chore(deps): update actions/checkout action to v6 - #20
Closed
renovate[bot] wants to merge 337 commits into
Closed
renovate[bot] wants to merge 337 commits into
renovate[bot] wants to merge 337 commits into
Conversation
Add three workflow templates for internal dogfood launch: - Deploy Notification: event trigger on deploy.succeeded → Slack - New User Onboarding: event trigger on member.added → welcome email - Daily Audit Digest: cron → query Chronicle → email summary
These files were referenced by committed code but never tracked, breaking Docker/CI builds that clone from git.
- Add requestId to GraphQL context via X-Request-Id header or generated ID - Improve authentication plugin logic - Update OAuth routes - Fix cron and polling trigger handling - Refresh integration catalog - Update workflow template seeds - Misc server and webhook handler cleanup
…orkflow helper
Replace scattered inline Hatchet.init() blocks and hatchet.event.push("workflow:execute") calls in api.ts, webhooks.ts, cron.ts, and polling.ts with the shared dispatchWorkflow helper. Remove dispatch.ts from Knip ignore list now that it is wired into callers.
Make command nullable and add transport (default stdio), url, and headers columns to support SSE and HTTP remote transport configurations.
POST /api/v1/plugins/upload accepts multipart form-data with a WASM binary, computes SHA256, uploads to S3 (PLUGIN_STORAGE_BUCKET), injects the public URL into the manifest, and inserts the plugin record into pluginTable.
- Extract `validateApiKey` into `src/lib/auth/apiKey.ts` and import it in both `api.ts` and `routes/plugins.ts` to eliminate duplication - Reject requests where `manifest.wasm` is pre-populated (reserved field) - Add `PLUGIN_STORAGE_BASE_URL` env var for S3-compatible store URL override - Move `S3Client` instantiation inside the handler after the bucket guard - Add 10MB file size limit to the WASM upload field - Add success-path `logger.info` after plugin insert
…module-level S3Client
…reation and monthly runs
All features open on all tiers per open-source parity model. Plugin creation now only enforces the max_plugins count limit, not a plan-tier feature flag. Removes unused isFeatureEnabled helper.
renovate
Bot
force-pushed
the
renovate/actions-checkout-6.x
branch
from
March 31, 2026 17:53
a591bee to
9b85b21
Compare
GATEKEEPER_ -> AUTH_, AETHER_ -> BILLING_. Core infra env vars should describe their use case, not their internal product name.
renovate
Bot
force-pushed
the
renovate/actions-checkout-6.x
branch
from
April 4, 2026 07:20
9b85b21 to
2e491b3
Compare
…e and quote events Route mantle.invoice.* and mantle.quote.* events to MyFi's /api/webhooks/mantle endpoint for automated accounting
The platform has grown beyond 16 internal subscriptions, hitting the previous default
Reads all user-organization memberships from the local DB (synced from Gatekeeper) and writes the corresponding authorization tuples to the Warden PDP. Supports --dry-run and --delete-orphans flags, following the same pattern as Runa's reconciliation scripts. Usage: bun authz:reconcile
renovate
Bot
force-pushed
the
renovate/actions-checkout-6.x
branch
from
April 9, 2026 16:03
2e491b3 to
f300ef2
Compare
Add three REST endpoints for external systems (e.g. Hatchet cron) to check and repair user-organization membership tuple drift between the DB and Warden PDP: - GET /api/v1/authz/tuples (expected tuples from DB) - GET /api/v1/authz/drift (diff expected vs PDP) - POST /api/v1/authz/reconcile (write missing, optionally delete orphans)
The API was blindly setting status='running' after dispatchWorkflow returned, but the worker can complete the run before the dispatch call returns (races of 100ms or less for simple workflows). This overwrote completed/failed terminal states back to running, leaving runs stuck forever in the UI. Add WHERE status='pending' guard so the update only fires if the worker hasn't already transitioned the state.
…er seats - Security: drizzle-orm 0.45.1 to 0.45.2 (SQL injection fix) - Deps: graphql 16.13.2, @sentry/bun 10.48.0, @hatchet-dev/typescript-sdk 1.21.0, graphql-yoga 5.21.0, @tanstack/query-core 5.97.0, @temporalio/client 1.16.0 - Auth: propagate idpUserId from Gatekeeper API keys so Warden checks run for API key holders (not just session users) - Billing: hard-enforce MAX_USERS entitlement in IDP webhook handler (was warn-only, now rejects when seat limit exceeded) - Tests: add regression tests for API key authZ propagation and seat enforcement - Chore: add packageManager field, rename WARDEN_SYNC to AUTHZ_SYNC in locks, fix graphql type dedup in schema generation script
renovate
Bot
force-pushed
the
renovate/actions-checkout-6.x
branch
from
April 10, 2026 21:00
f300ef2 to
5e4320a
Compare
renovate
Bot
force-pushed
the
renovate/actions-checkout-6.x
branch
from
April 10, 2026 22:00
5e4320a to
5d254a5
Compare
Add Warden authorization checks to 18 read endpoints and billing usage metering (recordUsage) to 20 mutation endpoints. Upgrade dependencies (graphile to stable 1.0.0). Align with Omni template conventions (package.json metadata, changeset config, husky). Note: tsc --noEmit has pre-existing PostGraphile v5 type errors from the graphile RC to stable upgrade that need separate resolution.
renovate
Bot
force-pushed
the
renovate/actions-checkout-6.x
branch
from
April 11, 2026 02:44
5d254a5 to
f143026
Compare
Add type annotations for graphile 1.0.0 stable API changes: - Cast fieldArgs.getRaw() returns (AnyInputStep to Step<any>) - Annotate Drizzle where callback parameters - Bridge GraphQLSchema type between graphql and graphql-yoga
…illing exports Close the authorization gap for event subscriptions by adding a GraphQL plugin that enforces admin+ role and max_subscriptions plan limits on create/update/delete mutations. Also export checkUsage from the billing module for worker-side pre-execution limit checks.
Add AUTHZ_API_URL and AUTHZ_SERVICE_KEY to all env config mocks so the warden/client.ts re-export does not fail when Bun runs multiple test files in the same process. Expand the wardenSyncPoller mock to preserve checkPermission behavior and prevent it from stubbing out the authorize wrapper tests. Add env config mock to execution.test.ts to prevent the real assertEnv from throwing.
…upgrade deps Add execution limit check to function invocation to prevent billing bypass. Add Warden authorize to DLQ list/stats endpoints. Add CLA workflow, changeset tooling, and source-code validation tests for enforcement coverage.
renovate
Bot
force-pushed
the
renovate/actions-checkout-6.x
branch
from
April 11, 2026 18:58
f143026 to
f09e43e
Compare
The dep upgrade resolved grafast ^1.0.0-rc.8 to stable 1.0.0, which has breaking changes in the planning lifecycle (currentLayerPlan). Pin to exact 1.0.0-rc.8 until PostGraphile v5 reaches stable.
renovate
Bot
force-pushed
the
renovate/actions-checkout-6.x
branch
from
April 11, 2026 23:24
f09e43e to
8666e9f
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
v4→v6Release Notes
actions/checkout (actions/checkout)
v6Compare Source
v5Compare Source
Configuration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.