* fix: let usage table expand to fill available width
The usage page was constrained to max-w-3xl while the leaderboard table
needs a 760px minimum for its 7 columns, so it always overflowed and
forced horizontal scrolling. Add an optional maxWidthClassName prop to
AppShell and widen the usage page to max-w-5xl so the table expands when
space allows, keeping overflow-x-auto as a narrow-screen fallback.
Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>
* refactor: use cn-merged className override on AppShell
Replace the single-purpose maxWidthClassName prop with a general
className prop merged via cn (twMerge), matching the shadcn pattern. This
lets callers override any of the content-container classes ad hoc rather
than adding a new prop per override. Usage page passes className=max-w-5xl.
Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>
---------
Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>
Co-authored-by: Johannes du Plessis <johannes@langchain.dev>
* feat: out-of-process usage-snapshot builder (Phase 1)
Move all usage-tab compute off the run-serving HTTP process (the #1434 bug
class). Read path is now a pure cache read with a typed computing placeholder
on cold miss; a dedicated usage_snapshot graph + global ~10min cron rebuild
every period's snapshot out-of-process, wrapped in asyncio.timeout and gated by
USAGE_SNAPSHOT_CRON_ENABLED. Lifespan makes one fire-and-forget scheduling call,
never a retained/looping task.
* fix: address PR review on usage-snapshot builder
- admin guard on /admin/usage/rebuild (was any logged-in user)
- cap lifespan loopback calls with asyncio.timeout(5) so a startup hang
can't block boot
- memoize cron registration so steady-state requests skip the loopback
check; reap duplicate crons from concurrent-replica races
- thread the computing flag through the usage payload too
* feat: add Claude Fable 5 as a supported model
Add Anthropic's claude-fable-5 (Mythos-class, released June 9 2026) to
the supported model list so it can be selected in the profile editor.
Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>
* fix: order Fable 5 after Opus 4.8 so stale-Anthropic fallback is preserved
provider_fallback_pair picks the first same-provider model, so placing
Fable 5 first redirected stale Opus selections to it. Keep Opus 4.8 first.
Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>
---------
Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>
* fix: prevent thread prefetches from marking threads viewed
Sidebar prefetches now request thread details with mark_viewed=false so
loading /agents no longer clears the unread/finished indicator for
threads the user has not opened.
Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>
* fix: always refetch active thread on mount to mark viewed
Prefetches cache details fetched with mark_viewed=false under the same
query key as the active thread. Forcing refetchOnMount="always" ensures
opening a thread issues a mark_viewed=true request, so last_viewed_* is
recorded even when prefetched data is still fresh.
Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>
---------
Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>
Pull the api-standards skill from the LangSmith Context Hub at reviewer
run start and inject it into the system prompt, gated on the PR adding or
modifying an API surface. Best-effort: failures fall back to no supplement.
Co-authored-by: GowriH-1 <218394553+GowriH-1@users.noreply.github.com>
Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>
Add conversations.info fetch so a repo:owner/name (or GitHub URL) token
in a Slack channel's topic/purpose pins the channel to a repo, slotting
in just below thread metadata in get_slack_repo_config.
Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>
Pin LangSmith to the last version verified in repo history before the websocket sandbox upgrade so production runs stop wedging while we investigate the SDK regression.
Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>
* fix: enforce client-side deadline on sandbox execute
The langsmith SDK's default execute path is now a WebSocket stream with
no client-side read deadline. On a live socket where the dataplane never
emits an exit/error frame, CommandHandle.result blocks forever in an
uncancellable thread, wedging the run (introduced by the langsmith
0.8.3 -> 0.8.8 bump in #1385). The command `timeout` is only enforced
server-side, so it doesn't fire.
TimeoutLangSmithSandbox drives a non-blocking CommandHandle and kills the
command if it overruns its timeout by a grace window
(SANDBOX_EXECUTE_CLIENT_GRACE_SECONDS, default 30), returning a timed-out
tool result instead of hanging. WS connect failures fall back to the base
wait=True path, whose HTTP fallback carries its own request deadline.
* fix: fall back to HTTP when WS execute connect fails
run(wait=False) eagerly opens the WebSocket and reads the "started" frame,
so connect/setup failures (and connect timeouts) raise from the run() call
itself, not from handle.result. The previous structure left run() outside
the try, so those failures bypassed the HTTP fallback and would fail every
sandbox command in any environment where the WS path is unavailable.
Move handle creation inside the fallback handler in both execute and
aexecute, and run it via to_thread in the async path since it now blocks on
connect. Add tests for connect-failure and connect-timeout fallback.
---------
Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>
The Pierre diff view hardcoded the syntax-highlight theme to
pierre-light, but the diff background follows the app theme
(--ui-panel), so in dark mode light-theme token colors rendered on a
dark background with poor contrast. Provide both light/dark Pierre
themes and follow the document color-scheme via themeType "system".
Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>
* feat(reviewer): surface dashboard UI link on PR reviews [INF-0000]
Post a transient "review in progress" comment (with an "Open in Web"
dashboard link) when a reviewer run starts, then delete it once the
review lands. The published review body now carries the same
"Open in Web" link, so the link persists on the review itself.
The transient comment's id is tracked in reviewer thread metadata
(status_comment_id) so it can be deleted on completion.
* refactor(reviewer): inline dashboard URL helper, drop redundant future import [INF-0000]
* feat: add dark mode support to web UI
Add a persisted, system-aware theme with a Light/Dark/System toggle in
the sidebar user menu. An inline head script applies the stored theme
before paint to avoid a flash, and the agents-ui surface gets dark
overrides for its --ui-* variables.
Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>
* fix: use static theme init script to satisfy CodeQL
Build the no-FOUC theme script from a fully static string literal
instead of interpolating THEME_STORAGE_KEY, so no value flows into
code construction (CodeQL "Improper code sanitization").
Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>
* fix: avoid theme flip on hydration for persisted preferences
Only apply a theme after the stored preference is read, instead of
eagerly applying the default "system" theme on first effect. This
prevented a brief flip to the OS theme (then back) on load for users
with a saved preference that differs from their OS setting.
Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>
---------
Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>
Adds an admin-managed, org-wide review guidelines field to team settings
that the reviewer injects into every PR review across all repos, alongside
the existing per-repo style prompt and AGENTS.md context. Repo-specific
rules take precedence when they conflict.
Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>
* fix: stop reviewer retrying out-of-diff findings
add_finding rejects findings anchored outside the PR diff, but the agent
retried the same finding 2-3x with adjacent line ranges before giving up,
burning a model turn each. Add a reviewer-prompt recovery block telling the
agent the rejection is authoritative (drop or re-anchor to a + line, don't
retry adjacent), and enrich the rejection payload with nearby in-diff line
ranges for the file so a single re-anchor needs no guessing.
* feat: surface out-of-diff findings in a collapsed dropdown
Instead of rejecting findings anchored outside the PR diff, accept them
(marked in_diff=false) and surface them in a collapsed <details> section of
the review summary, Devin-style. Inline comments stay reserved for in-diff
findings; out-of-diff are severity-gated and capped the same way.
Re-review normally suppresses the empty summary, but now makes an exception
when there are new out-of-diff findings to surface. Surfaced out-of-diff
findings carry a github_review_id so they aren't reposted on later pushes.
Supersedes the earlier 'drop/re-anchor out-of-diff' prompt guidance.
---------
Co-authored-by: open-swe[bot] <215916821+open-swe[bot]@users.noreply.github.com>
GitHub returns repository: null when the token can't read the repo (SAML,
expired token, private/deleted). dict.get(k, {}) doesn't coalesce explicit
null, so fetch_pr_review_threads crashed with AttributeError and publish_review
could never post a review. Guard with isinstance checks and return collected
threads on null repository; sweep the same pattern in resolve_review_thread.
Co-authored-by: open-swe[bot] <215916821+open-swe[bot]@users.noreply.github.com>
* feat: make web threads viewable by any org user
Reads (get/stream) now allow any logged-in org user to view a thread
whose source is surfaced (dashboard/github/slack/linear/schedule),
instead of requiring ownership. Internal reviewer/analyzer threads stay
hidden via the same source filter. Writes (send/cancel/delete) remain
owner-only.
Adds GET /threads?all=true to list every surfaced thread; the default
list stays per-user.
* feat: make all web threads readable by any org user
Drop the per-thread source/owner gate on reads: any logged-in org user
can now view and stream any thread, including reviewer/analyzer threads.
GET /threads?all=true returns every thread regardless of source. Writes
(send/cancel/delete) stay owner-only. All routes remain behind the
session + org-login gate.
The bot's numeric noreply (215916821+open-swe[bot]@users.noreply.github.com)
introduced in ae946d1a doesn't resolve to a GitHub account Vercel accepts,
breaking preview deploys on PRs in langchainplus. Revert OPEN_SWE_BOT_EMAIL
to open-swe@users.noreply.github.com.
Co-authored-by: open-swe[bot] <215916821+open-swe[bot]@users.noreply.github.com>
* feat: add scheduled web agents
Co-authored-by: open-swe[bot] <215916821+open-swe[bot]@users.noreply.github.com>
* fix: secure scheduled agent repositories
Co-authored-by: open-swe[bot] <215916821+open-swe[bot]@users.noreply.github.com>
* feat: rebuild scheduled agents as Automations tab
Scrap the inline ScheduledAgentsPanel and replace it with a dedicated
Automations tab: sidebar nav entry, list view with stat cards + empty
state, and a full editor (name, Active toggle, repo, scheduled trigger
picker, agent instructions + model).
* fix: clear collapsed-sidebar button on mobile in Automations
* fix: allow clearing automation repo on update
---------
Co-authored-by: open-swe[bot] <215916821+open-swe[bot]@users.noreply.github.com>
* fix: tidy agents home, mobile logo, and PWA dev/icon issues
- Remove recent-runs cards from the new agent page
- Scale the ASCII logo to fit narrow viewports instead of overflowing
- Serve manifest in dev and skip SW registration in dev to clear console errors
- Use a flat, opaque apple-touch-icon so iOS stops adding a black border
- Ignore generated ui/dev-dist
* feat: add send button and prevent iOS focus-zoom on chat input
- Add a circular send button (accent, spinner while sending) to the prompt bar
- Bump textarea to 16px on mobile so iOS doesn't zoom the viewport on focus
* fix: polish prompt bar and center logo
- Center the ASCII logo at all widths
- Prevent iOS focus-zoom via viewport maximum-scale instead of bumping the
input to 16px, so mobile text stays the intended size
- Give the model picker a chip/chevron treatment to anchor it next to the send button
* fix: simplify model picker to plain text + chevron
* fix: tighten prompt bar padding and shrink send button
---------
Co-authored-by: open-swe[bot] <215916821+open-swe[bot]@users.noreply.github.com>
* Make dashboard UI mobile-friendly
- Drop the thread title/repo header on the agent chat view.
- Expanded sidebar becomes a full-screen overlay on mobile (<768px) instead of a squished column; resize handle hidden.
- Default to collapsed on mobile first load so the chat stays visible; navigating a link/thread auto-collapses the overlay.
* Fix settings rows and run cards overflowing on small screens
- SettingsRow stacks label/control vertically below sm; reduce AppShell padding on mobile.
- Truncate long model/repo names in AgentRunCard metadata so cards stay within bounds.
* Keep collapsed-sidebar button from overlapping page titles on mobile
* Render page titles below the sidebar button on mobile instead of indenting
* Don't persist mobile auto-close to localStorage, preserving desktop preference
---------
Co-authored-by: open-swe[bot] <215916821+open-swe[bot]@users.noreply.github.com>
* fix: stabilize agent defaults and repo selector
Co-authored-by: open-swe[bot] <215916821+open-swe[bot]@users.noreply.github.com>
* fix: align default repo selector styling, restore text fallback
Match the repo selector to sibling settings controls (h-7, bg-input/20,
text-xs). Fall back to a text input when the repo list is empty so a
default repo can still be entered.
* fix: make repo selector dropdown more compact
---------
Co-authored-by: open-swe[bot] <215916821+open-swe[bot]@users.noreply.github.com>
* fix: tag Slack threads with stored identity so they surface in web
process_slack_mention gated the run on mapped_login (resolved from the stable
Slack user id), but upsert_agent_thread_owner_metadata independently re-resolved
the GitHub login from the Slack profile email. When that email differs from the
user's mapping email (e.g. a personal vs work address), the lookup returned None,
so github_login was never stamped on the thread and the thread never surfaced in
the web Agents UI (which searches by github_login / triggering_user_email).
Resolve the GitHub user from the store via the Slack id, pass that login through
to the owner metadata, and use the mapping's stored work email (falling back to
the Slack profile email for unmapped users) for both the run config and the
thread tagging, so Slack-started threads reliably appear in web.
* fix: stamp github_login on Slack threads so they surface in web
process_slack_mention gated the run on mapped_login (resolved from the stable
Slack user id) but upsert_agent_thread_owner_metadata re-resolved the login from
the Slack profile email; when that email isn't the user's mapping email the
lookup returns None and github_login is never stamped, so the thread is invisible
in the web Agents UI (which searches by github_login / triggering_user_email).
Pass the already-resolved mapped_login through to the owner metadata. The
dashboard match keys on the stable GitHub login, so this is sufficient; the
triggering email stays the live Slack profile value.
* fix: preserve Slack email during account mapping
* fix: require Slack OIDC for email mappings
* chore: format Slack OIDC mapping cleanup
Reviewer/push runs execute in a worker process, but the GitHub token was
cached by the webhook handler in the API server process — a different
process — so the worker's in-process cache was always cold. resolve_github_token
then failed (User not authenticated / Unknown source: github_push) and only the
app-token fallback kept reviews working, noisily.
The reviewer always acts as the GitHub App (open-swe[bot]), so resolve the
installation token directly at run start, scoped to the repo. This also bypasses
org SAML enforcement that blocks user OAuth tokens. Drop the now-dead
cross-process cache writes in the webhook reviewer-dispatch handlers, and stop
leave_failure_comment raising on the github_push source.