* Align repo docs, templates, and metadata with Sea Haven handbook
- Replace dynamic upstream-fork badges with static License, Python,
and TypeScript badges; add the GitHub-native CI badge for dev.
- Repoint SECURITY.md contact to adam@seahavenind.com.
- Add .github/CODEOWNERS assigning reviews to @amoussa1229.
- Add PR template using the handbook structure.
- Add issue templates for bug, feature, and task plus a security link.
- Remove emoji from the README per CONTRIBUTING.md style.
Refs: SH-93
* Restore Linear 👀 acknowledgement and update metadata contacts
- README.md: bring back the documented 👀 reaction on Linear issues.
- README.md: refresh the TypeScript badge to 6.0+ to match ui/package.json.
- SECURITY.md + issue template: switch security contact to role alias.
Refs: SH-93
---------
Co-authored-by: amoussa1229 <166072409+amoussa1229@users.noreply.github.com>
Co-authored-by: Adam Moussa <adam@seahavenind.com>
* chore: decommission self-hosted AWS LangGraph stack
Removes the now-dead self-host IaC and AWS-only CI/CD after destroying the
dev + prod CloudFormation stacks (open-swe-dev, open-swe-prod, open-swe-iam,
and the dev-exclusive CDKToolkit-oswedev bootstrap) in account 328440206208,
us-east-1. The deployment is now managed (LangGraph Cloud + Vercel).
- remove infra/ (CDK app: app + IAM stacks, constructs, aspects, tests)
- remove deploy/ami (Packer AMI build) and deploy/seahaven (boot/config
scripts, DEPLOYMENT/ROTATION runbooks)
- remove AWS-only workflows: cd-infra, ci-infra, build-artifacts, rollback
- README: rewrite the Deployment section to the managed LangGraph Cloud +
Vercel view; drop dead links to infra/ and deploy/seahaven
Preserved: the shared default CDKToolkit bootstrap and promote-dev-to-prod.yml.
The RETAIN'd Secrets Manager shells and open-swe-<env>-assets S3 buckets
survive cdk destroy by design (orphaned) and need a separate deliberate cleanup.
* chore: clean up dangling references left by the AWS decommission
Folds in the FIX-level items from the #64 review gates (GPT-4.1 cross-review +
/sh-security-review), none of which were blockers:
- delete orphaned .github/scripts/{package-artifacts,publish-and-deploy,roll-box,
rollback}.sh — their only callers were the removed AWS deploy workflows
- drop the deleted /infra dir from dependabot.yml npm directories (was producing
a recurring Dependabot config error)
- remove the stale OSWE-IAC-SECRETS-LIST-01 suppression (referenced the deleted
infra/lib/constructs/instance-role.ts)
- repoint the README promotion link to promote-to-main.yml (renamed in #63)
The promote-dev-to-prod.yml comment in check-dev-green.sh is intentionally left
to #63, which rewrites that same line.
Prod went live 2026-06-29 on self-hosted AWS EC2 behind the shared
seahaven-com ALB, superseding the on-prem VM model the runbook described.
- Rewrite deploy/seahaven/DEPLOYMENT.md as the canonical end-to-end runbook:
infra CD (CDK stacks + OIDC roles + prod approval gate), config seeding
(put-config.sh, the 13 boot-required prod vars, fetch-config fail-fast),
app artifact deploy (S3 + SSM roll + is-active gate), promotion/rollback,
live prod facts, and a RETAIN secret-shell troubleshooting entry that
cross-references infra/README.md.
- Correct retired *.seahavenind.com hosts to *.seahaven.com throughout and
document the live GitHub/Slack/Linear webhook + OAuth endpoints.
- Add a concise Deployment section to README pointing at the runbook.
- Fix the stale host in the retired on-prem nginx/openswe.conf and mark it
superseded by the AMI template.
Hardcoding the Sea Haven no-type-prefix PR title made every PR fail
semantic-PR-title gates (this repo's PR Title Lint, upstream open-swe),
forcing manual retitling. Make the title rule detect a conventional-commit
gate and conform, falling back to the imperative style otherwise. Also add
Closes/Refs issue-linking guidance and the default-branch auto-close caveat.
Refs: #41
Co-authored-by: seahaven-openswe[bot] <296972425+seahaven-openswe[bot]@users.noreply.github.com>
Codify the box-only #4 customizations into Git so the AWS deployment
(which deploys from this repo) actually applies them — previously only
the retired sh-openswe box had them.
- prompt.py: branch names feature|bug|hotfix/<kebab> (optional <KEY->);
imperative PR titles with no conventional-commit type: prefix; PR body
Summary/Validation/Tests/Notes; handbook commit format. Rewrite the
collaboration template from an attribution MANDATE to a PROHIBITION —
no Co-authored-by bot trailer, no "Made by [Open SWE]" footer, no
agent/AI notes on any artifact.
- github_comments.py: add @seahaven-openswe (the deployed App slug) to
the mention triggers.
- authorship.py: remove the now-unused attribution helpers
(build_pr_attribution_footer, add_bot_coauthor_trailer,
add_pr_collaboration_note, PR_ATTRIBUTION_*). Keep OPEN_SWE_BOT_* —
server.py still uses them for the sandbox git identity.
- Flip the attribution unit tests to assert the no-attribution behavior;
drop tests for the removed helpers.
Commits stay authored as the triggering user for now — flipping
authorship to the bot account depends on the Vercel preview-deploy
constraint and is deferred to #11.
Refs: #4#11
Claude-Session: https://claude.ai/code/session_01DMhLf4G5V8MStJQyAW95hi
* feat: server-side Datadog/LangSmith observability tools + team creds
Add team-wide observability credential settings (Datadog DD_SITE/API/APP
keys, LangSmith API key) stored encrypted server-side, with an admin
dashboard section to connect/disconnect each provider. When connected,
get_agent loads read-only observability tools server-side: Datadog via its
hosted MCP server (langchain-mcp-adapters, toolsets=core) and LangSmith
read tools (langsmith_get_trace, langsmith_list_runs). Credentials live in
the LangGraph server process and are never exposed to the sandbox.
Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>
* fix: address review on observability tools
Address PR review feedback:
- Authorize observability tools per triggering user (admins + the
OBSERVABILITY_AUTHORIZED_EMAILS allowlist) so prompt-injected runs from
untrusted contributors can't reach team Datadog/LangSmith data.
- Use the documented Datadog MCP auth headers DD_API_KEY / DD_APPLICATION_KEY.
- Store each provider's credentials under its own store key to avoid a
read-modify-write race dropping the other provider on concurrent saves.
Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>
* fix: async email resolution in observability authorization gate
---------
Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>
* docs: document dashboard + refresh local dev setup in INSTALLATION
- add the web dashboard (ui/) and its FastAPI backend API to the setup flow
- document dashboard-login OAuth (GITHUB_APP_CLIENT_ID/SECRET, second callback
URL) as distinct from the LangSmith-brokered agent-runtime OAuth
- add new env vars: DASHBOARD_API_BASE_URL/BASE_URL/JWT_SECRET/ALLOWED_ORIGINS,
CONFIGURED_ADMINS, X_SERVICE_AUTH_JWT_SECRET, LANGGRAPH_URL, SANDBOX_TYPE,
REVIEWER_OUTCOMES_DATASET, PUBLIC_REPO_ORG_GATE, SLACK_CLIENT_ID/SECRET/TEAM_ID,
SLACK_REPO_OWNER/NAME
- add "Sign in with Slack" OIDC account-linking setup
- rewrite local dev: make dev serves 3 graphs + FastAPI on :2024; new step for
running the UI (bun) on :3000, incl. the required DASHBOARD_ALLOWED_ORIGINS
CORS setting and cookie wiring
- correct production langgraph.json to three graphs; document Vercel UI deploy
- add dashboard verify + troubleshooting sections
- README: dashboard feature bullet + updated install blurb
* docs: clarify dashboard API setup
Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>
---------
Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>
* feat: move github workflows to gh cli
Use LangSmith proxy auth to support gh-driven GitHub workflows while removing custom GitHub wrapper tools.
* docker ignore + snapshot and docker image updates
* updated image and instructions
* removing open_pr if needed after agent call
* feat: default to GPT-5.5 medium reasoning
Use OpenAI GPT-5.5 with medium reasoning as the default model and document the completion-token budget semantics for reasoning models.
* fix: use Responses API reasoning config
Pass GPT-5.5 reasoning settings through LangChain's Responses API parameter instead of the Chat Completions-only reasoning_effort field.
* feat: raise GPT-5.5 output budget
Set the default GPT-5.5 output token budget to the model maximum so long-running coding tasks have more room for reasoning and final responses.
* feat: align recursion limit with Deep Agents
Use Deep Agents' default recursion limit so longer coding runs have room to complete without Open SWE imposing a lower cap.
* chore: remove minimal effort level
* chore: reduce max tokens to 64_000
---------
Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>
This repository is no longer actively maintained and will not receive further updates. Added a prominent warning notice at the top of the README to inform users that the project has been deprecated.
- Add deprecation warning in webhook handler when max labels are used
- Update documentation to indicate open-swe-max labels are deprecated
- Recommend users switch to standard open-swe labels with Opus 4.5
- Update README, best-practices.mdx, github.mdx, and prompts.ts
- Max labels still functional but now log deprecation warnings