Repository navigation
chore(deps): upgrade @effect/tsgo to 0.46.1 - #16360
Conversation
0.46.1 is the version Effect itself uses. It reports unknown rule names, so `importFromBarrel`, which Effect TSGo never ported, goes. It also extends `nodeBuiltinImport` to `crypto`, `timers`, and `stream`. Effect's Crypto covers only random values and ids, so each flagged import keeps Node's API behind a next-line opt-out that names what it needs.
ApprovabilityVerdict: Not approved Macroscope's review found this PR not approvable — The dependency upgrade expands into a cross-cutting production migration involving hashing, service wiring, request retries, and timing behavior across multiple subsystems. It also adds numerous static-analysis suppressions and changes authentication-related files, warranting human review. You can add or adjust custom eligibility rules. Learn more. |
|
Note Reviews pausedIt looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the Use the following commands to manage reviews:
Use the checkboxes below for quick actions:
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configuration
⛔ Files ignored due to path filters (1)
📒 Files selected for processing (3)
Included review availability: This review used your included allowance. Your plan provides up to 10 included reviews per hour; 9 remain after this review. 📝 WalkthroughWalkthroughThe pull request updates the ChangesEffect Diagnostic Updates
Priority: ⬇️ Low Estimated code review effort: 2 (Simple) | ~8 minutes Change: Other Suggested reviewers: Merge Risk: ⚪ Minimal · up to The PR updates tooling configuration and adds scoped diagnostic suppressions without changing executable behavior. The focused check recognizes the directives and found no errors or warnings, leaving no actionable merge-blocking risk. Architecture SummaryArchitecture risk: 🔵 Low · up to The change affects 7 systems. Changed systems: Architecture concerns Review detailsSystems and components
Before / after behavior
🚥 Pre-merge checks | ✅ 4✅ Passed checks (4 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
Comment |
|
@coderabbitai are all of these disable directives really true? effect/Crypto does have hashing. in the cases where we today use sync uuid gen, is there a reason for that or is it just leftovers? |
Effect's Crypto has `digest`, `randomBytes`, and UUIDs, so the opt-outs that said it has no `createHash` or `randomBytes` were wrong. Name only the APIs it lacks, and where a file needs only hashing or ids, say that the Node call is synchronous and Effect's is an Effect.
|
Tip For best results, initiate chat on the files or code changes. 🧩 Analysis chain🏁 Script executed: #!/bin/bash
set -euo pipefail
rg -n -C2 'effect:|@effect/tsgo|effect/|nodeBuiltinImport' pnpm-workspace.yaml tsconfig.base.json
rg -n -C1 'effect-diagnostics-next-line.*nodeBuiltinImport' apps infra packages
rg -n -C3 '\b(randomUUID|createHash|createHmac|timingSafeEqual)\s*\(' apps/server/src apps/desktop/src packages/shared/src infra/relay/src
fd -i '^Crypto\.ts$|^package\.json$' | head -60Length of output: 77999 🏁 Script executed: #!/bin/bash
set -euo pipefail
python - <<'PY'
import urllib.request,re
url="https://unpkg.com/effect@4.0.1/src/Crypto.ts"
s=urllib.request.urlopen(url).read().decode()
print("SOURCE",url)
lines=s.splitlines()
for i,line in enumerate(lines):
if re.search(r'^export (const|interface|class|type)|hash:|randomUUIDv4:|randomBytes:|digest:|subtle\.|randomUUID\(',line):
print("\n".join(f"{j+1}: {lines[j]}" for j in range(max(0,i-3),min(len(lines),i+18))))
PY
for f in apps/server/src/assets/AttachmentUpload.ts apps/server/src/cli/app.ts apps/server/src/preview/Manager.ts apps/server/src/project/ProjectSetupScriptRunner.ts apps/server/src/vcs/GitVcsDriver.ts apps/server/src/mcp/McpHttpServer.ts apps/desktop/src/preview/Manager.ts; do
echo "=== $f ==="
ast-grep outline "$f" --items all --type function --view compact | head -90
done
rg -n -C12 'NodeCrypto\.randomUUID\(' apps/server/src/assets/AttachmentUpload.ts apps/server/src/cli/app.ts apps/server/src/preview/Manager.ts apps/server/src/project/ProjectSetupScriptRunner.ts apps/server/src/vcs/GitVcsDriver.ts apps/server/src/mcp/McpHttpServer.ts apps/desktop/src/preview/Manager.ts
rg -n -C3 'Crypto\.(digest|randomUUIDv4|randomBytes)|from "effect/Crypto"' apps infra packages | head -180Length of output: 2573 🏁 Script executed: #!/bin/bash
python - <<'PY'
import urllib.request,json,tarfile,io,re
meta=json.load(urllib.request.urlopen("https://registry.npmjs.org/effect/4.0.1", timeout=30))
t=tarfile.open(fileobj=io.BytesIO(urllib.request.urlopen(meta["dist"]["tarball"],timeout=30).read()),mode="r:gz")
for name in ["package/src/Crypto.ts","package/dist/Crypto.d.ts"]:
try: s=t.extractfile(name).read().decode()
except KeyError: continue
print("SOURCE",name)
lines=s.splitlines()
for i,line in enumerate(lines):
if re.search(r'^export (const|interface|class|type)|hash:|randomUUIDv4:|randomBytes:|digest:|subtle\.|randomUUID\(',line):
print("\n".join(f"{j+1}: {lines[j]}" for j in range(max(0,i-2),min(len(lines),i+23))))
break
PY
for f in apps/server/src/assets/AttachmentUpload.ts apps/server/src/cli/app.ts apps/server/src/preview/Manager.ts apps/server/src/project/ProjectSetupScriptRunner.ts apps/server/src/vcs/GitVcsDriver.ts apps/server/src/mcp/McpHttpServer.ts apps/desktop/src/preview/Manager.ts; do
echo "=== $f ==="
ast-grep outline "$f" --items all --type function | head -65
done
sed -n '140,205p' apps/server/src/assets/AttachmentUpload.ts
sed -n '175,225p' apps/server/src/cli/app.ts
sed -n '325,382p' apps/server/src/project/ProjectSetupScriptRunner.ts
sed -n '790,825p' apps/server/src/vcs/GitVcsDriver.ts
sed -n '315,345p' apps/server/src/mcp/McpHttpServer.ts
sed -n '1640,1685p' apps/desktop/src/preview/Manager.ts
sed -n '4175,4205p' apps/desktop/src/preview/Manager.ts
rg -n -C3 'Crypto\.(digest|randomUUIDv4|randomBytes)|from "effect/Crypto"' apps infra packages | head -180Length of output: 44002
I checked the published Hashing and other crypto operations
Some hash-only imports are clear migration candidates. For example:
Their hash calls already run inside Effect generators. Other hash calls belong to synchronous helpers, such as Streaming hashes need a separate assessment. Synchronous UUID generationI found no demonstrated requirement for synchronous UUID generation in the eight UUID-only files. Their UUID calls are already inside Effect execution:
The desktop calls include These look like migration leftovers rather than required synchronous boundaries. I did not check their history, so I cannot establish the original intent. There is a real type-level cost: My recommendation is to migrate the UUID-only and Effect-native hash-only cases. Keep narrow suppressions for unsupported operations, synchronous contracts retained intentionally, and incremental hashing. The comments should state those actual constraints instead of saying that Effect lacks hashing. ✏️ Learnings added
You are interacting with an AI system. |
|
You're right, I missed On sync UUIDs: mostly leftovers. Of the 13 Moving the Effect-context ones to |
|
The move is up in #16377. Two corrections to my reply above:
|
|
Autopilot could not be updated. Open Coding to check access and billing. |
# Conflicts: # apps/desktop/src/preview/Manager.ts # apps/server/src/assets/AttachmentUpload.ts # apps/server/src/assets/NativeAppIconResolver.ts # apps/server/src/cli/app.ts # apps/server/src/device/SshDeviceHost.ts # apps/server/src/mcp/McpHttpServer.ts # apps/server/src/preview/Manager.ts # apps/server/src/project/ProjectSetupScriptRunner.ts # apps/server/src/provider/ProviderCredentialStore.ts # apps/server/src/provider/openCodeUsageLimits.ts # apps/server/src/pullRequest/GitHubPullRequestCli.ts # apps/server/src/vcs/GitVcsDriver.ts # apps/server/src/ws.ts
…s from main Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Replaces the nodeBuiltinImport opt-outs for synchronous createHash, randomUUID, randomBytes and Node timers with Effect's Crypto service and Effect.sleep/Schedule, threading Crypto through callers. Persisted hashes, refs and ids are unchanged; tests pin the previous outputs. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Reading the downloaded archive back to verify its SHA-256 loaded up to 1 GiB into memory. Hash each chunk as it streams with @noble/hashes, since Effect's Crypto only digests a whole buffer. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…raming (#28) * fix(server): forks no longer merge into their upstream repo's project group (pingdotgg#16353) Fixes pingdotgg#4880. Originally pingdotgg#14639 by @Project516. Co-authored-by: Project516 <138796702+Project516@users.noreply.github.com> * fix(server): stop the startup project sync from delaying the app window (pingdotgg#14912) * fix(web): avoid blocking image preparation conversions (pingdotgg#13342) * fix(server): return partial workspace index on timeout (pingdotgg#11500) * fix(server): probe project favicon candidates concurrently (pingdotgg#12543) * fix(observability): a failing trace disk no longer stalls the server (pingdotgg#13758) Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * fix(server): status polling no longer locks the git index (pingdotgg#14718) Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * perf(shared): scan PATH once per command before spawning, not on every spawn (pingdotgg#12600) * fix(server): main's startup auto-pull test compiles again (pingdotgg#16357) Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * fix(server): project favicons stop being rescanned every minute (pingdotgg#16206) Favicons in ProjectEnrichmentService now keep for 15 minutes. Repository identity keeps its 1-minute TTL, so remote changes still show within a minute. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * fix(server): Claude limits load again for users with large transcript histories (pingdotgg#16358) The Claude capabilities probe now asks for usage with skipBehaviors, so it no longer scans every local transcript and misses its 4 s deadline. Takes over pingdotgg#14456. Co-authored-by: Ashkaan <a@ashkaan.me> * Add esthor to the list of GitHub users * fix(server): caches and ids are written atomically (pingdotgg#16242) Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * fix(server): one-shot initializers no longer race (pingdotgg#16260) Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * fix(server): the PR cache sweep only removes real entry files (pingdotgg#16285) Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * chore: keep one copy each of undici 8 and ws 8 (pingdotgg#16211) Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * fix(shared): DrainableWorker keeps running after a failed item (pingdotgg#16223) Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * fix(server): metrics count interrupted work on the monotonic clock (pingdotgg#16207) Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * refactor(web): import connection storage as a namespace in its test (pingdotgg#16315) Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * fix(contracts): trimmed IDs round-trip (pingdotgg#16300) Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * fix(server): main's settings, keybindings and session tests compile again (pingdotgg#16363) Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * chore(lint): catch known tags with Effect.catchTags (pingdotgg#16361) * fix(observability): T3 Connect tracing stops at the relay boundary (pingdotgg#16314) Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * fix(relay): error and deadline responses carry CORS headers (pingdotgg#16253) Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * fix(web): bring back the live shimmer on work log rows (pingdotgg#16372) Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * refactor: Effect code gets UUIDs and SHA-256 from Effect's Crypto (pingdotgg#16377) * fix(relay): export traces through one tracer, one request span each (pingdotgg#16382) Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * fix(server): Pi thread titles use linked PR context (pingdotgg#16210) * fix(desktop): retry transient bearer bootstrap and degrade on session fetch failure (pingdotgg#12919) * fix(server): avoid scanning completed history for pending secrets (pingdotgg#16409) * fix(orchestration-v2): let Stop recover stalled runs (pingdotgg#15442) * fix(release): resolve version-qualified catalog overrides (pingdotgg#16411) * fix(web): type in front of bold that starts a composer line (pingdotgg#13217) Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com> * fix(desktop): prevent browser screenshot filename collisions (pingdotgg#14784) * fix(server): end clone options before the repository URL (pingdotgg#14781) * fix(web): queued messages no longer split the composer notice stack (pingdotgg#16400) Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Co-authored-by: Yash Singh <saiansh2525@gmail.com> * fix(server): reject invalid explicit Bitbucket repositories (pingdotgg#15876) * fix(desktop): use the crypto service for screenshot IDs (pingdotgg#16415) * fix(shared): find versioned JetBrains macOS app bundles (pingdotgg#16246) * fix(server): OpenCode 2 threads get T3 Code's MCP tools (pingdotgg#16142) * feat(preview): run the browser on the environment server (pingdotgg#15328) * fix: restore service references breaking ci (pingdotgg#16495) Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com> * fix(mcp): mark declared tool failures as errors (pingdotgg#15617) * fix(release): unblock nightly browser tests and cli builds (pingdotgg#16515) Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com> * fix(mcp): preserve thread command rejection reasons (pingdotgg#15627) * chore(deps): upgrade @effect/tsgo to 0.46.1 (pingdotgg#16360) Co-authored-by: Julius Marminge <julius0216@outlook.com> Co-authored-by: Julius Marminge <51714798+juliusmarminge@users.noreply.github.com> Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * fix(orchestration-v2): show reported subagent models (pingdotgg#14108) Co-authored-by: Yash Singh <saiansh2525@gmail.com> * fix(web): Apple logo no longer dips below the device host label (pingdotgg#14825) Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * fix(web): show subagent effort and speed in hover cards (pingdotgg#13056) Co-authored-by: Julius Marminge <julius0216@outlook.com> * feat(web): reopen closed tabs across the app (pingdotgg#15207) Co-authored-by: Julius Marminge <julius0216@outlook.com> * fix(web): stop wide ordered list markers from clipping (pingdotgg#16523) * fix(desktop): build AppImage with the static runtime toolset (fixes libfuse2 launch failure) (pingdotgg#7765) Co-authored-by: Julius Marminge <julius0216@outlook.com> * fix(mobile): keep usage-limit notice opaque (pingdotgg#15602) * feat(server): GitHub API transport that uses gh only for the token (pingdotgg#16319) Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * feat(server): pull requests talk to GitHub's API instead of the gh CLI (pingdotgg#16320) Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * feat(server): source control, media and discovery use GitHub's API instead of gh (pingdotgg#16321) Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * feat: choose the GitHub account per host, save a GitHub token, and fewer reads per PR action (pingdotgg#16322) Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * fix(server): Rebase stack moves each layer onto the rebased layer below it (pingdotgg#16551) Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * fix(web): diff panel keeps the chosen scope while a turn runs (pingdotgg#16571) Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * fix(desktop): honor the telemetry opt-out from the shell profile (pingdotgg#16563) Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * docs(marketing): disclose product usage data in the privacy policy (pingdotgg#16562) Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * feat(web): note anonymous usage data in onboarding and link the privacy policy (pingdotgg#16564) Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * perf(web): diff panel no longer re-renders every file header each time a patch arrives (pingdotgg#16033) Co-authored-by: Julius Marminge <51714798+juliusmarminge@users.noreply.github.com> Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * feat(server): every T3 MCP tool declares who may call it (pingdotgg#16335) Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * feat(server): outside agents sign in to the T3 MCP server with OAuth (pingdotgg#16336) Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * feat(web): copy an environment's MCP URL for outside agents (pingdotgg#16337) Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * chore(tsconfig): turn off the Schema-over-JSON diagnostic in test files (pingdotgg#16375) Co-authored-by: Julius Marminge <51714798+juliusmarminge@users.noreply.github.com> Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * chore(review): CodeRabbit gates outside contributors' pull requests (pingdotgg#16332) * fix(desktop): include Linux package license and app metadata (pingdotgg#16597) * fix(server): one failing RPC handler no longer ends the client's other requests (pingdotgg#15515) Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * fix(contracts): a context record that cannot be encoded no longer fails the send (pingdotgg#16398) Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * fix(web): open pull request row actions on right-click (pingdotgg#16612) * fix(web): show attempted paths in file preview errors (pingdotgg#15628) * fix(vcs): passive sidebar rows stop retaining remote pollers (pingdotgg#15666) * feat(web): group keybindings settings by area with a page toolbar (pingdotgg#12822) * feat(web): stop T3-owned subagents from Lineage (pingdotgg#15211) * feat(web): add fast actions to linked pull requests (pingdotgg#16627) * feat(web): open right panel tab menu with Mod+T (pingdotgg#15686) Co-authored-by: Julius Marminge <julius0216@outlook.com> * fix(server): provider sessions clean up when their start is interrupted (pingdotgg#15571) Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * fix(web): show "No project" near the top of the new thread picker (pingdotgg#16628) Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * refactor(server): instrument WS RPCs in group middleware (pingdotgg#15548) Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * chore(deps): upgrade @pierre/diffs to 1.5.2 and @pierre/trees to beta.6 (pingdotgg#16644) Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * fix(relay): a host restarting onto a deleted tunnel gets a new one (pingdotgg#16649) Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * fix(server): recover a deleted tunnel when Cloudflare says "Tunnel not found" (pingdotgg#16648) Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * fix(web): iPhone Duo fold controls follow the phone's orientation (pingdotgg#16630) Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * fix(web): keep workspace options when expanding lineage (pingdotgg#16635) * fix(web): preserve bare anchor placeholders in markdown (pingdotgg#16637) * fix(pi): preserve provider identity in discovered models (pingdotgg#16661) Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com> * fix(auth): preserve explicitly granted pairing scopes (pingdotgg#9785) Co-authored-by: Claude Fable 5 <noreply@anthropic.com> * feat(auth): separate environment administration permissions (pingdotgg#9786) Co-authored-by: Claude Fable 5 <noreply@anthropic.com> * feat(auth): separate source control write permissions (pingdotgg#9787) Co-authored-by: Claude Fable 5 <noreply@anthropic.com> * feat(auth): separate filesystem read and write permissions (pingdotgg#9788) Co-authored-by: Claude Fable 5 <noreply@anthropic.com> * feat(auth): separate browser preview control permissions (pingdotgg#9789) Co-authored-by: Claude Fable 5 <noreply@anthropic.com> * feat(auth): separate diagnostics and usage permissions (pingdotgg#9790) Co-authored-by: Claude Fable 5 <noreply@anthropic.com> * feat(auth): allow passive terminal observation (pingdotgg#9791) Co-authored-by: Claude Fable 5 <noreply@anthropic.com> * fix(auth): keep old clients connected across scope changes (pingdotgg#10298) Co-authored-by: Claude Fable 5 <noreply@anthropic.com> * feat(server): hosted agents like ChatGPT can sign in to the T3 MCP server (pingdotgg#16718) Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * docs: connect Claude Code, Codex, ChatGPT and bots over MCP (pingdotgg#16741) Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * fix(web): thread details card gives titles room to read (pingdotgg#16746) Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * fix(mcp): agent HTML pages stop painting slab backgrounds (pingdotgg#16752) Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * fix: composer picks up new project skills without a server restart (pingdotgg#16750) * feat(server): run a project action when a worktree thread settles (pingdotgg#16290) Co-authored-by: spoukyii <61633921+spoukyii@users.noreply.github.com> Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * feat(web): old Claude threads compact on send instead of stacking notices (pingdotgg#16631) Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * fix(server): settled threads stop polling their pull requests (pingdotgg#16762) Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * fix(server): stop storing tool image bytes no client reads (pingdotgg#16652) * fix(server): status refresh no longer pegs CPU in repos with thousands of untracked files (pingdotgg#16771) Co-authored-by: Braulio Oliveira <brauliobo@gmail.com> Co-authored-by: Claude Sonnet 5.5 <noreply@anthropic.com> * perf(server): background branch lookups share one GitHub query per sweep (pingdotgg#16760) Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * fix(server): threads settle as soon as a client sees their PR merge (pingdotgg#16761) Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * feat(server,web,mobile): agents see snooze state and link to threads (pingdotgg#16782) Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * fix(release): Forgejo build resolves version-qualified catalog overrides Upstream now pins overrides such as undici@^8 to the catalog; the packaging script looked up the whole selector and failed. Mirrors upstream pingdotgg#16411. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * fix(server): HTML renders and PDFs load behind a proxy that forbids framing Clients frame asset documents from the environment's origin, which is often not their own. A reverse proxy that adds X-Frame-Options: SAMEORIGIN blanked every HTML render and PDF preview in that setup. Inline HTML and PDF asset responses now carry `frame-ancestors *`, which browsers honour in place of X-Frame-Options. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * fix(server): desktop renderer may frame asset documents CSP's `*` matches only http(s) ancestors, so the desktop app's custom scheme origins are listed explicitly. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> --------- Co-authored-by: Theo Browne <me@t3.gg> Co-authored-by: Project516 <138796702+Project516@users.noreply.github.com> Co-authored-by: Igor Makowski <56691628+Mnigos@users.noreply.github.com> Co-authored-by: Bilal Bakr <62337003+Bil0000@users.noreply.github.com> Co-authored-by: Michel Liao <107891771+Michel-Liao@users.noreply.github.com> Co-authored-by: Ishaan Kothari <ishaanko.mail@gmail.com> Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Co-authored-by: ahalekelly <7078138+ahalekelly@users.noreply.github.com> Co-authored-by: SkiTee3000 <39069192+SkiTee3000@users.noreply.github.com> Co-authored-by: Ashkaan <a@ashkaan.me> Co-authored-by: Julius Marminge <julius0216@outlook.com> Co-authored-by: Erik Thorelli <ethorelli@gmail.com> Co-authored-by: James Villarrubia <8172873+jamesvillarrubia@users.noreply.github.com> Co-authored-by: Yash Singh <saiansh2525@gmail.com> Co-authored-by: Alex Southwell <saphid@gmail.com> Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> Co-authored-by: Tristan Manchester <108270628+tristanmanchester@users.noreply.github.com> Co-authored-by: Arav Jain <aravhawk@gmail.com> Co-authored-by: Sypher760-gif <sayffadil@gmail.com> Co-authored-by: Nikita Koynov <43469098+nkoynov@users.noreply.github.com> Co-authored-by: maria <maria@kuuro.net> Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com> Co-authored-by: Julius Marminge <51714798+juliusmarminge@users.noreply.github.com> Co-authored-by: Jake Leventhal <jakeleventhal@me.com> Co-authored-by: Utkarsh Patil <73941998+UtkarshUsername@users.noreply.github.com> Co-authored-by: Lorenzo <150276837+Bombatomica64@users.noreply.github.com> Co-authored-by: Benedikt Rump <bjrump@gmail.com> Co-authored-by: Stevan Borus <steva.borus@gmail.com> Co-authored-by: Gabriel De Andrade <30420087+gabrielelpidio@users.noreply.github.com> Co-authored-by: spoukyii <61633921+spoukyii@users.noreply.github.com> Co-authored-by: Derek Trimm <275381468+derektrimm@users.noreply.github.com> Co-authored-by: Braulio Oliveira <brauliobo@gmail.com>
Problem
@effect/tsgois pinned at 0.41.0, behind the 0.46.1 that Effect itself uses. 0.41 accepts unknowndiagnosticSeveritykeys without a warning (Effect-TS/tsgo#747), which is howimportFromBarrelsilently stopped running after the move to TSGo.Change
@effect/tsgo0.41.0 → 0.46.1. From 0.46, an unknown rule name fails the typecheck.importFromBarrelcomes out oftsconfig.base.json, since TSGo never ported it. chore(lint): import Effect modules from their subpaths #16326 makes the identical change, so whichever merges first, the other still merges cleanly.nodeBuiltinImporttocrypto,timers, andstream. Instead of excepting what it flags, the code moves onto Effect's services:Crypto. @juliusmarminge's commits here move the remaining hashes and UUIDs, including synchronous helpers and tests. Helpers such ascheckpointRefForScopeOrdinal,remoteStateKey, andclaudePromptUuidbecome Effects that needCrypto.Effect.sleepinstead ofnode:timers/promises.@noble/hashes.Crypto.digestonly hashes a whole buffer, and archives can reach 1 GiB.Cryptolacks: HMAC, signing, key generation or import, ortimingSafeEqual. 16 are in tests, and one is a type-onlystreamimport.unstableApiUsage. It warns on every use ofeffect/http,process,reactivity, and the other unstable modules, about 5,800 times here.TS2790errors that look like a packaging regression.Scope and approval
A toolchain upgrade plus moving Node crypto and timer calls onto Effect services. No behavior change is intended;
@noble/hashesis the one new dependency. @juliusmarminge agreed to the upgrade in a private chat and wrote the second half of the migration. I work at CodeRabbit.Verification
JSON.stringifyfor plain strings, nested objects and arrays,undefinedfields, and non-finite numbers.