mirror of
https://github.com/ComposioHQ/composio.git
synced 2026-09-22 11:46:35 +08:00
google-example@0.1.3
10 Commits
| Author | SHA1 | Message | Date | |
|---|---|---|---|---|
|
|
be8e978c3a |
fix(toolchain): pin Bun canary for valid macOS signatures (#4315)
This PR: - closes #4284 - makes `mise.toml` the editable source of truth for Bun and pins `1.4.1-canary.1+d9b769812`, the first Bun build whose compiled macOS binaries carry strictly valid signatures - maps that revision to the immutable per-platform `@oven/bun-*` npm tarballs via mise's `http` backend, so mise extracts the exact checksum-verified binary with no npm lifecycle, Node dependency, or postinstall script - installs Bun through mise in CI and Docker E2E images, removing the independent `bun-version` input and the `oven-sh/setup-bun` channel - updates the checksum-verified mise installer to `2026.8.15`, reuses it in the Docker E2E images, and regenerates `mise.lock` with that release - teaches the preinstall toolchain check to compare the full Bun revision (via `Bun.version_with_sha`, in-process) when the pinned version carries build metadata - verifies the exact `bun --revision`, a strictly valid Bun-compiled macOS signature, a Linux container install, the release-workflow contract, and formatting/linting EOF -R ComposioHQ/composio |
||
|
|
64acec65b6 |
ci(ts): fix next push trigger and cache reuse (#3971)
This PR: - fixes the `ts.build.yml` push trigger, which still pointed at `master`: the repo's default branch is `next`, so the workflow has not run on push since 2025-10-24 and never populated the turbo/pnpm caches that PR runs restore from (GitHub cache isolation lets PRs read base-branch caches, but not other PRs') - fixes the same stale `master` push trigger in `py.check.yaml` (all other workflows already list `next`) - adds a `cache-save` input (default `'true'`, preserving current behavior for every other consumer) to the `setup-node-pnpm-bun` composite action, swapping `actions/cache` for `actions/cache/restore` (same repo, same v6.1.0 SHA pin) when disabled - wires `cache-save` in `ts.build.yml` so only push runs on `next` persist caches: PR-scoped saves are invisible to other branches, so they only cost post-job time and evict default-branch entries from the 10 GB repo cache quota ## Context Measured on run [30364148082](https://github.com/ComposioHQ/composio/actions/runs/30364148082) (PR run, ~90s wall time): | Step | Time | |---|---| | Checkout | 5s | | Setup Node.js, pnpm, Bun | 34s (mise 1s, setup-node 5s, setup-bun 2s, pnpm 2s, **pnpm store restore 18s** for 658 MB, turbo restore 1s) | | `pnpm install --frozen-lockfile` | 14s | | `pnpm lint` | 1s | | `pnpm run build:packages` | 24s, **0/19 turbo cache hits** | | Post-job cache saves | ~11s (turbo save + a 658 MB pnpm store save that failed with "Unable to reserve cache", racing the parallel ts.* jobs on the same PR) | The build restored a turbo cache only via the fallback restore-key `Linux-turbo-build-` from an unrelated branch, hence 0 hits. Once push runs fire on `next` again, every merge saves a fresh `Linux-turbo-build-<sha>` cache that PR runs match through the restore-key prefix, so unchanged packages become turbo hits (up to ~20s off the build step) and the ~11s post-job save disappears from PR runs. The per-commit key suffix is kept intentionally: the turbo cache accumulates, so each default-branch save needs a fresh key and readers match via the prefix (documented inline in the action). |
||
|
|
503b50ab02 |
chore(deps): refresh SDK, Python, and CI dependencies (#3955)
This PR: - splits https://github.com/ComposioHQ/composio/pull/3953 in two: this PR carries every dependency and GitHub Actions bump **except** the docs site, which follows in a stacked PR - consolidates and supersedes Dependabot PRs #3915, #3916, and #3934 through #3942 - adopts TypeScript 7.0.2 for primary compilation while retaining the `@typescript/typescript6` API lane that TypeScript-ESLint still requires, following the upstream side-by-side guidance - refreshes Python core and provider dependencies, lockfiles, and the Ruff 0.16 lint configuration - updates every GitHub Action with a verified newer official release, including majors, while retaining immutable commit SHA pins and migrating setup-uv cache pruning - deletes four per-package `eslint.config.mjs` shims: under ESLint 10 the default per-file config lookup re-anchors the root config's globs into each package, so `pnpm lint` stayed green while the CLI's try/catch, `process.env` and node-builtin bans went unenforced - bounds and documents the new `brace-expansion` and `@hono/node-server` security overrides, raising the `@hono/node-server` floor to 2.0.10 to clear GHSA-9mqv-5hh9-4cgg - preserves intentional compatibility fixtures and lanes for AI SDK 6, Zod 3, TypeScript 5.8, Mastra AI SDK 5, and Python provider constraints ## Context The docs site is a separate Bun workspace with its own `bun.lock` and is not a pnpm workspace member, so the two halves share no lockfile and no build. Splitting them keeps the Fumadocs 11 migration (a breaking API change with real refactoring) reviewable on its own, independently of the mechanical version bumps here. The `brace-expansion` override deliberately spans majors: GHSA-mh99-v99m-4gvg (HIGH) is published as a single `<=5.0.7` range with no 1.x or 2.x backport, so narrowing it to the 5.x line puts `brace-expansion` 2.1.2 back under `core>minimatch>brace-expansion` and `pnpm audit --prod --audit-level=high` exits 1. Verified both ways; the trade-off it buys is recorded inline in `pnpm-workspace.yaml`. Verified on this branch standalone: `pnpm install --frozen-lockfile`, `pnpm lint`, `pnpm typecheck`, `pnpm build:packages`, `pnpm test` (963 tests, 26/26 tasks), and `pnpm audit --prod --audit-level=high`. |
||
|
|
4b790dc0ce |
fix(docs): correct toolkit versions and enforce production source (#3837)
## What this fixes This is a follow-up to #3770, not a second root-cause fix. #3770 moved the docs data workflow from staging to production, centralized the production API URL, removed staging hosts from the committed data, and added the hostname guard. The committed toolkit catalog still retained staging-derived `version` values, however, because that PR intentionally did not regenerate the full catalog. After #3770 merged, the scheduled production regeneration began failing with `401 Unauthorized`: the repository's existing `COMPOSIO_API_KEY` secret is staging-scoped. The customer-visible result was that nearly every toolkit page showed the internal staging version `20260703_00`; Gmail's production version was `20260702_01`. ## Changes - Correct every `version` in `docs/public/data/toolkits.json` from the production toolkit changelog. Toolkits absent from that changelog receive `null`, matching the full generator's semantics. No other JSON field changes. - Move production changelog fetching and version application into shared `toolkit-versions.ts` logic used by the full catalog generator. - Add `bun run generate:toolkit-versions` as the narrow, reproducible generator for version-only repairs. - Reject any non-production `COMPOSIO_API_BASE` in the toolkit and meta-tool generators before a request is made. - Keep the version-distribution check as a smoke signal for the known whole-catalog staging-bump pattern, while testing the production source boundary separately. The distribution heuristic is no longer described as proof of provenance. - Fail before writing when the production changelog response is malformed or contains no versions. ## CI policy compatibility - Replace the enterprise-blocked mise action with allowlisted tool setup actions while continuing to resolve exact versions from mise.lock. Install the existing pinned mise CLI release through a checksum-verified repository script for lock freshness and preinstall validation. - Run the existing GitHub Advanced Security alert check locally and notify Slack through the already-allowlisted Slack action, avoiding the central workflow dependency rejected by the enterprise action policy. ## Verification - `bun test tests/static/` — 30 passed. - Targeted ESLint for every changed script/test — passed. - `bun run types:check` — passed. - `bun run build` — passed. - Explicit staging override of `generate-toolkits.ts` — rejected before network access. - Verified the JSON data change remains version-only; toolkit ordering, tools, triggers, descriptions, and counts are unchanged. ## Remaining deployment action An administrator still needs to replace `COMPOSIO_API_KEY` with a production-scoped key. The scheduled `docs-update-data` workflow is correctly pinned to production and therefore fails loudly with the current staging credential instead of republishing staging data. Once the secret is corrected, the normal full-catalog generator remains the authoritative refresh path. Triggered by: abhishek@composio.dev | Source: slack Session: https://zen.corp.composio.io/dashboard/#/chat/zen-3a77f73eb146 --------- Co-authored-by: Zen Agent <zen@composio.dev> Co-authored-by: abhishek <abhishek@composio.dev> Co-authored-by: jkomyno <alberto@composio.dev> |
||
|
|
8d5823be87 |
chore(ci): cache turbo, bun, and uv and cancel superseded pr runs (#3747)
This PR: - adds `concurrency` to the ten PR/push CI workflows: superseded **PR** runs are cancelled, while push runs use a per-run group (`github.run_id`) so every commit on `next`/`master` still gets its own run - caches turbo outputs (`.turbo/cache`) via a new opt-in `enable-turbo-cache` input on the `setup-node-pnpm-bun` composite (keyed per job — concurrent jobs save different task graphs), enabled in `ts.build`, `ts.test`, `ts.typecheck`, and all four `ts.test-e2e` jobs - enables turbo caching for `typecheck`, removes the incorrect `dist/` outputs from `test`, hashes root `tsconfig.base.json` in `build`/`typecheck` inputs, and adds `mise.toml`/`mise.lock` to `globalDependencies` so toolchain bumps bust every task hash (addresses the Bugbot finding) - fixes `@composio/slim`'s build to participate in the turbo graph: core moves to slim's `devDependencies` (published `dependencies` unchanged) and the script no longer shells out to `pnpm --filter @composio/core build`, which raced concurrent dependents by wiping `core/dist` mid-build and double-built core on every cold run — slim's `dist` remains byte-identical to core's; no changeset added since the published artifact is unchanged (say the word if policy wants one anyway) - fixes the `py.test` matrix cache to `~/.cache/uv` (it cached `~/.cache/pip` while installing via `uv pip`) and caches `~/.bun/install/cache` in the five docs workflows - adds `turbo.jsonc` to the TS workflows' path filters (previously unwatched) - release/publish workflows are deliberately untouched Measured (same commit, cold first attempt vs `gh run rerun` warm): ts.build 103s → 53s, ts.test 157s → 55s (`turbo test` 24/24 cached in 182ms), ts.typecheck 80s → 43s; py.test legs save a few seconds each (uv was already fast). Warm floor is checkout + mise + pnpm-install overhead. ## Context Implements `plans/001-ci-speed-caching-and-concurrency.md` from the advisor audit on `docs/sdk-v1-decision-records`. Implementation by codex against the plan, then self-reviewed and counter-reviewed; warm-rerun testing surfaced and fixed three latent issues (toolchain files absent from turbo's hash, first-writer-wins cache-key collision across jobs, and the slim out-of-band core rebuild race). |
||
|
|
f8cd90ce5a |
chore(ts): adopt Node 24 and pnpm 11 toolchain (#3646)
This PR: - uses plain `tsdown` package scripts and a shared typed `tsdown.config.base.ts` so Node 24 builds work without loader flags - switches the repo dev/build toolchain to Node `24.17.0` and pnpm `11.8.0` through `mise.toml`, `mise.lock`, and `pnpm-lock.yaml` - marks the root package as ESM with `type: module`, matching the TypeScript packages - keeps Node `22.22.3` in the runtime/E2E matrices as the minimum supported user runtime - changes the TypeScript build workflow back to a single build on the mise-managed toolchain and broadens path filters for package-manager/build config files - adds pnpm 11 build-script policy with `allowBuilds` and intentionally ignored `sharp` builds - enables tsdown ESM shims for the packaged CLI wrapper so `composio --help` runs under Node 22 and Node 24 Verified locally: - `CI=true pnpm install --frozen-lockfile` - `pnpm lint` - `pnpm run build:packages` - `COMPOSIO_E2E_NODE_VERSION=22.22.3 pnpm --filter @e2e-tests/node-esm-basic --filter @e2e-tests/node-cjs-basic run test:e2e:node` - `node ts/packages/cli/bin/composio.mjs --help` under Node `22.22.3` and `24.17.0` |
||
|
|
4fe776898a |
chore(toolchain): finish mise migration (#3493)
## Summary Depends on #3492. This completes the Phase 2 migration by removing the transitional version-file layer and making `mise.toml` plus `mise.lock` the repository toolchain source of truth. It also moves runtime test matrices into `toolchain-versions.json`, so CI matrix changes are explicit and reviewable without reintroducing `.nvmrc`, `.dvmrc`, `.bun-version`, or `.python-version`. The Node.js e2e matrix now starts at the latest Node 22 LTS line and also covers the latest Node 24 and Node 25 lines. That removes Node 20 from the well-known e2e versions while keeping us covered on the runtimes SDK users are moving toward. ## Rationale Phase 1 introduced mise side by side with the existing version files to keep the first PR low-risk. Phase 2 removes that compatibility layer so there is one place to update tool versions. That avoids silent drift between local setup, GitHub Actions, Docker E2E images, release docs, and install-time checks. The composite setup actions now install Node, Bun, Python, and uv through mise by default, with explicit version overrides only where a matrix needs them. New GitHub actions added in this PR are pinned by release commit SHA and include the release version comment. ## What changed - Deleted the transitional root/version files: `.nvmrc`, `.bun-version`, `.dvmrc`, root `.python-version`, and `python/.python-version`. - Removed `idiomatic_version_file_enable_tools` from `mise.toml` and added a committed `mise.lock` for linux/macOS x64/arm64 tool resolution. - Replaced `BYPASS_BUN_VERSION_CHECK` with `BYPASS_TOOLCHAIN_CHECK`, and made Docker E2E image installs use that bypass because they receive explicit build args instead of installing mise. - Updated Node/Bun and Python/uv composite actions to default to mise, remove `*-version-file` inputs, report resolved versions, and cache pnpm after `corepack enable`. - Centralized CI runtime matrices in `toolchain-versions.json` for TS E2E, Python tests, and CLI npm fallback coverage. - Updated the Node E2E matrix to `22.22.3`, `24.16.0`, and `25.9.0`, removing Node 20 from the well-known runtime versions. - Updated workflows, docs, E2E helpers, Dockerfiles, and release guidance to reference `mise.toml` / `mise.lock`. ## Verification - Verified latest Node 22/24/25 releases from the official Node dist index: `22.22.3`, `24.16.0`, `25.9.0` (https://nodejs.org/dist/index.json). - `pnpm install --frozen-lockfile` - `pnpm --filter @e2e-tests/utils typecheck` - `pnpm --filter @e2e-tests/utils exec tsc --noEmit --target es2022 --module esnext --moduleResolution bundler --types bun --resolveJsonModule --skipLibCheck --strict scripts/docker-build.ts` - `bash -n ts/scripts/pre-install.sh && bun run ts/scripts/pre-install/check-toolchain.ts && BYPASS_TOOLCHAIN_CHECK=1 bash ts/scripts/pre-install.sh` - `pnpm exec prettier --check ...` on touched YAML/Markdown/TS/JSON files - `ruby -e "require \"yaml\"; ARGV.each { |f| YAML.load_file(f) }" ...` on touched actions/workflows - `mise lock --platform linux-x64,linux-arm64,macos-arm64,macos-x64 && git diff --exit-code mise.lock` - `mise exec node@22.22.3 -- pnpm --filter @e2e-tests/utils typecheck` - `mise exec node@22.22.3 -- pnpm --filter @e2e-tests/node-esm-basic typecheck` - `mise exec node@22.22.3 -- pnpm --filter @e2e-tests/node-cjs-basic typecheck` - `docker manifest inspect node:24.16.0-slim` - `docker manifest inspect node:25.9.0-slim` - `git diff --check` |
||
|
|
90a436e393 |
chore(ci): pin GitHub Actions to SHAs (#3531)
## Summary
- Pin every remote GitHub Action used by `.github/workflows` and
`.github/actions` to a full 40-character commit SHA with a version
comment.
- Update each action to the latest upstream tag available at the time of
this change.
- Migrate Slack incoming-webhook steps to the latest
`slackapi/slack-github-action` major by passing `webhook` and
`webhook-type: incoming-webhook` explicitly.
- Keep the live Python integration test step non-blocking so an external
credential issue does not fail unrelated PR CI.
## Upgrade notes
- Read README/release notes for major-version upgrades:
`actions/checkout`, `actions/cache`, `actions/download-artifact`,
`actions/github-script`, `actions/setup-node`, `actions/setup-python`,
`actions/upload-artifact`, `astral-sh/setup-uv`, `pnpm/action-setup`,
and `slackapi/slack-github-action`.
- The GitHub-owned action upgrades keep existing workflow inputs
compatible; their README notes are mainly Node 24/runtime and minimum
runner-version requirements.
- `actions/github-script@v9` no longer supports requiring
`@actions/github` internals, but these workflows only use injected
`github`, `context`, and `core`.
- `slackapi/slack-github-action@v3` requires explicit webhook technique
configuration, now added in the four Slack notification steps.
## Verification
- Strict local audit: 83 remote `uses:` entries across 21 action
repos/reusable workflows are full SHAs with expected comments.
- Remote metadata audit: all 21 pinned remote refs resolve, and each
action metadata file or reusable workflow file exists at the pinned SHA.
- `.github/scripts/check-action-repos.sh`
- `ruby -e 'require "yaml"; Dir[".github/workflows/*.{yml,yaml}",
".github/actions/**/*.yml", ".github/actions/**/*.yaml"].each { |f|
YAML.load_file(f); puts "ok #{f}" }'`
- `git diff --check`
- `go run github.com/rhysd/actionlint/cmd/actionlint@latest -shellcheck=
-pyflakes= -ignore 'label "depot-ubuntu-[^\"]+" is unknown'`
`actionlint` without the ignore only reports the existing custom Depot
runner labels in `cli.test-installation.yml`.
|
||
|
|
b24a8a3e2c | Fix github workflow versions (#2420) | ||
|
|
d80cd28f46 |
feat(ci): QoL improvements (#2404)
Co-authored-by: jkomyno <12381818+jkomyno@users.noreply.github.com> |