2026-07-03 11:46:00 -04:00
<!-- GENERATED — do not hand-edit. Edit docs/upstream-sync/triage.jsonl, then run `make triage-render` . Staleness is enforced in CI by `make triage-check` . -->
# Upstream triage ledger
Commits on `upstream/main` (langchain-ai/open-swe) not yet in `dev` , and the decision on each.
Rows key on the **upstream SHA** (stable across local cherry-picks). Deferred rows are provisional
— re-inspect before picking. See the fork-maintenance runbook in `CLAUDE.md` .
2026-09-14 12:38:04 +00:00
**Last synced `upstream/main` :** `9fba9672` (2026-09-14)
2026-07-03 11:46:00 -04:00
| sha | pr | subject | decision | why | branch |
|---|---|---|---|---|---|
| `0b76afdc` | #1653 | reviews block agenda, sticky headers, diff scroll | Landed | | cherry-pick-upstream |
| `7530653b` | #1655 | ResizeObserver settle for review scroll-to | Landed | | cherry-pick-upstream |
| `23bd4a63` | #1660 | top padding to sticky review block header | Landed | | cherry-pick-upstream |
| `9e5a1924` | #1656 | purge expired thread_wakeup crons | Landed | | cherry-pick-upstream |
| `63eb9a08` | #1661 | sidebar filter popover border tokens | Landed | | cherry-pick-upstream |
| `bc7ce591` | #1668 | preserve dashboard redirect after login | Landed | | cherry-pick-upstream |
| `f32e492a` | #1637 | return to thread after plan approval | Landed | | cherry-pick-upstream |
| `7ee3e057` | #1636 | make plan view mobile friendly | Landed | | cherry-pick-upstream |
| `6575c327` | #1654 | disable React StrictMode | Landed | kept fork's `PwaUpdateProvider` | cherry-pick-upstream |
2026-07-08 19:02:09 -04:00
| `00906401` | #1610 | editable plan mode | Landed | re-implemented in fork via #130 (editable plan mode) | |
2026-07-08 19:20:26 -04:00
| `f5670f24` | #1639 | require bun for ui agent work | Landed | cherry-picked (-x) in this PR (#132 ) | PR1 |
feat: port durable dispatch hardening and startup latency improvements (#160)
* feat: port plan-review & workflow-approval UX (#135)
Port six upstream commits onto dev:
- c03a6be7 (already ported): keep plan guidance high-level
- 546042a4: add workflow approval UI with diff preview, approval URLs,
web review links, and polling for approval status during active runs
- 216cf181: remove workflow token elevation; approved pushes pass
through directly without proxy token rewriting
- 3dbc0282: preserve plan redirects after login by accepting relative
same-origin redirect_to values and rejecting blocked paths
- bb104d93: submit plan comments with cmd+enter
- 90cb6caa: terse Slack replies, shared content via save_plan outside
plan mode (PLAN_STATUS_SHARED), reject shared-content mutations
Refs: #135
* feat: port durable dispatch hardening and startup latency improvements
Port five upstream PRs onto dev:
- #1621 / #1658: durable dispatch with loopback webhook defense,
create_durable_run helper, _config_with_prepare_run_id, degradation
to None for relative/loopback completion webhook URLs
- #1696: run-level completion webhook deduplication (replace
claim-then-post with post-then-flag per run_id), DeferredErrorModel
for graph-factory resilience, ToolRetryMiddleware for task subagents,
TimeoutWrapupMiddleware for all three graphs
- #1697: lazy-load __init__.py for agent.middleware, agent.tools,
agent.dashboard (PEP 562); defer heavy imports (exa_py in web_search,
agent.webapp in request_pr_review, deepagents in sandbox.py); add
ttl_cache.py with stale-while-revalidate for tool loaders
Refs: #137
* fix: restore login page render and clear CI lint/format
The plan-review port removed the authRedirectUrl import from login.tsx
but left its call site, crashing the login page at runtime (blank page,
no 'Sign in to open-swe'). Pass the relative path straight to loginUrl,
matching the plan route and the backend relative-redirect handling.
Also drop an unused os import in the guard test and reformat
workflow_push_guard.py to satisfy ruff.
* fix: restore RepairOrphaned middleware export and repoint model fake to deferred_model boundary
* fix: restore RepairOrphanedToolCallsMiddleware, fix E2E model-fake patch, drop dead ttl_cache
- Re-add RepairOrphanedToolCallsMiddleware to the lazy middleware __init__
(_MIDDLEWARE_MODULES, __all__, TYPE_CHECKING) so agent.reviewer can import it.
- Reroute E2E model patching to deferred_model.make_model so make_model_or_defer
(used by all three graph factories) returns the scripted fake instead of
building a real model with fake credentials.
- Drop unused agent/utils/ttl_cache.py — no agent module imports it.
- Fix import ordering in agent/reviewer.py and agent/analyzer.py (ruff I001).
- Format tests/test_dispatch.py.
* fix: claim-then-post run-level failure dedup; stop permanent suppression
---------
Co-authored-by: amoussa1229 <166072409+amoussa1229@users.noreply.github.com>
Co-authored-by: Adam Moussa <adam@seahavenind.com>
2026-07-09 17:11:25 -04:00
| `209132d3` | #1621 | durable interrupt dispatch + completion webhook | Landed | investigate first — may be applied | durable-dispatch |
| `02bb4dfd` | #1658 | don't attach loopback run-complete webhooks | Landed | | durable-dispatch |
| `29015fad` | #1614 | gate workflow pushes with approval | Landed | | durable-dispatch |
feat: port plan-review & workflow-approval UX (#159)
* feat: port plan-review & workflow-approval UX (#135)
Port six upstream commits onto dev:
- c03a6be7 (already ported): keep plan guidance high-level
- 546042a4: add workflow approval UI with diff preview, approval URLs,
web review links, and polling for approval status during active runs
- 216cf181: remove workflow token elevation; approved pushes pass
through directly without proxy token rewriting
- 3dbc0282: preserve plan redirects after login by accepting relative
same-origin redirect_to values and rejecting blocked paths
- bb104d93: submit plan comments with cmd+enter
- 90cb6caa: terse Slack replies, shared content via save_plan outside
plan mode (PLAN_STATUS_SHARED), reject shared-content mutations
Refs: #135
* fix: restore login page render and clear CI lint/format
The plan-review port removed the authRedirectUrl import from login.tsx
but left its call site, crashing the login page at runtime (blank page,
no 'Sign in to open-swe'). Pass the relative path straight to loginUrl,
matching the plan route and the backend relative-redirect handling.
Also drop an unused os import in the guard test and reformat
workflow_push_guard.py to satisfy ruff.
* fix: carry workflows:write on the standing proxy token
Complete the half-ported upstream 216cf181 cascade. The port dropped
_run_with_workflow_token from the guard but missed the paired github_app
change, so an approved .github/workflows push ran with the base token
(no workflows:write) and GitHub 403'd it.
Add workflows:write to BASE_RUNTIME_PROXY_TOKEN_PERMISSIONS and delete the
now-orphaned WORKFLOW_RUNTIME_PROXY_TOKEN_PERMISSIONS constant; update the
github_app and proxy_auth tests to match. The HITL approval gate in
workflow_push_guard.py is unchanged — this only lets the standing token
push once a human approves.
* fix: restore transient workflow-token elevation (revert standing workflows:write)
The standing GitHub-App proxy token (BASE_RUNTIME_PROXY_TOKEN_PERMISSIONS) is
ALWAYS-ON, so carrying workflows:write on it made the fork's HITL workflow-push
guard the sole control over unapproved workflow pushes. The guard's git-push
parser has gaps (obfuscated-expansion push, `gh api` REST contents PUT,
fully-qualified cross-branch refspecs); with a permanently workflows-scoped
token those gaps become live unapproved-workflow-push exploits (1 critical, 2
high — security review BLOCK on #159).
Restore dev's transient-elevation model:
- Drop workflows:write from BASE_RUNTIME_PROXY_TOKEN_PERMISSIONS; re-add the
WORKFLOW_RUNTIME_PROXY_TOKEN_PERMISSIONS constant (base + workflows:write).
- Re-introduce _run_with_workflow_token in the guard: it mints the
workflows-scoped token via refresh_proxy_token around the approved,
guard-normalized fixed_command, then downscopes to RUNTIME then BASE in a
finally. Route the approval branch through it.
- Restore the dev token/elevation tests.
The standing token no longer carries workflows:write, so the three parser
bypasses hit GitHub 403 again; an approved push still succeeds because the
elevation grants workflows:write only around the normalized command. Keeps all
of #159's diff-preview / approval-URL / Slack-card guard additions.
* fix: reject protocol-relative path from sanitizeAuthRedirect (open redirect)
sanitizeAuthRedirect returned parsed.pathname+search+hash, which `new URL` can
resolve to a protocol-relative `//host` (e.g. input `/..//evil.com` normalizes
same-origin, passing the origin check, but yields a path starting with `//`).
ClientRedirect / login.tsx feed that path to window.location.replace, so it
navigates cross-origin — an open redirect. Reject any resolved path that is not
a single-leading-slash path (`^/[^/]`), falling back to the default. Adds
coverage for `/..//evil.com`, `/.//evil.com`, and `//evil.com`.
* fix: log SECURITY error when workflow-token downscope fails
The elevate->push->downscope finally block was silent on failure. If both
refresh_proxy_token calls fail, the sandbox retains workflows:write for the
rest of the run with no signal. Log a SECURITY error on the partial and full
downscope-failure paths so the retention is observable.
Addresses the GPT-4.1 cross-family review of the token-scope remediation.
---------
Co-authored-by: amoussa1229 <166072409+amoussa1229@users.noreply.github.com>
Co-authored-by: Adam Moussa <adam@seahavenind.com>
2026-07-09 16:03:13 -04:00
| `546042a4` | #1652 | add workflow approval UI | Landed | | plan-approval |
2026-07-08 19:02:09 -04:00
| `ae04b72b` | #1635 | publish plans from sandbox files | Landed | ported (adapted) in #128 (save_plan reads sandbox file) | plan-approval |
feat: port plan-review & workflow-approval UX (#159)
* feat: port plan-review & workflow-approval UX (#135)
Port six upstream commits onto dev:
- c03a6be7 (already ported): keep plan guidance high-level
- 546042a4: add workflow approval UI with diff preview, approval URLs,
web review links, and polling for approval status during active runs
- 216cf181: remove workflow token elevation; approved pushes pass
through directly without proxy token rewriting
- 3dbc0282: preserve plan redirects after login by accepting relative
same-origin redirect_to values and rejecting blocked paths
- bb104d93: submit plan comments with cmd+enter
- 90cb6caa: terse Slack replies, shared content via save_plan outside
plan mode (PLAN_STATUS_SHARED), reject shared-content mutations
Refs: #135
* fix: restore login page render and clear CI lint/format
The plan-review port removed the authRedirectUrl import from login.tsx
but left its call site, crashing the login page at runtime (blank page,
no 'Sign in to open-swe'). Pass the relative path straight to loginUrl,
matching the plan route and the backend relative-redirect handling.
Also drop an unused os import in the guard test and reformat
workflow_push_guard.py to satisfy ruff.
* fix: carry workflows:write on the standing proxy token
Complete the half-ported upstream 216cf181 cascade. The port dropped
_run_with_workflow_token from the guard but missed the paired github_app
change, so an approved .github/workflows push ran with the base token
(no workflows:write) and GitHub 403'd it.
Add workflows:write to BASE_RUNTIME_PROXY_TOKEN_PERMISSIONS and delete the
now-orphaned WORKFLOW_RUNTIME_PROXY_TOKEN_PERMISSIONS constant; update the
github_app and proxy_auth tests to match. The HITL approval gate in
workflow_push_guard.py is unchanged — this only lets the standing token
push once a human approves.
* fix: restore transient workflow-token elevation (revert standing workflows:write)
The standing GitHub-App proxy token (BASE_RUNTIME_PROXY_TOKEN_PERMISSIONS) is
ALWAYS-ON, so carrying workflows:write on it made the fork's HITL workflow-push
guard the sole control over unapproved workflow pushes. The guard's git-push
parser has gaps (obfuscated-expansion push, `gh api` REST contents PUT,
fully-qualified cross-branch refspecs); with a permanently workflows-scoped
token those gaps become live unapproved-workflow-push exploits (1 critical, 2
high — security review BLOCK on #159).
Restore dev's transient-elevation model:
- Drop workflows:write from BASE_RUNTIME_PROXY_TOKEN_PERMISSIONS; re-add the
WORKFLOW_RUNTIME_PROXY_TOKEN_PERMISSIONS constant (base + workflows:write).
- Re-introduce _run_with_workflow_token in the guard: it mints the
workflows-scoped token via refresh_proxy_token around the approved,
guard-normalized fixed_command, then downscopes to RUNTIME then BASE in a
finally. Route the approval branch through it.
- Restore the dev token/elevation tests.
The standing token no longer carries workflows:write, so the three parser
bypasses hit GitHub 403 again; an approved push still succeeds because the
elevation grants workflows:write only around the normalized command. Keeps all
of #159's diff-preview / approval-URL / Slack-card guard additions.
* fix: reject protocol-relative path from sanitizeAuthRedirect (open redirect)
sanitizeAuthRedirect returned parsed.pathname+search+hash, which `new URL` can
resolve to a protocol-relative `//host` (e.g. input `/..//evil.com` normalizes
same-origin, passing the origin check, but yields a path starting with `//`).
ClientRedirect / login.tsx feed that path to window.location.replace, so it
navigates cross-origin — an open redirect. Reject any resolved path that is not
a single-leading-slash path (`^/[^/]`), falling back to the default. Adds
coverage for `/..//evil.com`, `/.//evil.com`, and `//evil.com`.
* fix: log SECURITY error when workflow-token downscope fails
The elevate->push->downscope finally block was silent on failure. If both
refresh_proxy_token calls fail, the sandbox retains workflows:write for the
rest of the run with no signal. Log a SECURITY error on the partial and full
downscope-failure paths so the retention is observable.
Addresses the GPT-4.1 cross-family review of the token-scope remediation.
---------
Co-authored-by: amoussa1229 <166072409+amoussa1229@users.noreply.github.com>
Co-authored-by: Adam Moussa <adam@seahavenind.com>
2026-07-09 16:03:13 -04:00
| `c03a6be7` | #1634 | keep plan guidance high-level | Landed | | plan-approval |
2026-07-08 19:02:09 -04:00
| `96cceb74` | #1632 | notify Slack on plan approval | Landed | ported (adapted) in #128 | plan-approval |
2026-07-08 19:27:31 -04:00
| `2f56d754` | #1618 | omit plan link when no plan exists | Landed | already in dev via #81 (upstream-sync); ledger was stale (was: likely regression) | plan-approval |
2026-07-03 15:51:31 -04:00
| `ee224d3e` | #1650 | add Slack reaction tool | Landed | | slack-tooling |
| `747ce4bb` | #1638 | add Slack breakout thread tool | Landed | | slack-tooling |
| `27d90ef1` | #1633 | include Slack channel context in prompts | Landed | | slack-tooling |
2026-07-08 19:02:09 -04:00
| `92dbf6f9` | #1630 | update Slack trace reply on web handoff | Landed | ported in #128 (trace_message_ts on first-mention run mapping) | slack-tooling |
2026-07-03 15:51:31 -04:00
| `bb36448b` | #1627 | surface Slack thread errors | Landed | | slack-tooling |
feat: port LangSmith LLM Gateway routing from upstream (#1671, #1673, #1674, #1678) (#155)
* feat: port LangSmith LLM Gateway routing from upstream (#1671, #1673, #1674, #1678)
Ports four upstream commits that add opt-in LLM call routing through the
LangSmith Gateway, preserving fork conventions (Bedrock/Fireworks model IDs,
no-agent-attribution, bun toolchain).
- #1671 (e9dc6e01): opt-in gateway routing — new gateway.py, team-settings
toggle, admin UI section, wired into make_model for all graph entrypoints
- #1673 (702ef908): dedicated LANGSMITH_GATEWAY_API_KEY precedence over
platform LANGSMITH_API_KEY
- #1674 (5f7c2f46): fix Fireworks gateway base URL to /fireworks (bare host,
SDK appends /v1/chat/completions) + SanitizeFireworksMessagesMiddleware
- #1678 (73b7d1c0): fix OpenAI Responses reasoning replay —
SanitizeOpenAIResponsesMiddleware, store/include config for encrypted
reasoning content, reasoning_effort coercion for Chat Completions fallback
Refs #134
* fix: downgrade gateway not-routed log to debug, add Bedrock UI note, add sanitizer parity
- Downgrade logger.warning to logger.debug in gateway_overrides for
not-routed providers and missing API key (Bedrock is the default
provider in this fork, so these are expected steady states)
- Add Bedrock to the LLMGatewaySection route-toggle description so
admins know it is not routed through the gateway
- Add SanitizeOpenAIResponsesMiddleware to chat.py for parity with
server.py and reviewer.py
- Restore the Bedrock region comment in model.py that explains the
AWS_REGION / AWS_DEFAULT_REGION precedence
Refs #138
---------
Co-authored-by: amoussa1229 <166072409+amoussa1229@users.noreply.github.com>
2026-07-09 14:44:15 -04:00
| `73b7d1c0` | #1678 | fix OpenAI Responses reasoning replay | Landed | | gateway-routing |
| `5f7c2f46` | #1674 | fix Fireworks Gateway base URL | Landed | | gateway-routing |
| `702ef908` | #1673 | dedicated LangSmith gateway API key | Landed | | gateway-routing |
| `e9dc6e01` | #1671 | opt-in LangSmith LLM Gateway routing | Landed | | gateway-routing |
2026-07-03 11:46:00 -04:00
| `289f5e3a` | #1651 | add Sonnet 5 to model picker | Landed | already in dev; added Bedrock family fallback fix (c16fb915) | gateway-routing |
2026-07-08 19:02:09 -04:00
| `5da3d0c6` | #1624 | post reviewer resolution notes verbatim | Landed | cherry-picked (-x) in #127 | reviewer-misc |
| `69148f54` | #1612 | add PR trace resolution | Landed | cherry-picked (-x) in #127 | reviewer-misc |
| `6d125526` | #1625 | stop wrapping installs in sfw | Landed | already present in dev; empty pick confirmed in #127 | reviewer-misc |
| `320bb39a` | #1657 | opt-in tracemalloc for aiohttp sessions | Landed | cherry-picked (-x) in #127 | reviewer-misc |
| `4f913198` | #1647 | widen split review diffs | Landed | already present in dev; empty pick confirmed in #127 | reviewer-misc |
2026-07-08 19:27:31 -04:00
| `20f63e8c` | #1646 | install missing deps before verification | Landed | already in dev via #81 (upstream-sync); ledger was stale | prompt-tweaks |
2026-07-08 19:02:09 -04:00
| `2f237b53` | #1626 | fall back to vision model for image threads | Landed | ported (adapted to Bedrock/Fireworks vision) in #128 | gateway-routing |
2026-07-17 12:36:30 -04:00
| `48217b68` | #1489 | feat(open-swe): add E2B sandbox provider (#1489 ) | Landed | re-implemented on fork's sync create_sandbox factory in #199 (E2B SDK is sync; async base not needed); langchain-e2b==0.0.4; dark-safe; GitHub proxy/App-token flow untouched | feat/port-1489-e2b-provider |
2026-07-10 13:00:12 -04:00
| `fbc6de85` | #1667 | chore(deps): bump fireworks-ai from 1.2.0a75 to 1.2.0a86 (#1667 ) | Landed | Superseded by #158 (fireworks-ai a85 -> a88, efeb6b12); dev already exceeds a86. No port needed. | deps |
feat: port model-fallback resilience from upstream (#1694, #1695) (#161)
* feat: port plan-review & workflow-approval UX (#135)
Port six upstream commits onto dev:
- c03a6be7 (already ported): keep plan guidance high-level
- 546042a4: add workflow approval UI with diff preview, approval URLs,
web review links, and polling for approval status during active runs
- 216cf181: remove workflow token elevation; approved pushes pass
through directly without proxy token rewriting
- 3dbc0282: preserve plan redirects after login by accepting relative
same-origin redirect_to values and rejecting blocked paths
- bb104d93: submit plan comments with cmd+enter
- 90cb6caa: terse Slack replies, shared content via save_plan outside
plan mode (PLAN_STATUS_SHARED), reject shared-content mutations
Refs: #135
* feat: port durable dispatch hardening and startup latency improvements
Port five upstream PRs onto dev:
- #1621 / #1658: durable dispatch with loopback webhook defense,
create_durable_run helper, _config_with_prepare_run_id, degradation
to None for relative/loopback completion webhook URLs
- #1696: run-level completion webhook deduplication (replace
claim-then-post with post-then-flag per run_id), DeferredErrorModel
for graph-factory resilience, ToolRetryMiddleware for task subagents,
TimeoutWrapupMiddleware for all three graphs
- #1697: lazy-load __init__.py for agent.middleware, agent.tools,
agent.dashboard (PEP 562); defer heavy imports (exa_py in web_search,
agent.webapp in request_pr_review, deepagents in sandbox.py); add
ttl_cache.py with stale-while-revalidate for tool loaders
Refs: #137
* fix: restore login page render and clear CI lint/format
The plan-review port removed the authRedirectUrl import from login.tsx
but left its call site, crashing the login page at runtime (blank page,
no 'Sign in to open-swe'). Pass the relative path straight to loginUrl,
matching the plan route and the backend relative-redirect handling.
Also drop an unused os import in the guard test and reformat
workflow_push_guard.py to satisfy ruff.
* feat: port model-fallback resilience from upstream (#1694, #1695)
- Add httpx.TransportError to the transient-exception set so
incomplete chunked reads on streamed responses trigger a
fallback instead of cancelling the run (#1694 / c9f6dd86).
- Rewrite fallback to alternate primary/fallback with exponential
backoff instead of a single failover, so the agent survives
multi-minute gateway outages spanning both providers (#1695 /
c9a9a7cd).
- Default backoff schedule (0, 5, 15, 30, 45) reaches past the
gateway's ~30s recovery window; jittered ±25%.
- On exhaustion, surface a terminal AIMessage explaining the
outage instead of crashing — progress is checkpointed so the
user can retrigger to continue.
- Preserve fork conventions: Bedrock ClientError retryability
check, sync wrap_model_call (using time.sleep instead of
asyncio.sleep), and existing access-error surfacing for
Anthropic, OpenAI, and Bedrock (botocore) provider errors.
- Update triage ledger (c9f6dd86, c9a9a7cd → landed) and
re-render triage.md.
Refs: #139
* fix: align workflow-push-guard tests with dev's transient-elevation impl
The dev merge auto-combined dev's elevation tests with the stale passthrough
tests inherited from the durable-dispatch branch; the passthrough tests
contradict dev's restored _run_with_workflow_token impl. Take dev's test file.
* fix: drop dead ttl_cache module; make fallback backoff jitter two-sided
ttl_cache.py was re-introduced via the dev merge but dev/#160 deliberately
removed it as dead code (no agent importer). Remove it to match dev.
Also make _jittered_delay symmetric (±25%) to match its docstring.
* chore(upstream-sync): triage 4 new upstream commits (#1708-#1713)
Synced ledger to upstream/main (71e3b818). New rows all deferred:
- #1708 add GPT-5.6 OpenAI models (FLAG-HUMAN: fork picker is Bedrock/Fireworks-only)
- #1709 stale admin model defaults after upgrades
- #1710 bump langchain-fireworks 1.4.4
- #1713 align reviewer eval with published findings
---------
Co-authored-by: amoussa1229 <166072409+amoussa1229@users.noreply.github.com>
Co-authored-by: Adam Moussa <adam@seahavenind.com>
2026-07-09 18:28:21 -04:00
| `c9f6dd86` | #1694 | fix: fall back on model stream transport errors (#1694 ) | Landed | adds httpx.TransportError to transient set; small conflict w/ dev's diverged Bedrock fallback | model-fallback |
| `c9a9a7cd` | #1695 | fix: retry model fallback exhaustion (#1695 ) | Landed | alternating retry+backoff rewrite; reconcile by hand w/ dev's Bedrock + sync wrap path | model-fallback |
feat: port durable dispatch hardening and startup latency improvements (#160)
* feat: port plan-review & workflow-approval UX (#135)
Port six upstream commits onto dev:
- c03a6be7 (already ported): keep plan guidance high-level
- 546042a4: add workflow approval UI with diff preview, approval URLs,
web review links, and polling for approval status during active runs
- 216cf181: remove workflow token elevation; approved pushes pass
through directly without proxy token rewriting
- 3dbc0282: preserve plan redirects after login by accepting relative
same-origin redirect_to values and rejecting blocked paths
- bb104d93: submit plan comments with cmd+enter
- 90cb6caa: terse Slack replies, shared content via save_plan outside
plan mode (PLAN_STATUS_SHARED), reject shared-content mutations
Refs: #135
* feat: port durable dispatch hardening and startup latency improvements
Port five upstream PRs onto dev:
- #1621 / #1658: durable dispatch with loopback webhook defense,
create_durable_run helper, _config_with_prepare_run_id, degradation
to None for relative/loopback completion webhook URLs
- #1696: run-level completion webhook deduplication (replace
claim-then-post with post-then-flag per run_id), DeferredErrorModel
for graph-factory resilience, ToolRetryMiddleware for task subagents,
TimeoutWrapupMiddleware for all three graphs
- #1697: lazy-load __init__.py for agent.middleware, agent.tools,
agent.dashboard (PEP 562); defer heavy imports (exa_py in web_search,
agent.webapp in request_pr_review, deepagents in sandbox.py); add
ttl_cache.py with stale-while-revalidate for tool loaders
Refs: #137
* fix: restore login page render and clear CI lint/format
The plan-review port removed the authRedirectUrl import from login.tsx
but left its call site, crashing the login page at runtime (blank page,
no 'Sign in to open-swe'). Pass the relative path straight to loginUrl,
matching the plan route and the backend relative-redirect handling.
Also drop an unused os import in the guard test and reformat
workflow_push_guard.py to satisfy ruff.
* fix: restore RepairOrphaned middleware export and repoint model fake to deferred_model boundary
* fix: restore RepairOrphanedToolCallsMiddleware, fix E2E model-fake patch, drop dead ttl_cache
- Re-add RepairOrphanedToolCallsMiddleware to the lazy middleware __init__
(_MIDDLEWARE_MODULES, __all__, TYPE_CHECKING) so agent.reviewer can import it.
- Reroute E2E model patching to deferred_model.make_model so make_model_or_defer
(used by all three graph factories) returns the scripted fake instead of
building a real model with fake credentials.
- Drop unused agent/utils/ttl_cache.py — no agent module imports it.
- Fix import ordering in agent/reviewer.py and agent/analyzer.py (ruff I001).
- Format tests/test_dispatch.py.
* fix: claim-then-post run-level failure dedup; stop permanent suppression
---------
Co-authored-by: amoussa1229 <166072409+amoussa1229@users.noreply.github.com>
Co-authored-by: Adam Moussa <adam@seahavenind.com>
2026-07-09 17:11:25 -04:00
| `e5dbc788` | #1696 | fix: Harden durable agent runs (#1696 ) | Landed | large durable-run hardening; 3 new modules dev lacks; rewrites fork dispatch/completion | durable-dispatch |
2026-07-08 19:02:09 -04:00
| `52fe2916` | #1698 | feat: add PR review link route (#1698 ) | Landed | cherry-picked (-x) in #127 (PR review link route) | reviewer-misc |
feat: port durable dispatch hardening and startup latency improvements (#160)
* feat: port plan-review & workflow-approval UX (#135)
Port six upstream commits onto dev:
- c03a6be7 (already ported): keep plan guidance high-level
- 546042a4: add workflow approval UI with diff preview, approval URLs,
web review links, and polling for approval status during active runs
- 216cf181: remove workflow token elevation; approved pushes pass
through directly without proxy token rewriting
- 3dbc0282: preserve plan redirects after login by accepting relative
same-origin redirect_to values and rejecting blocked paths
- bb104d93: submit plan comments with cmd+enter
- 90cb6caa: terse Slack replies, shared content via save_plan outside
plan mode (PLAN_STATUS_SHARED), reject shared-content mutations
Refs: #135
* feat: port durable dispatch hardening and startup latency improvements
Port five upstream PRs onto dev:
- #1621 / #1658: durable dispatch with loopback webhook defense,
create_durable_run helper, _config_with_prepare_run_id, degradation
to None for relative/loopback completion webhook URLs
- #1696: run-level completion webhook deduplication (replace
claim-then-post with post-then-flag per run_id), DeferredErrorModel
for graph-factory resilience, ToolRetryMiddleware for task subagents,
TimeoutWrapupMiddleware for all three graphs
- #1697: lazy-load __init__.py for agent.middleware, agent.tools,
agent.dashboard (PEP 562); defer heavy imports (exa_py in web_search,
agent.webapp in request_pr_review, deepagents in sandbox.py); add
ttl_cache.py with stale-while-revalidate for tool loaders
Refs: #137
* fix: restore login page render and clear CI lint/format
The plan-review port removed the authRedirectUrl import from login.tsx
but left its call site, crashing the login page at runtime (blank page,
no 'Sign in to open-swe'). Pass the relative path straight to loginUrl,
matching the plan route and the backend relative-redirect handling.
Also drop an unused os import in the guard test and reformat
workflow_push_guard.py to satisfy ruff.
* fix: restore RepairOrphaned middleware export and repoint model fake to deferred_model boundary
* fix: restore RepairOrphanedToolCallsMiddleware, fix E2E model-fake patch, drop dead ttl_cache
- Re-add RepairOrphanedToolCallsMiddleware to the lazy middleware __init__
(_MIDDLEWARE_MODULES, __all__, TYPE_CHECKING) so agent.reviewer can import it.
- Reroute E2E model patching to deferred_model.make_model so make_model_or_defer
(used by all three graph factories) returns the scripted fake instead of
building a real model with fake credentials.
- Drop unused agent/utils/ttl_cache.py — no agent module imports it.
- Fix import ordering in agent/reviewer.py and agent/analyzer.py (ruff I001).
- Format tests/test_dispatch.py.
* fix: claim-then-post run-level failure dedup; stop permanent suppression
---------
Co-authored-by: amoussa1229 <166072409+amoussa1229@users.noreply.github.com>
Co-authored-by: Adam Moussa <adam@seahavenind.com>
2026-07-09 17:11:25 -04:00
| `5f7f5fbd` | #1697 | fix: Reduce graph import and loader startup latency (#1697 ) | Landed | import-hygiene refactor; cross-cutting, references many deferred upstream-only modules | durable-dispatch |
feat: port plan-review & workflow-approval UX (#159)
* feat: port plan-review & workflow-approval UX (#135)
Port six upstream commits onto dev:
- c03a6be7 (already ported): keep plan guidance high-level
- 546042a4: add workflow approval UI with diff preview, approval URLs,
web review links, and polling for approval status during active runs
- 216cf181: remove workflow token elevation; approved pushes pass
through directly without proxy token rewriting
- 3dbc0282: preserve plan redirects after login by accepting relative
same-origin redirect_to values and rejecting blocked paths
- bb104d93: submit plan comments with cmd+enter
- 90cb6caa: terse Slack replies, shared content via save_plan outside
plan mode (PLAN_STATUS_SHARED), reject shared-content mutations
Refs: #135
* fix: restore login page render and clear CI lint/format
The plan-review port removed the authRedirectUrl import from login.tsx
but left its call site, crashing the login page at runtime (blank page,
no 'Sign in to open-swe'). Pass the relative path straight to loginUrl,
matching the plan route and the backend relative-redirect handling.
Also drop an unused os import in the guard test and reformat
workflow_push_guard.py to satisfy ruff.
* fix: carry workflows:write on the standing proxy token
Complete the half-ported upstream 216cf181 cascade. The port dropped
_run_with_workflow_token from the guard but missed the paired github_app
change, so an approved .github/workflows push ran with the base token
(no workflows:write) and GitHub 403'd it.
Add workflows:write to BASE_RUNTIME_PROXY_TOKEN_PERMISSIONS and delete the
now-orphaned WORKFLOW_RUNTIME_PROXY_TOKEN_PERMISSIONS constant; update the
github_app and proxy_auth tests to match. The HITL approval gate in
workflow_push_guard.py is unchanged — this only lets the standing token
push once a human approves.
* fix: restore transient workflow-token elevation (revert standing workflows:write)
The standing GitHub-App proxy token (BASE_RUNTIME_PROXY_TOKEN_PERMISSIONS) is
ALWAYS-ON, so carrying workflows:write on it made the fork's HITL workflow-push
guard the sole control over unapproved workflow pushes. The guard's git-push
parser has gaps (obfuscated-expansion push, `gh api` REST contents PUT,
fully-qualified cross-branch refspecs); with a permanently workflows-scoped
token those gaps become live unapproved-workflow-push exploits (1 critical, 2
high — security review BLOCK on #159).
Restore dev's transient-elevation model:
- Drop workflows:write from BASE_RUNTIME_PROXY_TOKEN_PERMISSIONS; re-add the
WORKFLOW_RUNTIME_PROXY_TOKEN_PERMISSIONS constant (base + workflows:write).
- Re-introduce _run_with_workflow_token in the guard: it mints the
workflows-scoped token via refresh_proxy_token around the approved,
guard-normalized fixed_command, then downscopes to RUNTIME then BASE in a
finally. Route the approval branch through it.
- Restore the dev token/elevation tests.
The standing token no longer carries workflows:write, so the three parser
bypasses hit GitHub 403 again; an approved push still succeeds because the
elevation grants workflows:write only around the normalized command. Keeps all
of #159's diff-preview / approval-URL / Slack-card guard additions.
* fix: reject protocol-relative path from sanitizeAuthRedirect (open redirect)
sanitizeAuthRedirect returned parsed.pathname+search+hash, which `new URL` can
resolve to a protocol-relative `//host` (e.g. input `/..//evil.com` normalizes
same-origin, passing the origin check, but yields a path starting with `//`).
ClientRedirect / login.tsx feed that path to window.location.replace, so it
navigates cross-origin — an open redirect. Reject any resolved path that is not
a single-leading-slash path (`^/[^/]`), falling back to the default. Adds
coverage for `/..//evil.com`, `/.//evil.com`, and `//evil.com`.
* fix: log SECURITY error when workflow-token downscope fails
The elevate->push->downscope finally block was silent on failure. If both
refresh_proxy_token calls fail, the sandbox retains workflows:write for the
rest of the run with no signal. Log a SECURITY error on the partial and full
downscope-failure paths so the retention is observable.
Addresses the GPT-4.1 cross-family review of the token-scope remediation.
---------
Co-authored-by: amoussa1229 <166072409+amoussa1229@users.noreply.github.com>
Co-authored-by: Adam Moussa <adam@seahavenind.com>
2026-07-09 16:03:13 -04:00
| `216cf181` | #1699 | fix: keep workflow HITL without token downscoping (#1699 ) | Landed | DIVERGES-FROM-UPSTREAM: fork deliberately does NOT adopt #1699 's standing-token workflows:write broadening. Security review (#159 ) BLOCKed it — the standing ALWAYS-ON proxy token carrying workflows:write turns the HITL guard's git-push-parser gaps (obfuscated-expansion push, `gh api` REST contents PUT, cross-branch refspecs) into live unapproved-workflow-push exploits. Fork keeps BASE without workflows:write and restores the transient per-approval elevation (_run_with_workflow_token mints WORKFLOW_RUNTIME_PROXY_TOKEN_PERMISSIONS around the approved, guard-normalized fixed_command, then downscopes to RUNTIME then BASE): the token scope is the backstop the parser relies on, so a bypass hits GitHub 403. HITL diff-preview/approval-URL/Slack-card additions from #159 retained; token-model divergence only. | plan-approval |
feat: surface attributed PR creation failures (#180)
* feat: surface attributed PR creation failures
Port upstream #1659: adds PullRequestCreationGuardMiddleware that
blocks shell fallbacks (gh pr create, gh api /pulls, curl) when
open_pull_request fails, keeping failures visible. Also adds preflight
branch/repo visibility checks in open_pull_request with structured
failure payloads, and updates the prompt to forbid PR creation
fallbacks.
Refs: #134
* fix: fall back to core GitHub App scope when optional grants missing (#1701)
* fix: fall back to core GitHub App scope when optional grants missing
Proxy-token minting requested workflows:write and actions:read in the
permission set used for every sandbox. GitHub 422s a token request that
asks for a permission the installation hasn't granted, so any install
without workflows:write failed to mint a token and every run died in
before-agent setup with "GitHub App installation token is unavailable".
_resolve_proxy_token now walks a permission ladder (full -> +workflows ->
core) and returns the first scope that mints, recording the granted scope
so hourly proxy refreshes stay consistent. A missing optional grant now
degrades to the install-time core scope instead of failing the run;
workflow-file HITL pushes still require workflows:write and fail at push
time when it is absent.
* refactor: flatten proxy-token ladder loop with continue
---------
Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>
(cherry picked from commit f53caff1aa24a7b29d851b267aa3bdfe62c1e935)
Sea Haven fork deviation: upstream #1701 folds workflows:write into the
standing BASE/RUNTIME scope. This fork deliberately keeps workflows:write
OUT of the standing permission ladder (RUNTIME = core + actions:read;
LADDER = (RUNTIME, CORE)) so the sandbox proxy token cannot push
.github/workflows/* during normal operation. workflows:write is minted only
transiently by WorkflowPushGuardMiddleware for an approved HITL push and
dropped on restore, preserving token scope as a backstop for the workflow-
push approval control. Security-reviewed (agentic fan-out + GPT-4.1 cross
review); the standing-scope-carries-workflows:write bypass was blocked.
* fix(open-swe): harden proxy-token restore and mint error handling
Two low-severity follow-ups from the security review of the #1701 port.
Restore the recorded baseline scope after a workflow-push elevation instead
of a hardcoded RUNTIME. An install granted workflows:write but not actions:read
resolves its standing token to core; hardcoding RUNTIME on restore requested the
ungranted actions:read, 422'd, and fired a false "SECURITY: failed to downscope"
error on every approved workflow push before the core fallback recovered. The
guard now captures the run's recorded scope before elevating (via the new
get_recorded_proxy_permissions) and restores exactly that, falling back to the
guaranteed core scope only when the baseline restore fails.
Classify installation-token mint failures. get_github_app_installation_token_
with_expiry now treats HTTP 422 (a permission the installation hasn't granted)
as the ladder's expected descend signal and keeps it at debug, while a non-422
failure (network/5xx/timeout) is surfaced at WARNING even when errors are
otherwise suppressed — so a transient blip no longer silently downscopes a whole
run under a debug-only trace. The reduced-scope warning no longer asserts a
missing grant as the sole cause.
* chore(triage): mark upstream #1701 landed on this branch
Ported via PR #181 as Option A (workflows:write kept out of the standing
proxy-token scope). Regenerated triage.md from triage.jsonl.
* fix: restructure PR creation to POST-first with diagnose-on-failure
Move preflight checks from an authoritative gate (before POST) to a
diagnostic run after POST failure. This avoids false-positive failures
when a just-pushed head branch is momentarily invisible to GitHub ref
endpoints, and eliminates 2-3 extra serial API round-trips on the happy
path.
Also drop unused _PR_CREATED_FALSE indirection and add a docstring to
pr_creation_guard acknowledging the fail-open detection design.
---------
Co-authored-by: amoussa1229 <166072409+amoussa1229@users.noreply.github.com>
Co-authored-by: Ramon Nogueira <ramon.nogueira@langchain.dev>
Co-authored-by: Adam Moussa <adam@seahavenind.com>
2026-07-13 14:45:19 -04:00
| `67abf5b0` | #1659 | fix: surface attributed PR creation failures (#1659 ) | Landed | PR-attribution-failure guard (new mw, safe imports); heavy conflict on diverged open_pull_request.py | pr-attribution |
feat: port plan-review & workflow-approval UX (#159)
* feat: port plan-review & workflow-approval UX (#135)
Port six upstream commits onto dev:
- c03a6be7 (already ported): keep plan guidance high-level
- 546042a4: add workflow approval UI with diff preview, approval URLs,
web review links, and polling for approval status during active runs
- 216cf181: remove workflow token elevation; approved pushes pass
through directly without proxy token rewriting
- 3dbc0282: preserve plan redirects after login by accepting relative
same-origin redirect_to values and rejecting blocked paths
- bb104d93: submit plan comments with cmd+enter
- 90cb6caa: terse Slack replies, shared content via save_plan outside
plan mode (PLAN_STATUS_SHARED), reject shared-content mutations
Refs: #135
* fix: restore login page render and clear CI lint/format
The plan-review port removed the authRedirectUrl import from login.tsx
but left its call site, crashing the login page at runtime (blank page,
no 'Sign in to open-swe'). Pass the relative path straight to loginUrl,
matching the plan route and the backend relative-redirect handling.
Also drop an unused os import in the guard test and reformat
workflow_push_guard.py to satisfy ruff.
* fix: carry workflows:write on the standing proxy token
Complete the half-ported upstream 216cf181 cascade. The port dropped
_run_with_workflow_token from the guard but missed the paired github_app
change, so an approved .github/workflows push ran with the base token
(no workflows:write) and GitHub 403'd it.
Add workflows:write to BASE_RUNTIME_PROXY_TOKEN_PERMISSIONS and delete the
now-orphaned WORKFLOW_RUNTIME_PROXY_TOKEN_PERMISSIONS constant; update the
github_app and proxy_auth tests to match. The HITL approval gate in
workflow_push_guard.py is unchanged — this only lets the standing token
push once a human approves.
* fix: restore transient workflow-token elevation (revert standing workflows:write)
The standing GitHub-App proxy token (BASE_RUNTIME_PROXY_TOKEN_PERMISSIONS) is
ALWAYS-ON, so carrying workflows:write on it made the fork's HITL workflow-push
guard the sole control over unapproved workflow pushes. The guard's git-push
parser has gaps (obfuscated-expansion push, `gh api` REST contents PUT,
fully-qualified cross-branch refspecs); with a permanently workflows-scoped
token those gaps become live unapproved-workflow-push exploits (1 critical, 2
high — security review BLOCK on #159).
Restore dev's transient-elevation model:
- Drop workflows:write from BASE_RUNTIME_PROXY_TOKEN_PERMISSIONS; re-add the
WORKFLOW_RUNTIME_PROXY_TOKEN_PERMISSIONS constant (base + workflows:write).
- Re-introduce _run_with_workflow_token in the guard: it mints the
workflows-scoped token via refresh_proxy_token around the approved,
guard-normalized fixed_command, then downscopes to RUNTIME then BASE in a
finally. Route the approval branch through it.
- Restore the dev token/elevation tests.
The standing token no longer carries workflows:write, so the three parser
bypasses hit GitHub 403 again; an approved push still succeeds because the
elevation grants workflows:write only around the normalized command. Keeps all
of #159's diff-preview / approval-URL / Slack-card guard additions.
* fix: reject protocol-relative path from sanitizeAuthRedirect (open redirect)
sanitizeAuthRedirect returned parsed.pathname+search+hash, which `new URL` can
resolve to a protocol-relative `//host` (e.g. input `/..//evil.com` normalizes
same-origin, passing the origin check, but yields a path starting with `//`).
ClientRedirect / login.tsx feed that path to window.location.replace, so it
navigates cross-origin — an open redirect. Reject any resolved path that is not
a single-leading-slash path (`^/[^/]`), falling back to the default. Adds
coverage for `/..//evil.com`, `/.//evil.com`, and `//evil.com`.
* fix: log SECURITY error when workflow-token downscope fails
The elevate->push->downscope finally block was silent on failure. If both
refresh_proxy_token calls fail, the sandbox retains workflows:write for the
rest of the run with no signal. Log a SECURITY error on the partial and full
downscope-failure paths so the retention is observable.
Addresses the GPT-4.1 cross-family review of the token-scope remediation.
---------
Co-authored-by: amoussa1229 <166072409+amoussa1229@users.noreply.github.com>
Co-authored-by: Adam Moussa <adam@seahavenind.com>
2026-07-09 16:03:13 -04:00
| `3dbc0282` | #1676 | fix: preserve plan redirects after login (#1676 ) | Landed | FLAG-HUMAN: follow-on to landed #1668 refining sanitize_redirect_to (open-redirect auth surface); not a dup | plan-approval |
2026-07-10 14:05:20 -04:00
| `c75cbb1f` | #1677 | feat: re-add Fable 5 with an admin toggle to disable it (#1677 ) | Landed | Ported + Bedrock-converted onto dev via feat/readd-fable5-bedrock; anthropic: Fable ID mapped to bedrock_converse:us.anthropic.claude-fable-5. | fable-admin-toggle |
feat: port plan-review & workflow-approval UX (#159)
* feat: port plan-review & workflow-approval UX (#135)
Port six upstream commits onto dev:
- c03a6be7 (already ported): keep plan guidance high-level
- 546042a4: add workflow approval UI with diff preview, approval URLs,
web review links, and polling for approval status during active runs
- 216cf181: remove workflow token elevation; approved pushes pass
through directly without proxy token rewriting
- 3dbc0282: preserve plan redirects after login by accepting relative
same-origin redirect_to values and rejecting blocked paths
- bb104d93: submit plan comments with cmd+enter
- 90cb6caa: terse Slack replies, shared content via save_plan outside
plan mode (PLAN_STATUS_SHARED), reject shared-content mutations
Refs: #135
* fix: restore login page render and clear CI lint/format
The plan-review port removed the authRedirectUrl import from login.tsx
but left its call site, crashing the login page at runtime (blank page,
no 'Sign in to open-swe'). Pass the relative path straight to loginUrl,
matching the plan route and the backend relative-redirect handling.
Also drop an unused os import in the guard test and reformat
workflow_push_guard.py to satisfy ruff.
* fix: carry workflows:write on the standing proxy token
Complete the half-ported upstream 216cf181 cascade. The port dropped
_run_with_workflow_token from the guard but missed the paired github_app
change, so an approved .github/workflows push ran with the base token
(no workflows:write) and GitHub 403'd it.
Add workflows:write to BASE_RUNTIME_PROXY_TOKEN_PERMISSIONS and delete the
now-orphaned WORKFLOW_RUNTIME_PROXY_TOKEN_PERMISSIONS constant; update the
github_app and proxy_auth tests to match. The HITL approval gate in
workflow_push_guard.py is unchanged — this only lets the standing token
push once a human approves.
* fix: restore transient workflow-token elevation (revert standing workflows:write)
The standing GitHub-App proxy token (BASE_RUNTIME_PROXY_TOKEN_PERMISSIONS) is
ALWAYS-ON, so carrying workflows:write on it made the fork's HITL workflow-push
guard the sole control over unapproved workflow pushes. The guard's git-push
parser has gaps (obfuscated-expansion push, `gh api` REST contents PUT,
fully-qualified cross-branch refspecs); with a permanently workflows-scoped
token those gaps become live unapproved-workflow-push exploits (1 critical, 2
high — security review BLOCK on #159).
Restore dev's transient-elevation model:
- Drop workflows:write from BASE_RUNTIME_PROXY_TOKEN_PERMISSIONS; re-add the
WORKFLOW_RUNTIME_PROXY_TOKEN_PERMISSIONS constant (base + workflows:write).
- Re-introduce _run_with_workflow_token in the guard: it mints the
workflows-scoped token via refresh_proxy_token around the approved,
guard-normalized fixed_command, then downscopes to RUNTIME then BASE in a
finally. Route the approval branch through it.
- Restore the dev token/elevation tests.
The standing token no longer carries workflows:write, so the three parser
bypasses hit GitHub 403 again; an approved push still succeeds because the
elevation grants workflows:write only around the normalized command. Keeps all
of #159's diff-preview / approval-URL / Slack-card guard additions.
* fix: reject protocol-relative path from sanitizeAuthRedirect (open redirect)
sanitizeAuthRedirect returned parsed.pathname+search+hash, which `new URL` can
resolve to a protocol-relative `//host` (e.g. input `/..//evil.com` normalizes
same-origin, passing the origin check, but yields a path starting with `//`).
ClientRedirect / login.tsx feed that path to window.location.replace, so it
navigates cross-origin — an open redirect. Reject any resolved path that is not
a single-leading-slash path (`^/[^/]`), falling back to the default. Adds
coverage for `/..//evil.com`, `/.//evil.com`, and `//evil.com`.
* fix: log SECURITY error when workflow-token downscope fails
The elevate->push->downscope finally block was silent on failure. If both
refresh_proxy_token calls fail, the sandbox retains workflows:write for the
rest of the run with no signal. Log a SECURITY error on the partial and full
downscope-failure paths so the retention is observable.
Addresses the GPT-4.1 cross-family review of the token-scope remediation.
---------
Co-authored-by: amoussa1229 <166072409+amoussa1229@users.noreply.github.com>
Co-authored-by: Adam Moussa <adam@seahavenind.com>
2026-07-09 16:03:13 -04:00
| `bb104d93` | #1679 | fix: submit plan comments with cmd enter (#1679 ) | Landed | applies clean but edits fork-diverged PlanReview.tsx (#130 ); needs UI/e2e validation — separate PR | plan-approval |
2026-07-13 13:16:26 -04:00
| `304032fa` | #1680 | chore: clarify question answering prompt (#1680 ) | Landed | reword Slack info-only answer guidance; conflicts w/ fork's customized Slack prompt | prompt-tweaks |
2026-07-13 15:17:00 -04:00
| `5003c953` | #1683 | feat: open Linear-triggered PRs as the triggering user (#1683 ) | Landed | FLAG-HUMAN: adds linear to resolve_github_token per-user OAuth branch (auth surface); depends on #1626 linear.py | feature/port-linear-pr-author |
2026-07-10 13:17:03 -04:00
| `feb7ac98` | #1689 | feat(web): surface thread sandbox ID with touch-friendly menu (#1689 ) | Landed | Ported to dev via feat/thread-sandbox-id-sidebar. | dashboard-ui |
2026-07-08 19:02:09 -04:00
| `7f7af715` | #1684 | feat: auto-load scoped AGENTS on reads (#1684 ) | Landed | ported in #129 (SubdirAgentsReadMiddleware) | subdir-agents |
| `88b62322` | #1685 | feat: add platform issue reporting tool (#1685 ) | Landed | ported in #129 (report_platform_issue tool) | small-tools |
feat: port plan-review & workflow-approval UX (#159)
* feat: port plan-review & workflow-approval UX (#135)
Port six upstream commits onto dev:
- c03a6be7 (already ported): keep plan guidance high-level
- 546042a4: add workflow approval UI with diff preview, approval URLs,
web review links, and polling for approval status during active runs
- 216cf181: remove workflow token elevation; approved pushes pass
through directly without proxy token rewriting
- 3dbc0282: preserve plan redirects after login by accepting relative
same-origin redirect_to values and rejecting blocked paths
- bb104d93: submit plan comments with cmd+enter
- 90cb6caa: terse Slack replies, shared content via save_plan outside
plan mode (PLAN_STATUS_SHARED), reject shared-content mutations
Refs: #135
* fix: restore login page render and clear CI lint/format
The plan-review port removed the authRedirectUrl import from login.tsx
but left its call site, crashing the login page at runtime (blank page,
no 'Sign in to open-swe'). Pass the relative path straight to loginUrl,
matching the plan route and the backend relative-redirect handling.
Also drop an unused os import in the guard test and reformat
workflow_push_guard.py to satisfy ruff.
* fix: carry workflows:write on the standing proxy token
Complete the half-ported upstream 216cf181 cascade. The port dropped
_run_with_workflow_token from the guard but missed the paired github_app
change, so an approved .github/workflows push ran with the base token
(no workflows:write) and GitHub 403'd it.
Add workflows:write to BASE_RUNTIME_PROXY_TOKEN_PERMISSIONS and delete the
now-orphaned WORKFLOW_RUNTIME_PROXY_TOKEN_PERMISSIONS constant; update the
github_app and proxy_auth tests to match. The HITL approval gate in
workflow_push_guard.py is unchanged — this only lets the standing token
push once a human approves.
* fix: restore transient workflow-token elevation (revert standing workflows:write)
The standing GitHub-App proxy token (BASE_RUNTIME_PROXY_TOKEN_PERMISSIONS) is
ALWAYS-ON, so carrying workflows:write on it made the fork's HITL workflow-push
guard the sole control over unapproved workflow pushes. The guard's git-push
parser has gaps (obfuscated-expansion push, `gh api` REST contents PUT,
fully-qualified cross-branch refspecs); with a permanently workflows-scoped
token those gaps become live unapproved-workflow-push exploits (1 critical, 2
high — security review BLOCK on #159).
Restore dev's transient-elevation model:
- Drop workflows:write from BASE_RUNTIME_PROXY_TOKEN_PERMISSIONS; re-add the
WORKFLOW_RUNTIME_PROXY_TOKEN_PERMISSIONS constant (base + workflows:write).
- Re-introduce _run_with_workflow_token in the guard: it mints the
workflows-scoped token via refresh_proxy_token around the approved,
guard-normalized fixed_command, then downscopes to RUNTIME then BASE in a
finally. Route the approval branch through it.
- Restore the dev token/elevation tests.
The standing token no longer carries workflows:write, so the three parser
bypasses hit GitHub 403 again; an approved push still succeeds because the
elevation grants workflows:write only around the normalized command. Keeps all
of #159's diff-preview / approval-URL / Slack-card guard additions.
* fix: reject protocol-relative path from sanitizeAuthRedirect (open redirect)
sanitizeAuthRedirect returned parsed.pathname+search+hash, which `new URL` can
resolve to a protocol-relative `//host` (e.g. input `/..//evil.com` normalizes
same-origin, passing the origin check, but yields a path starting with `//`).
ClientRedirect / login.tsx feed that path to window.location.replace, so it
navigates cross-origin — an open redirect. Reject any resolved path that is not
a single-leading-slash path (`^/[^/]`), falling back to the default. Adds
coverage for `/..//evil.com`, `/.//evil.com`, and `//evil.com`.
* fix: log SECURITY error when workflow-token downscope fails
The elevate->push->downscope finally block was silent on failure. If both
refresh_proxy_token calls fail, the sandbox retains workflows:write for the
rest of the run with no signal. Log a SECURITY error on the partial and full
downscope-failure paths so the retention is observable.
Addresses the GPT-4.1 cross-family review of the token-scope remediation.
---------
Co-authored-by: amoussa1229 <166072409+amoussa1229@users.noreply.github.com>
Co-authored-by: Adam Moussa <adam@seahavenind.com>
2026-07-09 16:03:13 -04:00
| `90cb6caa` | #1681 | feat: terse Slack replies, share long content via plan-review page (#1681 ) | Landed | terse Slack + long-content-via-plan-page; conflicts w/ fork prompt + diverged plan stack | plan-approval |
2026-07-13 14:24:37 -04:00
| `f53caff1` | #1701 | fix: fall back to core GitHub App scope when optional grants missing (#1701 ) | Landed | Ported as Option A: workflows:write kept OUT of standing scope, minted only transiently by the workflow-push guard (security-reviewed); PR #181 | chore/port-github-app-scope-fallback |
2026-07-16 15:28:35 -04:00
| `22e024cb` | #1704 | fix: link issue PRs and prompt repo conventions (#1704 ) | Landed | issue/PR linking + repo-convention prompt; clean but prompt-conflict risk vs #113 | chore/upstream-easy-picks |
2026-07-17 12:36:30 -04:00
| `62e0ca2d` | #1709 | fix: stale admin model defaults after model upgrades (#1709 ) | Landed | cherry-picked (-x) in #200 ; retired-model map converted to fork Bedrock/Fireworks IDs (Fable deliberately maps to Opus — provider-data-share gate; test-pinned); dropped #1708 -entangled profile tests | fix/port-1709-stale-model-defaults |
2026-07-16 16:55:13 -04:00
| `138ab9ec` | #1710 | fix: bump langchain-fireworks to 1.4.4 (#1710 ) | Landed | langchain-fireworks 1.4.4 adopted via fork Dependabot group PR #190 (dev now resolves langchain-fireworks==1.4.4); upstream commit not cherry-picked | deps |
2026-07-17 12:36:30 -04:00
| `71e3b818` | #1713 | fix: align reviewer eval with published findings (#1713 ) | Landed | cherry-picked (-x) in #201 ; reviewer.py + publish_review.py hand-reconciled into fork structure (kept sandbox/skills/middleware stack, kebab-case workflow, Bedrock eval default); publish_review cap param removed (tool-facing only) | fix/port-1713-reviewer-eval-alignment |
| `092abafa` | #1717 | fix: enforce terse Slack tool messages (#1717 ) | Landed | cherry-picked (-x) in #197 ; one test conflict resolved by adopting upstream's test (fork prompt now contains upstream text); follow-up to landed #1681 , not superseded by it | fix/port-1717-terse-slack-tool-msgs |
| `92d63170` | #1720 | fix: separate review access from automatic reviews (#1720 ) | Landed | cherry-picked (-x) in #198 + fork-only auto-fix gates renamed to _is_repo_auto_review_enabled (kept opt-in-gated); opt-in list now gates only AUTOMATIC reviews — manual/re-review/watch/finding-replies open to any App-installed repo. Adam signed off 2026-07-16; /sh-security-review explicitly waived by Adam 2026-07-16 | fix/port-1720-review-access-split |
docs: land reorg in ledger, fix path refs, ship plan artifacts (C7)
C7 of the domain-reorg adoption (build plan docs/upstream-sync/domain-reorg/
reorg-build-plan.md, step C7):
- CLAUDE.md / AGENTS.md: retarget architecture path references to the new
layout — graph entrypoints via agent.graphs.* shims, the agent/api/ +
agent/webhooks/*_routes.py FastAPI split (webapp.py now a shim),
agent/review/ package, tests/<domain>/ test paths, and the new-graph/
test conventions. README.md already pointed at docs/ (C1) — no change.
- triage.jsonl: flip 8356eb34 (#1726) to landed on branch
refactor/domain-reorg-adoption; add re-triage notes to the 8 unblocked
rows (#1732/#1761/#1744/#1748/#1742 clean, #1736/#1758/#1760 near-clean).
triage.md regenerated via make triage-render.
- Ship the plan, scoping report, move-map artifacts, and the
domain-reorg-adoption workflow so the exercise is reproducible.
Memory + Confluence handled out-of-band (not in this commit): project
memory updated with the new module layout; Confluence check found no IT
page documents the repo module map — no Confluence change required.
2026-07-17 15:01:45 -04:00
| `8356eb34` | #1726 | refactor: organize repository by domain (#1726 ) | Landed | Adopted as a file-move exercise (fork content, upstream layout) on branch refactor/domain-reorg-adoption — gate-approved plan in docs/upstream-sync/domain-reorg/. New layout: agent/{graphs,runtime,api,review,resources}, agent/webhooks/*_routes.py (webapp.py split into api/ + per-source route modules; webapp.py now a shim), tests/< domain > /, ui/src/features/. Kills the per-pick path-remap tax and unblocks 8 deferred rows (#1732/#1761/#1744/#1748/#1742 clean; #1736/#1758/#1760 near-clean). | refactor/domain-reorg-adoption |
2026-07-16 15:28:35 -04:00
| `129ddcf9` | #1728 | chore: include ripgrep in sandbox image (#1728 ) | Landed | 1-line Dockerfile add (ripgrep); dev image lacks it; trivial pick | chore/upstream-easy-picks |
| `1ea03a43` | #1729 | feat: include Cargo in sandbox image (#1729 ) | Landed | 2-line Dockerfile add (Cargo); adopt with #1728 | chore/upstream-easy-picks |
2026-07-16 16:05:03 -04:00
| `09eaf94c` | #1730 | fix: let admins interrupt runaway agents (#1730 ) | Landed | admin interrupt for runaway agents (dashboard route + UI); useful ops control; UI half on post-reorg ui/src/features — remap to ui/src/components/agents | feat/admin-thread-interrupt |
2026-07-17 17:31:54 -04:00
| `1ea0e600` | #1736 | fix: bind cached GitHub tokens to users (#1736 ) | Landed | Landed via fork PR #207 after both gates passed (GPT-4.1 cross-family: no BLOCK; /sh-security-review: 0 confirmed critical/high, 1 accepted low CWE-613). Composed with the fork's repo-binding: cache key (thread_id, principal), values keep bound_repo; unprincipaled user tokens refused. Added bot-fallback + cross-repo composition tests. | bug/bind-cached-github-tokens |
| `d714586c` | #1732 | fix: normalize dashboard label rendering (#1732 ) | Landed | Landed via fork PR #206 (clean cherry-pick). | feature/port-upstream-clean-batch |
| `3e8089c3` | #1744 | fix: collapse git panel by default (#1744 ) | Landed | Landed via fork PR #206 . One import-context conflict in AgentThreadView.tsx resolved (upstream moved panel prefs to ui/src/features/agents/lib/gitPanelPreferences.ts). | feature/port-upstream-clean-batch |
| `c34e04f4` | #1742 | fix: defensive copy in get_reviewer_agent and get_chat_agent [closes #1584 ] (#1742 ) | Landed | Landed via fork PR #206 (cherry-pick, authors reset). Two fork-only reviewer tests that relied on the pre-fix in-place config mutation updated to assert against the agent-bound config. | feature/port-upstream-clean-batch |
| `79df6b2f` | #1748 | feat: add Linear issue search tool (#1748 ) | Landed | Landed via fork PR #206 . Python auto-merged; fork's CLAUDE.md/AGENTS.md/README kept their own tool-list style with linear_search_issues inserted in place. | feature/port-upstream-clean-batch |
2026-07-16 15:28:35 -04:00
| `c69459ad` | #1751 | fix: prefer LangSmith tools for trace links (#1751 ) | Landed | 1-line prompt: prefer LangSmith tools for trace links; trivial but edits fork-customized prompt.py | chore/upstream-easy-picks |
| `5cb2e2bb` | #1750 | fix: add trace link to error banner (#1750 ) | Landed | adds trace link to error banner (13 lines); remap AgentThreadView.tsx path (fork: ui/src/components/agents/) | chore/upstream-easy-picks |
2026-07-17 17:31:54 -04:00
| `22383033` | #1758 | feat: inject extra JSON fields into sandbox create via env var (#1758 ) | Landed | Landed via fork PR #206 , re-implemented against the fork's sync SandboxClient (upstream is async AsyncSandboxClient — retry/reconnect helpers not adopted; future picks touching them will conflict). | feature/port-upstream-clean-batch |
| `e826864d` | #1760 | feat: optional separate LangSmith key/endpoint for sandboxes (#1760 ) | Landed | Landed via fork PR #206 on the sync client. Sandbox endpoint honors SANDBOX_LANGSMITH_ENDPOINT/LANGSMITH_ENDPOINT (LANGCHAIN_ENDPOINT alone no longer applies); new sandbox names thread-deterministic with _release_sandbox_name before create. | feature/port-upstream-clean-batch |
| `dd5b7bec` | #1761 | fix: capitalize dashboard tool labels (#1761 ) | Landed | Landed via fork PR #206 (clean cherry-pick, stacked on #1732 ). | feature/port-upstream-clean-batch |
2026-07-20 15:54:16 -04:00
| `b5e52925` | #1775 | feat: add structured Linear issue filters (#1775 ) | Landed | Clean pick: structured filters for linear_search_issues — stacks directly on #1748 (landed PR #206 ); zero fork drift on all three files. Ready whenever. | feature/upstream-clean-batch-security-linear |
| `31263f83` | #1785 | Fix: Fix Stored XSS in ReplyCard.tsx (#1785 ) | Landed | SECURITY priority, near-clean: diff is urlencode() hardening of the GitHub OAuth authorize URL in dashboard routes.py auth_login (upstream bot title says ReplyCard.tsx — mismatch, trust the diff). Fork auth_login has the identical f-string URL; hunk applies clean. Port promptly. | feature/upstream-clean-batch-security-linear |
| `3ea29d3f` | #1789 | Fix: Fix Improper privilege management in server.py (#1789 ) | Landed | SECURITY priority, near-clean: adds empty-signature reject to verify_github_signature (utils/github_comments.py) + verify_linear_signature (webhooks/common.py) (title says server.py — mismatch, trust the diff). Both fork functions match at the hunk sites; fork-only verify_jira_secret already guards empty token. Real value: None signature currently raises TypeError in compare_digest. Port BOTH hunks together. | feature/upstream-clean-batch-security-linear |
2026-07-24 18:49:53 -04:00
| `2e8ff4b7` | #1782 | chore: clarify shared response image guidance (#1782 ) | Landed | Landed via fork PR #226 | feature/upstream-clean-batch-jul21 |
| `4ea2441a` | #1791 | fix: match embedded review description background (#1791 ) | Landed | Landed via fork PR #226 | feature/upstream-clean-batch-jul21 |
| `75fb8b48` | #1786 | Fix PR creation guard shell bypasses (#1786 ) | Landed | Landed via fork PR #226 | feature/upstream-clean-batch-jul21 |
| `32e81f29` | #1788 | Fix: Fix Insecure Direct Object Reference in slack_start_new_thread.py (#1788 ) | Landed | Landed via fork PR #226 | feature/upstream-clean-batch-jul21 |
| `ab85b372` | #1764 | fix: add exc_info to swallowed exception in push re-review webhook (#1764 ) | Landed | Landed via fork PR #226 | feature/upstream-clean-batch-jul21 |
| `a77c4e47` | #1799 | fix: show current shared thread in sidebar (#1799 ) | Landed | Landed via fork PR #226 | feature/upstream-clean-batch-jul21 |
2026-07-03 11:46:00 -04:00
| `c3292d82` | #1611 | bake sfw binary into sandbox image | Won't merge | already in dev | |
| `48bf712b` | #1609 | show message timestamps | Won't merge | already in dev | |
| `85c0f63e` | #1620 | clickable shared PR header | Won't merge | already in dev | |
| `db2ae58e` | #1643 | pre-bundle shiki/@pierre deps | Won't merge | already in dev | |
| `1d9da064` | #1662 | bump astral-sh/setup-uv | Won't merge | dev ahead (v8.2.0, `checkout@v7` ) | |
| `83cb40a0` | #1616 | update langsmith sdk to 0.9.3 | Won't merge | regression — dev has 0.9.6 | |
| `e5a29eca` | #1613 | plan links in PR descriptions | Won't merge | regression — dev has async plan-ref | |
| `e1d85526` | #1645 | switch ui to pnpm | Won't merge | tooling — fork keeps bun | |
2026-07-17 12:36:30 -04:00
| `4cd5fa5c` | #1629 | avoid recapping Slack replies | Won't merge | already in dev — landed via sync PR #81 (1f060f2a), then deliberately superseded by the fork's refined Slack no-duplication rule in PR #159 (f87847ba) | |
| `baf0c248` | #1617 | filter & grouping menu in threads sidebar | Won't merge | already in dev — full feature present (sidebarFilter/sidebarPrefs/SidebarFilterMenu + AgentsSidebar wiring); only deltas are the later-landed #1661 token restyle | |
| `f29868ff` | #1615 | recover thread work as patch | Won't merge | already in dev via squash-sync PR #81 (1f060f2a) — recovery-patch vertical byte-identical to upstream; 6 recovery tests pass on dev | |
| `8e0788dc` | #1631 | show queued dashboard follow-ups | Won't merge | already in dev via squash-sync PR #81 (1f060f2a) — full queued-follow-ups vertical (types, QueuedMessages UI, streaming de-dupe, e2e) present and since evolved | |
| `9c601ca1` | #1648 | add Stagehand-powered browser subagent | Won't merge | requires Browserbase/Stagehand creds or Chromium-in-server-image + hard stagehand dep; browser runs in server process outside the sandbox; against fork curated-tools policy, no fork use case | |
| `8c944381` | #1622 | restore forced tool call | Won't merge | already in dev via squash-sync PR #81 (1f060f2a) — ensure_no_empty_msg middleware/tests/wiring/prompt line byte-identical to 8c944381; squash hid it from ancestry | |
2026-07-08 19:02:09 -04:00
| `5dc360d8` | #1619 | bump langgraph-checkpoint 4.1.0→4.1.1 | Won't merge | already in dev — uv.lock already resolves langgraph-checkpoint 4.1.1 | |
| `89f886e2` | #1642 | request actions read for sandbox logs | Won't merge | already in dev — actions:read in RUNTIME_PROXY_TOKEN_PERMISSIONS + identical prompt line | |
2026-07-17 12:36:30 -04:00
| `27f987dc` | #1686 | refactor: remove dead sync-interface compatibility code (#1686 ) | Won't merge | pure dead-sync-path deletion committing to the async-only posture the fork rejects; fork still uses get_sandbox_backend_sync; no embedded fix | |
| `2503a2f4` | #1687 | refactor(open-swe): provision LangSmith sandboxes natively async (#1687 ) | Won't merge | async pivot of create_sandbox/_configure_github_proxy (auth surface) — fork keeps sync lifecycle; langsmith bump subsumed by fork's 0.10.5 pin; metadata-await fix moot on fork's to_thread path | |
| `2529b109` | #1690 | fix: checkpoint per-run graph setup (#1690 ) | Won't merge | fork's get_agent re-runs idempotent setup by design (stateless), so the un-checkpointed-setup bug doesn't exist; faithful adaptation is a 4-graph rewrite presupposing the deferred async base | |
| `c0a7e93e` | #1691 | fix: reconnect sandbox backend on resumed runs (#1691 ) | Won't merge | fixes a #1690 -introduced regression (latched setup skips ensure on resume); fork unconditionally re-runs ensure_sandbox_for_thread (case-4 reconnect), so the gap doesn't exist | |
| `4f8bc2dd` | #1692 | refactor: simplify open-swe agent sandbox lifecycle (#1692 ) | Won't merge | structural rewrite deleting the fork's 4-case __creating__ sentinel; net diff is exactly the sentinel removal + rewritten test; collides with fork-only TID-COLLIDE-01 repo-binding guard | |
2026-07-08 19:02:09 -04:00
| `ab4eea4b` | #1663 | chore(deps): bump the major group across 1 directory with 3 updates (#1663 ) | Won't merge | already in dev — CI already on checkout@v7/setup -node@v6/upload -artifact@v7 | |
| `2bf207fb` | #1664 | chore(deps): bump python in the minor-and-patch group (#1664 ) | Won't merge | already in dev — Dockerfile already at python 3.14.6-slim-trixie | |
| `13b40113` | #1666 | chore(deps): bump cryptography from 48.0.1 to 49.0.0 in the major group (#1666 ) | Won't merge | already in dev — same 48->49 cryptography bump dev did via #105 | |
| `290d0fee` | #1669 | chore(deps): update langgraph-cli[inmem] requirement (#1669 ) | Won't merge | already in dev — langgraph-cli[inmem] at 0.4.30 | |
| `73a9e8b5` | #1693 | chore(deps): bump the minor-and-patch group across 1 directory with 19 updates (#1693 ) | Won't merge | dev at-or-ahead on 17/19; group fights dev's pinned langsmith==0.9.7 (#115 ) and carries an upstream plan-route test | |
| `9cd7e464` | #1700 | Fix workflow approval visibility (#1700 ) | Won't merge | superseded — dev's list_workflow_approvals_for_thread already enforces owner-only 403 | |
| `fd2541ce` | #1705 | fix: drop orphaned function_call items with stale OpenAI reasoning (#1705 ) | Won't merge | N/A — edits sanitize_openai_responses.py which dev deleted in the Bedrock/Fireworks migration (#62 ) | |
2026-07-17 12:36:30 -04:00
| `27b0ddeb` | #1708 | feat: add GPT-5.6 OpenAI models (#1708 ) | Won't merge | fork picker deliberately Bedrock/Fireworks-only — no-OpenAI-models product decision (consistent with #1725/#1727 ); options.py verified zero openai: IDs | |
| `35659177` | #1718 | fix: sanitize orphaned OpenAI tool results (#1718 ) | Won't merge | N/A — fork has no OpenAI Responses traffic path; middleware present is #155 's leaner rewrite lacking the orphan machinery #1718 patches; langchain-openai>=1.3.4 already satisfied; superseded upstream by #1731 (re-evaluate #155 rewrite when triaging #1731 ). Note: fd2541ce row's '#62 deleted sanitize_openai_responses.py' is inaccurate — the path was added fresh by #155 | |
2026-07-16 15:00:37 -04:00
| `5136079d` | #1725 | chore: disable todos for GPT-5.6 Sol (#1725 ) | Won't merge | superseded — #1733 (136d28e6) rewrites the same todo-exclusion block to a global default-off with env opt-in; per-model GPT-5.6 Sol list moot (fork picker has no OpenAI models) | |
| `bfa67a7a` | #1711 | chore(deps): bump soupsieve from 2.8.3 to 2.8.4 (#1711 ) | Won't merge | already in dev — uv.lock resolves soupsieve 2.8.4 | |
| `f7d94ad3` | #1721 | docs: add e2b to sandbox provider lists in AGENTS.md and CLAUDE.md (#1721 ) | Won't merge | N/A — edits upstream AGENTS.md/CLAUDE.md, both fully fork-rewritten; E2B provider itself deferred (48217b68) — add a doc line if/when E2B lands | |
| `4773b336` | #1746 | chore: point basedpyright at uv's .venv (#1746 ) | Won't merge | tooling — fork does not use basedpyright (lint stack is ruff); nothing to point at .venv | |
| `697adaa7` | #1752 | fix: update PyJWT to 2.13.0 (#1752 ) | Won't merge | already in dev — uv.lock resolves PyJWT 2.13.0 | |
| `714ea4a2` | #1759 | fix: clear basedpyright standard-mode type errors (#1759 ) | Won't merge | tooling — basedpyright type-error cleanup across 123 post-reorg files; fork uses ruff and the pre-reorg layout | |
2026-07-17 12:51:42 -04:00
| `dccf6437` | #1769 | fix: tighten sandbox config test types (#1769 ) | Won't merge | test-only change in post-reorg path tests/sandbox/ — fork doesn't have this file (domain reorg #1726 deferred) | |
| `c9a193e2` | #1766 | chore(deps): bump mcp from 1.27.2 to 1.28.1 (#1766 ) | Won't merge | indirect dependency bump (mcp); fork's own Dependabot handles these | |
2026-07-17 18:38:51 -04:00
| `d0b63551` | #1773 | fix: remove workflow push approval gating (#1773 ) | Won't merge | Removes WorkflowPushGuardMiddleware and the proxy-token permission ladder — both actively wired in this fork (server.py middleware stack; github_app.py scoped-mint fallback). Adopting would let agent runs push .github/workflows/ changes with no human approval and mint proxy tokens at full scope unconditionally — a security-posture loosening counter to Sea Haven gating. Keep the fork's guard; skip the doc/prompt relaxation too (fork prompt documents the approval flow). | |
2026-07-21 18:08:06 +00:00
| `589dfd83` | #1787 | fix: Harden Stagehand browser URL handling (#1787 ) | Won't merge | Follows #1648 (wont-merge): fork does not carry the Stagehand browser subagent — this 'fix' re-adds the entire module (992 insertions; modify/delete vs HEAD) plus the stagehand dep in pyproject/uv.lock. Adopting would resurrect a feature rejected under the curated-tools policy. | |
2026-07-23 16:59:36 +00:00
| `df743658` | #1774 | feat: add repository skill support to the coding agent (#1774 ) | Won't merge | Upstream reverted this feature in #1800: its factory-time ensure_sandbox_for_thread call ran outside the serialized run and raced the deterministic sandbox name (prod sandbox-create 409s spiking from the #1774 merge date). Feature withdrawn upstream; the fork's deferred security review is moot. If upstream re-lands repo skills (host-side .agents/skills resolution per #1800 ), triage that new commit fresh — the prompt-injection / trusted-ref concerns in the old reason still apply. | |
2026-07-21 18:08:06 +00:00
| `5b5e6076` | #1790 | chore: Add open wiki docs (#1790 ) | Won't merge | Upstream-repo openwiki doc site + AGENTS.md/CLAUDE.md pointers: content documents upstream's codebase and would be wrong for this fork (conflicts with the fork's heavily customized CLAUDE.md, which is canonical). Its companion auto-update workflow is bot-push docs automation counter to the fork's workflow-gating posture (#1773 ). | |
| `1443fc4b` | #1792 | fix: Update openwiki gh action (#1792 ) | Won't merge | Follows #1790 (wont-merge): fixes the openwiki-update workflow this fork does not carry (modify/delete vs HEAD). | |
2026-07-23 16:59:36 +00:00
| `e1138cf5` | #1797 | fix: merge concurrent trusted skill refs (#1797 ) | Won't merge | Follow-up fix to #1774 's TrustedSkillsMiddleware, which the fork never adopted (row df743658) and upstream itself reverted in #1800 — nothing to apply. | |
| `60e7307c` | #1800 | revert: repository skill support for the coding agent (#1774 , #1797 ) (#1800 ) | Won't merge | Revert of #1774 + #1797 ; the fork adopted neither, so there is nothing to revert. Upstream's rationale: #1774 's factory-time ensure_sandbox_for_thread ran outside the serialized run and raced the thread-deterministic sandbox name (prod create-409s). Fork invariant holds: its single provisioning call sits inside the __creating__ -sentinel lifecycle within the interrupt-serialized run. | |
2026-07-16 15:00:37 -04:00
| `83abea26` | #1724 | fix: accept natural-language Slack plan approvals (#1724 ) | Deferred | natural-language Slack plan approvals; touches fork-diverged plan-mode + Slack webhook stack (#130 ); post-reorg test paths need remap | plan-approval |
| `ddbe457b` | #1727 | fix: restore GPT-5.5 as default model (#1727 ) | Deferred | restores GPT-5.5 default in options/team_settings; fork picker is Bedrock/Fireworks-only — rides the #1708 OpenAI-models product decision (27b0ddeb) | model-picker |
| `30832d29` | #1731 | fix: preserve OpenAI Responses tool history (#1731 ) | Deferred | deletes SanitizeOpenAIResponsesMiddleware in favor of replay-history preservation in utils/model.py; supersedes deferred #1718 (35659177) — triage the pair together against fork-diverged middleware + model.py | openai-sanitize |
| `3fcb27ce` | #1737 | fix: bound reviewer diff fetching (#1737 ) | Deferred | bounds reviewer diff fetching + new fetch_review_diff tool; reviewer.py fork-diverged — reconcile like #1713 (71e3b818) | reviewer-misc |
| `ef68c09b` | #1734 | fix: handle Slack DMs as mentions (#1734 ) | Deferred | treat Slack DMs as mentions; touches fork-diverged Slack webhook + e2e harness; post-reorg test paths | slack-tooling |
| `26828ff9` | #1745 | chore: upgrade deepagents to 0.7.0a7 (#1745 ) | Deferred | deepagents 0.6.12 -> 0.7.0a7 alpha + [tool.uv] override-dependencies to bypass sandbox integrations < 0.7.0 bound ; fork is built on create_deep_agent — dedicated validation ( unit + e2e ) before adopting an alpha | deps |
| `ef0ed5af` | #1741 | fix: centralize SSRF-safe image fetches (#1741 ) | Deferred | security hardening — centralizes image fetches through url_safety.py (SSRF); fork has url_safety.py/multimodal.py (diverged) — hand-reconcile; untrusted-input surface: /sh-security-review on landing | ssrf-hardening |
| `136d28e6` | #1733 | fix: disable todos by default (#1733 ) | Deferred | global write_todos/TodoListMiddleware default-off with OPEN_SWE_ENABLE_TODOS opt-in; edits fork-customized prompt.py — small hand-merge; supersedes #1725 | prompt-tweaks |
| `5077e2c7` | #1735 | feat(open-swe): untagged two-party Slack replies + debounced interrupts (#1735 ) | Deferred | untagged two-party Slack replies + debounced interrupts (~620 LOC incl. e2e); rides fork-diverged Slack webhook stack; own branch + e2e validation | slack-untagged-replies |
| `8b26819f` | #1719 | fix: offload web tool results to sandbox (#1719 ) | Deferred | offloads large web tool results to sandbox files; touches fork-relevant web_search/http tools; check interplay with fork sandbox lifecycle | tool-offloading |
| `b7c5dbd6` | #1747 | fix: simplify Slack run links (#1747 ) | Deferred | simplifies Slack run links; heavy churn on fork-diverged Slack context/prompt tests | slack-tooling |
2026-07-17 18:38:51 -04:00
| `81d544bc` | #1765 | feat: Expose more specific AGENTS.md context to Open SWE reviewer (#1765 ) | Deferred | Near-clean: agents_md.py helper + tests are zero-drift; reviewer.py hunk is small (~39 lines) but lands in the fork's heavily-diverged reviewer — hand-apply the scoped_agents_md wiring onto the fork's fetch_agents_md call sites (reviewer.py ~L404/445/1031). | reviewer-context |
| `8c8e58bc` | #1776 | feat: connect automations to Slack channels (#1776 ) | Deferred | Moderate reconcile: Slack-channel wiring for automations. Fork helpers exist (post_slack_top_level_message_with_ts, generate_thread_id_from_slack_thread, slack_id_for_login); completion.py (+233 drift) and schedules.py (+167) need hand-merge; UI automations feature present. Keep backend+UI+tests as one vertical. | automations-slack |
| `f0897479` | #1778 | feat: surface context window usage in agents UI (#1778 ) | Deferred | Near-clean: context-window indicator UI is all new files (zero drift); options.py hunk must be re-keyed to the fork's Bedrock/Fireworks model map (fork model IDs differ from upstream's) — add context_window per fork entry rather than taking upstream values. | context-usage-ui |
2026-07-21 18:08:06 +00:00
| `9bbd65d3` | #1781 | fix: derive model context windows from LangChain profiles (#1781 ) | Deferred | Pair with deferred #1778 on context-usage-ui: derives model context windows from LangChain profiles. options.py conflicts — re-key to the fork's Bedrock/Fireworks model map (upstream IDs differ; verify LangChain profiles even resolve for the fork's Bedrock-style IDs, else keep static values). uv.lock bumps langchain to a profiles-capable version; test_model_fallback_resolution also conflicts. Port with/after #1778 . | context-usage-ui |
| `7312851d` | #1777 | feat: add explicit plan approval tool (#1777 ) | Deferred | Feature: explicit approve_plan tool + plan-mode exit. All deps exist in fork (plan_store PLAN_STATUS_APPROVED/SHARED, thread_api._user_owns_thread). Conflicts: prompt.py (fork prompt constants), server.py (tool/middleware wiring), check_message_queue.py (fork dashboard-handoff + mid-run injection drift), AGENTS.md. Hand re-key those four; keep the whole vertical (tool + plan_mode + thread_api + 4 test files) on one side. | |
| `e51abe14` | #1754 | fix: skip oversized images before model calls (#1754 ) | Deferred | Desirable: 10MB image size cap + 'image omitted' text block before model calls, prevents oversized-image model failures. Conflicts only because the fork hardened fetch_image_block (SSRF redirect guard, host-only logging) — hunks are compatible; re-key the size check around the fork's guarded fetch and port impl + test together. | |
| `0ed560a5` | #1779 | fix: settle review checks after run failures (#1779 ) | Deferred | Desirable: run-failure completion webhook now settles reviewer check runs left open when the graph dies (_settle_failed_reviewer_check; uses settle_review_check_run + review_check_pending_result, both already in the fork's review/publish.py from the #214/#215 ports). Conflict is fork drift in completion.py (failure-reply customizations); re-key the new helper in and port with its 159-line test. | |
2026-07-23 16:59:36 +00:00
| `bedc57b8` | #1796 | fix: cap execute output by making SandboxBackendProxy a BaseSandbox (#1796 ) | Deferred | Real fix (unbounded execute stdout pulled into the worker → OOM risk) but inapplicable at the fork's deepagents==0.6.12: no capture-offload API exists (ExecuteOffloadResult / execute_accepts_timeout absent; FilesystemMiddleware has no _resolve_capture BaseSandbox gate), so the bug it fixes cannot occur yet. Re-triage together with deferred #1745 (deepagents 0.6.12→0.7.x bump) — landing that bump makes this fix required. Fork's SandboxBackendProxy has diverged (sync-era, bound_repo repo-binding, no reconnect machinery): hand-apply the execute_with_offload/aexecute_with_offload delegation onto the fork proxy rather than cherry-pick. | |
2026-07-24 15:31:41 -04:00
| `b67215ed` | #1780 | feat: link originating Slack threads (#1780 ) | Deferred | Desirable for the Slack-heavy fork: dispatch records the originating Slack permalink in thread metadata (webhooks/common.py), open_pull_request embeds an 'Originating Slack thread' link in the PR body (gated to private repos), and the sidebar menu links it. Impl files auto-merge (thread_api / open_pull_request / webhooks/common); conflicts are fork drift in prompt.py (customized prompt constants), tests/e2e/harness.py, tests/slack/test_slack_context.py — hand re-key those; keep backend + UI (AgentsSidebar, types) + e2e dashboard spec as one vertical. | |
| `7d79d300` | #1804 | chore(deps): bump deepagents to 0.7.0b1 pin (#1804 ) | Deferred | Rides the deferred #1745 deepagents bump: 0.7.0a7→0.7.0b1 pin + wcmatch>=11.0 uv override (langchain-e2b's e2b dep still caps wcmatch< 11.0 ). Fork is pinned deepagents = =0.6.12 — and langsmith = =0.10.10 already satisfies the new > =0.10.9 floor — and never took the a7-era HARNESS_EXCLUDED_MIDDLEWARE code its prompt.py hunk deletes, so nothing applies standalone. Re-triage as one cluster: #1745 (bump, now targeting 0.7.0b1) + #1796 (offload delegation) + this pin/override. | |
| `0e2eefbc` | #1801 | chore: bump default sandbox resources and delete-after-stop (#1801 ) | Deferred | Capacity/cost policy, not a correctness fix: defaults 2→4 vCPU, 7936MiB→16GiB mem, 32→128GiB FS, stopped-sandbox delete 24h→14d. Would materially raise LangSmith sandbox spend on sh-openswe unless prod env already overrides; all five values are env-overridable today. Decide prod sizing first (ops decision), then adopt or reject. Textual conflict is only fork drift in integrations/langsmith.py (sync-era SandboxClient, reconnect constants absent) — the constants re-key trivially; docs hunks auto-merge. | |
2026-08-14 15:38:21 +00:00
| `d49553c2` | #1806 | fix: pass initialized backend instance to create_deep_agent (#1806 ) | Untriaged | | |
| `ed12bb8d` | #1807 | feat: add Claude Opus 5 support (#1807 ) | Untriaged | | |
| `e72a658e` | #1809 | fix: patch vulnerable dependencies (#1809 ) | Untriaged | | |
| `d3d02135` | #1810 | fix: never recreate or delete a thread's sandbox (#1810 ) | Untriaged | | |
| `1b01d9c1` | #1812 | fix: log automated Slack warnings as errors (#1812 ) | Untriaged | | |
| `fcf4db55` | #1811 | fix: let users explicitly override prompt instructions (#1811 ) | Untriaged | | |
| `998b8084` | #1814 | fix: make approve_plan work on Python 3.11 and bump langgraph-api (#1814 ) | Untriaged | | |
| `94653fdd` | #1815 | chore: bump deepagents and trim prompt shims (#1815 ) | Untriaged | | |
| `90b43423` | #1816 | fix: extend sandbox delete-after-stop ttl (#1816 ) | Untriaged | | |
| `f353a76b` | #1818 | feat: Cursor-style model picker; retire Opus 4.8 and GPT-5.5 (#1818 ) | Untriaged | | |
| `2c54ea7a` | #1817 | fix: let the reviewer recover from an unreachable sandbox (#1817 ) | Untriaged | | |
| `4be00103` | #1820 | chore: require LangSmith SDK 0.10.11 (#1820 ) | Untriaged | | |
| `30c339a3` | #1821 | fix: make the web stop button work and bound stalled model calls (#1821 ) | Untriaged | | |
| `dff6a5f8` | #1808 | feat: add deployable Open SWE Dockerfile (#1808 ) | Untriaged | | |
| `5f095229` | #1822 | feat: add persistent diff line wrapping (#1822 ) | Untriaged | | |
| `26c5b6d2` | #1824 | perf: cache the dashboard repo picker's repo list (#1824 ) | Untriaged | | |
| `f2dc7cd1` | #1825 | feat: add explicit sandbox recreation tool (#1825 ) | Untriaged | | |
| `6af059b5` | #1828 | fix: remove natural wording from approval prompts (#1828 ) | Untriaged | | |
| `60bdb911` | #1827 | feat: vary Slack acknowledgement reactions (#1827 ) | Untriaged | | |
| `940db8e6` | #1830 | feat: user-level custom instructions with agent self-edit (#1830 ) | Untriaged | | |
| `9ec6f851` | #1831 | chore: bump LangSmith and Deep Agents SDKs (#1831 ) | Untriaged | | |
| `7ddbbb17` | #1836 | fix: correct Kimi K3 Fireworks model id and effort levels (#1836 ) | Untriaged | | |
| `b7ecd8e4` | #1835 | feat: support forwarded Slack message context (#1835 ) | Untriaged | | |
| `883c1d08` | #1837 | fix: remove repeated Slack prompt instructions (#1837 ) | Untriaged | | |
| `9fb145a1` | #1834 | fix: show Kimi K3 context window (#1834 ) | Untriaged | | |
| `4ac5eb5e` | #1842 | fix: sync CLAUDE.md sandbox lifecycle (#1842 ) | Untriaged | | |
| `5b2cbabc` | #1840 | chore(deps): bump the major group with 4 updates (#1840 ) | Untriaged | | |
| `79596dc4` | #1839 | chore(deps): bump langchain/langgraph-api from 0.10.0rc3-py3.12 to 0.13.0.dev8-py3.12 in the minor-and-patch group (#1839 ) | Untriaged | | |
| `2c697312` | #1844 | chore(deps): bump the minor-and-patch group across 1 directory with 13 updates (#1844 ) | Untriaged | | |
| `4f414cb9` | #1845 | chore(deps): bump aiohttp from 3.14.1 to 3.14.3 (#1845 ) | Untriaged | | |
| `a5ccfb91` | #1846 | chore(deps): bump cryptography from 49.0.0 to 50.0.0 (#1846 ) | Untriaged | | |
| `b0be18ea` | #1847 | fix: avoid approval-like reactions on PR posts (#1847 ) | Untriaged | | |
| `e563e7bf` | #1849 | feat: support max reasoning for GPT-5.6 Luna (#1849 ) | Untriaged | | |
| `970548ff` | #1848 | fix: restrict user instructions tool scope (#1848 ) | Untriaged | | |
| `3305a5dd` | #1843 | fix: cancel active dashboard runs by ID (#1843 ) | Untriaged | | |
| `26c98fa7` | #1850 | feat: add user-managed agent skills (#1850 ) | Untriaged | | |
| `c059dfca` | #1851 | refactor(web): rebuild the agents chat surface on one palette (#1851 ) | Untriaged | | |
| `97f69066` | #1833 | feat: show run usage in Slack footers (#1833 ) | Untriaged | | |
| `ffe24c92` | #1855 | feat: add skill autocomplete to agent chat (#1855 ) | Untriaged | | |
| `5106116b` | #1858 | chore: bump LangSmith SDK to 0.10.16 (#1858 ) | Untriaged | | |
| `7138945d` | #1860 | chore(deps): bump langchain-anthropic minimum (#1860 ) | Untriaged | | |
| `652b426e` | #1859 | feat: add experimental Electron client (#1859 ) | Untriaged | | |
| `6a5cd535` | #1856 | feat: show plans in the agent side panel (#1856 ) | Untriaged | | |
| `133d3873` | #1862 | fix: collapse shell tool calls by default (#1862 ) | Untriaged | | |
| `52597446` | #1863 | feat: autofocus new agent input (#1863 ) | Untriaged | | |
| `6e329535` | #1867 | feat: allow org members to use LangSmith tools (#1867 ) | Untriaged | | |
| `0b9d69ee` | #1865 | feat: give agent chat a distinct typeface (#1865 ) | Untriaged | | |
| `b54d6b3d` | #1866 | fix(slack): drop rotating loading messages from assistant status (#1866 ) | Untriaged | | |
| `c410ff6b` | #1868 | feat: dynamically load integration tool schemas (#1868 ) | Untriaged | | |
| `6e090976` | #1870 | fix: let user scrolling override diff navigation (#1870 ) | Untriaged | | |
| `28ebd893` | #1871 | fix: require explicit request for PR reviewer (#1871 ) | Untriaged | | |
| `59de29c4` | #1864 | feat: run dcode locally in desktop app (#1864 ) | Untriaged | | |
| `98a30c7e` | #1873 | fix: remember right panel state per thread (#1873 ) | Untriaged | | |
| `eafe15c1` | #1872 | feat: let agents manage user skills (#1872 ) | Untriaged | | |
| `0696eb27` | #1875 | fix: restore desktop agent live updates (#1875 ) | Untriaged | | |
| `6b3e3009` | #1874 | feat: source changed-files views from git turn checkpoints (#1874 ) | Untriaged | | |
| `7fd374b0` | #1876 | fix: recover dashboard streams after suspension (#1876 ) | Untriaged | | |
| `95cce798` | #1878 | fix: recover desktop ACP sessions after prompt errors (#1878 ) | Untriaged | | |
| `cd0a3369` | #1879 | fix: show one static Slack tip per run (#1879 ) | Untriaged | | |
| `2a29d526` | #1883 | fix(web): bind the stream transport to the active thread (#1883 ) | Untriaged | | |
| `0a8ceb33` | #1880 | refactor: run sandbox and LangSmith IO natively async (#1880 ) | Untriaged | | |
| `f188d3bc` | #1881 | fix: show approval state on shared threads (#1881 ) | Untriaged | | |
| `7a42e2ed` | #1877 | feat: enable local terminal (#1877 ) | Untriaged | | |
| `dd79f4f2` | #1884 | feat: split the agents sidebar into Local and Cloud sections (#1884 ) | Untriaged | | |
| `1ce0c621` | #1885 | fix: soften dark and light theme palettes (#1885 ) | Untriaged | | |
| `ed6ab82b` | #1887 | fix(web): restore thread stream lifecycle (#1887 ) | Untriaged | | |
| `35e75e1f` | #1886 | feat: add per-user PR draft preference (#1886 ) | Untriaged | | |
| `3a38602d` | #1888 | feat: auto-approve dcode ACP permissions (#1888 ) | Untriaged | | |
| `ee3986b5` | #1889 | fix: make sidebar Local/Cloud headers read as headings (#1889 ) | Untriaged | | |
| `458ed232` | #1890 | fix: isolate desktop dev profile from installed app (#1890 ) | Untriaged | | |
| `24da2a9f` | #1861 | chore(deps-dev): bump electron (#1861 ) | Untriaged | | |
| `80e01ee6` | #1892 | style(web): format entire UI tree and enforce it in CI (#1892 ) | Untriaged | | |
2026-08-17 19:09:55 -04:00
| `46d64508` | #1891 | fix: route desktop login through backend (#1891 ) | Untriaged | | |
| `83344ca5` | #1895 | feat(open-swe): set the sandbox base snapshot at runtime (#1895 ) | Untriaged | | |
| `a9f07635` | #1897 | fix: always include Slack loading tips (#1897 ) | Untriaged | | |
| `d479a6ec` | #1896 | fix: keep queued messages visible during active runs (#1896 ) | Untriaged | | |
| `eb69d266` | #1898 | fix: reconnect chat after plan decisions (#1898 ) | Untriaged | | |
| `c263bec5` | #1899 | feat: make model picker selected-model first (#1899 ) | Untriaged | | |
| `c7fb16e0` | #1900 | feat: add deployment-aware dashboard UI context (#1900 ) | Untriaged | | |
| `2407abc4` | #1904 | fix: improve agents chat legibility and surface contrast (#1904 ) | Untriaged | | |
| `ff1ae2ea` | #1902 | fix: auto-open plan panel instead of in-progress plan banner (#1902 ) | Untriaged | | |
| `ae0b1583` | #1903 | feat: rebuild dashboard settings page (#1903 ) | Untriaged | | |
| `88375cdd` | #1907 | ci: remove PR title linting (#1907 ) | Untriaged | | |
| `87afa826` | #1908 | fix: even out chat composer gutters beside the git panel (#1908 ) | Untriaged | | |
| `a6933d44` | #1906 | feat: add macOS release pipeline (#1906 ) | Untriaged | | |
| `9f4fbbed` | #1905 | feat: git diff panel for desktop local mode sessions (#1905 ) | Untriaged | | |
| `ed9e058a` | #1901 | fix: keep Slack breakout roots headline-only (#1901 ) | Untriaged | | |
| `5efd0b9c` | #1911 | feat: preview deployment environment (#1911 ) | Untriaged | | |
| `6efe5c50` | #1912 | fix: read PR author association from the REST pulls endpoint (#1912 ) | Untriaged | | |
| `2ff8c0e8` | #1914 | ci: restore permissive PR title lint (#1914 ) | Untriaged | | |
| `82009c88` | #1915 | fix: keep local sandbox setup off event loop (#1915 ) | Untriaged | | |
| `5274b653` | #1910 | feat: port production desktop terminal (#1910 ) | Untriaged | | |
| `badf8920` | #1916 | feat: rebuild the agent side panel as a tabbed workspace (#1916 ) | Untriaged | | |
| `a93da9a0` | #1918 | fix: separate web and Slack model defaults (#1918 ) | Untriaged | | |
| `ea602cfe` | #1919 | feat: show repository in cloud session header (#1919 ) | Untriaged | | |
| `e218c194` | #1920 | security: update vulnerable transitive dependencies (#1920 ) | Untriaged | | |
| `92d3cd53` | #1923 | chore: bump LangSmith SDK to 0.10.18 (#1923 ) | Untriaged | | |
| `3f7631d6` | #1925 | feat: add defined chat header bar (#1925 ) | Untriaged | | |
| `6e811049` | #1926 | fix: load git diff from pull request repository (#1926 ) | Untriaged | | |
| `75b81ee8` | #1928 | fix: remove Slack assistant status calls (#1928 ) | Untriaged | | |
| `f41a418c` | #1922 | feat: trigger automations as tests (#1922 ) | Untriaged | | |
| `bc9d0ba2` | #1924 | fix: preserve original Slack thread owner (#1924 ) | Untriaged | | |
| `bea97cf4` | #1931 | feat: include Slack user timezone in agent context (#1931 ) | Untriaged | | |
| `54d314a6` | #1932 | feat: simplify review panel header (#1932 ) | Untriaged | | |
| `79f07996` | #1933 | refactor: reorganize the repo into a pnpm + Turborepo monorepo (#1933 ) | Untriaged | | |
| `c5abec89` | #1930 | fix: keep plan review header readable (#1930 ) | Untriaged | | |
| `2b779ab3` | #1929 | feat: add user-scoped LangSmith credentials (#1929 ) | Untriaged | | |
| `6800e374` | #1935 | fix: validate reviewer outcomes dataset name (#1935 ) | Untriaged | | |
| `8848a8d2` | #1934 | fix(slack): dedupe mention event deliveries (#1934 ) | Untriaged | | |
| `315ad0b1` | #1936 | fix: compact review diff header (#1936 ) | Untriaged | | |
| `e6d9dbbb` | #1927 | fix: clarify Slack acknowledgements and preference scope (#1927 ) | Untriaged | | |
| `98386c51` | #1941 | fix: drop unreplayable OpenAI reasoning items (#1941 ) | Untriaged | | |
| `e80f9a35` | #1942 | test: expect OpenAI replay sanitizer (#1942 ) | Untriaged | | |
| `d00377fc` | #1940 | fix(cache): stop keying TTL cache entries on callable addresses (#1940 ) | Untriaged | | |
| `609718f6` | #1939 | perf: overlap sandbox startup with agent assembly (#1939 ) | Untriaged | | |
| `9c862bc4` | #1921 | feat: add conditional automation Slack notifications (#1921 ) | Untriaged | | |
| `349875e0` | #1943 | fix: avoid duplicate Slack output and brittle prompt tests (#1943 ) | Untriaged | | |
| `ab27a34a` | #1944 | fix: honor forwarded scheme for desktop OAuth (#1944 ) | Untriaged | | |
| `84b74f51` | #1946 | feat(sandbox): set GH_TOKEN via the GitHub proxy rule (#1946 ) | Untriaged | | |
| `5f688018` | #1954 | fix(sandbox): keep local sandbox git identity out of ~/.gitconfig (#1954 ) | Untriaged | | |
| `a63b27ba` | #1956 | chore(typing): clear basedpyright errors and gate CI on typecheck (#1956 ) | Untriaged | | |
| `d94efde9` | #1958 | fix(sandbox): adopt an orphaned sandbox on name collision (#1958 ) | Untriaged | | |
| `d4a2fc02` | #1948 | fix: make prompts and tools source-aware (#1948 ) | Untriaged | | |
| `b6458aa4` | #1945 | fix: keep GitHub SAML login in desktop (#1945 ) | Untriaged | | |
| `2cbe4335` | #1947 | feat: generate thread titles in background (#1947 ) | Untriaged | | |
| `91efb6e5` | #1961 | feat: add macOS desktop install command (#1961 ) | Untriaged | | |
| `294bb0f1` | #1937 | feat: persist local ACP sessions (#1937 ) | Untriaged | | |
| `8a0f1853` | #1949 | feat: add Slack buttons for plan approvals (#1949 ) | Untriaged | | |
| `5230884b` | #1955 | fix: deny Slack tools to subagents (#1955 ) | Untriaged | | |
| `c8bee9c7` | #1963 | fix: inherit shell auth for desktop ACP (#1963 ) | Untriaged | | |
| `4571ab5d` | #1950 | fix: exclude plan setup from turn diffs (#1950 ) | Untriaged | | |
| `cd2ee509` | #1965 | fix: keep sidebar section headers visible (#1965 ) | Untriaged | | |
| `04833ffb` | #1952 | feat(environments): named prompt + captured snapshot per environment (#1952 ) | Untriaged | | |
| `2f4a0dee` | #1967 | fix: verify CI status before reporting success (#1967 ) | Untriaged | | |
| `006b9c94` | #1968 | fix: align local thread header with cloud (#1968 ) | Untriaged | | |
| `a6c36004` | #1969 | feat: delete local desktop sessions (#1969 ) | Untriaged | | |
| `de4cfc0f` | #1972 | feat: Enable terminals on the Desktop new-agent screen (#1972 ) | Untriaged | | |
| `9de6414b` | #1970 | feat: shimmer the conversation loader (#1970 ) | Untriaged | | |
| `8dcac4d4` | #1966 | feat: switch models in desktop threads (#1966 ) | Untriaged | | |
| `d572b93c` | #1971 | feat: show local project branch before runs (#1971 ) | Untriaged | | |
| `a6c31b41` | #1977 | feat(desktop): sign in through the user's own browser (#1977 ) | Untriaged | | |
| `ae22b6b2` | #1980 | fix(ui): allow the prod branch to deploy the production dashboard (#1980 ) | Untriaged | | |
| `c1fc7db1` | #1981 | fix(dashboard): keep thread-title generation out of the run's stream (#1981 ) | Untriaged | | |
| `8417fd0f` | #1982 | test(e2e): drop the blanket 8s stall from the fake implement script (#1982 ) | Untriaged | | |
| `db663b1e` | #1959 | feat(slack): drop quiet third parties from the untagged-reply gate (#1959 ) | Untriaged | | |
| `40832fb7` | #1984 | fix(environments): drop the tag from captured snapshot names (#1984 ) | Untriaged | | |
| `c70bae66` | #1983 | feat(ui): stop the running turn with Escape (#1983 ) | Untriaged | | |
| `2c26eba6` | #1985 | test(e2e): stop recording traces and video for passing CI runs (#1985 ) | Untriaged | | |
| `3c7aafec` | #1979 | build(ui): add a Dockerfile for the dashboard (#1979 ) | Untriaged | | |
| `74d55f34` | #1986 | feat: tint admin threads red (#1986 ) | Untriaged | | |
| `9e9727ed` | #1974 | feat: show local branch pull requests (#1974 ) | Untriaged | | |
| `6ced941e` | #1962 | fix(slack): dedupe on the message, not the delivery (#1962 ) | Untriaged | | |
| `1299f3bd` | #1960 | fix: display the repository used by an agent (#1960 ) | Untriaged | | |
| `87875e70` | #1976 | feat: add cloud sandbox terminals (#1976 ) | Untriaged | | |
| `e318e732` | #1990 | fix: restore desktop window drag region (#1990 ) | Untriaged | | |
| `516ae408` | #1988 | fix: fit chat composer on mobile (#1988 ) | Untriaged | | |
| `585ab55a` | #1989 | fix: shorten tool call file paths (#1989 ) | Untriaged | | |
| `217116e9` | #1987 | feat: add voice dictation to the composer (#1987 ) | Untriaged | | |
| `82678d85` | #1975 | feat: add organization skills (#1975 ) | Untriaged | | |
| `e95eff0c` | #1992 | fix: style plan approval as Slack status (#1992 ) | Untriaged | | |
2026-08-25 14:33:44 -04:00
| `a1a6a9c6` | #1991 | feat: require platform issue details (#1991 ) | Untriaged | | |
| `a2e38790` | #1993 | fix: require admin threads to create environments (#1993 ) | Untriaged | | |
| `41a78837` | #1994 | feat: show inline diffs for edit tool calls (#1994 ) | Untriaged | | |
| `4da9d1f9` | #1995 | feat: scope user settings reads to thread participants (#1995 ) | Untriaged | | |
| `331ea489` | #2003 | chore: migrate desktop Node code to TypeScript (#2003 ) | Untriaged | | |
| `b018817c` | #1996 | fix: restore cloud terminal connections (#1996 ) | Untriaged | | |
| `34c826b9` | #1998 | feat: retitle Slack-started agent threads (#1998 ) | Untriaged | | |
| `14575194` | #2012 | chore: update Gemini Flash model (#2012 ) | Untriaged | | |
| `4e1ccd1a` | #2005 | fix: collapse composer extras into a menu (#2005 ) | Untriaged | | |
| `14329d00` | #2000 | feat(desktop): pin dcode and add Electron E2E (#2000 ) | Untriaged | | |
| `41e456f6` | #1999 | fix: align OpenAI context windows with Codex (#1999 ) | Untriaged | | |
| `f4f20939` | #2010 | fix: ban white check mark Slack reactions (#2010 ) | Untriaged | | |
| `e950ce7a` | #2013 | Make dashboard plan mode opt-in (#2013 ) | Untriaged | | |
| `2980448e` | #1997 | feat: add guarded automatic PR approval (#1997 ) | Untriaged | | |
| `e712a9ef` | #2001 | fix: clarify Slack channel repo hint (#2001 ) | Untriaged | | |
| `9600cd04` | #2016 | fix: clear stale local session activity (#2016 ) | Untriaged | | |
| `5bec7959` | #2009 | feat: stop Slack runs on x reactions (#2009 ) | Untriaged | | |
| `90856eed` | #2015 | chore: ban future annotations imports (#2015 ) | Untriaged | | |
| `6f64f1d4` | #2014 | feat: separate automation threads from active work (#2014 ) | Untriaged | | |
| `49497d64` | #2007 | fix: warn before discarding automation changes (#2007 ) | Untriaged | | |
| `216e74d2` | #1964 | fix: pin thread settings and integration identity per thread (#1964 ) | Untriaged | | |
| `a268d381` | #2008 | fix: keep sent Slack messages visible (#2008 ) | Untriaged | | |
| `e007900d` | #2017 | fix: stop polling on unknown mergeability (#2017 ) | Untriaged | | |
| `ff9b4b3b` | #1829 | feat: add explicit Slack thread mapping and moves (#1829 ) | Untriaged | | |
| `4094aa50` | #2021 | chore: use sentence case for automatic thread titles (#2021 ) | Untriaged | | |
| `968aeeac` | #2022 | fix: rename agent button to thread (#2022 ) | Untriaged | | |
| `ab97334c` | #2029 | fix: handle cleared transcription model selection (#2029 ) | Untriaged | | |
| `0b130935` | #2027 | feat: prefer PR delivery for code changes (#2027 ) | Untriaged | | |
| `3482367a` | #2032 | chore: bump LangSmith SDK to 0.11.0 (#2032 ) | Untriaged | | |
| `2c37c618` | #2036 | fix: standardize user-facing Open SWE branding (#2036 ) | Untriaged | | |
| `710fb1d7` | #2028 | fix: tint active admin composer control (#2028 ) | Untriaged | | |
| `a4509db3` | #2026 | fix: open threads from completion notifications (#2026 ) | Untriaged | | |
| `7f7249ca` | #2024 | fix: exclude cached input from Slack token count (#2024 ) | Untriaged | | |
| `f2ae76bb` | #2004 | feat: allow collaborators to approve plans (#2004 ) | Untriaged | | |
| `7b51d7cd` | #2037 | fix(ui): proxy /webhooks through the hosted dashboard (#2037 ) | Untriaged | | |
| `39ba4ffc` | #2038 | fix: collapse PR button in narrow panels (#2038 ) | Untriaged | | |
| `98d25fc0` | #2006 | feat: add /baby-sit PR CI monitoring (#2006 ) | Untriaged | | |
| `33899d2f` | #2019 | feat: add flexible thread board view (#2019 ) | Untriaged | | |
| `21120a5c` | #2002 | fix: require explicit URLs for out-of-org edits (#2002 ) | Untriaged | | |
| `eeb8a32d` | #2018 | fix: align plan header in narrow panels (#2018 ) | Untriaged | | |
| `67dcaa8f` | #1882 | feat(web): render subagent activity, status, and results (#1882 ) | Untriaged | | |
| `0fec8531` | #2040 | fix: link PR references in user-facing responses (#2040 ) | Untriaged | | |
| `9edc1e6f` | #2033 | fix: persist Slack button selections (#2033 ) | Untriaged | | |
| `5649ac13` | #2039 | ci: publish the preview dashboard image on every preview build (#2039 ) | Untriaged | | |
| `56e69c19` | #2044 | revert: remove automatic PR approvals (#2044 ) | Untriaged | | |
| `2d7f8ddf` | #2042 | refactor(ui): read the backend URL at runtime, not build time (#2042 ) | Untriaged | | |
| `68cd8a3a` | #2045 | ci: publish the dashboard image to langchain-nonprod (#2045 ) | Untriaged | | |
| `827ac740` | #2047 | fix: keep thread board stable on refocus (#2047 ) | Untriaged | | |
| `88e02eb3` | #2048 | feat: add dollar skill picker (#2048 ) | Untriaged | | |
| `7130e603` | #2020 | feat: route rapid Slack follow-ups and edits (#2020 ) | Untriaged | | |
| `c539cc7e` | #2050 | fix: make preview-fe labels opt-in (#2050 ) | Untriaged | | |
| `dd37dafe` | #1957 | feat: add sandboxed iframe outputs (#1957 ) | Untriaged | | |
| `f6305107` | #2049 | fix: bound dashboard history hydration (#2049 ) | Untriaged | | |
| `16ef4156` | #2046 | feat: add focus grouping to agent sidebar (#2046 ) | Untriaged | | |
| `03cf5d50` | #2056 | chore: trim low-value tests (#2056 ) | Untriaged | | |
| `bdaef7da` | #2053 | feat: run desktop threads on the Open SWE graph (#2053 ) | Untriaged | | |
| `3f0ee041` | #2059 | Revert "feat(web): render subagent activity, status, and results (#1882 )" (#2059 ) | Untriaged | | |
| `bac661c9` | #2057 | feat: show cumulative session cost in Slack (#2057 ) | Untriaged | | |
| `69db791a` | #2054 | ci: parallelize Playwright E2E (#2054 ) | Untriaged | | |
| `761adce4` | #2060 | feat(ui): add an operations restart endpoint (#2060 ) | Untriaged | | |
| `61521fd7` | #2058 | feat: add non-blocking sandbox commands (#2058 ) | Untriaged | | |
| `8d83612f` | #2061 | fix: stop thread reloads on refocus (#2061 ) | Untriaged | | |
| `3159143d` | #2064 | feat: toggle desktop thread sources (#2064 ) | Untriaged | | |
| `64cf112e` | #2041 | feat: render skill commands as badges (#2041 ) | Untriaged | | |
| `13504613` | #2043 | feat: edit review comments (#2043 ) | Untriaged | | |
| `5df7cd99` | #2031 | feat: measure dashboard thread time to first token (#2031 ) | Untriaged | | |
| `8922e375` | #2067 | fix: simplify Slack session cost status (#2067 ) | Untriaged | | |
| `977b46e2` | #2070 | fix: ignore generated desktop backend runtime (#2070 ) | Untriaged | | |
| `7172b2c0` | #2072 | fix: allow narrower desktop windows (#2072 ) | Untriaged | | |
| `291e701e` | #2071 | fix: sync local thread running status (#2071 ) | Untriaged | | |
| `6f8773b0` | #2055 | feat: add in-run steer action (#2055 ) | Untriaged | | |
| `9d1e2aa6` | #2066 | fix: widen and expose baby-sit skill (#2066 ) | Untriaged | | |
| `d17e8843` | #1951 | fix: bound inline changed-file summaries (#1951 ) | Untriaged | | |
| `3c97210a` | #2075 | fix: allow desktop agents to create pull requests (#2075 ) | Untriaged | | |
| `ef99d987` | #2073 | feat(desktop): add local branch controls (#2073 ) | Untriaged | | |
| `6b944131` | #2025 | fix: expose Slack message IDs for reactions (#2025 ) | Untriaged | | |
| `2e9cd3e0` | #2077 | chore: ignore stray playwright output at the repo root (#2077 ) | Untriaged | | |
| `9ed1e4cb` | #2078 | fix: restore model switching for local threads (#2078 ) | Untriaged | | |
| `6c4d4c12` | #2076 | feat: persist agent run diffs (#2076 ) | Untriaged | | |
| `d6edf2b2` | #2079 | fix: toggle composer stop and send actions (#2079 ) | Untriaged | | |
| `800deb23` | #2074 | feat: add keyboard command system (#2074 ) | Untriaged | | |
| `17c1237b` | #2084 | fix: stop a failed or interrupted run from bricking its thread (#2084 ) | Untriaged | | |
| `0235fe28` | #2086 | perf: remove working repo middleware (#2086 ) | Untriaged | | |
| `7d6ac556` | #2080 | fix: sync managed skills to local sessions (#2080 ) | Untriaged | | |
| `537ad8f5` | #2083 | fix: guard review chat repo reads (#2083 ) | Untriaged | | |
| `efa653a5` | #2085 | fix: require one event loop per process, and say so when it is not (#2085 ) | Untriaged | | |
| `611618a7` | #2023 | fix: scope participant settings to each message (#2023 ) | Untriaged | | |
| `4c719981` | #2088 | fix: support local baby-sit monitoring (#2088 ) | Untriaged | | |
| `5c887597` | #2087 | refactor: lean on one loop per process instead of guarding every use (#2087 ) | Untriaged | | |
| `50c75492` | #2035 | feat: render plans as sandboxed HTML artifacts (#2035 ) | Untriaged | | |
| `b6ba2418` | #2089 | chore: refresh workspace repos before use (#2089 ) | Untriaged | | |
| `ec6a01c0` | #2030 | feat: structure model input messages (#2030 ) | Untriaged | | |
| `0ebd637e` | #2069 | feat: share sandbox files with LangSmith download URLs (#2069 ) | Untriaged | | |
| `f964ef83` | #2090 | chore: document workspace repos in environment prompts (#2090 ) | Untriaged | | |
| `47045874` | #2095 | fix(deps): patch nanoid and brace-expansion advisories (#2095 ) | Untriaged | | |
| `4094f067` | #2096 | fix: generate thread titles from the whole thread (#2096 ) | Untriaged | | |
| `920dc720` | #2097 | fix(sandbox): start a stopped sandbox before failing the proxy refresh (#2097 ) | Untriaged | | |
| `4c98d51f` | #2098 | perf(dashboard): warm the thread state fetch and time it server-side (#2098 ) | Untriaged | | |
| `21954ac7` | #2101 | perf(dashboard): warm the sidebar fetch and time it server-side (#2101 ) | Untriaged | | |
| `f9796ffc` | #2099 | fix(e2e): write the plan fixture as HTML so save_plan accepts it (#2099 ) | Untriaged | | |
| `67abe63a` | #2092 | fix(transcript): render every user message from its envelope (#2092 ) | Untriaged | | |
| `7a41b143` | #2110 | fix: correct GitHub OAuth storage documentation (#2110 ) | Untriaged | | |
| `10686dcf` | #2103 | perf: keep recent thread views mounted (#2103 ) | Untriaged | | |
| `ee64d020` | #2114 | fix: render Slack messages correctly in dashboard (#2114 ) | Untriaged | | |
| `db1958b2` | #2111 | feat: render iframe outputs from sandbox URLs (#2111 ) | Untriaged | | |
| `333a35fc` | #2102 | feat(dashboard): show a loading placeholder in the threads sidebar (#2102 ) | Untriaged | | |
| `f5343c6f` | #2068 | fix: simplify agent activity transcript (#2068 ) | Untriaged | | |
| `4dfa1ace` | #2034 | feat: keep thread pull request links visible (#2034 ) | Untriaged | | |
| `dc3c5ab8` | #2109 | fix: restrict admin thread messages (#2109 ) | Untriaged | | |
| `5d65c77f` | #2094 | feat: use C for new threads (#2094 ) | Untriaged | | |
| `abd49d7e` | #2116 | feat: show thread activity by run location (#2116 ) | Untriaged | | |
| `fd9fcc64` | #2107 | fix(slack): stop rendering Open SWE's own replies as user messages (#2107 ) | Untriaged | | |
| `79e36d09` | #2093 | fix: compact desktop sidebar header (#2093 ) | Untriaged | | |
| `141dedf7` | #2117 | fix: synchronize thread status caches (#2117 ) | Untriaged | | |
| `efd99191` | #2115 | feat: move environments into Settings (#2115 ) | Untriaged | | |
| `ffb8318d` | #2113 | fix: prevent new-thread dialog flash (#2113 ) | Untriaged | | |
| `f076c119` | #2118 | feat: add concise mode to core agent prompt (#2118 ) | Untriaged | | |
| `10ea60ae` | #2105 | feat: expose admin status for environment changes (#2105 ) | Untriaged | | |
| `fd806643` | #2120 | fix: reserve Slack reactions for active work (#2120 ) | Untriaged | | |
| `7eb79841` | #2106 | fix: cap thread wakeup loops (#2106 ) | Untriaged | | |
| `b1e18266` | #2119 | fix: let agent judge Slack plan approval (#2119 ) | Untriaged | | |
| `56367639` | #2104 | fix: close the LangSmith client in trace_context (#2104 ) | Untriaged | | |
| `2704f4a9` | #2121 | fix: render local task calls as subagents (#2121 ) | Untriaged | | |
| `1ba10f86` | #2123 | feat: make live work status expandable (#2123 ) | Untriaged | | |
| `e1b82901` | #2122 | fix: unify cloud and local changes panel (#2122 ) | Untriaged | | |
| `377a2230` | #2124 | feat: simplify sidebar navigation (#2124 ) | Untriaged | | |
| `1d81c17a` | #2125 | fix: show local run activity before messages (#2125 ) | Untriaged | | |
| `8c947769` | #2127 | feat: show thread activity as notification badges (#2127 ) | Untriaged | | |
| `8bc34151` | #2129 | feat: shimmer active task names (#2129 ) | Untriaged | | |
| `c4486dcd` | #2108 | feat: add parent thread management tools (#2108 ) | Untriaged | | |
| `b3e46d86` | #2130 | fix: stop web follow-ups rendering twice (#2130 ) | Untriaged | | |
| `a8f73edb` | #2100 | feat: make plan review read-only (#2100 ) | Untriaged | | |
| `9454f5ae` | #2112 | fix: progressively load sidebar threads (#2112 ) | Untriaged | | |
| `bea476a7` | #2131 | feat: multi-surface right panel (#2131 ) | Untriaged | | |
| `91c5dcf8` | #2133 | fix: align sidebar toggle in macOS fullscreen (#2133 ) | Untriaged | | |
| `d7f7b7bd` | #2135 | chore: move the langgraph runtime off end-of-life 0.10.x (#2135 ) | Untriaged | | |
| `9c0ea351` | #2132 | feat: highlight JSON tool results (#2132 ) | Untriaged | | |
| `d1bc9f1d` | #2134 | fix: read the Changes surface from a selectable diff scope (#2134 ) | Untriaged | | |
| `a52603e5` | #2137 | feat: add desktop checkout install command (#2137 ) | Untriaged | | |
| `9375c88d` | #2139 | fix: hide active run divider (#2139 ) | Untriaged | | |
| `c60aede5` | #2138 | feat: fold the PR surface into the diff scope selector (#2138 ) | Untriaged | | |
| `f069ef73` | #2140 | fix: optimistically render new threads (#2140 ) | Untriaged | | |
| `7966f55b` | #2141 | fix: clarify active tool call shimmer (#2141 ) | Untriaged | | |
| `1425d194` | #2142 | fix: read working tree changes from live sandbox (#2142 ) | Untriaged | | |
| `70fcea5c` | #2143 | fix: make sidebar trace links navigable (#2143 ) | Untriaged | | |
| `cefc171f` | #2144 | ci: run E2E tests only for relevant changes (#2144 ) | Untriaged | | |
| `574a96f4` | #2146 | fix: read working tree changes against head (#2146 ) | Untriaged | | |
| `01d29f1e` | #2150 | Add desktop local account sign-in (#2150 ) | Untriaged | | |
| `a375b2fe` | #2154 | fix: require explicit plan mode requests (#2154 ) | Untriaged | | |
| `0f30eb62` | #2152 | feat: configure environment sandbox creation (#2152 ) | Untriaged | | |
| `2ca48dbb` | #2153 | feat: allow admin automation threads (#2153 ) | Untriaged | | |
| `11492bd6` | #2158 | fix: allow desktop oauth callbacks without a state cookie (#2158 ) | Untriaged | | |
| `ee80d5c4` | #2155 | fix: offload FilesystemBackend construction and stop blockbuster_ctx leaks (#2155 ) | Untriaged | | |
| `3ba3e600` | #2162 | fix: read working tree directly from sandbox (#2162 ) | Untriaged | | |
| `02e0183e` | #2163 | fix(ui): clear dictation error on message send (#2163 ) | Untriaged | | |
| `265921f6` | #2145 | feat(ui): polish the cloud / this mac source selector (#2145 ) | Untriaged | | |
| `d5e2b9af` | #2164 | fix(desktop): derive local run activity from the LangGraph backend (#2164 ) | Untriaged | | |
| `682fdb57` | #2147 | fix: rebuild usage telemetry from source events (#2147 ) | Untriaged | | |
| `6af43462` | #2165 | feat: show Slack action indicator for automation runs (#2165 ) | Untriaged | | |
| `a3ff583a` | #2168 | fix: dispatch runs with Protocol v2 event streaming (#2168 ) | Untriaged | | |
| `65483007` | #2166 | chore: require screenshots for UI-facing changes (#2166 ) | Untriaged | | |
| `c0ea126f` | #2167 | feat: let admin threads manage organization skills (#2167 ) | Untriaged | | |
| `b4627bda` | #2157 | fix: use full viewport in HTML plan viewer (#2157 ) | Untriaged | | |
| `112f3f34` | #2160 | feat: show actionable pull request health (#2160 ) | Untriaged | | |
| `02a45b3b` | #2159 | fix: keep sidebar threads in creation order (#2159 ) | Untriaged | | |
| `cb572ab0` | #2170 | fix: keep resolved thread visible in sidebar (#2170 ) | Untriaged | | |
| `fccb5394` | #2174 | fix: keep active attention thread pinned (#2174 ) | Untriaged | | |
| `5ed86550` | #2171 | fix: open thread actions from row context menu (#2171 ) | Untriaged | | |
| `a0b5eca5` | #2148 | fix: reconnect cloud terminals after disconnects (#2148 ) | Untriaged | | |
| `fdb798d6` | #2175 | fix: initialize attention pins after sidebar load (#2175 ) | Untriaged | | |
| `9511f859` | #2172 | fix: recover new thread transcript hydration (#2172 ) | Untriaged | | |
| `b27338af` | #2178 | fix: resolve threads optimistically (#2178 ) | Untriaged | | |
| `267fa2cc` | #2187 | chore: prefer rg over deepagents search (#2187 ) | Untriaged | | |
| `7d534ce1` | #2188 | feat(agent): trace agent startup phases (#2188 ) | Untriaged | | |
| `6e6d2db3` | #2190 | feat(ui): enable React Compiler on Vite 8 (#2190 ) | Untriaged | | |
| `2446cb0d` | #2193 | feat: add admin sandbox reset tool (#2193 ) | Untriaged | | |
| `aa1934cd` | #2194 | ci: move preview environment builds out of this repository (#2194 ) | Untriaged | | |
2026-09-14 12:38:04 +00:00
| `f81bfcda` | #2195 | refactor: remove the per-turn git checkpoint feature (#2195 ) | Untriaged | | |
| `60e03a41` | #2196 | fix: hide sender context after thread refresh (#2196 ) | Untriaged | | |
| `b721b339` | #2198 | perf(agent): order parallel tool results deterministically (#2198 ) | Untriaged | | |
| `3009bfe0` | #2201 | perf(agent): load the factory's tool sets in parallel (#2201 ) | Untriaged | | |
| `8c9fdd20` | #2202 | fix(agent): inject context instead of rewriting history (#2202 ) | Untriaged | | |
| `37933d6a` | #2206 | perf(agent): write the git identity while the proxy is configured (#2206 ) | Untriaged | | |
| `0c92fb10` | #2203 | feat: add Datadog RUM to dashboard (#2203 ) | Untriaged | | |
| `999de6a5` | #2205 | fix: submit queued message after stopping (#2205 ) | Untriaged | | |
| `f038614d` | #2199 | fix: prevent stale Slack thread replies (#2199 ) | Untriaged | | |
| `d201c8c0` | #2208 | perf(agent): let an integration describe itself without being built (#2208 ) | Untriaged | | |
| `45a36634` | #2197 | refactor: run Stagehand in task sandboxes (#2197 ) | Untriaged | | |
| `534f2fa1` | #2192 | fix: hide sidebar keyboard shortcut (#2192 ) | Untriaged | | |
| `aa13a720` | #2204 | feat: show active thread in web title (#2204 ) | Untriaged | | |
| `46278d74` | #2210 | docs: document workflow push approval gate (#2210 ) | Untriaged | | |
| `daab5de0` | #2177 | fix: hide threads after resolving (#2177 ) | Untriaged | | |
| `97e9fc89` | #2211 | fix: reintroduce context on inbound messages, not at the model call (#2211 ) | Untriaged | | |
| `3a7cee6a` | #2220 | refactor: share middleware content normalization (#2220 ) | Untriaged | | |
| `dd09f5c2` | #2184 | fix(desktop): make the whole top strip of the window draggable (#2184 ) | Untriaged | | |
| `4d9c3b03` | #2224 | fix: allow concurrent web and desktop development (#2224 ) | Untriaged | | |
| `272dcda4` | #2221 | fix: keep changes toolbar responsive (#2221 ) | Untriaged | | |
| `50595908` | #2219 | refactor(review): one canonical record for a finding's GitHub identity (#2219 ) | Untriaged | | |
| `e86ad114` | #2217 | refactor: centralize model choice normalization (#2217 ) | Untriaged | | |
| `bbbd8791` | #2212 | fix: give the agent GitHub's actual response when a PR fails (#2212 ) | Untriaged | | |
| `a3c99316` | #2229 | fix: accept displayed integration tool names (#2229 ) | Untriaged | | |
| `239c9861` | #2230 | feat: attach sandbox HTML to Slack threads (#2230 ) | Untriaged | | |
| `8e4a71aa` | #2215 | refactor(store): one LangGraph Store helper with one error policy (#2215 ) | Untriaged | | |
| `700b99d9` | #2214 | refactor(middleware): delete dead middleware and correct the docs that claimed it (#2214 ) | Untriaged | | |
| `780cb0a0` | #2213 | refactor(thread-ids): derive every deterministic thread id in one module (#2213 ) | Untriaged | | |
| `30a8a0a7` | #2235 | build(pnpm): retire the last npm and npx call sites (#2235 ) | Untriaged | | |
| `c8a262cb` | #2218 | fix: keep first message visible during thread creation (#2218 ) | Untriaged | | |
| `d0bfaf3c` | #2216 | fix: group sidebar threads by recent activity (#2216 ) | Untriaged | | |
| `1a9d00b7` | #2243 | refactor(store): type LangGraph Store records and source_context with Pydantic (#2243 ) | Untriaged | | |
| `1adf7a72` | #2240 | feat: pin threads in the sidebar (#2240 ) | Untriaged | | |
| `b4932e94` | #2239 | fix: dedupe sender context by sender (#2239 ) | Untriaged | | |
| `080edb16` | #2251 | fix: align desktop filesystem paths with shell (#2251 ) | Untriaged | | |
| `9471d5ed` | #2249 | fix: arm scheduler cron monitors reliably (#2249 ) | Untriaged | | |
| `8da544d0` | #2250 | fix: enable desktop gateway routing (#2250 ) | Untriaged | | |
| `f4981e03` | #2248 | refactor(sandbox): remove per-repo snapshots (#2248 ) | Untriaged | | |
| `4673b332` | #2247 | feat(html-artifacts): one authoring contract, scripts allowed, no boilerplate (#2247 ) | Untriaged | | |
| `3e315bc6` | #2245 | chore: log legacy auth migration impact (#2245 ) | Untriaged | | |
| `75b0eac4` | #2237 | refactor: remove thread ownership (#2237 ) | Untriaged | | |
| `a01f702b` | #2254 | refactor(environments): migrate to TypedStore and delete KeyedRecordStore (#2254 ) | Untriaged | | |
| `9ed21832` | #2238 | fix: block external Slack channels (#2238 ) | Untriaged | | |
| `efe6b5b1` | #2236 | chore: drop Dockerfile.sandbox (#2236 ) | Untriaged | | |
| `9457a973` | #2234 | fix: keep changes panel controls and diffs visible (#2234 ) | Untriaged | | |
| `5e0f98e1` | #2226 | chore: defer PR descriptions to repository guidance (#2226 ) | Untriaged | | |
| `2be8c000` | #2252 | feat: integrate Slack code channels (#2252 ) | Untriaged | | |
| `c5a2419b` | #2241 | feat: scan actionable PR context before fixing (#2241 ) | Untriaged | | |
| `e143f7b9` | #2260 | fix: move code channel web link to context (#2260 ) | Untriaged | | |
| `f03233f5` | #2255 | feat: add Baseten GLM-5.3 Flash (#2255 ) | Untriaged | | |
| `c2c4f3f1` | #2256 | Add confirmation rule for conflicting thread guidance (#2256 ) | Untriaged | | |
| `324635df` | #2262 | feat: align code channel and thread titles (#2262 ) | Untriaged | | |
| `3da1a1bd` | #2266 | revert: remove the Slack thread_version optimistic lock (#2199 ) (#2266 ) | Untriaged | | |
| `db747418` | #2271 | fix: default Slack code channels to public (#2271 ) | Untriaged | | |
| `de85f3db` | #2268 | docs(prompt): require explicit path when using rg (#2268 ) | Untriaged | | |
| `024f821c` | #2274 | feat: add sandbox service URL tool (#2274 ) | Untriaged | | |
| `d4141066` | #2261 | Add native Slack Agent view support (#2261 ) | Untriaged | | |
| `46349a44` | #2258 | feat: stream agent steps in Slack (#2258 ) | Untriaged | | |
| `31ff4d66` | #2273 | feat: link code channels from web threads (#2273 ) | Untriaged | | |
| `e575a9b4` | #2269 | Fix Slack file upload to use form-encoded bodies (#2269 ) | Untriaged | | |
| `a2ed177f` | #2232 | feat: add anchored comments to plan previews (#2232 ) | Untriaged | | |
| `224676be` | #2279 | fix: Revert Slack Agent view support and agent step streaming (#2279 ) | Untriaged | | |
| `440c7670` | #2283 | feat: restore Slack Thinking Steps (#2283 ) | Untriaged | | |
| `af59a1c3` | #2286 | Group Slack thinking steps by run (#2286 ) | Untriaged | | |
| `4388627d` | #2276 | chore: migrate wiki to claims + okf v0.2 and update broken update workflow (#2276 ) | Untriaged | | |
| `5423c7f1` | #2263 | Make automations workspace admin managed (#2263 ) | Untriaged | | |
| `683d4e50` | #2297 | fix(sandbox): don't treat retryable sandbox errors as fatal (#2297 ) | Untriaged | | |
| `9dbddb5f` | #2287 | fix: ignore metadata-only Slack message edits (#2287 ) | Untriaged | | |
| `2f3020da` | #2293 | docs(repo): update OpenWiki (#2293 ) | Untriaged | | |
| `71151486` | #2299 | fix: show Slack command details (#2299 ) | Untriaged | | |
| `66a23eee` | #2301 | feat(models): replace GLM 5.2 with GLM 5.3 (#2301 ) | Untriaged | | |
| `9c426aac` | #2318 | feat(ui): redesign new agent chat and composer (#2318 ) | Untriaged | | |
| `4bed1112` | #2289 | feat(ui): redesign the agents sidebar (#2289 ) | Untriaged | | |
| `f4cd500d` | #2334 | fix: consolidate thread bug fixes (#2334 ) | Untriaged | | |
| `3daddc35` | #2336 | fix: stabilize desktop login and local development (#2336 ) | Untriaged | | |
| `0976f100` | #2339 | fix(ui): align sidebar hover actions with status icons (#2339 ) | Untriaged | | |
| `8d017bc5` | #2340 | perf(e2e): cut redundant specs and CI setup work (#2340 ) | Untriaged | | |
| `f93d05ad` | #2341 | feat: add Don't ask again to Slack onboarding (#2341 ) | Untriaged | | |
| `61ba9993` | #2344 | feat: default Slack implementation tasks to code channels (#2344 ) | Untriaged | | |
| `53dda2ae` | #2345 | refactor(ui): rebuild thread runtime lifecycle (#2345 ) | Untriaged | | |
| `509bc7da` | #2346 | fix: remove sidebar scroll shadow gap (#2346 ) | Untriaged | | |
| `4e3e7ea3` | #2328 | Render composer project picker upward (#2328 ) | Untriaged | | |
| `993e7bd4` | #2348 | feat(ui): render chat markdown properly (#2348 ) | Untriaged | | |
| `665512dc` | #2326 | docs(repo): update OpenWiki (#2326 ) | Untriaged | | |
| `427e119b` | #2354 | chore: upgrade LangSmith SDK to 0.12.0 (#2354 ) | Untriaged | | |
| `933fe9ae` | #2353 | feat: link pull requests from Slack channel cards (#2353 ) | Untriaged | | |
| `37732225` | #2357 | fix(ui): clarify settings scope (#2357 ) | Untriaged | | |
| `b10b113e` | #2347 | refactor(ui): split sidebar pagination by project (#2347 ) | Untriaged | | |
| `c2235db0` | #2285 | fix: hide sender context from agent chat (#2285 ) | Untriaged | | |
| `54a089f0` | #2356 | feat: open Slack threads in the native app (#2356 ) | Untriaged | | |
| `b1903145` | #2355 | fix: align collapsed sidebar button (#2355 ) | Untriaged | | |
| `6813f875` | #2359 | docs: reposition Open SWE as a software factory (#2359 ) | Untriaged | | |
| `c12055db` | #2361 | feat: expand command palette actions (#2361 ) | Untriaged | | |
| `64d6daed` | #2367 | fix(ui): queue mid-run follow-ups in local threads (#2367 ) | Untriaged | | |
| `9acd2904` | #2368 | fix: make sidebar expand button clickable (#2368 ) | Untriaged | | |
| `cd4f0d94` | #2298 | fix(slack): queue message edits instead of running them (#2298 ) | Untriaged | | |
| `6f56e5af` | #2363 | build(deps): bump the major group with 3 updates (#2363 ) | Untriaged | | |
| `20794d03` | #2362 | build(deps): bump langchain/langgraph-api in the minor-and-patch group (#2362 ) | Untriaged | | |
| `1cf3aadb` | #2352 | docs(repo): update OpenWiki (#2352 ) | Untriaged | | |
| `924a9be6` | #2322 | docs: clarify admin threads start in the Web UI (#2322 ) | Untriaged | | |
| `745dccad` | #2366 | feat: implement desktop release and nightly workflow (#2366 ) | Untriaged | | |
| `65aa51b7` | #2321 | chore(ui): pin nitro instead of tracking the latest dist-tag (#2321 ) | Untriaged | | |
| `cee104f5` | #2317 | ci: type-check the dashboard (#2317 ) | Untriaged | | |
| `05bca50a` | #2316 | fix: warn when ALLOWED_GITHUB_ORGS leaves dashboard login unrestricted (#2316 ) | Untriaged | | |
| `2c11a34d` | #2315 | test: skip the POSIX-shell html artifact tests on Windows (#2315 ) | Untriaged | | |
| `a683e8d3` | #2376 | refactor: split the sandbox and auth subsystems out of agent/utils (#2376 ) | Untriaged | | |
| `d7b26182` | #2380 | feat: replace Gemini 3.7 Flash with 3.8 Flash (#2380 ) | Untriaged | | |
| `9ded8a3a` | #2382 | fix: bundle local backend in desktop releases (#2382 ) | Untriaged | | |
| `16456e49` | #2384 | chore(desktop): bump version to 0.2.4 (#2384 ) | Untriaged | | |
| `50117174` | #2351 | feat(desktop): choose between the current checkout and a new worktree (#2351 ) | Untriaged | | |
| `e477fdef` | #2386 | fix(ui): stop duplicate initial prompt on local threads (#2386 ) | Untriaged | | |
| `90b5e581` | #2387 | fix(ui): make dropdown menus opaque (#2387 ) | Untriaged | | |
| `703621d3` | #2383 | feat: add desktop auto-updates (#2383 ) | Untriaged | | |
| `b7594875` | #2388 | fix: derive Slack error status from run outcome (#2388 ) | Untriaged | | |
| `72ca8c05` | #2389 | chore(desktop): bump version to 0.2.5 (#2389 ) | Untriaged | | |
| `45321107` | #2379 | feat(ui): search reviewer repositories (#2379 ) | Untriaged | | |
| `eb8f4afa` | #2373 | revert: stop defaulting Slack work to code channels (#2373 ) | Untriaged | | |
| `110098c3` | #2385 | fix(ui): remove context size checkmark (#2385 ) | Untriaged | | |
| `37641150` | #2381 | refactor: expose browser tools to the main agent (#2381 ) | Untriaged | | |
| `5ea63f4a` | #2364 | build(deps): bump the minor-and-patch group with 15 updates (#2364 ) | Untriaged | | |
| `22c1543a` | #2365 | build(deps): bump the major group with 2 updates (#2365 ) | Untriaged | | |
| `9a559481` | #2392 | Mark Kanban as experimental (#2392 ) | Untriaged | | |
| `2531b9dd` | #2374 | docs(repo): update OpenWiki (#2374 ) | Untriaged | | |
| `0d8ad72e` | #2270 | chore: bump deepagents to 0.7.9 (#2270 ) | Untriaged | | |
| `c6cb7ca4` | #2395 | fix(deps): patch transitive dependency vulnerabilities (#2395 ) | Untriaged | | |
| `395c6ec5` | #2398 | fix: support the default root sandbox snapshot (#2398 ) | Untriaged | | |
| `4989d854` | #2399 | fix: make code channel promotion opt-in (#2399 ) | Untriaged | | |
| `1463e370` | #2378 | refactor: group modules by service instead of by category (#2378 ) | Untriaged | | |
| `ed68d0d7` | #2323 | fix: surface working tree connection failures (#2323 ) | Untriaged | | |
| `ad29b0f0` | #2156 | chore: update Python and JavaScript dependencies (#2156 ) | Untriaged | | |
| `a40c28e4` | #2296 | refactor(config): model `configurable` as a pydantic RunConfig (#2296 ) | Untriaged | | |
| `11743d4c` | #2404 | feat: classify run failures and say why in the failure reply (#2404 ) | Untriaged | | |
| `2b5e814f` | #2407 | feat(github): log every inbound webhook payload in full (#2407 ) | Untriaged | | |
| `bc8b0891` | #2397 | fix: resolve threads after attached pull requests close (#2397 ) | Untriaged | | |
| `d120e433` | #2411 | docs: clarify desktop platform support (#2411 ) | Untriaged | | |
| `257987ca` | #2402 | chore: require Python 3.14 as the minimum version (#2402 ) | Untriaged | | |
| `2cc45ed6` | #2396 | fix: hide compaction summaries from chat (#2396 ) | Untriaged | | |
| `86cbbee2` | #2421 | chore: switch Python type checking to ty (#2421 ) | Untriaged | | |
| `9c4f13b6` | #2424 | fix: use bare code fences in Slack replies (#2424 ) | Untriaged | | |
| `8ca30952` | #2409 | fix(ui): forward backend responses instead of stringifying them (#2409 ) | Untriaged | | |
| `a3c9ed9d` | #2427 | feat(ui): move workflow approval into transcript (#2427 ) | Untriaged | | |
| `0323b8d2` | #2425 | docs: establish lightweight OEP process (#2425 ) | Untriaged | | |
| `5589fc24` | #2426 | fix: clarify workflow push approval prompts (#2426 ) | Untriaged | | |
| `d54c831c` | #2431 | chore(desktop): bump version to 0.2.6 (#2431 ) | Untriaged | | |
| `1fa5882b` | #2428 | fix(desktop): connect Slack and Notion through a loopback handoff (#2428 ) | Untriaged | | |
| `b7d687db` | #2433 | fix(desktop): preserve adaptive macOS Dock icon (#2433 ) | Untriaged | | |
| `7be36858` | #2394 | docs: drop the legacy LangSmith-brokered GitHub OAuth setup (#2394 ) | Untriaged | | |
| `2d407c41` | #2423 | docs: trim agent instructions (#2423 ) | Untriaged | | |
| `df99ccb5` | #2417 | fix(agent): narrow Corridor guidance (#2417 ) | Untriaged | | |
| `7fb7b6c7` | #2439 | docs: restore OpenWiki guidance (#2439 ) | Untriaged | | |
| `70004c6a` | #2416 | docs(customization): update prompt-section table with current section names (fixes #2371 ) (#2416 ) | Untriaged | | |
| `7da6f448` | #2438 | feat: replace Fable 5 with Fable 5.1 (#2438 ) | Untriaged | | |
| `a150cc67` | #2441 | Keep generated artifacts out of repositories (#2441 ) | Untriaged | | |
| `0f80306e` | #2390 | fix(ui): tweak themes (#2390 ) | Untriaged | | |
| `39644993` | #2440 | feat: persist agent run usage telemetry (#2440 ) | Untriaged | | |
| `01b54758` | #2435 | feat: inject user LangSmith credentials through sandbox proxy (#2435 ) | Untriaged | | |
| `b294314d` | #2442 | fix: remove sidebar bottom scroll shadow gap (#2442 ) | Untriaged | | |
| `d9095795` | #2450 | feat: Haiku thread-title fallback for Anthropic-only deployments (#2450 ) | Untriaged | | |
| `b224c29e` | #2449 | feat: allow explicitly authorized force pushes (#2449 ) | Untriaged | | |
| `f3e656b5` | #2408 | fix: preserve Slack reply order during active work (#2408 ) | Untriaged | | |
| `4e5e394d` | #2422 | fix(ui): scroll to submitted follow-ups (#2422 ) | Untriaged | | |
| `5361ef97` | #2434 | fix(desktop): keep updater artifact names consistent (#2434 ) | Untriaged | | |
| `1203aae1` | #2468 | fix(desktop): call Codex login a ChatGPT subscription (#2468 ) | Untriaged | | |
| `71530e70` | #2470 | fix: omit snapshot_id instead of sending "" for the root snapshot (#2470 ) | Untriaged | | |
| `265b00c3` | #2471 | fix: remove priority sidebar sorting (#2471 ) | Untriaged | | |
| `65d775f4` | #2350 | feat(desktop): enable terminal and changes on the local home screen (#2350 ) | Untriaged | | |
| `9ff59545` | #2467 | Dispatch stable desktop releases to Homebrew (#2467 ) | Untriaged | | |
| `135cac50` | #2475 | feat: add GPT-6 Astra (#2475 ) | Untriaged | | |
| `7eb1decd` | #2476 | chore(desktop): bump version to 0.2.7 (#2476 ) | Untriaged | | |
| `19cefef6` | #2481 | feat: support optional model and effort environment defaults (#2481 ) | Untriaged | | |
| `497fa043` | #2477 | fix: default to Opus for Anthropic-only deployments (#2477 ) | Untriaged | | |
| `4dff9ccb` | #2463 | refactor(config): unify environment configuration and standardize LangSmith env (#2463 ) | Untriaged | | |
| `0621c0f7` | #2489 | feat(langsmith): discover the tenant and trace every run into LANGSMITH_PROJECT (#2489 ) | Untriaged | | |
| `ea0abc82` | #2486 | feat(dashboard): serve the bundled dashboard from the backend origin (#2486 ) | Untriaged | | |
| `8a7982d0` | #2491 | fix(agent): keep the server's runtime out of the graphs factories bind (#2491 ) | Untriaged | | |
| `c87e5dce` | #2493 | feat(dashboard): hot reload on the backend's origin via a Vite dev proxy (#2493 ) | Untriaged | | |
| `0ed3ad89` | #2495 | fix(dashboard): treat the dev-proxied UI as living on the backend origin (#2495 ) | Untriaged | | |
| `2ad5524a` | #2496 | fix: guard subagent workflow pushes (#2496 ) | Untriaged | | |
| `33e735cb` | #2483 | chore: remove obsolete write_todos feedback (#2483 ) | Untriaged | | |
| `342559af` | #2499 | docs: split the guide into installation (deploying) and local development, add make tunnel (#2499 ) | Untriaged | | |
| `de7eb3a9` | #2507 | chore(config): drop the *_PROD environment aliases (#2507 ) | Untriaged | | |
| `4d7c1124` | #2503 | perf: scrub custom middleware trace inputs (#2503 ) | Untriaged | | |
| `1e6588c7` | #2511 | fix: remove docs-plz Slack gate (#2511 ) | Untriaged | | |
| `04e67efe` | #2469 | fix: land orphaned usage telemetry follow-ups (#2469 ) | Untriaged | | |
| `184dc55c` | #2512 | chore: log usage leaderboard aggregation (#2512 ) | Untriaged | | |
| `66afd4c1` | #2516 | Unify dashboard typography (#2516 ) | Untriaged | | |
| `3bbaead9` | #2523 | docs: require behavior-focused tests (#2523 ) | Untriaged | | |
| `e854f25b` | #2524 | fix: filter agent costs by trace (#2524 ) | Untriaged | | |
| `5951d56c` | #2510 | fix: keep queued messages visible after refresh (#2510 ) | Untriaged | | |
| `70412adb` | #2521 | fix(dashboard): lower thread-search page size to cut LangGraph rate-limit cost (#2521 ) | Untriaged | | |
| `646b274e` | #2403 | docs(repo): update OpenWiki (#2403 ) | Untriaged | | |
| `0eae53cb` | #2528 | ci: scope agent unit tests to relevant changes (#2528 ) | Untriaged | | |
| `8121935e` | #2479 | fix: keep composer branch aligned with current checkout (#2479 ) | Untriaged | | |
| `9d35037d` | #2509 | feat: show thread title and actions in the top bar (#2509 ) | Untriaged | | |
| `e56feb08` | #2536 | fix(tools): include the protocol id when the thread tool starts a run (#2536 ) | Untriaged | | |
| `629b3ec7` | #2526 | fix(ui): strip request framing headers in the backend proxy (#2526 ) | Untriaged | | |
| `4f2e7f93` | #2527 | fix: add LangSmith trace to failed-run footer (#2527 ) | Untriaged | | |
| `74ea4dc5` | #2525 | fix: migrate HTTP clients to HTTPX2 (#2525 ) | Untriaged | | |
| `ffc48254` | #2514 | feat(ui): add project compose shortcut (#2514 ) | Untriaged | | |
| `0ff86e22` | #2539 | fix(ui): make new thread heading project-agnostic (#2539 ) | Untriaged | | |
| `81baa595` | #2544 | fix(deps): patch hono and js-yaml security alerts (#2544 ) | Untriaged | | |
| `1bc788d3` | #2537 | refactor(ui): run agent threads on the SDK's useStream (#2537 ) | Untriaged | | |
| `648053fa` | #2522 | fix(models): align OpenAI context windows with Codex (#2522 ) | Untriaged | | |
| `cafbe464` | #2513 | fix: preserve background completion provenance (#2513 ) | Untriaged | | |
| `aad35eb7` | #2543 | feat: add workspace-scoped MCP connections (#2543 ) | Untriaged | | |
| `4ab72d1c` | #2506 | fix(slack): never go silent on an addressed request, and stop requiring a repository (#2506 ) | Untriaged | | |
| `2add0629` | #2538 | feat: sign PRs with model details (#2538 ) | Untriaged | | |
| `5cc9d6f9` | #2531 | fix: show web message sends optimistically (#2531 ) | Untriaged | | |
| `17c2857c` | #2540 | Trust unedited self-authored fix comments (#2540 ) | Untriaged | | |
| `d7b08e2b` | #2530 | refactor: use LangGraph v3 streaming throughout (#2530 ) | Untriaged | | |
| `b366be20` | #2551 | fix: render working directory in system prompt (#2551 ) | Untriaged | | |
| `b489426b` | #2541 | feat: add stable chat ordering and no-project grouping (#2541 ) | Untriaged | | |
| `0275efea` | #2552 | refactor(dashboard): split thread_api into a threads package (#2552 ) | Untriaged | | |
| `92ab8f5a` | #2553 | refactor: make cross-module helpers public and enforce it with ruff (#2553 ) | Untriaged | | |
| `1711e572` | #2547 | feat(slack): collect private thread ratings and comments (#2547 ) | Untriaged | | |
| `96fb6b07` | #2405 | feat: enhance Open SWE thread discovery and inspection (#2405 ) | Untriaged | | |
| `5853c66b` | #2555 | docs: codify concise PR descriptions (#2555 ) | Untriaged | | |
| `0061ec40` | #2546 | feat(ui): dev server against a deployed backend (#2546 ) | Untriaged | | |
| `808f8a79` | #2560 | fix: use Slack headers helper for modals (#2560 ) | Untriaged | | |
| `f60add00` | #2559 | chore(desktop): bump version to 0.2.8 (#2559 ) | Untriaged | | |
| `26bf6a58` | #2565 | feat: prefer Fireworks for GLM 5.3 Flash (#2565 ) | Untriaged | | |
| `36c828ad` | #2566 | ci: isolate Playwright from broken Chrome apt feed (#2566 ) | Untriaged | | |
| `430b290f` | #2571 | fix: restore native macOS window controls (#2571 ) | Untriaged | | |
| `6fb74746` | #2574 | Clarify README tagline punctuation (#2574 ) | Untriaged | | |
| `abedcbac` | #2572 | feat(desktop): add manual update check (#2572 ) | Untriaged | | |
| `d9556090` | #2575 | fix: respect no-project compose selection (#2575 ) | Untriaged | | |
| `ce25ad24` | #2564 | fix(slack): unify thread feedback submission and completion (#2564 ) | Untriaged | | |
| `d6240b1b` | #2567 | fix(ui): recover stuck pooled agent streams (#2567 ) | Untriaged | | |
| `201d41de` | #2474 | feat: roll out adaptive model routing to all threads (#2474 ) | Untriaged | | |
| `1c24c8f1` | #2563 | feat(mcp): add scoped runtime and OAuth client credentials (#2563 ) | Untriaged | | |
| `c9d3e4a7` | #2583 | feat: remove live review findings cap (#2583 ) | Untriaged | | |
| `8c99ba1f` | #2577 | feat: add backend swagger.json contract (#2577 ) | Untriaged | | |
| `5f1c16f4` | #2520 | fix: simplify status text shimmer (#2520 ) | Untriaged | | |
| `799ce3c1` | #2578 | docs: scope agent instructions to their directories (#2578 ) | Untriaged | | |
| `19da5d55` | #2591 | refactor: simplify system prompt delivery (#2591 ) | Untriaged | | |
| `1f7bb31a` | #2590 | fix(ui): return from settings to active thread (#2590 ) | Untriaged | | |
| `00b0af87` | #2587 | refactor: remove dedicated Corridor MCP integration (#2587 ) | Untriaged | | |
| `c415e093` | #2581 | fix: preserve desktop thread on reload (#2581 ) | Untriaged | | |
| `59998510` | #2580 | refactor: replace hardcoded provider tools with workspace MCPs (#2580 ) | Untriaged | | |
| `e4b9bedb` | #2599 | feat(desktop): enable Datadog RUM in releases (#2599 ) | Untriaged | | |
| `ec9d5546` | #2602 | refactor: extract model prompts into markdown resources (#2602 ) | Untriaged | | |
| `7140075e` | #2598 | feat: add delayed Slack thread feedback (#2598 ) | Untriaged | | |
| `2445e1af` | #2605 | feat: add web thread feedback (#2605 ) | Untriaged | | |
| `358bd880` | #2607 | ci: close stale pull requests automatically (#2607 ) | Untriaged | | |
| `b1725f21` | #2608 | feat: simplify thread feedback to Good and Bad (#2608 ) | Untriaged | | |
| `27f4e3c9` | #2415 | feat(environments): publish environments from the admin sandbox, verify nightly (#2415 ) | Untriaged | | |
| `f95b7e86` | #2621 | fix(ui): stop the agent thread page render loop (#2621 ) | Untriaged | | |
| `64b21669` | #2625 | fix: hide live compaction summaries (#2625 ) | Untriaged | | |
| `703a0e12` | #2606 | refactor: standardize agent execution terminology on invocation (#2606 ) | Untriaged | | |
| `2b0ab2e5` | #2508 | fix: require a GitHub login allowlist at startup (#2508 ) | Untriaged | | |
| `047d84fd` | #2632 | refactor: structure core agent prompts (#2632 ) | Untriaged | | |
| `b3fe46df` | #2637 | fix(slack): show only the last path component of model names in the footer (#2637 ) | Untriaged | | |
| `461c121f` | #2641 | fix: link Slack failure replies to LangSmith instead of Open SWE Web (#2641 ) | Untriaged | | |
| `ae9337a7` | #2642 | fix(ui): let modifier shortcuts like `Cmd` /`Ctrl` +`N` fire while typing (#2642 ) | Untriaged | | |
| `6f2b36e4` | #2644 | revert: recover stuck pooled agent streams (#2567 ) (#2644 ) | Untriaged | | |
| `a1e1345a` | #2634 | feat: hide compaction summaries and add conversation offloading (#2634 ) | Untriaged | | |
| `3b76cf26` | #2601 | feat: add owner-only private threads (#2601 ) | Untriaged | | |
| `0b2cc083` | #2651 | fix(ui): collapse long user messages with show more instead of nested scroll (#2651 ) | Untriaged | | |
| `cb9ca35a` | #2649 | fix: enforce default sandbox command timeout (#2649 ) | Untriaged | | |
| `cd5ebf76` | #2622 | fix: allow cross-repo baby-sit watches (#2622 ) | Untriaged | | |
| `8520b826` | #2623 | fix(sandbox): delete files through async execution (#2623 ) | Untriaged | | |
| `e8fdf291` | #2624 | fix: normalize missing run source before preparation (#2624 ) | Untriaged | | |
| `98ae7413` | #2633 | refactor(linear): remove direct API access (#2633 ) | Untriaged | | |
| `7eea59df` | #2597 | fix(desktop): keep the top strip draggable and the sidebar toggle clickable (#2597 ) | Untriaged | | |
| `e691cb14` | #2654 | feat: add Auto mode to the model picker (#2654 ) | Untriaged | | |
| `16b59261` | #2650 | feat: show Slack's animated Thinking status while the agent works in threads (#2650 ) | Untriaged | | |
| `0f439ec2` | #2557 | fix: allow concurrent local dev runs (#2557 ) | Untriaged | | |
| `14eea6ea` | #2653 | fix: stabilize adaptive model routing (#2653 ) | Untriaged | | |
| `1c0a8caa` | #2659 | feat(ui): move the thread visibility picker into the header (#2659 ) | Untriaged | | |
| `429085b6` | #2647 | feat: scope thread credentials and preserve initiator PR ownership (#2647 ) | Untriaged | | |
| `fd2e82f6` | #2660 | chore(desktop): bump version to 0.2.9 (#2660 ) | Untriaged | | |
| `77318fd7` | #2406 | fix: drop untrusted-data warning from background task notification (#2406 ) | Untriaged | | |
| `5a2c0bfa` | #2596 | fix: keep RunConfig.dump from raising on non-JSON extras (#2596 ) | Untriaged | | |
| `01f6a808` | #2614 | docs: include diffstats in PR delivery messages (#2614 ) | Untriaged | | |
| `0af3fe37` | #2617 | fix(ui): default Datadog RUM site to us5 (#2617 ) | Untriaged | | |
| `06352496` | #2375 | fix(dashboard): fill the Slack manifest with this deployment's URLs (#2375 ) | Untriaged | | |
| `f8361ce4` | #2418 | fix(slack): a join is news for the next turn, not a turn of its own (#2418 ) | Untriaged | | |
| `24672d95` | #2419 | feat(slack): let the agent name who starts out in a code channel (#2419 ) | Untriaged | | |
| `d7203932` | #2640 | feat: org-wide adaptive model routing toggle (#2640 ) | Untriaged | | |
| `ba086656` | #2669 | fix(slack): read subtype off the parsed event, not with dict.get (#2669 ) | Untriaged | | |
| `9752b06c` | #2682 | fix(e2e): expose installation repositories (#2682 ) | Untriaged | | |
| `8c86049c` | #2690 | fix: discover desktop updates without restarting (#2690 ) | Untriaged | | |
| `d77d7f4a` | #2673 | fix: persist web model choice across Slack turns (#2673 ) | Untriaged | | |
| `c10712e0` | #2693 | feat: add Linear ticket quality skill (#2693 ) | Untriaged | | |
| `143ca351` | #2668 | docs: propose expedited Slack review as OEP-0002 (#2668 ) | Untriaged | | |
| `711804bc` | #2636 | feat(ui): label the environment selector in the composer (#2636 ) | Untriaged | | |
| `7d40d1f5` | #2594 | feat(mcp): add user-scoped MCP connections (#2594 ) | Untriaged | | |
| `dbafb947` | #2549 | feat(sandbox): proxy sandbox service URLs through the dashboard (#2549 ) | Untriaged | | |
| `299df7d9` | #2701 | docs: align setup guides with global defaults navigation (#2701 ) | Untriaged | | |
| `5623f4e5` | #2694 | feat: add archive all threads setting (#2694 ) | Untriaged | | |
| `f8d11f2f` | #2702 | fix(ui): use repository selector for global default (#2702 ) | Untriaged | | |
| `fea4c785` | #2698 | feat(desktop): allow personal tracing projects (#2698 ) | Untriaged | | |
| `2ed7ab1e` | #2609 | feat: allow Slack bots to start system threads (#2609 ) | Untriaged | | |
| `f654b96e` | #2556 | docs: document optional code scanning alerts permission (#2556 ) | Untriaged | | |
| `5d7cd295` | #2670 | ci: typecheck main before promoting it to prod (#2670 ) | Untriaged | | |
| `0564ccb8` | #2713 | docs(prompt): clarify web sandbox workflow (#2713 ) | Untriaged | | |
| `e0d9aff5` | #2712 | refactor(slack): use the official async Python SDK (#2712 ) | Untriaged | | |
| `6c925eea` | #2717 | refactor: remove Stagehand browser automation and voice dictation (#2717 ) | Untriaged | | |
| `727f6969` | #2700 | fix(desktop): copy Datadog links natively (#2700 ) | Untriaged | | |
| `f5b43ed0` | #2615 | fix(ui): move terminal actions into panel header (#2615 ) | Untriaged | | |
| `ce328521` | #2720 | docs: encourage strong typing and discourage Any in AGENTS.md (#2720 ) | Untriaged | | |
| `b403ec75` | #2719 | feat(slack): stage uploaded Slack files in the thread sandbox (#2719 ) | Untriaged | | |
| `ae8ed49e` | #2722 | fix: attribute routed model in PR footers (#2722 ) | Untriaged | | |
| `68dcbb4e` | #2648 | fix: keep non-image bytes out of read_file image blocks (#2648 ) | Untriaged | | |
| `71a654cd` | #2665 | fix(slack): default untagged collaborative threads to silence (#2665 ) | Untriaged | | |
| `25641e04` | #2638 | feat(slack): add every Slack participant to existing agent threads (#2638 ) | Untriaged | | |
| `479463f9` | #2676 | fix: preview PR links throughout messages (#2676 ) | Untriaged | | |
| `e48bdf4c` | #2324 | test: remove static prompt prose assertions (#2324 ) | Untriaged | | |
| `f88baead` | #2725 | test: drop the unused OBSERVABILITY_AUTHORIZED_EMAILS setting (#2725 ) | Untriaged | | |
| `ac9740fb` | #2681 | fix: say "Feedback submitted" after Slack thread feedback (#2681 ) | Untriaged | | |
| `8ca9d7e2` | #2683 | feat(analytics): define PostgreSQL usage events and schema (#2683 ) | Untriaged | | |
| `e467dd31` | #2684 | feat(analytics): process usage events and retain durable history (#2684 ) | Untriaged | | |
| `1aa5d3b0` | #2685 | feat(analytics): derive all Usage reports from PostgreSQL (#2685 ) | Untriaged | | |
| `914f3d77` | #2729 | feat: include PR stack context in the fix prompt (#2729 ) | Untriaged | | |
| `ebd7b177` | #2731 | feat: add generic thread feedback tool (#2731 ) | Untriaged | | |
| `e2c8d781` | #2732 | fix(ui): stop the sidebar requesting the same page three times (#2732 ) | Untriaged | | |
| `9fba9672` | #2734 | feat: grant admin permissions to private admin threads (#2734 ) | Untriaged | | |
2026-07-03 11:46:00 -04:00
_Maintenance: after a `git sync` , add new `dev..upstream/main` SHAs as **Untriaged** (edit `triage.jsonl` ) and bump "Last synced". A successful `git cherry-pick -x` auto-moves the row to **Landed** via the `post-commit` journal + `make triage-reconcile` ._