mirror of
https://github.com/paperclipai/paperclip.git
synced 2026-10-06 10:48:12 +02:00
5458940a6e489099a03c37fbcb758ac0b8f45361
4069
Commits
| Author | SHA1 | Message | Date | |
|---|---|---|---|---|
|
|
79b464bf9d |
fix(server): surface skill materialization failures instead of dropping the skill (#12146)
## Thinking Path
> - Paperclip is the open source app people use to manage AI agents for
work
> - Runtime skill listing materializes each company skill's files before
handing them to the agent's adapter
> - A materialization failure was swallowed with catch-to-null, and the
skill silently vanished from the runtime while the library still showed
it installed
> - Operators saw "installed", agents saw nothing, and nobody saw the
cause; on claude-local a missing desired skill could even crash the
prompt-bundle hasher
> - This pull request turns both failure paths into structured "missing"
entries with the real error and makes every adapter skip unmountable
entries explicitly
> - The benefit is that a broken skill shows up as broken, with its
cause, instead of not existing
## Linked Issues or Issue Description
**What happened?**
A company skill whose runtime files fail to materialize (deleted source,
missing stored SKILL.md copy, failed version snapshot) disappears from
`listRuntimeSkillEntries` with no trace. Agent skill snapshots report a
generic "not available" with no cause. On claude-local, a desired skill
whose source path does not exist reaches the prompt-bundle hasher, whose
`fs.lstat` throws and can fail the whole run.
**Expected behavior**
The skill appears with `sourceStatus: "missing"` and a `missingDetail`
carrying the underlying error, snapshots and the UI show it as broken,
and adapters skip it at mount time with a logged warning instead of
crashing or dangling-symlinking.
**Steps to reproduce**
Install a local-path skill referenced by an agent, delete its source
directory contents so the stored SKILL.md copy cannot be recovered, and
start a run: before this change the skill vanishes from the runtime set
silently; on claude-local a pinned-but-unmaterializable version can fail
bundle preparation.
## What Changed
- `server/src/services/company-skills.ts` `resolveRuntimeSkillSource`:
both `.catch(() => null)` sites (version snapshot, runtime
materialization) now return the structured `{status: "missing", source,
detail}` shape the deliberate missing branch already used, with the
underlying error message in `detail`.
- `packages/adapter-utils/src/server-utils.ts`:
`isPaperclipSkillSourceMissing` is exported with a doc comment.
- `packages/adapters/claude-local/src/server/execute.ts`: missing
desired skills are filtered out of the prompt bundle and each one logs a
`[paperclip] Warning` with its detail to the run output.
- `cursor-local`, `gemini-local`, `kimi-local`, `opencode-local`,
`pi-local` `execute.ts`: mount loops (and the cursor/gemini injection
calls) skip missing entries instead of symlinking a nonexistent path.
## Verification
- `cd server && npx vitest run
src/__tests__/company-skills-service.test.ts` — new test pins the
missing-with-cause entry for a failed materialization. Nine pre-existing
project-workspace tests in this file fail on my machine at clean
`master` too (environment-specific); their count is unchanged by this
PR.
- `cd server && npx vitest run
src/__tests__/heartbeat-runtime-skills.test.ts
src/__tests__/claude-local-skill-sync.test.ts
src/__tests__/cursor-local-skill-sync.test.ts
src/__tests__/cursor-local-skill-injection.test.ts
src/__tests__/gemini-local-skill-sync.test.ts` — 12 tests pass.
- `cd packages/adapters/claude-local && npx vitest run` — 244 passed, 1
skipped.
- `pnpm run typecheck` clean in server, adapter-utils, and all six
touched adapters.
## Risks
- Runtime skill entry lists grow by the previously dropped entries (now
flagged missing). All shipped consumers either intersect with desired
sets, already handle `sourceStatus: "missing"`, or now skip missing
entries at mount time. The snapshot layer already understood the missing
shape via the `materializeMissing: false` path, so downstream contracts
are unchanged.
## Model Used
- Claude Fable 5 (`claude-fable-5`, Anthropic) with extended thinking
and tool use, via Claude Code.
## Checklist
- [x] I have included a thinking path that traces from project context
to this change
- [x] I have specified the model used (with version and capability
details)
- [x] I have checked ROADMAP.md and confirmed this PR does not duplicate
planned core work
- [x] I have searched GitHub for duplicate or related PRs and linked
them above
- [x] I have either (a) linked existing issues with `Fixes: #` / `Closes
#` / `Refs #` OR (b) described the issue in-PR following the relevant
issue template
- [x] I have not referenced internal/instance-local Paperclip issues or
links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip`
URLs)
- [x] My branch name describes the change (e.g. `docs/...`, `fix/...`)
and contains no internal Paperclip ticket id or instance-derived details
- [x] I have run tests locally and they pass
- [x] I have added or updated tests where applicable
- [x] I have updated relevant documentation to reflect my changes
- [x] I have considered and documented any risks above
- [ ] All Paperclip CI gates are green
- [ ] Greptile is 5/5 with no open P2s, recommendations, or follow-ups
- [x] I will address all Greptile and reviewer comments before
requesting merge
canary/v2026.825.0-canary.14
|
||
|
|
18b6c788d5 |
feat(server): de-duplicate imported company names (#12145)
## Thinking Path > - Paperclip is the open source app people use to manage AI agents for work > - Importing a company package as a new company takes the company name from the package manifest > - Repeat imports of the same package therefore create several identically named companies, distinguishable only by issue prefix > - Users cannot tell which import they are looking at, which feeds the "my import disappeared" loop of importing again > - This pull request suffixes manifest-derived names with " (2)", " (3)", … on collision, while honoring explicitly typed names verbatim > - The benefit is that every imported company has a recognizable name ## Linked Issues or Issue Description **What existing behavior does this improve?** Naming of companies created by the company package import. **Subsystem affected** Server — company import (`server/src/services/company-portability.ts`). **Current behavior** The new-company branch uses `newCompanyName ?? manifest name ?? "Imported Company"` with no de-duplication. Only the issue prefix is unique. Three imports of the same package yield three companies with the same name. **Proposed behavior** When the name comes from the manifest (no explicit `newCompanyName`), the import checks existing company names case-insensitively and appends the first free " (N)" suffix. Explicit names remain honored verbatim. Name exhaustion (thousands of collisions) falls back to the base name rather than failing the import, since names carry no uniqueness invariant. **Breaking changes** None. Only the default name of newly imported companies changes, and only on collision. ## What Changed - New exported pure helper `dedupeImportedCompanyName(baseName, existingNames)`. - The new-company branch resolves the name through it when no explicit name was provided, reading existing names via `companyService.list()`. ## Verification - `cd server && npx vitest run src/__tests__/company-portability.test.ts` — 87 tests pass (new: pure helper cases and two `importBundle` tests for the suffixed manifest name and the honored explicit name). - `cd server && npx vitest run src/__tests__/company-portability-routes.test.ts src/__tests__/company-portability-import-batching.test.ts` — 44 passed, 1 skipped (pre-existing skip). - `cd server && pnpm run typecheck` — clean. ## Risks - Low risk. The check-then-create has a theoretical race with a concurrent import, but names have no unique constraint — the worst case is today's behavior (a duplicate name). Issue-prefix uniqueness is untouched. ## Model Used - Claude Fable 5 (`claude-fable-5`, Anthropic) with extended thinking and tool use, via Claude Code. ## Checklist - [x] I have included a thinking path that traces from project context to this change - [x] I have specified the model used (with version and capability details) - [x] I have checked ROADMAP.md and confirmed this PR does not duplicate planned core work - [x] I have searched GitHub for duplicate or related PRs and linked them above - [x] I have either (a) linked existing issues with `Fixes: #` / `Closes #` / `Refs #` OR (b) described the issue in-PR following the relevant issue template - [x] I have not referenced internal/instance-local Paperclip issues or links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip` URLs) - [x] My branch name describes the change (e.g. `docs/...`, `fix/...`) and contains no internal Paperclip ticket id or instance-derived details - [x] I have run tests locally and they pass - [x] I have added or updated tests where applicable - [x] I have updated relevant documentation to reflect my changes - [x] I have considered and documented any risks above - [ ] All Paperclip CI gates are green - [ ] Greptile is 5/5 with no open P2s, recommendations, or follow-ups - [x] I will address all Greptile and reviewer comments before requesting merge |
||
|
|
fcb84d472d |
feat: already-imported transfer error names the landed company (#12144)
## Thinking Path
> - Paperclip is the open source app people use to manage AI agents for
work
> - Chunked company-import transfers are deduplicated by content: a
byte-identical zip that already finished an apply is rejected
> - The rejection said only "this exact package was already imported by
a completed transfer" without saying where that import went
> - Users who could not find the earlier import read the rejection as
data loss and kept retrying, or exported again and created duplicate
companies
> - This pull request makes the declaration response carry the company
the completed apply created, and both clients name it in the error
> - The benefit is that the dedupe rejection now points at the existing
import instead of implying it vanished
## Linked Issues or Issue Description
**What existing behavior does this improve?**
The `alreadyCompleted` rejection when re-declaring a chunked
company-import transfer.
**Subsystem affected**
Shared transfer contract
(`packages/shared/src/company-import-transfer.ts`), transfer declaration
route (`server/src/routes/companies.ts`), web import page, CLI import
command.
**Current behavior**
`POST /api/companies/import/transfers` returns `alreadyCompleted: true`
with no pointer to the earlier import. Web and CLI raise "This exact
package was already imported by a completed transfer. Re-export the
package to import it again."
**Proposed behavior**
The response includes an optional `company` field (`{id, name,
issuePrefix} | null`) resolved from the completed run's company link.
Web and CLI raise a shared message: `… It created the company
"Paperclip" (PAPA) — open it from the company switcher. Re-export the
package to import it again.` A company that was deleted since (or a link
that was never written) degrades to `null` and the original message.
**Breaking changes**
None. The new response field is optional; old clients ignore it.
## What Changed
- `CompanyImportTransferCreated` gains optional `company`, plus a shared
`buildAlreadyImportedMessage` used by both clients.
- The declaration route's `alreadyCompleted` branch resolves the landed
company null-safely via `companyService.getById`.
- Web (`ui/src/pages/CompanyImport.tsx`) and CLI
(`cli/src/commands/client/company.ts`) raise the shared message.
## Verification
- `cd packages/shared && npx vitest run
src/company-import-transfer.test.ts` — 3 tests (named company, id
fallback, no-company original message).
- `cd server && npx vitest run
src/__tests__/company-import-transfer-routes.test.ts` — 24 tests; the
re-declaration test now asserts the company payload and the
deleted-company null path.
- `cd cli && npx vitest run
src/__tests__/company-import-transfer.test.ts` — 17 tests; new test pins
the named-company message.
- `cd ui && npx vitest run src/pages/CompanyImport.test.tsx` — 23 tests.
- `pnpm run typecheck` clean in shared, server, ui, cli.
## Risks
- Low risk. The lookup runs only on the `alreadyCompleted` branch and is
null-safe; the transfer run is already scoped to the requesting actor
(user + instance context in the actor key), so the response never names
a company the caller did not import.
## Model Used
- Claude Fable 5 (`claude-fable-5`, Anthropic) with extended thinking
and tool use, via Claude Code.
## Checklist
- [x] I have included a thinking path that traces from project context
to this change
- [x] I have specified the model used (with version and capability
details)
- [x] I have checked ROADMAP.md and confirmed this PR does not duplicate
planned core work
- [x] I have searched GitHub for duplicate or related PRs and linked
them above
- [x] I have either (a) linked existing issues with `Fixes: #` / `Closes
#` / `Refs #` OR (b) described the issue in-PR following the relevant
issue template
- [x] I have not referenced internal/instance-local Paperclip issues or
links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip`
URLs)
- [x] My branch name describes the change (e.g. `docs/...`, `fix/...`)
and contains no internal Paperclip ticket id or instance-derived details
- [x] I have run tests locally and they pass
- [x] I have added or updated tests where applicable
- [x] I have updated relevant documentation to reflect my changes
- [x] I have considered and documented any risks above
- [ ] All Paperclip CI gates are green
- [ ] Greptile is 5/5 with no open P2s, recommendations, or follow-ups
- [x] I will address all Greptile and reviewer comments before
requesting merge
|
||
|
|
868e210a95 |
feat(ui): post-import landing CTAs on every outcome branch (#12143)
## Thinking Path
> - Paperclip is the open source app people use to manage AI agents for
work
> - Company import ends on one of two success screens: the full outcome,
or a soft-success panel when the job's in-memory result expired before
it could be read
> - The soft-success panel named no company and offered no way in, and
the full outcome never said that paused agents stay resumable after
leaving the page
> - Users on the soft-success path concluded the import vanished and ran
it again, producing duplicate companies
> - This pull request gives every success branch a named landing with a
direct CTA into the new company and a pointer to the paused-agents
banner
> - The benefit is that a finished import always lands the user
somewhere actionable
## Linked Issues or Issue Description
**What existing behavior does this improve?**
The outcome screens of the company import page.
**Subsystem affected**
Web UI — company import (`ui/src/pages/CompanyImport.tsx`).
**Current behavior**
The expired-job branch renders two sentences ("the company has been
added — open it to view it") with no company name and no link. The
full-outcome screen shows the activation checklist but does not say the
checklist's resume actions remain available on the dashboard, so users
treat the page as their only chance.
**Proposed behavior**
The expired branch keeps the landed company's name and dashboard path
when readable, renders an "Open company dashboard" button, and notes
that imported agents arrive paused and can be resumed from the dashboard
banner. When the company is unreadable it gives explicit switcher
guidance instead. The full-outcome screen states that paused items stay
resumable from the dashboard.
**Breaking changes**
None. Pure UI copy/state additions to an existing page.
## What Changed
- The `expired` import outcome now carries `companyName` and
`dashboardPath`, captured from the already-fetched company in
`onSuccess`.
- The expired panel renders the company name, a dashboard CTA
(`data-testid="import-expired-open-company"`), the paused-agents
pointer, and a switcher fallback.
- The full-outcome screen adds a line noting the dashboard offers the
same resume actions as the activation checklist.
## Verification
- `cd ui && npx vitest run src/pages/CompanyImport.test.tsx` — 24 tests
pass; the soft-success test now asserts the name, pointer, and CTA, and
a new test covers the unreadable-company fallback.
- `cd ui && pnpm run typecheck` — clean.
## Risks
- Low risk. The dashboard pointer references the paused-agents banner
shipping in #12142; until that merges the sentence still points at the
dashboard, where paused agents are already visible in the metric card.
## Model Used
- Claude Fable 5 (`claude-fable-5`, Anthropic) with extended thinking
and tool use, via Claude Code.
## Checklist
- [x] I have included a thinking path that traces from project context
to this change
- [x] I have specified the model used (with version and capability
details)
- [x] I have checked ROADMAP.md and confirmed this PR does not duplicate
planned core work
- [x] I have searched GitHub for duplicate or related PRs and linked
them above
- [x] I have either (a) linked existing issues with `Fixes: #` / `Closes
#` / `Refs #` OR (b) described the issue in-PR following the relevant
issue template
- [x] I have not referenced internal/instance-local Paperclip issues or
links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip`
URLs)
- [x] My branch name describes the change (e.g. `docs/...`, `fix/...`)
and contains no internal Paperclip ticket id or instance-derived details
- [x] I have run tests locally and they pass
- [x] I have added or updated tests where applicable
- [x] I have updated relevant documentation to reflect my changes
- [x] I have considered and documented any risks above
- [ ] All Paperclip CI gates are green
- [ ] Greptile is 5/5 with no open P2s, recommendations, or follow-ups
- [x] I will address all Greptile and reviewer comments before
requesting merge
|
||
|
|
11f6c754c9 |
feat: dedicated import pause reason with visible paused-assignee notices (#12140)
## Thinking Path > - Paperclip is the open source app people use to manage AI agents for work > - Company import parks every imported agent as a safety default, and issue assignment wakes are dropped for paused agents > - The pause was recorded as the generic reason "system" and was almost invisible: the chat-style task thread showed nothing, the legacy notice had no action, and the new-task dialog gave no hint > - Users assigned tasks in an imported company, nothing ran, and there was no explanation — the imported company looked broken > - This pull request records a dedicated "import" pause reason and makes the paused state visible and fixable where the user is looking > - The benefit is that a silent no-op becomes an explained state with a one-click resume ## Linked Issues or Issue Description **What existing behavior does this improve?** Working with a company whose agents arrived paused from a company import. **Subsystem affected** Shared constants (`PAUSE_REASONS`), company import service (`server/src/services/company-portability.ts`), task thread and new-task dialog UI. **Current behavior** Imported agents get `pauseReason: "system"`, the same value plugin-managed and built-in agent pauses use. Assigning an issue to a paused agent silently drops the wake. The chat-style task thread renders no paused notice; the legacy thread's notice says "It was paused by the system." with no action and only renders when the composer is shown. **Proposed behavior** Import writes `pauseReason: "import"`. The paused-assignee notice explains the import pause, offers an inline "Resume agent" button (suppressed for budget pauses, which clear on their own), and renders for read-only viewers. The chat-style task thread shows the same notice above the composer. The new-task dialog warns when the selected assignee is paused. **Breaking changes** None. `PAUSE_REASONS` is widened, not changed; the column already stores free-text values in other paths, and every consumer is an equality check with a manual fallback, so an older client shows the generic fallback copy for the new value. ## What Changed - `packages/shared/src/constants.ts`: `"import"` added to `PAUSE_REASONS`. - `server/src/services/company-portability.ts`: the import pause patch writes `pauseReason: "import"`. - `ui/src/components/IssueChatThread.tsx`: `IssueAssigneePausedNotice` gains import copy, a Resume button, test ids, and is exported; it now renders even when the composer is hidden. New `onResumeAssignee` / `resumeAssigneePending` props. - `ui/src/components/TaskChatThread.tsx`: renders the paused-assignee notice above the composer dock (the chat-style thread previously had no paused surface at all). - `ui/src/pages/IssueDetail.tsx`: wires a resume mutation (`agentsApi.resume`) through both thread variants and invalidates the company agent list. - `ui/src/components/NewIssueDialog.tsx`: inline note when the chosen assignee is paused, with import-specific copy. ## Verification - `cd server && npx vitest run src/__tests__/company-portability.test.ts` — 82 tests pass (pause pin updated to `"import"`). - `cd ui && npx vitest run src/components/IssueChatThread.test.tsx src/components/NewIssueDialog.test.tsx src/components/TaskChatThread.test.tsx` — 120 tests pass (new: notice copy per reason, resume click, budget suppression, active-agent null render, dialog note). - `pnpm run typecheck` in `packages/shared`, `server`, and `ui` — clean. ## Risks - Low risk. The resume action calls the existing `POST /agents/:id/resume` route with its existing guards. Existing rows keep `"system"` and fall back to the current generic copy; only new imports write `"import"`. ## Model Used - Claude Fable 5 (`claude-fable-5`, Anthropic) with extended thinking and tool use, via Claude Code. ## Checklist - [x] I have included a thinking path that traces from project context to this change - [x] I have specified the model used (with version and capability details) - [x] I have checked ROADMAP.md and confirmed this PR does not duplicate planned core work - [x] I have searched GitHub for duplicate or related PRs and linked them above - [x] I have either (a) linked existing issues with `Fixes: #` / `Closes #` / `Refs #` OR (b) described the issue in-PR following the relevant issue template - [x] I have not referenced internal/instance-local Paperclip issues or links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip` URLs) - [x] My branch name describes the change (e.g. `docs/...`, `fix/...`) and contains no internal Paperclip ticket id or instance-derived details - [x] I have run tests locally and they pass - [x] I have added or updated tests where applicable - [x] I have updated relevant documentation to reflect my changes - [x] I have considered and documented any risks above - [ ] All Paperclip CI gates are green - [ ] Greptile is 5/5 with no open P2s, recommendations, or follow-ups - [x] I will address all Greptile and reviewer comments before requesting merge |
||
|
|
5af49cb477 |
feat(server): CEO agents get the core paperclip skills by default (#12138)
## Thinking Path
> - Paperclip is the open source app people use to manage AI agents for
work
> - Each agent's runtime only receives skills listed in its own
desired-skill set; the company library alone does nothing for an agent
> - Every CEO creation path (first-run wizard hire, New Agent
first-agent flow, cloud onboarding seed) creates the CEO with an empty
desired-skill set
> - The default CEO instructions tell the agent to use the core
paperclip skills, so a fresh CEO contradicts its own instructions and
reports its toolkit as "not installed"
> - This pull request unions the core skill keys into every
skills-capable CEO hire/create and into the onboarding-seeded CEO's
adapter config
> - The benefit is that a new CEO can actually do what its instructions
describe, and stops telling users that installed skills do not exist
## Linked Issues or Issue Description
**What existing behavior does this improve?**
Creating the first lead agent (role `ceo`) via hire, create, or the
cloud onboarding seed.
**Subsystem affected**
Server — agent hire/create routes (`server/src/routes/agents.ts`),
onboarding seed (`server/src/services/onboarding-seed.ts`), company
skills service constant (`server/src/services/company-skills.ts`).
**Current behavior**
A CEO created by the wizard, the New Agent page, or the onboarding seed
has no `paperclipSkillSync` block. Its runtime mounts zero skills. Its
default instructions (`server/src/onboarding-assets/ceo/AGENTS.md`,
`HEARTBEAT.md`) tell it to use `paperclip-create-agent`,
`para-memory-files`, and the paperclip coordination skill. The agent
then reports these skills as not installed.
**Proposed behavior**
When the new agent's role is `ceo` and its adapter supports skill sync,
the hire and create routes union the five bundled
`paperclipai/paperclip/*` skill keys into the requested desired-skill
set. The onboarding seed writes the same preference into the seeded
CEO's adapter config. Explicit requests win over defaults for the same
key. Non-CEO agents are unchanged. Any default stays removable through
`POST /agents/:id/skills/sync`.
**Breaking changes**
None. The default is additive, applies only to role `ceo` on
skills-capable adapters, and the bundled skills are guaranteed present
in every company library by `ensureSkillInventoryCurrent`.
## What Changed
- New exported constant `PAPERCLIP_CORE_SKILL_KEYS` in
`server/src/services/company-skills.ts` (the five bundled
`paperclipai/paperclip/*` keys).
- `defaultRoleSkillSelections` + `withDefaultRoleSkillSelections`
helpers in `server/src/routes/agents.ts`, applied in both the hire and
create routes before `resolveDesiredSkillAssignment(..., "add")`.
- `server/src/services/onboarding-seed.ts` builds the seeded CEO's
adapter config with `writePaperclipSkillSyncPreference` instead of `{}`
when the seeded adapter supports skills.
## Verification
- `cd server && npx vitest run
src/__tests__/agent-skills-routes.test.ts` — 32 tests pass (three new:
CEO default set, union with a requested skill, non-CEO untouched).
- `cd server && npx vitest run
src/__tests__/onboarding-seed-route.test.ts` — 14 tests pass (seeded CEO
adapter config assertion added).
- `cd server && npx vitest run
src/__tests__/agent-permissions-routes.test.ts` — 54 tests pass.
- `cd server && pnpm run typecheck` — clean.
## Risks
- Existing CEOs are not modified; only newly created ones get the
defaults. An operator who wants a minimal CEO can remove the skills
after creation with the skills sync (mode `remove`), and that removal
sticks. Adapters without skill support are skipped, so the change is
inert there.
## Model Used
- Claude Fable 5 (`claude-fable-5`, Anthropic) with extended thinking
and tool use, via Claude Code.
## Checklist
- [x] I have included a thinking path that traces from project context
to this change
- [x] I have specified the model used (with version and capability
details)
- [x] I have checked ROADMAP.md and confirmed this PR does not duplicate
planned core work
- [x] I have searched GitHub for duplicate or related PRs and linked
them above
- [x] I have either (a) linked existing issues with `Fixes: #` / `Closes
#` / `Refs #` OR (b) described the issue in-PR following the relevant
issue template
- [x] I have not referenced internal/instance-local Paperclip issues or
links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip`
URLs)
- [x] My branch name describes the change (e.g. `docs/...`, `fix/...`)
and contains no internal Paperclip ticket id or instance-derived details
- [x] I have run tests locally and they pass
- [x] I have added or updated tests where applicable
- [x] I have updated relevant documentation to reflect my changes
- [x] I have considered and documented any risks above
- [ ] All Paperclip CI gates are green
- [ ] Greptile is 5/5 with no open P2s, recommendations, or follow-ups
- [x] I will address all Greptile and reviewer comments before
requesting merge
|
||
|
|
d2b9765cc8 |
feat(ui): offer enabling a skill for agents at install time (#12136)
## Thinking Path > - Paperclip is the open source app people use to manage AI agents for work > - The company skill library lets operators install skills, and each agent has its own enabled-skill set > - Installing a skill only writes the library row; no agent receives the skill, and the UI says "Skill installed" with no attach step > - Operators install a skill, ask an agent to use it, and the agent truthfully reports the skill as not available — the install felt broken > - This pull request adds an "Enable for agents" step to the install dialog and enables the skill for the selected agents right after install > - The benefit is that "install" defaults to a state where agents can actually use the skill, and the toast is honest when they cannot ## Linked Issues or Issue Description **What existing behavior does this improve?** Installing a skill from the catalog in the company Skills page. **Subsystem affected** Web UI — company skills catalog install flow (`ui/src/pages/CompanySkills.tsx`). **Current behavior** Install writes a `company_skills` row and shows a "Skill installed" toast. No agent is enabled for the skill. Agents resolve their skills from their own desired-skill set, so they report the skill as not installed. The operator has to find the separate "Add to agent" control to make the install effective. **Proposed behavior** The install dialog shows an "Enable for agents" section for fresh installs. It pre-selects every agent whose adapter supports skills. After install, the page enables the skill for each selected agent (skills sync with mode `add`). The success toast reports how many agents received the skill, and warns when the skill is in the library with no agents enabled. **Breaking changes** None. Updates and replacements of an existing skill do not show the new section and behave as before. ## What Changed - `InstallPreviewDialog` gains an "Enable for agents" section (fresh installs only) built on the existing `AgentMultiSelect`, with agents whose adapter lacks skills support disabled. - New exported helper `defaultInstallAgentSelection` pre-selects every skills-capable, non-required agent. - The install mutation enables the skill for each selected agent via `agentsApi.syncSkills(..., "add")` before invalidating queries, and reports per-agent failures in a warning toast without failing the install. - Toast copy now distinguishes "enabled for N agents" from "in the library but not enabled for any agent yet". ## Verification - `cd ui && npx vitest run src/pages/CompanySkills.test.tsx` — 23 tests pass, including three new ones: default-selection helper, confirm payload carries the pre-selected agents, update/replace path skips the section. - `cd ui && pnpm run typecheck` — clean. - Manual: install a catalog skill with two agents in the company; both are pre-selected; after install the skill page lists both under "Used by agents". ## Risks - Low risk. Enablement uses the existing per-agent skills sync route with mode `add`, so concurrent edits to an agent's desired set are not overwritten. A per-agent sync failure surfaces as a warning toast and never fails the install itself. ## Model Used - Claude Fable 5 (`claude-fable-5`, Anthropic) with extended thinking and tool use, via Claude Code. ## Checklist - [x] I have included a thinking path that traces from project context to this change - [x] I have specified the model used (with version and capability details) - [x] I have checked ROADMAP.md and confirmed this PR does not duplicate planned core work - [x] I have searched GitHub for duplicate or related PRs and linked them above - [x] I have either (a) linked existing issues with `Fixes: #` / `Closes #` / `Refs #` OR (b) described the issue in-PR following the relevant issue template - [x] I have not referenced internal/instance-local Paperclip issues or links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip` URLs) - [x] My branch name describes the change (e.g. `docs/...`, `fix/...`) and contains no internal Paperclip ticket id or instance-derived details - [x] I have run tests locally and they pass - [x] I have added or updated tests where applicable - [x] I have updated relevant documentation to reflect my changes - [x] I have considered and documented any risks above - [ ] All Paperclip CI gates are green - [ ] Greptile is 5/5 with no open P2s, recommendations, or follow-ups - [x] I will address all Greptile and reviewer comments before requesting merge |
||
|
|
3e28d64a72 |
fix(plugin-worker-manager): queue and replay pre-bind login pseudo-terminal frames (#12173)
## Thinking Path > - Paperclip routes plugin worker messages to agent sessions. > - The login pseudo-terminal route opens after the host receives the open reply. > - `readline` can deliver later frames from the same pipe read before that reply continuation runs. > - The host dropped early output and exit frames. > - The fix queues valid early frames, preserves arrival order, and replays them after the route opens. > - The route uses bounded memory and closes fail-closed when a bound breaks. > - The final tests also pin child issue ordering so the serialized suite remains deterministic. ## Linked Issues or Issue Description Fixes #12122 ## What Changed - Add a bounded queue for login pseudo-terminal output and exit frames during route opening. - Validate session ids, chunk types, and per-chunk limits before queue insertion. - Bound the queue by 10,000 frames and 8 MiB of characters. - Charge retained worker session identifiers against the character bound. - Preserve arrival order and stop replay after the first valid exit. - Drop repeated exits without changing the first exit position or code. - Bound the repeat-exit lookup and clear queued state on all terminal paths. - Add regression tests and fixture support for coalesced frames, ordering, limits, cleanup, and log safety. - Pin issue numbers in the child-wake test so its expected child order remains deterministic. ## Verification - Build the plugin SDK with `pnpm --filter @paperclipai/plugin-sdk build`. - Run `npx vitest run server/src/__tests__/plugin-worker-manager.test.ts` from the repository root. - Run `npx vitest run server/src/__tests__/issues-service.test.ts` from the repository root. - The focused plugin worker suite passes 66 of 66 tests at the prior reviewed head. - The issue service file passes 120 of 120 tests in two isolated runs at the current head. - Confirm that GitHub Actions passes all required checks. - Confirm that Greptile reports 5/5 with no unresolved review threads. - Storybook visual regression remains skipped because the PR has no `storybook-visual` label. ## Risks - The queue adds bounded memory use while the login pseudo-terminal route opens. - A queue limit breach closes the route and prevents unbounded buffering. - A hostile worker can fail only its own login route when it breaches a bound. - The first valid exit closes the route, so later records do not reach the session. - The child-wake test now uses distinct issue numbers to match the service sort contract. ## Model Used OpenAI Codex, GPT-5, extended reasoning, tool use, and code review support. The runtime does not expose a separate context-window value. ## Checklist - [x] I have included a thinking path that traces from project context to this change - [x] I have specified the model used with version and capability details - [x] I have checked ROADMAP.md and confirmed that this PR does not duplicate planned core work - [x] I have searched GitHub for duplicate or related PRs and linked them above - [x] I have linked the existing public issue with `Fixes: #12122` - [x] I have not referenced internal Paperclip issues or links - [x] My branch name describes the change and contains no internal ticket id - [x] I have run tests locally and they pass - [x] I have added or updated tests where applicable - [x] I have updated relevant documentation where needed - [x] I have considered and documented risks above - [x] All required Paperclip CI gates are green - [x] Greptile is 5/5 with no unresolved review threads - [x] I will address all Greptile and reviewer comments before requesting merge --------- Co-authored-by: Paperclip <noreply@paperclip.ing> |
||
|
|
1fc4591327 |
build(deps): bump commander from 13.1.0 to 15.0.0 (#11877)
Bumps [commander](https://github.com/tj/commander.js) from 13.1.0 to 15.0.0. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/tj/commander.js/releases">commander's releases</a>.</em></p> <blockquote> <h2>v15.0.0</h2> <p>Commander 15 is ESM only. This is expected to be seamless for ESM consumers, but some CommonJS consumers may hit issues with tooling requiring configuration for ESM-only dependencies. See Migration Tips below.</p> <p>The release of Commander 15 moves Commander 14 into maintenance. Commander 14 will get security updates for 12 months (to May 2027). For more info see <a href="https://github.com/tj/commander.js/blob/v15.0.0/docs/release-policy.md">Release Policy</a>.</p> <h3>Added</h3> <ul> <li>show excess command-arguments in error message (<a href="https://redirect.github.com/tj/commander.js/issues/2384">#2384</a>)</li> </ul> <h3>Fixed</h3> <ul> <li><em>Breaking:</em> only lone <code>--no-*</code> option sets default option value to <code>true</code>, default not implicitly set when define both positive and negative option in either order (<a href="https://redirect.github.com/tj/commander.js/issues/2405">#2405</a>)</li> <li>update example to use compatible character for MINGW64 (<a href="https://redirect.github.com/tj/commander.js/issues/2475">#2475</a>)</li> </ul> <h3>Changed</h3> <ul> <li><em>Breaking:</em> migrated Commander implementation from CommonJS to ESM (<a href="https://redirect.github.com/tj/commander.js/issues/2464">#2464</a>)</li> <li><em>Breaking:</em> Commander 15 requires Node.js v22.12.0 or higher (for <code>require(esm)</code>).</li> <li>dev: switch tests from Jest to <code>node:test</code> test runner (<a href="https://redirect.github.com/tj/commander.js/issues/2463">#2463</a>)</li> </ul> <h3>Deleted</h3> <ul> <li><em>Breaking:</em> removed deprecated export of <code>commander/esm.mjs</code> (<a href="https://redirect.github.com/tj/commander.js/issues/2464">#2464</a>)</li> </ul> <h3>Migration Tips</h3> <p>Commander 15 is ESM only, but this does not mean you need to migrate to ESM to use it. Importing ESM from CommonJS is supported by Node.js, and Bun, and Deno. Hopefully it Just Works for you! However, you may be using a different runtime or some other part of your setup that may not yet natively support importing ESM from CommonJS, such as your testing framework or bundler.</p> <p>If you have problems using Commander 15 in your environment, one option is stay on Commander 14 for now. Commander 14 will get security updates until May 2027 and things will hopefully improve for your setup in the meantime.</p> <h2>v15.0.0-0</h2> <p>Commander 15 is ESM only. This is expected to be seamless for ESM consumers, but some CommonJS consumers may hit issues with tooling requiring configuration for ESM-only dependencies. See Migration Tips below.</p> <p>The release of Commander 15 in May 2026 will move Commander 14 into maintenance. Commander 14 will get security updates for 12 months (to May 2027). For more info see <a href="https://github.com/tj/commander.js/blob/master/docs/release-policy.md">Release Policy</a>.</p> <h3>Added</h3> <ul> <li>show excess command-arguments in error message (<a href="https://redirect.github.com/tj/commander.js/issues/2384">#2384</a>)</li> </ul> <h3>Fixed</h3> <ul> <li><em>Breaking:</em> only lone <code>--no-*</code> option sets default option value to <code>true</code>, default not implicitly set when define both positive and negative option in either order (<a href="https://redirect.github.com/tj/commander.js/issues/2405">#2405</a>)</li> <li>update example to use compatible character for MINGW64 (<a href="https://redirect.github.com/tj/commander.js/issues/2475">#2475</a>)</li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/tj/commander.js/blob/master/CHANGELOG.md">commander's changelog</a>.</em></p> <blockquote> <h2>[15.0.0] (2026-05-29)</h2> <p>Commander 15 is ESM only. This is expected to be seamless for ESM consumers, but some CommonJS consumers may hit issues with tooling requiring configuration for ESM-only dependencies. See Migration Tips below.</p> <p>The release of Commander 15 moves Commander 14 into maintenance. Commander 14 will get security updates for 12 months (to May 2027). For more info see <a href="https://github.com/tj/commander.js/blob/master/docs/release-policy.md">Release Policy</a>.</p> <h3>Added</h3> <ul> <li>show excess command-arguments in error message (<a href="https://redirect.github.com/tj/commander.js/issues/2384">#2384</a>)</li> </ul> <h3>Fixed</h3> <ul> <li><em>Breaking:</em> only lone <code>--no-*</code> option sets default option value to <code>true</code>, default not implicitly set when define both positive and negative option in either order (<a href="https://redirect.github.com/tj/commander.js/issues/2405">#2405</a>)</li> <li>update example to use compatible character for MINGW64 (<a href="https://redirect.github.com/tj/commander.js/issues/2475">#2475</a>)</li> </ul> <h3>Changed</h3> <ul> <li><em>Breaking:</em> migrated Commander implementation from CommonJS to ESM (<a href="https://redirect.github.com/tj/commander.js/issues/2464">#2464</a>)</li> <li><em>Breaking:</em> Commander 15 requires Node.js v22.12.0 or higher (for <code>require(esm)</code>).</li> <li>dev: switch tests from Jest to <code>node:test</code> test runner (<a href="https://redirect.github.com/tj/commander.js/issues/2463">#2463</a>)</li> </ul> <h3>Deleted</h3> <ul> <li><em>Breaking:</em> removed deprecated export of <code>commander/esm.mjs</code> (<a href="https://redirect.github.com/tj/commander.js/issues/2464">#2464</a>)</li> </ul> <h3>Migration Tips</h3> <p>Commander 15 is ESM only, but this does not mean you need to migrate to ESM to use it. Importing ESM from CommonJS is supported by Node.js, and Bun, and Deno. Hopefully it Just Works for you! However, you may be using a different runtime or some other part of your setup that may not yet natively support importing ESM from CommonJS, such as your testing framework or bundler.</p> <p>If you have problems using Commander 15 in your environment, one option is stay on Commander 14 for now. Commander 14 will get security updates until May 2027 and things will hopefully improve for your setup in the meantime.</p> <h2>[15.0.0-0] (2026-02-22)</h2> <p>(Released as 15.0.0)</p> <h2>[14.0.3] (2026-01-31)</h2> <h3>Added</h3> <ul> <li>Release Policy document (<a href="https://redirect.github.com/tj/commander.js/issues/2462">#2462</a>)</li> </ul> <h3>Changes</h3> <ul> <li>old major versions now supported for 12 months instead of just previous major version, to give predictable end-of-life date (<a href="https://redirect.github.com/tj/commander.js/issues/2462">#2462</a>)</li> <li>clarify typing for deprecated callback parameter to <code>.outputHelp()</code> (<a href="https://redirect.github.com/tj/commander.js/issues/2427">#2427</a>)</li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/tj/commander.js/commit/ba6d13ddb4243e5913367734f8c159089ffe7834"><code>ba6d13d</code></a> Fix release dates in changelog (<a href="https://redirect.github.com/tj/commander.js/issues/2523">#2523</a>)</li> <li><a href="https://github.com/tj/commander.js/commit/a752ed909f179e3a5dcae31a890a89fb748473c4"><code>a752ed9</code></a> Pin GitHub actions with hash (<a href="https://redirect.github.com/tj/commander.js/issues/2521">#2521</a>)</li> <li><a href="https://github.com/tj/commander.js/commit/74d5dfe9b7e199d98e2269ecf88dcf771c260983"><code>74d5dfe</code></a> Drop EOL node 20 from test matrix, and add node 26 (<a href="https://redirect.github.com/tj/commander.js/issues/2520">#2520</a>)</li> <li><a href="https://github.com/tj/commander.js/commit/6df9b68b75ad8df1532ad3572e1d5a1c53bde6cd"><code>6df9b68</code></a> Update details for 15.0.0 release (<a href="https://redirect.github.com/tj/commander.js/issues/2519">#2519</a>)</li> <li><a href="https://github.com/tj/commander.js/commit/01ce5d0cd7e845d6ed749ab57616ec9c173cf91f"><code>01ce5d0</code></a> Remove jest esm examples (<a href="https://redirect.github.com/tj/commander.js/issues/2517">#2517</a>)</li> <li><a href="https://github.com/tj/commander.js/commit/d785d8b3b9448952ef023a8cd26a0a3923a90458"><code>d785d8b</code></a> Update dependencies (<a href="https://redirect.github.com/tj/commander.js/issues/2518">#2518</a>)</li> <li><a href="https://github.com/tj/commander.js/commit/9098b4863ef7678b9d138ae0f04afd949287510c"><code>9098b48</code></a> Update dependencies (<a href="https://redirect.github.com/tj/commander.js/issues/2506">#2506</a>)</li> <li><a href="https://github.com/tj/commander.js/commit/373f660f6febb720b82635220eea72dd9b7e0cba"><code>373f660</code></a> Use node:util stripVTControlCharacters instead of own code (<a href="https://redirect.github.com/tj/commander.js/issues/2486">#2486</a>)</li> <li><a href="https://github.com/tj/commander.js/commit/987f28966c71baecb0ef4a36780e727bcd575b31"><code>987f289</code></a> Use simple match in test (to avoid warning about expensive regex) (<a href="https://redirect.github.com/tj/commander.js/issues/2485">#2485</a>)</li> <li><a href="https://github.com/tj/commander.js/commit/0ea3bb3e883eaa909f1056d0d13a06cc31ec2c3c"><code>0ea3bb3</code></a> Update dependecies and lint (<a href="https://redirect.github.com/tj/commander.js/issues/2489">#2489</a>)</li> <li>Additional commits viewable in <a href="https://github.com/tj/commander.js/compare/v13.1.0...v15.0.0">compare view</a></li> </ul> </details> <br /> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |
||
|
|
d9f759b7bc |
chore(lockfile): refresh pnpm-lock.yaml (#12178)
Add the missing server importer for @paperclipai/paperclip-runner. |
||
|
|
9964b034bb |
feat(runner): add hidden server PRP coordinator (#12176)
## Thinking Path > - Paperclip is the open source app people use to manage AI agents for work. > - The Paperclip Runner needs a narrow server trust boundary before an adapter can start it. > - The package has durable runner transport, but the server does not host or authorize that transport. > - Native persistence exists, but no writer connects PRP events to those records. > - A direct adapter must not enter this path by accident. > - This pull request adds a hidden, run-bound PRP server coordinator. > - The benefit is a recoverable server boundary that remains unavailable to normal execution. ## Linked Issues or Issue Description Refs #11962 Refs #12129 Refs #12169 **Subsystem affected** Cross-cutting. The change affects the runner package and server orchestration. **Problem or motivation** The server cannot authenticate runnerd, commit PRP events before ACK, authorize semantic tools, or enter native finalization from a durable runner result. The application must have this hidden boundary before a guarded adapter can use the runner. **Proposed solution** Add an authenticated PRP WebSocket authority and register it only for one exact persisted native Codex run. Bind each connection and event to the company, issue, agent, run, runner, session, turn, item, and verified runner identity. Commit each event before its cumulative ACK. Project only authorized same-task read tools. Rebuild the accepted result and finalization record from durable result and terminal events. **Alternatives considered** The server could expose a broad runner API key or route semantic calls through existing adapter endpoints. Those options grant too much authority and weaken replay recovery. The server could also add the user-facing adapter in this pull request. That option would mix rollout selection with the transport trust boundary and make legacy compatibility harder to review. **Roadmap alignment** This work supports the shipped enforced-outcomes, governed-tool, and self-healing-run milestones. It does not add a new roadmap surface. ## What Changed - Add the durable PRP server authority with one-use bootstrap tickets, reconnect leases, encrypted frames, bounded state, cumulative ACKs, and idempotent commands. - Add `/api/runner/v1/connect/:runId`. Derive its `ws://` or `wss://` URL from the configured Paperclip API URL. - Register one authority only after the coordinator verifies the complete native Codex run binding. - Commit validated PRP events to `heartbeat_run_events` before ACK. Reject source gaps and conflicting replays. - Rebuild accepted results and finalization records from durable result and terminal events. Enforce finalization owner leases and retry times. - Project five same-task read operations. Recheck run, agent, task, and company authority for each call. - Keep the route hidden. No adapter selects this coordinator, and no code starts runnerd. - Vendor the compiled runner TypeScript runtime into the server package while keeping the workspace package development-only for the server. - Document the package, database writer, run-log payload, and credential exclusions. ## Verification - Run `pnpm --filter @paperclipai/paperclip-runner check:all`. All TypeScript protocol checks and 69 Vitest tests pass, including commit-before-ACK crash recovery. All 43 Rust unit tests and 13 Rust integration tests pass. Conformance and replay parity pass. - Run the focused server WebSocket, coordinator, package-build, and startup-wiring suites. All 26 tests pass, including a clean-checkout reproduction with the runner `dist` directory absent. - Run `pnpm -r typecheck`. - Run `pnpm test:run`. - Run `pnpm build`. - Confirm that the diff contains 19 files. Confirm that it contains no workflow or `pnpm-lock.yaml` change. ## Risks - The server installs the WebSocket route at startup. An unregistered or malformed run path fails closed and creates no native record. - Bootstrap tickets are one use. The private state directory uses mode `0700`, and the state file uses mode `0600`. The file stores derived authentication verifiers and never stores raw tickets or lease tokens. - The journal has explicit frame, command, event-window, and file-size bounds. A bound violation closes the runner connection or rejects the command. - A runner event reaches the database before its ACK. A crash between event commit and ACK causes a byte-equivalent replay, not a second logical effect. - The coordinator accepts only an existing queued or running native Codex row with exact company, task, agent, runner, session, and completion-contract ownership. - Existing direct adapters do not call this service. They keep their current execution, transcript, result, and finalization paths. - The server has no production dependency on the private runner package. Its build copies the compiled runtime into `server/dist`; the workspace link is development-only. This adds no external package and does not change the lockfile. > For core feature work, check [`ROADMAP.md`](ROADMAP.md) first and discuss it in `#dev` before opening the PR. Feature PRs that overlap with planned core work may need to be redirected — check the roadmap first. See `CONTRIBUTING.md`. ## Model Used - OpenAI Codex with GPT-5. The exact deployment ID and context-window size are not exposed. The model used agentic reasoning, repository tools, code execution, and test execution. ## Checklist - [x] I have included a thinking path that traces from project context to this change - [x] I have specified the model used (with version and capability details) - [x] I have checked ROADMAP.md and confirmed this PR does not duplicate planned core work - [x] I have searched GitHub for duplicate or related PRs and linked them above - [x] I have either (a) linked existing issues with `Fixes: #` / `Closes #` / `Refs #` OR (b) described the issue in-PR following the relevant issue template - [x] I have not referenced internal/instance-local Paperclip issues or links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip` URLs) - [x] My branch name describes the change (e.g. `docs/...`, `fix/...`) and contains no internal Paperclip ticket id or instance-derived details - [x] I have run tests locally and they pass - [x] I have added or updated tests where applicable - [x] I have updated relevant documentation to reflect my changes - [x] I have considered and documented any risks above - [x] All Paperclip CI gates are green - [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups - [x] I will address all Greptile and reviewer comments before requesting mergecanary/v2026.825.0-canary.13 |
||
|
|
86fe9339e1 |
chore(lockfile): refresh pnpm-lock.yaml (#12174)
Auto-generated lockfile refresh after dependencies changed on master. This PR only updates pnpm-lock.yaml. Co-authored-by: lockfile-bot <lockfile-bot@users.noreply.github.com> |
||
|
|
69e8585146 |
build(deps): bump better-auth from 1.6.28 to 1.7.0 (#11886)
Bumps [better-auth](https://github.com/better-auth/better-auth/tree/HEAD/packages/better-auth) from 1.6.28 to 1.7.0. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/better-auth/better-auth/releases">better-auth's releases</a>.</em></p> <blockquote> <h2>v1.7.0</h2> <p><strong>Blog post:</strong> <a href="https://better-auth.com/blog/1-7">Better Auth 1.7</a></p> <h2><code>better-auth</code></h2> <h3>❗ Breaking Changes</h3> <ul> <li>Moved database joins out of <code>experimental</code> into the stable <code>advanced.database.joins</code> option (<a href="https://redirect.github.com/better-auth/better-auth/pull/10359">#10359</a>) <blockquote> <p><strong>Migration:</strong> Replace <code>experimental: { joins: true }</code> with <code>advanced: { database: { joins: true } }</code>. Drizzle and Prisma users should regenerate their schema (<code>npx auth@latest generate</code>) so it includes the required relations.</p> </blockquote> </li> <li>Scoped account identity by trusted issuer, keying accounts on <code>(issuer, accountId)</code> (<a href="https://redirect.github.com/better-auth/better-auth/pull/10403">#10403</a>) <blockquote> <p><strong>Migration:</strong> Accounts now require <code>Account.issuer</code>. Read provider identity from <code>accountInfo.account.accountId</code>, drop <code>mapping.id</code> from SSO configs, and give the <code>microsoftEntraId</code> helper a concrete tenant GUID. Apply the account-identity backfill in the 1.7 upgrade guide before deploying.</p> </blockquote> </li> <li>Required captcha endpoint entries to match full auth paths, with wildcard support (<a href="https://redirect.github.com/better-auth/better-auth/pull/10004">#10004</a>) <blockquote> <p><strong>Migration:</strong> Replace partial paths such as <code>/sign-in</code> with explicit wildcards like <code>/sign-in/*</code> or <code>/sign-in/**</code>.</p> </blockquote> </li> <li>Moved the MCP plugin into its own <code>@better-auth/mcp</code> package built on the OAuth provider (<a href="https://redirect.github.com/better-auth/better-auth/pull/9992">#9992</a>) <blockquote> <p><strong>Migration:</strong> Install <code>@better-auth/mcp</code> and <code>@better-auth/cimd</code>, add the now-required <code>jwt()</code> plugin, and move options nested under <code>oidcConfig</code> to flat <code>mcp({ ... })</code> options. Rename <code>withMcpAuth</code> to <code>requireMcpAuth</code> and <code>mcpHandler</code> to <code>createMcpProtectedRequestHandler</code>. Regenerate the schema (<code>npx auth migrate</code>): <code>oauthApplication</code> becomes <code>oauthClient</code>, plus new <code>oauthRefreshToken</code> and <code>oauthClientAssertion</code> tables.</p> </blockquote> </li> <li>Added OIDC back-channel logout so ending a session cuts off every connected app's API access (<a href="https://redirect.github.com/better-auth/better-auth/pull/9304">#9304</a>) <blockquote> <p><strong>Migration:</strong> Introspecting an access token whose session has ended now returns <code>{ active: false }</code>, and <code>/oauth2/userinfo</code> rejects it. Clients opt into notifications by registering <code>backchannel_logout_uri</code>. Run the schema migration for the new <code>oauthClient</code> and <code>oauthAccessToken</code> columns.</p> </blockquote> </li> <li>Modeled OAuth protected resources explicitly, with per-resource TTLs, scopes, claims, and signing pins (<a href="https://redirect.github.com/better-auth/better-auth/pull/9648">#9648</a>) <blockquote> <p><strong>Migration:</strong> <code>validAudiences</code> is removed: move each resource identifier into <code>resources</code> and link restricted clients through <code>oauthClientResource</code>. <code>@better-auth/mcp</code> now requires an explicit <code>resource</code>. Run <code>npx @better-auth/cli generate</code> and apply the migration before deploying.</p> </blockquote> </li> <li>Decoupled SCIM provisioning from the organization plugin (<a href="https://redirect.github.com/better-auth/better-auth/pull/10390">#10390</a>) <blockquote> <p><strong>Migration:</strong> SCIM configuration, client APIs, database schema, and the Group model are all replaced, and provisioning state cannot migrate in place. Follow the SCIM cutover in the 1.7 upgrade guide, including a full directory reprovision, before resuming traffic.</p> </blockquote> </li> <li>Added OTP-only two-factor enablement with a discriminated <code>enableTwoFactor</code> response (<a href="https://redirect.github.com/better-auth/better-auth/pull/9057">#9057</a>) <blockquote> <p><strong>Migration:</strong> <code>enableTwoFactor</code> now returns a <code>method</code> field (<code>"otp"</code> or <code>"totp"</code>); narrow on it before reading <code>totpURI</code> and <code>backupCodes</code>. Pass <code>method: "otp"</code> for OTP enrollment, which requires <code>otpOptions.sendOTP</code>.</p> </blockquote> </li> <li>Resolved the auth origin from <code>Host</code> by default when using a dynamic <code>baseURL</code> (<a href="https://redirect.github.com/better-auth/better-auth/pull/9134">#9134</a>) <blockquote> <p><strong>Migration:</strong> If your proxy exposes the public hostname only through <code>x-forwarded-host</code>, set <code>advanced.trustedProxyHeaders: true</code>. Deployments where the proxy rewrites <code>Host</code> (nginx default, Vercel, Cloudflare, Netlify) are unaffected.</p> </blockquote> </li> <li>Added unique lookup indexes for the device authorization <code>deviceCode</code> and <code>userCode</code> columns (<a href="https://redirect.github.com/better-auth/better-auth/pull/10059">#10059</a>) <blockquote> <p><strong>Migration:</strong> Resolve duplicate code values before applying the migration. MySQL and SQL Server installations must also convert both columns to bounded strings and clean up values longer than 191 characters.</p> </blockquote> </li> <li>Enforced S256 PKCE in the Electron sign-in flow and hardened custom-scheme origin checks (<a href="https://redirect.github.com/better-auth/better-auth/pull/9645">#9645</a>) <blockquote> <p><strong>Migration:</strong> Upgrade the <code>@better-auth/electron</code> client and server together and add your app's scheme to <code>trustedOrigins</code>. The <code>code_challenge_method</code> parameter and <code>disableOriginOverride</code> option are removed, and host-bearing custom-scheme entries now match that host exactly.</p> </blockquote> </li> <li>Identified Microsoft Entra accounts by the stable <code>oid</code> claim (<a href="https://redirect.github.com/better-auth/better-auth/pull/10204">#10204</a>) <blockquote> <p><strong>Migration:</strong> Migrate existing Microsoft account rows created from <code>sub</code> before upgrading. Tokens without a valid <code>oid</code> are rejected.</p> </blockquote> </li> <li>Required a Google client ID before Google One Tap verifies ID tokens (<a href="https://redirect.github.com/better-auth/better-auth/pull/10036">#10036</a>) <blockquote> <p><strong>Migration:</strong> Configure <code>oneTap({ clientId })</code> or <code>socialProviders.google.clientId</code>.</p> </blockquote> </li> <li>Removed the deprecated <code>oidcProvider</code> plugin (<a href="https://redirect.github.com/better-auth/better-auth/pull/10031">#10031</a>) <blockquote> <p><strong>Migration:</strong> Move OIDC authorization-server integrations to <code>@better-auth/oauth-provider</code>.</p> </blockquote> </li> <li>Rewrote the generic OAuth plugin as a first-class social provider with OAuth 2.1 defaults (<a href="https://redirect.github.com/better-auth/better-auth/pull/9069">#9069</a>) <blockquote> <p><strong>Migration:</strong> Replace <code>signIn.oauth2({ providerId })</code> with <code>signIn.social({ provider })</code>, <code>oauth2.link()</code> with <code>linkSocial()</code>, and drop <code>genericOAuthClient()</code>. Callbacks move to <code>/api/auth/callback/:id</code>, <code>pkce</code> now defaults to <code>true</code>, and <code>issuer</code> and <code>requireIssuerValidation</code> are removed in favor of OIDC discovery.</p> </blockquote> </li> <li>Separated OAuth device grant ownership into <code>oauthDeviceAuthorization()</code> (<a href="https://redirect.github.com/better-auth/better-auth/pull/10746">#10746</a>) <blockquote> <p><strong>Migration:</strong> The OAuth integration replaces the optional <code>resource</code> column with <code>oauthClientId</code> and <code>resources</code>, so regenerate and apply the schema. Let pending device codes expire before upgrading from an earlier 1.7 prerelease.</p> </blockquote> </li> <li>Verified provider <code>id_tokens</code> with a single shared verifier (<a href="https://redirect.github.com/better-auth/better-auth/pull/9828">#9828</a>) <blockquote> <p><strong>Migration:</strong> Custom <code>UpstreamProvider</code> implementations replace the removed <code>verifyIdToken</code> method with an <code>idToken</code> config carrying a JWKS source, issuer, and audience. PayPal client <code>id_token</code> sign-in now returns <code>ID_TOKEN_NOT_SUPPORTED</code>; its redirect flow is unchanged.</p> </blockquote> </li> </ul> <h3>Features</h3> <ul> <li>Added <code>clientAssertion</code> support to the Microsoft Entra ID social provider (<a href="https://redirect.github.com/better-auth/better-auth/pull/9898">#9898</a>)</li> <li>Made the <code>Auth</code> instance directly fetchable (<a href="https://redirect.github.com/better-auth/better-auth/pull/9431">#9431</a>)</li> <li>Added per-provider <code>requireEmailVerification</code> for social sign-in (<a href="https://redirect.github.com/better-auth/better-auth/pull/9929">#9929</a>)</li> <li>Added a <code>user.validateUserInfo</code> gate for rejecting an identity before a user is created or linked (<a href="https://redirect.github.com/better-auth/better-auth/pull/9864">#9864</a>)</li> <li>Added <code>hydrateSession</code> so <code>useSession</code> returns server-fetched data on the first render (<a href="https://redirect.github.com/better-auth/better-auth/pull/8733">#8733</a>)</li> <li>Added compound table indexes to plugin database schemas (<a href="https://redirect.github.com/better-auth/better-auth/pull/10402">#10402</a>)</li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/better-auth/better-auth/blob/main/packages/better-auth/CHANGELOG.md">better-auth's changelog</a>.</em></p> <blockquote> <h2>1.7.0</h2> <h3>Minor Changes</h3> <ul> <li> <p><a href="https://redirect.github.com/better-auth/better-auth/pull/8733">#8733</a> <a href="https://github.com/better-auth/better-auth/commit/4e8e4c7fc5fb2723144cbf41c4a1bfa28de8d671"><code>4e8e4c7</code></a> Thanks <a href="https://github.com/bytaesu"><code>@bytaesu</code></a>! - Add <code>hydrateSession</code> to seed the client with a server-fetched session so <code>useSession</code> returns data on the first render.</p> </li> <li> <p><a href="https://redirect.github.com/better-auth/better-auth/pull/9930">#9930</a> <a href="https://github.com/better-auth/better-auth/commit/0cbaf81bed9dec4c56880ee78a532262386e1ec5"><code>0cbaf81</code></a> Thanks <a href="https://github.com/gustavovalverde"><code>@gustavovalverde</code></a>! - Anonymous account linking now works after social and generic OAuth sign-in in Expo and other in-app browsers, where the OAuth callback returns without the session cookie. <code>onLinkAccount</code> fires and the anonymous user is migrated; before, it was silently skipped.</p> <p>Plugins can now carry server-trusted data across an OAuth redirect with the new <code>addOAuthServerContext</code> API, read back on the callback via <code>getOAuthState().serverContext</code>. Unlike <code>additionalData</code>, it cannot be set from the request body, so it is the right place for values the server must trust.</p> <p>For <code>@better-auth/oauth-provider</code>, the post-login authorization query now travels through that server-only channel, so it can no longer be injected through <code>additionalData</code>.</p> </li> <li> <p><a href="https://redirect.github.com/better-auth/better-auth/pull/10004">#10004</a> <a href="https://github.com/better-auth/better-auth/commit/b36c38f9842d3416689340552989449a32007819"><code>b36c38f</code></a> Thanks <a href="https://github.com/bytaesu"><code>@bytaesu</code></a>! - The captcha plugin now requires endpoint entries to match full auth paths unless they use wildcard patterns. This prevents requests like <code>/sign-in//email</code> from bypassing captcha while preserving trailing-slash matches like <code>/sign-in/email/</code>. To protect multiple routes, replace partial paths like <code>/sign-in</code> with explicit wildcards such as <code>/sign-in/*</code> or <code>/sign-in/**</code>.</p> </li> <li> <p><a href="https://redirect.github.com/better-auth/better-auth/pull/10746">#10746</a> <a href="https://github.com/better-auth/better-auth/commit/6782647d7c2d248246f9ef3980e656725c29ce64"><code>6782647</code></a> Thanks <a href="https://github.com/gustavovalverde"><code>@gustavovalverde</code></a>! - OAuth device grants now use <code>oauthDeviceAuthorization()</code> alongside <code>oauthProvider()</code> or <code>mcp()</code>. This single integration replaces both the standalone <code>deviceCodeGrant()</code> plugin and the shared-grant configuration. Standalone Device Authorization no longer accepts or stores RFC 8707 resources, and <code>onDeviceAuthRequest</code> receives only <code>clientId</code> and <code>scope</code>. The OAuth integration rejects resource indicators that are not absolute, fragment-free URIs.</p> <p>The OAuth integration replaces the optional <code>resource</code> column with <code>oauthClientId</code> and <code>resources</code>. Regenerate and apply the schema when using it. Before upgrading from an earlier 1.7 prerelease, let pending OAuth device codes expire or delete them because they cannot be exchanged through the new integration.</p> </li> <li> <p><a href="https://redirect.github.com/better-auth/better-auth/pull/10402">#10402</a> <a href="https://github.com/better-auth/better-auth/commit/763a2671c5372d88c291881977c8a1c2e29034b1"><code>763a267</code></a> Thanks <a href="https://github.com/gustavovalverde"><code>@gustavovalverde</code></a>! - Plugin database schemas can now define named or generated table-level indexes across multiple fields. SQL migrations and generated Drizzle or Prisma schemas resolve configured table and column names consistently, while the MongoDB adapter creates the same indexes before the first index-enforcing write.</p> </li> <li> <p><a href="https://redirect.github.com/better-auth/better-auth/pull/9766">#9766</a> <a href="https://github.com/better-auth/better-auth/commit/bf39cbf13f3b934f728cde72b1e7ebdc4c85f641"><code>bf39cbf</code></a> Thanks <a href="https://github.com/GautamBytes"><code>@GautamBytes</code></a>! - Add a server-only <code>auth.api.consumePhoneNumberOTP</code> API for custom phone OTP flows that need to verify and consume a code without creating or updating users or sessions.</p> </li> <li> <p><a href="https://redirect.github.com/better-auth/better-auth/pull/10330">#10330</a> <a href="https://github.com/better-auth/better-auth/commit/081d3c379c720926295067d878c421b5e8684c78"><code>081d3c3</code></a> Thanks <a href="https://github.com/ping-maxwell"><code>@ping-maxwell</code></a>! - Allow the username plugin's separate <code>displayUsername</code> field to be omitted by setting <code>displayUsername: false</code> on both the server and client plugins.</p> </li> <li> <p><a href="https://redirect.github.com/better-auth/better-auth/pull/10059">#10059</a> <a href="https://github.com/better-auth/better-auth/commit/49b5cf650e1264ecc4c917ca193ea05c3b58a3b9"><code>49b5cf6</code></a> Thanks <a href="https://github.com/GautamBytes"><code>@GautamBytes</code></a>! - Device Authorization now creates unique database indexes for <code>deviceCode</code> and <code>userCode</code>, so each generated code must be unique in its column. Existing installations on every adapter must resolve duplicate values before applying the migration. MySQL and SQL Server installations must also convert both columns to bounded strings and clean up values longer than 191 characters before running it.</p> <p>Generated codes are limited to 191 characters. Issuance makes up to 3 attempts to overcome unique-key collisions, then returns <code>server_error</code> if it cannot create a unique <code>deviceCode</code> and <code>userCode</code>. Default-generated user codes accept case changes and readability separators during verification, approval, and denial; custom codes outside the default alphabet are matched exactly. The <code>/device</code> limiter allows 5 requests over a window equal to the configured code lifetime, while <code>/device/token</code> polling keeps its separate interval behavior.</p> </li> <li> <p><a href="https://redirect.github.com/better-auth/better-auth/pull/9645">#9645</a> <a href="https://github.com/better-auth/better-auth/commit/e0140297a59ddb59cccbcb4ba46c513de8cb86a7"><code>e014029</code></a> Thanks <a href="https://github.com/ping-maxwell"><code>@ping-maxwell</code></a>! - Harden the Electron OAuth flow and tighten custom-scheme trusted-origin matching.</p> <p>The Electron sign-in flow now mandates PKCE S256. Plain PKCE is rejected: the <code>code_challenge_method</code> parameter is gone and every authorization code is verified by hashing the verifier with SHA-256. The server no longer trusts an <code>electron-origin</code> header to set the request Origin. The Electron client now sends a real <code>Origin</code> (for example <code>myapp:/</code>), so upgrade the <code>@better-auth/electron</code> client and server together and make sure your app's scheme is in <code>trustedOrigins</code>. The unused <code>disableOriginOverride</code> option is removed.</p> <p>Custom-scheme entries in <code>trustedOrigins</code> now match by scheme and authority instead of string prefix. A host-less entry such as <code>myapp://</code> or <code>exp://</code> still trusts every host of that scheme, but a host-bearing entry such as <code>myapp://callback</code> matches that host exactly, so it is no longer satisfied by <code>myapp://callback.attacker.tld</code>.</p> </li> <li> <p><a href="https://redirect.github.com/better-auth/better-auth/pull/9948">#9948</a> <a href="https://github.com/better-auth/better-auth/commit/3d04fababbf3efd4c46a4012f46ed9397715c2e3"><code>3d04fab</code></a> Thanks <a href="https://github.com/yordis"><code>@yordis</code></a>! - feat(generic-oauth): add <code>refreshTokenParams</code> config to forward extra params on token refresh</p> <p>Multi-tenant OIDC providers (Zitadel multi-org, Auth0 with <code>audience</code>) need to send extra body params on the refresh call to rescope tokens without a full authorization redirect. The generic-oauth plugin now accepts a <code>refreshTokenParams</code> option (object or sync/async function) that is merged into the refresh request body, with <code>grant_type</code> and <code>refresh_token</code> protected from override. The function form receives request metadata for the request that triggered the refresh, so request-scoped data (headers, cookies) is available without out-of-band state like AsyncLocalStorage.</p> <p><code>UpstreamProvider.refreshAccessToken</code> now accepts an optional second <code>ctx</code> argument; the change is backwards compatible because existing implementations that take only <code>refreshToken</code> remain valid. See <a href="https://redirect.github.com/better-auth/better-auth/issues/7554">#7554</a>.</p> </li> <li> <p><a href="https://redirect.github.com/better-auth/better-auth/pull/9069">#9069</a> <a href="https://github.com/better-auth/better-auth/commit/c7d22539ec4f7322d9625ae2953d397c3863d097"><code>c7d2253</code></a> Thanks <a href="https://github.com/gustavovalverde"><code>@gustavovalverde</code></a>! - Rewrite the generic OAuth plugin as a first-class social provider with OAuth 2.1 security defaults. Providers now use <code>signIn.social</code> + <code>callback/:id</code> instead of dedicated plugin endpoints, with PKCE required by default (OAuth 2.1), RFC 9207 issuer validation, OIDC auto-discovery with <code>openid</code> scope injection, and typed provider IDs.</p> <p><strong>Breaking changes:</strong></p> <ul> <li><code>signIn.oauth2({ providerId })</code> replaced by <code>signIn.social({ provider })</code></li> <li><code>oauth2.link()</code> replaced by <code>linkSocial()</code></li> <li>Callback URL changed from <code>/api/auth/oauth2/callback/:id</code> to <code>/api/auth/callback/:id</code></li> <li><code>genericOAuthClient()</code> removed; generic OAuth providers now use the standard social client APIs</li> <li><code>pkce</code> defaults to <code>true</code> (was <code>false</code>); set <code>pkce: false</code> for providers that reject PKCE</li> <li><code>authorizationUrlParams</code> and <code>tokenUrlParams</code> only accept <code>Record<string, string></code></li> </ul> </li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/better-auth/better-auth/commit/ccd57c2dcb145a40a30c75ab3f6c89b94af08701"><code>ccd57c2</code></a> docs(changelog): align v1.7 release notes with final behavior (<a href="https://github.com/better-auth/better-auth/tree/HEAD/packages/better-auth/issues/10846">#10846</a>)</li> <li><a href="https://github.com/better-auth/better-auth/commit/f577ec5c766c4ccd0a677ad18ca5f4f17b245289"><code>f577ec5</code></a> chore: exit pre-release mode for v1.7.0</li> <li><a href="https://github.com/better-auth/better-auth/commit/69258d16709b977e519aa00a323ae54aea2b6164"><code>69258d1</code></a> chore: sync main to next</li> <li><a href="https://github.com/better-auth/better-auth/commit/e84ec5e76d30e10fd692e8084177360484d538c1"><code>e84ec5e</code></a> chore: release v1.6.30 (<a href="https://github.com/better-auth/better-auth/tree/HEAD/packages/better-auth/issues/10840">#10840</a>)</li> <li><a href="https://github.com/better-auth/better-auth/commit/bc93b27542cbdf74f6455e6f66a0b4292c247a12"><code>bc93b27</code></a> chore: release v1.7.0-rc.6 (<a href="https://github.com/better-auth/better-auth/tree/HEAD/packages/better-auth/issues/10772">#10772</a>)</li> <li><a href="https://github.com/better-auth/better-auth/commit/58c49eb97f04ff18aa823318a3856a013353fdc2"><code>58c49eb</code></a> chore: release v1.6.29 (<a href="https://github.com/better-auth/better-auth/tree/HEAD/packages/better-auth/issues/10809">#10809</a>)</li> <li><a href="https://github.com/better-auth/better-auth/commit/e6e1b4e8146a84d2a2c5fe2c497c81d03dfc2ad3"><code>e6e1b4e</code></a> perf(db): replace sequential get-then-delete loop with parallel deletes in de...</li> <li><a href="https://github.com/better-auth/better-auth/commit/80799e69314d4d13c875457d932545d54fbc7ada"><code>80799e6</code></a> chore: sync main to next</li> <li><a href="https://github.com/better-auth/better-auth/commit/3e485bf730c62b4ef3df2e55198179c3d15b5a9f"><code>3e485bf</code></a> docs(username): fix displayUsername release notes (<a href="https://github.com/better-auth/better-auth/tree/HEAD/packages/better-auth/issues/10776">#10776</a>)</li> <li><a href="https://github.com/better-auth/better-auth/commit/65fc17c755c3e2c8c77d5b401d612737764c219d"><code>65fc17c</code></a> fix(deps): align <code>drizzle-orm</code> peer range with drizzle-adapter (<a href="https://github.com/better-auth/better-auth/tree/HEAD/packages/better-auth/issues/10501">#10501</a>)</li> <li>Additional commits viewable in <a href="https://github.com/better-auth/better-auth/commits/v1.7.0/packages/better-auth">compare view</a></li> </ul> </details> <br /> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |
||
|
|
c5382b36ba |
build(deps-dev): bump vite from 6.4.3 to 8.2.2 (#11887)
Bumps [vite](https://github.com/vitejs/vite/tree/HEAD/packages/vite) from 6.4.3 to 8.2.2. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/vitejs/vite/releases">vite's releases</a>.</em></p> <blockquote> <h2>plugin-legacy@8.2.2</h2> <p>Please refer to <a href="https://github.com/vitejs/vite/blob/plugin-legacy@8.2.2/packages/plugin-legacy/CHANGELOG.md">CHANGELOG.md</a> for details.</p> <h2>v8.2.2</h2> <p>Please refer to <a href="https://github.com/vitejs/vite/blob/v8.2.2/packages/vite/CHANGELOG.md">CHANGELOG.md</a> for details.</p> <h2>plugin-legacy@8.2.1</h2> <p>Please refer to <a href="https://github.com/vitejs/vite/blob/plugin-legacy@8.2.1/packages/plugin-legacy/CHANGELOG.md">CHANGELOG.md</a> for details.</p> <h2>v8.2.1</h2> <p>Please refer to <a href="https://github.com/vitejs/vite/blob/v8.2.1/packages/vite/CHANGELOG.md">CHANGELOG.md</a> for details.</p> <h2>create-vite@8.2.0</h2> <p>Please refer to <a href="https://github.com/vitejs/vite/blob/create-vite@8.2.0/packages/create-vite/CHANGELOG.md">CHANGELOG.md</a> for details.</p> <h2>plugin-legacy@8.2.0</h2> <p>Please refer to <a href="https://github.com/vitejs/vite/blob/plugin-legacy@8.2.0/packages/plugin-legacy/CHANGELOG.md">CHANGELOG.md</a> for details.</p> <h2>v8.2.0</h2> <p>Please refer to <a href="https://github.com/vitejs/vite/blob/v8.2.0/packages/vite/CHANGELOG.md">CHANGELOG.md</a> for details.</p> <h2>v8.2.0-beta.0</h2> <p>Please refer to <a href="https://github.com/vitejs/vite/blob/v8.2.0-beta.0/packages/vite/CHANGELOG.md">CHANGELOG.md</a> for details.</p> <h2>v8.1.5</h2> <p>Please refer to <a href="https://github.com/vitejs/vite/blob/v8.1.5/packages/vite/CHANGELOG.md">CHANGELOG.md</a> for details.</p> <h2>v8.1.4</h2> <p>Please refer to <a href="https://github.com/vitejs/vite/blob/v8.1.4/packages/vite/CHANGELOG.md">CHANGELOG.md</a> for details.</p> <h2>v8.1.3</h2> <p>Please refer to <a href="https://github.com/vitejs/vite/blob/v8.1.3/packages/vite/CHANGELOG.md">CHANGELOG.md</a> for details.</p> <h2>v8.1.2</h2> <p>Please refer to <a href="https://github.com/vitejs/vite/blob/v8.1.2/packages/vite/CHANGELOG.md">CHANGELOG.md</a> for details.</p> <h2>v8.1.1</h2> <p>Please refer to <a href="https://github.com/vitejs/vite/blob/v8.1.1/packages/vite/CHANGELOG.md">CHANGELOG.md</a> for details.</p> <h2>create-vite@8.1.0</h2> <p>Please refer to <a href="https://github.com/vitejs/vite/blob/create-vite@8.1.0/packages/create-vite/CHANGELOG.md">CHANGELOG.md</a> for details.</p> <h2>plugin-legacy@8.1.0</h2> <p>Please refer to <a href="https://github.com/vitejs/vite/blob/plugin-legacy@8.1.0/packages/plugin-legacy/CHANGELOG.md">CHANGELOG.md</a> for details.</p> <h2>v8.1.0</h2> <p>Please refer to <a href="https://github.com/vitejs/vite/blob/v8.1.0/packages/vite/CHANGELOG.md">CHANGELOG.md</a> for details.</p> <h2>plugin-legacy@8.1.0-beta.0</h2> <p>Please refer to <a href="https://github.com/vitejs/vite/blob/plugin-legacy@8.1.0-beta.0/packages/plugin-legacy/CHANGELOG.md">CHANGELOG.md</a> for details.</p> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/vitejs/vite/blob/main/packages/vite/CHANGELOG.md">vite's changelog</a>.</em></p> <blockquote> <h2><!-- raw HTML omitted --><a href="https://github.com/vitejs/vite/compare/v8.2.1...v8.2.2">8.2.2</a> (2026-08-20)<!-- raw HTML omitted --></h2> <h3>Features</h3> <ul> <li><strong>deps:</strong> widen <code>@vitejs/devtools</code> peer range to v0.5.0 (<a href="https://redirect.github.com/vitejs/vite/issues/23302">#23302</a>) (<a href="https://github.com/vitejs/vite/commit/495d9ff5a7d843ca876a9e49799947a5deb704c7">495d9ff</a>)</li> </ul> <h3>Bug Fixes</h3> <ul> <li><strong>bundled-dev:</strong> handle lazy request error (<a href="https://redirect.github.com/vitejs/vite/issues/23291">#23291</a>) (<a href="https://github.com/vitejs/vite/commit/3ba026dade4af56df08815310d3458fa110f5c5c">3ba026d</a>)</li> <li><strong>bundled-dev:</strong> hot update through circular imports instead of reloading (<a href="https://redirect.github.com/vitejs/vite/issues/23259">#23259</a>) (<a href="https://github.com/vitejs/vite/commit/3dbddefaafc091a879b06f9279296f776691e455">3dbddef</a>)</li> <li><strong>config:</strong> resolve sourcemap paths against sourcemap location (<a href="https://redirect.github.com/vitejs/vite/issues/23239">#23239</a>) (<a href="https://github.com/vitejs/vite/commit/05a003e6a17a84d75f907ea0f1598bc39b8dce6c">05a003e</a>)</li> <li><strong>css:</strong> don't pass empty targets to lightningcss (<a href="https://redirect.github.com/vitejs/vite/issues/23295">#23295</a>) (<a href="https://github.com/vitejs/vite/commit/2804636ff608d105928009d274ffba7cfbe55340">2804636</a>)</li> <li><strong>define:</strong> fix match escaped dots to support $-prefixed define keys (<a href="https://redirect.github.com/vitejs/vite/issues/23249">#23249</a>) (<a href="https://github.com/vitejs/vite/commit/dcf88bd2ad2b1a8845f9029587cc8c825e382d42">dcf88bd</a>)</li> <li><strong>deps:</strong> update all non-major dependencies (<a href="https://redirect.github.com/vitejs/vite/issues/23217">#23217</a>) (<a href="https://github.com/vitejs/vite/commit/ba958bddfc9cabe302c6b34269dcf5c9634531e0">ba958bd</a>)</li> <li><strong>deps:</strong> update rolldown-related dependencies (<a href="https://redirect.github.com/vitejs/vite/issues/23218">#23218</a>) (<a href="https://github.com/vitejs/vite/commit/83ecb2c8059e8ce946a7cc835d4c14ef78aef4fd">83ecb2c</a>)</li> <li><strong>module-runner:</strong> exclude completed modules from in-flight cycle detection (fix <a href="https://redirect.github.com/vitejs/vite/issues/22999">#22999</a>) (<a href="https://redirect.github.com/vitejs/vite/issues/23009">#23009</a>) (<a href="https://github.com/vitejs/vite/commit/d9b10a98db1c293ee64300bd75d568b44c8ae931">d9b10a9</a>)</li> <li><strong>optimizer:</strong> close custom extension analysis bundles (<a href="https://redirect.github.com/vitejs/vite/issues/23207">#23207</a>) (<a href="https://github.com/vitejs/vite/commit/8fb76752836f61224d3095b502fa237b478a06b2">8fb7675</a>)</li> <li>reduce Windows 8.3-short-name detection false-positives (<a href="https://redirect.github.com/vitejs/vite/issues/23066">#23066</a>) (<a href="https://github.com/vitejs/vite/commit/02cffa9e2d38d5d8f12e4043ee9d0f7abb1471e2">02cffa9</a>)</li> <li>respect <code>resolve.preserveSymlinks</code> when resolving root (fix <a href="https://redirect.github.com/vitejs/vite/issues/23197">#23197</a>) (<a href="https://redirect.github.com/vitejs/vite/issues/23198">#23198</a>) (<a href="https://github.com/vitejs/vite/commit/8413052731836d4aaf3eb94a0f25788dd35d2888">8413052</a>)</li> <li><strong>ssr:</strong> rewrite computed key of destructing parameter (<a href="https://redirect.github.com/vitejs/vite/issues/23307">#23307</a>) (<a href="https://github.com/vitejs/vite/commit/9db0b61d4c9c7caad7ea1d9670b637faf2bb6c93">9db0b61</a>)</li> <li><strong>vite:</strong> update outdated upstream file links in license comments (<a href="https://redirect.github.com/vitejs/vite/issues/23285">#23285</a>) (<a href="https://github.com/vitejs/vite/commit/c0f2fc607ee97ee4499337b04826420c00654065">c0f2fc6</a>)</li> </ul> <h3>Documentation</h3> <ul> <li><strong>build:</strong> note cssTarget precedence (<a href="https://redirect.github.com/vitejs/vite/issues/23200">#23200</a>) (<a href="https://github.com/vitejs/vite/commit/a20a35ec0685e374519864d0f41dd5f6e9ba0271">a20a35e</a>)</li> </ul> <h3>Miscellaneous Chores</h3> <ul> <li>fix ts errors in build test cases (<a href="https://redirect.github.com/vitejs/vite/issues/23209">#23209</a>) (<a href="https://github.com/vitejs/vite/commit/a0cfcf72f8ef8bf0f2f11d553333b9bb31f1d316">a0cfcf7</a>)</li> </ul> <h3>Code Refactoring</h3> <ul> <li>use JSON import attributes instead of readFileSync in constants (<a href="https://redirect.github.com/vitejs/vite/issues/23258">#23258</a>) (<a href="https://github.com/vitejs/vite/commit/1d9fa392a43229241f80630236f8552ce8f7cd0f">1d9fa39</a>)</li> <li>use named regex constants over inline literals (<a href="https://redirect.github.com/vitejs/vite/issues/22964">#22964</a>) (<a href="https://github.com/vitejs/vite/commit/5c1c6c609718303202832f706884192e1f1e9223">5c1c6c6</a>)</li> </ul> <h3>Tests</h3> <ul> <li><strong>define:</strong> close rolldown bundler after generate (<a href="https://redirect.github.com/vitejs/vite/issues/23231">#23231</a>) (<a href="https://github.com/vitejs/vite/commit/b4d66fee14d970f45b8a6f3d7d6aee73ca9b88ab">b4d66fe</a>)</li> <li><strong>module-runner:</strong> add TLA circular import case (<a href="https://redirect.github.com/vitejs/vite/issues/23299">#23299</a>) (<a href="https://github.com/vitejs/vite/commit/4a261f242831bef92afd2f1aacfb81eab9dec371">4a261f2</a>)</li> <li><strong>module-runner:</strong> simplify server-hmr tests (<a href="https://redirect.github.com/vitejs/vite/issues/23300">#23300</a>) (<a href="https://github.com/vitejs/vite/commit/599b44b6600ec426e10cd556908d53b027b0c4fb">599b44b</a>)</li> <li><strong>ssr:</strong> add destructing assignment case for moduleRunnerTransform (<a href="https://redirect.github.com/vitejs/vite/issues/23308">#23308</a>) (<a href="https://github.com/vitejs/vite/commit/cb77e2a93bad2a8ece00b4aa0ef507c092582c45">cb77e2a</a>)</li> </ul> <h3>Build System</h3> <ul> <li>use JSON import attributes instead of readFIleSync in rolldown configs (<a href="https://redirect.github.com/vitejs/vite/issues/23251">#23251</a>) (<a href="https://github.com/vitejs/vite/commit/d615bcdb23d96c1ca5ce1ee45e21d8d87381106f">d615bcd</a>)</li> </ul> <h2><!-- raw HTML omitted --><a href="https://github.com/vitejs/vite/compare/v8.2.0...v8.2.1">8.2.1</a> (2026-08-06)<!-- raw HTML omitted --></h2> <h3>Bug Fixes</h3> <ul> <li><strong>build:</strong> make client chunkImportMap work with <code>sharedPlugins: true</code> (<a href="https://redirect.github.com/vitejs/vite/issues/23184">#23184</a>) (<a href="https://github.com/vitejs/vite/commit/15f03073c915d6ffb9a1fda447ef66b02bf5cde8">15f0307</a>)</li> <li><strong>bundled-dev:</strong> inject client script tag before chunk scripts (<a href="https://redirect.github.com/vitejs/vite/issues/23161">#23161</a>) (<a href="https://github.com/vitejs/vite/commit/eac0cc84aa2472a85a19ee84561c1ba71e381a55">eac0cc8</a>)</li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/vitejs/vite/commit/de1111ab0be00879b404e7ed3b2a80e264edddc1"><code>de1111a</code></a> release: v8.2.2</li> <li><a href="https://github.com/vitejs/vite/commit/cb77e2a93bad2a8ece00b4aa0ef507c092582c45"><code>cb77e2a</code></a> test(ssr): add destructing assignment case for moduleRunnerTransform (<a href="https://github.com/vitejs/vite/tree/HEAD/packages/vite/issues/23308">#23308</a>)</li> <li><a href="https://github.com/vitejs/vite/commit/9db0b61d4c9c7caad7ea1d9670b637faf2bb6c93"><code>9db0b61</code></a> fix(ssr): rewrite computed key of destructing parameter (<a href="https://github.com/vitejs/vite/tree/HEAD/packages/vite/issues/23307">#23307</a>)</li> <li><a href="https://github.com/vitejs/vite/commit/8413052731836d4aaf3eb94a0f25788dd35d2888"><code>8413052</code></a> fix: respect <code>resolve.preserveSymlinks</code> when resolving root (fix <a href="https://github.com/vitejs/vite/tree/HEAD/packages/vite/issues/23197">#23197</a>) (<a href="https://github.com/vitejs/vite/tree/HEAD/packages/vite/issues/23">#23</a>...</li> <li><a href="https://github.com/vitejs/vite/commit/05a003e6a17a84d75f907ea0f1598bc39b8dce6c"><code>05a003e</code></a> fix(config): resolve sourcemap paths against sourcemap location (<a href="https://github.com/vitejs/vite/tree/HEAD/packages/vite/issues/23239">#23239</a>)</li> <li><a href="https://github.com/vitejs/vite/commit/495d9ff5a7d843ca876a9e49799947a5deb704c7"><code>495d9ff</code></a> feat(deps): widen <code>@vitejs/devtools</code> peer range to v0.5.0 (<a href="https://github.com/vitejs/vite/tree/HEAD/packages/vite/issues/23302">#23302</a>)</li> <li><a href="https://github.com/vitejs/vite/commit/1d9fa392a43229241f80630236f8552ce8f7cd0f"><code>1d9fa39</code></a> refactor: use JSON import attributes instead of readFileSync in constants (<a href="https://github.com/vitejs/vite/tree/HEAD/packages/vite/issues/2">#2</a>...</li> <li><a href="https://github.com/vitejs/vite/commit/2804636ff608d105928009d274ffba7cfbe55340"><code>2804636</code></a> fix(css): don't pass empty targets to lightningcss (<a href="https://github.com/vitejs/vite/tree/HEAD/packages/vite/issues/23295">#23295</a>)</li> <li><a href="https://github.com/vitejs/vite/commit/599b44b6600ec426e10cd556908d53b027b0c4fb"><code>599b44b</code></a> test(module-runner): simplify server-hmr tests (<a href="https://github.com/vitejs/vite/tree/HEAD/packages/vite/issues/23300">#23300</a>)</li> <li><a href="https://github.com/vitejs/vite/commit/4a261f242831bef92afd2f1aacfb81eab9dec371"><code>4a261f2</code></a> test(module-runner): add TLA circular import case (<a href="https://github.com/vitejs/vite/tree/HEAD/packages/vite/issues/23299">#23299</a>)</li> <li>Additional commits viewable in <a href="https://github.com/vitejs/vite/commits/v8.2.2/packages/vite">compare view</a></li> </ul> </details> <br /> --------- Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: Priya Raman <priya@paperclip.ing> Co-authored-by: Paperclip <noreply@paperclip.ing> |
||
|
|
4d2af732ae |
feat(runner): add native persistence contracts (#12169)
## Thinking Path > - Paperclip is the open source app people use to manage AI agents for work. > - Agent runs need durable records so Paperclip can explain results and final status changes. > - The current heartbeat tables support direct adapters, but they do not model native runner evidence. > - The runner transport and server coordinator must share a strict finalization contract before they write production data. > - This pull request adds that contract and its additive database boundary. > - It does not select the Paperclip Runner or change any existing adapter execution path. > - The benefit is a reviewable persistence layer that preserves all current behavior and supports later guarded integration. ## Linked Issues or Issue Description Refs #11962 Refs #12129 ## What Changed - Add native run result, finalization, completion, assessment, status decision, and status effect tables. - Add inert native metadata to heartbeat runs and events. Keep `legacy` as the default runtime mode. - Bind each evidence relationship to one company, issue, run, contract, result, assessment, and decision with composite constraints. - Add a strict `paperclip.native_finalization.v1` shared type and validator. - Preserve database functions, triggers, and the unique indexes required by foreign keys in JavaScript backups. - Add migration, backup, mixed-owner denial, validator, and direct-adapter compatibility tests. - Document the new records and their ownership rules. ## Verification - Run `pnpm -r typecheck`. - Run `pnpm build`. - Run `pnpm db:generate`. The schema output and migration safety checks remain current. - Run `PAPERCLIP_PSQL_PATH=/Applications/Postgres.app/Contents/Versions/latest/bin/psql pnpm exec vitest run packages/shared/src/validators/native-finalization.test.ts packages/db/src/client.test.ts packages/db/src/backup-lib.test.ts server/src/__tests__/heartbeat-workspace-busy.test.ts server/src/__tests__/heartbeat-comment-wake-batching.test.ts`. All 52 tests pass. - The full local `pnpm test:run` run completed 4,688 tests. It found 30 existing macOS test-environment failures. A serial rerun with the canonical `/private/tmp` path reduced those failures to six existing listener-diagnostics and skill-browser cases. None of those suites use files in this change. - The full Linux GitHub Actions matrix passes. This includes all general-server, serialized-server, workspace, browser, build, typecheck, canary, and aggregate verification jobs. - Greptile passes at 5/5. Contributor trust, Superagent, Socket, and Snyk pass with no finding from this change. - Storybook visual regression skips by path because this pull request has no UI or Storybook change. - Confirm that the diff contains 25 files. Confirm that it contains no workflow or `pnpm-lock.yaml` changes. ## Risks - The migration adds tables, columns, indexes, a function, a trigger, and ownership constraints. It does not remove or rename existing data. - Composite foreign keys reject mixed-company, mixed-issue, and mixed-run evidence even when each ID exists. - The status-version trigger runs only when an issue status changes. Backup tests confirm that restore retains this trigger and its dependencies. - Native source identifiers are unique when present. Legacy event rows remain unchanged. - This change does not add a unique run sequence constraint. The later native writer must allocate its sequence atomically before that invariant can be safe. - Existing adapters keep their current execution and finalization paths. New heartbeat runs default to `legacy` mode. > For core feature work, check [`ROADMAP.md`](ROADMAP.md) first and discuss it in `#dev` before opening the PR. Feature PRs that overlap with planned core work may need to be redirected — check the roadmap first. See `CONTRIBUTING.md`. ## Model Used - OpenAI Codex with GPT-5. The exact deployment ID and context-window size are not exposed. The model used agentic reasoning, repository tools, code execution, and test execution. ## Checklist - [x] I have included a thinking path that traces from project context to this change - [x] I have specified the model used (with version and capability details) - [x] I have checked ROADMAP.md and confirmed this PR does not duplicate planned core work - [x] I have searched GitHub for duplicate or related PRs and linked them above - [x] I have either (a) linked existing issues with `Fixes: #` / `Closes #` / `Refs #` OR (b) described the issue in-PR following the relevant issue template - [x] I have not referenced internal/instance-local Paperclip issues or links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip` URLs) - [x] My branch name describes the change (e.g. `docs/...`, `fix/...`) and contains no internal Paperclip ticket id or instance-derived details - [x] I have run tests locally and they pass - [x] I have added or updated tests where applicable - [x] I have updated relevant documentation to reflect my changes - [x] I have considered and documented any risks above - [x] All Paperclip CI gates are green - [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups - [x] I will address all Greptile and reviewer comments before requesting merge --------- Co-authored-by: Paperclip <noreply@paperclip.ing> |
||
|
|
0b01593602 |
build(deps): bump lucide-react from 0.577.0 to 1.32.0 (#11885)
Bumps [lucide-react](https://github.com/lucide-icons/lucide/tree/HEAD/packages/lucide-react) from 0.577.0 to 1.32.0. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/lucide-icons/lucide/releases">lucide-react's releases</a>.</em></p> <blockquote> <h2>Version 1.32.0</h2> <h2>What's Changed</h2> <ul> <li>feat(icons): added <code>car-battery</code> icon by <a href="https://github.com/andreynaz4renko"><code>@andreynaz4renko</code></a> in <a href="https://redirect.github.com/lucide-icons/lucide/pull/4088">lucide-icons/lucide#4088</a></li> <li>fix(categories): fixes emoji.json by <a href="https://github.com/karsa-mistmere"><code>@karsa-mistmere</code></a> in <a href="https://redirect.github.com/lucide-icons/lucide/pull/4697">lucide-icons/lucide#4697</a></li> <li>chore(deps): bump vue from 3.5.40 to 3.5.41 in the vue-deps group across 1 directory by <a href="https://github.com/dependabot"><code>@dependabot</code></a>[bot] in <a href="https://redirect.github.com/lucide-icons/lucide/pull/4695">lucide-icons/lucide#4695</a></li> <li>chore(dev): upgrade ESLint to latest compatible stack (v10) by <a href="https://github.com/ericfennis"><code>@ericfennis</code></a> with <a href="https://github.com/Copilot"><code>@Copilot</code></a> in <a href="https://redirect.github.com/lucide-icons/lucide/pull/4378">lucide-icons/lucide#4378</a></li> <li>feat(icons): add square-text by <a href="https://github.com/samuelalake"><code>@samuelalake</code></a> in <a href="https://redirect.github.com/lucide-icons/lucide/pull/4609">lucide-icons/lucide#4609</a></li> </ul> <h2>New Contributors</h2> <ul> <li><a href="https://github.com/andreynaz4renko"><code>@andreynaz4renko</code></a> made their first contribution in <a href="https://redirect.github.com/lucide-icons/lucide/pull/4088">lucide-icons/lucide#4088</a></li> </ul> <p><strong>Full Changelog</strong>: <a href="https://github.com/lucide-icons/lucide/compare/1.31.0...1.32.0">https://github.com/lucide-icons/lucide/compare/1.31.0...1.32.0</a></p> <h2>Version 1.31.0</h2> <h2>What's Changed</h2> <ul> <li>feat(icons): added <code>mail-badge</code> icon by <a href="https://github.com/lazerg"><code>@lazerg</code></a> in <a href="https://redirect.github.com/lucide-icons/lucide/pull/4638">lucide-icons/lucide#4638</a></li> <li>feat(icons): add angle by <a href="https://github.com/samuelalake"><code>@samuelalake</code></a> in <a href="https://redirect.github.com/lucide-icons/lucide/pull/4545">lucide-icons/lucide#4545</a></li> <li>feat(icons): added <code>eject</code> icon by <a href="https://github.com/ThibautMarechal"><code>@ThibautMarechal</code></a> in <a href="https://redirect.github.com/lucide-icons/lucide/pull/4043">lucide-icons/lucide#4043</a></li> </ul> <h2>New Contributors</h2> <ul> <li><a href="https://github.com/lazerg"><code>@lazerg</code></a> made their first contribution in <a href="https://redirect.github.com/lucide-icons/lucide/pull/4638">lucide-icons/lucide#4638</a></li> <li><a href="https://github.com/ThibautMarechal"><code>@ThibautMarechal</code></a> made their first contribution in <a href="https://redirect.github.com/lucide-icons/lucide/pull/4043">lucide-icons/lucide#4043</a></li> </ul> <p><strong>Full Changelog</strong>: <a href="https://github.com/lucide-icons/lucide/compare/1.30.0...1.31.0">https://github.com/lucide-icons/lucide/compare/1.30.0...1.31.0</a></p> <h2>Version 1.30.0</h2> <h2>What's Changed</h2> <ul> <li>chore(icons): refine & rename various emoji icons by <a href="https://github.com/karsa-mistmere"><code>@karsa-mistmere</code></a> in <a href="https://redirect.github.com/lucide-icons/lucide/pull/4606">lucide-icons/lucide#4606</a></li> <li>fix(scripts): removed toBeRemovedInVersion from all scripts and tools by <a href="https://github.com/karsa-mistmere"><code>@karsa-mistmere</code></a> in <a href="https://redirect.github.com/lucide-icons/lucide/pull/4674">lucide-icons/lucide#4674</a></li> <li>feat(icons): added <code>audio-lines-x</code> icon by <a href="https://github.com/karsa-mistmere"><code>@karsa-mistmere</code></a> in <a href="https://redirect.github.com/lucide-icons/lucide/pull/4590">lucide-icons/lucide#4590</a></li> <li>feat(lab): added <code>chinese-character</code> icon to lab by <a href="https://github.com/congemcd"><code>@congemcd</code></a> in <a href="https://redirect.github.com/lucide-icons/lucide/pull/4212">lucide-icons/lucide#4212</a></li> <li>test(packages): updates unit test snapshots with face-slightly-smiling by <a href="https://github.com/karsa-mistmere"><code>@karsa-mistmere</code></a> in <a href="https://redirect.github.com/lucide-icons/lucide/pull/4676">lucide-icons/lucide#4676</a></li> <li>ci(dev): fix post-release job by downloading lucide-font artifact by name by <a href="https://github.com/ericfennis"><code>@ericfennis</code></a> with <a href="https://github.com/Copilot"><code>@Copilot</code></a> in <a href="https://redirect.github.com/lucide-icons/lucide/pull/4675">lucide-icons/lucide#4675</a></li> <li>feat(icons): add shield-lock icon by <a href="https://github.com/Caisere"><code>@Caisere</code></a> in <a href="https://redirect.github.com/lucide-icons/lucide/pull/3508">lucide-icons/lucide#3508</a></li> <li>ci(security): Pin sha actions by <a href="https://github.com/jguddas"><code>@jguddas</code></a> in <a href="https://redirect.github.com/lucide-icons/lucide/pull/4678">lucide-icons/lucide#4678</a></li> <li>feat(icons): added <code>broom</code> icon by <a href="https://github.com/karsa-mistmere"><code>@karsa-mistmere</code></a> in <a href="https://redirect.github.com/lucide-icons/lucide/pull/4683">lucide-icons/lucide#4683</a></li> </ul> <h2>New Contributors</h2> <ul> <li><a href="https://github.com/congemcd"><code>@congemcd</code></a> made their first contribution in <a href="https://redirect.github.com/lucide-icons/lucide/pull/4212">lucide-icons/lucide#4212</a></li> <li><a href="https://github.com/Caisere"><code>@Caisere</code></a> made their first contribution in <a href="https://redirect.github.com/lucide-icons/lucide/pull/3508">lucide-icons/lucide#3508</a></li> </ul> <p><strong>Full Changelog</strong>: <a href="https://github.com/lucide-icons/lucide/compare/1.29.0...1.30.0">https://github.com/lucide-icons/lucide/compare/1.29.0...1.30.0</a></p> <h2>Version 1.29.0</h2> <h2>What's Changed</h2> <ul> <li>fix(<code>@lucide/lab</code>): Fix lab build by <a href="https://github.com/ericfennis"><code>@ericfennis</code></a> in <a href="https://redirect.github.com/lucide-icons/lucide/pull/4618">lucide-icons/lucide#4618</a></li> <li>feat(copilot): remove incorrect spaces clause from copilot instructions by <a href="https://github.com/karsa-mistmere"><code>@karsa-mistmere</code></a> in <a href="https://redirect.github.com/lucide-icons/lucide/pull/4623">lucide-icons/lucide#4623</a></li> <li>feat(docs): remove Super and Noodle from showcase by <a href="https://github.com/karsa-mistmere"><code>@karsa-mistmere</code></a> in <a href="https://redirect.github.com/lucide-icons/lucide/pull/4626">lucide-icons/lucide#4626</a></li> <li>chore(deps-dev): bump <code>@angular/platform-server</code> from 21.2.18 to 21.2.19 by <a href="https://github.com/dependabot"><code>@dependabot</code></a>[bot] in <a href="https://redirect.github.com/lucide-icons/lucide/pull/4629">lucide-icons/lucide#4629</a></li> <li>ci(security): improve security with adding permissions by <a href="https://github.com/ericfennis"><code>@ericfennis</code></a> in <a href="https://redirect.github.com/lucide-icons/lucide/pull/4619">lucide-icons/lucide#4619</a></li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/lucide-icons/lucide/commit/75b55160aa9edd7095dfed1a6e3d88e66fb2b153"><code>75b5516</code></a> chore(dev): upgrade ESLint to latest compatible stack (v10) (<a href="https://github.com/lucide-icons/lucide/tree/HEAD/packages/lucide-react/issues/4378">#4378</a>)</li> <li><a href="https://github.com/lucide-icons/lucide/commit/0f8d48b266e7af1e2bab49ff12ab6ec0795ed204"><code>0f8d48b</code></a> test(packages): updates unit test snapshots with face-slightly-smiling (<a href="https://github.com/lucide-icons/lucide/tree/HEAD/packages/lucide-react/issues/4676">#4676</a>)</li> <li><a href="https://github.com/lucide-icons/lucide/commit/f229f83f0c42f46befeac3cfd8ef7aaa82a71325"><code>f229f83</code></a> chore(depedencies): Update dependencies (<a href="https://github.com/lucide-icons/lucide/tree/HEAD/packages/lucide-react/issues/4553">#4553</a>)</li> <li><a href="https://github.com/lucide-icons/lucide/commit/5ff536e1391335e4f7dc38d244c1bc458b9443e2"><code>5ff536e</code></a> ci(release.yml): Fix workflow and remove <code>version</code> scripts in package scripts...</li> <li><a href="https://github.com/lucide-icons/lucide/commit/07c885e6c1f9952965ba388b7fd2bb7c4d416a67"><code>07c885e</code></a> fix(docs): fix zephyr-cloud URL in readmes</li> <li><a href="https://github.com/lucide-icons/lucide/commit/50d8af5a1012e188f3d71ac8f1fc0fba1aab5357"><code>50d8af5</code></a> docs(readme): Update readme files (<a href="https://github.com/lucide-icons/lucide/tree/HEAD/packages/lucide-react/issues/4320">#4320</a>)</li> <li><a href="https://github.com/lucide-icons/lucide/commit/653e44b83293567ff24dcb90ca1094a9cf0a042a"><code>653e44b</code></a> feat(packages): use .mjs for ESM bundles (<a href="https://github.com/lucide-icons/lucide/tree/HEAD/packages/lucide-react/issues/4285">#4285</a>)</li> <li><a href="https://github.com/lucide-icons/lucide/commit/7623e23f787fe78e5075a613fd22da2cecbb9b1b"><code>7623e23</code></a> feat(docs): add Zephyr Cloud to Hero Backers tier & rework updateSponsors scr...</li> <li><a href="https://github.com/lucide-icons/lucide/commit/dada0a82970d3733d1d716e2089591c538272a39"><code>dada0a8</code></a> fix(lucide-react): Fix dynamic imports (<a href="https://github.com/lucide-icons/lucide/tree/HEAD/packages/lucide-react/issues/4210">#4210</a>)</li> <li><a href="https://github.com/lucide-icons/lucide/commit/a6e648a66ff470c2255d3666765fd73cfcc185ff"><code>a6e648a</code></a> fix(lucide-react): correct client directives in RSC files (<a href="https://github.com/lucide-icons/lucide/tree/HEAD/packages/lucide-react/issues/4189">#4189</a>)</li> <li>Additional commits viewable in <a href="https://github.com/lucide-icons/lucide/commits/1.32.0/packages/lucide-react">compare view</a></li> </ul> </details> <br /> --------- Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: Priya Raman <priya@paperclip.ing> Co-authored-by: Paperclip <noreply@paperclip.ing> |
||
|
|
18ba239d85 |
build(deps): bump @pierre/diffs from 1.2.11 to 1.3.5 (#11875)
Bumps @pierre/diffs from 1.2.11 to 1.3.5. --------- Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: Priya Raman <priya@paperclip.ing> Co-authored-by: Paperclip <noreply@paperclip.ing> |
||
|
|
f64123ba4b |
build(deps-dev): bump @storybook/addon-docs from 10.5.8 to 10.5.10 (#11869)
Bumps [@storybook/addon-docs](https://github.com/storybookjs/storybook/tree/HEAD/code/addons/docs) from 10.5.8 to 10.5.10. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/storybookjs/storybook/releases">@storybook/addon-docs's releases</a>.</em></p> <blockquote> <h2>v10.5.10</h2> <h2>10.5.10</h2> <ul> <li>Core: Fetch static open-service snapshots relative to the document - <a href="https://redirect.github.com/storybookjs/storybook/pull/35945">#35945</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Core: Pin oxc-resolver to 11.21.2 to keep tsconfig path aliases on solution-style tsconfigs - <a href="https://redirect.github.com/storybookjs/storybook/pull/35929">#35929</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Dependencies: Bump Vitest to 4.1.6 (CVE-2026-47428) - <a href="https://redirect.github.com/storybookjs/storybook/pull/35530">#35530</a>, thanks <a href="https://github.com/anupamme"><code>@anupamme</code></a>!</li> <li>Docs: Declare the font on overlay surfaces so docs tooltips are not left to inherit - <a href="https://redirect.github.com/storybookjs/storybook/pull/35966">#35966</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>ESLint Plugin: Bundle CSF helpers so the plugin loads without storybook - <a href="https://redirect.github.com/storybookjs/storybook/pull/35950">#35950</a>, thanks <a href="https://github.com/ndelangen"><code>@ndelangen</code></a>!</li> <li>React: Preserve discriminated union prop values in metadata extraction - <a href="https://redirect.github.com/storybookjs/storybook/pull/35844">#35844</a>, thanks <a href="https://github.com/s-robertson"><code>@s-robertson</code></a>!</li> </ul> <h2>v10.5.9</h2> <h2>10.5.9</h2> <ul> <li>Addon-Pseudo-States: Fix pseudo-states rewriting for nested functional selectors - <a href="https://redirect.github.com/storybookjs/storybook/pull/34318">#34318</a>, thanks <a href="https://github.com/filipw01"><code>@filipw01</code></a>!</li> <li>Core: Skip module-graph reverse-index mirror when a patch is a no-op - <a href="https://redirect.github.com/storybookjs/storybook/pull/35825">#35825</a>, thanks <a href="https://github.com/ndelangen"><code>@ndelangen</code></a>!</li> <li>Core: Split module-graph into hot revisions and cold index services - <a href="https://redirect.github.com/storybookjs/storybook/pull/35831">#35831</a>, thanks <a href="https://github.com/ndelangen"><code>@ndelangen</code></a>!</li> <li>Preview: Fix crash when initialising UrlStore on a docs path - <a href="https://redirect.github.com/storybookjs/storybook/pull/35521">#35521</a>, thanks <a href="https://github.com/TheSeydiCharyyev"><code>@TheSeydiCharyyev</code></a>!</li> <li>Pseudo-States: Make stylesheet rewrites WebKit-safe - <a href="https://redirect.github.com/storybookjs/storybook/pull/35629">#35629</a>, thanks <a href="https://github.com/ethriel3695"><code>@ethriel3695</code></a>!</li> <li>TanStack: Keep the layout id when cloning a standalone index file route - <a href="https://redirect.github.com/storybookjs/storybook/pull/35660">#35660</a>, thanks <a href="https://github.com/Insik-Han"><code>@Insik-Han</code></a>!</li> <li>TanStack: Render real link hrefs in the Link mock - <a href="https://redirect.github.com/storybookjs/storybook/pull/35505">#35505</a>, thanks <a href="https://github.com/unpunnyfuns"><code>@unpunnyfuns</code></a>!</li> <li>Webpack: Prevent long preview output filenames - <a href="https://redirect.github.com/storybookjs/storybook/pull/35533">#35533</a>, thanks <a href="https://github.com/zhangli091011"><code>@zhangli091011</code></a>!</li> </ul> </blockquote> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/storybookjs/storybook/blob/next/CHANGELOG.md">@storybook/addon-docs's changelog</a>.</em></p> <blockquote> <h2>10.5.10</h2> <ul> <li>Core: Fetch static open-service snapshots relative to the document - <a href="https://redirect.github.com/storybookjs/storybook/pull/35945">#35945</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Core: Pin oxc-resolver to 11.21.2 to keep tsconfig path aliases on solution-style tsconfigs - <a href="https://redirect.github.com/storybookjs/storybook/pull/35929">#35929</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Dependencies: Bump Vitest to 4.1.6 (CVE-2026-47428) - <a href="https://redirect.github.com/storybookjs/storybook/pull/35530">#35530</a>, thanks <a href="https://github.com/anupamme"><code>@anupamme</code></a>!</li> <li>Docs: Declare the font on overlay surfaces so docs tooltips are not left to inherit - <a href="https://redirect.github.com/storybookjs/storybook/pull/35966">#35966</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>ESLint Plugin: Bundle CSF helpers so the plugin loads without storybook - <a href="https://redirect.github.com/storybookjs/storybook/pull/35950">#35950</a>, thanks <a href="https://github.com/ndelangen"><code>@ndelangen</code></a>!</li> <li>React: Preserve discriminated union prop values in metadata extraction - <a href="https://redirect.github.com/storybookjs/storybook/pull/35844">#35844</a>, thanks <a href="https://github.com/s-robertson"><code>@s-robertson</code></a>!</li> </ul> <h2>10.5.9</h2> <ul> <li>Addon-Pseudo-States: Fix pseudo-states rewriting for nested functional selectors - <a href="https://redirect.github.com/storybookjs/storybook/pull/34318">#34318</a>, thanks <a href="https://github.com/filipw01"><code>@filipw01</code></a>!</li> <li>Core: Skip module-graph reverse-index mirror when a patch is a no-op - <a href="https://redirect.github.com/storybookjs/storybook/pull/35825">#35825</a>, thanks <a href="https://github.com/ndelangen"><code>@ndelangen</code></a>!</li> <li>Core: Split module-graph into hot revisions and cold index services - <a href="https://redirect.github.com/storybookjs/storybook/pull/35831">#35831</a>, thanks <a href="https://github.com/ndelangen"><code>@ndelangen</code></a>!</li> <li>Preview: Fix crash when initialising UrlStore on a docs path - <a href="https://redirect.github.com/storybookjs/storybook/pull/35521">#35521</a>, thanks <a href="https://github.com/TheSeydiCharyyev"><code>@TheSeydiCharyyev</code></a>!</li> <li>Pseudo-States: Make stylesheet rewrites WebKit-safe - <a href="https://redirect.github.com/storybookjs/storybook/pull/35629">#35629</a>, thanks <a href="https://github.com/ethriel3695"><code>@ethriel3695</code></a>!</li> <li>TanStack: Keep the layout id when cloning a standalone index file route - <a href="https://redirect.github.com/storybookjs/storybook/pull/35660">#35660</a>, thanks <a href="https://github.com/Insik-Han"><code>@Insik-Han</code></a>!</li> <li>TanStack: Render real link hrefs in the Link mock - <a href="https://redirect.github.com/storybookjs/storybook/pull/35505">#35505</a>, thanks <a href="https://github.com/unpunnyfuns"><code>@unpunnyfuns</code></a>!</li> <li>Webpack: Prevent long preview output filenames - <a href="https://redirect.github.com/storybookjs/storybook/pull/35533">#35533</a>, thanks <a href="https://github.com/zhangli091011"><code>@zhangli091011</code></a>!</li> </ul> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/storybookjs/storybook/commit/a2db7526e1538a48bfa0529a881822e8074b2009"><code>a2db752</code></a> Bump version from "10.5.9" to "10.5.10" [skip ci]</li> <li><a href="https://github.com/storybookjs/storybook/commit/8f561048949b3ce3674a71711942177a14e4e8f9"><code>8f56104</code></a> Bump version from "10.5.8" to "10.5.9" [skip ci]</li> <li>See full diff in <a href="https://github.com/storybookjs/storybook/commits/v10.5.10/code/addons/docs">compare view</a></li> </ul> </details> <br /> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |
||
|
|
bef9288669 |
build(deps): bump @agentclientprotocol/claude-agent-acp from 0.69.0 to 0.70.0 (#11873)
Bumps [@agentclientprotocol/claude-agent-acp](https://github.com/agentclientprotocol/claude-agent-acp) from 0.69.0 to 0.70.0. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/agentclientprotocol/claude-agent-acp/releases">@agentclientprotocol/claude-agent-acp's releases</a>.</em></p> <blockquote> <h2>v0.70.0</h2> <h2><a href="https://github.com/agentclientprotocol/claude-agent-acp/compare/v0.69.0...v0.70.0">0.70.0</a> (2026-08-17)</h2> <h3>Features</h3> <ul> <li>switch providers for loaded Claude sessions (<a href="https://redirect.github.com/agentclientprotocol/claude-agent-acp/issues/1002">#1002</a>) (<a href="https://github.com/agentclientprotocol/claude-agent-acp/commit/50a95434e94318456f2d07c3d21aaf3595c3407d">50a9543</a>)</li> </ul> </blockquote> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/agentclientprotocol/claude-agent-acp/blob/main/CHANGELOG.md">@agentclientprotocol/claude-agent-acp's changelog</a>.</em></p> <blockquote> <h2><a href="https://github.com/agentclientprotocol/claude-agent-acp/compare/v0.69.0...v0.70.0">0.70.0</a> (2026-08-17)</h2> <h3>Features</h3> <ul> <li>switch providers for loaded Claude sessions (<a href="https://redirect.github.com/agentclientprotocol/claude-agent-acp/issues/1002">#1002</a>) (<a href="https://github.com/agentclientprotocol/claude-agent-acp/commit/50a95434e94318456f2d07c3d21aaf3595c3407d">50a9543</a>)</li> </ul> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/agentclientprotocol/claude-agent-acp/commit/d0aafb1ca26427285ffaeac8d8a4452fff28e9c3"><code>d0aafb1</code></a> chore(main): release 0.70.0 (<a href="https://redirect.github.com/agentclientprotocol/claude-agent-acp/issues/1010">#1010</a>)</li> <li><a href="https://github.com/agentclientprotocol/claude-agent-acp/commit/50a95434e94318456f2d07c3d21aaf3595c3407d"><code>50a9543</code></a> feat: switch providers for loaded Claude sessions (<a href="https://redirect.github.com/agentclientprotocol/claude-agent-acp/issues/1002">#1002</a>)</li> <li>See full diff in <a href="https://github.com/agentclientprotocol/claude-agent-acp/compare/v0.69.0...v0.70.0">compare view</a></li> </ul> </details> <br /> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>canary/v2026.825.0-canary.12 beta/v2026.825.0-beta.1 nightly/v2026.825.0-nightly.3 |
||
|
|
0286854db5 |
build(deps-dev): bump @storybook/react-vite from 10.5.8 to 10.5.10 (#11868)
Bumps [@storybook/react-vite](https://github.com/storybookjs/storybook/tree/HEAD/code/frameworks/react-vite) from 10.5.8 to 10.5.10. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/storybookjs/storybook/releases">@storybook/react-vite's releases</a>.</em></p> <blockquote> <h2>v10.5.10</h2> <h2>10.5.10</h2> <ul> <li>Core: Fetch static open-service snapshots relative to the document - <a href="https://redirect.github.com/storybookjs/storybook/pull/35945">#35945</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Core: Pin oxc-resolver to 11.21.2 to keep tsconfig path aliases on solution-style tsconfigs - <a href="https://redirect.github.com/storybookjs/storybook/pull/35929">#35929</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Dependencies: Bump Vitest to 4.1.6 (CVE-2026-47428) - <a href="https://redirect.github.com/storybookjs/storybook/pull/35530">#35530</a>, thanks <a href="https://github.com/anupamme"><code>@anupamme</code></a>!</li> <li>Docs: Declare the font on overlay surfaces so docs tooltips are not left to inherit - <a href="https://redirect.github.com/storybookjs/storybook/pull/35966">#35966</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>ESLint Plugin: Bundle CSF helpers so the plugin loads without storybook - <a href="https://redirect.github.com/storybookjs/storybook/pull/35950">#35950</a>, thanks <a href="https://github.com/ndelangen"><code>@ndelangen</code></a>!</li> <li>React: Preserve discriminated union prop values in metadata extraction - <a href="https://redirect.github.com/storybookjs/storybook/pull/35844">#35844</a>, thanks <a href="https://github.com/s-robertson"><code>@s-robertson</code></a>!</li> </ul> <h2>v10.5.9</h2> <h2>10.5.9</h2> <ul> <li>Addon-Pseudo-States: Fix pseudo-states rewriting for nested functional selectors - <a href="https://redirect.github.com/storybookjs/storybook/pull/34318">#34318</a>, thanks <a href="https://github.com/filipw01"><code>@filipw01</code></a>!</li> <li>Core: Skip module-graph reverse-index mirror when a patch is a no-op - <a href="https://redirect.github.com/storybookjs/storybook/pull/35825">#35825</a>, thanks <a href="https://github.com/ndelangen"><code>@ndelangen</code></a>!</li> <li>Core: Split module-graph into hot revisions and cold index services - <a href="https://redirect.github.com/storybookjs/storybook/pull/35831">#35831</a>, thanks <a href="https://github.com/ndelangen"><code>@ndelangen</code></a>!</li> <li>Preview: Fix crash when initialising UrlStore on a docs path - <a href="https://redirect.github.com/storybookjs/storybook/pull/35521">#35521</a>, thanks <a href="https://github.com/TheSeydiCharyyev"><code>@TheSeydiCharyyev</code></a>!</li> <li>Pseudo-States: Make stylesheet rewrites WebKit-safe - <a href="https://redirect.github.com/storybookjs/storybook/pull/35629">#35629</a>, thanks <a href="https://github.com/ethriel3695"><code>@ethriel3695</code></a>!</li> <li>TanStack: Keep the layout id when cloning a standalone index file route - <a href="https://redirect.github.com/storybookjs/storybook/pull/35660">#35660</a>, thanks <a href="https://github.com/Insik-Han"><code>@Insik-Han</code></a>!</li> <li>TanStack: Render real link hrefs in the Link mock - <a href="https://redirect.github.com/storybookjs/storybook/pull/35505">#35505</a>, thanks <a href="https://github.com/unpunnyfuns"><code>@unpunnyfuns</code></a>!</li> <li>Webpack: Prevent long preview output filenames - <a href="https://redirect.github.com/storybookjs/storybook/pull/35533">#35533</a>, thanks <a href="https://github.com/zhangli091011"><code>@zhangli091011</code></a>!</li> </ul> </blockquote> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/storybookjs/storybook/blob/next/CHANGELOG.md">@storybook/react-vite's changelog</a>.</em></p> <blockquote> <h2>10.5.10</h2> <ul> <li>Core: Fetch static open-service snapshots relative to the document - <a href="https://redirect.github.com/storybookjs/storybook/pull/35945">#35945</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Core: Pin oxc-resolver to 11.21.2 to keep tsconfig path aliases on solution-style tsconfigs - <a href="https://redirect.github.com/storybookjs/storybook/pull/35929">#35929</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Dependencies: Bump Vitest to 4.1.6 (CVE-2026-47428) - <a href="https://redirect.github.com/storybookjs/storybook/pull/35530">#35530</a>, thanks <a href="https://github.com/anupamme"><code>@anupamme</code></a>!</li> <li>Docs: Declare the font on overlay surfaces so docs tooltips are not left to inherit - <a href="https://redirect.github.com/storybookjs/storybook/pull/35966">#35966</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>ESLint Plugin: Bundle CSF helpers so the plugin loads without storybook - <a href="https://redirect.github.com/storybookjs/storybook/pull/35950">#35950</a>, thanks <a href="https://github.com/ndelangen"><code>@ndelangen</code></a>!</li> <li>React: Preserve discriminated union prop values in metadata extraction - <a href="https://redirect.github.com/storybookjs/storybook/pull/35844">#35844</a>, thanks <a href="https://github.com/s-robertson"><code>@s-robertson</code></a>!</li> </ul> <h2>10.5.9</h2> <ul> <li>Addon-Pseudo-States: Fix pseudo-states rewriting for nested functional selectors - <a href="https://redirect.github.com/storybookjs/storybook/pull/34318">#34318</a>, thanks <a href="https://github.com/filipw01"><code>@filipw01</code></a>!</li> <li>Core: Skip module-graph reverse-index mirror when a patch is a no-op - <a href="https://redirect.github.com/storybookjs/storybook/pull/35825">#35825</a>, thanks <a href="https://github.com/ndelangen"><code>@ndelangen</code></a>!</li> <li>Core: Split module-graph into hot revisions and cold index services - <a href="https://redirect.github.com/storybookjs/storybook/pull/35831">#35831</a>, thanks <a href="https://github.com/ndelangen"><code>@ndelangen</code></a>!</li> <li>Preview: Fix crash when initialising UrlStore on a docs path - <a href="https://redirect.github.com/storybookjs/storybook/pull/35521">#35521</a>, thanks <a href="https://github.com/TheSeydiCharyyev"><code>@TheSeydiCharyyev</code></a>!</li> <li>Pseudo-States: Make stylesheet rewrites WebKit-safe - <a href="https://redirect.github.com/storybookjs/storybook/pull/35629">#35629</a>, thanks <a href="https://github.com/ethriel3695"><code>@ethriel3695</code></a>!</li> <li>TanStack: Keep the layout id when cloning a standalone index file route - <a href="https://redirect.github.com/storybookjs/storybook/pull/35660">#35660</a>, thanks <a href="https://github.com/Insik-Han"><code>@Insik-Han</code></a>!</li> <li>TanStack: Render real link hrefs in the Link mock - <a href="https://redirect.github.com/storybookjs/storybook/pull/35505">#35505</a>, thanks <a href="https://github.com/unpunnyfuns"><code>@unpunnyfuns</code></a>!</li> <li>Webpack: Prevent long preview output filenames - <a href="https://redirect.github.com/storybookjs/storybook/pull/35533">#35533</a>, thanks <a href="https://github.com/zhangli091011"><code>@zhangli091011</code></a>!</li> </ul> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/storybookjs/storybook/commit/a2db7526e1538a48bfa0529a881822e8074b2009"><code>a2db752</code></a> Bump version from "10.5.9" to "10.5.10" [skip ci]</li> <li><a href="https://github.com/storybookjs/storybook/commit/8f561048949b3ce3674a71711942177a14e4e8f9"><code>8f56104</code></a> Bump version from "10.5.8" to "10.5.9" [skip ci]</li> <li>See full diff in <a href="https://github.com/storybookjs/storybook/commits/v10.5.10/code/frameworks/react-vite">compare view</a></li> </ul> </details> <br /> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |
||
|
|
5db8ce3c44 |
fix(docker): make tini PID 1 in the server image so adopted orphans are reaped (#12137)
## Thinking Path
> - Paperclip is the open source app people use to manage AI agents for
work
> - Agent runs execute inside the server container, and they spawn many
short-lived descendants: git, the adapter CLI, esbuild, sh
> - The server image sets `ENTRYPOINT ["docker-entrypoint.sh"]`, and
that entrypoint ends in `exec`, so node becomes PID 1
> - Node reaps only the children it spawned itself. It installs no
`SIGCHLD`/`waitpid` handler for orphans that the kernel re-parents onto
PID 1, so those orphans stay as zombies forever
> - Zombies accumulate monotonically. When the cgroup pid limit is
reached, every `fork()` in the container fails and the instance is dead
> - This pull request installs `tini` and makes it PID 1 in front of the
existing entrypoint, adds a behavioural test that proves reaping, and
adds a `pids_limit` backstop to both compose files
> - The benefit is that a long-running container no longer degrades into
total fork failure, and a future regression is caught by CI instead of
by an outage
Depends-on: none — this change is self-contained in the image build and
its tests, and it touches no other in-flight branch
## Linked Issues or Issue Description
No public GitHub issue exists for this defect. It was found on a live
long-running instance. Description follows the bug report template.
**What happened?**
The server container ran for 22 hours and reached 2039 of 2048 pids in
its cgroup. Of 1760 processes, 1731 were zombies, and all 1731 had PID 1
as their parent. PID 1 was `node --import
./server/node_modules/tsx/dist/loader.mjs server/dist/index.js`. Zombies
accrued at about 79 per hour and were never reaped. The oldest zombie
was 20.8 hours old against a container uptime of 22.0 hours, so nothing
had been reaped since boot. Once the pid limit was reached, `git` and
`gh` failed with `pthread_create failed: Resource temporarily
unavailable`.
**Expected behavior**
PID 1 reaps orphaned processes that the kernel re-parents onto it. The
pid count of a long-running container stays flat instead of growing
without bound.
**Steps to reproduce**
1. Start the server image without `docker run --init` and without `init:
true`.
2. Run agent work that spawns descendants which outlive their immediate
parent.
3. Read `/sys/fs/cgroup/pids.current` and count processes in `Z` state
over several hours.
4. The zombie count grows monotonically and every zombie has PPID 1.
**Relevant logs or output**
```
cgroup pids.current / pids.max : 2039 / 2048
total processes : 1760
zombies : 1731 (98.4%)
parent of every zombie : PID 1 (1731/1731)
PID 1 cmdline : node --import .../tsx/dist/loader.mjs server/dist/index.js
container uptime : 22.0 h
oldest zombie : 20.8 h median: 14.4 h
zombie names : git 717, claude 280, MainThread 167, sleep 141,
esbuild 138, postgres 76, sh 65, sccache 50
```
**Additional context**
The fix pattern is already in this repository.
`docker/agent-runtime/Dockerfile.base` installs `tini` and sets
`ENTRYPOINT ["/usr/bin/tini", "--"]`. It was never applied to the server
image.
## What Changed
- `Dockerfile`: install `tini` in the `base` stage and set `ENTRYPOINT
["/usr/bin/tini", "--", "docker-entrypoint.sh"]`. The entrypoint stays
in the exec chain, so UID/GID remapping, `gosu`, and graceful shutdown
are unchanged.
- `scripts/assert-orphan-reaping.sh` (new): a behavioural probe. It
spawns a leader that forks a grandchild, exits the leader, and asserts
that the orphaned grandchild leaves `Z` state instead of persisting. It
fails closed if the grandchild is not re-parented onto PID 1, so a pass
cannot mean the check ran too early.
- `.github/workflows/docker.yml`: run that probe against the pushed
image after the publish step. The publish step is multi-arch with `push:
true`, so nothing is loaded into the runner daemon and the pushed tag is
the only thing to test. The cloud variant is `FROM production` and
inherits the same `ENTRYPOINT`.
- `scripts/docker-build-test.sh`: run the same probe against a local
build.
- `docker/docker-compose.yml` and
`docker/docker-compose.quickstart.yml`: add `pids_limit: 2048` as a
backstop, so a future leak dies visibly at its own ceiling instead of
starving the host of pids.
- `server/src/__tests__/container-init-reaping.test.ts` (new): 13
assertions that guard the configuration the probe depends on.
No per-orchestrator init lever was added. The image owning PID 1 covers
compose, plain `docker run`, the quadlet units, and the ECS task
definition in one place. Adding `init: true` in compose or
`initProcessEnabled` on the ECS task would nest a second init around
`tini`, and `tini` then warns on every boot that it is not PID 1. The
new test asserts the absence of both levers across all three manifests,
so the decision survives the next edit.
## Verification
| Check | Result |
|---|---|
| `scripts/assert-orphan-reaping.sh` against a real init | Grandchild
re-parented to PPID 1, then reaped. Exit 0. |
| Same probe forced against a genuine zombie | Reports `Z` and fails.
The failure branch is not vacuous. |
| Config guard against the pre-fix files | Exactly the 3 relevant
assertions turn red. |
| Config guard with `tini` removed from `apt-get` but the comments kept
| Red. It checks the install, not a mention of the name. |
| `cd server && npx vitest run
src/__tests__/container-init-reaping.test.ts` | 13 passed |
| `npx tsc --noEmit -p server` | Clean |
| `node scripts/check-docker-deps-stage.mjs` | PASS |
| `node --test scripts/release-verify-workflow.test.mjs` | 8 passed |
Not verified locally: no container runtime is available in the authoring
environment, so the probe has not run against a build of this image. The
new `docker.yml` step runs it against the pushed image on this PR.
## Risks
Low risk, but it is an image and entrypoint change, so it affects
deployments.
- `tini` adds one small package to the `base` stage.
`docker/agent-runtime/Dockerfile.base` already installs it from the same
Debian archive.
- Signal handling changes shape: `tini` receives `SIGTERM` and forwards
it to the entrypoint, which `exec`s node. `tini` forwards signals to its
direct child by default, and the exec chain keeps node as that child, so
graceful shutdown is preserved. A reviewer should confirm this on a real
stop.
- `pids_limit: 2048` is new for compose users. A deployment that
legitimately needs more than 2048 processes would now hit the ceiling.
The measured steady state on a busy instance was under 400.
- If a deployment already passes `--init` or `init: true`, `tini` runs
under another init and prints a warning that it is not PID 1. Reaping
still works because the outer init handles it. The compose files in this
repository do not set `init: true`.
## Model Used
Claude Opus 5 (`claude-opus-5`), extended thinking, with tool use and
code execution in an agent harness.
## Checklist
- [x] I have included a thinking path that traces from project context
to this change
- [x] I have specified the model used (with version and capability
details)
- [x] I have checked ROADMAP.md and confirmed this PR does not duplicate
planned core work
- [x] I have searched GitHub for duplicate or related PRs and linked
them above
- [x] I have either (a) linked existing issues with `Fixes: #` / `Closes
#` / `Refs #` OR (b) described the issue in-PR following the relevant
issue template
- [x] I have not referenced internal/instance-local issues or links
- [x] My branch name describes the change and contains no internal
ticket id or instance-derived details
- [x] I have run tests locally and they pass
- [x] I have added or updated tests where applicable
- [x] I have updated relevant documentation to reflect my changes
- [x] I have considered and documented any risks above
- [x] All CI gates are green
- [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups
- [x] I will address all Greptile and reviewer comments before
requesting merge
---------
Co-authored-by: zannis <1011451+zannis@users.noreply.github.com>
canary/v2026.825.0-canary.11
|
||
|
|
3a841e15d0 |
build(deps-dev): bump @types/supertest from 6.0.3 to 7.2.1 (#11878)
Bumps [@types/supertest](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/supertest) from 6.0.3 to 7.2.1. <details> <summary>Commits</summary> <ul> <li>See full diff in <a href="https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/supertest">compare view</a></li> </ul> </details> <br /> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |
||
|
|
3c328a7726 |
build(deps): bump @mdxeditor/editor from 3.55.0 to 4.2.1 (#11870)
Bumps [@mdxeditor/editor](https://github.com/mdx-editor/editor) from 3.55.0 to 4.2.1. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/mdx-editor/editor/releases">@mdxeditor/editor's releases</a>.</em></p> <blockquote> <h2>v4.2.1</h2> <h2><a href="https://github.com/mdx-editor/editor/compare/v4.2.0...v4.2.1">4.2.1</a> (2026-08-21)</h2> <h3>Bug Fixes</h3> <ul> <li>upgrade js-yaml to 4.3.1 to resolve GHSA-5p4m-2wfm-xmqj (<a href="https://github.com/mdx-editor/editor/commit/3ff7296ffddcba1c60245c3ca27005b642f8b3c7">3ff7296</a>)</li> </ul> <h2>v4.2.0</h2> <h1><a href="https://github.com/mdx-editor/editor/compare/v4.1.1...v4.2.0">4.2.0</a> (2026-08-02)</h1> <h3>Bug Fixes</h3> <ul> <li>declare the frontmatter node as a block-level decorator (<a href="https://github.com/mdx-editor/editor/commit/ebc4755212f643db5b6fb11d4e0418baad920200">ebc4755</a>), closes <a href="https://redirect.github.com/mdx-editor/editor/issues/957">#957</a></li> <li>support links on selected images (<a href="https://github.com/mdx-editor/editor/commit/d8c442b69fa030bac6e451447aa7a8510a6dec9a">d8c442b</a>), closes <a href="https://redirect.github.com/mdx-editor/editor/issues/753">#753</a></li> </ul> <h3>Features</h3> <ul> <li>mdxeditor-full-height opt-in class for editors that fill their parent (<a href="https://github.com/mdx-editor/editor/commit/cdeda5847e8d3ac319c1439fdfae3d8c2c93c2ef">cdeda58</a>), closes <a href="https://redirect.github.com/mdx-editor/editor/issues/953">#953</a></li> </ul> <h2>v4.1.1</h2> <h2><a href="https://github.com/mdx-editor/editor/compare/v4.1.0...v4.1.1">4.1.1</a> (2026-07-29)</h2> <h3>Bug Fixes</h3> <ul> <li>clear resolvable security audit findings in the dev dependency tree (<a href="https://github.com/mdx-editor/editor/commit/117dd849879b8917bfdb10d1d7cec709510b219c">117dd84</a>)</li> <li>respect configured heading shortcuts (<a href="https://github.com/mdx-editor/editor/commit/beacb4c3c21f572d34ec223dffcb1ec0be248771">beacb4c</a>)</li> </ul> <h2>v4.1.0</h2> <h1><a href="https://github.com/mdx-editor/editor/compare/v4.0.4...v4.1.0">4.1.0</a> (2026-07-19)</h1> <h3>Bug Fixes</h3> <ul> <li>harden Lexical adoption lifecycle edges (<a href="https://github.com/mdx-editor/editor/commit/859bf459af165897652105e0aaa4f20fea0f162f">859bf45</a>)</li> <li>pass Playwright install flags through npm (<a href="https://github.com/mdx-editor/editor/commit/0b2d19b3bfffe2ffd2b98b9bb43820fb2148c0b4">0b2d19b</a>)</li> <li>remove stray Realm provider token (<a href="https://github.com/mdx-editor/editor/commit/c432da3a838fbc9ab4c1e09df892f10ce50e6e01">c432da3</a>)</li> </ul> <h3>Features</h3> <ul> <li>adopt Lexical 0.48 with compatibility gates (<a href="https://github.com/mdx-editor/editor/commit/90a1466d5e675ffaca75b45a1cac75bcac222e09">90a1466</a>)</li> <li>export Markdown from the active selection (<a href="https://github.com/mdx-editor/editor/commit/a7c3baee1cced1307a17870e4524679e734039c2">a7c3bae</a>)</li> <li>make search replacement state-backed (<a href="https://github.com/mdx-editor/editor/commit/b108652c552920e88a1af55fe5c0b4fc220823f2">b108652</a>)</li> </ul> <h2>v4.0.4</h2> <h2><a href="https://github.com/mdx-editor/editor/compare/v4.0.3...v4.0.4">4.0.4</a> (2026-06-18)</h2> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/mdx-editor/editor/commit/3ff7296ffddcba1c60245c3ca27005b642f8b3c7"><code>3ff7296</code></a> fix: upgrade js-yaml to 4.3.1 to resolve GHSA-5p4m-2wfm-xmqj</li> <li><a href="https://github.com/mdx-editor/editor/commit/b5bc01b2c94c8a997238b89ced7ca9091e915454"><code>b5bc01b</code></a> Merge pull request <a href="https://redirect.github.com/mdx-editor/editor/issues/959">#959</a> from alexander-neuschl-tu-dresden-de/patch-1</li> <li><a href="https://github.com/mdx-editor/editor/commit/b607c8ce2d88ce582ea933615dd8d67bb6dcbb8a"><code>b607c8c</code></a> Update package-lock.json for js-yaml 4.3.1</li> <li><a href="https://github.com/mdx-editor/editor/commit/dda0c61c0b4f2aaea622b8c8017a68c491575ee7"><code>dda0c61</code></a> Upgrade js-yaml to 4.3.1 to resolve high vulnerability</li> <li><a href="https://github.com/mdx-editor/editor/commit/d8c442b69fa030bac6e451447aa7a8510a6dec9a"><code>d8c442b</code></a> fix: support links on selected images</li> <li><a href="https://github.com/mdx-editor/editor/commit/cdeda5847e8d3ac319c1439fdfae3d8c2c93c2ef"><code>cdeda58</code></a> feat: mdxeditor-full-height opt-in class for editors that fill their parent</li> <li><a href="https://github.com/mdx-editor/editor/commit/ebc4755212f643db5b6fb11d4e0418baad920200"><code>ebc4755</code></a> fix: declare the frontmatter node as a block-level decorator</li> <li><a href="https://github.com/mdx-editor/editor/commit/117dd849879b8917bfdb10d1d7cec709510b219c"><code>117dd84</code></a> fix: clear resolvable security audit findings in the dev dependency tree</li> <li><a href="https://github.com/mdx-editor/editor/commit/88b7545e5d7095d526eb1c79e660db157848e583"><code>88b7545</code></a> Merge branch 'pr-954'</li> <li><a href="https://github.com/mdx-editor/editor/commit/2b1af77dffc69806d94c8b72c9d1e8fd3e4f99cd"><code>2b1af77</code></a> Merge pull request <a href="https://redirect.github.com/mdx-editor/editor/issues/952">#952</a> from 11suixing11/fix/allowed-heading-shortcuts</li> <li>Additional commits viewable in <a href="https://github.com/mdx-editor/editor/compare/v3.55.0...v4.2.1">compare view</a></li> </ul> </details> <br /> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |
||
|
|
1d3195bfcd |
build(deps-dev): bump esbuild from 0.28.1 to 0.28.2 (#11882)
Bumps [esbuild](https://github.com/evanw/esbuild) from 0.28.1 to 0.28.2. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/evanw/esbuild/releases">esbuild's releases</a>.</em></p> <blockquote> <h2>v0.28.2</h2> <ul> <li> <p>Fix tree shaking bug due to TypeScript import alias (<a href="https://redirect.github.com/evanw/esbuild/issues/4507">#4507</a>)</p> <p>This release fixes a bug that could cause esbuild to incorrectly tree-shake imports that are used in a TypeScript type alias under certain circumstances. Affected code uses a TypeScript-specific <code>import</code> assignment and looks something like this:</p> <pre lang="ts"><code>import Base from './dep.js'; import Alias = Base.SomeType; </code></pre> </li> <li> <p>Fix CSS minification bug involving <code>&</code> (<a href="https://redirect.github.com/evanw/esbuild/issues/4497">#4497</a>)</p> <p>This release fixes a bug where esbuild's CSS minifier incorrectly removed a <code>&</code> when it was unsafe to do so. Here is an example:</p> <pre lang="css"><code>/* Original code */ .a .b { & .b:not(& .c) { color: red; } } <p>/* Old output (with --minify) */<br /> .a .b{.b:not(& .c){color:red}}</p> <p>/* New output (with --minify) */<br /> .a .b{& .b:not(& .c){color:red}}<br /> </code></pre></p> <p>This should match <code><span class="a"><span class="b"><span class="b">yes</span></span></span></code> but not <code><span class="a"><span class="b">no</span></span></code>. The old output incorrectly matched both.</p> </li> <li> <p>Avoid overwriting input files without <code>--allow-overwrite</code> (<a href="https://redirect.github.com/evanw/esbuild/issues/4484">#4484</a>)</p> <p>For example: <code>esbuild input.js --outfile=input.js</code> tells esbuild to overwrite <code>input.js</code> with the output of running esbuild on it. This was supposed to already be prevented by default, but it accidentally regressed in version 0.17.0 and apparently didn't have any test coverage. The error message was being printed but the input file was still being overwritten. Oops.</p> <p>This release puts the original behavior back. With this release, esbuild should now actually avoid overwriting input files unless <code>--allow-overwrite</code> is explicitly present. This is done by not writing out any files when a build error is encountered.</p> </li> <li> <p>Fix incorrect code generated when using top-level await (<a href="https://redirect.github.com/evanw/esbuild/issues/4498">#4498</a>)</p> <p>Previously esbuild could generate code containing a syntax error in complex scenarios involving top-level await used in a dependency cycle. The problem was a missing <code>async</code> on one or more module wrapper closures. With this release, esbuild now uses a fixed-point iteration algorithm to correctly annotate all dependencies in the cycle as needing an <code>async</code> module wrapper.</p> </li> <li> <p>Fix a minification bug with lowered logical assignment operators (<a href="https://redirect.github.com/evanw/esbuild/issues/4508">#4508</a>)</p> <p>This release fixes a bug that could cause esbuild to generate incorrect code for logical assignment operators when lowering them to an older target environment. Specifically the lowering process requires duplicating the left-hand side, but esbuild incorrectly failed to count the duplicate as a new usage when the left-hand side is an identifier. That then caused the minifier to believe that the left-hand side was only used once and could attempt to incorrectly inline an initializer into the first usage. This bug has now been fixed:</p> <pre lang="js"><code>// Original code function foo() { let x bar(x ||= {}) </code></pre> </li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/evanw/esbuild/blob/main/CHANGELOG.md">esbuild's changelog</a>.</em></p> <blockquote> <h2>0.28.2</h2> <ul> <li> <p>Fix tree shaking bug due to TypeScript import alias (<a href="https://redirect.github.com/evanw/esbuild/issues/4507">#4507</a>)</p> <p>This release fixes a bug that could cause esbuild to incorrectly tree-shake imports that are used in a TypeScript type alias under certain circumstances. Affected code uses a TypeScript-specific <code>import</code> assignment and looks something like this:</p> <pre lang="ts"><code>import Base from './dep.js'; import Alias = Base.SomeType; </code></pre> </li> <li> <p>Fix CSS minification bug involving <code>&</code> (<a href="https://redirect.github.com/evanw/esbuild/issues/4497">#4497</a>)</p> <p>This release fixes a bug where esbuild's CSS minifier incorrectly removed a <code>&</code> when it was unsafe to do so. Here is an example:</p> <pre lang="css"><code>/* Original code */ .a .b { & .b:not(& .c) { color: red; } } <p>/* Old output (with --minify) */<br /> .a .b{.b:not(& .c){color:red}}</p> <p>/* New output (with --minify) */<br /> .a .b{& .b:not(& .c){color:red}}<br /> </code></pre></p> <p>This should match <code><span class="a"><span class="b"><span class="b">yes</span></span></span></code> but not <code><span class="a"><span class="b">no</span></span></code>. The old output incorrectly matched both.</p> </li> <li> <p>Avoid overwriting input files without <code>--allow-overwrite</code> (<a href="https://redirect.github.com/evanw/esbuild/issues/4484">#4484</a>)</p> <p>For example: <code>esbuild input.js --outfile=input.js</code> tells esbuild to overwrite <code>input.js</code> with the output of running esbuild on it. This was supposed to already be prevented by default, but it accidentally regressed in version 0.17.0 and apparently didn't have any test coverage. The error message was being printed but the input file was still being overwritten. Oops.</p> <p>This release puts the original behavior back. With this release, esbuild should now actually avoid overwriting input files unless <code>--allow-overwrite</code> is explicitly present. This is done by not writing out any files when a build error is encountered.</p> </li> <li> <p>Fix incorrect code generated when using top-level await (<a href="https://redirect.github.com/evanw/esbuild/issues/4498">#4498</a>)</p> <p>Previously esbuild could generate code containing a syntax error in complex scenarios involving top-level await used in a dependency cycle. The problem was a missing <code>async</code> on one or more module wrapper closures. With this release, esbuild now uses a fixed-point iteration algorithm to correctly annotate all dependencies in the cycle as needing an <code>async</code> module wrapper.</p> </li> <li> <p>Fix a minification bug with lowered logical assignment operators (<a href="https://redirect.github.com/evanw/esbuild/issues/4508">#4508</a>)</p> <p>This release fixes a bug that could cause esbuild to generate incorrect code for logical assignment operators when lowering them to an older target environment. Specifically the lowering process requires duplicating the left-hand side, but esbuild incorrectly failed to count the duplicate as a new usage when the left-hand side is an identifier. That then caused the minifier to believe that the left-hand side was only used once and could attempt to incorrectly inline an initializer into the first usage. This bug has now been fixed:</p> <pre lang="js"><code>// Original code function foo() { let x </code></pre> </li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/evanw/esbuild/commit/609683d892977362a0f99026cb74b96263d728a9"><code>609683d</code></a> publish 0.28.2 to npm</li> <li><a href="https://github.com/evanw/esbuild/commit/11b1fe48df6859393d9469f323b5ebd17baaf989"><code>11b1fe4</code></a> add to release notes</li> <li><a href="https://github.com/evanw/esbuild/commit/ab50d91559a27e54cd0a27a403389130ea10d97d"><code>ab50d91</code></a> css: fix green/blue channel swap in oklch gamut mapping (<a href="https://redirect.github.com/evanw/esbuild/issues/4488">#4488</a>)</li> <li><a href="https://github.com/evanw/esbuild/commit/04627b6cf99b4a7491bebb0268173a7c77a85030"><code>04627b6</code></a> fix <a href="https://redirect.github.com/evanw/esbuild/issues/4498">#4498</a>: <code>async</code> TLA checks need a worklist</li> <li><a href="https://github.com/evanw/esbuild/commit/5c15177a308c7224604058a769c4abf0a66b0a36"><code>5c15177</code></a> disable <code>gopls</code> in the <code>go</code> folder</li> <li><a href="https://github.com/evanw/esbuild/commit/fc2ee9babc5a2e8ea7ec7c10dd5850b71f7cec7e"><code>fc2ee9b</code></a> css: adjust parser to allow <code>--foo: {...}</code></li> <li><a href="https://github.com/evanw/esbuild/commit/209db54371e62ad1c50e12e56bb93c74c53b0408"><code>209db54</code></a> release notes for css nesting bugfix</li> <li><a href="https://github.com/evanw/esbuild/commit/c625d31bf08a0647ec724bf76c7115f7aec55971"><code>c625d31</code></a> fix <a href="https://redirect.github.com/evanw/esbuild/issues/4497">#4497</a>: preserve nested ampersands during minification (<a href="https://redirect.github.com/evanw/esbuild/issues/4500">#4500</a>)</li> <li><a href="https://github.com/evanw/esbuild/commit/34474e278528a60f58c959c0f422d2bfa6f6886d"><code>34474e2</code></a> better isolation of current part in js parser</li> <li><a href="https://github.com/evanw/esbuild/commit/07f6e8c50677e0b41e5ed726c08b0ea200b14e5b"><code>07f6e8c</code></a> fix <a href="https://redirect.github.com/evanw/esbuild/issues/4507">#4507</a>: <code>import</code> assignment tree-shaking bug</li> <li>Additional commits viewable in <a href="https://github.com/evanw/esbuild/compare/v0.28.1...v0.28.2">compare view</a></li> </ul> </details> <br /> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |
||
|
|
ab4c4941f2 |
build(deps): bump @aws-sdk/client-s3 from 3.1111.0 to 3.1115.0 (#11876)
Bumps [@aws-sdk/client-s3](https://github.com/aws/aws-sdk-js-v3/tree/HEAD/clients/client-s3) from 3.1111.0 to 3.1115.0. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/aws/aws-sdk-js-v3/releases">@aws-sdk/client-s3's releases</a>.</em></p> <blockquote> <h2>v3.1115.0</h2> <h4>3.1115.0(2026-08-20)</h4> <h5>Documentation Changes</h5> <ul> <li><strong>client-pricing-plan-manager:</strong> Documentation update for the CreateSubscription API to correct the default value of the approval mode parameter. The default value for paid subscriptions is MANUAL, not IMMEDIATE as previously documented. The default value remains IMMEDIATE for FREE tier subscriptions. (<a href="https://github.com/aws/aws-sdk-js-v3/commit/50d16ae3f271fe02a775de35ff81f96c3fc3f3f5">50d16ae3</a>)</li> </ul> <h5>New Features</h5> <ul> <li><strong>client-sesv2:</strong> Amazon SES now supports per-message tracking overrides. You can use the new ConfigurationOverrides parameter in SendEmail and SendBulkEmail to enable or disable open and click tracking for individual messages without changing your account-level or configuration set settings. (<a href="https://github.com/aws/aws-sdk-js-v3/commit/da56caa551406c67f4add96bcb7a98ac9ad9ec5d">da56caa5</a>)</li> <li><strong>client-arc-region-switch:</strong> Adds support for Rds switchover read replica for Oracle databases in Region switch plans (<a href="https://github.com/aws/aws-sdk-js-v3/commit/85ffb20a7857736b13916df32017903c6fd0b3e0">85ffb20a</a>)</li> <li><strong>client-ec2:</strong> EC2 marks UEFI instance metadata field as sensitive. (<a href="https://github.com/aws/aws-sdk-js-v3/commit/c232746ad78da7961a997005c6102943c392c30c">c232746a</a>)</li> <li><strong>client-direct-connect:</strong> This release adds custom route prefix pool allocations for Direct Connect. You can set IPv4 and IPv6 route prefix counts on private and transit virtual interfaces, and view pool size and unallocated counts on connections and LAGs, plus direct connect gateway attachment prefix allocation totals. (<a href="https://github.com/aws/aws-sdk-js-v3/commit/a94fb9783b97be5c59ef543ea7448d0e09f6f048">a94fb978</a>)</li> <li><strong>client-amplify:</strong> Increased the maximum allowed length from 255 to 4,096 characters to support longer access tokens. (<a href="https://github.com/aws/aws-sdk-js-v3/commit/f7f8ecd1b8b45ba69bb48d1ac61a5bafc2a2d672">f7f8ecd1</a>)</li> <li><strong>client-batch:</strong> AWS Batch now supports a new compute environment type that provides fully managed EC2 capacity with broader compute flexibility than Fargate, including GPU instances, bare metal, and specific instance type selection, without infrastructure management overhead. (<a href="https://github.com/aws/aws-sdk-js-v3/commit/9c559a7366166cbe4e81c2752eb1c26696a884a9">9c559a73</a>)</li> <li><strong>client-sagemaker:</strong> Added IAM Identity Center (IdC) support to CreatePartnerApp and UpdatePartnerApp APIs. Added Customer Managed Key (CMK) support to CreateMlflowApp and DescribeMlflowApp. (<a href="https://github.com/aws/aws-sdk-js-v3/commit/5548588739d30ba5b7ebf1c6a88fa5749adb15b0">55485887</a>)</li> <li><strong>client-lambda:</strong> Adds support for full JSON resource-based policies, enabling customers to create, retrieve, update, and delete function resource policies as complete JSON documents. (<a href="https://github.com/aws/aws-sdk-js-v3/commit/72573a2ad860a406a0fe742dfd40b50458b6153d">72573a2a</a>)</li> <li><strong>client-cloudfront:</strong> Added SigV4a as a supported signing protocol for Origin Access Control (OAC), enabling CloudFront to sign requests to Amazon S3 Multi-Region Access Point (S3-MRAP) origins. (<a href="https://github.com/aws/aws-sdk-js-v3/commit/95476293d5fa70f266cb4aa4c54ecebce9c771ce">95476293</a>)</li> </ul> <hr /> <p>For list of updated packages, view <strong>updated-packages.md</strong> in <strong>assets-3.1115.0.zip</strong></p> <h2>v3.1114.0</h2> <h4>3.1114.0(2026-08-19)</h4> <h5>New Features</h5> <ul> <li><strong>client-eks:</strong> Adds support for EKS cluster certificate authorities (CA) (<a href="https://github.com/aws/aws-sdk-js-v3/commit/a1316eaec0734d880bdb975c082110f36d3d7180">a1316eae</a>)</li> <li><strong>client-bedrock-agentcore-control:</strong> AgentCore Memory now supports Flexible Namespaces (<a href="https://github.com/aws/aws-sdk-js-v3/commit/65c89d6d82897e07d0d671fbd0a3a0a44a93a9a2">65c89d6d</a>)</li> <li><strong>client-batch:</strong> AWS Batch now supports managing CloudWatch Container Insights on compute environments via CreateComputeEnvironment and UpdateComputeEnvironment. (<a href="https://github.com/aws/aws-sdk-js-v3/commit/f77fc37f101238d66a1849924da42be3ac50f4c5">f77fc37f</a>)</li> <li><strong>client-redshift:</strong> Amazon Redshift enhanced System Table retention that allows customers to store their system table data directly in S3 Tables in customer's account instead of Redshift Managed Storage (<a href="https://github.com/aws/aws-sdk-js-v3/commit/a46d1f96345459f8c606642be702b8a723d97d51">a46d1f96</a>)</li> <li><strong>client-bedrock-agentcore:</strong> AgentCore Memory now supports Flexible Namespaces and Non-Conversational Payloads in CreateEvent API (<a href="https://github.com/aws/aws-sdk-js-v3/commit/a0d8fb6df9d13bd1f22f89c1a5defef183becaf4">a0d8fb6d</a>)</li> <li><strong>client-medialive:</strong> AWS Elemental MediaLive now supports video cropping and output positioning. Use cropRectangle and outputPositionRectangle to position the encoded video within the output frame, with the surrounding area filled with black. (<a href="https://github.com/aws/aws-sdk-js-v3/commit/2bf1331a81cddad987b30380c685cc3b4f85f18b">2bf1331a</a>)</li> <li><strong>client-account-access:</strong> Adds throttling exceptions to operation outputs that were previously inconsistent with other operations. (<a href="https://github.com/aws/aws-sdk-js-v3/commit/1e39b38544c7b77246db936bc6313163f98718b9">1e39b385</a>)</li> <li><strong>client-vpc-lattice:</strong> Amazon VPC Lattice now supports modification of private DNS options on Service Network VPC Associations (<a href="https://github.com/aws/aws-sdk-js-v3/commit/92c89b2723c281f6fc8d2562ec86dbd3c9716bdf">92c89b27</a>)</li> <li><strong>client-redshift-serverless:</strong> Amazon Redshift Enhanced System Table Retention that allows customers to store their system table data directly in S3 Tables in customer's account instead of Redshift Managed Storage (<a href="https://github.com/aws/aws-sdk-js-v3/commit/73ad53c311578c41c4420d71835f63ff021b703a">73ad53c3</a>)</li> <li><strong>lib-transfer-manager:</strong> add file based download api and worker thread based download. (<a href="https://redirect.github.com/aws/aws-sdk-js-v3/pull/8259">#8259</a>) (<a href="https://github.com/aws/aws-sdk-js-v3/commit/b2d60357c87e86ce7da8902c9bd243bcc3bb34b2">b2d60357</a>)</li> </ul> <hr /> <p>For list of updated packages, view <strong>updated-packages.md</strong> in <strong>assets-3.1114.0.zip</strong></p> <h2>v3.1113.0</h2> <h4>3.1113.0(2026-08-18)</h4> <h5>Chores</h5> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/aws/aws-sdk-js-v3/blob/main/clients/client-s3/CHANGELOG.md">@aws-sdk/client-s3's changelog</a>.</em></p> <blockquote> <h1><a href="https://github.com/aws/aws-sdk-js-v3/compare/v3.1114.0...v3.1115.0">3.1115.0</a> (2026-08-20)</h1> <p><strong>Note:</strong> Version bump only for package <code>@aws-sdk/client-s3</code></p> <h1><a href="https://github.com/aws/aws-sdk-js-v3/compare/v3.1113.0...v3.1114.0">3.1114.0</a> (2026-08-19)</h1> <p><strong>Note:</strong> Version bump only for package <code>@aws-sdk/client-s3</code></p> <h1><a href="https://github.com/aws/aws-sdk-js-v3/compare/v3.1112.0...v3.1113.0">3.1113.0</a> (2026-08-18)</h1> <p><strong>Note:</strong> Version bump only for package <code>@aws-sdk/client-s3</code></p> <h1><a href="https://github.com/aws/aws-sdk-js-v3/compare/v3.1111.0...v3.1112.0">3.1112.0</a> (2026-08-17)</h1> <p><strong>Note:</strong> Version bump only for package <code>@aws-sdk/client-s3</code></p> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/aws/aws-sdk-js-v3/commit/efc86fc9c3f80861228ad7f1b2fc97084b7a1c20"><code>efc86fc</code></a> Publish v3.1115.0</li> <li><a href="https://github.com/aws/aws-sdk-js-v3/commit/5318b44c47c47e50ee77d6d8044cf8a472d2d08f"><code>5318b44</code></a> Publish v3.1114.0</li> <li><a href="https://github.com/aws/aws-sdk-js-v3/commit/73a06d2aeb7261977dbffd4f604a6dafc3c2d381"><code>73a06d2</code></a> Publish v3.1113.0</li> <li><a href="https://github.com/aws/aws-sdk-js-v3/commit/cb4ae7624bd56b21e127496f9641912b1a5a8ce2"><code>cb4ae76</code></a> Publish v3.1112.0</li> <li>See full diff in <a href="https://github.com/aws/aws-sdk-js-v3/commits/v3.1115.0/clients/client-s3">compare view</a></li> </ul> </details> <br /> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |
||
|
|
a68af9ed9c |
build(deps-dev): bump @storybook/addon-a11y from 10.5.8 to 10.5.10 (#11874)
Bumps [@storybook/addon-a11y](https://github.com/storybookjs/storybook/tree/HEAD/code/addons/a11y) from 10.5.8 to 10.5.10. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/storybookjs/storybook/releases">@storybook/addon-a11y's releases</a>.</em></p> <blockquote> <h2>v10.5.10</h2> <h2>10.5.10</h2> <ul> <li>Core: Fetch static open-service snapshots relative to the document - <a href="https://redirect.github.com/storybookjs/storybook/pull/35945">#35945</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Core: Pin oxc-resolver to 11.21.2 to keep tsconfig path aliases on solution-style tsconfigs - <a href="https://redirect.github.com/storybookjs/storybook/pull/35929">#35929</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Dependencies: Bump Vitest to 4.1.6 (CVE-2026-47428) - <a href="https://redirect.github.com/storybookjs/storybook/pull/35530">#35530</a>, thanks <a href="https://github.com/anupamme"><code>@anupamme</code></a>!</li> <li>Docs: Declare the font on overlay surfaces so docs tooltips are not left to inherit - <a href="https://redirect.github.com/storybookjs/storybook/pull/35966">#35966</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>ESLint Plugin: Bundle CSF helpers so the plugin loads without storybook - <a href="https://redirect.github.com/storybookjs/storybook/pull/35950">#35950</a>, thanks <a href="https://github.com/ndelangen"><code>@ndelangen</code></a>!</li> <li>React: Preserve discriminated union prop values in metadata extraction - <a href="https://redirect.github.com/storybookjs/storybook/pull/35844">#35844</a>, thanks <a href="https://github.com/s-robertson"><code>@s-robertson</code></a>!</li> </ul> <h2>v10.5.9</h2> <h2>10.5.9</h2> <ul> <li>Addon-Pseudo-States: Fix pseudo-states rewriting for nested functional selectors - <a href="https://redirect.github.com/storybookjs/storybook/pull/34318">#34318</a>, thanks <a href="https://github.com/filipw01"><code>@filipw01</code></a>!</li> <li>Core: Skip module-graph reverse-index mirror when a patch is a no-op - <a href="https://redirect.github.com/storybookjs/storybook/pull/35825">#35825</a>, thanks <a href="https://github.com/ndelangen"><code>@ndelangen</code></a>!</li> <li>Core: Split module-graph into hot revisions and cold index services - <a href="https://redirect.github.com/storybookjs/storybook/pull/35831">#35831</a>, thanks <a href="https://github.com/ndelangen"><code>@ndelangen</code></a>!</li> <li>Preview: Fix crash when initialising UrlStore on a docs path - <a href="https://redirect.github.com/storybookjs/storybook/pull/35521">#35521</a>, thanks <a href="https://github.com/TheSeydiCharyyev"><code>@TheSeydiCharyyev</code></a>!</li> <li>Pseudo-States: Make stylesheet rewrites WebKit-safe - <a href="https://redirect.github.com/storybookjs/storybook/pull/35629">#35629</a>, thanks <a href="https://github.com/ethriel3695"><code>@ethriel3695</code></a>!</li> <li>TanStack: Keep the layout id when cloning a standalone index file route - <a href="https://redirect.github.com/storybookjs/storybook/pull/35660">#35660</a>, thanks <a href="https://github.com/Insik-Han"><code>@Insik-Han</code></a>!</li> <li>TanStack: Render real link hrefs in the Link mock - <a href="https://redirect.github.com/storybookjs/storybook/pull/35505">#35505</a>, thanks <a href="https://github.com/unpunnyfuns"><code>@unpunnyfuns</code></a>!</li> <li>Webpack: Prevent long preview output filenames - <a href="https://redirect.github.com/storybookjs/storybook/pull/35533">#35533</a>, thanks <a href="https://github.com/zhangli091011"><code>@zhangli091011</code></a>!</li> </ul> </blockquote> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/storybookjs/storybook/blob/next/CHANGELOG.md">@storybook/addon-a11y's changelog</a>.</em></p> <blockquote> <h2>10.5.10</h2> <ul> <li>Core: Fetch static open-service snapshots relative to the document - <a href="https://redirect.github.com/storybookjs/storybook/pull/35945">#35945</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Core: Pin oxc-resolver to 11.21.2 to keep tsconfig path aliases on solution-style tsconfigs - <a href="https://redirect.github.com/storybookjs/storybook/pull/35929">#35929</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Dependencies: Bump Vitest to 4.1.6 (CVE-2026-47428) - <a href="https://redirect.github.com/storybookjs/storybook/pull/35530">#35530</a>, thanks <a href="https://github.com/anupamme"><code>@anupamme</code></a>!</li> <li>Docs: Declare the font on overlay surfaces so docs tooltips are not left to inherit - <a href="https://redirect.github.com/storybookjs/storybook/pull/35966">#35966</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>ESLint Plugin: Bundle CSF helpers so the plugin loads without storybook - <a href="https://redirect.github.com/storybookjs/storybook/pull/35950">#35950</a>, thanks <a href="https://github.com/ndelangen"><code>@ndelangen</code></a>!</li> <li>React: Preserve discriminated union prop values in metadata extraction - <a href="https://redirect.github.com/storybookjs/storybook/pull/35844">#35844</a>, thanks <a href="https://github.com/s-robertson"><code>@s-robertson</code></a>!</li> </ul> <h2>10.5.9</h2> <ul> <li>Addon-Pseudo-States: Fix pseudo-states rewriting for nested functional selectors - <a href="https://redirect.github.com/storybookjs/storybook/pull/34318">#34318</a>, thanks <a href="https://github.com/filipw01"><code>@filipw01</code></a>!</li> <li>Core: Skip module-graph reverse-index mirror when a patch is a no-op - <a href="https://redirect.github.com/storybookjs/storybook/pull/35825">#35825</a>, thanks <a href="https://github.com/ndelangen"><code>@ndelangen</code></a>!</li> <li>Core: Split module-graph into hot revisions and cold index services - <a href="https://redirect.github.com/storybookjs/storybook/pull/35831">#35831</a>, thanks <a href="https://github.com/ndelangen"><code>@ndelangen</code></a>!</li> <li>Preview: Fix crash when initialising UrlStore on a docs path - <a href="https://redirect.github.com/storybookjs/storybook/pull/35521">#35521</a>, thanks <a href="https://github.com/TheSeydiCharyyev"><code>@TheSeydiCharyyev</code></a>!</li> <li>Pseudo-States: Make stylesheet rewrites WebKit-safe - <a href="https://redirect.github.com/storybookjs/storybook/pull/35629">#35629</a>, thanks <a href="https://github.com/ethriel3695"><code>@ethriel3695</code></a>!</li> <li>TanStack: Keep the layout id when cloning a standalone index file route - <a href="https://redirect.github.com/storybookjs/storybook/pull/35660">#35660</a>, thanks <a href="https://github.com/Insik-Han"><code>@Insik-Han</code></a>!</li> <li>TanStack: Render real link hrefs in the Link mock - <a href="https://redirect.github.com/storybookjs/storybook/pull/35505">#35505</a>, thanks <a href="https://github.com/unpunnyfuns"><code>@unpunnyfuns</code></a>!</li> <li>Webpack: Prevent long preview output filenames - <a href="https://redirect.github.com/storybookjs/storybook/pull/35533">#35533</a>, thanks <a href="https://github.com/zhangli091011"><code>@zhangli091011</code></a>!</li> </ul> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/storybookjs/storybook/commit/a2db7526e1538a48bfa0529a881822e8074b2009"><code>a2db752</code></a> Bump version from "10.5.9" to "10.5.10" [skip ci]</li> <li><a href="https://github.com/storybookjs/storybook/commit/8f561048949b3ce3674a71711942177a14e4e8f9"><code>8f56104</code></a> Bump version from "10.5.8" to "10.5.9" [skip ci]</li> <li>See full diff in <a href="https://github.com/storybookjs/storybook/commits/v10.5.10/code/addons/a11y">compare view</a></li> </ul> </details> <br /> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |
||
|
|
41726ae279 |
build(deps): bump react-resizable-panels from 4.12.2 to 4.12.3 (#11872)
Bumps [react-resizable-panels](https://github.com/bvaughn/react-resizable-panels) from 4.12.2 to 4.12.3. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/bvaughn/react-resizable-panels/releases">react-resizable-panels's releases</a>.</em></p> <blockquote> <h2>4.12.3</h2> <ul> <li><a href="https://redirect.github.com/bvaughn/react-resizable-panels/pull/730">730</a>: Guard <code>CSSStyleSheet</code> construction to avoid throwing in unsupported environments (<a href="https://github.com/leo-yang-qiong"><code>@leo-yang-qiong</code></a>)</li> <li><a href="https://redirect.github.com/bvaughn/react-resizable-panels/pull/736">736</a>: Bugfix: Derived Panel constraints equality check</li> <li><a href="https://redirect.github.com/bvaughn/react-resizable-panels/pull/732">732</a>: Bugfix: Prevent orphaned groups in "pointerup" edge case (<a href="https://github.com/waterWang"><code>@waterWang</code></a>)</li> </ul> </blockquote> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/bvaughn/react-resizable-panels/blob/main/CHANGELOG.md">react-resizable-panels's changelog</a>.</em></p> <blockquote> <h2>4.12.3</h2> <ul> <li><a href="https://redirect.github.com/bvaughn/react-resizable-panels/pull/730">730</a>: Guard <code>CSSStyleSheet</code> construction to avoid throwing in unsupported environments (<a href="https://github.com/leo-yang-qiong"><code>@leo-yang-qiong</code></a>)</li> <li><a href="https://redirect.github.com/bvaughn/react-resizable-panels/pull/736">736</a>: Bugfix: Derived Panel constraints equality check</li> <li><a href="https://redirect.github.com/bvaughn/react-resizable-panels/pull/732">732</a>: Bugfix: Prevent orphaned groups in "pointerup" edge case (<a href="https://github.com/waterWang"><code>@waterWang</code></a>)</li> </ul> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/bvaughn/react-resizable-panels/commit/f9c422714a66e14f671a17f340a3560d8032fcdc"><code>f9c4227</code></a> 4.12.2 -> 4.12.3</li> <li><a href="https://github.com/bvaughn/react-resizable-panels/commit/30503d1dadef45456dc7f65e64579f72e09e311f"><code>30503d1</code></a> Fix derived Panel constraints equality check (<a href="https://redirect.github.com/bvaughn/react-resizable-panels/issues/736">#736</a>)</li> <li><a href="https://github.com/bvaughn/react-resizable-panels/commit/30aef6a448d26bfaeb0e80f2b7d7aeec7a113818"><code>30aef6a</code></a> Pending CHANGELOG</li> <li><a href="https://github.com/bvaughn/react-resizable-panels/commit/b1d574e504099717df19afd671753511fb515389"><code>b1d574e</code></a> fix: guard CSSStyleSheet construction with adoptedStyleSheets check (<a href="https://redirect.github.com/bvaughn/react-resizable-panels/issues/730">#730</a>)</li> <li><a href="https://github.com/bvaughn/react-resizable-panels/commit/6649f42e56cdd9f323d8156365ea7b85a6a5e966"><code>6649f42</code></a> fix: don't resurrect stale group entries on pointer-up commit (Fixes <a href="https://redirect.github.com/bvaughn/react-resizable-panels/issues/729">#729</a>) (#...</li> <li>See full diff in <a href="https://github.com/bvaughn/react-resizable-panels/compare/4.12.2...4.12.3">compare view</a></li> </ul> </details> <br /> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |
||
|
|
50e324638c |
build(deps): bump @assistant-ui/react from 0.15.14 to 0.15.16 (#11888)
Bumps [@assistant-ui/react](https://github.com/assistant-ui/assistant-ui/tree/HEAD/packages/react) from 0.15.14 to 0.15.16. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/assistant-ui/assistant-ui/releases">@assistant-ui/react's releases</a>.</em></p> <blockquote> <h2><code>@assistant-ui/react</code><a href="https://github.com/0"><code>@0</code></a>.15.16</h2> <h3>Patch Changes</h3> <ul> <li> <p><a href="https://redirect.github.com/assistant-ui/assistant-ui/pull/6136">#6136</a> <a href="https://github.com/assistant-ui/assistant-ui/commit/f7bd2d9392e1e71750012fa87649002e8c9d1dab"><code>f7bd2d9</code></a> - fix: keep DevTools updates flowing when a subscriber throws (<a href="https://github.com/Kinfe123"><code>@Kinfe123</code></a>)</p> </li> <li> <p><a href="https://redirect.github.com/assistant-ui/assistant-ui/pull/6055">#6055</a> <a href="https://github.com/assistant-ui/assistant-ui/commit/1f3eaa77897e617efa977f4d194de7e6013a0de5"><code>1f3eaa7</code></a> - fix: contain SandboxHost render failures after teardown (<a href="https://github.com/Kinfe123"><code>@Kinfe123</code></a>)</p> </li> <li> <p><a href="https://redirect.github.com/assistant-ui/assistant-ui/pull/6110">#6110</a> <a href="https://github.com/assistant-ui/assistant-ui/commit/48f95b1442c4e9f744660b8e25e7aceb9b5ba5dc"><code>48f95b1</code></a> - chore: delete the dead <code>ensureBinding</code> and <code>useRuntimeState</code> utilities (<a href="https://github.com/samdickson22"><code>@samdickson22</code></a>)</p> <p><code>src/context/react/utils/ensureBinding.ts</code> and <code>src/context/react/utils/useRuntimeState.ts</code> imported only each other. Nothing else in the repo referenced them, neither appears in the package barrel or the api-surface snapshot, and the <code>"."</code>-only exports map made them unreachable to consumers. <code>ensureBinding</code> was an external caller of <code>__internal_bindMethods</code> that no longer had a caller of its own; the runtime classes bind themselves in their constructors, so nothing changes at runtime. The public API surface is unchanged and every other emitted file is byte-identical.</p> </li> <li> <p><a href="https://redirect.github.com/assistant-ui/assistant-ui/pull/6156">#6156</a> <a href="https://github.com/assistant-ui/assistant-ui/commit/9c65b511bc7cdc7d6699c128cac4650cae728043"><code>9c65b51</code></a> - deprecate leftover Primitive.If and Empty wrappers on react-native and react-ink, and point them at AuiIf (<a href="https://github.com/okisdev"><code>@okisdev</code></a>)</p> <p>ThreadIf now reads <code>thread.isEmpty</code> instead of <code>messages.length === 0</code>, matching the loading-aware field already used by ThreadEmpty and AuiIf. First-party examples and docs samples that still called the leftover wrappers now use <code>AuiIf</code> directly.</p> </li> <li> <p><a href="https://redirect.github.com/assistant-ui/assistant-ui/pull/6084">#6084</a> <a href="https://github.com/assistant-ui/assistant-ui/commit/ca9e72ce85a9164b11947f9b7a38fb5801f7d04e"><code>ca9e72c</code></a> - fix: resync trigger popover cursor after selection (<a href="https://github.com/apps/rupic-app"><code>@rupic-app</code></a>)</p> </li> <li> <p><a href="https://redirect.github.com/assistant-ui/assistant-ui/pull/6054">#6054</a> <a href="https://github.com/assistant-ui/assistant-ui/commit/59e9a0881c3c392dd0f92508deab78aa50ddd605"><code>59e9a08</code></a> - fix: handle rejected asynchronous Markdown exports (<a href="https://github.com/Kinfe123"><code>@Kinfe123</code></a>)</p> </li> <li> <p><a href="https://redirect.github.com/assistant-ui/assistant-ui/pull/6098">#6098</a> <a href="https://github.com/assistant-ui/assistant-ui/commit/b9b9dad28af0fc7c873d0b653830c0f1a78197ed"><code>b9b9dad</code></a> - fix: drain unrevealed smooth text when a message completes before any frame (<a href="https://github.com/apps/rupic-app"><code>@rupic-app</code></a>)</p> </li> <li> <p><a href="https://redirect.github.com/assistant-ui/assistant-ui/pull/6061">#6061</a> <a href="https://github.com/assistant-ui/assistant-ui/commit/75dfbe3a2b7c3af61793fc1448e06d2d0063767a"><code>75dfbe3</code></a> - docs: document Escape-to-stop-speaking on ThreadPrimitive.Root (<a href="https://github.com/samdickson22"><code>@samdickson22</code></a>)</p> </li> <li> <p><a href="https://redirect.github.com/assistant-ui/assistant-ui/pull/6124">#6124</a> <a href="https://github.com/assistant-ui/assistant-ui/commit/06b04a7976d10fac3af40ae9ca59b52385ef2ae2"><code>06b04a7</code></a> - chore: update dependencies (<a href="https://github.com/okisdev"><code>@okisdev</code></a>)</p> </li> <li> <p>Updated dependencies [<a href="https://github.com/assistant-ui/assistant-ui/commit/fa309156e033dc085c0d3b8fb97c27c81a3d2c6e"><code>fa30915</code></a>, <a href="https://github.com/assistant-ui/assistant-ui/commit/b355aefbe2403025562f0e08494a57450bfdc049"><code>b355aef</code></a>, <a href="https://github.com/assistant-ui/assistant-ui/commit/f7bd2d9392e1e71750012fa87649002e8c9d1dab"><code>f7bd2d9</code></a>, <a href="https://github.com/assistant-ui/assistant-ui/commit/4947ef4f9b0956bd4ca21c457b3cc7e79a2fc9e0"><code>4947ef4</code></a>, <a href="https://github.com/assistant-ui/assistant-ui/commit/332f736e64bfa26f76cd60318279697ddbc0b36d"><code>332f736</code></a>, <a href="https://github.com/assistant-ui/assistant-ui/commit/ef9254d5b2174fb4b58b4e954a8a0d60910a484c"><code>ef9254d</code></a>, <a href="https://github.com/assistant-ui/assistant-ui/commit/9c65b511bc7cdc7d6699c128cac4650cae728043"><code>9c65b51</code></a>, <a href="https://github.com/assistant-ui/assistant-ui/commit/5845ba7c5690af776701683fbd2d04e9ca0eaaff"><code>5845ba7</code></a>, <a href="https://github.com/assistant-ui/assistant-ui/commit/1b30bfdabadfe3613b7c98296de3d6665122136b"><code>1b30bfd</code></a>, <a href="https://github.com/assistant-ui/assistant-ui/commit/365e763928ff38d2de518efa2a7c44249afbbf83"><code>365e763</code></a>, <a href="https://github.com/assistant-ui/assistant-ui/commit/d19921d3739efb53dcbbb1ae04ffd18a94dca080"><code>d19921d</code></a>, <a href="https://github.com/assistant-ui/assistant-ui/commit/996aa5723cf8d7db00cc72da08713226d90ec0e1"><code>996aa57</code></a>, <a href="https://github.com/assistant-ui/assistant-ui/commit/21d6e87dc2834af11babb93c004f7d4f3a4f9568"><code>21d6e87</code></a>, <a href="https://github.com/assistant-ui/assistant-ui/commit/cd247e557b4876c49feb9b79c4f5149cc2271dad"><code>cd247e5</code></a>, <a href="https://github.com/assistant-ui/assistant-ui/commit/f2b3ef8b6330e9353741973b0bfe0abf37d81e70"><code>f2b3ef8</code></a>, <a href="https://github.com/assistant-ui/assistant-ui/commit/1bf263ba208668ead7f6c0786ca0c3064e31c3ab"><code>1bf263b</code></a>, <a href="https://github.com/assistant-ui/assistant-ui/commit/19e52c4012a6a8c32e514134af9ce4eee1146864"><code>19e52c4</code></a>, <a href="https://github.com/assistant-ui/assistant-ui/commit/06b04a7976d10fac3af40ae9ca59b52385ef2ae2"><code>06b04a7</code></a>, <a href="https://github.com/assistant-ui/assistant-ui/commit/a614b5e44df5f59d82b63b60132a41c89f82e185"><code>a614b5e</code></a>, <a href="https://github.com/assistant-ui/assistant-ui/commit/07b51dbbc749c94023fa25df99bb7f64dc211ff1"><code>07b51db</code></a>, <a href="https://github.com/assistant-ui/assistant-ui/commit/92e52bd2c99ee8cacd242bf723f617df64e42e2a"><code>92e52bd</code></a>]:</p> <ul> <li><code>@assistant-ui/core</code><a href="https://github.com/0"><code>@0</code></a>.3.15</li> <li><code>@assistant-ui/tap</code><a href="https://github.com/0"><code>@0</code></a>.9.14</li> <li>assistant-stream@0.3.39</li> </ul> </li> </ul> <h2><code>@assistant-ui/react</code><a href="https://github.com/0"><code>@0</code></a>.15.15</h2> <h3>Patch Changes</h3> <ul> <li> <p><a href="https://redirect.github.com/assistant-ui/assistant-ui/pull/6071">#6071</a> <a href="https://github.com/assistant-ui/assistant-ui/commit/c3fd447f23cbaa36381b2f62058b420bd54cc148"><code>c3fd447</code></a> - feat: host assistant-cloud thread lists on AISDKThreads via RemoteThreadList (<a href="https://github.com/okisdev"><code>@okisdev</code></a>)</p> <p>AISDKThreads({ cloud }) uses RemoteThreadList and remounts each thread like useChatRuntime. Cloud history withFormat resolves persistence per call so one adapter can serve many threads. useExternalHistory waits for threadListItem.remoteId instead of latching on the first empty paint.</p> </li> <li> <p><a href="https://redirect.github.com/assistant-ui/assistant-ui/pull/5872">#5872</a> <a href="https://github.com/assistant-ui/assistant-ui/commit/f9529bfdea5018505ef393fe46e93809a0012032"><code>f9529bf</code></a> - feat: move useAssistantTransportRuntime into core/react (<a href="https://github.com/okisdev"><code>@okisdev</code></a>)</p> </li> <li> <p><a href="https://redirect.github.com/assistant-ui/assistant-ui/pull/5872">#5872</a> <a href="https://github.com/assistant-ui/assistant-ui/commit/f9529bfdea5018505ef393fe46e93809a0012032"><code>f9529bf</code></a> - fix: persist data message parts in aui/v0 cloud history (<a href="https://github.com/okisdev"><code>@okisdev</code></a>)</p> </li> <li> <p><a href="https://redirect.github.com/assistant-ui/assistant-ui/pull/5839">#5839</a> <a href="https://github.com/assistant-ui/assistant-ui/commit/24a1af7607a29e5026f1de77a24e0b3efa76bca4"><code>24a1af7</code></a> - fix: validate MCP App resource responses (<a href="https://github.com/Kinfe123"><code>@Kinfe123</code></a>)</p> </li> <li> <p><a href="https://redirect.github.com/assistant-ui/assistant-ui/pull/5817">#5817</a> <a href="https://github.com/assistant-ui/assistant-ui/commit/dab7b7af71773db87a729d7233035187a10a60db"><code>dab7b7a</code></a> - fix: dispose sandbox frames when bridge setup fails (<a href="https://github.com/Kinfe123"><code>@Kinfe123</code></a>)</p> </li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/assistant-ui/assistant-ui/blob/main/packages/react/CHANGELOG.md">@assistant-ui/react's changelog</a>.</em></p> <blockquote> <h2>0.15.16</h2> <h3>Patch Changes</h3> <ul> <li> <p><a href="https://redirect.github.com/assistant-ui/assistant-ui/pull/6136">#6136</a> <a href="https://github.com/assistant-ui/assistant-ui/commit/f7bd2d9392e1e71750012fa87649002e8c9d1dab"><code>f7bd2d9</code></a> - fix: keep DevTools updates flowing when a subscriber throws (<a href="https://github.com/Kinfe123"><code>@Kinfe123</code></a>)</p> </li> <li> <p><a href="https://redirect.github.com/assistant-ui/assistant-ui/pull/6055">#6055</a> <a href="https://github.com/assistant-ui/assistant-ui/commit/1f3eaa77897e617efa977f4d194de7e6013a0de5"><code>1f3eaa7</code></a> - fix: contain SandboxHost render failures after teardown (<a href="https://github.com/Kinfe123"><code>@Kinfe123</code></a>)</p> </li> <li> <p><a href="https://redirect.github.com/assistant-ui/assistant-ui/pull/6110">#6110</a> <a href="https://github.com/assistant-ui/assistant-ui/commit/48f95b1442c4e9f744660b8e25e7aceb9b5ba5dc"><code>48f95b1</code></a> - chore: delete the dead <code>ensureBinding</code> and <code>useRuntimeState</code> utilities (<a href="https://github.com/samdickson22"><code>@samdickson22</code></a>)</p> <p><code>src/context/react/utils/ensureBinding.ts</code> and <code>src/context/react/utils/useRuntimeState.ts</code> imported only each other. Nothing else in the repo referenced them, neither appears in the package barrel or the api-surface snapshot, and the <code>"."</code>-only exports map made them unreachable to consumers. <code>ensureBinding</code> was an external caller of <code>__internal_bindMethods</code> that no longer had a caller of its own; the runtime classes bind themselves in their constructors, so nothing changes at runtime. The public API surface is unchanged and every other emitted file is byte-identical.</p> </li> <li> <p><a href="https://redirect.github.com/assistant-ui/assistant-ui/pull/6156">#6156</a> <a href="https://github.com/assistant-ui/assistant-ui/commit/9c65b511bc7cdc7d6699c128cac4650cae728043"><code>9c65b51</code></a> - deprecate leftover Primitive.If and Empty wrappers on react-native and react-ink, and point them at AuiIf (<a href="https://github.com/okisdev"><code>@okisdev</code></a>)</p> <p>ThreadIf now reads <code>thread.isEmpty</code> instead of <code>messages.length === 0</code>, matching the loading-aware field already used by ThreadEmpty and AuiIf. First-party examples and docs samples that still called the leftover wrappers now use <code>AuiIf</code> directly.</p> </li> <li> <p><a href="https://redirect.github.com/assistant-ui/assistant-ui/pull/6084">#6084</a> <a href="https://github.com/assistant-ui/assistant-ui/commit/ca9e72ce85a9164b11947f9b7a38fb5801f7d04e"><code>ca9e72c</code></a> - fix: resync trigger popover cursor after selection (<a href="https://github.com/apps/rupic-app"><code>@rupic-app</code></a>)</p> </li> <li> <p><a href="https://redirect.github.com/assistant-ui/assistant-ui/pull/6054">#6054</a> <a href="https://github.com/assistant-ui/assistant-ui/commit/59e9a0881c3c392dd0f92508deab78aa50ddd605"><code>59e9a08</code></a> - fix: handle rejected asynchronous Markdown exports (<a href="https://github.com/Kinfe123"><code>@Kinfe123</code></a>)</p> </li> <li> <p><a href="https://redirect.github.com/assistant-ui/assistant-ui/pull/6098">#6098</a> <a href="https://github.com/assistant-ui/assistant-ui/commit/b9b9dad28af0fc7c873d0b653830c0f1a78197ed"><code>b9b9dad</code></a> - fix: drain unrevealed smooth text when a message completes before any frame (<a href="https://github.com/apps/rupic-app"><code>@rupic-app</code></a>)</p> </li> <li> <p><a href="https://redirect.github.com/assistant-ui/assistant-ui/pull/6061">#6061</a> <a href="https://github.com/assistant-ui/assistant-ui/commit/75dfbe3a2b7c3af61793fc1448e06d2d0063767a"><code>75dfbe3</code></a> - docs: document Escape-to-stop-speaking on ThreadPrimitive.Root (<a href="https://github.com/samdickson22"><code>@samdickson22</code></a>)</p> </li> <li> <p><a href="https://redirect.github.com/assistant-ui/assistant-ui/pull/6124">#6124</a> <a href="https://github.com/assistant-ui/assistant-ui/commit/06b04a7976d10fac3af40ae9ca59b52385ef2ae2"><code>06b04a7</code></a> - chore: update dependencies (<a href="https://github.com/okisdev"><code>@okisdev</code></a>)</p> </li> <li> <p>Updated dependencies [<a href="https://github.com/assistant-ui/assistant-ui/commit/fa309156e033dc085c0d3b8fb97c27c81a3d2c6e"><code>fa30915</code></a>, <a href="https://github.com/assistant-ui/assistant-ui/commit/b355aefbe2403025562f0e08494a57450bfdc049"><code>b355aef</code></a>, <a href="https://github.com/assistant-ui/assistant-ui/commit/f7bd2d9392e1e71750012fa87649002e8c9d1dab"><code>f7bd2d9</code></a>, <a href="https://github.com/assistant-ui/assistant-ui/commit/4947ef4f9b0956bd4ca21c457b3cc7e79a2fc9e0"><code>4947ef4</code></a>, <a href="https://github.com/assistant-ui/assistant-ui/commit/332f736e64bfa26f76cd60318279697ddbc0b36d"><code>332f736</code></a>, <a href="https://github.com/assistant-ui/assistant-ui/commit/ef9254d5b2174fb4b58b4e954a8a0d60910a484c"><code>ef9254d</code></a>, <a href="https://github.com/assistant-ui/assistant-ui/commit/9c65b511bc7cdc7d6699c128cac4650cae728043"><code>9c65b51</code></a>, <a href="https://github.com/assistant-ui/assistant-ui/commit/5845ba7c5690af776701683fbd2d04e9ca0eaaff"><code>5845ba7</code></a>, <a href="https://github.com/assistant-ui/assistant-ui/commit/1b30bfdabadfe3613b7c98296de3d6665122136b"><code>1b30bfd</code></a>, <a href="https://github.com/assistant-ui/assistant-ui/commit/365e763928ff38d2de518efa2a7c44249afbbf83"><code>365e763</code></a>, <a href="https://github.com/assistant-ui/assistant-ui/commit/d19921d3739efb53dcbbb1ae04ffd18a94dca080"><code>d19921d</code></a>, <a href="https://github.com/assistant-ui/assistant-ui/commit/996aa5723cf8d7db00cc72da08713226d90ec0e1"><code>996aa57</code></a>, <a href="https://github.com/assistant-ui/assistant-ui/commit/21d6e87dc2834af11babb93c004f7d4f3a4f9568"><code>21d6e87</code></a>, <a href="https://github.com/assistant-ui/assistant-ui/commit/cd247e557b4876c49feb9b79c4f5149cc2271dad"><code>cd247e5</code></a>, <a href="https://github.com/assistant-ui/assistant-ui/commit/f2b3ef8b6330e9353741973b0bfe0abf37d81e70"><code>f2b3ef8</code></a>, <a href="https://github.com/assistant-ui/assistant-ui/commit/1bf263ba208668ead7f6c0786ca0c3064e31c3ab"><code>1bf263b</code></a>, <a href="https://github.com/assistant-ui/assistant-ui/commit/19e52c4012a6a8c32e514134af9ce4eee1146864"><code>19e52c4</code></a>, <a href="https://github.com/assistant-ui/assistant-ui/commit/06b04a7976d10fac3af40ae9ca59b52385ef2ae2"><code>06b04a7</code></a>, <a href="https://github.com/assistant-ui/assistant-ui/commit/a614b5e44df5f59d82b63b60132a41c89f82e185"><code>a614b5e</code></a>, <a href="https://github.com/assistant-ui/assistant-ui/commit/07b51dbbc749c94023fa25df99bb7f64dc211ff1"><code>07b51db</code></a>, <a href="https://github.com/assistant-ui/assistant-ui/commit/92e52bd2c99ee8cacd242bf723f617df64e42e2a"><code>92e52bd</code></a>]:</p> <ul> <li><code>@assistant-ui/core</code><a href="https://github.com/0"><code>@0</code></a>.3.15</li> <li><code>@assistant-ui/tap</code><a href="https://github.com/0"><code>@0</code></a>.9.14</li> <li>assistant-stream@0.3.39</li> </ul> </li> </ul> <h2>0.15.15</h2> <h3>Patch Changes</h3> <ul> <li> <p><a href="https://redirect.github.com/assistant-ui/assistant-ui/pull/6071">#6071</a> <a href="https://github.com/assistant-ui/assistant-ui/commit/c3fd447f23cbaa36381b2f62058b420bd54cc148"><code>c3fd447</code></a> - feat: host assistant-cloud thread lists on AISDKThreads via RemoteThreadList (<a href="https://github.com/okisdev"><code>@okisdev</code></a>)</p> <p>AISDKThreads({ cloud }) uses RemoteThreadList and remounts each thread like useChatRuntime. Cloud history withFormat resolves persistence per call so one adapter can serve many threads. useExternalHistory waits for threadListItem.remoteId instead of latching on the first empty paint.</p> </li> <li> <p><a href="https://redirect.github.com/assistant-ui/assistant-ui/pull/5872">#5872</a> <a href="https://github.com/assistant-ui/assistant-ui/commit/f9529bfdea5018505ef393fe46e93809a0012032"><code>f9529bf</code></a> - feat: move useAssistantTransportRuntime into core/react (<a href="https://github.com/okisdev"><code>@okisdev</code></a>)</p> </li> <li> <p><a href="https://redirect.github.com/assistant-ui/assistant-ui/pull/5872">#5872</a> <a href="https://github.com/assistant-ui/assistant-ui/commit/f9529bfdea5018505ef393fe46e93809a0012032"><code>f9529bf</code></a> - fix: persist data message parts in aui/v0 cloud history (<a href="https://github.com/okisdev"><code>@okisdev</code></a>)</p> </li> <li> <p><a href="https://redirect.github.com/assistant-ui/assistant-ui/pull/5839">#5839</a> <a href="https://github.com/assistant-ui/assistant-ui/commit/24a1af7607a29e5026f1de77a24e0b3efa76bca4"><code>24a1af7</code></a> - fix: validate MCP App resource responses (<a href="https://github.com/Kinfe123"><code>@Kinfe123</code></a>)</p> </li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/assistant-ui/assistant-ui/commit/75e3ef71beb5dc99f6fc624624d3d61b307c8599"><code>75e3ef7</code></a> chore: update versions (<a href="https://github.com/assistant-ui/assistant-ui/tree/HEAD/packages/react/issues/6086">#6086</a>)</li> <li><a href="https://github.com/assistant-ui/assistant-ui/commit/f7bd2d9392e1e71750012fa87649002e8c9d1dab"><code>f7bd2d9</code></a> fix(react): isolate devtools subscribers (<a href="https://github.com/assistant-ui/assistant-ui/tree/HEAD/packages/react/issues/6136">#6136</a>)</li> <li><a href="https://github.com/assistant-ui/assistant-ui/commit/9c65b511bc7cdc7d6699c128cac4650cae728043"><code>9c65b51</code></a> fix(react-native,react-ink): honor thread.isEmpty in leftover ThreadIf (<a href="https://github.com/assistant-ui/assistant-ui/tree/HEAD/packages/react/issues/6156">#6156</a>)</li> <li><a href="https://github.com/assistant-ui/assistant-ui/commit/48f95b1442c4e9f744660b8e25e7aceb9b5ba5dc"><code>48f95b1</code></a> chore(react): delete the dead ensureBinding and useRuntimeState utilities (<a href="https://github.com/assistant-ui/assistant-ui/tree/HEAD/packages/react/issues/6">#6</a>...</li> <li><a href="https://github.com/assistant-ui/assistant-ui/commit/06b04a7976d10fac3af40ae9ca59b52385ef2ae2"><code>06b04a7</code></a> chore: update dependencies (<a href="https://github.com/assistant-ui/assistant-ui/tree/HEAD/packages/react/issues/6124">#6124</a>)</li> <li><a href="https://github.com/assistant-ui/assistant-ui/commit/b9b9dad28af0fc7c873d0b653830c0f1a78197ed"><code>b9b9dad</code></a> fix: drain smooth text when a message completes before an animation frame (<a href="https://github.com/assistant-ui/assistant-ui/tree/HEAD/packages/react/issues/6">#6</a>...</li> <li><a href="https://github.com/assistant-ui/assistant-ui/commit/10a0f3ade814aef47a327383fe50d59bd9d79538"><code>10a0f3a</code></a> test(react): vary live-completion fetcher and cacheKey independently (<a href="https://github.com/assistant-ui/assistant-ui/tree/HEAD/packages/react/issues/6062">#6062</a>)</li> <li><a href="https://github.com/assistant-ui/assistant-ui/commit/b355aefbe2403025562f0e08494a57450bfdc049"><code>b355aef</code></a> fix(core): prevent assistant frame origin downgrades (<a href="https://github.com/assistant-ui/assistant-ui/tree/HEAD/packages/react/issues/5823">#5823</a>)</li> <li><a href="https://github.com/assistant-ui/assistant-ui/commit/75dfbe3a2b7c3af61793fc1448e06d2d0063767a"><code>75dfbe3</code></a> docs(react): document Escape-to-stop-speaking on ThreadPrimitive.Root (<a href="https://github.com/assistant-ui/assistant-ui/tree/HEAD/packages/react/issues/6061">#6061</a>)</li> <li><a href="https://github.com/assistant-ui/assistant-ui/commit/ca9e72ce85a9164b11947f9b7a38fb5801f7d04e"><code>ca9e72c</code></a> fix(react): resync trigger cursor after selection (<a href="https://github.com/assistant-ui/assistant-ui/tree/HEAD/packages/react/issues/6082">#6082</a>) (<a href="https://github.com/assistant-ui/assistant-ui/tree/HEAD/packages/react/issues/6084">#6084</a>)</li> <li>Additional commits viewable in <a href="https://github.com/assistant-ui/assistant-ui/commits/@assistant-ui/react@0.15.16/packages/react">compare view</a></li> </ul> </details> <br /> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |
||
|
|
4fb0978578 |
build(deps): bump googleapis from 174.0.1 to 176.0.0 (#11889)
Bumps [googleapis](https://github.com/googleapis/google-api-nodejs-client) from 174.0.1 to 176.0.0. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/googleapis/google-api-nodejs-client/releases">googleapis's releases</a>.</em></p> <blockquote> <h2>googleapis: v176.0.0</h2> <h2><a href="https://github.com/googleapis/google-api-nodejs-client/compare/googleapis-v175.0.0...googleapis-v176.0.0">176.0.0</a> (2026-08-18)</h2> <h3>⚠ BREAKING CHANGES</h3> <ul> <li><strong>securityposture:</strong> This release has breaking changes.</li> <li><strong>compute:</strong> This release has breaking changes.</li> <li><strong>assuredworkloads:</strong> This release has breaking changes.</li> </ul> <h3>Features</h3> <ul> <li><strong>assuredworkloads:</strong> update the API (<a href="https://github.com/googleapis/google-api-nodejs-client/commit/4f787ecb10d2fcc0605045096ab472c8a3c848ce">4f787ec</a>)</li> <li><strong>bigqueryconnection:</strong> update the API (<a href="https://github.com/googleapis/google-api-nodejs-client/commit/19d67d7998bfd284eac66cbb2649df7479c3ecaa">19d67d7</a>)</li> <li><strong>bigquery:</strong> update the API (<a href="https://github.com/googleapis/google-api-nodejs-client/commit/5047629259ead4fb146cf95156bd8c28d5a0eb46">5047629</a>)</li> <li><strong>ces:</strong> update the API (<a href="https://github.com/googleapis/google-api-nodejs-client/commit/4d674e7e4efc6826072fe92f624378f9e03d0e34">4d674e7</a>)</li> <li><strong>compute:</strong> update the API (<a href="https://github.com/googleapis/google-api-nodejs-client/commit/88ee28ba7c20507de837c6335980f4aa239e5b4e">88ee28b</a>)</li> <li><strong>contactcenterinsights:</strong> update the API (<a href="https://github.com/googleapis/google-api-nodejs-client/commit/8987bcff71f26c6a511c92833049c0b7ad86469e">8987bcf</a>)</li> <li><strong>dialogflow:</strong> update the API (<a href="https://github.com/googleapis/google-api-nodejs-client/commit/cb090b72b2cae5d9b2053985b12237c51dd57ff7">cb090b7</a>)</li> <li><strong>discoveryengine:</strong> update the API (<a href="https://github.com/googleapis/google-api-nodejs-client/commit/c9a9b98cfcc0acedf8679fd3c791c74477c64654">c9a9b98</a>)</li> <li><strong>gkehub:</strong> update the API (<a href="https://github.com/googleapis/google-api-nodejs-client/commit/e7356ce9c0aa7240bd69688c544e4e3b3f81138a">e7356ce</a>)</li> <li><strong>looker:</strong> update the API (<a href="https://github.com/googleapis/google-api-nodejs-client/commit/ce6eba99279a866be197c7eaba9a8ea2e7f1eafa">ce6eba9</a>)</li> <li><strong>metastore:</strong> update the API (<a href="https://github.com/googleapis/google-api-nodejs-client/commit/266b861fd1a23ea8781f03ef252cf30dec2eb1f6">266b861</a>)</li> <li><strong>networkservices:</strong> update the API (<a href="https://github.com/googleapis/google-api-nodejs-client/commit/71b26e6c3734b967f4c228bb5cbc6658f0e8c42b">71b26e6</a>)</li> <li><strong>playdeveloperreporting:</strong> update the API (<a href="https://github.com/googleapis/google-api-nodejs-client/commit/b0d0c264919b34dc6c18179113ea4195375db638">b0d0c26</a>)</li> <li>regenerate index files (<a href="https://github.com/googleapis/google-api-nodejs-client/commit/0eb3a957cc14024a33be3910f970651aa7ba430b">0eb3a95</a>)</li> <li><strong>secretmanager:</strong> update the API (<a href="https://github.com/googleapis/google-api-nodejs-client/commit/333f48fa3afeb9daa9a506b77c7ddd9cdbed8fce">333f48f</a>)</li> <li><strong>securityposture:</strong> update the API (<a href="https://github.com/googleapis/google-api-nodejs-client/commit/868105393dbb9148f0cc827d5895c5effa51f372">8681053</a>)</li> <li><strong>storage:</strong> update the API (<a href="https://github.com/googleapis/google-api-nodejs-client/commit/9974109dd49839de0083621ed9ce133f6e1c37a8">9974109</a>)</li> <li><strong>webcontentpublisher:</strong> update the API (<a href="https://github.com/googleapis/google-api-nodejs-client/commit/7dc05fc5f268c8a7ca5d18429fde05b50a58b29c">7dc05fc</a>)</li> </ul> <h3>Bug Fixes</h3> <ul> <li><strong>datafusion:</strong> update the API (<a href="https://github.com/googleapis/google-api-nodejs-client/commit/2c691d571a3fdc8a93926fbfcbaa50273517756f">2c691d5</a>)</li> <li><strong>docs:</strong> run JSDoc once per documentation build (<a href="https://redirect.github.com/googleapis/google-api-nodejs-client/issues/3958">#3958</a>) (<a href="https://github.com/googleapis/google-api-nodejs-client/commit/5aaf111af860b22a55ed64da824e0444b119c007">5aaf111</a>)</li> <li><strong>redis:</strong> update the API (<a href="https://github.com/googleapis/google-api-nodejs-client/commit/c639065e6ab3019192384f71d95bc447fb176329">c639065</a>)</li> <li><strong>trafficdirector:</strong> update the API (<a href="https://github.com/googleapis/google-api-nodejs-client/commit/3331b0cd347a11ea9d8c774f61ee67029399ba73">3331b0c</a>)</li> <li><strong>workstations:</strong> update the API (<a href="https://github.com/googleapis/google-api-nodejs-client/commit/ee9521ce5cdb69590827c30c59e58f0f047fb70d">ee9521c</a>)</li> </ul> <h2>googleapis: v175.0.0</h2> <h2><a href="https://github.com/googleapis/google-api-nodejs-client/compare/googleapis-v174.0.1...googleapis-v175.0.0">175.0.0</a> (2026-08-14)</h2> <h3>⚠ BREAKING CHANGES</h3> <ul> <li><strong>merchantapi:</strong> This release has breaking changes.</li> <li><strong>discoveryengine:</strong> This release has breaking changes.</li> </ul> <h3>Features</h3> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/googleapis/google-api-nodejs-client/commit/a454f9bda019c742b835e5fd5077294ce85c7875"><code>a454f9b</code></a> chore: release main (<a href="https://redirect.github.com/googleapis/google-api-nodejs-client/issues/3976">#3976</a>)</li> <li><a href="https://github.com/googleapis/google-api-nodejs-client/commit/0eb3a957cc14024a33be3910f970651aa7ba430b"><code>0eb3a95</code></a> feat: regenerate index files</li> <li><a href="https://github.com/googleapis/google-api-nodejs-client/commit/ee9521ce5cdb69590827c30c59e58f0f047fb70d"><code>ee9521c</code></a> fix(workstations): update the API</li> <li><a href="https://github.com/googleapis/google-api-nodejs-client/commit/7dc05fc5f268c8a7ca5d18429fde05b50a58b29c"><code>7dc05fc</code></a> feat(webcontentpublisher): update the API</li> <li><a href="https://github.com/googleapis/google-api-nodejs-client/commit/3331b0cd347a11ea9d8c774f61ee67029399ba73"><code>3331b0c</code></a> fix(trafficdirector): update the API</li> <li><a href="https://github.com/googleapis/google-api-nodejs-client/commit/9974109dd49839de0083621ed9ce133f6e1c37a8"><code>9974109</code></a> feat(storage): update the API</li> <li><a href="https://github.com/googleapis/google-api-nodejs-client/commit/868105393dbb9148f0cc827d5895c5effa51f372"><code>8681053</code></a> feat(securityposture)!: update the API</li> <li><a href="https://github.com/googleapis/google-api-nodejs-client/commit/333f48fa3afeb9daa9a506b77c7ddd9cdbed8fce"><code>333f48f</code></a> feat(secretmanager): update the API</li> <li><a href="https://github.com/googleapis/google-api-nodejs-client/commit/c639065e6ab3019192384f71d95bc447fb176329"><code>c639065</code></a> fix(redis): update the API</li> <li><a href="https://github.com/googleapis/google-api-nodejs-client/commit/b0d0c264919b34dc6c18179113ea4195375db638"><code>b0d0c26</code></a> feat(playdeveloperreporting): update the API</li> <li>Additional commits viewable in <a href="https://github.com/googleapis/google-api-nodejs-client/compare/googleapis-v174.0.1...googleapis-v176.0.0">compare view</a></li> </ul> </details> <br /> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |
||
|
|
b67dced1bf |
build(deps): bump @agentclientprotocol/codex-acp from 1.2.0 to 1.6.2 (#11883)
Bumps [@agentclientprotocol/codex-acp](https://github.com/agentclientprotocol/codex-acp) from 1.2.0 to 1.6.2. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/agentclientprotocol/codex-acp/releases">@agentclientprotocol/codex-acp's releases</a>.</em></p> <blockquote> <h2>v1.6.2</h2> <h2><a href="https://github.com/agentclientprotocol/codex-acp/compare/v1.6.1...v1.6.2">1.6.2</a> (2026-08-19)</h2> <h3>Bug Fixes</h3> <ul> <li>right-size the apt timeouts so a slow mirror still finishes (<a href="https://github.com/agentclientprotocol/codex-acp/commit/86e0772204a07d6fc4a8853c523ceb5006431f88">86e0772</a>)</li> </ul> <h2>v1.6.1</h2> <h2><a href="https://github.com/agentclientprotocol/codex-acp/compare/v1.6.0...v1.6.1">1.6.1</a> (2026-08-19)</h2> <h3>Bug Fixes</h3> <ul> <li>kill stalled apt from outside and serialize the unit suite (<a href="https://github.com/agentclientprotocol/codex-acp/commit/51e011fef27b812b238bf29c2a815f8ad149fa87">51e011f</a>)</li> </ul> <h2>v1.6.0</h2> <h2><a href="https://github.com/agentclientprotocol/codex-acp/compare/v1.5.1...v1.6.0">1.6.0</a> (2026-08-19)</h2> <h3>Features</h3> <ul> <li>harden release pipeline against hangs and e2e flakes (<a href="https://redirect.github.com/agentclientprotocol/codex-acp/issues/413">#413</a>) (<a href="https://github.com/agentclientprotocol/codex-acp/commit/39af81c29b79a85f878db096f9cb593b6d1c7429">39af81c</a>)</li> </ul> <h2>v1.5.1</h2> <h2><a href="https://github.com/agentclientprotocol/codex-acp/compare/v1.5.0...v1.5.1">1.5.1</a> (2026-08-19)</h2> <h3>Bug Fixes</h3> <ul> <li>update codex to 0.148.0 (<a href="https://redirect.github.com/agentclientprotocol/codex-acp/issues/410">#410</a>) (<a href="https://github.com/agentclientprotocol/codex-acp/commit/3616954dc0e24af83b512adb618d7acbc5b98de5">3616954</a>)</li> </ul> <h2>v1.5.0</h2> <h2><a href="https://github.com/agentclientprotocol/codex-acp/compare/v1.4.0...v1.5.0">1.5.0</a> (2026-08-17)</h2> <h3>Features</h3> <ul> <li>switch providers for loaded Codex sessions (<a href="https://redirect.github.com/agentclientprotocol/codex-acp/issues/404">#404</a>) (<a href="https://github.com/agentclientprotocol/codex-acp/commit/47b57da5641a04df9aeeedc254a3aef53a9497da">47b57da</a>)</li> </ul> <h2>v1.4.0</h2> <h2><a href="https://github.com/agentclientprotocol/codex-acp/compare/v1.3.0...v1.4.0">1.4.0</a> (2026-08-16)</h2> <h3>Features</h3> <ul> <li>report changed files to AIR (<a href="https://redirect.github.com/agentclientprotocol/codex-acp/issues/403">#403</a>) (<a href="https://github.com/agentclientprotocol/codex-acp/commit/e305394d3f001f21e600597f41a3bee3d4530762">e305394</a>)</li> </ul> <h2>v1.3.0</h2> <h2><a href="https://github.com/agentclientprotocol/codex-acp/compare/v1.2.0...v1.3.0">1.3.0</a> (2026-08-14)</h2> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/agentclientprotocol/codex-acp/blob/main/CHANGELOG.md">@agentclientprotocol/codex-acp's changelog</a>.</em></p> <blockquote> <h2><a href="https://github.com/agentclientprotocol/codex-acp/compare/v1.6.1...v1.6.2">1.6.2</a> (2026-08-19)</h2> <h3>Bug Fixes</h3> <ul> <li>right-size the apt timeouts so a slow mirror still finishes (<a href="https://github.com/agentclientprotocol/codex-acp/commit/86e0772204a07d6fc4a8853c523ceb5006431f88">86e0772</a>)</li> </ul> <h2><a href="https://github.com/agentclientprotocol/codex-acp/compare/v1.6.0...v1.6.1">1.6.1</a> (2026-08-19)</h2> <h3>Bug Fixes</h3> <ul> <li>kill stalled apt from outside and serialize the unit suite (<a href="https://github.com/agentclientprotocol/codex-acp/commit/51e011fef27b812b238bf29c2a815f8ad149fa87">51e011f</a>)</li> </ul> <h2><a href="https://github.com/agentclientprotocol/codex-acp/compare/v1.5.1...v1.6.0">1.6.0</a> (2026-08-19)</h2> <h3>Features</h3> <ul> <li>harden release pipeline against hangs and e2e flakes (<a href="https://redirect.github.com/agentclientprotocol/codex-acp/issues/413">#413</a>) (<a href="https://github.com/agentclientprotocol/codex-acp/commit/39af81c29b79a85f878db096f9cb593b6d1c7429">39af81c</a>)</li> </ul> <h2><a href="https://github.com/agentclientprotocol/codex-acp/compare/v1.5.0...v1.5.1">1.5.1</a> (2026-08-19)</h2> <h3>Bug Fixes</h3> <ul> <li>update codex to 0.148.0 (<a href="https://redirect.github.com/agentclientprotocol/codex-acp/issues/410">#410</a>) (<a href="https://github.com/agentclientprotocol/codex-acp/commit/3616954dc0e24af83b512adb618d7acbc5b98de5">3616954</a>)</li> </ul> <h2><a href="https://github.com/agentclientprotocol/codex-acp/compare/v1.4.0...v1.5.0">1.5.0</a> (2026-08-17)</h2> <h3>Features</h3> <ul> <li>switch providers for loaded Codex sessions (<a href="https://redirect.github.com/agentclientprotocol/codex-acp/issues/404">#404</a>) (<a href="https://github.com/agentclientprotocol/codex-acp/commit/47b57da5641a04df9aeeedc254a3aef53a9497da">47b57da</a>)</li> </ul> <h2><a href="https://github.com/agentclientprotocol/codex-acp/compare/v1.3.0...v1.4.0">1.4.0</a> (2026-08-16)</h2> <h3>Features</h3> <ul> <li>report changed files to AIR (<a href="https://redirect.github.com/agentclientprotocol/codex-acp/issues/403">#403</a>) (<a href="https://github.com/agentclientprotocol/codex-acp/commit/e305394d3f001f21e600597f41a3bee3d4530762">e305394</a>)</li> </ul> <h2><a href="https://github.com/agentclientprotocol/codex-acp/compare/v1.2.0...v1.3.0">1.3.0</a> (2026-08-14)</h2> <h3>Features</h3> <ul> <li>add versioned context compaction metadata (<a href="https://redirect.github.com/agentclientprotocol/codex-acp/issues/396">#396</a>) (<a href="https://github.com/agentclientprotocol/codex-acp/commit/c4a9311f60a638e3a4b03a475afff1d7678e594f">c4a9311</a>)</li> <li>align typed session failures with AIR protocol (<a href="https://redirect.github.com/agentclientprotocol/codex-acp/issues/393">#393</a>) (<a href="https://github.com/agentclientprotocol/codex-acp/commit/e4fb92fffd8b8b9db9b40591ccbdb375c9f3f525">e4fb92f</a>)</li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/agentclientprotocol/codex-acp/commit/9780d314d34616b476b1ae451ad31089b3dce49a"><code>9780d31</code></a> chore(main): release 1.6.2 (<a href="https://redirect.github.com/agentclientprotocol/codex-acp/issues/417">#417</a>)</li> <li><a href="https://github.com/agentclientprotocol/codex-acp/commit/86e0772204a07d6fc4a8853c523ceb5006431f88"><code>86e0772</code></a> fix: right-size the apt timeouts so a slow mirror still finishes</li> <li><a href="https://github.com/agentclientprotocol/codex-acp/commit/096f5a88501db50c4420726e84c39f60f08c457f"><code>096f5a8</code></a> chore(main): release 1.6.1 (<a href="https://redirect.github.com/agentclientprotocol/codex-acp/issues/416">#416</a>)</li> <li><a href="https://github.com/agentclientprotocol/codex-acp/commit/51e011fef27b812b238bf29c2a815f8ad149fa87"><code>51e011f</code></a> fix: kill stalled apt from outside and serialize the unit suite</li> <li><a href="https://github.com/agentclientprotocol/codex-acp/commit/50bd611451c02868cc2b50bd6a7fc61ae5ef9b41"><code>50bd611</code></a> chore(main): release 1.6.0 (<a href="https://redirect.github.com/agentclientprotocol/codex-acp/issues/414">#414</a>)</li> <li><a href="https://github.com/agentclientprotocol/codex-acp/commit/39af81c29b79a85f878db096f9cb593b6d1c7429"><code>39af81c</code></a> feat: harden release pipeline against hangs and e2e flakes (<a href="https://redirect.github.com/agentclientprotocol/codex-acp/issues/413">#413</a>)</li> <li><a href="https://github.com/agentclientprotocol/codex-acp/commit/ad658e6ec64e8b70c455b10457ccc34f77173c9b"><code>ad658e6</code></a> chore(main): release 1.5.1 (<a href="https://redirect.github.com/agentclientprotocol/codex-acp/issues/412">#412</a>)</li> <li><a href="https://github.com/agentclientprotocol/codex-acp/commit/3616954dc0e24af83b512adb618d7acbc5b98de5"><code>3616954</code></a> fix: update codex to 0.148.0 (<a href="https://redirect.github.com/agentclientprotocol/codex-acp/issues/410">#410</a>)</li> <li><a href="https://github.com/agentclientprotocol/codex-acp/commit/3d5682722545a4b2d7cfcf8bdabbbfadbdaa37ea"><code>3d56827</code></a> chore(main): release 1.5.0 (<a href="https://redirect.github.com/agentclientprotocol/codex-acp/issues/409">#409</a>)</li> <li><a href="https://github.com/agentclientprotocol/codex-acp/commit/47b57da5641a04df9aeeedc254a3aef53a9497da"><code>47b57da</code></a> feat: switch providers for loaded Codex sessions (<a href="https://redirect.github.com/agentclientprotocol/codex-acp/issues/404">#404</a>)</li> <li>Additional commits viewable in <a href="https://github.com/agentclientprotocol/codex-acp/compare/v1.2.0...v1.6.2">compare view</a></li> </ul> </details> <br /> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |
||
|
|
b858fc7248 |
build(deps): bump @codemirror/view from 6.43.8 to 6.43.9 (#11879)
Bumps [@codemirror/view](https://github.com/codemirror/view) from 6.43.8 to 6.43.9. <details> <summary>Commits</summary> <ul> <li>See full diff in <a href="https://github.com/codemirror/view/commits">compare view</a></li> </ul> </details> <br /> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |
||
|
|
30f9888d3f |
build(deps-dev): bump storybook from 10.5.5 to 10.5.10 (#11884)
Bumps [storybook](https://github.com/storybookjs/storybook/tree/HEAD/code/core) from 10.5.5 to 10.5.10. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/storybookjs/storybook/releases">storybook's releases</a>.</em></p> <blockquote> <h2>v10.5.10</h2> <h2>10.5.10</h2> <ul> <li>Core: Fetch static open-service snapshots relative to the document - <a href="https://redirect.github.com/storybookjs/storybook/pull/35945">#35945</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Core: Pin oxc-resolver to 11.21.2 to keep tsconfig path aliases on solution-style tsconfigs - <a href="https://redirect.github.com/storybookjs/storybook/pull/35929">#35929</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Dependencies: Bump Vitest to 4.1.6 (CVE-2026-47428) - <a href="https://redirect.github.com/storybookjs/storybook/pull/35530">#35530</a>, thanks <a href="https://github.com/anupamme"><code>@anupamme</code></a>!</li> <li>Docs: Declare the font on overlay surfaces so docs tooltips are not left to inherit - <a href="https://redirect.github.com/storybookjs/storybook/pull/35966">#35966</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>ESLint Plugin: Bundle CSF helpers so the plugin loads without storybook - <a href="https://redirect.github.com/storybookjs/storybook/pull/35950">#35950</a>, thanks <a href="https://github.com/ndelangen"><code>@ndelangen</code></a>!</li> <li>React: Preserve discriminated union prop values in metadata extraction - <a href="https://redirect.github.com/storybookjs/storybook/pull/35844">#35844</a>, thanks <a href="https://github.com/s-robertson"><code>@s-robertson</code></a>!</li> </ul> <h2>v10.5.9</h2> <h2>10.5.9</h2> <ul> <li>Addon-Pseudo-States: Fix pseudo-states rewriting for nested functional selectors - <a href="https://redirect.github.com/storybookjs/storybook/pull/34318">#34318</a>, thanks <a href="https://github.com/filipw01"><code>@filipw01</code></a>!</li> <li>Core: Skip module-graph reverse-index mirror when a patch is a no-op - <a href="https://redirect.github.com/storybookjs/storybook/pull/35825">#35825</a>, thanks <a href="https://github.com/ndelangen"><code>@ndelangen</code></a>!</li> <li>Core: Split module-graph into hot revisions and cold index services - <a href="https://redirect.github.com/storybookjs/storybook/pull/35831">#35831</a>, thanks <a href="https://github.com/ndelangen"><code>@ndelangen</code></a>!</li> <li>Preview: Fix crash when initialising UrlStore on a docs path - <a href="https://redirect.github.com/storybookjs/storybook/pull/35521">#35521</a>, thanks <a href="https://github.com/TheSeydiCharyyev"><code>@TheSeydiCharyyev</code></a>!</li> <li>Pseudo-States: Make stylesheet rewrites WebKit-safe - <a href="https://redirect.github.com/storybookjs/storybook/pull/35629">#35629</a>, thanks <a href="https://github.com/ethriel3695"><code>@ethriel3695</code></a>!</li> <li>TanStack: Keep the layout id when cloning a standalone index file route - <a href="https://redirect.github.com/storybookjs/storybook/pull/35660">#35660</a>, thanks <a href="https://github.com/Insik-Han"><code>@Insik-Han</code></a>!</li> <li>TanStack: Render real link hrefs in the Link mock - <a href="https://redirect.github.com/storybookjs/storybook/pull/35505">#35505</a>, thanks <a href="https://github.com/unpunnyfuns"><code>@unpunnyfuns</code></a>!</li> <li>Webpack: Prevent long preview output filenames - <a href="https://redirect.github.com/storybookjs/storybook/pull/35533">#35533</a>, thanks <a href="https://github.com/zhangli091011"><code>@zhangli091011</code></a>!</li> </ul> <h2>v10.5.8</h2> <h2>10.5.8</h2> <ul> <li>React: Fix RDT tsconfig selection for Vite project references - <a href="https://redirect.github.com/storybookjs/storybook/pull/35743">#35743</a>, thanks <a href="https://github.com/ndelangen"><code>@ndelangen</code></a>!</li> <li>Tanstack React: Remove <code>@cloudflare/vite-plugin</code> from the inherited Vite config - <a href="https://redirect.github.com/storybookjs/storybook/pull/35706">#35706</a>, thanks <a href="https://github.com/FrancoKaddour"><code>@FrancoKaddour</code></a>!</li> <li>Tanstack: Wait for router to load before rendering - <a href="https://redirect.github.com/storybookjs/storybook/pull/35784">#35784</a>, thanks <a href="https://github.com/huang-julien"><code>@huang-julien</code></a>!</li> <li>Test: Fix Illegal invocation when reading prototype.focus - <a href="https://redirect.github.com/storybookjs/storybook/pull/35528">#35528</a>, thanks <a href="https://github.com/FrancoKaddour"><code>@FrancoKaddour</code></a>!</li> </ul> <h2>v10.5.7</h2> <h2>10.5.7</h2> <ul> <li>Angular: Serve ancestor node_modules for addon-vitest in browser mode - <a href="https://redirect.github.com/storybookjs/storybook/pull/35600">#35600</a>, thanks <a href="https://github.com/brandonroberts"><code>@brandonroberts</code></a>!</li> <li>Refactor: Update getVersionedPackages method to handle non-Storybook packages correctly - <a href="https://redirect.github.com/storybookjs/storybook/pull/35769">#35769</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> </ul> <h2>v10.5.6</h2> <h2>10.5.6</h2> <ul> <li>Dependencies: Pin `@testing-library/jest-dom` to `6.9.1` - <a href="https://redirect.github.com/storybookjs/storybook/pull/35614">#35614</a>, thanks <a href="https://github.com/ndelangen"><code>@ndelangen</code></a>!</li> <li>ESLint Plugin: Add plugin meta and document oxlint usage - <a href="https://redirect.github.com/storybookjs/storybook/pull/35655">#35655</a>, thanks <a href="https://github.com/yannbf"><code>@yannbf</code></a>!</li> <li>Vue: Skip docgen for module ids carrying a query - <a href="https://redirect.github.com/storybookjs/storybook/pull/35598">#35598</a>, thanks <a href="https://github.com/seanogdev"><code>@seanogdev</code></a>!</li> </ul> </blockquote> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/storybookjs/storybook/blob/next/CHANGELOG.md">storybook's changelog</a>.</em></p> <blockquote> <h2>10.5.10</h2> <ul> <li>Core: Fetch static open-service snapshots relative to the document - <a href="https://redirect.github.com/storybookjs/storybook/pull/35945">#35945</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Core: Pin oxc-resolver to 11.21.2 to keep tsconfig path aliases on solution-style tsconfigs - <a href="https://redirect.github.com/storybookjs/storybook/pull/35929">#35929</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Dependencies: Bump Vitest to 4.1.6 (CVE-2026-47428) - <a href="https://redirect.github.com/storybookjs/storybook/pull/35530">#35530</a>, thanks <a href="https://github.com/anupamme"><code>@anupamme</code></a>!</li> <li>Docs: Declare the font on overlay surfaces so docs tooltips are not left to inherit - <a href="https://redirect.github.com/storybookjs/storybook/pull/35966">#35966</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>ESLint Plugin: Bundle CSF helpers so the plugin loads without storybook - <a href="https://redirect.github.com/storybookjs/storybook/pull/35950">#35950</a>, thanks <a href="https://github.com/ndelangen"><code>@ndelangen</code></a>!</li> <li>React: Preserve discriminated union prop values in metadata extraction - <a href="https://redirect.github.com/storybookjs/storybook/pull/35844">#35844</a>, thanks <a href="https://github.com/s-robertson"><code>@s-robertson</code></a>!</li> </ul> <h2>10.5.9</h2> <ul> <li>Addon-Pseudo-States: Fix pseudo-states rewriting for nested functional selectors - <a href="https://redirect.github.com/storybookjs/storybook/pull/34318">#34318</a>, thanks <a href="https://github.com/filipw01"><code>@filipw01</code></a>!</li> <li>Core: Skip module-graph reverse-index mirror when a patch is a no-op - <a href="https://redirect.github.com/storybookjs/storybook/pull/35825">#35825</a>, thanks <a href="https://github.com/ndelangen"><code>@ndelangen</code></a>!</li> <li>Core: Split module-graph into hot revisions and cold index services - <a href="https://redirect.github.com/storybookjs/storybook/pull/35831">#35831</a>, thanks <a href="https://github.com/ndelangen"><code>@ndelangen</code></a>!</li> <li>Preview: Fix crash when initialising UrlStore on a docs path - <a href="https://redirect.github.com/storybookjs/storybook/pull/35521">#35521</a>, thanks <a href="https://github.com/TheSeydiCharyyev"><code>@TheSeydiCharyyev</code></a>!</li> <li>Pseudo-States: Make stylesheet rewrites WebKit-safe - <a href="https://redirect.github.com/storybookjs/storybook/pull/35629">#35629</a>, thanks <a href="https://github.com/ethriel3695"><code>@ethriel3695</code></a>!</li> <li>TanStack: Keep the layout id when cloning a standalone index file route - <a href="https://redirect.github.com/storybookjs/storybook/pull/35660">#35660</a>, thanks <a href="https://github.com/Insik-Han"><code>@Insik-Han</code></a>!</li> <li>TanStack: Render real link hrefs in the Link mock - <a href="https://redirect.github.com/storybookjs/storybook/pull/35505">#35505</a>, thanks <a href="https://github.com/unpunnyfuns"><code>@unpunnyfuns</code></a>!</li> <li>Webpack: Prevent long preview output filenames - <a href="https://redirect.github.com/storybookjs/storybook/pull/35533">#35533</a>, thanks <a href="https://github.com/zhangli091011"><code>@zhangli091011</code></a>!</li> </ul> <h2>10.5.8</h2> <ul> <li>React: Fix RDT tsconfig selection for Vite project references - <a href="https://redirect.github.com/storybookjs/storybook/pull/35743">#35743</a>, thanks <a href="https://github.com/ndelangen"><code>@ndelangen</code></a>!</li> <li>Tanstack React: Remove <code>@cloudflare/vite-plugin</code> from the inherited Vite config - <a href="https://redirect.github.com/storybookjs/storybook/pull/35706">#35706</a>, thanks <a href="https://github.com/FrancoKaddour"><code>@FrancoKaddour</code></a>!</li> <li>Tanstack: Wait for router to load before rendering - <a href="https://redirect.github.com/storybookjs/storybook/pull/35784">#35784</a>, thanks <a href="https://github.com/huang-julien"><code>@huang-julien</code></a>!</li> <li>Test: Fix Illegal invocation when reading prototype.focus - <a href="https://redirect.github.com/storybookjs/storybook/pull/35528">#35528</a>, thanks <a href="https://github.com/FrancoKaddour"><code>@FrancoKaddour</code></a>!</li> </ul> <h2>10.5.7</h2> <ul> <li>Angular: Serve ancestor node_modules for addon-vitest in browser mode - <a href="https://redirect.github.com/storybookjs/storybook/pull/35600">#35600</a>, thanks <a href="https://github.com/brandonroberts"><code>@brandonroberts</code></a>!</li> <li>Refactor: Update getVersionedPackages method to handle non-Storybook packages correctly - <a href="https://redirect.github.com/storybookjs/storybook/pull/35769">#35769</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> </ul> <h2>10.5.6</h2> <ul> <li>Dependencies: Pin <code>@testing-library/jest-dom</code> to <code>6.9.1</code> - <a href="https://redirect.github.com/storybookjs/storybook/pull/35614">#35614</a>, thanks <a href="https://github.com/ndelangen"><code>@ndelangen</code></a>!</li> <li>ESLint Plugin: Add plugin meta and document oxlint usage - <a href="https://redirect.github.com/storybookjs/storybook/pull/35655">#35655</a>, thanks <a href="https://github.com/yannbf"><code>@yannbf</code></a>!</li> <li>Vue: Skip docgen for module ids carrying a query - <a href="https://redirect.github.com/storybookjs/storybook/pull/35598">#35598</a>, thanks <a href="https://github.com/seanogdev"><code>@seanogdev</code></a>!</li> </ul> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/storybookjs/storybook/commit/a2db7526e1538a48bfa0529a881822e8074b2009"><code>a2db752</code></a> Bump version from "10.5.9" to "10.5.10" [skip ci]</li> <li><a href="https://github.com/storybookjs/storybook/commit/de77b083828f955353342f949a2ce9aa2e68ff94"><code>de77b08</code></a> Merge pull request <a href="https://github.com/storybookjs/storybook/tree/HEAD/code/core/issues/35929">#35929</a> from storybookjs/valentin/sb-1821-pin-oxc-resolver</li> <li><a href="https://github.com/storybookjs/storybook/commit/374b8b345112e221df9b82f978afff42d7c6da0c"><code>374b8b3</code></a> Merge pull request <a href="https://github.com/storybookjs/storybook/tree/HEAD/code/core/issues/35966">#35966</a> from storybookjs/valentin/docs-overlay-typography</li> <li><a href="https://github.com/storybookjs/storybook/commit/2148cdd5afa2ad069c4f8ec999f4234df64a69ca"><code>2148cdd</code></a> Merge pull request <a href="https://github.com/storybookjs/storybook/tree/HEAD/code/core/issues/35950">#35950</a> from storybookjs/fix/eslint-plugin-bundle-csf</li> <li><a href="https://github.com/storybookjs/storybook/commit/b336e8f5c12e7f0cd72e02e52ad025269f42653c"><code>b336e8f</code></a> Merge pull request <a href="https://github.com/storybookjs/storybook/tree/HEAD/code/core/issues/35945">#35945</a> from storybookjs/valentin/static-services-subpath-f...</li> <li><a href="https://github.com/storybookjs/storybook/commit/8f561048949b3ce3674a71711942177a14e4e8f9"><code>8f56104</code></a> Bump version from "10.5.8" to "10.5.9" [skip ci]</li> <li><a href="https://github.com/storybookjs/storybook/commit/f31554b81e167897a4d017930508ec977f31f092"><code>f31554b</code></a> Backport the module-graph hot/cold split and no-op index skip to 10.5.9.</li> <li><a href="https://github.com/storybookjs/storybook/commit/c1db83aae8bea708d718e84f4ef63e6ac53a3a46"><code>c1db83a</code></a> Merge pull request <a href="https://github.com/storybookjs/storybook/tree/HEAD/code/core/issues/35521">#35521</a> from TheSeydiCharyyev/fix/35436-urlstore-docs-path</li> <li><a href="https://github.com/storybookjs/storybook/commit/6ef7d1ae816ebd5fb8bf84b8dec7d4a92410d73c"><code>6ef7d1a</code></a> Bump version from "10.5.7" to "10.5.8" [skip ci]</li> <li><a href="https://github.com/storybookjs/storybook/commit/647e982151f1bb4e15163b0d2a31c5a1022efda3"><code>647e982</code></a> Merge pull request <a href="https://github.com/storybookjs/storybook/tree/HEAD/code/core/issues/35743">#35743</a> from storybookjs/norbert/revive-34415-file-aware-ts...</li> <li>Additional commits viewable in <a href="https://github.com/storybookjs/storybook/commits/v10.5.10/code/core">compare view</a></li> </ul> </details> <br /> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>canary/v2026.825.0-canary.10 |
||
|
|
2862e18484 |
refactor(adapter-utils): remove the retired duplex_v1 sandbox bridge transport (#12171)
## Thinking Path > - Paperclip is the open source app people use to manage AI agents for work > - The adapter utilities provide sandbox transport paths for agent execution > - The retired `duplex_v1` path remains in host, gateway, and test code after `http2_v1` replaced it > - Retired transport code adds maintenance cost and leaves an unsafe fallback for unknown gateway modes > - This pull request removes the retired path, moves shared `http2_v1` contracts to a leaf module, and closes mode dispatch to a fixed allowlist > - The benefit is a smaller transport surface and explicit failure for unsupported modes ## Linked Issues or Issue Description Refs #12120 The `http2_v1` transport replaced `duplex_v1`, but the retired broker, gateway, constants, and tests remain in the adapter utilities. An unknown bridge mode can also fall through to the queue gateway when a queue directory exists. This change removes the retired code and rejects unsupported modes before gateway selection. ## What Changed - Delete the host `duplex_v1` broker and its transport-only tests. - Delete the in-sandbox duplex gateway and retired mode constants. - Move shared `http2_v1` symbols into `bridge-transport-contract.ts`. - Update the remaining importers and repair their focused tests. - Validate bridge modes against `http2_v1` and `queue_v1` before queue lookup. - Keep `queue_v1`, `duplex-frame-codec.ts`, and duplex telemetry dimensions unchanged. ## Verification - [x] `npx tsc --noEmit -p packages/adapter-utils` passes. - [x] `npx vitest run packages/adapter-utils/src` passes: 48 files and 968 tests pass, with 4 pre-existing platform skips. - [x] Full CI is green on this pull request. - [x] Greptile review is complete and every finding is resolved. ## Risks The change removes an internal transport that no host path selects. The main risk is an overlooked import or test dependency. Targeted typecheck and tests cover the adapter utility package. Full CI must confirm workspace-wide compatibility. ## Model Used Anthropic Claude Sonnet 5 assisted with the implementation, as recorded in the commit. The commit does not record a context-window size or reasoning mode. ## Checklist - [x] I have included a thinking path that traces from project context to this change - [x] I have specified the model used (with version and capability details) - [x] I have checked ROADMAP.md and confirmed this PR does not duplicate planned core work - [x] I have searched GitHub for duplicate or related PRs and linked them above - [x] I have either (a) linked existing issues with `Fixes: #` / `Closes #` / `Refs #` OR (b) described the issue in-PR following the relevant issue template - [x] I have not referenced internal/instance-local Paperclip issues or links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip` URLs) - [x] My branch name describes the change (e.g. `docs/...`, `fix/...`) and contains no internal Paperclip ticket id or instance-derived details - [x] I have run tests locally and they pass - [x] I have added or updated tests where applicable - [x] I have updated relevant documentation to reflect my changes - [x] I have considered and documented any risks above - [x] All Paperclip CI gates are green - [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups - [x] I will address all Greptile and reviewer comments before requesting merge Co-authored-by: Paperclip <noreply@paperclip.ing>canary/v2026.825.0-canary.9 |
||
|
|
02a984068c |
refactor(adapter-utils): clean up the HTTP/2 bridge request-body bounds (#12166)
## Thinking Path > - Paperclip is the open source app people use to manage AI agents for work > - Agent adapters use the HTTP/2 bridge to carry requests and responses > - The bridge has an idle bound and a total-lifetime ceiling for request bodies > - The old renewable lifetime bound re-armed with each DATA chunk and could not act before the idle bound > - The code also repeated the same bounds and rationale in several places > - This pull request removes the unreachable renewable bound, keeps the one-shot ceiling, and simplifies the shared bounds object > - The benefit is clearer protection logic with the same default request-body behavior ## Linked Issues or Issue Description **What existing behavior does this improve?** The HTTP/2 bridge request-body reader uses several repeated bound parameters and comments. One renewable lifetime bound cannot act before the idle bound under the shipped defaults. **Subsystem affected** `packages/adapter-utils/` — HTTP/2 bridge adapter utilities. **Current behavior** The idle bound and renewable lifetime bound both re-arm after each DATA chunk. The renewable bound therefore does not act on its own. The total-lifetime ceiling also shares timer setup with the renewable bound. **Proposed behavior** Remove the renewable lifetime bound. Keep the total-lifetime ceiling as an independent one-shot timer. Pass one bounds object to the bridge call sites and keep tests for the idle bound and total-lifetime ceiling. **Reason and benefit** The change removes unreachable logic and repeated rationale. It keeps the independent total-lifetime protection and makes the bound behavior easier to review. **Breaking changes** The change removes two public constant and option names that repository-wide search found unused outside this implementation. The shipped default behavior does not change. ## What Changed - Remove the renewable request-body lifetime bound and its public names. - Keep the total-lifetime ceiling as a one-shot timer that starts when the body read starts. - Replace repeated bound parameters with one `Http2BridgeBodyBounds` object. - De-duplicate bound rationale comments. - Add shared test helpers and update tests for the idle bound and total-lifetime ceiling. ## Verification - Run `npx tsc --noEmit -p packages/adapter-utils`. - Run `npx vitest run packages/adapter-utils/src/http2-bridge-server.test.ts`. - Wait for the pull request CI checks. - Request the Greptile review and confirm a 5/5 verdict with no open findings. ## Risks The main risk is an incorrect timer lifetime after the renewable timer removal. The one-shot ceiling remains independent, and the updated tests cover its expiry and cleanup paths. The change does not alter the shipped default bounds. ## Model Used OpenAI Codex based on GPT-5. Exact runtime model version is GPT-5. The work used tool calls and code execution for repository inspection and GitHub operations. ## Checklist - [x] I have included a thinking path that traces from project context to this change - [x] I have specified the model used (with version and capability details) - [x] I have checked ROADMAP.md and confirmed this PR does not duplicate planned core work - [x] I have searched GitHub for duplicate or related PRs and linked them above - [x] I have either (a) linked existing issues with `Fixes: #` / `Closes #` / `Refs #` OR (b) described the issue in-PR following the relevant issue template - [x] I have not referenced internal/instance-local Paperclip issues or links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip` URLs) - [x] My branch name describes the change (e.g. `docs/...`, `fix/...`) and contains no internal Paperclip ticket id or instance-derived details - [x] I have run tests locally and they pass - [x] I have added or updated tests where applicable - [x] I have updated relevant documentation to reflect my changes - [x] I have considered and documented any risks above - [x] All Paperclip CI gates are green - [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups - [x] I will address all Greptile and reviewer comments before requesting merge Co-authored-by: Paperclip <noreply@paperclip.ing>canary/v2026.825.0-canary.8 |
||
|
|
445547c989 |
feat(duplex): run the Daytona sandbox callback bridge over Node HTTP/2 (#12120)
## Thinking Path > - Paperclip is the open source app people use to manage AI agents for work > - Sandbox providers carry agent work through controlled execution channels > - The Daytona callback bridge uses a bespoke line-framed protocol over its duplex channel > - The bespoke protocol adds framing work and does not use the Node transport that already supports multiplexed streams > - This pull request carries raw bytes across the channel, adds a Node HTTP/2 bridge, and selects it for Daytona > - The benefit is one authenticated, multiplexed callback session with queue_v1 as the bounded fallback ## Linked Issues or Issue Description **Subsystem affected** The packages/plugins Daytona provider and the shared duplex execution path. **Problem or motivation** The Daytona callback bridge uses a bespoke line-framed protocol over the provider duplex channel. This adds protocol work and limits stream handling. **Proposed solution** Carry raw bytes through the cross-layer channel. Add an authenticated Node HTTP/2 host server and sandbox client gateway. Select http2_v1 for Daytona and retain queue_v1 as the fallback. **Alternatives considered** Keep the current duplex_v1 protocol. This keeps the bespoke framing path and does not provide one HTTP/2 session for callback streams. **Roadmap alignment** ROADMAP.md lists Daytona under cloud and sandbox agents. This change improves the shipped Daytona provider path. **Additional context** The branch adds no dependency. Node 24 provides the http2 module. The host token check and canonical path parser remain the single dispatch path. ## What Changed - Carry raw Uint8Array chunks through the adapter, plugin, worker, runtime, and Daytona layers. - Encode bytes as base64 only across the JSON-RPC hop, because JSON has no binary type. - Add the bounded host HTTP/2 server and the in-sandbox HTTP/2 client gateway. - Authenticate every stream with the per-run bridge token before route work. - Parse the path once and reuse the canonical result for route and forwarding work. - Select http2_v1 for Daytona and fall back once to queue_v1 when the client preface is absent. - Add transport, session, stream, and fallback telemetry. - Mark HTTP/2 as the preferred transport and queue_v1 as the soft-deprecated fallback. ## Verification - `npx vitest run packages/adapter-utils/src` — 990 passed and 4 skipped. - `npx vitest run server/src/__tests__/plugin-worker-manager-duplex.test.ts` — 32 passed. - `npx vitest run --config packages/plugins/sandbox-providers/daytona/vitest.config.ts` — 220 passed and 6 skipped. - `npx tsc --noEmit` in `packages/adapter-utils`, `packages/shared`, `packages/plugins/sdk`, and `server` — clean. - No `package.json` or `pnpm-lock.yaml` file changed. - The live Daytona test skips when `DAYTONA_API_KEY` is absent. - The root `npx tsc --noEmit` command has a pre-existing missing `packages/adapters/droid-local` reference on this branch and on `master`. ## Risks - The transport change affects several duplex layers and could expose byte-boundary errors. - A missing HTTP/2 client preface falls back once to queue_v1 and records `preface_missing`. - The host token check and canonical path parser must remain on the shared dispatch path. - The live Daytona test needs `DAYTONA_API_KEY` and does not run in this agent sandbox. ## Model Used OpenAI GPT-5, tool-enabled coding agent with repository inspection, GitHub CLI, and shell execution. ## Checklist - [x] I have included a thinking path that traces from project context to this change - [x] I have specified the model used (with version and capability details) - [x] I have checked ROADMAP.md and confirmed this PR does not duplicate planned core work - [x] I have searched GitHub for duplicate or related PRs and linked them above - [x] I have either (a) linked existing issues with `Fixes: #` / `Closes #` / `Refs #` OR (b) described the issue in-PR following the relevant issue template - [x] I have not referenced internal/instance-local Paperclip issues or links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip` URLs) - [x] My branch name describes the change (e.g. `docs/...`, `fix/...`) and contains no internal Paperclip ticket id or instance-derived details - [x] I have run tests locally and they pass - [x] I have added or updated tests where applicable - [x] I have updated relevant documentation to reflect my changes - [x] I have considered and documented any risks above - [x] All Paperclip CI gates are green - [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups - [x] I will address all Greptile and reviewer comments before requesting merge --------- Co-authored-by: Paperclip <noreply@paperclip.ing>canary/v2026.825.0-canary.7 |
||
|
|
0f0e544317 |
fix(cli): open dashboard after onboarding service starts (#12164)
## Thinking Path > - Paperclip is the open source app people use to manage AI agents for work. > - The CLI can install and start Paperclip as a managed user service during onboarding. > - Recent fixes now install the service shim and remove the redundant foreground start prompt. > - The service path still ends without a dashboard URL or an open browser. > - The server can also move to a free port when the configured port is busy. > - This pull request adds a health-aware handoff to the managed service's actual endpoint. > - The benefit is that new users can reach Paperclip without starting a second process. ## Linked Issues or Issue Description **What happened?** After interactive onboarding installs and starts the managed service, the command ends without printing the dashboard URL or opening the browser. If the configured port is busy, the service can use a fallback port that the onboarding process does not know. **Expected behavior** Onboarding must print the dashboard URL that belongs to the managed service. An interactive terminal should open the URL after the local health check succeeds. A non-interactive terminal should only print the URL. **Steps to reproduce** 1. Start from a host without an installed Paperclip service. 2. Run another process on the configured Paperclip port. 3. Run `npx paperclipai@<version> onboard` in an interactive terminal. 4. Accept the managed service installation. 5. Observe that the service starts on a fallback port, but onboarding does not provide or open that dashboard URL. **Paperclip version or commit** `b6854e61c` on `master`, after #12148, #12151, and #12153. **Deployment mode** Local managed user service on macOS or Linux. **Installation method** `npx paperclipai@<version> onboard`. The same onboarding path can also run after `install.sh`. Related public pull requests: #12148, #12151, and #12153. ## What Changed - Record each running CLI server's PID, selected port, and dashboard URL in atomic per-instance runtime metadata. - Accept runtime metadata only when its PID matches the active managed service. - Wait for the selected runtime endpoint to report healthy before printing its URL. - Open the URL in interactive terminals and keep headless runs browser-free. - Keep the printed configured URL as a fallback when runtime discovery fails. - Use browser-launch wording that only claims the URL was sent to the opener. - Add runtime metadata, fallback-port, health handoff, headless, and failure-path tests. - Document the managed service dashboard handoff. ## Verification - `pnpm exec vitest run cli/src/__tests__/onboard-service.test.ts cli/src/__tests__/runtime-info.test.ts cli/src/__tests__/onboard.test.ts cli/src/__tests__/open-url.test.ts cli/src/__tests__/service-health-check.test.ts` — 44 tests passed. - `node --test scripts/service-onboard-smoke.test.mjs` — 4 tests passed. - `pnpm -r typecheck` — passed on head `82920596a`. - `pnpm build` — passed on head `82920596a`. - `pnpm test:run` — 4,685 tests passed. The command also reported 31 failures in nine server test files outside this change. This machine generated invalid test ports above 65,535, and some project-skill fixtures resolved outside the worktree. ## Risks - Risk is low because the new handoff runs only after a successful service installation. - Onboarding can wait up to 60 seconds when runtime metadata or the health check does not become ready. - Runtime metadata is matched to the supervisor PID, so stale or foreground-process metadata is ignored. - A non-interactive terminal does not open a browser. - A failed health check or browser launch does not fail onboarding. The CLI keeps a manual URL visible. > For core feature work, check [`ROADMAP.md`](ROADMAP.md) first and discuss it in `#dev` before opening the PR. Feature PRs that overlap with planned core work may need to be redirected — check the roadmap first. See `CONTRIBUTING.md`. ## Model Used OpenAI Codex, GPT-5 family. The runtime did not expose the exact model ID or context window. The model used reasoning, repository tools, GitHub access, and code execution. ## Checklist - [x] I have included a thinking path that traces from project context to this change - [x] I have specified the model used (with version and capability details) - [x] I have checked ROADMAP.md and confirmed this PR does not duplicate planned core work - [x] I have searched GitHub for duplicate or related PRs and linked them above - [x] I have either (a) linked existing issues with `Fixes: #` / `Closes #` / `Refs #` OR (b) described the issue in-PR following the relevant issue template - [x] I have not referenced internal/instance-local Paperclip issues or links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip` URLs) - [x] My branch name describes the change (e.g. `docs/...`, `fix/...`) and contains no internal Paperclip ticket id or instance-derived details - [x] I have run tests locally and they pass - [x] I have added or updated tests where applicable - [x] I have updated relevant documentation to reflect my changes - [x] I have considered and documented any risks above - [x] All Paperclip CI gates are green - [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups - [x] I will address all Greptile and reviewer comments before requesting merge --------- Co-authored-by: Paperclip <noreply@paperclip.ing> |
||
|
|
ffff1fe6e3 |
feat(runner): define package API and verification boundary (#12129)
## Thinking Path > - Paperclip is the open source app people use to manage AI agents for work. > - The runner package now has protocol, transport, provider, catalog, and authorization foundations. > - Its first upstream package boundary should expose only the implemented runtime and test-helper surfaces. > - Rust correctness belongs in the repository existing build verification, without introducing a parallel release process. > - Direct package creation must build the files declared by the package manifest. > - This pull request defines the minimal package API and verifies the optimized runner binaries in the existing PR and release Build jobs. > - The benefit is a production-ready runner package boundary with minimal build-process change. ## Linked Issues or Issue Description Refs #11962 This pull request replaces one bounded part of the archived large runner change. It follows the package-local authorization change in #12126. ## What Changed - Export only `@paperclipai/paperclip-runner` and `@paperclipai/paperclip-runner/testing`. - Keep Node-only fixture loading and semantic conformance helpers out of the runtime root. - Add a provider-neutral semantic conformance kit with stable JSON comparison and fail-closed input checks. - Keep deferred SDK, eval, browser, React, lab, and command surfaces private. - Pin the runner Rust toolchain to 1.97.1 with the minimal profile and `rustfmt`. - Run the Rust workspace tests in release mode. - Launch the optimized `paperclip-runnerd` and fake-harness binaries in process-level integration coverage. - Add one `pnpm --filter @paperclipai/paperclip-runner check:all` step to each existing PR and release Build job. - Make the existing server `prepack` lifecycle run its existing build after it prepares UI assets. - Document that no production adapter starts runnerd yet. This revision adds no standalone GitHub Actions job. It adds no server runner dependency or runner vendoring. It adds no Docker bootstrap or clean-consumer harness. It does not change `pnpm-lock.yaml`. ## Verification - `pnpm --filter @paperclipai/paperclip-runner check:all` - 66 TypeScript tests - 8 protocol contract tests - 56 Rust unit and integration tests - Release-mode integration coverage launches the optimized runnerd and fake-harness binaries. - `pnpm --filter @paperclipai/server exec vitest run src/__tests__/server-package-build-script.test.ts` (2 tests) - Clean `pnpm pack` from `server/` rebuilt the server and produced both `package/dist/index.js` and `package/dist/index.d.ts`. - `node --test scripts/__tests__/release-verify-workflow.test.mjs` (8 tests) - `pnpm -r typecheck` - `pnpm build` - `pnpm check:token-gates` - `git diff --check` - No `pnpm-lock.yaml` diff. - The diff changes 12 files. ## Risks The runner adds Rust work to the existing Build jobs. These jobs can take longer on a cold cache. The pinned toolchain makes contributor and CI behavior reproducible. Cargo tests use `--release` to verify optimized executables. The server prepack lifecycle now performs the build that its published entry points require. This can make direct server packing slower. This pull request does not wire runnerd into the server. It does not select runnerd for any adapter. Existing application execution and finalization paths remain unchanged. ## Model Used OpenAI Codex with GPT-5. Agentic coding mode used repository tools, code execution, and automated tests. ## Checklist - [x] I have included a thinking path that traces from project context to this change - [x] I have specified the model used (with version and capability details) - [x] I have checked ROADMAP.md and confirmed this PR does not duplicate planned core work - [x] I have searched GitHub for duplicate or related PRs and linked them above - [x] I have either (a) linked existing issues with `Fixes: #` / `Closes #` / `Refs #` OR (b) described the issue in-PR following the relevant issue template - [x] I have not referenced internal/instance-local Paperclip issues or links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip` URLs) - [x] My branch name describes the change (e.g. `docs/...`, `fix/...`) and contains no internal Paperclip ticket id or instance-derived details - [x] I have run tests locally and they pass - [x] I have added or updated tests where applicable - [x] I have updated relevant documentation to reflect my changes - [x] I have considered and documented any risks above - [x] All Paperclip CI gates are green - [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups - [x] I will address all Greptile and reviewer comments before requesting merge Co-authored-by: Paperclip <noreply@paperclip.ing> |
||
|
|
b6854e61c7 |
refactor(adapter-utils): rename EffectiveSandboxCapabilities to EffectiveExecutionCapabilities (#12119)
## Thinking Path > - Paperclip is the open source app people use to manage AI agents for work > - The adapter utilities package defines shared types for agent execution targets > - The type name EffectiveSandboxCapabilities describes only one transport > - All execution target drivers return the same resolved capability snapshot > - This pull request gives the snapshot a general name and keeps the old type as a deprecated alias > - The benefit is clearer public vocabulary with source compatibility for current consumers ## Linked Issues or Issue Description **What existing behavior does this improve?** The exported capability snapshot type uses the name `EffectiveSandboxCapabilities`, although local, SSH, sandbox, and plugin drivers return it. **Subsystem affected** The change affects `packages/adapter-utils` and its server consumers. **Current behavior** The public type name points to the sandbox transport. The private parser also uses the sandbox-only name. **Proposed behavior** Use `EffectiveExecutionCapabilities` for the public type and `parseEffectiveExecutionCapabilities` for the private parser. Keep a deprecated alias for the old public type. **Reason and benefit** The new name matches the established execution-target vocabulary. The alias keeps existing type imports working during the migration. **Breaking changes** None. The runtime field, capability flags, parsed shape, and package versions do not change. **Additional context** GitHub search found no duplicate or related open issue or pull request. ## What Changed - Rename the exported interface to `EffectiveExecutionCapabilities`. - Keep `EffectiveSandboxCapabilities` as a deprecated type alias. - Rename the private parser and update its call site and references. - Add a type-level test for the deprecated alias. ## Verification - `npx tsc --noEmit -p packages/adapter-utils` - `npx vitest run packages/adapter-utils/src/execution-target-sandbox.test.ts` - `npx vitest run server/src/__tests__/environment-execution-target-capabilities.test.ts server/src/__tests__/environment-execution-target-duplex.test.ts` - The local checks passed with 133 adapter-utils tests and 31 server tests. - Reviewers can confirm that the runtime field and capability flags stay unchanged. ## Risks Low risk. The alias protects existing type imports. The change does not alter runtime behavior or serialized data. ## Model Used OpenAI Codex, GPT-5, tool use and code execution. The runtime does not expose the context window size. ## Checklist - [x] I have included a thinking path that traces from project context to this change - [x] I have specified the model used (with version and capability details) - [x] I have checked ROADMAP.md and confirmed this PR does not duplicate planned core work - [x] I have searched GitHub for duplicate or related PRs and linked them above - [x] I have either (a) linked existing issues with `Fixes: #` / `Closes #` / `Refs #` OR (b) described the issue in-PR following the relevant issue template - [x] I have not referenced internal/instance-local Paperclip issues or links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip` URLs) - [x] My branch name describes the change (e.g. `docs/...`, `fix/...`) and contains no internal Paperclip ticket id or instance-derived details - [x] I have run tests locally and they pass - [x] I have added or updated tests where applicable - [x] I have updated relevant documentation to reflect my changes - [x] I have considered and documented any risks above - [x] All Paperclip CI gates are green - [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups - [x] I will address all Greptile and reviewer comments before requesting merge --------- Co-authored-by: Paperclip <noreply@paperclip.ing>canary/v2026.825.0-canary.6 |
||
|
|
8d714c2d84 |
fix(cli): skip the foreground-start prompt after the service starts (#12153)
## Thinking Path > - Paperclip is the open source app people use to manage AI agents for work > - The CLI onboarding wizard can install Paperclip as a background service, and it offers a foreground start when nothing else will serve > - After #12148, an interactive onboard installs and starts the service, then still asks "Start Paperclip now?" > - Answering yes runs the foreground start into the already-running instance guard, so a fully successful onboard ends with an error message > - This pull request excludes the just-installed-service case from the foreground-start prompt > - The benefit is that an interactive onboard that installs the service ends cleanly instead of steering the user into a guard refusal ## Linked Issues or Issue Description Refs #12148 — found while verifying that fix interactively. The `shouldRunNow` flag already accounts for `serviceInstalled`, but the interactive TTY fallback prompt did not, so only real interactive runs hit it: `--yes` runs, CI, and container smokes all skip the prompt branch. **What happened?** Interactive `onboard`, accept the background-service prompt. Output ends with: service installed and started, then "Start Paperclip now?" → yes → "Paperclip instance 'default' is already running as ing.paperclip.paperclipai. Use 'paperclipai service status --instance default' or pass --force to bypass this safety check." **What did you expect to happen?** Onboarding ends cleanly after "Installed and started …" — there is nothing left to start, so no prompt. **Steps to reproduce** Run `npx paperclipai@2026.825.0-nightly.1 onboard --data-dir "$(mktemp -d)"` in a terminal, accept the service prompt, then accept "Start Paperclip now?". ## What Changed - New `shouldOfferForegroundStart` predicate in `cli/src/onboard-service.ts`: the foreground-start prompt is offered only when the start was not already decided by flags, the service was not just installed, onboarding was not invoked by `run`, and the terminal is interactive. - Both onboarding call sites in `cli/src/commands/onboard.ts` use the predicate instead of the inline condition that ignored `serviceInstalled`. - Unit tests cover the predicate matrix in `cli/src/__tests__/onboard-service.test.ts`. ## Verification - `npx vitest run src/__tests__/onboard-service.test.ts` in `cli/`: 12 passed (5 new). - `tsc --noEmit` reports no errors in the changed files (remaining errors are pre-existing in `server/`). - Manual reproduction of the defect on macOS with `2026.825.0-nightly.1` before the fix: service installed, started, and healthy, then the prompt steered into the guard refusal. ## Risks - Low risk. The prompt still appears in every case it did before except when the service was just installed and is already serving. - No behavior change for `--yes`, `--run`, `--install-service` in non-interactive runs: those paths never reached the prompt. ## Model Used - Claude Fable 5 (Anthropic, model ID `claude-fable-5`), extended thinking, agentic tool use via Claude Code. ## Checklist - [x] I have included a thinking path that traces from project context to this change - [x] I have specified the model used (with version and capability details) - [x] I have checked ROADMAP.md and confirmed this PR does not duplicate planned core work - [x] I have searched GitHub for duplicate or related PRs and linked them above - [x] I have either (a) linked existing issues with `Fixes: #` / `Closes #` / `Refs #` OR (b) described the issue in-PR following the relevant issue template - [x] I have not referenced internal/instance-local Paperclip issues or links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip` URLs) - [x] My branch name describes the change (e.g. `docs/...`, `fix/...`) and contains no internal Paperclip ticket id or instance-derived details - [x] I have run tests locally and they pass - [x] I have added or updated tests where applicable - [x] I have updated relevant documentation to reflect my changes - [x] I have considered and documented any risks above - [ ] All Paperclip CI gates are green - [ ] Greptile is 5/5 with no open P2s, recommendations, or follow-ups - [x] I will address all Greptile and reviewer comments before requesting mergecanary/v2026.825.0-canary.5 nightly/v2026.825.0-nightly.2 |
||
|
|
0a01444514 |
test(release-smoke): cover the background-service leg of onboarding (#12151)
## Thinking Path > - Paperclip is the open source app people use to manage AI agents for work > - The release pipeline gates each nightly and beta on a smoke suite that onboards the published npm artifact and drives the golden path > - That smoke runs onboarding inside a Docker container, and containers have no service manager, so the background-service leg of onboarding has zero automated coverage > - v2026.824.0 shipped a service install that crash-looped on a missing shim, and every smoke check stayed green (#12148 fixed the defect itself) > - This pull request adds a `smoke_service` job that runs the same published artifact directly on the runner VM's systemd and requires the installed service to end up serving > - The benefit is that a release with a broken service install can no longer pass the release smoke suite ## Linked Issues or Issue Description Refs #12148 — the fix for the defect this coverage gap let through. The gap: the release smoke runs `onboard` with `--yes` inside Docker, which both skips the service prompt and lacks systemd, so no CI job ever executed `manager.install()` against a real service manager. ## What Changed - New `scripts/service-onboard-smoke.sh`: onboards the published artifact with `--yes --install-service` on a systemd host, then fails unless the managed shim exists and is executable, `paperclipai.service` is active, and `/api/health` answers. A health response while the unit is not active also fails, because that is the signature of something other than the service serving. The script refuses to run over an existing managed install unless `SMOKE_FORCE=true`, and cleans up after itself by default so it is safe to run locally. - New `smoke_service` job in `.github/workflows/release-smoke.yml`: starts a user systemd session on the hosted runner (`loginctl enable-linger` + exported `XDG_RUNTIME_DIR`/`DBUS_SESSION_BUS_ADDRESS`), runs the script against `inputs.paperclip_version`, and uploads `systemctl status` + journal output as diagnostics. - No `release.yml` changes needed: `smoke_nightly` and `smoke_beta` call this reusable workflow, and a `workflow_call` result aggregates all jobs, so the new job gates nightly promotion automatically. ## Verification - `bash -n scripts/service-onboard-smoke.sh` passes and the workflow YAML parses. - End-to-end: dispatched this branch's Release Smoke workflow against the published canary that contains #12148; the `smoke_service` job onboards, installs the service, and verifies the service serves health. (Run link in PR comments.) - Negative case: the same assertions fail against v2026.824.0 — reproduced in a systemd container during the #12148 investigation: shim missing, unit in a 203/EXEC restart loop. ## Risks - Low risk to the product: no application code changes. - Pipeline risk: a flaky user-session setup on the hosted runner would block nightly promotion. Mitigated by validating the job end-to-end from this branch before merge, a 30-minute job timeout, and diagnostics uploaded on every run. - The service leg only covers systemd. launchd (macOS) still has no CI coverage; a macOS runner job is a possible follow-up. ## Model Used - Claude Fable 5 (Anthropic, model ID `claude-fable-5`), extended thinking, agentic tool use via Claude Code. ## Checklist - [x] I have included a thinking path that traces from project context to this change - [x] I have specified the model used (with version and capability details) - [x] I have checked ROADMAP.md and confirmed this PR does not duplicate planned core work - [x] I have searched GitHub for duplicate or related PRs and linked them above - [x] I have either (a) linked existing issues with `Fixes: #` / `Closes #` / `Refs #` OR (b) described the issue in-PR following the relevant issue template - [x] I have not referenced internal/instance-local Paperclip issues or links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip` URLs) - [x] My branch name describes the change (e.g. `docs/...`, `fix/...`) and contains no internal Paperclip ticket id or instance-derived details - [x] I have run tests locally and they pass - [x] I have added or updated tests where applicable - [x] I have updated relevant documentation to reflect my changes - [x] I have considered and documented any risks above - [ ] All Paperclip CI gates are green - [ ] Greptile is 5/5 with no open P2s, recommendations, or follow-ups - [x] I will address all Greptile and reviewer comments before requesting mergecanary/v2026.825.0-canary.4 |
||
|
|
faad235aa2 |
fix(cli): materialize the managed install before the onboarding service install (#12148)
## Thinking Path > - Paperclip is the open source app people use to manage AI agents for work > - Interactive onboarding offers to install Paperclip as a background service, defaulting to yes > - The service definition targets the managed command shim, but an ephemeral npx run never installs it, and the service step never checks > - The result is a crash-looping service, a doctor hint about a nonexistent port conflict, and a first run that ends with nothing serving > - This pull request materializes the managed install before registering the service, or declines with the repair path > - The benefit is that saying yes to the service prompt yields a working service — or an honest explanation ## Linked Issues or Issue Description **What happened?** On a machine with no managed install, `npx paperclipai@2026.824.0 onboard` (interactive), accepting the background-service prompt, produced: a LaunchAgent pointing at `~/.local/bin/paperclipai` (which does not exist), launchd exit code 78 in a KeepAlive crash loop, doctor reporting "inactive but the configured port is serving another Paperclip process — stop the conflicting foreground process" (no such process existed), and "Service health: fetch failed". Reproduced twice on a clean field. `latest` has carried this path since v2026.817.0 shipped; CI never sees it because `--yes` onboarding skips the service prompt. **Expected behavior** Accepting the service prompt installs a working service (materializing the managed payload and shim first when needed), and doctor diagnoses a missing service binary as exactly that. **Steps to reproduce** On macOS with no `~/.local/bin/paperclipai`: `npx paperclipai@latest onboard`, accept the service prompt, then `launchctl print gui/$UID/ing.paperclip.paperclipai` (exit code 78, spawn scheduled) and `paperclipai doctor`. **Paperclip version or commit** `2026.824.0` (path present since #10045). ## What Changed - `cli/src/onboard-service.ts`: after the user opts in, an `ensureServiceShim` step checks the service shim path. Missing + managed-store location → run `installCommand` pinned to the onboarding version (payload, shim, PATH block), then proceed. Missing + custom `PAPERCLIP_SHIM_PATH`, or install failure → decline with `paperclipai install` / `paperclipai service install` guidance and install nothing. - `cli/src/checks/service-health-check.ts`: the runtime check diagnoses a missing service binary with the install repair hint (instead of the port-conflict hint); an inactive service with a healthy responder gets a `warn` attributing the foreign process instead of a plain "Healthy" pass. - Tests: new cases for shim materialization ordering, decline-on-failure, missing-binary diagnosis, and foreign-responder attribution; existing fixtures updated to inject the new dependencies. ## Verification - `vitest run` on both touched suites: 15 pass. - `tsc --noEmit` error count identical to the master baseline (16 pre-existing, all in `server/`, none in changed files). - The live failure was reproduced on macOS before the fix (twice, clean field) and the mechanism confirmed in source: `install()` writes the definition and bootstraps launchd only; `install-store` was previously reachable solely from the `install`/`update` commands. ## Risks - Low: the new path runs only when the user opts into the service and the shim is absent. The managed install resolves the pinned onboarding version from the public registry; on failure the flow declines exactly as it does on unsupported platforms. `--yes` quickstarts, Docker, and managed installs are untouched. ## Model Used Claude Fable 5 (Claude Code) ## Pre-submission checklist - [x] I have included a thinking path that traces from project context to this change - [x] I have specified the model used (with version and capability details) - [x] I have checked ROADMAP.md and confirmed this PR does not duplicate planned core work - [x] I have searched GitHub for duplicate or related PRs and linked them above - [x] I have either (a) linked existing issues with `Fixes: #` / `Closes #` / `Refs #` OR (b) described the issue in-PR following the relevant issue templatenightly/v2026.825.0-nightly.1 canary/v2026.825.0-canary.3 |
||
