open-swe/agent
seahaven-openswe[bot] e0828cfaf6
Some checks are pending
CI / Lint (push) Waiting to run
CI / Format check (push) Waiting to run
CI / Unit tests (push) Waiting to run
CI / Playwright E2E (push) Waiting to run
CI / Docker build smoke (push) Waiting to run
CI / Triage ledger up to date (push) Waiting to run
CI / ui bun.lock in sync (push) Waiting to run
chore: cherry-pick deferred reviewer-misc upstream commits (#127)
* feat: add PR trace resolution (#1612)

* feat: add PR trace resolution

Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>

* fix: inject reviewer trace context as JSON

Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>

* fix: address review on PR trace resolution

Use the documented LangSmith metadata filter syntax
(and(eq(metadata_key,...), eq(metadata_value,...))) instead of
has(metadata, '{...}'), which does not match runs — _list_thread_runs
was silently returning nothing. Bound full-text searches to a 90-day
window so they don't hit LangSmith's large-window rate limit.

Also folds in the best-effort branch->head-sha resolver (dropping the
weighted scoring/threshold + repo/file evidence + GitHub hydration),
sandbox JSON injection, and the admin "Resolve trace" dry-run endpoint.

The IDOR findings are moot: resolve_pr_to_threads/summarize_agent_session
were removed; resolution now runs deterministically from the trusted run
config with no model-controlled pr_url or thread_id.

* fix: scope branch trace search to the repo

Branch names like fix-tests aren't unique across repos (or older PRs) in
a shared tracing project, so an unscoped branch hit could resolve to an
unrelated thread and write its runs into the reviewer sandbox. Require
the repo slug to co-occur with the branch in matched runs; the full head
SHA stays unscoped since it is globally unique. Addresses open-swe review
on PR #1612.

---------

Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>
(cherry picked from commit 69148f54f5)

* fix: post reviewer resolution notes verbatim (#1624)

* fix: post reviewer resolution notes verbatim

Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>

* fix: stabilize dashboard follow-up e2e

Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>

* fix: preserve dashboard attribution in e2e

Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>

* fix: make e2e attribution marker durable

Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>

* fix: only echo found e2e attribution

Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>

* fix: check live dashboard attribution in e2e

Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>

---------

Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>
(cherry picked from commit 5da3d0c657)

* chore: opt-in tracemalloc to attribute unclosed aiohttp sessions (#1657)

Prod logs show bursts of 'Unclosed client session' (aiohttp), leaking
fds + memory, but the warning omits the allocation site. When
DEBUG_TRACEMALLOC is set, start tracemalloc at webapp import so aiohttp
appends an 'Object allocated at' traceback naming the exact source.
Inert when the env var is unset.

Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>
(cherry picked from commit 320bb39ab1f5cd7a2acdac52c7b375854334176c)

* feat: add PR review link route (#1698)

* feat: add PR review link route

Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>

* fix: avoid duplicate review shortcut runs

Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>

---------

Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>
(cherry picked from commit 52fe29168814d7936ee6612b9c81f33339bb05b0)

* style: clean up leftover blank lines from cherry-pick conflict resolution

* fix(e2e): drop duplicate _ATTRIBUTION_RE from cherry-pick

The reviewer-misc pick re-added _ATTRIBUTION_RE next to _latest_attribution,
but the constant was already defined at module top (line 57, alongside
_PLAN_URL_RE) via the earlier #81 sync. Remove the redundant redefinition;
_latest_attribution resolves the surviving top-level constant.

---------

Co-authored-by: Johannes du Plessis <johannes@langchain.dev>
Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>
Co-authored-by: seahaven-openswe[bot] <296972425+seahaven-openswe[bot]@users.noreply.github.com>
Co-authored-by: Adam Moussa <166072409+amoussa1229@users.noreply.github.com>
Co-authored-by: Adam Moussa <adam@seahavenind.com>
2026-07-08 17:28:21 -04:00
..
dashboard chore: cherry-pick deferred reviewer-misc upstream commits (#127) 2026-07-08 17:28:21 -04:00
integrations chore: sync upstream/main, defer #1621 modular webhooks (#81) 2026-06-30 16:45:19 -04:00
middleware feat: add Slack reaction tool (#1650) 2026-07-03 15:38:56 -04:00
skills feat: outcomes dataset + bootstrap/continual split via skills (#1365) 2026-06-01 13:25:12 -07:00
tools feat: add Slack reaction tool (#1650) 2026-07-03 15:38:56 -04:00
utils fix(security): fence and neutralize untrusted Slack channel description in agent prompt 2026-07-03 16:08:35 -04:00
webhooks fix(security): fence and neutralize untrusted Slack channel description in agent prompt 2026-07-03 16:08:35 -04:00
analyzer.py feat: route graphs to separate LangSmith tracing projects (#1508) 2026-06-11 17:57:16 -07:00
chat.py feat: chat with your PR on the review page (#1534) 2026-06-15 17:17:30 -07:00
ci_autofix.py refactor: adopt modular webhook architecture (#1621) + port fork customizations (#85) 2026-06-30 18:46:46 -04:00
ci_monitor.py feat: CI auto-fix and PR babysitting for agent PRs (#1530) 2026-06-15 13:53:50 -07:00
completion.py fix: surface Slack thread errors (#1627) 2026-07-03 15:50:30 -04:00
dispatch.py refactor: adopt modular webhook architecture (#1621) + port fork customizations (#85) 2026-06-30 18:46:46 -04:00
encryption.py feat: support TOKEN_ENCRYPTION_KEY rotation via MultiFernet [closes AB-2323] (#1275) 2026-05-08 14:29:23 -07:00
prompt.py feat: add Slack reaction tool (#1650) 2026-07-03 15:38:56 -04:00
reconcile.py refactor: adopt modular webhook architecture (#1621) + port fork customizations (#85) 2026-06-30 18:46:46 -04:00
review_style_collector.py feat: PR review page (#1495) 2026-06-11 16:11:10 -07:00
review_style_guidance.py feat: tune reviewer for precision — web/wiki tools + recalibrated prompt (#1312) 2026-05-20 18:35:00 +00:00
reviewer.py chore: sync upstream/main, defer #1621 modular webhooks (#81) 2026-06-30 16:45:19 -04:00
reviewer_diff.py fix: reviewer reviews full diff; fix review UI scroll + dark-mode composer (#1575) 2026-06-18 19:24:52 -07:00
reviewer_eval_store.py feat: Run reviewer eval in a GitHub Action; dashboard becomes read-only (#1556) 2026-06-16 19:38:36 -07:00
reviewer_findings.py fix: Reviews tab — anchored finding card, paginated list, file tree truncation (#1507) 2026-06-11 17:52:20 -07:00
reviewer_groups.py fix: Simplify review explanation: full-width, plain prose, no diff links (#1547) 2026-06-16 15:32:24 -07:00
reviewer_publish.py chore: sync upstream/main, defer #1621 modular webhooks (#81) 2026-06-30 16:45:19 -04:00
reviewer_reconcile.py chore: sync upstream/main, defer #1621 modular webhooks (#81) 2026-06-30 16:45:19 -04:00
reviewer_trace_context.py chore: sync upstream/main, defer #1621 modular webhooks (#81) 2026-06-30 16:45:19 -04:00
scheduler.py refactor: adopt modular webhook architecture (#1621) + port fork customizations (#85) 2026-06-30 18:46:46 -04:00
server.py feat: add Slack reaction tool (#1650) 2026-07-03 15:38:56 -04:00
webapp.py chore: cherry-pick deferred reviewer-misc upstream commits (#127) 2026-07-08 17:28:21 -04:00