Commit Graph

10 Commits

Author SHA1 Message Date
Alberto Schiabel be8e978c3a fix(toolchain): pin Bun canary for valid macOS signatures (#4315)
This PR:
- closes #4284
- makes `mise.toml` the editable source of truth for Bun and pins
`1.4.1-canary.1+d9b769812`, the first Bun build whose compiled macOS
binaries carry strictly valid signatures
- maps that revision to the immutable per-platform `@oven/bun-*` npm
tarballs via mise's `http` backend, so mise extracts the exact
checksum-verified binary with no npm lifecycle, Node dependency, or
postinstall script
- installs Bun through mise in CI and Docker E2E images, removing the
independent `bun-version` input and the `oven-sh/setup-bun` channel
- updates the checksum-verified mise installer to `2026.8.15`, reuses it
in the Docker E2E images, and regenerates `mise.lock` with that release
- teaches the preinstall toolchain check to compare the full Bun
revision (via `Bun.version_with_sha`, in-process) when the pinned
version carries build metadata
- verifies the exact `bun --revision`, a strictly valid Bun-compiled
macOS signature, a Linux container install, the release-workflow
contract, and formatting/linting
EOF -R ComposioHQ/composio
2026-09-03 11:51:22 +02:00
Alberto Schiabel 64acec65b6 ci(ts): fix next push trigger and cache reuse (#3971)
This PR:

- fixes the `ts.build.yml` push trigger, which still pointed at
`master`: the repo's default branch is `next`, so the workflow has not
run on push since 2025-10-24 and never populated the turbo/pnpm caches
that PR runs restore from (GitHub cache isolation lets PRs read
base-branch caches, but not other PRs')
- fixes the same stale `master` push trigger in `py.check.yaml` (all
other workflows already list `next`)
- adds a `cache-save` input (default `'true'`, preserving current
behavior for every other consumer) to the `setup-node-pnpm-bun`
composite action, swapping `actions/cache` for `actions/cache/restore`
(same repo, same v6.1.0 SHA pin) when disabled
- wires `cache-save` in `ts.build.yml` so only push runs on `next`
persist caches: PR-scoped saves are invisible to other branches, so they
only cost post-job time and evict default-branch entries from the 10 GB
repo cache quota

## Context

Measured on run
[30364148082](https://github.com/ComposioHQ/composio/actions/runs/30364148082)
(PR run, ~90s wall time):

| Step | Time |
|---|---|
| Checkout | 5s |
| Setup Node.js, pnpm, Bun | 34s (mise 1s, setup-node 5s, setup-bun 2s,
pnpm 2s, **pnpm store restore 18s** for 658 MB, turbo restore 1s) |
| `pnpm install --frozen-lockfile` | 14s |
| `pnpm lint` | 1s |
| `pnpm run build:packages` | 24s, **0/19 turbo cache hits** |
| Post-job cache saves | ~11s (turbo save + a 658 MB pnpm store save
that failed with "Unable to reserve cache", racing the parallel ts.*
jobs on the same PR) |

The build restored a turbo cache only via the fallback restore-key
`Linux-turbo-build-` from an unrelated branch, hence 0 hits. Once push
runs fire on `next` again, every merge saves a fresh
`Linux-turbo-build-<sha>` cache that PR runs match through the
restore-key prefix, so unchanged packages become turbo hits (up to ~20s
off the build step) and the ~11s post-job save disappears from PR runs.
The per-commit key suffix is kept intentionally: the turbo cache
accumulates, so each default-branch save needs a fresh key and readers
match via the prefix (documented inline in the action).
2026-07-28 19:53:19 +05:30
Alberto Schiabel 503b50ab02 chore(deps): refresh SDK, Python, and CI dependencies (#3955)
This PR:

- splits https://github.com/ComposioHQ/composio/pull/3953 in two: this
PR carries every dependency and GitHub Actions bump **except** the docs
site, which follows in a stacked PR
- consolidates and supersedes Dependabot PRs #3915, #3916, and #3934
through #3942
- adopts TypeScript 7.0.2 for primary compilation while retaining the
`@typescript/typescript6` API lane that TypeScript-ESLint still
requires, following the upstream side-by-side guidance
- refreshes Python core and provider dependencies, lockfiles, and the
Ruff 0.16 lint configuration
- updates every GitHub Action with a verified newer official release,
including majors, while retaining immutable commit SHA pins and
migrating setup-uv cache pruning
- deletes four per-package `eslint.config.mjs` shims: under ESLint 10
the default per-file config lookup re-anchors the root config's globs
into each package, so `pnpm lint` stayed green while the CLI's
try/catch, `process.env` and node-builtin bans went unenforced
- bounds and documents the new `brace-expansion` and `@hono/node-server`
security overrides, raising the `@hono/node-server` floor to 2.0.10 to
clear GHSA-9mqv-5hh9-4cgg
- preserves intentional compatibility fixtures and lanes for AI SDK 6,
Zod 3, TypeScript 5.8, Mastra AI SDK 5, and Python provider constraints

## Context

The docs site is a separate Bun workspace with its own `bun.lock` and is
not a pnpm workspace member, so the two halves share no lockfile and no
build. Splitting them keeps the Fumadocs 11 migration (a breaking API
change with real refactoring) reviewable on its own, independently of
the mechanical version bumps here.

The `brace-expansion` override deliberately spans majors:
GHSA-mh99-v99m-4gvg (HIGH) is published as a single `<=5.0.7` range with
no 1.x or 2.x backport, so narrowing it to the 5.x line puts
`brace-expansion` 2.1.2 back under `core>minimatch>brace-expansion` and
`pnpm audit --prod --audit-level=high` exits 1. Verified both ways; the
trade-off it buys is recorded inline in `pnpm-workspace.yaml`.

Verified on this branch standalone: `pnpm install --frozen-lockfile`,
`pnpm lint`, `pnpm typecheck`, `pnpm build:packages`, `pnpm test` (963
tests, 26/26 tasks), and `pnpm audit --prod --audit-level=high`.
2026-07-27 17:57:29 +05:30
composio-zen[bot] 4b790dc0ce fix(docs): correct toolkit versions and enforce production source (#3837)
## What this fixes

This is a follow-up to #3770, not a second root-cause fix.

#3770 moved the docs data workflow from staging to production,
centralized the production API URL, removed staging hosts from the
committed data, and added the hostname guard. The committed toolkit
catalog still retained staging-derived `version` values, however,
because that PR intentionally did not regenerate the full catalog. After
#3770 merged, the scheduled production regeneration began failing with
`401 Unauthorized`: the repository's existing `COMPOSIO_API_KEY` secret
is staging-scoped.

The customer-visible result was that nearly every toolkit page showed
the internal staging version `20260703_00`; Gmail's production version
was `20260702_01`.

## Changes

- Correct every `version` in `docs/public/data/toolkits.json` from the
production toolkit changelog. Toolkits absent from that changelog
receive `null`, matching the full generator's semantics. No other JSON
field changes.
- Move production changelog fetching and version application into shared
`toolkit-versions.ts` logic used by the full catalog generator.
- Add `bun run generate:toolkit-versions` as the narrow, reproducible
generator for version-only repairs.
- Reject any non-production `COMPOSIO_API_BASE` in the toolkit and
meta-tool generators before a request is made.
- Keep the version-distribution check as a smoke signal for the known
whole-catalog staging-bump pattern, while testing the production source
boundary separately. The distribution heuristic is no longer described
as proof of provenance.
- Fail before writing when the production changelog response is
malformed or contains no versions.

## CI policy compatibility

- Replace the enterprise-blocked mise action with allowlisted tool setup
actions while continuing to resolve exact versions from mise.lock.
Install the existing pinned mise CLI release through a checksum-verified
repository script for lock freshness and preinstall validation.
- Run the existing GitHub Advanced Security alert check locally and
notify Slack through the already-allowlisted Slack action, avoiding the
central workflow dependency rejected by the enterprise action policy.

## Verification

- `bun test tests/static/` — 30 passed.
- Targeted ESLint for every changed script/test — passed.
- `bun run types:check` — passed.
- `bun run build` — passed.
- Explicit staging override of `generate-toolkits.ts` — rejected before
network access.
- Verified the JSON data change remains version-only; toolkit ordering,
tools, triggers, descriptions, and counts are unchanged.

## Remaining deployment action

An administrator still needs to replace `COMPOSIO_API_KEY` with a
production-scoped key. The scheduled `docs-update-data` workflow is
correctly pinned to production and therefore fails loudly with the
current staging credential instead of republishing staging data. Once
the secret is corrected, the normal full-catalog generator remains the
authoritative refresh path.

Triggered by: abhishek@composio.dev | Source: slack
Session: https://zen.corp.composio.io/dashboard/#/chat/zen-3a77f73eb146

---------

Co-authored-by: Zen Agent <zen@composio.dev>
Co-authored-by: abhishek <abhishek@composio.dev>
Co-authored-by: jkomyno <alberto@composio.dev>
2026-07-15 17:16:44 +04:00
Alberto Schiabel 8d5823be87 chore(ci): cache turbo, bun, and uv and cancel superseded pr runs (#3747)
This PR:

- adds `concurrency` to the ten PR/push CI workflows: superseded **PR**
runs are cancelled, while push runs use a per-run group
(`github.run_id`) so every commit on `next`/`master` still gets its own
run
- caches turbo outputs (`.turbo/cache`) via a new opt-in
`enable-turbo-cache` input on the `setup-node-pnpm-bun` composite (keyed
per job — concurrent jobs save different task graphs), enabled in
`ts.build`, `ts.test`, `ts.typecheck`, and all four `ts.test-e2e` jobs
- enables turbo caching for `typecheck`, removes the incorrect `dist/`
outputs from `test`, hashes root `tsconfig.base.json` in
`build`/`typecheck` inputs, and adds `mise.toml`/`mise.lock` to
`globalDependencies` so toolchain bumps bust every task hash (addresses
the Bugbot finding)
- fixes `@composio/slim`'s build to participate in the turbo graph: core
moves to slim's `devDependencies` (published `dependencies` unchanged)
and the script no longer shells out to `pnpm --filter @composio/core
build`, which raced concurrent dependents by wiping `core/dist`
mid-build and double-built core on every cold run — slim's `dist`
remains byte-identical to core's; no changeset added since the published
artifact is unchanged (say the word if policy wants one anyway)
- fixes the `py.test` matrix cache to `~/.cache/uv` (it cached
`~/.cache/pip` while installing via `uv pip`) and caches
`~/.bun/install/cache` in the five docs workflows
- adds `turbo.jsonc` to the TS workflows' path filters (previously
unwatched)
- release/publish workflows are deliberately untouched

Measured (same commit, cold first attempt vs `gh run rerun` warm):
ts.build 103s → 53s, ts.test 157s → 55s (`turbo test` 24/24 cached in
182ms), ts.typecheck 80s → 43s; py.test legs save a few seconds each (uv
was already fast). Warm floor is checkout + mise + pnpm-install
overhead.

## Context

Implements `plans/001-ci-speed-caching-and-concurrency.md` from the
advisor audit on `docs/sdk-v1-decision-records`. Implementation by codex
against the plan, then self-reviewed and counter-reviewed; warm-rerun
testing surfaced and fixed three latent issues (toolchain files absent
from turbo's hash, first-writer-wins cache-key collision across jobs,
and the slim out-of-band core rebuild race).
2026-07-03 22:22:18 +04:00
Alberto Schiabel f8cd90ce5a chore(ts): adopt Node 24 and pnpm 11 toolchain (#3646)
This PR:

- uses plain `tsdown` package scripts and a shared typed
`tsdown.config.base.ts` so Node 24 builds work without loader flags
- switches the repo dev/build toolchain to Node `24.17.0` and pnpm
`11.8.0` through `mise.toml`, `mise.lock`, and `pnpm-lock.yaml`
- marks the root package as ESM with `type: module`, matching the
TypeScript packages
- keeps Node `22.22.3` in the runtime/E2E matrices as the minimum
supported user runtime
- changes the TypeScript build workflow back to a single build on the
mise-managed toolchain and broadens path filters for
package-manager/build config files
- adds pnpm 11 build-script policy with `allowBuilds` and intentionally
ignored `sharp` builds
- enables tsdown ESM shims for the packaged CLI wrapper so `composio
--help` runs under Node 22 and Node 24

Verified locally:

- `CI=true pnpm install --frozen-lockfile`
- `pnpm lint`
- `pnpm run build:packages`
- `COMPOSIO_E2E_NODE_VERSION=22.22.3 pnpm --filter
@e2e-tests/node-esm-basic --filter @e2e-tests/node-cjs-basic run
test:e2e:node`
- `node ts/packages/cli/bin/composio.mjs --help` under Node `22.22.3`
and `24.17.0`
2026-06-24 18:58:11 +04:00
Alberto Schiabel 4fe776898a chore(toolchain): finish mise migration (#3493)
## Summary

Depends on #3492.

This completes the Phase 2 migration by removing the transitional
version-file layer and making `mise.toml` plus `mise.lock` the
repository toolchain source of truth. It also moves runtime test
matrices into `toolchain-versions.json`, so CI matrix changes are
explicit and reviewable without reintroducing `.nvmrc`, `.dvmrc`,
`.bun-version`, or `.python-version`.

The Node.js e2e matrix now starts at the latest Node 22 LTS line and
also covers the latest Node 24 and Node 25 lines. That removes Node 20
from the well-known e2e versions while keeping us covered on the
runtimes SDK users are moving toward.

## Rationale

Phase 1 introduced mise side by side with the existing version files to
keep the first PR low-risk. Phase 2 removes that compatibility layer so
there is one place to update tool versions. That avoids silent drift
between local setup, GitHub Actions, Docker E2E images, release docs,
and install-time checks.

The composite setup actions now install Node, Bun, Python, and uv
through mise by default, with explicit version overrides only where a
matrix needs them. New GitHub actions added in this PR are pinned by
release commit SHA and include the release version comment.

## What changed

- Deleted the transitional root/version files: `.nvmrc`, `.bun-version`,
`.dvmrc`, root `.python-version`, and `python/.python-version`.
- Removed `idiomatic_version_file_enable_tools` from `mise.toml` and
added a committed `mise.lock` for linux/macOS x64/arm64 tool resolution.
- Replaced `BYPASS_BUN_VERSION_CHECK` with `BYPASS_TOOLCHAIN_CHECK`, and
made Docker E2E image installs use that bypass because they receive
explicit build args instead of installing mise.
- Updated Node/Bun and Python/uv composite actions to default to mise,
remove `*-version-file` inputs, report resolved versions, and cache pnpm
after `corepack enable`.
- Centralized CI runtime matrices in `toolchain-versions.json` for TS
E2E, Python tests, and CLI npm fallback coverage.
- Updated the Node E2E matrix to `22.22.3`, `24.16.0`, and `25.9.0`,
removing Node 20 from the well-known runtime versions.
- Updated workflows, docs, E2E helpers, Dockerfiles, and release
guidance to reference `mise.toml` / `mise.lock`.

## Verification

- Verified latest Node 22/24/25 releases from the official Node dist
index: `22.22.3`, `24.16.0`, `25.9.0`
(https://nodejs.org/dist/index.json).
- `pnpm install --frozen-lockfile`
- `pnpm --filter @e2e-tests/utils typecheck`
- `pnpm --filter @e2e-tests/utils exec tsc --noEmit --target es2022
--module esnext --moduleResolution bundler --types bun
--resolveJsonModule --skipLibCheck --strict scripts/docker-build.ts`
- `bash -n ts/scripts/pre-install.sh && bun run
ts/scripts/pre-install/check-toolchain.ts && BYPASS_TOOLCHAIN_CHECK=1
bash ts/scripts/pre-install.sh`
- `pnpm exec prettier --check ...` on touched YAML/Markdown/TS/JSON
files
- `ruby -e "require \"yaml\"; ARGV.each { |f| YAML.load_file(f) }" ...`
on touched actions/workflows
- `mise lock --platform linux-x64,linux-arm64,macos-arm64,macos-x64 &&
git diff --exit-code mise.lock`
- `mise exec node@22.22.3 -- pnpm --filter @e2e-tests/utils typecheck`
- `mise exec node@22.22.3 -- pnpm --filter @e2e-tests/node-esm-basic
typecheck`
- `mise exec node@22.22.3 -- pnpm --filter @e2e-tests/node-cjs-basic
typecheck`
- `docker manifest inspect node:24.16.0-slim`
- `docker manifest inspect node:25.9.0-slim`
- `git diff --check`
2026-06-15 14:03:21 +04:00
Alberto Schiabel 90a436e393 chore(ci): pin GitHub Actions to SHAs (#3531)
## Summary
- Pin every remote GitHub Action used by `.github/workflows` and
`.github/actions` to a full 40-character commit SHA with a version
comment.
- Update each action to the latest upstream tag available at the time of
this change.
- Migrate Slack incoming-webhook steps to the latest
`slackapi/slack-github-action` major by passing `webhook` and
`webhook-type: incoming-webhook` explicitly.
- Keep the live Python integration test step non-blocking so an external
credential issue does not fail unrelated PR CI.

## Upgrade notes
- Read README/release notes for major-version upgrades:
`actions/checkout`, `actions/cache`, `actions/download-artifact`,
`actions/github-script`, `actions/setup-node`, `actions/setup-python`,
`actions/upload-artifact`, `astral-sh/setup-uv`, `pnpm/action-setup`,
and `slackapi/slack-github-action`.
- The GitHub-owned action upgrades keep existing workflow inputs
compatible; their README notes are mainly Node 24/runtime and minimum
runner-version requirements.
- `actions/github-script@v9` no longer supports requiring
`@actions/github` internals, but these workflows only use injected
`github`, `context`, and `core`.
- `slackapi/slack-github-action@v3` requires explicit webhook technique
configuration, now added in the four Slack notification steps.

## Verification
- Strict local audit: 83 remote `uses:` entries across 21 action
repos/reusable workflows are full SHAs with expected comments.
- Remote metadata audit: all 21 pinned remote refs resolve, and each
action metadata file or reusable workflow file exists at the pinned SHA.
- `.github/scripts/check-action-repos.sh`
- `ruby -e 'require "yaml"; Dir[".github/workflows/*.{yml,yaml}",
".github/actions/**/*.yml", ".github/actions/**/*.yaml"].each { |f|
YAML.load_file(f); puts "ok #{f}" }'`
- `git diff --check`
- `go run github.com/rhysd/actionlint/cmd/actionlint@latest -shellcheck=
-pyflakes= -ignore 'label "depot-ubuntu-[^\"]+" is unknown'`

`actionlint` without the ignore only reports the existing custom Depot
runner labels in `cli.test-installation.yml`.
2026-06-08 14:39:33 -07:00
Musthaq Ahamad b24a8a3e2c Fix github workflow versions (#2420) 2026-01-20 15:52:14 +05:30
Alberto Schiabel d80cd28f46 feat(ci): QoL improvements (#2404)
Co-authored-by: jkomyno <12381818+jkomyno@users.noreply.github.com>
2026-01-20 11:25:12 +05:30