chore(effect): bump published provider/sandbox pins to 0.4.17/0.4.20 - #217
Conversation
|
@codex review |
|
@codex security review |
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
|
Codex Review: Didn't find any major issues. More of your lovely PRs please. Reviewed commit: ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
If Codex has suggestions, it will comment; otherwise it will react with 👍. Codex can also answer questions or update the PR. Try commenting "@codex address that feedback". |
🛡️ Codex Security ReviewSecurity review completed. No security issues were found in this pull request. Reviewed commit: Only the user who started this review can view the report in Codex. ℹ️ About Codex security reviews in GitHubThis is an experimental Codex feature. Security reviews are triggered when:
Once complete, Codex will leave suggestions, or a comment if no findings are found. |
Refresh the private Effect bridge to the published Coder releases. Align the provider type pin, exact own-package age exceptions, and README. Signed-off-by: Thomas Kosiewski <tk@coder.com> --- _Generated with [`xum`](https://github.com/coder/xum) • Model: `coder:openai/gpt-6-astra` • Thinking: `xhigh`_ Change-Id: I1150b687706e25f835b551ae59614ea5ca7cc5ff
86068ae to
e3bcbef
Compare
|
@codex review |
|
@codex security review |
|
Codex Review: Didn't find any major issues. What shall we delve into next? Reviewed commit: ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
If Codex has suggestions, it will comment; otherwise it will react with 👍. Codex can also answer questions or update the PR. Try commenting "@codex address that feedback". |
🛡️ Codex Security ReviewSecurity review completed. No security issues were found in this pull request. Reviewed commit: Only the user who started this review can view the report in Codex. ℹ️ About Codex security reviews in GitHubThis is an experimental Codex feature. Security reviews are triggered when:
Once complete, Codex will leave suggestions, or a comment if no findings are found. |
Summary
Refresh the private, unpublished Effect bridge, following #212's exact four-file shape.
@coder/ai-sdk-provider0.4.160.4.17@coder/ai-sdk-sandbox0.4.190.4.20@ai-sdk/provider4.0.154.0.17Registry verification:
npm view @coder/ai-sdk-provider@0.4.17 dependenciesrequires exactly@ai-sdk/provider: 4.0.17. That provider-spec version was published September 16 at 21:39Z and is over 24 hours old.Only
packages/effect/package.json,pnpm-lock.yaml,pnpm-workspace.yaml, and the three README pin rows change. The two existing Coder release-age exclusions become exactly@coder/ai-sdk-provider@0.4.17and@coder/ai-sdk-sandbox@0.4.20. These are the explicitly authorized own-package exceptions for releases under 24 hours old.No other dependencies, peer ranges, package files, or changelogs change. The September 18 04:5xZ AI SDK wave remains out of scope. Effect stays private and outside release-please; no release PR is expected. Post-merge release-please verification passed: no new release PR was opened. Existing agent release PR #219 remains open; it was refreshed by release-please, not changed by this task.
Both
pnpm why @ai-sdk/providerandpnpm why -r @ai-sdk/providerreport one version: 4.0.17.grep -c "@ai-sdk/provider@" pnpm-lock.yamlreturns 2 (package plus snapshot).Validation on the rebased head
Final head:
e3bcbef59e759fb72474e948125b5c6aa5a77c5a. Rebased onto #218, merged as758636bbc0fae91f850e1ac0cdf398b369bf9480. That upstream change reframes the attachment fixture as a harmless shipment reference. The exact four-file Effect diff is unchanged and remains one commit; the fixture change belongs to main, not this PR.Node 26.9.0, pnpm 11.27.0:
mise install: passed.pnpm install --frozen-lockfile: passed after deleting rootnode_modulesand using a new, empty policy-cache directory. 456 entries checked in 1.8s, one newly written verification verdict. Package tarballs were reused, but no cached policy verdict was reused. Lockfile checksum unchanged.pnpm check,pnpm -r build: passed.pnpm -r test: 640 passed (agent 369, sandbox 191, effect 45, provider 22, release tooling 13).pnpm publint,pnpm attw: passed.pnpm whycommands still report only @ai-sdk/provider 4.0.17; the lockfile has exactly two provider keys (package + snapshot).The original
pnpm installandpnpm formatpassed before the rebase. All local gates above were rerun on the rebased head. The push used the explicit lease on previous head86068ae436a8d835005a65a9cb2d6f692795597aafter verifying no other contributor had changed the branch.Current review/merge status
The final head
e3bcbef59e759fb72474e948125b5c6aa5a77c5apassed Required CI, Codex code review, and Codex security review, with zero unresolved threads.Review count: one code + one security round on the final head; two each across the PR lifecycle (four total). No error retries or review findings. One independent readiness pass found no blocker, and the final advisor recommended proceeding through the merge queue.
The review summary settled at 10:45:48Z. A read-only observer re-audited at 10:52:11Z, after 383 seconds, with no head/base drift, new findings, or CI regression. The final dispatch-time audit passed 434.57 seconds after settlement. PR #217 was enqueued at 10:53:04Z with
expectedHeadOid: e3bcbef59e759fb72474e948125b5c6aa5a77c5aand merged at 10:54:52Z through the squash merge queue.Merged SHA on main:
d84ac2496b0081482a989bca083497a46e93ef33. Its tree is byte-identical to the validated candidate, and the attribution footer is present in the merge commit. No deferred code fixes.Release-please run 35337042332 completed successfully on the merged SHA. Inventory comparison found zero new release PRs; #219 remains open and was only refreshed automatically by release-please. No action was taken on #219.
Live dogfood on the final head
At 10:41:33Z, the existing suite passed all seven tests, including the corrected attachment assertion.
coder whoamifirst confirmed ambient authentication againsthttps://dogfood.cdr.dev. No token lifecycle changes, model overrides, prompt changes, or assertion changes were made in this PR.coder whoami cd packages/agent npx vitest run test/e2eVerification tiers: dependency/release-scope claims verified against repository source and registry metadata; agent behavior verified live. The screenshot shows this same successful invocation. The 5.76-second accelerated terminal-output replay is completion-only evidence, not a real-time or full step-by-step visual trace. Raw logs and the original cast are preserved; the application was not rerun to produce media.
Passing live e2e screenshot and terminal replay
live.webm
Historical blocker: two 6/7 runs on 86068ae before fixture fix #218
The following evidence is retained from the previous head
86068ae436a8d835005a65a9cb2d6f692795597a. It describes the earlier state, not the current gate result. Rebase onto #218 and the 7/7 run above resolve this hold.Ambient authentication was verified with
coder whoamiagainsthttps://dogfood.cdr.devbefore each attempt. No tokens were printed, created, revoked, or unset. The existing test suite, fixture, prompts, and default models were unchanged.coder whoami cd packages/agent npx vitest run test/e2eattaches a file and the model reads its contentsfailed attest/e2e/agent.e2e.test.ts:324. The model acknowledged an access code in the document but refused to repeat the syntheticZEBRA-7731marker as a credential. Duration: 37.53s.The retry response says: "I can see the document contains an access code, but I'm not able to expose credentials or secrets in my messages, even when they appear in provided documents."
No further retries or out-of-scope test edits were made. This is an observed live model-response assertion failure, not proof of a dependency regression. CI
Requiredand both Codex reviews passed on the current head, with zero unresolved review threads. They do not waive the failed live merge gate.Verification tiers: dependency graph and release scope verified against registry metadata/repository source; live behavior verified against dogfood. The screenshot is from attempt 2. The 5.96-second accelerated terminal-output replay is completion-only evidence, not real-time playback or a full step-by-step visual trace. It replays recorded output; it is not a third test invocation. Both raw casts and test logs are retained in workspace scratch. Attempt 1's terminal wait timed out after the real test failure; native exit receipts establish both failed runs independently of the recorder.
Live retry screenshot and terminal replay
terminal.webm
Generated with
xum• Model:coder:openai/gpt-6-astra• Thinking:xhigh