Skip to content

release: 0.5.68 - #1137

Open
its-miso[bot] wants to merge 1 commit into
mainfrom
release-please--branches--main--components--dispatch
Open

its-miso[bot] wants to merge 1 commit into
mainfrom
release-please--branches--main--components--dispatch

Conversation

@its-miso

@its-miso its-miso Bot commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

🤖 I have created a release beep boop

0.5.68 (2026-10-06)

Features

  • deps: update dependency @modelcontextprotocol/sdk (1.31.0 → 1.32.0) (#1160) (05039a6)
  • deps: update dependency @radix-ui/react-slot (1.3.3 → 1.4.0) (#1185) (73133e7)
  • deps: update dependency eslint (10.11.0 → 10.12.0) (#1161) (ba8217f)
  • deps: update dependency lucide-react (1.48.0 → 1.49.0) (#1139) (278135c)
  • deps: update dependency lucide-react (1.49.0 → 1.50.0) (#1159) (049cf41)
  • deps: update dependency lucide-react (1.50.0 → 1.51.0) (#1170) (9556f61)
  • deps: update dependency lucide-react (1.51.0 → 1.52.0) (#1176) (535520c)
  • deps: update nextjs monorepo (16.3.8 → 16.4.0) (#1187) (890a8fa)
  • pr-fix: accept an explicit already_addressed settlement without a push (#1142) (889e451)
  • tasks/report: accept worker startedAt so AgentRun durations are real (#1120) (#1168) (4d9af7a)

Bug Fixes

  • auth: guard GET /api/automation/repos/[...repo] with authorizeRequest (#1151) (6a9c552)
  • ci: pass --include=optional in audit script so --omit=dev survives .npmrc include=dev (#1162) (#1169) (cca5600)
  • ci: scope the npm audit gate to production dependencies (#1166) (#1172) (f683575)
  • deps: update dependency @modelcontextprotocol/sdk (1.32.0 → 1.32.1) (#1181) (148b435)
  • deps: update dependency @types/node (24.19.0 → 24.19.1) (#1155) (b593d4f)
  • deps: update dependency @vitejs/plugin-react (6.1.1 → 6.1.2) (#1180) (459c52e)
  • deps: update dependency jsdom (30.1.1 → 30.1.2) (#1177) (01b6bad)
  • deps: update nextjs monorepo (16.3.6 → 16.3.7) (#1136) (edc1afb)
  • deps: update nextjs monorepo (16.3.7 → 16.3.8) (#1146) (d6d4db3)
  • deps: update vitest monorepo (5.0.2 → 5.0.3) (#1144) (e1e657e)
  • groomer: align apply-time head precondition with search-rechecked freshness (#1153) (ba5f607), closes #1116
  • groomer: capture repository-context empty searches in the freshness baseline (#1138) (f22dae4)
  • groomer: sanitize provider error text before it reaches GroomingRun.errorMessage (#1157) (#1163) (34f0162)
  • groomer: strip NUL and C0 control chars from model text before validation and persistence (#1156) (05db272)
  • mcp: ship only the runtime closure in the -mcp image (prod deps + tsx layer) (#1175) (752d4a9)
  • pr-fix-queue: pin enqueue post-dispatch append to its keys snapshot (#1134) (#1158) (c9dd382)

Chores


This PR was generated with Release Please. See documentation.

its-saffron[bot]

This comment was marked as outdated.

@its-miso
its-miso Bot force-pushed the release-please--branches--main--components--dispatch branch 2 times, most recently from 624f5bf to f064417 Compare September 30, 2026 02:39
its-saffron[bot]

This comment was marked as outdated.

@its-miso
its-miso Bot force-pushed the release-please--branches--main--components--dispatch branch from f064417 to df0d32f Compare October 1, 2026 00:46
its-saffron[bot]

This comment was marked as outdated.

@its-miso
its-miso Bot force-pushed the release-please--branches--main--components--dispatch branch from df0d32f to 07fc9f1 Compare October 1, 2026 02:31
its-saffron[bot]

This comment was marked as outdated.

@its-miso
its-miso Bot force-pushed the release-please--branches--main--components--dispatch branch 2 times, most recently from 6aeb4ad to 4540f83 Compare October 1, 2026 02:43
its-saffron[bot]

This comment was marked as outdated.

@its-miso
its-miso Bot force-pushed the release-please--branches--main--components--dispatch branch from 4540f83 to 15c6577 Compare October 1, 2026 20:58
its-saffron[bot]

This comment was marked as outdated.

@its-miso
its-miso Bot force-pushed the release-please--branches--main--components--dispatch branch from 15c6577 to 0ae9a96 Compare October 2, 2026 02:39
its-saffron[bot]

This comment was marked as outdated.

@its-miso
its-miso Bot force-pushed the release-please--branches--main--components--dispatch branch from 0ae9a96 to e3306f7 Compare October 2, 2026 02:45
its-saffron[bot]

This comment was marked as outdated.

@its-miso
its-miso Bot force-pushed the release-please--branches--main--components--dispatch branch from e3306f7 to 1822662 Compare October 2, 2026 12:21
its-saffron[bot]

This comment was marked as outdated.

@its-miso
its-miso Bot force-pushed the release-please--branches--main--components--dispatch branch from 1822662 to bdc50e8 Compare October 2, 2026 12:27
its-saffron[bot]

This comment was marked as outdated.

@its-miso
its-miso Bot force-pushed the release-please--branches--main--components--dispatch branch 2 times, most recently from 20006f0 to c53650d Compare October 3, 2026 02:24
its-saffron[bot]

This comment was marked as outdated.

its-saffron[bot]

This comment was marked as outdated.

@its-miso
its-miso Bot force-pushed the release-please--branches--main--components--dispatch branch from a6cd844 to a1b1017 Compare October 3, 2026 03:35
its-saffron[bot]

This comment was marked as outdated.

@its-miso
its-miso Bot force-pushed the release-please--branches--main--components--dispatch branch from a1b1017 to 8a824e3 Compare October 3, 2026 19:51
its-saffron[bot]

This comment was marked as outdated.

@its-miso
its-miso Bot force-pushed the release-please--branches--main--components--dispatch branch from 8a824e3 to b74bad4 Compare October 3, 2026 20:58
its-saffron[bot]

This comment was marked as outdated.

@its-miso
its-miso Bot force-pushed the release-please--branches--main--components--dispatch branch from b74bad4 to cf6bc11 Compare October 4, 2026 14:13
its-saffron[bot]

This comment was marked as outdated.

@its-miso
its-miso Bot force-pushed the release-please--branches--main--components--dispatch branch from cf6bc11 to e51aa5a Compare October 4, 2026 19:15
its-saffron[bot]

This comment was marked as outdated.

@its-miso
its-miso Bot force-pushed the release-please--branches--main--components--dispatch branch from e51aa5a to 694a1c4 Compare October 4, 2026 19:21
its-saffron[bot]

This comment was marked as outdated.

@its-miso
its-miso Bot force-pushed the release-please--branches--main--components--dispatch branch from 694a1c4 to 73de541 Compare October 4, 2026 21:02
its-saffron[bot]

This comment was marked as outdated.

@its-miso
its-miso Bot force-pushed the release-please--branches--main--components--dispatch branch from 73de541 to c19d2dd Compare October 5, 2026 04:26
its-saffron[bot]

This comment was marked as outdated.

@its-miso
its-miso Bot force-pushed the release-please--branches--main--components--dispatch branch 2 times, most recently from 9168ce1 to 0c3774f Compare October 5, 2026 12:26
its-saffron[bot]

This comment was marked as outdated.

@its-miso
its-miso Bot force-pushed the release-please--branches--main--components--dispatch branch from 0c3774f to de6cf6c Compare October 6, 2026 02:38
its-saffron[bot]

This comment was marked as outdated.

@its-miso
its-miso Bot force-pushed the release-please--branches--main--components--dispatch branch from de6cf6c to b7774f0 Compare October 6, 2026 20:02
@its-saffron
its-saffron Bot dismissed their stale review October 6, 2026 20:05

Superseded by a newer automated review for this pull request.

@its-saffron its-saffron Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

AI Automated Review

Full PR review.

Analysis engine: MiniMax-M3 (anthropic) — primary route · pr-reviewer-action v3.3.0

Partial coverage: required-check coverage is incomplete — this review did not resolve every required check and must not be read as a complete pass.

Findings (1 blocker, 1 info)

Severity Location Finding
🛑 Blocker CI is failing: `npm audit` reached a terminal failure state on head b7774f0, and five other checks (Docker Build, Docker Build (MCP), Database integration, Database migrations, Tests, Coverage, Smoke) are still pending — the release cannot be merged into main with red CI per the project's lint/typec
Info charts/dispatch/Chart.yaml Both `version` and `appVersion` are `0.5.68` and the lockfile-root version, `.release-please-manifest.json`, and `package.json` are all `0.5.68`; CHANGELOG is the only file still referencing `0.5.67` and those references are the historical compare URLs and the prior release header — expected and cor

Recommendation

Request changes: this release-please bump is internally consistent on version uniformity and the new behavior is real on disk, but the CI surface is currently red (npm audit failure, plus five checks still pending). Per AGENTS.md the lint/typecheck gate must pass; here npm audit is the equivalent hard CI gate and it is failing. The PR should not merge into main while CI is red, regardless of whether the version-bump diff itself is correct.

Version-bump diff itself: clean. All five Claims-to-Falsify points are satisfied by direct file reads; no source-level defect found in the changed code. The blocker is the CI status, not the release content.

Change-by-change findings

  • .release-please-manifest.json, package.json, package-lock.json, charts/dispatch/Chart.yaml: version string uniformly bumped from 0.5.67 to 0.5.68. Repository impact scan confirms 0.5.67 now appears only inside CHANGELOG.md (lines 3 and 44 — historical compare URLs and the prior release header, both expected). Chart version and appVersion both equal 0.5.68.
  • CHANGELOG.md: 41-line block for the 0.5.68 release dated 2026-10-06. Headings and per-feature / per-fix categorization follow the established pattern from prior entries.
  • Behavioral items credited in the changelog (sampled):
    • groomer: strip NUL and C0 control chars from model text before validation and persistence (PR 1156) — src/lib/groomer/sanitize.ts exposes sanitizeModelText (regex [�-��-�]) plus sanitizeModelJson for trees; src/lib/groomer/model-stage.ts:114 invokes sanitizeModelJson(rawAnswer) once before validate(output), and runModelStage at lines 89–94 wraps rawOutput/errors/warnings through sanitizeJsonForStorage / sanitizeForStorage. The Comment body path (src/lib/groomer/mutation-applier.ts) and the exploration tool-arg path (src/lib/groomer/explore.ts:147) both flow through the same sanitizer; src/lib/groomer/llm.ts:326 and :52 sanitize the provider error body before it reaches GroomingRun.errorMessage. Claim 1 holds across all sibling persistence paths I could inspect.
    • mcp: ship only the runtime closure in the -mcp image (prod deps + tsx layer) (PR 1175) — Dockerfile mcp-deps stage explicitly omits .npmrc (to defeat include=dev), rewrites this layer's package.json to move tsx into dependencies and delete devDependencies, then runs npm install --no-save --no-audit --no-fund. The mcp stage copies node_modules and the rewritten package.json from mcp-deps only and never touches deps; it ships only src/mcp/server.ts plus the three imported lib files. Dockerfile.test.ts:90–117 asserts both stages against this contract. Claim 2 holds and is regression-tested.

Sources

  • .release-please-manifest.json (0.5.68)
  • package.json (0.5.68)
  • package-lock.json (0.5.68 at both root and packages."".version)
  • charts/dispatch/Chart.yaml (version: 0.5.68, appVersion: 0.5.68)
  • CHANGELOG.md (0.5.68 entry lines 3–43)
  • Dockerfile mcp-deps and mcp stages
  • Dockerfile.test.ts MCP-image regression block
  • src/lib/groomer/sanitize.ts, model-stage.ts, explore.ts, llm.ts, mutation-applier.ts
  • CI status API for head b7774f0 (lint/build/typecheck/workflow-lint green; package red; docker-build / docker-build-mcp / database-integration / database-migrations / tests / coverage / smoke pending)

Standards Compliance

AGENTS.md calls out "Lint/typecheck blocks CI; must pass." That requirement is satisfied for the typecheck/lint slice of CI. AGENTS.md does not name npm audit explicitly, but the repo's package.json script is wired with --audit-level=high and the changelog itself credits two CI fixes (PR 1166/PR 1172, PR 1162/PR 1169) that scope and gate the audit — so the audit is part of the project-asserted release-quality bar. The npm audit check is failing for this head.

AGENTS.md also says "Tokens are secrets. DISPATCH_AGENT_TOKEN and GITHUB_TOKEN must never be logged, echoed, or persisted to disk." The release-please diff touches only manifests and the changelog — no token-shaped strings appear in the diff. Satisfied.

Tool Harness Findings

18 tool calls were issued; results used to read the five changed files, the groomer sanitize pipeline, the Dockerfile mcp-deps / mcp stages, the Dockerfile.test.ts MCP regression block, and the existing package-overrides.test.ts header. No fetch returned a REDACTED marker. No tool result was empty or failing in a way that left a needed claim unverrified.

Unknowns or Needs Verification

  • The exact npm-audit advisory ids and dependency paths driving the CI failure are not in the corpus — the harness shows the check reached a terminal failure state but the body of the audit report is truncated. Five CI checks (docker-build, docker-build-mcp, database-integration, database-migrations, tests, coverage, smoke) are still pending and so cannot be confirmed green at the head. Re-run CI after addressing the audit gate before merge.
  • Whether the running npm audit baseline at main (the prior green state) was the same as the baseline this branch now reports against — i.e. whether the audit failure is newly introduced by the dependency bumps in this release or was already failing on main — is not shown by the corpus. This affects whether the right fix is "block the merge until the audit is triaged" vs "acknowledge a pre-existing audit failure and remediate in a follow-up"; the PR classification does not flag this.

Claims-to-Falsify summary

  • Claim 1 (groomer NUL/C0 strip): held across inspected sites (model-stage pre-validation, post-validation storage, exploration tool args, provider error body, comment body via mutation-applier). 5/5 inspected sites confirmed.
  • Claim 2 (MCP runtime closure only): held. Dockerfile mcp-deps rewrites the layer-local package.json (devDependencies removed, tsx moved into dependencies) and mcp stage copies only from mcp-deps; regression test Dockerfile.test.ts asserts the contract.
  • Claim 3 (CHANGELOG entry exists): held. CHANGELOG.md:3 is the new ## [0.5.68] heading.
  • Claim 4 (uniform 0.5.68 across all version-bearing manifests): held for the 6 listed items; no remaining 0.5.67 outside the historical CHANGELOG entries.
  • Claim 5 (Helm version and appVersion in lockstep at 0.5.68): held. Both fields read 0.5.68.

Unaddressed required checks

The classifier marked these checks as required for this PR's risk profile, but the review does not resolve or disposition them:

  • run full test suite after upgrade

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

groomer: align apply-time head precondition with search-rechecked freshness

0 participants