sync: merge upstream/main (bc6de9a1) - #74
Merged
Merged
Conversation
Bumps [svgo](https://github.com/svg/svgo) from 3.3.2 to 3.3.5. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/svg/svgo/releases">svgo's releases</a>.</em></p> <blockquote> <h2>v3.3.5</h2> <h2>What's Changed</h2> <h3>Security</h3> <ul> <li>Backport the <code>removeScriptElement</code> hardening from SVGO v4 in <a href="https://redirect.github.com/svg/svgo/issues/2269">#2269</a>: <ul> <li>reject executable <code>data:</code> URLs and legacy <code>vbscript:</code> URLs</li> <li>sanitize executable HTML inside <code><foreignObject></code> elements</li> <li>handle namespace-prefixed SVG anchors and URL schemes containing ASCII tabs or newlines</li> </ul> </li> </ul> <p>This addresses <a href="https://github.com/svg/svgo/security/advisories/GHSA-4vpr-x523-8j87">GHSA-4vpr-x523-8j87</a> and <a href="https://github.com/svg/svgo/security/advisories/GHSA-w27v-7q3p-w38r">GHSA-w27v-7q3p-w38r</a> for the v3 release line.</p> <h2>Support</h2> <p>SVGO v3 is not officially supported; please consider upgrading to SVGO v4. This security fix has been backported, but there is no commitment to backport more complex changes in the future.</p> <p>See the <a href="https://svgo.dev/docs/migrations/migration-from-v3-to-v4/">migration guide from v3 to v4</a>.</p> <h2>v3.3.4</h2> <h2>What's Changed</h2> <h3>Security</h3> <ul> <li><a href="https://svgo.dev/docs/plugins/removeScripts/">removeScriptElement</a>, remove JavaScript URIs case-insensitively and make <code><script></code> handling namespace aware. By <a href="https://github.com/SethFalco"><code>@SethFalco</code></a></li> </ul> <h2>Support</h2> <p>SVGO v3 is not officially supported, please consider upgrading to SVGO v4 instead. We've backported this fix as there are security implications, but there is no commitment to do this for more complex changes in future.</p> <p>Consider reading our <a href="https://svgo.dev/docs/migrations/migration-from-v3-to-v4/">Migration Guide from v3 to v4</a> which should ease the process.</p> <h2>v3.3.3</h2> <h2>What's Changed</h2> <h3>Dependencies</h3> <ul> <li>Migrates from our unsupported fork of sax (<a href="https://www.npmjs.com/package/@trysound/sax">@trysound/sax</a>) to the upstream version of sax (<a href="https://www.npmjs.com/package/sax">sax</a>).</li> </ul> <h3>Bug Fixes</h3> <ul> <li>No longer throws error when encountering comments in DTD.</li> </ul> <h2>Metrics</h2> <p>Before and after of the browser bundle of each respective version:</p> <table> <thead> <tr> <th></th> <th>v3.3.2</th> <th>v3.3.3</th> <th>Delta</th> </tr> </thead> <tbody> <tr> <td>svgo.browser.js</td> <td>910.9 kB</td> <td>912.9 kB</td> <td>⬆️ 2 kB</td> </tr> </tbody> </table> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/svg/svgo/commit/438059032950dde2c2d36ce45f912085947e60d0"><code>4380590</code></a> ci: configure v3 publish tag in package metadata (<a href="https://redirect.github.com/svg/svgo/issues/2271">#2271</a>)</li> <li><a href="https://github.com/svg/svgo/commit/4c84fe7ef022f05350404a469ca66321e0afcb47"><code>4c84fe7</code></a> ci: publish v3 with npm trusted publishing (<a href="https://redirect.github.com/svg/svgo/issues/2270">#2270</a>)</li> <li><a href="https://github.com/svg/svgo/commit/994a9f00d79ddec68ce19a1ce9eb8ca08d747e4f"><code>994a9f0</code></a> fix(removeScriptElement): backport security hardening to v3 (<a href="https://redirect.github.com/svg/svgo/issues/2269">#2269</a>)</li> <li><a href="https://github.com/svg/svgo/commit/72a23886b4698b27624b936f3a15a80afd36d75f"><code>72a2388</code></a> Merge commit from fork</li> <li><a href="https://github.com/svg/svgo/commit/bbab162534d89654ac51c30dd6e62d7163b48a5e"><code>bbab162</code></a> deps: upgrade to sax v1.5.0</li> <li>See full diff in <a href="https://github.com/svg/svgo/compare/v3.3.2...v3.3.5">compare view</a></li> </ul> </details> <details> <summary>Maintainer changes</summary> <p>This version was pushed to npm by <a href="https://www.npmjs.com/~GitHub%20Actions">GitHub Actions</a>, a new releaser for svgo since your current version.</p> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/wavetermdev/waveterm/network/alerts). </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
…avetermdev#3229) Bumps [actions/upload-pages-artifact](https://github.com/actions/upload-pages-artifact) from 4 to 5. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/actions/upload-pages-artifact/releases">actions/upload-pages-artifact's releases</a>.</em></p> <blockquote> <h2>v5.0.0</h2> <h1>Changelog</h1> <ul> <li>Update upload-artifact action to version 7 <a href="https://github.com/Tom-van-Woudenberg"><code>@Tom-van-Woudenberg</code></a> (<a href="https://redirect.github.com/actions/upload-pages-artifact/issues/139">#139</a>)</li> <li>feat: add <code>include-hidden-files</code> input <a href="https://github.com/jonchurch"><code>@jonchurch</code></a> (<a href="https://redirect.github.com/actions/upload-pages-artifact/issues/137">#137</a>)</li> </ul> <p>See details of <a href="https://github.com/actions/upload-pages-artifact/compare/v4.0.0...v4.0.1">all code changes</a> since previous release.</p> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/actions/upload-pages-artifact/commit/fc324d3547104276b827a68afc52ff2a11cc49c9"><code>fc324d3</code></a> Merge pull request <a href="https://redirect.github.com/actions/upload-pages-artifact/issues/139">#139</a> from Tom-van-Woudenberg/patch-1</li> <li><a href="https://github.com/actions/upload-pages-artifact/commit/fe9d4b7d84090e1d8d9c53a0236f810d4e00d2c3"><code>fe9d4b7</code></a> Merge branch 'main' into patch-1</li> <li><a href="https://github.com/actions/upload-pages-artifact/commit/0ca16172ca884f0a37117fed41734f29784cc980"><code>0ca1617</code></a> Merge pull request <a href="https://redirect.github.com/actions/upload-pages-artifact/issues/137">#137</a> from jonchurch/include-hidden-files</li> <li><a href="https://github.com/actions/upload-pages-artifact/commit/57f0e8492b437b7818227931fef2faa1a379839b"><code>57f0e84</code></a> Update action.yml</li> <li><a href="https://github.com/actions/upload-pages-artifact/commit/4a90348b2933470dc78cec55534259872a6d3c0d"><code>4a90348</code></a> v7 --> hash</li> <li><a href="https://github.com/actions/upload-pages-artifact/commit/56f665a6f297fa95f8d735b314187fb2d7764569"><code>56f665a</code></a> Update upload-artifact action to version 7</li> <li><a href="https://github.com/actions/upload-pages-artifact/commit/f7615f5917213b24245d49ba96693d0f5375a414"><code>f7615f5</code></a> Add <code>include-hidden-files</code> input</li> <li>See full diff in <a href="https://github.com/actions/upload-pages-artifact/compare/v4...v5">compare view</a></li> </ul> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
…avetermdev#3227) Bumps [softprops/action-gh-release](https://github.com/softprops/action-gh-release) from 2 to 3. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/softprops/action-gh-release/releases">softprops/action-gh-release's releases</a>.</em></p> <blockquote> <h2>v3.0.0</h2> <p><code>3.0.0</code> is a major release that moves the action runtime from Node 20 to Node 24. Use <code>v3</code> on GitHub-hosted runners and self-hosted fleets that already support the Node 24 Actions runtime. If you still need the last Node 20-compatible line, stay on <code>v2.6.2</code>.</p> <h2>What's Changed</h2> <h3>Other Changes 🔄</h3> <ul> <li>Move the action runtime and bundle target to Node 24</li> <li>Update <code>@types/node</code> to the Node 24 line and allow future Dependabot updates</li> <li>Keep the floating major tag on <code>v3</code>; <code>v2</code> remains pinned to the latest <code>2.x</code> release</li> </ul> <h2>v2.6.2</h2> <!-- raw HTML omitted --> <h2>What's Changed</h2> <h3>Other Changes 🔄</h3> <ul> <li>chore(deps): bump picomatch from 4.0.3 to 4.0.4 by <a href="https://github.com/dependabot"><code>@dependabot</code></a>[bot] in <a href="https://redirect.github.com/softprops/action-gh-release/pull/775">softprops/action-gh-release#775</a></li> <li>chore(deps): bump brace-expansion from 5.0.4 to 5.0.5 by <a href="https://github.com/dependabot"><code>@dependabot</code></a>[bot] in <a href="https://redirect.github.com/softprops/action-gh-release/pull/777">softprops/action-gh-release#777</a></li> <li>chore(deps): bump vite from 8.0.0 to 8.0.5 by <a href="https://github.com/dependabot"><code>@dependabot</code></a>[bot] in <a href="https://redirect.github.com/softprops/action-gh-release/pull/781">softprops/action-gh-release#781</a></li> </ul> <p><strong>Full Changelog</strong>: <a href="https://github.com/softprops/action-gh-release/compare/v2...v2.6.2">https://github.com/softprops/action-gh-release/compare/v2...v2.6.2</a></p> <h2>v2.6.1</h2> <p><code>2.6.1</code> is a patch release focused on restoring linked discussion thread creation when <code>discussion_category_name</code> is set. It fixes <code>[wavetermdev#764](https://github.com/softprops/action-gh-release/issues/764)</code>, where the draft-first publish flow stopped carrying the discussion category through the final publish step.</p> <p>If you still hit an issue after upgrading, please open a report with the bug template and include a minimal repro or sanitized workflow snippet where possible.</p> <h2>What's Changed</h2> <h3>Bug fixes 🐛</h3> <ul> <li>fix: preserve discussion category on publish by <a href="https://github.com/chenrui333"><code>@chenrui333</code></a> in <a href="https://redirect.github.com/softprops/action-gh-release/pull/765">softprops/action-gh-release#765</a></li> </ul> <h2>v2.6.0</h2> <p><code>2.6.0</code> is a minor release centered on <code>previous_tag</code> support for <code>generate_release_notes</code>, which lets workflows pin GitHub's comparison base explicitly instead of relying on the default range. It also includes the recent concurrent asset upload recovery fix, a <code>working_directory</code> docs sync, a checked-bundle freshness guard for maintainers, and clearer immutable-prerelease guidance where GitHub platform behavior imposes constraints on how prerelease asset uploads can be published.</p> <p>If you still hit an issue after upgrading, please open a report with the bug template and include a minimal repro or sanitized workflow snippet where possible.</p> <h2>What's Changed</h2> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/softprops/action-gh-release/blob/master/CHANGELOG.md">softprops/action-gh-release's changelog</a>.</em></p> <blockquote> <h2>0.1.13</h2> <ul> <li>fix issue with multiple runs concatenating release bodies <a href="https://redirect.github.com/softprops/action-gh-release/pull/145">#145</a></li> </ul> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/softprops/action-gh-release/commit/b4309332981a82ec1c5618f44dd2e27cc8bfbfda"><code>b430933</code></a> release: cut v3.0.0 for Node 24 upgrade (<a href="https://redirect.github.com/softprops/action-gh-release/issues/670">#670</a>)</li> <li><a href="https://github.com/softprops/action-gh-release/commit/c2e35e05a74208bafbfcbdae5ebc9da7236e980f"><code>c2e35e0</code></a> chore(deps): bump the npm group across 1 directory with 7 updates (<a href="https://redirect.github.com/softprops/action-gh-release/issues/783">#783</a>)</li> <li>See full diff in <a href="https://github.com/softprops/action-gh-release/compare/v2...v3">compare view</a></li> </ul> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
## Summary - Set the root module, Tsunami SDK, all eight demo modules, and the scaffold module template to Go 1.26.8. - Make TestDriver builds, release builds, CodeQL, and Copilot setup read their Go version from the root `go.mod`, eliminating duplicate pins and future version drift. - Remove the unused Go version setting from the TestDriver run workflow. Dependency versions and historical release notes are unchanged. ## Why The TestDriver packaging step installs Go 1.25.6 while the root module requires Go 1.26.0. With `GOTOOLCHAIN=local`, packaging exits before TestDriver can run. This aligns the repository on the requested patched Go 1.26 release. ## Validation Performed using Go 1.26.8: - Passed: `go test ./cmd/generateschema ./pkg/wconfig ./pkg/util/utilfn ./pkg/util/shellutil`. - Passed: root and Tsunami `go mod tidy -diff`; Tsunami checked in a temporary tracked-source copy to avoid local generated scaffold files. - Passed: root and Tsunami `go mod verify`. - Passed: workflow YAML parsing, version-consistency assertions for all ten modules plus the template and all four Go setup steps, Prettier checks, and `git diff --check`. - Tsunami's full suite has a pre-existing `TestJsonH` failure (`data1: int`); reproduced identically on unchanged source with Go 1.26.8. All remaining Tsunami package tests pass with that single test excluded. Windows packaging/TestDriver and the full release build were not run locally; CI must confirm those paths. --- Pull Request opened by [Augment Code](https://www.augmentcode.com/) | [View session](https://cosmos.augmentcode.com/session?agentId=01M3WY5P0MP004SGE7VSVJ6MYV&panel=chat) Co-authored-by: Mike Sawka <mike@commandline.dev>
## Summary - Remove the TestDriver.ai build and run workflows, stopping repository-defined TestDriver automation once merged. - Remove the unused TestDriver onboarding script. - Remove TestDriver entries from Merge Gatekeeper's ignore list while preserving all other ignored checks. These entries were exclusions, not requirements. ## Validation - Parsed all 7 remaining GitHub Actions workflow YAML files. - Verified Gatekeeper's parsed configuration changes only by removing the two TestDriver ignore entries. - Verified all three TestDriver-specific files are removed and no tracked TestDriver/Dashcam references remain. - Passed `git diff --check` and staged diff checks. - Application tests/builds were not run because no application code changed; GitHub-hosted workflow behavior has not been exercised locally. ## Admin cleanup (not performed by this PR) - Disable both **TestDriver.ai Build** and **TestDriver.ai Run** workflows now if runs must stop before this PR merges; cancel existing runs if necessary. - Check classic branch protection for any required TestDriver checks before disabling workflows. The currently active rulesets on `main` do not require TestDriver; classic branch protection could not be inspected with the integration's permissions. - Remove the `DASHCAM_API` Actions secret from the applicable repository/environment scope, or remove this repository's access if it is organization-scoped and shared; revoke the corresponding TestDriver key if it is not used elsewhere. - If a TestDriver/Dashcam GitHub App or webhook is installed, remove this repository's access or uninstall it if unused elsewhere. Deleted files remain recoverable from Git history. This PR does not change GitHub settings, secrets, app installations, or vendor credentials. --- Pull Request opened by [Augment Code](https://www.augmentcode.com/) Co-authored-by: Mike Sawka <mike@commandline.dev>
Bumps [fast-uri](https://github.com/fastify/fast-uri) from 3.1.7 to 3.1.8. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/fastify/fast-uri/releases">fast-uri's releases</a>.</em></p> <blockquote> <h2>v3.1.8</h2> <h2>⚠️ Security Warning</h2> <p>This security release fixes the following medium-severity security advisory:</p> <ul> <li><a href="https://github.com/fastify/fast-uri/security/advisories/GHSA-hrr3-gc8f-f4qj">GHSA-hrr3-gc8f-f4qj</a> — inconsistent host case normalization via percent-encoded octets</li> </ul> <p>Users of the v3.x release line should upgrade to v3.1.8.</p> <p><strong>Full Changelog</strong>: <a href="https://github.com/fastify/fast-uri/compare/v3.1.7...v3.1.8">https://github.com/fastify/fast-uri/compare/v3.1.7...v3.1.8</a></p> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/fastify/fast-uri/commit/ead3ab7bb134c989e972c8174632d0670023f269"><code>ead3ab7</code></a> Bumped v3.1.8</li> <li><a href="https://github.com/fastify/fast-uri/commit/c88b59e3e3a20af1d5d6e499f48908d0fb12a66d"><code>c88b59e</code></a> fix: normalize decoded reg-name case</li> <li>See full diff in <a href="https://github.com/fastify/fast-uri/compare/v3.1.7...v3.1.8">compare view</a></li> </ul> </details> <br /> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Brings in the TestDriver.ai removal, Go 1.26.8 alignment, and dependency bumps (svgo 3.3.5, fast-uri 3.1.8, two workflow action bumps). Conflicts: codeql.yml takes upstream's go-version-file: go.mod and keeps the fork's path trigger; testdriver-build.yml is deleted as upstream did. Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01W6QMXXvRReaKxWk1JL5Et6
Atreus-X
marked this pull request as ready for review
October 2, 2026 18:14
This was referenced Oct 2, 2026
Merged
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Syncs
upstream/main(bc6de9a1, 6 commits since6d61b999) into the fork.testdriver.yml,testdriver-build.yml,testdriver/onboarding.yml.go.mod, tsunami modules and template; workflows usego-version-file: go.mod.Conflicts
codeql.yml: took upstream'sgo-version-file: go.mod, kept the fork's.github/workflows/codeql.ymlpath trigger.testdriver-build.yml: deleted, as upstream did (the fork had only bumped itsGO_VERSION).go.modandpackage-lock.jsonauto-merged; the fork'spkg/sftpadditions are intact.Testing
npx tsc --noEmit: no errors.npx vitest run: 111 passed.go vet ./pkg/wconfig/... ./pkg/wshrpc/...: clean (on Go 1.26.8, auto-downloaded by the toolchain).go vet ./...or an app build. The release build covers those.Notes
go.modnow needs Go 1.26.8; withGOTOOLCHAIN=autothe local toolchain fetches it on first use.SSH / wsh
CI, dependency and version changes only; no remote-host behaviour, so both routes are unaffected.
🤖 Generated with Claude Code
https://claude.ai/code/session_01W6QMXXvRReaKxWk1JL5Et6