Commit graph

359 commits

Author SHA1 Message Date
Brad Groux
ddca1b6cb4 fix: isolate status history tests from real state 2026-03-22 14:24:15 -05:00
Brad Groux
7483cc67f3
fix(security): harden localhost bypass and broadcast frontmatter parsing (closes #236) (#242)
- auth: disable localhost bypass entirely in production mode instead of
  just logging a warning — prevents misconfigured deployments from
  allowing unauthenticated access
- broadcast-storage: wrap JSON.parse() calls for tags and readBy
  frontmatter fields in try-catch, defaulting to empty arrays on parse
  failure instead of crashing the route handler

Co-authored-by: Brad Groux <bradgroux@users.noreply.github.com>
Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-03-21 15:20:31 -05:00
Brad Groux
303b7935b6
fix(api): make startup init failures fatal and add shutdown timeouts (closes #235) (#241)
- Service initialization (telemetry, policy, config, migrations) now
  calls process.exit(1) on failure instead of silently continuing with
  a partially broken server
- WebSocket server close gets a 3s timeout so stuck clients don't block
  shutdown indefinitely
- Telemetry flush gets a 5s timeout so a stuck write queue doesn't
  prevent shutdown

Co-authored-by: Brad Groux <bradgroux@users.noreply.github.com>
Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-03-21 15:20:28 -05:00
Brad Groux
0fc2c834ae
fix(api): prevent config cache stampede and log corrupted activity files (closes #234) (#240)
- config-service: coalesce concurrent getConfig() calls into a single
  disk read via pendingRead promise, preventing cache stampede under load
- activity-service: log warning when corrupted activity file is reset
  instead of silently discarding data

Co-authored-by: Brad Groux <bradgroux@users.noreply.github.com>
Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-03-21 15:20:26 -05:00
Brad Groux
74dc3a9074
fix(api): WebSocket event listener leaks and add message rate limiting (closes #233) (#239)
- Replace per-subscribe ws.on('close') listeners with tracked emitter
  references, preventing listener accumulation when clients re-subscribe
- Add message rate limiting (30 msgs / 10s window) to prevent DoS via
  WebSocket message spam
- Clean up emitter listeners on close handler to prevent callbacks on
  destroyed sockets

Co-authored-by: Brad Groux <bradgroux@users.noreply.github.com>
Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-03-21 15:20:23 -05:00
Brad Groux
aaf0f47ac6
fix(api): resolve promise handling issues causing crashes and data loss (closes #232) (#238)
- gateway-chat-client: add settled flag to prevent multiple resolve/reject
  on the same promise from concurrent timeout, error, and close events
- file-lock: add rejection handler on previous.then() in timeout path so
  a rejected predecessor doesn't cause an unhandled rejection
- telemetry-service: capture event reference at enqueue time instead of
  shifting from queue at write time, preventing event loss under concurrency
- status-history-service: await async init before any public method runs,
  preventing race conditions when logStatusChange is called before
  loadLastEntry completes

Co-authored-by: Brad Groux <bradgroux@users.noreply.github.com>
Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-03-21 15:20:20 -05:00
Brad Groux
43725e69e2
fix(security): enforce HS256 algorithm in JWT verification (closes #231) (#237)
Add explicit `algorithms: ['HS256']` to all `jwt.verify()` calls to
prevent algorithm confusion attacks (CVE-2015-9235). Without this,
an attacker could switch the algorithm header to exploit key type
mismatches and forge valid tokens.

Co-authored-by: Brad Groux <bradgroux@users.noreply.github.com>
Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-03-21 15:20:18 -05:00
Brad Groux
70c8c06e56
docs: v4.0 documentation update and cleanup (closes #229) (#230)
v4.0 docs update: CHANGELOG, README, FEATURES, API-REFERENCE, 11 new SOPs, MCP docs, version bumps to 4.0.0, docs cleanup. Closes #229.
2026-03-21 12:20:16 -05:00
Brad Groux
f084ce7d39
fix: add missing requireDeliverableForDone to settings schema (#228)
The requireDeliverableForDone field was used in task-service.ts and
the UI (TasksTab.tsx) but was missing from the Zod validation schema
in feature-settings-schema.ts. Due to .strict() mode on
TaskBehaviorSettingsSchema, PATCH /api/settings/features rejected
any payload containing this field with a 400 error.

Fix: Add requireDeliverableForDone: z.boolean().optional() to
TaskBehaviorSettingsSchema after autoSaveDelayMs.

Also add tests verifying the field is accepted (true and false) and
that unknown fields are still rejected by strict mode.

Reimplements #130. Original contribution by @TylonHH.

Co-authored-by: Brad Groux <bradgroux@users.noreply.github.com>
2026-03-21 11:51:40 -05:00
Brad Groux
415a095d31
feat: Prompt Template Registry with Version Control (#184) (#220)
* feat: prompt template registry with version control (#184)

- Add PromptTemplate, PromptVersion, PromptUsage, PromptStats types
- Implement prompt-registry service with full CRUD, versioning, and usage tracking
- Add prompt-registry REST endpoints with preview rendering and statistics
- Create React Query hooks (usePromptTemplates, usePromptStats, etc.)
- Implement multi-tab PromptRegistry component with Templates, Versions, Usage, Stats, Preview tabs
- Add INTEGRATION.md documenting manual merge points for existing files
- Supports variable interpolation {{variable_name}} and changelog tracking
- File-based storage pattern consistent with existing template system

* fix: export prompt-registry types from shared barrel

* fix: handle optional changelog in prompt version

* fix: handle optional content field in version creation

* fix: remove unused imports and variables in prompt registry

* fix: remove all unused imports in prompt registry web files

* ci: trigger checks (retry)

---------

Co-authored-by: Brad Groux <bradgroux@users.noreply.github.com>
2026-03-21 11:16:59 -05:00
Brad Groux
d0a2ee4922
feat: Global System Health Status Bar (#185) (#221)
* feat: global system health status bar (#185)

* fix: export system-health types from shared barrel

---------

Co-authored-by: Brad Groux <bradgroux@users.noreply.github.com>
2026-03-21 11:12:04 -05:00
Brad Groux
4e6d331a33
feat: User Feedback Loop with Sentiment Analytics (#182) (#222)
* feat: user feedback loop with sentiment analytics (#182)

* fix: export feedback types from shared barrel

* fix: TS errors in feedback panel and API client

* fix: tooltip formatter type compatibility

* ci: retry flaky test

---------

Co-authored-by: Brad Groux <bradgroux@users.noreply.github.com>
2026-03-21 10:56:36 -05:00
Brad Groux
45cfc822e4
feat: Behavioral Drift Detection & Alerting (#181) (#218)
* Implement drift detection and alerting

* fix: correct type predicate in drift service filter

* fix: resolve DriftMonitor formatter type and DriftAlertFilters cast

* fix: add rm export to fs-helpers for drift-service cleanup

* ci: trigger workflow

* chore: trigger ci

* fix: ViewContext union syntax error

* fix: add rm to docker-paths test node:fs/promises mock

---------

Co-authored-by: bradgroux <bradgroux@users.noreply.github.com>
2026-03-21 09:33:34 -05:00
Brad Groux
ac64785326
feat: Decision Audit Trail with Assumption Tracking (#179) (#216)
* feat: add decision audit trail with assumption tracking

* fix: mock node:fs/promises in tests for fs-helpers compat

* fix: add full fs/promises mock in docker-paths test

* fix: add mkdir to node:fs/promises mock in jwt-rotation test

* ci: trigger workflow

* chore: trigger ci

* fix: ViewContext union syntax, expand fs/promises mock

---------

Co-authored-by: bradgroux <bradgroux@users.noreply.github.com>
2026-03-21 09:28:35 -05:00
Brad Groux
50f76f811a
feat: Agent Output Evaluation & Scoring Framework (#180) (#217)
* Implement scoring evaluation framework

* fix: resolve TypeScript errors in ScoreExplorer component

---------

Co-authored-by: bradgroux <brad@digitalmeld.io>
Co-authored-by: Brad Groux <bradgroux@users.noreply.github.com>
2026-03-21 09:13:24 -05:00
Brad Groux
1a2476257e
feat: Agent Policy & Guard Engine (#178) (#215)
* Implement policy guard engine for agent actions

* fix: wrap policy routes with asyncHandler for type safety

* fix: prevent unhandled rejection race in security test cleanup

---------

Co-authored-by: bradgroux <bradgroux@users.noreply.github.com>
2026-03-21 09:03:01 -05:00
Brad Groux
9d453a09f6
feat(squad-chat): add Adaptive Card support to squad messages (#214)
Add optional 'card' field (Record<string, unknown>) to SquadMessage and
SquadMessageInput types, allowing callers to attach Adaptive Card v1.5
JSON payloads to squad chat messages.

Changes:
- shared: Add card? to SquadMessage and SquadMessageInput interfaces
- routes/chat: Add card to zod validation schema and passthrough
- chat-service: Accept and spread card into squad message object
- squad-webhook: Include card in webhook payload type and forwarding

The card field flows through the full pipeline: API validation → storage
→ API response → WebSocket broadcast → webhook forwarding. Cards are
transient (not serialized to markdown logs) and intended for real-time
delivery to Teams via Adaptive Card attachments.

Co-authored-by: Brad Groux <bradgroux@users.noreply.github.com>
2026-03-20 21:10:59 -05:00
Brad Groux
d7690888a3
fix: convert successRate from ratio to percentage in SystemHealthBar (#211) (#212)
getRunMetrics() returns successRate as 0-1 ratio but getOperationsSignal()
treated it as 0-100 percentage. This caused the banner to show '1% success
rate' when all runs succeeded, and incorrectly flagged operations as critical.

Multiply by 100 and round before threshold comparison and display.

Co-authored-by: Brad Groux <bradgroux@users.noreply.github.com>
2026-03-20 08:48:34 -05:00
Brad Groux
adbcfc930b
fix: resolve TypeScript build errors (#177)
- Add RunMode type and QaGateState interface to shared task.types.ts
- Add runMode and qaGate optional fields to Task and UpdateTaskInput interfaces
- Mirror changes in shared/src/types/task.types.d.ts (used by web bundler)
- Add RunModeGateSection.tsx component (was untracked, causing web build failure)
- Add qa-gate.test.ts and dependency-cycle.test.ts (untracked test files)

Co-authored-by: Brad Groux <bradgroux@users.noreply.github.com>
2026-03-19 22:09:46 -05:00
Brad Groux
681a3647b7
fix: correct false cycle detection in dependency API (#188) (#208)
- checkForCycle now accepts a direction parameter ('depends_on' | 'blocks')
  so DFS only traverses edges of the same relationship type being validated.
  Previously, mixing both types produced false positives: e.g. C depends_on D
  and D blocks E is a valid DAG, but the old DFS would traverse C→D→E through
  mixed edge types and incorrectly report a cycle when adding E depends_on C.

- Deep-copy task dependency objects before mutation so the in-memory cache is
  never corrupted by pre-commit edge additions, which caused the final race-
  condition check to mis-detect cycles on valid graphs.

- Fix blocks cycle detection direction: when adding A blocks B, the check
  should start from B and follow blocks edges to see if A is reachable,
  matching the same semantics as depends_on cycle detection.

- Add dependency-cycle.test.ts with 7 targeted test cases including the
  specific false-positive scenario from issue #188.

Co-authored-by: Brad Groux <bradgroux@users.noreply.github.com>
2026-03-19 19:48:35 -05:00
Brad Groux
2f9daca858
feat: add MCP comment CRUD tools (#200) (#206)
* feat(transcripts): add /api/transcripts/dedup-check endpoint for n8n dedup

Bridges n8n (no local fs) and inbox/transcripts/processed/ folder-based dedup rule.
Rule: processed file match = transcriptMatchFound:true (skip), else false (allow through).
Called by SMFL870bnazxSZem Transcript Dedup Check node (now HTTP Request, not Code node).

* feat(webhook): add /api/webhook/n8n endpoint for n8n email-directive + attachment ingest

- New route: POST /api/webhook/n8n (unauthenticated, before auth middleware)
- Accepts email-directive payloads from n8n Email Ingestion Engine
- Downloads base64-encoded attachments (docx/pdf/txt/csv/xlsx only)
- Saves to ~/clawd/inbox/attachments/ with timestamped names
- Writes sidecar .json metadata for each directive
- Validates against optional N8N_WEBHOOK_SECRET env var

Fixes: Post Directive Webhook was 404ing on every directive email

* feat: add MCP comment CRUD tools (#200)

---------

Co-authored-by: Brad Groux <bradgroux@users.noreply.github.com>
2026-03-19 19:48:30 -05:00
Francois Altwies
0580ebe55a
feat(hooks): wire lifecycle hooks to notification service (#201)
Complete the TODO at hook-service.ts:153 — when a hook config has
`notify: true`, create a notification via NotificationService for
the lifecycle event (created, started, blocked, completed, archived).

Follows the same non-blocking pattern as fireWebhook and fireSquadChat:
errors are logged but never propagate to the caller.

Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-19 19:48:17 -05:00
dependabot[bot]
f533772d16
chore: bump the production-dependencies group with 10 updates (#199)
Bumps the production-dependencies group with 10 updates:

| Package | From | To |
| --- | --- | --- |
| [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node) | `25.3.3` | `25.4.0` |
| [@typescript-eslint/eslint-plugin](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/eslint-plugin) | `8.56.1` | `8.57.0` |
| [@typescript-eslint/parser](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/parser) | `8.56.1` | `8.57.0` |
| [lint-staged](https://github.com/lint-staged/lint-staged) | `16.3.1` | `16.3.2` |
| [file-type](https://github.com/sindresorhus/file-type) | `21.3.0` | `21.3.1` |
| [@types/multer](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/multer) | `2.0.0` | `2.1.0` |
| [@types/sanitize-html](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/sanitize-html) | `2.16.0` | `2.16.1` |
| [dompurify](https://github.com/cure53/DOMPurify) | `3.3.1` | `3.3.2` |
| [lucide-react](https://github.com/lucide-icons/lucide/tree/HEAD/packages/lucide-react) | `0.576.0` | `0.577.0` |
| [recharts](https://github.com/recharts/recharts) | `3.7.0` | `3.8.0` |


Updates `@types/node` from 25.3.3 to 25.4.0
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node)

Updates `@typescript-eslint/eslint-plugin` from 8.56.1 to 8.57.0
- [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases)
- [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/eslint-plugin/CHANGELOG.md)
- [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.57.0/packages/eslint-plugin)

Updates `@typescript-eslint/parser` from 8.56.1 to 8.57.0
- [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases)
- [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/parser/CHANGELOG.md)
- [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.57.0/packages/parser)

Updates `lint-staged` from 16.3.1 to 16.3.2
- [Release notes](https://github.com/lint-staged/lint-staged/releases)
- [Changelog](https://github.com/lint-staged/lint-staged/blob/main/CHANGELOG.md)
- [Commits](https://github.com/lint-staged/lint-staged/compare/v16.3.1...v16.3.2)

Updates `file-type` from 21.3.0 to 21.3.1
- [Release notes](https://github.com/sindresorhus/file-type/releases)
- [Commits](https://github.com/sindresorhus/file-type/compare/v21.3.0...v21.3.1)

Updates `@types/multer` from 2.0.0 to 2.1.0
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/multer)

Updates `@types/sanitize-html` from 2.16.0 to 2.16.1
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/sanitize-html)

Updates `dompurify` from 3.3.1 to 3.3.2
- [Release notes](https://github.com/cure53/DOMPurify/releases)
- [Commits](https://github.com/cure53/DOMPurify/compare/3.3.1...3.3.2)

Updates `lucide-react` from 0.576.0 to 0.577.0
- [Release notes](https://github.com/lucide-icons/lucide/releases)
- [Commits](https://github.com/lucide-icons/lucide/commits/0.577.0/packages/lucide-react)

Updates `recharts` from 3.7.0 to 3.8.0
- [Release notes](https://github.com/recharts/recharts/releases)
- [Changelog](https://github.com/recharts/recharts/blob/main/CHANGELOG.md)
- [Commits](https://github.com/recharts/recharts/compare/v3.7.0...v3.8.0)

---
updated-dependencies:
- dependency-name: "@types/node"
  dependency-version: 25.4.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: production-dependencies
- dependency-name: "@typescript-eslint/eslint-plugin"
  dependency-version: 8.57.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: production-dependencies
- dependency-name: "@typescript-eslint/parser"
  dependency-version: 8.57.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: production-dependencies
- dependency-name: lint-staged
  dependency-version: 16.3.2
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: production-dependencies
- dependency-name: file-type
  dependency-version: 21.3.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production-dependencies
- dependency-name: "@types/multer"
  dependency-version: 2.1.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: production-dependencies
- dependency-name: "@types/sanitize-html"
  dependency-version: 2.16.1
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: production-dependencies
- dependency-name: dompurify
  dependency-version: 3.3.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production-dependencies
- dependency-name: lucide-react
  dependency-version: 0.577.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production-dependencies
- dependency-name: recharts
  dependency-version: 3.8.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-03-09 19:24:54 -05:00
Brad Groux
2afff60cc8 fix: resolve CI type errors in useTasks-patchCache test
- Widen assertPatchOnly hookFn parameter to accept any mutation hook return type
  instead of narrowly typing to useAddSubtask's signature
- Add explicit type annotation for 'call' parameter (TS7006)
- Update multer 2.1.0→2.1.1, express-rate-limit 8.2.1→8.2.2,
  hono 4.12.3→4.12.4+, @hono/node-server 1.19.9→1.19.10+,
  @modelcontextprotocol/sdk to resolve 4 high severity audit findings
2026-03-09 13:14:50 -05:00
Francois Altwies
678689299a
feat: add global system health status bar (#185) (#195)
Aggregate system, agent, and operations health signals into a single
status bar displayed below the header. The bar shows one of five states
(stable/reviewing/drifting/elevated/alert) with color-coded indicators
and expands on click to show per-signal details.

Backend: GET /api/v1/system/health aggregates storage/disk/memory checks,
agent registry stats, and 24h run metrics into a unified response.

Frontend: SystemHealthBar component with useSystemHealth hook polling
via @tanstack/react-query (30s connected, 60s disconnected).

Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-09 07:42:35 -05:00
Francois Altwies
100bf15147
fix(server): broadcast WebSocket events on comment mutations (#191)
Comment add/edit/delete operations update tasks via taskService but
don't notify WebSocket clients, causing stale UI for other connected
users. They only see comment changes after a full page refresh.

Add broadcastTaskChange('updated', taskId) calls to all three comment
endpoints (POST, PATCH, DELETE) matching the pattern used in the main
task routes (tasks.ts lines 564, 711, 773).

Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-09 07:42:30 -05:00
Francois Altwies
a5f54d6d4c
fix: allow any localhost origin in dev mode (closes #190) (#194)
Docker users mapping to non-standard ports (e.g., -p 3099:3001) were
getting CORS blocked because buildDefaultDevOrigins() only generated
origins for ports 5173 and 3000.

Two changes:
1. CORS origin callback now allows any localhost/127.0.0.1 origin in
   dev mode (NODE_ENV !== 'production'), mirroring the WebSocket origin
   validator in auth.ts.
2. buildDefaultDevOrigins() now includes the server's own PORT in the
   default origins list.

Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-09 07:42:20 -05:00
BradGroux
a8c623677a fix(types): eliminate as-any casts and add type-safe query helpers
Replace all 9 production `as any` casts and ~35 unsafe `as string`
casts across 12 files with proper type narrowing.

Changes:
- Add server/src/lib/query-helpers.ts with qStr, qStrD, qNum, qNumD,
  and paramStr utilities for safe Express 5 query/param extraction
- telemetry.ts: use discriminated union narrowing for run.completed
  durationMs instead of (eventInput as any).durationMs
- telemetry-service.ts: use intersection type cast instead of as any
  for durationMs capping
- docs.ts: replace (req.params as any).path with paramStr(); replace
  as string query casts with qStr/qStrD
- dashboard-metrics.ts: remove unnecessary as any on run.started agent
  (discriminated union already narrows correctly)
- config-service.ts: narrow as any to as Record<string,unknown>
- transition-hooks.ts: validate toStatus against TaskStatus enum
  instead of casting as any
- activity.ts, summary.ts, status-history.ts, digest.ts,
  error-learning.ts, task-observations.ts: replace all as string
  query param casts with type-safe helpers

Runtime behavior unchanged. All 1347 existing tests still pass.
tsc --noEmit: 0 errors (before and after).
2026-03-05 22:52:14 -06:00
BradGroux
1dfa5c764f fix(security): sanitize server error logging to prevent secret/token leakage
- Add lib/redact.ts: string-level redaction (Bearer tokens, JWTs, API keys,
  hex secrets), object-level redaction (sensitive key names), and pino
  serializers for err/req objects
- Update lib/logger.ts: wire redactSerializers and pino redact paths for
  auth headers (authorization, x-api-key, cookie, set-cookie)
- Fix auth.ts checkAdminKeyStrength(): no longer logs actual admin key value
  in weak-key warning (was exposing plaintext secret)
- Replace console.warn in auth.ts isLocalhostRequest() with structured logger
- Fix reset-password.ts: log only err.message, not full error object
- Add 28-test suite (__tests__/log-redaction.test.ts) covering:
  - String pattern redaction (Bearer, JWT, API key prefixes, hex tokens)
  - Object key redaction (password, token, apiKey, credentials, etc.)
  - Pino serializer behavior for err and req objects
  - requestId preservation through redaction
  - UUID-style ID preservation (not over-redacted)
  - Edge cases (null, depth limits, empty strings)

All 1458 existing tests + 28 new tests pass. TypeScript clean.

Closes: task_20260306_lv4K70
2026-03-05 22:34:23 -06:00
dependabot[bot]
a72200f114
chore: bump @types/supertest from 6.0.3 to 7.2.0 (#173)
Bumps [@types/supertest](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/supertest) from 6.0.3 to 7.2.0.
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/supertest)

---
updated-dependencies:
- dependency-name: "@types/supertest"
  dependency-version: 7.2.0
  dependency-type: direct:development
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-03-04 12:06:44 -06:00
Brad Groux
22d122bde5
fix(api): add bulk-archive-by-ids endpoint for board mass archive (#176)
* fix(sync): persist agent linkage across task updates + add route-level integration gate

* chore(pr): remove internal production checklist from upstream PR scope

* test(sync): remove fixed flap-guard sleep via configurable threshold

* fix(api): add bulk-archive-by-ids endpoint for board mass archive

* docs: record bulk-archive-by-ids fix for mass archive

---------

Co-authored-by: SETH VOS <sethai@SETHs-Mac-mini.lan>
Co-authored-by: BradGroux <super.seth.vos@gmail.com>
2026-03-04 11:35:13 -06:00
BradGroux
0b14f27488 chore(release): bump version to 3.3.3
Patch correction release delivering:
- fix(stability): Complete Zod 4 API migration (#162)
- fix(security): SSRF protection for webhook URLs (#165)
- perf(websocket): Batch broadcasts to prevent event loop blocking (#167)
- feat: Orchestrator Delegation Enforcement gate
- feat: Enforcement Gate Toast Notifications
- feat: Dashboard Enforcement Indicator
2026-03-01 14:00:13 -06:00
Brad Groux
d736621ca5
perf(websocket): batch broadcasts to prevent event loop blocking (#167)
Add batched WebSocket broadcasting to improve performance with
many connected clients.

Changes:
- New broadcastToClients() helper function
- Batches client.send() calls in groups of 50
- Uses setImmediate() between batches to yield event loop
- Preserves synchronous behavior for small client counts (<50)

Applied to all broadcast functions:
- broadcastTaskChange()
- broadcastChatMessage()
- broadcastSquadMessage()
- broadcastTelemetryEvent()
- broadcastNewMessage()
- broadcastWorkflowStatus()

Performance impact:
- Prevents main thread blocking with 100+ clients
- No impact on latency for typical deployments (<50 clients)
- Maintains message ordering within each client

Risk: Low - backward compatible, fallback to sync for small counts

Co-authored-by: BradGroux <super.seth.vos@gmail.com>
2026-03-01 13:56:09 -06:00
Brad Groux
319465c171
fix(security): Add SSRF protection for webhook URLs (#165)
* fix(stability): complete Zod 4 API migration

BREAKING CHANGE: Migrated from Zod 3 to Zod 4 API patterns

Changes:
- Replace ZodError.errors with ZodError.issues (Zod 4 API)
- Update z.record(valueSchema) to z.record(z.string(), valueSchema)
- Fix env.ts schema defaults to use correct types (numbers/booleans)
- Replace required_error with message in Zod schemas

This resolves 50+ TypeScript compilation errors that were blocking
CI/CD and potentially causing runtime issues.

Fixes: type checking errors in server and web packages
Risk: Low - straightforward API migration with full test coverage

* fix(zod4): use string defaults for transform/pipe schemas

Zod v4 changed .default() to require the input type (string) rather
than the output type. Fixed PORT, VERITAS_AUTH_ENABLED,
VERITAS_AUTH_LOCALHOST_BYPASS, CSP_REPORT_ONLY, and RATE_LIMIT_MAX
to pass string defaults to their respective portSchema / booleanString
/ positiveIntString coercing schemas.

* fix(security): add SSRF protection for webhook URLs

Add URL validation to prevent Server-Side Request Forgery (SSRF) attacks
via configured webhook endpoints.

Security improvements:
- New validateWebhookUrl() utility in utils/url-validation.ts
- Blocks private IP ranges (RFC 1918: 10.x, 172.16.x, 192.168.x)
- Blocks loopback addresses (127.0.0.0/8, ::1)
- Blocks link-local addresses (169.254.x.x, fe80::/10)
- Blocks cloud metadata endpoints (169.254.169.254)
- Enforces HTTPS in production (allows HTTP in dev)
- Logs blocked requests for security monitoring

Applied to all webhook services:
- clawdbot-webhook-service.ts
- hook-service.ts
- squad-webhook-service.ts
- transition-hooks-service.ts

Risk: Low - additive validation layer, graceful fallback
CVSS: 6.5 (Medium-High) - SSRF mitigation

Refs: vk-full-audit-2026-03-01

---------

Co-authored-by: BradGroux <super.seth.vos@gmail.com>
2026-03-01 13:54:32 -06:00
Brad Groux
112da181c8
fix(stability): Complete Zod 4 API migration (#162)
* fix(stability): complete Zod 4 API migration

BREAKING CHANGE: Migrated from Zod 3 to Zod 4 API patterns

Changes:
- Replace ZodError.errors with ZodError.issues (Zod 4 API)
- Update z.record(valueSchema) to z.record(z.string(), valueSchema)
- Fix env.ts schema defaults to use correct types (numbers/booleans)
- Replace required_error with message in Zod schemas

This resolves 50+ TypeScript compilation errors that were blocking
CI/CD and potentially causing runtime issues.

Fixes: type checking errors in server and web packages
Risk: Low - straightforward API migration with full test coverage

* fix(zod4): use string defaults for transform/pipe schemas

Zod v4 changed .default() to require the input type (string) rather
than the output type. Fixed PORT, VERITAS_AUTH_ENABLED,
VERITAS_AUTH_LOCALHOST_BYPASS, CSP_REPORT_ONLY, and RATE_LIMIT_MAX
to pass string defaults to their respective portSchema / booleanString
/ positiveIntString coercing schemas.

---------

Co-authored-by: BradGroux <super.seth.vos@gmail.com>
2026-03-01 13:52:49 -06:00
BradGroux
bd46ffb31a chore(release): v3.3.2
- Bump all package versions to 3.3.2
- Update CHANGELOG with #155 (task↔agent sync), #156 (circuit breaker tests), #159 (sync auth hardening), #161 (sprint CLI+MCP)
- Update README version badge to 3.3.2
2026-03-01 13:08:51 -06:00
Brad Groux
daee651c7f
fix(security): harden task-agent sync auth boundary (#157 #158) (#159)
Fixes #157 and #158. Tests updated to use createTaskSyncToken() factory.
2026-03-01 12:26:27 -06:00
supersethvos
8c4eb42d76
feat(sync): task↔agent state sync + reconciliation (#155)
* feat(sync): implement task↔agent state sync with reconciliation and flap guard

* fix(sync): add sync auth context, ref validation, and reconcile bounds

---------

Co-authored-by: SETH VOS <sethai@SETHs-Mac-mini.lan>
2026-03-01 12:05:23 -06:00
Brad Groux
2dfdaa486c
test: add circuit breaker test suite (18 tests) (#156)
Covers all state transitions: closed → open → half-open → closed,
failure threshold, sliding monitor window eviction, concurrent
half-open rejection, manual reset, and getStatus() output.

No production code changed.

Co-authored-by: Brad Groux <bradgroux@Brads-Mac-mini.local>
2026-03-01 11:43:57 -06:00
Brad Groux
0d7dfb135c chore: release v3.3.1 2026-02-28 09:57:48 -06:00
dependabot[bot]
12478768cc
chore: bump the production-dependencies group across 1 directory with 8 updates (#154)
Bumps the production-dependencies group with 8 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node) | `25.3.0` | `25.3.2` |
| [@typescript-eslint/eslint-plugin](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/eslint-plugin) | `8.56.0` | `8.56.1` |
| [@typescript-eslint/parser](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/parser) | `8.56.0` | `8.56.1` |
| [lint-staged](https://github.com/lint-staged/lint-staged) | `16.2.7` | `16.3.0` |
| [multer](https://github.com/expressjs/multer) | `2.0.2` | `2.1.0` |
| [simple-git](https://github.com/steveukx/git-js/tree/HEAD/simple-git) | `3.32.1` | `3.32.3` |
| [autoprefixer](https://github.com/postcss/autoprefixer) | `10.4.24` | `10.4.27` |
| [@modelcontextprotocol/sdk](https://github.com/modelcontextprotocol/typescript-sdk) | `1.26.0` | `1.27.1` |

Updates `@types/node` from 25.3.0 to 25.3.2
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node)

Updates `@typescript-eslint/eslint-plugin` from 8.56.0 to 8.56.1
- [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases)
- [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/eslint-plugin/CHANGELOG.md)
- [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.56.1/packages/eslint-plugin)

Updates `@typescript-eslint/parser` from 8.56.0 to 8.56.1
- [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases)
- [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/parser/CHANGELOG.md)
- [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.56.1/packages/parser)

Updates `lint-staged` from 16.2.7 to 16.3.0
- [Release notes](https://github.com/lint-staged/lint-staged/releases)
- [Changelog](https://github.com/lint-staged/lint-staged/blob/main/CHANGELOG.md)
- [Commits](https://github.com/lint-staged/lint-staged/compare/v16.2.7...v16.3.0)

Updates `multer` from 2.0.2 to 2.1.0
- [Release notes](https://github.com/expressjs/multer/releases)
- [Changelog](https://github.com/expressjs/multer/blob/main/CHANGELOG.md)
- [Commits](https://github.com/expressjs/multer/compare/v2.0.2...v2.1.0)

Updates `simple-git` from 3.32.1 to 3.32.3
- [Release notes](https://github.com/steveukx/git-js/releases)
- [Changelog](https://github.com/steveukx/git-js/blob/main/simple-git/CHANGELOG.md)
- [Commits](https://github.com/steveukx/git-js/commits/simple-git@3.32.3/simple-git)

Updates `autoprefixer` from 10.4.24 to 10.4.27
- [Release notes](https://github.com/postcss/autoprefixer/releases)
- [Changelog](https://github.com/postcss/autoprefixer/blob/main/CHANGELOG.md)
- [Commits](https://github.com/postcss/autoprefixer/compare/10.4.24...10.4.27)

