Commit Graph

172 Commits

Author SHA1 Message Date
github-actions[bot] 7f2050641e Version Packages (#2221)
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2026-06-10 17:24:42 -07:00
Pranay Prakash b93a071796 Patch vulnerable package dependencies (#2302)
* chore: patch package dependency vulnerabilities

Signed-off-by: Pranay Prakash <pranay.gp@gmail.com>

* Prefer direct dependency upgrades for security fixes

---------

Signed-off-by: Pranay Prakash <pranay.gp@gmail.com>
2026-06-08 16:29:13 -07:00
github-actions[bot] 3c89e0c368 Version Packages (#2213)
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2026-06-01 20:30:48 -07:00
github-actions[bot] a5cf3d7d37 Version Packages (#2203)
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2026-06-01 18:43:37 -07:00
github-actions[bot] 8e08d823fd Version Packages (#2131) 2026-05-31 11:52:52 +02:00
github-actions[bot] b93e7c3b59 Version Packages (#1921)
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2026-05-22 13:34:26 -07:00
workflow-devkit-release-bot[bot] dd139dfe76 Version Packages (#1789) 2026-04-16 17:10:05 -07:00
workflow-devkit-release-bot[bot] 2a7ead058a Version Packages (#1726)
Co-authored-by: workflow-devkit-release-bot[bot] <workflow-devkit-release-bot[bot]@users.noreply.github.com>
2026-04-16 22:41:58 +00:00
workflow-devkit-release-bot[bot] 7b045f0945 Version Packages (#1720)
Co-authored-by: workflow-devkit-release-bot[bot] <workflow-devkit-release-bot[bot]@users.noreply.github.com>
2026-04-13 19:19:08 -07:00
workflow-devkit-release-bot[bot] aed6ad262a Version Packages (#1657)
Co-authored-by: workflow-devkit-release-bot[bot] <workflow-devkit-release-bot[bot]@users.noreply.github.com>
2026-04-10 18:51:41 -07:00
workflow-devkit-release-bot[bot] 4e435e0332 Version Packages (#1621) 2026-04-07 16:53:33 -07:00
Peter Wielander f0d6a85ddd [cli] [core] Probe deployment specVersion before CLI start (#1629) 2026-04-07 11:18:42 -07:00
Pranay Prakash 125c38708e [changeset] Exit pre-release mode (to release 4.2 stable) (#1508) 2026-04-06 13:52:46 -07:00
Nathan Rajlich 2680a427f0 fix: add Request and Response revivers to web and CLI hydration (#1414) 2026-04-06 06:30:36 +00:00
workflow-devkit-release-bot[bot] 29fe9ded57 Version Packages (beta) (#1600) 2026-04-03 17:05:54 -07:00
Nathan Rajlich f5d2aef58f Add serde compliance tooling and improve custom class serialization DX (#1552)
* Add serde compliance tooling and update skill documentation

- Add serde compliance checker library to @workflow/builders
- Add build-time warnings for serde classes with Node.js imports in workflow bundle
- Add 'workflow transform' CLI command for inspecting SWC output
- Implement 'workflow validate' CLI command with serde compliance checks
- Add serde analysis panel to SWC playground
- Update workflow skill with custom class serialization documentation

* Fix --json + --strict: use process.exitCode so JSON output is returned before exit

* Address code review feedback

- Fix --strict exit code: honor process.exitCode in BaseCommand.finally()
- Remove unused --module-specifier flag from transform command
- Add missing Node.js builtins (e.g. test) to playground detection list
- De-dupe build-time serde warnings by grouping identical issues across classes
- Make Serde Analysis panel collapsible like the output panels

* Use .gitignore for validate file discovery; fix changeset wording
2026-04-03 21:03:59 +00:00
workflow-devkit-release-bot[bot] 45fd831b1d Version Packages (beta) (#1593) 2026-04-02 21:25:14 +00:00
workflow-devkit-release-bot[bot] 8462c5df89 Version Packages (beta) (#1563) 2026-04-01 16:08:49 -07:00
workflow-devkit-release-bot[bot] 91ba457764 Version Packages (beta) (#1550) 2026-03-30 13:42:22 -07:00
Harpreet cdf90d5a38 Rename Workflow DevKit to Workflow SDK, remove beta badge, add tweet wall (#1541)
* Rename Workflow DevKit to Workflow SDK, remove beta badge, add tweet wall

- Rename "Workflow DevKit" to "Workflow SDK" across all files (~108 files)
- Rename standalone "WDK" references to "Workflow SDK"
- Remove beta badge from homepage hero
- Add tweet wall component to homepage with 4 builder testimonials

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>

* Rename Workflow DevKit to Workflow SDK, remove beta badge, add tweet wall

- Rename "Workflow DevKit" to "Workflow SDK" across all files (~108 files)
- Rename standalone "WDK" references to "Workflow SDK"
- Remove beta badge from homepage hero
- Add tweet wall component to homepage with 4 builder testimonials

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
Signed-off-by: Harpreet Arora <harpreet.txt@gmail.com>

* Address review: fix missed trigger phrase renames and bump skill versions

- Rename "workflow devkit" to "workflow sdk" in trigger phrases for both skill files
- Bump workflow-init SKILL.md version to 1.1
- Bump workflow SKILL.md version to 1.5
- Note: CLAUDE.md is a symlink to AGENTS.md, already renamed

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
Signed-off-by: Harpreet Arora <harpreet.txt@gmail.com>

* link correct tweet

---------

Signed-off-by: Harpreet Arora <harpreet.txt@gmail.com>
Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
Co-authored-by: Karthik Kalyanaraman <karthik.kalyanaraman@vercel.com>
2026-03-29 16:05:39 -07:00
workflow-devkit-release-bot[bot] e11eebf1e5 Version Packages (beta) (#1514) 2026-03-27 11:17:22 -07:00
workflow-devkit-release-bot[bot] a375a3fd85 Version Packages (beta) (#1440)
Co-authored-by: workflow-devkit-release-bot[bot] <workflow-devkit-release-bot[bot]@users.noreply.github.com>
2026-03-24 17:19:33 +00:00
Peter Wielander 01bbe66d5a [world] Add stream pagination and metadata endpoints (#1470) 2026-03-23 17:39:39 -07:00
Peter Wielander 5837d577c2 [cli] [world-local] Ensure update checks don't suggest upgrading from stable release to pre-releases (#1490) 2026-03-23 17:29:34 -07:00
Pranay Prakash 2ef33d2828 feat: export semantic error types and add API reference docs (#1447)
* feat: export semantic error types and add API reference documentation

Add missing error exports (HookNotFoundError, EntityConflictError,
RunExpiredError, TooEarlyError, ThrottleError, RunNotSupportedError,
WorkflowWorldError) to workflow/internal/errors. Create new error
classes for world-level semantics. Tighten TSDoc comments on all
error classes. Add API reference docs for all error types.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>

* fix: use @setup declarations, workflow/errors import, and errors/ doc section

- Replace @skip-typecheck with proper `declare` + `// @setup` lines
  so code samples are typechecked but setup lines hidden from readers
- Add `workflow/errors` export to package.json (public API, replaces
  `workflow/internal/errors` in docs)
- Add `workflow/errors` path mapping in docs-typecheck type-checker
- Add HookConflictError to re-export list
- Move all error docs under api-reference/workflow/errors/ subdirectory
- Update all internal cross-references and links

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>

* refactor: move error docs to top-level workflow-errors section

- Move semantic error docs to api-reference/workflow-errors/ (matching
  the workflow/errors import path, like workflow-api for workflow/api)
- Keep FatalError and RetryableError in api-reference/workflow/ since
  they're imported from workflow, not workflow/errors
- Fix all cross-reference links

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>

* chore: update HTTP debug logger JSDoc to clarify scope

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>

* fix: make TooEarlyError.retryAfter a number (seconds) matching WorkflowWorldError

TooEarlyError.retryAfter is now seconds (number) instead of a Date,
consistent with ThrottleError and WorkflowWorldError. The conversion
from seconds to Date is done at the consumer site (step-handler) rather
than at construction time.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>

* fix: address review feedback on docs accuracy

- WorkflowWorldError docs: add status, code, url, retryAfter properties
  to TSDoc; clarify that .is() only matches direct instances (not
  subclasses); use instanceof in catch-all example
- TooEarlyError/ThrottleError docs: mark retryAfter as optional (?)
  to match actual type definitions

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-03-24 00:01:36 +00:00
Lucas Ralph 0d72b2d363 [cli] Add bulk cancel, --status filter, fix step JSON hydration (#1467) 2026-03-23 11:56:00 -07:00
Peter Wielander da6adf7798 [o11y] Polish display when run data has expired (#1438) 2026-03-23 11:38:19 -07:00
Peter Wielander fdbe853531 Fix CLI health check for Astro/Sveltekit and add debug http logs to world-vercel (#1442) 2026-03-18 12:58:03 -07:00
workflow-devkit-release-bot[bot] 5d196982a2 Version Packages (beta) (#1377)
Co-authored-by: workflow-devkit-release-bot[bot] <workflow-devkit-release-bot[bot]@users.noreply.github.com>
2026-03-18 10:21:57 -07:00
Vercel Release Bot 471cb5d9c6 Version Packages (beta) (#1352)
Co-authored-by: workflow-devkit-release-bot[bot] <workflow-devkit-release-bot[bot]@users.noreply.github.com>
2026-03-12 19:40:59 -07:00
Nathan Rajlich 3c3f80a1f0 fix(cli): remove short flag collision on -e in health command (#1343)
The health command's `endpoint` flag and the shared `env` flag both
declared `char: 'e'`, causing ambiguity. Remove the short flag from
`endpoint` so `-e` unambiguously maps to `--env`.
2026-03-12 12:23:51 -07:00
Nathan Rajlich 9f3551caec Fix flaky Vercel prod e2e tests by skipping CLI update check (#1350)
The e2e tests spawn a CLI subprocess for every inspect/cancel/health call.
Each subprocess performs an npm registry version check on startup, which
can hang under load and exceed the 20s spawn timeout, causing SIGTERM.

Add WORKFLOW_NO_UPDATE_CHECK=1 env var support to skip the check, and
set it in the e2e test harness.
2026-03-12 12:22:52 -07:00
Vercel Release Bot 9c3213926f Version Packages (beta) (#1325)
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2026-03-11 17:57:07 -07:00
Vercel Release Bot 5f4395de7b Version Packages (beta) (#1306) 2026-03-10 19:25:18 -07:00
Nathan Rajlich d842ce1c43 fix: surface 429 rate-limit errors in e2e tests and CLI (#1309)
Multiple layered issues caused encryption key 429 errors to produce
confusing, unrelated-looking test failures:

- awaitCommand() in e2e utils now rejects on non-zero exit codes
  instead of silently resolving (the most critical fix)
- cliInspectJson/cliHealthJson throw on empty stdout instead of
  falling back to '{}'
- maybeDecryptFields re-throws HTTP errors instead of silently
  falling back to encrypted placeholders
- fetchRunKey includes response body and status text in errors
- Added 429 to CLI status text map
2026-03-10 00:23:05 -07:00
Peter Wielander 887cc2bd55 [web-shared] [cli] Refactor observability data fetching (#1261) 2026-03-10 01:36:03 +00:00
Nathan Rajlich 83dbd46456 Stop reading WORKFLOW_VERCEL_* env vars at runtime to prevent unintended proxy routing (#1304)
* Stop reading WORKFLOW_VERCEL_* env vars at runtime to prevent unintended proxy routing

createWorld() in core no longer reads WORKFLOW_VERCEL_PROJECT, WORKFLOW_VERCEL_TEAM,
WORKFLOW_VERCEL_AUTH_TOKEN, WORKFLOW_VERCEL_ENV, or WORKFLOW_VERCEL_PROJECT_NAME from
process.env. These env vars are intended for CLI/observability tooling only, and
reading them at runtime caused all workflow traffic to route through the
api.vercel.com proxy when users mistakenly set them as Vercel project env vars.

The Vercel runtime already provides everything needed: OIDC tokens for auth,
VERCEL_PROJECT_ID for encryption context, and VERCEL_DEPLOYMENT_ID for world
selection. createWorld() now calls createVercelWorld() with no config.

A warning is emitted if the env vars are detected at runtime, telling users to
remove them.

The CLI and e2e tests are updated to call createVercelWorld() directly with an
explicit config object and inject via setWorld(), keeping the WORKFLOW_VERCEL_*
env vars scoped to tooling contexts only.

* Refactor inferVercelEnvVars to return config instead of relying on process.env

inferVercelEnvVars() now returns a VercelEnvVars object with the resolved
config values. setup.ts uses the returned object directly for
createVercelWorld() instead of re-reading from process.env via getEnvVars().

The writeEnvVars() calls inside inferVercelEnvVars are consolidated into a
single call at the end, retained only for the embedded web UI which reads
process.env as a fallback in its server actions. The scattered writeEnvVars
calls after each inference step are removed.

* Address review: consistent e2e gate and expanded warning

- Use WORKFLOW_VERCEL_ENV as the gate in both e2e.test.ts and
  bench.bench.ts for consistency (was WORKFLOW_VERCEL_AUTH_TOKEN in
  e2e.test.ts, WORKFLOW_VERCEL_ENV in bench.bench.ts)
- Expand the misconfiguration warning to also detect
  WORKFLOW_VERCEL_AUTH_TOKEN and WORKFLOW_VERCEL_ENV, listing the
  specific env vars that are set

* Add changeset

Signed-off-by: Nathan Rajlich <n@n8.io>

---------

Signed-off-by: Nathan Rajlich <n@n8.io>
2026-03-09 20:46:19 +00:00
Vercel Release Bot 0063180d65 Version Packages (beta) (#1291)
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2026-03-07 20:33:25 +00:00
Vercel Release Bot 58afeb25c2 Version Packages (beta) (#1284)
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2026-03-06 13:46:57 -08:00
Vercel Release Bot 596d105323 Version Packages (beta) (#1279) 2026-03-06 00:20:52 +00:00
Nathan Rajlich 97932d3086 fix: thread runId through stream inspection for encryption key resolution (#1277)
CLI showStream:
- Requires --run with --decrypt for encrypted stream decryption
- Warns when --decrypt is used without --run

Web stream reading:
- readStreamServerAction accepts runId parameter for key resolution
- Stream API route reads runId from query param
- readStream client function passes runId to the API route
- useStreamReader hook accepts and passes runId
- run-detail-view passes runId to useStreamReader

Removes getRunIdFromStreamId helper (stream IDs don't always share
the run's ULID, e.g. streams serialized across step/workflow boundaries).
2026-03-05 23:36:36 +00:00
Peter Wielander 11dcb646d3 [world-local] [world-postgres] [cli] Validate local run ID and quiet dotenv logs (#1273) 2026-03-05 21:35:23 +00:00
Vercel Release Bot 597afa5174 Version Packages (beta) (#1250)
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2026-03-05 13:01:55 -08:00
Pranay Prakash 1926296c67 Manually bump core packages to 4.2.x (#1272) 2026-03-05 10:48:58 -08:00
Nathan Rajlich b68ed630ec fix(cli): read orgId from project entry in repo.json, not root (#1263)
The Vercel CLI's repo.json format puts orgId on each project entry,
not at the root level. The CLI was reading repoConfig.orgId (undefined)
instead of project.orgId, which meant teamId was never set. Without
teamId, the world-vercel URL selector used the direct vercel-workflow.com
URL instead of the api.vercel.com proxy, causing 401 errors because
vercel-workflow.com only accepts OIDC tokens (not CLI auth tokens).

Also fix the RepoProjectConfig/RepoProjectsConfig type definitions
to match the actual repo.json structure.
2026-03-04 23:22:46 +00:00
Nathan Rajlich bbe40ff00a Opt-in decryption for o11y tooling (CLI + web) (#1256)
* Add browser-compatible AES-GCM to core and HKDF key derivation to world-vercel

* update changeset

* Move HKDF key derivation server-side: API returns per-run derived key

* Refactor encrypt/decrypt to accept CryptoKey, export importKey for callers to import once per run

* Overload getEncryptionKeyForRun: accept context for start(), fetch WorkflowRun in resume-hook

* Split changeset into per-package descriptions for world, world-vercel, and core

* Remove unnecessary Uint8Array.from() wrapper around Buffer.from()

* Use zod to parse Vercel API response

* fix: restore world-vercel files to main versions

The rebase incorrectly picked up older versions of these files from
early encryption branch commits. The main versions are correct and
up-to-date.

* fix: add type cast for hydrateStepReturnValue return in hook.ts

* Make decryption an explicit opt-in for o11y tooling

* Restore encrypted data handling in o11y hydration layer

* Use EncryptedDataRef with util.inspect.custom for CLI encrypted data display

* Fix Decrypt button crash: use correct 'refresh' callback from useWorkflowResourceData

* Implement client-side decryption for web o11y with getEncryptionKeyForRun RPC

* Fix CLI decrypt: fetch WorkflowRun for key resolution, cache per runId

* Use named constructor pattern for encrypted data display in web o11y

* Decrypt event data when encryption key is available after Decrypt button click

* Lift encryption key to run-level state, auto-decrypt on fetch, fix field pollution

* Re-load expanded event data when encryption key becomes available

* Consolidate Decrypt to title bar Button, remove sidebar decrypt card

* Add hover tooltip to Decrypt button explaining scope and state

* Show flat Encrypted label for encrypted fields, use Lucide Lock icon in DataInspector

* Render eventData subfields individually to avoid encrypted markers in collapsed preview

* Revert: render eventData subfields individually

* Fix Lock icon vertical alignment in DataInspector encrypted label

* update changeset

* Update CLI, web, and stream callers for CryptoKey: importKey at resolution sites

* Pass teamId to the get-key endpoint

* fix: remove unused DataInspector import in events-list.tsx

* fix: restore world-vercel files to base branch versions

Cherry-pick conflict resolution incorrectly took the older opt-in-decrypt
versions of these files, reverting improvements from main (dispatcher,
createGetEncryptionKeyForRun extraction, nullable key response).

* fix: address PR review feedback

- Remove duplicate AttributePanel/EventsList rendering in entity-detail-panel.tsx.
  Thread encryptionKey into the existing EventsList render instead.
- Restore missing re-exports (isClassInstanceRef, isStreamId, isStreamRef)
  in web-shared/src/index.ts to maintain backwards compatibility.
- Add 'error' to replaceEncryptedWithMarkers field list in web-shared
  hydration.ts to match the decrypt path.
- Extend CLI hydration eventData decrypt/placeholder to cover all known
  serialized fields (output, metadata, payload) not just result/input.
- Add 'error' to CLI replaceEncryptedWithRef field list.
- Remove invalid encryptionKey option from useWorkflowResourceData call
  (hook doesn't support it yet), add TODO.
- Add 4 unit tests for hydrateDataWithKey in serialization-format.test.ts:
  encrypted+key decrypts, encrypted+noKey returns raw, non-encrypted
  hydrates normally, non-Uint8Array legacy data passes through.

* feat: thread encryptionKey through useWorkflowResourceData hook

Instead of leaving a TODO, implement the encryptionKey support directly:
- Add optional encryptionKey to useWorkflowResourceData options
- When key is available, use hydrateResourceIOWithKey (async decrypt)
  instead of hydrateResourceIO for all resource types
- Remove redundant hydrateResourceIO from fetchResourceWithCorrelationId

* fix: address comprehensive review feedback on PR #1256

High priority:
- Gate showStream key fetch on --decrypt flag, warn when --decrypt
  used without --run
- Fix workflow-server-actions.server.ts missing cryptoKey params
  (undefined for both getExternalRevivers and getDeserializeStream)
- Add hydration + decryption to listEvents (was completely missing)
- Fix error/eventData display: check isEncryptedMarker before
  hasDisplayContent so encrypted markers don't silently disappear

Medium priority:
- handleDecrypt: use toast.error() instead of console.error for
  user-visible feedback on key fetch failures
- CLI maybeDecryptFields: add try/catch with graceful fallback to
  encrypted placeholders + warning, also decrypt error field
- use-resource-data: wrap hook/sleep hydrate() in try/catch to
  prevent stuck loading state on decryption errors
- Decrypt button: also check run.error and step input/output for
  encrypted markers, not just run.input/output

Low priority:
- event-list-view: add .catch() to re-load useEffect promise
- Export ENCRYPTED_DISPLAY_NAME from hydration.ts and import in
  data-inspector.tsx instead of raw 'Encrypted' string
2026-03-04 13:17:09 -08:00
Nathan Rajlich 7618ac36c2 Wire AES-GCM encryption into serialization layer (#1251)
* fix(core): chain unconsumed event check onto promiseQueue to prevent false positives

The EventsConsumer's unconsumed event check (setTimeout(0)) was racing
against the promiseQueue's async deserialization. When parallel steps
completed and their hydrateStepReturnValue did real async work (e.g.,
decryption), the setTimeout(0) fired before the promise chain resolved
the step results and triggered the next subscribe() call. This caused
step_created events for sequential steps to be falsely flagged as
unconsumed/orphaned.

Fix: chain the unconsumed check onto the promiseQueue via getPromiseQueue()
so it only fires after all pending async work completes. Use
process.nextTick (not setTimeout) after the queue drains to give
synchronous subscribe() calls from resolved user code a chance to cancel.
Version-based cancellation replaces clearTimeout since the check is now
promise-based.

Adds getPromiseQueue option to EventsConsumerOptions. The workflow.ts
context uses a getter/setter to keep the promiseQueue holder in sync.

Reproduction test: parallel steps A+B with 10ms mock deserialization
delay, followed by sequential step C. Previously failed with
'Unconsumed event: step_created(C)'. Now passes.

* fix: chain hydrateWorkflowArguments onto promiseQueue to prevent false unconsumed events

The unconsumed event check was firing during the async gap between
run_started consumption and the workflow function subscribing its
first step callbacks. This happened because hydrateWorkflowArguments
is async, and during its await, the EventsConsumer advanced to
step_created events that had no subscriber yet.

Fix: chain hydrateWorkflowArguments onto the promiseQueue so the
unconsumed check (which waits for the queue to drain) doesn't fire
until after the workflow arguments are hydrated and the workflow
function has been invoked.

* fix: use setTimeout(0) macrotask for unconsumed check to ensure VM promise propagation completes

The process.nextTick-based unconsumed check was still racing against
VM promise propagation. After promiseQueue resolves and the user code's
resolve() fires, there are multiple microtask hops through the VM
boundary before the workflow code actually calls subscribe() for the
next steps. process.nextTick fires before those VM microtasks complete.

setTimeout(0) is a macrotask that is guaranteed to fire only after ALL
microtasks (including VM promise chain propagation) have drained. The
pendingUnconsumedTimeout handle is stored and cleared in subscribe()
to prevent keeping the event loop alive unnecessarily.

* fix: increase unconsumed event check delay to 100ms for cross-VM promise propagation

setTimeout(0) is insufficient because Node.js does not guarantee that
macrotasks fire after all cross-context (VM boundary) microtasks settle.
After promiseQueue resolves and resolve() fires in the host context,
there are multiple microtask hops through the VM boundary before the
workflow code actually calls subscribe(). A 100ms delay provides
sufficient time for this propagation while still detecting truly
orphaned events promptly.

Also update sleep.test.ts to wait 200ms for the unconsumed check.

* Add browser-compatible AES-GCM to core and HKDF key derivation to world-vercel

* update changeset

* Move HKDF key derivation server-side: API returns per-run derived key

* Refactor encrypt/decrypt to accept CryptoKey, export importKey for callers to import once per run

* Overload getEncryptionKeyForRun: accept context for start(), fetch WorkflowRun in resume-hook

* Split changeset into per-package descriptions for world, world-vercel, and core

* Remove unnecessary Uint8Array.from() wrapper around Buffer.from()

* Use zod to parse Vercel API response

* Wire encryption into serialization layer

* Wire AES-GCM encryption into serialization layer

* update changeset

* Add encryption unit tests: primitives, maybeEncrypt/maybeDecrypt, isEncrypted, complex type round-trips

* Accept CryptoKey in encrypt/decrypt, export importKey for callers to import once per run

* Fix review comments: cache stream encryption key, remove redundant casts, fix stale comments

* Trying to clean up some type non-sense

* fix: restore world-vercel files to main versions

The rebase incorrectly picked up older versions of these files from
early encryption branch commits. The main versions are correct and
up-to-date.

* fix: add type cast for hydrateStepReturnValue return in hook.ts

* fix: address review feedback on encryption PR

- Remove Vercel-specific error message from maybeDecrypt (core should
  not reference VERCEL_DEPLOYMENT_KEY)
- Move stream encryption/decryption from transport layer
  (WorkflowServerReadableStream/WritableStream) to framing layer
  (getSerializeStream/getDeserializeStream). Frame length headers stay
  in the clear so frame boundaries are always parseable regardless of
  transport chunking; encryption wraps the frame payload.
- Remove explicit Promise<unknown> return types from all 4 hydrate
  functions. On main these had inferred types (any from devalue),
  so callers didn't need casts. The encryption branch added explicit
  annotations that broke this.
- Revert unnecessary type casts in run.ts, step-handler.ts, hook.ts
  that were only needed due to the explicit Promise<unknown> annotations
- Revert closureVars type from unknown back to Record<string, any>
  in context-storage.ts to match the contract with getClosureVars
- Fix hydrateWorkflowArguments JSDoc for unused _runId parameter

* Revert more unnecessary changes

* cleanup: remove unused runId param, deduplicate processFrames, add legacy comments

- Remove unused _runId parameter from WorkflowServerReadableStream
  constructor and all 4 call sites
- Deduplicate processFrames decryption: decrypt first and reassign
  format/payload, then fall through to single deserialization path
- Add comments on all legacy non-Uint8Array branches explaining when
  this happens (specVersion 1 runs stored data as plain JSON arrays)
- Fix duplicate code block in hydrateStepReturnValue

* feat: wire cryptoKey through stream serialize/deserialize pipeline

Thread the encryption key through the entire stream serialization chain
so that ReadableStream and WritableStream values are encrypted/decrypted
at the framing level.

- Add optional cryptoKey param to getExternalReducers, getStepReducers,
  getExternalRevivers, getStepRevivers
- Pass cryptoKey to getSerializeStream/getDeserializeStream at all 8
  internal call sites within reducers/revivers
- Thread key from dehydrate/hydrate functions into their reducers/revivers
- Cache encryption key in Run class (resolved once via getEncryptionKey(),
  reused for returnValue, getReadable(), etc.)
- Make Run#getReadable() async to resolve the cached key before creating
  the deserialize stream
- Add encryptionKey to step context storage so getWritable() can access
  it during step execution

* fix: make cryptoKey required-but-nullable to prevent silent omission, add stream encryption tests

Change cryptoKey parameter from optional (cryptoKey?) to required-but-
nullable (cryptoKey: CryptoKey | undefined) on all 6 functions:
- getSerializeStream, getDeserializeStream
- getExternalReducers, getStepReducers
- getExternalRevivers, getStepRevivers

This ensures every call site must explicitly pass the key or undefined,
making it impossible to accidentally omit it and silently skip encryption.

Add 7 stream encryption round-trip tests:
- Encrypted frames have 'encr' prefix inside length header
- Full round-trip: encrypt serialize -> decrypt deserialize
- Concatenated encrypted frames (transport coalescing)
- Split encrypted frames (transport splitting)
- Error when encrypted data encountered without key
- No encryption when key is undefined
- Large payload round-trip

Full audit confirms all encryption key threading is complete:
- All 8 dehydrate/hydrate functions pass key to reducers/revivers
- All stream serialize/deserialize call sites pass key
- Run class caches key for reuse across returnValue and getReadable()
- Step context storage carries key for getWritable()

* fix: keep Run#getReadable() sync, resolve encryption key lazily in streams

- Revert Run#getReadable() to synchronous (non-breaking API).
  The encryption key is passed as a Promise through the chain and
  resolved lazily inside the first async transform() call.
- Add EncryptionKeyParam type alias that accepts CryptoKey, undefined,
  or Promise<CryptoKey | undefined>. Used by getSerializeStream,
  getDeserializeStream, and all reducer/reviver functions.
- Key promises are resolved once on first use via a keyState cache
  object inside each stream's transform closure.
- Fix CLI showStream to resolve encryption key from world when runId
  is provided via --run flag, instead of passing undefined.
- Remove incorrect CLI warning that --run is not supported for streams
  (it is now needed for encrypted stream decryption).

* .

* fix: address review feedback from PR #1251

- Fix 4 broken dehydrateWorkflowArguments calls in workflow.test.ts
  that were passing ops as runId (missing runId and key params)
- Use WorkflowRuntimeError instead of plain Error in decodeFormatPrefix
  for unknown serialization formats, for consistency and programmatic
  error handling
- Document maybeDecrypt throw behavior: callers should be aware this
  surfaces as a rejected promise during key rotation/misconfiguration
- Document key-fetch rejection timing in streams: promise rejection
  won't surface until the first chunk is processed
2026-03-04 12:19:49 -08:00
Vercel Release Bot 09343c1b13 Version Packages (beta) (#1238) 2026-03-03 12:47:33 -08:00
JJ Kasper a9fea9132e Update workbench tests to build and run outside of monorepo (#1230)
* Setup fixes

* ci: run local e2e against staged tarball workbenches

* ci: update staged workbench tarball setup script

* chore: set nextjs workbenches back to next 16.1.6

* update lock

* test(e2e): resolve workbench path from WORKBENCH_APP_PATH

* fix: address deferred builder issues outside monorepo

* ci: stage tarball workbenches only for nextjs local e2e

* fix(next): discover deferred steps imported via workflows

* test(core): gate deferred step-discovery dev test to canary

* test(e2e): cover cross-file imported step in build/start lanes

* fix(e2e): use local manifest in local runs and relax dev rebuild timeout

* fix(workbench): add imported-step workflow symlink for sveltekit/astro

* test(e2e): scope imported-step workflow test to nextjs lanes

* fix(next): rebuild deferred entries on discovered file updates

* fix(next): watch transitive deferred step deps for dev rebuilds

* fix(next): restore socket-driven deferred step rebuilds

* add changeset

* chore: address review feedback on deferred e2e updates

* fix(cli): guard stream flush against closed write streams
2026-03-03 11:17:39 -08:00
Vercel Release Bot a602fcbf6b Version Packages (beta) (#1215) 2026-02-27 14:20:42 -08:00