Feat/competitive parity 2026 - #259
Merged
Merged
Conversation
Bumps [axum](https://github.com/tokio-rs/axum) from 0.7.9 to 0.8.9. - [Release notes](https://github.com/tokio-rs/axum/releases) - [Changelog](https://github.com/tokio-rs/axum/blob/main/CHANGELOG.md) - [Commits](tokio-rs/axum@axum-v0.7.9...axum-v0.8.9) --- updated-dependencies: - dependency-name: axum dependency-version: 0.8.9 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps [tower-http](https://github.com/tower-rs/tower-http) from 0.6.11 to 0.7.0. - [Release notes](https://github.com/tower-rs/tower-http/releases) - [Commits](tower-rs/tower-http@tower-http-0.6.11...tower-http-0.7.0) --- updated-dependencies: - dependency-name: tower-http dependency-version: 0.7.0 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
…0' into dependabot/cargo/axum-0.8.9
axum 0.8 breaking changes addressed:
1. Route path syntax ':param' -> '{param}'. axum 0.8 panics at router
build on any segment starting with ':' (validate_v07_paths). Migrated
all :param routes in serve.rs, watch_bridge.rs, a2a_http.rs, and
vibe-indexer/main.rs (route registrations + adjacent doc comments).
REST doc-labels in commands.rs/app_builder.rs left as ':id' (not
axum routes).
2. WebSocket Message types: Text(String)->Text(Utf8Bytes),
Binary(Vec<u8>)->Binary(Bytes). Added .into() at the 8 collab-WS
send/receive sites in serve.rs.
tower-http 0.7 (CorsLayer/SetResponseHeaderLayer/Any) API unchanged.
Verified: cargo check --workspace clean; a2a_http_bdd (3 scenarios,
12 steps) + serve_integration pass.
* chore(deps): bump axum 0.7→0.8 + tower-http 0.6→0.7 (with route-syntax + WS migration)
Migrates axum 0.7→0.8 and tower-http 0.6→0.7 (coupled — axum 0.8 requires tower-http 0.7). Includes the required source migration: route path syntax :param→{param} (axum 0.8 panics on :param segments) across serve.rs/watch_bridge.rs/a2a_http.rs/vibe-indexer, and WebSocket Message type conversions (Text→Utf8Bytes, Binary→Bytes). tower-http 0.7 CorsLayer/SetResponseHeaderLayer API unchanged. Subsumes #144 (tower-http bump carried here so the two coupled deps land together). Verified: cargo check --workspace clean; a2a_http_bdd 3 scenarios/12 steps pass.
* chore(deps): bump onnx from 1.21.0 to 1.22.0 in /vibe-rl-py (#155)
Bumps [onnx](https://github.com/onnx/onnx) from 1.21.0 to 1.22.0.
- [Release notes](https://github.com/onnx/onnx/releases)
- [Changelog](https://github.com/onnx/onnx/blob/main/docs/Changelog-ml.md)
- [Commits](onnx/onnx@v1.21.0...v1.22.0)
---
updated-dependencies:
- dependency-name: onnx
dependency-version: 1.22.0
dependency-type: direct:production
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
* chore(deps): bump transformers from 4.57.6 to 5.3.0 in /vibe-rl-py (#150)
Bumps [transformers](https://github.com/huggingface/transformers) from 4.57.6 to 5.3.0.
- [Release notes](https://github.com/huggingface/transformers/releases)
- [Commits](huggingface/transformers@v4.57.6...v5.3.0)
---
updated-dependencies:
- dependency-name: transformers
dependency-version: 5.3.0
dependency-type: direct:production
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
* chore(deps): bump org.jetbrains.kotlinx:kotlinx-coroutines-play-services (#133)
Bumps [org.jetbrains.kotlinx:kotlinx-coroutines-play-services](https://github.com/Kotlin/kotlinx.coroutines) from 1.8.1 to 1.11.0.
- [Release notes](https://github.com/Kotlin/kotlinx.coroutines/releases)
- [Changelog](https://github.com/Kotlin/kotlinx.coroutines/blob/master/CHANGES.md)
- [Commits](Kotlin/kotlinx.coroutines@1.8.1...1.11.0)
---
updated-dependencies:
- dependency-name: org.jetbrains.kotlinx:kotlinx-coroutines-play-services
dependency-version: 1.11.0
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
* chore(deps): bump androidx.compose.ui:ui-tooling-preview (#153)
Bumps androidx.compose.ui:ui-tooling-preview from 1.7.6 to 1.11.4.
---
updated-dependencies:
- dependency-name: androidx.compose.ui:ui-tooling-preview
dependency-version: 1.11.4
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
* chore(deps): bump gradle-wrapper in /vibewatch/VibeCodyWear (#147)
Bumps [gradle-wrapper](https://github.com/gradle/gradle) from 8.10.2 to 9.6.1.
- [Release notes](https://github.com/gradle/gradle/releases)
- [Commits](gradle/gradle@v8.10.2...v9.6.1)
---
updated-dependencies:
- dependency-name: gradle-wrapper
dependency-version: 9.6.1
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
* Dependabot/cargo/axum 0.8.9 (#156)
* chore(deps): bump axum from 0.7.9 to 0.8.9
Bumps [axum](https://github.com/tokio-rs/axum) from 0.7.9 to 0.8.9.
- [Release notes](https://github.com/tokio-rs/axum/releases)
- [Changelog](https://github.com/tokio-rs/axum/blob/main/CHANGELOG.md)
- [Commits](tokio-rs/axum@axum-v0.7.9...axum-v0.8.9)
---
updated-dependencies:
- dependency-name: axum
dependency-version: 0.8.9
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com>
* chore(deps): bump tower-http from 0.6.11 to 0.7.0
Bumps [tower-http](https://github.com/tower-rs/tower-http) from 0.6.11 to 0.7.0.
- [Release notes](https://github.com/tower-rs/tower-http/releases)
- [Commits](tower-rs/tower-http@tower-http-0.6.11...tower-http-0.7.0)
---
updated-dependencies:
- dependency-name: tower-http
dependency-version: 0.7.0
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com>
* Migrate axum 0.8 route syntax + WS message types
axum 0.8 breaking changes addressed:
1. Route path syntax ':param' -> '{param}'. axum 0.8 panics at router
build on any segment starting with ':' (validate_v07_paths). Migrated
all :param routes in serve.rs, watch_bridge.rs, a2a_http.rs, and
vibe-indexer/main.rs (route registrations + adjacent doc comments).
REST doc-labels in commands.rs/app_builder.rs left as ':id' (not
axum routes).
2. WebSocket Message types: Text(String)->Text(Utf8Bytes),
Binary(Vec<u8>)->Binary(Bytes). Added .into() at the 8 collab-WS
send/receive sites in serve.rs.
tower-http 0.7 (CorsLayer/SetResponseHeaderLayer/Any) API unchanged.
Verified: cargo check --workspace clean; a2a_http_bdd (3 scenarios,
12 steps) + serve_integration pass.
---------
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
---------
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [typescript](https://github.com/microsoft/TypeScript) from 6.0.3 to 7.0.2. - [Release notes](https://github.com/microsoft/TypeScript/releases) - [Commits](https://github.com/microsoft/TypeScript/commits) --- updated-dependencies: - dependency-name: typescript dependency-version: 7.0.2 dependency-type: direct:development update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps [org.jetbrains.kotlin.android](https://github.com/JetBrains/kotlin) from 2.1.0 to 2.4.10. - [Release notes](https://github.com/JetBrains/kotlin/releases) - [Changelog](https://github.com/JetBrains/kotlin/blob/master/ChangeLog.md) - [Commits](JetBrains/kotlin@v2.1.0...v2.4.10) --- updated-dependencies: - dependency-name: org.jetbrains.kotlin.android dependency-version: 2.4.10 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps [actions/setup-python](https://github.com/actions/setup-python) from 6 to 7. - [Release notes](https://github.com/actions/setup-python/releases) - [Commits](actions/setup-python@v6...v7) --- updated-dependencies: - dependency-name: actions/setup-python dependency-version: '7' dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps [actions/setup-java](https://github.com/actions/setup-java) from 5.3.0 to 5.7.0. - [Release notes](https://github.com/actions/setup-java/releases) - [Commits](actions/setup-java@ad2b381...b6effb0) --- updated-dependencies: - dependency-name: actions/setup-java dependency-version: 5.7.0 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps [actions/setup-node](https://github.com/actions/setup-node) from 6.4.0 to 7.0.0. - [Release notes](https://github.com/actions/setup-node/releases) - [Commits](actions/setup-node@48b55a0...8207627) --- updated-dependencies: - dependency-name: actions/setup-node dependency-version: 7.0.0 dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps [jsdom](https://github.com/jsdom/jsdom) from 29.1.1 to 30.0.1. - [Release notes](https://github.com/jsdom/jsdom/releases) - [Commits](jsdom/jsdom@v29.1.1...v30.0.1) --- updated-dependencies: - dependency-name: jsdom dependency-version: 30.0.1 dependency-type: direct:development update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps [EmbarkStudios/cargo-deny-action](https://github.com/embarkstudios/cargo-deny-action) from 2.0.20 to 2.1.1. - [Release notes](https://github.com/embarkstudios/cargo-deny-action/releases) - [Commits](EmbarkStudios/cargo-deny-action@bb137d7...3c63498) --- updated-dependencies: - dependency-name: EmbarkStudios/cargo-deny-action dependency-version: 2.1.1 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps [tree-sitter](https://github.com/tree-sitter/tree-sitter) from 0.25.10 to 0.26.11. - [Release notes](https://github.com/tree-sitter/tree-sitter/releases) - [Commits](tree-sitter/tree-sitter@v0.25.10...v0.26.11) --- updated-dependencies: - dependency-name: tree-sitter dependency-version: 0.26.11 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps [sysinfo](https://github.com/GuillaumeGomez/sysinfo) from 0.36.1 to 0.39.6. - [Changelog](https://github.com/GuillaumeGomez/sysinfo/blob/main/CHANGELOG.md) - [Commits](GuillaumeGomez/sysinfo@v0.36.1...v0.39.6) --- updated-dependencies: - dependency-name: sysinfo dependency-version: 0.39.6 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps [tokio-tungstenite](https://github.com/snapview/tokio-tungstenite) from 0.28.0 to 0.29.0. - [Changelog](https://github.com/snapview/tokio-tungstenite/blob/master/CHANGELOG.md) - [Commits](snapview/tokio-tungstenite@v0.28.0...v0.29.0) --- updated-dependencies: - dependency-name: tokio-tungstenite dependency-version: 0.29.0 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps [rustyline](https://github.com/kkawakam/rustyline) from 14.0.0 to 17.0.2. - [Release notes](https://github.com/kkawakam/rustyline/releases) - [Changelog](https://github.com/kkawakam/rustyline/blob/master/History.md) - [Commits](kkawakam/rustyline@v14.0.0...v17.0.2) --- updated-dependencies: - dependency-name: rustyline dependency-version: 17.0.2 dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps [typescript](https://github.com/microsoft/TypeScript) from 6.0.3 to 7.0.2. - [Release notes](https://github.com/microsoft/TypeScript/releases) - [Commits](https://github.com/microsoft/TypeScript/commits) --- updated-dependencies: - dependency-name: typescript dependency-version: 7.0.2 dependency-type: direct:development update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps [chacha20poly1305](https://github.com/RustCrypto/AEADs) from 0.10.1 to 0.11.0. - [Commits](RustCrypto/AEADs@chacha20poly1305-v0.10.1...chacha20poly1305-v0.11.0) --- updated-dependencies: - dependency-name: chacha20poly1305 dependency-version: 0.11.0 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps [gradle-wrapper](https://github.com/gradle/gradle) from 9.6.1 to 9.7.0. - [Release notes](https://github.com/gradle/gradle/releases) - [Commits](gradle/gradle@v9.6.1...v9.7.0) --- updated-dependencies: - dependency-name: gradle-wrapper dependency-version: 9.7.0 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps [flutter_secure_storage](https://github.com/mogol/flutter_secure_storage) from 10.3.1 to 11.0.0. - [Release notes](https://github.com/mogol/flutter_secure_storage/releases) - [Commits](juliansteenbakker/flutter_secure_storage@v10.3.1...flutter_secure_storage-v11.0.0) --- updated-dependencies: - dependency-name: flutter_secure_storage dependency-version: 11.0.0 dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com>
… updates Bumps the vibecoder-minor group with 5 updates in the /vibecoder directory: | Package | From | To | | --- | --- | --- | | [lucide-react](https://github.com/lucide-icons/lucide/tree/HEAD/packages/lucide-react) | `1.28.0` | `1.29.0` | | [y-websocket](https://github.com/yjs/y-websocket) | `3.0.0` | `3.1.0` | | [yjs](https://github.com/yjs/yjs) | `13.6.31` | `13.6.32` | | [monaco-editor](https://github.com/microsoft/monaco-editor) | `0.55.1` | `0.56.0` | | [vite](https://github.com/vitejs/vite/tree/HEAD/packages/vite) | `8.2.0` | `8.2.1` | Updates `lucide-react` from 1.28.0 to 1.29.0 - [Release notes](https://github.com/lucide-icons/lucide/releases) - [Commits](https://github.com/lucide-icons/lucide/commits/1.29.0/packages/lucide-react) Updates `y-websocket` from 3.0.0 to 3.1.0 - [Release notes](https://github.com/yjs/y-websocket/releases) - [Commits](yjs/y-websocket@v3.0.0...v3.1.0) Updates `yjs` from 13.6.31 to 13.6.32 - [Release notes](https://github.com/yjs/yjs/releases) - [Commits](yjs/yjs@v13.6.31...v13.6.32) Updates `monaco-editor` from 0.55.1 to 0.56.0 - [Release notes](https://github.com/microsoft/monaco-editor/releases) - [Changelog](https://github.com/microsoft/monaco-editor/blob/main/CHANGELOG.md) - [Commits](microsoft/monaco-editor@v0.55.1...v0.56.0) Updates `vite` from 8.2.0 to 8.2.1 - [Release notes](https://github.com/vitejs/vite/releases) - [Changelog](https://github.com/vitejs/vite/blob/main/packages/vite/CHANGELOG.md) - [Commits](https://github.com/vitejs/vite/commits/v8.2.1/packages/vite) --- updated-dependencies: - dependency-name: lucide-react dependency-version: 1.29.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: vibecoder-minor - dependency-name: y-websocket dependency-version: 3.1.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: vibecoder-minor - dependency-name: yjs dependency-version: 13.6.32 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: vibecoder-minor - dependency-name: monaco-editor dependency-version: 0.56.0 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: vibecoder-minor - dependency-name: vite dependency-version: 8.2.1 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: vibecoder-minor ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps [gradle-wrapper](https://github.com/gradle/gradle) from 9.6.1 to 9.7.0. - [Release notes](https://github.com/gradle/gradle/releases) - [Commits](gradle/gradle@v9.6.1...v9.7.0) --- updated-dependencies: - dependency-name: gradle-wrapper dependency-version: 9.7.0 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps [gradle-wrapper](https://github.com/gradle/gradle) from 9.6.1 to 9.7.0. - [Release notes](https://github.com/gradle/gradle/releases) - [Commits](gradle/gradle@v9.6.1...v9.7.0) --- updated-dependencies: - dependency-name: gradle-wrapper dependency-version: 9.7.0 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps the vibeaichat-minor group in /vibeaichat with 1 update: [vite](https://github.com/vitejs/vite/tree/HEAD/packages/vite). Updates `vite` from 8.2.0 to 8.2.1 - [Release notes](https://github.com/vitejs/vite/releases) - [Changelog](https://github.com/vitejs/vite/blob/main/packages/vite/CHANGELOG.md) - [Commits](https://github.com/vitejs/vite/commits/v8.2.1/packages/vite) --- updated-dependencies: - dependency-name: vite dependency-version: 8.2.1 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: vibeaichat-minor ... Signed-off-by: dependabot[bot] <support@github.com>
…updates Bumps the vibedesk-minor group with 2 updates in the /vibedesk directory: [lucide-react](https://github.com/lucide-icons/lucide/tree/HEAD/packages/lucide-react) and [@tauri-apps/cli](https://github.com/tauri-apps/tauri). Updates `lucide-react` from 1.28.0 to 1.29.0 - [Release notes](https://github.com/lucide-icons/lucide/releases) - [Commits](https://github.com/lucide-icons/lucide/commits/1.29.0/packages/lucide-react) Updates `@tauri-apps/cli` from 2.11.2 to 2.11.4 - [Release notes](https://github.com/tauri-apps/tauri/releases) - [Commits](https://github.com/tauri-apps/tauri/compare/@tauri-apps/cli-v2.11.2...@tauri-apps/cli-v2.11.4) --- updated-dependencies: - dependency-name: "@tauri-apps/cli" dependency-version: 2.11.4 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: vibedesk-minor - dependency-name: lucide-react dependency-version: 1.29.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: vibedesk-minor ... Signed-off-by: dependabot[bot] <support@github.com>
My previous commit replaced the single-line `run: npx tauri build` with a
multi-line POSIX-shell block that exports the Apple variables conditionally.
Windows runners default to PowerShell, so all three Windows bundles failed with
ParserError: D:\a\_temp\<id>.ps1:2
before tauri ever started. They had been green.
GitHub provides bash on Windows runners, and the rest of the workflow already
uses `shell: bash` for its cross-platform steps (see "Collect artifacts"), so
this matches the existing convention rather than introducing one.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Replace rsa crate usage with ring for RS256 JWT signing in vibe-broker to avoid a timing side-channel advisory. Add pkcs8 PEM→DER helper, comprehensive unit tests that verify JWT structure and signature verification, and a test PEM fixture. Also trim syntect default features (dropping yaml-rust) and update Cargo.toml/Cargo.lock to reflect dependency changes.
Bumps [similar](https://github.com/mitsuhiko/similar) from 2.7.0 to 3.1.2. - [Changelog](https://github.com/mitsuhiko/similar/blob/main/CHANGELOG.md) - [Commits](mitsuhiko/similar@2.7.0...3.1.2) --- updated-dependencies: - dependency-name: similar dependency-version: 3.1.2 dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps [typescript](https://github.com/microsoft/TypeScript) from 5.9.3 to 7.0.2. - [Release notes](https://github.com/microsoft/TypeScript/releases) - [Commits](https://github.com/microsoft/TypeScript/commits) --- updated-dependencies: - dependency-name: typescript dependency-version: 7.0.2 dependency-type: direct:development update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com>
…bundles v0.5.7 and v0.5.8 both went green, uploaded artifacts, and were killed by macOS on every user's machine: the signing step fell back to ad-hoc, and nothing downstream checked. build-cli had guarded against that since it was written; the three Tauri app bundles and the iOS .ipa had not. - Verify, don't trust. Each macOS bundle job (VibeCoder, VibeAIChat, VibeDesk) and the iOS packaging step now run `codesign --verify --deep --strict` and fail the job when the result is `Signature=adhoc` despite a certificate having been imported. Ad-hoc remains the intended outcome when no certificate is configured — the check only runs when one was. - Notarize the CLI binary. A Developer ID signature alone is not enough for a quarantined download; the ticket lives on Apple's servers for a bare Mach-O (stapling only works for .app/.dmg/.pkg), and `notarytool --wait` returns 0 only on Accepted. Skipped with a notice when credentials are absent. - APPLE_KEYCHAIN_PASSWORD is no longer required. The keychain is created, used and discarded inside the job, so a generated password protects the same nothing — and removes the silent failure where an empty one makes `security` behave differently than intended. - Signed iOS builds. Gated on all three of APPLE_TEAM_ID / APPLE_DIST_CERT_P12_BASE64 / APPLE_IOS_PROFILE_BASE64; the unsigned sideloadable .ipa still ships when they are absent. - watchOS gate checks every secret it needs, not just APPLE_TEAM_ID, which is shared with the desktop jobs — configuring desktop signing used to arm this job and then kill it on an empty provisioning profile. Its `if:` also referenced its own step output, so it always evaluated true. TestFlight upload is now gated separately from producing a signed IPA. - The ad-hoc notices say what actually happens (macOS kills the app; `xattr -dr com.apple.quarantine`) instead of "unidentified developer, right-click → Open", which does not reliably fix it. - scripts/setup-apple-signing.sh configures all of the above secrets from a Mac that holds the certificate. It pairs certificate and private key by public modulus — PEM export order is not guaranteed, and pairing by position yields a .p12 that imports cleanly and then cannot sign. - .cargo/audit.toml collects the RUSTSEC suppression list that had been copied into three places and drifted, which is how v0.5.8's release failed on an advisory only one copy carried. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…r_secure_storage-11.0.0' into feat/competitive-parity-2026
…xtension/typescript-7.0.2' into feat/competitive-parity-2026
…at/typescript-7.0.2' into feat/competitive-parity-2026
…at/vibeaichat-minor-7f7e8a2361' into feat/competitive-parity-2026 # Conflicts: # vibeaichat/package-lock.json # vibeaichat/package.json
…r/jsdom-30.0.1' into feat/competitive-parity-2026
…r/typescript-7.0.2' into feat/competitive-parity-2026
…r/vibecoder-minor-951f0d5853' into feat/competitive-parity-2026
Introduce a new ghost-text completion surface that triggers only on explicit user gestures (⌘. style), replacing the keystroke-driven keystroke-driven path removed in commit 5a7eef7 for patent reasons. Changes: - New vibe_ai::ghost module with request/response types, message building, and sanitization (caps output to 12 lines, handles code fences) - Extract resolve_editing_provider() to route both diffcomplete and ghost text through the toolbar's provider/model selection, fixing a bug where diffcomplete dropped the model entirely - Add model parameter to diffcomplete_generate to pass toolbar selection through - Register ghost_complete Tauri command The ghost module intentionally carries no hidden state, edit history, or automatic triggering — only the visible prefix/suffix window and optional project memory. This keeps the boundary between explicit and automatic requests clear, with the gate living in the editor's inline-completion provider.
The Dependabot bump to typescript ~7.0.2 left vibecoder with an unresolvable dependency graph: typescript-eslint@8.66.0 peers on typescript >=4.8.4 <6.1.0, and no published typescript-eslint (8.67.0 latest) supports TS 7 yet. The bump merged textually clean, so npm was never invoked and never objected — npm install --package-lock-only fails with ERESOLVE. Restores the version this project was on before the bump (~6.0.3) and regenerates the lockfile from the manifest, so the two agree again. vibeaichat and vibedesk keep TS 7 — neither uses typescript-eslint. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…nsion typescript-eslint@8.57.2 peers on typescript <6.1.0. Restores ^5.3.0, the version before the Dependabot bump, and re-locks. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…/vibedesk-minor-f9c1d22261' into feat/competitive-parity-2026
…into feat/competitive-parity-2026
…5-0.11.0' into feat/competitive-parity-2026 # Conflicts: # Cargo.lock
…to feat/competitive-parity-2026 # Conflicts: # Cargo.lock
…to feat/competitive-parity-2026 # Conflicts: # Cargo.lock # Cargo.toml
…2' into feat/competitive-parity-2026
…into feat/competitive-parity-2026
… into feat/competitive-parity-2026 # Conflicts: # Cargo.lock
…te-0.29.0' into feat/competitive-parity-2026
…6.11' into feat/competitive-parity-2026
… feat/competitive-parity-2026 # Conflicts: # Cargo.lock
Resolved entirely to HEAD. The branch predates the VibeUI -> VibeCoder rename by 224 commits, so git matched vibeui/package.json onto vibecoder/package.json. Every version on its side is older than HEAD's (typescript-eslint 8.57.2 < 8.66.0, vite 8.0.16 < 8.2.1, vitest 4.1.0 < 4.1.10) and it lacks the dompurify overrides block. Its only forward change is typescript 7, which cannot resolve against typescript-eslint. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Three conflicts, all resolved deliberately: - .github/workflows/release.yml — all three hunks are additions present only on HEAD: the 'verify the bundle is not ad-hoc signed' guard. The release branch predates it. Taking its side would delete the check that exists because v0.5.7 and v0.5.8 shipped ad-hoc-signed bundles that macOS killed on every user's machine. Kept HEAD. - vibecli/crates/vibe-broker/Cargo.toml — base64 0.23 (Dependabot bump already merged here) over the branch's 0.22. - vibecli/crates/vibe-broker/src/token_mint.rs — pure rustfmt difference, no semantic change (hunk 1 differs only by closure braces). Took the formatted side, since that branch exists to fix a red 'Rust (fmt)'; cargo fmt --check is clean on the result. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Introduce an explicit-trigger "ghost text" inline completion feature. Adds /v1/ghost/complete server route and daemon->vibe_ai glue, a new vibecoder lib (ghostText.ts) with unit tests, and registers the provider + Alt+\ keybinding in the App UI (forwards provider+model). Update LSP completion context mapping to translate Monaco trigger kinds to LSP. VS Code extension: add ghostComplete command, inline provider, API client method, settings and keybinding. Gate: only responds to explicit/user trigger (no debounce or keystroke-driven requests); truncated responses are surfaced.
The Dependabot typescript ^7.0.2 bump is merged here (vibeaichat has no typescript-eslint, so unlike vibecoder and vscode-extension it can take it). TS 7 raises TS2882 on side-effect imports with no declaration, and vibeaichat had no .d.ts at all — four errors on './App.css' and the @vibe/shared stylesheets. Adds the same src/vite-env.d.ts that vibecoder already carries. tsc --noEmit is clean on TypeScript 7.0.2. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…ty-2026 Contributes axum 0.8.9 in Cargo.lock; Cargo.toml's `axum = "0.8"` already covered it. Every other conflict resolved to HEAD — the branch is from PR #157 and predates several renames and fixes, so its side is uniformly older: - serve.rs / watch_bridge.rs — 'VibeX' and 'VibeUI' naming, superseded by the VibeDesk and VibeCoder renames. - vibe-rl-py/pyproject.toml — mujoco>=3.0 / gymnasium>=0.29 against HEAD's >=3.11.0 / >=1.3.0, and it reinstates the accept-rom-license extra that HEAD removed because gymnasium 1.0 dropped it. - gradle wrapper — older than the 9.7.0 already merged from dependabot/gradle/vibewatch/VibeCodyWear/gradle-wrapper-9.7.0. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Introduce explicit-trigger "ghost text" docs and hook up related tests and fixes. - Add docs/ghost-text.md and expose it in docs/_config.yml sidebar. - Update docs/diffcomplete.md to describe ghost-text as an explicit-trigger alternative and clarify behavior. - Add server-side tests for POST /v1/ghost/complete: unauthenticated 401 and empty-window BAD_REQUEST checks (vibecli/vibecli-cli/src/serve.rs). - Update frontend tests (DiffCompleteModal) to include the model field when sending provider so the backend preserves the host's model choice. - Add LSP mapping tests (toLspCompletionContext) to ensure Monaco trigger kinds map correctly to LSP (avoid emitting LSP's invalid 0). Rationale: document and validate the new short-form inline completion flow (explicit trigger only), and fix/test completion trigger mapping and model forwarding to avoid provider/model misrouting.
…e-parity-2026 (#257) (#258) * chore(deps): bump axum from 0.7.9 to 0.8.9 Bumps [axum](https://github.com/tokio-rs/axum) from 0.7.9 to 0.8.9. - [Release notes](https://github.com/tokio-rs/axum/releases) - [Changelog](https://github.com/tokio-rs/axum/blob/main/CHANGELOG.md) - [Commits](https://github.com/tokio-rs/axum/compare/axum-v0.7.9...axum-v0.8.9) --- updated-dependencies: - dependency-name: axum dependency-version: 0.8.9 dependency-type: direct:production update-type: version-update:semver-minor ... * chore(deps): bump tower-http from 0.6.11 to 0.7.0 Bumps [tower-http](https://github.com/tower-rs/tower-http) from 0.6.11 to 0.7.0. - [Release notes](https://github.com/tower-rs/tower-http/releases) - [Commits](https://github.com/tower-rs/tower-http/compare/tower-http-0.6.11...tower-http-0.7.0) --- updated-dependencies: - dependency-name: tower-http dependency-version: 0.7.0 dependency-type: direct:production update-type: version-update:semver-minor ... * Migrate axum 0.8 route syntax + WS message types axum 0.8 breaking changes addressed: 1. Route path syntax ':param' -> '{param}'. axum 0.8 panics at router build on any segment starting with ':' (validate_v07_paths). Migrated all :param routes in serve.rs, watch_bridge.rs, a2a_http.rs, and vibe-indexer/main.rs (route registrations + adjacent doc comments). REST doc-labels in commands.rs/app_builder.rs left as ':id' (not axum routes). 2. WebSocket Message types: Text(String)->Text(Utf8Bytes), Binary(Vec<u8>)->Binary(Bytes). Added .into() at the 8 collab-WS send/receive sites in serve.rs. tower-http 0.7 (CorsLayer/SetResponseHeaderLayer/Any) API unchanged. Verified: cargo check --workspace clean; a2a_http_bdd (3 scenarios, 12 steps) + serve_integration pass. * update branch (#157) * chore(deps): bump axum 0.7→0.8 + tower-http 0.6→0.7 (with route-syntax + WS migration) Migrates axum 0.7→0.8 and tower-http 0.6→0.7 (coupled — axum 0.8 requires tower-http 0.7). Includes the required source migration: route path syntax :param→{param} (axum 0.8 panics on :param segments) across serve.rs/watch_bridge.rs/a2a_http.rs/vibe-indexer, and WebSocket Message type conversions (Text→Utf8Bytes, Binary→Bytes). tower-http 0.7 CorsLayer/SetResponseHeaderLayer API unchanged. Subsumes #144 (tower-http bump carried here so the two coupled deps land together). Verified: cargo check --workspace clean; a2a_http_bdd 3 scenarios/12 steps pass. * chore(deps): bump onnx from 1.21.0 to 1.22.0 in /vibe-rl-py (#155) Bumps [onnx](https://github.com/onnx/onnx) from 1.21.0 to 1.22.0. - [Release notes](https://github.com/onnx/onnx/releases) - [Changelog](https://github.com/onnx/onnx/blob/main/docs/Changelog-ml.md) - [Commits](https://github.com/onnx/onnx/compare/v1.21.0...v1.22.0) --- updated-dependencies: - dependency-name: onnx dependency-version: 1.22.0 dependency-type: direct:production ... * chore(deps): bump transformers from 4.57.6 to 5.3.0 in /vibe-rl-py (#150) Bumps [transformers](https://github.com/huggingface/transformers) from 4.57.6 to 5.3.0. - [Release notes](https://github.com/huggingface/transformers/releases) - [Commits](https://github.com/huggingface/transformers/compare/v4.57.6...v5.3.0) --- updated-dependencies: - dependency-name: transformers dependency-version: 5.3.0 dependency-type: direct:production ... * chore(deps): bump org.jetbrains.kotlinx:kotlinx-coroutines-play-services (#133) Bumps [org.jetbrains.kotlinx:kotlinx-coroutines-play-services](https://github.com/Kotlin/kotlinx.coroutines) from 1.8.1 to 1.11.0. - [Release notes](https://github.com/Kotlin/kotlinx.coroutines/releases) - [Changelog](https://github.com/Kotlin/kotlinx.coroutines/blob/master/CHANGES.md) - [Commits](https://github.com/Kotlin/kotlinx.coroutines/compare/1.8.1...1.11.0) --- updated-dependencies: - dependency-name: org.jetbrains.kotlinx:kotlinx-coroutines-play-services dependency-version: 1.11.0 dependency-type: direct:production update-type: version-update:semver-minor ... * chore(deps): bump androidx.compose.ui:ui-tooling-preview (#153) Bumps androidx.compose.ui:ui-tooling-preview from 1.7.6 to 1.11.4. --- updated-dependencies: - dependency-name: androidx.compose.ui:ui-tooling-preview dependency-version: 1.11.4 dependency-type: direct:production update-type: version-update:semver-minor ... * chore(deps): bump gradle-wrapper in /vibewatch/VibeCodyWear (#147) Bumps [gradle-wrapper](https://github.com/gradle/gradle) from 8.10.2 to 9.6.1. - [Release notes](https://github.com/gradle/gradle/releases) - [Commits](https://github.com/gradle/gradle/compare/v8.10.2...v9.6.1) --- updated-dependencies: - dependency-name: gradle-wrapper dependency-version: 9.6.1 dependency-type: direct:production update-type: version-update:semver-major ... * Dependabot/cargo/axum 0.8.9 (#156) * chore(deps): bump axum from 0.7.9 to 0.8.9 Bumps [axum](https://github.com/tokio-rs/axum) from 0.7.9 to 0.8.9. - [Release notes](https://github.com/tokio-rs/axum/releases) - [Changelog](https://github.com/tokio-rs/axum/blob/main/CHANGELOG.md) - [Commits](https://github.com/tokio-rs/axum/compare/axum-v0.7.9...axum-v0.8.9) --- updated-dependencies: - dependency-name: axum dependency-version: 0.8.9 dependency-type: direct:production update-type: version-update:semver-minor ... * chore(deps): bump tower-http from 0.6.11 to 0.7.0 Bumps [tower-http](https://github.com/tower-rs/tower-http) from 0.6.11 to 0.7.0. - [Release notes](https://github.com/tower-rs/tower-http/releases) - [Commits](https://github.com/tower-rs/tower-http/compare/tower-http-0.6.11...tower-http-0.7.0) --- updated-dependencies: - dependency-name: tower-http dependency-version: 0.7.0 dependency-type: direct:production update-type: version-update:semver-minor ... * Migrate axum 0.8 route syntax + WS message types axum 0.8 breaking changes addressed: 1. Route path syntax ':param' -> '{param}'. axum 0.8 panics at router build on any segment starting with ':' (validate_v07_paths). Migrated all :param routes in serve.rs, watch_bridge.rs, a2a_http.rs, and vibe-indexer/main.rs (route registrations + adjacent doc comments). REST doc-labels in commands.rs/app_builder.rs left as ':id' (not axum routes). 2. WebSocket Message types: Text(String)->Text(Utf8Bytes), Binary(Vec<u8>)->Binary(Bytes). Added .into() at the 8 collab-WS send/receive sites in serve.rs. tower-http 0.7 (CorsLayer/SetResponseHeaderLayer/Any) API unchanged. Verified: cargo check --workspace clean; a2a_http_bdd (3 scenarios, 12 steps) + serve_integration pass. --------- --------- * chore(deps-dev): bump typescript from 6.0.3 to 7.0.2 in /vibeui Bumps [typescript](https://github.com/microsoft/TypeScript) from 6.0.3 to 7.0.2. - [Release notes](https://github.com/microsoft/TypeScript/releases) - [Commits](https://github.com/microsoft/TypeScript/commits) --- updated-dependencies: - dependency-name: typescript dependency-version: 7.0.2 dependency-type: direct:development update-type: version-update:semver-major ... * chore(deps): bump org.jetbrains.kotlin.android in /vibemobile/android Bumps [org.jetbrains.kotlin.android](https://github.com/JetBrains/kotlin) from 2.1.0 to 2.4.10. - [Release notes](https://github.com/JetBrains/kotlin/releases) - [Changelog](https://github.com/JetBrains/kotlin/blob/master/ChangeLog.md) - [Commits](https://github.com/JetBrains/kotlin/compare/v2.1.0...v2.4.10) --- updated-dependencies: - dependency-name: org.jetbrains.kotlin.android dependency-version: 2.4.10 dependency-type: direct:production update-type: version-update:semver-minor ... * chore(deps): bump actions/setup-python from 6 to 7 Bumps [actions/setup-python](https://github.com/actions/setup-python) from 6 to 7. - [Release notes](https://github.com/actions/setup-python/releases) - [Commits](https://github.com/actions/setup-python/compare/v6...v7) --- updated-dependencies: - dependency-name: actions/setup-python dependency-version: '7' dependency-type: direct:production update-type: version-update:semver-major ... * chore(deps): bump actions/setup-java from 5.3.0 to 5.7.0 Bumps [actions/setup-java](https://github.com/actions/setup-java) from 5.3.0 to 5.7.0. - [Release notes](https://github.com/actions/setup-java/releases) - [Commits](https://github.com/actions/setup-java/compare/ad2b38190b15e4d6bdf0c97fb4fca8412226d287...b6effb05e454b25005698d916606bdc6ffcbf961) --- updated-dependencies: - dependency-name: actions/setup-java dependency-version: 5.7.0 dependency-type: direct:production update-type: version-update:semver-minor ... * chore(deps): bump actions/setup-node from 6.4.0 to 7.0.0 Bumps [actions/setup-node](https://github.com/actions/setup-node) from 6.4.0 to 7.0.0. - [Release notes](https://github.com/actions/setup-node/releases) - [Commits](https://github.com/actions/setup-node/compare/48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e...820762786026740c76f36085b0efc47a31fe5020) --- updated-dependencies: - dependency-name: actions/setup-node dependency-version: 7.0.0 dependency-type: direct:production update-type: version-update:semver-major ... * chore(deps-dev): bump jsdom from 29.1.1 to 30.0.1 in /vibecoder Bumps [jsdom](https://github.com/jsdom/jsdom) from 29.1.1 to 30.0.1. - [Release notes](https://github.com/jsdom/jsdom/releases) - [Commits](https://github.com/jsdom/jsdom/compare/v29.1.1...v30.0.1) --- updated-dependencies: - dependency-name: jsdom dependency-version: 30.0.1 dependency-type: direct:development update-type: version-update:semver-major ... * chore(deps): bump EmbarkStudios/cargo-deny-action from 2.0.20 to 2.1.1 Bumps [EmbarkStudios/cargo-deny-action](https://github.com/embarkstudios/cargo-deny-action) from 2.0.20 to 2.1.1. - [Release notes](https://github.com/embarkstudios/cargo-deny-action/releases) - [Commits](https://github.com/embarkstudios/cargo-deny-action/compare/bb137d7af7e4fb67e5f82a49c4fce4fad40782fe...3c6349835b2b7b196a839186cb8b78e02f7b5f25) --- updated-dependencies: - dependency-name: EmbarkStudios/cargo-deny-action dependency-version: 2.1.1 dependency-type: direct:production update-type: version-update:semver-minor ... * chore(deps): bump tree-sitter from 0.25.10 to 0.26.11 Bumps [tree-sitter](https://github.com/tree-sitter/tree-sitter) from 0.25.10 to 0.26.11. - [Release notes](https://github.com/tree-sitter/tree-sitter/releases) - [Commits](https://github.com/tree-sitter/tree-sitter/compare/v0.25.10...v0.26.11) --- updated-dependencies: - dependency-name: tree-sitter dependency-version: 0.26.11 dependency-type: direct:production update-type: version-update:semver-minor ... * chore(deps): bump sysinfo from 0.36.1 to 0.39.6 Bumps [sysinfo](https://github.com/GuillaumeGomez/sysinfo) from 0.36.1 to 0.39.6. - [Changelog](https://github.com/GuillaumeGomez/sysinfo/blob/main/CHANGELOG.md) - [Commits](https://github.com/GuillaumeGomez/sysinfo/compare/v0.36.1...v0.39.6) --- updated-dependencies: - dependency-name: sysinfo dependency-version: 0.39.6 dependency-type: direct:production update-type: version-update:semver-minor ... * chore(deps): bump tokio-tungstenite from 0.28.0 to 0.29.0 Bumps [tokio-tungstenite](https://github.com/snapview/tokio-tungstenite) from 0.28.0 to 0.29.0. - [Changelog](https://github.com/snapview/tokio-tungstenite/blob/master/CHANGELOG.md) - [Commits](https://github.com/snapview/tokio-tungstenite/compare/v0.28.0...v0.29.0) --- updated-dependencies: - dependency-name: tokio-tungstenite dependency-version: 0.29.0 dependency-type: direct:production update-type: version-update:semver-minor ... * chore(deps): bump rustyline from 14.0.0 to 17.0.2 Bumps [rustyline](https://github.com/kkawakam/rustyline) from 14.0.0 to 17.0.2. - [Release notes](https://github.com/kkawakam/rustyline/releases) - [Changelog](https://github.com/kkawakam/rustyline/blob/master/History.md) - [Commits](https://github.com/kkawakam/rustyline/compare/v14.0.0...v17.0.2) --- updated-dependencies: - dependency-name: rustyline dependency-version: 17.0.2 dependency-type: direct:production update-type: version-update:semver-major ... * chore(deps-dev): bump typescript from 6.0.3 to 7.0.2 in /vibecoder Bumps [typescript](https://github.com/microsoft/TypeScript) from 6.0.3 to 7.0.2. - [Release notes](https://github.com/microsoft/TypeScript/releases) - [Commits](https://github.com/microsoft/TypeScript/commits) --- updated-dependencies: - dependency-name: typescript dependency-version: 7.0.2 dependency-type: direct:development update-type: version-update:semver-major ... * chore(deps): bump chacha20poly1305 from 0.10.1 to 0.11.0 Bumps [chacha20poly1305](https://github.com/RustCrypto/AEADs) from 0.10.1 to 0.11.0. - [Commits](https://github.com/RustCrypto/AEADs/compare/chacha20poly1305-v0.10.1...chacha20poly1305-v0.11.0) --- updated-dependencies: - dependency-name: chacha20poly1305 dependency-version: 0.11.0 dependency-type: direct:production update-type: version-update:semver-minor ... * chore(deps): bump gradle-wrapper in /vibewatch/VibeCodyWear Bumps [gradle-wrapper](https://github.com/gradle/gradle) from 9.6.1 to 9.7.0. - [Release notes](https://github.com/gradle/gradle/releases) - [Commits](https://github.com/gradle/gradle/compare/v9.6.1...v9.7.0) --- updated-dependencies: - dependency-name: gradle-wrapper dependency-version: 9.7.0 dependency-type: direct:production update-type: version-update:semver-minor ... * chore(deps): bump flutter_secure_storage in /vibemobile Bumps [flutter_secure_storage](https://github.com/mogol/flutter_secure_storage) from 10.3.1 to 11.0.0. - [Release notes](https://github.com/mogol/flutter_secure_storage/releases) - [Commits](https://github.com/mogol/flutter_secure_storage/compare/v10.3.1...flutter_secure_storage-v11.0.0) --- updated-dependencies: - dependency-name: flutter_secure_storage dependency-version: 11.0.0 dependency-type: direct:production update-type: version-update:semver-major ... * chore(deps): bump the vibecoder-minor group across 1 directory with 5 updates Bumps the vibecoder-minor group with 5 updates in the /vibecoder directory: | Package | From | To | | --- | --- | --- | | [lucide-react](https://github.com/lucide-icons/lucide/tree/HEAD/packages/lucide-react) | `1.28.0` | `1.29.0` | | [y-websocket](https://github.com/yjs/y-websocket) | `3.0.0` | `3.1.0` | | [yjs](https://github.com/yjs/yjs) | `13.6.31` | `13.6.32` | | [monaco-editor](https://github.com/microsoft/monaco-editor) | `0.55.1` | `0.56.0` | | [vite](https://github.com/vitejs/vite/tree/HEAD/packages/vite) | `8.2.0` | `8.2.1` | Updates `lucide-react` from 1.28.0 to 1.29.0 - [Release notes](https://github.com/lucide-icons/lucide/releases) - [Commits](https://github.com/lucide-icons/lucide/commits/1.29.0/packages/lucide-react) Updates `y-websocket` from 3.0.0 to 3.1.0 - [Release notes](https://github.com/yjs/y-websocket/releases) - [Commits](https://github.com/yjs/y-websocket/compare/v3.0.0...v3.1.0) Updates `yjs` from 13.6.31 to 13.6.32 - [Release notes](https://github.com/yjs/yjs/releases) - [Commits](https://github.com/yjs/yjs/compare/v13.6.31...v13.6.32) Updates `monaco-editor` from 0.55.1 to 0.56.0 - [Release notes](https://github.com/microsoft/monaco-editor/releases) - [Changelog](https://github.com/microsoft/monaco-editor/blob/main/CHANGELOG.md) - [Commits](https://github.com/microsoft/monaco-editor/compare/v0.55.1...v0.56.0) Updates `vite` from 8.2.0 to 8.2.1 - [Release notes](https://github.com/vitejs/vite/releases) - [Changelog](https://github.com/vitejs/vite/blob/main/packages/vite/CHANGELOG.md) - [Commits](https://github.com/vitejs/vite/commits/v8.2.1/packages/vite) --- updated-dependencies: - dependency-name: lucide-react dependency-version: 1.29.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: vibecoder-minor - dependency-name: y-websocket dependency-version: 3.1.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: vibecoder-minor - dependency-name: yjs dependency-version: 13.6.32 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: vibecoder-minor - dependency-name: monaco-editor dependency-version: 0.56.0 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: vibecoder-minor - dependency-name: vite dependency-version: 8.2.1 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: vibecoder-minor ... * chore(deps): bump gradle-wrapper in /jetbrains-plugin Bumps [gradle-wrapper](https://github.com/gradle/gradle) from 9.6.1 to 9.7.0. - [Release notes](https://github.com/gradle/gradle/releases) - [Commits](https://github.com/gradle/gradle/compare/v9.6.1...v9.7.0) --- updated-dependencies: - dependency-name: gradle-wrapper dependency-version: 9.7.0 dependency-type: direct:production update-type: version-update:semver-minor ... * chore(deps): bump gradle-wrapper in /vibemobile/android Bumps [gradle-wrapper](https://github.com/gradle/gradle) from 9.6.1 to 9.7.0. - [Release notes](https://github.com/gradle/gradle/releases) - [Commits](https://github.com/gradle/gradle/compare/v9.6.1...v9.7.0) --- updated-dependencies: - dependency-name: gradle-wrapper dependency-version: 9.7.0 dependency-type: direct:production update-type: version-update:semver-minor ... * chore(deps-dev): bump vite in /vibeaichat in the vibeaichat-minor group Bumps the vibeaichat-minor group in /vibeaichat with 1 update: [vite](https://github.com/vitejs/vite/tree/HEAD/packages/vite). Updates `vite` from 8.2.0 to 8.2.1 - [Release notes](https://github.com/vitejs/vite/releases) - [Changelog](https://github.com/vitejs/vite/blob/main/packages/vite/CHANGELOG.md) - [Commits](https://github.com/vitejs/vite/commits/v8.2.1/packages/vite) --- updated-dependencies: - dependency-name: vite dependency-version: 8.2.1 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: vibeaichat-minor ... * chore(deps): bump the vibedesk-minor group across 1 directory with 2 updates Bumps the vibedesk-minor group with 2 updates in the /vibedesk directory: [lucide-react](https://github.com/lucide-icons/lucide/tree/HEAD/packages/lucide-react) and [@tauri-apps/cli](https://github.com/tauri-apps/tauri). Updates `lucide-react` from 1.28.0 to 1.29.0 - [Release notes](https://github.com/lucide-icons/lucide/releases) - [Commits](https://github.com/lucide-icons/lucide/commits/1.29.0/packages/lucide-react) Updates `@tauri-apps/cli` from 2.11.2 to 2.11.4 - [Release notes](https://github.com/tauri-apps/tauri/releases) - [Commits](https://github.com/tauri-apps/tauri/compare/@tauri-apps/cli-v2.11.2...@tauri-apps/cli-v2.11.4) --- updated-dependencies: - dependency-name: "@tauri-apps/cli" dependency-version: 2.11.4 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: vibedesk-minor - dependency-name: lucide-react dependency-version: 1.29.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: vibedesk-minor ... * fix(release): `shell: bash` — the conditional export block broke Windows My previous commit replaced the single-line `run: npx tauri build` with a multi-line POSIX-shell block that exports the Apple variables conditionally. Windows runners default to PowerShell, so all three Windows bundles failed with ParserError: D:\a\_temp\<id>.ps1:2 before tauri ever started. They had been green. GitHub provides bash on Windows runners, and the rest of the workflow already uses `shell: bash` for its cross-platform steps (see "Collect artifacts"), so this matches the existing convention rather than introducing one. * Use ring for RS256 JWT signing; add tests Replace rsa crate usage with ring for RS256 JWT signing in vibe-broker to avoid a timing side-channel advisory. Add pkcs8 PEM→DER helper, comprehensive unit tests that verify JWT structure and signature verification, and a test PEM fixture. Also trim syntect default features (dropping yaml-rust) and update Cargo.toml/Cargo.lock to reflect dependency changes. * build(deps): bump similar from 2.7.0 to 3.1.2 Bumps [similar](https://github.com/mitsuhiko/similar) from 2.7.0 to 3.1.2. - [Changelog](https://github.com/mitsuhiko/similar/blob/main/CHANGELOG.md) - [Commits](https://github.com/mitsuhiko/similar/compare/2.7.0...3.1.2) --- updated-dependencies: - dependency-name: similar dependency-version: 3.1.2 dependency-type: direct:production update-type: version-update:semver-major ... * build(deps-dev): bump typescript from 5.9.3 to 7.0.2 in /vibeaichat Bumps [typescript](https://github.com/microsoft/TypeScript) from 5.9.3 to 7.0.2. - [Release notes](https://github.com/microsoft/TypeScript/releases) - [Commits](https://github.com/microsoft/TypeScript/commits) --- updated-dependencies: - dependency-name: typescript dependency-version: 7.0.2 dependency-type: direct:development update-type: version-update:semver-major ... * ci(release): make Apple signing verifiable, and stop shipping ad-hoc bundles v0.5.7 and v0.5.8 both went green, uploaded artifacts, and were killed by macOS on every user's machine: the signing step fell back to ad-hoc, and nothing downstream checked. build-cli had guarded against that since it was written; the three Tauri app bundles and the iOS .ipa had not. - Verify, don't trust. Each macOS bundle job (VibeCoder, VibeAIChat, VibeDesk) and the iOS packaging step now run `codesign --verify --deep --strict` and fail the job when the result is `Signature=adhoc` despite a certificate having been imported. Ad-hoc remains the intended outcome when no certificate is configured — the check only runs when one was. - Notarize the CLI binary. A Developer ID signature alone is not enough for a quarantined download; the ticket lives on Apple's servers for a bare Mach-O (stapling only works for .app/.dmg/.pkg), and `notarytool --wait` returns 0 only on Accepted. Skipped with a notice when credentials are absent. - APPLE_KEYCHAIN_PASSWORD is no longer required. The keychain is created, used and discarded inside the job, so a generated password protects the same nothing — and removes the silent failure where an empty one makes `security` behave differently than intended. - Signed iOS builds. Gated on all three of APPLE_TEAM_ID / APPLE_DIST_CERT_P12_BASE64 / APPLE_IOS_PROFILE_BASE64; the unsigned sideloadable .ipa still ships when they are absent. - watchOS gate checks every secret it needs, not just APPLE_TEAM_ID, which is shared with the desktop jobs — configuring desktop signing used to arm this job and then kill it on an empty provisioning profile. Its `if:` also referenced its own step output, so it always evaluated true. TestFlight upload is now gated separately from producing a signed IPA. - The ad-hoc notices say what actually happens (macOS kills the app; `xattr -dr com.apple.quarantine`) instead of "unidentified developer, right-click → Open", which does not reliably fix it. - scripts/setup-apple-signing.sh configures all of the above secrets from a Mac that holds the certificate. It pairs certificate and private key by public modulus — PEM export order is not guaranteed, and pairing by position yields a .p12 that imports cleanly and then cannot sign. - .cargo/audit.toml collects the RUSTSEC suppression list that had been copied into three places and drifted, which is how v0.5.8's release failed on an advisory only one copy carried. * fix(skills): every installed build shipped an empty skill catalogue `list_skills` / `get_skill`, `GET /v1/skilllens/skills` and the SkillForge panel returned zero skills on every release binary while working fine in-tree — which read as a regression rather than what it was: the ~710 `skills/*.md` files were never packaged. The resolver's primary path was `${CARGO_MANIFEST_DIR}/skills`, baked in at compile time, so an installed `vibecli` looked for a GitHub Actions path (`/Users/runner/work/...`). The documented next fallback, `<exe>/../share/vibecli/skills`, was a convention nothing implemented: release.yml tars the bare executable, so no sibling `share/` tree ever travels with it. - The catalogue is compiled into the binary (`include_dir!`) — the only fallback that survives how the binary is actually distributed, a single file copied anywhere. It is extracted once to `~/.vibecli/bundled-skills/<version>/` and loaded from there, so `skill.path` still names a file that exists and the scoring / body-render paths that re-read it are unchanged. Extraction is version-scoped, guarded by a completeness marker so an interrupted run re-extracts rather than caching a partial tree, and prunes older versions. Deliberately not `~/.vibecli/skills`, which is the promoted-override dir. - One resolver, not two. `mcp_server` and `skillforge_index` each carried a copy of the fallback chain; both now call `skills_embedded::resolve_skills_dir()`. `VIBECLI_SKILLS_DIR` still wins and is used verbatim — an override that silently fell through to the embedded copy would hide an operator's typo. - `vibecli doctor` reports the catalogue it actually loads. The old check looked at `~/.vibecli/skills` — the override dir, not the catalogue — so it printed a benign "no directory" line throughout. It now prints the resolved path, the skill count and which rule chose it, and fails the line when the count is zero. * feat(bugbot): committable fixes, full-diff coverage, and a real --bugbot flag BugBot reviewed the first 8 000 characters of a diff, said nothing about the rest, and ended its review with prose. Every competing PR-review bot ends with a fix a reviewer applies in one click. Added - Committable suggestions (`bugbot_autofix.rs`, docs/bugbot.md). Findings can now carry GitHub ```suggestion blocks. Anchors come from the diff, never from the model: GitHub applies a suggestion by replacing the exact lines the comment is anchored to, so an off-by-one anchor silently destroys code. A `PostImage` index maps path → new-line → text from the diff's own context and added lines, and a proposal that cannot be located there is refused, not guessed. Seven typed refusals (AnchorMissing, SpanTooLarge, EmptyReplacement, Unchanged, FenceInReplacement, ModelDeclined, Unparseable) are printed with the finding rather than swallowed. `AnchorVerified` means the target lines were found and the replacement is non-empty and different — nothing more, and every posted comment says the fix has not been compiled or tested, because it hasn't. - Full-diff coverage (`ReviewPlan` / `ReviewCoverage`). The diff is split per file, packed into batches that each fit the request budget, and every batch is reviewed — a small diff still costs one call, a 64 KB one up to eight. What was read is reported ("Reviewed 12/12 file(s) in 3 model call(s)"), and when it wasn't everything, the skipped and truncated files are named on stderr, appended to the commit-status description, and returned as a `coverage` object on the webhook response. - `--passes N` trades cost for recall: each batch is reviewed N times with the file order rotated, because a defect in the last file of a prompt is likelier to be missed than one in the first. Rotation is deterministic, so two runs over the same diff issue the same requests — something a randomised ordering could not promise in CI. Findings are deduplicated by location plus a normalised message, keeping the highest severity seen. - `--bugbot` exists. `bugbot.rs` had advertised `vibecli --bugbot --diff` / `--pr 123` in its module docs since it was written; no such flag existed and the only caller was the GitHub webhook. `--bugbot` reviews uncommitted changes, `--staged` the index, `--pr N` a pull request, and it exits 1 on any error-severity finding so it drops into a pre-push hook or CI step. `--propose-fixes` adds suggestions, `--apply-fixes` writes them (skipping any file that moved since the diff, printing both counts). `--pr` refuses a non-GitHub remote instead of guessing a slug that would review an unrelated repository. Fixed - `POST /webhook/github` failed open when no webhook secret was set. Signature verification ran only `if let Some(secret) = …`; with none configured, every unsigned POST was acted on. The route is public by design, and a review is not a read — it spends model budget and calls the GitHub API with the operator's token against whatever repository the payload names. Unsigned webhooks are now rejected, and the error names the command that fixes it. - The GitHub App webhook secret could not be stored encrypted. `resolve_webhook_secret` reads the ProfileStore key `github_app_webhook_secret` first, per Zero-Config First — but `set-key` validated the name against a list that omitted it and answered "unknown provider", leaving only a plaintext config.toml field and an environment variable, both of which the same rule forbids for a secret. - `[github_app] auto_fix` was a dead flag: documented, serialised, defaulted, covered by three tests, and read by no production path. It now drives the suggestion pass, and its documentation says what it actually does — it attaches committable suggestions and never pushes a commit. The webhook response gained an honest `fixes_proposed` count, which excludes findings the fixer declined. * feat(daemon): wire two modules that had been counted as shipped `mcp_well_known` and the workspace half of `trust_resolution` were both written, tested, marked `#![allow(dead_code)]`, and left without a caller — present in the tree and counted as closed on the roadmap. Neither did anything. - `GET /.well-known/mcp.json` (A3) is served from the public rate-limited router. Hosts read a `.well-known` document before they hold a token, and the descriptor carries tool names and descriptions only — the same class of metadata `/models` already serves unauthenticated. `mcp_server::tool_defs()` stays the single source of truth; the route only reshapes it, and a test pins the tool count to it so the descriptor cannot drift from `tools/list`. - Workspace trust (E4) gets both an enforcement point and a way to set it, because either alone is just another unreachable module. `/trustdir allow|deny|reset` writes `~/.vibecli/trust.json`; `serve::workspace_denied` reads it in `start_agent`, after `resolve_run_root`, so the run path is gated once instead of per-handler. Deny-only, deliberately: the resolver's `default_policy` is `RequireApproval`, so honouring the full policy would make every existing workspace start prompting the moment this shipped — a Zero-Config First break for a store no user has yet. Only an explicit entry in `denied_paths` (or a parent of one) blocks a run; a missing, unreadable, or malformed store denies nothing. The tests pin that negative property first. It is `/trustdir`, not `/trust`: `/trust` is taken and scores *agents*, while this governs *directories*. * fix(bugbot): a failed model call is not coverage `review_once` returned `Vec<BugReport>` and mapped a provider error to an empty vec, so a review that never happened was indistinguishable from one that found nothing. With the provider down, unconfigured, or rate limited, `--bugbot` printed "0 findings, 1/1 file(s) reviewed" — a clean bill of health nobody gave, on the struct written to stop exactly that. - `review_once` returns `Option<Vec<BugReport>>`: `None` is "the provider failed", `Some(vec![])` is "the model looked and found nothing". - `ReviewCoverage` gains `llm_calls_failed` and `files_provider_failed`, and `files_reviewed` counts only files whose batch completed a pass. `is_complete()` and `caveat()` account for them, so the caveat reaches the PR body and commit status as well as the terminal. - The terminal message distinguishes the two remedies: a call-budget skip says review a smaller change, a provider failure says check `--doctor`. Advising "try --staged" for an outage was wrong advice. - Tests cover a failing provider end to end: the file is reported unreviewed, the deterministic static scan still runs (and still reports the hardcoded key), and an empty diff still costs no model calls. * feat(skills): import 433 Jobs-To-Be-Done skills — catalogue goes 710 → 1,143 A national-operating-system skill library, converted from Anthropic Agent-Skills format (a directory per skill, `SKILL.md` + frontmatter) into VibeCody's flat catalogue: 24 sector operating systems with their 204 AI-personnel role skills and 27 autonomous-machine skills, 26 industry overlays, 15 cross-cutting role archetypes, 12 strategic missions, 8 subsector packs, 108 catalogue skills, and 2 routers. Categories reuse the existing vocabulary where one fits (energy, healthcare, defense, finance, logistics, robotics) and add a domain slug where none did. - Every relative cross-reference was rewritten, because a flat catalogue has no `../..`. The source tree navigates by path — 302 references to `../../../00-framework/SKILL.md`, 266 to a role's own `../../SKILL.md`, plus directory pointers. Left alone they would send an agent to files that do not exist. Each now names the flat skill or the name glob the directory became. The import refuses to write while any path-shaped reference remains unresolved; it reports zero. - The 52 `references/*.md` companions are inlined, not dropped: they carry the controls, exception tables, and subsector maps the overlays point at. A flat catalogue can hold neither the directory nor the pointer, so each is appended as a `## Reference — <title>` section with headings demoted, and every pointer repointed at that section. - Triggers are derived, never invented — from the title, the bold spans the description uses to name its subject, the domain, and the explicit "trigger this skill when…" sentence the source carries. Triggers are the main signal in `skill_matches_query`, so no skill ships with none. - Pointers to files outside the skill tree (a vault note, a routing matrix, `examples/*.py`) were already dangling at the source and are reworded rather than shipped as dead ends. Also: `build.rs` now emits `cargo:rerun-if-changed=skills`. `include_dir!` tracks the contents of the files it expanded to, not the directory listing — and the existing `rerun-if-env-changed` lines had already disabled cargo's default whole-package rescan, so adding or deleting a skill would have shipped a stale embedded catalogue with nothing to notice. * ci(security): finish the audit.toml migration — one suppression list, enforced .cargo/audit.toml landed in fe9a7e97 claiming to be the single source of truth, but both workflows still passed their own 29-flag `--ignore` lists and deny.toml carried a third copy — the drift the file was written to end was untouched. - Both workflows now run a bare `cargo audit --deny warnings`. cargo-audit reads .cargo/audit.toml from the repo root automatically. Verified empirically: with the file present the audit exits 0, with it moved aside 23 advisories fire and it exits 1, so the file is load-bearing rather than merely present. - deny.toml is named authoritative — cargo-deny cannot read audit.toml and its schema is the only one carrying a reason and review-by per entry. The ids are mirrored, and a new `Suppression lists agree` step in security.yml diffs the two sets and fails on any difference. That is what makes "they cannot disagree" true instead of aspirational; the step also fails when either extraction comes back empty, so a reflowed array cannot silently check nothing. - The lists were reconciled, not assumed equal. audit.toml was missing three ids every other copy had — RUSTSEC-2023-0071 (rsa Marvin timing sidechannel), RUSTSEC-2024-0320 (yaml-rust), RUSTSEC-2025-0134 (rustls-pemfile). rustls-pemfile fires against the current lockfile, so landing the migration without it would have turned the release audit red. - RUSTSEC-2026-0222 is dropped. audit.toml claimed it was "present in security.yml's list"; it appears there only in a comment describing the quinn-proto advisory that a regenerated lockfile once hid. quinn-proto is 0.11.15 in the lock — past the affected 0.11.14 — so suppressing it would have re-hidden a real vulnerability if it ever came back. - RUSTSEC-2026-0002 and RUSTSEC-2026-0215 were each listed twice; deduped. Two suppressions are now inert: `rsa` and `yaml-rust` are no longer in Cargo.lock at all. They are carried with a note rather than dropped, because removing a suppression in the same change that consolidates the lists is a policy change wearing a refactor's clothes. Next triage should delete them. * docs(bugbot): document that a failed model call is not coverage The behaviour landed in c7a1c614; this is its documentation. Records the distinction the code makes — `Some(vec![])` versus `None`, `llm_calls` versus `llm_calls_failed` — the two terminal outputs a reader will actually see, and the two new `coverage` fields on the webhook response. * ci(release): audit and attest the lockfile the release actually builds Both Rust jobs ran `cargo generate-lockfile` first, under a step named "Generate Cargo.lock (gitignored)". Cargo.lock is committed and has never been gitignored, and regenerating it re-resolves every dependency to the newest semver-compatible release — so both jobs described a dependency set that existed only on the runner. security.yml already documents where that leads: quinn-proto 0.11.14 (RUSTSEC-2026-0222 et al.) sat in the committed lock behind a green audit, which is why that workflow stopped regenerating. The release gate — the stricter of the two, and the one that decides whether a tag ships — had kept doing it, making the audit that mattered more the one that meant less. - The audit job verifies the lockfile instead of replacing it: `cargo metadata --locked` fails if the committed lock cannot satisfy Cargo.toml, so a stale lock stops the release rather than being silently papered over. - The SBOM job gets the same treatment, where the consequence is worse. An SBOM is an attestation of what a release contains, published so auditors can cross-reference it against future advisories. Generated from a regenerated lock it would clear — or blame — versions no artifact ever contained. - `cargo build` gains `--locked`, closing the loop: the audit verifies the committed lock and the build now refuses anything else. Without it cargo silently updates the lock when it cannot satisfy the manifest, and the shipped binary drifts from the set that was audited and published. Verified locally: `cargo metadata --locked` and `cargo tree --locked -p vibecli` both succeed against the committed lock, so none of the three changes turns the current release red. Both workflow files still parse. Not touched: ci.yml also runs `cargo generate-lockfile` before fmt / clippy / test. Same class of problem — it checks versions the repo never pins — but it gates a PR rather than a release artifact, and the three Tauri bundle jobs build through `npm run tauri build`, where `--locked` is not a flag this workflow controls. * test(skills): assert reachability, not catalogue size `embedded_skill_count() > 1000` recorded what the catalogue happened to hold the day it was written. It goes stale on the next import, and — worse — it passes while a third of the tree is missing. How many skills ship is a product decision; what has to hold is that each one can be reached from the context it belongs to. - `embedded_tree_is_not_empty` — zero is the bug, and there is no bound above it. Same for categories: `categories().len() > 5` becomes non-empty, since how many categories the catalogue uses is also a product decision. - `every_embedded_skill_is_retrievable_by_its_own_name_and_triggers` — the property that replaces the number. A skill must come back from a `list()` query for its own name and for each trigger it declares, checked on a fixed stride (the full cross product is quadratic over every skill body). Writing it surfaced a gap the count never would have: 157 of the 1,143 skills carry no YAML frontmatter at all, so they parse to `SkillFrontmatter::default()` — no triggers, no category. All 157 predate the Jobs-To-Be-Done import; every one of its 433 skills declares both. They are not unreachable — `skill_matches_query` also substring-matches the body — but they are reachable only by accident: they never match a category filter, and they surface for a free-text query only when the words happen to appear somewhere in their prose. `every_embedded_skill_declares_triggers_and_a_category` states that invariant and is `#[ignore]`d with the reason, so the gap is recorded in the suite rather than in a comment nobody runs. Verified: 7 passed, 1 ignored. * perf(skills): cache the built-in catalogue instead of re-reading it per call `list_skills` and `get_skill` each called `SkillCatalog::load_from_with_cwd_plugins` per MCP invocation: 1,143 file reads, ~990 YAML parses, and a `WorkspaceStore::open` — which *creates* the encrypted database, in whatever directory the MCP host happened to launch in — to answer one question. An agent calling `list_skills` three times in a turn paid all of it three times. - `load_with_cwd_plugins_cached` shares one `Arc<SkillCatalog>` per directory. - Revalidated by fingerprint, not by a timer, so authoring a skill in-tree still takes effect without a restart: file count, combined size, and newest mtime across the directory — ~7 ms over 1,143 files against ~60 ms+ to re-read and re-parse. The directory's own mtime would be a single `stat`, but it does not move when a file's contents change, which is exactly how skills are edited. - The plugin overlay is deliberately not cached — a handful of files whose enablement can change at any time, recomposed per call while the expensive built-in load is shared. With no plugin skills the shared catalogue is returned as-is, with no copy of its ~5.8 MB of bodies. - The `WorkspaceStore` open is gated on `<cwd>/.vibecli/workspace.db` already existing, so the skills path stops creating stray workspace databases in scratch directories. Verified: 27 passed, 1 ignored (the known frontmatter gap). The five new tests cover allocation reuse, invalidation on a changed body and on an added file, per-directory keying, and a missing directory reporting an error rather than an empty catalogue. * build(deps): bump actions/checkout from 7.0.0 to 7.0.1 Bumps [actions/checkout](https://github.com/actions/checkout) from 7.0.0 to 7.0.1. - [Release notes](https://github.com/actions/checkout/releases) - [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md) - [Commits](https://github.com/actions/checkout/compare/9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0...3d3c42e5aac5ba805825da76410c181273ba90b1) --- updated-dependencies: - dependency-name: actions/checkout dependency-version: 7.0.1 dependency-type: direct:production update-type: version-update:semver-patch ... * build(deps): bump hmac from 0.12.1 to 0.13.0 Bumps [hmac](https://github.com/RustCrypto/MACs) from 0.12.1 to 0.13.0. - [Commits](https://github.com/RustCrypto/MACs/compare/hmac-v0.12.1...hmac-v0.13.0) --- updated-dependencies: - dependency-name: hmac dependency-version: 0.13.0 dependency-type: direct:production update-type: version-update:semver-minor ... * build(deps): bump p256 from 0.13.2 to 0.14.0 Bumps [p256](https://github.com/RustCrypto/elliptic-curves) from 0.13.2 to 0.14.0. - [Commits](https://github.com/RustCrypto/elliptic-curves/compare/p256/v0.13.2...p256/v0.14.0) --- updated-dependencies: - dependency-name: p256 dependency-version: 0.14.0 dependency-type: direct:production update-type: version-update:semver-minor ... * build(deps): bump base64 from 0.22.1 to 0.23.1 Bumps [base64](https://github.com/marshallpierce/rust-base64) from 0.22.1 to 0.23.1. - [Changelog](https://github.com/marshallpierce/rust-base64/blob/master/RELEASE-NOTES.md) - [Commits](https://github.com/marshallpierce/rust-base64/compare/v0.22.1...v0.23.1) --- updated-dependencies: - dependency-name: base64 dependency-version: 0.23.1 dependency-type: direct:production update-type: version-update:semver-minor ... * build(deps): bump zip from 2.4.2 to 8.6.0 Bumps [zip](https://github.com/zip-rs/zip2) from 2.4.2 to 8.6.0. - [Release notes](https://github.com/zip-rs/zip2/releases) - [Changelog](https://github.com/zip-rs/zip2/blob/master/CHANGELOG.md) - [Commits](https://github.com/zip-rs/zip2/compare/v2.4.2...v8.6.0) --- updated-dependencies: - dependency-name: zip dependency-version: 8.6.0 dependency-type: direct:production update-type: version-update:semver-major ... * Sync provider lists and add 'poolside' provider Ensure new AI providers are selectable across clients and document the workflow. Updates: - Expand add-provider skill to include 8-file backend dance and client lists so providers are selectable. - Add a catalog test that verifies vscode-extension/package.json offers every catalog provider. - Add "poolside" to VS Code extension manifest and VibeAIChat labels. - Expand JetBrains provider list to mirror catalog and use it in the UI combo box. - Update AGENTS.md, CLAUDE.md, SOUL.md, README.md to reflect VibeDesk and 14 clients and to clarify surfaces to touch (Tauri handlers, tauri.conf.json, version bump, etc.). These changes fix a class of bugs where a provider was supported by the daemon but missing from client manifests, making it unselectable. * Backfill skill frontmatter and wire ACP stdio mode Adds YAML frontmatter (triggers, tools_allowed, category) to all 157 previously-missing skill files, enabling proper skill discovery and categorization. Implements the missing stdio transport for ACP (Agent Client Protocol) by wiring the complete but unreachable dispatcher to the CLI via `--acp` flag, allowing IDEs like Zed, JetBrains, Neovim, and Emacs to launch VibeCLI as an agent subprocess. Includes comprehensive ACP stdio tests and a new catalog validation test for JetBrains provider availability. * build(deps-dev): bump typescript in /vscode-extension Bumps [typescript](https://github.com/microsoft/TypeScript) from 5.9.3 to 7.0.2. - [Release notes](https://github.com/microsoft/TypeScript/releases) - [Commits](https://github.com/microsoft/TypeScript/commits) --- updated-dependencies: - dependency-name: typescript dependency-version: 7.0.2 dependency-type: direct:development update-type: version-update:semver-major ... * Add explicit-trigger inline completion (ghost text) Introduce a new ghost-text completion surface that triggers only on explicit user gestures (⌘. style), replacing the keystroke-driven keystroke-driven path removed in commit 5a7eef7c for patent reasons. Changes: - New vibe_ai::ghost module with request/response types, message building, and sanitization (caps output to 12 lines, handles code fences) - Extract resolve_editing_provider() to route both diffcomplete and ghost text through the toolbar's provider/model selection, fixing a bug where diffcomplete dropped the model entirely - Add model parameter to diffcomplete_generate to pass toolbar selection through - Register ghost_complete Tauri command The ghost module intentionally carries no hidden state, edit history, or automatic triggering — only the visible prefix/suffix window and optional project memory. This keeps the boundary between explicit and automatic requests clear, with the gate living in the editor's inline-completion provider. * fix(deps): TypeScript 7 cannot resolve against typescript-eslint The Dependabot bump to typescript ~7.0.2 left vibecoder with an unresolvable dependency graph: typescript-eslint@8.66.0 peers on typescript >=4.8.4 <6.1.0, and no published typescript-eslint (8.67.0 latest) supports TS 7 yet. The bump merged textually clean, so npm was never invoked and never objected — npm install --package-lock-only fails with ERESOLVE. Restores the version this project was on before the bump (~6.0.3) and regenerates the lockfile from the manifest, so the two agree again. vibeaichat and vibedesk keep TS 7 — neither uses typescript-eslint. * fix(deps): same TypeScript 7 / typescript-eslint clash in vscode-extension typescript-eslint@8.57.2 peers on typescript <6.1.0. Restores ^5.3.0, the version before the Dependabot bump, and re-locks. * Add explicit-trigger ghost text inline completion Introduce an explicit-trigger "ghost text" inline completion feature. Adds /v1/ghost/complete server route and daemon->vibe_ai glue, a new vibecoder lib (ghostText.ts) with unit tests, and registers the provider + Alt+\ keybinding in the App UI (forwards provider+model). Update LSP completion context mapping to translate Monaco trigger kinds to LSP. VS Code extension: add ghostComplete command, inline provider, API client method, settings and keybinding. Gate: only responds to explicit/user trigger (no debounce or keystroke-driven requests); truncated responses are surfaced. * fix(vibeaichat): declare Vite client types so TS 7 accepts CSS imports The Dependabot typescript ^7.0.2 bump is merged here (vibeaichat has no typescript-eslint, so unlike vibecoder and vscode-extension it can take it). TS 7 raises TS2882 on side-effect imports with no declaration, and vibeaichat had no .d.ts at all — four errors on './App.css' and the @vibe/shared stylesheets. Adds the same src/vite-env.d.ts that vibecoder already carries. tsc --noEmit is clean on TypeScript 7.0.2. * Add explicit-trigger ghost text docs & tests Introduce explicit-trigger "ghost text" docs and hook up related tests and fixes. - Add docs/ghost-text.md and expose it in docs/_config.yml sidebar. - Update docs/diffcomplete.md to describe ghost-text as an explicit-trigger alternative and clarify behavior. - Add server-side tests for POST /v1/ghost/complete: unauthenticated 401 and empty-window BAD_REQUEST checks (vibecli/vibecli-cli/src/serve.rs). - Update frontend tests (DiffCompleteModal) to include the model field when sending provider so the backend preserves the host's model choice. - Add LSP mapping tests (toLspCompletionContext) to ensure Monaco trigger kinds map correctly to LSP (avoid emitting LSP's invalid 0). Rationale: document and validate the new short-form inline completion flow (explicit trigger only), and fix/test completion trigger mapping and model forwarding to avoid provider/model misrouting. --------- Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
No description provided.