Product session traces (ClickHouse), pull-only deploy stack, DeepAgents/workspace reliability, Graph MCP stdio
fixes, and unified-diff proposed fixes for SCM comments.
Added
- Platform ClickHouse product traces — optional install-wide sink (Platform settings). When enabled, every
org dual-writes full session observations (agents, tools, LLM I/O, metadata; secret-redacted, no normal truncation)
for session deep-dive + analytics. Orgs cannot disable ingestion; they may only override TTL days
(GET/PUT /v1/org/trace-ttl). Read paths:GET /v1/org/trace-storage,GET /v1/org/traces/sessions,
GET /v1/sessions/:id/traces. Env:CLICKHOUSE_URL,CLICKHOUSE_USER,CLICKHOUSE_PASSWORD,
CLICKHOUSE_DATABASE,STEW_CLICKHOUSE_DEFAULT_TTL_DAYS. - Traces UI — org-scoped Traces nav (any tenant member when ClickHouse is enabled): list sessions with
stored observations, expand generations / tools / spans with readable I/O (raw JSON optional). Collapsible
help for event types and LangChain internals (RunnableSequence,RunnableLambda, graph spans). - ClickHouse compose overlay —
deploy/compose/docker-compose.clickhouse.yml(+clickhouse/config.d) for
local product-trace testing; configure the sink in Platform → ClickHouse (no preferred env wire file). - Pull-only stack — standalone
deploy/compose/docker-compose.stack.yml(optional
docker-compose.stack.swarm.ymlfor Swarm): published GHCR images, no monorepo / no build. - Re-review GitHub thread resolve — when lifecycle marks prior findings
fixed(fingerprint gone after a new
push/session), resolve matching PR review threads via GraphQL whenscmCommentId/ fingerprint / finding markers
match. Disable withSTEW_RESOLVE_FIXED_THREADS=0. - Org Analytics — token totals, average tokens per session, estimated total cost, and average cost per session
(from sessiontokenUsage/ list-price estimates). - Langfuse dual-write / sticky session IDs — full agent + subagent turns dual-written with product
sessionId
(org + platform destinations); specialist trace ids scoped per unit/role for parallel runs.
Changed
- Proposed fixes are always unified git diffs — specialists are prompted for unified-diff
suggestedFix;
extract normalizes plain snippets →---/+++/@@hunks; PR comments, session reports, and Findings UI always
render Proposed fix as a```difffence (Context blocks still use path language, e.g.go/ts).
Fixes GH comment parsers that previously saw language-tagged fences around diff-shaped bodies. - PR finding Context blocks continue to use GFM language tags from the file path for non-fix snippets.
- Finding status mix labels are humanized (
false_positive→ “False positive”). - DeepAgents review filesystem —
FilesystemBackendrooted on the unit clone (virtualMode), path jail +
host/cross-repo rewrite, empty permissions (avoidspath must be absolutekills), read-only write/edit refuse,
sandbox tools jailed to unit cwd, prompts no longer leak hostrepoPath. - Worker Graph MCP — default
GRAPH_MCP_COMMAND=/opt/graph-venv/bin/codesteward-mcp; image installs uv CPython
underUV_PYTHON_INSTALL_DIR=/opt/uv-python(readable by uid 1001); entrypoint opens legacy/root/.local/share/uv
when needed; stdio protocol is NDJSON (not Content-Length) forcodesteward-mcp.
Fixed
- DeepAgents empty filesystem tools — built-in
ls/read_file/glob/grepbound to the review clone
instead of an empty in-memory FS;sandbox_ls/ smartersandbox_read; cross-repo mistaken host paths
(workspace/local/ses_…/cross/…) rewritten or refused. - DeepAgents
path must be absolute: "."— non-empty DeepAgentspermissionsforced absolute paths before
our normalizer and aborted specialists underSTEW_REQUIRE_TOOL_AGENTS. Permissions cleared; jail/read-only
enforced in the review backend. - Graph MCP
spawn … EACCESas steward — uv CPython lived under mode-700/root; shebang could not load
libpythonafter privilege drop. Fixed install path + entrypoint chmod. - Worker not claiming jobs after Graph MCP hang — Content-Length framing broke
codesteward-mcpNDJSON
init; worker never entered dequeue. NDJSON write/parse + short init timeout; job loop starts even if graph soft-fails. - Cross-repo specialist path probing — unit-rooted tools + prompt/metadata host-path redaction so agents do not
lssession tree prefixes relative to the linked clone.
Upgrade notes
- Pull images / chart for 1.5.0:
helm upgrade --install codesteward oci://ghcr.io/codesteward/codesteward/charts/codesteward \ --version 1.5.0 \ --set image.tag=1.5.0 \ --set ui.image.tag=1.5.0
- Optional product traces: deploy ClickHouse (or managed), set platform ClickHouse in UI, or compose
docker-compose.clickhouse.yml. Members see Traces when the sink is enabled. - Workers: rebuild so Graph MCP binary + NDJSON client ship; confirm logs show
[graph-mcp] stdio session readythen[worker] starting Codesteward review worker. - Suggested code fixes: existing DB rows may still store plain snippets; new extracts + PR publish always
emit unified```difffor proposed fixes.
Container images
docker pull ghcr.io/codesteward/codesteward:1.5.0
docker pull ghcr.io/codesteward/codesteward/ui:1.5.0
docker pull ghcr.io/codesteward/codesteward/keycloak:26.7.0 # tag = upstream Keycloak, not product 1.5.0App image runs API by default (SERVICE=api). Worker:
docker run --rm -e SERVICE=worker ghcr.io/codesteward/codesteward:1.5.0Keycloak image tags match upstream Keycloak (theme + realm baked in; no git mounts):
docker run --rm -p 8083:8083 -e KEYCLOAK_ADMIN=admin -e KEYCLOAK_ADMIN_PASSWORD=admin \
ghcr.io/codesteward/codesteward/keycloak:26.7.0 start-dev --import-realm --http-port=8083Helm chart (OCI on GHCR)
helm install codesteward oci://ghcr.io/codesteward/codesteward/charts/codesteward --version 1.5.0
# or: helm pull oci://ghcr.io/codesteward/codesteward/charts/codesteward --version 1.5.0Chart package is also attached to this release as codesteward-1.5.0.tgz.
Docs: Kubernetes quick start in the product documentation site.
Images are signed with cosign keyless via GitHub OIDC.
Verify with:
cosign verify ghcr.io/codesteward/codesteward:1.5.0 \
--certificate-identity-regexp 'https://github.com/Codesteward/codesteward/.*' \
--certificate-oidc-issuer https://token.actions.githubusercontent.com