provider update advisories - #2312

Merged
juliusmarminge merged 36 commits into
pingdotgg:mainfrom
justsomelegs:feature/provider-update-advisories
May 5, 2026
Merged

provider update advisories#2312
juliusmarminge merged 36 commits into
pingdotgg:mainfrom
justsomelegs:feature/provider-update-advisories

Conversation

@justsomelegs

@justsomelegsjustsomelegs commented Apr 23, 2026

Copy link
Copy Markdown
Contributor

What Changed

Compared to main, this PR adds provider update advisories and update-state UI for installed providers.

Server-side:

  • adds provider version lifecycle/update state tracking
  • adds provider updater logic and related contract/RPC plumbing so the UI can know when a provider has an update available, is updating, succeeded, or failed

Web-side:

  • adds provider update toasts with a one-click Update action
  • adds a sidebar provider update pill for in-progress, success, and failure states
  • adds provider-specific success/failure copy
  • updates provider settings status copy to Up to date.
  • smooth-scrolls to the providers section when opening settings from update UI entry points

Also includes tests covering the update lifecycle, updater behavior, notification logic, and the rebased provider registry fixture change.

Why

main does not have provider update advisories or a dedicated way to surface provider update state in the UI.

This PR adds that missing flow so users can:

  • see when an installed provider has an update available
  • trigger the update directly from the UI
  • see update progress and result state in a persistent place
  • get clearer provider status after the update completes

The toast handles the action. The sidebar pill handles ongoing state and final status.

UI Changes

Compared to main:

Before:

  • no provider update advisory UI
  • no provider update progress/status pill
  • provider settings did not show post-update status

After:

  • outdated providers can surface update toasts with an Update action
  • the sidebar shows provider update progress/result state
  • success auto-dismisses after a short timeout
  • failure remains visible until dismissed
  • provider settings show Up to date. after a successful update
TOASTS Screenshot 2026-04-23 140501 SETTINGS Screenshot 2026-04-23 122852
update.demo.vid.mp4

Checklist

  • This PR is small and focused
  • I explained what changed and why
  • I included before/after screenshots for any UI changes
  • I included a video for animation/interaction changes

Note

Add provider update advisories, one-click updates, and version tracking across AI provider drivers

  • Adds version advisory support to Claude, Codex, Cursor, and OpenCode drivers: each driver now queries npm/Homebrew/native CLI for the latest version and attaches a versionAdvisory (status, versions, update command) to provider snapshots.
  • Introduces ProviderMaintenanceRunner and providerMaintenance modules to resolve per-driver update capabilities, coordinate serialized update command execution, and capture bounded stdout/stderr with timeout control.
  • Exposes a new server.updateProvider RPC/IPC method (WebSocket + LocalApi) that triggers provider updates and returns updated provider snapshots.
  • Adds a dedicated Providers settings panel with per-card update UI: an 'Update available' popover with a one-click 'Update now' button or clipboard copy for the update command.
  • Adds ProviderUpdateLaunchNotification (app-shell toast) and SidebarProviderUpdatePill (sidebar footer) to surface update prompts at launch with auto-dismiss, progress tracking, and navigation to provider settings.
  • Persists dismissed notification keys in client settings and localStorage via providerUpdateDismissal utilities.
  • Risk: makeManagedServerProvider now requires a maintenanceCapabilities field (breaking change for callers); driver environments must provide HttpClient.

Macroscope summarized 55f46fa.


Open in Devin Review

Note

High Risk
Adds a new server-side update runner that executes provider update commands and threads volatile update state through the provider registry and WebSocket RPC, which is security- and stability-sensitive. Also changes provider snapshot construction/enrichment and persistence behavior, increasing risk of regressions in provider status caching and UI state.

Overview
Adds provider update advisories and one-click updates. Provider drivers now compute maintenanceCapabilities and enrich snapshots with a versionAdvisory fetched via HTTP (npm latest) so the UI can detect “behind latest” providers.

Introduces an update execution flow. A new ProviderMaintenanceRunner runs allowlisted update commands (with locking, timeouts, and truncated output capture), exposes it via serverUpdateProvider WebSocket RPC, and projects per-instance updateState into provider snapshots without persisting it.

Refactors snapshot/caching plumbing to support this state.makeManagedServerProvider now requires maintenanceCapabilities; ProviderRegistry adds helpers to merge snapshots while preserving model capabilities on empty refreshes and only persists refreshed instances; and stream text collection is centralized via collectUint8StreamText (also reused by VCS output collection).

Reviewed by Cursor Bugbot for commit 55f46fa. Bugbot is set up for automated code reviews on this repo. Configure here.

@coderabbitai

coderabbitaiBot commented Apr 23, 2026

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Repository UI

Review profile: CHILL

Plan: Pro

Run ID: 343c17c5-6351-43e2-9829-63a3c893691d

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests

Tip

💬 Introducing Slack Agent: The best way for teams to turn conversations into code.

Slack Agent is built on CodeRabbit's deep understanding of your code, so your team can collaborate across the entire SDLC without losing context.

  • Generate code and open pull requests
  • Plan features and break down work
  • Investigate incidents and troubleshoot customer tickets together
  • Automate recurring tasks and respond to alerts with triggers
  • Summarize progress and report instantly

Built for teams:

  • Shared memory across your entire org—no repeating context
  • Per-thread sandboxes to safely plan and execute work
  • Governance built-in—scoped access, auditability, and budget controls

One agent for your entire SDLC. Right inside Slack.

👉 Get started


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@github-actionsgithub-actionsBot added size:XXL 1,000+ changed lines (additions + deletions). vouch:unvouched PR author is not yet trusted in the VOUCHED list. labels Apr 23, 2026
@justsomelegsjustsomelegs changed the title update providers in applicationprovider update advisoriesApr 23, 2026
@macroscopeapp

macroscopeappBot commented Apr 23, 2026

Copy link
Copy Markdown
Contributor

Approvability

Verdict: Needs human review

Diff is too large for automated approval analysis. A human reviewer should evaluate this PR.

You can customize Macroscope's approvability policy. Learn more.

@juliusmarminge

Copy link
Copy Markdown
Member

just merged a large refactor on how drivers work and is registerred so this will need to be updated, i can review it when it is

@justsomelegs
justsomelegsforce-pushed the feature/provider-update-advisories branch from aeb88d0 to 9c34d30CompareApril 30, 2026 11:22
@justsomelegs

Copy link
Copy Markdown
ContributorAuthor

@juliusmarminge this has been rebased now :)

Comment threadapps/server/src/provider/providerUpdater.ts Outdated
Comment threadapps/server/src/provider/providerUpdater.ts Outdated
Comment threadapps/server/src/provider/providerUpdater.ts Outdated
@github-actionsgithub-actionsBot added vouch:trusted PR author is trusted by repo permissions or the VOUCHED list. and removed vouch:unvouched PR author is not yet trusted in the VOUCHED list. labels Apr 30, 2026
@juliusmarminge

Copy link
Copy Markdown
Member

where is the update button?

CleanShot 2026-05-02 at 00 04 20@2x

@juliusmarminge

Copy link
Copy Markdown
Member

and there should be some "dismiss until next update" or something so it doesn't reprompt every load:

CleanShot.2026-05-02.at.00.05.13.mp4

- Rename provider update lifecycle types and resolvers
- Update provider snapshots and registry wiring
- Add advisory maintenance coordinator and tests
- Replace driver-scoped update state with per-instance maintenance action state
- Resolve update capabilities and progress through the target instance only
- Update provider updater and tests for the new registry API
Comment threadapps/server/src/provider/providerUpdater.ts Outdated
Comment threadapps/server/src/provider/providerMaintenance.ts Outdated
@juliusmarminge

juliusmarminge commented May 4, 2026

Copy link
Copy Markdown
Member

@justsomelegs mind trying it out now? made some changers

@justsomelegs

Copy link
Copy Markdown
ContributorAuthor

@juliusmarminge LGTM, the only things i changed were the toast to track the providers exact provider instanceId instead of collapsing by driver, so it stays aligned with the new instance-scoped update state and updated the tests to accomofate the popover changes you made

@juliusmarminge

Copy link
Copy Markdown
Member

yea made some architectural changes since i think this flow will eventually be extended to support installing drivers from and adding a proper onboarding etc

- Add Effect-based maintenance command runner with process spawning
- Allow dynamic update lock keys and preserve provider update advisories
- Update tests to cover the new runner and command flow
Comment threadapps/server/src/provider/providerMaintenanceRunner.ts Outdated
- move maintenance runner behind an Effect service
- add shared stream text collection for command output
- broaden tests around command execution and update locking
- Switch provider maintenance/version advisory helpers to Effect.fn
- Preserve npm/pnpm symlink detection while improving Effect test coverage
Comment threadapps/server/src/provider/providerMaintenance.ts
- Thread HttpClient through provider maintenance and snapshot refreshes
- Switch provider update visibility to ISO timestamps
- Add and update tests for maintenance and launch notification logic
Co-authored-by: codex <codex@users.noreply.github.com>
Comment threadapps/server/src/provider/Layers/CursorProvider.ts
- propagate maintenance capabilities into cursor snapshot enrichment
- surface queued update state while another provider update runs
- reset provider version cache between tests
Comment threadapps/server/src/provider/providerMaintenance.ts
- Add `/settings/providers` and route update entry points there
- Move provider management UI out of General settings
- Refresh provider card spacing and hierarchy
- Reduce padding in settings rows for a denser layout
- Remove extra line-height from row descriptions
Comment threadapps/server/src/provider/Layers/ProviderRegistry.ts Outdated
- Require `HttpClient` in Claude, Codex, Cursor, and OpenCode drivers
- Provide a test HTTP client in provider registry and instance registry specs
- Co-authored-by: codex <codex@users.noreply.github.com>
- keep cached models when refreshes return an empty list
- persist only the updated provider snapshots after merge

@cursorcursorBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes and found 1 potential issue.

There are 4 total unresolved issues (including 3 from previous reviews).

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit 55f46fa. Configure here.

if (onQueued) {
yield* onQueued;
}
return yield* lock.withPermits(1)(run);

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Queued state always published even without contention

Low Severity

onQueued fires unconditionally before acquiring the semaphore permit, meaning every provider update transitions through a "queued" state with message "Waiting for another provider update to finish." even when the semaphore is immediately available and no other update is running. This results in a briefly misleading sidebar pill and state history for single-provider updates with no contention.

Fix in CursorFix in Web

Reviewed by Cursor Bugbot for commit 55f46fa. Configure here.

@juliusmarminge
juliusmarminge merged commit 9b604bc into pingdotgg:mainMay 5, 2026
12 checks passed
imabdulazeez added a commit to imabdulazeez/t3code that referenced this pull request May 6, 2026
Brings in: server CLI submodule split (pingdotgg#2545), process/trace diagnostics
views (pingdotgg#2532), JetBrains editor support (pingdotgg#2475), MessagesTimeline render
optimizations (pingdotgg#2527, pingdotgg#2498), git/terminal test stabilization (pingdotgg#2540),
keybindings settings editor (pingdotgg#2533), and provider update advisories
(pingdotgg#2312).
Conflict resolutions:
- packages/contracts/src/settings.ts: kept aa's diffFontFamily and
terminalFontFamily alongside upstream's
dismissedProviderUpdateNotificationKeys.
- apps/desktop/src/clientPersistence.test.ts: same shape, fixture mirrors
the schema.
- apps/web/src/components/settings/SettingsPanels.tsx: kept both import
groups (FontPicker from aa, ProviderUpdateLaunchNotification.logic from
upstream).
- apps/web/src/localApi.test.ts: extended both fixtures with
diffFontFamily and terminalFontFamily so the merged ClientSettings
shape typechecks against the strict desktop bridge contract.
Pre-existing aa typecheck issues fixed at the root so the merge commit
is green:
- apps/desktop/src/electron.d.ts: declaration-merge "local-fonts" into
Electron's Session.setPermissionRequestHandler permission union (the
Electron 40 typings omit it even though the runtime supports it).
- apps/web/src/components/DiffPanel.tsx: conditionally spread style on
Virtualizer instead of passing undefined, satisfying
exactOptionalPropertyTypes.
sak0a referenced this pull request in saka-gg/ryco May 20, 2026
- ProviderRegistry: drop redundant applyProviderUpdateState call in setProviderMaintenanceActionState; upsertProviders already re-applies it
- providerMaintenance: remove /usr/local/bin/ from Homebrew matcher (over-matched npm-installed binaries when realPath did not resolve to /Cellar/); rely on Cellar/Caskroom/opt-homebrew/bin paths
- providerMaintenance: stop encodeURIComponent-ing scoped npm package names (encoded '@' as %40, which some registry proxies reject); only percent-encode the '/' separator
- providerSnapshot: drop dead 'driver' parameter on buildServerProvider and the unreachable createProviderVersionAdvisory branch; advisories come exclusively from enrichSnapshot
NeilTheFisher pushed a commit to NeilTheFisher/t3code that referenced this pull request Aug 18, 2026
Co-authored-by: Julius Marminge <julius0216@outlook.com>
Co-authored-by: codex <codex@users.noreply.github.com>
darjss pushed a commit to darjss/t3code that referenced this pull request Aug 26, 2026
Co-authored-by: Julius Marminge <julius0216@outlook.com>
Co-authored-by: codex <codex@users.noreply.github.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:XXL1,000+ changed lines (additions + deletions).vouch:trustedPR author is trusted by repo permissions or the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@justsomelegs@juliusmarminge@asfires
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

provider update advisories - #2312

Merged
juliusmarminge merged 36 commits into
pingdotgg:mainfrom
justsomelegs:feature/provider-update-advisories
May 5, 2026
Merged

provider update advisories#2312
juliusmarminge merged 36 commits into
pingdotgg:mainfrom
justsomelegs:feature/provider-update-advisories

Conversation

@justsomelegs

@justsomelegsjustsomelegs commented Apr 23, 2026

Copy link
Copy Markdown
Contributor

What Changed

Compared to main, this PR adds provider update advisories and update-state UI for installed providers.

Server-side:

  • adds provider version lifecycle/update state tracking
  • adds provider updater logic and related contract/RPC plumbing so the UI can know when a provider has an update available, is updating, succeeded, or failed

Web-side:

  • adds provider update toasts with a one-click Update action
  • adds a sidebar provider update pill for in-progress, success, and failure states
  • adds provider-specific success/failure copy
  • updates provider settings status copy to Up to date.
  • smooth-scrolls to the providers section when opening settings from update UI entry points

Also includes tests covering the update lifecycle, updater behavior, notification logic, and the rebased provider registry fixture change.

Why

main does not have provider update advisories or a dedicated way to surface provider update state in the UI.

This PR adds that missing flow so users can:

  • see when an installed provider has an update available
  • trigger the update directly from the UI
  • see update progress and result state in a persistent place
  • get clearer provider status after the update completes

The toast handles the action. The sidebar pill handles ongoing state and final status.

UI Changes

Compared to main:

Before:

  • no provider update advisory UI
  • no provider update progress/status pill
  • provider settings did not show post-update status

After:

  • outdated providers can surface update toasts with an Update action
  • the sidebar shows provider update progress/result state
  • success auto-dismisses after a short timeout
  • failure remains visible until dismissed
  • provider settings show Up to date. after a successful update
TOASTS Screenshot 2026-04-23 140501 SETTINGS Screenshot 2026-04-23 122852
update.demo.vid.mp4

Checklist

  • This PR is small and focused
  • I explained what changed and why
  • I included before/after screenshots for any UI changes
  • I included a video for animation/interaction changes

Note

Add provider update advisories, one-click updates, and version tracking across AI provider drivers

  • Adds version advisory support to Claude, Codex, Cursor, and OpenCode drivers: each driver now queries npm/Homebrew/native CLI for the latest version and attaches a versionAdvisory (status, versions, update command) to provider snapshots.
  • Introduces ProviderMaintenanceRunner and providerMaintenance modules to resolve per-driver update capabilities, coordinate serialized update command execution, and capture bounded stdout/stderr with timeout control.
  • Exposes a new server.updateProvider RPC/IPC method (WebSocket + LocalApi) that triggers provider updates and returns updated provider snapshots.
  • Adds a dedicated Providers settings panel with per-card update UI: an 'Update available' popover with a one-click 'Update now' button or clipboard copy for the update command.
  • Adds ProviderUpdateLaunchNotification (app-shell toast) and SidebarProviderUpdatePill (sidebar footer) to surface update prompts at launch with auto-dismiss, progress tracking, and navigation to provider settings.
  • Persists dismissed notification keys in client settings and localStorage via providerUpdateDismissal utilities.
  • Risk: makeManagedServerProvider now requires a maintenanceCapabilities field (breaking change for callers); driver environments must provide HttpClient.

Macroscope summarized 55f46fa.


Open in Devin Review

Note

High Risk
Adds a new server-side update runner that executes provider update commands and threads volatile update state through the provider registry and WebSocket RPC, which is security- and stability-sensitive. Also changes provider snapshot construction/enrichment and persistence behavior, increasing risk of regressions in provider status caching and UI state.

Overview
Adds provider update advisories and one-click updates. Provider drivers now compute maintenanceCapabilities and enrich snapshots with a versionAdvisory fetched via HTTP (npm latest) so the UI can detect “behind latest” providers.

Introduces an update execution flow. A new ProviderMaintenanceRunner runs allowlisted update commands (with locking, timeouts, and truncated output capture), exposes it via serverUpdateProvider WebSocket RPC, and projects per-instance updateState into provider snapshots without persisting it.

Refactors snapshot/caching plumbing to support this state.makeManagedServerProvider now requires maintenanceCapabilities; ProviderRegistry adds helpers to merge snapshots while preserving model capabilities on empty refreshes and only persists refreshed instances; and stream text collection is centralized via collectUint8StreamText (also reused by VCS output collection).

Reviewed by Cursor Bugbot for commit 55f46fa. Bugbot is set up for automated code reviews on this repo. Configure here.

@coderabbitai

coderabbitaiBot commented Apr 23, 2026

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Repository UI

Review profile: CHILL

Plan: Pro

Run ID: 343c17c5-6351-43e2-9829-63a3c893691d

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests

Tip

💬 Introducing Slack Agent: The best way for teams to turn conversations into code.

Slack Agent is built on CodeRabbit's deep understanding of your code, so your team can collaborate across the entire SDLC without losing context.

  • Generate code and open pull requests
  • Plan features and break down work
  • Investigate incidents and troubleshoot customer tickets together
  • Automate recurring tasks and respond to alerts with triggers
  • Summarize progress and report instantly

Built for teams:

  • Shared memory across your entire org—no repeating context
  • Per-thread sandboxes to safely plan and execute work
  • Governance built-in—scoped access, auditability, and budget controls

One agent for your entire SDLC. Right inside Slack.

👉 Get started


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@github-actionsgithub-actionsBot added size:XXL 1,000+ changed lines (additions + deletions). vouch:unvouched PR author is not yet trusted in the VOUCHED list. labels Apr 23, 2026
@justsomelegsjustsomelegs changed the title update providers in applicationprovider update advisoriesApr 23, 2026
@macroscopeapp

macroscopeappBot commented Apr 23, 2026

Copy link
Copy Markdown
Contributor

Approvability

Verdict: Needs human review

Diff is too large for automated approval analysis. A human reviewer should evaluate this PR.

You can customize Macroscope's approvability policy. Learn more.

@juliusmarminge

Copy link
Copy Markdown
Member

just merged a large refactor on how drivers work and is registerred so this will need to be updated, i can review it when it is

@justsomelegs
justsomelegsforce-pushed the feature/provider-update-advisories branch from aeb88d0 to 9c34d30CompareApril 30, 2026 11:22
@justsomelegs

Copy link
Copy Markdown
ContributorAuthor

@juliusmarminge this has been rebased now :)

Comment threadapps/server/src/provider/providerUpdater.ts Outdated
Comment threadapps/server/src/provider/providerUpdater.ts Outdated
Comment threadapps/server/src/provider/providerUpdater.ts Outdated
@github-actionsgithub-actionsBot added vouch:trusted PR author is trusted by repo permissions or the VOUCHED list. and removed vouch:unvouched PR author is not yet trusted in the VOUCHED list. labels Apr 30, 2026
@juliusmarminge

Copy link
Copy Markdown
Member

where is the update button?

CleanShot 2026-05-02 at 00 04 20@2x

@juliusmarminge

Copy link
Copy Markdown
Member

and there should be some "dismiss until next update" or something so it doesn't reprompt every load:

CleanShot.2026-05-02.at.00.05.13.mp4

- Rename provider update lifecycle types and resolvers
- Update provider snapshots and registry wiring
- Add advisory maintenance coordinator and tests
- Replace driver-scoped update state with per-instance maintenance action state
- Resolve update capabilities and progress through the target instance only
- Update provider updater and tests for the new registry API
Comment threadapps/server/src/provider/providerUpdater.ts Outdated
Comment threadapps/server/src/provider/providerMaintenance.ts Outdated
@juliusmarminge

juliusmarminge commented May 4, 2026

Copy link
Copy Markdown
Member

@justsomelegs mind trying it out now? made some changers

@justsomelegs

Copy link
Copy Markdown
ContributorAuthor

@juliusmarminge LGTM, the only things i changed were the toast to track the providers exact provider instanceId instead of collapsing by driver, so it stays aligned with the new instance-scoped update state and updated the tests to accomofate the popover changes you made

@juliusmarminge

Copy link
Copy Markdown
Member

yea made some architectural changes since i think this flow will eventually be extended to support installing drivers from and adding a proper onboarding etc

- Add Effect-based maintenance command runner with process spawning
- Allow dynamic update lock keys and preserve provider update advisories
- Update tests to cover the new runner and command flow
Comment threadapps/server/src/provider/providerMaintenanceRunner.ts Outdated
- move maintenance runner behind an Effect service
- add shared stream text collection for command output
- broaden tests around command execution and update locking
- Switch provider maintenance/version advisory helpers to Effect.fn
- Preserve npm/pnpm symlink detection while improving Effect test coverage
Comment threadapps/server/src/provider/providerMaintenance.ts
- Thread HttpClient through provider maintenance and snapshot refreshes
- Switch provider update visibility to ISO timestamps
- Add and update tests for maintenance and launch notification logic
Co-authored-by: codex <codex@users.noreply.github.com>
Comment threadapps/server/src/provider/Layers/CursorProvider.ts
- propagate maintenance capabilities into cursor snapshot enrichment
- surface queued update state while another provider update runs
- reset provider version cache between tests
Comment threadapps/server/src/provider/providerMaintenance.ts
- Add `/settings/providers` and route update entry points there
- Move provider management UI out of General settings
- Refresh provider card spacing and hierarchy
- Reduce padding in settings rows for a denser layout
- Remove extra line-height from row descriptions
Comment threadapps/server/src/provider/Layers/ProviderRegistry.ts Outdated
- Require `HttpClient` in Claude, Codex, Cursor, and OpenCode drivers
- Provide a test HTTP client in provider registry and instance registry specs
- Co-authored-by: codex <codex@users.noreply.github.com>
- keep cached models when refreshes return an empty list
- persist only the updated provider snapshots after merge

@cursorcursorBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes and found 1 potential issue.

There are 4 total unresolved issues (including 3 from previous reviews).

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit 55f46fa. Configure here.

if (onQueued) {
yield* onQueued;
}
return yield* lock.withPermits(1)(run);

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Queued state always published even without contention

Low Severity

onQueued fires unconditionally before acquiring the semaphore permit, meaning every provider update transitions through a "queued" state with message "Waiting for another provider update to finish." even when the semaphore is immediately available and no other update is running. This results in a briefly misleading sidebar pill and state history for single-provider updates with no contention.

Fix in CursorFix in Web

Reviewed by Cursor Bugbot for commit 55f46fa. Configure here.

@juliusmarminge
juliusmarminge merged commit 9b604bc into pingdotgg:mainMay 5, 2026
12 checks passed
imabdulazeez added a commit to imabdulazeez/t3code that referenced this pull request May 6, 2026
Brings in: server CLI submodule split (pingdotgg#2545), process/trace diagnostics
views (pingdotgg#2532), JetBrains editor support (pingdotgg#2475), MessagesTimeline render
optimizations (pingdotgg#2527, pingdotgg#2498), git/terminal test stabilization (pingdotgg#2540),
keybindings settings editor (pingdotgg#2533), and provider update advisories
(pingdotgg#2312).
Conflict resolutions:
- packages/contracts/src/settings.ts: kept aa's diffFontFamily and
terminalFontFamily alongside upstream's
dismissedProviderUpdateNotificationKeys.
- apps/desktop/src/clientPersistence.test.ts: same shape, fixture mirrors
the schema.
- apps/web/src/components/settings/SettingsPanels.tsx: kept both import
groups (FontPicker from aa, ProviderUpdateLaunchNotification.logic from
upstream).
- apps/web/src/localApi.test.ts: extended both fixtures with
diffFontFamily and terminalFontFamily so the merged ClientSettings
shape typechecks against the strict desktop bridge contract.
Pre-existing aa typecheck issues fixed at the root so the merge commit
is green:
- apps/desktop/src/electron.d.ts: declaration-merge "local-fonts" into
Electron's Session.setPermissionRequestHandler permission union (the
Electron 40 typings omit it even though the runtime supports it).
- apps/web/src/components/DiffPanel.tsx: conditionally spread style on
Virtualizer instead of passing undefined, satisfying
exactOptionalPropertyTypes.
sak0a referenced this pull request in saka-gg/ryco May 20, 2026
- ProviderRegistry: drop redundant applyProviderUpdateState call in setProviderMaintenanceActionState; upsertProviders already re-applies it
- providerMaintenance: remove /usr/local/bin/ from Homebrew matcher (over-matched npm-installed binaries when realPath did not resolve to /Cellar/); rely on Cellar/Caskroom/opt-homebrew/bin paths
- providerMaintenance: stop encodeURIComponent-ing scoped npm package names (encoded '@' as %40, which some registry proxies reject); only percent-encode the '/' separator
- providerSnapshot: drop dead 'driver' parameter on buildServerProvider and the unreachable createProviderVersionAdvisory branch; advisories come exclusively from enrichSnapshot
NeilTheFisher pushed a commit to NeilTheFisher/t3code that referenced this pull request Aug 18, 2026
Co-authored-by: Julius Marminge <julius0216@outlook.com>
Co-authored-by: codex <codex@users.noreply.github.com>
darjss pushed a commit to darjss/t3code that referenced this pull request Aug 26, 2026
Co-authored-by: Julius Marminge <julius0216@outlook.com>
Co-authored-by: codex <codex@users.noreply.github.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:XXL1,000+ changed lines (additions + deletions).vouch:trustedPR author is trusted by repo permissions or the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@justsomelegs@juliusmarminge@asfires
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

provider update advisories - #2312

Merged
juliusmarminge merged 36 commits into
pingdotgg:mainfrom
justsomelegs:feature/provider-update-advisories
May 5, 2026
Merged

provider update advisories#2312
juliusmarminge merged 36 commits into
pingdotgg:mainfrom
justsomelegs:feature/provider-update-advisories

Conversation

@justsomelegs

@justsomelegsjustsomelegs commented Apr 23, 2026

Copy link
Copy Markdown
Contributor

What Changed

Compared to main, this PR adds provider update advisories and update-state UI for installed providers.

