open-swe/agent/dashboard
Adam Moussa d48cb12e08
Some checks failed
CI / Lint (push) Has been cancelled
CI / Format check (push) Has been cancelled
CI / Typecheck (push) Has been cancelled
CI / Unit tests (push) Has been cancelled
CI / Playwright E2E (push) Has been cancelled
CI / Docker build smoke (push) Has been cancelled
CI / Triage ledger up to date (push) Has been cancelled
CI / ui bun.lock in sync (push) Has been cancelled
feat(open-swe): port upstream clean batch (#1788, #1786, #1764, #1782, #1791, #1799) + guard hardening (#226)
* Fix: Fix Insecure Direct Object Reference in slack_start_new_thread.py (#1788)

Co-authored-by: corridor-security[bot] <203152403+corridor-security[bot]@users.noreply.github.com>
(cherry picked from commit 32e81f2979a7baf11fe387df59f7d13a31889c74)

* Fix PR creation guard shell bypasses (#1786)

Co-authored-by: langsmith-fleet[bot] <langsmith-fleet[bot]@users.noreply.github.com>
(cherry picked from commit 75fb8b487852003916c4984504a13ee7226b2ceb)

* fix: add exc_info to swallowed exception in push re-review webhook (#1764)

(cherry picked from commit ab85b372b4f37b7feb849054553daed10852a42c)

* chore: clarify shared response image guidance (#1782)

Co-authored-by: Ramon Nogueira <270434257+ramon-langchain@users.noreply.github.com>
Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>
(cherry picked from commit 2e8ff4b72f1148bb36c0c1181063a3abd78b15d0)

* fix: match embedded review description background (#1791)

Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>
(cherry picked from commit 4ea2441ada1229bc414b02950d821786be2f7301)

* fix: show current shared thread in sidebar (#1799)

* fix: show current shared thread in sidebar

Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>

* fix: preserve resolved active sidebar threads

Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>

---------

Co-authored-by: Ramon Nogueira <270434257+ramon-langchain@users.noreply.github.com>
Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>
Co-authored-by: Johannes du Plessis <51395795+johannes117@users.noreply.github.com>
(cherry picked from commit a77c4e475643b4a55bb2f0c93c0aa2669014fbac)

* chore: switch deferred items to landed in upstream-sync triage documentation and jsonl entries (fork PR #226).

Signed-off-by: Adam Moussa <adam@seahavenind.com>

* harden PR guards + sidebar after security review

- Mirror upstream #1786's nested-shell / executable-normalization hardening
  into the fork-only pr_verdict_guard.py (verdict-gating is a real fork
  control), keeping it in parity with pr_creation_guard.py.
- Close the glued short-flag bypass (bash -c'...') in BOTH guards: a shell's
  -c argument can be concatenated into the same argv token, which the
  space-separated -c detection missed. Diverges pr_creation_guard.py from
  upstream #1786 by design; to be upstreamed.
- Gate the new #1799 sidebar active-thread refresh on ownership so a non-owner
  viewing a shared thread reads last-known state without persisting a metadata
  write (mirrors the is_owner gate on the single-thread read path).
- Fix an F821 in the #1799 cherry-pick (Mapping import / concrete dict type).

Guards remain intentionally fail-open per the honest-agent threat model;
docstrings narrowed to name the residual exotic-shell / stdin-fed vectors.

---------

Signed-off-by: Adam Moussa <adam@seahavenind.com>
Co-authored-by: corridor-security[bot] <203152403+corridor-security[bot]@users.noreply.github.com>
Co-authored-by: John Kennedy <65985482+jkennedyvz@users.noreply.github.com>
Co-authored-by: langsmith-fleet[bot] <langsmith-fleet[bot]@users.noreply.github.com>
Co-authored-by: Suraj Bayas <surajyou24@gmail.com>
Co-authored-by: Ramon Nogueira <ramon.nogueira@langchain.dev>
Co-authored-by: Ramon Nogueira <270434257+ramon-langchain@users.noreply.github.com>
Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>
Co-authored-by: Johannes du Plessis <johannes@langchain.dev>
Co-authored-by: Johannes du Plessis <51395795+johannes117@users.noreply.github.com>
2026-07-24 18:49:53 -04:00
..
__init__.py refactor: split webapp.py into api/ + per-source webhook routes 2026-07-17 14:30:05 -04:00
admin.py fix: allow GitHub logins for dashboard admins (#1582) 2026-06-20 09:44:12 -07:00
agent_instructions.py feat: per-repo custom instructions for the coding agent (#1460) 2026-06-09 15:46:29 -07:00
agent_overrides.py feat: author Slack/dashboard/schedule commits + PRs as the app by default (#57) (#60) 2026-06-29 14:22:33 -04:00
agent_usage.py refactor: consolidate reviewer modules into agent/review/ 2026-07-17 13:52:03 -04:00
analyzer_cron.py feat: outcomes dataset + bootstrap/continual split via skills (#1365) 2026-06-01 13:25:12 -07:00
autofix_state.py feat: activate PR babysitting UI toggles for autofix and trigger mode (#1561) 2026-06-17 14:12:04 -07:00
enabled_repos.py feat: restructure Open SWE Review tab + wire create_prs (#1319) 2026-05-21 09:17:07 -07:00
eval_jobs.py refactor: consolidate reviewer modules into agent/review/ 2026-07-17 13:52:03 -04:00
notion_oauth.py feat: add user-scoped Notion MCP OAuth (#1593) 2026-06-23 12:07:13 -07:00
oauth.py feat: port plan-review & workflow-approval UX (#159) 2026-07-09 16:03:13 -04:00
options.py feat(open-swe): re-add Fable 5 behind an admin toggle (Bedrock) (#172) 2026-07-10 14:05:20 -04:00
plan_api.py feat: port plan-review & workflow-approval UX (#159) 2026-07-09 16:03:13 -04:00
plan_store.py feat: port plan-review & workflow-approval UX (#159) 2026-07-09 16:03:13 -04:00
pr_diff.py feat: render Reviews page diffs with pierre MultiFileDiff (#1517) 2026-06-12 11:03:51 -07:00
profiles.py fix: auto-recover from expired GitHub refresh tokens (#1491) 2026-06-11 12:05:27 -07:00
repo_access.py chore: sync upstream/main, defer #1621 modular webhooks (#81) 2026-06-30 16:45:19 -04:00
repo_snapshots.py feat: optional separate LangSmith key/endpoint for sandboxes (#1760) 2026-07-17 16:22:38 -04:00
review_api.py refactor: split webapp.py into api/ + per-source webhook routes 2026-07-17 14:30:05 -04:00
review_chat_api.py refactor: consolidate reviewer modules into agent/review/ 2026-07-17 13:52:03 -04:00
review_style_jobs.py refactor: split webapp.py into api/ + per-source webhook routes 2026-07-17 14:30:05 -04:00
review_styles.py feat: outcomes dataset + bootstrap/continual split via skills (#1365) 2026-06-01 13:25:12 -07:00
routes.py feat(open-swe): port upstream clean batch (#1788, #1786, #1764, #1782, #1791, #1799) + guard hardening (#226) 2026-07-24 18:49:53 -04:00
schedules.py feat(open-swe): re-add Fable 5 behind an admin toggle (Bedrock) (#172) 2026-07-10 14:05:20 -04:00
slack_oauth.py chore: sync upstream/main, defer #1621 modular webhooks (#81) 2026-06-30 16:45:19 -04:00
team_credentials.py feat: server-side Datadog/LangSmith observability tools + team creds [closes OPE-54] (#1476) 2026-06-10 11:07:42 -07:00
team_settings.py fix: stale admin model defaults after model upgrades (#1709) (#200) 2026-07-16 18:03:44 -04:00
thread_api.py feat(open-swe): port upstream clean batch (#1788, #1786, #1764, #1782, #1791, #1799) + guard hardening (#226) 2026-07-24 18:49:53 -04:00
user_credentials.py feat: add user-scoped Notion MCP OAuth (#1593) 2026-06-23 12:07:13 -07:00
user_mappings.py feat: managed LangGraph Cloud + Vercel migration (PR2 — code fixes + docs) (#65) 2026-06-29 19:58:38 -04:00
workflow_approval.py feat: port plan-review & workflow-approval UX (#159) 2026-07-09 16:03:13 -04:00
workflow_approval_api.py feat: port plan-review & workflow-approval UX (#159) 2026-07-09 16:03:13 -04:00