Welcome AI-assisted contributions while reserving co-author trailers for human credit. Reuse commitlint and Git trailer parsing to reject known assistant identities in new commits without altering existing history or legitimate credits.
* fix(packages): make packed exports runtime-safe
Make checked-in package manifests truthful for ordinary npm and Bun packing, and verify installed artifacts under both runtimes. Centralize package discovery, artifact inspection, and bounded process execution so CI and release publication share the same contracts.
* ci: build package dependencies before checks
Keep workspace jobs independent of ignored dist output now that public package exports consistently resolve built artifacts.
* ci: preserve source-first engine tests
Keep the broader dependency build for package and repository validation, but retain Core-only setup for engine shards so workspace tests continue exercising source modules.
* ci: build engine shard dependencies
Build the seven workspace packages imported by engine tests in dependency order. This preserves a single module instance per package and keeps each clean CI shard independent of ignored dist output.
* ci: restore established package build boundaries
Keep the original repository and engine job setup, and add installed artifact verification only after the existing package build. Avoid changing which module copies unrelated tests execute.
* fix(packages): preserve Bun source identity in tarballs
Retain source-first workspace resolution and ship complete source trees for Bun conditions. Verify clean installed consumers without overlaying archives, reuse consumer validation before release publication, and repair Bun 1.3.10 private source alias resolution.
* refactor(tooling): reuse package and process utilities
Use pkg-types for manifest I/O and types, tinyexec for subprocess lifecycle, and npm's pack listing for release staging. Preserve archive verification and project release invariants rather than reimplementing package-manager file selection.
* refactor(tooling): resolve workspace roots at CLI boundaries
Discover and validate the nearest workspace once, support explicit roots, and pass roots to reusable checks. Replace subprocess entrypoint dispatch with direct calls and preserve aggregate package diagnostics without adding arbitrary test timeout increases.
* fix(release): enforce publication boundaries
Use root version alignment and shared validated npm output parsing. Enforce the public npm registry policy and test verification-before-publication, mismatched artifacts, and partial retries without registry writes.
* refactor(tooling): validate package responses with Valibot
Express npm pack and manifest identity contracts as schemas, infer parsed output types, and preserve contextual failures and relative-path safety. Document Valibot as the first-party validation convention while retaining Zod at SDK boundaries.
* refactor(tooling): validate manifests at input boundaries
Share Valibot schemas for consumed manifest fields, recursive exports, supported workspace declarations, and npm registry responses. Infer domain types and reject malformed metadata instead of silently skipping it downstream.
* refactor(tooling): group package helpers by ownership
Colocate manifest and workspace contracts, separate npm response parsing from generic JSON handling, and split smoke packing, installation, and runtime checks. Remove the release tarball forwarding shim and consolidate its coverage in package-artifacts. Preserve public tooling exports and CLI commands.
* Revert "feat(ai): add HarnessAgent sidecar foundation (#560)"
This reverts commit 83a5ea1b42.
* Revert "Revert "feat(ai): add HarnessAgent sidecar foundation (#560)""
This reverts commit 0d8c03515888c62dc47186d4a3b0b7b04e78f8af.
* refactor(ai): ship Harness as optional companion
* fix(ai): support Harness companion on Windows
* test(ai): restore navigator after Harness Windows test
* ci: parallelize quality and trim shard builds
- Split source, package, repository, and Storybook checks into independent jobs
- Build only Core before quick unit shards instead of all public packages
- Keep full package and dist validation in the dedicated package-quality job
- Disable duplicate Storybook component metadata extraction
* fix(ci): build declarations before source checks
* fix(ci): apply review security and docgen settings
- Pin checkout and disable credential persistence
- Declare read-only workflow permissions
- Explicitly disable Storybook Vue docgen
* ci: clarify check and step names
* fix(ci): cap workflow job runtimes
- Limit the WebView dependency install to three minutes
- Limit native contracts to eight minutes
- Limit all other CI jobs to ten minutes
* ci: retry native contracts on a fresh runner
* ci: move native contracts to Ubuntu 24
- Leave the deprecated Ubuntu 22 hosted image
- Retry WebKit dependency provisioning on the current runner image
* ci: prebuild native contract dependencies
* ci: pin native contracts image digest
* fix(ci): authenticate native image pulls
* fix(ci): include Bun archive tooling
* ci: pin updated native contracts image
* fix(tools): register CI image tooling
- Extract the release body from the changelog section matching the pushed tag.\n- Keep the GitHub Release title identical to the tag.\n- Document signing, updater, publication, deployment, and Homebrew handoff.
- Replace the ambiguous Guide section with explicit overview, reference, and development routes while preserving legacy URLs with redirects
- Route missing localized content to maintained canonical pages and emit SEO alternates only for real translations
- Add parser-backed documentation integrity checks and make the optimized local build the default while retaining a complete production build
- Add a lightweight AI assistance field to the pull request template
- Ask contributors to list materially used models without requiring prompts or automated enforcement
- Introduce Nuxt UI-style Tailwind Variants themes and 26px panel primitives\n- Align section and field action rails across labeled property rows\n- Add Storybook with dark/light states, accessibility tooling, and CI build coverage\n- Standardize UI acronym casing across app and Vue SDK types
- Add a downloaded font cache hook to FontManager
- Store Tauri font downloads under AppLocalData with manifest validation
- Prefer cached downloads before system font lookup on desktop
- Skip opt-in heavy .fig parsing tests in PR CI
Auto-generated release notes from CHANGELOG.md are often wrong.
Create as draft so the changelog section can be reviewed and
pasted manually before publishing.
Fork PRs can't access repo secrets with pull_request trigger.
pull_request_target runs in the base repo context so Cloudflare
secrets are available for all PRs.