Server-side:

  • adds provider version lifecycle/update state tracking
  • adds provider updater logic and related contract/RPC plumbing so the UI can know when a provider has an update available, is updating, succeeded, or failed

Web-side:

  • adds provider update toasts with a one-click Update action
  • adds a sidebar provider update pill for in-progress, success, and failure states
  • adds provider-specific success/failure copy
  • updates provider settings status copy to Up to date.
  • smooth-scrolls to the providers section when opening settings from update UI entry points

Also includes tests covering the update lifecycle, updater behavior, notification logic, and the rebased provider registry fixture change.

Why

main does not have provider update advisories or a dedicated way to surface provider update state in the UI.

This PR adds that missing flow so users can:

  • see when an installed provider has an update available
  • trigger the update directly from the UI
  • see update progress and result state in a persistent place
  • get clearer provider status after the update completes

The toast handles the action. The sidebar pill handles ongoing state and final status.

UI Changes

Compared to main:

Before:

  • no provider update advisory UI
  • no provider update progress/status pill
  • provider settings did not show post-update status

After:

  • outdated providers can surface update toasts with an Update action
  • the sidebar shows provider update progress/result state
  • success auto-dismisses after a short timeout
  • failure remains visible until dismissed
  • provider settings show Up to date. after a successful update
TOASTS Screenshot 2026-04-23 140501 SETTINGS Screenshot 2026-04-23 122852
update.demo.vid.mp4

Checklist

  • This PR is small and focused
  • I explained what changed and why
  • I included before/after screenshots for any UI changes
  • I included a video for animation/interaction changes

Note

Add provider update advisories, one-click updates, and version tracking across AI provider drivers

  • Adds version advisory support to Claude, Codex, Cursor, and OpenCode drivers: each driver now queries npm/Homebrew/native CLI for the latest version and attaches a versionAdvisory (status, versions, update command) to provider snapshots.
  • Introduces ProviderMaintenanceRunner and providerMaintenance modules to resolve per-driver update capabilities, coordinate serialized update command execution, and capture bounded stdout/stderr with timeout control.
  • Exposes a new server.updateProvider RPC/IPC method (WebSocket + LocalApi) that triggers provider updates and returns updated provider snapshots.
  • Adds a dedicated Providers settings panel with per-card update UI: an 'Update available' popover with a one-click 'Update now' button or clipboard copy for the update command.
  • Adds ProviderUpdateLaunchNotification (app-shell toast) and SidebarProviderUpdatePill (sidebar footer) to surface update prompts at launch with auto-dismiss, progress tracking, and navigation to provider settings.
  • Persists dismissed notification keys in client settings and localStorage via providerUpdateDismissal utilities.
  • Risk: makeManagedServerProvider now requires a maintenanceCapabilities field (breaking change for callers); driver environments must provide HttpClient.

Macroscope summarized 55f46fa.


Open in Devin Review

Note

High Risk
Adds a new server-side update runner that executes provider update commands and threads volatile update state through the provider registry and WebSocket RPC, which is security- and stability-sensitive. Also changes provider snapshot construction/enrichment and persistence behavior, increasing risk of regressions in provider status caching and UI state.

Overview
Adds provider update advisories and one-click updates. Provider drivers now compute maintenanceCapabilities and enrich snapshots with a versionAdvisory fetched via HTTP (npm latest) so the UI can detect “behind latest” providers.

Introduces an update execution flow. A new ProviderMaintenanceRunner runs allowlisted update commands (with locking, timeouts, and truncated output capture), exposes it via serverUpdateProvider WebSocket RPC, and projects per-instance updateState into provider snapshots without persisting it.

Refactors snapshot/caching plumbing to support this state.makeManagedServerProvider now requires maintenanceCapabilities; ProviderRegistry adds helpers to merge snapshots while preserving model capabilities on empty refreshes and only persists refreshed instances; and stream text collection is centralized via collectUint8StreamText (also reused by VCS output collection).

Reviewed by Cursor Bugbot for commit 55f46fa. Bugbot is set up for automated code reviews on this repo. Configure here.

@coderabbitai

coderabbitaiBot commented Apr 23, 2026

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Repository UI

Review profile: CHILL

Plan: Pro

Run ID: 343c17c5-6351-43e2-9829-63a3c893691d

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests

Tip

💬 Introducing Slack Agent: The best way for teams to turn conversations into code.

Slack Agent is built on CodeRabbit's deep understanding of your code, so your team can collaborate across the entire SDLC without losing context.

  • Generate code and open pull requests
  • Plan features and break down work
  • Investigate incidents and troubleshoot customer tickets together
  • Automate recurring tasks and respond to alerts with triggers
  • Summarize progress and report instantly

Built for teams:

  • Shared memory across your entire org—no repeating context
  • Per-thread sandboxes to safely plan and execute work
  • Governance built-in—scoped access, auditability, and budget controls

One agent for your entire SDLC. Right inside Slack.

👉 Get started


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@github-actionsgithub-actionsBot added size:XXL 1,000+ changed lines (additions + deletions). vouch:unvouched PR author is not yet trusted in the VOUCHED list. labels Apr 23, 2026
@justsomelegsjustsomelegs changed the title update providers in applicationprovider update advisoriesApr 23, 2026
@macroscopeapp

macroscopeappBot commented Apr 23, 2026

Copy link
Copy Markdown
Contributor

Approvability

Verdict: Needs human review

Diff is too large for automated approval analysis. A human reviewer should evaluate this PR.

You can customize Macroscope's approvability policy. Learn more.

@juliusmarminge

Copy link
Copy Markdown
Member

just merged a large refactor on how drivers work and is registerred so this will need to be updated, i can review it when it is

@justsomelegs
justsomelegsforce-pushed the feature/provider-update-advisories branch from aeb88d0 to 9c34d30CompareApril 30, 2026 11:22
@justsomelegs

Copy link
Copy Markdown
ContributorAuthor

@juliusmarminge this has been rebased now :)

Comment threadapps/server/src/provider/providerUpdater.ts Outdated
Comment threadapps/server/src/provider/providerUpdater.ts Outdated
Comment threadapps/server/src/provider/providerUpdater.ts Outdated
@github-actionsgithub-actionsBot added vouch:trusted PR author is trusted by repo permissions or the VOUCHED list. and removed vouch:unvouched PR author is not yet trusted in the VOUCHED list. labels Apr 30, 2026
@juliusmarminge

Copy link
Copy Markdown
Member

where is the update button?

CleanShot 2026-05-02 at 00 04 20@2x

@juliusmarminge

Copy link
Copy Markdown
Member

and there should be some "dismiss until next update" or something so it doesn't reprompt every load:

CleanShot.2026-05-02.at.00.05.13.mp4

- Rename provider update lifecycle types and resolvers
- Update provider snapshots and registry wiring
- Add advisory maintenance coordinator and tests
- Replace driver-scoped update state with per-instance maintenance action state
- Resolve update capabilities and progress through the target instance only
- Update provider updater and tests for the new registry API
Comment threadapps/server/src/provider/providerUpdater.ts Outdated
Comment threadapps/server/src/provider/providerMaintenance.ts Outdated
@juliusmarminge

juliusmarminge commented May 4, 2026

Copy link
Copy Markdown
Member

@justsomelegs mind trying it out now? made some changers

@justsomelegs

Copy link
Copy Markdown
ContributorAuthor

@juliusmarminge LGTM, the only things i changed were the toast to track the providers exact provider instanceId instead of collapsing by driver, so it stays aligned with the new instance-scoped update state and updated the tests to accomofate the popover changes you made

@juliusmarminge

Copy link
Copy Markdown
Member

yea made some architectural changes since i think this flow will eventually be extended to support installing drivers from and adding a proper onboarding etc

- Add Effect-based maintenance command runner with process spawning
- Allow dynamic update lock keys and preserve provider update advisories
- Update tests to cover the new runner and command flow
Comment threadapps/server/src/provider/providerMaintenanceRunner.ts Outdated
- move maintenance runner behind an Effect service
- add shared stream text collection for command output
- broaden tests around command execution and update locking
- Switch provider maintenance/version advisory helpers to Effect.fn
- Preserve npm/pnpm symlink detection while improving Effect test coverage
Comment threadapps/server/src/provider/providerMaintenance.ts
- Thread HttpClient through provider maintenance and snapshot refreshes
- Switch provider update visibility to ISO timestamps
- Add and update tests for maintenance and launch notification logic
Co-authored-by: codex <codex@users.noreply.github.com>
Comment threadapps/server/src/provider/Layers/CursorProvider.ts
- propagate maintenance capabilities into cursor snapshot enrichment
- surface queued update state while another provider update runs
- reset provider version cache between tests
Comment threadapps/server/src/provider/providerMaintenance.ts
- Add `/settings/providers` and route update entry points there
- Move provider management UI out of General settings
- Refresh provider card spacing and hierarchy
- Reduce padding in settings rows for a denser layout
- Remove extra line-height from row descriptions
Comment threadapps/server/src/provider/Layers/ProviderRegistry.ts Outdated
- Require `HttpClient` in Claude, Codex, Cursor, and OpenCode drivers
- Provide a test HTTP client in provider registry and instance registry specs
- Co-authored-by: codex <codex@users.noreply.github.com>
- keep cached models when refreshes return an empty list
- persist only the updated provider snapshots after merge

@cursorcursorBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes and found 1 potential issue.

There are 4 total unresolved issues (including 3 from previous reviews).

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit 55f46fa. Configure here.

if (onQueued) {
yield* onQueued;
}
return yield* lock.withPermits(1)(run);

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Queued state always published even without contention

Low Severity

onQueued fires unconditionally before acquiring the semaphore permit, meaning every provider update transitions through a "queued" state with message "Waiting for another provider update to finish." even when the semaphore is immediately available and no other update is running. This results in a briefly misleading sidebar pill and state history for single-provider updates with no contention.

Fix in CursorFix in Web

Reviewed by Cursor Bugbot for commit 55f46fa. Configure here.

@juliusmarminge
juliusmarminge merged commit 9b604bc into pingdotgg:mainMay 5, 2026
12 checks passed
imabdulazeez added a commit to imabdulazeez/t3code that referenced this pull request May 6, 2026
Brings in: server CLI submodule split (pingdotgg#2545), process/trace diagnostics
views (pingdotgg#2532), JetBrains editor support (pingdotgg#2475), MessagesTimeline render
optimizations (pingdotgg#2527, pingdotgg#2498), git/terminal test stabilization (pingdotgg#2540),
keybindings settings editor (pingdotgg#2533), and provider update advisories
(pingdotgg#2312).
Conflict resolutions:
- packages/contracts/src/settings.ts: kept aa's diffFontFamily and
terminalFontFamily alongside upstream's
dismissedProviderUpdateNotificationKeys.
- apps/desktop/src/clientPersistence.test.ts: same shape, fixture mirrors
the schema.
- apps/web/src/components/settings/SettingsPanels.tsx: kept both import
groups (FontPicker from aa, ProviderUpdateLaunchNotification.logic from
upstream).
- apps/web/src/localApi.test.ts: extended both fixtures with
diffFontFamily and terminalFontFamily so the merged ClientSettings
shape typechecks against the strict desktop bridge contract.
Pre-existing aa typecheck issues fixed at the root so the merge commit
is green:
- apps/desktop/src/electron.d.ts: declaration-merge "local-fonts" into
Electron's Session.setPermissionRequestHandler permission union (the
Electron 40 typings omit it even though the runtime supports it).
- apps/web/src/components/DiffPanel.tsx: conditionally spread style on
Virtualizer instead of passing undefined, satisfying
exactOptionalPropertyTypes.
sak0a referenced this pull request in saka-gg/ryco May 20, 2026
- ProviderRegistry: drop redundant applyProviderUpdateState call in setProviderMaintenanceActionState; upsertProviders already re-applies it
- providerMaintenance: remove /usr/local/bin/ from Homebrew matcher (over-matched npm-installed binaries when realPath did not resolve to /Cellar/); rely on Cellar/Caskroom/opt-homebrew/bin paths
- providerMaintenance: stop encodeURIComponent-ing scoped npm package names (encoded '@' as %40, which some registry proxies reject); only percent-encode the '/' separator
- providerSnapshot: drop dead 'driver' parameter on buildServerProvider and the unreachable createProviderVersionAdvisory branch; advisories come exclusively from enrichSnapshot
NeilTheFisher pushed a commit to NeilTheFisher/t3code that referenced this pull request Aug 18, 2026
Co-authored-by: Julius Marminge <julius0216@outlook.com>
Co-authored-by: codex <codex@users.noreply.github.com>
darjss pushed a commit to darjss/t3code that referenced this pull request Aug 26, 2026
Co-authored-by: Julius Marminge <julius0216@outlook.com>
Co-authored-by: codex <codex@users.noreply.github.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:XXL1,000+ changed lines (additions + deletions).vouch:trustedPR author is trusted by repo permissions or the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@justsomelegs@juliusmarminge@asfires
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

provider update advisories - #2312

Merged
juliusmarminge merged 36 commits into
pingdotgg:mainfrom
justsomelegs:feature/provider-update-advisories
May 5, 2026
Merged

provider update advisories#2312
juliusmarminge merged 36 commits into
pingdotgg:mainfrom
justsomelegs:feature/provider-update-advisories

Conversation

@justsomelegs

@justsomelegsjustsomelegs commented Apr 23, 2026

Copy link
Copy Markdown
Contributor

What Changed

Compared to main, this PR adds provider update advisories and update-state UI for installed providers.

Server-side:

  • adds provider version lifecycle/update state tracking
  • adds provider updater logic and related contract/RPC plumbing so the UI can know when a provider has an update available, is updating, succeeded, or failed

Web-side:

  • adds provider update toasts with a one-click Update action
  • adds a sidebar provider update pill for in-progress, success, and failure states
  • adds provider-specific success/failure copy
  • updates provider settings status copy to Up to date.
  • smooth-scrolls to the providers section when opening settings from update UI entry points

Also includes tests covering the update lifecycle, updater behavior, notification logic, and the rebased provider registry fixture change.

Why

main does not have provider update advisories or a dedicated way to surface provider update state in the UI.

This PR adds that missing flow so users can:

  • see when an installed provider has an update available
  • trigger the update directly from the UI
  • see update progress and result state in a persistent place
  • get clearer provider status after the update completes

The toast handles the action. The sidebar pill handles ongoing state and final status.

UI Changes

Compared to main:

Before:

  • no provider update advisory UI
  • no provider update progress/status pill
  • provider settings did not show post-update status

After:

  • outdated providers can surface update toasts with an Update action
  • the sidebar shows provider update progress/result state
  • success auto-dismisses after a short timeout
  • failure remains visible until dismissed
  • provider settings show Up to date. after a successful update
TOASTS Screenshot 2026-04-23 140501 SETTINGS Screenshot 2026-04-23 122852
update.demo.vid.mp4

Checklist

  • This PR is small and focused
  • I explained what changed and why
  • I included before/after screenshots for any UI changes
  • I included a video for animation/interaction changes

Note

Add provider update advisories, one-click updates, and version tracking across AI provider drivers

  • Adds version advisory support to Claude, Codex, Cursor, and OpenCode drivers: each driver now queries npm/Homebrew/native CLI for the latest version and attaches a versionAdvisory (status, versions, update command) to provider snapshots.
  • Introduces ProviderMaintenanceRunner and providerMaintenance modules to resolve per-driver update capabilities, coordinate serialized update command execution, and capture bounded stdout/stderr with timeout control.
  • Exposes a new server.updateProvider RPC/IPC method (WebSocket + LocalApi) that triggers provider updates and returns updated provider snapshots.
  • Adds a dedicated Providers settings panel with per-card update UI: an 'Update available' popover with a one-click 'Update now' button or clipboard copy for the update command.
  • Adds ProviderUpdateLaunchNotification (app-shell toast) and SidebarProviderUpdatePill (sidebar footer) to surface update prompts at launch with auto-dismiss, progress tracking, and navigation to provider settings.
  • Persists dismissed notification keys in client settings and localStorage via providerUpdateDismissal utilities.
  • Risk: makeManagedServerProvider now requires a maintenanceCapabilities field (breaking change for callers); driver environments must provide HttpClient.

Macroscope summarized 55f46fa.


Open in Devin Review

Note

High Risk
Adds a new server-side update runner that executes provider update commands and threads volatile update state through the provider registry and WebSocket RPC, which is security- and stability-sensitive. Also changes provider snapshot construction/enrichment and persistence behavior, increasing risk of regressions in provider status caching and UI state.

Overview
Adds provider update advisories and one-click updates. Provider drivers now compute maintenanceCapabilities and enrich snapshots with a versionAdvisory fetched via HTTP (npm latest) so the UI can detect “behind latest” providers.

Introduces an update execution flow. A new ProviderMaintenanceRunner runs allowlisted update commands (with locking, timeouts, and truncated output capture), exposes it via serverUpdateProvider WebSocket RPC, and projects per-instance updateState into provider snapshots without persisting it.

Refactors snapshot/caching plumbing to support this state.makeManagedServerProvider now requires maintenanceCapabilities; ProviderRegistry adds helpers to merge snapshots while preserving model capabilities on empty refreshes and only persists refreshed instances; and stream text collection is centralized via collectUint8StreamText (also reused by VCS output collection).

Reviewed by Cursor Bugbot for commit 55f46fa. Bugbot is set up for automated code reviews on this repo. Configure here.

@coderabbitai

coderabbitaiBot commented Apr 23, 2026

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Repository UI

Review profile: CHILL

Plan: Pro

Run ID: 343c17c5-6351-43e2-9829-63a3c893691d

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests

Tip

💬 Introducing Slack Agent: The best way for teams to turn conversations into code.

Slack Agent is built on CodeRabbit's deep understanding of your code, so your team can collaborate across the entire SDLC without losing context.

  • Generate code and open pull requests
  • Plan features and break down work
  • Investigate incidents and troubleshoot customer tickets together
  • Automate recurring tasks and respond to alerts with triggers
  • Summarize progress and report instantly

Built for teams:

  • Shared memory across your entire org—no repeating context
  • Per-thread sandboxes to safely plan and execute work
  • Governance built-in—scoped access, auditability, and budget controls

One agent for your entire SDLC. Right inside Slack.

👉 Get started


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@github-actionsgithub-actionsBot added size:XXL 1,000+ changed lines (additions + deletions). vouch:unvouched PR author is not yet trusted in the VOUCHED list. labels Apr 23, 2026
@justsomelegsjustsomelegs changed the title update providers in applicationprovider update advisoriesApr 23, 2026
@macroscopeapp

macroscopeappBot commented Apr 23, 2026

Copy link
Copy Markdown
Contributor

Approvability

Verdict: Needs human review

Diff is too large for automated approval analysis. A human reviewer should evaluate this PR.

You can customize Macroscope's approvability policy. Learn more.

@juliusmarminge

Copy link
Copy Markdown
Member

just merged a large refactor on how drivers work and is registerred so this will need to be updated, i can review it when it is

@justsomelegs
justsomelegsforce-pushed the feature/provider-update-advisories branch from aeb88d0 to 9c34d30CompareApril 30, 2026 11:22
@justsomelegs

Copy link
Copy Markdown
ContributorAuthor

@juliusmarminge this has been rebased now :)

Comment threadapps/server/src/provider/providerUpdater.ts Outdated
Comment threadapps/server/src/provider/providerUpdater.ts Outdated
Comment threadapps/server/src/provider/providerUpdater.ts Outdated
@github-actionsgithub-actionsBot added vouch:trusted PR author is trusted by repo permissions or the VOUCHED list. and removed vouch:unvouched PR author is not yet trusted in the VOUCHED list. labels Apr 30, 2026
@juliusmarminge

Copy link
Copy Markdown
Member

where is the update button?

CleanShot 2026-05-02 at 00 04 20@2x

@juliusmarminge

Copy link
Copy Markdown
Member

and there should be some "dismiss until next update" or something so it doesn't reprompt every load:

CleanShot.2026-05-02.at.00.05.13.mp4

- Rename provider update lifecycle types and resolvers
- Update provider snapshots and registry wiring
- Add advisory maintenance coordinator and tests
- Replace driver-scoped update state with per-instance maintenance action state
- Resolve update capabilities and progress through the target instance only
- Update provider updater and tests for the new registry API
Comment threadapps/server/src/provider/providerUpdater.ts Outdated
Comment threadapps/server/src/provider/providerMaintenance.ts Outdated
@juliusmarminge

juliusmarminge commented May 4, 2026

Copy link
Copy Markdown
Member

@justsomelegs mind trying it out now? made some changers

@justsomelegs

Copy link
Copy Markdown
ContributorAuthor

@juliusmarminge LGTM, the only things i changed were the toast to track the providers exact provider instanceId instead of collapsing by driver, so it stays aligned with the new instance-scoped update state and updated the tests to accomofate the popover changes you made

@juliusmarminge

Copy link
Copy Markdown
Member

yea made some architectural changes since i think this flow will eventually be extended to support installing drivers from and adding a proper onboarding etc

- Add Effect-based maintenance command runner with process spawning
- Allow dynamic update lock keys and preserve provider update advisories
- Update tests to cover the new runner and command flow
Comment threadapps/server/src/provider/providerMaintenanceRunner.ts Outdated
- move maintenance runner behind an Effect service
- add shared stream text collection for command output
- broaden tests around command execution and update locking
- Switch provider maintenance/version advisory helpers to Effect.fn
- Preserve npm/pnpm symlink detection while improving Effect test coverage
Comment threadapps/server/src/provider/providerMaintenance.ts
- Thread HttpClient through provider maintenance and snapshot refreshes
- Switch provider update visibility to ISO timestamps
- Add and update tests for maintenance and launch notification logic
Co-authored-by: codex <codex@users.noreply.github.com>
Comment threadapps/server/src/provider/Layers/CursorProvider.ts
- propagate maintenance capabilities into cursor snapshot enrichment
- surface queued update state while another provider update runs
- reset provider version cache between tests
Comment threadapps/server/src/provider/providerMaintenance.ts
- Add `/settings/providers` and route update entry points there
- Move provider management UI out of General settings
- Refresh provider card spacing and hierarchy
- Reduce padding in settings rows for a denser layout
- Remove extra line-height from row descriptions
Comment threadapps/server/src/provider/Layers/ProviderRegistry.ts Outdated
- Require `HttpClient` in Claude, Codex, Cursor, and OpenCode drivers
- Provide a test HTTP client in provider registry and instance registry specs
- Co-authored-by: codex <codex@users.noreply.github.com>
- keep cached models when refreshes return an empty list
- persist only the updated provider snapshots after merge

@cursorcursorBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes and found 1 potential issue.

There are 4 total unresolved issues (including 3 from previous reviews).

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit 55f46fa. Configure here.

if (onQueued) {
yield* onQueued;
}
return yield* lock.withPermits(1)(run);

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Queued state always published even without contention

Low Severity

onQueued fires unconditionally before acquiring the semaphore permit, meaning every provider update transitions through a "queued" state with message "Waiting for another provider update to finish." even when the semaphore is immediately available and no other update is running. This results in a briefly misleading sidebar pill and state history for single-provider updates with no contention.

Fix in CursorFix in Web

Reviewed by Cursor Bugbot for commit 55f46fa. Configure here.

@juliusmarminge
juliusmarminge merged commit 9b604bc into pingdotgg:mainMay 5, 2026
12 checks passed
imabdulazeez added a commit to imabdulazeez/t3code that referenced this pull request May 6, 2026
Brings in: server CLI submodule split (pingdotgg#2545), process/trace diagnostics
views (pingdotgg#2532), JetBrains editor support (pingdotgg#2475), MessagesTimeline render
optimizations (pingdotgg#2527, pingdotgg#2498), git/terminal test stabilization (pingdotgg#2540),
keybindings settings editor (pingdotgg#2533), and provider update advisories
(pingdotgg#2312).
Conflict resolutions:
- packages/contracts/src/settings.ts: kept aa's diffFontFamily and
terminalFontFamily alongside upstream's
dismissedProviderUpdateNotificationKeys.
- apps/desktop/src/clientPersistence.test.ts: same shape, fixture mirrors
the schema.
- apps/web/src/components/settings/SettingsPanels.tsx: kept both import
groups (FontPicker from aa, ProviderUpdateLaunchNotification.logic from
upstream).
- apps/web/src/localApi.test.ts: extended both fixtures with
diffFontFamily and terminalFontFamily so the merged ClientSettings
shape typechecks against the strict desktop bridge contract.
Pre-existing aa typecheck issues fixed at the root so the merge commit
is green:
- apps/desktop/src/electron.d.ts: declaration-merge "local-fonts" into
Electron's Session.setPermissionRequestHandler permission union (the
Electron 40 typings omit it even though the runtime supports it).
- apps/web/src/components/DiffPanel.tsx: conditionally spread style on
Virtualizer instead of passing undefined, satisfying
exactOptionalPropertyTypes.
sak0a referenced this pull request in saka-gg/ryco May 20, 2026
- ProviderRegistry: drop redundant applyProviderUpdateState call in setProviderMaintenanceActionState; upsertProviders already re-applies it
- providerMaintenance: remove /usr/local/bin/ from Homebrew matcher (over-matched npm-installed binaries when realPath did not resolve to /Cellar/); rely on Cellar/Caskroom/opt-homebrew/bin paths
- providerMaintenance: stop encodeURIComponent-ing scoped npm package names (encoded '@' as %40, which some registry proxies reject); only percent-encode the '/' separator
- providerSnapshot: drop dead 'driver' parameter on buildServerProvider and the unreachable createProviderVersionAdvisory branch; advisories come exclusively from enrichSnapshot
NeilTheFisher pushed a commit to NeilTheFisher/t3code that referenced this pull request Aug 18, 2026
Co-authored-by: Julius Marminge <julius0216@outlook.com>
Co-authored-by: codex <codex@users.noreply.github.com>
darjss pushed a commit to darjss/t3code that referenced this pull request Aug 26, 2026
Co-authored-by: Julius Marminge <julius0216@outlook.com>
Co-authored-by: codex <codex@users.noreply.github.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:XXL1,000+ changed lines (additions + deletions).vouch:trustedPR author is trusted by repo permissions or the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@justsomelegs@juliusmarminge@asfires
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

provider update advisories - #2312

Merged
juliusmarminge merged 36 commits into
pingdotgg:mainfrom
justsomelegs:feature/provider-update-advisories
May 5, 2026
Merged

provider update advisories#2312
juliusmarminge merged 36 commits into
pingdotgg:mainfrom
justsomelegs:feature/provider-update-advisories

Conversation

@justsomelegs

@justsomelegsjustsomelegs commented Apr 23, 2026

Copy link
Copy Markdown
Contributor

What Changed

Compared to main, this PR adds provider update advisories and update-state UI for installed providers.

Server-side:

  • adds provider version lifecycle/update state tracking
  • adds provider updater logic and related contract/RPC plumbing so the UI can know when a provider has an update available, is updating, succeeded, or failed

Web-side:

  • adds provider update toasts with a one-click Update action
  • adds a sidebar provider update pill for in-progress, success, and failure states
  • adds provider-specific success/failure copy
  • updates provider settings status copy to Up to date.
  • smooth-scrolls to the providers section when opening settings from update UI entry points

Also includes tests covering the update lifecycle, updater behavior, notification logic, and the rebased provider registry fixture change.

Why

main does not have provider update advisories or a dedicated way to surface provider update state in the UI.

This PR adds that missing flow so users can:

  • see when an installed provider has an update available
  • trigger the update directly from the UI
  • see update progress and result state in a persistent place
  • get clearer provider status after the update completes

The toast handles the action. The sidebar pill handles ongoing state and final status.

UI Changes

Compared to main:

Before:

  • no provider update advisory UI
  • no provider update progress/status pill
  • provider settings did not show post-update status

After:

  • outdated providers can surface update toasts with an Update action
  • the sidebar shows provider update progress/result state
  • success auto-dismisses after a short timeout
  • failure remains visible until dismissed
  • provider settings show Up to date. after a successful update
TOASTS Screenshot 2026-04-23 140501 SETTINGS Screenshot 2026-04-23 122852
update.demo.vid.mp4

Checklist

  • This PR is small and focused
  • I explained what changed and why
  • I included before/after screenshots for any UI changes
  • I included a video for animation/interaction changes

Note

Add provider update advisories, one-click updates, and version tracking across AI provider drivers

  • Adds version advisory support to Claude, Codex, Cursor, and OpenCode drivers: each driver now queries npm/Homebrew/native CLI for the latest version and attaches a versionAdvisory (status, versions, update command) to provider snapshots.
  • Introduces ProviderMaintenanceRunner and providerMaintenance modules to resolve per-driver update capabilities, coordinate serialized update command execution, and capture bounded stdout/stderr with timeout control.
  • Exposes a new server.updateProvider RPC/IPC method (WebSocket + LocalApi) that triggers provider updates and returns updated provider snapshots.
  • Adds a dedicated Providers settings panel with per-card update UI: an 'Update available' popover with a one-click 'Update now' button or clipboard copy for the update command.
  • Adds ProviderUpdateLaunchNotification (app-shell toast) and SidebarProviderUpdatePill (sidebar footer) to surface update prompts at launch with auto-dismiss, progress tracking, and navigation to provider settings.
  • Persists dismissed notification keys in client settings and localStorage via providerUpdateDismissal utilities.
  • Risk: makeManagedServerProvider now requires a maintenanceCapabilities field (breaking change for callers); driver environments must provide HttpClient.

Macroscope summarized 55f46fa.


Open in Devin Review

Note

High Risk
Adds a new server-side update runner that executes provider update commands and threads volatile update state through the provider registry and WebSocket RPC, which is security- and stability-sensitive. Also changes provider snapshot construction/enrichment and persistence behavior, increasing risk of regressions in provider status caching and UI state.

Overview
Adds provider update advisories and one-click updates. Provider drivers now compute maintenanceCapabilities and enrich snapshots with a versionAdvisory fetched via HTTP (npm latest) so the UI can detect “behind latest” providers.

Introduces an update execution flow. A new ProviderMaintenanceRunner runs allowlisted update commands (with locking, timeouts, and truncated output capture), exposes it via serverUpdateProvider WebSocket RPC, and projects per-instance updateState into provider snapshots without persisting it.

Refactors snapshot/caching plumbing to support this state.makeManagedServerProvider now requires maintenanceCapabilities; ProviderRegistry adds helpers to merge snapshots while preserving model capabilities on empty refreshes and only persists refreshed instances; and stream text collection is centralized via collectUint8StreamText (also reused by VCS output collection).

Reviewed by Cursor Bugbot for commit 55f46fa. Bugbot is set up for automated code reviews on this repo. Configure here.

@coderabbitai

coderabbitaiBot commented Apr 23, 2026

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Repository UI

Review profile: CHILL

Plan: Pro

Run ID: 343c17c5-6351-43e2-9829-63a3c893691d

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests

Tip

💬 Introducing Slack Agent: The best way for teams to turn conversations into code.

Slack Agent is built on CodeRabbit's deep understanding of your code, so your team can collaborate across the entire SDLC without losing context.

  • Generate code and open pull requests
  • Plan features and break down work
  • Investigate incidents and troubleshoot customer tickets together
  • Automate recurring tasks and respond to alerts with triggers
  • Summarize progress and report instantly

Built for teams:

  • Shared memory across your entire org—no repeating context
  • Per-thread sandboxes to safely plan and execute work
  • Governance built-in—scoped access, auditability, and budget controls

One agent for your entire SDLC. Right inside Slack.

👉 Get started


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@github-actionsgithub-actionsBot added size:XXL 1,000+ changed lines (additions + deletions). vouch:unvouched PR author is not yet trusted in the VOUCHED list. labels Apr 23, 2026
@justsomelegsjustsomelegs changed the title update providers in applicationprovider update advisoriesApr 23, 2026
@macroscopeapp

macroscopeappBot commented Apr 23, 2026

Copy link
Copy Markdown
Contributor

Approvability

Verdict: Needs human review

Diff is too large for automated approval analysis. A human reviewer should evaluate this PR.

You can customize Macroscope's approvability policy. Learn more.

@juliusmarminge

Copy link
Copy Markdown
Member

just merged a large refactor on how drivers work and is registerred so this will need to be updated, i can review it when it is

@justsomelegs
justsomelegsforce-pushed the feature/provider-update-advisories branch from aeb88d0 to 9c34d30CompareApril 30, 2026 11:22
@justsomelegs

Copy link
Copy Markdown
ContributorAuthor

@juliusmarminge this has been rebased now :)

Comment threadapps/server/src/provider/providerUpdater.ts Outdated
Comment threadapps/server/src/provider/providerUpdater.ts Outdated
Comment threadapps/server/src/provider/providerUpdater.ts Outdated
@github-actionsgithub-actionsBot added vouch:trusted PR author is trusted by repo permissions or the VOUCHED list. and removed vouch:unvouched PR author is not yet trusted in the VOUCHED list. labels Apr 30, 2026
@juliusmarminge

Copy link
Copy Markdown
Member

where is the update button?

CleanShot 2026-05-02 at 00 04 20@2x

@juliusmarminge

Copy link
Copy Markdown
Member

and there should be some "dismiss until next update" or something so it doesn't reprompt every load:

CleanShot.2026-05-02.at.00.05.13.mp4

- Rename provider update lifecycle types and resolvers
- Update provider snapshots and registry wiring
- Add advisory maintenance coordinator and tests
- Replace driver-scoped update state with per-instance maintenance action state
- Resolve update capabilities and progress through the target instance only
- Update provider updater and tests for the new registry API
Comment threadapps/server/src/provider/providerUpdater.ts Outdated
Comment threadapps/server/src/provider/providerMaintenance.ts Outdated
@juliusmarminge

juliusmarminge commented May 4, 2026

Copy link
Copy Markdown
Member

@justsomelegs mind trying it out now? made some changers

@justsomelegs

Copy link
Copy Markdown
ContributorAuthor

@juliusmarminge LGTM, the only things i changed were the toast to track the providers exact provider instanceId instead of collapsing by driver, so it stays aligned with the new instance-scoped update state and updated the tests to accomofate the popover changes you made

@juliusmarminge

Copy link
Copy Markdown
Member

yea made some architectural changes since i think this flow will eventually be extended to support installing drivers from and adding a proper onboarding etc

- Add Effect-based maintenance command runner with process spawning
- Allow dynamic update lock keys and preserve provider update advisories
- Update tests to cover the new runner and command flow
Comment threadapps/server/src/provider/providerMaintenanceRunner.ts Outdated
- move maintenance runner behind an Effect service
- add shared stream text collection for command output
- broaden tests around command execution and update locking
- Switch provider maintenance/version advisory helpers to Effect.fn
- Preserve npm/pnpm symlink detection while improving Effect test coverage
Comment threadapps/server/src/provider/providerMaintenance.ts
- Thread HttpClient through provider maintenance and snapshot refreshes
- Switch provider update visibility to ISO timestamps
- Add and update tests for maintenance and launch notification logic
Co-authored-by: codex <codex@users.noreply.github.com>
Comment threadapps/server/src/provider/Layers/CursorProvider.ts
- propagate maintenance capabilities into cursor snapshot enrichment
- surface queued update state while another provider update runs
- reset provider version cache between tests
Comment threadapps/server/src/provider/providerMaintenance.ts
- Add `/settings/providers` and route update entry points there
- Move provider management UI out of General settings
- Refresh provider card spacing and hierarchy
- Reduce padding in settings rows for a denser layout
- Remove extra line-height from row descriptions
Comment threadapps/server/src/provider/Layers/ProviderRegistry.ts Outdated
- Require `HttpClient` in Claude, Codex, Cursor, and OpenCode drivers
- Provide a test HTTP client in provider registry and instance registry specs
- Co-authored-by: codex <codex@users.noreply.github.com>
- keep cached models when refreshes return an empty list
- persist only the updated provider snapshots after merge

@cursorcursorBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes and found 1 potential issue.

There are 4 total unresolved issues (including 3 from previous reviews).

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit 55f46fa. Configure here.

if (onQueued) {
yield* onQueued;
}
return yield* lock.withPermits(1)(run);

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Queued state always published even without contention

Low Severity

onQueued fires unconditionally before acquiring the semaphore permit, meaning every provider update transitions through a "queued" state with message "Waiting for another provider update to finish." even when the semaphore is immediately available and no other update is running. This results in a briefly misleading sidebar pill and state history for single-provider updates with no contention.

Fix in CursorFix in Web

Reviewed by Cursor Bugbot for commit 55f46fa. Configure here.

@juliusmarminge
juliusmarminge merged commit 9b604bc into pingdotgg:mainMay 5, 2026
12 checks passed
imabdulazeez added a commit to imabdulazeez/t3code that referenced this pull request May 6, 2026
Brings in: server CLI submodule split (pingdotgg#2545), process/trace diagnostics
views (pingdotgg#2532), JetBrains editor support (pingdotgg#2475), MessagesTimeline render
optimizations (pingdotgg#2527, pingdotgg#2498), git/terminal test stabilization (pingdotgg#2540),
keybindings settings editor (pingdotgg#2533), and provider update advisories
(pingdotgg#2312).
Conflict resolutions:
- packages/contracts/src/settings.ts: kept aa's diffFontFamily and
terminalFontFamily alongside upstream's
dismissedProviderUpdateNotificationKeys.
- apps/desktop/src/clientPersistence.test.ts: same shape, fixture mirrors
the schema.
- apps/web/src/components/settings/SettingsPanels.tsx: kept both import
groups (FontPicker from aa, ProviderUpdateLaunchNotification.logic from
upstream).
- apps/web/src/localApi.test.ts: extended both fixtures with
diffFontFamily and terminalFontFamily so the merged ClientSettings
shape typechecks against the strict desktop bridge contract.
Pre-existing aa typecheck issues fixed at the root so the merge commit
is green:
- apps/desktop/src/electron.d.ts: declaration-merge "local-fonts" into
Electron's Session.setPermissionRequestHandler permission union (the
Electron 40 typings omit it even though the runtime supports it).
- apps/web/src/components/DiffPanel.tsx: conditionally spread style on
Virtualizer instead of passing undefined, satisfying
exactOptionalPropertyTypes.
sak0a referenced this pull request in saka-gg/ryco May 20, 2026
- ProviderRegistry: drop redundant applyProviderUpdateState call in setProviderMaintenanceActionState; upsertProviders already re-applies it
- providerMaintenance: remove /usr/local/bin/ from Homebrew matcher (over-matched npm-installed binaries when realPath did not resolve to /Cellar/); rely on Cellar/Caskroom/opt-homebrew/bin paths
- providerMaintenance: stop encodeURIComponent-ing scoped npm package names (encoded '@' as %40, which some registry proxies reject); only percent-encode the '/' separator
- providerSnapshot: drop dead 'driver' parameter on buildServerProvider and the unreachable createProviderVersionAdvisory branch; advisories come exclusively from enrichSnapshot
NeilTheFisher pushed a commit to NeilTheFisher/t3code that referenced this pull request Aug 18, 2026
Co-authored-by: Julius Marminge <julius0216@outlook.com>
Co-authored-by: codex <codex@users.noreply.github.com>
darjss pushed a commit to darjss/t3code that referenced this pull request Aug 26, 2026
Co-authored-by: Julius Marminge <julius0216@outlook.com>
Co-authored-by: codex <codex@users.noreply.github.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:XXL1,000+ changed lines (additions + deletions).vouch:trustedPR author is trusted by repo permissions or the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@justsomelegs@juliusmarminge@asfires
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

provider update advisories - #2312

Merged
juliusmarminge merged 36 commits into
pingdotgg:mainfrom
justsomelegs:feature/provider-update-advisories
May 5, 2026
Merged

provider update advisories#2312
juliusmarminge merged 36 commits into
pingdotgg:mainfrom
justsomelegs:feature/provider-update-advisories

Conversation

@justsomelegs

@justsomelegsjustsomelegs commented Apr 23, 2026

Copy link
Copy Markdown
Contributor

What Changed

Compared to main, this PR adds provider update advisories and update-state UI for installed providers.

Server-side:

  • adds provider version lifecycle/update state tracking
  • adds provider updater logic and related contract/RPC plumbing so the UI can know when a provider has an update available, is updating, succeeded, or failed

Web-side:

  • adds provider update toasts with a one-click Update action
  • adds a sidebar provider update pill for in-progress, success, and failure states
  • adds provider-specific success/failure copy
  • updates provider settings status copy to Up to date.
  • smooth-scrolls to the providers section when opening settings from update UI entry points

Also includes tests covering the update lifecycle, updater behavior, notification logic, and the rebased provider registry fixture change.

Why

main does not have provider update advisories or a dedicated way to surface provider update state in the UI.

This PR adds that missing flow so users can:

  • see when an installed provider has an update available
  • trigger the update directly from the UI
  • see update progress and result state in a persistent place
  • get clearer provider status after the update completes

The toast handles the action. The sidebar pill handles ongoing state and final status.

UI Changes

Compared to main:

Before:

  • no provider update advisory UI
  • no provider update progress/status pill
  • provider settings did not show post-update status

After:

  • outdated providers can surface update toasts with an Update action
  • the sidebar shows provider update progress/result state
  • success auto-dismisses after a short timeout
  • failure remains visible until dismissed
  • provider settings show Up to date. after a successful update
TOASTS Screenshot 2026-04-23 140501 SETTINGS Screenshot 2026-04-23 122852
update.demo.vid.mp4

Checklist

  • This PR is small and focused
  • I explained what changed and why
  • I included before/after screenshots for any UI changes
  • I included a video for animation/interaction changes

Note

Add provider update advisories, one-click updates, and version tracking across AI provider drivers

  • Adds version advisory support to Claude, Codex, Cursor, and OpenCode drivers: each driver now queries npm/Homebrew/native CLI for the latest version and attaches a versionAdvisory (status, versions, update command) to provider snapshots.
  • Introduces ProviderMaintenanceRunner and providerMaintenance modules to resolve per-driver update capabilities, coordinate serialized update command execution, and capture bounded stdout/stderr with timeout control.
  • Exposes a new server.updateProvider RPC/IPC method (WebSocket + LocalApi) that triggers provider updates and returns updated provider snapshots.
  • Adds a dedicated Providers settings panel with per-card update UI: an 'Update available' popover with a one-click 'Update now' button or clipboard copy for the update command.
  • Adds ProviderUpdateLaunchNotification (app-shell toast) and SidebarProviderUpdatePill (sidebar footer) to surface update prompts at launch with auto-dismiss, progress tracking, and navigation to provider settings.
  • Persists dismissed notification keys in client settings and localStorage via providerUpdateDismissal utilities.
  • Risk: makeManagedServerProvider now requires a maintenanceCapabilities field (breaking change for callers); driver environments must provide HttpClient.

Macroscope summarized 55f46fa.


Open in Devin Review

Note

High Risk
Adds a new server-side update runner that executes provider update commands and threads volatile update state through the provider registry and WebSocket RPC, which is security- and stability-sensitive. Also changes provider snapshot construction/enrichment and persistence behavior, increasing risk of regressions in provider status caching and UI state.

Overview
Adds provider update advisories and one-click updates. Provider drivers now compute maintenanceCapabilities and enrich snapshots with a versionAdvisory fetched via HTTP (npm latest) so the UI can detect “behind latest” providers.

Introduces an update execution flow. A new ProviderMaintenanceRunner runs allowlisted update commands (with locking, timeouts, and truncated output capture), exposes it via serverUpdateProvider WebSocket RPC, and projects per-instance updateState into provider snapshots without persisting it.

Refactors snapshot/caching plumbing to support this state.makeManagedServerProvider now requires maintenanceCapabilities; ProviderRegistry adds helpers to merge snapshots while preserving model capabilities on empty refreshes and only persists refreshed instances; and stream text collection is centralized via collectUint8StreamText (also reused by VCS output collection).

Reviewed by Cursor Bugbot for commit 55f46fa. Bugbot is set up for automated code reviews on this repo. Configure here.

@coderabbitai

coderabbitaiBot commented Apr 23, 2026

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Repository UI

Review profile: CHILL

Plan: Pro

Run ID: 343c17c5-6351-43e2-9829-63a3c893691d

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests

Tip

💬 Introducing Slack Agent: The best way for teams to turn conversations into code.

Slack Agent is built on CodeRabbit's deep understanding of your code, so your team can collaborate across the entire SDLC without losing context.

  • Generate code and open pull requests
  • Plan features and break down work
  • Investigate incidents and troubleshoot customer tickets together
  • Automate recurring tasks and respond to alerts with triggers
  • Summarize progress and report instantly

Built for teams:

  • Shared memory across your entire org—no repeating context
  • Per-thread sandboxes to safely plan and execute work
  • Governance built-in—scoped access, auditability, and budget controls

One agent for your entire SDLC. Right inside Slack.

👉 Get started


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@github-actionsgithub-actionsBot added size:XXL 1,000+ changed lines (additions + deletions). vouch:unvouched PR author is not yet trusted in the VOUCHED list. labels Apr 23, 2026
@justsomelegsjustsomelegs changed the title update providers in applicationprovider update advisoriesApr 23, 2026
@macroscopeapp

macroscopeappBot commented Apr 23, 2026

Copy link
Copy Markdown
Contributor

Approvability

Verdict: Needs human review

Diff is too large for automated approval analysis. A human reviewer should evaluate this PR.

You can customize Macroscope's approvability policy. Learn more.

@juliusmarminge

Copy link
Copy Markdown
Member

just merged a large refactor on how drivers work and is registerred so this will need to be updated, i can review it when it is

@justsomelegs
justsomelegsforce-pushed the feature/provider-update-advisories branch from aeb88d0 to 9c34d30CompareApril 30, 2026 11:22
@justsomelegs

Copy link
Copy Markdown
ContributorAuthor

@juliusmarminge this has been rebased now :)

Comment threadapps/server/src/provider/providerUpdater.ts Outdated
Comment threadapps/server/src/provider/providerUpdater.ts Outdated
Comment threadapps/server/src/provider/providerUpdater.ts Outdated
@github-actionsgithub-actionsBot added vouch:trusted PR author is trusted by repo permissions or the VOUCHED list. and removed vouch:unvouched PR author is not yet trusted in the VOUCHED list. labels Apr 30, 2026
@juliusmarminge

Copy link
Copy Markdown
Member

where is the update button?

CleanShot 2026-05-02 at 00 04 20@2x

@juliusmarminge

Copy link
Copy Markdown
Member

and there should be some "dismiss until next update" or something so it doesn't reprompt every load:

CleanShot.2026-05-02.at.00.05.13.mp4

- Rename provider update lifecycle types and resolvers
- Update provider snapshots and registry wiring
- Add advisory maintenance coordinator and tests
- Replace driver-scoped update state with per-instance maintenance action state
- Resolve update capabilities and progress through the target instance only
- Update provider updater and tests for the new registry API
Comment threadapps/server/src/provider/providerUpdater.ts Outdated
Comment threadapps/server/src/provider/providerMaintenance.ts Outdated
@juliusmarminge

juliusmarminge commented May 4, 2026

Copy link
Copy Markdown
Member

@justsomelegs mind trying it out now? made some changers

@justsomelegs

Copy link
Copy Markdown
ContributorAuthor

@juliusmarminge LGTM, the only things i changed were the toast to track the providers exact provider instanceId instead of collapsing by driver, so it stays aligned with the new instance-scoped update state and updated the tests to accomofate the popover changes you made

@juliusmarminge

Copy link
Copy Markdown
Member

yea made some architectural changes since i think this flow will eventually be extended to support installing drivers from and adding a proper onboarding etc

- Add Effect-based maintenance command runner with process spawning
- Allow dynamic update lock keys and preserve provider update advisories
- Update tests to cover the new runner and command flow
Comment threadapps/server/src/provider/providerMaintenanceRunner.ts Outdated
- move maintenance runner behind an Effect service
- add shared stream text collection for command output
- broaden tests around command execution and update locking
- Switch provider maintenance/version advisory helpers to Effect.fn
- Preserve npm/pnpm symlink detection while improving Effect test coverage
Comment threadapps/server/src/provider/providerMaintenance.ts
- Thread HttpClient through provider maintenance and snapshot refreshes
- Switch provider update visibility to ISO timestamps
- Add and update tests for maintenance and launch notification logic
Co-authored-by: codex <codex@users.noreply.github.com>
Comment threadapps/server/src/provider/Layers/CursorProvider.ts
- propagate maintenance capabilities into cursor snapshot enrichment
- surface queued update state while another provider update runs
- reset provider version cache between tests
Comment threadapps/server/src/provider/providerMaintenance.ts
- Add `/settings/providers` and route update entry points there
- Move provider management UI out of General settings
- Refresh provider card spacing and hierarchy
- Reduce padding in settings rows for a denser layout
- Remove extra line-height from row descriptions
Comment threadapps/server/src/provider/Layers/ProviderRegistry.ts Outdated
- Require `HttpClient` in Claude, Codex, Cursor, and OpenCode drivers
- Provide a test HTTP client in provider registry and instance registry specs
- Co-authored-by: codex <codex@users.noreply.github.com>
- keep cached models when refreshes return an empty list
- persist only the updated provider snapshots after merge

@cursorcursorBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes and found 1 potential issue.

There are 4 total unresolved issues (including 3 from previous reviews).

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit 55f46fa. Configure here.

if (onQueued) {
yield* onQueued;
}
return yield* lock.withPermits(1)(run);

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Queued state always published even without contention

Low Severity

onQueued fires unconditionally before acquiring the semaphore permit, meaning every provider update transitions through a "queued" state with message "Waiting for another provider update to finish." even when the semaphore is immediately available and no other update is running. This results in a briefly misleading sidebar pill and state history for single-provider updates with no contention.

Fix in CursorFix in Web

Reviewed by Cursor Bugbot for commit 55f46fa. Configure here.

@juliusmarminge
juliusmarminge merged commit 9b604bc into pingdotgg:mainMay 5, 2026
12 checks passed
imabdulazeez added a commit to imabdulazeez/t3code that referenced this pull request May 6, 2026
Brings in: server CLI submodule split (pingdotgg#2545), process/trace diagnostics
views (pingdotgg#2532), JetBrains editor support (pingdotgg#2475), MessagesTimeline render
optimizations (pingdotgg#2527, pingdotgg#2498), git/terminal test stabilization (pingdotgg#2540),
keybindings settings editor (pingdotgg#2533), and provider update advisories
(pingdotgg#2312).
Conflict resolutions:
- packages/contracts/src/settings.ts: kept aa's diffFontFamily and
terminalFontFamily alongside upstream's
dismissedProviderUpdateNotificationKeys.
- apps/desktop/src/clientPersistence.test.ts: same shape, fixture mirrors
the schema.
- apps/web/src/components/settings/SettingsPanels.tsx: kept both import
groups (FontPicker from aa, ProviderUpdateLaunchNotification.logic from
upstream).
- apps/web/src/localApi.test.ts: extended both fixtures with
diffFontFamily and terminalFontFamily so the merged ClientSettings
shape typechecks against the strict desktop bridge contract.
Pre-existing aa typecheck issues fixed at the root so the merge commit
is green:
- apps/desktop/src/electron.d.ts: declaration-merge "local-fonts" into
Electron's Session.setPermissionRequestHandler permission union (the
Electron 40 typings omit it even though the runtime supports it).
- apps/web/src/components/DiffPanel.tsx: conditionally spread style on
Virtualizer instead of passing undefined, satisfying
exactOptionalPropertyTypes.
sak0a referenced this pull request in saka-gg/ryco May 20, 2026
- ProviderRegistry: drop redundant applyProviderUpdateState call in setProviderMaintenanceActionState; upsertProviders already re-applies it
- providerMaintenance: remove /usr/local/bin/ from Homebrew matcher (over-matched npm-installed binaries when realPath did not resolve to /Cellar/); rely on Cellar/Caskroom/opt-homebrew/bin paths
- providerMaintenance: stop encodeURIComponent-ing scoped npm package names (encoded '@' as %40, which some registry proxies reject); only percent-encode the '/' separator
- providerSnapshot: drop dead 'driver' parameter on buildServerProvider and the unreachable createProviderVersionAdvisory branch; advisories come exclusively from enrichSnapshot
NeilTheFisher pushed a commit to NeilTheFisher/t3code that referenced this pull request Aug 18, 2026
Co-authored-by: Julius Marminge <julius0216@outlook.com>
Co-authored-by: codex <codex@users.noreply.github.com>
darjss pushed a commit to darjss/t3code that referenced this pull request Aug 26, 2026
Co-authored-by: Julius Marminge <julius0216@outlook.com>
Co-authored-by: codex <codex@users.noreply.github.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:XXL1,000+ changed lines (additions + deletions).vouch:trustedPR author is trusted by repo permissions or the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@justsomelegs@juliusmarminge@asfires
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

provider update advisories - #2312

Merged
juliusmarminge merged 36 commits into
pingdotgg:mainfrom
justsomelegs:feature/provider-update-advisories
May 5, 2026
Merged

provider update advisories#2312
juliusmarminge merged 36 commits into
pingdotgg:mainfrom
justsomelegs:feature/provider-update-advisories

Conversation

@justsomelegs

@justsomelegsjustsomelegs commented Apr 23, 2026

Copy link
Copy Markdown
Contributor

What Changed

Compared to main, this PR adds provider update advisories and update-state UI for installed providers.

Server-side:

  • adds provider version lifecycle/update state tracking
  • adds provider updater logic and related contract/RPC plumbing so the UI can know when a provider has an update available, is updating, succeeded, or failed

Web-side:

  • adds provider update toasts with a one-click Update action
  • adds a sidebar provider update pill for in-progress, success, and failure states
  • adds provider-specific success/failure copy
  • updates provider settings status copy to Up to date.
  • smooth-scrolls to the providers section when opening settings from update UI entry points

Also includes tests covering the update lifecycle, updater behavior, notification logic, and the rebased provider registry fixture change.

Why

main does not have provider update advisories or a dedicated way to surface provider update state in the UI.

This PR adds that missing flow so users can:

  • see when an installed provider has an update available
  • trigger the update directly from the UI
  • see update progress and result state in a persistent place
  • get clearer provider status after the update completes

The toast handles the action. The sidebar pill handles ongoing state and final status.

UI Changes

Compared to main:

Before:

  • no provider update advisory UI
  • no provider update progress/status pill
  • provider settings did not show post-update status

After:

  • outdated providers can surface update toasts with an Update action
  • the sidebar shows provider update progress/result state
  • success auto-dismisses after a short timeout
  • failure remains visible until dismissed
  • provider settings show Up to date. after a successful update
TOASTS Screenshot 2026-04-23 140501 SETTINGS Screenshot 2026-04-23 122852
update.demo.vid.mp4

Checklist

  • This PR is small and focused
  • I explained what changed and why
  • I included before/after screenshots for any UI changes
  • I included a video for animation/interaction changes

Note

Add provider update advisories, one-click updates, and version tracking across AI provider drivers

  • Adds version advisory support to Claude, Codex, Cursor, and OpenCode drivers: each driver now queries npm/Homebrew/native CLI for the latest version and attaches a versionAdvisory (status, versions, update command) to provider snapshots.
  • Introduces ProviderMaintenanceRunner and providerMaintenance modules to resolve per-driver update capabilities, coordinate serialized update command execution, and capture bounded stdout/stderr with timeout control.
  • Exposes a new server.updateProvider RPC/IPC method (WebSocket + LocalApi) that triggers provider updates and returns updated provider snapshots.
  • Adds a dedicated Providers settings panel with per-card update UI: an 'Update available' popover with a one-click 'Update now' button or clipboard copy for the update command.
  • Adds ProviderUpdateLaunchNotification (app-shell toast) and SidebarProviderUpdatePill (sidebar footer) to surface update prompts at launch with auto-dismiss, progress tracking, and navigation to provider settings.
  • Persists dismissed notification keys in client settings and localStorage via providerUpdateDismissal utilities.
  • Risk: makeManagedServerProvider now requires a maintenanceCapabilities field (breaking change for callers); driver environments must provide HttpClient.

Macroscope summarized 55f46fa.


Open in Devin Review

Note

High Risk
Adds a new server-side update runner that executes provider update commands and threads volatile update state through the provider registry and WebSocket RPC, which is security- and stability-sensitive. Also changes provider snapshot construction/enrichment and persistence behavior, increasing risk of regressions in provider status caching and UI state.

Overview
Adds provider update advisories and one-click updates. Provider drivers now compute maintenanceCapabilities and enrich snapshots with a versionAdvisory fetched via HTTP (npm latest) so the UI can detect “behind latest” providers.

Introduces an update execution flow. A new ProviderMaintenanceRunner runs allowlisted update commands (with locking, timeouts, and truncated output capture), exposes it via serverUpdateProvider WebSocket RPC, and projects per-instance updateState into provider snapshots without persisting it.

Refactors snapshot/caching plumbing to support this state.makeManagedServerProvider now requires maintenanceCapabilities; ProviderRegistry adds helpers to merge snapshots while preserving model capabilities on empty refreshes and only persists refreshed instances; and stream text collection is centralized via collectUint8StreamText (also reused by VCS output collection).

Reviewed by Cursor Bugbot for commit 55f46fa. Bugbot is set up for automated code reviews on this repo. Configure here.

@coderabbitai

coderabbitaiBot commented Apr 23, 2026

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Repository UI

Review profile: CHILL

Plan: Pro

Run ID: 343c17c5-6351-43e2-9829-63a3c893691d

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests

Tip

💬 Introducing Slack Agent: The best way for teams to turn conversations into code.

Slack Agent is built on CodeRabbit's deep understanding of your code, so your team can collaborate across the entire SDLC without losing context.

  • Generate code and open pull requests
  • Plan features and break down work
  • Investigate incidents and troubleshoot customer tickets together
  • Automate recurring tasks and respond to alerts with triggers
  • Summarize progress and report instantly

Built for teams:

  • Shared memory across your entire org—no repeating context
  • Per-thread sandboxes to safely plan and execute work
  • Governance built-in—scoped access, auditability, and budget controls

One agent for your entire SDLC. Right inside Slack.

👉 Get started


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@github-actionsgithub-actionsBot added size:XXL 1,000+ changed lines (additions + deletions). vouch:unvouched PR author is not yet trusted in the VOUCHED list. labels Apr 23, 2026
@justsomelegsjustsomelegs changed the title update providers in applicationprovider update advisoriesApr 23, 2026
@macroscopeapp

macroscopeappBot commented Apr 23, 2026

Copy link
Copy Markdown
Contributor

Approvability

Verdict: Needs human review

Diff is too large for automated approval analysis. A human reviewer should evaluate this PR.

You can customize Macroscope's approvability policy. Learn more.

@juliusmarminge

Copy link
Copy Markdown
Member

just merged a large refactor on how drivers work and is registerred so this will need to be updated, i can review it when it is

@justsomelegs
justsomelegsforce-pushed the feature/provider-update-advisories branch from aeb88d0 to 9c34d30CompareApril 30, 2026 11:22
@justsomelegs

Copy link
Copy Markdown
ContributorAuthor

@juliusmarminge this has been rebased now :)

Comment threadapps/server/src/provider/providerUpdater.ts Outdated
Comment threadapps/server/src/provider/providerUpdater.ts Outdated
Comment threadapps/server/src/provider/providerUpdater.ts Outdated
@github-actionsgithub-actionsBot added vouch:trusted PR author is trusted by repo permissions or the VOUCHED list. and removed vouch:unvouched PR author is not yet trusted in the VOUCHED list. labels Apr 30, 2026
@juliusmarminge

Copy link
Copy Markdown
Member

where is the update button?

CleanShot 2026-05-02 at 00 04 20@2x

@juliusmarminge

Copy link
Copy Markdown
Member

and there should be some "dismiss until next update" or something so it doesn't reprompt every load:

CleanShot.2026-05-02.at.00.05.13.mp4

- Rename provider update lifecycle types and resolvers
- Update provider snapshots and registry wiring
- Add advisory maintenance coordinator and tests
- Replace driver-scoped update state with per-instance maintenance action state
- Resolve update capabilities and progress through the target instance only
- Update provider updater and tests for the new registry API
Comment threadapps/server/src/provider/providerUpdater.ts Outdated
Comment threadapps/server/src/provider/providerMaintenance.ts Outdated
@juliusmarminge

juliusmarminge commented May 4, 2026

Copy link
Copy Markdown
Member

@justsomelegs mind trying it out now? made some changers

@justsomelegs

Copy link
Copy Markdown
ContributorAuthor

@juliusmarminge LGTM, the only things i changed were the toast to track the providers exact provider instanceId instead of collapsing by driver, so it stays aligned with the new instance-scoped update state and updated the tests to accomofate the popover changes you made

@juliusmarminge

Copy link
Copy Markdown
Member

yea made some architectural changes since i think this flow will eventually be extended to support installing drivers from and adding a proper onboarding etc

- Add Effect-based maintenance command runner with process spawning
- Allow dynamic update lock keys and preserve provider update advisories
- Update tests to cover the new runner and command flow
Comment threadapps/server/src/provider/providerMaintenanceRunner.ts Outdated
- move maintenance runner behind an Effect service
- add shared stream text collection for command output
- broaden tests around command execution and update locking
- Switch provider maintenance/version advisory helpers to Effect.fn
- Preserve npm/pnpm symlink detection while improving Effect test coverage
Comment threadapps/server/src/provider/providerMaintenance.ts
- Thread HttpClient through provider maintenance and snapshot refreshes
- Switch provider update visibility to ISO timestamps
- Add and update tests for maintenance and launch notification logic
Co-authored-by: codex <codex@users.noreply.github.com>
Comment threadapps/server/src/provider/Layers/CursorProvider.ts
- propagate maintenance capabilities into cursor snapshot enrichment
- surface queued update state while another provider update runs
- reset provider version cache between tests
Comment threadapps/server/src/provider/providerMaintenance.ts
- Add `/settings/providers` and route update entry points there
- Move provider management UI out of General settings
- Refresh provider card spacing and hierarchy
- Reduce padding in settings rows for a denser layout
- Remove extra line-height from row descriptions
Comment threadapps/server/src/provider/Layers/ProviderRegistry.ts Outdated
- Require `HttpClient` in Claude, Codex, Cursor, and OpenCode drivers
- Provide a test HTTP client in provider registry and instance registry specs
- Co-authored-by: codex <codex@users.noreply.github.com>
- keep cached models when refreshes return an empty list
- persist only the updated provider snapshots after merge

@cursorcursorBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes and found 1 potential issue.

There are 4 total unresolved issues (including 3 from previous reviews).

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit 55f46fa. Configure here.

if (onQueued) {
yield* onQueued;
}
return yield* lock.withPermits(1)(run);

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Queued state always published even without contention

Low Severity

onQueued fires unconditionally before acquiring the semaphore permit, meaning every provider update transitions through a "queued" state with message "Waiting for another provider update to finish." even when the semaphore is immediately available and no other update is running. This results in a briefly misleading sidebar pill and state history for single-provider updates with no contention.

Fix in CursorFix in Web

Reviewed by Cursor Bugbot for commit 55f46fa. Configure here.

@juliusmarminge
juliusmarminge merged commit 9b604bc into pingdotgg:mainMay 5, 2026
12 checks passed
imabdulazeez added a commit to imabdulazeez/t3code that referenced this pull request May 6, 2026
Brings in: server CLI submodule split (pingdotgg#2545), process/trace diagnostics
views (pingdotgg#2532), JetBrains editor support (pingdotgg#2475), MessagesTimeline render
optimizations (pingdotgg#2527, pingdotgg#2498), git/terminal test stabilization (pingdotgg#2540),
keybindings settings editor (pingdotgg#2533), and provider update advisories
(pingdotgg#2312).
Conflict resolutions:
- packages/contracts/src/settings.ts: kept aa's diffFontFamily and
terminalFontFamily alongside upstream's
dismissedProviderUpdateNotificationKeys.
- apps/desktop/src/clientPersistence.test.ts: same shape, fixture mirrors
the schema.
- apps/web/src/components/settings/SettingsPanels.tsx: kept both import
groups (FontPicker from aa, ProviderUpdateLaunchNotification.logic from
upstream).
- apps/web/src/localApi.test.ts: extended both fixtures with
diffFontFamily and terminalFontFamily so the merged ClientSettings
shape typechecks against the strict desktop bridge contract.
Pre-existing aa typecheck issues fixed at the root so the merge commit
is green:
- apps/desktop/src/electron.d.ts: declaration-merge "local-fonts" into
Electron's Session.setPermissionRequestHandler permission union (the
Electron 40 typings omit it even though the runtime supports it).
- apps/web/src/components/DiffPanel.tsx: conditionally spread style on
Virtualizer instead of passing undefined, satisfying
exactOptionalPropertyTypes.
sak0a referenced this pull request in saka-gg/ryco May 20, 2026
- ProviderRegistry: drop redundant applyProviderUpdateState call in setProviderMaintenanceActionState; upsertProviders already re-applies it
- providerMaintenance: remove /usr/local/bin/ from Homebrew matcher (over-matched npm-installed binaries when realPath did not resolve to /Cellar/); rely on Cellar/Caskroom/opt-homebrew/bin paths
- providerMaintenance: stop encodeURIComponent-ing scoped npm package names (encoded '@' as %40, which some registry proxies reject); only percent-encode the '/' separator
- providerSnapshot: drop dead 'driver' parameter on buildServerProvider and the unreachable createProviderVersionAdvisory branch; advisories come exclusively from enrichSnapshot
NeilTheFisher pushed a commit to NeilTheFisher/t3code that referenced this pull request Aug 18, 2026
Co-authored-by: Julius Marminge <julius0216@outlook.com>
Co-authored-by: codex <codex@users.noreply.github.com>
darjss pushed a commit to darjss/t3code that referenced this pull request Aug 26, 2026
Co-authored-by: Julius Marminge <julius0216@outlook.com>
Co-authored-by: codex <codex@users.noreply.github.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:XXL1,000+ changed lines (additions + deletions).vouch:trustedPR author is trusted by repo permissions or the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@justsomelegs@juliusmarminge@asfires
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

provider update advisories - #2312

Merged
juliusmarminge merged 36 commits into
pingdotgg:mainfrom
justsomelegs:feature/provider-update-advisories
May 5, 2026
Merged

provider update advisories#2312
juliusmarminge merged 36 commits into
pingdotgg:mainfrom
justsomelegs:feature/provider-update-advisories

Conversation

@justsomelegs

@justsomelegsjustsomelegs commented Apr 23, 2026

Copy link
Copy Markdown
Contributor

What Changed

Compared to main, this PR adds provider update advisories and update-state UI for installed providers.

Server-side:

  • adds provider version lifecycle/update state tracking
  • adds provider updater logic and related contract/RPC plumbing so the UI can know when a provider has an update available, is updating, succeeded, or failed

Web-side:

  • adds provider update toasts with a one-click Update action
  • adds a sidebar provider update pill for in-progress, success, and failure states
  • adds provider-specific success/failure copy
  • updates provider settings status copy to Up to date.
  • smooth-scrolls to the providers section when opening settings from update UI entry points

Also includes tests covering the update lifecycle, updater behavior, notification logic, and the rebased provider registry fixture change.

Why

main does not have provider update advisories or a dedicated way to surface provider update state in the UI.

This PR adds that missing flow so users can:

  • see when an installed provider has an update available
  • trigger the update directly from the UI
  • see update progress and result state in a persistent place
  • get clearer provider status after the update completes

The toast handles the action. The sidebar pill handles ongoing state and final status.

UI Changes

Compared to main:

Before:

  • no provider update advisory UI
  • no provider update progress/status pill
  • provider settings did not show post-update status

After:

  • outdated providers can surface update toasts with an Update action
  • the sidebar shows provider update progress/result state
  • success auto-dismisses after a short timeout
  • failure remains visible until dismissed
  • provider settings show Up to date. after a successful update
TOASTS Screenshot 2026-04-23 140501 SETTINGS Screenshot 2026-04-23 122852
update.demo.vid.mp4

Checklist

  • This PR is small and focused
  • I explained what changed and why
  • I included before/after screenshots for any UI changes
  • I included a video for animation/interaction changes

Note

Add provider update advisories, one-click updates, and version tracking across AI provider drivers

  • Adds version advisory support to Claude, Codex, Cursor, and OpenCode drivers: each driver now queries npm/Homebrew/native CLI for the latest version and attaches a versionAdvisory (status, versions, update command) to provider snapshots.
  • Introduces ProviderMaintenanceRunner and providerMaintenance modules to resolve per-driver update capabilities, coordinate serialized update command execution, and capture bounded stdout/stderr with timeout control.
  • Exposes a new server.updateProvider RPC/IPC method (WebSocket + LocalApi) that triggers provider updates and returns updated provider snapshots.
  • Adds a dedicated Providers settings panel with per-card update UI: an 'Update available' popover with a one-click 'Update now' button or clipboard copy for the update command.
  • Adds ProviderUpdateLaunchNotification (app-shell toast) and SidebarProviderUpdatePill (sidebar footer) to surface update prompts at launch with auto-dismiss, progress tracking, and navigation to provider settings.
  • Persists dismissed notification keys in client settings and localStorage via providerUpdateDismissal utilities.
  • Risk: makeManagedServerProvider now requires a maintenanceCapabilities field (breaking change for callers); driver environments must provide HttpClient.

Macroscope summarized 55f46fa.


Open in Devin Review

Note

High Risk
Adds a new server-side update runner that executes provider update commands and threads volatile update state through the provider registry and WebSocket RPC, which is security- and stability-sensitive. Also changes provider snapshot construction/enrichment and persistence behavior, increasing risk of regressions in provider status caching and UI state.

Overview
Adds provider update advisories and one-click updates. Provider drivers now compute maintenanceCapabilities and enrich snapshots with a versionAdvisory fetched via HTTP (npm latest) so the UI can detect “behind latest” providers.

Introduces an update execution flow. A new ProviderMaintenanceRunner runs allowlisted update commands (with locking, timeouts, and truncated output capture), exposes it via serverUpdateProvider WebSocket RPC, and projects per-instance updateState into provider snapshots without persisting it.

Refactors snapshot/caching plumbing to support this state.makeManagedServerProvider now requires maintenanceCapabilities; ProviderRegistry adds helpers to merge snapshots while preserving model capabilities on empty refreshes and only persists refreshed instances; and stream text collection is centralized via collectUint8StreamText (also reused by VCS output collection).

Reviewed by Cursor Bugbot for commit 55f46fa. Bugbot is set up for automated code reviews on this repo. Configure here.

@coderabbitai

coderabbitaiBot commented Apr 23, 2026

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Repository UI

Review profile: CHILL

Plan: Pro

Run ID: 343c17c5-6351-43e2-9829-63a3c893691d

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests

Tip

💬 Introducing Slack Agent: The best way for teams to turn conversations into code.

Slack Agent is built on CodeRabbit's deep understanding of your code, so your team can collaborate across the entire SDLC without losing context.

  • Generate code and open pull requests
  • Plan features and break down work
  • Investigate incidents and troubleshoot customer tickets together
  • Automate recurring tasks and respond to alerts with triggers
  • Summarize progress and report instantly

Built for teams:

  • Shared memory across your entire org—no repeating context
  • Per-thread sandboxes to safely plan and execute work
  • Governance built-in—scoped access, auditability, and budget controls

One agent for your entire SDLC. Right inside Slack.

👉 Get started


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@github-actionsgithub-actionsBot added size:XXL 1,000+ changed lines (additions + deletions). vouch:unvouched PR author is not yet trusted in the VOUCHED list. labels Apr 23, 2026
@justsomelegsjustsomelegs changed the title update providers in applicationprovider update advisoriesApr 23, 2026
@macroscopeapp

macroscopeappBot commented Apr 23, 2026

Copy link
Copy Markdown
Contributor

Approvability

Verdict: Needs human review

Diff is too large for automated approval analysis. A human reviewer should evaluate this PR.

You can customize Macroscope's approvability policy. Learn more.

@juliusmarminge

Copy link
Copy Markdown
Member

just merged a large refactor on how drivers work and is registerred so this will need to be updated, i can review it when it is

@justsomelegs
justsomelegsforce-pushed the feature/provider-update-advisories branch from aeb88d0 to 9c34d30CompareApril 30, 2026 11:22
@justsomelegs

Copy link
Copy Markdown
ContributorAuthor

@juliusmarminge this has been rebased now :)

Comment threadapps/server/src/provider/providerUpdater.ts Outdated
Comment threadapps/server/src/provider/providerUpdater.ts Outdated
Comment threadapps/server/src/provider/providerUpdater.ts Outdated
@github-actionsgithub-actionsBot added vouch:trusted PR author is trusted by repo permissions or the VOUCHED list. and removed vouch:unvouched PR author is not yet trusted in the VOUCHED list. labels Apr 30, 2026
@juliusmarminge

Copy link
Copy Markdown
Member

where is the update button?

CleanShot 2026-05-02 at 00 04 20@2x

@juliusmarminge

Copy link
Copy Markdown
Member

and there should be some "dismiss until next update" or something so it doesn't reprompt every load:

CleanShot.2026-05-02.at.00.05.13.mp4

- Rename provider update lifecycle types and resolvers
- Update provider snapshots and registry wiring
- Add advisory maintenance coordinator and tests
- Replace driver-scoped update state with per-instance maintenance action state
- Resolve update capabilities and progress through the target instance only
- Update provider updater and tests for the new registry API
Comment threadapps/server/src/provider/providerUpdater.ts Outdated
Comment threadapps/server/src/provider/providerMaintenance.ts Outdated
@juliusmarminge

juliusmarminge commented May 4, 2026

Copy link
Copy Markdown
Member

@justsomelegs mind trying it out now? made some changers

@justsomelegs

Copy link
Copy Markdown
ContributorAuthor

@juliusmarminge LGTM, the only things i changed were the toast to track the providers exact provider instanceId instead of collapsing by driver, so it stays aligned with the new instance-scoped update state and updated the tests to accomofate the popover changes you made

@juliusmarminge

Copy link
Copy Markdown
Member

yea made some architectural changes since i think this flow will eventually be extended to support installing drivers from and adding a proper onboarding etc

- Add Effect-based maintenance command runner with process spawning
- Allow dynamic update lock keys and preserve provider update advisories
- Update tests to cover the new runner and command flow
Comment threadapps/server/src/provider/providerMaintenanceRunner.ts Outdated
- move maintenance runner behind an Effect service
- add shared stream text collection for command output
- broaden tests around command execution and update locking
- Switch provider maintenance/version advisory helpers to Effect.fn
- Preserve npm/pnpm symlink detection while improving Effect test coverage
Comment threadapps/server/src/provider/providerMaintenance.ts
- Thread HttpClient through provider maintenance and snapshot refreshes
- Switch provider update visibility to ISO timestamps
- Add and update tests for maintenance and launch notification logic
Co-authored-by: codex <codex@users.noreply.github.com>
Comment threadapps/server/src/provider/Layers/CursorProvider.ts
- propagate maintenance capabilities into cursor snapshot enrichment
- surface queued update state while another provider update runs
- reset provider version cache between tests
Comment threadapps/server/src/provider/providerMaintenance.ts
- Add `/settings/providers` and route update entry points there
- Move provider management UI out of General settings
- Refresh provider card spacing and hierarchy
- Reduce padding in settings rows for a denser layout
- Remove extra line-height from row descriptions
Comment threadapps/server/src/provider/Layers/ProviderRegistry.ts Outdated
- Require `HttpClient` in Claude, Codex, Cursor, and OpenCode drivers
- Provide a test HTTP client in provider registry and instance registry specs
- Co-authored-by: codex <codex@users.noreply.github.com>
- keep cached models when refreshes return an empty list
- persist only the updated provider snapshots after merge

@cursorcursorBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes and found 1 potential issue.

There are 4 total unresolved issues (including 3 from previous reviews).

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit 55f46fa. Configure here.

if (onQueued) {
yield* onQueued;
}
return yield* lock.withPermits(1)(run);

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Queued state always published even without contention

Low Severity

onQueued fires unconditionally before acquiring the semaphore permit, meaning every provider update transitions through a "queued" state with message "Waiting for another provider update to finish." even when the semaphore is immediately available and no other update is running. This results in a briefly misleading sidebar pill and state history for single-provider updates with no contention.

Fix in CursorFix in Web

Reviewed by Cursor Bugbot for commit 55f46fa. Configure here.

@juliusmarminge
juliusmarminge merged commit 9b604bc into pingdotgg:mainMay 5, 2026
12 checks passed
imabdulazeez added a commit to imabdulazeez/t3code that referenced this pull request May 6, 2026
Brings in: server CLI submodule split (pingdotgg#2545), process/trace diagnostics
views (pingdotgg#2532), JetBrains editor support (pingdotgg#2475), MessagesTimeline render
optimizations (pingdotgg#2527, pingdotgg#2498), git/terminal test stabilization (pingdotgg#2540),
keybindings settings editor (pingdotgg#2533), and provider update advisories
(pingdotgg#2312).
Conflict resolutions:
- packages/contracts/src/settings.ts: kept aa's diffFontFamily and
terminalFontFamily alongside upstream's
dismissedProviderUpdateNotificationKeys.
- apps/desktop/src/clientPersistence.test.ts: same shape, fixture mirrors
the schema.
- apps/web/src/components/settings/SettingsPanels.tsx: kept both import
groups (FontPicker from aa, ProviderUpdateLaunchNotification.logic from
upstream).
- apps/web/src/localApi.test.ts: extended both fixtures with
diffFontFamily and terminalFontFamily so the merged ClientSettings
shape typechecks against the strict desktop bridge contract.
Pre-existing aa typecheck issues fixed at the root so the merge commit
is green:
- apps/desktop/src/electron.d.ts: declaration-merge "local-fonts" into
Electron's Session.setPermissionRequestHandler permission union (the
Electron 40 typings omit it even though the runtime supports it).
- apps/web/src/components/DiffPanel.tsx: conditionally spread style on
Virtualizer instead of passing undefined, satisfying
exactOptionalPropertyTypes.
sak0a referenced this pull request in saka-gg/ryco May 20, 2026
- ProviderRegistry: drop redundant applyProviderUpdateState call in setProviderMaintenanceActionState; upsertProviders already re-applies it
- providerMaintenance: remove /usr/local/bin/ from Homebrew matcher (over-matched npm-installed binaries when realPath did not resolve to /Cellar/); rely on Cellar/Caskroom/opt-homebrew/bin paths
- providerMaintenance: stop encodeURIComponent-ing scoped npm package names (encoded '@' as %40, which some registry proxies reject); only percent-encode the '/' separator
- providerSnapshot: drop dead 'driver' parameter on buildServerProvider and the unreachable createProviderVersionAdvisory branch; advisories come exclusively from enrichSnapshot
NeilTheFisher pushed a commit to NeilTheFisher/t3code that referenced this pull request Aug 18, 2026
Co-authored-by: Julius Marminge <julius0216@outlook.com>
Co-authored-by: codex <codex@users.noreply.github.com>
darjss pushed a commit to darjss/t3code that referenced this pull request Aug 26, 2026
Co-authored-by: Julius Marminge <julius0216@outlook.com>
Co-authored-by: codex <codex@users.noreply.github.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:XXL1,000+ changed lines (additions + deletions).vouch:trustedPR author is trusted by repo permissions or the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@justsomelegs@juliusmarminge@asfires