Updates `@modelcontextprotocol/sdk` from 1.26.0 to 1.27.1
- [Release notes](https://github.com/modelcontextprotocol/typescript-sdk/releases)
- [Commits](https://github.com/modelcontextprotocol/typescript-sdk/compare/v1.26.0...v1.27.1)

---
updated-dependencies:
- dependency-name: "@types/node"
  dependency-version: 25.3.2
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: production-dependencies
- dependency-name: "@typescript-eslint/eslint-plugin"
  dependency-version: 8.56.1
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: production-dependencies
- dependency-name: "@typescript-eslint/parser"
  dependency-version: 8.56.1
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: production-dependencies
- dependency-name: lint-staged
  dependency-version: 16.3.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: production-dependencies
- dependency-name: multer
  dependency-version: 2.1.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production-dependencies
- dependency-name: simple-git
  dependency-version: 3.32.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production-dependencies
- dependency-name: autoprefixer
  dependency-version: 10.4.27
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: production-dependencies
- dependency-name: "@modelcontextprotocol/sdk"
  dependency-version: 1.27.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-02-28 09:50:16 -06:00
Brad Groux
522d24c748
fix: update wildcard routes for Express 5 / path-to-regexp v8 (#153)
Express 5 uses path-to-regexp v8+ which requires named wildcards.
Bare '*' patterns are no longer valid.

Fixes #150

Co-authored-by: Brad Groux <bradgroux@Brads-Mac-mini.local>
2026-02-28 08:44:20 -06:00
Brad Groux
99f7fbdcc4 Revert "feat(security): add API key authentication for external requests"
This reverts commit 6b052e6b8d.
2026-02-22 11:26:44 -06:00
Brad Groux
6b052e6b8d feat(security): add API key authentication for external requests
- New middleware: external-api-key.ts
- Requires X-API-Key header for non-localhost requests
- Protects tunnel endpoint (vk-api.ops.digitalmeld.cloud)
- Localhost requests bypass key check for dev convenience
- Key stored in 1Password and VK_API_KEY env var
2026-02-22 11:23:05 -06:00
V.K. Watson
50dfff84ef revert: restore port 3001 across codebase, keep Express 5 path fix
Reverts port change from 1b7a9fe. OpenClaw gateway will move off 3001 instead.
2026-02-20 21:12:49 -06:00
V.K. Watson
1b7a9feb03 fix: update default API port from 3001 to 3002 across codebase
Avoids conflict with OpenClaw gateway on port 3001.
Updated: server config, docs, README, WebSocket hook.
2026-02-20 21:11:40 -06:00
V.K. Watson
095a181b5f fix: Express 5 path-to-regexp compatibility + move API to port 3002
- /file/* → /file/*path (Express 5 named wildcard syntax)
- req.params[0] → req.params.path (Express 5 param access)
- PORT 3001 → 3002 (avoid OpenClaw gateway conflict on localhost)
2026-02-20 21:10:31 -06:00
dependabot[bot]
90c7014558
chore: bump express to 5.2.1 (dependabot #140)
Bumps [express](https://github.com/expressjs/express) from 4.22.1 to 5.2.1.
- [Release notes](https://github.com/expressjs/express/releases)
- [Changelog](https://github.com/expressjs/express/blob/master/History.md)
- [Commits](https://github.com/expressjs/express/compare/v4.22.1...v5.2.1)

---
updated-dependencies:
- dependency-name: express
  dependency-version: 5.2.1
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-02-20 02:05:21 -06:00
dependabot[bot]
707039a171
chore: update production deps (dependabot #134)
Bumps the production-dependencies group with 15 updates:

| Package | From | To |
| --- | --- | --- |
| [@playwright/test](https://github.com/microsoft/playwright) | `1.58.0` | `1.58.2` |
| [@typescript-eslint/eslint-plugin](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/eslint-plugin) | `8.54.0` | `8.56.0` |
| [@typescript-eslint/parser](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/parser) | `8.54.0` | `8.56.0` |
| [ajv](https://github.com/ajv-validator/ajv) | `8.17.1` | `8.18.0` |
| [dotenv](https://github.com/motdotla/dotenv) | `17.2.3` | `17.3.1` |
| [pino](https://github.com/pinojs/pino) | `10.3.0` | `10.3.1` |
| [sanitize-html](https://github.com/apostrophecms/apostrophe/tree/HEAD/packages/sanitize-html) | `2.17.0` | `2.17.1` |
| [simple-git](https://github.com/steveukx/git-js/tree/HEAD/simple-git) | `3.30.0` | `3.31.1` |
| [@tanstack/react-query](https://github.com/TanStack/query/tree/HEAD/packages/react-query) | `5.90.20` | `5.90.21` |
| [lucide-react](https://github.com/lucide-icons/lucide/tree/HEAD/packages/lucide-react) | `0.468.0` | `0.575.0` |
| [react](https://github.com/facebook/react/tree/HEAD/packages/react) | `19.2.3` | `19.2.4` |
| [@types/react](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/react) | `19.2.9` | `19.2.14` |
| [react-dom](https://github.com/facebook/react/tree/HEAD/packages/react-dom) | `19.2.3` | `19.2.4` |
| [autoprefixer](https://github.com/postcss/autoprefixer) | `10.4.23` | `10.4.24` |
| [hono](https://github.com/honojs/hono) | `4.11.7` | `4.12.0` |

Updates `@playwright/test` from 1.58.0 to 1.58.2
- [Release notes](https://github.com/microsoft/playwright/releases)
- [Commits](https://github.com/microsoft/playwright/compare/v1.58.0...v1.58.2)

Updates `@typescript-eslint/eslint-plugin` from 8.54.0 to 8.56.0
- [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases)
- [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/eslint-plugin/CHANGELOG.md)
- [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.56.0/packages/eslint-plugin)

Updates `@typescript-eslint/parser` from 8.54.0 to 8.56.0
- [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases)
- [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/parser/CHANGELOG.md)
- [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.56.0/packages/parser)

Updates `ajv` from 8.17.1 to 8.18.0
- [Release notes](https://github.com/ajv-validator/ajv/releases)
- [Commits](https://github.com/ajv-validator/ajv/compare/v8.17.1...v8.18.0)

Updates `dotenv` from 17.2.3 to 17.3.1
- [Changelog](https://github.com/motdotla/dotenv/blob/master/CHANGELOG.md)
- [Commits](https://github.com/motdotla/dotenv/compare/v17.2.3...v17.3.1)

Updates `pino` from 10.3.0 to 10.3.1
- [Release notes](https://github.com/pinojs/pino/releases)
- [Commits](https://github.com/pinojs/pino/compare/v10.3.0...v10.3.1)

Updates `sanitize-html` from 2.17.0 to 2.17.1
- [Changelog](https://github.com/apostrophecms/apostrophe/blob/main/packages/sanitize-html/CHANGELOG.md)
- [Commits](https://github.com/apostrophecms/apostrophe/commits/2.17.1/packages/sanitize-html)

Updates `simple-git` from 3.30.0 to 3.31.1
- [Release notes](https://github.com/steveukx/git-js/releases)
- [Changelog](https://github.com/steveukx/git-js/blob/main/simple-git/CHANGELOG.md)
- [Commits](https://github.com/steveukx/git-js/commits/simple-git@3.31.1/simple-git)

Updates `@tanstack/react-query` from 5.90.20 to 5.90.21
- [Release notes](https://github.com/TanStack/query/releases)
- [Changelog](https://github.com/TanStack/query/blob/main/packages/react-query/CHANGELOG.md)
- [Commits](https://github.com/TanStack/query/commits/@tanstack/react-query@5.90.21/packages/react-query)

Updates `lucide-react` from 0.468.0 to 0.575.0
- [Release notes](https://github.com/lucide-icons/lucide/releases)
- [Commits](https://github.com/lucide-icons/lucide/commits/0.575.0/packages/lucide-react)

Updates `react` from 19.2.3 to 19.2.4
- [Release notes](https://github.com/facebook/react/releases)
- [Changelog](https://github.com/facebook/react/blob/main/CHANGELOG.md)
- [Commits](https://github.com/facebook/react/commits/v19.2.4/packages/react)

Updates `@types/react` from 19.2.9 to 19.2.14
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/react)

Updates `react-dom` from 19.2.3 to 19.2.4
- [Release notes](https://github.com/facebook/react/releases)
- [Changelog](https://github.com/facebook/react/blob/main/CHANGELOG.md)
- [Commits](https://github.com/facebook/react/commits/v19.2.4/packages/react-dom)

Updates `@types/react` from 19.2.9 to 19.2.14
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/react)

Updates `autoprefixer` from 10.4.23 to 10.4.24
- [Release notes](https://github.com/postcss/autoprefixer/releases)
- [Changelog](https://github.com/postcss/autoprefixer/blob/main/CHANGELOG.md)
- [Commits](https://github.com/postcss/autoprefixer/compare/10.4.23...10.4.24)

Updates `hono` from 4.11.7 to 4.12.0
- [Release notes](https://github.com/honojs/hono/releases)
- [Commits](https://github.com/honojs/hono/compare/v4.11.7...v4.12.0)

---
updated-dependencies:
- dependency-name: "@playwright/test"
  dependency-version: 1.58.2
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: production-dependencies
- dependency-name: "@typescript-eslint/eslint-plugin"
  dependency-version: 8.56.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: production-dependencies
- dependency-name: "@typescript-eslint/parser"
  dependency-version: 8.56.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: production-dependencies
- dependency-name: ajv
  dependency-version: 8.18.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production-dependencies
- dependency-name: dotenv
  dependency-version: 17.3.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production-dependencies
- dependency-name: pino
  dependency-version: 10.3.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production-dependencies
- dependency-name: sanitize-html
  dependency-version: 2.17.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production-dependencies
- dependency-name: simple-git
  dependency-version: 3.31.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production-dependencies
- dependency-name: "@tanstack/react-query"
  dependency-version: 5.90.21
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production-dependencies
- dependency-name: lucide-react
  dependency-version: 0.575.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production-dependencies
- dependency-name: react
  dependency-version: 19.2.4
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production-dependencies
- dependency-name: "@types/react"
  dependency-version: 19.2.14
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: production-dependencies
- dependency-name: react-dom
  dependency-version: 19.2.4
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production-dependencies
- dependency-name: "@types/react"
  dependency-version: 19.2.14
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: production-dependencies
- dependency-name: autoprefixer
  dependency-version: 10.4.24
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: production-dependencies
- dependency-name: hono
  dependency-version: 4.12.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-02-20 01:55:18 -06:00
V.K. Watson
9657e731b6
fix: guard updatedTask null check in task routes
also clean up observations section build warning
2026-02-20 01:51:45 -06:00