Skip to content

v0.9.10: geo, chat fixes, sandbox fixes - #8539

Merged
waleedlatif1 merged 31 commits into
mainfrom
staging
Oct 2, 2026
Merged

waleedlatif1 merged 31 commits into
mainfrom
staging

Conversation

@waleedlatif1

@waleedlatif1 waleedlatif1 commented Oct 1, 2026 •

Copy link
Copy Markdown
Collaborator

waleedlatif1 and others added 13 commits October 1, 2026 10:32
* feat(chat): cycle available composer modes with Shift+Tab

* fix(chat): skip unavailable Search during mode cycling
* docs(library): restore content dropped by automated refreshes

Restore the 1.1x hosted-key rate and BYOK provider list (from #8323), Logs/Chat/Tables operational passages (from #8298), the dated pricing comparison (from #8299), and align the n8n license date (from #8296). Correct BYOK and local-model plan gating and scope Apache 2.0 claims to Sim's core with the Sim Enterprise License noted.

* fix(library): scope BYOK providers by use and qualify hosted fallback and log snapshots

* fix(library): restore sales/CRM FAQ entries and ai-agent-ideas link dropped by a refresh
)

* chore(content): add check:library-content audit for blog, library, and customer posts

Validates frontmatter against the strict ContentFrontmatterSchema, slug/folder parity, local ogImage existence, MDX compilation with remark-gfm, FAQ placement, and internal post links (including retired and moved slugs). Moves the library slug redirect maps into lib/library/retired-slugs.ts so next.config.ts and the audit share one source. Fixes two FAQ answers that rendered Markdown links as literal text.

* fix(content): tighten check:library-content link, author, and ogImage rules

Treat draft blog/library posts and customer stories missing from CUSTOMER_STORIES as unserved link targets, reserve only sibling folders that define a page or route, validate author profiles with AuthorSchema, check moved blog slug destinations, and reject ogImage paths that resolve outside public.
… Sim Enterprise License (#8530)

* fix(library): scope sales/CRM license claims to Sim's Apache 2.0 core and the Sim Enterprise License

* fix(library): scope Sim license claims to the Apache 2.0 core and the Sim Enterprise License
* feat(dashboards): embed live dashboard panels in markdown

* improvement(dashboards): lazy-load markdown dashboard embeds

* fix(dashboards): address review on chart annotations and embed refresh

* fix(dashboards): re-anchor reset embeds and cover the collab placeholder while streaming

* fix(dashboards): scope live refresh to each embed and place the chart starter caret
* fix(accounts): scope organization OAuth outbound requests

* fix(accounts): preserve outbound ownership during reconnect
* fix(wiza): surface Wiza's nested error messages

* fix(wiza): keep plain-text errors and parse reveal polling failures

* fix(wiza): only accept trimmed string messages in error extractor
* fix(chat): preserve per-chat resource panel widths

* fix(chat): finalize panel resizing against current layout

* fix(chat): keep active resizes aligned across chat adoption
* chore(search): remove legacy indexed enterprise search

* fix(search): preserve live onboarding and Slack scope policies

* fix(search): close retired document writes and refresh Search consent

* fix(search): preserve ordinary knowledge base classification
…onses (#8536)

* fix(sandbox): preserve workbench availability for unrecorded API responses

* fix(sandbox): preserve completed table mutation outcomes
…ts (#8537)

* fix(mothership): stop duplicating chat resource tabs in workspace chats

* fix(mothership): scope tool side-effect resources inside handleResourceSideEffects

* fix(mothership): assert emitted resource events instead of mock calls
…8534)

* chore(search): add paced projection replacement and data retirement

* chore(search): keep retirement usage in the CLI

* fix(db): fence schema push and require direct retirement sessions

* fix(db): preserve test connection URL parameters
@waleedlatif1
waleedlatif1 requested a review from a team as a code owner October 1, 2026 20:36
@vercel

vercel Bot commented Oct 1, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
docs Ready Ready Preview Oct 2, 2026 3:35am UTC

Request Review

@cubic-dev-ai cubic-dev-ai Bot left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

1 issue found across 404 files

Confidence score: 3/5

  • In sandbox-resource-transport.ts, GET /api/v2/secrets can return stored values for unredacted workspace secrets, but this branch only logs and leaves workbench provenance unchanged. Record the response as unknown or update the secret provenance.
Prompt for AI agents (unresolved issues)

Check if these issues are valid — if so, understand the root cause of each and fix them. When an issue isn't valid or won't be fixed in this PR, reply in its thread with the reason and then resolve the thread. If appropriate, use sub-agents to investigate and fix each issue separately.


<file name="apps/sim/lib/mothership/tools/sandbox-resource-transport.ts">

<violation number="1" location="apps/sim/lib/mothership/tools/sandbox-resource-transport.ts:155">
P1: `GET /api/v2/secrets` can return stored values for unredacted workspace secrets, but this branch only logs and leaves the workbench provenance unchanged. Record such responses as unknown or observe their secret provenance before returning them, so later workbench output cannot expose the plaintext.</violation>
</file>

Note: This PR contains a large number of files. cubic selects up to 200 of the highest-priority eligible files for this review, so some files may not have been reviewed.
Tip: instead of fixing issues one by one fix them all with cubic

Re-trigger cubic

Comment thread apps/sim/lib/credential-groups/service.ts Outdated
Comment thread packages/db/maintenance/search-retirement-health.ts
Comment thread packages/db/knowledge-projection.ts
Comment thread packages/db/maintenance/search-retirement.ts
Comment thread packages/db/scripts/push.ts
Comment thread apps/sim/lib/mothership/tools/server/knowledge/workspace-search.ts Outdated
Comment thread apps/sim/lib/dashboards/time.ts
Comment thread apps/sim/lib/charts/annotations.ts
Comment thread packages/db/schema.ts Outdated
Comment thread scripts/check-library-content.ts Outdated
@greptile-apps

greptile-apps Bot commented Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

RetriggerConfidence Score: 4/5

[High risk] Removes indexed search backend and related API routes.

The PR appears safe to merge, with a non-blocking panel-collapse edge case to address.

Findings

  1. P2 Collapsed panel stays expanded ▶

Summary

This PR adds chat composer shortcuts and persistent panel widths, embeds live dashboard panels in markdown, adjusts OAuth and sandbox handling, audits library content, and retires the legacy indexed Search path.

  • The panel resize lifecycle needs to respect an automatic collapse that occurs mid-gesture.
Diagram
%%{init: {'theme': 'neutral'}}%%
flowchart LR
  A[Resource list becomes empty] --> B[Panel state becomes collapsed]
  B --> C[Active drag defers width restoration]
  C --> D[Gesture ends]
  D --> E[Expanded inline width is restored]
Loading

Reviews (1) · Last reviewed commit: "chore(search): add paced projection repl..."

… check:library-content (#8540)

* fix(library): ignore sentence punctuation after bare internal URLs in check:library-content

* fix(library): only strip trailing punctuation from bare URLs, not explicit link targets
…lake (#8544)

* fix(ci): isolate HTTP end-to-end suites and stop the SCIM readiness flake

The SCIM step cold-compiles the app under next dev before its first
request; readiness took 42-150s on 8 vCPU runners against a fixed 120s
deadline, so the slow tail failed. It also ran on both provisioning legs
of the integration matrix, which are the PR critical path (~13 min).

- Move SCIM and the four search HTTP suites into their own job with its
  own database, off the integration legs and run once against migrate.
- Readiness waits up to 300s, fails fast if the server exits, prints the
  server log tail, and uploads the server log with the reports.
- Factor Bun/Node/cache/install setup into a setup-workspace action.

* fix(ci): drop SCIM step timeout and update the SCIM CI guide
…hold axis from first series (#8541)

* fix(dashboards): keep DST fall-back range endpoints and resolve threshold axis from first series

* fix(dashboards): reject invalid first-series axis refs and show exclusive end for sub-minute ranges

* fix(dashboards): show inclusive range end in exact caption and cover id/x-axis threshold lookups

* fix(charts): resolve threshold axis by index before id, matching ECharts
* fix(search): correct onboarding and live citations

* fix(search): clear onboarding readiness after credential disconnect
TheodoreSpeaks and others added 2 commits October 1, 2026 18:04
* improvement(files): theme mermaid diagrams with app tokens

* feat(files): render diff fences with source-checked state

* improvement(files): frame diffs as cards with tinted change rows

* improvement(files): render prose diffs as source excerpt cards and compare two documents

* improvement(files): put the open link beside the excerpt title

* improvement(files): render inline bold and code in prose diffs

* improvement(files): render edits as line diffs with softer change colors

* improvement(files): draw mermaid flowcharts like workflow blocks and edges

* fix(files): keep mermaid labels inside their nodes and fork edges cleanly

* improvement(files): drop diff source checks and split view, size tables to content

* improvement(files): keep the diff parser out of the editor bundle

* fix(files): parse multi-file and copy git diffs, cap word diffs, readable pie labels

* fix(files): title renames by their new path and expand collapsed lines one run at a time
…8545)

* fix(slack): verify Search permissions before changing active grants

* fix(slack): bind authorization to every Search approval state

* chore(tests): require Redis for Slack authorization integration
…8546)

* fix(mothership): bound stream recovery and hand off only on a lost lease

A recovered Chat controller that failed to persist an event for any reason
other than a budget refusal was treated as superseded, so it left its run
recoverable without finalizing. Every reconnect poll then claimed the run
again and re-POSTed it to the worker, for as long as a tab stayed open.

- Only a lease another controller holds is a hand-off. A failed leased append
  latches StreamPersistenceFailedError in the writer, like a budget refusal:
  the turn ends as an error through the existing terminal path, which settles
  the run and stops the worker run. An unreadable lease proves nothing, so the
  fenced writes that follow decide ownership.
- Refusals, persistence failures and recovery exhaustion share one
  StreamTurnFailure base that the lifecycle classifies as an error, never a
  cancellation or a hand-off.
- Recovery takeovers carry a per-run budget in the run's request context,
  written in the same token-compared claim UPDATE, so it covers every pod, tab
  and caller. The first takeover is immediate; later ones wait an exponential
  backoff (1 s base, 60 s cap). After 5 takeovers without a controller staying
  alive for 5 minutes, the next claim ends the run as an error and stops the
  worker run. Each claim logs one line with its attempt number.

* fix(mothership): hand off a failed replay append again, bounded by the recovery budget

Ending the turn on any leased append error that was not a lost lease turned a
short Redis blip (a failover READONLY or a connection reset that outlasts the
append retries) into a failed Chat turn and a worker stop. Before, that turn was
handed off and a successor completed it.

- A failed append that is not a budget refusal hands off again, as on staging.
  The per-run recovery budget bounds a persistent failure: MAX_RECOVERY_ATTEMPTS
  takeovers with backoff, and then the run ends as stream_recovery_exhausted.
- Drop StreamPersistenceFailedError and stream_persistence_failed. The writer
  only latches budget refusals again, and finalizeAsError surfaces a failed
  terminal append as it did before.
- Keep the change that an unreadable lease is not a hand-off. Its test now
  fails a lease read alone: a corrupted lock key also fails the fenced append,
  which is now a hand-off.
- Storm suite: a single failed append hands off and the next controller
  completes the turn. A persistent append failure exhausts the budget, the same
  as a lease lost with no successor.

* fix(mothership): claim a recovering run only once its takeover can start

Recovery claimed the run before reading its replay, resolving billing and
checking access. A takeover that then failed released the lock but had already
spent an attempt and refreshed the run, so an exhausted run whose takeover kept
failing there stayed active, and the refreshed row kept the orphan sweep away.

Claim last: a takeover that fails before it starts leaves the run untouched,
and an exhausted claim always reaches the terminal path.
…he request path (#8535)

* improvement(cron): run stale execution cleanup as a background task

* fix(cron): run sync-log retention test against the cleanup task

* fix(cron): assert stale cleanup route by its response only

* fix(cron): cover stale cleanup dispatch window through the route response

* improvement(cron): dispatch file version cleanup from a background task

* fix(cron): retry and serialize cleanup dispatch on the task definition
* fix(slack): honor implicit Search approval during authorization

* fix(slack): serialize Search approval changes with consent
…orepo (#8549)

* chore(skills): vendor codebase-design deep-module vocabulary skill

* chore(cleanup): remove dead client hooks, query exports, and orphaned scheduled-tasks utils

* refactor(queries): concentrate workflow search MCP list fetches into two helpers

* chore(cleanup): dedupe app copies of shared package helpers

- import subflow helpers from @sim/workflow-persistence/subflow-helpers
- drop env-capabilities and service-account-metadata re-export shims
- use isWorkflowBlockProtected in block-enablement
- move anonymous user identity into @sim/auth/principal
- reuse isLightTileColor from @sim/workflow-renderer/tile-icon-color
- use @sim/utils sleep/getErrorMessage in sim-cli (bundled)
- remove dead normalizeSandboxProvider export

* chore(cleanup): trim log-views to toOverview and use interruptibleSleep in data drains

* chore(cleanup): use @sim/utils/object helpers in internal clients and drop dead vanta input-size

* chore(cleanup): remove dead logs types, organization utils, and workspace permission queries

* chore(cleanup): remove dead custom-tool use cases and unused folder, slack-search, skills, and selector helpers

* chore(cleanup): remove unreachable application use cases and API helpers

Delete test-only Copilot/executor use cases (bulk table rows by filter,
credential delete-many, credential-group invite send/link, sandbox and
connected-accounts adapters) with their operation entries, the unused
public API route wrapper, parseToolRequest, the invitation management
error policy, the execution invitation rate limit, and dead table/chat
route helpers.

* chore(cleanup): remove dead application use cases and utils, share workflow context resolver

- Delete unreachable platform-context, workflow VFS, deployment-overview, chat
  undeploy, and Copilot block-output/upstream-reference use cases plus their
  workflowOperations entries
- Delete dead fetch-deadline and scheduling utils and unused exported helpers
- Add resolvePrincipalWorkflowContext and use it at the 16 identical resolvers
- Share processCodeFailure between the Daytona and E2B adapters
- Use escapeRegExp and generateId in place of inline equivalents

* chore(cleanup): remove unreferenced Copilot table commands, workflow mutation handlers, and param types

chore(cleanup): drop unused billing client usage-pill and plan-view exports

* chore(cleanup): share webhook provider config, notification URL, and credential token helpers

* chore(cleanup): remove dead billing, credential, MCP, and API key exports

* chore(cleanup): remove dead executor helpers and redundant LoopConfigWithNodes type

* refactor(executor): export subflow node-id codec functions directly and drop forwarders

* refactor(providers): drop pass-through model wrappers and share the json_schema response format builder

* chore(cleanup): remove dead executor, tools, and block registry exports

* chore(cleanup): remove unreachable workspace-file and table use cases

* chore(cleanup): reuse knowledge tag slot constants in the tags service

* chore(cleanup): share escapeLikePattern from @sim/utils/string

* chore(cleanup): reuse zip-guard EOCD parsing in the file sniffer

* chore(cleanup): use isRecordLike for inline record guards

* chore(cleanup): remove dead uploads, tokenization, table, knowledge, and search exports

* chore(cleanup): use shared escapeLikePattern in list-query and logs filters

* docs(skills): align codebase-design testing guidance with repo rules and add its license

* chore(cleanup): cascade-remove use cases, helpers, and mocks orphaned by deleted Copilot commands

* chore(cleanup): consolidate shared helpers and restore TSDoc on moved codec and subflow helpers

* test(cleanup): port storage-cleanup ownership tests and drop stale mock keys

* test(scripts): follow model-access import move in application-graph fixture

* chore(skills): drop vendored codebase-design skill from the repo
…8551)

* chore(lint): delete commented-out code

Removes dead sub-block configs from the Human in the Loop and Greptile
blocks and an unused commented-out DisplayMode type. The docs generator
read the commented-out greptile_search entry in tools.access, so the
generated Greptile docs advertised a disabled operation; regenerated.

* improvement(audits): add check:comment-hygiene

Fails on banner separator comments and on line comments whose text
parses as TypeScript (commented-out code). Comments come from the Babel
token stream so strings are never inspected; prose lines split comment
groups, and labels, literals and one-off glosses are rejected, giving
zero false positives across the tree. Change-history phrasing was
measured and left out because most hits describe live state.

* chore(lint): remove banner separators and narrating comments

Converts decorated section banners to plain comments or drops them, and
sweeps the noisiest files for comments that restate the code or name
what follows. Field-level notes that carry units, enums or invariants
move to TSDoc. Comment-only: the non-comment token stream of every
changed file is identical.

* fix(audits): fail comment-hygiene on unparsable files, raise listing buffer, correct ribbon arc note
* feat(workflows): describe container changes and build a canvas diff overlay

The comparison engine now reports which loop and parallel fields changed and
which blocks entered or left a container, and exposes the field lists and a
shared hasChanges helper. A new overlay module merges two workflow states into
one canvas: removed blocks, containers and edges ride along as ghosts at their
old positions (nudged clear of live cards), deleted condition and router
branches stay on the surviving card so their ghost edge keeps a handle, and
every edge is classified by canonical port key. The renderer edge view gains a
quiet ghost style for those removed connections.

* feat(preview): paint comparison status on the read-only canvas

The preview canvas accepts per-block and per-edge diff status: added and
modified cards get a ring and a shared status label, removed cards and
containers fade to a ghost, changed sub-block rows and sentence chips tint,
and ghost edges sit under live ones so a rewired port shows the new line on top.

* feat(workflows): version diff view with a field-level change list

Side-by-side view of two workflow states: the overlaid canvas on the left and a
change list on the right, sharing selection. Each touched block is a collapsible
card with the app's block tile; modified blocks show field rows as folded line
diffs with word marks, item-by-item list diffs for tools, conditions, routes and
input fields, old to new pairs for scalars, and only the fact for secrets. Added
and removed blocks show every field diffed against nothing, with long one-sided
bodies capped behind one expander. Fork comparisons group credentials, picked
resources and trigger paths into a muted environment bindings section.

* feat(deploy): compare deployment versions and the draft

The deploy modal offers "View changes" (live against the draft) when a redeploy
is pending and a "Compare" action on every version row, opening a full-width
comparison whose two sides are pickable from the header. The draft state hook is
shared with change detection and only subscribes while something to compare
against exists.

* feat(forks): preview one workflow's block-level changes before a sync

The synced deployed workflows list gets a "View changes" action per row. A new
internal route and fork use case return the target as its editor holds it and
the source deployment re-keyed into the target's block ids through the fork block
map (or the derived id the sync would assign), with condition and route ids and
variable ids aligned, so the two sides diff block for block like two versions of
one workflow.

* fix(workflows): harden the version diff after review

Comparison: keep basic/advanced mode changes visible, include a tool's
permission, server and implementation fields in list diffs, include input field
defaults, read checkbox records as records, show whitespace-only edits, cap word
and line diffing so a pathological prompt cannot stall the pane, slot deleted
branches back at their old position, never reuse a ghost edge id, and mask
secret-looking keys at any depth (including key/value table rows) with a
name-based fallback when a block definition is unknown.

Change list: memoized cards that only re-render when their own selection
changes, nested cards for blocks inside an added or removed container, a
shared sign map, muted tokens that exist, hover and focus treatment, scroll
edge fades, and a shared skeleton for both hosts.

Fork preview: the before side is the target draft the sync overwrites, read
in one snapshot and scoped to the target workspace; variables and their
assignments are re-keyed by unique name; a create reports no target id; the
change rows are a discriminated union; the query key sits under the fork diff
keys so a sync invalidates it; a direction switch closes the preview.

* fix(workflows): scope the fork preview to one workflow and close review gaps

- Fork "View changes" now loads only the previewed workflow: its deployed
  state, its identity mapping, its target row and its block pairs, instead of
  every deployed state in the source workspace plus the full promote plan.
  The plan item comes from the same buildForkPromotePlanItems decision the
  promote uses. The route gets a per-user rate limit.
- Word marks give up past 64 edits per line pair, so many long rewritten
  lines cannot stall the tab.
- Agent tool params that their block marks as password fields are masked
  whatever their name.
- A list item whose label changed but whose body did not is no longer
  flagged as a masked value change.
- Hoist double casts under their annotations, make sourceWorkflowId
  optional on the wire for rollout, lazy-load both diff modals, and
  re-record the settings module baseline: the block registry the diff canvas
  needs is reached only through the lazy chunk opened on click.

* test(forks): use a neutral workflow name in preview fixtures

* fix(forks): offer "View changes" only on workflows the sync changes

- Sync details load each replaced target's draft and diff it against the
  projected source, using the same projection and "has changes" rule as the
  per-workflow preview, so a row and its preview never disagree. Rows the sync
  would not change read "No changes" and offer no comparison.
- Preview buttons wait until the list matches the selected direction.
- Mask JSON-encoded secrets in text and scalar fields, and say "A masked
  value changed" when masking hides the only difference.
- Show role changes on agent messages, highlight a router's changed Context
  on the canvas, and keep ghost edges under live ones into containers.
- Added or removed loops and parallels list their iteration settings.
- Size ghost containers the way the preview draws them.
- "Order changed" only when items moved; CRLF and CR read as line breaks;
  collapsing unchanged lines closes every fold; selecting a nested block
  opens its container card; the version pickers have distinct names.
- Drop redundant mock resets flagged by check:test-patterns.

* fix(workflows): bound the sync change check and tighten diff rendering

- The sync list's per-workflow change check measures the target drafts in one
  query first and skips itself past the fork state limit, then reads drafts a
  few at a time and drops each after comparing, instead of holding them all.
- Mask keys with a secret word anywhere in them (secretAccessKey,
  aws_secret_access_key) while credential references stay readable.
- Inline diffs show whitespace-only changes.
- Opened folds reset when the compared bodies change.
- Ghost collision boxes use the canvas's own block measurement.

* fix(workflows): mask message text, count all block columns, reset selection per comparison

- Agent message bodies go through the same masking as other text fields.
- The sync change check's size guard counts block outputs and data, not only sub-blocks.
- Picking another version clears the block selection.

* fix(workflows): scope selection reset to picked versions and test outcomes, not mock calls

- Key the comparison view by the picked version pair instead of resetting on state identity, so live draft updates no longer clear the selection.
- Agent message changes hidden by masking say so, like other fields.
- Fork preview tests assert results, with mocks that answer only the right arguments, instead of asserting mock calls.

* fix(workflows): only call a message change masked when the message exists on both sides

* test(workflows): use absolute imports in new tests

* fix(workflows): unify version comparison and simplify diff UI

* fix(workflows): compare against previous saved version by default

* fix(workflows): preserve comparison semantics and preview ports

* feat(workflows): render structured version changes by subblock type

* fix(api): remove stale OpenAPI operation count assertions

* fix(workflows): preserve scoped fields and snapshot ports

* fix(workflows): preserve version-specific container labels

* fix(workflows): retain tool context when masking encoded params

---------

Co-authored-by: Vikhyath Mondreti <vikhyath@simstudio.ai>
* fix(files): align workbench reads with provenance policy

* fix(files): validate snapshots and audit completed admissions

* fix(files): audit completed workbench transfers
)

* fix(cli): report authentication accurately and preserve file text

* fix(cli): preserve whoami compatibility diagnostics
…es repo-wide (#8554)

* chore(lint): remove unused catch bindings, dead private types, and unused loggers

* chore(lint): delete unused variables and parameters across apps

Remove dead locals, constants, helpers, test mock aliases, and unused
function parameters (updating callers), drop the unused BlockConfig type
parameter and the response types that only fed it.

* improvement(lint): enforce noUnusedVariables and noUnusedFunctionParameters repo-wide

Enable both rules as errors at the root with no autofix, so bun run lint
never mass-renames bindings to _x, and ignoreRestSiblings so the
{ a, ...rest } omit idiom stays legal. The packages/** override is now
redundant and removed. Document the rule in CLAUDE.md.

* docs: drop BlockConfig type argument from contributing example; fix stale run-options note

* fix(resume): update the per-context form cache outside the state updater
…ames (#8550)

* improvement(audits): ratchet knip unused exports, types, and duplicates

check:unused-exports runs knip once with the dead-code issue types gated at
zero plus exports/types/duplicates compared against a shrink-only baseline
of path#symbol entries. Package entry exports stay public surface via an
explicit includeEntryExports: false. run-audits skips check:dead-code since
this pass covers it.

* improvement(audits): ratchet explicit any and non-null assertions per file

check:explicit-any runs Biome's noExplicitAny and noNonNullAssertion rules
(off repo-wide) and fails when a file's count rises or drops without a
baseline update.

* improvement(audits): enforce file naming conventions with a ratchet

check:file-names flags non-kebab-case paths, utils/helpers files that repeat
their folder's role, and files that repeat their parent folder's name, with
the expected short name in the failure output.

* docs(agents): point naming and any rules at their checks; run root test in ship gate

* improvement(audits): make baseline updates shrink-only and tolerate biome diagnostic exit codes

* improvement(audits): fail closed on missing baselines, write nothing on refused updates, flag utils/utils.ts

* improvement(audits): include root scripts in the explicit-any ratchet

* fix(audits): gate every knip issue type and exclude generated contracts from the export ratchet

knip's dependencies include also reports optionalPeerDependencies, which the
strict list dropped. Gate every non-ratchet issue key so a new type fails
closed. Generated contract files are excluded via ignoreIssues so rerunning
their generators cannot trip the ratchet (359 baseline entries dropped).
Print a rename hint when a baselined symbol moves files.

* improvement(audits): lint tracked uploads source, reject any/! suppressions, name-check root scripts

Anchor biome's build/out/uploads ignores to the real output and runtime
dirs so apps/sim/lib/uploads and the uploads API routes are linted and
counted by check:explicit-any (baseline grows only under those paths).
check:explicit-any fails on biome-ignore comments for its two rules.
check:file-names scans root scripts/ and vitest.shared.ts, allows Next.js
interception segments and dot-prefixed names, ignores the old path of an
unstaged mv, and points tool-mandated names at its allowlist. All three
ratchets print a rename hint instead of only the shrink instruction.

* improvement(audits): rebaseline ratchets on current staging, lint newly covered uploads files, anchor suppression detection to comments

* improvement(audits): fail on unparsable files, refuse suppressed updates, require balanced dynamic segments
Comment thread scripts/check-file-names.ts Dismissed
… test (#8556)

The test disabled only sequential scans, so the planner could still answer a page with a
bitmap scan that reads every remaining row. Which plan it chose depended on whether
autovacuum had analyzed the fresh fixture rows, making the read-count assertion flaky in CI.
Analyze the table and disable bitmap scans too, matching production's primary-key walk.
@waleedlatif1
waleedlatif1 merged commit 43cd243 into main Oct 2, 2026
73 checks passed

This branch was successfully deployed

1 active deployment
Preview — 70412cc8 Deployed Oct 2, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants