Skip to content

Bump omercnet/context-mode to 1.2.1 - #160

Open
github-actions[bot] wants to merge 1 commit into
mainfrom
bump/omercnet/context-mode-1.2.1
Open

github-actions[bot] wants to merge 1 commit into
mainfrom
bump/omercnet/context-mode-1.2.1

Conversation

@github-actions

@github-actions github-actions Bot commented Oct 7, 2026

Copy link
Copy Markdown
Contributor

omercnet/context-mode: {"kind":"npm","package":"@omercnet/paseo-context-mode","version":"1.2.0","resolved":"https://registry.npmjs.org/@omercnet/paseo-context-mode/-/paseo-context-mode-1.2.0.tgz","integrity":"sha512-ku7Opzor1TeBAlMK1GXhjgXdwoY9aFhaL4YOQns0LXCL3Wmvc40XPAiE7tKSLYQK5+QwHwUNijO8zlrw1qeD0Q=="} -> {"kind":"npm","package":"@omercnet/paseo-context-mode","version":"1.2.1","resolved":"https://registry.npmjs.org/@omercnet/paseo-context-mode/-/paseo-context-mode-1.2.1.tgz","integrity":"sha512-0OG9MBpboUmv+Ft5/8SlODC/0QBJzrAFLilgbU6BAuBXYagbnn6aBr+cqtUW0r+5E7z2qu04hIGKVHJvXqmXog=="}
Provenance verified: built from https://github.com/omercnet/paseo-plugins/tree/HEAD/context-mode at 8e8dfa1aebbe7c23673f344e75d93dfac91daba9.
Submitted by @omercnet.

Merging approves this version. The published index keeps pointing at the previous one until then.

Artifact diff
diff -ruN a/package/client/analytics-dashboard.tsx b/package/client/analytics-dashboard.tsx
--- a/package/client/analytics-dashboard.tsx	1985-10-26 08:15:00.000000000 +0000
+++ b/package/client/analytics-dashboard.tsx	1985-10-26 08:15:00.000000000 +0000
@@ -122,7 +122,7 @@
         backgroundColor: theme.colors.surface1,
       },
       eyebrow: {
-        color: theme.colors.accent,
+        color: theme.colors.foregroundMuted,
         fontSize: 11,
         fontWeight: "700" as const,
         letterSpacing: 0.7,
diff -ruN a/package/client/screen-scope.ts b/package/client/screen-scope.ts
--- a/package/client/screen-scope.ts	1985-10-26 08:15:00.000000000 +0000
+++ b/package/client/screen-scope.ts	1985-10-26 08:15:00.000000000 +0000
@@ -1,6 +1,8 @@
-import type { PaseoApi } from "@getpaseo/client";
+import type { PluginClientContext } from "@getpaseo/plugin/client";
 import { type ContextModeProvider, ContextModeProviderSchema } from "../shared/knowledge";
 
+type PaseoApi = PluginClientContext["paseo"];
+
 export type SurfaceTab = "savings" | "knowledge" | "setup";
 export type KnowledgeScope = {
   provider: ContextModeProvider | null;
diff -ruN a/package/package.json b/package/package.json
--- a/package/package.json	1985-10-26 08:15:00.000000000 +0000
+++ b/package/package.json	1985-10-26 08:15:00.000000000 +0000
@@ -1,6 +1,6 @@
 {
   "name": "@omercnet/paseo-context-mode",
-  "version": "1.2.0",
+  "version": "1.2.1",
   "type": "module",
   "description": "Provider-aware Context Mode health, savings, and MCP activation for Paseo.",
   "license": "MIT",
@@ -50,10 +50,10 @@
   },
   "devDependencies": {
     "@biomejs/biome": "^2.5.10",
-    "@getpaseo/cli": "0.11.0-beta.3",
-    "@getpaseo/client": "0.11.0-beta.3",
-    "@getpaseo/plugin": "0.11.0-beta.3",
-    "@getpaseo/protocol": "0.11.0-beta.3",
+    "@getpaseo/cli": "0.11.0-beta.5",
+    "@getpaseo/client": "0.11.0-beta.5",
+    "@getpaseo/plugin": "0.11.0-beta.5",
+    "@getpaseo/protocol": "0.11.0-beta.5",
     "@tanstack/react-query": "^5.102.3",
     "@types/node": "^24.10.1",
     "@types/react": "^19.2.18",

This version has no OVERVIEW.md. The registry requires one to update a listing; the bump cannot merge until the repository adds it.

Inline validation failed. See the Bump workflow log.

@github-actions github-actions Bot added the bump Pinned artifact update label Oct 7, 2026

@paseo-bot paseo-bot Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Needs from you: nothing, changes requested

@omercnet, @omercnet/paseo-context-mode 1.2.1 can't merge yet: the package has no OVERVIEW.md, and the registry needs one for every new version.

Change needed: add OVERVIEW.md next to paseo-plugin.json in context-mode/, include it in the published package, and release a new version; the bump workflow opens a fresh pull request for it. Your file replaces the registry copy plugins/omercnet/context-mode.md, which you can start from without its last "imported from paseo.cafe" line. The shape is in REVIEW.md: what it is and does, how it works if needed, setup, then what it reads or sends and known limits, with no installation steps, badges, or changelog.

The code change in 1.2.1 is fine. Nothing else needs to change.

Review data

  • Artifact: npm @omercnet/paseo-context-mode 1.2.1 (from 1.2.0), https://registry.npmjs.org/@omercnet/paseo-context-mode/-/paseo-context-mode-1.2.1.tgz. npm provenance names omercnet/paseo-plugins at 8e8dfa1aebbe7c23673f344e75d93dfac91daba9, built by .github/workflows/release-please.yml on main.
  • Integrity: SHA-512 of both tarballs matches the record (old and new pin), npm's dist.integrity, and the provenance subject digest.
  • Validation: npm test passes (140/140). node scripts/validate.ts --online --changed fails with one error: omercnet/context-mode/OVERVIEW.md is required.
  • Extracted and inspected: both tarballs (31 files each), extracted and diffed locally. client/analytics-dashboard.tsx:125 changes a label colour; client/screen-scope.ts:1-4 takes the PaseoApi type from @getpaseo/plugin/client (type only, no runtime change); package.json changes the version and moves dev @getpaseo/* to 0.11.0-beta.5.
  • Install-time commands: none in the package. paseo-plugin.json has no install or build; package.json has no preinstall, install, postinstall, or prepare. The runtime dependency context-mode declares a postinstall, which does not run because Paseo installs with --ignore-scripts; it is unchanged from 1.2.0.
  • Dependencies: runtime context-mode 1.0.169, the Context Mode MCP server the plugin wraps, unchanged. The monorepo has bun.lock and no npm lockfile: all 1076 registry entries carry sha512 integrity, with no git or tarball sources. This package has no install or build command, so no repository lockfile is used at install; Paseo installs the published package with --ignore-scripts.
  • Hosts: none added; context-mode.com was already present.
  • Credentials and environment: none added; the existing process.env reads in server/binary.ts, server/integration.ts, server/knowledge.ts, server/mcp-process.ts, and server/storage-discovery.ts are unchanged.
  • Filesystem: no change.
  • Execution: none added; the existing spawn that starts Context Mode (server/mcp-process.ts) is unchanged. No eval, new Function, or dynamic import().
  • Runtime installs: none; the Setup tab only shows an install command.
  • Source match: every file is byte-identical to context-mode/ at 8e8dfa1 except package.json, where catalog: specifiers are replaced by the root catalog's versions. Readable TypeScript, nothing bundled.
  • Listing media: screenshot.png and screenshot-compact.png, each HTTP 200 image/png.
  • Overview: missing in the 1.2.1 package and in context-mode/ at 8e8dfa1. The registry copy still describes 1.2.1.
  • Decision: changes requested, because OVERVIEW.md is missing.
  • Reviewed commit: 60755506ccce3d61db7251329a609022f1ce2622

@paseo-bot paseo-bot Bot mentioned this pull request Oct 7, 2026

@paseo-bot paseo-bot Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Context Mode 1.2.1 remains unpublished because its npm artifact does not lock the runtime dependency tree. The earlier request for an artifact OVERVIEW.md is withdrawn: your existing registry overview and screenshots are sufficient, and the client change is acceptable.

Please publish a new version that includes an npm-shrinkwrap.json at the package root, locking context-mode and all transitive runtime dependencies with resolved sources and integrity, then update this PR’s artifact pin. An exact context-mode version alone does not fix its transitive ranges. The monorepo’s bun.lock is absent from the published package and is not consumed by Paseo’s npm installation. This is an existing packaging gap, not a new runtime change in 1.2.1. See REVIEW.md’s packaging requirement and the npm publishing guide.

Optional next release: ship your own OVERVIEW.md to maintain the listing page directly; no overview-only release is needed. Listing-page format.

Review data
  • PR head: 60755506ccce3d61db7251329a609022f1ce2622; REVIEW.md blob: 7268134d240de9e474c52480f4937af4e369a6e2.
  • npm @omercnet/paseo-context-mode@1.2.1, from 1.2.0. Downloaded both pinned tarballs, verified SHA-512 against records and npm metadata, checked paths and independently extracted/compared 31 regular files each. Provenance identifies omercnet/paseo-plugins commit 8e8dfa1aebbe7c23673f344e75d93dfac91daba9.
  • Diff: analytics label colour, a type-only SDK import, package version and dev SDK versions. Server and runtime dependency declarations are unchanged.
  • Installation: manifest has no preparation command and package no lifecycle scripts. Runtime dependency is context-mode@1.0.169; neither tarball contains npm-shrinkwrap.json, package-lock.json or bun.lock. npm metadata for Context Mode declares eight dependencies with ranges, including better-sqlite3 ^12.6.2 and MCP SDK ^1.26.0. No bundled dependency tree is shipped.
  • Existing access checked: PATH/PATHEXT and configured binary lookup (server/binary.ts:93-169); provider config detection and agent-create MCP injection (server/integration.ts:366-414); Context Mode spawned without a shell with provider environment (server/mcp-process.ts:123-129); user-requested indexing/search/fetch/purge (server/knowledge.ts); analytics reads local databases. Setup install/upgrade handlers return commands for display (server/actions.ts:132-164). These serve the described purpose and are unchanged.
  • Scope: package/manifest, complete diff, affected client scope function, entrypoints and relevant binary/integration/MCP/action/knowledge paths. No plugin/dependency code installed, built or run. Dependency internals and lifecycle files were not fully audited because the actual installed tree is not pinned; no security approval is claimed.
  • Registry overview retained unchanged and accurate; both HTTPS PNGs resolve as image/png, dashboard screenshot visually inspected. No registry edits were needed. Trusted current-main online validation was run; its output is retained locally. It does not enforce the dependency lockfile requirement. Not approved or merged. No linked submission issue or author replies found.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bump Pinned artifact update

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants