Skip to content

chore(deps): bump the npm_and_yarn group across 1 directory with 3 updates - #12411

Merged
juliusmarminge merged 1 commit into
mainfrom
dependabot/npm_and_yarn/npm_and_yarn-1c23d3fe4e
Sep 18, 2026
Merged

juliusmarminge merged 1 commit into
mainfrom
dependabot/npm_and_yarn/npm_and_yarn-1c23d3fe4e

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 18, 2026

Copy link
Copy Markdown
Contributor

Bumps the npm_and_yarn group with 3 updates in the / directory: astro, sharp and svgo.

Updates astro from 7.0.3 to 7.2.8

Release notes

Sourced from astro's releases.

astro@7.2.8

Patch Changes

astro@7.2.7

Patch Changes

  • #17415 55d38c8 Thanks @​iseraph-dev! - Deserializes each route once when loading the SSR manifest

  • #17772 023b48b Thanks @​matthewp! - Fixes route selection for normalized request paths in adapter and development request handling

  • #17819 633855b Thanks @​matthewp! - Updates generated and default Cloudflare compatibility_date values to match the installed runtime and requires Wrangler ^4.125.0

  • #17813 ae26d18 Thanks @​matthewp! - Fixes rewrite() and next(payload) for GET and HEAD requests with host-provided bodies

  • #17816 a0d2fe3 Thanks @​astro-factory! - Fixes the experimental svgOptimizer not generating unique per-file ID prefixes when using SVGO's prefixIds plugin

astro@7.2.6

Patch Changes

  • #17812 29af6da Thanks @​matthewp! - Fixes a bug where new FetchState(request) could fail in development when server dependencies were optimized

astro@7.2.5

Patch Changes

  • #17758 5f419e2 Thanks @​astro-factory! - Fixes a bug where experimental_getFontFileURL() rejected valid font URLs when using the Cloudflare adapter

  • #17416 493796b Thanks @​iseraph-dev! - Skips no-op pathname writes when normalizing SSR request URLs

  • #17712 bd374b7 Thanks @​fkatsuhiro! - Updates deprecation messages target from Astro 7 to 8

  • #17719 dac1768 Thanks @​astrobot-houston! - Fixes session ID validation to reject non-UUID cookie values before using them as storage keys

  • #17770 84eb7e7 Thanks @​astro-factory! - Fixes --mode, --site, --base, --out-dir, --verbose, --silent, and --open flags being silently dropped when using astro dev --background or astro preview --background

  • #17713 d035290 Thanks @​wakqasahmed! - Fixes content-modules.mjs not removing entries for deleted or renamed content files, which could cause Vite to attempt to resolve non-existent modules

    As part of this fix, #moduleImports is now fully rebuilt from deferredRender entries before every write, so a module import added only through the public addModuleImport() API without a corresponding deferredRender entry in the store will no longer be preserved across writes.

  • #17743 adc750f Thanks @​contactjawad! - Fixes Astro.preferredLocale and Astro.preferredLocaleList ignoring Accept-Language quality values when they are absent or 0. An entry without an explicit q= now correctly counts as quality 1.0 (per RFC 7231) and an entry with q=0 is treated as not acceptable, so the highest-quality locale is selected regardless of header order.

  • #17757 660991c Thanks @​astro-factory! - Fixes build errors showing wrong file location, missing line:col, and misleading hints when a plugin error (e.g. from MDX) is wrapped by Vite's build error

  • #17783 60b14ff Thanks @​matthewp! - Fixes a type error when passing an image from a content collection image() schema to a component or <Image />. The schema returned by image() was missing the apng format, so it no longer matched the type of an imported image.

  • #17664 d483125 Thanks @​astrobot-houston! - Fixes an issue where Astro CSP support didn't correctly handle cases "unsafe-inline" resource. Now when "unsafe-inline", Astro won't emit hashes for the directive specified.

... (truncated)

Changelog

Sourced from astro's changelog.

7.2.8

Patch Changes

7.2.7

Patch Changes

  • #17415 55d38c8 Thanks @​iseraph-dev! - Deserializes each route once when loading the SSR manifest

  • #17772 023b48b Thanks @​matthewp! - Fixes route selection for normalized request paths in adapter and development request handling

  • #17819 633855b Thanks @​matthewp! - Updates generated and default Cloudflare compatibility_date values to match the installed runtime and requires Wrangler ^4.125.0

  • #17813 ae26d18 Thanks @​matthewp! - Fixes rewrite() and next(payload) for GET and HEAD requests with host-provided bodies

  • #17816 a0d2fe3 Thanks @​astro-factory! - Fixes the experimental svgOptimizer not generating unique per-file ID prefixes when using SVGO's prefixIds plugin

7.2.6

Patch Changes

  • #17812 29af6da Thanks @​matthewp! - Fixes a bug where new FetchState(request) could fail in development when server dependencies were optimized

7.2.5

Patch Changes

  • #17758 5f419e2 Thanks @​astro-factory! - Fixes a bug where experimental_getFontFileURL() rejected valid font URLs when using the Cloudflare adapter

  • #17416 493796b Thanks @​iseraph-dev! - Skips no-op pathname writes when normalizing SSR request URLs

  • #17712 bd374b7 Thanks @​fkatsuhiro! - Updates deprecation messages target from Astro 7 to 8

  • #17719 dac1768 Thanks @​astrobot-houston! - Fixes session ID validation to reject non-UUID cookie values before using them as storage keys

  • #17770 84eb7e7 Thanks @​astro-factory! - Fixes --mode, --site, --base, --out-dir, --verbose, --silent, and --open flags being silently dropped when using astro dev --background or astro preview --background

  • #17713 d035290 Thanks @​wakqasahmed! - Fixes content-modules.mjs not removing entries for deleted or renamed content files, which could cause Vite to attempt to resolve non-existent modules

    As part of this fix, #moduleImports is now fully rebuilt from deferredRender entries before every write, so a module import added only through the public addModuleImport() API without a corresponding deferredRender entry in the store will no longer be preserved across writes.

  • #17743 adc750f Thanks @​contactjawad! - Fixes Astro.preferredLocale and Astro.preferredLocaleList ignoring Accept-Language quality values when they are absent or 0. An entry without an explicit q= now correctly counts as quality 1.0 (per RFC 7231) and an entry with q=0 is treated as not acceptable, so the highest-quality locale is selected regardless of header order.

  • #17757 660991c Thanks @​astro-factory! - Fixes build errors showing wrong file location, missing line:col, and misleading hints when a plugin error (e.g. from MDX) is wrapped by Vite's build error

... (truncated)

Commits

Updates sharp from 0.34.5 to 0.35.4

Release notes

Sourced from sharp's releases.

v0.35.4

https://github.com/lovell/sharp-libvips/releases/tag/v1.3.3

v0.35.4-rc.0

... (truncated)

Commits
  • 7f1a0a2 Release v0.35.4
  • f927818 Upgrade to sharp-libvips v1.3.3
  • e802092 Prerelease v0.35.4-rc.0
  • e13eb2f CI: Fix wasm32 build (#4589)
  • a82a0b3 Upgrade to libvips v8.18.6
  • 8044fe4 Bound resize dimensions to coordinate limit
  • 147f859 Docs: changelog entries for #4578 #4584
  • ee5bfb8 Tests: use yauzl directly rather than via extract-zip wrapper
  • 7a77889 Bump uraimo/run-on-arch-action from 3.1.0 to 3.2.0 (#4588)
  • ea5bef2 Improve support for input Streams finishing before output is requested (#4584)
  • Additional commits viewable in compare view

Updates svgo from 4.0.1 to 4.1.0

Release notes

Sourced from svgo's releases.

v4.1.0

This minor release upgrades the SAX parser and introduces stricter XML validation. It also includes important security hardening for removeScripts, dependency updates, and improvements to the test and regression infrastructure.

Support SVGO

If SVGO is valuable to you or your organization, please consider supporting the project on OpenCollective. Your sponsorship helps fund ongoing maintenance and security work.

Stricter XML validation

SVGO now uses sax 1.6.1, upgraded from 1.5.0 (#2257).

The new parser version validates numeric character references against the ranges permitted by XML. Invalid references are now rejected in both text and attributes, including:

  • disallowed control characters such as &[#1](https://github.com/svg/svgo/issues/1);, &#xB;, and &#x1F;;
  • UTF-16 surrogate code points such as &#xD800;;
  • invalid XML code points such as &#xFFFF;.

Valid boundary values—including U+0020, U+D7FF, U+E000, U+FFFD, and characters through U+10FFFF—remain supported.

Parser failures are consistently exposed as SvgoParserError errors with an Invalid character entity reason.

This is an intentional behavior change: malformed SVGs that were previously accepted may now produce a parser error, while valid XML documents are unaffected.

Security

The removeScripts plugin has been hardened against several script-execution bypasses:

  • Filters executable data: URLs containing HTML, XHTML, or SVG documents while preserving inert data such as PNG images, and filters legacy vbscript: URLs (#2263).
  • Sanitizes content inside SVG <foreignObject> elements by removing HTML event-handler attributes, srcdoc, and executable URLs from action, data, formaction, href, and src, while preserving non-executable HTML and visual content (#2264).
  • Recognizes namespace-prefixed SVG <a> elements and removes ASCII tabs and newlines before checking URL schemes, preventing values such as java&[#9](https://github.com/svg/svgo/issues/9);script: from bypassing detection while preserving elements in unrelated custom namespaces (#2268).

These changes address:

Dependencies

  • Upgraded css-select to v6 and css-what to v7, and updated SVGO's custom selector adapter for css-select v6 (#2244).

Project maintenance

@​TrySound is back as an active SVGO maintainer.

Many thanks to @​KTibow, @​SethFalco, and @​XhmikosR for maintaining and improving SVGO over the past several years.

Full Changelog: svg/svgo@v4.0.2...v4.1.0

v4.0.2

... (truncated)

Commits
  • 5765cbe chore: prepare v4.1.0 release (#2275)
  • 3db3ef3 fix(removeScripts): handle anchor URL bypasses (#2268)
  • 4e9b9ae chore: cache regression screenshots (#2267)
  • d55270c chore(regression): migrate comparison workers to Tinypool (#2266)
  • fd51e47 fix(removeScripts): sanitize foreignObject content (#2264)
  • dcaf957 chore: optimize fixtures in a bounded worker pool (#2265)
  • a354293 fix(removeScripts): filter executable data URLs (#2263)
  • 4e0d2ac ci(typecheck): return typechecking on CI
  • 0b97fed test(typescript): drop tsd for vitest type testing API
  • f6e8ae1 chore(pnpm): drop package.json#pnpm.onlyBuiltDependencies
  • Additional commits viewable in compare view
Maintainer changes

This version was pushed to npm by GitHub Actions, a new releaser for svgo since your current version.


Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions
    You can disable automated security fix PRs for this repo from the Security Alerts page.

…dates

Bumps the npm_and_yarn group with 3 updates in the / directory: [astro](https://github.com/withastro/astro/tree/HEAD/packages/astro), [sharp](https://github.com/lovell/sharp) and [svgo](https://github.com/svg/svgo).


Updates `astro` from 7.0.3 to 7.2.8
- [Release notes](https://github.com/withastro/astro/releases)
- [Changelog](https://github.com/withastro/astro/blob/main/packages/astro/CHANGELOG.md)
- [Commits](https://github.com/withastro/astro/commits/astro@7.2.8/packages/astro)

Updates `sharp` from 0.34.5 to 0.35.4
- [Release notes](https://github.com/lovell/sharp/releases)
- [Commits](lovell/sharp@v0.34.5...v0.35.4)

Updates `svgo` from 4.0.1 to 4.1.0
- [Release notes](https://github.com/svg/svgo/releases)
- [Commits](svg/svgo@v4.0.1...v4.1.0)

---
updated-dependencies:
- dependency-name: astro
  dependency-version: 7.2.8
  dependency-type: direct:production
  dependency-group: npm_and_yarn
- dependency-name: sharp
  dependency-version: 0.35.4
  dependency-type: direct:production
  dependency-group: npm_and_yarn
- dependency-name: svgo
  dependency-version: 4.1.0
  dependency-type: indirect
  dependency-group: npm_and_yarn
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Sep 18, 2026
@github-actions github-actions Bot added vouch:trusted PR author is trusted by repo permissions or the VOUCHED list. size:XXL 1,000+ changed lines (additions + deletions). labels Sep 18, 2026
@macroscopeapp

macroscopeapp Bot commented Sep 18, 2026

Copy link
Copy Markdown
Contributor

Approvability

Verdict: Approved at e248e68

Macroscope's review found this PR approvable — This Dependabot PR only refreshes dependency metadata and the lockfile within repository-ignored paths; it does not modify application logic, product defaults, or static-analysis configuration. No significant independently authored runtime behavior or other disqualifying change is present.

Notes:

  • No code objects were reviewed. Approvability was decided on eligibility alone.

You can add or adjust custom eligibility rules. Learn more.

@juliusmarminge
juliusmarminge merged commit c5bbf3d into main Sep 18, 2026
33 checks passed
@juliusmarminge
juliusmarminge deleted the dependabot/npm_and_yarn/npm_and_yarn-1c23d3fe4e branch September 18, 2026 07:24
@github-actions

Copy link
Copy Markdown
Contributor

Thread transfer impact

✅ Thread transfer remains within every enforced ceiling.

Provider Metric Main baseline This PR Impact PR ceiling
Codex Total thread wire 13.5 KiB 13.5 KiB +40 B (+0.3%) 15.1 KiB ✅
Codex Thread snapshot wire 7.1 KiB 7.1 KiB −1 B (−0.0%) 7.3 KiB ✅
Codex Live turn WebSocket wire 6.4 KiB 6.5 KiB +41 B (+0.6%) 7.8 KiB ✅
Codex Live turn WebSocket decoded 56.2 KiB 56.3 KiB +44 B (+0.1%) 66.4 KiB ✅
Codex Live turn messages 9 10 +1 (+11.1%) 21 ✅
Claude Total thread wire 13.5 KiB 13.5 KiB +7 B (+0.1%) 15.1 KiB ✅
Claude Thread snapshot wire 7.1 KiB 7.1 KiB +6 B (+0.1%) 7.3 KiB ✅
Claude Live turn WebSocket wire 6.4 KiB 6.4 KiB +1 B (+0.0%) 7.8 KiB ✅
Claude Live turn WebSocket decoded 57.0 KiB 57.0 KiB 0 B (0.0%) 66.4 KiB ✅
Claude Live turn messages 9 9 0 (0.0%) 21 ✅

Baseline: 7479625 · PR result: e248e68 · Source CI: success

Scenario and decoded snapshot size

10 historical turns, 5 command tools per turn, 878.9 KiB retained MCP result per historical turn, and a 1.05 MiB retained result in the measured turn.

  • Codex decoded thread snapshot: 113.9 KiB
  • Claude decoded thread snapshot: 114.6 KiB

Updated in place by a trusted workflow. PR artifacts are strictly validated and never executed.

juliusmarminge added a commit that referenced this pull request Sep 18, 2026
Enabling Dependabot alerts surfaced ~135 advisories against pnpm-lock.yaml,
almost all in transitive dependencies of build tooling (electron-builder,
alchemy, @clerk/expo, the Claude Agent SDK's MCP dependency). None of the
parents have shipped a release that lifts the floors yet, so this adds
major-scoped overrides in pnpm-workspace.yaml for each affected package.

Every override key is scoped to the major the dependents already declare, so
no edge crosses a breaking version. pnpm audit drops from 137 advisories to
13; the remainder are astro/sharp (Dependabot #12411), image-size@1 under
metro, uuid@7 under xcode, decode-uri-component@0.2 under query-string, and
xml2js@0.4 under dbus-next, none of which have an in-major patched release.

Made with Claude Fable 5 via Claude Code in T3 Code.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
aorwall added a commit to aorwall/t3code that referenced this pull request Sep 19, 2026
Merges `pingdotgg/t3code` at `5378f87f9` into the fork, 51 commits from
base `994654198`.

`4232` files landed against `4233` in the upstream range; the gap of one
is `apps/server/src/cli/pair.ts`, which this fork deletes on purpose.
Fork delta afterwards: `777` files.

## Usable as-is

Nothing here needs Moatless backend or deployment work.

- **Client spans reach the trace proxy again** (pingdotgg#12332). Upstream
rebuilt the fork's own `ClientTracingLive` as
`apps/web/src/observability/clientTracer.ts` — same behaviour,
upstream's name — so the fork delta retired into it. `clientTracing.ts`
and `lib/runtime.ts` are byte-identical to upstream again.
- **Sidebar search matches message content** (pingdotgg#11761), with a new
`ThreadSearchMatch` component and the logic moved out of the command
palette.
- **A file-to-symlink type change no longer crashes the diff view**
(pingdotgg#11075).
- **Obsolete code removed** (pingdotgg#9917). This deleted `SidebarGroupLabel`
from `components/ui/sidebar.tsx`; the fork's `SettingsSidebarNav` was
its only caller, so the label is now inlined there rather than
re-exported from an upstream-owned file.
- **Build fixes**: executable imports parsed without matching source
strings (pingdotgg#12488), and multiple license notices retained for one package
(pingdotgg#12489) — the second sits on the `vp build` path this fork's image
workflow runs.
- **Dependencies**: Effect rc.115 and Alchemy beta.78 with their
reference sync (pingdotgg#12326, pingdotgg#12327), plus two security bumps of vulnerable
transitives (pingdotgg#12417, pingdotgg#12411).
- **`test-t3-app` rewritten around the desktop Browser panel** (pingdotgg#12414).
Taken whole with the fork's scope note re-applied.

Not applicable rather than usable, listed so the next merge does not
re-derive them: the relay deploy and client-config work (pingdotgg#12401, pingdotgg#12484,
pingdotgg#12518, pingdotgg#12519) and the CI label/report automation (pingdotgg#12517, pingdotgg#12492)
belong to infrastructure this fork does not run — every inherited
workflow here is `disabled_manually`.

## Unsupported in Moatless / needs implementation

- **Sort pull requests by what is blocked on me** (pingdotgg#12508,
`apps/web/src/components/pullRequest/pullRequestList.logic.ts`). Needs
`pullRequests.list`, `detail` and `activity`, which the backend does not
dispatch. `FEATURES.pullRequestSurface` is `false`, so the route this
lands in is not reachable here; Moatless serves `pullRequests.summary`
and nothing else in the family. The server half of the same surface is
pingdotgg#11825, below.
- **View and control agent devices from mobile** (pingdotgg#12531,
`apps/mobile/src/features/devices/`). A device panel driven by a device
stream brokered by the bundled server between a client and a registered
device. Moatless has no device registry and device pairing is decided
out in this fork, so the whole path — registration, stream transport,
control commands — is backend work.
- **The mobile client generally.** Twenty-two further mobile changes
landed in this range — pull-to-refresh, native settings and snooze
controls, model favourites, project search, platform header and menu
splits, Live Activity and Material You import isolation, notification
and permission delegate synchronization, copy-thread-id. They are in the
tree and typecheck, but whether this fork's mobile client can reach a
Moatless backend at all is still unverified; see `docs/fork/gaps.md`,
_Mobile testing against Moatless is undocumented because it is
unverified_, which this merge extended.
- **ACP SDK elicitation requests** (pingdotgg#11294,
`packages/effect-acp/src/{client,protocol,rpc}.ts`). Elicitation is an
agent-to-client request: the agent asks the user for input mid-turn and
blocks on the answer. Moatless drives its own agents rather than hosting
upstream's ACP adapters, so the round-trip has to exist on the backend
before any client surface can render it.

## Backend behavior to consider reproducing in Moatless

Nine server-side fixes, all recorded in `docs/fork/gaps.md` under
_Runtime fixes upstream made to its own server_ with the file each lives
in:

- **An oversized pull request diff should not be cached** (pingdotgg#12523) — 512
KiB cap on cached patch text, with invalidation of an entry already
held. A capacity-bounded cache with no size bound is how one enormous PR
pins memory.
- **Checkpoint git commands should be retried on a transient failure**
(pingdotgg#11665) — `…lock: file exists` and `no such file or directory`
classified as retryable and retried twice at 75 ms. The race is an agent
writing files while a checkpoint is captured, which a sandbox makes more
likely.
- **A failed settings write should roll its secret changes back**
(pingdotgg#12487) — otherwise a persistence failure leaves a provider key removed
with nothing to restore it from, and nothing says so until the provider
is next used.
- **A fetch failure should be explained without echoing the remote**
(pingdotgg#12485) — four recognised stderr shapes mapped to fixed sentences,
anything else left generic, because fetch stderr can carry credentials
from the remote URL into a persisted error.
- **A branch switch should not be readable as a path checkout** (pingdotgg#10574)
— one `--` appended to `git checkout <ref>`, with losing uncommitted
work behind it.
- **Rate limits from a tolerated read should still be recorded**
(pingdotgg#12486). Bitbucket is not a fork target; the shape is — the budget was
spent whether or not the caller wanted the answer.
- **An evicted preview host should be able to register again** (pingdotgg#12535)
— completes the RPC stream instead of shutting the queue down, so a
desktop that was merely slow can re-register. Follows pingdotgg#11381 from the
2026-09-16 merge. The client half landed here in
`packages/client-runtime`.
- **A server should export log records, not only traces and metrics**
(pingdotgg#12493) — `otlpLogsUrl` plus a shared `otlpResource`, which is what
makes the three signals joinable at the collector. The fork already
exports client spans.
- **Pull request reads should be batched rather than fanned out**
(pingdotgg#11825) — far fewer GitHub requests per preview, with a measurement
script. Moatless does its own GitHub reads behind
`pullRequests.summary`.

## Merge notes

Five conflicts, each resolved with the verdict `preflight.mjs` printed.
The one that needed thought was `apps/web/src/lib/runtime.ts`: pingdotgg#12332
reimplemented the fork's tracer layer upstream and, in the same change,
removed the `activeDelegate` binding the fork's layer read — so the fork
block auto-merged into `clientTracing.ts` referencing a symbol that no
longer existed. Resolved by converging onto upstream rather than
repairing the fork copy.

Two inventory gaps this merge closed: `apps/server/src/bin.ts` had no
path-policy entry despite holding the only references to the deleted
`cli/pair.ts` (now `server-cli-entrypoint`, `converged`), and the fork's
own `typecheck.yml` was missing from `offRepo.allowedActiveWorkflows`,
which made `tripwires.mjs` report it as an inherited workflow switched
back on.

`unsupported-methods.mjs` reported ADD 0 / DROP 0 — no change to
`packages/contracts/src/rpc.ts`.

`verify.mjs`: all 10 checks green on the final full pass, tests included
— 334 files, 5144 tests. Tripwires: Clerk 4, pairing 96, session
bootstrap 8, 5 known deletions, 4 active workflows.

Tracker entry: `docs/fork/upstream-merge-log.md`, 2026-09-19.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

---
Moatless task:
https://moatless.soaplabstest.com/tasks/0a5d08b0-0bd4-412e-a837-782ac67e5a13
github-actions Bot added a commit to omarcresp/t3code-flake that referenced this pull request Sep 19, 2026
## What's Changed
* fix(mobile): use singular label for one settings environment by @juliusmarminge in pingdotgg/t3code#12282
* feat(mobile): add copy thread ID to thread list actions by @jakeleventhal in pingdotgg/t3code#12228
* fix(mobile): remove Android input underline backgrounds by @juliusmarminge in pingdotgg/t3code#12394
* chore(deps): upgrade Effect to rc.115 and Alchemy to beta.78 by @juliusmarminge in pingdotgg/t3code#12326
* chore(refs): sync Effect and Alchemy references to rc.115 and beta.78 by @juliusmarminge in pingdotgg/t3code#12327
* chore(relay): deploy with the Alchemy CLI and publish client config through an Action by @juliusmarminge in pingdotgg/t3code#12401
* chore(deps): bump the npm_and_yarn group across 1 directory with 3 updates by @dependabot[bot] in pingdotgg/t3code#12411
* fix(git): prevent stale branch selections from restoring files by @yashranaway in pingdotgg/t3code#10574
* chore(deps): bump parents that carry vulnerable transitive dependencies by @juliusmarminge in pingdotgg/t3code#12417
* fix(web): keep a file-to-symlink type change from crashing the diff view by @Mnigos in pingdotgg/t3code#11075
* Use T3 Device panel for mobile testing by @juliusmarminge in pingdotgg/t3code#12414
* fix(web): client spans reach the trace proxy again by @yordis in pingdotgg/t3code#12332
* fix(bitbucket): preserve rate limits from optional PR reads by @juliusmarminge in pingdotgg/t3code#12486
* fix(mobile): synchronize native permission registry access by @juliusmarminge in pingdotgg/t3code#12482
* fix(build): retain multiple license notices for one package by @juliusmarminge in pingdotgg/t3code#12489
* fix(build): parse executable imports without matching source strings by @juliusmarminge in pingdotgg/t3code#12488
* fix(mobile): synchronize native notification delegates by @juliusmarminge in pingdotgg/t3code#12483
* fix(relay): accept delegated thread IDs in activity routes by @juliusmarminge in pingdotgg/t3code#12484
* fix(git): explain fetch failures without exposing remote output by @juliusmarminge in pingdotgg/t3code#12485
* fix(web): sidebar search matches message content by @koushikxd in pingdotgg/t3code#11761
* fix(server): restore secrets when settings persistence fails by @juliusmarminge in pingdotgg/t3code#12487
* fix(ci): accept V2 transfer reports without cross-scenario comparisons by @juliusmarminge in pingdotgg/t3code#12492
* fix(web): speed up PR previews with fewer GitHub requests by @dominic-r in pingdotgg/t3code#11825
* fix(server): retry transient git failures during checkpoint capture by @saphid in pingdotgg/t3code#11665
* fix(mobile): keep archived threads visible during iOS search by @juliusmarminge in pingdotgg/t3code#12420
* perf(mobile): isolate Material You conversion on Android by @juliusmarminge in pingdotgg/t3code#12379
* perf(mobile): isolate iOS Live Activity imports by @juliusmarminge in pingdotgg/t3code#12380
* refactor(mobile): split home headers by platform by @juliusmarminge in pingdotgg/t3code#12381
* refactor(mobile): split native menus by platform by @juliusmarminge in pingdotgg/t3code#12382
* refactor(mobile): isolate thread row appearance by platform by @juliusmarminge in pingdotgg/t3code#12383
* refactor(mobile): split settings selection rows by platform by @juliusmarminge in pingdotgg/t3code#12384
* refactor(mobile): centralize platform header rendering by @juliusmarminge in pingdotgg/t3code#12388
* refactor(mobile): configure thread headers through the shared core by @juliusmarminge in pingdotgg/t3code#12389
* refactor(mobile): share file header actions and search configuration by @juliusmarminge in pingdotgg/t3code#12390
* refactor(mobile): share terminal header and menu configuration by @juliusmarminge in pingdotgg/t3code#12391
* refactor(mobile): share archived thread header configuration by @juliusmarminge in pingdotgg/t3code#12399
* refactor(mobile): compose review menus through the shared header by @juliusmarminge in pingdotgg/t3code#12400
* feat(mobile): search projects when starting a task by @juliusmarminge in pingdotgg/t3code#12496
* fix(mobile): preserve multiple model favorites by @juliusmarminge in pingdotgg/t3code#12505
* feat(server): export log records over OTLP by @yordis in pingdotgg/t3code#12493
* fix(mobile): use native settings and snooze controls by @juliusmarminge in pingdotgg/t3code#12512
* feat(web): sort pull requests by what is blocked on me by @flamboh in pingdotgg/t3code#12508
* fix(mobile): prefer pull-to-refresh on list screens by @juliusmarminge in pingdotgg/t3code#12515
* fix(acp): accept SDK elicitation requests by @shivamhwp in pingdotgg/t3code#11294
* fix(release): read relay configuration without loading deployment providers by @juliusmarminge in pingdotgg/t3code#12518
* fix(ci): reconcile native change labels against pinned commits by @juliusmarminge in pingdotgg/t3code#12517
* fix(release): strip Alchemy progress before parsing relay state by @juliusmarminge in pingdotgg/t3code#12519
* refactor: remove obsolete code by @t3dotgg in pingdotgg/t3code#9917
* fix(server): release oversized pull request diff cache entries by @juliusmarminge in pingdotgg/t3code#12523
* feat(mobile): view and control agent devices by @juliusmarminge in pingdotgg/t3code#12531
* fix(preview): recover host registration after request timeouts by @juliusmarminge in pingdotgg/t3code#12535
* fix(mobile): align built-in theme colors with desktop by @juliusmarminge in pingdotgg/t3code#12534
* feat(desktop): export main process telemetry over OTLP by @yordis in pingdotgg/t3code#12520
* fix(codex): surface app permission requests as approvable by @Exotic209093 in pingdotgg/t3code#7861
* chore(desktop): leave main process metrics export off until a metric exists by @juliusmarminge in pingdotgg/t3code#12540
* fix(release): drop placeholder allowBuilds entry that broke desktop builds by @juliusmarminge in pingdotgg/t3code#12544

## New Contributors
* @dependabot[bot] made their first contribution in pingdotgg/t3code#12411
* @koushikxd made their first contribution in pingdotgg/t3code#11761

**Full Changelog**: pingdotgg/t3code@v0.0.43-nightly.20260918.1895...v0.0.43-nightly.20260919.1948

Upstream release: https://github.com/pingdotgg/t3code/releases/tag/v0.0.43-nightly.20260919.1948
Peyton-Spencer added a commit to ditto-assistant/ditto-desktop that referenced this pull request Sep 22, 2026
* fix(web): show tooltips for composer environment and workspace controls (pingdotgg#11787)

* fix(chat): group thoughts into the changing tool activity line (pingdotgg#12147)

* fix(web): keep tool timestamps before disclosure chevrons (pingdotgg#12152)

* fix(web): default diff panel to working tree (pingdotgg#12139)

Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com>

* design(mobile): unify Android Material layouts and native controls (pingdotgg#11841)

Co-authored-by: Julius Marminge <julius0216@outlook.com>

* feat(web): choose themes from chat with color previews (pingdotgg#12143)

* fix(web): align follow-up and license settings controls (pingdotgg#12167)

* fix(web): align composer task rows (pingdotgg#12165)

* fix(mobile): prevent Android compose FAB animation jitter (pingdotgg#12169)

* fix(server): keep large sparse checkouts on the fast checkpoint path (pingdotgg#12154)

* feat(web): make pull request comments easier to scan (pingdotgg#12150)

Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com>

* fix(server): propagate linked pr changes and settle threads immediately (pingdotgg#12161)

* fix(web): reuse cached GitHub PR details across entry points (pingdotgg#12168)

Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com>

* Remove `new` badge from Fable 5.1 (pingdotgg#12173)

* fix(web): show author avatars in pull request previews (pingdotgg#12125)

* fix(server): settle cancelled worktree setup before rollback (pingdotgg#12176)

* feat(mobile): port worktree setup progress and agent handoff (pingdotgg#12177)

* fix(server): flush checkpoint objects and refs before publishing them (pingdotgg#10944)

* chore(mobile): bump app version to 1.2.1

Co-authored-by: codex <codex@users.noreply.github.com>

* fix(server): keep ready checkpoints when a later placeholder arrives (pingdotgg#8432)

Co-authored-by: Julius Marminge <51714798+juliusmarminge@users.noreply.github.com>

* fix(server): keep VCS waits from blocking turn completion (pingdotgg#11970)

Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com>
Co-authored-by: Julius Marminge <51714798+juliusmarminge@users.noreply.github.com>

* fix(web): keep header spacing stable when sidebar drawer opens (pingdotgg#12162)

* fix(web): fall back when pull request avatars fail (pingdotgg#11728)

* feat(web): enable rich text composer by default (pingdotgg#12160)

Co-authored-by: maria-rcks <maria@kuuro.net>

* feat(web): make keybindings searchable from settings search (pingdotgg#12175)

* fix(web): preserve thread reading positions (pingdotgg#12144)

Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com>

* fix(diff): collapse files by default (pingdotgg#12190)

* fix(web): folder links from chat open the file tree instead of a broken preview (pingdotgg#10909)

Co-authored-by: exe.dev user <exedev@ropeway-swimming.exe.xyz>
Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com>
Co-authored-by: Yash Singh <saiansh2525@gmail.com>

* feat(web): command palette search matches thread IDs (pingdotgg#11185)

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>

* fix(web): align notification icons with titles (pingdotgg#12202)

Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com>

* fix(skills): support unicode currency symbols as skill aliases (pingdotgg#12098)

Co-authored-by: maria-rcks <maria@kuuro.net>

* feat(settings): add automatic storage cleanup per machine and project (pingdotgg#11598)

Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com>

* feat(web): command palette finds the pull requests and usage pages (pingdotgg#12211)

* feat(web): start new threads with multiple models in separate worktrees (pingdotgg#12179)

Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com>

* fix(mobile): keep screen awake during dictation (pingdotgg#12227)

* feat(mobile): add favorites to model picker (pingdotgg#12231)

* fix(desktop): keep preview picking active across subframe navigation (pingdotgg#9741)

Co-authored-by: Simone <185146821+Lucenx9@users.noreply.github.com>
Co-authored-by: shivam <91240327+shivamhwp@users.noreply.github.com>

* fix(shared): keep the newest shared usage scan (pingdotgg#10315)

Co-authored-by: shivam <91240327+shivamhwp@users.noreply.github.com>

* fix(web): keep thoughts and failed tool calls in one activity row (pingdotgg#12270)

* fix(web): avoid reopening settled threads when adding projects (pingdotgg#11804)

* feat(mobile): make Settings easier to navigate and scope (pingdotgg#12272)

* fix(mobile): prevent overlapping text and UI on Android chat messages (pingdotgg#11611)

Co-authored-by: Julius Marminge <julius0216@outlook.com>

* feat(web): pull request files can be marked as viewed (pingdotgg#7721)

Signed-off-by: Yordis Prieto <yordis.prieto@gmail.com>
Co-authored-by: maria <maria@kuuro.net>

* fix(web): keep composer banners compact and readable (pingdotgg#12166)

* fix(web): collapse thoughts within tool groups (pingdotgg#12302)

Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com>
Co-authored-by: Julius Marminge <julius0216@outlook.com>

* fix(usage): preserve saved totals after transcript cleanup (pingdotgg#12304)

Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com>

* fix(mobile): show Agent behavior icon on Android (pingdotgg#12316)

* fix(web): keep PR panel actions in the current thread (pingdotgg#12320)

Co-authored-by: Julius Marminge <51714798+juliusmarminge@users.noreply.github.com>
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>

* fix(web): keep browser pages aligned during panel animations (pingdotgg#12329)

* fix(server): bound provider event log records before serialization (pingdotgg#12305)

* fix(server): reject file rewind in shared workspaces (pingdotgg#12306)

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>

* fix(server): capture checkpoints when baseline lookup fails (pingdotgg#12307)

* fix(server): refresh file search outside checkpoint processing (pingdotgg#12308)

* fix(web): keep chat from jumping when the scroll-to-end pill mounts (pingdotgg#12317)

* fix(server): checkpoint workspaces with empty nested repositories (pingdotgg#12181)

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: Julius Marminge <51714798+juliusmarminge@users.noreply.github.com>

* chore(review): keep review bots out of the vendored .repos references (pingdotgg#12333)

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>

* fix(server): pass Codex image attachments by path to avoid oversized requests (pingdotgg#11050)

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>

* feat(web): filter sidebar from thread menu (pingdotgg#8719)

Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>

* feat(web): open diff files from a right-click context menu (pingdotgg#11842)

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>

* fix(web): keep numbered jumps from stealing browser tabs (pingdotgg#12315)

Co-authored-by: Cursor <cursoragent@cursor.com>

* fix(mobile): define Clerk colors in every Uniwind theme (pingdotgg#12344)

* refactor(web): reuse searchable picker inputs (pingdotgg#12353)

* fix(web): share touch-visible pull request edit actions (pingdotgg#12370)

* fix(mobile): share accessible connection trace controls (pingdotgg#12371)

* fix(mobile): share settings control row layout (pingdotgg#12356)

* refactor(web): share diagnostic process actions (pingdotgg#12358)

* refactor(mobile): share Android toolbar search fields (pingdotgg#12359)

* refactor(web): share settings group surfaces (pingdotgg#12360)

* refactor(web): reuse inline settings actions (pingdotgg#12362)

* refactor(mobile): share thread list section controls (pingdotgg#12363)

* refactor(mobile): share connection form fields (pingdotgg#12364)

* refactor(mobile): share local environment lists (pingdotgg#12365)

* refactor(mobile): share file preview feedback (pingdotgg#12368)

* refactor(web): share standalone page layout (pingdotgg#12354)

* fix(mobile): share settings action row defaults (pingdotgg#12369)

* fix(mobile): share request action button defaults (pingdotgg#12366)

* fix(web): share accessible color picker controls (pingdotgg#12355)

* fix(mobile): use singular label for one settings environment (pingdotgg#12282)

* feat(mobile): add copy thread ID to thread list actions (pingdotgg#12228)

* fix(mobile): remove Android input underline backgrounds (pingdotgg#12394)

* chore(deps): upgrade Effect to rc.115 and Alchemy to beta.78 (pingdotgg#12326)

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>

* chore(refs): sync Effect and Alchemy references to rc.115 and beta.78 (pingdotgg#12327)

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>

* chore(relay): deploy with the Alchemy CLI and publish client config through an Action (pingdotgg#12401)

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>

* chore(deps): bump the npm_and_yarn group across 1 directory with 3 updates (pingdotgg#12411)

Signed-off-by: dependabot[bot] <support@github.com>

* fix(git): prevent stale branch selections from restoring files (pingdotgg#10574)

Co-authored-by: shivam <91240327+shivamhwp@users.noreply.github.com>

* chore(deps): bump parents that carry vulnerable transitive dependencies (pingdotgg#12417)

* fix(web): keep a file-to-symlink type change from crashing the diff view (pingdotgg#11075)

Co-authored-by: shivam <91240327+shivamhwp@users.noreply.github.com>

* Use T3 Device panel for mobile testing (pingdotgg#12414)

* fix(web): client spans reach the trace proxy again (pingdotgg#12332)

Signed-off-by: Yordis Prieto <yordis.prieto@gmail.com>

* fix(bitbucket): preserve rate limits from optional PR reads (pingdotgg#12486)

* fix(mobile): synchronize native permission registry access (pingdotgg#12482)

* fix(build): retain multiple license notices for one package (pingdotgg#12489)

* fix(build): parse executable imports without matching source strings (pingdotgg#12488)

* fix(mobile): synchronize native notification delegates (pingdotgg#12483)

* fix(relay): accept delegated thread IDs in activity routes (pingdotgg#12484)

* fix(git): explain fetch failures without exposing remote output (pingdotgg#12485)

* fix(web): sidebar search matches message content (pingdotgg#11761)

* fix(server): restore secrets when settings persistence fails (pingdotgg#12487)

* fix(ci): accept V2 transfer reports without cross-scenario comparisons (pingdotgg#12492)

* fix(web): speed up PR previews with fewer GitHub requests (pingdotgg#11825)

Co-authored-by: Julius Marminge <julius0216@outlook.com>

* fix(server): retry transient git failures during checkpoint capture (pingdotgg#11665)

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: Julius Marminge <51714798+juliusmarminge@users.noreply.github.com>

* fix(mobile): keep archived threads visible during iOS search (pingdotgg#12420)

* perf(mobile): isolate Material You conversion on Android (pingdotgg#12379)

* perf(mobile): isolate iOS Live Activity imports (pingdotgg#12380)

* refactor(mobile): split home headers by platform (pingdotgg#12381)

* refactor(mobile): split native menus by platform (pingdotgg#12382)

* refactor(mobile): isolate thread row appearance by platform (pingdotgg#12383)

* refactor(mobile): split settings selection rows by platform (pingdotgg#12384)

* refactor(mobile): centralize platform header rendering (pingdotgg#12388)

* refactor(mobile): configure thread headers through the shared core (pingdotgg#12389)

* refactor(mobile): share file header actions and search configuration (pingdotgg#12390)

* refactor(mobile): share terminal header and menu configuration (pingdotgg#12391)

* refactor(mobile): share archived thread header configuration (pingdotgg#12399)

* refactor(mobile): compose review menus through the shared header (pingdotgg#12400)

* feat(mobile): search projects when starting a task (pingdotgg#12496)

* fix(mobile): preserve multiple model favorites (pingdotgg#12505)

* feat(server): export log records over OTLP (pingdotgg#12493)

Signed-off-by: Yordis Prieto <yordis.prieto@gmail.com>

* fix(mobile): use native settings and snooze controls (pingdotgg#12512)

* feat(web): sort pull requests by what is blocked on me (pingdotgg#12508)

* fix(mobile): prefer pull-to-refresh on list screens (pingdotgg#12515)

* fix(acp): accept SDK elicitation requests (pingdotgg#11294)

* fix(release): read relay configuration without loading deployment providers (pingdotgg#12518)

* fix(ci): reconcile native change labels against pinned commits (pingdotgg#12517)

* fix(release): strip Alchemy progress before parsing relay state (pingdotgg#12519)

* refactor: remove obsolete code (pingdotgg#9917)

Co-authored-by: Julius Marminge <julius0216@outlook.com>

* fix(server): release oversized pull request diff cache entries (pingdotgg#12523)

* feat(mobile): view and control agent devices (pingdotgg#12531)

* fix(preview): recover host registration after request timeouts (pingdotgg#12535)

* fix(mobile): align built-in theme colors with desktop (pingdotgg#12534)

* feat(desktop): export main process telemetry over OTLP (pingdotgg#12520)

Signed-off-by: Yordis Prieto <yordis.prieto@gmail.com>

* fix(codex): surface app permission requests as approvable (pingdotgg#7861)

Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com>

* chore(desktop): leave main process metrics export off until a metric exists (pingdotgg#12540)

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>

* fix(release): drop placeholder allowBuilds entry that broke desktop builds (pingdotgg#12544)

* fix(mobile): adapt workspace navigation and expand controls (pingdotgg#12551)

* chore(mobile): add dev client script with preview environment (pingdotgg#12558)

* fix: detect installed editors outside PATH (pingdotgg#12439)

Co-authored-by: shivam <91240327+shivamhwp@users.noreply.github.com>

* fix(web): show plain text in collapsed thought previews (pingdotgg#12377)

Co-authored-by: shivam <91240327+shivamhwp@users.noreply.github.com>

* fix(web): wrap long titles in confirmation dialogs (pingdotgg#12571)

* fix(mobile): keep the Android composer placeholder on one line (pingdotgg#12605)

* fix(web): restore providers settings heading (pingdotgg#12552)

* Add new GitHub user 'yordis' to VOUCHED.td (pingdotgg#12546)

* chore: vouch cestercian (pingdotgg#12638)

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>

* fix(web): keep desktop annotation screenshots under CSP (pingdotgg#12636)

* fix(web): keep typed text when a question option is clicked (pingdotgg#12577)

* fix(server): empty Claude homePath shares continuation with ~/.claude (pingdotgg#12624)

* fix(desktop): include SnapShot app text for Flatpak and GTK4 (pingdotgg#12635)

Co-authored-by: Julius Marminge <51714798+juliusmarminge@users.noreply.github.com>
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>

* fix(server): surface ACP stderr when cursor-agent exits at session start (pingdotgg#12625)

Co-authored-by: Julius Marminge <51714798+juliusmarminge@users.noreply.github.com>
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>

* fix(web): align pull request state glyph to top of row (pingdotgg#11268)

* fix(web): align menu item icons in pull request detail panel (pingdotgg#11263)

* fix(web): honor whitespace settings in pull request diffs (pingdotgg#12438)

Co-authored-by: shivam <91240327+shivamhwp@users.noreply.github.com>

* fix(web): keep citation comment when popover is dismissed (pingdotgg#10831)

Co-authored-by: shivam <91240327+shivamhwp@users.noreply.github.com>

* fix(web): keep narrow chat headers readable and aligned (pingdotgg#12453)

* refactor(observability): hold OTLP export settings per signal (pingdotgg#12657)

Signed-off-by: Yordis Prieto <yordis.prieto@gmail.com>

* fix(web): explain what enabling network access means in its confirmation (pingdotgg#10098)

Co-authored-by: shivamhwp <91240327+shivamhwp@users.noreply.github.com>

* fix(web): reuse current PR status in the sidebar (pingdotgg#12545)

* fix(web): stabilize pull request loading layout (pingdotgg#12721)

Co-authored-by: Julius Marminge <51714798+juliusmarminge@users.noreply.github.com>

* fix(desktop): align preview recording cursors and show input feedback (pingdotgg#12779)

* fix(web): the Run on / Workspace menu closes after a pick (pingdotgg#12685)

* fix(web): keep portaled menus clickable over Electron drag regions (pingdotgg#12527)

* fix(web): render citations in queued messages (pingdotgg#12403)

* fix(web): keep the timeline still when the resting composer expands (pingdotgg#12771)

* fix: composer hero reads project name to screen readers (pingdotgg#12397)

* fix(mobile): respect word wrap in diffs (pingdotgg#12590)

Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Co-authored-by: Julius Marminge <julius0216@outlook.com>

* fix(web): allow full contrast in assistant replies (pingdotgg#12405)

* fix(web): pull request chips share the link hover preview (pingdotgg#12719)

* fix(web): compact the worktree setup glass popover (pingdotgg#12802)

* fix(web): route keyboard submit through the primary worktree action (pingdotgg#12526)

* fix(web): skip image inline chip when composer is empty (pingdotgg#12528)

* fix(web): only show notice details when text is clipped (pingdotgg#12760)

Co-authored-by: t3-code[bot] <269035359+t3-code[bot]@users.noreply.github.com>
Co-authored-by: Exotic <118054752+extoci@users.noreply.github.com>

* fix(devices): recover simulator streams after failures (pingdotgg#12639)

* chore(server): bump device tooling versions (pingdotgg#12809)

* fix: allow more attachments without raising the image payload budget (pingdotgg#12620)

* fix(web): device Reconnect starts one stream instead of two (pingdotgg#12808)

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>

* fix(server): tolerate shutting down an iOS simulator that is already off (pingdotgg#12807)

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>

* feat(web): use the linked pull request row layout on the pull requests page (pingdotgg#12536)

Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com>

* fix(clients): keep backslashes in copied Codex citations (pingdotgg#12243)

Co-authored-by: Simone <185146821+Lucenx9@users.noreply.github.com>

* feat(web): truncate branch names and paths in the middle (pingdotgg#12805)

Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com>

* fix(web): paste markdown with inline code inside bold, italic, or strikethrough (pingdotgg#12290)

* feat(web): show the pull request refresh spinning in the detail header (pingdotgg#12833)

Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com>

* fix(web): dismiss composer suggestions with Escape (pingdotgg#12836)

* fix(mobile): keep the source worktree when starting a thread on a branch (pingdotgg#12623)

Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
Co-authored-by: Julius Marminge <51714798+juliusmarminge@users.noreply.github.com>
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>

* fix(web): keep composer controls visible while they fit (pingdotgg#12837)

* feat(devices): show installed and running tool versions per host (pingdotgg#12816)

* feat(devices): show automatic update progress and host retry (pingdotgg#12817)

* feat(devices): add read-only update discovery and remote ownership (pingdotgg#12818)

* fix(devices): safely reclaim obsolete managed tool versions (pingdotgg#12819)

* fix(web): match thread notification icons to sidebar status (pingdotgg#12806)

* fix(web): move sidebar shelves as one block (pingdotgg#11772)

Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com>
Co-authored-by: Cursor <cursoragent@cursor.com>

* fix(web): offer undo after unpinning a thread (pingdotgg#10744)

* feat(web): undo settle, snooze and archive, with a mod+z shortcut (pingdotgg#12848)

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>

* fix(mobile): use a proper pull request icon on iOS (pingdotgg#12855)

* test(web): remove redundant favicon test (pingdotgg#12856)

* feat(devices): offer manual updates in tool version details (pingdotgg#12877)

* feat(web): answer pull request actions on the row at once (pingdotgg#12843)

Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com>

* fix(mobile): stop iOS autocorrect from rewriting search queries (pingdotgg#12949)

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>

* fix(web): pull request embed chip shows the state icon (pingdotgg#12951)

* fix(web): dismiss selection actions when pressing buttons (pingdotgg#12950)

* fix(web): name message copy actions accurately (pingdotgg#12865)

* fix(contracts): old message-sent events without turnId no longer stop the server from starting (pingdotgg#12763)

* fix(web): the custom snooze calendar starts the week where the locale does (pingdotgg#12745)

* chore(mobile): bump app version to 1.3.0

Co-authored-by: codex <codex@users.noreply.github.com>

* feat(server): let t3.json limit or disable submodule init in new worktrees (pingdotgg#12953)

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>

* feat(settings): resolve t3.json inside the project settings resolver (pingdotgg#12954)

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>

* feat(settings): choose how new worktrees initialize submodules (pingdotgg#12955)

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>

* fix(web): show thread undo notice in the sidebar (pingdotgg#12972)

* feat(web): merge the comment and review buttons into one composer (pingdotgg#12945)

Co-authored-by: maria-rcks <maria@kuuro.net>

* fix(web): allow text selection when renaming threads (pingdotgg#12935)

* chore(lint): report className restyling of components/ui exports (pingdotgg#12982)

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>

* refactor(web): drop className overrides that repeat the base styles (pingdotgg#12984)

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>

* fix(web): close menus when clicking into the browser tab (pingdotgg#11148)

* refactor(web): give Spinner and RefreshIcon a size prop (pingdotgg#12985)

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>

* fix(web): retry failed attachment uploads after reconnect (pingdotgg#10338)

* fix(web): respect panel motion in composer transitions (pingdotgg#11064)

* fix(web): read panel animation settings in the composer (pingdotgg#13098)

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>

* feat(models): add opus 5.5 without changing existing aliases (pingdotgg#13094)

Co-authored-by: Anco <anco@bluebarry.ai>
Co-authored-by: Exotic <118054752+extoci@users.noreply.github.com>
Co-authored-by: Julius Marminge <51714798+juliusmarminge@users.noreply.github.com>

* Update model manifest with new timestamps and models

* refactor(web): use ghost-muted where ghost buttons restyled to muted (pingdotgg#13020)

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>

* refactor(web): fold repeated overrides into ui defaults (pingdotgg#13021)

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>

* refactor(web): mark the current menu value with MenuRadioGroup (pingdotgg#13022)

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>

* refactor(web): add an active prop to CommandItem (pingdotgg#13023)

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>

* chore(lint): exempt CollapsibleTrigger from no-restyle (pingdotgg#13024)

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>

* refactor(web): use icon-xs where icon buttons were forced to size-6 (pingdotgg#13025)

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>

* refactor(web): add radius="none" to ScrollArea (pingdotgg#13026)

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>

* refactor(web): add font="mono" to Input (pingdotgg#13027)

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>

* refactor(web): add SidebarInput (pingdotgg#13028)

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>

* refactor(web): add a label variant to Badge (pingdotgg#13029)

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>

* refactor(web): give Skeleton three shapes (pingdotgg#13030)

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>

* refactor(web): one wrap width for tooltips, plus a code variant (pingdotgg#13031)

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>

* refactor(web): one vertical rhythm for dialog bodies (pingdotgg#13032)

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>

* refactor(web): ghost-muted icons follow the text; add ghost-destructive (pingdotgg#13033)

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>

* refactor(web): InlineButton underlines on hover and takes a tone (pingdotgg#13034)

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>

* refactor(web): one minimum width for menus, three widths for popovers (pingdotgg#13035)

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>

* refactor(web): every textarea caps its growth; the diff comment box is a Textarea (pingdotgg#13036)

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>

* refactor(web): stacked sidebar groups share one inset (pingdotgg#13037)

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>

* refactor(web): Collapsible stays a plain container (pingdotgg#13038)

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>

* refactor(web): show more / show less are ordinary sidebar sub-rows (pingdotgg#13039)

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>

* refactor(web): Empty has three sizes (pingdotgg#13040)

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>

* refactor(web): one row height for select, combobox and radio items (pingdotgg#13041)

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>

* refactor(web): render menu and popover triggers through Button (pingdotgg#13042)

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>

* refactor(web): sidebar alerts use the standard variants; one keycap (pingdotgg#13043)

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>

* fix(server): bypass owned caches on explicit provider refresh (pingdotgg#13109)

* chore(devices): bump agent-device to 0.21.12 (pingdotgg#13124)

* fix(mobile): restore command palette import after upstream sync

* fix: align packaging and branded preflight tests with upstream

* chore: normalize lockfile after full workspace install

* fix: reconcile mobile screens and tests after upstream sync

* fix: complete bootstrap worktree handoff after sync

* chore: set Ditto UI override baseline after upstream sync

* fix: restore project filter action in thread menu

---------

Signed-off-by: Yordis Prieto <yordis.prieto@gmail.com>
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: oliver <97427849+flamboh@users.noreply.github.com>
Co-authored-by: maria <maria@kuuro.net>
Co-authored-by: Yash Singh <saiansh2525@gmail.com>
Co-authored-by: maria-rcks <254055478+maria-rcks@users.noreply.github.com>
Co-authored-by: Alex <me@pixp.cc>
Co-authored-by: Julius Marminge <julius0216@outlook.com>
Co-authored-by: Bilal Bakr <62337003+Bil0000@users.noreply.github.com>
Co-authored-by: Ved Pandey <33724654+vedprakash2302@users.noreply.github.com>
Co-authored-by: Exotic <118054752+extoci@users.noreply.github.com>
Co-authored-by: Igor Makowski <56691628+Mnigos@users.noreply.github.com>
Co-authored-by: t3-code[bot] <269035359+t3-code[bot]@users.noreply.github.com>
Co-authored-by: codex <codex@users.noreply.github.com>
Co-authored-by: Adolanium <94890352+Adolanium@users.noreply.github.com>
Co-authored-by: Julius Marminge <51714798+juliusmarminge@users.noreply.github.com>
Co-authored-by: Patrik Votoček <patrik@votocek.cz>
Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com>
Co-authored-by: Harshith Goka <harshith9399@gmail.com>
Co-authored-by: pcstyle <134572227+pc-style@users.noreply.github.com>
Co-authored-by: exe.dev user <exedev@ropeway-swimming.exe.xyz>
Co-authored-by: Alex Southwell <saphid@gmail.com>
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: Wilgot <wilgot10@yahoo.com>
Co-authored-by: Simone <lucenz@proton.me>
Co-authored-by: Simone <185146821+Lucenx9@users.noreply.github.com>
Co-authored-by: shivam <91240327+shivamhwp@users.noreply.github.com>
Co-authored-by: Aditya Garud <153842990+yashranaway@users.noreply.github.com>
Co-authored-by: Dominic Roy <dominic@sdko.org>
Co-authored-by: James C <134711311+Exotic209093@users.noreply.github.com>
Co-authored-by: Yordis Prieto <yordis.prieto@gmail.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Jake Leventhal <jakeleventhal@me.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Koushik_xd <122906171+koushikxd@users.noreply.github.com>
Co-authored-by: Theo Browne <me@t3.gg>
Co-authored-by: Dara Adedeji <76637177+SunkenInTime@users.noreply.github.com>
Co-authored-by: Cestercian <yashafaid@gmail.com>
Co-authored-by: Akash Moradiya <64416825+akash3444@users.noreply.github.com>
Co-authored-by: Khai Shern, Toh <55418374+Leos-Khai@users.noreply.github.com>
Co-authored-by: Guillermo Casanova <75276669+Gigioxx@users.noreply.github.com>
Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
Co-authored-by: Carter Smith <51297686+carterwsmith@users.noreply.github.com>
Co-authored-by: Wout Stiens <71498452+StiensWout@users.noreply.github.com>
Co-authored-by: Gianmarco <gianmarcosimone89@gmail.com>
Co-authored-by: Anco <anco@bluebarry.ai>
Co-authored-by: Peyton Spencer <peyton@peyton-mac-mini.local>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code size:XXL 1,000+ changed lines (additions + deletions). vouch:trusted PR author is trusted by repo permissions or the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant