Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
65 commits
Select commit Hold shift + click to select a range
1b5830c
chore: prepare v3.62.0 release (#658)
navedmerchant Jun 19, 2026
f798462
chore(deps): update dependency undici to v6.27.0 [security] (#659)
renovate[bot] Jun 20, 2026
35356b1
fix(McpHub): resolve persistently flaky McpHub.spec.ts tests after Vi…
edelauna Jun 20, 2026
74583b5
feat(fireworks): add kimi-k2p7-code model (#599)
p12tic Jun 20, 2026
f21802c
chore(deps): update dependency @types/node to v20.19.43 (#669)
renovate[bot] Jun 20, 2026
ad7dcfe
chore(deps): update dependency @vscode/test-cli to v0.0.12 (#670)
renovate[bot] Jun 20, 2026
dfb31da
chore(deps): update dependency execa to v9.6.1 (#671)
renovate[bot] Jun 20, 2026
ccf07eb
chore(deps): update dependency axios to v1.18.0 (#673)
renovate[bot] Jun 20, 2026
de8886a
fix: auto-close files setting cannot be unchecked — always reverts to…
navedmerchant Jun 21, 2026
e2fce6c
[Feat] Add Roo Code history import to the About page (#141)
roomote[bot] Jun 21, 2026
37008b7
fix(ask_followup_question): report non-array follow_up as a type erro…
nh2 Jun 22, 2026
b6baa32
feat: add TaskSemaphore utility (#675)
edelauna Jun 22, 2026
0f1054e
feat(experiments): register PARALLEL_TOOL_EXECUTION flag (internal-on…
edelauna Jun 22, 2026
518bae4
fix(edit-unsuccessfull): introduce configurable relaxed diff threshol…
nigeldelviero Jun 23, 2026
28c54a7
feat: add abort signal core plumbing (#674)
easonLiangWorldedtech Jun 23, 2026
e8acc6a
🐛 test(mcp): fix McpHub Windows command wrapping test ordering (#632)
HappyLiang12 Jun 23, 2026
31b7c51
docs(prompt): enhance apply_diff tool instructions to improve Gemini …
awschmeder Jun 24, 2026
0084cc8
Add completion change actions (#633)
ivanarifin Jun 24, 2026
6670962
fix(delegation): serialize delegateParentAndOpenChild with atomicRead…
edelauna Jun 25, 2026
1b26b6a
fix(diff-view): make auto-closing edited files opt-in (#720)
edelauna Jun 25, 2026
f75b64e
feat(settings): add rules management UI (#657)
ivanarifin Jun 26, 2026
34898d2
fix: parse Gemma 4 <thought> reasoning tags alongside <think> (#324)
sagidM Jun 26, 2026
6705e67
chore: prepare v3.64.0 release (#729)
edelauna Jun 26, 2026
1e95591
chore(deps): update dependency only-allow to v1.2.2 (#737)
renovate[bot] Jun 27, 2026
fdb07e6
chore(deps): update dependency pdf-parse to v1.1.4 (#739)
renovate[bot] Jun 27, 2026
12af5de
chore(deps): update dependency react-use to v17.6.1 (#740)
renovate[bot] Jun 27, 2026
16dc13f
chore(deps): update dependency ovsx to v0.10.12 (#738)
renovate[bot] Jun 27, 2026
4e68b59
chore(deps): update dependency reconnecting-eventsource to v1.6.5 (#741)
renovate[bot] Jun 27, 2026
5b7ae24
chore: upgrade @anthropic-ai/sdk to 0.104.1 and @anthropic-ai/vertex-…
p12tic Jun 28, 2026
f63f7a9
fix(deps): update ai sdks and providers (#744)
renovate[bot] Jun 28, 2026
5587e2d
chore(deps): update dependency posthog-js to v1.393.4 (#746)
renovate[bot] Jun 28, 2026
d4741f6
chore(deps): update dependency ajv to v8.20.0 (#747)
renovate[bot] Jun 28, 2026
9bc4e39
chore(deps): update dependency mermaid to v11.16.0 (#742)
renovate[bot] Jun 28, 2026
83fc6bb
chore(deps): update build, lint, and test tooling (#745)
renovate[bot] Jun 28, 2026
78e11a7
fix: LiteLLM cache key collision and silent fallback to non-existent …
awschmeder Jun 29, 2026
515437b
fix: shell default profile name type guard (#687)
daewoongoh Jun 29, 2026
8849f1a
chore: enforce no-floating-promises in core/task/ (#253)
0xMink Jun 30, 2026
80fb159
ci: improve PR label reconciliation with CI gating and event triggers…
roomote[bot] Jun 30, 2026
67df9f9
fix(delegation): atomically serialize reopenParentFromDelegation (#725)
edelauna Jun 30, 2026
9a2e8d8
fix(vscode-lm): reliable auto context condensing (#710)
simurg79 Jul 1, 2026
211d360
fix(ThinkingBudget): support xhigh and all extended reasoning effort …
edelauna Jul 1, 2026
f845f2a
feat: implement Claude Sonnet 5 support in Zoo Code (#778)
navedmerchant Jul 1, 2026
7476c67
feat(task-lifecycle): task status transition guard and startup delega…
edelauna Jul 1, 2026
63dec51
fix(#689): provider cache reset after settings import (#726)
JunyongParkDev Jul 1, 2026
29c2d2e
fix(gemini): base64 encoding though signature (#776)
edelauna Jul 1, 2026
8d4ed32
feat(semble): upgrade to v0.4.1, flatten result parsing, localize sta…
navedmerchant Jul 2, 2026
1c728e7
chore(security): dependency-review, invisible-char detection, and lea…
edelauna Jul 2, 2026
8e76b8d
fix(deepseek): round-trip reasoning_content in thinking mode to preve…
edelauna Jul 3, 2026
39351a9
chore: prepare v3.66.0 release (#795)
navedmerchant Jul 3, 2026
fa3af3f
fix(label-pr-review-state): fixing behaviour on forked prs (#234)
roomote[bot] Jul 4, 2026
7fa008c
refactor: remove deprecated openai-error-handler shim and use error-h…
daewoongoh Jul 4, 2026
4e5f601
feat(label-pr-review-state): tag PRs with conflicts (#269)
roomote[bot] Jul 4, 2026
1211eaa
fix: avoid unsafe array index access in AnthropicVertex completePromp…
daewoongoh Jul 4, 2026
21a15e5
feat(nightly-publish): adding ovsx pre-release step (#790)
edelauna Jul 4, 2026
737f27d
fix(task-lifecycle): preserve parent-child link when delegated subtas…
edelauna Jul 6, 2026
12fd60b
chore(deps): update github/codeql-action digest to 411c4c9 (#803)
renovate[bot] Jul 6, 2026
15d4d8c
chore(deps): update dependency @types/react to v18.3.31 (#805)
renovate[bot] Jul 7, 2026
ea032d4
feat(friendli): add Friendli provider with GLM-5.2 support (#721)
Lee-Si-Yoon Jul 7, 2026
ff3730a
chore(deps): update dependency axios to v1.18.1 (#806)
renovate[bot] Jul 7, 2026
e2cdd3c
feat(ollama): add native thinking/reasoning support (#832)
navedmerchant Jul 7, 2026
edb6564
fix: Ollama provider tool result handling and premature context conde…
navedmerchant Jul 9, 2026
13c803b
fix(anthropic): honor custom apiModelId instead of silently defaultin…
grizmin Jul 9, 2026
1833f5a
chore: prepare v3.68.0 release
taltas Jul 11, 2026
ff20416
Merge upstream v3.68.0 into local/daily-driver
Jul 11, 2026
f8b31ec
docs(fork): record v3.68.0 sync pain points + Sonnet 5 decision
Jul 11, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
11 changes: 11 additions & 0 deletions .changeset/fix-anthropic-custom-model-id-fallback.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,11 @@
---
"zoo-code": patch
---

Fix Anthropic provider silently replacing a custom/unrecognized `apiModelId` with the hardcoded default model.

`AnthropicHandler.getModel()` coerced any `apiModelId` not present in the static `anthropicModels` table down to `anthropicDefaultModelId` ("claude-sonnet-4-5"), and that coerced id was what actually got sent as `model` in the API request -- silently ignoring a user-configured custom model name (e.g. a custom Anthropic-compatible deployment or proxy). This produced confusing "model does not exist" errors for the default model instead of the model the user actually selected (#418).

The same fallback also affected capability lookups used to build the `thinking` request parameter: an unrecognized id fell back to the default model's info, which can be from an older model generation with a different API contract, causing the request to use the legacy `thinking: {type: "enabled", budget_tokens}` shape and get rejected with a 400 by models that require `{type: "adaptive"}`.

The model id sent to the API now always honors a user-configured `apiModelId`. For unrecognized values, capabilities are best-effort guessed by matching known model-family substrings (mirroring the existing `BedrockHandler.guessModelInfoFromId` heuristic) instead of defaulting to `anthropicDefaultModelId`'s info.
28 changes: 28 additions & 0 deletions .changeset/fix-litellm-model-desync.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,28 @@
---
"zoo-code": patch
---

Fix LiteLLM provider cache key collision, credential priority, and model-selection fallback to non-existent default.

Two bugs are addressed:

1. **Cache key collision**: All URL-scoped providers (LiteLLM, Ollama, LM Studio, Poe, DeepSeek,
Requesty) previously shared one cache entry keyed only on the provider name. Switching between
profiles backed by different servers silently served the wrong model list and the stale list
persisted across VS Code restarts via the disk cache. Fixed with a compound cache key:
URL-scoped providers use `provider:baseUrl`; key-scoped providers (LiteLLM, Poe, Requesty)
additionally include a short, irreversible discriminator derived from the API key
(`provider:baseUrl:<discriminator>`) so that two different API keys on the same server never share
a cache entry (relevant when the server enforces per-key model allowlists). Both the discriminator
and the on-disk filename digest are derived via truncated PBKDF2 so neither can be reversed to
identify the API key written to the cache filename. The `RouterProvider.getModel()` cold-start
fallback is also corrected to pass the full options so it resolves the same compound key.

2. **Silent fallback to hardcoded default**: When the LiteLLM model list was empty (due to the
collision above, a failed sync, or a transient error), `useSelectedModel` reset the configured
model ID to `claude-3-7-sonnet-20250219` -- a model that typically does not exist on user
LiteLLM servers. Four sub-fixes: preserve the configured model ID when the list is empty;
invalidate the React Query router-models cache after a successful "Sync Models" click; pass the
current LiteLLM credentials in the debounced `requestRouterModels` message; and correct the
credential priority in `webviewMessageHandler.ts` so that message values (current unsaved field
state) take precedence over stale saved config, matching the pattern already used for DeepSeek.
5 changes: 5 additions & 0 deletions .changeset/improve-apply-diff-prompt.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
---
"zoo-code": patch
---

Enhance the `apply_diff` tool description and parameter instructions to recommend `:start_line:` with exact syntax and emphasize copy-paste exact matching requirements, improving success rates for Gemini Flash and other smaller/faster models.
5 changes: 5 additions & 0 deletions .github/workflows/cli-release.yml
Original file line number Diff line number Diff line change
Expand Up @@ -13,6 +13,11 @@ on:
type: boolean
default: false

# Least privilege: the release job escalates to contents: write via its own
# job-level permissions block.
permissions:
contents: read

jobs:
# Build CLI for each platform.
build:
Expand Down
49 changes: 49 additions & 0 deletions .github/workflows/code-qa.yml
Original file line number Diff line number Diff line change
Expand Up @@ -9,7 +9,56 @@ on:
merge_group:
types: [checks_requested]

# Least privilege: every job below escalates only where it needs to.
permissions:
contents: read

jobs:
dependency-review:
runs-on: ubuntu-latest
# Only meaningful for PRs — validates the dependency diff of the pull
# request against GitHub's advisory database before merge.
if: github.event_name == 'pull_request'
steps:
- name: Checkout code
uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4
with:
# This job never pushes — don't persist the GITHUB_TOKEN.
persist-credentials: false
- name: Dependency review
uses: actions/dependency-review-action@a1d282b36b6f3519aa1f3fc636f609c47dddb294 # v5.0.0

invisible-chars:
runs-on: ubuntu-latest
# Reject invisible / homoglyph Unicode that GitHub's diff UI renders
# invisibly and most editors hide. These compile fine, which is the
# risk: identifier-splitting, string-literal injection, and the
# "Trojan Source" bidi-override attack (U+202A-U+202E). Scanning raw
# bytes catches them in strings, identifiers, and comments alike.
steps:
- name: Checkout code
uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4
with:
# This job never pushes — don't persist the GITHUB_TOKEN.
persist-credentials: false
- name: Reject invisible / homoglyph Unicode
run: |
# zero-width (U+200B-200F), word joiner (U+2060), BOM (U+FEFF),
# bidi overrides (U+202A-202E), soft hyphen (U+00AD).
# Covers source, release-adjacent executable scripts
# (*.sh / *.cjs / *.cts / *.mts), and the executable shell
# blocks inside GitHub workflow/action YAML.
if grep -rnP '[\x{200B}-\x{200F}\x{202A}-\x{202E}\x{2060}\x{FEFF}\x{00AD}]' \
--include='*.ts' --include='*.tsx' --include='*.js' --include='*.mjs' \
--include='*.cjs' --include='*.cts' --include='*.mts' --include='*.sh' \
--include='*.yml' --include='*.yaml' \
--exclude-dir=node_modules --exclude-dir=dist --exclude-dir=out \
--exclude-dir=coverage --exclude-dir=.turbo --exclude-dir=.vinxi \
src webview-ui packages apps .github; then
echo "::error::Found invisible or homoglyph Unicode characters (zero-width / bidi-override / BOM / soft hyphen)"
exit 1
fi

check-translations:
runs-on: ubuntu-latest
steps:
Expand Down
9 changes: 7 additions & 2 deletions .github/workflows/codeql.yml
Original file line number Diff line number Diff line change
Expand Up @@ -7,6 +7,11 @@ on:
schedule:
- cron: '24 19 * * 3'

# Least privilege: the analyze job escalates to security-events: write via its
# own job-level permissions block.
permissions:
contents: read

jobs:
analyze:
name: Analyze (${{ matrix.language }})
Expand Down Expand Up @@ -47,7 +52,7 @@ jobs:

# Initializes the CodeQL tools for scanning.
- name: Initialize CodeQL
uses: github/codeql-action/init@dd903d2e4f5405488e5ef1422510ee31c8b32357 # v3
uses: github/codeql-action/init@411c4c9a36b3fca4d674f06b6396b2c6d23522c6 # v3
with:
languages: ${{ matrix.language }}
build-mode: ${{ matrix.build-mode }}
Expand Down Expand Up @@ -75,6 +80,6 @@ jobs:
exit 1

- name: Perform CodeQL Analysis
uses: github/codeql-action/analyze@dd903d2e4f5405488e5ef1422510ee31c8b32357 # v3
uses: github/codeql-action/analyze@411c4c9a36b3fca4d674f06b6396b2c6d23522c6 # v3
with:
category: "/language:${{matrix.language}}"
19 changes: 19 additions & 0 deletions .github/workflows/e2e.yml
Original file line number Diff line number Diff line change
Expand Up @@ -7,6 +7,9 @@ on:
merge_group:
types: [checks_requested]

permissions:
contents: read

jobs:
e2e-mock:
runs-on: ubuntu-latest
Expand Down Expand Up @@ -34,6 +37,22 @@ jobs:
- name: Install xvfb
if: github.event_name != 'pull_request' || steps.e2e-marker.outputs.cache-hit != 'true'
run: sudo apt-get install -y xvfb

- name: Get VS Code version from package.json
if: github.event_name != 'pull_request' || steps.e2e-marker.outputs.cache-hit != 'true'
id: vscode-ver
run: |
VERSION=$(node -p 'require("./apps/vscode-e2e/package.json").devDependencies["@types/vscode"]')
echo "version=$VERSION" >> $GITHUB_OUTPUT

- name: Cache VS Code test binary
if: github.event_name != 'pull_request' || steps.e2e-marker.outputs.cache-hit != 'true'
uses: actions/cache@0057852bfaa89a56745cba8c7296529d2fc39830 # v4
with:
path: |
apps/vscode-e2e/.vscode-test/
key: vscode-test-${{ runner.os }}-${{ steps.vscode-ver.outputs.version }}-v1

- name: Run mocked E2E tests
id: run-e2e
# merge_group and workflow_dispatch always run; cache skip is pull_request only
Expand Down
Loading
Loading