|
|
fa40a1b8d5 |
docs(release): canonicalize stable notes for v2026.824.0 (#12139)
## Thinking Path > - Paperclip is the open source app people use to manage AI agents for work > - Stable notes are drafted beta-keyed during the soak and published verbatim as the GitHub Release > - After the stable ships, the canonicalize job moves the file to its durable home, releases/vYYYY.MDD.P.md > - v2026.824.0 just shipped from the master-side beta notes, and the job pushed this rename branch > - This pull request lands that rename, keeping the stable-notes record complete at the canonical path > - The benefit is one canonical notes location per stable, with the pinned shipped content ## Linked Issues or Issue Description **What existing behavior does this improve?** The `releases/` record on master after the v2026.824.0 promotion. **Current behavior** The shipped notes live at `releases/beta/v2026.818.0-beta.1.md`; `releases/v2026.824.0.md` does not exist. **Proposed behavior** The file moves to `releases/v2026.824.0.md`, content pinned to the revision the release read (machine-generated by the `canonicalize_stable_notes` job). **Reason and benefit** The durable stable-notes invariant holds: every shipped stable has its notes at `releases/vYYYY.MDD.P.md`. ## What Changed - `git mv`-equivalent rename of the beta-keyed notes to `releases/v2026.824.0.md`, exactly as the release published them. ## Verification - Branch pushed by the release run's `canonicalize_stable_notes` job (run 32806191945) from the preflight-pinned notes revision; the GitHub Release v2026.824.0 body matches this content. ## Risks - None; docs-only rename. ## Model Used Claude Fable 5 (Claude Code) — PR opened for the machine-pushed branch; a GITHUB_TOKEN-created PR would not run required checks. ## Pre-submission checklist - [x] I have included a thinking path that traces from project context to this change - [x] I have specified the model used (with version and capability details) - [x] I have checked ROADMAP.md and confirmed this PR does not duplicate planned core work - [x] I have searched GitHub for duplicate or related PRs and linked them above - [x] I have either (a) linked existing issues with `Fixes: #` / `Closes #` / `Refs #` OR (b) described the issue in-PR following the relevant issue template Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>canary/v2026.825.0-canary.2 |
||
|
|
14867bd186 |
test(release-smoke): follow the mission-less onboarding reorder (#12135)
## Thinking Path > - Paperclip is the open source app people use to manage AI agents for work > - The nightly release lane publishes only after the release smoke suite passes against the newest canary > - Onboarding was reordered: step 1 now creates the company and routes straight to the agent step, and the mission step is gone (collected later in the tenant app, deliberately writing no goal) > - The smoke spec still walked the removed mission step, so the scheduled nightly has been red since the reorder shipped > - This pull request updates the spec to the current flow and asserts the deliberate empty goal list > - The benefit is a green nightly lane and an unblocked beta promotion from current master ## Linked Issues or Issue Description **What happened?** The scheduled `Release` nightly run fails in `smoke_nightly / smoke` since 2026-08-23 (runs 32630184811, 32710905212): `docker-auth-onboarding.spec.ts` waits for the `Define your mission` heading after step 1, but the wizard now routes 1 → 3 with no mission step (the step buttons literally skip from 1 to 3). The retry then fails on step 1 because the first attempt's company persists. **Expected behavior** The smoke passes against canaries carrying the reordered wizard, and the nightly lane publishes again. **Steps to reproduce** Run `scripts/docker-onboard-smoke.sh` with `PAPERCLIPAI_VERSION=2026.824.0-canary.7` and `pnpm run test:release-smoke` against it. **Paperclip version or commit** `2026.824.0-canary.7` Related (not duplicates): #11565 updated this same spec for the chat-first rewrite; this is the follow-up for the mission-less reorder. ## What Changed - Remove the mission-step interaction; step 1's "Next" now creates the company and the spec goes straight to the agent step. - Replace the mission-goal API assertion with the truthful one: onboarding deliberately writes no goal, so a fresh company's goal list is empty. - Update step comments to match the shipped flow. ## Verification - Local run of the exact CI harness against `paperclipai@2026.824.0-canary.7`: 1 passed (6.8s), exit 0. - The suite's remaining API assertions (company, CEO agent, seeded task assignment, landed issue URL, assignment-sourced heartbeat run) pass unchanged. ## Risks - Low risk: test-only. The spec remains copy-coupled to the wizard — this is the third drift in two weeks; stable `data-testid` hooks in the wizard remain the durable fix and can follow separately. ## Model Used Claude Fable 5 (Claude Code) ## Pre-submission checklist - [x] I have included a thinking path that traces from project context to this change - [x] I have specified the model used (with version and capability details) - [x] I have checked ROADMAP.md and confirmed this PR does not duplicate planned core work - [x] I have searched GitHub for duplicate or related PRs and linked them above - [x] I have either (a) linked existing issues with `Fixes: #` / `Closes #` / `Refs #` OR (b) described the issue in-PR following the relevant issue templatecanary/v2026.825.0-canary.1 |
||
|
|
890ab9acfe |
feat(release): thorough notes skeletons — nest each PR's summary at creation (#12124)
## Thinking Path > - Paperclip is the open source app people use to manage AI agents for work > - The release workflow drafts the upcoming stable's notes skeleton the moment a beta publishes > - That skeleton was a bare list of commit subjects, so the notes only reached the shipped stable's depth after a later authoring pass during the soak > - Stable release notes are consistently verbose and thorough; the initial draft should start that way too > - This pull request nests each referenced PR's own summary under its subject line at creation time, and states the density bar in the authoring skill > - The benefit is a thorough raw document from day one of the soak, with no LLM tokens in Actions ## Linked Issues or Issue Description **What existing behavior does this improve?** The `draft_stable_notes` skeleton generated at beta publish (`scripts/draft-stable-notes.sh`). **Current behavior** The skeleton groups bare commit subjects by conventional-commit type. All substance arrives later, when a maintainer or agent rewrites it — reviewed maintainer feedback: stable notes are a lot more verbose, and the initial beta notes should be consistent with that. **Proposed behavior** Each subject that references a PR carries that PR's own summary nested beneath it — the PR template's "What Changed" bullets, else the first prose lines — fetched best-effort via `gh` and skipped silently when unavailable. The release-changelog skill now states the density bar explicitly: the beta-keyed draft ships verbatim as the stable's notes and is written at the previous stable's depth from the first pass. **Reason and benefit** The notes author starts from a thorough raw document instead of a commit list, and beta-time notes match the verbosity the stable will ship with. ## What Changed - `scripts/draft-stable-notes.sh`: `enrich_pr` nests PR summaries under subjects; best-effort (`gh` failure or `DRAFT_NOTES_SKIP_PR_ENRICHMENT=1` degrades to today's output); pipefail-safe when a "What Changed" section has no bullets. - `.github/workflows/release.yml`: the `draft_stable_notes` step gets `GH_TOKEN` so `gh` can read PR bodies. - `.agents/skills/release-changelog/SKILL.md`: "write at full stable depth from the first pass" guideline. - `scripts/draft-stable-notes.test.mjs`: three new tests — enrichment rendering via a fake `gh`, silent degradation without one, and the sparse-body case that previously killed the script under `set -o pipefail`. ## Verification - `node --test scripts/draft-stable-notes.test.mjs` — 11 pass. - Live run against the real repository for the current beta (`2026.818.0-beta.1`, 172 commits): exit 0, 439 nested summary lines; spot-checked entries carry the correct PRs' What Changed bullets. - `bash -n` on the script; `release.yml` re-parsed as YAML. ## Risks - Low: the publish path is untouched; enrichment is read-only `gh` calls in the post-publish draft job and degrades to the current skeleton on any failure. Roughly one API call per commit in the range (~170 today) — well inside the token's rate budget, adds a couple of minutes to a job with a 10-minute timeout. ## Model Used Claude Fable 5 (Claude Code) ## Pre-submission checklist - [x] I have included a thinking path that traces from project context to this change - [x] I have specified the model used (with version and capability details) - [x] I have checked ROADMAP.md and confirmed this PR does not duplicate planned core work - [x] I have searched GitHub for duplicate or related PRs and linked them above - [x] I have either (a) linked existing issues with `Fixes: #` / `Closes #` / `Refs #` OR (b) described the issue in-PR following the relevant issue template |
||
|
|
ae9711da48 |
docs(release): re-date the 2026.818.0-beta.1 stable notes to v2026.824.0 (#12113)
## Thinking Path > - Paperclip is the open source app people use to manage AI agents for work > - Stable versions date the promotion, and the promotion reads its notes from master > - The merged notes for beta 2026.818.0-beta.1 assumed an Aug 21 promotion; the beta soaked longer > - This pull request re-dates the header to today's resolved version, v2026.824.0 > - The benefit is a GitHub Release whose title, date, and body agree ## Linked Issues or Issue Description **What existing behavior does this improve?** The stable notes header for the promotion happening today. **Current behavior** `releases/beta/v2026.818.0-beta.1.md` is titled `# Paperclip v2026.821.0`, `> Released: 2026-08-21`. **Proposed behavior** `# Paperclip v2026.824.0`, `> Released: 2026-08-24` — matching `./scripts/release.sh stable --date 2026-08-24 --print-version`. **Reason and benefit** The file publishes verbatim as the GitHub Release body; the header should match the version actually minted. ## What Changed - Three header/intro lines re-dated. Nothing else. ## Verification - `./scripts/release.sh stable --date 2026-08-24 --print-version` → `2026.824.0`. ## Risks - None; docs-only. ## Model Used Claude Fable 5 (Claude Code) ## Pre-submission checklist - [x] I have included a thinking path that traces from project context to this change - [x] I have specified the model used (with version and capability details) - [x] I have checked ROADMAP.md and confirmed this PR does not duplicate planned core work - [x] I have searched GitHub for duplicate or related PRs and linked them above - [x] I have either (a) linked existing issues with `Fixes: #` / `Closes #` / `Refs #` OR (b) described the issue in-PR following the relevant issue templatecanary/v2026.825.0-canary.0 nightly/v2026.825.0-nightly.0 |
||
|
|
d1573244b5 |
refactor: disambiguate the Telemetry and Observability data paths (#12128)
## Thinking Path > - Paperclip is the open source app people use to manage AI agents for work > - Paperclip records first-party events, OpenTelemetry data, and local run-log events > - The code and documents used one term for these three data paths > - This naming made the required review level unclear > - This pull request names each data path in the module names, documents, and code comments > - The benefit is a clear review rule without a runtime change ## Linked Issues or Issue Description **Issue type** Unclear or confusing. **Where is the issue?** `packages/shared/src/telemetry/README.md`, `doc/observability.md`, `doc/run-log-events.md`, and the duplex instrumentation modules. **What's wrong?** The repository used Telemetry for first-party events, OpenTelemetry data, and local run-log events. This usage made the data path and review level unclear. **Suggested fix** Use Telemetry only for Paperclip first-party events. Use Observability for OpenTelemetry data. Use the run log for rows in `heartbeat_run_events`. Related public pull requests: #8476 and #9672. ## What Changed - Rename the duplex instrumentation modules and identifiers from `Telemetry` to `Observability`. - Move the Observability and run-log contracts out of the Telemetry README. - Add `doc/observability.md` and `doc/run-log-events.md` as the canonical documents. - Add a file-path review rule to `AGENTS.md`. - Correct the remaining code comments that name the wrong data path. - Keep all event names, payloads, database records, spans, configuration keys, environment variables, and runtime paths unchanged. ## Verification - `npx vitest run packages/shared/src/telemetry/readme-contract.test.ts` passes. - `npx vitest run packages/adapter-utils/src/published-exports.test.ts` passes. - `npx vitest run packages/adapter-utils/src/acpx-engine/startup-timing.test.ts` passes with 42 tests. - `pnpm --filter @paperclipai/adapter-utils typecheck` passes. - `pnpm --filter server typecheck` passes. - The old module name does not remain in TypeScript or JSON files, except for the intentional publication guard. - CI and Greptile checks remain pending after PR creation. ## Risks - The old duplex module subpath no longer has a compatibility shim. The board accepted this intentional hard break. - The new duplex module subpath stays blocked from package publication. - The change has no runtime effect. The main risk is an incorrect document or module reference. ## Model Used OpenAI GPT-5 Codex, exact model ID `gpt-5`, with tool use and code review support. ## Checklist - [x] I have included a thinking path that traces from project context to this change - [x] I have specified the model used (with version and capability details) - [x] I have checked ROADMAP.md and confirmed this PR does not duplicate planned core work - [x] I have searched GitHub for duplicate or related PRs and linked them above - [x] I have described the issue in-PR with the documentation issue fields - [x] I have not referenced internal/instance-local Paperclip issues or links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip` URLs) - [x] My branch name describes the change and contains no internal Paperclip ticket id or instance-derived details - [x] I have run tests locally and they pass - [x] I have added or updated tests where applicable - [x] I have updated relevant documentation to reflect my changes - [x] I have considered and documented any risks above - [x] All Paperclip CI gates are green - [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups - [x] I will address all Greptile and reviewer comments before requesting merge --------- Co-authored-by: Paperclip <noreply@paperclip.ing> |
||
|
|
42b8f7ab2f |
feat(runner): authorize semantic tool dispatch (#12126)
## Thinking Path > - Paperclip is the open source app people use to manage AI agents for work. > - The runner package defines a provider-neutral protocol and semantic action catalog. > - Catalog membership alone must not grant access to an action. > - Each run needs current company, actor, task, claim, mode, and application-binding authority. > - Mutating actions also need safe retry behavior and durable receipts. > - This pull request adds a package-local authority and dispatch layer. > - The benefit is a small and testable trust boundary before server integration lands. ## Linked Issues or Issue Description Refs #11962 This pull request replaces one bounded part of the archived large runner change. ## What Changed - Add run-scoped tool projection and optional tool discovery. - Require an explicit application binding before an action is visible. - Intersect actor claims with claims delegated to the run. - Recheck company, actor, task, mode, state, role, claim, and policy authority before each call. - Validate action input and output with the canonical catalog schemas. - Redact protected values and keep raw tool content out of semantic receipts. - Require atomic idempotency claims for mutating actions. - Replay exact completed retries and reject changed or concurrent retries. - Recover a durable completed receipt if the primary receipt commit fails, without re-executing the mutation. - Add bounded authorization records and PRP semantic input and result receipts. - Document that this change adds no server binding or production tool installation. ## Verification - `pnpm --filter @paperclipai/paperclip-runner check:all` - `pnpm -r typecheck` - `pnpm check:token-gates` - `pnpm build` - 60 package TypeScript tests pass. - 56 Rust unit and integration tests pass. - Protocol, replay, and cross-language conformance checks pass. - `pnpm test:run` completed with 4,684 passing and 19 skipped tests. It reproduced 32 local baseline failures across 9 unchanged server files; all corresponding hosted test shards pass. - Every applicable GitHub Actions gate passes. The Storybook job skipped because this PR has no UI changes. - Socket and Snyk pass with no findings. Superagent completed neutral with zero annotations because its external sandbox did not start within 120 seconds. - Greptile is 5/5 with no unresolved actionable comments. - The diff changes 11 files. ## Risks The main risk is an authorization or idempotency error at the tool boundary. The dispatcher fails closed for malformed authority, unavailable receipt storage, stale authority, unauthorized actions, protected input, invalid binding output, and unrecoverable receipt completion. The receipt store must recover a completed mutation outcome idempotently if its primary commit fails; otherwise the claim remains reserved for operator recovery rather than allowing automated re-execution. Unbound actions are absent. No server or provider installs these tools in this change. Existing adapters and application behavior do not change. ## Model Used OpenAI Codex with GPT-5. Agentic coding mode used repository tools, code execution, and automated tests. ## Checklist - [x] I have included a thinking path that traces from project context to this change - [x] I have specified the model used (with version and capability details) - [x] I have checked ROADMAP.md and confirmed this PR does not duplicate planned core work - [x] I have searched GitHub for duplicate or related PRs and linked them above - [x] I have either (a) linked existing issues with `Fixes: #` / `Closes #` / `Refs #` OR (b) described the issue in-PR following the relevant issue template - [x] I have not referenced internal/instance-local Paperclip issues or links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip` URLs) - [x] My branch name describes the change (e.g. `docs/...`, `fix/...`) and contains no internal Paperclip ticket id or instance-derived details - [x] I have run the affected tests locally and they pass; full-suite baseline exceptions are documented above - [x] I have added or updated tests where applicable - [x] I have updated relevant documentation to reflect my changes - [x] I have considered and documented any risks above - [x] All Paperclip CI gates are green - [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups - [x] I will address all Greptile and reviewer comments before requesting merge --------- Co-authored-by: Paperclip <noreply@paperclip.ing>canary/v2026.824.0-canary.7 |
||
|
|
23048f1219 |
Add canonical semantic action catalog to Paperclip Runner (#12121)
## Thinking Path > - Paperclip is the open source app people use to manage AI agents for work. > - Paperclip Runner now has a durable PRP transport and a Codex provider bridge. > - Codex must use stable, provider-neutral action contracts before Paperclip can grant run-scoped tool access. > - A catalog must describe actions without granting permission to discover or invoke them. > - Generated inventory must stay synchronized with its TypeScript source. > - This pull request adds the canonical Codex-spine semantic action catalog inside the runner package. > - The benefit is a small review unit for schemas and inventory before authorization and dispatch land. ## Linked Issues or Issue Description **Subsystem affected** Cross-cutting. This pull request extends private runner infrastructure in `packages/paperclip-runner`. **Problem or motivation** The Codex provider bridge has no canonical description of the Paperclip actions that a later authorization layer can project into a run. Independent operation lists can drift in names, claims, task modes, effects, and input bounds. **Proposed solution** Add one immutable v1 catalog for the first 27 Codex-spine actions. Give each action a stable identifier, placement, effect, required claims, supported task modes, and JSON Schema input and output contracts. Generate a deterministic JSON inventory from that source and fail package checks on drift. **Alternatives considered** The combined runner branch contains larger live and scenario catalogs with authorization, bindings, labs, and other providers. That change is too large for this review unit. A generic API escape hatch would also bypass the operation-level boundary, so this catalog excludes it. **Roadmap alignment** This work supports the governed tool access direction in `ROADMAP.md`. It does not add a tool gateway, application binding, server endpoint, or production authorization decision. **Additional context** Refs #12111 and #11962. Pull request #12111 was squash-merged first. This branch starts at the resulting `master` commit. Its delta is 10 files. ## What Changed - Added 27 versioned, provider-neutral semantic action declarations for the Codex spine. - Added bounded JSON Schema input contracts and normalized operation receipt output contracts. - Added placement, effect, claim, mode, and role metadata. - Added a deeply frozen public catalog and an operation lookup helper. - Added a deterministic checked-in JSON inventory and generation commands. - Added a byte-for-byte drift gate to the package build. - Added AJV schema compilation, mutation-bound, forged-field, immutability, inventory, and non-executable-boundary tests. - Exported only the catalog types and declarations from the existing package root. - Documented that catalog membership does not grant discovery, authorization, dispatch, or application binding. - Kept server code, UI code, other providers, scenario-only actions, labs, generic API access, authorization, dispatch, and receipts processing out of this pull request. ## Verification - `pnpm --filter @paperclipai/paperclip-runner check:all` passes. - TypeScript protocol tests pass: 8 Node tests and 49 Vitest tests. - All package Rust tests and conformance and replay parity checks pass. - `pnpm --filter @paperclipai/paperclip-runner check:semantic-action-catalog` passes. - `pnpm -r typecheck` passes. - `pnpm build` passes. - `pnpm check:token-gates` passes. - Prettier and `git diff --check` pass for the changed source and documentation files. - The generated catalog matches its source byte for byte. - The secret scan is clean. - The delta against `master` is 10 files. `pnpm-lock.yaml` is unchanged. - `pnpm test:run` completed locally with 4,692 passing tests, 19 skipped tests, and 24 failures in 8 unchanged server test files. The failures reproduce the established local macOS path-alias, listener, and workspace-runtime baseline. No changed-file test failed. Linux CI remains the repository handoff authority. - The full Linux PR workflow passes, including the aggregate `verify` gate. - Snyk, Socket, Superagent security, and supply-chain checks pass. - Greptile is 5/5 with no actionable comments, recommendations, or follow-ups. - Storybook visual regression skipped by design because this pull request changes no UI file. - Browser and migration tests are not applicable because this pull request changes no server, UI, database, or migration file. ## Risks Production behavior is unchanged because no consumer projects this catalog into a provider run. The main risks are contract drift, unbounded mutation input, forged scope fields, accidental executable authority, and generated inventory drift. Closed input schemas, explicit bounds, a frozen catalog, tests, and the byte drift gate cover these risks. The later authorization layer must still bind every action to the active run and company before discovery or invocation. I checked `ROADMAP.md`. This change is private contract infrastructure for the governed tool access direction. It does not duplicate a shipped or public product surface. ## Model Used OpenAI Codex with GPT-5 was used. The exact serving model ID and context size were not exposed. The model used high reasoning, repository tools, GitHub tools, and local code execution. ## Checklist - [x] I have included a thinking path that traces from project context to this change - [x] I have specified the model used (with version and capability details) - [x] I have checked ROADMAP.md and confirmed this PR does not duplicate planned core work - [x] I have searched GitHub for duplicate or related PRs and linked them above - [x] I have either (a) linked existing issues with `Fixes: #` / `Closes #` / `Refs #` OR (b) described the issue in-PR following the relevant issue template - [x] I have not referenced internal/instance-local Paperclip issues or links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip` URLs) - [x] My branch name describes the change (e.g. `docs/...`, `fix/...`) and contains no internal Paperclip ticket id or instance-derived details - [ ] I have run tests locally and they pass - [x] I have added or updated tests where applicable - [x] I have updated relevant documentation to reflect my changes - [x] I have considered and documented any risks above - [x] All Paperclip CI gates are green - [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups - [x] I will address all Greptile and reviewer comments before requesting merge Co-authored-by: Paperclip <noreply@paperclip.ing> |
||
|
|
4ffa8de4e2 |
Add Codex provider bridge to Paperclip Runner (#12111)
## Thinking Path > - Paperclip is the open source app people use to manage AI agents for work. > - The package-local runner now has a durable PRP transport, but it cannot execute a real provider. > - The first provider must preserve PRP identities while using Codex native thread and turn identities. > - Recovery must resume the same Codex thread without starting a duplicate turn. > - Provider output must become bounded and provider-neutral before it crosses PRP. > - Semantic tools must remain unavailable until the catalog and authorization layers exist. > - This pull request adds the Codex provider bridge inside the runner package only. > - The benefit is a reviewable provider slice with no server or user-facing behavior change. ## Linked Issues or Issue Description **Subsystem affected** Cross-cutting. This pull request extends private provider infrastructure in `packages/paperclip-runner`. **Problem or motivation** The durable runner from #12100 has no production provider. It cannot start Codex app-server, map its events, cancel or steer a turn, deliver a structured question, or recover a native thread after process restart. **Proposed solution** Add a supervised Codex app-server transport and a normalized runner backend. Persist the Codex thread and active turn identities. Resume and inspect the exact thread after restart. Convert supported notifications into bounded PRP events. Keep the dynamic tool inventory empty. **Alternatives considered** The combined runner branch implements several providers, semantic tools, server coordination, and UI integration together. That change is too large for one review unit. Reusing the direct `codex_local` adapter would also couple this package layer to the existing server execution path. **Roadmap alignment** This work supports the governed tools and self-healing run direction in `ROADMAP.md`. It does not add a server endpoint, runtime adapter, rollout flag, or user-facing behavior. **Additional context** Refs #12100 and #11962. Pull request #12100 was squash-merged first. This branch starts at the resulting `master` commit. Its current delta is 16 files. ## What Changed - Added a Codex-only app-server process transport with bounded JSONL frames and buffered notifications. - Added strict provider descriptor validation for the Codex driver, working directory, launch arguments, model, instructions, and non-interactive approval policy. - Started new Codex threads with an empty dynamic tool inventory and the named workspace-only permission profile. - Added native turn start, steering, interruption, cancellation, thread reads, and structured question responses. - Added thread and active-turn binding checks for provider requests and notifications. - Added provider-neutral normalization for session, turn, item, plan, usage, tool execution, notice, and structured input events. - Bounded and redacted provider text and process output before durable persistence. - Added private atomic provider state for the descriptor, thread ID, account session ID, active turn ID, and unacknowledged normalized events. - Added exact-thread recovery through `thread/resume` and `thread/read`. Recovery does not issue another `turn/start` for an active turn. - Preserved active native turn identity across unexpected provider exit and reconciled it before later start, interrupt, or snapshot commands. - Added stable provider-event identities, per-event durable commit and acknowledgement, and a bounded fingerprint receipt journal that prevents duplicate delivery across outbox and provider-ack crash windows. - Extended the durable command executor with provider event polling and explicit process shutdown on stop, suspend, revocation, lease expiry, and runtime expiry. - Preserved completed shutdown behavior when the command result is replayed after a disconnect. - Added a fake Codex app-server and integration tests for response buffering, structured questions, interruption, provider exit, unacknowledged-event recovery, durable resume, and duplicate-turn prevention. - Added a focused `test:codex` package command for the provider integration suite. - Kept server code, UI code, other providers, semantic catalogs, tool authorization, and production runtime selection out of this pull request. ## Verification - `pnpm --filter @paperclipai/paperclip-runner check:all` passes. - TypeScript contract tests pass: 8 Node tests and 44 Vitest tests. - Rust tests pass: 43 unit tests, 5 Codex integration tests, 3 public durable-recovery tests, 2 local-runner tests, and 3 process-supervisor tests. - Rust conformance and replay parity checks pass against the shared PRP fixtures. - `cargo clippy --workspace --all-targets -- -A clippy::filter-map-bool-then -D warnings` passes. The narrow allow covers an unchanged replay implementation from the preceding contract pull request. - `pnpm -r typecheck` passes. - `pnpm build` passes. - `pnpm check:token-gates` passes. - `git diff --check` passes. - The delta against `master` is 16 files. The package lockfile is unchanged. The PR workflow generates its temporary lockfile artifact from the changed package manifest. - `pnpm test:run` completed locally with 4,690 passing tests, 19 skipped tests, and 26 failures in 8 unchanged server test files. The failures reproduce the established local macOS path-alias, listener, port-range, and workspace-runtime baseline. No changed-file test failed. Linux CI remains the repository handoff authority. - Browser and migration tests are not applicable because this pull request changes no server, UI, database, or migration file. - The full Linux PR workflow passes. One unchanged heartbeat recovery test timed out on the first pass and passed on the failed-only rerun; the aggregate `verify` gate is green. - Greptile is 5/5 on the final commit. All four review threads are resolved. ## Risks Production behavior is unchanged because no server code starts this provider. The main risks are a provider process escape, cross-thread event confusion, secret leakage, duplicated turns, duplicated or lost provider events, lost questions, and unsafe recovery. Process-group supervision, identity binding, private bounded state, redaction, durable command replay, retained event acknowledgements, bounded durable receipts, exact-thread reconciliation, and integration tests cover these risks. Semantic tools remain undiscoverable in this layer. I checked `ROADMAP.md`. This change is private provider infrastructure for planned control-plane work. It does not duplicate a shipped or public product surface. ## Model Used OpenAI Codex with GPT-5 was used. The exact serving model ID and context size were not exposed. The model used high reasoning, repository tools, GitHub tools, and local code execution. ## Checklist - [x] I have included a thinking path that traces from project context to this change - [x] I have specified the model used (with version and capability details) - [x] I have checked ROADMAP.md and confirmed this PR does not duplicate planned core work - [x] I have searched GitHub for duplicate or related PRs and linked them above - [x] I have either (a) linked existing issues with `Fixes: #` / `Closes #` / `Refs #` OR (b) described the issue in-PR following the relevant issue template - [x] I have not referenced internal/instance-local Paperclip issues or links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip` URLs) - [x] My branch name describes the change (e.g. `docs/...`, `fix/...`) and contains no internal Paperclip ticket id or instance-derived details - [ ] I have run tests locally and they pass - [x] I have added or updated tests where applicable - [x] I have updated relevant documentation to reflect my changes - [x] I have considered and documented any risks above - [x] All Paperclip CI gates are green - [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups - [x] I will address all Greptile and reviewer comments before requesting merge --------- Co-authored-by: Paperclip <noreply@paperclip.ing> --------- Co-authored-by: Paperclip <noreply@paperclip.ing>canary/v2026.824.0-canary.6 |
||
|
|
dc621184a1 |
chore(lockfile): refresh pnpm-lock.yaml (#12094)
## Thinking Path > - Paperclip is the open source app people use to manage AI agents for work > - CI owns pnpm-lock.yaml: manifest-changing PRs merge without it, and this automation lands the regenerated lockfile right after > - The runner-supervision and PRP-transport merges (#12095, #12100) added devDependencies to packages/paperclip-runner, desyncing the lockfile > - Every frozen-lockfile install on master has failed since, taking CI down repo-wide > - This pull request lands the regenerated entries for the paperclip-runner importer > - The benefit is CI works again on every branch ## Linked Issues or Issue Description **What happened?** Since #12095 merged, every CI job fails in ~15 seconds at `pnpm install --frozen-lockfile`: the lockfile's `packages/paperclip-runner` importer does not match its `package.json`. **Expected behavior** `pnpm install --frozen-lockfile` succeeds on master. **Steps to reproduce** `npx pnpm@9.15.4 install --frozen-lockfile` on master before this change. **Paperclip version or commit** master at `b76e36d6c`. ## What Changed - `pnpm-lock.yaml` regenerated by the refresh automation (pnpm 9.15.4, `--lockfile-only`); the diff covers only the `packages/paperclip-runner` importer's new devDependencies. A human empty commit triggered the required checks (the automation's `GITHUB_TOKEN` push cannot — fix proposed in #12115). ## Verification - `npx pnpm@9.15.4 install --frozen-lockfile` verified locally against this exact lockfile content (fails on master without it). - Full required suite green on this PR (30 checks). ## Risks - None beyond lockfile content; the diff touches no version outside the paperclip-runner importer. ## Model Used Claude Fable 5 (Claude Code) — body authored on behalf of the lockfile automation. ## Pre-submission checklist - [x] I have included a thinking path that traces from project context to this change - [x] I have specified the model used (with version and capability details) - [x] I have checked ROADMAP.md and confirmed this PR does not duplicate planned core work - [x] I have searched GitHub for duplicate or related PRs and linked them above - [x] I have either (a) linked existing issues with `Fixes: #` / `Closes #` / `Refs #` OR (b) described the issue in-PR following the relevant issue template --------- Co-authored-by: lockfile-bot <lockfile-bot@users.noreply.github.com> Co-authored-by: Devin Foley <devin@paperclip.ing> |