Skip to content

v0.9.17: tables ledger, oracle integrations, mship improvements - #8853

Open
waleedlatif1 wants to merge 59 commits into
mainfrom
staging
Open

waleedlatif1 wants to merge 59 commits into
mainfrom
staging

Conversation

@waleedlatif1

@waleedlatif1 waleedlatif1 commented Oct 9, 2026 •

Copy link
Copy Markdown
Collaborator

waleedlatif1 and others added 30 commits October 8, 2026 07:51
* feat(integrations): add saved Ramp and Vanta credentials

* fix(integrations): harden credential renewal and connection setup

* fix(integrations): make credential renewal waits abortable

* docs(integrations): document token credential availability registration

* improvement(integrations): refresh Ramp branding and simplify credential forms
Co-authored-by: Bill Leoutsakos <billleoutsakos@Bills-MacBook-Pro.local>
Co-authored-by: Bill Leoutsakos <billleoutsakos@Bills-MacBook-Pro.local>
Co-authored-by: Bill Leoutsakos <bill@sim.ai>
…rface lint on deploy (#8803)

* fix(workflows): lint unquoted string references in JSON fields and surface lint on deploy

* fix(workflows): lint only the JSON fields the operation sends, and lint deploys as the acting user

* fix(workflows): check JSON editors sent under a canonical param
…th Sim? (#8804)

* feat(library): How Do You Build a Salesforce AI Lead-Scoring Agent With Sim?

* Pi Babysit: address PR #8804 feedback

---------

Co-authored-by: Sim Pi Agent <pi@sim.ai>
* docs(library): update best-ai-agents-support-ticket-triage

* Pi Babysit: address PR #8805 feedback

---------

Co-authored-by: Sim Pi Agent <pi@sim.ai>
… 2026 (#8806)

Co-authored-by: Sim Pi Agent <pi@sim.ai>
…ags (#8808)

* chore(config): retire unused env vars and fully-rolled-out feature flags

* chore(helm): bump chart version for removed TABLE_ROW_TTL value
* feat(oracledb): add Oracle Database integration

* test(oracledb): remove retired block secret fields from masking inventory

---------

Co-authored-by: Waleed Latif <walif6@gmail.com>
* fix(files): support arbitrary uploads and in-document links

* fix(files): normalize previews and avoid oversized retries

* fix(files): bound decoded text for encoded responses
…es a missing organization (#8809)

* fix(billing): acknowledge Stripe webhooks whose subscription references a missing organization instead of retrying for days

* test(billing): prove the not-yet-matching issuance branch by redelivery; drop the logging-only update catch

* test(testing): a swapped price in the Stripe fake no longer reports the previous amount
* fix(db): retire unused keyword search projections

* fix(db): retire keyword writers before schema push

* fix(db): require approval before retiring push writers
* fix(google-ads): align reporting with current API access

* fix(google-ads): preserve nullable inputs and redact retired credentials
* feat(dashboards): add empty-state graphic for the dashboard page

Claude-Session: https://claude.ai/code/session_01J7A6CWpREr1jiPAdWyTQbA

* improvement(dashboards): mark empty-state chart points as const

Claude-Session: https://claude.ai/code/session_01J7A6CWpREr1jiPAdWyTQbA
…table definition row (#8765)

* fix(tables): log row writes to the change log instead of locking the table definition row

* fix(tables): lock the change log before the dev count reconcile, and tighten the held-row test

* test(tables): name the renumbered change-log migration
* fix(tables): drop the per-table row-order lock from inserts

Appends mint keys in a random slot after the last key, so concurrent appends
never share a key and a batch stays contiguous. Positions are left best-effort
and may repeat; the run dispatcher finishes a tied position before advancing
its cursor. Positional inserts skip tied keys. Concurrent replaces stay
serialized by the table's unique lock, which every replace already takes.

* test(tables): order rows bytewise in the lockless-insert tests and stub the job queue locally
…ition source (#8815)

* feat(analytics): attribute sign-ups and demo requests to their acquisition source

- Record first and last marketing touch (campaign params, referring domain, landing path) in consent-gated first-party cookies on marketing and sign-in pages; attach them to user_created and the PostHog person
- Capture $pageview on marketing routes, landing_demo_request_submitted, landing_demo_booked, external_sign_in_started, and email_type on identify
- Add useCaptureWhenReady so view events captured on mount are no longer dropped before PostHog initializes
- Include attribution in the demo-request sales notification
- List the attribution cookies in the cookie policy

* fix(analytics): cap attribution cookies at the consent grant, enforce stored field shapes, and lock sign-in buttons while pending
* feat(changelog): publish curated product updates

* fix(changelog): harden feed rendering and media validation

* improvement(changelog): present updates in a crawlable list

* improvement(changelog): define the Sim editorial workflow

Document scheduled discovery, durable candidate state, draft PR preparation, real-media review, and operational checks. Reuse the existing cached checkout for trusted Helm PR checks while preserving full history.

* fix(changelog): preserve editorial decisions in the workflow plan

* docs(changelog): refine product stories and define editorial quality

* refactor(changelog): simplify presentation and validate model links
… leave-site prompt is answered (#8432)

* fix(desktop-browser): ask the user before a page's alert, confirm, or leave-site prompt is answered

* fix(desktop-browser): ask only about the user's own on-screen page, never the agent's

* fix(desktop-browser): label frame dialogs with their own origin and cover reload leave prompts

* fix(desktop-browser): preserve native dialog ownership and keyboard focus
…IPAA, GDPR, Data Residency, On-Prem, and VPC (#8822)

Co-authored-by: Sim Pi Agent <pi@sim.ai>
Co-authored-by: Sim Pi Agent <pi@sim.ai>
Co-authored-by: Sim Pi Agent <pi@sim.ai>
* fix(mcp): add directory verification compatibility

* test(mcp): verify ownership challenge over HTTP
* fix(chat): send entitlements and agent mode from the public chat API

`/api/v2/chat` (what `sim chat` uses) stopped sending `entitlements` and `mode`
in #8208, so CLI and API chats got no entitlement-gated tools and every CLI
service refused them with "CLI services require agent mode". The route now
computes entitlements per turn like the workspace chat and sends
`mode: 'agent'`. Its test still mocked the old entitlements function and
listed `mode` as a forbidden legacy field; both are updated.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EHGBgHrtePpi7KMrEfy41R

* feat(tests): workflow tests as a workspace resource

Workflow tests are a workspace resource whose source is a plain vitest file,
`tests/<name>.test.js`, owned by the test (workspace_files.context = 'test').
Sim creates a test's metadata with the tests tool and writes its cases with
the file tools; every write is collected in the sandbox and refused if the
file does not load.

- Runner: test files run in the isolated-vm sandbox against draft or
  deployed workflows. `runWorkflow` executes real runs; `mockBlock`,
  `mockTool` (Agent tool calls) and `spyOnBlock` reach blocks in the tested
  workflow and in every child workflow it runs, matched by name as each
  workflow starts. `.mockSampleOutput()` builds outputs shaped like the real
  block or tool. `toMatchRubric` asks a model judge for pass or fail.
- Runs record live per-case progress, the source hash, and the deployment of
  every workflow they ran, so results show as out of date once the test or
  a workflow changes.
- UI: Tests page and test page (Edit / Split / Preview over the file, the
  preview a dashboard of the selected run), a test resource type in chat,
  and a Tests sidebar entry behind the `workflow-tests` flag.
- Owned files never open as file tabs in chat: only workspace files and
  chat uploads do.
- Migration 0400 adds workflow_test and workflow_test_run.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EHGBgHrtePpi7KMrEfy41R

* feat(tests): pick a run from a dropdown and open what each run ran against

The test page shows one run at a time, chosen from a run picker with status
dots and Draft / Out of date chips. Case statuses use the Badge status chip.
Each ran-against entry records one execution, so a draft row opens the
workflow snapshot from that run.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EHGBgHrtePpi7KMrEfy41R

* fix(tests): type errors and tests broken by workflow tests

- Narrow the test principal to the kinds workflow_tests.run admits before
  handing it to executeWorkflow.
- Select progress with the latest-run rows, guard file upsert ids in the
  tab filter, and set the sandbox Event polyfills through Reflect.
- Cover the tests tool in the management tool contract, expect content
  writes to reach test files, and stub test availability in the payload test.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EHGBgHrtePpi7KMrEfy41R

* fix(tests): address review on redaction, staleness, and the harness

- Redact each run's resolved secrets from what returns to the sandbox
  (output, errors, mocked tool inputs); mocked tools get only declared params.
- Custom blocks no longer receive the consumer's test hooks.
- Draft runs go stale when the draft changes; children a run calls are
  recorded in ran-against.
- Test cases commit in the same transaction as the source file write.
- Harness: runWorkflow is rejected in suite hooks, a timed-out case stops
  the file, and expect.assertions/hasAssertions are supported.
- Insert run rows in one statement and start each run's clock with its file;
  check bans before each workflow run; restrict owned-file access to Copilot
  delegation; validate names in the tool contract.
- Delete soft-deletes the test file and removes the chat tab; a finished run
  shows its own cases; polling at 3s on a separate read bucket; list error
  state; store reset; tests stay in the org Add Resource picker.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EHGBgHrtePpi7KMrEfy41R

* fix(tests): reserve run slots, await pending assertions, keep dynamic tool args

- Each test workflow run reserves and releases an execution slot.
- A case waits for assertions it did not await and fails if one fails.
- Mocked MCP and custom tools keep the arguments their schema declares.
- A closed session refuses starts still awaiting their lookups.
- Stable refresh callback; scroll fade on the results pane.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EHGBgHrtePpi7KMrEfy41R

* fix(tests): keep test sources out of file tabs, refresh after runs, reopen tests

- File-edit tool results mark a non-tab file `fileTab: false`, and the browser
  skips promoting it.
- Idle test pages poll every 15s so runs started elsewhere appear; a Mothership
  run returns its tests as resource changes.
- open_resource accepts test resources through an authorized read.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EHGBgHrtePpi7KMrEfy41R

* fix(tests): refresh test tabs after a run, keep saved edits successful

- A finished Mothership run refreshes its tests instead of upserting tabs, so a
  test deleted mid-run does not come back.
- A failed file-tab lookup after a saved edit opens no tab instead of
  reporting the edit as failed.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EHGBgHrtePpi7KMrEfy41R

* fix(tests): starter source imports every test helper

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EHGBgHrtePpi7KMrEfy41R

* build(tests): add @vitest/expect and @vitest/spy for the sandbox bundle

The vitest-expect sandbox bundle builds from these packages; rebuilt with the
Reflect-based event polyfills.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EHGBgHrtePpi7KMrEfy41R

* build(tests): tell knip the sandbox bundle uses @vitest/expect and @vitest/spy

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EHGBgHrtePpi7KMrEfy41R

* feat(tests): name MCP and custom tool mocks by server and title

MCP tool ids embed the server's database id, which changes when a server is
re-added or a workspace is forked, so a stale mock silently stopped matching
and the real server was called. Tests now name workspace tools the way the
workspace does: mockTool({ mcp: 'Server', tool: 'name' }) resolved per run
(failing on an unknown or ambiguous server), and mockTool({ customTool:
'Title' }) matched case- and space-insensitively. Raw mcp- and custom_ ids
are rejected; built-in catalog ids are unchanged.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EHGBgHrtePpi7KMrEfy41R

* fix(tests): reserve the run name, hold Run for unsaved edits, cancel judges on close

- A test named "run" collided with the static run endpoint, so its detail
  page got a 405; the name is now reserved.
- Run is disabled while the open editor holds edits the server has not
  saved (including a refused save), so a run never uses the previous source.
- toMatchRubric model calls are aborted when the sandbox run ends, so a
  stopped test no longer keeps calling or billing the judge.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EHGBgHrtePpi7KMrEfy41R

* fix(tests): fail a run whose selected case names no test in the file

A renamed or misspelled `only` path skipped every case, and the run was then
saved as passing. The harness now rejects unknown names, so the run is
recorded as an error with the names it could not find.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EHGBgHrtePpi7KMrEfy41R

---------

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
* fix(providers): remove default agent tool-call iteration cap

* docs(providers): note no execution timeout when billing is disabled
* fix(desktop): ask before accessing local files

* fix(desktop): remember folder permissions across chats

* fix(desktop): cancel pending file consent and recheck access

* fix(desktop): enumerate approved directory descriptors

* fix(desktop): reject replaced directory listings

* fix(desktop): share pending folder consent decisions

* fix(desktop): complete file consent and add full file access

* fix(desktop): revalidate folder consent and preserve exact identities
…gement-in-2026 (#8849)

* docs(library): update best-ai-agents-for-scheduling-and-calendar-management-in-2026

* Pi Babysit: address PR #8849 feedback

---------

Co-authored-by: Sim Pi Agent <pi@sim.ai>
Co-authored-by: Sim Pi Agent <pi@sim.ai>
…atform and Workflow Guide (#8847)

* feat(library): AI Agents for Asana and monday.com Task Automation: Platform and Workflow Guide

* Pi Babysit: address PR #8847 feedback

---------

Co-authored-by: Sim Pi Agent <pi@sim.ai>
…8846)

* docs(library): update best-ai-agent-marketplaces-template-libraries

* Pi Babysit: address PR #8846 feedback

---------

Co-authored-by: Sim Pi Agent <pi@sim.ai>
@greptile-apps

greptile-apps Bot commented Oct 9, 2026 •

Copy link
Copy Markdown
Contributor

RetriggerConfidence Score: 2/5

[High impact] Adds Oracle database integration and membership features with build and workflow changes.

Fix workflow-test cleanup, storage accounting, and version tracking before merging.

Findings

  1. P1 Deleted tests block cleanup ▶
  2. P1 Deleted tests keep consuming quota ▶
  3. P1 Changed workflows look tested ▶

Summary

This release adds Oracle and Checkr integrations, saved credentials, workspace workflow tests, table-write improvements, and broader Chat commands. It also updates billing reads, desktop consent, file previews, and product content.

  • Deleted test files cannot finish cleanup because their test owners still reference them.
  • Test storage adds to billed usage but is excluded from billed cleanup.
  • Test reports can mark changed workflows as current when edits or child redeployments happen during a run.

Diagram

%%{init: {'theme': 'neutral'}}%%
flowchart TD
  A[Create workflow test] --> B[Store source file with test context]
  B --> C[Increase billed storage]
  A --> D[Run test]
  D --> E[Load workflow state]
  E --> F[Finish test]
  F --> G[Read current timestamps and child versions]
  G --> H[Save report]
  A --> I[Delete test]
  I --> J[Mark test and source deleted]
  J --> K[Retention cleanup]
  K --> L[Delete stored source]
  L --> M[Delete file row]
  M --> N[Foreign key rejects deletion]
  K --> O[Test context skips billed cleanup]
Loading

Reviews (1) · Last reviewed commit: "fix(sim-cli): an unknown option lists th..." · Reviewed by Greptile

Comment thread apps/sim/lib/workflow-tests/repository.ts
Comment thread apps/sim/lib/uploads/contexts/workspace/workspace-file-manager.ts
Comment thread apps/sim/lib/workflow-tests/repository.ts Outdated
Comment thread apps/sim/scripts/test-google-ads-e2e.ts Fixed
* fix(desktop): open Folder Access from a focused utility window

* test(desktop): cover Folder Access from a utility window in the Electron e2e
* fix(credentials): allow encoded Oracle connection payloads

* fix(credentials): keep regression assertions at HTTP boundary
…ons as loaded (#8858)

* fix(tests): purge deleted tests, bill their storage, and record versions as loaded

- Retention cleanup removes an expired test's row before its source file, which its
  foreign key blocked, and treats test sources as billed so their bytes are released.
- A run records each workflow's deployment, and a draft's timestamp, as the executor
  loads it, so an edit or redeploy mid-run no longer makes the run look current.
- Organization-chat workspace submenus leave tests out, like the composer.
- Open test opens a new tab on web; doc fixes for hook inheritance and mockSampleOutput.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* fix(tests): take a draft's timestamp from before the run loads it

Reading it after the load let an edit landing in between look tested; the snapshot from
before the load can only err toward stale.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
…zation chat (#8861)

* fix(mothership): keep the workspace target on revealed workspace API keys in organization chat

* fix(mothership): bind a revealed key to the workspace it was created in

* test(mothership): exercise the copy action in the organization chat key regression

* fix(mothership): render a saved masked key without a workspace target check
)

Make navigation, chat composers, resource controls, settings, and workflow panels fit narrow touch screens while preserving desktop and fullscreen layouts. Add the Chromium/WebKit mobile CI matrix and the mobile design-review checklist.

Keep workflow actions visible in compact panels and attachment scrolling bounded, with shared cues for hidden content. Stabilize clock-sensitive billing assertions and the post-commit connector deletion test without changing production behavior.
…8860)

* improvement(editor): refine previews and compact formatting controls

* fix(editor): retain focus after choosing a format

* fix(emcn): centralize neutral chip keyboard focus

* fix(emcn): preserve selected segment focus surfaces
* improvement(diff): refine embedded diff presentation

* fix(diff): keep comparison headings aligned while scrolling

* fix(diff): keep the comparison divider outside scroll fades

* fix(diff): pair complete change blocks in document comparisons

* fix(diff): preserve heading-level changes in comparisons

This branch was previously deployed

1 inactive deployment
Preview — 9d649134 Deployed Oct 9, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

requires-mothership-merge Has a companion PR on the mothership/copilot side — merge in lockstep

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants