Skip to content

chore: version packages - #6772

Open
gram-bot[bot] wants to merge 1 commit into
mainfrom
changeset-release/main
Open

gram-bot[bot] wants to merge 1 commit into
mainfrom
changeset-release/main

Conversation

@gram-bot

@gram-bot gram-bot Bot commented Sep 24, 2026 •

Copy link
Copy Markdown
Contributor

This PR was opened by the Changesets release GitHub action. When you're ready to do a release, you can merge this and the packages will be published to npm automatically. If you're not ready to do a release yet, that's fine, whenever you add more changesets to main, this PR will be updated.

Releases

admin@0.6.0

Minor Changes

  • f480067: Add an MCP Servers view to the admin organization navigator that lists a project's MCP servers with their URL, visibility, source and creation date, and copies a server's URL in one click.

Patch Changes

  • 35060d1: Protect active identity-chaining bindings during issuer lifecycle changes. Block unsafe issuer deletion and consolidation, and show binding counts and explicit unlinking guidance in the dashboard and admin migration review.

server@2.12.0

Minor Changes

  • f480067: Add an MCP Servers view to the admin organization navigator that lists a project's MCP servers with their URL, visibility, source and creation date, and copies a server's URL in one click.
  • 068e1bf: Configure Remote MCP server identity through one atomic provider and client setup operation.

Patch Changes

  • ab78538: Allow public PKCE clients (token_endpoint_auth_method: none) to register with the staff Admin MCP, so desktop MCP clients can connect. Clients registered with a secret must still authenticate with HTTP Basic, and public clients must present no credentials.
  • 81693dd: Adds the workload:read and workload:write RBAC scopes, which gate managing an organization's workload identity trust policy: its issuers, its admitted subjects, and which agent each inherits its policy from. Both are admin system-role defaults and neither is a member default, since reading the policy discloses which machines an organization recognises. They are registered as agent-runtime scopes but deliberately not agent-runtime-safe, so a workload cannot use its inherited policy to admit further machines.
  • c5b9863: Let organization admins turn off the device agent's Shadow AI scan from the fleet configuration.
  • d192f03: Add management API and SDK operations to prepare, inspect, and unlink downstream identity-chaining client registrations with explicit grant evidence and generation checks. Readiness fails closed on missing grant evidence, and uncertain registration persistence requires reconciliation rather than replay.
  • 52c3dc3: Hook ingest pins a session to the project that first created its chat, so a later request with a different project header cannot stamp messages onto that chat. Chat list counts and last-message times now ignore those sibling-project rows, matching the transcript the UI can actually load.
  • 35060d1: Protect active identity-chaining bindings during issuer lifecycle changes. Block unsafe issuer deletion and consolidation, and show binding counts and explicit unlinking guidance in the dashboard and admin migration review.
  • 8762f37: Expose advertised authorization grant profiles in identity-provider API and SDK models. Discovery and refresh retain only fresh, matching-issuer evidence and preserve upstream HTTP status in partial-discovery diagnostics. Advertised profiles describe capabilities, not client authorization or user access.
  • 52cbebd: Add the launcher.judge management endpoint (POST /rpc/launcher.judge), which routes command palette intent decisions to Jev via OpenRouter. The dashboard sends the typed query and a short list of fuzzy-prefiltered candidates; the server frames target, action and readiness questions for TypeSafe's System One judge, pays with the organization's internal OpenRouter key, and returns probability distributions keyed by the caller's candidate ids. Organizations without a usable OpenRouter key get disabled: true and no outbound call is made. Person candidates are never forwarded.
  • e0d0e98: Fix the MCP consent page looping on "Connected elsewhere" when one remote session client is shared by remote MCP servers with different upstream URLs. Connecting now records the upstream of the server being connected.
  • 8b9f7ec: Accept Tailscale identities with names beginning with RFC 2047 Q-encoded characters and empty optional profile-picture headers.

dashboard@0.125.1

Patch Changes

  • ada7519: Make API key scopes readable at a glance. Creating a key now opens in a side pane rather than a modal, so the form is no longer boxed in by a fixed height, and each scope is a card that leads with the integration it exists for — calling MCP servers at runtime, setup automation, plugin telemetry, device agent rollout — with its exact grants and exclusions one click away instead of crowding the page. The descriptions were also corrected against what the API enforces: a Consumer key does not reach the toolsets service, a Producer key covers everything a Consumer key can do, and the Agent key's setup instructions are now separate from its permissions. The Chat scope is no longer offered, since nothing is provisioned against it any more; keys that already carry it keep working. The project binding list is now alphabetical rather than newest-first.
  • 068e1bf: Configure Remote MCP server identity through one atomic provider and client setup operation.
  • 52cbebd: Rank command palette (⌘K) results by intent. On every keystroke the palette sends the typed text and a short list of prefiltered candidates to launcher.judge, re-orders the list from Jev's probability distributions, and shows a green ↵ on the top row when the intent is settled. Jev can also pick a verb per row: open, enable or disable an MCP server, or publish the plugin marketplace; mutating verbs always require a second Enter inside the palette. Without a resolvable OpenRouter key the palette behaves as before.
  • c5b9863: Let organization admins turn off the device agent's Shadow AI scan from the fleet configuration.
  • d192f03: Add management API and SDK operations to prepare, inspect, and unlink downstream identity-chaining client registrations with explicit grant evidence and generation checks. Readiness fails closed on missing grant evidence, and uncertain registration persistence requires reconciliation rather than replay.
  • 35060d1: Protect active identity-chaining bindings during issuer lifecycle changes. Block unsafe issuer deletion and consolidation, and show binding counts and explicit unlinking guidance in the dashboard and admin migration review.

@gram-bot
gram-bot Bot requested a review from a team as a code owner September 24, 2026 15:30
@gram-bot
gram-bot Bot force-pushed the changeset-release/main branch from 31b37c9 to dec3637 Compare September 24, 2026 16:14
@gram-bot
gram-bot Bot requested a review from a team as a code owner September 24, 2026 16:14
@gram-bot
gram-bot Bot force-pushed the changeset-release/main branch 13 times, most recently from 12e4f8c to 8caba24 Compare September 24, 2026 22:33
@alx-xo
alx-xo added this pull request to the merge queue Sep 24, 2026
@github-merge-queue
github-merge-queue Bot removed this pull request from the merge queue due to failed status checks Sep 24, 2026
@gram-bot
gram-bot Bot force-pushed the changeset-release/main branch 5 times, most recently from b454c88 to d717ad8 Compare September 25, 2026 04:11
@gram-bot
gram-bot Bot force-pushed the changeset-release/main branch from d717ad8 to 9db66c7 Compare September 25, 2026 05:59

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant