Brad Groux
11e94aef4e
feat: run codex workflow steps ( #316 )
2026-05-05 22:01:05 -05:00
Brad Groux
7bf8df6666
feat: add codex cloud delegation ( #315 )
2026-05-05 21:53:47 -05:00
Brad Groux
42fb759cca
feat: add codex sdk sessions ( #314 )
2026-05-05 21:44:29 -05:00
Brad Groux
bd6c1744e1
feat: add codex cli agent execution
...
Adds built-in Codex agent configuration and local codex exec support through the Veritas agent lifecycle.
2026-05-05 21:20:27 -05:00
Brad Groux
0df2b02781
chore: bump release version to 4.2.0
...
Aligns workspace package versions and README badge with the v4.2 release track.
2026-05-05 21:03:50 -05:00
Brad Groux
3f45965fd9
chore: bump version to 4.1.0
2026-05-04 03:19:18 -05:00
Brad Groux
ef9e88ca1d
feat: add qmd index maintenance
2026-05-04 03:10:16 -05:00
Brad Groux
a211b484ba
feat: inject veritas retrieval context
2026-05-04 03:03:36 -05:00
Brad Groux
f0f7d7b03e
feat: add qmd search foundation
2026-05-04 02:35:00 -05:00
Brad Groux
31f4baba56
test: stabilize delegation history cap coverage
2026-05-04 02:06:17 -05:00
dependabot[bot]
53746191b3
chore: bump the production-dependencies group across 1 directory with 19 updates
...
Bumps the production-dependencies group with 19 updates in the / directory:
| Package | From | To |
| --- | --- | --- |
| [@typescript-eslint/eslint-plugin](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/eslint-plugin ) | `8.58.2` | `8.59.1` |
| [@typescript-eslint/parser](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/parser ) | `8.58.2` | `8.59.1` |
| [eslint-plugin-react-hooks](https://github.com/facebook/react/tree/HEAD/packages/eslint-plugin-react-hooks ) | `7.0.1` | `7.1.1` |
| [typescript](https://github.com/microsoft/TypeScript ) | `6.0.2` | `6.0.3` |
| [vitest](https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest ) | `4.1.4` | `4.1.5` |
| [ajv](https://github.com/ajv-validator/ajv ) | `8.18.0` | `8.20.0` |
| [express-rate-limit](https://github.com/express-rate-limit/express-rate-limit ) | `8.3.2` | `8.4.1` |
| [nanoid](https://github.com/ai/nanoid ) | `5.1.7` | `5.1.11` |
| [unpdf](https://github.com/unjs/unpdf ) | `1.6.0` | `1.6.2` |
| [yaml](https://github.com/eemeli/yaml ) | `2.8.3` | `2.8.4` |
| [@vitest/coverage-v8](https://github.com/vitest-dev/vitest/tree/HEAD/packages/coverage-v8 ) | `4.1.4` | `4.1.5` |
| [@tanstack/react-query](https://github.com/TanStack/query/tree/HEAD/packages/react-query ) | `5.99.0` | `5.100.9` |
| [dompurify](https://github.com/cure53/DOMPurify ) | `3.4.0` | `3.4.2` |
| [lucide-react](https://github.com/lucide-icons/lucide/tree/HEAD/packages/lucide-react ) | `1.8.0` | `1.14.0` |
| [shadcn](https://github.com/shadcn-ui/ui/tree/HEAD/packages/shadcn ) | `4.2.0` | `4.6.0` |
| [@tailwindcss/vite](https://github.com/tailwindlabs/tailwindcss/tree/HEAD/packages/@tailwindcss-vite ) | `4.2.2` | `4.2.4` |
| [jsdom](https://github.com/jsdom/jsdom ) | `29.0.2` | `29.1.1` |
| [tailwindcss](https://github.com/tailwindlabs/tailwindcss/tree/HEAD/packages/tailwindcss ) | `4.2.2` | `4.2.4` |
| [vite](https://github.com/vitejs/vite/tree/HEAD/packages/vite ) | `8.0.8` | `8.0.10` |
Updates `@typescript-eslint/eslint-plugin` from 8.58.2 to 8.59.1
- [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases )
- [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/eslint-plugin/CHANGELOG.md )
- [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.59.1/packages/eslint-plugin )
Updates `@typescript-eslint/parser` from 8.58.2 to 8.59.1
- [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases )
- [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/parser/CHANGELOG.md )
- [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.59.1/packages/parser )
Updates `eslint-plugin-react-hooks` from 7.0.1 to 7.1.1
- [Release notes](https://github.com/facebook/react/releases )
- [Changelog](https://github.com/facebook/react/blob/main/packages/eslint-plugin-react-hooks/CHANGELOG.md )
- [Commits](https://github.com/facebook/react/commits/eslint-plugin-react-hooks@7.1.1/packages/eslint-plugin-react-hooks )
Updates `typescript` from 6.0.2 to 6.0.3
- [Release notes](https://github.com/microsoft/TypeScript/releases )
- [Commits](https://github.com/microsoft/TypeScript/compare/v6.0.2...v6.0.3 )
Updates `vitest` from 4.1.4 to 4.1.5
- [Release notes](https://github.com/vitest-dev/vitest/releases )
- [Commits](https://github.com/vitest-dev/vitest/commits/v4.1.5/packages/vitest )
Updates `ajv` from 8.18.0 to 8.20.0
- [Release notes](https://github.com/ajv-validator/ajv/releases )
- [Commits](https://github.com/ajv-validator/ajv/compare/v8.18.0...v8.20.0 )
Updates `express-rate-limit` from 8.3.2 to 8.4.1
- [Release notes](https://github.com/express-rate-limit/express-rate-limit/releases )
- [Commits](https://github.com/express-rate-limit/express-rate-limit/compare/v8.3.2...v8.4.1 )
Updates `nanoid` from 5.1.7 to 5.1.11
- [Release notes](https://github.com/ai/nanoid/releases )
- [Changelog](https://github.com/ai/nanoid/blob/main/CHANGELOG.md )
- [Commits](https://github.com/ai/nanoid/compare/5.1.7...5.1.11 )
Updates `unpdf` from 1.6.0 to 1.6.2
- [Release notes](https://github.com/unjs/unpdf/releases )
- [Commits](https://github.com/unjs/unpdf/compare/v1.6.0...v1.6.2 )
Updates `yaml` from 2.8.3 to 2.8.4
- [Release notes](https://github.com/eemeli/yaml/releases )
- [Commits](https://github.com/eemeli/yaml/compare/v2.8.3...v2.8.4 )
Updates `@vitest/coverage-v8` from 4.1.4 to 4.1.5
- [Release notes](https://github.com/vitest-dev/vitest/releases )
- [Commits](https://github.com/vitest-dev/vitest/commits/v4.1.5/packages/coverage-v8 )
Updates `@tanstack/react-query` from 5.99.0 to 5.100.9
- [Release notes](https://github.com/TanStack/query/releases )
- [Changelog](https://github.com/TanStack/query/blob/main/packages/react-query/CHANGELOG.md )
- [Commits](https://github.com/TanStack/query/commits/@tanstack/react-query@5.100.9/packages/react-query )
Updates `dompurify` from 3.4.0 to 3.4.2
- [Release notes](https://github.com/cure53/DOMPurify/releases )
- [Commits](https://github.com/cure53/DOMPurify/compare/3.4.0...3.4.2 )
Updates `lucide-react` from 1.8.0 to 1.14.0
- [Release notes](https://github.com/lucide-icons/lucide/releases )
- [Commits](https://github.com/lucide-icons/lucide/commits/1.14.0/packages/lucide-react )
Updates `shadcn` from 4.2.0 to 4.6.0
- [Release notes](https://github.com/shadcn-ui/ui/releases )
- [Changelog](https://github.com/shadcn-ui/ui/blob/main/packages/shadcn/CHANGELOG.md )
- [Commits](https://github.com/shadcn-ui/ui/commits/shadcn@4.6.0/packages/shadcn )
Updates `@tailwindcss/vite` from 4.2.2 to 4.2.4
- [Release notes](https://github.com/tailwindlabs/tailwindcss/releases )
- [Changelog](https://github.com/tailwindlabs/tailwindcss/blob/main/CHANGELOG.md )
- [Commits](https://github.com/tailwindlabs/tailwindcss/commits/v4.2.4/packages/@tailwindcss-vite )
Updates `jsdom` from 29.0.2 to 29.1.1
- [Release notes](https://github.com/jsdom/jsdom/releases )
- [Commits](https://github.com/jsdom/jsdom/compare/v29.0.2...v29.1.1 )
Updates `tailwindcss` from 4.2.2 to 4.2.4
- [Release notes](https://github.com/tailwindlabs/tailwindcss/releases )
- [Changelog](https://github.com/tailwindlabs/tailwindcss/blob/main/CHANGELOG.md )
- [Commits](https://github.com/tailwindlabs/tailwindcss/commits/v4.2.4/packages/tailwindcss )
Updates `vite` from 8.0.8 to 8.0.10
- [Release notes](https://github.com/vitejs/vite/releases )
- [Changelog](https://github.com/vitejs/vite/blob/main/packages/vite/CHANGELOG.md )
- [Commits](https://github.com/vitejs/vite/commits/v8.0.10/packages/vite )
---
updated-dependencies:
- dependency-name: "@typescript-eslint/eslint-plugin"
dependency-version: 8.59.1
dependency-type: direct:development
update-type: version-update:semver-minor
dependency-group: production-dependencies
- dependency-name: "@typescript-eslint/parser"
dependency-version: 8.59.1
dependency-type: direct:development
update-type: version-update:semver-minor
dependency-group: production-dependencies
- dependency-name: eslint-plugin-react-hooks
dependency-version: 7.1.1
dependency-type: direct:development
update-type: version-update:semver-minor
dependency-group: production-dependencies
- dependency-name: typescript
dependency-version: 6.0.3
dependency-type: direct:development
update-type: version-update:semver-patch
dependency-group: production-dependencies
- dependency-name: vitest
dependency-version: 4.1.5
dependency-type: direct:development
update-type: version-update:semver-patch
dependency-group: production-dependencies
- dependency-name: ajv
dependency-version: 8.20.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: production-dependencies
- dependency-name: express-rate-limit
dependency-version: 8.4.1
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: production-dependencies
- dependency-name: nanoid
dependency-version: 5.1.11
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: production-dependencies
- dependency-name: unpdf
dependency-version: 1.6.2
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: production-dependencies
- dependency-name: yaml
dependency-version: 2.8.4
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: production-dependencies
- dependency-name: "@vitest/coverage-v8"
dependency-version: 4.1.5
dependency-type: direct:development
update-type: version-update:semver-patch
dependency-group: production-dependencies
- dependency-name: "@tanstack/react-query"
dependency-version: 5.100.9
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: production-dependencies
- dependency-name: dompurify
dependency-version: 3.4.2
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: production-dependencies
- dependency-name: lucide-react
dependency-version: 1.14.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: production-dependencies
- dependency-name: shadcn
dependency-version: 4.6.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: production-dependencies
- dependency-name: "@tailwindcss/vite"
dependency-version: 4.2.4
dependency-type: direct:development
update-type: version-update:semver-patch
dependency-group: production-dependencies
- dependency-name: jsdom
dependency-version: 29.1.1
dependency-type: direct:development
update-type: version-update:semver-minor
dependency-group: production-dependencies
- dependency-name: tailwindcss
dependency-version: 4.2.4
dependency-type: direct:development
update-type: version-update:semver-patch
dependency-group: production-dependencies
- dependency-name: vite
dependency-version: 8.0.10
dependency-type: direct:development
update-type: version-update:semver-patch
dependency-group: production-dependencies
...
Signed-off-by: dependabot[bot] <support@github.com>
2026-05-04 04:00:13 +00:00
Brad Groux
55d98a6017
fix task popout spacing and harden webhook
CI / Lint & Type Check (push) Waiting to run
CI / Workspace Unit Tests (push) Waiting to run
CI / Build (push) Waiting to run
CI / Security Audit (push) Waiting to run
2026-05-03 22:40:24 -05:00
dependabot[bot]
acaf875d2d
chore: bump typescript from 5.9.3 to 6.0.2
...
Bumps [typescript](https://github.com/microsoft/TypeScript ) from 5.9.3 to 6.0.2.
- [Release notes](https://github.com/microsoft/TypeScript/releases )
- [Commits](https://github.com/microsoft/TypeScript/compare/v5.9.3...v6.0.2 )
---
updated-dependencies:
- dependency-name: typescript
dependency-version: 6.0.2
dependency-type: direct:development
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com>
2026-04-14 22:16:50 -05:00
dependabot[bot]
ef60d621cd
chore: bump the production-dependencies group with 21 updates
...
Bumps the production-dependencies group with 21 updates:
| Package | From | To |
| --- | --- | --- |
| [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node ) | `25.5.2` | `25.6.0` |
| [@typescript-eslint/eslint-plugin](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/eslint-plugin ) | `8.58.0` | `8.58.2` |
| [@typescript-eslint/parser](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/parser ) | `8.58.0` | `8.58.2` |
| [prettier](https://github.com/prettier/prettier ) | `3.8.1` | `3.8.2` |
| [vitest](https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest ) | `4.1.2` | `4.1.4` |
| [content-disposition](https://github.com/jshttp/content-disposition ) | `1.0.1` | `1.1.0` |
| [dotenv](https://github.com/motdotla/dotenv ) | `17.4.1` | `17.4.2` |
| [file-type](https://github.com/sindresorhus/file-type ) | `22.0.0` | `22.0.1` |
| [simple-git](https://github.com/steveukx/git-js/tree/HEAD/simple-git ) | `3.35.2` | `3.36.0` |
| [unpdf](https://github.com/unjs/unpdf ) | `1.4.0` | `1.6.0` |
| [@vitest/coverage-v8](https://github.com/vitest-dev/vitest/tree/HEAD/packages/coverage-v8 ) | `4.1.2` | `4.1.4` |
| [@tanstack/react-query](https://github.com/TanStack/query/tree/HEAD/packages/react-query ) | `5.96.2` | `5.99.0` |
| [lucide-react](https://github.com/lucide-icons/lucide/tree/HEAD/packages/lucide-react ) | `1.7.0` | `1.8.0` |
| [react](https://github.com/facebook/react/tree/HEAD/packages/react ) | `19.2.4` | `19.2.5` |
| [react-dom](https://github.com/facebook/react/tree/HEAD/packages/react-dom ) | `19.2.4` | `19.2.5` |
| [shadcn](https://github.com/shadcn-ui/ui/tree/HEAD/packages/shadcn ) | `4.1.2` | `4.2.0` |
| [autoprefixer](https://github.com/postcss/autoprefixer ) | `10.4.27` | `10.5.0` |
| [jsdom](https://github.com/jsdom/jsdom ) | `29.0.1` | `29.0.2` |
| [postcss](https://github.com/postcss/postcss ) | `8.5.8` | `8.5.9` |
| [vite](https://github.com/vitejs/vite/tree/HEAD/packages/vite ) | `8.0.5` | `8.0.8` |
| [hono](https://github.com/honojs/hono ) | `4.12.11` | `4.12.12` |
Updates `@types/node` from 25.5.2 to 25.6.0
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases )
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node )
Updates `@typescript-eslint/eslint-plugin` from 8.58.0 to 8.58.2
- [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases )
- [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/eslint-plugin/CHANGELOG.md )
- [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.58.2/packages/eslint-plugin )
Updates `@typescript-eslint/parser` from 8.58.0 to 8.58.2
- [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases )
- [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/parser/CHANGELOG.md )
- [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.58.2/packages/parser )
Updates `prettier` from 3.8.1 to 3.8.2
- [Release notes](https://github.com/prettier/prettier/releases )
- [Changelog](https://github.com/prettier/prettier/blob/main/CHANGELOG.md )
- [Commits](https://github.com/prettier/prettier/compare/3.8.1...3.8.2 )
Updates `vitest` from 4.1.2 to 4.1.4
- [Release notes](https://github.com/vitest-dev/vitest/releases )
- [Commits](https://github.com/vitest-dev/vitest/commits/v4.1.4/packages/vitest )
Updates `content-disposition` from 1.0.1 to 1.1.0
- [Release notes](https://github.com/jshttp/content-disposition/releases )
- [Commits](https://github.com/jshttp/content-disposition/compare/v1.0.1...v1.1.0 )
Updates `dotenv` from 17.4.1 to 17.4.2
- [Changelog](https://github.com/motdotla/dotenv/blob/master/CHANGELOG.md )
- [Commits](https://github.com/motdotla/dotenv/compare/v17.4.1...v17.4.2 )
Updates `file-type` from 22.0.0 to 22.0.1
- [Release notes](https://github.com/sindresorhus/file-type/releases )
- [Commits](https://github.com/sindresorhus/file-type/compare/v22.0.0...v22.0.1 )
Updates `simple-git` from 3.35.2 to 3.36.0
- [Release notes](https://github.com/steveukx/git-js/releases )
- [Changelog](https://github.com/steveukx/git-js/blob/main/simple-git/CHANGELOG.md )
- [Commits](https://github.com/steveukx/git-js/commits/simple-git@3.36.0/simple-git )
Updates `unpdf` from 1.4.0 to 1.6.0
- [Release notes](https://github.com/unjs/unpdf/releases )
- [Commits](https://github.com/unjs/unpdf/compare/v1.4.0...v1.6.0 )
Updates `@vitest/coverage-v8` from 4.1.2 to 4.1.4
- [Release notes](https://github.com/vitest-dev/vitest/releases )
- [Commits](https://github.com/vitest-dev/vitest/commits/v4.1.4/packages/coverage-v8 )
Updates `@tanstack/react-query` from 5.96.2 to 5.99.0
- [Release notes](https://github.com/TanStack/query/releases )
- [Changelog](https://github.com/TanStack/query/blob/main/packages/react-query/CHANGELOG.md )
- [Commits](https://github.com/TanStack/query/commits/@tanstack/react-query@5.99.0/packages/react-query )
Updates `lucide-react` from 1.7.0 to 1.8.0
- [Release notes](https://github.com/lucide-icons/lucide/releases )
- [Commits](https://github.com/lucide-icons/lucide/commits/1.8.0/packages/lucide-react )
Updates `react` from 19.2.4 to 19.2.5
- [Release notes](https://github.com/facebook/react/releases )
- [Changelog](https://github.com/facebook/react/blob/main/CHANGELOG.md )
- [Commits](https://github.com/facebook/react/commits/v19.2.5/packages/react )
Updates `react-dom` from 19.2.4 to 19.2.5
- [Release notes](https://github.com/facebook/react/releases )
- [Changelog](https://github.com/facebook/react/blob/main/CHANGELOG.md )
- [Commits](https://github.com/facebook/react/commits/v19.2.5/packages/react-dom )
Updates `shadcn` from 4.1.2 to 4.2.0
- [Release notes](https://github.com/shadcn-ui/ui/releases )
- [Changelog](https://github.com/shadcn-ui/ui/blob/main/packages/shadcn/CHANGELOG.md )
- [Commits](https://github.com/shadcn-ui/ui/commits/shadcn@4.2.0/packages/shadcn )
Updates `autoprefixer` from 10.4.27 to 10.5.0
- [Release notes](https://github.com/postcss/autoprefixer/releases )
- [Changelog](https://github.com/postcss/autoprefixer/blob/main/CHANGELOG.md )
- [Commits](https://github.com/postcss/autoprefixer/compare/10.4.27...10.5.0 )
Updates `jsdom` from 29.0.1 to 29.0.2
- [Release notes](https://github.com/jsdom/jsdom/releases )
- [Commits](https://github.com/jsdom/jsdom/compare/v29.0.1...v29.0.2 )
Updates `postcss` from 8.5.8 to 8.5.9
- [Release notes](https://github.com/postcss/postcss/releases )
- [Changelog](https://github.com/postcss/postcss/blob/main/CHANGELOG.md )
- [Commits](https://github.com/postcss/postcss/compare/8.5.8...8.5.9 )
Updates `vite` from 8.0.5 to 8.0.8
- [Release notes](https://github.com/vitejs/vite/releases )
- [Changelog](https://github.com/vitejs/vite/blob/main/packages/vite/CHANGELOG.md )
- [Commits](https://github.com/vitejs/vite/commits/v8.0.8/packages/vite )
Updates `hono` from 4.12.11 to 4.12.12
- [Release notes](https://github.com/honojs/hono/releases )
- [Commits](https://github.com/honojs/hono/compare/v4.12.11...v4.12.12 )
---
updated-dependencies:
- dependency-name: "@types/node"
dependency-version: 25.6.0
dependency-type: direct:development
update-type: version-update:semver-minor
dependency-group: production-dependencies
- dependency-name: "@typescript-eslint/eslint-plugin"
dependency-version: 8.58.2
dependency-type: direct:development
update-type: version-update:semver-patch
dependency-group: production-dependencies
- dependency-name: "@typescript-eslint/parser"
dependency-version: 8.58.2
dependency-type: direct:development
update-type: version-update:semver-patch
dependency-group: production-dependencies
- dependency-name: prettier
dependency-version: 3.8.2
dependency-type: direct:development
update-type: version-update:semver-patch
dependency-group: production-dependencies
- dependency-name: vitest
dependency-version: 4.1.4
dependency-type: direct:development
update-type: version-update:semver-patch
dependency-group: production-dependencies
- dependency-name: content-disposition
dependency-version: 1.1.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: production-dependencies
- dependency-name: dotenv
dependency-version: 17.4.2
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: production-dependencies
- dependency-name: file-type
dependency-version: 22.0.1
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: production-dependencies
- dependency-name: simple-git
dependency-version: 3.36.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: production-dependencies
- dependency-name: unpdf
dependency-version: 1.6.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: production-dependencies
- dependency-name: "@vitest/coverage-v8"
dependency-version: 4.1.4
dependency-type: direct:development
update-type: version-update:semver-patch
dependency-group: production-dependencies
- dependency-name: "@tanstack/react-query"
dependency-version: 5.99.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: production-dependencies
- dependency-name: lucide-react
dependency-version: 1.8.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: production-dependencies
- dependency-name: react
dependency-version: 19.2.5
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: production-dependencies
- dependency-name: react-dom
dependency-version: 19.2.5
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: production-dependencies
- dependency-name: shadcn
dependency-version: 4.2.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: production-dependencies
- dependency-name: autoprefixer
dependency-version: 10.5.0
dependency-type: direct:development
update-type: version-update:semver-minor
dependency-group: production-dependencies
- dependency-name: jsdom
dependency-version: 29.0.2
dependency-type: direct:development
update-type: version-update:semver-patch
dependency-group: production-dependencies
- dependency-name: postcss
dependency-version: 8.5.9
dependency-type: direct:development
update-type: version-update:semver-patch
dependency-group: production-dependencies
- dependency-name: vite
dependency-version: 8.0.8
dependency-type: direct:development
update-type: version-update:semver-patch
dependency-group: production-dependencies
- dependency-name: hono
dependency-version: 4.12.12
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: production-dependencies
...
Signed-off-by: dependabot[bot] <support@github.com>
2026-04-13 23:31:09 +00:00
dependabot[bot]
ccdffe2960
chore: bump the production-dependencies group across 1 directory with 17 updates
...
Bumps the production-dependencies group with 17 updates in the / directory:
| Package | From | To |
| --- | --- | --- |
| [@playwright/test](https://github.com/microsoft/playwright ) | `1.58.2` | `1.59.1` |
| [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node ) | `25.5.0` | `25.5.2` |
| [@typescript-eslint/eslint-plugin](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/eslint-plugin ) | `8.57.2` | `8.58.0` |
| [@typescript-eslint/parser](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/parser ) | `8.57.2` | `8.58.0` |
| [vitest](https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest ) | `4.1.1` | `4.1.2` |
| [dotenv](https://github.com/motdotla/dotenv ) | `17.3.1` | `17.4.1` |
| [express-rate-limit](https://github.com/express-rate-limit/express-rate-limit ) | `8.3.1` | `8.3.2` |
| [simple-git](https://github.com/steveukx/git-js/tree/HEAD/simple-git ) | `3.33.0` | `3.35.2` |
| [@vitest/coverage-v8](https://github.com/vitest-dev/vitest/tree/HEAD/packages/coverage-v8 ) | `4.1.1` | `4.1.2` |
| [@tanstack/react-query](https://github.com/TanStack/query/tree/HEAD/packages/react-query ) | `5.95.2` | `5.96.2` |
| [lucide-react](https://github.com/lucide-icons/lucide/tree/HEAD/packages/lucide-react ) | `1.0.1` | `1.7.0` |
| [react-grid-layout](https://github.com/STRML/react-grid-layout ) | `2.2.2` | `2.2.3` |
| [recharts](https://github.com/recharts/recharts ) | `3.8.0` | `3.8.1` |
| [shadcn](https://github.com/shadcn-ui/ui/tree/HEAD/packages/shadcn ) | `4.1.0` | `4.1.2` |
| [vite](https://github.com/vitejs/vite/tree/HEAD/packages/vite ) | `8.0.2` | `8.0.5` |
| [@modelcontextprotocol/sdk](https://github.com/modelcontextprotocol/typescript-sdk ) | `1.27.1` | `1.29.0` |
| [hono](https://github.com/honojs/hono ) | `4.12.9` | `4.12.11` |
Updates `@playwright/test` from 1.58.2 to 1.59.1
- [Release notes](https://github.com/microsoft/playwright/releases )
- [Commits](https://github.com/microsoft/playwright/compare/v1.58.2...v1.59.1 )
Updates `@types/node` from 25.5.0 to 25.5.2
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases )
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node )
Updates `@typescript-eslint/eslint-plugin` from 8.57.2 to 8.58.0
- [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases )
- [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/eslint-plugin/CHANGELOG.md )
- [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.58.0/packages/eslint-plugin )
Updates `@typescript-eslint/parser` from 8.57.2 to 8.58.0
- [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases )
- [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/parser/CHANGELOG.md )
- [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.58.0/packages/parser )
Updates `vitest` from 4.1.1 to 4.1.2
- [Release notes](https://github.com/vitest-dev/vitest/releases )
- [Commits](https://github.com/vitest-dev/vitest/commits/v4.1.2/packages/vitest )
Updates `dotenv` from 17.3.1 to 17.4.1
- [Changelog](https://github.com/motdotla/dotenv/blob/master/CHANGELOG.md )
- [Commits](https://github.com/motdotla/dotenv/compare/v17.3.1...v17.4.1 )
Updates `express-rate-limit` from 8.3.1 to 8.3.2
- [Release notes](https://github.com/express-rate-limit/express-rate-limit/releases )
- [Commits](https://github.com/express-rate-limit/express-rate-limit/compare/v8.3.1...v8.3.2 )
Updates `simple-git` from 3.33.0 to 3.35.2
- [Release notes](https://github.com/steveukx/git-js/releases )
- [Changelog](https://github.com/steveukx/git-js/blob/main/simple-git/CHANGELOG.md )
- [Commits](https://github.com/steveukx/git-js/commits/simple-git@3.35.2/simple-git )
Updates `@vitest/coverage-v8` from 4.1.1 to 4.1.2
- [Release notes](https://github.com/vitest-dev/vitest/releases )
- [Commits](https://github.com/vitest-dev/vitest/commits/v4.1.2/packages/coverage-v8 )
Updates `@tanstack/react-query` from 5.95.2 to 5.96.2
- [Release notes](https://github.com/TanStack/query/releases )
- [Changelog](https://github.com/TanStack/query/blob/main/packages/react-query/CHANGELOG.md )
- [Commits](https://github.com/TanStack/query/commits/@tanstack/react-query@5.96.2/packages/react-query )
Updates `lucide-react` from 1.0.1 to 1.7.0
- [Release notes](https://github.com/lucide-icons/lucide/releases )
- [Commits](https://github.com/lucide-icons/lucide/commits/1.7.0/packages/lucide-react )
Updates `react-grid-layout` from 2.2.2 to 2.2.3
- [Release notes](https://github.com/STRML/react-grid-layout/releases )
- [Changelog](https://github.com/react-grid-layout/react-grid-layout/blob/master/CHANGELOG.md )
- [Commits](https://github.com/STRML/react-grid-layout/compare/2.2.2...2.2.3 )
Updates `recharts` from 3.8.0 to 3.8.1
- [Release notes](https://github.com/recharts/recharts/releases )
- [Changelog](https://github.com/recharts/recharts/blob/main/CHANGELOG.md )
- [Commits](https://github.com/recharts/recharts/compare/v3.8.0...v3.8.1 )
Updates `shadcn` from 4.1.0 to 4.1.2
- [Release notes](https://github.com/shadcn-ui/ui/releases )
- [Changelog](https://github.com/shadcn-ui/ui/blob/main/packages/shadcn/CHANGELOG.md )
- [Commits](https://github.com/shadcn-ui/ui/commits/shadcn@4.1.2/packages/shadcn )
Updates `vite` from 8.0.2 to 8.0.5
- [Release notes](https://github.com/vitejs/vite/releases )
- [Changelog](https://github.com/vitejs/vite/blob/main/packages/vite/CHANGELOG.md )
- [Commits](https://github.com/vitejs/vite/commits/v8.0.5/packages/vite )
Updates `@modelcontextprotocol/sdk` from 1.27.1 to 1.29.0
- [Release notes](https://github.com/modelcontextprotocol/typescript-sdk/releases )
- [Commits](https://github.com/modelcontextprotocol/typescript-sdk/compare/v1.27.1...v1.29.0 )
Updates `hono` from 4.12.9 to 4.12.11
- [Release notes](https://github.com/honojs/hono/releases )
- [Commits](https://github.com/honojs/hono/compare/v4.12.9...v4.12.11 )
---
updated-dependencies:
- dependency-name: "@playwright/test"
dependency-version: 1.59.1
dependency-type: direct:development
update-type: version-update:semver-minor
dependency-group: production-dependencies
- dependency-name: "@types/node"
dependency-version: 25.5.2
dependency-type: direct:development
update-type: version-update:semver-patch
dependency-group: production-dependencies
- dependency-name: "@typescript-eslint/eslint-plugin"
dependency-version: 8.58.0
dependency-type: direct:development
update-type: version-update:semver-minor
dependency-group: production-dependencies
- dependency-name: "@typescript-eslint/parser"
dependency-version: 8.58.0
dependency-type: direct:development
update-type: version-update:semver-minor
dependency-group: production-dependencies
- dependency-name: vitest
dependency-version: 4.1.2
dependency-type: direct:development
update-type: version-update:semver-patch
dependency-group: production-dependencies
- dependency-name: dotenv
dependency-version: 17.4.1
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: production-dependencies
- dependency-name: express-rate-limit
dependency-version: 8.3.2
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: production-dependencies
- dependency-name: simple-git
dependency-version: 3.35.2
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: production-dependencies
- dependency-name: "@vitest/coverage-v8"
dependency-version: 4.1.2
dependency-type: direct:development
update-type: version-update:semver-patch
dependency-group: production-dependencies
- dependency-name: "@tanstack/react-query"
dependency-version: 5.96.2
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: production-dependencies
- dependency-name: lucide-react
dependency-version: 1.7.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: production-dependencies
- dependency-name: react-grid-layout
dependency-version: 2.2.3
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: production-dependencies
- dependency-name: recharts
dependency-version: 3.8.1
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: production-dependencies
- dependency-name: shadcn
dependency-version: 4.1.2
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: production-dependencies
- dependency-name: vite
dependency-version: 8.0.5
dependency-type: direct:development
update-type: version-update:semver-patch
dependency-group: production-dependencies
- dependency-name: "@modelcontextprotocol/sdk"
dependency-version: 1.29.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: production-dependencies
- dependency-name: hono
dependency-version: 4.12.11
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: production-dependencies
...
Signed-off-by: dependabot[bot] <support@github.com>
2026-04-06 23:18:51 +00:00
dependabot[bot]
87a0c0fecd
chore: bump file-type from 21.3.4 to 22.0.0 ( #273 )
...
* chore: bump file-type from 21.3.4 to 22.0.0
Bumps [file-type](https://github.com/sindresorhus/file-type ) from 21.3.4 to 22.0.0.
- [Release notes](https://github.com/sindresorhus/file-type/releases )
- [Commits](https://github.com/sindresorhus/file-type/compare/v21.3.4...v22.0.0 )
---
updated-dependencies:
- dependency-name: file-type
dependency-version: 22.0.0
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com>
* fix: unblock security audit in dependabot file-type bump
---------
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: bradgroux <brad@digitalmeld.io>
2026-03-31 03:15:55 -05:00
Brad Groux
bee813b2d6
fix(tests): use valid PNG IHDR chunks in mime-validation fixtures ( #266 )
...
file-type >=21.3.4 now validates PNG structure beyond just the 8-byte
signature. The minimal header+zeros buffer no longer detects as image/png.
Updated both the PNG acceptance test and the PNG-as-JPG mismatch test
to include a valid IHDR chunk (1x1 RGB pixel), making them compatible
with both current and upcoming file-type versions.
Co-authored-by: bradgroux <brad@digitalmeld.io>
2026-03-23 20:30:59 -05:00
Brad Groux
9f49379b72
test: comprehensive unit tests for v4.0 governance services ( #249 ) ( #263 )
...
* test: decision-service tests (issue #249 )
* test: chat-service tests (issue #249 )
* test: feedback-service tests (issue #249 )
* docs: security audit findings for #254 — governance endpoint review
Audit-only report covering:
- v1 router rate limiting (confirmed global coverage)
- chat.ts: unbounded message/agent fields (MEDIUM)
- prompt-registry.ts: unbounded content/sampleVariables (MEDIUM)
- delegation.ts: missing .max() on string fields, unvalidated limit param (LOW)
- workflows.ts: unbounded context/config depth (LOW)
- No SSRF or path traversal vectors found in audited routes
No code changes. Fixes to be tracked in follow-up issues.
Closes #254 (audit report delivered)
* test: add remaining governance service coverage (#249 )
* chore: remove stray audit file from wrong branch
---------
Co-authored-by: Brad Groux <bradgroux@users.noreply.github.com>
Co-authored-by: bradgroux <brad@digitalmeld.io>
2026-03-23 20:16:55 -05:00
Brad Groux
07f1b9857e
test(routes): add feedback, chat, and system-health route tests ( #250 ) ( #257 )
...
* perf(task-service): batch file reads with bounded concurrency (#253 )
- Add batchedMap() to fs-helpers.ts: Promise.all-based worker pool capped
at BATCH_CONCURRENCY (10) concurrent operations. Individual item errors
become null — one bad file never aborts the entire batch.
- Replace unbounded Promise.all in loadCacheFromDisk() with batchedMap()
- Replace unbounded Promise.all in listArchivedTasks() with batchedMap()
- Add batch-reads-benchmark.test.ts: concurrency-cap proof, order
preservation, error isolation, corrupt/missing file tolerance, and a
50-file wall-clock benchmark (3.4× improvement on local tmpfs)
Closes #253
* Revert "perf(task-service): batch file reads with bounded concurrency (#253 )"
This reverts commit a423e5ea25 .
* test(routes): add feedback, chat, and system-health route tests (#250 )
- feedback.test.ts: 27 tests covering GET/POST/PUT/DELETE, validation, auth, errors
- chat.test.ts: 32 tests covering sessions, squad messages, auth enforcement
- system-health.test.ts: 12 tests covering health check endpoints and response shape
All 71 tests pass. Closes #250
---------
Co-authored-by: Brad Groux <bradgroux@users.noreply.github.com>
2026-03-23 20:16:33 -05:00
Brad Groux
c23d261b9e
perf(task-service): batch file reads with bounded concurrency ( #253 ) ( #255 )
...
- Add batchedMap() to fs-helpers.ts: Promise.all-based worker pool capped
at BATCH_CONCURRENCY (10) concurrent operations. Individual item errors
become null — one bad file never aborts the entire batch.
- Replace unbounded Promise.all in loadCacheFromDisk() with batchedMap()
- Replace unbounded Promise.all in listArchivedTasks() with batchedMap()
- Add batch-reads-benchmark.test.ts: concurrency-cap proof, order
preservation, error isolation, corrupt/missing file tolerance, and a
50-file wall-clock benchmark (3.4× improvement on local tmpfs)
Closes #253
Co-authored-by: Brad Groux <bradgroux@users.noreply.github.com>
2026-03-23 20:16:25 -05:00
Brad Groux
ddca1b6cb4
fix: isolate status history tests from real state
2026-03-22 14:24:15 -05:00
Brad Groux
7483cc67f3
fix(security): harden localhost bypass and broadcast frontmatter parsing ( closes #236 ) ( #242 )
...
- auth: disable localhost bypass entirely in production mode instead of
just logging a warning — prevents misconfigured deployments from
allowing unauthenticated access
- broadcast-storage: wrap JSON.parse() calls for tags and readBy
frontmatter fields in try-catch, defaulting to empty arrays on parse
failure instead of crashing the route handler
Co-authored-by: Brad Groux <bradgroux@users.noreply.github.com>
Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-03-21 15:20:31 -05:00
Brad Groux
303b7935b6
fix(api): make startup init failures fatal and add shutdown timeouts ( closes #235 ) ( #241 )
...
- Service initialization (telemetry, policy, config, migrations) now
calls process.exit(1) on failure instead of silently continuing with
a partially broken server
- WebSocket server close gets a 3s timeout so stuck clients don't block
shutdown indefinitely
- Telemetry flush gets a 5s timeout so a stuck write queue doesn't
prevent shutdown
Co-authored-by: Brad Groux <bradgroux@users.noreply.github.com>
Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-03-21 15:20:28 -05:00
Brad Groux
0fc2c834ae
fix(api): prevent config cache stampede and log corrupted activity files ( closes #234 ) ( #240 )
...
- config-service: coalesce concurrent getConfig() calls into a single
disk read via pendingRead promise, preventing cache stampede under load
- activity-service: log warning when corrupted activity file is reset
instead of silently discarding data
Co-authored-by: Brad Groux <bradgroux@users.noreply.github.com>
Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-03-21 15:20:26 -05:00
Brad Groux
74dc3a9074
fix(api): WebSocket event listener leaks and add message rate limiting ( closes #233 ) ( #239 )
...
- Replace per-subscribe ws.on('close') listeners with tracked emitter
references, preventing listener accumulation when clients re-subscribe
- Add message rate limiting (30 msgs / 10s window) to prevent DoS via
WebSocket message spam
- Clean up emitter listeners on close handler to prevent callbacks on
destroyed sockets
Co-authored-by: Brad Groux <bradgroux@users.noreply.github.com>
Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-03-21 15:20:23 -05:00
Brad Groux
aaf0f47ac6
fix(api): resolve promise handling issues causing crashes and data loss ( closes #232 ) ( #238 )
...
- gateway-chat-client: add settled flag to prevent multiple resolve/reject
on the same promise from concurrent timeout, error, and close events
- file-lock: add rejection handler on previous.then() in timeout path so
a rejected predecessor doesn't cause an unhandled rejection
- telemetry-service: capture event reference at enqueue time instead of
shifting from queue at write time, preventing event loss under concurrency
- status-history-service: await async init before any public method runs,
preventing race conditions when logStatusChange is called before
loadLastEntry completes
Co-authored-by: Brad Groux <bradgroux@users.noreply.github.com>
Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-03-21 15:20:20 -05:00
Brad Groux
43725e69e2
fix(security): enforce HS256 algorithm in JWT verification ( closes #231 ) ( #237 )
...
Add explicit `algorithms: ['HS256']` to all `jwt.verify()` calls to
prevent algorithm confusion attacks (CVE-2015-9235). Without this,
an attacker could switch the algorithm header to exploit key type
mismatches and forge valid tokens.
Co-authored-by: Brad Groux <bradgroux@users.noreply.github.com>
Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-03-21 15:20:18 -05:00
Brad Groux
70c8c06e56
docs: v4.0 documentation update and cleanup ( closes #229 ) ( #230 )
...
v4.0 docs update: CHANGELOG, README, FEATURES, API-REFERENCE, 11 new SOPs, MCP docs, version bumps to 4.0.0, docs cleanup. Closes #229 .
2026-03-21 12:20:16 -05:00
Brad Groux
f084ce7d39
fix: add missing requireDeliverableForDone to settings schema ( #228 )
...
The requireDeliverableForDone field was used in task-service.ts and
the UI (TasksTab.tsx) but was missing from the Zod validation schema
in feature-settings-schema.ts. Due to .strict() mode on
TaskBehaviorSettingsSchema, PATCH /api/settings/features rejected
any payload containing this field with a 400 error.
Fix: Add requireDeliverableForDone: z.boolean().optional() to
TaskBehaviorSettingsSchema after autoSaveDelayMs.
Also add tests verifying the field is accepted (true and false) and
that unknown fields are still rejected by strict mode.
Reimplements #130 . Original contribution by @TylonHH.
Co-authored-by: Brad Groux <bradgroux@users.noreply.github.com>
2026-03-21 11:51:40 -05:00
Brad Groux
415a095d31
feat: Prompt Template Registry with Version Control ( #184 ) ( #220 )
...
* feat: prompt template registry with version control (#184 )
- Add PromptTemplate, PromptVersion, PromptUsage, PromptStats types
- Implement prompt-registry service with full CRUD, versioning, and usage tracking
- Add prompt-registry REST endpoints with preview rendering and statistics
- Create React Query hooks (usePromptTemplates, usePromptStats, etc.)
- Implement multi-tab PromptRegistry component with Templates, Versions, Usage, Stats, Preview tabs
- Add INTEGRATION.md documenting manual merge points for existing files
- Supports variable interpolation {{variable_name}} and changelog tracking
- File-based storage pattern consistent with existing template system
* fix: export prompt-registry types from shared barrel
* fix: handle optional changelog in prompt version
* fix: handle optional content field in version creation
* fix: remove unused imports and variables in prompt registry
* fix: remove all unused imports in prompt registry web files
* ci: trigger checks (retry)
---------
Co-authored-by: Brad Groux <bradgroux@users.noreply.github.com>
2026-03-21 11:16:59 -05:00
Brad Groux
d0a2ee4922
feat: Global System Health Status Bar ( #185 ) ( #221 )
...
* feat: global system health status bar (#185 )
* fix: export system-health types from shared barrel
---------
Co-authored-by: Brad Groux <bradgroux@users.noreply.github.com>
2026-03-21 11:12:04 -05:00
Brad Groux
4e6d331a33
feat: User Feedback Loop with Sentiment Analytics ( #182 ) ( #222 )
...
* feat: user feedback loop with sentiment analytics (#182 )
* fix: export feedback types from shared barrel
* fix: TS errors in feedback panel and API client
* fix: tooltip formatter type compatibility
* ci: retry flaky test
---------
Co-authored-by: Brad Groux <bradgroux@users.noreply.github.com>
2026-03-21 10:56:36 -05:00
Brad Groux
45cfc822e4
feat: Behavioral Drift Detection & Alerting ( #181 ) ( #218 )
...
* Implement drift detection and alerting
* fix: correct type predicate in drift service filter
* fix: resolve DriftMonitor formatter type and DriftAlertFilters cast
* fix: add rm export to fs-helpers for drift-service cleanup
* ci: trigger workflow
* chore: trigger ci
* fix: ViewContext union syntax error
* fix: add rm to docker-paths test node:fs/promises mock
---------
Co-authored-by: bradgroux <bradgroux@users.noreply.github.com>
2026-03-21 09:33:34 -05:00
Brad Groux
ac64785326
feat: Decision Audit Trail with Assumption Tracking ( #179 ) ( #216 )
...
* feat: add decision audit trail with assumption tracking
* fix: mock node:fs/promises in tests for fs-helpers compat
* fix: add full fs/promises mock in docker-paths test
* fix: add mkdir to node:fs/promises mock in jwt-rotation test
* ci: trigger workflow
* chore: trigger ci
* fix: ViewContext union syntax, expand fs/promises mock
---------
Co-authored-by: bradgroux <bradgroux@users.noreply.github.com>
2026-03-21 09:28:35 -05:00
Brad Groux
50f76f811a
feat: Agent Output Evaluation & Scoring Framework ( #180 ) ( #217 )
...
* Implement scoring evaluation framework
* fix: resolve TypeScript errors in ScoreExplorer component
---------
Co-authored-by: bradgroux <brad@digitalmeld.io>
Co-authored-by: Brad Groux <bradgroux@users.noreply.github.com>
2026-03-21 09:13:24 -05:00
Brad Groux
1a2476257e
feat: Agent Policy & Guard Engine ( #178 ) ( #215 )
...
* Implement policy guard engine for agent actions
* fix: wrap policy routes with asyncHandler for type safety
* fix: prevent unhandled rejection race in security test cleanup
---------
Co-authored-by: bradgroux <bradgroux@users.noreply.github.com>
2026-03-21 09:03:01 -05:00
Brad Groux
9d453a09f6
feat(squad-chat): add Adaptive Card support to squad messages ( #214 )
...
Add optional 'card' field (Record<string, unknown>) to SquadMessage and
SquadMessageInput types, allowing callers to attach Adaptive Card v1.5
JSON payloads to squad chat messages.
Changes:
- shared: Add card? to SquadMessage and SquadMessageInput interfaces
- routes/chat: Add card to zod validation schema and passthrough
- chat-service: Accept and spread card into squad message object
- squad-webhook: Include card in webhook payload type and forwarding
The card field flows through the full pipeline: API validation → storage
→ API response → WebSocket broadcast → webhook forwarding. Cards are
transient (not serialized to markdown logs) and intended for real-time
delivery to Teams via Adaptive Card attachments.
Co-authored-by: Brad Groux <bradgroux@users.noreply.github.com>
2026-03-20 21:10:59 -05:00
Brad Groux
d7690888a3
fix: convert successRate from ratio to percentage in SystemHealthBar ( #211 ) ( #212 )
...
getRunMetrics() returns successRate as 0-1 ratio but getOperationsSignal()
treated it as 0-100 percentage. This caused the banner to show '1% success
rate' when all runs succeeded, and incorrectly flagged operations as critical.
Multiply by 100 and round before threshold comparison and display.
Co-authored-by: Brad Groux <bradgroux@users.noreply.github.com>
2026-03-20 08:48:34 -05:00
Brad Groux
adbcfc930b
fix: resolve TypeScript build errors ( #177 )
...
- Add RunMode type and QaGateState interface to shared task.types.ts
- Add runMode and qaGate optional fields to Task and UpdateTaskInput interfaces
- Mirror changes in shared/src/types/task.types.d.ts (used by web bundler)
- Add RunModeGateSection.tsx component (was untracked, causing web build failure)
- Add qa-gate.test.ts and dependency-cycle.test.ts (untracked test files)
Co-authored-by: Brad Groux <bradgroux@users.noreply.github.com>
2026-03-19 22:09:46 -05:00
Brad Groux
681a3647b7
fix: correct false cycle detection in dependency API ( #188 ) ( #208 )
...
- checkForCycle now accepts a direction parameter ('depends_on' | 'blocks')
so DFS only traverses edges of the same relationship type being validated.
Previously, mixing both types produced false positives: e.g. C depends_on D
and D blocks E is a valid DAG, but the old DFS would traverse C→D→E through
mixed edge types and incorrectly report a cycle when adding E depends_on C.
- Deep-copy task dependency objects before mutation so the in-memory cache is
never corrupted by pre-commit edge additions, which caused the final race-
condition check to mis-detect cycles on valid graphs.
- Fix blocks cycle detection direction: when adding A blocks B, the check
should start from B and follow blocks edges to see if A is reachable,
matching the same semantics as depends_on cycle detection.
- Add dependency-cycle.test.ts with 7 targeted test cases including the
specific false-positive scenario from issue #188 .
Co-authored-by: Brad Groux <bradgroux@users.noreply.github.com>
2026-03-19 19:48:35 -05:00
Brad Groux
2f9daca858
feat: add MCP comment CRUD tools ( #200 ) ( #206 )
...
* feat(transcripts): add /api/transcripts/dedup-check endpoint for n8n dedup
Bridges n8n (no local fs) and inbox/transcripts/processed/ folder-based dedup rule.
Rule: processed file match = transcriptMatchFound:true (skip), else false (allow through).
Called by SMFL870bnazxSZem Transcript Dedup Check node (now HTTP Request, not Code node).
* feat(webhook): add /api/webhook/n8n endpoint for n8n email-directive + attachment ingest
- New route: POST /api/webhook/n8n (unauthenticated, before auth middleware)
- Accepts email-directive payloads from n8n Email Ingestion Engine
- Downloads base64-encoded attachments (docx/pdf/txt/csv/xlsx only)
- Saves to ~/clawd/inbox/attachments/ with timestamped names
- Writes sidecar .json metadata for each directive
- Validates against optional N8N_WEBHOOK_SECRET env var
Fixes: Post Directive Webhook was 404ing on every directive email
* feat: add MCP comment CRUD tools (#200 )
---------
Co-authored-by: Brad Groux <bradgroux@users.noreply.github.com>
2026-03-19 19:48:30 -05:00
Francois Altwies
0580ebe55a
feat(hooks): wire lifecycle hooks to notification service ( #201 )
...
Complete the TODO at hook-service.ts:153 — when a hook config has
`notify: true`, create a notification via NotificationService for
the lifecycle event (created, started, blocked, completed, archived).
Follows the same non-blocking pattern as fireWebhook and fireSquadChat:
errors are logged but never propagate to the caller.
Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-19 19:48:17 -05:00
dependabot[bot]
f533772d16
chore: bump the production-dependencies group with 10 updates ( #199 )
...
Bumps the production-dependencies group with 10 updates:
| Package | From | To |
| --- | --- | --- |
| [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node ) | `25.3.3` | `25.4.0` |
| [@typescript-eslint/eslint-plugin](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/eslint-plugin ) | `8.56.1` | `8.57.0` |
| [@typescript-eslint/parser](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/parser ) | `8.56.1` | `8.57.0` |
| [lint-staged](https://github.com/lint-staged/lint-staged ) | `16.3.1` | `16.3.2` |
| [file-type](https://github.com/sindresorhus/file-type ) | `21.3.0` | `21.3.1` |
| [@types/multer](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/multer ) | `2.0.0` | `2.1.0` |
| [@types/sanitize-html](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/sanitize-html ) | `2.16.0` | `2.16.1` |
| [dompurify](https://github.com/cure53/DOMPurify ) | `3.3.1` | `3.3.2` |
| [lucide-react](https://github.com/lucide-icons/lucide/tree/HEAD/packages/lucide-react ) | `0.576.0` | `0.577.0` |
| [recharts](https://github.com/recharts/recharts ) | `3.7.0` | `3.8.0` |
Updates `@types/node` from 25.3.3 to 25.4.0
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases )
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node )
Updates `@typescript-eslint/eslint-plugin` from 8.56.1 to 8.57.0
- [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases )
- [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/eslint-plugin/CHANGELOG.md )
- [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.57.0/packages/eslint-plugin )
Updates `@typescript-eslint/parser` from 8.56.1 to 8.57.0
- [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases )
- [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/parser/CHANGELOG.md )
- [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.57.0/packages/parser )
Updates `lint-staged` from 16.3.1 to 16.3.2
- [Release notes](https://github.com/lint-staged/lint-staged/releases )
- [Changelog](https://github.com/lint-staged/lint-staged/blob/main/CHANGELOG.md )
- [Commits](https://github.com/lint-staged/lint-staged/compare/v16.3.1...v16.3.2 )
Updates `file-type` from 21.3.0 to 21.3.1
- [Release notes](https://github.com/sindresorhus/file-type/releases )
- [Commits](https://github.com/sindresorhus/file-type/compare/v21.3.0...v21.3.1 )
Updates `@types/multer` from 2.0.0 to 2.1.0
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases )
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/multer )
Updates `@types/sanitize-html` from 2.16.0 to 2.16.1
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases )
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/sanitize-html )
Updates `dompurify` from 3.3.1 to 3.3.2
- [Release notes](https://github.com/cure53/DOMPurify/releases )
- [Commits](https://github.com/cure53/DOMPurify/compare/3.3.1...3.3.2 )
Updates `lucide-react` from 0.576.0 to 0.577.0
- [Release notes](https://github.com/lucide-icons/lucide/releases )
- [Commits](https://github.com/lucide-icons/lucide/commits/0.577.0/packages/lucide-react )
Updates `recharts` from 3.7.0 to 3.8.0
- [Release notes](https://github.com/recharts/recharts/releases )
- [Changelog](https://github.com/recharts/recharts/blob/main/CHANGELOG.md )
- [Commits](https://github.com/recharts/recharts/compare/v3.7.0...v3.8.0 )
---
updated-dependencies:
- dependency-name: "@types/node"
dependency-version: 25.4.0
dependency-type: direct:development
update-type: version-update:semver-minor
dependency-group: production-dependencies
- dependency-name: "@typescript-eslint/eslint-plugin"
dependency-version: 8.57.0
dependency-type: direct:development
update-type: version-update:semver-minor
dependency-group: production-dependencies
- dependency-name: "@typescript-eslint/parser"
dependency-version: 8.57.0
dependency-type: direct:development
update-type: version-update:semver-minor
dependency-group: production-dependencies
- dependency-name: lint-staged
dependency-version: 16.3.2
dependency-type: direct:development
update-type: version-update:semver-patch
dependency-group: production-dependencies
- dependency-name: file-type
dependency-version: 21.3.1
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: production-dependencies
- dependency-name: "@types/multer"
dependency-version: 2.1.0
dependency-type: direct:development
update-type: version-update:semver-minor
dependency-group: production-dependencies
- dependency-name: "@types/sanitize-html"
dependency-version: 2.16.1
dependency-type: direct:development
update-type: version-update:semver-patch
dependency-group: production-dependencies
- dependency-name: dompurify
dependency-version: 3.3.2
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: production-dependencies
- dependency-name: lucide-react
dependency-version: 0.577.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: production-dependencies
- dependency-name: recharts
dependency-version: 3.8.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: production-dependencies
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-03-09 19:24:54 -05:00
Brad Groux
2afff60cc8
fix: resolve CI type errors in useTasks-patchCache test
...
- Widen assertPatchOnly hookFn parameter to accept any mutation hook return type
instead of narrowly typing to useAddSubtask's signature
- Add explicit type annotation for 'call' parameter (TS7006)
- Update multer 2.1.0→2.1.1, express-rate-limit 8.2.1→8.2.2,
hono 4.12.3→4.12.4+, @hono/node-server 1.19.9→1.19.10+,
@modelcontextprotocol/sdk to resolve 4 high severity audit findings
2026-03-09 13:14:50 -05:00
Francois Altwies
678689299a
feat: add global system health status bar ( #185 ) ( #195 )
...
Aggregate system, agent, and operations health signals into a single
status bar displayed below the header. The bar shows one of five states
(stable/reviewing/drifting/elevated/alert) with color-coded indicators
and expands on click to show per-signal details.
Backend: GET /api/v1/system/health aggregates storage/disk/memory checks,
agent registry stats, and 24h run metrics into a unified response.
Frontend: SystemHealthBar component with useSystemHealth hook polling
via @tanstack/react-query (30s connected, 60s disconnected).
Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-09 07:42:35 -05:00
Francois Altwies
100bf15147
fix(server): broadcast WebSocket events on comment mutations ( #191 )
...
Comment add/edit/delete operations update tasks via taskService but
don't notify WebSocket clients, causing stale UI for other connected
users. They only see comment changes after a full page refresh.
Add broadcastTaskChange('updated', taskId) calls to all three comment
endpoints (POST, PATCH, DELETE) matching the pattern used in the main
task routes (tasks.ts lines 564, 711, 773).
Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-09 07:42:30 -05:00
Francois Altwies
a5f54d6d4c
fix: allow any localhost origin in dev mode ( closes #190 ) ( #194 )
...
Docker users mapping to non-standard ports (e.g., -p 3099:3001) were
getting CORS blocked because buildDefaultDevOrigins() only generated
origins for ports 5173 and 3000.
Two changes:
1. CORS origin callback now allows any localhost/127.0.0.1 origin in
dev mode (NODE_ENV !== 'production'), mirroring the WebSocket origin
validator in auth.ts.
2. buildDefaultDevOrigins() now includes the server's own PORT in the
default origins list.
Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-09 07:42:20 -05:00
BradGroux
a8c623677a
fix(types): eliminate as-any casts and add type-safe query helpers
...
Replace all 9 production `as any` casts and ~35 unsafe `as string`
casts across 12 files with proper type narrowing.
Changes:
- Add server/src/lib/query-helpers.ts with qStr, qStrD, qNum, qNumD,
and paramStr utilities for safe Express 5 query/param extraction
- telemetry.ts: use discriminated union narrowing for run.completed
durationMs instead of (eventInput as any).durationMs
- telemetry-service.ts: use intersection type cast instead of as any
for durationMs capping
- docs.ts: replace (req.params as any).path with paramStr(); replace
as string query casts with qStr/qStrD
- dashboard-metrics.ts: remove unnecessary as any on run.started agent
(discriminated union already narrows correctly)
- config-service.ts: narrow as any to as Record<string,unknown>
- transition-hooks.ts: validate toStatus against TaskStatus enum
instead of casting as any
- activity.ts, summary.ts, status-history.ts, digest.ts,
error-learning.ts, task-observations.ts: replace all as string
query param casts with type-safe helpers
Runtime behavior unchanged. All 1347 existing tests still pass.
tsc --noEmit: 0 errors (before and after).
2026-03-05 22:52:14 -06:00
BradGroux
1dfa5c764f
fix(security): sanitize server error logging to prevent secret/token leakage
...
- Add lib/redact.ts: string-level redaction (Bearer tokens, JWTs, API keys,
hex secrets), object-level redaction (sensitive key names), and pino
serializers for err/req objects
- Update lib/logger.ts: wire redactSerializers and pino redact paths for
auth headers (authorization, x-api-key, cookie, set-cookie)
- Fix auth.ts checkAdminKeyStrength(): no longer logs actual admin key value
in weak-key warning (was exposing plaintext secret)
- Replace console.warn in auth.ts isLocalhostRequest() with structured logger
- Fix reset-password.ts: log only err.message, not full error object
- Add 28-test suite (__tests__/log-redaction.test.ts) covering:
- String pattern redaction (Bearer, JWT, API key prefixes, hex tokens)
- Object key redaction (password, token, apiKey, credentials, etc.)
- Pino serializer behavior for err and req objects
- requestId preservation through redaction
- UUID-style ID preservation (not over-redacted)
- Edge cases (null, depth limits, empty strings)
All 1458 existing tests + 28 new tests pass. TypeScript clean.
Closes: task_20260306_lv4K70
2026-03-05 22:34:23 -06:00
dependabot[bot]
a72200f114
chore: bump @types/supertest from 6.0.3 to 7.2.0 ( #173 )
...
Bumps [@types/supertest](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/supertest ) from 6.0.3 to 7.2.0.
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases )
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/supertest )
---
updated-dependencies:
- dependency-name: "@types/supertest"
dependency-version: 7.2.0
dependency-type: direct:development
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-03-04 12:06:44 -06:00