mirror of
https://github.com/ComposioHQ/composio.git
synced 2026-09-22 11:46:35 +08:00
4b790dc0ce
## What this fixes This is a follow-up to #3770, not a second root-cause fix. #3770 moved the docs data workflow from staging to production, centralized the production API URL, removed staging hosts from the committed data, and added the hostname guard. The committed toolkit catalog still retained staging-derived `version` values, however, because that PR intentionally did not regenerate the full catalog. After #3770 merged, the scheduled production regeneration began failing with `401 Unauthorized`: the repository's existing `COMPOSIO_API_KEY` secret is staging-scoped. The customer-visible result was that nearly every toolkit page showed the internal staging version `20260703_00`; Gmail's production version was `20260702_01`. ## Changes - Correct every `version` in `docs/public/data/toolkits.json` from the production toolkit changelog. Toolkits absent from that changelog receive `null`, matching the full generator's semantics. No other JSON field changes. - Move production changelog fetching and version application into shared `toolkit-versions.ts` logic used by the full catalog generator. - Add `bun run generate:toolkit-versions` as the narrow, reproducible generator for version-only repairs. - Reject any non-production `COMPOSIO_API_BASE` in the toolkit and meta-tool generators before a request is made. - Keep the version-distribution check as a smoke signal for the known whole-catalog staging-bump pattern, while testing the production source boundary separately. The distribution heuristic is no longer described as proof of provenance. - Fail before writing when the production changelog response is malformed or contains no versions. ## CI policy compatibility - Replace the enterprise-blocked mise action with allowlisted tool setup actions while continuing to resolve exact versions from mise.lock. Install the existing pinned mise CLI release through a checksum-verified repository script for lock freshness and preinstall validation. - Run the existing GitHub Advanced Security alert check locally and notify Slack through the already-allowlisted Slack action, avoiding the central workflow dependency rejected by the enterprise action policy. ## Verification - `bun test tests/static/` — 30 passed. - Targeted ESLint for every changed script/test — passed. - `bun run types:check` — passed. - `bun run build` — passed. - Explicit staging override of `generate-toolkits.ts` — rejected before network access. - Verified the JSON data change remains version-only; toolkit ordering, tools, triggers, descriptions, and counts are unchanged. ## Remaining deployment action An administrator still needs to replace `COMPOSIO_API_KEY` with a production-scoped key. The scheduled `docs-update-data` workflow is correctly pinned to production and therefore fails loudly with the current staging credential instead of republishing staging data. Once the secret is corrected, the normal full-catalog generator remains the authoritative refresh path. Triggered by: abhishek@composio.dev | Source: slack Session: https://zen.corp.composio.io/dashboard/#/chat/zen-3a77f73eb146 --------- Co-authored-by: Zen Agent <zen@composio.dev> Co-authored-by: abhishek <abhishek@composio.dev> Co-authored-by: jkomyno <alberto@composio.dev>
53 lines
1.5 KiB
TypeScript
53 lines
1.5 KiB
TypeScript
/**
|
|
* Refresh only the version field in the committed toolkit catalog.
|
|
*
|
|
* This is the narrow, reproducible repair path for version-only incidents. The
|
|
* full `generate-toolkits.ts` script remains the owner of complete catalog
|
|
* regeneration.
|
|
*
|
|
* Run from docs/: bun run generate:toolkit-versions
|
|
*/
|
|
|
|
import { readFile, writeFile } from 'fs/promises';
|
|
import { join } from 'path';
|
|
import {
|
|
applyToolkitVersions,
|
|
fetchProductionToolkitVersions,
|
|
} from './toolkit-versions';
|
|
|
|
interface Toolkit {
|
|
slug: string;
|
|
version: string | null;
|
|
[key: string]: unknown;
|
|
}
|
|
|
|
const TOOLKITS_PATH = join(process.cwd(), 'public/data/toolkits.json');
|
|
|
|
export async function refreshToolkitVersions(apiKey: string): Promise<void> {
|
|
const raw = await readFile(TOOLKITS_PATH, 'utf-8');
|
|
const toolkits = JSON.parse(raw) as Toolkit[];
|
|
|
|
if (!Array.isArray(toolkits)) {
|
|
throw new Error('Expected public/data/toolkits.json to contain an array');
|
|
}
|
|
|
|
const versionMap = await fetchProductionToolkitVersions(apiKey);
|
|
const { matched, missing } = applyToolkitVersions(toolkits, versionMap);
|
|
|
|
await writeFile(TOOLKITS_PATH, JSON.stringify(toolkits, null, 2));
|
|
console.log(`Updated ${matched} toolkit versions from production; ${missing} set to null`);
|
|
}
|
|
|
|
if (import.meta.main) {
|
|
const apiKey = process.env.COMPOSIO_API_KEY;
|
|
if (!apiKey) {
|
|
console.error('Error: COMPOSIO_API_KEY environment variable is required');
|
|
process.exit(1);
|
|
}
|
|
|
|
refreshToolkitVersions(apiKey).catch((error) => {
|
|
console.error('Fatal error:', error);
|
|
process.exit(1);
|
|
});
|
|
}
|