Skip to content

v0.9.13: code hygiene, security hardening - #8606

Open
waleedlatif1 wants to merge 12 commits into
mainfrom
staging
Open

waleedlatif1 wants to merge 12 commits into
mainfrom
staging

Conversation

@waleedlatif1

Copy link
Copy Markdown
Collaborator

waleedlatif1 and others added 12 commits October 3, 2026 01:29
… their files, fix stale guidance (#8594)

* improvement(guidance): make every ratchet shrink-only, scope rules to their files, fix stale guidance

- check:test-patterns --update refuses new violations and fails closed on a missing baseline
- check:react-query drops its unused, growable baseline: every violation fails, as it already did
- check:utils drops the id.ts allowlist entry by rewording the comment that tripped it
- constitution, react-performance, and url-state rules load only for the files they govern
- guidance: Switch stays the boolean toggle, current chip names, @sim/utils/random, db-migrate covers the schema mock and drizzle sync, apps/sim/AGENTS.md maps common tasks to skills

* chore(guidance): widen rule scopes to the changelog route, package hooks, and nuqs navigation helpers

* chore(guidance): scope url-state by directory so app hooks and helpers stay covered
…ead generic resource data path (#8596)

* improvement(tools): delete unreferenced tool response types and the dead generic resource data path

- delete 168 exported tool *Response types nothing references (mostly umbrella unions) and the 24 local types only they used
- add-integration and add-tools templates declare one response type per tool and no umbrella union
- drop the never-set genericResourceData chat field; the generic resource panel renders its empty state directly

* chore(skills): name InternalToolConfig beside ToolConfig in the response-type guidance
…file (#8597)

- Drop `export` from 406 tool types referenced only inside their own types.ts
- Delete 27 tool types used nowhere, plus 5 private param types only they referenced
- Remove the dead `DataverseResponse` re-export from microsoft_dynamics_365/index.ts
- Shrink check-unused-exports baseline by 434 entries; `export const` output schemas untouched
… their dead barrels (#8595)

* improvement(knip): check entry exports of private packages and delete their dead barrels

- knip.jsonc: includeEntryExports on for every private package except db
- delete the bare @sim/utils and @sim/workflow-persistence barrels and their "." exports
- drop unused re-exports from the workflow-renderer and desktop-bridge barrels; un-export symbols only used in-file
- delete 7 unreferenced emcn icons
- baseline the remaining 262 entry-export findings (one-time rule expansion via --update --init)

* improvement(packages): resolve the private-package exports the entry-export check exposed

- Delete exports nothing uses: RadarChart, ChipModalPromptBody, InputOTPSeparator,
  DropdownMenuGroup/Portal, legacy terminal tool names, and dead types and helpers
- Drop `export` from declarations used only in their own file, and remove barrel
  re-exports no consumer imports
- Tag getOAuthClientCapabilityFields and generateRandomBytes `@public`: generate-docs
  loads the first by file path, and check:utils names the second
- Trim the workflow-authz mock to the module's remaining exports
- The unused-exports baseline gains no entries and drops one

* fix(emcn): keep ChipTimePicker in the barrel as documented chip-family API

* chore(emcn): export CVA variants only once another module composes them

* chore(emcn): delete the PillsRing icon, unused since the generic resource panel lost its entry list

* chore(knip): shrink the unused-exports baseline after rebasing onto staging
#8598)

* feat(library): How do you build an AI voice agent with Twilio and Sim?

* Pi Babysit: address PR #8598 feedback

* Pi Babysit: address PR #8598 feedback

---------

Co-authored-by: Sim Pi Agent <pi@sim.ai>
…in 2026 (#8599)

* feat(library): Best HubSpot Alternatives for AI Marketing Automation in 2026

* Pi Babysit: address PR #8599 feedback

---------

Co-authored-by: Sim Pi Agent <pi@sim.ai>
…Guide (#8600)

Co-authored-by: Sim Pi Agent <pi@sim.ai>
…8601)

* fix(docs): cap search query length and time out the embedding call

* fix(docs): truncate long search queries instead of dropping them

* fix(docs): truncate search queries on a code point boundary
…e API (#8602)

* fix(tools): check usage limits before running hosted-key tools via the API

* fix(tools): gate hosted-key calls whose key is an unresolved variable reference

* fix(tools): exempt variable references that resolve to the caller's own key

* fix(tools): resolve the key reference with the registry's own resolver

* fix(tools): decide hosted-key admission on registry-resolved params
* fix(tools): reject dot path segments in tool request URLs

* fix(tools): match URL parser boundary stripping in dot-segment check
@waleedlatif1
waleedlatif1 requested a review from a team as a code owner October 3, 2026 21:21
@vercel

vercel Bot commented Oct 3, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

1 Skipped Deployment
Project Deployment Actions Updated
docs Skipped Skipped Oct 3, 2026 9:21pm UTC

Request Review

@cubic-dev-ai cubic-dev-ai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No issues found across 338 files

Confidence score: 5/5

  • Automated review surfaced no issues in the provided summaries.
  • No files require special attention.

Note: This PR contains a large number of files. cubic selects up to 200 of the highest-priority eligible files for this review, so some files may not have been reviewed.

Re-trigger cubic

@greptile-apps

greptile-apps Bot commented Oct 3, 2026 •

Copy link
Copy Markdown
Contributor

RetriggerConfidence Score: 4/5

[Medium risk] Documentation, rules, and test updates across the codebase.

The PR should not merge until webhook deployment checks stop treating non-deliverable legacy rows as path owners.

Findings

  1. P1 Stale webhook blocks deployment ▶

Summary

This PR tightens tool URL and usage admission, protects webhook path claims, adjusts shell placeholder scanning, removes unused exports, strengthens audits, and adds library content.

  • The webhook pre-claim check can reject a path based on a legacy row that the active deployment cannot serve.
Diagram
%%{init: {'theme': 'neutral'}}%%
flowchart LR
  D[Deploy webhook] --> L[Check existing path owners]
  L --> C{Conflicting owner?}
  C -->|Yes| X[Reject deployment]
  C -->|No| A[Atomically claim path]
  R[Legacy webhook row] --> L
  R --> V[Runtime checks active deployment version]
Loading

Reviews (1) · Last reviewed commit: "fix(tools): reject dot path segments in ..."

if (desired.path) {
// Unclaimed legacy rows of other workflows still own their path.
const path = normalizeWebhookRegistrationPath(desired.path) ?? desired.path
const conflictingOwner = await findConflictingWebhookPathOwner({

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Stale webhook blocks deployment

When another workflow has an active deployment, an older webhook row—or one with no deployment version—cannot receive traffic. This new check still treats that row as the path owner because it checks the path and active flags but not the deployment version. A workflow trying to deploy on that otherwise-free path gets a conflict and cannot deploy its webhook. Check whether a legacy row can receive traffic before letting it block a claim.

Knowledge Base Used: Triggers and background automation

This branch was previously deployed

1 inactive deployment
Preview — 825e7e76 Deployed Oct 3, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants