Commit graph

1206 commits

Author SHA1 Message Date
dependabot[bot]
7cfc987cd6
chore(deps): bump pyasn1 from 0.6.3 to 0.6.4
Bumps [pyasn1](https://github.com/pyasn1/pyasn1) from 0.6.3 to 0.6.4.
- [Release notes](https://github.com/pyasn1/pyasn1/releases)
- [Changelog](https://github.com/pyasn1/pyasn1/blob/main/CHANGES.rst)
- [Commits](https://github.com/pyasn1/pyasn1/compare/v0.6.3...v0.6.4)

---
updated-dependencies:
- dependency-name: pyasn1
  dependency-version: 0.6.4
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-08-01 13:48:57 +00:00
Adam Moussa
7a1da5d0af
Merge pull request #247 from Sea-Haven-Industries/fix/issue-240-dashboard-verdict
Some checks are pending
CI / Lint (push) Waiting to run
CI / Format check (push) Waiting to run
CI / Typecheck (push) Waiting to run
CI / Unit tests (push) Waiting to run
CI / Playwright E2E (push) Waiting to run
CI / Docker build smoke (push) Waiting to run
CI / Triage ledger up to date (push) Waiting to run
CI / ui bun.lock in sync (push) Waiting to run
fix(dashboard): authorize review verdicts from UI trigger
2026-07-31 19:45:37 -04:00
056688e822
fix(dashboard): authorize review verdicts 2026-07-31 12:34:56 -04:00
Adam Moussa
674f9ccc4e
Merge pull request #238 from Sea-Haven-Industries/dependabot/uv/minor-and-patch-a12baf45a1
Some checks are pending
CI / Lint (push) Waiting to run
CI / Format check (push) Waiting to run
CI / Typecheck (push) Waiting to run
CI / Unit tests (push) Waiting to run
CI / Playwright E2E (push) Waiting to run
CI / Docker build smoke (push) Waiting to run
CI / Triage ledger up to date (push) Waiting to run
CI / ui bun.lock in sync (push) Waiting to run
chore(deps): bump the minor-and-patch group across 1 directory with 10 updates
2026-07-31 10:21:25 -04:00
ba3f33d91f
chore: exclude markdown files from ruff format 2026-07-31 10:18:09 -04:00
Adam Moussa
02d2740bfd
Merge branch 'dev' into dependabot/uv/minor-and-patch-a12baf45a1 2026-07-31 10:09:30 -04:00
Adam Moussa
6d68634574
Merge pull request #236 from Sea-Haven-Industries/dependabot/npm_and_yarn/ui/jsdom-30.0.1
chore(deps-dev): bump jsdom from 29.1.1 to 30.0.0 in /ui
2026-07-31 09:44:09 -04:00
3eb2ae09c5
chore: regenerate bun.lock with updated dependencies 2026-07-31 09:33:43 -04:00
dependabot[bot]
9f201b6695
chore(deps-dev): bump jsdom from 29.1.1 to 30.0.0 in /ui
Bumps [jsdom](https://github.com/jsdom/jsdom) from 29.1.1 to 30.0.0.
- [Release notes](https://github.com/jsdom/jsdom/releases)
- [Commits](https://github.com/jsdom/jsdom/compare/v29.1.1...v30.0.0)

---
updated-dependencies:
- dependency-name: jsdom
  dependency-version: 30.0.1
  dependency-type: direct:development
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-07-31 09:33:43 -04:00
aeb95a447a
chore: regenerate bun.lock with updated dependencies 2026-07-31 09:31:26 -04:00
dependabot[bot]
e80f3b1f81
chore(deps): bump the minor-and-patch group across 1 directory with 10 updates
Bumps the minor-and-patch group with 10 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [fastapi](https://github.com/fastapi/fastapi) | `0.139.2` | `0.140.7` |
| [langchain-anthropic](https://github.com/langchain-ai/langchain) | `1.5.0` | `1.5.2` |
| [langchain-openai](https://github.com/langchain-ai/langchain) | `1.4.0` | `1.4.1` |
| [langchain-fireworks](https://github.com/langchain-ai/langchain) | `1.5.0` | `1.5.2` |
| [fireworks-ai](https://github.com/fw-ai-external/python-sdk) | `1.2.3` | `1.2.4` |
| [langchain-e2b](https://github.com/e2b-dev/langchain-e2b) | `0.0.5` | `0.0.6` |
| exa-py | `2.16.0` | `2.16.2` |
| [langchain-google-genai](https://github.com/langchain-ai/langchain-google) | `4.3.1` | `4.3.2` |
| [langchain-mcp-adapters](https://github.com/langchain-ai/langchain-mcp-adapters) | `0.3.0` | `0.3.1` |
| [ruff](https://github.com/astral-sh/ruff) | `0.15.22` | `0.16.0` |



Updates `fastapi` from 0.139.2 to 0.140.7
- [Release notes](https://github.com/fastapi/fastapi/releases)
- [Commits](https://github.com/fastapi/fastapi/compare/0.139.2...0.140.7)

Updates `langchain-anthropic` from 1.5.0 to 1.5.2
- [Release notes](https://github.com/langchain-ai/langchain/releases)
- [Commits](https://github.com/langchain-ai/langchain/compare/langchain-anthropic==1.5.0...langchain-anthropic==1.5.2)

Updates `langchain-openai` from 1.4.0 to 1.4.1
- [Release notes](https://github.com/langchain-ai/langchain/releases)
- [Commits](https://github.com/langchain-ai/langchain/compare/langchain-openai==1.4.0...langchain-openai==1.4.1)

Updates `langchain-fireworks` from 1.5.0 to 1.5.2
- [Release notes](https://github.com/langchain-ai/langchain/releases)
- [Commits](https://github.com/langchain-ai/langchain/compare/langchain-fireworks==1.5.0...langchain-fireworks==1.5.2)

Updates `fireworks-ai` from 1.2.3 to 1.2.4
- [Release notes](https://github.com/fw-ai-external/python-sdk/releases)
- [Changelog](https://github.com/fw-ai-external/python-sdk/blob/main/CHANGELOG.md)
- [Commits](https://github.com/fw-ai-external/python-sdk/compare/v1.2.3...v1.2.4)

Updates `langchain-e2b` from 0.0.5 to 0.0.6
- [Release notes](https://github.com/e2b-dev/langchain-e2b/releases)
- [Changelog](https://github.com/e2b-dev/langchain-e2b/blob/main/CHANGELOG.md)
- [Commits](https://github.com/e2b-dev/langchain-e2b/compare/v0.0.5...v0.0.6)

Updates `exa-py` from 2.16.0 to 2.16.2

Updates `langchain-google-genai` from 4.3.1 to 4.3.2
- [Release notes](https://github.com/langchain-ai/langchain-google/releases)
- [Commits](https://github.com/langchain-ai/langchain-google/compare/libs/genai/v4.3.1...libs/genai/v4.3.2)

Updates `langchain-mcp-adapters` from 0.3.0 to 0.3.1
- [Release notes](https://github.com/langchain-ai/langchain-mcp-adapters/releases)
- [Commits](https://github.com/langchain-ai/langchain-mcp-adapters/compare/langchain-mcp-adapters==0.3.0...langchain-mcp-adapters==0.3.1)

Updates `ruff` from 0.15.22 to 0.16.0
- [Release notes](https://github.com/astral-sh/ruff/releases)
- [Changelog](https://github.com/astral-sh/ruff/blob/main/CHANGELOG.md)
- [Commits](https://github.com/astral-sh/ruff/compare/0.15.22...0.16.0)

---
updated-dependencies:
- dependency-name: fastapi
  dependency-version: 0.140.7
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: langchain-anthropic
  dependency-version: 1.5.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: langchain-openai
  dependency-version: 1.4.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: langchain-fireworks
  dependency-version: 1.5.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: fireworks-ai
  dependency-version: 1.2.4
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: langchain-e2b
  dependency-version: 0.0.6
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: exa-py
  dependency-version: 2.16.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: langchain-google-genai
  dependency-version: 4.3.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: langchain-mcp-adapters
  dependency-version: 0.3.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: ruff
  dependency-version: 0.16.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-07-30 19:05:36 +00:00
dependabot[bot]
4b676022e7
chore(deps-dev): bump jsdom from 29.1.1 to 30.0.0 in /ui
Bumps [jsdom](https://github.com/jsdom/jsdom) from 29.1.1 to 30.0.0.
- [Release notes](https://github.com/jsdom/jsdom/releases)
- [Commits](https://github.com/jsdom/jsdom/compare/v29.1.1...v30.0.0)

---
updated-dependencies:
- dependency-name: jsdom
  dependency-version: 30.0.1
  dependency-type: direct:development
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-07-30 18:50:11 +00:00
Adam Moussa
2655bf95fc
Merge pull request #235 from Sea-Haven-Industries/dependabot/npm_and_yarn/ui/pierre/trees-1.0.0-beta.6
Some checks are pending
CI / Lint (push) Waiting to run
CI / Format check (push) Waiting to run
CI / Typecheck (push) Waiting to run
CI / Unit tests (push) Waiting to run
CI / Playwright E2E (push) Waiting to run
CI / Docker build smoke (push) Waiting to run
CI / Triage ledger up to date (push) Waiting to run
CI / ui bun.lock in sync (push) Waiting to run
chore(deps): bump @pierre/trees from 1.0.0-beta.5 to 1.0.0-beta.6 in /ui
2026-07-30 14:46:17 -04:00
8aeed0a72d
fix: regenerate bun.lock with updated dependencies 2026-07-30 14:41:30 -04:00
dependabot[bot]
0d518a1399
chore(deps): bump @pierre/trees from 1.0.0-beta.5 to 1.0.0-beta.6 in /ui
Bumps @pierre/trees from 1.0.0-beta.5 to 1.0.0-beta.6.

---
updated-dependencies:
- dependency-name: "@pierre/trees"
  dependency-version: 1.0.0-beta.6
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-07-30 18:37:04 +00:00
Adam Moussa
5cfc1ed64f
Merge pull request #233 from Sea-Haven-Industries/dependabot/npm_and_yarn/tests/e2e/minor-and-patch-edf4b8f5b6
chore(deps-dev): bump @playwright/test from 1.61.1 to 1.62.1 in /tests/e2e in the minor-and-patch group across 1 directory
2026-07-30 14:32:46 -04:00
dependabot[bot]
aeec4f09dc
chore(deps-dev): bump @playwright/test
Bumps the minor-and-patch group with 1 update in the /tests/e2e directory: [@playwright/test](https://github.com/microsoft/playwright).


Updates `@playwright/test` from 1.61.1 to 1.62.1
- [Release notes](https://github.com/microsoft/playwright/releases)
- [Commits](https://github.com/microsoft/playwright/compare/v1.61.1...v1.62.1)

---
updated-dependencies:
- dependency-name: "@playwright/test"
  dependency-version: 1.62.1
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-07-30 18:10:02 +00:00
Adam Moussa
1b3f735cc4
Merge pull request #232 from Sea-Haven-Industries/dependabot/github_actions/minor-and-patch-224896af34
chore(deps): bump the minor-and-patch group with 2 updates
2026-07-30 14:08:40 -04:00
dependabot[bot]
06a607e13c
chore(deps): bump the minor-and-patch group with 2 updates
Bumps the minor-and-patch group with 2 updates: [Sea-Haven-Industries/.github/.github/workflows/callable-dependency-review.yaml](https://github.com/sea-haven-industries/.github) and [Sea-Haven-Industries/.github/.github/workflows/callable-labeler.yaml](https://github.com/sea-haven-industries/.github).


Updates `Sea-Haven-Industries/.github/.github/workflows/callable-dependency-review.yaml` from 1.0.2 to 1.0.3
- [Release notes](https://github.com/sea-haven-industries/.github/releases)
- [Commits](0170a57c0d...3f74677422)

Updates `Sea-Haven-Industries/.github/.github/workflows/callable-labeler.yaml` from 1.0.2 to 1.0.3
- [Release notes](https://github.com/sea-haven-industries/.github/releases)
- [Commits](0170a57c0d...3f74677422)

---
updated-dependencies:
- dependency-name: Sea-Haven-Industries/.github/.github/workflows/callable-dependency-review.yaml
  dependency-version: 1.0.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: Sea-Haven-Industries/.github/.github/workflows/callable-labeler.yaml
  dependency-version: 1.0.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-07-30 16:44:29 +00:00
Adam Moussa
ef7b666340
Merge pull request #231 from Sea-Haven-Industries/ci/weekly-upstream-sync
Some checks failed
CI / Lint (push) Has been cancelled
CI / Format check (push) Has been cancelled
CI / Typecheck (push) Has been cancelled
CI / Unit tests (push) Has been cancelled
CI / Playwright E2E (push) Has been cancelled
CI / Docker build smoke (push) Has been cancelled
CI / Triage ledger up to date (push) Has been cancelled
CI / ui bun.lock in sync (push) Has been cancelled
ci: run ledger sync weekly on Mondays instead of daily
2026-07-29 11:58:30 -04:00
d6bc90f625
ci(upstream-sync): run ledger sync weekly on Mondays instead of daily 2026-07-29 11:51:25 -04:00
Adam Moussa
c18b676d6b
Merge pull request #230 from Sea-Haven-Industries/fix/audit-dep-review
Some checks are pending
CI / Lint (push) Waiting to run
CI / Format check (push) Waiting to run
CI / Typecheck (push) Waiting to run
CI / Unit tests (push) Waiting to run
CI / Playwright E2E (push) Waiting to run
CI / Docker build smoke (push) Waiting to run
CI / Triage ledger up to date (push) Waiting to run
CI / ui bun.lock in sync (push) Waiting to run
ci: replace bespoke dependency-review with the org callable
2026-07-28 18:40:49 -04:00
Adam Moussa
6efa00b67d ci: replace bespoke dependency-review with the org callable 2026-07-28 18:37:34 -04:00
Adam Moussa
9af427f014
Merge pull request #229 from Sea-Haven-Industries/ci/pin-reusables-v1.0.2
ci(deps): pin org reusable workflows to v1.0.2
2026-07-28 18:11:48 -04:00
Adam Moussa
0267159c49 style(ci): normalize workflow block spacing 2026-07-28 18:07:05 -04:00
Adam Moussa
d82f5257af ci(deps): pin org reusable workflows to v1.0.2 2026-07-28 17:57:08 -04:00
Adam Moussa
42e8af84ed
ci: pin reusable-workflow refs to commit SHA (#228)
Some checks failed
CI / Lint (push) Has been cancelled
CI / Format check (push) Has been cancelled
CI / Typecheck (push) Has been cancelled
CI / Unit tests (push) Has been cancelled
CI / Playwright E2E (push) Has been cancelled
CI / Docker build smoke (push) Has been cancelled
CI / Triage ledger up to date (push) Has been cancelled
CI / ui bun.lock in sync (push) Has been cancelled
Pins the labeler caller to the current .github main tip per the SHA-pin
convention (engineering-handbook PR #18). Dependabot github-actions
updates advance the pin weekly.
2026-07-27 15:45:07 -04:00
Adam Moussa
d48cb12e08
feat(open-swe): port upstream clean batch (#1788, #1786, #1764, #1782, #1791, #1799) + guard hardening (#226)
Some checks failed
CI / Lint (push) Has been cancelled
CI / Format check (push) Has been cancelled
CI / Typecheck (push) Has been cancelled
CI / Unit tests (push) Has been cancelled
CI / Playwright E2E (push) Has been cancelled
CI / Docker build smoke (push) Has been cancelled
CI / Triage ledger up to date (push) Has been cancelled
CI / ui bun.lock in sync (push) Has been cancelled
* Fix: Fix Insecure Direct Object Reference in slack_start_new_thread.py (#1788)

Co-authored-by: corridor-security[bot] <203152403+corridor-security[bot]@users.noreply.github.com>
(cherry picked from commit 32e81f2979a7baf11fe387df59f7d13a31889c74)

* Fix PR creation guard shell bypasses (#1786)

Co-authored-by: langsmith-fleet[bot] <langsmith-fleet[bot]@users.noreply.github.com>
(cherry picked from commit 75fb8b487852003916c4984504a13ee7226b2ceb)

* fix: add exc_info to swallowed exception in push re-review webhook (#1764)

(cherry picked from commit ab85b372b4f37b7feb849054553daed10852a42c)

* chore: clarify shared response image guidance (#1782)

Co-authored-by: Ramon Nogueira <270434257+ramon-langchain@users.noreply.github.com>
Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>
(cherry picked from commit 2e8ff4b72f1148bb36c0c1181063a3abd78b15d0)

* fix: match embedded review description background (#1791)

Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>
(cherry picked from commit 4ea2441ada1229bc414b02950d821786be2f7301)

* fix: show current shared thread in sidebar (#1799)

* fix: show current shared thread in sidebar

Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>

* fix: preserve resolved active sidebar threads

Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>

---------

Co-authored-by: Ramon Nogueira <270434257+ramon-langchain@users.noreply.github.com>
Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>
Co-authored-by: Johannes du Plessis <51395795+johannes117@users.noreply.github.com>
(cherry picked from commit a77c4e475643b4a55bb2f0c93c0aa2669014fbac)

* chore: switch deferred items to landed in upstream-sync triage documentation and jsonl entries (fork PR #226).

Signed-off-by: Adam Moussa <adam@seahavenind.com>

* harden PR guards + sidebar after security review

- Mirror upstream #1786's nested-shell / executable-normalization hardening
  into the fork-only pr_verdict_guard.py (verdict-gating is a real fork
  control), keeping it in parity with pr_creation_guard.py.
- Close the glued short-flag bypass (bash -c'...') in BOTH guards: a shell's
  -c argument can be concatenated into the same argv token, which the
  space-separated -c detection missed. Diverges pr_creation_guard.py from
  upstream #1786 by design; to be upstreamed.
- Gate the new #1799 sidebar active-thread refresh on ownership so a non-owner
  viewing a shared thread reads last-known state without persisting a metadata
  write (mirrors the is_owner gate on the single-thread read path).
- Fix an F821 in the #1799 cherry-pick (Mapping import / concrete dict type).

Guards remain intentionally fail-open per the honest-agent threat model;
docstrings narrowed to name the residual exotic-shell / stdin-fed vectors.

---------

Signed-off-by: Adam Moussa <adam@seahavenind.com>
Co-authored-by: corridor-security[bot] <203152403+corridor-security[bot]@users.noreply.github.com>
Co-authored-by: John Kennedy <65985482+jkennedyvz@users.noreply.github.com>
Co-authored-by: langsmith-fleet[bot] <langsmith-fleet[bot]@users.noreply.github.com>
Co-authored-by: Suraj Bayas <surajyou24@gmail.com>
Co-authored-by: Ramon Nogueira <ramon.nogueira@langchain.dev>
Co-authored-by: Ramon Nogueira <270434257+ramon-langchain@users.noreply.github.com>
Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>
Co-authored-by: Johannes du Plessis <johannes@langchain.dev>
Co-authored-by: Johannes du Plessis <51395795+johannes117@users.noreply.github.com>
2026-07-24 18:49:53 -04:00
seahaven-promotion[bot]
ac773482a2
chore: sync upstream triage ledger (#225)
Some checks are pending
CI / Lint (push) Waiting to run
CI / Format check (push) Waiting to run
CI / Typecheck (push) Waiting to run
CI / Unit tests (push) Waiting to run
CI / Playwright E2E (push) Waiting to run
CI / Docker build smoke (push) Waiting to run
CI / Triage ledger up to date (push) Waiting to run
CI / ui bun.lock in sync (push) Waiting to run
* chore: sync upstream triage ledger

* chore: triage 2026-07-24 ledger sync (#1799/#1780/#1804/#1801 deferred)

---------

Co-authored-by: amoussa1229 <166072409+amoussa1229@users.noreply.github.com>
Co-authored-by: Adam Moussa <adam@seahavenind.com>
2026-07-24 15:31:41 -04:00
dependabot[bot]
3c7e8ddf28
chore(deps-dev): bump web-vitals from 5.3.0 to 6.0.0 in /ui (#224)
Some checks are pending
CI / Lint (push) Waiting to run
CI / Format check (push) Waiting to run
CI / Typecheck (push) Waiting to run
CI / Unit tests (push) Waiting to run
CI / Playwright E2E (push) Waiting to run
CI / Docker build smoke (push) Waiting to run
CI / Triage ledger up to date (push) Waiting to run
CI / ui bun.lock in sync (push) Waiting to run
* chore(deps-dev): bump web-vitals from 5.3.0 to 6.0.0 in /ui

Bumps [web-vitals](https://github.com/GoogleChrome/web-vitals) from 5.3.0 to 6.0.0.
- [Changelog](https://github.com/GoogleChrome/web-vitals/blob/main/CHANGELOG.md)
- [Commits](https://github.com/GoogleChrome/web-vitals/compare/v5.3.0...v6.0.0)

---
updated-dependencies:
- dependency-name: web-vitals
  dependency-version: 6.0.0
  dependency-type: direct:development
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>

* fix: regenerate bun.lock with updated dependencies

Signed-off-by: Adam Moussa <adam@seahavenind.com>

---------

Signed-off-by: dependabot[bot] <support@github.com>
Signed-off-by: Adam Moussa <adam@seahavenind.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Adam Moussa <adam@seahavenind.com>
2026-07-23 15:12:56 -04:00
dependabot[bot]
6f5b3f6119
chore(deps): bump the minor-and-patch group across 1 directory with 8 updates (#223)
Bumps the minor-and-patch group with 8 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [langchain-anthropic](https://github.com/langchain-ai/langchain) | `1.4.8` | `1.5.0` |
| [langchain-aws](https://github.com/langchain-ai/langchain-aws) | `1.6.2` | `1.6.3` |
| [langsmith](https://github.com/langchain-ai/langsmith-sdk) | `0.10.5` | `0.10.10` |
| [langchain-openai](https://github.com/langchain-ai/langchain) | `1.3.5` | `1.4.0` |
| [langchain-fireworks](https://github.com/langchain-ai/langchain) | `1.4.4` | `1.5.0` |
| [fireworks-ai](https://github.com/fw-ai-external/python-sdk) | `1.2.0` | `1.2.3` |
| [langchain-e2b](https://github.com/e2b-dev/langchain-e2b) | `0.0.4` | `0.0.5` |
| [langchain-google-genai](https://github.com/langchain-ai/langchain-google) | `4.2.7` | `4.3.1` |



Updates `langchain-anthropic` from 1.4.8 to 1.5.0
- [Release notes](https://github.com/langchain-ai/langchain/releases)
- [Commits](https://github.com/langchain-ai/langchain/compare/langchain-anthropic==1.4.8...langchain-anthropic==1.5.0)

Updates `langchain-aws` from 1.6.2 to 1.6.3
- [Release notes](https://github.com/langchain-ai/langchain-aws/releases)
- [Commits](https://github.com/langchain-ai/langchain-aws/compare/langchain-aws==1.6.2...langchain-aws==1.6.3)

Updates `langsmith` from 0.10.5 to 0.10.10
- [Release notes](https://github.com/langchain-ai/langsmith-sdk/releases)
- [Commits](https://github.com/langchain-ai/langsmith-sdk/compare/v0.10.5...v0.10.10)

Updates `langchain-openai` from 1.3.5 to 1.4.0
- [Release notes](https://github.com/langchain-ai/langchain/releases)
- [Commits](https://github.com/langchain-ai/langchain/compare/langchain-openai==1.3.5...langchain-openai==1.4.0)

Updates `langchain-fireworks` from 1.4.4 to 1.5.0
- [Release notes](https://github.com/langchain-ai/langchain/releases)
- [Commits](https://github.com/langchain-ai/langchain/compare/langchain-fireworks==1.4.4...langchain-fireworks==1.5.0)

Updates `fireworks-ai` from 1.2.0 to 1.2.3
- [Release notes](https://github.com/fw-ai-external/python-sdk/releases)
- [Changelog](https://github.com/fw-ai-external/python-sdk/blob/main/CHANGELOG.md)
- [Commits](https://github.com/fw-ai-external/python-sdk/compare/v1.2.0...v1.2.3)

Updates `langchain-e2b` from 0.0.4 to 0.0.5
- [Release notes](https://github.com/e2b-dev/langchain-e2b/releases)
- [Changelog](https://github.com/e2b-dev/langchain-e2b/blob/main/CHANGELOG.md)
- [Commits](https://github.com/e2b-dev/langchain-e2b/compare/v0.0.4...v0.0.5)

Updates `langchain-google-genai` from 4.2.7 to 4.3.1
- [Release notes](https://github.com/langchain-ai/langchain-google/releases)
- [Commits](https://github.com/langchain-ai/langchain-google/compare/libs/genai/v4.2.7...libs/genai/v4.3.1)

---
updated-dependencies:
- dependency-name: fireworks-ai
  dependency-version: 1.2.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: langchain-anthropic
  dependency-version: 1.5.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: langchain-aws
  dependency-version: 1.6.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: langchain-e2b
  dependency-version: 0.0.5
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: langchain-fireworks
  dependency-version: 1.5.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: langchain-google-genai
  dependency-version: 4.3.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: langchain-openai
  dependency-version: 1.4.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: langsmith
  dependency-version: 0.10.10
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-23 18:34:14 +00:00
dependabot[bot]
2e42cef213
chore(deps): bump monaco-editor from 0.55.1 to 0.56.0 in /ui in the minor-and-patch group across 1 directory (#222)
Some checks are pending
CI / Lint (push) Waiting to run
CI / Format check (push) Waiting to run
CI / Typecheck (push) Waiting to run
CI / Unit tests (push) Waiting to run
CI / Playwright E2E (push) Waiting to run
CI / Docker build smoke (push) Waiting to run
CI / Triage ledger up to date (push) Waiting to run
CI / ui bun.lock in sync (push) Waiting to run
* chore(deps): bump monaco-editor

Bumps the minor-and-patch group with 1 update in the /ui directory: [monaco-editor](https://github.com/microsoft/monaco-editor).


Updates `monaco-editor` from 0.55.1 to 0.56.0
- [Release notes](https://github.com/microsoft/monaco-editor/releases)
- [Changelog](https://github.com/microsoft/monaco-editor/blob/main/CHANGELOG.md)
- [Commits](https://github.com/microsoft/monaco-editor/compare/v0.55.1...v0.56.0)

---
updated-dependencies:
- dependency-name: monaco-editor
  dependency-version: 0.56.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
...

Signed-off-by: dependabot[bot] <support@github.com>

* fix: regenerate bun.lock with updated dependencies

Signed-off-by: Adam Moussa <adam@seahavenind.com>

---------

Signed-off-by: dependabot[bot] <support@github.com>
Signed-off-by: Adam Moussa <adam@seahavenind.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Adam Moussa <166072409+amoussa1229@users.noreply.github.com>
Co-authored-by: Adam Moussa <adam@seahavenind.com>
2026-07-23 18:22:24 +00:00
dependabot[bot]
ac31618f85
chore(deps): bump astral-sh/setup-uv from 8.3.2 to 9.0.0 (#221)
Bumps [astral-sh/setup-uv](https://github.com/astral-sh/setup-uv) from 8.3.2 to 9.0.0.
- [Release notes](https://github.com/astral-sh/setup-uv/releases)
- [Commits](11f9893b08...c771a70e62)

---
updated-dependencies:
- dependency-name: astral-sh/setup-uv
  dependency-version: 9.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-23 14:06:40 -04:00
dependabot[bot]
5ce2d3f632
chore(deps): bump actions/setup-python from 6 to 7 (#220)
Some checks are pending
CI / Lint (push) Waiting to run
CI / Format check (push) Waiting to run
CI / Typecheck (push) Waiting to run
CI / Unit tests (push) Waiting to run
CI / Playwright E2E (push) Waiting to run
CI / Docker build smoke (push) Waiting to run
CI / Triage ledger up to date (push) Waiting to run
CI / ui bun.lock in sync (push) Waiting to run
Bumps [actions/setup-python](https://github.com/actions/setup-python) from 6 to 7.
- [Release notes](https://github.com/actions/setup-python/releases)
- [Commits](https://github.com/actions/setup-python/compare/v6...v7)

---
updated-dependencies:
- dependency-name: actions/setup-python
  dependency-version: '7'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-23 17:11:15 +00:00
seahaven-promotion[bot]
33667778ee
chore: sync upstream triage ledger (#219)
* chore: sync upstream triage ledger

* docs: triage upstream rows #1796, #1797, #1800; flip #1774 to wont-merge

#1796 deferred pending the deepagents 0.7.x bump (#1745); #1797/#1800
wont-merge (repo-skills feature reverted upstream); #1774 flipped from
deferred to wont-merge since upstream withdrew the feature in #1800.

---------

Co-authored-by: amoussa1229 <166072409+amoussa1229@users.noreply.github.com>
Co-authored-by: Adam Moussa <adam@seahavenind.com>
2026-07-23 16:59:36 +00:00
Adam Moussa
c99bd78179
feat: clean-review auto-approve for unsolicited verdicts [BLOCKED — security] (#217)
Some checks failed
CI / Lint (push) Has been cancelled
CI / Format check (push) Has been cancelled
CI / Typecheck (push) Has been cancelled
CI / Unit tests (push) Has been cancelled
CI / Playwright E2E (push) Has been cancelled
CI / Docker build smoke (push) Has been cancelled
CI / Triage ledger up to date (push) Has been cancelled
CI / ui bun.lock in sync (push) Has been cancelled
* feat(reviewer): clean-review auto-approve for unsolicited publish_review verdicts

An unsolicited publish_review(verdict="approve") — a run dispatched
without verdict_requested — is now honored when the review has zero open
findings, so clean auto-reviews land a real APPROVE. With open findings
it downgrades to a comment review (verdict_ignored_reason=
"approve_with_open_findings"). request_changes stays explicit-request-
only; the self-review, head-moved, and author-unknown downgrades and the
shell verdict guard are unchanged. The reviewer base prompt now instructs
the clean-approve call on auto-reviews.

* chore(security): record accepted-risk suppressions for clean-review auto-approve

Two confirmed-HIGH findings from /sh-security-review on the clean-review
auto-approve change are accepted and deferred (Adam, 2026-07-21), tracked
in #218. Machine-recorded per the mandatory-security-review policy; the
revisit trigger is promotion from dev to main/prod.
2026-07-21 20:18:25 -04:00
seahaven-promotion[bot]
ac569b9a0a
chore: sync upstream triage ledger (#216)
Some checks are pending
CI / Lint (push) Waiting to run
CI / Format check (push) Waiting to run
CI / Typecheck (push) Waiting to run
CI / Unit tests (push) Waiting to run
CI / Playwright E2E (push) Waiting to run
CI / Docker build smoke (push) Waiting to run
CI / Triage ledger up to date (push) Waiting to run
CI / ui bun.lock in sync (push) Waiting to run
* chore: sync upstream triage ledger

* chore: triage new commits and regenerate ledger (3 wont-merge, 10 deferred)

Signed-off-by: Adam Moussa <adam@seahavenind.com>

---------

Signed-off-by: Adam Moussa <adam@seahavenind.com>
Co-authored-by: amoussa1229 <166072409+amoussa1229@users.noreply.github.com>
Co-authored-by: Adam Moussa <adam@seahavenind.com>
2026-07-21 18:08:06 +00:00
Adam Moussa
db05d5826f
feat(open-swe): port upstream clean batch (#1775, #1785, #1789) (#215)
Some checks are pending
CI / Lint (push) Waiting to run
CI / Format check (push) Waiting to run
CI / Typecheck (push) Waiting to run
CI / Unit tests (push) Waiting to run
CI / Playwright E2E (push) Waiting to run
CI / Docker build smoke (push) Waiting to run
CI / Triage ledger up to date (push) Waiting to run
CI / ui bun.lock in sync (push) Waiting to run
* Fix: Fix Improper privilege management in server.py (#1789)

Co-authored-by: corridor-security[bot] <203152403+corridor-security[bot]@users.noreply.github.com>
(cherry picked from commit 3ea29d3f231dd66bd7627769b5659564be4525df)

* Fix: Fix Stored XSS in ReplyCard.tsx (#1785)

Co-authored-by: corridor-security[bot] <203152403+corridor-security[bot]@users.noreply.github.com>
(cherry picked from commit 31263f832a2ecedf669eee2e27b827a358a6a4d7)

* feat: add structured Linear issue filters (#1775)

Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>
(cherry picked from commit b5e529252c3012818289eca1b1cdeb8014721310)

* chore(triage): mark #1775 #1785 #1789 landed

Move the three clean cherry-picks in this batch from deferred to landed
in the upstream-sync ledger and re-render triage.md.

---------

Co-authored-by: corridor-security[bot] <203152403+corridor-security[bot]@users.noreply.github.com>
Co-authored-by: Johannes du Plessis <johannes@langchain.dev>
Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>
2026-07-20 19:54:16 +00:00
Adam Moussa
0f0f616cd4
feat(open-swe): explicit-request reviewer verdicts + shell verdict guard (#214)
Some checks failed
CI / Lint (push) Has been cancelled
CI / Format check (push) Has been cancelled
CI / Typecheck (push) Has been cancelled
CI / Unit tests (push) Has been cancelled
CI / Playwright E2E (push) Has been cancelled
CI / Docker build smoke (push) Has been cancelled
CI / Triage ledger up to date (push) Has been cancelled
CI / ui bun.lock in sync (push) Has been cancelled
* feat(reviewer): explicit-request verdicts + shell verdict guard

Mention-triggered reviews that explicitly ask for a verdict now submit a
real APPROVE/REQUEST_CHANGES through publish_review; auto-reviews stay
advisory (COMMENT). Authorization is enforced in code: publish_review
honors a verdict only when the dispatching webhook set verdict_requested,
which only the explicit-mention path does.

- request_pr_review gains instructions (forwarded verbatim into an escaped
  requester_instructions data block) and request_verdict
- self-review guard downgrades verdicts on Open SWE-authored PRs; stale
  APPROVEs are best-effort dismissed when later findings land
- new PullRequestVerdictGuardMiddleware blocks gh pr review
  --approve/-a/--request-changes/-r, gh api, and curl verdict fallbacks on
  both the coding-agent and reviewer graphs
- shared escape helper moved to agent/utils/prompt_data.py

* fix(reviewer): harden verdict path against security-review findings

Adversarial security review (detector fan-out + proof-or-kill verifier)
of the verdict feature surfaced several verdict-integrity gaps; resolve
the confirmed ones:

- head-drift (high): a mid-run push moves the resolved head, so an APPROVE
  could anchor to an unreviewed commit. Downgrade any verdict to a comment
  when the resolved head differs from the reviewed head (verdict_ignored
  reason head_moved); the push's own re-review submits a fresh verdict.
- self-review fail-open: downgrade to comment when the PR author cannot be
  confirmed (author_unknown), and compare bot logins case-insensitively.
- verdict_submitted now reflects GitHub's returned review state, not just
  the event we asked for, so a coerced APPROVE isn't reported as submitted.
- an authorized verdict whose findings all anchor outside the diff now
  posts as a bodied review with zero inline comments instead of failing.
- add finding_reply to the shared data-block escape tag superset.
2026-07-20 15:28:00 -04:00
seahaven-promotion[bot]
29e1a6dff7
chore: sync upstream triage ledger (#213)
Some checks are pending
CI / Lint (push) Waiting to run
CI / Format check (push) Waiting to run
CI / Typecheck (push) Waiting to run
CI / Unit tests (push) Waiting to run
CI / Playwright E2E (push) Waiting to run
CI / Docker build smoke (push) Waiting to run
CI / Triage ledger up to date (push) Waiting to run
CI / ui bun.lock in sync (push) Waiting to run
* chore: sync upstream triage ledger

* chore(sync): triage 31263f83 and 3ea29d3f as deferred security ports

---------

Co-authored-by: amoussa1229 <166072409+amoussa1229@users.noreply.github.com>
Co-authored-by: Adam Moussa <adam@seahavenind.com>
2026-07-20 18:07:16 +00:00
seahaven-promotion[bot]
c2d8c487f1
chore: sync upstream triage ledger (#212)
Some checks failed
CI / Lint (push) Has been cancelled
CI / Format check (push) Has been cancelled
CI / Typecheck (push) Has been cancelled
CI / Unit tests (push) Has been cancelled
CI / Playwright E2E (push) Has been cancelled
CI / Docker build smoke (push) Has been cancelled
CI / Triage ledger up to date (push) Has been cancelled
CI / ui bun.lock in sync (push) Has been cancelled
2026-07-19 11:07:15 -04:00
seahaven-promotion[bot]
b6e74d37d6
chore: sync upstream triage ledger (#211)
Some checks failed
CI / Lint (push) Has been cancelled
CI / Format check (push) Has been cancelled
CI / Typecheck (push) Has been cancelled
CI / Unit tests (push) Has been cancelled
CI / Playwright E2E (push) Has been cancelled
CI / Docker build smoke (push) Has been cancelled
CI / Triage ledger up to date (push) Has been cancelled
CI / ui bun.lock in sync (push) Has been cancelled
* chore: sync upstream triage ledger

* docs: triage the 5 new upstream rows (1 wont-merge, 4 deferred)

#1773 wont-merge (removes workflow-push gating + token ladder the fork
keeps); #1775/#1765/#1776/#1778 deferred with reconcile notes.

---------

Co-authored-by: amoussa1229 <166072409+amoussa1229@users.noreply.github.com>
Co-authored-by: Adam Moussa <adam@seahavenind.com>
2026-07-17 18:38:51 -04:00
dependabot[bot]
774fba4df5
chore(deps): bump mcp from 1.27.2 to 1.28.1 (#210)
Bumps [mcp](https://github.com/modelcontextprotocol/python-sdk) from 1.27.2 to 1.28.1.
- [Release notes](https://github.com/modelcontextprotocol/python-sdk/releases)
- [Changelog](https://github.com/modelcontextprotocol/python-sdk/blob/main/RELEASE.md)
- [Commits](https://github.com/modelcontextprotocol/python-sdk/compare/v1.27.2...v1.28.1)

---
updated-dependencies:
- dependency-name: mcp
  dependency-version: 1.28.1
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-17 18:27:19 -04:00
Adam Moussa
f70e284408
Merge pull request #209 from Sea-Haven-Industries/chore/correct-ui-console-warning
chore: fail Vercel builds when VITE_DASHBOARD_API_BASE_URL is set
2026-07-17 18:20:18 -04:00
5b52e92d2d
fix: fail Vercel builds when VITE_DASHBOARD_API_BASE_URL is set
Signed-off-by: Adam Moussa <adam@seahavenind.com>
2026-07-17 18:06:09 -04:00
Adam Moussa
26f8fe91a9
Merge pull request #208 from Sea-Haven-Industries/chore/ledger-port-batch-landed
Some checks are pending
CI / Lint (push) Waiting to run
CI / Format check (push) Waiting to run
CI / Typecheck (push) Waiting to run
CI / Unit tests (push) Waiting to run
CI / Playwright E2E (push) Waiting to run
CI / Docker build smoke (push) Waiting to run
CI / Triage ledger up to date (push) Waiting to run
CI / ui bun.lock in sync (push) Waiting to run
docs: land the 8 ported upstream picks in the triage ledger
2026-07-17 17:47:12 -04:00
1e762637f4
docs: land the 8 post-reorg upstream picks in the triage ledger
Flip #1732, #1761, #1744, #1748, #1742, #1758, #1760, #1736 to landed
(fork PRs #206/#207) with their dev commit SHAs.
2026-07-17 17:31:54 -04:00
Adam Moussa
28916064d5
Merge pull request #207 from Sea-Haven-Industries/bug/bind-cached-github-tokens
feat: Bind cached GitHub tokens to users (upstream #1736)
2026-07-17 17:14:42 -04:00
d980209157
test: cover bot-token fallback when an unbound user token is refused
Cross-family review (GPT-4.1) FIX item on the #1736 port: prove the
warn-and-drop path for unprincipaled user tokens leaves the cached bot
token reachable.
2026-07-17 17:08:09 -04:00
8d8d5bbbbf
fix: bind cached GitHub tokens to users (#1736)
Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>
(cherry picked from commit 1ea0e600dcc234fa5a333c6f4b80b90e2e6679d3)

Co-authored-by: Johannes du Plessis <johannes@langchain.dev>
2026-07-17 17:08:09 -04:00