Skip to content

Release v1.3.1: workspace reliability and compatible security patches - #5755

Merged
loopx-agent merged 3 commits into
mainfrom
codex/release-1.3.1
Oct 6, 2026
Merged

loopx-agent merged 3 commits into
mainfrom
codex/release-1.3.1

Conversation

@loopx-agent

@loopx-agent loopx-agent commented Oct 6, 2026 •

Copy link
Copy Markdown
Collaborator

Problem and result

Prepare an expedited v1.3.1 patch release from main baseline73f429aad3399db9e52768e953de2743d02b2f73. Existing installs need a distinct package/tag for the merged Chat, workspace, collaboration and desktop fixes. The version owners, generated manpage and bilingual developer-book anchors move together to1.3.1.

The dashboard applies seroval1.6.8, source-map-js1.2.2 and linkify-it6.1.0. The root fix uses the new named LinkifyIt export and bundled types, removes the obsolete @types package, and explicitly sets urlAuth:true to preserve existing authenticated-URL recognition. Complete-address checks, dangerous-protocol refusal, inert HTML and existing rendering regressions pass. No state/authority contract changes. The dependency-only #5753 build failure remains documented at its original head.

Validation boundary

Version/CLI-manpage/release-document/developer-book smokes, semantic advisory and diff hygiene pass; the initial missing book-index anchors were corrected and the existing smoke rerun passed.81 focused Python regressions pass. Packaged frontend build and npm audit pass after the two dependency patches (zero dashboard vulnerabilities). Exact-head quality, focused UI regressions and merge-readiness passed before the authorized admin merge. PR CI is not queried. Full Python/public smoke, new paid model matrix and unavailable backend/platform qualification are not rerun for this expedited release; v1.3.0 evidence remains prior-version evidence, not a certificate for the new source.

No new framework/helper is needed: existing version and dependency owners suffice. Rollback is the previous immutable package/tag; persisted data is not automatically migrated or restored by a package downgrade.

Community Contributors

中文说明

快速发布1.3.1:对齐两个版本源、生成 manpage 和中英文开发者手册锚点,收录基线 main 已合入的修复。依赖更新 seroval、source-map-js 和 linkify-it6.1;根因修复采用命名导出和内置类型,移除旧 @types 包,显式 urlAuth:true 保留原链接识别策略。生产构建及完整/截断 userinfo、危险协议和惰性 HTML 的原有回归通过。定向验证与来源/制品回读继续执行;不把1.3.0的全量与模型结果重新标为1.3.1通过。

社区贡献者

Companion: Personal 1.3.1 illustrated upgrade guide, with verified ownership and current-tag screenshots. All 12 public assets, GitHub/PyPI hash equivalence, actual 1.3.0-to-1.3.1 upgrades, signed desktop-stable feed and a fresh CLI stable installation/source-manifest readback passed; this is an explicitly expedited qualification, not a new full model matrix.

配套:个人 1.3.1 图文升级指南,ownership 与当前 tag 截图已回读。12个公开资产、GitHub/PyPI哈希、实际1.3.0→1.3.1升级、签名desktop-stable feed及CLI stable全新安装/来源manifest均已回读;本次为明确授权的加速资格化,未新增完整模型矩阵。

@loopx-agent loopx-agent left a comment

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewer: model_agent; gpt-6.1-sol; OpenAI; runtime_reported; reasoning_effort=xhigh.

Approval conclusion (author-owned PR; GitHub blocks formal self-approval).

动机

无阻塞发现。受影响的是升级 LoopX 的用户与发布维护者:主线修复已合入,仍缺少独立补丁版本;同时直接升级链接识别库会使前端无法编译。升级后用户获得明确的1.3.1包身份和可正常构建的安全链接显示。非目标是改变 Goal 权限、持久状态或扩大全量资格声明。这里的前端修复不是仅撤回升级:真实新版本 API 已适配,原链接边界继续受验证。

改动思路

精确审阅 e432cecc8ec03ee8e82d8cd88b914fa6d66136c9,基线 73f429aad3399db9e52768e953de2743d02b2f73。读取现有版本合同 docs/product/release-readiness.md,固定 revision 73f429aad3399db9e52768e953de2743d02b2f73,验收项 bump loopx.__version__ and pyproject.toml together;规范文本要求版本源与当前帮助/手册检查点一致。既有安全 Markdown owner 是 markdown.tsx,而非依赖自动化的新决定源。复用版本、lockfile和renderer,不增加控制面、协议、helper或代理包装。

具体改动

loopx/__init__.py::__version__ 与 pyproject.toml 同步1.3.1;生成 manpage及中英开发者手册四处当前锚点同步,历史版本不改。package.json/lockfile更新 linkify-it6.1、其 uc.micro3、seroval1.6.8与source-map-js1.2.2,并移除多余 @types/linkify-it5。完整diff共10个现有文件,全部为上述版本/依赖/适配内容,没有新模块或状态。

markdown.tsx::webLinks 使用6.x命名导出 LinkifyIt,显式 urlAuth:true 保留原URL用户信息识别;fuzzyLink/fuzzyEmail仍关闭,ftp/mailto/相对协议仍禁用。completeWebMatch 继续阻止截断 userinfo 被误识别成其他host,React节点保持 raw HTML 惰性。Chat和TeamArtifactContent复用 MarkdownText,实际SSR检查覆盖两入口、中文标点、路径括号/query、普通显式链接、代码块、不完整/完整userinfo、危险协议和HTML。生产TypeScript/Vite构建、npm ci与审计清零均通过。

对主干的风险

最强反例是编译修好了却改变链接目标或使旧文本变成可执行HTML。保留现有安全rendering断言,team-report、team-artifact-comparison与attention-details三组回归通过,没有修改预期或阈值。依赖-only #5753 原head实测TS2351失败;此head相同生产构建通过,API与类型来源已直接核对。移除旧 @types 避免两个类型来源;不需要新兼容wrapper或长期双版本分支。

版本/manifest正反例、manpage、release文档、修正后的book检查、语义advisory和diff hygiene通过。81项定向Python回归通过,产品Python内容与该运行一致;之后只改前端依赖及renderer。初始book锚点漏更失败已保留并由补齐锚点后的同一smoke通过覆盖。strict quality与风险canary按最终diff执行;无PR CI查询。全量Python/public smoke、新真实模型矩阵及缺失backend/platform环境按授权快速路径不重跑,不将1.3.0证据冒称新source通过。

权限、默认能力开关、结算与调度规则保持;既有有限URL自动识别继续生效,未授予任何网络访问或外发权限。公共差异没有凭据、本机路径、私有日志或内部链接。版本回退按现有安装owner,包降级不是数据恢复;原有版式和第一屏导航未改。long_horizon preserved:无控制面执行链更改;user_experience improved:升级身份一致且新依赖可以保留安全链接阅读。

我的整体评价

APPROVE。根因修复、依赖安全更新和补丁版本一致性形成同一可回滚发行包,实测覆盖产品消费者及旧失败,不靠审计清零代替构建。未来重构检查已移除过时独立类型来源,保留仍有真实负例的完整地址guard;没有值得再加的抽象。授权快速发布不会扩大资格,制品/PyPI/stable/个人指南仍需发布后独立回读;精确head closeout与readiness继续是合并前条件。

English verdict: APPROVE at e432cecc8ec03ee8e82d8cd88b914fa6d66136c9. Version owners/help/book anchors agree on1.3.1. linkify-it6.1 uses its named class and bundled types; explicit urlAuth preserves policy and complete-address refusal remains. Production build, clean install/zero audit, three real renderer regressions, version/docs checks and81 focused Python tests pass. Full qualification is intentionally not re-certified; public artifact readbacks remain release operations. No authority/state/UI-navigation expansion; no PR CI queried.

@loopx-agent
loopx-agent merged commit 7445ae3 into main Oct 6, 2026
9 checks passed
@loopx-agent
loopx-agent deleted the codex/release-1.3.1 branch October 6, 2026 08:06
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant