v0.9.13: code hygiene, security hardening - #8606
Conversation
waleedlatif1
commented
Oct 3, 2026
- improvement(guidance): make every ratchet shrink-only, scope rules to their files, fix stale guidance (improvement(guidance): make every ratchet shrink-only, scope rules to their files, fix stale guidance #8594)
- improvement(tools): delete unreferenced tool response types and the dead generic resource data path (improvement(tools): delete unreferenced tool response types and the dead generic resource data path #8596)
- improvement(tools): stop exporting tool types used only in their own file (improvement(tools): stop exporting tool types used only in their own file #8597)
- improvement(knip): check entry exports of private packages and delete their dead barrels (improvement(knip): check entry exports of private packages and delete their dead barrels #8595)
- feat(library): How do you build an AI voice agent with Twilio and Sim? (feat(library): How do you build an AI voice agent with Twilio and Sim? #8598)
- feat(library): Best HubSpot Alternatives for AI Marketing Automation in 2026 (feat(library): Best HubSpot Alternatives for AI Marketing Automation in 2026 #8599)
- feat(library): Slack AI Agent Security: Permissions, Data, and Audit Guide (feat(library): Slack AI Agent Security: Permissions, Data, and Audit Guide #8600)
- fix(docs): cap search query length and time out the embedding call (fix(docs): cap search query length and time out the embedding call #8601)
- fix(tools): check usage limits before running hosted-key tools via the API (fix(tools): check usage limits before running hosted-key tools via the API #8602)
- fix(code-placeholders): skip heredoc bodies when scanning shell quote context (fix(code-placeholders): skip heredoc bodies when scanning shell quote context #8603)
- fix(webhooks): check existing path owners before claiming on deploy (fix(webhooks): check existing path owners before claiming on deploy #8605)
- fix(tools): reject dot path segments in tool request URLs (fix(tools): reject dot path segments in tool request URLs #8604)
… their files, fix stale guidance (#8594) * improvement(guidance): make every ratchet shrink-only, scope rules to their files, fix stale guidance - check:test-patterns --update refuses new violations and fails closed on a missing baseline - check:react-query drops its unused, growable baseline: every violation fails, as it already did - check:utils drops the id.ts allowlist entry by rewording the comment that tripped it - constitution, react-performance, and url-state rules load only for the files they govern - guidance: Switch stays the boolean toggle, current chip names, @sim/utils/random, db-migrate covers the schema mock and drizzle sync, apps/sim/AGENTS.md maps common tasks to skills * chore(guidance): widen rule scopes to the changelog route, package hooks, and nuqs navigation helpers * chore(guidance): scope url-state by directory so app hooks and helpers stay covered
…ead generic resource data path (#8596) * improvement(tools): delete unreferenced tool response types and the dead generic resource data path - delete 168 exported tool *Response types nothing references (mostly umbrella unions) and the 24 local types only they used - add-integration and add-tools templates declare one response type per tool and no umbrella union - drop the never-set genericResourceData chat field; the generic resource panel renders its empty state directly * chore(skills): name InternalToolConfig beside ToolConfig in the response-type guidance
…file (#8597) - Drop `export` from 406 tool types referenced only inside their own types.ts - Delete 27 tool types used nowhere, plus 5 private param types only they referenced - Remove the dead `DataverseResponse` re-export from microsoft_dynamics_365/index.ts - Shrink check-unused-exports baseline by 434 entries; `export const` output schemas untouched
… their dead barrels (#8595) * improvement(knip): check entry exports of private packages and delete their dead barrels - knip.jsonc: includeEntryExports on for every private package except db - delete the bare @sim/utils and @sim/workflow-persistence barrels and their "." exports - drop unused re-exports from the workflow-renderer and desktop-bridge barrels; un-export symbols only used in-file - delete 7 unreferenced emcn icons - baseline the remaining 262 entry-export findings (one-time rule expansion via --update --init) * improvement(packages): resolve the private-package exports the entry-export check exposed - Delete exports nothing uses: RadarChart, ChipModalPromptBody, InputOTPSeparator, DropdownMenuGroup/Portal, legacy terminal tool names, and dead types and helpers - Drop `export` from declarations used only in their own file, and remove barrel re-exports no consumer imports - Tag getOAuthClientCapabilityFields and generateRandomBytes `@public`: generate-docs loads the first by file path, and check:utils names the second - Trim the workflow-authz mock to the module's remaining exports - The unused-exports baseline gains no entries and drops one * fix(emcn): keep ChipTimePicker in the barrel as documented chip-family API * chore(emcn): export CVA variants only once another module composes them * chore(emcn): delete the PillsRing icon, unused since the generic resource panel lost its entry list * chore(knip): shrink the unused-exports baseline after rebasing onto staging
…Guide (#8600) Co-authored-by: Sim Pi Agent <pi@sim.ai>
…8601) * fix(docs): cap search query length and time out the embedding call * fix(docs): truncate long search queries instead of dropping them * fix(docs): truncate search queries on a code point boundary
…e API (#8602) * fix(tools): check usage limits before running hosted-key tools via the API * fix(tools): gate hosted-key calls whose key is an unresolved variable reference * fix(tools): exempt variable references that resolve to the caller's own key * fix(tools): resolve the key reference with the registry's own resolver * fix(tools): decide hosted-key admission on registry-resolved params
* fix(tools): reject dot path segments in tool request URLs * fix(tools): match URL parser boundary stripping in dot-segment check
|
The latest updates on your projects. Learn more about Vercel for GitHub. |
There was a problem hiding this comment.
No issues found across 338 files
Confidence score: 5/5
- Automated review surfaced no issues in the provided summaries.
- No files require special attention.
Note: This PR contains a large number of files. cubic selects up to 200 of the highest-priority eligible files for this review, so some files may not have been reviewed.
Re-trigger cubic
|