mirror of
https://github.com/paperclipai/paperclip.git
synced 2026-10-07 07:23:08 +02:00
## Thinking Path
> - Paperclip is the open source app people use to manage AI agents for
work.
> - Paperclip uses separate server and browser packages for runtime
services and the board.
> - Sentry integrations need an exact SDK version and safe optional
loading.
> - A version range can select an SDK that the privacy tests did not
audit.
> - Missing peer metadata does not describe the optional server SDK
contract.
> - This pull request pins the browser SDK and gates the optional server
SDK on its exact version.
> - The benefit is a clear SDK contract with fail-open startup behavior.
## Linked Issues or Issue Description
**What happened?**
The browser package used the range ^10.71.0, so a lockfile refresh could
select a newer SDK. The server loaded @sentry/node dynamically but did
not declare its optional peer contract.
**Expected behavior**
The browser package must use the audited 10.71.0 version. The server
must load @sentry/node only when the installed peer matches 10.71.0. The
server must start when the optional peer is absent.
**Steps to reproduce**
1. Install the project dependencies.
2. Inspect the browser Sentry version and the server package metadata.
3. Start the server without installing @sentry/node.
4. Confirm that the server starts and that the dynamic Sentry bootstrap
does not load an unsupported peer version.
**Paperclip version or commit**
9c57c0f119
**Deployment mode**
Built from source with pnpm dev or pnpm build.
**Installation method**
Built from source.
**Agent adapter(s) involved**
Not adapter-specific (core change).
**Database mode**
Not database-related.
## What Changed
- Pin @sentry/browser to exactly 10.71.0 as a UI development dependency.
- Declare @sentry/node as an optional server peer dependency at 10.71.0.
- Gate the dynamic server bootstrap on the exact peer version.
- Add tests for the browser pin, peer metadata, version gate, and
fail-open loading.
- Document the supported server SDK version.
- Keep the lockfile unchanged because the pull request workflow
regenerates it for manifest changes.
## Verification
- Server tests pass with six expected skips when @sentry/node is absent.
- UI tests pass.
- The UI build emits the lazy Sentry browser chunk.
- git diff --check passes.
- GitHub pull request checks must pass after this pull request opens.
- Greptile must return a 5/5 score with no open findings.
## Risks
The exact version gate prevents Sentry startup when an unsupported SDK
version exists. The integration remains optional and fail-open. The
lockfile workflow must regenerate the lockfile before frozen downstream
jobs run. The label-gated Storybook visual job must not run until it can
restore the generated lockfile artifact.
## Model Used
OpenAI Codex, GPT-5, tool use and code review support, exact context
window details are managed by the execution platform.
## Checklist
- [x] I have included a thinking path that traces from project context
to this change
- [x] I have specified the model used (with version and capability
details)
- [x] I have checked ROADMAP.md and confirmed this PR does not duplicate
planned core work
- [x] I have searched GitHub for duplicate or related PRs and linked
them above
- [x] I have either (a) linked existing issues with Fixes: # / Closes: #
/ Refs: # OR (b) described the issue in-PR following the relevant issue
template
- [x] I have not referenced internal/instance-local Paperclip issues or
links
- [x] My branch name describes the change and contains no internal
Paperclip ticket id or instance-derived details
- [x] I have run tests locally and they pass
- [x] I have added or updated tests where applicable
- [x] I have updated relevant documentation to reflect my changes
- [x] I have considered and documented any risks above
- [x] All Paperclip CI gates are green
- [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups
- [x] I will address all Greptile and reviewer comments before
requesting merge
---------
Co-authored-by: Paperclip <noreply@paperclip.ing>
143 lines
4.7 KiB
JSON
143 lines
4.7 KiB
JSON
{
|
|
"name": "@paperclipai/server",
|
|
"version": "0.3.1",
|
|
"license": "MIT",
|
|
"homepage": "https://github.com/paperclipai/paperclip",
|
|
"bugs": {
|
|
"url": "https://github.com/paperclipai/paperclip/issues"
|
|
},
|
|
"repository": {
|
|
"type": "git",
|
|
"url": "https://github.com/paperclipai/paperclip",
|
|
"directory": "server"
|
|
},
|
|
"type": "module",
|
|
"exports": {
|
|
".": "./src/index.ts"
|
|
},
|
|
"publishConfig": {
|
|
"access": "public",
|
|
"exports": {
|
|
".": {
|
|
"types": "./dist/index.d.ts",
|
|
"import": "./dist/index.js"
|
|
}
|
|
},
|
|
"main": "./dist/index.js",
|
|
"types": "./dist/index.d.ts"
|
|
},
|
|
"files": [
|
|
"dist",
|
|
"ui-dist",
|
|
"skills"
|
|
],
|
|
"scripts": {
|
|
"dev": "tsx src/index.ts",
|
|
"dev:watch": "cross-env PAPERCLIP_MIGRATION_PROMPT=never PAPERCLIP_MIGRATION_AUTO_APPLY=true tsx ./scripts/dev-watch.ts",
|
|
"prepare:ui-dist": "bash ../scripts/prepare-server-ui-dist.sh",
|
|
"build": "pnpm run prepare:runner-vendor && tsc && mkdir -p dist/onboarding-assets dist/built-ins dist/services/scripts dist/vendor/paperclip-runner && cp -R src/onboarding-assets/. dist/onboarding-assets/ && cp -R src/built-ins/. dist/built-ins/ && cp -R src/services/scripts/. dist/services/scripts/ && cp -R ../packages/paperclip-runner/dist/. dist/vendor/paperclip-runner/ && node scripts/write-build-stamp.mjs",
|
|
"prepack": "pnpm run prepare:ui-dist && pnpm run build",
|
|
"postpack": "rm -rf ui-dist",
|
|
"clean": "rm -rf dist",
|
|
"start": "node dist/index.js",
|
|
"prepare:runner-vendor": "pnpm --filter @paperclipai/paperclip-runner build",
|
|
"typecheck": "pnpm run prepare:runner-vendor && pnpm --filter @paperclipai/plugin-sdk ensure-build-deps && tsc --noEmit"
|
|
},
|
|
"dependencies": {
|
|
"@aws-sdk/client-s3": "^3.1115.0",
|
|
"@opentelemetry/api": "^1.9.0",
|
|
"@paperclipai/adapter-claude-local": "workspace:*",
|
|
"@paperclipai/adapter-codex-local": "workspace:*",
|
|
"@paperclipai/adapter-cursor-cloud": "workspace:*",
|
|
"@paperclipai/adapter-cursor-local": "workspace:*",
|
|
"@paperclipai/adapter-gemini-local": "workspace:*",
|
|
"@paperclipai/adapter-grok-local": "workspace:*",
|
|
"@paperclipai/adapter-kimi-local": "workspace:*",
|
|
"@paperclipai/adapter-openclaw-gateway": "workspace:*",
|
|
"@paperclipai/adapter-opencode-local": "workspace:*",
|
|
"@paperclipai/adapter-pi-local": "workspace:*",
|
|
"@paperclipai/adapter-utils": "workspace:*",
|
|
"@paperclipai/db": "workspace:*",
|
|
"@paperclipai/plugin-sdk": "workspace:*",
|
|
"@paperclipai/shared": "workspace:*",
|
|
"@paperclipai/skills-catalog": "workspace:*",
|
|
"@paperclipai/hermes-paperclip-adapter": "workspace:*",
|
|
"ajv": "^8.20.0",
|
|
"ajv-formats": "^3.0.1",
|
|
"better-auth": "1.7.0",
|
|
"chokidar": "^5.0.0",
|
|
"detect-port": "^2.1.0",
|
|
"dompurify": "^3.4.13",
|
|
"dotenv": "^17.4.2",
|
|
"drizzle-orm": "^0.45.2",
|
|
"embedded-postgres": "^18.1.0-beta.16",
|
|
"express": "^5.1.0",
|
|
"jsdom": "^30.0.1",
|
|
"multer": "^2.2.0",
|
|
"open": "^11.0.1",
|
|
"pino": "^10.0.0",
|
|
"pino-http": "^11.0.0",
|
|
"pino-pretty": "^13.1.3",
|
|
"sharp": "^0.35.3",
|
|
"ssh2": "^1.17.0",
|
|
"ws": "^8.21.3",
|
|
"zod": "^4.4.3"
|
|
},
|
|
"devDependencies": {
|
|
"@paperclipai/paperclip-runner": "workspace:*",
|
|
"@types/express": "^5.0.0",
|
|
"@types/express-serve-static-core": "^5.1.3",
|
|
"@types/jsdom": "^30.0.0",
|
|
"@types/multer": "^2.2.0",
|
|
"@types/node": "^24.0.0",
|
|
"@types/sharp": "^0.32.0",
|
|
"@types/supertest": "^7.2.1",
|
|
"@types/ws": "^8.18.1",
|
|
"cross-env": "^10.1.0",
|
|
"supertest": "^7.0.0",
|
|
"tsx": "^4.23.12",
|
|
"typescript": "^7.0.2",
|
|
"vite": "^8.2.2",
|
|
"vitest": "^4.1.10"
|
|
},
|
|
"peerDependencies": {
|
|
"@opentelemetry/auto-instrumentations-node": "0.79.0",
|
|
"@opentelemetry/exporter-trace-otlp-grpc": "0.221.0",
|
|
"@opentelemetry/exporter-trace-otlp-http": "0.221.0",
|
|
"@opentelemetry/exporter-trace-otlp-proto": "0.221.0",
|
|
"@opentelemetry/resources": "2.10.0",
|
|
"@opentelemetry/sdk-node": "0.221.0",
|
|
"@opentelemetry/semantic-conventions": "1.43.0",
|
|
"@sentry/node": "10.71.0"
|
|
},
|
|
"peerDependenciesMeta": {
|
|
"@opentelemetry/auto-instrumentations-node": {
|
|
"optional": true
|
|
},
|
|
"@opentelemetry/exporter-trace-otlp-grpc": {
|
|
"optional": true
|
|
},
|
|
"@opentelemetry/exporter-trace-otlp-http": {
|
|
"optional": true
|
|
},
|
|
"@opentelemetry/exporter-trace-otlp-proto": {
|
|
"optional": true
|
|
},
|
|
"@opentelemetry/resources": {
|
|
"optional": true
|
|
},
|
|
"@opentelemetry/sdk-node": {
|
|
"optional": true
|
|
},
|
|
"@opentelemetry/semantic-conventions": {
|
|
"optional": true
|
|
},
|
|
"@sentry/node": {
|
|
"optional": true
|
|
}
|
|
},
|
|
"engines": {
|
|
"node": ">=24.11.0"
|
|
}
|
|
}
|