Merge branch 'dev' into dependabot/npm_and_yarn/ui/minor-and-patch-a2a21cbdeb

This commit is contained in:
Adam Moussa 2026-07-23 14:07:53 -04:00 • committed by GitHub
commit 0e290a159c
No known key found for this signature in database
GPG key ID: B5690EEEBB952194
5 changed files with 16 additions and 10 deletions

View file

@ -22,7 +22,7 @@ jobs:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v7
- uses: astral-sh/setup-uv@11f9893b081a58869d3b5fccaea48c9e9e46f990 # v8.3.2
- uses: astral-sh/setup-uv@c771a70e6277c0a99b617c7a806ffedaca235ff9 # v9.0.0
- name: Install dependencies
run: uv sync --locked --extra dev
- name: Run lint
@ -33,7 +33,7 @@ jobs:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v7
- uses: astral-sh/setup-uv@11f9893b081a58869d3b5fccaea48c9e9e46f990 # v8.3.2
- uses: astral-sh/setup-uv@c771a70e6277c0a99b617c7a806ffedaca235ff9 # v9.0.0
- name: Install dependencies
run: uv sync --locked --extra dev
- name: Run format check
@ -59,7 +59,7 @@ jobs:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v7
- uses: astral-sh/setup-uv@11f9893b081a58869d3b5fccaea48c9e9e46f990 # v8.3.2
- uses: astral-sh/setup-uv@c771a70e6277c0a99b617c7a806ffedaca235ff9 # v9.0.0
- name: Install dependencies
run: uv sync --locked --extra dev
- name: Run unit tests
@ -71,7 +71,7 @@ jobs:
timeout-minutes: 30
steps:
- uses: actions/checkout@v7
- uses: astral-sh/setup-uv@11f9893b081a58869d3b5fccaea48c9e9e46f990 # v8.3.2
- uses: astral-sh/setup-uv@c771a70e6277c0a99b617c7a806ffedaca235ff9 # v9.0.0
- uses: actions/setup-node@v7
with:
node-version: "24"

View file

@ -79,7 +79,7 @@ jobs:
timeout-minutes: 360
steps:
- uses: actions/checkout@v7
- uses: astral-sh/setup-uv@11f9893b081a58869d3b5fccaea48c9e9e46f990 # v8.3.2
- uses: astral-sh/setup-uv@c771a70e6277c0a99b617c7a806ffedaca235ff9 # v9.0.0
- name: Install dependencies
run: uv sync --locked
- name: Run reviewer eval

View file

@ -26,7 +26,7 @@ jobs:
run: |
git remote add upstream https://github.com/langchain-ai/open-swe.git || true
- uses: actions/setup-python@v6
- uses: actions/setup-python@v7
with:
python-version: "3.12"

View file

@ -1,4 +1,4 @@
{"_meta": {"last_synced": "1443fc4b", "last_synced_date": "2026-07-21"}}
{"_meta": {"last_synced": "60e7307c", "last_synced_date": "2026-07-23"}}
{"sha": "0b76afdc", "pr": 1653, "subject": "reviews block agenda, sticky headers, diff scroll", "disposition": "landed", "reason": "", "branch": "cherry-pick-upstream", "local_sha": null, "updated": "2026-07-02T00:00:00Z"}
{"sha": "7530653b", "pr": 1655, "subject": "ResizeObserver settle for review scroll-to", "disposition": "landed", "reason": "", "branch": "cherry-pick-upstream", "local_sha": null, "updated": "2026-07-02T00:00:00Z"}
{"sha": "23bd4a63", "pr": 1660, "subject": "top padding to sticky review block header", "disposition": "landed", "reason": "", "branch": "cherry-pick-upstream", "local_sha": null, "updated": "2026-07-02T00:00:00Z"}
@ -134,7 +134,7 @@
{"sha": "4ea2441a", "pr": 1791, "subject": "fix: match embedded review description background (#1791)", "disposition": "deferred", "reason": "Near-clean UI-only: ReviewMainBody.tsx background match for the embedded review description; merges clean, zero fork drift. Batch with the next clean-port round.", "branch": "feature/upstream-clean-batch-jul21", "local_sha": null, "updated": "2026-07-21T18:00:13Z"}
{"sha": "589dfd83", "pr": 1787, "subject": "fix: Harden Stagehand browser URL handling (#1787)", "disposition": "wont-merge", "reason": "Follows #1648 (wont-merge): fork does not carry the Stagehand browser subagent — this 'fix' re-adds the entire module (992 insertions; modify/delete vs HEAD) plus the stagehand dep in pyproject/uv.lock. Adopting would resurrect a feature rejected under the curated-tools policy.", "branch": "", "local_sha": null, "updated": "2026-07-21T18:00:14Z"}
{"sha": "9bbd65d3", "pr": 1781, "subject": "fix: derive model context windows from LangChain profiles (#1781)", "disposition": "deferred", "reason": "Pair with deferred #1778 on context-usage-ui: derives model context windows from LangChain profiles. options.py conflicts — re-key to the fork's Bedrock/Fireworks model map (upstream IDs differ; verify LangChain profiles even resolve for the fork's Bedrock-style IDs, else keep static values). uv.lock bumps langchain to a profiles-capable version; test_model_fallback_resolution also conflicts. Port with/after #1778.", "branch": "context-usage-ui", "local_sha": null, "updated": "2026-07-21T18:00:14Z"}
{"sha": "df743658", "pr": 1774, "subject": "feat: add repository skill support to the coding agent (#1774)", "disposition": "deferred", "reason": "New feature: loads repo-provided skills into the coding agent (TrustedSkillsMiddleware, a deepagents SkillsMiddleware subclass pinned to a trusted ref, + repo_prep discovery). SECURITY review required before adopting — skills are repo-controlled prompt content (injection surface); verify the trusted-ref pinning against the fork threat model before wiring. Only server.py conflicts (fork tool/middleware wiring — re-key stack order); trusted_skills.py and repo_prep.py hunks merge clean.", "branch": "", "local_sha": null, "updated": "2026-07-21T18:00:23Z"}
{"sha": "df743658", "pr": 1774, "subject": "feat: add repository skill support to the coding agent (#1774)", "disposition": "wont-merge", "reason": "Upstream reverted this feature in #1800: its factory-time ensure_sandbox_for_thread call ran outside the serialized run and raced the deterministic sandbox name (prod sandbox-create 409s spiking from the #1774 merge date). Feature withdrawn upstream; the fork's deferred security review is moot. If upstream re-lands repo skills (host-side .agents/skills resolution per #1800), triage that new commit fresh — the prompt-injection / trusted-ref concerns in the old reason still apply.", "branch": "", "local_sha": null, "updated": "2026-07-23T16:54:54Z"}
{"sha": "75fb8b48", "pr": 1786, "subject": "Fix PR creation guard shell bypasses (#1786)", "disposition": "deferred", "reason": "SECURITY priority, clean merge: closes shell-bypass holes in PullRequestCreationGuardMiddleware (nested 'bash -c' expansion to depth 3, quoted-executable normalization) — a guard this fork actively wires. Port promptly; ALSO mirror the nested-shell expansion into the fork-only PullRequestVerdictGuardMiddleware (pr_verdict_guard.py), which shares the naive shlex approach and has the same bypass shape.", "branch": "feature/upstream-clean-batch-jul21", "local_sha": null, "updated": "2026-07-21T18:00:23Z"}
{"sha": "32e81f29", "pr": 1788, "subject": "Fix: Fix Insecure Direct Object Reference in slack_start_new_thread.py (#1788)", "disposition": "deferred", "reason": "SECURITY priority, clean merge: IDOR fix — slack_start_new_thread now enforces the deployment allowlist (_is_repo_allowed) and per-user repo access (require_repo_access_for_user keyed on the parent thread's github_login) before dispatching a run against a different repo. Both helpers exist in the fork at the same paths; merges clean. Port promptly.", "branch": "feature/upstream-clean-batch-jul21", "local_sha": null, "updated": "2026-07-21T18:00:23Z"}
{"sha": "ab85b372", "pr": 1764, "subject": "fix: add exc_info to swallowed exception in push re-review webhook (#1764)", "disposition": "deferred", "reason": "Trivial: adds exc_info=True to the swallowed exception log in process_github_push_event (webhooks/github.py). Merges clean. Batch with the next clean-port round.", "branch": "feature/upstream-clean-batch-jul21", "local_sha": null, "updated": "2026-07-21T18:00:23Z"}
@ -143,3 +143,6 @@
{"sha": "0ed560a5", "pr": 1779, "subject": "fix: settle review checks after run failures (#1779)", "disposition": "deferred", "reason": "Desirable: run-failure completion webhook now settles reviewer check runs left open when the graph dies (_settle_failed_reviewer_check; uses settle_review_check_run + review_check_pending_result, both already in the fork's review/publish.py from the #214/#215 ports). Conflict is fork drift in completion.py (failure-reply customizations); re-key the new helper in and port with its 159-line test.", "branch": "", "local_sha": null, "updated": "2026-07-21T18:00:33Z"}
{"sha": "5b5e6076", "pr": 1790, "subject": "chore: Add open wiki docs (#1790)", "disposition": "wont-merge", "reason": "Upstream-repo openwiki doc site + AGENTS.md/CLAUDE.md pointers: content documents upstream's codebase and would be wrong for this fork (conflicts with the fork's heavily customized CLAUDE.md, which is canonical). Its companion auto-update workflow is bot-push docs automation counter to the fork's workflow-gating posture (#1773).", "branch": "", "local_sha": null, "updated": "2026-07-21T18:00:33Z"}
{"sha": "1443fc4b", "pr": 1792, "subject": "fix: Update openwiki gh action (#1792)", "disposition": "wont-merge", "reason": "Follows #1790 (wont-merge): fixes the openwiki-update workflow this fork does not carry (modify/delete vs HEAD).", "branch": "", "local_sha": null, "updated": "2026-07-21T18:00:33Z"}
{"sha": "bedc57b8", "pr": 1796, "subject": "fix: cap execute output by making SandboxBackendProxy a BaseSandbox (#1796)", "disposition": "deferred", "reason": "Real fix (unbounded execute stdout pulled into the worker → OOM risk) but inapplicable at the fork's deepagents==0.6.12: no capture-offload API exists (ExecuteOffloadResult / execute_accepts_timeout absent; FilesystemMiddleware has no _resolve_capture BaseSandbox gate), so the bug it fixes cannot occur yet. Re-triage together with deferred #1745 (deepagents 0.6.12→0.7.x bump) — landing that bump makes this fix required. Fork's SandboxBackendProxy has diverged (sync-era, bound_repo repo-binding, no reconnect machinery): hand-apply the execute_with_offload/aexecute_with_offload delegation onto the fork proxy rather than cherry-pick.", "branch": "", "local_sha": null, "updated": "2026-07-23T16:54:54Z"}
{"sha": "e1138cf5", "pr": 1797, "subject": "fix: merge concurrent trusted skill refs (#1797)", "disposition": "wont-merge", "reason": "Follow-up fix to #1774's TrustedSkillsMiddleware, which the fork never adopted (row df743658) and upstream itself reverted in #1800 — nothing to apply.", "branch": "", "local_sha": null, "updated": "2026-07-23T16:54:54Z"}
{"sha": "60e7307c", "pr": 1800, "subject": "revert: repository skill support for the coding agent (#1774, #1797) (#1800)", "disposition": "wont-merge", "reason": "Revert of #1774 + #1797; the fork adopted neither, so there is nothing to revert. Upstream's rationale: #1774's factory-time ensure_sandbox_for_thread ran outside the serialized run and raced the thread-deterministic sandbox name (prod create-409s). Fork invariant holds: its single provisioning call sits inside the __creating__-sentinel lifecycle within the interrupt-serialized run.", "branch": "", "local_sha": null, "updated": "2026-07-23T16:54:54Z"}

View file

@ -6,7 +6,7 @@ Commits on `upstream/main` (langchain-ai/open-swe) not yet in `dev`, and the dec
Rows key on the **upstream SHA** (stable across local cherry-picks). Deferred rows are provisional
— re-inspect before picking. See the fork-maintenance runbook in `CLAUDE.md`.
**Last synced `upstream/main`:** `1443fc4b` (2026-07-21)
**Last synced `upstream/main`:** `60e7307c` (2026-07-23)
| sha | pr | subject | decision | why | branch |
|---|---|---|---|---|---|
@ -128,8 +128,11 @@ Rows key on the **upstream SHA** (stable across local cherry-picks). Deferred ro
| `c9a193e2` | #1766 | chore(deps): bump mcp from 1.27.2 to 1.28.1 (#1766) | Won't merge | indirect dependency bump (mcp); fork's own Dependabot handles these | |
| `d0b63551` | #1773 | fix: remove workflow push approval gating (#1773) | Won't merge | Removes WorkflowPushGuardMiddleware and the proxy-token permission ladder — both actively wired in this fork (server.py middleware stack; github_app.py scoped-mint fallback). Adopting would let agent runs push .github/workflows/ changes with no human approval and mint proxy tokens at full scope unconditionally — a security-posture loosening counter to Sea Haven gating. Keep the fork's guard; skip the doc/prompt relaxation too (fork prompt documents the approval flow). | |
| `589dfd83` | #1787 | fix: Harden Stagehand browser URL handling (#1787) | Won't merge | Follows #1648 (wont-merge): fork does not carry the Stagehand browser subagent — this 'fix' re-adds the entire module (992 insertions; modify/delete vs HEAD) plus the stagehand dep in pyproject/uv.lock. Adopting would resurrect a feature rejected under the curated-tools policy. | |
| `df743658` | #1774 | feat: add repository skill support to the coding agent (#1774) | Won't merge | Upstream reverted this feature in #1800: its factory-time ensure_sandbox_for_thread call ran outside the serialized run and raced the deterministic sandbox name (prod sandbox-create 409s spiking from the #1774 merge date). Feature withdrawn upstream; the fork's deferred security review is moot. If upstream re-lands repo skills (host-side .agents/skills resolution per #1800), triage that new commit fresh — the prompt-injection / trusted-ref concerns in the old reason still apply. | |
| `5b5e6076` | #1790 | chore: Add open wiki docs (#1790) | Won't merge | Upstream-repo openwiki doc site + AGENTS.md/CLAUDE.md pointers: content documents upstream's codebase and would be wrong for this fork (conflicts with the fork's heavily customized CLAUDE.md, which is canonical). Its companion auto-update workflow is bot-push docs automation counter to the fork's workflow-gating posture (#1773). | |
| `1443fc4b` | #1792 | fix: Update openwiki gh action (#1792) | Won't merge | Follows #1790 (wont-merge): fixes the openwiki-update workflow this fork does not carry (modify/delete vs HEAD). | |
| `e1138cf5` | #1797 | fix: merge concurrent trusted skill refs (#1797) | Won't merge | Follow-up fix to #1774's TrustedSkillsMiddleware, which the fork never adopted (row df743658) and upstream itself reverted in #1800 — nothing to apply. | |
| `60e7307c` | #1800 | revert: repository skill support for the coding agent (#1774, #1797) (#1800) | Won't merge | Revert of #1774 + #1797; the fork adopted neither, so there is nothing to revert. Upstream's rationale: #1774's factory-time ensure_sandbox_for_thread ran outside the serialized run and raced the thread-deterministic sandbox name (prod create-409s). Fork invariant holds: its single provisioning call sits inside the __creating__-sentinel lifecycle within the interrupt-serialized run. | |
| `83abea26` | #1724 | fix: accept natural-language Slack plan approvals (#1724) | Deferred | natural-language Slack plan approvals; touches fork-diverged plan-mode + Slack webhook stack (#130); post-reorg test paths need remap | plan-approval |
| `ddbe457b` | #1727 | fix: restore GPT-5.5 as default model (#1727) | Deferred | restores GPT-5.5 default in options/team_settings; fork picker is Bedrock/Fireworks-only — rides the #1708 OpenAI-models product decision (27b0ddeb) | model-picker |
| `30832d29` | #1731 | fix: preserve OpenAI Responses tool history (#1731) | Deferred | deletes SanitizeOpenAIResponsesMiddleware in favor of replay-history preservation in utils/model.py; supersedes deferred #1718 (35659177) — triage the pair together against fork-diverged middleware + model.py | openai-sanitize |
@ -147,12 +150,12 @@ Rows key on the **upstream SHA** (stable across local cherry-picks). Deferred ro
| `2e8ff4b7` | #1782 | chore: clarify shared response image guidance (#1782) | Deferred | Near-clean: docstring-only guidance in save_plan (shared responses persist Markdown only, never sandbox-local images — post screenshots directly to Slack) + 2 assertions in test_plan_review. Merges clean against fork. Batch with the next clean-port round. | feature/upstream-clean-batch-jul21 |
| `4ea2441a` | #1791 | fix: match embedded review description background (#1791) | Deferred | Near-clean UI-only: ReviewMainBody.tsx background match for the embedded review description; merges clean, zero fork drift. Batch with the next clean-port round. | feature/upstream-clean-batch-jul21 |
| `9bbd65d3` | #1781 | fix: derive model context windows from LangChain profiles (#1781) | Deferred | Pair with deferred #1778 on context-usage-ui: derives model context windows from LangChain profiles. options.py conflicts — re-key to the fork's Bedrock/Fireworks model map (upstream IDs differ; verify LangChain profiles even resolve for the fork's Bedrock-style IDs, else keep static values). uv.lock bumps langchain to a profiles-capable version; test_model_fallback_resolution also conflicts. Port with/after #1778. | context-usage-ui |
| `df743658` | #1774 | feat: add repository skill support to the coding agent (#1774) | Deferred | New feature: loads repo-provided skills into the coding agent (TrustedSkillsMiddleware, a deepagents SkillsMiddleware subclass pinned to a trusted ref, + repo_prep discovery). SECURITY review required before adopting — skills are repo-controlled prompt content (injection surface); verify the trusted-ref pinning against the fork threat model before wiring. Only server.py conflicts (fork tool/middleware wiring — re-key stack order); trusted_skills.py and repo_prep.py hunks merge clean. | |
| `75fb8b48` | #1786 | Fix PR creation guard shell bypasses (#1786) | Deferred | SECURITY priority, clean merge: closes shell-bypass holes in PullRequestCreationGuardMiddleware (nested 'bash -c' expansion to depth 3, quoted-executable normalization) — a guard this fork actively wires. Port promptly; ALSO mirror the nested-shell expansion into the fork-only PullRequestVerdictGuardMiddleware (pr_verdict_guard.py), which shares the naive shlex approach and has the same bypass shape. | feature/upstream-clean-batch-jul21 |
| `32e81f29` | #1788 | Fix: Fix Insecure Direct Object Reference in slack_start_new_thread.py (#1788) | Deferred | SECURITY priority, clean merge: IDOR fix — slack_start_new_thread now enforces the deployment allowlist (_is_repo_allowed) and per-user repo access (require_repo_access_for_user keyed on the parent thread's github_login) before dispatching a run against a different repo. Both helpers exist in the fork at the same paths; merges clean. Port promptly. | feature/upstream-clean-batch-jul21 |
| `ab85b372` | #1764 | fix: add exc_info to swallowed exception in push re-review webhook (#1764) | Deferred | Trivial: adds exc_info=True to the swallowed exception log in process_github_push_event (webhooks/github.py). Merges clean. Batch with the next clean-port round. | feature/upstream-clean-batch-jul21 |
| `7312851d` | #1777 | feat: add explicit plan approval tool (#1777) | Deferred | Feature: explicit approve_plan tool + plan-mode exit. All deps exist in fork (plan_store PLAN_STATUS_APPROVED/SHARED, thread_api._user_owns_thread). Conflicts: prompt.py (fork prompt constants), server.py (tool/middleware wiring), check_message_queue.py (fork dashboard-handoff + mid-run injection drift), AGENTS.md. Hand re-key those four; keep the whole vertical (tool + plan_mode + thread_api + 4 test files) on one side. | |
| `e51abe14` | #1754 | fix: skip oversized images before model calls (#1754) | Deferred | Desirable: 10MB image size cap + 'image omitted' text block before model calls, prevents oversized-image model failures. Conflicts only because the fork hardened fetch_image_block (SSRF redirect guard, host-only logging) — hunks are compatible; re-key the size check around the fork's guarded fetch and port impl + test together. | |
| `0ed560a5` | #1779 | fix: settle review checks after run failures (#1779) | Deferred | Desirable: run-failure completion webhook now settles reviewer check runs left open when the graph dies (_settle_failed_reviewer_check; uses settle_review_check_run + review_check_pending_result, both already in the fork's review/publish.py from the #214/#215 ports). Conflict is fork drift in completion.py (failure-reply customizations); re-key the new helper in and port with its 159-line test. | |
| `bedc57b8` | #1796 | fix: cap execute output by making SandboxBackendProxy a BaseSandbox (#1796) | Deferred | Real fix (unbounded execute stdout pulled into the worker → OOM risk) but inapplicable at the fork's deepagents==0.6.12: no capture-offload API exists (ExecuteOffloadResult / execute_accepts_timeout absent; FilesystemMiddleware has no _resolve_capture BaseSandbox gate), so the bug it fixes cannot occur yet. Re-triage together with deferred #1745 (deepagents 0.6.12→0.7.x bump) — landing that bump makes this fix required. Fork's SandboxBackendProxy has diverged (sync-era, bound_repo repo-binding, no reconnect machinery): hand-apply the execute_with_offload/aexecute_with_offload delegation onto the fork proxy rather than cherry-pick. | |
_Maintenance: after a `git sync`, add new `dev..upstream/main` SHAs as **Untriaged** (edit `triage.jsonl`) and bump "Last synced". A successful `git cherry-pick -x` auto-moves the row to **Landed** via the `post-commit` journal + `make triage-reconcile`._