* fix: stream the ai chat compaction request instead of waiting on it
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
* fix: reject a compaction stream stopped midway instead of keeping partial text
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
* fix: reject a compaction stream that ends without a finish reason
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
* test: cover a completed responses stream in the streamed completion helper
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
* fix: delete a flow chat turn with its flow run, not its step jobs
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
* fix: give flow-written answers and overlapping turns their own flow run
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
* feat: redesign the service logs page
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
* fix: drop a stale jump after a cached host switch and remove unused max_lines
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
* fix: keep focus on url sync and expose host selection and new logs to assistive tech
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
* fix: reset the tail on dropdown host picks, resume refresh after search, key log cache by host
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
* fix: clear the pending jump when a host switch needs no fetch
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
* feat: show upcoming events when hovering a schedule's cron expression
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
* fix: read cron version from the draft for draft-only schedule previews
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
* feat: replace the AI input filling toggle with an additional prompt for AI
* feat: pass the additional prompt for AI to MCP clients and shared AI guidance
* feat: shrink the run page AI card to a button and a collapsed prompt
* fix: offer writers a way to add a prompt for AI from the run page
* fix: keep a resource default set in the schema when the script is redeployed
Fixes#11493
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
* fix: keep a schema resource default only while the arg stays that resource type
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
* fix: drop a scalar resource default when the arg becomes a list
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
* fix: stop the pg executor cache from pinning a pooler slot
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
* test: retry while the evicted pg backend exits
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
* feat: read the OIDC signing key from a file and rotate it
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
* chore: bump ee ref
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
* chore: bump ee ref
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
* chore: bump ee ref
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
* chore: bump ee ref
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012rmQBQKBgsrd4dJ55vv8n5
* chore: update ee-repo-ref to fe47a306d3760ac2d5a8e14365f05a3503a3ac35
This commit updates the EE repository reference after PR #841 was merged in windmill-ee-private.
Previous ee-repo-ref: 7bd97ee7ce32188a171df9190af990d84586752b
New ee-repo-ref: fe47a306d3760ac2d5a8e14365f05a3503a3ac35
Automated by sync-ee-ref workflow.
---------
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-authored-by: windmill-internal-app[bot] <windmill-internal-app[bot]@users.noreply.github.com>
* fix: never return the instance signing secrets from the settings API
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
* fix: tell wmill instance get-config users that jwt_secret is not exported
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
* chore: point ee-repo-ref at the oidc signing key fix
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
* fix: block rsa_keys from agent workers and keep get-config stdout pure yaml
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
* fix: keep server secrets in exports by default behind EXPORT_SERVER_SECRETS
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
* chore: update ee-repo-ref to 43b2ce8866a393b2666b17647ddb1466afc70bb1
This commit updates the EE repository reference after PR #842 was merged in windmill-ee-private.
Previous ee-repo-ref: 3a0d0c3f45eeb9f5fe8d50ce3798239aa9101a22
New ee-repo-ref: 43b2ce8866a393b2666b17647ddb1466afc70bb1
Automated by sync-ee-ref workflow.
* fix: withhold server secrets on any non-true EXPORT_SERVER_SECRETS value
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-authored-by: windmill-internal-app[bot] <windmill-internal-app[bot]@users.noreply.github.com>
* fix: let legacy draft-only items be discarded from the home page
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
* fix: describe the legacy draft move guard as it now is
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
* feat: add trigger, tag, run-as and digest claims to job OIDC tokens
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
* fix: parse digest floats exactly and derive the codebase digest like push
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
* fix: give flows that reference flow nodes no digest and keep --json clean
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
* fix: list flow step digests from module positions only
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
* test: skip the pulled module-script digest check on windows
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
* chore: update ee-repo-ref to 71b8c1042fd8188c2d2882476f12b671cb5ba421
This commit updates the EE repository reference after PR #840 was merged in windmill-ee-private.
Previous ee-repo-ref: ba1870536789a43c5b6ec18522a93edb9cb07f3d
New ee-repo-ref: 71b8c1042fd8188c2d2882476f12b671cb5ba421
Automated by sync-ee-ref workflow.
---------
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-authored-by: windmill-internal-app[bot] <windmill-internal-app[bot]@users.noreply.github.com>
* feat: add a cancel-only jobs:cancel token scope, optionally path-scoped
jobs:cancel grants the four cancel routes (cancel, force cancel, cancel
selection, cancel persistent) and nothing else; jobs:write keeps covering
them. With paths, the handlers only cancel a job whose own runnable path,
or a parent flow's, matches; others get the invisible-job NotFound.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
* fix: confine cancel_selection like the by-id cancel routes
A token that also carries a path-scoped jobs:run scope is confined to
those runnables on the by-id cancels (through the job read check), so
apply the same run confinement to each selected job.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
* fix: confine persistent cancels, admit agent runs, batch selection checks
cancel_persistent applies the run-scope confinement the other cancel routes
apply; a path-scoped jobs:cancel admits agent runs under the agent's path,
recognized as the run-scope read check does; cancel_selection checks the
cancel scope in one query.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
* fix: let a jobs:cancel grant stand on its own on the cancel routes
Intersecting cancels with the token's jobs:run scopes did not hold: the
token could mint itself a child carrying only the cancel scope. The cancel
routes now apply the cancel paths and the usual per-job visibility, and
leave the run-scope read confinement to reads, as jobs:write does.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
* feat: add an instance setting routing all dependency jobs to one tag
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
* fix: keep bunnative locks on bun and explain the default dependency routing
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
* fix: unstick postgres jobs on large results with custom-typed columns
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
* fix: carry the parked-rows delivery fix in the postgres fork
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
* fix: describe postgres queries before streaming instead of parking rows
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
* perf: skip the postgres describe for statements that return no rows
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
* fix: look for returning in the whole postgres statement
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
* fix: read the leading postgres keyword past nested block comments
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
* fix: end leading postgres line comments at CR too
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
* feat: add test key button to AI resource drawers
* fix: scope-check inline AI resource values and keep test model editable
* fix: keep test model editable for unsaved resources, own-key provider check
* fix: restore the save to workspace button on inline flow steps
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
* fix: make the inline step save to workspace button icon only
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
* feat: add wmill datatable migrate status
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
* feat: show unpushed local migrations in datatable migrate status
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
* docs: move pushLocalMigrations doc comment back onto its function
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
Keeps the calendar.events default. Adds calendarlist.readonly, calendars.readonly
and freebusy as labelled scope_options so the hub's get_calendar_list,
get_calendar_metadata and free/busy scripts can be granted least-privilege.
Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
* fix: offer user scopes in the slack scope editor and drop the generated description on type change
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
* feat: offer slack write scopes as bot and user scope options
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
* fix: send npmrc basic auth (_auth, username/_password) from the npm proxy
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
* fix: resolve npmrc credentials from parent paths like npm
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
* fix: honor empty npmrc overrides and keep registry credentials to its origin
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
* feat(sessions): show an item's deployed page in the preview panel
The preview panel showed an item's editor and nothing else. It now shows the
deployed page too, as a tab of its own.
**Two sides, two tabs.** The editor and the deployed page are different things
to look at, so `isItemTabFor` keys on the side rather than the item: asking for
a side already open focuses it, asking for the other opens it alongside. Two
editors for one item still cannot coexist — they would race its single
(kind, path) cell — but an editor beside a viewer is safe, since the viewer
reads the deployed version over the API and holds no cell. The tab breadcrumb
keeps re-pointing in place; `Exit & see details` and the detail page's `Edit`
open the other side instead of consuming the one you are on. A tab's label
carries `(edit)` when it is the editor side.
**The detail pages moved out of their routes.** `/scripts/get` and `/flows/get`
are now thin wrappers over `ScriptDetail` and `FlowDetail`, which the panel
renders too. Everything they reach — drawers, triggers, saved inputs — is scoped
to the viewer's workspace through `setOperatingWorkspace`, and every navigation
they attempt is caught by `interceptNav` and turned into a move inside the
panel, so nothing takes the browser out of the session. A plain click is
intercepted; ⌘-click and middle-click still open a real tab, which is why the
pages keep their `href`s.
**The picker opens what exists.** A row opens the deployed page, or the editor
when nothing is deployed there, and carries a Draft / Draft only badge in the
review dock's words. `WorkspaceItem` gained `draftOnly` and `hasDraft` from the
listers, which already returned both; deploys now invalidate the picker cache
through `itemDeployed`, so a just-deployed item stops reading as a draft. Rows
also carry a hover Edit action, reachable from the keyboard with the pick
modifier.
`open_preview` gained a `mode`, narrowed out of the advertised schema for a
session that cannot write drafts and re-checked per path in the handler, where
a refusal reports "couldn't check" apart from "denied". The mode is resolved
before those checks, so a call that omits it is gated as the editor it will
become.
Alongside, the workspace a detail page acts on is now the one it is showing
rather than the one the browser is navigated to: `MoveDrawer`,
`toggleWorkspaceErrorHandler` and the pages' own permission gates read the
operating workspace and its acting user, and `RunForm` mints a password
argument's ephemeral variable there too — in a fork session all of these
previously answered for the parent. `InWorkspaceAppViewer` hands the app's
`ctx` user down as a prop instead of writing the global `userStore`, which from
a session tab was re-pointing every permission check on the page.
Fixes found on the way: `DetailPageLayout` claimed `h-screen` inside a panel
that is not the viewport; Edit on a historical script version dropped the
version from the intercepted click; the Run button stayed spinning after a run
that left the page mounted; and the window-level run shortcut fired from a
collapsed panel and from keys another handler had already claimed.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
* fix(sessions): historical edits, stale not-found, shared edit rights, tab labels
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
* fix(sessions): keep deployed-page links and workspace reads in the session
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
* fix(sessions): scope detail hrefs to the session, re-point the viewer's own tab
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
* fix(sessions): keep a previewed raw app's route out of the session URL
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
* fix(sessions): resolve edit-in-fork against the session workspace
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
* fix(sessions): read advanced run tags from the session workspace
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
* fix(sessions): fork from the session workspace, star only navigation items
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
* fix(sessions): mount only the side a preview tab shows
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
* fix(sessions): address CI review round 1 findings
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
* fix(sessions): route links in a deployed page's drawers through the panel
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
* fix(sessions): tell the chat which deployed page the panel shows
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
* fix(sessions): only a 404 reads as an undeployed raw app
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
* fix(sessions): scope the unparseable-JSON run gate to the form
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
* fix(sessions): a flow deleted from the panel stays in its tab
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
* fix(sessions): the picker's edit shortcut works on the current row
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
* fix(sessions): load-error toasts say what failed
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
* fix(sessions): keep an oversized invalid JSON editor in its form's run gate
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
* revert: keep main's draft_only description in openapi.yaml
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
* feat: let slack connects issue a user token via user_scope
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
* chore: keep trailing newline in ee-repo-ref
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
* chore: bump ee-repo-ref
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
* fix: name the provider in slack token descriptions and refresh them on reconnect
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
* fix: drop the generated slack description when connecting another provider
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
* chore: drop the slack scope pin migration, slack ignores scope on refresh
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
* fix: clear the generated slack description on client-credentials connects too
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
* chore: update ee-repo-ref to ff4d04f17721d84fb9a1f655af50ff7e4e7dcbc7
This commit updates the EE repository reference after PR #837 was merged in windmill-ee-private.
Previous ee-repo-ref: 83298dcf23574d5ed05e6c767bf1d9b067ab7a95
New ee-repo-ref: ff4d04f17721d84fb9a1f655af50ff7e4e7dcbc7
Automated by sync-ee-ref workflow.
---------
Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
Co-authored-by: Ruben Fiszel <ruben@windmill.dev>
Co-authored-by: windmill-internal-app[bot] <windmill-internal-app[bot]@users.noreply.github.com>
* feat: harden job OIDC tokens with version claims, jti and a lifetime cap
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
* fix: count restarted flow nodes as latest only if the current version uses them
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
* fix: follow stored loop and branch bodies when resolving current flow nodes
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
* fix: bind current flow nodes to their step id and skip non-numeric node keys
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
* refactor: derive flow step currency from the flow above it and restarts
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
* fix: treat every restarted job but a version-checked flow as not latest
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
* feat: count a restarted body as latest when the run it came from was current
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
* chore: update ee-repo-ref to b469efc9ceddfaaa1040e4cb2c18993822f92c78
This commit updates the EE repository reference after PR #838 was merged in windmill-ee-private.
Previous ee-repo-ref: 25e0b9ae1c6c60419a479fa38d5dc5928832790a
New ee-repo-ref: b469efc9ceddfaaa1040e4cb2c18993822f92c78
Automated by sync-ee-ref workflow.
---------
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-authored-by: windmill-internal-app[bot] <windmill-internal-app[bot]@users.noreply.github.com>
* fix: stop running deleted script versions from worker caches
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
* refactor: reuse script cache invalidate and test the deletion notify payload
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
* fix: keep a deleted copy from shadowing the same hash in another workspace
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
* fix: drop deletions missed while down and fills racing the eviction
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
* fix: batch deletion events, evict path caches and cover version pruning
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
* fix: evict the raw-import cache on both passes and split large deletion events
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
* feat: show human labels for oauth scope options in the connect dialog
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
* feat: always show scope checkboxes, label gdocs and gchat scopes
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
* feat: offer default scopes as checkboxes for every oauth provider
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
* fix: block runs while a JSON input does not parse
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
* fix: clear json editor error on unmount and flush editors before run
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
* fix: restore validity when a nullable arg input is cleared
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
* fix: let field editors parse before the run check and reset the message on view switch
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
* fix: clear the run refusal message when form validity changes
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
* ci: move CI AI models to opus 5.5, gpt-6 and deepseek v4.1 flash
* test: point the deepseek eval alias at v4.1 flash
* ci: run the codex review on gpt-6.1-sol with codex cli 0.159.3
* feat: add //no_network annotation to deny all network access in native scripts
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
* fix: close no_network bypasses (quic dns, header parsing, token, non-native)
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
* fix: refuse //no_network on deno regardless of //native, derive disabled ops from deno_net
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
* refactor: scope //no_network to native scripts only, drop bun/deno refusal
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>