Skip to content

chore(release): version packages - #421

Merged
crs48 merged 1 commit into
mainfrom
changeset-release/main
Jul 10, 2026
Merged

chore(release): version packages#421
crs48 merged 1 commit into
mainfrom
changeset-release/main

Conversation

@github-actions

@github-actions github-actions Bot commented Jul 9, 2026

Copy link
Copy Markdown
Contributor

This PR was opened by the Changesets release GitHub action. When you're ready to do a release, you can merge this and the packages will be published to npm automatically. If you're not ready to do a release yet, that's fine, whenever you add more changesets to main, this PR will be updated.

Releases

@xnetjs/devkit@1.0.0

Major Changes

  • #439 677856e Thanks @crs48! - Secure the browser↔local-model bridge (exploration 0289).
    • @xnetjs/devkit (breaking): the agent bridge daemon now requires a
      per-launch pairing token
      (Authorization: Bearer <token>, constant-time
      compared) on its data endpoints (/v1/chat/completions, /run) and validates
      the Host header to reject DNS-rebinding requests. BridgeServerConfig gains
      pairingToken?, BridgeServerHandle exposes pairingToken, and a token is
      auto-generated when none is supplied — so a client that previously called the
      data endpoints with no auth now gets 401. /health stays unauthenticated so
      detection still works before pairing. New openAiChatAgent lets the bridge
      front a raw OpenAI-compatible model server (Ollama/LM Studio) through the same
      authenticated door.
    • @xnetjs/plugins: ConnectorEnv gains appOrigin and the local-server
      setup hint now names the exact OLLAMA_ORIGINS=<origin> line (never a
      wildcard); new localServerSetupHint export; the MCP HTTP transport now
      validates the Host header (defense-in-depth, no change for legitimate
      callers). Additive.
    • @xnetjs/cli: xnet bridge serve prints the pairing code and gains
      --token (pin the code) and --upstream / --upstream-model (front a raw
      local model). Additive.

Patch Changes

  • #446 10c9f87 Thanks @crs48! - Isolate git subprocesses from inherited repo-location env. When the dev loop (or
    its tests) ran while a git hook was active — e.g. husky pre-push running
    pnpm test — the hook's exported GIT_DIR/GIT_WORK_TREE/GIT_INDEX_FILE
    leaked into git children and overrode the explicit cwd, so operations
    (config, commit, even push) targeted the hook's repo instead of the
    requested worktree. NodeCommandRunner now scrubs git's repo-location env vars
    for git invocations so cwd is always authoritative; an explicit
    options.env entry still wins.

@xnetjs/cli@0.1.0

Minor Changes

  • #439 677856e Thanks @crs48! - Secure the browser↔local-model bridge (exploration 0289).
    • @xnetjs/devkit (breaking): the agent bridge daemon now requires a
      per-launch pairing token
      (Authorization: Bearer <token>, constant-time
      compared) on its data endpoints (/v1/chat/completions, /run) and validates
      the Host header to reject DNS-rebinding requests. BridgeServerConfig gains
      pairingToken?, BridgeServerHandle exposes pairingToken, and a token is
      auto-generated when none is supplied — so a client that previously called the
      data endpoints with no auth now gets 401. /health stays unauthenticated so
      detection still works before pairing. New openAiChatAgent lets the bridge
      front a raw OpenAI-compatible model server (Ollama/LM Studio) through the same
      authenticated door.
    • @xnetjs/plugins: ConnectorEnv gains appOrigin and the local-server
      setup hint now names the exact OLLAMA_ORIGINS=<origin> line (never a
      wildcard); new localServerSetupHint export; the MCP HTTP transport now
      validates the Host header (defense-in-depth, no change for legitimate
      callers). Additive.
    • @xnetjs/cli: xnet bridge serve prints the pairing code and gains
      --token (pin the code) and --upstream / --upstream-model (front a raw
      local model). Additive.

Patch Changes

  • Updated dependencies [dd3b1cb, 853d849, 10c9f87, 677856e]:
    • @xnetjs/plugins@0.8.0
    • @xnetjs/runtime@0.2.0
    • @xnetjs/devkit@1.0.0
    • @xnetjs/data@0.8.0
    • @xnetjs/sqlite@0.8.0
    • @xnetjs/sync@0.8.0
    • @xnetjs/identity@0.8.0
    • @xnetjs/crypto@0.8.0
    • @xnetjs/core@0.8.0

@xnetjs/plugins@0.8.0

Minor Changes

  • #420 dd3b1cb Thanks @crs48! - Single-shell layout primitives (exploration 0284): createDefaultTree() and DEFAULT_WORKSPACE_ID join the workspace layout API — the one canonical tree (a sectioned sidebar in the rail, the full left dock, tabs on) that replaces the quiet/calm/bench preset trichotomy. Purely additive: createPresetTree and the preset ids remain for the devtools seed and portable-workspace round-trips.

  • #439 677856e Thanks @crs48! - Secure the browser↔local-model bridge (exploration 0289).

    • @xnetjs/devkit (breaking): the agent bridge daemon now requires a
      per-launch pairing token
      (Authorization: Bearer <token>, constant-time
      compared) on its data endpoints (/v1/chat/completions, /run) and validates
      the Host header to reject DNS-rebinding requests. BridgeServerConfig gains
      pairingToken?, BridgeServerHandle exposes pairingToken, and a token is
      auto-generated when none is supplied — so a client that previously called the
      data endpoints with no auth now gets 401. /health stays unauthenticated so
      detection still works before pairing. New openAiChatAgent lets the bridge
      front a raw OpenAI-compatible model server (Ollama/LM Studio) through the same
      authenticated door.
    • @xnetjs/plugins: ConnectorEnv gains appOrigin and the local-server
      setup hint now names the exact OLLAMA_ORIGINS=<origin> line (never a
      wildcard); new localServerSetupHint export; the MCP HTTP transport now
      validates the Host header (defense-in-depth, no change for legitimate
      callers). Additive.
    • @xnetjs/cli: xnet bridge serve prints the pairing code and gains
      --token (pin the code) and --upstream / --upstream-model (front a raw
      local model). Additive.

Patch Changes

  • Updated dependencies []:
    • @xnetjs/data@0.8.0
    • @xnetjs/abuse@0.8.0
    • @xnetjs/core@0.8.0

@xnetjs/runtime@0.2.0

Minor Changes

  • #448 853d849 Thanks @crs48! - NodeStoreSyncProvider now handles hub capacity rejections gracefully: on the first QUOTA_EXCEEDED (over the hub's per-user cap) or STORAGE_FULL (hub disk full) rejection it pauses outbound sync instead of re-flooding the hub, keeps local data intact, and resumes on the next reconnect. Subscribe to the new onSyncBlocked(listener) API (with SyncBlockedReason/SyncBlockedListener types) to surface a "storage full" notice in your app.

Patch Changes

  • Updated dependencies [dd3b1cb, 677856e]:
    • @xnetjs/plugins@0.8.0
    • @xnetjs/history@0.8.0
    • @xnetjs/data-bridge@0.8.0
    • @xnetjs/data@0.8.0
    • @xnetjs/storage@0.8.0
    • @xnetjs/sync@0.8.0
    • @xnetjs/identity@0.8.0
    • @xnetjs/crypto@0.8.0
    • @xnetjs/core@0.8.0

@xnetjs/abuse@0.8.0

Patch Changes

  • Updated dependencies []:
    • @xnetjs/identity@0.8.0
    • @xnetjs/crypto@0.8.0

@xnetjs/crypto@0.8.0

Patch Changes

  • Updated dependencies []:
    • @xnetjs/core@0.8.0

@xnetjs/data@0.8.0

Patch Changes

  • Updated dependencies []:
    • @xnetjs/storage@0.8.0
    • @xnetjs/sqlite@0.8.0
    • @xnetjs/sync@0.8.0
    • @xnetjs/identity@0.8.0
    • @xnetjs/crypto@0.8.0
    • @xnetjs/core@0.8.0

@xnetjs/data-bridge@0.8.0

Patch Changes

  • Updated dependencies []:
    • @xnetjs/data@0.8.0
    • @xnetjs/sqlite@0.8.0
    • @xnetjs/sync@0.8.0
    • @xnetjs/core@0.8.0

@xnetjs/history@0.8.0

Patch Changes

  • Updated dependencies []:
    • @xnetjs/data@0.8.0
    • @xnetjs/sync@0.8.0
    • @xnetjs/core@0.8.0

@xnetjs/identity@0.8.0

Patch Changes

  • Updated dependencies []:
    • @xnetjs/crypto@0.8.0
    • @xnetjs/core@0.8.0

@xnetjs/react@0.8.0

Patch Changes

  • Updated dependencies [dd3b1cb, 853d849, 677856e]:
    • @xnetjs/plugins@0.8.0
    • @xnetjs/runtime@0.2.0
    • @xnetjs/history@0.8.0
    • @xnetjs/data-bridge@0.8.0
    • @xnetjs/data@0.8.0
    • @xnetjs/sync@0.8.0
    • @xnetjs/identity@0.8.0
    • @xnetjs/crypto@0.8.0
    • @xnetjs/core@0.8.0

@xnetjs/storage@0.8.0

Patch Changes

  • Updated dependencies []:
    • @xnetjs/sqlite@0.8.0
    • @xnetjs/crypto@0.8.0
    • @xnetjs/core@0.8.0

@xnetjs/sync@0.8.0

Patch Changes

  • Updated dependencies []:
    • @xnetjs/identity@0.8.0
    • @xnetjs/crypto@0.8.0
    • @xnetjs/core@0.8.0

@xnetjs/core@0.8.0

@xnetjs/sqlite@0.8.0

xnet-cloud@0.0.11

Patch Changes

  • Updated dependencies []:
    • @xnetjs/crypto@0.8.0
    • @xnetjs/cloud@0.0.1

@xnetjs/brain@0.0.12

Patch Changes

  • Updated dependencies []:
    • @xnetjs/data@0.8.0
    • @xnetjs/vectors@0.0.1

@xnetjs/comms@0.0.12

Patch Changes

  • Updated dependencies []:
    • @xnetjs/data@0.8.0
    • @xnetjs/crypto@0.8.0

@xnetjs/dashboard@0.0.12

Patch Changes

  • Updated dependencies [dd3b1cb, 677856e]:
    • @xnetjs/plugins@0.8.0
    • @xnetjs/react@0.8.0
    • @xnetjs/data@0.8.0
    • @xnetjs/social@0.0.12

@xnetjs/labs@0.0.12

Patch Changes

  • Updated dependencies [dd3b1cb, 677856e]:
    • @xnetjs/plugins@0.8.0
    • @xnetjs/data@0.8.0

@xnetjs/licenses@0.0.12

Patch Changes

  • Updated dependencies []:
    • @xnetjs/crypto@0.8.0

@xnetjs/maps@0.0.12

Patch Changes

  • Updated dependencies []:
    • @xnetjs/data@0.8.0

@xnetjs/meetings@0.0.5

Patch Changes

  • Updated dependencies [dd3b1cb, 677856e]:
    • @xnetjs/plugins@0.8.0
    • @xnetjs/data@0.8.0

@xnetjs/server@0.0.11

Patch Changes

  • Updated dependencies []:
    • @xnetjs/data-bridge@0.8.0
    • @xnetjs/data@0.8.0
    • @xnetjs/identity@0.8.0
    • @xnetjs/crypto@0.8.0

@xnetjs/social@0.0.12

Patch Changes

  • Updated dependencies []:
    • @xnetjs/data@0.8.0
    • @xnetjs/crypto@0.8.0

@xnetjs/unreal@0.0.12

Patch Changes

  • Updated dependencies []:
    • @xnetjs/data@0.8.0

xnet-desktop@0.8.0

Desktop shell release riding the @xnetjs/core 0.8.0 train. Desktop-specific changes are not tracked here; see the core packages' changelogs for what shipped.

@github-actions
github-actions Bot force-pushed the changeset-release/main branch 25 times, most recently from 32f1304 to 3501b04 Compare July 10, 2026 15:24
@github-actions
github-actions Bot force-pushed the changeset-release/main branch from 3501b04 to 633d74d Compare July 10, 2026 15:43
@crs48
crs48 merged commit 03782e3 into main Jul 10, 2026
@crs48
crs48 deleted the changeset-release/main branch July 10, 2026 15:45
@github-actions

Copy link
Copy Markdown
Contributor Author

Preview removed for PR #421.

crs48 added a commit that referenced this pull request Jul 10, 2026
npm 12.0.0 (released today, now `npm@latest`) is missing the `sigstore`
module its own `libnpmpublish` provenance path requires — every
`--provenance` publish dies with `MODULE_NOT_FOUND`. This broke today's
release run (nothing published; all packages still at their prior
versions, no partial state).

Pin the trusted-publishing step to `npm@11` (what all previous
successful releases used). Bump deliberately once a 12.x publish is
verified.

After merge, the push-triggered npm Release run should publish the
staged 0.8.0/0.2.0 versions from #421.

🤖 Generated with [Claude Code](https://claude.com/claude-code)
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant