Peter Steinberger
a3b2700dff
fix(deps): bump @openclaw/fs-safe to 0.5.5 for win32 zero-inode identity ( #122427 )
2026-08-11 21:46:22 -07:00
Peter Steinberger
750d0dcd9e
improve(ui): make warm session switching instant ( #121625 )
...
* perf(ui): make warm session switching instant
Amp-Thread-ID: https://ampcode.com/threads/T-019fe957-0e49-707f-859f-9600ef536125
* fix(ui): harden retained session ownership
Amp-Thread-ID: https://ampcode.com/threads/T-019fe957-0e49-707f-859f-9600ef536125
* test(ui): scope retained session assertions
Amp-Thread-ID: https://ampcode.com/threads/T-019fe957-0e49-707f-859f-9600ef536125
* fix(ui): align generated image preview checks
* fix(ui): preserve early transcript reading position
Amp-Thread-ID: https://ampcode.com/threads/T-019fe957-0e49-707f-859f-9600ef536125
* fix(ui): adopt latest-navigation-wins router
Amp-Thread-ID: https://ampcode.com/threads/T-019fe957-0e49-707f-859f-9600ef536125
* fix(ui): restore retained pane reactivity
Amp-Thread-ID: https://ampcode.com/threads/T-019fe957-0e49-707f-859f-9600ef536125
* test(auto-reply): align item lifecycle expectations
* fix(ci): repair current-main validation gates
Amp-Thread-ID: https://ampcode.com/threads/T-019fe957-0e49-707f-859f-9600ef536125
---------
Co-authored-by: Amp <amp@ampcode.com >
2026-08-10 16:17:25 -07:00
Ayaan Zaidi
5295f2578e
fix(agents): make file reads safe and explicit ( #121508 )
...
Use fs-safe 0.5.4 for nonblocking, descriptor-validated reads. Resolve one unambiguous Unicode-equivalent path and return explicit empty/EOF results.
Default local reads now reject final symlinks and special files.
Co-authored-by: Ayaan Zaidi <hi@obviy.us >
2026-08-10 20:17:53 +05:30
Vincent Koc
b5180b6816
fix(codex): support app-server 0.147.0 ( #120594 )
...
* fix(codex): support app-server 0.147.0
* docs(codex): clarify marketplace version provenance
2026-08-08 23:07:05 +08:00
Peter Steinberger
e8da40010a
fix(deps): update nanoid past advisory ( #120368 )
2026-08-07 15:36:56 -07:00
Vincent Koc
c67556df31
fix(tooling): stop pnpm from reconciling shared worktree deps ( #119863 )
2026-08-06 16:58:01 +08:00
Vincent Koc
b269e652bc
chore(codex): bump app-server to 0.146.1
2026-08-06 07:11:37 +08:00
Peter Steinberger
58025dd33c
fix(fs): adopt fs-safe 0.5.2 untrusted filename sanitization ( #119363 )
...
* fix(fs): adopt fs-safe 0.5.2 untrusted filename sanitization
* fix(media): classify pre-open identity drift as access denial
* chore(checks): refresh SDK baseline and env-var budget for fs-safe adoption
* test(media): compact sanitizer cases under max-lines
* fix(agents): keep workspace symlink contract under fs-safe 0.5.2
* fix(infra): align path normalization and atomic-write proofs with fs-safe 0.5.2
* fix(fs): keep operator symlink contracts on config, control-ui, skills, hooks
* fix(fs): restore sandbox and session-lock contracts under fs-safe 0.5.2
* test(claws): expect symlink diagnostic for tampered plan parents
* fix(agents): canonicalize apply-patch mutations through contained aliases
* test(agents): split alias-update regression into focused file
---------
Co-authored-by: Peter Steinberger <steipete@mac-studio-sf2.local >
2026-08-04 17:53:44 -07:00
Vincent Koc
45643863d7
fix(test): isolate shared state between test files ( #118781 )
...
* fix(test): isolate session suspension state
* fix(test): isolate nonzero worker exit coverage
* fix(test): keep suspension reset generations monotonic
* fix(test): isolate archived session UI mocks
* fix(deps): patch fast-uri and undici advisories
* fix(test): isolate stateful UI suites
2026-08-04 15:26:22 +08:00
Peter Steinberger
25aa29d7a1
refactor: delete dead post-landing plugin/hooks scaffolding ( #118920 )
...
* refactor: delete dead post-landing plugin/hooks scaffolding
* fix(security): resolve fast-uri and undici HIGH advisories
2026-08-04 04:26:22 +08:00
Peter Steinberger
2efac6c999
feat(cli): add session archive and delete commands ( #118791 )
...
* feat(cli): add session lifecycle commands
* fix(deps): update brace-expansion security pin
* chore: defer session lifecycle release note
2026-08-03 11:00:17 -07:00
pash-openai
e52354ea13
fix(build): pin typebox to a published release ( #116333 )
2026-07-30 09:58:51 +00:00
Peter Steinberger
dc60a9442d
feat(talk): support GPT-Live over gateway relay ( #115831 )
...
* feat(talk): add GPT-Live gateway relay peer
* fix(talk): ignore duplicate GPT-Live sideband audio
* fix(openai): harden GPT-Live relay startup
* fix(deps): replace vulnerable werift ip helper
* fix(deps): scope werift ip override version
* fix(openai): normalize relay startup errors
* test(ci): register GPT-Live gateway live shard
* fix(talk): tighten GPT-Live relay readiness
* fix(talk): keep relay override helper private
* fix(talk): resolve relay readiness with launch model
* fix(openai): preserve GPT-Live media clock
* fix(talk): align GPT-Live relay readiness and framing
* fix(openai): expire pending GPT-Live reservations
* fix(openai): harden GPT-Live delegation audio
* style(openai): satisfy RTP reorder lint
2026-07-29 12:54:23 -04:00
stevenlee-oai
a00438a867
fix(codex): restore connected apps for token-authenticated runs ( #115075 )
...
* fix(codex): restore connected apps for token-authenticated runs
* fix(codex): keep app inventory protocol types private
* fix(codex): align native runtime with Codex 0.146.0
Co-authored-by: Steven Lee <stevenlee@openai.com >
* fix(codex): clean up latest app-server integration
Co-authored-by: Steven Lee <stevenlee@openai.com >
* fix(codex): keep internal protocol types private
* fix(ci): repair current main Codex landing gates
* fix(ci): format inherited code mode matrix
* fix(codex): reconcile native app-server contracts with main
Prepare a verified GitHub-hosted mainline merge while preserving the reviewed Codex 0.146.0 fixes and canonical OpenAI authentication.
Co-authored-by: Steven Lee <stevenlee@openai.com >
* fix(codex): keep QA evidence in its owning plugin
Resolve the current-main Code Mode test rename without resurrecting the retired core test path.
Co-authored-by: Steven Lee <stevenlee@openai.com >
* fix(codex): enforce canonical OpenAI app-server auth
Reject retired provider aliases without runtime compatibility, direct operators to the doctor migration, and remove the redundant OpenAI API-key predicate.
Co-authored-by: Steven Lee <stevenlee@openai.com >
* chore(codex): reconcile latest main dependency graph
Preserve current main dependency changes while preparing the original Codex PR for an ancestry-preserving signed mainline merge.
Co-authored-by: Steven Lee <stevenlee@openai.com >
* fix(codex): unify bundled Codex 0.146 runtimes
Keep the ACP adapter on the same 0.146.0 Codex release as the managed runtime, remove obsolete 0.145.0 platform artifacts and unused semver compatibility, and preserve the latest main dependency upgrades.
Co-authored-by: Steven Lee <stevenlee@openai.com >
---------
Co-authored-by: Peter Steinberger <peter@steipete.me >
Co-authored-by: Peter Steinberger <steipete@gmail.com >
2026-07-29 06:21:25 -04:00
Peter Steinberger
4232126bba
chore: update dependencies across workspace ( #115677 )
...
* chore(deps): update dependencies
* fix(deps): restore CI compatibility
2026-07-29 05:16:42 -04:00
Vincent Koc
9d5bec8487
fix(deps): remediate tar and Hono advisories ( #115029 )
2026-07-28 16:48:04 +08:00
Peter Steinberger
0d7fb8eb39
refactor(fs): adopt fs-safe 0.5 core primitives ( #113705 )
...
* refactor(fs): unify exclusive file publication
* fix(fs): fence stale lock reclamation
* refactor(fs): bound wiki scans and secret reads
* chore(fs): finalize fs-safe 0.5 compatibility
* fix(fs): preserve publication ownership and legacy mode
* fix(fs): fail closed on unverifiable lock owners
* fix(fs): preserve concurrent backup publications
* refactor(fs): preserve ambiguous backup outputs
* fix(fs): preserve mixed-version lock coordination
* refactor(file-transfer): adopt fs-safe archive extraction
* refactor(fs): add bounded walk and secret seams
* refactor(auth): replace proper-lockfile with fs-safe
* fix(fs): honor Windows mode override casing
* refactor(snapshot): adopt fs-safe publication
* refactor(memory-wiki): adopt prunable root walks
* refactor(fleet): adopt bounded archive restore
* fix(fs): preserve post-publication ownership receipts
* refactor(fs): harvest final fs-safe primitives
* style(fs): clean harvest lint
* chore(plugin-sdk): refresh move helper API baseline
* refactor(snapshot): adopt native Windows ACL facts
* refactor(fs): adopt hardened atomic outputs
* fix(fs): scope lock reentrancy to logical owners
* chore(config): lower env var count budget
* fix(deps): adopt published fs-safe 0.5.0
* fix(ci): align SDK surface ratchets
* fix(ci): regenerate SDK API baseline after rebase
* fix(fs): preserve owner-scoped file lock nesting
* fix(ci): refresh SDK API baseline for file locks
* fix(fs): separate SQLite and file lock reentrancy
* fix(imessage): bound pinned attachment reads
* fix(agents): narrow session-key lock options
* fix(fs): preserve fs-safe 0.5 compatibility contracts
* fix(windows): retain private SQLite directory owner
* refactor(sqlite): centralize exclusive coordinator
* refactor(snapshot): isolate Windows ACL policy
* fix(windows): retain snapshot ACL inspector
* chore(config): realign env budget after rebase
* test(agents): accept canonical sandbox escape error
* docs(changelog): defer fs-safe release note
2026-07-28 03:41:47 -04:00
Peter Steinberger
d6971f46ca
fix: make filesystem publication crash-durable ( #113453 )
...
* fix(fs): centralize directory durability
* chore: keep release notes in PR body
* test(sqlite): canonicalize read-only race paths
* test(fs): clean durability fixtures
* chore(lint): prune sqlite snapshot baseline
* fix(backup): reject unsupported commit sync
* fix(fs): enforce strict durability outcomes
* refactor(tls): flatten preserved-output failures
* fix(reef): require durable journal commits
* fix(fs): route durability through policy boundaries
* fix(reef): preserve Windows journal compatibility
* fix(fs): bind publication to canonical directories
* fix(ci): align durability boundary fixtures
2026-07-24 20:58:17 -07:00
Vincent Koc
78d8c1f934
fix(deps): pin brace-expansion 5.0.8 ( #113428 )
2026-07-24 22:57:28 +00:00
Peter Steinberger
3b7b2a2a1f
chore: update dependencies and migrate major contracts ( #112963 )
...
* build(deps): complete latest dependency migrations
* fix(deps): satisfy updated dependency types
* fix(deps): hold incompatible build tooling
* fix(deps): preserve portable tooling contracts
* build(deps): allow reviewed fresh transitive releases
* fix(deps): repair major upgrade validation
* build(deps): regenerate current dependency graph
* fix(logging): keep tslog adapter type private
* fix(agents): narrow grep subprocess handle
* fix(codex): prefer pinned managed binary
* fix(codex): fence managed native provenance
* build(deps): align codex ACP with managed harness
* fix(slack): use socket-mode Undici runtime
* fix(slack): detect cross-runtime responses
* fix(slack): bridge package-owned fetch types
* fix(deps): retain tslog v4 JSON contract
* build(plugin-sdk): refresh logging API manifest
2026-07-23 21:21:01 -07:00
Peter Steinberger
acd92f6a3d
chore(deps): refresh repository dependencies ( #112453 )
...
* build(deps): update QA broker dependency
* build(deps): refresh repository dependencies
* build(deps): reconcile rebased shrinkwraps
* test(plugins): remove stale loader test state
* test(deps): stabilize updated dependency coverage
* fix(swift): use caller-isolated TaskLocal overload
* build(deps): regenerate rebased shrinkwraps
* test(msteams): preserve DNS validation in fetch helper
* fix(deps): avoid vulnerable optional image stack
* test(deps): validate generated LRU override
* refactor(ui): extract chat resizable divider
* test(ui): update divider ownership path
* fix(matrix): retain restart-compatible SDK
* style(cron): format update test
2026-07-23 16:17:13 +00:00
Vincent Koc
2396bd189b
fix(deps): patch fast-uri host confusion
2026-07-22 07:43:55 +08:00
Peter Steinberger
c84921634d
fix(macos): require explicit consent for privacy-sensitive access ( #112321 )
...
* fix(macos): avoid passive Automation prompts
* fix(macos): keep Voice Wake recognition on device
* fix(macos): require consent for activity presence
* chore(apps): refresh native i18n inventory
* fix(macos): preserve presence clears across gateway versions
* fix(macos): prioritize activity privacy opt-out
* chore(apps): refresh native i18n inventory
* fix(macos): scrub legacy presence activity
* fix(macos): migrate permission status caller
* fix(macos): preserve unknown permission state
* fix(macos): refresh privacy change artifacts
* refactor(macos): remove stale presence helper
* fix(deps): patch URI and Jaeger advisories
* test(gateway): adopt pairing-bound node sessions
2026-07-21 15:28:13 -07:00
Vincent Koc
1be9db038f
fix(deps): update fast-uri past advisory
2026-07-22 05:11:45 +08:00
Vincent Koc
b7e17855b9
fix(diagnostics-otel): update OpenTelemetry runtime
2026-07-22 05:11:45 +08:00
xingzhou
186c25f7f7
fix(gateway): avoid stale wake delays after node re-pairing ( #109647 )
...
* fix(gateway): clear wake state on node removal
* fix(gateway): invalidate wake flows on node removal
* fix(gateway): preserve active wakes on disconnect
* fix(gateway): share node removal runtime cleanup
* fix(gateway): clean up pending node work reliably
* fix(gateway): bind node work to pairing generations
* fix(gateway): fence stale node pairing sessions
* fix(gateway): tighten node pairing ownership
* fix(gateway): close node pairing mutation races
* fix(gateway): bind node sessions to pairing generation
* fix(gateway): harden node pairing generation guards
* fix(gateway): close node pairing generation races
* fix(gateway): guard APNs transport ownership
* fix(gateway): revoke reapproved node transports
* fix(gateway): guard retired node lifecycles
* fix(gateway): preserve pending work across reconnects
* fix(gateway): bind node subscriptions to pairing generations
* fix(gateway): settle subscription fanout failures
* fix(gateway): fence pairing generation ownership
* fix(gateway): fence asynchronous node events
* fix(gateway): fence watch results and voice wake fanout
* fix(gateway): guard voice wake generation fanout
* fix(gateway): carry authenticated snapshot generation
* fix(gateway): bind node state to pairing generation
* fix(gateway): align generation guards with current base
* fix(gateway): enforce pairing-owned node lifecycle
* fix(gateway): fence detached voice session writes
* chore(deps): bump proxyline to 0.3.4
* fix(gateway): close pairing lifecycle races
Co-authored-by: zhang-guiping <zhang.guiping@xydigit.com >
* fix(gateway): distinguish pending action mutation
Co-authored-by: zhang-guiping <zhang.guiping@xydigit.com >
* test(gateway): align lifecycle coverage
Co-authored-by: zhang-guiping <zhang.guiping@xydigit.com >
* test(skills): split remote reconciliation coverage
Co-authored-by: zhang-guiping <zhang.guiping@xydigit.com >
* style: format pairing lifecycle changes
Co-authored-by: zhang-guiping <zhang.guiping@xydigit.com >
---------
Co-authored-by: Peter Steinberger <steipete@gmail.com >
2026-07-21 05:10:08 -07:00
Peter Steinberger
a230f742f2
fix(deps): bump protobufjs to 7.6.5 to resolve GHSA-j3f2-48v5-ccww ( #112184 )
2026-07-21 02:04:10 -07:00
Dallin Romney
cde2e71d43
fix(deps): update axios past proxy advisory ( #111984 )
2026-07-21 09:21:14 +09:00
Peter Steinberger
f07a1fb502
refactor: centralize bounded file reads in fs-safe ( #111104 )
...
* refactor: use fs-safe bounded descriptor reads
* build: update fs-safe to 0.4.2
* build: refresh root npm shrinkwrap
* fix: satisfy bounded read return paths
* fix: update fs-safe integration for latest main
* fix: adopt fs-safe overflow compatibility release
* build: complete fs-safe lockfile update
* build: update fs-safe to 0.4.4
* build: refresh plugin SDK API baseline
* test: follow fs-safe bounded read seam
2026-07-19 01:29:23 -07:00
Peter Steinberger
b4d82f4729
refactor(ui): use libterminal color query responder ( #108234 )
2026-07-15 03:17:31 -07:00
Paul Campbell
008f04a656
feat(mxc): add Windows MXC sandbox backend ( #97086 )
...
* feat(mxc): add Windows MXC sandbox backend
Add the official MXC sandbox plugin package with Windows ProcessContainer execution, plugin-owned MXC SDK dependency packaging, host-backed filesystem bridge support, and configured MXC policy file loading via mxcPolicyPaths.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com >
* fix(mxc): preserve Windows binary override paths
* fix: remove stray sandbox barrel export
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com >
Copilot-Session: 9ea19539-b8ca-44fb-93bd-b8496e3deb2c
* fix(mxc): address sandbox review feedback
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com >
* fix(mxc): satisfy test type checks
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com >
* fix(mxc): clarify protected skill enforcement
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com >
* test(mxc): align fail-closed expectations
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com >
* fix(mxc): satisfy extension lint
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com >
* fix(plugin-sdk): narrow fs-safe remove surface
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com >
* fix(mxc): repair rebased CI failures
* fix(scripts): declare shrinkwrap override normalizer
---------
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com >
Co-authored-by: Gio Della-Libera <235387111+giodl73-repo@users.noreply.github.com >
Co-authored-by: Dallin Romney <dallinromney@gmail.com >
2026-07-12 23:07:25 -07:00
Peter Steinberger
d9623bd46f
fix(qa-lab): consume Crabline 0.1.11 artifacts ( #105983 )
...
* fix(qa-lab): consume Crabline 0.1.11 artifacts
* style(qa-lab): keep Crabline path note compact
* test(qa-lab): align Telegram scenario with group transport
2026-07-12 21:29:31 -07:00
Peter Steinberger
0d90ca6b5d
refactor(config): retire flat and scalar streaming keys from matrix, feishu, and qqbot ( #105808 )
...
* feat(doctor): migrate legacy matrix/feishu/qqbot streaming spellings to nested config
* test(matrix): shorten setup fixture tokens below the review secret-scanner threshold
* refactor(config): retire flat/scalar streaming keys from matrix, feishu, and qqbot
* docs: describe nested-only streaming config for matrix, feishu, and qqbot
* fix(qa-matrix): compose nested streaming config for the matrix QA harness
* test(feishu): compose negative webhook fixtures outside the GHSA opengrep pattern
* docs: refresh generated docs map
* test(feishu): compose negative webhook fixtures from lint-clean bases outside the GHSA opengrep pattern
* fix(qa-lab): rewrite crabline flat streaming config into the nested channel shape
* chore(config): regenerate channel config metadata and plugin-sdk API baseline for nested-only streaming
* chore(plugin-sdk): absorb main-side deprecated pairing/conversation pin drift
* fix(qa-lab): consume Crabline nested streaming config
2026-07-12 20:33:14 -07:00
Peter Steinberger
062f88e3e3
refactor: extract reusable AI runtime package ( #99059 )
...
* refactor: extract reusable AI runtime package
* refactor: complete AI provider relocation
* refactor: keep llm core internal
* refactor(ai): make @openclaw/ai self-contained with host policy ports
Move pure transport helpers (tool projections, strict-schema normalization,
prompt-cache boundary, stream guards, anthropic/openai compat, request
activity) from src into packages/ai; move utf16-slice into
normalization-core. Inject host policy (guarded fetch, redaction,
strict-tool defaults, diagnostics logging) through AiTransportHost with
inert library defaults installed by src/llm/stream.ts. Narrow the public
barrel to instance-scoped createApiRegistry/createLlmRuntime; the
process-default runtime moves behind internal/ and
registerBuiltInApiProviders takes an explicit registry. Delete the
src/llm/api-registry re-export facade.
* fix(ai): teach node, jiti, and vite resolvers the @openclaw/ai and utf16-slice subpaths
The workspace alias tables in root-alias.cjs, plugin-sdk-native-resolver,
sdk-alias, the shared vitest config, and the Control UI vite config only
knew @openclaw/llm-core; Node-side plugin loading resolved @openclaw/ai
through the pnpm symlink to the unbuilt dist (checks-node-compact CI
failures), and the Control UI build broke on the new
normalization-core/utf16-slice subpath.
* chore(ui): drop leftover service-worker debug logging
* build(release): ship @openclaw/ai with its own shrinkwrap and honest dependency set
packages/ai declares only its six real runtime deps (kysely, chalk, json5,
tslog, zod, fs-safe, and proxyline were never imported); orphaned root deps
removed. generate-npm-shrinkwrap now treats publishable packages/* like
publishable plugins so the AI tarball pins its transitive tree even though
workspace deps are omitted from the root shrinkwrap. knip learns the
package entry points; the tsdown dts neverBundle option moves to its
documented deps.dts home; the README documents the no-semver internal/*
contract and host ports.
* docs(ai): add minimal external-consumer example app
examples/ai-chat consumes only the public @openclaw/ai surface (built dist
via the workspace link): isolated runtime, built-in provider registration,
one streamed completion. Supports Anthropic/OpenAI via env keys and a
keyless local Ollama target; live-verified against Ollama.
* docs(ai): document the @openclaw/ai package and workspace shrinkwrap boundary
* chore(check): include examples/ in duplicate-scan targets
* fix: emit normalization package subpaths
* fix: complete AI package boundary artifacts
* fix: align AI package boundary contracts
* fix(ci): stabilize package release contracts
* test: align documentation contract checks
* test: keep cron docs guard aligned
* test: align restored docs contract guards
* test: follow upstream docs contracts
* docs: drop superseded talk wording
2026-07-05 01:56:40 -04:00
Shakker
65e12328aa
feat: refactor the Control UI architecture
...
Refactor the Control UI around route-owned page lifecycle and state while preserving existing behavior and design.
Prepared head SHA: bd51b6fa76
Co-authored-by: Shakker <165377636+shakkernerd@users.noreply.github.com >
Reviewed-by: @shakkernerd
2026-07-04 23:19:38 +01:00
Peter Steinberger
614e87cce1
chore: update dependencies ( #100027 )
2026-07-04 14:56:50 -04:00
Dallin Romney
1ab021fba9
fix(qa): consume Crabline events without recorder polling ( #99679 )
...
* fix(qa): consume Crabline events in process
* chore(qa): use Crabline 0.1.9
2026-07-03 16:15:03 -07:00
Dallin Romney
8d535fb039
test(qa): cover Crabline Zalo transport ( #99303 )
2026-07-02 19:09:22 -07:00
Dallin Romney
e701dc76b0
test(qa): prove native command targeting across QA transports ( #98751 )
...
* QA: prove native command session targeting
* QA: remove superseded native stop e2e
* test(qa): run native commands through Crabline Telegram
* chore(deps): scope Crabline release exception
* test(qa): retain native stop queue cleanup regression
2026-07-02 16:51:30 -07:00
Vincent Koc
51e0997c2b
test(qa): accept async image fixture coverage
...
(cherry picked from commit 9b703d0cd6 )
2026-06-30 15:54:11 -07:00
Dallin Romney
5dae3d49e6
Update QA Lab Crabline integration ( #97941 )
...
* Update QA Lab Crabline integration
* Refresh docs map
2026-06-29 16:07:38 -07:00
Dallin Romney
5816e0194e
feat(qa): wire crabline whatsapp transport ( #95920 )
2026-06-29 11:13:17 -07:00
Dallin Romney
2cc43aec2d
feat(qa): wire crabline slack transport ( #97891 )
2026-06-29 10:57:17 -07:00
Vincent Koc
c313642ae2
fix(qa-lab): use scoped crabline package
2026-06-23 17:47:07 +08:00
Vincent Koc
cc1b3a8550
fix(install): skip llama cpp native build by default
2026-06-23 12:58:41 +08:00
Dallin Romney
63b13ea837
feat(qa): crabline channel driver ( #91502 )
...
* feat(qa): add crabline channel driver seam
* feat: run crabline channel driver smoke
* chore: keep crabline qa dependency dev-only
* refactor(qa): keep crabline driver details opaque
* chore(qa): pin crabline to merged driver API
* feat(qa): drive channel driver from profiles
* fix(qa): declare crabline runtime peer
* feat(qa): resolve crabline channel from scenarios
* feat(qa): treat unsupported profile channels as coverage gaps
* Revert "feat(qa): treat unsupported profile channels as coverage gaps"
This reverts commit 65a97016558705514a1c1ec74870de9b0a6e7886.
* fix(qa): adapt crabline driver to chat sdk cli
* refactor(qa): pass channel driver metadata directly
* chore(qa): update crabline provider pin
* chore(qa): default channel scenarios to driver
* chore: repair qa dependency lockfile
* chore: allow native qa dependency builds
* fix(qa): satisfy crabline driver lint
* fix(qa): satisfy crabline ci gates
* Use crabline transport for smoke QA profile
* fix(qa): keep crabline driver opt-in
* fix(qa): reuse crabline telegram driver token
* fix(qa): route smoke profile through crabline
* fix(qa): run full smoke profile lane
* fix(qa): remove smoke scenario workflow filter
* fix: stabilize crabline smoke qa profile
* fix: pin crabline qa dependency
* test: keep crabline smoke credential-free
* fix: skip visible reasoning lane for crabline smoke
* fix: unblock crabline qa ci
* Update crabline dependency
* Pin crabline to merged main
* Use Crabline fake provider servers
2026-06-22 15:24:59 -07:00
Vincent Koc
d79d5487aa
fix(deps): remediate Dependabot alerts ( #93857 )
...
Merged via squash.
Prepared head SHA: 51ece24eef
Co-authored-by: vincentkoc <25068+vincentkoc@users.noreply.github.com >
Co-authored-by: vincentkoc <25068+vincentkoc@users.noreply.github.com >
Reviewed-by: @vincentkoc
2026-06-17 11:15:31 +08:00
Vincent Koc
05584427a8
fix(deps): update Hono security pin
...
Update the global Hono override and published shrinkwraps to 4.12.25 so release packages avoid the current high-severity CORS advisory.
2026-06-16 23:12:39 +08:00
Shakker
dc573a38dc
fix: update dependency pins
2026-06-15 19:48:43 +01:00
Dallin Romney
777edadb36
fix: update esbuild audit pin ( #92540 )
2026-06-12 15:36:49 -07:00