mirror of
https://github.com/paperclipai/paperclip.git
synced 2026-10-07 07:23:08 +02:00
a661caf74e704f7700a8b8a1e79b76ebd04e3483
4151
Commits
| Author | SHA1 | Message | Date | |
|---|---|---|---|---|
|
|
a661caf74e |
chore(deps): bump motion from 12.43.0 to 13.1.1 (#12255)
Bumps [motion](https://github.com/motiondivision/motion) from 12.43.0 to 13.1.1. <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/motiondivision/motion/blob/main/CHANGELOG.md">motion's changelog</a>.</em></p> <blockquote> <h2>[13.1.1] 2026-08-18</h2> <h3>Fixed</h3> <ul> <li>Guard animation <code>window</code> access in non-browser runtimes.</li> <li><code>AnimatePresence</code>: Improved compat with React 19 strict mode.</li> </ul> <h2>[13.1.0] 2026-08-10</h2> <h3>Added</h3> <ul> <li><code>Reorder</code>: Multidimensional reorder.</li> <li><code>Reorder</code>: Automatic axis detection.</li> <li><code>Reorder</code>: RTL support.</li> </ul> <h2>[13.0.0] 2026-08-05</h2> <h3>Changed</h3> <ul> <li>Removed optional <code>@emotion/is-prop-valid</code> dependency in favour of explicit <code><MotionConfig isValidProp={isPropValid}></code>.</li> </ul> <h3>Fixed</h3> <ul> <li>Hardware-accelerated SVG elements correctly apply final style on animation complete.</li> <li><code>AnimatePresence</code>: Ensure nodes are marked as safe to remove when rendering <code>propagate</code> with no <code>motion</code> children.</li> </ul> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/motiondivision/motion/commit/1b037b0032578b52af94b06ff3920bfa0aaa5e36"><code>1b037b0</code></a> v13.1.1</li> <li><a href="https://github.com/motiondivision/motion/commit/d734481aca2a7c45a244155f9ce3a2e56a2c69a6"><code>d734481</code></a> Updating changelog</li> <li><a href="https://github.com/motiondivision/motion/commit/9b9190da212b0f633735c5a7ea7c8d73f4624436"><code>9b9190d</code></a> Latest</li> <li><a href="https://github.com/motiondivision/motion/commit/c07d12e2bfb581482c7e6c82a2b3b4c2394f8d08"><code>c07d12e</code></a> Merge pull request <a href="https://redirect.github.com/motiondivision/motion/issues/3752">#3752</a> from motiondivision/fix-3746-animatepresence-strictm...</li> <li><a href="https://github.com/motiondivision/motion/commit/b497f1d2ac2ffc8139f988101d732e8cd7d4733a"><code>b497f1d</code></a> Merge branch 'main' into fix-3746-animatepresence-strictmode-remount</li> <li><a href="https://github.com/motiondivision/motion/commit/bbabb0066427bc4d91850504e01e3949f03f8857"><code>bbabb00</code></a> Merge pull request <a href="https://redirect.github.com/motiondivision/motion/issues/3751">#3751</a> from motiondivision/worktree-fix-issue-3735</li> <li><a href="https://github.com/motiondivision/motion/commit/06540faa2cb80ddd1d9103cd736a56ed524cd0e2"><code>06540fa</code></a> Merge branch 'main' into worktree-fix-issue-3735</li> <li><a href="https://github.com/motiondivision/motion/commit/adaf7a4e5368d704ea350669f6ac674fb26ff270"><code>adaf7a4</code></a> v13.1.0</li> <li><a href="https://github.com/motiondivision/motion/commit/e713759e5095298069b37701395083107eb4fc97"><code>e713759</code></a> Updating changelog</li> <li><a href="https://github.com/motiondivision/motion/commit/bc81c031212416f8aeee75d125a1431016a4e6bf"><code>bc81c03</code></a> Updating publish</li> <li>Additional commits viewable in <a href="https://github.com/motiondivision/motion/compare/v12.43.0...v13.1.1">compare view</a></li> </ul> </details> <br /> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>canary/v2026.904.0-canary.0 |
||
|
|
1f92011f99 |
chore(deps): bump dompurify from 3.4.13 to 3.4.14 (#12266)
Bumps [dompurify](https://github.com/cure53/DOMPurify) from 3.4.13 to 3.4.14. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/cure53/DOMPurify/releases">dompurify's releases</a>.</em></p> <blockquote> <h2>DOMPurify 3.4.14</h2> <ul> <li>Fixed an issue with possible bypasses when risky tags are allow-listed, thanks <a href="https://github.com/AlirezaRouhbakhsh"><code>@AlirezaRouhbakhsh</code></a></li> <li>Fixed a couple of edge cases with mixed document contexts, thanks <a href="https://github.com/fishjojo1"><code>@fishjojo1</code></a></li> <li>Added the SVG <code>pointer-events</code> and <code>vector-effect</code> presentation attributes to the allow-list, thanks <a href="https://github.com/Jaybhade"><code>@Jaybhade</code></a></li> <li>Conducted another refactoring run, removed dead branches and duplicated logic, flattened attribute validation</li> <li>Updated the documentation in several spots, README, wiki, etc., thanks <a href="https://github.com/Akokonunes"><code>@Akokonunes</code></a></li> <li>Updated several development dependencies and CI workflow actions</li> </ul> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/cure53/DOMPurify/commit/4e6fe24173f1a85eafacd95e3c82966e29d34d49"><code>4e6fe24</code></a> release: 3.4.14 (<a href="https://redirect.github.com/cure53/DOMPurify/issues/1587">#1587</a>)</li> <li>See full diff in <a href="https://github.com/cure53/DOMPurify/compare/3.4.13...3.4.14">compare view</a></li> </ul> </details> <br /> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |
||
|
|
d95c71027d |
chore(deps-dev): bump @types/react-dom from 19.2.4 to 19.2.5 (#12253)
Bumps [@types/react-dom](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/react-dom) from 19.2.4 to 19.2.5. <details> <summary>Commits</summary> <ul> <li>See full diff in <a href="https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/react-dom">compare view</a></li> </ul> </details> <br /> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |
||
|
|
03faa644fb |
ci(runner): inspect Daytona image metadata remotely (#12795)
## Thinking Path The reused Daytona image path already verifies the signed immutable digest. It then downloads every filesystem layer only to read OCI config fields. Buildx can retrieve the same config from that immutable digest without pulling the layers. The assertions can therefore stay intact while removing the expensive transfer. ## What Changed - inspect the signed immutable Daytona image config through Buildx after GHCR logout - preserve digest, source revision, content ID, platform, user, and provider-pack assertions - extend the workflow contract test for the metadata-only path ## Verification - Daytona image and workflow security tests: 10 passed - Prettier and git diff checks passed - observed full pull/prune cost: about 4m55s; metadata inspection: about one second ## Risks The current image has one runnable linux/amd64 platform plus its attestation. A future genuinely multi-platform image would need explicit linux/amd64 selection. ## Model Used Codex (GPT-5) |
||
|
|
871f7d1124 |
fix(ui): polish core navigation and task layout (#12793)
<!-- Write all pull request text in Simplified Technical English (ASD-STE100): short sentences, one instruction per sentence, simple approved vocabulary, and the active voice. --> ## Thinking Path > - Paperclip is the open source app people use to manage AI agents for work. > - Operators use the main navigation, contextual navigation, and task chat throughout the product. > - The recent core UI refactor left uneven spacing and inconsistent navigation styles. > - The Apps label also did not match the Connectors product language. > - The account area did not provide a clear direct path for feedback. > - This pull request aligns these related core UI surfaces and preserves their existing behavior. > - The benefit is a more consistent interface with clearer navigation and balanced task-chat layout. ## Linked Issues or Issue Description **What existing behavior does this improve?** This improves the core sidebar, Settings navigation, Connectors catalog, task-chat layout, and account controls. **Subsystem affected** `ui/` — React and Vite board UI. **Current behavior** The task chat had uneven edge treatment. Settings used a separate contextual-navigation style. Apps used inconsistent product labels. The account footer did not expose a direct feedback control. **Proposed behavior** The task chat keeps balanced content padding while its scrollbar sits at the properties boundary. Settings replaces the primary sidebar with a matching navigation surface and a Back to app link. Apps uses Connectors and Browse labels. The account footer provides a dedicated feedback icon with a tooltip. **Reason and benefit** These changes make related navigation and layout patterns predictable. They reduce duplicate labels and improve access to feedback. **Breaking changes** None. Routes, APIs, and stored data do not change. ## What Changed - Balanced the task-chat content gutter and moved its scrollbar to the properties-panel boundary. - Reworked Settings navigation to replace the main sidebar and use the shared primary-sidebar style. - Added a Back to app navigation item to Settings. - Renamed Apps to Connectors in the main navigation and added the `Unplug` icon. - Renamed the Connectors contextual item to Browse. - Added the Connectors top-level header and aligned the search field with the connector cards. - Added account-footer hover states and a direct feedback flag with a Share feedback tooltip. - Removed the duplicate Feedback item from the account popover. - Added regression coverage for each changed UI surface. ## Verification - `pnpm --filter @paperclipai/ui exec vitest run src/components/AppsSidebar.test.tsx src/components/CompanySettingsSidebar.test.tsx src/components/Layout.test.tsx src/components/Sidebar.test.tsx src/components/SidebarAccountMenu.test.tsx src/components/task-chat/TaskMessageScroller.test.tsx src/pages/apps/Browse.test.tsx` — 90 tests passed. - `pnpm --filter @paperclipai/ui typecheck` — passed. - `pnpm --filter @paperclipai/ui build` — passed. - `pnpm check:token-gates` — passed. - `git diff --check origin/master...HEAD` — passed. - `env PAPERCLIP_PLAYWRIGHT_CHANNEL=chrome PAPERCLIP_E2E_PORT=3201 pnpm exec playwright test --config tests/e2e/playwright.config.ts tests/e2e/apps-dark-mode-shots.spec.ts tests/e2e/sidebar-takeover.spec.ts` — 10 tests passed. - The full workspace typecheck and build reached the Rust runner and stopped because `cargo` is not installed on this machine. - The full test suite exposed unrelated server and workspace-runtime failures and was stopped after the affected suites completed. No changed UI test failed. - Manually verified the changed Settings, Connectors, task-chat, and account-menu surfaces in the running app. ## Risks - Low risk. The change affects layout and navigation presentation only. - The Settings sidebar now replaces the main sidebar by design. Users must use Back to app to return to the application navigation. - The task scrollbar offset depends on the existing responsive page gutters. Regression tests cover both narrow and desktop spacing. > For core feature work, check [`ROADMAP.md`](ROADMAP.md) first and discuss it in `#dev` before opening the PR. Feature PRs that overlap with planned core work may need to be redirected — check the roadmap first. See `CONTRIBUTING.md`. ## Model Used - OpenAI Codex, `gpt-5.6-sol`, extended reasoning with tool use and code execution. The host does not expose the context-window size. ## Checklist - [x] I have included a thinking path that traces from project context to this change - [x] I have specified the model used (with version and capability details) - [x] I have checked ROADMAP.md and confirmed this PR does not duplicate planned core work - [x] I have searched GitHub for duplicate or related PRs and linked them above - [x] I have either (a) linked existing issues with `Fixes: #` / `Closes #` / `Refs #` OR (b) described the issue in-PR following the relevant issue template - [x] I have not referenced internal/instance-local Paperclip issues or links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip` URLs) - [x] My branch name describes the change (e.g. `docs/...`, `fix/...`) and contains no internal Paperclip ticket id or instance-derived details - [ ] I have run tests locally and they pass - [x] I have added or updated tests where applicable - [x] I have updated relevant documentation to reflect my changes - [x] I have considered and documented any risks above - [x] All Paperclip CI gates are green - [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups - [x] I will address all Greptile and reviewer comments before requesting merge --------- Co-authored-by: Scott Tong <scott@scottsmbpm5max.lan> Co-authored-by: Paperclip <noreply@paperclip.ing>canary/v2026.903.0-canary.9 |
||
|
|
fa86407ad8 |
chore(deps): bump yjs from 13.6.29 to 13.6.32 (#12256)
Bumps [yjs](https://github.com/yjs/yjs) from 13.6.29 to 13.6.32. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/yjs/yjs/releases">yjs's releases</a>.</em></p> <blockquote> <h2>v13.6.32</h2> <ul> <li>fix <a href="https://redirect.github.com/yjs/yjs/issues/797">#797</a> - undomanager clears destroy handler 95e890d9</li> </ul> <hr /> <p><a href="https://github.com/yjs/yjs/compare/v13.6.31...v13.6.32">https://github.com/yjs/yjs/compare/v13.6.31...v13.6.32</a></p> <h2>v13.6.31</h2> <ul> <li>Merge branch &<a href="https://redirect.github.com/yjs/yjs/issues/39">#39</a>;ppiotrowicz-fix/757-undo-attr-redo&<a href="https://redirect.github.com/yjs/yjs/issues/39">#39</a>; into v13 1ddba7e4</li> <li>fix <a href="https://redirect.github.com/yjs/yjs/issues/757">#757</a> in v13 d9aaff72</li> <li>fix undoing setAttribute combined with delete corrupts remote state - closes <a href="https://redirect.github.com/yjs/yjs/issues/757">#757</a> 67c809ee</li> </ul> <hr /> <p><a href="https://github.com/yjs/yjs/compare/v13.6.30...v13.6.31">https://github.com/yjs/yjs/compare/v13.6.30...v13.6.31</a></p> <h2>v13.6.30</h2> <ul> <li>lint 0504939a</li> <li>fix mutation of DeleteItem in sortAndMergeDeleteSet - closes <a href="https://redirect.github.com/yjs/yjs/issues/767">#767</a> 5d5f1ad6</li> </ul> <hr /> <p><a href="https://github.com/yjs/yjs/compare/v13.6.29...v13.6.30">https://github.com/yjs/yjs/compare/v13.6.29...v13.6.30</a></p> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/yjs/yjs/commit/1ce38f75f786e4bc0b2cc9703afbc6eea8fe7859"><code>1ce38f7</code></a> 13.6.32</li> <li><a href="https://github.com/yjs/yjs/commit/95e890d99ac6b8462fc02722e60b1dbd17c9c29d"><code>95e890d</code></a> fix <a href="https://redirect.github.com/yjs/yjs/issues/797">#797</a> - undomanager clears destroy handler</li> <li><a href="https://github.com/yjs/yjs/commit/271330889b13eae102873bb417d6747a0ddd8b4a"><code>2713308</code></a> 13.6.31</li> <li><a href="https://github.com/yjs/yjs/commit/1ddba7e48cfa9cdf4c0c51b2a1bd22986a0e8704"><code>1ddba7e</code></a> Merge branch 'ppiotrowicz-fix/757-undo-attr-redo' into v13</li> <li><a href="https://github.com/yjs/yjs/commit/d9aaff72b246c0f2a5c07eaa4f685079fe9e6e5a"><code>d9aaff7</code></a> fix <a href="https://redirect.github.com/yjs/yjs/issues/757">#757</a> in v13</li> <li><a href="https://github.com/yjs/yjs/commit/67c809ee6b787984d7bf709df9900b93cccffb7e"><code>67c809e</code></a> fix undoing setAttribute combined with delete corrupts remote state - closes ...</li> <li><a href="https://github.com/yjs/yjs/commit/676cc334edb39867b74bd1f50a05eb85c8275d9b"><code>676cc33</code></a> 13.6.30</li> <li><a href="https://github.com/yjs/yjs/commit/0504939a753165d32b8d968d38639f959c834eae"><code>0504939</code></a> lint</li> <li><a href="https://github.com/yjs/yjs/commit/5d5f1ad6fa0a91603cbbb783184b2fdfa80eef7d"><code>5d5f1ad</code></a> fix mutation of DeleteItem in sortAndMergeDeleteSet - closes <a href="https://redirect.github.com/yjs/yjs/issues/767">#767</a></li> <li>See full diff in <a href="https://github.com/yjs/yjs/compare/v13.6.29...v13.6.32">compare view</a></li> </ul> </details> <br /> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |
||
|
|
daa2391021 |
chore(deps): bump @aws-sdk/client-s3 from 3.1120.0 to 3.1122.0 (#12261)
Bumps [@aws-sdk/client-s3](https://github.com/aws/aws-sdk-js-v3/tree/HEAD/clients/client-s3) from 3.1120.0 to 3.1122.0. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/aws/aws-sdk-js-v3/releases">@aws-sdk/client-s3's releases</a>.</em></p> <blockquote> <h2>v3.1122.0</h2> <h4>3.1122.0(2026-08-31)</h4> <h5>Documentation Changes</h5> <ul> <li><strong>client-controltower:</strong> Updated the descriptions for the AWS Control Tower ListEnabledControls API parameters to make them more accurate and intuitive. (<a href="https://github.com/aws/aws-sdk-js-v3/commit/c54ac4e6019f585fcf54a956b8d30e38c6cb1a86">c54ac4e6</a>)</li> </ul> <h5>New Features</h5> <ul> <li><strong>client-pinpoint-sms-voice-v2:</strong> AWS End User Messaging SMS now returns ConditionalBehavior on DescribeRegistrationFieldDefinitions, allowing you to programmatically discover which registration fields are required, optional, or disallowed based on the values of other fields in the same form. (<a href="https://github.com/aws/aws-sdk-js-v3/commit/9cbace13989c31d55c45812ee801a29cf90f00ed">9cbace13</a>)</li> <li><strong>client-customer-profiles:</strong> This release introduces new APIs for segment membership events allowing segment definition membership events to be exported to a kinesis stream for downstream processing. Additionally, includes new calculated attribute statistic and 2 new segment dimension types. (<a href="https://github.com/aws/aws-sdk-js-v3/commit/be1a9dab4280a118cd0e47c7aaacee919e01c02b">be1a9dab</a>)</li> <li><strong>client-sagemaker:</strong> Amazon SageMaker Batch Transform now supports G6e instances, powered by NVIDIA L40S Tensor Core GPUs. G6e instances are the most cost-efficient GPU instances for deploying generative AI models and the highest-performance GPU instances for spatial computing workloads. (<a href="https://github.com/aws/aws-sdk-js-v3/commit/b063cf77a91073f3b32a33a1386f20978b646059">b063cf77</a>)</li> <li><strong>client-quicksight:</strong> This release adds support for managing apps in Amazon QuickSight with ListApps, SearchApps, DescribeApp, DescribeAppPermissions, UpdateAppPermissions, and DeleteApp (<a href="https://github.com/aws/aws-sdk-js-v3/commit/98a49570d50f800f74fce9014ec4ab0985fc0775">98a49570</a>)</li> <li><strong>client-connect:</strong> Added support for global routing on Amazon Connect Global Resiliency instances. New APIs GetCrossRegionRouting and UpdateCrossRegionRouting allow you to view and control cross-region contact routing between linked instances, so both Regions are active at all times. (<a href="https://github.com/aws/aws-sdk-js-v3/commit/ce41026342e42c9454be6c68ef24fe721f8149f2">ce410263</a>)</li> <li><strong>client-agent-registry-control:</strong> AWS Agent Registry becomes Generally Available (<a href="https://github.com/aws/aws-sdk-js-v3/commit/e41244e9301730ac7632a4e5f67bb2933156769c">e41244e9</a>)</li> <li><strong>client-kinesis:</strong> Adds support for data delivery to Amazon S3 Tables (Apache Iceberg) and general purpose Amazon S3 buckets with new CreateChannel, UpdateChannel, DeleteChannel, DescribeChannel, and ListChannels APIs for Amazon Kinesis Data Streams. (<a href="https://github.com/aws/aws-sdk-js-v3/commit/64ebb058e0b7ae64bd240c7ae325099fc64ab43a">64ebb058</a>)</li> <li><strong>client-agent-registry:</strong> AWS Agent Registry becomes Generally Available (<a href="https://github.com/aws/aws-sdk-js-v3/commit/e60306f198e7ad374089161aa448602dab590287">e60306f1</a>)</li> <li><strong>client-devops-agent:</strong> Adds support for Slack bidirectional communication configuration in AWS DevOps Agent agent spaces. (<a href="https://github.com/aws/aws-sdk-js-v3/commit/75bc6d6da3f88c398be5a737ad01d8d631773fcf">75bc6d6d</a>)</li> <li><strong>client-kafkaconnect:</strong> Amazon MSK Connect now supports restarting newly created connectors via the asynchronous RestartConnector API. Restart all tasks or only failed tasks, while preserving configuration and committed offsets. This returns a connector operation ARN that you can track with DescribeConnectorOperation. (<a href="https://github.com/aws/aws-sdk-js-v3/commit/8771afafd4c1723c29c1745ff8683145a837bda2">8771afaf</a>)</li> <li><strong>client-support:</strong> AWS Support now allows up to 10 attachments (150 MB each) per case correspondence, up from 3 at 5 MB. Customers can share large diagnostic logs, heap dumps, and packet captures directly in cases to reduce back-and-forth and speed up resolution. Available in US East, US West, and Europe (Ireland). (<a href="https://github.com/aws/aws-sdk-js-v3/commit/4ddd79c10633ffa37d957d96313bdffddcba4867">4ddd79c1</a>)</li> <li><strong>client-workspaces-instances:</strong> Amazon WorkSpaces Core managed instances now support nested virtualization. Customers can enable nested virtualization with supported instance types at launch via CpuOptions.NestedVirtualization in CreateWorkspaceInstance to run hypervisors and virtual machines inside their WorkSpaces Instance. (<a href="https://github.com/aws/aws-sdk-js-v3/commit/29587d1236c8805f7f72305e06a011bfc48ae55c">29587d12</a>)</li> </ul> <hr /> <p>For list of updated packages, view <strong>updated-packages.md</strong> in <strong>assets-3.1122.0.zip</strong></p> <h2>v3.1121.0</h2> <h4>3.1121.0(2026-08-28)</h4> <h5>New Features</h5> <ul> <li><strong>client-ecs:</strong> Amazon Elastic Container Service - This release adds support for early success criteria on ECS rolling deployments, letting deployment complete once a configurable percentage of tasks are healthy, with configurable BLOCKING (required) or DEFERRED (asynchronous) cleanup of previous service revisions. (<a href="https://github.com/aws/aws-sdk-js-v3/commit/ef22d750f27bd01ff6b88b8e1cc0f34efea8d171">ef22d750</a>)</li> <li><strong>client-healthlake:</strong> New HealthLake API, RestoreFHIRDatastore, providing the capability to restore active datastores to a point in time within the last 30 days or recover a deleted datastore from the delete snapshot. (<a href="https://github.com/aws/aws-sdk-js-v3/commit/6249174262656b83d0bba16cf59ba892b849a707">62491742</a>)</li> <li><strong>client-bedrock-agentcore:</strong> AgentCore Memory now supports direct ingestion into long-term memory via IngestData API (<a href="https://github.com/aws/aws-sdk-js-v3/commit/20d652de566b291145576f6e4c24a7c8da4ea2be">20d652de</a>)</li> <li><strong>client-partnercentral-selling:</strong> Releasing PARC, new APN Program that lets sellers add solftware revenue details to aws opportunity summary (<a href="https://github.com/aws/aws-sdk-js-v3/commit/2b6350f01269baa5e6d079a93ff9f6b0804d982f">2b6350f0</a>)</li> <li><strong>client-cognito-identity-provider:</strong> Adds two new operations - GetClientToken which allows M2M auth through the SDK, and DescribeTermsByClient to find which Terms are associated with a user-pool client without knowing the Terms resource id. (<a href="https://github.com/aws/aws-sdk-js-v3/commit/86dffd282f1ac269d1268f9a75f1550df61c5cc6">86dffd28</a>)</li> <li><strong>client-bedrock-agent:</strong> Adds an optional syncSchedule field to CreateDataSource and UpdateDataSource for Managed Knowledge Bases data source connectors, so a data source can sync automatically on a daily, weekly, or monthly schedule. (<a href="https://github.com/aws/aws-sdk-js-v3/commit/a8d3714a751f972452553ba631a98176e6ea584c">a8d3714a</a>)</li> </ul> <hr /> <p>For list of updated packages, view <strong>updated-packages.md</strong> in <strong>assets-3.1121.0.zip</strong></p> </blockquote> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/aws/aws-sdk-js-v3/blob/main/clients/client-s3/CHANGELOG.md">@aws-sdk/client-s3's changelog</a>.</em></p> <blockquote> <h1><a href="https://github.com/aws/aws-sdk-js-v3/compare/v3.1121.0...v3.1122.0">3.1122.0</a> (2026-08-31)</h1> <p><strong>Note:</strong> Version bump only for package <code>@aws-sdk/client-s3</code></p> <h1><a href="https://github.com/aws/aws-sdk-js-v3/compare/v3.1120.0...v3.1121.0">3.1121.0</a> (2026-08-28)</h1> <p><strong>Note:</strong> Version bump only for package <code>@aws-sdk/client-s3</code></p> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/aws/aws-sdk-js-v3/commit/e1cf460a1e4707e137931804e3e7b71a8392f227"><code>e1cf460</code></a> Publish v3.1122.0</li> <li><a href="https://github.com/aws/aws-sdk-js-v3/commit/e53a25aafbdd772c90d26471dc271e383f1daf71"><code>e53a25a</code></a> Publish v3.1121.0</li> <li>See full diff in <a href="https://github.com/aws/aws-sdk-js-v3/commits/v3.1122.0/clients/client-s3">compare view</a></li> </ul> </details> <br /> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |
||
|
|
a0028d7e1b |
chore(deps-dev): bump vitest from 4.1.10 to 4.1.11 (#12262)
Bumps [vitest](https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest) from 4.1.10 to 4.1.11. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/vitest-dev/vitest/releases">vitest's releases</a>.</em></p> <blockquote> <h2>v4.1.11</h2> <h3> 🐞 Bug Fixes</h3> <ul> <li>Revive global concurrency limit for test lifecycle [backport to v4] - by <a href="https://github.com/sheremet-va"><code>@sheremet-va</code></a> and <a href="https://github.com/hi-ogawa"><code>@hi-ogawa</code></a> in <a href="https://redirect.github.com/vitest-dev/vitest/issues/10992">vitest-dev/vitest#10992</a> <a href="https://github.com/vitest-dev/vitest/commit/5146df80b"><!-- raw HTML omitted -->(5146d)<!-- raw HTML omitted --></a></li> <li><strong>browser</strong>: <ul> <li>Encode iframeId in tester iframe URL [backport to v4] - by <a href="https://github.com/sheremet-va"><code>@sheremet-va</code></a>, <strong>Pduhard</strong> and <strong>Claude Opus 4.8</strong> in <a href="https://redirect.github.com/vitest-dev/vitest/issues/10955">vitest-dev/vitest#10955</a> <a href="https://github.com/vitest-dev/vitest/commit/10b2cd201"><!-- raw HTML omitted -->(10b2c)<!-- raw HTML omitted --></a></li> <li>Trigger playwright/chromium gc on lower disk availability [backport to v4] - by <a href="https://github.com/hi-ogawa"><code>@hi-ogawa</code></a>, <strong>Hiroshi Ogawa</strong> and <strong>OpenCode</strong> in <a href="https://redirect.github.com/vitest-dev/vitest/issues/10951">vitest-dev/vitest#10951</a> <a href="https://github.com/vitest-dev/vitest/commit/9851dbc41"><!-- raw HTML omitted -->(9851d)<!-- raw HTML omitted --></a></li> </ul> </li> <li><strong>mocker</strong>: <ul> <li>Restrict redirect mocks to the fs allowlist [backport to v4] - by <a href="https://github.com/sheremet-va"><code>@sheremet-va</code></a> in <a href="https://redirect.github.com/vitest-dev/vitest/issues/10974">vitest-dev/vitest#10974</a> <a href="https://github.com/vitest-dev/vitest/commit/fe5a11d3c"><!-- raw HTML omitted -->(fe5a1)<!-- raw HTML omitted --></a></li> </ul> </li> </ul> <h5> <a href="https://github.com/vitest-dev/vitest/compare/v4.1.10...v4.1.11">View changes on GitHub</a></h5> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/vitest-dev/vitest/commit/9bd8d464e6328c567c2dbcd8fdd977d57a9425c2"><code>9bd8d46</code></a> chore: release v4.1.11 (<a href="https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest/issues/10995">#10995</a>)</li> <li><a href="https://github.com/vitest-dev/vitest/commit/9851dbc41c286a30abfb6b29cce65f3e5b7b40a1"><code>9851dbc</code></a> fix(browser): trigger playwright/chromium gc on lower disk availability [back...</li> <li>See full diff in <a href="https://github.com/vitest-dev/vitest/commits/v4.1.11/packages/vitest">compare view</a></li> </ul> </details> <br /> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |
||
|
|
3e28ec5f4c |
chore(deps): bump react-i18next from 17.0.11 to 17.0.12 (#12263)
Bumps [react-i18next](https://github.com/i18next/react-i18next) from 17.0.11 to 17.0.12. <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/i18next/react-i18next/blob/master/CHANGELOG.md">react-i18next's changelog</a>.</em></p> <blockquote> <h2>17.0.12</h2> <ul> <li>fix(IcuTrans): key-less <code>icu.macro</code> nodes (<code><Trans>Welcome, {name}!</Trans></code>, <code><Select></code>, <code><Plural></code> without <code>i18nKey</code>) rendered an empty string since 17.0.0. The macro now emits <code><IcuTrans defaultTranslation="…"></code> without a key and <code>IcuTrans</code> passed <code>undefined</code> to <code>t()</code>, which returns <code>''</code>. Like <code>Trans</code>, <code>IcuTrans</code> now uses <code>defaultTranslation</code> as the key when <code>i18nKey</code> is not provided.</li> </ul> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/i18next/react-i18next/commit/ea721fb58dccf1c569015969e5689c374ae20e4b"><code>ea721fb</code></a> 17.0.12</li> <li><a href="https://github.com/i18next/react-i18next/commit/6c2a71e1c0a67b4265a89d177dfc5ebf87e62b8d"><code>6c2a71e</code></a> fix(IcuTrans): use defaultTranslation as key when no i18nKey is given</li> <li><a href="https://github.com/i18next/react-i18next/commit/258c96daab2c332da0904469d2d7b53ae6da202b"><code>258c96d</code></a> chore(examples): upgrade all example apps off unmaintained toolchains</li> <li><a href="https://github.com/i18next/react-i18next/commit/b8677c805cd6634902bae49b99143a8fa60a02fe"><code>b8677c8</code></a> chore: update dependencies to close dependabot alerts</li> <li><a href="https://github.com/i18next/react-i18next/commit/aa9c92bd7fdbe638d970ef34c35eb1712fa0912d"><code>aa9c92b</code></a> docs: point Trans component links at the current docs (<a href="https://redirect.github.com/i18next/react-i18next/issues/1929">#1929</a>)</li> <li>See full diff in <a href="https://github.com/i18next/react-i18next/compare/v17.0.11...v17.0.12">compare view</a></li> </ul> </details> <br /> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |
||
|
|
2392a9895e |
fix(ui): drop the "Open invite" action from the invites section (#12787)
## Thinking Path > - Paperclip is the open source app people use to manage AI agents for work > - The Members page has an Invites tab where an admin mints single-use invite links for people > - After a link is created, the section offers two actions: "Copy link" and "Open invite" > - "Open invite" opens the inviter's own single-use link in a new tab, which is never what the inviter means — the link is for the invitee > - This pull request removes the "Open invite" button and keeps "Copy link" as the only action > - The benefit is that the section no longer invites a mistake, and the one remaining action matches the section's purpose ## Linked Issues or Issue Description No existing issue. Description follows the enhancement template: **What existing behavior does this improve?** The latest-invite panel on the Members page Invites tab. **Subsystem affected** UI — `ui/src/components/access/InvitesSection.tsx`. **Current behavior** After an invite is created, the panel shows a "Copy link" button and an "Open invite" button. "Open invite" opens the invite URL in a new tab as the inviter. **Proposed behavior** The panel shows only "Copy link". The invite URL field itself stays visible and selectable. **Reason and benefit** Invite links are single-use and addressed to the invitee. The inviter opening their own link at best shows them their own landing page and at worst walks the link toward consumption. Removing the button removes the trap. **Breaking changes** None. No API or data change. ## What Changed - Removed the "Open invite" anchor button from `InvitesSection`. - Removed the now-unused `ExternalLink` icon import. - The component test now asserts the action is absent. ## Verification - `cd ui && npx vitest run src/components/access/InvitesSection.test.tsx` — 3 tests pass. - `cd ui && npx tsc -p tsconfig.json --noEmit` — clean. - Manual: create an invite on the Members page Invites tab; the latest-invite panel shows the URL field and "Copy link" only. ## Risks Low risk. UI-only removal of one button; the invite URL remains fully visible and copyable. ## Model Used Claude Fable 5 (`claude-fable-5`, Anthropic), extended thinking, agentic tool use via Claude Code. ## Checklist - [x] I have included a thinking path that traces from project context to this change - [x] I have specified the model used (with version and capability details) - [x] I have checked ROADMAP.md and confirmed this PR does not duplicate planned core work - [x] I have searched GitHub for duplicate or related PRs and linked them above - [x] I have either (a) linked existing issues with `Fixes: #` / `Closes #` / `Refs #` OR (b) described the issue in-PR following the relevant issue template - [x] I have not referenced internal/instance-local Paperclip issues or links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip` URLs) - [x] My branch name describes the change (e.g. `docs/...`, `fix/...`) and contains no internal Paperclip ticket id or instance-derived details - [x] I have run tests locally and they pass - [x] I have added or updated tests where applicable - [x] I have updated relevant documentation to reflect my changes - [x] I have considered and documented any risks above - [ ] All Paperclip CI gates are green - [ ] Greptile is 5/5 with no open P2s, recommendations, or follow-ups - [x] I will address all Greptile and reviewer comments before requesting merge |
||
|
|
112ef5beec |
chore(deps): bump i18next from 26.3.6 to 26.4.0 (#12267)
Bumps [i18next](https://github.com/i18next/i18next) from 26.3.6 to 26.4.0. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/i18next/i18next/releases">i18next's releases</a>.</em></p> <blockquote> <h2>v26.4.0</h2> <ul> <li>perf: cache <code>toResolveHierarchy</code> results per <code>(code, fallbackCode)</code> pair. The hierarchy resolver runs on every <code>t()</code> call and calls <code>Intl.getCanonicalLocales</code> multiple times, which showed up prominently when profiling render-heavy UIs (e.g. virtualized data grids); with the cache the per-call cost drops from ~886 ns to ~41 ns. The cache is invalidated automatically when <code>options.fallbackLng</code> changes (reassignment or in-place array mutation); if you mutate other resolution-relevant options at runtime (<code>load</code>, <code>lowerCaseLng</code>, <code>cleanCode</code>, <code>nonExplicitSupportedLngs</code>), call <code>i18next.services.languageUtils.clearCache()</code> afterwards. Function-valued <code>fallbackLng</code> and per-call array/object <code>fallbackLng</code> options are never cached, so dynamic fallbacks keep working as before. Thanks <a href="https://github.com/equaterina"><code>@equaterina</code></a> (<a href="https://redirect.github.com/i18next/i18next/pull/2444">#2444</a>).</li> <li>chore: update all devDependencies (Babel stays on 7.x until <code>@rollup/plugin-babel</code> supports 8, eslint on 9.x for neostandard). Removed the unused <code>coveralls</code> package (CI uses the Coveralls GitHub Action) and replaced <code>sinon</code> with <code>nise</code> + <code>vitest.spyOn</code> in the v1 compatibility tests, which resolves all open <code>npm audit</code> findings (0 vulnerabilities) and should close the dependabot alerts on the lockfile.</li> </ul> </blockquote> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/i18next/i18next/blob/master/CHANGELOG.md">i18next's changelog</a>.</em></p> <blockquote> <h2>26.4.0</h2> <ul> <li>perf: cache <code>toResolveHierarchy</code> results per <code>(code, fallbackCode)</code> pair. The hierarchy resolver runs on every <code>t()</code> call and calls <code>Intl.getCanonicalLocales</code> multiple times, which showed up prominently when profiling render-heavy UIs (e.g. virtualized data grids); with the cache the per-call cost drops from ~886 ns to ~41 ns. The cache is invalidated automatically when <code>options.fallbackLng</code> changes (reassignment or in-place array mutation); if you mutate other resolution-relevant options at runtime (<code>load</code>, <code>lowerCaseLng</code>, <code>cleanCode</code>, <code>nonExplicitSupportedLngs</code>), call <code>i18next.services.languageUtils.clearCache()</code> afterwards. Function-valued <code>fallbackLng</code> and per-call array/object <code>fallbackLng</code> options are never cached, so dynamic fallbacks keep working as before. Thanks <a href="https://github.com/equaterina"><code>@equaterina</code></a> (<a href="https://redirect.github.com/i18next/i18next/pull/2444">#2444</a>).</li> <li>chore: update all devDependencies (Babel stays on 7.x until <code>@rollup/plugin-babel</code> supports 8, eslint on 9.x for neostandard). Removed the unused <code>coveralls</code> package (CI uses the Coveralls GitHub Action) and replaced <code>sinon</code> with <code>nise</code> + <code>vitest.spyOn</code> in the v1 compatibility tests, which resolves all open <code>npm audit</code> findings (0 vulnerabilities) and should close the dependabot alerts on the lockfile.</li> </ul> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/i18next/i18next/commit/652847e70fd68344d00456f20ef0584da51e59f7"><code>652847e</code></a> 26.4.0</li> <li><a href="https://github.com/i18next/i18next/commit/6c6025f87e89f0b5e8ef3f0bf23fd61158bd64d3"><code>6c6025f</code></a> prettier fix</li> <li><a href="https://github.com/i18next/i18next/commit/742b9a95dd240891368bd296b6dbb09844bd365a"><code>742b9a9</code></a> chore: update dependencies and clean up dev tooling</li> <li><a href="https://github.com/i18next/i18next/commit/06924d961c64bd01a1f3d707b425b6c392a72a9a"><code>06924d9</code></a> fix: invalidate toResolveHierarchy cache on in-place fallbackLng mutation</li> <li><a href="https://github.com/i18next/i18next/commit/bb80369e1453cb9621011d51feaf7e0b8ba002f3"><code>bb80369</code></a> perf: cache toResolveHierarchy (<a href="https://redirect.github.com/i18next/i18next/issues/2444">#2444</a>)</li> <li>See full diff in <a href="https://github.com/i18next/i18next/compare/v26.3.6...v26.4.0">compare view</a></li> </ul> </details> <br /> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>canary/v2026.903.0-canary.8 |
||
|
|
5f87090894 |
Make managed Cloud OAuth handoffs invisible (#12790)
## Thinking Path > - Paperclip is the open source app people use to manage AI agents for work > - Apps let people give agents governed access to external providers > - Paperclip Cloud brokers shared provider authorization for managed stacks > - The managed flow sent the browser through a confirmation page after the tenant had already prepared sign-in > - A lost confirmation response could also show an expired-session error before the provider page opened > - This pull request adds an opaque handoff contract and one shared tenant coordinator > - The benefit is a direct and recoverable transition from Paperclip to every Cloud-brokered provider ## Linked Issues or Issue Description **What happened?** A managed Paperclip Cloud connection opened the Cloud confirmation route. A response-loss race could show an expired-session error while the authorization still continued. **Expected behavior** The current Paperclip loading state must stay visible while the tenant exchanges an opaque session. The browser must then open the provider directly. Self-hosted and direct OAuth must keep their existing behavior. **Steps to reproduce** 1. Open Apps on a Paperclip Cloud stack. 2. Start a managed provider connection. 3. Select Continue to sign in. 4. Observe that the browser visits the Cloud confirmation route before it reaches the provider. **Paperclip version or commit** `b872cd3d1b404bdaff70af493a2973ceb7e5d6ec` **Deployment mode** Paperclip Cloud hosted stack. No related open issue or pull request was found in the repository search. ## What Changed - Add a backward-compatible opaque Cloud handoff to the shared OAuth start contract. - Validate the Cloud descriptor on the server and expose no browser-selected endpoint. - Exchange managed handoffs through one fixed same-origin route in every Apps OAuth launcher. - Keep dialog popups reserved before asynchronous work and retain the tenant loading state. - Add recent-login resume storage, bounded retry behavior, terminal tenant errors, tests, and Storybook states. ## Verification - `pnpm check:token-gates` - `pnpm -r typecheck` - Focused connector and UI suites: 184 passed and 202 skipped. - `pnpm build` - `pnpm build-storybook` - The full local suite reached one unrelated macOS path-alias failure. The untouched test expected `/var/...` and received the equivalent `/private/var/...`. The same test reproduces in isolation. ## Risks - A malformed managed descriptor now fails closed in Paperclip instead of opening a URL. - A legacy Cloud deployment can omit the descriptor. Paperclip then uses the existing validated confirmation URL. - Direct provider OAuth and self-hosted flows do not receive a handoff and remain unchanged. - Rollback is a normal revert of this commit because the contract is optional and backward compatible. > For core feature work, check [`ROADMAP.md`](ROADMAP.md) first and discuss it in `#dev` before opening the PR. Feature PRs that overlap with planned core work may need to be redirected — check the roadmap first. See `CONTRIBUTING.md`. ## Model Used - OpenAI Codex with GPT-5.6, reasoning mode, tool use, code execution, and browser verification. ## Checklist - [x] I have included a thinking path that traces from project context to this change - [x] I have specified the model used (with version and capability details) - [x] I have checked ROADMAP.md and confirmed this PR does not duplicate planned core work - [x] I have searched GitHub for duplicate or related PRs and linked them above - [x] I have either (a) linked existing issues with `Fixes: #` / `Closes #` / `Refs #` OR (b) described the issue in-PR following the relevant issue template - [x] I have not referenced internal/instance-local Paperclip issues or links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip` URLs) - [x] My branch name describes the change (e.g. `docs/...`, `fix/...`) and contains no internal Paperclip ticket id or instance-derived details - [ ] I have run tests locally and they pass - [x] I have added or updated tests where applicable - [x] I have updated relevant documentation to reflect my changes - [x] I have considered and documented any risks above - [x] All Paperclip CI gates are green - [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups - [x] I will address all Greptile and reviewer comments before requesting merge Co-authored-by: Paperclip <noreply@paperclip.ing> |
||
|
|
a36020da6a |
chore(deps): bump @radix-ui/react-slot from 1.3.0 to 1.3.3 (#12268)
Bumps [@radix-ui/react-slot](https://github.com/radix-ui/primitives/tree/HEAD/packages/react/slot) from 1.3.0 to 1.3.3. <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/radix-ui/primitives/blob/main/packages/react/slot/CHANGELOG.md">@radix-ui/react-slot's changelog</a>.</em></p> <blockquote> <h2>1.3.2, 1.3.3</h2> <ul> <li>Reverted breaking changes that caused compatibility issues with React Server Components.</li> </ul> <h2>1.3.1</h2> <ul> <li>Republish through CI to attach provenance attestations. The previous versions of these packages were published manually outside of CI and therefore shipped without provenance; this patch re-releases the same code through the CI pipeline so every package includes an attestation.</li> <li>Updated dependencies: <code>@radix-ui/primitive@1.1.7</code>, <code>@radix-ui/react-compose-refs@1.1.4</code></li> </ul> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li>See full diff in <a href="https://github.com/radix-ui/primitives/commits/HEAD/packages/react/slot">compare view</a></li> </ul> </details> <br /> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |
||
|
|
d3c04d8932 |
fix(runner-e2e): prepare frozen Daytona plugin dependencies (#12791)
## Thinking Path
> - Paperclip manages AI agents and their provider runtimes.
> - The paid runner workflow installs target dependencies with lifecycle
scripts disabled.
> - The bundled Daytona plugin depends on an audited repo-local plugin
SDK link.
> - The lifecycle-safe install path did not create that link.
> - This pull request restores only the trusted Daytona preparation step
before provider secrets are exposed.
> - The benefit is a working Daytona canary without enabling dependency
lifecycle scripts.
## Linked Issues or Issue Description
**What happened?**
The Daytona paid canary stopped before lease or provider startup. The
trusted paid job disabled root lifecycle scripts, so the repo-local
plugin SDK link was absent. The plugin install returned a missing
runtime dependency error for @paperclipai/plugin-sdk.
**Expected behavior**
The trusted workflow must prepare the bundled Daytona plugin without
running untrusted dependency lifecycle scripts. The paid cell must start
only after its runtime dependencies and entrypoints pass validation.
**Steps to reproduce**
1. Dispatch the runner full-stack paid workflow for
core-compatibility.runner-acpx-claude.daytona.message-marker.
2. Let the trusted job install root dependencies with lifecycle scripts
disabled.
3. Observe the Daytona plugin installation fail before a lease or
provider process starts.
**Paperclip version or commit**
Feature head
|
||
|
|
e0d5f02b8e |
chore(deps): bump @pierre/diffs from 1.3.5 to 1.3.6 (#12311)
Bumps @pierre/diffs from 1.3.5 to 1.3.6. <details> <summary>Maintainer changes</summary> <p>This version was pushed to npm by <a href="https://www.npmjs.com/~ije">ije</a>, a new releaser for <code>@pierre/diffs</code> since your current version.</p> </details> <br /> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |
||
|
|
66ea41812d |
test(server): make the instance settings route suite deterministic under CPU contention (#12789)
## Thinking Path > - Paperclip is the open source app people use to manage AI agents for work > - Paperclip tests its server routes with mocked services and database calls > - The instance settings route suite reset and reloaded its module graph before each test > - Two concurrent module imports could bind a route to the real service module under CPU contention > - The task-drain overlap test also relied on a fixed delay and operating system request order > - This pull request loads the mocked graph once and waits for real events that prove request order > - The benefit is a deterministic 48-test suite with no production code change ## Linked Issues or Issue Description **What happened?** The instance settings route suite failed intermittently under CPU contention. A request that expected a 200 or 403 response sometimes received 500. The failing test changed between runs. **Expected behavior** The suite must use the configured service mocks for every test and must produce the expected response on every run. **Steps to reproduce** 1. Run `npx vitest run server/src/__tests__/instance-settings-routes.test.ts` many times in parallel on a busy host. 2. Compare the result with the same command on the base branch. 3. Observe intermittent 500 responses on the base branch and stable results on this branch. **Paperclip version or commit** Commit `02ae87010e621cf46bfbdf0d48b6f73887448a83`. **Deployment mode** Local dev (`pnpm dev`). The change affects tests only. **Installation method** Built from source. **Agent adapter(s) involved** Not adapter-specific (core bug). **Database mode** Not database-related. The test uses a mocked database layer. **Access context** Not applicable. **Node.js version** The CI environment runs the repository-supported Node.js version. **Operating system** Linux in continuous integration. **Relevant logs or output** The base branch reproduced `expected 500 to be 200` and `expected 500 to be 403` under parallel contention. **Relevant config (if applicable)** Not applicable. **Additional context** The branch loads the mocked module graph once per suite, restores mock behavior before each test, waits for the real transaction events, and sends the DELETE request after the POST holds the transition queue. ## What Changed - Load the mocked instance settings module graph once for the suite. - Restore each mock implementation before every test. - Wait for two real transaction events instead of a fixed 30 millisecond delay. - Send the overlapping DELETE request after the POST proves that it holds the transition queue. - Keep the test count at 48 with no skipped tests. ## Verification - Run `npx vitest run server/src/__tests__/instance-settings-routes.test.ts`. - Confirm that all 48 tests pass. - Run the 20-way parallel contention differential. - Confirm that the base arm passed 18 of 20 runs and reproduced two failures. - Confirm that the branch arm passed 20 of 20 runs, with 48 tests in each run. - Confirm that `git status --porcelain` is clean at the submitted commit. ## Risks Low risk. The change affects one test file and does not change production code, route behavior, database schema, or public API behavior. ## Model Used OpenAI Codex, GPT-5, current deployment, tool use and code execution enabled. ## Checklist - [x] I have included a thinking path that traces from project context to this change - [x] I have specified the model used (with version and capability details) - [x] I have checked ROADMAP.md and confirmed this PR does not duplicate planned core work - [x] I have searched GitHub for duplicate or related PRs and linked them above - [x] I have either (a) linked existing issues with `Fixes: #` / `Closes: #` / `Refs: #` OR (b) described the issue in-PR following the relevant issue template - [x] I have not referenced internal/instance-local Paperclip issues or links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip` URLs) - [x] My branch name describes the change (e.g. `docs/...`, `fix/...`) and contains no internal Paperclip ticket id or instance-derived details - [x] I have run tests locally and they pass - [x] I have added or updated tests where applicable - [x] I have updated relevant documentation to reflect my changes - [x] I have considered and documented any risks above - [x] All Paperclip CI gates are green - [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups - [x] I will address all Greptile and reviewer comments before requesting merge --------- Co-authored-by: Paperclip <noreply@paperclip.ing> |
||
|
|
b872cd3d1b |
test(server): select exposure reservation host ports at run time (#12783)
## Thinking Path > - Paperclip is the open source app people use to manage AI agents for work > - The server manages runtime exposure and host port leases for workspace services > - This test suite used fixed host port pairs inside the Linux ephemeral port range > - An unrelated short-lived socket could take one pair and cause a false test failure > - This pull request selects free host port pairs at run time and starts above the low lease lane > - The benefit is a more stable test suite with the same deterministic allocator checks ## Linked Issues or Issue Description **What happened?** The runtime exposure reservation test suite used two fixed app and HMR port pairs. These ports sit inside the Linux ephemeral port range. An unrelated socket could use a pair during the test, and the guest bind could fail with `EADDRINUSE`. **Expected behavior** The suite must select two free app and HMR port pairs before each test. It must avoid the low lease lane that a live instance can own without a listener. **Steps to reproduce** 1. Run `npx vitest run server/src/__tests__/workspace-runtime-exposure-reservation.test.ts`. 2. Start another process that briefly uses one fixed test port. 3. Observe that the guest bind can fail even when the allocator works correctly. **Paperclip version or commit** `c982003e00f4e8a325bafec3af4ddb113c0c1f8a` **Deployment mode** Local dev test run. **Installation method** Built from source with pnpm. **Agent adapter(s) involved** Not adapter-specific. This change tests the runtime exposure allocator. **Database mode** Not database-related. ## What Changed - Select two free app and HMR port pairs in `beforeEach`. - Start the scan 500 ports above the runtime exposure range minimum. - Keep the synthetic host stub limited to the selected pairs. - Keep all seven test cases and the existing lifecycle coverage. ## Verification - Run `npx vitest run server/src/__tests__/workspace-runtime-exposure-reservation.test.ts`. - Run `npx vitest run server/src/services/workspace-runtime-exposure.test.ts`. - Run `pnpm --filter @paperclipai/server exec tsc --noEmit`. - Confirm the full CI suite reaches a terminal green state. ## Risks Low risk. This change updates one test file and does not change production code. A port can still become busy after discovery and before the guest bind; the test documents this remaining race. ## Model Used OpenAI GPT-5 (`gpt-5`), tool use and code execution. ## Checklist - [x] I have included a thinking path that traces from project context to this change - [x] I have specified the model used (with version and capability details) - [x] I have checked ROADMAP.md and confirmed this PR does not duplicate planned core work - [x] I have searched GitHub for duplicate or related PRs and linked them above - [x] I have either (a) linked existing issues with `Fixes: #` / `Closes #` / `Refs #` OR (b) described the issue in-PR following the relevant issue template - [x] I have not referenced internal/instance-local Paperclip issues or links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip` URLs) - [x] My branch name describes the change (e.g. `docs/...`, `fix/...`) and contains no internal Paperclip ticket id or instance-derived details - [x] I have run tests locally and they pass - [x] I have added or updated tests where applicable - [x] I have updated relevant documentation to reflect my changes - [x] I have considered and documented any risks above - [x] All Paperclip CI gates are green - [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups - [x] I will address all Greptile and reviewer comments before requesting merge --------- Co-authored-by: Paperclip <noreply@paperclip.ing> |
||
|
|
236588c753 |
fix(ui): stamp the service worker with a per-build id so deploys reach parked tabs (#12725)
## Thinking Path > - Paperclip is the open source app people use to manage AI agents for work. > - The web UI ships a service worker (`ui/public/sw.js`) plus update logic (`ui/src/lib/service-worker-updates.ts`) whose job is to keep long-lived, parked SPA tabs on the freshly deployed bundle. > - That reload-on-update path fires only on `controllerchange` — i.e., only when the browser installs a new `sw.js`. > - But `sw.js` was a static public asset (`CACHE_NAME = "paperclip-v2"`), copied verbatim and never varying per deploy, so a normal deploy (new app bundle, unchanged `sw.js`) installed no new worker and triggered no reload. > - So a parked tab kept running the old bundle after a deploy until a manual reload — the exact failure the update logic was written to prevent. > - This pull request makes `sw.js` change whenever the app bundle changes, by stamping it with a per-build id at build time. > - The benefit is that shipped UI fixes actually reach open tabs, instead of waiting for each user to reload by hand. ## Linked Issues or Issue Description No separate issue. Describing the bug in-PR using the bug-report fields: **What happened?** After a deploy that changes the app bundle but not `sw.js`, tabs left open across the upgrade keep running the old bundle indefinitely. The network-first service worker means a manual reload always recovers, but nothing triggers that reload automatically. Concretely, the `2026.831.1` onboarding fix did not reach tabs that were open on `2026.831.0`. **Expected behavior** When a new bundle is deployed, the existing update machinery (`registration.update()` on visibility/interval, reload on `controllerchange`) should bring parked tabs onto the new bundle without a manual reload. **Steps to reproduce** 1. Open the app and leave the tab open. 2. Deploy a build that changes the app bundle but not `sw.js` (the common case — `sw.js` was static). 3. Observe the open tab keeps running the previous bundle; no new worker installs, so no `controllerchange` and no reload. **Paperclip version or commit** Reproduced against `2026.831.1` and `master` before this change. **Deployment mode** Any web deployment that serves the built UI (local trusted quickstart, managed, or self-hosted). Related PRs (searched open + closed before opening this one): - Refs #12198 (merged) — added the parked-tab `update()`/`controllerchange` reload logic this PR completes by making `sw.js` actually change per deploy. - Refs #9951 (open) — an alternative "prompt to reload on new build" approach to the same problem; this PR instead reuses the existing silent auto-reload path. Reviewers may want to pick one. - Refs #8112 (open) — serves `sw.js` with `no-cache`; complementary (that keeps the worker script itself fresh; this makes the script vary per build). ## What Changed - `ui/public/sw.js`: derive `CACHE_NAME` from a `__PAPERCLIP_BUILD_ID__` placeholder so the worker source varies per build. - `ui/src/lib/vite-sw-build-id.ts`: new Vite build plugin that rewrites the placeholder in the emitted `sw.js` with the entry chunk's content hash (stable when the app is unchanged, new when it changes). Throws if the placeholder is missing, so the worker can never silently stop rotating. - `ui/vite.config.ts`: register the plugin. - `ui/src/lib/vite-sw-build-id.test.ts`: unit tests for the stamping helper, the build-id derivation, and a contract test that `public/sw.js` still carries the placeholder. ## Verification - `vitest run ui/src/lib/vite-sw-build-id.test.ts` — 7 tests pass. - `vite build` — the emitted `dist/sw.js` contains `BUILD_ID = "index-<hash>"` matching the entry chunk `dist/assets/index-<hash>.js`, and the `__PAPERCLIP_BUILD_ID__` placeholder is gone. A subsequent build with unchanged app code produces the same id (no needless worker churn); a build with changed code produces a new id. - Dev (`vite serve`) leaves the literal placeholder in `sw.js`, where HMR (not the worker) drives refreshes. ## Risks - Low risk, build-time only. No runtime service-worker logic changes beyond the cache name being build-specific; the activate handler already deletes all caches, so a rotating name is inert there. - If a future edit removes the placeholder, the build fails loudly rather than silently shipping a non-rotating worker. ## Model Used - Claude (Anthropic), model id `claude-fable-5` (Claude Fable 5), used with tool use, shell commands, file editing, and test execution. ## Checklist - [x] I have included a thinking path that traces from project context to this change - [x] I have specified the model used (with version and capability details) - [x] I have checked ROADMAP.md and confirmed this PR does not duplicate planned core work - [x] I have searched GitHub for duplicate or related PRs and linked them above - [x] I have not referenced internal/instance-local Paperclip issues or links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip` URLs) - [x] My branch name describes the change (e.g. `docs/...`, `fix/...`) and contains no internal Paperclip ticket id or instance-derived details - [x] I have run tests locally and they pass - [x] I have added or updated tests where applicable - [x] I have considered and documented any risks above - [x] All Paperclip CI gates are green - [ ] Greptile is 5/5 with no open P2s, recommendations, or follow-ups - [x] I will address all Greptile and reviewer comments before requesting merge |
||
|
|
0cf06c8fa1 |
test(server): make secret write-serialization tests deterministic (#12781)
## Thinking Path > - Paperclip is the open source app people use to manage AI agents for work > - Paperclip stores and controls secrets through server services > - The secret service tests check that concurrent writes use one lock at a time > - Fixed sleep times do not prove that a provider write started or stayed queued > - This pull request uses provider-write signals and measured waits to test lock behavior > - The benefit is stable test results and stronger detection of lock failures ## Linked Issues or Issue Description **What happened?** The secret write-serialization tests used fixed 20 ms sleeps. The sleeps sometimes ran before a provider write or after a queued write entered. The tests then failed or missed a broken lock. **Expected behavior** The tests must wait for real provider-write events and must detect a queued write that enters before the first write finishes. **Steps to reproduce** 1. Run `npx vitest run server/src/__tests__/secrets-service.test.ts`. 2. Repeat the test file under sustained load. 3. Remove the write lock and run the concurrency tests. 4. Observe intermittent timing failures or missed lock failures. **Paperclip version or commit** `13bff0adee0216ee9ec67c843e9ead94aa788c68` **Deployment mode** Local dev (`pnpm dev`) **Installation method** Built from source (`pnpm dev` / `pnpm build`) **Agent adapter(s) involved** Not adapter-specific (core test) **Database mode** Not database-related **Additional context** This pull request changes tests only. It does not change production code. ## What Changed - Wait for a deferred signal when the first operation reaches its provider write. - Measure an uncontended provider-write duration and use a safety multiple for the queued-write check. - Release the test gate in a `finally` block so failed assertions do not leave a write active. - Throw when the measurement helper does not observe the provider write. ## Verification - `npx tsc --noEmit -p server/tsconfig.json` reports no errors in the changed file. - `npx vitest run server/src/__tests__/secrets-service.test.ts` passes 90 of 90 tests. - The engineer ran the test file five times under sustained load, and all runs passed. - Full CI must pass after this pull request starts. ## Risks Low risk. The change affects test code only. The measured wait can expose a real lock regression, but it does not change runtime behavior. ## Model Used OpenAI Codex, GPT-5, tool use and code execution. The exact context window and reasoning mode are not exposed by the runtime. ## Checklist - [x] I have included a thinking path that traces from project context to this change - [x] I have specified the model used (with version and capability details) - [x] I have checked ROADMAP.md and confirmed this PR does not duplicate planned core work - [x] I have searched GitHub for duplicate or related PRs and linked them above - [x] I have either (a) linked existing issues with `Fixes: #` / `Closes: #` / `Refs: #` OR (b) described the issue in-PR following the relevant issue template - [x] I have not referenced internal/instance-local Paperclip issues or links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip` URLs) - [x] My branch name describes the change (e.g. `docs/...`, `fix/...`) and contains no internal Paperclip ticket id or instance-derived details - [x] I have run tests locally and they pass - [x] I have added or updated tests where applicable - [x] I have updated relevant documentation to reflect my changes - [x] I have considered and documented any risks above - [x] All Paperclip CI gates are green - [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups - [x] I will address all Greptile and reviewer comments before requesting merge --------- Co-authored-by: Paperclip <noreply@paperclip.ing> |
||
|
|
1c9580e89b |
test(acpx): bind ACPX credential waits to the real retry envelope (#12780)
## Thinking Path > - Paperclip is the open source app people use to manage AI agents for work > - The ACPX runtime host tests manage credentials and sandbox operations. > - These tests poll operations that can join quarantine recovery. > - Recovery uses real backoff and directory synchronization, so the default poll deadline can expire while the operation makes progress. > - Three tests also stage a contender before the kernel lease release completes. > - This pull request binds every relevant poll and staging call to the documented retry envelope. > - The benefit is more stable tests and error output that names the last observed cause. ## Linked Issues or Issue Description **What happened?** Under concurrent test load, ACPX runtime host tests failed while credential recovery still made progress. Three tests also saw an active lease after they removed `auth.json`. **Expected behavior** The tests must wait for the documented retry envelope before they report a failure. They must stage a contender only after the credential lease becomes available. **Steps to reproduce** 1. Run `npx vitest run src/drivers/acpx/` from `packages/paperclip-runner`. 2. Run the suite under high concurrent load. 3. Observe intermittent timeout or active-lease failures in `runtime-host.test.ts`. **Paperclip version or commit** `865b4854fb44d3689f1c0ff17e3e715d52aaea73` base commit. **Deployment mode** Built from source. **Installation method** Built from source. **Agent adapter(s) involved** ACPX Codex runtime host tests. **Database mode** Not database-related. **Access context** Unclear / not applicable. **Node.js version** Not recorded in the handoff. **Operating system** Not recorded in the handoff. **Relevant logs or output** Under concurrent load, the failure included `Timed out in waitFor!` after 1157 ms and `Managed Codex credential home already has an active lease`. **Relevant config (if applicable)** Not applicable. **Additional context** The change touches test code only. It adds no test, removes no test, and weakens no assertion. The file keeps 28 tests and 146 assertions. ## What Changed - Add a test-local wait helper with an explicit 10-second deadline. - Apply the helper to every credential and sandbox poll in `runtime-host.test.ts`. - Report the last observed error when a poll reaches its deadline. - Guard the three credential staging calls that could race with lease release. - Set a 20-second timeout on tests that use the long wait. ## Verification - `npx vitest run src/drivers/acpx/runtime-host.test.ts` passes all 28 tests on the change branch. - A 40-run concurrent comparison produced zero `runtime-host.test.ts` failures on the change branch. - The base comparison produced 13 `runtime-host.test.ts` failures across 40 runs. - The broader ACPX suite still has a separate `codex-credentials.test.ts` flake on both arms. - CI and Greptile results will provide the remaining merge checks. ## Risks Low risk. The change affects test synchronization only. It increases selected test wait limits and does not change product behavior. ## Model Used OpenAI Codex, GPT-5. The model used tool calls and code execution. The runtime did not provide a context window value. ## Checklist - [x] I have included a thinking path that traces from project context to this change - [x] I have specified the model used (with version and capability details) - [x] I have checked ROADMAP.md and confirmed this PR does not duplicate planned core work - [x] I have searched GitHub for duplicate or related PRs and linked them above - [x] I have either (a) linked existing issues with `Fixes: #` / `Closes: #` / `Refs #` OR (b) described the issue in-PR following the relevant issue template - [x] I have not referenced internal/instance-local Paperclip issues or links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip` URLs) - [x] My branch name describes the change (e.g. `docs/...`, `fix/...`) and contains no internal Paperclip ticket id or instance-derived details - [x] I have run tests locally and recorded the separate ACPX suite flake above - [x] I have added or updated tests where applicable - [x] I have updated relevant documentation to reflect my changes - [x] I have considered and documented any risks above - [x] All Paperclip CI gates are green - [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups - [x] I will address all Greptile and reviewer comments before requesting merge --------- Co-authored-by: Paperclip <noreply@paperclip.ing> |
||
|
|
db4eeb1688 |
fix(server): validate project goal ids exist and belong to the company (#12779)
## Thinking Path
> - Paperclip is the open source app people use to manage AI agents for
work
> - Projects can link to goals, through the `goalIds` list or the legacy
`goalId` field. The project service writes those links on create and
update.
> - The service never checked the goal ids. A nonexistent id died at the
`projects.goal_id` foreign key as an opaque 500, and the caller got no
actionable feedback — observed live on 2026-09-03, where one caller
retried the same bad id four times.
> - The foreign key also only proves a goal exists, not who owns it. A
goal id from another company linked silently on a multi-company
instance.
> - This pull request asserts every resolved goal id exists under the
caller's company before any write, and rejects with a 422 that names the
unknown ids.
> - The benefit is a clear, actionable client error instead of a 500,
and no cross-company goal links.
## Linked Issues or Issue Description
**What happened?**
`POST /companies/:companyId/projects` with a `goalIds` entry that does
not exist fails with an internal error: `insert or update on table
"projects" violates foreign key constraint
"projects_goal_id_goals_id_fk"`. The caller sees a 500 and retries. A
goal id that exists but belongs to a different company is accepted and
linked.
**Expected behavior**
The request fails fast with a 422 that names the unknown goal id(s).
Goals from other companies are rejected the same way. Valid links behave
exactly as before.
**Steps to reproduce**
1. Create a company and no goals.
2. `POST /companies/:companyId/projects` with `{ "name": "Rocket",
"goalIds": ["<any-uuid>"] }`.
3. Before this change: 500 from the foreign key. After: 422 naming the
id.
**Deployment mode**
Any; observed on an authenticated public deployment.
## What Changed
- `assertGoalsBelongToCompany` in the project service: one query for the
resolved ids scoped to the company; unknown ids produce `unprocessable`
(422) with the ids in the message and details
- called on create (before the project row insert, so no partial writes)
and on update (scoped to the existing project's company); both `goalIds`
and the legacy `goalId` field flow through the same resolution
- new embedded-Postgres test file: valid link, nonexistent id on create
with no partial insert, legacy field, another company's goal on create,
and a foreign-goal update that leaves existing links unchanged
## Verification
- `pnpm vitest run src/__tests__/project-goal-validation.test.ts` — 5
passed
- adjacent suites (`project-icon-persistence`,
`project-shortname-resolution`, `issue-goal-fallback`,
`project-goal-telemetry-routes`, `heartbeat-referenced-projects`,
`projects-list-archived-routes`) — 35 passed
## Risks
- Low risk. One extra indexed select per create/update that carries goal
ids. Requests that previously 500ed now 422; requests that silently
linked a foreign goal now fail — both are corrections, not regressions.
- Existing rows with foreign links (written before this check) are
untouched; only new writes validate.
## Model Used
Claude Fable 5 (claude-fable-5) via Claude Code, extended thinking with
tool use.
## Checklist
- [x] I have included a thinking path that traces from project context
to this change
- [x] I have specified the model used (with version and capability
details)
- [x] I have checked ROADMAP.md and confirmed this PR does not duplicate
planned core work
- [x] I have searched GitHub for duplicate or related PRs and linked
them above (none found for goal-id validation)
- [x] I have either (a) linked existing issues with `Fixes: #` / `Closes
#` / `Refs #` OR (b) described the issue in-PR following the relevant
issue template
- [x] I have not referenced internal/instance-local Paperclip issues or
links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip`
URLs)
- [x] My branch name describes the change (e.g. `docs/...`, `fix/...`)
and contains no internal Paperclip ticket id or instance-derived details
- [x] I have run tests locally and they pass
- [x] I have added or updated tests where applicable
- [x] I have updated relevant documentation to reflect my changes (doc
comments; no user-facing docs affected)
- [x] I have considered and documented any risks above
canary/v2026.903.0-canary.6
|
||
|
|
2177b85eb5 |
fix(server): retry cloud-tenant auth sync once on a dropped DB connection (#12773)
## Thinking Path > - Paperclip is the open source app people use to manage AI agents for work > - Managed-cloud deployments authenticate tenant requests through trusted headers. The middleware syncs the tenant's user, company, and membership rows on the way through. > - Pooled Postgres endpoints sometimes close an established connection under an in-flight query (pooler recycle, compute suspend). The driver reconnects on the next query, but the statement on the wire fails. > - In this path a single dropped statement fails the whole request with a 500. This happened live on 2026-09-03: the idempotent company bootstrap insert died with `write CONNECTION_CLOSED`. > - This pull request retries the actor resolution exactly once when the error chain carries a postgres.js closed-connection code. The sync is idempotent end to end, so the replay is safe. > - The benefit is that a routine pooler blip no longer fails an authenticated request on the entry path. ## Linked Issues or Issue Description **What happened?** A cloud tenant request hit the trusted-header authentication middleware while the pooled Postgres endpoint closed the connection mid-query. The insert failed with `write CONNECTION_CLOSED <host>:5432` wrapped in a `Failed query: insert into "companies" …` error, and the request failed. **Expected behavior** The driver reconnects on the next query, and every statement in the tenant sync is idempotent (upserts, on-conflict inserts, deletes; the write debounce records only after the full sync succeeds). One in-request retry should absorb the blip and serve the request. Non-transient failures must keep failing fast. **Steps to reproduce** 1. Run an authenticated public deployment against a pooled Postgres endpoint. 2. Have the pooler close the connection while the middleware's tenant sync insert is on the wire. 3. Before this change the request fails with a 500; after it the retry serves the request. **Deployment mode** Authenticated public (managed cloud), external pooled PostgreSQL. ## What Changed - `resolveCloudTenantActor` now delegates to the (unchanged) resolution body through `retryOnTransientDbConnectionError`, which retries exactly once on a transient closed-connection failure - `isTransientDbConnectionError` walks the error `cause` chain (drizzle wraps the driver error) for the postgres.js codes `CONNECTION_CLOSED`, `CONNECTION_ENDED`, `CONNECTION_DESTROYED`; both helpers are exported for tests - New unit test file `cloud-tenant-transient-db-retry.test.ts`: detection matrix (including a `23505` staying non-transient), retry-once-then-succeed, no-retry on non-transient, propagate-on-second-failure ## Verification - `pnpm vitest run src/__tests__/cloud-tenant-transient-db-retry.test.ts` — 5 passed - `pnpm vitest run src/__tests__/cloud-tenant-company-provisioning.test.ts` — 7 passed against embedded Postgres, driving the real resolution path through the new wrapper ## Risks - Low risk. The retry is bounded to one attempt, gated on three explicit driver codes, and wraps an operation that is already idempotent by design. Every other failure propagates unchanged. - A genuinely down database now fails after two attempts instead of one — a few milliseconds of added latency on an already-failing request. ## Model Used Claude Fable 5 (claude-fable-5) via Claude Code, extended thinking with tool use. ## Checklist - [x] I have included a thinking path that traces from project context to this change - [x] I have specified the model used (with version and capability details) - [x] I have checked ROADMAP.md and confirmed this PR does not duplicate planned core work - [x] I have searched GitHub for duplicate or related PRs and linked them above (none found for connection-retry work in this path) - [x] I have either (a) linked existing issues with `Fixes: #` / `Closes #` / `Refs #` OR (b) described the issue in-PR following the relevant issue template - [x] I have not referenced internal/instance-local Paperclip issues or links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip` URLs) - [x] My branch name describes the change (e.g. `docs/...`, `fix/...`) and contains no internal Paperclip ticket id or instance-derived details - [x] I have run tests locally and they pass - [x] I have added or updated tests where applicable - [x] I have updated relevant documentation to reflect my changes (doc comments; no user-facing docs affected) - [x] I have considered and documented any risks above |
||
|
|
9dd6526b47 |
fix(security): harden privileged server boundaries (#12776)
## Thinking Path > - Paperclip is the open source app people use to manage AI agents for work > - The server controls secrets, host files, outbound requests, and workspace commands > - A red-team review found cases where restricted callers could cross these trust boundaries > - These cases could expose credentials or let untrusted input reach privileged resources > - This pull request applies least-privilege checks at each affected server boundary > - The benefit is safer agent execution without changing the private-instance bootstrap contract ## Linked Issues or Issue Description **What happened?** Several server paths used authorization, redaction, or content-delivery rules that were too broad. Restricted agent keys could obtain company-level operational data. Some adapter and instruction paths could reach server-owned network or file resources without the required owner approval. **Expected behavior** Paperclip must redact credential values, enforce restricted-key scopes, guard outbound network access, prevent same-origin script execution, and reserve host-level file and command controls for authorized operators. **Steps to reproduce** 1. Configure an authenticated development instance at the parent commit. 2. Exercise the affected APIs with a restricted agent key or a non-instance-admin company user. 3. Observe that the parent commit returns privileged data or accepts a privileged operation. 4. Repeat on this branch and observe a redacted response, a safe download, or an HTTP 403 response. **Paperclip version or commit** The findings reproduce from commit `39898ab22` and are fixed by this pull request. **Deployment mode** Authenticated self-hosted server and local development modes. **Installation method** Built from source with pnpm. ## What Changed - Redact generic secret `value` and `token` fields recursively in structured logs. - Classify exact and separator-suffixed `KEY` environment names as secrets in company exports. - Limit restricted self-identity responses and protect company run, log, and secret catalog APIs. - Route HTTP adapter requests through DNS-pinned SSRF protection with exact private-origin allowlisting. - Download HTML, SVG, and other script-capable assets with `nosniff` and a sandbox CSP. - Require instance-admin access for external instruction roots and exports that read them. - Block agent-authenticated host command persistence across supported workspace runtime shapes. - Apply the central runtime-management decision before workspace command controls. - Keep the documented first-user instance-admin claim contract unchanged. - Add regression tests and server-owner configuration documentation. ## Verification - `pnpm -r typecheck` passes. - The Node 24 remediation suite passes with 365 tests. It skips 25 environment-gated tests. - `pnpm build` passes under Node 24. - `git diff --check` passes. - The full local runner reaches known macOS-only general-server harness failures before the serialized route lane. The Linux PR matrix is the authoritative full-suite gate. ## Risks - Restricted agent keys now receive HTTP 403 responses from company-wide run, log, and secret catalog endpoints. - Script-capable assets now download instead of rendering inline. - External instruction roots now require instance-admin access. - Private HTTP adapter endpoints now require an exact origin in `PAPERCLIP_HTTP_ADAPTER_PRIVATE_ENDPOINT_ALLOWLIST`. - Public HTTP adapter endpoints remain enabled. Redirects and metadata or link-local targets remain blocked. - No database migration is required. > For core feature work, check [`ROADMAP.md`](ROADMAP.md) first and discuss it in `#dev` before opening the PR. Feature PRs that overlap with planned core work may need to be redirected — check the roadmap first. See `CONTRIBUTING.md`. ## Model Used OpenAI Codex, GPT-5. The exact serving snapshot and context-window size are not exposed. The model used tool-enabled reasoning, repository access, code execution, and test execution. ## Checklist - [x] I have included a thinking path that traces from project context to this change - [x] I have specified the model used (with version and capability details) - [x] I have checked ROADMAP.md and confirmed this PR does not duplicate planned core work - [x] I have searched GitHub for duplicate or related PRs and linked them above - [x] I have either (a) linked existing issues with `Fixes: #` / `Closes #` / `Refs #` OR (b) described the issue in-PR following the relevant issue template - [x] I have not referenced internal/instance-local Paperclip issues or links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip` URLs) - [x] My branch name describes the change (e.g. `docs/...`, `fix/...`) and contains no internal Paperclip ticket id or instance-derived details - [x] I have run tests locally and they pass - [x] I have added or updated tests where applicable - [x] I have updated relevant documentation to reflect my changes - [x] I have considered and documented any risks above - [x] All Paperclip CI gates are green - [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups - [x] I will address all Greptile and reviewer comments before requesting merge --------- Co-authored-by: Paperclip <noreply@paperclip.ing> |
||
|
|
31a63638ac |
fix(agents): redact plaintext env values in agent read and mutation responses (#9860)
## Thinking Path
> - Paperclip is the open source app people use to manage AI agents for
work
> - Agents are configured through `adapterConfig`, whose `env` block
holds the credentials an agent needs to talk to its provider (API keys,
tokens, and similar)
> - Those bindings come in several shapes: a legacy bare string, `{
type: "plain", value }`, and the indirection forms `{ type: "secret_ref"
}` / `{ type: "user_secret_ref" }`
> - Every endpoint that serializes an agent returned `adapterConfig` as
stored, so every `plain` binding was returned verbatim in the API
response
> - That means any caller able to read an agent — including the agent
itself via `GET /api/agents/me` — received live credentials in
plaintext, and those values then propagate into client state, logs, and
network traces
> - The exposure spans three response families that share no common
serializer: the single-agent detail reads, the company agent-list read,
and the create/update/lifecycle routes that echo the stored row straight
back
> - This pull request routes all three through one presenter that
redacts `plain` env bindings, so the leak is closed server-side and
cannot be bypassed by the caller
> - The benefit is that agent credentials stop appearing in API
responses while `secret_ref` indirection continues to work unchanged
## Linked Issues or Issue Description
No public upstream issue exists for this, so the underlying bug is
described inline below following
`.github/ISSUE_TEMPLATE/bug_report.yml`.
**What happened?**
Every endpoint that serializes an agent returned the full plaintext
value of each `adapterConfig.env` entry whose `type` was `"plain"` (and
each legacy bare-string binding). Any actor authorized to read an agent
received that agent's live credentials in the response body. Three
distinct response families were affected:
- **Single-agent reads** — `GET /api/agents/{id}` and `GET
/api/agents/me`, via `buildAgentDetail`.
- **Company agent list** — `GET /api/companies/{companyId}/agents`,
which serializes rows directly and therefore does not inherit any fix
applied to `buildAgentDetail`. Callers that pass the configuration-read
check received unredacted rows for every agent in the company in a
single request, making this the broadest of the three.
- **Mutation responses** — agent create, `PATCH /api/agents/{id}`, and
the `pause` / `resume` / `clear-error` / `approve` / `terminate` routes,
each of which echoes the stored row back to the caller.
**Expected behavior**
Read endpoints should never emit stored plaintext credentials. `plain`
bindings should be replaced with a redaction sentinel before
serialization, while `secret_ref` and `user_secret_ref` bindings — which
contain no secret material — pass through untouched.
**Steps to reproduce**
1. Configure an agent with an `adapterConfig.env` entry such as `{
"OPENAI_API_KEY": { "type": "plain", "value": "sk-example" } }`.
2. Call `GET /api/agents/{id}` (or authenticate as that agent and call
`GET /api/agents/me`).
3. Observe `sk-example` returned verbatim in the response body.
4. Call `GET /api/companies/{companyId}/agents` as a
configuration-reading caller and observe `sk-example` returned verbatim
for that agent alongside every other agent's credentials.
5. Call `PATCH /api/agents/{id}` with any unrelated field (for example
`{ "title": "Renamed" }`) and observe `sk-example` returned verbatim in
the mutation response.
**Paperclip version or commit**
Reproduced on `master` at `f12bb27b`.
**Deployment mode**
Self-hosted / local development server.
## What Changed
- `server/src/redaction.ts`: adds `redactAgentAdapterConfig`, which
rewrites every bare-string or `{ type: "plain", value }` env binding to
`{ type: "plain", value: "***REDACTED***" }` and passes `secret_ref` /
`user_secret_ref` bindings through unchanged. Reuses the existing
`REDACTED_EVENT_VALUE` and `isSecretRefBinding` /
`isUserSecretRefBinding` / `isPlainBinding` helpers — no new
dependencies.
