mirror of
https://github.com/Sea-Haven-Industries/open-swe.git
synced 2026-09-30 13:53:15 +00:00
#1796 deferred pending the deepagents 0.7.x bump (#1745); #1797/#1800 wont-merge (repo-skills feature reverted upstream); #1774 flipped from deferred to wont-merge since upstream withdrew the feature in #1800.
35 KiB
35 KiB
Upstream triage ledger
Commits on upstream/main (langchain-ai/open-swe) not yet in dev, and the decision on each.
Rows key on the upstream SHA (stable across local cherry-picks). Deferred rows are provisional
— re-inspect before picking. See the fork-maintenance runbook in CLAUDE.md.
Last synced upstream/main: 60e7307c (2026-07-23)
| sha | pr | subject | decision | why | branch |
|---|---|---|---|---|---|
0b76afdc |
#1653 | reviews block agenda, sticky headers, diff scroll | Landed | cherry-pick-upstream | |
7530653b |
#1655 | ResizeObserver settle for review scroll-to | Landed | cherry-pick-upstream | |
23bd4a63 |
#1660 | top padding to sticky review block header | Landed | cherry-pick-upstream | |
9e5a1924 |
#1656 | purge expired thread_wakeup crons | Landed | cherry-pick-upstream | |
63eb9a08 |
#1661 | sidebar filter popover border tokens | Landed | cherry-pick-upstream | |
bc7ce591 |
#1668 | preserve dashboard redirect after login | Landed | cherry-pick-upstream | |
f32e492a |
#1637 | return to thread after plan approval | Landed | cherry-pick-upstream | |
7ee3e057 |
#1636 | make plan view mobile friendly | Landed | cherry-pick-upstream | |
6575c327 |
#1654 | disable React StrictMode | Landed | kept fork's PwaUpdateProvider |
cherry-pick-upstream |
00906401 |
#1610 | editable plan mode | Landed | re-implemented in fork via #130 (editable plan mode) | |
f5670f24 |
#1639 | require bun for ui agent work | Landed | cherry-picked (-x) in this PR (#132) | PR1 |
209132d3 |
#1621 | durable interrupt dispatch + completion webhook | Landed | investigate first — may be applied | durable-dispatch |
02bb4dfd |
#1658 | don't attach loopback run-complete webhooks | Landed | durable-dispatch | |
29015fad |
#1614 | gate workflow pushes with approval | Landed | durable-dispatch | |
546042a4 |
#1652 | add workflow approval UI | Landed | plan-approval | |
ae04b72b |
#1635 | publish plans from sandbox files | Landed | ported (adapted) in #128 (save_plan reads sandbox file) | plan-approval |
c03a6be7 |
#1634 | keep plan guidance high-level | Landed | plan-approval | |
96cceb74 |
#1632 | notify Slack on plan approval | Landed | ported (adapted) in #128 | plan-approval |
2f56d754 |
#1618 | omit plan link when no plan exists | Landed | already in dev via #81 (upstream-sync); ledger was stale (was: likely regression) | plan-approval |
ee224d3e |
#1650 | add Slack reaction tool | Landed | slack-tooling | |
747ce4bb |
#1638 | add Slack breakout thread tool | Landed | slack-tooling | |
27d90ef1 |
#1633 | include Slack channel context in prompts | Landed | slack-tooling | |
92dbf6f9 |
#1630 | update Slack trace reply on web handoff | Landed | ported in #128 (trace_message_ts on first-mention run mapping) | slack-tooling |
bb36448b |
#1627 | surface Slack thread errors | Landed | slack-tooling | |
73b7d1c0 |
#1678 | fix OpenAI Responses reasoning replay | Landed | gateway-routing | |
5f7c2f46 |
#1674 | fix Fireworks Gateway base URL | Landed | gateway-routing | |
702ef908 |
#1673 | dedicated LangSmith gateway API key | Landed | gateway-routing | |
e9dc6e01 |
#1671 | opt-in LangSmith LLM Gateway routing | Landed | gateway-routing | |
289f5e3a |
#1651 | add Sonnet 5 to model picker | Landed | already in dev; added Bedrock family fallback fix (c16fb915) |
gateway-routing |
5da3d0c6 |
#1624 | post reviewer resolution notes verbatim | Landed | cherry-picked (-x) in #127 | reviewer-misc |
69148f54 |
#1612 | add PR trace resolution | Landed | cherry-picked (-x) in #127 | reviewer-misc |
6d125526 |
#1625 | stop wrapping installs in sfw | Landed | already present in dev; empty pick confirmed in #127 | reviewer-misc |
320bb39a |
#1657 | opt-in tracemalloc for aiohttp sessions | Landed | cherry-picked (-x) in #127 | reviewer-misc |
4f913198 |
#1647 | widen split review diffs | Landed | already present in dev; empty pick confirmed in #127 | reviewer-misc |
20f63e8c |
#1646 | install missing deps before verification | Landed | already in dev via #81 (upstream-sync); ledger was stale | prompt-tweaks |
2f237b53 |
#1626 | fall back to vision model for image threads | Landed | ported (adapted to Bedrock/Fireworks vision) in #128 | gateway-routing |
48217b68 |
#1489 | feat(open-swe): add E2B sandbox provider (#1489) | Landed | re-implemented on fork's sync create_sandbox factory in #199 (E2B SDK is sync; async base not needed); langchain-e2b==0.0.4; dark-safe; GitHub proxy/App-token flow untouched | feat/port-1489-e2b-provider |
fbc6de85 |
#1667 | chore(deps): bump fireworks-ai from 1.2.0a75 to 1.2.0a86 (#1667) | Landed | Superseded by #158 (fireworks-ai a85 -> a88, efeb6b12); dev already exceeds a86. No port needed. |
deps |
c9f6dd86 |
#1694 | fix: fall back on model stream transport errors (#1694) | Landed | adds httpx.TransportError to transient set; small conflict w/ dev's diverged Bedrock fallback | model-fallback |
c9a9a7cd |
#1695 | fix: retry model fallback exhaustion (#1695) | Landed | alternating retry+backoff rewrite; reconcile by hand w/ dev's Bedrock + sync wrap path | model-fallback |
e5dbc788 |
#1696 | fix: Harden durable agent runs (#1696) | Landed | large durable-run hardening; 3 new modules dev lacks; rewrites fork dispatch/completion | durable-dispatch |
52fe2916 |
#1698 | feat: add PR review link route (#1698) | Landed | cherry-picked (-x) in #127 (PR review link route) | reviewer-misc |
5f7f5fbd |
#1697 | fix: Reduce graph import and loader startup latency (#1697) | Landed | import-hygiene refactor; cross-cutting, references many deferred upstream-only modules | durable-dispatch |
216cf181 |
#1699 | fix: keep workflow HITL without token downscoping (#1699) | Landed | DIVERGES-FROM-UPSTREAM: fork deliberately does NOT adopt #1699's standing-token workflows:write broadening. Security review (#159) BLOCKed it — the standing ALWAYS-ON proxy token carrying workflows:write turns the HITL guard's git-push-parser gaps (obfuscated-expansion push, gh api REST contents PUT, cross-branch refspecs) into live unapproved-workflow-push exploits. Fork keeps BASE without workflows:write and restores the transient per-approval elevation (_run_with_workflow_token mints WORKFLOW_RUNTIME_PROXY_TOKEN_PERMISSIONS around the approved, guard-normalized fixed_command, then downscopes to RUNTIME then BASE): the token scope is the backstop the parser relies on, so a bypass hits GitHub 403. HITL diff-preview/approval-URL/Slack-card additions from #159 retained; token-model divergence only. |
plan-approval |
67abf5b0 |
#1659 | fix: surface attributed PR creation failures (#1659) | Landed | PR-attribution-failure guard (new mw, safe imports); heavy conflict on diverged open_pull_request.py | pr-attribution |
3dbc0282 |
#1676 | fix: preserve plan redirects after login (#1676) | Landed | FLAG-HUMAN: follow-on to landed #1668 refining sanitize_redirect_to (open-redirect auth surface); not a dup | plan-approval |
c75cbb1f |
#1677 | feat: re-add Fable 5 with an admin toggle to disable it (#1677) | Landed | Ported + Bedrock-converted onto dev via feat/readd-fable5-bedrock; anthropic: Fable ID mapped to bedrock_converse:us.anthropic.claude-fable-5. | fable-admin-toggle |
bb104d93 |
#1679 | fix: submit plan comments with cmd enter (#1679) | Landed | applies clean but edits fork-diverged PlanReview.tsx (#130); needs UI/e2e validation — separate PR | plan-approval |
304032fa |
#1680 | chore: clarify question answering prompt (#1680) | Landed | reword Slack info-only answer guidance; conflicts w/ fork's customized Slack prompt | prompt-tweaks |
5003c953 |
#1683 | feat: open Linear-triggered PRs as the triggering user (#1683) | Landed | FLAG-HUMAN: adds linear to resolve_github_token per-user OAuth branch (auth surface); depends on #1626 linear.py | feature/port-linear-pr-author |
feb7ac98 |
#1689 | feat(web): surface thread sandbox ID with touch-friendly menu (#1689) | Landed | Ported to dev via feat/thread-sandbox-id-sidebar. | dashboard-ui |
7f7af715 |
#1684 | feat: auto-load scoped AGENTS on reads (#1684) | Landed | ported in #129 (SubdirAgentsReadMiddleware) | subdir-agents |
88b62322 |
#1685 | feat: add platform issue reporting tool (#1685) | Landed | ported in #129 (report_platform_issue tool) | small-tools |
90cb6caa |
#1681 | feat: terse Slack replies, share long content via plan-review page (#1681) | Landed | terse Slack + long-content-via-plan-page; conflicts w/ fork prompt + diverged plan stack | plan-approval |
f53caff1 |
#1701 | fix: fall back to core GitHub App scope when optional grants missing (#1701) | Landed | Ported as Option A: workflows:write kept OUT of standing scope, minted only transiently by the workflow-push guard (security-reviewed); PR #181 | chore/port-github-app-scope-fallback |
22e024cb |
#1704 | fix: link issue PRs and prompt repo conventions (#1704) | Landed | issue/PR linking + repo-convention prompt; clean but prompt-conflict risk vs #113 | chore/upstream-easy-picks |
62e0ca2d |
#1709 | fix: stale admin model defaults after model upgrades (#1709) | Landed | cherry-picked (-x) in #200; retired-model map converted to fork Bedrock/Fireworks IDs (Fable deliberately maps to Opus — provider-data-share gate; test-pinned); dropped #1708-entangled profile tests | fix/port-1709-stale-model-defaults |
138ab9ec |
#1710 | fix: bump langchain-fireworks to 1.4.4 (#1710) | Landed | langchain-fireworks 1.4.4 adopted via fork Dependabot group PR #190 (dev now resolves langchain-fireworks==1.4.4); upstream commit not cherry-picked | deps |
71e3b818 |
#1713 | fix: align reviewer eval with published findings (#1713) | Landed | cherry-picked (-x) in #201; reviewer.py + publish_review.py hand-reconciled into fork structure (kept sandbox/skills/middleware stack, kebab-case workflow, Bedrock eval default); publish_review cap param removed (tool-facing only) | fix/port-1713-reviewer-eval-alignment |
092abafa |
#1717 | fix: enforce terse Slack tool messages (#1717) | Landed | cherry-picked (-x) in #197; one test conflict resolved by adopting upstream's test (fork prompt now contains upstream text); follow-up to landed #1681, not superseded by it | fix/port-1717-terse-slack-tool-msgs |
92d63170 |
#1720 | fix: separate review access from automatic reviews (#1720) | Landed | cherry-picked (-x) in #198 + fork-only auto-fix gates renamed to _is_repo_auto_review_enabled (kept opt-in-gated); opt-in list now gates only AUTOMATIC reviews — manual/re-review/watch/finding-replies open to any App-installed repo. Adam signed off 2026-07-16; /sh-security-review explicitly waived by Adam 2026-07-16 | fix/port-1720-review-access-split |
8356eb34 |
#1726 | refactor: organize repository by domain (#1726) | Landed | Adopted as a file-move exercise (fork content, upstream layout) on branch refactor/domain-reorg-adoption — gate-approved plan in docs/upstream-sync/domain-reorg/. New layout: agent/{graphs,runtime,api,review,resources}, agent/webhooks/*_routes.py (webapp.py split into api/ + per-source route modules; webapp.py now a shim), tests//, ui/src/features/. Kills the per-pick path-remap tax and unblocks 8 deferred rows (#1732/#1761/#1744/#1748/#1742 clean; #1736/#1758/#1760 near-clean). | refactor/domain-reorg-adoption |
129ddcf9 |
#1728 | chore: include ripgrep in sandbox image (#1728) | Landed | 1-line Dockerfile add (ripgrep); dev image lacks it; trivial pick | chore/upstream-easy-picks |
1ea03a43 |
#1729 | feat: include Cargo in sandbox image (#1729) | Landed | 2-line Dockerfile add (Cargo); adopt with #1728 | chore/upstream-easy-picks |
09eaf94c |
#1730 | fix: let admins interrupt runaway agents (#1730) | Landed | admin interrupt for runaway agents (dashboard route + UI); useful ops control; UI half on post-reorg ui/src/features — remap to ui/src/components/agents | feat/admin-thread-interrupt |
1ea0e600 |
#1736 | fix: bind cached GitHub tokens to users (#1736) | Landed | Landed via fork PR #207 after both gates passed (GPT-4.1 cross-family: no BLOCK; /sh-security-review: 0 confirmed critical/high, 1 accepted low CWE-613). Composed with the fork's repo-binding: cache key (thread_id, principal), values keep bound_repo; unprincipaled user tokens refused. Added bot-fallback + cross-repo composition tests. | bug/bind-cached-github-tokens |
d714586c |
#1732 | fix: normalize dashboard label rendering (#1732) | Landed | Landed via fork PR #206 (clean cherry-pick). | feature/port-upstream-clean-batch |
3e8089c3 |
#1744 | fix: collapse git panel by default (#1744) | Landed | Landed via fork PR #206. One import-context conflict in AgentThreadView.tsx resolved (upstream moved panel prefs to ui/src/features/agents/lib/gitPanelPreferences.ts). | feature/port-upstream-clean-batch |
c34e04f4 |
#1742 | fix: defensive copy in get_reviewer_agent and get_chat_agent [closes #1584] (#1742) | Landed | Landed via fork PR #206 (cherry-pick, authors reset). Two fork-only reviewer tests that relied on the pre-fix in-place config mutation updated to assert against the agent-bound config. | feature/port-upstream-clean-batch |
79df6b2f |
#1748 | feat: add Linear issue search tool (#1748) | Landed | Landed via fork PR #206. Python auto-merged; fork's CLAUDE.md/AGENTS.md/README kept their own tool-list style with linear_search_issues inserted in place. | feature/port-upstream-clean-batch |
c69459ad |
#1751 | fix: prefer LangSmith tools for trace links (#1751) | Landed | 1-line prompt: prefer LangSmith tools for trace links; trivial but edits fork-customized prompt.py | chore/upstream-easy-picks |
5cb2e2bb |
#1750 | fix: add trace link to error banner (#1750) | Landed | adds trace link to error banner (13 lines); remap AgentThreadView.tsx path (fork: ui/src/components/agents/) | chore/upstream-easy-picks |
22383033 |
#1758 | feat: inject extra JSON fields into sandbox create via env var (#1758) | Landed | Landed via fork PR #206, re-implemented against the fork's sync SandboxClient (upstream is async AsyncSandboxClient — retry/reconnect helpers not adopted; future picks touching them will conflict). | feature/port-upstream-clean-batch |
e826864d |
#1760 | feat: optional separate LangSmith key/endpoint for sandboxes (#1760) | Landed | Landed via fork PR #206 on the sync client. Sandbox endpoint honors SANDBOX_LANGSMITH_ENDPOINT/LANGSMITH_ENDPOINT (LANGCHAIN_ENDPOINT alone no longer applies); new sandbox names thread-deterministic with _release_sandbox_name before create. | feature/port-upstream-clean-batch |
dd5b7bec |
#1761 | fix: capitalize dashboard tool labels (#1761) | Landed | Landed via fork PR #206 (clean cherry-pick, stacked on #1732). | feature/port-upstream-clean-batch |
b5e52925 |
#1775 | feat: add structured Linear issue filters (#1775) | Landed | Clean pick: structured filters for linear_search_issues — stacks directly on #1748 (landed PR #206); zero fork drift on all three files. Ready whenever. | feature/upstream-clean-batch-security-linear |
31263f83 |
#1785 | Fix: Fix Stored XSS in ReplyCard.tsx (#1785) | Landed | SECURITY priority, near-clean: diff is urlencode() hardening of the GitHub OAuth authorize URL in dashboard routes.py auth_login (upstream bot title says ReplyCard.tsx — mismatch, trust the diff). Fork auth_login has the identical f-string URL; hunk applies clean. Port promptly. | feature/upstream-clean-batch-security-linear |
3ea29d3f |
#1789 | Fix: Fix Improper privilege management in server.py (#1789) | Landed | SECURITY priority, near-clean: adds empty-signature reject to verify_github_signature (utils/github_comments.py) + verify_linear_signature (webhooks/common.py) (title says server.py — mismatch, trust the diff). Both fork functions match at the hunk sites; fork-only verify_jira_secret already guards empty token. Real value: None signature currently raises TypeError in compare_digest. Port BOTH hunks together. | feature/upstream-clean-batch-security-linear |
c3292d82 |
#1611 | bake sfw binary into sandbox image | Won't merge | already in dev | |
48bf712b |
#1609 | show message timestamps | Won't merge | already in dev | |
85c0f63e |
#1620 | clickable shared PR header | Won't merge | already in dev | |
db2ae58e |
#1643 | pre-bundle shiki/@pierre deps | Won't merge | already in dev | |
1d9da064 |
#1662 | bump astral-sh/setup-uv | Won't merge | dev ahead (v8.2.0, checkout@v7) |
|
83cb40a0 |
#1616 | update langsmith sdk to 0.9.3 | Won't merge | regression — dev has 0.9.6 | |
e5a29eca |
#1613 | plan links in PR descriptions | Won't merge | regression — dev has async plan-ref | |
e1d85526 |
#1645 | switch ui to pnpm | Won't merge | tooling — fork keeps bun | |
4cd5fa5c |
#1629 | avoid recapping Slack replies | Won't merge | already in dev — landed via sync PR #81 (1f060f2a), then deliberately superseded by the fork's refined Slack no-duplication rule in PR #159 (f87847ba) |
|
baf0c248 |
#1617 | filter & grouping menu in threads sidebar | Won't merge | already in dev — full feature present (sidebarFilter/sidebarPrefs/SidebarFilterMenu + AgentsSidebar wiring); only deltas are the later-landed #1661 token restyle | |
f29868ff |
#1615 | recover thread work as patch | Won't merge | already in dev via squash-sync PR #81 (1f060f2a) — recovery-patch vertical byte-identical to upstream; 6 recovery tests pass on dev |
|
8e0788dc |
