Skip to content

chore: release - merge dev into main - #1556

Merged
zbigniewsobiecki merged 13 commits into
mainfrom
dev
Sep 21, 2026
Merged

zbigniewsobiecki merged 13 commits into
mainfrom
dev

Conversation

@zbigniewsobiecki

Copy link
Copy Markdown
Member

Automated release PR created by the release workflow.

Commits (13):

a6451fc5 Merge pull request #1554 from mongrel-intelligence/feat/codex-0.155.1-gpt-6-astra
e4aabcaa Merge pull request #1553 from mongrel-intelligence/fix/codex-resume-arg-order
b0a8c5ff feat(codex): pin Codex CLI 0.155.1 and add GPT-6 Astra
b98c10d6 fix(deps): bump js-yaml to 4.3.2 to clear high-severity audit failure
40888708 fix(codex): put exec options before the resume subcommand
aee88e20 fix(router): authenticate worker-image pulls against private registries (#1539)
fcc2823f chore(deps): bump hono from 4.12.32 to 4.13.4 (#1537)
50e39ecb chore(deps): bump fast-uri from 3.1.4 to 3.1.5 (#1527)
ff90435d chore(deps): bump undici from 7.28.0 to 7.29.0 (#1526)
dcf1833e Merge pull request #1548 from mongrel-intelligence/docs/slim-claude-md-areas
e6ce010a docs: correct instruction context scope
e76e5bcb docs: slim CLAUDE.md to a 76-line core, move area rules to docs/areas, add CI budget guards
6d64c8b6 cleanup

zbigniewsobiecki and others added 13 commits August 25, 2026 13:28
…, add CI budget guards

CLAUDE.md is cat-injected into every CASCADE worker prompt (inline only under
CONTEXT_OFFLOAD_CONFIG.inlineThreshold) and loaded into every Claude Code session.
It was 217 lines plus 95 KB of @imports, 89% of the worker inline cliff, and mostly
duplicated docs/architecture or spec/incident narrative; the Git hooks section was wrong.

- CLAUDE.md: 76 lines / ~1.7k tokens - commands, gotchas (corrected lefthook contract),
  hard invariants, env pointer, area pointer table, placement rule; zero @imports
- docs/areas/{pm-integrations,router-dispatch,agents,backends}.md: imperatives + links
- only-home facts placed first in 01-services, 03-trigger-system, 10-resilience,
  tests/README.md and .env.example before their CLAUDE.md copies were removed
- tests/unit/architecture-docs.test.ts: line/token budget derived from the real
  inlineThreshold, no-@import, no-narrative, area-doc shape + linkage guards;
  tests/unit/repo-hygiene.test.ts pins the shared root/web Zod major
- src/integrations/README.md: spec-changelog tables removed, duplicate contract table
  merged; JIRA authType now has one home (08-config-credentials points at it)
- SECURITY/README/CONTRIBUTING/ARCHITECTURE/.env.example pointers fixed; CHANGELOG entry
- documentation-maintenance partial re-routed (run npm run db:seed-prompts after deploy)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…d-areas

docs: slim CLAUDE.md to a 76-line core + pointer-loaded docs/areas, with CI budget guards
Bumps [undici](https://github.com/nodejs/undici) from 7.28.0 to 7.29.0.
- [Release notes](https://github.com/nodejs/undici/releases)
- [Commits](nodejs/undici@v7.28.0...v7.29.0)

---
updated-dependencies:
- dependency-name: undici
  dependency-version: 7.29.0
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [fast-uri](https://github.com/fastify/fast-uri) from 3.1.4 to 3.1.5.
- [Release notes](https://github.com/fastify/fast-uri/releases)
- [Commits](fastify/fast-uri@v3.1.4...v3.1.5)

---
updated-dependencies:
- dependency-name: fast-uri
  dependency-version: 3.1.5
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [hono](https://github.com/honojs/hono) from 4.12.32 to 4.13.4.
- [Release notes](https://github.com/honojs/hono/releases)
- [Commits](honojs/hono@v4.12.32...v4.13.4)

---
updated-dependencies:
- dependency-name: hono
  dependency-version: 4.13.1
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
…es (#1539)

* fix(router): authenticate worker-image pulls against private registries

All router-side registry pulls (spawn self-heal, worker-image validation,
Dockerfile-build base refresh) funnel through pullImageOnce, whose dockerode
pull sends no credentials — the daemon has no ambient login and never reads
~/.docker/config.json. Anonymous pulls 401 on private registries, so a host
image prune that removed the worker image turned every spawn into
`Head .../manifests/latest: unauthorized` (verified live 2026-08-20).

New optional env: WORKER_IMAGE_REGISTRY_USERNAME / _PASSWORD (+ _SERVER
override; host otherwise derived from the image ref, Docker Hub as the
no-host fallback). Unset preserves anonymous pulls; partial credentials warn
and stay anonymous.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* fix(deps): bump js-yaml to 4.3.1 to clear high-severity audit failure

CI's `npm audit --omit=dev --audit-level=high` step began failing on the
newly disclosed CVE-2026-59870 (GHSA-5p4m-2wfm-xmqj): quadratic CPU
consumption in js-yaml's !!omap resolution, affecting >=4.0.0 <4.3.1.
js-yaml is a direct production dependency; the 4.3.1 patch release fixes
it and all transitive consumers (llmist, @llmist/cli) dedupe to it.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

---------

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
Co-authored-by: Cascade Bot <bot@cascade.dev>
Continuation turns resumed a Codex thread with
`codex exec resume <id> ... -C <dir> ... -s <mode> ...`. In the pinned CLI
`-C`/`--cd` and `-s`/`--sandbox` are parent-only `exec` options, so
clap rejected the resume with "unexpected argument '-C'" before the model
was reached and the run was recorded as failed. Emit every option first and
the subcommand plus stdin marker last: `codex exec <options> resume <id> -`.

Verified the generated argv against @openai/codex@0.145.0: it now fails only
at thread lookup ("no rollout found"), not in argument parsing.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
js-yaml 4.0.0-4.3.1 is affected by GHSA-2883-xcg3-v3hh (maxTotalMergeKeys
does not limit CPU use for empty merge sources), which fails the CI
'npm audit --omit=dev --audit-level=high' step. Bump the direct
dependency to ^4.3.2 and add a matching override so all transitive
resolutions (via @commitlint, llmist) pick up the patched version.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
GPT-6 Astra (gpt-6-astra) joins the Codex model catalog with its published
API pricing. The worker image moves from Codex 0.145.0 to 0.155.1 because
older CLIs have no catalog entry for Astra and run it on fallback metadata.

Adjustments for the newer CLI:
- `[features].web_search` is deprecated and web search now defaults on, so
  buildArgs always passes the top-level `web_search` mode (`live` when the
  engine setting is true, `disabled` otherwise).
- The git-push deny hook was re-verified live on 0.155.1 with gpt-5.5 and
  gpt-6-astra (tool_name is still `Bash`).

Guards:
- Dockerfile.worker ends with a model-free grammar probe
  (dist/backends/codex/grammarSmokeCli.js) that feeds CASCADE's exact
  continuation argv to the pinned CLI and passes only when it stops at
  thread lookup, so a grammar-incompatible pin fails the image build.
- tests/fixtures/codex/0.155.1 carries the regenerated protocol schema and a
  recorded exec stream; the event-schema test reads the pin from
  Dockerfile.worker and fails when fixtures for it are missing.

Also corrects the GPT-5.6 Sol/Terra/Luna pricing rows to the currently
published rates (they were overstated, Luna by 5x).

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
…rg-order

fix(codex): put exec options before the resume subcommand
…-gpt-6-astra

feat(codex): pin Codex CLI 0.155.1 and add GPT-6 Astra
@zbigniewsobiecki
zbigniewsobiecki merged commit ba65e05 into main Sep 21, 2026
16 of 18 checks passed
@codecov

codecov Bot commented Sep 21, 2026

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 92.96875% with 9 lines in your changes missing coverage. Please review.

Files with missing lines Patch % Lines
src/backends/codex/grammarSmokeCli.ts 0.00% 7 Missing ⚠️
src/backends/codex/grammarSmoke.ts 98.64% 1 Missing ⚠️
src/router/registry-auth.ts 96.55% 1 Missing ⚠️

📢 Thoughts on this report? Let us know!

This branch had an error being deployed

1 failed deployment
CI — a6451fc5 Deployed Sep 21, 2026 by zbigniewsobiecki via Build and Deploy (Dev) #990
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant