07dccbe2bda8358290c5116da2a99c07b36bbb0b
13179 Commits
| Author | SHA1 | Message | Date | |
|---|---|---|---|---|
|
|
07dccbe2bd |
FN-8783: parallelize static merge-gate validators
Run independent static merge-gate policy validators concurrently without weakening gate ordering. - Add a fail-closed concurrent static-validator runner with coverage for inventory and failures. - Preserve curated engine, PostgreSQL, unit, and CI-shape gate contracts. - Document the gate composition and warm-cache performance policy. Files changed: docs/testing.md | 13 ++- package.json | 3 +- packages/cli/src/__tests__/ci-workflow.test.ts | 21 ++-- packages/engine/vitest.config.ts | 36 +++++-- .../__tests__/engine-vitest-gate-policy.test.mjs | 90 +++++++++++++---- scripts/__tests__/run-static-gate-checks.test.mjs | 100 +++++++++++++++++++ scripts/run-static-gate-checks.mjs | 106 +++++++++++++++++++++ 7 files changed, 332 insertions(+), 37 deletions(-) Fusion-Task-Id: FN-8783 Fusion-Task-Lineage: d5d3c9e1-b3c4-45ff-a3e7-f9555585cd70 Co-authored-by: Fusion (runfusion.ai) <noreply@runfusion.ai> |
||
|
|
9e4a0817db |
feat: restart the development engine on source changes (#3329)
## Summary Add an opt-in source-development loop that restarts the dashboard and engine when runtime TypeScript or JSON changes. Use `pnpm dev:watch`; `pnpm dev:hmr` now combines Vite UI HMR with the same supervised API/engine restart path. The watcher filters tests, fixtures, generated declarations, build output, and task state. It coalesces bursts with a two-second maximum wait, waits for the child to acknowledge its IPC listener, and rebuilds runtime dist artifacts before a source-triggered respawn. ## Safety model - Close scheduler, triage, heartbeat, mission, routine, self-healing, and merge admission before checking for active work. - Let already-running agents reach a safe boundary; do not mutate durable pause settings. - Enter the existing graceful exit-code-86 shutdown and supervised respawn path. - Retry failed liveness reads and declined restart requests instead of dropping the pending change. - Keep ordinary `pnpm dev` behavior unchanged; inherited watch state does not break nested non-dashboard development commands. A development restart intentionally replaces the dashboard process, so transient dashboard connections and project dev-server children reconnect or restart with it. Agent work is the protected boundary. ## Validation - `pnpm lint` - `pnpm test:gate` (753 tests passed across engine, core, PostgreSQL gate, and CI-shape suites) - Focused CLI watcher/restart/supervision suites: 40 tests passed - Focused engine drain/manager suites: 52 tests passed - `pnpm --filter @runfusion/fusion typecheck` - `pnpm --filter @fusion/engine typecheck` - `pnpm verify:fast` (13 steps passed, including CLI build and real health boot smoke) - Manual unsupported-command probe confirms explicit `--watch` fails clearly outside the dashboard command ## Post-Deploy Monitoring & Validation - Watch for `[fusion:dev] source changed`, `source restart deferred`, `active work drained`, and `restart requested` logs during the first watched development session. - Healthy behavior is one exit-86 respawn per edit batch, no interrupted active agents, refreshed dist artifacts, and a healthy dashboard after respawn. - Investigate repeated restart loops, watcher attachment warnings, declined restart retries, or liveness-read failures. - Immediate mitigation is to use ordinary `pnpm dev` without `--watch`; no production runtime behavior or durable setting needs rollback. - Validation owner: Fusion maintainers during the first source edit after merge. --- [](https://github.com/EveryInc/compound-engineering-plugin) <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added `pnpm dev:watch` to automatically restart development runtime processes when source files change. * Development restarts now wait for active work to finish, preventing new work from starting during the transition. * Enhanced `pnpm dev:hmr` with graceful runtime source restarts while keeping the dashboard available. * Rapid source changes are grouped to avoid unnecessary restarts. * **Documentation** * Updated development setup and contribution guides with the new watch workflow. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
b00d8adaeb |
test(engine): fix moved skill resolver fixture import (#3328)
## Summary - update the CE workflow-step fixture runtime import to the moved `cli-runtime/skill-resolver.js` path - align the runtime specifier with the existing type-only import ## Test plan - `pnpm --filter @fusion/engine exec vitest run --project=engine-default src/__tests__/ce-workflow-step-executor.test.ts --silent=passed-only --reporter=dot --maxWorkers=1 --no-file-parallelism` (52 passed) - `pnpm --filter @fusion/engine typecheck` - `pnpm check:changesets` <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Tests** * Updated test configuration to reference the correct skill resolver location. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
be3799e7a3 |
FN-8782: stabilize TaskDetailModal rendering tests
Cover TaskDetailModal definition refresh behavior with reliable Promise-backed API mocks. - Reset detail fetch mocks to preserve the production Promise contract - Test refreshed markdown file links, rejected refreshes, visibility polling, and stale response fencing - Update optimistic detail expectations for authoritative Definition refreshes Files changed: .../__tests__/TaskDetailModal.rendering.test.tsx | 200 +++++++++++++++++++-- .../__tests__/TaskDetailModal.test-helpers.ts | 17 +- 2 files changed, 197 insertions(+), 20 deletions(-) Fusion-Task-Id: FN-8782 Fusion-Task-Lineage: 302a7d58-c014-473b-97f0-8751b510169c Co-authored-by: Fusion (runfusion.ai) <noreply@runfusion.ai> |
||
|
|
993a2f9d86 |
chore(release): v0.75.0-beta.1
Version bump via changesets. |
||
|
|
3cc1d9373f |
FN-8780: expand Activity thinking blocks by default
Make Task Detail Activity reasoning immediately readable in every workflow column. - Default newly mounted thinking segments to expanded state - Preserve user collapse choices while streamed reasoning updates - Add coverage for default, toggle, and streaming behavior Files changed: .changeset/fn-8780-activity-thinking-open.md | 7 ++ packages/dashboard/app/components/TaskChatTab.tsx | 25 ++----- .../app/components/__tests__/TaskChatTab.test.tsx | 79 +++++++++------------- 3 files changed, 45 insertions(+), 66 deletions(-) Fusion-Task-Id: FN-8780 Fusion-Task-Lineage: 51a0be0d-0bc8-4e1f-ac1d-b30583d7b202 Co-authored-by: Fusion (runfusion.ai) <noreply@runfusion.ai> |
||
|
|
7b1c8db1d3 |
FN-8779: keep Activity Feed scrolling above footer
Keep Feed history scrollable within Task Detail while the action footer remains fixed. - Add a Feed-specific flex and overflow layout for Activity history. - Keep Task Detail footer and modal controls outside the scrolling body. - Cover Feed footer containment and responsive layout behavior. Files changed: packages/dashboard/app/components/TaskDetailModal.css | 38 +++++++++++++-- packages/dashboard/app/components/TaskDetailModal.tsx | 12 ++--- ...etailModal.responsive-and-dependencies.test.tsx | 46 ++++++++++++++++++ .../TaskDetailModal.task-activity-chat.test.tsx | 54 ++++++++++++++++++++++ 4 files changed, 139 insertions(+), 11 deletions(-) Fusion-Task-Id: FN-8779 Fusion-Task-Lineage: 4bc4851c-27a1-4b45-afdb-11ccbc8a017e Co-authored-by: Fusion (runfusion.ai) <noreply@runfusion.ai> |
||
|
|
ad2cb6958e |
FN-8778: reconcile task state on board re-entry
Keep Board and List task data current after users return from views without SSE. - Refresh task data on every genuine false-to-true task-view transition - Coalesce concurrent project switches with re-entry refreshes - Cover server-state reconciliation, empty snapshots, and late responses Files changed: .../dashboard/app/hooks/__tests__/useTasks.test.ts | 87 ++++++++++------------ packages/dashboard/app/hooks/useTasks.ts | 45 ++++------- 2 files changed, 55 insertions(+), 77 deletions(-) Fusion-Task-Id: FN-8778 Fusion-Task-Lineage: 8123b24a-9228-46cc-a382-19c91aa72e73 Co-authored-by: Fusion (runfusion.ai) <noreply@runfusion.ai> |
||
|
|
c10a880fc9 |
FN-8777: scope voice dictation to selected projects
Keep voice dictation sessions and requests isolated to the active dashboard project. - Append the encoded project ID to voice status, session, transcription, and cleanup requests. - Add real-route and composer coverage for scoped sessions and project changes. - Document the project boundary and add a patch changeset. Files changed: .changeset/fn-8777-voice-entry-e2e.md | 7 + docs/dashboard-guide.md | 5 + .../__tests__/voice-dictation-composers.test.tsx | 19 ++- .../app/hooks/__tests__/useVoiceDictation.test.tsx | 149 ++++++++++++++++++++- packages/dashboard/app/hooks/useVoiceDictation.ts | 44 ++++-- .../routes/__tests__/register-voice-routes.test.ts | 28 ++++ 6 files changed, 238 insertions(+), 14 deletions(-) Fusion-Task-Id: FN-8777 Fusion-Task-Lineage: 65390f79-3e29-4759-88c6-275b1c9f17d4 Co-authored-by: Fusion (runfusion.ai) <noreply@runfusion.ai> |
||
|
|
f344715df5 | docs: describe planning and review prompt fixes | ||
|
|
dd2cb0c8ba |
fix(FN-8778): preserve planning lock receiver
Fusion-Task-Id: FN-8778 |
||
|
|
9939897aab |
fix: prevent stale planning approvals and review churn (#3327)
## Summary Planning can no longer approve or execute against evidence from a superseded dependency episode. Dependency mutations, approval decisions, recovery, and execution admission now share serialized lifecycle rules, so stale planner work cannot restore an invalid approval or release an unplanned task. Review also converges instead of discovering one blocker per round. Planning performs a repository-grounded completeness pass up front; Plan Review batches all independently discoverable blockers and carries an episode-scoped decision ledger across revisions; code review traces changed invariants through production consumers and tests. Repeated feedback still advances the safety budget, while provider failures and superseded episodes stay outside the remediation ledger. The dashboard now exposes manual approval only for the intended exhausted-review state, and refusal/recovery audit events make rejected lifecycle transitions diagnosable without leaking prompt content. ## Validation - `pnpm verify:fast` — scoped typechecks/builds, CLI build, and boot smoke passed. - Focused Core and Engine regression suites — 511 tests passed. - `pnpm lint`, strict changeset validation, Core/Engine typechecks, and package builds passed. Fixes #3325. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Improved Plan Review approvals, rejections, and replan-cap handling across task workflows. * Added cumulative feedback and attempt tracking across repeated planning reviews. * Added safer recovery for stalled planning handoffs and interrupted approval updates. * **Bug Fixes** * Prevented stale approvals and unplanned execution after dependency changes. * Improved concurrent approval handling, retryability, and refusal-record deduplication. * Refined dashboard approval indicators and responsive approval views. * **Quality Improvements** * Strengthened planning and code-review completeness checks and blocking-finding coverage. * Preserved review history while clearly marking outdated approvals. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
e3cf0d6dc5 |
FN-8776: complete planning route test mocks
Complete planning route mocks so GitHub tracking tests exercise the production create-task contract. - Add epoch-advance mock coverage for repeated and stale task creation. - Add task-handoff formatting mock coverage to prevent HTTP 500 regressions. Files changed: .../dashboard/src/__tests__/routes-planning-tracking.test.ts | 10 +++++++--- 1 file changed, 7 insertions(+), 3 deletions(-) Fusion-Task-Id: FN-8776 Fusion-Task-Lineage: efa8cf96-ebba-4085-b3fe-d34cd1d4e04f Co-authored-by: Fusion (runfusion.ai) <noreply@runfusion.ai> |
||
|
|
2249b9bc20 |
FN-8774: retain Kimi K3 quarantine through deadline
Keep the Kimi K3 dashboard route test quarantined until the mandated deletion date. - Preserve the /api/models supplemental test and paired Vitest exclusion through 2026-08-15. - Record the explicit retention deadline in the quarantine ledger. Files changed: packages/dashboard/vitest.config.ts | 5 +++++ scripts/lib/test-quarantine.json | 2 +- 2 files changed, 6 insertions(+), 1 deletion(-) Fusion-Task-Id: FN-8774 Fusion-Task-Lineage: 8ef704e4-f682-4a97-af1a-2070ca43d8a1 Co-authored-by: Fusion (runfusion.ai) <noreply@runfusion.ai> |
||
|
|
3b2c6f4c12 |
FN-8772: refresh W32 test-velocity baseline
Refresh the weekly test-velocity baseline with the latest measurements. - Record current gate, boot-smoke, and changed-only test timings - Update slowest-test attribution and quarantine counts - Append the captured snapshot to the velocity history Files changed: docs/test-velocity-baseline.md | 67 +++++++++++----------- scripts/test-velocity-history.json | 112 +++++++++++++++++++++++++++++++++++++ 2 files changed, 145 insertions(+), 34 deletions(-) Fusion-Task-Id: FN-8772 Fusion-Task-Lineage: 84d73aef-f0ca-4322-a21b-447f230bb203 Co-authored-by: Fusion (runfusion.ai) <noreply@runfusion.ai> |
||
|
|
bb17baaacf |
FN-8768: recover planning handoffs after dependency reseeds
Prevent dependency reseeds from leaving completed planning work without a dispatchable continuation. - Serialize dependency invalidation with workflow claims and retire only pending continuations. - Persist dispatch-deduplication state and recover legacy reseeded planning handoffs safely. - Add PostgreSQL migration, integration coverage, architecture guidance, and a patch changeset. Files changed: .changeset/fn-8768-planning-reseed.md | 7 ++ docs/architecture.md | 10 +- .../core/src/__test-utils__/pg-test-harness.ts | 8 ++ .../__tests__/postgres/backend-resolver.test.ts | 5 + .../src/__tests__/postgres/schema-applier.test.ts | 17 ++- .../postgres/task-dependency-mutation.pg.test.ts | 42 ++++++- .../__tests__/task-update-lanes-resolved.test.ts | 20 +++- packages/core/src/postgres/advisory-locks.ts | 122 +++++++++++++++++++++ packages/core/src/postgres/backend-resolver.ts | 13 ++- packages/core/src/postgres/data-layer.ts | 4 + packages/core/src/postgres/embedded-lifecycle.ts | 6 + .../migrations/0043_fn8768_dispatch_dedupe.sql | 17 +++ packages/core/src/postgres/schema-applier.ts | 13 ++- packages/core/src/postgres/schema/project.ts | 15 +++ packages/core/src/store.ts | 56 +++++++++- packages/core/src/task-store/audit-ops.ts | 49 +++++++++ .../core/src/task-store/branch-and-pr-entities.ts | 30 +++++ packages/core/src/task-store/project-store-ops.ts | 55 ++++++++-- packages/core/src/task-store/task-update.ts | 30 ++++- packages/core/src/task-store/update-task-deps.ts | 30 ++++- packages/engine/src/__tests__/triage.test.ts | 66 ++++++++++- packages/engine/src/execution/hold-release.ts | 45 ++++++++ packages/engine/src/scheduler.ts | 3 +- packages/engine/src/triage.ts | 87 ++++++++++++++- 24 files changed, 713 insertions(+), 37 deletions(-) Fusion-Task-Id: FN-8768 Fusion-Task-Lineage: 539ef649-5a13-4eaa-a695-bc68370fed22 Co-authored-by: Fusion (runfusion.ai) <noreply@runfusion.ai> |
||
|
|
9dc7b94c17 |
fix(FN-8768): resume manually approved plans
Persist exhausted Plan Review approval as audited terminal evidence and wake scheduler and deferred continuations immediately. Fusion-Task-Id: FN-8768 |
||
|
|
4f9f5e4276 |
test(FN-perf): convert research-dispatcher polling test to fake timers
Replace ~200ms of real-time sleep() waits with deterministic fake-timer advances. The dispatcher clamps tickIntervalMs to a 100ms floor, so the old 30-40ms real sleeps never fired a second interval tick — the double-dispatch and stop-cancels-timer cases now genuinely exercise a follow-up tick, making them both faster and stronger. Fusion-Task-Id: FN-perf |
||
|
|
b7d9cbf186 |
FN-8771: fix PostgreSQL workflow fixture import
Use the canonical workflow module in PostgreSQL mission-store fixture coverage. - Import the built-in coding workflow IR from its dedicated workflow module. - Document the schema/workflow API boundary for renamed-lane coverage. Files changed: packages/core/src/__tests__/postgres/mission-store.pg.test.ts | 8 +++++++- 1 file changed, 7 insertions(+), 1 deletion(-) Fusion-Task-Id: FN-8771 Fusion-Task-Lineage: d287a0fa-5d79-4784-8576-cc6b3d788258 Co-authored-by: Fusion (runfusion.ai) <noreply@runfusion.ai> |
||
|
|
7824150715 |
FN-8769: protect default-branch mission merges
Keep mission group members behind manual release controls when their target is the default branch. - Create deterministic intermediate branches for project-default mission groups. - Gate default-branch group routing and auto-merge exemptions behind the normal manual-release flow. - Cover intermediate and default-branch group behavior with core and engine tests. Files changed: ...fn-8769-default-branch-group-auto-merge-gate.md | 7 ++ docs/architecture.md | 2 +- docs/missions.md | 2 +- .../mission-store.sync-auto-merge.test.ts | 4 +- packages/core/src/__tests__/task-merge.test.ts | 16 ++- .../core/src/async-stores/async-mission-store.ts | 12 ++- packages/core/src/merge/task-merge.ts | 23 +++- packages/core/src/missions/mission-store.ts | 11 +- ...cutor-live-branch-group-auto-merge-hold.test.ts | 16 ++- .../src/__tests__/group-merge-coordinator.test.ts | 118 ++++++++++++++++++++- .../engine/src/__tests__/project-engine.test.ts | 16 ++- packages/engine/src/executor.ts | 4 +- .../engine/src/merge/group-merge-coordinator.ts | 13 +++ packages/engine/src/project-engine.ts | 15 ++- 14 files changed, 235 insertions(+), 24 deletions(-) Fusion-Task-Id: FN-8769 Fusion-Task-Lineage: dff96c8e-ca96-437c-94bf-9691bdf572e9 Co-authored-by: Fusion (runfusion.ai) <noreply@runfusion.ai> |
||
|
|
0d492f9056 |
FN-8770: consolidate task display sorting
Centralize workflow column sorting in core and remove the duplicate dashboard implementation. - Export shared display-column sort options and complete-column modes from core. - Route board, lane, list, and column consumers through the shared sorter. - Harden inert flag seam checks for same-named module functions. Files changed: .../display-ranking-roles-resolved.test.ts | 6 +- packages/core/src/__tests__/task-priority.test.ts | 63 +++++++ packages/core/src/index.gate.ts | 2 + packages/core/src/index.ts | 2 + packages/core/src/tasks/task-priority.ts | 87 +++++---- packages/core/src/types.ts | 9 + packages/dashboard/app/components/Board.tsx | 45 +---- packages/dashboard/app/components/Column.tsx | 4 +- packages/dashboard/app/components/Lane.tsx | 34 +--- packages/dashboard/app/components/ListView.tsx | 19 +- .../app/components/__tests__/Lane.test.tsx | 8 +- .../app/components/__tests__/taskSorting.test.ts | 201 --------------------- packages/dashboard/app/components/taskSorting.ts | 138 -------------- scripts/__tests__/check-inert-flag-seams.test.mjs | 4 +- scripts/check-inert-flag-seams.mjs | 83 +++------ 15 files changed, 177 insertions(+), 528 deletions(-) Fusion-Task-Id: FN-8770 Fusion-Task-Lineage: 81740c52-0a3c-44df-9fbb-addaefdfeb82 Co-authored-by: Fusion (runfusion.ai) <noreply@runfusion.ai> |
||
|
|
77c698a249 |
chore(release): v0.75.0-beta.0
Version bump via changesets. |
||
|
|
338caa89b7 |
FN-8767: strengthen dependency-link test assertions
Strengthen TaskDetailModal dependency-link coverage with scoped fetch and navigation assertions. - Verify dependency requests retain project scope after the initial modal load. - Cover successful, failed, keyboard-activated, and removal-click dependency interactions. Files changed: ...etailModal.responsive-and-dependencies.test.tsx | 108 +++++++++++++++------ 1 file changed, 81 insertions(+), 27 deletions(-) Fusion-Task-Id: FN-8767 Fusion-Task-Lineage: 656b40de-2e20-481b-b23e-51fa786b05b6 Co-authored-by: Fusion (runfusion.ai) <noreply@runfusion.ai> |
||
|
|
fef9692cba |
FN-8766: align task detail popup inset
Align the desktop Task Detail popup header and content edges without losing resize access. - Remove the Task Detail desktop body gutter while preserving shared scrollbar clearance. - Move Task Detail east resize targets outside the painted shell and retain mobile clipping. - Add geometry regression coverage and a patch changeset. Files changed: .changeset/fn-8766-task-detail-popup-spacing.md | 7 +++ .../dashboard/app/components/FloatingWindow.css | 30 +++++++++++ .../components/__tests__/FloatingWindow.test.tsx | 32 +++++++----- ...etailModal.responsive-and-dependencies.test.tsx | 58 ++++++++++++++++++++++ 4 files changed, 115 insertions(+), 12 deletions(-) Fusion-Task-Id: FN-8766 Fusion-Task-Lineage: b4d23a5e-51d0-45cb-8cbb-4fefb81fa09f Co-authored-by: Fusion (runfusion.ai) <noreply@runfusion.ai> |
||
|
|
c8ff721362 |
fix: release manually approved plans (#3323)
## Summary Approving or rejecting a plan now releases the task instead of leaving it permanently blocked as `awaiting-approval`. The workflow routes use the task store's durable clear semantics, and approval records the current plan fingerprint while safely clearing a stale fingerprint when the plan cannot be read. Real PostgreSQL route coverage proves both actions clear the scheduler hold and persist the expected fingerprint state. Fixes #3322. ## Validation - `pnpm --filter @fusion/dashboard exec vitest run src/__tests__/plan-approval-status.pg.test.ts --silent=passed-only --reporter=dot` - `pnpm --filter @fusion/dashboard exec vitest run src/__tests__/routes-github.test.ts --silent=passed-only --reporter=dot -t 'POST /tasks/:id/(approve-plan|reject-plan)'` - `pnpm --filter @fusion/core exec vitest run src/__tests__/task-update-awaiting-approval-reason.test.ts --silent=passed-only --reporter=dot` - Core and dashboard typechecks - Scoped ESLint and strict changeset validation --- [](https://github.com/EveryInc/compound-engineering-plugin) <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Manually approved plans now resume correctly in their workflow. * Rejected plans are fully cleared, preventing stale approval information from affecting future decisions. * Approval records accurately reflect the latest plan, including when plan details are unavailable. * Failed cleanup keeps rejected plans from being released prematurely. * **Tests** * Added coverage for approval and rejection persistence, workflow state, and cleanup failures. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
56819e21e9 | fix: restore plugin SDK and Todo packaging | ||
|
|
78543233aa |
fix(planning): allow repeated task creation
Advance the durable creation epoch for each explicit Planning Mode action while preserving idempotency for transport retries. Recover soft-deleted task links with a fresh claim key and cover live, deleted, and retry paths. |
||
|
|
5d8d494230 |
fix(todos): restore clean build and navigation coverage (#3321)
## Summary - remove an unavailable jest-dom type from the Todo plugin production TypeScript build - update the dashboard navigation fixture for the plugin-owned Todo destination and root test id ## Test plan - `corepack pnpm --filter @fusion-plugin-examples/todos build` - `corepack pnpm --filter @fusion-plugin-examples/todos test` - `FUSION_DASHBOARD_DEEP=1 corepack pnpm --filter @fusion/dashboard exec vitest run app/components/__tests__/navigation-history.test.tsx --project dashboard-app-quality-components-a --silent=passed-only --reporter=dot` - `corepack pnpm check:changesets` <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Restored CLI packaging for the bundled Todo Lists plugin. * Made `AgentStore` available to bundled plugins at runtime. * **Tests** * Updated navigation coverage for Todo Lists dashboard views, overflow placement, and ordering. * Added coverage for opening and dismissing the Todo view through browser history navigation. * Improved validation of runtime exports. * **Chores** * Simplified test type configuration for the Todo Lists plugin. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
4ff41a723c |
fix: self-heal executor credential resolution for custom providers
Stop synthesizing credentialInstanceId "default" into executor sessions, soft-fail unresolved instances to the legacy unscoped auth path, and collapse-match renamed custom-provider auth slugs so task execute matches chat. |
||
|
|
19f6456821 | fix(FN-8762): restore Todos plugin build | ||
|
|
5b2b31d2c9 |
FN-8762: extract Todo Lists into bundled plugin
Move Todo Lists into a bundled, project-enabled plugin package. - Move Todo UI, client API, and server routes into the plugin package. - Register and bundle Todo as an enabled plugin dashboard view rather than a static host feature. - Preserve Todo route validation and server-error semantics, including task assignment agent lookup. - Keep disabled and legacy Todo views out of project navigation and main content. Files changed: .changeset/fn-8762-todos-plugin.md | 7 + AGENTS.md | 3 +- docs/PLUGIN_AUTHORING.md | 4 + docs/dashboard-guide.md | 4 + docs/todo-view.md | 151 +---- .../cli/src/plugins/staged-bundled-plugin-ids.ts | 1 + packages/cli/tsup.config.ts | 8 + .../core/src/board/mobile-nav-primary-items.ts | 2 - .../__tests__/bundled-plugin-install.test.ts | 2 + .../core/src/plugins/bundled-plugin-install.ts | 1 + packages/dashboard/app/App.tsx | 18 +- .../app/__tests__/lazy-loaded-views-docs.test.ts | 9 +- packages/dashboard/app/api/legacy.ts | 15 - packages/dashboard/app/api/system/index.ts | 1 - packages/dashboard/app/api/system/todo.ts | 85 --- packages/dashboard/app/components/Header.tsx | 23 +- .../dashboard/app/components/LeftSidebarNav.tsx | 1 - packages/dashboard/app/components/MobileNavBar.tsx | 4 - .../dashboard/app/components/SettingsModal.tsx | 2 - .../app/components/__tests__/App.test.tsx | 7 - .../app/components/__tests__/Header.test.tsx | 42 -- .../app/components/__tests__/RightDock.test.tsx | 18 +- ...skDetail.mobile-transition.board-panel.test.tsx | 1 - .../__tests__/TaskDetail.swipe-back.test.tsx | 1 - .../__tests__/TodoView.mobile-css.test.ts | 66 --- .../app/components/__tests__/TodoView.test.tsx | 649 --------------------- .../__tests__/navigation-history.test.tsx | 3 - .../__tests__/overflowViewRegistry.test.tsx | 118 +--- .../app/components/dashboard/MainContent.tsx | 27 +- .../dashboard/app/components/dashboard/types.ts | 6 +- .../app/components/overflowViewRegistry.tsx | 21 +- .../app/hooks/__tests__/useTodoLists.test.ts | 291 --------- .../app/hooks/__tests__/useViewState.test.ts | 11 + packages/dashboard/app/hooks/useAppSettings.ts | 5 - packages/dashboard/app/hooks/useViewState.ts | 5 + .../__tests__/registerBundledPluginViews.test.tsx | 14 + packages/dashboard/app/plugins/bundled-todos.d.ts | 5 + .../app/plugins/registerBundledPluginViews.ts | 18 + packages/dashboard/app/plugins/types.ts | 4 + .../src/__tests__/todo-documentation.test.ts | 68 --- .../dashboard/src/__tests__/todo-routes.test.ts | 577 ------------------ packages/dashboard/src/registry-manifest.json | 101 +++- packages/dashboard/src/routes.ts | 1 - .../src/routes/plugin-bundled-runtimes.ts | 1 + .../src/routes/register-integrated-routers.ts | 2 - packages/dashboard/src/shared/dashboard-views.ts | 6 - packages/dashboard/src/todo-routes.ts | 342 ----------- packages/dashboard/vite.config.ts | 8 + packages/dashboard/vitest.config.ts | 8 + packages/desktop/scripts/workspace-tools.ts | 1 + plugins/fusion-plugin-todos/README.md | 20 + plugins/fusion-plugin-todos/manifest.json | 6 + plugins/fusion-plugin-todos/package.json | 38 ++ .../fusion-plugin-todos/src/dashboard-interop.d.ts | 12 + plugins/fusion-plugin-todos/src/dashboard-view.tsx | 4 + .../src/dashboard/LoadingSpinner.tsx | 1 + .../src/dashboard}/TodoView.css | 0 .../src/dashboard}/TodoView.tsx | 16 +- plugins/fusion-plugin-todos/src/dashboard/api.ts | 15 + .../src/dashboard/projectStorage.ts | 3 + .../fusion-plugin-todos/src/dashboard/swrCache.ts | 6 + .../src/dashboard/useConfirm.ts | 1 + .../src/dashboard}/useTodoLists.ts | 4 +- plugins/fusion-plugin-todos/src/index.ts | 4 + .../fusion-plugin-todos/src/todo-routes.test.ts | 46 ++ plugins/fusion-plugin-todos/src/todo-routes.ts | 156 +++++ plugins/fusion-plugin-todos/tsconfig.json | 28 + plugins/fusion-plugin-todos/vitest.config.ts | 9 + pnpm-lock.yaml | 64 +- pnpm-workspace.yaml | 1 + 70 files changed, 671 insertions(+), 2531 deletions(-) Fusion-Task-Id: FN-8762 Fusion-Task-Lineage: 3beb502c-3793-451b-b357-50c243395410 Co-authored-by: Fusion (runfusion.ai) <noreply@runfusion.ai> |
||
|
|
f1ed5ac613 |
FN-8759: preserve planning interview context in created tasks
Retain complete Planning Mode decisions throughout task creation. - Add a canonical handoff formatter that embeds ordered interview Q&A without duplicates. - Apply the handoff to single-task, API, and multi-task planning creation paths. - Cover selected, custom, and commented answers; document the retained context and add a patch changeset. Files changed: .changeset/fn-8759-planning-session-qa.md | 7 ++++ docs/dashboard-guide.md | 3 +- .../planning-interview-formatters.test.ts | 45 +++++++++++++++++++++- .../planning-question-regeneration.test.ts | 35 +++++++++++++++++ .../src/__tests__/routes-planning.test.ts | 28 +++++++++++++- packages/dashboard/src/planning.ts | 42 ++++++++++++++------ .../src/routes/register-planning-subtask-routes.ts | 10 ++--- 7 files changed, 150 insertions(+), 20 deletions(-) Fusion-Task-Id: FN-8759 Fusion-Task-Lineage: c07e1714-cd0e-4701-9448-b77db773211d Co-authored-by: Fusion (runfusion.ai) <noreply@runfusion.ai> |
||
|
|
71ba437cfe |
FN-8760: publish workflow lanes for new tasks
Publish durable workflow lane metadata when new tasks wake triage. - Defer task-created events until selected workflow lanes are durable. - Cache and emit resolved lifecycle lanes while preserving listener compatibility. - Prevent proposal-claim replays from issuing duplicate triage wakes and cover custom lanes. Files changed: .changeset/fn-8760-planning-wake.md | 7 ++++ .../postgres/task-proposal-claim.pg.test.ts | 48 +++++++++++++++++++++- .../__tests__/task-updated-lanes-payload.test.ts | 20 ++++++++- packages/core/src/store.ts | 12 ++++-- packages/core/src/task-store/task-creation.ts | 44 ++++++++++++++++---- packages/engine/src/__tests__/triage.test.ts | 34 ++++++++++++++- 6 files changed, 152 insertions(+), 13 deletions(-) Fusion-Task-Id: FN-8760 Fusion-Task-Lineage: 06275d4a-3fc0-405e-baa5-3cdc8d195695 Co-authored-by: Fusion (runfusion.ai) <noreply@runfusion.ai> |
||
|
|
b269bff4d4 |
FN-8757: add mobile planning review shortcut
Add a reversible Plan preview shortcut after five answered mobile interview questions. - Count only populated question-and-response history entries toward the threshold. - Preserve unsent answers while switching between mobile question and plan tabs. - Add coverage, operator documentation, and a patch changeset. Files changed: .changeset/fn-8757-mobile-planning-review.md | 7 ++ docs/dashboard-guide.md | 3 + .../suite-only-flakes-observed-register.md | 14 +++ .../dashboard/app/components/PlanningModeModal.tsx | 32 +++++- .../PlanningModeModal.planning-flow.test.tsx | 113 +++++++++++++++++++++ 5 files changed, 167 insertions(+), 2 deletions(-) Fusion-Task-Id: FN-8757 Fusion-Task-Lineage: ac92a785-aafd-4c92-a1af-b089c21dbb99 Co-authored-by: Fusion (runfusion.ai) <noreply@runfusion.ai> |
||
|
|
dd8df26e5e |
FN-8756: suppress duplicate planner generation banners
Suppresses harmless duplicate-response errors when a planner response is already generating. - Clear the shared error banner for duplicate response-generation conflicts after durable state recovery. - Preserve actionable response errors and cover question and generation states on desktop and mobile. Files changed: packages/dashboard/app/components/PlanningModeModal.tsx | 17 ++++ - packages/dashboard/app/components/__tests__/PlanningModeModal.planning-flow.test.tsx | 82 ++++++++++++++++++++++ 2 files changed, 97 insertions(+), 2 deletions(-) Fusion-Task-Id: FN-8756 Fusion-Task-Lineage: 79cb1db1-e5e7-4b00-98f1-aeb34f2f588e Co-authored-by: Fusion (runfusion.ai) <noreply@runfusion.ai> |
||
|
|
5d7fa7c6b6 |
fix(dashboard): align List browser smoke fixture (#3316)
## Summary - mark the native mobile List fixture with the production single-pane class introduced by FN-8754 - add fixture coverage so the production selector cannot drift silently ## Test Plan - `pnpm --filter @fusion/dashboard exec vitest run app/__tests__/browser-layout-smoke-fixture.test.ts --silent=passed-only --reporter=dot` - `pnpm check:changesets` - `pnpm build` - `pnpm --filter @fusion/dashboard test:browser-smoke -- --require-browser` <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Updated the mobile list layout fixture to include the production single-pane styling class, improving alignment with the app’s mobile layout behavior. * **Tests** * Added a browser smoke test to verify the expected mobile list layout class is generated reliably. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
cb57093d03 |
refactor: domain folder layout (types, API, core, engine) (#2398)
## Summary Wave 17 organizes Fusion into **domain folders** (stacks on #2397). ### Layout - **core/types/** — board, task, agents, settings, merge, workflow, mesh, … - **core/src/** — agents, ai, async-stores, workflows, tasks, config, db, … - **dashboard/app/api/** — client, tasks, agents, git, missions, planning, … - **engine/src/** — agents, auth, execution, merge, missions, overseer, worktree, … Root keepers retained for large entrypoints (`store.ts`, `executor.ts`, `merger.ts`, …). Public barrels (`@fusion/core`, `@fusion/engine`, `app/api.ts` → legacy) stay stable. ## Test plan - [x] `@fusion/core` typecheck - [x] `@fusion/engine` typecheck (pre-existing playwright-core noise only) - [ ] CI merge gate **Stack:** #2394 → #2397 → **this PR** |
||
|
|
40453ac8cd |
fix(i18n): restore settings locale parity (#3315)
## Summary - add FN-8752 executor escalation model keys to every secondary locale - add FN-8753 voice input runtime-state keys to every secondary locale - preserve existing aggregate-only locale keys removed by raw i18n sync ## Test Plan - `pnpm i18n:status` - `pnpm --filter @fusion/i18n test` - `pnpm check:changesets` - `pnpm build` <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Localization** * Added Spanish, French, Korean, Simplified Chinese, and Traditional Chinese translations for chat reset and escalation model settings. * Added translated voice-input status messages covering preparation, errors, loading, compatibility, and runtime issues. * **Release** * Prepared a patch release to restore translation parity across supported locales. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
af66b382e0 |
FN-8755: add undo and redo controls to file editor
Add localized CodeMirror history controls while preserving current editor mode during external content resets. - Add native undo/redo commands, toolbar controls, keyboard shortcuts, and translations - Reset history for accepted external replacements while retaining stale self-echo history - Cover simultaneous content and read-only transitions and document editor shortcuts Files changed: .changeset/fn-8755-file-editor-history.md | 7 ++ docs/dashboard-guide.md | 2 +- packages/dashboard/app/components/FileEditor.tsx | 96 ++++++++++++------ .../app/components/__tests__/FileEditor.test.tsx | 108 +++++++++++++++++++++ packages/dashboard/package.json | 3 +- packages/i18n/locales/en/app.json | 2 + packages/i18n/locales/es/app.json | 20 +++- packages/i18n/locales/fr/app.json | 20 +++- packages/i18n/locales/ko/app.json | 20 +++- packages/i18n/locales/zh-CN/app.json | 20 +++- packages/i18n/locales/zh-TW/app.json | 20 +++- packages/i18n/src/resources.d.ts | 2 + pnpm-lock.yaml | 45 ++++++--- 13 files changed, 294 insertions(+), 71 deletions(-) Fusion-Task-Id: FN-8755 Fusion-Task-Lineage: 1c0bdb9b-f866-4e01-8002-afe27f34d670 Co-authored-by: Fusion (runfusion.ai) <noreply@runfusion.ai> |
||
|
|
a6d64eba8c |
chore(deps): bump i18next from 26.3.1 to 26.3.6 (#3307)
Bumps [i18next](https://github.com/i18next/i18next) from 26.3.1 to 26.3.6. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/i18next/i18next/releases">i18next's releases</a>.</em></p> <blockquote> <h2>v26.3.6</h2> <ul> <li>fix: allow TypeScript 7 in the optional <code>typescript</code> peer dependency range (<code>^5 || ^6 || ^7</code>). With <code>typescript@7.0.2</code> in a project, <code>npm install</code> failed with an <code>ERESOLVE</code> peer conflict. The published types are TS7-compatible as-is: every <code>test/typescript</code> suite produces identical results under 6.0 and 7.0.2. Reported in <a href="https://redirect.github.com/i18next/react-i18next/issues/1927">react-i18next#1927</a>, thanks <a href="https://github.com/andikapradanaarif"><code>@andikapradanaarif</code></a>.</li> </ul> <h2>v26.3.5</h2> <ul> <li>fix: <code>$t()</code> nesting options blocks that span multiple lines are now parsed. <code>nest()</code> decided where the nested key ends by testing <code>match[1]</code> with <code>/{.*}/</code>, whose dot does not cross line breaks — so a <code>$t(key, { ... })</code> options object containing a newline was treated as having no options, mis-split as formatters, and the nested lookup ran without its options (placeholders stayed unresolved). The nesting regexp itself already matches newlines inside <code>$t(...)</code>; adding the <code>s</code> (dotAll) flag makes multiline options behave like the single-line form. Thanks <a href="https://github.com/spokodev"><code>@spokodev</code></a> (<a href="https://redirect.github.com/i18next/i18next/pull/2440">#2440</a>).</li> <li>fix: <code>getUsedParamsDetails</code> (the <code>returnDetails: true</code> path) no longer mutates the passed <code>replace</code> object. It wrote <code>count</code> straight onto <code>options.replace</code> so the returned <code>usedParams</code> would include it — a caller reusing one <code>replace</code> object across <code>t()</code> calls then carried a stale <code>count</code> into later interpolations (e.g. a previous call's <code>count: 5</code> rendered instead of the current call's value). The details are now built from a copy; <code>usedParams</code> still includes <code>count</code>. Thanks <a href="https://github.com/spokodev"><code>@spokodev</code></a> (<a href="https://redirect.github.com/i18next/i18next/pull/2441">#2441</a>).</li> <li>fix: with the default <code>skipOnVariables: true</code> + <code>escapeValue: true</code>, a <code>{{placeholder}}</code> carried inside an interpolated value now stays literal even when the value contains escapable characters. The skip logic advanced the regex <code>lastIndex</code> by the raw value length, but the escaped text written into the string is longer, so <code>lastIndex</code> landed inside the inserted value and a trailing <code>{{placeholder}}</code> in it got interpolated — leaking another in-scope variable that should have stayed literal (values without escapable characters were already skipped correctly). The advance now uses the escaped length that is actually written, and the regex-safe <code>$</code>-doubling is applied only at the <code>String.replace</code> call so it can't distort the length arithmetic. Thanks <a href="https://github.com/spokodev"><code>@spokodev</code></a> (<a href="https://redirect.github.com/i18next/i18next/pull/2442">#2442</a>).</li> </ul> <h2>v26.3.4</h2> <ul> <li>fix(security): <code>deepExtend</code> (used by <code>addResourceBundle(..., deep, overwrite)</code>) no longer recurses into inherited properties. It checked key existence with the <code>in</code> operator, which walks the prototype chain, so a source key matching an inherited built-in (e.g. <code>hasOwnProperty</code>, <code>toString</code>) caused recursion into the shared <code>Object.prototype</code> function and, with <code>overwrite: true</code>, could overwrite e.g. <code>Object.prototype.hasOwnProperty.call</code> with a non-callable value — corrupting a shared built-in process-wide (DoS). Existence is now checked with <code>Object.prototype.hasOwnProperty.call</code>, so such keys are copied as plain own data instead. This complements the existing <code>__proto__</code>/<code>constructor</code> guard and is also strictly more correct for an own-property merge. Only affects applications that pass attacker-controlled data with <code>deep: true</code> and <code>overwrite: true</code>; no standard backend/integration does this. Distinct from CVE-2026-48713 / CVE-2026-48714 (different packages, <code>setPath</code> mechanism). Thanks to zx (Jace) for the responsible disclosure.</li> </ul> <h2>v26.3.3</h2> <ul> <li>fix(types): selector <code>t($ => $.arr, { returnObjects: true, context })</code> on a JSON array of <strong>heterogeneous</strong> objects now preserves each element's full shape (e.g. <code>{ transKey1: string; transKey2: string }[]</code>) instead of collapsing to a union of partial element types. Two type-level causes: (1) <code>FilterKeys</code> evaluated the whole array element type at once, so <code>keyof (A | B)</code> only saw the keys common to every element — it now distributes over the object union and filters each element independently; (2) when TypeScript merges mismatched array element types it injects phantom optional <code>undefined</code> keys (e.g. <code>transKey1_withContext?: undefined</code> on elements that don't define it), which the context-detection helpers mistook for real context variants — they now skip keys typed as <code>undefined</code>. Also adds a dedicated <code>context</code> + <code>returnObjects: true</code> selector overload using <code>const Fn</code> + <code>ReturnType<Fn></code>, so <code>Target</code> is no longer collapsed to <code>unknown</code> via <code>ApplyTarget</code>. Resolves Problem 1 of <a href="https://redirect.github.com/i18next/i18next/issues/2398">#2398</a> (Problem 2 was already fixed on master). Thanks <a href="https://github.com/sauravgupta-dotcom"><code>@sauravgupta-dotcom</code></a> (<a href="https://redirect.github.com/i18next/i18next/pull/2438">#2438</a>). Fixes <a href="https://redirect.github.com/i18next/i18next/issues/2398">#2398</a>.</li> </ul> <h2>v26.3.2</h2> <ul> <li>fix: chained formatters with a parenthesised option that contains the format separator (e.g. <code>join(separator: ', ')</code>) now work at <strong>any</strong> position in the chain, not just first. Previously the comma-in-parens reassembly only repaired <code>formats[0]</code>, so <code>{{v, uppercase, join(separator: ', ')}}</code> split the <code>join(...)</code> option on the inner comma and never rejoined it, producing corrupt output. Replaced the first-position-only repair with a position-independent pass that re-joins fragments until each open paren closes. Thanks <a href="https://github.com/spokodev"><code>@spokodev</code></a> (<a href="https://redirect.github.com/i18next/i18next/pull/2437">#2437</a>).</li> </ul> </blockquote> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/i18next/i18next/blob/master/CHANGELOG.md">i18next's changelog</a>.</em></p> <blockquote> <h2>26.3.6</h2> <ul> <li>fix: allow TypeScript 7 in the optional <code>typescript</code> peer dependency range (<code>^5 || ^6 || ^7</code>). With <code>typescript@7.0.2</code> in a project, <code>npm install</code> failed with an <code>ERESOLVE</code> peer conflict. The published types are TS7-compatible as-is: every <code>test/typescript</code> suite produces identical results under 6.0 and 7.0.2. Reported in <a href="https://redirect.github.com/i18next/react-i18next/issues/1927">react-i18next#1927</a>, thanks <a href="https://github.com/andikapradanaarif"><code>@andikapradanaarif</code></a>.</li> </ul> <h2>26.3.5</h2> <ul> <li>fix: <code>$t()</code> nesting options blocks that span multiple lines are now parsed. <code>nest()</code> decided where the nested key ends by testing <code>match[1]</code> with <code>/{.*}/</code>, whose dot does not cross line breaks — so a <code>$t(key, { ... })</code> options object containing a newline was treated as having no options, mis-split as formatters, and the nested lookup ran without its options (placeholders stayed unresolved). The nesting regexp itself already matches newlines inside <code>$t(...)</code>; adding the <code>s</code> (dotAll) flag makes multiline options behave like the single-line form. Thanks <a href="https://github.com/spokodev"><code>@spokodev</code></a> (<a href="https://redirect.github.com/i18next/i18next/pull/2440">#2440</a>).</li> <li>fix: <code>getUsedParamsDetails</code> (the <code>returnDetails: true</code> path) no longer mutates the passed <code>replace</code> object. It wrote <code>count</code> straight onto <code>options.replace</code> so the returned <code>usedParams</code> would include it — a caller reusing one <code>replace</code> object across <code>t()</code> calls then carried a stale <code>count</code> into later interpolations (e.g. a previous call's <code>count: 5</code> rendered instead of the current call's value). The details are now built from a copy; <code>usedParams</code> still includes <code>count</code>. Thanks <a href="https://github.com/spokodev"><code>@spokodev</code></a> (<a href="https://redirect.github.com/i18next/i18next/pull/2441">#2441</a>).</li> <li>fix: with the default <code>skipOnVariables: true</code> + <code>escapeValue: true</code>, a <code>{{placeholder}}</code> carried inside an interpolated value now stays literal even when the value contains escapable characters. The skip logic advanced the regex <code>lastIndex</code> by the raw value length, but the escaped text written into the string is longer, so <code>lastIndex</code> landed inside the inserted value and a trailing <code>{{placeholder}}</code> in it got interpolated — leaking another in-scope variable that should have stayed literal (values without escapable characters were already skipped correctly). The advance now uses the escaped length that is actually written, and the regex-safe <code>$</code>-doubling is applied only at the <code>String.replace</code> call so it can't distort the length arithmetic. Thanks <a href="https://github.com/spokodev"><code>@spokodev</code></a> (<a href="https://redirect.github.com/i18next/i18next/pull/2442">#2442</a>).</li> </ul> <h2>26.3.4</h2> <ul> <li>fix(security): <code>deepExtend</code> (used by <code>addResourceBundle(..., deep, overwrite)</code>) no longer recurses into inherited properties. It checked key existence with the <code>in</code> operator, which walks the prototype chain, so a source key matching an inherited built-in (e.g. <code>hasOwnProperty</code>, <code>toString</code>) caused recursion into the shared <code>Object.prototype</code> function and, with <code>overwrite: true</code>, could overwrite e.g. <code>Object.prototype.hasOwnProperty.call</code> with a non-callable value — corrupting a shared built-in process-wide (DoS). Existence is now checked with <code>Object.prototype.hasOwnProperty.call</code>, so such keys are copied as plain own data instead. This complements the existing <code>__proto__</code>/<code>constructor</code> guard and is also strictly more correct for an own-property merge. Only affects applications that pass attacker-controlled data with <code>deep: true</code> and <code>overwrite: true</code>; no standard backend/integration does this. Distinct from CVE-2026-48713 / CVE-2026-48714 (different packages, <code>setPath</code> mechanism). See advisory <a href="https://github.com/i18next/i18next/security/advisories/GHSA-6jcc-5g8w-32mx">GHSA-6jcc-5g8w-32mx</a>, CVSS 5.9 (<code>CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:H</code>). Thanks to zx (Jace) <a href="https://github.com/manus-use"><code>@manus-use</code></a> for the responsible disclosure.</li> </ul> <h2>26.3.3</h2> <ul> <li>fix(types): selector <code>t($ => $.arr, { returnObjects: true, context })</code> on a JSON array of <strong>heterogeneous</strong> objects now preserves each element's full shape (e.g. <code>{ transKey1: string; transKey2: string }[]</code>) instead of collapsing to a union of partial element types. Two type-level causes: (1) <code>FilterKeys</code> evaluated the whole array element type at once, so <code>keyof (A | B)</code> only saw the keys common to every element — it now distributes over the object union and filters each element independently; (2) when TypeScript merges mismatched array element types it injects phantom optional <code>undefined</code> keys (e.g. <code>transKey1_withContext?: undefined</code> on elements that don't define it), which the context-detection helpers mistook for real context variants — they now skip keys typed as <code>undefined</code>. Also adds a dedicated <code>context</code> + <code>returnObjects: true</code> selector overload using <code>const Fn</code> + <code>ReturnType<Fn></code>, so <code>Target</code> is no longer collapsed to <code>unknown</code> via <code>ApplyTarget</code>. Resolves Problem 1 of <a href="https://redirect.github.com/i18next/i18next/issues/2398">#2398</a> (Problem 2 was already fixed on master). Thanks <a href="https://github.com/sauravgupta-dotcom"><code>@sauravgupta-dotcom</code></a> (<a href="https://redirect.github.com/i18next/i18next/pull/2438">#2438</a>). Fixes <a href="https://redirect.github.com/i18next/i18next/issues/2398">#2398</a>.</li> </ul> <h2>26.3.2</h2> <ul> <li>fix: chained formatters with a parenthesised option that contains the format separator (e.g. <code>join(separator: ', ')</code>) now work at <strong>any</strong> position in the chain, not just first. Previously the comma-in-parens reassembly only repaired <code>formats[0]</code>, so <code>{{v, uppercase, join(separator: ', ')}}</code> split the <code>join(...)</code> option on the inner comma and never rejoined it, producing corrupt output. Replaced the first-position-only repair with a position-independent pass that re-joins fragments until each open paren closes. Thanks <a href="https://github.com/spokodev"><code>@spokodev</code></a> (<a href="https://redirect.github.com/i18next/i18next/pull/2437">#2437</a>).</li> </ul> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href=" |
||
|
|
86a749cac9 |
fix(ci): disable package-manager-cache on skip-install setup-node
actions/setup-node@v5 defaults package-manager-cache:true, so the agent-browser pack fixture still registered a pnpm store path and failed post-job with Path Validation Error after a successful pack/upload. Explicitly set package-manager-cache:false when skip-install is true. |
||
|
|
d39acb5c55 |
FN-8754: adapt List task details to available width
Adapt List task detail routing to the usable content width. - Measure the List container to choose split-pane or modal detail routing. - Preserve phone and popup-preference routing while allowing wide tablets to use the split pane. - Add responsive routing coverage and document the behavior. Files changed: .changeset/fn-8754-responsive-list-detail.md | 7 + docs/dashboard-guide.md | 4 +- packages/dashboard/app/components/ListView.css | 25 +-- packages/dashboard/app/components/ListView.tsx | 47 +++++- .../app/components/__tests__/ListView.test.tsx | 169 +++++++++++++++++++-- 5 files changed, 216 insertions(+), 36 deletions(-) Fusion-Task-Id: FN-8754 Fusion-Task-Lineage: 2051e7d5-a5a9-47b8-bfc2-42586b9554cc Co-authored-by: Fusion (runfusion.ai) <noreply@runfusion.ai> |
||
|
|
73fe461db5 |
fix: demote routine engine log noise to debug
Keep the default TUI for lifecycle transitions (Starting/Specifying/Worktree created/merge/move). Demote expected skips, schedule-trigger echoes, session setup bookkeeping, warm worktree reuse, and fn_run_verification command-fail detail. Pin via severity manifest and contract tests. |
||
|
|
b2373431e4 |
FN-8752: move escalation model to project selector
Centralize executor escalation model selection with the project-scoped provider-aware model control. - Move escalation provider and model fields from Scheduling to Project Models - Persist and clear escalation model pairs atomically through the shared selector - Update search metadata, localization, documentation, and mobile coverage Files changed: docs/settings-reference.md | 6 +- .../__tests__/SettingsModal.mobileClose.test.tsx | 29 +++++++ .../__tests__/SettingsModal.models-auth.test.tsx | 94 ++++++++++++++++++++++ .../search/__tests__/settings-search-index.test.ts | 17 ++++ .../app/components/settings/section-keys.ts | 4 +- .../sections/ProjectModelsSection.search.ts | 10 +++ .../settings/sections/ProjectModelsSection.tsx | 39 +++++++++ .../settings/sections/SchedulingSection.search.ts | 18 ----- .../settings/sections/SchedulingSection.tsx | 2 - .../settings-default-descriptions.test.tsx | 4 +- packages/dashboard/src/shared/settings-sections.ts | 9 +++ packages/i18n/locales/en/app.json | 4 + packages/i18n/src/resources.d.ts | 4 + 13 files changed, 213 insertions(+), 27 deletions(-) Fusion-Task-Id: FN-8752 Fusion-Task-Lineage: f0f430d7-7976-4b65-89c5-8eab3487d26a Co-authored-by: Fusion (runfusion.ai) <noreply@runfusion.ai> |
||
|
|
fb0863f660 |
FN-8753: enable installed voice input in project settings
Make Voice Input available only after its local model and runtime are ready. - Bundle the optional sherpa runtime with the published CLI. - Gate the project setting on model installation and stable runtime status codes. - Add localized recovery guidance, documentation, and coverage. Files changed: .changeset/fn-8753-voice-input-enable.md | 7 ++++ docs/dashboard-guide.md | 2 +- docs/settings-reference.md | 8 +++-- packages/cli/package.json | 3 ++ packages/cli/src/__tests__/package-config.test.ts | 16 +++++++++ .../settings/__tests__/VoiceInputSection.test.tsx | 36 ++++++++++++++++---- .../settings/sections/VoiceInputSection.tsx | 30 ++++++++++++----- packages/dashboard/package.json | 2 +- .../routes/__tests__/register-voice-routes.test.ts | 39 ++++++++++++++++++++++ .../dashboard/src/stt/__tests__/voice-stt.test.ts | 27 ++++++++++++--- packages/dashboard/src/stt/parakeet-service.ts | 26 ++++++++++----- packages/i18n/locales/en/app.json | 6 ++++ pnpm-lock.yaml | 6 +++- 13 files changed, 175 insertions(+), 33 deletions(-) Fusion-Task-Id: FN-8753 Fusion-Task-Lineage: db92b148-37f0-45d2-b616-ed2e3f2d54f6 Co-authored-by: Fusion (runfusion.ai) <noreply@runfusion.ai> |
||
|
|
46583a4cb6 |
chore(deps): bump @xterm/addon-search from 0.15.0 to 0.16.0 (#3308)
Bumps [@xterm/addon-search](https://github.com/xtermjs/xterm.js) from 0.15.0 to 0.16.0. <details> <summary>Commits</summary> <ul> <li><a href=" |
||
|
|
5301605130 |
chore(deps): bump pnpm/action-setup from 4 to 6 (#3305)
Bumps [pnpm/action-setup](https://github.com/pnpm/action-setup) from 4 to 6. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/pnpm/action-setup/releases">pnpm/action-setup's releases</a>.</em></p> <blockquote> <h2>v6.0.0</h2> <p>Added support for pnpm <a href="https://github.com/pnpm/pnpm/releases/tag/v11.0.0-rc.0">v11</a>.</p> <h2>v5.0.0</h2> <p>Updated the action to use Node.js 24.</p> <h2>v4.4.0</h2> <p>Updated the action to use Node.js 24.</p> <h2>v4.3.0</h2> <h2>What's Changed</h2> <ul> <li>docs: fix the run_install example in the Readme by <a href="https://github.com/dreyks"><code>@dreyks</code></a> in <a href="https://redirect.github.com/pnpm/action-setup/pull/175">pnpm/action-setup#175</a></li> <li>chore: remove unused <code>@types/node-fetch</code> dependency by <a href="https://github.com/silverwind"><code>@silverwind</code></a> in <a href="https://redirect.github.com/pnpm/action-setup/pull/186">pnpm/action-setup#186</a></li> <li>Clarify that package_json_file is relative to GITHUB_WORKSPACE by <a href="https://github.com/chris-martin"><code>@chris-martin</code></a> in <a href="https://redirect.github.com/pnpm/action-setup/pull/184">pnpm/action-setup#184</a></li> <li>feat: store caching by <a href="https://github.com/jrmajor"><code>@jrmajor</code></a> in <a href="https://redirect.github.com/pnpm/action-setup/pull/188">pnpm/action-setup#188</a></li> <li>refactor: remove star imports by <a href="https://github.com/KSXGitHub"><code>@KSXGitHub</code></a> in <a href="https://redirect.github.com/pnpm/action-setup/pull/196">pnpm/action-setup#196</a></li> <li>fix(ci): exclude macos by <a href="https://github.com/KSXGitHub"><code>@KSXGitHub</code></a> in <a href="https://redirect.github.com/pnpm/action-setup/pull/197">pnpm/action-setup#197</a></li> </ul> <h2>New Contributors</h2> <ul> <li><a href="https://github.com/dreyks"><code>@dreyks</code></a> made their first contribution in <a href="https://redirect.github.com/pnpm/action-setup/pull/175">pnpm/action-setup#175</a></li> <li><a href="https://github.com/silverwind"><code>@silverwind</code></a> made their first contribution in <a href="https://redirect.github.com/pnpm/action-setup/pull/186">pnpm/action-setup#186</a></li> <li><a href="https://github.com/chris-martin"><code>@chris-martin</code></a> made their first contribution in <a href="https://redirect.github.com/pnpm/action-setup/pull/184">pnpm/action-setup#184</a></li> <li><a href="https://github.com/jrmajor"><code>@jrmajor</code></a> made their first contribution in <a href="https://redirect.github.com/pnpm/action-setup/pull/188">pnpm/action-setup#188</a></li> <li><a href="https://github.com/Boosted-Bonobo"><code>@Boosted-Bonobo</code></a> made their first contribution in <a href="https://redirect.github.com/pnpm/action-setup/pull/199">pnpm/action-setup#199</a></li> </ul> <p><strong>Full Changelog</strong>: <a href="https://github.com/pnpm/action-setup/compare/v4.2.0...v4.3.0">https://github.com/pnpm/action-setup/compare/v4.2.0...v4.3.0</a></p> <h2>v4.2.0</h2> <p>When there's a <code>.npmrc</code> file at the root of the repository, pnpm will be fetched from the registry that is specified in that <code>.npmrc</code> file <a href="https://redirect.github.com/pnpm/action-setup/pull/179">#179</a></p> <h2>v4.1.0</h2> <p>Add support for <code>package.yaml</code> <a href="https://redirect.github.com/pnpm/action-setup/pull/156">#156</a>.</p> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href=" |
||
|
|
f4b3d9adc3 |
chore(deps): bump i18next-resources-to-backend from 1.2.1 to 1.2.2 (#3309)
Bumps [i18next-resources-to-backend](https://github.com/i18next/i18next-resources-to-backend) from 1.2.1 to 1.2.2. <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/i18next/i18next-resources-to-backend/blob/main/CHANGELOG.md">i18next-resources-to-backend's changelog</a>.</em></p> <blockquote> <h3>1.2.2</h3> <ul> <li>security: validate <code>language</code> and <code>namespace</code> in <code>read()</code> before they are passed to the loader. i18next resolves any string as a language unless <code>supportedLngs</code> is set, so these values can carry whatever a language detector picked up from the querystring, path or a cookie. The documented usage pattern is <code>import(</code>./locales/${language}/${namespace}.json<code>)</code>, and while a bundler compiles that template to a fixed context map, an unbundled ESM runtime (Node SSR) resolves the specifier against the filesystem, where a crafted value escapes the locales directory. Values containing <code>..</code>, <code>\</code>, control characters, <code>__proto__</code> / <code>constructor</code> / <code>prototype</code>, or longer than 128 characters are now rejected with an error and the loader is never called; <code>/</code> is rejected for <code>language</code> but allowed for <code>namespace</code>, where nested layouts such as <code>a/b</code> are legitimate. The same check keeps the static-resources lookup off <code>Object.prototype</code>.</li> </ul> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href=" |
||
|
|
6e416b044d |
chore(deps): bump actions/download-artifact from 4 to 8 (#3304)
Bumps [actions/download-artifact](https://github.com/actions/download-artifact) from 4 to 8. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/actions/download-artifact/releases">actions/download-artifact's releases</a>.</em></p> <blockquote> <h2>v8.0.0</h2> <h2>v8 - What's new</h2> <blockquote> <p>[!IMPORTANT] actions/download-artifact@v8 has been migrated to an ESM module. This should be transparent to the caller but forks might need to make significant changes.</p> </blockquote> <blockquote> <p>[!IMPORTANT] Hash mismatches will now error by default. Users can override this behavior with a setting change (see below).</p> </blockquote> <h3>Direct downloads</h3> <p>To support direct uploads in <code>actions/upload-artifact</code>, the action will no longer attempt to unzip all downloaded files. Instead, the action checks the <code>Content-Type</code> header ahead of unzipping and skips non-zipped files. Callers wishing to download a zipped file as-is can also set the new <code>skip-decompress</code> parameter to <code>true</code>.</p> <h3>Enforced checks (breaking)</h3> <p>A previous release introduced digest checks on the download. If a download hash didn't match the expected hash from the server, the action would log a warning. Callers can now configure the behavior on mismatch with the <code>digest-mismatch</code> parameter. To be secure by default, we are now defaulting the behavior to <code>error</code> which will fail the workflow run.</p> <h3>ESM</h3> <p>To support new versions of the @actions/* packages, we've upgraded the package to ESM.</p> <h2>What's Changed</h2> <ul> <li>Don't attempt to un-zip non-zipped downloads by <a href="https://github.com/danwkennedy"><code>@danwkennedy</code></a> in <a href="https://redirect.github.com/actions/download-artifact/pull/460">actions/download-artifact#460</a></li> <li>Add a setting to specify what to do on hash mismatch and default it to <code>error</code> by <a href="https://github.com/danwkennedy"><code>@danwkennedy</code></a> in <a href="https://redirect.github.com/actions/download-artifact/pull/461">actions/download-artifact#461</a></li> </ul> <p><strong>Full Changelog</strong>: <a href="https://github.com/actions/download-artifact/compare/v7...v8.0.0">https://github.com/actions/download-artifact/compare/v7...v8.0.0</a></p> <h2>v7.0.0</h2> <h2>v7 - What's new</h2> <blockquote> <p>[!IMPORTANT] actions/download-artifact@v7 now runs on Node.js 24 (<code>runs.using: node24</code>) and requires a minimum Actions Runner version of 2.327.1. If you are using self-hosted runners, ensure they are updated before upgrading.</p> </blockquote> <h3>Node.js 24</h3> <p>This release updates the runtime to Node.js 24. v6 had preliminary support for Node 24, however this action was by default still running on Node.js 20. Now this action by default will run on Node.js 24.</p> <h2>What's Changed</h2> <ul> <li>Update GHES guidance to include reference to Node 20 version by <a href="https://github.com/patrikpolyak"><code>@patrikpolyak</code></a> in <a href="https://redirect.github.com/actions/download-artifact/pull/440">actions/download-artifact#440</a></li> <li>Download Artifact Node24 support by <a href="https://github.com/salmanmkc"><code>@salmanmkc</code></a> in <a href="https://redirect.github.com/actions/download-artifact/pull/415">actions/download-artifact#415</a></li> <li>fix: update <code>@actions/artifact</code> to fix Node.js 24 punycode deprecation by <a href="https://github.com/salmanmkc"><code>@salmanmkc</code></a> in <a href="https://redirect.github.com/actions/download-artifact/pull/451">actions/download-artifact#451</a></li> <li>prepare release v7.0.0 for Node.js 24 support by <a href="https://github.com/salmanmkc"><code>@salmanmkc</code></a> in <a href="https://redirect.github.com/actions/download-artifact/pull/452">actions/download-artifact#452</a></li> </ul> <h2>New Contributors</h2> <ul> <li><a href="https://github.com/patrikpolyak"><code>@patrikpolyak</code></a> made their first contribution in <a href="https://redirect.github.com/actions/download-artifact/pull/440">actions/download-artifact#440</a></li> <li><a href="https://github.com/salmanmkc"><code>@salmanmkc</code></a> made their first contribution in <a href="https://redirect.github.com/actions/download-artifact/pull/415">actions/download-artifact#415</a></li> </ul> <p><strong>Full Changelog</strong>: <a href="https://github.com/actions/download-artifact/compare/v6.0.0...v7.0.0">https://github.com/actions/download-artifact/compare/v6.0.0...v7.0.0</a></p> <h2>v6.0.0</h2> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href=" |
||
|
|
0583f1684b |
chore(deps): bump ink from 7.0.5 to 7.1.1 (#3306)
Bumps [ink](https://github.com/vadimdemedes/ink) from 7.0.5 to 7.1.1. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/vadimdemedes/ink/releases">ink's releases</a>.</em></p> <blockquote> <h2>v7.1.1</h2> <ul> <li>Fix: Preserve last <code><Static></code> line erased after a full-clear frame (<a href="https://redirect.github.com/vadimdemedes/ink/issues/974">#974</a>) e51dfdd</li> <li>Make <code>measureElement()</code> also return position coordinates (<a href="https://redirect.github.com/vadimdemedes/ink/issues/968">#968</a>) c073b27</li> </ul> <hr /> <p><a href="https://github.com/vadimdemedes/ink/compare/v7.1.0...v7.1.1">https://github.com/vadimdemedes/ink/compare/v7.1.0...v7.1.1</a></p> <h2>v7.1.0</h2> <ul> <li>Add <a href="https://github.com/vadimdemedes/ink#suspendterminalcallback"><code>suspendTerminal()</code></a> to hand the terminal to a child process (<a href="https://redirect.github.com/vadimdemedes/ink/issues/972">#972</a>) 9e8ed1f</li> </ul> <hr /> <p><a href="https://github.com/vadimdemedes/ink/compare/v7.0.6...v7.1.0">https://github.com/vadimdemedes/ink/compare/v7.0.6...v7.1.0</a></p> <h2>v7.0.6</h2> <ul> <li>Fix stale frames on Windows when output exactly fills the terminal (<a href="https://redirect.github.com/vadimdemedes/ink/issues/971">#971</a>) 2c08d55</li> </ul> <hr /> <p><a href="https://github.com/vadimdemedes/ink/compare/v7.0.5...v7.0.6">https://github.com/vadimdemedes/ink/compare/v7.0.5...v7.0.6</a></p> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href=" |