dependabot[bot]
557157c2d6
build(deps): bump docker/login-action from 3 to 4 ( #1124 )
...
Integrated into release/v3.6.2
2026-04-11 09:44:30 -03:00
dependabot[bot]
0bae35d387
build(deps): bump peter-evans/dockerhub-description from 4 to 5 ( #1123 )
...
Integrated into release/v3.6.2
2026-04-11 09:44:27 -03:00
dependabot[bot]
c7062bc560
build(deps): bump actions/github-script from 8 to 9 ( #1122 )
...
Integrated into release/v3.6.2
2026-04-11 09:44:24 -03:00
dependabot[bot]
a344352365
build(deps): bump actions/cache from 4 to 5 ( #1121 )
...
Integrated into release/v3.6.2
2026-04-11 09:44:21 -03:00
dependabot[bot]
33d86ad3b5
build(deps): bump actions/upload-artifact from 4 to 7 ( #1120 )
...
Integrated into release/v3.6.2
2026-04-11 09:44:18 -03:00
diegosouzapw
388e0fe845
fix(api): harden provider sync and stream escaping
...
Escape backslashes before injecting combo stream tags so tagged SSE
payloads remain valid JSON, and call the provider models handler
directly during sync to avoid internal fetch SSRF warnings.
Also restore crypto UUID generation for Gemini request translation,
tighten dashboard error sanitization, and update tests to use stricter
URL matching and UUID-based fixture keys.
2026-04-07 12:14:34 -03:00
diegosouzapw
726673f926
ci: enable playwright sharding and native test runner parallelization
2026-04-07 01:05:17 -03:00
diegosouzapw
b0683f77c2
ci: increase E2E timeout to 45min for 16 sequential spec files
2026-04-06 23:53:48 -03:00
diegosouzapw
7aceabed07
ci: add timeout-minutes to all test jobs to prevent indefinite hangs
2026-04-06 21:37:55 -03:00
diegosouzapw
78db90e4bf
chore: optimize local git hooks and fix T11 any budget strictness
...
- Removed the expensive (40s+) `npm run test:unit` step from the `pre-commit` hook
- Created `.husky/pre-push` to run the unit test suite before pushing rather than per commit
- This prevents spurious async teardown errors from local test runners from blocking fast commits
- Replaced an explicit `any` cast with `Record<string, unknown> | undefined` in `chatCore.ts` to pass the `check:any-budget:t11` strict checker which enforces a budget of 0
2026-04-06 00:29:54 -03:00
diegosouzapw
592ca9b5c4
fix: remove hardcoded localhost default arg from GET /api/keys, unify coverage to single coverage/ dir, fix test to pass explicit Request
...
- Remove `new Request('http://localhost/api/keys ')` default arg from GET handler in src/app/api/keys/route.ts (line 26)
- Fix api-key-reveal-route.test.mjs to pass explicit Request instead of calling GET() with no args
- Add --output-dir coverage to all c8 scripts in package.json
- Add coverage.reportsDirectory: 'coverage' to vitest.config.ts and vitest.mcp.config.ts
- Fix CHANGELOG.md structure (# Changelog + [Unreleased] to top)
- Remove 30+ stale coverage-* directories from project root
- Coverage: Statements 78.76% | Branches 72.75% | Functions 80.93% | Lines 78.76% (all thresholds passed)
2026-04-05 23:21:08 -03:00
dependabot[bot]
185d53da6a
build(deps): bump actions/setup-node from 4 to 6 ( #964 )
...
Bumps [actions/setup-node](https://github.com/actions/setup-node ) from 4 to 6.
- [Release notes](https://github.com/actions/setup-node/releases )
- [Commits](https://github.com/actions/setup-node/compare/v4...v6 )
---
updated-dependencies:
- dependency-name: actions/setup-node
dependency-version: '6'
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-04-03 19:18:49 -03:00
dependabot[bot]
07c1071c36
build(deps): bump docker/setup-buildx-action from 3 to 4 ( #965 )
...
Bumps [docker/setup-buildx-action](https://github.com/docker/setup-buildx-action ) from 3 to 4.
- [Release notes](https://github.com/docker/setup-buildx-action/releases )
- [Commits](https://github.com/docker/setup-buildx-action/compare/v3...v4 )
---
updated-dependencies:
- dependency-name: docker/setup-buildx-action
dependency-version: '4'
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-04-03 18:48:46 -03:00
dependabot[bot]
a9d0453811
build(deps): bump actions/download-artifact from 4 to 8 ( #962 )
...
Bumps [actions/download-artifact](https://github.com/actions/download-artifact ) from 4 to 8.
- [Release notes](https://github.com/actions/download-artifact/releases )
- [Commits](https://github.com/actions/download-artifact/compare/v4...v8 )
---
updated-dependencies:
- dependency-name: actions/download-artifact
dependency-version: '8'
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-04-03 18:48:25 -03:00
dependabot[bot]
54ef217de4
build(deps): bump actions/checkout from 4 to 6 ( #963 )
...
Bumps [actions/checkout](https://github.com/actions/checkout ) from 4 to 6.
- [Release notes](https://github.com/actions/checkout/releases )
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md )
- [Commits](https://github.com/actions/checkout/compare/v4...v6 )
---
updated-dependencies:
- dependency-name: actions/checkout
dependency-version: '6'
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-04-03 18:48:12 -03:00
dependabot[bot]
0ebfa89783
build(deps): bump docker/setup-qemu-action from 3 to 4 ( #961 )
...
Bumps [docker/setup-qemu-action](https://github.com/docker/setup-qemu-action ) from 3 to 4.
- [Release notes](https://github.com/docker/setup-qemu-action/releases )
- [Commits](https://github.com/docker/setup-qemu-action/compare/v3...v4 )
---
updated-dependencies:
- dependency-name: docker/setup-qemu-action
dependency-version: '4'
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-04-03 18:48:03 -03:00
diegosouzapw
4b0bcf4464
chore(security): remove legacy sync workflow and enforce lodash-es replacement for npm audit passing
2026-04-02 10:47:38 -03:00
diegosouzapw
763da979a8
fix(ci): fix any-budget validation by using typecast correctly and adjust npm audit step so it never fails the workflow
2026-04-02 09:36:17 -03:00
diegosouzapw
8c58f7a04e
test(ci): fix t06 validation error by adding Zod validation to memory/skills routes and allow security audit failure
2026-04-02 09:26:09 -03:00
zenobit
2c63e0fdd6
chore(ci): improve and show CI summary
2026-04-01 20:47:30 -03:00
zenobit
895e3931bd
fix(ci): i18n validation
2026-04-01 01:14:17 +02:00
zenobit
a987425f4a
fix(ci): Update action/setup-python@v6.2.0
2026-04-01 01:14:17 +02:00
zenobit
971d2dfc31
fix(ci): Fix language list
2026-04-01 01:14:17 +02:00
zenobit
5bb99f941c
fix(ci): fix jq command with -R raw input flag
...
- Also fix quick_check to only fail on missing keys (not untranslated)
- Use compact JSON for GITHUB_OUTPUT
2026-04-01 01:14:17 +02:00
diegosouzapw
7a37c79ebc
ci: fix pipeline errors and enforce route lint validatation
2026-03-30 17:54:44 -03:00
diegosouzapw
5ad687c6d8
fix(ui/ci): use ProviderIcon for Provider header breadcrumbs and add permissions to electron-release.yml ( #745 , #761 )
...
- Use ProviderIcon for internal .png paths solving SVG provider 404 images (#745 ).
- Add id-token: write and packages: write permissions to .github/workflows/electron-release.yml to fix permissions denied failure when calling the reusable workflow npm-publish.yml (#761 ).
- Fix tests and ESM resolution for autoUpdate.ts override logic.
2026-03-30 07:38:30 -03:00
diegosouzapw
d69e7ec850
chore(release): v3.3.3 — Core UI bugfixes and AutoUpdate repairs
2026-03-29 21:18:07 -03:00
tombii
3571421a0e
fix(ci): push sync to correct fork repo
2026-03-29 10:45:21 +02:00
tombii
aed80f3e4f
ci: add upstream sync workflow
2026-03-29 10:44:45 +02:00
Diego Souza
500bfdf588
ci: authorize packages write scopes for github packages
2026-03-29 02:06:28 -03:00
Diego Souza
bf76da3222
ci: enable ghcr build on main
2026-03-28 23:25:04 -03:00
Diego Souza
6ec8745d2e
ci: add GitHub Packages publish configuration for GHCR and NPM
2026-03-28 22:04:02 -03:00
diegosouzapw
9248ab4dfd
fix(ci): route validation, CodeQL alerts, Docker workflow
...
- Add Zod schemas + validateBody() to 5 routes missing validation:
model-combo-mappings (POST, PUT), webhooks (POST, PUT), openapi/try (POST)
- Fix 6 polynomial-redos CodeQL alerts in provider.ts and chatCore.ts
by replacing (?:^|/) alternation patterns with segment-based matching
- Fix insecure-randomness in acp/manager.ts (crypto.randomUUID)
- Fix shell-command-injection in prepublish.mjs (JSON.stringify)
- Upgrade docker/setup-buildx-action from v3 to v4 (Node.js 20 deprecation)
CI check:route-validation:t06 PASS (176/176 routes validated)
Tests: 926/926 pass
2026-03-24 16:08:02 -03:00
jay77721
f1be3e6bb0
fix(npm): link electron-release to npm-publish via workflow_call
...
- Add workflow_call trigger to npm-publish.yml for direct cross-workflow invocation
- Add publish-npm job to electron-release.yml that calls npm-publish after release
- Add dist-tag support: prerelease versions auto-get 'next' tag, stable gets 'latest'
- Add v-prefix stripping for robust version handling
- Fixes issue where GitHub releases created by bots don't reliably trigger npm-publish
- Refs #579
2026-03-24 21:52:34 +08:00
Diego Rodrigues de Sa e Souza
7c34c178cd
Merge pull request #503 from diegosouzapw/dependabot/github_actions/docker/login-action-4
...
chore(deps): bump docker/login-action from 3 to 4
2026-03-20 16:07:00 -03:00
Diego Rodrigues de Sa e Souza
ac7cb41483
Merge pull request #502 from diegosouzapw/dependabot/github_actions/docker/setup-qemu-action-4
...
chore(deps): bump docker/setup-qemu-action from 3 to 4
2026-03-20 16:06:58 -03:00
Diego Rodrigues de Sa e Souza
0ab388b88e
Merge pull request #501 from diegosouzapw/dependabot/github_actions/peter-evans/dockerhub-description-5
...
chore(deps): bump peter-evans/dockerhub-description from 4 to 5
2026-03-20 16:06:56 -03:00
Diego Rodrigues de Sa e Souza
54448902f1
Merge pull request #500 from diegosouzapw/dependabot/github_actions/actions/checkout-6
...
chore(deps): bump actions/checkout from 4 to 6
2026-03-20 16:06:53 -03:00
dependabot[bot]
ee0afa1eec
chore(deps): bump docker/login-action from 3 to 4
...
Bumps [docker/login-action](https://github.com/docker/login-action ) from 3 to 4.
- [Release notes](https://github.com/docker/login-action/releases )
- [Commits](https://github.com/docker/login-action/compare/v3...v4 )
---
updated-dependencies:
- dependency-name: docker/login-action
dependency-version: '4'
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-03-20 18:26:04 +00:00
dependabot[bot]
83cdd0dafe
chore(deps): bump docker/setup-qemu-action from 3 to 4
...
Bumps [docker/setup-qemu-action](https://github.com/docker/setup-qemu-action ) from 3 to 4.
- [Release notes](https://github.com/docker/setup-qemu-action/releases )
- [Commits](https://github.com/docker/setup-qemu-action/compare/v3...v4 )
---
updated-dependencies:
- dependency-name: docker/setup-qemu-action
dependency-version: '4'
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-03-20 18:25:58 +00:00
dependabot[bot]
5be025f1d1
chore(deps): bump peter-evans/dockerhub-description from 4 to 5
...
Bumps [peter-evans/dockerhub-description](https://github.com/peter-evans/dockerhub-description ) from 4 to 5.
- [Release notes](https://github.com/peter-evans/dockerhub-description/releases )
- [Commits](https://github.com/peter-evans/dockerhub-description/compare/v4...v5 )
---
updated-dependencies:
- dependency-name: peter-evans/dockerhub-description
dependency-version: '5'
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-03-20 18:25:55 +00:00
dependabot[bot]
c651842ea1
chore(deps): bump actions/checkout from 4 to 6
...
Bumps [actions/checkout](https://github.com/actions/checkout ) from 4 to 6.
- [Release notes](https://github.com/actions/checkout/releases )
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md )
- [Commits](https://github.com/actions/checkout/compare/v4...v6 )
---
updated-dependencies:
- dependency-name: actions/checkout
dependency-version: '6'
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-03-20 18:25:51 +00:00
dependabot[bot]
423abe6788
chore(deps): bump docker/build-push-action from 6 to 7
...
Bumps [docker/build-push-action](https://github.com/docker/build-push-action ) from 6 to 7.
- [Release notes](https://github.com/docker/build-push-action/releases )
- [Commits](https://github.com/docker/build-push-action/compare/v6...v7 )
---
updated-dependencies:
- dependency-name: docker/build-push-action
dependency-version: '7'
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-03-20 18:25:45 +00:00
diegosouzapw
d0fb4576a8
ci: add workflow_dispatch to npm-publish, fix version sync for manual triggers
2026-03-15 20:20:44 -03:00
diegosouzapw
df1105d0c6
fix: add workflow_dispatch to docker-publish, update action versions ( #392 )
2026-03-15 20:06:49 -03:00
dependabot[bot]
dfbbbeb1b4
chore(deps): bump docker/setup-buildx-action from 3 to 4 ( #343 )
...
* chore(deps): bump docker/setup-buildx-action from 3 to 4
Bumps [docker/setup-buildx-action](https://github.com/docker/setup-buildx-action ) from 3 to 4.
- [Release notes](https://github.com/docker/setup-buildx-action/releases )
- [Commits](https://github.com/docker/setup-buildx-action/compare/v3...v4 )
---
updated-dependencies:
- dependency-name: docker/setup-buildx-action
dependency-version: '4'
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com >
* Initial plan
---------
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: openai-code-agent[bot] <242516109+Codex@users.noreply.github.com >
Co-authored-by: Diego Rodrigues de Sa e Souza <8016841+diegosouzapw@users.noreply.github.com >
2026-03-14 10:56:20 -03:00
dependabot[bot]
7f3ffd935e
chore(deps): bump docker/setup-qemu-action from 3 to 4 ( #342 )
...
Bumps [docker/setup-qemu-action](https://github.com/docker/setup-qemu-action ) from 3 to 4.
- [Release notes](https://github.com/docker/setup-qemu-action/releases )
- [Commits](https://github.com/docker/setup-qemu-action/compare/v3...v4 )
---
updated-dependencies:
- dependency-name: docker/setup-qemu-action
dependency-version: '4'
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-03-14 10:56:18 -03:00
diegosouzapw
6d672ab09a
fix(ci): docs-sync, electron linux fpm, docker cache env
...
CI Lint fixes:
- docs/openapi.yaml: bump version 2.2.0 → 2.2.3 (was out of sync with package.json)
- CHANGELOG.md: add '## [Unreleased]' as first section (required by check:docs-sync)
Electron Linux fix:
- electron-release.yml: add 'gem install fpm' step for Linux builds
fpm is required by electron-builder to package .deb installers;
ubuntu-latest runners don't have it pre-installed
Docker publish:
- docker-publish.yml: add DOCKER_BUILDKIT_INLINE_CACHE env; prev 502 was
a transient Docker Hub network error, no code change needed
2026-03-10 14:31:48 -03:00
Diego Rodrigues de Sa e Souza
ce560ebe9d
fix: resolve issues #273 , #276 , #277 — image routing, models route, missing-key error ( #282 )
...
Squash merge PR #282 : bug fixes for #273 (Gemini image routing), #276 (Ollama Cloud models), #277 (missing apiKey error), lint fix, and all security code-scanning patches.
2026-03-10 09:48:50 -03:00
diegosouzapw
f900a81ec9
fix(ci): use npm install in npm-publish to survive lock file drift on old tags
...
npm ci fails if the tag commit's lock file is out of sync (as happened
with v2.2.0 when @swc/helpers was missing). npm install is safe here
because the publish workflow only needs deps to run prepublish.mjs —
strict lock enforcement is not required for the publish step.
2026-03-10 09:48:35 -03:00