#1631 | show queued dashboard follow-ups | Won't merge | already in dev via squash-sync PR #81 (1f060f2a) — full queued-follow-ups vertical (types, QueuedMessages UI, streaming de-dupe, e2e) present and since evolved |
|
9c601ca1 |
#1648 | add Stagehand-powered browser subagent | Won't merge | requires Browserbase/Stagehand creds or Chromium-in-server-image + hard stagehand dep; browser runs in server process outside the sandbox; against fork curated-tools policy, no fork use case | |
8c944381 |
#1622 | restore forced tool call | Won't merge | already in dev via squash-sync PR #81 (1f060f2a) — ensure_no_empty_msg middleware/tests/wiring/prompt line byte-identical to 8c944381; squash hid it from ancestry |
|
5dc360d8 |
#1619 | bump langgraph-checkpoint 4.1.0→4.1.1 | Won't merge | already in dev — uv.lock already resolves langgraph-checkpoint 4.1.1 | |
89f886e2 |
#1642 | request actions read for sandbox logs | Won't merge | already in dev — actions:read in RUNTIME_PROXY_TOKEN_PERMISSIONS + identical prompt line | |
27f987dc |
#1686 | refactor: remove dead sync-interface compatibility code (#1686) | Won't merge | pure dead-sync-path deletion committing to the async-only posture the fork rejects; fork still uses get_sandbox_backend_sync; no embedded fix | |
2503a2f4 |
#1687 | refactor(open-swe): provision LangSmith sandboxes natively async (#1687) | Won't merge | async pivot of create_sandbox/_configure_github_proxy (auth surface) — fork keeps sync lifecycle; langsmith bump subsumed by fork's 0.10.5 pin; metadata-await fix moot on fork's to_thread path | |
2529b109 |
#1690 | fix: checkpoint per-run graph setup (#1690) | Won't merge | fork's get_agent re-runs idempotent setup by design (stateless), so the un-checkpointed-setup bug doesn't exist; faithful adaptation is a 4-graph rewrite presupposing the deferred async base | |
c0a7e93e |
#1691 | fix: reconnect sandbox backend on resumed runs (#1691) | Won't merge | fixes a #1690-introduced regression (latched setup skips ensure on resume); fork unconditionally re-runs ensure_sandbox_for_thread (case-4 reconnect), so the gap doesn't exist | |
4f8bc2dd |
#1692 | refactor: simplify open-swe agent sandbox lifecycle (#1692) | Won't merge | structural rewrite deleting the fork's 4-case creating sentinel; net diff is exactly the sentinel removal + rewritten test; collides with fork-only TID-COLLIDE-01 repo-binding guard | |
ab4eea4b |
#1663 | chore(deps): bump the major group across 1 directory with 3 updates (#1663) | Won't merge | already in dev — CI already on checkout@v7/setup-node@v6/upload-artifact@v7 | |
2bf207fb |
#1664 | chore(deps): bump python in the minor-and-patch group (#1664) | Won't merge | already in dev — Dockerfile already at python 3.14.6-slim-trixie | |
13b40113 |
#1666 | chore(deps): bump cryptography from 48.0.1 to 49.0.0 in the major group (#1666) | Won't merge | already in dev — same 48->49 cryptography bump dev did via #105 | |
290d0fee |
#1669 | chore(deps): update langgraph-cli[inmem] requirement (#1669) | Won't merge | already in dev — langgraph-cli[inmem] at 0.4.30 | |
73a9e8b5 |
#1693 | chore(deps): bump the minor-and-patch group across 1 directory with 19 updates (#1693) | Won't merge | dev at-or-ahead on 17/19; group fights dev's pinned langsmith==0.9.7 (#115) and carries an upstream plan-route test | |
9cd7e464 |
#1700 | Fix workflow approval visibility (#1700) | Won't merge | superseded — dev's list_workflow_approvals_for_thread already enforces owner-only 403 | |
fd2541ce |
#1705 | fix: drop orphaned function_call items with stale OpenAI reasoning (#1705) | Won't merge | N/A — edits sanitize_openai_responses.py which dev deleted in the Bedrock/Fireworks migration (#62) | |
27b0ddeb |
#1708 | feat: add GPT-5.6 OpenAI models (#1708) | Won't merge | fork picker deliberately Bedrock/Fireworks-only — no-OpenAI-models product decision (consistent with #1725/#1727); options.py verified zero openai: IDs | |
35659177 |
#1718 | fix: sanitize orphaned OpenAI tool results (#1718) | Won't merge | N/A — fork has no OpenAI Responses traffic path; middleware present is #155's leaner rewrite lacking the orphan machinery #1718 patches; langchain-openai>=1.3.4 already satisfied; superseded upstream by #1731 (re-evaluate #155 rewrite when triaging #1731). Note: fd2541ce row's '#62 deleted sanitize_openai_responses.py' is inaccurate — the path was added fresh by #155 | |
5136079d |
#1725 | chore: disable todos for GPT-5.6 Sol (#1725) | Won't merge | superseded — #1733 (136d28e6) rewrites the same todo-exclusion block to a global default-off with env opt-in; per-model GPT-5.6 Sol list moot (fork picker has no OpenAI models) | |
bfa67a7a |
#1711 | chore(deps): bump soupsieve from 2.8.3 to 2.8.4 (#1711) | Won't merge | already in dev — uv.lock resolves soupsieve 2.8.4 | |
f7d94ad3 |
#1721 | docs: add e2b to sandbox provider lists in AGENTS.md and CLAUDE.md (#1721) | Won't merge | N/A — edits upstream AGENTS.md/CLAUDE.md, both fully fork-rewritten; E2B provider itself deferred (48217b68) — add a doc line if/when E2B lands | |
4773b336 |
#1746 | chore: point basedpyright at uv's .venv (#1746) | Won't merge | tooling — fork does not use basedpyright (lint stack is ruff); nothing to point at .venv | |
697adaa7 |
#1752 | fix: update PyJWT to 2.13.0 (#1752) | Won't merge | already in dev — uv.lock resolves PyJWT 2.13.0 | |
714ea4a2 |
#1759 | fix: clear basedpyright standard-mode type errors (#1759) | Won't merge | tooling — basedpyright type-error cleanup across 123 post-reorg files; fork uses ruff and the pre-reorg layout | |
dccf6437 |
#1769 | fix: tighten sandbox config test types (#1769) | Won't merge | test-only change in post-reorg path tests/sandbox/ — fork doesn't have this file (domain reorg #1726 deferred) | |
c9a193e2 |
#1766 | chore(deps): bump mcp from 1.27.2 to 1.28.1 (#1766) | Won't merge | indirect dependency bump (mcp); fork's own Dependabot handles these | |
d0b63551 |
#1773 | fix: remove workflow push approval gating (#1773) | Won't merge | Removes WorkflowPushGuardMiddleware and the proxy-token permission ladder — both actively wired in this fork (server.py middleware stack; github_app.py scoped-mint fallback). Adopting would let agent runs push .github/workflows/ changes with no human approval and mint proxy tokens at full scope unconditionally — a security-posture loosening counter to Sea Haven gating. Keep the fork's guard; skip the doc/prompt relaxation too (fork prompt documents the approval flow). | |
589dfd83 |
#1787 | fix: Harden Stagehand browser URL handling (#1787) | Won't merge | Follows #1648 (wont-merge): fork does not carry the Stagehand browser subagent — this 'fix' re-adds the entire module (992 insertions; modify/delete vs HEAD) plus the stagehand dep in pyproject/uv.lock. Adopting would resurrect a feature rejected under the curated-tools policy. | |
df743658 |
#1774 | feat: add repository skill support to the coding agent (#1774) | Won't merge | Upstream reverted this feature in #1800: its factory-time ensure_sandbox_for_thread call ran outside the serialized run and raced the deterministic sandbox name (prod sandbox-create 409s spiking from the #1774 merge date). Feature withdrawn upstream; the fork's deferred security review is moot. If upstream re-lands repo skills (host-side .agents/skills resolution per #1800), triage that new commit fresh — the prompt-injection / trusted-ref concerns in the old reason still apply. | |
5b5e6076 |
#1790 | chore: Add open wiki docs (#1790) | Won't merge | Upstream-repo openwiki doc site + AGENTS.md/CLAUDE.md pointers: content documents upstream's codebase and would be wrong for this fork (conflicts with the fork's heavily customized CLAUDE.md, which is canonical). Its companion auto-update workflow is bot-push docs automation counter to the fork's workflow-gating posture (#1773). | |
1443fc4b |
#1792 | fix: Update openwiki gh action (#1792) | Won't merge | Follows #1790 (wont-merge): fixes the openwiki-update workflow this fork does not carry (modify/delete vs HEAD). | |
e1138cf5 |
#1797 | fix: merge concurrent trusted skill refs (#1797) | Won't merge | Follow-up fix to #1774's TrustedSkillsMiddleware, which the fork never adopted (row df743658) and upstream itself reverted in #1800 — nothing to apply. | |
60e7307c |
#1800 | revert: repository skill support for the coding agent (#1774, #1797) (#1800) | Won't merge | Revert of #1774 + #1797; the fork adopted neither, so there is nothing to revert. Upstream's rationale: #1774's factory-time ensure_sandbox_for_thread ran outside the serialized run and raced the thread-deterministic sandbox name (prod create-409s). Fork invariant holds: its single provisioning call sits inside the creating-sentinel lifecycle within the interrupt-serialized run. | |
83abea26 |
#1724 | fix: accept natural-language Slack plan approvals (#1724) | Deferred | natural-language Slack plan approvals; touches fork-diverged plan-mode + Slack webhook stack (#130); post-reorg test paths need remap | plan-approval |
ddbe457b |
#1727 | fix: restore GPT-5.5 as default model (#1727) | Deferred | restores GPT-5.5 default in options/team_settings; fork picker is Bedrock/Fireworks-only — rides the #1708 OpenAI-models product decision (27b0ddeb) | model-picker |
30832d29 |
#1731 | fix: preserve OpenAI Responses tool history (#1731) | Deferred | deletes SanitizeOpenAIResponsesMiddleware in favor of replay-history preservation in utils/model.py; supersedes deferred #1718 (35659177) — triage the pair together against fork-diverged middleware + model.py | openai-sanitize |
3fcb27ce |
#1737 | fix: bound reviewer diff fetching (#1737) | Deferred | bounds reviewer diff fetching + new fetch_review_diff tool; reviewer.py fork-diverged — reconcile like #1713 (71e3b818) | reviewer-misc |
ef68c09b |
#1734 | fix: handle Slack DMs as mentions (#1734) | Deferred | treat Slack DMs as mentions; touches fork-diverged Slack webhook + e2e harness; post-reorg test paths | slack-tooling |
26828ff9 |
#1745 | chore: upgrade deepagents to 0.7.0a7 (#1745) | Deferred | deepagents 0.6.12 -> 0.7.0a7 alpha + [tool.uv] override-dependencies to bypass sandbox integrations <0.7.0 bound; fork is built on create_deep_agent — dedicated validation (unit + e2e) before adopting an alpha | deps |
ef0ed5af |
#1741 | fix: centralize SSRF-safe image fetches (#1741) | Deferred | security hardening — centralizes image fetches through url_safety.py (SSRF); fork has url_safety.py/multimodal.py (diverged) — hand-reconcile; untrusted-input surface: /sh-security-review on landing | ssrf-hardening |
136d28e6 |
#1733 | fix: disable todos by default (#1733) | Deferred | global write_todos/TodoListMiddleware default-off with OPEN_SWE_ENABLE_TODOS opt-in; edits fork-customized prompt.py — small hand-merge; supersedes #1725 | prompt-tweaks |
5077e2c7 |
#1735 | feat(open-swe): untagged two-party Slack replies + debounced interrupts (#1735) | Deferred | untagged two-party Slack replies + debounced interrupts (~620 LOC incl. e2e); rides fork-diverged Slack webhook stack; own branch + e2e validation | slack-untagged-replies |
8b26819f |
#1719 | fix: offload web tool results to sandbox (#1719) | Deferred | offloads large web tool results to sandbox files; touches fork-relevant web_search/http tools; check interplay with fork sandbox lifecycle | tool-offloading |
b7c5dbd6 |
#1747 | fix: simplify Slack run links (#1747) | Deferred | simplifies Slack run links; heavy churn on fork-diverged Slack context/prompt tests | slack-tooling |
81d544bc |
#1765 | feat: Expose more specific AGENTS.md context to Open SWE reviewer (#1765) | Deferred | Near-clean: agents_md.py helper + tests are zero-drift; reviewer.py hunk is small (~39 lines) but lands in the fork's heavily-diverged reviewer — hand-apply the scoped_agents_md wiring onto the fork's fetch_agents_md call sites (reviewer.py ~L404/445/1031). | reviewer-context |
8c8e58bc |
#1776 | feat: connect automations to Slack channels (#1776) | Deferred | Moderate reconcile: Slack-channel wiring for automations. Fork helpers exist (post_slack_top_level_message_with_ts, generate_thread_id_from_slack_thread, slack_id_for_login); completion.py (+233 drift) and schedules.py (+167) need hand-merge; UI automations feature present. Keep backend+UI+tests as one vertical. | automations-slack |
f0897479 |
#1778 | feat: surface context window usage in agents UI (#1778) | Deferred | Near-clean: context-window indicator UI is all new files (zero drift); options.py hunk must be re-keyed to the fork's Bedrock/Fireworks model map (fork model IDs differ from upstream's) — add context_window per fork entry rather than taking upstream values. | context-usage-ui |
2e8ff4b7 |
#1782 | chore: clarify shared response image guidance (#1782) | Deferred | Near-clean: docstring-only guidance in save_plan (shared responses persist Markdown only, never sandbox-local images — post screenshots directly to Slack) + 2 assertions in test_plan_review. Merges clean against fork. Batch with the next clean-port round. | feature/upstream-clean-batch-jul21 |
4ea2441a |
#1791 | fix: match embedded review description background (#1791) | Deferred | Near-clean UI-only: ReviewMainBody.tsx background match for the embedded review description; merges clean, zero fork drift. Batch with the next clean-port round. | feature/upstream-clean-batch-jul21 |
9bbd65d3 |
#1781 | fix: derive model context windows from LangChain profiles (#1781) | Deferred | Pair with deferred #1778 on context-usage-ui: derives model context windows from LangChain profiles. options.py conflicts — re-key to the fork's Bedrock/Fireworks model map (upstream IDs differ; verify LangChain profiles even resolve for the fork's Bedrock-style IDs, else keep static values). uv.lock bumps langchain to a profiles-capable version; test_model_fallback_resolution also conflicts. Port with/after #1778. | context-usage-ui |
75fb8b48 |
#1786 | Fix PR creation guard shell bypasses (#1786) | Deferred | SECURITY priority, clean merge: closes shell-bypass holes in PullRequestCreationGuardMiddleware (nested 'bash -c' expansion to depth 3, quoted-executable normalization) — a guard this fork actively wires. Port promptly; ALSO mirror the nested-shell expansion into the fork-only PullRequestVerdictGuardMiddleware (pr_verdict_guard.py), which shares the naive shlex approach and has the same bypass shape. | feature/upstream-clean-batch-jul21 |
32e81f29 |
#1788 | Fix: Fix Insecure Direct Object Reference in slack_start_new_thread.py (#1788) | Deferred | SECURITY priority, clean merge: IDOR fix — slack_start_new_thread now enforces the deployment allowlist (_is_repo_allowed) and per-user repo access (require_repo_access_for_user keyed on the parent thread's github_login) before dispatching a run against a different repo. Both helpers exist in the fork at the same paths; merges clean. Port promptly. | feature/upstream-clean-batch-jul21 |
ab85b372 |
#1764 | fix: add exc_info to swallowed exception in push re-review webhook (#1764) | Deferred | Trivial: adds exc_info=True to the swallowed exception log in process_github_push_event (webhooks/github.py). Merges clean. Batch with the next clean-port round. | feature/upstream-clean-batch-jul21 |
7312851d |
#1777 | feat: add explicit plan approval tool (#1777) | Deferred | Feature: explicit approve_plan tool + plan-mode exit. All deps exist in fork (plan_store PLAN_STATUS_APPROVED/SHARED, thread_api._user_owns_thread). Conflicts: prompt.py (fork prompt constants), server.py (tool/middleware wiring), check_message_queue.py (fork dashboard-handoff + mid-run injection drift), AGENTS.md. Hand re-key those four; keep the whole vertical (tool + plan_mode + thread_api + 4 test files) on one side. | |
e51abe14 |
#1754 | fix: skip oversized images before model calls (#1754) | Deferred | Desirable: 10MB image size cap + 'image omitted' text block before model calls, prevents oversized-image model failures. Conflicts only because the fork hardened fetch_image_block (SSRF redirect guard, host-only logging) — hunks are compatible; re-key the size check around the fork's guarded fetch and port impl + test together. | |
0ed560a5 |
#1779 | fix: settle review checks after run failures (#1779) | Deferred | Desirable: run-failure completion webhook now settles reviewer check runs left open when the graph dies (_settle_failed_reviewer_check; uses settle_review_check_run + review_check_pending_result, both already in the fork's review/publish.py from the #214/#215 ports). Conflict is fork drift in completion.py (failure-reply customizations); re-key the new helper in and port with its 159-line test. | |
bedc57b8 |
#1796 | fix: cap execute output by making SandboxBackendProxy a BaseSandbox (#1796) | Deferred | Real fix (unbounded execute stdout pulled into the worker → OOM risk) but inapplicable at the fork's deepagents==0.6.12: no capture-offload API exists (ExecuteOffloadResult / execute_accepts_timeout absent; FilesystemMiddleware has no _resolve_capture BaseSandbox gate), so the bug it fixes cannot occur yet. Re-triage together with deferred #1745 (deepagents 0.6.12→0.7.x bump) — landing that bump makes this fix required. Fork's SandboxBackendProxy has diverged (sync-era, bound_repo repo-binding, no reconnect machinery): hand-apply the execute_with_offload/aexecute_with_offload delegation onto the fork proxy rather than cherry-pick. |
Maintenance: after a git sync, add new dev..upstream/main SHAs as Untriaged (edit triage.jsonl) and bump "Last synced". A successful git cherry-pick -x auto-moves the row to Landed via the post-commit journal + make triage-reconcile.