- Add dompurify override (3.3.3) to force mermaid's transitive dep away from 3.3.1
- Switch kilo-gateway solid-js from pinned 1.9.10 to catalog (1.9.12) to eliminate seroval@1.3.2
Update hono catalog version from 4.10.7 to 4.12.12 to fix 14 advisories
including JWT algorithm confusion (GHSA-f67f-6cw9-8mq4, GHSA-3vhc-576x-3qv4),
CORS bypass, body limit bypass, XSS, cookie injection, SSE injection,
path traversal, and prototype pollution.
Add null guard for ptyID param in pty.ts to satisfy hono 4.12's stricter
return type for c.req.param().
* feat: add WarpGrep AI-powered codebase search tool
Add WarpGrep integration as a new tool for intelligent multi-step
codebase search. WarpGrep delegates search to Morph's RL-trained
search agent, which runs parallel tool calls across multiple turns
and returns only relevant code spans.
- Add WarpGrep core client with multi-turn API loop, local tool
executors (ripgrep, file read, directory list), and XML parsing
- Add tool definition gated behind KILO_ENABLE_WARPGREP flag
- Register tool in registry with feature flag gating
- Add warpgrep permission to orchestrator, ask, and explore agents
- Conditionally enhance explore agent prompt when WarpGrep available
- Add unit tests for parsing, file ops, and tool registration
* fix: align warpgrep with Morph XML protocol
* chore: drop warpgrep test changes from branch
* chore: remove warpgrep test files from branch
* refactor: replace custom WarpGrep implementation with @morphllm/morphsdk
- Delete 396-line custom warpgrep.ts, replace with SDK's WarpGrepClient
- Only check MORPH_API_KEY (drop WARPGREP_API_KEY)
- Route through Kilo proxy during free period when no API key is set
- Add actionable error message for when free period ends
- Grep for FREE_PERIOD_TODO to find what to change post-free-period
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* feat: rename warpgrep to codebase_search, add error toast for 429/402
- Rename tool from warpgrep to codebase_search throughout
- Switch proxy URL to /api/gateway
- Detect auth/rate-limit errors (401/402/429) and show actionable
fallback message telling users to set MORPH_API_KEY
- Fire a TUI toast notification on auth/rate-limit errors so users
see a visible popup, not just hidden tool output
- Wire up GlobalBus "global.event" in TUI thread so Bus events from
tools can reach the TUI event system
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* build: bump @morphllm/morphsdk to 0.2.141
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* fix: use Bus.publish for toast, revert global.event subscription
Address PR review: emit toast via Bus.publish(TuiEvent.ToastShow)
instead of GlobalBus.emit() so it works in both direct-RPC and
server-backed TUI modes. Revert the global.event subscription in
createEventSource since it's no longer needed and caused double
event delivery.
Also update codebase_search tool description to clarify natural
language input.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* feat: add codebase search toggle to experimental settings
Replace KILO_ENABLE_WARPGREP env var with a UI toggle in the
Experimental settings tab. The tool is now gated by the
experimental.codebase_search config field, accessible from both
VSCode settings and TUI config file.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* Update packages/opencode/src/tool/warpgrep.ts
Co-authored-by: Marius <marius@kilocode.ai>
* feat: limit codebase_search output to prevent context bloat
When search results exceed 45k chars (~15k tokens), degrade to showing
file paths and line ranges instead of full content. Also bumps
@morphllm/morphsdk from 0.2.129 to 0.2.147.
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
* build: bump @morphllm/morphsdk to 0.2.148
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
* fix: format codebaseSearch i18n strings to respect prettier line width
* fix: only advertise codebase_search in explore prompt when feature flag is enabled
---------
Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
Co-authored-by: Christiaan Arnoldus <christiaan.arnoldus@outlook.com>
Co-authored-by: Marius <marius@kilocode.ai>
Bump tsgo from 20251207 to 20260316 (~3 months of nightly releases).
The new version is stricter about type resolution — it no longer
auto-resolves @types/* packages without explicit 'types' in tsconfig.
Add 'types' field to sdk, plugin, kilo-telemetry, and app tsconfigs.