Skip to content

[pull] master from reactive:master - #168

Open
pull[bot] wants to merge 73 commits into
erickirt:masterfrom
reactive:master
Open

[pull] master from reactive:master#168
pull[bot] wants to merge 73 commits into
erickirt:masterfrom
reactive:master

Conversation

@pull

@pull pull Bot commented May 30, 2026

Copy link
Copy Markdown

See Commits and Changes for more details.


Created by pull[bot] (v2.0.0-alpha.4)

Can you help keep this open source service alive? 💖 Please sponsor : )

@pull pull Bot locked and limited conversation to collaborators May 30, 2026
@pull pull Bot added ⤵️ pull merge-conflict Resolve conflicts manually labels May 30, 2026
renovate Bot and others added 25 commits June 2, 2026 08:20
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Bumps [launch-editor](https://github.com/vitejs/launch-editor) from 2.6.1 to 2.14.1.
- [Commits](vitejs/launch-editor@v2.6.1...v2.14.1)

---
updated-dependencies:
- dependency-name: launch-editor
  dependency-version: 2.14.1
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [launch-editor](https://github.com/vitejs/launch-editor) from 2.6.1 to 2.14.1.
- [Commits](vitejs/launch-editor@v2.6.1...v2.14.1)

---
updated-dependencies:
- dependency-name: launch-editor
  dependency-version: 2.14.1
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [shell-quote](https://github.com/ljharb/shell-quote) from 1.8.1 to 1.8.4.
- [Changelog](https://github.com/ljharb/shell-quote/blob/main/CHANGELOG.md)
- [Commits](ljharb/shell-quote@v1.8.1...v1.8.4)

---
updated-dependencies:
- dependency-name: shell-quote
  dependency-version: 1.8.4
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [esbuild](https://github.com/evanw/esbuild) from 0.28.0 to 0.28.1.
- [Release notes](https://github.com/evanw/esbuild/releases)
- [Changelog](https://github.com/evanw/esbuild/blob/main/CHANGELOG.md)
- [Commits](evanw/esbuild@v0.28.0...v0.28.1)

---
updated-dependencies:
- dependency-name: esbuild
  dependency-version: 0.28.1
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [joi](https://github.com/hapijs/joi) from 17.9.2 to 17.13.4.
- [Commits](hapijs/joi@v17.9.2...v17.13.4)

---
updated-dependencies:
- dependency-name: joi
  dependency-version: 17.13.4
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Removes [esbuild](https://github.com/evanw/esbuild). It's no longer used after updating ancestor dependency [vite](https://github.com/vitejs/vite/tree/HEAD/packages/vite). These dependencies need to be updated together.


Removes `esbuild`

Updates `vite` from 7.3.3 to 8.0.16
- [Release notes](https://github.com/vitejs/vite/releases)
- [Changelog](https://github.com/vitejs/vite/blob/main/packages/vite/CHANGELOG.md)
- [Commits](https://github.com/vitejs/vite/commits/v8.0.16/packages/vite)

---
updated-dependencies:
- dependency-name: esbuild
  dependency-version:
  dependency-type: indirect
- dependency-name: vite
  dependency-version: 8.0.16
  dependency-type: direct:development
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [shell-quote](https://github.com/ljharb/shell-quote) from 1.8.3 to 1.8.4.
- [Changelog](https://github.com/ljharb/shell-quote/blob/main/CHANGELOG.md)
- [Commits](ljharb/shell-quote@v1.8.3...v1.8.4)

---
updated-dependencies:
- dependency-name: shell-quote
  dependency-version: 1.8.4
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [tmp](https://github.com/raszi/node-tmp) from 0.2.6 to 0.2.7.
- [Changelog](https://github.com/raszi/node-tmp/blob/master/CHANGELOG.md)
- [Commits](raszi/node-tmp@v0.2.6...v0.2.7)

---
updated-dependencies:
- dependency-name: tmp
  dependency-version: 0.2.7
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Bumps [webpack-dev-server](https://github.com/webpack/webpack-dev-server) from 5.2.4 to 5.2.5.
- [Release notes](https://github.com/webpack/webpack-dev-server/releases)
- [Changelog](https://github.com/webpack/webpack-dev-server/blob/main/CHANGELOG.md)
- [Commits](webpack/webpack-dev-server@v5.2.4...v5.2.5)

---
updated-dependencies:
- dependency-name: webpack-dev-server
  dependency-version: 5.2.5
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [http-proxy-middleware](https://github.com/chimurai/http-proxy-middleware) from 2.0.9 to 2.0.10.
- [Release notes](https://github.com/chimurai/http-proxy-middleware/releases)
- [Changelog](https://github.com/chimurai/http-proxy-middleware/blob/v2.0.10/CHANGELOG.md)
- [Commits](chimurai/http-proxy-middleware@v2.0.9...v2.0.10)

---
updated-dependencies:
- dependency-name: http-proxy-middleware
  dependency-version: 2.0.10
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [undici](https://github.com/nodejs/undici) from 6.25.0 to 6.27.0.
- [Release notes](https://github.com/nodejs/undici/releases)
- [Commits](nodejs/undici@v6.25.0...v6.27.0)

---
updated-dependencies:
- dependency-name: undici
  dependency-version: 6.27.0
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
…3988)

Bumps [tar](https://github.com/isaacs/node-tar) from 7.5.11 to 7.5.17.
- [Release notes](https://github.com/isaacs/node-tar/releases)
- [Changelog](https://github.com/isaacs/node-tar/blob/main/CHANGELOG.md)
- [Commits](isaacs/node-tar@v7.5.11...v7.5.17)

---
updated-dependencies:
- dependency-name: tar
  dependency-version: 7.5.16
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Bumps [@sigstore/core](https://github.com/sigstore/sigstore-js) from 3.0.0 to 3.2.1.
- [Release notes](https://github.com/sigstore/sigstore-js/releases)
- [Commits](https://github.com/sigstore/sigstore-js/compare/@sigstore/core@3.0.0...@sigstore/core@3.2.1)

---
updated-dependencies:
- dependency-name: "@sigstore/core"
  dependency-version: 3.2.1
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
…4007)

* internal: Cut CircleCI validation critical path latency

- Compute esmodule relevance once in setup and persist a flag file;
  downstream jobs read the flag instead of doing a full checkout + git
  diff each (removes dead time from both hops of the esmodule chain)
- Run ci:build:types and ci:build-test-lib concurrently in setup (they
  are independent; babel/rollup compile from src, not tsc output)
- Pin Jest --maxWorkers to the resource class vCPUs; os.cpus() reports
  the docker host's CPUs, oversubscribing workers
- Remove no-op checkout depth parameter (built-in checkout ignores it)

* internal: Cache Playwright browsers in benchmark-react workflow

Keyed on the resolved playwright version so Renovate bumps invalidate
the cache automatically. On cache hit only system deps are installed.

* internal: retrigger CI to check unit_tests-native flakiness

* fix(ci): esmodule relevance diff silently failed on PR branches

git fetch --depth=1 of the base branch severs the merge base, making
the three-dot diff error out; with the old '|| true' fallback the
changed-file list came back empty and every esmodule job halted on PR
branches. Fetch with full history and fail open (treat as relevant)
when the diff cannot be computed.

* fix(ci): Don't cap Jest workers for ReactNative suites

The native suites are dominated by fake-timer waits rather than CPU;
capping to 4 workers serialized the heavy hook suites (16s -> 26s) and
flaked integration-garbage-collection's 5s timeout in two consecutive
runs. Coverage/DOM runs keep the cap where it measurably helps
(unit_tests-latest 49s -> 33s).

* internal: Simplify CI relevance detection and Playwright caching

- Unify fail-open handling in the esmodule detect step: one
  ESMODULE_RELEVANT boolean instead of a sentinel filename that
  depended on the grep regex matching it; identical diff-failure
  behavior on default-branch and PR paths
- Fetch base branch with --filter=blob:none (commit graph only is
  needed for --name-only diffs; degrades to full fetch when the
  server ignores the filter)
- Add examples/normalizr-relationships/ to the relevance regex; it is
  built by validate-esmodule-browser-build
- Log fail-open explicitly when the relevance flag is missing
- Replace inline PID juggling with run-p via new ci:build:setup script
  (npm-run-all already a dev dependency; runnable locally)
- Merge identical ^17/^18 Jest branches
- Merge conditional Playwright install steps into one; resolve the
  playwright version from the workspace explicitly so hoisting changes
  can't break the cache key
- Document worker pinning and the relevance flag in AGENTS.md

* internal: Move CI guidance from AGENTS.md to glob-scoped cursor rule

Only attaches when editing .circleci/** or .github/workflows/*.yml
instead of costing context on every conversation.

* internal: Halt esmodule jobs before attach_workspace

Transport the relevance flag via save_cache/restore_cache (keyed on
CIRCLE_SHA1) instead of the workspace. Halted jobs previously paid
13-16s attaching the ~1.3GB workspace before reading the flag; a
cache restore of one file takes ~1s. Cache miss fails open (jobs
run). Detection is deterministic per commit, so the immutable cache
key is safe across reruns.
Bumps [js-yaml](https://github.com/nodeca/js-yaml) from 3.14.2 to 3.15.0.
- [Changelog](https://github.com/nodeca/js-yaml/blob/master/CHANGELOG.md)
- [Commits](nodeca/js-yaml@3.14.2...3.15.0)

---
updated-dependencies:
- dependency-name: js-yaml
  dependency-version: 3.15.0
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
* Simplify website Playground: remove dead code, consolidate duplication, perf fixes

- Delete unused usingMonaco.ts; drop unused imports/exports/props
  (transformCode, monacoMaster, largeOptions/large pathway, lastChild,
  usePrismTheme, useBaseUrl) and stale commented-out code
- Consolidate UA regexes into isMobileOrBot.ts; skip Monaco + type bundle
  downloads on mobile (was bot-only) since mobile renders LiveEditor
- Share Monaco CDN base URL via MONACO_CDN_VS constant
- Replace hand-rolled LiveProviderProps with ComponentProps<typeof LiveProvider>
- Use docusaurus parseLanguage instead of hand-rolled regex
- Extract shared StoreToggle row from StoreInspector for preview fallback
- Merge identical FixturePreview function-response branches
- CurrentTime: 1s interval (was ~4ms) + hoisted Intl formatter
- Tree: hoist Intl formatter and color map to module scope
- Defer preview code with useDeferredValue so typing isn't blocked by
  re-transpilation; memoize PlaygroundMonacoEditor and its loading element
- useAutoHeight: skip forced layout when computed height is unchanged
- Minor type/readability fixes (double negation, spread-delete,
  collapsible boolean, optional chain, endpoint cast, useId comment)

* Fix Playground handler and lazy component types

- Type PreviewWithScopeLazy with the real component so props typecheck
- Use MouseEventHandler<HTMLDivElement> for the store toggle instead of
  mismatched HTMLLIElement event types
ntucker and others added 30 commits July 12, 2026 11:23
Exclude playground snippets from tsc, fix the real website TypeScript baseline, add a canonical typecheck command and CI gate, and replace the global console.error demotion with a scoped LivePreview hook.

Co-authored-by: Cursor <cursoragent@cursor.com>
Align GH Actions with CircleCI and .nvmrc on the Current Node line.

Co-authored-by: Cursor <cursoragent@cursor.com>
#4026)

* fix(website): Clear docs hydration errors and playground console noise

Invalid MDX markup caused React hydration warnings, the SWAPI demo URL
redirected without CORS, and react-live's classic JSX / ErrorBoundary
noise cluttered the console during live previews.

Co-authored-by: Cursor <cursoragent@cursor.com>

* internal(website): Document playground console demotion ownership policy

Clarify that matchers only cover third-party react-live/React noise;
@data-client and first-party site issues must be fixed, not hidden.

Co-authored-by: Cursor <cursoragent@cursor.com>

---------

Co-authored-by: Cursor <cursoragent@cursor.com>
Generate version-matched CDN hints and inject them before Monaco initialization so static and client-side navigations avoid stale hashes and competing type preloads.

Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
…4030)

* perf(website): Mount only the selected Demo playground

Avoid hydrating Monaco and DataProvider for every protocol tab on the
homepage. Align CodeProvider tab sync with Docusaurus and fix
useTabStorage double-prefixing localStorage keys.

Co-authored-by: Cursor <cursoragent@cursor.com>

* fix(website): Keep Demo protocols mounted for SSG, defer hydration

Restore mounting all protocol sandboxes so open-file source stays in
static HTML for crawlers. Skip LivePreview while hidden and latch Monaco
hydration on first show so inactive protocols stay cheap without losing
editor state after a visit.

Co-authored-by: Cursor <cursoragent@cursor.com>

---------

Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
)

* fix(website): Strip multiline imports in playground transformCode

Prettier-wrapped import { … } from blocks were only partially removed,
leaving orphan } from '…' syntax that broke GraphQL live previews.
Also include Playground tests in the ReactDOM Jest project.

Co-authored-by: Cursor <cursoragent@cursor.com>

* fix(website): Match side-effect imports in transformCode

Require whitespace or a from-clause before the module string so
import './setup' is stripped like other static imports.

Co-authored-by: Cursor <cursoragent@cursor.com>

* fix(ci): Persist Playground tests without breaking CircleCI workspace

CircleCI attach_workspace omits website/, so a hard-coded Jest root
failed validation. Only add the Playground root when present, and
persist that path so ReactDOM CI still runs transformCode/codeModel.

Co-authored-by: Cursor <cursoragent@cursor.com>

---------

Co-authored-by: Cursor <cursoragent@cursor.com>
Bumps [websocket-driver](https://github.com/faye/websocket-driver-node) from 0.7.4 to 0.7.5.
- [Changelog](https://github.com/faye/websocket-driver-node/blob/main/CHANGELOG.md)
- [Commits](faye/websocket-driver-node@0.7.4...0.7.5)

---
updated-dependencies:
- dependency-name: websocket-driver
  dependency-version: 0.7.5
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [websocket-driver](https://github.com/faye/websocket-driver-node) from 0.7.4 to 0.7.5.
- [Changelog](https://github.com/faye/websocket-driver-node/blob/main/CHANGELOG.md)
- [Commits](faye/websocket-driver-node@0.7.4...0.7.5)

---
updated-dependencies:
- dependency-name: websocket-driver
  dependency-version: 0.7.5
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Expand plans/garbage-collection.md Validation gates with layered harnesses,
scenario axes, lifecycle boundaries, result vocabulary, calibration rules,
priorities, and automation boundary while preserving existing GC direction.
Bumps [brace-expansion](https://github.com/juliangruber/brace-expansion) from 1.1.11 to 1.1.16.
- [Release notes](https://github.com/juliangruber/brace-expansion/releases)
- [Commits](juliangruber/brace-expansion@1.1.11...v1.1.16)

---
updated-dependencies:
- dependency-name: brace-expansion
  dependency-version: 1.1.16
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [body-parser](https://github.com/expressjs/body-parser) from 1.20.5 to 1.20.6.
- [Release notes](https://github.com/expressjs/body-parser/releases)
- [Changelog](https://github.com/expressjs/body-parser/blob/master/HISTORY.md)
- [Commits](expressjs/body-parser@1.20.5...1.20.6)

---
updated-dependencies:
- dependency-name: body-parser
  dependency-version: 1.20.6
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [shell-quote](https://github.com/ljharb/shell-quote) from 1.8.4 to 1.10.0.
- [Changelog](https://github.com/ljharb/shell-quote/blob/main/CHANGELOG.md)
- [Commits](ljharb/shell-quote@v1.8.4...v1.10.0)

---
updated-dependencies:
- dependency-name: shell-quote
  dependency-version: 1.10.0
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [webpack-dev-server](https://github.com/webpack/webpack-dev-server) from 5.2.5 to 5.2.6.
- [Release notes](https://github.com/webpack/webpack-dev-server/releases)
- [Changelog](https://github.com/webpack/webpack-dev-server/blob/v5.2.6/CHANGELOG.md)
- [Commits](webpack/webpack-dev-server@v5.2.5...v5.2.6)

---
updated-dependencies:
- dependency-name: webpack-dev-server
  dependency-version: 5.2.6
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [fast-uri](https://github.com/fastify/fast-uri) from 3.1.2 to 3.1.4.
- [Release notes](https://github.com/fastify/fast-uri/releases)
- [Commits](fastify/fast-uri@v3.1.2...v3.1.4)

---
updated-dependencies:
- dependency-name: fast-uri
  dependency-version: 3.1.4
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [svgo](https://github.com/svg/svgo) from 3.3.3 to 3.3.4.
- [Release notes](https://github.com/svg/svgo/releases)
- [Commits](svg/svgo@v3.3.3...v3.3.4)

---
updated-dependencies:
- dependency-name: svgo
  dependency-version: 3.3.4
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
#4050)

Bumps [fast-uri](https://github.com/fastify/fast-uri) from 3.1.2 to 3.1.4.
- [Release notes](https://github.com/fastify/fast-uri/releases)
- [Commits](fastify/fast-uri@v3.1.2...v3.1.4)

---
updated-dependencies:
- dependency-name: fast-uri
  dependency-version: 3.1.4
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
* fix(website): Resolve monaco-editor root under 0.56 exports map

monaco-editor 0.56 remaps `./*` to esm paths, so require.resolve of
package.json crashed docusaurus config before the preload manifest
could regenerate.

Co-authored-by: Cursor <cursoragent@cursor.com>

* internal(website): Derive Monaco roots from package entry path

Avoid the package.json walk now that we know the 0.56 entry is
min/vs/index.js.

Co-authored-by: Cursor <cursoragent@cursor.com>

* perf(website): Preload Monaco 0.56 AMD bootstrap closure

BFS static deps from editor.main so nested index modules
(basic-languages, toggleHighContrast, editorWorkerHost) no longer
waterfall. Also migrate to monaco.typescript and pin DiffEditor to
the built-in advanced algorithm (CDN cannot load @vscode/diff).

Co-authored-by: Cursor <cursoragent@cursor.com>

---------

Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Force patched versions via yarn resolutions and example npm overrides,
and refresh lockfiles across root and standalone examples.

Co-authored-by: Cursor <cursoragent@cursor.com>
Bumps [ip-address](https://github.com/beaugunderson/ip-address) from 10.2.0 to 10.4.0.
- [Release notes](https://github.com/beaugunderson/ip-address/releases)
- [Commits](beaugunderson/ip-address@v10.2.0...v10.4.0)

---
updated-dependencies:
- dependency-name: ip-address
  dependency-version: 10.4.0
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
* pkg(security): Bump transitive CVEs and non-major deps

Force patched versions via yarn resolutions and example npm overrides,
refresh lockfiles, and fold in open Renovate/Dependabot dependency bumps.

Co-authored-by: Cursor <cursoragent@cursor.com>

* fix(ci): Keep antd at 6.5.2 to avoid Yarn quarantine

antd@6.5.4 is quarantined by Yarn's time gate, which broke the CircleCI
setup job when github-app is added to the workspace.

Co-authored-by: Cursor <cursoragent@cursor.com>

* fix(ci): Deduplicate @types/react for website typecheck

Force a single @types/react/@types/react-dom version via resolutions so
Docusaurus nested types match the workspace after the 19.2.18 bump.

Co-authored-by: Cursor <cursoragent@cursor.com>

* internal(pkg): Drop unnecessary resolution and override pins

Keep lockfile-driven CVE bumps and only retain package.json changes that
update existing entries or are required (@types/react dedupe).

Co-authored-by: Cursor <cursoragent@cursor.com>

* fix(ci): Revert @types/react 19.2.18 for TS 4.0 matrix

The forced 19.2.18 resolution blocked esmodule-types-4.0 from installing
@types/react@ts4.0, so tsc 4.0 failed on template literal types.

Co-authored-by: Cursor <cursoragent@cursor.com>

---------

Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
SCP-style git+ssh://git@github.com:org/repo.git is not a valid WHATWG URL.
Node 26's url.parse() throws ERR_INVALID_ARG_VALUE (Invalid port), which
breaks npm-run-all (run-s) during yarn build:bundle.

Co-authored-by: Cursor Agent <cursoragent@cursor.com>
* internal: Move agent skills to .agents/skills/

Use the vendor-neutral Agent Skills path so Cursor, Codex, and
npx skills all discover the same repo skills.

Co-authored-by: Nathaniel Tucker <me@ntucker.me>

* internal: Keep advisor-workflow Cursor-only

Move advisor-workflow back to .cursor/skills/ so Codex does not
load it, and point initialize at repo-root CONTRIBUTING.md.

Co-authored-by: Nathaniel Tucker <me@ntucker.me>

---------

Co-authored-by: Cursor Agent <cursoragent@cursor.com>
Use Claude Fable 5.1 at extra-high effort instead of Fable 5 high thinking.
Fable 5.1 thinking is always-on; effort=xhigh is the documented control.

Co-authored-by: Cursor Agent <cursoragent@cursor.com>
…decision (#4075)

* internal: Make principal-advisor blocking vs background a dependency decision

Drop the artificial 'at most once per task' cap in favor of the resume
mechanism for follow-ups, and stop mandating background launch: when the
decision gates downstream work (the common case for architecture spikes)
the consult must block, since background results cannot be awaited and
implementing against a guess risks larger rework than the wait.

Co-authored-by: natmaster <natmaster@gmail.com>

* internal: Measure principal-advisor blast radius over the project's future

Critical decisions include those whose consequences outlive the current
task - public contracts, constraints on later work, and bearing on
GOALS.md - so the advisor description, its reasoning guidance, and the
skill's decision-point extraction now weigh that horizon explicitly.

Co-authored-by: natmaster <natmaster@gmail.com>

* internal: State consult-worthiness as lifetime cost principles

Replace the instance list (public contract, GOALS.md) with two
generalizable criteria for whether a consult is worth it: how costly the
decision is to reverse once depended upon, and whether getting it right
lets the design absorb future use cases without change. Apply the same
lifetime framing to the skill's spend policy and cost principles.

Co-authored-by: natmaster <natmaster@gmail.com>

* internal: State lifetime-cost test as principle, without instances

Replace the parenthetical example list with the three factors that
determine a decision's stakes: how much will come to depend on it, how
costly it is to reverse once that dependence exists, and how wide a
range of future demands it must hold under without change.

Co-authored-by: natmaster <natmaster@gmail.com>

* internal: Tighten principal-advisor description

Remove the duplicated cost threshold and details already carried by the
advisor-workflow skill (assumption re-check on arrival, packet field
list); same routing rules in ~100 words instead of ~165.

Co-authored-by: natmaster <natmaster@gmail.com>

* internal: Align principal-advisor reasoning with the three stakes factors; fix background claim

The advisor's lifetime bullet omitted 'how much will come to depend on
it', so advisor and parent scored stakes on different rubrics. The skill
claimed background results 'cannot be polled or awaited'; Cursor docs
state the parent can read background progress files, so the accurate and
sufficient claim is that the parent cannot block on a background
subagent.

Co-authored-by: natmaster <natmaster@gmail.com>

---------

Co-authored-by: Cursor Agent <cursoragent@cursor.com>
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

⤵️ pull merge-conflict Resolve conflicts manually

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant