v0.9.13: code hygiene, security hardening - #8606
waleedlatif1 wants to merge 12 commits into
Conversation
waleedlatif1
commented
Oct 3, 2026
- improvement(guidance): make every ratchet shrink-only, scope rules to their files, fix stale guidance (improvement(guidance): make every ratchet shrink-only, scope rules to their files, fix stale guidance #8594)
- improvement(tools): delete unreferenced tool response types and the dead generic resource data path (improvement(tools): delete unreferenced tool response types and the dead generic resource data path #8596)
- improvement(tools): stop exporting tool types used only in their own file (improvement(tools): stop exporting tool types used only in their own file #8597)
- improvement(knip): check entry exports of private packages and delete their dead barrels (improvement(knip): check entry exports of private packages and delete their dead barrels #8595)
- feat(library): How do you build an AI voice agent with Twilio and Sim? (feat(library): How do you build an AI voice agent with Twilio and Sim? #8598)
- feat(library): Best HubSpot Alternatives for AI Marketing Automation in 2026 (feat(library): Best HubSpot Alternatives for AI Marketing Automation in 2026 #8599)
- feat(library): Slack AI Agent Security: Permissions, Data, and Audit Guide (feat(library): Slack AI Agent Security: Permissions, Data, and Audit Guide #8600)
- fix(docs): cap search query length and time out the embedding call (fix(docs): cap search query length and time out the embedding call #8601)
- fix(tools): check usage limits before running hosted-key tools via the API (fix(tools): check usage limits before running hosted-key tools via the API #8602)
- fix(code-placeholders): skip heredoc bodies when scanning shell quote context (fix(code-placeholders): skip heredoc bodies when scanning shell quote context #8603)
- fix(webhooks): check existing path owners before claiming on deploy (fix(webhooks): check existing path owners before claiming on deploy #8605)
- fix(tools): reject dot path segments in tool request URLs (fix(tools): reject dot path segments in tool request URLs #8604)
… their files, fix stale guidance (#8594) * improvement(guidance): make every ratchet shrink-only, scope rules to their files, fix stale guidance - check:test-patterns --update refuses new violations and fails closed on a missing baseline - check:react-query drops its unused, growable baseline: every violation fails, as it already did - check:utils drops the id.ts allowlist entry by rewording the comment that tripped it - constitution, react-performance, and url-state rules load only for the files they govern - guidance: Switch stays the boolean toggle, current chip names, @sim/utils/random, db-migrate covers the schema mock and drizzle sync, apps/sim/AGENTS.md maps common tasks to skills * chore(guidance): widen rule scopes to the changelog route, package hooks, and nuqs navigation helpers * chore(guidance): scope url-state by directory so app hooks and helpers stay covered
…ead generic resource data path (#8596) * improvement(tools): delete unreferenced tool response types and the dead generic resource data path - delete 168 exported tool *Response types nothing references (mostly umbrella unions) and the 24 local types only they used - add-integration and add-tools templates declare one response type per tool and no umbrella union - drop the never-set genericResourceData chat field; the generic resource panel renders its empty state directly * chore(skills): name InternalToolConfig beside ToolConfig in the response-type guidance
…file (#8597) - Drop `export` from 406 tool types referenced only inside their own types.ts - Delete 27 tool types used nowhere, plus 5 private param types only they referenced - Remove the dead `DataverseResponse` re-export from microsoft_dynamics_365/index.ts - Shrink check-unused-exports baseline by 434 entries; `export const` output schemas untouched
… their dead barrels (#8595) * improvement(knip): check entry exports of private packages and delete their dead barrels - knip.jsonc: includeEntryExports on for every private package except db - delete the bare @sim/utils and @sim/workflow-persistence barrels and their "." exports - drop unused re-exports from the workflow-renderer and desktop-bridge barrels; un-export symbols only used in-file - delete 7 unreferenced emcn icons - baseline the remaining 262 entry-export findings (one-time rule expansion via --update --init) * improvement(packages): resolve the private-package exports the entry-export check exposed - Delete exports nothing uses: RadarChart, ChipModalPromptBody, InputOTPSeparator, DropdownMenuGroup/Portal, legacy terminal tool names, and dead types and helpers - Drop `export` from declarations used only in their own file, and remove barrel re-exports no consumer imports - Tag getOAuthClientCapabilityFields and generateRandomBytes `@public`: generate-docs loads the first by file path, and check:utils names the second - Trim the workflow-authz mock to the module's remaining exports - The unused-exports baseline gains no entries and drops one * fix(emcn): keep ChipTimePicker in the barrel as documented chip-family API * chore(emcn): export CVA variants only once another module composes them * chore(emcn): delete the PillsRing icon, unused since the generic resource panel lost its entry list * chore(knip): shrink the unused-exports baseline after rebasing onto staging
…Guide (#8600) Co-authored-by: Sim Pi Agent <pi@sim.ai>
…8601) * fix(docs): cap search query length and time out the embedding call * fix(docs): truncate long search queries instead of dropping them * fix(docs): truncate search queries on a code point boundary
…e API (#8602) * fix(tools): check usage limits before running hosted-key tools via the API * fix(tools): gate hosted-key calls whose key is an unresolved variable reference * fix(tools): exempt variable references that resolve to the caller's own key * fix(tools): resolve the key reference with the registry's own resolver * fix(tools): decide hosted-key admission on registry-resolved params
* fix(tools): reject dot path segments in tool request URLs * fix(tools): match URL parser boundary stripping in dot-segment check
|
The latest updates on your projects. Learn more about Vercel for GitHub. |
There was a problem hiding this comment.
No issues found across 338 files
Confidence score: 5/5
- Automated review surfaced no issues in the provided summaries.
- No files require special attention.
Note: This PR contains a large number of files. cubic selects up to 200 of the highest-priority eligible files for this review, so some files may not have been reviewed.
Re-trigger cubic
|
| if (desired.path) { | ||
| // Unclaimed legacy rows of other workflows still own their path. | ||
| const path = normalizeWebhookRegistrationPath(desired.path) ?? desired.path | ||
| const conflictingOwner = await findConflictingWebhookPathOwner({ |
There was a problem hiding this comment.
Stale webhook blocks deployment
When another workflow has an active deployment, an older webhook row—or one with no deployment version—cannot receive traffic. This new check still treats that row as the path owner because it checks the path and active flags but not the deployment version. A workflow trying to deploy on that otherwise-free path gets a conflict and cannot deploy its webhook. Check whether a legacy row can receive traffic before letting it block a claim.
Knowledge Base Used: Triggers and background automation