mirror of
https://github.com/paperclipai/paperclip.git
synced 2026-10-06 10:48:12 +02:00
5af49cb4776f9cdce32046d903b4e8a0f7d298fe
3864
Commits
| Author | SHA1 | Message | Date | |
|---|---|---|---|---|
|
|
5af49cb477 |
feat(server): CEO agents get the core paperclip skills by default (#12138)
## Thinking Path
> - Paperclip is the open source app people use to manage AI agents for
work
> - Each agent's runtime only receives skills listed in its own
desired-skill set; the company library alone does nothing for an agent
> - Every CEO creation path (first-run wizard hire, New Agent
first-agent flow, cloud onboarding seed) creates the CEO with an empty
desired-skill set
> - The default CEO instructions tell the agent to use the core
paperclip skills, so a fresh CEO contradicts its own instructions and
reports its toolkit as "not installed"
> - This pull request unions the core skill keys into every
skills-capable CEO hire/create and into the onboarding-seeded CEO's
adapter config
> - The benefit is that a new CEO can actually do what its instructions
describe, and stops telling users that installed skills do not exist
## Linked Issues or Issue Description
**What existing behavior does this improve?**
Creating the first lead agent (role `ceo`) via hire, create, or the
cloud onboarding seed.
**Subsystem affected**
Server — agent hire/create routes (`server/src/routes/agents.ts`),
onboarding seed (`server/src/services/onboarding-seed.ts`), company
skills service constant (`server/src/services/company-skills.ts`).
**Current behavior**
A CEO created by the wizard, the New Agent page, or the onboarding seed
has no `paperclipSkillSync` block. Its runtime mounts zero skills. Its
default instructions (`server/src/onboarding-assets/ceo/AGENTS.md`,
`HEARTBEAT.md`) tell it to use `paperclip-create-agent`,
`para-memory-files`, and the paperclip coordination skill. The agent
then reports these skills as not installed.
**Proposed behavior**
When the new agent's role is `ceo` and its adapter supports skill sync,
the hire and create routes union the five bundled
`paperclipai/paperclip/*` skill keys into the requested desired-skill
set. The onboarding seed writes the same preference into the seeded
CEO's adapter config. Explicit requests win over defaults for the same
key. Non-CEO agents are unchanged. Any default stays removable through
`POST /agents/:id/skills/sync`.
**Breaking changes**
None. The default is additive, applies only to role `ceo` on
skills-capable adapters, and the bundled skills are guaranteed present
in every company library by `ensureSkillInventoryCurrent`.
## What Changed
- New exported constant `PAPERCLIP_CORE_SKILL_KEYS` in
`server/src/services/company-skills.ts` (the five bundled
`paperclipai/paperclip/*` keys).
- `defaultRoleSkillSelections` + `withDefaultRoleSkillSelections`
helpers in `server/src/routes/agents.ts`, applied in both the hire and
create routes before `resolveDesiredSkillAssignment(..., "add")`.
- `server/src/services/onboarding-seed.ts` builds the seeded CEO's
adapter config with `writePaperclipSkillSyncPreference` instead of `{}`
when the seeded adapter supports skills.
## Verification
- `cd server && npx vitest run
src/__tests__/agent-skills-routes.test.ts` — 32 tests pass (three new:
CEO default set, union with a requested skill, non-CEO untouched).
- `cd server && npx vitest run
src/__tests__/onboarding-seed-route.test.ts` — 14 tests pass (seeded CEO
adapter config assertion added).
- `cd server && npx vitest run
src/__tests__/agent-permissions-routes.test.ts` — 54 tests pass.
- `cd server && pnpm run typecheck` — clean.
## Risks
- Existing CEOs are not modified; only newly created ones get the
defaults. An operator who wants a minimal CEO can remove the skills
after creation with the skills sync (mode `remove`), and that removal
sticks. Adapters without skill support are skipped, so the change is
inert there.
## Model Used
- Claude Fable 5 (`claude-fable-5`, Anthropic) with extended thinking
and tool use, via Claude Code.
## Checklist
- [x] I have included a thinking path that traces from project context
to this change
- [x] I have specified the model used (with version and capability
details)
- [x] I have checked ROADMAP.md and confirmed this PR does not duplicate
planned core work
- [x] I have searched GitHub for duplicate or related PRs and linked
them above
- [x] I have either (a) linked existing issues with `Fixes: #` / `Closes
#` / `Refs #` OR (b) described the issue in-PR following the relevant
issue template
- [x] I have not referenced internal/instance-local Paperclip issues or
links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip`
URLs)
- [x] My branch name describes the change (e.g. `docs/...`, `fix/...`)
and contains no internal Paperclip ticket id or instance-derived details
- [x] I have run tests locally and they pass
- [x] I have added or updated tests where applicable
- [x] I have updated relevant documentation to reflect my changes
- [x] I have considered and documented any risks above
- [ ] All Paperclip CI gates are green
- [ ] Greptile is 5/5 with no open P2s, recommendations, or follow-ups
- [x] I will address all Greptile and reviewer comments before
requesting merge
|
||
|
|
d2b9765cc8 |
feat(ui): offer enabling a skill for agents at install time (#12136)
## Thinking Path > - Paperclip is the open source app people use to manage AI agents for work > - The company skill library lets operators install skills, and each agent has its own enabled-skill set > - Installing a skill only writes the library row; no agent receives the skill, and the UI says "Skill installed" with no attach step > - Operators install a skill, ask an agent to use it, and the agent truthfully reports the skill as not available — the install felt broken > - This pull request adds an "Enable for agents" step to the install dialog and enables the skill for the selected agents right after install > - The benefit is that "install" defaults to a state where agents can actually use the skill, and the toast is honest when they cannot ## Linked Issues or Issue Description **What existing behavior does this improve?** Installing a skill from the catalog in the company Skills page. **Subsystem affected** Web UI — company skills catalog install flow (`ui/src/pages/CompanySkills.tsx`). **Current behavior** Install writes a `company_skills` row and shows a "Skill installed" toast. No agent is enabled for the skill. Agents resolve their skills from their own desired-skill set, so they report the skill as not installed. The operator has to find the separate "Add to agent" control to make the install effective. **Proposed behavior** The install dialog shows an "Enable for agents" section for fresh installs. It pre-selects every agent whose adapter supports skills. After install, the page enables the skill for each selected agent (skills sync with mode `add`). The success toast reports how many agents received the skill, and warns when the skill is in the library with no agents enabled. **Breaking changes** None. Updates and replacements of an existing skill do not show the new section and behave as before. ## What Changed - `InstallPreviewDialog` gains an "Enable for agents" section (fresh installs only) built on the existing `AgentMultiSelect`, with agents whose adapter lacks skills support disabled. - New exported helper `defaultInstallAgentSelection` pre-selects every skills-capable, non-required agent. - The install mutation enables the skill for each selected agent via `agentsApi.syncSkills(..., "add")` before invalidating queries, and reports per-agent failures in a warning toast without failing the install. - Toast copy now distinguishes "enabled for N agents" from "in the library but not enabled for any agent yet". ## Verification - `cd ui && npx vitest run src/pages/CompanySkills.test.tsx` — 23 tests pass, including three new ones: default-selection helper, confirm payload carries the pre-selected agents, update/replace path skips the section. - `cd ui && pnpm run typecheck` — clean. - Manual: install a catalog skill with two agents in the company; both are pre-selected; after install the skill page lists both under "Used by agents". ## Risks - Low risk. Enablement uses the existing per-agent skills sync route with mode `add`, so concurrent edits to an agent's desired set are not overwritten. A per-agent sync failure surfaces as a warning toast and never fails the install itself. ## Model Used - Claude Fable 5 (`claude-fable-5`, Anthropic) with extended thinking and tool use, via Claude Code. ## Checklist - [x] I have included a thinking path that traces from project context to this change - [x] I have specified the model used (with version and capability details) - [x] I have checked ROADMAP.md and confirmed this PR does not duplicate planned core work - [x] I have searched GitHub for duplicate or related PRs and linked them above - [x] I have either (a) linked existing issues with `Fixes: #` / `Closes #` / `Refs #` OR (b) described the issue in-PR following the relevant issue template - [x] I have not referenced internal/instance-local Paperclip issues or links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip` URLs) - [x] My branch name describes the change (e.g. `docs/...`, `fix/...`) and contains no internal Paperclip ticket id or instance-derived details - [x] I have run tests locally and they pass - [x] I have added or updated tests where applicable - [x] I have updated relevant documentation to reflect my changes - [x] I have considered and documented any risks above - [ ] All Paperclip CI gates are green - [ ] Greptile is 5/5 with no open P2s, recommendations, or follow-ups - [x] I will address all Greptile and reviewer comments before requesting merge |
||
|
|
3e28d64a72 |
fix(plugin-worker-manager): queue and replay pre-bind login pseudo-terminal frames (#12173)
## Thinking Path > - Paperclip routes plugin worker messages to agent sessions. > - The login pseudo-terminal route opens after the host receives the open reply. > - `readline` can deliver later frames from the same pipe read before that reply continuation runs. > - The host dropped early output and exit frames. > - The fix queues valid early frames, preserves arrival order, and replays them after the route opens. > - The route uses bounded memory and closes fail-closed when a bound breaks. > - The final tests also pin child issue ordering so the serialized suite remains deterministic. ## Linked Issues or Issue Description Fixes #12122 ## What Changed - Add a bounded queue for login pseudo-terminal output and exit frames during route opening. - Validate session ids, chunk types, and per-chunk limits before queue insertion. - Bound the queue by 10,000 frames and 8 MiB of characters. - Charge retained worker session identifiers against the character bound. - Preserve arrival order and stop replay after the first valid exit. - Drop repeated exits without changing the first exit position or code. - Bound the repeat-exit lookup and clear queued state on all terminal paths. - Add regression tests and fixture support for coalesced frames, ordering, limits, cleanup, and log safety. - Pin issue numbers in the child-wake test so its expected child order remains deterministic. ## Verification - Build the plugin SDK with `pnpm --filter @paperclipai/plugin-sdk build`. - Run `npx vitest run server/src/__tests__/plugin-worker-manager.test.ts` from the repository root. - Run `npx vitest run server/src/__tests__/issues-service.test.ts` from the repository root. - The focused plugin worker suite passes 66 of 66 tests at the prior reviewed head. - The issue service file passes 120 of 120 tests in two isolated runs at the current head. - Confirm that GitHub Actions passes all required checks. - Confirm that Greptile reports 5/5 with no unresolved review threads. - Storybook visual regression remains skipped because the PR has no `storybook-visual` label. ## Risks - The queue adds bounded memory use while the login pseudo-terminal route opens. - A queue limit breach closes the route and prevents unbounded buffering. - A hostile worker can fail only its own login route when it breaches a bound. - The first valid exit closes the route, so later records do not reach the session. - The child-wake test now uses distinct issue numbers to match the service sort contract. ## Model Used OpenAI Codex, GPT-5, extended reasoning, tool use, and code review support. The runtime does not expose a separate context-window value. ## Checklist - [x] I have included a thinking path that traces from project context to this change - [x] I have specified the model used with version and capability details - [x] I have checked ROADMAP.md and confirmed that this PR does not duplicate planned core work - [x] I have searched GitHub for duplicate or related PRs and linked them above - [x] I have linked the existing public issue with `Fixes: #12122` - [x] I have not referenced internal Paperclip issues or links - [x] My branch name describes the change and contains no internal ticket id - [x] I have run tests locally and they pass - [x] I have added or updated tests where applicable - [x] I have updated relevant documentation where needed - [x] I have considered and documented risks above - [x] All required Paperclip CI gates are green - [x] Greptile is 5/5 with no unresolved review threads - [x] I will address all Greptile and reviewer comments before requesting merge --------- Co-authored-by: Paperclip <noreply@paperclip.ing> |
||
|
|
1fc4591327 |
build(deps): bump commander from 13.1.0 to 15.0.0 (#11877)
Bumps [commander](https://github.com/tj/commander.js) from 13.1.0 to 15.0.0. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/tj/commander.js/releases">commander's releases</a>.</em></p> <blockquote> <h2>v15.0.0</h2> <p>Commander 15 is ESM only. This is expected to be seamless for ESM consumers, but some CommonJS consumers may hit issues with tooling requiring configuration for ESM-only dependencies. See Migration Tips below.</p> <p>The release of Commander 15 moves Commander 14 into maintenance. Commander 14 will get security updates for 12 months (to May 2027). For more info see <a href="https://github.com/tj/commander.js/blob/v15.0.0/docs/release-policy.md">Release Policy</a>.</p> <h3>Added</h3> <ul> <li>show excess command-arguments in error message (<a href="https://redirect.github.com/tj/commander.js/issues/2384">#2384</a>)</li> </ul> <h3>Fixed</h3> <ul> <li><em>Breaking:</em> only lone <code>--no-*</code> option sets default option value to <code>true</code>, default not implicitly set when define both positive and negative option in either order (<a href="https://redirect.github.com/tj/commander.js/issues/2405">#2405</a>)</li> <li>update example to use compatible character for MINGW64 (<a href="https://redirect.github.com/tj/commander.js/issues/2475">#2475</a>)</li> </ul> <h3>Changed</h3> <ul> <li><em>Breaking:</em> migrated Commander implementation from CommonJS to ESM (<a href="https://redirect.github.com/tj/commander.js/issues/2464">#2464</a>)</li> <li><em>Breaking:</em> Commander 15 requires Node.js v22.12.0 or higher (for <code>require(esm)</code>).</li> <li>dev: switch tests from Jest to <code>node:test</code> test runner (<a href="https://redirect.github.com/tj/commander.js/issues/2463">#2463</a>)</li> </ul> <h3>Deleted</h3> <ul> <li><em>Breaking:</em> removed deprecated export of <code>commander/esm.mjs</code> (<a href="https://redirect.github.com/tj/commander.js/issues/2464">#2464</a>)</li> </ul> <h3>Migration Tips</h3> <p>Commander 15 is ESM only, but this does not mean you need to migrate to ESM to use it. Importing ESM from CommonJS is supported by Node.js, and Bun, and Deno. Hopefully it Just Works for you! However, you may be using a different runtime or some other part of your setup that may not yet natively support importing ESM from CommonJS, such as your testing framework or bundler.</p> <p>If you have problems using Commander 15 in your environment, one option is stay on Commander 14 for now. Commander 14 will get security updates until May 2027 and things will hopefully improve for your setup in the meantime.</p> <h2>v15.0.0-0</h2> <p>Commander 15 is ESM only. This is expected to be seamless for ESM consumers, but some CommonJS consumers may hit issues with tooling requiring configuration for ESM-only dependencies. See Migration Tips below.</p> <p>The release of Commander 15 in May 2026 will move Commander 14 into maintenance. Commander 14 will get security updates for 12 months (to May 2027). For more info see <a href="https://github.com/tj/commander.js/blob/master/docs/release-policy.md">Release Policy</a>.</p> <h3>Added</h3> <ul> <li>show excess command-arguments in error message (<a href="https://redirect.github.com/tj/commander.js/issues/2384">#2384</a>)</li> </ul> <h3>Fixed</h3> <ul> <li><em>Breaking:</em> only lone <code>--no-*</code> option sets default option value to <code>true</code>, default not implicitly set when define both positive and negative option in either order (<a href="https://redirect.github.com/tj/commander.js/issues/2405">#2405</a>)</li> <li>update example to use compatible character for MINGW64 (<a href="https://redirect.github.com/tj/commander.js/issues/2475">#2475</a>)</li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/tj/commander.js/blob/master/CHANGELOG.md">commander's changelog</a>.</em></p> <blockquote> <h2>[15.0.0] (2026-05-29)</h2> <p>Commander 15 is ESM only. This is expected to be seamless for ESM consumers, but some CommonJS consumers may hit issues with tooling requiring configuration for ESM-only dependencies. See Migration Tips below.</p> <p>The release of Commander 15 moves Commander 14 into maintenance. Commander 14 will get security updates for 12 months (to May 2027). For more info see <a href="https://github.com/tj/commander.js/blob/master/docs/release-policy.md">Release Policy</a>.</p> <h3>Added</h3> <ul> <li>show excess command-arguments in error message (<a href="https://redirect.github.com/tj/commander.js/issues/2384">#2384</a>)</li> </ul> <h3>Fixed</h3> <ul> <li><em>Breaking:</em> only lone <code>--no-*</code> option sets default option value to <code>true</code>, default not implicitly set when define both positive and negative option in either order (<a href="https://redirect.github.com/tj/commander.js/issues/2405">#2405</a>)</li> <li>update example to use compatible character for MINGW64 (<a href="https://redirect.github.com/tj/commander.js/issues/2475">#2475</a>)</li> </ul> <h3>Changed</h3> <ul> <li><em>Breaking:</em> migrated Commander implementation from CommonJS to ESM (<a href="https://redirect.github.com/tj/commander.js/issues/2464">#2464</a>)</li> <li><em>Breaking:</em> Commander 15 requires Node.js v22.12.0 or higher (for <code>require(esm)</code>).</li> <li>dev: switch tests from Jest to <code>node:test</code> test runner (<a href="https://redirect.github.com/tj/commander.js/issues/2463">#2463</a>)</li> </ul> <h3>Deleted</h3> <ul> <li><em>Breaking:</em> removed deprecated export of <code>commander/esm.mjs</code> (<a href="https://redirect.github.com/tj/commander.js/issues/2464">#2464</a>)</li> </ul> <h3>Migration Tips</h3> <p>Commander 15 is ESM only, but this does not mean you need to migrate to ESM to use it. Importing ESM from CommonJS is supported by Node.js, and Bun, and Deno. Hopefully it Just Works for you! However, you may be using a different runtime or some other part of your setup that may not yet natively support importing ESM from CommonJS, such as your testing framework or bundler.</p> <p>If you have problems using Commander 15 in your environment, one option is stay on Commander 14 for now. Commander 14 will get security updates until May 2027 and things will hopefully improve for your setup in the meantime.</p> <h2>[15.0.0-0] (2026-02-22)</h2> <p>(Released as 15.0.0)</p> <h2>[14.0.3] (2026-01-31)</h2> <h3>Added</h3> <ul> <li>Release Policy document (<a href="https://redirect.github.com/tj/commander.js/issues/2462">#2462</a>)</li> </ul> <h3>Changes</h3> <ul> <li>old major versions now supported for 12 months instead of just previous major version, to give predictable end-of-life date (<a href="https://redirect.github.com/tj/commander.js/issues/2462">#2462</a>)</li> <li>clarify typing for deprecated callback parameter to <code>.outputHelp()</code> (<a href="https://redirect.github.com/tj/commander.js/issues/2427">#2427</a>)</li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/tj/commander.js/commit/ba6d13ddb4243e5913367734f8c159089ffe7834"><code>ba6d13d</code></a> Fix release dates in changelog (<a href="https://redirect.github.com/tj/commander.js/issues/2523">#2523</a>)</li> <li><a href="https://github.com/tj/commander.js/commit/a752ed909f179e3a5dcae31a890a89fb748473c4"><code>a752ed9</code></a> Pin GitHub actions with hash (<a href="https://redirect.github.com/tj/commander.js/issues/2521">#2521</a>)</li> <li><a href="https://github.com/tj/commander.js/commit/74d5dfe9b7e199d98e2269ecf88dcf771c260983"><code>74d5dfe</code></a> Drop EOL node 20 from test matrix, and add node 26 (<a href="https://redirect.github.com/tj/commander.js/issues/2520">#2520</a>)</li> <li><a href="https://github.com/tj/commander.js/commit/6df9b68b75ad8df1532ad3572e1d5a1c53bde6cd"><code>6df9b68</code></a> Update details for 15.0.0 release (<a href="https://redirect.github.com/tj/commander.js/issues/2519">#2519</a>)</li> <li><a href="https://github.com/tj/commander.js/commit/01ce5d0cd7e845d6ed749ab57616ec9c173cf91f"><code>01ce5d0</code></a> Remove jest esm examples (<a href="https://redirect.github.com/tj/commander.js/issues/2517">#2517</a>)</li> <li><a href="https://github.com/tj/commander.js/commit/d785d8b3b9448952ef023a8cd26a0a3923a90458"><code>d785d8b</code></a> Update dependencies (<a href="https://redirect.github.com/tj/commander.js/issues/2518">#2518</a>)</li> <li><a href="https://github.com/tj/commander.js/commit/9098b4863ef7678b9d138ae0f04afd949287510c"><code>9098b48</code></a> Update dependencies (<a href="https://redirect.github.com/tj/commander.js/issues/2506">#2506</a>)</li> <li><a href="https://github.com/tj/commander.js/commit/373f660f6febb720b82635220eea72dd9b7e0cba"><code>373f660</code></a> Use node:util stripVTControlCharacters instead of own code (<a href="https://redirect.github.com/tj/commander.js/issues/2486">#2486</a>)</li> <li><a href="https://github.com/tj/commander.js/commit/987f28966c71baecb0ef4a36780e727bcd575b31"><code>987f289</code></a> Use simple match in test (to avoid warning about expensive regex) (<a href="https://redirect.github.com/tj/commander.js/issues/2485">#2485</a>)</li> <li><a href="https://github.com/tj/commander.js/commit/0ea3bb3e883eaa909f1056d0d13a06cc31ec2c3c"><code>0ea3bb3</code></a> Update dependecies and lint (<a href="https://redirect.github.com/tj/commander.js/issues/2489">#2489</a>)</li> <li>Additional commits viewable in <a href="https://github.com/tj/commander.js/compare/v13.1.0...v15.0.0">compare view</a></li> </ul> </details> <br /> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |
||
|
|
d9f759b7bc |
chore(lockfile): refresh pnpm-lock.yaml (#12178)
Add the missing server importer for @paperclipai/paperclip-runner. |
||
|
|
9964b034bb |
feat(runner): add hidden server PRP coordinator (#12176)
## Thinking Path > - Paperclip is the open source app people use to manage AI agents for work. > - The Paperclip Runner needs a narrow server trust boundary before an adapter can start it. > - The package has durable runner transport, but the server does not host or authorize that transport. > - Native persistence exists, but no writer connects PRP events to those records. > - A direct adapter must not enter this path by accident. > - This pull request adds a hidden, run-bound PRP server coordinator. > - The benefit is a recoverable server boundary that remains unavailable to normal execution. ## Linked Issues or Issue Description Refs #11962 Refs #12129 Refs #12169 **Subsystem affected** Cross-cutting. The change affects the runner package and server orchestration. **Problem or motivation** The server cannot authenticate runnerd, commit PRP events before ACK, authorize semantic tools, or enter native finalization from a durable runner result. The application must have this hidden boundary before a guarded adapter can use the runner. **Proposed solution** Add an authenticated PRP WebSocket authority and register it only for one exact persisted native Codex run. Bind each connection and event to the company, issue, agent, run, runner, session, turn, item, and verified runner identity. Commit each event before its cumulative ACK. Project only authorized same-task read tools. Rebuild the accepted result and finalization record from durable result and terminal events. **Alternatives considered** The server could expose a broad runner API key or route semantic calls through existing adapter endpoints. Those options grant too much authority and weaken replay recovery. The server could also add the user-facing adapter in this pull request. That option would mix rollout selection with the transport trust boundary and make legacy compatibility harder to review. **Roadmap alignment** This work supports the shipped enforced-outcomes, governed-tool, and self-healing-run milestones. It does not add a new roadmap surface. ## What Changed - Add the durable PRP server authority with one-use bootstrap tickets, reconnect leases, encrypted frames, bounded state, cumulative ACKs, and idempotent commands. - Add `/api/runner/v1/connect/:runId`. Derive its `ws://` or `wss://` URL from the configured Paperclip API URL. - Register one authority only after the coordinator verifies the complete native Codex run binding. - Commit validated PRP events to `heartbeat_run_events` before ACK. Reject source gaps and conflicting replays. - Rebuild accepted results and finalization records from durable result and terminal events. Enforce finalization owner leases and retry times. - Project five same-task read operations. Recheck run, agent, task, and company authority for each call. - Keep the route hidden. No adapter selects this coordinator, and no code starts runnerd. - Vendor the compiled runner TypeScript runtime into the server package while keeping the workspace package development-only for the server. - Document the package, database writer, run-log payload, and credential exclusions. ## Verification - Run `pnpm --filter @paperclipai/paperclip-runner check:all`. All TypeScript protocol checks and 69 Vitest tests pass, including commit-before-ACK crash recovery. All 43 Rust unit tests and 13 Rust integration tests pass. Conformance and replay parity pass. - Run the focused server WebSocket, coordinator, package-build, and startup-wiring suites. All 26 tests pass, including a clean-checkout reproduction with the runner `dist` directory absent. - Run `pnpm -r typecheck`. - Run `pnpm test:run`. - Run `pnpm build`. - Confirm that the diff contains 19 files. Confirm that it contains no workflow or `pnpm-lock.yaml` change. ## Risks - The server installs the WebSocket route at startup. An unregistered or malformed run path fails closed and creates no native record. - Bootstrap tickets are one use. The private state directory uses mode `0700`, and the state file uses mode `0600`. The file stores derived authentication verifiers and never stores raw tickets or lease tokens. - The journal has explicit frame, command, event-window, and file-size bounds. A bound violation closes the runner connection or rejects the command. - A runner event reaches the database before its ACK. A crash between event commit and ACK causes a byte-equivalent replay, not a second logical effect. - The coordinator accepts only an existing queued or running native Codex row with exact company, task, agent, runner, session, and completion-contract ownership. - Existing direct adapters do not call this service. They keep their current execution, transcript, result, and finalization paths. - The server has no production dependency on the private runner package. Its build copies the compiled runtime into `server/dist`; the workspace link is development-only. This adds no external package and does not change the lockfile. > For core feature work, check [`ROADMAP.md`](ROADMAP.md) first and discuss it in `#dev` before opening the PR. Feature PRs that overlap with planned core work may need to be redirected — check the roadmap first. See `CONTRIBUTING.md`. ## Model Used - OpenAI Codex with GPT-5. The exact deployment ID and context-window size are not exposed. The model used agentic reasoning, repository tools, code execution, and test execution. ## Checklist - [x] I have included a thinking path that traces from project context to this change - [x] I have specified the model used (with version and capability details) - [x] I have checked ROADMAP.md and confirmed this PR does not duplicate planned core work - [x] I have searched GitHub for duplicate or related PRs and linked them above - [x] I have either (a) linked existing issues with `Fixes: #` / `Closes #` / `Refs #` OR (b) described the issue in-PR following the relevant issue template - [x] I have not referenced internal/instance-local Paperclip issues or links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip` URLs) - [x] My branch name describes the change (e.g. `docs/...`, `fix/...`) and contains no internal Paperclip ticket id or instance-derived details - [x] I have run tests locally and they pass - [x] I have added or updated tests where applicable - [x] I have updated relevant documentation to reflect my changes - [x] I have considered and documented any risks above - [x] All Paperclip CI gates are green - [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups - [x] I will address all Greptile and reviewer comments before requesting mergecanary/v2026.825.0-canary.13 |
||
|
|
86fe9339e1 |
chore(lockfile): refresh pnpm-lock.yaml (#12174)
Auto-generated lockfile refresh after dependencies changed on master. This PR only updates pnpm-lock.yaml. Co-authored-by: lockfile-bot <lockfile-bot@users.noreply.github.com> |
||
|
|
69e8585146 |
build(deps): bump better-auth from 1.6.28 to 1.7.0 (#11886)
Bumps [better-auth](https://github.com/better-auth/better-auth/tree/HEAD/packages/better-auth) from 1.6.28 to 1.7.0. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/better-auth/better-auth/releases">better-auth's releases</a>.</em></p> <blockquote> <h2>v1.7.0</h2> <p><strong>Blog post:</strong> <a href="https://better-auth.com/blog/1-7">Better Auth 1.7</a></p> <h2><code>better-auth</code></h2> <h3>❗ Breaking Changes</h3> <ul> <li>Moved database joins out of <code>experimental</code> into the stable <code>advanced.database.joins</code> option (<a href="https://redirect.github.com/better-auth/better-auth/pull/10359">#10359</a>) <blockquote> <p><strong>Migration:</strong> Replace <code>experimental: { joins: true }</code> with <code>advanced: { database: { joins: true } }</code>. Drizzle and Prisma users should regenerate their schema (<code>npx auth@latest generate</code>) so it includes the required relations.</p> </blockquote> </li> <li>Scoped account identity by trusted issuer, keying accounts on <code>(issuer, accountId)</code> (<a href="https://redirect.github.com/better-auth/better-auth/pull/10403">#10403</a>) <blockquote> <p><strong>Migration:</strong> Accounts now require <code>Account.issuer</code>. Read provider identity from <code>accountInfo.account.accountId</code>, drop <code>mapping.id</code> from SSO configs, and give the <code>microsoftEntraId</code> helper a concrete tenant GUID. Apply the account-identity backfill in the 1.7 upgrade guide before deploying.</p> </blockquote> </li> <li>Required captcha endpoint entries to match full auth paths, with wildcard support (<a href="https://redirect.github.com/better-auth/better-auth/pull/10004">#10004</a>) <blockquote> <p><strong>Migration:</strong> Replace partial paths such as <code>/sign-in</code> with explicit wildcards like <code>/sign-in/*</code> or <code>/sign-in/**</code>.</p> </blockquote> </li> <li>Moved the MCP plugin into its own <code>@better-auth/mcp</code> package built on the OAuth provider (<a href="https://redirect.github.com/better-auth/better-auth/pull/9992">#9992</a>) <blockquote> <p><strong>Migration:</strong> Install <code>@better-auth/mcp</code> and <code>@better-auth/cimd</code>, add the now-required <code>jwt()</code> plugin, and move options nested under <code>oidcConfig</code> to flat <code>mcp({ ... })</code> options. Rename <code>withMcpAuth</code> to <code>requireMcpAuth</code> and <code>mcpHandler</code> to <code>createMcpProtectedRequestHandler</code>. Regenerate the schema (<code>npx auth migrate</code>): <code>oauthApplication</code> becomes <code>oauthClient</code>, plus new <code>oauthRefreshToken</code> and <code>oauthClientAssertion</code> tables.</p> </blockquote> </li> <li>Added OIDC back-channel logout so ending a session cuts off every connected app's API access (<a href="https://redirect.github.com/better-auth/better-auth/pull/9304">#9304</a>) <blockquote> <p><strong>Migration:</strong> Introspecting an access token whose session has ended now returns <code>{ active: false }</code>, and <code>/oauth2/userinfo</code> rejects it. Clients opt into notifications by registering <code>backchannel_logout_uri</code>. Run the schema migration for the new <code>oauthClient</code> and <code>oauthAccessToken</code> columns.</p> </blockquote> </li> <li>Modeled OAuth protected resources explicitly, with per-resource TTLs, scopes, claims, and signing pins (<a href="https://redirect.github.com/better-auth/better-auth/pull/9648">#9648</a>) <blockquote> <p><strong>Migration:</strong> <code>validAudiences</code> is removed: move each resource identifier into <code>resources</code> and link restricted clients through <code>oauthClientResource</code>. <code>@better-auth/mcp</code> now requires an explicit <code>resource</code>. Run <code>npx @better-auth/cli generate</code> and apply the migration before deploying.</p> </blockquote> </li> <li>Decoupled SCIM provisioning from the organization plugin (<a href="https://redirect.github.com/better-auth/better-auth/pull/10390">#10390</a>) <blockquote> <p><strong>Migration:</strong> SCIM configuration, client APIs, database schema, and the Group model are all replaced, and provisioning state cannot migrate in place. Follow the SCIM cutover in the 1.7 upgrade guide, including a full directory reprovision, before resuming traffic.</p> </blockquote> </li> <li>Added OTP-only two-factor enablement with a discriminated <code>enableTwoFactor</code> response (<a href="https://redirect.github.com/better-auth/better-auth/pull/9057">#9057</a>) <blockquote> <p><strong>Migration:</strong> <code>enableTwoFactor</code> now returns a <code>method</code> field (<code>"otp"</code> or <code>"totp"</code>); narrow on it before reading <code>totpURI</code> and <code>backupCodes</code>. Pass <code>method: "otp"</code> for OTP enrollment, which requires <code>otpOptions.sendOTP</code>.</p> </blockquote> </li> <li>Resolved the auth origin from <code>Host</code> by default when using a dynamic <code>baseURL</code> (<a href="https://redirect.github.com/better-auth/better-auth/pull/9134">#9134</a>) <blockquote> <p><strong>Migration:</strong> If your proxy exposes the public hostname only through <code>x-forwarded-host</code>, set <code>advanced.trustedProxyHeaders: true</code>. Deployments where the proxy rewrites <code>Host</code> (nginx default, Vercel, Cloudflare, Netlify) are unaffected.</p> </blockquote> </li> <li>Added unique lookup indexes for the device authorization <code>deviceCode</code> and <code>userCode</code> columns (<a href="https://redirect.github.com/better-auth/better-auth/pull/10059">#10059</a>) <blockquote> <p><strong>Migration:</strong> Resolve duplicate code values before applying the migration. MySQL and SQL Server installations must also convert both columns to bounded strings and clean up values longer than 191 characters.</p> </blockquote> </li> <li>Enforced S256 PKCE in the Electron sign-in flow and hardened custom-scheme origin checks (<a href="https://redirect.github.com/better-auth/better-auth/pull/9645">#9645</a>) <blockquote> <p><strong>Migration:</strong> Upgrade the <code>@better-auth/electron</code> client and server together and add your app's scheme to <code>trustedOrigins</code>. The <code>code_challenge_method</code> parameter and <code>disableOriginOverride</code> option are removed, and host-bearing custom-scheme entries now match that host exactly.</p> </blockquote> </li> <li>Identified Microsoft Entra accounts by the stable <code>oid</code> claim (<a href="https://redirect.github.com/better-auth/better-auth/pull/10204">#10204</a>) <blockquote> <p><strong>Migration:</strong> Migrate existing Microsoft account rows created from <code>sub</code> before upgrading. Tokens without a valid <code>oid</code> are rejected.</p> </blockquote> </li> <li>Required a Google client ID before Google One Tap verifies ID tokens (<a href="https://redirect.github.com/better-auth/better-auth/pull/10036">#10036</a>) <blockquote> <p><strong>Migration:</strong> Configure <code>oneTap({ clientId })</code> or <code>socialProviders.google.clientId</code>.</p> </blockquote> </li> <li>Removed the deprecated <code>oidcProvider</code> plugin (<a href="https://redirect.github.com/better-auth/better-auth/pull/10031">#10031</a>) <blockquote> <p><strong>Migration:</strong> Move OIDC authorization-server integrations to <code>@better-auth/oauth-provider</code>.</p> </blockquote> </li> <li>Rewrote the generic OAuth plugin as a first-class social provider with OAuth 2.1 defaults (<a href="https://redirect.github.com/better-auth/better-auth/pull/9069">#9069</a>) <blockquote> <p><strong>Migration:</strong> Replace <code>signIn.oauth2({ providerId })</code> with <code>signIn.social({ provider })</code>, <code>oauth2.link()</code> with <code>linkSocial()</code>, and drop <code>genericOAuthClient()</code>. Callbacks move to <code>/api/auth/callback/:id</code>, <code>pkce</code> now defaults to <code>true</code>, and <code>issuer</code> and <code>requireIssuerValidation</code> are removed in favor of OIDC discovery.</p> </blockquote> </li> <li>Separated OAuth device grant ownership into <code>oauthDeviceAuthorization()</code> (<a href="https://redirect.github.com/better-auth/better-auth/pull/10746">#10746</a>) <blockquote> <p><strong>Migration:</strong> The OAuth integration replaces the optional <code>resource</code> column with <code>oauthClientId</code> and <code>resources</code>, so regenerate and apply the schema. Let pending device codes expire before upgrading from an earlier 1.7 prerelease.</p> </blockquote> </li> <li>Verified provider <code>id_tokens</code> with a single shared verifier (<a href="https://redirect.github.com/better-auth/better-auth/pull/9828">#9828</a>) <blockquote> <p><strong>Migration:</strong> Custom <code>UpstreamProvider</code> implementations replace the removed <code>verifyIdToken</code> method with an <code>idToken</code> config carrying a JWKS source, issuer, and audience. PayPal client <code>id_token</code> sign-in now returns <code>ID_TOKEN_NOT_SUPPORTED</code>; its redirect flow is unchanged.</p> </blockquote> </li> </ul> <h3>Features</h3> <ul> <li>Added <code>clientAssertion</code> support to the Microsoft Entra ID social provider (<a href="https://redirect.github.com/better-auth/better-auth/pull/9898">#9898</a>)</li> <li>Made the <code>Auth</code> instance directly fetchable (<a href="https://redirect.github.com/better-auth/better-auth/pull/9431">#9431</a>)</li> <li>Added per-provider <code>requireEmailVerification</code> for social sign-in (<a href="https://redirect.github.com/better-auth/better-auth/pull/9929">#9929</a>)</li> <li>Added a <code>user.validateUserInfo</code> gate for rejecting an identity before a user is created or linked (<a href="https://redirect.github.com/better-auth/better-auth/pull/9864">#9864</a>)</li> <li>Added <code>hydrateSession</code> so <code>useSession</code> returns server-fetched data on the first render (<a href="https://redirect.github.com/better-auth/better-auth/pull/8733">#8733</a>)</li> <li>Added compound table indexes to plugin database schemas (<a href="https://redirect.github.com/better-auth/better-auth/pull/10402">#10402</a>)</li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/better-auth/better-auth/blob/main/packages/better-auth/CHANGELOG.md">better-auth's changelog</a>.</em></p> <blockquote> <h2>1.7.0</h2> <h3>Minor Changes</h3> <ul> <li> <p><a href="https://redirect.github.com/better-auth/better-auth/pull/8733">#8733</a> <a href="https://github.com/better-auth/better-auth/commit/4e8e4c7fc5fb2723144cbf41c4a1bfa28de8d671"><code>4e8e4c7</code></a> Thanks <a href="https://github.com/bytaesu"><code>@bytaesu</code></a>! - Add <code>hydrateSession</code> to seed the client with a server-fetched session so <code>useSession</code> returns data on the first render.</p> </li> <li> <p><a href="https://redirect.github.com/better-auth/better-auth/pull/9930">#9930</a> <a href="https://github.com/better-auth/better-auth/commit/0cbaf81bed9dec4c56880ee78a532262386e1ec5"><code>0cbaf81</code></a> Thanks <a href="https://github.com/gustavovalverde"><code>@gustavovalverde</code></a>! - Anonymous account linking now works after social and generic OAuth sign-in in Expo and other in-app browsers, where the OAuth callback returns without the session cookie. <code>onLinkAccount</code> fires and the anonymous user is migrated; before, it was silently skipped.</p> <p>Plugins can now carry server-trusted data across an OAuth redirect with the new <code>addOAuthServerContext</code> API, read back on the callback via <code>getOAuthState().serverContext</code>. Unlike <code>additionalData</code>, it cannot be set from the request body, so it is the right place for values the server must trust.</p> <p>For <code>@better-auth/oauth-provider</code>, the post-login authorization query now travels through that server-only channel, so it can no longer be injected through <code>additionalData</code>.</p> </li> <li> <p><a href="https://redirect.github.com/better-auth/better-auth/pull/10004">#10004</a> <a href="https://github.com/better-auth/better-auth/commit/b36c38f9842d3416689340552989449a32007819"><code>b36c38f</code></a> Thanks <a href="https://github.com/bytaesu"><code>@bytaesu</code></a>! - The captcha plugin now requires endpoint entries to match full auth paths unless they use wildcard patterns. This prevents requests like <code>/sign-in//email</code> from bypassing captcha while preserving trailing-slash matches like <code>/sign-in/email/</code>. To protect multiple routes, replace partial paths like <code>/sign-in</code> with explicit wildcards such as <code>/sign-in/*</code> or <code>/sign-in/**</code>.</p> </li> <li> <p><a href="https://redirect.github.com/better-auth/better-auth/pull/10746">#10746</a> <a href="https://github.com/better-auth/better-auth/commit/6782647d7c2d248246f9ef3980e656725c29ce64"><code>6782647</code></a> Thanks <a href="https://github.com/gustavovalverde"><code>@gustavovalverde</code></a>! - OAuth device grants now use <code>oauthDeviceAuthorization()</code> alongside <code>oauthProvider()</code> or <code>mcp()</code>. This single integration replaces both the standalone <code>deviceCodeGrant()</code> plugin and the shared-grant configuration. Standalone Device Authorization no longer accepts or stores RFC 8707 resources, and <code>onDeviceAuthRequest</code> receives only <code>clientId</code> and <code>scope</code>. The OAuth integration rejects resource indicators that are not absolute, fragment-free URIs.</p> <p>The OAuth integration replaces the optional <code>resource</code> column with <code>oauthClientId</code> and <code>resources</code>. Regenerate and apply the schema when using it. Before upgrading from an earlier 1.7 prerelease, let pending OAuth device codes expire or delete them because they cannot be exchanged through the new integration.</p> </li> <li> <p><a href="https://redirect.github.com/better-auth/better-auth/pull/10402">#10402</a> <a href="https://github.com/better-auth/better-auth/commit/763a2671c5372d88c291881977c8a1c2e29034b1"><code>763a267</code></a> Thanks <a href="https://github.com/gustavovalverde"><code>@gustavovalverde</code></a>! - Plugin database schemas can now define named or generated table-level indexes across multiple fields. SQL migrations and generated Drizzle or Prisma schemas resolve configured table and column names consistently, while the MongoDB adapter creates the same indexes before the first index-enforcing write.</p> </li> <li> <p><a href="https://redirect.github.com/better-auth/better-auth/pull/9766">#9766</a> <a href="https://github.com/better-auth/better-auth/commit/bf39cbf13f3b934f728cde72b1e7ebdc4c85f641"><code>bf39cbf</code></a> Thanks <a href="https://github.com/GautamBytes"><code>@GautamBytes</code></a>! - Add a server-only <code>auth.api.consumePhoneNumberOTP</code> API for custom phone OTP flows that need to verify and consume a code without creating or updating users or sessions.</p> </li> <li> <p><a href="https://redirect.github.com/better-auth/better-auth/pull/10330">#10330</a> <a href="https://github.com/better-auth/better-auth/commit/081d3c379c720926295067d878c421b5e8684c78"><code>081d3c3</code></a> Thanks <a href="https://github.com/ping-maxwell"><code>@ping-maxwell</code></a>! - Allow the username plugin's separate <code>displayUsername</code> field to be omitted by setting <code>displayUsername: false</code> on both the server and client plugins.</p> </li> <li> <p><a href="https://redirect.github.com/better-auth/better-auth/pull/10059">#10059</a> <a href="https://github.com/better-auth/better-auth/commit/49b5cf650e1264ecc4c917ca193ea05c3b58a3b9"><code>49b5cf6</code></a> Thanks <a href="https://github.com/GautamBytes"><code>@GautamBytes</code></a>! - Device Authorization now creates unique database indexes for <code>deviceCode</code> and <code>userCode</code>, so each generated code must be unique in its column. Existing installations on every adapter must resolve duplicate values before applying the migration. MySQL and SQL Server installations must also convert both columns to bounded strings and clean up values longer than 191 characters before running it.</p> <p>Generated codes are limited to 191 characters. Issuance makes up to 3 attempts to overcome unique-key collisions, then returns <code>server_error</code> if it cannot create a unique <code>deviceCode</code> and <code>userCode</code>. Default-generated user codes accept case changes and readability separators during verification, approval, and denial; custom codes outside the default alphabet are matched exactly. The <code>/device</code> limiter allows 5 requests over a window equal to the configured code lifetime, while <code>/device/token</code> polling keeps its separate interval behavior.</p> </li> <li> <p><a href="https://redirect.github.com/better-auth/better-auth/pull/9645">#9645</a> <a href="https://github.com/better-auth/better-auth/commit/e0140297a59ddb59cccbcb4ba46c513de8cb86a7"><code>e014029</code></a> Thanks <a href="https://github.com/ping-maxwell"><code>@ping-maxwell</code></a>! - Harden the Electron OAuth flow and tighten custom-scheme trusted-origin matching.</p> <p>The Electron sign-in flow now mandates PKCE S256. Plain PKCE is rejected: the <code>code_challenge_method</code> parameter is gone and every authorization code is verified by hashing the verifier with SHA-256. The server no longer trusts an <code>electron-origin</code> header to set the request Origin. The Electron client now sends a real <code>Origin</code> (for example <code>myapp:/</code>), so upgrade the <code>@better-auth/electron</code> client and server together and make sure your app's scheme is in <code>trustedOrigins</code>. The unused <code>disableOriginOverride</code> option is removed.</p> <p>Custom-scheme entries in <code>trustedOrigins</code> now match by scheme and authority instead of string prefix. A host-less entry such as <code>myapp://</code> or <code>exp://</code> still trusts every host of that scheme, but a host-bearing entry such as <code>myapp://callback</code> matches that host exactly, so it is no longer satisfied by <code>myapp://callback.attacker.tld</code>.</p> </li> <li> <p><a href="https://redirect.github.com/better-auth/better-auth/pull/9948">#9948</a> <a href="https://github.com/better-auth/better-auth/commit/3d04fababbf3efd4c46a4012f46ed9397715c2e3"><code>3d04fab</code></a> Thanks <a href="https://github.com/yordis"><code>@yordis</code></a>! - feat(generic-oauth): add <code>refreshTokenParams</code> config to forward extra params on token refresh</p> <p>Multi-tenant OIDC providers (Zitadel multi-org, Auth0 with <code>audience</code>) need to send extra body params on the refresh call to rescope tokens without a full authorization redirect. The generic-oauth plugin now accepts a <code>refreshTokenParams</code> option (object or sync/async function) that is merged into the refresh request body, with <code>grant_type</code> and <code>refresh_token</code> protected from override. The function form receives request metadata for the request that triggered the refresh, so request-scoped data (headers, cookies) is available without out-of-band state like AsyncLocalStorage.</p> <p><code>UpstreamProvider.refreshAccessToken</code> now accepts an optional second <code>ctx</code> argument; the change is backwards compatible because existing implementations that take only <code>refreshToken</code> remain valid. See <a href="https://redirect.github.com/better-auth/better-auth/issues/7554">#7554</a>.</p> </li> <li> <p><a href="https://redirect.github.com/better-auth/better-auth/pull/9069">#9069</a> <a href="https://github.com/better-auth/better-auth/commit/c7d22539ec4f7322d9625ae2953d397c3863d097"><code>c7d2253</code></a> Thanks <a href="https://github.com/gustavovalverde"><code>@gustavovalverde</code></a>! - Rewrite the generic OAuth plugin as a first-class social provider with OAuth 2.1 security defaults. Providers now use <code>signIn.social</code> + <code>callback/:id</code> instead of dedicated plugin endpoints, with PKCE required by default (OAuth 2.1), RFC 9207 issuer validation, OIDC auto-discovery with <code>openid</code> scope injection, and typed provider IDs.</p> <p><strong>Breaking changes:</strong></p> <ul> <li><code>signIn.oauth2({ providerId })</code> replaced by <code>signIn.social({ provider })</code></li> <li><code>oauth2.link()</code> replaced by <code>linkSocial()</code></li> <li>Callback URL changed from <code>/api/auth/oauth2/callback/:id</code> to <code>/api/auth/callback/:id</code></li> <li><code>genericOAuthClient()</code> removed; generic OAuth providers now use the standard social client APIs</li> <li><code>pkce</code> defaults to <code>true</code> (was <code>false</code>); set <code>pkce: false</code> for providers that reject PKCE</li> <li><code>authorizationUrlParams</code> and <code>tokenUrlParams</code> only accept <code>Record<string, string></code></li> </ul> </li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/better-auth/better-auth/commit/ccd57c2dcb145a40a30c75ab3f6c89b94af08701"><code>ccd57c2</code></a> docs(changelog): align v1.7 release notes with final behavior (<a href="https://github.com/better-auth/better-auth/tree/HEAD/packages/better-auth/issues/10846">#10846</a>)</li> <li><a href="https://github.com/better-auth/better-auth/commit/f577ec5c766c4ccd0a677ad18ca5f4f17b245289"><code>f577ec5</code></a> chore: exit pre-release mode for v1.7.0</li> <li><a href="https://github.com/better-auth/better-auth/commit/69258d16709b977e519aa00a323ae54aea2b6164"><code>69258d1</code></a> chore: sync main to next</li> <li><a href="https://github.com/better-auth/better-auth/commit/e84ec5e76d30e10fd692e8084177360484d538c1"><code>e84ec5e</code></a> chore: release v1.6.30 (<a href="https://github.com/better-auth/better-auth/tree/HEAD/packages/better-auth/issues/10840">#10840</a>)</li> <li><a href="https://github.com/better-auth/better-auth/commit/bc93b27542cbdf74f6455e6f66a0b4292c247a12"><code>bc93b27</code></a> chore: release v1.7.0-rc.6 (<a href="https://github.com/better-auth/better-auth/tree/HEAD/packages/better-auth/issues/10772">#10772</a>)</li> <li><a href="https://github.com/better-auth/better-auth/commit/58c49eb97f04ff18aa823318a3856a013353fdc2"><code>58c49eb</code></a> chore: release v1.6.29 (<a href="https://github.com/better-auth/better-auth/tree/HEAD/packages/better-auth/issues/10809">#10809</a>)</li> <li><a href="https://github.com/better-auth/better-auth/commit/e6e1b4e8146a84d2a2c5fe2c497c81d03dfc2ad3"><code>e6e1b4e</code></a> perf(db): replace sequential get-then-delete loop with parallel deletes in de...</li> <li><a href="https://github.com/better-auth/better-auth/commit/80799e69314d4d13c875457d932545d54fbc7ada"><code>80799e6</code></a> chore: sync main to next</li> <li><a href="https://github.com/better-auth/better-auth/commit/3e485bf730c62b4ef3df2e55198179c3d15b5a9f"><code>3e485bf</code></a> docs(username): fix displayUsername release notes (<a href="https://github.com/better-auth/better-auth/tree/HEAD/packages/better-auth/issues/10776">#10776</a>)</li> <li><a href="https://github.com/better-auth/better-auth/commit/65fc17c755c3e2c8c77d5b401d612737764c219d"><code>65fc17c</code></a> fix(deps): align <code>drizzle-orm</code> peer range with drizzle-adapter (<a href="https://github.com/better-auth/better-auth/tree/HEAD/packages/better-auth/issues/10501">#10501</a>)</li> <li>Additional commits viewable in <a href="https://github.com/better-auth/better-auth/commits/v1.7.0/packages/better-auth">compare view</a></li> </ul> </details> <br /> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |
||
|
|
c5382b36ba |
build(deps-dev): bump vite from 6.4.3 to 8.2.2 (#11887)
Bumps [vite](https://github.com/vitejs/vite/tree/HEAD/packages/vite) from 6.4.3 to 8.2.2. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/vitejs/vite/releases">vite's releases</a>.</em></p> <blockquote> <h2>plugin-legacy@8.2.2</h2> <p>Please refer to <a href="https://github.com/vitejs/vite/blob/plugin-legacy@8.2.2/packages/plugin-legacy/CHANGELOG.md">CHANGELOG.md</a> for details.</p> <h2>v8.2.2</h2> <p>Please refer to <a href="https://github.com/vitejs/vite/blob/v8.2.2/packages/vite/CHANGELOG.md">CHANGELOG.md</a> for details.</p> <h2>plugin-legacy@8.2.1</h2> <p>Please refer to <a href="https://github.com/vitejs/vite/blob/plugin-legacy@8.2.1/packages/plugin-legacy/CHANGELOG.md">CHANGELOG.md</a> for details.</p> <h2>v8.2.1</h2> <p>Please refer to <a href="https://github.com/vitejs/vite/blob/v8.2.1/packages/vite/CHANGELOG.md">CHANGELOG.md</a> for details.</p> <h2>create-vite@8.2.0</h2> <p>Please refer to <a href="https://github.com/vitejs/vite/blob/create-vite@8.2.0/packages/create-vite/CHANGELOG.md">CHANGELOG.md</a> for details.</p> <h2>plugin-legacy@8.2.0</h2> <p>Please refer to <a href="https://github.com/vitejs/vite/blob/plugin-legacy@8.2.0/packages/plugin-legacy/CHANGELOG.md">CHANGELOG.md</a> for details.</p> <h2>v8.2.0</h2> <p>Please refer to <a href="https://github.com/vitejs/vite/blob/v8.2.0/packages/vite/CHANGELOG.md">CHANGELOG.md</a> for details.</p> <h2>v8.2.0-beta.0</h2> <p>Please refer to <a href="https://github.com/vitejs/vite/blob/v8.2.0-beta.0/packages/vite/CHANGELOG.md">CHANGELOG.md</a> for details.</p> <h2>v8.1.5</h2> <p>Please refer to <a href="https://github.com/vitejs/vite/blob/v8.1.5/packages/vite/CHANGELOG.md">CHANGELOG.md</a> for details.</p> <h2>v8.1.4</h2> <p>Please refer to <a href="https://github.com/vitejs/vite/blob/v8.1.4/packages/vite/CHANGELOG.md">CHANGELOG.md</a> for details.</p> <h2>v8.1.3</h2> <p>Please refer to <a href="https://github.com/vitejs/vite/blob/v8.1.3/packages/vite/CHANGELOG.md">CHANGELOG.md</a> for details.</p> <h2>v8.1.2</h2> <p>Please refer to <a href="https://github.com/vitejs/vite/blob/v8.1.2/packages/vite/CHANGELOG.md">CHANGELOG.md</a> for details.</p> <h2>v8.1.1</h2> <p>Please refer to <a href="https://github.com/vitejs/vite/blob/v8.1.1/packages/vite/CHANGELOG.md">CHANGELOG.md</a> for details.</p> <h2>create-vite@8.1.0</h2> <p>Please refer to <a href="https://github.com/vitejs/vite/blob/create-vite@8.1.0/packages/create-vite/CHANGELOG.md">CHANGELOG.md</a> for details.</p> <h2>plugin-legacy@8.1.0</h2> <p>Please refer to <a href="https://github.com/vitejs/vite/blob/plugin-legacy@8.1.0/packages/plugin-legacy/CHANGELOG.md">CHANGELOG.md</a> for details.</p> <h2>v8.1.0</h2> <p>Please refer to <a href="https://github.com/vitejs/vite/blob/v8.1.0/packages/vite/CHANGELOG.md">CHANGELOG.md</a> for details.</p> <h2>plugin-legacy@8.1.0-beta.0</h2> <p>Please refer to <a href="https://github.com/vitejs/vite/blob/plugin-legacy@8.1.0-beta.0/packages/plugin-legacy/CHANGELOG.md">CHANGELOG.md</a> for details.</p> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/vitejs/vite/blob/main/packages/vite/CHANGELOG.md">vite's changelog</a>.</em></p> <blockquote> <h2><!-- raw HTML omitted --><a href="https://github.com/vitejs/vite/compare/v8.2.1...v8.2.2">8.2.2</a> (2026-08-20)<!-- raw HTML omitted --></h2> <h3>Features</h3> <ul> <li><strong>deps:</strong> widen <code>@vitejs/devtools</code> peer range to v0.5.0 (<a href="https://redirect.github.com/vitejs/vite/issues/23302">#23302</a>) (<a href="https://github.com/vitejs/vite/commit/495d9ff5a7d843ca876a9e49799947a5deb704c7">495d9ff</a>)</li> </ul> <h3>Bug Fixes</h3> <ul> <li><strong>bundled-dev:</strong> handle lazy request error (<a href="https://redirect.github.com/vitejs/vite/issues/23291">#23291</a>) (<a href="https://github.com/vitejs/vite/commit/3ba026dade4af56df08815310d3458fa110f5c5c">3ba026d</a>)</li> <li><strong>bundled-dev:</strong> hot update through circular imports instead of reloading (<a href="https://redirect.github.com/vitejs/vite/issues/23259">#23259</a>) (<a href="https://github.com/vitejs/vite/commit/3dbddefaafc091a879b06f9279296f776691e455">3dbddef</a>)</li> <li><strong>config:</strong> resolve sourcemap paths against sourcemap location (<a href="https://redirect.github.com/vitejs/vite/issues/23239">#23239</a>) (<a href="https://github.com/vitejs/vite/commit/05a003e6a17a84d75f907ea0f1598bc39b8dce6c">05a003e</a>)</li> <li><strong>css:</strong> don't pass empty targets to lightningcss (<a href="https://redirect.github.com/vitejs/vite/issues/23295">#23295</a>) (<a href="https://github.com/vitejs/vite/commit/2804636ff608d105928009d274ffba7cfbe55340">2804636</a>)</li> <li><strong>define:</strong> fix match escaped dots to support $-prefixed define keys (<a href="https://redirect.github.com/vitejs/vite/issues/23249">#23249</a>) (<a href="https://github.com/vitejs/vite/commit/dcf88bd2ad2b1a8845f9029587cc8c825e382d42">dcf88bd</a>)</li> <li><strong>deps:</strong> update all non-major dependencies (<a href="https://redirect.github.com/vitejs/vite/issues/23217">#23217</a>) (<a href="https://github.com/vitejs/vite/commit/ba958bddfc9cabe302c6b34269dcf5c9634531e0">ba958bd</a>)</li> <li><strong>deps:</strong> update rolldown-related dependencies (<a href="https://redirect.github.com/vitejs/vite/issues/23218">#23218</a>) (<a href="https://github.com/vitejs/vite/commit/83ecb2c8059e8ce946a7cc835d4c14ef78aef4fd">83ecb2c</a>)</li> <li><strong>module-runner:</strong> exclude completed modules from in-flight cycle detection (fix <a href="https://redirect.github.com/vitejs/vite/issues/22999">#22999</a>) (<a href="https://redirect.github.com/vitejs/vite/issues/23009">#23009</a>) (<a href="https://github.com/vitejs/vite/commit/d9b10a98db1c293ee64300bd75d568b44c8ae931">d9b10a9</a>)</li> <li><strong>optimizer:</strong> close custom extension analysis bundles (<a href="https://redirect.github.com/vitejs/vite/issues/23207">#23207</a>) (<a href="https://github.com/vitejs/vite/commit/8fb76752836f61224d3095b502fa237b478a06b2">8fb7675</a>)</li> <li>reduce Windows 8.3-short-name detection false-positives (<a href="https://redirect.github.com/vitejs/vite/issues/23066">#23066</a>) (<a href="https://github.com/vitejs/vite/commit/02cffa9e2d38d5d8f12e4043ee9d0f7abb1471e2">02cffa9</a>)</li> <li>respect <code>resolve.preserveSymlinks</code> when resolving root (fix <a href="https://redirect.github.com/vitejs/vite/issues/23197">#23197</a>) (<a href="https://redirect.github.com/vitejs/vite/issues/23198">#23198</a>) (<a href="https://github.com/vitejs/vite/commit/8413052731836d4aaf3eb94a0f25788dd35d2888">8413052</a>)</li> <li><strong>ssr:</strong> rewrite computed key of destructing parameter (<a href="https://redirect.github.com/vitejs/vite/issues/23307">#23307</a>) (<a href="https://github.com/vitejs/vite/commit/9db0b61d4c9c7caad7ea1d9670b637faf2bb6c93">9db0b61</a>)</li> <li><strong>vite:</strong> update outdated upstream file links in license comments (<a href="https://redirect.github.com/vitejs/vite/issues/23285">#23285</a>) (<a href="https://github.com/vitejs/vite/commit/c0f2fc607ee97ee4499337b04826420c00654065">c0f2fc6</a>)</li> </ul> <h3>Documentation</h3> <ul> <li><strong>build:</strong> note cssTarget precedence (<a href="https://redirect.github.com/vitejs/vite/issues/23200">#23200</a>) (<a href="https://github.com/vitejs/vite/commit/a20a35ec0685e374519864d0f41dd5f6e9ba0271">a20a35e</a>)</li> </ul> <h3>Miscellaneous Chores</h3> <ul> <li>fix ts errors in build test cases (<a href="https://redirect.github.com/vitejs/vite/issues/23209">#23209</a>) (<a href="https://github.com/vitejs/vite/commit/a0cfcf72f8ef8bf0f2f11d553333b9bb31f1d316">a0cfcf7</a>)</li> </ul> <h3>Code Refactoring</h3> <ul> <li>use JSON import attributes instead of readFileSync in constants (<a href="https://redirect.github.com/vitejs/vite/issues/23258">#23258</a>) (<a href="https://github.com/vitejs/vite/commit/1d9fa392a43229241f80630236f8552ce8f7cd0f">1d9fa39</a>)</li> <li>use named regex constants over inline literals (<a href="https://redirect.github.com/vitejs/vite/issues/22964">#22964</a>) (<a href="https://github.com/vitejs/vite/commit/5c1c6c609718303202832f706884192e1f1e9223">5c1c6c6</a>)</li> </ul> <h3>Tests</h3> <ul> <li><strong>define:</strong> close rolldown bundler after generate (<a href="https://redirect.github.com/vitejs/vite/issues/23231">#23231</a>) (<a href="https://github.com/vitejs/vite/commit/b4d66fee14d970f45b8a6f3d7d6aee73ca9b88ab">b4d66fe</a>)</li> <li><strong>module-runner:</strong> add TLA circular import case (<a href="https://redirect.github.com/vitejs/vite/issues/23299">#23299</a>) (<a href="https://github.com/vitejs/vite/commit/4a261f242831bef92afd2f1aacfb81eab9dec371">4a261f2</a>)</li> <li><strong>module-runner:</strong> simplify server-hmr tests (<a href="https://redirect.github.com/vitejs/vite/issues/23300">#23300</a>) (<a href="https://github.com/vitejs/vite/commit/599b44b6600ec426e10cd556908d53b027b0c4fb">599b44b</a>)</li> <li><strong>ssr:</strong> add destructing assignment case for moduleRunnerTransform (<a href="https://redirect.github.com/vitejs/vite/issues/23308">#23308</a>) (<a href="https://github.com/vitejs/vite/commit/cb77e2a93bad2a8ece00b4aa0ef507c092582c45">cb77e2a</a>)</li> </ul> <h3>Build System</h3> <ul> <li>use JSON import attributes instead of readFIleSync in rolldown configs (<a href="https://redirect.github.com/vitejs/vite/issues/23251">#23251</a>) (<a href="https://github.com/vitejs/vite/commit/d615bcdb23d96c1ca5ce1ee45e21d8d87381106f">d615bcd</a>)</li> </ul> <h2><!-- raw HTML omitted --><a href="https://github.com/vitejs/vite/compare/v8.2.0...v8.2.1">8.2.1</a> (2026-08-06)<!-- raw HTML omitted --></h2> <h3>Bug Fixes</h3> <ul> <li><strong>build:</strong> make client chunkImportMap work with <code>sharedPlugins: true</code> (<a href="https://redirect.github.com/vitejs/vite/issues/23184">#23184</a>) (<a href="https://github.com/vitejs/vite/commit/15f03073c915d6ffb9a1fda447ef66b02bf5cde8">15f0307</a>)</li> <li><strong>bundled-dev:</strong> inject client script tag before chunk scripts (<a href="https://redirect.github.com/vitejs/vite/issues/23161">#23161</a>) (<a href="https://github.com/vitejs/vite/commit/eac0cc84aa2472a85a19ee84561c1ba71e381a55">eac0cc8</a>)</li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/vitejs/vite/commit/de1111ab0be00879b404e7ed3b2a80e264edddc1"><code>de1111a</code></a> release: v8.2.2</li> <li><a href="https://github.com/vitejs/vite/commit/cb77e2a93bad2a8ece00b4aa0ef507c092582c45"><code>cb77e2a</code></a> test(ssr): add destructing assignment case for moduleRunnerTransform (<a href="https://github.com/vitejs/vite/tree/HEAD/packages/vite/issues/23308">#23308</a>)</li> <li><a href="https://github.com/vitejs/vite/commit/9db0b61d4c9c7caad7ea1d9670b637faf2bb6c93"><code>9db0b61</code></a> fix(ssr): rewrite computed key of destructing parameter (<a href="https://github.com/vitejs/vite/tree/HEAD/packages/vite/issues/23307">#23307</a>)</li> <li><a href="https://github.com/vitejs/vite/commit/8413052731836d4aaf3eb94a0f25788dd35d2888"><code>8413052</code></a> fix: respect <code>resolve.preserveSymlinks</code> when resolving root (fix <a href="https://github.com/vitejs/vite/tree/HEAD/packages/vite/issues/23197">#23197</a>) (<a href="https://github.com/vitejs/vite/tree/HEAD/packages/vite/issues/23">#23</a>...</li> <li><a href="https://github.com/vitejs/vite/commit/05a003e6a17a84d75f907ea0f1598bc39b8dce6c"><code>05a003e</code></a> fix(config): resolve sourcemap paths against sourcemap location (<a href="https://github.com/vitejs/vite/tree/HEAD/packages/vite/issues/23239">#23239</a>)</li> <li><a href="https://github.com/vitejs/vite/commit/495d9ff5a7d843ca876a9e49799947a5deb704c7"><code>495d9ff</code></a> feat(deps): widen <code>@vitejs/devtools</code> peer range to v0.5.0 (<a href="https://github.com/vitejs/vite/tree/HEAD/packages/vite/issues/23302">#23302</a>)</li> <li><a href="https://github.com/vitejs/vite/commit/1d9fa392a43229241f80630236f8552ce8f7cd0f"><code>1d9fa39</code></a> refactor: use JSON import attributes instead of readFileSync in constants (<a href="https://github.com/vitejs/vite/tree/HEAD/packages/vite/issues/2">#2</a>...</li> <li><a href="https://github.com/vitejs/vite/commit/2804636ff608d105928009d274ffba7cfbe55340"><code>2804636</code></a> fix(css): don't pass empty targets to lightningcss (<a href="https://github.com/vitejs/vite/tree/HEAD/packages/vite/issues/23295">#23295</a>)</li> <li><a href="https://github.com/vitejs/vite/commit/599b44b6600ec426e10cd556908d53b027b0c4fb"><code>599b44b</code></a> test(module-runner): simplify server-hmr tests (<a href="https://github.com/vitejs/vite/tree/HEAD/packages/vite/issues/23300">#23300</a>)</li> <li><a href="https://github.com/vitejs/vite/commit/4a261f242831bef92afd2f1aacfb81eab9dec371"><code>4a261f2</code></a> test(module-runner): add TLA circular import case (<a href="https://github.com/vitejs/vite/tree/HEAD/packages/vite/issues/23299">#23299</a>)</li> <li>Additional commits viewable in <a href="https://github.com/vitejs/vite/commits/v8.2.2/packages/vite">compare view</a></li> </ul> </details> <br /> --------- Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: Priya Raman <priya@paperclip.ing> Co-authored-by: Paperclip <noreply@paperclip.ing> |
||
|
|
4d2af732ae |
feat(runner): add native persistence contracts (#12169)
## Thinking Path > - Paperclip is the open source app people use to manage AI agents for work. > - Agent runs need durable records so Paperclip can explain results and final status changes. > - The current heartbeat tables support direct adapters, but they do not model native runner evidence. > - The runner transport and server coordinator must share a strict finalization contract before they write production data. > - This pull request adds that contract and its additive database boundary. > - It does not select the Paperclip Runner or change any existing adapter execution path. > - The benefit is a reviewable persistence layer that preserves all current behavior and supports later guarded integration. ## Linked Issues or Issue Description Refs #11962 Refs #12129 ## What Changed - Add native run result, finalization, completion, assessment, status decision, and status effect tables. - Add inert native metadata to heartbeat runs and events. Keep `legacy` as the default runtime mode. - Bind each evidence relationship to one company, issue, run, contract, result, assessment, and decision with composite constraints. - Add a strict `paperclip.native_finalization.v1` shared type and validator. - Preserve database functions, triggers, and the unique indexes required by foreign keys in JavaScript backups. - Add migration, backup, mixed-owner denial, validator, and direct-adapter compatibility tests. - Document the new records and their ownership rules. ## Verification - Run `pnpm -r typecheck`. - Run `pnpm build`. - Run `pnpm db:generate`. The schema output and migration safety checks remain current. - Run `PAPERCLIP_PSQL_PATH=/Applications/Postgres.app/Contents/Versions/latest/bin/psql pnpm exec vitest run packages/shared/src/validators/native-finalization.test.ts packages/db/src/client.test.ts packages/db/src/backup-lib.test.ts server/src/__tests__/heartbeat-workspace-busy.test.ts server/src/__tests__/heartbeat-comment-wake-batching.test.ts`. All 52 tests pass. - The full local `pnpm test:run` run completed 4,688 tests. It found 30 existing macOS test-environment failures. A serial rerun with the canonical `/private/tmp` path reduced those failures to six existing listener-diagnostics and skill-browser cases. None of those suites use files in this change. - The full Linux GitHub Actions matrix passes. This includes all general-server, serialized-server, workspace, browser, build, typecheck, canary, and aggregate verification jobs. - Greptile passes at 5/5. Contributor trust, Superagent, Socket, and Snyk pass with no finding from this change. - Storybook visual regression skips by path because this pull request has no UI or Storybook change. - Confirm that the diff contains 25 files. Confirm that it contains no workflow or `pnpm-lock.yaml` changes. ## Risks - The migration adds tables, columns, indexes, a function, a trigger, and ownership constraints. It does not remove or rename existing data. - Composite foreign keys reject mixed-company, mixed-issue, and mixed-run evidence even when each ID exists. - The status-version trigger runs only when an issue status changes. Backup tests confirm that restore retains this trigger and its dependencies. - Native source identifiers are unique when present. Legacy event rows remain unchanged. - This change does not add a unique run sequence constraint. The later native writer must allocate its sequence atomically before that invariant can be safe. - Existing adapters keep their current execution and finalization paths. New heartbeat runs default to `legacy` mode. > For core feature work, check [`ROADMAP.md`](ROADMAP.md) first and discuss it in `#dev` before opening the PR. Feature PRs that overlap with planned core work may need to be redirected — check the roadmap first. See `CONTRIBUTING.md`. ## Model Used - OpenAI Codex with GPT-5. The exact deployment ID and context-window size are not exposed. The model used agentic reasoning, repository tools, code execution, and test execution. ## Checklist - [x] I have included a thinking path that traces from project context to this change - [x] I have specified the model used (with version and capability details) - [x] I have checked ROADMAP.md and confirmed this PR does not duplicate planned core work - [x] I have searched GitHub for duplicate or related PRs and linked them above - [x] I have either (a) linked existing issues with `Fixes: #` / `Closes #` / `Refs #` OR (b) described the issue in-PR following the relevant issue template - [x] I have not referenced internal/instance-local Paperclip issues or links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip` URLs) - [x] My branch name describes the change (e.g. `docs/...`, `fix/...`) and contains no internal Paperclip ticket id or instance-derived details - [x] I have run tests locally and they pass - [x] I have added or updated tests where applicable - [x] I have updated relevant documentation to reflect my changes - [x] I have considered and documented any risks above - [x] All Paperclip CI gates are green - [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups - [x] I will address all Greptile and reviewer comments before requesting merge --------- Co-authored-by: Paperclip <noreply@paperclip.ing> |
||
|
|
0b01593602 |
build(deps): bump lucide-react from 0.577.0 to 1.32.0 (#11885)
Bumps [lucide-react](https://github.com/lucide-icons/lucide/tree/HEAD/packages/lucide-react) from 0.577.0 to 1.32.0. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/lucide-icons/lucide/releases">lucide-react's releases</a>.</em></p> <blockquote> <h2>Version 1.32.0</h2> <h2>What's Changed</h2> <ul> <li>feat(icons): added <code>car-battery</code> icon by <a href="https://github.com/andreynaz4renko"><code>@andreynaz4renko</code></a> in <a href="https://redirect.github.com/lucide-icons/lucide/pull/4088">lucide-icons/lucide#4088</a></li> <li>fix(categories): fixes emoji.json by <a href="https://github.com/karsa-mistmere"><code>@karsa-mistmere</code></a> in <a href="https://redirect.github.com/lucide-icons/lucide/pull/4697">lucide-icons/lucide#4697</a></li> <li>chore(deps): bump vue from 3.5.40 to 3.5.41 in the vue-deps group across 1 directory by <a href="https://github.com/dependabot"><code>@dependabot</code></a>[bot] in <a href="https://redirect.github.com/lucide-icons/lucide/pull/4695">lucide-icons/lucide#4695</a></li> <li>chore(dev): upgrade ESLint to latest compatible stack (v10) by <a href="https://github.com/ericfennis"><code>@ericfennis</code></a> with <a href="https://github.com/Copilot"><code>@Copilot</code></a> in <a href="https://redirect.github.com/lucide-icons/lucide/pull/4378">lucide-icons/lucide#4378</a></li> <li>feat(icons): add square-text by <a href="https://github.com/samuelalake"><code>@samuelalake</code></a> in <a href="https://redirect.github.com/lucide-icons/lucide/pull/4609">lucide-icons/lucide#4609</a></li> </ul> <h2>New Contributors</h2> <ul> <li><a href="https://github.com/andreynaz4renko"><code>@andreynaz4renko</code></a> made their first contribution in <a href="https://redirect.github.com/lucide-icons/lucide/pull/4088">lucide-icons/lucide#4088</a></li> </ul> <p><strong>Full Changelog</strong>: <a href="https://github.com/lucide-icons/lucide/compare/1.31.0...1.32.0">https://github.com/lucide-icons/lucide/compare/1.31.0...1.32.0</a></p> <h2>Version 1.31.0</h2> <h2>What's Changed</h2> <ul> <li>feat(icons): added <code>mail-badge</code> icon by <a href="https://github.com/lazerg"><code>@lazerg</code></a> in <a href="https://redirect.github.com/lucide-icons/lucide/pull/4638">lucide-icons/lucide#4638</a></li> <li>feat(icons): add angle by <a href="https://github.com/samuelalake"><code>@samuelalake</code></a> in <a href="https://redirect.github.com/lucide-icons/lucide/pull/4545">lucide-icons/lucide#4545</a></li> <li>feat(icons): added <code>eject</code> icon by <a href="https://github.com/ThibautMarechal"><code>@ThibautMarechal</code></a> in <a href="https://redirect.github.com/lucide-icons/lucide/pull/4043">lucide-icons/lucide#4043</a></li> </ul> <h2>New Contributors</h2> <ul> <li><a href="https://github.com/lazerg"><code>@lazerg</code></a> made their first contribution in <a href="https://redirect.github.com/lucide-icons/lucide/pull/4638">lucide-icons/lucide#4638</a></li> <li><a href="https://github.com/ThibautMarechal"><code>@ThibautMarechal</code></a> made their first contribution in <a href="https://redirect.github.com/lucide-icons/lucide/pull/4043">lucide-icons/lucide#4043</a></li> </ul> <p><strong>Full Changelog</strong>: <a href="https://github.com/lucide-icons/lucide/compare/1.30.0...1.31.0">https://github.com/lucide-icons/lucide/compare/1.30.0...1.31.0</a></p> <h2>Version 1.30.0</h2> <h2>What's Changed</h2> <ul> <li>chore(icons): refine & rename various emoji icons by <a href="https://github.com/karsa-mistmere"><code>@karsa-mistmere</code></a> in <a href="https://redirect.github.com/lucide-icons/lucide/pull/4606">lucide-icons/lucide#4606</a></li> <li>fix(scripts): removed toBeRemovedInVersion from all scripts and tools by <a href="https://github.com/karsa-mistmere"><code>@karsa-mistmere</code></a> in <a href="https://redirect.github.com/lucide-icons/lucide/pull/4674">lucide-icons/lucide#4674</a></li> <li>feat(icons): added <code>audio-lines-x</code> icon by <a href="https://github.com/karsa-mistmere"><code>@karsa-mistmere</code></a> in <a href="https://redirect.github.com/lucide-icons/lucide/pull/4590">lucide-icons/lucide#4590</a></li> <li>feat(lab): added <code>chinese-character</code> icon to lab by <a href="https://github.com/congemcd"><code>@congemcd</code></a> in <a href="https://redirect.github.com/lucide-icons/lucide/pull/4212">lucide-icons/lucide#4212</a></li> <li>test(packages): updates unit test snapshots with face-slightly-smiling by <a href="https://github.com/karsa-mistmere"><code>@karsa-mistmere</code></a> in <a href="https://redirect.github.com/lucide-icons/lucide/pull/4676">lucide-icons/lucide#4676</a></li> <li>ci(dev): fix post-release job by downloading lucide-font artifact by name by <a href="https://github.com/ericfennis"><code>@ericfennis</code></a> with <a href="https://github.com/Copilot"><code>@Copilot</code></a> in <a href="https://redirect.github.com/lucide-icons/lucide/pull/4675">lucide-icons/lucide#4675</a></li> <li>feat(icons): add shield-lock icon by <a href="https://github.com/Caisere"><code>@Caisere</code></a> in <a href="https://redirect.github.com/lucide-icons/lucide/pull/3508">lucide-icons/lucide#3508</a></li> <li>ci(security): Pin sha actions by <a href="https://github.com/jguddas"><code>@jguddas</code></a> in <a href="https://redirect.github.com/lucide-icons/lucide/pull/4678">lucide-icons/lucide#4678</a></li> <li>feat(icons): added <code>broom</code> icon by <a href="https://github.com/karsa-mistmere"><code>@karsa-mistmere</code></a> in <a href="https://redirect.github.com/lucide-icons/lucide/pull/4683">lucide-icons/lucide#4683</a></li> </ul> <h2>New Contributors</h2> <ul> <li><a href="https://github.com/congemcd"><code>@congemcd</code></a> made their first contribution in <a href="https://redirect.github.com/lucide-icons/lucide/pull/4212">lucide-icons/lucide#4212</a></li> <li><a href="https://github.com/Caisere"><code>@Caisere</code></a> made their first contribution in <a href="https://redirect.github.com/lucide-icons/lucide/pull/3508">lucide-icons/lucide#3508</a></li> </ul> <p><strong>Full Changelog</strong>: <a href="https://github.com/lucide-icons/lucide/compare/1.29.0...1.30.0">https://github.com/lucide-icons/lucide/compare/1.29.0...1.30.0</a></p> <h2>Version 1.29.0</h2> <h2>What's Changed</h2> <ul> <li>fix(<code>@lucide/lab</code>): Fix lab build by <a href="https://github.com/ericfennis"><code>@ericfennis</code></a> in <a href="https://redirect.github.com/lucide-icons/lucide/pull/4618">lucide-icons/lucide#4618</a></li> <li>feat(copilot): remove incorrect spaces clause from copilot instructions by <a href="https://github.com/karsa-mistmere"><code>@karsa-mistmere</code></a> in <a href="https://redirect.github.com/lucide-icons/lucide/pull/4623">lucide-icons/lucide#4623</a></li> <li>feat(docs): remove Super and Noodle from showcase by <a href="https://github.com/karsa-mistmere"><code>@karsa-mistmere</code></a> in <a href="https://redirect.github.com/lucide-icons/lucide/pull/4626">lucide-icons/lucide#4626</a></li> <li>chore(deps-dev): bump <code>@angular/platform-server</code> from 21.2.18 to 21.2.19 by <a href="https://github.com/dependabot"><code>@dependabot</code></a>[bot] in <a href="https://redirect.github.com/lucide-icons/lucide/pull/4629">lucide-icons/lucide#4629</a></li> <li>ci(security): improve security with adding permissions by <a href="https://github.com/ericfennis"><code>@ericfennis</code></a> in <a href="https://redirect.github.com/lucide-icons/lucide/pull/4619">lucide-icons/lucide#4619</a></li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/lucide-icons/lucide/commit/75b55160aa9edd7095dfed1a6e3d88e66fb2b153"><code>75b5516</code></a> chore(dev): upgrade ESLint to latest compatible stack (v10) (<a href="https://github.com/lucide-icons/lucide/tree/HEAD/packages/lucide-react/issues/4378">#4378</a>)</li> <li><a href="https://github.com/lucide-icons/lucide/commit/0f8d48b266e7af1e2bab49ff12ab6ec0795ed204"><code>0f8d48b</code></a> test(packages): updates unit test snapshots with face-slightly-smiling (<a href="https://github.com/lucide-icons/lucide/tree/HEAD/packages/lucide-react/issues/4676">#4676</a>)</li> <li><a href="https://github.com/lucide-icons/lucide/commit/f229f83f0c42f46befeac3cfd8ef7aaa82a71325"><code>f229f83</code></a> chore(depedencies): Update dependencies (<a href="https://github.com/lucide-icons/lucide/tree/HEAD/packages/lucide-react/issues/4553">#4553</a>)</li> <li><a href="https://github.com/lucide-icons/lucide/commit/5ff536e1391335e4f7dc38d244c1bc458b9443e2"><code>5ff536e</code></a> ci(release.yml): Fix workflow and remove <code>version</code> scripts in package scripts...</li> <li><a href="https://github.com/lucide-icons/lucide/commit/07c885e6c1f9952965ba388b7fd2bb7c4d416a67"><code>07c885e</code></a> fix(docs): fix zephyr-cloud URL in readmes</li> <li><a href="https://github.com/lucide-icons/lucide/commit/50d8af5a1012e188f3d71ac8f1fc0fba1aab5357"><code>50d8af5</code></a> docs(readme): Update readme files (<a href="https://github.com/lucide-icons/lucide/tree/HEAD/packages/lucide-react/issues/4320">#4320</a>)</li> <li><a href="https://github.com/lucide-icons/lucide/commit/653e44b83293567ff24dcb90ca1094a9cf0a042a"><code>653e44b</code></a> feat(packages): use .mjs for ESM bundles (<a href="https://github.com/lucide-icons/lucide/tree/HEAD/packages/lucide-react/issues/4285">#4285</a>)</li> <li><a href="https://github.com/lucide-icons/lucide/commit/7623e23f787fe78e5075a613fd22da2cecbb9b1b"><code>7623e23</code></a> feat(docs): add Zephyr Cloud to Hero Backers tier & rework updateSponsors scr...</li> <li><a href="https://github.com/lucide-icons/lucide/commit/dada0a82970d3733d1d716e2089591c538272a39"><code>dada0a8</code></a> fix(lucide-react): Fix dynamic imports (<a href="https://github.com/lucide-icons/lucide/tree/HEAD/packages/lucide-react/issues/4210">#4210</a>)</li> <li><a href="https://github.com/lucide-icons/lucide/commit/a6e648a66ff470c2255d3666765fd73cfcc185ff"><code>a6e648a</code></a> fix(lucide-react): correct client directives in RSC files (<a href="https://github.com/lucide-icons/lucide/tree/HEAD/packages/lucide-react/issues/4189">#4189</a>)</li> <li>Additional commits viewable in <a href="https://github.com/lucide-icons/lucide/commits/1.32.0/packages/lucide-react">compare view</a></li> </ul> </details> <br /> --------- Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: Priya Raman <priya@paperclip.ing> Co-authored-by: Paperclip <noreply@paperclip.ing> |
||
|
|
18ba239d85 |
build(deps): bump @pierre/diffs from 1.2.11 to 1.3.5 (#11875)
Bumps @pierre/diffs from 1.2.11 to 1.3.5. --------- Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: Priya Raman <priya@paperclip.ing> Co-authored-by: Paperclip <noreply@paperclip.ing> |
||
|
|
f64123ba4b |
build(deps-dev): bump @storybook/addon-docs from 10.5.8 to 10.5.10 (#11869)
Bumps [@storybook/addon-docs](https://github.com/storybookjs/storybook/tree/HEAD/code/addons/docs) from 10.5.8 to 10.5.10. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/storybookjs/storybook/releases">@storybook/addon-docs's releases</a>.</em></p> <blockquote> <h2>v10.5.10</h2> <h2>10.5.10</h2> <ul> <li>Core: Fetch static open-service snapshots relative to the document - <a href="https://redirect.github.com/storybookjs/storybook/pull/35945">#35945</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Core: Pin oxc-resolver to 11.21.2 to keep tsconfig path aliases on solution-style tsconfigs - <a href="https://redirect.github.com/storybookjs/storybook/pull/35929">#35929</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Dependencies: Bump Vitest to 4.1.6 (CVE-2026-47428) - <a href="https://redirect.github.com/storybookjs/storybook/pull/35530">#35530</a>, thanks <a href="https://github.com/anupamme"><code>@anupamme</code></a>!</li> <li>Docs: Declare the font on overlay surfaces so docs tooltips are not left to inherit - <a href="https://redirect.github.com/storybookjs/storybook/pull/35966">#35966</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>ESLint Plugin: Bundle CSF helpers so the plugin loads without storybook - <a href="https://redirect.github.com/storybookjs/storybook/pull/35950">#35950</a>, thanks <a href="https://github.com/ndelangen"><code>@ndelangen</code></a>!</li> <li>React: Preserve discriminated union prop values in metadata extraction - <a href="https://redirect.github.com/storybookjs/storybook/pull/35844">#35844</a>, thanks <a href="https://github.com/s-robertson"><code>@s-robertson</code></a>!</li> </ul> <h2>v10.5.9</h2> <h2>10.5.9</h2> <ul> <li>Addon-Pseudo-States: Fix pseudo-states rewriting for nested functional selectors - <a href="https://redirect.github.com/storybookjs/storybook/pull/34318">#34318</a>, thanks <a href="https://github.com/filipw01"><code>@filipw01</code></a>!</li> <li>Core: Skip module-graph reverse-index mirror when a patch is a no-op - <a href="https://redirect.github.com/storybookjs/storybook/pull/35825">#35825</a>, thanks <a href="https://github.com/ndelangen"><code>@ndelangen</code></a>!</li> <li>Core: Split module-graph into hot revisions and cold index services - <a href="https://redirect.github.com/storybookjs/storybook/pull/35831">#35831</a>, thanks <a href="https://github.com/ndelangen"><code>@ndelangen</code></a>!</li> <li>Preview: Fix crash when initialising UrlStore on a docs path - <a href="https://redirect.github.com/storybookjs/storybook/pull/35521">#35521</a>, thanks <a href="https://github.com/TheSeydiCharyyev"><code>@TheSeydiCharyyev</code></a>!</li> <li>Pseudo-States: Make stylesheet rewrites WebKit-safe - <a href="https://redirect.github.com/storybookjs/storybook/pull/35629">#35629</a>, thanks <a href="https://github.com/ethriel3695"><code>@ethriel3695</code></a>!</li> <li>TanStack: Keep the layout id when cloning a standalone index file route - <a href="https://redirect.github.com/storybookjs/storybook/pull/35660">#35660</a>, thanks <a href="https://github.com/Insik-Han"><code>@Insik-Han</code></a>!</li> <li>TanStack: Render real link hrefs in the Link mock - <a href="https://redirect.github.com/storybookjs/storybook/pull/35505">#35505</a>, thanks <a href="https://github.com/unpunnyfuns"><code>@unpunnyfuns</code></a>!</li> <li>Webpack: Prevent long preview output filenames - <a href="https://redirect.github.com/storybookjs/storybook/pull/35533">#35533</a>, thanks <a href="https://github.com/zhangli091011"><code>@zhangli091011</code></a>!</li> </ul> </blockquote> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/storybookjs/storybook/blob/next/CHANGELOG.md">@storybook/addon-docs's changelog</a>.</em></p> <blockquote> <h2>10.5.10</h2> <ul> <li>Core: Fetch static open-service snapshots relative to the document - <a href="https://redirect.github.com/storybookjs/storybook/pull/35945">#35945</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Core: Pin oxc-resolver to 11.21.2 to keep tsconfig path aliases on solution-style tsconfigs - <a href="https://redirect.github.com/storybookjs/storybook/pull/35929">#35929</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Dependencies: Bump Vitest to 4.1.6 (CVE-2026-47428) - <a href="https://redirect.github.com/storybookjs/storybook/pull/35530">#35530</a>, thanks <a href="https://github.com/anupamme"><code>@anupamme</code></a>!</li> <li>Docs: Declare the font on overlay surfaces so docs tooltips are not left to inherit - <a href="https://redirect.github.com/storybookjs/storybook/pull/35966">#35966</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>ESLint Plugin: Bundle CSF helpers so the plugin loads without storybook - <a href="https://redirect.github.com/storybookjs/storybook/pull/35950">#35950</a>, thanks <a href="https://github.com/ndelangen"><code>@ndelangen</code></a>!</li> <li>React: Preserve discriminated union prop values in metadata extraction - <a href="https://redirect.github.com/storybookjs/storybook/pull/35844">#35844</a>, thanks <a href="https://github.com/s-robertson"><code>@s-robertson</code></a>!</li> </ul> <h2>10.5.9</h2> <ul> <li>Addon-Pseudo-States: Fix pseudo-states rewriting for nested functional selectors - <a href="https://redirect.github.com/storybookjs/storybook/pull/34318">#34318</a>, thanks <a href="https://github.com/filipw01"><code>@filipw01</code></a>!</li> <li>Core: Skip module-graph reverse-index mirror when a patch is a no-op - <a href="https://redirect.github.com/storybookjs/storybook/pull/35825">#35825</a>, thanks <a href="https://github.com/ndelangen"><code>@ndelangen</code></a>!</li> <li>Core: Split module-graph into hot revisions and cold index services - <a href="https://redirect.github.com/storybookjs/storybook/pull/35831">#35831</a>, thanks <a href="https://github.com/ndelangen"><code>@ndelangen</code></a>!</li> <li>Preview: Fix crash when initialising UrlStore on a docs path - <a href="https://redirect.github.com/storybookjs/storybook/pull/35521">#35521</a>, thanks <a href="https://github.com/TheSeydiCharyyev"><code>@TheSeydiCharyyev</code></a>!</li> <li>Pseudo-States: Make stylesheet rewrites WebKit-safe - <a href="https://redirect.github.com/storybookjs/storybook/pull/35629">#35629</a>, thanks <a href="https://github.com/ethriel3695"><code>@ethriel3695</code></a>!</li> <li>TanStack: Keep the layout id when cloning a standalone index file route - <a href="https://redirect.github.com/storybookjs/storybook/pull/35660">#35660</a>, thanks <a href="https://github.com/Insik-Han"><code>@Insik-Han</code></a>!</li> <li>TanStack: Render real link hrefs in the Link mock - <a href="https://redirect.github.com/storybookjs/storybook/pull/35505">#35505</a>, thanks <a href="https://github.com/unpunnyfuns"><code>@unpunnyfuns</code></a>!</li> <li>Webpack: Prevent long preview output filenames - <a href="https://redirect.github.com/storybookjs/storybook/pull/35533">#35533</a>, thanks <a href="https://github.com/zhangli091011"><code>@zhangli091011</code></a>!</li> </ul> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/storybookjs/storybook/commit/a2db7526e1538a48bfa0529a881822e8074b2009"><code>a2db752</code></a> Bump version from "10.5.9" to "10.5.10" [skip ci]</li> <li><a href="https://github.com/storybookjs/storybook/commit/8f561048949b3ce3674a71711942177a14e4e8f9"><code>8f56104</code></a> Bump version from "10.5.8" to "10.5.9" [skip ci]</li> <li>See full diff in <a href="https://github.com/storybookjs/storybook/commits/v10.5.10/code/addons/docs">compare view</a></li> </ul> </details> <br /> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |
||
|
|
bef9288669 |
build(deps): bump @agentclientprotocol/claude-agent-acp from 0.69.0 to 0.70.0 (#11873)
Bumps [@agentclientprotocol/claude-agent-acp](https://github.com/agentclientprotocol/claude-agent-acp) from 0.69.0 to 0.70.0. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/agentclientprotocol/claude-agent-acp/releases">@agentclientprotocol/claude-agent-acp's releases</a>.</em></p> <blockquote> <h2>v0.70.0</h2> <h2><a href="https://github.com/agentclientprotocol/claude-agent-acp/compare/v0.69.0...v0.70.0">0.70.0</a> (2026-08-17)</h2> <h3>Features</h3> <ul> <li>switch providers for loaded Claude sessions (<a href="https://redirect.github.com/agentclientprotocol/claude-agent-acp/issues/1002">#1002</a>) (<a href="https://github.com/agentclientprotocol/claude-agent-acp/commit/50a95434e94318456f2d07c3d21aaf3595c3407d">50a9543</a>)</li> </ul> </blockquote> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/agentclientprotocol/claude-agent-acp/blob/main/CHANGELOG.md">@agentclientprotocol/claude-agent-acp's changelog</a>.</em></p> <blockquote> <h2><a href="https://github.com/agentclientprotocol/claude-agent-acp/compare/v0.69.0...v0.70.0">0.70.0</a> (2026-08-17)</h2> <h3>Features</h3> <ul> <li>switch providers for loaded Claude sessions (<a href="https://redirect.github.com/agentclientprotocol/claude-agent-acp/issues/1002">#1002</a>) (<a href="https://github.com/agentclientprotocol/claude-agent-acp/commit/50a95434e94318456f2d07c3d21aaf3595c3407d">50a9543</a>)</li> </ul> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/agentclientprotocol/claude-agent-acp/commit/d0aafb1ca26427285ffaeac8d8a4452fff28e9c3"><code>d0aafb1</code></a> chore(main): release 0.70.0 (<a href="https://redirect.github.com/agentclientprotocol/claude-agent-acp/issues/1010">#1010</a>)</li> <li><a href="https://github.com/agentclientprotocol/claude-agent-acp/commit/50a95434e94318456f2d07c3d21aaf3595c3407d"><code>50a9543</code></a> feat: switch providers for loaded Claude sessions (<a href="https://redirect.github.com/agentclientprotocol/claude-agent-acp/issues/1002">#1002</a>)</li> <li>See full diff in <a href="https://github.com/agentclientprotocol/claude-agent-acp/compare/v0.69.0...v0.70.0">compare view</a></li> </ul> </details> <br /> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>canary/v2026.825.0-canary.12 beta/v2026.825.0-beta.1 nightly/v2026.825.0-nightly.3 |
||
|
|
0286854db5 |
build(deps-dev): bump @storybook/react-vite from 10.5.8 to 10.5.10 (#11868)
Bumps [@storybook/react-vite](https://github.com/storybookjs/storybook/tree/HEAD/code/frameworks/react-vite) from 10.5.8 to 10.5.10. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/storybookjs/storybook/releases">@storybook/react-vite's releases</a>.</em></p> <blockquote> <h2>v10.5.10</h2> <h2>10.5.10</h2> <ul> <li>Core: Fetch static open-service snapshots relative to the document - <a href="https://redirect.github.com/storybookjs/storybook/pull/35945">#35945</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Core: Pin oxc-resolver to 11.21.2 to keep tsconfig path aliases on solution-style tsconfigs - <a href="https://redirect.github.com/storybookjs/storybook/pull/35929">#35929</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Dependencies: Bump Vitest to 4.1.6 (CVE-2026-47428) - <a href="https://redirect.github.com/storybookjs/storybook/pull/35530">#35530</a>, thanks <a href="https://github.com/anupamme"><code>@anupamme</code></a>!</li> <li>Docs: Declare the font on overlay surfaces so docs tooltips are not left to inherit - <a href="https://redirect.github.com/storybookjs/storybook/pull/35966">#35966</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>ESLint Plugin: Bundle CSF helpers so the plugin loads without storybook - <a href="https://redirect.github.com/storybookjs/storybook/pull/35950">#35950</a>, thanks <a href="https://github.com/ndelangen"><code>@ndelangen</code></a>!</li> <li>React: Preserve discriminated union prop values in metadata extraction - <a href="https://redirect.github.com/storybookjs/storybook/pull/35844">#35844</a>, thanks <a href="https://github.com/s-robertson"><code>@s-robertson</code></a>!</li> </ul> <h2>v10.5.9</h2> <h2>10.5.9</h2> <ul> <li>Addon-Pseudo-States: Fix pseudo-states rewriting for nested functional selectors - <a href="https://redirect.github.com/storybookjs/storybook/pull/34318">#34318</a>, thanks <a href="https://github.com/filipw01"><code>@filipw01</code></a>!</li> <li>Core: Skip module-graph reverse-index mirror when a patch is a no-op - <a href="https://redirect.github.com/storybookjs/storybook/pull/35825">#35825</a>, thanks <a href="https://github.com/ndelangen"><code>@ndelangen</code></a>!</li> <li>Core: Split module-graph into hot revisions and cold index services - <a href="https://redirect.github.com/storybookjs/storybook/pull/35831">#35831</a>, thanks <a href="https://github.com/ndelangen"><code>@ndelangen</code></a>!</li> <li>Preview: Fix crash when initialising UrlStore on a docs path - <a href="https://redirect.github.com/storybookjs/storybook/pull/35521">#35521</a>, thanks <a href="https://github.com/TheSeydiCharyyev"><code>@TheSeydiCharyyev</code></a>!</li> <li>Pseudo-States: Make stylesheet rewrites WebKit-safe - <a href="https://redirect.github.com/storybookjs/storybook/pull/35629">#35629</a>, thanks <a href="https://github.com/ethriel3695"><code>@ethriel3695</code></a>!</li> <li>TanStack: Keep the layout id when cloning a standalone index file route - <a href="https://redirect.github.com/storybookjs/storybook/pull/35660">#35660</a>, thanks <a href="https://github.com/Insik-Han"><code>@Insik-Han</code></a>!</li> <li>TanStack: Render real link hrefs in the Link mock - <a href="https://redirect.github.com/storybookjs/storybook/pull/35505">#35505</a>, thanks <a href="https://github.com/unpunnyfuns"><code>@unpunnyfuns</code></a>!</li> <li>Webpack: Prevent long preview output filenames - <a href="https://redirect.github.com/storybookjs/storybook/pull/35533">#35533</a>, thanks <a href="https://github.com/zhangli091011"><code>@zhangli091011</code></a>!</li> </ul> </blockquote> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/storybookjs/storybook/blob/next/CHANGELOG.md">@storybook/react-vite's changelog</a>.</em></p> <blockquote> <h2>10.5.10</h2> <ul> <li>Core: Fetch static open-service snapshots relative to the document - <a href="https://redirect.github.com/storybookjs/storybook/pull/35945">#35945</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Core: Pin oxc-resolver to 11.21.2 to keep tsconfig path aliases on solution-style tsconfigs - <a href="https://redirect.github.com/storybookjs/storybook/pull/35929">#35929</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Dependencies: Bump Vitest to 4.1.6 (CVE-2026-47428) - <a href="https://redirect.github.com/storybookjs/storybook/pull/35530">#35530</a>, thanks <a href="https://github.com/anupamme"><code>@anupamme</code></a>!</li> <li>Docs: Declare the font on overlay surfaces so docs tooltips are not left to inherit - <a href="https://redirect.github.com/storybookjs/storybook/pull/35966">#35966</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>ESLint Plugin: Bundle CSF helpers so the plugin loads without storybook - <a href="https://redirect.github.com/storybookjs/storybook/pull/35950">#35950</a>, thanks <a href="https://github.com/ndelangen"><code>@ndelangen</code></a>!</li> <li>React: Preserve discriminated union prop values in metadata extraction - <a href="https://redirect.github.com/storybookjs/storybook/pull/35844">#35844</a>, thanks <a href="https://github.com/s-robertson"><code>@s-robertson</code></a>!</li> </ul> <h2>10.5.9</h2> <ul> <li>Addon-Pseudo-States: Fix pseudo-states rewriting for nested functional selectors - <a href="https://redirect.github.com/storybookjs/storybook/pull/34318">#34318</a>, thanks <a href="https://github.com/filipw01"><code>@filipw01</code></a>!</li> <li>Core: Skip module-graph reverse-index mirror when a patch is a no-op - <a href="https://redirect.github.com/storybookjs/storybook/pull/35825">#35825</a>, thanks <a href="https://github.com/ndelangen"><code>@ndelangen</code></a>!</li> <li>Core: Split module-graph into hot revisions and cold index services - <a href="https://redirect.github.com/storybookjs/storybook/pull/35831">#35831</a>, thanks <a href="https://github.com/ndelangen"><code>@ndelangen</code></a>!</li> <li>Preview: Fix crash when initialising UrlStore on a docs path - <a href="https://redirect.github.com/storybookjs/storybook/pull/35521">#35521</a>, thanks <a href="https://github.com/TheSeydiCharyyev"><code>@TheSeydiCharyyev</code></a>!</li> <li>Pseudo-States: Make stylesheet rewrites WebKit-safe - <a href="https://redirect.github.com/storybookjs/storybook/pull/35629">#35629</a>, thanks <a href="https://github.com/ethriel3695"><code>@ethriel3695</code></a>!</li> <li>TanStack: Keep the layout id when cloning a standalone index file route - <a href="https://redirect.github.com/storybookjs/storybook/pull/35660">#35660</a>, thanks <a href="https://github.com/Insik-Han"><code>@Insik-Han</code></a>!</li> <li>TanStack: Render real link hrefs in the Link mock - <a href="https://redirect.github.com/storybookjs/storybook/pull/35505">#35505</a>, thanks <a href="https://github.com/unpunnyfuns"><code>@unpunnyfuns</code></a>!</li> <li>Webpack: Prevent long preview output filenames - <a href="https://redirect.github.com/storybookjs/storybook/pull/35533">#35533</a>, thanks <a href="https://github.com/zhangli091011"><code>@zhangli091011</code></a>!</li> </ul> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/storybookjs/storybook/commit/a2db7526e1538a48bfa0529a881822e8074b2009"><code>a2db752</code></a> Bump version from "10.5.9" to "10.5.10" [skip ci]</li> <li><a href="https://github.com/storybookjs/storybook/commit/8f561048949b3ce3674a71711942177a14e4e8f9"><code>8f56104</code></a> Bump version from "10.5.8" to "10.5.9" [skip ci]</li> <li>See full diff in <a href="https://github.com/storybookjs/storybook/commits/v10.5.10/code/frameworks/react-vite">compare view</a></li> </ul> </details> <br /> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |
||
|
|
5db8ce3c44 |
fix(docker): make tini PID 1 in the server image so adopted orphans are reaped (#12137)
## Thinking Path
> - Paperclip is the open source app people use to manage AI agents for
work
> - Agent runs execute inside the server container, and they spawn many
short-lived descendants: git, the adapter CLI, esbuild, sh
> - The server image sets `ENTRYPOINT ["docker-entrypoint.sh"]`, and
that entrypoint ends in `exec`, so node becomes PID 1
> - Node reaps only the children it spawned itself. It installs no
`SIGCHLD`/`waitpid` handler for orphans that the kernel re-parents onto
PID 1, so those orphans stay as zombies forever
> - Zombies accumulate monotonically. When the cgroup pid limit is
reached, every `fork()` in the container fails and the instance is dead
> - This pull request installs `tini` and makes it PID 1 in front of the
existing entrypoint, adds a behavioural test that proves reaping, and
adds a `pids_limit` backstop to both compose files
> - The benefit is that a long-running container no longer degrades into
total fork failure, and a future regression is caught by CI instead of
by an outage
Depends-on: none — this change is self-contained in the image build and
its tests, and it touches no other in-flight branch
## Linked Issues or Issue Description
No public GitHub issue exists for this defect. It was found on a live
long-running instance. Description follows the bug report template.
**What happened?**
The server container ran for 22 hours and reached 2039 of 2048 pids in
its cgroup. Of 1760 processes, 1731 were zombies, and all 1731 had PID 1
as their parent. PID 1 was `node --import
./server/node_modules/tsx/dist/loader.mjs server/dist/index.js`. Zombies
accrued at about 79 per hour and were never reaped. The oldest zombie
was 20.8 hours old against a container uptime of 22.0 hours, so nothing
had been reaped since boot. Once the pid limit was reached, `git` and
`gh` failed with `pthread_create failed: Resource temporarily
unavailable`.
**Expected behavior**
PID 1 reaps orphaned processes that the kernel re-parents onto it. The
pid count of a long-running container stays flat instead of growing
without bound.
**Steps to reproduce**
1. Start the server image without `docker run --init` and without `init:
true`.
2. Run agent work that spawns descendants which outlive their immediate
parent.
3. Read `/sys/fs/cgroup/pids.current` and count processes in `Z` state
over several hours.
4. The zombie count grows monotonically and every zombie has PPID 1.
**Relevant logs or output**
```
cgroup pids.current / pids.max : 2039 / 2048
total processes : 1760
zombies : 1731 (98.4%)
parent of every zombie : PID 1 (1731/1731)
PID 1 cmdline : node --import .../tsx/dist/loader.mjs server/dist/index.js
container uptime : 22.0 h
oldest zombie : 20.8 h median: 14.4 h
zombie names : git 717, claude 280, MainThread 167, sleep 141,
esbuild 138, postgres 76, sh 65, sccache 50
```
**Additional context**
The fix pattern is already in this repository.
`docker/agent-runtime/Dockerfile.base` installs `tini` and sets
`ENTRYPOINT ["/usr/bin/tini", "--"]`. It was never applied to the server
image.
## What Changed
- `Dockerfile`: install `tini` in the `base` stage and set `ENTRYPOINT
["/usr/bin/tini", "--", "docker-entrypoint.sh"]`. The entrypoint stays
in the exec chain, so UID/GID remapping, `gosu`, and graceful shutdown
are unchanged.
- `scripts/assert-orphan-reaping.sh` (new): a behavioural probe. It
spawns a leader that forks a grandchild, exits the leader, and asserts
that the orphaned grandchild leaves `Z` state instead of persisting. It
fails closed if the grandchild is not re-parented onto PID 1, so a pass
cannot mean the check ran too early.
- `.github/workflows/docker.yml`: run that probe against the pushed
image after the publish step. The publish step is multi-arch with `push:
true`, so nothing is loaded into the runner daemon and the pushed tag is
the only thing to test. The cloud variant is `FROM production` and
inherits the same `ENTRYPOINT`.
- `scripts/docker-build-test.sh`: run the same probe against a local
build.
- `docker/docker-compose.yml` and
`docker/docker-compose.quickstart.yml`: add `pids_limit: 2048` as a
backstop, so a future leak dies visibly at its own ceiling instead of
starving the host of pids.
- `server/src/__tests__/container-init-reaping.test.ts` (new): 13
assertions that guard the configuration the probe depends on.
No per-orchestrator init lever was added. The image owning PID 1 covers
compose, plain `docker run`, the quadlet units, and the ECS task
definition in one place. Adding `init: true` in compose or
`initProcessEnabled` on the ECS task would nest a second init around
`tini`, and `tini` then warns on every boot that it is not PID 1. The
new test asserts the absence of both levers across all three manifests,
so the decision survives the next edit.
## Verification
| Check | Result |
|---|---|
| `scripts/assert-orphan-reaping.sh` against a real init | Grandchild
re-parented to PPID 1, then reaped. Exit 0. |
| Same probe forced against a genuine zombie | Reports `Z` and fails.
The failure branch is not vacuous. |
| Config guard against the pre-fix files | Exactly the 3 relevant
assertions turn red. |
| Config guard with `tini` removed from `apt-get` but the comments kept
| Red. It checks the install, not a mention of the name. |
| `cd server && npx vitest run
src/__tests__/container-init-reaping.test.ts` | 13 passed |
| `npx tsc --noEmit -p server` | Clean |
| `node scripts/check-docker-deps-stage.mjs` | PASS |
| `node --test scripts/release-verify-workflow.test.mjs` | 8 passed |
Not verified locally: no container runtime is available in the authoring
environment, so the probe has not run against a build of this image. The
new `docker.yml` step runs it against the pushed image on this PR.
## Risks
Low risk, but it is an image and entrypoint change, so it affects
deployments.
- `tini` adds one small package to the `base` stage.
`docker/agent-runtime/Dockerfile.base` already installs it from the same
Debian archive.
- Signal handling changes shape: `tini` receives `SIGTERM` and forwards
it to the entrypoint, which `exec`s node. `tini` forwards signals to its
direct child by default, and the exec chain keeps node as that child, so
graceful shutdown is preserved. A reviewer should confirm this on a real
stop.
- `pids_limit: 2048` is new for compose users. A deployment that
legitimately needs more than 2048 processes would now hit the ceiling.
The measured steady state on a busy instance was under 400.
- If a deployment already passes `--init` or `init: true`, `tini` runs
under another init and prints a warning that it is not PID 1. Reaping
still works because the outer init handles it. The compose files in this
repository do not set `init: true`.
## Model Used
Claude Opus 5 (`claude-opus-5`), extended thinking, with tool use and
code execution in an agent harness.
## Checklist
- [x] I have included a thinking path that traces from project context
to this change
- [x] I have specified the model used (with version and capability
details)
- [x] I have checked ROADMAP.md and confirmed this PR does not duplicate
planned core work
- [x] I have searched GitHub for duplicate or related PRs and linked
them above
- [x] I have either (a) linked existing issues with `Fixes: #` / `Closes
#` / `Refs #` OR (b) described the issue in-PR following the relevant
issue template
- [x] I have not referenced internal/instance-local issues or links
- [x] My branch name describes the change and contains no internal
ticket id or instance-derived details
- [x] I have run tests locally and they pass
- [x] I have added or updated tests where applicable
- [x] I have updated relevant documentation to reflect my changes
- [x] I have considered and documented any risks above
- [x] All CI gates are green
- [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups
- [x] I will address all Greptile and reviewer comments before
requesting merge
---------
Co-authored-by: zannis <1011451+zannis@users.noreply.github.com>
canary/v2026.825.0-canary.11
|
||
|
|
3a841e15d0 |
build(deps-dev): bump @types/supertest from 6.0.3 to 7.2.1 (#11878)
Bumps [@types/supertest](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/supertest) from 6.0.3 to 7.2.1. <details> <summary>Commits</summary> <ul> <li>See full diff in <a href="https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/supertest">compare view</a></li> </ul> </details> <br /> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |
||
|
|
3c328a7726 |
build(deps): bump @mdxeditor/editor from 3.55.0 to 4.2.1 (#11870)
Bumps [@mdxeditor/editor](https://github.com/mdx-editor/editor) from 3.55.0 to 4.2.1. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/mdx-editor/editor/releases">@mdxeditor/editor's releases</a>.</em></p> <blockquote> <h2>v4.2.1</h2> <h2><a href="https://github.com/mdx-editor/editor/compare/v4.2.0...v4.2.1">4.2.1</a> (2026-08-21)</h2> <h3>Bug Fixes</h3> <ul> <li>upgrade js-yaml to 4.3.1 to resolve GHSA-5p4m-2wfm-xmqj (<a href="https://github.com/mdx-editor/editor/commit/3ff7296ffddcba1c60245c3ca27005b642f8b3c7">3ff7296</a>)</li> </ul> <h2>v4.2.0</h2> <h1><a href="https://github.com/mdx-editor/editor/compare/v4.1.1...v4.2.0">4.2.0</a> (2026-08-02)</h1> <h3>Bug Fixes</h3> <ul> <li>declare the frontmatter node as a block-level decorator (<a href="https://github.com/mdx-editor/editor/commit/ebc4755212f643db5b6fb11d4e0418baad920200">ebc4755</a>), closes <a href="https://redirect.github.com/mdx-editor/editor/issues/957">#957</a></li> <li>support links on selected images (<a href="https://github.com/mdx-editor/editor/commit/d8c442b69fa030bac6e451447aa7a8510a6dec9a">d8c442b</a>), closes <a href="https://redirect.github.com/mdx-editor/editor/issues/753">#753</a></li> </ul> <h3>Features</h3> <ul> <li>mdxeditor-full-height opt-in class for editors that fill their parent (<a href="https://github.com/mdx-editor/editor/commit/cdeda5847e8d3ac319c1439fdfae3d8c2c93c2ef">cdeda58</a>), closes <a href="https://redirect.github.com/mdx-editor/editor/issues/953">#953</a></li> </ul> <h2>v4.1.1</h2> <h2><a href="https://github.com/mdx-editor/editor/compare/v4.1.0...v4.1.1">4.1.1</a> (2026-07-29)</h2> <h3>Bug Fixes</h3> <ul> <li>clear resolvable security audit findings in the dev dependency tree (<a href="https://github.com/mdx-editor/editor/commit/117dd849879b8917bfdb10d1d7cec709510b219c">117dd84</a>)</li> <li>respect configured heading shortcuts (<a href="https://github.com/mdx-editor/editor/commit/beacb4c3c21f572d34ec223dffcb1ec0be248771">beacb4c</a>)</li> </ul> <h2>v4.1.0</h2> <h1><a href="https://github.com/mdx-editor/editor/compare/v4.0.4...v4.1.0">4.1.0</a> (2026-07-19)</h1> <h3>Bug Fixes</h3> <ul> <li>harden Lexical adoption lifecycle edges (<a href="https://github.com/mdx-editor/editor/commit/859bf459af165897652105e0aaa4f20fea0f162f">859bf45</a>)</li> <li>pass Playwright install flags through npm (<a href="https://github.com/mdx-editor/editor/commit/0b2d19b3bfffe2ffd2b98b9bb43820fb2148c0b4">0b2d19b</a>)</li> <li>remove stray Realm provider token (<a href="https://github.com/mdx-editor/editor/commit/c432da3a838fbc9ab4c1e09df892f10ce50e6e01">c432da3</a>)</li> </ul> <h3>Features</h3> <ul> <li>adopt Lexical 0.48 with compatibility gates (<a href="https://github.com/mdx-editor/editor/commit/90a1466d5e675ffaca75b45a1cac75bcac222e09">90a1466</a>)</li> <li>export Markdown from the active selection (<a href="https://github.com/mdx-editor/editor/commit/a7c3baee1cced1307a17870e4524679e734039c2">a7c3bae</a>)</li> <li>make search replacement state-backed (<a href="https://github.com/mdx-editor/editor/commit/b108652c552920e88a1af55fe5c0b4fc220823f2">b108652</a>)</li> </ul> <h2>v4.0.4</h2> <h2><a href="https://github.com/mdx-editor/editor/compare/v4.0.3...v4.0.4">4.0.4</a> (2026-06-18)</h2> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/mdx-editor/editor/commit/3ff7296ffddcba1c60245c3ca27005b642f8b3c7"><code>3ff7296</code></a> fix: upgrade js-yaml to 4.3.1 to resolve GHSA-5p4m-2wfm-xmqj</li> <li><a href="https://github.com/mdx-editor/editor/commit/b5bc01b2c94c8a997238b89ced7ca9091e915454"><code>b5bc01b</code></a> Merge pull request <a href="https://redirect.github.com/mdx-editor/editor/issues/959">#959</a> from alexander-neuschl-tu-dresden-de/patch-1</li> <li><a href="https://github.com/mdx-editor/editor/commit/b607c8ce2d88ce582ea933615dd8d67bb6dcbb8a"><code>b607c8c</code></a> Update package-lock.json for js-yaml 4.3.1</li> <li><a href="https://github.com/mdx-editor/editor/commit/dda0c61c0b4f2aaea622b8c8017a68c491575ee7"><code>dda0c61</code></a> Upgrade js-yaml to 4.3.1 to resolve high vulnerability</li> <li><a href="https://github.com/mdx-editor/editor/commit/d8c442b69fa030bac6e451447aa7a8510a6dec9a"><code>d8c442b</code></a> fix: support links on selected images</li> <li><a href="https://github.com/mdx-editor/editor/commit/cdeda5847e8d3ac319c1439fdfae3d8c2c93c2ef"><code>cdeda58</code></a> feat: mdxeditor-full-height opt-in class for editors that fill their parent</li> <li><a href="https://github.com/mdx-editor/editor/commit/ebc4755212f643db5b6fb11d4e0418baad920200"><code>ebc4755</code></a> fix: declare the frontmatter node as a block-level decorator</li> <li><a href="https://github.com/mdx-editor/editor/commit/117dd849879b8917bfdb10d1d7cec709510b219c"><code>117dd84</code></a> fix: clear resolvable security audit findings in the dev dependency tree</li> <li><a href="https://github.com/mdx-editor/editor/commit/88b7545e5d7095d526eb1c79e660db157848e583"><code>88b7545</code></a> Merge branch 'pr-954'</li> <li><a href="https://github.com/mdx-editor/editor/commit/2b1af77dffc69806d94c8b72c9d1e8fd3e4f99cd"><code>2b1af77</code></a> Merge pull request <a href="https://redirect.github.com/mdx-editor/editor/issues/952">#952</a> from 11suixing11/fix/allowed-heading-shortcuts</li> <li>Additional commits viewable in <a href="https://github.com/mdx-editor/editor/compare/v3.55.0...v4.2.1">compare view</a></li> </ul> </details> <br /> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |
||
|
|
1d3195bfcd |
build(deps-dev): bump esbuild from 0.28.1 to 0.28.2 (#11882)
Bumps [esbuild](https://github.com/evanw/esbuild) from 0.28.1 to 0.28.2. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/evanw/esbuild/releases">esbuild's releases</a>.</em></p> <blockquote> <h2>v0.28.2</h2> <ul> <li> <p>Fix tree shaking bug due to TypeScript import alias (<a href="https://redirect.github.com/evanw/esbuild/issues/4507">#4507</a>)</p> <p>This release fixes a bug that could cause esbuild to incorrectly tree-shake imports that are used in a TypeScript type alias under certain circumstances. Affected code uses a TypeScript-specific <code>import</code> assignment and looks something like this:</p> <pre lang="ts"><code>import Base from './dep.js'; import Alias = Base.SomeType; </code></pre> </li> <li> <p>Fix CSS minification bug involving <code>&</code> (<a href="https://redirect.github.com/evanw/esbuild/issues/4497">#4497</a>)</p> <p>This release fixes a bug where esbuild's CSS minifier incorrectly removed a <code>&</code> when it was unsafe to do so. Here is an example:</p> <pre lang="css"><code>/* Original code */ .a .b { & .b:not(& .c) { color: red; } } <p>/* Old output (with --minify) */<br /> .a .b{.b:not(& .c){color:red}}</p> <p>/* New output (with --minify) */<br /> .a .b{& .b:not(& .c){color:red}}<br /> </code></pre></p> <p>This should match <code><span class="a"><span class="b"><span class="b">yes</span></span></span></code> but not <code><span class="a"><span class="b">no</span></span></code>. The old output incorrectly matched both.</p> </li> <li> <p>Avoid overwriting input files without <code>--allow-overwrite</code> (<a href="https://redirect.github.com/evanw/esbuild/issues/4484">#4484</a>)</p> <p>For example: <code>esbuild input.js --outfile=input.js</code> tells esbuild to overwrite <code>input.js</code> with the output of running esbuild on it. This was supposed to already be prevented by default, but it accidentally regressed in version 0.17.0 and apparently didn't have any test coverage. The error message was being printed but the input file was still being overwritten. Oops.</p> <p>This release puts the original behavior back. With this release, esbuild should now actually avoid overwriting input files unless <code>--allow-overwrite</code> is explicitly present. This is done by not writing out any files when a build error is encountered.</p> </li> <li> <p>Fix incorrect code generated when using top-level await (<a href="https://redirect.github.com/evanw/esbuild/issues/4498">#4498</a>)</p> <p>Previously esbuild could generate code containing a syntax error in complex scenarios involving top-level await used in a dependency cycle. The problem was a missing <code>async</code> on one or more module wrapper closures. With this release, esbuild now uses a fixed-point iteration algorithm to correctly annotate all dependencies in the cycle as needing an <code>async</code> module wrapper.</p> </li> <li> <p>Fix a minification bug with lowered logical assignment operators (<a href="https://redirect.github.com/evanw/esbuild/issues/4508">#4508</a>)</p> <p>This release fixes a bug that could cause esbuild to generate incorrect code for logical assignment operators when lowering them to an older target environment. Specifically the lowering process requires duplicating the left-hand side, but esbuild incorrectly failed to count the duplicate as a new usage when the left-hand side is an identifier. That then caused the minifier to believe that the left-hand side was only used once and could attempt to incorrectly inline an initializer into the first usage. This bug has now been fixed:</p> <pre lang="js"><code>// Original code function foo() { let x bar(x ||= {}) </code></pre> </li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/evanw/esbuild/blob/main/CHANGELOG.md">esbuild's changelog</a>.</em></p> <blockquote> <h2>0.28.2</h2> <ul> <li> <p>Fix tree shaking bug due to TypeScript import alias (<a href="https://redirect.github.com/evanw/esbuild/issues/4507">#4507</a>)</p> <p>This release fixes a bug that could cause esbuild to incorrectly tree-shake imports that are used in a TypeScript type alias under certain circumstances. Affected code uses a TypeScript-specific <code>import</code> assignment and looks something like this:</p> <pre lang="ts"><code>import Base from './dep.js'; import Alias = Base.SomeType; </code></pre> </li> <li> <p>Fix CSS minification bug involving <code>&</code> (<a href="https://redirect.github.com/evanw/esbuild/issues/4497">#4497</a>)</p> <p>This release fixes a bug where esbuild's CSS minifier incorrectly removed a <code>&</code> when it was unsafe to do so. Here is an example:</p> <pre lang="css"><code>/* Original code */ .a .b { & .b:not(& .c) { color: red; } } <p>/* Old output (with --minify) */<br /> .a .b{.b:not(& .c){color:red}}</p> <p>/* New output (with --minify) */<br /> .a .b{& .b:not(& .c){color:red}}<br /> </code></pre></p> <p>This should match <code><span class="a"><span class="b"><span class="b">yes</span></span></span></code> but not <code><span class="a"><span class="b">no</span></span></code>. The old output incorrectly matched both.</p> </li> <li> <p>Avoid overwriting input files without <code>--allow-overwrite</code> (<a href="https://redirect.github.com/evanw/esbuild/issues/4484">#4484</a>)</p> <p>For example: <code>esbuild input.js --outfile=input.js</code> tells esbuild to overwrite <code>input.js</code> with the output of running esbuild on it. This was supposed to already be prevented by default, but it accidentally regressed in version 0.17.0 and apparently didn't have any test coverage. The error message was being printed but the input file was still being overwritten. Oops.</p> <p>This release puts the original behavior back. With this release, esbuild should now actually avoid overwriting input files unless <code>--allow-overwrite</code> is explicitly present. This is done by not writing out any files when a build error is encountered.</p> </li> <li> <p>Fix incorrect code generated when using top-level await (<a href="https://redirect.github.com/evanw/esbuild/issues/4498">#4498</a>)</p> <p>Previously esbuild could generate code containing a syntax error in complex scenarios involving top-level await used in a dependency cycle. The problem was a missing <code>async</code> on one or more module wrapper closures. With this release, esbuild now uses a fixed-point iteration algorithm to correctly annotate all dependencies in the cycle as needing an <code>async</code> module wrapper.</p> </li> <li> <p>Fix a minification bug with lowered logical assignment operators (<a href="https://redirect.github.com/evanw/esbuild/issues/4508">#4508</a>)</p> <p>This release fixes a bug that could cause esbuild to generate incorrect code for logical assignment operators when lowering them to an older target environment. Specifically the lowering process requires duplicating the left-hand side, but esbuild incorrectly failed to count the duplicate as a new usage when the left-hand side is an identifier. That then caused the minifier to believe that the left-hand side was only used once and could attempt to incorrectly inline an initializer into the first usage. This bug has now been fixed:</p> <pre lang="js"><code>// Original code function foo() { let x </code></pre> </li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/evanw/esbuild/commit/609683d892977362a0f99026cb74b96263d728a9"><code>609683d</code></a> publish 0.28.2 to npm</li> <li><a href="https://github.com/evanw/esbuild/commit/11b1fe48df6859393d9469f323b5ebd17baaf989"><code>11b1fe4</code></a> add to release notes</li> <li><a href="https://github.com/evanw/esbuild/commit/ab50d91559a27e54cd0a27a403389130ea10d97d"><code>ab50d91</code></a> css: fix green/blue channel swap in oklch gamut mapping (<a href="https://redirect.github.com/evanw/esbuild/issues/4488">#4488</a>)</li> <li><a href="https://github.com/evanw/esbuild/commit/04627b6cf99b4a7491bebb0268173a7c77a85030"><code>04627b6</code></a> fix <a href="https://redirect.github.com/evanw/esbuild/issues/4498">#4498</a>: <code>async</code> TLA checks need a worklist</li> <li><a href="https://github.com/evanw/esbuild/commit/5c15177a308c7224604058a769c4abf0a66b0a36"><code>5c15177</code></a> disable <code>gopls</code> in the <code>go</code> folder</li> <li><a href="https://github.com/evanw/esbuild/commit/fc2ee9babc5a2e8ea7ec7c10dd5850b71f7cec7e"><code>fc2ee9b</code></a> css: adjust parser to allow <code>--foo: {...}</code></li> <li><a href="https://github.com/evanw/esbuild/commit/209db54371e62ad1c50e12e56bb93c74c53b0408"><code>209db54</code></a> release notes for css nesting bugfix</li> <li><a href="https://github.com/evanw/esbuild/commit/c625d31bf08a0647ec724bf76c7115f7aec55971"><code>c625d31</code></a> fix <a href="https://redirect.github.com/evanw/esbuild/issues/4497">#4497</a>: preserve nested ampersands during minification (<a href="https://redirect.github.com/evanw/esbuild/issues/4500">#4500</a>)</li> <li><a href="https://github.com/evanw/esbuild/commit/34474e278528a60f58c959c0f422d2bfa6f6886d"><code>34474e2</code></a> better isolation of current part in js parser</li> <li><a href="https://github.com/evanw/esbuild/commit/07f6e8c50677e0b41e5ed726c08b0ea200b14e5b"><code>07f6e8c</code></a> fix <a href="https://redirect.github.com/evanw/esbuild/issues/4507">#4507</a>: <code>import</code> assignment tree-shaking bug</li> <li>Additional commits viewable in <a href="https://github.com/evanw/esbuild/compare/v0.28.1...v0.28.2">compare view</a></li> </ul> </details> <br /> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |
||
|
|
ab4c4941f2 |
build(deps): bump @aws-sdk/client-s3 from 3.1111.0 to 3.1115.0 (#11876)
Bumps [@aws-sdk/client-s3](https://github.com/aws/aws-sdk-js-v3/tree/HEAD/clients/client-s3) from 3.1111.0 to 3.1115.0. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/aws/aws-sdk-js-v3/releases">@aws-sdk/client-s3's releases</a>.</em></p> <blockquote> <h2>v3.1115.0</h2> <h4>3.1115.0(2026-08-20)</h4> <h5>Documentation Changes</h5> <ul> <li><strong>client-pricing-plan-manager:</strong> Documentation update for the CreateSubscription API to correct the default value of the approval mode parameter. The default value for paid subscriptions is MANUAL, not IMMEDIATE as previously documented. The default value remains IMMEDIATE for FREE tier subscriptions. (<a href="https://github.com/aws/aws-sdk-js-v3/commit/50d16ae3f271fe02a775de35ff81f96c3fc3f3f5">50d16ae3</a>)</li> </ul> <h5>New Features</h5> <ul> <li><strong>client-sesv2:</strong> Amazon SES now supports per-message tracking overrides. You can use the new ConfigurationOverrides parameter in SendEmail and SendBulkEmail to enable or disable open and click tracking for individual messages without changing your account-level or configuration set settings. (<a href="https://github.com/aws/aws-sdk-js-v3/commit/da56caa551406c67f4add96bcb7a98ac9ad9ec5d">da56caa5</a>)</li> <li><strong>client-arc-region-switch:</strong> Adds support for Rds switchover read replica for Oracle databases in Region switch plans (<a href="https://github.com/aws/aws-sdk-js-v3/commit/85ffb20a7857736b13916df32017903c6fd0b3e0">85ffb20a</a>)</li> <li><strong>client-ec2:</strong> EC2 marks UEFI instance metadata field as sensitive. (<a href="https://github.com/aws/aws-sdk-js-v3/commit/c232746ad78da7961a997005c6102943c392c30c">c232746a</a>)</li> <li><strong>client-direct-connect:</strong> This release adds custom route prefix pool allocations for Direct Connect. You can set IPv4 and IPv6 route prefix counts on private and transit virtual interfaces, and view pool size and unallocated counts on connections and LAGs, plus direct connect gateway attachment prefix allocation totals. (<a href="https://github.com/aws/aws-sdk-js-v3/commit/a94fb9783b97be5c59ef543ea7448d0e09f6f048">a94fb978</a>)</li> <li><strong>client-amplify:</strong> Increased the maximum allowed length from 255 to 4,096 characters to support longer access tokens. (<a href="https://github.com/aws/aws-sdk-js-v3/commit/f7f8ecd1b8b45ba69bb48d1ac61a5bafc2a2d672">f7f8ecd1</a>)</li> <li><strong>client-batch:</strong> AWS Batch now supports a new compute environment type that provides fully managed EC2 capacity with broader compute flexibility than Fargate, including GPU instances, bare metal, and specific instance type selection, without infrastructure management overhead. (<a href="https://github.com/aws/aws-sdk-js-v3/commit/9c559a7366166cbe4e81c2752eb1c26696a884a9">9c559a73</a>)</li> <li><strong>client-sagemaker:</strong> Added IAM Identity Center (IdC) support to CreatePartnerApp and UpdatePartnerApp APIs. Added Customer Managed Key (CMK) support to CreateMlflowApp and DescribeMlflowApp. (<a href="https://github.com/aws/aws-sdk-js-v3/commit/5548588739d30ba5b7ebf1c6a88fa5749adb15b0">55485887</a>)</li> <li><strong>client-lambda:</strong> Adds support for full JSON resource-based policies, enabling customers to create, retrieve, update, and delete function resource policies as complete JSON documents. (<a href="https://github.com/aws/aws-sdk-js-v3/commit/72573a2ad860a406a0fe742dfd40b50458b6153d">72573a2a</a>)</li> <li><strong>client-cloudfront:</strong> Added SigV4a as a supported signing protocol for Origin Access Control (OAC), enabling CloudFront to sign requests to Amazon S3 Multi-Region Access Point (S3-MRAP) origins. (<a href="https://github.com/aws/aws-sdk-js-v3/commit/95476293d5fa70f266cb4aa4c54ecebce9c771ce">95476293</a>)</li> </ul> <hr /> <p>For list of updated packages, view <strong>updated-packages.md</strong> in <strong>assets-3.1115.0.zip</strong></p> <h2>v3.1114.0</h2> <h4>3.1114.0(2026-08-19)</h4> <h5>New Features</h5> <ul> <li><strong>client-eks:</strong> Adds support for EKS cluster certificate authorities (CA) (<a href="https://github.com/aws/aws-sdk-js-v3/commit/a1316eaec0734d880bdb975c082110f36d3d7180">a1316eae</a>)</li> <li><strong>client-bedrock-agentcore-control:</strong> AgentCore Memory now supports Flexible Namespaces (<a href="https://github.com/aws/aws-sdk-js-v3/commit/65c89d6d82897e07d0d671fbd0a3a0a44a93a9a2">65c89d6d</a>)</li> <li><strong>client-batch:</strong> AWS Batch now supports managing CloudWatch Container Insights on compute environments via CreateComputeEnvironment and UpdateComputeEnvironment. (<a href="https://github.com/aws/aws-sdk-js-v3/commit/f77fc37f101238d66a1849924da42be3ac50f4c5">f77fc37f</a>)</li> <li><strong>client-redshift:</strong> Amazon Redshift enhanced System Table retention that allows customers to store their system table data directly in S3 Tables in customer's account instead of Redshift Managed Storage (<a href="https://github.com/aws/aws-sdk-js-v3/commit/a46d1f96345459f8c606642be702b8a723d97d51">a46d1f96</a>)</li> <li><strong>client-bedrock-agentcore:</strong> AgentCore Memory now supports Flexible Namespaces and Non-Conversational Payloads in CreateEvent API (<a href="https://github.com/aws/aws-sdk-js-v3/commit/a0d8fb6df9d13bd1f22f89c1a5defef183becaf4">a0d8fb6d</a>)</li> <li><strong>client-medialive:</strong> AWS Elemental MediaLive now supports video cropping and output positioning. Use cropRectangle and outputPositionRectangle to position the encoded video within the output frame, with the surrounding area filled with black. (<a href="https://github.com/aws/aws-sdk-js-v3/commit/2bf1331a81cddad987b30380c685cc3b4f85f18b">2bf1331a</a>)</li> <li><strong>client-account-access:</strong> Adds throttling exceptions to operation outputs that were previously inconsistent with other operations. (<a href="https://github.com/aws/aws-sdk-js-v3/commit/1e39b38544c7b77246db936bc6313163f98718b9">1e39b385</a>)</li> <li><strong>client-vpc-lattice:</strong> Amazon VPC Lattice now supports modification of private DNS options on Service Network VPC Associations (<a href="https://github.com/aws/aws-sdk-js-v3/commit/92c89b2723c281f6fc8d2562ec86dbd3c9716bdf">92c89b27</a>)</li> <li><strong>client-redshift-serverless:</strong> Amazon Redshift Enhanced System Table Retention that allows customers to store their system table data directly in S3 Tables in customer's account instead of Redshift Managed Storage (<a href="https://github.com/aws/aws-sdk-js-v3/commit/73ad53c311578c41c4420d71835f63ff021b703a">73ad53c3</a>)</li> <li><strong>lib-transfer-manager:</strong> add file based download api and worker thread based download. (<a href="https://redirect.github.com/aws/aws-sdk-js-v3/pull/8259">#8259</a>) (<a href="https://github.com/aws/aws-sdk-js-v3/commit/b2d60357c87e86ce7da8902c9bd243bcc3bb34b2">b2d60357</a>)</li> </ul> <hr /> <p>For list of updated packages, view <strong>updated-packages.md</strong> in <strong>assets-3.1114.0.zip</strong></p> <h2>v3.1113.0</h2> <h4>3.1113.0(2026-08-18)</h4> <h5>Chores</h5> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/aws/aws-sdk-js-v3/blob/main/clients/client-s3/CHANGELOG.md">@aws-sdk/client-s3's changelog</a>.</em></p> <blockquote> <h1><a href="https://github.com/aws/aws-sdk-js-v3/compare/v3.1114.0...v3.1115.0">3.1115.0</a> (2026-08-20)</h1> <p><strong>Note:</strong> Version bump only for package <code>@aws-sdk/client-s3</code></p> <h1><a href="https://github.com/aws/aws-sdk-js-v3/compare/v3.1113.0...v3.1114.0">3.1114.0</a> (2026-08-19)</h1> <p><strong>Note:</strong> Version bump only for package <code>@aws-sdk/client-s3</code></p> <h1><a href="https://github.com/aws/aws-sdk-js-v3/compare/v3.1112.0...v3.1113.0">3.1113.0</a> (2026-08-18)</h1> <p><strong>Note:</strong> Version bump only for package <code>@aws-sdk/client-s3</code></p> <h1><a href="https://github.com/aws/aws-sdk-js-v3/compare/v3.1111.0...v3.1112.0">3.1112.0</a> (2026-08-17)</h1> <p><strong>Note:</strong> Version bump only for package <code>@aws-sdk/client-s3</code></p> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/aws/aws-sdk-js-v3/commit/efc86fc9c3f80861228ad7f1b2fc97084b7a1c20"><code>efc86fc</code></a> Publish v3.1115.0</li> <li><a href="https://github.com/aws/aws-sdk-js-v3/commit/5318b44c47c47e50ee77d6d8044cf8a472d2d08f"><code>5318b44</code></a> Publish v3.1114.0</li> <li><a href="https://github.com/aws/aws-sdk-js-v3/commit/73a06d2aeb7261977dbffd4f604a6dafc3c2d381"><code>73a06d2</code></a> Publish v3.1113.0</li> <li><a href="https://github.com/aws/aws-sdk-js-v3/commit/cb4ae7624bd56b21e127496f9641912b1a5a8ce2"><code>cb4ae76</code></a> Publish v3.1112.0</li> <li>See full diff in <a href="https://github.com/aws/aws-sdk-js-v3/commits/v3.1115.0/clients/client-s3">compare view</a></li> </ul> </details> <br /> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |
||
|
|
a68af9ed9c |
build(deps-dev): bump @storybook/addon-a11y from 10.5.8 to 10.5.10 (#11874)
Bumps [@storybook/addon-a11y](https://github.com/storybookjs/storybook/tree/HEAD/code/addons/a11y) from 10.5.8 to 10.5.10. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/storybookjs/storybook/releases">@storybook/addon-a11y's releases</a>.</em></p> <blockquote> <h2>v10.5.10</h2> <h2>10.5.10</h2> <ul> <li>Core: Fetch static open-service snapshots relative to the document - <a href="https://redirect.github.com/storybookjs/storybook/pull/35945">#35945</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Core: Pin oxc-resolver to 11.21.2 to keep tsconfig path aliases on solution-style tsconfigs - <a href="https://redirect.github.com/storybookjs/storybook/pull/35929">#35929</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Dependencies: Bump Vitest to 4.1.6 (CVE-2026-47428) - <a href="https://redirect.github.com/storybookjs/storybook/pull/35530">#35530</a>, thanks <a href="https://github.com/anupamme"><code>@anupamme</code></a>!</li> <li>Docs: Declare the font on overlay surfaces so docs tooltips are not left to inherit - <a href="https://redirect.github.com/storybookjs/storybook/pull/35966">#35966</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>ESLint Plugin: Bundle CSF helpers so the plugin loads without storybook - <a href="https://redirect.github.com/storybookjs/storybook/pull/35950">#35950</a>, thanks <a href="https://github.com/ndelangen"><code>@ndelangen</code></a>!</li> <li>React: Preserve discriminated union prop values in metadata extraction - <a href="https://redirect.github.com/storybookjs/storybook/pull/35844">#35844</a>, thanks <a href="https://github.com/s-robertson"><code>@s-robertson</code></a>!</li> </ul> <h2>v10.5.9</h2> <h2>10.5.9</h2> <ul> <li>Addon-Pseudo-States: Fix pseudo-states rewriting for nested functional selectors - <a href="https://redirect.github.com/storybookjs/storybook/pull/34318">#34318</a>, thanks <a href="https://github.com/filipw01"><code>@filipw01</code></a>!</li> <li>Core: Skip module-graph reverse-index mirror when a patch is a no-op - <a href="https://redirect.github.com/storybookjs/storybook/pull/35825">#35825</a>, thanks <a href="https://github.com/ndelangen"><code>@ndelangen</code></a>!</li> <li>Core: Split module-graph into hot revisions and cold index services - <a href="https://redirect.github.com/storybookjs/storybook/pull/35831">#35831</a>, thanks <a href="https://github.com/ndelangen"><code>@ndelangen</code></a>!</li> <li>Preview: Fix crash when initialising UrlStore on a docs path - <a href="https://redirect.github.com/storybookjs/storybook/pull/35521">#35521</a>, thanks <a href="https://github.com/TheSeydiCharyyev"><code>@TheSeydiCharyyev</code></a>!</li> <li>Pseudo-States: Make stylesheet rewrites WebKit-safe - <a href="https://redirect.github.com/storybookjs/storybook/pull/35629">#35629</a>, thanks <a href="https://github.com/ethriel3695"><code>@ethriel3695</code></a>!</li> <li>TanStack: Keep the layout id when cloning a standalone index file route - <a href="https://redirect.github.com/storybookjs/storybook/pull/35660">#35660</a>, thanks <a href="https://github.com/Insik-Han"><code>@Insik-Han</code></a>!</li> <li>TanStack: Render real link hrefs in the Link mock - <a href="https://redirect.github.com/storybookjs/storybook/pull/35505">#35505</a>, thanks <a href="https://github.com/unpunnyfuns"><code>@unpunnyfuns</code></a>!</li> <li>Webpack: Prevent long preview output filenames - <a href="https://redirect.github.com/storybookjs/storybook/pull/35533">#35533</a>, thanks <a href="https://github.com/zhangli091011"><code>@zhangli091011</code></a>!</li> </ul> </blockquote> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/storybookjs/storybook/blob/next/CHANGELOG.md">@storybook/addon-a11y's changelog</a>.</em></p> <blockquote> <h2>10.5.10</h2> <ul> <li>Core: Fetch static open-service snapshots relative to the document - <a href="https://redirect.github.com/storybookjs/storybook/pull/35945">#35945</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Core: Pin oxc-resolver to 11.21.2 to keep tsconfig path aliases on solution-style tsconfigs - <a href="https://redirect.github.com/storybookjs/storybook/pull/35929">#35929</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Dependencies: Bump Vitest to 4.1.6 (CVE-2026-47428) - <a href="https://redirect.github.com/storybookjs/storybook/pull/35530">#35530</a>, thanks <a href="https://github.com/anupamme"><code>@anupamme</code></a>!</li> <li>Docs: Declare the font on overlay surfaces so docs tooltips are not left to inherit - <a href="https://redirect.github.com/storybookjs/storybook/pull/35966">#35966</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>ESLint Plugin: Bundle CSF helpers so the plugin loads without storybook - <a href="https://redirect.github.com/storybookjs/storybook/pull/35950">#35950</a>, thanks <a href="https://github.com/ndelangen"><code>@ndelangen</code></a>!</li> <li>React: Preserve discriminated union prop values in metadata extraction - <a href="https://redirect.github.com/storybookjs/storybook/pull/35844">#35844</a>, thanks <a href="https://github.com/s-robertson"><code>@s-robertson</code></a>!</li> </ul> <h2>10.5.9</h2> <ul> <li>Addon-Pseudo-States: Fix pseudo-states rewriting for nested functional selectors - <a href="https://redirect.github.com/storybookjs/storybook/pull/34318">#34318</a>, thanks <a href="https://github.com/filipw01"><code>@filipw01</code></a>!</li> <li>Core: Skip module-graph reverse-index mirror when a patch is a no-op - <a href="https://redirect.github.com/storybookjs/storybook/pull/35825">#35825</a>, thanks <a href="https://github.com/ndelangen"><code>@ndelangen</code></a>!</li> <li>Core: Split module-graph into hot revisions and cold index services - <a href="https://redirect.github.com/storybookjs/storybook/pull/35831">#35831</a>, thanks <a href="https://github.com/ndelangen"><code>@ndelangen</code></a>!</li> <li>Preview: Fix crash when initialising UrlStore on a docs path - <a href="https://redirect.github.com/storybookjs/storybook/pull/35521">#35521</a>, thanks <a href="https://github.com/TheSeydiCharyyev"><code>@TheSeydiCharyyev</code></a>!</li> <li>Pseudo-States: Make stylesheet rewrites WebKit-safe - <a href="https://redirect.github.com/storybookjs/storybook/pull/35629">#35629</a>, thanks <a href="https://github.com/ethriel3695"><code>@ethriel3695</code></a>!</li> <li>TanStack: Keep the layout id when cloning a standalone index file route - <a href="https://redirect.github.com/storybookjs/storybook/pull/35660">#35660</a>, thanks <a href="https://github.com/Insik-Han"><code>@Insik-Han</code></a>!</li> <li>TanStack: Render real link hrefs in the Link mock - <a href="https://redirect.github.com/storybookjs/storybook/pull/35505">#35505</a>, thanks <a href="https://github.com/unpunnyfuns"><code>@unpunnyfuns</code></a>!</li> <li>Webpack: Prevent long preview output filenames - <a href="https://redirect.github.com/storybookjs/storybook/pull/35533">#35533</a>, thanks <a href="https://github.com/zhangli091011"><code>@zhangli091011</code></a>!</li> </ul> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/storybookjs/storybook/commit/a2db7526e1538a48bfa0529a881822e8074b2009"><code>a2db752</code></a> Bump version from "10.5.9" to "10.5.10" [skip ci]</li> <li><a href="https://github.com/storybookjs/storybook/commit/8f561048949b3ce3674a71711942177a14e4e8f9"><code>8f56104</code></a> Bump version from "10.5.8" to "10.5.9" [skip ci]</li> <li>See full diff in <a href="https://github.com/storybookjs/storybook/commits/v10.5.10/code/addons/a11y">compare view</a></li> </ul> </details> <br /> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |
||
|
|
41726ae279 |
build(deps): bump react-resizable-panels from 4.12.2 to 4.12.3 (#11872)
Bumps [react-resizable-panels](https://github.com/bvaughn/react-resizable-panels) from 4.12.2 to 4.12.3. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/bvaughn/react-resizable-panels/releases">react-resizable-panels's releases</a>.</em></p> <blockquote> <h2>4.12.3</h2> <ul> <li><a href="https://redirect.github.com/bvaughn/react-resizable-panels/pull/730">730</a>: Guard <code>CSSStyleSheet</code> construction to avoid throwing in unsupported environments (<a href="https://github.com/leo-yang-qiong"><code>@leo-yang-qiong</code></a>)</li> <li><a href="https://redirect.github.com/bvaughn/react-resizable-panels/pull/736">736</a>: Bugfix: Derived Panel constraints equality check</li> <li><a href="https://redirect.github.com/bvaughn/react-resizable-panels/pull/732">732</a>: Bugfix: Prevent orphaned groups in "pointerup" edge case (<a href="https://github.com/waterWang"><code>@waterWang</code></a>)</li> </ul> </blockquote> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/bvaughn/react-resizable-panels/blob/main/CHANGELOG.md">react-resizable-panels's changelog</a>.</em></p> <blockquote> <h2>4.12.3</h2> <ul> <li><a href="https://redirect.github.com/bvaughn/react-resizable-panels/pull/730">730</a>: Guard <code>CSSStyleSheet</code> construction to avoid throwing in unsupported environments (<a href="https://github.com/leo-yang-qiong"><code>@leo-yang-qiong</code></a>)</li> <li><a href="https://redirect.github.com/bvaughn/react-resizable-panels/pull/736">736</a>: Bugfix: Derived Panel constraints equality check</li> <li><a href="https://redirect.github.com/bvaughn/react-resizable-panels/pull/732">732</a>: Bugfix: Prevent orphaned groups in "pointerup" edge case (<a href="https://github.com/waterWang"><code>@waterWang</code></a>)</li> </ul> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/bvaughn/react-resizable-panels/commit/f9c422714a66e14f671a17f340a3560d8032fcdc"><code>f9c4227</code></a> 4.12.2 -> 4.12.3</li> <li><a href="https://github.com/bvaughn/react-resizable-panels/commit/30503d1dadef45456dc7f65e64579f72e09e311f"><code>30503d1</code></a> Fix derived Panel constraints equality check (<a href="https://redirect.github.com/bvaughn/react-resizable-panels/issues/736">#736</a>)</li> <li><a href="https://github.com/bvaughn/react-resizable-panels/commit/30aef6a448d26bfaeb0e80f2b7d7aeec7a113818"><code>30aef6a</code></a> Pending CHANGELOG</li> <li><a href="https://github.com/bvaughn/react-resizable-panels/commit/b1d574e504099717df19afd671753511fb515389"><code>b1d574e</code></a> fix: guard CSSStyleSheet construction with adoptedStyleSheets check (<a href="https://redirect.github.com/bvaughn/react-resizable-panels/issues/730">#730</a>)</li> <li><a href="https://github.com/bvaughn/react-resizable-panels/commit/6649f42e56cdd9f323d8156365ea7b85a6a5e966"><code>6649f42</code></a> fix: don't resurrect stale group entries on pointer-up commit (Fixes <a href="https://redirect.github.com/bvaughn/react-resizable-panels/issues/729">#729</a>) (#...</li> <li>See full diff in <a href="https://github.com/bvaughn/react-resizable-panels/compare/4.12.2...4.12.3">compare view</a></li> </ul> </details> <br /> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |
||
|
|
50e324638c |
build(deps): bump @assistant-ui/react from 0.15.14 to 0.15.16 (#11888)
Bumps [@assistant-ui/react](https://github.com/assistant-ui/assistant-ui/tree/HEAD/packages/react) from 0.15.14 to 0.15.16. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/assistant-ui/assistant-ui/releases">@assistant-ui/react's releases</a>.</em></p> <blockquote> <h2><code>@assistant-ui/react</code><a href="https://github.com/0"><code>@0</code></a>.15.16</h2> <h3>Patch Changes</h3> <ul> <li> <p><a href="https://redirect.github.com/assistant-ui/assistant-ui/pull/6136">#6136</a> <a href="https://github.com/assistant-ui/assistant-ui/commit/f7bd2d9392e1e71750012fa87649002e8c9d1dab"><code>f7bd2d9</code></a> - fix: keep DevTools updates flowing when a subscriber throws (<a href="https://github.com/Kinfe123"><code>@Kinfe123</code></a>)</p> </li> <li> <p><a href="https://redirect.github.com/assistant-ui/assistant-ui/pull/6055">#6055</a> <a href="https://github.com/assistant-ui/assistant-ui/commit/1f3eaa77897e617efa977f4d194de7e6013a0de5"><code>1f3eaa7</code></a> - fix: contain SandboxHost render failures after teardown (<a href="https://github.com/Kinfe123"><code>@Kinfe123</code></a>)</p> </li> <li> <p><a href="https://redirect.github.com/assistant-ui/assistant-ui/pull/6110">#6110</a> <a href="https://github.com/assistant-ui/assistant-ui/commit/48f95b1442c4e9f744660b8e25e7aceb9b5ba5dc"><code>48f95b1</code></a> - chore: delete the dead <code>ensureBinding</code> and <code>useRuntimeState</code> utilities (<a href="https://github.com/samdickson22"><code>@samdickson22</code></a>)</p> <p><code>src/context/react/utils/ensureBinding.ts</code> and <code>src/context/react/utils/useRuntimeState.ts</code> imported only each other. Nothing else in the repo referenced them, neither appears in the package barrel or the api-surface snapshot, and the <code>"."</code>-only exports map made them unreachable to consumers. <code>ensureBinding</code> was an external caller of <code>__internal_bindMethods</code> that no longer had a caller of its own; the runtime classes bind themselves in their constructors, so nothing changes at runtime. The public API surface is unchanged and every other emitted file is byte-identical.</p> </li> <li> <p><a href="https://redirect.github.com/assistant-ui/assistant-ui/pull/6156">#6156</a> <a href="https://github.com/assistant-ui/assistant-ui/commit/9c65b511bc7cdc7d6699c128cac4650cae728043"><code>9c65b51</code></a> - deprecate leftover Primitive.If and Empty wrappers on react-native and react-ink, and point them at AuiIf (<a href="https://github.com/okisdev"><code>@okisdev</code></a>)</p> <p>ThreadIf now reads <code>thread.isEmpty</code> instead of <code>messages.length === 0</code>, matching the loading-aware field already used by ThreadEmpty and AuiIf. First-party examples and docs samples that still called the leftover wrappers now use <code>AuiIf</code> directly.</p> </li> <li> <p><a href="https://redirect.github.com/assistant-ui/assistant-ui/pull/6084">#6084</a> <a href="https://github.com/assistant-ui/assistant-ui/commit/ca9e72ce85a9164b11947f9b7a38fb5801f7d04e"><code>ca9e72c</code></a> - fix: resync trigger popover cursor after selection (<a href="https://github.com/apps/rupic-app"><code>@rupic-app</code></a>)</p> </li> <li> <p><a href="https://redirect.github.com/assistant-ui/assistant-ui/pull/6054">#6054</a> <a href="https://github.com/assistant-ui/assistant-ui/commit/59e9a0881c3c392dd0f92508deab78aa50ddd605"><code>59e9a08</code></a> - fix: handle rejected asynchronous Markdown exports (<a href="https://github.com/Kinfe123"><code>@Kinfe123</code></a>)</p> </li> <li> <p><a href="https://redirect.github.com/assistant-ui/assistant-ui/pull/6098">#6098</a> <a href="https://github.com/assistant-ui/assistant-ui/commit/b9b9dad28af0fc7c873d0b653830c0f1a78197ed"><code>b9b9dad</code></a> - fix: drain unrevealed smooth text when a message completes before any frame (<a href="https://github.com/apps/rupic-app"><code>@rupic-app</code></a>)</p> </li> <li> <p><a href="https://redirect.github.com/assistant-ui/assistant-ui/pull/6061">#6061</a> <a href="https://github.com/assistant-ui/assistant-ui/commit/75dfbe3a2b7c3af61793fc1448e06d2d0063767a"><code>75dfbe3</code></a> - docs: document Escape-to-stop-speaking on ThreadPrimitive.Root (<a href="https://github.com/samdickson22"><code>@samdickson22</code></a>)</p> </li> <li> <p><a href="https://redirect.github.com/assistant-ui/assistant-ui/pull/6124">#6124</a> <a href="https://github.com/assistant-ui/assistant-ui/commit/06b04a7976d10fac3af40ae9ca59b52385ef2ae2"><code>06b04a7</code></a> - chore: update dependencies (<a href="https://github.com/okisdev"><code>@okisdev</code></a>)</p> </li> <li> <p>Updated dependencies [<a href="https://github.com/assistant-ui/assistant-ui/commit/fa309156e033dc085c0d3b8fb97c27c81a3d2c6e"><code>fa30915</code></a>, <a href="https://github.com/assistant-ui/assistant-ui/commit/b355aefbe2403025562f0e08494a57450bfdc049"><code>b355aef</code></a>, <a href="https://github.com/assistant-ui/assistant-ui/commit/f7bd2d9392e1e71750012fa87649002e8c9d1dab"><code>f7bd2d9</code></a>, <a href="https://github.com/assistant-ui/assistant-ui/commit/4947ef4f9b0956bd4ca21c457b3cc7e79a2fc9e0"><code>4947ef4</code></a>, <a href="https://github.com/assistant-ui/assistant-ui/commit/332f736e64bfa26f76cd60318279697ddbc0b36d"><code>332f736</code></a>, <a href="https://github.com/assistant-ui/assistant-ui/commit/ef9254d5b2174fb4b58b4e954a8a0d60910a484c"><code>ef9254d</code></a>, <a href="https://github.com/assistant-ui/assistant-ui/commit/9c65b511bc7cdc7d6699c128cac4650cae728043"><code>9c65b51</code></a>, <a href="https://github.com/assistant-ui/assistant-ui/commit/5845ba7c5690af776701683fbd2d04e9ca0eaaff"><code>5845ba7</code></a>, <a href="https://github.com/assistant-ui/assistant-ui/commit/1b30bfdabadfe3613b7c98296de3d6665122136b"><code>1b30bfd</code></a>, <a href="https://github.com/assistant-ui/assistant-ui/commit/365e763928ff38d2de518efa2a7c44249afbbf83"><code>365e763</code></a>, <a href="https://github.com/assistant-ui/assistant-ui/commit/d19921d3739efb53dcbbb1ae04ffd18a94dca080"><code>d19921d</code></a>, <a href="https://github.com/assistant-ui/assistant-ui/commit/996aa5723cf8d7db00cc72da08713226d90ec0e1"><code>996aa57</code></a>, <a href="https://github.com/assistant-ui/assistant-ui/commit/21d6e87dc2834af11babb93c004f7d4f3a4f9568"><code>21d6e87</code></a>, <a href="https://github.com/assistant-ui/assistant-ui/commit/cd247e557b4876c49feb9b79c4f5149cc2271dad"><code>cd247e5</code></a>, <a href="https://github.com/assistant-ui/assistant-ui/commit/f2b3ef8b6330e9353741973b0bfe0abf37d81e70"><code>f2b3ef8</code></a>, <a href="https://github.com/assistant-ui/assistant-ui/commit/1bf263ba208668ead7f6c0786ca0c3064e31c3ab"><code>1bf263b</code></a>, <a href="https://github.com/assistant-ui/assistant-ui/commit/19e52c4012a6a8c32e514134af9ce4eee1146864"><code>19e52c4</code></a>, <a href="https://github.com/assistant-ui/assistant-ui/commit/06b04a7976d10fac3af40ae9ca59b52385ef2ae2"><code>06b04a7</code></a>, <a href="https://github.com/assistant-ui/assistant-ui/commit/a614b5e44df5f59d82b63b60132a41c89f82e185"><code>a614b5e</code></a>, <a href="https://github.com/assistant-ui/assistant-ui/commit/07b51dbbc749c94023fa25df99bb7f64dc211ff1"><code>07b51db</code></a>, <a href="https://github.com/assistant-ui/assistant-ui/commit/92e52bd2c99ee8cacd242bf723f617df64e42e2a"><code>92e52bd</code></a>]:</p> <ul> <li><code>@assistant-ui/core</code><a href="https://github.com/0"><code>@0</code></a>.3.15</li> <li><code>@assistant-ui/tap</code><a href="https://github.com/0"><code>@0</code></a>.9.14</li> <li>assistant-stream@0.3.39</li> </ul> </li> </ul> <h2><code>@assistant-ui/react</code><a href="https://github.com/0"><code>@0</code></a>.15.15</h2> <h3>Patch Changes</h3> <ul> <li> <p><a href="https://redirect.github.com/assistant-ui/assistant-ui/pull/6071">#6071</a> <a href="https://github.com/assistant-ui/assistant-ui/commit/c3fd447f23cbaa36381b2f62058b420bd54cc148"><code>c3fd447</code></a> - feat: host assistant-cloud thread lists on AISDKThreads via RemoteThreadList (<a href="https://github.com/okisdev"><code>@okisdev</code></a>)</p> <p>AISDKThreads({ cloud }) uses RemoteThreadList and remounts each thread like useChatRuntime. Cloud history withFormat resolves persistence per call so one adapter can serve many threads. useExternalHistory waits for threadListItem.remoteId instead of latching on the first empty paint.</p> </li> <li> <p><a href="https://redirect.github.com/assistant-ui/assistant-ui/pull/5872">#5872</a> <a href="https://github.com/assistant-ui/assistant-ui/commit/f9529bfdea5018505ef393fe46e93809a0012032"><code>f9529bf</code></a> - feat: move useAssistantTransportRuntime into core/react (<a href="https://github.com/okisdev"><code>@okisdev</code></a>)</p> </li> <li> <p><a href="https://redirect.github.com/assistant-ui/assistant-ui/pull/5872">#5872</a> <a href="https://github.com/assistant-ui/assistant-ui/commit/f9529bfdea5018505ef393fe46e93809a0012032"><code>f9529bf</code></a> - fix: persist data message parts in aui/v0 cloud history (<a href="https://github.com/okisdev"><code>@okisdev</code></a>)</p> </li> <li> <p><a href="https://redirect.github.com/assistant-ui/assistant-ui/pull/5839">#5839</a> <a href="https://github.com/assistant-ui/assistant-ui/commit/24a1af7607a29e5026f1de77a24e0b3efa76bca4"><code>24a1af7</code></a> - fix: validate MCP App resource responses (<a href="https://github.com/Kinfe123"><code>@Kinfe123</code></a>)</p> </li> <li> <p><a href="https://redirect.github.com/assistant-ui/assistant-ui/pull/5817">#5817</a> <a href="https://github.com/assistant-ui/assistant-ui/commit/dab7b7af71773db87a729d7233035187a10a60db"><code>dab7b7a</code></a> - fix: dispose sandbox frames when bridge setup fails (<a href="https://github.com/Kinfe123"><code>@Kinfe123</code></a>)</p> </li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/assistant-ui/assistant-ui/blob/main/packages/react/CHANGELOG.md">@assistant-ui/react's changelog</a>.</em></p> <blockquote> <h2>0.15.16</h2> <h3>Patch Changes</h3> <ul> <li> <p><a href="https://redirect.github.com/assistant-ui/assistant-ui/pull/6136">#6136</a> <a href="https://github.com/assistant-ui/assistant-ui/commit/f7bd2d9392e1e71750012fa87649002e8c9d1dab"><code>f7bd2d9</code></a> - fix: keep DevTools updates flowing when a subscriber throws (<a href="https://github.com/Kinfe123"><code>@Kinfe123</code></a>)</p> </li> <li> <p><a href="https://redirect.github.com/assistant-ui/assistant-ui/pull/6055">#6055</a> <a href="https://github.com/assistant-ui/assistant-ui/commit/1f3eaa77897e617efa977f4d194de7e6013a0de5"><code>1f3eaa7</code></a> - fix: contain SandboxHost render failures after teardown (<a href="https://github.com/Kinfe123"><code>@Kinfe123</code></a>)</p> </li> <li> <p><a href="https://redirect.github.com/assistant-ui/assistant-ui/pull/6110">#6110</a> <a href="https://github.com/assistant-ui/assistant-ui/commit/48f95b1442c4e9f744660b8e25e7aceb9b5ba5dc"><code>48f95b1</code></a> - chore: delete the dead <code>ensureBinding</code> and <code>useRuntimeState</code> utilities (<a href="https://github.com/samdickson22"><code>@samdickson22</code></a>)</p> <p><code>src/context/react/utils/ensureBinding.ts</code> and <code>src/context/react/utils/useRuntimeState.ts</code> imported only each other. Nothing else in the repo referenced them, neither appears in the package barrel or the api-surface snapshot, and the <code>"."</code>-only exports map made them unreachable to consumers. <code>ensureBinding</code> was an external caller of <code>__internal_bindMethods</code> that no longer had a caller of its own; the runtime classes bind themselves in their constructors, so nothing changes at runtime. The public API surface is unchanged and every other emitted file is byte-identical.</p> </li> <li> <p><a href="https://redirect.github.com/assistant-ui/assistant-ui/pull/6156">#6156</a> <a href="https://github.com/assistant-ui/assistant-ui/commit/9c65b511bc7cdc7d6699c128cac4650cae728043"><code>9c65b51</code></a> - deprecate leftover Primitive.If and Empty wrappers on react-native and react-ink, and point them at AuiIf (<a href="https://github.com/okisdev"><code>@okisdev</code></a>)</p> <p>ThreadIf now reads <code>thread.isEmpty</code> instead of <code>messages.length === 0</code>, matching the loading-aware field already used by ThreadEmpty and AuiIf. First-party examples and docs samples that still called the leftover wrappers now use <code>AuiIf</code> directly.</p> </li> <li> <p><a href="https://redirect.github.com/assistant-ui/assistant-ui/pull/6084">#6084</a> <a href="https://github.com/assistant-ui/assistant-ui/commit/ca9e72ce85a9164b11947f9b7a38fb5801f7d04e"><code>ca9e72c</code></a> - fix: resync trigger popover cursor after selection (<a href="https://github.com/apps/rupic-app"><code>@rupic-app</code></a>)</p> </li> <li> <p><a href="https://redirect.github.com/assistant-ui/assistant-ui/pull/6054">#6054</a> <a href="https://github.com/assistant-ui/assistant-ui/commit/59e9a0881c3c392dd0f92508deab78aa50ddd605"><code>59e9a08</code></a> - fix: handle rejected asynchronous Markdown exports (<a href="https://github.com/Kinfe123"><code>@Kinfe123</code></a>)</p> </li> <li> <p><a href="https://redirect.github.com/assistant-ui/assistant-ui/pull/6098">#6098</a> <a href="https://github.com/assistant-ui/assistant-ui/commit/b9b9dad28af0fc7c873d0b653830c0f1a78197ed"><code>b9b9dad</code></a> - fix: drain unrevealed smooth text when a message completes before any frame (<a href="https://github.com/apps/rupic-app"><code>@rupic-app</code></a>)</p> </li> <li> <p><a href="https://redirect.github.com/assistant-ui/assistant-ui/pull/6061">#6061</a> <a href="https://github.com/assistant-ui/assistant-ui/commit/75dfbe3a2b7c3af61793fc1448e06d2d0063767a"><code>75dfbe3</code></a> - docs: document Escape-to-stop-speaking on ThreadPrimitive.Root (<a href="https://github.com/samdickson22"><code>@samdickson22</code></a>)</p> </li> <li> <p><a href="https://redirect.github.com/assistant-ui/assistant-ui/pull/6124">#6124</a> <a href="https://github.com/assistant-ui/assistant-ui/commit/06b04a7976d10fac3af40ae9ca59b52385ef2ae2"><code>06b04a7</code></a> - chore: update dependencies (<a href="https://github.com/okisdev"><code>@okisdev</code></a>)</p> </li> <li> <p>Updated dependencies [<a href="https://github.com/assistant-ui/assistant-ui/commit/fa309156e033dc085c0d3b8fb97c27c81a3d2c6e"><code>fa30915</code></a>, <a href="https://github.com/assistant-ui/assistant-ui/commit/b355aefbe2403025562f0e08494a57450bfdc049"><code>b355aef</code></a>, <a href="https://github.com/assistant-ui/assistant-ui/commit/f7bd2d9392e1e71750012fa87649002e8c9d1dab"><code>f7bd2d9</code></a>, <a href="https://github.com/assistant-ui/assistant-ui/commit/4947ef4f9b0956bd4ca21c457b3cc7e79a2fc9e0"><code>4947ef4</code></a>, <a href="https://github.com/assistant-ui/assistant-ui/commit/332f736e64bfa26f76cd60318279697ddbc0b36d"><code>332f736</code></a>, <a href="https://github.com/assistant-ui/assistant-ui/commit/ef9254d5b2174fb4b58b4e954a8a0d60910a484c"><code>ef9254d</code></a>, <a href="https://github.com/assistant-ui/assistant-ui/commit/9c65b511bc7cdc7d6699c128cac4650cae728043"><code>9c65b51</code></a>, <a href="https://github.com/assistant-ui/assistant-ui/commit/5845ba7c5690af776701683fbd2d04e9ca0eaaff"><code>5845ba7</code></a>, <a href="https://github.com/assistant-ui/assistant-ui/commit/1b30bfdabadfe3613b7c98296de3d6665122136b"><code>1b30bfd</code></a>, <a href="https://github.com/assistant-ui/assistant-ui/commit/365e763928ff38d2de518efa2a7c44249afbbf83"><code>365e763</code></a>, <a href="https://github.com/assistant-ui/assistant-ui/commit/d19921d3739efb53dcbbb1ae04ffd18a94dca080"><code>d19921d</code></a>, <a href="https://github.com/assistant-ui/assistant-ui/commit/996aa5723cf8d7db00cc72da08713226d90ec0e1"><code>996aa57</code></a>, <a href="https://github.com/assistant-ui/assistant-ui/commit/21d6e87dc2834af11babb93c004f7d4f3a4f9568"><code>21d6e87</code></a>, <a href="https://github.com/assistant-ui/assistant-ui/commit/cd247e557b4876c49feb9b79c4f5149cc2271dad"><code>cd247e5</code></a>, <a href="https://github.com/assistant-ui/assistant-ui/commit/f2b3ef8b6330e9353741973b0bfe0abf37d81e70"><code>f2b3ef8</code></a>, <a href="https://github.com/assistant-ui/assistant-ui/commit/1bf263ba208668ead7f6c0786ca0c3064e31c3ab"><code>1bf263b</code></a>, <a href="https://github.com/assistant-ui/assistant-ui/commit/19e52c4012a6a8c32e514134af9ce4eee1146864"><code>19e52c4</code></a>, <a href="https://github.com/assistant-ui/assistant-ui/commit/06b04a7976d10fac3af40ae9ca59b52385ef2ae2"><code>06b04a7</code></a>, <a href="https://github.com/assistant-ui/assistant-ui/commit/a614b5e44df5f59d82b63b60132a41c89f82e185"><code>a614b5e</code></a>, <a href="https://github.com/assistant-ui/assistant-ui/commit/07b51dbbc749c94023fa25df99bb7f64dc211ff1"><code>07b51db</code></a>, <a href="https://github.com/assistant-ui/assistant-ui/commit/92e52bd2c99ee8cacd242bf723f617df64e42e2a"><code>92e52bd</code></a>]:</p> <ul> <li><code>@assistant-ui/core</code><a href="https://github.com/0"><code>@0</code></a>.3.15</li> <li><code>@assistant-ui/tap</code><a href="https://github.com/0"><code>@0</code></a>.9.14</li> <li>assistant-stream@0.3.39</li> </ul> </li> </ul> <h2>0.15.15</h2> <h3>Patch Changes</h3> <ul> <li> <p><a href="https://redirect.github.com/assistant-ui/assistant-ui/pull/6071">#6071</a> <a href="https://github.com/assistant-ui/assistant-ui/commit/c3fd447f23cbaa36381b2f62058b420bd54cc148"><code>c3fd447</code></a> - feat: host assistant-cloud thread lists on AISDKThreads via RemoteThreadList (<a href="https://github.com/okisdev"><code>@okisdev</code></a>)</p> <p>AISDKThreads({ cloud }) uses RemoteThreadList and remounts each thread like useChatRuntime. Cloud history withFormat resolves persistence per call so one adapter can serve many threads. useExternalHistory waits for threadListItem.remoteId instead of latching on the first empty paint.</p> </li> <li> <p><a href="https://redirect.github.com/assistant-ui/assistant-ui/pull/5872">#5872</a> <a href="https://github.com/assistant-ui/assistant-ui/commit/f9529bfdea5018505ef393fe46e93809a0012032"><code>f9529bf</code></a> - feat: move useAssistantTransportRuntime into core/react (<a href="https://github.com/okisdev"><code>@okisdev</code></a>)</p> </li> <li> <p><a href="https://redirect.github.com/assistant-ui/assistant-ui/pull/5872">#5872</a> <a href="https://github.com/assistant-ui/assistant-ui/commit/f9529bfdea5018505ef393fe46e93809a0012032"><code>f9529bf</code></a> - fix: persist data message parts in aui/v0 cloud history (<a href="https://github.com/okisdev"><code>@okisdev</code></a>)</p> </li> <li> <p><a href="https://redirect.github.com/assistant-ui/assistant-ui/pull/5839">#5839</a> <a href="https://github.com/assistant-ui/assistant-ui/commit/24a1af7607a29e5026f1de77a24e0b3efa76bca4"><code>24a1af7</code></a> - fix: validate MCP App resource responses (<a href="https://github.com/Kinfe123"><code>@Kinfe123</code></a>)</p> </li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/assistant-ui/assistant-ui/commit/75e3ef71beb5dc99f6fc624624d3d61b307c8599"><code>75e3ef7</code></a> chore: update versions (<a href="https://github.com/assistant-ui/assistant-ui/tree/HEAD/packages/react/issues/6086">#6086</a>)</li> <li><a href="https://github.com/assistant-ui/assistant-ui/commit/f7bd2d9392e1e71750012fa87649002e8c9d1dab"><code>f7bd2d9</code></a> fix(react): isolate devtools subscribers (<a href="https://github.com/assistant-ui/assistant-ui/tree/HEAD/packages/react/issues/6136">#6136</a>)</li> <li><a href="https://github.com/assistant-ui/assistant-ui/commit/9c65b511bc7cdc7d6699c128cac4650cae728043"><code>9c65b51</code></a> fix(react-native,react-ink): honor thread.isEmpty in leftover ThreadIf (<a href="https://github.com/assistant-ui/assistant-ui/tree/HEAD/packages/react/issues/6156">#6156</a>)</li> <li><a href="https://github.com/assistant-ui/assistant-ui/commit/48f95b1442c4e9f744660b8e25e7aceb9b5ba5dc"><code>48f95b1</code></a> chore(react): delete the dead ensureBinding and useRuntimeState utilities (<a href="https://github.com/assistant-ui/assistant-ui/tree/HEAD/packages/react/issues/6">#6</a>...</li> <li><a href="https://github.com/assistant-ui/assistant-ui/commit/06b04a7976d10fac3af40ae9ca59b52385ef2ae2"><code>06b04a7</code></a> chore: update dependencies (<a href="https://github.com/assistant-ui/assistant-ui/tree/HEAD/packages/react/issues/6124">#6124</a>)</li> <li><a href="https://github.com/assistant-ui/assistant-ui/commit/b9b9dad28af0fc7c873d0b653830c0f1a78197ed"><code>b9b9dad</code></a> fix: drain smooth text when a message completes before an animation frame (<a href="https://github.com/assistant-ui/assistant-ui/tree/HEAD/packages/react/issues/6">#6</a>...</li> <li><a href="https://github.com/assistant-ui/assistant-ui/commit/10a0f3ade814aef47a327383fe50d59bd9d79538"><code>10a0f3a</code></a> test(react): vary live-completion fetcher and cacheKey independently (<a href="https://github.com/assistant-ui/assistant-ui/tree/HEAD/packages/react/issues/6062">#6062</a>)</li> <li><a href="https://github.com/assistant-ui/assistant-ui/commit/b355aefbe2403025562f0e08494a57450bfdc049"><code>b355aef</code></a> fix(core): prevent assistant frame origin downgrades (<a href="https://github.com/assistant-ui/assistant-ui/tree/HEAD/packages/react/issues/5823">#5823</a>)</li> <li><a href="https://github.com/assistant-ui/assistant-ui/commit/75dfbe3a2b7c3af61793fc1448e06d2d0063767a"><code>75dfbe3</code></a> docs(react): document Escape-to-stop-speaking on ThreadPrimitive.Root (<a href="https://github.com/assistant-ui/assistant-ui/tree/HEAD/packages/react/issues/6061">#6061</a>)</li> <li><a href="https://github.com/assistant-ui/assistant-ui/commit/ca9e72ce85a9164b11947f9b7a38fb5801f7d04e"><code>ca9e72c</code></a> fix(react): resync trigger cursor after selection (<a href="https://github.com/assistant-ui/assistant-ui/tree/HEAD/packages/react/issues/6082">#6082</a>) (<a href="https://github.com/assistant-ui/assistant-ui/tree/HEAD/packages/react/issues/6084">#6084</a>)</li> <li>Additional commits viewable in <a href="https://github.com/assistant-ui/assistant-ui/commits/@assistant-ui/react@0.15.16/packages/react">compare view</a></li> </ul> </details> <br /> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |
||
|
|
4fb0978578 |
build(deps): bump googleapis from 174.0.1 to 176.0.0 (#11889)
Bumps [googleapis](https://github.com/googleapis/google-api-nodejs-client) from 174.0.1 to 176.0.0. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/googleapis/google-api-nodejs-client/releases">googleapis's releases</a>.</em></p> <blockquote> <h2>googleapis: v176.0.0</h2> <h2><a href="https://github.com/googleapis/google-api-nodejs-client/compare/googleapis-v175.0.0...googleapis-v176.0.0">176.0.0</a> (2026-08-18)</h2> <h3>⚠ BREAKING CHANGES</h3> <ul> <li><strong>securityposture:</strong> This release has breaking changes.</li> <li><strong>compute:</strong> This release has breaking changes.</li> <li><strong>assuredworkloads:</strong> This release has breaking changes.</li> </ul> <h3>Features</h3> <ul> <li><strong>assuredworkloads:</strong> update the API (<a href="https://github.com/googleapis/google-api-nodejs-client/commit/4f787ecb10d2fcc0605045096ab472c8a3c848ce">4f787ec</a>)</li> <li><strong>bigqueryconnection:</strong> update the API (<a href="https://github.com/googleapis/google-api-nodejs-client/commit/19d67d7998bfd284eac66cbb2649df7479c3ecaa">19d67d7</a>)</li> <li><strong>bigquery:</strong> update the API (<a href="https://github.com/googleapis/google-api-nodejs-client/commit/5047629259ead4fb146cf95156bd8c28d5a0eb46">5047629</a>)</li> <li><strong>ces:</strong> update the API (<a href="https://github.com/googleapis/google-api-nodejs-client/commit/4d674e7e4efc6826072fe92f624378f9e03d0e34">4d674e7</a>)</li> <li><strong>compute:</strong> update the API (<a href="https://github.com/googleapis/google-api-nodejs-client/commit/88ee28ba7c20507de837c6335980f4aa239e5b4e">88ee28b</a>)</li> <li><strong>contactcenterinsights:</strong> update the API (<a href="https://github.com/googleapis/google-api-nodejs-client/commit/8987bcff71f26c6a511c92833049c0b7ad86469e">8987bcf</a>)</li> <li><strong>dialogflow:</strong> update the API (<a href="https://github.com/googleapis/google-api-nodejs-client/commit/cb090b72b2cae5d9b2053985b12237c51dd57ff7">cb090b7</a>)</li> <li><strong>discoveryengine:</strong> update the API (<a href="https://github.com/googleapis/google-api-nodejs-client/commit/c9a9b98cfcc0acedf8679fd3c791c74477c64654">c9a9b98</a>)</li> <li><strong>gkehub:</strong> update the API (<a href="https://github.com/googleapis/google-api-nodejs-client/commit/e7356ce9c0aa7240bd69688c544e4e3b3f81138a">e7356ce</a>)</li> <li><strong>looker:</strong> update the API (<a href="https://github.com/googleapis/google-api-nodejs-client/commit/ce6eba99279a866be197c7eaba9a8ea2e7f1eafa">ce6eba9</a>)</li> <li><strong>metastore:</strong> update the API (<a href="https://github.com/googleapis/google-api-nodejs-client/commit/266b861fd1a23ea8781f03ef252cf30dec2eb1f6">266b861</a>)</li> <li><strong>networkservices:</strong> update the API (<a href="https://github.com/googleapis/google-api-nodejs-client/commit/71b26e6c3734b967f4c228bb5cbc6658f0e8c42b">71b26e6</a>)</li> <li><strong>playdeveloperreporting:</strong> update the API (<a href="https://github.com/googleapis/google-api-nodejs-client/commit/b0d0c264919b34dc6c18179113ea4195375db638">b0d0c26</a>)</li> <li>regenerate index files (<a href="https://github.com/googleapis/google-api-nodejs-client/commit/0eb3a957cc14024a33be3910f970651aa7ba430b">0eb3a95</a>)</li> <li><strong>secretmanager:</strong> update the API (<a href="https://github.com/googleapis/google-api-nodejs-client/commit/333f48fa3afeb9daa9a506b77c7ddd9cdbed8fce">333f48f</a>)</li> <li><strong>securityposture:</strong> update the API (<a href="https://github.com/googleapis/google-api-nodejs-client/commit/868105393dbb9148f0cc827d5895c5effa51f372">8681053</a>)</li> <li><strong>storage:</strong> update the API (<a href="https://github.com/googleapis/google-api-nodejs-client/commit/9974109dd49839de0083621ed9ce133f6e1c37a8">9974109</a>)</li> <li><strong>webcontentpublisher:</strong> update the API (<a href="https://github.com/googleapis/google-api-nodejs-client/commit/7dc05fc5f268c8a7ca5d18429fde05b50a58b29c">7dc05fc</a>)</li> </ul> <h3>Bug Fixes</h3> <ul> <li><strong>datafusion:</strong> update the API (<a href="https://github.com/googleapis/google-api-nodejs-client/commit/2c691d571a3fdc8a93926fbfcbaa50273517756f">2c691d5</a>)</li> <li><strong>docs:</strong> run JSDoc once per documentation build (<a href="https://redirect.github.com/googleapis/google-api-nodejs-client/issues/3958">#3958</a>) (<a href="https://github.com/googleapis/google-api-nodejs-client/commit/5aaf111af860b22a55ed64da824e0444b119c007">5aaf111</a>)</li> <li><strong>redis:</strong> update the API (<a href="https://github.com/googleapis/google-api-nodejs-client/commit/c639065e6ab3019192384f71d95bc447fb176329">c639065</a>)</li> <li><strong>trafficdirector:</strong> update the API (<a href="https://github.com/googleapis/google-api-nodejs-client/commit/3331b0cd347a11ea9d8c774f61ee67029399ba73">3331b0c</a>)</li> <li><strong>workstations:</strong> update the API (<a href="https://github.com/googleapis/google-api-nodejs-client/commit/ee9521ce5cdb69590827c30c59e58f0f047fb70d">ee9521c</a>)</li> </ul> <h2>googleapis: v175.0.0</h2> <h2><a href="https://github.com/googleapis/google-api-nodejs-client/compare/googleapis-v174.0.1...googleapis-v175.0.0">175.0.0</a> (2026-08-14)</h2> <h3>⚠ BREAKING CHANGES</h3> <ul> <li><strong>merchantapi:</strong> This release has breaking changes.</li> <li><strong>discoveryengine:</strong> This release has breaking changes.</li> </ul> <h3>Features</h3> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/googleapis/google-api-nodejs-client/commit/a454f9bda019c742b835e5fd5077294ce85c7875"><code>a454f9b</code></a> chore: release main (<a href="https://redirect.github.com/googleapis/google-api-nodejs-client/issues/3976">#3976</a>)</li> <li><a href="https://github.com/googleapis/google-api-nodejs-client/commit/0eb3a957cc14024a33be3910f970651aa7ba430b"><code>0eb3a95</code></a> feat: regenerate index files</li> <li><a href="https://github.com/googleapis/google-api-nodejs-client/commit/ee9521ce5cdb69590827c30c59e58f0f047fb70d"><code>ee9521c</code></a> fix(workstations): update the API</li> <li><a href="https://github.com/googleapis/google-api-nodejs-client/commit/7dc05fc5f268c8a7ca5d18429fde05b50a58b29c"><code>7dc05fc</code></a> feat(webcontentpublisher): update the API</li> <li><a href="https://github.com/googleapis/google-api-nodejs-client/commit/3331b0cd347a11ea9d8c774f61ee67029399ba73"><code>3331b0c</code></a> fix(trafficdirector): update the API</li> <li><a href="https://github.com/googleapis/google-api-nodejs-client/commit/9974109dd49839de0083621ed9ce133f6e1c37a8"><code>9974109</code></a> feat(storage): update the API</li> <li><a href="https://github.com/googleapis/google-api-nodejs-client/commit/868105393dbb9148f0cc827d5895c5effa51f372"><code>8681053</code></a> feat(securityposture)!: update the API</li> <li><a href="https://github.com/googleapis/google-api-nodejs-client/commit/333f48fa3afeb9daa9a506b77c7ddd9cdbed8fce"><code>333f48f</code></a> feat(secretmanager): update the API</li> <li><a href="https://github.com/googleapis/google-api-nodejs-client/commit/c639065e6ab3019192384f71d95bc447fb176329"><code>c639065</code></a> fix(redis): update the API</li> <li><a href="https://github.com/googleapis/google-api-nodejs-client/commit/b0d0c264919b34dc6c18179113ea4195375db638"><code>b0d0c26</code></a> feat(playdeveloperreporting): update the API</li> <li>Additional commits viewable in <a href="https://github.com/googleapis/google-api-nodejs-client/compare/googleapis-v174.0.1...googleapis-v176.0.0">compare view</a></li> </ul> </details> <br /> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |
||
|
|
b67dced1bf |
build(deps): bump @agentclientprotocol/codex-acp from 1.2.0 to 1.6.2 (#11883)
Bumps [@agentclientprotocol/codex-acp](https://github.com/agentclientprotocol/codex-acp) from 1.2.0 to 1.6.2. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/agentclientprotocol/codex-acp/releases">@agentclientprotocol/codex-acp's releases</a>.</em></p> <blockquote> <h2>v1.6.2</h2> <h2><a href="https://github.com/agentclientprotocol/codex-acp/compare/v1.6.1...v1.6.2">1.6.2</a> (2026-08-19)</h2> <h3>Bug Fixes</h3> <ul> <li>right-size the apt timeouts so a slow mirror still finishes (<a href="https://github.com/agentclientprotocol/codex-acp/commit/86e0772204a07d6fc4a8853c523ceb5006431f88">86e0772</a>)</li> </ul> <h2>v1.6.1</h2> <h2><a href="https://github.com/agentclientprotocol/codex-acp/compare/v1.6.0...v1.6.1">1.6.1</a> (2026-08-19)</h2> <h3>Bug Fixes</h3> <ul> <li>kill stalled apt from outside and serialize the unit suite (<a href="https://github.com/agentclientprotocol/codex-acp/commit/51e011fef27b812b238bf29c2a815f8ad149fa87">51e011f</a>)</li> </ul> <h2>v1.6.0</h2> <h2><a href="https://github.com/agentclientprotocol/codex-acp/compare/v1.5.1...v1.6.0">1.6.0</a> (2026-08-19)</h2> <h3>Features</h3> <ul> <li>harden release pipeline against hangs and e2e flakes (<a href="https://redirect.github.com/agentclientprotocol/codex-acp/issues/413">#413</a>) (<a href="https://github.com/agentclientprotocol/codex-acp/commit/39af81c29b79a85f878db096f9cb593b6d1c7429">39af81c</a>)</li> </ul> <h2>v1.5.1</h2> <h2><a href="https://github.com/agentclientprotocol/codex-acp/compare/v1.5.0...v1.5.1">1.5.1</a> (2026-08-19)</h2> <h3>Bug Fixes</h3> <ul> <li>update codex to 0.148.0 (<a href="https://redirect.github.com/agentclientprotocol/codex-acp/issues/410">#410</a>) (<a href="https://github.com/agentclientprotocol/codex-acp/commit/3616954dc0e24af83b512adb618d7acbc5b98de5">3616954</a>)</li> </ul> <h2>v1.5.0</h2> <h2><a href="https://github.com/agentclientprotocol/codex-acp/compare/v1.4.0...v1.5.0">1.5.0</a> (2026-08-17)</h2> <h3>Features</h3> <ul> <li>switch providers for loaded Codex sessions (<a href="https://redirect.github.com/agentclientprotocol/codex-acp/issues/404">#404</a>) (<a href="https://github.com/agentclientprotocol/codex-acp/commit/47b57da5641a04df9aeeedc254a3aef53a9497da">47b57da</a>)</li> </ul> <h2>v1.4.0</h2> <h2><a href="https://github.com/agentclientprotocol/codex-acp/compare/v1.3.0...v1.4.0">1.4.0</a> (2026-08-16)</h2> <h3>Features</h3> <ul> <li>report changed files to AIR (<a href="https://redirect.github.com/agentclientprotocol/codex-acp/issues/403">#403</a>) (<a href="https://github.com/agentclientprotocol/codex-acp/commit/e305394d3f001f21e600597f41a3bee3d4530762">e305394</a>)</li> </ul> <h2>v1.3.0</h2> <h2><a href="https://github.com/agentclientprotocol/codex-acp/compare/v1.2.0...v1.3.0">1.3.0</a> (2026-08-14)</h2> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/agentclientprotocol/codex-acp/blob/main/CHANGELOG.md">@agentclientprotocol/codex-acp's changelog</a>.</em></p> <blockquote> <h2><a href="https://github.com/agentclientprotocol/codex-acp/compare/v1.6.1...v1.6.2">1.6.2</a> (2026-08-19)</h2> <h3>Bug Fixes</h3> <ul> <li>right-size the apt timeouts so a slow mirror still finishes (<a href="https://github.com/agentclientprotocol/codex-acp/commit/86e0772204a07d6fc4a8853c523ceb5006431f88">86e0772</a>)</li> </ul> <h2><a href="https://github.com/agentclientprotocol/codex-acp/compare/v1.6.0...v1.6.1">1.6.1</a> (2026-08-19)</h2> <h3>Bug Fixes</h3> <ul> <li>kill stalled apt from outside and serialize the unit suite (<a href="https://github.com/agentclientprotocol/codex-acp/commit/51e011fef27b812b238bf29c2a815f8ad149fa87">51e011f</a>)</li> </ul> <h2><a href="https://github.com/agentclientprotocol/codex-acp/compare/v1.5.1...v1.6.0">1.6.0</a> (2026-08-19)</h2> <h3>Features</h3> <ul> <li>harden release pipeline against hangs and e2e flakes (<a href="https://redirect.github.com/agentclientprotocol/codex-acp/issues/413">#413</a>) (<a href="https://github.com/agentclientprotocol/codex-acp/commit/39af81c29b79a85f878db096f9cb593b6d1c7429">39af81c</a>)</li> </ul> <h2><a href="https://github.com/agentclientprotocol/codex-acp/compare/v1.5.0...v1.5.1">1.5.1</a> (2026-08-19)</h2> <h3>Bug Fixes</h3> <ul> <li>update codex to 0.148.0 (<a href="https://redirect.github.com/agentclientprotocol/codex-acp/issues/410">#410</a>) (<a href="https://github.com/agentclientprotocol/codex-acp/commit/3616954dc0e24af83b512adb618d7acbc5b98de5">3616954</a>)</li> </ul> <h2><a href="https://github.com/agentclientprotocol/codex-acp/compare/v1.4.0...v1.5.0">1.5.0</a> (2026-08-17)</h2> <h3>Features</h3> <ul> <li>switch providers for loaded Codex sessions (<a href="https://redirect.github.com/agentclientprotocol/codex-acp/issues/404">#404</a>) (<a href="https://github.com/agentclientprotocol/codex-acp/commit/47b57da5641a04df9aeeedc254a3aef53a9497da">47b57da</a>)</li> </ul> <h2><a href="https://github.com/agentclientprotocol/codex-acp/compare/v1.3.0...v1.4.0">1.4.0</a> (2026-08-16)</h2> <h3>Features</h3> <ul> <li>report changed files to AIR (<a href="https://redirect.github.com/agentclientprotocol/codex-acp/issues/403">#403</a>) (<a href="https://github.com/agentclientprotocol/codex-acp/commit/e305394d3f001f21e600597f41a3bee3d4530762">e305394</a>)</li> </ul> <h2><a href="https://github.com/agentclientprotocol/codex-acp/compare/v1.2.0...v1.3.0">1.3.0</a> (2026-08-14)</h2> <h3>Features</h3> <ul> <li>add versioned context compaction metadata (<a href="https://redirect.github.com/agentclientprotocol/codex-acp/issues/396">#396</a>) (<a href="https://github.com/agentclientprotocol/codex-acp/commit/c4a9311f60a638e3a4b03a475afff1d7678e594f">c4a9311</a>)</li> <li>align typed session failures with AIR protocol (<a href="https://redirect.github.com/agentclientprotocol/codex-acp/issues/393">#393</a>) (<a href="https://github.com/agentclientprotocol/codex-acp/commit/e4fb92fffd8b8b9db9b40591ccbdb375c9f3f525">e4fb92f</a>)</li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/agentclientprotocol/codex-acp/commit/9780d314d34616b476b1ae451ad31089b3dce49a"><code>9780d31</code></a> chore(main): release 1.6.2 (<a href="https://redirect.github.com/agentclientprotocol/codex-acp/issues/417">#417</a>)</li> <li><a href="https://github.com/agentclientprotocol/codex-acp/commit/86e0772204a07d6fc4a8853c523ceb5006431f88"><code>86e0772</code></a> fix: right-size the apt timeouts so a slow mirror still finishes</li> <li><a href="https://github.com/agentclientprotocol/codex-acp/commit/096f5a88501db50c4420726e84c39f60f08c457f"><code>096f5a8</code></a> chore(main): release 1.6.1 (<a href="https://redirect.github.com/agentclientprotocol/codex-acp/issues/416">#416</a>)</li> <li><a href="https://github.com/agentclientprotocol/codex-acp/commit/51e011fef27b812b238bf29c2a815f8ad149fa87"><code>51e011f</code></a> fix: kill stalled apt from outside and serialize the unit suite</li> <li><a href="https://github.com/agentclientprotocol/codex-acp/commit/50bd611451c02868cc2b50bd6a7fc61ae5ef9b41"><code>50bd611</code></a> chore(main): release 1.6.0 (<a href="https://redirect.github.com/agentclientprotocol/codex-acp/issues/414">#414</a>)</li> <li><a href="https://github.com/agentclientprotocol/codex-acp/commit/39af81c29b79a85f878db096f9cb593b6d1c7429"><code>39af81c</code></a> feat: harden release pipeline against hangs and e2e flakes (<a href="https://redirect.github.com/agentclientprotocol/codex-acp/issues/413">#413</a>)</li> <li><a href="https://github.com/agentclientprotocol/codex-acp/commit/ad658e6ec64e8b70c455b10457ccc34f77173c9b"><code>ad658e6</code></a> chore(main): release 1.5.1 (<a href="https://redirect.github.com/agentclientprotocol/codex-acp/issues/412">#412</a>)</li> <li><a href="https://github.com/agentclientprotocol/codex-acp/commit/3616954dc0e24af83b512adb618d7acbc5b98de5"><code>3616954</code></a> fix: update codex to 0.148.0 (<a href="https://redirect.github.com/agentclientprotocol/codex-acp/issues/410">#410</a>)</li> <li><a href="https://github.com/agentclientprotocol/codex-acp/commit/3d5682722545a4b2d7cfcf8bdabbbfadbdaa37ea"><code>3d56827</code></a> chore(main): release 1.5.0 (<a href="https://redirect.github.com/agentclientprotocol/codex-acp/issues/409">#409</a>)</li> <li><a href="https://github.com/agentclientprotocol/codex-acp/commit/47b57da5641a04df9aeeedc254a3aef53a9497da"><code>47b57da</code></a> feat: switch providers for loaded Codex sessions (<a href="https://redirect.github.com/agentclientprotocol/codex-acp/issues/404">#404</a>)</li> <li>Additional commits viewable in <a href="https://github.com/agentclientprotocol/codex-acp/compare/v1.2.0...v1.6.2">compare view</a></li> </ul> </details> <br /> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |
||
|
|
b858fc7248 |
build(deps): bump @codemirror/view from 6.43.8 to 6.43.9 (#11879)
Bumps [@codemirror/view](https://github.com/codemirror/view) from 6.43.8 to 6.43.9. <details> <summary>Commits</summary> <ul> <li>See full diff in <a href="https://github.com/codemirror/view/commits">compare view</a></li> </ul> </details> <br /> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |
||
|
|
30f9888d3f |
build(deps-dev): bump storybook from 10.5.5 to 10.5.10 (#11884)
Bumps [storybook](https://github.com/storybookjs/storybook/tree/HEAD/code/core) from 10.5.5 to 10.5.10. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/storybookjs/storybook/releases">storybook's releases</a>.</em></p> <blockquote> <h2>v10.5.10</h2> <h2>10.5.10</h2> <ul> <li>Core: Fetch static open-service snapshots relative to the document - <a href="https://redirect.github.com/storybookjs/storybook/pull/35945">#35945</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Core: Pin oxc-resolver to 11.21.2 to keep tsconfig path aliases on solution-style tsconfigs - <a href="https://redirect.github.com/storybookjs/storybook/pull/35929">#35929</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Dependencies: Bump Vitest to 4.1.6 (CVE-2026-47428) - <a href="https://redirect.github.com/storybookjs/storybook/pull/35530">#35530</a>, thanks <a href="https://github.com/anupamme"><code>@anupamme</code></a>!</li> <li>Docs: Declare the font on overlay surfaces so docs tooltips are not left to inherit - <a href="https://redirect.github.com/storybookjs/storybook/pull/35966">#35966</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>ESLint Plugin: Bundle CSF helpers so the plugin loads without storybook - <a href="https://redirect.github.com/storybookjs/storybook/pull/35950">#35950</a>, thanks <a href="https://github.com/ndelangen"><code>@ndelangen</code></a>!</li> <li>React: Preserve discriminated union prop values in metadata extraction - <a href="https://redirect.github.com/storybookjs/storybook/pull/35844">#35844</a>, thanks <a href="https://github.com/s-robertson"><code>@s-robertson</code></a>!</li> </ul> <h2>v10.5.9</h2> <h2>10.5.9</h2> <ul> <li>Addon-Pseudo-States: Fix pseudo-states rewriting for nested functional selectors - <a href="https://redirect.github.com/storybookjs/storybook/pull/34318">#34318</a>, thanks <a href="https://github.com/filipw01"><code>@filipw01</code></a>!</li> <li>Core: Skip module-graph reverse-index mirror when a patch is a no-op - <a href="https://redirect.github.com/storybookjs/storybook/pull/35825">#35825</a>, thanks <a href="https://github.com/ndelangen"><code>@ndelangen</code></a>!</li> <li>Core: Split module-graph into hot revisions and cold index services - <a href="https://redirect.github.com/storybookjs/storybook/pull/35831">#35831</a>, thanks <a href="https://github.com/ndelangen"><code>@ndelangen</code></a>!</li> <li>Preview: Fix crash when initialising UrlStore on a docs path - <a href="https://redirect.github.com/storybookjs/storybook/pull/35521">#35521</a>, thanks <a href="https://github.com/TheSeydiCharyyev"><code>@TheSeydiCharyyev</code></a>!</li> <li>Pseudo-States: Make stylesheet rewrites WebKit-safe - <a href="https://redirect.github.com/storybookjs/storybook/pull/35629">#35629</a>, thanks <a href="https://github.com/ethriel3695"><code>@ethriel3695</code></a>!</li> <li>TanStack: Keep the layout id when cloning a standalone index file route - <a href="https://redirect.github.com/storybookjs/storybook/pull/35660">#35660</a>, thanks <a href="https://github.com/Insik-Han"><code>@Insik-Han</code></a>!</li> <li>TanStack: Render real link hrefs in the Link mock - <a href="https://redirect.github.com/storybookjs/storybook/pull/35505">#35505</a>, thanks <a href="https://github.com/unpunnyfuns"><code>@unpunnyfuns</code></a>!</li> <li>Webpack: Prevent long preview output filenames - <a href="https://redirect.github.com/storybookjs/storybook/pull/35533">#35533</a>, thanks <a href="https://github.com/zhangli091011"><code>@zhangli091011</code></a>!</li> </ul> <h2>v10.5.8</h2> <h2>10.5.8</h2> <ul> <li>React: Fix RDT tsconfig selection for Vite project references - <a href="https://redirect.github.com/storybookjs/storybook/pull/35743">#35743</a>, thanks <a href="https://github.com/ndelangen"><code>@ndelangen</code></a>!</li> <li>Tanstack React: Remove <code>@cloudflare/vite-plugin</code> from the inherited Vite config - <a href="https://redirect.github.com/storybookjs/storybook/pull/35706">#35706</a>, thanks <a href="https://github.com/FrancoKaddour"><code>@FrancoKaddour</code></a>!</li> <li>Tanstack: Wait for router to load before rendering - <a href="https://redirect.github.com/storybookjs/storybook/pull/35784">#35784</a>, thanks <a href="https://github.com/huang-julien"><code>@huang-julien</code></a>!</li> <li>Test: Fix Illegal invocation when reading prototype.focus - <a href="https://redirect.github.com/storybookjs/storybook/pull/35528">#35528</a>, thanks <a href="https://github.com/FrancoKaddour"><code>@FrancoKaddour</code></a>!</li> </ul> <h2>v10.5.7</h2> <h2>10.5.7</h2> <ul> <li>Angular: Serve ancestor node_modules for addon-vitest in browser mode - <a href="https://redirect.github.com/storybookjs/storybook/pull/35600">#35600</a>, thanks <a href="https://github.com/brandonroberts"><code>@brandonroberts</code></a>!</li> <li>Refactor: Update getVersionedPackages method to handle non-Storybook packages correctly - <a href="https://redirect.github.com/storybookjs/storybook/pull/35769">#35769</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> </ul> <h2>v10.5.6</h2> <h2>10.5.6</h2> <ul> <li>Dependencies: Pin `@testing-library/jest-dom` to `6.9.1` - <a href="https://redirect.github.com/storybookjs/storybook/pull/35614">#35614</a>, thanks <a href="https://github.com/ndelangen"><code>@ndelangen</code></a>!</li> <li>ESLint Plugin: Add plugin meta and document oxlint usage - <a href="https://redirect.github.com/storybookjs/storybook/pull/35655">#35655</a>, thanks <a href="https://github.com/yannbf"><code>@yannbf</code></a>!</li> <li>Vue: Skip docgen for module ids carrying a query - <a href="https://redirect.github.com/storybookjs/storybook/pull/35598">#35598</a>, thanks <a href="https://github.com/seanogdev"><code>@seanogdev</code></a>!</li> </ul> </blockquote> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/storybookjs/storybook/blob/next/CHANGELOG.md">storybook's changelog</a>.</em></p> <blockquote> <h2>10.5.10</h2> <ul> <li>Core: Fetch static open-service snapshots relative to the document - <a href="https://redirect.github.com/storybookjs/storybook/pull/35945">#35945</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Core: Pin oxc-resolver to 11.21.2 to keep tsconfig path aliases on solution-style tsconfigs - <a href="https://redirect.github.com/storybookjs/storybook/pull/35929">#35929</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>Dependencies: Bump Vitest to 4.1.6 (CVE-2026-47428) - <a href="https://redirect.github.com/storybookjs/storybook/pull/35530">#35530</a>, thanks <a href="https://github.com/anupamme"><code>@anupamme</code></a>!</li> <li>Docs: Declare the font on overlay surfaces so docs tooltips are not left to inherit - <a href="https://redirect.github.com/storybookjs/storybook/pull/35966">#35966</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> <li>ESLint Plugin: Bundle CSF helpers so the plugin loads without storybook - <a href="https://redirect.github.com/storybookjs/storybook/pull/35950">#35950</a>, thanks <a href="https://github.com/ndelangen"><code>@ndelangen</code></a>!</li> <li>React: Preserve discriminated union prop values in metadata extraction - <a href="https://redirect.github.com/storybookjs/storybook/pull/35844">#35844</a>, thanks <a href="https://github.com/s-robertson"><code>@s-robertson</code></a>!</li> </ul> <h2>10.5.9</h2> <ul> <li>Addon-Pseudo-States: Fix pseudo-states rewriting for nested functional selectors - <a href="https://redirect.github.com/storybookjs/storybook/pull/34318">#34318</a>, thanks <a href="https://github.com/filipw01"><code>@filipw01</code></a>!</li> <li>Core: Skip module-graph reverse-index mirror when a patch is a no-op - <a href="https://redirect.github.com/storybookjs/storybook/pull/35825">#35825</a>, thanks <a href="https://github.com/ndelangen"><code>@ndelangen</code></a>!</li> <li>Core: Split module-graph into hot revisions and cold index services - <a href="https://redirect.github.com/storybookjs/storybook/pull/35831">#35831</a>, thanks <a href="https://github.com/ndelangen"><code>@ndelangen</code></a>!</li> <li>Preview: Fix crash when initialising UrlStore on a docs path - <a href="https://redirect.github.com/storybookjs/storybook/pull/35521">#35521</a>, thanks <a href="https://github.com/TheSeydiCharyyev"><code>@TheSeydiCharyyev</code></a>!</li> <li>Pseudo-States: Make stylesheet rewrites WebKit-safe - <a href="https://redirect.github.com/storybookjs/storybook/pull/35629">#35629</a>, thanks <a href="https://github.com/ethriel3695"><code>@ethriel3695</code></a>!</li> <li>TanStack: Keep the layout id when cloning a standalone index file route - <a href="https://redirect.github.com/storybookjs/storybook/pull/35660">#35660</a>, thanks <a href="https://github.com/Insik-Han"><code>@Insik-Han</code></a>!</li> <li>TanStack: Render real link hrefs in the Link mock - <a href="https://redirect.github.com/storybookjs/storybook/pull/35505">#35505</a>, thanks <a href="https://github.com/unpunnyfuns"><code>@unpunnyfuns</code></a>!</li> <li>Webpack: Prevent long preview output filenames - <a href="https://redirect.github.com/storybookjs/storybook/pull/35533">#35533</a>, thanks <a href="https://github.com/zhangli091011"><code>@zhangli091011</code></a>!</li> </ul> <h2>10.5.8</h2> <ul> <li>React: Fix RDT tsconfig selection for Vite project references - <a href="https://redirect.github.com/storybookjs/storybook/pull/35743">#35743</a>, thanks <a href="https://github.com/ndelangen"><code>@ndelangen</code></a>!</li> <li>Tanstack React: Remove <code>@cloudflare/vite-plugin</code> from the inherited Vite config - <a href="https://redirect.github.com/storybookjs/storybook/pull/35706">#35706</a>, thanks <a href="https://github.com/FrancoKaddour"><code>@FrancoKaddour</code></a>!</li> <li>Tanstack: Wait for router to load before rendering - <a href="https://redirect.github.com/storybookjs/storybook/pull/35784">#35784</a>, thanks <a href="https://github.com/huang-julien"><code>@huang-julien</code></a>!</li> <li>Test: Fix Illegal invocation when reading prototype.focus - <a href="https://redirect.github.com/storybookjs/storybook/pull/35528">#35528</a>, thanks <a href="https://github.com/FrancoKaddour"><code>@FrancoKaddour</code></a>!</li> </ul> <h2>10.5.7</h2> <ul> <li>Angular: Serve ancestor node_modules for addon-vitest in browser mode - <a href="https://redirect.github.com/storybookjs/storybook/pull/35600">#35600</a>, thanks <a href="https://github.com/brandonroberts"><code>@brandonroberts</code></a>!</li> <li>Refactor: Update getVersionedPackages method to handle non-Storybook packages correctly - <a href="https://redirect.github.com/storybookjs/storybook/pull/35769">#35769</a>, thanks <a href="https://github.com/valentinpalkovic"><code>@valentinpalkovic</code></a>!</li> </ul> <h2>10.5.6</h2> <ul> <li>Dependencies: Pin <code>@testing-library/jest-dom</code> to <code>6.9.1</code> - <a href="https://redirect.github.com/storybookjs/storybook/pull/35614">#35614</a>, thanks <a href="https://github.com/ndelangen"><code>@ndelangen</code></a>!</li> <li>ESLint Plugin: Add plugin meta and document oxlint usage - <a href="https://redirect.github.com/storybookjs/storybook/pull/35655">#35655</a>, thanks <a href="https://github.com/yannbf"><code>@yannbf</code></a>!</li> <li>Vue: Skip docgen for module ids carrying a query - <a href="https://redirect.github.com/storybookjs/storybook/pull/35598">#35598</a>, thanks <a href="https://github.com/seanogdev"><code>@seanogdev</code></a>!</li> </ul> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/storybookjs/storybook/commit/a2db7526e1538a48bfa0529a881822e8074b2009"><code>a2db752</code></a> Bump version from "10.5.9" to "10.5.10" [skip ci]</li> <li><a href="https://github.com/storybookjs/storybook/commit/de77b083828f955353342f949a2ce9aa2e68ff94"><code>de77b08</code></a> Merge pull request <a href="https://github.com/storybookjs/storybook/tree/HEAD/code/core/issues/35929">#35929</a> from storybookjs/valentin/sb-1821-pin-oxc-resolver</li> <li><a href="https://github.com/storybookjs/storybook/commit/374b8b345112e221df9b82f978afff42d7c6da0c"><code>374b8b3</code></a> Merge pull request <a href="https://github.com/storybookjs/storybook/tree/HEAD/code/core/issues/35966">#35966</a> from storybookjs/valentin/docs-overlay-typography</li> <li><a href="https://github.com/storybookjs/storybook/commit/2148cdd5afa2ad069c4f8ec999f4234df64a69ca"><code>2148cdd</code></a> Merge pull request <a href="https://github.com/storybookjs/storybook/tree/HEAD/code/core/issues/35950">#35950</a> from storybookjs/fix/eslint-plugin-bundle-csf</li> <li><a href="https://github.com/storybookjs/storybook/commit/b336e8f5c12e7f0cd72e02e52ad025269f42653c"><code>b336e8f</code></a> Merge pull request <a href="https://github.com/storybookjs/storybook/tree/HEAD/code/core/issues/35945">#35945</a> from storybookjs/valentin/static-services-subpath-f...</li> <li><a href="https://github.com/storybookjs/storybook/commit/8f561048949b3ce3674a71711942177a14e4e8f9"><code>8f56104</code></a> Bump version from "10.5.8" to "10.5.9" [skip ci]</li> <li><a href="https://github.com/storybookjs/storybook/commit/f31554b81e167897a4d017930508ec977f31f092"><code>f31554b</code></a> Backport the module-graph hot/cold split and no-op index skip to 10.5.9.</li> <li><a href="https://github.com/storybookjs/storybook/commit/c1db83aae8bea708d718e84f4ef63e6ac53a3a46"><code>c1db83a</code></a> Merge pull request <a href="https://github.com/storybookjs/storybook/tree/HEAD/code/core/issues/35521">#35521</a> from TheSeydiCharyyev/fix/35436-urlstore-docs-path</li> <li><a href="https://github.com/storybookjs/storybook/commit/6ef7d1ae816ebd5fb8bf84b8dec7d4a92410d73c"><code>6ef7d1a</code></a> Bump version from "10.5.7" to "10.5.8" [skip ci]</li> <li><a href="https://github.com/storybookjs/storybook/commit/647e982151f1bb4e15163b0d2a31c5a1022efda3"><code>647e982</code></a> Merge pull request <a href="https://github.com/storybookjs/storybook/tree/HEAD/code/core/issues/35743">#35743</a> from storybookjs/norbert/revive-34415-file-aware-ts...</li> <li>Additional commits viewable in <a href="https://github.com/storybookjs/storybook/commits/v10.5.10/code/core">compare view</a></li> </ul> </details> <br /> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>canary/v2026.825.0-canary.10 |
||
|
|
2862e18484 |
refactor(adapter-utils): remove the retired duplex_v1 sandbox bridge transport (#12171)
## Thinking Path > - Paperclip is the open source app people use to manage AI agents for work > - The adapter utilities provide sandbox transport paths for agent execution > - The retired `duplex_v1` path remains in host, gateway, and test code after `http2_v1` replaced it > - Retired transport code adds maintenance cost and leaves an unsafe fallback for unknown gateway modes > - This pull request removes the retired path, moves shared `http2_v1` contracts to a leaf module, and closes mode dispatch to a fixed allowlist > - The benefit is a smaller transport surface and explicit failure for unsupported modes ## Linked Issues or Issue Description Refs #12120 The `http2_v1` transport replaced `duplex_v1`, but the retired broker, gateway, constants, and tests remain in the adapter utilities. An unknown bridge mode can also fall through to the queue gateway when a queue directory exists. This change removes the retired code and rejects unsupported modes before gateway selection. ## What Changed - Delete the host `duplex_v1` broker and its transport-only tests. - Delete the in-sandbox duplex gateway and retired mode constants. - Move shared `http2_v1` symbols into `bridge-transport-contract.ts`. - Update the remaining importers and repair their focused tests. - Validate bridge modes against `http2_v1` and `queue_v1` before queue lookup. - Keep `queue_v1`, `duplex-frame-codec.ts`, and duplex telemetry dimensions unchanged. ## Verification - [x] `npx tsc --noEmit -p packages/adapter-utils` passes. - [x] `npx vitest run packages/adapter-utils/src` passes: 48 files and 968 tests pass, with 4 pre-existing platform skips. - [x] Full CI is green on this pull request. - [x] Greptile review is complete and every finding is resolved. ## Risks The change removes an internal transport that no host path selects. The main risk is an overlooked import or test dependency. Targeted typecheck and tests cover the adapter utility package. Full CI must confirm workspace-wide compatibility. ## Model Used Anthropic Claude Sonnet 5 assisted with the implementation, as recorded in the commit. The commit does not record a context-window size or reasoning mode. ## Checklist - [x] I have included a thinking path that traces from project context to this change - [x] I have specified the model used (with version and capability details) - [x] I have checked ROADMAP.md and confirmed this PR does not duplicate planned core work - [x] I have searched GitHub for duplicate or related PRs and linked them above - [x] I have either (a) linked existing issues with `Fixes: #` / `Closes #` / `Refs #` OR (b) described the issue in-PR following the relevant issue template - [x] I have not referenced internal/instance-local Paperclip issues or links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip` URLs) - [x] My branch name describes the change (e.g. `docs/...`, `fix/...`) and contains no internal Paperclip ticket id or instance-derived details - [x] I have run tests locally and they pass - [x] I have added or updated tests where applicable - [x] I have updated relevant documentation to reflect my changes - [x] I have considered and documented any risks above - [x] All Paperclip CI gates are green - [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups - [x] I will address all Greptile and reviewer comments before requesting merge Co-authored-by: Paperclip <noreply@paperclip.ing>canary/v2026.825.0-canary.9 |
||
|
|
02a984068c |
refactor(adapter-utils): clean up the HTTP/2 bridge request-body bounds (#12166)
## Thinking Path > - Paperclip is the open source app people use to manage AI agents for work > - Agent adapters use the HTTP/2 bridge to carry requests and responses > - The bridge has an idle bound and a total-lifetime ceiling for request bodies > - The old renewable lifetime bound re-armed with each DATA chunk and could not act before the idle bound > - The code also repeated the same bounds and rationale in several places > - This pull request removes the unreachable renewable bound, keeps the one-shot ceiling, and simplifies the shared bounds object > - The benefit is clearer protection logic with the same default request-body behavior ## Linked Issues or Issue Description **What existing behavior does this improve?** The HTTP/2 bridge request-body reader uses several repeated bound parameters and comments. One renewable lifetime bound cannot act before the idle bound under the shipped defaults. **Subsystem affected** `packages/adapter-utils/` — HTTP/2 bridge adapter utilities. **Current behavior** The idle bound and renewable lifetime bound both re-arm after each DATA chunk. The renewable bound therefore does not act on its own. The total-lifetime ceiling also shares timer setup with the renewable bound. **Proposed behavior** Remove the renewable lifetime bound. Keep the total-lifetime ceiling as an independent one-shot timer. Pass one bounds object to the bridge call sites and keep tests for the idle bound and total-lifetime ceiling. **Reason and benefit** The change removes unreachable logic and repeated rationale. It keeps the independent total-lifetime protection and makes the bound behavior easier to review. **Breaking changes** The change removes two public constant and option names that repository-wide search found unused outside this implementation. The shipped default behavior does not change. ## What Changed - Remove the renewable request-body lifetime bound and its public names. - Keep the total-lifetime ceiling as a one-shot timer that starts when the body read starts. - Replace repeated bound parameters with one `Http2BridgeBodyBounds` object. - De-duplicate bound rationale comments. - Add shared test helpers and update tests for the idle bound and total-lifetime ceiling. ## Verification - Run `npx tsc --noEmit -p packages/adapter-utils`. - Run `npx vitest run packages/adapter-utils/src/http2-bridge-server.test.ts`. - Wait for the pull request CI checks. - Request the Greptile review and confirm a 5/5 verdict with no open findings. ## Risks The main risk is an incorrect timer lifetime after the renewable timer removal. The one-shot ceiling remains independent, and the updated tests cover its expiry and cleanup paths. The change does not alter the shipped default bounds. ## Model Used OpenAI Codex based on GPT-5. Exact runtime model version is GPT-5. The work used tool calls and code execution for repository inspection and GitHub operations. ## Checklist - [x] I have included a thinking path that traces from project context to this change - [x] I have specified the model used (with version and capability details) - [x] I have checked ROADMAP.md and confirmed this PR does not duplicate planned core work - [x] I have searched GitHub for duplicate or related PRs and linked them above - [x] I have either (a) linked existing issues with `Fixes: #` / `Closes #` / `Refs #` OR (b) described the issue in-PR following the relevant issue template - [x] I have not referenced internal/instance-local Paperclip issues or links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip` URLs) - [x] My branch name describes the change (e.g. `docs/...`, `fix/...`) and contains no internal Paperclip ticket id or instance-derived details - [x] I have run tests locally and they pass - [x] I have added or updated tests where applicable - [x] I have updated relevant documentation to reflect my changes - [x] I have considered and documented any risks above - [x] All Paperclip CI gates are green - [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups - [x] I will address all Greptile and reviewer comments before requesting merge Co-authored-by: Paperclip <noreply@paperclip.ing>canary/v2026.825.0-canary.8 |
||
|
|
445547c989 |
feat(duplex): run the Daytona sandbox callback bridge over Node HTTP/2 (#12120)
## Thinking Path > - Paperclip is the open source app people use to manage AI agents for work > - Sandbox providers carry agent work through controlled execution channels > - The Daytona callback bridge uses a bespoke line-framed protocol over its duplex channel > - The bespoke protocol adds framing work and does not use the Node transport that already supports multiplexed streams > - This pull request carries raw bytes across the channel, adds a Node HTTP/2 bridge, and selects it for Daytona > - The benefit is one authenticated, multiplexed callback session with queue_v1 as the bounded fallback ## Linked Issues or Issue Description **Subsystem affected** The packages/plugins Daytona provider and the shared duplex execution path. **Problem or motivation** The Daytona callback bridge uses a bespoke line-framed protocol over the provider duplex channel. This adds protocol work and limits stream handling. **Proposed solution** Carry raw bytes through the cross-layer channel. Add an authenticated Node HTTP/2 host server and sandbox client gateway. Select http2_v1 for Daytona and retain queue_v1 as the fallback. **Alternatives considered** Keep the current duplex_v1 protocol. This keeps the bespoke framing path and does not provide one HTTP/2 session for callback streams. **Roadmap alignment** ROADMAP.md lists Daytona under cloud and sandbox agents. This change improves the shipped Daytona provider path. **Additional context** The branch adds no dependency. Node 24 provides the http2 module. The host token check and canonical path parser remain the single dispatch path. ## What Changed - Carry raw Uint8Array chunks through the adapter, plugin, worker, runtime, and Daytona layers. - Encode bytes as base64 only across the JSON-RPC hop, because JSON has no binary type. - Add the bounded host HTTP/2 server and the in-sandbox HTTP/2 client gateway. - Authenticate every stream with the per-run bridge token before route work. - Parse the path once and reuse the canonical result for route and forwarding work. - Select http2_v1 for Daytona and fall back once to queue_v1 when the client preface is absent. - Add transport, session, stream, and fallback telemetry. - Mark HTTP/2 as the preferred transport and queue_v1 as the soft-deprecated fallback. ## Verification - `npx vitest run packages/adapter-utils/src` — 990 passed and 4 skipped. - `npx vitest run server/src/__tests__/plugin-worker-manager-duplex.test.ts` — 32 passed. - `npx vitest run --config packages/plugins/sandbox-providers/daytona/vitest.config.ts` — 220 passed and 6 skipped. - `npx tsc --noEmit` in `packages/adapter-utils`, `packages/shared`, `packages/plugins/sdk`, and `server` — clean. - No `package.json` or `pnpm-lock.yaml` file changed. - The live Daytona test skips when `DAYTONA_API_KEY` is absent. - The root `npx tsc --noEmit` command has a pre-existing missing `packages/adapters/droid-local` reference on this branch and on `master`. ## Risks - The transport change affects several duplex layers and could expose byte-boundary errors. - A missing HTTP/2 client preface falls back once to queue_v1 and records `preface_missing`. - The host token check and canonical path parser must remain on the shared dispatch path. - The live Daytona test needs `DAYTONA_API_KEY` and does not run in this agent sandbox. ## Model Used OpenAI GPT-5, tool-enabled coding agent with repository inspection, GitHub CLI, and shell execution. ## Checklist - [x] I have included a thinking path that traces from project context to this change - [x] I have specified the model used (with version and capability details) - [x] I have checked ROADMAP.md and confirmed this PR does not duplicate planned core work - [x] I have searched GitHub for duplicate or related PRs and linked them above - [x] I have either (a) linked existing issues with `Fixes: #` / `Closes #` / `Refs #` OR (b) described the issue in-PR following the relevant issue template - [x] I have not referenced internal/instance-local Paperclip issues or links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip` URLs) - [x] My branch name describes the change (e.g. `docs/...`, `fix/...`) and contains no internal Paperclip ticket id or instance-derived details - [x] I have run tests locally and they pass - [x] I have added or updated tests where applicable - [x] I have updated relevant documentation to reflect my changes - [x] I have considered and documented any risks above - [x] All Paperclip CI gates are green - [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups - [x] I will address all Greptile and reviewer comments before requesting merge --------- Co-authored-by: Paperclip <noreply@paperclip.ing>canary/v2026.825.0-canary.7 |
||
|
|
0f0e544317 |
fix(cli): open dashboard after onboarding service starts (#12164)
## Thinking Path > - Paperclip is the open source app people use to manage AI agents for work. > - The CLI can install and start Paperclip as a managed user service during onboarding. > - Recent fixes now install the service shim and remove the redundant foreground start prompt. > - The service path still ends without a dashboard URL or an open browser. > - The server can also move to a free port when the configured port is busy. > - This pull request adds a health-aware handoff to the managed service's actual endpoint. > - The benefit is that new users can reach Paperclip without starting a second process. ## Linked Issues or Issue Description **What happened?** After interactive onboarding installs and starts the managed service, the command ends without printing the dashboard URL or opening the browser. If the configured port is busy, the service can use a fallback port that the onboarding process does not know. **Expected behavior** Onboarding must print the dashboard URL that belongs to the managed service. An interactive terminal should open the URL after the local health check succeeds. A non-interactive terminal should only print the URL. **Steps to reproduce** 1. Start from a host without an installed Paperclip service. 2. Run another process on the configured Paperclip port. 3. Run `npx paperclipai@<version> onboard` in an interactive terminal. 4. Accept the managed service installation. 5. Observe that the service starts on a fallback port, but onboarding does not provide or open that dashboard URL. **Paperclip version or commit** `b6854e61c` on `master`, after #12148, #12151, and #12153. **Deployment mode** Local managed user service on macOS or Linux. **Installation method** `npx paperclipai@<version> onboard`. The same onboarding path can also run after `install.sh`. Related public pull requests: #12148, #12151, and #12153. ## What Changed - Record each running CLI server's PID, selected port, and dashboard URL in atomic per-instance runtime metadata. - Accept runtime metadata only when its PID matches the active managed service. - Wait for the selected runtime endpoint to report healthy before printing its URL. - Open the URL in interactive terminals and keep headless runs browser-free. - Keep the printed configured URL as a fallback when runtime discovery fails. - Use browser-launch wording that only claims the URL was sent to the opener. - Add runtime metadata, fallback-port, health handoff, headless, and failure-path tests. - Document the managed service dashboard handoff. ## Verification - `pnpm exec vitest run cli/src/__tests__/onboard-service.test.ts cli/src/__tests__/runtime-info.test.ts cli/src/__tests__/onboard.test.ts cli/src/__tests__/open-url.test.ts cli/src/__tests__/service-health-check.test.ts` — 44 tests passed. - `node --test scripts/service-onboard-smoke.test.mjs` — 4 tests passed. - `pnpm -r typecheck` — passed on head `82920596a`. - `pnpm build` — passed on head `82920596a`. - `pnpm test:run` — 4,685 tests passed. The command also reported 31 failures in nine server test files outside this change. This machine generated invalid test ports above 65,535, and some project-skill fixtures resolved outside the worktree. ## Risks - Risk is low because the new handoff runs only after a successful service installation. - Onboarding can wait up to 60 seconds when runtime metadata or the health check does not become ready. - Runtime metadata is matched to the supervisor PID, so stale or foreground-process metadata is ignored. - A non-interactive terminal does not open a browser. - A failed health check or browser launch does not fail onboarding. The CLI keeps a manual URL visible. > For core feature work, check [`ROADMAP.md`](ROADMAP.md) first and discuss it in `#dev` before opening the PR. Feature PRs that overlap with planned core work may need to be redirected — check the roadmap first. See `CONTRIBUTING.md`. ## Model Used OpenAI Codex, GPT-5 family. The runtime did not expose the exact model ID or context window. The model used reasoning, repository tools, GitHub access, and code execution. ## Checklist - [x] I have included a thinking path that traces from project context to this change - [x] I have specified the model used (with version and capability details) - [x] I have checked ROADMAP.md and confirmed this PR does not duplicate planned core work - [x] I have searched GitHub for duplicate or related PRs and linked them above - [x] I have either (a) linked existing issues with `Fixes: #` / `Closes #` / `Refs #` OR (b) described the issue in-PR following the relevant issue template - [x] I have not referenced internal/instance-local Paperclip issues or links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip` URLs) - [x] My branch name describes the change (e.g. `docs/...`, `fix/...`) and contains no internal Paperclip ticket id or instance-derived details - [x] I have run tests locally and they pass - [x] I have added or updated tests where applicable - [x] I have updated relevant documentation to reflect my changes - [x] I have considered and documented any risks above - [x] All Paperclip CI gates are green - [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups - [x] I will address all Greptile and reviewer comments before requesting merge --------- Co-authored-by: Paperclip <noreply@paperclip.ing> |
||
|
|
ffff1fe6e3 |
feat(runner): define package API and verification boundary (#12129)
## Thinking Path > - Paperclip is the open source app people use to manage AI agents for work. > - The runner package now has protocol, transport, provider, catalog, and authorization foundations. > - Its first upstream package boundary should expose only the implemented runtime and test-helper surfaces. > - Rust correctness belongs in the repository existing build verification, without introducing a parallel release process. > - Direct package creation must build the files declared by the package manifest. > - This pull request defines the minimal package API and verifies the optimized runner binaries in the existing PR and release Build jobs. > - The benefit is a production-ready runner package boundary with minimal build-process change. ## Linked Issues or Issue Description Refs #11962 This pull request replaces one bounded part of the archived large runner change. It follows the package-local authorization change in #12126. ## What Changed - Export only `@paperclipai/paperclip-runner` and `@paperclipai/paperclip-runner/testing`. - Keep Node-only fixture loading and semantic conformance helpers out of the runtime root. - Add a provider-neutral semantic conformance kit with stable JSON comparison and fail-closed input checks. - Keep deferred SDK, eval, browser, React, lab, and command surfaces private. - Pin the runner Rust toolchain to 1.97.1 with the minimal profile and `rustfmt`. - Run the Rust workspace tests in release mode. - Launch the optimized `paperclip-runnerd` and fake-harness binaries in process-level integration coverage. - Add one `pnpm --filter @paperclipai/paperclip-runner check:all` step to each existing PR and release Build job. - Make the existing server `prepack` lifecycle run its existing build after it prepares UI assets. - Document that no production adapter starts runnerd yet. This revision adds no standalone GitHub Actions job. It adds no server runner dependency or runner vendoring. It adds no Docker bootstrap or clean-consumer harness. It does not change `pnpm-lock.yaml`. ## Verification - `pnpm --filter @paperclipai/paperclip-runner check:all` - 66 TypeScript tests - 8 protocol contract tests - 56 Rust unit and integration tests - Release-mode integration coverage launches the optimized runnerd and fake-harness binaries. - `pnpm --filter @paperclipai/server exec vitest run src/__tests__/server-package-build-script.test.ts` (2 tests) - Clean `pnpm pack` from `server/` rebuilt the server and produced both `package/dist/index.js` and `package/dist/index.d.ts`. - `node --test scripts/__tests__/release-verify-workflow.test.mjs` (8 tests) - `pnpm -r typecheck` - `pnpm build` - `pnpm check:token-gates` - `git diff --check` - No `pnpm-lock.yaml` diff. - The diff changes 12 files. ## Risks The runner adds Rust work to the existing Build jobs. These jobs can take longer on a cold cache. The pinned toolchain makes contributor and CI behavior reproducible. Cargo tests use `--release` to verify optimized executables. The server prepack lifecycle now performs the build that its published entry points require. This can make direct server packing slower. This pull request does not wire runnerd into the server. It does not select runnerd for any adapter. Existing application execution and finalization paths remain unchanged. ## Model Used OpenAI Codex with GPT-5. Agentic coding mode used repository tools, code execution, and automated tests. ## Checklist - [x] I have included a thinking path that traces from project context to this change - [x] I have specified the model used (with version and capability details) - [x] I have checked ROADMAP.md and confirmed this PR does not duplicate planned core work - [x] I have searched GitHub for duplicate or related PRs and linked them above - [x] I have either (a) linked existing issues with `Fixes: #` / `Closes #` / `Refs #` OR (b) described the issue in-PR following the relevant issue template - [x] I have not referenced internal/instance-local Paperclip issues or links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip` URLs) - [x] My branch name describes the change (e.g. `docs/...`, `fix/...`) and contains no internal Paperclip ticket id or instance-derived details - [x] I have run tests locally and they pass - [x] I have added or updated tests where applicable - [x] I have updated relevant documentation to reflect my changes - [x] I have considered and documented any risks above - [x] All Paperclip CI gates are green - [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups - [x] I will address all Greptile and reviewer comments before requesting merge Co-authored-by: Paperclip <noreply@paperclip.ing> |
||
|
|
b6854e61c7 |
refactor(adapter-utils): rename EffectiveSandboxCapabilities to EffectiveExecutionCapabilities (#12119)
## Thinking Path > - Paperclip is the open source app people use to manage AI agents for work > - The adapter utilities package defines shared types for agent execution targets > - The type name EffectiveSandboxCapabilities describes only one transport > - All execution target drivers return the same resolved capability snapshot > - This pull request gives the snapshot a general name and keeps the old type as a deprecated alias > - The benefit is clearer public vocabulary with source compatibility for current consumers ## Linked Issues or Issue Description **What existing behavior does this improve?** The exported capability snapshot type uses the name `EffectiveSandboxCapabilities`, although local, SSH, sandbox, and plugin drivers return it. **Subsystem affected** The change affects `packages/adapter-utils` and its server consumers. **Current behavior** The public type name points to the sandbox transport. The private parser also uses the sandbox-only name. **Proposed behavior** Use `EffectiveExecutionCapabilities` for the public type and `parseEffectiveExecutionCapabilities` for the private parser. Keep a deprecated alias for the old public type. **Reason and benefit** The new name matches the established execution-target vocabulary. The alias keeps existing type imports working during the migration. **Breaking changes** None. The runtime field, capability flags, parsed shape, and package versions do not change. **Additional context** GitHub search found no duplicate or related open issue or pull request. ## What Changed - Rename the exported interface to `EffectiveExecutionCapabilities`. - Keep `EffectiveSandboxCapabilities` as a deprecated type alias. - Rename the private parser and update its call site and references. - Add a type-level test for the deprecated alias. ## Verification - `npx tsc --noEmit -p packages/adapter-utils` - `npx vitest run packages/adapter-utils/src/execution-target-sandbox.test.ts` - `npx vitest run server/src/__tests__/environment-execution-target-capabilities.test.ts server/src/__tests__/environment-execution-target-duplex.test.ts` - The local checks passed with 133 adapter-utils tests and 31 server tests. - Reviewers can confirm that the runtime field and capability flags stay unchanged. ## Risks Low risk. The alias protects existing type imports. The change does not alter runtime behavior or serialized data. ## Model Used OpenAI Codex, GPT-5, tool use and code execution. The runtime does not expose the context window size. ## Checklist - [x] I have included a thinking path that traces from project context to this change - [x] I have specified the model used (with version and capability details) - [x] I have checked ROADMAP.md and confirmed this PR does not duplicate planned core work - [x] I have searched GitHub for duplicate or related PRs and linked them above - [x] I have either (a) linked existing issues with `Fixes: #` / `Closes #` / `Refs #` OR (b) described the issue in-PR following the relevant issue template - [x] I have not referenced internal/instance-local Paperclip issues or links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip` URLs) - [x] My branch name describes the change (e.g. `docs/...`, `fix/...`) and contains no internal Paperclip ticket id or instance-derived details - [x] I have run tests locally and they pass - [x] I have added or updated tests where applicable - [x] I have updated relevant documentation to reflect my changes - [x] I have considered and documented any risks above - [x] All Paperclip CI gates are green - [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups - [x] I will address all Greptile and reviewer comments before requesting merge --------- Co-authored-by: Paperclip <noreply@paperclip.ing>canary/v2026.825.0-canary.6 |
||
|
|
8d714c2d84 |
fix(cli): skip the foreground-start prompt after the service starts (#12153)
## Thinking Path > - Paperclip is the open source app people use to manage AI agents for work > - The CLI onboarding wizard can install Paperclip as a background service, and it offers a foreground start when nothing else will serve > - After #12148, an interactive onboard installs and starts the service, then still asks "Start Paperclip now?" > - Answering yes runs the foreground start into the already-running instance guard, so a fully successful onboard ends with an error message > - This pull request excludes the just-installed-service case from the foreground-start prompt > - The benefit is that an interactive onboard that installs the service ends cleanly instead of steering the user into a guard refusal ## Linked Issues or Issue Description Refs #12148 — found while verifying that fix interactively. The `shouldRunNow` flag already accounts for `serviceInstalled`, but the interactive TTY fallback prompt did not, so only real interactive runs hit it: `--yes` runs, CI, and container smokes all skip the prompt branch. **What happened?** Interactive `onboard`, accept the background-service prompt. Output ends with: service installed and started, then "Start Paperclip now?" → yes → "Paperclip instance 'default' is already running as ing.paperclip.paperclipai. Use 'paperclipai service status --instance default' or pass --force to bypass this safety check." **What did you expect to happen?** Onboarding ends cleanly after "Installed and started …" — there is nothing left to start, so no prompt. **Steps to reproduce** Run `npx paperclipai@2026.825.0-nightly.1 onboard --data-dir "$(mktemp -d)"` in a terminal, accept the service prompt, then accept "Start Paperclip now?". ## What Changed - New `shouldOfferForegroundStart` predicate in `cli/src/onboard-service.ts`: the foreground-start prompt is offered only when the start was not already decided by flags, the service was not just installed, onboarding was not invoked by `run`, and the terminal is interactive. - Both onboarding call sites in `cli/src/commands/onboard.ts` use the predicate instead of the inline condition that ignored `serviceInstalled`. - Unit tests cover the predicate matrix in `cli/src/__tests__/onboard-service.test.ts`. ## Verification - `npx vitest run src/__tests__/onboard-service.test.ts` in `cli/`: 12 passed (5 new). - `tsc --noEmit` reports no errors in the changed files (remaining errors are pre-existing in `server/`). - Manual reproduction of the defect on macOS with `2026.825.0-nightly.1` before the fix: service installed, started, and healthy, then the prompt steered into the guard refusal. ## Risks - Low risk. The prompt still appears in every case it did before except when the service was just installed and is already serving. - No behavior change for `--yes`, `--run`, `--install-service` in non-interactive runs: those paths never reached the prompt. ## Model Used - Claude Fable 5 (Anthropic, model ID `claude-fable-5`), extended thinking, agentic tool use via Claude Code. ## Checklist - [x] I have included a thinking path that traces from project context to this change - [x] I have specified the model used (with version and capability details) - [x] I have checked ROADMAP.md and confirmed this PR does not duplicate planned core work - [x] I have searched GitHub for duplicate or related PRs and linked them above - [x] I have either (a) linked existing issues with `Fixes: #` / `Closes #` / `Refs #` OR (b) described the issue in-PR following the relevant issue template - [x] I have not referenced internal/instance-local Paperclip issues or links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip` URLs) - [x] My branch name describes the change (e.g. `docs/...`, `fix/...`) and contains no internal Paperclip ticket id or instance-derived details - [x] I have run tests locally and they pass - [x] I have added or updated tests where applicable - [x] I have updated relevant documentation to reflect my changes - [x] I have considered and documented any risks above - [ ] All Paperclip CI gates are green - [ ] Greptile is 5/5 with no open P2s, recommendations, or follow-ups - [x] I will address all Greptile and reviewer comments before requesting mergecanary/v2026.825.0-canary.5 nightly/v2026.825.0-nightly.2 |
||
|
|
0a01444514 |
test(release-smoke): cover the background-service leg of onboarding (#12151)
## Thinking Path > - Paperclip is the open source app people use to manage AI agents for work > - The release pipeline gates each nightly and beta on a smoke suite that onboards the published npm artifact and drives the golden path > - That smoke runs onboarding inside a Docker container, and containers have no service manager, so the background-service leg of onboarding has zero automated coverage > - v2026.824.0 shipped a service install that crash-looped on a missing shim, and every smoke check stayed green (#12148 fixed the defect itself) > - This pull request adds a `smoke_service` job that runs the same published artifact directly on the runner VM's systemd and requires the installed service to end up serving > - The benefit is that a release with a broken service install can no longer pass the release smoke suite ## Linked Issues or Issue Description Refs #12148 — the fix for the defect this coverage gap let through. The gap: the release smoke runs `onboard` with `--yes` inside Docker, which both skips the service prompt and lacks systemd, so no CI job ever executed `manager.install()` against a real service manager. ## What Changed - New `scripts/service-onboard-smoke.sh`: onboards the published artifact with `--yes --install-service` on a systemd host, then fails unless the managed shim exists and is executable, `paperclipai.service` is active, and `/api/health` answers. A health response while the unit is not active also fails, because that is the signature of something other than the service serving. The script refuses to run over an existing managed install unless `SMOKE_FORCE=true`, and cleans up after itself by default so it is safe to run locally. - New `smoke_service` job in `.github/workflows/release-smoke.yml`: starts a user systemd session on the hosted runner (`loginctl enable-linger` + exported `XDG_RUNTIME_DIR`/`DBUS_SESSION_BUS_ADDRESS`), runs the script against `inputs.paperclip_version`, and uploads `systemctl status` + journal output as diagnostics. - No `release.yml` changes needed: `smoke_nightly` and `smoke_beta` call this reusable workflow, and a `workflow_call` result aggregates all jobs, so the new job gates nightly promotion automatically. ## Verification - `bash -n scripts/service-onboard-smoke.sh` passes and the workflow YAML parses. - End-to-end: dispatched this branch's Release Smoke workflow against the published canary that contains #12148; the `smoke_service` job onboards, installs the service, and verifies the service serves health. (Run link in PR comments.) - Negative case: the same assertions fail against v2026.824.0 — reproduced in a systemd container during the #12148 investigation: shim missing, unit in a 203/EXEC restart loop. ## Risks - Low risk to the product: no application code changes. - Pipeline risk: a flaky user-session setup on the hosted runner would block nightly promotion. Mitigated by validating the job end-to-end from this branch before merge, a 30-minute job timeout, and diagnostics uploaded on every run. - The service leg only covers systemd. launchd (macOS) still has no CI coverage; a macOS runner job is a possible follow-up. ## Model Used - Claude Fable 5 (Anthropic, model ID `claude-fable-5`), extended thinking, agentic tool use via Claude Code. ## Checklist - [x] I have included a thinking path that traces from project context to this change - [x] I have specified the model used (with version and capability details) - [x] I have checked ROADMAP.md and confirmed this PR does not duplicate planned core work - [x] I have searched GitHub for duplicate or related PRs and linked them above - [x] I have either (a) linked existing issues with `Fixes: #` / `Closes #` / `Refs #` OR (b) described the issue in-PR following the relevant issue template - [x] I have not referenced internal/instance-local Paperclip issues or links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip` URLs) - [x] My branch name describes the change (e.g. `docs/...`, `fix/...`) and contains no internal Paperclip ticket id or instance-derived details - [x] I have run tests locally and they pass - [x] I have added or updated tests where applicable - [x] I have updated relevant documentation to reflect my changes - [x] I have considered and documented any risks above - [ ] All Paperclip CI gates are green - [ ] Greptile is 5/5 with no open P2s, recommendations, or follow-ups - [x] I will address all Greptile and reviewer comments before requesting mergecanary/v2026.825.0-canary.4 |
||
|
|
faad235aa2 |
fix(cli): materialize the managed install before the onboarding service install (#12148)
## Thinking Path > - Paperclip is the open source app people use to manage AI agents for work > - Interactive onboarding offers to install Paperclip as a background service, defaulting to yes > - The service definition targets the managed command shim, but an ephemeral npx run never installs it, and the service step never checks > - The result is a crash-looping service, a doctor hint about a nonexistent port conflict, and a first run that ends with nothing serving > - This pull request materializes the managed install before registering the service, or declines with the repair path > - The benefit is that saying yes to the service prompt yields a working service — or an honest explanation ## Linked Issues or Issue Description **What happened?** On a machine with no managed install, `npx paperclipai@2026.824.0 onboard` (interactive), accepting the background-service prompt, produced: a LaunchAgent pointing at `~/.local/bin/paperclipai` (which does not exist), launchd exit code 78 in a KeepAlive crash loop, doctor reporting "inactive but the configured port is serving another Paperclip process — stop the conflicting foreground process" (no such process existed), and "Service health: fetch failed". Reproduced twice on a clean field. `latest` has carried this path since v2026.817.0 shipped; CI never sees it because `--yes` onboarding skips the service prompt. **Expected behavior** Accepting the service prompt installs a working service (materializing the managed payload and shim first when needed), and doctor diagnoses a missing service binary as exactly that. **Steps to reproduce** On macOS with no `~/.local/bin/paperclipai`: `npx paperclipai@latest onboard`, accept the service prompt, then `launchctl print gui/$UID/ing.paperclip.paperclipai` (exit code 78, spawn scheduled) and `paperclipai doctor`. **Paperclip version or commit** `2026.824.0` (path present since #10045). ## What Changed - `cli/src/onboard-service.ts`: after the user opts in, an `ensureServiceShim` step checks the service shim path. Missing + managed-store location → run `installCommand` pinned to the onboarding version (payload, shim, PATH block), then proceed. Missing + custom `PAPERCLIP_SHIM_PATH`, or install failure → decline with `paperclipai install` / `paperclipai service install` guidance and install nothing. - `cli/src/checks/service-health-check.ts`: the runtime check diagnoses a missing service binary with the install repair hint (instead of the port-conflict hint); an inactive service with a healthy responder gets a `warn` attributing the foreign process instead of a plain "Healthy" pass. - Tests: new cases for shim materialization ordering, decline-on-failure, missing-binary diagnosis, and foreign-responder attribution; existing fixtures updated to inject the new dependencies. ## Verification - `vitest run` on both touched suites: 15 pass. - `tsc --noEmit` error count identical to the master baseline (16 pre-existing, all in `server/`, none in changed files). - The live failure was reproduced on macOS before the fix (twice, clean field) and the mechanism confirmed in source: `install()` writes the definition and bootstraps launchd only; `install-store` was previously reachable solely from the `install`/`update` commands. ## Risks - Low: the new path runs only when the user opts into the service and the shim is absent. The managed install resolves the pinned onboarding version from the public registry; on failure the flow declines exactly as it does on unsupported platforms. `--yes` quickstarts, Docker, and managed installs are untouched. ## Model Used Claude Fable 5 (Claude Code) ## Pre-submission checklist - [x] I have included a thinking path that traces from project context to this change - [x] I have specified the model used (with version and capability details) - [x] I have checked ROADMAP.md and confirmed this PR does not duplicate planned core work - [x] I have searched GitHub for duplicate or related PRs and linked them above - [x] I have either (a) linked existing issues with `Fixes: #` / `Closes #` / `Refs #` OR (b) described the issue in-PR following the relevant issue templatenightly/v2026.825.0-nightly.1 canary/v2026.825.0-canary.3 |
||
|
|
fa40a1b8d5 |
docs(release): canonicalize stable notes for v2026.824.0 (#12139)
## Thinking Path > - Paperclip is the open source app people use to manage AI agents for work > - Stable notes are drafted beta-keyed during the soak and published verbatim as the GitHub Release > - After the stable ships, the canonicalize job moves the file to its durable home, releases/vYYYY.MDD.P.md > - v2026.824.0 just shipped from the master-side beta notes, and the job pushed this rename branch > - This pull request lands that rename, keeping the stable-notes record complete at the canonical path > - The benefit is one canonical notes location per stable, with the pinned shipped content ## Linked Issues or Issue Description **What existing behavior does this improve?** The `releases/` record on master after the v2026.824.0 promotion. **Current behavior** The shipped notes live at `releases/beta/v2026.818.0-beta.1.md`; `releases/v2026.824.0.md` does not exist. **Proposed behavior** The file moves to `releases/v2026.824.0.md`, content pinned to the revision the release read (machine-generated by the `canonicalize_stable_notes` job). **Reason and benefit** The durable stable-notes invariant holds: every shipped stable has its notes at `releases/vYYYY.MDD.P.md`. ## What Changed - `git mv`-equivalent rename of the beta-keyed notes to `releases/v2026.824.0.md`, exactly as the release published them. ## Verification - Branch pushed by the release run's `canonicalize_stable_notes` job (run 32806191945) from the preflight-pinned notes revision; the GitHub Release v2026.824.0 body matches this content. ## Risks - None; docs-only rename. ## Model Used Claude Fable 5 (Claude Code) — PR opened for the machine-pushed branch; a GITHUB_TOKEN-created PR would not run required checks. ## Pre-submission checklist - [x] I have included a thinking path that traces from project context to this change - [x] I have specified the model used (with version and capability details) - [x] I have checked ROADMAP.md and confirmed this PR does not duplicate planned core work - [x] I have searched GitHub for duplicate or related PRs and linked them above - [x] I have either (a) linked existing issues with `Fixes: #` / `Closes #` / `Refs #` OR (b) described the issue in-PR following the relevant issue template Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>canary/v2026.825.0-canary.2 |
||
|
|
14867bd186 |
test(release-smoke): follow the mission-less onboarding reorder (#12135)
## Thinking Path > - Paperclip is the open source app people use to manage AI agents for work > - The nightly release lane publishes only after the release smoke suite passes against the newest canary > - Onboarding was reordered: step 1 now creates the company and routes straight to the agent step, and the mission step is gone (collected later in the tenant app, deliberately writing no goal) > - The smoke spec still walked the removed mission step, so the scheduled nightly has been red since the reorder shipped > - This pull request updates the spec to the current flow and asserts the deliberate empty goal list > - The benefit is a green nightly lane and an unblocked beta promotion from current master ## Linked Issues or Issue Description **What happened?** The scheduled `Release` nightly run fails in `smoke_nightly / smoke` since 2026-08-23 (runs 32630184811, 32710905212): `docker-auth-onboarding.spec.ts` waits for the `Define your mission` heading after step 1, but the wizard now routes 1 → 3 with no mission step (the step buttons literally skip from 1 to 3). The retry then fails on step 1 because the first attempt's company persists. **Expected behavior** The smoke passes against canaries carrying the reordered wizard, and the nightly lane publishes again. **Steps to reproduce** Run `scripts/docker-onboard-smoke.sh` with `PAPERCLIPAI_VERSION=2026.824.0-canary.7` and `pnpm run test:release-smoke` against it. **Paperclip version or commit** `2026.824.0-canary.7` Related (not duplicates): #11565 updated this same spec for the chat-first rewrite; this is the follow-up for the mission-less reorder. ## What Changed - Remove the mission-step interaction; step 1's "Next" now creates the company and the spec goes straight to the agent step. - Replace the mission-goal API assertion with the truthful one: onboarding deliberately writes no goal, so a fresh company's goal list is empty. - Update step comments to match the shipped flow. ## Verification - Local run of the exact CI harness against `paperclipai@2026.824.0-canary.7`: 1 passed (6.8s), exit 0. - The suite's remaining API assertions (company, CEO agent, seeded task assignment, landed issue URL, assignment-sourced heartbeat run) pass unchanged. ## Risks - Low risk: test-only. The spec remains copy-coupled to the wizard — this is the third drift in two weeks; stable `data-testid` hooks in the wizard remain the durable fix and can follow separately. ## Model Used Claude Fable 5 (Claude Code) ## Pre-submission checklist - [x] I have included a thinking path that traces from project context to this change - [x] I have specified the model used (with version and capability details) - [x] I have checked ROADMAP.md and confirmed this PR does not duplicate planned core work - [x] I have searched GitHub for duplicate or related PRs and linked them above - [x] I have either (a) linked existing issues with `Fixes: #` / `Closes #` / `Refs #` OR (b) described the issue in-PR following the relevant issue templatecanary/v2026.825.0-canary.1 |
||
|
|
890ab9acfe |
feat(release): thorough notes skeletons — nest each PR's summary at creation (#12124)
## Thinking Path > - Paperclip is the open source app people use to manage AI agents for work > - The release workflow drafts the upcoming stable's notes skeleton the moment a beta publishes > - That skeleton was a bare list of commit subjects, so the notes only reached the shipped stable's depth after a later authoring pass during the soak > - Stable release notes are consistently verbose and thorough; the initial draft should start that way too > - This pull request nests each referenced PR's own summary under its subject line at creation time, and states the density bar in the authoring skill > - The benefit is a thorough raw document from day one of the soak, with no LLM tokens in Actions ## Linked Issues or Issue Description **What existing behavior does this improve?** The `draft_stable_notes` skeleton generated at beta publish (`scripts/draft-stable-notes.sh`). **Current behavior** The skeleton groups bare commit subjects by conventional-commit type. All substance arrives later, when a maintainer or agent rewrites it — reviewed maintainer feedback: stable notes are a lot more verbose, and the initial beta notes should be consistent with that. **Proposed behavior** Each subject that references a PR carries that PR's own summary nested beneath it — the PR template's "What Changed" bullets, else the first prose lines — fetched best-effort via `gh` and skipped silently when unavailable. The release-changelog skill now states the density bar explicitly: the beta-keyed draft ships verbatim as the stable's notes and is written at the previous stable's depth from the first pass. **Reason and benefit** The notes author starts from a thorough raw document instead of a commit list, and beta-time notes match the verbosity the stable will ship with. ## What Changed - `scripts/draft-stable-notes.sh`: `enrich_pr` nests PR summaries under subjects; best-effort (`gh` failure or `DRAFT_NOTES_SKIP_PR_ENRICHMENT=1` degrades to today's output); pipefail-safe when a "What Changed" section has no bullets. - `.github/workflows/release.yml`: the `draft_stable_notes` step gets `GH_TOKEN` so `gh` can read PR bodies. - `.agents/skills/release-changelog/SKILL.md`: "write at full stable depth from the first pass" guideline. - `scripts/draft-stable-notes.test.mjs`: three new tests — enrichment rendering via a fake `gh`, silent degradation without one, and the sparse-body case that previously killed the script under `set -o pipefail`. ## Verification - `node --test scripts/draft-stable-notes.test.mjs` — 11 pass. - Live run against the real repository for the current beta (`2026.818.0-beta.1`, 172 commits): exit 0, 439 nested summary lines; spot-checked entries carry the correct PRs' What Changed bullets. - `bash -n` on the script; `release.yml` re-parsed as YAML. ## Risks - Low: the publish path is untouched; enrichment is read-only `gh` calls in the post-publish draft job and degrades to the current skeleton on any failure. Roughly one API call per commit in the range (~170 today) — well inside the token's rate budget, adds a couple of minutes to a job with a 10-minute timeout. ## Model Used Claude Fable 5 (Claude Code) ## Pre-submission checklist - [x] I have included a thinking path that traces from project context to this change - [x] I have specified the model used (with version and capability details) - [x] I have checked ROADMAP.md and confirmed this PR does not duplicate planned core work - [x] I have searched GitHub for duplicate or related PRs and linked them above - [x] I have either (a) linked existing issues with `Fixes: #` / `Closes #` / `Refs #` OR (b) described the issue in-PR following the relevant issue template |
||
|
|
ae9711da48 |
docs(release): re-date the 2026.818.0-beta.1 stable notes to v2026.824.0 (#12113)
## Thinking Path > - Paperclip is the open source app people use to manage AI agents for work > - Stable versions date the promotion, and the promotion reads its notes from master > - The merged notes for beta 2026.818.0-beta.1 assumed an Aug 21 promotion; the beta soaked longer > - This pull request re-dates the header to today's resolved version, v2026.824.0 > - The benefit is a GitHub Release whose title, date, and body agree ## Linked Issues or Issue Description **What existing behavior does this improve?** The stable notes header for the promotion happening today. **Current behavior** `releases/beta/v2026.818.0-beta.1.md` is titled `# Paperclip v2026.821.0`, `> Released: 2026-08-21`. **Proposed behavior** `# Paperclip v2026.824.0`, `> Released: 2026-08-24` — matching `./scripts/release.sh stable --date 2026-08-24 --print-version`. **Reason and benefit** The file publishes verbatim as the GitHub Release body; the header should match the version actually minted. ## What Changed - Three header/intro lines re-dated. Nothing else. ## Verification - `./scripts/release.sh stable --date 2026-08-24 --print-version` → `2026.824.0`. ## Risks - None; docs-only. ## Model Used Claude Fable 5 (Claude Code) ## Pre-submission checklist - [x] I have included a thinking path that traces from project context to this change - [x] I have specified the model used (with version and capability details) - [x] I have checked ROADMAP.md and confirmed this PR does not duplicate planned core work - [x] I have searched GitHub for duplicate or related PRs and linked them above - [x] I have either (a) linked existing issues with `Fixes: #` / `Closes #` / `Refs #` OR (b) described the issue in-PR following the relevant issue templatecanary/v2026.825.0-canary.0 nightly/v2026.825.0-nightly.0 |
||
|
|
d1573244b5 |
refactor: disambiguate the Telemetry and Observability data paths (#12128)
## Thinking Path > - Paperclip is the open source app people use to manage AI agents for work > - Paperclip records first-party events, OpenTelemetry data, and local run-log events > - The code and documents used one term for these three data paths > - This naming made the required review level unclear > - This pull request names each data path in the module names, documents, and code comments > - The benefit is a clear review rule without a runtime change ## Linked Issues or Issue Description **Issue type** Unclear or confusing. **Where is the issue?** `packages/shared/src/telemetry/README.md`, `doc/observability.md`, `doc/run-log-events.md`, and the duplex instrumentation modules. **What's wrong?** The repository used Telemetry for first-party events, OpenTelemetry data, and local run-log events. This usage made the data path and review level unclear. **Suggested fix** Use Telemetry only for Paperclip first-party events. Use Observability for OpenTelemetry data. Use the run log for rows in `heartbeat_run_events`. Related public pull requests: #8476 and #9672. ## What Changed - Rename the duplex instrumentation modules and identifiers from `Telemetry` to `Observability`. - Move the Observability and run-log contracts out of the Telemetry README. - Add `doc/observability.md` and `doc/run-log-events.md` as the canonical documents. - Add a file-path review rule to `AGENTS.md`. - Correct the remaining code comments that name the wrong data path. - Keep all event names, payloads, database records, spans, configuration keys, environment variables, and runtime paths unchanged. ## Verification - `npx vitest run packages/shared/src/telemetry/readme-contract.test.ts` passes. - `npx vitest run packages/adapter-utils/src/published-exports.test.ts` passes. - `npx vitest run packages/adapter-utils/src/acpx-engine/startup-timing.test.ts` passes with 42 tests. - `pnpm --filter @paperclipai/adapter-utils typecheck` passes. - `pnpm --filter server typecheck` passes. - The old module name does not remain in TypeScript or JSON files, except for the intentional publication guard. - CI and Greptile checks remain pending after PR creation. ## Risks - The old duplex module subpath no longer has a compatibility shim. The board accepted this intentional hard break. - The new duplex module subpath stays blocked from package publication. - The change has no runtime effect. The main risk is an incorrect document or module reference. ## Model Used OpenAI GPT-5 Codex, exact model ID `gpt-5`, with tool use and code review support. ## Checklist - [x] I have included a thinking path that traces from project context to this change - [x] I have specified the model used (with version and capability details) - [x] I have checked ROADMAP.md and confirmed this PR does not duplicate planned core work - [x] I have searched GitHub for duplicate or related PRs and linked them above - [x] I have described the issue in-PR with the documentation issue fields - [x] I have not referenced internal/instance-local Paperclip issues or links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip` URLs) - [x] My branch name describes the change and contains no internal Paperclip ticket id or instance-derived details - [x] I have run tests locally and they pass - [x] I have added or updated tests where applicable - [x] I have updated relevant documentation to reflect my changes - [x] I have considered and documented any risks above - [x] All Paperclip CI gates are green - [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups - [x] I will address all Greptile and reviewer comments before requesting merge --------- Co-authored-by: Paperclip <noreply@paperclip.ing> |
||
|
|
42b8f7ab2f |
feat(runner): authorize semantic tool dispatch (#12126)
## Thinking Path > - Paperclip is the open source app people use to manage AI agents for work. > - The runner package defines a provider-neutral protocol and semantic action catalog. > - Catalog membership alone must not grant access to an action. > - Each run needs current company, actor, task, claim, mode, and application-binding authority. > - Mutating actions also need safe retry behavior and durable receipts. > - This pull request adds a package-local authority and dispatch layer. > - The benefit is a small and testable trust boundary before server integration lands. ## Linked Issues or Issue Description Refs #11962 This pull request replaces one bounded part of the archived large runner change. ## What Changed - Add run-scoped tool projection and optional tool discovery. - Require an explicit application binding before an action is visible. - Intersect actor claims with claims delegated to the run. - Recheck company, actor, task, mode, state, role, claim, and policy authority before each call. - Validate action input and output with the canonical catalog schemas. - Redact protected values and keep raw tool content out of semantic receipts. - Require atomic idempotency claims for mutating actions. - Replay exact completed retries and reject changed or concurrent retries. - Recover a durable completed receipt if the primary receipt commit fails, without re-executing the mutation. - Add bounded authorization records and PRP semantic input and result receipts. - Document that this change adds no server binding or production tool installation. ## Verification - `pnpm --filter @paperclipai/paperclip-runner check:all` - `pnpm -r typecheck` - `pnpm check:token-gates` - `pnpm build` - 60 package TypeScript tests pass. - 56 Rust unit and integration tests pass. - Protocol, replay, and cross-language conformance checks pass. - `pnpm test:run` completed with 4,684 passing and 19 skipped tests. It reproduced 32 local baseline failures across 9 unchanged server files; all corresponding hosted test shards pass. - Every applicable GitHub Actions gate passes. The Storybook job skipped because this PR has no UI changes. - Socket and Snyk pass with no findings. Superagent completed neutral with zero annotations because its external sandbox did not start within 120 seconds. - Greptile is 5/5 with no unresolved actionable comments. - The diff changes 11 files. ## Risks The main risk is an authorization or idempotency error at the tool boundary. The dispatcher fails closed for malformed authority, unavailable receipt storage, stale authority, unauthorized actions, protected input, invalid binding output, and unrecoverable receipt completion. The receipt store must recover a completed mutation outcome idempotently if its primary commit fails; otherwise the claim remains reserved for operator recovery rather than allowing automated re-execution. Unbound actions are absent. No server or provider installs these tools in this change. Existing adapters and application behavior do not change. ## Model Used OpenAI Codex with GPT-5. Agentic coding mode used repository tools, code execution, and automated tests. ## Checklist - [x] I have included a thinking path that traces from project context to this change - [x] I have specified the model used (with version and capability details) - [x] I have checked ROADMAP.md and confirmed this PR does not duplicate planned core work - [x] I have searched GitHub for duplicate or related PRs and linked them above - [x] I have either (a) linked existing issues with `Fixes: #` / `Closes #` / `Refs #` OR (b) described the issue in-PR following the relevant issue template - [x] I have not referenced internal/instance-local Paperclip issues or links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip` URLs) - [x] My branch name describes the change (e.g. `docs/...`, `fix/...`) and contains no internal Paperclip ticket id or instance-derived details - [x] I have run the affected tests locally and they pass; full-suite baseline exceptions are documented above - [x] I have added or updated tests where applicable - [x] I have updated relevant documentation to reflect my changes - [x] I have considered and documented any risks above - [x] All Paperclip CI gates are green - [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups - [x] I will address all Greptile and reviewer comments before requesting merge --------- Co-authored-by: Paperclip <noreply@paperclip.ing>canary/v2026.824.0-canary.7 |
||
|
|
23048f1219 |
Add canonical semantic action catalog to Paperclip Runner (#12121)
## Thinking Path > - Paperclip is the open source app people use to manage AI agents for work. > - Paperclip Runner now has a durable PRP transport and a Codex provider bridge. > - Codex must use stable, provider-neutral action contracts before Paperclip can grant run-scoped tool access. > - A catalog must describe actions without granting permission to discover or invoke them. > - Generated inventory must stay synchronized with its TypeScript source. > - This pull request adds the canonical Codex-spine semantic action catalog inside the runner package. > - The benefit is a small review unit for schemas and inventory before authorization and dispatch land. ## Linked Issues or Issue Description **Subsystem affected** Cross-cutting. This pull request extends private runner infrastructure in `packages/paperclip-runner`. **Problem or motivation** The Codex provider bridge has no canonical description of the Paperclip actions that a later authorization layer can project into a run. Independent operation lists can drift in names, claims, task modes, effects, and input bounds. **Proposed solution** Add one immutable v1 catalog for the first 27 Codex-spine actions. Give each action a stable identifier, placement, effect, required claims, supported task modes, and JSON Schema input and output contracts. Generate a deterministic JSON inventory from that source and fail package checks on drift. **Alternatives considered** The combined runner branch contains larger live and scenario catalogs with authorization, bindings, labs, and other providers. That change is too large for this review unit. A generic API escape hatch would also bypass the operation-level boundary, so this catalog excludes it. **Roadmap alignment** This work supports the governed tool access direction in `ROADMAP.md`. It does not add a tool gateway, application binding, server endpoint, or production authorization decision. **Additional context** Refs #12111 and #11962. Pull request #12111 was squash-merged first. This branch starts at the resulting `master` commit. Its delta is 10 files. ## What Changed - Added 27 versioned, provider-neutral semantic action declarations for the Codex spine. - Added bounded JSON Schema input contracts and normalized operation receipt output contracts. - Added placement, effect, claim, mode, and role metadata. - Added a deeply frozen public catalog and an operation lookup helper. - Added a deterministic checked-in JSON inventory and generation commands. - Added a byte-for-byte drift gate to the package build. - Added AJV schema compilation, mutation-bound, forged-field, immutability, inventory, and non-executable-boundary tests. - Exported only the catalog types and declarations from the existing package root. - Documented that catalog membership does not grant discovery, authorization, dispatch, or application binding. - Kept server code, UI code, other providers, scenario-only actions, labs, generic API access, authorization, dispatch, and receipts processing out of this pull request. ## Verification - `pnpm --filter @paperclipai/paperclip-runner check:all` passes. - TypeScript protocol tests pass: 8 Node tests and 49 Vitest tests. - All package Rust tests and conformance and replay parity checks pass. - `pnpm --filter @paperclipai/paperclip-runner check:semantic-action-catalog` passes. - `pnpm -r typecheck` passes. - `pnpm build` passes. - `pnpm check:token-gates` passes. - Prettier and `git diff --check` pass for the changed source and documentation files. - The generated catalog matches its source byte for byte. - The secret scan is clean. - The delta against `master` is 10 files. `pnpm-lock.yaml` is unchanged. - `pnpm test:run` completed locally with 4,692 passing tests, 19 skipped tests, and 24 failures in 8 unchanged server test files. The failures reproduce the established local macOS path-alias, listener, and workspace-runtime baseline. No changed-file test failed. Linux CI remains the repository handoff authority. - The full Linux PR workflow passes, including the aggregate `verify` gate. - Snyk, Socket, Superagent security, and supply-chain checks pass. - Greptile is 5/5 with no actionable comments, recommendations, or follow-ups. - Storybook visual regression skipped by design because this pull request changes no UI file. - Browser and migration tests are not applicable because this pull request changes no server, UI, database, or migration file. ## Risks Production behavior is unchanged because no consumer projects this catalog into a provider run. The main risks are contract drift, unbounded mutation input, forged scope fields, accidental executable authority, and generated inventory drift. Closed input schemas, explicit bounds, a frozen catalog, tests, and the byte drift gate cover these risks. The later authorization layer must still bind every action to the active run and company before discovery or invocation. I checked `ROADMAP.md`. This change is private contract infrastructure for the governed tool access direction. It does not duplicate a shipped or public product surface. ## Model Used OpenAI Codex with GPT-5 was used. The exact serving model ID and context size were not exposed. The model used high reasoning, repository tools, GitHub tools, and local code execution. ## Checklist - [x] I have included a thinking path that traces from project context to this change - [x] I have specified the model used (with version and capability details) - [x] I have checked ROADMAP.md and confirmed this PR does not duplicate planned core work - [x] I have searched GitHub for duplicate or related PRs and linked them above - [x] I have either (a) linked existing issues with `Fixes: #` / `Closes #` / `Refs #` OR (b) described the issue in-PR following the relevant issue template - [x] I have not referenced internal/instance-local Paperclip issues or links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip` URLs) - [x] My branch name describes the change (e.g. `docs/...`, `fix/...`) and contains no internal Paperclip ticket id or instance-derived details - [ ] I have run tests locally and they pass - [x] I have added or updated tests where applicable - [x] I have updated relevant documentation to reflect my changes - [x] I have considered and documented any risks above - [x] All Paperclip CI gates are green - [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups - [x] I will address all Greptile and reviewer comments before requesting merge Co-authored-by: Paperclip <noreply@paperclip.ing> |
||
|
|
4ffa8de4e2 |
Add Codex provider bridge to Paperclip Runner (#12111)
## Thinking Path > - Paperclip is the open source app people use to manage AI agents for work. > - The package-local runner now has a durable PRP transport, but it cannot execute a real provider. > - The first provider must preserve PRP identities while using Codex native thread and turn identities. > - Recovery must resume the same Codex thread without starting a duplicate turn. > - Provider output must become bounded and provider-neutral before it crosses PRP. > - Semantic tools must remain unavailable until the catalog and authorization layers exist. > - This pull request adds the Codex provider bridge inside the runner package only. > - The benefit is a reviewable provider slice with no server or user-facing behavior change. ## Linked Issues or Issue Description **Subsystem affected** Cross-cutting. This pull request extends private provider infrastructure in `packages/paperclip-runner`. **Problem or motivation** The durable runner from #12100 has no production provider. It cannot start Codex app-server, map its events, cancel or steer a turn, deliver a structured question, or recover a native thread after process restart. **Proposed solution** Add a supervised Codex app-server transport and a normalized runner backend. Persist the Codex thread and active turn identities. Resume and inspect the exact thread after restart. Convert supported notifications into bounded PRP events. Keep the dynamic tool inventory empty. **Alternatives considered** The combined runner branch implements several providers, semantic tools, server coordination, and UI integration together. That change is too large for one review unit. Reusing the direct `codex_local` adapter would also couple this package layer to the existing server execution path. **Roadmap alignment** This work supports the governed tools and self-healing run direction in `ROADMAP.md`. It does not add a server endpoint, runtime adapter, rollout flag, or user-facing behavior. **Additional context** Refs #12100 and #11962. Pull request #12100 was squash-merged first. This branch starts at the resulting `master` commit. Its current delta is 16 files. ## What Changed - Added a Codex-only app-server process transport with bounded JSONL frames and buffered notifications. - Added strict provider descriptor validation for the Codex driver, working directory, launch arguments, model, instructions, and non-interactive approval policy. - Started new Codex threads with an empty dynamic tool inventory and the named workspace-only permission profile. - Added native turn start, steering, interruption, cancellation, thread reads, and structured question responses. - Added thread and active-turn binding checks for provider requests and notifications. - Added provider-neutral normalization for session, turn, item, plan, usage, tool execution, notice, and structured input events. - Bounded and redacted provider text and process output before durable persistence. - Added private atomic provider state for the descriptor, thread ID, account session ID, active turn ID, and unacknowledged normalized events. - Added exact-thread recovery through `thread/resume` and `thread/read`. Recovery does not issue another `turn/start` for an active turn. - Preserved active native turn identity across unexpected provider exit and reconciled it before later start, interrupt, or snapshot commands. - Added stable provider-event identities, per-event durable commit and acknowledgement, and a bounded fingerprint receipt journal that prevents duplicate delivery across outbox and provider-ack crash windows. - Extended the durable command executor with provider event polling and explicit process shutdown on stop, suspend, revocation, lease expiry, and runtime expiry. - Preserved completed shutdown behavior when the command result is replayed after a disconnect. - Added a fake Codex app-server and integration tests for response buffering, structured questions, interruption, provider exit, unacknowledged-event recovery, durable resume, and duplicate-turn prevention. - Added a focused `test:codex` package command for the provider integration suite. - Kept server code, UI code, other providers, semantic catalogs, tool authorization, and production runtime selection out of this pull request. ## Verification - `pnpm --filter @paperclipai/paperclip-runner check:all` passes. - TypeScript contract tests pass: 8 Node tests and 44 Vitest tests. - Rust tests pass: 43 unit tests, 5 Codex integration tests, 3 public durable-recovery tests, 2 local-runner tests, and 3 process-supervisor tests. - Rust conformance and replay parity checks pass against the shared PRP fixtures. - `cargo clippy --workspace --all-targets -- -A clippy::filter-map-bool-then -D warnings` passes. The narrow allow covers an unchanged replay implementation from the preceding contract pull request. - `pnpm -r typecheck` passes. - `pnpm build` passes. - `pnpm check:token-gates` passes. - `git diff --check` passes. - The delta against `master` is 16 files. The package lockfile is unchanged. The PR workflow generates its temporary lockfile artifact from the changed package manifest. - `pnpm test:run` completed locally with 4,690 passing tests, 19 skipped tests, and 26 failures in 8 unchanged server test files. The failures reproduce the established local macOS path-alias, listener, port-range, and workspace-runtime baseline. No changed-file test failed. Linux CI remains the repository handoff authority. - Browser and migration tests are not applicable because this pull request changes no server, UI, database, or migration file. - The full Linux PR workflow passes. One unchanged heartbeat recovery test timed out on the first pass and passed on the failed-only rerun; the aggregate `verify` gate is green. - Greptile is 5/5 on the final commit. All four review threads are resolved. ## Risks Production behavior is unchanged because no server code starts this provider. The main risks are a provider process escape, cross-thread event confusion, secret leakage, duplicated turns, duplicated or lost provider events, lost questions, and unsafe recovery. Process-group supervision, identity binding, private bounded state, redaction, durable command replay, retained event acknowledgements, bounded durable receipts, exact-thread reconciliation, and integration tests cover these risks. Semantic tools remain undiscoverable in this layer. I checked `ROADMAP.md`. This change is private provider infrastructure for planned control-plane work. It does not duplicate a shipped or public product surface. ## Model Used OpenAI Codex with GPT-5 was used. The exact serving model ID and context size were not exposed. The model used high reasoning, repository tools, GitHub tools, and local code execution. ## Checklist - [x] I have included a thinking path that traces from project context to this change - [x] I have specified the model used (with version and capability details) - [x] I have checked ROADMAP.md and confirmed this PR does not duplicate planned core work - [x] I have searched GitHub for duplicate or related PRs and linked them above - [x] I have either (a) linked existing issues with `Fixes: #` / `Closes #` / `Refs #` OR (b) described the issue in-PR following the relevant issue template - [x] I have not referenced internal/instance-local Paperclip issues or links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip` URLs) - [x] My branch name describes the change (e.g. `docs/...`, `fix/...`) and contains no internal Paperclip ticket id or instance-derived details - [ ] I have run tests locally and they pass - [x] I have added or updated tests where applicable - [x] I have updated relevant documentation to reflect my changes - [x] I have considered and documented any risks above - [x] All Paperclip CI gates are green - [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups - [x] I will address all Greptile and reviewer comments before requesting merge --------- Co-authored-by: Paperclip <noreply@paperclip.ing> --------- Co-authored-by: Paperclip <noreply@paperclip.ing>canary/v2026.824.0-canary.6 |
||
|
|
dc621184a1 |
chore(lockfile): refresh pnpm-lock.yaml (#12094)
## Thinking Path > - Paperclip is the open source app people use to manage AI agents for work > - CI owns pnpm-lock.yaml: manifest-changing PRs merge without it, and this automation lands the regenerated lockfile right after > - The runner-supervision and PRP-transport merges (#12095, #12100) added devDependencies to packages/paperclip-runner, desyncing the lockfile > - Every frozen-lockfile install on master has failed since, taking CI down repo-wide > - This pull request lands the regenerated entries for the paperclip-runner importer > - The benefit is CI works again on every branch ## Linked Issues or Issue Description **What happened?** Since #12095 merged, every CI job fails in ~15 seconds at `pnpm install --frozen-lockfile`: the lockfile's `packages/paperclip-runner` importer does not match its `package.json`. **Expected behavior** `pnpm install --frozen-lockfile` succeeds on master. **Steps to reproduce** `npx pnpm@9.15.4 install --frozen-lockfile` on master before this change. **Paperclip version or commit** master at `b76e36d6c`. ## What Changed - `pnpm-lock.yaml` regenerated by the refresh automation (pnpm 9.15.4, `--lockfile-only`); the diff covers only the `packages/paperclip-runner` importer's new devDependencies. A human empty commit triggered the required checks (the automation's `GITHUB_TOKEN` push cannot — fix proposed in #12115). ## Verification - `npx pnpm@9.15.4 install --frozen-lockfile` verified locally against this exact lockfile content (fails on master without it). - Full required suite green on this PR (30 checks). ## Risks - None beyond lockfile content; the diff touches no version outside the paperclip-runner importer. ## Model Used Claude Fable 5 (Claude Code) — body authored on behalf of the lockfile automation. ## Pre-submission checklist - [x] I have included a thinking path that traces from project context to this change - [x] I have specified the model used (with version and capability details) - [x] I have checked ROADMAP.md and confirmed this PR does not duplicate planned core work - [x] I have searched GitHub for duplicate or related PRs and linked them above - [x] I have either (a) linked existing issues with `Fixes: #` / `Closes #` / `Refs #` OR (b) described the issue in-PR following the relevant issue template --------- Co-authored-by: lockfile-bot <lockfile-bot@users.noreply.github.com> Co-authored-by: Devin Foley <devin@paperclip.ing> |
||
|
|
b76e36d6cf |
Add durable PRP transport and recovery (#12100)
## Thinking Path > - Paperclip is the open source app people use to manage AI agents for work. > - The package-local runner can supervise a local process, but it cannot yet survive a broken controller connection. > - A production transport must authenticate both peers without putting the bootstrap secret on the wire. > - Commands and events must remain bounded, ordered, and recoverable across reconnects and crashes. > - Retrying an uncertain side effect is unsafe, so indeterminate outcomes must fail closed instead of running twice. > - This pull request adds those transport and recovery guarantees inside the runner package only. > - The benefit is a durable PRP boundary that can be reviewed before any provider or server integration exists. ## Linked Issues or Issue Description **Subsystem affected** Cross-cutting. This pull request extends private transport infrastructure in `packages/paperclip-runner`. **Problem or motivation** The local runner introduced by #12095 has no authenticated network handshake, durable outbox, reconnect lease, cumulative acknowledgement, or crash-safe command journal. A dropped connection could otherwise lose an event or tempt a controller to repeat a side effect whose outcome is unknown. **Proposed solution** Add an authenticated PRP v1 WebSocket transport, encrypted frames, lease-based reconnects, a bounded durable event outbox, cumulative acknowledgements, and an idempotent command journal. Preserve pending commands before execution and classify the crash window as indeterminate so an uncertain side effect is never repeated automatically. **Alternatives considered** The combined runner branch implements transport together with Codex, semantic tools, and server coordination. That change is too large for one review unit. Keeping transport in memory would make reconnect and crash recovery unverifiable. Re-running a pending command after restart would weaken the at-most-once side-effect boundary. **Roadmap alignment** This work supports the governed tools and self-healing run direction in `ROADMAP.md`. It does not add a production provider, server endpoint, adapter, feature flag, or user-facing behavior. **Additional context** Refs #12095 and #11962. Pull request #12095 was squash-merged first. This branch has been rebased onto the resulting `master` commit, and its current delta is 13 files. ## What Changed - Added a loopback-only WebSocket connection policy with one-time DNS resolution and pinned reconnect addresses. - Added an HMAC mutual-authentication handshake that never sends the bootstrap ticket over the socket. - Added AES-256-GCM secure frames with per-direction keys, monotonic counters, and session-bound authenticated data. - Added one-use bootstrap-ticket handling and lease-based reconnect validation with expiry, revocation, and epoch checks. - Added a private, symlink-resistant state directory with atomic, synchronized state replacement. - Added a bounded durable event outbox, priority-zero reserve, cumulative acknowledgements, and reconnect replay of only the unacknowledged suffix. - Added a bounded command journal with contiguous sequence enforcement, persistent results, and deterministic duplicate responses. Duplicate replay requires a SHA-256 match over the complete canonical command. - Persisted commands before their effects. A crash after persistence but before result storage returns an indeterminate terminal result and does not execute the command again. - Migrated pre-fingerprint command journals by compacting through their persisted controller cursor. Legacy redelivery fails closed instead of reconstructing an incomplete identity or repeating an uncertain effect. - Added strict limits and validation for frames, state, results, outbox entries, command history, and redacted diagnostics. - Added a transport-only `paperclip-runnerd --connect-url` mode. It handles lifecycle commands and rejects provider commands because no provider is present in this pull request. - Added a full disconnect-before-ack fault test that reconnects with the lease, replays identical command and event state, and proves the effect ran once. - Kept provider transports, semantic tools, server integration, and production runtime selection out of this pull request. ## Verification - `pnpm --filter @paperclipai/paperclip-runner check:all` passes. - TypeScript contract tests pass: 8 Node tests and 44 Vitest tests. - Rust tests pass: 33 unit tests, 3 public durable-recovery integration tests, plus the existing 2 local-runner and 3 process-supervisor tests. - The disconnect-before-ack, lease reconnect, duplicate command, malformed state, unknown command, bounds, and crash-window tests pass. - Rust conformance and replay parity checks pass against the shared PRP fixtures. - `cargo clippy --workspace --all-targets -- -A clippy::filter-map-bool-then -D warnings` passes. The narrow allow covers an unchanged replay implementation from the preceding contract pull request. - `pnpm -r typecheck` passes. - `pnpm build` passes. - `pnpm check:token-gates` passes. - `git diff --check` passes. - The delta against `master` is 13 files. The package lockfile is unchanged. - `pnpm test:run` completed locally with 4,686 passing tests, 19 skipped tests, and 30 failures in 8 unchanged server test files. The failures reproduce the established local macOS path-alias, listener, port-range, and workspace-runtime baseline. No changed-file test failed; Linux CI remains the repository handoff authority. - Storybook visual regression is not applicable because this pull request changes no UI or story files. ## Risks Production behavior is unchanged because no server code starts or connects to this transport. The main risks are secret disclosure, forged or replayed frames, state corruption, unbounded disk growth, duplicated side effects, and incorrect recovery. Mutual authentication, encrypted counter-bound frames, private atomic state, explicit bounds, cumulative acknowledgements, a durable command journal, fail-closed indeterminate recovery, and fault-injection tests cover these risks. I checked `ROADMAP.md`. This change is private transport infrastructure for planned control-plane work. It does not duplicate a shipped or public product surface. ## Model Used OpenAI Codex with GPT-5 was used. The exact serving model ID and context size were not exposed. The model used high reasoning, repository tools, GitHub tools, and local code execution. ## Checklist - [x] I have included a thinking path that traces from project context to this change - [x] I have specified the model used (with version and capability details) - [x] I have checked ROADMAP.md and confirmed this PR does not duplicate planned core work - [x] I have searched GitHub for duplicate or related PRs and linked them above - [x] I have either (a) linked existing issues with `Fixes: #` / `Closes #` / `Refs #` OR (b) described the issue in-PR following the relevant issue template - [x] I have not referenced internal/instance-local Paperclip issues or links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip` URLs) - [x] My branch name describes the change (e.g. `docs/...`, `fix/...`) and contains no internal Paperclip ticket id or instance-derived details - [ ] I have run tests locally and they pass - [x] I have added or updated tests where applicable - [x] I have updated relevant documentation to reflect my changes - [x] I have considered and documented any risks above - [x] All Paperclip CI gates are green - [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups - [x] I will address all Greptile and reviewer comments before requesting merge --------- Co-authored-by: Paperclip <noreply@paperclip.ing> --------- Co-authored-by: Paperclip <noreply@paperclip.ing> |
||
|
|
6b20cc97cc |
Add local fake runner supervision (#12095)
## Thinking Path > - Paperclip is the open source app people use to manage AI agents for work. > - Paperclip Runner needs a small local process model before it can connect to a production provider or server. > - The TypeScript PRP contracts now define the expected replay behavior. > - A second language implementation must produce the same result from the same fixtures. > - Local child processes also need bounded input, bounded output, and complete descendant cleanup. > - This pull request adds a package-local Rust runner, a scripted fake harness, and deterministic parity checks. > - The benefit is a testable process boundary with no production Paperclip behavior change. ## Linked Issues or Issue Description **Subsystem affected** Cross-cutting. This pull request adds private test infrastructure to `packages/paperclip-runner`. **Problem or motivation** The PRP contracts have no second implementation on `master`. There is also no small harness that can prove process cleanup, command idempotency, terminal reconciliation, or bounded JSONL handling without a production provider. **Proposed solution** Add a minimal Rust workspace. Add a local runner process, a scripted fake harness, a bounded process supervisor, and Rust conformance and replay checks. Keep all binaries package-local. Do not connect them to the Paperclip server. **Alternatives considered** The combined runner branch includes provider transports, durable networking, SDKs, labs, and server behavior. That change is too large for this review unit. A TypeScript-only harness would not test cross-language contract parity. **Roadmap alignment** This work supports the governed tools and self-healing run direction in `ROADMAP.md`. It does not add a user-facing runtime, adapter, endpoint, or rollout flag. **Additional context** Refs #12091 and #11962. Pull request #12091 was merged before this branch opened. This branch is based on the current `master`. Its delta is 25 files. ## What Changed - Added a minimal locked Rust workspace with only `serde` and `serde_json` dependencies. - Added a package-local `paperclip-runnerd` local mode and a scripted fake harness. - Added bounded controller input, harness input, subprocess output queues, line sizes, log retention, script sizes, script steps, and command history. - Added contiguous controller and harness sequence checks and equivalent-command replay handling. - Added process-group supervision that cleans up child processes and remaining descendants after forced or natural harness exit. - Added runner-owned terminal reconciliation for success, failure, interruption, cancellation, controller closure, and protocol failure. - Added Rust conformance output and deterministic replay summaries for the shared PRP fixtures. - Added fake scripts for success, failure, interruption, interaction, duplicate terminal output, process cleanup, and oversized output. - Added package scripts and documentation for the Rust and cross-language checks. - Kept provider transport, server integration, semantic tools, and production runtime selection out of this pull request. ## Verification - `pnpm --filter @paperclipai/paperclip-runner check:all` passes. - TypeScript contract tests pass: 8 Node tests and 44 Vitest tests. - Rust tests pass: 20 unit tests, 2 local-runner tests, and 3 process-supervisor tests. - The Rust conformance and replay parity checks pass against the shared fixtures. - The natural-exit and forced-exit tests confirm that the harness and its worker process are stopped. - The oversized-frame test confirms that a harness frame above the configured limit is rejected. - `pnpm -r typecheck` passes after the final rebase to `master`. - `pnpm build` passes after the final rebase to `master`. - `pnpm check:token-gates` passes. - `git diff --check` passes. - The delta against `master` is 25 files. The package lockfile is unchanged. - `pnpm test:run` completed locally with 4,686 passing tests, 19 skipped tests, and 30 failures in 8 unchanged server test files. The failures are local macOS path-alias, listener, port-range, and workspace-runtime baseline failures. No changed-file test failed, and every applicable Linux CI shard passes. - Storybook visual regression skipped intentionally because this pull request changes no UI or story files. ## Risks Low production risk. No server code invokes the new binaries. The package remains private. The main risks are process leaks, unbounded local input, and cross-language drift. Bounded queues and sizes, process-group cleanup tests, fixture manifests, and parity checks cover these risks. I checked `ROADMAP.md`. This change is private test infrastructure for planned control-plane work. It does not duplicate a shipped or public product surface. ## Model Used OpenAI Codex with GPT-5 was used. The exact serving model ID and context size were not exposed. The model used high reasoning, repository tools, GitHub tools, and local code execution. ## Checklist - [x] I have included a thinking path that traces from project context to this change - [x] I have specified the model used (with version and capability details) - [x] I have checked ROADMAP.md and confirmed this PR does not duplicate planned core work - [x] I have searched GitHub for duplicate or related PRs and linked them above - [x] I have either (a) linked existing issues with `Fixes: #` / `Closes #` / `Refs #` OR (b) described the issue in-PR following the relevant issue template - [x] I have not referenced internal/instance-local Paperclip issues or links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip` URLs) - [x] My branch name describes the change (e.g. `docs/...`, `fix/...`) and contains no internal Paperclip ticket id or instance-derived details - [ ] I have run tests locally and they pass - [x] I have added or updated tests where applicable - [x] I have updated relevant documentation to reflect my changes - [x] I have considered and documented any risks above - [x] All Paperclip CI gates are green - [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups - [x] I will address all Greptile and reviewer comments before requesting merge --------- Co-authored-by: Paperclip <noreply@paperclip.ing> Co-authored-by: Paperclip <noreply@paperclip.ing> |
||
|
|
83fefaadd1 |
fix(grok_local): do not warn when the default model sentinel is unavailable (#12062)
## Thinking Path > - Paperclip is the open source app people use to manage AI agents for work. > - Each agent runs under an adapter. The `grok_local` adapter runs the Grok Build CLI. > - The adapter has an environment test. It probes the CLI and reports checks to the operator. > - `DEFAULT_GROK_LOCAL_MODEL` is `"grok-build"`. This value is a sentinel. It means "use the Grok CLI's own default model". > - `execute.ts` only passes `--model` when the configured model differs from the sentinel. So the sentinel is never sent to grok. > - The environment test still compared the sentinel to the models that `grok models` lists. Real grok never lists `grok-build`. > - So every probe emitted a false "Configured model not found" warning, even on a correctly configured agent. > - This pull request stops the false warning and keeps the real check for user-set models. > - The benefit is an accurate environment test: operators see a warning only when it is real. ## Linked Issues or Issue Description No public issue exists. The problem, in bug-report form: **What happened?** The `grok_local` environment test always warns `Configured model "grok-build" not found in available models`, even when the agent works. `grok-build` is the default sentinel, not a real model id, and it is never sent to the CLI. **Expected behavior** When the model is left at the default, the test reports the CLI's own default model as info and does not warn. It warns only when a user sets a real model that `grok models` does not list. **Steps to reproduce** 1. Create a `grok_local` agent and leave the model at its default. 2. Run the adapter environment test. 3. See the `grok_model_not_found` warning, although `grok models` and the hello probe succeed. **Agent adapter(s) involved** grok_local (Grok Build CLI). ## What Changed - `packages/adapters/grok-local/src/server/test.ts`: the model check now treats the default sentinel as valid and reports it as info (`Using the Grok CLI's default model (<default>)`). It still warns when an explicitly configured, non-sentinel model is absent from the discovered list. This matches `execute.ts`, which never sends the sentinel to grok. - `packages/adapters/grok-local/src/server/test.test.ts`: adds a test that the default sentinel does not warn when it is absent from the real model list, and a test that a real, unavailable model still warns. ## Verification - `pnpm exec vitest run packages/adapters/grok-local/src/server/test.test.ts` — 5 passed. ## Risks Low risk. The change only affects one adapter's environment-test reporting. It does not change how runs pass `--model`. No schema, no runtime behavior change. ## Model Used Claude Fable 5 (`claude-fable-5`), extended thinking, with tool use and code execution. ## Checklist - [x] I have included a thinking path that traces from project context to this change - [x] I have specified the model used (with version and capability details) - [x] I have checked ROADMAP.md and confirmed this PR does not duplicate planned core work - [x] I have searched GitHub for duplicate or related PRs and linked them above - [x] I have either (a) linked existing issues OR (b) described the issue in-PR following the relevant issue template - [x] I have not referenced internal/instance-local Paperclip issues or links - [x] My branch name describes the change and contains no internal Paperclip ticket id - [x] I have run tests locally and they pass - [x] I have added or updated tests where applicable - [x] I have updated relevant documentation to reflect my changes (n/a — no doc change) - [x] I have considered and documented any risks above - [ ] All Paperclip CI gates are green - [ ] Greptile is 5/5 with no open P2s, recommendations, or follow-ups - [ ] I will address all Greptile and reviewer comments before requesting mergecanary/v2026.824.0-canary.5 |
||
|
|
0dfa0fb988 |
ci: refresh general-server shard duration manifest (#12075)
<!-- Write all pull request text in Simplified Technical English (ASD-STE100). --> ## Thinking Path > - Paperclip is the open source app people use to manage AI agents for work > - The PR verify workflow gates every pull request; its slowest check sets the feedback time for all contributors > - The general-server test lane splits its vitest suites across five runners with a duration-weighted partition (`scripts/general-server-shard.mjs`) > - The partition reads a duration manifest that was sampled on 2026-08-04, when the lane had 279 suites and 946s of serial time > - The lane has since grown to 405 suites and 1274s; 126 suites had no recorded duration and one suite grew from 37s to 123s > - The stale weights made the partition uneven: in the fully green actions run 32708351172, "General tests (server (2/5))" ran 364s and was the slowest check in the whole run, while sibling shards ran 292-330s > - This pull request refreshes the manifest with per-suite durations measured from that same run > - The benefit is a level five-shard split (255s ±1s of predicted suite time per shard), which removes ~50s from the slowest PR check ## Linked Issues or Issue Description **Describe the current behavior** In the fully green PR actions run [32708351172](https://github.com/paperclipai/paperclip/actions/runs/32708351172) (2026-08-24), the check "General tests (server (2/5))" completed in 364s. Its test step ran 315s while sibling shards ran 241-276s. It was the slowest check in the run. **Describe the improvement** The duration manifest `scripts/general-server-shard-durations.json` is stale. It holds 279 suites sampled on 2026-08-04, but the lane now has 405 suites. The 126 unknown suites fall back to the median weight (~1.3s), and `server/src/__tests__/workspace-runtime.test.ts` grew from 37.4s to 123.3s. The partition therefore predicts a level split but produces an uneven one. Refreshing the manifest restores the level split without any code change. **Expected impact** All five server shards level at ~255s of predicted suite time (~310s job time). The slowest PR check drops from 364s to about 317s, so the PR critical path improves by roughly 50s. ## What Changed - Regenerated `scripts/general-server-shard-durations.json` from actions run 32708351172 (2026-08-24): 405 suites, 1274s total serial time (was 279 suites, 946s from 2026-08-04) - Updated the `$comment` field to name the new sample run and date - No code changes; the partition logic in `scripts/general-server-shard.mjs` is untouched ## Verification - Parsed all five "General tests (server (n/5))" job logs from run 32708351172 with the consecutive-completion-timestamp method described in the manifest `$comment`; asserted that the parsed suite set equals the exact file list that `run-vitest-stable.mjs` collects (405/405, no misses, no extras) - Ran `node scripts/run-vitest-stable.mjs --mode general --group general-server --shard-index N --shard-count 5 --dry-run` for N=0..4 with the new manifest: each shard predicts 255s (±1s) of suite time, and the five shards form a complete, non-overlapping cover of all 405 suites - Ran `node --test ./scripts/__tests__/run-vitest-stable-shard.test.mjs`: 13/13 pass ## Risks - Low risk. The change is data-only. Wrong weights cannot break correctness: the partition always covers every suite exactly once, so the worst case of a bad weight is an uneven shard, which is the current state. ## Model Used - Claude (Anthropic), model ID `claude-fable-5`, agentic coding session with tool use (Claude Code / Claude Agent SDK) ## Checklist - [x] I have included a thinking path that traces from project context to this change - [x] I have specified the model used (with version and capability details) - [x] I have checked ROADMAP.md and confirmed this PR does not duplicate planned core work - [x] I have searched GitHub for duplicate or related PRs and linked them above - [x] I have either (a) linked existing issues with `Fixes: #` / `Closes #` / `Refs #` OR (b) described the issue in-PR following the relevant issue template - [x] I have not referenced internal/instance-local Paperclip issues or links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip` URLs) - [x] My branch name describes the change (e.g. `docs/...`, `fix/...`) and contains no internal Paperclip ticket id or instance-derived details - [x] I have run tests locally and they pass - [x] I have added or updated tests where applicable (no code change; existing partition tests pass) - [x] I have updated relevant documentation to reflect my changes (manifest `$comment` updated) - [x] I have considered and documented any risks above - [x] All Paperclip CI gates are green - [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups - [x] I will address all Greptile and reviewer comments before requesting merge Related prior work: #11528 (balanced the serialized server shards by recorded duration), #10923 (split serialized tests into five shards), #11156 (split workspaces-a into two shards). Co-authored-by: Claude <noreply@paperclip.ing>canary/v2026.824.0-canary.4 |
||
|
|
87d68f476b |
fix: harden the sandbox bridge gateway against crashes and queue wedge (#12060)
## Thinking Path > - Paperclip is the open source app people use to manage AI agents for work > - Agents on remote sandbox targets reach the Paperclip API through the sandbox callback bridge: a loopback HTTP gateway inside the sandbox queues request files for a host-side worker > - The gateway process has no supervisor: nothing inside the sandbox respawns it, so a crash leaves a dead loopback port for the rest of the run > - The gateway also never cleaned up request files whose responses never arrived, so a stalled host wedged the queue at its depth cap and every later request got an immediate 503 > - #12052 made the host-side worker survive transient faults; this pull request hardens the other half of the relay > - The benefit is that a gateway fault degrades one request instead of severing the agent from the control plane until run end ## Linked Issues or Issue Description Refs #12052 (host-side worker half of the same relay). Refs #9904 and #8977 (adjacent bridge behavior). No public issue exists for this defect. The description below follows the bug report template. **What happened?** During a staging run, an agent's API calls to the bridge's loopback port began failing at the connection level (curl reported HTTP 000) partway through the run. A dead gateway process is the only mechanism that produces connection-level failures on that port, and nothing restarts it. Separately, request files for timed-out requests stayed in the queue; after 64 accumulated, the gateway answered every request with `503 Bridge request queue is full.` until the run ended. **Expected behavior** An uncaught fault in the gateway must not kill the loopback listener. A request that times out must not leave its file counting toward the queue-depth cap. A queue full of orphaned files must recover instead of rejecting until run end. **Steps to reproduce** 1. Start a remote-sandbox run and stop the host-side bridge worker. 2. Send requests to the gateway until they time out; the request files stay in `requests/`. 3. After 64 such files, every request gets an immediate 503, even after the host recovers. 4. Independently, raise any uncaught exception in the gateway process; the loopback port dies for the rest of the run. ## What Changed - The generated gateway source installs global `uncaughtException` / `unhandledRejection` handlers that log to stderr (already redirected to `logs/bridge.log`) and keep serving. The relay holds no state a fault can corrupt beyond the one request it interrupted. - Survival is gated on readiness: before the gateway has written its readiness file (file mode) or sent its READY frame (duplex mode), the same handlers exit(1) instead. A startup fault (failed bind, failed readiness write) means the process can never serve, and surviving there would only leave an un-ready zombie while the host waits out its readiness poll. - The file gateway attaches an explicit `error` listener to its server and pins the event loop with a keepalive until the bind settles. Newer Node runtimes do not reliably surface a failed bind through `uncaughtException` in this shape: the process can drain and exit 0 before the error event is delivered (reproduced on Node 24/25; Node 22 delivered it). The duplex gateway already had an explicit listener. - A request that times out waiting for the host now deletes its own request file. The host's response write is guarded on that file, so the removal also signals that no caller waits anymore. - At the queue-depth cap, the gateway sweeps request files older than the response deadline (orphans from killed callers or a previous gateway process) before rejecting with 503. - Host-side, `processRequestFile` treats a request file that vanished before the read as the benign caller-gave-up race and skips it quietly instead of escalating into the recovery pass. ## Verification - `npx vitest run packages/adapter-utils/src/sandbox-callback-bridge.test.ts` — 43 passed, verified on both Node 22 and Node 25. - New end-to-end test: with no worker running, a request times out (502), its file is cleaned, and the same gateway then serves a 200 once a worker starts — no wedge, no dead port. - New end-to-end test: with `maxQueueDepth: 1` and a backdated orphan file at the cap, the gateway sweeps the orphan and admits the request instead of answering 503. - New worker test: a request file that vanishes before the read is skipped without a handler call, a response write, or a run-level error. - New generated-source test: spawned directly against an already-occupied port, the gateway exits 1 promptly with the `EADDRINUSE` fault on stderr instead of lingering un-ready (or exiting 0 silently, the pre-existing behavior on Node 24/25). - A pin keeps the crash handlers, the readiness gate, and the sweep in the generated source. - `pnpm --filter @paperclipai/adapter-utils typecheck`. ## Risks - Keeping a Node process alive after `uncaughtException` is normally suspect; here the alternative is a dead loopback port for the rest of the run, and the gateway is a stateless per-request relay. The fault is logged with its stack to `bridge.log`, and survival applies only after readiness — startup faults still fail fast. - Deleting a timed-out request file could race a host that is mid-processing. The host's response write is already guarded on request-file existence, and the new host-side skip treats the vanished file as a no-op, so no duplicate mutation path is introduced. - The stale sweep runs only at the depth cap and only removes files older than the response deadline plus a 2 s grace, so a live caller's file is never swept. - Orphaned response files (host responded after the caller gave up) still linger; that pre-existing minor leak is unchanged here. ## Model Used - Claude Fable 5 (Anthropic), model id `claude-fable-5`, extended thinking enabled, agentic tool use via Claude Code (CLI harness), 200k context window. ## Checklist - [x] I have included a thinking path that traces from project context to this change - [x] I have specified the model used (with version and capability details) - [x] I have checked ROADMAP.md and confirmed this PR does not duplicate planned core work - [x] I have searched GitHub for duplicate or related PRs and linked them above - [x] I have either (a) linked existing issues with `Fixes: #` / `Closes #` / `Refs #` OR (b) described the issue in-PR following the relevant issue template - [x] I have not referenced internal/instance-local Paperclip issues or links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip` URLs) - [x] My branch name describes the change (e.g. `docs/...`, `fix/...`) and contains no internal Paperclip ticket id or instance-derived details - [x] I have run tests locally and they pass - [x] I have added or updated tests where applicable - [x] I have updated relevant documentation to reflect my changes - [x] I have considered and documented any risks above - [x] All Paperclip CI gates are green - [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups - [x] I will address all Greptile and reviewer comments before requesting merge |