Repository navigation
chore: release - merge dev into main - #1556
Merged
Merged
Conversation
…, add CI budget guards CLAUDE.md is cat-injected into every CASCADE worker prompt (inline only under CONTEXT_OFFLOAD_CONFIG.inlineThreshold) and loaded into every Claude Code session. It was 217 lines plus 95 KB of @imports, 89% of the worker inline cliff, and mostly duplicated docs/architecture or spec/incident narrative; the Git hooks section was wrong. - CLAUDE.md: 76 lines / ~1.7k tokens - commands, gotchas (corrected lefthook contract), hard invariants, env pointer, area pointer table, placement rule; zero @imports - docs/areas/{pm-integrations,router-dispatch,agents,backends}.md: imperatives + links - only-home facts placed first in 01-services, 03-trigger-system, 10-resilience, tests/README.md and .env.example before their CLAUDE.md copies were removed - tests/unit/architecture-docs.test.ts: line/token budget derived from the real inlineThreshold, no-@import, no-narrative, area-doc shape + linkage guards; tests/unit/repo-hygiene.test.ts pins the shared root/web Zod major - src/integrations/README.md: spec-changelog tables removed, duplicate contract table merged; JIRA authType now has one home (08-config-credentials points at it) - SECURITY/README/CONTRIBUTING/ARCHITECTURE/.env.example pointers fixed; CHANGELOG entry - documentation-maintenance partial re-routed (run npm run db:seed-prompts after deploy) Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…d-areas docs: slim CLAUDE.md to a 76-line core + pointer-loaded docs/areas, with CI budget guards
Bumps [undici](https://github.com/nodejs/undici) from 7.28.0 to 7.29.0. - [Release notes](https://github.com/nodejs/undici/releases) - [Commits](nodejs/undici@v7.28.0...v7.29.0) --- updated-dependencies: - dependency-name: undici dependency-version: 7.29.0 dependency-type: indirect ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [fast-uri](https://github.com/fastify/fast-uri) from 3.1.4 to 3.1.5. - [Release notes](https://github.com/fastify/fast-uri/releases) - [Commits](fastify/fast-uri@v3.1.4...v3.1.5) --- updated-dependencies: - dependency-name: fast-uri dependency-version: 3.1.5 dependency-type: indirect ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [hono](https://github.com/honojs/hono) from 4.12.32 to 4.13.4. - [Release notes](https://github.com/honojs/hono/releases) - [Commits](honojs/hono@v4.12.32...v4.13.4) --- updated-dependencies: - dependency-name: hono dependency-version: 4.13.1 dependency-type: direct:production ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
…es (#1539) * fix(router): authenticate worker-image pulls against private registries All router-side registry pulls (spawn self-heal, worker-image validation, Dockerfile-build base refresh) funnel through pullImageOnce, whose dockerode pull sends no credentials — the daemon has no ambient login and never reads ~/.docker/config.json. Anonymous pulls 401 on private registries, so a host image prune that removed the worker image turned every spawn into `Head .../manifests/latest: unauthorized` (verified live 2026-08-20). New optional env: WORKER_IMAGE_REGISTRY_USERNAME / _PASSWORD (+ _SERVER override; host otherwise derived from the image ref, Docker Hub as the no-host fallback). Unset preserves anonymous pulls; partial credentials warn and stay anonymous. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * fix(deps): bump js-yaml to 4.3.1 to clear high-severity audit failure CI's `npm audit --omit=dev --audit-level=high` step began failing on the newly disclosed CVE-2026-59870 (GHSA-5p4m-2wfm-xmqj): quadratic CPU consumption in js-yaml's !!omap resolution, affecting >=4.0.0 <4.3.1. js-yaml is a direct production dependency; the 4.3.1 patch release fixes it and all transitive consumers (llmist, @llmist/cli) dedupe to it. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> --------- Co-authored-by: Claude Fable 5 <noreply@anthropic.com> Co-authored-by: Cascade Bot <bot@cascade.dev>
Continuation turns resumed a Codex thread with
`codex exec resume <id> ... -C <dir> ... -s <mode> ...`. In the pinned CLI
`-C`/`--cd` and `-s`/`--sandbox` are parent-only `exec` options, so
clap rejected the resume with "unexpected argument '-C'" before the model
was reached and the run was recorded as failed. Emit every option first and
the subcommand plus stdin marker last: `codex exec <options> resume <id> -`.
Verified the generated argv against @openai/codex@0.145.0: it now fails only
at thread lookup ("no rollout found"), not in argument parsing.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
js-yaml 4.0.0-4.3.1 is affected by GHSA-2883-xcg3-v3hh (maxTotalMergeKeys does not limit CPU use for empty merge sources), which fails the CI 'npm audit --omit=dev --audit-level=high' step. Bump the direct dependency to ^4.3.2 and add a matching override so all transitive resolutions (via @commitlint, llmist) pick up the patched version. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
GPT-6 Astra (gpt-6-astra) joins the Codex model catalog with its published API pricing. The worker image moves from Codex 0.145.0 to 0.155.1 because older CLIs have no catalog entry for Astra and run it on fallback metadata. Adjustments for the newer CLI: - `[features].web_search` is deprecated and web search now defaults on, so buildArgs always passes the top-level `web_search` mode (`live` when the engine setting is true, `disabled` otherwise). - The git-push deny hook was re-verified live on 0.155.1 with gpt-5.5 and gpt-6-astra (tool_name is still `Bash`). Guards: - Dockerfile.worker ends with a model-free grammar probe (dist/backends/codex/grammarSmokeCli.js) that feeds CASCADE's exact continuation argv to the pinned CLI and passes only when it stops at thread lookup, so a grammar-incompatible pin fails the image build. - tests/fixtures/codex/0.155.1 carries the regenerated protocol schema and a recorded exec stream; the event-schema test reads the pin from Dockerfile.worker and fails when fixtures for it are missing. Also corrects the GPT-5.6 Sol/Terra/Luna pricing rows to the currently published rates (they were overstated, Luna by 5x). Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
…rg-order fix(codex): put exec options before the resume subcommand
…-gpt-6-astra feat(codex): pin Codex CLI 0.155.1 and add GPT-6 Astra
Codecov Report❌ Patch coverage is
📢 Thoughts on this report? Let us know! |
This branch had an error being deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Automated release PR created by the release workflow.
Commits (13):