Commit Graph
14100 Commits
Author SHA1 Message Date
dependabot[bot] 44b0fa4065 chore: bump github.com/valyala/fasthttp from 1.70.0 to 1.71.0 (#24958)
Bumps [github.com/valyala/fasthttp](https://github.com/valyala/fasthttp)
from 1.70.0 to 1.71.0.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/valyala/fasthttp/releases">github.com/valyala/fasthttp's
releases</a>.</em></p>
<blockquote>
<h2>v1.71.0</h2>
<h2>What's Changed</h2>
<ul>
<li>feat(client): add RetryIfErrUpstream function to handle upstream
information by <a
href="https://github.com/mdenushev"><code>@​mdenushev</code></a> in <a
href="https://redirect.github.com/valyala/fasthttp/pull/2176">valyala/fasthttp#2176</a></li>
<li>Match net/http sensitive header redirect policy by <a
href="https://github.com/erikdubbelboer"><code>@​erikdubbelboer</code></a>
in <a
href="https://redirect.github.com/valyala/fasthttp/pull/2181">valyala/fasthttp#2181</a></li>
<li>Sanitize first-line header setters to prevent CRLF injection by <a
href="https://github.com/erikdubbelboer"><code>@​erikdubbelboer</code></a>
in <a
href="https://redirect.github.com/valyala/fasthttp/pull/2182">valyala/fasthttp#2182</a></li>
<li>server: apply ReadTimeout before first byte with ReduceMemoryUsage
by <a
href="https://github.com/erikdubbelboer"><code>@​erikdubbelboer</code></a>
in <a
href="https://redirect.github.com/valyala/fasthttp/pull/2183">valyala/fasthttp#2183</a></li>
<li>header: reject invalid trailer names by <a
href="https://github.com/erikdubbelboer"><code>@​erikdubbelboer</code></a>
in <a
href="https://redirect.github.com/valyala/fasthttp/pull/2188">valyala/fasthttp#2188</a></li>
<li>header: reject pre-colon whitespace in request headers by <a
href="https://github.com/erikdubbelboer"><code>@​erikdubbelboer</code></a>
in <a
href="https://redirect.github.com/valyala/fasthttp/pull/2187">valyala/fasthttp#2187</a></li>
<li>Sanitize redirect Location header to prevent CRLF injection by <a
href="https://github.com/erikdubbelboer"><code>@​erikdubbelboer</code></a>
in <a
href="https://redirect.github.com/valyala/fasthttp/pull/2186">valyala/fasthttp#2186</a></li>
<li>server: keep hijacked reader out of pool by <a
href="https://github.com/erikdubbelboer"><code>@​erikdubbelboer</code></a>
in <a
href="https://redirect.github.com/valyala/fasthttp/pull/2184">valyala/fasthttp#2184</a></li>
<li>Sanitize cookie setters to prevent CRLF injection by <a
href="https://github.com/erikdubbelboer"><code>@​erikdubbelboer</code></a>
in <a
href="https://redirect.github.com/valyala/fasthttp/pull/2185">valyala/fasthttp#2185</a></li>
<li>feat: add ExpectHandler for richer Expect: 100-continue handling by
<a href="https://github.com/miretskiy"><code>@​miretskiy</code></a> in
<a
href="https://redirect.github.com/valyala/fasthttp/pull/2175">valyala/fasthttp#2175</a></li>
<li>http: reject whitespace before chunk extensions by <a
href="https://github.com/erikdubbelboer"><code>@​erikdubbelboer</code></a>
in <a
href="https://redirect.github.com/valyala/fasthttp/pull/2193">valyala/fasthttp#2193</a></li>
<li>header: reject unsupported response Transfer-Encoding by <a
href="https://github.com/erikdubbelboer"><code>@​erikdubbelboer</code></a>
in <a
href="https://redirect.github.com/valyala/fasthttp/pull/2192">valyala/fasthttp#2192</a></li>
<li>header: match net/http CL+TE handling by <a
href="https://github.com/erikdubbelboer"><code>@​erikdubbelboer</code></a>
in <a
href="https://redirect.github.com/valyala/fasthttp/pull/2190">valyala/fasthttp#2190</a></li>
<li>chore(deps): bump securego/gosec from 2.25.0 to 2.26.1 by <a
href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
in <a
href="https://redirect.github.com/valyala/fasthttp/pull/2195">valyala/fasthttp#2195</a></li>
<li>chore(deps): bump github.com/klauspost/compress from 1.18.5 to
1.18.6 by <a
href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
in <a
href="https://redirect.github.com/valyala/fasthttp/pull/2196">valyala/fasthttp#2196</a></li>
<li>feat(prefork): Enhance prefork management with WatchMaster,
CommandProducer, and Windows support by <a
href="https://github.com/ReneWerner87"><code>@​ReneWerner87</code></a>
in <a
href="https://redirect.github.com/valyala/fasthttp/pull/2180">valyala/fasthttp#2180</a></li>
</ul>
<h2>New Contributors</h2>
<ul>
<li><a href="https://github.com/miretskiy"><code>@​miretskiy</code></a>
made their first contribution in <a
href="https://redirect.github.com/valyala/fasthttp/pull/2175">valyala/fasthttp#2175</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/valyala/fasthttp/compare/v1.70.0...v1.71.0">https://github.com/valyala/fasthttp/compare/v1.70.0...v1.71.0</a></p>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/valyala/fasthttp/commit/e9208ecebf0c102176bb0635043c17333b10401d"><code>e9208ec</code></a>
Revert &quot;feat(prefork): graceful shutdown, leak fixes, hook
robustness&quot; commit</li>
<li><a
href="https://github.com/valyala/fasthttp/commit/481e579af9e7d79f9ce27909edd2c42ef9dce173"><code>481e579</code></a>
feat(prefork): Enhance prefork management with WatchMaster,
CommandProducer, ...</li>
<li><a
href="https://github.com/valyala/fasthttp/commit/805cd1046567aa8a8b97a8bfe9e7b411621f68b2"><code>805cd10</code></a>
Add note on MaxResponseBodySize compatibility with
StreamResponseBody</li>
<li><a
href="https://github.com/valyala/fasthttp/commit/5b5c1be52ca382dcea0ed86931b3f1d2aba9dce6"><code>5b5c1be</code></a>
chore(deps): bump github.com/klauspost/compress from 1.18.5 to 1.18.6
(<a
href="https://redirect.github.com/valyala/fasthttp/issues/2196">#2196</a>)</li>
<li><a
href="https://github.com/valyala/fasthttp/commit/d6a99db432025de9ae13051cb42b3e6c3d6568a3"><code>d6a99db</code></a>
chore(deps): bump securego/gosec from 2.25.0 to 2.26.1 (<a
href="https://redirect.github.com/valyala/fasthttp/issues/2195">#2195</a>)</li>
<li><a
href="https://github.com/valyala/fasthttp/commit/f36c9009027f81f4fbf304822f96752517b08949"><code>f36c900</code></a>
header: match net/http CL+TE handling (<a
href="https://redirect.github.com/valyala/fasthttp/issues/2190">#2190</a>)</li>
<li><a
href="https://github.com/valyala/fasthttp/commit/0b4cede30fa0eb22f9d10999e23ebaabba15e107"><code>0b4cede</code></a>
header: reject unsupported response Transfer-Encoding (<a
href="https://redirect.github.com/valyala/fasthttp/issues/2192">#2192</a>)</li>
<li><a
href="https://github.com/valyala/fasthttp/commit/c497746f7d52ab88597dc88310e7f797cc7755aa"><code>c497746</code></a>
http: reject whitespace before chunk extensions (<a
href="https://redirect.github.com/valyala/fasthttp/issues/2193">#2193</a>)</li>
<li><a
href="https://github.com/valyala/fasthttp/commit/97b38d3a4884b7c3d8891750a4c752073bc3c152"><code>97b38d3</code></a>
server: document SaveMultipartFile path trust requirement</li>
<li><a
href="https://github.com/valyala/fasthttp/commit/19e4b24955fb0ef764229802378a5e36ae7a822b"><code>19e4b24</code></a>
feat: add ExpectHandler for richer Expect: 100-continue handling (<a
href="https://redirect.github.com/valyala/fasthttp/issues/2175">#2175</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/valyala/fasthttp/compare/v1.70.0...v1.71.0">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=github.com/valyala/fasthttp&package-manager=go_modules&previous-version=1.70.0&new-version=1.71.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)


</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-05-05 11:19:28 +00:00
dependabot[bot] a970ffdac8 chore: bump github.com/gohugoio/hugo from 0.160.0 to 0.161.1 (#24957)
Bumps [github.com/gohugoio/hugo](https://github.com/gohugoio/hugo) from
0.160.0 to 0.161.1.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/gohugoio/hugo/releases">github.com/gohugoio/hugo's
releases</a>.</em></p>
<blockquote>
<h2>v0.161.1</h2>
<h2>What's Changed</h2>
<ul>
<li>resources: Honor Retry-After header in resources.GetRemote retries
c4eba928 <a href="https://github.com/bep"><code>@​bep</code></a> <a
href="https://redirect.github.com/gohugoio/hugo/issues/14828">#14828</a></li>
<li>warpc: Move to parson.c in <a
href="https://github.com/kgabis/parson">https://github.com/kgabis/parson</a>
8b40a96b <a href="https://github.com/bep"><code>@​bep</code></a> <a
href="https://redirect.github.com/gohugoio/hugo/issues/14823">#14823</a></li>
<li>config/security: Add AllowChildProcess to security.node.permissions
d65af84d <a href="https://github.com/bep"><code>@​bep</code></a> <a
href="https://redirect.github.com/gohugoio/hugo/issues/14824">#14824</a></li>
<li>config/security: Restrict default http.urls &quot;@&quot; deny to
userinfo 454450a6 <a
href="https://github.com/bep"><code>@​bep</code></a> <a
href="https://redirect.github.com/gohugoio/hugo/issues/14825">#14825</a></li>
</ul>
<h2>v0.161.0</h2>
<p>This release contains two security hardening fixes:</p>
<ul>
<li>We now run the Node tools PostCSS, Babel and TailwindCSS, by
default, with the <code>--permission</code> flag with the permissions
defined in <a
href="https://gohugo.io/configuration/security/">security.node.permissions</a>.
This means that you need Node &gt;= 22 installed and that
<code>css.TailwindCSS</code> now requires that the Tailwind CSS CLI must
be installed as a Node.js package. The <a
href="https://github.com/tailwindlabs/tailwindcss/releases/latest">standalone
executable</a> is no longer supported</li>
<li>We have made the defaults in <a
href="https://gohugo.io/configuration/security/#httpurls">security.http.urls</a>
more restrictive.</li>
</ul>
<p>But there are some notable new features, as well:</p>
<h2>Nested vars support in css.Build and css.Sass</h2>
<p>A practical example in <code>css.Build</code> would be to have
something like this in <code>hugo.toml</code>:</p>
<pre lang="toml"><code>[params.style]
primary =
&quot;[#000000](https://github.com/gohugoio/hugo/issues/000000)&quot;
    background = &quot;#ffffff&quot;
    [params.style.dark]
        primary    = &quot;#ffffff&quot;
background =
&quot;[#000000](https://github.com/gohugoio/hugo/issues/000000)&quot;
</code></pre>
<p>And in the stylesheet:</p>
<pre lang="css"><code>@import &quot;hugo:vars&quot;;
@import &quot;hugo:vars/dark&quot; (prefers-color-scheme: dark);
<p>:root {
color-scheme: light dark;
}
</code></pre></p>
<h2>Slice-based permalinks config</h2>
<p>The <code>permalinks</code> configuration is now much more flexible
(the old setup still works). It uses the same <a
href="https://gohugo.io/configuration/cascade/#target">target</a>
matchers as in the <code>cascade</code> config, meaning you can now
do:</p>
<pre lang="yaml"><code>permalinks:
  - target:
      kind: page
      path: &quot;/books/**&quot;
&lt;/tr&gt;&lt;/table&gt; 
</code></pre>
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/gohugoio/hugo/commit/ea8f66a7ce988664dcc84c052fc96757042e2e4a"><code>ea8f66a</code></a>
releaser: Bump versions for release of 0.161.1</li>
<li><a
href="https://github.com/gohugoio/hugo/commit/c4eba92863bbb988b23e63af40a22d6661b0ced6"><code>c4eba92</code></a>
resources: Honor Retry-After header in resources.GetRemote retries</li>
<li><a
href="https://github.com/gohugoio/hugo/commit/8b40a96b6e992fbacd8626c24168889f50152808"><code>8b40a96</code></a>
warpc: Move to parson.c in <a
href="https://github.com/kgabis/parson">https://github.com/kgabis/parson</a></li>
<li><a
href="https://github.com/gohugoio/hugo/commit/d65af84d1572326057a9a55e26beb0cee784698a"><code>d65af84</code></a>
config/security: Add AllowChildProcess to security.node.permissions</li>
<li><a
href="https://github.com/gohugoio/hugo/commit/454450a647111e5e0b41af595b310f3062c5630e"><code>454450a</code></a>
config/security: Restrict default http.urls &quot;@&quot; deny to
userinfo</li>
<li><a
href="https://github.com/gohugoio/hugo/commit/2bfcc6b9941724cd1d0b490583e89413d7a66979"><code>2bfcc6b</code></a>
releaser: Prepare repository for 0.162.0-DEV</li>
<li><a
href="https://github.com/gohugoio/hugo/commit/98d396c16a07b51df06e7673d817a3880da6218d"><code>98d396c</code></a>
releaser: Bump versions for release of 0.161.0</li>
<li><a
href="https://github.com/gohugoio/hugo/commit/d4ae662d598db81d239a291bc26336be5fec6893"><code>d4ae662</code></a>
build(deps): bump github.com/getkin/kin-openapi from 0.135.0 to
0.137.0</li>
<li><a
href="https://github.com/gohugoio/hugo/commit/9ede5fb9e0304d3eb193b3c1a9214c735f05db21"><code>9ede5fb</code></a>
build(deps): bump github.com/mattn/go-isatty from 0.0.21 to 0.0.22</li>
<li><a
href="https://github.com/gohugoio/hugo/commit/833a878eef4fce2bbabb05dcbb8a7e31f93aadda"><code>833a878</code></a>
build(deps): bump github.com/tdewolff/minify/v2 from 2.24.12 to
2.24.13</li>
<li>Additional commits viewable in <a
href="https://github.com/gohugoio/hugo/compare/v0.160.0...v0.161.1">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=github.com/gohugoio/hugo&package-manager=go_modules&previous-version=0.160.0&new-version=0.161.1)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)


</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-05-05 11:19:15 +00:00
dependabot[bot] fc04f0d71e chore: bump github.com/fsnotify/fsnotify from 1.9.0 to 1.10.1 (#24962)
Bumps
[github.com/fsnotify/fsnotify](https://github.com/fsnotify/fsnotify)
from 1.9.0 to 1.10.1.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/fsnotify/fsnotify/releases">github.com/fsnotify/fsnotify's
releases</a>.</em></p>
<blockquote>
<h2>v1.10.1</h2>
<h3>Changes and fixes</h3>
<ul>
<li>
<p>inotify: don't remove sibling watches sharing a path prefix (<a
href="https://redirect.github.com/fsnotify/fsnotify/issues/754">#754</a>)</p>
</li>
<li>
<p>inotify, windows: don't rename sibling watches sharing a path prefix
(<a
href="https://redirect.github.com/fsnotify/fsnotify/issues/755">#755</a>)</p>
</li>
</ul>
<p><a
href="https://redirect.github.com/fsnotify/fsnotify/issues/754">#754</a>:
<a
href="https://redirect.github.com/fsnotify/fsnotify/pull/754">fsnotify/fsnotify#754</a>
<a
href="https://redirect.github.com/fsnotify/fsnotify/issues/755">#755</a>:
<a
href="https://redirect.github.com/fsnotify/fsnotify/pull/755">fsnotify/fsnotify#755</a></p>
<h2>v1.10.0</h2>
<p>This version of fsnotify needs Go 1.23.</p>
<h3>Changes and fixes</h3>
<ul>
<li>
<p>inotify: improve initialization error message (<a
href="https://redirect.github.com/fsnotify/fsnotify/issues/731">#731</a>)</p>
</li>
<li>
<p>inotify: send Rename event if recursive watch is renamed (<a
href="https://redirect.github.com/fsnotify/fsnotify/issues/696">#696</a>)</p>
</li>
<li>
<p>inotify: avoid copying event buffers when reading names (<a
href="https://redirect.github.com/fsnotify/fsnotify/issues/741">#741</a>)</p>
</li>
<li>
<p>kqueue: skip dangling symlinks (ENOENT) in watchDirectoryFiles, so a
bad entry no longer aborts Watcher.Add for the whole directory (<a
href="https://redirect.github.com/fsnotify/fsnotify/issues/748">#748</a>)</p>
</li>
<li>
<p>kqueue: drop watches directly in Close() to fix a file descriptor
leak when recycling watchers (<a
href="https://redirect.github.com/fsnotify/fsnotify/issues/740">#740</a>)</p>
</li>
<li>
<p>windows: fix nil pointer dereference in remWatch (<a
href="https://redirect.github.com/fsnotify/fsnotify/issues/736">#736</a>)</p>
</li>
<li>
<p>windows: lock watch field updates against concurrent WatchList to fix
a race introduced in v1.9.0 (<a
href="https://redirect.github.com/fsnotify/fsnotify/issues/709">#709</a>,
<a
href="https://redirect.github.com/fsnotify/fsnotify/issues/749">#749</a>)</p>
</li>
</ul>
<p><a
href="https://redirect.github.com/fsnotify/fsnotify/issues/696">#696</a>:
<a
href="https://redirect.github.com/fsnotify/fsnotify/pull/696">fsnotify/fsnotify#696</a>
<a
href="https://redirect.github.com/fsnotify/fsnotify/issues/709">#709</a>:
<a
href="https://redirect.github.com/fsnotify/fsnotify/pull/709">fsnotify/fsnotify#709</a>
<a
href="https://redirect.github.com/fsnotify/fsnotify/issues/731">#731</a>:
<a
href="https://redirect.github.com/fsnotify/fsnotify/pull/731">fsnotify/fsnotify#731</a>
<a
href="https://redirect.github.com/fsnotify/fsnotify/issues/736">#736</a>:
<a
href="https://redirect.github.com/fsnotify/fsnotify/pull/736">fsnotify/fsnotify#736</a>
<a
href="https://redirect.github.com/fsnotify/fsnotify/issues/740">#740</a>:
<a
href="https://redirect.github.com/fsnotify/fsnotify/pull/740">fsnotify/fsnotify#740</a>
<a
href="https://redirect.github.com/fsnotify/fsnotify/issues/741">#741</a>:
<a
href="https://redirect.github.com/fsnotify/fsnotify/pull/741">fsnotify/fsnotify#741</a>
<a
href="https://redirect.github.com/fsnotify/fsnotify/issues/748">#748</a>:
<a
href="https://redirect.github.com/fsnotify/fsnotify/pull/748">fsnotify/fsnotify#748</a>
<a
href="https://redirect.github.com/fsnotify/fsnotify/issues/749">#749</a>:
<a
href="https://redirect.github.com/fsnotify/fsnotify/pull/749">fsnotify/fsnotify#749</a></p>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/fsnotify/fsnotify/blob/main/CHANGELOG.md">github.com/fsnotify/fsnotify's
changelog</a>.</em></p>
<blockquote>
<h2>1.10.1 2026-05-04</h2>
<h3>Changes and fixes</h3>
<ul>
<li>
<p>inotify: don't remove sibling watches sharing a path prefix (<a
href="https://redirect.github.com/fsnotify/fsnotify/issues/754">#754</a>)</p>
</li>
<li>
<p>inotify, windows: don't rename sibling watches sharing a path prefix
(<a
href="https://redirect.github.com/fsnotify/fsnotify/issues/755">#755</a>)</p>
</li>
</ul>
<p><a
href="https://redirect.github.com/fsnotify/fsnotify/issues/754">#754</a>:
<a
href="https://redirect.github.com/fsnotify/fsnotify/pull/754">fsnotify/fsnotify#754</a>
<a
href="https://redirect.github.com/fsnotify/fsnotify/issues/755">#755</a>:
<a
href="https://redirect.github.com/fsnotify/fsnotify/pull/755">fsnotify/fsnotify#755</a></p>
<h2>1.10.0 2026-04-30</h2>
<p>This version of fsnotify needs Go 1.23.</p>
<h3>Changes and fixes</h3>
<ul>
<li>
<p>inotify: improve initialization error message (<a
href="https://redirect.github.com/fsnotify/fsnotify/issues/731">#731</a>)</p>
</li>
<li>
<p>inotify: send Rename event if recursive watch is renamed (<a
href="https://redirect.github.com/fsnotify/fsnotify/issues/696">#696</a>)</p>
</li>
<li>
<p>inotify: avoid copying event buffers when reading names (<a
href="https://redirect.github.com/fsnotify/fsnotify/issues/741">#741</a>)</p>
</li>
<li>
<p>kqueue: skip dangling symlinks (ENOENT) in watchDirectoryFiles, so a
bad entry no longer aborts Watcher.Add for the whole directory (<a
href="https://redirect.github.com/fsnotify/fsnotify/issues/748">#748</a>)</p>
</li>
<li>
<p>kqueue: drop watches directly in Close() to fix a file descriptor
leak
when recycling watchers (<a
href="https://redirect.github.com/fsnotify/fsnotify/issues/740">#740</a>)</p>
</li>
<li>
<p>windows: fix nil pointer dereference in remWatch (<a
href="https://redirect.github.com/fsnotify/fsnotify/issues/736">#736</a>)</p>
</li>
<li>
<p>windows: lock watch field updates against concurrent WatchList to fix
a race introduced in v1.9.0 (<a
href="https://redirect.github.com/fsnotify/fsnotify/issues/709">#709</a>,
<a
href="https://redirect.github.com/fsnotify/fsnotify/issues/749">#749</a>)</p>
</li>
</ul>
<p><a
href="https://redirect.github.com/fsnotify/fsnotify/issues/696">#696</a>:
<a
href="https://redirect.github.com/fsnotify/fsnotify/pull/696">fsnotify/fsnotify#696</a>
<a
href="https://redirect.github.com/fsnotify/fsnotify/issues/709">#709</a>:
<a
href="https://redirect.github.com/fsnotify/fsnotify/pull/709">fsnotify/fsnotify#709</a>
<a
href="https://redirect.github.com/fsnotify/fsnotify/issues/731">#731</a>:
<a
href="https://redirect.github.com/fsnotify/fsnotify/pull/731">fsnotify/fsnotify#731</a>
<a
href="https://redirect.github.com/fsnotify/fsnotify/issues/736">#736</a>:
<a
href="https://redirect.github.com/fsnotify/fsnotify/pull/736">fsnotify/fsnotify#736</a>
<a
href="https://redirect.github.com/fsnotify/fsnotify/issues/740">#740</a>:
<a
href="https://redirect.github.com/fsnotify/fsnotify/pull/740">fsnotify/fsnotify#740</a>
<a
href="https://redirect.github.com/fsnotify/fsnotify/issues/741">#741</a>:
<a
href="https://redirect.github.com/fsnotify/fsnotify/pull/741">fsnotify/fsnotify#741</a>
<a
href="https://redirect.github.com/fsnotify/fsnotify/issues/748">#748</a>:
<a
href="https://redirect.github.com/fsnotify/fsnotify/pull/748">fsnotify/fsnotify#748</a>
<a
href="https://redirect.github.com/fsnotify/fsnotify/issues/749">#749</a>:
<a
href="https://redirect.github.com/fsnotify/fsnotify/pull/749">fsnotify/fsnotify#749</a></p>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/fsnotify/fsnotify/commit/76b01a6e8f502187fecedea8b025e79e5a86085c"><code>76b01a6</code></a>
Release 1.10.1</li>
<li><a
href="https://github.com/fsnotify/fsnotify/commit/fec150b807510e54e5b25def4b6e5fb001b4898c"><code>fec150b</code></a>
Update changelog</li>
<li><a
href="https://github.com/fsnotify/fsnotify/commit/162b4216ab8f92ecd26425530bee198972c9b3cb"><code>162b421</code></a>
inotify, windows: don't rename sibling watches sharing a path prefix (<a
href="https://redirect.github.com/fsnotify/fsnotify/issues/755">#755</a>)</li>
<li><a
href="https://github.com/fsnotify/fsnotify/commit/224257f23b2f3a96509b316c5cead71dd4a9099a"><code>224257f</code></a>
inotify: don't remove sibling watches sharing a path prefix (<a
href="https://redirect.github.com/fsnotify/fsnotify/issues/754">#754</a>)</li>
<li><a
href="https://github.com/fsnotify/fsnotify/commit/e0c956c0ccaf51562fee30ef5c055c74e6ae2104"><code>e0c956c</code></a>
windows: document directory Write events and stabilize tests (<a
href="https://redirect.github.com/fsnotify/fsnotify/issues/745">#745</a>)</li>
<li><a
href="https://github.com/fsnotify/fsnotify/commit/8d01d7b9cbe0199e4a1e60fbd965fb05dbb42123"><code>8d01d7b</code></a>
Release 1.10.0</li>
<li><a
href="https://github.com/fsnotify/fsnotify/commit/602284e4a8cadd488d7a5fa07c48462dfac25108"><code>602284e</code></a>
Update changelog</li>
<li><a
href="https://github.com/fsnotify/fsnotify/commit/7f03e59f9659552d8a084e03024cb9b983748ed7"><code>7f03e59</code></a>
kqueue: skip ENOENT entries in watchDirectoryFiles (<a
href="https://redirect.github.com/fsnotify/fsnotify/issues/748">#748</a>)</li>
<li><a
href="https://github.com/fsnotify/fsnotify/commit/dab9dde2fc9ba4d0c1076318f81cabcc8fdb2ec9"><code>dab9dde</code></a>
windows: lock watch field updates against concurrent WatchList (<a
href="https://redirect.github.com/fsnotify/fsnotify/issues/709">#709</a>)
(<a
href="https://redirect.github.com/fsnotify/fsnotify/issues/749">#749</a>)</li>
<li><a
href="https://github.com/fsnotify/fsnotify/commit/eadf267ce152b5e62d48cc2c13bb08bd4062b6c7"><code>eadf267</code></a>
kqueue: drop watches directly in Close() instead of going through
remove() (#...</li>
<li>Additional commits viewable in <a
href="https://github.com/fsnotify/fsnotify/compare/v1.9.0...v1.10.1">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=github.com/fsnotify/fsnotify&package-manager=go_modules&previous-version=1.9.0&new-version=1.10.1)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)


</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-05-05 11:18:24 +00:00
Michael Suchacz 1e7874c2c1 feat(site): add personal model override settings UI (#24748)
Adds the UI for personal chat model overrides for root chats, General
subagents, and Explore subagents. Backend support landed in #24715, and
this PR now targets `main`.

## Summary

- Add the admin switch for enabling user personal model overrides.
- Add the user `Agents` settings page at `/agents/settings/user-agents`.
- Use one dropdown per context with pinned chat default and deployment
default options.
- Show the resolved deployment default model in personal settings when
available.
- Teach root chat creation to honor saved root preferences without
replacing explicit user selections.
- Add shared unavailable and malformed override alerts, select separator
support, and Storybook coverage.

## Testing

- `pnpm --dir site lint:types`
- `pnpm --dir site check`
- `pnpm --dir site test:storybook
src/pages/AgentsPage/AgentSettingsUserAgentsPageView.stories.tsx
src/pages/AgentsPage/components/AdminPersonalModelOverridesSettings.stories.tsx
src/pages/AgentsPage/components/AgentCreateForm.stories.tsx
src/pages/AgentsPage/components/Sidebar/AgentsSidebar.stories.tsx`

> Mux is working on behalf of Mike.
2026-05-05 13:11:59 +02:00
Mathias Fredriksson 0c5a25c018 fix(site): deduplicate expired-attachment probes for repeated file IDs (#24760)
When multiple RemoteImageBlock components share a file ID, Chromium
fires native error events on all of them before the first probe's
fetch resolves. Each handler independently checked hasExpired(),
saw false, and started its own probe.

FileProbeContext (renamed from ExpiredFileIdsContext) now coordinates
probes across blocks for the same file ID:

- A ref-based pending set (isPending/markPending/clearPending) gates
  duplicate probes. A ref is used so the second handler can read it
  synchronously before React re-renders.
- Resolved outcomes are stored in context state (probeResults map) so
  sibling blocks re-render with the full result, including API error
  detail for tooltips.
- Context writes (markExpired, setProbeResult) run above the
  per-instance abort-controller guard so siblings receive the result
  even if the probing block unmounts mid-flight.
2026-05-05 14:01:06 +03:00
Sas Swart 1ba7139f21 feat: add session correlation fields to BoundaryLog proto (#24809)
1 of 9 [next >>](https://github.com/coder/coder/pull/24811)

RFC: [Bridge ↔ Boundaries Correlation
RFC](https://www.notion.so/Bridge-Boundaries-Correlation-313d579be59281f3b4efdbfd6896775a)

Adds three new proto fields for boundary session correlation.

**`ReportBoundaryLogsRequest`**
- `session_id` (string, field 2) — UUID generated by boundary at
startup,
  shared across all batches from a single run.
- `confined_process` (string, field 3) — name of the confined process
  (e.g. `claude-code`, `codex`, `copilot`).

**`BoundaryLog`**
- `sequence_number` (uint64, field 4) — monotonically increasing counter
  per session, primary ordering key when boundary is in use.

`BoundaryLog.time` already existed at field 2; no change needed there.

API version bumped to v2.9.

No behaviour change in coderd or the agent. This is a pure schema bump
that the boundary repo will consume in its own stack.

> Generated by Coder Agents
2026-05-05 10:36:26 +02:00
dependabot[bot] e8e9e51036 chore: bump the coder-modules group across 3 directories with 1 update (#24953)
Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore <dependency name> major version` will close this
group update PR and stop Dependabot creating any more for the specific
dependency's major version (unless you unignore this specific
dependency's major version or upgrade to it yourself)
- `@dependabot ignore <dependency name> minor version` will close this
group update PR and stop Dependabot creating any more for the specific
dependency's minor version (unless you unignore this specific
dependency's minor version or upgrade to it yourself)
- `@dependabot ignore <dependency name>` will close this group update PR
and stop Dependabot creating any more for the specific dependency
(unless you unignore this specific dependency or upgrade to it yourself)
- `@dependabot unignore <dependency name>` will remove all of the ignore
conditions of the specified dependency
- `@dependabot unignore <dependency name> <ignore condition>` will
remove the ignore condition of the specified dependency and ignore
conditions


</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-05-05 03:18:23 +00:00
Ethan 4751416b29 fix!: persist structured chat errors (#24919)
**Breaking change for changelog:**

> `codersdk.Chat.last_error` now returns a structured `ChatError` object
(`{message, kind, provider, retryable, status_code, detail}`) instead of
a plain string. The chats API is experimental
(`/api/experimental/chats`), so this ships without a deprecation cycle;
consumers reading `chat.last_error` as a string must update to read
`chat.last_error.message`. SDK/generated TypeScript terminal error
payloads now use the single `ChatError` type; the live stream error
payload type is renamed from `ChatStreamError` to `ChatError`.

Persisted chat errors now carry the same provider-specific detail (kind,
provider, retryable, HTTP status, optional detail) as the live stream,
so refreshing a failed chat rehydrates with the full structured error
instead of a one-line headline.

Existing rows are migrated in place: legacy text errors are wrapped into
`{message, kind: "generic"}` so already-errored chats still render, and
rows with `last_error IS NULL` stay NULL. Internally, persisted fallback
decoding now reuses the existing `chaterror.KindGeneric` constant, with
no JSON value change.

Closes CODAGT-239
2026-05-05 12:56:06 +10:00
Ethan 7e01edeb8e fix: align chat attachment picker with allowed file types (#24917)
The agent chat composer only advertised image uploads to the OS file
picker and filtered drag-and-drop and paste events to `image/*`, even
though the backend accepts text, CSV, JSON, PDF, and a narrower set of
image types.

Move the allowed chat attachment media types into `codersdk` so the
frontend picker and backend enforcement share one source of truth. Use
the generated TypeScript list to drive the file input `accept` attribute
and the drag-and-drop and paste filters, while adding common text
extensions so platforms without MIME registrations still surface those
files in the picker.
2026-05-05 12:25:13 +10:00
Michael Suchacz 632dcdb63a feat: add personal chat model overrides (#24715) 2026-05-05 00:57:51 +02:00
Michael Suchacz 43aa0498d6 feat(site): warn when viewing another user's chat (#24941) 2026-05-05 00:47:24 +02:00
Atif Ali fad69df710 fix: correct SCIM Swagger try it out URLs (#24779) 2026-05-05 02:54:03 +05:00
Kyle Carberry f0fd2111fd feat(site/src/pages/AgentsPage): render markdown attachments in preview popup (#24936)
Markdown attachments on `/agents` now render through the same `Response`
component used for chat messages instead of falling back to a monospaced
`<pre>` block. The popup detects markdown via an explicit
`text/markdown` media type and falls back to the `.md`/`.markdown`
filename extension when no media type is available.

`PreviewTextAttachment` and `TextPreviewDialog` gain an optional
`mediaType` so that callers (`AttachmentBlock` for already-sent messages
and `AttachmentPreview` for live drafts) can plumb the upload metadata
through. Plain `.txt` and unrecognized text attachments keep the
existing monospaced rendering.

## Demo

![Markdown attachment preview
demo](https://raw.githubusercontent.com/coder/coder/kylecarbs/preview-assets-md-attachments/markdown-attachment-preview.gif)

## Screenshots

| Markdown rendering | Plain text rendering |
| --- | --- |
| ![Markdown by
extension](https://raw.githubusercontent.com/coder/coder/kylecarbs/preview-assets-md-attachments/markdown-by-extension.png)
| ![Plain text stays
monospaced](https://raw.githubusercontent.com/coder/coder/kylecarbs/preview-assets-md-attachments/plain-text-stays-monospaced.png)
|

Light theme also verified:

![Markdown by extension
(light)](https://raw.githubusercontent.com/coder/coder/kylecarbs/preview-assets-md-attachments/markdown-by-extension-light.png)

<details>
<summary>Coverage details</summary>

New stories in `TextPreviewDialog.stories.tsx` cover:

- `MarkdownByExtension` — `.md` filename, headings/lists/tables/fenced
code render natively.
- `MarkdownByMediaType` — explicit `text/markdown` mediaType wins even
without a `.md` suffix.
- `MarkdownProseOnly` — inline `**bold**`, `_italic_`, and `` `code` ``
render via streamdown.
- `PlainTextStaysMonospaced` — `.txt` content stays inside `<pre>` so
existing previews don't regress.

Manual verification (desktop, Chromium, dark + light): all four stories
above plus the existing `Default`, `LongContent`, and `NoFileName`
stories pass.
</details>

_Coder Agents generated PR._
2026-05-04 17:37:57 -04:00
dependabot[bot] 63412012b6 chore: bump lodash from 4.17.21 to 4.18.1 in /site (#24940)
Bumps [lodash](https://github.com/lodash/lodash) from 4.17.21 to 4.18.1.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/lodash/lodash/releases">lodash's
releases</a>.</em></p>
<blockquote>
<h2>4.18.1</h2>
<h2>Bugs</h2>
<p>Fixes a <code>ReferenceError</code> issue in <code>lodash</code>
<code>lodash-es</code> <code>lodash-amd</code> and
<code>lodash.template</code> when using the <code>template</code> and
<code>fromPairs</code> functions from the modular builds. See <a
href="https://redirect.github.com/lodash/lodash/issues/6167#issuecomment-4165269769">lodash/lodash#6167</a></p>
<p>These defects were related to how lodash distributions are built from
the main branch using <a
href="https://github.com/lodash-archive/lodash-cli">https://github.com/lodash-archive/lodash-cli</a>.
When internal dependencies change inside lodash functions, equivalent
updates need to be made to a mapping in the lodash-cli. (hey, it was
ahead of its time once upon a time!). We know this, but we missed it in
the last release. It's the kind of thing that passes in CI, but fails bc
the build is not the same thing you tested.</p>
<p>There is no diff on main for this, but you can see the diffs for each
of the npm packages on their respective branches:</p>
<ul>
<li><code>lodash</code>: <a
href="https://github.com/lodash/lodash/compare/4.18.0-npm...4.18.1-npm">https://github.com/lodash/lodash/compare/4.18.0-npm...4.18.1-npm</a></li>
<li><code>lodash-es</code>: <a
href="https://github.com/lodash/lodash/compare/4.18.0-es...4.18.1-es">https://github.com/lodash/lodash/compare/4.18.0-es...4.18.1-es</a></li>
<li><code>lodash-amd</code>: <a
href="https://github.com/lodash/lodash/compare/4.18.0-amd...4.18.1-amd">https://github.com/lodash/lodash/compare/4.18.0-amd...4.18.1-amd</a></li>
<li><code>lodash.template</code><a
href="https://github.com/lodash/lodash/compare/4.18.0-npm-packages...4.18.1-npm-packages">https://github.com/lodash/lodash/compare/4.18.0-npm-packages...4.18.1-npm-packages</a></li>
</ul>
<h2>4.18.0</h2>
<h2>v4.18.0</h2>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/lodash/lodash/compare/4.17.23...4.18.0">https://github.com/lodash/lodash/compare/4.17.23...4.18.0</a></p>
<h3>Security</h3>
<p><strong><code>_.unset</code> / <code>_.omit</code></strong>: Fixed
prototype pollution via <code>constructor</code>/<code>prototype</code>
path traversal (<a
href="https://github.com/lodash/lodash/security/advisories/GHSA-f23m-r3pf-42rh">GHSA-f23m-r3pf-42rh</a>,
<a
href="https://github.com/lodash/lodash/commit/fe8d32eda854377349a4f922ab7655c8e5df9a0b">fe8d32e</a>).
Previously, array-wrapped path segments and primitive roots could bypass
the existing guards, allowing deletion of properties from built-in
prototypes. Now <code>constructor</code> and <code>prototype</code> are
blocked unconditionally as non-terminal path keys, matching
<code>baseSet</code>. Calls that previously returned <code>true</code>
and deleted the property now return <code>false</code> and leave the
target untouched.</p>
<p><strong><code>_.template</code></strong>: Fixed code injection via
<code>imports</code> keys (<a
href="https://github.com/lodash/lodash/security/advisories/GHSA-r5fr-rjxr-66jc">GHSA-r5fr-rjxr-66jc</a>,
CVE-2026-4800, <a
href="https://github.com/lodash/lodash/commit/879aaa93132d78c2f8d20c60279da9f8b21576d6">879aaa9</a>).
Fixes an incomplete patch for CVE-2021-23337. The <code>variable</code>
option was validated against <code>reForbiddenIdentifierChars</code> but
<code>importsKeys</code> was left unguarded, allowing code injection via
the same <code>Function()</code> constructor sink. <code>imports</code>
keys containing forbidden identifier characters now throw
<code>&quot;Invalid imports option passed into
_.template&quot;</code>.</p>
<h3>Docs</h3>
<ul>
<li>Add security notice for <code>_.template</code> in threat model and
API docs (<a
href="https://redirect.github.com/lodash/lodash/pull/6099">#6099</a>)</li>
<li>Document <code>lower &gt; upper</code> behavior in
<code>_.random</code> (<a
href="https://redirect.github.com/lodash/lodash/pull/6115">#6115</a>)</li>
<li>Fix quotes in <code>_.compact</code> jsdoc (<a
href="https://redirect.github.com/lodash/lodash/pull/6090">#6090</a>)</li>
</ul>
<h3><code>lodash.*</code> modular packages</h3>
<p><a
href="https://redirect.github.com/lodash/lodash/pull/6157">Diff</a></p>
<p>We have also regenerated and published a select number of the
<code>lodash.*</code> modular packages.</p>
<p>These modular packages had fallen out of sync significantly from the
minor/patch updates to lodash. Specifically, we have brought the
following packages up to parity w/ the latest lodash release because
they have had CVEs on them in the past:</p>
<ul>
<li><a
href="https://www.npmjs.com/package/lodash.orderby">lodash.orderby</a></li>
<li><a
href="https://www.npmjs.com/package/lodash.tonumber">lodash.tonumber</a></li>
<li><a
href="https://www.npmjs.com/package/lodash.trim">lodash.trim</a></li>
<li><a
href="https://www.npmjs.com/package/lodash.trimend">lodash.trimend</a></li>
<li><a
href="https://www.npmjs.com/package/lodash.sortedindexby">lodash.sortedindexby</a></li>
<li><a
href="https://www.npmjs.com/package/lodash.zipobjectdeep">lodash.zipobjectdeep</a></li>
<li><a
href="https://www.npmjs.com/package/lodash.unset">lodash.unset</a></li>
<li><a
href="https://www.npmjs.com/package/lodash.omit">lodash.omit</a></li>
<li><a
href="https://www.npmjs.com/package/lodash.template">lodash.template</a></li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/lodash/lodash/commit/cb0b9b9212521c08e3eafe7c8cb0af1b42b6649e"><code>cb0b9b9</code></a>
release(patch): bump main to 4.18.1 (<a
href="https://redirect.github.com/lodash/lodash/issues/6177">#6177</a>)</li>
<li><a
href="https://github.com/lodash/lodash/commit/75535f57883b7225adb96de1cfc1cd4169cfcb51"><code>75535f5</code></a>
chore: prune stale advisory refs (<a
href="https://redirect.github.com/lodash/lodash/issues/6170">#6170</a>)</li>
<li><a
href="https://github.com/lodash/lodash/commit/62e91bc6a39c98d85b9ada8c44d40593deaf82a4"><code>62e91bc</code></a>
docs: remove n_ Node.js &lt; 6 REPL note from README (<a
href="https://redirect.github.com/lodash/lodash/issues/6165">#6165</a>)</li>
<li><a
href="https://github.com/lodash/lodash/commit/59be2de61f8aa9461c7856533b51d31b7d8babc4"><code>59be2de</code></a>
release(minor): bump to 4.18.0 (<a
href="https://redirect.github.com/lodash/lodash/issues/6161">#6161</a>)</li>
<li><a
href="https://github.com/lodash/lodash/commit/af634573030f979194871da7c68f79420992f53d"><code>af63457</code></a>
fix: broken tests for _.template 879aaa9</li>
<li><a
href="https://github.com/lodash/lodash/commit/1073a7693e1727e0cf3641e5f71f75ddcf8de7c0"><code>1073a76</code></a>
fix: linting issues</li>
<li><a
href="https://github.com/lodash/lodash/commit/879aaa93132d78c2f8d20c60279da9f8b21576d6"><code>879aaa9</code></a>
fix: validate imports keys in _.template</li>
<li><a
href="https://github.com/lodash/lodash/commit/fe8d32eda854377349a4f922ab7655c8e5df9a0b"><code>fe8d32e</code></a>
fix: block prototype pollution in baseUnset via constructor/prototype
traversal</li>
<li><a
href="https://github.com/lodash/lodash/commit/18ba0a32f42fd02117f096b032f89c984173462d"><code>18ba0a3</code></a>
refactor(fromPairs): use baseAssignValue for consistent assignment (<a
href="https://redirect.github.com/lodash/lodash/issues/6153">#6153</a>)</li>
<li><a
href="https://github.com/lodash/lodash/commit/b8190803d48d60b8c80ad45d39125f32fa618cb2"><code>b819080</code></a>
ci: add dist sync validation workflow (<a
href="https://redirect.github.com/lodash/lodash/issues/6137">#6137</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/lodash/lodash/compare/4.17.21...4.18.1">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=lodash&package-manager=npm_and_yarn&previous-version=4.17.21&new-version=4.18.1)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)
You can disable automated security fix PRs for this repo from the
[Security Alerts page](https://github.com/coder/coder/network/alerts).

</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-05-04 18:45:57 +00:00
Steven Masley d4f913a4cf chore: bump coder/serpent to accept empty env vars (#24926)
Non-zero default values can now be set to `""` with env vars. Eg:
`--log-human="" --log-json="/dev/stderr"`
2026-05-04 13:42:03 -05:00
Michael Suchacz 0bb09935bc feat: add computer-use provider selection for AI agents (#24772)
Adds a deployment-wide setting to select the computer-use provider
(Anthropic or OpenAI) for AI agents, plus the OpenAI computer-use runner
needed to honor that selection.

The setting is stored in `site_configs` under
`agents_computer_use_provider`, defaults to Anthropic when unset, and is
exposed via experimental GET/PUT endpoints under
`/api/experimental/chats/config/computer-use-provider`. The chatd
computer-use tool now dispatches to either `runAnthropicComputerUse` or
`runOpenAIComputerUse` based on the resolved provider, with
provider-specific result metadata for OpenAI screenshots.

Frontend adds a provider dropdown to the Agents Experiments settings
page nested under the virtual desktop toggle, with disabled state
handling while virtual desktop is off and skeleton loaders while config
queries are in flight.

Hugo and Codex review follow-up:
- Uses shared provider validation and clearer computer-use constant
names.
- Removes stale OpenAI pending-safety-checks commentary.
- Documents why provider result metadata is needed for OpenAI
screenshots.
- Keeps the computer-use subagent visible when provider credentials are
missing, then returns a clear spawn-time configuration error.
- Uses OpenAI's recommended 1600x900 screenshot geometry to preserve the
native 16:9 aspect ratio.
- Moves OpenAI-specific computer-use helpers into
`coderd/x/chatd/chatopenai/computeruse` after rebasing onto the provider
package refactor in `main`.
- Converts OpenAI pixel scroll deltas to Coder desktop wheel-click
amounts.
- Preserves OpenAI pointer modifiers with key down/up desktop actions
and rejects unsupported non-left double-click buttons explicitly.
- Maps OpenAI back/forward side-button clicks to browser navigation key
actions.
- Defaults omitted OpenAI click buttons to left-click.
- Retries mouse release cleanup if the final OpenAI drag release fails.
- Keeps computer-use subagent availability messages stable when provider
config cannot be loaded, while logging the backend error.
- Releases remaining OpenAI modifier keys if a synthetic key-up cleanup
action fails.
- Updates Storybook interaction stories so provider snapshots show the
selected final provider.

> Mux updated this PR description on behalf of Mike.
2026-05-04 20:30:50 +02:00
da6e708bd2 fix(coderd/externalauth): detect concurrent refresh race to prevent cache poisoning (#24228)
<!--

If you have used AI to produce some or all of this PR, please ensure you
have read our [AI Contribution
guidelines](https://coder.com/docs/about/contributing/AI_CONTRIBUTING)
before submitting.

-->

Fixes https://github.com/coder/coder/issues/17069

Builds on #24332 and #24334 which addressed token persistence and rate
limit handling.

## Problem

When multiple concurrent requests race to refresh an expiring external
auth token, providers with single-use refresh tokens (e.g., GitHub Apps)
reject all but the first refresh attempt with `bad_refresh_token`. The
losing request caches this transient error in the
`oauth_refresh_failure_reason` database column and clears the refresh
token, blocking all subsequent refresh attempts until the user manually
re-authenticates.

This is common for users with multiple terminals, IDE connections, or
workspaces open, all of which poll the external auth endpoint and
trigger concurrent refreshes when the token nears expiry. Database
analysis showed 5 of 7 affected users failed within 5-10 seconds of
token expiry, matching the Go oauth2 library's `expiryDelta` window.

## Fix

Before caching a `bad_refresh_token` failure, re-read the external auth
link from the database. If the refresh token has changed (indicating a
concurrent caller already refreshed successfully), return the winner's
updated link instead of writing a failure. An empty-string guard ensures
a token cleared by another loser isn't mistaken for a winner's
successful refresh.

Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
Co-authored-by: Garrett Delfosse <garrett@coder.com>
2026-05-04 14:02:07 -04:00
Kyle Carberry 1ecdad689b fix(site/src/pages/AgentsPage): restore sticky user message pinning after react-infinite-scroll-component refactor (#24937)
Restores the sticky user message pinning behavior in the Agents chat
that regressed after #24687 swapped the chat scroll container for
`react-infinite-scroll-component`.

## Root cause

`react-infinite-scroll-component` renders two wrapper divs between the
`.overflow-y-auto` scroller and the rendered messages, and its inner
wrapper hard-codes `overflow: auto` in its inline style. With the new
layout, `position: sticky` on a user message resolved against that
inner wrapper rather than the real scroller, so the message scrolled
out with its sentinel and the existing fade/clip overlay never
engaged.

## Fix

Force both InfiniteScroll wrappers to `display: contents` so they no
longer participate in layout. The user message's nearest scrolling
ancestor is once again the `.overflow-y-auto` element, and
`position: sticky` anchors to the scroll container as it did before
#24687.

The outer wrapper is reached via the Tailwind arbitrary selector
`[&>[class$=outerdiv]]:contents` because the library only exposes
`style` for the inner wrapper.

The inverse infinite-scroll behavior is preserved: the scroller
itself stays `flex-col-reverse`, so it remains bottom-anchored and
the library's load-more sentinel still lands at the visual top of
the content stack.

Also drops the dead `overflow-y-auto` class on the floating
scroll-to-bottom button wrapper noted in the bug report.

## Test coverage

Adds `StickyUserMessagePinsOnScroll` to
`AgentChatPageView.stories.tsx`. With a 40-message conversation it
walks the user-message sentinels in reverse DOM order to find the
one currently pinned (the latest sentinel above the scroller's top
edge) and asserts the matching sticky container is anchored within
a few pixels of that edge. Without the fix the container ends up
hundreds of pixels above the scroller because `position: sticky`
silently no-ops.

The existing structural `StickyUserMessageStructure` story in
`ConversationTimeline.stories.tsx` continues to pass unchanged.

<details>
<summary>Verification</summary>

```sh
pnpm exec tsc -p .                                      # 0 errors
pnpm run lint:check                                     # passes
pnpm exec vitest run --project=unit                     # 2303 passed
pnpm exec vitest run --project=storybook \
  src/pages/AgentsPage/AgentChatPage.stories.tsx \
  src/pages/AgentsPage/AgentChatPageView.stories.tsx \
  src/pages/AgentsPage/components/ChatConversation/ConversationTimeline.stories.tsx
                                                        # 90 passed
```

Confirmed the new story fails on `main` (sticky container at the
sentinel's position instead of the scroller top) and passes with
the fix applied.

</details>

---

Generated by Coder Agents.
2026-05-04 13:35:35 -04:00
Kayla はな 162acaf8bf feat: update UsersPage role editing to match new designs (#24857) 2026-05-04 11:19:21 -06:00
Matt Vollmer 5612bb81cb docs(docs/ai-coder): replace Coder Tasks references with Coder Agents (#24929)
Updates `docs/ai-coder/index.md`, `docs/ai-coder/best-practices.md`, and
`docs/ai-coder/ai-governance.md` to point readers at Coder Agents and
the AI Governance Add-On instead of Coder Tasks and Agent Firewall
(CODAGT-157).

## Changes

- `docs/ai-coder/index.md`:
- Rename `## Agents with Coder Tasks` to `## Coder Agents`. Drop the
Devin / ChatGPT Codex name-drops and the Tasks pitch. New copy points at
`./agents/index.md`, names the agent loop in the control plane, and
notes that workspaces can be completely network isolated. Image swapped
from `tasks-ui.png` to `agents-hero-image.png` (the hero shot added in
#24915).
- Replace the `## Secure Your Workflows with Agent Firewall` section
with `## Govern AI activity with the AI Governance Add-On`. The new
section opens with adoption-first framing (visibility, guardrails, cost)
and links to `./ai-governance.md`, with bulleted callouts for AI
Gateway, Agent Firewall, and the expanded Agent Workspace Build
allowance the add-on bundles.
- `docs/ai-coder/best-practices.md`:
- In the use-case table, swap `[Tasks](./tasks.md)` to `[Coder
Agents](./agents/index.md)` for the developer-led-investigation and
prototyping rows, and swap the "Tasks API *(in development)*" cell to
`[Coder Agents API](./agents/chats-api.md)` for the background-jobs row.
Retitle the Security section link from "securing agents with Coder
Tasks" to "securing AI agents" since `security.md` does not actually
mention Tasks. Re-ran `markdown-table-formatter` to repad column widths.
- In `## Provide Agents with Proper Context`, add a paragraph describing
how context is provided in Coder Agents (admin-configured system
prompts, centrally registered MCP servers, and skills shipped from repos
or templates under `.agents/skills/`), with a transition line clarifying
that the existing Memory and Tools subsections cover BYO-agent patterns.
- `docs/ai-coder/ai-governance.md`: drop the "Additional Tasks Use (via
Agent Workspace Builds)" bullet from the intro feature list and the
"Expanding the use of Coder Tasks for AI-driven background work" bullet
from the audience list. The `## How Coder Tasks usage is measured`
section and the rest of the Tasks-related prose on this page are
intentionally left for a follow-up PR.

## Notes for the reviewer

- The `[Coder Agents API](./agents/chats-api.md)` link in
`best-practices.md` will need to be retargeted if #24830 (which replaces
`agents/chats-api.md` with auto-generated `reference/api/chats.md`)
lands first.
- This is the first slice of the Tasks-references audit. Remaining files
(`tasks-core-principles.md`, `tasks-lifecycle.md`, `tasks-migration.md`,
`cli.md`, `github-to-tasks.md`, `agent-compatibility.md`, the rest of
`ai-governance.md`, `custom-agents.md`,
`ai-gateway/clients/claude-code.md`, `manifest.json`,
`reference/api/tasks.md`, the `task*` CLI references, the ESR upgrade
guide, `feature-stages.md`, `workspace-scheduling.md`,
`shared-workspaces.md`) will land in follow-up PRs against the same
Linear ticket. Open PRs #24831, #24833, and #24841 cover separate slices
and do not touch any file in this PR.
- Validation: `markdownlint-cli2`, `markdown-table-formatter`,
`scripts/check_emdash.sh`, and `make pre-commit-light` all pass.

PR generated with Coder Agents.
2026-05-04 13:00:39 -04:00
Ben Potter f6eccbab23 feat(site/src): add ports submenu to WorkspacePill in agents chat (#24887)
Adds a **Ports (n) >** submenu item to the `WorkspacePill` dropdown
shown in the `/agents` chat UI when a workspace is attached, sitting
alongside VS Code, Terminal, and other app items.

The submenu shows a **Listening Ports** section with clickable port
links that open in a new tab, a **Shared Ports** section with
sharing-level icons when any ports are shared, and a **Manage sharing**
footer link to the workspace detail page. Port data is fetched on a 5s
polling interval while the dropdown is open and only when the agent is
connected. The trigger is disabled when the workspace is not running.

Also adds `DropdownMenuSub`, `DropdownMenuSubTrigger`, and
`DropdownMenuSubContent` to the shared `DropdownMenu` component for use
here and future consumers.

![ports submenu
demo](https://raw.githubusercontent.com/coder/coder/screenshots/ports-submenu/ports-submenu-demo.gif)

<details>
<summary>Implementation notes</summary>

- `host` for port-forward URL construction comes from
`useProxy().proxy.preferredWildcardHostname`, the same source used by
`PortForwardButton` on the workspace detail page.
- Port queries are gated on `isOpen && agent.status === "connected"` so
no requests fire when the dropdown is closed or the agent is
disconnected.
- Shared ports that overlap with listening ports are deduplicated: they
only appear in the Shared section.
- Port sharing controls (create/update/delete) are intentionally
excluded to keep the agents toolbar lightweight; the "Manage sharing"
link surfaces the workspace page for that.
- The port count badge on the trigger (`Ports (n)`) uses the raw
listening-port count, matching the existing `PortForwardButton` behavior
on the workspace detail page.
</details>

> Generated by [Coder Agent](https://coder.com)
2026-05-04 11:56:51 -05:00
Kyle Carberry c16034d127 fix(site/src/pages/AgentsPage/components): match chat input font size to message bubbles (#24928)
The `/agents` chat composer rendered user input at 15px, but once a
message was sent the user message bubble displays content at 13px (via
`MessageContent` in `ChatElements/Message.tsx`). The size jump made what
you typed not match what got displayed.

Sets the `ChatMessageInput` className inside `AgentChatInput` to
`text-[13px] leading-relaxed` so the composer matches the rendered user
message.

<sub>This PR was opened by a Coder agent on behalf of @kylecarbs.</sub>
2026-05-05 02:22:26 +10:00
Thomas Kosiewski 69610cca75 feat(site/src): add Known Model autocomplete and frontend defaults (#24842)
Replaces the blank Model Identifier free-text input on the **Add Model**
page with provider-scoped Known Model autocomplete and frontend-only
metadata defaults for native OpenAI and Anthropic providers. Selecting a
Known Model, or typing an exact canonical identifier and blurring the
field, prefills `contextLimit`, the appropriate max-output-tokens field,
and flat base pricing in the existing form. Edit mode, duplicate mode,
and unsupported providers preserve the existing plain `Input` behavior
and submit payload byte-for-byte.

The catalog is curated TypeScript records sourced from `models.dev`,
scoped initially to 6 OpenAI and 5 Anthropic models in declared display
order. The pure `applyKnownModelDefaults` helper only writes a field
when its current value still equals the form's initial value (or was
last applied by Known Model defaulting in this form session, tracked
cumulatively across selections). It never sets `compressionThreshold` or
any reasoning/thinking fields, ignores tiered pricing, and never writes
to the `model` field (canonicalization is the caller's responsibility).

This PR also makes two narrow, additive changes outside the panel
directory:

- `site/src/components/Autocomplete/Autocomplete.tsx` gains optional
`triggerAriaInvalid`, `triggerAriaDescribedBy`, and `onEscapeKeyDown`
props so the new catalog branch can preserve `aria-invalid` /
`aria-describedby` parity with the plain input and observe Escape close
intent reliably across the Radix portal. Existing `Autocomplete`
consumers are unaffected; `stopPropagation` is gated on
`onEscapeKeyDown` being provided.
-
`site/src/pages/AgentsPage/components/ChatModelAdminPanel/modelConfigFormLogic.ts`
exports `deepGet` / `deepSet` so the defaulting helper can reuse them
instead of re-implementing the same path traversal.

No backend, API, SDK, or DB changes. No edits to `ModelsSection.tsx`,
`ModelConfigFields.tsx`, `pricingFields.ts`, or
`providerPolicyDefaults.ts`.

## Validation

- 37 colocated unit tests across `knownModels/` (catalog, search,
exact-canonical lookup, exact-alias lookup, badge, defaulting helper).
- 134 unit tests across the full ChatModelAdminPanel directory pass.
- 50 Storybook play tests on `ChatModelAdminPanel.stories.tsx` pass,
including 17 DEREM-traceable interaction tests covering each plan-listed
and review-driven scenario (open-no-error, Escape cancellation,
sequential selection, double-apply guard, blur-canonical, alias
cancellation, provider-change reset, ARIA parity, no-options copy,
off-catalog substring commit, stale-cost-field, off-catalog
interleaving, chain tracking, keyboard selection, clearable-disabled,
off-catalog punctuation variant).
- `tsc -p .` passes.

## Dogfooding

Storybook was run locally and the user-facing flows were exercised
end-to-end via `agent-browser`, capturing screenshots for:

1. OpenAI happy path (selection → defaults applied note → populated
fields).
2. Anthropic happy path (selection → populated fields,
reasoning/thinking blank).
3. Unsupported provider fallback (Google plain input, no popover).
4. OpenAI suggestion popover at empty focus (declared catalog order,
context badges).
5. OpenAI search filter (typing `5.4` filters to GPT-5.4 / 5.4 mini /
5.4 nano).
6. Edit mode plain input (autocomplete correctly gated to add mode
only).
7. DEREM-3: empty popover open on Add Model — no premature `Model ID is
required.` error.
8. DEREM-1: autocomplete trigger `aria-invalid="true"` and
`aria-describedby` matching the rendered error element.
9. DEREM-6: exact `No matching known models. You can still use this
identifier.` copy.


---

<details>
<summary>📋 Implementation Plan</summary>

# Plan: Known Model autocomplete and frontend-only defaults for Chat
Model Admin

## Goal

Improve the admin Add Model onboarding flow by replacing the blank Model
Identifier experience with provider-scoped Known Model discovery
suggestions for native OpenAI and Anthropic providers. Selecting a Known
Model, or typing an exact canonical Known Model identifier and blurring
the field, should prefill safe objective model metadata in the existing
form without changing backend APIs, database schema, or runtime
behavior.

The primary UX goal is discovery for admins who do not know exact
provider model identifiers or metadata. Typing convenience is a
secondary benefit.

## Evidence and current code facts

- The current Model Identifier field is a plain free-text `Input` in
`site/src/pages/AgentsPage/components/ChatModelAdminPanel/ModelForm.tsx`.
It submits as `model` and is only validated as a non-empty string.
- The provider selector is disabled in edit and duplicate modes. In add
mode, `ModelsSection.tsx` keys the form by provider, so provider changes
remount `ModelForm`.
- The shared `site/src/components/Autocomplete/Autocomplete.tsx`
primitive already supports free-text input with suggestions and is the
right UI primitive for this feature.
- `modelConfigFormLogic.ts` owns form initialization via
`buildInitialModelFormValues(...)`, and `modelConfigFormLogic.test.ts`
already covers this pure logic area.
- No frontend or backend Known Model catalog exists today.
- The database has a non-unique `(provider, model)` index, not a
uniqueness constraint. Multiple Model Configs can share the same
Provider and Model Identifier, so suggestions must not hide
already-configured models.
- `models.dev/api.json` has provider-keyed model metadata with canonical
IDs, names, limits, pricing, release dates, and `last_updated` values.
The Phase 1 catalog should copy a curated subset into TypeScript
records, not fetch at runtime.

## Domain language

Use these terms consistently in code, tests, docs, and review
discussion:

- **Provider**: configured external AI service such as native `openai`
or `anthropic`.
- **Model Config**: persisted admin-defined config row used by Coder
chat runtime.
- **Model Identifier**: exact provider API string submitted as `model`,
such as `gpt-5.5`.
- **Known Model**: curated frontend catalog entry with advisory metadata
for one canonical Model Identifier.
- **Model Catalog**: checked-in frontend-only list of Known Models.
- **Off-catalog Model Identifier**: user-entered Model Identifier that
does not match any Known Model and remains valid.
- **Default application**: copying advisory Known Model metadata into a
draft add-mode Model Config form.

## Resolved design decisions

### UX scope

- Implement this on the Add Model page/form only.
- Do not add provider success popups, provider-side calls to action, or
new deep-link behavior in this pass.
- Use `Autocomplete` only when all are true:
  - form mode is add;
  - selected Provider is native `openai` or native `anthropic`;
  - that Provider has Known Models.
- Edit mode, duplicate mode, and unsupported providers keep the existing
free-text input behavior.

### Suggestion behavior

- Suggestions open on focus only when the Model Identifier field is
empty.
- Once the field has text, suggestions open while typing or interacting
with the autocomplete.
- Empty unsupported-provider catalogs degrade silently to the existing
plain input behavior.
- When a supported provider has zero matches for a non-empty query, show
a non-blocking empty state such as: `No matching known models. You can
still use this identifier.`
- Suggestion rows show:
  - display name;
  - canonical Model Identifier;
  - context-window badge, for example `1.05M context`.
- Format context badges with a deterministic helper covered by tests,
for example `200K context`, `400K context`, and `1.05M context`.
- Do not show pricing, recommendations, capability tags, or
large-context caveats in suggestion rows.
- Keep catalog display order as product ordering. Do not show a visible
`Recommended` badge.

### Canonical IDs and aliases

- Selecting a Known Model always writes its canonical Model Identifier
into the form.
- Use non-date latest aliases as canonical onboarding IDs when the
provider exposes them, such as `gpt-5.5` or `claude-sonnet-4-6`.
- Date-pinned IDs may be aliases for search, but selecting a Known Model
writes the non-date canonical ID.
- Typing aliases filters suggestions but does not rewrite the field and
does not apply defaults by itself.
- Search over canonical ID, display name, and explicit aliases.
- Search is case-insensitive and normalizes spaces, hyphens,
underscores, and dots before substring matching.
- Aliases are objective name or identifier variants only. Do not include
editorial intent tags such as `best`, `cheap`, `fast`, `coding`, or
`reasoning`.
- Do not implement typo-tolerant fuzzy search in Phase 1.

### Default application rules

- Default application only runs in add mode.
- Explicit Known Model selection applies defaults immediately.
- Exact typed or pasted canonical Model Identifier applies defaults on
blur, not on every keystroke. This avoids prematurely applying `gpt-5.5`
while the admin is typing `gpt-5.5-pro`.
- Defaults fill only target fields whose current values still equal this
form session's initial values.
- Do not use Formik touched state as the source of truth for safety.
- Do not implement field-level provenance tracking in Phase 1.
- Capture an immutable `initialValuesRef` at `ModelForm` mount/remount
and compare against that snapshot for safe default application. Do not
compare against a live Formik reference that can drift.
- Do not reapply repeatedly for the same provider/model pair in a single
form session.
- The defaulting helper must return both the next values and the list of
applied form paths:

```ts
interface ApplyKnownModelDefaultsResult {
  values: ModelFormValues;
  appliedFields: readonly string[];
}
```

- Treat Model Identifier canonicalization separately from metadata
default application. `appliedFields` tracks populated metadata/form
paths only, not the `model` field change caused by selecting a Known
Model.
- Show an inline note near Model Identifier only when
`appliedFields.length > 0`, such as: `Defaults applied from GPT-5.5.
Review and adjust before saving.`
- Do not show a note for off-catalog identifiers, no-op Known Model
selections, or selections that only canonicalize the Model Identifier.

### Initial Model Catalog

Use curated TypeScript records with source metadata copied from
models.dev. Do not check in the full `models.dev/api.json` snapshot and
do not add a generator in Phase 1. Add a file-level comment that array
order controls suggestion order so future cleanup does not accidentally
change onboarding UX.

Initial native OpenAI entries, in display order:

1. `gpt-5.5`
2. `gpt-5.5-pro`
3. `gpt-5.4`
4. `gpt-5.4-mini`
5. `gpt-5.4-nano`
6. `gpt-5.3-codex`

Initial native Anthropic entries, in display order:

1. `claude-opus-4-7`
2. `claude-opus-4-6`
3. `claude-sonnet-4-6`
4. `claude-haiku-4-5`
5. `claude-sonnet-4-5`

Do not include GPT-4.x, pre-5.3 GPT models, or Claude models older than
4.5 in this onboarding catalog unless product intentionally expands
scope.

Each Known Model record should include:

- provider;
- canonical Model Identifier;
- display name;
- aliases;
- source metadata, including `sourceName: "models.dev"`,
`sourceRetrievedAt`, and the model record's `last_updated` value;
- `contextLimit` from `limit.context`;
- `maxOutputTokens` from `limit.output`;
- flat base pricing from supported `cost.*` fields.

### Field mapping

- `models.dev.limit.context` maps to `contextLimit`.
- `models.dev.limit.output` maps to the selected provider's exact
max-output-tokens field when one exists, otherwise to generic
`config.maxOutputTokens`.
- Never fill both generic and provider-specific output-token fields for
the same Known Model.
- Ignore `models.dev.limit.input` unless the current form schema already
exposes an exact matching field.
- Map only flat base pricing fields that the existing form can persist:
  - `cost.input`;
  - `cost.output`;
  - `cost.cache_read`;
  - `cost.cache_write`.
- Reuse `pricingFields.ts` or the existing pricing field descriptors
instead of hard-coding cost form paths.
- If `cache_read` or `cache_write` is absent from a models.dev entry,
leave the corresponding field at its initial value and do not include it
in `appliedFields`.
- Ignore tiered pricing such as `context_over_200k` in Phase 1. Add a
code comment in the adapter explaining that Coder currently persists
flat pricing only.
- Do not show a UI caveat for tiered pricing in Phase 1.
- Do not set `compressionThreshold` from Known Models.
- Do not prefill provider-specific reasoning or thinking fields in Phase
1, including:
  - OpenAI `reasoningEffort` and `reasoningSummary`;
  - Anthropic `sendReasoning`, `effort`, and `thinking.budgetTokens`.

## Proposed file structure

Use `knownModels/` rather than `modelDefaults/` because the data powers
both discovery and default application.

New files:

-
`site/src/pages/AgentsPage/components/ChatModelAdminPanel/knownModels/types.ts`
-
`site/src/pages/AgentsPage/components/ChatModelAdminPanel/knownModels/openai.ts`
-
`site/src/pages/AgentsPage/components/ChatModelAdminPanel/knownModels/anthropic.ts`
-
`site/src/pages/AgentsPage/components/ChatModelAdminPanel/knownModels/index.ts`
-
`site/src/pages/AgentsPage/components/ChatModelAdminPanel/knownModels/applyKnownModelDefaults.ts`
-
`site/src/pages/AgentsPage/components/ChatModelAdminPanel/ModelIdentifierField.tsx`

Existing files to modify:

-
`site/src/pages/AgentsPage/components/ChatModelAdminPanel/ModelForm.tsx`
-
`site/src/pages/AgentsPage/components/ChatModelAdminPanel/modelConfigFormLogic.ts`
-
`site/src/pages/AgentsPage/components/ChatModelAdminPanel/modelConfigFormLogic.test.ts`
-
`site/src/pages/AgentsPage/components/ChatModelAdminPanel/ChatModelAdminPanel.stories.tsx`

Documentation artifacts to keep in sync if implementing from a clean
workspace:

- `site/src/pages/AgentsPage/components/ChatModelAdminPanel/CONTEXT.md`
-
`site/src/pages/AgentsPage/components/ChatModelAdminPanel/docs/adr/0001-frontend-known-model-catalog.md`

## Implementation plan

### Phase 1: Red, define pure behavior first

1. Add tests in `modelConfigFormLogic.test.ts` or a colocated
`knownModels` test file for:
   - provider-scoped lookup;
   - normalized alias search;
   - canonicalization on selection;
   - unknown model leaves values unchanged;
   - exact canonical ID lookup;
   - safe initial-value patching;
- `appliedFields` output that excludes Model Identifier
canonicalization;
   - tiered pricing ignored;
   - missing cache pricing fields left at initial values;
   - compression threshold not populated;
   - reasoning/thinking fields not populated;
- output-token mapping prefers provider-specific exact field and never
fills both;
   - context badge formatting.
2. Add lifecycle tests where feasible:
- provider change in add mode remounts the form and resets
`initialValuesRef`, `lastAppliedProviderModelRef`, and inline
default-feedback state.
3. Add edge-case tests for event and reapplication semantics:
- selecting `gpt-5.5` then blurring does not apply defaults a second
time;
- typing `gpt-5.5-pro` then blurring applies only pro defaults, never
prefix `gpt-5.5` defaults;
- selecting one Known Model, then another, does not overwrite fields
already populated by the first selection because they no longer match
initial values;
- typing an alias then blurring does not canonicalize or apply defaults;
- an Off-catalog value for a supported provider remains valid and
preserves existing required-field validation behavior.
4. Add tests for the initial OpenAI and Anthropic catalog entries to
ensure IDs, source metadata, and display order remain intentional.

Quality gate: targeted unit tests fail for missing implementation.

### Phase 2: Green, add Known Model catalog and pure helpers

1. Add `knownModels/types.ts` with readonly types for catalog records
and source metadata.
2. Add `knownModels/openai.ts` and `knownModels/anthropic.ts` with the
initial catalog entries and file-level refresh comments.
3. Add lookup and search helpers in `knownModels/index.ts`.
4. Add `applyKnownModelDefaults(...)` as a pure helper that accepts:
   - current form values;
   - initial form values;
   - selected provider;
   - Known Model;
   - provider field mapping helpers if needed.
5. Ensure assertions or explicit guards make impossible cases fail fast
during tests, for example missing provider, missing canonical ID, or
invalid source metadata.

Quality gate: targeted unit tests pass.

### Phase 3: Wire Model Identifier autocomplete UX

Autocomplete integration constraints:

- Control the shared `Autocomplete` with `inputValue` for the free-text
Model Identifier string and `value: KnownModel | null` for selected
suggestions.
- Pass pre-filtered Known Model options to `Autocomplete`; do not rely
on `cmdk` internal filtering once `inputValue` is controlled.
- Clear the selected `KnownModel | null` value whenever the admin types
arbitrary text that no longer corresponds to the selected Known Model.
- Guard selection and blur event ordering so selecting a row does not
cause the input blur handler to apply defaults a second time.
- Run exact-match blur behavior only when focus leaves the whole
field/combobox, not when focus moves into the suggestion list.
- Store the last-applied provider/model pair in form-local state or a
ref so add-mode provider remounts reset it naturally.
- Preserve the existing field contract: label, tooltip/help text,
`name`, validation error rendering, `aria-invalid`, `aria-describedby`,
disabled state, Formik blur/touched behavior, and submitted request
shape.

1. Add `ModelIdentifierField.tsx`.
2. Preserve existing plain `Input` markup for edit mode, duplicate mode,
and unsupported providers.
3. For add-mode supported providers, render `Autocomplete` with:
   - controlled free-text value tied to Formik's `model` field;
- custom row rendering with display name, canonical ID, and context
badge;
   - open-on-empty-focus behavior;
- non-blocking no-match copy for non-empty supported-provider queries;
   - keyboard support inherited from `Autocomplete`.
4. On Known Model selection:
   - set the form's `model` field to the canonical ID;
   - apply defaults immediately;
   - show inline feedback only if fields changed.
5. On blur:
- if the final field value exactly equals a Known Model canonical ID,
apply defaults safely;
   - do not auto-apply aliases on blur.
6. Track the last applied provider/model pair in the form session to
avoid repeated reapplication.

Quality gate: Storybook stories compile and the main interaction paths
work locally.

### Phase 4: Storybook and UX coverage

Add or extend `ChatModelAdminPanel.stories.tsx` with three user-visible
flows:

1. OpenAI happy path:
   - open Add Model for OpenAI;
   - focus empty Model Identifier;
   - suggestions appear;
   - select `GPT-5.5`;
   - assert `gpt-5.5` is in the input;
   - assert inline defaults note appears;
   - assert visible context limit and max output fields populate;
- expand the pricing section before asserting pricing fields, or keep
detailed pricing assertions in unit tests if the Storybook UI would
become brittle.
2. Anthropic happy path:
   - open Add Model for Anthropic;
   - select `Claude Opus 4.7`;
- assert canonical ID, visible context limit, and output field populate;
- expand the pricing section before asserting pricing fields, or keep
detailed pricing assertions in unit tests if the Storybook UI would
become brittle;
   - assert Anthropic reasoning/thinking fields remain blank.
3. Unsupported provider fallback:
   - open Add Model for Azure or openai-compat;
- assert Model Identifier behaves as plain free text and no suggestion
popover appears.

If practical, include one keyboard selection path in Storybook or manual
dogfooding:

- tab/focus Model Identifier;
- arrow to a suggestion;
- press Enter;
- verify canonicalization and defaults.

Quality gate: Storybook interaction tests pass for touched stories.

### Phase 5: Refactor and documentation pass

1. Keep catalog data isolated from UI rendering code.
2. Keep provider field mapping in one helper so future Google, Bedrock,
OpenRouter, or Azure support does not require editing defaulting logic
everywhere.
3. Ensure comments explain why tiered pricing and reasoning defaults are
excluded.
4. Update `CONTEXT.md` and ADR if implementation changes any design
decision captured there.
5. Run formatting and linting for touched frontend files.

Quality gate: no broad refactors beyond this feature's files.

## Validation commands

Use the repo's existing frontend validation commands, scoped where
possible:

- `pnpm -C site test <targeted ChatModelAdminPanel pattern>`
- `pnpm -C site test <targeted modelConfigFormLogic pattern>`
- `pnpm -C site test:storybook`
- `pnpm -C site lint:types`
- `pnpm -C site check`

If command names differ in this workspace, inspect `site/package.json`
and use the closest existing targeted commands. Do not claim success
until the actual commands run and pass.

## Dogfooding plan

Primary dogfood path is Storybook because this is a form-level UI
improvement using mocked admin data.

1. Run Storybook for the Chat Model Admin Panel.
2. Record a short video showing:
- OpenAI Add Model, focus empty Model Identifier, suggestions appear,
select `GPT-5.5`, defaults note appears, fields populate;
- Anthropic Add Model, select `Claude Opus 4.7`, fields populate,
reasoning/thinking fields remain blank;
- unsupported provider Add Model, Model Identifier stays free text with
no suggestions.
3. Capture screenshots for the final state of each flow and attach them
for review.
4. If implementation touches routing, `ModelsSection` URL state, or
provider pages, also run the local UI and record
`/agents/settings/models?newModel=openai` exercising the same OpenAI
flow.

## Acceptance criteria

- Add-mode native OpenAI and Anthropic Model Identifier fields provide
discovery suggestions from the curated Known Model catalog.
- Suggestions appear on empty focus and filter as the admin types.
- Unsupported providers, edit mode, and duplicate mode preserve the
current plain input behavior.
- Selecting a Known Model canonicalizes the field and safely applies
objective defaults.
- Exact typed/pasted canonical IDs apply defaults on blur.
- Off-catalog Model Identifiers remain valid and non-blocking.
- Display name, context limit, output-token field, and flat pricing fill
only when target fields still match initial values.
- Compression threshold, tiered pricing, and provider-specific
reasoning/thinking fields are not populated by Phase 1 defaults.
- Inline feedback appears only when default application changed at least
one field.
- Unit tests, Storybook coverage, typecheck, formatting, and lint/check
commands pass.
- Dogfooding includes screenshots and video recordings.

## Risks and mitigations

- **Catalog staleness**: models change frequently. Mitigate with source
metadata and clear file-level refresh comments.
- **Provider namespace mistakes**: Azure, Bedrock, OpenRouter, and
openai-compat use different identifier semantics. Mitigate by supporting
only native OpenAI and Anthropic in Phase 1.
- **Auto-fill surprise**: defaults can feel magical. Mitigate with
selection-first UX, blur-only exact-match behavior, initial-value safety
checks, and inline feedback.
- **Pricing inaccuracy for tiered models**: current form persists flat
prices only. Mitigate by mapping base flat prices only and documenting
tiered pricing as out of scope.
- **Reasoning option overreach**: generic source metadata does not map
cleanly to provider-specific controls. Mitigate by leaving
reasoning/thinking fields blank in Phase 1.
- **Overbroad UI changes**: replacing an input can affect accessibility
and keyboard users. Mitigate by using the shared Autocomplete primitive,
preserving plain Input fallback, and dogfooding keyboard selection.


</details>

---
_Generated with [`mux`](https://github.com/coder/mux) • Model:
`anthropic:claude-opus-4-7` • Thinking: `max`_
2026-05-04 16:40:11 +02:00
Jaayden Halko 6149fc3619 feat(site): add colorblind-friendly themes for protan/deuter and tritan (#24672)
This is part 1 to lay the foundation for the theme changes.

Part 2 which adds the UI implementation is in this PR,
https://github.com/coder/coder/pull/24680

-----------------

Adds four sitewide colorblind-friendly theme palettes alongside the
existing
light and dark themes. The palettes retune the red/green and blue/yellow
semantic axes so success/error, warning, and diff additions/deletions
remain distinguishable under the most common color vision deficiencies.

| Preference ID | Purpose |
|---|---|
| `dark-protan-deuter` / `light-protan-deuter` | Protanopia &
deuteranopia (red/green). Success and additions shift to sky-blue;
destructive and deletions shift to vermilion/orange; warning shifts to
fuchsia so warning and destructive states do not collapse onto the same
hue. |
| `dark-tritan` / `light-tritan` | Tritanopia (blue/yellow). Warning
shifts from amber to fuchsia; red/green semantic pair is preserved. |

The diff panel and every semantic role (`success`, `error`, `warning`,
`notice`, `danger`) pick up the new palette automatically because they
consume the sitewide CSS variables in `site/src/index.css`. No backend
or database change is required: `theme_preference` is already a
free-form `text` column.

The existing `"dark"`, `"light"`, and `"auto"` preferences are
unchanged.

This PR ships the palettes and the resolution machinery
(`CONCRETE_THEMES`, `resolveThemeName`, `isConcreteThemeName`, and the
ThemeProvider/AgentEmbedPage plumbing). It intentionally does **not**
add UI to select the new themes; the follow-up PR #24680 adds a Theme
mode dropdown (Sync with system / Single theme) that exposes every
concrete theme, including the four added here.

Produced with Coder Agents assistance.

<details>
<summary>Implementation plan and decision log</summary>

Full plan (investigation, file layout, TDD phases, open risks) is
attached to the chat that produced this PR.

Key decisions:

- **Sitewide, not agent-scoped.** The diff panel already consumes the
sitewide theme via CSS variables. Keeping the change at the user
appearance layer also fixes red/green accents in alerts, badges, and
build states in one change, and matches how comparable products (e.g.
GitHub) ship this feature.
- **No backend change.** `codersdk/users.go` already accepts any
`theme_preference` string, and `ThemeProvider` now has a shared resolver
(`resolveThemeName`) that maps any persisted value to a concrete theme,
tolerating unknowns and the legacy `"auto"` value.
- **Palette provenance.** The protan/deuter palette is inspired by
CVD-safe blue/orange palettes and tuned within the existing Tailwind
color scales; the tritan palette keeps red/green semantics intact and
shifts warning to fuchsia. This PR does not claim exact Okabe-Ito or
WCAG AA derivation without recorded contrast data.
- **UI deferred.** Selecting the new themes is gated on the follow-up PR
#24680 which replaces the flat theme grid with a Theme mode dropdown.

</details>
2026-05-04 14:02:58 +01:00
Ben Potter 6711552f7b docs: add Coder Agents to README and about page (#24915)
Adds Coder Agents messaging to the README and about page
(docs/README.md), and updates the hero screenshots.

**README.md**: Adds agents to the tagline, intro paragraph, feature
bullets, and documentation links. Reorders docs section (Workspaces,
Templates, Agents, Administration, Premium, IDEs). Refreshes
integrations: Registry first, renames Dev Container Builder to Dev
Containers, Setup Coder to GitHub Actions, adds community
templates/modules/Discord links. Removes "we" language and vague link
text per docs style feedback.

**docs/README.md**: Adds dedicated Coder Workspaces and Coder Agents
sections with inline links to their respective doc pages. Rewrites "Why
remote development" as prose instead of a flat bullet list. Adds agents
benefits to "Why Coder" (MCP servers, skills, system prompts). Fixes
heading punctuation, replaces "Up next" with "Learn more", corrects
ARM/OS positioning. Removes stale Coder v1 section.

**Screenshots**: Replaces hero-image.png with an updated screenshot
showing templates and a running workspace with IDE apps. Adds
agents-hero-image.png showing the agents chat UI with the git diff
sidebar.

> Generated with [Coder Agents](https://coder.com/agents)
2026-05-04 07:30:41 -05:00
Michael Suchacz 033ed0bb82 feat: add admin-configurable chat title generation model (#24838)
Adds an admin-configurable deployment-wide setting that controls which
model is used for chat title generation. Admins can pick any enabled
chat model config from the Agents settings page, or leave the setting
unset to keep the existing fast-models-then-chat-model fallback
algorithm.

When a model is selected, both automatic and manual title generation use
only that model, with no silent fallback. When the configured model is
disabled, missing credentials, or otherwise unusable, automatic title
generation skips entirely (best-effort) and manual title regeneration
returns a clear error, so admins notice the misconfiguration instead of
silently routing title traffic through another provider.

## Surface

- New deployment-wide setting stored as a `site_configs` row
(`agents_chat_title_generation_model_override`).
- New experimental endpoint `GET/PUT
/api/experimental/chats/config/model-override/{context}`.
- Frontend: title generation now appears as a third dropdown on the
Agents admin settings page alongside the existing general and explore
context overrides.

## DRY refactors folded in

Title generation is integrated as a third value of the existing
`ChatModelOverrideContext` type alongside `general` and `explore`,
sharing the parameterized HTTP route, SDK methods, generated types, and
frontend API plumbing rather than introducing a parallel surface. The
`Agent` prefix was dropped from the type and route since title
generation is not a delegated agent.

The chatd model-override resolver is also shared.
`resolveConfiguredModelOverride` now takes a `failureMode` parameter:

- Subagent overrides use soft failure: misconfigured overrides are
logged and the parent model is used.
- Title generation uses hard failure: misconfigured overrides return an
explicit error so manual title regeneration surfaces the
misconfiguration and automatic title generation skips instead of
silently falling back.

> Mux is acting on Mike's behalf.
2026-05-04 13:13:00 +02:00
Michael Suchacz 203b0a9df8 refactor(coderd/x/chatd): extract OpenAI logic into chatopenai package (#24788)
Extracts OpenAI-specific logic from `coderd/x/chatd` into
`coderd/x/chatd/chatopenai` so the main chat path no longer references
`fantasyopenai` directly for chain mode info, response IDs, web search
tooling, or option mapping.

Structural refactor. The only deliberate behavioral narrowing is
consolidating Responses store checks and related keyed option or
metadata access on `opts[fantasyopenai.Name]`. That is documented by
`TestIsResponsesStoreEnabledIgnoresMalformedNonOpenAIKey` and is
unreachable in production where Responses options always live under
`fantasyopenai.Name`.

Summary:

- Moves OpenAI Responses chain mode info, response ID helpers, web
search tool construction, and provider option conversion into
`chatopenai`.
- Keeps Anthropic, Google, OpenRouter, and Vercel provider branches as
thin, existing code paths.
- `chatopenai` only imports `chatprompt` from chatd subpackages. It does
not import `chatd`, `chatloop`, `chatprovider`, or `chaterror`.
- Follow-up review fixes align helper names, keyed provider option
access, map cloning behavior, and PR documentation with the extracted
package boundary.
- Final sweep trims unused chain-mode state, removes a duplicate
store-check test case, drops an unused provider-tool parameter, and
shares the chat-message test helper through `chattest`.

> Mux is updating this PR on Mike's behalf.
2026-05-04 11:17:19 +02:00
Ethan 761adfa62a fix(coderd/rbac): grant template admin read access to dormant workspaces (#23554)
## Summary

Template admins could **list** dormant workspaces but could not **read**
them individually, resulting in a 403 when clicking into a dormant
workspace that was visible in the list.

### Root cause

- `GetWorkspaces` prepares its SQL authorization filter against the
`workspace` type, so dormant workspaces pass the filter and appear in
list results for template admins.
- `GetWorkspaceByID` calls `RBACObject()` on the fetched workspace,
which returns `workspace_dormant` when `DormantAt` is set. Template
admin had zero permissions on that type, so the read was denied.

### Fix

Add `ActionRead` on `ResourceWorkspaceDormant` to both the site-level
`template-admin` and org-level `organization-template-admin` roles. This
is the minimal grant needed to make list and read consistent without
granting any lifecycle permissions (create, update, delete, stop, etc.)
on dormant workspaces.

Split the `WorkspaceDormant` RBAC test case into `WorkspaceDormantRead`
(read only) and `WorkspaceDormant` (remaining write/lifecycle actions)
so the new permission can be asserted independently.

Template admins can read non-dormant workspaces, so this is the only
missing permission.

---

> This PR was generated with Coder agents and reviewed by a human.
2026-05-04 01:55:28 +00:00
Ethan 3a153ebb15 fix(coderd/x/chatd): replay retry phase on subscribe (#24569)
Retry events were previously fire-and-forget, so subscribers that
connected after a retry started only saw durable history plus
`status=running` and could not tell the stream was backing off.

Keep the current retry phase in `chatStreamState`, capture it atomically
with subscriber registration, replay it in the initial snapshot for
same-chat late joiners, and clear it when streaming resumes or ends so
reconnects get consistent retry state without duplicate delivery at the
subscription boundary.

Relates to CODAGT-139
2026-05-04 11:48:39 +10:00
Kyle CarberryandCoder Agents d889ba1842 feat: add user_oidc auth type for MCP servers (#24793)
Adds a 5th MCP server authentication mode, `user_oidc` ("User OIDC
Identity"), that forwards the calling user's OIDC access token from
`user_links.oauth_access_token` to the upstream MCP server as
`Authorization: Bearer <token>`.

The token is read from `user_links` and refreshed transparently via
`oauth2.TokenSource` before each MCP request. No new per-MCP-server
secret storage and no per-user connect/disconnect step.

**Limitation**: only users who logged in via OIDC have a forwardable
token. Users authenticated via password or GitHub will see requests sent
without an `Authorization` header, and the upstream MCP server is
expected to respond with 401. A pluggable token source (e.g. CLI-minted
E2E tokens) is left as future work.

<details>
<summary>Implementation notes</summary>

- Schema: new
`coderd/database/migrations/000481_mcp_user_oidc_auth.{up,down}.sql`
relaxes the `mcp_server_configs.auth_type` CHECK constraint to include
`user_oidc`. Down migration deletes affected rows before restoring the
old constraint.
- SDK validation: `codersdk/mcp.go` extends `oneof` for
`CreateMCPServerConfigRequest` and `UpdateMCPServerConfigRequest`.
- Handler: `coderd/mcp.go` adds `case "user_oidc":` to the
field-clearing switch on update. The existing list and detail handlers
already report `auth_connected = true` for any non-`oauth2` auth type.
- Header construction: `coderd/x/chatd/mcpclient/mcpclient.go`
introduces a `UserOIDCTokenSource` interface and adds the `user_oidc`
case to `buildAuthHeaders`. `ConnectAll` / `connectOne` /
`buildAuthHeaders` gain `userID uuid.UUID, oidcSrc UserOIDCTokenSource`
parameters.
- Wiring: `coderd/x/chatd/chatd.go` adds `OIDCTokenSource` to `Config` /
`Server` and passes `chat.OwnerID` plus the source through `ConnectAll`.
`coderd/coderd.go` constructs the source next to the `chatd.New` call
when `options.OIDCConfig` is non-nil.
- Token source: `oidcMCPTokenSource` lives in `coderd/mcp.go`. It reads
the user's OIDC link, refreshes via `oauth2.TokenSource`, and writes the
refreshed token back to `user_links`. Logic is duplicated from
`provisionerdserver.ObtainOIDCAccessToken` to avoid an MCP ->
provisionerdserver dependency. The two copies must be kept in sync; a
comment on `oidcMCPTokenSource` records this.
- Frontend: `MCPServerAdminPanel.tsx` adds the new dropdown option, an
explanatory helper block (no admin-configurable fields), and a Storybook
story (`CreateServerUserOIDC`).
- Tests:
- `mcpclient_test.go`: `TestConnectAll_UserOIDCAuth`,
`TestConnectAll_UserOIDCAuth_NoLink`,
`TestConnectAll_UserOIDCAuth_NilSource`. All existing tests updated for
the new signature.
- `mcp_test.go`: extends `TestMCPServerConfigsAuthConnected` to assert
`auth_connected=true` for `user_oidc`; adds
`TestMCPServerConfigsUserOIDCClearsFields` and
`TestMCPServerConfigsUserOIDCDirect`.
- Docs: `docs/ai-coder/agents/platform-controls/mcp-servers.md`
describes the new mode and its OIDC-only limitation.

</details>

This PR was created by Coder Agents.

---------

Co-authored-by: Coder Agents <agents@coder.com>
2026-05-03 11:31:48 -04:00
Jon Ayers 6b9637d85a feat: replace pgcoordinator pg_notify triggers with app-level Publish() (#24717) 2026-05-01 15:00:08 -05:00
Asher 453a39be97 feat: show ui for individual failed scripts (#24506)
Previously we only showed an error when the startup script failed.  Now:

- Add a warning icon to each failed script.
- Sort the failed script tabs first.
- Modify agent health messages to pull the errors notices from the new 
  location instead of from the single agent lifecycle enum. This means
  errors are shown for each script and the count is accurate.
2026-05-01 10:54:23 -08:00
Ben Potter 67fc169c06 fix(site): remove "Tasks on Docker" as featured template (#24908)
Removes "Tasks on Docker" from the featured/prioritized template lists
in the templates empty state and the starter templates gallery. Docker
remains as the primary featured starter template.

Fixes https://linear.app/codercom/issue/DEVREL-20

> Generated with [Coder Agents](https://coder.com/agents)
2026-05-01 13:50:54 -05:00
Garrett Delfosse a8222e02e5 fix(scripts/releaser): fix tag sorting and changelog blurb for older branches (#24798)
Fixes two bugs in the release tool.

## 1. RC tags chosen over release tags on release branches

`allSemverTags()` and `mergedSemverTags()` rely on `git tag
--sort=-v:refname` for ordering. Git's version sort treats pre-release
suffixes (e.g. `-rc.0`) as *greater* than the base release version,
which is the opposite of semver where `v2.32.0 > v2.32.0-rc.0`.

When the release branch code iterates the tag list looking for the first
matching `major.minor`, it finds the RC tag first, leading to incorrect
version suggestions (e.g. suggesting `v2.32.0` again instead of
`v2.32.1`).

**Fix:** Re-sort parsed tags using the existing `GreaterThan` method via
a new `sortVersionsDesc` helper.

## 2. Misleading mainline changelog blurb on ESR/older branch patches

When releasing a patch on an older branch (e.g. `release/2.29` for ESR),
the version is neither mainline nor stable. Declining the stable prompt
would always produce the mainline changelog note ("This is a mainline
Coder release..."), which is incorrect.

**Fix:** Only emit the mainline note when the version's minor matches
the current mainline series. For older branches the changelog omits the
note entirely.

> Generated by Coder Agents
2026-05-01 14:41:09 -04:00
Ben Potter 2487005cca docs(docs/install): remove outdated Apple Silicon ARM64 warning (#24906)
Removes the outdated Apple Silicon ARM64 warning block from the install
docs.

Coder compiles fine for ARM64, and the chip variant list (M1/M2/M3/M4)
would never stay up to date as new chips are released.

Fixes https://linear.app/codercom/issue/DEVREL-19

> Generated with [Coder Agents](https://coder.com/agents)
2026-05-01 13:36:54 -05:00
Zach 1c7064c066 fix: use atomic.Int64 for workspace traffic metrics (#24844)
connMetrics.total was written to via atomic.AddInt64 and read as a plain
int64, producing a data race. Fix by switching the field to atomic.Int64
and using its typed Add/Load methods.

The testMetrics mock had a similar issue where mutex use was missing
where GetTotalBytes read the total bytes, which is also fixed in this
change.
2026-05-01 09:16:42 -06:00
Jeremy Ruppel 8709d42fe0 feat(site): add loading <Spinner /> to AgentRow (#24825)
Adds a `<Spinner />` next to the log count during agent startup.

Also, there was some complexity in sizing the spinner because `<Badge
/>` automatically sizes any `svg`s it contains to `size-icon-xs`. In
order to maintain the `svg` sizing inside existing Badges across the
site, this introduces a new `svgSize` prop that defaults to `xs`.
Existing consumers will still get `[&_svg]:size-icon-xs` regardless of
the Badge size, but can now be overridden to `sm` or `lg` (there is no
`md`).

Also also fixes a tiny spacing issue with the warning triangle
🕵️‍♂️

<img width="1203" height="624" alt="Screenshot 2026-04-29 at 3 24 35 PM"
src="https://github.com/user-attachments/assets/e4fc4a3a-e88f-4253-a697-195f8a347230"
/>
2026-05-01 10:57:30 -04:00
Jake Howell fa227be74a feat: de-mui <AccountForm /> (#24859)
This pull-request takes our `<AccountForm />`'s dependencies and removes
the reliance on `@mui/Material/TextField` for the `<AccountForm />`.

| Old | New |
| --- | --- |
| <img width="521" height="392" alt="account_settings_old"
src="https://github.com/user-attachments/assets/3dc4e2d9-7176-438c-a522-5c55d3ad122a"
/> | <img width="520" height="447" alt="account_settings_new"
src="https://github.com/user-attachments/assets/cb9f2da8-d848-4b3e-923a-b212f73e6a1c"
/> |
2026-05-02 00:13:06 +10:00
Jaayden Halko efda5c2c12 feat: disable Git controls when Git is not active (#24673)
closes CODAGT-148

In chats with no Git context (no repositories known to the watcher, no
PR tab, no remote diff), the refresh button fires an "Unable to refresh
git status" toast because the watcher WebSocket never opens.

Derive `isGitActive = repositories.size > 0 || showRemoteTab` in
`GitPanel` and use it to:

- Disable the refresh button, unified-diff toggle, and split-diff toggle
  with a "Git is not set up for this chat" tooltip.
- Show a dedicated empty state explaining how to enable Git, replacing
  the generic "No pushed changes yet" copy.

Chats with at least one repository or a PR tab are unaffected; all
controls remain enabled and behave as before.

Adds a `GitNotActive` Storybook story with play-function assertions
covering the disabled controls and empty-state copy.
2026-05-01 14:46:46 +01:00
Jaayden Halko a799356bc3 feat(site/src/pages/AgentsPage/components/Sidebar): animate generated rename title (#24860)
Animates the generated rename title returned by `onPropose` into the
rename input character-by-character, replacing the previous instant set.

Uses a local `requestAnimationFrame` typing loop (~80 chars/sec) with
`Intl.Segmenter` for grapheme-safe splitting, gated by the existing
`sessionRef` race protection so stale generate responses and stale
animation frames cannot overwrite the active dialog. The animation is
canceled on dialog close, cancel, submit, chat change, generate retry,
manual input edits, and unmount. Save is disabled while the generated
title is still typing so partial values cannot be saved. Storybook
coverage updated to assert an intermediate animated prefix,
disabled-while-typing button states, and that errors do not start an
animation.
2026-05-01 14:44:19 +01:00
dependabot[bot] 7fe86429b7 chore: bump the react group across 1 directory with 3 updates (#24865)
Bumps the react group with 3 updates in the /site directory:
[react](https://github.com/facebook/react/tree/HEAD/packages/react),
[@types/react](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/react)
and
[react-dom](https://github.com/facebook/react/tree/HEAD/packages/react-dom).

Updates `react` from 19.2.2 to 19.2.5
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/facebook/react/releases">react's
releases</a>.</em></p>
<blockquote>
<h2>19.2.5 (April 8th, 2026)</h2>
<h2>React Server Components</h2>
<ul>
<li>Add more cycle protections (<a
href="https://redirect.github.com/facebook/react/pull/36236">#36236</a>
by <a href="https://github.com/eps1lon"><code>@​eps1lon</code></a> and
<a
href="https://github.com/unstubbable"><code>@​unstubbable</code></a>)</li>
</ul>
<h2>19.2.4 (January 26th, 2026)</h2>
<h2>React Server Components</h2>
<ul>
<li>Add more DoS mitigations to Server Actions, and harden Server
Components (<a
href="https://redirect.github.com/facebook/react/pull/35632">#35632</a>
by <a href="https://github.com/gnoff"><code>@​gnoff</code></a>, <a
href="https://github.com/lubieowoce"><code>@​lubieowoce</code></a>, <a
href="https://github.com/sebmarkbage"><code>@​sebmarkbage</code></a>, <a
href="https://github.com/unstubbable"><code>@​unstubbable</code></a>)</li>
</ul>
<h2>19.2.3 (December 11th, 2025)</h2>
<h2>React Server Components</h2>
<ul>
<li>Add extra loop protection to React Server Functions (<a
href="https://github.com/sebmarkbage"><code>@​sebmarkbage</code></a> <a
href="https://redirect.github.com/facebook/react/pull/35351">#35351</a>)</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/facebook/react/commit/23f4f9f30da9e9af2108c18bb197bae75ab584ea"><code>23f4f9f</code></a>
19.2.5</li>
<li><a
href="https://github.com/facebook/react/commit/90ab3f89f4824ac763b6f877c6f711200d1338d2"><code>90ab3f8</code></a>
Version 19.2.4</li>
<li><a
href="https://github.com/facebook/react/commit/612e371fb215498edde4c853bd1e0c8e9203808f"><code>612e371</code></a>
Version 19.2.3</li>
<li>See full diff in <a
href="https://github.com/facebook/react/commits/v19.2.5/packages/react">compare
view</a></li>
</ul>
</details>
<br />

Updates `@types/react` from 19.2.7 to 19.2.14
<details>
<summary>Commits</summary>
<ul>
<li>See full diff in <a
href="https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/react">compare
view</a></li>
</ul>
</details>
<br />

Updates `react-dom` from 19.2.2 to 19.2.5
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/facebook/react/releases">react-dom's
releases</a>.</em></p>
<blockquote>
<h2>19.2.5 (April 8th, 2026)</h2>
<h2>React Server Components</h2>
<ul>
<li>Add more cycle protections (<a
href="https://redirect.github.com/facebook/react/pull/36236">#36236</a>
by <a href="https://github.com/eps1lon"><code>@​eps1lon</code></a> and
<a
href="https://github.com/unstubbable"><code>@​unstubbable</code></a>)</li>
</ul>
<h2>19.2.4 (January 26th, 2026)</h2>
<h2>React Server Components</h2>
<ul>
<li>Add more DoS mitigations to Server Actions, and harden Server
Components (<a
href="https://redirect.github.com/facebook/react/pull/35632">#35632</a>
by <a href="https://github.com/gnoff"><code>@​gnoff</code></a>, <a
href="https://github.com/lubieowoce"><code>@​lubieowoce</code></a>, <a
href="https://github.com/sebmarkbage"><code>@​sebmarkbage</code></a>, <a
href="https://github.com/unstubbable"><code>@​unstubbable</code></a>)</li>
</ul>
<h2>19.2.3 (December 11th, 2025)</h2>
<h2>React Server Components</h2>
<ul>
<li>Add extra loop protection to React Server Functions (<a
href="https://github.com/sebmarkbage"><code>@​sebmarkbage</code></a> <a
href="https://redirect.github.com/facebook/react/pull/35351">#35351</a>)</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/facebook/react/commit/23f4f9f30da9e9af2108c18bb197bae75ab584ea"><code>23f4f9f</code></a>
19.2.5</li>
<li><a
href="https://github.com/facebook/react/commit/90ab3f89f4824ac763b6f877c6f711200d1338d2"><code>90ab3f8</code></a>
Version 19.2.4</li>
<li><a
href="https://github.com/facebook/react/commit/612e371fb215498edde4c853bd1e0c8e9203808f"><code>612e371</code></a>
Version 19.2.3</li>
<li>See full diff in <a
href="https://github.com/facebook/react/commits/v19.2.5/packages/react-dom">compare
view</a></li>
</ul>
</details>
<br />

Updates `@types/react` from 19.2.7 to 19.2.14
<details>
<summary>Commits</summary>
<ul>
<li>See full diff in <a
href="https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/react">compare
view</a></li>
</ul>
</details>
<br />

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-05-01 13:31:12 +00:00
dependabot[bot] f17e0e354a chore: bump diff from 8.0.3 to 8.0.4 in /site (#24875)
Bumps [diff](https://github.com/kpdecker/jsdiff) from 8.0.3 to 8.0.4.
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/kpdecker/jsdiff/blob/master/release-notes.md">diff's
changelog</a>.</em></p>
<blockquote>
<h2>8.0.4</h2>
<ul>
<li><a
href="https://redirect.github.com/kpdecker/jsdiff/pull/667">#667</a> -
<strong>fix another bug in <code>diffWords</code> when used with an
<code>Intl.Segmenter</code></strong>. If the text to be diffed included
a combining mark after a whitespace character (i.e. roughly speaking, an
accented space), <code>diffWords</code> would previously crash. Now this
case is handled correctly.</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/kpdecker/jsdiff/commit/dd2f99497703a1540b2ae406b51c49b74b5fc1a1"><code>dd2f994</code></a>
8.0.4 release (<a
href="https://redirect.github.com/kpdecker/jsdiff/issues/678">#678</a>)</li>
<li><a
href="https://github.com/kpdecker/jsdiff/commit/3cc438434db53c5d1c40412b727ea7650f6f145a"><code>3cc4384</code></a>
Update docs on releasing to reflect migration to yarn berry (<a
href="https://redirect.github.com/kpdecker/jsdiff/issues/677">#677</a>)</li>
<li><a
href="https://github.com/kpdecker/jsdiff/commit/6fc2aa6b7672af08774b50aae00d97b99c5b5715"><code>6fc2aa6</code></a>
yarn up '*' &amp;&amp; yarn up -R '**' (<a
href="https://redirect.github.com/kpdecker/jsdiff/issues/676">#676</a>)</li>
<li><a
href="https://github.com/kpdecker/jsdiff/commit/af7393ac3404565dc8da655c2e7aeeed28c01ff7"><code>af7393a</code></a>
yarn up '*' &amp;&amp; yarn up -R '**' (<a
href="https://redirect.github.com/kpdecker/jsdiff/issues/670">#670</a>)</li>
<li><a
href="https://github.com/kpdecker/jsdiff/commit/4b5d1800370bf29b61a3378fb8086aeb231d3ef7"><code>4b5d180</code></a>
Fix another bug in diffWords's &quot;intlSegmenter&quot; mode (<a
href="https://redirect.github.com/kpdecker/jsdiff/issues/667">#667</a>)</li>
<li><a
href="https://github.com/kpdecker/jsdiff/commit/10da50c466709e7bd4b192dac96af0af46f8b7bd"><code>10da50c</code></a>
yarn up '*' &amp;&amp; yarn up -R '**' (<a
href="https://redirect.github.com/kpdecker/jsdiff/issues/666">#666</a>)</li>
<li><a
href="https://github.com/kpdecker/jsdiff/commit/8dc164b5d133b8114738927aa90ed6dfcf49d497"><code>8dc164b</code></a>
Migrate from Yarn Classic to Yarn Berry (<a
href="https://redirect.github.com/kpdecker/jsdiff/issues/662">#662</a>)</li>
<li><a
href="https://github.com/kpdecker/jsdiff/commit/750fbd6472fcdda02d90f8c7d04afa7119953447"><code>750fbd6</code></a>
yarn upgrade --latest (<a
href="https://redirect.github.com/kpdecker/jsdiff/issues/661">#661</a>)</li>
<li><a
href="https://github.com/kpdecker/jsdiff/commit/abe2bde240f9fb65d29ebf275fb8fec7d39b1d63"><code>abe2bde</code></a>
Add release notes for undocumented releases (<a
href="https://redirect.github.com/kpdecker/jsdiff/issues/658">#658</a>)</li>
<li>See full diff in <a
href="https://github.com/kpdecker/jsdiff/compare/v8.0.3...8.0.4">compare
view</a></li>
</ul>
</details>
<br />

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-05-01 13:21:25 +00:00
dependabot[bot] 241599750f chore: bump @rolldown/plugin-babel from 0.2.2 to 0.2.3 in /site (#24878)
Bumps
[@rolldown/plugin-babel](https://github.com/rolldown/plugins/tree/HEAD/packages/babel)
from 0.2.2 to 0.2.3.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/rolldown/plugins/releases"><code>@​rolldown/plugin-babel</code>'s
releases</a>.</em></p>
<blockquote>
<h2>plugin-babel@0.2.3</h2>
<p>Please refer to <a
href="https://github.com/rolldown/plugins/blob/plugin-babel@0.2.3/packages/babel/CHANGELOG.md">CHANGELOG.md</a>
for details.</p>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/rolldown/plugins/blob/main/packages/babel/CHANGELOG.md"><code>@​rolldown/plugin-babel</code>'s
changelog</a>.</em></p>
<blockquote>
<h2><!-- raw HTML omitted --><a
href="https://github.com/rolldown/plugins/compare/plugin-babel@0.2.2...plugin-babel@0.2.3">0.2.3</a>
(2026-04-13)<!-- raw HTML omitted --></h2>
<h3>Bug Fixes</h3>
<ul>
<li><strong>babel:</strong> exclude rolldown runtime module by default
(<a
href="https://redirect.github.com/rolldown/plugins/issues/57">#57</a>)
(<a
href="https://github.com/rolldown/plugins/commit/d42ec45ded69e93870d1dfc2977ae11f5ab01e01">d42ec45</a>)</li>
<li><strong>deps:</strong> update all non-major dependencies (<a
href="https://redirect.github.com/rolldown/plugins/issues/35">#35</a>)
(<a
href="https://github.com/rolldown/plugins/commit/f359c3923b3802e4efa68da6c9e85aec1fda96d3">f359c39</a>)</li>
<li><strong>deps:</strong> update all non-major dependencies (<a
href="https://redirect.github.com/rolldown/plugins/issues/40">#40</a>)
(<a
href="https://github.com/rolldown/plugins/commit/1963ed13059fb08caf33ca96739c3b90f5b10099">1963ed1</a>)</li>
<li><strong>deps:</strong> update all non-major dependencies (<a
href="https://redirect.github.com/rolldown/plugins/issues/49">#49</a>)
(<a
href="https://github.com/rolldown/plugins/commit/8047e05a978ba7e0544111d8c2deb7ca335af076">8047e05</a>)</li>
<li><strong>deps:</strong> update rolldown-related dependencies (<a
href="https://redirect.github.com/rolldown/plugins/issues/36">#36</a>)
(<a
href="https://github.com/rolldown/plugins/commit/b2bf24bd65d23bd051aa2f7b3cdee22ca1d58e2f">b2bf24b</a>)</li>
<li><strong>deps:</strong> update rolldown-related dependencies (<a
href="https://redirect.github.com/rolldown/plugins/issues/46">#46</a>)
(<a
href="https://github.com/rolldown/plugins/commit/6b7fcfcc8f0107c0c698ead7d29a65d4ea7c46cd">6b7fcfc</a>)</li>
<li><strong>deps:</strong> update rolldown-related dependencies (<a
href="https://redirect.github.com/rolldown/plugins/issues/50">#50</a>)
(<a
href="https://github.com/rolldown/plugins/commit/232515f251da54c60e0e139d655677f62c3868e5">232515f</a>)</li>
<li><strong>deps:</strong> update rolldown-related dependencies (<a
href="https://redirect.github.com/rolldown/plugins/issues/55">#55</a>)
(<a
href="https://github.com/rolldown/plugins/commit/c43259004d90b7a0e5eb9b8ede94de3e651f25c1">c432590</a>)</li>
</ul>
<h3>Miscellaneous Chores</h3>
<ul>
<li><strong>deps:</strong> update dependency <code>@​types/node</code>
to v24 (<a
href="https://redirect.github.com/rolldown/plugins/issues/38">#38</a>)
(<a
href="https://github.com/rolldown/plugins/commit/d6b8baaf69d80604a9204e018db6cd4a1e4809ba">d6b8baa</a>)</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/rolldown/plugins/commit/015e64a267e3de500d3141b017bfacd6d287776c"><code>015e64a</code></a>
release: plugin-babel@0.2.3</li>
<li><a
href="https://github.com/rolldown/plugins/commit/d42ec45ded69e93870d1dfc2977ae11f5ab01e01"><code>d42ec45</code></a>
fix(babel): exclude rolldown runtime module by default (<a
href="https://github.com/rolldown/plugins/tree/HEAD/packages/babel/issues/57">#57</a>)</li>
<li><a
href="https://github.com/rolldown/plugins/commit/c43259004d90b7a0e5eb9b8ede94de3e651f25c1"><code>c432590</code></a>
fix(deps): update rolldown-related dependencies (<a
href="https://github.com/rolldown/plugins/tree/HEAD/packages/babel/issues/55">#55</a>)</li>
<li><a
href="https://github.com/rolldown/plugins/commit/232515f251da54c60e0e139d655677f62c3868e5"><code>232515f</code></a>
fix(deps): update rolldown-related dependencies (<a
href="https://github.com/rolldown/plugins/tree/HEAD/packages/babel/issues/50">#50</a>)</li>
<li><a
href="https://github.com/rolldown/plugins/commit/8047e05a978ba7e0544111d8c2deb7ca335af076"><code>8047e05</code></a>
fix(deps): update all non-major dependencies (<a
href="https://github.com/rolldown/plugins/tree/HEAD/packages/babel/issues/49">#49</a>)</li>
<li><a
href="https://github.com/rolldown/plugins/commit/1963ed13059fb08caf33ca96739c3b90f5b10099"><code>1963ed1</code></a>
fix(deps): update all non-major dependencies (<a
href="https://github.com/rolldown/plugins/tree/HEAD/packages/babel/issues/40">#40</a>)</li>
<li><a
href="https://github.com/rolldown/plugins/commit/6b7fcfcc8f0107c0c698ead7d29a65d4ea7c46cd"><code>6b7fcfc</code></a>
fix(deps): update rolldown-related dependencies (<a
href="https://github.com/rolldown/plugins/tree/HEAD/packages/babel/issues/46">#46</a>)</li>
<li><a
href="https://github.com/rolldown/plugins/commit/d6b8baaf69d80604a9204e018db6cd4a1e4809ba"><code>d6b8baa</code></a>
chore(deps): update dependency <code>@​types/node</code> to v24 (<a
href="https://github.com/rolldown/plugins/tree/HEAD/packages/babel/issues/38">#38</a>)</li>
<li><a
href="https://github.com/rolldown/plugins/commit/b2bf24bd65d23bd051aa2f7b3cdee22ca1d58e2f"><code>b2bf24b</code></a>
fix(deps): update rolldown-related dependencies (<a
href="https://github.com/rolldown/plugins/tree/HEAD/packages/babel/issues/36">#36</a>)</li>
<li><a
href="https://github.com/rolldown/plugins/commit/f359c3923b3802e4efa68da6c9e85aec1fda96d3"><code>f359c39</code></a>
fix(deps): update all non-major dependencies (<a
href="https://github.com/rolldown/plugins/tree/HEAD/packages/babel/issues/35">#35</a>)</li>
<li>See full diff in <a
href="https://github.com/rolldown/plugins/commits/plugin-babel@0.2.3/packages/babel">compare
view</a></li>
</ul>
</details>
<br />

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-05-01 13:20:44 +00:00
dependabot[bot] 53e91fe60c chore: bump motion from 12.34.1 to 12.38.0 in /site (#24880)
Bumps [motion](https://github.com/motiondivision/motion) from 12.34.1 to
12.38.0.
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/motiondivision/motion/blob/main/CHANGELOG.md">motion's
changelog</a>.</em></p>
<blockquote>
<h2>[12.38.0] 2026-03-16</h2>
<h3>Added</h3>
<ul>
<li>Added <code>layoutAnchor</code> prop to configure custom anchor
point for resolving relative projection boxes.</li>
</ul>
<h3>Fixed</h3>
<ul>
<li><code>Reorder</code>: Fix axis switching after window resize.</li>
<li><code>Reorder</code>: Fix with virtualised lists.</li>
<li><code>AnimatePresence</code>: Ensure children are removed when exit
animation matches current values.</li>
</ul>
<h2>[12.37.0] 2026-03-16</h2>
<h3>Added</h3>
<ul>
<li>Support for hardware accelerating <code>&quot;start&quot;</code> and
<code>&quot;end&quot;</code> offsets in <code>scroll</code> and
<code>useScroll</code>.</li>
<li>Support for <code>oklch</code>, <code>oklab</code>,
<code>lab</code>, <code>lch</code>, <code>color</code>,
<code>color-mix</code>, <code>light-dark</code> color types.</li>
</ul>
<h3>Fixed</h3>
<ul>
<li>Fix <code>whileInView</code> with client-side navigation.</li>
<li>Fix draggable elements when layout updates due to surrounding
element re-renders.</li>
<li>Improved memory pressure of layout animations.</li>
<li>Ensure motion value returned from <code>useSpring</code> reports
correct <code>isAnimating()</code>.</li>
</ul>
<h2>[12.36.0] 2026-03-09</h2>
<h3>Added</h3>
<ul>
<li>Allow <code>dragSnapToOrigin</code> to accept
<code>&quot;x&quot;</code> or <code>&quot;y&quot;</code> for per-axis
snapping.</li>
<li>Added axis-locked layout animations with
<code>layout=&quot;x&quot;</code> and
<code>layout=&quot;y&quot;</code>.</li>
<li>Added <code>skipInitialAnimation</code> to
<code>useSpring</code>.</li>
</ul>
<h3>Fixed</h3>
<ul>
<li>Fixed <code>height</code> and <code>width: auto</code> animations
with <code>box-sizing: border-box</code>.</li>
<li>Reset component values when exit animation finishes.</li>
<li>Ensure <code>anticipate</code> easing returns <code>1</code> at
<code>p === 1</code>.</li>
<li>Fix <code>@emotion/is-prop-valid</code> resolve error in
Storybook.</li>
<li>Remove <code>data-pop-layout-id</code> from exiting elements when
animation interrupted.</li>
<li>Ensure we skip WAAPI for non-animatable keyframes.</li>
<li>Ensure we skip WAAPI for SVG transforms.</li>
<li>Ensure <code>MotionValue</code> props are not passed to SVG.</li>
<li><code>AnimatePresence</code>: Prevent
<code>mode=&quot;wait&quot;</code> elements from getting stuck when
switched rapidly.</li>
</ul>
<h2>[12.35.2] 2026-03-09</h2>
<h3>Fixed</h3>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/motiondivision/motion/commit/0bfc9fe015f7170c538ca70ba4677ec59d83ee76"><code>0bfc9fe</code></a>
v12.38.0</li>
<li><a
href="https://github.com/motiondivision/motion/commit/343cb0c69e10d5c2bcc9837fb6a83d437257f064"><code>343cb0c</code></a>
Updating layoutAnchor</li>
<li><a
href="https://github.com/motiondivision/motion/commit/ee99ad25f734287c2885d53ec0af8a8f1f6ca306"><code>ee99ad2</code></a>
Updating changelog</li>
<li><a
href="https://github.com/motiondivision/motion/commit/062660b3c5c982d7274adbd382c6dfcd5aea77ad"><code>062660b</code></a>
Updating changgelog</li>
<li><a
href="https://github.com/motiondivision/motion/commit/303da7dddfc41f521ec500aef8a72643169582e0"><code>303da7d</code></a>
Updating readme</li>
<li><a
href="https://github.com/motiondivision/motion/commit/b075adc4b1dde8fa1fb1c488b1b4e7e97a07331e"><code>b075adc</code></a>
Merge pull request <a
href="https://redirect.github.com/motiondivision/motion/issues/3647">#3647</a>
from motiondivision/feat/layout-anchor</li>
<li><a
href="https://github.com/motiondivision/motion/commit/f0991d6728f425eebbb58ce926bd33d05336b724"><code>f0991d6</code></a>
Add missing layoutAnchor !== false guard in
attemptToResolveRelativeTarget</li>
<li><a
href="https://github.com/motiondivision/motion/commit/b5798e99e78738a1fa8ec3414bff63796f9eb39b"><code>b5798e9</code></a>
Merge pull request <a
href="https://redirect.github.com/motiondivision/motion/issues/3642">#3642</a>
from motiondivision/worktree-fix-issue-3078</li>
<li><a
href="https://github.com/motiondivision/motion/commit/7686c193e349f3b3360455615ee6ca45b8532c28"><code>7686c19</code></a>
Merge pull request <a
href="https://redirect.github.com/motiondivision/motion/issues/3636">#3636</a>
from motiondivision/worktree-fix-issue-3061</li>
<li><a
href="https://github.com/motiondivision/motion/commit/a95c4877c879f0e189295cc9f4f5f1c1e1d7df2a"><code>a95c487</code></a>
Fix auto-scroll in reorder-virtualized test page</li>
<li>Additional commits viewable in <a
href="https://github.com/motiondivision/motion/compare/v12.34.1...v12.38.0">compare
view</a></li>
</ul>
</details>
<br />

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-05-01 13:17:14 +00:00
dependabot[bot] a5dc2d1ce1 chore: bump @types/node from 20.19.25 to 20.19.39 in /site (#24879)
Bumps
[@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node)
from 20.19.25 to 20.19.39.
<details>
<summary>Commits</summary>
<ul>
<li>See full diff in <a
href="https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node">compare
view</a></li>
</ul>
</details>
<br />

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-05-01 13:11:16 +00:00
dependabot[bot] d8a030bb35 chore: bump autoprefixer from 10.4.22 to 10.5.0 in /site (#24883)
Bumps [autoprefixer](https://github.com/postcss/autoprefixer) from
10.4.22 to 10.5.0.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/postcss/autoprefixer/releases">autoprefixer's
releases</a>.</em></p>
<blockquote>
<h2>10.5.0 “Each Endeavouring, All Achieving”</h2>
<!-- raw HTML omitted -->
<ul>
<li>Added <code>mask-position-x</code> and <code>mask-position-y</code>
support (by <a
href="https://github.com/toporek"><code>@​toporek</code></a>).</li>
</ul>
<h2>10.4.27</h2>
<ul>
<li>Removed development key from <code>package.json</code>.</li>
</ul>
<h2>10.4.26</h2>
<ul>
<li>Reduced package size.</li>
</ul>
<h2>10.4.25</h2>
<ul>
<li>Fixed broken gradients on CSS Custom Properties (by <a
href="https://github.com/serger777"><code>@​serger777</code></a>).</li>
</ul>
<h2>10.4.24</h2>
<ul>
<li>Made Autoprefixer a little faster (by <a
href="https://github.com/Cherry"><code>@​Cherry</code></a>).</li>
</ul>
<h2>10.4.23</h2>
<ul>
<li>Reduced dependencies (by <a
href="https://github.com/hyperz111"><code>@​hyperz111</code></a>).</li>
</ul>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/postcss/autoprefixer/blob/main/CHANGELOG.md">autoprefixer's
changelog</a>.</em></p>
<blockquote>
<h2>10.5.0 “Each Endeavouring, All Achieving”</h2>
<ul>
<li>Added <code>mask-position-x</code> and <code>mask-position-y</code>
support (by <a
href="https://github.com/toporek"><code>@​toporek</code></a>).</li>
</ul>
<h2>10.4.27</h2>
<ul>
<li>Removed development key from <code>package.json</code>.</li>
</ul>
<h2>10.4.26</h2>
<ul>
<li>Reduced package size.</li>
</ul>
<h2>10.4.25</h2>
<ul>
<li>Fixed broken gradients on CSS Custom Properties (by <a
href="https://github.com/serger777"><code>@​serger777</code></a>).</li>
</ul>
<h2>10.4.24</h2>
<ul>
<li>Made Autoprefixer a little faster (by <a
href="https://github.com/Cherry"><code>@​Cherry</code></a>).</li>
</ul>
<h2>10.4.23</h2>
<ul>
<li>Reduced dependencies (by <a
href="https://github.com/hyperz111"><code>@​hyperz111</code></a>).</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/postcss/autoprefixer/commit/faf456a4be572dbcb60cbe5d76a8927e23809ef5"><code>faf456a</code></a>
Release 10.5 version</li>
<li><a
href="https://github.com/postcss/autoprefixer/commit/b841fc53575a2e8c3dd8d04b0bc5998ee11e7587"><code>b841fc5</code></a>
Update dependencies</li>
<li><a
href="https://github.com/postcss/autoprefixer/commit/47d6e68b27009f7cb60513172f765783b55bb000"><code>47d6e68</code></a>
Update email</li>
<li><a
href="https://github.com/postcss/autoprefixer/commit/45cfc0827012fda39b809f1654136e1d5ab7ab25"><code>45cfc08</code></a>
Replace ESLint and Prettier to oxlint and oxfmt</li>
<li><a
href="https://github.com/postcss/autoprefixer/commit/7e3ec7db7274289ccc385fb788bc48f14a4e1dd8"><code>7e3ec7d</code></a>
Add prefixing support for mask-position-x and mask-position-y (<a
href="https://redirect.github.com/postcss/autoprefixer/issues/1548">#1548</a>)</li>
<li><a
href="https://github.com/postcss/autoprefixer/commit/360f2d9ecbad3315fbabc61fb2131ac939fee211"><code>360f2d9</code></a>
Release 10.4.27 version</li>
<li><a
href="https://github.com/postcss/autoprefixer/commit/ab5260c30de086760abf7f666bb52f9267ff387e"><code>ab5260c</code></a>
Update clean-publish</li>
<li><a
href="https://github.com/postcss/autoprefixer/commit/09e9dd12c023a02a90d05db46c3c75166525674c"><code>09e9dd1</code></a>
Release 10.4.26 version</li>
<li><a
href="https://github.com/postcss/autoprefixer/commit/ec7554060076640e1261e16d3af8f81c3a2b17cf"><code>ec75540</code></a>
Ignore local patches</li>
<li><a
href="https://github.com/postcss/autoprefixer/commit/59601b89582c2ca286a5e2a545ba98fb0004a5aa"><code>59601b8</code></a>
Update c8 and clean-publish</li>
<li>Additional commits viewable in <a
href="https://github.com/postcss/autoprefixer/compare/10.4.22...10.5.0">compare
view</a></li>
</ul>
</details>
<br />

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-05-01 13:11:02 +00:00
dependabot[bot] ecc39efbb5 chore: bump @pierre/diffs from 1.1.0-beta.19 to 1.1.19 in /site (#24885)
Bumps @pierre/diffs from 1.1.0-beta.19 to 1.1.19.


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=@pierre/diffs&package-manager=npm_and_yarn&previous-version=1.1.0-beta.19&new-version=1.1.19)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)


</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-05-01 13:08:42 +00:00
dependabot[bot] d50384c105 chore: bump typescript from 6.0.2 to 6.0.3 in /offlinedocs (#24871)
Bumps [typescript](https://github.com/microsoft/TypeScript) from 6.0.2
to 6.0.3.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/microsoft/TypeScript/releases">typescript's
releases</a>.</em></p>
<blockquote>
<h2>TypeScript 6.0.3</h2>
<p>For release notes, check out the <a
href="https://devblogs.microsoft.com/typescript/announcing-typescript-6-0/">release
announcement blog post</a>.</p>
<ul>
<li><a
href="https://github.com/Microsoft/TypeScript/issues?utf8=%E2%9C%93&amp;q=milestone%3A%22TypeScript+6.0.0%22">fixed
issues query for TypeScript 6.0.0 (Beta)</a>.</li>
<li><a
href="https://github.com/Microsoft/TypeScript/issues?utf8=%E2%9C%93&amp;q=milestone%3A%22TypeScript+6.0.1%22">fixed
issues query for TypeScript 6.0.1 (RC)</a>.</li>
<li><a
href="https://github.com/Microsoft/TypeScript/issues?utf8=%E2%9C%93&amp;q=milestone%3A%22TypeScript+6.0.2%22">fixed
issues query for TypeScript 6.0.2 (Stable)</a>.</li>
<li><a
href="https://github.com/Microsoft/TypeScript/issues?utf8=%E2%9C%93&amp;q=milestone%3A%22TypeScript+6.0.3%22">fixed
issues query for TypeScript 6.0.3 (Stable)</a>.</li>
</ul>
<p>Downloads are available on:</p>
<ul>
<li><a href="https://www.npmjs.com/package/typescript">npm</a></li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/microsoft/TypeScript/commit/050880ce59e30b356b686bd3144efe24f875ebc8"><code>050880c</code></a>
Bump version to 6.0.3 and LKG</li>
<li><a
href="https://github.com/microsoft/TypeScript/commit/eeae9dd0f17aa494658e4ec079dc002e02dd625e"><code>eeae9dd</code></a>
🤖 Pick PR <a
href="https://redirect.github.com/microsoft/TypeScript/issues/63401">#63401</a>
(Also check package name validity in...) into release-6.0 (#...</li>
<li><a
href="https://github.com/microsoft/TypeScript/commit/ad1c695fada682764bb510dd680e8f175ae54094"><code>ad1c695</code></a>
🤖 Pick PR <a
href="https://redirect.github.com/microsoft/TypeScript/issues/63368">#63368</a>
(Harden ATA package name filtering) into release-6.0 (<a
href="https://redirect.github.com/microsoft/TypeScript/issues/63372">#63372</a>)</li>
<li><a
href="https://github.com/microsoft/TypeScript/commit/0725fb4664a1d5ec94040b6d94db77dc1cc354e4"><code>0725fb4</code></a>
🤖 Pick PR <a
href="https://redirect.github.com/microsoft/TypeScript/issues/63310">#63310</a>
(Mark class property initializers as...) into release-6.0 (#...</li>
<li>See full diff in <a
href="https://github.com/microsoft/TypeScript/compare/v6.0.2...v6.0.3">compare
view</a></li>
</ul>
</details>
<br />

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-05-01 13:07:33 +00:00
dependabot[bot] f535c42550 chore: bump websocket-ts from 2.2.1 to 2.3.0 in /site (#24884)
Bumps [websocket-ts](https://github.com/jjxxs/websocket-ts) from 2.2.1
to 2.3.0.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/jjxxs/websocket-ts/releases">websocket-ts's
releases</a>.</em></p>
<blockquote>
<h2>v2.3.0</h2>
<h2>websocket-ts v2.3.0</h2>
<h3>New Features</h3>
<ul>
<li><strong>UrlProvider</strong> — <code>Websocket</code> and
<code>WebsocketBuilder</code> now accept a <code>UrlProvider</code>: a
string or <code>() =&gt; string</code> function called on each
connection attempt. Enables dynamic URL resolution for load balancing,
auth token rotation, and failover. (<a
href="https://redirect.github.com/jjxxs/websocket-ts/issues/31">jjxxs/websocket-ts#31</a>)</li>
<li><strong>WebsocketEvent as const object</strong> — Replaced the
TypeScript <code>enum</code> with a <code>const</code> object and type
union, allowing plain string literals like <code>&quot;open&quot;</code>
alongside <code>WebsocketEvent.open</code>. Fully backwards compatible.
(<a
href="https://redirect.github.com/jjxxs/websocket-ts/issues/32">jjxxs/websocket-ts#32</a>)</li>
</ul>
<h3>Improvements</h3>
<ul>
<li>npm publish with <code>--provenance</code> for supply chain
transparency</li>
<li>CI workflows updated to latest action versions with npm caching and
<code>npm ci</code></li>
<li>Coverage uploads switched from <code>coveralls</code> package to
<code>coverallsapp/github-action</code></li>
<li>All devDependencies updated to latest semver-compatible
versions</li>
<li><code>package-lock.json</code> added for reproducible builds</li>
<li>README refreshed with new badges and improved documentation</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/jjxxs/websocket-ts/commit/2ed2b204011bcabd8f398daa74ef00bd52c663c9"><code>2ed2b20</code></a>
Upgrade npm for OIDC trusted publishing support</li>
<li><a
href="https://github.com/jjxxs/websocket-ts/commit/1abf7a013d7e5f7371104525a165c0ed564a4c5a"><code>1abf7a0</code></a>
Upgrade npm for OIDC trusted publishing support</li>
<li><a
href="https://github.com/jjxxs/websocket-ts/commit/f667fbb27c64abcad7007d5bb983e875c4128431"><code>f667fbb</code></a>
Set registry via npm config instead of setup-node for trusted
publishing</li>
<li><a
href="https://github.com/jjxxs/websocket-ts/commit/dd1c7311173058658b3301ca86f6769053b20343"><code>dd1c731</code></a>
Restore registry-url for npm trusted publishing</li>
<li><a
href="https://github.com/jjxxs/websocket-ts/commit/8879dc684fb5827b53f3189aa21b4ae3c2334009"><code>8879dc6</code></a>
Remove registry-url from setup-node to fix trusted publishing</li>
<li><a
href="https://github.com/jjxxs/websocket-ts/commit/92f01da09ffa6f1a15c466fc16ad205e56f9061f"><code>92f01da</code></a>
Use trusted publishing for npm, remove NPM_TOKEN secret</li>
<li><a
href="https://github.com/jjxxs/websocket-ts/commit/dd3dd8cb7cc7ade860ab01a32ea326adce0252d6"><code>dd3dd8c</code></a>
Merge pull request <a
href="https://redirect.github.com/jjxxs/websocket-ts/issues/40">#40</a>
from jjxxs/release/websocket-ts-2-3-0</li>
<li><a
href="https://github.com/jjxxs/websocket-ts/commit/cf13fb0964bc51ff3101f5b8d8746e234867dd45"><code>cf13fb0</code></a>
Update devDependencies to latest semver-compatible versions</li>
<li><a
href="https://github.com/jjxxs/websocket-ts/commit/b4a0f39a33d791804efa88888e1cfaba2b7230bd"><code>b4a0f39</code></a>
Added documentation for UrlProvider</li>
<li><a
href="https://github.com/jjxxs/websocket-ts/commit/d04039d57c3119fde1c767e1964d17757dec6a21"><code>d04039d</code></a>
Add UrlProvider support to accept string or function for WebSocket
URL</li>
<li>Additional commits viewable in <a
href="https://github.com/jjxxs/websocket-ts/compare/v2.2.1...v2.3.0">compare
view</a></li>
</ul>
</details>
<details>
<summary>Maintainer changes</summary>
<p>This version was pushed to npm by <a
href="https://www.npmjs.com/~GitHub%20Actions">GitHub Actions</a>, a new
releaser for websocket-ts since your current version.</p>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=websocket-ts&package-manager=npm_and_yarn&previous-version=2.2.1&new-version=2.3.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)


</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-05-01 13:07:28 +00:00
dependabot[bot] ce366b828d chore: bump next from 15.5.9 to 15.5.15 in /offlinedocs (#24873)
Bumps [next](https://github.com/vercel/next.js) from 15.5.9 to 15.5.15.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/vercel/next.js/releases">next's
releases</a>.</em></p>
<blockquote>
<h2>v15.5.15</h2>
<p>Please refer the following changelogs for more information about this
security release:</p>
<p><a
href="https://vercel.com/changelog/summary-of-cve-2026-23869">https://vercel.com/changelog/summary-of-cve-2026-23869</a></p>
<h2>v15.5.14</h2>
<blockquote>
<p>[!NOTE]
This release is backporting bug fixes. It does <strong>not</strong>
include all pending features/changes on canary.</p>
</blockquote>
<h3>Core Changes</h3>
<ul>
<li>feat(next/image): add lru disk cache and images.maximumDiskCacheSize
(<a
href="https://redirect.github.com/vercel/next.js/issues/91660">#91660</a>)</li>
<li>Fix(pages-router): restore Content-Length and ETag for /_next/data/
JSON responses (<a
href="https://redirect.github.com/vercel/next.js/issues/90304">#90304</a>)</li>
</ul>
<h3>Credits</h3>
<p>Huge thanks to <a
href="https://github.com/styfle"><code>@​styfle</code></a> and <a
href="https://github.com/lllomh"><code>@​lllomh</code></a> for
helping!</p>
<h2>v15.5.13</h2>
<blockquote>
<p>[!NOTE]
This release is backporting bug fixes. It does <strong>not</strong>
include all pending features/changes on canary.</p>
</blockquote>
<h3>Core Changes</h3>
<ul>
<li>fix: patch http-proxy to prevent request smuggling in rewrites (See:
<a
href="https://github.com/vercel/next.js/security/advisories/GHSA-ggv3-7p47-pfv8">CVE-2026-29057</a>)</li>
</ul>
<h3>Credits</h3>
<p>Huge thanks to <a
href="https://github.com/ztanner"><code>@​ztanner</code></a> for
helping!</p>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/vercel/next.js/commit/412eb90b6587ec02e8361c92efa9091487e7348f"><code>412eb90</code></a>
v15.5.15</li>
<li><a
href="https://github.com/vercel/next.js/commit/cb90de98be409653f39ec602072740b38689a4e5"><code>cb90de9</code></a>
[15.x] Avoid consuming cyclic models multiple times (<a
href="https://redirect.github.com/vercel/next.js/issues/74">#74</a>)</li>
<li><a
href="https://github.com/vercel/next.js/commit/fffef9ef3059a4883def5b847315fb6017668846"><code>fffef9e</code></a>
Fix CI for glibc linux builds</li>
<li><a
href="https://github.com/vercel/next.js/commit/d7b012d787c01e0435f8cdf2a47211891668d13b"><code>d7b012d</code></a>
v15.5.14</li>
<li><a
href="https://github.com/vercel/next.js/commit/2b0525123245da5b1b9d1abedc636c5fd3ee1d07"><code>2b05251</code></a>
[backport] feat(next/image): add lru disk cache and
`images.maximumDiskCacheS...</li>
<li><a
href="https://github.com/vercel/next.js/commit/f88cee9604f0ec8ab869a2f94ced984194277b9e"><code>f88cee9</code></a>
Backport: Fix(pages-router): restore Content-Length and ETag for
/_next/data/...</li>
<li><a
href="https://github.com/vercel/next.js/commit/cfd5f533b08df3038476dcd54f1d6d660d85f069"><code>cfd5f53</code></a>
v15.5.13</li>
<li><a
href="https://github.com/vercel/next.js/commit/15f28911fd272041707dbf6b7c07d62642593be8"><code>15f2891</code></a>
[backport]: fix: patch http-proxy to prevent request smuggling in
rewrites (#...</li>
<li><a
href="https://github.com/vercel/next.js/commit/d23f41c42506005fe6978e076a1ccbf8979e4925"><code>d23f41c</code></a>
v15.5.12</li>
<li><a
href="https://github.com/vercel/next.js/commit/8e75765a6544dc0e6b20aefeade7d33190ffcb7c"><code>8e75765</code></a>
fix unlock in publish-native</li>
<li>Additional commits viewable in <a
href="https://github.com/vercel/next.js/compare/v15.5.9...v15.5.15">compare
view</a></li>
</ul>
</details>
<br />

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-05-01 13:04:27 +00:00