work.
> - Agent Chat keeps one conversation for each agent and board user.
> - The Chat sidebar entry opens the agent chooser each time.
> - A user must then find and reopen the chat they just used.
> - The browser already records recent agent chat visits by company and
user.
> - This pull request uses that record to reopen the last available
chat.
> - The chooser still serves users who have no available saved chat.

## Linked Issues or Issue Description

Related: #14706 added the secondary Agent Chat navigation.

**What happened?**

The Chat sidebar entry opened the agent chooser, even after a user
opened an agent chat.

**Expected behavior**

The Chat entry should reopen the last agent chat visited by the current
user in the current company.

**Steps to reproduce**

1. Enable Agent Chat and open a chat with an agent.
2. Open another page.
3. Select Chat in the sidebar.
4. Observe the agent chooser instead of the chat.

**Paperclip version or commit**

Reproduced on master at `0829d94af`.

**Deployment mode**

Local development, browser UI. The change also uses the same browser
storage path in authenticated mode.

## What Changed

- Use the existing recent chat record when the Chat landing route opens.
- Check saved agents against the current roster and chat history before
redirecting.
- Keep the chooser when no saved chat is available, and show a retry
state for load errors.
- Add route tests and update the Agent Chat implementation spec.

## Verification

- `pnpm exec vitest run ui/src/pages/AgentChats.test.tsx
ui/src/lib/recent-agent-chats.test.ts` — 16 tests passed.
- `pnpm check:token-gates` — passed.
- `pnpm exec playwright test --config tests/e2e/playwright.config.ts
tests/e2e/agent-chat-sessions.spec.ts --grep 'secondary chat navigation
preserves layout'` — passed.
- `pnpm --filter @paperclipai/ui typecheck` — passed on the final
commit.
- `pnpm -r typecheck` and `pnpm build` — passed earlier in this branch;
latest-head CI completed all 47 jobs successfully.
- `pnpm test:run` reported an unrelated native runtime test failure
before it was stopped. That test and an unrelated external object
refresh test passed in isolation. CI runs the same suites on the PR.
- To check in the UI: open an agent chat, leave it, and select Chat. The
same chat should open. Clear the recent chat record or use another
company to see the chooser.

## Risks

- The recent order is stored in the browser. Clearing browser storage
returns the user to the chooser.
- An existing chat ID is stored with its visit. If the chat is removed,
the landing route skips that visit when history loads. Cross-tab storage
removal clears the identity; failed writes retain an in-tab fallback.
- The landing route waits for the agent roster and validates saved issue
IDs against chat history when available. If history fails, an active
agent chat can still open; roster or session failures show a retry
action.
- No database or API contract changes are required.

> For core feature work, check [`ROADMAP.md`](ROADMAP.md) first and
discuss it in `#dev` before opening the PR. Feature PRs that overlap
with planned core work may need to be redirected — check the roadmap
first. See `CONTRIBUTING.md`.

## Model Used

OpenAI Codex, GPT-6 family. The runtime did not expose an exact API
model ID or context window. It used reasoning, repository tools, shell
commands, and code execution.

## Checklist

- [x] I have included a thinking path that traces from project context
to this change
- [x] I have specified the model used (with version and capability
details)
- [x] I have checked ROADMAP.md and confirmed this PR does not duplicate
planned core work
- [x] I have searched GitHub for duplicate or related PRs and linked
them above
- [x] I have either (a) linked existing issues with `Fixes: #` / `Closes
#` / `Refs #` OR (b) described the issue in-PR following the relevant
issue template
- [x] I have not referenced internal/instance-local Paperclip issues or
links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip`
URLs)
- [x] My branch name describes the change (e.g. `docs/...`, `fix/...`)
and contains no internal Paperclip ticket id or instance-derived details
- [x] I have run tests locally and they pass
- [x] I have added or updated tests where applicable
- [x] I have updated relevant documentation to reflect my changes
- [x] I have considered and documented any risks above
- [x] All Paperclip CI gates are green
- [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups
- [x] I will address all Greptile and reviewer comments before
requesting merge

---------

Co-authored-by: Paperclip <noreply@paperclip.ing>
2026-10-01 11:01:45 -05:00
dependabot[bot] 26900655b4 chore(deps): bump lucide-react from 1.38.0 to 1.45.0
Bumps
[lucide-react](https://github.com/lucide-icons/lucide/tree/HEAD/packages/lucide-react)
from 1.38.0 to 1.45.0.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/lucide-icons/lucide/releases">lucide-react's
releases</a>.</em></p>
<blockquote>
<h2>Version 1.45.0</h2>
<h2>What's Changed</h2>
<ul>
<li>feat(icons): added <code>calendar-chevrons-right</code> icon by <a
href="https://github.com/AlexandrePhilibert"><code>@​AlexandrePhilibert</code></a>
in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/3565">lucide-icons/lucide#3565</a></li>
<li>feat(icons): added <code>building-complex-plus</code> icon by <a
href="https://github.com/tylerkade"><code>@​tylerkade</code></a> in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/4758">lucide-icons/lucide#4758</a></li>
<li>feat(icons): add hourglass-cog icon by <a
href="https://github.com/lazerg"><code>@​lazerg</code></a> in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/4635">lucide-icons/lucide#4635</a></li>
<li>feat(icons): added <code>mouth</code> &amp; <code>mouth-off</code>
by <a
href="https://github.com/karsa-mistmere"><code>@​karsa-mistmere</code></a>
in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/4787">lucide-icons/lucide#4787</a></li>
<li>feat(icons): added <code>iv-bag</code> icon by <a
href="https://github.com/karsa-mistmere"><code>@​karsa-mistmere</code></a>
in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/4821">lucide-icons/lucide#4821</a></li>
<li>fix(icons): changed <code>lectern</code> icon by <a
href="https://github.com/UsamaKhan"><code>@​UsamaKhan</code></a> in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/2925">lucide-icons/lucide#2925</a></li>
<li>feat(icons): add <code>layout-arrow-right</code> and
<code>layout-arrow-down</code> by <a
href="https://github.com/samuelalake"><code>@​samuelalake</code></a> in
<a
href="https://redirect.github.com/lucide-icons/lucide/pull/4541">lucide-icons/lucide#4541</a></li>
<li>feat(icons): added <code>park</code> icon by <a
href="https://github.com/skajosborn"><code>@​skajosborn</code></a> in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/3177">lucide-icons/lucide#3177</a></li>
<li>fix(icons): changed <code>album</code>, <code>book-marked</code>,
<code>folder-bookmark</code> icons by <a
href="https://github.com/karsa-mistmere"><code>@​karsa-mistmere</code></a>
in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/3043">lucide-icons/lucide#3043</a></li>
<li>fix(icons): correct misspelled tags by <a
href="https://github.com/decknamec"><code>@​decknamec</code></a> in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/4836">lucide-icons/lucide#4836</a></li>
<li>feat(icons): added <code>houses</code> icon by <a
href="https://github.com/danielbayley"><code>@​danielbayley</code></a>
in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/3241">lucide-icons/lucide#3241</a></li>
<li>feat(icons): added <code>notebook-dot</code> icon by <a
href="https://github.com/elenakovelskikh"><code>@​elenakovelskikh</code></a>
in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/3228">lucide-icons/lucide#3228</a></li>
<li>feat(icons): add <code>messages-circle</code> icon by <a
href="https://github.com/Mirazstudio-offical"><code>@​Mirazstudio-offical</code></a>
in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/4754">lucide-icons/lucide#4754</a></li>
<li>feat(icons): added <code>plant-pot</code> icon by <a
href="https://github.com/vqh2602"><code>@​vqh2602</code></a> in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/3122">lucide-icons/lucide#3122</a></li>
<li>fix(icons): changed <code>cookie</code> icon by <a
href="https://github.com/karsa-mistmere"><code>@​karsa-mistmere</code></a>
in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/4815">lucide-icons/lucide#4815</a></li>
<li>fix(icons): remove duplicate use-cases prop from cookie.json by <a
href="https://github.com/karsa-mistmere"><code>@​karsa-mistmere</code></a>
in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/4838">lucide-icons/lucide#4838</a></li>
<li>fix(site): fix home card icons by <a
href="https://github.com/karsa-mistmere"><code>@​karsa-mistmere</code></a>
in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/4839">lucide-icons/lucide#4839</a></li>
<li>feat(docs): added &quot;How to use Lucide icons&quot; section to
resources by <a
href="https://github.com/karsa-mistmere"><code>@​karsa-mistmere</code></a>
in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/4829">lucide-icons/lucide#4829</a></li>
<li>fix(packages/vue): fix generated icon declaration types for
<code>@​lucide/vue</code> by <a
href="https://github.com/karsa-mistmere"><code>@​karsa-mistmere</code></a>
in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/4841">lucide-icons/lucide#4841</a></li>
<li>chore(deps-dev): bump vitest from 4.1.10 to 4.1.11 by <a
href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/4845">lucide-icons/lucide#4845</a></li>
<li>chore(deps-dev): bump vitest from 4.1.10 to 4.1.11 in
/integrations/lucide-react/vite by <a
href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/4844">lucide-icons/lucide#4844</a></li>
<li>ci(ci.yml): Add dispatch post release by <a
href="https://github.com/ericfennis"><code>@​ericfennis</code></a> in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/4847">lucide-icons/lucide#4847</a></li>
<li>feat(icons): added <code>globe-code</code> icon by <a
href="https://github.com/AleksejDix"><code>@​AleksejDix</code></a> in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/3722">lucide-icons/lucide#3722</a></li>
</ul>
<h2>New Contributors</h2>
<ul>
<li><a href="https://github.com/tylerkade"><code>@​tylerkade</code></a>
made their first contribution in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/4758">lucide-icons/lucide#4758</a></li>
<li><a href="https://github.com/alx-xo"><code>@​alx-xo</code></a> made
their first contribution in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/4115">lucide-icons/lucide#4115</a></li>
<li><a
href="https://github.com/skajosborn"><code>@​skajosborn</code></a> made
their first contribution in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/3177">lucide-icons/lucide#3177</a></li>
<li><a
href="https://github.com/elenakovelskikh"><code>@​elenakovelskikh</code></a>
made their first contribution in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/3228">lucide-icons/lucide#3228</a></li>
<li><a
href="https://github.com/Mirazstudio-offical"><code>@​Mirazstudio-offical</code></a>
made their first contribution in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/4754">lucide-icons/lucide#4754</a></li>
<li><a
href="https://github.com/AleksejDix"><code>@​AleksejDix</code></a> made
their first contribution in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/3722">lucide-icons/lucide#3722</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/lucide-icons/lucide/compare/1.44.0...1.45.0">https://github.com/lucide-icons/lucide/compare/1.44.0...1.45.0</a></p>
<h2>Version 1.44.0</h2>
<h2>What's Changed</h2>
<ul>
<li>feat(packages/icons): fixed <code>@​lucide/icons</code> rollup
config by <a
href="https://github.com/karsa-mistmere"><code>@​karsa-mistmere</code></a>
in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/4824">lucide-icons/lucide#4824</a></li>
<li>fix(icons): changed <code>door-open</code> by <a
href="https://github.com/karsa-mistmere"><code>@​karsa-mistmere</code></a>
in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/4826">lucide-icons/lucide#4826</a></li>
<li>fix(docs): replace missing LucideIcon icon names in guides by <a
href="https://github.com/karsa-mistmere"><code>@​karsa-mistmere</code></a>
in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/4827">lucide-icons/lucide#4827</a></li>
<li>feat(docs): fixed fuse js search by <a
href="https://github.com/karsa-mistmere"><code>@​karsa-mistmere</code></a>
in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/4825">lucide-icons/lucide#4825</a></li>
<li>fix(icons): changed <code>satellite-dish</code> icon by <a
href="https://github.com/karsa-mistmere"><code>@​karsa-mistmere</code></a>
in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/4813">lucide-icons/lucide#4813</a></li>
<li>fix(icons): arcified flip icons &amp; renamed them by <a
href="https://github.com/karsa-mistmere"><code>@​karsa-mistmere</code></a>
in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/4833">lucide-icons/lucide#4833</a></li>
<li>fix(icons): improve legibility of credit card icons by <a
href="https://github.com/karsa-mistmere"><code>@​karsa-mistmere</code></a>
in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/4831">lucide-icons/lucide#4831</a></li>
<li>feat(lab): add check-x icon by <a
href="https://github.com/ishanbagra18"><code>@​ishanbagra18</code></a>
in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/4737">lucide-icons/lucide#4737</a></li>
<li>fix(icons): correct compromised tags in shield icons by <a
href="https://github.com/decknamec"><code>@​decknamec</code></a> in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/4835">lucide-icons/lucide#4835</a></li>
<li>feat(icons): added <code>toothbrush</code> icon by <a
href="https://github.com/karsa-mistmere"><code>@​karsa-mistmere</code></a>
in <a
href="https://redirect.github.com/lucide-icons/lucide/pull/4755">lucide-icons/lucide#4755</a></li>
</ul>
<h2>New Contributors</h2>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/lucide-icons/lucide/commit/94e4cb9d9db5907053ebf3636a97c45529cf776b"><code>94e4cb9</code></a>
chore(dependencies): Update dependencies (<a
href="https://github.com/lucide-icons/lucide/tree/HEAD/packages/lucide-react/issues/4806">#4806</a>)</li>
<li><a
href="https://github.com/lucide-icons/lucide/commit/99d25bdee231922e73e19525f57a585d1682fab2"><code>99d25bd</code></a>
feat(packages): extract icon build logic into
<code>@lucide/shared</code> (<a
href="https://github.com/lucide-icons/lucide/tree/HEAD/packages/lucide-react/issues/4409">#4409</a>)</li>
<li>See full diff in <a
href="https://github.com/lucide-icons/lucide/commits/1.45.0/packages/lucide-react">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=lucide-react&package-manager=npm_and_yarn&previous-version=1.38.0&new-version=1.45.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)


</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-10-01 08:49:02 -07:00
DottaandPaperclip 4ac374103f fix(connections): repair Asana MCP and add shared-app sign-in (#14756)
## Thinking Path

> - Paperclip is the open source app people use to manage AI agents for
work.
> - Connections let agents use provider tools through the permission
gateway.
> - Asana provides an official remote MCP server, but its v2 server
requires a registered MCP OAuth app.
> - Setup can discover retired v1 endpoints and send a callback that
differs from the displayed URL.
> - This pull request repairs custom app setup and adds sign-in through
Paperclip's shared app.
> - Users can choose their own app without enrolling with Paperclip
Cloud.
> - Agents can use Asana tools after the user connects their account and
sets action permissions.

## Linked Issues or Issue Description

Related: #14739 supplies the personal credential repair used by resumed
Asana setup. No duplicate Asana authentication PR was found.

**What happened?**

Asana setup failed even with a user-created app. Root discovery metadata
still points at v1. MCP v2 uses the Asana OAuth issuer and requires an
MCP app with a client secret. Local setup also displayed a localhost
callback while an Origin header could make authorization use a numeric
loopback callback.

**Expected behavior**

Sign in with Paperclip's app when its broker profile is available. Keep
custom MCP app setup available without Cloud enrollment. Use the correct
issuer, callback, client credentials, and resource throughout setup.

**Steps to reproduce**

1. Open Asana in the connection catalog.
2. Supply an Asana MCP app's client ID and secret.
3. Start OAuth on a local instance opened with a numeric loopback
address, or resume a draft that cached v1 metadata.
4. Observe the wrong discovery endpoint or callback mismatch.

**Paperclip version or commit**

Reproduced from b54b2dc35c. Rebased onto
master at `0829d94af` after the single-screen setup change in #14811.

**Deployment mode**

Local development from source. The managed path also supports enrolled
self-hosted instances.

## What Changed

- Add the `asana.mcp` managed profile and the default Sign in with Asana
method.
- Use Asana's reviewed v2 protected-resource metadata before cached
endpoints.
- Require a custom MCP app's client secret and retain saved credentials
during setup or reconnect. Repair only the known Asana v1
issuer/resource binding, retaining company and callback checks.
- Expose a boolean for the acting user's saved client secret. The form
offers secret reuse only when that user has an active grant with the
required reference.
- Let users select their own app from the enrollment and
shared-app-unavailable screens, or from Advanced on the single-screen
setup page.
- Canonicalize HTTP loopback callbacks even when the request includes an
Origin header.
- Extend signed broker claims and provider URL validation for Asana.
Require refresh credentials on managed authorization.
- Document setup, distribution, and shared-app rollout requirements.
- Resolve permission-profile name collisions when finishing another
account. The live staging test found this after renaming the first Asana
connection; OAuth succeeded but profile finalization failed.

## Verification

- Final live staging proof used app commit
`c6053157c4e42ac017727117b754ae77fa5c45fa` and the real Cloud broker at
`767b63835170f664542afd0df99a76615e204b62`. In the embedded browser,
default shared sign-in required no client credentials, returned through
the central Cloud callback to the tenant, and discovered 39 actions. Get
me succeeded through the gateway as the selected QA agent (2.1 seconds).
The custom-app connection also returned a real result on this final
build (0.9 seconds).
- Retried the shared draft that failed during the first staging test. It
completed after the profile-name fix, retained the selected agent, and
kept the existing custom connection intact. Two database regressions
reproduced the collision before the fix and passed afterward. The
updated transaction rollback test also passes.
- Shared reconnect returned to the same staging connection with 39
actions. Earlier staging checks verified the custom-app fallback when
the shared profile was unavailable, saved-secret reuse on reconnect, and
Off blocking the action test. Allowed was restored after that check.
- Local live-provider checks also repaired a saved Asana v1
issuer/resource binding without reentering the secret and verified that
numeric-loopback setup uses the displayed localhost callback. Expiring
the local managed access-token timestamp triggered a real Asana refresh
and a successful Get me call. These early local broker tests used
enrollment/authentication and storage fixtures; the final staging proof
used deployed Cloud identity and persistent storage.
- The new production app is registered and configured, but production
sign-in has not been deployed or verified. Live provider revocation was
not run because the existing staging test app is shared with other
connections.

- After rebasing onto the single-screen setup flow, full `pnpm -r
typecheck`, `pnpm build`, and `pnpm check:token-gates` pass. Focused
verification passes 365 service and 36 broker-client tests. Broader
checks pass all 833 shared-package tests and all 530 connector-page
tests. The shared suite uses `TMPDIR=/private/tmp` to avoid macOS
temporary-directory symlinks in its canonical-path tests. The UI tests
verify the shared-app default and switching to a custom app with its
required client secret.
- Embedded-browser smoke on the current rebased build verified the
shared sign-in default, Advanced → custom app (client ID and secret
required), and switching back to Paperclip. Both existing Asana
connections remained connected after restart. No new provider
authorization was performed during this smoke.
- The full local `pnpm test:run` was interrupted when the execution
session restarted. Before interruption, it reported one runtime-slot
restart test failure. That test passed on an isolated retry after
clearing two unused PostgreSQL shared-memory segments. The full local
suite did not complete; CI must pass on the current head before merge.
- All 52 CI and security checks pass on
`9318fd4e9b616cdc3de12f40cdb9bd32d865af4c` (CI run `36882064080`),
including all eight browser shards, nine serialized-server shards,
build, typecheck, and canary dry run. Two optional Storybook checks were
skipped. Greptile review 4 reports 5/5 on this exact commit, with all
review threads resolved. Its updated summary identifies the current SHA;
this comment-triggered review did not publish a separate GitHub check
run.
- Provider revocation is unit-tested in the companion broker. Live
provider revocation was not run because the existing test app is shared
with other connections.

## Risks

- The shared Paperclip Asana MCP app has been registered with its
production callback and Any workspace distribution. Its secret is
provisioned in the production secret store, and the runtime client ID
and secret reference are configured. The production profile is enabled
in the saved deployment configuration. The companion broker has merged
and passed staging deployment; production sign-in still requires a
production deployment and live verification. Custom setup remains
available.
- Asana MCP uses the provider's fixed `default` grant. Paperclip action
policies limit agent tool use; they do not narrow provider consent.
- The callback correction affects HTTP loopback OAuth flows. Public
HTTPS callbacks retain their existing behavior.
- Reviewed discovery URLs now override stale cached endpoints. Tests
cover the Asana v1-to-v2 repair.
- No schema migration. Connection removal retains the existing
local-only revocation behavior.

## Model Used

OpenAI GPT-6 through Codex, with code execution, browser testing, and
GitHub tooling. The exact model variant and context window are not
exposed in this session.

## Checklist

- [x] I have included a thinking path that traces from project context
to this change
- [x] I have specified the model used (with version and capability
details)
- [x] I have checked ROADMAP.md and confirmed this PR does not duplicate
planned core work
- [x] I have searched GitHub for duplicate or related PRs and linked
them above
- [x] I have either (a) linked existing issues with `Fixes: #` / `Closes
#` / `Refs #` OR (b) described the issue in-PR following the relevant
issue template
- [x] I have not referenced internal/instance-local Paperclip issues or
links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip`
URLs)
- [x] My branch name describes the change (e.g. `docs/...`, `fix/...`)
and contains no internal Paperclip ticket id or instance-derived details
- [x] I have run tests locally and they pass
- [x] I have added or updated tests where applicable
- [x] I have updated relevant documentation to reflect my changes
- [x] I have considered and documented any risks above
- [x] All Paperclip CI gates are green
- [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups
- [x] I will address all Greptile and reviewer comments before
requesting merge

---------

Co-authored-by: Paperclip <noreply@paperclip.ing>
2026-10-01 10:24:44 -05:00
dependabot[bot] 8458c31915 chore(deps): bump @assistant-ui/react from 0.15.16 to 0.15.21 (#13477)
Bumps
[@assistant-ui/react](https://github.com/assistant-ui/assistant-ui/tree/HEAD/packages/react)
from 0.15.16 to 0.15.21.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/assistant-ui/assistant-ui/releases">@​assistant-ui/react's
releases</a>.</em></p>
<blockquote>
<h2><code>@​assistant-ui/react</code><a
href="https://github.com/0"><code>@​0</code></a>.15.21</h2>
<h3>Patch Changes</h3>
<ul>
<li>
<p><a
href="https://redirect.github.com/assistant-ui/assistant-ui/pull/7692">#7692</a>
<a
href="https://github.com/assistant-ui/assistant-ui/commit/dbb1496e4bc28c8e0fd8d25aeba2dfd079c69116"><code>dbb1496</code></a>
- fix: resume bottom following when auto-scroll is enabled at runtime
(<a href="https://github.com/Kinfe123"><code>@​Kinfe123</code></a>)</p>
</li>
<li>
<p><a
href="https://redirect.github.com/assistant-ui/assistant-ui/pull/7370">#7370</a>
<a
href="https://github.com/assistant-ui/assistant-ui/commit/b7f9a960dda7c7548ac1ebdf3bae368fe28bcbfc"><code>b7f9a96</code></a>
- chore: update dependencies (<a
href="https://github.com/Yonom"><code>@​Yonom</code></a>)</p>
</li>
<li>
<p><a
href="https://redirect.github.com/assistant-ui/assistant-ui/pull/7518">#7518</a>
<a
href="https://github.com/assistant-ui/assistant-ui/commit/d99c80e437ce7b480501e3f74a90d391b26f62a3"><code>d99c80e</code></a>
- fix: cancel the selection toolbar's pending animation frame on
teardown and between selection events (<a
href="https://github.com/Kinfe123"><code>@​Kinfe123</code></a>)</p>
</li>
<li>
<p>Updated dependencies [<a
href="https://github.com/assistant-ui/assistant-ui/commit/43b587d9bc15adf624437950c270e50b749602d0"><code>43b587d</code></a>,
<a
href="https://github.com/assistant-ui/assistant-ui/commit/5428610760ed57e90577fddd459ca9f86adc397b"><code>5428610</code></a>,
<a
href="https://github.com/assistant-ui/assistant-ui/commit/562e495139605d5279e9bd39abc223ef52b79a94"><code>562e495</code></a>,
<a
href="https://github.com/assistant-ui/assistant-ui/commit/ddb720192d22a7b97572318eb527e5e55d62c413"><code>ddb7201</code></a>,
<a
href="https://github.com/assistant-ui/assistant-ui/commit/69c3d0f171e5bb61fd3d45db093cf69ba224eb5e"><code>69c3d0f</code></a>,
<a
href="https://github.com/assistant-ui/assistant-ui/commit/c046153b0cd5e0e6f9c3e894722b707efc559ffc"><code>c046153</code></a>,
<a
href="https://github.com/assistant-ui/assistant-ui/commit/4788b61eb9f6e9b8481e3b85348a95ea8ad7c4ba"><code>4788b61</code></a>,
<a
href="https://github.com/assistant-ui/assistant-ui/commit/99c9988951b5c469b2706bc3c85116a65660836a"><code>99c9988</code></a>,
<a
href="https://github.com/assistant-ui/assistant-ui/commit/37a5a955d4d51a1b7013232a358e5e7461879d28"><code>37a5a95</code></a>,
<a
href="https://github.com/assistant-ui/assistant-ui/commit/2caa1cebe9ef7db666496e6d109813caee708ee4"><code>2caa1ce</code></a>,
<a
href="https://github.com/assistant-ui/assistant-ui/commit/bd77c46263d295d3fca6a57de37b44614189d689"><code>bd77c46</code></a>,
<a
href="https://github.com/assistant-ui/assistant-ui/commit/e8cf372a3ba08f937149dc924e807228324b45f7"><code>e8cf372</code></a>,
<a
href="https://github.com/assistant-ui/assistant-ui/commit/4e08ba680a4adb66fb39043d93f46377be0f861a"><code>4e08ba6</code></a>,
<a
href="https://github.com/assistant-ui/assistant-ui/commit/b7f9a960dda7c7548ac1ebdf3bae368fe28bcbfc"><code>b7f9a96</code></a>,
<a
href="https://github.com/assistant-ui/assistant-ui/commit/50d65c04a37255111206d038b9dfb34d3e0ba6e4"><code>50d65c0</code></a>,
<a
href="https://github.com/assistant-ui/assistant-ui/commit/11969a219201f49eb42a76d05e9f3cc787c5f025"><code>11969a2</code></a>,
<a
href="https://github.com/assistant-ui/assistant-ui/commit/408d5f43a69baa9df723b395eaafba7a501f8884"><code>408d5f4</code></a>,
<a
href="https://github.com/assistant-ui/assistant-ui/commit/bc842502b68a0dcc4c3728e6f6ea542e5a9bcbc5"><code>bc84250</code></a>,
<a
href="https://github.com/assistant-ui/assistant-ui/commit/f513bc7cbdede455e81652004b8142c05e323353"><code>f513bc7</code></a>,
<a
href="https://github.com/assistant-ui/assistant-ui/commit/b712ee83bde9a89fce2812968f951a5742d757b9"><code>b712ee8</code></a>,
<a
href="https://github.com/assistant-ui/assistant-ui/commit/e02bf06e88c76e21ba3f303559d65269010c0269"><code>e02bf06</code></a>,
<a
href="https://github.com/assistant-ui/assistant-ui/commit/5c5522271e67eade40482a555c836b9bf7301429"><code>5c55222</code></a>,
<a
href="https://github.com/assistant-ui/assistant-ui/commit/479d6a3a363bcf9362421e44a834865c0c152808"><code>479d6a3</code></a>,
<a
href="https://github.com/assistant-ui/assistant-ui/commit/44248e03036ffd89c3a278041f8715dbc3f1b587"><code>44248e0</code></a>,
<a
href="https://github.com/assistant-ui/assistant-ui/commit/70b633f378deff6c693f2720ceb9cbb5b8677d8c"><code>70b633f</code></a>]:</p>
<ul>
<li><code>@​assistant-ui/core</code><a
href="https://github.com/0"><code>@​0</code></a>.3.20</li>
<li>assistant-stream@0.3.44</li>
<li>assistant-cloud@0.2.2</li>
<li>safe-content-frame@0.0.31</li>
<li><code>@​assistant-ui/store</code><a
href="https://github.com/0"><code>@​0</code></a>.3.14</li>
<li><code>@​assistant-ui/tap</code><a
href="https://github.com/0"><code>@​0</code></a>.9.18</li>
</ul>
</li>
</ul>
<h2><code>@​assistant-ui/react</code><a
href="https://github.com/0"><code>@​0</code></a>.15.20</h2>
<h3>Patch Changes</h3>
<ul>
<li>
<p><a
href="https://redirect.github.com/assistant-ui/assistant-ui/pull/7414">#7414</a>
<a
href="https://github.com/assistant-ui/assistant-ui/commit/00cff0bc9c475e2acc6cb258b5f96c28eb3292a2"><code>00cff0b</code></a>
- feat: add an opt-in cache to <code>convertExternalMessages</code> so a
source message that has not changed keeps its <code>ThreadMessage</code>
object across calls (<code>createExternalMessageConversionCache</code>,
exported as <code>unstable_createExternalMessageConversionCache</code>
from react and react-native); react-langchain uses it for subagent
transcripts, so a streamed token no longer rebuilds every message of the
nested transcript (<a
href="https://github.com/apps/rupic-app"><code>@​rupic-app</code></a>)</p>
</li>
<li>
<p><a
href="https://redirect.github.com/assistant-ui/assistant-ui/pull/7185">#7185</a>
<a
href="https://github.com/assistant-ui/assistant-ui/commit/2c22f5d7fdeb45f10891a0ab2457d046ace668fa"><code>2c22f5d</code></a>
- fix: settle pending frame tool calls when cancellation fails (<a
href="https://github.com/Kinfe123"><code>@​Kinfe123</code></a>)</p>
</li>
<li>
<p><a
href="https://redirect.github.com/assistant-ui/assistant-ui/pull/7359">#7359</a>
<a
href="https://github.com/assistant-ui/assistant-ui/commit/75b3bd36e0d580a32d35e15a54ef2c42fb6ba61a"><code>75b3bd3</code></a>
- feat: derive thread.tasks from tool calls that carry nested
conversations, with a task scope (<a
href="https://github.com/okisdev"><code>@​okisdev</code></a>)</p>
</li>
<li>
<p><a
href="https://redirect.github.com/assistant-ui/assistant-ui/pull/7213">#7213</a>
<a
href="https://github.com/assistant-ui/assistant-ui/commit/cd42d1caab1f910841741b738cc2ca8691f71b9c"><code>cd42d1c</code></a>
- fix: keep notifying thread viewport scroll listeners after a listener
fails (<a
href="https://github.com/Kinfe123"><code>@​Kinfe123</code></a>)</p>
</li>
<li>
<p><a
href="https://redirect.github.com/assistant-ui/assistant-ui/pull/7351">#7351</a>
<a
href="https://github.com/assistant-ui/assistant-ui/commit/f6b7ba98cbd88154e5e7b8e51de5729d2b950c4e"><code>f6b7ba9</code></a>
- feat: mark voice transcript messages with metadata.modality (<a
href="https://github.com/okisdev"><code>@​okisdev</code></a>)</p>
</li>
<li>
<p>Updated dependencies [<a
href="https://github.com/assistant-ui/assistant-ui/commit/628df887b9cfc9e0381cf53139a32dd0e75bbc67"><code>628df88</code></a>,
<a
href="https://github.com/assistant-ui/assistant-ui/commit/ed77e956811a161243e6c9faf13320846db30a8a"><code>ed77e95</code></a>,
<a
href="https://github.com/assistant-ui/assistant-ui/commit/00cff0bc9c475e2acc6cb258b5f96c28eb3292a2"><code>00cff0b</code></a>,
<a
href="https://github.com/assistant-ui/assistant-ui/commit/b82150660dcf2ca6902b3b987c34440a2ff0af46"><code>b821506</code></a>,
<a
href="https://github.com/assistant-ui/assistant-ui/commit/79c221977f9c2fe9da4374bd45132ed28d02cae4"><code>79c2219</code></a>,
<a
href="https://github.com/assistant-ui/assistant-ui/commit/f0bbcecdee210c5d73ca4ec39ce31abd5c139cf3"><code>f0bbcec</code></a>,
<a
href="https://github.com/assistant-ui/assistant-ui/commit/c41d93a84231a54256e0e1fe6f64951603a039d7"><code>c41d93a</code></a>,
<a
href="https://github.com/assistant-ui/assistant-ui/commit/4cc817d4cb0d49c1704352845731b82f8591b623"><code>4cc817d</code></a>,
<a
href="https://github.com/assistant-ui/assistant-ui/commit/46193357fb581d8440c40b6e2fbf3e79560d6870"><code>4619335</code></a>,
<a
href="https://github.com/assistant-ui/assistant-ui/commit/4e5fde6c2d09909c5b286fee098c9950615a26d3"><code>4e5fde6</code></a>,
<a
href="https://github.com/assistant-ui/assistant-ui/commit/e54bf9aacd73a2431e3194aaced86dfdff67ed2d"><code>e54bf9a</code></a>,
<a
href="https://github.com/assistant-ui/assistant-ui/commit/e54bf9aacd73a2431e3194aaced86dfdff67ed2d"><code>e54bf9a</code></a>,
<a
href="https://github.com/assistant-ui/assistant-ui/commit/c083236df07705cae1109e4342c08f6c8bcd7c3b"><code>c083236</code></a>,
<a
href="https://github.com/assistant-ui/assistant-ui/commit/3cd77005ede1d8e3a30345991e6567e28bd8e75f"><code>3cd7700</code></a>,
<a
href="https://github.com/assistant-ui/assistant-ui/commit/617bbf9277dac2bda46e3cf526c54dd64cbccc79"><code>617bbf9</code></a>,
<a
href="https://github.com/assistant-ui/assistant-ui/commit/5fb3235b68a96dc02695aeb28f7d5720ec893302"><code>5fb3235</code></a>,
<a
href="https://github.com/assistant-ui/assistant-ui/commit/83ede73e8d3f0eadcb3969fae62d41fb7f253f1b"><code>83ede73</code></a>,
<a
href="https://github.com/assistant-ui/assistant-ui/commit/49ee689f7ec5540aabc38f293090901f246978a9"><code>49ee689</code></a>,
<a
href="https://github.com/assistant-ui/assistant-ui/commit/49ee689f7ec5540aabc38f293090901f246978a9"><code>49ee689</code></a>,
<a
href="https://github.com/assistant-ui/assistant-ui/commit/a8e0ff741611714aa56b9917439b4f603715723f"><code>a8e0ff7</code></a>,
<a
href="https://github.com/assistant-ui/assistant-ui/commit/050d915daa2caf4d791f7254a8e42d31fc59e6da"><code>050d915</code></a>,
<a
href="https://github.com/assistant-ui/assistant-ui/commit/d49ff906869981c4d2f3f2443089bf0b2f4a3c42"><code>d49ff90</code></a>,
<a
href="https://github.com/assistant-ui/assistant-ui/commit/e7bdef5df7201663f2d5c269d035ab3643cacde7"><code>e7bdef5</code></a>,
<a
href="https://github.com/assistant-ui/assistant-ui/commit/69cbf47bfa24d1d588cdb7461c42b2f9887075e3"><code>69cbf47</code></a>,
<a
href="https://github.com/assistant-ui/assistant-ui/commit/37bd6763d2e2a1799f8f52ae62afc9bf026f6984"><code>37bd676</code></a>,
<a
href="https://github.com/assistant-ui/assistant-ui/commit/be818db8e1cc97c3398948e5b4ae5ae8e70c672f"><code>be818db</code></a>,
<a
href="https://github.com/assistant-ui/assistant-ui/commit/ff1c692d67eda7e07878b2a8d7cc2bf1b3d90476"><code>ff1c692</code></a>,
<a
href="https://github.com/assistant-ui/assistant-ui/commit/b4b00813ef30a37c36df3fd8acf3be0a5cbd498c"><code>b4b0081</code></a>,
<a
href="https://github.com/assistant-ui/assistant-ui/commit/6b29e7de829bef7e51297d3d66cd9e97175f3fc5"><code>6b29e7d</code></a>,
<a
href="https://github.com/assistant-ui/assistant-ui/commit/de6d6b7667ca5c778409fc9a81b8d2b6ca07ca48"><code>de6d6b7</code></a>,
<a
href="https://github.com/assistant-ui/assistant-ui/commit/f6f52cde1814bac7bca41c5da163bb50021921ff"><code>f6f52cd</code></a>,
<a
href="https://github.com/assistant-ui/assistant-ui/commit/ab97a410a4f67e097ddcb186e12fd4a637790876"><code>ab97a41</code></a>,
<a
href="https://github.com/assistant-ui/assistant-ui/commit/790217b85d9130116ac1a06c46a7902a2552ed07"><code>790217b</code></a>,
<a
href="https://github.com/assistant-ui/assistant-ui/commit/8530b17b8aee50413c5cbbe628832ad039a6d584"><code>8530b17</code></a>,
<a
href="https://github.com/assistant-ui/assistant-ui/commit/063b9ec8c92098c51b6924d49b1a6c3cc80eec45"><code>063b9ec</code></a>,
<a
href="https://github.com/assistant-ui/assistant-ui/commit/063b9ec8c92098c51b6924d49b1a6c3cc80eec45"><code>063b9ec</code></a>,
<a
href="https://github.com/assistant-ui/assistant-ui/commit/2c22f5d7fdeb45f10891a0ab2457d046ace668fa"><code>2c22f5d</code></a>,
<a
href="https://github.com/assistant-ui/assistant-ui/commit/d7aa090819e7f36c04e9fe5ecdc60651b52c83a5"><code>d7aa090</code></a>,
<a
href="https://github.com/assistant-ui/assistant-ui/commit/dacfcecf633340250e38f6055eeea3c9e01a978d"><code>dacfcec</code></a>,
<a
href="https://github.com/assistant-ui/assistant-ui/commit/7af910126ecf03c68a9870917363f264c3ac14fa"><code>7af9101</code></a>,
<a
href="https://github.com/assistant-ui/assistant-ui/commit/63ae5b8917898f7403bee81b439f2dc9c574976d"><code>63ae5b8</code></a>,
<a
href="https://github.com/assistant-ui/assistant-ui/commit/97bd4b39fce83163354c9ec8d9d4fb2c9bd1aac7"><code>97bd4b3</code></a>,
<a
href="https://github.com/assistant-ui/assistant-ui/commit/c0d615046cbbbdfee1a183428f51e9c547564a8c"><code>c0d6150</code></a>,
<a
href="https://github.com/assistant-ui/assistant-ui/commit/275eeb91d0be1d43e98b7b48a53a9609e87419c4"><code>275eeb9</code></a>,
<a
href="https://github.com/assistant-ui/assistant-ui/commit/e57c33f956b28d1c504ea6a1eadbc9e3092e4931"><code>e57c33f</code></a>,
<a
href="https://github.com/assistant-ui/assistant-ui/commit/e63d2e440239a8b9add59c74cfa2044567f0b362"><code>e63d2e4</code></a>,
<a
href="https://github.com/assistant-ui/assistant-ui/commit/75b3bd36e0d580a32d35e15a54ef2c42fb6ba61a"><code>75b3bd3</code></a>,
<a
href="https://github.com/assistant-ui/assistant-ui/commit/f03be0ced78dc2b60b7c698919592005a0ce7532"><code>f03be0c</code></a>,
<a
href="https://github.com/assistant-ui/assistant-ui/commit/06bdf1f9e4d8796ff12b91379a4175625f3a75e8"><code>06bdf1f</code></a>,
<a
href="https://github.com/assistant-ui/assistant-ui/commit/e533f6b2790d4f8ffcc75c256d3753c95f801a9e"><code>e533f6b</code></a>,
<a
href="https://github.com/assistant-ui/assistant-ui/commit/28691a5ef6f7f0a333fa910220f29b0b2a0fae8c"><code>28691a5</code></a>,
<a
href="https://github.com/assistant-ui/assistant-ui/commit/3cfddfdc9282a87186a3a26b74558d6cf8cdc204"><code>3cfddfd</code></a>,
<a
href="https://github.com/assistant-ui/assistant-ui/commit/f6b7ba98cbd88154e5e7b8e51de5729d2b950c4e"><code>f6b7ba9</code></a>]:</p>
<ul>
<li>assistant-stream@0.3.43</li>
<li><code>@​assistant-ui/core</code><a
href="https://github.com/0"><code>@​0</code></a>.3.19</li>
<li>assistant-cloud@0.2.1</li>
</ul>
</li>
</ul>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/assistant-ui/assistant-ui/blob/main/packages/react/CHANGELOG.md">@​assistant-ui/react's
changelog</a>.</em></p>
<blockquote>
<h2>0.15.21</h2>
<h3>Patch Changes</h3>
<ul>
<li>
<p><a
href="https://redirect.github.com/assistant-ui/assistant-ui/pull/7692">#7692</a>
<a
href="https://github.com/assistant-ui/assistant-ui/commit/dbb1496e4bc28c8e0fd8d25aeba2dfd079c69116"><code>dbb1496</code></a>
- fix: resume bottom following when auto-scroll is enabled at runtime
(<a href="https://github.com/Kinfe123"><code>@​Kinfe123</code></a>)</p>
</li>
<li>
<p><a
href="https://redirect.github.com/assistant-ui/assistant-ui/pull/7370">#7370</a>
<a
href="https://github.com/assistant-ui/assistant-ui/commit/b7f9a960dda7c7548ac1ebdf3bae368fe28bcbfc"><code>b7f9a96</code></a>
- chore: update dependencies (<a
href="https://github.com/Yonom"><code>@​Yonom</code></a>)</p>
</li>
<li>
<p><a
href="https://redirect.github.com/assistant-ui/assistant-ui/pull/7518">#7518</a>
<a
href="https://github.com/assistant-ui/assistant-ui/commit/d99c80e437ce7b480501e3f74a90d391b26f62a3"><code>d99c80e</code></a>
- fix: cancel the selection toolbar's pending animation frame on
teardown and between selection events (<a
href="https://github.com/Kinfe123"><code>@​Kinfe123</code></a>)</p>
</li>
<li>
<p>Updated dependencies [<a
href="https://github.com/assistant-ui/assistant-ui/commit/43b587d9bc15adf624437950c270e50b749602d0"><code>43b587d</code></a>,
<a
href="https://github.com/assistant-ui/assistant-ui/commit/5428610760ed57e90577fddd459ca9f86adc397b"><code>5428610</code></a>,
<a
href="https://github.com/assistant-ui/assistant-ui/commit/562e495139605d5279e9bd39abc223ef52b79a94"><code>562e495</code></a>,
<a
href="https://github.com/assistant-ui/assistant-ui/commit/ddb720192d22a7b97572318eb527e5e55d62c413"><code>ddb7201</code></a>,
<a
href="https://github.com/assistant-ui/assistant-ui/commit/69c3d0f171e5bb61fd3d45db093cf69ba224eb5e"><code>69c3d0f</code></a>,
<a
href="https://github.com/assistant-ui/assistant-ui/commit/c046153b0cd5e0e6f9c3e894722b707efc559ffc"><code>c046153</code></a>,
<a
href="https://github.com/assistant-ui/assistant-ui/commit/4788b61eb9f6e9b8481e3b85348a95ea8ad7c4ba"><code>4788b61</code></a>,
<a
href="https://github.com/assistant-ui/assistant-ui/commit/99c9988951b5c469b2706bc3c85116a65660836a"><code>99c9988</code></a>,
<a
href="https://github.com/assistant-ui/assistant-ui/commit/37a5a955d4d51a1b7013232a358e5e7461879d28"><code>37a5a95</code></a>,
<a
href="https://github.com/assistant-ui/assistant-ui/commit/2caa1cebe9ef7db666496e6d109813caee708ee4"><code>2caa1ce</code></a>,
<a
href="https://github.com/assistant-ui/assistant-ui/commit/bd77c46263d295d3fca6a57de37b44614189d689"><code>bd77c46</code></a>,
<a
href="https://github.com/assistant-ui/assistant-ui/commit/e8cf372a3ba08f937149dc924e807228324b45f7"><code>e8cf372</code></a>,
<a
href="https://github.com/assistant-ui/assistant-ui/commit/4e08ba680a4adb66fb39043d93f46377be0f861a"><code>4e08ba6</code></a>,
<a
href="https://github.com/assistant-ui/assistant-ui/commit/b7f9a960dda7c7548ac1ebdf3bae368fe28bcbfc"><code>b7f9a96</code></a>,
<a
href="https://github.com/assistant-ui/assistant-ui/commit/50d65c04a37255111206d038b9dfb34d3e0ba6e4"><code>50d65c0</code></a>,
<a
href="https://github.com/assistant-ui/assistant-ui/commit/11969a219201f49eb42a76d05e9f3cc787c5f025"><code>11969a2</code></a>,
<a
href="https://github.com/assistant-ui/assistant-ui/commit/408d5f43a69baa9df723b395eaafba7a501f8884"><code>408d5f4</code></a>,
<a
href="https://github.com/assistant-ui/assistant-ui/commit/bc842502b68a0dcc4c3728e6f6ea542e5a9bcbc5"><code>bc84250</code></a>,
<a
href="https://github.com/assistant-ui/assistant-ui/commit/f513bc7cbdede455e81652004b8142c05e323353"><code>f513bc7</code></a>,
<a
href="https://github.com/assistant-ui/assistant-ui/commit/b712ee83bde9a89fce2812968f951a5742d757b9"><code>b712ee8</code></a>,
<a
href="https://github.com/assistant-ui/assistant-ui/commit/e02bf06e88c76e21ba3f303559d65269010c0269"><code>e02bf06</code></a>,
<a
href="https://github.com/assistant-ui/assistant-ui/commit/5c5522271e67eade40482a555c836b9bf7301429"><code>5c55222</code></a>,
<a
href="https://github.com/assistant-ui/assistant-ui/commit/479d6a3a363bcf9362421e44a834865c0c152808"><code>479d6a3</code></a>,
<a
href="https://github.com/assistant-ui/assistant-ui/commit/44248e03036ffd89c3a278041f8715dbc3f1b587"><code>44248e0</code></a>,
<a
href="https://github.com/assistant-ui/assistant-ui/commit/70b633f378deff6c693f2720ceb9cbb5b8677d8c"><code>70b633f</code></a>]:</p>
<ul>
<li><code>@​assistant-ui/core</code><a
href="https://github.com/0"><code>@​0</code></a>.3.20</li>
<li>assistant-stream@0.3.44</li>
<li>assistant-cloud@0.2.2</li>
<li>safe-content-frame@0.0.31</li>
<li><code>@​assistant-ui/store</code><a
href="https://github.com/0"><code>@​0</code></a>.3.14</li>
<li><code>@​assistant-ui/tap</code><a
href="https://github.com/0"><code>@​0</code></a>.9.18</li>
</ul>
</li>
</ul>
<h2>0.15.20</h2>
<h3>Patch Changes</h3>
<ul>
<li>
<p><a
href="https://redirect.github.com/assistant-ui/assistant-ui/pull/7414">#7414</a>
<a
href="https://github.com/assistant-ui/assistant-ui/commit/00cff0bc9c475e2acc6cb258b5f96c28eb3292a2"><code>00cff0b</code></a>
- feat: add an opt-in cache to <code>convertExternalMessages</code> so a
source message that has not changed keeps its <code>ThreadMessage</code>
object across calls (<code>createExternalMessageConversionCache</code>,
exported as <code>unstable_createExternalMessageConversionCache</code>
from react and react-native); react-langchain uses it for subagent
transcripts, so a streamed token no longer rebuilds every message of the
nested transcript (<a
href="https://github.com/apps/rupic-app"><code>@​rupic-app</code></a>)</p>
</li>
<li>
<p><a
href="https://redirect.github.com/assistant-ui/assistant-ui/pull/7185">#7185</a>
<a
href="https://github.com/assistant-ui/assistant-ui/commit/2c22f5d7fdeb45f10891a0ab2457d046ace668fa"><code>2c22f5d</code></a>
- fix: settle pending frame tool calls when cancellation fails (<a
href="https://github.com/Kinfe123"><code>@​Kinfe123</code></a>)</p>
</li>
<li>
<p><a
href="https://redirect.github.com/assistant-ui/assistant-ui/pull/7359">#7359</a>
<a
href="https://github.com/assistant-ui/assistant-ui/commit/75b3bd36e0d580a32d35e15a54ef2c42fb6ba61a"><code>75b3bd3</code></a>
- feat: derive thread.tasks from tool calls that carry nested
conversations, with a task scope (<a
href="https://github.com/okisdev"><code>@​okisdev</code></a>)</p>
</li>
<li>
<p><a
href="https://redirect.github.com/assistant-ui/assistant-ui/pull/7213">#7213</a>
<a
href="https://github.com/assistant-ui/assistant-ui/commit/cd42d1caab1f910841741b738cc2ca8691f71b9c"><code>cd42d1c</code></a>
- fix: keep notifying thread viewport scroll listeners after a listener
fails (<a
href="https://github.com/Kinfe123"><code>@​Kinfe123</code></a>)</p>
</li>
<li>
<p><a
href="https://redirect.github.com/assistant-ui/assistant-ui/pull/7351">#7351</a>
<a
href="https://github.com/assistant-ui/assistant-ui/commit/f6b7ba98cbd88154e5e7b8e51de5729d2b950c4e"><code>f6b7ba9</code></a>
- feat: mark voice transcript messages with metadata.modality (<a
href="https://github.com/okisdev"><code>@​okisdev</code></a>)</p>
</li>
<li>
<p>Updated dependencies [<a
href="https://github.com/assistant-ui/assistant-ui/commit/628df887b9cfc9e0381cf53139a32dd0e75bbc67"><code>628df88</code></a>,
<a
href="https://github.com/assistant-ui/assistant-ui/commit/ed77e956811a161243e6c9faf13320846db30a8a"><code>ed77e95</code></a>,
<a
href="https://github.com/assistant-ui/assistant-ui/commit/00cff0bc9c475e2acc6cb258b5f96c28eb3292a2"><code>00cff0b</code></a>,
<a
href="https://github.com/assistant-ui/assistant-ui/commit/b82150660dcf2ca6902b3b987c34440a2ff0af46"><code>b821506</code></a>,
<a
href="https://github.com/assistant-ui/assistant-ui/commit/79c221977f9c2fe9da4374bd45132ed28d02cae4"><code>79c2219</code></a>,
<a
href="https://github.com/assistant-ui/assistant-ui/commit/f0bbcecdee210c5d73ca4ec39ce31abd5c139cf3"><code>f0bbcec</code></a>,
<a
href="https://github.com/assistant-ui/assistant-ui/commit/c41d93a84231a54256e0e1fe6f64951603a039d7"><code>c41d93a</code></a>,
<a
href="https://github.com/assistant-ui/assistant-ui/commit/4cc817d4cb0d49c1704352845731b82f8591b623"><code>4cc817d</code></a>,
<a
href="https://github.com/assistant-ui/assistant-ui/commit/46193357fb581d8440c40b6e2fbf3e79560d6870"><code>4619335</code></a>,
<a
href="https://github.com/assistant-ui/assistant-ui/commit/4e5fde6c2d09909c5b286fee098c9950615a26d3"><code>4e5fde6</code></a>,
<a
href="https://github.com/assistant-ui/assistant-ui/commit/e54bf9aacd73a2431e3194aaced86dfdff67ed2d"><code>e54bf9a</code></a>,
<a
href="https://github.com/assistant-ui/assistant-ui/commit/e54bf9aacd73a2431e3194aaced86dfdff67ed2d"><code>e54bf9a</code></a>,
<a
href="https://github.com/assistant-ui/assistant-ui/commit/c083236df07705cae1109e4342c08f6c8bcd7c3b"><code>c083236</code></a>,
<a
href="https://github.com/assistant-ui/assistant-ui/commit/3cd77005ede1d8e3a30345991e6567e28bd8e75f"><code>3cd7700</code></a>,
<a
href="https://github.com/assistant-ui/assistant-ui/commit/617bbf9277dac2bda46e3cf526c54dd64cbccc79"><code>617bbf9</code></a>,
<a
href="https://github.com/assistant-ui/assistant-ui/commit/5fb3235b68a96dc02695aeb28f7d5720ec893302"><code>5fb3235</code></a>,
<a
href="https://github.com/assistant-ui/assistant-ui/commit/83ede73e8d3f0eadcb3969fae62d41fb7f253f1b"><code>83ede73</code></a>,
<a
href="https://github.com/assistant-ui/assistant-ui/commit/49ee689f7ec5540aabc38f293090901f246978a9"><code>49ee689</code></a>,
<a
href="https://github.com/assistant-ui/assistant-ui/commit/49ee689f7ec5540aabc38f293090901f246978a9"><code>49ee689</code></a>,
<a
href="https://github.com/assistant-ui/assistant-ui/commit/a8e0ff741611714aa56b9917439b4f603715723f"><code>a8e0ff7</code></a>,
<a
href="https://github.com/assistant-ui/assistant-ui/commit/050d915daa2caf4d791f7254a8e42d31fc59e6da"><code>050d915</code></a>,
<a
href="https://github.com/assistant-ui/assistant-ui/commit/d49ff906869981c4d2f3f2443089bf0b2f4a3c42"><code>d49ff90</code></a>,
<a
href="https://github.com/assistant-ui/assistant-ui/commit/e7bdef5df7201663f2d5c269d035ab3643cacde7"><code>e7bdef5</code></a>,
<a
href="https://github.com/assistant-ui/assistant-ui/commit/69cbf47bfa24d1d588cdb7461c42b2f9887075e3"><code>69cbf47</code></a>,
<a
href="https://github.com/assistant-ui/assistant-ui/commit/37bd6763d2e2a1799f8f52ae62afc9bf026f6984"><code>37bd676</code></a>,
<a
href="https://github.com/assistant-ui/assistant-ui/commit/be818db8e1cc97c3398948e5b4ae5ae8e70c672f"><code>be818db</code></a>,
<a
href="https://github.com/assistant-ui/assistant-ui/commit/ff1c692d67eda7e07878b2a8d7cc2bf1b3d90476"><code>ff1c692</code></a>,
<a
href="https://github.com/assistant-ui/assistant-ui/commit/b4b00813ef30a37c36df3fd8acf3be0a5cbd498c"><code>b4b0081</code></a>,
<a
href="https://github.com/assistant-ui/assistant-ui/commit/6b29e7de829bef7e51297d3d66cd9e97175f3fc5"><code>6b29e7d</code></a>,
<a
href="https://github.com/assistant-ui/assistant-ui/commit/de6d6b7667ca5c778409fc9a81b8d2b6ca07ca48"><code>de6d6b7</code></a>,
<a
href="https://github.com/assistant-ui/assistant-ui/commit/f6f52cde1814bac7bca41c5da163bb50021921ff"><code>f6f52cd</code></a>,
<a
href="https://github.com/assistant-ui/assistant-ui/commit/ab97a410a4f67e097ddcb186e12fd4a637790876"><code>ab97a41</code></a>,
<a
href="https://github.com/assistant-ui/assistant-ui/commit/790217b85d9130116ac1a06c46a7902a2552ed07"><code>790217b</code></a>,
<a
href="https://github.com/assistant-ui/assistant-ui/commit/8530b17b8aee50413c5cbbe628832ad039a6d584"><code>8530b17</code></a>,
<a
href="https://github.com/assistant-ui/assistant-ui/commit/063b9ec8c92098c51b6924d49b1a6c3cc80eec45"><code>063b9ec</code></a>,
<a
href="https://github.com/assistant-ui/assistant-ui/commit/063b9ec8c92098c51b6924d49b1a6c3cc80eec45"><code>063b9ec</code></a>,
<a
href="https://github.com/assistant-ui/assistant-ui/commit/2c22f5d7fdeb45f10891a0ab2457d046ace668fa"><code>2c22f5d</code></a>,
<a
href="https://github.com/assistant-ui/assistant-ui/commit/d7aa090819e7f36c04e9fe5ecdc60651b52c83a5"><code>d7aa090</code></a>,
<a
href="https://github.com/assistant-ui/assistant-ui/commit/dacfcecf633340250e38f6055eeea3c9e01a978d"><code>dacfcec</code></a>,
<a
href="https://github.com/assistant-ui/assistant-ui/commit/7af910126ecf03c68a9870917363f264c3ac14fa"><code>7af9101</code></a>,
<a
href="https://github.com/assistant-ui/assistant-ui/commit/63ae5b8917898f7403bee81b439f2dc9c574976d"><code>63ae5b8</code></a>,
<a
href="https://github.com/assistant-ui/assistant-ui/commit/97bd4b39fce83163354c9ec8d9d4fb2c9bd1aac7"><code>97bd4b3</code></a>,
<a
href="https://github.com/assistant-ui/assistant-ui/commit/c0d615046cbbbdfee1a183428f51e9c547564a8c"><code>c0d6150</code></a>,
<a
href="https://github.com/assistant-ui/assistant-ui/commit/275eeb91d0be1d43e98b7b48a53a9609e87419c4"><code>275eeb9</code></a>,
<a
href="https://github.com/assistant-ui/assistant-ui/commit/e57c33f956b28d1c504ea6a1eadbc9e3092e4931"><code>e57c33f</code></a>,
<a
href="https://github.com/assistant-ui/assistant-ui/commit/e63d2e440239a8b9add59c74cfa2044567f0b362"><code>e63d2e4</code></a>,
<a
href="https://github.com/assistant-ui/assistant-ui/commit/75b3bd36e0d580a32d35e15a54ef2c42fb6ba61a"><code>75b3bd3</code></a>,
<a
href="https://github.com/assistant-ui/assistant-ui/commit/f03be0ced78dc2b60b7c698919592005a0ce7532"><code>f03be0c</code></a>,
<a
href="https://github.com/assistant-ui/assistant-ui/commit/06bdf1f9e4d8796ff12b91379a4175625f3a75e8"><code>06bdf1f</code></a>,
<a
href="https://github.com/assistant-ui/assistant-ui/commit/e533f6b2790d4f8ffcc75c256d3753c95f801a9e"><code>e533f6b</code></a>,
<a
href="https://github.com/assistant-ui/assistant-ui/commit/28691a5ef6f7f0a333fa910220f29b0b2a0fae8c"><code>28691a5</code></a>,
<a
href="https://github.com/assistant-ui/assistant-ui/commit/3cfddfdc9282a87186a3a26b74558d6cf8cdc204"><code>3cfddfd</code></a>,
<a
href="https://github.com/assistant-ui/assistant-ui/commit/f6b7ba98cbd88154e5e7b8e51de5729d2b950c4e"><code>f6b7ba9</code></a>]:</p>
<ul>
<li>assistant-stream@0.3.43</li>
<li><code>@​assistant-ui/core</code><a
href="https://github.com/0"><code>@​0</code></a>.3.19</li>
<li>assistant-cloud@0.2.1</li>
</ul>
</li>
</ul>
<h2>0.15.19</h2>
<h3>Patch Changes</h3>
<ul>
<li>
<p><a
href="https://redirect.github.com/assistant-ui/assistant-ui/pull/6971">#6971</a>
<a
href="https://github.com/assistant-ui/assistant-ui/commit/9247ae3fe1c05181f6975bc2fdbd74491eed494d"><code>9247ae3</code></a>
- fix: honor message part text render elements with an explicit
component. (<a
href="https://github.com/apps/rupic-app"><code>@​rupic-app</code></a>)</p>
</li>
<li>
<p><a
href="https://redirect.github.com/assistant-ui/assistant-ui/pull/6738">#6738</a>
<a
href="https://github.com/assistant-ui/assistant-ui/commit/3c17a5f08cacc55a5eaa5c6eb7016664847a80a6"><code>3c17a5f</code></a>
- fix: prevent queued live completion requests from starting after
unmount (<a
href="https://github.com/Kinfe123"><code>@​Kinfe123</code></a>)</p>
</li>
<li>
<p><a
href="https://redirect.github.com/assistant-ui/assistant-ui/pull/7115">#7115</a>
<a
href="https://github.com/assistant-ui/assistant-ui/commit/4767a923d818cc2a4a7b0e50ce12d2abbe83bccb"><code>4767a92</code></a>
- feat: align the cloud SDK with Assistant Cloud 0.2 (<a
href="https://github.com/okisdev"><code>@​okisdev</code></a>)</p>
<!-- raw HTML omitted -->
<ul>
<li>run reports now carry <code>provider</code>,
<code>outcome_type</code> (<code>aborted</code>,
<code>disconnected</code>, <code>length</code>,
<code>content_filter</code>), <code>error_code</code> and
<code>error</code>, <code>message_id</code>,
<code>first_token_ms</code>, <code>duration_ms</code>, a
<code>finish_reason</code> per step from <code>useCloudChat</code> and
<code>trace_id</code>, plus <code>environment</code>,
<code>release</code> and <code>tags</code> from the
<code>telemetry</code> config; one <code>createRunReport</code> builder
in <code>assistant-cloud</code> assembles the body for the assistant-ui
runtime and for <code>@assistant-ui/cloud-ai-sdk</code>, and
<code>provider_type</code> and <code>metadata</code> stay on the wire
for older self hosted clouds</li>
<li><code>assistant-cloud/telemetry</code> (server side):
<code>createAssistantCloudTraceExporter</code>,
<code>createAssistantCloudSpanProcessor</code>,
<code>assistantCloudTraceMetadata</code> and
<code>withAssistantCloudTraceMetadata</code> send AI SDK GenAI spans to
<code>POST /v1/traces</code> and hand the trace id to the browser, so a
client report and its server spans merge into one run; the OpenTelemetry
packages are optional peers of the subpath only</li>
<li>engagement events: sends, edits, stops, regenerates, copies, branch
switches, suggestions, attachments, thread switches, speech, voice and
shown errors are batched to <code>POST /v1/events</code> without any
message content; <code>telemetry.events: false</code> opts out</li>
</ul>
</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/assistant-ui/assistant-ui/commit/f6bcca7cd0c901ae5a0a58a9ad3ce75fcf07bb09"><code>f6bcca7</code></a>
chore: update versions (<a
href="https://github.com/assistant-ui/assistant-ui/tree/HEAD/packages/react/issues/7471">#7471</a>)</li>
<li><a
href="https://github.com/assistant-ui/assistant-ui/commit/dbb1496e4bc28c8e0fd8d25aeba2dfd079c69116"><code>dbb1496</code></a>
fix(react): resume dynamically enabled auto-scroll (<a
href="https://github.com/assistant-ui/assistant-ui/tree/HEAD/packages/react/issues/7692">#7692</a>)</li>
<li><a
href="https://github.com/assistant-ui/assistant-ui/commit/b7f9a960dda7c7548ac1ebdf3bae368fe28bcbfc"><code>b7f9a96</code></a>
chore: update dependencies (<a
href="https://github.com/assistant-ui/assistant-ui/tree/HEAD/packages/react/issues/7370">#7370</a>)</li>
<li><a
href="https://github.com/assistant-ui/assistant-ui/commit/9163e3d6adca8e194c93f267be2f0d89ed9cdaa2"><code>9163e3d</code></a>
ci: typecheck changed workspaces with a turbo typecheck task (<a
href="https://github.com/assistant-ui/assistant-ui/tree/HEAD/packages/react/issues/7562">#7562</a>)</li>
<li><a
href="https://github.com/assistant-ui/assistant-ui/commit/108c6520567cb0f59b5cd5f1e961a2daf94a3874"><code>108c652</code></a>
test(react): make the test files typecheck (<a
href="https://github.com/assistant-ui/assistant-ui/tree/HEAD/packages/react/issues/7550">#7550</a>)</li>
<li><a
href="https://github.com/assistant-ui/assistant-ui/commit/d99c80e437ce7b480501e3f74a90d391b26f62a3"><code>d99c80e</code></a>
fix(react): cancel the selection toolbar's pending animation frame (<a
href="https://github.com/assistant-ui/assistant-ui/tree/HEAD/packages/react/issues/7518">#7518</a>)</li>
<li><a
href="https://github.com/assistant-ui/assistant-ui/commit/6cd9226241d7e3f1a89e93f3160baa4f63157f6f"><code>6cd9226</code></a>
chore: update versions (<a
href="https://github.com/assistant-ui/assistant-ui/tree/HEAD/packages/react/issues/7192">#7192</a>)</li>
<li><a
href="https://github.com/assistant-ui/assistant-ui/commit/00cff0bc9c475e2acc6cb258b5f96c28eb3292a2"><code>00cff0b</code></a>
feat: add a conversion cache so nested transcripts keep message identity
(<a
href="https://github.com/assistant-ui/assistant-ui/tree/HEAD/packages/react/issues/7414">#7414</a>)</li>
<li><a
href="https://github.com/assistant-ui/assistant-ui/commit/75b3bd36e0d580a32d35e15a54ef2c42fb6ba61a"><code>75b3bd3</code></a>
feat(core): derive thread.tasks from tool calls that carry nested
conversatio...</li>
<li><a
href="https://github.com/assistant-ui/assistant-ui/commit/f6b7ba98cbd88154e5e7b8e51de5729d2b950c4e"><code>f6b7ba9</code></a>
feat(core): mark voice transcript messages with metadata.modality (<a
href="https://github.com/assistant-ui/assistant-ui/tree/HEAD/packages/react/issues/7351">#7351</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/assistant-ui/assistant-ui/commits/@assistant-ui/react@0.15.21/packages/react">compare
view</a></li>
</ul>
</details>
<br />

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-10-01 08:20:39 -07:00
dependabot[bot]andPriya Raman 8b4aa06920 build(deps): bump multer from 2.2.0 to 2.4.0 (#14493)
Bumps [multer](https://github.com/expressjs/multer) from 2.2.0 to 2.4.0.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/expressjs/multer/releases">multer's
releases</a>.</em></p>
<blockquote>
<h2>v2.4.0</h2>
<h2>Highlights</h2>
<p><strong>multer finally supports Google Cloud Functions and Firebase
🎉</strong></p>
<p>These platforms read the request body before your code runs, so
multer's classic <code>req.pipe(busboy)</code> received nothing: empty
<code>req.body</code>, empty <code>req.files</code>, and nearly a decade
of duplicated issues.</p>
<p>The new <code>streamHandler</code> option closes that gap: you decide
how the body reaches the parser, so the pre-read <code>rawBody</code>
just works (see image).</p>
<pre lang="js"><code>const multer = require('multer')
<p>const upload = multer({<br />
storage: multer.memoryStorage(),<br />
streamHandler: (req, busboy) =&gt; {<br />
// Cloud Functions / Firebase expose the pre-read body here<br />
if (req.rawBody) busboy.end(req.rawBody)<br />
else req.pipe(busboy)<br />
}<br />
})</p>
<p>app.post('/upload', upload.single('file'), (req, res) =&gt; {<br />
res.json({ name: req.file.originalname, size: req.file.size })<br />
})<br />
</code></pre></p>
<p>This landed thanks to community PRs going back to 2017; their authors
are credited as co-authors in the release.</p>
<h2>Important: Security</h2>
<ul>
<li>Fix <a
href="https://www.cve.org/CVERecord?id=CVE-2026-88932">CVE-2026-88932</a>
(<a
href="https://github.com/expressjs/multer/security/advisories/GHSA-3pph-fpjx-jg34">GHSA-3pph-fpjx-jg34</a>)</li>
</ul>
<h2>What's Changed</h2>
<ul>
<li>docs: remove README translations by <a
href="https://github.com/UlisesGascon"><code>@​UlisesGascon</code></a>
in <a
href="https://redirect.github.com/expressjs/multer/pull/1463">expressjs/multer#1463</a></li>
<li>ci: add macOS to the test matrix by <a
href="https://github.com/kilisamemarisaaa"><code>@​kilisamemarisaaa</code></a>
in <a
href="https://redirect.github.com/expressjs/multer/pull/1464">expressjs/multer#1464</a></li>
<li>feat. improve wording for LIMIT_UNEXPECTED_FILE error code by <a
href="https://github.com/flashbag"><code>@​flashbag</code></a> in <a
href="https://redirect.github.com/expressjs/multer/pull/426">expressjs/multer#426</a></li>
<li>feat: add filename to file errors by <a
href="https://github.com/UjjwalKumar239"><code>@​UjjwalKumar239</code></a>
in <a
href="https://redirect.github.com/expressjs/multer/pull/1416">expressjs/multer#1416</a></li>
<li>refactor: remove concat-stream dependency by <a
href="https://github.com/Phillip9587"><code>@​Phillip9587</code></a> in
<a
href="https://redirect.github.com/expressjs/multer/pull/1356">expressjs/multer#1356</a></li>
<li>fix: reject non-integer fileSize limits by <a
href="https://github.com/abhu85"><code>@​abhu85</code></a> in <a
href="https://redirect.github.com/expressjs/multer/pull/1395">expressjs/multer#1395</a></li>
<li>fix: allow exactly limits.parts parts by <a
href="https://github.com/deepakganesh78"><code>@​deepakganesh78</code></a>
in <a
href="https://redirect.github.com/expressjs/multer/pull/1446">expressjs/multer#1446</a></li>
<li>fix: do not consume maxCount for files skipped by fileFilter by <a
href="https://github.com/Sagargupta16"><code>@​Sagargupta16</code></a>
in <a
href="https://redirect.github.com/expressjs/multer/pull/1426">expressjs/multer#1426</a></li>
<li>fix: validate all limits at construction time by <a
href="https://github.com/ShubhamOulkar"><code>@​ShubhamOulkar</code></a>
in <a
href="https://redirect.github.com/expressjs/multer/pull/1335">expressjs/multer#1335</a></li>
<li>test: cover storage engine _removeFile invocation semantics by <a
href="https://github.com/kilisamemarisaaa"><code>@​kilisamemarisaaa</code></a>
in <a
href="https://redirect.github.com/expressjs/multer/pull/1460">expressjs/multer#1460</a></li>
<li>feat: accept a function for limits by <a
href="https://github.com/hossein-zare"><code>@​hossein-zare</code></a>
in <a
href="https://redirect.github.com/expressjs/multer/pull/1133">expressjs/multer#1133</a></li>
<li>fix: add flush option to disk storage to fsync files before
completion by <a
href="https://github.com/kilisamemarisaaa"><code>@​kilisamemarisaaa</code></a>
in <a
href="https://redirect.github.com/expressjs/multer/pull/1458">expressjs/multer#1458</a></li>
<li>feat: expose busboy defCharset, highWaterMark and fileHwm options by
<a
href="https://github.com/UlisesGascon"><code>@​UlisesGascon</code></a>
in <a
href="https://redirect.github.com/expressjs/multer/pull/1465">expressjs/multer#1465</a></li>
<li>docs: describe the file stream contract for storage engines by <a
href="https://github.com/UlisesGascon"><code>@​UlisesGascon</code></a>
in <a
href="https://redirect.github.com/expressjs/multer/pull/1468">expressjs/multer#1468</a></li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/expressjs/multer/blob/main/CHANGELOG.md">multer's
changelog</a>.</em></p>
<blockquote>
<h2>2.4.0</h2>
<ul>
<li>Fix <a
href="https://www.cve.org/CVERecord?id=CVE-2026-88932">CVE-2026-88932</a>
(<a
href="https://github.com/expressjs/multer/security/advisories/GHSA-3pph-fpjx-jg34">GHSA-3pph-fpjx-jg34</a>)</li>
<li>Add <code>filename</code> to <code>LIMIT_FILE_SIZE</code> and
<code>LIMIT_UNEXPECTED_FILE</code> errors (<a
href="https://redirect.github.com/expressjs/multer/pull/1416">#1416</a>)</li>
<li>Accept a function for <code>limits</code>, called with the request,
to set limits per request (<a
href="https://redirect.github.com/expressjs/multer/pull/1133">#1133</a>)</li>
<li>Add opt-in <code>flush</code> option to <code>DiskStorage</code> to
fsync files before the callback runs (<a
href="https://redirect.github.com/expressjs/multer/pull/1458">#1458</a>)</li>
<li>Expose busboy's <code>defCharset</code>, <code>highWaterMark</code>
and <code>fileHwm</code> options (<a
href="https://redirect.github.com/expressjs/multer/pull/1465">#1465</a>)</li>
<li>Add <code>streamHandler</code> option to feed busboy from
pre-consumed bodies (Google Cloud Functions, Firebase) (<a
href="https://redirect.github.com/expressjs/multer/pull/1466">#1466</a>)</li>
<li>Allow <code>multer.diskStorage()</code> to be called without options
(<a
href="https://redirect.github.com/expressjs/multer/pull/1471">#1471</a>)</li>
<li>Decode WHATWG-escaped characters (<code>%0A</code>,
<code>%0D</code>, <code>%22</code>) in field names, matching
<code>file.originalname</code> since 2.3.0: <code>req.body</code> keys,
<code>file.fieldname</code> and <code>err.field</code> now carry the
real name. If you matched the escaped spelling as a workaround, use the
real name now (<a
href="https://redirect.github.com/expressjs/multer/pull/1473">#1473</a>)</li>
<li>Report the decoded filename in <code>err.filename</code> on
<code>LIMIT_FILE_SIZE</code> errors, matching
<code>file.originalname</code> (<a
href="https://redirect.github.com/expressjs/multer/pull/1478">#1478</a>)</li>
<li>Reject non-integer or negative <code>limits</code> values at
construction time; a float limit silently disabled the check (<a
href="https://redirect.github.com/expressjs/multer/pull/1395">#1395</a>,
<a
href="https://redirect.github.com/expressjs/multer/pull/1335">#1335</a>)</li>
<li>Accept requests with exactly <code>limits.parts</code> parts;
<code>LIMIT_PART_COUNT</code> now fires only when the limit is exceeded.
If you set <code>parts</code> one higher to work around this, you can
drop the extra one (<a
href="https://redirect.github.com/expressjs/multer/pull/1446">#1446</a>)</li>
<li>Files skipped by <code>fileFilter</code> no longer count towards
<code>maxCount</code> (<a
href="https://redirect.github.com/expressjs/multer/pull/1426">#1426</a>)</li>
<li>Change the <code>LIMIT_UNEXPECTED_FILE</code> message to
&quot;Unexpected file field&quot; (<a
href="https://redirect.github.com/expressjs/multer/pull/426">#426</a>)</li>
<li>Remove the <code>concat-stream</code> dependency (<a
href="https://redirect.github.com/expressjs/multer/pull/1356">#1356</a>)</li>
<li>Docs: add JSDoc to the public API and document the storage engine
stream contract (<a
href="https://redirect.github.com/expressjs/multer/pull/1467">#1467</a>,
<a
href="https://redirect.github.com/expressjs/multer/pull/1468">#1468</a>)</li>
<li>Docs: add FormData upload examples (<a
href="https://redirect.github.com/expressjs/multer/pull/896">#896</a>)</li>
<li>Docs: remove the translated READMEs (<a
href="https://redirect.github.com/expressjs/multer/pull/1463">#1463</a>)</li>
<li>Internal: run the test suite on macOS (<a
href="https://redirect.github.com/expressjs/multer/pull/1464">#1464</a>)</li>
</ul>
<h2>2.3.0</h2>
<ul>
<li>Fix <a
href="https://www.cve.org/CVERecord?id=CVE-2026-77078">CVE-2026-77078</a>
(<a
href="https://github.com/expressjs/multer/security/advisories/GHSA-wc9g-mqfw-jrwm">GHSA-wc9g-mqfw-jrwm</a>)</li>
<li>Fix <a
href="https://www.cve.org/CVERecord?id=CVE-2026-77037">CVE-2026-77037</a>
(<a
href="https://github.com/expressjs/multer/security/advisories/GHSA-qfvm-cv95-jqjf">GHSA-qfvm-cv95-jqjf</a>)</li>
<li>Fix <a
href="https://www.cve.org/CVERecord?id=CVE-2026-77063">CVE-2026-77063</a>
(<a
href="https://github.com/expressjs/multer/security/advisories/GHSA-qvfw-j98x-7q72">GHSA-qvfw-j98x-7q72</a>)</li>
<li>Fix <a
href="https://www.cve.org/CVERecord?id=CVE-2026-82333">CVE-2026-82333</a>
(<a
href="https://github.com/expressjs/multer/security/advisories/GHSA-535w-7cp7-47q4">GHSA-535w-7cp7-47q4</a>)</li>
<li>Add <code>MulterError</code> codes <code>INVALID_FIELD_NAME</code>
and <code>STREAM_DESTROYED</code></li>
<li>Add opt-in <code>limits.fieldArrayIndexLimit</code> to bound numeric
array indexes in field names (<a
href="https://redirect.github.com/expressjs/multer/pull/1438">#1438</a>)</li>
<li>Accept files whose size is exactly <code>limits.fileSize</code> (<a
href="https://redirect.github.com/expressjs/multer/pull/1407">#1407</a>)</li>
<li>Preserve the caller's async context (<code>AsyncLocalStorage</code>)
when calling <code>next()</code> (<a
href="https://redirect.github.com/expressjs/multer/pull/1124">#1124</a>)</li>
<li>Decode WHATWG-escaped characters (<code>%0A</code>,
<code>%0D</code>, <code>%22</code>) in <code>file.originalname</code>
(<a
href="https://redirect.github.com/expressjs/multer/pull/1421">#1421</a>)</li>
<li>Do not crash when <code>fileFilter</code> invokes its callback more
than once (<a
href="https://redirect.github.com/expressjs/multer/pull/1427">#1427</a>)</li>
<li>Use a fallback message for <code>MulterError</code> codes without a
mapping (<a
href="https://redirect.github.com/expressjs/multer/pull/1448">#1448</a>)</li>
<li>Docs: clarify <code>preservePath</code> and <code>parts</code>, use
<code>crypto.randomBytes</code> in the <code>DiskStorage</code> example
(<a
href="https://redirect.github.com/expressjs/multer/pull/1414">#1414</a>,
<a
href="https://redirect.github.com/expressjs/multer/pull/1430">#1430</a>,
<a
href="https://redirect.github.com/expressjs/multer/pull/1436">#1436</a>)</li>
<li>Docs: add Indonesian, Japanese and Tamil translations and refresh
all translations from the current README (<a
href="https://redirect.github.com/expressjs/multer/pull/1431">#1431</a>,
<a
href="https://redirect.github.com/expressjs/multer/pull/1354">#1354</a>,
<a
href="https://redirect.github.com/expressjs/multer/pull/1462">#1462</a>)</li>
<li>Internal: run the test suite on Windows (<a
href="https://redirect.github.com/expressjs/multer/pull/1334">#1334</a>)</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/expressjs/multer/commit/35979e5afbb814bdb4b750ce028b125eb84c53af"><code>35979e5</code></a>
2.4.0 (<a
href="https://redirect.github.com/expressjs/multer/issues/1469">#1469</a>)</li>
<li><a
href="https://github.com/expressjs/multer/commit/b888532fe2e10ceb13da44286448cb2bb4ce9720"><code>b888532</code></a>
chore(deps): bump github/codeql-action/upload-sarif to 4.37.9 (<a
href="https://redirect.github.com/expressjs/multer/issues/1474">#1474</a>)</li>
<li><a
href="https://github.com/expressjs/multer/commit/e6bcd7db69315714fb9a38b1cd1e0f582cbce65a"><code>e6bcd7d</code></a>
chore(deps): bump github/codeql-action/analyze from 4.37.4 to 4.37.9 (<a
href="https://redirect.github.com/expressjs/multer/issues/1475">#1475</a>)</li>
<li><a
href="https://github.com/expressjs/multer/commit/00dec43b394c5bfaf4efb6d0fe8467bad05525ed"><code>00dec43</code></a>
chore(deps): bump github/codeql-action/init from 4.37.4 to 4.37.9 (<a
href="https://redirect.github.com/expressjs/multer/issues/1476">#1476</a>)</li>
<li><a
href="https://github.com/expressjs/multer/commit/8d5c3b72e430e7edaa2749e96dcb75bf18d84733"><code>8d5c3b7</code></a>
feat: allow diskStorage without options (<a
href="https://redirect.github.com/expressjs/multer/issues/1471">#1471</a>)</li>
<li><a
href="https://github.com/expressjs/multer/commit/02f6e8265b6bf6b6921a819db3b84276efa03ed2"><code>02f6e82</code></a>
fix: report the decoded filename on LIMIT_FILE_SIZE (<a
href="https://redirect.github.com/expressjs/multer/issues/1478">#1478</a>)</li>
<li><a
href="https://github.com/expressjs/multer/commit/bc3f72d5edaa19b993771348e3fb47b366316a88"><code>bc3f72d</code></a>
fix: decode escaped field names, not just filenames (<a
href="https://redirect.github.com/expressjs/multer/issues/1473">#1473</a>)</li>
<li><a
href="https://github.com/expressjs/multer/commit/2661325ba8ca2a72b7fb554b63d2df51da9290c4"><code>2661325</code></a>
docs: add JSDoc to the public API (<a
href="https://redirect.github.com/expressjs/multer/issues/1467">#1467</a>)</li>
<li><a
href="https://github.com/expressjs/multer/commit/53337f9713619ef3381ee6b4e541f926dbaac305"><code>53337f9</code></a>
fix: remove late-completing uploads aborted before the engine names
them</li>
<li><a
href="https://github.com/expressjs/multer/commit/7f2c9ab5f35c0478a7b3bb0f5e1af9b536780132"><code>7f2c9ab</code></a>
feat: add streamHandler option to feed busboy from pre-consumed bodies
(<a
href="https://redirect.github.com/expressjs/multer/issues/1466">#1466</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/expressjs/multer/compare/v2.2.0...v2.4.0">compare
view</a></li>
</ul>
</details>
<details>
<summary>Maintainer changes</summary>
<p>This version was pushed to npm by <a
href="https://www.npmjs.com/~GitHub%20Actions">GitHub Actions</a>, a new
releaser for multer since your current version.</p>
</details>
<br />

---------

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Priya Raman <noreply@paperclip.ing>
canary/v2026.1001.0-canary.2
2026-10-01 15:00:48 +00:00
DottaandPaperclip 0829d94af2 fix(auth): derive low-trust human direction from existing execution records (#14775)
## Thinking Path

> - Paperclip is the open source app people use to manage AI agents for
work.
> - Low-trust review contains work that may include hostile input.
> - Its default intake boundary currently blocks direct human chat and
tasks outside that boundary.
> - Human direction should authorize the assigned work while preserving
containment.
> - Existing conversations and execution requests already identify
direct human instructions.
> - This pull request derives exact-task authority from those records
and the current assignee.
> - The agent can perform that work without gaining access to unrelated
tasks or privileged tools.

## Linked Issues or Issue Description

**What happened?**

A low-trust agent with a project boundary rejects its owner's direct
Agent Chat before provider execution. Human-assigned tasks outside that
project fail the same check.

**Expected behavior**

An authorized human can talk to the agent or assign it a task. The exact
task runs with its existing sandbox, credential, and tool restrictions.

**Steps to reproduce**

1. Enable Agent Chat and isolated workspaces. Configure a sandbox agent
with low-trust review scoped to an intake project.
2. Send the agent a direct board chat message, or assign it a
projectless task.
3. Observe `low_trust_boundary_mismatch` before execution.

Related: #14766 adds private task directories for repo-free low-trust
execution. It is now merged into master and included in the branch base,
so CI and staging verify the combined behavior.

## What Changed

- Derive owner-chat access from existing conversation identity.
- Derive exact-task access from the existing human requester and
server-owned request origin, including coalesced requests. Plugin and
external sender attribution do not authorize work.
- Follow existing `retryOfRunId` database links for automatic
continuations, checking company, agent, and task throughout; cancelled
ancestors cannot grant authority.
- Require a live run and current assignment. Preserve sandbox,
credential, privileged-tool, responsible-user, and quarantined-output
checks.
- Retain board backlog assignments in existing request records without
starting execution. Reassignment cancels old human requests in the
common service transaction, including plugin writes; late settlement
cannot revive them.
- Add real database and HTTP coverage for request provenance, retry
ancestry, cancelled runs, concurrent reassignment, spoofing, and
containment. Document the rule.
- Preserve legacy board assignment requests through their existing
source, reason, and human requester.
- Use the existing wrapped-error helper for concurrent chat-question
idempotency; a deterministic race test reproduces the CI failure before
the fix and passes after it.
- No new schema, migrations, or user-identity fields. Existing requester
columns hold attribution.

## Verification

- Passed the focused database, policy-retention, HTTP, and reassignment
tests locally. The HTTP test creates a task through the real board route
and checks the resulting persisted wakeup before exercising agent reads,
comments, mutations, and review handoff.
- Database tests hold a reassignment transaction open to verify coherent
authorization before and after commit, with a two-connection pool. They
cover retries, coalesced requests, cancelled ancestry, invalid
cross-company/agent/task links, cycles, and forged attribution.
- Full local `pnpm -r typecheck` and `pnpm build` passed on the final
commit (`d107c26df`). [Latest-head
CI](https://github.com/paperclipai/paperclip/actions/runs/36815589542)
passed: 54 successful checks, two expected skips, including all eight
browser-test shards. Greptile is 5/5 on this exact commit with no
unresolved threads. Local tests were targeted; the full test suite ran
through CI’s test matrix.
- The revised HTTP suite passed all 13 tests; database authorization
tests passed all 11, including legacy compatibility and late watchdog
settlement; the backlog route contract passed all 3 tests. Another 102
tests covering durable chat admission, wake queues, and Cursor execution
passed.
- All 90 interaction-service tests passed with both create calls
deliberately held until their optimistic reads complete, forcing
duplicate-key recovery. That forced race failed before switching to the
shared wrapped-error helper.
- Previous staging proof covered owner chat and projectless task
persistence. The simplified revision has not been redeployed; that
earlier proof is not claimed for the new implementation.

## Risks

- This is an authorization change: only the live run's exact task
qualifies, and normal responsible-user restrictions still apply.
- Existing request and retry records are authoritative. Merely naming a
responsible/originating user or an external connector sender does not
qualify.
- Reassignment invalidates existing human request records
transactionally. A cancelled run or request cannot regain authority when
the task is assigned back.
- Ordinary task exceptions require server-owned origin or the legacy
board assignment source/reason/actor combination. Existing owner chats
use conversation identity.

## Model Used

OpenAI GPT-6 in Codex, with reasoning, repository tools, code execution,
and browser testing. The runtime does not expose a more specific model
ID or context-window size.

## Checklist

- [x] I have included a thinking path that traces from project context
to this change
- [x] I have specified the model used (with version and capability
details)
- [x] I have checked ROADMAP.md and confirmed this PR does not duplicate
planned core work
- [x] I have searched GitHub for duplicate or related PRs and linked
them above
- [x] I have either (a) linked existing issues with `Fixes: #` / `Closes
#` / `Refs #` OR (b) described the issue in-PR following the relevant
issue template
- [x] I have not referenced internal/instance-local Paperclip issues or
links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip`
URLs)
- [x] My branch name describes the change (e.g. `docs/...`, `fix/...`)
and contains no internal Paperclip ticket id or instance-derived details
- [x] I have run tests locally and they pass
- [x] I have added or updated tests where applicable
- [x] I have updated relevant documentation to reflect my changes
- [x] I have considered and documented any risks above
- [x] All Paperclip CI gates are green
- [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups
- [x] I will address all Greptile and reviewer comments before
requesting merge

---------

Co-authored-by: Paperclip <noreply@paperclip.ing>
2026-10-01 09:45:18 -05:00
467125fafb feat(connections): one-screen connector setup with stated defaults (#14811)
## Thinking Path

> - Paperclip is the open source app people use to manage AI agents for
work
> - Agents use Connections (the Apps catalog) to act in services like
Notion, GitHub, Google Workspace and Railway
> - Each connector asked the user to answer setup questions before it
went to the provider. Most of the questions already had the correct
answer selected
> - ROADMAP.md lists "simpler setup" for Apps and Connections as ongoing
work. This change continues that work
> - This pull request removes the questions that Paperclip can answer
itself. It states the defaults in one line and moves the choices behind
"Change" and onto the Permissions tab
> - The benefit is that most connectors take one click in Paperclip and
then the provider's own consent screen

## Linked Issues or Issue Description

No public issue exists. This is the description, from the enhancement
template.

**What existing behavior does this improve?**
The setup flow for tool connectors in the Apps catalog.

**Subsystem affected**
Apps and Connections: `ui/src/features/connections`,
`ui/src/pages/apps`, the `packages/shared` app definitions, and the
OAuth routes in `server/src/routes/tool-access.ts`.

**Current behavior**
Every connector opened with an Access step. The step asked who can use
the connection and which agents get it, and both answers were already
selected. 18 connectors also asked "How do you want to connect?" when
Paperclip could rank the methods. The Google apps and Postman also asked
"What should Paperclip be able to do?" before sign-in. The four gateway
connectors (Zapier, Arcade, Composio, Executor) used a separate two-step
wizard. Asana was pinned to a customer-owned OAuth app, so the user had
to register an app in Asana's developer console. The "Set all" control
on the Permissions tab changed only one action. After the user approved
access, Railway's consent page showed "you can close this window" and
did not return to Paperclip.

**Proposed behavior**
One screen per connector, with one primary button. The screen states the
defaults in one sentence, for example "Connects for everyone in your
organization, available to all agents". A "Change" link opens one
Advanced panel. When the provider's metadata allows dynamic client
registration, Paperclip registers a client itself. Connecting lands on
the Permissions tab. On that tab, "Set all" changes every action in the
group.

**Reason and benefit**
The user makes fewer decisions before the connection exists. Most
choices are easier to make after the connection, on the Permissions tab,
where a change has an immediate effect.

**Breaking changes**
None. No schema or API change. Existing connections keep their settings.

## What Changed

- **No Access step.** `ConnectionSetupFlow` no longer has the Access
step. The flow shows the resolved default above the primary button and
on the completion screen. The access controls moved into one Advanced
panel. The panel opens automatically only when a setting in it is
required.
- **A default method for every app.** The flow always picks the ranked
default method. Alternate methods are in the Advanced panel. The Google
and Postman capability choice is not asked before sign-in. The
write-capable method is the default.
- **Gateway connectors.** `RemoteMcpProductionSetup` (Zapier, Arcade,
Composio, Executor) no longer has its own Access step. Its commit path
and the main commit path use one helper, `askFirstCatalogEntryIdsFor`,
for server-suggested defaults.
- **Dynamic registration from live metadata.**
`canRegisterOAuthClientDynamically` now allows registration when the
provider advertises a registration endpoint, even if the catalog entry
lists only customer-owned clients. The Asana and Linear definitions and
catalog text match live probes. Asana issues clients for loopback
callbacks only, so a hosted deployment still needs an Asana app.
- **Connection setup states.** New
`packages/shared/src/connection-setup-state.ts` sorts each method into
`instant`, `authorize`, `paste` or `register`. The gallery card verb
("Connect" or "Add key") comes from this resolver and the instance's
ownership availability.
- **Generic MCP.** The generic path no longer asks "Does it need a key?"
first. A credential challenge from the server shows the key field.
- **Permissions tab.** Each action row shows its risk level. Each group
has a "Set all" control. The control sends one change for the whole
group. Before, each row's save started from the same render, so the
saves overwrote each other. The Zapier/Arcade/Composio/Executor setup
screen had the same defect.
- **OAuth callback interstitial.** A cross-site browser navigation to
`/api/tools/oauth/callback` gets a small same-origin "Finishing your
connection…" page. That page repeats the request, and the repeat does
the code exchange. Railway's consent page replaces itself after about
two seconds, and the code exchange plus tool discovery takes longer than
that. The interstitial uses only a meta refresh, because the OAuth code
is single-use. Requests without `Sec-Fetch-Site: cross-site` take the
old path.
- **Linear registers through its MCP server.** Linear pins the console
endpoints at `linear.app`. Pinned endpoints now replace discovery only
when the method cannot register, or when the connection has an
operator-entered client. So a Linear connection now finds the
registration endpoint at `mcp.linear.app`.
- **Own-OAuth-app recovery stays on the one-click screen.** When the
method also accepts a customer-owned client, the client fields are in
the Advanced panel. The panel opens after a failed sign-in. "Try again"
resumes the draft with the operator's client.
- **E2E specs** follow the one-screen flow. The Access-step clicks are
removed, the specs open **Change** before they pick agents, and they
expect GitHub's **Add key** verb.
- **Default permissions do not change.** New connections still allow
every action. The user can set actions to Ask first or Off on the
Permissions tab.

## Verification

- `cd ui && npx vitest run src/pages/apps src/features/connections
--no-file-parallelism`
- `cd packages/shared && npx vitest run src/app-definitions.test.ts
src/connection-setup-state.test.ts`
- `cd server && npx vitest run src/__tests__/tool-access-service.test.ts
src/__tests__/remote-mcp-connectors.test.ts`
- `pnpm check:token-gates`
- New tests:
- `PermissionsPanel.group.test.tsx` checks that "Set all" sends one
change for the whole group. It fails on the old code.
  - `action-permissions.test.ts` checks the group update.
  - `connection-setup-state.test.ts` checks the four setup states.
- A server test checks that a cross-site callback gets the interstitial
and does not use the OAuth state, and that the same-origin repeat
completes the connection.
- Manual check on a hosted staging deployment. GitHub, Google Drive,
Composio, Notion, PostHog and Railway each connected from one screen and
returned to the Permissions tab. On Railway, "Set all" changed all 65
write actions, and the change remained after a reload.
- Visual changes: snapshot baselines are intentionally not updated. See
the `doc/design/DECISION-SHEET.md` entry "Per-change snapshot
verification demoted to dormant (Jul 13 2026)".

## Risks

- **Fewer confirmation clicks.** Organization-wide access is the
default, and the user does not confirm it on a separate step. This was
already the preselected answer. The flow shows the default before the
user clicks and again after the connection.
- **Google write scope.** Google apps now request the write-capable
scope by default. A narrower scope needs a new sign-in.
- **Dynamic registration from live metadata.** A provider can advertise
registration and then reject a redirect URI. Asana rejects hosted
callbacks, for example. In that case registration fails, and the
customer-owned client path remains available for recovery.
- **Callback interstitial.** The OAuth callback adds one same-origin
step for cross-site browser navigations. Browsers without `Sec-Fetch-*`
headers use the old direct path.
- Chat and bot connectors (Discord, Telegram, Microsoft Teams, iMessage)
do not change.

> For core feature work, check [`ROADMAP.md`](ROADMAP.md) first and
discuss it in `#dev` before opening the PR. Feature PRs that overlap
with planned core work may need to be redirected — check the roadmap
first. See `CONTRIBUTING.md`.

## Model Used

- Claude Opus 5.5 (Anthropic), model ID `claude-opus-5-5`, used through
Claude Code with tool use (shell, file editing, browser automation) and
extended thinking. It wrote the code, the tests and this description. A
human product owner directed the work and tested it by hand.

## Checklist

- [x] I have included a thinking path that traces from project context
to this change
- [x] I have specified the model used (with version and capability
details)
- [x] I have checked ROADMAP.md and confirmed this PR does not duplicate
planned core work
- [x] I have searched GitHub for duplicate or related PRs and linked
them above
- [x] I have either (a) linked existing issues with `Fixes: #` / `Closes
#` / `Refs #` OR (b) described the issue in-PR following the relevant
issue template
- [x] I have not referenced internal/instance-local Paperclip issues or
links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip`
URLs)
- [x] My branch name describes the change (e.g. `docs/...`, `fix/...`)
and contains no internal Paperclip ticket id or instance-derived details
- [x] I have run tests locally and they pass
- [x] I have added or updated tests where applicable
- [x] I have updated relevant documentation to reflect my changes
- [x] I have considered and documented any risks above
- [x] All Paperclip CI gates are green
- [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups
- [x] I will address all Greptile and reviewer comments before
requesting merge

🤖 Generated with [Claude Code](https://claude.com/claude-code)

---------

Co-authored-by: scotttong <squadbot000@gmail.com>
Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
canary/v2026.1001.0-canary.1 nightly/v2026.1001.0-nightly.0 beta/v2026.1002.0-beta.0 v2026.1005.0
2026-09-30 23:13:47 -07:00
Devin FoleyandPaperclip 0d3e7bf6ac fix(daytona): keep commands alive after log stream closure (#14799)
## Thinking Path

> - Paperclip is the open source app people use to manage AI agents for
work.
> - Sandbox providers run agent processes and send their output to the
host.
> - The Daytona SDK can close a log socket while the remote command
still runs.
> - The driver treated a clean socket close as completion before it had
a command exit code.
> - This pull request recovers log observation for the same command and
waits for a recorded exit.
> - The host keeps receiving new output without a second command
dispatch.

## Linked Issues or Issue Description

**What happened?**

A clean close of the Daytona session log WebSocket resolves the SDK
callback promise. If the command still runs, the driver returned
`exitCode: null` with `timedOut: false` after a short status check. A
streamed ACP bridge can then report a process disconnect.

**Expected behavior**

A log socket close must not complete a running command. Recovery must
preserve new output, the caller's lifetime controls, and one command
dispatch.

**Steps to reproduce**

Use the callback form of `getSessionCommandLogs`. Let that promise
resolve while `getSessionCommand` still has no exit code. Keep the
command running, then expose its final logs and exit code. The new
regressions exercise this sequence, including streams that run longer
than the provider operation timeout.

Related: #11021, #11049. #14485 covers input delivery retries, which are
a separate transport path.

## What Changed

- Require a recorded command exit after a clean log-stream close.
Reconnect once, then read status and full log snapshots at most once per
second.
- Forward new output during recovery. Remove replayed prefixes and
reconcile a final snapshot so bytes written after socket close are
retained.
- Hold a trailing UTF-8 replacement suffix until replay or completion
resolves it. This handles the SDK decoder flush when a socket closes in
the middle of a character.
- Preserve healthy initial and reconnected stream lifetimes. Bound each
recovery read. Preserve the existing fallback timeout budget after
rejected stream attempts.
- Retain partial output on timeout. A log-observation timeout reports an
unconfirmed result and preserves any observed exit code in metadata; it
does not synthesize successful completion.

## Verification

- `pnpm exec vitest run --config
packages/plugins/sandbox-providers/daytona/vitest.config.ts`: 335
passed, 14 gated tests skipped.
- `pnpm exec vitest run --project @paperclipai/plugin-daytona`: 335
passed, 14 gated tests skipped.
- `pnpm exec tsc --noEmit -p
packages/plugins/sandbox-providers/daytona/tsconfig.json`: passed.
- `pnpm exec tsc -p
packages/plugins/sandbox-providers/daytona/tsconfig.json`: passed.
- `pnpm --workspace-concurrency=1 -r typecheck`: passed.
- `CARGO_BUILD_JOBS=2 pnpm --workspace-concurrency=1 -r build`: passed.
- `pnpm test:run`: exited with failure after 845.77 seconds. The server
phase reported 43 failed files, 529 passed, and 163 skipped; 14 failed
tests, 9,122 passed, and 5,599 skipped. All failure entries were traced
to local PostgreSQL startup/cleanup errors or ten macOS skill-cache
rename errors. The package helper restored 17 missing PostgreSQL library
links; the four sequencing/migration tests and fourteen
native-workspace-finalizer tests then passed. The ten cache failures
match clean-base evidence with identical source/test blobs. This is not
a full-suite pass; later local test groups did not run. PR CI supplies
the complete check result.
- Regressions cover clean and rejected stream recovery, two hour-long
streams with a five-minute operation budget, live fallback output, one
dispatch, delayed final output, stale snapshots, SDK UTF-8 decoding,
bounded observation, and timer cleanup.
- `git diff --check` and a local diff scan for secrets and private
identifiers passed.
- Greptile reviewed head `293c4dbe67` at 5/5. Both prior findings are
fixed, both threads are resolved, and no new actionable findings remain.

## Risks

- The SDK returns full snapshots with no offset API. After both stream
attempts end, polling bandwidth grows with retained output. The
one-second cadence limits request frequency.
- The SDK callback stream has no cancellation handle. Existing caller
stop logic and provider/session teardown still own its lifetime. Late
callbacks from a settled stream are ignored.
- A successful status read with no exit code keeps recovery active under
the existing caller guard. A failed read stops recovery; it is not
retried indefinitely.
- No command replay, provider API change, schema migration, or runtime
timeout policy change is included.

## Model Used

OpenAI GPT-6 through Codex, with tool use and independent code review.
The exact serving model identifier is not exposed in this session.

## Checklist

- [x] I have included a thinking path that traces from project context
to this change
- [x] I have specified the model used (with version and capability
details)
- [x] I have checked ROADMAP.md and confirmed this PR does not duplicate
planned core work
- [x] I have searched GitHub for duplicate or related PRs and linked
them above
- [x] I have either (a) linked existing issues with `Fixes: #` / `Closes
#` / `Refs #` OR (b) described the issue in-PR following the relevant
issue template
- [x] I have not referenced internal/instance-local Paperclip issues or
links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip`
URLs)
- [x] My branch name describes the change (e.g. `docs/...`, `fix/...`)
and contains no internal Paperclip ticket id or instance-derived details
- [ ] I have run tests locally and they pass
- [x] I have added or updated tests where applicable
- [x] I have updated relevant documentation to reflect my changes
- [x] I have considered and documented any risks above
- [ ] All Paperclip CI gates are green
- [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups
- [x] I will address all Greptile and reviewer comments before
requesting merge

---------

Co-authored-by: Paperclip <noreply@paperclip.ing>
2026-09-30 18:37:54 -07:00
Devin FoleyandPaperclip 0dc8d80eea Clarify worktree seed source setup failures (#14795)
## Thinking Path

> - Paperclip is the open source app people use to manage AI agents for
work.
> - Managed worktrees can prepare an isolated Paperclip development
instance.
> - The built-in provisioner requires a canonical registered seed source
config.
> - A missing source currently has the same message as a rejected
symlink or non-regular file.
> - This pull request separates those messages and names the supported
setup choices.
> - Operators can choose the intended setup without changing the
source-validation guards.

## Linked Issues or Issue Description

**What happened?**

A plain repository checkout can select the control-plane instance as its
seed source. If that instance runs with environment-only configuration,
the source config file can be unavailable. The provisioner stops with a
message that also covers noncanonical files and gives no repair
guidance.

**Expected behavior**

The error should identify the selected source and distinguish an
unavailable prerequisite from a rejected file. It should explain that a
seeded development instance needs a canonical registered source. It
should describe the explicit no-op only for a checkout-only worktree.

**Steps to reproduce**

1. Use a plain base checkout with no repository-local config.
2. Leave the control-plane instance config file absent.
3. Run the built-in worktree provisioner against an isolated checkout.

**Paperclip version or commit**

Base commit `c8f874311c`.

**Deployment mode**

Managed local worktrees, including servers configured only through
environment variables.

Related: #11733 adds deeper source-readiness checks. #11735 changes
runtime and seed lifecycle handling. This change only improves the
existing shell guard's diagnostics.

## What Changed

- Distinguish unavailable source configs from symlinks and non-regular
files.
- Identify whether the selected source belongs to the base workspace or
control-plane instance.
- Explain seeded-instance prerequisites and the explicit checkout-only
setup choice.
- Verify failure still precedes target-state creation and CLI
invocation.
- Document the setup choice and its runtime-readiness limit.

## Verification

- `node --test scripts/__tests__/provision-worktree-self-heal.test.mjs`:
21 passed; one platform-gated test skipped because macOS lacks `flock`.
- `bash -n scripts/provision-worktree.sh` and `git diff --check`:
passed.
- `pnpm -r typecheck`: passed.
- `pnpm exec vitest run server/src/__tests__/ai-connections.test.ts`: 50
passed after running the installed PostgreSQL package's own symlink
hydration script in this worktree.
- `pnpm test:run`: attempted, then stopped after unrelated database
suites failed at startup. The offline install had omitted PostgreSQL
native library symlinks. The focused database rerun above verifies the
local repair; the complete suite is delegated to CI.
- `pnpm build`: passed.

- [Required PR
CI](https://github.com/paperclipai/paperclip/actions/runs/36797650741)
passed on `0a3ba63e12`: 50 successful checks and two intentional
Storybook skips. Greptile scored that exact commit 5/5; there are zero
unresolved review threads and no merge conflicts.

## Risks

- Diagnostics only. This does not supply a source config or repair an
existing blocked task.
- The failure predicates and exit status stay unchanged. Symlink and
non-regular-file errors do not recommend skipping setup.
- The checkout-only no-op requires an explicit policy choice. It does
not grant runtime or seed readiness.
- No schema, migration, tenant policy, deployment, or Sentry reporting
change.

## Model Used

OpenAI GPT-6-based Codex, with reasoning, shell tools, and code
execution. The exact serving model ID and context-window size are not
exposed by this session.

## Checklist

- [x] I have included a thinking path that traces from project context
to this change
- [x] I have specified the model used (with version and capability
details)
- [x] I have checked ROADMAP.md and confirmed this PR does not duplicate
planned core work
- [x] I have searched GitHub for duplicate or related PRs and linked
them above
- [x] I have either (a) linked existing issues with `Fixes: #` / `Closes
#` / `Refs #` OR (b) described the issue in-PR following the relevant
issue template
- [x] I have not referenced internal/instance-local Paperclip issues or
links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip`
URLs)
- [x] My branch name describes the change (e.g. `docs/...`, `fix/...`)
and contains no internal Paperclip ticket id or instance-derived details
- [x] I have run tests locally and they pass
- [x] I have added or updated tests where applicable
- [x] I have updated relevant documentation to reflect my changes
- [x] I have considered and documented any risks above
- [x] All Paperclip CI gates are green
- [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups
- [x] I will address all Greptile and reviewer comments before
requesting merge

Co-authored-by: Paperclip <noreply@paperclip.ing>
2026-09-30 18:35:33 -07:00
Devin FoleyandPaperclip 4b9a6000f7 Add bounded evidence for directory lock timeouts (#14787)
## Thinking Path

> - Paperclip is the open source app people use to manage AI agents for
work.
> - Agent files use directory locks during collection and cleanup.
> - A lock timeout can fail finalization after the model turn completes.
> - The timeout currently identifies no owner state or waiting
operation.
> - This pull request adds bounded evidence to the existing run failure
report.
> - Operators can distinguish a known local holder from a possible old
lock without changing lock safety.

## Linked Issues or Issue Description

**What happened?**

A directory lock timeout does not distinguish active local work from an
owner record left by an earlier process. The stored execution stage can
also precede the cleanup operation that failed.

**Expected behavior**

The failure report should identify the waiting operation and expose
bounded ownership clues. It must preserve the timeout and keep unknown
ownership protected.

**Steps to reproduce**

Hold a directory merge lock while a second caller reaches its
acquisition deadline. The regression tests exercise a live holder and an
older owner record with a live PID.

Related: #9667 proposes stale-lock recovery under a single-server
assumption. This change only adds evidence and does not adopt that
assumption. #14575 and #14665 add other run failure diagnostics.

## What Changed

- Record lock owner state, capped age and wait duration, same-process
and process-age comparisons, and whether this module holds the lock.
- Label agent-directory release, collection, checkpoint, and warm
handoff timeouts with a fixed operation code.
- Validate each field before the existing event-local Sentry report
accepts it. Exclude owner records, PIDs, paths, and absolute timestamps.
- Limit the extra diagnostic owner read to 100 ms with best-effort
abort; malformed JSON is `invalid` and unreadable owner records remain
`unknown`.
- Document the diagnostic limits and verify that contenders never
reclaim protected locks.

## Verification

- Focused lock, diagnostic, real Sentry SDK, and database-backed
agent-directory tests: 126 passed, including stalled-read and
malformed/missing/unreadable-owner regression coverage.
- Final revision `0691613dcc`: all 54 reported checks successful, with
two intentionally skipped Storybook checks. Greptile: 5/5, zero
unresolved review threads; no merge conflicts.
- `pnpm -r typecheck`: passed.
- `pnpm build`: passed.
- `pnpm test:run`: complete suite coverage ran with the existing
repository shard flags: four general-server shards, four serialized
shards, two general-workspaces-a shards, and general-workspaces-b. The
full run is not green because of the base failures below.
- The broad run found 13 failures in the unchanged macOS skill-cache
tests. All 13 reproduce on the clean base revision. Open PR #14290
covers that existing failure.
- Two unchanged CLI archive tests hit their five-second limits during
the broad run; all 17 tests in that file pass on recheck. A CLI auth
socket error also cleared on recheck (19 tests), and its full serialized
shard passed on rerun.

## Risks

This is a diagnostic change, not a stale-lock fix. Owner observations
can race with release. Wall-clock shifts can affect the age comparison.
A local-holder flag covers only this module instance. None of these
fields authorizes reclamation or proves a file save. Lock acquisition,
release, retries, task status, and recovery guards retain their current
behavior. No schema change or deployment action is required.

## Model Used

OpenAI Codex, based on GPT-6, with code execution and repository tools.
The exact model build and context window were not exposed to this agent.

## Checklist

- [x] I have included a thinking path that traces from project context
to this change
- [x] I have specified the model used (with version and capability
details)
- [x] I have checked ROADMAP.md and confirmed this PR does not duplicate
planned core work
- [x] I have searched GitHub for duplicate or related PRs and linked
them above
- [x] I have either (a) linked existing issues with `Fixes: #` / `Closes
#` / `Refs #` OR (b) described the issue in-PR following the relevant
issue template
- [x] I have not referenced internal/instance-local Paperclip issues or
links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip`
URLs)
- [x] My branch name describes the change (e.g. `docs/...`, `fix/...`)
and contains no internal Paperclip ticket id or instance-derived details
- [ ] I have run tests locally and they pass (focused checks pass;
existing base failures are documented above)
- [x] I have added or updated tests where applicable
- [x] I have updated relevant documentation to reflect my changes
- [x] I have considered and documented any risks above
- [x] All Paperclip CI gates are green
- [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups
- [x] I will address all Greptile and reviewer comments before
requesting merge

---------

Co-authored-by: Paperclip <noreply@paperclip.ing>
2026-09-30 18:35:12 -07:00
842efe0181 fix(ui): stack project field save indicator below its label (#14765)
## Thinking Path

> - Paperclip is the open source app people use to manage AI agents for
work.
> - The web UI has a project detail page. A properties panel on that
page lets a user edit the project name, description, and other fields.
> - Each field shows a "Saving...", "Saved", or "Failed" indicator while
an edit is in progress.
> - The indicator was rendered next to the label text in a fixed 80px
label column. The "Description" label almost fills that column, so the
indicator spilled into the value column and covered the description
text.
> - A user cannot read the description while the indicator is visible.
This looks broken and it hides content.
> - This pull request stacks the indicator directly below the label
text, so it stays inside the label column.
> - The benefit is that the indicator never covers the field value, for
the description and for every other labelled field.

## Linked Issues or Issue Description

No public GitHub issue exists for this bug. The issue is described here.

**What happened?**

When a user edits a project description in the project properties panel,
the "Saving..." and "Saved" indicator appears next to the "Description"
label. The label column is 80px wide. The indicator does not fit, so it
overflows into the value column and overlaps the description text.

**Expected behavior**

The "Saving..." / "Saved" / "Failed" indicator must appear directly
below the "Description" label. It must not overlap the description text
or any other field value.

**Steps to reproduce**

1. Open a project in the Paperclip web UI.
2. Click the Description field in the properties panel and change the
text.
3. Click outside the field to save.
4. Look at the "Description" label while the "Saving..." and then
"Saved" indicator is visible. The indicator overlaps the description
text.

**Paperclip version or commit**

master at `5edf55d7350c7f08c9dd132c7e0f1421fa0bf2fb`.

**Deployment mode**

Local development (`pnpm dev`). The bug is in the UI layout, so it
applies to every deployment mode.

## What Changed

- `ui/src/components/ProjectProperties.tsx`: `FieldLabel` now renders
the label text and the `SaveIndicator` in a vertical flex column
(`flex-col`) instead of a horizontal row. The indicator sits directly
below the label and stays inside the 80px label column. This applies to
every labelled property row (Name, Description, Env, and so on), so no
label can overflow.
- `ui/src/components/ProjectProperties.save-indicator.test.tsx`: new
regression test. It asserts that the indicator is a stacked sibling
under the Description label for the `saving` and `saved` states, and
that no indicator renders for the `idle` state.

## Verification

- Run `pnpm --filter @paperclipai/ui exec vitest run
src/components/ProjectProperties` from the repo root. All
ProjectProperties tests pass, including the new save-indicator test.
- The new test fails against the previous inline layout (2 of 3 cases
fail) and passes with this change (3 of 3 cases pass).
- The existing `ProjectProperties.concurrency`,
`ProjectProperties.managed-sandbox`, and `ProjectDetail` tests pass (18
tests).
- `tsc -b` in `ui/` reports no errors in the changed files.
- Manual check: open a project, edit the description, and save. The
"Saving..." and "Saved" indicator now appears below the "Description"
label and does not cover the description text.

## Risks

- Low risk. The change is a single flex-direction swap on the label
wrapper in one component.
- Every labelled row in the project properties panel gets a slightly
taller label cell while an indicator is visible. This is intentional and
it matches the requested layout.
- No data, API, or migration changes.

## Model Used

- Claude Fable 5.1 (Anthropic), model id `claude-fable-5-1`, with
extended thinking and tool use, run through Claude Code inside a
Paperclip agent session. A human reviewed the change and the pull
request text.

## Checklist

- [x] I have included a thinking path that traces from project context
to this change
- [x] I have specified the model used (with version and capability
details)
- [x] I have checked ROADMAP.md and confirmed this PR does not duplicate
planned core work
- [x] I have searched GitHub for duplicate or related PRs and linked
them above
- [x] I have either (a) linked existing issues with `Fixes: #` / `Closes
#` / `Refs #` OR (b) described the issue in-PR following the relevant
issue template
- [x] I have not referenced internal/instance-local Paperclip issues or
links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip`
URLs)
- [ ] My branch name describes the change (e.g. `docs/...`, `fix/...`)
and contains no internal Paperclip ticket id or instance-derived details
- [x] I have run tests locally and they pass
- [x] I have added or updated tests where applicable
- [x] I have updated relevant documentation to reflect my changes
- [x] I have considered and documented any risks above
- [x] All Paperclip CI gates are green
- [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups
- [x] I will address all Greptile and reviewer comments before
requesting merge

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-authored-by: Bender (Fable) <bender@paperclip.local>
Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com>
2026-09-30 18:34:41 -07:00
Devin FoleyandPaperclip 98d8a6ccac Stop replaying ambiguous database disconnects (#14773)
## Thinking Path

> - Paperclip stores agent work and control state in PostgreSQL.
> - Its database client must not repeat a mutation after an uncertain
result.
> - The global retry wrapper treated `write CONNECTION_CLOSED` as proof
that PostgreSQL never received a statement.
> - postgres.js also uses that message when the connection closes after
statement delivery.
> - This pull request removes that global replay and tests the actual
driver over a local wire connection.
> - Callers retain control of retries when they can prove the complete
operation is idempotent.

## Linked Issues or Issue Description

Follow-up to #13417. Preserve the transaction disconnect handling from
#13643 and the explicit actor synchronization retries introduced in
#12773. Searched open and closed issues and PRs for database retries,
disconnects, and `CONNECTION_CLOSED`. The open circuit-breaker proposal
#11142 addresses outage queue growth; it does not establish whether an
already-sent statement can be replayed.

**What happened?**
The database wrapper replayed an arbitrary statement up to three times
after `write CONNECTION_CLOSED`. The driver adds `write ` to
connection-close errors even after the peer receives the statement. A
local protocol peer receives the same submitted INSERT three times when
it drops each response. A committed write could therefore execute more
than once.

**Expected behavior**
An ambiguous statement result must fail without automatic replay. A
subsequent operation must be able to reconnect.

**Steps to reproduce**
Run the new wire regression against the parent commit. The six Simple
Query cases and the parameterized Drizzle case receive three executions
instead of one. The named prepared-client case was already safe and
stays covered. The peer reads the entire statement and then closes the
connection. This demonstrates repeated delivery with the real driver; it
does not claim that a historical incident duplicated a committed write.

**Paperclip version or commit**
Reproduced on source commit `018993140f` with the patched postgres.js
3.4.9 dependency.

**Deployment mode**
Built from source with a local PostgreSQL protocol peer. No live
provider or customer database is used.

## What Changed

- Pass the original postgres.js client to Drizzle and remove the global
statement replay wrapper.
- Add eight wire regressions: six Simple Query cases for INSERT,
side-effect-capable SELECT, and a data-changing CTE, plus parameterized
Drizzle and named prepared-client cases. The extended peer processes
Parse, Describe, Bind, and Execute, verifies bound parameters, and drops
the response only after Execute. Each case checks one delivery and
recovery on a fresh query.
- Document ambiguous outcomes and the retry compatibility tradeoff. Keep
explicit idempotent actor-sync retries and disconnected-transaction
handling unchanged.

## Verification

- Before the fix: the six Simple Query cases and the parameterized
Drizzle case failed with three executions instead of one. The named
prepared-client case was already safe. All eight wire cases pass on this
branch.
- Final focused client, pool teardown, configuration, and actor-sync
retry checks: 28 tests passed. `pnpm --filter @paperclipai/db typecheck`
also passed after the test-only follow-up.
- First implementation head, `pnpm exec vitest run --project
@paperclipai/db`: all 158 tests passed across 45 files, including real
PostgreSQL transaction/reserved-connection recovery. The local embedded
dependency's symlinks were hydrated before this run.
- `pnpm -r typecheck`: passed.
- `pnpm build`: passed.
- The complete local `pnpm test:run` did not finish; no complete local
suite pass is claimed. All CI test, typecheck, and build gates passed on
the first implementation head `11f8b22d90`. Final-head CI is pending
after the test-only follow-up.
- `git diff --check`: passed. Reviewed the diff for secrets, personal
data, generated output, and run artifacts.

## Risks

Some transient statement failures that the global wrapper previously
replayed now reach the caller. Operation owners must retry only when
they have an idempotency guarantee or a durable receipt that prevents
duplicate effects. A connection error is not proof that a write failed
to commit. There is no SQL-text retry heuristic, new suppression, schema
change, or migration. This change prevents unsafe replay; it does not
prevent network disconnects.

## Model Used

OpenAI Codex / GPT-6, with reasoning, repository inspection, code
execution, and local protocol tests. The exact backend model ID and
context-window size are not exposed in this session.

## Checklist

- [x] I have included a thinking path that traces from project context
to this change
- [x] I have specified the model used (with version and capability
details)
- [x] I have checked ROADMAP.md and confirmed this PR does not duplicate
planned core work
- [x] I have searched GitHub for duplicate or related PRs and linked
them above
- [x] I have either (a) linked existing issues with `Fixes: #` / `Closes
#` / `Refs #` OR (b) described the issue in-PR following the relevant
issue template
- [x] I have not referenced internal/instance-local Paperclip issues or
links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip`
URLs)
- [x] My branch name describes the change (e.g. `docs/...`, `fix/...`)
and contains no internal Paperclip ticket id or instance-derived details
- [x] I have run tests locally and they pass
- [x] I have added or updated tests where applicable
- [x] I have updated relevant documentation to reflect my changes
- [x] I have considered and documented any risks above
- [ ] All Paperclip CI gates are green
- [ ] Greptile is 5/5 with no open P2s, recommendations, or follow-ups
- [x] I will address all Greptile and reviewer comments before
requesting merge


Final verification (September30): every final-head CI check passed at
`3004c5bda39c985c3557547ec45e33870ce5d010`. Greptile scored5/5 on this
head, all review threads are resolved, and the branch is mergeable.
Eight real-wire regressions cover simple, parameterized Drizzle, and
named prepared queries. Full local suite did not produce a completed
result; the complete CI matrix passed. This public PR remains open for
maintainer merge.

---------

Co-authored-by: Paperclip <noreply@paperclip.ing>
canary/v2026.1001.0-canary.0
2026-09-30 18:34:00 -07:00
DottaandPaperclip c8f874311c fix(ui): hide Google connectors only on the Connections page (#14774)
## Thinking Path

> - Paperclip helps people manage AI agents for work.
> - The Connections page lists the apps and saved accounts that agents
can use.
> - Google Workspace verification is still pending.
> - Google entries must be temporarily hidden from this page without
removing their implementations.
> - This PR filters the final page rows, including saved Google
accounts, after the page resolves their provider.
> - Definitions, direct setup routes, OAuth profiles, credentials, and
runtime access stay intact.
> - Review instances can keep the prior UI by staying on their pinned
app release.

## Linked Issues or Issue Description

**What existing behavior does this improve?**

Temporary provider visibility on the Connections landing page.

**Current behavior**

The page can show Google Workspace catalog entries and saved accounts
while verification is pending.

**Proposed behavior**

Hide all nine Google Workspace rows on this page. Keep every other
connector and all Google integration code unchanged. Use an existing
release pin for review instances instead of a hostname exception in the
app.

**Reason and benefit**

Pause public discovery without disabling existing runtime tools or
removing the implementation needed for verification and later
re-enablement.

**Breaking changes**

Google accounts are no longer visible on this landing page. Direct setup
and management routes remain available. This is not an access-control
restriction.

Related completed work: #13551 used catalog-level visibility. This
change is deliberately limited to the landing page and also covers saved
account rows. #14740 reduced Google scopes; this change leaves those
scopes unchanged. No duplicate open PR or matching open issue was found.

## What Changed

- Derive the Google app slugs from the existing Workspace profile
registry.
- Filter the combined catalog and saved-account rows only inside
`Browse`.
- Cover all nine Google entries, active/draft/disabled accounts, legacy
connection metadata, mixed-provider rows, and independently identified
non-Google connectors in regression tests.
- Document the display-only hold, pinned review builds, and how to
restore visibility after approval.

## Verification

- Passed: `pnpm exec vitest run ui/src/pages/apps/Browse.test.tsx
ui/src/pages/apps/AppsConnect.test.tsx` (199 tests, including the latest
master changes).
- Passed: `pnpm check:token-gates`.
- Passed: `pnpm build`.
- Passed: `pnpm -r typecheck` and `pnpm build` after merging the latest
master. An earlier overlapping run hit a local runner codesign race;
sequential checks passed.
- Passed again after the final custom-provider fix: `pnpm --filter
@paperclipai/ui typecheck` and `pnpm --filter @paperclipai/ui build`.
- The full local `pnpm test:run` was started, then stopped after the
full remote CI suite passed to avoid continuing duplicate long-running
work on the developer machine. It is not claimed as a completed local
pass.
- All 54 latest-head CI checks passed. Two non-applicable Storybook jobs
were skipped. One serialized server job lost its self-hosted runner
connection; its single retry passed.
- Greptile: 5/5 on `aeda167bf4494feed6ee0de2585960511fb02918`, with no
unresolved review threads.
- Confirmed in the existing review instance that all nine Google entries
still appear after its current release was pinned. No new app release
was deployed to that instance.
- Reviewer steps: open Connections on this branch with Google catalog
entries and saved Google accounts. None should appear. Non-Google
connectors must remain. Direct Google setup routes must still load.

## Risks

- Existing Google accounts cannot be found on this page during the hold.
Their data and runtime access remain unchanged.
- This is a UI-only filter, not an authorization gate. Direct routes and
API access still work by design.
- Review instances must not receive this UI build until the hold is
removed. Their existing release pin excludes fleet app upgrades; an
explicit targeted upgrade must still be avoided.
- No migrations, backend changes, broker changes, or credential changes.

## Model Used

OpenAI Codex (GPT-5-based coding agent), with reasoning, tool use, code
execution, and browser inspection. The exact deployment model ID and
context window are not exposed in this session.

## Checklist

- [x] I have included a thinking path that traces from project context
to this change
- [x] I have specified the model used (with version and capability
details)
- [x] I have checked ROADMAP.md and confirmed this PR does not duplicate
planned core work
- [x] I have searched GitHub for duplicate or related PRs and linked
them above
- [x] I have either (a) linked existing issues with `Fixes: #` / `Closes
#` / `Refs #` OR (b) described the issue in-PR following the relevant
issue template
- [x] I have not referenced internal/instance-local Paperclip issues or
links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip`
URLs)
- [x] My branch name describes the change (e.g. `docs/...`, `fix/...`)
and contains no internal Paperclip ticket id or instance-derived details
- [x] I have run tests locally and they pass
- [x] I have added or updated tests where applicable
- [x] I have updated relevant documentation to reflect my changes
- [x] I have considered and documented any risks above
- [x] All Paperclip CI gates are green
- [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups
- [x] I will address all Greptile and reviewer comments before
requesting merge

---------

Co-authored-by: Paperclip <noreply@paperclip.ing>
canary/v2026.930.0-canary.17
2026-09-30 18:22:25 -05:00
d6fa1fd1ef feat(ui): streamline account menu profile access and add Invite shortcut (#14480)
## Thinking Path

> - Paperclip is the open source app people use to manage AI agents for
work.
> - Humans work in teams, so Paperclip has a multi-user system with
logins, profiles, and a company sidebar.
> - The account menu in the lower-left corner of the sidebar is the main
entry point for a user's own settings.
> - The account menu spent half of its rows on "View profile" and "Edit
profile". Users open these rows rarely.
> - The account menu had no fast path to invite a new member. The invite
flow is different on a self-hosted instance and on Paperclip Cloud.
> - This pull request removes the two profile rows, makes the header a
link to the profile, adds an "Edit profile" button on the profile page,
and adds an "Invite" row.
> - The benefit is a shorter account menu that keeps profile access and
gives users with the invite permission a one-click path to invite
people.

## Linked Issues or Issue Description

No public GitHub issue exists for this change. The description below
follows the enhancement template.

Refs #14060. That earlier pull request holds the first two commits and
the first Greptile review. It closed when the branch got a new name to
remove an internal ticket id. All Greptile findings from both reviews
are fixed in this branch.

**What existing behavior does this improve?**

The account menu in the sidebar (`SidebarAccountMenu` and its
`.production` variant) and the user profile page at `/u/:userSlug`.

**Subsystem affected**

ui/ — React + Vite board UI

**Current behavior**

The account menu shows the user's picture and name at the top. Below
them, the menu shows "View profile" and "Edit profile" rows, then the
other rows. The header is not a link. The menu has no row to invite
people. On a self-hosted instance, the user must open Company settings,
then Members, then the Invites tab. On Paperclip Cloud, the user must
open the Members page and use the Cloud People link there.

**Proposed behavior**

The account menu does not show "View profile" or "Edit profile". The
picture and name at the top of the menu are a link to the user's own
profile page. The profile page shows an "Edit profile" button when the
viewer looks at their own profile. The account menu shows an "Invite"
row with the same `UserPlus` icon as the company menu. On a self-hosted
instance, the row opens the Members page on the Invites tab, and shows
only to boards that hold the `users:invite` grant (company owners and
admins, instance admins, and local boards). On Paperclip Cloud, the row
opens the People settings for the current stack, and shows only to the
owner or admin of the stack, the same rule the Members page uses.

**Reason and benefit**

Users open their profile rarely, but the two rows took half of the menu.
Inviting people is a common task, but it needed three clicks and a
different path on Cloud. The new menu is shorter, keeps profile access
in one tap on the header, and gives one "Invite" entry point on both
hosting modes to the users who can invite.

**Breaking changes**

None. Routes, API responses, and settings keys do not change. The
profile page and the invite pages keep their current URLs.

## What Changed

- `SidebarAccountMenu.tsx` and `SidebarAccountMenu.production.tsx`:
remove the "View profile" and "Edit profile" rows. Make the picture and
name header a link to the user's profile. Add the "Invite" row after
"Settings" in the streamlined menu and first in the production menu.
- Header structure: `master` added a staging commit SHA link under the
email in the same header. The profile link is now a stretched overlay
behind the header content, so the SHA anchor sits beside the email and
the header has no nested anchors.
- `ui/src/lib/userProfileLinks.ts` (new): build the profile path from
the user id first. The profile endpoint treats the id as the one unique
slug, so two members with the same display name get different links.
Name and email are a fallback only when the session has no id.
- `ui/src/hooks/useCloudInviteUrl.ts` (new): read the Cloud stack
portfolio and return the People settings URL only when the current stack
role is owner or admin. This is the same rule as the Members page.
- `ui/src/hooks/useCompanyInviteAccess.ts` (new): read the current board
access snapshot and report whether the board may invite people to the
selected company on a self-hosted instance. Local boards and instance
admins pass. Other boards need an active owner or admin membership, the
roles that carry `users:invite`. This follows the same client-side gate
pattern as `ToolsAdminGate` and the run ledger. The server stays
authoritative.
- Invite row visibility: the row is hidden when the operator hides
`company.members` or `company.invites`, and until the health check
resolves. On self-hosted instances, the row is hidden until the board
access snapshot loads and when the board cannot invite. On Cloud, the
row is hidden when no People URL can be built. The in-app Invites tab is
never a fallback on Cloud, because it drives a different flow.
- `ui/src/pages/UserProfile.tsx`: add an "Edit profile" button that
links to `/company/settings/instance/profile`. The button shows only on
the viewer's own profile and follows the `instance.profile`
hidden-settings gate.
- Tests: extend `SidebarAccountMenu.test.tsx`; add
`userProfileLinks.test.ts`, `UserProfile.test.tsx`, and
`useCompanyInviteAccess.test.ts`.
- No documentation references the removed menu rows, so no docs change
is needed.

## Verification

Run the focused tests from the `ui/` directory:

```bash
pnpm vitest run src/components/SidebarAccountMenu.test.tsx src/hooks/useCompanyInviteAccess.test.ts src/lib/userProfileLinks.test.ts src/pages/UserProfile.test.tsx
```

- 52 tests pass in these four files. They cover the header link by user
id, the removed rows, the header overlay with no nested anchors, the
self-hosted invite target, the self-hosted permission gate (owner,
admin, instance admin, and local board see the row; an operator does
not, on both menu variants), the Cloud invite target with no
`target="_blank"`, the menu order, the hidden-settings gate on both
variants, the Cloud role gate (a plain member sees no row), the
no-fallback rule when Cloud stack metadata is missing, the staging
commit SHA link from `master`, and the own-profile-only "Edit profile"
button.
- `tsc -b` in `ui/` reports no errors in the changed files. The only
errors are pre-existing `@paperclipai/plugin-sdk/ui` resolution errors
in `PluginOrganizationSwitcher.tsx` from an unbuilt workspace package.

Manual steps:

1. Sign in and open the account menu in the lower-left corner. Confirm
the menu has no "View profile" or "Edit profile" rows.
2. Click your picture or name at the top of the menu. Confirm your
profile page opens and shows an "Edit profile" button.
3. Open another user's profile. Confirm the page shows no "Edit profile"
button.
4. On a self-hosted instance, as a company owner or admin, click
"Invite". Confirm the Members page opens on the Invites tab. As an
operator or viewer, confirm the menu shows no "Invite" row.
5. On Paperclip Cloud, as a stack owner or admin, click "Invite".
Confirm the Cloud People settings page opens in the same tab. As a plain
member, confirm the menu shows no "Invite" row.

## Risks

- Low risk. The change is limited to the UI and touches ten files.
- Users who know the "View profile" and "Edit profile" rows must learn
the new header link. The header has hover and focus styles to show that
it is a link.
- On self-hosted instances, the "Invite" row depends on the board access
snapshot from `/cli-auth/me`, which other gates in the UI already use. A
member with a custom `users:invite` grant but an operator or viewer role
does not see the row. That member can still use the Members page. The
row is a shortcut, not the only path.
- On Paperclip Cloud, the "Invite" row depends on the stack portfolio
query. When that query fails or the role is unknown, the menu hides the
row instead of sending the user to the wrong flow.
- Both menu variants change together, so a behavior difference between
them is not expected.

## Model Used

- Provider: Anthropic. Model: Claude Fable 5.1 (`claude-fable-5-1`).
- Run through Claude Code on the Claude Agent SDK inside a Paperclip
`claude_local` agent, with extended thinking and tool use (file edits,
shell, tests, GitHub API).
- The model wrote the code, the tests, and this description. A human
reviewed the pull request and requested the review fixes.

## Checklist

- [x] I have included a thinking path that traces from project context
to this change
- [x] I have specified the model used (with version and capability
details)
- [x] I have checked ROADMAP.md and confirmed this PR does not duplicate
planned core work
- [x] I have searched GitHub for duplicate or related PRs and linked
them above
- [x] I have either (a) linked existing issues with `Fixes: #` / `Closes
#` / `Refs #` OR (b) described the issue in-PR following the relevant
issue template
- [x] I have not referenced internal/instance-local Paperclip issues or
links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip`
URLs)
- [x] My branch name describes the change (e.g. `docs/...`, `fix/...`)
and contains no internal Paperclip ticket id or instance-derived details
- [x] I have run tests locally and they pass
- [x] I have added or updated tests where applicable
- [x] I have updated relevant documentation to reflect my changes
- [x] I have considered and documented any risks above
- [x] All Paperclip CI gates are green
- [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups
- [x] I will address all Greptile and reviewer comments before
requesting merge

🤖 Generated with [Claude Code](https://claude.com/claude-code)

---------

Co-authored-by: Bender (Fable) <bender@paperclip.local>
Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com>
Co-authored-by: devinfoley <139239+devinfoley@users.noreply.github.com>
2026-09-30 16:18:59 -07:00