## Thinking Path
> - Paperclip uses a frozen pnpm lockfile to create the same dependency
graph for each build.
> - The Claude local adapter now uses
`@agentclientprotocol/claude-agent-acp` version 0.73.0.
> - The root patch configuration contains a patch for version 0.73.0.
> - The committed lockfile did not contain the matching patch record.
> - A frozen install rejected this mismatch and stopped the master
deployment.
> - This pull request regenerates only `pnpm-lock.yaml` from the current
master manifests.
> - The change makes the frozen install valid again.
## Linked Issues or Issue Description
Refs #12730
**What happened?**
The master lockfile did not match the current patched dependency
configuration.
**Expected behavior**
The frozen install must accept the lockfile on master.
**Steps to reproduce**
1. Extract a clean archive of master.
2. Run `NODE_ENV=development CI=true pnpm install --frozen-lockfile
--force`.
3. Observe that pnpm rejects the stale lockfile.
**Paperclip version or commit**
`b1f4910ee57789c7045705a38c31ca34704f3575`
**Deployment mode**
Self-hosted server.
**Installation method**
Built from source with pnpm.
## What Changed
- Added the patch record for
`@agentclientprotocol/claude-agent-acp@0.73.0`.
- Updated the Claude local adapter lock entry to version 0.73.0.
- Added the matching transitive Claude agent SDK lock entries.
## Verification
- `git diff --check` passes.
- A clean archive of commit `236767cdd1832575fe93ea50f50df2890fb2bf1f`
accepts the frozen lockfile.
- `NODE_ENV=development CI=true pnpm install --frozen-lockfile --force`
completes with exit code 0 in that archive.
- Latest-head GitHub checks are green (32/32 success, neutral, or
skipped).
- Greptile passed the same head at 5/5 with zero unresolved threads.
## Risks
- Risk is low because pnpm generated the only changed file.
- The lockfile now records the dependency version that the manifests
already require.
## Model Used
OpenAI Codex with a GPT-5 family model produced this change. The runtime
does not expose the exact deployment ID or context size. The model used
high reasoning and shell execution.
## Checklist
- [x] I have included a thinking path that traces from project context
to this change
- [x] I have specified the model used with the available version and
capability details
- [x] I have checked ROADMAP.md and confirmed this PR does not duplicate
planned core work
- [x] I have searched GitHub for duplicate or related PRs and linked
them above
- [x] I have linked the related public pull request with `Refs #`
- [x] I have not referenced internal or instance-local Paperclip issues
or links
- [x] My branch name describes the change and contains no internal
Paperclip ticket id
- [x] I have run the required local verification and it passes
- [x] Tests do not need source changes for this generated lockfile
correction
- [x] Documentation does not need changes because behavior and commands
are unchanged
- [x] I have considered and documented the risks above
- [x] All Paperclip CI gates are green
- [x] Greptile has no open P2 findings, recommendations, or follow-ups
- [x] I will address all Greptile and reviewer comments before merge
Co-authored-by: lockfile-bot <lockfile-bot@users.noreply.github.com>
Co-authored-by: Paperclip <noreply@paperclip.ing>
Auto-generated lockfile refresh after dependencies changed on master.
This PR only updates pnpm-lock.yaml.
Co-authored-by: lockfile-bot <lockfile-bot@users.noreply.github.com>
Auto-generated lockfile refresh after dependencies changed on master.
This PR only updates pnpm-lock.yaml.
Co-authored-by: lockfile-bot <lockfile-bot@users.noreply.github.com>
Auto-generated lockfile refresh after dependencies changed on master.
This PR only updates pnpm-lock.yaml.
Co-authored-by: lockfile-bot <lockfile-bot@users.noreply.github.com>
Auto-generated lockfile refresh after dependencies changed on master.
This PR only updates pnpm-lock.yaml.
Co-authored-by: lockfile-bot <lockfile-bot@users.noreply.github.com>
## Thinking Path
> - Paperclip uses one lockfile for all workspace packages.
> - The lockfile makes dependency installation repeatable.
> - The root manifest now includes AgentMail.
> - The old lockfile did not include AgentMail.
> - A frozen installation stopped before deployment.
> - This pull request refreshes the lockfile through the master
workflow.
> - The refresh makes the frozen installation complete again.
## Linked Issues or Issue Description
**What happened?**
The root manifest declared `agentmail@^0.5.14`. The root lockfile did
not contain that dependency. The frozen installation failed.
**Expected behavior**
The lockfile must contain all root dependencies. A frozen installation
must complete without changing the lockfile.
**Steps to reproduce**
1. Check out commit `4310b0c947727ef1ce1a6de3f4a556cd6a1e0ae1`.
2. Run `NODE_ENV=development CI=true pnpm install --frozen-lockfile
--force`.
3. Observe the missing dependency error.
**Paperclip version or commit**
`4310b0c947727ef1ce1a6de3f4a556cd6a1e0ae1`
**Deployment mode**
A self-hosted Linux arm64 deployment uses the master branch.
## What Changed
- Added `agentmail@^0.5.14` to the root lockfile importer.
- Added the dependency resolutions required by the current workspace
manifests.
- Kept the change limited to `pnpm-lock.yaml`.
## Verification
- Used Node.js 24.20.0 and pnpm 9.15.4.
- Ran `NODE_ENV=development CI=true pnpm install --frozen-lockfile
--force`.
- Confirmed that the command completed successfully.
- Confirmed that the command did not change `pnpm-lock.yaml`.
## Risks
- Risk is low because this pull request changes only the generated
lockfile.
- The refresh adds packages that the current manifests already declare.
- A future manifest change can require another lockfile refresh.
> This pull request does not change a core feature. It does not overlap
with `ROADMAP.md`.
## Model Used
OpenAI Codex used the `gpt-5` model. The runtime did not provide the
context-window size. The model used reasoning, shell tools, and code
execution.
## Checklist
- [x] I have included a thinking path that traces from project context
to this change
- [x] I have specified the model used (with version and capability
details)
- [x] I have checked ROADMAP.md and confirmed this PR does not duplicate
planned core work
- [x] I have searched GitHub for duplicate or related PRs and linked
them above
- [x] I have either (a) linked existing issues with `Fixes: #` / `Closes
#` / `Refs #` OR (b) described the issue in-PR following the relevant
issue template
- [x] I have not referenced internal/instance-local Paperclip issues or
links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip`
URLs)
- [x] My branch name describes the change (e.g. `docs/...`, `fix/...`)
and contains no internal Paperclip ticket id or instance-derived details
- [x] I have run tests locally and they pass
- [x] I have added or updated tests where applicable
- [x] I have updated relevant documentation to reflect my changes
- [x] I have considered and documented any risks above
- [x] All Paperclip CI gates are green
- [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups
- [x] I will address all Greptile and reviewer comments before
requesting merge
Co-authored-by: lockfile-bot <lockfile-bot@users.noreply.github.com>
## Thinking Path
> - Paperclip uses workspace manifests to declare package dependencies.
> - The lockfile records each workspace link for repeatable installs.
> - PR #12469 added `@paperclipai/shared` to the Grok local adapter
manifest.
> - The `master` lockfile did not include this new workspace link.
> - A frozen install requires the manifest and lockfile to match.
> - This pull request regenerates the lockfile with the repository
workflow.
> - The benefit is a repeatable frozen install from `master`.
## Linked Issues or Issue Description
Refs #12469
## What Changed
- Added the `@paperclipai/shared` workspace link to the Grok local
adapter importer in `pnpm-lock.yaml`.
## Verification
- Ran `CI=true pnpm install --frozen-lockfile` successfully.
- Ran the full pull request CI suite under Node.js 24. All 23 jobs
passed.
## Risks
- Low risk. This pull request changes only one lockfile importer.
- The package manifest already declares the dependency.
> For core feature work, check [`ROADMAP.md`](ROADMAP.md) first and
discuss it in `#dev` before opening the PR. Feature PRs that overlap
with planned core work may need to be redirected — check the roadmap
first. See `CONTRIBUTING.md`.
## Model Used
- OpenAI Codex with GPT-5 (`gpt-5`). The runtime does not expose the
context limit. Agentic reasoning, repository tools, API tools, and code
execution were enabled.
## Checklist
- [x] I have included a thinking path that traces from project context
to this change
- [x] I have specified the model used (with version and capability
details)
- [x] I have checked ROADMAP.md and confirmed this PR does not duplicate
planned core work
- [x] I have searched GitHub for duplicate or related PRs and linked
them above
- [x] I have either (a) linked existing issues with `Fixes: #` / `Closes
#` / `Refs #` OR (b) described the issue in-PR following the relevant
issue template
- [x] I have not referenced internal/instance-local Paperclip issues or
links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip`
URLs)
- [x] My branch name describes the change (e.g. `docs/...`, `fix/...`)
and contains no internal Paperclip ticket id or instance-derived details
- [x] I have run tests locally and they pass
- [x] I have added or updated tests where applicable
- [x] I have updated relevant documentation to reflect my changes
- [x] I have considered and documented any risks above
- [x] All Paperclip CI gates are green
- [ ] Greptile is 5/5 with no open P2s, recommendations, or follow-ups
- [x] I will address all Greptile and reviewer comments before
requesting merge
Co-authored-by: lockfile-bot <lockfile-bot@users.noreply.github.com>
Auto-generated lockfile refresh after dependencies changed on master.
This PR only updates pnpm-lock.yaml.
Co-authored-by: lockfile-bot <lockfile-bot@users.noreply.github.com>
Auto-generated lockfile refresh after dependencies changed on master.
This PR only updates pnpm-lock.yaml.
Co-authored-by: lockfile-bot <lockfile-bot@users.noreply.github.com>
Auto-generated lockfile refresh after dependencies changed on master.
This PR only updates pnpm-lock.yaml.
Co-authored-by: lockfile-bot <lockfile-bot@users.noreply.github.com>
Auto-generated lockfile refresh after dependencies changed on master.
This PR only updates pnpm-lock.yaml.
Co-authored-by: lockfile-bot <lockfile-bot@users.noreply.github.com>
Auto-generated lockfile refresh after dependencies changed on master.
This PR only updates pnpm-lock.yaml.
Co-authored-by: lockfile-bot <lockfile-bot@users.noreply.github.com>
## Thinking Path
> - Paperclip is the open source app people use to manage AI agents for
work
> - CI owns pnpm-lock.yaml: manifest-changing PRs merge without it, and
this automation lands the regenerated lockfile right after
> - The runner-supervision and PRP-transport merges (#12095, #12100)
added devDependencies to packages/paperclip-runner, desyncing the
lockfile
> - Every frozen-lockfile install on master has failed since, taking CI
down repo-wide
> - This pull request lands the regenerated entries for the
paperclip-runner importer
> - The benefit is CI works again on every branch
## Linked Issues or Issue Description
**What happened?**
Since #12095 merged, every CI job fails in ~15 seconds at `pnpm install
--frozen-lockfile`: the lockfile's `packages/paperclip-runner` importer
does not match its `package.json`.
**Expected behavior**
`pnpm install --frozen-lockfile` succeeds on master.
**Steps to reproduce**
`npx pnpm@9.15.4 install --frozen-lockfile` on master before this
change.
**Paperclip version or commit**
master at `b76e36d6c`.
## What Changed
- `pnpm-lock.yaml` regenerated by the refresh automation (pnpm 9.15.4,
`--lockfile-only`); the diff covers only the `packages/paperclip-runner`
importer's new devDependencies. A human empty commit triggered the
required checks (the automation's `GITHUB_TOKEN` push cannot — fix
proposed in #12115).
## Verification
- `npx pnpm@9.15.4 install --frozen-lockfile` verified locally against
this exact lockfile content (fails on master without it).
- Full required suite green on this PR (30 checks).
## Risks
- None beyond lockfile content; the diff touches no version outside the
paperclip-runner importer.
## Model Used
Claude Fable 5 (Claude Code) — body authored on behalf of the lockfile
automation.
## Pre-submission checklist
- [x] I have included a thinking path that traces from project context
to this change
- [x] I have specified the model used (with version and capability
details)
- [x] I have checked ROADMAP.md and confirmed this PR does not duplicate
planned core work
- [x] I have searched GitHub for duplicate or related PRs and linked
them above
- [x] I have either (a) linked existing issues with `Fixes: #` / `Closes
#` / `Refs #` OR (b) described the issue in-PR following the relevant
issue template
---------
Co-authored-by: lockfile-bot <lockfile-bot@users.noreply.github.com>
Co-authored-by: Devin Foley <devin@paperclip.ing>
Auto-generated lockfile refresh after dependencies changed on master.
This PR only updates pnpm-lock.yaml.
Co-authored-by: lockfile-bot <lockfile-bot@users.noreply.github.com>
Auto-generated lockfile refresh after dependencies changed on master.
This PR only updates pnpm-lock.yaml.
Co-authored-by: lockfile-bot <lockfile-bot@users.noreply.github.com>
## Thinking Path
> - Paperclip uses a pnpm workspace for its packages.
> - Package manifests and the lockfile must stay synchronized.
> - A merged Node version policy fix changed package manifests on
master.
> - The frozen lockfile no longer matched those manifests.
> - This automated pull request refreshes the generated lockfile.
> - The benefit is that clean installs and required CI jobs can run
again.
## What Changed
- Regenerated `pnpm-lock.yaml` from the current package manifests.
## Verification
- `pnpm install --lockfile-only --ignore-scripts --no-frozen-lockfile`
- The repository PR workflow validates the generated lockfile with a
frozen install.
## Risks
Low risk. This is an automation-generated lockfile-only update after
manifest changes on master.
## Model Used
None — automation-generated.
Co-authored-by: lockfile-bot <lockfile-bot@users.noreply.github.com>
Auto-generated lockfile refresh after dependencies changed on master.
This PR only updates pnpm-lock.yaml.
Co-authored-by: lockfile-bot <lockfile-bot@users.noreply.github.com>
Auto-generated lockfile refresh after dependencies changed on master.
This PR only updates pnpm-lock.yaml.
Co-authored-by: lockfile-bot <lockfile-bot@users.noreply.github.com>
Auto-generated lockfile refresh after dependencies changed on master.
This PR only updates pnpm-lock.yaml.
Co-authored-by: lockfile-bot <lockfile-bot@users.noreply.github.com>
Auto-generated lockfile refresh after dependencies changed on master.
This PR only updates pnpm-lock.yaml.
Co-authored-by: lockfile-bot <lockfile-bot@users.noreply.github.com>
Auto-generated lockfile refresh after dependencies changed on master.
This PR only updates pnpm-lock.yaml.
Co-authored-by: lockfile-bot <lockfile-bot@users.noreply.github.com>
Auto-generated lockfile refresh after dependencies changed on master.
This PR only updates pnpm-lock.yaml.
Co-authored-by: lockfile-bot <lockfile-bot@users.noreply.github.com>
Auto-generated lockfile refresh after dependencies changed on master.
This PR only updates pnpm-lock.yaml.
Co-authored-by: lockfile-bot <lockfile-bot@users.noreply.github.com>
Auto-generated lockfile refresh after dependencies changed on master.
This PR only updates pnpm-lock.yaml.
Co-authored-by: lockfile-bot <lockfile-bot@users.noreply.github.com>
Auto-generated lockfile refresh after dependencies changed on master.
This PR only updates pnpm-lock.yaml.
Co-authored-by: lockfile-bot <lockfile-bot@users.noreply.github.com>
Auto-generated lockfile refresh after dependencies changed on master.
This PR only updates pnpm-lock.yaml.
Co-authored-by: lockfile-bot <lockfile-bot@users.noreply.github.com>
Auto-generated lockfile refresh after dependencies changed on master.
This PR only updates pnpm-lock.yaml.
Co-authored-by: lockfile-bot <lockfile-bot@users.noreply.github.com>
Auto-generated lockfile refresh after dependencies changed on master.
This PR only updates pnpm-lock.yaml.
Co-authored-by: lockfile-bot <lockfile-bot@users.noreply.github.com>
Auto-generated lockfile refresh after dependencies changed on master.
This PR only updates pnpm-lock.yaml.
Co-authored-by: lockfile-bot <lockfile-bot@users.noreply.github.com>
Auto-generated lockfile refresh after dependencies changed on master.
This PR only updates pnpm-lock.yaml.
Co-authored-by: lockfile-bot <lockfile-bot@users.noreply.github.com>
Auto-generated lockfile refresh after dependencies changed on master.
This PR only updates pnpm-lock.yaml.
Co-authored-by: lockfile-bot <lockfile-bot@users.noreply.github.com>
Auto-generated lockfile refresh after dependencies changed on master.
This PR only updates pnpm-lock.yaml.
Co-authored-by: lockfile-bot <lockfile-bot@users.noreply.github.com>
Auto-generated lockfile refresh after dependencies changed on master.
This PR only updates pnpm-lock.yaml.
Co-authored-by: lockfile-bot <lockfile-bot@users.noreply.github.com>
Auto-generated lockfile refresh after dependencies changed on master.
This PR only updates pnpm-lock.yaml.
Co-authored-by: lockfile-bot <lockfile-bot@users.noreply.github.com>
## Thinking Path
> - Paperclip is the open source app people use to manage AI agents for
work.
> - The JavaScript workspace depends on a frozen pnpm lockfile so CI and
installs resolve the same dependency graph everywhere.
> - PR #8557 updated the React package manifests and overrides to
`^19.2.7`, but master kept a stale lockfile.
> - That left master unable to run `pnpm install --frozen-lockfile`
because the lockfile override metadata no longer matched `package.json`.
> - This pull request refreshes only `pnpm-lock.yaml` from current
master so the dependency graph matches the already-merged manifests.
> - The benefit is that master CI can install dependencies again and
React/React DOM consistently resolve to `19.2.7`.
## Linked Issues or Issue Description
Bug fix: PR #8557 merged React/React DOM manifest and override
alignment, but the resulting master branch retained a stale
`pnpm-lock.yaml`. Running `CI=true pnpm install --frozen-lockfile` on
master failed with `ERR_PNPM_LOCKFILE_CONFIG_MISMATCH`, and the lockfile
still resolved React packages through `19.2.4` entries instead of
`19.2.7`.
Related public PR: #8557.
## What Changed
- Refreshed `pnpm-lock.yaml` from current master.
- Kept the diff lockfile-only.
- Brought `react` and `react-dom` lockfile resolution to `19.2.7`.
## Verification
- `CI=true pnpm install --frozen-lockfile`
- `git diff --name-status origin/master..HEAD` shows only
`pnpm-lock.yaml`.
- Lockfile inspection shows `react@19.2.7` and `react-dom@19.2.7`
entries.
## Risks
Low risk. This is a generated lockfile-only refresh. The main risk is
merge-time lockfile drift if master changes dependencies before this
lands; if that happens, regenerate the lockfile instead of taking the
stale master side.
## Model Used
OpenAI GPT-5 Codex via Codex CLI, with repository tool use and command
execution.
## Checklist
- [x] I have included a thinking path that traces from project context
to this change
- [x] I have specified the model used (with version and capability
details)
- [x] I have checked ROADMAP.md and confirmed this PR does not duplicate
planned core work
- [x] I have searched GitHub for duplicate or related PRs and linked
them above
- [x] I have either (a) linked existing issues with `Fixes: #` / `Closes
#` / `Refs #` OR (b) described the issue in-PR following the relevant
issue template
- [x] I have not referenced internal/instance-local Paperclip issues or
links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip`
URLs)
- [x] My branch name describes the change (e.g. `docs/...`, `fix/...`)
and contains no internal Paperclip ticket id or instance-derived details
- [x] I have run tests locally and they pass
- [x] I have added or updated tests where applicable
- [x] I have updated relevant documentation to reflect my changes
- [x] I have considered and documented any risks above
- [ ] All Paperclip CI gates are green
- [ ] Greptile is 5/5 with no open P2s, recommendations, or follow-ups
- [x] I will address all Greptile and reviewer comments before
requesting merge
Co-authored-by: lockfile-bot <lockfile-bot@users.noreply.github.com>
Auto-generated lockfile refresh after dependencies changed on master.
This PR only updates pnpm-lock.yaml.
Co-authored-by: lockfile-bot <lockfile-bot@users.noreply.github.com>
Auto-generated lockfile refresh after dependencies changed on master.
This PR only updates pnpm-lock.yaml.
Co-authored-by: lockfile-bot <lockfile-bot@users.noreply.github.com>
Auto-generated lockfile refresh after dependencies changed on master.
This PR only updates pnpm-lock.yaml.
Co-authored-by: lockfile-bot <lockfile-bot@users.noreply.github.com>
Auto-generated lockfile refresh after dependencies changed on master.
This PR only updates pnpm-lock.yaml.
Co-authored-by: lockfile-bot <lockfile-bot@users.noreply.github.com>
Auto-generated lockfile refresh after dependencies changed on master.
This PR only updates pnpm-lock.yaml.
Co-authored-by: lockfile-bot <lockfile-bot@users.noreply.github.com>
Auto-generated lockfile refresh after dependencies changed on master.
This PR only updates pnpm-lock.yaml.
Co-authored-by: lockfile-bot <lockfile-bot@users.noreply.github.com>
Auto-generated lockfile refresh after dependencies changed on master.
This PR only updates pnpm-lock.yaml.
Co-authored-by: lockfile-bot <lockfile-bot@users.noreply.github.com>
Auto-generated lockfile refresh after dependencies changed on master.
This PR only updates pnpm-lock.yaml.
Co-authored-by: lockfile-bot <lockfile-bot@users.noreply.github.com>
Auto-generated lockfile refresh after dependencies changed on master.
This PR only updates pnpm-lock.yaml.
Co-authored-by: lockfile-bot <lockfile-bot@users.noreply.github.com>
Auto-generated lockfile refresh after dependencies changed on master.
This PR only updates pnpm-lock.yaml.
Co-authored-by: lockfile-bot <lockfile-bot@users.noreply.github.com>
Auto-generated lockfile refresh after dependencies changed on master.
This PR only updates pnpm-lock.yaml.
Co-authored-by: lockfile-bot <lockfile-bot@users.noreply.github.com>
Auto-generated lockfile refresh after dependencies changed on master.
This PR only updates pnpm-lock.yaml.
Co-authored-by: lockfile-bot <lockfile-bot@users.noreply.github.com>