From 78e5ff3b9b252d9cc1178aa4836ab9d62d43c98c Mon Sep 17 00:00:00 2001 From: Parafee41 Date: Thu, 18 Jun 2026 04:52:31 +0800 Subject: [PATCH 1/7] fix(wiki): keep graph DB pinned during generation (#2232) --- gitnexus/src/core/wiki/generator.ts | 3 + gitnexus/src/core/wiki/graph-queries.ts | 11 +- gitnexus/test/unit/lbug-pool-pinning.test.ts | 18 +++ gitnexus/test/unit/wiki-db-pin.test.ts | 104 ++++++++++++++++++ gitnexus/test/unit/wiki-flags.test.ts | 2 + .../test/unit/wiki-grouping-batch.test.ts | 3 + 6 files changed, 140 insertions(+), 1 deletion(-) create mode 100644 gitnexus/test/unit/wiki-db-pin.test.ts diff --git a/gitnexus/src/core/wiki/generator.ts b/gitnexus/src/core/wiki/generator.ts index 11df0b6c2..2e6180731 100644 --- a/gitnexus/src/core/wiki/generator.ts +++ b/gitnexus/src/core/wiki/generator.ts @@ -18,6 +18,7 @@ import { initWikiDb, closeWikiDb, touchWikiDb, + pinWikiDb, getFilesWithExports, getAllFiles, getIntraModuleCallEdges, @@ -291,6 +292,7 @@ export class WikiGenerator { // Init graph this.onProgress('init', 2, 'Connecting to knowledge graph...'); + const releaseWikiDbPin = pinWikiDb(); await initWikiDb(this.lbugPath); let result: WikiRunResult; @@ -310,6 +312,7 @@ export class WikiGenerator { result = await this.fullGeneration(currentCommit); } } finally { + releaseWikiDbPin(); await closeWikiDb(); } diff --git a/gitnexus/src/core/wiki/graph-queries.ts b/gitnexus/src/core/wiki/graph-queries.ts index 26d9f1a54..43b7a1e23 100644 --- a/gitnexus/src/core/wiki/graph-queries.ts +++ b/gitnexus/src/core/wiki/graph-queries.ts @@ -5,7 +5,7 @@ * Uses the MCP-style pooled lbug-adapter for connection management. */ -import { initLbug, executeQuery, closeLbug, touchRepo } from '../lbug/pool-adapter.js'; +import { initLbug, executeQuery, closeLbug, touchRepo, pinRepo } from '../lbug/pool-adapter.js'; const REPO_ID = '__wiki__'; @@ -16,6 +16,15 @@ export function touchWikiDb(): void { touchRepo(REPO_ID); } +/** + * Keep the wiki DB resident for a full generation run. Wiki generation can spend + * minutes inside LLM calls, and the pooled DB must survive both idle cleanup and + * unrelated LRU pressure until the run reaches its final graph queries. + */ +export function pinWikiDb(): () => void { + return pinRepo(REPO_ID); +} + export interface FileWithExports { filePath: string; symbols: Array<{ name: string; type: string }>; diff --git a/gitnexus/test/unit/lbug-pool-pinning.test.ts b/gitnexus/test/unit/lbug-pool-pinning.test.ts index 914647b09..602239525 100644 --- a/gitnexus/test/unit/lbug-pool-pinning.test.ts +++ b/gitnexus/test/unit/lbug-pool-pinning.test.ts @@ -62,6 +62,7 @@ vi.mock('../../src/core/lbug/sidecar-recovery.js', () => ({ const { initLbug, closeLbug, isLbugReady, pinRepo, unpinRepo } = await import('../../src/core/lbug/pool-adapter.js'); +const { initWikiDb, closeWikiDb, pinWikiDb } = await import('../../src/core/wiki/graph-queries.js'); describe('pool-adapter repo pinning (issue #2189)', () => { let tmpDir: string; @@ -151,6 +152,23 @@ describe('pool-adapter repo pinning (issue #2189)', () => { expect(isLbugReady('unpinned-idle')).toBe(false); }); + it('wiki DB pin wrapper keeps __wiki__ resident past idle cleanup', async () => { + vi.useFakeTimers(); + + const releaseWikiPin = pinWikiDb(); + await initWikiDb(dbPathFor('wiki-wrapper')); + expect(isLbugReady('__wiki__')).toBe(true); + + await vi.advanceTimersByTimeAsync(5 * 60 * 1000 + 60 * 1000); + expect(isLbugReady('__wiki__')).toBe(true); + + releaseWikiPin(); + await vi.advanceTimersByTimeAsync(5 * 60 * 1000 + 60 * 1000); + expect(isLbugReady('__wiki__')).toBe(false); + + await closeWikiDb(); + }); + it('unpinRepo re-enables eviction for that repo', async () => { // Pin five repos and fill the pool; a sixth init evicts nothing (all pinned). for (let i = 1; i <= 5; i++) { diff --git a/gitnexus/test/unit/wiki-db-pin.test.ts b/gitnexus/test/unit/wiki-db-pin.test.ts new file mode 100644 index 000000000..8af799710 --- /dev/null +++ b/gitnexus/test/unit/wiki-db-pin.test.ts @@ -0,0 +1,104 @@ +import { afterEach, beforeEach, describe, expect, it, vi } from 'vitest'; +import fs from 'node:fs/promises'; +import os from 'node:os'; +import path from 'node:path'; + +const { + closeWikiDbMock, + getAllFilesMock, + getFilesWithExportsMock, + initWikiDbMock, + pinWikiDbMock, + releaseWikiDbPinMock, +} = vi.hoisted(() => ({ + closeWikiDbMock: vi.fn(), + getAllFilesMock: vi.fn(), + getFilesWithExportsMock: vi.fn(), + initWikiDbMock: vi.fn(), + pinWikiDbMock: vi.fn(), + releaseWikiDbPinMock: vi.fn(), +})); + +vi.mock('../../src/core/wiki/graph-queries.js', () => ({ + initWikiDb: initWikiDbMock, + closeWikiDb: closeWikiDbMock, + touchWikiDb: vi.fn(), + pinWikiDb: pinWikiDbMock, + getFilesWithExports: getFilesWithExportsMock, + getAllFiles: getAllFilesMock, + getIntraModuleCallEdges: vi.fn(), + getInterModuleCallEdges: vi.fn(), + getProcessesForFiles: vi.fn(), + getAllProcesses: vi.fn(), + getInterModuleEdgesForOverview: vi.fn(), +})); + +vi.mock('../../src/core/wiki/html-viewer.js', () => ({ + generateHTMLViewer: vi.fn().mockResolvedValue(''), +})); + +describe('WikiGenerator DB pinning', () => { + let tmpDir: string; + let repoPath: string; + let storagePath: string; + let lbugPath: string; + + beforeEach(async () => { + tmpDir = await fs.mkdtemp(path.join(os.tmpdir(), 'gitnexus-wiki-pin-')); + repoPath = path.join(tmpDir, 'repo'); + storagePath = path.join(repoPath, '.gitnexus'); + lbugPath = path.join(storagePath, 'lbug'); + + await fs.mkdir(path.join(repoPath, 'src'), { recursive: true }); + await fs.mkdir(path.join(storagePath, 'wiki'), { recursive: true }); + await fs.writeFile(path.join(repoPath, 'src', 'index.ts'), 'export const value = 1;\n'); + await fs.writeFile(lbugPath, ''); + await fs.writeFile( + path.join(storagePath, 'wiki', 'module_tree.json'), + JSON.stringify([{ name: 'Core', slug: 'core', files: ['src/index.ts'] }]), + ); + + initWikiDbMock.mockResolvedValue(undefined); + closeWikiDbMock.mockResolvedValue(undefined); + releaseWikiDbPinMock.mockReset(); + pinWikiDbMock.mockReturnValue(releaseWikiDbPinMock); + getFilesWithExportsMock.mockResolvedValue([ + { filePath: 'src/index.ts', symbols: [{ name: 'value', type: 'Variable' }] }, + ]); + getAllFilesMock.mockResolvedValue(['src/index.ts']); + }); + + afterEach(async () => { + vi.restoreAllMocks(); + await fs.rm(tmpDir, { recursive: true, force: true }); + }); + + it('pins the wiki DB for the run and releases the lease before closing', async () => { + const { WikiGenerator } = await import('../../src/core/wiki/generator.js'); + const generator = new WikiGenerator( + repoPath, + storagePath, + lbugPath, + { + provider: 'openai', + model: 'test-model', + baseUrl: 'http://127.0.0.1:1/v1', + apiKey: 'test', + }, + { force: true, reviewOnly: true }, + ); + + await expect(generator.run()).resolves.toMatchObject({ + mode: 'full', + pagesGenerated: 0, + }); + + expect(initWikiDbMock).toHaveBeenCalledWith(lbugPath); + expect(pinWikiDbMock).toHaveBeenCalledTimes(1); + expect(releaseWikiDbPinMock).toHaveBeenCalledTimes(1); + expect(closeWikiDbMock).toHaveBeenCalledTimes(1); + expect(releaseWikiDbPinMock.mock.invocationCallOrder[0]).toBeLessThan( + closeWikiDbMock.mock.invocationCallOrder[0], + ); + }); +}); diff --git a/gitnexus/test/unit/wiki-flags.test.ts b/gitnexus/test/unit/wiki-flags.test.ts index 0d6c71413..165ca2e87 100644 --- a/gitnexus/test/unit/wiki-flags.test.ts +++ b/gitnexus/test/unit/wiki-flags.test.ts @@ -323,6 +323,7 @@ describe('WikiGenerator --review mode', () => { initWikiDb: vi.fn().mockResolvedValue(undefined), closeWikiDb: vi.fn().mockResolvedValue(undefined), touchWikiDb: vi.fn(), + pinWikiDb: vi.fn(() => vi.fn()), getFilesWithExports: vi .fn() .mockResolvedValue(fakeFiles.map((f) => ({ filePath: f, symbols: [] }))), @@ -1762,6 +1763,7 @@ describe('WikiGenerator grouping prompt isolation', () => { initWikiDb: vi.fn().mockResolvedValue(undefined), closeWikiDb: vi.fn().mockResolvedValue(undefined), touchWikiDb: vi.fn(), + pinWikiDb: vi.fn(() => vi.fn()), getFilesWithExports: vi.fn().mockResolvedValue([{ filePath: 'src/auth.ts', symbols: [] }]), getAllFiles: vi.fn().mockResolvedValue(['src/auth.ts']), getIntraModuleCallEdges: vi.fn().mockResolvedValue([]), diff --git a/gitnexus/test/unit/wiki-grouping-batch.test.ts b/gitnexus/test/unit/wiki-grouping-batch.test.ts index 9acc80a8f..e7ec658ee 100644 --- a/gitnexus/test/unit/wiki-grouping-batch.test.ts +++ b/gitnexus/test/unit/wiki-grouping-batch.test.ts @@ -351,6 +351,7 @@ describe('buildModuleTree batched grouping', () => { initWikiDb: vi.fn().mockResolvedValue(undefined), closeWikiDb: vi.fn().mockResolvedValue(undefined), touchWikiDb: vi.fn(), + pinWikiDb: vi.fn(() => vi.fn()), getFilesWithExports: vi.fn().mockResolvedValue(fakeFiles), getAllFiles: vi.fn().mockResolvedValue(fakeFiles.map((f) => f.filePath)), getIntraModuleCallEdges: vi.fn().mockResolvedValue([]), @@ -426,6 +427,7 @@ describe('buildModuleTree batched grouping', () => { initWikiDb: vi.fn().mockResolvedValue(undefined), closeWikiDb: vi.fn().mockResolvedValue(undefined), touchWikiDb: vi.fn(), + pinWikiDb: vi.fn(() => vi.fn()), getFilesWithExports: vi.fn().mockResolvedValue(fakeFiles), getAllFiles: vi.fn().mockResolvedValue(fakeFiles.map((f) => f.filePath)), getIntraModuleCallEdges: vi.fn().mockResolvedValue([]), @@ -513,6 +515,7 @@ describe('buildModuleTree batched grouping', () => { initWikiDb: vi.fn().mockResolvedValue(undefined), closeWikiDb: vi.fn().mockResolvedValue(undefined), touchWikiDb: vi.fn(), + pinWikiDb: vi.fn(() => vi.fn()), getFilesWithExports: vi.fn().mockResolvedValue(fakeFiles), getAllFiles: vi.fn().mockResolvedValue(fakeFiles.map((f) => f.filePath)), getIntraModuleCallEdges: vi.fn().mockResolvedValue([]), From e33f9087759f3d0aba138c2998efab87758fcbdb Mon Sep 17 00:00:00 2001 From: Parafee41 Date: Thu, 18 Jun 2026 12:14:44 +0800 Subject: [PATCH 2/7] ci: keep tree-sitter readiness summary counts current (#2196) --- .../test_check_tree_sitter_upgrade_readiness.py | 15 +++++++++++++++ .../workflows/tree-sitter-upgrade-readiness.yml | 6 +++--- 2 files changed, 18 insertions(+), 3 deletions(-) diff --git a/.github/scripts/test_check_tree_sitter_upgrade_readiness.py b/.github/scripts/test_check_tree_sitter_upgrade_readiness.py index c36e68d07..b3526fd9f 100644 --- a/.github/scripts/test_check_tree_sitter_upgrade_readiness.py +++ b/.github/scripts/test_check_tree_sitter_upgrade_readiness.py @@ -39,6 +39,13 @@ _spec.loader.exec_module(readiness) # type: ignore[union-attr] # format change that would silently break change-detection fails here. Group 2 is # ONLY the Status cell ([^|]+? before the final `|$`). _ROW_DIFF_RE = re.compile(r"\| `(tree-sitter-[^`]+)` \|.*\| ([^|]+?) \|$", re.M) +# Mirrors the scheduled issue-update summary extraction in +# tree-sitter-upgrade-readiness.yml. If the report prose changes again, the issue +# comment should not silently degrade to "?/? ready. ? blocker(s)". +_ISSUE_READY_RE = re.compile( + r"- (\d+)/(\d+) npm-installed grammars already accept tree-sitter@" +) +_ISSUE_BLOCKER_RE = re.compile(r"\*\*Blocked\*\* — (\d+) grammars? ") def _physical_vendor_grammars() -> set[str]: @@ -291,6 +298,14 @@ class ReportRendering(TestCase): for status in self.rows.values(): self.assertNotIn("|", status) + def test_issue_update_summary_regex_matches_current_report(self): + ready = _ISSUE_READY_RE.search(self.report) + blockers = _ISSUE_BLOCKER_RE.search(self.report) + self.assertIsNotNone(ready) + self.assertIsNotNone(blockers) + self.assertEqual(ready.groups(), ("9", "10")) + self.assertEqual(blockers.group(1), "2") + def _matrix_row(self, name: str) -> str: for line in self.report.splitlines(): if line.startswith(f"| `{name}` |"): diff --git a/.github/workflows/tree-sitter-upgrade-readiness.yml b/.github/workflows/tree-sitter-upgrade-readiness.yml index bd887319f..72fa54b55 100644 --- a/.github/workflows/tree-sitter-upgrade-readiness.yml +++ b/.github/workflows/tree-sitter-upgrade-readiness.yml @@ -133,8 +133,8 @@ jobs: const existing = open.find(i => i.title === title); if (existing) { // Extract ready/total count for the changelog comment. - const readyMatch = report.match(/\*\*(\d+)\/(\d+)\*\* grammars ready/); - const blockerMatch = report.match(/\*\*(\d+) blocker/); + const readyMatch = report.match(/- (\d+)\/(\d+) npm-installed grammars already accept tree-sitter@/); + const blockerMatch = report.match(/\*\*Blocked\*\* — (\d+) grammars? /); const ready = readyMatch ? readyMatch[1] : '?'; const total = readyMatch ? readyMatch[2] : '?'; const blockers = blockerMatch ? blockerMatch[1] : '?'; @@ -165,7 +165,7 @@ jobs: } const today = new Date().toISOString().slice(0, 10); - let comment = `**${today}:** ${ready}/${total} ready. ${blockers} blocker(s) remaining.`; + let comment = `**${today}:** ${ready}/${total} npm-installed ready. ${blockers} blocker(s) remaining.`; if (changes.length > 0) { comment += '\n\nChanges:\n' + changes.map(c => `- ${c}`).join('\n'); } else { From 4d9318e2eef3cabff33526fb08ec9f641fbc8806 Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Thu, 18 Jun 2026 05:56:59 +0100 Subject: [PATCH 3/7] chore(deps)(deps): bump hono from 4.12.23 to 4.12.26 in /gitnexus (#2244) Bumps [hono](https://github.com/honojs/hono) from 4.12.23 to 4.12.26. - [Release notes](https://github.com/honojs/hono/releases) - [Commits](https://github.com/honojs/hono/compare/v4.12.23...v4.12.26) --- updated-dependencies: - dependency-name: hono dependency-version: 4.12.26 dependency-type: indirect ... Signed-off-by: dependabot[bot] Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> --- gitnexus/package-lock.json | 40 +++----------------------------------- 1 file changed, 3 insertions(+), 37 deletions(-) diff --git a/gitnexus/package-lock.json b/gitnexus/package-lock.json index 3a93b9339..cb0e2115d 100644 --- a/gitnexus/package-lock.json +++ b/gitnexus/package-lock.json @@ -3269,9 +3269,9 @@ "license": "MIT" }, "node_modules/hono": { - "version": "4.12.23", - "resolved": "https://registry.npmjs.org/hono/-/hono-4.12.23.tgz", - "integrity": "sha512-eIaZ9qDgu7XV0pxOCrg7/WhnQ6Ivm22UcxhXx/A3dcbqbbYgBEkc6e/J/s7j2tS96zoB0S9VBdLwQNCWwUo4LA==", + "version": "4.12.26", + "resolved": "https://registry.npmjs.org/hono/-/hono-4.12.26.tgz", + "integrity": "sha512-uyZtpnYxM9CmQ7QsQknM4zN8EftNqhON1qYeIKM0Se67CCEe2c44xyGURwB0axX2fBDu1dqHrHAc1hmNT8ITkw==", "license": "MIT", "engines": { "node": ">=16.9.0" @@ -5628,40 +5628,6 @@ "peerDependencies": { "zod": "^3.25.28 || ^4" } - }, - "vendor/tree-sitter-dart": { - "version": "1.0.0", - "extraneous": true, - "license": "ISC", - "peerDependencies": { - "tree-sitter": "^0.21.0" - }, - "peerDependenciesMeta": { - "tree_sitter": { - "optional": true - } - } - }, - "vendor/tree-sitter-proto": { - "version": "0.4.1", - "extraneous": true, - "license": "MIT", - "peerDependencies": { - "tree-sitter": ">=0.21.0" - } - }, - "vendor/tree-sitter-swift": { - "version": "0.7.1", - "extraneous": true, - "license": "MIT", - "peerDependencies": { - "tree-sitter": "^0.21.1 || ^0.22.1" - }, - "peerDependenciesMeta": { - "tree-sitter": { - "optional": true - } - } } } } From 21315f02c941325a5e3b362073208af0b6285406 Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Thu, 18 Jun 2026 05:57:15 +0100 Subject: [PATCH 4/7] chore(deps): bump github/codeql-action from 4.36.0 to 4.36.2 (#2242) Bumps [github/codeql-action](https://github.com/github/codeql-action) from 4.36.0 to 4.36.2. - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](https://github.com/github/codeql-action/compare/7211b7c8077ea37d8641b6271f6a365a22a5fbfa...8aad20d150bbac5944a9f9d289da16a4b0d87c1e) --- updated-dependencies: - dependency-name: github/codeql-action dependency-version: 4.36.2 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> --- .github/workflows/codeql.yml | 4 ++-- .github/workflows/scorecard.yml | 2 +- .github/workflows/trivy.yml | 2 +- .github/workflows/workflow-lint.yml | 2 +- 4 files changed, 5 insertions(+), 5 deletions(-) diff --git a/.github/workflows/codeql.yml b/.github/workflows/codeql.yml index 95598e9ef..2c57ce0f8 100644 --- a/.github/workflows/codeql.yml +++ b/.github/workflows/codeql.yml @@ -48,7 +48,7 @@ jobs: persist-credentials: false - name: Initialize CodeQL - uses: github/codeql-action/init@7211b7c8077ea37d8641b6271f6a365a22a5fbfa # v4.36.0 + uses: github/codeql-action/init@8aad20d150bbac5944a9f9d289da16a4b0d87c1e # v4.36.2 with: languages: ${{ matrix.language }} queries: security-and-quality @@ -73,6 +73,6 @@ jobs: - '**/test/**/fixtures/**' - name: Perform CodeQL Analysis - uses: github/codeql-action/analyze@7211b7c8077ea37d8641b6271f6a365a22a5fbfa # v4.36.0 + uses: github/codeql-action/analyze@8aad20d150bbac5944a9f9d289da16a4b0d87c1e # v4.36.2 with: category: '/language:${{ matrix.language }}' diff --git a/.github/workflows/scorecard.yml b/.github/workflows/scorecard.yml index 229286daf..7031653e8 100644 --- a/.github/workflows/scorecard.yml +++ b/.github/workflows/scorecard.yml @@ -53,6 +53,6 @@ jobs: retention-days: 5 - name: Upload to Security tab - uses: github/codeql-action/upload-sarif@7211b7c8077ea37d8641b6271f6a365a22a5fbfa # v4.36.0 + uses: github/codeql-action/upload-sarif@8aad20d150bbac5944a9f9d289da16a4b0d87c1e # v4.36.2 with: sarif_file: results.sarif diff --git a/.github/workflows/trivy.yml b/.github/workflows/trivy.yml index fd7ade8b5..4446c884a 100644 --- a/.github/workflows/trivy.yml +++ b/.github/workflows/trivy.yml @@ -76,7 +76,7 @@ jobs: exit-code: '0' - name: Upload to Security tab - uses: github/codeql-action/upload-sarif@7211b7c8077ea37d8641b6271f6a365a22a5fbfa # v4.36.0 + uses: github/codeql-action/upload-sarif@8aad20d150bbac5944a9f9d289da16a4b0d87c1e # v4.36.2 with: sarif_file: trivy-${{ matrix.image.name }}.sarif category: trivy-${{ matrix.image.name }} diff --git a/.github/workflows/workflow-lint.yml b/.github/workflows/workflow-lint.yml index 678ed1a4a..ea400ce45 100644 --- a/.github/workflows/workflow-lint.yml +++ b/.github/workflows/workflow-lint.yml @@ -76,7 +76,7 @@ jobs: continue-on-error: true - name: Upload SARIF - uses: github/codeql-action/upload-sarif@7211b7c8077ea37d8641b6271f6a365a22a5fbfa # v4.36.0 + uses: github/codeql-action/upload-sarif@8aad20d150bbac5944a9f9d289da16a4b0d87c1e # v4.36.2 with: sarif_file: zizmor.sarif category: zizmor From 542f54f6161b6b509b7ab441778fd1bd4b5fe7af Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Thu, 18 Jun 2026 05:57:39 +0100 Subject: [PATCH 5/7] chore(deps): bump gitleaks/gitleaks-action from 2.3.9 to 3.0.0 (#2241) Bumps [gitleaks/gitleaks-action](https://github.com/gitleaks/gitleaks-action) from 2.3.9 to 3.0.0. - [Release notes](https://github.com/gitleaks/gitleaks-action/releases) - [Commits](https://github.com/gitleaks/gitleaks-action/compare/ff98106e4c7b2bc287b24eaf42907196329070c7...e0c47f4f8be36e29cdc102c57e68cb5cbf0e8d1e) --- updated-dependencies: - dependency-name: gitleaks/gitleaks-action dependency-version: 3.0.0 dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> --- .github/workflows/gitleaks.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.github/workflows/gitleaks.yml b/.github/workflows/gitleaks.yml index ee5ba8ecc..c34505692 100644 --- a/.github/workflows/gitleaks.yml +++ b/.github/workflows/gitleaks.yml @@ -53,7 +53,7 @@ jobs: # No GITLEAKS_LICENSE secret is required for OSS / public-repo usage. # If this repo becomes private, the action will require a license key. - name: Gitleaks - uses: gitleaks/gitleaks-action@ff98106e4c7b2bc287b24eaf42907196329070c7 # v2.3.9 + uses: gitleaks/gitleaks-action@e0c47f4f8be36e29cdc102c57e68cb5cbf0e8d1e # v3.0.0 env: GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} GITLEAKS_ENABLE_UPLOAD_ARTIFACT: true From 9898acc5bae19a34fa99caee2a50fc76ee389e75 Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Thu, 18 Jun 2026 05:57:57 +0100 Subject: [PATCH 6/7] chore(deps)(deps): bump @langchain/ollama in /gitnexus-web (#2236) Bumps [@langchain/ollama](https://github.com/langchain-ai/langchainjs) from 1.2.6 to 1.2.7. - [Release notes](https://github.com/langchain-ai/langchainjs/releases) - [Commits](https://github.com/langchain-ai/langchainjs/compare/@langchain/ollama@1.2.6...langchain@1.2.7) --- updated-dependencies: - dependency-name: "@langchain/ollama" dependency-version: 1.2.7 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> --- gitnexus-web/package-lock.json | 24 +++++------------------- gitnexus-web/package.json | 2 +- 2 files changed, 6 insertions(+), 20 deletions(-) diff --git a/gitnexus-web/package-lock.json b/gitnexus-web/package-lock.json index 6647ee373..a0614a6d9 100644 --- a/gitnexus-web/package-lock.json +++ b/gitnexus-web/package-lock.json @@ -12,7 +12,7 @@ "@langchain/core": "^1.1.44", "@langchain/google-genai": "^2.1.30", "@langchain/langgraph": "^1.3.2", - "@langchain/ollama": "^1.2.6", + "@langchain/ollama": "^1.2.7", "@langchain/openai": "^1.4.5", "@sigma/edge-curve": "^3.1.0", "@tailwindcss/vite": "^4.3.0", @@ -1538,13 +1538,12 @@ } }, "node_modules/@langchain/ollama": { - "version": "1.2.6", - "resolved": "https://registry.npmjs.org/@langchain/ollama/-/ollama-1.2.6.tgz", - "integrity": "sha512-wEfjRjyB20SMduqjriIBEalXZf1twbfaNTxxLIjKCVrufHPtKJKGy1a0tQHqa+27HwektNNXlcMre7MTuaS5Rw==", + "version": "1.2.7", + "resolved": "https://registry.npmjs.org/@langchain/ollama/-/ollama-1.2.7.tgz", + "integrity": "sha512-7Gu17q1dn4nKGB3ZYJyaaL8H/2k7LHvcL6V25S8cVDniTTSvd0fWzI5MzPJvbf9WPxBhvmf+rDDLAhOWljHEtQ==", "license": "MIT", "dependencies": { - "ollama": "^0.6.3", - "uuid": "^10.0.0" + "ollama": "^0.6.3" }, "engines": { "node": ">=20" @@ -1553,19 +1552,6 @@ "@langchain/core": "^1.0.0" } }, - "node_modules/@langchain/ollama/node_modules/uuid": { - "version": "10.0.0", - "resolved": "https://registry.npmjs.org/uuid/-/uuid-10.0.0.tgz", - "integrity": "sha512-8XkAphELsDnEGrDxUOHB3RGvXz6TeuYSGEZBOjtTtPm2lwhGBjLgOzLHB63IUWfBpNucQjND6d3AOudO+H3RWQ==", - "funding": [ - "https://github.com/sponsors/broofa", - "https://github.com/sponsors/ctavan" - ], - "license": "MIT", - "bin": { - "uuid": "dist/bin/uuid" - } - }, "node_modules/@langchain/openai": { "version": "1.4.5", "resolved": "https://registry.npmjs.org/@langchain/openai/-/openai-1.4.5.tgz", diff --git a/gitnexus-web/package.json b/gitnexus-web/package.json index a8ce1dbe5..0fd5f3bd2 100644 --- a/gitnexus-web/package.json +++ b/gitnexus-web/package.json @@ -22,7 +22,7 @@ "@langchain/core": "^1.1.44", "@langchain/google-genai": "^2.1.30", "@langchain/langgraph": "^1.3.2", - "@langchain/ollama": "^1.2.6", + "@langchain/ollama": "^1.2.7", "@langchain/openai": "^1.4.5", "@sigma/edge-curve": "^3.1.0", "@tailwindcss/vite": "^4.3.0", From c899814393ff59a8b68712386cff2ea6eb7d962b Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Thu, 18 Jun 2026 05:59:01 +0100 Subject: [PATCH 7/7] chore(deps)(deps): bump react-dom from 19.2.6 to 19.2.7 in /gitnexus-web (#2240) Bumps [react-dom](https://github.com/facebook/react/tree/HEAD/packages/react-dom) from 19.2.6 to 19.2.7. - [Release notes](https://github.com/facebook/react/releases) - [Changelog](https://github.com/react/react/blob/main/CHANGELOG.md) - [Commits](https://github.com/facebook/react/commits/v19.2.7/packages/react-dom) --- updated-dependencies: - dependency-name: react-dom dependency-version: 19.2.7 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> --- gitnexus-web/package-lock.json | 16 ++++++++-------- gitnexus-web/package.json | 2 +- 2 files changed, 9 insertions(+), 9 deletions(-) diff --git a/gitnexus-web/package-lock.json b/gitnexus-web/package-lock.json index a0614a6d9..47b57b691 100644 --- a/gitnexus-web/package-lock.json +++ b/gitnexus-web/package-lock.json @@ -35,7 +35,7 @@ "mnemonist": "^0.39.0", "pandemonium": "^2.4.0", "react": "^19.2.5", - "react-dom": "^19.2.6", + "react-dom": "^19.2.7", "react-i18next": "^17.0.8", "react-markdown": "^10.1.0", "react-syntax-highlighter": "^16.1.1", @@ -7739,24 +7739,24 @@ "license": "MIT" }, "node_modules/react": { - "version": "19.2.6", - "resolved": "https://registry.npmjs.org/react/-/react-19.2.6.tgz", - "integrity": "sha512-sfWGGfavi0xr8Pg0sVsyHMAOziVYKgPLNrS7ig+ivMNb3wbCBw3KxtflsGBAwD3gYQlE/AEZsTLgToRrSCjb0Q==", + "version": "19.2.7", + "resolved": "https://registry.npmjs.org/react/-/react-19.2.7.tgz", + "integrity": "sha512-HNe9WslTbXmFK8o8cmwgAeJFSBvt1bPdHCVKtaaV+WlAN36mpT4hcRpwbf3fY56ar2oIXzsBpOAiIRHAdY0OlQ==", "license": "MIT", "engines": { "node": ">=0.10.0" } }, "node_modules/react-dom": { - "version": "19.2.6", - "resolved": "https://registry.npmjs.org/react-dom/-/react-dom-19.2.6.tgz", - "integrity": "sha512-0prMI+hvBbPjsWnxDLxlCGyM8PN6UuWjEUCYmZhO67xIV9Xasa/r/vDnq+Xyq4Lo27g8QSbO5YzARu0D1Sps3g==", + "version": "19.2.7", + "resolved": "https://registry.npmjs.org/react-dom/-/react-dom-19.2.7.tgz", + "integrity": "sha512-t0BRVXvbiE/o20Hfw669rLbMCDWtYZLvmJigy2f0MxsXF+71pxhR3xOkspmsO8h3ZlNzyibAmtCa3l4lYKk6gQ==", "license": "MIT", "dependencies": { "scheduler": "^0.27.0" }, "peerDependencies": { - "react": "^19.2.6" + "react": "^19.2.7" } }, "node_modules/react-i18next": { diff --git a/gitnexus-web/package.json b/gitnexus-web/package.json index 0fd5f3bd2..a9ff3073f 100644 --- a/gitnexus-web/package.json +++ b/gitnexus-web/package.json @@ -45,7 +45,7 @@ "mnemonist": "^0.39.0", "pandemonium": "^2.4.0", "react": "^19.2.5", - "react-dom": "^19.2.6", + "react-dom": "^19.2.7", "react-i18next": "^17.0.8", "react-markdown": "^10.1.0", "react-syntax-highlighter": "^16.1.1",