Repository navigation
CLI: Update SDK to 454206ab83bc3c94fe8f8b1746a1c422b4681983 and add new commands/flags - #278
Merged
Merged
Conversation
SDK version bump only. A full enumeration of SDK methods vs CLI commands found no coverage gaps (config-registry endpoints are x-cli-skip). Tested: go build ./... (no new commands/flags to smoke test) Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
|
Review the following changes in direct dependencies. Learn more about Socket for GitHub.
|
- Bump github.com/kernel/kernel-go-sdk to 10c4031082d73b41180adeb54a722f89341907ff - Add --totp-algorithm, --totp-digits, --totp-period to `kernel credentials create` and `kernel credentials update` (CreateCredentialRequestParam / UpdateCredentialRequestParam TotpAlgorithm, TotpDigits, TotpPeriod) - Show TOTP algorithm/digits/period in credentials get/create output Tested: credentials create --totp-secret --totp-algorithm sha256 --totp-digits 8 --totp-period 60 (8-digit code returned, metadata shown in get), credentials totp-code, credentials update --totp-secret --totp-algorithm SHA512 --totp-digits 7 (verified in get -o json), invalid --totp-algorithm rejected, otpauth:// URI params take precedence over explicit flags, credentials delete cleanup. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Bumps kernel-go-sdk to v0.116.0 (c026e806a1bd). The SDK changes since 10c4031082d7 are release metadata only. A full enumeration of SDK methods against CLI commands found no coverage gaps. Config-registry endpoints are x-cli-skip. Tested: go build ./..., go test ./... (SDK version bump only, no new commands/flags) Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
- Bump github.com/kernel/kernel-go-sdk to 615cfaf0c5a80549cba3cd643c00b58c517f5475 - Add `webmcp_invoke` to `kernel vaults items invoke` (--params/--spec-file with browser_id, tool_ref, page_url, input, bindings, timeout_sec) for WebmcpInvokeVaultItemOperationRequestParam / VaultWebmcpBindingParam Tested: created vault + credential (populated via hosted collect form), vault-bound browser with a custom WebMCP tool on example.com; `vaults items invoke <vault> login webmcp_invoke --params ...` (table) and `--spec-file - -o json` both returned completed with vaulted values substituted; mismatched page_url returned HTTP 400 with guidance. Resources cleaned up. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
SDK bump only (v0.117.0 release; no API changes). Full enumeration of SDK methods vs CLI commands found no coverage gaps. Tested: go build, go test ./cmd/..., kernel browsers list Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
- Bump kernel-go-sdk to 0aa2b3c772eb7eff991947d84a8f0bbb3a879abe - Add --query to `kernel vaults list` (VaultListParams.Query); preserved in Next: hint - Forward explicit --since to InvocationFollowParams.Since in `kernel logs --invocation` Tested: vaults create/list --query (substring match, no match, -o json)/delete; logs <app> --invocation <id> [--since 1h]; go test ./... Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Update kernel-go-sdk to a1378239c479aeeb6d360e0719426ff0c9821da6. - vaults wallets create / cards create: accept --provider kernel (KernelWalletVaultItemSpecParam, KernelCardVaultItemSpecParam) - Reject provider config/tokens-file for Kernel wallets and updates for Kernel cards (unsupported per API) - Document KernelWalletSpec and KernelCardSpec in spec help - Show merchant URL, card last4, and network token last4 (masks.token_last4) in item output; keep token_last4 in filtered JSON Tested: vaults wallets create --provider kernel (request forwarded; staging API returned "provider configuration is unavailable"), vaults cards create --provider kernel (API validated kernel spec), client-side rejection of cards update/provider-config for kernel, items get output, vault cleanup. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Bump kernel-go-sdk to v0.118.0 (681b969). The SDK change is a release only (no API surface changes); full enumeration found no coverage gaps. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Bump kernel-go-sdk to 73817c0b9c4e93502daf9ecaa0bcf27e11e827bb, which adds the managed_auth credential vault item spec (ManagedAuthCredentialVaultItemSpecInputParam). - vaults credentials create accepts spec provider "managed_auth" with connection_id and optional description - Display-safe vault output keeps spec.connection_id and state.fields[*].type, and no longer rewrites managed_auth state fields with has_value - Table output shows the managed auth connection; help/README document the flow Tested: vaults credentials create --spec-file (provider managed_auth) against the live API, then vaults items get (table + json), vaults items list, missing connection_id validation, unknown connection (404), cleanup via items delete and vaults delete. go test ./... passes. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…9.0) Full enumeration of SDK methods vs CLI commands found no coverage gaps; the SDK change contains only release metadata (version/changelog). Tested: go build ./..., go vet ./..., go test ./... Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Bump kernel-go-sdk to acf8805 (Exa highlights / Perplexity context-size doc changes; reachable via search --request JSON). Fix compile errors left by the main merge: drop duplicated WebMCP params field, invoke dispatch, validation, and help/example text in favor of main's version. Full enumeration of SDK methods vs CLI commands found no new gaps. Tested: go build ./..., go vet ./..., go test ./..., vaults list --query -o json Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Bump kernel-go-sdk to f96f8682ead8a515498bb3363da9c68818dcde23. The SDK change only updates Kernel wallet documentation (wallets connect once the card is stored; network tokens are best-effort), so the KernelWalletSpec help text is updated to match. Full SDK/CLI enumeration found no coverage gaps. Tested: go build ./..., go test ./..., vaults wallets create --help Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…d --allowed-host - Bump github.com/kernel/kernel-go-sdk to be15dab89b9b8e2a23c27f8977255a69388ba8a4 - browsers create: add --allowed-host for BrowserNetworkConfigParam.AllowedHosts (egress allowlist, max 100 entries, create-only, conflicts with pool flags) - browsers create/get: show Allowed Hosts row Tested: - go test ./cmd/ passes (new TestBrowsersCreate_WithAllowedHosts) - browsers create --allowed-host example.com,*.example.com --start-url https://example.com: request reaches API, which returns feature_not_enabled (org flag gated) - browsers create / get: Allowed Hosts row renders '-' when unset; deleted - browsers create --pool-name x --allowed-host ...: flagged as pool conflict Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…0.0) SDK diff since 0f34ffb9d53a is a release-only bump (version/changelog), with no API surface changes. Full enumeration of api.md vs CLI commands found no coverage gaps (config-registry endpoints are x-cli-skip). Tested: go build ./..., go vet ./..., go test ./... (all pass) Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…host Update kernel-go-sdk to b71ecfcbaeecb29db2b273575df0e7d96e9533f6. New flags on `kernel browsers update` (BrowserUpdateParams.Network.AllowedHosts): - --allowed-host: replace a running session's egress allowlist - --clear-allowed-hosts: remove the allowlist (sends allowed_hosts: null) Datacenter proxy deprecation: the SDK dropped the datacenter proxy type. - `proxies create --type datacenter` still works (the API still accepts it) but prints a deprecation warning pointing to --type isp - Datacenter is removed from help text, examples, and the README - get/list/check still show the country for existing datacenter proxies Tested: - browsers create --allowed-host example.com, then browsers update --allowed-host example.com,*.wikipedia.org (get shows the new list), --allowed-host with --start-url, --clear-allowed-hosts (allowlist removed), -o json, client-side validation errors, and API validation errors - proxies create/get/list/delete --type isp - proxies create --type datacenter shows the warning and is accepted by API validation (provisioning fails upstream: the provider account is suspended) - go build, go vet, and go test ./... pass Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
… access requests
The SDK removed BrowserID from 1pw_create_access_request and
1pw_access_request_status (requests now go over the 1Password API; no
browser needed). Remove browser_id from the accepted params for both
operations, make --params optional for them, and update help text.
1pw_fill still requires browser_id.
Tested: go test ./...; vaults items invoke ... 1pw_create_access_request
(no params) and 1pw_access_request_status --params '{"timeout_seconds":5}'
reach the API (404 on nonexistent vault); browser_id is now rejected for
access requests; 1pw_fill still requires --params.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…1.0) SDK diff since aa4c1318242d contains only the version bump; full enumeration of api.md methods/params found no CLI coverage gaps. Tested: go build ./..., go test ./... Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…d pool proxy routes Browser pools now accept network.proxy_routes, so expose them: - browser-pools create: --proxy-route HOST[,HOST...]=PROXY (repeatable) - browser-pools update: --proxy-route and --clear-proxy-routes - browser-pools get: shows a Proxy Routes row - browsers create --proxy-route help/README: routes now apply to start_url Tested against the live API: browser-pools create --proxy-route (ID selector), get shows routes; update --proxy-route name:... with --private-host; update --clear-proxy-routes --private-host keeps private hosts; update --clear-private-hosts drops routes; conflicting flags rejected; pool deleted. go test ./... passes. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Bump kernel-go-sdk to 168ca3675c63 (feature-gated Korean ISP proxies). The SDK change is documentation-only; update `kernel proxies create` help text to list KR as a supported ISP country. Full enumeration of api.md methods vs CLI commands found no new coverage gaps (ConfigRegistry endpoints are x-cli-skip). Tested: proxies create --help shows KR; proxies create --type isp --country SG + delete succeed; --country KR returns an API internal error for the test org (feature-gated server-side). Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Bump kernel-go-sdk to 207ed0d79aba4410438fdb6def40838fca156504. The SDK change only updates doc comments on vault fill retry safety; the CLI already describes fill as safe to retry. Full enumeration found no coverage gaps. Tested: go build ./..., go test ./... Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Bump kernel-go-sdk from v0.121.0 to 454206ab83bc. The SDK diff adds no new methods or param fields; it adds captcha telemetry response fields (captcha_provider, task_kind, inferred) that pass through JSON output, plus doc changes. - proxies create: list KR as a supported ISP proxy country. - Fix TestOnePasswordOperationValidation after the main merge: access request operations no longer require --params, so replace the stale "requires --params" case with request tests for both access request operations without --params. Tested: go test ./...; proxies create --type isp --country KR (created, get shows country kr, deleted); browsers telemetry events --categories captcha on a fresh browser. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
There was a problem hiding this comment.
Cursor Bugbot has reviewed your changes using default effort and found 1 potential issue.
❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.
Reviewed by Cursor Bugbot for commit 6c1eb91. Configure here.
Main (#281) added the browsers playwright executors list/delete commands and --executor flag in cmd/browsers_playwright.go. The branch's earlier versions in cmd/browsers_playwright_executors.go redeclared the same symbols and broke the build, so drop them in favor of main's implementation. SDK stays at kernel-go-sdk 454206ab83bc3c94fe8f8b1746a1c422b4681983; the SDK diff is empty and a full api.md enumeration found no coverage gaps. Tested: go build ./..., go vet ./cmd/..., go test ./... all pass. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
rgarcia
approved these changes
Oct 9, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.

This PR updates the Go SDK to 454206ab83bc3c94fe8f8b1746a1c422b4681983 and adds CLI commands/flags for new SDK methods.
SDK Update
cmd/browsers_playwright_executors.go, and the copies redeclared main's symbols incmd/browsers_playwright.goand broke the build. That file and its test are removed, so main's implementation is the only one. The executor commands and flags are no longer part of this PR's diff.browsertelemetry.go. Captcha telemetry events gaininferred,captcha_provider, andtask_kindas output-only fields, andchallenge_idis now optional. The CLI prints telemetry events as JSON, so the new fields show up without code changes.api.mdis unchanged, and a full enumeration found no new methods or param fields.proxies createhelp, brokenTestOnePasswordOperationValidation, and removed two1pw_fillvalidation cases. All three are fixed in this PR.vaultitem.go: a plainfillnever submits the page, so it is safe to retry after a failure, anunknownoutcome, or a transport error. The CLI already says this (vaultFillUncertain, and the credentials help says "fill never submits and is safe to retry"). The 1Password flow still says not to retry1pw_fillautomatically, because that operation does submit.api.mdis unchanged, and a full enumeration found no new coverage gaps.kernel proxies createhelp (--typedescription and--countryflag) now lists KR.api.mdis unchanged, and a full enumeration found no new coverage gaps.network.proxy_routes. It also addscaptcha_providerandtask_kindto the captcha telemetry events (output only; the CLI prints telemetry events as JSON, so these show up without changes).api.mdis unchanged.internal/version.go. A full enumeration found no new coverage gaps.vaultitem.go.api.mdis unchanged.network.allowed_hostson a running browser. The SDK also drops thedatacenterproxy type.Coverage Analysis
This PR was generated by performing a full enumeration of SDK methods and CLI commands. Every method in api.md has a CLI command, except the
x-cli-skipendpoints (config-registry,/mpp/browsers,/auth/connections/{id}/exchange).New Flags
--proxy-routeonkernel browser-pools createandkernel browser-pools updateforBrowserPoolNewParams.Network.ProxyRoutes/BrowserPoolUpdateParams.Network.ProxyRoutes. It uses the sameHOST[,HOST...]=PROXYsyntax askernel browsers create --proxy-route.--clear-proxy-routesonkernel browser-pools update. It sendsnetwork: {proxy_routes: []}, plus any--private-hostentries given in the same command.kernel browser-pools getnow has a Proxy Routes row.networkobject. So--proxy-routeon its own drops an existing private-host override, and--clear-private-hostsalso drops the routes. The help text and README say so: pass both flags to keep both settings.--proxy-routehelp onbrowsers createand the README no longer say thatstart_urluses the top-level proxy. Routes now apply from the start of the session.--allowed-hostonkernel browsers updateforBrowserUpdateParams.Network.AllowedHosts(BrowserNetworkUpdateParam). It replaces the allowlist of a running session.--clear-allowed-hostsonkernel browsers update. It removes the allowlist by sendingallowed_hosts: null, which returns the session to unfiltered egress. The API rejects an empty list, so the CLI rejects--allowed-hostwith no entries and points to this flag.1Password access requests no longer take a browser
The SDK removed
BrowserIDfromOnePasswordRequestAccessVaultItemOperationRequestParamandVaultItemPerformOperationParamsBody1pwAccessRequestStatus. Without a change the CLI would not compile.kernel vaults items invoke <vault> <key> 1pw_create_access_requestaccepts onlygoal,reason, andkeywords.1pw_access_request_statusaccepts onlytimeout_seconds. Passingbrowser_idto either one now fails validation locally.--paramsis now optional for these two operations, because all of their fields are optional.1pw_fillstill requiresbrowser_idandpage_url.Datacenter proxy removal
This follows main (#286). The SDK no longer has the
datacenterproxy type.kernel proxies create --type datacenternow fails as an invalid type. It no longer prints a deprecation warning and passes the request through.datacenteris removed from the--typehelp, from the examples, and from the README. The README examples now useisp.proxies get,list, andcheckhandle only the remaining proxy types.--allowed-hosthelp onbrowsers createno longer says "Create-only".Testing
go build ./...,go vet ./cmd/..., andgo test ./...pass after removing the duplicate files. No new commands or flags, so there was nothing to smoke-test.go build ./...,go vet ./cmd/, andgo test ./...pass. Smoke-tested against the production API:proxies create --type isp --country KRsucceeded.proxies getshowedCountry: kr, and the proxy was then deleted.browsers telemetry events <id> --categories captcharan without errors on a fresh browser, which was deleted afterward.go build ./...,go vet ./cmd/..., andgo test ./...pass. No new commands or flags, so there was nothing to smoke-test.go build ./...andgo test ./cmd/proxies/...pass.proxies create --helplists KR.proxies create --type isp --country SGfollowed by delete works against production.--country KRcurrently returnsInternal_error: failed to apply proxy configfor the test org, which is expected while the feature is gated server-side. No proxy was left behind.go test ./...passes. New unit tests cover pool create/update with routes, clearing routes (with and without--private-host), the conflicting-flag check, and the Get row. Smoke-tested against the production API on a temporary pool, which was deleted afterward:browser-pools create --proxy-route 'api.ipify.org,*.ipify.org=<id>'worked, andgetshowed the routes.update --proxy-route example.com=name:us-residential-test --private-host 10.0.0.0/8set both. The API resolved the name to an ID.update --clear-proxy-routes --private-host 10.0.0.0/8removed the routes and kept the private hosts.update --proxy-route ...on its own replaced the network config, dropping the private hosts.--clear-private-hoststhen removed everything.--proxy-routetogether with--clear-proxy-routesis rejected.go build ./...andgo test ./...pass. No new commands or flags, so there was nothing to smoke-test.go test ./...passes, with unit tests updated for request bodies withoutbrowser_idand for invoking with no--params. Smoke-tested against the production API:1pw_create_access_requestwith no params and1pw_access_request_status --params '{"timeout_seconds":5}'both reach the API (404 for a nonexistent vault). Passingbrowser_idis rejected locally, and1pw_fillstill requires--params. A full approval round trip was not tested, because it needs a connected 1Password account.go build ./...,go vet ./...andgo test ./...pass. New unit tests cover forwarding allowed hosts, sending null on clear, leavingnetworkout of unrelated updates, and validation (set+clear, empty entries, more than 100 entries).browsers create --allowed-host example.com, thenbrowsers update --allowed-host example.com,*.wikipedia.org.browsers getshows the new list.--allowed-host en.wikipedia.org --start-url https://en.wikipedia.orgworked in a single update.--clear-allowed-hostsremoved the allowlist (networkno longer hasallowed_hosts).-o jsonoutput is correct.hostnames must not include a URL scheme.proxies create/get/list/delete --type ispwork.proxies create --type datacentershows the warning and passes API validation. Provisioning then fails upstream with "Account is suspended" from the datacenter provider, which matches the deprecation.Triggered by: kernel/kernel-go-sdk@454206a
Reviewer: @kernel-internal[bot] (previous bumps: @rgarcia)
🤖 Generated with Claude Code
Note
Medium Risk
Changes touch egress network policy (allowlists, pool proxy routes) and vault credential/payment flows; mistakes could block browser traffic or misconfigure pools, though behavior is mostly API-aligned with local validation.
Overview
Bumps kernel-go-sdk and wires several new API surfaces into the CLI, with README updates to match.
Browsers: Adds
--allowed-hostat create and--allowed-host/--clear-allowed-hostson update for Kernel-managed egress allowlists (proxy v3, not pools). Create/update/get output shows Allowed Hosts; pool acquire rejects allowlists.--proxy-routehelp now says routes apply from session start (including setup traffic).Browser pools: Adds
--proxy-routeon create/update and--clear-proxy-routeson update, with display on get. Network updates replace the wholenetworkobject—docs and validation call out pairing--private-hostwith route changes.Vaults:
vaults list --query;managed_authcredential specs viaconnection_id;kernelprovider for wallets/cards (no card update). Output/help covers managed auth and Kernel card fields.Other:
us-westin region docs; ISP proxies add KR; credentials show TOTP metadata;logsforwards--sinceonly when set; 1Password1pw_create_access_request/1pw_access_request_statusallow empty params (no browser).Reviewed by Cursor Bugbot for commit 3f864d3. Bugbot is set up for automated code reviews on this repo. Configure here.