Commit Graph

13442 Commits

Author SHA1 Message Date
Jordan Ritter 55afcf4365 fix(showcase): harden prod D0-gone monitor (CR round 1)
Bucket-(a) fixes, each with a local red-green test:

- A1: replace the substring `:${slug}` onset match with an anchored
  exact slug-segment match (`keyBelongsToSlug`) so a prefix-colliding
  sibling (`strands` vs `strands-typescript`) no longer mis-attributes
  the earlier sibling's red onset. RED: strands' sinceAt was pulled to
  the strands-typescript onset; GREEN: each slug gets its own onset.
- A2: recovery/CLOSE is now SYMMETRIC with OPEN — a recovery requires a
  second agreeing fresh-healthy read (confirm scan). RED: a single
  transient healthy read fired a false "recovered"; GREEN: held until
  two reads agree.
- A3: guard an empty/degenerate schedule set — longestPeriodMs 0/NaN
  would make idleWindowMs 0 → isProducerLive permanently false → the
  monitor SUSPENDS forever and never pages. Falls back to a 45m default
  window (DEFAULT_IDLE_WINDOW_MS) and logs at error.
- A4: bound readStatusRows — guard NaN/undefined totalPages (a `page >=
  NaN` break never trips) and add a hard MAX_STATUS_PAGES cap so a full
  page + bad totalPages cannot infinite-loop/OOM. RED: OOM; GREEN:
  terminates at the cap.
- A5: a registry-load failure logs at error with a stable errorId (not a
  silent warn-once permanent no-op), and the monitor accepts a loader
  thunk so it re-reads registry.json each tick while the wired-cell set
  is empty — a transiently-missing file self-heals without a redeploy.
- A6 (verified, no code change): createSlackWebhookTarget already throws
  on every non-2xx (4xx/5xx/429/3xx/network-exhausted); added a test
  asserting the monitor does NOT delete recovery state when the post
  throws.

Bucket-(b): stamp the recovery message with the confirm-scan instant
(evidenceMs) not tick-start; wrap the scheduler tick handler in a
catch+errorId; log the prod env-gate skip at warn with a reason; add a
clarifying comment that the aggregate lastAlertAt reset is intentional
one-message-one-clock cadence; simplify the three dashboard barrel-shim
comments (drop the rot-prone enumerated symbol lists).
2026-07-13 14:30:24 -07:00
Ben Taylor 6ef59ca8a2 fix(core,react-core): defer runtime /info out of the core constructor (#5801) (#5942)
Fixes #5801.

## Problem

`CopilotKitProvider` constructs the core **during render** (the `useRef`
init pattern), and the `CopilotKitCore` constructor synchronously starts
the `/info` network request. React can start-and-discard renders
(concurrent rendering / Suspense / StrictMode), and for a *mounting*
fiber `copilotkitRef.current` is `null` again on each discarded attempt
— so a brand-new core is constructed, and fires its own `/info`, per
discarded render. The reporter observed **70–80 `/info` requests on a
single page load** (production build, self-hosted runtime with real
latency).

Root causes (all confirmed on current `main`):
1. Core constructed during render — `CopilotKitProvider.tsx`.
2. Constructor kicks off network I/O — ctor → `setRuntimeUrl` →
`updateRuntimeConnection()` → `fetch(/info)`.
3. `updateRuntimeConnection()` had no in-flight guard.

The dominant multiplier is **cross-instance** (N discarded renders → N
cores → N fetches), so an in-flight guard alone can't fix it — the fetch
must not fire during construction.

## Fix

Separate **construction** (pure) from **connection** (network I/O), as
the issue recommends:

- **core** — new `deferInitialConnection` option: the constructor
records the runtime config (so `copilotkit.runtimeUrl` stays available
*synchronously* to hooks like `use-threads` / the CopilotChat context —
no first-render regression) but does **not** start the `/info` fetch. A
new `connect()` method starts the single connection; it's idempotent
(no-op unless status is `Disconnected`, which `updateRuntimeConnection`
flips to `Connecting` synchronously), so a StrictMode double-invoked
mount effect collapses to one request. `updateRuntimeConnection` also
gains an in-flight guard keyed by `url + requested transport` so
concurrent same-target calls de-dupe (a change to a different target
supersedes).
- **react-core** — the provider constructs with `deferInitialConnection:
true` and calls `copilotkit.connect()` from its existing commit-phase
mount effect. Renders discarded before commit never reach the effect, so
they never fetch. The subscribe effect runs before `connect()`, so the
status-change event is caught (no reliance on the catch-up read for the
common path).

**Backward compatible:** without `deferInitialConnection`, the
constructor still connects — Vue/Angular/vanilla consumers are
unaffected.

## Testing

- **TDD.** New core tests fail on the pre-fix code (constructor fetches)
and pass after.
- **core** (`core-defer-runtime-connection.test.ts`, 7 tests) — the
authoritative proof of the mechanism: deferred construct fires **zero**
`/info`; `runtimeUrl` still exposed synchronously; `connect()` → exactly
one `/info`; `connect()` idempotent across repeated calls; **N orphaned
cores that never `connect()` → 0 fetches, only the committed one
fetches** (directly models the discarded-render bug); in-flight de-dupe;
backward-compat.
- **react-core** (`CopilotKitProvider.deferWiring.test.tsx`) — asserts
the provider constructs with `deferInitialConnection: true` and drives
`connect()` from an effect; **this is the provider-level test that
distinguishes the fix from the bug** (it fails if the deferral wiring is
dropped — verified by reverting).
- **react-core** (`CopilotKitProvider.deferConnection.test.tsx`, 2
tests) — normal-mount regression guards: exactly one `/info` on mount,
and one under `React.StrictMode`.

*Scope note (found via adversarial review):* the raw dozens-of-`/info`
symptom only manifests with React *discarding* in-progress renders and
constructing multiple orphaned cores — Testing Library can't reproduce
that (a single committed mount yields one `/info` either way, and the
ctor's fetch is several microtasks deep so ordering can't distinguish
it). Hence the multi-instance proof lives in the core test above, and
the provider is guarded by the wiring assertion.

- Full suites green: **core 576/576**, **react-core provider 141/141**
(updated one fake-core mock to implement `connect()`). `tsc` 0 errors
(core + react-core); `oxlint` 0 errors; `oxfmt` clean.

🤖 Generated with [Claude Code](https://claude.com/claude-code)
2026-07-13 16:29:59 -05:00
Benjamin Taylor 690108bfd6 test(react-core): strengthen #5801 provider coverage to actually catch ctor-fetch
Adversarial review found the original provider tests passed even with the fix
removed: a single committed mount yields exactly one /info whether the ctor or
an effect fires it, and the ctor's fetch is several microtasks deep so ordering
can't distinguish it — only the multi-instance (discarded-render) case differs,
which Testing Library can't reproduce.

- Add CopilotKitProvider.deferWiring.test.tsx (mocked core): asserts the provider
  constructs with `deferInitialConnection: true` and calls `connect()` from an
  effect. This FAILS if the deferral wiring is dropped (verified).
- Keep the two real-core tests as normal-mount regression guards (one /info on
  mount; idempotent under StrictMode) and document that the multi-instance proof
  lives in core-defer-runtime-connection.test.ts.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-07-13 16:21:22 -05:00
github-actions[bot] 6ab7e9d3d6 style: auto-fix formatting 2026-07-13 16:21:22 -05:00
Benjamin Taylor ce2d52397d fix(core,react-core): defer runtime /info out of the core constructor (#5801)
CopilotKitProvider constructs the core during React's render phase, and React
can start-and-discard renders (concurrent rendering / Suspense / StrictMode).
Because the constructor fired the `/info` request synchronously, every discarded
-and-recreated core issued its own request — a single page load was observed
firing 70-80 `/info` requests instead of one.

Separate construction (pure) from connection (network I/O):

- core: `deferInitialConnection` lets the constructor record the runtime config
  (so `runtimeUrl` stays available synchronously to hooks) WITHOUT starting the
  `/info` fetch. `connect()` starts the single connection and is idempotent
  (bails unless status is Disconnected), so a double-invoked mount effect
  collapses to one request. `updateRuntimeConnection` also gains an in-flight
  guard keyed by url+transport so concurrent same-target calls de-dupe.
- react-core: the provider constructs with `deferInitialConnection: true` and
  calls `copilotkit.connect()` from its commit-phase mount effect — so renders
  discarded before commit never fetch.

Backward compatible: without `deferInitialConnection` the constructor still
connects (Vue/Angular/vanilla unaffected).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-07-13 16:21:22 -05:00
Jordan Ritter 2481510c2b feat(showcase): prod D0-gone monitor
Add a harness-native monitor that pages #oss-alerts when a whole
integration column collapses to red-D0 ("completely gone" / backend
unreachable) in production — the incident class the per-cell alert rules
miss (LGT went fully gone on 2026-07-13 and nothing paged).

Detection runs the dashboard's OWN buildCellModel fold (the shared
cell-model module both the dashboard and the monitor import) over the
same PocketBase status rows and applies a column-gone predicate over the
resulting CellModel fields, so the monitor's verdict equals the DepthChip
the dashboard renders by construction — no parallel re-derivation.

- d0-gone-predicate.ts: pure cellGone/columnGone/columnFreshHealthy over
  buildCellModel outputs + registry-derived wired-cell enumeration
  (mirrors the dashboard page-stats iteration / determineCellStatus rule).
- d0-gone-monitor.ts: createD0GoneMonitor factory — producer-liveness
  SUSPENDED gate (reuses the family-silence inflight-aware /api/runs
  reasoning, 3x-longest-period idle window), 60s confirm re-read (never a
  re-probe), 15m-detect vs 1h-repost state machine, positive-fresh-healthy
  CLOSE gate, ONE aggregated outage / consolidated recovery Slack message,
  durable per-slug JSON map in alert_state (getSet/putSet).
- orchestrator.ts: register internal:prod-d0-gone-monitor @ */15, gated on
  SHOWCASE_ENV ?? RAILWAY_ENVIRONMENT_NAME === production + kill-switch,
  control-plane-only (inside runControlPlane), reusing the oss_alerts
  webhook target + shared memoized family summary.
- unified-cell.test.tsx: add the required isStaleCell/observedAtAgeMs
  fields to the CellModel test literal (Phase-1 dashboard tsc gate).

Red-green: a frozen test-only naiveGone (achievedDepth===0 alone)
mislabels gray-D0-no-data and stale columns as gone on committed
fixtures (RED); the real predicate fires only on red-D0-fresh and matches
buildCellModel's own outputs (GREEN). Producer-idle SUSPENDED proven
load-bearing (disabling the gate flips both F1 tests red). Plus
confirm-scan blip-rejection, hourly dedup, recovery-clear, failure modes,
and the prod-only/kill-switch registration gate.
2026-07-13 14:09:56 -07:00
Sam Julien 7c1eb25f65 docs(shell-docs): link both LangGraph thread UIs 2026-07-13 13:46:36 -07:00
Jordan Ritter d2451be0ed refactor(showcase): relocate pure cell-model fold into harness shared/
Move the pure cell-classification fold cluster (cell-model, live-status,
staleness, format-ts) out of showcase/shell-dashboard/src/lib/ into
showcase/harness/src/shared/cell-model/ so BOTH the dashboard and a new
harness monitor import ONE copy with zero duplication and no behavior change.

The harness builds via tsc -p tsconfig.build.json with rootDir:"src" and
cannot import outside its own src/, so the harness is the correct library
home. The dashboard consumes the cluster via relative path across the package
boundary (established precedent, e.g. d5-cadence-banner.redgreen.test.ts).

- git mv the four files into harness shared/cell-model/; their intra-cluster
  relative imports stay valid (they move together, no external coupling).
- Replace the four original shell-dashboard paths with thin export-* barrels
  so all ~51 existing dashboard import sites resolve unchanged.
- Repoint commError-contract-drift.test.ts's source-text drift parse at the
  new canonical harness location (the barrels carry no derivation body).
- Add cell-model.equivalence.test.ts + committed fixtures + a pre-move
  baseline JSON (generated from the original git-HEAD code) proving the move
  is byte-identical across a red-D0, gray no-data, stale, mixed, all-green,
  and unsupported column.
2026-07-13 13:46:31 -07:00
Sam Julien 5da3a672fb docs(shell-docs): refine CLI import guidance 2026-07-13 13:42:36 -07:00
Sam Julien ec043b39d6 test(shell-docs): cover nested authored nav pages 2026-07-13 13:27:37 -07:00
Sam Julien 6b69616ce4 docs(shell-docs): clarify thread import project flow 2026-07-13 13:27:29 -07:00
Tyler Slaton f2787e682e docs(channels): use Channels SDK naming (#5939)
## Problem

The package and docs routes were renamed from Bots to Channels, but the
docs still presented the old “Bots” and “Bot SDK” product name in
navigation and integration guides. The Channels reference page was
titled only “Channels” instead of “Channels SDK.”

## Why

The stale naming makes the Channels SDK links unclear in launch
communications and creates an inconsistent journey between the package
names, Slack and Teams quickstarts, and API reference.

## Fix

- Title the Channels guide and `/reference/channels` page “Channels
SDK.”
- Update the reference chooser and Slack, Teams, and WhatsApp guides to
use the Channels SDK name.
- Remove the stale wrench icon from the Slack and Teams early-access
sidebar link, with a regression test for the navigation node.
- Preserve the existing `/channels`, `/reference/channels`, `/slack`,
and `/teams` routes and all existing link targets.
- Verify permanent redirects from `/bots` and `/bots/*` to `/channels`,
and from `/reference/bot` and `/reference/bot/*` to
`/reference/channels`, with regression coverage for both exact and
nested routes.

Verification:

- `npm run lint`
- `npm run typecheck`
- `npm test`
- `npm run build`
- Local production smoke checks returned HTTP 200 for `/channels`,
`/reference/channels`, `/slack`, and `/teams`; rendered `/slack`
contains no wrench markup.
2026-07-13 13:09:52 -07:00
Tyler Slaton ce5b6a5b7a test(docs): protect Bots SDK redirects 2026-07-13 13:08:24 -07:00
Tyler Slaton 2c1ef7268a fix(docs): remove early-access sidebar wrench 2026-07-13 13:08:24 -07:00
Tyler Slaton 440e3acd4f docs(channels): use Channels SDK naming 2026-07-13 13:08:24 -07:00
Jordan Ritter 5ba9290f0d fix(showcase/langgraph-typescript): disable FileSystemPersistence disk flush (permanent LGT outage fix) (#5937)
## What & why

Permanent fix for the recurring langgraph-typescript (LGT) Railway
outage — most recently **2026-07-13**, when both staging and prod went
dead at D0.

**Root cause.** The LGT backend uses `@langchain/langgraph-api@1.1.17`,
whose `FileSystemPersistence` (`dist/storage/persist.mjs`) serialises
**all** accumulated thread/run/checkpoint state to
`/app/src/agent/.langgraph_api` on a 3-second timer. Under the D6 probe
fan-out (36 parallel probes in ~55s) the dir filled to **201MB in
~90s**, tripping the 200MB size-watchdog in `entrypoint.sh`:

```
[watchdog:size] Size threshold exceeded (201MB >= 200MB) — killing agent PID 5 ... exit code 137
```

Each restart refilled and re-tripped; after enough rapid kill→restart
cycles Railway crash-loop backoff stopped restarting the container → the
whole LGT column dead on **both** staging and prod.

## How this mirrors #5825

PR #5825 fixed the **python** side (commit `b4adfc6296`) by exporting
`LANGGRAPH_DISABLE_FILE_PERSISTENCE=true`, which python's
`langgraph_runtime_inmem` reads at import time to skip its
pickle-flush-to-disk loop. **The TS side (commit `ef103f5f58`) never
disabled persistence** — it only added the boot-purge + size-gated
watchdog, which is exactly the mechanism that failed on 2026-07-13 (it
kills on oversize, but the dir refills faster than backoff tolerates).

This PR does for TS what #5825 did for python: **stop the unbounded disk
writes.** The mechanism differs because `@langchain/langgraph-api` has
**no** `LANGGRAPH_DISABLE_FILE_PERSISTENCE` switch, its persistence
writers are unexported module singletons, and the package `exports` map
blocks a deep import of `persist.mjs` (`ERR_PACKAGE_PATH_NOT_EXPORTED`,
verified). The only disk-write surface is `fs.writeFile`/`fs.mkdir` from
`node:fs/promises`, so:

- **`src/agent/disable-file-persistence.mjs`** (new) — a `node --import`
preload that, gated on `LANGGRAPH_DISABLE_FILE_PERSISTENCE=true`, no-ops
`node:fs/promises` `writeFile`/`mkdir` for `.langgraph_api` paths only.
Uses the CJS handle `require("node:fs").promises` because an ESM
namespace object is sealed (`fsPromises.writeFile = …` throws —
verified); the package's `import * as fs` named exports are backed by
that same object, so the patch is observed by the package. In-memory
state (the actual runtime state) is untouched.
- **`src/agent/package.json`** — `start` now `node --import
./disable-file-persistence.mjs --import tsx liveness.mjs` (patch
installs before any langgraph code touches the fs).
- **`entrypoint.sh`** — `export LANGGRAPH_DISABLE_FILE_PERSISTENCE=true`
before launching the agent (same placement/intent as #5825's python
entrypoint).

Behavior preserved: runs still execute, thread state reads back from the
in-memory checkpointer within a container's lifetime (D4/D5/D6
round-trips unaffected). Only disk persistence is removed — bounded by
process memory, discarded on restart, matching python.

## LOCAL RED-GREEN PROOF (real surface)

Exercised the **real** `@langchain/langgraph-api@1.1.17` `startServer`
with a real compiled `StateGraph`, drove real runs via
`@langchain/langgraph-sdk`, then ran the **real** `entrypoint.sh
--check-size-once` watchdog seam against the produced dir.

### RED (pre-fix) — unbounded growth trips the real watchdog

40 real runs, no preload → `.langgraph_api` = **43,320 KB**
(checkpointer 32MB + ops 12MB). Real `entrypoint.sh` watchdog against it
(threshold 30MB):

```
[watchdog:size] Persistence dir size: 43MB (threshold: 30MB)
[watchdog:size] Size threshold exceeded (43MB >= 30MB) — killing agent PID 78845 (and its npm→node tree) to trigger container restart and boot-purge
watchdog exit code (1 = killed): 1
dummy agent was KILLED by watchdog (RED reproduced)
```

### GREEN (post-fix) — no growth, watchdog never fires, round-trip still
works

Same 40 real runs, with preload + env var → `.langgraph_api` = **0 KB
(no dir)**. Real watchdog, same threshold:

```
[persistence] LANGGRAPH_DISABLE_FILE_PERSISTENCE=true — FileSystemPersistence disk flush disabled (in-memory only)
===RESULT=== runs=40 persistDirSizeKB=0
[watchdog:size] Persistence dir /tmp/lgt-persist-proof/.langgraph_api does not exist — skipping size check
watchdog exit code (0 = no kill): 0
dummy agent STILL ALIVE — watchdog did NOT fire (GREEN)
```

Behavior-preserved round-trip (with fix):

```
ROUND-TRIP: messages returned = 2 | assistant content length = 200000
ROUND-TRIP OK: true
persist dir after round-trip: 0 (no dir)
```

## Tests

`tests/python/test_entrypoint_watchdog.py` gains
`TestFilePersistenceDisabled` (behavioral `bash -x` export-on-boot-path
check + source/wiring guards). Full suite: **22 passed** (18
pre-existing + 4 new). No watchdog-logic regressions.

## Deferred (out of scope)

The size-watchdog restart contract still has no restart cooldown /
crash-loop guard. With this fix the dir never grows so the watchdog
should never trip under probe load, but a restart cooldown would harden
against any future writer. Left out deliberately — root cause (the
unbounded write) is eliminated here.

## ⚠ Before merge

The entrypoint env-var + preload are source-verified and locally
red-green-proven against the real package, but the full container has
not been run on Railway from this branch. Recommend a branch deploy
(boots, serves 200, `.langgraph_api` stays empty under a probe wave)
before merge. Kept as a **draft** pending that validation + maintainer
approval.


---

## Round-2 CR fixes (7 reviewers + pre-audit)

Seven reviewers plus a pre-audit flagged that the round-1
`disable-file-persistence.mjs` was **surface-coupled and unanchored**,
and that the entrypoint watchdog tests asserted a stale mechanism. All
mandatory findings resolved and re-proven against the **real** package.

### Empirical truth about the writer (verified on installed
`@langchain/langgraph-api@1.1.17`)

`FileSystemPersistence` (`dist/storage/persist.mjs`) uses `import * as
fs from "node:fs/promises"` and calls `fs.writeFile(...)` /
`fs.mkdir(...)` via **namespace property access** — which DOES read
through to the CJS `.promises` patch. So the round-1 mechanism was *not*
a silent no-op on this version (the pre-audit's named-import fear does
not apply here). But the patch covered **only `writeFile` + `mkdir`**
with an **unanchored substring**, leaving atomic write-then-rename,
`appendFile`, the `*Sync` variants, `open`+handle, and
`createWriteStream` as **silent bypasses** — the exact way the outage
recurs if the pinned package's writer shape changes on upgrade. There is
**no** env/config knob to disable or redirect persistence (the dir is
hardcoded `path.resolve(cwd, ".langgraph_api", name)`), and
`persist.mjs` is not deep-importable — so a hardened monkeypatch is the
only faithful option.

### What changed

- **Patch every fs write surface** for the persist dir —
`promises.{writeFile,appendFile,mkdir,rename,cp,open}`,
`fs.{writeFileSync,appendFileSync,mkdirSync,renameSync,openSync,createWriteStream}`
— so no future writer shape silently grows `.langgraph_api`.
- **Anchor path matching to the `.langgraph_api` path segment** (not a
bare substring); normalise string/Buffer/URL forms. Fixes over-match
data loss (`/tmp/x.langgraph_api.log`, `.langgraph_api_backup` now write
normally).
- **Version + writer-shape guard that fails loudly at boot** if
`@langchain/langgraph-api` is upgraded off `1.1.17` or switches to named
imports — a silent recurrence on upgrade becomes an obvious boot crash
with an actionable message.
- **mkdir `{recursive:true}` return contract honoured**; **env gate
accepts `1`/`true`/`TRUE`/`yes`/`on`** and **logs on both branches**
(enabled AND "not enabled — persistence ACTIVE").
- **Observability**: one-time "intercepted first persist-dir write via
<surface>" log.
- **Tests**: assert the SHIPPED reaper (`trap _reap_watchdog_children
EXIT` + `$BASHPID` PPID-walk), not a comment-only stale trap string;
replace the mock-of-old-shape behavioral reaper test with one that
drives the **real** extracted `entrypoint.sh` helpers; fix a flaky
single-shot `poll()` with a bounded retry loop; refresh the stale
truncate-era docstring; **add a real-package behavioral test** that
drives the real `FileSystemPersistence` and asserts `.langgraph_api`
stays 0 bytes while an in-memory round-trip still returns an assistant
response.

### Round-2 RED-GREEN — real package, bypass surface

RED — round-1 fix (from committed HEAD), flag ON, an atomic
write-then-rename (`writeFileSync`+`rename`) into `.langgraph_api` still
lands on disk:

```
[persistence] LANGGRAPH_DISABLE_FILE_PERSISTENCE=true — FileSystemPersistence disk flush disabled (in-memory only)
RESULT bytes=4428903 files=.langgraphjs_api.checkpointer.json
DISK_GROWS=YES
```

GREEN — corrected fix, real `FileSystemPersistence.persist()` flush of
2000 threads:

```
[persistence] LANGGRAPH_DISABLE_FILE_PERSISTENCE enabled (value="true") — FileSystemPersistence disk flush disabled across all fs write surfaces (in-memory only)
[persistence] intercepted first persist-dir write via promises.mkdir (target=.../.langgraph_api); further hits silent
RESULT bytes=0 files=(none)
DISK_GROWS=NO
```

GREEN — corrected fix, the SAME bypass surface as RED is now closed:

```
RESULT bytes=0 files=(dir-not-created)
DISK_GROWS=NO
```

GREEN — real in-memory round-trip still works (conversation capability
preserved) while disk stays empty:

```
ASSISTANT_RESPONSE="Hello from LGT"
DISK bytes=0
ROUNDTRIP=OK_AND_NO_DISK
```

Version guard fails loudly on a simulated upgrade (installed 1.2.0 vs
expected 1.1.17):

```
[persistence] version/shape guard failed: @langchain/langgraph-api is 1.2.0, but the fs-write interception was verified against 1.1.17 ... Refusing to boot with an unverified writer shape.
```

`pytest tests/python/test_entrypoint_watchdog.py` → **23 passed** (incl.
the new real-package + real-reaper behavioral tests; they run, not skip,
when the agent's `node_modules` is installed).


---

## Round-3 CR fixes

Confirmation-CR round-2 raised two HIGH findings + three LOWs; all
resolved on this branch (commit `01d3fa7794`).

**HIGH-1 — ESM-namespace-snapshot fragility (silent bypass on
load-order).** The patch mutates `require("node:fs").promises.*`; a
consumer's `import * as fs from "node:fs/promises"` observes it only if
fs/promises links *after* the reassignment. If anything links it first,
the namespace snapshots the ORIGINAL fn and every persist write silently
bypasses the no-op. Added a runtime binding-identity net: after
patching, the preload `await import("node:fs/promises")` and asserts
`ns[name] === patchedFn` for every member it installed (writeFile,
appendFile, mkdir, rename, open, cp); on any mismatch it FAILS BOOT
naming the members, never continues silently. The source-string guard
could not catch this (it checks text, not runtime identity).

**HIGH-2 — behavioral test skipped in CI (green-but-unproven).** The
sole real-package proof `pytest.skip`ped when agent `node_modules` was
absent, and no CI installed them. Now the test reads
`LGT_REQUIRE_BEHAVIORAL`: `=1` (CI) turns a missing runtime into a
FAILURE; unset (local dev) still skips gracefully. The
`python-unit-tests` job in `showcase_validate.yml` now sets up Node 22,
`npm install`s the agent deps, and runs the langgraph-typescript pytest
with `LGT_REQUIRE_BEHAVIORAL=1`, so a green check genuinely proves the
interception fired.

**LOWs:** tolerant writer-shape guard regex (quote/whitespace/alias
agnostic; still trips on a named-import switch); read-only
`open`/`openSync` reject an ENOENT-shaped error for suppressed paths
(write-intent still no-ops) so a reader hits its missing-file branch;
`mkdir {recursive:true}` returns the topmost-created dir per the real fs
contract.

### Round-3 red-green — REAL `@langchain/langgraph-api@1.1.17`

RED (no preload; the real writer's flush lands on disk):
```
REAL-PACKAGE-RESULT {"readBack":"reply-0","bytes":32302}
```

GREEN (preload + `LANGGRAPH_DISABLE_FILE_PERSISTENCE=true`; dir stays
empty, round-trip intact):
```
[persistence] ... disabled across all fs write surfaces (in-memory only); namespace binding-identity verified for 6 members
REAL-PACKAGE-RESULT {"readBack":"reply-0","bytes":0}
```

HIGH-1 guard-fires (fs/promises linked before the patch → boot THROWS,
exit 1):
```
[persistence] FATAL: node:fs/promises namespace binding does NOT reflect the installed patch for: writeFile, appendFile, mkdir, rename, open, cp. ... Refusing to boot. ...
EXIT=1
```

`LGT_REQUIRE_BEHAVIORAL=1 pytest
tests/python/test_entrypoint_watchdog.py` → **24 passed** (adds the
HIGH-1 guard-fires regression test; the real-package behavioral proof
now runs, not skips, and is CI-gated).
2026-07-13 11:42:38 -07:00
Jordan Ritter 01d3fa7794 fix(showcase/langgraph-typescript): assert fs/promises binding identity + gate behavioral proof in CI
Round-3 CR fixes for the LGT persistence-disable preload.

HIGH-1: after installing the fs-write patches, import the node:fs/promises
namespace and assert each patched member is identity-equal to the installed
function; throw (fail boot) naming any mismatched member. Catches the
load-order case where fs/promises was linked before the reassignment and the
namespace snapshotted the original fn (silent bypass -> disk-growth recurrence).

HIGH-2: make the real-package behavioral test non-skippable under
LGT_REQUIRE_BEHAVIORAL=1 (missing runtime fails, not skips), and wire the
python-unit-tests job to set up Node, npm install the agent deps, and run the
langgraph-typescript pytest with that flag so a green check proves interception.

LOW: tolerant writer-shape guard regex (quote/whitespace/alias agnostic; still
trips on a named-import switch); read-only open/openSync reject ENOENT for
suppressed paths (write-intent still no-ops); mkdir recursive returns the
topmost-created dir per the real fs contract.

Adds a HIGH-1 guard-fires regression test.
2026-07-13 11:27:13 -07:00
Ran Shem Tov ad3e8b89db test(showcase): bump aimock exact-duplicate ceiling 297 -> 301 (post-main-merge)
Merging main into the branch pushed the aimock exact-duplicate count to 301
(main added cross-demo fixture aliases of the runtime-disambiguated-by-fixtureFile
kind, e.g. ag2 headless-complete/gen-ui-headless-complete). Verified the +4 are
NOT in the mastra context — the Partner Refresh's new fixtures introduce zero new
exact dupes. Ratchet the ceiling to match; 828/828 aimock-fixtures tests pass.
2026-07-13 11:19:53 -07:00
Jordan Ritter 897ba8a447 fix(showcase/langgraph-typescript): harden persistence disable across all fs write surfaces
Round-2 CR fixes for the LGT file-persistence disable. Empirically verified
against the real @langchain/langgraph-api@1.1.17: the FileSystemPersistence
writer uses namespace fs access (fs.writeFile via import * as fs), so the
CJS .promises patch IS observed — but the round-1 patch covered only
writeFile+mkdir with an unanchored substring, leaving atomic write-then-rename
/ appendFile / *Sync / stream surfaces as silent bypasses.

- Patch every fs write surface (promises + sync + open/openSync/createWriteStream)
  for the persist dir, so no future writer shape can silently grow .langgraph_api.
- Anchor path matching to the .langgraph_api path segment (not a substring);
  normalise string/Buffer/URL forms — no more over-match data loss.
- Add a version + writer-shape guard that fails loudly at boot if the package
  is upgraded or switches to named imports (prevents a silent recurrence).
- Honour mkdir {recursive:true} return contract; accept 1/true/yes/on env
  conventions and log on both enabled and not-enabled branches.
- Tests: assert the SHIPPED reaper (_reap_watchdog_children/$BASHPID walk) not
  a stale comment-only trap; replace the mock-shape behavioral reaper test with
  one that drives the real entrypoint helpers; fix a flaky single-shot poll with
  a bounded retry loop; refresh the stale truncate-era docstring; add a
  real-package behavioral test proving disk stays empty and in-memory round-trip
  still returns an assistant response.
2026-07-13 11:12:19 -07:00
Jordan Ritter 28ed085408 fix(showcase/langgraph-typescript): disable FileSystemPersistence disk flush
The langgraph-typescript backend's @langchain/langgraph-api FileSystemPersistence
serialises all accumulated thread/run/checkpoint state to .langgraph_api on a
3-second timer. Under the D6 probe fan-out (36 parallel probes) the dir filled
past the 200MB size-watchdog threshold in ~90s, the watchdog killed the agent,
and on rapid restart the D6 cron refilled and re-tripped it until Railway
crash-loop backoff stopped restarting the container (2026-07-13 outage, staging
and prod).

Mirror PR #5825's langgraph-python fix, which exported
LANGGRAPH_DISABLE_FILE_PERSISTENCE=true so the python inmem runtime skips its
flush-to-disk loop. The TS package has no such switch and its persistence
writers are unexported module singletons behind an exports-map wall, so ship a
node --import preload (src/agent/disable-file-persistence.mjs) that, gated on the
same env var, no-ops node:fs/promises writeFile/mkdir for .langgraph_api paths
while leaving in-memory state (the real runtime state) intact. Wire it into
npm start and export the env var in entrypoint.sh.

Behavior preserved: runs still execute and thread state reads back from the
in-memory checkpointer within the container lifetime; only disk persistence is
removed, so the size-watchdog has nothing to fill and never trips under load.
2026-07-13 10:50:25 -07:00
Ran Shemtov ca1df2415b Merge branch 'main' into claude/brave-kirch-8dbf00 2026-07-13 19:45:50 +02:00
Aria Zhao 96390cac64 fix(react-core): forward refs through DropdownMenuTrigger and TooltipTrigger
Wrap the DropdownMenuTrigger and TooltipTrigger UI primitives in
React.forwardRef so they forward the ref to their underlying Radix
primitive. Radix `asChild` slots pass a ref to their child; as plain
function components these triggers dropped it, producing the React 18.3
"Function components cannot be given refs" warning on every render of
CopilotChatInput's AddMenuButton.

Fixes #5744
2026-07-13 16:07:50 +00:00
Ben Taylor 2c22f212bc fix(channels-teams): fail-loud egress + document HITL button envelope (0.1.2) (#5917)
## Summary

Two fixes to `@copilotkit/channels-teams` found while Intelligence PR
#511 (managed Microsoft Teams, **OSS-450**) deep-imports this package's
run renderer for managed egress. Ships as **0.1.2** so Intelligence can
bump the pin.

## 1. Fail-loud final send (silent egress failure)

`TeamsMessageStream.flushNow()` caught every POST/PUT failure and
resolved, so `finish()` resolved **after a failed final send** — a
consumer then marks the turn "sent" though nothing was delivered
(reproduced: a `post` throwing `provider_down` logged to console but the
end handler resolved successfully).

- `finish()` now drains the throttled queue, then performs the **final
send fail-loud**: a transport failure **rejects** so the caller can
fail/retry.
- Mid-stream throttled edits stay **tolerant** (log + retry on the next
flush) — a dropped edit shouldn't sink a streaming reply.
- Refactor: a shared `doSend()` advances `posted` only *after* the
transport call succeeds (a throw leaves it for retry); `flushNow`
swallows, `flushFinal` propagates.
- **Tests:** final `post` failure → `finish()` rejects; final `update`
failure → rejects; a mid-stream edit failure is tolerated and the final
flush still delivers.

## 2. HITL button action envelope (documented + contract-tested)

Confirmed the actual emitted/inbound shape and published an
authoritative note (`docs/button-action-envelope.md`) + a round-trip
contract test (`src/button-action-envelope.contract.test.ts`) so the
Intelligence ingress can decode clicks out-of-band.

**Outbound** — a `<Button>` renders as a top-level **`Action.Submit`**
(deliberately *not* `Action.Execute` — no `verb`); the opaque id + value
ride in `data`:

```jsonc
{ "type": "Action.Submit", "title": "Approve",
  "data": { "ckActionId": "ck:approve", "value": { "decision": "yes" } },
  "style": "positive" }
```
(`data.ckActionId` only when the Button has an `onClick`; `data.value`
only when it has a `value` prop. A link Button → `Action.OpenUrl`, no
`data`.)

**Inbound** — Teams delivers the click as a **Message activity** (`type:
"message"`), *not* an invoke/`Action.Execute`. The action `data` becomes
`activity.value`; `text` is empty:

```jsonc
{ "type": "message", "text": "",
  "value": { "ckActionId": "ck:approve", "value": { "decision": "yes" } },
  "conversation": { "id": "<stable conversation id>" } }
```
**Decode:** it's a card action iff `typeof activity.value.ckActionId ===
"string"`; then `id = activity.value.ckActionId`, `value =
activity.value.value`. Any `<Input>`/`<Select>` values are merged into
`activity.value` alongside these. Derive the conversation key from
`activity.conversation.id`.

## Verification

`@copilotkit/channels-teams`: **88 tests pass** (incl. the 3 new
fail-loud stream tests + the new envelope contract test), `tsc` build
clean.

Refs Intelligence **OSS-450** / PR #511 (cross-repo consumer).

🤖 Generated with [Claude Code](https://claude.com/claude-code)
2026-07-13 09:06:49 -05:00
github-actions[bot] 1b057bf9df style: auto-fix formatting 2026-07-13 08:16:05 -05:00
Benjamin Taylor 6b6ee2e3c7 docs(channels-teams): document HITL button action envelope + contract test
Authoritative wire shape for the Action.Submit button + the Message activity Teams
delivers on click (activity.value carries { ckActionId, value }, text empty; not
Action.Execute). Round-trip contract test locks emit↔decode.
2026-07-13 08:16:05 -05:00
Benjamin Taylor 14a2276818 fix(channels-teams): fail-loud final send in TeamsMessageStream
finish() now performs the final send outside the error-swallowing throttle path
and rejects on transport failure, so a consumer never marks a turn delivered when
the last post/update didn't land. Mid-stream edits stay tolerant (log + retry).
2026-07-13 08:16:05 -05:00
enekesabel 4f29932ca8 fix(vue): keep attachment sources structuredClone-safe 2026-07-13 11:35:07 +02:00
renovate[bot] 62a46840e3 chore(deps): update github actions (#5845)
> ℹ️ **Note**
> 
> This PR body was truncated due to platform limits.

This PR contains the following updates:

| Package | Type | Update | Change |
|---|---|---|---|
| [actions/cache](https://redirect.github.com/actions/cache) | action |
major | `v5.0.5` → `v6.1.0` |
| [actions/checkout](https://redirect.github.com/actions/checkout) |
action | major | `v4` → `v7` |
|
[actions/download-artifact](https://redirect.github.com/actions/download-artifact)
| action | major | `v4` → `v8` |
|
[actions/github-script](https://redirect.github.com/actions/github-script)
| action | major | `v7` → `v9` |
| [actions/setup-java](https://redirect.github.com/actions/setup-java) |
action | major | `v4.8.0` → `v5.5.0` |
|
[actions/setup-python](https://redirect.github.com/actions/setup-python)
| action | minor | `v6.2.0` → `v6.3.0` |
|
[actions/upload-artifact](https://redirect.github.com/actions/upload-artifact)
| action | major | `v4.6.2` → `v7.0.1` |
|
[actions/upload-artifact](https://redirect.github.com/actions/upload-artifact)
| action | major | `v4` → `v7` |
| [astral-sh/setup-uv](https://redirect.github.com/astral-sh/setup-uv) |
action | major | `v6` → `v8.3.2` |
| [astral-sh/setup-uv](https://redirect.github.com/astral-sh/setup-uv) |
action | minor | `v8.1.0` → `v8.3.2` |
|
[docker/build-push-action](https://redirect.github.com/docker/build-push-action)
| action | major | `v6` → `v7` |
| [docker/login-action](https://redirect.github.com/docker/login-action)
| action | minor | `v4.2.0` → `v4.4.0` |
| [dorny/paths-filter](https://redirect.github.com/dorny/paths-filter) |
action | patch | `v4.0.1` → `v4.0.2` |
| [pnpm/action-setup](https://redirect.github.com/pnpm/action-setup) |
action | patch | `v6.0.8` → `v6.0.9` |
|
[preactjs/compressed-size-action](https://redirect.github.com/preactjs/compressed-size-action)
| action | minor | `2.9.1` → `2.10.0` |
| [ruby/setup-ruby](https://redirect.github.com/ruby/setup-ruby) |
action | minor | `v1.310.0` → `v1.316.0` |
|
[slackapi/slack-github-action](https://redirect.github.com/slackapi/slack-github-action)
| action | major | `v2.1.0` → `v3.0.5` |
| [snok/install-poetry](https://redirect.github.com/snok/install-poetry)
| action | patch | `v1.4.1` → `v1.4.2` |
|
[zizmorcore/zizmor-action](https://redirect.github.com/zizmorcore/zizmor-action)
| action | patch | `v0.5.6` → `v0.5.7` |

---

> [!WARNING]
> Some dependencies could not be looked up. Check the [Dependency
Dashboard](../issues/592) for more information.

---

### Release Notes

<details>
<summary>actions/cache (actions/cache)</summary>

###
[`v6.1.0`](https://redirect.github.com/actions/cache/releases/tag/v6.1.0)

[Compare
Source](https://redirect.github.com/actions/cache/compare/v6.0.0...v6.1.0)

##### What's Changed

- Bump
[@&#8203;actions/cache](https://redirect.github.com/actions/cache) to
v6.1.0 - handle read-only cache access by
[@&#8203;jasongin](https://redirect.github.com/jasongin) in
[#&#8203;1768](https://redirect.github.com/actions/cache/pull/1768)

**Full Changelog**:
<https://github.com/actions/cache/compare/v6...v6.1.0>

###
[`v6.0.0`](https://redirect.github.com/actions/cache/releases/tag/v6.0.0)

[Compare
Source](https://redirect.github.com/actions/cache/compare/v6.0.0...v6.0.0)

#### What's Changed

- Update packages, migrate to ESM by
[@&#8203;Samirat](https://redirect.github.com/Samirat) in
[#&#8203;1760](https://redirect.github.com/actions/cache/pull/1760)

**Full Changelog**:
<https://github.com/actions/cache/compare/v5...v6.0.0>

###
[`v6`](https://redirect.github.com/actions/cache/compare/v5.0.5...v6.0.0)

[Compare
Source](https://redirect.github.com/actions/cache/compare/v5.1.0...v6.0.0)

###
[`v5.1.0`](https://redirect.github.com/actions/cache/releases/tag/v5.1.0)

[Compare
Source](https://redirect.github.com/actions/cache/compare/v5.0.5...v5.1.0)

##### What's Changed

- Bump
[@&#8203;actions/cache](https://redirect.github.com/actions/cache) to
v5.1.0 - handle read-only cache access by
[@&#8203;jasongin](https://redirect.github.com/jasongin) in
[#&#8203;1775](https://redirect.github.com/actions/cache/pull/1775)

**Full Changelog**:
<https://github.com/actions/cache/compare/v5...v5.1.0>

</details>

<details>
<summary>actions/checkout (actions/checkout)</summary>

###
[`v7.0.0`](https://redirect.github.com/actions/checkout/blob/HEAD/CHANGELOG.md#v700)

[Compare
Source](https://redirect.github.com/actions/checkout/compare/v7.0.0...v7.0.0)

- Block checking out fork PR for pull\_request\_target and workflow\_run
by [@&#8203;aiqiaoy](https://redirect.github.com/aiqiaoy) in
[#&#8203;2454](https://redirect.github.com/actions/checkout/pull/2454)
- Bump actions/publish-immutable-action from 0.0.3 to 0.0.4 in the
minor-actions-dependencies group across 1 directory by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;2458](https://redirect.github.com/actions/checkout/pull/2458)
- Bump flatted from 3.3.1 to 3.4.2 by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;2460](https://redirect.github.com/actions/checkout/pull/2460)
- Bump js-yaml from 4.1.0 to 4.2.0 by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;2461](https://redirect.github.com/actions/checkout/pull/2461)
- Bump [@&#8203;actions/core](https://redirect.github.com/actions/core)
and
[@&#8203;actions/tool-cache](https://redirect.github.com/actions/tool-cache)
and Remove uuid by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;2459](https://redirect.github.com/actions/checkout/pull/2459)
- upgrade module to esm and update dependencies by
[@&#8203;aiqiaoy](https://redirect.github.com/aiqiaoy) in
[#&#8203;2463](https://redirect.github.com/actions/checkout/pull/2463)
- Bump the minor-npm-dependencies group across 1 directory with 3
updates by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;2462](https://redirect.github.com/actions/checkout/pull/2462)

###
[`v7`](https://redirect.github.com/actions/checkout/blob/HEAD/CHANGELOG.md#v700)

[Compare
Source](https://redirect.github.com/actions/checkout/compare/v6.0.3...v7.0.0)

- Block checking out fork PR for pull\_request\_target and workflow\_run
by [@&#8203;aiqiaoy](https://redirect.github.com/aiqiaoy) in
[#&#8203;2454](https://redirect.github.com/actions/checkout/pull/2454)
- Bump actions/publish-immutable-action from 0.0.3 to 0.0.4 in the
minor-actions-dependencies group across 1 directory by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;2458](https://redirect.github.com/actions/checkout/pull/2458)
- Bump flatted from 3.3.1 to 3.4.2 by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;2460](https://redirect.github.com/actions/checkout/pull/2460)
- Bump js-yaml from 4.1.0 to 4.2.0 by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;2461](https://redirect.github.com/actions/checkout/pull/2461)
- Bump [@&#8203;actions/core](https://redirect.github.com/actions/core)
and
[@&#8203;actions/tool-cache](https://redirect.github.com/actions/tool-cache)
and Remove uuid by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;2459](https://redirect.github.com/actions/checkout/pull/2459)
- upgrade module to esm and update dependencies by
[@&#8203;aiqiaoy](https://redirect.github.com/aiqiaoy) in
[#&#8203;2463](https://redirect.github.com/actions/checkout/pull/2463)
- Bump the minor-npm-dependencies group across 1 directory with 3
updates by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;2462](https://redirect.github.com/actions/checkout/pull/2462)

###
[`v6.0.3`](https://redirect.github.com/actions/checkout/blob/HEAD/CHANGELOG.md#v603)

[Compare
Source](https://redirect.github.com/actions/checkout/compare/v6.0.2...v6.0.3)

- Fix checkout init for SHA-256 repositories by
[@&#8203;yaananth](https://redirect.github.com/yaananth) in
[#&#8203;2439](https://redirect.github.com/actions/checkout/pull/2439)
- fix: expand merge commit SHA regex and add SHA-256 test cases by
[@&#8203;yaananth](https://redirect.github.com/yaananth) in
[#&#8203;2414](https://redirect.github.com/actions/checkout/pull/2414)

###
[`v6.0.2`](https://redirect.github.com/actions/checkout/blob/HEAD/CHANGELOG.md#v602)

[Compare
Source](https://redirect.github.com/actions/checkout/compare/v6.0.1...v6.0.2)

- Fix tag handling: preserve annotations and explicit fetch-tags by
[@&#8203;ericsciple](https://redirect.github.com/ericsciple) in
[#&#8203;2356](https://redirect.github.com/actions/checkout/pull/2356)

###
[`v6.0.1`](https://redirect.github.com/actions/checkout/blob/HEAD/CHANGELOG.md#v601)

[Compare
Source](https://redirect.github.com/actions/checkout/compare/v6...v6.0.1)

- Add worktree support for persist-credentials includeIf by
[@&#8203;ericsciple](https://redirect.github.com/ericsciple) in
[#&#8203;2327](https://redirect.github.com/actions/checkout/pull/2327)

###
[`v6.0.0`](https://redirect.github.com/actions/checkout/blob/HEAD/CHANGELOG.md#v600)

[Compare
Source](https://redirect.github.com/actions/checkout/compare/v6...v6)

- Persist creds to a separate file by
[@&#8203;ericsciple](https://redirect.github.com/ericsciple) in
[#&#8203;2286](https://redirect.github.com/actions/checkout/pull/2286)
- Update README to include Node.js 24 support details and requirements
by [@&#8203;salmanmkc](https://redirect.github.com/salmanmkc) in
[#&#8203;2248](https://redirect.github.com/actions/checkout/pull/2248)

###
[`v6`](https://redirect.github.com/actions/checkout/blob/HEAD/CHANGELOG.md#v603)

[Compare
Source](https://redirect.github.com/actions/checkout/compare/v5.0.1...v6)

- Fix checkout init for SHA-256 repositories by
[@&#8203;yaananth](https://redirect.github.com/yaananth) in
[#&#8203;2439](https://redirect.github.com/actions/checkout/pull/2439)
- fix: expand merge commit SHA regex and add SHA-256 test cases by
[@&#8203;yaananth](https://redirect.github.com/yaananth) in
[#&#8203;2414](https://redirect.github.com/actions/checkout/pull/2414)

###
[`v5.0.1`](https://redirect.github.com/actions/checkout/blob/HEAD/CHANGELOG.md#v501)

[Compare
Source](https://redirect.github.com/actions/checkout/compare/v5...v5.0.1)

- Port v6 cleanup to v5 by
[@&#8203;ericsciple](https://redirect.github.com/ericsciple) in
[#&#8203;2301](https://redirect.github.com/actions/checkout/pull/2301)

###
[`v5.0.0`](https://redirect.github.com/actions/checkout/blob/HEAD/CHANGELOG.md#v500)

[Compare
Source](https://redirect.github.com/actions/checkout/compare/v5...v5)

- Update actions checkout to use node 24 by
[@&#8203;salmanmkc](https://redirect.github.com/salmanmkc) in
[#&#8203;2226](https://redirect.github.com/actions/checkout/pull/2226)

###
[`v5`](https://redirect.github.com/actions/checkout/blob/HEAD/CHANGELOG.md#v501)

[Compare
Source](https://redirect.github.com/actions/checkout/compare/v4.3.1...v5)

- Port v6 cleanup to v5 by
[@&#8203;ericsciple](https://redirect.github.com/ericsciple) in
[#&#8203;2301](https://redirect.github.com/actions/checkout/pull/2301)

</details>

<details>
<summary>actions/download-artifact (actions/download-artifact)</summary>

###
[`v8.0.1`](https://redirect.github.com/actions/download-artifact/releases/tag/v8.0.1)

[Compare
Source](https://redirect.github.com/actions/download-artifact/compare/v8...v8.0.1)

#### What's Changed

- Support for CJK characters in the artifact name by
[@&#8203;danwkennedy](https://redirect.github.com/danwkennedy) in
[#&#8203;471](https://redirect.github.com/actions/download-artifact/pull/471)
- Add a regression test for artifact name + content-type mismatches by
[@&#8203;danwkennedy](https://redirect.github.com/danwkennedy) in
[#&#8203;472](https://redirect.github.com/actions/download-artifact/pull/472)

**Full Changelog**:
<https://github.com/actions/download-artifact/compare/v8...v8.0.1>

###
[`v8.0.0`](https://redirect.github.com/actions/download-artifact/releases/tag/v8.0.0)

[Compare
Source](https://redirect.github.com/actions/download-artifact/compare/v8...v8)

#### v8 - What's new

> \[!IMPORTANT]
> actions/download-artifact\@&#8203;v8 has been migrated to an ESM
module. This should be transparent to the caller but forks might need to
make significant changes.

> \[!IMPORTANT]
> Hash mismatches will now error by default. Users can override this
behavior with a setting change (see below).

##### Direct downloads

To support direct uploads in `actions/upload-artifact`, the action will
no longer attempt to unzip all downloaded files. Instead, the action
checks the `Content-Type` header ahead of unzipping and skips non-zipped
files. Callers wishing to download a zipped file as-is can also set the
new `skip-decompress` parameter to `true`.

##### Enforced checks (breaking)

A previous release introduced digest checks on the download. If a
download hash didn't match the expected hash from the server, the action
would log a warning. Callers can now configure the behavior on mismatch
with the `digest-mismatch` parameter. To be secure by default, we are
now defaulting the behavior to `error` which will fail the workflow run.

##### ESM

To support new versions of the @&#8203;actions/\* packages, we've
upgraded the package to ESM.

#### What's Changed

- Don't attempt to un-zip non-zipped downloads by
[@&#8203;danwkennedy](https://redirect.github.com/danwkennedy) in
[#&#8203;460](https://redirect.github.com/actions/download-artifact/pull/460)
- Add a setting to specify what to do on hash mismatch and default it to
`error` by
[@&#8203;danwkennedy](https://redirect.github.com/danwkennedy) in
[#&#8203;461](https://redirect.github.com/actions/download-artifact/pull/461)

**Full Changelog**:
<https://github.com/actions/download-artifact/compare/v7...v8.0.0>

###
[`v8`](https://redirect.github.com/actions/download-artifact/compare/v7.0.0...v8)

[Compare
Source](https://redirect.github.com/actions/download-artifact/compare/v7.0.0...v8)

###
[`v7.0.0`](https://redirect.github.com/actions/download-artifact/releases/tag/v7.0.0)

[Compare
Source](https://redirect.github.com/actions/download-artifact/compare/v7.0.0...v7.0.0)

#### v7 - What's new

> \[!IMPORTANT]
> actions/download-artifact\@&#8203;v7 now runs on Node.js 24
(`runs.using: node24`) and requires a minimum Actions Runner version of
2.327.1. If you are using self-hosted runners, ensure they are updated
before upgrading.

##### Node.js 24

This release updates the runtime to Node.js 24. v6 had preliminary
support for Node 24, however this action was by default still running on
Node.js 20. Now this action by default will run on Node.js 24.

#### What's Changed

- Update GHES guidance to include reference to Node 20 version by
[@&#8203;patrikpolyak](https://redirect.github.com/patrikpolyak) in
[#&#8203;440](https://redirect.github.com/actions/download-artifact/pull/440)
- Download Artifact Node24 support by
[@&#8203;salmanmkc](https://redirect.github.com/salmanmkc) in
[#&#8203;415](https://redirect.github.com/actions/download-artifact/pull/415)
- fix: update
[@&#8203;actions/artifact](https://redirect.github.com/actions/artifact)
to fix Node.js 24 punycode deprecation by
[@&#8203;salmanmkc](https://redirect.github.com/salmanmkc) in
[#&#8203;451](https://redirect.github.com/actions/download-artifact/pull/451)
- prepare release v7.0.0 for Node.js 24 support by
[@&#8203;salmanmkc](https://redirect.github.com/salmanmkc) in
[#&#8203;452](https://redirect.github.com/actions/download-artifact/pull/452)

#### New Contributors

- [@&#8203;patrikpolyak](https://redirect.github.com/patrikpolyak) made
their first contribution in
[#&#8203;440](https://redirect.github.com/actions/download-artifact/pull/440)
- [@&#8203;salmanmkc](https://redirect.github.com/salmanmkc) made their
first contribution in
[#&#8203;415](https://redirect.github.com/actions/download-artifact/pull/415)

**Full Changelog**:
<https://github.com/actions/download-artifact/compare/v6.0.0...v7.0.0>

###
[`v7`](https://redirect.github.com/actions/download-artifact/compare/v6.0.0...v7.0.0)

[Compare
Source](https://redirect.github.com/actions/download-artifact/compare/v6.0.0...v7.0.0)

###
[`v6.0.0`](https://redirect.github.com/actions/download-artifact/releases/tag/v6.0.0)

[Compare
Source](https://redirect.github.com/actions/download-artifact/compare/v6.0.0...v6.0.0)

#### What's Changed

**BREAKING CHANGE:** this update supports Node `v24.x`. This is not a
breaking change per-se but we're treating it as such.

- Update README for download-artifact v5 changes by
[@&#8203;yacaovsnc](https://redirect.github.com/yacaovsnc) in
[#&#8203;417](https://redirect.github.com/actions/download-artifact/pull/417)
- Update README with artifact extraction details by
[@&#8203;yacaovsnc](https://redirect.github.com/yacaovsnc) in
[#&#8203;424](https://redirect.github.com/actions/download-artifact/pull/424)
- Readme: spell out the first use of GHES by
[@&#8203;danwkennedy](https://redirect.github.com/danwkennedy) in
[#&#8203;431](https://redirect.github.com/actions/download-artifact/pull/431)
- Bump `@actions/artifact` to `v4.0.0`
- Prepare `v6.0.0` by
[@&#8203;danwkennedy](https://redirect.github.com/danwkennedy) in
[#&#8203;438](https://redirect.github.com/actions/download-artifact/pull/438)

#### New Contributors

- [@&#8203;danwkennedy](https://redirect.github.com/danwkennedy) made
their first contribution in
[#&#8203;431](https://redirect.github.com/actions/download-artifact/pull/431)

**Full Changelog**:
<https://github.com/actions/download-artifact/compare/v5...v6.0.0>

###
[`v6`](https://redirect.github.com/actions/download-artifact/compare/v5.0.0...v6.0.0)

[Compare
Source](https://redirect.github.com/actions/download-artifact/compare/v5.0.0...v6.0.0)

###
[`v5.0.0`](https://redirect.github.com/actions/download-artifact/releases/tag/v5.0.0)

[Compare
Source](https://redirect.github.com/actions/download-artifact/compare/v5.0.0...v5.0.0)

#### What's Changed

- Update README.md by
[@&#8203;nebuk89](https://redirect.github.com/nebuk89) in
[#&#8203;407](https://redirect.github.com/actions/download-artifact/pull/407)
- BREAKING fix: inconsistent path behavior for single artifact downloads
by ID by [@&#8203;GrantBirki](https://redirect.github.com/GrantBirki) in
[#&#8203;416](https://redirect.github.com/actions/download-artifact/pull/416)

#### v5.0.0

##### 🚨 Breaking Change

This release fixes an inconsistency in path behavior for single artifact
downloads by ID. **If you're downloading single artifacts by ID, the
output path may change.**

##### What Changed

Previously, **single artifact downloads** behaved differently depending
on how you specified the artifact:

- **By name**: `name: my-artifact` → extracted to `path/` (direct)
- **By ID**: `artifact-ids: 12345` → extracted to `path/my-artifact/`
(nested)

Now both methods are consistent:

- **By name**: `name: my-artifact` → extracted to `path/` (unchanged)
- **By ID**: `artifact-ids: 12345` → extracted to `path/` (fixed - now
direct)

##### Migration Guide

##### ✅ No Action Needed If:

- You download artifacts by **name**
- You download **multiple** artifacts by ID
- You already use `merge-multiple: true` as a workaround

##### ⚠️ Action Required If:

You download **single artifacts by ID** and your workflows expect the
nested directory structure.

**Before v5 (nested structure):**

```yaml
- uses: actions/download-artifact@v4
  with:
    artifact-ids: 12345
    path: dist

# Files were in: dist/my-artifact/
```

> Where `my-artifact` is the name of the artifact you previously
uploaded

**To maintain old behavior (if needed):**

```yaml
- uses: actions/download-artifact@v5
  with:
    artifact-ids: 12345
    path: dist/my-artifact  # Explicitly specify the nested path
```

#### New Contributors

- [@&#8203;nebuk89](https://redirect.github.com/nebuk89) made their
first contribution in
[#&#8203;407](https://redirect.github.com/actions/download-artifact/pull/407)

**Full Changelog**:
<https://github.com/actions/download-artifact/compare/v4...v5.0.0>

###
[`v5`](https://redirect.github.com/actions/download-artifact/compare/v4.3.0...v5.0.0)

[Compare
Source](https://redirect.github.com/actions/download-artifact/compare/v4.3.0...v5.0.0)

</details>

<details>
<summary>actions/github-script (actions/github-script)</summary>

###
[`v9.0.0`](https://redirect.github.com/actions/github-script/releases/tag/v9.0.0)

[Compare
Source](https://redirect.github.com/actions/github-script/compare/v9.0.0...v9.0.0)

**New features:**

- **`getOctokit` factory function** — Available directly in the script
context. Create additional authenticated Octokit clients with different
tokens for multi-token workflows, GitHub App tokens, and cross-org
access. See [Creating additional clients with
`getOctokit`](https://redirect.github.com/actions/github-script#creating-additional-clients-with-getoctokit)
for details and examples.
- **Orchestration ID in user-agent** — The `ACTIONS_ORCHESTRATION_ID`
environment variable is automatically appended to the user-agent string
for request tracing.

**Breaking changes:**

- **`require('@&#8203;actions/github')` no longer works in scripts.**
The upgrade to `@actions/github` v9 (ESM-only) means
`require('@&#8203;actions/github')` will fail at runtime. If you
previously used patterns like `const { getOctokit } =
require('@&#8203;actions/github')` to create secondary clients, use the
new injected `getOctokit` function instead — it's available directly in
the script context with no imports needed.
- `getOctokit` is now an injected function parameter. Scripts that
declare `const getOctokit = ...` or `let getOctokit = ...` will get a
`SyntaxError` because JavaScript does not allow `const`/`let`
redeclaration of function parameters. Use the injected `getOctokit`
directly, or use `var getOctokit = ...` if you need to redeclare it.
- If your script accesses other `@actions/github` internals beyond the
standard `github`/`octokit` client, you may need to update those
references for v9 compatibility.

##### What's Changed

- Add ACTIONS\_ORCHESTRATION\_ID to user-agent string by
[@&#8203;Copilot](https://redirect.github.com/Copilot) in
[#&#8203;695](https://redirect.github.com/actions/github-script/pull/695)
- ci: use deployment: false for integration test environments by
[@&#8203;salmanmkc](https://redirect.github.com/salmanmkc) in
[#&#8203;712](https://redirect.github.com/actions/github-script/pull/712)
- feat!: add getOctokit to script context, upgrade
[@&#8203;actions/github](https://redirect.github.com/actions/github) v9,
[@&#8203;octokit/core](https://redirect.github.com/octokit/core) v7, and
related packages by
[@&#8203;salmanmkc](https://redirect.github.com/salmanmkc) in
[#&#8203;700](https://redirect.github.com/actions/github-script/pull/700)

##### New Contributors

- [@&#8203;Copilot](https://redirect.github.com/Copilot) made their
first contribution in
[#&#8203;695](https://redirect.github.com/actions/github-script/pull/695)

**Full Changelog**:
<https://github.com/actions/github-script/compare/v8.0.0...v9.0.0>

###
[`v9`](https://redirect.github.com/actions/github-script/compare/v8.0.0...v9.0.0)

[Compare
Source](https://redirect.github.com/actions/github-script/compare/v8.0.0...v9.0.0)

###
[`v8.0.0`](https://redirect.github.com/actions/github-script/compare/v8.0.0...v8.0.0)

[Compare
Source](https://redirect.github.com/actions/github-script/compare/v8.0.0...v8.0.0)

###
[`v8`](https://redirect.github.com/actions/github-script/releases/tag/v8):
.0.0

[Compare
Source](https://redirect.github.com/actions/github-script/compare/v7.1.0...v8.0.0)

#### What's Changed

- Update Node.js version support to 24.x by
[@&#8203;salmanmkc](https://redirect.github.com/salmanmkc) in
[#&#8203;637](https://redirect.github.com/actions/github-script/pull/637)
- README for updating actions/github-script from v7 to v8 by
[@&#8203;sneha-krip](https://redirect.github.com/sneha-krip) in
[#&#8203;653](https://redirect.github.com/actions/github-script/pull/653)

#### ⚠️ Minimum Compatible Runner Version

**v2.327.1**\
[Release
Notes](https://redirect.github.com/actions/runner/releases/tag/v2.327.1)

Make sure your runner is updated to this version or newer to use this
release.

#### New Contributors

- [@&#8203;salmanmkc](https://redirect.github.com/salmanmkc) made their
first contribution in
[#&#8203;637](https://redirect.github.com/actions/github-script/pull/637)
- [@&#8203;sneha-krip](https://redirect.github.com/sneha-krip) made
their first contribution in
[#&#8203;653](https://redirect.github.com/actions/github-script/pull/653)

**Full Changelog**:
<https://github.com/actions/github-script/compare/v7.1.0...v8.0.0>

</details>

<details>
<summary>actions/setup-java (actions/setup-java)</summary>

###
[`v5.5.0`](https://redirect.github.com/actions/setup-java/compare/v5.4.0...v5.5.0)

[Compare
Source](https://redirect.github.com/actions/setup-java/compare/v5.4.0...v5.5.0)

###
[`v5.4.0`](https://redirect.github.com/actions/setup-java/releases/tag/v5.4.0)

[Compare
Source](https://redirect.github.com/actions/setup-java/compare/v5.3.0...v5.4.0)

##### What's Changed

- Bump
[@&#8203;typescript-eslint/parser](https://redirect.github.com/typescript-eslint/parser)
from 8.48.0 to 8.61.1 by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;1021](https://redirect.github.com/actions/setup-java/pull/1021)
- Fix codeql workflow permissions by
[@&#8203;jsoref](https://redirect.github.com/jsoref) in
[#&#8203;993](https://redirect.github.com/actions/setup-java/pull/993)
- fix CodeQL permissions by
[@&#8203;gdams](https://redirect.github.com/gdams) in
[#&#8203;1025](https://redirect.github.com/actions/setup-java/pull/1025)
- fix: reject non-semver candidate versions in isVersionSatisfies by
[@&#8203;sproctor](https://redirect.github.com/sproctor) in
[#&#8203;1009](https://redirect.github.com/actions/setup-java/pull/1009)
- Bump
[@&#8203;actions/cache](https://redirect.github.com/actions/cache) to
5.1.0, handle cache write denied by
[@&#8203;jasongin](https://redirect.github.com/jasongin) in
[#&#8203;1026](https://redirect.github.com/actions/setup-java/pull/1026)
- Add Maven Wrapper cache feature by
[@&#8203;mahabaleshwars](https://redirect.github.com/mahabaleshwars) in
[#&#8203;1027](https://redirect.github.com/actions/setup-java/pull/1027)
- Spelling by [@&#8203;jsoref](https://redirect.github.com/jsoref) in
[#&#8203;713](https://redirect.github.com/actions/setup-java/pull/713)
- add link to advanced configuration for JetBrains by
[@&#8203;robstoll](https://redirect.github.com/robstoll) in
[#&#8203;850](https://redirect.github.com/actions/setup-java/pull/850)
- docs(action): fix missing required or default fields by
[@&#8203;kranthipoturaju](https://redirect.github.com/kranthipoturaju)
in
[#&#8203;1007](https://redirect.github.com/actions/setup-java/pull/1007)
- feat: add microsoft openjdk 17.0.18 by
[@&#8203;al-kau](https://redirect.github.com/al-kau) in
[#&#8203;1002](https://redirect.github.com/actions/setup-java/pull/1002)
- Update README.md - use "alert syntax for Markdown" for notes by
[@&#8203;mhoffrog](https://redirect.github.com/mhoffrog) in
[#&#8203;924](https://redirect.github.com/actions/setup-java/pull/924)
- Bump undici from 6.24.1 to 6.27.0 by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;1033](https://redirect.github.com/actions/setup-java/pull/1033)
- Update contributor guide with emoji for clarity by
[@&#8203;brunoborges](https://redirect.github.com/brunoborges) in
[#&#8203;1028](https://redirect.github.com/actions/setup-java/pull/1028)
- add javac problem matcher by
[@&#8203;Trass3r](https://redirect.github.com/Trass3r) in
[#&#8203;562](https://redirect.github.com/actions/setup-java/pull/562)
- Clarify README version syntax and migration guidance by
[@&#8203;brunoborges](https://redirect.github.com/brunoborges) with
[@&#8203;Copilot](https://redirect.github.com/Copilot) in
[#&#8203;1038](https://redirect.github.com/actions/setup-java/pull/1038)
- Update undici artifacts to 6.27.0 (license cache + dist) by
[@&#8203;brunoborges](https://redirect.github.com/brunoborges) in
[#&#8203;1040](https://redirect.github.com/actions/setup-java/pull/1040)
- docs: enhance custom jdk file installation by
[@&#8203;stephanabel](https://redirect.github.com/stephanabel) in
[#&#8203;996](https://redirect.github.com/actions/setup-java/pull/996)
- Templates for new Java distributions by
[@&#8203;panticmilos](https://redirect.github.com/panticmilos) in
[#&#8203;429](https://redirect.github.com/actions/setup-java/pull/429)
- Bump actions/checkout from 6 to 7 by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;1032](https://redirect.github.com/actions/setup-java/pull/1032)
- Bump [@&#8203;types/node](https://redirect.github.com/types/node) from
25.9.3 to 26.0.0 by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;1031](https://redirect.github.com/actions/setup-java/pull/1031)
- docs: replace non-existent HelloWorldApp references with java
--version by
[@&#8203;brunoborges](https://redirect.github.com/brunoborges) with
[@&#8203;Copilot](https://redirect.github.com/Copilot) in
[#&#8203;1043](https://redirect.github.com/actions/setup-java/pull/1043)
- docs: add JavaFX Maven project configuration instructions by
[@&#8203;brunoborges](https://redirect.github.com/brunoborges) with
[@&#8203;Copilot](https://redirect.github.com/Copilot) in
[#&#8203;1044](https://redirect.github.com/actions/setup-java/pull/1044)
- docs: self-signed certificate / internal CA handling for GitHub
Enterprise by
[@&#8203;brunoborges](https://redirect.github.com/brunoborges) in
[#&#8203;1050](https://redirect.github.com/actions/setup-java/pull/1050)
- docs: document importing an internal CA into the installed JDK
(cacerts) by
[@&#8203;brunoborges](https://redirect.github.com/brunoborges) in
[#&#8203;1051](https://redirect.github.com/actions/setup-java/pull/1051)
- chore: Harden workflows: least-privilege permissions + zizmor
integration by
[@&#8203;brunoborges](https://redirect.github.com/brunoborges) in
[#&#8203;1039](https://redirect.github.com/actions/setup-java/pull/1039)
- dist: Add GraalVM Community distribution support by
[@&#8203;brunoborges](https://redirect.github.com/brunoborges) with
[@&#8203;Copilot](https://redirect.github.com/Copilot) in
[#&#8203;1042](https://redirect.github.com/actions/setup-java/pull/1042)
- docs: note jdkfile approach for Early Access / unreleased JDK builds
by [@&#8203;brunoborges](https://redirect.github.com/brunoborges) in
[#&#8203;1058](https://redirect.github.com/actions/setup-java/pull/1058)
- dist: Apply Copilot review suggestions from PR
[#&#8203;1042](https://redirect.github.com/actions/setup-java/issues/1042)
(GraalVM Community) by
[@&#8203;brunoborges](https://redirect.github.com/brunoborges) in
[#&#8203;1059](https://redirect.github.com/actions/setup-java/pull/1059)

##### New Contributors

- [@&#8203;jsoref](https://redirect.github.com/jsoref) made their first
contribution in
[#&#8203;993](https://redirect.github.com/actions/setup-java/pull/993)
- [@&#8203;sproctor](https://redirect.github.com/sproctor) made their
first contribution in
[#&#8203;1009](https://redirect.github.com/actions/setup-java/pull/1009)
- [@&#8203;jasongin](https://redirect.github.com/jasongin) made their
first contribution in
[#&#8203;1026](https://redirect.github.com/actions/setup-java/pull/1026)
- [@&#8203;robstoll](https://redirect.github.com/robstoll) made their
first contribution in
[#&#8203;850](https://redirect.github.com/actions/setup-java/pull/850)
- [@&#8203;kranthipoturaju](https://redirect.github.com/kranthipoturaju)
made their first contribution in
[#&#8203;1007](https://redirect.github.com/actions/setup-java/pull/1007)
- [@&#8203;al-kau](https://redirect.github.com/al-kau) made their first
contribution in
[#&#8203;1002](https://redirect.github.com/actions/setup-java/pull/1002)
- [@&#8203;mhoffrog](https://redirect.github.com/mhoffrog) made their
first contribution in
[#&#8203;924](https://redirect.github.com/actions/setup-java/pull/924)
- [@&#8203;brunoborges](https://redirect.github.com/brunoborges) made
their first contribution in
[#&#8203;1028](https://redirect.github.com/actions/setup-java/pull/1028)
- [@&#8203;Trass3r](https://redirect.github.com/Trass3r) made their
first contribution in
[#&#8203;562](https://redirect.github.com/actions/setup-java/pull/562)
- [@&#8203;stephanabel](https://redirect.github.com/stephanabel) made
their first contribution in
[#&#8203;996](https://redirect.github.com/actions/setup-java/pull/996)

**Full Changelog**:
<https://github.com/actions/setup-java/compare/v5...v5.4.0>

###
[`v5.3.0`](https://redirect.github.com/actions/setup-java/releases/tag/v5.3.0)

[Compare
Source](https://redirect.github.com/actions/setup-java/compare/v5.2.0...v5.3.0)

##### What's Changed

- chore: update Java version to 25 in setup examples by
[@&#8203;alaahong](https://redirect.github.com/alaahong) in
[#&#8203;969](https://redirect.github.com/actions/setup-java/pull/969)
- Bump minimatch from 3.1.2 to 3.1.5 by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;984](https://redirect.github.com/actions/setup-java/pull/984)
- Refactor error handling and improve test logging for installers by
[@&#8203;chiranjib-swain](https://redirect.github.com/chiranjib-swain)
in
[#&#8203;989](https://redirect.github.com/actions/setup-java/pull/989)
- chore: upgrade dependencies
([@&#8203;actions/core](https://redirect.github.com/actions/core),
cache, glob, http-client, tool-cache, xmlbuilder2) by
[@&#8203;Copilot](https://redirect.github.com/Copilot) in
[#&#8203;999](https://redirect.github.com/actions/setup-java/pull/999)
- Add Oracle JDK 17 licensing limitation note by
[@&#8203;mahabaleshwars](https://redirect.github.com/mahabaleshwars) in
[#&#8203;1001](https://redirect.github.com/actions/setup-java/pull/1001)
- Update readme for ubuntu sudo java\_home behavior by
[@&#8203;mahabaleshwars](https://redirect.github.com/mahabaleshwars) in
[#&#8203;1013](https://redirect.github.com/actions/setup-java/pull/1013)
- temurin: add support for Alpine Linux by
[@&#8203;gdams](https://redirect.github.com/gdams) in
[#&#8203;674](https://redirect.github.com/actions/setup-java/pull/674)
- fix: resolve npm audit vulnerabilities in fast-xml-builder and
fast-xml-parser by [@&#8203;gdams](https://redirect.github.com/gdams) in
[#&#8203;1015](https://redirect.github.com/actions/setup-java/pull/1015)
- Bump
[@&#8203;typescript-eslint/eslint-plugin](https://redirect.github.com/typescript-eslint/eslint-plugin)
from 8.35.1 to 8.48.0 by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;952](https://redirect.github.com/actions/setup-java/pull/952)
- Bump eslint-config-prettier from 8.10.0 to 10.1.8 by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;881](https://redirect.github.com/actions/setup-java/pull/881)
- Bump picomatch,
[@&#8203;types/jest](https://redirect.github.com/types/jest), jest,
jest-circus and ts-jest by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;1016](https://redirect.github.com/actions/setup-java/pull/1016)
- Bump [@&#8203;types/node](https://redirect.github.com/types/node) from
24.1.0 to 25.9.3 by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;950](https://redirect.github.com/actions/setup-java/pull/950)
- Implement pagination with link headers for Adoptium based apis by
[@&#8203;johnoliver](https://redirect.github.com/johnoliver) in
[#&#8203;1014](https://redirect.github.com/actions/setup-java/pull/1014)
- Make the Adoptopenjdk package type look at the Temurin repo first for
latest assets by
[@&#8203;johnoliver](https://redirect.github.com/johnoliver) in
[#&#8203;522](https://redirect.github.com/actions/setup-java/pull/522)
- Bump [@&#8203;vercel/ncc](https://redirect.github.com/vercel/ncc) from
0.38.1 to 0.44.0 by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;1018](https://redirect.github.com/actions/setup-java/pull/1018)

##### New Contributors

- [@&#8203;alaahong](https://redirect.github.com/alaahong) made their
first contribution in
[#&#8203;969](https://redirect.github.com/actions/setup-java/pull/969)
- [@&#8203;Copilot](https://redirect.github.com/Copilot) made their
first contribution in
[#&#8203;999](https://redirect.github.com/actions/setup-java/pull/999)
- [@&#8203;johnoliver](https://redirect.github.com/johnoliver) made
their first contribution in
[#&#8203;1014](https://redirect.github.com/actions/setup-java/pull/1014)

**Full Changelog**:
<https://github.com/actions/setup-java/compare/v5...v5.3.0>

###
[`v5.2.0`](https://redirect.github.com/actions/setup-java/releases/tag/v5.2.0)

[Compare
Source](https://redirect.github.com/actions/setup-java/compare/v5.1.0...v5.2.0)

##### What's Changed

##### Enhancement

- Retry on HTTP 522 Connection timed out by
[@&#8203;findepi](https://redirect.github.com/findepi) in
[#&#8203;964](https://redirect.github.com/actions/setup-java/pull/964)

##### Documentation Changes

- Update gradle caching by
[@&#8203;priya-kinthali](https://redirect.github.com/priya-kinthali) in
[#&#8203;972](https://redirect.github.com/actions/setup-java/pull/972)
- Update checkout to v6 by
[@&#8203;mahabaleshwars](https://redirect.github.com/mahabaleshwars) in
[#&#8203;973](https://redirect.github.com/actions/setup-java/pull/973)

##### Dependency Updates

- Upgrade
[@&#8203;actions/cache](https://redirect.github.com/actions/cache) to v5
by [@&#8203;salmanmkc](https://redirect.github.com/salmanmkc) in
[#&#8203;968](https://redirect.github.com/actions/setup-java/pull/968)
- Upgrade actions/checkout from 5 to 6 by
[@&#8203;dependabot](https://redirect.github.com/dependabot) in
[#&#8203;961](https://redirect.github.com/actions/setup-java/pull/961)

##### New Contributors

- [@&#8203;findepi](https://redirect.github.com/findepi) made their
first contribution in
[#&#8203;964](https://redirect.github.com/actions/setup-java/pull/964)

**Full Changelog**:
<https://github.com/actions/setup-java/compare/v5...v5.2.0>

###
[`v5.1.0`](https://redirect.github.com/actions/setup-java/releases/tag/v5.1.0)

[Compare
Source](https://redirect.github.com/actions/setup-java/compare/v5...v5.1.0)

##### What's Changed

##### New Features

- Add support for `.sdkmanrc` file in `java-version-file` parameter by
[@&#8203;guicamest](https://redirect.github.com/guicamest) in
[#&#8203;736](https://redirect.github.com/actions/setup-java/pull/736)
- Add support for Microsoft OpenJDK 25 builds by
[@&#8203;the-mod](https://redirect.github.com/the-mod) in
[#&#8203;927](https://redirect.github.com/actions/setup-java/pull/927)

##### Bug Fixes & Improvements

- Update Regex to Support All ASDF Versions for the supported
distributions in tool-versions File by
[@&#8203;aparnajyothi-y](https://redirect.github.com/aparnajyothi-y) in
[#&#8203;767](https://redirect.github.com/actions/setup-java/pull/767)
- Enhance error logging for network failures to include endpoint/IP
details, add retry mechanism and update workflows to use macos-15-intel
by [@&#8203;priya-kinthali](https://redirect.github.com/priya-kinthali)
in
[#&#8203;946](https://redirect.github.com/actions/setup-java/pull/946)
- Update SapMachine URLs by
[@&#8203;RealCLanger](https://redirect.github.com/RealCLanger) in
[#&#8203;955](https://redirect.github.com/actions/setup-java/pull/955)
- Add GitHub Token Support for GraalVM and Refactor Code by
[@&#8203;mahabaleshwars](https://redirect.github.com/mahabaleshwars) in
[#&#8203;849](https://redirect.github.com/actions/setup-java/pull/849)

##### Documentation changes

- Update documentation to use checkout and Java v5 by
[@&#8203;lmvysakh](https://redirect.github.com/lmvysakh) in
[#&#8203;903](https://redirect.github.com/actions/setup-java/pull/903)
- Clarify JAVA\_HOME and PATH setup in README by
[@&#8203;chiranjib-swain](https://redirect.github.com/chiranjib-swain)
in
[#&#8203;841](https://redirect.github.com/actions/setup-java/pull/841)

##### Dependency updates

- Upgrade prettier from 2.8.8 to 3.6.2 and document breaking changes in
v5 by [@&#8203;dependabot](https://redirect.github.com/dependabot) in
[#&#8203;873](https://redirect.github.com/actions/setup-java/pull/873)
- Upgrade actions/publish-action from 0.3.0 to 0.4.0 by
[@&#8203;dependabot](https://redirect.github.com/dependabot) in
[#&#8203;912](https://redirect.github.com/actions/setup-java/pull/912)

##### New Contributors

- [@&#8203;lmvysakh](https://redirect.github.com/lmvysakh) made their
first contribution in
[#&#8203;903](https://redirect.github.com/actions/setup-java/pull/903)
- [@&#8203;chiranjib-swain](https://redirect.github.com/chiranjib-swain)
made their first contribution in
[#&#8203;841](https://redirect.github.com/actions/setup-java/pull/841)
- [@&#8203;the-mod](https://redirect.github.com/the-mod) made their
first contribution in
[#&#8203;927](https://redirect.github.com/actions/setup-java/pull/927)
- [@&#8203;priya-kinthali](https://redirect.github.com/priya-kinthali)
made their first contribution in
[#&#8203;946](https://redirect.github.com/actions/setup-java/pull/946)
- [@&#8203;guicamest](https://redirect.github.com/guicamest) made their
first contribution in
[#&#8203;736](https://redirect.github.com/actions/setup-java/pull/736)

**Full Changelog**:
<https://github.com/actions/setup-java/compare/v5...v5.1.0>

###
[`v5.0.0`](https://redirect.github.com/actions/setup-java/releases/tag/v5.0.0)

[Compare
Source](https://redirect.github.com/actions/setup-java/compare/v5...v5)

##### What's Changed

##### Breaking Changes

- Upgrade to node 24 by
[@&#8203;salmanmkc](https://redirect.github.com/salmanmkc) in
[#&#8203;888](https://redirect.github.com/actions/setup-java/pull/888)

Make sure your runner is updated to this version or newer to use this
release. v2.327.1 [Release
Notes](https://redirect.github.com/actions/runner/releases/tag/v2.327.1)

##### Dependency Upgrades

- Upgrade Publish Immutable Action by
[@&#8203;HarithaVattikuti](https://redirect.github.com/HarithaVattikuti)
in
[#&#8203;798](https://redirect.github.com/actions/setup-java/pull/798)
- Upgrade eslint-plugin-jest from 27.9.0 to 28.11.0 by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;730](https://redirect.github.com/actions/setup-java/pull/730)
- Upgrade undici from 5.28.5 to 5.29.0 by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;833](https://redirect.github.com/actions/setup-java/pull/833)
- Upgrade form-data to bring in fix for critical vulnerability by
[@&#8203;gowridurgad](https://redirect.github.com/gowridurgad) in
[#&#8203;887](https://redirect.github.com/actions/setup-java/pull/887)
- Upgrade actions/checkout from 4 to 5 by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;896](https://redirect.github.com/actions/setup-java/pull/896)

##### Bug Fixes

- Prevent default installation of JetBrains pre-releases by
[@&#8203;priyagupta108](https://redirect.github.com/priyagupta108) in
[#&#8203;859](https://redirect.github.com/actions/setup-java/pull/859)
- Improve Error Handling for Setup-Java Action to Help Debug
Intermittent Failures by
[@&#8203;gowridurgad](https://redirect.github.com/gowridurgad) in
[#&#8203;848](https://redirect.github.com/actions/setup-java/pull/848)

##### New Contributors

- [@&#8203;gowridurgad](https://redirect.github.com/gowridurgad) made
their first contribution in
[#&#8203;848](https://redirect.github.com/actions/setup-java/pull/848)
- [@&#8203;salmanmkc](https://redirect.github.com/salmanmkc) made their
first contribution in
[#&#8203;888](https://redirect.github.com/actions/setup-java/pull/888)

**Full Changelog**:
<https://github.com/actions/setup-java/compare/v4...v5.0.0>

###
[`v5`](https://redirect.github.com/actions/setup-java/compare/v4.8.0...v5)

[Compare
Source](https://redirect.github.com/actions/setup-java/compare/v4.8.0...v5)

</details>

<details>
<summary>actions/setup-python (actions/setup-python)</summary>

###
[`v6.3.0`](https://redirect.github.com/actions/setup-python/releases/tag/v6.3.0)

[Compare
Source](https://redirect.github.com/actions/setup-python/compare/v6.2.0...v6.3.0)

##### What's Changed

##### Enhancement

- Add RHEL support and include Linux distro in cache keys by
[@&#8203;priyagupta108](https://redirect.github.com/priyagupta108) in
[#&#8203;1323](https://redirect.github.com/actions/setup-python/pull/1323)
- Fix pip cache error handling on Windows by
[@&#8203;priyagupta108](https://redirect.github.com/priyagupta108) in
[#&#8203;1040](https://redirect.github.com/actions/setup-python/pull/1040)

##### Dependency update

- Upgrade minimatch from 3.1.2 to 3.1.5 by
[@&#8203;dependabot](https://redirect.github.com/dependabot) in
[#&#8203;1281](https://redirect.github.com/actions/setup-python/pull/1281)
- Upgrade actions dependencies by
[@&#8203;gowridurgad](https://redirect.github.com/gowridurgad) with
[@&#8203;Copilot](https://redirect.github.com/Copilot) in
[#&#8203;1303](https://redirect.github.com/actions/setup-python/pull/1303)
- Upgrade
[@&#8203;actions/cache](https://redirect.github.com/actions/cache) to
5.1.0, log cache write denied by
[@&#8203;jasongin](https://redirect.github.com/jasongin) in
[#&#8203;1324](https://redirect.github.com/actions/setup-python/pull/1324)
- Upgrade dependency versions and test workflow configuration by
[@&#8203;HarithaVattikuti](https://redirect.github.com/HarithaVattikuti)
in
[#&#8203;1322](https://redirect.github.com/actions/setup-python/pull/1322)

##### Documentation

- Update advanced-usage.md by
[@&#8203;Dunky-Z](https://redirect.github.com/Dunky-Z) in
[#&#8203;811](https://redirect.github.com/actions/setup-python/pull/811)

##### New Contributors

- [@&#8203;gowridurgad](https://redirect.github.com/gowridurgad) with
[@&#8203;Copilot](https://redirect.github.com/Copilot) made their first
contribution in
[#&#8203;1303](https://redirect.github.com/actions/setup-python/pull/1303)
- [@&#8203;jasongin](https://redirect.github.com/jasongin) made their
first contribution in
[#&#8203;1324](https://redirect.github.com/actions/setup-python/pull/1324)
- [@&#8203;Dunky-Z](https://redirect.github.com/Dunky-Z) made their
first contribution in
[#&#8203;811](https://redirect.github.com/actions/setup-python/pull/811)

**Full Changelog**:
<https://github.com/actions/setup-python/compare/v6...v6.3.0>

</details>

<details>
<summary>actions/upload-artifact (actions/upload-artifact)</summary>

###
[`v7.0.1`](https://redirect.github.com/actions/upload-artifact/releases/tag/v7.0.1)

[Compare
Source](https://redirect.github.com/actions/upload-artifact/compare/v7...v7.0.1)

#### What's Changed

- Update the readme with direct upload details by
[@&#8203;danwkennedy](https://redirect.github.com/danwkennedy) in
[#&#8203;795](https://redirect.github.com/actions/upload-artifact/pull/795)
- Readme: bump all the example versions to v7 by
[@&#8203;danwkennedy](https://redirect.github.com/danwkennedy) in
[#&#8203;796](https://redirect.github.com/actions/upload-artifact/pull/796)
- Include changes in typespec/ts-http-runtime 0.3.5 by
[@&#8203;yacaovsnc](https://redirect.github.com/yacaovsnc) in
[#&#8203;797](https://redirect.github.com/actions/upload-artifact/pull/797)

**Full Changelog**:
<https://github.com/actions/upload-artifact/compare/v7...v7.0.1>

###
[`v7.0.0`](https://redirect.github.com/actions/upload-artifact/releases/tag/v7.0.0)

[Compare
Source](https://redirect.github.com/actions/upload-artifact/compare/v7...v7)

#### v7 What's new

##### Direct Uploads

Adds support for uploading single files directly (unzipped). Callers can
set the new `archive` parameter to `false` to skip zipping the file
during upload. Right now, we only support single files. The action will
fail if the glob passed resolves to multiple files. The `name` parameter
is also ignored with this setting. Instead, the name of the artifact
will be the name of the uploaded file.

##### ESM

To support new versions of the `@actions/*` packages, we've upgraded the
package to ESM.

#### What's Changed

- Add proxy integration test by
[@&#8203;Link-](https://redirect.github.com/Link-) in
[#&#8203;754](https://redirect.github.com/actions/upload-artifact/pull/754)
- Upgrade the module to ESM and bump dependencies by
[@&#8203;danwkennedy](https://redirect.github.com/danwkennedy) in
[#&#8203;762](https://redirect.github.com/actions/upload-artifact/pull/762)
- Support direct file uploads by
[@&#8203;danwkennedy](https://redirect.github.com/danwkennedy) in
[#&#8203;764](https://redirect.github.com/actions/upload-artifact/pull/764)

#### New Contributors

- [@&#8203;Link-](https://redirect.github.com/Link-) made their first
contribution in
[#&#8203;754](https://redirect.github.com/actions/upload-artifact/pull/754)

**Full Changelog**:
<https://github.com/actions/upload-artifact/compare/v6...v7.0.0>

###
[`v7`](https://redirect.github.com/actions/upload-artifact/compare/v6.0.0...v7)

[Compare
Source](https://redirect.github.com/actions/upload-artifact/compare/v6.0.0...v7)

###
[`v6.0.0`](https://redirect.github.com/actions/upload-artifact/releases/tag/v6.0.0)

[Compare
Source](https://redirect.github.com/actions/upload-artifact/compare/v6.0.0...v6.0.0)

#### v6 - What's new

> \[!IMPORTANT]
> actions/upload-artifact\@&#8203;v6 now runs on Node.js 24
(`runs.using: node24`) and requires a minimum Actions Runner version of
2.327.1. If you are using self-hosted runners, ensure they are updated
before upgrading.

##### Node.js 24

This release updates the runtime to Node.js 24. v5 had preliminary
support for Node.js 24, however this action was by default still running
on Node.js 20. Now this action by default will run on Node.js 24.

#### What's Changed

- Upload Artifact Node 24 support by
[@&#8203;salmanmkc](https://redirect.github.com/salmanmkc) in
[#&#8203;719](https://redirect.github.com/actions/upload-artifact/pull/719)
- fix: update
[@&#8203;actions/artifact](https://redirect.github.com/actions/artifact)
for Node.js 24 punycode deprecation by
[@&#8203;salmanmkc](https://redirect.github.com/salmanmkc) in
[#&#8203;744](https://redirect.github.com/actions/upload-artifact/pull/744)
- prepare release v6.0.0 for Node.js 24 support by
[@&#8203;salmanmkc](https://redirect.github.com/salmanmkc) in
[#&#8203;745](https://redirect.github.com/actions/upload-artifact/pull/745)

**Full Changelog**:
<https://github.com/actions/upload-artifact/compare/v5.0.0...v6.0.0>

###
[`v6`](https://redirect.github.com/actions/upload-artifact/compare/v5.0.0...v6.0.0)

[Compare
Source](https://redirect.github.com/actions/upload-artifact/compare/v5.0.0...v6.0.0)

###
[`v5.0.0`](https://redirect.github.com/actions/upload-artifact/releases/tag/v5.0.0)

[Compare
Source](https://redirect.github.com/actions/upload-artifact/compare/v5.0.0...v5.0.0)

#### What's Changed

**BREAKING CHANGE:** this update supports Node `v24.x`. This is not a
breaking change per-se but we're treating it as such.

- Update README.md by
[@&#8203;GhadimiR](https://redirect.github.com/GhadimiR) in
[#&#8203;681](https://redirect.github.com/actions/upload-artifact/pull/681)
- Update README.md by
[@&#8203;nebuk89](https://redirect.github.com/nebuk89) in
[#&#8203;712](https://redirect.github.com/actions/upload-artifact/pull/712)
- Readme: spell out the first use of GHES by
[@&#8203;danwkennedy](https://redirect.github.com/danwkennedy) in
[#&#8203;727](https://redirect.github.com/actions/upload-artifact/pull/727)
- Update GHES guidance to include reference to Node 20 version by
[@&#8203;patrikpolyak](https://redirect.github.com/patrikpolyak) in
[#&#8203;725](https://redirect.github.com/actions/upload-artifact/pull/725)
- Bump `@actions/artifact` to `v4.0.0`
- Prepare `v5.0.0` by
[@&#8203;danwkennedy](https://redirect.github.com/danwkennedy) in
[#&#8203;734](https://redirect.github.com/actions/upload-artifact/pull/734)

#### New Contributors

- [@&#8203;GhadimiR](https://redirect.github.com/GhadimiR) made their
first contribution in
[#&#8203;681](https://redirect.github.com/actions/upload-artifact/pull/681)
- [@&#8203;nebuk89](https://redirect.github.com/nebuk89) made their
first contribution in
[#&#8203;712](https://redirect.github.com/actions/upload-artifact/pull/712)
- [@&#8203;danwkennedy](https://redirect.github.com/danwkennedy) made
their first contribution in
[#&#8203;727](https://redirect.github.com/actions/upload-artifact/pull/727)
- [@&#8203;patrikpolyak](https://redirect.github.com/patrikpolyak) made
their first contribution in
[#&#8203;725](https://redirect.github.com/actions/upload-artifact/pull/725)

**Full Changelog**:
<https://github.com/actions/upload-artifact/compare/v4...v5.0.0>

###
[`v5`](https://redirect.github.com/actions/upload-artifact/compare/v4.6.2...v5.0.0)

[Compare
Source](https://redirect.github.com/actions/upload-artifact/compare/v4.6.2...v5.0.0)

</details>

<details>
<summary>astral-sh/setup-uv (astral-sh/setup-uv)</summary>

###
[`v8.3.2`](https://redirect.github.com/astral-sh/setup-uv/compare/v8.3.1...v8.3.2)

[Compare
Source](https://redirect.github.com/astral-sh/setup-uv/compare/v8.3.1...v8.3.2)

###
[`v8.3.1`](https://redirect.github.com/astral-sh/setup-uv/compare/v8.3.0...v8.3.1)

[Compare
Source](https://redirect.github.com/astral-sh/setup-uv/compare/v8.3.0...v8.3.1)

###
[`v8.3.0`](https://redirect.github.com/astral-sh/setup-uv/compare/v8.2.0...v8.3.0)

[Compare
Source](https://redirect.github.com/astral-sh/setup-uv/compare/v8.2.0...v8.3.0)

###
[`v8.2.0`](https://redirect.github.com/astral-sh/setup-uv/releases/tag/v8.2.0):
🌈 New inputs `quiet` and `download-from-astral-mirror`

[Compare
Source](https://redirect.github.com/astral-sh/setup-uv/compare/v8.1.0...v8.2.0)

##### Changes

This release brings two new inputs and a few bug fixes.

##### New inputs

Lets talk about the new inputs first.

##### quiet

Pretty simple. It turns of all `info` loggings. Useful if you use this
in a composite action and are not interested in all the details.
In the upcoming releases we will add log groups to fully implement
support for "less noise"

> \[!NOTE]\
> Warnings and errors are always logged.

##### download-from-astral-mirror

In some cases you may want to directly use the fallback of checking for
available versions and downloading releases from GitHub instead of using
the astral.sh mirror. Setting `download-from-astral-mirror: false`
allows you to do that.

##### Bugfixes

When using the astral.sh mirror to query available versions and download
releases (done by default) we now stop sending the GitHub token in the
header. The mirror never looked at it but we shouldn't be handing out
that data even if it is just a short lived token.
All other bugfixes try to limit the impact of failed GitHub queries due
to retries and other faults.

We couldn't pinpoint all rootcauses yet but added more logging for error
cases to track them down.

##### 🐛 Bug fixes

- fix: report unexpected cache save failures
[@&#8203;eifinger](https://redirect.github.com/eifinger)
([#&#8203;896](https://redirect.github.com/astral-sh/setup-uv/issues/896))
- fix: report unexpected setup failures
[@&#8203;eifinger](https://redirect.github.com/eifinger)
([#&#8203;895](https://redirect.github.com/astral-sh/setup-uv/issues/895))
- fix: add timeout to fetch to prevent silent hangs
[@&#8203;eifinger-bot](https://redirect.github.com/eifinger-bot)
([#&#8203;883](https://redirect.github.com/astral-sh/setup-uv/issues/883))
- Limit GitHub tokens to github.com download URLs
[@&#8203;zsol](https://redirect.github.com/zsol)
([#&#8203;878](https://redirect.github.com/astral-sh/setup-uv/issues/878))
- increase libuv-workaround timeout to 100ms
[@&#8203;eifinger](https://redirect.github.com/eifinger)
([#&#8203;880](https://redirect.github.com/astral-sh/setup-uv/issues/880))

##### 🚀 Enhancements

- Add quiet input to suppress info-level log output
[@&#8203;eifinger](https://redirect.github.com/eifinger)
([#&#8203;898](https://redirect.github.com/astral-sh/setup-uv/issues/898))
- feat: add `download-from-astral-mirror` input
[@&#8203;eifinger](https://redirect.github.com/eifinger)
([#&#8203;897](https://redirect.github.com/astral-sh/setup-uv/issues/897))

##### 🧰 Maintenance

- docs: update dependabot rollup biome guidance
[@&#8203;eifinger](https://redirect.github.com/eifinger)
([#&#8203;902](https://redirect.github.com/astral-sh/setup-uv/issues/902))
- chore: update known checksums for 0.11.18
@&#8203;[github-actions\[bot\]](https://redirect.github.com/apps/github-actions)
([#&#8203;899](https://redirect.github.com/astral-sh/setup-uv/issues/899))
- chore: update known checksums for 0.11.17
@&#8203;[github-actions\[bot\]](https://redirect.github.com/apps/github-actions)
([#&#8203;892](https://redirect.github.com/astral-sh/setup-uv/issues/892))
- chore: update known checksums for 0.11.16 @&#8203;[github-act

> ✂ **Note**
> 
> PR body was truncated to here.


</details>

---

### Configuration

📅 **Schedule**: (in timezone America/Los_Angeles)

- Branch creation
  - "before 9am every weekday"
- Automerge
  - At any time (no schedule defined)

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR is behind base branch, or you tick the
rebase/retry checkbox.

👻 **Immortal**: This PR will be recreated if closed unmerged. Get
[config
help](https://redirect.github.com/renovatebot/renovate/discussions) if
that's undesired.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR was generated by [Mend Renovate](https://mend.io/renovate/).
View the [repository job
log](https://developer.mend.io/github/CopilotKit/CopilotKit).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4yNDIuMiIsInVwZGF0ZWRJblZlciI6IjQzLjI0Mi4yIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6W119-->
2026-07-12 03:03:26 +00:00
renovate[bot] 47ab65c6c0 chore(deps): update github actions 2026-07-12 02:46:24 +00:00
Jordan Ritter 0ffc05bed4 ci: pin ad-hoc CI tool installs to satisfy zizmor adhoc-packages (#5929)
## What

Replaces four ad-hoc `npm install -g` steps (flagged by zizmor's
`adhoc-packages` audit) with lockfile-managed or pinned-action installs.
Root-cause fix, not suppression. Behavior is preserved in every case.

## Per-line fix

| # | File:line (before) | Fix | Why this form |
|---|---|---|---|
| 1 | `test_integration-docs.yml:67` — `npm install -g
@copilotkit/aimock@1.24.1` | Invoke workspace-pinned `llmock` bin from
frozen lockfile | **lockfile-devDep.** The `CopilotKit/aimock` composite
action wraps the newer config-only `aimock` CLI, which does **not**
accept `--fixtures`; these jobs need `--fixtures`/`--validate-on-load`.
`@copilotkit/aimock@1.26.1` is already a dep of
`@copilotkit/showcase-scripts`, so no new dep needed. |
| 2 | `test_e2e-showcase-on-demand.yml:276` — `npm install -g
"@copilotkit/aimock@^1.16.4" --ignore-scripts` | Scoped frozen install +
workspace `llmock` bin (4 `--fixtures` dirs, `/__aimock/health` probe,
PID capture preserved) | Same as above; added an `Install aimock` step
(`pnpm --filter @copilotkit/showcase-scripts install --frozen-lockfile
--ignore-scripts`) before the start step since the full `pnpm install`
runs later in the job. |
| 3 | `social_copy-generator.yml:209` — `npm install -g
@anthropic-ai/claude-code` (unpinned) | Pin
`@anthropic-ai/claude-code@2.1.207` as a root devDependency; install
from frozen lockfile; invoke via `cli-wrapper.cjs` |
**lockfile-devDep.** `anthropics/claude-code-action` is for PR/issue
automation; this job uses `claude -p ... --output-format json` as a
scripted CLI, which the action does not fit. Added
`setup-node`+`pnpm`+install to the job (it had none). |
| 4 | `static_quality.yml:54` — `npm install -g oxfmt@0.36` | Install
from frozen lockfile (`oxfmt` is already a root devDep `^0.36.0`), put
`node_modules/.bin` on PATH | No official oxfmt action → lockfile
devDep. |
| 5 | `static_quality.yml:61` — `pipx install ruff==0.15.13` | Pinned
`astral-sh/ruff-action@278981a28ce3188b1e39527901f38254bf3aac89 #
v4.1.0`, `version: "0.15.13"`, `args: "--version"` (install-only) |
Official action, SHA-pinned. Note: `pipx install` was **not** actually
flagged by zizmor `adhoc-packages` (only the 4 `npm install -g` lines
are), but switching it to the pinned action matches intent and is
strictly better. |

## Red → Green proof

Exact CI invocation: `zizmor --min-severity low --config
.github/zizmor.yml .github/workflows` (zizmor 1.26.1).

**RED (main):** exit `12`, **4** `adhoc-packages` findings:
- `social_copy-generator.yml:209`
- `static_quality.yml:54`
- `test_e2e-showcase-on-demand.yml:276`
- `test_integration-docs.yml:67`

**GREEN (this branch):** exit `0`, **0** `adhoc-packages` findings,
**0** `unpinned-uses` (the new `ruff-action` is SHA-pinned) → `No
findings to report. Good job!`

## Behavior verification (local)

- aimock (both jobs): started the workspace `llmock` bin exactly as each
workflow does — process stays alive, `/health` **and**
`/__aimock/health` return 200, all 4 e2e fixture dirs load with
`--validate-on-load`.
- claude-code: `node
node_modules/@anthropic-ai/claude-code/cli-wrapper.cjs --version` →
`2.1.207 (Claude Code)`; `--help` shows `-p/--print` passthrough.
(Installed with `--ignore-scripts`; the wrapper resolves the native
binary from the installed optionalDependency, the package's documented
fallback path.)
- oxfmt: resolves from `node_modules/.bin`,
`--no-error-on-unmatched-pattern --check` works.
- `pnpm install --frozen-lockfile` passes (exit 0) with the updated
lockfile; lockfile diff is 100% the new `@anthropic-ai/claude-code`
entries (87 additions, zero unrelated churn). `claude-code@2.1.207` is
>24h old, satisfying `.npmrc` `minimum-release-age=1440`.

## Notes

- All new `uses:` are SHA-pinned with a `# vX.Y.Z` comment per repo
convention.
- The heavy local lefthook pre-commit (full Nx test/build) was skipped
for this CI-only YAML change; CI runs the real checks.

🤖 Generated with [Claude Code](https://claude.com/claude-code)
2026-07-11 19:27:08 -07:00
Jordan Ritter e906d0f631 ci: replace ad-hoc tool installs with lockfile/pinned-action installs (zizmor adhoc-packages)
Four workflow steps installed CLI tools ad-hoc via `npm install -g`, which
zizmor's `adhoc-packages` audit flags (install outside a lockfile). Replace
each with a lockfile-managed or pinned-action install, preserving behavior:

- aimock (test_integration-docs, test_e2e-showcase-on-demand): invoke the
  workspace-pinned @copilotkit/aimock `llmock` bin from the frozen lockfile
  (already a dep of @copilotkit/showcase-scripts) instead of `npm install -g`.
  Kept lockfile-devDep rather than the CopilotKit/aimock composite action:
  the action wraps the newer config-only `aimock` CLI and can't do the
  multi-`--fixtures` / `--validate-on-load` / `/__aimock/health` invocation
  these jobs need.
- claude-code (social_copy-generator): pin @anthropic-ai/claude-code as a root
  devDependency, install from the frozen lockfile, invoke via its documented
  cli-wrapper.cjs entrypoint. Kept lockfile-devDep rather than
  anthropics/claude-code-action: the job uses claude as a scripted `-p` CLI,
  not PR/issue automation.
- oxfmt (static_quality): already a root devDependency; install from the frozen
  lockfile and put node_modules/.bin on PATH instead of `npm install -g`.
- ruff (static_quality): switch `pipx install` to the pinned official
  astral-sh/ruff-action@278981a (v4.1.0) with the same 0.15.13 version.

zizmor --min-severity low --config .github/zizmor.yml .github/workflows:
  before: exit 12, 4 adhoc-packages findings
  after:  exit 0,  0 adhoc-packages findings, 0 unpinned-uses (no findings)
2026-07-11 19:19:45 -07:00
Tyler Slaton 87db1b01e7 chore: release channels-whatsapp v0.0.2 (#5924)
## Release channels-whatsapp v0.0.2

**Scope:** `channels-whatsapp` | **Bump:** `patch`

---

### How this release process works

1. **This PR was created automatically** by the "release / create-pr"
workflow.
   It bumped the `channels-whatsapp` packages to `0.0.2`
   and generated AI-enhanced release notes.

2. **CI runs on this PR** — the full test suite (unit tests, lint, type
checks, build)
   must pass before merging. This is the review gate.

3. **Review the release notes** in `release-notes.md` in this PR.
If a Notion draft was created, you can edit the release notes there
before merging.

4. **When this PR is merged**, the `release / publish` workflow
automatically:
   - Builds all packages
- Publishes the `channels-whatsapp` packages to npm at version `0.0.2`
   - Creates git tag `channels-whatsapp/v0.0.2`
   - Creates a GitHub Release with the final release notes

### Before merging

- [ ] CI is green (tests, lint, types, build)
- [ ] Version bumps look correct
- [ ] Release notes are accurate (edit in Notion if a draft was created)

---

> **Do not merge until CI is fully green.** The full test suite runs
automatically on this PR.
channels-whatsapp/v0.0.2
2026-07-10 15:56:51 -07:00
Tyler Slaton 41caca8f2c chore: release channels-telegram v0.0.4 (#5923)
## Release channels-telegram v0.0.4

**Scope:** `channels-telegram` | **Bump:** `patch`

---

### How this release process works

1. **This PR was created automatically** by the "release / create-pr"
workflow.
   It bumped the `channels-telegram` packages to `0.0.4`
   and generated AI-enhanced release notes.

2. **CI runs on this PR** — the full test suite (unit tests, lint, type
checks, build)
   must pass before merging. This is the review gate.

3. **Review the release notes** in `release-notes.md` in this PR.
If a Notion draft was created, you can edit the release notes there
before merging.

4. **When this PR is merged**, the `release / publish` workflow
automatically:
   - Builds all packages
- Publishes the `channels-telegram` packages to npm at version `0.0.4`
   - Creates git tag `channels-telegram/v0.0.4`
   - Creates a GitHub Release with the final release notes

### Before merging

- [ ] CI is green (tests, lint, types, build)
- [ ] Version bumps look correct
- [ ] Release notes are accurate (edit in Notion if a draft was created)

---

> **Do not merge until CI is fully green.** The full test suite runs
automatically on this PR.
channels-telegram/v0.0.4
2026-07-10 15:56:41 -07:00
Tyler Slaton 6f038317c7 chore: release channels-intelligence v0.1.1 (#5920)
## Release channels-intelligence v0.1.1

**Scope:** `channels-intelligence` | **Bump:** `patch`

---

### How this release process works

1. **This PR was created automatically** by the "release / create-pr"
workflow.
   It bumped the `channels-intelligence` packages to `0.1.1`
   and generated AI-enhanced release notes.

2. **CI runs on this PR** — the full test suite (unit tests, lint, type
checks, build)
   must pass before merging. This is the review gate.

3. **Review the release notes** in `release-notes.md` in this PR.
If a Notion draft was created, you can edit the release notes there
before merging.

4. **When this PR is merged**, the `release / publish` workflow
automatically:
   - Builds all packages
- Publishes the `channels-intelligence` packages to npm at version
`0.1.1`
   - Creates git tag `channels-intelligence/v0.1.1`
   - Creates a GitHub Release with the final release notes

### Before merging

- [ ] CI is green (tests, lint, types, build)
- [ ] Version bumps look correct
- [ ] Release notes are accurate (edit in Notion if a draft was created)

---

> **Do not merge until CI is fully green.** The full test suite runs
automatically on this PR.
channels-intelligence/v0.1.1
2026-07-10 15:56:32 -07:00
Tyler Slaton e99e1dc746 chore: release channels-teams v0.1.2 (#5921)
## Release channels-teams v0.1.2

**Scope:** `channels-teams` | **Bump:** `patch`

---

### How this release process works

1. **This PR was created automatically** by the "release / create-pr"
workflow.
   It bumped the `channels-teams` packages to `0.1.2`
   and generated AI-enhanced release notes.

2. **CI runs on this PR** — the full test suite (unit tests, lint, type
checks, build)
   must pass before merging. This is the review gate.

3. **Review the release notes** in `release-notes.md` in this PR.
If a Notion draft was created, you can edit the release notes there
before merging.

4. **When this PR is merged**, the `release / publish` workflow
automatically:
   - Builds all packages
   - Publishes the `channels-teams` packages to npm at version `0.1.2`
   - Creates git tag `channels-teams/v0.1.2`
   - Creates a GitHub Release with the final release notes

### Before merging

- [ ] CI is green (tests, lint, types, build)
- [ ] Version bumps look correct
- [ ] Release notes are accurate (edit in Notion if a draft was created)

---

> **Do not merge until CI is fully green.** The full test suite runs
automatically on this PR.
channels-teams/v0.1.2
2026-07-10 15:56:14 -07:00
Tyler Slaton cb1fd90827 chore: release channels-slack v0.1.2 (#5922)
## Release channels-slack v0.1.2

**Scope:** `channels-slack` | **Bump:** `patch`

---

### How this release process works

1. **This PR was created automatically** by the "release / create-pr"
workflow.
   It bumped the `channels-slack` packages to `0.1.2`
   and generated AI-enhanced release notes.

2. **CI runs on this PR** — the full test suite (unit tests, lint, type
checks, build)
   must pass before merging. This is the review gate.

3. **Review the release notes** in `release-notes.md` in this PR.
If a Notion draft was created, you can edit the release notes there
before merging.

4. **When this PR is merged**, the `release / publish` workflow
automatically:
   - Builds all packages
   - Publishes the `channels-slack` packages to npm at version `0.1.2`
   - Creates git tag `channels-slack/v0.1.2`
   - Creates a GitHub Release with the final release notes

### Before merging

- [ ] CI is green (tests, lint, types, build)
- [ ] Version bumps look correct
- [ ] Release notes are accurate (edit in Notion if a draft was created)

---

> **Do not merge until CI is fully green.** The full test suite runs
automatically on this PR.
channels-slack/v0.1.2
2026-07-10 15:56:07 -07:00
Tyler Slaton 8427fa187e chore: release channels-discord v0.0.3 (#5919)
## Release channels-discord v0.0.3

**Scope:** `channels-discord` | **Bump:** `patch`

---

### How this release process works

1. **This PR was created automatically** by the "release / create-pr"
workflow.
   It bumped the `channels-discord` packages to `0.0.3`
   and generated AI-enhanced release notes.

2. **CI runs on this PR** — the full test suite (unit tests, lint, type
checks, build)
   must pass before merging. This is the review gate.

3. **Review the release notes** in `release-notes.md` in this PR.
If a Notion draft was created, you can edit the release notes there
before merging.

4. **When this PR is merged**, the `release / publish` workflow
automatically:
   - Builds all packages
   - Publishes the `channels-discord` packages to npm at version `0.0.3`
   - Creates git tag `channels-discord/v0.0.3`
   - Creates a GitHub Release with the final release notes

### Before merging

- [ ] CI is green (tests, lint, types, build)
- [ ] Version bumps look correct
- [ ] Release notes are accurate (edit in Notion if a draft was created)

---

> **Do not merge until CI is fully green.** The full test suite runs
automatically on this PR.
channels-discord/v0.0.3
2026-07-10 15:55:57 -07:00
Tyler Slaton 5e389aab83 chore: release channels v0.1.1 (#5918)
## Release channels v0.1.1

**Scope:** `channels` | **Bump:** `patch`

---

### How this release process works

1. **This PR was created automatically** by the "release / create-pr"
workflow.
   It bumped the `channels` packages to `0.1.1`
   and generated AI-enhanced release notes.

2. **CI runs on this PR** — the full test suite (unit tests, lint, type
checks, build)
   must pass before merging. This is the review gate.

3. **Review the release notes** in `release-notes.md` in this PR.
If a Notion draft was created, you can edit the release notes there
before merging.

4. **When this PR is merged**, the `release / publish` workflow
automatically:
   - Builds all packages
   - Publishes the `channels` packages to npm at version `0.1.1`
   - Creates git tag `channels/v0.1.1`
   - Creates a GitHub Release with the final release notes

### Before merging

- [ ] CI is green (tests, lint, types, build)
- [ ] Version bumps look correct
- [ ] Release notes are accurate (edit in Notion if a draft was created)

---

> **Do not merge until CI is fully green.** The full test suite runs
automatically on this PR.
channels/v0.1.1
2026-07-10 15:55:56 -07:00
tylerslaton 4c04e8028e chore: release channels-whatsapp v0.0.2 2026-07-10 22:45:18 +00:00
tylerslaton 6281beaf6f chore: release channels-telegram v0.0.4 2026-07-10 22:45:08 +00:00
tylerslaton 2893feecde chore: release channels-teams v0.1.2 2026-07-10 22:44:52 +00:00
tylerslaton 4ce3124c5c chore: release channels-slack v0.1.2 2026-07-10 22:44:52 +00:00
tylerslaton f4e19e2039 chore: release channels-intelligence v0.1.1 2026-07-10 22:44:50 +00:00
tylerslaton ceae64cf1b chore: release channels-discord v0.0.3 2026-07-10 22:44:42 +00:00
tylerslaton ea50654ec0 chore: release channels v0.1.1 2026-07-10 22:44:26 +00:00
Ben Taylor 77d43dcb1a refactor(channels-intelligence): migrate to Channels API (#5916)
## Problem

`@copilotkit/channels-intelligence` still used the retired Bot
HTTP/realtime contract and exposed Phoenix implementation details. The
managed Slack entrypoint used the same legacy API.

## Why

Intelligence now exposes a clean-break Channels contract. The SDK must
use it consistently, while keeping the Phoenix-backed transport private
behind a product-neutral Realtime Gateway API. Compatibility aliases
would hide integration mismatches.

## Fix

- Migrated HTTP paths, payloads, config, and KV state to Channel
terminology.
- Added the Realtime Gateway abstraction and Channel realtime wire
contract.
- Renamed remaining APIs/types, updated the managed Slack example, and
added forbidden-term coverage.
- Preserved framework and vendor `Bot` terminology only where it remains
semantically correct.
2026-07-10 17:29:03 -05:00
Tyler Slaton 001dda539a chore(channels-intelligence): complete channel terminology sweep 2026-07-10 14:47:06 -07:00
Ben Taylor 4970f55878 Add Inspector Threads empty-state onboarding (#5909)
## Summary

Adds production onboarding for the Inspector Threads empty state:

- Moves the Threads `Talk to an Engineer` CTA into the main inspector
tab nav when Threads is active.
- Replaces the enabled-empty `No threads yet` state with example thread
rows and a deselected overview.
- Lets users select an example thread to preview the real thread-details
UI with Timeline, Raw AG-UI Events, and State data.
- Adds a dismissible/reopenable example tour that persists dismissal in
local storage.
- Hides examples once real threads are present.
- Adds the `Learn how Threads work` and `Explore self-hosted
Intelligence` CTAs.
- Adds a deferred autoplay video preview to the enabled-empty deselected
overview.

## Telemetry

New/updated Threads events in this PR:

- `oss.inspector.threads_tab_clicked` — fires when the rendered Threads
nav tab is clicked.
- `oss.inspector.threads_locked_viewed` — fires once per inspector
instance for the locked state.
- `oss.inspector.threads_empty_enabled_viewed` — fires once per
inspector instance when Threads are enabled with zero real threads.
- `oss.inspector.threads_enabled_viewed` — fires once per inspector
instance when real threads are present.
- `oss.inspector.threads_intelligence_signup_clicked` — fires from
locked-state Intelligence signup CTAs.
- `oss.inspector.threads_talk_to_engineer_clicked` /
`oss.inspector.talk_to_engineer_clicked` — fire from Threads-specific
and shared Talk to an Engineer CTAs.
- `oss.inspector.threads_example_viewed` — fires once per example thread
shown in the empty state.
- `oss.inspector.threads_example_selected` — fires once per example
thread selection.
- `oss.inspector.threads_example_tour_started` — fires when the tour
auto-starts for the first selected example.
- `oss.inspector.threads_example_tour_step_viewed` — fires once per
example thread/tour step.
- `oss.inspector.threads_example_tour_dismissed` — fires when the user
skips the tour.
- `oss.inspector.threads_example_tour_completed` — fires when the user
finishes the tour.
- `oss.inspector.threads_example_tour_reopened` — fires when the user
clicks `Show tour` after dismissal.

Telemetry properties are limited to product metadata and funnel context:
package/version, inspector distinct IDs,
intelligence/thread-service/license/runtime status, runtime URL type,
CTA surface/type, telemetry-disabled status, thread count, example
thread ID, tour step/tab, and dismiss method. We do **not** send message
content, AG-UI event payloads, agent state, prompts, completions, or
thread bodies.

No telemetry was added for passive video loading; it is a visual
affordance rather than a user intent signal.

## Outbound Attribution

Threads onboarding CTAs now include existing `ref` attribution plus
these UTM parameters:

- `utm_source=copilotkit_inspector`
- `utm_medium=in_product`
- `utm_campaign=threads_onboarding`

Affected links are limited to Threads onboarding surfaces:

- Threads tab-nav `Talk to an Engineer`
- Threads locked-state `Sign up for Intelligence`
(`https://dashboard.operations.copilotkit.ai/sign-in`)
- Empty Threads overview `Learn how Threads work`
- Empty Threads overview `Explore self-hosted Intelligence`

The UTM params are opt-in for these Threads onboarding CTAs and do not
apply to generic announcement/banner links or locked Memories CTAs. The
inspector spec includes a regression test to keep locked Memories CTAs
free of the Threads campaign params.

## Video Asset + Performance

- The overview video uses the CDN-hosted asset at
`https://cdn.copilotkit.ai/corp-site/videos/copilotkit-generative-ui-agentic-frontend-demo.webm`
instead of committing a binary to `@copilotkit/web-inspector`.
- Verified the URL serves `200`, `Content-Type: video/webm`,
`Content-Length: 6765736`, and a CloudFront cache hit.
- `@copilotkit/web-inspector` currently only inlines CSS and SVG assets
in its package build, while larger docs/showcase media commonly lives on
hosted/CDN-style URLs.
- The video `src` is not rendered on the initial overview paint. It is
deferred until `requestIdleCallback` or a short timeout fallback, uses
`preload="metadata"`, fades in after `loadeddata`, and does not load for
`prefers-reduced-motion: reduce`.

## Validation

- `NX_TUI=false npx -y pnpm@10.33.4 nx run
@copilotkit/web-inspector:test -- web-inspector.spec.ts`
- `NX_TUI=false npx -y pnpm@10.33.4 nx run
@copilotkit/web-inspector:check-types`

<img width="1662" height="1382" alt="CleanShot 2026-07-10 at 12 01
03@2x"
src="https://github.com/user-attachments/assets/e2031570-f602-40dc-a54c-e9c7690fc0ba"
/>
<img width="1680" height="1388" alt="CleanShot 2026-07-10 at 12 01
12@2x"
src="https://github.com/user-attachments/assets/2c8db42f-3ab0-47e2-a235-ea54e8dd292b"
/>
2026-07-10 16:46:32 -05:00
Tyler Slaton 68e43fefe1 refactor(channels-intelligence): rename remaining channel APIs 2026-07-10 14:39:56 -07:00
Sam Julien b9091c40a4 fix(web-inspector): address threads onboarding review 2026-07-10 14:11:55 -07:00