Skip to content

Commit 6d46534

Browse files
chore: release v4.6.2 (#4942)
## Summary 5 improvements, 4 bug fixes. ## Improvements - Authorize stored realtime payload and output downloads against their owning run. Large packet hydration continues to work for run-, task-, tag-, and batch-scoped public tokens without permitting arbitrary packet reads. ([`76031b0a1`](76031b0)) - Show warm idle time and durable waits separately in chat agent traces. Durable waits now open the waitpoint inspector while waiting and after completion. Message span names are shorter, and repeated session IDs no longer crowd message-wait and default output-stream spans. ([`0754931cc`](0754931)) - chat.agent: the between-turns compaction check now receives the last step's token usage (the context the model actually held) instead of the turn's sum over every tool-calling step, so a single tool-using turn no longer compacts a short conversation. The summed figure is still available as `turnUsage` on the event. A head-start handover whose pending tool call completes under the same message id now replaces its spliced partial in the model lane directly instead of falling back to a full reconversion. ([`04c837569`](04c8375)) - Validate resource IDs when creating scoped public tokens. Explicitly empty IDs are now rejected instead of being interpreted as type-wide permissions. ([`22f8fb2b5`](22f8fb2)) ## Server changes These changes affect the self-hosted Docker image and Trigger.dev Cloud: - The banner that prompts you to set a billing limit now lets you choose to run without one, so you don't have to open your billing limit settings to dismiss it. - Org member invites now match emails case-insensitively, so an invite whose email casing differs from the invitee's account email can be accepted. ([#3849](#3849)) - Limit public access tokens created through the JWT endpoint to the API key's permissions and a maximum 24-hour lifetime. Rotated environment keys can no longer create tokens during their grace period. - Realtime session writers now receive authorization limited to the requested session channel. - Prevent public session access tokens from authorizing durable chat snapshot uploads <details> <summary>Raw changeset output</summary> # Releases ## @trigger.dev/build@4.6.2 ### Patch Changes - Updated dependencies: - `@trigger.dev/core@4.6.2` ## trigger.dev@4.6.2 ### Patch Changes - Updated dependencies: - `@trigger.dev/core@4.6.2` - `@trigger.dev/build@4.6.2` - `@trigger.dev/schema-to-json@4.6.2` ## @trigger.dev/core@4.6.2 ### Patch Changes - Authorize stored realtime payload and output downloads against their owning run. Large packet hydration continues to work for run-, task-, tag-, and batch-scoped public tokens without permitting arbitrary packet reads. ([`76031b0a1`](76031b0)) ## @trigger.dev/python@4.6.2 ### Patch Changes - Updated dependencies: - `@trigger.dev/sdk@4.6.2` - `@trigger.dev/core@4.6.2` - `@trigger.dev/build@4.6.2` ## @trigger.dev/react-hooks@4.6.2 ### Patch Changes - Updated dependencies: - `@trigger.dev/core@4.6.2` ## @trigger.dev/redis-worker@4.6.2 ### Patch Changes - Updated dependencies: - `@trigger.dev/core@4.6.2` ## @trigger.dev/rsc@4.6.2 ### Patch Changes - Updated dependencies: - `@trigger.dev/core@4.6.2` ## @trigger.dev/schema-to-json@4.6.2 ### Patch Changes - Updated dependencies: - `@trigger.dev/core@4.6.2` ## @trigger.dev/sdk@4.6.2 ### Patch Changes - Show warm idle time and durable waits separately in chat agent traces. Durable waits now open the waitpoint inspector while waiting and after completion. Message span names are shorter, and repeated session IDs no longer crowd message-wait and default output-stream spans. ([`0754931cc`](0754931)) - chat.agent: the between-turns compaction check now receives the last step's token usage (the context the model actually held) instead of the turn's sum over every tool-calling step, so a single tool-using turn no longer compacts a short conversation. The summed figure is still available as `turnUsage` on the event. A head-start handover whose pending tool call completes under the same message id now replaces its spliced partial in the model lane directly instead of falling back to a full reconversion. ([`04c837569`](04c8375)) - Validate resource IDs when creating scoped public tokens. Explicitly empty IDs are now rejected instead of being interpreted as type-wide permissions. ([`22f8fb2b5`](22f8fb2)) - Updated dependencies: - `@trigger.dev/core@4.6.2` </details> Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
1 parent 787ca8e commit 6d46534

29 files changed

Lines changed: 104 additions & 85 deletions

‎.changeset/chat-idle-wait-traces.md‎

Lines changed: 0 additions & 5 deletions
This file was deleted.

‎.changeset/outer-compaction-last-step-usage.md‎

Lines changed: 0 additions & 5 deletions
This file was deleted.

‎.changeset/strict-public-token-scope-ids.md‎

Lines changed: 0 additions & 5 deletions
This file was deleted.

‎.changeset/tidy-packets-scope.md‎

Lines changed: 0 additions & 5 deletions
This file was deleted.

‎.server-changes/billing-limit-banner-no-limit-button.md‎

Lines changed: 0 additions & 6 deletions
This file was deleted.

‎.server-changes/invite-email-case-insensitive.md‎

Lines changed: 0 additions & 6 deletions
This file was deleted.

‎.server-changes/jwt-mint-hardening.md‎

Lines changed: 0 additions & 6 deletions
This file was deleted.

‎.server-changes/narrow-session-stream-authorization.md‎

Lines changed: 0 additions & 6 deletions
This file was deleted.

‎.server-changes/restrict-session-snapshot-uploads.md‎

Lines changed: 0 additions & 6 deletions
This file was deleted.

‎hosting/k8s/helm/Chart.yaml‎

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -2,8 +2,8 @@ apiVersion: v2
22
name: trigger
33
description: The official Trigger.dev Helm chart
44
type: application
5-
version: 4.6.1
6-
appVersion: v4.6.1
5+
version: 4.6.2
6+
appVersion: v4.6.2
77
home: https://trigger.dev
88
sources:
99
- https://github.com/triggerdotdev/trigger.dev

0 commit comments

Comments
 (0)