Brad Groux
ddca1b6cb4
fix: isolate status history tests from real state
2026-03-22 14:24:15 -05:00
Brad Groux
7483cc67f3
fix(security): harden localhost bypass and broadcast frontmatter parsing ( closes #236 ) ( #242 )
...
- auth: disable localhost bypass entirely in production mode instead of
just logging a warning — prevents misconfigured deployments from
allowing unauthenticated access
- broadcast-storage: wrap JSON.parse() calls for tags and readBy
frontmatter fields in try-catch, defaulting to empty arrays on parse
failure instead of crashing the route handler
Co-authored-by: Brad Groux <bradgroux@users.noreply.github.com>
Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-03-21 15:20:31 -05:00
Brad Groux
303b7935b6
fix(api): make startup init failures fatal and add shutdown timeouts ( closes #235 ) ( #241 )
...
- Service initialization (telemetry, policy, config, migrations) now
calls process.exit(1) on failure instead of silently continuing with
a partially broken server
- WebSocket server close gets a 3s timeout so stuck clients don't block
shutdown indefinitely
- Telemetry flush gets a 5s timeout so a stuck write queue doesn't
prevent shutdown
Co-authored-by: Brad Groux <bradgroux@users.noreply.github.com>
Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-03-21 15:20:28 -05:00
Brad Groux
0fc2c834ae
fix(api): prevent config cache stampede and log corrupted activity files ( closes #234 ) ( #240 )
...
- config-service: coalesce concurrent getConfig() calls into a single
disk read via pendingRead promise, preventing cache stampede under load
- activity-service: log warning when corrupted activity file is reset
instead of silently discarding data
Co-authored-by: Brad Groux <bradgroux@users.noreply.github.com>
Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-03-21 15:20:26 -05:00
Brad Groux
74dc3a9074
fix(api): WebSocket event listener leaks and add message rate limiting ( closes #233 ) ( #239 )
...
- Replace per-subscribe ws.on('close') listeners with tracked emitter
references, preventing listener accumulation when clients re-subscribe
- Add message rate limiting (30 msgs / 10s window) to prevent DoS via
WebSocket message spam
- Clean up emitter listeners on close handler to prevent callbacks on
destroyed sockets
Co-authored-by: Brad Groux <bradgroux@users.noreply.github.com>
Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-03-21 15:20:23 -05:00
Brad Groux
aaf0f47ac6
fix(api): resolve promise handling issues causing crashes and data loss ( closes #232 ) ( #238 )
...
- gateway-chat-client: add settled flag to prevent multiple resolve/reject
on the same promise from concurrent timeout, error, and close events
- file-lock: add rejection handler on previous.then() in timeout path so
a rejected predecessor doesn't cause an unhandled rejection
- telemetry-service: capture event reference at enqueue time instead of
shifting from queue at write time, preventing event loss under concurrency
- status-history-service: await async init before any public method runs,
preventing race conditions when logStatusChange is called before
loadLastEntry completes
Co-authored-by: Brad Groux <bradgroux@users.noreply.github.com>
Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-03-21 15:20:20 -05:00
Brad Groux
43725e69e2
fix(security): enforce HS256 algorithm in JWT verification ( closes #231 ) ( #237 )
...
Add explicit `algorithms: ['HS256']` to all `jwt.verify()` calls to
prevent algorithm confusion attacks (CVE-2015-9235). Without this,
an attacker could switch the algorithm header to exploit key type
mismatches and forge valid tokens.
Co-authored-by: Brad Groux <bradgroux@users.noreply.github.com>
Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-03-21 15:20:18 -05:00
Brad Groux
70c8c06e56
docs: v4.0 documentation update and cleanup ( closes #229 ) ( #230 )
...
v4.0 docs update: CHANGELOG, README, FEATURES, API-REFERENCE, 11 new SOPs, MCP docs, version bumps to 4.0.0, docs cleanup. Closes #229 .
2026-03-21 12:20:16 -05:00
Brad Groux
f084ce7d39
fix: add missing requireDeliverableForDone to settings schema ( #228 )
...
The requireDeliverableForDone field was used in task-service.ts and
the UI (TasksTab.tsx) but was missing from the Zod validation schema
in feature-settings-schema.ts. Due to .strict() mode on
TaskBehaviorSettingsSchema, PATCH /api/settings/features rejected
any payload containing this field with a 400 error.
Fix: Add requireDeliverableForDone: z.boolean().optional() to
TaskBehaviorSettingsSchema after autoSaveDelayMs.
Also add tests verifying the field is accepted (true and false) and
that unknown fields are still rejected by strict mode.
Reimplements #130 . Original contribution by @TylonHH.
Co-authored-by: Brad Groux <bradgroux@users.noreply.github.com>
2026-03-21 11:51:40 -05:00
Brad Groux
415a095d31
feat: Prompt Template Registry with Version Control ( #184 ) ( #220 )
...
* feat: prompt template registry with version control (#184 )
- Add PromptTemplate, PromptVersion, PromptUsage, PromptStats types
- Implement prompt-registry service with full CRUD, versioning, and usage tracking
- Add prompt-registry REST endpoints with preview rendering and statistics
- Create React Query hooks (usePromptTemplates, usePromptStats, etc.)
- Implement multi-tab PromptRegistry component with Templates, Versions, Usage, Stats, Preview tabs
- Add INTEGRATION.md documenting manual merge points for existing files
- Supports variable interpolation {{variable_name}} and changelog tracking
- File-based storage pattern consistent with existing template system
* fix: export prompt-registry types from shared barrel
* fix: handle optional changelog in prompt version
* fix: handle optional content field in version creation
* fix: remove unused imports and variables in prompt registry
* fix: remove all unused imports in prompt registry web files
* ci: trigger checks (retry)
---------
Co-authored-by: Brad Groux <bradgroux@users.noreply.github.com>
2026-03-21 11:16:59 -05:00
Brad Groux
d0a2ee4922
feat: Global System Health Status Bar ( #185 ) ( #221 )
...
* feat: global system health status bar (#185 )
* fix: export system-health types from shared barrel
---------
Co-authored-by: Brad Groux <bradgroux@users.noreply.github.com>
2026-03-21 11:12:04 -05:00
Brad Groux
4e6d331a33
feat: User Feedback Loop with Sentiment Analytics ( #182 ) ( #222 )
...
* feat: user feedback loop with sentiment analytics (#182 )
* fix: export feedback types from shared barrel
* fix: TS errors in feedback panel and API client
* fix: tooltip formatter type compatibility
* ci: retry flaky test
---------
Co-authored-by: Brad Groux <bradgroux@users.noreply.github.com>
2026-03-21 10:56:36 -05:00
Brad Groux
45cfc822e4
feat: Behavioral Drift Detection & Alerting ( #181 ) ( #218 )
...
* Implement drift detection and alerting
* fix: correct type predicate in drift service filter
* fix: resolve DriftMonitor formatter type and DriftAlertFilters cast
* fix: add rm export to fs-helpers for drift-service cleanup
* ci: trigger workflow
* chore: trigger ci
* fix: ViewContext union syntax error
* fix: add rm to docker-paths test node:fs/promises mock
---------
Co-authored-by: bradgroux <bradgroux@users.noreply.github.com>
2026-03-21 09:33:34 -05:00
Brad Groux
ac64785326
feat: Decision Audit Trail with Assumption Tracking ( #179 ) ( #216 )
...
* feat: add decision audit trail with assumption tracking
* fix: mock node:fs/promises in tests for fs-helpers compat
* fix: add full fs/promises mock in docker-paths test
* fix: add mkdir to node:fs/promises mock in jwt-rotation test
* ci: trigger workflow
* chore: trigger ci
* fix: ViewContext union syntax, expand fs/promises mock
---------
Co-authored-by: bradgroux <bradgroux@users.noreply.github.com>
2026-03-21 09:28:35 -05:00
Brad Groux
50f76f811a
feat: Agent Output Evaluation & Scoring Framework ( #180 ) ( #217 )
...
* Implement scoring evaluation framework
* fix: resolve TypeScript errors in ScoreExplorer component
---------
Co-authored-by: bradgroux <brad@digitalmeld.io>
Co-authored-by: Brad Groux <bradgroux@users.noreply.github.com>
2026-03-21 09:13:24 -05:00
Brad Groux
1a2476257e
feat: Agent Policy & Guard Engine ( #178 ) ( #215 )
...
* Implement policy guard engine for agent actions
* fix: wrap policy routes with asyncHandler for type safety
* fix: prevent unhandled rejection race in security test cleanup
---------
Co-authored-by: bradgroux <bradgroux@users.noreply.github.com>
2026-03-21 09:03:01 -05:00
Brad Groux
9d453a09f6
feat(squad-chat): add Adaptive Card support to squad messages ( #214 )
...
Add optional 'card' field (Record<string, unknown>) to SquadMessage and
SquadMessageInput types, allowing callers to attach Adaptive Card v1.5
JSON payloads to squad chat messages.
Changes:
- shared: Add card? to SquadMessage and SquadMessageInput interfaces
- routes/chat: Add card to zod validation schema and passthrough
- chat-service: Accept and spread card into squad message object
- squad-webhook: Include card in webhook payload type and forwarding
The card field flows through the full pipeline: API validation → storage
→ API response → WebSocket broadcast → webhook forwarding. Cards are
transient (not serialized to markdown logs) and intended for real-time
delivery to Teams via Adaptive Card attachments.
Co-authored-by: Brad Groux <bradgroux@users.noreply.github.com>
2026-03-20 21:10:59 -05:00
Brad Groux
d7690888a3
fix: convert successRate from ratio to percentage in SystemHealthBar ( #211 ) ( #212 )
...
getRunMetrics() returns successRate as 0-1 ratio but getOperationsSignal()
treated it as 0-100 percentage. This caused the banner to show '1% success
rate' when all runs succeeded, and incorrectly flagged operations as critical.
Multiply by 100 and round before threshold comparison and display.
Co-authored-by: Brad Groux <bradgroux@users.noreply.github.com>
2026-03-20 08:48:34 -05:00
Brad Groux
adbcfc930b
fix: resolve TypeScript build errors ( #177 )
...
- Add RunMode type and QaGateState interface to shared task.types.ts
- Add runMode and qaGate optional fields to Task and UpdateTaskInput interfaces
- Mirror changes in shared/src/types/task.types.d.ts (used by web bundler)
- Add RunModeGateSection.tsx component (was untracked, causing web build failure)
- Add qa-gate.test.ts and dependency-cycle.test.ts (untracked test files)
Co-authored-by: Brad Groux <bradgroux@users.noreply.github.com>
2026-03-19 22:09:46 -05:00
Brad Groux
681a3647b7
fix: correct false cycle detection in dependency API ( #188 ) ( #208 )
...
- checkForCycle now accepts a direction parameter ('depends_on' | 'blocks')
so DFS only traverses edges of the same relationship type being validated.
Previously, mixing both types produced false positives: e.g. C depends_on D
and D blocks E is a valid DAG, but the old DFS would traverse C→D→E through
mixed edge types and incorrectly report a cycle when adding E depends_on C.
- Deep-copy task dependency objects before mutation so the in-memory cache is
never corrupted by pre-commit edge additions, which caused the final race-
condition check to mis-detect cycles on valid graphs.
- Fix blocks cycle detection direction: when adding A blocks B, the check
should start from B and follow blocks edges to see if A is reachable,
matching the same semantics as depends_on cycle detection.
- Add dependency-cycle.test.ts with 7 targeted test cases including the
specific false-positive scenario from issue #188 .
Co-authored-by: Brad Groux <bradgroux@users.noreply.github.com>
2026-03-19 19:48:35 -05:00
Brad Groux
2f9daca858
feat: add MCP comment CRUD tools ( #200 ) ( #206 )
...
* feat(transcripts): add /api/transcripts/dedup-check endpoint for n8n dedup
Bridges n8n (no local fs) and inbox/transcripts/processed/ folder-based dedup rule.
Rule: processed file match = transcriptMatchFound:true (skip), else false (allow through).
Called by SMFL870bnazxSZem Transcript Dedup Check node (now HTTP Request, not Code node).
* feat(webhook): add /api/webhook/n8n endpoint for n8n email-directive + attachment ingest
- New route: POST /api/webhook/n8n (unauthenticated, before auth middleware)
- Accepts email-directive payloads from n8n Email Ingestion Engine
- Downloads base64-encoded attachments (docx/pdf/txt/csv/xlsx only)
- Saves to ~/clawd/inbox/attachments/ with timestamped names
- Writes sidecar .json metadata for each directive
- Validates against optional N8N_WEBHOOK_SECRET env var
Fixes: Post Directive Webhook was 404ing on every directive email
* feat: add MCP comment CRUD tools (#200 )
---------
Co-authored-by: Brad Groux <bradgroux@users.noreply.github.com>
2026-03-19 19:48:30 -05:00
Francois Altwies
0580ebe55a
feat(hooks): wire lifecycle hooks to notification service ( #201 )
...
Complete the TODO at hook-service.ts:153 — when a hook config has
`notify: true`, create a notification via NotificationService for
the lifecycle event (created, started, blocked, completed, archived).
Follows the same non-blocking pattern as fireWebhook and fireSquadChat:
errors are logged but never propagate to the caller.
Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-19 19:48:17 -05:00
dependabot[bot]
f533772d16
chore: bump the production-dependencies group with 10 updates ( #199 )
...
Bumps the production-dependencies group with 10 updates:
| Package | From | To |
| --- | --- | --- |
| [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node ) | `25.3.3` | `25.4.0` |
| [@typescript-eslint/eslint-plugin](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/eslint-plugin ) | `8.56.1` | `8.57.0` |
| [@typescript-eslint/parser](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/parser ) | `8.56.1` | `8.57.0` |
| [lint-staged](https://github.com/lint-staged/lint-staged ) | `16.3.1` | `16.3.2` |
| [file-type](https://github.com/sindresorhus/file-type ) | `21.3.0` | `21.3.1` |
| [@types/multer](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/multer ) | `2.0.0` | `2.1.0` |
| [@types/sanitize-html](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/sanitize-html ) | `2.16.0` | `2.16.1` |
| [dompurify](https://github.com/cure53/DOMPurify ) | `3.3.1` | `3.3.2` |
| [lucide-react](https://github.com/lucide-icons/lucide/tree/HEAD/packages/lucide-react ) | `0.576.0` | `0.577.0` |
| [recharts](https://github.com/recharts/recharts ) | `3.7.0` | `3.8.0` |
Updates `@types/node` from 25.3.3 to 25.4.0
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases )
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node )
Updates `@typescript-eslint/eslint-plugin` from 8.56.1 to 8.57.0
- [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases )
- [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/eslint-plugin/CHANGELOG.md )
- [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.57.0/packages/eslint-plugin )
Updates `@typescript-eslint/parser` from 8.56.1 to 8.57.0
- [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases )
- [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/parser/CHANGELOG.md )
- [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.57.0/packages/parser )
Updates `lint-staged` from 16.3.1 to 16.3.2
- [Release notes](https://github.com/lint-staged/lint-staged/releases )
- [Changelog](https://github.com/lint-staged/lint-staged/blob/main/CHANGELOG.md )
- [Commits](https://github.com/lint-staged/lint-staged/compare/v16.3.1...v16.3.2 )
Updates `file-type` from 21.3.0 to 21.3.1
- [Release notes](https://github.com/sindresorhus/file-type/releases )
- [Commits](https://github.com/sindresorhus/file-type/compare/v21.3.0...v21.3.1 )
Updates `@types/multer` from 2.0.0 to 2.1.0
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases )
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/multer )
Updates `@types/sanitize-html` from 2.16.0 to 2.16.1
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases )
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/sanitize-html )
Updates `dompurify` from 3.3.1 to 3.3.2
- [Release notes](https://github.com/cure53/DOMPurify/releases )
- [Commits](https://github.com/cure53/DOMPurify/compare/3.3.1...3.3.2 )
Updates `lucide-react` from 0.576.0 to 0.577.0
- [Release notes](https://github.com/lucide-icons/lucide/releases )
- [Commits](https://github.com/lucide-icons/lucide/commits/0.577.0/packages/lucide-react )
Updates `recharts` from 3.7.0 to 3.8.0
- [Release notes](https://github.com/recharts/recharts/releases )
- [Changelog](https://github.com/recharts/recharts/blob/main/CHANGELOG.md )
- [Commits](https://github.com/recharts/recharts/compare/v3.7.0...v3.8.0 )
---
updated-dependencies:
- dependency-name: "@types/node"
dependency-version: 25.4.0
dependency-type: direct:development
update-type: version-update:semver-minor
dependency-group: production-dependencies
- dependency-name: "@typescript-eslint/eslint-plugin"
dependency-version: 8.57.0
dependency-type: direct:development
update-type: version-update:semver-minor
dependency-group: production-dependencies
- dependency-name: "@typescript-eslint/parser"
dependency-version: 8.57.0
dependency-type: direct:development
update-type: version-update:semver-minor
dependency-group: production-dependencies
- dependency-name: lint-staged
dependency-version: 16.3.2
dependency-type: direct:development
update-type: version-update:semver-patch
dependency-group: production-dependencies
- dependency-name: file-type
dependency-version: 21.3.1
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: production-dependencies
- dependency-name: "@types/multer"
dependency-version: 2.1.0
dependency-type: direct:development
update-type: version-update:semver-minor
dependency-group: production-dependencies
- dependency-name: "@types/sanitize-html"
dependency-version: 2.16.1
dependency-type: direct:development
update-type: version-update:semver-patch
dependency-group: production-dependencies
- dependency-name: dompurify
dependency-version: 3.3.2
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: production-dependencies
- dependency-name: lucide-react
dependency-version: 0.577.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: production-dependencies
- dependency-name: recharts
dependency-version: 3.8.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: production-dependencies
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-03-09 19:24:54 -05:00
Brad Groux
2afff60cc8
fix: resolve CI type errors in useTasks-patchCache test
...
- Widen assertPatchOnly hookFn parameter to accept any mutation hook return type
instead of narrowly typing to useAddSubtask's signature
- Add explicit type annotation for 'call' parameter (TS7006)
- Update multer 2.1.0→2.1.1, express-rate-limit 8.2.1→8.2.2,
hono 4.12.3→4.12.4+, @hono/node-server 1.19.9→1.19.10+,
@modelcontextprotocol/sdk to resolve 4 high severity audit findings
2026-03-09 13:14:50 -05:00
Francois Altwies
678689299a
feat: add global system health status bar ( #185 ) ( #195 )
...
Aggregate system, agent, and operations health signals into a single
status bar displayed below the header. The bar shows one of five states
(stable/reviewing/drifting/elevated/alert) with color-coded indicators
and expands on click to show per-signal details.
Backend: GET /api/v1/system/health aggregates storage/disk/memory checks,
agent registry stats, and 24h run metrics into a unified response.
Frontend: SystemHealthBar component with useSystemHealth hook polling
via @tanstack/react-query (30s connected, 60s disconnected).
Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-09 07:42:35 -05:00
Francois Altwies
100bf15147
fix(server): broadcast WebSocket events on comment mutations ( #191 )
...
Comment add/edit/delete operations update tasks via taskService but
don't notify WebSocket clients, causing stale UI for other connected
users. They only see comment changes after a full page refresh.
Add broadcastTaskChange('updated', taskId) calls to all three comment
endpoints (POST, PATCH, DELETE) matching the pattern used in the main
task routes (tasks.ts lines 564, 711, 773).
Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-09 07:42:30 -05:00
Francois Altwies
a5f54d6d4c
fix: allow any localhost origin in dev mode ( closes #190 ) ( #194 )
...
Docker users mapping to non-standard ports (e.g., -p 3099:3001) were
getting CORS blocked because buildDefaultDevOrigins() only generated
origins for ports 5173 and 3000.
Two changes:
1. CORS origin callback now allows any localhost/127.0.0.1 origin in
dev mode (NODE_ENV !== 'production'), mirroring the WebSocket origin
validator in auth.ts.
2. buildDefaultDevOrigins() now includes the server's own PORT in the
default origins list.
Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-09 07:42:20 -05:00
BradGroux
a8c623677a
fix(types): eliminate as-any casts and add type-safe query helpers
...
Replace all 9 production `as any` casts and ~35 unsafe `as string`
casts across 12 files with proper type narrowing.
Changes:
- Add server/src/lib/query-helpers.ts with qStr, qStrD, qNum, qNumD,
and paramStr utilities for safe Express 5 query/param extraction
- telemetry.ts: use discriminated union narrowing for run.completed
durationMs instead of (eventInput as any).durationMs
- telemetry-service.ts: use intersection type cast instead of as any
for durationMs capping
- docs.ts: replace (req.params as any).path with paramStr(); replace
as string query casts with qStr/qStrD
- dashboard-metrics.ts: remove unnecessary as any on run.started agent
(discriminated union already narrows correctly)
- config-service.ts: narrow as any to as Record<string,unknown>
- transition-hooks.ts: validate toStatus against TaskStatus enum
instead of casting as any
- activity.ts, summary.ts, status-history.ts, digest.ts,
error-learning.ts, task-observations.ts: replace all as string
query param casts with type-safe helpers
Runtime behavior unchanged. All 1347 existing tests still pass.
tsc --noEmit: 0 errors (before and after).
2026-03-05 22:52:14 -06:00
BradGroux
1dfa5c764f
fix(security): sanitize server error logging to prevent secret/token leakage
...
- Add lib/redact.ts: string-level redaction (Bearer tokens, JWTs, API keys,
hex secrets), object-level redaction (sensitive key names), and pino
serializers for err/req objects
- Update lib/logger.ts: wire redactSerializers and pino redact paths for
auth headers (authorization, x-api-key, cookie, set-cookie)
- Fix auth.ts checkAdminKeyStrength(): no longer logs actual admin key value
in weak-key warning (was exposing plaintext secret)
- Replace console.warn in auth.ts isLocalhostRequest() with structured logger
- Fix reset-password.ts: log only err.message, not full error object
- Add 28-test suite (__tests__/log-redaction.test.ts) covering:
- String pattern redaction (Bearer, JWT, API key prefixes, hex tokens)
- Object key redaction (password, token, apiKey, credentials, etc.)
- Pino serializer behavior for err and req objects
- requestId preservation through redaction
- UUID-style ID preservation (not over-redacted)
- Edge cases (null, depth limits, empty strings)
All 1458 existing tests + 28 new tests pass. TypeScript clean.
Closes: task_20260306_lv4K70
2026-03-05 22:34:23 -06:00
dependabot[bot]
a72200f114
chore: bump @types/supertest from 6.0.3 to 7.2.0 ( #173 )
...
Bumps [@types/supertest](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/supertest ) from 6.0.3 to 7.2.0.
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases )
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/supertest )
---
updated-dependencies:
- dependency-name: "@types/supertest"
dependency-version: 7.2.0
dependency-type: direct:development
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-03-04 12:06:44 -06:00
Brad Groux
22d122bde5
fix(api): add bulk-archive-by-ids endpoint for board mass archive ( #176 )
...
* fix(sync): persist agent linkage across task updates + add route-level integration gate
* chore(pr): remove internal production checklist from upstream PR scope
* test(sync): remove fixed flap-guard sleep via configurable threshold
* fix(api): add bulk-archive-by-ids endpoint for board mass archive
* docs: record bulk-archive-by-ids fix for mass archive
---------
Co-authored-by: SETH VOS <sethai@SETHs-Mac-mini.lan>
Co-authored-by: BradGroux <super.seth.vos@gmail.com>
2026-03-04 11:35:13 -06:00
BradGroux
0b14f27488
chore(release): bump version to 3.3.3
...
Patch correction release delivering:
- fix(stability): Complete Zod 4 API migration (#162 )
- fix(security): SSRF protection for webhook URLs (#165 )
- perf(websocket): Batch broadcasts to prevent event loop blocking (#167 )
- feat: Orchestrator Delegation Enforcement gate
- feat: Enforcement Gate Toast Notifications
- feat: Dashboard Enforcement Indicator
2026-03-01 14:00:13 -06:00
Brad Groux
d736621ca5
perf(websocket): batch broadcasts to prevent event loop blocking ( #167 )
...
Add batched WebSocket broadcasting to improve performance with
many connected clients.
Changes:
- New broadcastToClients() helper function
- Batches client.send() calls in groups of 50
- Uses setImmediate() between batches to yield event loop
- Preserves synchronous behavior for small client counts (<50)
Applied to all broadcast functions:
- broadcastTaskChange()
- broadcastChatMessage()
- broadcastSquadMessage()
- broadcastTelemetryEvent()
- broadcastNewMessage()
- broadcastWorkflowStatus()
Performance impact:
- Prevents main thread blocking with 100+ clients
- No impact on latency for typical deployments (<50 clients)
- Maintains message ordering within each client
Risk: Low - backward compatible, fallback to sync for small counts
Co-authored-by: BradGroux <super.seth.vos@gmail.com>
2026-03-01 13:56:09 -06:00
Brad Groux
319465c171
fix(security): Add SSRF protection for webhook URLs ( #165 )
...
* fix(stability): complete Zod 4 API migration
BREAKING CHANGE: Migrated from Zod 3 to Zod 4 API patterns
Changes:
- Replace ZodError.errors with ZodError.issues (Zod 4 API)
- Update z.record(valueSchema) to z.record(z.string(), valueSchema)
- Fix env.ts schema defaults to use correct types (numbers/booleans)
- Replace required_error with message in Zod schemas
This resolves 50+ TypeScript compilation errors that were blocking
CI/CD and potentially causing runtime issues.
Fixes: type checking errors in server and web packages
Risk: Low - straightforward API migration with full test coverage
* fix(zod4): use string defaults for transform/pipe schemas
Zod v4 changed .default() to require the input type (string) rather
than the output type. Fixed PORT, VERITAS_AUTH_ENABLED,
VERITAS_AUTH_LOCALHOST_BYPASS, CSP_REPORT_ONLY, and RATE_LIMIT_MAX
to pass string defaults to their respective portSchema / booleanString
/ positiveIntString coercing schemas.
* fix(security): add SSRF protection for webhook URLs
Add URL validation to prevent Server-Side Request Forgery (SSRF) attacks
via configured webhook endpoints.
Security improvements:
- New validateWebhookUrl() utility in utils/url-validation.ts
- Blocks private IP ranges (RFC 1918: 10.x, 172.16.x, 192.168.x)
- Blocks loopback addresses (127.0.0.0/8, ::1)
- Blocks link-local addresses (169.254.x.x, fe80::/10)
- Blocks cloud metadata endpoints (169.254.169.254)
- Enforces HTTPS in production (allows HTTP in dev)
- Logs blocked requests for security monitoring
Applied to all webhook services:
- clawdbot-webhook-service.ts
- hook-service.ts
- squad-webhook-service.ts
- transition-hooks-service.ts
Risk: Low - additive validation layer, graceful fallback
CVSS: 6.5 (Medium-High) - SSRF mitigation
Refs: vk-full-audit-2026-03-01
---------
Co-authored-by: BradGroux <super.seth.vos@gmail.com>
2026-03-01 13:54:32 -06:00
Brad Groux
112da181c8
fix(stability): Complete Zod 4 API migration ( #162 )
...
* fix(stability): complete Zod 4 API migration
BREAKING CHANGE: Migrated from Zod 3 to Zod 4 API patterns
Changes:
- Replace ZodError.errors with ZodError.issues (Zod 4 API)
- Update z.record(valueSchema) to z.record(z.string(), valueSchema)
- Fix env.ts schema defaults to use correct types (numbers/booleans)
- Replace required_error with message in Zod schemas
This resolves 50+ TypeScript compilation errors that were blocking
CI/CD and potentially causing runtime issues.
Fixes: type checking errors in server and web packages
Risk: Low - straightforward API migration with full test coverage
* fix(zod4): use string defaults for transform/pipe schemas
Zod v4 changed .default() to require the input type (string) rather
than the output type. Fixed PORT, VERITAS_AUTH_ENABLED,
VERITAS_AUTH_LOCALHOST_BYPASS, CSP_REPORT_ONLY, and RATE_LIMIT_MAX
to pass string defaults to their respective portSchema / booleanString
/ positiveIntString coercing schemas.
---------
Co-authored-by: BradGroux <super.seth.vos@gmail.com>
2026-03-01 13:52:49 -06:00
BradGroux
bd46ffb31a
chore(release): v3.3.2
...
- Bump all package versions to 3.3.2
- Update CHANGELOG with #155 (task↔agent sync), #156 (circuit breaker tests), #159 (sync auth hardening), #161 (sprint CLI+MCP)
- Update README version badge to 3.3.2
2026-03-01 13:08:51 -06:00
Brad Groux
daee651c7f
fix(security): harden task-agent sync auth boundary ( #157 #158 ) ( #159 )
...
Fixes #157 and #158 . Tests updated to use createTaskSyncToken() factory.
2026-03-01 12:26:27 -06:00
supersethvos
8c4eb42d76
feat(sync): task↔agent state sync + reconciliation ( #155 )
...
* feat(sync): implement task↔agent state sync with reconciliation and flap guard
* fix(sync): add sync auth context, ref validation, and reconcile bounds
---------
Co-authored-by: SETH VOS <sethai@SETHs-Mac-mini.lan>
2026-03-01 12:05:23 -06:00
Brad Groux
2dfdaa486c
test: add circuit breaker test suite (18 tests) ( #156 )
...
Covers all state transitions: closed → open → half-open → closed,
failure threshold, sliding monitor window eviction, concurrent
half-open rejection, manual reset, and getStatus() output.
No production code changed.
Co-authored-by: Brad Groux <bradgroux@Brads-Mac-mini.local>
2026-03-01 11:43:57 -06:00
Brad Groux
0d7dfb135c
chore: release v3.3.1
2026-02-28 09:57:48 -06:00
dependabot[bot]
12478768cc
chore: bump the production-dependencies group across 1 directory with 8 updates ( #154 )
...
Bumps the production-dependencies group with 8 updates in the / directory:
| Package | From | To |
| --- | --- | --- |
| [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node ) | `25.3.0` | `25.3.2` |
| [@typescript-eslint/eslint-plugin](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/eslint-plugin ) | `8.56.0` | `8.56.1` |
| [@typescript-eslint/parser](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/parser ) | `8.56.0` | `8.56.1` |
| [lint-staged](https://github.com/lint-staged/lint-staged ) | `16.2.7` | `16.3.0` |
| [multer](https://github.com/expressjs/multer ) | `2.0.2` | `2.1.0` |
| [simple-git](https://github.com/steveukx/git-js/tree/HEAD/simple-git ) | `3.32.1` | `3.32.3` |
| [autoprefixer](https://github.com/postcss/autoprefixer ) | `10.4.24` | `10.4.27` |
| [@modelcontextprotocol/sdk](https://github.com/modelcontextprotocol/typescript-sdk ) | `1.26.0` | `1.27.1` |
Updates `@types/node` from 25.3.0 to 25.3.2
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases )
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node )
Updates `@typescript-eslint/eslint-plugin` from 8.56.0 to 8.56.1
- [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases )
- [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/eslint-plugin/CHANGELOG.md )
- [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.56.1/packages/eslint-plugin )
Updates `@typescript-eslint/parser` from 8.56.0 to 8.56.1
- [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases )
- [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/parser/CHANGELOG.md )
- [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.56.1/packages/parser )
Updates `lint-staged` from 16.2.7 to 16.3.0
- [Release notes](https://github.com/lint-staged/lint-staged/releases )
- [Changelog](https://github.com/lint-staged/lint-staged/blob/main/CHANGELOG.md )
- [Commits](https://github.com/lint-staged/lint-staged/compare/v16.2.7...v16.3.0 )
Updates `multer` from 2.0.2 to 2.1.0
- [Release notes](https://github.com/expressjs/multer/releases )
- [Changelog](https://github.com/expressjs/multer/blob/main/CHANGELOG.md )
- [Commits](https://github.com/expressjs/multer/compare/v2.0.2...v2.1.0 )
Updates `simple-git` from 3.32.1 to 3.32.3
- [Release notes](https://github.com/steveukx/git-js/releases )
- [Changelog](https://github.com/steveukx/git-js/blob/main/simple-git/CHANGELOG.md )
- [Commits](https://github.com/steveukx/git-js/commits/simple-git@3.32.3/simple-git )
Updates `autoprefixer` from 10.4.24 to 10.4.27
- [Release notes](https://github.com/postcss/autoprefixer/releases )
- [Changelog](https://github.com/postcss/autoprefixer/blob/main/CHANGELOG.md )
- [Commits](https://github.com/postcss/autoprefixer/compare/10.4.24...10.4.27 )
Updates `@modelcontextprotocol/sdk` from 1.26.0 to 1.27.1
- [Release notes](https://github.com/modelcontextprotocol/typescript-sdk/releases )
- [Commits](https://github.com/modelcontextprotocol/typescript-sdk/compare/v1.26.0...v1.27.1 )
---
updated-dependencies:
- dependency-name: "@types/node"
dependency-version: 25.3.2
dependency-type: direct:development
update-type: version-update:semver-patch
dependency-group: production-dependencies
- dependency-name: "@typescript-eslint/eslint-plugin"
dependency-version: 8.56.1
dependency-type: direct:development
update-type: version-update:semver-patch
dependency-group: production-dependencies
- dependency-name: "@typescript-eslint/parser"
dependency-version: 8.56.1
dependency-type: direct:development
update-type: version-update:semver-patch
dependency-group: production-dependencies
- dependency-name: lint-staged
dependency-version: 16.3.0
dependency-type: direct:development
update-type: version-update:semver-minor
dependency-group: production-dependencies
- dependency-name: multer
dependency-version: 2.1.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: production-dependencies
- dependency-name: simple-git
dependency-version: 3.32.3
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: production-dependencies
- dependency-name: autoprefixer
dependency-version: 10.4.27
dependency-type: direct:development
update-type: version-update:semver-patch
dependency-group: production-dependencies
- dependency-name: "@modelcontextprotocol/sdk"
dependency-version: 1.27.1
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: production-dependencies
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-02-28 09:50:16 -06:00
Brad Groux
522d24c748
fix: update wildcard routes for Express 5 / path-to-regexp v8 ( #153 )
...
Express 5 uses path-to-regexp v8+ which requires named wildcards.
Bare '*' patterns are no longer valid.
Fixes #150
Co-authored-by: Brad Groux <bradgroux@Brads-Mac-mini.local>
2026-02-28 08:44:20 -06:00
Brad Groux
99f7fbdcc4
Revert "feat(security): add API key authentication for external requests"
...
This reverts commit 6b052e6b8d .
2026-02-22 11:26:44 -06:00
Brad Groux
6b052e6b8d
feat(security): add API key authentication for external requests
...
- New middleware: external-api-key.ts
- Requires X-API-Key header for non-localhost requests
- Protects tunnel endpoint (vk-api.ops.digitalmeld.cloud)
- Localhost requests bypass key check for dev convenience
- Key stored in 1Password and VK_API_KEY env var
2026-02-22 11:23:05 -06:00
V.K. Watson
50dfff84ef
revert: restore port 3001 across codebase, keep Express 5 path fix
...
Reverts port change from 1b7a9fe . OpenClaw gateway will move off 3001 instead.
2026-02-20 21:12:49 -06:00
V.K. Watson
1b7a9feb03
fix: update default API port from 3001 to 3002 across codebase
...
Avoids conflict with OpenClaw gateway on port 3001.
Updated: server config, docs, README, WebSocket hook.
2026-02-20 21:11:40 -06:00
V.K. Watson
095a181b5f
fix: Express 5 path-to-regexp compatibility + move API to port 3002
...
- /file/* → /file/*path (Express 5 named wildcard syntax)
- req.params[0] → req.params.path (Express 5 param access)
- PORT 3001 → 3002 (avoid OpenClaw gateway conflict on localhost)
2026-02-20 21:10:31 -06:00
dependabot[bot]
90c7014558
chore: bump express to 5.2.1 (dependabot #140 )
...
Bumps [express](https://github.com/expressjs/express ) from 4.22.1 to 5.2.1.
- [Release notes](https://github.com/expressjs/express/releases )
- [Changelog](https://github.com/expressjs/express/blob/master/History.md )
- [Commits](https://github.com/expressjs/express/compare/v4.22.1...v5.2.1 )
---
updated-dependencies:
- dependency-name: express
dependency-version: 5.2.1
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-02-20 02:05:21 -06:00
dependabot[bot]
707039a171
chore: update production deps (dependabot #134 )
...
Bumps the production-dependencies group with 15 updates:
| Package | From | To |
| --- | --- | --- |
| [@playwright/test](https://github.com/microsoft/playwright ) | `1.58.0` | `1.58.2` |
| [@typescript-eslint/eslint-plugin](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/eslint-plugin ) | `8.54.0` | `8.56.0` |
| [@typescript-eslint/parser](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/parser ) | `8.54.0` | `8.56.0` |
| [ajv](https://github.com/ajv-validator/ajv ) | `8.17.1` | `8.18.0` |
| [dotenv](https://github.com/motdotla/dotenv ) | `17.2.3` | `17.3.1` |
| [pino](https://github.com/pinojs/pino ) | `10.3.0` | `10.3.1` |
| [sanitize-html](https://github.com/apostrophecms/apostrophe/tree/HEAD/packages/sanitize-html ) | `2.17.0` | `2.17.1` |
| [simple-git](https://github.com/steveukx/git-js/tree/HEAD/simple-git ) | `3.30.0` | `3.31.1` |
| [@tanstack/react-query](https://github.com/TanStack/query/tree/HEAD/packages/react-query ) | `5.90.20` | `5.90.21` |
| [lucide-react](https://github.com/lucide-icons/lucide/tree/HEAD/packages/lucide-react ) | `0.468.0` | `0.575.0` |
| [react](https://github.com/facebook/react/tree/HEAD/packages/react ) | `19.2.3` | `19.2.4` |
| [@types/react](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/react ) | `19.2.9` | `19.2.14` |
| [react-dom](https://github.com/facebook/react/tree/HEAD/packages/react-dom ) | `19.2.3` | `19.2.4` |
| [autoprefixer](https://github.com/postcss/autoprefixer ) | `10.4.23` | `10.4.24` |
| [hono](https://github.com/honojs/hono ) | `4.11.7` | `4.12.0` |
Updates `@playwright/test` from 1.58.0 to 1.58.2
- [Release notes](https://github.com/microsoft/playwright/releases )
- [Commits](https://github.com/microsoft/playwright/compare/v1.58.0...v1.58.2 )
Updates `@typescript-eslint/eslint-plugin` from 8.54.0 to 8.56.0
- [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases )
- [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/eslint-plugin/CHANGELOG.md )
- [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.56.0/packages/eslint-plugin )
Updates `@typescript-eslint/parser` from 8.54.0 to 8.56.0
- [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases )
- [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/parser/CHANGELOG.md )
- [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.56.0/packages/parser )
Updates `ajv` from 8.17.1 to 8.18.0
- [Release notes](https://github.com/ajv-validator/ajv/releases )
- [Commits](https://github.com/ajv-validator/ajv/compare/v8.17.1...v8.18.0 )
Updates `dotenv` from 17.2.3 to 17.3.1
- [Changelog](https://github.com/motdotla/dotenv/blob/master/CHANGELOG.md )
- [Commits](https://github.com/motdotla/dotenv/compare/v17.2.3...v17.3.1 )
Updates `pino` from 10.3.0 to 10.3.1
- [Release notes](https://github.com/pinojs/pino/releases )
- [Commits](https://github.com/pinojs/pino/compare/v10.3.0...v10.3.1 )
Updates `sanitize-html` from 2.17.0 to 2.17.1
- [Changelog](https://github.com/apostrophecms/apostrophe/blob/main/packages/sanitize-html/CHANGELOG.md )
- [Commits](https://github.com/apostrophecms/apostrophe/commits/2.17.1/packages/sanitize-html )
Updates `simple-git` from 3.30.0 to 3.31.1
- [Release notes](https://github.com/steveukx/git-js/releases )
- [Changelog](https://github.com/steveukx/git-js/blob/main/simple-git/CHANGELOG.md )
- [Commits](https://github.com/steveukx/git-js/commits/simple-git@3.31.1/simple-git )
Updates `@tanstack/react-query` from 5.90.20 to 5.90.21
- [Release notes](https://github.com/TanStack/query/releases )
- [Changelog](https://github.com/TanStack/query/blob/main/packages/react-query/CHANGELOG.md )
- [Commits](https://github.com/TanStack/query/commits/@tanstack/react-query@5.90.21/packages/react-query )
Updates `lucide-react` from 0.468.0 to 0.575.0
- [Release notes](https://github.com/lucide-icons/lucide/releases )
- [Commits](https://github.com/lucide-icons/lucide/commits/0.575.0/packages/lucide-react )
Updates `react` from 19.2.3 to 19.2.4
- [Release notes](https://github.com/facebook/react/releases )
- [Changelog](https://github.com/facebook/react/blob/main/CHANGELOG.md )
- [Commits](https://github.com/facebook/react/commits/v19.2.4/packages/react )
Updates `@types/react` from 19.2.9 to 19.2.14
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases )
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/react )
Updates `react-dom` from 19.2.3 to 19.2.4
- [Release notes](https://github.com/facebook/react/releases )
- [Changelog](https://github.com/facebook/react/blob/main/CHANGELOG.md )
- [Commits](https://github.com/facebook/react/commits/v19.2.4/packages/react-dom )
Updates `@types/react` from 19.2.9 to 19.2.14
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases )
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/react )
Updates `autoprefixer` from 10.4.23 to 10.4.24
- [Release notes](https://github.com/postcss/autoprefixer/releases )
- [Changelog](https://github.com/postcss/autoprefixer/blob/main/CHANGELOG.md )
- [Commits](https://github.com/postcss/autoprefixer/compare/10.4.23...10.4.24 )
Updates `hono` from 4.11.7 to 4.12.0
- [Release notes](https://github.com/honojs/hono/releases )
- [Commits](https://github.com/honojs/hono/compare/v4.11.7...v4.12.0 )
---
updated-dependencies:
- dependency-name: "@playwright/test"
dependency-version: 1.58.2
dependency-type: direct:development
update-type: version-update:semver-patch
dependency-group: production-dependencies
- dependency-name: "@typescript-eslint/eslint-plugin"
dependency-version: 8.56.0
dependency-type: direct:development
update-type: version-update:semver-minor
dependency-group: production-dependencies
- dependency-name: "@typescript-eslint/parser"
dependency-version: 8.56.0
dependency-type: direct:development
update-type: version-update:semver-minor
dependency-group: production-dependencies
- dependency-name: ajv
dependency-version: 8.18.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: production-dependencies
- dependency-name: dotenv
dependency-version: 17.3.1
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: production-dependencies
- dependency-name: pino
dependency-version: 10.3.1
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: production-dependencies
- dependency-name: sanitize-html
dependency-version: 2.17.1
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: production-dependencies
- dependency-name: simple-git
dependency-version: 3.31.1
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: production-dependencies
- dependency-name: "@tanstack/react-query"
dependency-version: 5.90.21
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: production-dependencies
- dependency-name: lucide-react
dependency-version: 0.575.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: production-dependencies
- dependency-name: react
dependency-version: 19.2.4
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: production-dependencies
- dependency-name: "@types/react"
dependency-version: 19.2.14
dependency-type: direct:development
update-type: version-update:semver-patch
dependency-group: production-dependencies
- dependency-name: react-dom
dependency-version: 19.2.4
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: production-dependencies
- dependency-name: "@types/react"
dependency-version: 19.2.14
dependency-type: direct:development
update-type: version-update:semver-patch
dependency-group: production-dependencies
- dependency-name: autoprefixer
dependency-version: 10.4.24
dependency-type: direct:development
update-type: version-update:semver-patch
dependency-group: production-dependencies
- dependency-name: hono
dependency-version: 4.12.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: production-dependencies
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-02-20 01:55:18 -06:00
V.K. Watson
9657e731b6
fix: guard updatedTask null check in task routes
...
also clean up observations section build warning
2026-02-20 01:51:45 -06:00