Commit Graph

12980 Commits

Author SHA1 Message Date
Jordan Ritter 5cfb6ac717 test(showcase/langgraph-typescript): make watchdog tests genuinely gate
The watchdog test cluster in test_entrypoint_watchdog.py had three soundness
defects that let tests pass without exercising real behavior.

1. test_size_pid_reaped_by_in_subshell_trap asserted the literal
   trap kill $SIZE_PID string, which exists ONLY in an explanatory comment
   describing the old design. The shipped code registers
   trap _reap_watchdog_children EXIT, so the test passed even when the real
   trap registration was removed. Now asserts the shipped registration on an
   executable (comment-stripped) line and that the named handler is defined.

2. test_size_pid_reaped_on_watchdog_exit_behavioral wrote its own mock
   watchdog using the older SIZE_PID trap shape and never invoked shipped
   code, so it passed even when the shipped reaper was gutted. Now extracts
   the real _agent_descendants and _reap_watchdog_children definitions
   verbatim from entrypoint.sh and drives them with the shipped order.

3. dummy_was_killed used a single-shot dummy.poll() immediately after the
   run returned, racing the asynchronous SIGKILL delivery. Replaced with
   bounded _wait_process_exited / _assert_still_alive helpers selected by
   return code, making the killed/alive assertion deterministic.

entrypoint.sh unchanged. 22 passed; determinism confirmed by repeated runs.
2026-07-13 11:15:25 -07:00
Jordan Ritter 28ed085408 fix(showcase/langgraph-typescript): disable FileSystemPersistence disk flush
The langgraph-typescript backend's @langchain/langgraph-api FileSystemPersistence
serialises all accumulated thread/run/checkpoint state to .langgraph_api on a
3-second timer. Under the D6 probe fan-out (36 parallel probes) the dir filled
past the 200MB size-watchdog threshold in ~90s, the watchdog killed the agent,
and on rapid restart the D6 cron refilled and re-tripped it until Railway
crash-loop backoff stopped restarting the container (2026-07-13 outage, staging
and prod).

Mirror PR #5825's langgraph-python fix, which exported
LANGGRAPH_DISABLE_FILE_PERSISTENCE=true so the python inmem runtime skips its
flush-to-disk loop. The TS package has no such switch and its persistence
writers are unexported module singletons behind an exports-map wall, so ship a
node --import preload (src/agent/disable-file-persistence.mjs) that, gated on the
same env var, no-ops node:fs/promises writeFile/mkdir for .langgraph_api paths
while leaving in-memory state (the real runtime state) intact. Wire it into
npm start and export the env var in entrypoint.sh.

Behavior preserved: runs still execute and thread state reads back from the
in-memory checkpointer within the container lifetime; only disk persistence is
removed, so the size-watchdog has nothing to fill and never trips under load.
2026-07-13 10:50:25 -07:00
Ben Taylor 2c22f212bc fix(channels-teams): fail-loud egress + document HITL button envelope (0.1.2) (#5917)
## Summary

Two fixes to `@copilotkit/channels-teams` found while Intelligence PR
#511 (managed Microsoft Teams, **OSS-450**) deep-imports this package's
run renderer for managed egress. Ships as **0.1.2** so Intelligence can
bump the pin.

## 1. Fail-loud final send (silent egress failure)

`TeamsMessageStream.flushNow()` caught every POST/PUT failure and
resolved, so `finish()` resolved **after a failed final send** — a
consumer then marks the turn "sent" though nothing was delivered
(reproduced: a `post` throwing `provider_down` logged to console but the
end handler resolved successfully).

- `finish()` now drains the throttled queue, then performs the **final
send fail-loud**: a transport failure **rejects** so the caller can
fail/retry.
- Mid-stream throttled edits stay **tolerant** (log + retry on the next
flush) — a dropped edit shouldn't sink a streaming reply.
- Refactor: a shared `doSend()` advances `posted` only *after* the
transport call succeeds (a throw leaves it for retry); `flushNow`
swallows, `flushFinal` propagates.
- **Tests:** final `post` failure → `finish()` rejects; final `update`
failure → rejects; a mid-stream edit failure is tolerated and the final
flush still delivers.

## 2. HITL button action envelope (documented + contract-tested)

Confirmed the actual emitted/inbound shape and published an
authoritative note (`docs/button-action-envelope.md`) + a round-trip
contract test (`src/button-action-envelope.contract.test.ts`) so the
Intelligence ingress can decode clicks out-of-band.

**Outbound** — a `<Button>` renders as a top-level **`Action.Submit`**
(deliberately *not* `Action.Execute` — no `verb`); the opaque id + value
ride in `data`:

```jsonc
{ "type": "Action.Submit", "title": "Approve",
  "data": { "ckActionId": "ck:approve", "value": { "decision": "yes" } },
  "style": "positive" }
```
(`data.ckActionId` only when the Button has an `onClick`; `data.value`
only when it has a `value` prop. A link Button → `Action.OpenUrl`, no
`data`.)

**Inbound** — Teams delivers the click as a **Message activity** (`type:
"message"`), *not* an invoke/`Action.Execute`. The action `data` becomes
`activity.value`; `text` is empty:

```jsonc
{ "type": "message", "text": "",
  "value": { "ckActionId": "ck:approve", "value": { "decision": "yes" } },
  "conversation": { "id": "<stable conversation id>" } }
```
**Decode:** it's a card action iff `typeof activity.value.ckActionId ===
"string"`; then `id = activity.value.ckActionId`, `value =
activity.value.value`. Any `<Input>`/`<Select>` values are merged into
`activity.value` alongside these. Derive the conversation key from
`activity.conversation.id`.

## Verification

`@copilotkit/channels-teams`: **88 tests pass** (incl. the 3 new
fail-loud stream tests + the new envelope contract test), `tsc` build
clean.

Refs Intelligence **OSS-450** / PR #511 (cross-repo consumer).

🤖 Generated with [Claude Code](https://claude.com/claude-code)
2026-07-13 09:06:49 -05:00
github-actions[bot] 1b057bf9df style: auto-fix formatting 2026-07-13 08:16:05 -05:00
Benjamin Taylor 6b6ee2e3c7 docs(channels-teams): document HITL button action envelope + contract test
Authoritative wire shape for the Action.Submit button + the Message activity Teams
delivers on click (activity.value carries { ckActionId, value }, text empty; not
Action.Execute). Round-trip contract test locks emit↔decode.
2026-07-13 08:16:05 -05:00
Benjamin Taylor 14a2276818 fix(channels-teams): fail-loud final send in TeamsMessageStream
finish() now performs the final send outside the error-swallowing throttle path
and rejects on transport failure, so a consumer never marks a turn delivered when
the last post/update didn't land. Mid-stream edits stay tolerant (log + retry).
2026-07-13 08:16:05 -05:00
renovate[bot] 62a46840e3 chore(deps): update github actions (#5845)
> ℹ️ **Note**
> 
> This PR body was truncated due to platform limits.

This PR contains the following updates:

| Package | Type | Update | Change |
|---|---|---|---|
| [actions/cache](https://redirect.github.com/actions/cache) | action |
major | `v5.0.5` → `v6.1.0` |
| [actions/checkout](https://redirect.github.com/actions/checkout) |
action | major | `v4` → `v7` |
|
[actions/download-artifact](https://redirect.github.com/actions/download-artifact)
| action | major | `v4` → `v8` |
|
[actions/github-script](https://redirect.github.com/actions/github-script)
| action | major | `v7` → `v9` |
| [actions/setup-java](https://redirect.github.com/actions/setup-java) |
action | major | `v4.8.0` → `v5.5.0` |
|
[actions/setup-python](https://redirect.github.com/actions/setup-python)
| action | minor | `v6.2.0` → `v6.3.0` |
|
[actions/upload-artifact](https://redirect.github.com/actions/upload-artifact)
| action | major | `v4.6.2` → `v7.0.1` |
|
[actions/upload-artifact](https://redirect.github.com/actions/upload-artifact)
| action | major | `v4` → `v7` |
| [astral-sh/setup-uv](https://redirect.github.com/astral-sh/setup-uv) |
action | major | `v6` → `v8.3.2` |
| [astral-sh/setup-uv](https://redirect.github.com/astral-sh/setup-uv) |
action | minor | `v8.1.0` → `v8.3.2` |
|
[docker/build-push-action](https://redirect.github.com/docker/build-push-action)
| action | major | `v6` → `v7` |
| [docker/login-action](https://redirect.github.com/docker/login-action)
| action | minor | `v4.2.0` → `v4.4.0` |
| [dorny/paths-filter](https://redirect.github.com/dorny/paths-filter) |
action | patch | `v4.0.1` → `v4.0.2` |
| [pnpm/action-setup](https://redirect.github.com/pnpm/action-setup) |
action | patch | `v6.0.8` → `v6.0.9` |
|
[preactjs/compressed-size-action](https://redirect.github.com/preactjs/compressed-size-action)
| action | minor | `2.9.1` → `2.10.0` |
| [ruby/setup-ruby](https://redirect.github.com/ruby/setup-ruby) |
action | minor | `v1.310.0` → `v1.316.0` |
|
[slackapi/slack-github-action](https://redirect.github.com/slackapi/slack-github-action)
| action | major | `v2.1.0` → `v3.0.5` |
| [snok/install-poetry](https://redirect.github.com/snok/install-poetry)
| action | patch | `v1.4.1` → `v1.4.2` |
|
[zizmorcore/zizmor-action](https://redirect.github.com/zizmorcore/zizmor-action)
| action | patch | `v0.5.6` → `v0.5.7` |

---

> [!WARNING]
> Some dependencies could not be looked up. Check the [Dependency
Dashboard](../issues/592) for more information.

---

### Release Notes

<details>
<summary>actions/cache (actions/cache)</summary>

###
[`v6.1.0`](https://redirect.github.com/actions/cache/releases/tag/v6.1.0)

[Compare
Source](https://redirect.github.com/actions/cache/compare/v6.0.0...v6.1.0)

##### What's Changed

- Bump
[@&#8203;actions/cache](https://redirect.github.com/actions/cache) to
v6.1.0 - handle read-only cache access by
[@&#8203;jasongin](https://redirect.github.com/jasongin) in
[#&#8203;1768](https://redirect.github.com/actions/cache/pull/1768)

**Full Changelog**:
<https://github.com/actions/cache/compare/v6...v6.1.0>

###
[`v6.0.0`](https://redirect.github.com/actions/cache/releases/tag/v6.0.0)

[Compare
Source](https://redirect.github.com/actions/cache/compare/v6.0.0...v6.0.0)

#### What's Changed

- Update packages, migrate to ESM by
[@&#8203;Samirat](https://redirect.github.com/Samirat) in
[#&#8203;1760](https://redirect.github.com/actions/cache/pull/1760)

**Full Changelog**:
<https://github.com/actions/cache/compare/v5...v6.0.0>

###
[`v6`](https://redirect.github.com/actions/cache/compare/v5.0.5...v6.0.0)

[Compare
Source](https://redirect.github.com/actions/cache/compare/v5.1.0...v6.0.0)

###
[`v5.1.0`](https://redirect.github.com/actions/cache/releases/tag/v5.1.0)

[Compare
Source](https://redirect.github.com/actions/cache/compare/v5.0.5...v5.1.0)

##### What's Changed

- Bump
[@&#8203;actions/cache](https://redirect.github.com/actions/cache) to
v5.1.0 - handle read-only cache access by
[@&#8203;jasongin](https://redirect.github.com/jasongin) in
[#&#8203;1775](https://redirect.github.com/actions/cache/pull/1775)

**Full Changelog**:
<https://github.com/actions/cache/compare/v5...v5.1.0>

</details>

<details>
<summary>actions/checkout (actions/checkout)</summary>

###
[`v7.0.0`](https://redirect.github.com/actions/checkout/blob/HEAD/CHANGELOG.md#v700)

[Compare
Source](https://redirect.github.com/actions/checkout/compare/v7.0.0...v7.0.0)

- Block checking out fork PR for pull\_request\_target and workflow\_run
by [@&#8203;aiqiaoy](https://redirect.github.com/aiqiaoy) in
[#&#8203;2454](https://redirect.github.com/actions/checkout/pull/2454)
- Bump actions/publish-immutable-action from 0.0.3 to 0.0.4 in the
minor-actions-dependencies group across 1 directory by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;2458](https://redirect.github.com/actions/checkout/pull/2458)
- Bump flatted from 3.3.1 to 3.4.2 by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;2460](https://redirect.github.com/actions/checkout/pull/2460)
- Bump js-yaml from 4.1.0 to 4.2.0 by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;2461](https://redirect.github.com/actions/checkout/pull/2461)
- Bump [@&#8203;actions/core](https://redirect.github.com/actions/core)
and
[@&#8203;actions/tool-cache](https://redirect.github.com/actions/tool-cache)
and Remove uuid by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;2459](https://redirect.github.com/actions/checkout/pull/2459)
- upgrade module to esm and update dependencies by
[@&#8203;aiqiaoy](https://redirect.github.com/aiqiaoy) in
[#&#8203;2463](https://redirect.github.com/actions/checkout/pull/2463)
- Bump the minor-npm-dependencies group across 1 directory with 3
updates by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;2462](https://redirect.github.com/actions/checkout/pull/2462)

###
[`v7`](https://redirect.github.com/actions/checkout/blob/HEAD/CHANGELOG.md#v700)

[Compare
Source](https://redirect.github.com/actions/checkout/compare/v6.0.3...v7.0.0)

- Block checking out fork PR for pull\_request\_target and workflow\_run
by [@&#8203;aiqiaoy](https://redirect.github.com/aiqiaoy) in
[#&#8203;2454](https://redirect.github.com/actions/checkout/pull/2454)
- Bump actions/publish-immutable-action from 0.0.3 to 0.0.4 in the
minor-actions-dependencies group across 1 directory by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;2458](https://redirect.github.com/actions/checkout/pull/2458)
- Bump flatted from 3.3.1 to 3.4.2 by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;2460](https://redirect.github.com/actions/checkout/pull/2460)
- Bump js-yaml from 4.1.0 to 4.2.0 by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;2461](https://redirect.github.com/actions/checkout/pull/2461)
- Bump [@&#8203;actions/core](https://redirect.github.com/actions/core)
and
[@&#8203;actions/tool-cache](https://redirect.github.com/actions/tool-cache)
and Remove uuid by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;2459](https://redirect.github.com/actions/checkout/pull/2459)
- upgrade module to esm and update dependencies by
[@&#8203;aiqiaoy](https://redirect.github.com/aiqiaoy) in
[#&#8203;2463](https://redirect.github.com/actions/checkout/pull/2463)
- Bump the minor-npm-dependencies group across 1 directory with 3
updates by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;2462](https://redirect.github.com/actions/checkout/pull/2462)

###
[`v6.0.3`](https://redirect.github.com/actions/checkout/blob/HEAD/CHANGELOG.md#v603)

[Compare
Source](https://redirect.github.com/actions/checkout/compare/v6.0.2...v6.0.3)

- Fix checkout init for SHA-256 repositories by
[@&#8203;yaananth](https://redirect.github.com/yaananth) in
[#&#8203;2439](https://redirect.github.com/actions/checkout/pull/2439)
- fix: expand merge commit SHA regex and add SHA-256 test cases by
[@&#8203;yaananth](https://redirect.github.com/yaananth) in
[#&#8203;2414](https://redirect.github.com/actions/checkout/pull/2414)

###
[`v6.0.2`](https://redirect.github.com/actions/checkout/blob/HEAD/CHANGELOG.md#v602)

[Compare
Source](https://redirect.github.com/actions/checkout/compare/v6.0.1...v6.0.2)

- Fix tag handling: preserve annotations and explicit fetch-tags by
[@&#8203;ericsciple](https://redirect.github.com/ericsciple) in
[#&#8203;2356](https://redirect.github.com/actions/checkout/pull/2356)

###
[`v6.0.1`](https://redirect.github.com/actions/checkout/blob/HEAD/CHANGELOG.md#v601)

[Compare
Source](https://redirect.github.com/actions/checkout/compare/v6...v6.0.1)

- Add worktree support for persist-credentials includeIf by
[@&#8203;ericsciple](https://redirect.github.com/ericsciple) in
[#&#8203;2327](https://redirect.github.com/actions/checkout/pull/2327)

###
[`v6.0.0`](https://redirect.github.com/actions/checkout/blob/HEAD/CHANGELOG.md#v600)

[Compare
Source](https://redirect.github.com/actions/checkout/compare/v6...v6)

- Persist creds to a separate file by
[@&#8203;ericsciple](https://redirect.github.com/ericsciple) in
[#&#8203;2286](https://redirect.github.com/actions/checkout/pull/2286)
- Update README to include Node.js 24 support details and requirements
by [@&#8203;salmanmkc](https://redirect.github.com/salmanmkc) in
[#&#8203;2248](https://redirect.github.com/actions/checkout/pull/2248)

###
[`v6`](https://redirect.github.com/actions/checkout/blob/HEAD/CHANGELOG.md#v603)

[Compare
Source](https://redirect.github.com/actions/checkout/compare/v5.0.1...v6)

- Fix checkout init for SHA-256 repositories by
[@&#8203;yaananth](https://redirect.github.com/yaananth) in
[#&#8203;2439](https://redirect.github.com/actions/checkout/pull/2439)
- fix: expand merge commit SHA regex and add SHA-256 test cases by
[@&#8203;yaananth](https://redirect.github.com/yaananth) in
[#&#8203;2414](https://redirect.github.com/actions/checkout/pull/2414)

###
[`v5.0.1`](https://redirect.github.com/actions/checkout/blob/HEAD/CHANGELOG.md#v501)

[Compare
Source](https://redirect.github.com/actions/checkout/compare/v5...v5.0.1)

- Port v6 cleanup to v5 by
[@&#8203;ericsciple](https://redirect.github.com/ericsciple) in
[#&#8203;2301](https://redirect.github.com/actions/checkout/pull/2301)

###
[`v5.0.0`](https://redirect.github.com/actions/checkout/blob/HEAD/CHANGELOG.md#v500)

[Compare
Source](https://redirect.github.com/actions/checkout/compare/v5...v5)

- Update actions checkout to use node 24 by
[@&#8203;salmanmkc](https://redirect.github.com/salmanmkc) in
[#&#8203;2226](https://redirect.github.com/actions/checkout/pull/2226)

###
[`v5`](https://redirect.github.com/actions/checkout/blob/HEAD/CHANGELOG.md#v501)

[Compare
Source](https://redirect.github.com/actions/checkout/compare/v4.3.1...v5)

- Port v6 cleanup to v5 by
[@&#8203;ericsciple](https://redirect.github.com/ericsciple) in
[#&#8203;2301](https://redirect.github.com/actions/checkout/pull/2301)

</details>

<details>
<summary>actions/download-artifact (actions/download-artifact)</summary>

###
[`v8.0.1`](https://redirect.github.com/actions/download-artifact/releases/tag/v8.0.1)

[Compare
Source](https://redirect.github.com/actions/download-artifact/compare/v8...v8.0.1)

#### What's Changed

- Support for CJK characters in the artifact name by
[@&#8203;danwkennedy](https://redirect.github.com/danwkennedy) in
[#&#8203;471](https://redirect.github.com/actions/download-artifact/pull/471)
- Add a regression test for artifact name + content-type mismatches by
[@&#8203;danwkennedy](https://redirect.github.com/danwkennedy) in
[#&#8203;472](https://redirect.github.com/actions/download-artifact/pull/472)

**Full Changelog**:
<https://github.com/actions/download-artifact/compare/v8...v8.0.1>

###
[`v8.0.0`](https://redirect.github.com/actions/download-artifact/releases/tag/v8.0.0)

[Compare
Source](https://redirect.github.com/actions/download-artifact/compare/v8...v8)

#### v8 - What's new

> \[!IMPORTANT]
> actions/download-artifact\@&#8203;v8 has been migrated to an ESM
module. This should be transparent to the caller but forks might need to
make significant changes.

> \[!IMPORTANT]
> Hash mismatches will now error by default. Users can override this
behavior with a setting change (see below).

##### Direct downloads

To support direct uploads in `actions/upload-artifact`, the action will
no longer attempt to unzip all downloaded files. Instead, the action
checks the `Content-Type` header ahead of unzipping and skips non-zipped
files. Callers wishing to download a zipped file as-is can also set the
new `skip-decompress` parameter to `true`.

##### Enforced checks (breaking)

A previous release introduced digest checks on the download. If a
download hash didn't match the expected hash from the server, the action
would log a warning. Callers can now configure the behavior on mismatch
with the `digest-mismatch` parameter. To be secure by default, we are
now defaulting the behavior to `error` which will fail the workflow run.

##### ESM

To support new versions of the @&#8203;actions/\* packages, we've
upgraded the package to ESM.

#### What's Changed

- Don't attempt to un-zip non-zipped downloads by
[@&#8203;danwkennedy](https://redirect.github.com/danwkennedy) in
[#&#8203;460](https://redirect.github.com/actions/download-artifact/pull/460)
- Add a setting to specify what to do on hash mismatch and default it to
`error` by
[@&#8203;danwkennedy](https://redirect.github.com/danwkennedy) in
[#&#8203;461](https://redirect.github.com/actions/download-artifact/pull/461)

**Full Changelog**:
<https://github.com/actions/download-artifact/compare/v7...v8.0.0>

###
[`v8`](https://redirect.github.com/actions/download-artifact/compare/v7.0.0...v8)

[Compare
Source](https://redirect.github.com/actions/download-artifact/compare/v7.0.0...v8)

###
[`v7.0.0`](https://redirect.github.com/actions/download-artifact/releases/tag/v7.0.0)

[Compare
Source](https://redirect.github.com/actions/download-artifact/compare/v7.0.0...v7.0.0)

#### v7 - What's new

> \[!IMPORTANT]
> actions/download-artifact\@&#8203;v7 now runs on Node.js 24
(`runs.using: node24`) and requires a minimum Actions Runner version of
2.327.1. If you are using self-hosted runners, ensure they are updated
before upgrading.

##### Node.js 24

This release updates the runtime to Node.js 24. v6 had preliminary
support for Node 24, however this action was by default still running on
Node.js 20. Now this action by default will run on Node.js 24.

#### What's Changed

- Update GHES guidance to include reference to Node 20 version by
[@&#8203;patrikpolyak](https://redirect.github.com/patrikpolyak) in
[#&#8203;440](https://redirect.github.com/actions/download-artifact/pull/440)
- Download Artifact Node24 support by
[@&#8203;salmanmkc](https://redirect.github.com/salmanmkc) in
[#&#8203;415](https://redirect.github.com/actions/download-artifact/pull/415)
- fix: update
[@&#8203;actions/artifact](https://redirect.github.com/actions/artifact)
to fix Node.js 24 punycode deprecation by
[@&#8203;salmanmkc](https://redirect.github.com/salmanmkc) in
[#&#8203;451](https://redirect.github.com/actions/download-artifact/pull/451)
- prepare release v7.0.0 for Node.js 24 support by
[@&#8203;salmanmkc](https://redirect.github.com/salmanmkc) in
[#&#8203;452](https://redirect.github.com/actions/download-artifact/pull/452)

#### New Contributors

- [@&#8203;patrikpolyak](https://redirect.github.com/patrikpolyak) made
their first contribution in
[#&#8203;440](https://redirect.github.com/actions/download-artifact/pull/440)
- [@&#8203;salmanmkc](https://redirect.github.com/salmanmkc) made their
first contribution in
[#&#8203;415](https://redirect.github.com/actions/download-artifact/pull/415)

**Full Changelog**:
<https://github.com/actions/download-artifact/compare/v6.0.0...v7.0.0>

###
[`v7`](https://redirect.github.com/actions/download-artifact/compare/v6.0.0...v7.0.0)

[Compare
Source](https://redirect.github.com/actions/download-artifact/compare/v6.0.0...v7.0.0)

###
[`v6.0.0`](https://redirect.github.com/actions/download-artifact/releases/tag/v6.0.0)

[Compare
Source](https://redirect.github.com/actions/download-artifact/compare/v6.0.0...v6.0.0)

#### What's Changed

**BREAKING CHANGE:** this update supports Node `v24.x`. This is not a
breaking change per-se but we're treating it as such.

- Update README for download-artifact v5 changes by
[@&#8203;yacaovsnc](https://redirect.github.com/yacaovsnc) in
[#&#8203;417](https://redirect.github.com/actions/download-artifact/pull/417)
- Update README with artifact extraction details by
[@&#8203;yacaovsnc](https://redirect.github.com/yacaovsnc) in
[#&#8203;424](https://redirect.github.com/actions/download-artifact/pull/424)
- Readme: spell out the first use of GHES by
[@&#8203;danwkennedy](https://redirect.github.com/danwkennedy) in
[#&#8203;431](https://redirect.github.com/actions/download-artifact/pull/431)
- Bump `@actions/artifact` to `v4.0.0`
- Prepare `v6.0.0` by
[@&#8203;danwkennedy](https://redirect.github.com/danwkennedy) in
[#&#8203;438](https://redirect.github.com/actions/download-artifact/pull/438)

#### New Contributors

- [@&#8203;danwkennedy](https://redirect.github.com/danwkennedy) made
their first contribution in
[#&#8203;431](https://redirect.github.com/actions/download-artifact/pull/431)

**Full Changelog**:
<https://github.com/actions/download-artifact/compare/v5...v6.0.0>

###
[`v6`](https://redirect.github.com/actions/download-artifact/compare/v5.0.0...v6.0.0)

[Compare
Source](https://redirect.github.com/actions/download-artifact/compare/v5.0.0...v6.0.0)

###
[`v5.0.0`](https://redirect.github.com/actions/download-artifact/releases/tag/v5.0.0)

[Compare
Source](https://redirect.github.com/actions/download-artifact/compare/v5.0.0...v5.0.0)

#### What's Changed

- Update README.md by
[@&#8203;nebuk89](https://redirect.github.com/nebuk89) in
[#&#8203;407](https://redirect.github.com/actions/download-artifact/pull/407)
- BREAKING fix: inconsistent path behavior for single artifact downloads
by ID by [@&#8203;GrantBirki](https://redirect.github.com/GrantBirki) in
[#&#8203;416](https://redirect.github.com/actions/download-artifact/pull/416)

#### v5.0.0

##### 🚨 Breaking Change

This release fixes an inconsistency in path behavior for single artifact
downloads by ID. **If you're downloading single artifacts by ID, the
output path may change.**

##### What Changed

Previously, **single artifact downloads** behaved differently depending
on how you specified the artifact:

- **By name**: `name: my-artifact` → extracted to `path/` (direct)
- **By ID**: `artifact-ids: 12345` → extracted to `path/my-artifact/`
(nested)

Now both methods are consistent:

- **By name**: `name: my-artifact` → extracted to `path/` (unchanged)
- **By ID**: `artifact-ids: 12345` → extracted to `path/` (fixed - now
direct)

##### Migration Guide

##### ✅ No Action Needed If:

- You download artifacts by **name**
- You download **multiple** artifacts by ID
- You already use `merge-multiple: true` as a workaround

##### ⚠️ Action Required If:

You download **single artifacts by ID** and your workflows expect the
nested directory structure.

**Before v5 (nested structure):**

```yaml
- uses: actions/download-artifact@v4
  with:
    artifact-ids: 12345
    path: dist

# Files were in: dist/my-artifact/
```

> Where `my-artifact` is the name of the artifact you previously
uploaded

**To maintain old behavior (if needed):**

```yaml
- uses: actions/download-artifact@v5
  with:
    artifact-ids: 12345
    path: dist/my-artifact  # Explicitly specify the nested path
```

#### New Contributors

- [@&#8203;nebuk89](https://redirect.github.com/nebuk89) made their
first contribution in
[#&#8203;407](https://redirect.github.com/actions/download-artifact/pull/407)

**Full Changelog**:
<https://github.com/actions/download-artifact/compare/v4...v5.0.0>

###
[`v5`](https://redirect.github.com/actions/download-artifact/compare/v4.3.0...v5.0.0)

[Compare
Source](https://redirect.github.com/actions/download-artifact/compare/v4.3.0...v5.0.0)

</details>

<details>
<summary>actions/github-script (actions/github-script)</summary>

###
[`v9.0.0`](https://redirect.github.com/actions/github-script/releases/tag/v9.0.0)

[Compare
Source](https://redirect.github.com/actions/github-script/compare/v9.0.0...v9.0.0)

**New features:**

- **`getOctokit` factory function** — Available directly in the script
context. Create additional authenticated Octokit clients with different
tokens for multi-token workflows, GitHub App tokens, and cross-org
access. See [Creating additional clients with
`getOctokit`](https://redirect.github.com/actions/github-script#creating-additional-clients-with-getoctokit)
for details and examples.
- **Orchestration ID in user-agent** — The `ACTIONS_ORCHESTRATION_ID`
environment variable is automatically appended to the user-agent string
for request tracing.

**Breaking changes:**

- **`require('@&#8203;actions/github')` no longer works in scripts.**
The upgrade to `@actions/github` v9 (ESM-only) means
`require('@&#8203;actions/github')` will fail at runtime. If you
previously used patterns like `const { getOctokit } =
require('@&#8203;actions/github')` to create secondary clients, use the
new injected `getOctokit` function instead — it's available directly in
the script context with no imports needed.
- `getOctokit` is now an injected function parameter. Scripts that
declare `const getOctokit = ...` or `let getOctokit = ...` will get a
`SyntaxError` because JavaScript does not allow `const`/`let`
redeclaration of function parameters. Use the injected `getOctokit`
directly, or use `var getOctokit = ...` if you need to redeclare it.
- If your script accesses other `@actions/github` internals beyond the
standard `github`/`octokit` client, you may need to update those
references for v9 compatibility.

##### What's Changed

- Add ACTIONS\_ORCHESTRATION\_ID to user-agent string by
[@&#8203;Copilot](https://redirect.github.com/Copilot) in
[#&#8203;695](https://redirect.github.com/actions/github-script/pull/695)
- ci: use deployment: false for integration test environments by
[@&#8203;salmanmkc](https://redirect.github.com/salmanmkc) in
[#&#8203;712](https://redirect.github.com/actions/github-script/pull/712)
- feat!: add getOctokit to script context, upgrade
[@&#8203;actions/github](https://redirect.github.com/actions/github) v9,
[@&#8203;octokit/core](https://redirect.github.com/octokit/core) v7, and
related packages by
[@&#8203;salmanmkc](https://redirect.github.com/salmanmkc) in
[#&#8203;700](https://redirect.github.com/actions/github-script/pull/700)

##### New Contributors

- [@&#8203;Copilot](https://redirect.github.com/Copilot) made their
first contribution in
[#&#8203;695](https://redirect.github.com/actions/github-script/pull/695)

**Full Changelog**:
<https://github.com/actions/github-script/compare/v8.0.0...v9.0.0>

###
[`v9`](https://redirect.github.com/actions/github-script/compare/v8.0.0...v9.0.0)

[Compare
Source](https://redirect.github.com/actions/github-script/compare/v8.0.0...v9.0.0)

###
[`v8.0.0`](https://redirect.github.com/actions/github-script/compare/v8.0.0...v8.0.0)

[Compare
Source](https://redirect.github.com/actions/github-script/compare/v8.0.0...v8.0.0)

###
[`v8`](https://redirect.github.com/actions/github-script/releases/tag/v8):
.0.0

[Compare
Source](https://redirect.github.com/actions/github-script/compare/v7.1.0...v8.0.0)

#### What's Changed

- Update Node.js version support to 24.x by
[@&#8203;salmanmkc](https://redirect.github.com/salmanmkc) in
[#&#8203;637](https://redirect.github.com/actions/github-script/pull/637)
- README for updating actions/github-script from v7 to v8 by
[@&#8203;sneha-krip](https://redirect.github.com/sneha-krip) in
[#&#8203;653](https://redirect.github.com/actions/github-script/pull/653)

#### ⚠️ Minimum Compatible Runner Version

**v2.327.1**\
[Release
Notes](https://redirect.github.com/actions/runner/releases/tag/v2.327.1)

Make sure your runner is updated to this version or newer to use this
release.

#### New Contributors

- [@&#8203;salmanmkc](https://redirect.github.com/salmanmkc) made their
first contribution in
[#&#8203;637](https://redirect.github.com/actions/github-script/pull/637)
- [@&#8203;sneha-krip](https://redirect.github.com/sneha-krip) made
their first contribution in
[#&#8203;653](https://redirect.github.com/actions/github-script/pull/653)

**Full Changelog**:
<https://github.com/actions/github-script/compare/v7.1.0...v8.0.0>

</details>

<details>
<summary>actions/setup-java (actions/setup-java)</summary>

###
[`v5.5.0`](https://redirect.github.com/actions/setup-java/compare/v5.4.0...v5.5.0)

[Compare
Source](https://redirect.github.com/actions/setup-java/compare/v5.4.0...v5.5.0)

###
[`v5.4.0`](https://redirect.github.com/actions/setup-java/releases/tag/v5.4.0)

[Compare
Source](https://redirect.github.com/actions/setup-java/compare/v5.3.0...v5.4.0)

##### What's Changed

- Bump
[@&#8203;typescript-eslint/parser](https://redirect.github.com/typescript-eslint/parser)
from 8.48.0 to 8.61.1 by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;1021](https://redirect.github.com/actions/setup-java/pull/1021)
- Fix codeql workflow permissions by
[@&#8203;jsoref](https://redirect.github.com/jsoref) in
[#&#8203;993](https://redirect.github.com/actions/setup-java/pull/993)
- fix CodeQL permissions by
[@&#8203;gdams](https://redirect.github.com/gdams) in
[#&#8203;1025](https://redirect.github.com/actions/setup-java/pull/1025)
- fix: reject non-semver candidate versions in isVersionSatisfies by
[@&#8203;sproctor](https://redirect.github.com/sproctor) in
[#&#8203;1009](https://redirect.github.com/actions/setup-java/pull/1009)
- Bump
[@&#8203;actions/cache](https://redirect.github.com/actions/cache) to
5.1.0, handle cache write denied by
[@&#8203;jasongin](https://redirect.github.com/jasongin) in
[#&#8203;1026](https://redirect.github.com/actions/setup-java/pull/1026)
- Add Maven Wrapper cache feature by
[@&#8203;mahabaleshwars](https://redirect.github.com/mahabaleshwars) in
[#&#8203;1027](https://redirect.github.com/actions/setup-java/pull/1027)
- Spelling by [@&#8203;jsoref](https://redirect.github.com/jsoref) in
[#&#8203;713](https://redirect.github.com/actions/setup-java/pull/713)
- add link to advanced configuration for JetBrains by
[@&#8203;robstoll](https://redirect.github.com/robstoll) in
[#&#8203;850](https://redirect.github.com/actions/setup-java/pull/850)
- docs(action): fix missing required or default fields by
[@&#8203;kranthipoturaju](https://redirect.github.com/kranthipoturaju)
in
[#&#8203;1007](https://redirect.github.com/actions/setup-java/pull/1007)
- feat: add microsoft openjdk 17.0.18 by
[@&#8203;al-kau](https://redirect.github.com/al-kau) in
[#&#8203;1002](https://redirect.github.com/actions/setup-java/pull/1002)
- Update README.md - use "alert syntax for Markdown" for notes by
[@&#8203;mhoffrog](https://redirect.github.com/mhoffrog) in
[#&#8203;924](https://redirect.github.com/actions/setup-java/pull/924)
- Bump undici from 6.24.1 to 6.27.0 by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;1033](https://redirect.github.com/actions/setup-java/pull/1033)
- Update contributor guide with emoji for clarity by
[@&#8203;brunoborges](https://redirect.github.com/brunoborges) in
[#&#8203;1028](https://redirect.github.com/actions/setup-java/pull/1028)
- add javac problem matcher by
[@&#8203;Trass3r](https://redirect.github.com/Trass3r) in
[#&#8203;562](https://redirect.github.com/actions/setup-java/pull/562)
- Clarify README version syntax and migration guidance by
[@&#8203;brunoborges](https://redirect.github.com/brunoborges) with
[@&#8203;Copilot](https://redirect.github.com/Copilot) in
[#&#8203;1038](https://redirect.github.com/actions/setup-java/pull/1038)
- Update undici artifacts to 6.27.0 (license cache + dist) by
[@&#8203;brunoborges](https://redirect.github.com/brunoborges) in
[#&#8203;1040](https://redirect.github.com/actions/setup-java/pull/1040)
- docs: enhance custom jdk file installation by
[@&#8203;stephanabel](https://redirect.github.com/stephanabel) in
[#&#8203;996](https://redirect.github.com/actions/setup-java/pull/996)
- Templates for new Java distributions by
[@&#8203;panticmilos](https://redirect.github.com/panticmilos) in
[#&#8203;429](https://redirect.github.com/actions/setup-java/pull/429)
- Bump actions/checkout from 6 to 7 by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;1032](https://redirect.github.com/actions/setup-java/pull/1032)
- Bump [@&#8203;types/node](https://redirect.github.com/types/node) from
25.9.3 to 26.0.0 by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;1031](https://redirect.github.com/actions/setup-java/pull/1031)
- docs: replace non-existent HelloWorldApp references with java
--version by
[@&#8203;brunoborges](https://redirect.github.com/brunoborges) with
[@&#8203;Copilot](https://redirect.github.com/Copilot) in
[#&#8203;1043](https://redirect.github.com/actions/setup-java/pull/1043)
- docs: add JavaFX Maven project configuration instructions by
[@&#8203;brunoborges](https://redirect.github.com/brunoborges) with
[@&#8203;Copilot](https://redirect.github.com/Copilot) in
[#&#8203;1044](https://redirect.github.com/actions/setup-java/pull/1044)
- docs: self-signed certificate / internal CA handling for GitHub
Enterprise by
[@&#8203;brunoborges](https://redirect.github.com/brunoborges) in
[#&#8203;1050](https://redirect.github.com/actions/setup-java/pull/1050)
- docs: document importing an internal CA into the installed JDK
(cacerts) by
[@&#8203;brunoborges](https://redirect.github.com/brunoborges) in
[#&#8203;1051](https://redirect.github.com/actions/setup-java/pull/1051)
- chore: Harden workflows: least-privilege permissions + zizmor
integration by
[@&#8203;brunoborges](https://redirect.github.com/brunoborges) in
[#&#8203;1039](https://redirect.github.com/actions/setup-java/pull/1039)
- dist: Add GraalVM Community distribution support by
[@&#8203;brunoborges](https://redirect.github.com/brunoborges) with
[@&#8203;Copilot](https://redirect.github.com/Copilot) in
[#&#8203;1042](https://redirect.github.com/actions/setup-java/pull/1042)
- docs: note jdkfile approach for Early Access / unreleased JDK builds
by [@&#8203;brunoborges](https://redirect.github.com/brunoborges) in
[#&#8203;1058](https://redirect.github.com/actions/setup-java/pull/1058)
- dist: Apply Copilot review suggestions from PR
[#&#8203;1042](https://redirect.github.com/actions/setup-java/issues/1042)
(GraalVM Community) by
[@&#8203;brunoborges](https://redirect.github.com/brunoborges) in
[#&#8203;1059](https://redirect.github.com/actions/setup-java/pull/1059)

##### New Contributors

- [@&#8203;jsoref](https://redirect.github.com/jsoref) made their first
contribution in
[#&#8203;993](https://redirect.github.com/actions/setup-java/pull/993)
- [@&#8203;sproctor](https://redirect.github.com/sproctor) made their
first contribution in
[#&#8203;1009](https://redirect.github.com/actions/setup-java/pull/1009)
- [@&#8203;jasongin](https://redirect.github.com/jasongin) made their
first contribution in
[#&#8203;1026](https://redirect.github.com/actions/setup-java/pull/1026)
- [@&#8203;robstoll](https://redirect.github.com/robstoll) made their
first contribution in
[#&#8203;850](https://redirect.github.com/actions/setup-java/pull/850)
- [@&#8203;kranthipoturaju](https://redirect.github.com/kranthipoturaju)
made their first contribution in
[#&#8203;1007](https://redirect.github.com/actions/setup-java/pull/1007)
- [@&#8203;al-kau](https://redirect.github.com/al-kau) made their first
contribution in
[#&#8203;1002](https://redirect.github.com/actions/setup-java/pull/1002)
- [@&#8203;mhoffrog](https://redirect.github.com/mhoffrog) made their
first contribution in
[#&#8203;924](https://redirect.github.com/actions/setup-java/pull/924)
- [@&#8203;brunoborges](https://redirect.github.com/brunoborges) made
their first contribution in
[#&#8203;1028](https://redirect.github.com/actions/setup-java/pull/1028)
- [@&#8203;Trass3r](https://redirect.github.com/Trass3r) made their
first contribution in
[#&#8203;562](https://redirect.github.com/actions/setup-java/pull/562)
- [@&#8203;stephanabel](https://redirect.github.com/stephanabel) made
their first contribution in
[#&#8203;996](https://redirect.github.com/actions/setup-java/pull/996)

**Full Changelog**:
<https://github.com/actions/setup-java/compare/v5...v5.4.0>

###
[`v5.3.0`](https://redirect.github.com/actions/setup-java/releases/tag/v5.3.0)

[Compare
Source](https://redirect.github.com/actions/setup-java/compare/v5.2.0...v5.3.0)

##### What's Changed

- chore: update Java version to 25 in setup examples by
[@&#8203;alaahong](https://redirect.github.com/alaahong) in
[#&#8203;969](https://redirect.github.com/actions/setup-java/pull/969)
- Bump minimatch from 3.1.2 to 3.1.5 by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;984](https://redirect.github.com/actions/setup-java/pull/984)
- Refactor error handling and improve test logging for installers by
[@&#8203;chiranjib-swain](https://redirect.github.com/chiranjib-swain)
in
[#&#8203;989](https://redirect.github.com/actions/setup-java/pull/989)
- chore: upgrade dependencies
([@&#8203;actions/core](https://redirect.github.com/actions/core),
cache, glob, http-client, tool-cache, xmlbuilder2) by
[@&#8203;Copilot](https://redirect.github.com/Copilot) in
[#&#8203;999](https://redirect.github.com/actions/setup-java/pull/999)
- Add Oracle JDK 17 licensing limitation note by
[@&#8203;mahabaleshwars](https://redirect.github.com/mahabaleshwars) in
[#&#8203;1001](https://redirect.github.com/actions/setup-java/pull/1001)
- Update readme for ubuntu sudo java\_home behavior by
[@&#8203;mahabaleshwars](https://redirect.github.com/mahabaleshwars) in
[#&#8203;1013](https://redirect.github.com/actions/setup-java/pull/1013)
- temurin: add support for Alpine Linux by
[@&#8203;gdams](https://redirect.github.com/gdams) in
[#&#8203;674](https://redirect.github.com/actions/setup-java/pull/674)
- fix: resolve npm audit vulnerabilities in fast-xml-builder and
fast-xml-parser by [@&#8203;gdams](https://redirect.github.com/gdams) in
[#&#8203;1015](https://redirect.github.com/actions/setup-java/pull/1015)
- Bump
[@&#8203;typescript-eslint/eslint-plugin](https://redirect.github.com/typescript-eslint/eslint-plugin)
from 8.35.1 to 8.48.0 by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;952](https://redirect.github.com/actions/setup-java/pull/952)
- Bump eslint-config-prettier from 8.10.0 to 10.1.8 by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;881](https://redirect.github.com/actions/setup-java/pull/881)
- Bump picomatch,
[@&#8203;types/jest](https://redirect.github.com/types/jest), jest,
jest-circus and ts-jest by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;1016](https://redirect.github.com/actions/setup-java/pull/1016)
- Bump [@&#8203;types/node](https://redirect.github.com/types/node) from
24.1.0 to 25.9.3 by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;950](https://redirect.github.com/actions/setup-java/pull/950)
- Implement pagination with link headers for Adoptium based apis by
[@&#8203;johnoliver](https://redirect.github.com/johnoliver) in
[#&#8203;1014](https://redirect.github.com/actions/setup-java/pull/1014)
- Make the Adoptopenjdk package type look at the Temurin repo first for
latest assets by
[@&#8203;johnoliver](https://redirect.github.com/johnoliver) in
[#&#8203;522](https://redirect.github.com/actions/setup-java/pull/522)
- Bump [@&#8203;vercel/ncc](https://redirect.github.com/vercel/ncc) from
0.38.1 to 0.44.0 by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;1018](https://redirect.github.com/actions/setup-java/pull/1018)

##### New Contributors

- [@&#8203;alaahong](https://redirect.github.com/alaahong) made their
first contribution in
[#&#8203;969](https://redirect.github.com/actions/setup-java/pull/969)
- [@&#8203;Copilot](https://redirect.github.com/Copilot) made their
first contribution in
[#&#8203;999](https://redirect.github.com/actions/setup-java/pull/999)
- [@&#8203;johnoliver](https://redirect.github.com/johnoliver) made
their first contribution in
[#&#8203;1014](https://redirect.github.com/actions/setup-java/pull/1014)

**Full Changelog**:
<https://github.com/actions/setup-java/compare/v5...v5.3.0>

###
[`v5.2.0`](https://redirect.github.com/actions/setup-java/releases/tag/v5.2.0)

[Compare
Source](https://redirect.github.com/actions/setup-java/compare/v5.1.0...v5.2.0)

##### What's Changed

##### Enhancement

- Retry on HTTP 522 Connection timed out by
[@&#8203;findepi](https://redirect.github.com/findepi) in
[#&#8203;964](https://redirect.github.com/actions/setup-java/pull/964)

##### Documentation Changes

- Update gradle caching by
[@&#8203;priya-kinthali](https://redirect.github.com/priya-kinthali) in
[#&#8203;972](https://redirect.github.com/actions/setup-java/pull/972)
- Update checkout to v6 by
[@&#8203;mahabaleshwars](https://redirect.github.com/mahabaleshwars) in
[#&#8203;973](https://redirect.github.com/actions/setup-java/pull/973)

##### Dependency Updates

- Upgrade
[@&#8203;actions/cache](https://redirect.github.com/actions/cache) to v5
by [@&#8203;salmanmkc](https://redirect.github.com/salmanmkc) in
[#&#8203;968](https://redirect.github.com/actions/setup-java/pull/968)
- Upgrade actions/checkout from 5 to 6 by
[@&#8203;dependabot](https://redirect.github.com/dependabot) in
[#&#8203;961](https://redirect.github.com/actions/setup-java/pull/961)

##### New Contributors

- [@&#8203;findepi](https://redirect.github.com/findepi) made their
first contribution in
[#&#8203;964](https://redirect.github.com/actions/setup-java/pull/964)

**Full Changelog**:
<https://github.com/actions/setup-java/compare/v5...v5.2.0>

###
[`v5.1.0`](https://redirect.github.com/actions/setup-java/releases/tag/v5.1.0)

[Compare
Source](https://redirect.github.com/actions/setup-java/compare/v5...v5.1.0)

##### What's Changed

##### New Features

- Add support for `.sdkmanrc` file in `java-version-file` parameter by
[@&#8203;guicamest](https://redirect.github.com/guicamest) in
[#&#8203;736](https://redirect.github.com/actions/setup-java/pull/736)
- Add support for Microsoft OpenJDK 25 builds by
[@&#8203;the-mod](https://redirect.github.com/the-mod) in
[#&#8203;927](https://redirect.github.com/actions/setup-java/pull/927)

##### Bug Fixes & Improvements

- Update Regex to Support All ASDF Versions for the supported
distributions in tool-versions File by
[@&#8203;aparnajyothi-y](https://redirect.github.com/aparnajyothi-y) in
[#&#8203;767](https://redirect.github.com/actions/setup-java/pull/767)
- Enhance error logging for network failures to include endpoint/IP
details, add retry mechanism and update workflows to use macos-15-intel
by [@&#8203;priya-kinthali](https://redirect.github.com/priya-kinthali)
in
[#&#8203;946](https://redirect.github.com/actions/setup-java/pull/946)
- Update SapMachine URLs by
[@&#8203;RealCLanger](https://redirect.github.com/RealCLanger) in
[#&#8203;955](https://redirect.github.com/actions/setup-java/pull/955)
- Add GitHub Token Support for GraalVM and Refactor Code by
[@&#8203;mahabaleshwars](https://redirect.github.com/mahabaleshwars) in
[#&#8203;849](https://redirect.github.com/actions/setup-java/pull/849)

##### Documentation changes

- Update documentation to use checkout and Java v5 by
[@&#8203;lmvysakh](https://redirect.github.com/lmvysakh) in
[#&#8203;903](https://redirect.github.com/actions/setup-java/pull/903)
- Clarify JAVA\_HOME and PATH setup in README by
[@&#8203;chiranjib-swain](https://redirect.github.com/chiranjib-swain)
in
[#&#8203;841](https://redirect.github.com/actions/setup-java/pull/841)

##### Dependency updates

- Upgrade prettier from 2.8.8 to 3.6.2 and document breaking changes in
v5 by [@&#8203;dependabot](https://redirect.github.com/dependabot) in
[#&#8203;873](https://redirect.github.com/actions/setup-java/pull/873)
- Upgrade actions/publish-action from 0.3.0 to 0.4.0 by
[@&#8203;dependabot](https://redirect.github.com/dependabot) in
[#&#8203;912](https://redirect.github.com/actions/setup-java/pull/912)

##### New Contributors

- [@&#8203;lmvysakh](https://redirect.github.com/lmvysakh) made their
first contribution in
[#&#8203;903](https://redirect.github.com/actions/setup-java/pull/903)
- [@&#8203;chiranjib-swain](https://redirect.github.com/chiranjib-swain)
made their first contribution in
[#&#8203;841](https://redirect.github.com/actions/setup-java/pull/841)
- [@&#8203;the-mod](https://redirect.github.com/the-mod) made their
first contribution in
[#&#8203;927](https://redirect.github.com/actions/setup-java/pull/927)
- [@&#8203;priya-kinthali](https://redirect.github.com/priya-kinthali)
made their first contribution in
[#&#8203;946](https://redirect.github.com/actions/setup-java/pull/946)
- [@&#8203;guicamest](https://redirect.github.com/guicamest) made their
first contribution in
[#&#8203;736](https://redirect.github.com/actions/setup-java/pull/736)

**Full Changelog**:
<https://github.com/actions/setup-java/compare/v5...v5.1.0>

###
[`v5.0.0`](https://redirect.github.com/actions/setup-java/releases/tag/v5.0.0)

[Compare
Source](https://redirect.github.com/actions/setup-java/compare/v5...v5)

##### What's Changed

##### Breaking Changes

- Upgrade to node 24 by
[@&#8203;salmanmkc](https://redirect.github.com/salmanmkc) in
[#&#8203;888](https://redirect.github.com/actions/setup-java/pull/888)

Make sure your runner is updated to this version or newer to use this
release. v2.327.1 [Release
Notes](https://redirect.github.com/actions/runner/releases/tag/v2.327.1)

##### Dependency Upgrades

- Upgrade Publish Immutable Action by
[@&#8203;HarithaVattikuti](https://redirect.github.com/HarithaVattikuti)
in
[#&#8203;798](https://redirect.github.com/actions/setup-java/pull/798)
- Upgrade eslint-plugin-jest from 27.9.0 to 28.11.0 by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;730](https://redirect.github.com/actions/setup-java/pull/730)
- Upgrade undici from 5.28.5 to 5.29.0 by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;833](https://redirect.github.com/actions/setup-java/pull/833)
- Upgrade form-data to bring in fix for critical vulnerability by
[@&#8203;gowridurgad](https://redirect.github.com/gowridurgad) in
[#&#8203;887](https://redirect.github.com/actions/setup-java/pull/887)
- Upgrade actions/checkout from 4 to 5 by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;896](https://redirect.github.com/actions/setup-java/pull/896)

##### Bug Fixes

- Prevent default installation of JetBrains pre-releases by
[@&#8203;priyagupta108](https://redirect.github.com/priyagupta108) in
[#&#8203;859](https://redirect.github.com/actions/setup-java/pull/859)
- Improve Error Handling for Setup-Java Action to Help Debug
Intermittent Failures by
[@&#8203;gowridurgad](https://redirect.github.com/gowridurgad) in
[#&#8203;848](https://redirect.github.com/actions/setup-java/pull/848)

##### New Contributors

- [@&#8203;gowridurgad](https://redirect.github.com/gowridurgad) made
their first contribution in
[#&#8203;848](https://redirect.github.com/actions/setup-java/pull/848)
- [@&#8203;salmanmkc](https://redirect.github.com/salmanmkc) made their
first contribution in
[#&#8203;888](https://redirect.github.com/actions/setup-java/pull/888)

**Full Changelog**:
<https://github.com/actions/setup-java/compare/v4...v5.0.0>

###
[`v5`](https://redirect.github.com/actions/setup-java/compare/v4.8.0...v5)

[Compare
Source](https://redirect.github.com/actions/setup-java/compare/v4.8.0...v5)

</details>

<details>
<summary>actions/setup-python (actions/setup-python)</summary>

###
[`v6.3.0`](https://redirect.github.com/actions/setup-python/releases/tag/v6.3.0)

[Compare
Source](https://redirect.github.com/actions/setup-python/compare/v6.2.0...v6.3.0)

##### What's Changed

##### Enhancement

- Add RHEL support and include Linux distro in cache keys by
[@&#8203;priyagupta108](https://redirect.github.com/priyagupta108) in
[#&#8203;1323](https://redirect.github.com/actions/setup-python/pull/1323)
- Fix pip cache error handling on Windows by
[@&#8203;priyagupta108](https://redirect.github.com/priyagupta108) in
[#&#8203;1040](https://redirect.github.com/actions/setup-python/pull/1040)

##### Dependency update

- Upgrade minimatch from 3.1.2 to 3.1.5 by
[@&#8203;dependabot](https://redirect.github.com/dependabot) in
[#&#8203;1281](https://redirect.github.com/actions/setup-python/pull/1281)
- Upgrade actions dependencies by
[@&#8203;gowridurgad](https://redirect.github.com/gowridurgad) with
[@&#8203;Copilot](https://redirect.github.com/Copilot) in
[#&#8203;1303](https://redirect.github.com/actions/setup-python/pull/1303)
- Upgrade
[@&#8203;actions/cache](https://redirect.github.com/actions/cache) to
5.1.0, log cache write denied by
[@&#8203;jasongin](https://redirect.github.com/jasongin) in
[#&#8203;1324](https://redirect.github.com/actions/setup-python/pull/1324)
- Upgrade dependency versions and test workflow configuration by
[@&#8203;HarithaVattikuti](https://redirect.github.com/HarithaVattikuti)
in
[#&#8203;1322](https://redirect.github.com/actions/setup-python/pull/1322)

##### Documentation

- Update advanced-usage.md by
[@&#8203;Dunky-Z](https://redirect.github.com/Dunky-Z) in
[#&#8203;811](https://redirect.github.com/actions/setup-python/pull/811)

##### New Contributors

- [@&#8203;gowridurgad](https://redirect.github.com/gowridurgad) with
[@&#8203;Copilot](https://redirect.github.com/Copilot) made their first
contribution in
[#&#8203;1303](https://redirect.github.com/actions/setup-python/pull/1303)
- [@&#8203;jasongin](https://redirect.github.com/jasongin) made their
first contribution in
[#&#8203;1324](https://redirect.github.com/actions/setup-python/pull/1324)
- [@&#8203;Dunky-Z](https://redirect.github.com/Dunky-Z) made their
first contribution in
[#&#8203;811](https://redirect.github.com/actions/setup-python/pull/811)

**Full Changelog**:
<https://github.com/actions/setup-python/compare/v6...v6.3.0>

</details>

<details>
<summary>actions/upload-artifact (actions/upload-artifact)</summary>

###
[`v7.0.1`](https://redirect.github.com/actions/upload-artifact/releases/tag/v7.0.1)

[Compare
Source](https://redirect.github.com/actions/upload-artifact/compare/v7...v7.0.1)

#### What's Changed

- Update the readme with direct upload details by
[@&#8203;danwkennedy](https://redirect.github.com/danwkennedy) in
[#&#8203;795](https://redirect.github.com/actions/upload-artifact/pull/795)
- Readme: bump all the example versions to v7 by
[@&#8203;danwkennedy](https://redirect.github.com/danwkennedy) in
[#&#8203;796](https://redirect.github.com/actions/upload-artifact/pull/796)
- Include changes in typespec/ts-http-runtime 0.3.5 by
[@&#8203;yacaovsnc](https://redirect.github.com/yacaovsnc) in
[#&#8203;797](https://redirect.github.com/actions/upload-artifact/pull/797)

**Full Changelog**:
<https://github.com/actions/upload-artifact/compare/v7...v7.0.1>

###
[`v7.0.0`](https://redirect.github.com/actions/upload-artifact/releases/tag/v7.0.0)

[Compare
Source](https://redirect.github.com/actions/upload-artifact/compare/v7...v7)

#### v7 What's new

##### Direct Uploads

Adds support for uploading single files directly (unzipped). Callers can
set the new `archive` parameter to `false` to skip zipping the file
during upload. Right now, we only support single files. The action will
fail if the glob passed resolves to multiple files. The `name` parameter
is also ignored with this setting. Instead, the name of the artifact
will be the name of the uploaded file.

##### ESM

To support new versions of the `@actions/*` packages, we've upgraded the
package to ESM.

#### What's Changed

- Add proxy integration test by
[@&#8203;Link-](https://redirect.github.com/Link-) in
[#&#8203;754](https://redirect.github.com/actions/upload-artifact/pull/754)
- Upgrade the module to ESM and bump dependencies by
[@&#8203;danwkennedy](https://redirect.github.com/danwkennedy) in
[#&#8203;762](https://redirect.github.com/actions/upload-artifact/pull/762)
- Support direct file uploads by
[@&#8203;danwkennedy](https://redirect.github.com/danwkennedy) in
[#&#8203;764](https://redirect.github.com/actions/upload-artifact/pull/764)

#### New Contributors

- [@&#8203;Link-](https://redirect.github.com/Link-) made their first
contribution in
[#&#8203;754](https://redirect.github.com/actions/upload-artifact/pull/754)

**Full Changelog**:
<https://github.com/actions/upload-artifact/compare/v6...v7.0.0>

###
[`v7`](https://redirect.github.com/actions/upload-artifact/compare/v6.0.0...v7)

[Compare
Source](https://redirect.github.com/actions/upload-artifact/compare/v6.0.0...v7)

###
[`v6.0.0`](https://redirect.github.com/actions/upload-artifact/releases/tag/v6.0.0)

[Compare
Source](https://redirect.github.com/actions/upload-artifact/compare/v6.0.0...v6.0.0)

#### v6 - What's new

> \[!IMPORTANT]
> actions/upload-artifact\@&#8203;v6 now runs on Node.js 24
(`runs.using: node24`) and requires a minimum Actions Runner version of
2.327.1. If you are using self-hosted runners, ensure they are updated
before upgrading.

##### Node.js 24

This release updates the runtime to Node.js 24. v5 had preliminary
support for Node.js 24, however this action was by default still running
on Node.js 20. Now this action by default will run on Node.js 24.

#### What's Changed

- Upload Artifact Node 24 support by
[@&#8203;salmanmkc](https://redirect.github.com/salmanmkc) in
[#&#8203;719](https://redirect.github.com/actions/upload-artifact/pull/719)
- fix: update
[@&#8203;actions/artifact](https://redirect.github.com/actions/artifact)
for Node.js 24 punycode deprecation by
[@&#8203;salmanmkc](https://redirect.github.com/salmanmkc) in
[#&#8203;744](https://redirect.github.com/actions/upload-artifact/pull/744)
- prepare release v6.0.0 for Node.js 24 support by
[@&#8203;salmanmkc](https://redirect.github.com/salmanmkc) in
[#&#8203;745](https://redirect.github.com/actions/upload-artifact/pull/745)

**Full Changelog**:
<https://github.com/actions/upload-artifact/compare/v5.0.0...v6.0.0>

###
[`v6`](https://redirect.github.com/actions/upload-artifact/compare/v5.0.0...v6.0.0)

[Compare
Source](https://redirect.github.com/actions/upload-artifact/compare/v5.0.0...v6.0.0)

###
[`v5.0.0`](https://redirect.github.com/actions/upload-artifact/releases/tag/v5.0.0)

[Compare
Source](https://redirect.github.com/actions/upload-artifact/compare/v5.0.0...v5.0.0)

#### What's Changed

**BREAKING CHANGE:** this update supports Node `v24.x`. This is not a
breaking change per-se but we're treating it as such.

- Update README.md by
[@&#8203;GhadimiR](https://redirect.github.com/GhadimiR) in
[#&#8203;681](https://redirect.github.com/actions/upload-artifact/pull/681)
- Update README.md by
[@&#8203;nebuk89](https://redirect.github.com/nebuk89) in
[#&#8203;712](https://redirect.github.com/actions/upload-artifact/pull/712)
- Readme: spell out the first use of GHES by
[@&#8203;danwkennedy](https://redirect.github.com/danwkennedy) in
[#&#8203;727](https://redirect.github.com/actions/upload-artifact/pull/727)
- Update GHES guidance to include reference to Node 20 version by
[@&#8203;patrikpolyak](https://redirect.github.com/patrikpolyak) in
[#&#8203;725](https://redirect.github.com/actions/upload-artifact/pull/725)
- Bump `@actions/artifact` to `v4.0.0`
- Prepare `v5.0.0` by
[@&#8203;danwkennedy](https://redirect.github.com/danwkennedy) in
[#&#8203;734](https://redirect.github.com/actions/upload-artifact/pull/734)

#### New Contributors

- [@&#8203;GhadimiR](https://redirect.github.com/GhadimiR) made their
first contribution in
[#&#8203;681](https://redirect.github.com/actions/upload-artifact/pull/681)
- [@&#8203;nebuk89](https://redirect.github.com/nebuk89) made their
first contribution in
[#&#8203;712](https://redirect.github.com/actions/upload-artifact/pull/712)
- [@&#8203;danwkennedy](https://redirect.github.com/danwkennedy) made
their first contribution in
[#&#8203;727](https://redirect.github.com/actions/upload-artifact/pull/727)
- [@&#8203;patrikpolyak](https://redirect.github.com/patrikpolyak) made
their first contribution in
[#&#8203;725](https://redirect.github.com/actions/upload-artifact/pull/725)

**Full Changelog**:
<https://github.com/actions/upload-artifact/compare/v4...v5.0.0>

###
[`v5`](https://redirect.github.com/actions/upload-artifact/compare/v4.6.2...v5.0.0)

[Compare
Source](https://redirect.github.com/actions/upload-artifact/compare/v4.6.2...v5.0.0)

</details>

<details>
<summary>astral-sh/setup-uv (astral-sh/setup-uv)</summary>

###
[`v8.3.2`](https://redirect.github.com/astral-sh/setup-uv/compare/v8.3.1...v8.3.2)

[Compare
Source](https://redirect.github.com/astral-sh/setup-uv/compare/v8.3.1...v8.3.2)

###
[`v8.3.1`](https://redirect.github.com/astral-sh/setup-uv/compare/v8.3.0...v8.3.1)

[Compare
Source](https://redirect.github.com/astral-sh/setup-uv/compare/v8.3.0...v8.3.1)

###
[`v8.3.0`](https://redirect.github.com/astral-sh/setup-uv/compare/v8.2.0...v8.3.0)

[Compare
Source](https://redirect.github.com/astral-sh/setup-uv/compare/v8.2.0...v8.3.0)

###
[`v8.2.0`](https://redirect.github.com/astral-sh/setup-uv/releases/tag/v8.2.0):
🌈 New inputs `quiet` and `download-from-astral-mirror`

[Compare
Source](https://redirect.github.com/astral-sh/setup-uv/compare/v8.1.0...v8.2.0)

##### Changes

This release brings two new inputs and a few bug fixes.

##### New inputs

Lets talk about the new inputs first.

##### quiet

Pretty simple. It turns of all `info` loggings. Useful if you use this
in a composite action and are not interested in all the details.
In the upcoming releases we will add log groups to fully implement
support for "less noise"

> \[!NOTE]\
> Warnings and errors are always logged.

##### download-from-astral-mirror

In some cases you may want to directly use the fallback of checking for
available versions and downloading releases from GitHub instead of using
the astral.sh mirror. Setting `download-from-astral-mirror: false`
allows you to do that.

##### Bugfixes

When using the astral.sh mirror to query available versions and download
releases (done by default) we now stop sending the GitHub token in the
header. The mirror never looked at it but we shouldn't be handing out
that data even if it is just a short lived token.
All other bugfixes try to limit the impact of failed GitHub queries due
to retries and other faults.

We couldn't pinpoint all rootcauses yet but added more logging for error
cases to track them down.

##### 🐛 Bug fixes

- fix: report unexpected cache save failures
[@&#8203;eifinger](https://redirect.github.com/eifinger)
([#&#8203;896](https://redirect.github.com/astral-sh/setup-uv/issues/896))
- fix: report unexpected setup failures
[@&#8203;eifinger](https://redirect.github.com/eifinger)
([#&#8203;895](https://redirect.github.com/astral-sh/setup-uv/issues/895))
- fix: add timeout to fetch to prevent silent hangs
[@&#8203;eifinger-bot](https://redirect.github.com/eifinger-bot)
([#&#8203;883](https://redirect.github.com/astral-sh/setup-uv/issues/883))
- Limit GitHub tokens to github.com download URLs
[@&#8203;zsol](https://redirect.github.com/zsol)
([#&#8203;878](https://redirect.github.com/astral-sh/setup-uv/issues/878))
- increase libuv-workaround timeout to 100ms
[@&#8203;eifinger](https://redirect.github.com/eifinger)
([#&#8203;880](https://redirect.github.com/astral-sh/setup-uv/issues/880))

##### 🚀 Enhancements

- Add quiet input to suppress info-level log output
[@&#8203;eifinger](https://redirect.github.com/eifinger)
([#&#8203;898](https://redirect.github.com/astral-sh/setup-uv/issues/898))
- feat: add `download-from-astral-mirror` input
[@&#8203;eifinger](https://redirect.github.com/eifinger)
([#&#8203;897](https://redirect.github.com/astral-sh/setup-uv/issues/897))

##### 🧰 Maintenance

- docs: update dependabot rollup biome guidance
[@&#8203;eifinger](https://redirect.github.com/eifinger)
([#&#8203;902](https://redirect.github.com/astral-sh/setup-uv/issues/902))
- chore: update known checksums for 0.11.18
@&#8203;[github-actions\[bot\]](https://redirect.github.com/apps/github-actions)
([#&#8203;899](https://redirect.github.com/astral-sh/setup-uv/issues/899))
- chore: update known checksums for 0.11.17
@&#8203;[github-actions\[bot\]](https://redirect.github.com/apps/github-actions)
([#&#8203;892](https://redirect.github.com/astral-sh/setup-uv/issues/892))
- chore: update known checksums for 0.11.16 @&#8203;[github-act

> ✂ **Note**
> 
> PR body was truncated to here.


</details>

---

### Configuration

📅 **Schedule**: (in timezone America/Los_Angeles)

- Branch creation
  - "before 9am every weekday"
- Automerge
  - At any time (no schedule defined)

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR is behind base branch, or you tick the
rebase/retry checkbox.

👻 **Immortal**: This PR will be recreated if closed unmerged. Get
[config
help](https://redirect.github.com/renovatebot/renovate/discussions) if
that's undesired.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR was generated by [Mend Renovate](https://mend.io/renovate/).
View the [repository job
log](https://developer.mend.io/github/CopilotKit/CopilotKit).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4yNDIuMiIsInVwZGF0ZWRJblZlciI6IjQzLjI0Mi4yIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6W119-->
2026-07-12 03:03:26 +00:00
renovate[bot] 47ab65c6c0 chore(deps): update github actions 2026-07-12 02:46:24 +00:00
Jordan Ritter 0ffc05bed4 ci: pin ad-hoc CI tool installs to satisfy zizmor adhoc-packages (#5929)
## What

Replaces four ad-hoc `npm install -g` steps (flagged by zizmor's
`adhoc-packages` audit) with lockfile-managed or pinned-action installs.
Root-cause fix, not suppression. Behavior is preserved in every case.

## Per-line fix

| # | File:line (before) | Fix | Why this form |
|---|---|---|---|
| 1 | `test_integration-docs.yml:67` — `npm install -g
@copilotkit/aimock@1.24.1` | Invoke workspace-pinned `llmock` bin from
frozen lockfile | **lockfile-devDep.** The `CopilotKit/aimock` composite
action wraps the newer config-only `aimock` CLI, which does **not**
accept `--fixtures`; these jobs need `--fixtures`/`--validate-on-load`.
`@copilotkit/aimock@1.26.1` is already a dep of
`@copilotkit/showcase-scripts`, so no new dep needed. |
| 2 | `test_e2e-showcase-on-demand.yml:276` — `npm install -g
"@copilotkit/aimock@^1.16.4" --ignore-scripts` | Scoped frozen install +
workspace `llmock` bin (4 `--fixtures` dirs, `/__aimock/health` probe,
PID capture preserved) | Same as above; added an `Install aimock` step
(`pnpm --filter @copilotkit/showcase-scripts install --frozen-lockfile
--ignore-scripts`) before the start step since the full `pnpm install`
runs later in the job. |
| 3 | `social_copy-generator.yml:209` — `npm install -g
@anthropic-ai/claude-code` (unpinned) | Pin
`@anthropic-ai/claude-code@2.1.207` as a root devDependency; install
from frozen lockfile; invoke via `cli-wrapper.cjs` |
**lockfile-devDep.** `anthropics/claude-code-action` is for PR/issue
automation; this job uses `claude -p ... --output-format json` as a
scripted CLI, which the action does not fit. Added
`setup-node`+`pnpm`+install to the job (it had none). |
| 4 | `static_quality.yml:54` — `npm install -g oxfmt@0.36` | Install
from frozen lockfile (`oxfmt` is already a root devDep `^0.36.0`), put
`node_modules/.bin` on PATH | No official oxfmt action → lockfile
devDep. |
| 5 | `static_quality.yml:61` — `pipx install ruff==0.15.13` | Pinned
`astral-sh/ruff-action@278981a28ce3188b1e39527901f38254bf3aac89 #
v4.1.0`, `version: "0.15.13"`, `args: "--version"` (install-only) |
Official action, SHA-pinned. Note: `pipx install` was **not** actually
flagged by zizmor `adhoc-packages` (only the 4 `npm install -g` lines
are), but switching it to the pinned action matches intent and is
strictly better. |

## Red → Green proof

Exact CI invocation: `zizmor --min-severity low --config
.github/zizmor.yml .github/workflows` (zizmor 1.26.1).

**RED (main):** exit `12`, **4** `adhoc-packages` findings:
- `social_copy-generator.yml:209`
- `static_quality.yml:54`
- `test_e2e-showcase-on-demand.yml:276`
- `test_integration-docs.yml:67`

**GREEN (this branch):** exit `0`, **0** `adhoc-packages` findings,
**0** `unpinned-uses` (the new `ruff-action` is SHA-pinned) → `No
findings to report. Good job!`

## Behavior verification (local)

- aimock (both jobs): started the workspace `llmock` bin exactly as each
workflow does — process stays alive, `/health` **and**
`/__aimock/health` return 200, all 4 e2e fixture dirs load with
`--validate-on-load`.
- claude-code: `node
node_modules/@anthropic-ai/claude-code/cli-wrapper.cjs --version` →
`2.1.207 (Claude Code)`; `--help` shows `-p/--print` passthrough.
(Installed with `--ignore-scripts`; the wrapper resolves the native
binary from the installed optionalDependency, the package's documented
fallback path.)
- oxfmt: resolves from `node_modules/.bin`,
`--no-error-on-unmatched-pattern --check` works.
- `pnpm install --frozen-lockfile` passes (exit 0) with the updated
lockfile; lockfile diff is 100% the new `@anthropic-ai/claude-code`
entries (87 additions, zero unrelated churn). `claude-code@2.1.207` is
>24h old, satisfying `.npmrc` `minimum-release-age=1440`.

## Notes

- All new `uses:` are SHA-pinned with a `# vX.Y.Z` comment per repo
convention.
- The heavy local lefthook pre-commit (full Nx test/build) was skipped
for this CI-only YAML change; CI runs the real checks.

🤖 Generated with [Claude Code](https://claude.com/claude-code)
2026-07-11 19:27:08 -07:00
Jordan Ritter e906d0f631 ci: replace ad-hoc tool installs with lockfile/pinned-action installs (zizmor adhoc-packages)
Four workflow steps installed CLI tools ad-hoc via `npm install -g`, which
zizmor's `adhoc-packages` audit flags (install outside a lockfile). Replace
each with a lockfile-managed or pinned-action install, preserving behavior:

- aimock (test_integration-docs, test_e2e-showcase-on-demand): invoke the
  workspace-pinned @copilotkit/aimock `llmock` bin from the frozen lockfile
  (already a dep of @copilotkit/showcase-scripts) instead of `npm install -g`.
  Kept lockfile-devDep rather than the CopilotKit/aimock composite action:
  the action wraps the newer config-only `aimock` CLI and can't do the
  multi-`--fixtures` / `--validate-on-load` / `/__aimock/health` invocation
  these jobs need.
- claude-code (social_copy-generator): pin @anthropic-ai/claude-code as a root
  devDependency, install from the frozen lockfile, invoke via its documented
  cli-wrapper.cjs entrypoint. Kept lockfile-devDep rather than
  anthropics/claude-code-action: the job uses claude as a scripted `-p` CLI,
  not PR/issue automation.
- oxfmt (static_quality): already a root devDependency; install from the frozen
  lockfile and put node_modules/.bin on PATH instead of `npm install -g`.
- ruff (static_quality): switch `pipx install` to the pinned official
  astral-sh/ruff-action@278981a (v4.1.0) with the same 0.15.13 version.

zizmor --min-severity low --config .github/zizmor.yml .github/workflows:
  before: exit 12, 4 adhoc-packages findings
  after:  exit 0,  0 adhoc-packages findings, 0 unpinned-uses (no findings)
2026-07-11 19:19:45 -07:00
Tyler Slaton 87db1b01e7 chore: release channels-whatsapp v0.0.2 (#5924)
## Release channels-whatsapp v0.0.2

**Scope:** `channels-whatsapp` | **Bump:** `patch`

---

### How this release process works

1. **This PR was created automatically** by the "release / create-pr"
workflow.
   It bumped the `channels-whatsapp` packages to `0.0.2`
   and generated AI-enhanced release notes.

2. **CI runs on this PR** — the full test suite (unit tests, lint, type
checks, build)
   must pass before merging. This is the review gate.

3. **Review the release notes** in `release-notes.md` in this PR.
If a Notion draft was created, you can edit the release notes there
before merging.

4. **When this PR is merged**, the `release / publish` workflow
automatically:
   - Builds all packages
- Publishes the `channels-whatsapp` packages to npm at version `0.0.2`
   - Creates git tag `channels-whatsapp/v0.0.2`
   - Creates a GitHub Release with the final release notes

### Before merging

- [ ] CI is green (tests, lint, types, build)
- [ ] Version bumps look correct
- [ ] Release notes are accurate (edit in Notion if a draft was created)

---

> **Do not merge until CI is fully green.** The full test suite runs
automatically on this PR.
channels-whatsapp/v0.0.2
2026-07-10 15:56:51 -07:00
Tyler Slaton 41caca8f2c chore: release channels-telegram v0.0.4 (#5923)
## Release channels-telegram v0.0.4

**Scope:** `channels-telegram` | **Bump:** `patch`

---

### How this release process works

1. **This PR was created automatically** by the "release / create-pr"
workflow.
   It bumped the `channels-telegram` packages to `0.0.4`
   and generated AI-enhanced release notes.

2. **CI runs on this PR** — the full test suite (unit tests, lint, type
checks, build)
   must pass before merging. This is the review gate.

3. **Review the release notes** in `release-notes.md` in this PR.
If a Notion draft was created, you can edit the release notes there
before merging.

4. **When this PR is merged**, the `release / publish` workflow
automatically:
   - Builds all packages
- Publishes the `channels-telegram` packages to npm at version `0.0.4`
   - Creates git tag `channels-telegram/v0.0.4`
   - Creates a GitHub Release with the final release notes

### Before merging

- [ ] CI is green (tests, lint, types, build)
- [ ] Version bumps look correct
- [ ] Release notes are accurate (edit in Notion if a draft was created)

---

> **Do not merge until CI is fully green.** The full test suite runs
automatically on this PR.
channels-telegram/v0.0.4
2026-07-10 15:56:41 -07:00
Tyler Slaton 6f038317c7 chore: release channels-intelligence v0.1.1 (#5920)
## Release channels-intelligence v0.1.1

**Scope:** `channels-intelligence` | **Bump:** `patch`

---

### How this release process works

1. **This PR was created automatically** by the "release / create-pr"
workflow.
   It bumped the `channels-intelligence` packages to `0.1.1`
   and generated AI-enhanced release notes.

2. **CI runs on this PR** — the full test suite (unit tests, lint, type
checks, build)
   must pass before merging. This is the review gate.

3. **Review the release notes** in `release-notes.md` in this PR.
If a Notion draft was created, you can edit the release notes there
before merging.

4. **When this PR is merged**, the `release / publish` workflow
automatically:
   - Builds all packages
- Publishes the `channels-intelligence` packages to npm at version
`0.1.1`
   - Creates git tag `channels-intelligence/v0.1.1`
   - Creates a GitHub Release with the final release notes

### Before merging

- [ ] CI is green (tests, lint, types, build)
- [ ] Version bumps look correct
- [ ] Release notes are accurate (edit in Notion if a draft was created)

---

> **Do not merge until CI is fully green.** The full test suite runs
automatically on this PR.
channels-intelligence/v0.1.1
2026-07-10 15:56:32 -07:00
Tyler Slaton e99e1dc746 chore: release channels-teams v0.1.2 (#5921)
## Release channels-teams v0.1.2

**Scope:** `channels-teams` | **Bump:** `patch`

---

### How this release process works

1. **This PR was created automatically** by the "release / create-pr"
workflow.
   It bumped the `channels-teams` packages to `0.1.2`
   and generated AI-enhanced release notes.

2. **CI runs on this PR** — the full test suite (unit tests, lint, type
checks, build)
   must pass before merging. This is the review gate.

3. **Review the release notes** in `release-notes.md` in this PR.
If a Notion draft was created, you can edit the release notes there
before merging.

4. **When this PR is merged**, the `release / publish` workflow
automatically:
   - Builds all packages
   - Publishes the `channels-teams` packages to npm at version `0.1.2`
   - Creates git tag `channels-teams/v0.1.2`
   - Creates a GitHub Release with the final release notes

### Before merging

- [ ] CI is green (tests, lint, types, build)
- [ ] Version bumps look correct
- [ ] Release notes are accurate (edit in Notion if a draft was created)

---

> **Do not merge until CI is fully green.** The full test suite runs
automatically on this PR.
channels-teams/v0.1.2
2026-07-10 15:56:14 -07:00
Tyler Slaton cb1fd90827 chore: release channels-slack v0.1.2 (#5922)
## Release channels-slack v0.1.2

**Scope:** `channels-slack` | **Bump:** `patch`

---

### How this release process works

1. **This PR was created automatically** by the "release / create-pr"
workflow.
   It bumped the `channels-slack` packages to `0.1.2`
   and generated AI-enhanced release notes.

2. **CI runs on this PR** — the full test suite (unit tests, lint, type
checks, build)
   must pass before merging. This is the review gate.

3. **Review the release notes** in `release-notes.md` in this PR.
If a Notion draft was created, you can edit the release notes there
before merging.

4. **When this PR is merged**, the `release / publish` workflow
automatically:
   - Builds all packages
   - Publishes the `channels-slack` packages to npm at version `0.1.2`
   - Creates git tag `channels-slack/v0.1.2`
   - Creates a GitHub Release with the final release notes

### Before merging

- [ ] CI is green (tests, lint, types, build)
- [ ] Version bumps look correct
- [ ] Release notes are accurate (edit in Notion if a draft was created)

---

> **Do not merge until CI is fully green.** The full test suite runs
automatically on this PR.
channels-slack/v0.1.2
2026-07-10 15:56:07 -07:00
Tyler Slaton 8427fa187e chore: release channels-discord v0.0.3 (#5919)
## Release channels-discord v0.0.3

**Scope:** `channels-discord` | **Bump:** `patch`

---

### How this release process works

1. **This PR was created automatically** by the "release / create-pr"
workflow.
   It bumped the `channels-discord` packages to `0.0.3`
   and generated AI-enhanced release notes.

2. **CI runs on this PR** — the full test suite (unit tests, lint, type
checks, build)
   must pass before merging. This is the review gate.

3. **Review the release notes** in `release-notes.md` in this PR.
If a Notion draft was created, you can edit the release notes there
before merging.

4. **When this PR is merged**, the `release / publish` workflow
automatically:
   - Builds all packages
   - Publishes the `channels-discord` packages to npm at version `0.0.3`
   - Creates git tag `channels-discord/v0.0.3`
   - Creates a GitHub Release with the final release notes

### Before merging

- [ ] CI is green (tests, lint, types, build)
- [ ] Version bumps look correct
- [ ] Release notes are accurate (edit in Notion if a draft was created)

---

> **Do not merge until CI is fully green.** The full test suite runs
automatically on this PR.
channels-discord/v0.0.3
2026-07-10 15:55:57 -07:00
Tyler Slaton 5e389aab83 chore: release channels v0.1.1 (#5918)
## Release channels v0.1.1

**Scope:** `channels` | **Bump:** `patch`

---

### How this release process works

1. **This PR was created automatically** by the "release / create-pr"
workflow.
   It bumped the `channels` packages to `0.1.1`
   and generated AI-enhanced release notes.

2. **CI runs on this PR** — the full test suite (unit tests, lint, type
checks, build)
   must pass before merging. This is the review gate.

3. **Review the release notes** in `release-notes.md` in this PR.
If a Notion draft was created, you can edit the release notes there
before merging.

4. **When this PR is merged**, the `release / publish` workflow
automatically:
   - Builds all packages
   - Publishes the `channels` packages to npm at version `0.1.1`
   - Creates git tag `channels/v0.1.1`
   - Creates a GitHub Release with the final release notes

### Before merging

- [ ] CI is green (tests, lint, types, build)
- [ ] Version bumps look correct
- [ ] Release notes are accurate (edit in Notion if a draft was created)

---

> **Do not merge until CI is fully green.** The full test suite runs
automatically on this PR.
channels/v0.1.1
2026-07-10 15:55:56 -07:00
tylerslaton 4c04e8028e chore: release channels-whatsapp v0.0.2 2026-07-10 22:45:18 +00:00
tylerslaton 6281beaf6f chore: release channels-telegram v0.0.4 2026-07-10 22:45:08 +00:00
tylerslaton 2893feecde chore: release channels-teams v0.1.2 2026-07-10 22:44:52 +00:00
tylerslaton 4ce3124c5c chore: release channels-slack v0.1.2 2026-07-10 22:44:52 +00:00
tylerslaton f4e19e2039 chore: release channels-intelligence v0.1.1 2026-07-10 22:44:50 +00:00
tylerslaton ceae64cf1b chore: release channels-discord v0.0.3 2026-07-10 22:44:42 +00:00
tylerslaton ea50654ec0 chore: release channels v0.1.1 2026-07-10 22:44:26 +00:00
Ben Taylor 77d43dcb1a refactor(channels-intelligence): migrate to Channels API (#5916)
## Problem

`@copilotkit/channels-intelligence` still used the retired Bot
HTTP/realtime contract and exposed Phoenix implementation details. The
managed Slack entrypoint used the same legacy API.

## Why

Intelligence now exposes a clean-break Channels contract. The SDK must
use it consistently, while keeping the Phoenix-backed transport private
behind a product-neutral Realtime Gateway API. Compatibility aliases
would hide integration mismatches.

## Fix

- Migrated HTTP paths, payloads, config, and KV state to Channel
terminology.
- Added the Realtime Gateway abstraction and Channel realtime wire
contract.
- Renamed remaining APIs/types, updated the managed Slack example, and
added forbidden-term coverage.
- Preserved framework and vendor `Bot` terminology only where it remains
semantically correct.
2026-07-10 17:29:03 -05:00
Tyler Slaton 001dda539a chore(channels-intelligence): complete channel terminology sweep 2026-07-10 14:47:06 -07:00
Ben Taylor 4970f55878 Add Inspector Threads empty-state onboarding (#5909)
## Summary

Adds production onboarding for the Inspector Threads empty state:

- Moves the Threads `Talk to an Engineer` CTA into the main inspector
tab nav when Threads is active.
- Replaces the enabled-empty `No threads yet` state with example thread
rows and a deselected overview.
- Lets users select an example thread to preview the real thread-details
UI with Timeline, Raw AG-UI Events, and State data.
- Adds a dismissible/reopenable example tour that persists dismissal in
local storage.
- Hides examples once real threads are present.
- Adds the `Learn how Threads work` and `Explore self-hosted
Intelligence` CTAs.
- Adds a deferred autoplay video preview to the enabled-empty deselected
overview.

## Telemetry

New/updated Threads events in this PR:

- `oss.inspector.threads_tab_clicked` — fires when the rendered Threads
nav tab is clicked.
- `oss.inspector.threads_locked_viewed` — fires once per inspector
instance for the locked state.
- `oss.inspector.threads_empty_enabled_viewed` — fires once per
inspector instance when Threads are enabled with zero real threads.
- `oss.inspector.threads_enabled_viewed` — fires once per inspector
instance when real threads are present.
- `oss.inspector.threads_intelligence_signup_clicked` — fires from
locked-state Intelligence signup CTAs.
- `oss.inspector.threads_talk_to_engineer_clicked` /
`oss.inspector.talk_to_engineer_clicked` — fire from Threads-specific
and shared Talk to an Engineer CTAs.
- `oss.inspector.threads_example_viewed` — fires once per example thread
shown in the empty state.
- `oss.inspector.threads_example_selected` — fires once per example
thread selection.
- `oss.inspector.threads_example_tour_started` — fires when the tour
auto-starts for the first selected example.
- `oss.inspector.threads_example_tour_step_viewed` — fires once per
example thread/tour step.
- `oss.inspector.threads_example_tour_dismissed` — fires when the user
skips the tour.
- `oss.inspector.threads_example_tour_completed` — fires when the user
finishes the tour.
- `oss.inspector.threads_example_tour_reopened` — fires when the user
clicks `Show tour` after dismissal.

Telemetry properties are limited to product metadata and funnel context:
package/version, inspector distinct IDs,
intelligence/thread-service/license/runtime status, runtime URL type,
CTA surface/type, telemetry-disabled status, thread count, example
thread ID, tour step/tab, and dismiss method. We do **not** send message
content, AG-UI event payloads, agent state, prompts, completions, or
thread bodies.

No telemetry was added for passive video loading; it is a visual
affordance rather than a user intent signal.

## Outbound Attribution

Threads onboarding CTAs now include existing `ref` attribution plus
these UTM parameters:

- `utm_source=copilotkit_inspector`
- `utm_medium=in_product`
- `utm_campaign=threads_onboarding`

Affected links are limited to Threads onboarding surfaces:

- Threads tab-nav `Talk to an Engineer`
- Threads locked-state `Sign up for Intelligence`
(`https://dashboard.operations.copilotkit.ai/sign-in`)
- Empty Threads overview `Learn how Threads work`
- Empty Threads overview `Explore self-hosted Intelligence`

The UTM params are opt-in for these Threads onboarding CTAs and do not
apply to generic announcement/banner links or locked Memories CTAs. The
inspector spec includes a regression test to keep locked Memories CTAs
free of the Threads campaign params.

## Video Asset + Performance

- The overview video uses the CDN-hosted asset at
`https://cdn.copilotkit.ai/corp-site/videos/copilotkit-generative-ui-agentic-frontend-demo.webm`
instead of committing a binary to `@copilotkit/web-inspector`.
- Verified the URL serves `200`, `Content-Type: video/webm`,
`Content-Length: 6765736`, and a CloudFront cache hit.
- `@copilotkit/web-inspector` currently only inlines CSS and SVG assets
in its package build, while larger docs/showcase media commonly lives on
hosted/CDN-style URLs.
- The video `src` is not rendered on the initial overview paint. It is
deferred until `requestIdleCallback` or a short timeout fallback, uses
`preload="metadata"`, fades in after `loadeddata`, and does not load for
`prefers-reduced-motion: reduce`.

## Validation

- `NX_TUI=false npx -y pnpm@10.33.4 nx run
@copilotkit/web-inspector:test -- web-inspector.spec.ts`
- `NX_TUI=false npx -y pnpm@10.33.4 nx run
@copilotkit/web-inspector:check-types`

<img width="1662" height="1382" alt="CleanShot 2026-07-10 at 12 01
03@2x"
src="https://github.com/user-attachments/assets/e2031570-f602-40dc-a54c-e9c7690fc0ba"
/>
<img width="1680" height="1388" alt="CleanShot 2026-07-10 at 12 01
12@2x"
src="https://github.com/user-attachments/assets/2c8db42f-3ab0-47e2-a235-ea54e8dd292b"
/>
2026-07-10 16:46:32 -05:00
Tyler Slaton 68e43fefe1 refactor(channels-intelligence): rename remaining channel APIs 2026-07-10 14:39:56 -07:00
Sam Julien b9091c40a4 fix(web-inspector): address threads onboarding review 2026-07-10 14:11:55 -07:00
Tyler Slaton ea9910ae93 refactor(channels-intelligence): introduce realtime gateway abstraction 2026-07-10 14:10:30 -07:00
Tyler Slaton 4dddabd79f test(channels-intelligence): align claim test with provider-agnostic flow 2026-07-10 13:44:11 -07:00
Tyler Slaton 21d3b8c7df Merge remote-tracking branch 'origin/main' into update-intelligence-channels 2026-07-10 13:43:04 -07:00
Tyler Slaton 67fce71690 refactor(channels-intelligence): migrate HTTP contract to channels 2026-07-10 13:25:17 -07:00
Tyler Slaton 5c217538ab fix(channels-intelligence): claim deliveries provider-agnostically (#5914)
## Problem

A managed bot with **both** a Slack and a Teams adapter attached only
ever received its **Slack** deliveries. Teams deliveries stayed `queued`
forever — never claimed, never sent.

## Root cause

`channels-intelligence`'s runtime claim loop (`http-transports.ts` →
`claimOnce()`) posted a per-provider filter to
`/api/bots/listener/claim`:

```ts
{
  runtimeInstanceId: this.cfg.runtimeInstanceId,
  adapters: [this.cfg.adapter], // defaults to "slack"
}
```

app-api filters claimable deliveries by that list (`$adapters IS NULL OR
bie.provider = ANY($adapters)`), so a runtime declaring only `"slack"`
is never handed the same bot's Teams deliveries.

But the managed runtime is **provider-agnostic**: it emits abstract
render frames and Intelligence renders each reply per the delivery's own
reply target. There is no reason for the runtime to constrain claims by
provider — one `intelligenceAdapter()` should serve every channel its
bot has attached.

## Fix

Drop the `adapters` field from the claim body. `adapters` is already
optional on the app-api side (absent → `NULL` → no provider filter → all
providers), so this needs no coordinated backend change.
`this.cfg.adapter` is still used for the heartbeat's declared bots and
for egress, both unaffected.

## Testing

Verified end-to-end locally against a managed Teams bot: inbound Bot
Framework JWT → claim → agent run → render → Bot Connector egress all
`succeed` with this change. Slack continues to work unchanged.
2026-07-10 12:52:32 -07:00
Benjamin Taylor 150164a4bd fix(channels-intelligence): derive conversationKey per provider (Teams-safe)
Follow-up to the provider-agnostic claim change on this branch. Now that the
runtime claims deliveries for every provider its bot has attached, Teams
deliveries flow through the same bridge — and their reply target is a distinct
shape (serviceUrl/conversationId/tenantId, no teamId/channel/threadTs). Deriving
conversationKey from Slack-only fields collapsed every Teams conversation onto
one degenerate key, and conversationKey keys the agent/session
(getOrCreate -> makeAgent), so distinct Teams conversations would share
state/memory.

Make replyTarget a discriminated union (slack|teams) and derive conversationKey
per provider: teams:{tenantId}:{conversationId}, matching Intelligence app-api's
thread_key (OSS-441 slice 2, Intelligence #511) so client and server agree on
conversation identity. Unknown adapters fail loud (the claim loop's existing
catch nacks, not wedges).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-07-10 14:34:09 -05:00
github-actions[bot] 556ba9d8c0 style: auto-fix formatting 2026-07-10 19:14:02 +00:00
Sam Julien b11fd7d8d0 fix(web-inspector): remove threads cta utms 2026-07-10 12:13:07 -07:00
Sam Julien e245a990aa fix(web-inspector): use operations sign-in for threads signup 2026-07-10 11:48:38 -07:00
Sam Julien 852d41e176 fix(web-inspector): scope threads utm links 2026-07-10 11:38:55 -07:00
github-actions[bot] feffbacb6d style: auto-fix formatting 2026-07-10 18:33:39 +00:00
Sam Julien 81c1740726 fix(web-inspector): add inspector utm attribution 2026-07-10 11:32:43 -07:00
Tyler Slaton 4de005701d feat(channels-intelligence): managed-over-Phoenix launcher + slack managed entrypoint (OSS-406 Phase 1) (#5907)
## Summary

**OSS-406 Phase 1** — the missing composition that runs a managed bot
over the **Phoenix realtime path**, plus a real consumer of it.

The realtime foundation is live on main (gateway
`hosted_bots:project:<id>` channel, Redis fan-out, app-api durable
authority + lease fencing), and the SDK primitives — `startManagedBots`,
`connectPhoenixHostedBotChannel`, `PhoenixRealtimeTransport` — exist and
are unit-tested. But **nothing composed them**, so the managed adapter
fell back to its HTTP default and Phoenix was never exercised
end-to-end. This adds the launcher **and wires an example to it** so it
isn't an unused export.

## Launcher (`channels-intelligence/phoenix-launcher.ts`)

- **`startManagedBotsOnChannel(bots, { channel, scope,
runtimeInstanceId, log? })`** — wraps an already-connected channel in a
`PhoenixRealtimeTransport` (delivery source + render sink) and starts
the bots via `startManagedBots`. Split out so the *behavior* is
unit-testable against a fake channel.
- **`startManagedBotsOverPhoenix(bots, config)`** — thin glue:
`connectPhoenixHostedBotChannel` → delegate → `disconnect()` on
`stop()`.
- **`phoenixEgress`** — fail-loud `EgressSink`. `intelligenceAdapter` is
exclusive and, with a render sink wired, routes every
`post`/`update`/run-render through it — the generic `EgressSink` must
never be hit.

## Consumer (`examples/slack/app/managed.ts`)

A **real caller** of the launcher: the *same* Slack bot as
`examples/slack/app/index.ts` — identical agent, tools, context,
commands, and turn handlers — run in **managed mode over Phoenix**
instead of the native `slack()` adapter. `index.ts` (native/self-hosted)
is left untouched; `managed.ts` holds no Slack creds and no public
endpoint, just a runtime key + a Phoenix connection. Demonstrates the
"same bot, swap the transport" thesis concretely:

```
native:   createBot({ adapters: [ slack({ botToken, appToken }) ] })   // index.ts
managed:  startManagedBotsOverPhoenix([ createBot({ … }) ], { … })     // managed.ts
```

The managed `onMention` handler passes the current message as `prompt`
to `runAgent` — see the validation note below for why this is required
on the managed path (and not on native).

## Tests

Drive a **real `createBot`** through the **full managed path** over a
fake channel:
- a Phoenix-delivered turn → handler runs → `render_event` frame →
`complete_requested` (completion **intent**, never a self-ack);
- a throwing handler → `fail` intent (no completion, no ack).

Build + 97 package tests green; `examples/slack` `managed.ts`
type-clean.

## Validation — live E2E over the real Phoenix path

This didn't just pass unit tests against a fake channel; the whole loop
was driven end-to-end on a real local stack with a **real OpenAI
backend**, and I verified the message actually traveled the websocket
path (not the HTTP fallback).

**Stack:** Intelligence `main` via docker-compose (postgres,
postgres-ops, redis, keycloak, minio, tei, realtime-gateway on `:4401`)
+ app-api on `:7050` (graphile migrations applied). Managed-bots
entitlement was granted via the managed-service path (a stub ops
entitlement endpoint + `FF_MANAGED_BOTS=true` on both app-api and the
gateway; gateway join otherwise rejects with
`disabled_by_feature_flag`).

**Provisioning:** created a managed Slack bot + attached a Slack adapter
(fixture workspace/creds) against app-api, then triggered a real
`app-mention` event through a fake-Slack provider into app-api's signed
ingress.

**What was proven:**
- app-api ingress → Redis publish → gateway leases the delivery and
pushes `delivery.available` over Phoenix → `managed.ts` (via the
launcher) receives it, runs the **real OpenAI** agent, and streams
`render_event` frames back → durable render acceptances written
(`run_started`, `text_delta`, `text_end`, `finalize`) →
`complete_requested` intent → app-api commits the ack. Delivery ended
`succeeded`.
- **It genuinely used the websocket path.** With gateway debug logging
bumped, frames showed `HANDLED hosted_bot.render_event.v1 INCOMING ON
hosted_bots:project:<id> (SdkChannel)`. All app-api delivery-side calls
originated from the gateway's HTTP client (`hackney`), with **zero
launcher-originated HTTP delivery calls**, and the launcher contains no
HTTP delivery code at all. The render frames went bot → gateway over the
Phoenix socket.

**Bug found and fixed during validation (the reason `managed.ts` passes
`prompt`):**
The first real run failed with an OpenAI `400 input.messages=0` — the
agent received **zero messages**. Root cause: `runAgent`
(packages/channels `thread.ts`) only injects a user message when
`extra.prompt` is set; otherwise it relies on the adapter's
reconstructed history. The **native** path gets away with omitting
`prompt` because the native adapter's `getHistory` rebuilds the live
thread *including* the triggering message. The **managed** path does
not: app-api's `GET /api/bots/history`
(`reconstructManagedThreadHistory`) rebuilds only *prior committed*
deliveries and structurally excludes the in-flight turn (the current
delivery is handed to the SDK as the delivery envelope, not via
history). So a managed handler that omits `prompt` drops the newest user
message — turn 1 → 0 messages → 400; turn 2+ → the agent answers a
*stale* prompt. FakeAgent unit tests never caught it because they don't
exercise the history round-trip.

Fixed here by having the managed `onMention` pass `message.contentParts
?? message.text` as `prompt`. This is a **systemic** footgun for every
managed entrypoint; it's tracked with a durable-fix recommendation
(adapter auto-injects the current message so managed handlers match
native) in **OSS-459**.

## Scope

- **This PR:** the launcher composition + its first consumer +
unit/contract coverage, **plus the live-stack E2E above** which closes
OSS-406's "realtime path is unproven" gap and surfaced/fixed the managed
`prompt` bug.
- **Deferred (OSS-459):** Teams managed entrypoint, multi-tenant
multiplexing, BYO, promote to a deployable Intelligence managed-bot
runtime app, HTTP-path deprecation, shared bot-def extraction, and the
durable managed-`prompt` fix.

Refs OSS-406.

🤖 Generated with [Claude Code](https://claude.com/claude-code)
2026-07-10 11:23:54 -07:00
Tyler Slaton 779bb3df8d fix(examples/slack): exit nonzero when managed shutdown fails 2026-07-10 11:08:29 -07:00
Benjamin Taylor 57ddcb9532 fix(channels-intelligence): enforce runtimeInstanceId on OnChannel + leak-path tests + fail-loud managed entrypoint (OSS-406 review r3) 2026-07-10 12:31:24 -05:00
Sam Julien bfa9df05bb fix(web-inspector): use CDN threads overview video 2026-07-10 10:23:03 -07:00
Alem Tuzlak 2a16becf61 fix(channels-intelligence): claim deliveries provider-agnostically
The managed runtime's claimOnce() declared `adapters: [this.cfg.adapter]`
(defaulting to "slack"), which Intelligence used to filter claimable
deliveries by provider. A runtime serving a bot with both Slack and Teams
adapters would therefore never receive the bot's Teams deliveries — they
stayed queued forever while Slack worked.

The managed runtime is provider-agnostic: it emits abstract render frames
and Intelligence renders per the delivery's own reply target. So the claim
must not filter by provider. Drop the adapter filter from the claim body;
one config-free `intelligenceAdapter()` now serves every channel its bot
has attached.

Verified end-to-end locally against managed Teams: inbound JWT -> claim ->
agent -> render -> Bot Connector egress all succeed with this change.
2026-07-10 19:06:44 +02:00
Sam Julien b2dda71bb0 fix(web-inspector): remove threads nav sheen 2026-07-10 10:03:52 -07:00
github-actions[bot] 43fa5be1a9 style: auto-fix formatting 2026-07-10 16:53:55 +00:00
Sam Julien 3c1b5187d9 feat(web-inspector): add threads onboarding motion cues 2026-07-10 09:52:45 -07:00
github-actions[bot] 2851d83a8e style: auto-fix formatting 2026-07-10 16:49:23 +00:00