## Problem
On
[docs.copilotkit.ai/built-in-agent/build-with-agents](https://docs.copilotkit.ai/built-in-agent/build-with-agents),
**"JSON Configuration File"** shows a blank panel.
<img width="789" height="99" alt="image"
src="https://github.com/user-attachments/assets/1f8d8c4a-c5fb-4d59-9d3e-785352a3bf5c"
/>
## Why
Our `Tab` wrapper called `escapeValue()` before passing to Fumadocs's
`FumadocsTab` — which also calls it internally. For 3-word labels, the
double-escape produces different values for the trigger vs the content
panel, so Radix hides the content.
```
"JSON Configuration File"
→ trigger (1 pass): json-configuration file ← space
→ content (2 passes): json-configuration-file ← hyphen (mismatch → hidden)
```
## Fix
Remove `escapeValue()` from the `Tab` wrapper — Fumadocs already handles
it. The `Tabs` `defaultValue` still needs pre-escaping since
`FumadocsTabs` doesn't apply it internally.
Fumadocs's Tab component applies escapeValue() internally to the value
prop. Our DocsTab wrapper was also calling escapeValue() before passing
to FumadocsTab, causing multi-word tab values to be escaped twice.
For "JSON Configuration File" (3 words, 2 spaces):
1st escape (our wrapper): "json-configuration file" (1 space left)
2nd escape (Fumadocs Tab): "json-configuration-file" (fully hyphenated)
The trigger value uses only ONE escapeValue call:
escapeValue("JSON Configuration File") = "json-configuration file"
Trigger "json-configuration file" != content "json-configuration-file"
so Radix sets data-state="inactive" on the content panel, which is
then hidden by data-[state=inactive]:hidden.
Fix: remove escapeValue() from our Tab wrapper. The Tabs defaultValue
still needs pre-escaping because FumadocsTabs accepts it as-is (no
internal escape); only the individual Tab has internal escaping.
Single-word and two-word tabs (HTTP, Application Settings) were
unaffected because one escapeValue pass already produces a hyphen-only
string that is idempotent under a second pass. Same bug also affected
"stdio Transport (Local)" in the Windsurf section.
Three classes of legacy URLs were 404'ing because shell-docs (with BIA
as the soft-default framework) doesn't serve them at the root surface
the old docs did:
1. BIA-canonical pages — /server-tools, /mcp-servers, /model-selection,
/advanced-configuration, /agent-app-context live only under
/built-in-agent/ now. Internal sidebar clicks already framework-scope
via SidebarLink; external traffic (marketing, blog posts, bookmarks)
was 404'ing.
2. Moved root pages — /mcp-apps (moved to /generative-ui/),
/copilot-runtime, /custom-agent (moved to /backend/), /deep-agents
(renamed to /deepagents), /multi-agent-flows (LangGraph-only),
/custom-look-and-feel folder index, /generative-ui/specs/* (specs
subgroup retired), plus assorted misc (/what-is-copilotkit,
/getting-started/quickstart-chatbot, /telemetry, /migration-guides/*,
/reference/hooks/useCoAgent).
3. Legacy /integrations/<fw>/* prefix — R15/R17 already handled the
built-in-agent variant; this extends the same pattern to every other
framework, mirroring the existing /docs/integrations/* coverage.
All redirect destinations verified to return 200 against a local dev
build; existing tests still pass.
## What does this PR do?
Fixes#4995 in the Python SDK by making `LangGraphAGUIAgent.dict_repr()`
build its metadata directly instead of calling `super().dict_repr()`.
### Problem description
`CopilotKitRemoteEndpoint.info()` crashed with `AttributeError: 'super'
object has no attribute 'dict_repr'` whenever a registered agent was a
`LangGraphAGUIAgent`. That made the runtime info endpoint unusable for
LangGraph CoAgent setups.
### Root cause
`LangGraphAGUIAgent` inherits from AG-UI's `LangGraphAgent`, and that
upstream base class does not implement `dict_repr()`. The existing
implementation called `super().dict_repr()`, so Python resolved to
`object` and raised `AttributeError`.
### Fix
- Replace the `super().dict_repr()` call with an explicit metadata dict
built from `self.name` and `self.description`
- Preserve the existing CopilotKit-specific `type: "langgraph_agui"`
field
- Add regression coverage for both `dict_repr()` and
`CopilotKitRemoteEndpoint.info()`
## Related PRs and Issues
- Fixes#4995
## Testing
- [x] `python3 -m pytest sdk-python/tests/test_agui_agent.py -q`
- [x] `python3 -m pytest sdk-python/tests/test_agui_agent.py
sdk-python/tests/test_agui_context_serializable.py
sdk-python/tests/test_emit_filtering.py -q`
- [x] `python3 -m pytest sdk-python/tests -q`
- [x] Manual verification that `CopilotKitRemoteEndpoint.info()` returns
serialized LangGraph AGUI agent metadata without raising
## Checklist
- [x] I have read the [Contribution
Guide](https://github.com/copilotkit/copilotkit/blob/master/CONTRIBUTING.md)
- [ ] If the PR changes or adds functionality, I have updated the
relevant documentation
- [x] "Allow edits by maintainers" is checked (lets us help iterate on
your PR directly — faster turnaround for everyone)
Three classes of legacy URLs were 404'ing because shell-docs (with BIA
as the soft-default framework) doesn't serve them at the root surface
the old docs did:
1. BIA-canonical pages — /server-tools, /mcp-servers, /model-selection,
/advanced-configuration, /agent-app-context live only under
/built-in-agent/ now. Internal sidebar clicks already framework-scope
via SidebarLink; external traffic (marketing, blog posts, bookmarks)
was 404'ing.
2. Moved root pages — /mcp-apps (moved to /generative-ui/),
/copilot-runtime, /custom-agent (moved to /backend/), /deep-agents
(renamed to /deepagents), /multi-agent-flows (LangGraph-only),
/custom-look-and-feel folder index, /generative-ui/specs/* (specs
subgroup retired), plus assorted misc (/what-is-copilotkit,
/getting-started/quickstart-chatbot, /telemetry, /migration-guides/*,
/reference/hooks/useCoAgent).
3. Legacy /integrations/<fw>/* prefix — R15/R17 already handled the
built-in-agent variant; this extends the same pattern to every other
framework, mirroring the existing /docs/integrations/* coverage.
All redirect destinations verified to return 200 against a local dev
build; existing tests still pass.
## What does this PR do?
Add complimentary TypeScript examples now that the TypeScript Strands
integration (`@ag-ui/aws-strands`) has been published.
## Related PRs and Issues
- https://github.com/ag-ui-protocol/ag-ui/pull/1681
## Checklist
- [x] I have read the [Contribution
Guide](https://github.com/copilotkit/copilotkit/blob/master/CONTRIBUTING.md)
- [x] If the PR changes or adds functionality, I have updated the
relevant documentation
- [x] "Allow edits by maintainers" is checked (lets us help iterate on
your PR directly — faster turnaround for everyone)
## Why
npm OIDC trusted publishers match on the **caller's** `workflow_ref`
claim, not the callee's `job_workflow_ref`. The PR-A / PR-B
reusable-workflow architecture was structurally incompatible with that
matching rule: any prerelease publish dispatched via a separate
`prerelease.yml` caller would present a `workflow_ref` that npm's
trusted-publisher records (registered against `publish-release.yml`)
would reject.
The canonical fix used by Storybook, Nx, and Vite is a single-workflow
pattern: one entry-point workflow that branches internally on a `mode`
input. That's what this PR implements.
## What
- **Deletes** `.github/workflows/prerelease.yml`.
- **Refactors** `.github/workflows/publish-release.yml` to handle both
`stable` and `prerelease` modes via `workflow_dispatch` inputs (`mode`,
`suffix`, `dry-run`).
- Adds a `Bump prerelease versions` step in the build job (gated on
`mode == 'prerelease'`) that validates the user-supplied suffix against
`[a-zA-Z0-9._-]+` and falls back to the script's timestamp default when
the suffix input is empty.
- Mode-aware publish script selection (`prerelease.ts` vs
`publish-release.ts`) via env var on the publish step.
- Mode-aware gating on tag creation, GitHub Release creation, Notion
notification, and the release-summary step — all skipped for
prereleases.
- Adds a `Verify publish step emitted version` step that aborts if the
publish script didn't emit a `version` output (would otherwise produce
blank-version summaries and malformed tags/releases).
## Evidence
A dry-run dispatched against this workflow file completed all build +
publish stages successfully (publish step skipped via `dry-run=true`,
summary rendered correctly). The verification canary run `26544606752`
failed against pre-PR-C `main`, confirming that the PR-A/PR-B
architecture cannot pass OIDC and that PR-C is required.
## Code Review
- **Round 1:** 7-agent CR returned 5 consensus Bucket B findings (suffix
validation, version-emission verification, mode-aware tag/release gating
wording, comment cleanups). All applied.
- **Round 2:** 7-agent CR confirmation returned **zero Bucket A
findings**. Two trivial additive nits applied in the final commit: `set
-euo pipefail` on the new verification step for consistency with every
other shell step in the file, and a leading comment on the `Bump
prerelease versions` step explaining the validation logic.
Prerelease canary publishing is now an input mode on publish-release.yml's
workflow_dispatch. The dedicated prerelease.yml workflow is no longer
reachable and its workflow_call delegation never worked (npm matches the
OIDC token's caller `workflow_ref`, which was always prerelease.yml —
unregistered with any package's trust record).
Canaries are now dispatched via:
gh workflow run publish-release.yml \
-f scope=monorepo -f mode=prerelease -f suffix=<name>
The `bump-prerelease.ts` and `prerelease.ts` scripts remain unchanged; they
are invoked by publish-release.yml when `mode=prerelease`.
Folds prerelease.yml's canary publishing back into publish-release.yml, which
is the workflow registered as npm trusted publisher for all 15 @copilotkit/*
monorepo packages and @copilotkitnext/angular. Since npm matches on the OIDC
token's `workflow_ref` claim (the caller), the canary must dispatch from THIS
workflow file — not from a separate workflow that delegates via workflow_call.
Changes:
- Add `mode` (stable|prerelease) and `suffix` inputs to workflow_dispatch.
`mode` selects the publish script and gates post-publish tag/release steps;
`suffix` is forwarded to bump-prerelease.ts when mode=prerelease.
- Add a conditional `Bump prerelease versions` step in the build job that
runs `scripts/release/bump-prerelease.ts` before `Build packages` whenever
`inputs.mode == 'prerelease'`. The bumped versions flow through the
workspace artifact to the publish job exactly as in the deleted
prerelease.yml.
- Switch the publish step's `PUBLISH_SCRIPT` env var to be mode-driven:
`prerelease.ts` for canaries, `publish-release.ts` for stable. The old
`inputs.publish-script` plumbing was removed in the prior commit along
with the workflow_call inputs schema.
- Simplify the publish-job `meta` step now that workflow_call is gone: mode
defaults to `stable` unless workflow_dispatch passes `prerelease`.
- Rewrite the top-of-file comment to document both modes and the OIDC trust
binding, replacing the old "MANUAL RETRIGGER" wording which only covered
the stable retrigger path.
All post-publish gating (`steps.meta.outputs.mode != 'prerelease'` on the tag,
release, and stable-summary steps; `mode == 'prerelease'` on the prerelease
summary) was already in place from the prior PR-A architecture and is left
intact. The `Verify publish step emitted version` step keeps its prerelease
bypass.
Canary invocation after this lands:
gh workflow run publish-release.yml \
-f scope=monorepo -f mode=prerelease -f suffix=<name>
The workflow_call trigger was added in the PR-A/B architecture so prerelease.yml
could invoke this workflow as a reusable workflow. That architecture was wrong:
npm's trusted-publisher matching uses the OIDC token's `workflow_ref` claim,
which is the CALLER workflow (prerelease.yml), not the callee's
`job_workflow_ref` (publish-release.yml). Since prerelease.yml has no trust
record, every canary attempt failed at the npm publish step with ENEEDAUTH.
This commit removes the dead code:
- workflow_call: trigger block (inputs schema + secrets block)
- the `github.event_name != 'workflow_call'` guard on the build job
- the `needs.build.result == 'skipped' && github.event_name == 'workflow_call'`
branch on the publish job's `if:` (simplified to plain success check)
The follow-up commit folds prerelease support back into this workflow as a
`workflow_dispatch` mode, so the canary path executes from the workflow with
the trust record.
The @ag-ui/aws-strands TypeScript adapter ships alongside the Python
ag_ui_strands package but the docs only showed Python snippets. Add a
TypeScript tab next to every Python snippet (Python default, `persist`
on the tab group so a reader's choice sticks across pages) covering:
- quickstart: project init, install, agent file, run command
- frontend-tools: @tool stub + createStrandsApp server
- shared-state (read + write): StrandsAgentConfig.stateContextBuilder
- generative-ui tool-rendering: backend tool definition
- generative-ui state-rendering: ToolBehavior.stateFromArgs
Also applied to the parallel showcase/shell-docs tree. Non-code pages
(deploy-agentcore, copilot-runtime, inspector, etc.) remain untouched
since they either re-export shared snippets or have no framework code.
## Summary
- Inline MDX helpers imported from `@/snippets/...` recursively by
import target
- Remove the `ComponentExamples` SNIPPET_MAP workaround
- Add focused regression coverage for snippet helper imports and runtime
component imports
## Tests
- `npm test` in `showcase/shell-docs`
- `npm run typecheck` in `showcase/shell-docs`
- `npm run lint` in `showcase/shell-docs` (passes with existing
warnings)
- `npm run build` in `showcase/shell-docs`
- pre-commit: root package tests and package checks via lefthook
## Why
Follow-up to #5063. Together they unblock customer canary publishes that
have been failing with `npm ENEEDAUTH` since 2026-05-15.
#5063 parametrized `publish-release.yml` to support `workflow_call`.
This PR converts `prerelease.yml`'s publish path into a thin caller of
that reusable workflow. Because npm OIDC's `job_workflow_ref` claim
resolves to the callee in a reusable-workflow invocation, the existing
trust record on `publish-release.yml` covers both stable AND canary
publishes — no second trusted-publisher record needed (npm only allows
one per package).
## What changes
- `prerelease.yml`'s `build` job is preserved verbatim (checkout,
install, `bump-prerelease.ts --suffix`, build, test, upload `workspace`
artifact).
- The old `publish` job is replaced with `uses:
./.github/workflows/publish-release.yml` with `mode: prerelease`,
`publish-script: prerelease.ts`, `scope`, `dry-run`.
- The caller's `publish` job grants explicit `permissions: { contents:
write, id-token: write, actions: read }` — REQUIRED for the callee's npm
OIDC mint (per GitHub Actions, caller's per-job permissions cap the
callee's declared permissions).
- The caller's `workflow_dispatch.inputs.dry_run` (underscore, preserved
for backwards compat) maps to the callee's `dry-run` (hyphen) at the
`with:` boundary.
- No `secrets:` block — Notion not needed for prereleases; callee
declares `NOTION_API_KEY` optional and gates it on `mode == 'stable'`.
## Verification plan
1. Dispatch `prerelease.yml` with `scope: monorepo`, `suffix:
test-oidc-refactor`, `dry_run: true` → confirms plumbing without an
actual publish.
2. Dispatch again with `dry_run: false` → first OIDC-handshake-verifying
real canary.
3. `npm view @copilotkit/runtime@1.58.0-canary.test-oidc-refactor --json
| jq '.dist.attestations'` → confirm provenance attestation references
`publish-release.yml`.
## Test plan
- [ ] CI green.
- [ ] Post-merge: dispatch dry-run + real canary per Verification plan
above.
- [ ] Confirm provenance attestations land via `npm view`.
Supersedes #5066 (closed when #5063's base branch was deleted).
## Summary
- Bundle Inter Medium/Bold locally for shell-docs OG image rendering and
pass them to ImageResponse.
- Localize the OG background and CopilotKit logo as data URIs so the
route avoids render-time remote image fetches.
- Add route tests for valid image construction, unknown slug 404
propagation, render failure 500 behavior, and framework-scoped slug
resolution.
## Verification
- pnpm test in showcase/shell-docs (36 passed)
- pnpm lint in showcase/shell-docs (exits 0; existing warnings only)
- Local dev-server curl: /og/quickstart/og.png returned 200 image/png,
valid 1200 x 630 PNG
- Local dev-server curl: /og/does-not-exist/og.png returned 404
- Commit hook ran test-and-check-packages successfully
## Notes
- showcase/shell-docs is not present in the Nx project graph, so there
was no direct shell-docs Nx target to run.
- pnpm typecheck / pnpm build for standalone shell-docs currently fail
on pre-existing src/lib/rehype-code-meta.ts missing shiki types.
## Summary
- Unify authored and generated shell-docs navigation so the sidebar
keeps the same structure across framework modes.
- Restore setup-content bundling from integration-owned docs and wire
shell-docs to consume the generated bundle at runtime.
- Audit and fix the LangGraph TypeScript and Google ADK code regions so
the generated snippets are more useful and accurate.
- Tighten docs/build routing and workflow triggers so shell-docs
rebuilds when the relevant integration docs inputs change.
## Testing
- Shell-docs unit tests passed.
- Shell-docs typecheck passed.
- Shell-docs lint passed with existing repository warnings only.
- Setup-content bundle generation passed.
- Python integration files compiled successfully.
- Workflow YAML parsed successfully.
## Summary
- Restore the missing NewLookAndFeelPreview component for shell-docs
troubleshooting migration pages.
- Wire the MDX registry to render the real preview instead of an empty
shim.
## Verification
- npm --prefix showcase/shell-docs run typecheck
- npm --prefix showcase/shell-docs run lint (warnings only,
pre-existing)
- Browser verified
http://localhost:3003/built-in-agent/troubleshooting/migrate-to-1.8.2:
preview launcher renders and opens populated panel
- git commit pre-commit hooks passed: check-binaries, lint-fix,
test-and-check-packages
## Notes
- @copilotkit/showcase-scripts:verify-shell-docs:fast runs but fails on
existing broad shell-docs dead-link/import/content backlog unrelated to
PDX-203.
- Production next build hung locally after content generation with no
diagnostics; verified the affected route via dev server instead.
PR-B CR-r1 fix: reusable-workflow permissions in GitHub Actions are capped by
the caller's per-job permissions. The callee (publish-release.yml from PR-A)
declares id-token: write + contents: write on its publish job, but without
the caller (prerelease.yml) granting those at its own publish-job level, the
callee gets only the workflow-level default (contents: read). The OIDC token
mint then fails silently and npm publish errors.
4 of 7 CR agents independently flagged this. The spec missed it.
Adds contents: write (callee uses it in stable mode; gated off in prerelease
but matches the callee's declaration), id-token: write (required for OIDC),
and actions: read (required for actions/download-artifact in callee).
Spec updated to document this requirement.
PR-B of the two-PR refactor: prerelease.yml's build job is preserved verbatim
(checkout, install, bump-prerelease.ts with --suffix, build, test, upload-
artifact "workspace"); its publish job is replaced with a workflow_call
invocation into publish-release.yml from PR-A. The reusable workflow's
job_workflow_ref OIDC claim matches the existing trusted-publisher record on
publish-release.yml, so the canary publishes succeed without registering a
second trust binding (which npm does not allow).
The caller's workflow_dispatch.inputs.dry_run (underscore, preserved) maps
to the callee's dry-run (hyphen) at the with: boundary — independent keys
in independent namespaces. No secrets passed; Notion not needed for
prereleases.
Spec: https://www.notion.so/36d3aa381852811ba10ad1bcd228d6d8
Unblocks: @copilotkit/react-core canary --suffix thread-id-propagation.
Stacked on PR-A (fix/publish-release-workflow-call).
## Why
The `release / pre` workflow (`prerelease.yml`) has been failing with
`npm ENEEDAUTH` on every run since 2026-05-15 — see e.g. run
`26529550757`. Customer canary publishes are blocked.
Root cause: npm enforces **exactly one** trusted publisher per package.
All 16 monorepo-scoped packages (15 `@copilotkit/*` +
`@copilotkitnext/angular`) are bound to `publish-release.yml @
CopilotKit/CopilotKit`. `prerelease.yml` cannot register as a second
trusted publisher and therefore cannot complete the OIDC handshake.
## Fix (sequenced)
**This PR (PR-A)** parametrizes `publish-release.yml` so it can also be
invoked via `workflow_call`. A follow-up PR (PR-B) converts
`prerelease.yml` into a thin caller of this workflow. Because npm OIDC's
`job_workflow_ref` claim resolves to the *callee* in a reusable-workflow
invocation, the existing trust record on `publish-release.yml` covers
both the stable and canary publish paths — no npm UI changes, no second
trusted publisher.
## What changes
- New `workflow_call:` trigger with input schema (`scope`, `mode`,
`dry-run`, `publish-script`) and optional `NOTION_API_KEY` secret.
- New `dry-run` input on the existing `workflow_dispatch` trigger
(enables this PR's own post-merge verification via a sacrificial release
branch).
- New `meta` step in the publish job unifying scope+mode resolution
across all 3 event types (`pull_request`, `workflow_dispatch`,
`workflow_call`).
- Build job gated to skip on `workflow_call` (the caller provides the
artifact).
- Publish job `if:` override allows skipped-`needs.build` *only* when
`event_name == 'workflow_call'` (prevents phantom publish on
`pull_request: closed` without merge).
- All post-publish steps gated on `success() && inputs.dry-run != true
&& steps.meta.outputs.mode != 'prerelease'` so tag push and GH Release
are only created on a successful stable publish.
- `NOTION_API_KEY` env wiring gated on `mode == 'stable'`.
- `Release summary` split into three variants (stable / prerelease /
dry-run) so the summary never lies about what actually happened.
- New `Verify publish step emitted version` guard between npm publish
and tag creation.
- `inputs.publish-script` and `steps.meta.outputs.scope` passed via
`env:` (defense-in-depth shell hygiene).
- Concurrency key kept static (`publish-release`) — explicit decision,
documented in the spec.
## Verification plan (post-merge, before PR-B)
1. Cut a sacrificial release branch (e.g.
`release/publish/monorepo/v0.0.0-test`).
2. Dispatch `publish-release.yml` via `workflow_dispatch` with
`scope=monorepo`, `dry-run=true`.
3. Confirm the new gating logic, scope/mode resolution, and artifact
handoff all work end-to-end without an actual npm publish (the publish
step is skipped under `dry-run`). Note: `dry-run` does NOT exercise the
OIDC handshake — that is verified by PR-B's first real canary.
## Test plan
- [ ] CI green on the PR.
- [ ] After merge: sacrificial-branch `workflow_dispatch` with
`dry-run=true` runs cleanly and emits the "Dry Run Completed" summary.
- [ ] No regression to stable releases — verified by next real stable
release using the existing `pull_request: closed` path.
## Summary
- Disabled Fumadocs search in `showcase/shell-docs` so Cmd/Ctrl+K no
longer opens the built-in dialog.
- Centralized the custom search modal behind a single app-level
provider/event bridge so desktop and mobile triggers share one instance.
- Kept the custom search button and hotkey behavior intact, including
Escape to close.
## Testing
- `npm run typecheck` in `showcase/shell-docs` passed.
- `npm run lint` in `showcase/shell-docs` passed with pre-existing
warnings only.
- Verified locally in the in-app browser that Cmd+K opens one custom
search modal, Escape closes it, and no Fumadocs search dialog appears.
## Summary
- Bumps `@ag-ui/langgraph` from `0.0.33` to `0.0.34` across runtime,
sdk-js, and the showcase langgraph-typescript integration.
- Picks up the forwarded-headers fix from ag-ui PR #1798:
https://github.com/ag-ui-protocol/ag-ui/pull/1798
## Why
`@ag-ui/langgraph@0.0.34` injects `agent.headers` as
`config.configurable.copilotkit_forwarded_headers` inside
`prepareStream`. This means the X-AIMock-Context header (and any other
X-* header) reliably reaches the CopilotKit Python middleware regardless
of whether the LangGraph dev server has the
`LANGGRAPH_HTTP=configurable_headers` bridge enabled. This closes the
header-propagation gap that was preventing showcase D5/D6
langgraph-typescript probes from going green.
## Test plan
- [ ] CI green
- [ ] D5/D6 langgraph-typescript probes go GREEN after merge + deploy
## Risk
The ag-ui PR's `dojo / langgraph-typescript` CI was flaky on the rerun
(passed on the 2nd attempt after 3-retry exhaustion on the 1st). Watch
the showcase D6 langgraph-typescript probe closely after deploy.
Commit 0a24b5c430 attempted to regenerate the outer lockfile but produced
invalid JSON (trailing commas, JSON5-style formatting from a non-npm
tool). Docker stage 1 (frontend) npm ci --legacy-peer-deps fails with
EUSAGE "can only install with an existing package-lock.json" because npm
refuses to parse it.
This commit regenerates the file via `npm install --package-lock-only
--legacy-peer-deps` to produce a strict-JSON lockfile pinning
@ag-ui/langgraph@0.0.34. Diff is large because the prior file's
formatting differs structurally from canonical npm output.
PR-A CR-r2 fixes (2 bucket-(a) findings from 7-agent confirmation round).
A4: Tighten publish-job `if:` so `needs.build.result == 'skipped'` is only honored when
the event is `workflow_call` (the intentional skip for the reusable workflow callee).
Previously, a `pull_request: closed` event on a release branch where the PR was closed
WITHOUT merging would cause the build job to skip (its own merged-true guard), then the
publish job's permissive `if:` would still run it — a phantom publish from an unmerged
release PR.
A5: Every post-publish step's custom `if:` overrode the default implicit `success()`
check, meaning a failure in `Publish to npm` or the `Verify version` guard would not
prevent downstream steps (tag push, GitHub Release create) from running. Prepended
`success() && ` to all post-publish step `if:` conditions to restore the implicit gate.
Spec: https://www.notion.so/36d3aa381852811ba10ad1bcd228d6d8