Commit graph

27 commits

Author SHA1 Message Date
Ramon Nogueira
a8c7af4192
test(open-swe): add Playwright E2E for the Slack → PR → web handoff (#1583)
* test(open-swe): add Playwright E2E for the Slack → PR → web handoff

Local, secrets-free end-to-end suite that drives the full happy path through mock Slack/GitHub control panels and the real dashboard UI. Only the LLM and external SaaS HTTP boundaries (GitHub/Slack APIs, OAuth token mint) are faked — the real process_slack_mention, get_agent, deepagents loop, tools, middleware, and dashboard authorization all run under `langgraph dev` with a scripted fake chat model and a local temp-dir sandbox.

- full_flow: a Slack mention runs the agent, which implements a change in the sandbox, opens a PR against a fake GitHub remote, and replies with the PR link in the same thread.
- dashboard: clicking the bot's real "Open in Web" link loads the built ui/ app (served same-origin); the thread owner can continue the conversation, while a different user sees the same thread read-only (no composer).

Wired into Agent CI as a `Playwright E2E` job that runs on pull requests.

* fix(open-swe): serve E2E UI assets via explicit route; pin Playwright

The dashboard E2E served the built ui/ SPA's /assets via app.mount(StaticFiles), but LangGraph's custom-app loader serves APIRoutes and drops sub-app Mounts, so /assets 404'd under `langgraph dev` in CI — the React app never booted and the composer/transcript never rendered. Serve assets via an explicit route instead.

Also pin @playwright/test to the latest (1.61.0) for reproducible runs, and make the owner composer assertion tolerant of either hydration state.

* test(open-swe): record Playwright trace + video on every E2E run

Capture a replayable trace (DOM snapshots, network, console, source) and a screen recording for every test, not just retries, plus a screenshot on failure. The CI job already uploads playwright-report/ and test-results/, so each run now has a downloadable replay; documented how to open it.
2026-06-22 12:54:46 -07:00
Johannes du Plessis
0927f2dd9c
feat: Run reviewer eval in a GitHub Action; dashboard becomes read-only (#1556)
* Run reviewer eval in a GitHub Action; make dashboard a read-only progress view

The dashboard launched the eval as a subprocess inside the serving deployment
worker, so a container recycle killed long runs and discarded results that had
already completed server-side. Move the harness to a workflow_dispatch Action
(run on prod). run_eval now publishes status/progress/log-tail to the LangGraph
store record the dashboard reads, so /admin/evals stays a live view; a killed
Action surfaces as failed via the stale-heartbeat reconcile.

* reviewer_eval workflow: pass inputs via env, no shell interpolation

Addresses the reviewer finding: workflow_dispatch string inputs were
interpolated into the run: block (limit unquoted), allowing shell injection in
a job holding LANGSMITH/ANTHROPIC keys. Pass inputs through env and reference
quoted "$VARS"; validate limit is numeric and build its flag in bash.

---------

Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>
2026-06-16 19:38:36 -07:00
Johannes du Plessis
ce8fe0b142
ci: nightly promote of main to prod for LangGraph deploys (#1285)
Adds a scheduled workflow that force-pushes main onto a prod branch at
08:00 UTC (midnight PST / 1am PDT). The LangGraph deployment will track
prod instead of main, so routine merges no longer trigger redeploys
that cancel in-flight 30-minute coding runs. workflow_dispatch is
retained for hotfixes that need to ship immediately.
2026-05-09 01:15:26 +00:00
dependabot[bot]
3d3d8403fe
chore(deps): bump astral-sh/setup-uv in the minor-and-patch group (#1232)
Bumps the minor-and-patch group with 1 update: [astral-sh/setup-uv](https://github.com/astral-sh/setup-uv).


Updates `astral-sh/setup-uv` from 8.0.0 to 8.1.0
- [Release notes](https://github.com/astral-sh/setup-uv/releases)
- [Commits](cec208311d...08807647e7)

---
updated-dependencies:
- dependency-name: astral-sh/setup-uv
  dependency-version: 8.1.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-05-01 18:00:53 -07:00
dependabot[bot]
4af9eb885c
chore(deps): bump python-dotenv from 1.2.1 to 1.2.2 (#1212)
* chore(deps): bump python-dotenv from 1.2.1 to 1.2.2

Bumps [python-dotenv](https://github.com/theskumar/python-dotenv) from 1.2.1 to 1.2.2.
- [Release notes](https://github.com/theskumar/python-dotenv/releases)
- [Changelog](https://github.com/theskumar/python-dotenv/blob/main/CHANGELOG.md)
- [Commits](https://github.com/theskumar/python-dotenv/compare/v1.2.1...v1.2.2)

---
updated-dependencies:
- dependency-name: python-dotenv
  dependency-version: 1.2.2
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>

* added deps to pr scopes

---------

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Johannes du Plessis <johannes@langchain.dev>
2026-05-01 22:27:21 +00:00
dependabot[bot]
d2042bfefd
chore(deps): bump astral-sh/setup-uv from 4.2.0 to 8.0.0 (#1196)
Bumps [astral-sh/setup-uv](https://github.com/astral-sh/setup-uv) from 4.2.0 to 8.0.0.
- [Release notes](https://github.com/astral-sh/setup-uv/releases)
- [Commits](38f3f10444...cec208311d)

---
updated-dependencies:
- dependency-name: astral-sh/setup-uv
  dependency-version: 8.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-04-15 23:45:46 -07:00
dependabot[bot]
8ae4179378
chore(deps): bump amannn/action-semantic-pull-request from 5 to 6 (#1197)
Bumps [amannn/action-semantic-pull-request](https://github.com/amannn/action-semantic-pull-request) from 5 to 6.
- [Release notes](https://github.com/amannn/action-semantic-pull-request/releases)
- [Changelog](https://github.com/amannn/action-semantic-pull-request/blob/main/CHANGELOG.md)
- [Commits](e32d7e603d...48f256284b)

---
updated-dependencies:
- dependency-name: amannn/action-semantic-pull-request
  dependency-version: '6'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-04-15 23:41:08 -07:00
dependabot[bot]
9219912068
chore(deps): bump actions/checkout from 4 to 6 (#1194)
Bumps [actions/checkout](https://github.com/actions/checkout) from 4 to 6.
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](https://github.com/actions/checkout/compare/v4...v6)

---
updated-dependencies:
- dependency-name: actions/checkout
  dependency-version: '6'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-04-15 23:37:03 -07:00
John Kennedy
a94fb8b94c
ci: SHA-pin third-party actions in workflow files (#1193)
Pin astral-sh/setup-uv and amannn/action-semantic-pull-request to
full commit SHAs to prevent supply chain attacks via tag hijacking.
2026-04-15 23:36:07 -07:00
John Kennedy
da11bcdf60
chore: add dependabot.yml with uv, docker, and github-actions coverage (#1192)
Adds a compliant dependabot configuration covering all detected
ecosystems with monthly schedule and grouped update-type splits.
2026-04-15 23:35:42 -07:00
Brace Sproul
bd52e5e09d
chore: Drop monorepo (#1029)
* chore: Drop monorepo

* cr
2026-03-06 16:10:34 -08:00
Brace Sproul
ad4452032f
fix: Security fixes for ci (#974) 2026-02-24 07:52:47 -08:00
Brace Sproul
4a851a05ea
ci: Add CI actions (#972)
* ci: Add CI actions

* cr

* cr

* cr
2026-02-23 19:11:41 -08:00
aran-yogesh
3bd7399862 fix: only run open-swe jobs when apps/open-swe exists 2026-02-13 14:56:20 -08:00
aran-yogesh
1083989723 env var changed to LANGSMITH_API_KEY_PROD isntead of LANGSMITH_API_KEY 2026-02-05 13:36:02 -08:00
Brace Sproul
700bbf20f5
chore: add proper jsonwebtoken deps (#659)
* deps: add proper jsonwebtoken deps

* cr
2025-08-04 13:31:59 -07:00
Brace Sproul
37d2a4eb05
fix: Auto sync docs workflow conditional, sync images too (#590) 2025-07-29 11:29:57 -07:00
Brace Sproul
1bb24ac7c8
ci: Fix deploy langgraph revision action (#585)
* ci: Fix deploy langgraph revision action

* cr

* cr

* cr
2025-07-29 09:51:00 -07:00
open-swe[bot]
8eb83c11e5
feat: Add LangGraph Deployment GitHub Action and TypeScript Deployment Script (#550)
* Apply patch

* Apply patch

* Apply patch

* Apply patch

* Apply patch

* Apply patch

* Apply patch

* Apply patch

* Apply patch

* Apply patch

* Apply patch

* move into workflows dir

* cr

---------

Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>
Co-authored-by: bracesproul <braceasproul@gmail.com>
2025-07-28 18:32:11 -07:00
Brace Sproul
0923c8b47e
fix: running tests and in ci (#536)
* fix: running tests and in ci

* cr

* cr

* cr

* exit 0 when no tests

* cr
2025-07-27 19:11:34 +00:00
Brace Sproul
1d7ddf22a5
ci: Add PR title lint workflow (#472) 2025-07-22 18:21:45 +00:00
Brace Sproul
13329fe5c1
fix: Actions testing (#432)
* fix: Actions testing

* cr

* cr
2025-07-16 12:09:16 -07:00
Brace Sproul
4a49eecd3c
feat: Auto doc sync (#428)
* feat: Auto doc sync

* fix: drop concepts page
2025-07-16 11:52:19 -07:00
Brace Sproul
56d9df7246
chore: Add CI job which runs the dev server (#61)
* chore: Add CI job which runs the dev server

* cr

* cr

* cr
2025-05-30 13:54:44 -07:00
Brace Sproul
2e4cf9ed63
chore: Add ci job to build project (#33) 2025-05-27 21:46:40 +00:00
Brace Sproul
c6d867e1a7
feat: Monorepo (#22)
* feat: Monorepo

* cr

* cr
2025-05-26 13:02:51 -07:00
bracesproul
e2415aee3f init commit 2025-05-21 14:47:56 -07:00