Commit Graph

373 Commits

Author SHA1 Message Date
Luis Meyer 4a190b1bd4 Merge branch 'main' into flags-version-header 2026-09-17 09:38:07 +02:00
Luis Meyer 2e03f56280 op 2026-09-16 13:19:47 +02:00
Luis Meyer b167598b77 fix(flags-core): use plural flags config version headers 2026-09-16 12:04:24 +02:00
Damien Simonin Feugas 4848877ca6 [@vercel/flags-core] Add custom waitUntil option (#497) 2026-09-16 09:58:56 +00:00
Luis Meyer 3c12c2c04d revert(flags-core): remove source debug logging 2026-09-16 11:44:50 +02:00
Luis Meyer 25154ede50 fix(flags-core): use singular flags config version headers 2026-09-16 11:18:23 +02:00
Vincent Derks 18bbece5e5 docs(skills): fix flag cleanup and Next.js guidance (#500) 2026-09-15 16:17:43 +02:00
Luis Meyer 48afe11165 feat(flags-core): add bundled source debug diagnostics 2026-09-15 12:21:50 +02:00
Luis Meyer 0fd2f412e9 debug 2026-09-15 11:38:43 +02:00
Luis Meyer 004baf818f fix 2026-09-15 10:25:46 +02:00
Luis Meyer da0b044c2f fix(flags-core): handle cancelled header refreshes and add changeset 2026-09-15 10:13:50 +02:00
Luis Meyer 923ea09467 stuff 2026-09-15 10:03:39 +02:00
Luis Meyer 7332270a2a [vercel-flags-core] add vercel client mode 2026-09-14 18:30:25 +02:00
Luis Meyer a3fc275ed3 docs(flags-core): clarify request-time initialization with OIDC (#496) 2026-09-10 16:36:37 +02:00
Vincent Derks f923203a0c docs(skills): separate flag management from SDK setup (#495)
* docs(skills): separate flag management from SDK setup

* docs(skills): restore vercel link step and route CLI-only requests

* docs(skills): keep setup first and define CLI-only requests

Move the CLI-only section below the setup and create flows, define when a request is CLI-only, and describe link verification once under Project targeting (EXP-3453).

* docs(skills): tighten CLI-only trigger and link to CLI reference
2026-09-10 10:59:26 +02:00
github-actions[bot] 6444210ee9 Version Packages (#493)
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
@vercel/flags-core@1.8.1 @flags-sdk/vercel@1.4.8 flags@4.3.1
2026-09-09 09:26:12 +00:00
Luis Meyer e0eebe6fbc fix(flags-core): request identity on the stream so Bun receives the first datafile (#494)
* fix(flags-core): request gzip on the stream so Bun receives the first datafile

* test(flags-core): expect Accept-Encoding on stream requests in black-box tests

* fix(flags-core): send Accept-Encoding: identity on the stream only when running on Bun
2026-09-09 11:16:11 +02:00
Dominik Ferber c9d28116eb Experiments (#486)
* step 1

* single experiment

* reuse variants

* single experiment

* exposures

* undo exposureLogging boolean

* Attach experiment metadata to all evaluated flag outcomes

* version

* hybrid and override exposure reporting

* Initialize adapters before reporting flag overrides

* Update package versions for experiment replacement

* versions

* fix test

* Rename exposure reporting APIs as experimental

* Add APIs for reporting flag exposures and overrides

* Update changeset for exposure reporting APIs

* Remove default exposure reporting

* Defer exposure reporting with waitUntil

* Fix override reporting without a reporter

* Handle optional override reporting in Vercel adapter

* Update override reporting to accept parameter objects

* patch
2026-09-04 12:21:17 +00:00
Vincent Derks 752a05f9ad Trim duplicated vercel flags CLI docs from flags-sdk skill (#492)
* Trim duplicated vercel flags CLI docs from flags-sdk skill

Point agents at --help for syntax and keep lifecycle/safety guidance that skills must own (EXP-3411).

* Shrink flags-sdk skill description under 1024 chars

Drop duplicate CLI trigger phrases; keep subcommand names once for activation.

* Drop stale skill-tables wording from CLI pointer

* Align flags-sdk skill with EXP-3411 acceptance criteria

Make --help discovery and the vercel-cli cross-link explicit in SKILL.md and providers.md.

* Trim frontmatter subcommand list and drop duplicated CLI prerequisites

* Add CLI-to-SDK glue and existing-flag flow to flags-sdk skill

* Address review: restore rm/unarchive/open in frontmatter, fix split default-variant wording

* Correct set/use-targeting semantics: targeting is paused, not replaced

* Ground CLI lifecycle guidance in public Vercel Flags docs

* Align authentication guidance with vercel.com docs: OIDC default, SDK keys manual

* Fix singleton client auth note; drop nonexistent targeting subcommand

* Consolidate env pull guidance into one section
2026-09-03 09:15:12 +02:00
Vincent Derks 22083e7d99 Prefer vercel flags create over add in the skill (#488) 2026-09-01 09:17:07 +00:00
Vincent Derks eaa7f1e609 Make flags-sdk skill setup-first for discovery (#487)
* Make flags-sdk skill setup-first for discovery

Lead the skill description and structure with install/setup so agents load it for configuration, not only usage. Split setup vs create-flag workflows and sync CLI guidance to create/rules plus timestamp epoch-ms notes (EXP-3256).

* Widen skill title to cover setup and usage

* Drop timestamp CLI notes from this PR

* Keep create vs add CLI rename out of this PR

* Fix setup order and restore skill discovery triggers

Create flags.ts before Flags Explorer, pull FLAGS during configure, and restore frontmatter usage triggers dropped in the setup-first rewrite.

* Shrink skill description under 1024-char limit

Keep setup-first and restored triggers; trim wording so Skills CI validation passes.

* Harden flags-sdk skill setup guidance

Use export {} for empty flags.ts, note Explorer import path when flags are not at root, and clarify FLAGS_SECRET for setup-only.

* Remove Hypertune from flags-sdk skill

Hypertune is no longer supported; drop it from the skill description, references list, and providers guide.
2026-09-01 09:01:05 +00:00
github-actions[bot] f13fd27816 Version Packages (#484)
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
@vercel/flags-core@1.8.0 @flags-sdk/vercel@1.4.7
2026-08-26 12:57:29 +02:00
Luis Meyer cc8c26648c feat(flags-core): add metrics environment option (#453)
* feat(flags-core): support explicit environment

Co-Authored-By: Claude <noreply@anthropic.com>

Co-Authored-By: Luis Meyer <luis.meyer@vercel.com>

* fix(flags-core): scope environment to metrics ingest

Co-Authored-By: Claude <noreply@anthropic.com>

Co-Authored-By: Luis Meyer <luis.meyer@vercel.com>

* fix(flags-core): clarify metrics environment

Co-Authored-By: Claude <noreply@anthropic.com>

* fix(flags-core): restrict metric environment values

* docs(flags-core): clarify metrics environment fallback

---------

Co-authored-by: vercel[bot] <35613825+vercel[bot]@users.noreply.github.com>
Co-authored-by: Claude <noreply@anthropic.com>
2026-08-26 12:28:13 +02:00
Rich Haines 9f77c88979 docs: fix Global Config links (#483) 2026-08-25 13:47:45 +02:00
Rich Haines 0c0872710b [docs] upgrade Geistdocs to 1.20.4 (#480)
Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
Co-authored-by: molebox <22930449+molebox@users.noreply.github.com>
2026-08-25 10:47:27 +02:00
Rich Haines 03f971440a Update Geistdocs to 1.23.0 (#481) 2026-08-25 10:38:22 +03:00
Dominik Ferber 6294177c50 docs: update marketing pages guide examples (#479)
Rename the Proxy function to `proxy` and simplify the `identify` example
with the `Identify` type helper.

Co-authored-by: vercel[bot] <35613825+vercel[bot]@users.noreply.github.com>
Co-authored-by: Dominik Ferber <1765075+dferber90@users.noreply.github.com>
2026-08-18 08:59:39 +02:00
Dominik Ferber 5838f58412 chore: upgrade Changesets to v3 (#478)
Changesets v3 is the first major release since v2. All packages are now ES
modules, and the dependency tree is smaller.

- @changesets/cli 2.31.0 -> 3.0.0
- @changesets/changelog-github ^0.7.0 -> ^1.0.0
- changesets/action v1.7.0 -> v2.1.0 (v1 supports only Changesets v2)
- root engines.node -> ^22.11 || ^24 || >=26, the requirement of the new CLI

Remove the onlyUpdatePeerDependentsWhenOutOfRange experimental option.
Changesets v3 gives a peer dependent a patch increase, and only when the new
version leaves the declared range. This makes the option redundant for the
release plan.

Empty the ignore list. Changesets v3 does not version private packages by
default, and every ignored package is private.

Set format to false. Changesets v3 no longer bundles Prettier, and it excludes
Biome from formatter auto-detection.

Co-authored-by: vercel[bot] <35613825+vercel[bot]@users.noreply.github.com>
Co-authored-by: Dominik Ferber <1765075+dferber90@users.noreply.github.com>
2026-08-17 14:06:45 +03:00
github-actions[bot] a427635e24 Version Packages (#475)
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
@flags-sdk/openfeature@0.1.3
2026-08-13 19:35:54 +00:00
Dominik Ferber 2dfc85c3ec [openfeature] allow recovering from bad init (#474) 2026-08-13 22:32:43 +03:00
Dominik Ferber b64b6bccdb chore: override nanoid@3 to fix Dependabot alert (#471)
`hypertune` and `@vercel/microfrontends` resolved to nanoid 3.3.16, which
is vulnerable to an infinite loop when a custom generator is called with
size zero. The existing `nanoid@>=4` override did not cover the v3 range,
so add a matching `nanoid@3: ^3.3.18` override.

Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-08-12 11:22:17 +03:00
github-actions[bot] f0f8a00848 Version Packages (#465)
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
@flags-sdk/global-config@0.3.1 @flags-sdk/statsig@0.3.1 @flags-sdk/launchdarkly@1.1.1 @flags-sdk/hypertune@0.3.4 @flags-sdk/growthbook@0.3.1
2026-08-12 08:39:34 +02:00
Dominik Ferber 2532e99ea8 chore: fix open Dependabot security alerts (#470)
Bumps the vulnerable transitive dependencies flagged by Dependabot via
pnpm overrides, and the direct nanoid dependency in the examples.

- nanoid >= 4 -> ^5.1.16 (GHSA infinite loop on negative/zero size)
- brace-expansion >= 4 -> ^5.0.9 (DoS via unbounded intermediate arrays)
- dompurify -> ^3.4.13 (XSS via detached subtree after IN_PLACE hook removal)
- fast-uri -> ^3.1.5 (host confusion via backslash authority introducer)
- js-yaml 3 -> ^3.15.1, js-yaml 4 -> ^4.3.1 (quadratic CPU in !!omap)
- mermaid -> ^11.16.1 (DoS, prototype pollution, CSS injection)
- postcss -> ^8.5.23 (arbitrary .map file read via sourceMappingURL)
- @sveltejs/kit -> ^2.70.2 (ReDoS in Accept header content negotiation)

image-size (alerts #979, #980) has no patched release yet, so it is left
as-is. It is only used at build time by the docs site.

Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-08-11 20:14:54 +02:00
Andy 8913cf1578 Bump @vercel/global-config to 1.5.1 (#464)
* Bump Global Config SDK

* Add changeset
2026-08-07 16:00:05 +02:00
christopherkindl db7ce9aa66 [docs] upgrade geistdocs to 1.19.4 (#463) 2026-08-05 09:51:51 +03:00
github-actions[bot] c7a56d6a66 Version Packages (#461)
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
@flags-sdk/hypertune@0.3.3 @flags-sdk/statsig@0.3.0 flags@4.3.0 @flags-sdk/growthbook@0.3.0 @flags-sdk/launchdarkly@1.1.0 @flags-sdk/posthog@1.0.1 @flags-sdk/reflag@1.0.2 @flags-sdk/global-config@0.3.0
2026-08-04 19:12:09 +02:00
Andy 0258b6ca3c Update exports and changesets (#462) 2026-08-04 13:14:03 +02:00
Luis Meyer 58e1f5bcdf Rename Edge Config packages to Global Config (#452)
* Rename edge config packages

* Rename Global Config APIs

* Fix Global Config environment setup

* Rename Global Config endpoints

* Update Global Config documentation links

* Undo lockfile changes

* Update lockfile

* Undo lockfile changes

* Update lockfile

* Fall back to EDGE_CONFIG

---------

Co-authored-by: Andy Bitz <artzbitz@gmail.com>
2026-08-04 12:36:41 +02:00
Dominik Ferber 3a5ba70f53 docs: add no-store to flags discovery endpoint (#459) 2026-08-03 16:14:28 +03:00
christopherkindl 6ddb6b75aa [docs] upgrade geistdocs to 1.19 and rework the homepage layout (#457) 2026-07-31 16:25:46 +02:00
github-actions[bot] 81707e7a0e Version Packages (#456)
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
@flags-sdk/posthog@1.0.0
2026-07-29 15:01:19 +00:00
Dominik Ferber aec3c03430 @flags-sdk/posthog: upgrade posthog-node; explicit evaluation modes (#436)
* @flags-sdk/posthog: upgrade posthog-node

* @flags-sdk/posthog: make local vs remote evaluation explicit

The default adapter passed POSTHOG_PERSONAL_API_KEY into the runtime
posthog-node client, which enabled local evaluation and started a
feature-flag poller in every warm process. On serverless this produced
large, traffic-independent PostHog feature flag request volume.

Local evaluation is now opt-in via POSTHOG_SECRET_KEY; without it the
adapter evaluates remotely. POSTHOG_PERSONAL_API_KEY is used only by
getProviderData (Flags Explorer) and no longer affects runtime
evaluation. Drops the forced 10s poll interval in favor of the v5
default. Updates docs, README, and tests.

* remove unused @vercel/edge-config dependency

* add remote vs local tradeoffs

* rm edge config tag

* modernize

* rm trimKey

* lockfile

* update

* fixes

* reword changeset

* merge changesets

* reword changelog
2026-07-29 14:54:40 +00:00
github-actions[bot] e718915540 Version Packages (#455)
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
flags@4.2.4
2026-07-29 09:49:11 -04:00
Dominik Ferber dcb74ff938 return no-store on flags discovery endpoint (#454) 2026-07-29 09:42:01 -04:00
github-actions[bot] 5ff8eafec9 Version Packages (#451)
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
@flags-sdk/vercel@1.4.6 @vercel/flags-core@1.7.1
2026-07-27 10:32:21 -04:00
Dominik Ferber ceb15198f7 [@vercel/flags-core] strip g and y regex flags (#450) 2026-07-27 13:50:24 +00:00
Dominik Ferber fde6ab7135 address CodeQL alerts (#448)
* explicit workflow permissions

* max-delay

* better parsing
2026-07-26 10:20:17 -04:00
Dominik Ferber 6dbf589e0c upgrade toolbar and others (#447) 2026-07-26 13:42:26 +00:00
Dominik Ferber 42cc02cacd upgrade more packages (#446) 2026-07-26 13:20:24 +00:00
Dominik Ferber 1f000784e5 upgrade vite & vitest (#445) 2026-07-26 08:25:37 -04:00