- `server/src/redaction.ts`: `env` is destructured out and sanitized
only by `redactAgentEnvBinding`, while the remaining adapter keys go
through `redactEventPayload`. Previously the already-redacted `env` was
passed back through `sanitizeRecord`, so each binding was processed
twice — safe only because the sentinel is a fixed point of that second
pass. The two paths are now disjoint, making the invariant structural
rather than coincidental.
- `server/src/routes/agents.ts`: `buildAgentDetail` applies
`redactAgentAdapterConfig` before serialization, so `GET
/api/agents/{id}` and `GET /api/agents/me` both redact at the response
layer. Restricted views inherit the same protection.
- `server/src/routes/agents.ts`: adds `redactAgentRowForResponse`, the
single presenter for every response that emits a raw agent row, and
applies it to the company agent-list route and to the create / update /
pause / resume / clear-error / approve / terminate routes. It composes
with `redactForRestrictedAgentView` rather than replacing it: that
helper is an authorization filter (blank the whole config for low-trust
actors), this one is secret hygiene (mask values for every actor scope),
and the two invariants stay independent. `buildAgentDetail` now
delegates to the same presenter instead of inlining the call.
- `server/src/routes/agents.ts`: adds `restoreRedactedAgentEnv` on the
PATCH path so a client that round-trips a redacted detail response back
through `PATCH /api/agents/{id}` does not zero out stored values —
redacted-sentinel entries matching an existing key are restored from
storage.
## Verification
- `pnpm --filter @paperclipai/server exec tsc --noEmit` — clean.
- `pnpm --filter @paperclipai/server exec vitest run
agent-permissions-routes.test.ts` — 57 tests pass.
- Adjacent suites (`redaction`, `agent-adapter-validation-routes`,
`agent-cross-tenant-authz-routes`, `agents-pending-approval-config`,
`agents-service-secret-bindings`, `built-in-agent-routes`,
`plugin-managed-agents`, `agent-skills-routes`) — 8 files, 72 tests
pass, no regressions.
- Both new route tests were confirmed to **fail** with the route changes
reverted and pass with them applied, so they genuinely pin the behaviour
rather than passing incidentally.
Tests added:
- `server/src/__tests__/redaction.test.ts`: covers legacy-string, `{
type: "plain" }`, `secret_ref`, and `user_secret_ref` bindings,
asserting the plaintext value never appears in the serialized result;
plus coverage that non-env adapter keys are still sanitized, that env
binding shapes survive intact, and that configs with no `env` block are
handled.
- `server/src/__tests__/agent-permissions-routes.test.ts`: `GET
/api/agents/{id}` asserts redaction rather than plaintext passthrough;
new `GET /api/agents/me` redaction test across the same binding shapes;
new test asserting the `PATCH` round-trip preserves stored values; new
test asserting the board `GET /api/companies/{companyId}/agents`
response redacts every binding shape; new test asserting a mutation
response redacts rather than echoing the stored plaintext.
No real secret values appear in any test, fixture, or commit message.
## Risks
- **Behavioral change for API consumers.** Any client that read a
plaintext credential out of an agent detail, agent-list, or mutation
response will now receive `***REDACTED***`. This is the intended
security fix, but it is a breaking change for such consumers, which must
move to `secret_ref` indirection.
- **Mutation responses are redacted too.** Callers that previously
relied on a create or update response to echo back the credential they
had just written must now read it from their own request. This is
consistent with the `restoreRedactedAgentEnv` round-trip path, which
already assumes the client holds a redacted copy.
- **Round-trip data loss, mitigated.** A client that GETs an agent and
PATCHes the object straight back would otherwise persist the sentinel
over the real value. `restoreRedactedAgentEnv` restores redacted entries
from storage; the round-trip is covered by a regression test. A PATCH
that *intentionally* sets a value literally equal to the sentinel is not
distinguishable and would be treated as "unchanged" — an acceptable
trade-off given the sentinel is not a plausible credential.
- **No migration.** Stored data is untouched; redaction happens purely
at serialization time, so the change is fully reversible by revert.
- **Overlap with existing PRs** — see the duplicate-search note below.
Maintainers may prefer to consolidate rather than merge this in
isolation.
## Model Used
Claude Opus 4.8 (`claude-opus-4-8`), extended thinking enabled, with
tool use and local test execution.
## Duplicate search
Searching open and closed PRs for prior art surfaced several overlapping
efforts against the same defect. Linking them for maintainer triage — I
am not claiming this PR supersedes them, and consolidation may well be
preferable:
- #9823 — `fix(security): redact adapterConfig secrets on all agent read
endpoints` (closest overlap)
- #8779 — `fix(server): redact agent config secrets in read and mutation
responses`
- #8330 — `fix(server): redact adapterConfig.env for cross-actor agent
reads`
- #4856 — `fix(server): redact adapter env secrets in agent API
responses`
- #4763 — `fix(server): redact adapter_config secrets in agent detail
responses`
- #1839 — `fix: redact secret env vars from agent API responses`
- #4967 — `fix(routines): redact adapterConfig.env in GET
/api/routines/{id}` (same class, routines surface)
## Checklist
- [x] I have included a thinking path that traces from project context
to this change
- [x] I have specified the model used (with version and capability
details)
- [x] I have checked ROADMAP.md and confirmed this PR does not duplicate
planned core work
- [x] I searched the GitHub PR list (open and closed) for similar or
duplicate PRs and linked them above
- [x] I have either (a) linked existing issues with `Fixes: #` / `Closes
#` / `Refs #` OR (b) described the issue in-PR following the relevant
issue template
- [x] I have not referenced internal/instance-local Paperclip issues or
links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip`
URLs)
- [ ] My branch name describes the change and contains no internal
Paperclip ticket id — **not met**: the branch and title carry an
internal ticket id. Renaming the branch would invalidate this PR; happy
to reopen from a clean branch if maintainers prefer.
- [x] I have run tests locally and they pass
- [x] I have added or updated tests where applicable
- [x] I have updated relevant documentation to reflect my changes (no
user-facing docs affected)
- [x] I have considered and documented any risks above
- [x] All Paperclip CI gates are green
- [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups —
the one P2 (env entries processed twice) is addressed above
- [x] I will address all Greptile and reviewer comments before
requesting merge
---------
Co-authored-by: Paperclip <noreply@paperclip.ing>
Co-authored-by: Matthew Glover <5413384+glovario@users.noreply.github.com>
Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
Co-authored-by: Andrew Aymeloglu <aaymeloglu@gmail.com>
|
||
|
|
313d6ca115 |
fix(runner): materialize pinned OpenCode binary (#12782)
## Thinking Path > - Paperclip manages AI agents and their provider runtimes. > - Paid runner validation installs target dependencies with lifecycle scripts disabled. > - OpenCode leaves a sentinel executable until its package lifecycle script runs. > - Running arbitrary lifecycle code would weaken the paid-secret boundary. > - This pull request materializes one exact pinned binary before secrets are exposed. > - The benefit is working OpenCode validation without trusting dependency install scripts. ## Linked Issues or Issue Description **What happened?** Every local OpenCode paid cell stopped before provider startup because `pnpm install --ignore-scripts` correctly retained `opencode-ai/bin/opencode.exe` as a sentinel. **Expected behavior** The trusted workflow must make the exact lockfile-pinned OpenCode executable available without running package lifecycle scripts. **Steps to reproduce** Run a local legacy or native OpenCode paid cell from the trusted workflow after the target dependency install. The provider health check reports that the OpenCode postinstall script was not run. **Paperclip version or commit** Default branch commit `865b4854fb44d3689f1c0ff17e3e715d52aaea73`. ## What Changed - Materialize only `opencode-linux-x64-baseline@1.18.17` into the matching `opencode-ai@1.18.17` package. - Verify package identity, version, regular-file type, SHA-256 equality, executable permissions, and runtime `--version`. - Invoke the helper for local OpenCode and breadth cells and for remote provider-pack assembly. - Retain `pnpm install --ignore-scripts`. - Add helper and trusted-workflow security regressions. ## Verification - Helper syntax checks passed. - Helper unit tests passed: 2/2. - Workflow-security tests passed: 5/5. - Prettier, actionlint, and diff whitespace checks passed. ## Risks Risk is low and contained to paid runner setup. The helper supports only Linux x64, fails closed on package or version drift, and runs before provider credentials enter the job. ## Model Used OpenAI GPT-5 Codex with repository tools and code execution. ## Checklist - [x] I have included a thinking path that traces from project context to this change. - [x] I have specified the model used. - [x] I have checked ROADMAP.md and confirmed this does not duplicate planned core work. - [x] I have searched GitHub for duplicate or related PRs and found none. - [x] I have described the issue in this PR with the bug template labels. - [x] I have not referenced internal or instance-local issues. - [x] My branch name describes the change. - [x] Focused local tests pass. - [x] I added tests for the change. - [x] I updated the runner E2E security documentation. - [x] I documented the risks above. |
||
|
|
865b4854fb |
ci(runner): build paid artifacts once per campaign (#12777)
## Thinking Path > - Paid cells repeated the same TypeScript and Rust builds even when one campaign selected dozens of cells. > - The trusted workflow can compile once without provider credentials and distribute run-scoped, digest-verified artifacts. > - The paid cell can then disable install lifecycle scripts, verify each artifact before extraction, and expose provider credentials only to the final test step. > - Local JS-backed providers also need the setup-node interpreter permission-qualified before Rust verifies the launch artifact. ## Linked Issues or Issue Description Run 33786122875 proved target-lock setup and catalog selection, then failed before provider creation because trusted master did not yet qualify the setup-node interpreter. The same workflow also rebuilt TypeScript and Rust inside every matrix cell. ## What Changed - Build runner TypeScript and native binaries once per campaign in a credential-free job. - Build the remote provider pack once only when selected Daytona cells require it. - Upload run-scoped bundles with SHA-256 manifests and verify before extraction in each paid cell. - Remove repeated TypeScript, provider-pack, and Rust builds from paid cells. - Qualify the local provider Node interpreter before verified launch. - Propagate the resolved target lockfile through all five target-code jobs. - Keep local-only selection off Daytona and exclude Xiaomi from the 67-cell catalog. ## Risks A shared build artifact could fan out a bad payload to many cells. The producing jobs receive no provider credentials, use the exact authorized target SHA and resolved lockfile, and publish run-scoped artifacts. Every consuming job verifies SHA-256 before extraction. Paid dependency setup keeps lifecycle scripts disabled and provider credentials remain scoped to the final test step. ## Verification - Focused runner workflow-security, catalog, and Daytona-image tests: 25/25 passed. - Prettier passed. - Actionlint passed with only the two pre-existing SC2129 style notices ignored. - Git diff check passed. ## Model Used OpenAI Codex, GPT-5. ## Checklist - [x] Build jobs are credential-free. - [x] Paid installs disable lifecycle scripts. - [x] Artifacts are run-scoped and digest-verified before extraction. - [x] Trusted report and history jobs remain isolated from target artifacts. - [x] No Daytona or Xiaomi paid run was started for this change.canary/v2026.903.0-canary.5 |
||
|
|
06c0e883fa |
chore(deps): bump lucide-react from 1.32.0 to 1.38.0 (#12313)
Bumps [lucide-react](https://github.com/lucide-icons/lucide/tree/HEAD/packages/lucide-react) from 1.32.0 to 1.38.0. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/lucide-icons/lucide/releases">lucide-react's releases</a>.</em></p> <blockquote> <h2>Version 1.38.0</h2> <h2>What's Changed</h2> <ul> <li>feat(icons): Add polygon icon by <a href="https://github.com/timmy471"><code>@timmy471</code></a> in <a href="https://redirect.github.com/lucide-icons/lucide/pull/3007">lucide-icons/lucide#3007</a></li> </ul> <p><strong>Full Changelog</strong>: <a href="https://github.com/lucide-icons/lucide/compare/1.36.0...1.38.0">https://github.com/lucide-icons/lucide/compare/1.36.0...1.38.0</a></p> <h2>Version 1.37.0</h2> <h2>What's Changed</h2> <ul> <li>feat(icons): added 'robot-vacuum' icon by <a href="https://github.com/benhaube"><code>@benhaube</code></a> in <a href="https://redirect.github.com/lucide-icons/lucide/pull/4599">lucide-icons/lucide#4599</a></li> <li>feat(icons): made <code>face-angry</code> even more angry by <a href="https://github.com/karsa-mistmere"><code>@karsa-mistmere</code></a> in <a href="https://redirect.github.com/lucide-icons/lucide/pull/4708">lucide-icons/lucide#4708</a></li> <li>fix(icons): changed <code>swords</code> icon by <a href="https://github.com/jguddas"><code>@jguddas</code></a> in <a href="https://redirect.github.com/lucide-icons/lucide/pull/4707">lucide-icons/lucide#4707</a></li> <li>fix(icons): changed <code>shopping-cart</code> icon by <a href="https://github.com/jguddas"><code>@jguddas</code></a> in <a href="https://redirect.github.com/lucide-icons/lucide/pull/2909">lucide-icons/lucide#2909</a></li> <li>docs(icon-description): added old and empty tags/use case for ghost by <a href="https://github.com/TFJ5183"><code>@TFJ5183</code></a> in <a href="https://redirect.github.com/lucide-icons/lucide/pull/4762">lucide-icons/lucide#4762</a></li> <li>feat(icons): add <code>playing-card</code>, <code>playing-cards</code>, and <code>playing-cards-fan</code> by <a href="https://github.com/Barakudum"><code>@Barakudum</code></a> in <a href="https://redirect.github.com/lucide-icons/lucide/pull/4258">lucide-icons/lucide#4258</a></li> <li>fix(icons): changed <code>beef</code> icon by <a href="https://github.com/jguddas"><code>@jguddas</code></a> in <a href="https://redirect.github.com/lucide-icons/lucide/pull/3457">lucide-icons/lucide#3457</a></li> <li>chore(tags): added music disc related tags to <code>circle-dot</code> by <a href="https://github.com/jguddas"><code>@jguddas</code></a> in <a href="https://redirect.github.com/lucide-icons/lucide/pull/3909">lucide-icons/lucide#3909</a></li> <li>fix(icons): changed <code>panda</code> icon by <a href="https://github.com/jguddas"><code>@jguddas</code></a> in <a href="https://redirect.github.com/lucide-icons/lucide/pull/3187">lucide-icons/lucide#3187</a></li> <li>fix(icons): rotate <code>blend</code> icon by <a href="https://github.com/jguddas"><code>@jguddas</code></a> in <a href="https://redirect.github.com/lucide-icons/lucide/pull/3105">lucide-icons/lucide#3105</a></li> <li>fix(icons): rotate <code>key</code> icon by <a href="https://github.com/jguddas"><code>@jguddas</code></a> in <a href="https://redirect.github.com/lucide-icons/lucide/pull/3111">lucide-icons/lucide#3111</a></li> <li>fix(icons): changed <code>square-split-vertical</code> icon by <a href="https://github.com/jguddas"><code>@jguddas</code></a> in <a href="https://redirect.github.com/lucide-icons/lucide/pull/3939">lucide-icons/lucide#3939</a></li> <li>fix(icons): changed <code>asterisk</code> icon by <a href="https://github.com/jguddas"><code>@jguddas</code></a> in <a href="https://redirect.github.com/lucide-icons/lucide/pull/3906">lucide-icons/lucide#3906</a></li> <li>fix(icons): unify check, cross and plus sizes across icons by <a href="https://github.com/karsa-mistmere"><code>@karsa-mistmere</code></a> in <a href="https://redirect.github.com/lucide-icons/lucide/pull/3875">lucide-icons/lucide#3875</a></li> <li>feat(icons): added <code>message-circle-dashed-check</code> icon by <a href="https://github.com/aliyasirnac"><code>@aliyasirnac</code></a> in <a href="https://redirect.github.com/lucide-icons/lucide/pull/3678">lucide-icons/lucide#3678</a></li> <li>fix(icons): changed <code>piano</code> icon by <a href="https://github.com/karsa-mistmere"><code>@karsa-mistmere</code></a> in <a href="https://redirect.github.com/lucide-icons/lucide/pull/4766">lucide-icons/lucide#4766</a></li> <li>feat(icons): added <code>credit-card-x</code> & <code>credit-card-check</code> icon by <a href="https://github.com/karsa-mistmere"><code>@karsa-mistmere</code></a> in <a href="https://redirect.github.com/lucide-icons/lucide/pull/4763">lucide-icons/lucide#4763</a></li> <li>feat(icons): added <code>credit-card-minus</code> icon by <a href="https://github.com/ameniti-mx"><code>@ameniti-mx</code></a> in <a href="https://redirect.github.com/lucide-icons/lucide/pull/4440">lucide-icons/lucide#4440</a></li> <li>feat(icons): added <code>credit-card-plus</code> icon by <a href="https://github.com/ameniti-mx"><code>@ameniti-mx</code></a> in <a href="https://redirect.github.com/lucide-icons/lucide/pull/4441">lucide-icons/lucide#4441</a></li> </ul> <h2>New Contributors</h2> <ul> <li><a href="https://github.com/benhaube"><code>@benhaube</code></a> made their first contribution in <a href="https://redirect.github.com/lucide-icons/lucide/pull/4599">lucide-icons/lucide#4599</a></li> <li><a href="https://github.com/TFJ5183"><code>@TFJ5183</code></a> made their first contribution in <a href="https://redirect.github.com/lucide-icons/lucide/pull/4762">lucide-icons/lucide#4762</a></li> <li><a href="https://github.com/aliyasirnac"><code>@aliyasirnac</code></a> made their first contribution in <a href="https://redirect.github.com/lucide-icons/lucide/pull/3678">lucide-icons/lucide#3678</a></li> <li><a href="https://github.com/ameniti-mx"><code>@ameniti-mx</code></a> made their first contribution in <a href="https://redirect.github.com/lucide-icons/lucide/pull/4440">lucide-icons/lucide#4440</a></li> </ul> <p><strong>Full Changelog</strong>: <a href="https://github.com/lucide-icons/lucide/compare/1.35.0...1.37.0">https://github.com/lucide-icons/lucide/compare/1.35.0...1.37.0</a></p> <h2>Version 1.36.0</h2> <h2>What's Changed</h2> <ul> <li>feat(icons): added 'robot-vacuum' icon by <a href="https://github.com/benhaube"><code>@benhaube</code></a> in <a href="https://redirect.github.com/lucide-icons/lucide/pull/4599">lucide-icons/lucide#4599</a></li> <li>feat(icons): made <code>face-angry</code> even more angry by <a href="https://github.com/karsa-mistmere"><code>@karsa-mistmere</code></a> in <a href="https://redirect.github.com/lucide-icons/lucide/pull/4708">lucide-icons/lucide#4708</a></li> <li>fix(icons): changed <code>swords</code> icon by <a href="https://github.com/jguddas"><code>@jguddas</code></a> in <a href="https://redirect.github.com/lucide-icons/lucide/pull/4707">lucide-icons/lucide#4707</a></li> <li>fix(icons): changed <code>shopping-cart</code> icon by <a href="https://github.com/jguddas"><code>@jguddas</code></a> in <a href="https://redirect.github.com/lucide-icons/lucide/pull/2909">lucide-icons/lucide#2909</a></li> <li>docs(icon-description): added old and empty tags/use case for ghost by <a href="https://github.com/TFJ5183"><code>@TFJ5183</code></a> in <a href="https://redirect.github.com/lucide-icons/lucide/pull/4762">lucide-icons/lucide#4762</a></li> <li>feat(icons): add <code>playing-card</code>, <code>playing-cards</code>, and <code>playing-cards-fan</code> by <a href="https://github.com/Barakudum"><code>@Barakudum</code></a> in <a href="https://redirect.github.com/lucide-icons/lucide/pull/4258">lucide-icons/lucide#4258</a></li> <li>fix(icons): changed <code>beef</code> icon by <a href="https://github.com/jguddas"><code>@jguddas</code></a> in <a href="https://redirect.github.com/lucide-icons/lucide/pull/3457">lucide-icons/lucide#3457</a></li> <li>chore(tags): added music disc related tags to <code>circle-dot</code> by <a href="https://github.com/jguddas"><code>@jguddas</code></a> in <a href="https://redirect.github.com/lucide-icons/lucide/pull/3909">lucide-icons/lucide#3909</a></li> <li>fix(icons): changed <code>panda</code> icon by <a href="https://github.com/jguddas"><code>@jguddas</code></a> in <a href="https://redirect.github.com/lucide-icons/lucide/pull/3187">lucide-icons/lucide#3187</a></li> <li>fix(icons): rotate <code>blend</code> icon by <a href="https://github.com/jguddas"><code>@jguddas</code></a> in <a href="https://redirect.github.com/lucide-icons/lucide/pull/3105">lucide-icons/lucide#3105</a></li> <li>fix(icons): rotate <code>key</code> icon by <a href="https://github.com/jguddas"><code>@jguddas</code></a> in <a href="https://redirect.github.com/lucide-icons/lucide/pull/3111">lucide-icons/lucide#3111</a></li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li>See full diff in <a href="https://github.com/lucide-icons/lucide/commits/1.38.0/packages/lucide-react">compare view</a></li> </ul> </details> <br /> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>canary/v2026.903.0-canary.4 |
||
|
|
6e50ca9d0a |
ci(runner): prepare target lockfile once for paid validation (#12774)
## Thinking Path > - The trusted target-branch runner workflow checks out PR code before paid tests. > - PR policy intentionally forbids manual lockfile commits. > - Some runner changes legitimately alter pnpm patch hashes. > - Frozen installs therefore fail before test selection. > - Resolve one script-disabled lockfile from the authorized immutable target SHA and distribute it by exact artifact ID and digest. > - Keep provider credentials and trusted reporting outside this resolution job. ## Linked Issues or Issue Description Target-branch paid runner campaigns currently fail frozen install when a PR changes pnpm patch content, even though ordinary PR CI regenerates the lockfile. ## What Changed - Added one credential-free target-lock job that resolves the authorized immutable target SHA with lifecycle scripts disabled. - Uploaded the resolved lockfile with its SHA-256 and restored it by exact artifact ID before every target-code frozen install. - Left trusted reporting and history jobs on the workflow SHA. - Changed the disabled-AWS fallback from unavailable ubuntu-latest-m to ubuntu-latest. ## Risks The workflow evaluates pnpm lockfile resolution from authorized target code. That job receives no provider credentials, disables lifecycle scripts, rejects unrelated workspace mutations, and exposes only a digest-verified lockfile artifact. Paid-secret jobs consume only that lockfile after exact artifact-ID and SHA-256 validation. ## Verification - Runner workflow-security focused tests pass. - actionlint passes. - Prettier and git diff checks pass. ## Model Used OpenAI Codex, GPT-5. ## Checklist - [x] Change is narrowly scoped to paid runner orchestration. - [x] Target lock resolution has no provider credentials and disables lifecycle scripts. - [x] Downloaded artifacts are selected by exact artifact ID and verified by SHA-256. - [x] Trusted reporting and history jobs remain on the workflow SHA. |
||
|
|
39898ab22f |
chore(deps): bump paperclipai/paperclip/.github/workflows/pr-trusted.yml from 39b8ee2960 to f038633bf5 (#12562)
Bumps [paperclipai/paperclip/.github/workflows/pr-trusted.yml](https://github.com/paperclipai/paperclip) from |
||
|
|
6826452856 |
chore(deps): bump sharp from 0.35.3 to 0.35.4 (#12563)
Bumps [sharp](https://github.com/lovell/sharp) from 0.35.3 to 0.35.4. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/lovell/sharp/releases">sharp's releases</a>.</em></p> <blockquote> <h2>v0.35.4</h2> <p><a href="https://github.com/lovell/sharp-libvips/releases/tag/v1.3.3">https://github.com/lovell/sharp-libvips/releases/tag/v1.3.3</a></p> <ul> <li> <p>Bound resize dimensions to coordinate limit.</p> </li> <li> <p>Bound composite left and top to coordinate limit. <a href="https://redirect.github.com/lovell/sharp/pull/4564">#4564</a> <a href="https://github.com/metsw24-max"><code>@metsw24-max</code></a></p> </li> <li> <p>Round palette bit depth up for png and gif colours. <a href="https://redirect.github.com/lovell/sharp/pull/4569">#4569</a> <a href="https://github.com/metsw24-max"><code>@metsw24-max</code></a></p> </li> <li> <p>Ensure tiff.subifd input option is used. <a href="https://redirect.github.com/lovell/sharp/pull/4572">#4572</a> <a href="https://github.com/metsw24-max"><code>@metsw24-max</code></a></p> </li> <li> <p>Ensure <code>info.pages</code> is correct when limiting input page range. <a href="https://redirect.github.com/lovell/sharp/pull/4578">#4578</a> <a href="https://github.com/metsw24-max"><code>@metsw24-max</code></a></p> </li> <li> <p>Improve support for input Streams finishing before output is requested. <a href="https://redirect.github.com/lovell/sharp/pull/4584">#4584</a> <a href="https://github.com/Jaybhade"><code>@Jaybhade</code></a></p> </li> </ul> <h2>v0.35.4-rc.0</h2> <ul> <li> <p>Upgrade to libvips v8.18.6 for upstream bug fixes.</p> </li> <li> <p>Bound resize dimensions to coordinate limit.</p> </li> <li> <p>Bound composite left and top to coordinate limit. <a href="https://redirect.github.com/lovell/sharp/pull/4564">#4564</a> <a href="https://github.com/metsw24-max"><code>@metsw24-max</code></a></p> </li> <li> <p>Round palette bit depth up for png and gif colours. <a href="https://redirect.github.com/lovell/sharp/pull/4569">#4569</a> <a href="https://github.com/metsw24-max"><code>@metsw24-max</code></a></p> </li> <li> <p>Ensure tiff.subifd input option is used. <a href="https://redirect.github.com/lovell/sharp/pull/4572">#4572</a> <a href="https://github.com/metsw24-max"><code>@metsw24-max</code></a></p> </li> <li> <p>Ensure <code>info.pages</code> is correct when limiting input page range. <a href="https://redirect.github.com/lovell/sharp/pull/4578">#4578</a> <a href="https://github.com/metsw24-max"><code>@metsw24-max</code></a></p> </li> <li> <p>Improve support for input Streams finishing before output is requested. <a href="https://redirect.github.com/lovell/sharp/pull/4584">#4584</a> <a href="https://github.com/Jaybhade"><code>@Jaybhade</code></a></p> </li> </ul> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/lovell/sharp/commit/7f1a0a22cc285fe180766f4935d50b55af6e8432"><code>7f1a0a2</code></a> Release v0.35.4</li> <li><a href="https://github.com/lovell/sharp/commit/f927818924bc5a9493d822a4e8b23ec5857c52e1"><code>f927818</code></a> Upgrade to sharp-libvips v1.3.3</li> <li><a href="https://github.com/lovell/sharp/commit/e80209240d005c71e1173a50dd9cd4db4ce2a9e6"><code>e802092</code></a> Prerelease v0.35.4-rc.0</li> <li><a href="https://github.com/lovell/sharp/commit/e13eb2f97a0a22f1ef726e8d0cd33f7c56835945"><code>e13eb2f</code></a> CI: Fix wasm32 build (<a href="https://redirect.github.com/lovell/sharp/issues/4589">#4589</a>)</li> <li><a href="https://github.com/lovell/sharp/commit/a82a0b3d58bc25854ad1e925e6eb0a50725d1489"><code>a82a0b3</code></a> Upgrade to libvips v8.18.6</li> <li><a href="https://github.com/lovell/sharp/commit/8044fe43e36d0ea7f8beb89f79a37bb0f3342e84"><code>8044fe4</code></a> Bound resize dimensions to coordinate limit</li> <li><a href="https://github.com/lovell/sharp/commit/147f8591a153bc4a1e199c3fe3150fac2931b30c"><code>147f859</code></a> Docs: changelog entries for <a href="https://redirect.github.com/lovell/sharp/issues/4578">#4578</a> <a href="https://redirect.github.com/lovell/sharp/issues/4584">#4584</a></li> <li><a href="https://github.com/lovell/sharp/commit/ee5bfb853de75a611c64381783b04032a3a897d8"><code>ee5bfb8</code></a> Tests: use yauzl directly rather than via extract-zip wrapper</li> <li><a href="https://github.com/lovell/sharp/commit/7a7788928f8a2a429f45039010a87cee35401694"><code>7a77889</code></a> Bump uraimo/run-on-arch-action from 3.1.0 to 3.2.0 (<a href="https://redirect.github.com/lovell/sharp/issues/4588">#4588</a>)</li> <li><a href="https://github.com/lovell/sharp/commit/ea5bef24c187b2c7ee3fe3cad3b45c8cb67a46fd"><code>ea5bef2</code></a> Improve support for input Streams finishing before output is requested (<a href="https://redirect.github.com/lovell/sharp/issues/4584">#4584</a>)</li> <li>Additional commits viewable in <a href="https://github.com/lovell/sharp/compare/v0.35.3...v0.35.4">compare view</a></li> </ul> </details> <br /> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |
||
|
|
d1d396c44a |
chore(deps): bump @mdxeditor/editor from 4.2.1 to 4.2.3 (#12564)
Bumps [@mdxeditor/editor](https://github.com/mdx-editor/editor) from 4.2.1 to 4.2.3. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/mdx-editor/editor/releases">@mdxeditor/editor's releases</a>.</em></p> <blockquote> <h2>v4.2.3</h2> <h2><a href="https://github.com/mdx-editor/editor/compare/v4.2.2...v4.2.3">4.2.3</a> (2026-08-27)</h2> <h3>Bug Fixes</h3> <ul> <li>prevent JSX kind mismatches from crashing the editor (<a href="https://github.com/mdx-editor/editor/commit/a5f57634bc403c55fd43fd230af64a5bba198669">a5f5763</a>)</li> </ul> <h2>v4.2.2</h2> <h2><a href="https://github.com/mdx-editor/editor/compare/v4.2.1...v4.2.2">4.2.2</a> (2026-08-26)</h2> <h3>Bug Fixes</h3> <ul> <li>prevent stale table actions from crashing (<a href="https://github.com/mdx-editor/editor/commit/1b43250fc78cf93ff2787fba8c0acd2a783d9a0a">1b43250</a>), closes <a href="https://redirect.github.com/mdx-editor/editor/issues/961">#961</a></li> </ul> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/mdx-editor/editor/commit/300dfd5520da0fe598c867ca0ae8087f8434bbcc"><code>300dfd5</code></a> Merge pull request <a href="https://redirect.github.com/mdx-editor/editor/issues/963">#963</a> from mdx-editor/petyosi/jsx-kind-mismatch-policy</li> <li><a href="https://github.com/mdx-editor/editor/commit/a5f57634bc403c55fd43fd230af64a5bba198669"><code>a5f5763</code></a> fix: prevent JSX kind mismatches from crashing the editor</li> <li><a href="https://github.com/mdx-editor/editor/commit/1b43250fc78cf93ff2787fba8c0acd2a783d9a0a"><code>1b43250</code></a> fix: prevent stale table actions from crashing</li> <li>See full diff in <a href="https://github.com/mdx-editor/editor/compare/v4.2.1...v4.2.3">compare view</a></li> </ul> </details> <br /> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |
||
|
|
174e35a144 |
fix(server): stop paging Sentry for supervised boot races in managed cloud (#12772)
## Thinking Path > - Paperclip is the open source app people use to manage AI agents for work > - The server refuses to boot when its database is not migrated, or when an authenticated public deployment has no `DATABASE_URL`. These refusals are deliberate and correct. > - In managed cloud, a supervisor creates each stack, migrates its fresh database, applies configuration, and restarts the app. The app container often boots before those steps finish. > - Each early boot hits one of the two refusals, exits, and captures the refusal to Sentry. One fleet build batch produces hundreds of identical expected events. Real errors get buried. > - This pull request classifies exactly those two refusals as expected transients when `PAPERCLIP_CLOUD_API_ORIGIN` marks a supervised deployment, and skips only the Sentry capture for them. > - The benefit is a clean error signal: expected provisioning noise stops, and every real failure still reports. ## Linked Issues or Issue Description **What happened?** A managed-cloud stack boots its app container before the supervisor migrates the empty database or finishes applying configuration. The container refuses to start, crash-loops briefly, and converges after the supervisor restarts it. Every refused boot sends an error event to Sentry. A batch of new stacks produces hundreds of these expected events. **Expected behavior** The refusal logs and exits nonzero, so the supervisor can act. Sentry receives no event for an expected provisioning transient. Sentry still receives events for real failures: schema drift, malformed configuration, and every refusal outside managed cloud. **Steps to reproduce** 1. Set `PAPERCLIP_MIGRATION_AUTO_APPLY=false`, `PAPERCLIP_MIGRATION_PROMPT=never`, `SENTRY_DSN`, and `PAPERCLIP_CLOUD_API_ORIGIN`. 2. Point `DATABASE_URL` at an empty database and start the server. 3. The server refuses to start. Before this change it also captures the refusal to Sentry on every boot. **Deployment mode** Authenticated public (managed cloud). ## What Changed - New `server/src/startup-refusals.ts`: a `StartupRefusalError` class for refusals whose remedy belongs to the deployment supervisor, `migrationRefusalError()` to classify a pending-migrations refusal (zero applied migrations = never migrated = supervised transient; any applied history = drift = plain always-reported `Error`), and `shouldReportStartupFailure()` for the capture decision. - `server/src/index.ts`: the pending-migrations refusal uses the classifier; the missing-`DATABASE_URL` refusal under the authenticated-public contract becomes a `StartupRefusalError` (the malformed-URL refusal stays a plain `Error`); the startup crash handler consults `shouldReportStartupFailure()` before `captureException`. Logging and the nonzero exit are unchanged. - New `server/src/__tests__/startup-refusals.test.ts` covering the classification and decision matrix, including the unchanged self-hosted paths. ## Verification - `pnpm vitest run src/__tests__/startup-refusals.test.ts` — 7 passed. - Review the decision matrix in the test file: refusals report when `PAPERCLIP_CLOUD_API_ORIGIN` is absent or blank; non-refusal errors and non-`Error` throwables always report; drift always reports. ## Risks - Low risk. The change only skips a Sentry capture in one narrow, marker-gated case. Boot behavior, logging, and the exit code do not change. - Self-hosted deployments do not set `PAPERCLIP_CLOUD_API_ORIGIN`, so their reporting is unchanged, and the tests pin that. - A supervised deployment with a genuinely stuck migration runner loses per-boot Sentry events for that stack. The supervisor's own health checks and monitoring own that signal, and the container logs still carry the refusal. ## Model Used Claude Fable 5 (claude-fable-5) via Claude Code, extended thinking with tool use. ## Checklist - [x] I have included a thinking path that traces from project context to this change - [x] I have specified the model used (with version and capability details) - [x] I have checked ROADMAP.md and confirmed this PR does not duplicate planned core work - [x] I have searched GitHub for duplicate or related PRs and linked them above (none found for startup Sentry suppression) - [x] I have either (a) linked existing issues with `Fixes: #` / `Closes #` / `Refs #` OR (b) described the issue in-PR following the relevant issue template - [x] I have not referenced internal/instance-local Paperclip issues or links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip` URLs) - [x] My branch name describes the change (e.g. `docs/...`, `fix/...`) and contains no internal Paperclip ticket id or instance-derived details - [x] I have run tests locally and they pass - [x] I have added or updated tests where applicable - [x] I have updated relevant documentation to reflect my changes (module doc comment; no user-facing docs affected) - [x] I have considered and documented any risks abovecanary/v2026.903.0-canary.3 |
||
|
|
0798c77fde |
Secure Cloud canonical runtime identity (#12766)
Accept and persist Cloud-signed canonical runtime identity before activation, then route absolute self-URLs through the durable runtime identity provider. Co-Authored-By: Codex <codex@openai.com> |
||
|
|
2e8521e57c |
chore(deps): bump better-auth from 1.7.0 to 1.7.2 (#12565)
Bumps [better-auth](https://github.com/better-auth/better-auth/tree/HEAD/packages/better-auth) from 1.7.0 to 1.7.2. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/better-auth/better-auth/releases">better-auth's releases</a>.</em></p> <blockquote> <h2>v1.7.2</h2> <h2><code>better-auth</code></h2> <h3>Bug Fixes</h3> <ul> <li>Fixed permanent user bans to clear expiration dates from previous temporary bans. (<a href="https://redirect.github.com/better-auth/better-auth/pull/10823">#10823</a>)</li> <li>Fixed client types with more plugins being assignable to types declaring fewer plugins. (<a href="https://redirect.github.com/better-auth/better-auth/pull/10907">#10907</a>)</li> <li>Added warnings for invalid signed session data in the cookie cache. (<a href="https://redirect.github.com/better-auth/better-auth/pull/10934">#10934</a>)</li> <li>Fixed disabled MyISAM indexes from satisfying migration index checks. (<a href="https://redirect.github.com/better-auth/better-auth/pull/10877">#10877</a>)</li> <li>Fixed programmatic migrations on Cloudflare D1 while preserving existing-index validation. (<a href="https://redirect.github.com/better-auth/better-auth/pull/10875">#10875</a>)</li> <li>Allowed <code>~</code> in relative callback URLs validated by trusted-origin checks. (<a href="https://redirect.github.com/better-auth/better-auth/pull/10041">#10041</a>)</li> <li>Improved validation of relative callback and redirect URLs with paths, queries, and fragments. (<a href="https://redirect.github.com/better-auth/better-auth/pull/10979">#10979</a>)</li> <li>Allowed same-origin form submissions with <code>Referrer-Policy: no-referrer</code> while continuing to reject untrusted origins. (<a href="https://redirect.github.com/better-auth/better-auth/pull/10959">#10959</a>)</li> <li>Improved <code>getTestInstance</code> performance with a faster default password hasher. (<a href="https://redirect.github.com/better-auth/better-auth/pull/10879">#10879</a>)</li> <li>Standardized built-in placeholder emails to the namespaced <code>{identifier}@{namespace}.placeholder.invalid</code> format. (<a href="https://redirect.github.com/better-auth/better-auth/pull/10982">#10982</a>)</li> </ul> <p>For detailed changes, see <a href="https://github.com/better-auth/better-auth/blob/c50200bfc716cf43f5c29a2dd5766f6485c46aa1/packages/better-auth/CHANGELOG.md"><code>CHANGELOG</code></a></p> <h2><code>@better-auth/core</code></h2> <h3>Bug Fixes</h3> <ul> <li>Fixed async context loss in Cloudflare Workers bundles with multiple runtime conditions. (<a href="https://redirect.github.com/better-auth/better-auth/pull/10855">#10855</a>)</li> <li>Fixed auth request logs to respect the configured logger, log level, and disabled setting. (<a href="https://redirect.github.com/better-auth/better-auth/pull/10939">#10939</a>)</li> <li>Improved validation of relative callback and redirect URLs with paths, queries, and fragments. (<a href="https://redirect.github.com/better-auth/better-auth/pull/10979">#10979</a>)</li> <li>Standardized built-in placeholder emails to the namespaced <code>{identifier}@{namespace}.placeholder.invalid</code> format. (<a href="https://redirect.github.com/better-auth/better-auth/pull/10982">#10982</a>)</li> <li>Added synchronous and optional access to the current auth endpoint context. (<a href="https://redirect.github.com/better-auth/better-auth/pull/10938">#10938</a>)</li> </ul> <p>For detailed changes, see <a href="https://github.com/better-auth/better-auth/blob/c50200bfc716cf43f5c29a2dd5766f6485c46aa1/packages/core/CHANGELOG.md"><code>CHANGELOG</code></a></p> <h2><code>@better-auth/oauth-provider</code></h2> <h3>Bug Fixes</h3> <ul> <li>Fixed Client ID Metadata Document registration when clients share at least one supported grant with the server. (<a href="https://redirect.github.com/better-auth/better-auth/pull/11010">#11010</a>)</li> <li>Improved validation of relative callback and redirect URLs with paths, queries, and fragments. (<a href="https://redirect.github.com/better-auth/better-auth/pull/10979">#10979</a>)</li> <li>Fixed relative redirect URLs containing fragments. (<a href="https://redirect.github.com/better-auth/better-auth/pull/10983">#10983</a>)</li> </ul> <p>For detailed changes, see <a href="https://github.com/better-auth/better-auth/blob/c50200bfc716cf43f5c29a2dd5766f6485c46aa1/packages/oauth-provider/CHANGELOG.md"><code>CHANGELOG</code></a></p> <h2><code>@better-auth/drizzle-adapter</code></h2> <h3>Bug Fixes</h3> <ul> <li>Fixed one-to-one Drizzle relations when <code>usePlural</code> is enabled. (<a href="https://redirect.github.com/better-auth/better-auth/pull/10941">#10941</a>)</li> <li>Added validation for missing Drizzle schema fields in compound <code>where</code> clauses. (<a href="https://redirect.github.com/better-auth/better-auth/pull/10859">#10859</a>)</li> </ul> <p>For detailed changes, see <a href="https://github.com/better-auth/better-auth/blob/c50200bfc716cf43f5c29a2dd5766f6485c46aa1/packages/drizzle-adapter/CHANGELOG.md"><code>CHANGELOG</code></a></p> <h2><code>@better-auth/kysely-adapter</code></h2> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/better-auth/better-auth/blob/main/packages/better-auth/CHANGELOG.md">better-auth's changelog</a>.</em></p> <blockquote> <h2>1.7.2</h2> <h3>Patch Changes</h3> <ul> <li> <p><a href="https://redirect.github.com/better-auth/better-auth/pull/10875">#10875</a> <a href="https://github.com/better-auth/better-auth/commit/d5d889bfd8708601d8f27526d35fb9568450b51e"><code>d5d889b</code></a> Thanks <a href="https://github.com/bytaesu"><code>@bytaesu</code></a>! - Fix programmatic migrations failing on Cloudflare D1 while preserving existing-index validation across supported databases.</p> </li> <li> <p><a href="https://redirect.github.com/better-auth/better-auth/pull/10982">#10982</a> <a href="https://github.com/better-auth/better-auth/commit/b4ad5a110ca4f2e043c0f23a8e5f87e0b31c3fc6"><code>b4ad5a1</code></a> Thanks <a href="https://github.com/bytaesu"><code>@bytaesu</code></a>! - Built-in placeholder emails now consistently use the namespaced <code>{identifier}@{namespace}.placeholder.invalid</code> format.</p> </li> <li> <p><a href="https://redirect.github.com/better-auth/better-auth/pull/10934">#10934</a> <a href="https://github.com/better-auth/better-auth/commit/c7a5c1a7ed65a5169e98bd347df91b16bb394692"><code>c7a5c1a</code></a> Thanks <a href="https://github.com/bytaesu"><code>@bytaesu</code></a>! - Cookie-cache reads now warn when signed session data is invalid instead of silently appearing as a signed-out session.</p> </li> <li> <p><a href="https://redirect.github.com/better-auth/better-auth/pull/10879">#10879</a> <a href="https://github.com/better-auth/better-auth/commit/78f0c3922c273de29bd0b77213fbc37cc3b5917e"><code>78f0c39</code></a> Thanks <a href="https://github.com/apps/starslingdev"><code>@starslingdev</code></a>! - Test suites using <code>getTestInstance</code> now run faster because the shared fixture avoids production password-hashing costs by default. Custom <code>emailAndPassword.password</code> implementations continue to take precedence.</p> </li> <li> <p><a href="https://redirect.github.com/better-auth/better-auth/pull/10823">#10823</a> <a href="https://github.com/better-auth/better-auth/commit/ce8a3ab5442fdd388f3b1346b71292cf617c3146"><code>ce8a3ab</code></a> Thanks <a href="https://github.com/sosyz"><code>@sosyz</code></a>! - Ensure permanently banning a user clears any expiration from a previous temporary ban.</p> </li> <li> <p><a href="https://redirect.github.com/better-auth/better-auth/pull/10907">#10907</a> <a href="https://github.com/better-auth/better-auth/commit/a021eafaf235dd08c0835d91ee714aca24c4605e"><code>a021eaf</code></a> Thanks <a href="https://github.com/heliohm"><code>@heliohm</code></a>! - A client created with more plugins is again assignable to a client type declaring fewer plugins, as in 1.6.</p> </li> <li> <p><a href="https://redirect.github.com/better-auth/better-auth/pull/10959">#10959</a> <a href="https://github.com/better-auth/better-auth/commit/c8dcfa57e11e22325dbb2a0cc1af6775f41b1315"><code>c8dcfa5</code></a> Thanks <a href="https://github.com/bytaesu"><code>@bytaesu</code></a>! - Allow same-origin form submissions from pages using <code>Referrer-Policy: no-referrer</code> while continuing to reject untrusted request origins.</p> </li> <li> <p><a href="https://redirect.github.com/better-auth/better-auth/pull/10979">#10979</a> <a href="https://github.com/better-auth/better-auth/commit/fced1a5d360c14e6358f88dedc9014ff862873f1"><code>fced1a5</code></a> Thanks <a href="https://github.com/bytaesu"><code>@bytaesu</code></a>! - Allow relative callback and redirect URLs to use standard path, query, and fragment syntax while preserving open-redirect protections.</p> </li> <li> <p><a href="https://redirect.github.com/better-auth/better-auth/pull/10041">#10041</a> <a href="https://github.com/better-auth/better-auth/commit/f6891a2d2d4f7ead7e9b13e65316a0cbd88f3fe4"><code>f6891a2</code></a> Thanks <a href="https://github.com/GautamBytes"><code>@GautamBytes</code></a>! - Allow <code>~</code> in relative callback URLs validated by trusted origin checks.</p> </li> <li> <p><a href="https://redirect.github.com/better-auth/better-auth/pull/10877">#10877</a> <a href="https://github.com/better-auth/better-auth/commit/649818a2969594e58147a2cc08157812ea0b75ef"><code>649818a</code></a> Thanks <a href="https://github.com/bytaesu"><code>@bytaesu</code></a>! - Prevent disabled MyISAM indexes from satisfying migration index checks.</p> </li> <li> <p>Updated dependencies [<a href="https://github.com/better-auth/better-auth/commit/557e19bfad0f2d2842903ddb1e768a0506aceaea"><code>557e19b</code></a>, <a href="https://github.com/better-auth/better-auth/commit/64da15b0b1ca078d80f115ee0a5bd9ad4ca4d64e"><code>64da15b</code></a>, <a href="https://github.com/better-auth/better-auth/commit/d5d889bfd8708601d8f27526d35fb9568450b51e"><code>d5d889b</code></a>, <a href="https://github.com/better-auth/better-auth/commit/b4ad5a110ca4f2e043c0f23a8e5f87e0b31c3fc6"><code>b4ad5a1</code></a>, <a href="https://github.com/better-auth/better-auth/commit/ea77118d4e00f69ddffed4fb42dfedc08594ea9e"><code>ea77118</code></a>, <a href="https://github.com/better-auth/better-auth/commit/5aea9f77284dfb7b187e8e7bec0cebd4b8834123"><code>5aea9f7</code></a>, <a href="https://github.com/better-auth/better-auth/commit/fced1a5d360c14e6358f88dedc9014ff862873f1"><code>fced1a5</code></a>, <a href="https://github.com/better-auth/better-auth/commit/e1d40116e2b6a797372ac82b9feea39f57285632"><code>e1d4011</code></a>]:</p> <ul> <li><code>@better-auth/core</code><a href="https://github.com/1"><code>@1</code></a>.7.2</li> <li><code>@better-auth/kysely-adapter</code><a href="https://github.com/1"><code>@1</code></a>.7.2</li> <li><code>@better-auth/drizzle-adapter</code><a href="https://github.com/1"><code>@1</code></a>.7.2</li> <li><code>@better-auth/memory-adapter</code><a href="https://github.com/1"><code>@1</code></a>.7.2</li> <li><code>@better-auth/mongo-adapter</code><a href="https://github.com/1"><code>@1</code></a>.7.2</li> <li><code>@better-auth/prisma-adapter</code><a href="https://github.com/1"><code>@1</code></a>.7.2</li> <li><code>@better-auth/telemetry</code><a href="https://github.com/1"><code>@1</code></a>.7.2</li> </ul> </li> </ul> <h2>1.7.1</h2> <h3>Patch Changes</h3> <ul> <li> <p><a href="https://redirect.github.com/better-auth/better-auth/pull/10863">#10863</a> <a href="https://github.com/better-auth/better-auth/commit/845bbd1de682ab87e03ce925f85087da81249a4e"><code>845bbd1</code></a> Thanks <a href="https://github.com/gustavovalverde"><code>@gustavovalverde</code></a>! - <code>auth migrate</code> no longer attempts to add a required column with no default value to a table that already has rows. It stops with an error naming the column and the backfill to run first. Previously the generated statement failed on SQLite, Postgres, and SQL Server; on MySQL it filled the new column with an empty string for every existing row and reported success. If <code>auth migrate</code> already ran against a MySQL database on 1.7, run the check in the upgrade guide's account identity section.</p> <p><code>getMigrations</code> throws the new <code>UnsafeMigrationError</code> (exported from <code>better-auth/db/migration</code>) for this refusal, so callers can distinguish it from other migration errors such as an index-definition conflict.</p> <p><code>auth generate</code> still emits the statements for external migration tooling, with a comment banner naming any column that needs a manual backfill first.</p> <p>A required field whose database column is still nullable logs a warning instead of blocking the migration.</p> <p>A CLI command that fails now prints its error and exits with a non-zero code instead of an unhandled promise rejection.</p> </li> <li> <p>Updated dependencies []:</p> <ul> <li><code>@better-auth/core</code><a href="https://github.com/1"><code>@1</code></a>.7.1</li> <li><code>@better-auth/drizzle-adapter</code><a href="https://github.com/1"><code>@1</code></a>.7.1</li> </ul> </li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/better-auth/better-auth/commit/ba12fcdfa774ca27d417079dbac0b1b5894ccaf2"><code>ba12fcd</code></a> chore: release v1.7.2 (<a href="https://github.com/better-auth/better-auth/tree/HEAD/packages/better-auth/issues/10870">#10870</a>)</li> <li><a href="https://github.com/better-auth/better-auth/commit/79904f0be8fadb939743e90a61bbfee207c152e1"><code>79904f0</code></a> fix(origin-check): support fragments in relative redirect URLs (<a href="https://github.com/better-auth/better-auth/tree/HEAD/packages/better-auth/issues/10983">#10983</a>)</li> <li><a href="https://github.com/better-auth/better-auth/commit/c8dcfa57e11e22325dbb2a0cc1af6775f41b1315"><code>c8dcfa5</code></a> fix(origin-check): validate null origins using fetch metadata (<a href="https://github.com/better-auth/better-auth/tree/HEAD/packages/better-auth/issues/10959">#10959</a>)</li> <li><a href="https://github.com/better-auth/better-auth/commit/e1d40116e2b6a797372ac82b9feea39f57285632"><code>e1d4011</code></a> fix(logger): respect configured logger in auth request context (<a href="https://github.com/better-auth/better-auth/tree/HEAD/packages/better-auth/issues/10939">#10939</a>)</li> <li><a href="https://github.com/better-auth/better-auth/commit/557e19bfad0f2d2842903ddb1e768a0506aceaea"><code>557e19b</code></a> refactor(context): clarify auth endpoint context access (<a href="https://github.com/better-auth/better-auth/tree/HEAD/packages/better-auth/issues/10938">#10938</a>)</li> <li><a href="https://github.com/better-auth/better-auth/commit/b4ad5a110ca4f2e043c0f23a8e5f87e0b31c3fc6"><code>b4ad5a1</code></a> refactor: centralize placeholder email generation (<a href="https://github.com/better-auth/better-auth/tree/HEAD/packages/better-auth/issues/10982">#10982</a>)</li> <li><a href="https://github.com/better-auth/better-auth/commit/fced1a5d360c14e6358f88dedc9014ff862873f1"><code>fced1a5</code></a> fix(origin-check): improve relative callback URL validation (<a href="https://github.com/better-auth/better-auth/tree/HEAD/packages/better-auth/issues/10979">#10979</a>)</li> <li><a href="https://github.com/better-auth/better-auth/commit/f6891a2d2d4f7ead7e9b13e65316a0cbd88f3fe4"><code>f6891a2</code></a> fix(origin-check): allow tilde in relative callback URLs (<a href="https://github.com/better-auth/better-auth/tree/HEAD/packages/better-auth/issues/10041">#10041</a>)</li> <li><a href="https://github.com/better-auth/better-auth/commit/ce8a3ab5442fdd388f3b1346b71292cf617c3146"><code>ce8a3ab</code></a> fix(admin): ban without a duration should clear the previous expiration (<a href="https://github.com/better-auth/better-auth/tree/HEAD/packages/better-auth/issues/10823">#10823</a>)</li> <li><a href="https://github.com/better-auth/better-auth/commit/a021eafaf235dd08c0835d91ee714aca24c4605e"><code>a021eaf</code></a> fix(client): a client with more plugins fits a narrower client type again (<a href="https://github.com/better-auth/better-auth/tree/HEAD/packages/better-auth/issues/1">#1</a>...</li> <li>Additional commits viewable in <a href="https://github.com/better-auth/better-auth/commits/v1.7.2/packages/better-auth">compare view</a></li> </ul> </details> <br /> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |
||
|
|
4e56afec11 |
chore(deps-dev): bump @vitejs/plugin-react from 4.7.0 to 6.1.1 (#12566)
Bumps [@vitejs/plugin-react](https://github.com/vitejs/vite-plugin-react/tree/HEAD/packages/plugin-react) from 4.7.0 to 6.1.1. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/vitejs/vite-plugin-react/releases">@vitejs/plugin-react's releases</a>.</em></p> <blockquote> <h2>plugin-react@6.1.1</h2> <h3>Add <code>compiler.logDiagnostics</code> option</h3> <p>Recoverable React Compiler diagnostics are no longer logged by default. Set <code>compiler.logDiagnostics</code> to <code>true</code> to log them through Vite. Fatal diagnostics are always logged and fail the transform.</p> <h3>Respect environment sourcemap option for React Compiler transform when <code>builder.sharedPlugins</code> is enabled (<a href="https://redirect.github.com/vitejs/vite-plugin-react/pull/1439">#1439</a>)</h3> <p>The React Compiler transform was using the top-level sourcemap option instead of the environment sourcemap option. This caused a problem when the experimental <code>builder.sharedPlugins</code> was enabled.</p> <h2>plugin-react@6.1.0</h2> <h3>Add experimental native React Compiler support (<a href="https://redirect.github.com/vitejs/vite-plugin-react/pull/1419">#1419</a>)</h3> <p>Add experimental native React Compiler support.</p> <p>You can use it by installing <code>oxc-transform-react</code> and enabling it via the <code>compiler</code> option:</p> <pre lang="sh"><code>npm install -D oxc-transform-react </code></pre> <pre lang="js"><code>import { defineConfig } from 'vite' import react from '@vitejs/plugin-react' <p>export default defineConfig({<br /> plugins: [<br /> react({ compiler: true })<br /> ]<br /> })<br /> </code></pre></p> <h2>plugin-react@6.0.5</h2> <h3>Fixed the react compiler preset filter to be linear (<a href="https://redirect.github.com/vitejs/vite-plugin-react/pull/1353">#1353</a>)</h3> <p>The improved filter in v6.0.3 was non-linear and caused a performance regression (<a href="https://redirect.github.com/vitejs/vite-plugin-react/issues/1349">#1349</a>). The filter was changed to be linear to avoid that.</p> <h2>plugin-react@6.0.4</h2> <h3>Fixed <code>$RefreshSig$ is not defined</code> error when running <code>vite dev</code> with <code>NODE_ENV=production</code></h3> <p>When running <code>vite dev</code> with <code>NODE_ENV=production</code>, the app errored with <code>$RefreshSig$ is not defined</code>. This error is now fixed.</p> <h2>plugin-react@6.0.3</h2> <p>No release notes provided.</p> <h2>plugin-react@6.0.2</h2> <h3>Allow all options in reactCompilerPreset (<a href="https://redirect.github.com/vitejs/vite-plugin-react/pull/1189">#1189</a>)</h3> <p>This is a type only change. Only <code>compilationMode</code> and <code>target</code> options were available for <code>reactCompilerPreset</code>.</p> <h2>plugin-react@6.0.1</h2> <h3>Expand <code>@rolldown/plugin-babel</code> peer dep range (<a href="https://redirect.github.com/vitejs/vite-plugin-react/pull/1146">#1146</a>)</h3> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/vitejs/vite-plugin-react/blob/main/packages/plugin-react/CHANGELOG.md">@vitejs/plugin-react's changelog</a>.</em></p> <blockquote> <h2>6.1.1 (2026-08-28)</h2> <h3>Add <code>compiler.logDiagnostics</code> option</h3> <p>Recoverable React Compiler diagnostics are no longer logged by default. Set <code>compiler.logDiagnostics</code> to <code>true</code> to log them through Vite. Fatal diagnostics are always logged and fail the transform.</p> <h3>Respect environment sourcemap option for React Compiler transform when <code>builder.sharedPlugins</code> is enabled (<a href="https://redirect.github.com/vitejs/vite-plugin-react/pull/1439">#1439</a>)</h3> <p>The React Compiler transform was using the top-level sourcemap option instead of the environment sourcemap option. This caused a problem when the experimental <code>builder.sharedPlugins</code> was enabled.</p> <h2>6.1.0 (2026-08-19)</h2> <h3>Add experimental native React Compiler support (<a href="https://redirect.github.com/vitejs/vite-plugin-react/pull/1419">#1419</a>)</h3> <p>Add experimental native React Compiler support.</p> <p>You can use it by installing <code>oxc-transform-react</code> and enabling it via the <code>compiler</code> option:</p> <pre lang="sh"><code>npm install -D oxc-transform-react </code></pre> <pre lang="js"><code>import { defineConfig } from 'vite' import react from '@vitejs/plugin-react' <p>export default defineConfig({<br /> plugins: [<br /> react({ compiler: true })<br /> ]<br /> })<br /> </code></pre></p> <h2>6.0.5 (2026-07-30)</h2> <h3>Fixed the react compiler preset filter to be linear (<a href="https://redirect.github.com/vitejs/vite-plugin-react/pull/1353">#1353</a>)</h3> <p>The improved filter in v6.0.3 was non-linear and caused a performance regression (<a href="https://redirect.github.com/vitejs/vite-plugin-react/issues/1349">#1349</a>). The filter was changed to be linear to avoid that.</p> <h2>6.0.4 (2026-07-22)</h2> <h3>Fixed <code>$RefreshSig$ is not defined</code> error when running <code>vite dev</code> with <code>NODE_ENV=production</code></h3> <p>When running <code>vite dev</code> with <code>NODE_ENV=production</code>, the app errored with <code>$RefreshSig$ is not defined</code>. This error is now fixed.</p> <h2>6.0.3 (2026-06-23)</h2> <h3>Improve the react compiler preset filter to reduce false-positives (<a href="https://redirect.github.com/vitejs/vite-plugin-react/pull/1138">#1138</a>)</h3> <p>Improved the filter in the react compiler babel preset to reduce the false-positives so that less modules are processed by the react compiler.</p> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/vitejs/vite-plugin-react/commit/04cac5020e349f452d76c5a4f6d788ad4b38930a"><code>04cac50</code></a> release: plugin-react@6.1.1 (<a href="https://github.com/vitejs/vite-plugin-react/tree/HEAD/packages/plugin-react/issues/1440">#1440</a>)</li> <li><a href="https://github.com/vitejs/vite-plugin-react/commit/82d35abe4946eddd4e6456802bf2b53444e264f2"><code>82d35ab</code></a> fix(react): respect environment sourcemap option when <code>builder.sharedPlugins</code>...</li> <li><a href="https://github.com/vitejs/vite-plugin-react/commit/397e8471a559f18a16dd21bd797ac01a369dabdc"><code>397e847</code></a> fix(react): make logging diagnostics an opt-in for React Compiler (<a href="https://github.com/vitejs/vite-plugin-react/tree/HEAD/packages/plugin-react/issues/1431">#1431</a>)</li> <li><a href="https://github.com/vitejs/vite-plugin-react/commit/61006e6f52124821c24121a78712f7162ae36f5b"><code>61006e6</code></a> fix(deps): update all non-major dependencies (<a href="https://github.com/vitejs/vite-plugin-react/tree/HEAD/packages/plugin-react/issues/1433">#1433</a>)</li> <li><a href="https://github.com/vitejs/vite-plugin-react/commit/e2a649cbaa7334d6991f843563683975667e1be1"><code>e2a649c</code></a> chore: use <code>deps.neverBundle</code> instead of <code>external</code> in tsdown config (<a href="https://github.com/vitejs/vite-plugin-react/tree/HEAD/packages/plugin-react/issues/1430">#1430</a>)</li> <li><a href="https://github.com/vitejs/vite-plugin-react/commit/fb2d6f3635acbb0f3acbd0e9a914f6c620460957"><code>fb2d6f3</code></a> fix(deps): update all non-major dependencies (<a href="https://github.com/vitejs/vite-plugin-react/tree/HEAD/packages/plugin-react/issues/1427">#1427</a>)</li> <li><a href="https://github.com/vitejs/vite-plugin-react/commit/39b31735bf79c2dd380eedaba7ed849256f92a29"><code>39b3173</code></a> release: plugin-react@6.1.0 (<a href="https://github.com/vitejs/vite-plugin-react/tree/HEAD/packages/plugin-react/issues/1428">#1428</a>)</li> <li><a href="https://github.com/vitejs/vite-plugin-react/commit/f1340b0c760b1c16e1b780eeba46fd933ddd52eb"><code>f1340b0</code></a> feat(react): add native React Compiler support (<a href="https://github.com/vitejs/vite-plugin-react/tree/HEAD/packages/plugin-react/issues/1419">#1419</a>)</li> <li><a href="https://github.com/vitejs/vite-plugin-react/commit/9ab698eafc38ffa14861db450291ed2f6f557557"><code>9ab698e</code></a> fix(deps): update all non-major dependencies (<a href="https://github.com/vitejs/vite-plugin-react/tree/HEAD/packages/plugin-react/issues/1375">#1375</a>)</li> <li><a href="https://github.com/vitejs/vite-plugin-react/commit/68c0cb8796ce18bd049c3d05c5210eaf0617eac0"><code>68c0cb8</code></a> release: plugin-react@6.0.5 (<a href="https://github.com/vitejs/vite-plugin-react/tree/HEAD/packages/plugin-react/issues/1362">#1362</a>)</li> <li>Additional commits viewable in <a href="https://github.com/vitejs/vite-plugin-react/commits/plugin-react@6.1.1/packages/plugin-react">compare view</a></li> </ul> </details> <details> <summary>Maintainer changes</summary> <p>This version was pushed to npm by <a href="https://www.npmjs.com/~GitHub%20Actions">GitHub Actions</a>, a new releaser for <code>@vitejs/plugin-react</code> since your current version.</p> </details> <br /> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |
||
|
|
fa16f88d6b |
chore(lockfile): refresh pnpm-lock.yaml (#12771)
Use full dependency resolution in automated lockfile repair paths, add regression coverage, and refresh the stale Rollup snapshot. Co-Authored-By: Dotta <cryppadotta@users.noreply.github.com> Co-Authored-By: Codex <codex@openai.com> Co-Authored-By: lockfile-bot <lockfile-bot@users.noreply.github.com>canary/v2026.903.0-canary.2 |
||
|
|
eb7b4d1371 |
chore(deps): bump @aws-sdk/client-s3 from 3.1115.0 to 3.1120.0 (#12567)
Bumps [@aws-sdk/client-s3](https://github.com/aws/aws-sdk-js-v3/tree/HEAD/clients/client-s3) from 3.1115.0 to 3.1120.0. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/aws/aws-sdk-js-v3/releases">@aws-sdk/client-s3's releases</a>.</em></p> <blockquote> <h2>v3.1120.0</h2> <h4>3.1120.0(2026-08-27)</h4> <h5>Documentation Changes</h5> <ul> <li><strong>client-opensearch:</strong> Updating SDK and CLI documentation for AttachDataSource API. (<a href="https://github.com/aws/aws-sdk-js-v3/commit/d696fe7602bb2f5c022a2a850767b2284b85d64a">d696fe76</a>)</li> </ul> <h5>New Features</h5> <ul> <li><strong>client-lambda-microvms:</strong> Added InsufficientCapacityException to RunMicrovm for capacity-related failures. Added lifecycle status field (AVAILABLE, DEPRECATED) to ListManagedMicrovmImageVersions. Added ConflictException to CreateMicrovmAuthToken and CreateMicrovmShellAuthToken for unregistered MicroVMs. (<a href="https://github.com/aws/aws-sdk-js-v3/commit/72a8ff80923f172e73030a0b28d9946fb16d0ffa">72a8ff80</a>)</li> <li><strong>client-codedeploy:</strong> Added a deploymentMode parameter to CreateDeployment. Set it to RESTART to restart an EC2 and on-premises fleet, using the last successful revision, honoring Deployment Configuration. (<a href="https://github.com/aws/aws-sdk-js-v3/commit/78d4f9640b6a9fe509f5a466cfa821052f76a614">78d4f964</a>)</li> <li><strong>client-cloudwatch-logs:</strong> Added resultCount to QueryStatistics in GetQueryResults. This field returns the total number of output rows in the final result set, helping customers programmatically determine whether a query produced results after all operations including post-aggregation filters. (<a href="https://github.com/aws/aws-sdk-js-v3/commit/0e4d242b71b24dc7305d6a3b7356e052bd969e67">0e4d242b</a>)</li> <li><strong>client-datazone:</strong> Add cascadeDelete to DeleteDomain. When specified, DataZone recursively deletes all projects, environments, subscriptions, and their underlying AWS resources before removing the domain. Deletion progress is reported via deleteProgress and resource failures via failureReasons on GetDomain. (<a href="https://github.com/aws/aws-sdk-js-v3/commit/3a74dc4b94d54616c93dabef996e6680c2ef1edb">3a74dc4b</a>)</li> <li><strong>client-rds:</strong> Adding support for the full snapshot size, in bytes, of DB instance snapshots. (<a href="https://github.com/aws/aws-sdk-js-v3/commit/ab2f66f5f52d48690e0e914fb1cf52c290837ec5">ab2f66f5</a>)</li> <li><strong>client-ec2:</strong> EC2 allows AMI owners to define compatible instance types on their AMIs, blocking RunInstances calls automatically for launches on non-permitted instance types. (<a href="https://github.com/aws/aws-sdk-js-v3/commit/311b3b26dbad32a32a94713fca4ffb65eaf2ec61">311b3b26</a>)</li> <li><strong>client-cognito-identity-provider:</strong> Adds the AdminDeleteSoftwareToken API operation, enabling administrators to remove a user's registered TOTP (software token) MFA configuration from a user pool. (<a href="https://github.com/aws/aws-sdk-js-v3/commit/f661bebc4db63a4cea2e02b2ec722e82e4908425">f661bebc</a>)</li> </ul> <hr /> <p>For list of updated packages, view <strong>updated-packages.md</strong> in <strong>assets-3.1120.0.zip</strong></p> <h2>v3.1119.0</h2> <h4>3.1119.0(2026-08-26)</h4> <h5>Chores</h5> <ul> <li><strong>codegen:</strong> smithy-aws-typescript-codegen 0.53.0 (<a href="https://redirect.github.com/aws/aws-sdk-js-v3/pull/8276">#8276</a>) (<a href="https://github.com/aws/aws-sdk-js-v3/commit/dffb383bdc2ebc39a18c0dfe7494215a7783ff04">dffb383b</a>)</li> </ul> <h5>New Features</h5> <ul> <li><strong>client-sagemaker:</strong> Amazon SageMaker AI now supports ml.g7 instances for model optimization. You can now run model optimization jobs on ml.g7 instances, in supported AWS Regions. (<a href="https://github.com/aws/aws-sdk-js-v3/commit/6d5e106634bcc6f63cf148bb3339a64f3d5c0404">6d5e1066</a>)</li> <li><strong>client-devops-agent:</strong> AWS DevOps Agent now supports trigger filter groups for Release Readiness Review, letting you control when the capability auto-triggers based on webhook events and target branches. (<a href="https://github.com/aws/aws-sdk-js-v3/commit/bc3d53d55006d95d34928b8044289a080f3fe512">bc3d53d5</a>)</li> <li><strong>client-license-manager-user-subscriptions:</strong> Released support for License Expiry field in ListProductSubscriptions API (<a href="https://github.com/aws/aws-sdk-js-v3/commit/454d7f7ffbfe044a534ac3f874c108e4eae1739e">454d7f7f</a>)</li> <li><strong>client-ec2:</strong> Adds deleting state to possible VPC States. (<a href="https://github.com/aws/aws-sdk-js-v3/commit/43091d55b3ca5ef039506afdcbd9c293162c61f3">43091d55</a>)</li> <li><strong>client-network-firewall:</strong> Adding new status enum for Firewalls. (<a href="https://github.com/aws/aws-sdk-js-v3/commit/4cb21cb3b82b7dbb9bdad31694d084e517f8047a">4cb21cb3</a>)</li> </ul> <hr /> <p>For list of updated packages, view <strong>updated-packages.md</strong> in <strong>assets-3.1119.0.zip</strong></p> <h2>v3.1118.0</h2> <h4>3.1118.0(2026-08-25)</h4> <h5>Documentation Changes</h5> <ul> <li><strong>client-marketplace-metering:</strong> Updated documentation to clarify duplicate-billing prevention and BatchMeterUsage retry guidance (<a href="https://github.com/aws/aws-sdk-js-v3/commit/322310259e52948dc826a3ad3f3e95544df95fcc">32231025</a>)</li> </ul> <h5>New Features</h5> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/aws/aws-sdk-js-v3/blob/main/clients/client-s3/CHANGELOG.md">@aws-sdk/client-s3's changelog</a>.</em></p> <blockquote> <h1><a href="https://github.com/aws/aws-sdk-js-v3/compare/v3.1119.0...v3.1120.0">3.1120.0</a> (2026-08-27)</h1> <p><strong>Note:</strong> Version bump only for package <code>@aws-sdk/client-s3</code></p> <h1><a href="https://github.com/aws/aws-sdk-js-v3/compare/v3.1118.0...v3.1119.0">3.1119.0</a> (2026-08-26)</h1> <p><strong>Note:</strong> Version bump only for package <code>@aws-sdk/client-s3</code></p> <h1><a href="https://github.com/aws/aws-sdk-js-v3/compare/v3.1117.0...v3.1118.0">3.1118.0</a> (2026-08-25)</h1> <p><strong>Note:</strong> Version bump only for package <code>@aws-sdk/client-s3</code></p> <h1><a href="https://github.com/aws/aws-sdk-js-v3/compare/v3.1116.0...v3.1117.0">3.1117.0</a> (2026-08-24)</h1> <p><strong>Note:</strong> Version bump only for package <code>@aws-sdk/client-s3</code></p> <h1><a href="https://github.com/aws/aws-sdk-js-v3/compare/v3.1115.0...v3.1116.0">3.1116.0</a> (2026-08-21)</h1> <p><strong>Note:</strong> Version bump only for package <code>@aws-sdk/client-s3</code></p> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/aws/aws-sdk-js-v3/commit/d6be6f8dd3ee8d43fd70dfb5b52a977ce251c720"><code>d6be6f8</code></a> Publish v3.1120.0</li> <li><a href="https://github.com/aws/aws-sdk-js-v3/commit/ba4e4498a7610ec0b5ad7af195db137f618e09bc"><code>ba4e449</code></a> Publish v3.1119.0</li> <li><a href="https://github.com/aws/aws-sdk-js-v3/commit/c65dd6533de52787da39c1bc58177b4258a044ea"><code>c65dd65</code></a> Publish v3.1118.0</li> <li><a href="https://github.com/aws/aws-sdk-js-v3/commit/78b069ac777c0b3e8cca25aff07efc551ab59608"><code>78b069a</code></a> Publish v3.1117.0</li> <li><a href="https://github.com/aws/aws-sdk-js-v3/commit/d760a00859a08b5d04590ee047510b49add12361"><code>d760a00</code></a> Publish v3.1116.0</li> <li><a href="https://github.com/aws/aws-sdk-js-v3/commit/8369ada75d60056e24e1ee8bca20f16ce2faea93"><code>8369ada</code></a> chore(codegen): update to sync with the latest smithy-ts (<a href="https://github.com/aws/aws-sdk-js-v3/tree/HEAD/clients/client-s3/issues/8272">#8272</a>)</li> <li>See full diff in <a href="https://github.com/aws/aws-sdk-js-v3/commits/v3.1120.0/clients/client-s3">compare view</a></li> </ul> </details> <br /> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |
||
|
|
98c569b2df |
ci(runner): allow trusted branch targets (#12768)
## Thinking Path > - Paperclip uses paid runner tests to qualify agent execution. > - The runner workflow controls provider secrets and AWS runner access. > - The trusted workflow must stay on the protected default branch. > - The code under test often exists on a branch before merge. > - CODEOWNERS need a safe way to select that branch. > - This pull request separates workflow authority from the code under test. > - The benefit is pre-merge AWS testing without target-controlled workflow code. ## Linked Issues or Issue Description **What existing behavior does this improve?** The manual Runner Full-Stack E2E workflow can test only the default branch. **Subsystem affected** GitHub Actions and the paid runner E2E security boundary. **Current behavior** A CODEOWNER must merge runner changes before the trusted AWS workflow can test them. Selecting another branch as the workflow ref is rejected. **Proposed behavior** A CODEOWNER starts the workflow from `master` and supplies a same-repository branch in `target_branch`. The authorization job resolves the branch to one commit SHA. Catalog, image, and paid test jobs check out that SHA after authorization. Report sanitization and AWS publication use the trusted workflow SHA. **Reason and benefit** This permits paid pre-merge qualification on AWS. It keeps the workflow definition, report sanitizer, history publisher, environment deployment, and runner-group permission on `master`. **Breaking changes** None. The new input is optional. An omitted input still tests the default branch. ## What Changed - Add the optional `target_branch` workflow input. - Resolve only a branch in `paperclipai/paperclip` to an immutable SHA. - Pin catalog, image, paid test, and Daytona provenance to the target SHA. - Pin report sanitization and AWS history publication to the trusted workflow SHA. - Disable persisted checkout credentials in every job. - Key cancellation by the selected target branch. - Add policy regression coverage and operator documentation. ## Verification - `pnpm test:e2e:runner:unit` passes with 65 tests. - `actionlint -ignore SC2129 .github/workflows/runner-full-stack-e2e.yml` passes. - Prettier checks pass for all changed files. - `git diff --check` passes. ## Risks A CODEOWNER can authorize selected branch code to receive a cell-scoped provider credential. This is the intended trust decision. The workflow rejects fork refs and target-controlled workflow definitions. The trusted workflow SHA owns report sanitization and AWS history publication. > For core feature work, check [`ROADMAP.md`](ROADMAP.md) first and discuss it in `#dev` before opening the PR. Feature PRs that overlap with planned core work may need to be redirected — check the roadmap first. See `CONTRIBUTING.md`. ## Model Used OpenAI Codex, GPT-5. The exact serving snapshot and context-window size are not exposed. The model used tool-enabled reasoning and code execution. ## Checklist - [x] I have included a thinking path that traces from project context to this change - [x] I have specified the model used (with version and capability details) - [x] I have checked ROADMAP.md and confirmed this PR does not duplicate planned core work - [x] I have searched GitHub for duplicate or related PRs and linked them above - [x] I have either (a) linked existing issues with `Fixes: #` / `Closes #` / `Refs #` OR (b) described the issue in-PR following the relevant issue template - [x] I have not referenced internal/instance-local Paperclip issues or links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip` URLs) - [x] My branch name describes the change (e.g. `docs/...`, `fix/...`) and contains no internal Paperclip ticket id or instance-derived details - [x] I have run tests locally and they pass - [x] I have added or updated tests where applicable - [x] I have updated relevant documentation to reflect my changes - [x] I have considered and documented any risks above - [ ] All Paperclip CI gates are green - [ ] Greptile is 5/5 with no open P2s, recommendations, or follow-ups - [x] I will address all Greptile and reviewer comments before requesting merge |
||
|
|
6b625425a5 |
chore(deps): bump @tanstack/react-query from 5.101.4 to 5.102.8 (#12568)
Bumps [@tanstack/react-query](https://github.com/TanStack/query/tree/HEAD/packages/react-query) from 5.101.4 to 5.102.8. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/TanStack/query/releases">@tanstack/react-query's releases</a>.</em></p> <blockquote> <h2><code>@tanstack/react-query-devtools</code><a href="https://github.com/5"><code>@5</code></a>.102.8</h2> <h3>Patch Changes</h3> <ul> <li>Updated dependencies []: <ul> <li><code>@tanstack/query-devtools</code><a href="https://github.com/5"><code>@5</code></a>.102.8</li> <li><code>@tanstack/react-query</code><a href="https://github.com/5"><code>@5</code></a>.102.8</li> </ul> </li> </ul> <h2><code>@tanstack/react-query-next-experimental</code><a href="https://github.com/5"><code>@5</code></a>.102.8</h2> <h3>Patch Changes</h3> <ul> <li>Updated dependencies []: <ul> <li><code>@tanstack/react-query</code><a href="https://github.com/5"><code>@5</code></a>.102.8</li> </ul> </li> </ul> <h2><code>@tanstack/react-query-persist-client</code><a href="https://github.com/5"><code>@5</code></a>.102.8</h2> <h3>Patch Changes</h3> <ul> <li>Updated dependencies []: <ul> <li><code>@tanstack/query-persist-client-core</code><a href="https://github.com/5"><code>@5</code></a>.102.8</li> <li><code>@tanstack/react-query</code><a href="https://github.com/5"><code>@5</code></a>.102.8</li> </ul> </li> </ul> <h2><code>@tanstack/react-query</code><a href="https://github.com/5"><code>@5</code></a>.102.8</h2> <h3>Patch Changes</h3> <ul> <li>Updated dependencies []: <ul> <li><code>@tanstack/query-core</code><a href="https://github.com/5"><code>@5</code></a>.102.8</li> </ul> </li> </ul> <h2><code>@tanstack/react-query-devtools</code><a href="https://github.com/5"><code>@5</code></a>.102.7</h2> <h3>Patch Changes</h3> <ul> <li>Updated dependencies []: <ul> <li><code>@tanstack/query-devtools</code><a href="https://github.com/5"><code>@5</code></a>.102.7</li> <li><code>@tanstack/react-query</code><a href="https://github.com/5"><code>@5</code></a>.102.7</li> </ul> </li> </ul> <h2><code>@tanstack/react-query-next-experimental</code><a href="https://github.com/5"><code>@5</code></a>.102.7</h2> <h3>Patch Changes</h3> <ul> <li>Updated dependencies []: <ul> <li><code>@tanstack/react-query</code><a href="https://github.com/5"><code>@5</code></a>.102.7</li> </ul> </li> </ul> <h2><code>@tanstack/react-query-persist-client</code><a href="https://github.com/5"><code>@5</code></a>.102.7</h2> <h3>Patch Changes</h3> <ul> <li>Updated dependencies []: <ul> <li><code>@tanstack/query-persist-client-core</code><a href="https://github.com/5"><code>@5</code></a>.102.7</li> <li><code>@tanstack/react-query</code><a href="https://github.com/5"><code>@5</code></a>.102.7</li> </ul> </li> </ul> <h2><code>@tanstack/react-query</code><a href="https://github.com/5"><code>@5</code></a>.102.7</h2> <h3>Patch Changes</h3> <ul> <li>Updated dependencies []:</li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/TanStack/query/blob/main/packages/react-query/CHANGELOG.md">@tanstack/react-query's changelog</a>.</em></p> <blockquote> <h2>5.102.8</h2> <h3>Patch Changes</h3> <ul> <li>Updated dependencies []: <ul> <li><code>@tanstack/query-core</code><a href="https://github.com/5"><code>@5</code></a>.102.8</li> </ul> </li> </ul> <h2>5.102.7</h2> <h3>Patch Changes</h3> <ul> <li>Updated dependencies []: <ul> <li><code>@tanstack/query-core</code><a href="https://github.com/5"><code>@5</code></a>.102.7</li> </ul> </li> </ul> <h2>5.102.6</h2> <h3>Patch Changes</h3> <ul> <li> <p><a href="https://redirect.github.com/TanStack/query/pull/11305">#11305</a> <a href="https://github.com/TanStack/query/commit/ac2b61230ea35b90b177ba35dc030598bac9c9a6"><code>ac2b612</code></a> - fix(react-query): throw falsy errors from <code>useQueries</code> and <code>useSuspenseQueries</code> to the error boundary</p> </li> <li> <p>Updated dependencies []:</p> <ul> <li><code>@tanstack/query-core</code><a href="https://github.com/5"><code>@5</code></a>.102.6</li> </ul> </li> </ul> <h2>5.102.5</h2> <h3>Patch Changes</h3> <ul> <li>Updated dependencies [<a href="https://github.com/TanStack/query/commit/578e5c26e8ebd0d7351b4b8e2bafba695e672b8d"><code>578e5c2</code></a>]: <ul> <li><code>@tanstack/query-core</code><a href="https://github.com/5"><code>@5</code></a>.102.5</li> </ul> </li> </ul> <h2>5.102.4</h2> <h3>Patch Changes</h3> <ul> <li>Updated dependencies [<a href="https://github.com/TanStack/query/commit/a05df6aefb0e2489ec2c879ae16e2ee7cb3123ec"><code>a05df6a</code></a>]: <ul> <li><code>@tanstack/query-core</code><a href="https://github.com/5"><code>@5</code></a>.102.4</li> </ul> </li> </ul> <h2>5.102.3</h2> <h3>Patch Changes</h3> <ul> <li>Updated dependencies []: <ul> <li><code>@tanstack/query-core</code><a href="https://github.com/5"><code>@5</code></a>.102.3</li> </ul> </li> </ul> <h2>5.102.2</h2> <h3>Patch Changes</h3> <ul> <li>Updated dependencies [<a href="https://github.com/TanStack/query/commit/80fbf73e77892d702c107e14a84c219a8ed825dc"><code>80fbf73</code></a>]: <ul> <li><code>@tanstack/query-core</code><a href="https://github.com/5"><code>@5</code></a>.102.2</li> </ul> </li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/TanStack/query/commit/2969edf32f7e0c48e2a108d84712d6e01edfde21"><code>2969edf</code></a> ci: Version Packages (<a href="https://github.com/TanStack/query/tree/HEAD/packages/react-query/issues/11316">#11316</a>)</li> <li><a href="https://github.com/TanStack/query/commit/2eb3c7c76f4dd175b2c8b6b91d5062595fff8b84"><code>2eb3c7c</code></a> ci: Version Packages (<a href="https://github.com/TanStack/query/tree/HEAD/packages/react-query/issues/11313">#11313</a>)</li> <li><a href="https://github.com/TanStack/query/commit/714df67ab11c6e16666e4282dfec8654175591f7"><code>714df67</code></a> ci: Version Packages (<a href="https://github.com/TanStack/query/tree/HEAD/packages/react-query/issues/11306">#11306</a>)</li> <li><a href="https://github.com/TanStack/query/commit/ac2b61230ea35b90b177ba35dc030598bac9c9a6"><code>ac2b612</code></a> fix(react-query): propagate falsy errors to the error boundary (<a href="https://github.com/TanStack/query/tree/HEAD/packages/react-query/issues/11305">#11305</a>)</li> <li><a href="https://github.com/TanStack/query/commit/1836e61b8ccc42a79399fc98047bb324d20de8e2"><code>1836e61</code></a> ci: Version Packages (<a href="https://github.com/TanStack/query/tree/HEAD/packages/react-query/issues/11303">#11303</a>)</li> <li><a href="https://github.com/TanStack/query/commit/51f12db9199477d653347319d3b38ad5e9564824"><code>51f12db</code></a> ci: Version Packages (<a href="https://github.com/TanStack/query/tree/HEAD/packages/react-query/issues/11294">#11294</a>)</li> <li><a href="https://github.com/TanStack/query/commit/730b3aa06c49337068e1b84a5025bca75887348b"><code>730b3aa</code></a> ci: Version Packages (<a href="https://github.com/TanStack/query/tree/HEAD/packages/react-query/issues/11276">#11276</a>)</li> <li><a href="https://github.com/TanStack/query/commit/388bbaf181c4e7b7017b5dbb5cbf2a57eb22e267"><code>388bbaf</code></a> ci: Version Packages (<a href="https://github.com/TanStack/query/tree/HEAD/packages/react-query/issues/11265">#11265</a>)</li> <li><a href="https://github.com/TanStack/query/commit/bc423b37ef7fa2a34cfc7286945fd640d74b4071"><code>bc423b3</code></a> ci: Version Packages (<a href="https://github.com/TanStack/query/tree/HEAD/packages/react-query/issues/11261">#11261</a>)</li> <li><a href="https://github.com/TanStack/query/commit/be1352b848cf2a9a43eb8828ad023e0a9f74ad36"><code>be1352b</code></a> test(*): add adapter-level type coverage for optional undefinable mutate vari...</li> <li>Additional commits viewable in <a href="https://github.com/TanStack/query/commits/@tanstack/react-query@5.102.8/packages/react-query">compare view</a></li> </ul> </details> <br /> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |
||
|
|
c0a815339f |
chore(deps): bump mermaid from 11.16.1 to 11.17.2 (#12569)
Bumps [mermaid](https://github.com/mermaid-js/mermaid) from 11.16.1 to 11.17.2. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/mermaid-js/mermaid/releases">mermaid's releases</a>.</em></p> <blockquote> <h2>mermaid@11.17.2</h2> <h3>Patch Changes</h3> <ul> <li><a href="https://redirect.github.com/mermaid-js/mermaid/pull/8125">#8125</a> <a href="https://github.com/mermaid-js/mermaid/commit/178d7c79fcbafcf0662b822ec34ed989372ee5c2"><code>178d7c7</code></a> Thanks <a href="https://github.com/knsv-bot"><code>@knsv-bot</code></a>! - fix: restore the <code>edgePaths</code> class on the edge group in rendered SVG, and point the flowchart, block and user journey stylesheets at it</li> </ul> <h2>mermaid@11.17.1</h2> <h3>Patch Changes</h3> <ul> <li> <p><a href="https://redirect.github.com/mermaid-js/mermaid/pull/8092">#8092</a> <a href="https://github.com/mermaid-js/mermaid/commit/31ce60a596746c76dc932ab540d910a6c7fff8be"><code>31ce60a</code></a> Thanks <a href="https://github.com/pbrolin47"><code>@pbrolin47</code></a>! - fix(c4): wrap element labels to <code>c4.width</code> again</p> <p>C4 element labels (<code>System</code>, <code>Container</code>, <code>Component</code>, <code>Person</code> and their <code>_Ext</code> variants) stopped wrapping in 11.17.0, so long descriptions rendered on one unbroken line and the shape grew sideways well past the configured <code>c4.width</code>. The unified-shapes label helper gated wrapping on the root-level <code>wrap</code> option, which has no schema default and is therefore <code>undefined</code>; it now gates on <code>c4.wrap</code> (default <code>true</code>), which is what the legacy renderer used.</p> </li> <li> <p><a href="https://redirect.github.com/mermaid-js/mermaid/pull/8088">#8088</a> <a href="https://github.com/mermaid-js/mermaid/commit/c66200bc2302006c908f77819c584109f50c06e7"><code>c66200b</code></a> Thanks <a href="https://github.com/ashishjain0512"><code>@ashishjain0512</code></a>! - fix: neo-look arrowheads and crow's-foot markers no longer fall back to default theme colours/stroke widths on the first render with <code>layout: elk</code>. State diagram arrowheads stayed dark on dark themes, and ER / requirement markers were drawn at the default stroke width, because markers were created from the layout package's own bundled copy of mermaid, whose config had not been initialized yet.</p> </li> <li> <p><a href="https://redirect.github.com/mermaid-js/mermaid/pull/8079">#8079</a> <a href="https://github.com/mermaid-js/mermaid/commit/281cd7b0705a7cdf4295bfd5e3171647dc809dfb"><code>281cd7b</code></a> Thanks <a href="https://github.com/ashishjain0512"><code>@ashishjain0512</code></a>! - fix(class): class diagram relation markers (composition, aggregation, extension, dependency, lollipop) no longer scale with the edge stroke width, so they stay outside the class box boundary in themes that set <code>strokeWidth: 2</code> (<code>redux</code>, <code>redux-dark</code>, <code>redux-color</code>, <code>redux-dark-color</code>, <code>neo</code>, <code>neo-dark</code>) with the default <code>classic</code> look.</p> </li> </ul> <h2>mermaid@11.17.0</h2> <h3>Minor Changes</h3> <ul> <li> <p><a href="https://redirect.github.com/mermaid-js/mermaid/pull/7842">#7842</a> <a href="https://github.com/mermaid-js/mermaid/commit/3670b4e2d99b27945240dd3fe71da9175fddcaec"><code>3670b4e</code></a> Thanks <a href="https://github.com/filipsajdak"><code>@filipsajdak</code></a>! - feat(c4): render C4 elements through the unified shape system, using the new person shape</p> </li> <li> <p><a href="https://redirect.github.com/mermaid-js/mermaid/pull/7812">#7812</a> <a href="https://github.com/mermaid-js/mermaid/commit/cdfc0ea65f47bc8f9605a2a646ed87c25a692216"><code>cdfc0ea</code></a> Thanks <a href="https://github.com/knsv-bot"><code>@knsv-bot</code></a>! - feat(class): route <code>classDiagram</code> to the unified (v2) renderer by default</p> <p>Set <code>class: { defaultRenderer: 'dagre-d3' }</code> in the config to restore the legacy renderer.</p> </li> <li> <p><a href="https://redirect.github.com/mermaid-js/mermaid/pull/7785">#7785</a> <a href="https://github.com/mermaid-js/mermaid/commit/c45cde9582ede4add658f62b771ba2a7efadde83"><code>c45cde9</code></a> Thanks <a href="https://github.com/knsv-bot"><code>@knsv-bot</code></a>! - feat(flowchart): add collapsible flowchart subgraphs via <code>subgraphId@{ view: collapsed }</code></p> </li> <li> <p><a href="https://redirect.github.com/mermaid-js/mermaid/pull/7828">#7828</a> <a href="https://github.com/mermaid-js/mermaid/commit/8eb3afc08c64e0f5d2b2447daac417250a202c13"><code>8eb3afc</code></a> Thanks <a href="https://github.com/knsv-bot"><code>@knsv-bot</code></a>! - feat(elk): add <code>elk.keepEntryNodeOnTop</code> config option to keep a recursive flow's entry node on top</p> </li> <li> <p><a href="https://redirect.github.com/mermaid-js/mermaid/pull/7803">#7803</a> <a href="https://github.com/mermaid-js/mermaid/commit/74e44ebf86d293cee1f2314c8b8a163284ea3911"><code>74e44eb</code></a> Thanks <a href="https://github.com/knsv-bot"><code>@knsv-bot</code></a>! - feat(elk): add <code>elk.nodePlacementAlignment</code> config option</p> </li> <li> <p><a href="https://redirect.github.com/mermaid-js/mermaid/pull/7792">#7792</a> <a href="https://github.com/mermaid-js/mermaid/commit/ea55b31bcfb36cfdfbc31a531058ee8c4ee53a4f"><code>ea55b31</code></a> Thanks <a href="https://github.com/RodrigojndSantos"><code>@RodrigojndSantos</code></a>! - feat(er): add subgraph support to ER diagrams.</p> </li> <li> <p><a href="https://redirect.github.com/mermaid-js/mermaid/pull/7970">#7970</a> <a href="https://github.com/mermaid-js/mermaid/commit/a2c0fb6cdf8073b8feb10595ea3cccff0237049b"><code>a2c0fb6</code></a> Thanks <a href="https://github.com/filipsajdak"><code>@filipsajdak</code></a>! - feat(flowchart): add <code>folder</code>, <code>bucket</code>, <code>console</code> (terminal window) and <code>browser</code> shapes</p> </li> <li> <p><a href="https://redirect.github.com/mermaid-js/mermaid/pull/7842">#7842</a> <a href="https://github.com/mermaid-js/mermaid/commit/ae3e1157c166fab7520d9ee2ed67b16613f6c243"><code>ae3e115</code></a> Thanks <a href="https://github.com/filipsajdak"><code>@filipsajdak</code></a>! - feat(flowchart): add <code>person</code> shape (circular head above a rounded body), usable in flowcharts via <code>A@{ shape: person }</code></p> </li> <li> <p><a href="https://redirect.github.com/mermaid-js/mermaid/pull/7724">#7724</a> <a href="https://github.com/mermaid-js/mermaid/commit/0fd7a9fe0d10a1ac39359bc5cb5341b5010a624e"><code>0fd7a9f</code></a> Thanks <a href="https://github.com/xdumaine"><code>@xdumaine</code></a>! - feat(xyChart): add legends for named line and bar series</p> </li> </ul> <h3>Patch Changes</h3> <ul> <li> <p><a href="https://redirect.github.com/mermaid-js/mermaid/pull/7847">#7847</a> <a href="https://github.com/mermaid-js/mermaid/commit/215fe89d3ecfb47cf0836cb52bf272b14fc99f29"><code>215fe89</code></a> Thanks <a href="https://github.com/filipsajdak"><code>@filipsajdak</code></a>! - fix(c4): named attributes such as <code>$tags</code>, <code>$link</code> and <code>$sprite</code> are no longer clobbered to undefined when they arrive in an earlier positional slot of Person/System/Container/Component/Boundary/Rel statements.</p> </li> <li> <p><a href="https://redirect.github.com/mermaid-js/mermaid/pull/7871">#7871</a> <a href="https://github.com/mermaid-js/mermaid/commit/8d874c49fa1699cf22e99d4936b16f16dde1fc7f"><code>8d874c4</code></a> Thanks <a href="https://github.com/knsv-bot"><code>@knsv-bot</code></a>! - fix(flowchart): stop dagre layout from spamming <code>warn</code>-level logs on every node/edge/cluster</p> </li> <li> <p><a href="https://redirect.github.com/mermaid-js/mermaid/pull/8071">#8071</a> <a href="https://github.com/mermaid-js/mermaid/commit/b3d1f6316717faf099cbe21c9fb9f41c2e0bc069"><code>b3d1f63</code></a> Thanks <a href="https://github.com/pbrolin47"><code>@pbrolin47</code></a>! - fix(block): sibling blocks overlapping in block diagrams when one has a label wider than 200px</p> </li> <li> <p><a href="https://redirect.github.com/mermaid-js/mermaid/pull/7870">#7870</a> <a href="https://github.com/mermaid-js/mermaid/commit/71b8843fb5ae25d7b884f5cc7ba856d978e0420b"><code>71b8843</code></a> Thanks <a href="https://github.com/knsv-bot"><code>@knsv-bot</code></a>! - fix: a <code>RangeError: Invalid array length</code> crash when rendering certain edges.</p> </li> <li> <p><a href="https://redirect.github.com/mermaid-js/mermaid/pull/7924">#7924</a> <a href="https://github.com/mermaid-js/mermaid/commit/9cbef5d94f3aa6bea04b44f23ad81c1b8d7ca2b7"><code>9cbef5d</code></a> Thanks <a href="https://github.com/nightt5879"><code>@nightt5879</code></a>! - fix(treeView): icons disappearing after strict security sanitization.</p> </li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/mermaid-js/mermaid/commit/dcb694ddb58dc5ad3502e7e903cac05fd812eac3"><code>dcb694d</code></a> Version Packages (<a href="https://redirect.github.com/mermaid-js/mermaid/issues/8130">#8130</a>)</li> <li><a href="https://github.com/mermaid-js/mermaid/commit/178d7c79fcbafcf0662b822ec34ed989372ee5c2"><code>178d7c7</code></a> fix: restore edgePaths class on the edge group (<a href="https://redirect.github.com/mermaid-js/mermaid/issues/8125">#8125</a>)</li> <li><a href="https://github.com/mermaid-js/mermaid/commit/569f46e2617f6627e00e56f9a3669369fc86f9c1"><code>569f46e</code></a> Version Packages (<a href="https://redirect.github.com/mermaid-js/mermaid/issues/8114">#8114</a>)</li> <li><a href="https://github.com/mermaid-js/mermaid/commit/3054836688bfa5cef4abca757548e5da6da962b9"><code>3054836</code></a> Version Packages</li> <li><a href="https://github.com/mermaid-js/mermaid/commit/5b17e0a38f8e1094f1fd62b7f74a2877c3cbf0b8"><code>5b17e0a</code></a> Merge pull request <a href="https://redirect.github.com/mermaid-js/mermaid/issues/8092">#8092</a> from mermaid-js/hotfix/11.17.1</li> <li><a href="https://github.com/mermaid-js/mermaid/commit/655211a0657add5136f8358756dd5294c6dcd821"><code>655211a</code></a> Reverted change of wrap-options</li> <li><a href="https://github.com/mermaid-js/mermaid/commit/8a2348020038cd908a819685f555b16694f3d490"><code>8a23480</code></a> Updated doc from feedback</li> <li><a href="https://github.com/mermaid-js/mermaid/commit/412c80abb749da9844322855378140fc2b2a6877"><code>412c80a</code></a> Update doc and consistent handlig in c4 as for seq diags</li> <li><a href="https://github.com/mermaid-js/mermaid/commit/b433a9aad549f650d268309b4ac1af180502cea3"><code>b433a9a</code></a> Updated changeset to describe specifik diagram affected</li> <li><a href="https://github.com/mermaid-js/mermaid/commit/6bae15eb59d2836faf45e6642b24f4a039526d62"><code>6bae15e</code></a> Updated tests to Playwright API</li> <li>Additional commits viewable in <a href="https://github.com/mermaid-js/mermaid/compare/mermaid@11.16.1...mermaid@11.17.2">compare view</a></li> </ul> </details> <br /> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |
||
|
|
480630041d |
chore(deps-dev): bump rollup from 4.62.4 to 4.63.1 (#12570)
Bumps [rollup](https://github.com/rollup/rollup) from 4.62.4 to 4.63.1. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/rollup/rollup/releases">rollup's releases</a>.</em></p> <blockquote> <h2>v4.63.1</h2> <h2>4.63.1</h2> <p><em>2026-08-28</em></p> <h3>Bug Fixes</h3> <ul> <li>Revert function return value tracking until the most recent issue is understood (<a href="https://redirect.github.com/rollup/rollup/issues/6490">#6490</a>)</li> </ul> <h3>Pull Requests</h3> <ul> <li><a href="https://redirect.github.com/rollup/rollup/pull/6489">#6489</a>: fix(deps): update minor/patch updates (<a href="https://github.com/renovate"><code>@renovate</code></a>[bot])</li> <li><a href="https://redirect.github.com/rollup/rollup/pull/6490">#6490</a>: Revert improve function return value tracking (<a href="https://github.com/lukastaegert"><code>@lukastaegert</code></a>)</li> </ul> <h2>v4.63.0</h2> <h2>4.63.0</h2> <p><em>2026-08-25</em></p> <h3>Features</h3> <ul> <li>Allow to analyze function return values in many more cases (<a href="https://redirect.github.com/rollup/rollup/issues/6065">#6065</a>)</li> </ul> <h3>Pull Requests</h3> <ul> <li><a href="https://redirect.github.com/rollup/rollup/pull/6065">#6065</a>: feat: improve function return value tracking (<a href="https://github.com/cyyynthia"><code>@cyyynthia</code></a>, <a href="https://github.com/lukastaegert"><code>@lukastaegert</code></a>)</li> <li><a href="https://redirect.github.com/rollup/rollup/pull/6482">#6482</a>: Remove unused rendered module sources map (<a href="https://github.com/yoominho91"><code>@yoominho91</code></a>, <a href="https://github.com/irontaek"><code>@irontaek</code></a>, <a href="https://github.com/lukastaegert"><code>@lukastaegert</code></a>)</li> <li><a href="https://redirect.github.com/rollup/rollup/pull/6483">#6483</a>: chore(deps): update minor/patch updates (<a href="https://github.com/renovate"><code>@renovate</code></a>[bot])</li> <li><a href="https://redirect.github.com/rollup/rollup/pull/6484">#6484</a>: fix(deps): update swc monorepo (major) (<a href="https://github.com/renovate"><code>@renovate</code></a>[bot], <a href="https://github.com/lukastaegert"><code>@lukastaegert</code></a>)</li> <li><a href="https://redirect.github.com/rollup/rollup/pull/6485">#6485</a>: chore(deps): lock file maintenance (<a href="https://github.com/renovate"><code>@renovate</code></a>[bot], <a href="https://github.com/lukastaegert"><code>@lukastaegert</code></a>)</li> <li><a href="https://redirect.github.com/rollup/rollup/pull/6486">#6486</a>: chore(deps): lock file maintenance (<a href="https://github.com/renovate"><code>@renovate</code></a>[bot])</li> </ul> <h2>v4.62.5</h2> <h2>4.62.5</h2> <p><em>2026-08-20</em></p> <h3>Bug Fixes</h3> <ul> <li>Resolve an issue where compact mode could result in invalid module concatenations (<a href="https://redirect.github.com/rollup/rollup/issues/6468">#6468</a>)</li> </ul> <h3>Pull Requests</h3> <ul> <li><a href="https://redirect.github.com/rollup/rollup/pull/6468">#6468</a>: Keep the semicolon added after a replaced default export (<a href="https://github.com/Jaybhade"><code>@Jaybhade</code></a>, <a href="https://github.com/lukastaegert"><code>@lukastaegert</code></a>)</li> <li><a href="https://redirect.github.com/rollup/rollup/pull/6469">#6469</a>: fix(deps): update minor/patch updates (<a href="https://github.com/renovate"><code>@renovate</code></a>[bot])</li> <li><a href="https://redirect.github.com/rollup/rollup/pull/6470">#6470</a>: fix(deps): update swc monorepo (major) (<a href="https://github.com/renovate"><code>@renovate</code></a>[bot])</li> <li><a href="https://redirect.github.com/rollup/rollup/pull/6471">#6471</a>: chore(deps): lock file maintenance (<a href="https://github.com/renovate"><code>@renovate</code></a>[bot])</li> <li><a href="https://redirect.github.com/rollup/rollup/pull/6472">#6472</a>: chore(deps): update dependency eslint-plugin-unicorn to v73 (<a href="https://github.com/renovate"><code>@renovate</code></a>[bot])</li> <li><a href="https://redirect.github.com/rollup/rollup/pull/6476">#6476</a>: chore(deps): update dtolnay/rust-toolchain digest to 4360b52 (<a href="https://github.com/renovate"><code>@renovate</code></a>[bot])</li> <li><a href="https://redirect.github.com/rollup/rollup/pull/6477">#6477</a>: fix(deps): update minor/patch updates (<a href="https://github.com/renovate"><code>@renovate</code></a>[bot])</li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/rollup/rollup/blob/master/CHANGELOG.md">rollup's changelog</a>.</em></p> <blockquote> <h2>4.63.1</h2> <p><em>2026-08-28</em></p> <h3>Bug Fixes</h3> <ul> <li>Revert function return value tracking until the most recent issue is understood (<a href="https://redirect.github.com/rollup/rollup/issues/6490">#6490</a>)</li> </ul> <h3>Pull Requests</h3> <ul> <li><a href="https://redirect.github.com/rollup/rollup/pull/6489">#6489</a>: fix(deps): update minor/patch updates (<a href="https://github.com/renovate"><code>@renovate</code></a>[bot])</li> <li><a href="https://redirect.github.com/rollup/rollup/pull/6490">#6490</a>: Revert improve function return value tracking (<a href="https://github.com/lukastaegert"><code>@lukastaegert</code></a>)</li> </ul> <h2>4.63.0</h2> <p><em>2026-08-25</em></p> <h3>Features</h3> <ul> <li>Allow to analyze function return values in many more cases (<a href="https://redirect.github.com/rollup/rollup/issues/6065">#6065</a>)</li> </ul> <h3>Pull Requests</h3> <ul> <li><a href="https://redirect.github.com/rollup/rollup/pull/6065">#6065</a>: feat: improve function return value tracking (<a href="https://github.com/cyyynthia"><code>@cyyynthia</code></a>, <a href="https://github.com/lukastaegert"><code>@lukastaegert</code></a>)</li> <li><a href="https://redirect.github.com/rollup/rollup/pull/6482">#6482</a>: Remove unused rendered module sources map (<a href="https://github.com/yoominho91"><code>@yoominho91</code></a>, <a href="https://github.com/irontaek"><code>@irontaek</code></a>, <a href="https://github.com/lukastaegert"><code>@lukastaegert</code></a>)</li> <li><a href="https://redirect.github.com/rollup/rollup/pull/6483">#6483</a>: chore(deps): update minor/patch updates (<a href="https://github.com/renovate"><code>@renovate</code></a>[bot])</li> <li><a href="https://redirect.github.com/rollup/rollup/pull/6484">#6484</a>: fix(deps): update swc monorepo (major) (<a href="https://github.com/renovate"><code>@renovate</code></a>[bot], <a href="https://github.com/lukastaegert"><code>@lukastaegert</code></a>)</li> <li><a href="https://redirect.github.com/rollup/rollup/pull/6485">#6485</a>: chore(deps): lock file maintenance (<a href="https://github.com/renovate"><code>@renovate</code></a>[bot], <a href="https://github.com/lukastaegert"><code>@lukastaegert</code></a>)</li> <li><a href="https://redirect.github.com/rollup/rollup/pull/6486">#6486</a>: chore(deps): lock file maintenance (<a href="https://github.com/renovate"><code>@renovate</code></a>[bot])</li> </ul> <h2>4.62.5</h2> <p><em>2026-08-20</em></p> <h3>Bug Fixes</h3> <ul> <li>Resolve an issue where compact mode could result in invalid module concatenations (<a href="https://redirect.github.com/rollup/rollup/issues/6468">#6468</a>)</li> </ul> <h3>Pull Requests</h3> <ul> <li><a href="https://redirect.github.com/rollup/rollup/pull/6468">#6468</a>: Keep the semicolon added after a replaced default export (<a href="https://github.com/Jaybhade"><code>@Jaybhade</code></a>, <a href="https://github.com/lukastaegert"><code>@lukastaegert</code></a>)</li> <li><a href="https://redirect.github.com/rollup/rollup/pull/6469">#6469</a>: fix(deps): update minor/patch updates (<a href="https://github.com/renovate"><code>@renovate</code></a>[bot])</li> <li><a href="https://redirect.github.com/rollup/rollup/pull/6470">#6470</a>: fix(deps): update swc monorepo (major) (<a href="https://github.com/renovate"><code>@renovate</code></a>[bot])</li> <li><a href="https://redirect.github.com/rollup/rollup/pull/6471">#6471</a>: chore(deps): lock file maintenance (<a href="https://github.com/renovate"><code>@renovate</code></a>[bot])</li> <li><a href="https://redirect.github.com/rollup/rollup/pull/6472">#6472</a>: chore(deps): update dependency eslint-plugin-unicorn to v73 (<a href="https://github.com/renovate"><code>@renovate</code></a>[bot])</li> <li><a href="https://redirect.github.com/rollup/rollup/pull/6476">#6476</a>: chore(deps): update dtolnay/rust-toolchain digest to 4360b52 (<a href="https://github.com/renovate"><code>@renovate</code></a>[bot])</li> <li><a href="https://redirect.github.com/rollup/rollup/pull/6477">#6477</a>: fix(deps): update minor/patch updates (<a href="https://github.com/renovate"><code>@renovate</code></a>[bot])</li> <li><a href="https://redirect.github.com/rollup/rollup/pull/6478">#6478</a>: chore(deps): lock file maintenance (<a href="https://github.com/renovate"><code>@renovate</code></a>[bot])</li> <li><a href="https://redirect.github.com/rollup/rollup/pull/6479">#6479</a>: chore(deps): lock file maintenance (<a href="https://github.com/renovate"><code>@renovate</code></a>[bot])</li> <li><a href="https://redirect.github.com/rollup/rollup/pull/6480">#6480</a>: chore(deps): lock file maintenance (<a href="https://github.com/renovate"><code>@renovate</code></a>[bot])</li> </ul> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/rollup/rollup/commit/78bfef0cb94479566f81012fafa372c84b90bd34"><code>78bfef0</code></a> 4.63.1</li> <li><a href="https://github.com/rollup/rollup/commit/be6b8352974d521a0574205940b9d1bda66acd9c"><code>be6b835</code></a> Revert improve function return value tracking (<a href="https://redirect.github.com/rollup/rollup/issues/6490">#6490</a>)</li> <li><a href="https://github.com/rollup/rollup/commit/db15922c05713465fa11e5eb976e88ffdb0d3376"><code>db15922</code></a> fix(deps): update minor/patch updates (<a href="https://redirect.github.com/rollup/rollup/issues/6489">#6489</a>)</li> <li><a href="https://github.com/rollup/rollup/commit/34b8b924c815ec9413d7821f6fd54cc615584a51"><code>34b8b92</code></a> 4.63.0</li> <li><a href="https://github.com/rollup/rollup/commit/456b237dbfcc35c48d76c6be2060f881f440a532"><code>456b237</code></a> feat: improve function return value tracking (<a href="https://redirect.github.com/rollup/rollup/issues/6065">#6065</a>)</li> <li><a href="https://github.com/rollup/rollup/commit/21528bb381e0c5a5853f91e04d597fa2f45568fa"><code>21528bb</code></a> fix(deps): update swc monorepo (major) (<a href="https://redirect.github.com/rollup/rollup/issues/6484">#6484</a>)</li> <li><a href="https://github.com/rollup/rollup/commit/250b175b33b6a3ef96b54d509137f23db669ee9f"><code>250b175</code></a> chore(deps): lock file maintenance (<a href="https://redirect.github.com/rollup/rollup/issues/6486">#6486</a>)</li> <li><a href="https://github.com/rollup/rollup/commit/89bda2cd8e9def2ea037e7dbffaf392ce9f1ddcb"><code>89bda2c</code></a> chore(deps): update minor/patch updates (<a href="https://redirect.github.com/rollup/rollup/issues/6483">#6483</a>)</li> <li><a href="https://github.com/rollup/rollup/commit/f0b0413470667e1c4efe6e07ef9aecc144a2a950"><code>f0b0413</code></a> chore(deps): lock file maintenance (<a href="https://redirect.github.com/rollup/rollup/issues/6485">#6485</a>)</li> <li><a href="https://github.com/rollup/rollup/commit/a362d28d4cc01513c927678d068182f569954eba"><code>a362d28</code></a> Remove unused rendered module sources map (<a href="https://redirect.github.com/rollup/rollup/issues/6482">#6482</a>)</li> <li>Additional commits viewable in <a href="https://github.com/rollup/rollup/compare/v4.62.4...v4.63.1">compare view</a></li> </ul> </details> <br /> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |
||
|
|
1b74561fea |
ci(runner): route paid matrix to AWS fleet (#12765)
## Thinking Path > - Paperclip manages AI agents that perform work. > - The paid runner matrix verifies complete runner behavior with real providers. > - Each matrix job currently repeats work on GitHub-hosted runners. > - Paperclip has an ephemeral AWS runner fleet for trusted workflows. > - The paid workflow needs a reviewed and fail-closed route to that fleet. > - This pull request adds that route and keeps the existing hosted runner as the disabled-state fallback. > - The benefit is faster paid campaigns with the same actor, environment, and secret boundaries. ## Linked Issues or Issue Description **What happened?** The Runner Full-Stack E2E workflow always uses `ubuntu-latest-m`. It limits the matrix to 57 parallel jobs. The repository AWS fleet can run 100 ephemeral jobs, but the paid workflow cannot select it. **Expected behavior** An explicit repository flag must select the reviewed AWS fleet label. A missing or invalid flag must keep the existing hosted runner. The workflow must authorize the stable actor identity before it routes any paid job. **Steps to reproduce** 1. Dispatch the Runner Full-Stack E2E workflow from `master`. 2. Inspect a paid matrix job. 3. Observe that the job requests `ubuntu-latest-m` even when the AWS fleet should be used. **Paperclip version or commit** `da0947d3582ac7779d6bf11851c9938eca6c5c8c` **Deployment mode** GitHub Actions paid runner campaign. ## What Changed - Add a fail-closed `RUNNER_E2E_AWS_ENABLED` switch. - Select only the reviewed AWS fleet label or the existing hosted label. - Permit up to 100 parallel jobs in AWS mode. - Keep the hosted-runner limit at 57. - Reauthorize paid execution before checkout and provider access. - Stop paid checkouts from storing GitHub credentials. - Cancel superseded validation-ref campaigns while preserving `master` audit runs. - Add workflow policy checks and operator documentation. ## Verification - `git diff --check` - `actionlint -ignore SC2129 .github/workflows/runner-full-stack-e2e.yml` - The organization runner group permits this workflow only from `refs/heads/master`. - The repository AWS switch remains disabled until this pull request is merged and a one-cell probe succeeds. ## Risks - A wrong fleet policy can leave jobs queued. The disabled state keeps the existing hosted runner. - The AWS fleet uses paid compute. The workflow validates a configured maximum of 100 jobs. - The runner group, actor allowlist, and paid environment remain separate enforcement layers. > For core feature work, check [`ROADMAP.md`](ROADMAP.md) first and discuss it in `#dev` before opening the PR. Feature PRs that overlap with planned core work may need to be redirected — check the roadmap first. See `CONTRIBUTING.md`. ## Model Used OpenAI Codex based on GPT-5 with agentic reasoning, repository inspection, code editing, Git, GitHub API coordination, and static workflow analysis. The exact deployed model identifier and context-window size are not exposed to this task. ## Checklist - [x] I have included a thinking path that traces from project context to this change - [x] I have specified the model used (with version and capability details) - [x] I have checked ROADMAP.md and confirmed this PR does not duplicate planned core work - [x] I have searched GitHub for duplicate or related PRs and linked them above - [x] I have either (a) linked existing issues with `Fixes: #` / `Closes #` / `Refs #` OR (b) described the issue in-PR following the relevant issue template - [x] I have not referenced internal/instance-local Paperclip issues or links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip` URLs) - [x] My branch name describes the change (e.g. `docs/...`, `fix/...`) and contains no internal Paperclip ticket id or instance-derived details - [ ] I have run tests locally and they pass - [x] I have added or updated tests where applicable - [x] I have updated relevant documentation to reflect my changes - [x] I have considered and documented any risks above - [ ] All Paperclip CI gates are green - [ ] Greptile is 5/5 with no open P2s, recommendations, or follow-ups - [x] I will address all Greptile and reviewer comments before requesting mergecanary/v2026.903.0-canary.1 |
||
|
|
e4afd163bf |
fix(paperclip-runner): emit turn.accepted before any terminal turn event (#12752)
> - Paperclip is the open source app people use to manage AI agents for work > - Paperclip uses local adapters to connect agent sessions to the control plane > - The Codex adapter emits turn events from response and notification channels > - A terminal notification can arrive before the turn/start response > - This pull request gates the terminal event on turn.accepted > - The result keeps the event order stable for consumers and tests ## Thinking Path > - Paperclip is the open source app people use to manage AI agents for work > - Paperclip uses local adapters to connect agent sessions to the control plane > - The Codex adapter emits turn events from response and notification channels > - A terminal notification can arrive before the turn/start response > - This pull request gates the terminal event on turn.accepted > - The result keeps the event order stable for consumers and tests ## Linked Issues or Issue Description **What happened?** The Codex harness session emitted `turn.accepted` only after the `turn/start` response resolved. A terminal notification could arrive before that response and reach consumers first. **Expected behavior** The Codex driver must emit `turn.accepted` before any terminal event for the same turn. **Steps to reproduce** 1. Start a Codex harness session. 2. Keep the `turn/start` response pending. 3. Send `turn/started` and `turn/completed` notifications. 4. Observe the event order. **Paperclip version or commit** `afbcd28dae9e51108738c4258929b95ca359186c` **Deployment mode** Built from source with the Codex driver test harness. **Agent adapter(s) involved** Codex. ## What Changed - Add session state that tracks a pending `turn/start` operation. - Resolve the state when `turn/start` succeeds or fails. - Wait for that state before the terminal notification handler emits its event. - Add a regression test that delivers a terminal notification while `turn/start` remains pending. ## Verification - The regression test failed 5 of 5 times before this change and passed 5 of 5 times after it. - The Codex driver suite passed 189 of 189 tests. - The affected live transport test file passed 46 of 46 tests on 10 consecutive runs. - The TypeScript check exited with status 0. - Continuous integration must pass before merge. ## Risks The change affects only Codex turn event ordering. It adds no sleep, retry, or timeout. The main risk is a provider path that does not settle `turn/start`; existing provider response handling still controls completion. ## Model Used OpenAI GPT-5. The exact deployment identifier is not exposed in this environment. Tool use and code execution assisted this change. ## Checklist - [x] I have included a thinking path that traces from project context to this change - [x] I have specified the model used (with version and capability details) - [x] I have checked ROADMAP.md and confirmed this PR does not duplicate planned core work - [x] I have searched GitHub for duplicate or related PRs and linked them above - [x] I have either (a) linked existing issues with `Fixes: #` / `Closes: #` / `Refs #` OR (b) described the issue in-PR following the relevant issue template - [x] I have not referenced internal/instance-local Paperclip issues or links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip` URLs) - [x] My branch name describes the change (e.g. `docs/...`, `fix/...`) and contains no internal Paperclip ticket id or instance-derived details - [x] I have run tests locally and they pass - [x] I have added or updated tests where applicable - [x] I have updated relevant documentation to reflect my changes - [x] I have considered and documented any risks above - [x] All Paperclip CI gates are green - [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups - [x] I will address all Greptile and reviewer comments before requesting merge --------- Co-authored-by: Paperclip <noreply@paperclip.ing> |
||
|
|
1d493eb62a |
test(heartbeat): drain in-flight runs before native-isolation TRUNCATE (#12751)
## Thinking Path > - Paperclip is the open source app people use to manage AI agents for work > - Paperclip runs agent heartbeats and stores their run state in a database > - The direct-adapter native-isolation tests start heartbeat runs and then clear database state > - A terminal run status does not prove that its background database work has stopped > - The teardown can then deadlock with a live run during PostgreSQL `TRUNCATE` > - This pull request drains active runs before teardown and adds a guard for queued or running runs > - The benefit is stable test teardown without a production code change ## Linked Issues or Issue Description This change fixes an intermittent test deadlock in the direct-adapter native-isolation suite. **What happened?** The test teardown could run PostgreSQL `TRUNCATE` while a heartbeat execution still held a write transaction. PostgreSQL then returned error `40P01` during some test runs. **Expected behavior** The test teardown must wait until all heartbeat executions finish before it clears the test database. **Steps to reproduce** 1. Run `server/src/__tests__/heartbeat-direct-adapter-native-isolation.test.ts` repeatedly. 2. Run the suite against PostgreSQL-backed native isolation. 3. Observe intermittent deadlock error `40P01` during teardown. **Paperclip version or commit** Commit `57515726d3ef45a07df9b5ee2dfaf7d108556478`. **Deployment mode** Built from source with the native-isolation test suite. **Agent adapter(s) involved** Not adapter-specific. The test covers the direct adapter path. **Database mode** External PostgreSQL used by the native-isolation test suite. **Additional context** Related prior attempt: [#12715](https://github.com/paperclipai/paperclip/pull/12715). This pull request starts from current `master` and does not depend on that pull request. ## What Changed - Drain active heartbeat run executions before `afterEach` runs `TRUNCATE`. - Assert that no heartbeat run remains `queued` or `running` before teardown. - Drain active executions before `afterAll` removes the temporary database. - Create one shared `heartbeatService` instance in `beforeAll` so the drain tracks the test runs. ## Verification - Run `server/src/__tests__/heartbeat-direct-adapter-native-isolation.test.ts` 20 times. All 20 runs pass. - Run the target suite with `server/src/__tests__/native-run-finalizer.test.ts`. Both files pass with 19 tests. - Run `tsc --noEmit`. The branch adds no new error compared with `master`. - Run the pull request checks after GitHub starts them. ## Risks Low risk. The change affects one test file and no production code. The added drain can expose an incomplete test run before teardown, which is the intended guard. ## Model Used OpenAI GPT-5. Exact runtime model ID: GPT-5. The context window is not exposed to this agent. The model used tool calls and code execution. ## Checklist - [x] I have included a thinking path that traces from project context to this change - [x] I have specified the model used (with version and capability details) - [x] I have checked ROADMAP.md and confirmed this PR does not duplicate planned core work - [x] I have searched GitHub for duplicate or related PRs and linked them above - [x] I have either (a) linked existing issues with `Fixes: #` / `Closes: #` / `Refs: #` OR (b) described the issue in-PR following the relevant issue template - [x] I have not referenced internal/instance-local Paperclip issues or links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip` URLs) - [x] My branch name describes the change (e.g. `docs/...`, `fix/...`) and contains no internal Paperclip ticket id or instance-derived details - [x] I have run tests locally and they pass - [x] I have added or updated tests where applicable - [x] I have updated relevant documentation to reflect my changes - [x] I have considered and documented any risks above - [x] All Paperclip CI gates are green - [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups - [x] I will address all Greptile and reviewer comments before requesting merge Co-authored-by: Paperclip <noreply@paperclip.ing>canary/v2026.903.0-canary.0 |
||
|
|
da0947d358 |
chore(lockfile): refresh pnpm-lock.yaml (#12737)
## Thinking Path > - Paperclip uses a frozen pnpm lockfile to create the same dependency graph for each build. > - The Claude local adapter now uses `@agentclientprotocol/claude-agent-acp` version 0.73.0. > - The root patch configuration contains a patch for version 0.73.0. > - The committed lockfile did not contain the matching patch record. > - A frozen install rejected this mismatch and stopped the master deployment. > - This pull request regenerates only `pnpm-lock.yaml` from the current master manifests. > - The change makes the frozen install valid again. ## Linked Issues or Issue Description Refs #12730 **What happened?** The master lockfile did not match the current patched dependency configuration. **Expected behavior** The frozen install must accept the lockfile on master. **Steps to reproduce** 1. Extract a clean archive of master. 2. Run `NODE_ENV=development CI=true pnpm install --frozen-lockfile --force`. 3. Observe that pnpm rejects the stale lockfile. **Paperclip version or commit** `b1f4910ee57789c7045705a38c31ca34704f3575` **Deployment mode** Self-hosted server. **Installation method** Built from source with pnpm. ## What Changed - Added the patch record for `@agentclientprotocol/claude-agent-acp@0.73.0`. - Updated the Claude local adapter lock entry to version 0.73.0. - Added the matching transitive Claude agent SDK lock entries. ## Verification - `git diff --check` passes. - A clean archive of commit `236767cdd1832575fe93ea50f50df2890fb2bf1f` accepts the frozen lockfile. - `NODE_ENV=development CI=true pnpm install --frozen-lockfile --force` completes with exit code 0 in that archive. - Latest-head GitHub checks are green (32/32 success, neutral, or skipped). - Greptile passed the same head at 5/5 with zero unresolved threads. ## Risks - Risk is low because pnpm generated the only changed file. - The lockfile now records the dependency version that the manifests already require. ## Model Used OpenAI Codex with a GPT-5 family model produced this change. The runtime does not expose the exact deployment ID or context size. The model used high reasoning and shell execution. ## Checklist - [x] I have included a thinking path that traces from project context to this change - [x] I have specified the model used with the available version and capability details - [x] I have checked ROADMAP.md and confirmed this PR does not duplicate planned core work - [x] I have searched GitHub for duplicate or related PRs and linked them above - [x] I have linked the related public pull request with `Refs #` - [x] I have not referenced internal or instance-local Paperclip issues or links - [x] My branch name describes the change and contains no internal Paperclip ticket id - [x] I have run the required local verification and it passes - [x] Tests do not need source changes for this generated lockfile correction - [x] Documentation does not need changes because behavior and commands are unchanged - [x] I have considered and documented the risks above - [x] All Paperclip CI gates are green - [x] Greptile has no open P2 findings, recommendations, or follow-ups - [x] I will address all Greptile and reviewer comments before merge Co-authored-by: lockfile-bot <lockfile-bot@users.noreply.github.com> Co-authored-by: Paperclip <noreply@paperclip.ing> |
||
|
|
f1d9206c4a |
fix(runner): retain aborted admission cleanup (#12755)
## Thinking Path > - Paperclip manages AI agents and their work. > - The runner starts ACPX sessions and controls their resources. > - An aborted admission can leave sandbox preparation active after the opening promise rejects. > - Test teardown can then remove the sandbox directory before that work ends. > - This pull request retains and observes each unfinished admission stage. > - The change gives runtime resources and temporary directories one deterministic cleanup owner. ## Linked Issues or Issue Description **What happened?** Under full test load, an aborted admission test can end before sandbox preparation settles. Test teardown then removes the temporary session directory. The active preparation can report an unhandled `ENOENT` error. **Expected behavior** An aborted admission must observe and retain all active preparation work. Test teardown must wait until that work settles. **Steps to reproduce** 1. Run the complete `@paperclipai/paperclip-runner` test suite under CI load. 2. Abort runtime admission during credential or sandbox preparation. 3. Observe an intermittent test timeout or an unhandled missing-directory error. **Paperclip version or commit** The failure occurred on a branch based on commit `b1f4910ee`. This fix is based on current `master` commit `4d30efa8e`. **Deployment mode** The failure occurred in GitHub Actions on a source build. ## What Changed - Retain each unfinished abortable admission stage in the global runtime-host cleanup set. - Notify the embedding lifecycle when an aborted stage needs deferred cleanup. - Make test teardown abort and await all active opening and cleanup promises before directory removal. - Replace time-based stage detection with exact deferred stage signals. - Add a deterministic regression test for an abort during sandbox preparation. ## Verification - Ran the focused runtime-host file in 20 separate processes. All 20 runs passed without an unhandled error. - Ran `pnpm --filter @paperclipai/paperclip-runner exec vitest run src/drivers/acpx/runtime-host.test.ts` after the rebase. All 27 tests passed. - Ran `pnpm --filter @paperclipai/paperclip-runner check:all` after the rebase. The full command passed. - The final TypeScript test stage passed 127 files and 1,490 tests. All Rust checks, tests, and parity checks passed. - Greptile reviewed two heads. The final review is 5/5 with no open comments. - All latest-head CI and security checks passed. One unrelated workspace test passed on its permitted rerun. ## Risks - Risk is low. An aborted stage now delays final runtime-host cleanup until its active operation settles. - A stage that never settles can delay embedding shutdown. The existing stage operations have bounded or controlled owners. - The regression test holds sandbox preparation and confirms the new cleanup order. > For core feature work, check [`ROADMAP.md`](ROADMAP.md) first and discuss it in `#dev` before opening the PR. Feature PRs that overlap with planned core work may need to be redirected — check the roadmap first. See `CONTRIBUTING.md`. ## Model Used OpenAI Codex with GPT-5 assisted this change. The environment did not provide the exact deployment ID or context size. The model used reasoning, shell tools, code editing, and test execution. ## Checklist - [x] I have included a thinking path that traces from project context to this change - [x] I have specified the model used (with version and capability details) - [x] I have checked ROADMAP.md and confirmed this PR does not duplicate planned core work - [x] I have searched GitHub for duplicate or related PRs and linked them above - [x] I have either (a) linked existing issues with `Fixes: #` / `Closes #` / `Refs #` OR (b) described the issue in-PR following the relevant issue template - [x] I have not referenced internal/instance-local Paperclip issues or links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip` URLs) - [x] My branch name describes the change (e.g. `docs/...`, `fix/...`) and contains no internal Paperclip ticket id or instance-derived details - [x] I have run tests locally and they pass - [x] I have added or updated tests where applicable - [x] I have updated relevant documentation to reflect my changes - [x] I have considered and documented any risks above - [x] All Paperclip CI gates are green - [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups - [x] I will address all Greptile and reviewer comments before requesting merge --------- Co-authored-by: Paperclip <noreply@paperclip.ing> |
||
|
|
4d30efa8e3 | feat(ui): refine streamlined task experience (#12748) | ||
|
|
b1f4910ee5 | feat(ui): refine streamlined workspace surfaces (#12747) | ||
|
|
597fd63b61 | feat(ui): add streamlined navigation foundation (#12746) | ||
|
|
8c89340444 |
fix(onboarding): preserve draft through company refetch (#12735)
## Thinking Path > - Paperclip is the open source app people use to manage AI agents for work. > - Onboarding creates an organization in the browser. > - The browser keeps onboarding drafts for the same origin. > - A new data directory does not clear that browser data. > - The organization create request refreshes the company list. > - The old gate unmounted the live wizard during that refresh. > - This pull request keeps the wizard mounted after its first draft check. > - The customer can continue to the agent step after the organization is created. ## Linked Issues or Issue Description No matching public issue was found. Related earlier fix: Refs #12667. **What happened?** A local canary install could create an organization through the API and then return the browser to an empty organization-name screen. **Expected behavior** The wizard must continue to the agent step after it creates the organization. **Steps to reproduce** 1. Keep a Paperclip onboarding draft in the browser. 2. Run npx paperclipai@canary onboard with a new data directory. 3. Open /onboarding. 4. Enter an organization name and select Continue. **Paperclip version or commit** 2026.902.0-canary.7. The fix is based on current master. **Deployment mode** Local trusted mode through the Paperclip CLI. **Install method** npx package install. **Agent adapter(s) involved** Not adapter-specific. **Database mode** Embedded PostgreSQL. ## What Changed - Keep the onboarding wizard mounted after its first successful draft ownership check. - Keep a failed ownership check retryable, so a later verified fetch restores the saved draft. - Add component, source E2E, and published-canary coverage for the retained-draft refetch case. ## Verification - Confirmed that the new canary scenario fails against 2026.902.0-canary.7 before this fix. - pnpm exec vitest run ui/src/components/OnboardingWizard.test.tsx - PAPERCLIP_E2E_PORT=3245 pnpm exec playwright test --config tests/e2e/playwright.config.ts tests/e2e/onboarding.spec.ts --reporter=line - pnpm --filter @paperclipai/ui typecheck - pnpm check:token-gates ## Risks Low risk. The initial ownership check still waits for a fresh company list. A later successful retry can restore a retained draft. Later background refetches preserve live wizard state. ## Model Used OpenAI Codex, GPT-5. Reasoning, tool use, code editing, terminal execution, and browser testing were used. The execution environment does not expose a context-window size. ## Checklist - [x] I have included a thinking path that traces from project context to this change - [x] I have specified the model used with version and capability details - [x] I have checked ROADMAP.md and confirmed this PR does not duplicate planned core work - [x] I have searched GitHub for duplicate or related PRs and linked them above - [x] I have described the issue in-PR following the bug issue template - [x] I have not referenced internal or instance-local Paperclip issues or links - [x] My branch name describes the change and contains no internal Paperclip ticket id or instance-derived details - [x] I have run tests locally and they pass - [x] I have added or updated tests where applicable - [x] I have updated relevant documentation to reflect my changes - [x] I have considered and documented any risks above - [x] All Paperclip CI gates are green - [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups - [x] I will address all Greptile and reviewer comments before requesting merge --------- Co-authored-by: Paperclip <noreply@paperclip.ing> |