Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
17 commits
Select commit Hold shift + click to select a range
1b7e5ac
feat(model-capabilities): drive model capabilities and labels from on…
wpfleger96 Aug 17, 2026
f716eef
fix(desktop): enforce shared agent access across devices (#6086)
wesbillman Aug 17, 2026
edc4a09
feat(workflows): add responsive library card actions (#6008)
tellaho Aug 17, 2026
5b3f037
fix(acp): replace Goose native system prompt (#5964)
atishpatel Aug 17, 2026
54f1121
fix(acp): gate relay-signed workflow messages on their attributed aut…
TheSentinel454 Aug 17, 2026
d12d825
fix(desktop): resolve agent profiles through one archive-aware select…
wpfleger96 Aug 17, 2026
076081b
Rename Bumble agent to Pollen (#5864)
klopez4212 Aug 17, 2026
85bacea
Remove GitHub security advisory commitment (#6144)
jmecom Aug 17, 2026
a282e06
fix(cli): keep project replacement timestamps at or after wall clock …
Illuminfti Aug 17, 2026
57feca2
fix(desktop): repair dropped team membership links at boot and on edi…
wpfleger96 Aug 17, 2026
439c037
fix(desktop): align preview sidebar row styling (#6163)
wesbillman Aug 17, 2026
f64899e
Remove Startup Recovery section in base prompt (#6161)
salman1993 Aug 17, 2026
f7a01bd
fix(workflows): preserve multi-channel listing semantics (#6009)
tellaho Aug 17, 2026
7f61cf4
Preserve managed agent mentions during relay errors (#6167)
wesbillman Aug 17, 2026
c8c8eb5
chore(release): release Buzz Desktop version 0.5.15 (#6173)
wesbillman Aug 17, 2026
f8692fa
test(desktop): cover exact workflow batch limit (#6168)
wesbillman Aug 17, 2026
a60636b
Merge remote-tracking branch 'upstream/main' into upstream-sync-20260818
adrienlacombe Aug 18, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 4 additions & 0 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -46,10 +46,14 @@ jobs:
- 'deny.toml'
- '.github/workflows/ci.yml'
- 'scripts/run-tests.sh'
- 'scripts/model-capabilities.json'
- 'scripts/normative-corpus.json'
- 'justfile'
desktop:
- 'scripts/check-file-sizes-core.mjs'
- 'scripts/check-file-sizes-core.test.mjs'
- 'scripts/model-capabilities.json'
- 'scripts/normative-corpus.json'
- 'desktop/**'
- '!desktop/src-tauri/**'
- 'pnpm-lock.yaml'
Expand Down
14 changes: 7 additions & 7 deletions .release/desktop-candidate.json
Original file line number Diff line number Diff line change
@@ -1,10 +1,10 @@
{
"schema": 2,
"version": "0.5.14",
"base_sha": "1b3dbcaaea882eeea90359c1db02e306d2f4f50a",
"previous_tag": "desktop-v0.5.13",
"previous_base_sha": "09768100ec3420f0aa7cd278bd00fe0baab5de8d",
"previous_merge_sha": "51beba603886d34e751349d12b33c0c5aeb92c28",
"tag": "desktop-v0.5.14",
"commit_count": 1
"version": "0.5.15",
"base_sha": "7f61cf431af1d8f0480a0baf525881a12f2be7f2",
"previous_tag": "desktop-v0.5.14",
"previous_base_sha": "1b3dbcaaea882eeea90359c1db02e306d2f4f50a",
"previous_merge_sha": "82f7ed1532f50e0d28afca5580ed522f1c2ef1ca",
"tag": "desktop-v0.5.15",
"commit_count": 18
}
28 changes: 28 additions & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
@@ -1,5 +1,33 @@
# Changelog

## v0.5.15

### Desktop and shared changes

- Preserve managed agent mentions during relay errors ([#6167](https://github.com/block/buzz/pull/6167)) ([`7f61cf431af1d8f0480a0baf525881a12f2be7f2`](https://github.com/block/buzz/commit/7f61cf431af1d8f0480a0baf525881a12f2be7f2))
- fix(workflows): preserve multi-channel listing semantics ([#6009](https://github.com/block/buzz/pull/6009)) ([`f7a01bda7b1bf95cdbc9dc21bb69970955b14ecc`](https://github.com/block/buzz/commit/f7a01bda7b1bf95cdbc9dc21bb69970955b14ecc))
- fix(desktop): align preview sidebar row styling ([#6163](https://github.com/block/buzz/pull/6163)) ([`439c03749182495ee09f85a73423dd17e7ccda61`](https://github.com/block/buzz/commit/439c03749182495ee09f85a73423dd17e7ccda61))
- fix(desktop): repair dropped team membership links at boot and on edit ([#5904](https://github.com/block/buzz/pull/5904)) ([`57feca2f20bb3434d70ce770b9ed98b1c1472332`](https://github.com/block/buzz/commit/57feca2f20bb3434d70ce770b9ed98b1c1472332))
- Rename Bumble agent to Pollen ([#5864](https://github.com/block/buzz/pull/5864)) ([`076081bfc646f8fdf8ff9dc6e00843b5bdae0ad0`](https://github.com/block/buzz/commit/076081bfc646f8fdf8ff9dc6e00843b5bdae0ad0))
- fix(desktop): resolve agent profiles through one archive-aware selector ([#5706](https://github.com/block/buzz/pull/5706)) ([`d12d82577818a95babac4d30cf242c46124feb5e`](https://github.com/block/buzz/commit/d12d82577818a95babac4d30cf242c46124feb5e))
- feat(workflows): add responsive library card actions ([#6008](https://github.com/block/buzz/pull/6008)) ([`edc4a09aaa41c29e2495a28247c895febaf6587d`](https://github.com/block/buzz/commit/edc4a09aaa41c29e2495a28247c895febaf6587d))
- fix(desktop): enforce shared agent access across devices ([#6086](https://github.com/block/buzz/pull/6086)) ([`f716eef437dcf91994518b8df7f581e86bb51748`](https://github.com/block/buzz/commit/f716eef437dcf91994518b8df7f581e86bb51748))
- feat(model-capabilities): drive model capabilities and labels from one manifest ([#5597](https://github.com/block/buzz/pull/5597)) ([`1b7e5ac1be641f5ecc2b2a0ba37a1dc400e073c9`](https://github.com/block/buzz/commit/1b7e5ac1be641f5ecc2b2a0ba37a1dc400e073c9))
- fix(desktop): hide the offcanvas-collapsed sidebar so it stops painting over the community rail ([#5947](https://github.com/block/buzz/pull/5947)) ([`78cbffeb64c01220e705adf0aa9690fdbd0d7a37`](https://github.com/block/buzz/commit/78cbffeb64c01220e705adf0aa9690fdbd0d7a37))

### Other repository changes

- Remove Startup Recovery section in base prompt ([#6161](https://github.com/block/buzz/pull/6161)) ([`f64899e5d17df4c928ea415a5f42052120edaecb`](https://github.com/block/buzz/commit/f64899e5d17df4c928ea415a5f42052120edaecb))
- fix(cli): keep project replacement timestamps at or after wall clock ([#5666](https://github.com/block/buzz/pull/5666)) ([`a282e0643fe0f14ace4d9b57ead99d0635e38995`](https://github.com/block/buzz/commit/a282e0643fe0f14ace4d9b57ead99d0635e38995))
- Remove GitHub security advisory commitment ([#6144](https://github.com/block/buzz/pull/6144)) ([`85bacea52b8359999f22c6ac07207a130809c488`](https://github.com/block/buzz/commit/85bacea52b8359999f22c6ac07207a130809c488))
- fix(acp): gate relay-signed workflow messages on their attributed author ([#6129](https://github.com/block/buzz/pull/6129)) ([`54f11219efe6b2617ba74d1ef8701fb5413956d8`](https://github.com/block/buzz/commit/54f11219efe6b2617ba74d1ef8701fb5413956d8))
- fix(acp): replace Goose native system prompt ([#5964](https://github.com/block/buzz/pull/5964)) ([`5b3f0375a26843d73b29b55cc2f3c313bd857ccb`](https://github.com/block/buzz/commit/5b3f0375a26843d73b29b55cc2f3c313bd857ccb))
- docs: refresh agent development guidance ([#6049](https://github.com/block/buzz/pull/6049)) ([`f956e6fe06a76e50cbd8fba1a162482e752e7f1a`](https://github.com/block/buzz/commit/f956e6fe06a76e50cbd8fba1a162482e752e7f1a))
- feat(mobile): require device authentication for identity export ([#5116](https://github.com/block/buzz/pull/5116)) ([`d8281b9c93395f15d55091b131bb2747a0a3da8a`](https://github.com/block/buzz/commit/d8281b9c93395f15d55091b131bb2747a0a3da8a))
- Polish mobile message threads and composer ([#5645](https://github.com/block/buzz/pull/5645)) ([`69107dc3bfecbb80cc5f5b8bb6a7647ad054ce57`](https://github.com/block/buzz/commit/69107dc3bfecbb80cc5f5b8bb6a7647ad054ce57))

[Compare desktop-v0.5.14...desktop-v0.5.15](https://github.com/block/buzz/compare/desktop-v0.5.14...desktop-v0.5.15)

## v0.5.14

### Desktop and shared changes
Expand Down
17 changes: 17 additions & 0 deletions Justfile
Original file line number Diff line number Diff line change
Expand Up @@ -323,6 +323,14 @@ test-unit:
# because nothing in CI runs `cargo test --workspace` — workspace
# membership alone buys clippy/check, not a single executed test.
cargo nextest run -p buzz-backend-kubernetes
# buzz-agent model-capabilities corpus: the Rust half of the
# cross-language drift guard. `model_capabilities.rs` embeds
# scripts/model-capabilities.json + scripts/normative-corpus.json via
# include_str! and replays all 103 vectors as pure in-process tests (no
# infra). Enumerated explicitly because nothing in CI runs
# `cargo test --workspace`; without this step a manifest edit that
# diverges Rust from the corpus ships green.
cargo nextest run -p buzz-agent --lib
else
./scripts/run-tests.sh unit
fi
Expand All @@ -331,6 +339,15 @@ test-unit:
test-integration:
./scripts/run-tests.sh integration

# Regenerate the model-capability normative corpus from the production Rust
# resolver. The corpus is a golden snapshot, never hand-edited: this runs the
# `#[ignore]`d writer test in buzz-agent, which serializes `resolve()` over the
# inputs-only question table to scripts/normative-corpus.json. Run this after
# any model-capabilities.json edit, then commit the regenerated file. The
# `corpus_matches_generated_snapshot` gate fails CI if the committed file drifts.
regen-model-corpus:
cargo test -p buzz-agent --lib model_capabilities::tests::regen_corpus_file -- --ignored --exact

# Buzz shared compute e2e: current desktop discovery/admission logic and
# Playwright UI coverage.
mesh-e2e:
Expand Down
4 changes: 1 addition & 3 deletions SECURITY.md
Original file line number Diff line number Diff line change
Expand Up @@ -121,6 +121,4 @@ We use `cargo audit` in CI to scan for known vulnerabilities in dependencies.
## Disclosure Policy

We follow [coordinated disclosure](https://en.wikipedia.org/wiki/Coordinated_vulnerability_disclosure).
Once a fix is ready and released, we will publish a security advisory on
GitHub describing the vulnerability, its impact, and the fix. Reporters will
be credited unless they request anonymity.
Reporters will be credited unless they request anonymity.
8 changes: 4 additions & 4 deletions crates/buzz-acp/src/acp.rs
Original file line number Diff line number Diff line change
Expand Up @@ -702,7 +702,7 @@ impl AcpClient {
.session_id)
}

/// Send Goose's custom system-prompt request after `session/new`.
/// Replace Goose's native system prompt after `session/new`.
pub async fn session_set_goose_system_prompt(
&mut self,
session_id: &str,
Expand All @@ -712,7 +712,7 @@ impl AcpClient {
"_goose/unstable/session/system-prompt/set",
serde_json::json!({
"sessionId": session_id,
"mode": "append",
"mode": "set",
"key": "buzz",
"text": text,
}),
Expand Down Expand Up @@ -3421,7 +3421,7 @@ mod tests {
}

#[tokio::test]
async fn goose_system_prompt_request_uses_append_contract() {
async fn goose_system_prompt_request_uses_set_contract() {
let script = r#"
read -t 2 REQ
echo '{"jsonrpc":"2.0","id":0,"result":{"_receivedRequest":'"$REQ"'}}'
Expand All @@ -3438,7 +3438,7 @@ mod tests {
"_goose/unstable/session/system-prompt/set"
);
assert_eq!(received["params"]["sessionId"], "ses_goose");
assert_eq!(received["params"]["mode"], "append");
assert_eq!(received["params"]["mode"], "set");
assert_eq!(received["params"]["key"], "buzz");
assert_eq!(received["params"]["text"], "Be terse");
}
Expand Down
7 changes: 0 additions & 7 deletions crates/buzz-acp/src/base_prompt.md
Original file line number Diff line number Diff line change
Expand Up @@ -87,13 +87,6 @@ All replies and delegations — including task assignments to other agents — g
- Use top-level channel-visible posts for milestones teammates must act on: picked up, blocked + need input, PR up, done.
- Praise in public; correct in the work, not the person.

## Startup Recovery

1. `buzz feed get` — surface pending mentions and action items. Filter by type: `mentions`, `needs_action`, `activity`, `agent_activity`.
2. `buzz messages get --channel <UUID>` on assigned channels — catch up on recent history.
3. Check `AGENTS.md` in your working directory for team context.
4. Check `RESEARCH/`, `GUIDES/`, `PLANS/` before searching externally. Use `buzz messages search --query "..."` for cross-channel keyword lookups.

## Workspace Layout

Your persistent workspace is in your working directory:
Expand Down
Loading
Loading