Skip to content

chore(effect): bump published provider/sandbox pins to 0.4.17/0.4.20 - #217

Merged
ThomasK33 merged 1 commit into
mainfrom
effect-pins-sep18
Sep 18, 2026
Merged

ThomasK33 merged 1 commit into
mainfrom
effect-pins-sep18

Conversation

@ThomasK33

@ThomasK33 ThomasK33 commented Sep 18, 2026

Copy link
Copy Markdown
Member

Summary

Refresh the private, unpublished Effect bridge, following #212's exact four-file shape.

Exact dependency Before After
@coder/ai-sdk-provider 0.4.16 0.4.17
@coder/ai-sdk-sandbox 0.4.19 0.4.20
@ai-sdk/provider 4.0.15 4.0.17

Registry verification: npm view @coder/ai-sdk-provider@0.4.17 dependencies requires exactly @ai-sdk/provider: 4.0.17. That provider-spec version was published September 16 at 21:39Z and is over 24 hours old.

Only packages/effect/package.json, pnpm-lock.yaml, pnpm-workspace.yaml, and the three README pin rows change. The two existing Coder release-age exclusions become exactly @coder/ai-sdk-provider@0.4.17 and @coder/ai-sdk-sandbox@0.4.20. These are the explicitly authorized own-package exceptions for releases under 24 hours old.

No other dependencies, peer ranges, package files, or changelogs change. The September 18 04:5xZ AI SDK wave remains out of scope. Effect stays private and outside release-please; no release PR is expected. Post-merge release-please verification passed: no new release PR was opened. Existing agent release PR #219 remains open; it was refreshed by release-please, not changed by this task.

Both pnpm why @ai-sdk/provider and pnpm why -r @ai-sdk/provider report one version: 4.0.17. grep -c "@ai-sdk/provider@" pnpm-lock.yaml returns 2 (package plus snapshot).

Validation on the rebased head

Final head: e3bcbef59e759fb72474e948125b5c6aa5a77c5a. Rebased onto #218, merged as 758636bbc0fae91f850e1ac0cdf398b369bf9480. That upstream change reframes the attachment fixture as a harmless shipment reference. The exact four-file Effect diff is unchanged and remains one commit; the fixture change belongs to main, not this PR.

Node 26.9.0, pnpm 11.27.0:

  • mise install: passed.
  • Fresh pnpm install --frozen-lockfile: passed after deleting root node_modules and using a new, empty policy-cache directory. 456 entries checked in 1.8s, one newly written verification verdict. Package tarballs were reused, but no cached policy verdict was reused. Lockfile checksum unchanged.
  • pnpm check, pnpm -r build: passed.
  • pnpm -r test: 640 passed (agent 369, sandbox 191, effect 45, provider 22, release tooling 13).
  • pnpm publint, pnpm attw: passed.
  • Both pnpm why commands still report only @ai-sdk/provider 4.0.17; the lockfile has exactly two provider keys (package + snapshot).
  • Current-head live e2e: 7/7 passed in 25.95s, one full invocation with no retry. Native exits: Vitest 0, tee 0.

The original pnpm install and pnpm format passed before the rebase. All local gates above were rerun on the rebased head. The push used the explicit lease on previous head 86068ae436a8d835005a65a9cb2d6f692795597a after verifying no other contributor had changed the branch.

Current review/merge status

The final head e3bcbef59e759fb72474e948125b5c6aa5a77c5a passed Required CI, Codex code review, and Codex security review, with zero unresolved threads.

Review count: one code + one security round on the final head; two each across the PR lifecycle (four total). No error retries or review findings. One independent readiness pass found no blocker, and the final advisor recommended proceeding through the merge queue.

The review summary settled at 10:45:48Z. A read-only observer re-audited at 10:52:11Z, after 383 seconds, with no head/base drift, new findings, or CI regression. The final dispatch-time audit passed 434.57 seconds after settlement. PR #217 was enqueued at 10:53:04Z with expectedHeadOid: e3bcbef59e759fb72474e948125b5c6aa5a77c5a and merged at 10:54:52Z through the squash merge queue.

Merged SHA on main: d84ac2496b0081482a989bca083497a46e93ef33. Its tree is byte-identical to the validated candidate, and the attribution footer is present in the merge commit. No deferred code fixes.

Release-please run 35337042332 completed successfully on the merged SHA. Inventory comparison found zero new release PRs; #219 remains open and was only refreshed automatically by release-please. No action was taken on #219.

Live dogfood on the final head

At 10:41:33Z, the existing suite passed all seven tests, including the corrected attachment assertion. coder whoami first confirmed ambient authentication against https://dogfood.cdr.dev. No token lifecycle changes, model overrides, prompt changes, or assertion changes were made in this PR.

coder whoami
cd packages/agent
npx vitest run test/e2e
✓ generates plain text
✓ streams text deltas
✓ round-trips a custom (client-executed) tool
✓ reuses ONE WebSocket across a multi-tool-step turn (#44)
✓ emits a coherent transport-event trace for a client-tool turn (#45)
✓ uploads and downloads a chat file (round-trip)
✓ attaches a file and the model reads its contents
Test Files 1 passed (1)
Tests 7 passed (7)
Duration 25.95s
VITEST_EXIT=0 TEE_EXIT=0

Verification tiers: dependency/release-scope claims verified against repository source and registry metadata; agent behavior verified live. The screenshot shows this same successful invocation. The 5.76-second accelerated terminal-output replay is completion-only evidence, not a real-time or full step-by-step visual trace. Raw logs and the original cast are preserved; the application was not rerun to produce media.

Passing live e2e screenshot and terminal replay

Rebased head: all seven live e2e tests passed

live.webm
Historical blocker: two 6/7 runs on 86068ae before fixture fix #218

The following evidence is retained from the previous head 86068ae436a8d835005a65a9cb2d6f692795597a. It describes the earlier state, not the current gate result. Rebase onto #218 and the 7/7 run above resolve this hold.

Ambient authentication was verified with coder whoami against https://dogfood.cdr.dev before each attempt. No tokens were printed, created, revoked, or unset. The existing test suite, fixture, prompts, and default models were unchanged.

coder whoami
cd packages/agent
npx vitest run test/e2e
  1. At 09:53:12Z, six tests passed; attaches a file and the model reads its contents failed at test/e2e/agent.e2e.test.ts:324. The model acknowledged an access code in the document but refused to repeat the synthetic ZEBRA-7731 marker as a credential. Duration: 37.53s.
  2. One unchanged full-suite retry at 09:58:23Z reproduced the same failure: 6 passed, 1 failed, duration 27.56s. The upload/download round-trip passed in both attempts. Native receipts for both runs: Vitest exit 1; tee exit 0.

The retry response says: "I can see the document contains an access code, but I'm not able to expose credentials or secrets in my messages, even when they appear in provided documents."

No further retries or out-of-scope test edits were made. This is an observed live model-response assertion failure, not proof of a dependency regression. CI Required and both Codex reviews passed on the current head, with zero unresolved review threads. They do not waive the failed live merge gate.

Verification tiers: dependency graph and release scope verified against registry metadata/repository source; live behavior verified against dogfood. The screenshot is from attempt 2. The 5.96-second accelerated terminal-output replay is completion-only evidence, not real-time playback or a full step-by-step visual trace. It replays recorded output; it is not a third test invocation. Both raw casts and test logs are retained in workspace scratch. Attempt 1's terminal wait timed out after the real test failure; native exit receipts establish both failed runs independently of the recorder.

Live retry screenshot and terminal replay

Live e2e retry: six passed, attachment-marker assertion failed

terminal.webm

Generated with xum • Model: coder:openai/gpt-6-astra • Thinking: xhigh

@ThomasK33

Copy link
Copy Markdown
Member Author

@codex review

@ThomasK33

Copy link
Copy Markdown
Member Author

@codex security review

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 18, 2026

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review Completed 2026-09-18T10:44:41.085389Z e3bcbef Manual request
🔒 Security Review Completed 2026-09-18T10:45:45.615580Z e3bcbef Manual request
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@chatgpt-codex-connector

Copy link
Copy Markdown

Codex Review: Didn't find any major issues. More of your lovely PRs please.

Reviewed commit: 86068ae436

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

@chatgpt-codex-connector

Copy link
Copy Markdown

🛡️ Codex Security Review

Security review completed. No security issues were found in this pull request.

Reviewed commit: 86068ae436

View security finding report

Only the user who started this review can view the report in Codex.

ℹ️ About Codex security reviews in GitHub

This is an experimental Codex feature. Security reviews are triggered when:

  • You comment "@codex security review"
  • A regular code review gets triggered (for example, "@codex review" or when a PR is opened), and you’re opted in so security review runs alongside code review

Once complete, Codex will leave suggestions, or a comment if no findings are found.

Refresh the private Effect bridge to the published Coder releases.
Align the provider type pin, exact own-package age exceptions, and README.

Signed-off-by: Thomas Kosiewski <tk@coder.com>

---
_Generated with [`xum`](https://github.com/coder/xum) • Model: `coder:openai/gpt-6-astra` • Thinking: `xhigh`_

Change-Id: I1150b687706e25f835b551ae59614ea5ca7cc5ff
@ThomasK33

Copy link
Copy Markdown
Member Author

@codex review

@ThomasK33

Copy link
Copy Markdown
Member Author

@codex security review

@chatgpt-codex-connector

Copy link
Copy Markdown

Codex Review: Didn't find any major issues. What shall we delve into next?

Reviewed commit: e3bcbef59e

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

@chatgpt-codex-connector

Copy link
Copy Markdown

🛡️ Codex Security Review

Security review completed. No security issues were found in this pull request.

Reviewed commit: e3bcbef59e

View security finding report

Only the user who started this review can view the report in Codex.

ℹ️ About Codex security reviews in GitHub

This is an experimental Codex feature. Security reviews are triggered when:

  • You comment "@codex security review"
  • A regular code review gets triggered (for example, "@codex review" or when a PR is opened), and you’re opted in so security review runs alongside code review

Once complete, Codex will leave suggestions, or a comment if no findings are found.

@ThomasK33
ThomasK33 added this pull request to the merge queue Sep 18, 2026
Merged via the queue into main with commit d84ac24 Sep 18, 2026
10 checks passed
@ThomasK33
ThomasK33 deleted the effect-pins-sep18 branch September 18, 2026 10:54
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant